IP Library › Granted Patent US 12,273,384
Granted Patent B2
US 12,273,384 · App. 17/882,429 · Granted Apr 8, 2025

User activity-triggered URL scan

Inventors: Oliver G. Devane (Upton, GB); Abhishek Karnik (Portland, OR)
Assignee: McAfee, LLC
H04L63/1483G06F16/953H04L63/1416H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,273,384
App. No.
17/882,429
Granted
Apr 8, 2025
Kind
B2
Abstract

There is disclosed in one example a computing apparatus, including: a hardware platform including a processor and a memory; a network interface; a user-space application including instructions to interact with a web site via a uniform resource locator (URL); and a security agent including instructions to: intercept an interaction of the user-space application with the web site; determine that the intercepted interaction is to send sensitive information to the web site; suspend the interaction; and assign a reputation to the URL.

Claims (33)

1. A method of protecting a user of a device from phishing attacks, comprising:

detecting an attempted hypertext markup language (HTML) POST operation by the user on a website;

after detecting the HTML POST operation, pausing the HTML POST operation before the device sends data associated with the HTML POST operation to the website;

getting a reputation for the website; and

based on determining that the reputation is a good reputation, unpausing the HTML POST operation, or based on determining that the reputation is a bad reputation, taking a remedial action, wherein determining that the reputation is a bad reputation comprises determining that the website has a reputation against policy for an enterprise that the device belongs to or connects to.

2. The method of claim 1 , wherein getting the reputation comprises querying a cloud-based reputation store.

3. The method of claim 1 , wherein getting the reputation comprises analyzing the website for phishing features.

4. The method of claim 3 , wherein analyzing the website for phishing features comprises analyzing the website on the device.

5. The method of claim 3 , wherein analyzing the website for phishing features comprises sending the website or features of the website to a cloud service for analysis.

6. The method of claim 1 , wherein getting the reputation comprises getting a reputation for a uniform resource locator (URL) of the website.

7. The method of claim 1 , wherein determining that the reputation is a good reputation comprises determining that the website has a reputation as a legitimate website.

8. The method of claim 1 , wherein determining that the reputation is a bad reputation comprises determining that the website has a reputation as a phishing website.

9. The method of claim 1 , wherein determining that the reputation is a bad reputation comprises determining that the website has a reputation as a malware website.

10. The method of claim 1 , wherein the remedial action comprises blocking the website.

11. The method of claim 1 , wherein the remedial action comprises warning the user.

12. One or more tangible, non-transitory computer-readable media having stored thereon executable instructions to instruct a processor circuit to:

intercept an attempted hypertext markup language (HTML) POST operation initiated by a user on a website;

after intercepting the HTML POST operation, pause the HTML POST operation before sending any data associated with the HTML POST operation to the website;

while the HTML POST operation is paused, get a reputation for the website, wherein the reputation includes a policy for an enterprise; and

based on the reputation, determine whether to allow the HTML POST operation or to take a remedial action.

13. The one or more tangible, non-transitory computer-readable media of claim 12 , wherein getting the reputation comprises querying a cloud-based reputation store.

14. The one or more tangible, non-transitory computer-readable media of claim 12 , wherein getting the reputation comprises analyzing the website for phishing features.

15. The one or more tangible, non-transitory computer-readable media of claim 14 , wherein analyzing the website for phishing features comprises analyzing the website on a local device.

16. The one or more tangible, non-transitory computer-readable media of claim 14 , wherein analyzing the website for phishing features comprises sending the website or features of the website to a cloud service for analysis.

17. A computing apparatus, comprising:

a processor circuit and a memory; and

instructions encoded within the memory to instruct the processor circuit to:

intercept a hypertext markup language (HTML) POST operation initiated by a user for a website;

suspend the HTML POST operation before the computing apparatus sends data associated with the HTML POST operation to the website;

get a reputation for the website, wherein the reputation includes a policy for an enterprise that the computing apparat s connects to; and

based on the reputation, determine whether to unsuspend the HTML POST operation or to take a remedial action.

18. The computing apparatus of claim 17 , wherein getting the reputation comprises querying a cloud-based reputation store.

19. The computing apparatus of claim 17 , wherein getting the reputation comprises analyzing the website for phishing features.

Continuity (2)
Continuation 16506267 · Jul 9, 2019
Related Publication 20220385695A1 · Dec 1, 2022
References Cited (20)
US 8521667B2 · Zhu · 2013 [cited by examiner]
US 8910279B2 · Yanovsky · 2014 [cited by examiner]
US 9224006B1 · Firestone · 2015 [cited by examiner]
US 9338137B1 · Fedko · 2016 [cited by examiner]
US 9398028B1 · Karandikar · 2016 [cited by examiner]
US 20100186088A1 · Banerjee · 2010 [cited by examiner]
US 20110087781A1 · Kim · 2011 [cited by examiner]
US 20110296519A1 · Ide · 2011 [cited by examiner]
US 20120030293A1 · Bobotek · 2012 [cited by examiner]
US 20130133048A1 · Wyn-Harris · 2013 [cited by examiner]
US 20140090055A1 · Palumbo · 2014 [cited by examiner]
US 20140331119A1 · Dixon · 2014 [cited by examiner]
US 20150134956A1 · Stachura · 2015 [cited by examiner]
US 20160028673A1 · Jeyaraman · 2016 [cited by examiner]
US 20160127475A1 · PalChaudhuri · 2016 [cited by examiner]
US 20170195363A1 · Dahan · 2017 [cited by examiner]
US 20180191777A1 · Volkov · 2018 [cited by examiner]
US 20190020664A1 · Wood · 2019 [cited by examiner]
US 20190132357A1 · Damian · 2019 [cited by examiner]
US 20200004989A1 · Lockhart, III · 2020 [cited by examiner]