Web Application Malicious Code Detection Through Configuration Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Web applications are vulnerable to cyberattacks and unauthorized access, with malicious code and users posing challenges in securing non-public information and causing network congestion and performance degradation.

Innovation Solution

A system and method for detecting malicious code and users by analyzing configuration parameters, determining anomalies, and implementing countermeasures such as blocking network communications and masking sensitive data to protect non-public information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If web applications are made accessible and open, then ease of operation and user access are improved, but vulnerability to cyberattacks and unauthorized access increases

Engineering Contradiction:
Improveaccessibility of web applicationVSAvoidvulnerability to cyberattacks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a machine learning-based detection system as an intermediary layer between the web application and external users. This system monitors configuration parameters, analyzes user behavior patterns, and identifies malicious activities before they can compromise the application, thereby maintaining accessibility while providing security protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary analysis of configuration parameters and user behavior patterns to detect potential threats before they can execute harmful actions. By continuously monitoring and analyzing data in advance, the system can identify and respond to malicious activities proactively, preventing unauthorized access while keeping the application open.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If security measures are strengthened to protect non-public information, then reliability and security are improved, but device complexity and processing requirements increase

Engineering Contradiction:
Improvesecurity of non-public informationVSAvoidcomplexity of security system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a self-service security system that automatically monitors configuration parameters, detects anomalies, and responds to threats without requiring complex manual security infrastructure. The machine learning model continuously trains on observed data and autonomously identifies malicious patterns, reducing the need for complex rule-based security systems while maintaining high reliability.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If monitoring and detection of malicious code is enhanced, then measurement precision of threats is improved, but loss of time and processing overhead increase

Engineering Contradiction:
Improvedetection accuracy of malicious codeVSAvoidtime for analysis and response
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system continuously monitors configuration parameters and user behavior patterns in real-time without interrupting application operations. The machine learning model processes data streams continuously, maintaining constant vigilance for malicious activities while minimizing processing overhead through efficient anomaly detection algorithms that can quickly identify threats without requiring extensive analysis time.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS20250247420A1System and method for detecting and countering malicious code
Publication Date: 2025.07.31 BANK OF AMERICA CORP
  • US20250247420A1 patent drawing
  • US20250247420A1 patent drawing
  • US20250247420A1 patent drawing

AI summary

A system for detecting and countering malicious code executed on a web application detects a set of configuration parameter values from the web application. The system compares each configuration parameter value with a counterpart from among a set of historical configuration parameter values. In response to the comparison, the system determines that a malicious code is executed on the web application, and determines a function associated with the malicious code. The system determines one or more actions to counter the malicious code based on the function of the malicious code. The system executes at least one of the one or more actions.