Web Domain Classification Using Client Reputation Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for classifying web domains for maliciousness are inefficient and unreliable, relying on manual user feedback and lacking in accuracy, as they do not effectively utilize client reputation data to assess the risk of web domains.

Innovation Solution

A system that identifies clients attempting to access web domains, determines their reputation scores, and classifies the domains based on these scores, using a centralized server to aggregate reputation information and update classifications dynamically, incorporating both client and third-party classifications to determine a web domain's maliciousness threshold.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual user feedback methods are used to classify web domains, then users can identify malicious domains they have personally encountered, but the classification accuracy remains low and the system is inefficient

Engineering Contradiction:
Improveclassification accuracyVSAvoidclassification efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent combines multiple data sources including client reputation data, third-party classifications, and security event information into a unified domain classification system. This merging of diverse information sources improves both the accuracy and efficiency of malicious domain identification beyond what manual user feedback alone could achieve.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system implements a feedback mechanism where client security events and reputation data are continuously collected and used to update domain classifications. This creates a self-improving system that learns from accumulated data, enhancing classification accuracy over time while automating the process to improve efficiency.

Inventive Principle:
Principle #23Feedback

2Reliability

If client reputation data is collected and processed to improve classification accuracy, then the reliability of domain classification improves, but the system complexity increases

Engineering Contradiction:
Improveclassification accuracyVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the domain classification system into distinct functional components: a reputation data collection module, a third-party classification integration module, a security event processing module, and a domain classification module. This segmentation manages system complexity by organizing functions into manageable, modular units while maintaining high classification accuracy through their coordinated operation.

Inventive Principle:
Principle #1Segmentation

3Measurement precision

If comprehensive reputation information from multiple sources is aggregated, then the accuracy of malicious domain identification improves, but the time required for classification increases

Engineering Contradiction:
Improvedomain maliciousness detection accuracyVSAvoidclassification time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-collecting and storing reputation data from multiple clients and third-party sources before classification is needed. This advance preparation ensures that when domain classification is required, the system can quickly retrieve and process pre-aggregated data, improving detection accuracy without incurring time delays during the actual classification process.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8826444B1Systems and methods for using client reputation data to classify web domains
Publication Date: 2014.09.02 GEN DIGITAL INC
  • US8826444B1 patent drawing
  • US8826444B1 patent drawing
  • US8826444B1 patent drawing

AI summary

A computer-implemented method for using client reputation data to classify web domains may include identifying a web domain. The computer-implemented method may also include identifying at least one client that has attempted to access the web domain. The computer-implemented method may further include identifying a reputation associated with the client that attempted to access the web domain. The computer-implemented method may additionally include classifying the web domain based at least in part on the reputation of the client that attempted to access the web domain. Various other methods, systems, and computer-readable media are also disclosed.