Methods for preventing cyber intrusions and phishing activity
US-2018027013-A1 · Jan 25, 2018 · US
US11843633B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-11843633-B2 |
| Application number | US-201917261173-A |
| Country | US |
| Kind code | B2 |
| Filing date | Apr 26, 2019 |
| Priority date | Jul 25, 2018 |
| Publication date | Dec 12, 2023 |
| Grant date | Dec 12, 2023 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
An analysis device includes an input unit that receives input of communication destination information to be analyzed, a conversion unit that converts a partial character string included in the communication destination information into an image, a search unit that obtains a character string that is visually similar to an image converted by the conversion unit and searches for known communication destination information that is visually similar to the communication destination information based on the character string obtained, and an output unit that outputs a combination of the communication destination information and the known communication destination information that is visually similar to the communication destination information.
Opening claim text (preview).
The invention claimed is: 1. An analysis device comprising: a memory; and a processor coupled to the memory and programmed to execute a process comprising: receiving input of communication destination information to be analyzed; converting a partial character string included in the communication destination information into an image; obtaining a character string that is visually similar to an image converted by the converting and searching for known communication destination information that is visually similar to the communication destination information based on the character string obtained; and outputting a combination of the communication destination information and the known communication destination information that is visually similar to the communication destination information. 2. The analysis device according to claim 1 , wherein the converting specifies a region that can be registered or specified from the communication destination information, splits a partial character string in a specified region at an arbitrary delimiter or at every arbitrary number of characters, and converts each of split character strings into an image. 3. The analysis device according to claim 1 , wherein the searching applies optical character recognition to an image converted by the converting to obtain the character string that is visually similar to the image, extracts, as a conversion table, a combination of a partial character string included in the communication destination information to be analyzed and the character string that is visually similar to a converted image of the partial character string, refers to the conversion table and a list of known communication destination information, and searches for communication destination information that is visually similar to the communication destination information in the list of known communication destination information. 4. The analysis device according to claim 1 , further comprising acquiring setting information or registration information of known communication destination information that is visually similar to the communication destination information and identifying whether the known communication destination information that is visually similar to the communication destination information is managed by a same manager as a manager of the communication destination information or by a third party that is different from the manager of the communication destination information, wherein the outputting outputs a combination of the communication destination information and the known communication destination information visually similar to the communication destination information together with an identification result by the identifying. 5. An analysis method performed by an analysis device, the method comprising: a step of receiving input of communication destination information to be analyzed; a step of converting a partial character string included in the communication destination information into an image; a step of obtaining a character string that is visually similar to a converted image and searching for known communication destination information that is visually similar to the communication destination information based on the character string obtained; and a step of outputting a combination of the communication destination information and the known communication destination information that is visually similar to the communication destination information. 6. A non-transitory computer-readable recording medium having stored therein an analysis program for causing a computer to execute a process comprising: a step of receiving input of communication destination information to be analyzed; a step of converting a partial character string included in the communication destination information into an image; a step of obtaining a character string that is visually similar to a converted image and searching for known communication destination information that is visually similar to the communication destination information based on the character string obtained; and a step of outputting a combination of the communication destination information and the known communication destination information that is visually similar to the communication destination information.
service impersonation, e.g. phishing, pharming or web spoofing (detection of rogue wireless access points H04W12/12) · CPC title
Matching criteria, e.g. proximity measures · CPC title
involving long-term monitoring or reporting · CPC title
Authenticating web pages, e.g. with suspicious links · CPC title
Detecting local intrusion or implementing counter-measures · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.