EP1683293A4 - System und verfahren zum angehen von email- und elektronischem kommunikationsbetrug - Google Patents
System und verfahren zum angehen von email- und elektronischem kommunikationsbetrugInfo
- Publication number
- EP1683293A4 EP1683293A4 EP04800816A EP04800816A EP1683293A4 EP 1683293 A4 EP1683293 A4 EP 1683293A4 EP 04800816 A EP04800816 A EP 04800816A EP 04800816 A EP04800816 A EP 04800816A EP 1683293 A4 EP1683293 A4 EP 1683293A4
- Authority
- EP
- European Patent Office
- Prior art keywords
- wherem
- data
- mcludmg
- details
- memod
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Withdrawn
Links
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
- G06F21/554—Detecting local intrusion or implementing counter-measures involving event detection and direct action
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L51/00—User-to-user messaging in packet-switching networks, transmitted according to store-and-forward or real-time protocols, e.g. e-mail
- H04L51/21—Monitoring or handling of messages
- H04L51/212—Monitoring or handling of messages using filtering or selective blocking
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1441—Countermeasures against malicious traffic
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1441—Countermeasures against malicious traffic
- H04L63/1491—Countermeasures against malicious traffic using deception as countermeasure, e.g. honeypots, honeynets, decoys or entrapment
Definitions
- the present invention relates to email fraud detection and prevention, more specifically to interfering with and/or tracking certain fraudulent attacks; furthermore, the present invention relates to testing data gathering systems.
- Phishing can injure valuable corporate brand equity, ruin customer trust, increase operational costs through growing customer complaints, and present additional risks and problems.
- the bank or other attached company may has to publish a general warning to its customers, and sometimes even cancel or block people's accounts. PMshing may involve, but is not limited to, for example: (1) The originators of 'Thishing" e-mails attempt to make the e-mail distributed seem to be coming from a legitimate source.
- the Phishing e-mail may be disguised as a legitimate e-mail, and includes elements and characteristics of a legitimate organization, such as (without limitation) logo, domain names, brands and colors;
- the originators of "PMsMng" need to somehow divert information that the tasting consumers submit in response to the seemingly legitimate e-mail. Such information might be diverted via for example a link to a separate web-page that requires the individual to input valuable private information, or via telephone, if the e-mail directs the recipient to call a certain telephone number (following which the recipients valuable information might be collected over the phone).
- illegitimate contact pointers Such illegitimate links or contact telephone numbers may be referred to as "illegitimate contact pointers".
- the implications of the above characteristics of PMshing are that any PMsMng e- mails typically include a mixture of both legitimate and iUegitimate contact pointers (such as hnks to other web pages or telephone numbers).
- Legitimate contact pointers would point to web pages or telephone numbers that belong to legitimate e-mail senders.
- Illegitimate contact pointers would point to web pages or telephone numbers that belong to the parties committing fraud.
- a system and method may respond to a fraudulent attack, such as a PMshing attack.
- the system and method may send a number of responses to party committing fraud, the responses designed to mimic the responses to a PMshing attack.
- the responses may include codes or marked information designed to entrap or detect the party committing fraud.
- Embodiments of the present invention relate to a method and system for reducing negative consequences associated with the submitting of valuable and confidential information by individuals to fraudulent impostors, as well as for increasing the likelihood that fraudulent impostors be captured.
- Embodiments of the current mvention include a system and method for rmnimizmg the impact of PMsMng scams as well as facihtating the detection of the originators of the attack.
- Fig. 1 depicts a system according to one embodiment of the invention
- Fig. 2 illustrates a multiple-access-point computer network wMch may be used with an embodiment of the present invention.
- the detection of PMsMng scams can be done using existing anti e-mail-spam methods
- wMch can issue alerts whenever they detect an e-mail
- wMch contains at least X (e.g., a suitable number, where one may be a s table number) legitimate contact pointers such as domains, trademarks, service names, phone numbers, etc., by a centralized service, such as a "Service Provider,” along with illegitimate pointers.
- X e.g., a suitable number, where one may be a s table number
- legitimate contact pointers such as domains, trademarks, service names, phone numbers, etc.
- a centralized service such as a "Service Provider”
- An anti e- mail-spam company that works with tMs method may set up numerous e-mail accounts that do not belong to real people or entities, and hsts them pubhc e-mail guides. If an e-mail gets to these addresses it can be either the result of a spam or an honest mistake. If the e-mail reaches several addresses the chances of an honest mistake are shm. Other methods may mclude for example content filtering or smffing. Once a potential PMsMng scam or other unwanted data commumcation is identified some pre-processing may be performed to make sure it is mdeed a suspicious e-mail or commumcation.
- Various devices and arcMtectures, and sets of devices may form a system according to various embodiments of the present invention, and my effect a method according to embodiments of the present invention.
- Methods accordmg to various embodiments of the present mvention may, for example, be executed by one or more processors or computing systems (mcludmg, for example, memories, processors, software, databases, etc.), wMch, for example, may be distributed across various sites or computing platforms; alternatively some methods according to embodiments may be executed by s gle processors or computing systems.
- the following illustration outlines a solution arcMtecture according to one embodiment of the present mvention; other smtable arcMtectures are possible m accordance with other embodiments of the mvention.
- a network 10 such as the Mternet, the Internet m combination with other networks, or some other network combmation of networks connects a set of entities.
- a central server 20 may provide services such as momtoring PMshing or other e-mail oriented fraud, and may try to counteract, mterfere with, or track such fraud, or attempt to track down the identity of the perpetrators.
- a set (where set can include one element) of institutions 30, such as banks, financial mstitutions, or other mstitutions, wMch may be targets of PMsMng or other fraud, may request services from the central server 20.
- One or more parties committing fraud may be known as for example "fraudsters" 40 may attempt to commit fraud via email, for example via "PMsMng", by sending fraudulent emails to a set of users 50, for example requesting the users to contact an mstitution 30 usmg a contact pomt or address (e.g., an email address, an Mternet address, etc.) or phone number that is actually directed to the party 40 or an associate.
- the contact po t or address may be made to appear as it if belongs to a legitimate institution 30.
- the central server 20 may attempt to send fake or other information to the contact point or other address to interfere with or stop fraudulent activities, m one embodiment server 20 momtors for PMsMng attacks; m other embodiments other entities such as institutions may inform server 20 regarding PMsMng attacks.
- the contact point may be an e-mail address.
- the data in a response may be sent to the party committing fraud via email, possibly directly (e.g. by the party requesting the details to be sent via the "Reply To" email option, or by a JavaScript client side code that does so automatically, etc.) or indirectly to the party (e.g., the party may implement a web-to-mail mterface, wherem the user data is eventually sent to an email address from where it is later collected by the party).
- Central server 20 may clude one or more database(s) 22, a controller or processor 24, and software 26, wMch may mclude for example, an identity generator 28, or other suitable modules. Controller or processor 24 may execute mstructions m software 26 to perform various functions such as those described herein.
- the functionahty of central server 20 may be implemented m other manners, such as being distributed among other sites, be g mcluded m one or more Mstitutions, etc.
- a bank may include the fraud blockmg or trackmg capabihties as described here .
- the central server 20 may have as customers mstitutions 30 that wish to stop and/or entrap fraud committing parties, but such a customer-client relationsMp is not needed; for example central server 20 may be a government or non-profit entity, part of a consortium of Mterested parties, or part of an institution 30.
- the central server 20 may detect fraudulent activity (e.g., PMsMng); alternatively the central server 20 may act after being requested by an other party wMch has detected fraudulent activity.
- the central server 20 may for example, provide multiple responses to a contact pomt created by a party 40.
- the central server may respond multiple times to mimic a group of users responding to the fraud (each response may mclude different data), and the responses maybe timed, paced, and/or numbered to mimic the natural response of a large group of people. For example, responses may start with a flurry and then gradually slow down, and each response may be sent at a somewhat random time within an overall desired pattern.
- the total number of responses may be proportion to a size of the attack in response to wMch the responses are sent.
- the number of responses canbe X% (e.g., 0.1%, 1%, 5%, 10%, etc.) of the number of emails or other commumcations that constituted the PMsMng or other attack, possibly based on known response rates.
- Each response may be for example the central server filhng m or sending details to a web site or web form, possibly at the contact pomt. Furthermore, within each response, data may be entered at a speed an pace to mimic a human entering information usmg a keyboard and pomting device (e.g., mouse).
- a response may mclude a set of details such as a set of false personal information. Multiple sets of false personal information can be created and for example stored M a database 22.
- the central server may perform tasks such as, for example: Dilution: For example, a PMsMng website (e.g., at a contact pomt defined by a party 40) maintained by a party 40 wMch tries to collect data from the central server (or "Service Provider") customers (e.g., mstitutions 30) is filled with fake records of people, thus diluting the quality of data that the parties cornmittmg fraud obtaM;
- Mark & Block For example, usMg responses with marked data, the PMsMng website wMch tries to collect data from mstiMtion 30 is filled with fake records of people.
- the central server 20 When the central server 20 detects that those "fake people” attempt to access the central server 20 real website/Service or an Mstitution 30 website, it may be possible to identify the source of that attempt (usmg the phony records) and to block any further attempts from that same source (e.g. IP, location etc), tMs way, when the party cornmitting fraud (e.g., "fraudster") attempts to access central server 20 or MstiMtion 30 service usmg real valuable stolen data (and not the fake one sent to it) such usage will be blocked, mcludmg good details; (3) Mark and Capture: For example, the PMsMng website wMch tries to collect data from the Service Provider's customers, is filled with fake records of people via responses with marked data.
- fraud e.g., "fraudster”
- a central server 20 or mstiMtion 30 can mo tor, for example, an MstiMtion or central server website, for the use of marked data M an attempted transaction. Other actions may be taken.
- dummy responses may be sent to the fraudulent site (e.g., mamtamed by a party 40) by, for example, the central server 20 as if the responses were cormng from real users who were defrauded by the scam.
- the fraudMent site is fed with useless records, and hence the quality of data that is obtamed is diluted.
- the amount of responses can be configurable so that it would be consistent with the estimated attack size (importantly the estimated number of users who may actoally give away their personal information, wMch can be deterrmned by usmg statistical assessment).
- the central server 20 may sMiulate a real human user feeding data at an appropriately slow, human typmg pace, seemmgly from multiple IP addresses with Mtervals between data string to the other.
- Data M a response may Mclude or be marked with for example data or codes identifiable to a central server 20 or mstiMtion 30, so that for example its use can be tracked.
- data may be marked with cryptograpMcally encoded portions.
- Details may be marked m a manner makmg it (for example by usMg a cryptograpMcally strong algorithms) infeasible to spot or detect, except for those ,who have a cryptograpMc key with wMch the markmg can be deciphered and or extracted from the data.
- An embodiment of the system and method may be designed to reduce the quality of the data obtamed by the party committing fraud during a PMsMng attack, and thus mitigate the attack's negative consequences. By diluting the data obtamed by the party committing fraud, the stolen data obtamed by the "fraudster" becomes less valuable, hence reducMg the mcentive to attack service providers who utilize the proposed system and method.
- a limited amount of dummy responses are submitted to the fraudulent site where the responses are marked, such that the responses can be tracked at a later stage.
- TMs may be done M combination with sending un-marked responses.
- TMs way the use of the credentials provided as part of these responses can be moMtored.
- the system identifies an attempt to use such "marked credentials” it is possible according to one embodiment to block the access to the service from such location (typically an IP address where "bait information" was attempted to be used from), and therefore prevent attempts to use real credentials from such location.
- the current mvention parties committing fraud might be located based on the marked responses.
- M many cases these "fraudsters" obtaM Mformation during a PMsMng attack, but do not attempt to use the data for several months. Markmg the dummy credentials submitted to the fraudster accordmg to the above embodiment may allow a server or other party to follow the credentials for a long period of time. M addition, M other embodiments hav g other uses, dummy, randomized or manufactured responses, with randomized or fake data, may be submitted to other sites or contact pomts, such as systems be g tested or debugged, or for the purpose of training.
- a multiple-access-poMt computer network may be used to simMate responses from various pomts of presence via different network connections, such as for example Mternet connections. Parties committing fraud therefore are not able to simply "ignore" all information comMg from a smgle pomt of presence, and cannot detect that M fact fake credentials are fed.
- the system may m responding and sendmg false data use a multiple-access-pomt computer network wMch uses several levels of design, wMch helps to ensure that dummy responses are undetectable.
- Responding maybe conducted usmg multiple Mternet access pomts, multiple Mtermediate networks, and/or mMtiple Mtermediate Mternet service providers.
- Mternet accounts used to generate the dummy responses may use dynamic network IP addresses, or use proxy servers and imitate behavior or users that pass via proxy when relevant usmg both dialup and broadband connection M order to fruther disguise the counter-measure.
- the dialup connections may alternate between different telephone exchanges m order to prevent sopMsticated parties committing fraud from trackmg the physical location of the source JJP addresses.
- - Fig. 2 illustrates a multiple-access-poMt computer network wMch may be used with an embodiment of the present Mvention.
- Users, computers, or other access pomts 60 may contact a party 40 wMch mtends to commit fraud via multiple ISPs or other service providers 100 and 102, possibly bemg geograpMcally distributed, possibly via network 10 (Fig. 1).
- central server 20 may contact party 40 via multiple ISPs or other service providers 100 and 102.
- the central server 20 may use a scheduler or other system wMch may regulate the "response sending rate" M order to ensure that the dummy responses are momtored, and may thus sMiulate real responses.
- the scheduler may be important where large amounts of dummy responses are fed to the spoofed site m order to de-value the obtamed mformation.
- the scheduler can be implemented M the software 26.
- the Mvention responses may be designed to resemble human behavior and appear to be sent from acMal recipients of the fraudulent e- mail.
- TMs can be done for example without limitation by usMg Robot-like software, possibly implemented M the software 22.
- Each response may mclude details wMch are Mternally consistent witMn the response.
- the system and method M includes an "identity generator", wMch produces phony details that appear to be legitimate (e.g., adhering to the rules of different data elements, such as user names and passwords, onhne bankmg credentials, credit card details, checks etc.).
- the identity generator maybe configured to match each specific company's details and rules.
- the identity generator may create dummy or fake identities usmg a large database (e.g., part of database 22) of names, local addresses, e-mail domams, and more. Such fake identities may be part of database 22.
- the dummy identity may be coherent or consistent, meaning different pieces of information do not contradict each other, and also may match the external conditions (such as for example ternet connection).
- the details witMn a response m cludes a set of details consistent with an Mternet service provider to be used for the response.
- a phone number that may be part of the details may match the address as well as the telephone exchange used for a dial-up connection used to transmit the response.
- M addition the e-mail address may match the ISP used and so on.
- Other sets of details maybe used.
- the central server 20 may randomly generate usernames and passwords that match the company's rules as well as an e-mail address wMch appears to match the username etc.
- a system that responds to PMsMng attacks by generating random credentials and feeding them to web-forms could serve additional purposes such as test g services, debuggmg services as well as for the sake of demonstrating various scenarios.
- M such an embodiment, a website or other contact poMt to be demonstrated, tested, etc. can be contacted multiple times to, for example, enter data, fill m a web-form, etc. with a set of data.
- Each set of data can Mclude, for example, a set of details, the set of details McludMg a set of false personal information.
- the contacts or filling of data on for example the web-form can Mclude transmittmg information at a speed designed to mimic a human entering data.
- the timing of the contacting can be set to resemble that of a set of unrelated users.
- Each contact or response may Mclude a set of details that are Mternalry consistent.
- a database may be created, McludMg a set of false or manufactured data wMch may be for example organized Mto identities, each false identity McMdMg a set of data wMch is consistent witMn the set.
- McludMg a set of false or manufactured data wMch may be for example organized Mto identities, each false identity McMdMg a set of data wMch is consistent witMn the set.
- a database may be stored M database(s) 22.
- Credentials generated and used as part of Me service may be created usmg a cryptograpMc key, such that Me markMg of the credentials could not be detected without Me key.
- Real data may be used, so that Me party committing fraud will acMally perform true transactions, and coMd more easily be tracked.
- a system and meMod that creates and/or transmits manufactured data, as described herem may have oMer uses, for example, training, testing, developmg, demonstrating, etc.
- responses or other sets of manufactured or fake personal data may be sent to one or more contact pomts, wherem, Me data is used to tram people, such as customer support representatives, sales representatives, etc., Mteracting wiM the system.
- BoM the system or server generating Me data and the system receivMg Me data may be witMn the same organization or the same system.
- An automated or semi-automated system for deahng with large numbers of people can be designed, demonstrated, or tested usmg such a system and meMod.
- Responses or sets of false or manufactured data may be sent to demonstrate, debug, test or develop a system wMch may deal with sensitive personal information, so Mat real data is not revealed to Me viewers.
- a system and meMod Mat creates and/or transmits fake or manufactured data, as described hereM, may for example be used agamst software such as "Trojan horses", or oMer software, where, for stance, malicious software Mstalls itself on a user's system (e.g., a workstation, a personal computer, etc.) M stealM mode.
- the piece of software may listen to McomMg and outgoMg commumcations of Me chent's system via for example the Mternet, and may momtor browser events and user puts (e.g. keyboard loggMg).
- a piece of software tercepts a log activity M wMch the user logs M to a designated web site or system (or to any site)
- Me logM credentials may be collected mrough the keyboard loggmg facility and covertly transmitted to a site m control of the party committing fraud.
- Such transmission can occur over a multiphcity of protocols, such as e-mail (e.g., SMTP), the Mternet (e.g., HTTP HTTPS), FTP, and oMers.
- the mvention a system and method may generate and/or transmit, for example a set of responses or transmissions McludMg fake data, rrrimickMg Me behavior of "Trojan horses", or oMer malicious software Mat may be designed to be Mstalled on a user's systems.
- such responses may be sent at a pace Mat mhmcs a set of responses from a set of geograpMcally dispersed users usMg different computer and commuMcations systems, and may Mclude fake data as described hereM.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Theoretical Computer Science (AREA)
- Software Systems (AREA)
- Computer Hardware Design (AREA)
- General Engineering & Computer Science (AREA)
- Signal Processing (AREA)
- Computer Networks & Wireless Communication (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Computing Systems (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
- Information Transfer Between Computers (AREA)
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| US51786803P | 2003-11-07 | 2003-11-07 | |
| PCT/US2004/036993 WO2005048522A1 (en) | 2003-11-07 | 2004-11-08 | System and method of addressing email and electronic communication fraud |
Publications (2)
| Publication Number | Publication Date |
|---|---|
| EP1683293A1 EP1683293A1 (de) | 2006-07-26 |
| EP1683293A4 true EP1683293A4 (de) | 2007-07-25 |
Family
ID=34590201
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP04800816A Withdrawn EP1683293A4 (de) | 2003-11-07 | 2004-11-08 | System und verfahren zum angehen von email- und elektronischem kommunikationsbetrug |
Country Status (2)
| Country | Link |
|---|---|
| EP (1) | EP1683293A4 (de) |
| WO (1) | WO2005048522A1 (de) |
Families Citing this family (12)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US8041769B2 (en) | 2004-05-02 | 2011-10-18 | Markmonitor Inc. | Generating phish messages |
| US7457823B2 (en) | 2004-05-02 | 2008-11-25 | Markmonitor Inc. | Methods and systems for analyzing data related to possible online fraud |
| US9203648B2 (en) | 2004-05-02 | 2015-12-01 | Thomson Reuters Global Resources | Online fraud solution |
| US8145718B1 (en) * | 2005-10-21 | 2012-03-27 | Voltage Security, Inc. | Secure messaging system with personalization information |
| US7831915B2 (en) | 2005-11-10 | 2010-11-09 | Microsoft Corporation | Dynamically protecting against web resources associated with undesirable activities |
| US8353029B2 (en) | 2005-11-10 | 2013-01-08 | Microsoft Corporation | On demand protection against web resources associated with undesirable activities |
| TWI459232B (zh) * | 2011-12-02 | 2014-11-01 | Inst Information Industry | 釣魚網站處理方法、系統以及儲存其之電腦可讀取記錄媒體 |
| US9027126B2 (en) | 2012-08-01 | 2015-05-05 | Bank Of America Corporation | Method and apparatus for baiting phishing websites |
| US9094452B2 (en) | 2012-08-01 | 2015-07-28 | Bank Of America Corporation | Method and apparatus for locating phishing kits |
| US8943594B1 (en) | 2013-06-24 | 2015-01-27 | Haystack Security LLC | Cyber attack disruption through multiple detonations of received payloads |
| CN105574036B (zh) * | 2014-10-16 | 2020-04-21 | 腾讯科技(深圳)有限公司 | 一种网页数据的处理方法及装置 |
| JP6899567B2 (ja) | 2016-12-08 | 2021-07-07 | セクエンス セキュリティ,インコーポレイテッド | ウェブサービスに対する悪意の自動攻撃の防止 |
Family Cites Families (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US6546472B2 (en) * | 2000-12-29 | 2003-04-08 | Hewlett-Packard Development Company, L.P. | Fast suspend to disk |
| KR100460322B1 (ko) * | 2002-05-31 | 2004-12-08 | (주) 시큐컴 | 스팸메일 방지 시스템 및 방법 |
| US7461263B2 (en) * | 2003-01-23 | 2008-12-02 | Unspam, Llc. | Method and apparatus for a non-revealing do-not-contact list system |
-
2004
- 2004-11-08 EP EP04800816A patent/EP1683293A4/de not_active Withdrawn
- 2004-11-08 WO PCT/US2004/036993 patent/WO2005048522A1/en not_active Ceased
Non-Patent Citations (4)
| Title |
|---|
| CHESWICK B: "An Evening with Berferd In Which a Cracker is Lured, Endured, and Studied", PROCEEDINGS OF THE WINTER USENIX CONFERENCE, XX, XX, 20 January 1992 (1992-01-20), pages 163 - 173, XP002952580 * |
| CHUNMING RONG ET AL: "Honeypots in Blackhat Mode and its Implications", PARALLEL AND DISTRIBUTED COMPUTING, APPLICATIONS AND TECHNOLOGIES, 2003. PDCAT'2003. PROCEEDINGS OF THE FOURTH INTERNATIONAL CONFERENCE ON AUG. 27 - 29, 2003, PISCATAWAY, NJ, USA,IEEE, 27 August 2003 (2003-08-27), pages 185 - 188, XP010661258, ISBN: 0-7803-7840-7 * |
| See also references of WO2005048522A1 * |
| SPITZNER L: "Honeytokens: The Other Honeypot", INTERNET, 21 July 2003 (2003-07-21), XP002437720, Retrieved from the Internet <URL:http://web.archive.org/web/20030811090852/http://www.securityfocus.com/infocus/1713> [retrieved on 20070614] * |
Also Published As
| Publication number | Publication date |
|---|---|
| EP1683293A1 (de) | 2006-07-26 |
| WO2005048522A1 (en) | 2005-05-26 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US9076132B2 (en) | System and method of addressing email and electronic communication fraud | |
| US7493403B2 (en) | Domain name ownership validation | |
| US9356947B2 (en) | Methods and systems for analyzing data related to possible online fraud | |
| US7913302B2 (en) | Advanced responses to online fraud | |
| US7870608B2 (en) | Early detection and monitoring of online fraud | |
| US7992204B2 (en) | Enhanced responses to online fraud | |
| US9203648B2 (en) | Online fraud solution | |
| US20060224677A1 (en) | Method and apparatus for detecting email fraud | |
| US20070107053A1 (en) | Enhanced responses to online fraud | |
| US20070299915A1 (en) | Customer-based detection of online fraud | |
| WO2007058732A2 (en) | B2c authentication system and methods | |
| Husák et al. | PhiGARo: Automatic phishing detection and incident response framework | |
| EP1683293A1 (de) | System und verfahren zum angehen von email- und elektronischem kommunikationsbetrug | |
| US20070250916A1 (en) | B2C Authentication | |
| Syiemlieh et al. | Phishing-an analysis on the types, causes, preventive measuresand case studies in the current situation | |
| Nasution et al. | Defense in Depth Strategy from Phising Attacks in Using Instagram | |
| van der Merwe et al. | Phishing in the system of systems settings: mobile technology | |
| Chaudhary | Development review on phishing: a computer security threat | |
| Rawat et al. | An integrated review study on efficient methods for protecting users from phishing attacks | |
| Singh | Detection of Phishing e-mail | |
| Bhardwaj et al. | Types of hacking attack and their countermeasure | |
| Patayo | A Preventive and Detective Model for Phishing Attack in Small and Medium Size Businesses | |
| Mehendele et al. | Review of Phishing Attacks and Anti Phishing Tools | |
| Patel | Design and Implementation of Heuristic based Phishing detection technique | |
| Dhinakaran et al. | " Reminder: please update your details": Phishing Trends |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| 17P | Request for examination filed |
Effective date: 20060602 |
|
| AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HU IE IS IT LI LU MC NL PL PT RO SE SI SK TR |
|
| DAX | Request for extension of the european patent (deleted) | ||
| RIN1 | Information on inventor provided before grant (corrected) |
Inventor name: ORAD, AMIR Inventor name: BENNETT, NAFTALI Inventor name: GOLAN, LIOR Inventor name: TSUR, MICHAL Inventor name: RIVNER, NIRA |
|
| A4 | Supplementary search report drawn up and despatched |
Effective date: 20070627 |
|
| RIC1 | Information provided on ipc code assigned before grant |
Ipc: G06F 1/00 20060101AFI20070615BHEP Ipc: H04L 29/06 20060101ALI20070615BHEP |
|
| 17Q | First examination report despatched |
Effective date: 20071022 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE APPLICATION IS DEEMED TO BE WITHDRAWN |
|
| 18D | Application deemed to be withdrawn |
Effective date: 20080603 |