Web Link Analysis for Hidden Malicious Content Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for detecting malicious web addresses are inefficient in identifying hidden content, prone to rule evasion, resource-intensive, and limited to personal computers and emails, failing to detect new or future malicious web addresses.
Innovation Solution
A link characteristic analysis-based method that traverses internal and external links using a crawler, identifies normal or abnormal web content through connection or disconnection states, and uses a digital chain principle to distinguish between organically interconnected normal and disconnected abnormal content, employing AI for validation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If rule-based detection method is used, then detection speed is improved, but detection accuracy deteriorates due to inability to detect new or changed malicious web addresses
Solution Approach 1:
The system performs preliminary actions by proactively crawling and storing normal web content and its internal links before malicious changes occur. This enables the system to detect new or modified malicious web addresses by comparing current content against the stored baseline of normal content, rather than relying on pre-defined rules that can be evaded by attackers.
2Ease of operation
If user navigation method is used, then ease of operation is improved, but detection capability deteriorates due to inability to detect hidden content without internal links
Solution Approach 1:
The system segments the web content into two categories: normal web content that should have internal links and hidden content that lacks internal links. By analyzing the presence or absence of internal links as a distinguishing feature, the system can detect hidden malicious content without requiring users to manually navigate through the website structure.
3Quantity of substance
If rule-based detection is used, then storage requirement is reduced, but adaptability deteriorates due to inability to detect new malicious web addresses
Solution Approach 1:
The system performs self-service by automatically crawling, storing, and analyzing web content to build its own detection capabilities. Instead of relying on externally maintained rule databases, the system independently collects normal web content patterns and uses this self-acquired data to detect anomalies, enabling it to adapt to new malicious web addresses without external intervention.
4Measurement precision
If antivirus or email security tool is used, then detection accuracy is improved, but scope is limited to personal computers and emails
Solution Approach 1:
The system achieves universality by designing a web content detection method that can be applied across all websites without being limited to specific platforms like personal computers or emails. The system analyzes web content structure and internal link patterns universally, making it applicable to any website regardless of its hosting platform or access method.
Data Source
AI summary
The present invention relates to a link characteristic analysis-based abnormal web content detection method and system for detecting and verifying a hidden malicious web address and visualizing web content by viewing a public content list and a hidden content list.


