Infected Website Detection via Redirect-Malware Correlation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional website infection detection techniques fail to effectively identify infected websites, especially those employing conditional redirections, and often produce false positives due to inability to distinguish between intentional and malicious redirects.
Innovation Solution
A method and system for detecting infected websites by analyzing correlation between redirection reports and malware reports, aggregating information, and determining conditions for redirection, which includes sending protection information to security agents and notifying registered contacts, while considering the timing and conditions of redirects.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If conventional website infection detection techniques are used, then the detection process is simple, but the detection accuracy is low and false positives occur
Solution Approach 1:
The patent combines multiple detection data sources (redirect reports, malware reports, correlation analysis) into a unified detection framework. The information aggregation module merges data from different security agents and analysis results to improve detection accuracy while managing complexity through systematic integration.
Solution Approach 2:
The patent introduces an information aggregation module as an intermediary between raw detection reports and final infection detection results. This intermediary processes and correlates multiple data sources, enabling accurate detection without directly handling the complexity of individual report analyses.
2Reliability
If conditional redirection is implemented, then the malicious code can trigger redirects only under specific conditions, but conventional detection techniques cannot reproduce or verify the infection
Solution Approach 1:
The patent implements feedback mechanisms where security agents report redirection events and malware detections back to the detection system. The information aggregation module uses this feedback to correlate conditional redirection patterns with malware reports, enabling verification of infections that would otherwise be difficult to reproduce.
Solution Approach 2:
The patent performs preliminary correlation analysis on redirection and malware reports before final detection. By pre-processing and aggregating information from multiple sources, the system prepares detection data in advance, making it possible to verify conditional infections without requiring reproduction of the exact triggering conditions.
3Object-affected harmful factors
If redirection protection information is sent to security agents, then user protection is improved, but network communication overhead increases
Solution Approach 1:
The patent extracts only the essential redirection protection information needed by security agents, rather than transmitting complete detection datasets. The information aggregation module identifies and sends only the critical protection rules and correlated findings, reducing network overhead while maintaining effective protection.
Data Source
AI summary
Techniques for detecting infected websites are disclosed. In one particular embodiment, the techniques may be realized as a method for detecting an infected website comprising receiving at least one redirection report from at least one security agent, receiving at least one malware report from the at least one security agent, analyzing correlation between the at least one redirection report and the at least one malware report, aggregating information from the at least one redirection report, the at least one malware report, and the correlation analysis, and detecting an infected website based on the aggregated information.


