IP Library Granted Patent US 12,192,233
Granted Patent B2
US 12,192,233 · App. 17/231,618 · Granted Jan 7, 2025

Systems and methods for phishing attack protection based on identity provider verification

Inventor: Manbinder Pal Singh (Coral Springs, FL)
Assignee: Citrix Systems, Inc.
H04L63/1483G06N3/04G06N3/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,192,233
App. No.
17/231,618
Granted
Jan 7, 2025
Kind
B2
Abstract

A computer system is provided. The computer system includes a memory and at least one processor coupled to the memory and configured to provide phishing attack protection based on identity provider verification. The at least one processor is further configured to capture an image of a browser web page to which the user has navigated and identify the domain name associated with the browser web page. The at least one processor is further configured to determine that the captured image matches an image of a known identity provider web page. The at least one processor is further configured to detect a phishing attempt in response to the determination that the images match and that the domain name associated with the browser web page differs from the domain name associated with the identity provider web page.

Claims (42)

1. A computer system comprising:

a memory; and

at least one processor coupled to the memory and configured to:

train a neural network, the training including:

navigating to an identity provider (IdP) web page based on a domain name associated with the IdP web page;

capturing an image of the IdP web page;

generating variations of the image of the IdP web page by modifying attributes of the image of the IdP, the attributes including one or more of a background color, logos, fonts, dimensions, languages, words, or phrases; and

employing the variations to train the neural network;

capture an image of a browser web page;

identify a domain name associated with the browser web page;

employ the neural network to determine an image match where the captured image matches the image of the IdP web page; and

detect a phishing attempt in response to the determination of the image match, if the domain name associated with the browser web page differs from the domain name associated with the IdP web page.

2. The computer system of claim 1 , wherein the domain name associated with the IdP web page is obtained from a datastore of IdP web pages, the datastore configured by an administrator.

3. The computer system of claim 1 , wherein the at least one processor is further configured to bypass the detection of the phishing attempt in response to a determination that the browser web page is not a sign-in page.

4. The computer system of claim 1 , wherein the at least one processor is further configured to perform a security action in response to the detected phishing attempt, the security action including one or more of providing a warning to a device associated with a user who navigated to the browser web page, logging the detection, and generating an alert to an administrator.

5. A method for protection of user credentials comprising:

training, by a computer system, a neural network, the training including:

navigating to an identity provider (IdP) web page based on a second domain name associated with the IdP web page;

capturing an image of the IdP web page;

generating variations of the image of the IdP web page by modifying attributes of the image of the IdP, the attributes including one or more of a background color, logos, fonts, dimensions, languages, words, or phrases; and

employing the variations to train the neural network;

capturing, by the computer system, an image of a browser web page;

identifying, by the computer system, a first domain name associated with the browser web page;

employing, by the computer system, the neural network to determine that the captured image matches an image of the IdP web page;

determining, by the computer system, that the first domain name differs from the second domain name; and

detecting, by the computer system, a phishing attempt in response to the determination that the captured image matches the image of the IdP web page and the determination that the first domain name differs from the second domain name.

6. The method of claim 5 , wherein the second domain name is obtained from a datastore of IdP web pages, the datastore configured by an administrator.

7. The method of claim 5 , further comprising bypassing the detection of the phishing attempt in response to a determination that the browser web page is not a sign-in page.

8. The method of claim 5 , further comprising performing a security action in response to the detected phishing attempt, the security action including one or more of providing a warning to a device associated with a user who navigated to the browser web page, logging the detection, and generating an alert to an administrator.

9. A non-transitory computer readable medium storing executable sequences of instructions to provide protection of user credentials, the sequences of instructions comprising instructions to:

train a neural network, the training including:

navigating to an identity provider (IdP) web page based on a domain name associated with the IdP web page;

capturing an image of the IdP web page;

generating variations of the image of the IdP web page by modifying attributes of the image of the IdP, the attributes including one or more of a background color, logos, fonts, dimensions, languages, words, or phrases; and

employing the variations to train the neural network;

capture an image of a browser web page;

identify a domain name associated with the browser web page;

employ the neural network to determine an image match where the captured image matches the image of the IdP web page; and

detect a phishing attempt in response to the determination of the image match, if the domain name associated with the browser web page differs from the domain name associated with the IdP web page.

10. The computer readable medium of claim 9 , wherein the domain name associated with the IdP web page is obtained from a datastore of IdP web pages, the datastore configured by an administrator.

11. The computer readable medium of claim 9 , wherein the sequences of instructions further include instructions to bypass the detection of the phishing attempt in response to a determination that the browser web page is not a sign-in page.

12. The computer readable medium of claim 9 , wherein the sequences of instructions further include instructions to perform a security action in response to the detected phishing attempt, the security action including one or more of providing a warning to a device associated with a user who navigated to the browser web page, logging the detection, and generating an alert to an administrator.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 29, 2021
From: SINGH, MANBINDER PAL
To: CITRIX SYSTEMS, INC.
Reel/Frame 056085/0177 →
Continuity (1)
Related Publication 20220337625A1 · Oct 20, 2022
References Cited (25)
US 8220047B1 · Soghoian et al. · 2012 [cited by applicant]
US 9736147B1 · Mead · 2017 [cited by applicant]
US 11356481B1 · Singh · 2022 [cited by examiner]
US 11997135B2 · Wing · 2024 [cited by applicant]
US 20070006305A1 · Florencio et al. · 2007 [cited by applicant]
US 20070199054A1 · Florencio et al. · 2007 [cited by applicant]
US 20080098464A1 · Mizrah · 2008 [cited by applicant]
US 20090063462A1 · Alfonseca · 2009 [cited by applicant]
US 20160253492A1 · Chougle · 2016 [cited by applicant]
US 20190014149A1 · Cleveland · 2019 [cited by examiner]
US 20190173921A1 · Dicorpo et al. · 2019 [cited by applicant]
US 20200137110A1 · Tyler et al. · 2020 [cited by applicant]
US 20210092155A1 · Wang et al. · 2021 [cited by applicant]
US 20210344711A1 · Cleveland · 2021 [cited by examiner]
US 20220030029A1 · Kagan · 2022 [cited by examiner]
US 20230121470A1 · Singh · 2023 [cited by examiner]
EP 2348442 · 2011 [cited by applicant]
WO 2020110109A1 · 2020 [cited by applicant]
WO 2021056230A1 · 2021 [cited by applicant]
Adebowale M.A. et al., “Intelligent Phishing Detection Scheme Using Deep Learning Algorithms”, retrieved from the Internet: https://arro.anglia.ac.uk/id/eprint/705509/1/Adebowale_2020.pdf [copy retrieved Apr. 8, 2021], … [cited by applicant]
International Search Report mailed Jun. 23, 2020 for International Patent Application No. PCT/CN2019/107676, 4 pages. [cited by applicant]
Written Opinion mailed Jun. 23, 2020 for International Patent Application No. PCT/CN2019/107676, 4 pages. [cited by applicant]
How to check the security state of an XMLHTTPRequest over SSL, downloaded from https://developer.mozilla.org/en-US/docs/Web/API/XMLHttpRequest/How_to_check_the_secruity_state_of_an_XMLHTTPRequest_over_SSL, downloaded No… [cited by applicant]
International Search Report and Written Submission mailed Apr. 25, 2022 for International Application No. PCT/US2022/013791 (10 pages). [cited by applicant]
International Search Report and Written Submission mailed Mar. 25, 2022 for International Application No. DCT/US2021/064914 (7 pages). [cited by applicant]
Cited By (1)
US 12,625,964