URL Reputation Rating System for Malicious Site Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional computing-security technologies struggle to detect malicious websites due to their inability to quickly and correctly create digital signatures for the numerous variations of new websites and content generated daily by malware developers, and whitelisting methods face challenges in manually creating comprehensive lists and accurately identifying legitimate websites.

Innovation Solution

A reputation-based rating system for URLs that evaluates potential security risk by considering the computing health of users who accessed the URL, along with other factors such as the URL's age, domain reputation, and server reliability, to generate accurate reputation ratings for URLs, which can be used to verify trustworthiness classifications and block malicious access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If blacklisting technologies are used to detect malicious websites by scanning and creating digital signatures, then detection capability is provided, but the system fails to keep up with the rapid generation of new website variations by malware developers

Engineering Contradiction:
Improvemalware detection capabilityVSAvoidspeed of creating digital signatures
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary actions by establishing a reputation baseline for URLs before malware developers can create new variations. By continuously monitoring and updating reputation scores based on historical access patterns and user behavior, the system prepares detection mechanisms in advance, allowing rapid response to new malicious sites without needing to create digital signatures from scratch.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms where access patterns, user reports, and security events continuously update URL reputation scores. This feedback loop enables the system to adapt to new malware variations in real-time, adjusting detection criteria dynamically rather than relying on static digital signatures that cannot keep pace with rapid site generation.

Inventive Principle:
Principle #23Feedback

2Measurement precision

If manual whitelisting methods are used to create comprehensive website lists, then accuracy in identifying legitimate sites is improved, but the process becomes time-consuming and cannot keep up with the high number of new websites created daily

Engineering Contradiction:
Improveaccuracy of legitimate site identificationVSAvoidtime required to create comprehensive whitelist
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system enables self-service by allowing URLs to build their own reputation scores automatically based on access patterns and user behavior. Rather than requiring manual verification for each site, the system autonomously evaluates legitimacy through aggregated data from multiple users, dramatically reducing the time needed to maintain comprehensive whitelists while preserving accuracy.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The reputation system operates continuously, constantly updating URL scores based on ongoing access patterns. This continuous action ensures the whitelist remains comprehensive and accurate without requiring periodic manual updates, as the system automatically adapts to new legitimate sites as they are created daily.

Inventive Principle:
Principle #20Continuity of useful action

3Productivity

If automatic whitelisting techniques are used to identify websites, then the process becomes faster, but the system becomes prone to falsely identifying illegitimate websites as legitimate and vice-versa

Engineering Contradiction:
Improvespeed of whitelist creationVSAvoidaccuracy of site classification
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system applies local quality by evaluating each URL's reputation independently based on its specific access patterns and user interactions, rather than applying uniform automatic classification rules. This localized evaluation allows the system to distinguish between legitimate and illegitimate sites more accurately while maintaining high processing speed through parallel reputation calculations.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system changes parameters dynamically by adjusting reputation thresholds and weighting factors based on current security conditions and user behavior patterns. This parameter adaptation allows the system to maintain high productivity in automatic classification while improving reliability by adjusting detection criteria to reduce false positives and false negatives.

Inventive Principle:
Principle #35Parameter changes

4Measurement precision

If conventional security technologies scan website contents statically, then analysis depth is provided, but the system cannot quickly respond to new website variations generated daily by malware developers

Engineering Contradiction:
Improvedepth of website analysisVSAvoidresponse speed to new websites
Core Design Contradiction:
Measurement precisionVSSpeed

Solution Approach 1:

The system performs preliminary reputation assessment actions continuously, maintaining updated reputation scores for URLs before malware developers can deploy new variations. By pre-establishing reputation baselines and monitoring patterns in advance, the system enables rapid response to new malicious sites without needing to perform deep static scanning at the moment of detection.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system transitions from static content scanning to dynamic reputation evaluation that adapts to changing website patterns. By continuously updating reputation scores based on real-time access patterns and user behavior, the system maintains both analysis depth and rapid response capability, adjusting its evaluation approach dynamically rather than relying on fixed scanning methods.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8826426B1Systems and methods for generating reputation-based ratings for uniform resource locators
Publication Date: 2014.09.02 CA TECH INC
  • US8826426B1 patent drawing
  • US8826426B1 patent drawing
  • US8826426B1 patent drawing

AI summary

An exemplary computer-implemented method for generating reputation ratings for URLs may include (1) identifying a URL that identifies the location of at least one web resource, (2) identifying the computing health of at least one member of a computing community that has accessed the URL, (3) generating, based at least in part on the computing health of the member(s) that accessed the URL, a reputation rating for the URL that indicates whether the URL represents a potential security risk, and then (4) providing the reputation rating for the URL to at least one additional computing device to enable the additional computing device to evaluate whether the URL represents a potential security risk. In addition, a client-side, computer-implemented method for determining whether a URL represents a potential security risk may be based at least in part on such a reputation rating. Various other methods, systems, and computer-readable media are also disclosed.