Malicious Content Detection via Domain Association Mapping
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current anti-malware solutions are primarily reactive and unable to detect malware in a timely manner, leading to potential hours or days of exposure to harmful content before adequate blocking can be effected, and they fail to identify new malware and malicious websites distributing harmful content in real-time.
Innovation Solution
The system identifies potentially harmful content by examining associations with known offending entities and domains, assigning suspicion levels based on proximity to the source of malicious code, and prioritizing further scrutiny using a relational mapping approach to quickly identify and block malicious content.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual research methods are used to identify harmful content, then detection accuracy can be maintained, but the time required for detection increases significantly
Solution Approach 1:
The patent segments the detection process into multiple automated components: collecting URL data from multiple sources, analyzing content against known harmful patterns, examining associations with identified harmful entities, and assigning suspicion levels. This segmentation allows parallel processing of different detection tasks, maintaining accuracy while reducing overall detection time.
Solution Approach 2:
The patent replaces manual research methods with automated computer-implemented processes. The system automatically collects URL data, analyzes content, identifies associations, and prioritizes scrutiny without human intervention, substituting mechanical automation for manual analysis while maintaining or improving detection accuracy through systematic automated procedures.
2Reliability
If comprehensive manual analysis is performed on all potential threats, then detection thoroughness is improved, but productivity decreases due to time consumption
Solution Approach 1:
The patent implements preliminary automated analysis that assigns suspicion levels to URLs and domains before comprehensive scrutiny is applied. By pre-processing and prioritizing targets based on initial automated assessment, the system prepares a ranked list of high-probability threats, enabling focused thorough analysis on the most suspicious cases while maintaining overall detection speed.
Solution Approach 2:
The patent applies partial analysis to all potential threats through automated suspicion level assignment, then applies excessive (comprehensive) analysis only to high-priority targets identified as most suspicious. This selective approach ensures thorough detection of critical threats while avoiding the time cost of exhaustive manual analysis of every potential threat.
3Use of energy by moving object
If reactive anti-malware solutions are used, then resource consumption is minimized, but the system cannot prevent harm before it occurs
Solution Approach 1:
The patent performs preliminary automated identification and suspicion level assignment on URLs and domains before they cause harm. By proactively detecting and prioritizing potentially harmful content in advance, the system enables preventive blocking of high-suspicion targets, transitioning from reactive to proactive security while maintaining efficient resource consumption through automated prioritization.
Data Source
AI summary
Methods for identifying potentially harmful, malicious, or unwanted content based upon associations with known offenders are provided. Executable content associated with a domain is identified. The executable content URL and the domain are compared to URLs/domains known to be associated with malicious content. If the URL and/or the domain has been identified as associated with offending code, the remaining domain contents and any available associated information are examined to identify any referencing domains, referenced domains, linking domains, affiliated entities, etc. Each identified domain, affiliate, etc. is subsequently examined in a similar manner to identify any domain, entity, etc. having an association with malicious content. Each identified domain, entity, etc. is assigned a suspicion level based upon proximity to the source of the offending code. If desired, relationships among the domains, entities, and the like may be relationally mapped to render associations easier to identify.


