Website Safety Reputation System Using Community Reports

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computer security systems are limited in their ability to proactively protect users from malware by only reacting after malware is detected on a computer, and they face resource-intensive challenges in thoroughly analyzing network sites for safety, leading to impractical coverage and outdated information.

Innovation Solution

A community-based system that determines a network site's safety reputation using user reports, malware detection from nodes, non-specific information, and external feeds, prioritizing resource allocation for detailed analysis of potentially malicious sites based on historical data and commercial importance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If thorough security analysis of every network site is performed, then measurement precision of site safety is improved, but use of energy and computational resources becomes impractical

Engineering Contradiction:
Improvesafety analysis accuracyVSAvoidcomputational resources
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent segments the security analysis process into two distinct phases: a lightweight initial assessment phase that all sites undergo, and a detailed thorough analysis phase reserved only for suspect sites identified by the initial phase. This segmentation allows the system to maintain measurement precision for sites requiring it while avoiding the prohibitive resource cost of applying thorough analysis to all sites universally.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by providing different levels of analysis quality to different sites based on their risk profile. High-value suspect sites receive thorough detailed analysis with high measurement precision, while low-risk sites receive only the lightweight initial assessment. This differential approach optimizes resource allocation by concentrating computational resources where they provide the most value.

Inventive Principle:
Principle #3Local quality

2Reliability

If frequent analysis of network sites is performed to maintain fresh information, then reliability of safety information is improved, but use of energy and resources increases

Engineering Contradiction:
Improveinformation freshnessVSAvoidanalysis resources
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent implements periodic action by scheduling detailed analysis of suspect sites at optimized intervals rather than continuously. The system determines appropriate re-analysis periods based on factors such as site risk level, changes in community reports, and resource availability. This periodic approach maintains information reliability for high-priority sites while dramatically reducing overall resource consumption compared to continuous monitoring.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The system employs community-based monitoring where user nodes continuously report on site activity and anomalies in the background. This self-service mechanism provides ongoing reliability checks without requiring centralized resource-intensive analysis, allowing the system to maintain fresh safety information through distributed community participation rather than centralized periodic scanning.

Inventive Principle:
Principle #25Self-service

3Reliability

If detailed analysis is performed on all network sites, then coverage of malicious sites is improved, but productivity of the analysis system decreases

Engineering Contradiction:
Improvedetection coverageVSAvoidanalysis throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies preliminary action by performing a quick initial assessment on all sites before detailed analysis. This preliminary screening identifies suspect sites that warrant thorough investigation while filtering out benign sites. By performing this preliminary action first, the system maintains broad detection coverage for malicious sites while preserving productivity by avoiding detailed analysis on sites that don't require it.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements partial action by applying detailed analysis only to the portion of sites that are identified as suspects through community reports and initial assessment, rather than performing excessive action of analyzing all sites. This selective approach maintains detection coverage for malicious sites while significantly improving overall system productivity by limiting detailed analysis to necessary cases.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS8667587B1Real-time website safety reputation system
Publication Date: 2014.03.04 GEN DIGITAL INC
  • US8667587B1 patent drawing
  • US8667587B1 patent drawing
  • US8667587B1 patent drawing

AI summary

A mechanism is provided for determining a safety reputation for a network site in a manner that provides both wide coverage of potentially malicious sites as well as improves the freshness of information from which the safety reputation is derived. Community-based information, such as reports from users related to recently-visited network sites, malware detected by reporting network nodes, non-specific information such as unusual CPU usage and network activity of visiting nodes, and information received from other types of external feeds is used in determining the safety reputation and updating the safety reputation. Such information is analyzed in order to determine network sites that are potential sources of malware, which can then be subjected to more detailed analysis. Historical information as to a site's reputation and other factors such as commercial importance can also be reviewed to make a determination as to whether information being currently gathered by a community of users is sufficient to trigger additional analysis of the network site. Thus, resources used for detailed analysis of suspect network sites is conserved.