Web Security Configuration via Reputation Server Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security configurations, particularly in web browsers, are inadequate in protecting users from eavesdropping, impersonation, and hacking due to vulnerabilities, and existing security measures often break websites, making them difficult for users to navigate securely.

Innovation Solution

A method and apparatus that utilize a reputation server to analyze and automatically configure security settings for web site features by retrieving and processing reputation data for URLs, determining which features are allowed based on trust levels, thereby enabling secure browsing without manual intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual security configuration is implemented by disabling Java, blocking flash or PDFs and running NoScript, then security protection against eavesdropping, impersonation and hacking is improved, but ease of operation deteriorates as users must manually allow different web site features for each web site

Engineering Contradiction:
Improvesecurity protectionVSAvoidmanual configuration requirement
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system automatically configures security settings by retrieving reputation data for URLs and determining executable web site features without requiring manual user intervention. The client terminal autonomously manages security configurations based on reputation assessments, eliminating the tedious manual process of allowing or blocking features for each website.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

A reputation server acts as an intermediary between the client terminal and web sites, providing reputation data that enables automatic security decisions. This intermediary service allows the system to maintain high security protection while avoiding manual configuration by mediating the trust assessment between users and web site features.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If automatic security configuration based on reputation data is implemented, then ease of operation is improved by eliminating manual configuration, but device complexity increases due to reputation data retrieval and processing

Engineering Contradiction:
Improveautomatic configurationVSAvoidreputation data processing system
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The complex reputation data processing functionality is extracted from the client terminal and implemented as a separate reputation server service. This extraction reduces device complexity at the client end while maintaining automatic security configuration capabilities, as the heavy lifting of reputation assessment is performed by the external server rather than embedded in every client device.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If security settings are tightened to block potentially harmful content, then reliability against security threats is improved, but productivity deteriorates as legitimate web site features are blocked requiring manual intervention

Engineering Contradiction:
Improvesecurity against threatsVSAvoidweb browsing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system applies different security levels to different web site features based on their reputation data. Instead of uniformly blocking all potentially harmful content, the system selectively allows or blocks specific features (Java, flash, PDFs, scripts) based on the assessed trust level of each URL, maintaining browsing efficiency for legitimate sites while protecting against threats.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system continuously retrieves updated reputation data for URLs and adjusts security configurations accordingly. This feedback mechanism ensures that security settings remain optimized, automatically allowing legitimate features when reputation is good and blocking potentially harmful content when reputation deteriorates, thereby maintaining both security and productivity dynamically.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP2719141B1Method and device for security configuration
Publication Date: 2018.01.24 F SECURE CORP
  • EP2719141B1 patent drawingFigure 1
  • EP2719141B1 patent drawingFigure 2

AI summary

An example embodiment of the present invention provides an apparatus including at least one processor; and at least one memory including executable instructions, the at least one memory and the executable instructions being configured to, in cooperation with the at least one processor, cause the apparatus to perform at least the following: retrieving (206), from a reputation server, reputation data of uniform resource locators (URL) of one or more web sites relating to one or more web site features that are available via the web site; and determining (210, 212, 214, 216, 218) executable web site features on the basis of the retrieved reputation data.