Web Analyzer Engine for Automated URL and File Threat Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing IT environments face inefficiencies and inconsistencies in analyzing security threats, particularly due to time-consuming manual processes and ad hoc methods that can lead to improper or missed threat analysis, especially with evolving and sophisticated attack methods.

Innovation Solution

A software-based threat analysis platform with dedicated engines that automate various security analysis actions, including navigating URLs, analyzing documents and files, and emulating embedded code, providing automated interfaces and APIs for efficient and accurate threat investigation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual security threat analysis processes are used, then security analysts can investigate threats, but the analysis is time-consuming and inconsistent leading to improper or missed threat detection

Engineering Contradiction:
Improvethreat analysis accuracyVSAvoidthreat analysis time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the manual threat analysis process into distinct automated components: URL analysis engine, file analysis engine, and interactive interface element analysis engine. Each engine handles specific aspects of threat analysis independently, enabling parallel processing and reducing overall analysis time while maintaining comprehensive coverage through specialized analysis modules.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements self-service through automated analysis engines that independently execute threat detection without continuous human intervention. The engines automatically navigate URLs, analyze files, interact with web pages, and generate risk scores, allowing the system to serve its own threat analysis needs while reducing dependency on manual analyst labor.

Inventive Principle:
Principle #25Self-service

2Productivity

If automated analysis engines are implemented, then threat analysis efficiency improves, but system complexity increases

Engineering Contradiction:
Improvethreat analysis throughputVSAvoidanalysis platform complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The complex automated analysis platform is divided into separate, modular engines: URL analysis engine for web resource analysis, file analysis engine for document and executable analysis, and interactive interface element analysis engine for dynamic content analysis. This segmentation manages system complexity by creating independent, maintainable components while enabling high throughput through parallel operation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The analysis platform implements multi-functional engines that can handle multiple types of threats and file formats within single components. The file analysis engine, for example, can analyze documents, executables, and other file types using unified processing logic, reducing overall system complexity while maintaining versatile threat detection capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If comprehensive threat analysis is performed on all interactive interface elements, then security detection coverage improves, but analysis time increases

Engineering Contradiction:
Improvethreat detection coverageVSAvoidinteractive element analysis time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The interactive interface element analysis engine implements partial action by prioritizing analysis of high-risk interface elements while performing simplified analysis on lower-risk elements. The engine identifies and focuses computational resources on critical interactive elements that pose greater security risks, achieving adequate coverage without analyzing every element in exhaustive detail, thus reducing overall analysis time while maintaining effective threat detection.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20260058988A1Web analyzer engine for identifying security-related threats
Publication Date: 2026.02.26 CISCO TECHNOLOGY INC
  • US20260058988A1 patent drawing
  • US20260058988A1 patent drawing
  • US20260058988A1 patent drawing

AI summary

Techniques are described for providing a threat analysis platform capable of automating actions performed to analyze security-related threats affecting IT environments. Users or applications can submit objects (e.g., URLs, files, etc.) for analysis by the threat analysis platform. Once submitted, the threat analysis platform routes the objects to dedicated engines that can perform static and dynamic analysis processes to determine a likelihood that an object is associated with malicious activity such as phishing attacks, malware, or other types of security threats. The automated actions performed by the threat analysis platform can include, for example, navigating to submitted URLs and recording activity related to accessing the corresponding resource, analyzing files and documents by extracting text and metadata, extracting and emulating execution of embedded macro source code, performing optical character recognition (OCR) and other types of image analysis, submitting objects to third-party security services for analysis, among many other possible actions.