Malicious Ad Creative Detection via SSP Feeding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Internet advertisements often contain malicious code that can compromise user security, leading to unwanted actions and data access, with current browser controls being insufficient to prevent sophisticated malware attacks.

Innovation Solution

A system and method for detecting and reporting malicious creatives in internet advertisements, which involves a user device detecting and sending reports of attempted unwanted actions to a feeding computing device, which then extracts and feeds identification data to supply side platforms (SSPs) to block such ads in the future.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If ads are allowed to run in the trusted scope of the user browsing session, then ad functionality and user experience are improved, but security risks and malware exposure increase

Engineering Contradiction:
Improvead functionalityVSAvoidmalware exposure
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary system between the ad delivery network and the user's browser. This intermediary monitors ad content, detects malicious creatives, and blocks harmful ads before they execute in the user's trusted browsing scope. The intermediary acts as a mediator that preserves legitimate ad functionality while filtering out malware, thus resolving the contradiction between ad usability and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary detection and blocking of malicious ads before they can execute in the user's browser. By analyzing ad creatives in advance and identifying malicious patterns prior to rendering, the system prevents malware exposure while allowing legitimate ads to proceed normally, thus maintaining ad functionality without security risks.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If browser sandbox attributes and CSP are used to limit ad capabilities, then security is improved, but sophisticated malware can still bypass these controls

Engineering Contradiction:
Improvesecurity controlVSAvoidsophisticated malware attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements a feedback mechanism where the system continuously monitors ad behavior, learns from detected malware patterns, and updates blocking rules dynamically. When sophisticated malware attempts to bypass sandbox controls, the system detects the anomaly, blocks it, and uses the feedback to improve future detection accuracy, creating an adaptive security system that evolves against new threats.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system replaces static mechanical security controls (sandbox attributes and CSP) with an intelligent detection system that uses pattern recognition and machine learning. Instead of relying solely on predefined technical constraints that malware can bypass, the system substitutes these with adaptive behavioral analysis that can identify and block sophisticated attacks regardless of how they attempt to evade traditional controls.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If ads are thoroughly vetted and reviewed before delivery, then security is improved, but ad delivery speed and productivity decrease

Engineering Contradiction:
Improvead securityVSAvoidad delivery speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs security vetting of ad creatives in advance, before they are delivered to users. Malicious ads are identified and blocked in the preliminary stage, while legitimate ads are approved and delivered immediately. This preliminary action separates security checking from real-time delivery, ensuring security without slowing down ad productivity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts the security detection function from the real-time ad delivery process. By separating the vetting mechanism into a distinct preliminary stage that operates independently from the delivery pipeline, the system ensures thorough security review without creating bottlenecks. Legitimate ads that pass the extracted security check are delivered at full speed, while only malicious ads are slowed down for analysis.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11487877B2Identifying malicious creatives to supply side platforms (SSP)
Publication Date: 2022.11.01 HUMAN SECURITY INC
  • US11487877B2 patent drawing
  • US11487877B2 patent drawing
  • US11487877B2 patent drawing

AI summary

There are disclosed devices, system and methods for feeding identification data of malicious creatives existing in internet advertisements to a supply side platform (SSP) by receiving reports of unwanted actions without user action by malicious creatives of internet advertisements (ads) requested from the SSP by webpages being displayed to users. The reports include a creative identification (ID), a malicious code chain of events, and a demand side platform (DSP) ID or a seat ID. The reports are pre-processed by classifying the unwanted action attempts based on the chain of events. The pre-processed reports are parsed to extract the creative IDs, the SSP IDs and the DSP IDs; and then stored in a searchable database. The stored parsed pre-processed reports are feed to SSPs based on the SSP identifications. The feed includes the creative IDs, the SSP IDs, the DSP IDs, timestamps of the unwanted action attempt and the classifications.