IP Library Granted Patent US 12,706,949
Granted Patent B2
US 12,706,949 · App. 17/675,955 · Granted Aug 11, 2026

Phishing website detection by checking form differences followed by false credentials submission

Inventor: Fatih Orhan (Cedar Grove, NJ)
H04L63/1483H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,706,949
App. No.
17/675,955
Filed
Feb 18, 2022
Granted
Aug 11, 2026
Kind
B2
Art Unit
2493
USPC
726/23
Abstract

There is provided a method to detect phishing websites so as to protect users from sending their sensitive information to criminal servers. When browsing a web site having an input form asking sensitive information, the input fields are recorded (i.e. username field and password field). Then false credentials are generated and submitted in background. The new control layer then checks the response page content whether it includes an input form and if there is an input, it checks whether the form has the same fields as the first form. If the responded page does not have a form, or it has a form but includes different fields than the initial page's form, then the original site is identified as phishing.

Claims (11)

1 . A method to detect a phishing website by introducing a control layer between a user and a website to be visited, where the control layer checks whether said website, requiring sensitive information, is a phishing website by comparing input forms after a false credential submission comprising:

browsing said website where said website has a first input form with username and password input fields asking sensitive information; said control layer is implemented as a web browser extension usable in real time while said user is browsing any website;

checking a whitelist and a blacklist of said control layer to determine if said browsed website is in said whitelist or in said blacklist or is unknown;

recording said input fields;

generating and submitting false credentials for said input fields in background;

enabling a user enabled permissive functionality after said false credentials are sent to said website by warning said user about phishing content detection and allowing said user to continue using said website or stop interaction with said website by having “Allow this website” button after the false credentials have been submitted once;

checking by said control layer content of a response page whether said content of said response page includes said first input form of said website; said response page having a second input form;

checking by said control layer whether said second input form of said response page has the same input fields as the first input form of said website, if said first input form of said website is included;

identifying said website as a phishing site, if said response page does not have said first input form of said website, or if said response page has said first input form of said website with different fields than the first input form of the website; and

identifying said website as a phishing site and blocking if said response page has no input form.

2 . The method according to claim 1 to detect phishing website by introducing a control layer between a user and a website to be visited, where said control layer triggers interaction with said website and analyzes its behavior before actual interaction with said user.

Continuity (3)
Continuation 16544865 · Aug 19, 2019
Provisional Application 62721520 · Aug 22, 2018
Related Publication 20220247782A1 · Aug 4, 2022
References Cited (56)
US 7634810B2 · Goodman et al. · 2009 [cited by applicant]
US 7854001B1 · Chen et al. · 2010 [cited by applicant]
US 7925883B2 · Florencio et al. · 2011 [cited by applicant]
US 8220047B1 · Soghoian · 2012 [cited by examiner]
US 8566938B1 · Prakash et al. · 2013 [cited by applicant]
US 9027126B2 · Larkins · 2015 [cited by applicant]
US 9230105B1 · Satish · 2016 [cited by examiner]
US 9578048B1 · Hunt · 2017 [cited by examiner]
US 9843602B2 · Tsao et al. · 2017 [cited by applicant]
US 10652277B1 · Venkatesan · 2020 [cited by examiner]
US 20060080735A1 · Brinson et al. · 2006 [cited by applicant]
US 20070250920A1 · Lindsay · 2007 [cited by examiner]
US 20080046738A1 · Galloway · 2008 [cited by examiner]
US 20080092242A1 · Rowley · 2008 [cited by examiner]
US 20090006861A1 · Bemmel · 2009 [cited by examiner]
US 20090228780A1 · McGeehan · 2009 [cited by examiner]
US 20100175136A1 · Frumer et al. · 2010 [cited by applicant]
US 20110126289A1 · Yue et al. · 2011 [cited by applicant]
US 20130333038A1 · Chien · 2013 [cited by examiner]
US 20140359760A1 · Gupta · 2014 [cited by examiner]
US 20150058986A1 · Zhao · 2015 [cited by examiner]
US 20150074390A1 · Stoback · 2015 [cited by examiner]
US 20170099319A1 · Hunt et al. · 2017 [cited by applicant]
US 20170244755A1 · Tsao · 2017 [cited by examiner]
US 20180007066A1 · Goutal · 2018 [cited by applicant]
US 20180077199A1 · Tsao · 2018 [cited by examiner]
US 20190068638A1 · Bartik · 2019 [cited by examiner]
US 20200204587A1 · Hunt · 2020 [cited by examiner]
US 20210160280A1 · Yadav · 2021 [cited by examiner]
US 20210314353A1 · Melson · 2021 [cited by examiner]
CN 102724186A · 2012 [cited by examiner]
CN 102932348A · 2013 [cited by examiner]
KR 20080111310A · 2008 [cited by examiner]
WO WO2015000422A1 · 2015 [cited by examiner]
Ndibwile et al., “UnPhishMe: Phishing Attack Detection by Deceptive Login Simulation through an Android Mobile App,” 2017 12th Asia Joint Conference on Information Security (AsiaJCIS), 2017, pp. 38-47, doi: 10.1109/Asia… [cited by examiner]
Faris et al., “Phishing Web Page Detection Methods: URL and HTML Features Detection,” 2020 IEEE International Conference on Internet of Things and Intelligence System (IoTaIS), BALI, Indonesia, 2021, pp. 167-171, doi: 1… [cited by examiner]
Ndibwile et al., “UnPhishMe: Phishing Attack Detection by Deceptive Login Simulation through an Android Mobile App,” 2017 12th Asia Joint Conference on Information Security (AsiaJCIS), Seoul, Korea (South), 2017, pp. 38… [cited by examiner]
Barraclough et al., “Online phishing detection toolbar for transactions,” 2015 Science and Information Conference (SAI), London, UK, 2015, pp. 1321-1328, doi: 10.1109/SAI.2015.7237314. (Year: 2015). [cited by examiner]
Armano et al., “Real-Time Client-Side Phishing Prevention Add-On,” 2016 IEEE 36th International Conference on Distributed Computing Systems (ICDCS), Nara, Japan, 2016, pp. 777-778, doi: 10.1109/ICDCS.2016.44. (Year: 201… [cited by examiner]
Ahmed et al., “Real time detection of phishing websites,” 2016 IEEE 7th Annual Information Technology, Electronics and Mobile Communication Conference (IEMCON), Vancouver, BC, Canada, 2016, pp. 1-6, doi: 10.1109/IEMCON.… [cited by examiner]
Adil et al., “Preventive Techniques of Phishing Attacks in Networks,” 2020 3rd International Conference on Advancements in Computational Sciences (ICACS), Lahore, Pakistan, 2020, pp. 1-8, doi: 10.1109/ICACS47775.2020.90… [cited by examiner]
Shahriar et al., “Information Source-Based Classification of Automatic Phishing Website Detectors,” 2011 IEEE/IPSJ International Symposium on Applications and the Internet, Munich, Germany, 2011, pp. 190-195, doi: 10.11… [cited by examiner]
Yue et al., “Anti-Phishing in Offense and Defense,” 2008 Annual Computer Security Applications Conference (ACSAC), Anaheim, CA, USA, 2008, pp. 345-354, doi: 10.1109/ACSAC.2008.32. (Year: 2008). [cited by examiner]
Shahriar et al., “PhishTester: Automatic Testing of Phishing Attacks,” 2010 Fourth International Conference on Secure Software Integration and Reliability Improvement, Singapore, 2010, pp. 198-207, doi: 10.1109/SSIRI.20… [cited by examiner]
Churi et al., “A secured methodology for anti-phishing,” 2017 International Conference on Innovations in Information, Embedded and Communication Systems (ICIIECS), Coimbatore, India, 2017, pp. 1-4, doi: 10.1109/ICIIECS.… [cited by examiner]
Kalangi et al., “Phishing Attack Detection using Collaborative Learning Approach at Dynamic Cloud Platform,” 2023 Global Conference on Information Technologies and Communications (GCITC), Bangalore, India, 2023, pp. 1-6… [cited by examiner]
K. Kumar and K. Alekhya, “Detecting Phishing Websites Using Fuzzy Logic,” International Journal of Advanced Research in Computer Engineering & Technology (IJARCET), vol. 5, Issue 10, Oct. 2016. [cited by applicant]
M. Aburrous, et al., “Intelligent Detection System for E-Banking Phishing Websites Using Fuzzy Data Mining,” Expert Systems With Applications 37, pp. 7913-7921, 2010. [cited by applicant]
L. Wenyin, et al., “Phishing Web Page Detection,” Document Analysis and Recognition, 2005. [cited by applicant]
S. Afroz and R. Greenstadt, “Phizhzoo: An Automated Web Phishing Detection Approach Based on Profiling and Fuzzy Matching,” Drexel University, Tech. Rep., Mar. 2009. [cited by applicant]
S. Abu-Nimeh, et al., “A Comparison of Machine Learning Techniques for Phishing Detection,” Proceedings of the Anti-Phishing Working Groups 2nd Annual eCrime Researches Summit, pp. 60-69, Oct. 2007. [cited by applicant]
A. Jain and V. Richariya, “Implementing a Web Browser With Phishing Detection Techniques,” World of Computer Science and Information Technology Journal (WCSIT), vol. 1, No. 7, 289-291, 2011. [cited by applicant]
A. Bergholz, et al., Improved Phishing Detection Using Model-Based Features. In CEAS, 2008. [cited by applicant]
G. Ehringer and P. A. Barrachlough, “Intelligent Security for Phishing Online Using Adaptive Neuro Fuzzy Systems,” (IJACSA), International Journal of Advanced Computer Science and Applications, vol. 8, No. 6, 2017. [cited by applicant]
Gajek S., Sadeghi AR. (2008) A Forensic Framework for Tracing Phishers. In: Fischer-Hubner S., Duquenoy P., Zuccato A., Martucci L. (eds.) The Future of Identity in the Information Society. Privacy and Identity 2007. IF… [cited by applicant]
H. Shahriar and M. Zulkernine, “PhishTester: Automatic Testing of Phishing Attacks,” 2010 Fourth International Conference on Secure Software Integration and Reliability Improvement, 2010, pp. 198-207, doi:10.1109/SSIRI.… [cited by applicant]