CPC H04L 63/1483 (2013.01) | 12 Claims |
1. A method for detecting phishing messages in network communications, the method comprising:
receiving a transmitted message and detecting characteristics of the message;
determining if the message matches a pattern of a phishing message in a database;
in the case of the message matching a known phishing message, classifying the message as spam or a phishing message and moved to a phishing or spam folder;
in the case of the message not matching a known phishing message pattern, checking the message for common signs of phishing or spam by determining the severity of a threat embodied by the message, and categorizing the message as having phishing characteristics;
in the case of a determination of a low probability of phishing characteristics, not further process the message for phishing;
in the case of a determination of a high or moderate probability of phishing characteristics, classifying the message as presenting signs of a phishing attempt;
in the case of a determination indicating phishing with a high accuracy, classifying the message as presenting signs of a phishing attempt with a high accuracy, and sending a warning message of a high probability of phishing to the recipient; and
in the case of a determination indicating phishing with a moderate or medium accuracy, classifying the message as presenting signs of a phishing attempt with a moderate or medium accuracy, and sending a warning message of a moderate probability of phishing.
|