Bottom-up Network Site Analysis for Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for identifying malicious network sites are time-consuming and struggle to keep pace with the evolving threats in a network environment, as they typically involve accessing sites and following links, which may not efficiently detect diverse and rapidly changing threats.

Innovation Solution

A bottom-up analysis approach using malware analysis modules to identify distribution sites hosting malicious content, a linking analysis module to determine linked landing sites, and a landing site classification system that trains a model to assess unknown sites based on property and safety-related information, enabling timely identification of suspect sites.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If a top-down analysis approach is used to investigate site safety by accessing sites and following links, then comprehensive threat detection is achieved, but the analysis time becomes too long to keep pace with evolving threats

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent inverts the traditional top-down analysis approach by implementing a bottom-up analysis method. Instead of starting from user-accessed landing sites and following links downward, the system starts from known malicious distribution sites and traces upward through linking relationships to identify suspect landing sites. This inversion dramatically reduces analysis time while maintaining detection accuracy by leveraging known malicious site information as the starting point.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The system performs preliminary analysis by pre-identifying and storing information about malicious distribution sites before they are accessed by users. By maintaining an updated database of known malicious sites and their linking relationships, the system can quickly assess new sites without performing complete top-down analysis each time, thus reducing analysis time while preserving detection capability.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If traditional site analysis methods are used, then thorough investigation of linked resources is performed, but the process cannot keep abreast of rapidly changing threats

Engineering Contradiction:
Improvethreat detection reliabilityVSAvoidthreat response speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent reverses the analysis direction to improve productivity. By starting from confirmed malicious distribution sites and tracing upward through hyperlink relationships, the system可以快速 identify suspect landing sites without needing to perform exhaustive top-down analysis of all possible links, thus increasing threat response speed while maintaining reliable detection.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The system implements feedback mechanisms where analysis results from identified suspect sites are fed back into the database of known malicious sites. This creates a learning loop that continuously improves the system's ability to detect threats, enhancing both reliability and productivity over time as the database grows and is refined through continuous analysis feedback.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8161130B2Bottom-up analysis of network sites
Publication Date: 2012.04.17 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8161130B2 patent drawing
  • US8161130B2 patent drawing
  • US8161130B2 patent drawing

AI summary

An approach for identifying suspect network sites in a network environment entails using one or more malware analysis modules to identify distribution sites that host malicious content and/or benign content. The approach then uses a linking analysis module to identify landing sites that are linked to the distribution sites. These linked sites are identified as suspect sites for further analysis. This analysis can be characterized as “bottom up” because it is initiated by the detection of potentially problematic distribution sites. The approach can also perform linking analysis to identify a suspect network site based on a number of alternating paths between that network site and a set of distribution sites that are known to host malicious content. The approach can also train a classifier module to predict whether an unknown landing site is a malicious landing site or a benign landing site.