Referral URL Fraud Detection via Pre-loaded Malicious Database

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Malicious or counterfeit websites redirect users to legitimate sites to deceive them, making it difficult for users to recognize online scams, and existing technologies lack effective methods to detect and block such redirects in real-time.

Innovation Solution

A browser extension and counterfeit URL detection system that analyzes referral URLs, uses machine learning to assess the authenticity of URLs, and blocks access to counterfeit websites, while also tracking user behavior and initiating corrective actions such as fraud notifications and login credential changes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If referral URLs are logged and analyzed to detect fraudulent websites, then user protection against online scams is improved, but system complexity and processing requirements increase

Engineering Contradiction:
Improveuser protection against online scamsVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system pre-loads and stores known fraudulent URLs in a data structure before they are encountered during user browsing. When a referral URL is received, the system performs a quick lookup against this pre-populated database of malicious URLs, avoiding the need for complex real-time analysis of each URL. This preliminary preparation of fraud data enables fast detection while keeping the runtime system simple.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary component (fraud detection system/module) that sits between the web browser and the fraudulent websites. This intermediary intercepts referral URLs, checks them against the stored fraudulent URL database, and blocks access to malicious sites. By placing this intermediary layer, the system simplifies the detection process while effectively protecting users without requiring complex modifications to the browser or website infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Speed

If real-time analysis of referral URLs is performed to block counterfeit websites, then detection speed is improved, but computational resources and processing time are increased

Engineering Contradiction:
Improvedetection speedVSAvoidcomputational resources
Core Design Contradiction:
SpeedVSUse of energy by moving object

Solution Approach 1:

The system performs the computationally intensive task of identifying and storing fraudulent URLs in advance, creating a ready-to-use database of malicious URLs. During real-time operation, the system only performs simple string matching or hashing comparisons against this pre-processed database, which requires minimal computational resources. This separation of heavy preprocessing from light real-time checking enables fast detection with low energy consumption.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent employs efficient, lightweight data structures for storing and comparing URLs, such as hash sets or trie structures, that enable O(1) or O(log n) lookup time. These optimized data structures use minimal memory and processing power, allowing the system to perform rapid URL matching without requiring substantial computational resources. The system prioritizes using cheap, efficient algorithms over complex, resource-intensive approaches.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS12041084B2Systems and methods for determining user intent at a website and responding to the user intent
Publication Date: 2024.07.16 BOLSTER INC
  • US12041084B2 patent drawing
  • US12041084B2 patent drawing
  • US12041084B2 patent drawing

AI summary

Methods for determining user intent at a website and responding to it include using one or more processors to fetch a referral URL, associated with a prior website, from one or more web server logs associated with a web server. The referral URL is provided to the web server in conjunction with a user navigating from the prior website to a current website using a browser. The processor(s) determine whether the prior website is fraudulent based at least in part on determining whether the referral URL matches a URL in one or more data stores and/or receiving an indication from a machine learning (ML) engine indicating whether the prior website is fraudulent. If prior website is not fraudulent, the processor(s) process one or more user requests at the current website. If the prior website is fraudulent the processor(s) block the user request(s). Related systems are configured to implement the methods.