| CPC H04L 63/1483 (2013.01) [G06N 3/08 (2013.01); H04L 63/1416 (2013.01)] | 20 Claims |

|
1. A mobile device associated with a user for reducing computer network bandwidth and server processing resources via local determination of malicious messages, the mobile device comprising:
one or more processors and non-transitory computer-readable media comprising instructions that, when executed by the one or more processors, cause operations comprising:
prior to a second user application on the mobile device receiving a new message from a server associated with an entity, receiving, via a first user application executing on the mobile device associated with the entity, a reference hash from the server associated with the entity sending the new message, wherein the reference hash is associated with at least a portion of the new message;
receiving, via the second user application on the user-mobile device, the new message;
in response to determining that the new message is associated with the entity, comparing, with the reference hash, a second hash derived from hashing at least the portion of the received new message; and
in response to the mobile device comparing the second hash with the reference hash, determining, based on the comparison, that the received new message is a phishing attempt and displaying a notification to the user, the phishing attempt being directed to steal sensitive information associated with the first user application, wherein the first user application is different from the second user application, via which the new message is received.
|