Behavioral Sandbox for Malicious Ad Code Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Internet advertisements often contain malicious code that can compromise user security, allowing unauthorized access and unwanted actions, as current browser controls are insufficient to prevent malicious actors from executing harmful redirects and data access.
Innovation Solution
A system and method for detecting malicious code in internet advertisements, which includes a user device equipped with protection code that intercepts, stops, and refuses to load malicious code, using a behavioral sandbox to monitor and intercept unwanted actions, and a content delivery network to provide updated protection code.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If ads are allowed to run in the trusted scope of the user browsing session, then ad functionality and user experience are improved, but security risks increase as malicious code can access user data and perform unwanted actions
Solution Approach 1:
The patent introduces a security intermediary layer that sits between the ad code and the user browsing session. This intermediary monitors and controls ad execution, allowing legitimate ad functionality while blocking malicious actions. The intermediary acts as a mediator that permits trusted operations while preventing harmful ones, resolving the contradiction between ad usability and security.
Solution Approach 2:
The patent implements preliminary security checks and monitoring before ads execute harmful actions. By establishing security controls in advance and continuously monitoring ad behavior during execution, the system can prevent malicious code from accessing user data or performing unwanted actions while still allowing legitimate ads to function normally.
2Reliability
If browser sandbox attributes and cryptographic service provider controls are used, then some security is improved, but sophisticated malware can still bypass these controls
Solution Approach 1:
The patent implements a feedback mechanism that continuously monitors ad execution and dynamically adjusts security controls based on detected behavior. The system observes ad actions in real-time, compares them against expected legitimate behavior, and responds by blocking suspicious actions. This feedback loop enables the system to adapt to sophisticated malware that attempts to bypass traditional static controls.
Solution Approach 2:
The patent transitions from static security controls to dynamic monitoring and control mechanisms. Instead of relying on fixed sandbox attributes and CSP policies that malware can learn to bypass, the system continuously adapts its security measures based on real-time ad behavior analysis, making it difficult for sophisticated malware to predict and exploit control weaknesses.
3Reliability
If ads are thoroughly vetted and reviewed before deployment, then security is improved, but ad delivery speed and productivity decrease
Solution Approach 1:
The patent performs preliminary security setup by establishing monitoring frameworks and control mechanisms before ads are deployed. This initial setup enables continuous security monitoring without requiring slow, thorough reviews of each individual ad before delivery. The system prepares security controls in advance, allowing rapid ad deployment while maintaining security through ongoing monitoring rather than pre-approval bottlenecks.
Data Source
AI summary
There are disclosed devices, system and methods for detecting malicious code existing in an internet advertisement (ad) requested by a published webpage viewed by a user. First, receipt of malicious code of the ad is detected, where that code may be malicious code that causes a browser unwanted action without user action. The content is wrapped in a java script (JS) closure and stripped of hyper-text markup language (HTML) content that would provide an extraneous count impression for the ad. The content is then executed in a behavior sandbox that prevents display of the malicious code and the unwanted action. When a security error results from this execution, it is discontinued, the content is not displayed and the unwanted action is intercepted. After execution in the behavior sandbox begins, the ad may be executed in browser sandbox that causes a first count impression for the ad.


