首页> 外国专利> Prevention of credential phishing based upon login behavior analysis

Prevention of credential phishing based upon login behavior analysis

机译:基于登录行为分析的凭证钓鱼防范

摘要

A system is implemented in browser plug-in software or in endpoint agent software on a user computer. The user accesses a Web site and fills in a login request form and submits it to the Web site. The system triggers a “forgot password” feature and detects a phishing Web site by determining that it does not send a reset link to a valid user e-mail address, or, the system detects a phishing Web site by determining that it does send a reset link to an invalid e-mail address. Or, the system detects a phishing Web site by determining that it sends a reset link to a user e-mail address from a domain different from the domain of a login request form. Or, the system fills in an incorrect account name or password in a login request form and detects a phishing Web site by determining that the Web site does not indicate that the incorrect user name or incorrect password are incorrect. Or, the system submits incorrect credentials and detects a phishing Web site by determining that the Web site does not implement any way to reset the account name or password.
机译:系统在浏览器插件软件或用户计算机上的端点代理软件中实现。用户访问网站并填写登录请求表,然后将其提交到网站。系统触发“忘记密码”功能,并通过确定未向有效用户电子邮件地址发送重置链接来检测钓鱼网站,或通过确定向无效电子邮件地址发送重置链接来检测钓鱼网站。或者,系统通过确定从不同于登录请求表单域的域向用户电子邮件地址发送重置链接来检测仿冒网站。或者,系统在登录请求表单中填写错误的帐户名或密码,并通过确定网站未指示错误的用户名或密码不正确来检测钓鱼网站。或者,系统提交不正确的凭据,并通过确定网站未实现任何重置帐户名或密码的方法来检测钓鱼网站。

著录项

  • 公开/公告号US11323476B1

    专利类型

  • 公开/公告日2022-05-03

    原文格式PDF

  • 申请/专利权人 TREND MICRO INC.;

    申请/专利号US201916692680

  • 发明设计人 JING CAO;QUAN YUAN;BO LIU;

    申请日2019-11-22

  • 分类号G06F15/16;H04L29/06;G06F16/954;G06F11/32;

  • 国家 US

  • 入库时间 2022-08-25 00:48:07

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号