Distributed Web Analysis via Intermediary Proxy Masking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cybersecurity systems face challenges in detecting malicious websites as bad actors evolve to evade detection by identifying and blocking the IP addresses or signatures of security systems, leading to ineffective prevention of malicious website discovery.
Innovation Solution
A classification system that distributes tasks across network devices to analyze web resources, masking security measures by varying query parameters and acting as proxies to mimic normal communication patterns, thereby conserving computing resources and avoiding detection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If a centralized security system queries malicious websites directly, then detection capability is improved, but the system's IP address and signature are detected and blocked by bad actors
Solution Approach 1:
The patent introduces intermediary devices (user devices, network devices, or honeypot devices) that act as mediators between the centralized security system and the target websites. These intermediaries perform the actual querying and content retrieval, masking the identity of the security system. The security system sends queries through these intermediaries, which then interact with target websites, preventing direct exposure of the security system's IP address and signatures while maintaining detection capabilities.
Solution Approach 2:
The patent segments the security system into multiple components: a centralized security system that coordinates analysis tasks, and distributed intermediary devices that execute the actual queries. This segmentation allows the security system to maintain detection capabilities while distributing the risk of detection and blocking across multiple independent devices, preventing a single point of failure or identification.
2Use of energy by moving object
If multiple network devices distribute analysis tasks, then computing resources are conserved, but coordination complexity increases
Solution Approach 1:
The patent merges the coordination function into a centralized security system while distributing the execution function to multiple network devices. The centralized system consolidates task management, result aggregation, and analysis coordination, while individual devices perform localized content retrieval and feature extraction. This merging of coordination functions reduces overall system complexity compared to fully distributed coordination.
Solution Approach 2:
The intermediary devices are designed with multi-functionality, serving as both user devices for normal operations and as security analysis nodes when tasked by the centralized system. This universality allows the same devices to perform both regular internet browsing and security-related content analysis, reducing the need for dedicated hardware and simplifying system deployment.
3Reliability
If the system uses proxies to mimic normal communication, then detection evasion is improved, but query accuracy may be reduced
Solution Approach 1:
The patent applies local quality by allowing different intermediary devices to use different proxying strategies based on their specific contexts and capabilities. Each device can adjust its query parameters, timing, and behavior patterns locally to match normal user behavior in its specific environment, maintaining detection evasion while preserving query accuracy for the specific conditions each device encounters.
Data Source
AI summary
The disclosed technology relates a system is configured to identify a domain for analysis, transmit instructions for querying the domain to each network device in a set of network devices, receive domain reports associated with the domain for analysis from the set of network devices, and determine, based on the domain reports, that the domain is associated with malicious features.


