Malicious Ad Creative Detection via SSP Feeding
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Internet advertisements often contain malicious code that can compromise user security, leading to unwanted actions and data access, with current browser controls being insufficient to prevent sophisticated malware attacks.
Innovation Solution
A system and method for detecting and reporting malicious creatives in internet advertisements, which involves a user device detecting and sending reports of attempted unwanted actions to a feeding computing device, which then extracts and feeds identification data to supply side platforms (SSPs) to block such ads in the future.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If ads are allowed to run in the trusted scope of the user browsing session, then ad functionality and user experience are improved, but security risks and malware exposure increase
Solution Approach 1:
The patent introduces an intermediary system between the ad delivery network and the user's browser. This intermediary monitors ad content, detects malicious creatives, and blocks harmful ads before they execute in the user's trusted browsing scope. The intermediary acts as a mediator that preserves legitimate ad functionality while filtering out malware, thus resolving the contradiction between ad usability and security.
Solution Approach 2:
The system performs preliminary detection and blocking of malicious ads before they can execute in the user's browser. By analyzing ad creatives in advance and identifying malicious patterns prior to rendering, the system prevents malware exposure while allowing legitimate ads to proceed normally, thus maintaining ad functionality without security risks.
2Reliability
If browser sandbox attributes and CSP are used to limit ad capabilities, then security is improved, but sophisticated malware can still bypass these controls
Solution Approach 1:
The patent implements a feedback mechanism where the system continuously monitors ad behavior, learns from detected malware patterns, and updates blocking rules dynamically. When sophisticated malware attempts to bypass sandbox controls, the system detects the anomaly, blocks it, and uses the feedback to improve future detection accuracy, creating an adaptive security system that evolves against new threats.
Solution Approach 2:
The system replaces static mechanical security controls (sandbox attributes and CSP) with an intelligent detection system that uses pattern recognition and machine learning. Instead of relying solely on predefined technical constraints that malware can bypass, the system substitutes these with adaptive behavioral analysis that can identify and block sophisticated attacks regardless of how they attempt to evade traditional controls.
3Reliability
If ads are thoroughly vetted and reviewed before delivery, then security is improved, but ad delivery speed and productivity decrease
Solution Approach 1:
The system performs security vetting of ad creatives in advance, before they are delivered to users. Malicious ads are identified and blocked in the preliminary stage, while legitimate ads are approved and delivered immediately. This preliminary action separates security checking from real-time delivery, ensuring security without slowing down ad productivity.
Solution Approach 2:
The patent extracts the security detection function from the real-time ad delivery process. By separating the vetting mechanism into a distinct preliminary stage that operates independently from the delivery pipeline, the system ensures thorough security review without creating bottlenecks. Legitimate ads that pass the extracted security check are delivered at full speed, while only malicious ads are slowed down for analysis.
Data Source
AI summary
There are disclosed devices, system and methods for feeding identification data of malicious creatives existing in internet advertisements to a supply side platform (SSP) by receiving reports of unwanted actions without user action by malicious creatives of internet advertisements (ads) requested from the SSP by webpages being displayed to users. The reports include a creative identification (ID), a malicious code chain of events, and a demand side platform (DSP) ID or a seat ID. The reports are pre-processed by classifying the unwanted action attempts based on the chain of events. The pre-processed reports are parsed to extract the creative IDs, the SSP IDs and the DSP IDs; and then stored in a searchable database. The stored parsed pre-processed reports are feed to SSPs based on the SSP identifications. The feed includes the creative IDs, the SSP IDs, the DSP IDs, timestamps of the unwanted action attempt and the classifications.


