Infected Website Detection via Redirect-Malware Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional website infection detection techniques fail to effectively identify infected websites, especially those employing conditional redirections, and often produce false positives due to inability to distinguish between intentional and malicious redirects.

Innovation Solution

A method and system for detecting infected websites by analyzing correlation between redirection reports and malware reports, aggregating information, and determining conditions for redirection, which includes sending protection information to security agents and notifying registered contacts, while considering the timing and conditions of redirects.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional website infection detection techniques are used, then the detection process is simple, but the detection accuracy is low and false positives occur

Engineering Contradiction:
Improvedetection accuracyVSAvoiddetection process complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent combines multiple detection data sources (redirect reports, malware reports, correlation analysis) into a unified detection framework. The information aggregation module merges data from different security agents and analysis results to improve detection accuracy while managing complexity through systematic integration.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces an information aggregation module as an intermediary between raw detection reports and final infection detection results. This intermediary processes and correlates multiple data sources, enabling accurate detection without directly handling the complexity of individual report analyses.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If conditional redirection is implemented, then the malicious code can trigger redirects only under specific conditions, but conventional detection techniques cannot reproduce or verify the infection

Engineering Contradiction:
Improveinfection verification reliabilityVSAvoidconditional redirection detection difficulty
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements feedback mechanisms where security agents report redirection events and malware detections back to the detection system. The information aggregation module uses this feedback to correlate conditional redirection patterns with malware reports, enabling verification of infections that would otherwise be difficult to reproduce.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent performs preliminary correlation analysis on redirection and malware reports before final detection. By pre-processing and aggregating information from multiple sources, the system prepares detection data in advance, making it possible to verify conditional infections without requiring reproduction of the exact triggering conditions.

Inventive Principle:
Principle #10Preliminary action

3Object-affected harmful factors

If redirection protection information is sent to security agents, then user protection is improved, but network communication overhead increases

Engineering Contradiction:
Improvemalicious redirect protectionVSAvoidnetwork communication overhead
Core Design Contradiction:
Object-affected harmful factorsVSLoss of energy

Solution Approach 1:

The patent extracts only the essential redirection protection information needed by security agents, rather than transmitting complete detection datasets. The information aggregation module identifies and sends only the critical protection rules and correlated findings, reducing network overhead while maintaining effective protection.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS8997228B1Techniques for detecting infected websites
Publication Date: 2015.03.31 CA TECH INC
  • US8997228B1 patent drawing
  • US8997228B1 patent drawing
  • US8997228B1 patent drawing

AI summary

Techniques for detecting infected websites are disclosed. In one particular embodiment, the techniques may be realized as a method for detecting an infected website comprising receiving at least one redirection report from at least one security agent, receiving at least one malware report from the at least one security agent, analyzing correlation between the at least one redirection report and the at least one malware report, aggregating information from the at least one redirection report, the at least one malware report, and the correlation analysis, and detecting an infected website based on the aggregated information.