Hierarchical Internet Security Risk Scoring and Blocking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional methods struggle to effectively block malicious Internet content due to its increasingly sophisticated hiding techniques, often resulting in over-blocking or under-blocking, as they typically evaluate security risks at a single hierarchical level without considering indirect evidence or analyzing hierarchical levels with no direct evidence.
Innovation Solution
A computer-implemented method that identifies evidence of security risks across multiple hierarchical levels of the Internet hierarchy, generates security risk scores, and blocks network devices from accessing Internet content at or below the highest hierarchical level with a score above a threshold, using both direct and indirect evidence, and weighting indirect evidence based on its corresponding level.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If conventional methods evaluate security risks at a single hierarchical level, then the evaluation process is simple, but the accuracy of blocking decisions deteriorates resulting in over-blocking or under-blocking
Solution Approach 1:
The patent segments the Internet hierarchy into multiple levels (TLD, ASN, CIDR Range, IP address, Domain, Host, Path, File) and evaluates security risks at each level independently. This segmentation allows the system to analyze risks at appropriate granularities, preventing both over-blocking and under-blocking by identifying the most specific level where malicious content resides.
Solution Approach 2:
The patent adds a hierarchical dimension to security risk evaluation by analyzing multiple levels of the Internet hierarchy simultaneously. Instead of evaluating at a single level, the system propagates risk scores across hierarchical levels, enabling comprehensive assessment that captures both direct and indirect security risks.
2Reliability
If direct evidence only is used for risk assessment, then the assessment is reliable, but the coverage of detected malicious content deteriorates failing to identify hidden threats
Solution Approach 1:
The patent performs preliminary actions by generating indirect evidence through propagation across hierarchical levels before making blocking decisions. When direct evidence is unavailable at a particular level, the system proactively infers risks by propagating evidence from related levels, enabling detection of hidden threats that would otherwise go undetected.
Solution Approach 2:
The patent uses hierarchical propagation as an intermediary mechanism to connect direct evidence at one level with potential risks at other levels. The propagation process acts as a mediator that translates direct security evidence into indirect evidence across the hierarchy, bridging gaps where direct evidence is absent.
3Object-affected harmful factors
If blocking is applied at higher hierarchical levels, then more malicious content is blocked, but more benign content is also blocked reducing accessibility
Solution Approach 1:
The patent applies local quality by identifying the most specific hierarchical level where malicious content resides and blocking only at that level and below. Rather than applying blanket blocking at high levels, the system tailors blocking decisions to local conditions at each hierarchical level, ensuring minimal impact on benign content while maximizing malicious content blocking.
Solution Approach 2:
The patent changes the parameter of blocking scope by dynamically selecting the appropriate hierarchical level for blocking based on risk scores and evidence quality. The system adjusts which hierarchical level becomes the blocking boundary, transforming a static blocking approach into a dynamic one that adapts to the specific security situation.
Data Source
AI summary
Blocking malicious Internet content at an appropriate hierarchical level. In one embodiment, a method may include identifying evidence of security risks in hierarchical levels of an Internet hierarchy. The method may also include generating security risk scores for the hierarchical levels of the Internet hierarchy based on the evidence of security risks. The method may further include identifying a security risk threshold. The method may also include identifying, as an appropriate blocking level, the highest hierarchical level of the Internet hierarchy having a security risk score at or above the security risk threshold. The method may further include blocking a network device from accessing Internet content in the Internet hierarchy at or below the appropriate blocking level.


