US 12,316,606 B2
Systems and methods for in-process URL condemnation
Pranay Harsadbhai Patel, Broomfield, CO (US); and Juan Marcelo Da Cruz Pinto, Portland, OR (US)
Assigned to PROOFPOINT, INC., Sunnyvale, CA (US)
Filed by Proofpoint, Inc., Sunnyvale, CA (US)
Filed on Apr. 4, 2024, as Appl. No. 18/626,323.
Application 18/626,323 is a continuation of application No. 18/304,248, filed on Apr. 20, 2023, granted, now 11,973,786.
Application 18/304,248 is a continuation of application No. 17/214,599, filed on Mar. 26, 2021, granted, now 11,716,310, issued on Aug. 1, 2023.
Claims priority of provisional application 63/133,085, filed on Dec. 31, 2020.
Prior Publication US 2024/0275764 A1, Aug. 15, 2024
Int. Cl. H04L 9/40 (2022.01); G06F 16/22 (2019.01); G06F 16/955 (2019.01); G06F 16/958 (2019.01); G06F 21/51 (2013.01); G06F 21/56 (2013.01); G06F 21/57 (2013.01)
CPC H04L 63/0236 (2013.01) [G06F 16/22 (2019.01); G06F 16/9566 (2019.01); G06F 16/986 (2019.01); H04L 63/1416 (2013.01); H04L 63/1425 (2013.01); G06F 21/51 (2013.01); G06F 21/566 (2013.01); G06F 21/577 (2013.01)] 20 Claims
OG exemplary drawing
 
1. A method, comprising:
receiving, by a computer, a real time click event as a browser on a user device attempts to load a page linked by a universal resource locator (URL); and
while the page is being rendered by the browser with page data from a web server hosting the page, performing, by the computer:
determining whether the URL is known as a bad URL; and
responsive to the URL not being known as a bad URL:
intercepting the page data communicated from the web server to the browser;
determining, from the page data, microfeatures of the page and any URLs referenced by the page;
applying detection rules to events associated with rendering the page in the browser, the microfeatures of the page, and the URLs referenced by the page;
determining whether application of the detection rules indicates that any content, activity, or sequence of events associated with the page is considered malicious; and
responsive to the page being considered malicious, condemning the URL before the content of the page is fully rendered on the user device.