IP Library Granted Patent US 12,592,964
Granted Patent B2
US 12,592,964 · App. 18/238,770 · Granted Mar 31, 2026

Systems and methods for efficiently processing communications for malicious hyperlinks

Inventor: Jochen Pretli (Waghaeusel, DE)
Assignee: Fortinet, Inc.
H04L63/1483H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,592,964
App. No.
18/238,770
Granted
Mar 31, 2026
Kind
B2
Abstract

Systems, devices, and methods are discussed for mitigating security threats due to web-domain characteristic changes.

Claims (59)

1 . A computer-implemented method, the method comprising:

identifying, by a processing resource, a set of hyperlinks in a received electronic message;

automatically determining, by the processing resource, that a first hyperlink in the set of hyperlinks comprises a non-focus hyperlink relative to the set of hyperlinks, by determining, at least in part, that the first hyperlink is not visually distinct from the received electronic message;

automatically determining, by the processing resource, that a second hyperlink in the set of hyperlinks comprises a focus hyperlink relative to the set of hyperlinks, by determining, at least in part, that the first hyperlink is visually distinct from the received electronic message; and

applying, by the processing resource, a security process concerning at least the first hyperlink or the second hyperlink.

2 . The method of claim 1 , the method further comprising:

forwarding, by the processing resource, the modified electronic message to a recipient based at least in part upon a determination that the second hyperlink is not associated with a malicious website.

3 . The method of claim 1 , wherein the electronic message is selected from a group consisting of: an email, and a text message.

4 . The method of claim 1 , wherein applying the security process to the second hyperlink includes performing a web filter process wherein a uniform record locator associated with the second hyperlink is compared with a plurality of known malicious websites.

5 . The method of claim 4 , wherein the web filter process indicates that the second hyperlink is safe, and wherein applying the security process to the second hyperlink further includes applying a sandbox process to the second hyperlink that accesses a website associated with the second hyperlink to determine a malicious status of the website.

6 . The method of claim 1 , wherein the determining that the first hyperlink in the set of hyperlinks is a non-focus hyperlink includes:

determining, by the processing resource, a size of the first hyperlink;

comparing, by the processing resource, the size of the first hyperlink with a defined size; and

identifying, by the processing resource, the first hyperlink as a non-focus hyperlink when the size of the first hyperlink is less than the defined size.

7 . The method of claim 6 , wherein the first hyperlink is represented as text, and wherein the size of the first hyperlink is a font size of one character of the first hyperlink.

8 . The method of claim 6 , wherein the first hyperlink is represented as an image, and wherein the size of the first hyperlink is a number of pixels squares of the image.

9 . The method of claim 1 , wherein the determining that the first hyperlink in the set of hyperlinks is a non-focus hyperlink includes:

determining, by the processing resource, a color of the first hyperlink;

comparing, by the processing resource, the color of the first hyperlink with a background color of the received electronic message; and

identifying, by the processing resource, the first hyperlink as a non-focus hyperlink when the color of the first hyperlink is less than twenty percent different that the background color of the received electronic message.

10 . The method of claim 1 , wherein the determining that the first hyperlink in the set of hyperlinks is a non-focus hyperlink includes:

determining, by the processing resource, a size of the first hyperlink and a maximum size of any hyperlink in the set of hyperlinks;

comparing, by the processing resource, the size of the first hyperlink with the maximum size of any hyperlink in the set of hyperlinks; and

identifying, by the processing resource, the first hyperlink as a non-focus hyperlink when the size of the first hyperlink is less than a defined ratio of the first hyperlink to the maximum size.

11 . The method of claim 10 , wherein the defined threshold is less than 0.4.

12 . The method of claim 1 , the method further comprising:

rejecting, by the processing resource, the modified electronic message based at least in part upon a determination that the second hyperlink is associated with a malicious website.

13 . The method of claim 1 , the method further comprising:

rejecting, by the processing resource, the received electronic message when a characteristic of the electronic message is determined, wherein the characteristic of the electronic message is selected from a group consisting of:

a total number of hyperlinks included in the set of hyperlinks exceeds a defined threshold; and

a ratio of a number of hyperlinks determined to be non-focus hyperlinks to the total number of hyperlinks included in the set of hyperlinks exceeds a defined ratio.

14 . A non-transitory computer-readable storage medium embodying a set of instructions, which when executed by a processing resource, causes the processing resource to:

identify a set of hyperlinks in a received electronic message;

automatically determine that a first hyperlink in the set of hyperlinks comprises a non-focus hyperlink relative to the set of hyperlinks, by determining, at least in part, that the first hyperlink is not visually distinct from the received electronic message;

automatically determine, by the processing resource, that a second hyperlink in the set of hyperlinks comprises a focus hyperlink relative to the set of hyperlinks, by determining, at least in part, that the first hyperlink is visually distinct from the received electronic message; and

apply a security process to concerning at least the first hyperlink or the second hyperlink.

15 . The non-transitory computer-readable storage medium of claim 14 , wherein the set of instructions, when executed by the processing resource, further causes the processing resource to:

forward the modified electronic message to a recipient based at least in part upon a determination that the second hyperlink is not associated with a malicious website.

16 . The non-transitory computer-readable storage medium of claim 14 , wherein applying the security process to the second hyperlink includes performing a web filter process wherein a uniform record locator associated with the second hyperlink is compared with a plurality of known malicious websites.

17 . The non-transitory computer-readable storage medium of claim 16 , wherein the web filter process indicates that the second hyperlink is safe, and wherein applying the security process to the second hyperlink further includes applying a sandbox process to the second hyperlink that accesses a website associated with the second hyperlink to determine a malicious status of the website.

18 . The non-transitory computer-readable storage medium of claim 14 , wherein determining that the first hyperlink in the set of hyperlinks is a non-focus hyperlink includes:

determining a size of the first hyperlink;

comparing the size of the first hyperlink with a defined size; and

identifying the first hyperlink as a non-focus hyperlink when the size of the first hyperlink is less than the defined size.

19 . The non-transitory computer-readable storage medium of claim 14 , wherein determining that the first hyperlink in the set of hyperlinks is a non-focus hyperlink includes:

determining a color of the first hyperlink;

comparing the color of the first hyperlink with a background color of the received electronic message; and

identifying the first hyperlink as a non-focus hyperlink when the color of the first hyperlink is less than twenty percent different that the background color of the received electronic message.

20 . The non-transitory computer-readable storage medium of claim 14 , wherein determining that the first hyperlink in the set of hyperlinks is a non-focus hyperlink includes:

determining a size of the first hyperlink and a maximum size of any hyperlink in the set of hyperlinks;

comparing the size of the first hyperlink with the maximum size of any hyperlink in the set of hyperlinks; and

identifying the first hyperlink as a non-focus hyperlink when the size of the first hyperlink is less than a defined ratio of the first hyperlink to the maximum size.

21 . A system for performing network security, the system comprising:

a processing resource;

a non-transitory computer-readable medium, coupled to the processing resource, having stored therein instructions that when executed by the processing resource cause the processing resource to:

identify a set of hyperlinks in a received electronic message;

automatically determine that a first hyperlink in the set of hyperlinks comprises a non-focus hyperlink relative to the set of hyperlinks, by determining, at least in part, that the first hyperlink is not visually distinct from the received electronic message;

automatically determine, by the processing resource, that a second hyperlink in the set of hyperlinks comprises a focus hyperlink relative to the set of hyperlinks, by determining, at least in part, that the first hyperlink is visually distinct from the received electronic message; and

apply a security process concerning at least the first hyperlink or the second hyperlink.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 28, 2023
From: PRETLI, JOCHEN
To: FORTINET, INC.
Reel/Frame 064723/0232 →
Continuity (1)
Related Publication 20250080576A1 · Mar 6, 2025
References Cited (10)
US 11595437B1 · Mushtaq · 2023 [cited by examiner]
US 11997115B1 · Higbee · 2024 [cited by examiner]
US 20130333028A1 · Hagar · 2013 [cited by examiner]
US 20180063168A1 · Sofka · 2018 [cited by examiner]
US 20230259625A1 · Gechman · 2023 [cited by examiner]
US 20230283634A1 · Kwatra · 2023 [cited by examiner]
CN 116400989A · 2023 [cited by examiner]
EP 3128449B1 · 2018 [cited by examiner]
EP 3716575A1 · 2020 [cited by examiner]
WO WO2023028596A1 · 2023 [cited by examiner]