IP Library Granted Patent US 12,413,621
Granted Patent B2
US 12,413,621 · App. 18/649,734 · Granted Sep 9, 2025

Visual detection of phishing websites via headless browser

Inventor: Shashi KIran N (Bangalore, IN)
Assignee: McAfee, LLC
H04L63/1483G06F16/955G06N20/00H04L63/1416H04L63/1433H04L63/166
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,413,621
App. No.
18/649,734
Granted
Sep 9, 2025
Kind
B2
Abstract

There is disclosed a computer-implemented system and method for protecting a user from phishing attacks, including detecting that the user has opened a website associated with a uniform resource locator (URL), and determining that the URL does not have a known good reputation; rendering a test version of the website in a headless web browser, including abstracting the website into at least one visual element of the test version; visually inspecting the test version of the website with a digital eye, and determining that the test version of the web looks like a known legitimate website not associated with the URL; and based on the visual inspection, warning the user that the website is or may be a phishing website.

Claims (34)

1. A computer-implemented method of protecting a user from phishing attacks, comprising:

detecting that the user has opened a website associated with a uniform resource locator (URL), and determining that the URL does not have a known good reputation, comprising querying a cloud-based reputation store for the URL;

in response to the determining, rendering a test version of the website in a headless web browser, including abstracting the website into at least one visual element of the test version;

visually inspecting the test version of the website with a digital eye, the digital eye comprising a machine learning model visually trained on known legitimate websites, and determining that the test version of the web looks like a known legitimate website not associated with the URL; and

based on the visual inspection, warning the user that the website is or may be a phishing website.

2. The method of claim 1 , further comprising querying a cloud reputation service to determine that the URL does not have a known good reputation.

3. The method of claim 1 , further comprising querying a local reputation cache to determine that the URL does not have a known good reputation.

4. The method of claim 1 , further comprising determining that the user has not previously visited the URL to determine that the URL does not have a known good reputation.

5. The method of claim 1 , wherein abstracting the at least one visual element includes a corporate logo.

6. The method of claim 1 , wherein abstracting the at least one visual element includes a font.

7. The method of claim 1 , wherein abstracting the at least one visual element includes a background color.

8. The method of claim 1 , wherein abstracting the at least one visual element includes a background pattern.

9. The method of claim 1 , wherein abstracting the at least one visual element includes a color scheme.

10. The method of claim 1 , wherein determining that the test version of the website looks like the known legitimate website not associated with the URL comprises determining that the URL is a non-secure hypertext transport protocol (HTTP) URL.

11. The method of claim 1 , wherein determining that the test version of the website looks like the known legitimate website not associated with the URL comprises determining that the URL uses transport layer security (TLS), but that a certificate of the URL is not associated with the known legitimate website.

12. The method of claim 1 , wherein determining that the test version of the website looks like the known legitimate website not associated with the URL comprises determining that the URL belongs to a blogs or personal webpages subdomain of a known third-party service not associated with the known legitimate website.

13. One or more tangible, nontransitory computer-readable storage media having stored thereon executable instructions to:

detect that a user has opened a website associated with a uniform resource locator (URL), and determine that the URL does not have a known good reputation, comprising querying a cloud-based reputation store for the URL;

in response to the determining, render a test version of the website in a headless web browser, including abstracting the website into at least one visual element of the test version;

visually inspect the test version of the website with a digital eye, the digital eye comprising a machine learning model visually trained on known legitimate websites, and determine that the test version of the web looks like a known legitimate website not associated with the URL; and

based on the visual inspection, warn the user that the website is or may be a phishing website.

14. The one or more tangible, nontransitory computer-readable storage media of claim 13 , wherein the instructions are further to query a cloud reputation service to determine that the URL does not have a known good reputation.

15. The one or more tangible, nontransitory computer-readable storage media of claim 13 , wherein the instructions are further to query a local reputation cache to determine that the URL does not have a known good reputation.

16. The one or more tangible, nontransitory computer-readable storage media of claim 13 , wherein the instructions are further to determine that the user has not previously visited the URL to determine that the URL does not have a known good reputation.

17. A computing apparatus, comprising:

a hardware platform comprising a processor circuit and a memory; and

instructions encoded within the memory to instruct the processor circuit to:

detect that a user has opened a website associated with a uniform resource locator (URL), and determine that the URL does not have a known good reputation, comprising querying a cloud-based reputation store for the URL;

in response to the determining, render a test version of the website in a headless web browser, including abstracting the website into at least one visual element of the test version;

visually inspect the test version of the website with a digital eye, the digital eye comprising a machine learning model visually trained on known legitimate websites, and determine that the test version of the web looks like a known legitimate website not associated with the URL; and

based on the visual inspection, warn the user that the website is or may be a phishing website.

18. The computing apparatus of claim 17 , wherein the instructions are further to query a cloud reputation service to determine that the URL does not have a known good reputation.

19. The computing apparatus of claim 17 , wherein the instructions are further to query a local reputation cache to determine that the URL does not have a known good reputation.

20. The computing apparatus of claim 17 , wherein the computing apparatus is a gateway.

Continuity (3)
Continuation 17882460 · Aug 5, 2022
Continuation 16676939 · Nov 7, 2019
Related Publication 20240283821A1 · Aug 22, 2024
References Cited (48)
US 7890612B2 · Todd et al. · 2011 [cited by applicant]
US 8332947B1 · Bregman · 2012 [cited by examiner]
US 8806622B2 · Waterson et al. · 2014 [cited by applicant]
US 8819826B2 · Sallam · 2014 [cited by applicant]
US 9009820B1 · McDougal et al. · 2015 [cited by applicant]
US 9516055B1 · Liu · 2016 [cited by applicant]
US 9516058B2 · Antonakakis et al. · 2016 [cited by applicant]
US 9621566B2 · Gupta et al. · 2017 [cited by applicant]
US 10044739B2 · Muttik · 2018 [cited by applicant]
US 10574696B2 · Celik · 2020 [cited by applicant]
US 10581883B1 · Syme et al. · 2020 [cited by applicant]
US 10834128B1 · Rajagopalan · 2020 [cited by examiner]
US 10999322B1 · Yuan · 2021 [cited by examiner]
US 11003775B2 · Kraemer et al. · 2021 [cited by applicant]
US 11146576B1 · Mushtaq · 2021 [cited by examiner]
US 11381597B2 · Lancioni et al. · 2022 [cited by applicant]
US 20060253578A1 · Dixon · 2006 [cited by examiner]
US 20060253580A1 · Dixon · 2006 [cited by examiner]
US 20070118528A1 · Choi et al. · 2007 [cited by applicant]
US 20070245422A1 · Hwang et al. · 2007 [cited by applicant]
US 20070283000A1 · Proux · 2007 [cited by examiner]
US 20070294352A1 · Shraim et al. · 2007 [cited by applicant]
US 20080133540A1 · Hubbard et al. · 2008 [cited by applicant]
US 20100100958A1 · Jeremiah · 2010 [cited by applicant]
US 20100332593A1 · Barash et al. · 2010 [cited by applicant]
US 20120158626A1 · Zhu et al. · 2012 [cited by applicant]
US 20130074185A1 · McDougal et al. · 2013 [cited by applicant]
US 20130227636A1 · Bettini et al. · 2013 [cited by applicant]
US 20140359760A1 · Gupta et al. · 2014 [cited by applicant]
US 20170155665A1 · Dufour · 2017 [cited by examiner]
US 20170195363A1 · Dahan et al. · 2017 [cited by applicant]
US 20180027013A1 · Wright et al. · 2018 [cited by applicant]
US 20180054737A1 · Guo et al. · 2018 [cited by applicant]
US 20180191778A1 · Volkov · 2018 [cited by applicant]
US 20190014149A1 · Cleveland et al. · 2019 [cited by applicant]
US 20190068638A1 · Bartik et al. · 2019 [cited by applicant]
US 20190327267A1 · Onut · 2019 [cited by examiner]
US 20200036751A1 · Kohavi · 2020 [cited by applicant]
US 20200252428A1 · Gardezi et al. · 2020 [cited by applicant]
US 20210014269A1 · Devane · 2021 [cited by examiner]
US 20210021638A1 · Lancioni et al. · 2021 [cited by applicant]
US 20210037006A1 · Belenko · 2021 [cited by examiner]
US 20210075826A1 · Johnson · 2021 [cited by examiner]
EP 3599753A1 · 2020 [cited by applicant]
KR 1020080027035A · 2008 [cited by applicant]
WO 2016034935A1 · 2016 [cited by applicant]
WO 2021016142 · 2021 [cited by applicant]
Cordero, et al., “Catching Phish: Detecting Phishing Attacks from Rendered Website Images,” Dec. 2006. [cited by applicant]