Web Page Malware Quarantine via Intermediary Scanning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing server protection methods, such as antivirus software, are inadequate in preventing the propagation of malware from compromised servers to clients, and blacklisting servers can lead to difficulties for operators in correcting issues and recovering from loss of goodwill and revenue.
Innovation Solution
A malware detection and remediation system that performs static and dynamic analysis of web page content to identify and quarantine malicious elements, preventing their propagation to clients and providing tools for site administrators to remediate infected pages, while also monitoring blacklists for affected sites.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If antivirus software is installed on servers to protect from malware, then server protection is improved, but malware propagation to clients can still occur through compromised pages
Solution Approach 1:
The patent introduces an intermediary malware scanning system that sits between the server and clients. This scanner intercepts page requests, scans for malware, and filters infected content before it reaches clients. The scanner acts as a mediator that protects clients without requiring changes to server antivirus software, thus resolving the contradiction between server protection and preventing malware propagation.
Solution Approach 2:
The patent implements preliminary scanning of web pages before they are served to clients. By scanning pages in advance and identifying malware presence beforehand, the system prevents infected content from being transmitted to clients. This preliminary action approach ensures that even if servers are compromised, malware cannot be propagated to clients.
2Object-affected harmful factors
If servers are blacklisted to protect clients from malware, then client protection is improved, but operators face difficulty in correction and recovery
Solution Approach 1:
The patent implements selective quarantine of only the infected pages or specific malicious elements within pages, rather than blacklisting entire servers. This local quality approach allows operators to maintain server accessibility while targeting only the harmful content. Operators can correct issues and request delisting more easily when only specific pages are quarantined rather than the entire server being blacklisted.
Solution Approach 2:
The patent provides automated feedback mechanisms to operators, including notifications when pages are scanned and quarantined, and tools to request delisting after remediation. This feedback loop enables operators to quickly respond to malware detections, correct issues, and restore server reputation without prolonged blacklisting, thus improving ease of operation while maintaining client protection.
3Measurement precision
If comprehensive malware scanning is performed on all pages, then detection accuracy is improved, but processing time and system resources increase
Solution Approach 1:
The patent implements a two-tier scanning approach where all pages receive basic scanning and only pages with suspicious characteristics undergo comprehensive scanning. This partial action strategy maintains high detection accuracy for potentially infected pages while reducing processing time for the majority of clean pages, thus resolving the contradiction between detection accuracy and processing time.
Solution Approach 2:
The patent segments the scanning process into multiple stages: initial rapid scanning of all pages, followed by deeper analysis only of pages exhibiting suspicious features. This segmentation allows the system to maintain high detection accuracy for problematic pages while minimizing the time loss associated with comprehensive scanning of all pages, thereby resolving the contradiction between precision and time efficiency.
Data Source
AI summary
Remediating a suspicious element in a web page is disclosed. An indication of a suspicious element is received. A quarantine instruction is sent to a server of the web page. One example of a quarantine instruction is an instruction to block the page from being served. Another example of a quarantine instruction in as instruction to block an element of the page from being served.


