Automated Malicious Web Page Discovery System
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for identifying and managing malicious web pages are inefficient due to reliance on human intervention, leading to unchecked suspicious URLs, incomplete database updates, and resource constraints, resulting in ineffective virus pattern detection and protection.
Innovation Solution
An active malicious web page monitoring system comprising a web monitor module, crawler module, and malicious page identifier (MPI) that automates the monitoring, downloading, and verification of potential suspicious URLs, minimizing human intervention and enabling timely analysis and database maintenance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual analysis by engineers is used to identify suspicious web pages, then analysis accuracy can be maintained, but productivity is severely limited and time loss increases
Solution Approach 1:
The patent introduces an automated analysis system that acts as an intermediary between the suspicious URL lists and the engineers. This system automatically downloads, scans, and analyzes web pages using anti-virus programs and heuristics, filtering results before presenting them to engineers for final verification. This intermediary automation handles the bulk analysis work while engineers focus on complex cases, resolving the contradiction between maintaining accuracy and increasing productivity.
Solution Approach 2:
The patent replaces the mechanical manual analysis process with an automated electronic system. The automated system uses software-based scanning, pattern recognition, and heuristics to analyze web pages, replacing the need for engineers to manually examine each URL. This substitution dramatically increases analysis throughput while maintaining quality through multiple verification layers.
2Reliability
If engineers dedicate resources to reviewing potential suspicious URLs, then detection capability is maintained, but database maintenance becomes neglected and complexity increases
Solution Approach 1:
The patent divides the overall security system into distinct functional modules: an automated analysis module that handles URL scanning and classification, a database management module that maintains the suspicious URL lists and results, and an engineer review module that handles complex cases. This segmentation allows each component to specialize in its function, improving detection capability while managing system complexity through modular design.
Solution Approach 2:
The automated analysis system performs self-service by automatically downloading web pages, scanning them with anti-virus programs, applying heuristics, and classifying results without requiring engineer intervention for each URL. This self-automated process maintains reliable detection capability while freeing engineers from routine tasks, allowing the system to manage its own operational workload.
3Adaptability or versatility
If the scope of analysis is expanded to cover more URLs, then protection coverage improves, but resource consumption increases and productivity decreases
Solution Approach 1:
The patent implements a multi-tiered analysis approach where not all URLs receive the same level of scrutiny. The system applies quick heuristic scans to all URLs (partial action), performs full anti-virus scanning only on suspicious URLs (excessive action on specific targets), and reserves engineer review for the most critical cases. This differentiated approach expands protection coverage to all URLs while maintaining productivity by avoiding excessive resource consumption on clearly safe URLs.
Data Source
AI summary
An arrangement for performing active malicious web page discovery is provided. The arrangement includes a web monitor module, which is configured to monitor a plurality of potential suspicious unified resource locators (URLs). The arrangement also includes a crawler module, which is configured to download the plurality of potential suspicious URLs. The arrangement further includes a malicious page identifier (MPI), which is configured to verify a set of risk statuses for the plurality of potential suspicious URLs.


