Scriptable Browser for Detecting Malicious Ad Redirects

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Unscrupulous advertisers inject malicious code into web pages and applications, causing unauthorized redirects that are difficult to detect due to encoding techniques and device-specific targeting, leading to mistrust between users and publishers, and existing detection methods are inadequate.

Innovation Solution

A system utilizing a scriptable browser and controller to analyze web pages for malicious redirects, attributing the source of unauthorized redirects by inspecting content patterns and blocking navigation until explicitly allowed, and isolating ad content to identify and attribute malicious behavior.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If publishers host multiple advertisements from several advertising networks on a single page, then monetization capability is improved, but identification of the specific advertisement responsible for malicious redirects becomes difficult

Engineering Contradiction:
Improvemonetization capabilityVSAvoididentification of malicious advertisement source
Core Design Contradiction:
ProductivityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent segments the web page into multiple frames, with each frame potentially containing content from different advertising networks. By isolating each frame and injecting a scriptable browser into individual frames, the system can independently monitor and attribute redirects to specific advertising sources, resolving the identification problem while maintaining multi-network monetization

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a scriptable browser as an intermediary component within each frame that acts as a mediator between the advertising content and the main page navigation. This intermediary monitors and captures redirect attempts, attributing them to the specific frame (and thus specific advertisement) that initiated them, enabling precise source identification

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-generated harmful factors

If unscrupulous advertisers use encoding techniques and hide malicious code in images or CSS files, then detection difficulty is increased, but advertisement functionality is maintained

Engineering Contradiction:
Improvemalicious redirect capabilityVSAvoidmalware detection difficulty
Core Design Contradiction:
Object-generated harmful factorsVSDifficulty of detecting and measuring

Solution Approach 1:

The patent applies preliminary action by injecting the scriptable browser into frames before the malicious code has a chance to execute its redirect function. The scriptable browser is positioned and configured in advance to intercept navigation attempts, preventing the encoded malicious code from successfully redirecting the user while maintaining the advertisement's display functionality

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces traditional static code inspection methods with a dynamic scriptable browser environment that can execute and monitor JavaScript, CSS, and image-based obfuscated code in real-time. This substitution allows the system to detect malicious behavior regardless of the encoding technique used, as the scriptable browser can interpret and monitor all these formats dynamically

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Measurement precision

If advertisers use device-specific targeting to send malicious code only to specific devices or browsers, then fraud precision is improved, but pre-inspection capability is reduced

Engineering Contradiction:
Improvetargeting precisionVSAvoidpre-inspection capability
Core Design Contradiction:
Measurement precisionVSDifficulty of detecting and measuring

Solution Approach 1:

The patent applies self-service by enabling the scriptable browser to automatically detect and respond to device-specific targeting conditions without requiring external analysis. The scriptable browser monitors the execution environment, identifies when device-specific conditions are met, and automatically intercepts malicious redirects targeted at that specific device configuration, making pre-inspection unnecessary

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11683342B2Detecting and attributing undesirable automatic redirects
Publication Date: 2023.06.20 AD LIGHTNING INC
  • US11683342B2 patent drawing
  • US11683342B2 patent drawing
  • US11683342B2 patent drawing

AI summary

Techniques are described for detecting and attributing automatic unauthorized redirects originating from executable code contained within an advertisement hosted within a web page or application displayed on an end user's mobile or desktop computing devices.