Website Safety Reputation System Using Community Reports
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current computer security systems are limited in their ability to proactively protect users from malware by only reacting after malware is detected on a computer, and they face resource-intensive challenges in thoroughly analyzing network sites for safety, leading to impractical coverage and outdated information.
Innovation Solution
A community-based system that determines a network site's safety reputation using user reports, malware detection from nodes, non-specific information, and external feeds, prioritizing resource allocation for detailed analysis of potentially malicious sites based on historical data and commercial importance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If thorough security analysis of every network site is performed, then measurement precision of site safety is improved, but use of energy and computational resources becomes impractical
Solution Approach 1:
The patent segments the security analysis process into two distinct phases: a lightweight initial assessment phase that all sites undergo, and a detailed thorough analysis phase reserved only for suspect sites identified by the initial phase. This segmentation allows the system to maintain measurement precision for sites requiring it while avoiding the prohibitive resource cost of applying thorough analysis to all sites universally.
Solution Approach 2:
The patent applies local quality by providing different levels of analysis quality to different sites based on their risk profile. High-value suspect sites receive thorough detailed analysis with high measurement precision, while low-risk sites receive only the lightweight initial assessment. This differential approach optimizes resource allocation by concentrating computational resources where they provide the most value.
2Reliability
If frequent analysis of network sites is performed to maintain fresh information, then reliability of safety information is improved, but use of energy and resources increases
Solution Approach 1:
The patent implements periodic action by scheduling detailed analysis of suspect sites at optimized intervals rather than continuously. The system determines appropriate re-analysis periods based on factors such as site risk level, changes in community reports, and resource availability. This periodic approach maintains information reliability for high-priority sites while dramatically reducing overall resource consumption compared to continuous monitoring.
Solution Approach 2:
The system employs community-based monitoring where user nodes continuously report on site activity and anomalies in the background. This self-service mechanism provides ongoing reliability checks without requiring centralized resource-intensive analysis, allowing the system to maintain fresh safety information through distributed community participation rather than centralized periodic scanning.
3Reliability
If detailed analysis is performed on all network sites, then coverage of malicious sites is improved, but productivity of the analysis system decreases
Solution Approach 1:
The patent applies preliminary action by performing a quick initial assessment on all sites before detailed analysis. This preliminary screening identifies suspect sites that warrant thorough investigation while filtering out benign sites. By performing this preliminary action first, the system maintains broad detection coverage for malicious sites while preserving productivity by avoiding detailed analysis on sites that don't require it.
Solution Approach 2:
The patent implements partial action by applying detailed analysis only to the portion of sites that are identified as suspects through community reports and initial assessment, rather than performing excessive action of analyzing all sites. This selective approach maintains detection coverage for malicious sites while significantly improving overall system productivity by limiting detailed analysis to necessary cases.
Data Source
AI summary
A mechanism is provided for determining a safety reputation for a network site in a manner that provides both wide coverage of potentially malicious sites as well as improves the freshness of information from which the safety reputation is derived. Community-based information, such as reports from users related to recently-visited network sites, malware detected by reporting network nodes, non-specific information such as unusual CPU usage and network activity of visiting nodes, and information received from other types of external feeds is used in determining the safety reputation and updating the safety reputation. Such information is analyzed in order to determine network sites that are potential sources of malware, which can then be subjected to more detailed analysis. Historical information as to a site's reputation and other factors such as commercial importance can also be reviewed to make a determination as to whether information being currently gathered by a community of users is sufficient to trigger additional analysis of the network site. Thus, resources used for detailed analysis of suspect network sites is conserved.


