URL Selection Method for Malicious URL Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing URL selection systems face detection omission of malicious URLs due to limitations in processing capacity and variability in detection accuracy across different analysis techniques, leading to impaired diversity in technique usage and increased erroneous detection rates.
Innovation Solution
A URL selection method that extracts URLs up to a predetermined number from each group based on priority, with a secondary extraction step to fill the total number, ensuring the maximum allowable number is reached while maintaining priority order, thereby generating a comprehensive and accurate malicious URL list.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If all malicious URLs found by analysis techniques are imported to the security appliance, then detection accuracy is improved, but processing performance exceeds the upper limit value
Solution Approach 1:
The patent extracts only the necessary subset of malicious URLs from the complete set found by analysis techniques. The URL list generation unit selectively imports URLs into the security appliance based on priority rankings and upper limit values, rather than importing all detected URLs. This extraction approach maintains detection accuracy by including the most critical URLs while respecting processing performance constraints.
Solution Approach 2:
The patent changes the parameter of URL quantity from 'all detected URLs' to 'optimized subset of URLs'. By introducing priority values and upper limit values as controlling parameters, the system transforms the URL list from a complete but unmanageable set into a optimized subset that balances detection accuracy with processing performance capabilities.
2Measurement precision
If priority-based extraction from multiple analysis techniques is used, then detection accuracy is improved, but diversity in technique usage is impaired
Solution Approach 1:
The patent segments the URL extraction process into two distinct steps: first extracting URLs up to technique-specific upper limit values, then performing secondary extraction to fill remaining capacity. This segmentation allows each analysis technique to contribute its findings while maintaining overall diversity, as the secondary extraction step ensures that capacity is fully utilized across multiple techniques rather than being dominated by a single high-priority technique.
Solution Approach 2:
The patent applies partial action by extracting only the necessary portion of URLs from each technique (up to upper limit values) rather than using all URLs from all techniques equally. The secondary extraction step then supplements this partial extraction to reach the optimal total number, ensuring both priority-based selection and diverse technique utilization without excessive processing.
3Measurement precision
If the latest found URL is written to the URL list, then detection accuracy is improved, but erroneous detection rate increases
Solution Approach 1:
The patent performs preliminary ranking of URLs by priority value before they are imported to the security appliance. By pre-ordering URLs based on their priority scores from multiple analysis techniques, the system ensures that the most reliable detections are processed first. This preliminary action prevents hasty importation of potentially erroneous latest URLs while maintaining detection accuracy through systematic priority-based selection.
Data Source
AI summary
A URL selection method disclosed in the present application includes a first extraction step and a second extraction step. The first extraction step extracts URLs up to an upper limit value of the number of URLs set to each of URL groups in a range where a total number of URLs is within a predetermined number of URLs, in order of priority set to each of the URL groups, from each of the URL groups identified by analyzing a traffic log by techniques in different categories. The second extraction step further extracts URLs within the predetermined number of URLs, based on the priority, when the total number of URLs extracted from each of the URL groups in the first extraction step is less than the predetermined number of URLs.


