Web Asset Malware Detection via Continuous Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

As web-based applications grow in popularity, there is an increasing need to ensure hosted web assets are trustworthy and tamper-free, as cybercriminals can use trusted assets to mount attacks, potentially affecting large user communities and damaging brand reputation, necessitating automatic scanning and proactive mitigation against malware attacks.

Innovation Solution

A system and method for actively identifying and mitigating malware attacks on hosted web assets through continuous monitoring and analysis, using a Web asset assessment engine, threat detection engine, threat summary and reporting engine, and protection policy application engine, which automatically creates and applies security policies to prevent threats without human intervention, utilizing communication protocols to protect users and applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security scanning methods are used, then detection capability is provided, but response time is delayed and human intervention is required

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidresponse time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary security assessment of web assets before they are compromised. By continuously monitoring and evaluating web assets in advance, the system detects tampering early and automatically responds without waiting for traditional security scanning, thus reducing response time while maintaining detection capability

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements automated self-service security protection by using the web asset assessment engine and threat detection engine to autonomously identify, assess, and respond to threats without human intervention. The automatic policy application engine executes mitigation actions independently, eliminating delays associated with manual security operations

Inventive Principle:
Principle #25Self-service

2Measurement precision

If comprehensive security scanning of all web assets is implemented, then threat detection accuracy is improved, but system complexity increases

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments the security assessment process into distinct functional modules: web asset assessment engine for initial evaluation, threat detection engine for malicious content identification, and automatic policy application engine for response actions. This segmentation maintains comprehensive scanning capability while organizing system complexity into manageable, specialized components

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The web asset assessment engine serves as an intermediary that preprocesses and evaluates web assets before they reach the threat detection engine. This intermediary layer filters and prepares data, enabling the threat detection engine to focus on identifying malicious content with high accuracy without being overwhelmed by the complexity of analyzing all raw web asset data

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If automated threat mitigation is implemented, then response speed is improved, but potential false positives increase

Engineering Contradiction:
Improveresponse speedVSAvoidfalse positive rate
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system implements feedback mechanisms where the threat detection engine continuously monitors the effectiveness of automated mitigation actions. By analyzing the outcomes of policy applications and comparing detected threats against known patterns, the system refines its detection algorithms to reduce false positives while maintaining rapid automated response capability

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The web asset assessment engine performs preliminary evaluation and scoring of web assets before threats are fully developed. By identifying suspicious patterns early in the asset lifecycle, the system can apply targeted mitigation policies with higher confidence, reducing false positives while maintaining fast automated response

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10860715B2Method and apparatus for proactively identifying and mitigating malware attacks via hosted web assets
Publication Date: 2020.12.08 BARRACUDA NETWORKS INC
  • US10860715B2 patent drawing
  • US10860715B2 patent drawing

AI summary

A new approach is proposed that contemplates systems and methods to provide identification and mitigation of malware attack via Web assets hosted on a Web application, site, or platform in an automated and proactive manner. From the moment the Web assets are hosted on the Web application platform and protected by a Web application security device, the hosted Web assets are constantly monitored and assessed for potential risks. Whenever there is a new instance or a modification of a Web asset, a copy of the Web asset is automatically downloaded and analyzed for potential vulnerabilities. If a suspicious indicator of malicious contents in the Web asset is detected during the analysis, a plurality of security policies are created and applied to the Web application security device to mitigate threats of the Web asset and protect users of the Web application against malware attacks via the tampered Web asset.