Web Page Malware Quarantine via Intermediary Scanning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing server protection methods, such as antivirus software, are inadequate in preventing the propagation of malware from compromised servers to clients, and blacklisting servers can lead to difficulties for operators in correcting issues and recovering from loss of goodwill and revenue.

Innovation Solution

A malware detection and remediation system that performs static and dynamic analysis of web page content to identify and quarantine malicious elements, preventing their propagation to clients and providing tools for site administrators to remediate infected pages, while also monitoring blacklists for affected sites.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If antivirus software is installed on servers to protect from malware, then server protection is improved, but malware propagation to clients can still occur through compromised pages

Engineering Contradiction:
Improveserver protectionVSAvoidmalware propagation
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent introduces an intermediary malware scanning system that sits between the server and clients. This scanner intercepts page requests, scans for malware, and filters infected content before it reaches clients. The scanner acts as a mediator that protects clients without requiring changes to server antivirus software, thus resolving the contradiction between server protection and preventing malware propagation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary scanning of web pages before they are served to clients. By scanning pages in advance and identifying malware presence beforehand, the system prevents infected content from being transmitted to clients. This preliminary action approach ensures that even if servers are compromised, malware cannot be propagated to clients.

Inventive Principle:
Principle #10Preliminary action

2Object-affected harmful factors

If servers are blacklisted to protect clients from malware, then client protection is improved, but operators face difficulty in correction and recovery

Engineering Contradiction:
Improveclient protectionVSAvoidoperator correction and recovery
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent implements selective quarantine of only the infected pages or specific malicious elements within pages, rather than blacklisting entire servers. This local quality approach allows operators to maintain server accessibility while targeting only the harmful content. Operators can correct issues and request delisting more easily when only specific pages are quarantined rather than the entire server being blacklisted.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent provides automated feedback mechanisms to operators, including notifications when pages are scanned and quarantined, and tools to request delisting after remediation. This feedback loop enables operators to quickly respond to malware detections, correct issues, and restore server reputation without prolonged blacklisting, thus improving ease of operation while maintaining client protection.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If comprehensive malware scanning is performed on all pages, then detection accuracy is improved, but processing time and system resources increase

Engineering Contradiction:
Improvemalware detection accuracyVSAvoidpage processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements a two-tier scanning approach where all pages receive basic scanning and only pages with suspicious characteristics undergo comprehensive scanning. This partial action strategy maintains high detection accuracy for potentially infected pages while reducing processing time for the majority of clean pages, thus resolving the contradiction between detection accuracy and processing time.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent segments the scanning process into multiple stages: initial rapid scanning of all pages, followed by deeper analysis only of pages exhibiting suspicious features. This segmentation allows the system to maintain high detection accuracy for problematic pages while minimizing the time loss associated with comprehensive scanning of all pages, thereby resolving the contradiction between precision and time efficiency.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8656491B1Mitigating malware
Publication Date: 2014.02.18 DASIENT
  • US8656491B1 patent drawing
  • US8656491B1 patent drawing
  • US8656491B1 patent drawing

AI summary

Remediating a suspicious element in a web page is disclosed. An indication of a suspicious element is received. A quarantine instruction is sent to a server of the web page. One example of a quarantine instruction is an instruction to block the page from being served. Another example of a quarantine instruction in as instruction to block an element of the page from being served.