Digital Auditing System Detecting Unauthorized Website Activities
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional digital auditing systems are ineffective in detecting unauthorized activities on websites, such as cyber-attacks and fraud, due to the lack of detectable footprints or signatures left by perpetrators, leading to digital theft, fraud, and liabilities for advertisers, publishers, and platform providers.
Innovation Solution
A digital auditing system with various modules and an improved database that monitors and detects unauthorized activities using Qualitative Comparative Analysis (QCA) and machine learning techniques, recognizing patterns in user information, IP addresses, and code strings, and provides real-time alerts and lockdown procedures to prevent further attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If conventional antivirus software or malware detection systems are used, then programmatic detection of footprints or signatures can be performed, but manual manipulation of data or covert replacement of character strings cannot be detected
Solution Approach 1:
The patent introduces an intermediary auditing system that sits between the website and external threats, monitoring data flow and detecting unauthorized activities. This intermediary layer captures both programmatic signatures and manual manipulations by observing the actual data transformations and comparisons, rather than relying solely on predefined detection rules.
Solution Approach 2:
The system dynamically changes detection parameters by comparing data at different states (before and after operations). It monitors changes in character strings, data structures, and operational patterns, allowing detection of both automated malware and manual manipulations through parameter comparison rather than static signature matching.
2Reliability
If conventional auditing systems are used, then basic monitoring can be performed, but effective warning and discovery of unauthorized activities cannot be achieved due to lack of detectable footprints
Solution Approach 1:
The system performs preliminary actions by establishing baseline data states before unauthorized activities occur. It captures initial character strings, data structures, and operational patterns, then compares these baselines against subsequent states to detect deviations. This preliminary recording creates detectable footprints even when perpetrators attempt to conceal their activities.
Solution Approach 2:
The auditing system implements continuous feedback by constantly comparing current data states against established baselines and providing real-time warnings when unauthorized activities are detected. This feedback mechanism ensures reliable detection by immediately responding to changes in data footprints, character strings, or operational patterns that indicate malicious activity.
3Device complexity
If simple detection methods are used, then system complexity is reduced, but detection precision for sophisticated cyber-attacks deteriorates
Solution Approach 1:
The auditing system is segmented into distinct functional modules: data capture components that record baseline states, comparison components that analyze changes, and warning components that alert to unauthorized activities. This segmentation allows the system to maintain manageable complexity while achieving high detection precision through specialized functions in each module.
Solution Approach 2:
The system replaces complex mechanical or manual detection methods with automated computational processes. Instead of relying on intricate rule-based systems or manual analysis, it uses algorithmic comparison of data states, character strings, and operational patterns to achieve high detection accuracy with relatively simple automated logic.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
An auditing system (10) is provided for detecting at least one unauthorized operational activity in at least one website, and includes a processor coupled to at least one database (34) for storing data related to the at least one unauthorized operational activity. The processor is programmed to detect the at least one unauthorized operational activity in the at least one website using a monitoring module (22) configured to monitor the at least one website via a network (16) and provide unauthorized operational status information about the at least one website using a plurality of status messages generated based on the data, and a detection module (24) configured to examine the plurality of status messages and detect an anomaly caused by the at least one unauthorized operational activity.