Web Asset Malware Detection via Continuous Monitoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
As web-based applications grow in popularity, there is an increasing need to ensure hosted web assets are trustworthy and tamper-free, as cybercriminals can use trusted assets to mount attacks, potentially affecting large user communities and damaging brand reputation, necessitating automatic scanning and proactive mitigation against malware attacks.
Innovation Solution
A system and method for actively identifying and mitigating malware attacks on hosted web assets through continuous monitoring and analysis, using a Web asset assessment engine, threat detection engine, threat summary and reporting engine, and protection policy application engine, which automatically creates and applies security policies to prevent threats without human intervention, utilizing communication protocols to protect users and applications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional security scanning methods are used, then detection capability is provided, but response time is delayed and human intervention is required
Solution Approach 1:
The system performs preliminary security assessment of web assets before they are compromised. By continuously monitoring and evaluating web assets in advance, the system detects tampering early and automatically responds without waiting for traditional security scanning, thus reducing response time while maintaining detection capability
Solution Approach 2:
The system implements automated self-service security protection by using the web asset assessment engine and threat detection engine to autonomously identify, assess, and respond to threats without human intervention. The automatic policy application engine executes mitigation actions independently, eliminating delays associated with manual security operations
2Measurement precision
If comprehensive security scanning of all web assets is implemented, then threat detection accuracy is improved, but system complexity increases
Solution Approach 1:
The system segments the security assessment process into distinct functional modules: web asset assessment engine for initial evaluation, threat detection engine for malicious content identification, and automatic policy application engine for response actions. This segmentation maintains comprehensive scanning capability while organizing system complexity into manageable, specialized components
Solution Approach 2:
The web asset assessment engine serves as an intermediary that preprocesses and evaluates web assets before they reach the threat detection engine. This intermediary layer filters and prepares data, enabling the threat detection engine to focus on identifying malicious content with high accuracy without being overwhelmed by the complexity of analyzing all raw web asset data
3Productivity
If automated threat mitigation is implemented, then response speed is improved, but potential false positives increase
Solution Approach 1:
The system implements feedback mechanisms where the threat detection engine continuously monitors the effectiveness of automated mitigation actions. By analyzing the outcomes of policy applications and comparing detected threats against known patterns, the system refines its detection algorithms to reduce false positives while maintaining rapid automated response capability
Solution Approach 2:
The web asset assessment engine performs preliminary evaluation and scoring of web assets before threats are fully developed. By identifying suspicious patterns early in the asset lifecycle, the system can apply targeted mitigation policies with higher confidence, reducing false positives while maintaining fast automated response
Data Source
AI summary
A new approach is proposed that contemplates systems and methods to provide identification and mitigation of malware attack via Web assets hosted on a Web application, site, or platform in an automated and proactive manner. From the moment the Web assets are hosted on the Web application platform and protected by a Web application security device, the hosted Web assets are constantly monitored and assessed for potential risks. Whenever there is a new instance or a modification of a Web asset, a copy of the Web asset is automatically downloaded and analyzed for potential vulnerabilities. If a suspicious indicator of malicious contents in the Web asset is detected during the analysis, a plurality of security policies are created and applied to the Web application security device to mitigate threats of the Web asset and protect users of the Web application against malware attacks via the tampered Web asset.

