Web Content Analysis Gateway for Malicious Code Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems fail to effectively detect and categorize malicious web content without compromising user functionality, particularly in environments where selective access to certain types of content is necessary, and existing solutions like heightened security settings or network firewalls are either ineffective or obstructive.
Innovation Solution
A system and method that classify web content by receiving and analyzing web page content, identifying properties, and storing them in a database for comparison against definitions to categorize active content, using a gateway server module and database management system to block or allow requests based on categorization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If heightened security settings are used on the web browser, then protection from malicious code is improved, but user functionality and access to safe applications are obstructed
Solution Approach 1:
The patent introduces a gateway server as an intermediary between the user's web browser and the internet. This gateway server analyzes web content before it reaches the browser, detecting malicious code while allowing safe content to pass through. This resolves the contradiction by providing security protection without requiring the browser to operate in high-security mode that would block legitimate applications.
Solution Approach 2:
The system performs preliminary analysis of web content at the gateway server before the content reaches the user's browser. By detecting and blocking malicious code in advance, the system provides protection without needing to rely on reactive browser security settings that would otherwise obstruct user functionality.
2Reliability
If network firewall applications are used to block executable content, then protection from malicious code is improved, but selective access to necessary content is lost
Solution Approach 1:
The gateway server performs localized analysis of web content, examining specific properties and characteristics of individual web pages and executable content. Rather than applying a blanket block to all executable content, the system analyzes each piece of content locally to determine whether it is malicious or safe, enabling selective access while maintaining protection.
Solution Approach 2:
The system changes the parameters of content analysis by examining multiple properties of web content (such as file type, source, behavior patterns) rather than relying on a single parameter like blocking all executable content. This multi-parameter approach enables the system to distinguish between malicious and safe content, providing both protection and selective access.
3Measurement precision
If web content is analyzed and categorized before delivery, then detection of malicious content is improved, but processing time and delay are increased
Solution Approach 1:
The gateway server performs partial analysis of web content by focusing on key properties and characteristics that are most indicative of malicious content. Rather than conducting a complete and exhaustive analysis of every piece of content, the system applies targeted analysis to the most relevant aspects, improving detection precision while minimizing processing delay.
Solution Approach 2:
The system uses predefined categories and property comparisons to quickly skip through the analysis process for content that matches known patterns. By comparing web content properties against stored definitions and categories, the system can rapidly identify and categorize content without requiring lengthy detailed analysis, thus reducing processing time while maintaining detection accuracy.
Data Source
AI summary
A system and computer based method are provided for identifying active content in websites on a network. In one aspects, a method for classifying web content includes determining a first property associated with static content of a web page, determining a second property associated with the content of the web page based at least in part on active content associated with the web page, evaluating a logical expression relating the first property and the second property, at least in part by evaluating whether a constant value matches at least a portion of the content of the web page, associating the web page with a category based on a result of the evaluation, and determining whether to allow network access to the web page based on the category.


