Malicious Flash Ad Detection via Pre-execution Risk Rating

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing sophistication of online advertising, particularly through Adobe Flash, has led to a rise in malicious exploits such as Flash Redirectors, Flash Sockets, Clipboard Jacking, and Cross-Site Scripting, which pose significant security threats by allowing hackers to infect systems with malware or adware, and existing threat detection engines struggle to detect these threats effectively due to their reliance on static URL submissions.

Innovation Solution

A system and method for risk rating and proactively filtering malicious online advertisements, which involves a gateway with an anti-malware filter, URL filter database, and malware detector that scans and categorizes URLs, and uses a risk database to assess the likelihood of malware, and includes client-side and server-side components to extract, analyze, and block potentially malicious Flash content before it is executed on user systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If Adobe Flash is used to deliver interactive advertising content, then advertising sophistication and user engagement are improved, but security vulnerabilities increase allowing hackers to exploit security holes to deliver malware

Engineering Contradiction:
Improveadvertising sophisticationVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary analysis of Flash advertisements before they are displayed to users. The gateway intercepts and scans Flash content in advance, checking for malicious code, exploit attempts, and security vulnerabilities. This proactive approach allows the system to identify and block threats before they can infect user systems, resolving the contradiction by maintaining Flash's advertising capabilities while eliminating its security risks through pre-screening.

Inventive Principle:
Principle #10Preliminary action

2Device complexity

If static URL submission-based threat detection engines are used, then system simplicity is maintained, but detection effectiveness deteriorates due to inability to detect sophisticated malicious exploits

Engineering Contradiction:
Improvedetection system simplicityVSAvoiddetection effectiveness
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The system transitions from static URL submission-based detection to dynamic, multi-dimensional analysis. The gateway performs real-time scanning of Flash content, analyzing multiple parameters including code patterns, network requests, and behavioral characteristics. This dynamic approach adapts to sophisticated threats while maintaining system manageability through automated analysis, resolving the contradiction between detection effectiveness and system complexity.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9306968B2Systems and methods for risk rating and pro-actively detecting malicious online ads
Publication Date: 2016.04.05 MCAFEE LLC
  • US9306968B2 patent drawing
  • US9306968B2 patent drawing
  • US9306968B2 patent drawing

AI summary

Methods and systems for risk rating and pro-actively detecting malicious online ads are described. In one example embodiment, a system for risk rating and pro-actively detecting malicious online ads includes an extraction module, an analysis engine, and a filter module. The extraction module is configured to extract a SWF file from a web page downloaded by the system. The analysis engine is communicatively coupled to the extraction module. The analysis engine is configured to determine a risk rating for the SWF file and send the risk rating to a web application for display. In an example, determining the risk rating includes locating an embedded redirection URL and determining a risk rating for the embedded redirection URL. The filter module is configured to determine, based on the risk rating, whether to block the SWF file and send a warning to the web application for display.