Selective Website Vulnerability Testing via Traffic-Aware Pacing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional website security testing methods generate significant traffic and bandwidth usage, leading to server overload and performance degradation, especially in shared hosting environments where small websites are hosted, making it challenging to achieve timely and high-confidence integrity and security testing without impacting website availability.
Innovation Solution
A method for selective website vulnerability and infection testing based on expected site traffic volume and hosting configuration, which includes pacing website vulnerability and infection testing, selecting between higher and lower bandwidth-consuming test procedures, and prioritizing website pages for testing based on factors like malware likelihood and historical data to minimize bandwidth demand and ensure website availability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional website security testing methods are used to generate tens of thousands of page requests, then comprehensive security testing coverage is achieved, but server bandwidth is overloaded and website performance degrades
Solution Approach 1:
The patent segments the website testing process into multiple phases: initial comprehensive testing, followed by incremental testing of newly added pages, and selective re-testing based on risk factors. This segmentation allows security testing to be distributed over time rather than concentrated in a single high-bandwidth event, thereby maintaining website performance while achieving comprehensive coverage.
Solution Approach 2:
The patent implements periodic security testing where the website is tested at scheduled intervals rather than continuously. Between periodic tests, only newly added or modified pages are tested. This periodic approach reduces overall bandwidth consumption while maintaining security coverage through strategic timing of comprehensive tests.
2Reliability
If frequent comprehensive security testing is performed, then security reliability is improved, but server resources are consumed and availability decreases
Solution Approach 1:
The patent applies partial action by testing only the necessary portion of the website at any given time. Instead of re-testing the entire website frequently, it tests only newly added pages and selectively re-tests pages based on risk factors. This partial approach maintains security reliability while minimizing server resource consumption and preserving availability.
Solution Approach 2:
The patent changes the testing parameters dynamically based on website characteristics such as size, traffic volume, and risk profile. For high-traffic websites, testing frequency and intensity are adjusted to balance security needs with availability requirements. This parameter adaptation allows frequent security monitoring without consistently overloading server resources.
3Reliability
If all website pages are tested for vulnerabilities, then complete security coverage is achieved, but bandwidth consumption increases significantly
Solution Approach 1:
The patent performs preliminary risk assessment and categorization of website pages before conducting vulnerability testing. Pages are prioritized based on factors such as traffic volume, sensitivity of content, and historical security issues. This preliminary action allows the system to focus bandwidth on high-risk pages while maintaining complete security coverage through systematic prioritization.
Solution Approach 2:
The patent implements partial testing by focusing vulnerability scans on high-risk pages identified through preliminary assessment, rather than uniformly testing all pages. This selective approach achieves effective security coverage by concentrating resources on pages most likely to contain vulnerabilities, thereby reducing overall bandwidth consumption while maintaining security effectiveness.
Data Source
AI summary
In embodiments of the present invention improved capabilities are described for selective website vulnerability and infection testing and intelligently paced rigorous direct website testing. By providing robust website content integrity checking while only lightly loading the website hosting server, visitor bandwidth availability is maintained through selective testing and intelligently paced external website exercising. A modular pod-based computing architecture of interconnected severs configured with a sharded database facilitates selective website testing and intelligent direct website test pacing while providing scalability to support large numbers of website testing subscribers.


