US2010042687A1PendingUtilityA1
System and method for combating phishing
Est. expiryAug 12, 2028(~2 yrs left)· nominal 20-yr term from priority
Inventors:Tak Yin Wang
H04L 63/1441G06F 21/51
47
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
In one embodiment, the present invention relates to a method and system for combating phishing. A computer receives an email comprising a sender email address and a link. The computer determines a sender domain name from the sender email address and ascertains a Uniform Resource Locator (URL) corresponding to the link. The computer then determines a link domain name from the URL. The computer then determines whether the sender domain name is different than the link domain name, so as to classify the URL as a potential phishing URL.
Claims
exact text as granted — not AI-modified1 . A method comprising:
receiving an email comprising a sender email address and a link; determining, using a computer, a sender domain name from the sender email address; ascertaining, using the computer, a Uniform Resource Locator (URL) corresponding to the link; determining, using the computer, a link domain name from the URL; and determining, using the computer, whether the sender domain name is different than the link domain name, so as to classify the URL as a potential phishing URL.
2 . The method of claim 1 , wherein the determining whether the sender domain name is different than the link domain name further comprises determining that the sender domain name is found in a stored list of domain names.
3 . The method of claim 2 , further comprising determining that the link domain name matches the sender domain name and is found in the stored list of domain names.
4 . The method of claim 1 , wherein the email further comprises a recipient email address.
5 . The method of claim 4 , wherein the determining whether the sender domain name is different than the link domain name further comprises:
determining that the sender domain name is not found in a stored list of domain names; determining that the sender email address is not found in an address book associated with the recipient email address; and determining that the link domain name does not match the sender domain name and is not found in the stored list of domain names.
6 . The method of claim 4 , further comprising transmitting the email to the recipient email address.
7 . The method of claim 1 , further comprising storing a sender login page associated with the sender domain name.
8 . The method of claim 7 , further comprising identifying differences between the sender login page and a link login page associated with the link domain name.
9 . The method of claim 6 , further comprising indicating to a computer displaying the email that the link in the email has a potential phishing URL.
10 . The method of claim 9 , further comprising transmitting a confirmation web page to the computer when a user associated with the recipient email address clicks on the link in the email.
11 . A computer readable medium storing computer program instructions capable of being executed by a computer processor, the computer program instructions defining the steps of:
receiving an email comprising a sender email address and a link; determining, using a computer, a sender domain name from the sender email address; ascertaining, using the computer, a Uniform Resource Locator (URL) corresponding to the link; determining, using the computer, a link domain name from the URL; and determining, using the computer, whether the sender domain name is different than the link domain name, so as to classify the URL as a potential phishing URL.
12 . The computer readable medium of claim 11 , wherein the computer program instructions defining the step of determining whether the sender domain name is different than the link domain name further comprises computer program instructions defining the step of determining that the sender domain name is found in a stored list of domain names.
13 . The computer readable medium of claim 12 , further comprising computer program instructions defining the step of determining that the link domain name matches the sender domain name and is found in the stored list of domain names.
14 . The computer readable medium of claim 11 , wherein the email further comprises a recipient email address.
15 . The computer readable medium of claim 14 , wherein the computer program instructions defining the step of determining whether the sender domain name is different than the link domain name further comprises computer program instructions defining the steps of:
determining that the sender domain name is not found in a stored list of domain names; determining that the sender email address is not found in an address book associated with the recipient email address; and determining that the link domain name does not match the sender domain name and is not found in the stored list of domain names.
16 . The computer readable medium of claim 14 , further comprising computer program instructions defining the step of transmitting the email to the recipient email address.
17 . The computer readable medium of claim 11 , further comprising computer program instructions defining the step of storing a sender login page associated with the sender domain name.
18 . The computer readable medium of claim 17 , further comprising computer program instructions defining the step of identifying differences between the sender login page and a link login page associated with the link domain name.
19 . The computer readable medium of claim 16 , further comprising computer program instructions defining the step of indicating to a computer displaying the email that the link in the email has a potential phishing URL.
20 . The computer readable medium of claim 19 , further comprising computer program instructions defining the step of transmitting a confirmation web page to the computer when a user associated with the recipient email address clicks on the link in the email.Join the waitlist — get patent alerts
Track US2010042687A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.