Reputation Index for Internet Resource Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current solutions fail to predictively assess the security risk of Internet resources before infections occur, allowing attackers to compromise legitimate sites and bypass reputation-based systems, leading to data-stealing attacks and spamming issues.
Innovation Solution
A statistical model is developed to generate a reputation index for Internet resources based on various factors, including domain registration age, behavior, and associations, using a Maximum Entropy Discrimination classifier to evaluate and predict potential risks, allowing for real-time access control decisions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If content filtering is used to manage internet access, then visibility into employee time usage and network bandwidth usage is improved, but security risk prediction capability deteriorates
Solution Approach 1:
The patent segments the security assessment into multiple independent reputation factors (domain age, SSL certificate validity, HTTP security headers, content analysis, etc.) that can be evaluated separately and combined to form an overall security score, enabling both content filtering and security risk prediction to function simultaneously
Solution Approach 2:
The patent introduces a reputation scoring system as an intermediary layer between content filtering and security assessment. This intermediary evaluates multiple factors and generates a composite security reputation score that enhances security risk prediction without interfering with content filtering operations
2Measurement precision
If anti-virus products examine file or Web page content, then known security threats are detected, but predictive security assessment before infections occur deteriorates
Solution Approach 1:
The patent performs preliminary security assessments by evaluating reputation factors (domain registration age, SSL certificate status, HTTP security headers) before content is downloaded or executed. This preliminary action detects potential threats based on security configurations and reputation metrics before infections can occur or be confirmed
Solution Approach 2:
The patent transitions from traditional single-dimension antivirus scanning to a multi-dimensional security assessment that evaluates domain reputation, SSL certificates, HTTP headers, content analysis, and behavioral patterns simultaneously, enabling predictive security assessment across multiple dimensions
3Reliability
If reputation-based systems are used to block malicious sites, then security protection is improved, but attackers can bypass by compromising legitimate sites deteriorates
Solution Approach 1:
The patent changes the parameters used for reputation assessment from simple black/white lists to multi-factor evaluation including domain age, SSL certificate validity, HTTP security headers, content security policies, and behavioral analysis. This parameter expansion makes it harder for attackers to bypass by compromising legitimate sites, as the system evaluates multiple security dimensions rather than relying on simple reputation labels
Data Source
AI summary
A method and system for controlling access to an Internet resource is disclosed herein. When a request for an Internet resource, such as a Web site, is transmitted by an end-user of a LAN, a security appliance for the LAN analyzes a reputation index for the Internet resource before transmitting the request over the Internet. The reputation index is based on a reputation vector which includes a plurality of factors for the Internet resource such as country of domain registration, country of service hosting, country of an internet protocol address block, age of a domain registration, popularity rank, internet protocol address, number of hosts, to-level domain, a plurality of run-time behaviors, JavaScript block count, picture count, immediate redirect and response latency. If the reputation index for the Internet resource is at or above a threshold value established for the LAN, then access to the Internet resource is permitted. If the reputation index for the Internet resource is below a threshold value established for the LAN, then access to the Internet resource is denied.


