Web Page Security Analysis via Structural Reputation Scoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for remediating security threats from compromised computers infected with bots and malware are ineffective, slow, or incomplete, particularly when attackers are behind firewalls or state actors, making it difficult to identify and mitigate attacks on enterprise networks.
Innovation Solution
A distributed network of sensor computers is deployed near compromised computers to detect and analyze network messages, identify security threats, and provide remediation measures to block attacks, using a security control computer with logic to inspect web pages, determine reputation scores, and implement remediation without considering content, and reconfigure firewalls or compromised computers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional security remediation methods are used, then existing security measures can be maintained, but the effectiveness is insufficient and the speed is too slow to counter modern threats
Solution Approach 1:
The system performs preliminary actions by proactively inspecting web pages and determining reputation scores before threats can fully execute. The security control computer continuously monitors and pre-identifies potential threats, enabling preventive remediation rather than reactive response, thereby improving both effectiveness and speed of security countermeasures
Solution Approach 2:
The system implements feedback mechanisms where sensor computers continuously report on compromised computers and web page reputations to the security control computer. This real-time feedback loop enables dynamic adjustment of remediation strategies, improving response effectiveness and speed by continuously adapting to evolving threat landscapes
2Measurement precision
If comprehensive content analysis is performed, then threat identification accuracy improves, but processing time increases and system complexity grows
Solution Approach 1:
The system extracts and focuses analysis on the most critical structural elements of web pages (hierarchical structure, links, and referenced files) while excluding less relevant content. This selective extraction approach maintains high threat identification accuracy by concentrating resources on the most indicative features, thereby reducing processing time without sacrificing detection precision
Solution Approach 2:
The system changes the analysis parameters from comprehensive content examination to structural feature evaluation. By shifting focus to hierarchical structure, link patterns, and file references rather than detailed content analysis, the system achieves efficient threat identification with reduced processing time while maintaining accuracy through these structural parameters
3Reliability
If deep inspection of web page content is performed, then threat detection improves, but the system complexity and resource requirements increase
Solution Approach 1:
The system extracts only the essential structural parameters from web pages (hierarchical structure, links, and file references) for security analysis, omitting detailed content examination. This extraction approach simplifies the inspection system by focusing on the most critical security-relevant features, reducing computational complexity while maintaining reliable threat detection
Solution Approach 2:
The system employs a universal inspection framework that handles multiple security assessment tasks through a single simplified structure-based analysis approach. This multi-functional framework can detect various threat types (malware distribution, phishing, command-and-control communications) using the same structural inspection mechanism, reducing overall system complexity compared to specialized analyses for each threat type
Data Source
AI summary
In an embodiment, a data processing method providing an improvement in computer security comprises selecting, from a queue identifying a plurality of web pages, a particular web page to retrieve from one of a plurality of internet sources; causing retrieving a copy of the particular web page from a particular internet source; determining a hierarchical structure of the particular web page; based upon a hierarchical structure of the particular web page and without consideration of content of the particular web page, identifying one or more features, of links in the particular web page or files referenced in the particular web page, that indicate one or more security threats; determining a reputation score for the particular web page; determining a specified remediation measure, based upon the reputation score, to remediate a security threat that is identified in the particular web page; providing the specified remediation measure to one or more of a compromised computer, a sensor computer and an enterprise computer.


