Prevention of man-in-the-middle phishing
Techniques for prevention of man-in-the-middle phishing are disclosed. In some embodiments, a system/process/computer program product for prevention of man-in-the-middle (MitM) phishing includes monitoring a session, wherein the session includes a request to access a website; evaluating a payload associated with the request to access the website using a MitM phishing profile to determine that the request to access the website matches at least in part the MitM phishing profile; and performing a remedial action in response to determining that the payload is associated with MitM phishing activity.
1 . A system, comprising:
a processor configured to:
monitor a session, wherein the session includes a request to access a website;
evaluate a payload associated with the request to access the website using a Man in the Middle (MitM) phishing profile to determine that the request to access the website matches at least in part the MitM phishing profile, wherein a MitM phishing Uniform Resource Locator (URL) is extracted from the payload that was determined to be associated with the MitM phishing activity based on the MitM phishing profile, wherein the MitM phishing URL is added to a URL block list, wherein a machine learning model is used to generate the MitM phishing profile, and wherein the machine learning model includes a large language model (LLM), wherein the MitM phishing profile is periodically updated using the LLM, and wherein the evaluating of the payload comprises to:
extract a header and a cookie from an HyperText Transfer Protocol (HTTP) response associated with the website to identify a target brand; and
after identifying the target brand, determine that the header and the cookie are associated with a MitM phishing page, comprising to:
verify that the cookie relates to a legitimate domain associated with the target brand;
determine that the header is properly set; and
in response to a determination that the cookie relates to the legitimate domain associated with the target brand and the header is properly set, determine that the payload associated with the request to access the website matches at least in part the MitM phishing profile; and
perform a remedial action in response to determining that the payload is associated with MitM phishing activity; and
a memory coupled to the processor and configured to provide the processor with instructions.
2 . The system of claim 1 , wherein the remedial action includes blocking the request.
3 . The system of claim 1 , wherein performing the remedial action includes adding a Uniform Resource Locator (URL) associated with a detected MitM phishing server to a block list.
4 . The system of claim 1 , wherein performing the remedial action includes providing a verdict of MitM phishing to a data appliance.
5 . A method, comprising:
monitoring a session, wherein the session includes a request to access a website;
evaluating a payload associated with the request to access the website using a Man in the Middle (MitM) phishing profile to determine that the request to access the website matches at least in part the MitM phishing profile, wherein a MitM phishing Uniform Resource Locator (URL) is extracted from the payload that was determined to be associated with the MitM phishing activity based on the MitM phishing profile, wherein the MitM phishing URL is added to a URL block list, wherein a machine learning model is used to generate the MitM phishing profile, and wherein the machine learning model includes a large language model (LLM), wherein the MitM phishing profile is periodically updated using the LLM, and wherein the evaluating of the payload comprises:
extracting a header and a cookie from an HyperText Transfer Protocol (HTTP) response associated with the website to identify a target brand; and
after identifying the target brand, determining that the header and the cookie are associated with a MitM phishing page, comprising:
verifying that the cookie relates to a legitimate domain associated with the target brand;
determining that the header is properly set; and
in response to a determination that the cookie relates to the legitimate domain associated with the target brand and the header is properly set, determining that the payload associated with the request to access the website matches at least in part the MitM phishing profile; and
performing a remedial action in response to determining that the payload is associated with MitM phishing activity.
6 . The method of claim 5 , wherein the remedial action includes blocking the request.
7 . A computer program product embodied in a non-transitory computer readable medium and comprising computer instructions for:
monitoring a session, wherein the session includes a request to access a website;
evaluating a payload associated with the request to access the website using a Man in the Middle (MitM) phishing profile to determine that the request to access the website matches at least in part the MitM phishing profile, wherein a MitM phishing Uniform Resource Locator (URL) is extracted from the payload that was determined to be associated with the MitM phishing activity based on the MitM phishing profile wherein the MitM phishing URL is added to a URL block list, wherein a machine learning model is used to generate the MitM phishing profile, and wherein the machine learning model includes a large language model (LLM), wherein the MitM phishing profile is periodically updated using the LLM, and wherein the evaluating of the payload comprises:
extracting a header and a cookie from an HyperText Transfer Protocol (HTTP) response associated with the website to identify a target brand; and
after identifying the target brand, determining that the header and the cookie are associated with a MitM phishing page, comprising:
verifying that the cookie relates to a legitimate domain associated with the target brand;
determining that the header is properly set; and
in response to a determination that the cookie relates to the legitimate domain associated with the target brand and the header is properly set, determining that the payload associated with the request to access the website matches at least in part the MitM phishing profile; and
performing a remedial action in response to determining that the payload is associated with MitM phishing activity.
8 . The computer program product of claim 7 , wherein the remedial action includes blocking the request.