IP Library › Granted Patent US 12,647,456
Granted Patent B2
US 12,647,456 · App. 18/640,737 · Granted Jun 2, 2026

Prevention of man-in-the-middle phishing

Inventors: Xunhua Tong (San Jose, CA); Suiqiang Deng (Fremont, CA); Oleksii Starov (Sunnyvale, CA); Lucas Hu (San Francisco, CA)
Assignee: Palo Alto Networks, Inc.
H04L63/1483H04L63/1466
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,647,456
App. No.
18/640,737
Granted
Jun 2, 2026
Kind
B2
Abstract

Techniques for prevention of man-in-the-middle phishing are disclosed. In some embodiments, a system/process/computer program product for prevention of man-in-the-middle (MitM) phishing includes monitoring a session, wherein the session includes a request to access a website; evaluating a payload associated with the request to access the website using a MitM phishing profile to determine that the request to access the website matches at least in part the MitM phishing profile; and performing a remedial action in response to determining that the payload is associated with MitM phishing activity.

Claims (34)

1 . A system, comprising:

a processor configured to:

monitor a session, wherein the session includes a request to access a website;

evaluate a payload associated with the request to access the website using a Man in the Middle (MitM) phishing profile to determine that the request to access the website matches at least in part the MitM phishing profile, wherein a MitM phishing Uniform Resource Locator (URL) is extracted from the payload that was determined to be associated with the MitM phishing activity based on the MitM phishing profile, wherein the MitM phishing URL is added to a URL block list, wherein a machine learning model is used to generate the MitM phishing profile, and wherein the machine learning model includes a large language model (LLM), wherein the MitM phishing profile is periodically updated using the LLM, and wherein the evaluating of the payload comprises to:

extract a header and a cookie from an HyperText Transfer Protocol (HTTP) response associated with the website to identify a target brand; and

after identifying the target brand, determine that the header and the cookie are associated with a MitM phishing page, comprising to:

verify that the cookie relates to a legitimate domain associated with the target brand;

determine that the header is properly set; and

in response to a determination that the cookie relates to the legitimate domain associated with the target brand and the header is properly set, determine that the payload associated with the request to access the website matches at least in part the MitM phishing profile; and

perform a remedial action in response to determining that the payload is associated with MitM phishing activity; and

a memory coupled to the processor and configured to provide the processor with instructions.

2 . The system of claim 1 , wherein the remedial action includes blocking the request.

3 . The system of claim 1 , wherein performing the remedial action includes adding a Uniform Resource Locator (URL) associated with a detected MitM phishing server to a block list.

4 . The system of claim 1 , wherein performing the remedial action includes providing a verdict of MitM phishing to a data appliance.

5 . A method, comprising:

monitoring a session, wherein the session includes a request to access a website;

evaluating a payload associated with the request to access the website using a Man in the Middle (MitM) phishing profile to determine that the request to access the website matches at least in part the MitM phishing profile, wherein a MitM phishing Uniform Resource Locator (URL) is extracted from the payload that was determined to be associated with the MitM phishing activity based on the MitM phishing profile, wherein the MitM phishing URL is added to a URL block list, wherein a machine learning model is used to generate the MitM phishing profile, and wherein the machine learning model includes a large language model (LLM), wherein the MitM phishing profile is periodically updated using the LLM, and wherein the evaluating of the payload comprises:

extracting a header and a cookie from an HyperText Transfer Protocol (HTTP) response associated with the website to identify a target brand; and

after identifying the target brand, determining that the header and the cookie are associated with a MitM phishing page, comprising:

verifying that the cookie relates to a legitimate domain associated with the target brand;

determining that the header is properly set; and

in response to a determination that the cookie relates to the legitimate domain associated with the target brand and the header is properly set, determining that the payload associated with the request to access the website matches at least in part the MitM phishing profile; and

performing a remedial action in response to determining that the payload is associated with MitM phishing activity.

6 . The method of claim 5 , wherein the remedial action includes blocking the request.

7 . A computer program product embodied in a non-transitory computer readable medium and comprising computer instructions for:

monitoring a session, wherein the session includes a request to access a website;

evaluating a payload associated with the request to access the website using a Man in the Middle (MitM) phishing profile to determine that the request to access the website matches at least in part the MitM phishing profile, wherein a MitM phishing Uniform Resource Locator (URL) is extracted from the payload that was determined to be associated with the MitM phishing activity based on the MitM phishing profile wherein the MitM phishing URL is added to a URL block list, wherein a machine learning model is used to generate the MitM phishing profile, and wherein the machine learning model includes a large language model (LLM), wherein the MitM phishing profile is periodically updated using the LLM, and wherein the evaluating of the payload comprises:

extracting a header and a cookie from an HyperText Transfer Protocol (HTTP) response associated with the website to identify a target brand; and

after identifying the target brand, determining that the header and the cookie are associated with a MitM phishing page, comprising:

verifying that the cookie relates to a legitimate domain associated with the target brand;

determining that the header is properly set; and

in response to a determination that the cookie relates to the legitimate domain associated with the target brand and the header is properly set, determining that the payload associated with the request to access the website matches at least in part the MitM phishing profile; and

performing a remedial action in response to determining that the payload is associated with MitM phishing activity.

8 . The computer program product of claim 7 , wherein the remedial action includes blocking the request.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 27, 2024
From: TONG, XUNHUA; DENG, SUIQIANG; STAROV, OLEKSII; HU, LUCAS
To: PALO ALTO NETWORKS, INC.
Reel/Frame 067859/0335 →
Continuity (1)
Related Publication 20250330491A1 · Oct 23, 2025
References Cited (16)
US 10999322B1 · Yuan · 2021 [cited by applicant]
US 12217480B1 · Karpman · 2025 [cited by applicant]
US 12413620B1 · Dambra · 2025 [cited by applicant]
US 20190014149A1 · Cleveland · 2019 [cited by applicant]
US 20200358819A1 · Bowditch · 2020 [cited by applicant]
US 20210344711A1 · Cleveland · 2021 [cited by applicant]
US 20220377110A1 · N · 2022 [cited by examiner]
US 20240265114A1 · Lambotte · 2024 [cited by examiner]
CN 114448664 · 2024 [cited by applicant]
CN 117935292 · 2024 [cited by applicant]
Github—lindsey98, PhishIntention: Phishing Detection Through Webpage Intention, 2022. [cited by applicant]
Github, OpenGVLab/Siamese-Image-Modeling: [CVPR 2023], Implementation of Siamese Image Modeling for Self-Supervised Vision Representation Learning, pp. 1-4. [cited by applicant]
Hu et al., Meddler-in-the-Middle Phishing Attacks Explained, Dec. 21, 2022, pp. 1-15. [cited by applicant]
Kondracki et al., Catching Transparent Phish: Analyzing and Detecting MITM Phishing Toolkits, CCS '21, Nov. 15-19, 2021, pp. 1-15. [cited by applicant]
Liu et al., Inferring Phishing Intention via Webpage Appearance and Dynamics: A Deep Vision Based Approach, Proceedings of the 31st USENIX Security Symposium, Aug. 10-12, 2022, pp. 1633-1650. [cited by applicant]
Walkowiak et al., Evaluation of Vector Embedding Models in Clustering of Text Documents, Proceedings of Recent Advances in Natural Language Processing, pp. 1304-1311. [cited by applicant]