Bottom-up Network Site Analysis for Threat Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for identifying malicious network sites are time-consuming and struggle to keep pace with the evolving threats in a network environment, as they typically involve accessing sites and following links, which may not efficiently detect diverse and rapidly changing threats.
Innovation Solution
A bottom-up analysis approach using malware analysis modules to identify distribution sites hosting malicious content, a linking analysis module to determine linked landing sites, and a landing site classification system that trains a model to assess unknown sites based on property and safety-related information, enabling timely identification of suspect sites.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If a top-down analysis approach is used to investigate site safety by accessing sites and following links, then comprehensive threat detection is achieved, but the analysis time becomes too long to keep pace with evolving threats
Solution Approach 1:
The patent inverts the traditional top-down analysis approach by implementing a bottom-up analysis method. Instead of starting from user-accessed landing sites and following links downward, the system starts from known malicious distribution sites and traces upward through linking relationships to identify suspect landing sites. This inversion dramatically reduces analysis time while maintaining detection accuracy by leveraging known malicious site information as the starting point.
Solution Approach 2:
The system performs preliminary analysis by pre-identifying and storing information about malicious distribution sites before they are accessed by users. By maintaining an updated database of known malicious sites and their linking relationships, the system can quickly assess new sites without performing complete top-down analysis each time, thus reducing analysis time while preserving detection capability.
2Reliability
If traditional site analysis methods are used, then thorough investigation of linked resources is performed, but the process cannot keep abreast of rapidly changing threats
Solution Approach 1:
The patent reverses the analysis direction to improve productivity. By starting from confirmed malicious distribution sites and tracing upward through hyperlink relationships, the system可以快速 identify suspect landing sites without needing to perform exhaustive top-down analysis of all possible links, thus increasing threat response speed while maintaining reliable detection.
Solution Approach 2:
The system implements feedback mechanisms where analysis results from identified suspect sites are fed back into the database of known malicious sites. This creates a learning loop that continuously improves the system's ability to detect threats, enhancing both reliability and productivity over time as the database grows and is refined through continuous analysis feedback.
Data Source
AI summary
An approach for identifying suspect network sites in a network environment entails using one or more malware analysis modules to identify distribution sites that host malicious content and/or benign content. The approach then uses a linking analysis module to identify landing sites that are linked to the distribution sites. These linked sites are identified as suspect sites for further analysis. This analysis can be characterized as “bottom up” because it is initiated by the detection of potentially problematic distribution sites. The approach can also perform linking analysis to identify a suspect network site based on a number of alternating paths between that network site and a set of distribution sites that are known to host malicious content. The approach can also train a classifier module to predict whether an unknown landing site is a malicious landing site or a benign landing site.


