Malicious Content Detection via Domain Association Mapping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current anti-malware solutions are primarily reactive and unable to detect malware in a timely manner, leading to potential hours or days of exposure to harmful content before adequate blocking can be effected, and they fail to identify new malware and malicious websites distributing harmful content in real-time.

Innovation Solution

The system identifies potentially harmful content by examining associations with known offending entities and domains, assigning suspicion levels based on proximity to the source of malicious code, and prioritizing further scrutiny using a relational mapping approach to quickly identify and block malicious content.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual research methods are used to identify harmful content, then detection accuracy can be maintained, but the time required for detection increases significantly

Engineering Contradiction:
Improvedetection accuracyVSAvoiddetection time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent segments the detection process into multiple automated components: collecting URL data from multiple sources, analyzing content against known harmful patterns, examining associations with identified harmful entities, and assigning suspicion levels. This segmentation allows parallel processing of different detection tasks, maintaining accuracy while reducing overall detection time.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent replaces manual research methods with automated computer-implemented processes. The system automatically collects URL data, analyzes content, identifies associations, and prioritizes scrutiny without human intervention, substituting mechanical automation for manual analysis while maintaining or improving detection accuracy through systematic automated procedures.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If comprehensive manual analysis is performed on all potential threats, then detection thoroughness is improved, but productivity decreases due to time consumption

Engineering Contradiction:
Improvedetection thoroughnessVSAvoiddetection speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements preliminary automated analysis that assigns suspicion levels to URLs and domains before comprehensive scrutiny is applied. By pre-processing and prioritizing targets based on initial automated assessment, the system prepares a ranked list of high-probability threats, enabling focused thorough analysis on the most suspicious cases while maintaining overall detection speed.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies partial analysis to all potential threats through automated suspicion level assignment, then applies excessive (comprehensive) analysis only to high-priority targets identified as most suspicious. This selective approach ensures thorough detection of critical threats while avoiding the time cost of exhaustive manual analysis of every potential threat.

Inventive Principle:
Principle #16Partial or excessive action

3Use of energy by moving object

If reactive anti-malware solutions are used, then resource consumption is minimized, but the system cannot prevent harm before it occurs

Engineering Contradiction:
Improveresource consumptionVSAvoidprevention capability
Core Design Contradiction:
Use of energy by moving objectVSReliability

Solution Approach 1:

The patent performs preliminary automated identification and suspicion level assignment on URLs and domains before they cause harm. By proactively detecting and prioritizing potentially harmful content in advance, the system enables preventive blocking of high-suspicion targets, transitioning from reactive to proactive security while maintaining efficient resource consumption through automated prioritization.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8769673B2Identifying potentially offending content using associations
Publication Date: 2014.07.01 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8769673B2 patent drawing
  • US8769673B2 patent drawing
  • US8769673B2 patent drawing

AI summary

Methods for identifying potentially harmful, malicious, or unwanted content based upon associations with known offenders are provided. Executable content associated with a domain is identified. The executable content URL and the domain are compared to URLs/domains known to be associated with malicious content. If the URL and/or the domain has been identified as associated with offending code, the remaining domain contents and any available associated information are examined to identify any referencing domains, referenced domains, linking domains, affiliated entities, etc. Each identified domain, affiliate, etc. is subsequently examined in a similar manner to identify any domain, entity, etc. having an association with malicious content. Each identified domain, entity, etc. is assigned a suspicion level based upon proximity to the source of the offending code. If desired, relationships among the domains, entities, and the like may be relationally mapped to render associations easier to identify.