Webpage Malware Detection Through Layered AI Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cybersecurity technologies struggle to detect and respond to new or variant malware, decoy information, and advanced persistent threats (APT) effectively, lacking standardized methods for describing malware and attack techniques, and are limited in predicting future threats.
Innovation Solution
A cyber threat information processing apparatus and method that utilizes multiple layers of detection, including antivirus-based and AI algorithms, to identify malware, attack techniques, and attackers, with capabilities to process webpages for malicious content, and predict future threats through machine learning.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If conventional pattern-based detection methods are used, then detection speed and accuracy for known malware is improved, but detection capability for new or variant malware deteriorates
Solution Approach 1:
The system performs preliminary actions by collecting and analyzing malware samples, extracting their characteristics, and storing them in a database before actual detection occurs. This preparatory phase enables the system to have reference data ready for comparing against new threats, improving both detection speed and capability for variant malware.
Solution Approach 2:
The patent transitions from traditional single-dimension pattern matching to multi-dimensional analysis by examining malware from multiple perspectives: code characteristics, behavioral patterns, network activity, and file system modifications. This dimensional expansion enables detection of new and variant malware that would evade conventional single-method detection.
2Adaptability or versatility
If AI analysis is used to detect and analyze malware, then analysis capability is improved, but inability to address decoy information and fake information deteriorates
Solution Approach 1:
The system implements feedback mechanisms where detection results are continuously analyzed and used to refine detection rules and models. When decoy information is encountered, the feedback loop enables the system to learn from these encounters and improve its ability to distinguish genuine threats from decoys over time, enhancing both reliability and adaptability.
Solution Approach 2:
The patent introduces intermediary verification layers that validate AI analysis results before final detection. Multiple independent analysis methods are used as intermediaries to cross-verify findings, reducing the impact of decoy information and fake data on the overall detection accuracy.
3Measurement precision
If individual case-focused detection method is used, then detection of specific malware is improved, but prediction capability for future threats deteriorates
Solution Approach 1:
The system achieves universality by designing a multi-functional detection framework that simultaneously performs specific malware detection and general threat prediction. The same infrastructure used for detecting individual malware cases is also utilized for analyzing attack patterns and predicting future threats, making the system both precise and adaptable.
Solution Approach 2:
The patent ensures continuity by maintaining ongoing data collection, analysis, and model updating processes. Rather than performing discrete detection tasks, the system continuously learns from incoming data, enabling it to maintain high detection precision for current threats while simultaneously building predictive capabilities for future attacks through uninterrupted analysis.
4Adaptability or versatility
If multiple layers of detection including AI algorithms are used, then detection capability for variant malware is improved, but processing time and system complexity deteriorates
Solution Approach 1:
The system applies segmentation by dividing the complex multi-layer detection process into distinct, modular components: initial filtering layer, AI analysis layer, verification layer, and response layer. Each layer handles specific tasks independently, reducing overall system complexity while maintaining comprehensive detection capability for variant malware.
Solution Approach 2:
The patent implements partial action by applying different levels of detection intensity to different threats. Not all malware samples undergo the complete multi-layer analysis; instead, the system applies appropriate detection depth based on initial assessment, reducing processing complexity for low-risk cases while maintaining high detection capability for suspicious variants that require extensive analysis.
Data Source
AI summary
Provided is a cyber threat information processing method including collecting a webpage and classifying data included in the webpage or data linked according to link depth, detecting whether the data included in the webpage or the linked data is malicious on a plurality of layers, the plurality of layers including at least two of antivirus-based malicious pattern detection, signature malicious pattern detection according to a certain rule, or malignancy detection according to an artificial intelligence (AI) algorithm for the data, and providing or storing record data of the webpage when the data is detected to be malicious as a result of the detection.


