Automated Malicious Web Page Discovery System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for identifying and managing malicious web pages are inefficient due to reliance on human intervention, leading to unchecked suspicious URLs, incomplete database updates, and resource constraints, resulting in ineffective virus pattern detection and protection.

Innovation Solution

An active malicious web page monitoring system comprising a web monitor module, crawler module, and malicious page identifier (MPI) that automates the monitoring, downloading, and verification of potential suspicious URLs, minimizing human intervention and enabling timely analysis and database maintenance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual analysis by engineers is used to identify suspicious web pages, then analysis accuracy can be maintained, but productivity is severely limited and time loss increases

Engineering Contradiction:
Improveanalysis accuracyVSAvoidanalysis throughput
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent introduces an automated analysis system that acts as an intermediary between the suspicious URL lists and the engineers. This system automatically downloads, scans, and analyzes web pages using anti-virus programs and heuristics, filtering results before presenting them to engineers for final verification. This intermediary automation handles the bulk analysis work while engineers focus on complex cases, resolving the contradiction between maintaining accuracy and increasing productivity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical manual analysis process with an automated electronic system. The automated system uses software-based scanning, pattern recognition, and heuristics to analyze web pages, replacing the need for engineers to manually examine each URL. This substitution dramatically increases analysis throughput while maintaining quality through multiple verification layers.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If engineers dedicate resources to reviewing potential suspicious URLs, then detection capability is maintained, but database maintenance becomes neglected and complexity increases

Engineering Contradiction:
Improvedetection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the overall security system into distinct functional modules: an automated analysis module that handles URL scanning and classification, a database management module that maintains the suspicious URL lists and results, and an engineer review module that handles complex cases. This segmentation allows each component to specialize in its function, improving detection capability while managing system complexity through modular design.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The automated analysis system performs self-service by automatically downloading web pages, scanning them with anti-virus programs, applying heuristics, and classifying results without requiring engineer intervention for each URL. This self-automated process maintains reliable detection capability while freeing engineers from routine tasks, allowing the system to manage its own operational workload.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If the scope of analysis is expanded to cover more URLs, then protection coverage improves, but resource consumption increases and productivity decreases

Engineering Contradiction:
Improveprotection coverageVSAvoidanalysis efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent implements a multi-tiered analysis approach where not all URLs receive the same level of scrutiny. The system applies quick heuristic scans to all URLs (partial action), performs full anti-virus scanning only on suspicious URLs (excessive action on specific targets), and reserves engineer review for the most critical cases. This differentiated approach expands protection coverage to all URLs while maintaining productivity by avoiding excessive resource consumption on clearly safe URLs.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS7865953B1Methods and arrangement for active malicious web pages discovery
Publication Date: 2011.01.04 TREND MICRO INC
  • US7865953B1 patent drawing
  • US7865953B1 patent drawing
  • US7865953B1 patent drawing

AI summary

An arrangement for performing active malicious web page discovery is provided. The arrangement includes a web monitor module, which is configured to monitor a plurality of potential suspicious unified resource locators (URLs). The arrangement also includes a crawler module, which is configured to download the plurality of potential suspicious URLs. The arrangement further includes a malicious page identifier (MPI), which is configured to verify a set of risk statuses for the plurality of potential suspicious URLs.