DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Summary
This action is a responsive to the Applicant’s Argument filed on 4/28/2026.
Claims 22-24 are new.
Claims 1-24 are pending and have been examined.
Claims 1-24 are rejected.
Response to Arguments
Drawing Objections
Applicant’s Response:
FIGS. 1 and 8A-8C have been amended in a manner that is believed to overcome the claim objections. Accordingly, withdrawal of the objections is respectfully requested.
Examiner’s Response:
Applicant’s arguments, see remarks, filed 4/28/26, with respect to FIGS. 1 and 8A-8C have been fully considered and are persuasive. The objection of 1/28/26 has been withdrawn.
Claim Objections
Applicant’s Response:
Claims 1, 11, 12, 14, 16, 18, 20, and 21 have been objected to over informalities. Applicant respectfully traverses these objections.
Claim 1 has been amended in a manner that is believed to overcome the claim objections. Accordingly, withdrawal of the objections is respectfully requested.
Examiner’s Response:
Applicant’s arguments, see remarks, filed 4/28/26, with respect to Claims 1, 11, 12, 14, 16, 18, 20, and 21 have been fully considered and are persuasive. The objection of 1/28/26 has been withdrawn.
Rejection of Claims under 35 USC 112
Applicant’s Response:
Claims 1, 20, and 21 have been rejected under 35 U.S.C. § 112, second paragraph as allegedly being indefinite. Applicant respectfully traverses these rejections. Claims 1, 20, and 21 have been amended in a manner that is believed to overcome the rejection under 35 U.S.C. § 112. Accordingly, withdrawal of the rejections is respectfully requested.
Examiner’s Response:
Applicant’s arguments, see remarks, filed 4/28/26, with respect to Claims 1, 20, and 21 have been fully considered and are persuasive. The rejection of 1/28/26 has been withdrawn.
Rejection of Claims under 35 USC 103
Applicant’s Response:
Applicant submits that the cited references fail to teach the newly added limitations of:
determined based at least in part on performing perceptual image hashing to obtain a first grouping and obtaining a second grouping based at least in part on refining the first grouping by encoding the plurality of images using a predetermined deep learning model and merging groups based on a similarity among the encoded images being greater than a predefined similarity threshold
Examiner’s Response:
Applicant’s arguments with respect to claims 1, 20, 21 have been considered but are moot because the arguments are directed to amended subject matter properly addressed with the newly cited references of Li et al. (US 20230231879 A1) and ZVERKOV et al. (US 20220385694 A1) and AZARAFROOZ et al. (US 20230082481 A1).
The combination of Li et al. (US 20230231879 A1) and ZVERKOV et al. (US 20220385694 A1) and AZARAFROOZ et al. (US 20230082481 A1) teaches the language of the independent claims.
All remaining arguments are now moot in regards to the new rejection.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention.
Claims 1-23 are rejected under 35 U.S.C. 103 as being unpatentable over Li et al. (US 20230231879 A1) and further in view of ZVERKOV et al. (US 20220385694 A1) and AZARAFROOZ et al. (US 20230082481 A1).
As to claim 1, Li et al. teaches A system, comprising: one or more processors configured to: group a plurality of images associated with a plurality of samples to obtain a set of image groups, wherein the plurality of images are grouped based at least in part on visual similarities determined based at least in part on performing perceptual image hashing to obtain a first grouping (See ¶¶ [0030]-[033] Teaches that First, we convert webpage screenshot into a perceptual hashing value. A perceptual hash is a type of locality-sensitive hash, which is analogous if features of the multimedia are similar. Then, Hamming distance is employed to calculate similarity of the dHash of a webpage screenshot with that of phishing websites. The Bayes Classifier outputs probabilities to classify a webpage phishing or not. These probabilities also can be regarded as the similarities or dissimilarities that given web pages have with the phishing webpage.. In this case K=2, C0=Not Phishing, C1=Phishing; n=2, x1,=similarity_tag , x2,=similarity_ss. Our classifier can easily apply to cases with more features (n>2) . A list (similarity_tag, similarity_ss) is output from which the highest probability is chosen. If the probability p(Ck|X) exceeds a predefined threshold θT, the webpage is classified as phishing; otherwise, the web page is classified as normal.);
determine one or more patterns from uniform resource locators (URLs) for samples associated with images comprised in a particular image group of the second grouping (See ¶¶ [0025]-[0028], Teaches that First, a webpage can be represented using a set of strings by combining three consequent tags. As shown in FIG. 1 , tags <html> <head> <title> <meta> <meta> <meta> <meta> <body> <script> <div>are transformed to a set of strings by combining three consequent set tags [“html head title”,“head title meta”,“title meta meta”,“meta meta meta”,“meta meta body”,“meta body script”,“body script div”]. Then, a Jaccard similarity coefficient, in one embodiment, to calculate the similarity of a website with phishing websites. This value is 0 when the two sets are disjoint, 1 when they are equal, and strictly between 0 and 1 otherwise. Two sets are more similar (i.e., have relatively more members in common) when their Jaccard index is closer to 1. The set tags of a webpage can be used to match that of known phishing websites to get a small set of phishing websites which have closest Jaccard coefficient to it. Finally, this continuous variable is converted into a discrete one so that it can be used in our classier. By splitting up it into bins, e.g., (0-0.1)->0, (0.1,0.2)->1, . . . (0.9,1.0)->9, it will become a discrete value in {0,1, . . . 9}, denoted as the similarity_tag.);
generate a signature for each of the determined one or more patterns from the URLs (See ¶¶ [0025]-[0028], Teaches that First, a webpage can be represented using a set of strings by combining three consequent tags. As shown in FIG. 1 , tags <html> <head> <title> <meta> <meta> <meta> <meta> <body> <script> <div>are transformed to a set of strings by combining three consequent set tags [“html head title”,“head title meta”,“title meta meta”,“meta meta meta”,“meta meta body”,“meta body script”,“body script div”]. Then, a Jaccard similarity coefficient, in one embodiment, to calculate the similarity of a website with phishing websites. This value is 0 when the two sets are disjoint, 1 when they are equal, and strictly between 0 and 1 otherwise. Two sets are more similar (i.e., have relatively more members in common) when their Jaccard index is closer to 1. The set tags of a webpage can be used to match that of known phishing websites to get a small set of phishing websites which have closest Jaccard coefficient to it. Finally, this continuous variable is converted into a discrete one so that it can be used in our classier. By splitting up it into bins, e.g., (0-0.1)->0, (0.1,0.2)->1, . . . (0.9,1.0)->9, it will become a discrete value in {0,1, . . . 9}, denoted as the similarity_tag);
and a memory coupled to the one or more processors and configured to provide the one or more processors with instructions (See ¶ [0052], Teaches that The processor 620 can receive and execute instructions and data stored in the memory 610 or the hard drive 630.).
However, it does not expressly teach the details of obtaining a second grouping based at least in part on refining the first grouping by encoding the plurality of images using a predetermined deep learning model and merging groups based on a similarity among the encoded images being greater than a predefined similarity threshold; URLs.
ZVERKOV et al., from analogous art, teaches obtaining a second grouping based at least in part on refining the first grouping by encoding the plurality of images using a predetermined deep learning model and merging groups based on a similarity among the encoded images being greater than a predefined similarity threshold (See ¶¶ [0141], [0106], Teaches that in some non-limiting embodiments of the present technology, the processor 701 can be configured to combine clusters based on pairwise comparison between contours thereof, such as described above. Thus, if a given pair of clusters a number of similar contours exceeds a predetermined threshold, the processor 701 can be configured to combine the given pair of clusters in a single cluster. In other words, all the contours of a first cluster of the given pair of clusters are compared with all the contours of a second one, as described above. In some non-limiting embodiments of the present technology, the above criteria for deleting the contours could be predetermined by an expert or generated automatically based on statistic data about use of content elements in the plurality of web resources. For example, if a predetermined threshold value of the number of web resources associated with a given content element is exceeded, it could be considered as a standard content element. Threshold value can be set manually by an operator, or be selected using various automated algorithms, including machine learning ones.).
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of ZVERKOV et al. into Li et al. in order to improve accuracy of identifying phishing web resources (See ZVERKOV et al. See ¶ [0017]).
However, it does not expressly teach the details of URLs.
AZARAFROOZ et al., from analogous art, teaches URLs (See ¶ [0065], Teaches that phishing detection engine 202 utilizes feature hashing of content of webpages as well as security information present in the response headers, to complement the features available in both benign and phishing webpages. The content is expressed in JavaScript in one implementation. A different language, such as Python can be used in another embodiment. URL feature hasher 222 receives URL 214 and parses the URL into features and hashes the features to produce URL feature hash 242, resulting in dimensionality reduction of the URL n-gram.).
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of AZARAFROOZ et al. into the combination of Li et al. and ZVERKOV et al. in order to detecting phishing in real time via URL links and downloaded HTML, through machine learning and statistical analysis (See AZARAFROOZ et al. See ¶ [0020]).
As to claim 2, the combination of Li et al. and ZVERKOV et al. and AZARAFROOZ et al. teaches the system according to claim 1 above. Li et al. further teaches wherein each image in the plurality of images is an image of web site content (See ¶¶ [0030]-[0033] Teaches that First, we convert webpage screenshot into a perceptual hashing value. A perceptual hash is a type of locality-sensitive hash, which is analogous if features of the multimedia are similar. There are a variety of image perceptual hashing algorithms, such as Average Hashing (aHash), Median Hashing (mHash), Difference Hashing (dHash). We use dHash method for example, which can be done in flowing steps: (1) Convert the image to grayscale; (2) Downsize it to a 9×9 thumbnail; (3) Produce a 64-bit “row hash”: a 1 bit means the pixel intensity is increasing in the x direction, 0 means it's decreasing; (4) Do the same to produce a 64-bit “column hash” in the y direction; and (5) Combine the two values to produce the final 128-bit hash value.).
As to claim 3, the combination of Li et al. and ZVERKOV et al. and AZARAFROOZ et al. teaches the system according to claim 1 above. Li et al. further teaches wherein the plurality of images is grouped based at least in part on performing a hashing of each image (See ¶¶ [0030]-[0033] Teaches that First, we convert webpage screenshot into a perceptual hashing value. A perceptual hash is a type of locality-sensitive hash, which is analogous if features of the multimedia are similar. Then, Hamming distance is employed to calculate similarity of the dHash of a webpage screenshot with that of phishing websites. The Bayes Classifier outputs probabilities to classify a webpage phishing or not. These probabilities also can be regarded as the similarities or dissimilarities that given web pages have with the phishing webpage.. In this case K=2, C0=Not Phishing, C1=Phishing; n=2, x1,=similarity_tag , x2,=similarity_ss. Our classifier can easily apply to cases with more features (n>2) . A list (similarity_tag, similarity_ss) is output from which the highest probability is chosen. If the probability p(Ck|X) exceeds a predefined threshold θT, the webpage is classified as phishing; otherwise, the web page is classified as normal).
As to claim 4, the combination of Li et al. and ZVERKOV et al. and AZARAFROOZ et al. teaches the system according to claim 3 above. Li et al. further teaches wherein the performing the hashing of each image comprises: obtaining a plurality of hashes based on performing a perceptual image hashing with respect to each image (See ¶¶ [0030]-[0033] Teaches that First, we convert webpage screenshot into a perceptual hashing value. A perceptual hash is a type of locality-sensitive hash, which is analogous if features of the multimedia are similar. Then, Hamming distance is employed to calculate similarity of the dHash of a webpage screenshot with that of phishing websites. The Bayes Classifier outputs probabilities to classify a webpage phishing or not. These probabilities also can be regarded as the similarities or dissimilarities that given web pages have with the phishing webpage.. In this case K=2, C0=Not Phishing, C1=Phishing; n=2, x1,=similarity_tag , x2,=similarity_ss. Our classifier can easily apply to cases with more features (n>2) . A list (similarity_tag, similarity_ss) is output from which the highest probability is chosen. If the probability p(Ck|X) exceeds a predefined threshold θT, the webpage is classified as phishing; otherwise, the web page is classified as normal).
As to claim 5, the combination of Li et al. and ZVERKOV et al. and AZARAFROOZ et al. teaches the system according to claim 4 above. Li et al. further teaches wherein grouping the plurality of images comprises: determining a first grouping of the plurality of images based at least in part on the plurality of hashes (See ¶¶ [0030]-[0033] Teaches that First, we convert webpage screenshot into a perceptual hashing value. A perceptual hash is a type of locality-sensitive hash, which is analogous if features of the multimedia are similar. Then, Hamming distance is employed to calculate similarity of the dHash of a webpage screenshot with that of phishing websites. The Bayes Classifier outputs probabilities to classify a webpage phishing or not. These probabilities also can be regarded as the similarities or dissimilarities that given web pages have with the phishing webpage.. In this case K=2, C0=Not Phishing, C1=Phishing; n=2, x1,=similarity_tag , x2,=similarity_ss. Our classifier can easily apply to cases with more features (n>2) . A list (similarity_tag, similarity_ss) is output from which the highest probability is chosen. If the probability p(Ck|X) exceeds a predefined threshold θT, the webpage is classified as phishing; otherwise, the web page is classified as normal).
As to claim 6, the combination of Li et al. and ZVERKOV et al. and AZARAFROOZ et al. teaches the system according to claim 5 above. Li et al. further teaches wherein the grouping the plurality of images comprises: refining the first grouping of the plurality of images to obtain the set of image groups (See ¶¶ [0030]-[0033] Teaches that First, we convert webpage screenshot into a perceptual hashing value. A perceptual hash is a type of locality-sensitive hash, which is analogous if features of the multimedia are similar. Then, Hamming distance is employed to calculate similarity of the dHash of a webpage screenshot with that of phishing websites. The Bayes Classifier outputs probabilities to classify a webpage phishing or not. These probabilities also can be regarded as the similarities or dissimilarities that given web pages have with the phishing webpage.. In this case K=2, C0=Not Phishing, C1=Phishing; n=2, x1,=similarity_tag , x2,=similarity_ss. Our classifier can easily apply to cases with more features (n>2) . A list (similarity_tag, similarity_ss) is output from which the highest probability is chosen. If the probability p(Ck|X) exceeds a predefined threshold θT, the webpage is classified as phishing; otherwise, the web page is classified as normal).
As to claim 7, the combination of Li et al. and ZVERKOV et al. and AZARAFROOZ et al. teaches the system according to claim 6 above. However, it does not expressly teach the details of wherein the refining the first grouping of the plurality of image comprises: encoding the plurality of images based at least in part on a predetermined deep learning model.
AZARAFROOZ et al., from analogous art, teaches wherein the refining the first grouping of the plurality of image comprises: encoding the plurality of images based at least in part on a predetermined deep learning model (See ¶ [0067], Teaches that Headless browser 226 snapshots and provides captured image 248 to image embedder 256, which is pretrained on images, and produces an embedding of the image captured from the content page. Image embedding can increase efficiency and improve phishing detection for obfuscated cases. Embedder 256 encodes captured image 248 as image embedding 257. Embedder 256 utilizes a standard embedder, residual neural network (ResNet50), with pretrained classifier 258 for images, in one embodiment.).
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of AZARAFROOZ et al. into the combination of Li et al. and ZVERKOV et al. and AZARAFROOZ et al. in order to detecting phishing in real time via URL links and downloaded HTML, through machine learning and statistical analysis (See AZARAFROOZ et al. See ¶ [0020]).
As to claim 8, the combination of Li et al. and ZVERKOV et al. and AZARAFROOZ et al. teaches the system according to claim 7 above. However, it does not expressly teach the details of wherein the predetermined deep learning model is ResNet-50.
AZARAFROOZ et al., from analogous art, teaches wherein the predetermined deep learning model is ResNet-50 (See ¶ [0067], Teaches that Headless browser 226 snapshots and provides captured image 248 to image embedder 256, which is pretrained on images, and produces an embedding of the image captured from the content page. Image embedding can increase efficiency and improve phishing detection for obfuscated cases. Embedder 256 encodes captured image 248 as image embedding 257. Embedder 256 utilizes a standard embedder, residual neural network (ResNet50), with pretrained classifier 258 for images, in one embodiment.).
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of AZARAFROOZ et al. into the combination of Li et al. and ZVERKOV et al. and AZARAFROOZ et al. in order to detecting phishing in real time via URL links and downloaded HTML, through machine learning and statistical analysis (See AZARAFROOZ et al. See ¶ [0020]).
As to claim 9, the combination of Li et al. and ZVERKOV et al. and AZARAFROOZ et al. teaches the system according to claim 7 above. However, it does not expressly teach the details of wherein the refining the first grouping of the plurality of images further comprises: determining the set of image groups based at least in part on the encoding of the plurality of images by merging a plurality of groups from the first grouping based at least in part on a similarity among the plurality of groups.
ZVERKOV et al., from analogous art, teaches wherein the refining the first grouping of the plurality of images further comprises: determining the set of image groups based at least in part on the encoding of the plurality of images by merging a plurality of groups from the first grouping based at least in part on a similarity among the plurality of groups (See ¶¶ [0141], [0106], Teaches that in some non-limiting embodiments of the present technology, the processor 701 can be configured to combine clusters based on pairwise comparison between contours thereof, such as described above. Thus, if a given pair of clusters a number of similar contours exceeds a predetermined threshold, the processor 701 can be configured to combine the given pair of clusters in a single cluster. In other words, all the contours of a first cluster of the given pair of clusters are compared with all the contours of a second one, as described above. In some non-limiting embodiments of the present technology, the above criteria for deleting the contours could be predetermined by an expert or generated automatically based on statistic data about use of content elements in the plurality of web resources. For example, if a predetermined threshold value of the number of web resources associated with a given content element is exceeded, it could be considered as a standard content element. Threshold value can be set manually by an operator, or be selected using various automated algorithms, including machine learning ones.).
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of ZVERKOV et al. into the combination of Li et al. and ZVERKOV et al. and AZARAFROOZ et al. in order to improve accuracy of identifying phishing web resources (See ZVERKOV et al. See ¶ [0017]).
As to claim 10, the combination of Li et al. and ZVERKOV et al. and AZARAFROOZ et al. teaches the system according to claim 9 above. However, it does not expressly teach the details of wherein the determining the set of image groups based at least in part on the encoding of the plurality of images comprises: merging a plurality of groups from the first grouping based at least in part on a similarity among the plurality of groups.
ZVERKOV et al., from analogous art, teaches wherein the determining the set of image groups based at least in part on the encoding of the plurality of images comprises: merging a plurality of groups from the first grouping based at least in part on a similarity among the plurality of groups (See ¶¶ [0141], [0106], Teaches that in some non-limiting embodiments of the present technology, the processor 701 can be configured to combine clusters based on pairwise comparison between contours thereof, such as described above. Thus, if a given pair of clusters a number of similar contours exceeds a predetermined threshold, the processor 701 can be configured to combine the given pair of clusters in a single cluster. In other words, all the contours of a first cluster of the given pair of clusters are compared with all the contours of a second one, as described above. In some non-limiting embodiments of the present technology, the above criteria for deleting the contours could be predetermined by an expert or generated automatically based on statistic data about use of content elements in the plurality of web resources. For example, if a predetermined threshold value of the number of web resources associated with a given content element is exceeded, it could be considered as a standard content element. Threshold value can be set manually by an operator, or be selected using various automated algorithms, including machine learning ones.).
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of ZVERKOV et al. into the combination of Li et al. and ZVERKOV et al. and AZARAFROOZ et al. in order to improve accuracy of identifying phishing web resources (See ZVERKOV et al. See ¶ [0017]).
As to claim 11, the combination of Li et al. and ZVERKOV et al. and AZARAFROOZ et al. in teaches the system according to claim 1 above. However, it does not expressly teach the details of wherein the one or more patterns from the URLS for samples are determined based at least in part on one or more heuristics.
AZARAFROOZ et al., from analogous art, teaches wherein the one or more patterns from the URLS for samples are determined based at least in part on one or more heuristics (See ¶ [0082], Teaches that Phishing detection engine 602 uses URL link sequence extractor 622 that extracts characters in a predetermined character set from the URL 614 to produce a URL character sequence 642. One dimensional 1D convolutional neural network (Conv1D) URL embedder 652 produces a URL embedding 653. Prior to use for classifications, URL embedder 652 and URL classifier 654 are trained using example URLs accompanied by ground truth 632 that classifies the URL as phishing or as not phishing. The dashed block outline of trained URL classifier 654 distinguishes the training from later processing of active URLs. During training of URL embedder 652 the differences beyond the phishing classifier layers to embedding layers used to produce the URL embedding are back-propagated.).
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of AZARAFROOZ et al. into the combination of Li et al. and ZVERKOV et al. and AZARAFROOZ et al. in order to detecting phishing in real time via URL links and downloaded HTML, through machine learning and analysis (See AZARAFROOZ et al. See ¶ [0020]).
As to claim 12, the combination of Li et al. and ZVERKOV et al. and AZARAFROOZ et al. in teaches the system according to claim 1 above. However, it does not expressly teach the details of wherein the one or more patterns from the URLS for samples are determined based at least in part on performing a deep learning clustering.
AZARAFROOZ et al., from analogous art, teaches wherein the one or more patterns from the URLS for samples are determined based at least in part on performing a deep learning clustering (See ¶¶ [0082], [0048] Teaches that Phishing detection engine 602 uses URL link sequence extractor 622 that extracts characters in a predetermined character set from the URL 614 to produce a URL character sequence 642. One dimensional 1D convolutional neural network (Conv1D) URL embedder 652 produces a URL embedding 653. Prior to use for classifications, URL embedder 652 and URL classifier 654 are trained using example URLs accompanied by ground truth 632 that classifies the URL as phishing or as not phishing. The dashed block outline of trained URL classifier 654 distinguishes the training from later processing of active URLs. During training of URL embedder 652 the differences beyond the phishing classifier layers to embedding layers used to produce the URL embedding are back-propagated. The technology disclosed applies machine learning/deep learning (ML/DL) to phishing detection with a very low false positive rate and good recall. Three transfer learning techniques are presented, based on text/image analysis and based on HTML analysis.).
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of AZARAFROOZ et al. into the combination of Li et al. and ZVERKOV et al. and AZARAFROOZ et al. in order to detecting phishing in real time via URL links and downloaded HTML, through machine learning and statistical analysis (See AZARAFROOZ et al. See ¶ [0020]).
As to claim 13, the combination of Li et al. and ZVERKOV et al. and AZARAFROOZ et al. in teaches the system according to claim 1 above. Li et al. further teaches wherein the one or more processors are further configured to: determine one or more patterns from HTMLs for samples associated with the images comprised in a particular image group (See ¶¶ [0025]-[0028], Teaches that First, a webpage can be represented using a set of strings by combining three consequent tags. As shown in FIG. 1 , tags <html> <head> <title> <meta> <meta> <meta> <meta> <body> <script> <div>are transformed to a set of strings by combining three consequent set tags [“html head title”,“head title meta”,“title meta meta”,“meta meta meta”,“meta meta body”,“meta body script”,“body script div”]. Then, a Jaccard similarity coefficient, in one embodiment, to calculate the similarity of a website with phishing websites. This value is 0 when the two sets are disjoint, 1 when they are equal, and strictly between 0 and 1 otherwise. Two sets are more similar (i.e., have relatively more members in common) when their Jaccard index is closer to 1. The set tags of a webpage can be used to match that of known phishing websites to get a small set of phishing websites which have closest Jaccard coefficient to it. Finally, this continuous variable is converted into a discrete one so that it can be used in our classier. By splitting up it into bins, e.g., (0-0.1)->0, (0.1,0.2)->1, . . . (0.9,1.0)->9, it will become a discrete value in {0,1, . . . 9}, denoted as the similarity_tag.).
As to claim 14, the combination of Li et al. and ZVERKOV et al. and AZARAFROOZ et al. in teaches the system according to claim 1 above. However, it does not expressly teach the details of wherein the one or more processors are further configured to: obtain a new sample; determine a signature for the new sample; and classify the new sample based at least in part on the signature for the new sample and signatures for the one or more patterns from the URLs.
AZARAFROOZ et al., from analogous art, teaches wherein the one or more processors are further configured to: obtain a new sample; determine a signature for the new sample; and classify the new sample based at least in part on the signature for the new sample and signatures for the one or more patterns from the URLs (See ¶¶ [0063]-[0068], Teaches that FIG. 2 illustrates a high-level block diagram 200 of disclosed phishing detection engine 202 that utilizes ML/DL with a URL feature hash, encoding of natural language (NL) words and embedding of a captured website image for detecting phishing sites. Disclosed phishing classifier layers 275 generate likelihood score(s) 285 that signal how likely it is that a specific website is a phishing website. Phishing detection engine 202 utilizes a Multilingual Bidirectional Encoder Representations from Transformers (BERT) model which supports over 100+ languages as encoder 264, and utilizes a residual neural network (ResNet50), for images as embedder 256, in one embodiment. URL feature hash 242, word encoding 265 and image embedding 257 then are passed to neural network phishing classifier layers 275 for final training and inference, as described below. Phishing classifier layers 275, of disclosed phishing detection engine 202, are trained on the URL feature hashes, the encoding of the words extracted from the content page and the embedding of the image captures from the content page of example URLs, with each example URL accompanied by a ground truth classification as phishing or as not phishing. Phishing classifier layers 275 process the URL feature hash, word encoding and image embedding to produce at least one likelihood score that the URL and the content accessed via the URL represents a phishing risk.).
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of AZARAFROOZ et al. into the combination of Li et al. and ZVERKOV et al. and AZARAFROOZ et al. in order to detecting phishing in real time via URL links and downloaded HTML, through machine learning and statistical analysis (See AZARAFROOZ et al. See ¶ [0020]).
As to claim 15, the combination of Li et al. and ZVERKOV et al. and AZARAFROOZ et al. in teaches the system according to claim 1 above. However, it does not expressly teach the details of wherein the one or more patterns comprises one or more regexes.
AZARAFROOZ et al., from analogous art, teaches wherein the one or more patterns comprises one or more regexes (See ¶¶ [0063]-[0064], Teaches that FIG. 2 illustrates a high-level block diagram 200 of disclosed phishing detection engine 202 that utilizes ML/DL with a URL feature hash, encoding of natural language (NL) words and embedding of a captured website image for detecting phishing sites. Disclosed phishing classifier layers 275 generate likelihood score(s) 285 that signal how likely it is that a specific website is a phishing website. Phishing detection engine 202 utilizes a Multilingual Bidirectional Encoder Representations from Transformers (BERT) model which supports over 100+ languages as encoder 264, and utilizes a residual neural network (ResNet50), for images as embedder 256, in one embodiment. URL feature hash 242, word encoding 265 and image embedding 257 then are passed to neural network phishing classifier layers 275 for final training and inference, as described below. Encoders can be trained by pairing an encoder and a decoder. The encoder and decoder can be trained to squeeze the input into the embedding space, then reconstruct the input from the embedding. Once the encoder is trained, it can be repurposed, as described herein. Phishing classifier layers 275 utilize URL feature hash 242 of the URL n-gram, word encoding 265 of words extracted from the content page, and image embedding 257 of an image captured from content page 216 at URL 214 web address.).
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of AZARAFROOZ et al. into the combination of Li et al. and ZVERKOV et al. and AZARAFROOZ et al. in order to detecting phishing in real time via URL links and downloaded HTML, through machine learning and statistical analysis (See AZARAFROOZ et al. See ¶ [0020]).
As to claim 16, the combination of Li et al. and ZVERKOV et al. and AZARAFROOZ et al. in teaches the system according to claim 1 above. However, it does not expressly teach the details of wherein the one or more processors are further configured to: classify the signature for a particular pattern from the URLs as benign or malicious based at least in part on historical information.
AZARAFROOZ et al., from analogous art, teaches wherein the one or more processors are further configured to: classify the signature for a particular pattern from the URLs as benign or malicious based at least in part on historical information (See ¶¶ [0063]-[0068], [0057], Teaches that FIG. 2 illustrates a high-level block diagram 200 of disclosed phishing detection engine 202 that utilizes ML/DL with a URL feature hash, encoding of natural language (NL) words and embedding of a captured website image for detecting phishing sites. Disclosed phishing classifier layers 275 generate likelihood score(s) 285 that signal how likely it is that a specific website is a phishing website. Phishing detection engine 202 utilizes a Multilingual Bidirectional Encoder Representations from Transformers (BERT) model which supports over 100+ languages as encoder 264, and utilizes a residual neural network (ResNet50), for images as embedder 256, in one embodiment. URL feature hash 242, word encoding 265 and image embedding 257 then are passed to neural network phishing classifier layers 275 for final training and inference, as described below. Phishing classifier layers 275, of disclosed phishing detection engine 202, are trained on the URL feature hashes, the encoding of the words extracted from the content page and the embedding of the image captures from the content page of example URLs, with each example URL accompanied by a ground truth classification as phishing or as not phishing. Phishing classifier layers 275 process the URL feature hash, word encoding and image embedding to produce at least one likelihood score that the URL and the content accessed via the URL represents a phishing risk. The signatures are used to detect malicious links, typically by matching part or all of a URL or a compact hash thereof. data store 164 stores information from one or more tenants into tables of a common database image to form an on-demand database service (ODDS), which can be implemented in many ways, such as a multi-tenant database system (MTDS). A database image can include one or more database objects. In other implementations, the databases can be relational database management systems (RDBMSs), object-oriented database management systems (OODBMSs), distributed file systems (DFS), no-schema database, or any other data storing systems or computing devices.).
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of AZARAFROOZ et al. into the combination of Li et al. and ZVERKOV et al. and AZARAFROOZ et al. in order to detecting phishing in real time via URL links and downloaded HTML, through machine learning and statistical analysis (See AZARAFROOZ et al. See ¶ [0020]).
As to claim 17, the combination of Li et al. and ZVERKOV et al. and AZARAFROOZ et al. in teaches the system according to claim 1 above. However, it does not expressly teach the details of wherein classification of the signature for a particular pattern is used to train a machine learning model configured to detect malicious samples.
AZARAFROOZ et al., from analogous art, teaches wherein classification of the signature for a particular pattern is used to train a machine learning model configured to detect malicious samples (See ¶¶ [0064], [0057], Teaches that Encoders can be trained by pairing an encoder and a decoder. The encoder and decoder can be trained to squeeze the input into the embedding space, then reconstruct the input from the embedding. Once the encoder is trained, it can be repurposed, as described herein. Phishing classifier layers 275 utilize URL feature hash 242 of the URL n-gram, word encoding 265 of words extracted from the content page, and image embedding 257 of an image captured from content page 216 at URL 214 web address. Data store 164 stores lists of malicious links and signatures from malicious URLs. The signatures are used to detect malicious links, typically by matching part or all of a URL or a compact hash thereof.).
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of AZARAFROOZ et al. into the combination of Li et al. and ZVERKOV et al. and AZARAFROOZ et al. in order to detecting phishing in real time via URL links and downloaded HTML, through machine learning and statistical analysis (See AZARAFROOZ et al. See ¶ [0020]).
As to claim 18, the combination of Li et al. and ZVERKOV et al. and AZARAFROOZ et al. in teaches the system according to claim 1 above. However, it does not expressly teach the details of wherein the signature for a particular pattern is used to cover unclassified URLs to increase detection coverage or reduce false positive maliciousness classifications.
AZARAFROOZ et al., from analogous art, teaches wherein the signature for a particular pattern is used to cover unclassified URLs to increase detection coverage or reduce false positive maliciousness classifications (See ¶ [0089], Teaches that Phishing patterns evolve constantly, and it is often challenging for a detection method to achieve a high true positive rate (TPR) while maintaining a low false positive rate (FPR). A precision-recall curve shows the relationship between precision (=positive predictive value) and recall (=sensitivity) for the possible cut-offs.).
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of AZARAFROOZ et al. into the combination of Li et al. and ZVERKOV et al. and AZARAFROOZ et al. in order to detecting phishing in real time via URL links and downloaded HTML, through machine learning and statistical analysis (See AZARAFROOZ et al. See ¶ [0020]).
As to claim 19, the combination of Li et al. and ZVERKOV et al. and AZARAFROOZ et al. in teaches the system according to claim 1 above. However, it does not expressly teach the details of wherein the plurality of samples are obtained from a database of log data.
AZARAFROOZ et al., from analogous art, teaches wherein the plurality of samples are obtained from a database of log data (See ¶ [0057], Teaches that data store 164 stores information from one or more tenants into tables of a common database image to form an on-demand database service (ODDS), which can be implemented in many ways, such as a multi-tenant database system (MTDS). A database image can include one or more database objects. In other implementations, the databases can be relational database management systems (RDBMSs), object-oriented database management systems (OODBMSs), distributed file systems (DFS), no-schema database, or any other data storing systems or computing devices.).
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of AZARAFROOZ et al. into the combination of Li et al. and ZVERKOV et al. and AZARAFROOZ et al. in order to detecting phishing in real time via URL links and downloaded HTML, through machine learning and statistical analysis (See AZARAFROOZ et al. See ¶ [0020]).
As to claim 20, Li et al. teaches A method, comprising: grouping a plurality of images associated with a plurality of samples to obtain a set of image groups, wherein the plurality of images are grouped based at least in part on visual similarities determined based at least in part on performing perceptual image hashing to obtain a first grouping (See ¶¶ [0030]-[033] Teaches that First, we convert webpage screenshot into a perceptual hashing value. A perceptual hash is a type of locality-sensitive hash, which is analogous if features of the multimedia are similar. Then, Hamming distance is employed to calculate similarity of the dHash of a webpage screenshot with that of phishing websites. The Bayes Classifier outputs probabilities to classify a webpage phishing or not. These probabilities also can be regarded as the similarities or dissimilarities that given web pages have with the phishing webpage.. In this case K=2, C0=Not Phishing, C1=Phishing; n=2, x1,=similarity_tag , x2,=similarity_ss. Our classifier can easily apply to cases with more features (n>2) . A list (similarity_tag, similarity_ss) is output from which the highest probability is chosen. If the probability p(Ck|X) exceeds a predefined threshold θT, the webpage is classified as phishing; otherwise, the web page is classified as normal.);
determining one or more patterns from uniform resource locators (URLs) for samples associated with images comprised in a particular image group of the second grouping (See ¶¶ [0025]-[0028], Teaches that First, a webpage can be represented using a set of strings by combining three consequent tags. As shown in FIG. 1 , tags <html> <head> <title> <meta> <meta> <meta> <meta> <body> <script> <div>are transformed to a set of strings by combining three consequent set tags [“html head title”,“head title meta”,“title meta meta”,“meta meta meta”,“meta meta body”,“meta body script”,“body script div”]. Then, a Jaccard similarity coefficient, in one embodiment, to calculate the similarity of a website with phishing websites. This value is 0 when the two sets are disjoint, 1 when they are equal, and strictly between 0 and 1 otherwise. Two sets are more similar (i.e., have relatively more members in common) when their Jaccard index is closer to 1. The set tags of a webpage can be used to match that of known phishing websites to get a small set of phishing websites which have closest Jaccard coefficient to it. Finally, this continuous variable is converted into a discrete one so that it can be used in our classier. By splitting up it into bins, e.g., (0-0.1)->0, (0.1,0.2)->1, . . . (0.9,1.0)->9, it will become a discrete value in {0,1, . . . 9}, denoted as the similarity_tag.);
and generating a signature for each of the determined one or more patterns form the URLs (See ¶¶ [0025]-[0028], Teaches that First, a webpage can be represented using a set of strings by combining three consequent tags. As shown in FIG. 1 , tags <html> <head> <title> <meta> <meta> <meta> <meta> <body> <script> <div>are transformed to a set of strings by combining three consequent set tags [“html head title”,“head title meta”,“title meta meta”,“meta meta meta”,“meta meta body”,“meta body script”,“body script div”]. Then, a Jaccard similarity coefficient, in one embodiment, to calculate the similarity of a website with phishing websites. This value is 0 when the two sets are disjoint, 1 when they are equal, and strictly between 0 and 1 otherwise. Two sets are more similar (i.e., have relatively more members in common) when their Jaccard index is closer to 1. The set tags of a webpage can be used to match that of known phishing websites to get a small set of phishing websites which have closest Jaccard coefficient to it. Finally, this continuous variable is converted into a discrete one so that it can be used in our classier. By splitting up it into bins, e.g., (0-0.1)->0, (0.1,0.2)->1, . . . (0.9,1.0)->9, it will become a discrete value in {0,1, . . . 9}, denoted as the similarity_tag).
However, it does not expressly teach the details of obtaining a second grouping based at least in part on refining the first grouping by encoding the plurality of images using a predetermined deep learning model and merging groups based on a similarity among the encoded images being greater than a predefined similarity threshold; URLs.
ZVERKOV et al., from analogous art, teaches obtaining a second grouping based at least in part on refining the first grouping by encoding the plurality of images using a predetermined deep learning model and merging groups based on a similarity among the encoded images being greater than a predefined similarity threshold (See ¶¶ [0141], [0106], Teaches that in some non-limiting embodiments of the present technology, the processor 701 can be configured to combine clusters based on pairwise comparison between contours thereof, such as described above. Thus, if a given pair of clusters a number of similar contours exceeds a predetermined threshold, the processor 701 can be configured to combine the given pair of clusters in a single cluster. In other words, all the contours of a first cluster of the given pair of clusters are compared with all the contours of a second one, as described above. In some non-limiting embodiments of the present technology, the above criteria for deleting the contours could be predetermined by an expert or generated automatically based on statistic data about use of content elements in the plurality of web resources. For example, if a predetermined threshold value of the number of web resources associated with a given content element is exceeded, it could be considered as a standard content element. Threshold value can be set manually by an operator, or be selected using various automated algorithms, including machine learning ones.).
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of ZVERKOV et al. into Li et al. in order to improve accuracy of identifying phishing web resources (See ZVERKOV et al. See ¶ [0017]).
However, it does not expressly teach the details of URLs.
AZARAFROOZ et al., from analogous art, teaches URLs (See ¶ [0065], Teaches that phishing detection engine 202 utilizes feature hashing of content of webpages as well as security information present in the response headers, to complement the features available in both benign and phishing webpages. The content is expressed in JavaScript in one implementation. A different language, such as Python can be used in another embodiment. URL feature hasher 222 receives URL 214 and parses the URL into features and hashes the features to produce URL feature hash 242, resulting in dimensionality reduction of the URL n-gram.).
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of AZARAFROOZ et al. into the combination of Li et al. and ZVERKOV et al. in order to detecting phishing in real time via URL links and downloaded HTML, through machine learning and statistical analysis (See AZARAFROOZ et al. See ¶ [0020]).
As to claim 21, Li et al. teaches A computer program product embodied in a non-transitory computer readable medium and comprising computer instructions for: grouping a plurality of images associated with a plurality of samples to obtain a set of image groups, wherein the plurality of images are grouped based at least in part on visual similarities determined based at least in part on performing perceptual image hashing to obtain a first grouping (See ¶¶ [0030]-[033] Teaches that First, we convert webpage screenshot into a perceptual hashing value. A perceptual hash is a type of locality-sensitive hash, which is analogous if features of the multimedia are similar. Then, Hamming distance is employed to calculate similarity of the dHash of a webpage screenshot with that of phishing websites. The Bayes Classifier outputs probabilities to classify a webpage phishing or not. These probabilities also can be regarded as the similarities or dissimilarities that given web pages have with the phishing webpage.. In this case K=2, C0=Not Phishing, C1=Phishing; n=2, x1,=similarity_tag , x2,=similarity_ss. Our classifier can easily apply to cases with more features (n>2) . A list (similarity_tag, similarity_ss) is output from which the highest probability is chosen. If the probability p(Ck|X) exceeds a predefined threshold θT, the webpage is classified as phishing; otherwise, the web page is classified as normal.);
determining one or more patterns from uniform resource locators (URLs) for samples associated with images comprised in a particular image group of the second grouping (See ¶¶ [0025]-[0028], Teaches that First, a webpage can be represented using a set of strings by combining three consequent tags. As shown in FIG. 1 , tags <html> <head> <title> <meta> <meta> <meta> <meta> <body> <script> <div>are transformed to a set of strings by combining three consequent set tags [“html head title”,“head title meta”,“title meta meta”,“meta meta meta”,“meta meta body”,“meta body script”,“body script div”]. Then, a Jaccard similarity coefficient, in one embodiment, to calculate the similarity of a website with phishing websites. This value is 0 when the two sets are disjoint, 1 when they are equal, and strictly between 0 and 1 otherwise. Two sets are more similar (i.e., have relatively more members in common) when their Jaccard index is closer to 1. The set tags of a webpage can be used to match that of known phishing websites to get a small set of phishing websites which have closest Jaccard coefficient to it. Finally, this continuous variable is converted into a discrete one so that it can be used in our classier. By splitting up it into bins, e.g., (0-0.1)->0, (0.1,0.2)->1, . . . (0.9,1.0)->9, it will become a discrete value in {0,1, . . . 9}, denoted as the similarity_tag.);
and generating a signature for each of the determined one or more patterns form the URLs (See ¶¶ [0025]-[0028], Teaches that First, a webpage can be represented using a set of strings by combining three consequent tags. As shown in FIG. 1 , tags <html> <head> <title> <meta> <meta> <meta> <meta> <body> <script> <div>are transformed to a set of strings by combining three consequent set tags [“html head title”,“head title meta”,“title meta meta”,“meta meta meta”,“meta meta body”,“meta body script”,“body script div”]. Then, a Jaccard similarity coefficient, in one embodiment, to calculate the similarity of a website with phishing websites. This value is 0 when the two sets are disjoint, 1 when they are equal, and strictly between 0 and 1 otherwise. Two sets are more similar (i.e., have relatively more members in common) when their Jaccard index is closer to 1. The set tags of a webpage can be used to match that of known phishing websites to get a small set of phishing websites which have closest Jaccard coefficient to it. Finally, this continuous variable is converted into a discrete one so that it can be used in our classier. By splitting up it into bins, e.g., (0-0.1)->0, (0.1,0.2)->1, . . . (0.9,1.0)->9, it will become a discrete value in {0,1, . . . 9}, denoted as the similarity_tag).
However, it does not expressly teach the details of obtaining a second grouping based at least in part on refining the first grouping by encoding the plurality of images using a predetermined deep learning model and merging groups based on a similarity among the encoded images being greater than a predefined similarity threshold; URLs.
ZVERKOV et al., from analogous art, teaches obtaining a second grouping based at least in part on refining the first grouping by encoding the plurality of images using a predetermined deep learning model and merging groups based on a similarity among the encoded images being greater than a predefined similarity threshold (See ¶¶ [0141], [0106], Teaches that in some non-limiting embodiments of the present technology, the processor 701 can be configured to combine clusters based on pairwise comparison between contours thereof, such as described above. Thus, if a given pair of clusters a number of similar contours exceeds a predetermined threshold, the processor 701 can be configured to combine the given pair of clusters in a single cluster. In other words, all the contours of a first cluster of the given pair of clusters are compared with all the contours of a second one, as described above. In some non-limiting embodiments of the present technology, the above criteria for deleting the contours could be predetermined by an expert or generated automatically based on statistic data about use of content elements in the plurality of web resources. For example, if a predetermined threshold value of the number of web resources associated with a given content element is exceeded, it could be considered as a standard content element. Threshold value can be set manually by an operator, or be selected using various automated algorithms, including machine learning ones.).
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of ZVERKOV et al. into Li et al. in order to improve accuracy of identifying phishing web resources (See ZVERKOV et al. See ¶ [0017]).
However, it does not expressly teach the details of URLs.
AZARAFROOZ et al., from analogous art, teaches URLs (See ¶ [0065], Teaches that phishing detection engine 202 utilizes feature hashing of content of webpages as well as security information present in the response headers, to complement the features available in both benign and phishing webpages. The content is expressed in JavaScript in one implementation. A different language, such as Python can be used in another embodiment. URL feature hasher 222 receives URL 214 and parses the URL into features and hashes the features to produce URL feature hash 242, resulting in dimensionality reduction of the URL n-gram.).
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of AZARAFROOZ et al. into the combination of Li et al. and ZVERKOV et al. in order to detecting phishing in real time via URL links and downloaded HTML, through machine learning and statistical analysis (See AZARAFROOZ et al. See ¶ [0020]).
As to claim 22, the combination of Li et al. and ZVERKOV et al. and AZARAFROOZ et al. in teaches the system according to claim 1 above. However, it does not expressly teach the details of wherein the one or more processors are further configured to: collate the URLs associated with the images comprised in the particular image group; and determine the one or more patterns by performing at least one of heuristics-based clustering or deep-learning clustering on the collated URLs.
AZARAFROOZ et al., from analogous art, teaches wherein the one or more processors are further configured to: collate the URLs associated with the images comprised in the particular image group; and determine the one or more patterns by performing at least one of heuristics-based clustering or deep-learning clustering on the collated URLs (See ¶¶ [0085]-[0086], Teaches that phishing classifier layers 675 are trained on URL embedding and the HTML encoding of example URLs, each example URL accompanied by the ground truth classification as phishing or as not phishing 632. During training of URL embedder 652, the differences to encoding layers used to produce the URL embedding 653 are back-propagated beyond the phishing classifier layers. That is, once HTML encoder 664 is pre-trained, the URL embedding 653 network is trained alongside the rest of network (classifier layers 675 and fine-tuning step of the HTML encoder 654) with loss function and the help of URL examples with ground truth 632 for the input information. After training, phishing classifier layers 675 process a concatenated input of the URL embedding 653 and the HTML encoding 665 to produce at least one likelihood score that the URL and the content accessed via the URL presents a phishing risk. Phishing detection engine 602 applies phishing classifier layers 675 to a concatenated input of the URL embedding and the HTML encoding, to produce at least one likelihood score 685 that the URL and the content accessed via the URL presents a phishing risk.).
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of AZARAFROOZ et al. into the combination of Li et al. and ZVERKOV et al. and AZARAFROOZ et al. in order to detecting phishing in real time via URL links and downloaded HTML, through machine learning and statistical analysis (See AZARAFROOZ et al. See ¶ [0020]).
As to claim 23, the combination of Li et al. and ZVERKOV et al. and AZARAFROOZ et al. in teaches the system according to claim 1 above. However, it does not expressly teach the details of wherein the one or more processors are further configured to: use the generated signatures for the one or more patterns to automatically discover phishing campaigns from production network traffic; and train or update a machine learning model using the discovered phishing campaigns to detect emergent exploits.
AZARAFROOZ et al., from analogous art, teaches wherein the one or more processors are further configured to: use the generated signatures for the one or more patterns to automatically discover phishing campaigns from production network traffic (See ¶ [0068], Teaches that Phishing classifier layers 275, of disclosed phishing detection engine 202, are trained on the URL feature hashes, the encoding of the words extracted from the content page and the embedding of the image captures from the content page of example URLs, with each example URL accompanied by a ground truth classification as phishing or as not phishing. Phishing classifier layers 275 process the URL feature hash, word encoding and image embedding to produce at least one likelihood score that the URL and the content accessed via the URL represents a phishing risk. The likelihood score 285 signals how likely it is that the specific website is a phishing website. In one embodiment, the input size to phishing classifier layers 275 is 2048+768+1024, where the output of BERT is 768, the ResNet50 embedding size is 2048, and the size of feature hash over n-grams of URLs is 1024. Phishing detection engine 202 is highly suitable for semantically meaningful detection of phishing websites regardless of their language. The disclosed near real-time crawling pipeline captures the contents of new and suspicious webpages quickly, before they get invalidated, thus addressing the short life-cycle nature of phishing attacks, and this helps to accumulate a larger training dataset for continuous retraining of the prescribed deep learning architecture.);
and train or update a machine learning model using the discovered phishing campaigns to detect emergent exploits (See ¶¶ [0085]-[0086], Teaches that phishing classifier layers 675 are trained on URL embedding and the HTML encoding of example URLs, each example URL accompanied by the ground truth classification as phishing or as not phishing 632. During training of URL embedder 652, the differences to encoding layers used to produce the URL embedding 653 are back-propagated beyond the phishing classifier layers. That is, once HTML encoder 664 is pre-trained, the URL embedding 653 network is trained alongside the rest of network (classifier layers 675 and fine-tuning step of the HTML encoder 654) with loss function and the help of URL examples with ground truth 632 for the input information. After training, phishing classifier layers 675 process a concatenated input of the URL embedding 653 and the HTML encoding 665 to produce at least one likelihood score that the URL and the content accessed via the URL presents a phishing risk. Phishing detection engine 602 applies phishing classifier layers 675 to a concatenated input of the URL embedding and the HTML encoding, to produce at least one likelihood score 685 that the URL and the content accessed via the URL presents a phishing risk.).
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of AZARAFROOZ et al. into the combination of Li et al. and ZVERKOV et al. and AZARAFROOZ et al. in order to detecting phishing in real time via URL links and downloaded HTML, through machine learning and statistical analysis (See AZARAFROOZ et al. See ¶ [0020]).
Claim 24 is rejected under 35 U.S.C. 103 as being unpatentable over Li et al. (US 20230231879 A1) and ZVERKOV et al. (US 20220385694 A1) and AZARAFROOZ et al. (US 20230082481 A1) and further in view of PURATHEPPARAMBIL et al. (US 20200021620 A1).
As to claim 24, the combination of Li et al. and ZVERKOV et al. and AZARAFROOZ et al. in teaches the system according to claim 1 above. However, it does not expressly teach the details of wherein the one or more processors are further configured to: use the generated signatures for the one or more patterns to provide contextual or visual explainability of detected phishing campaigns to users.
PURATHEPPARAMBIL et al., from analogous art, teaches wherein the one or more processors are further configured to: use the generated signatures for the one or more patterns to provide contextual or visual explainability of detected phishing campaigns to users (See ¶ [0042], Teaches that the targeted, contextual notification messages are micro-messages comprising, for example, short lines of text reciting preventive warnings, providing links to access contextual awareness content, recommendations, etc., that aim to reduce security incidents in an organization. In an embodiment, the SBMS, in communication with one or more context libraries, dynamically generates contextual awareness content using one or more security behavioral models, automatically generated awareness strategies, and personalization preferences of the target user and an organization associated with the target user. The contextual awareness content comprises, for example, security use cases derived from the external applications and the data acquisition sources, security training modules, newsletters, and multi-channel threat simulations configured to educate the target user prior to a real-time threat. The SBMS aligns the security training modules towards the security incidents and how the security incidents spread. For example, the SBMS renders a spam avoidance module to a spam recipient, an online safety module to an online cyberattack victim, a USB safety module to a USB device infection victim, etc. The contextual awareness content promotes creation of personalized, contextual awareness based on security activities.).
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of PURATHEPPARAMBIL et al. into the combination of Li et al. and ZVERKOV et al. and AZARAFROOZ et al. in order to be notify and alert users about their actions (See PURATHEPPARAMBIL et al. See ¶ [0003]).
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to James R Hollister whose telephone number is (571)270-3152. The examiner can normally be reached Mon - Fri 7:30 am - 4:00 pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Philip Chea can be reached at (571) 272-3951. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
James Hollister
/J.R.H./Examiner, Art Unit 2499 7/29/26
/PHILIP J CHEA/Supervisory Patent Examiner, Art Unit 2499