Analyzing user activity for composite objects
By generating an event list of composite objects and performing clustering and classification analysis, the problem of inability to effectively analyze the user activities of multiple objects in the prior art is solved, and the accurate identification and manipulation behavior of composite objects is realized.
Patent Information
- Application Number
- CN202380093033.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2022-12-08
- Filing Date
- 2023-12-06
- Publication Date
- 2025-08-29
AI Technical Summary
The prior art is difficult to effectively analyze user activities between multiple objects, especially in the context of composite objects, and it is impossible to accurately identify whether there is manipulation behavior.
By generating an event list of composite objects, analyzing user activities using clustering and classification processes, identifying and evaluating whether event clustering represents a given type of user behavior.
It realizes effective analysis of user activities of composite objects, can identify and indicate possible manipulation behaviors, and improves the accuracy and flexibility of the analysis.
Smart Images

Figure FT_1 
Figure FT_2 
Figure FT_3
Abstract
Description
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS
[0002] This application claims priority to U.S. patent application No. 18 / 077,518, filed on December 8, 2022, the entire contents of which are incorporated herein by reference. Background Art
[0003] In systems such as communication networks, users can take actions against objects. Data regarding such user activity can be collected for the purpose of analyzing the user activity. For example, user activity can be analyzed to determine whether it corresponds to certain types of behavior. In some examples, this analysis can be used to determine whether any further action should be taken, such as to further investigate the user activity or provide an alert that a given type of behavior has occurred. BRIEF DESCRIPTION OF THE DRAWINGS
[0004] Certain embodiments are disclosed with reference to the following drawings.
[0005] Figure 1 is a block diagram illustrating a computing device according to some embodiments.
[0006] Figure 2 is a block diagram illustrating a computing device for performing an example method for analyzing user activity.
[0007] Figure 3 is a flow chart illustrating an example method for analyzing user activity.
[0008] Figure 4A is a diagram illustrating an example of a first event report set and a second event report set.
[0009] Figure 4B It is shown by Figure 4A The first event set represented by the first event report set and the first event set represented by Figure 4A A schematic diagram of a second event set represented by a second event report set.
[0010] Figure 4C It is shown that Figure 4B Schematic diagram of an example of event lists of a first event set and a second event set shown in .
[0011] Figure 5 is a flow chart illustrating an example of an analysis process performed on a list of events occurring for a composite object.
[0012] Figure 6A is shown as Figure 4B Schematic diagram of an example of event clusters generated as part of the analysis process performed on the event list shown in FIG.
[0013] Figure 6B Is shown in the analysis Figure 6A Schematic diagram of aspects of an example method of clustering in the example clustering shown in .
[0014] Figure 7 is a flow chart illustrating an example of a selection process for selecting a first event report set and a second event report set to generate a list of events occurring for a composite object.
[0015] Figure 8A is a schematic diagram illustrating a plurality of event report sets from which an event report set is selected by an example selection process.
[0016] Figure 8B is a block diagram illustrating aspects of an example selection process.
[0017] Figure 9 is a block diagram illustrating an example of an electronic transaction system in which certain embodiments may be employed.
[0018] Figure 10 is a block diagram illustrating an example of an electronic transaction system in which certain embodiments may be employed.
[0019] Figure 11 is a diagram showing a method for analyzing electronic trading systems such as Figure 9 and Figure 10 A block diagram of a system of user activities in one of the example electronic trading systems.
[0020] Certain embodiments will be better understood when read in conjunction with the accompanying drawings which illustrate examples. It should be understood, however, that the embodiments are not limited to the arrangements and instrumentality shown in the drawings. DETAILED DESCRIPTION
[0021] The disclosed embodiments generally relate to techniques for analyzing user activity associated with a composite object comprising at least a first object and a second object. For example, the first object and the second object may be objects against which a user (e.g., a user in a communication network) can take various actions, such as sending messages to manipulate the object or storing data associated with the object and the user. Instances of user activity may be recorded in corresponding event reports. User activity for a single object may be analyzed by analyzing events that occur for that object. However, in some examples, user activity may involve more than one object. For example, user activity may occur for related objects. The first object and the second object may, for example, be related such that the state of one object may affect the state of the other.
[0022] The disclosed embodiments allow for analysis of user activity related to multiple objects by treating the multiple objects as a composite object and generating an analysis of user activity for the composite object. This enables analysis of types of user activity that cannot be analyzed by analyzing only events occurring for one or the other of a first object and a second object. User activity related to a composite object may be referred to herein as a composite user activity. The results of the analysis may provide an indication of whether the user activity corresponds to a given type of behavior occurring for the composite object. For example, the results of the analysis of user activity for a composite object may indicate whether the user activity corresponds to manipulation of the state of the composite object or one or more objects included in the composite object.
[0023] Although this description discloses embodiments that include software and other components executed on hardware, it should be noted that the embodiments are merely illustrative and should not be considered limiting. For example, it is contemplated that any or all of these hardware and software components may be embodied exclusively in hardware, exclusively in software, exclusively in firmware, or in any combination of hardware, software, and / or firmware. Accordingly, certain embodiments may be implemented in other ways.
[0024] I. Brief Description of Certain Embodiments
[0025] Certain embodiments provide a method comprising: obtaining, by a computing device: a first set of event reports, wherein each event report in the first set of event reports represents a corresponding event that occurred for a first object. The method also comprises obtaining, by a computing device, a second set of event reports, wherein each event report in the second set of event reports represents a corresponding event that occurred for a second object different from the first object. The method also comprises generating, by the computing device and using the first set of event reports and the second set of event reports, a list of events that occurred for a composite object comprising the first object and the second object. In addition, the method comprises generating, by the computing device and using the event list, an analysis of user activities for the composite object by performing an analysis process on the events in the event list. These features allow the first object and the second object to be treated as composite objects. This allows the composite object to be analyzed to generate an analysis of composite user activities related to the composite object. Thus, an effective analysis of user activities involving activities across multiple objects can be provided.
[0026] In some embodiments, the event reports in the first event report set and the event reports in the second event report set indicate respective occurrence times of the events represented by the event reports in the first event report set and the event reports in the second event report set, and generating the event list includes sorting the events based on their respective occurrence times. This can allow the event list to represent a series of events ordered by time. This can allow for generating an analysis of user activity that takes into account the order and timing of event occurrence.
[0027] In some embodiments, the analysis process includes: performing a clustering process on the events in the event list to generate one or more event clusters; and analyzing the clusters to generate an analysis of user activity with respect to the composite object. This can allow for identification of units of user activity that can be analyzed to generate an analysis of user activity with respect to the composite object.
[0028] In some embodiments, the clustering process includes generating one or more event clusters based on the respective occurrence times of the events. This can allow clustering to represent units of temporally continuous user activity.
[0029] In some embodiments, analyzing the clusters includes performing a classification process to determine corresponding classifications for one or more event clusters, wherein a given classification for a given event cluster indicates an estimate of whether the given event cluster represents a given type of user activity. Categorizing the clusters can allow the analysis generated by the method to be presented based on an indication of whether the given cluster represents a given type of user activity. Thus, a viewer examining the analysis can, for example, identify clusters of behavior of interest for further investigation.
[0030] In some embodiments, the classification process includes: calculating corresponding features of one or more event clusters; and determining corresponding classifications for the one or more event clusters based on the corresponding features of the one or more event clusters using a classification model. This allows clusters to be evaluated and classified in a flexible and accurate manner based on a model that can be configured to determine whether a cluster represents a given type of user behavior. For example, machine learning and / or rule-based algorithms can be used to classify clusters.
[0031] In some embodiments, the clustering process is based on an analysis of a given type of user activity to be generated, and the analysis of the clusters includes analyzing the clusters based on the analysis of the given type of user activity. One or more features of the analysis process can be based on the analysis of the given type of user activity to be generated. This allows different types of user behavior to be detected by different applications of the analysis process with different corresponding features.
[0032] In some embodiments, the method includes performing a selection process to select a first event report set and a second event report set from a plurality of event report sets including a first event report set and a second event report set for obtaining and generating an event list. In some embodiments, the selection process includes: performing a first analysis process for events represented by event reports in the first event report set to generate a first analysis of user activity for the first object; performing a second analysis process for events represented by event reports in the second event report set to generate a second analysis of user activity for the second object; and selecting the first event report set and the second event report set based on the first analysis and the second analysis. This allows for efficient determination of objects to be included in a composite object. For example, the selection process can allow for determination of objects that are related to each other, as indicated by analysis of user activity for those objects.
[0033] In some embodiments, the first analysis process includes performing a clustering process on the events represented by the event reports in the first event report set to generate a first set of event clusters, and the second analysis process includes performing a clustering process on the events represented by the event reports in the second event report set to generate a second set of event clusters. In such an embodiment, the selection of the first event report set and the second event report set is based on a comparison between one or more clusters in the first cluster set and one or more clusters in the second cluster set. This allows the selection process to take into account clusters of events for the first object and the second object. For example, clusters of events that occur at overlapping times can be analyzed to determine whether they represent related behavior across the first object and the second object.
[0034] In some embodiments, one or more clusters in the first set of clusters and one or more clusters in the second set of clusters each span a corresponding time period. In some embodiments, the comparison between one or more clusters in the first set of clusters and one or more clusters in the second set of clusters includes determining whether the corresponding time period of one or more clusters in the first set of clusters overlaps in time with the corresponding time period of one or more clusters in the second set of clusters. This allows clusters that overlap in time to be compared to each other to determine whether they represent related behavior across the first object and the second object. For example, event clusters that occur at overlapping times may be more likely to be related, and therefore the occurrence of such clusters can indicate that user activity across the first object and the second object is related.
[0035] In some embodiments, a comparison between one or more clusters in a first set of clusters and one or more clusters in a second set of clusters includes: determining a respective classification of a given cluster in the first set of clusters and a given cluster in the second set of clusters that temporally overlaps with the given cluster in the first set of clusters; and determining whether the respective classification of at least one of the overlapping clusters meets a predetermined criterion. This can allow a determination to be made as to whether the overlapping clusters indicate that the user activities they represent are related. For example, if a cluster of events occurring for a first object and a cluster of events occurring for a second object overlap in time and at least one of them is classified as representing a given type of behavior, this can provide an indication that activity across the two objects should be analyzed for that type of behavior.
[0036] In some embodiments, the event occurring for the first object and the event occurring for the second object are events that occur over the same predetermined elapsed time period. In some embodiments, the predetermined elapsed time period is a fixed-length period or the duration of a user activity session. In some embodiments, the analysis of user activity for the composite object includes an indication of an estimated likelihood of whether the user activity corresponds to specific user behavior. This allows the generated analysis to represent an analysis of user activity over a specific time period of interest.
[0037] In some embodiments, the first object and the second object are, respectively, a first tradable object and a second tradable object. In some embodiments, events represented by event reports in the first event report set relate to orders for the first tradable object, and events represented by event reports in the second event report set may relate to orders for the second tradable object. In some embodiments, given user behavior includes market manipulation (such as spoofing, front-running, or momentum ignition). This can allow for the detection of market manipulation by analyzing events related to composite objects. Tradable objects can be related to each other, and thus user activity on one object can affect the state of another related object. In examples, this method allows for the analysis of such activity by treating tradable objects as composite objects.
[0038] Certain embodiments provide a tangible computer-readable storage medium comprising instructions that, when executed, cause a computing device to: obtain: a first set of event reports, wherein each event report in the first set of event reports represents a corresponding event that occurred for a first object; and a second set of event reports, wherein each event report in the second set of event reports represents a corresponding event that occurred for a second object that is different from the first object; use the first set of event reports and the second set of event reports to generate a list of events that occurred for a composite object that includes the first object and the second object; and use the event list to generate an analysis of user activity for the composite object by performing an analysis process on the events in the event list.
[0039] Certain embodiments provide a computing device comprising: a report obtainer for obtaining: a first event report set, wherein each event report in the first event report set represents a corresponding event that occurred for a first object; and a second event report set, wherein each event report in the second event report set represents a corresponding event that occurred for a second object different from the first object; a list generator for using the first event report set and the second event report set to generate a list of events that occurred for a composite object including the first object and the second object; and an analyzer for using the event list to generate an analysis of user activities for the composite object by performing an analysis process on the events in the event list.
[0040] II. Example computing device
[0041] Figure 1 A block diagram of an example computing device 100 is illustrated. Computing device 100 can be used to implement certain embodiments described herein. In other examples, other computing devices may be used. Computing device 100 includes a communication bus 110, a processor 112, a memory 114, a network interface 116, an input device 118, and an output device 120. Processor 112, memory 114, network interface 116, input device 118, and output device 120 are coupled to communication bus 110. Computing device 100 is connected to an external network 140 (such as a local area network (LAN) or a wide area network (WAN), such as the Internet). The computing device is connected to external network 140 via network interface 116. Computing device 100 may include additional, different, or fewer components. For example, multiple communication buses (or other types of component interconnects), multiple processors, multiple memory devices, multiple interfaces, multiple input devices, multiple output devices, or any combination thereof may be provided. As another example, computing device 100 may not include input device 118 or output device 120. As another example, one or more components of computing device 100 may be combined into a single physical element, such as a field programmable gate array (FPGA) or a system on a chip (SoC).
[0042] Communication bus 110 may include a channel, electrical or optical network, circuit, switch, fabric, or other mechanism for communicating data between components in computing device 100. Communication bus 110 may communicatively couple with and transfer data between any component of computing device 100.
[0043] Processor 112 may be any suitable processor, processing unit, or microprocessor. Processor 112 may include, for example, one or more general-purpose processors, digital signal processors, application-specific integrated circuits, FPGAs, analog circuits, digital circuits, programmed processors, and / or combinations thereof. Processor 112 may be a multi-core processor that may include multiple processing cores of the same or different types. Processor 112 may be a single device or a combination of devices (such as one or more devices associated with a network or distributed processing system). Processor 112 may support various processing strategies (such as multiprocessing, multitasking, parallel processing, and / or remote processing). Processing may be local or remote and may be moved from one processor to another. In some embodiments, computing device 100 is a multi-processor system and, therefore, may include one or more additional processors communicatively coupled to communication bus 110.
[0044] The processor 112 may be operable to execute logic and other computer-readable instructions encoded in one or more tangible media, such as memory 114. As used herein, logic encoded in one or more tangible media includes instructions that can be executed by the processor 112 or a different processor. For example, the logic may be stored as part of software, hardware, an integrated circuit, firmware, and / or microcode. The logic may be received from an external communication device via the communication network 140. The processor 112 may execute the logic to perform the functions, actions, or tasks described herein.
[0045] Memory 114 can be one or more tangible media (such as computer-readable storage media). Computer-readable storage media can include various types of volatile and non-volatile storage media, including, for example, random access memory, read-only memory, programmable read-only memory, electrically programmable read-only memory, electrically erasable read-only memory, flash memory, any combination thereof, or any other tangible data storage device. As used herein, the term non-transitory or tangible computer-readable medium is expressly defined to include any type of computer-readable medium and does not include propagating signals. Memory 114 can include any desired type of mass storage device, including hard drives, optical media, magnetic tape or disk, etc.
[0046] The memory 114 may include one or more memory devices. For example, the memory 114 may include cache memory, local memory, mass storage devices, volatile memory, non-volatile memory, or a combination thereof. The memory 114 may be adjacent to the processor 112, part of the processor 112, programmed with the processor 112, networked with the processor 112, and / or remote from the processor 112, so that data stored in the memory 114 can be retrieved and processed, for example, by the processor 112. The memory 114 may store instructions executable by the processor 112. The instructions may be executed to perform one or more of the actions or functions described herein.
[0047] The memory 114 may store an application 130 that implements the disclosed technology. In some embodiments, the application 130 may be accessed from or stored in different locations. The processor 112 may access the application 130 stored in the memory 114 and execute computer-readable instructions included in the application 130.
[0048] The network interface 116 may include one or more network adapters. The network adapter may be a wired or wireless network adapter. The network interface 116 may allow the computing device 100 to communicate with the external network 140. The computing device 100 may communicate with other devices via the network interface 116 using one or more network protocols (such as Ethernet, Internet Protocol (IP), Transmission Control Protocol (TCP), User Datagram Protocol (UDP), wireless network protocols such as Wi-Fi, Long Term Evolution (LTE) protocol, or other suitable protocols).
[0049] The input device(s) 118 may include a position input device, such as a mouse, touchpad, touch screen, etc.; a keyboard, buttons, switches, etc.; and / or other human interface devices. The output device(s) 120 may include a display, which may be a liquid crystal display (LCD), a cathode ray tube (CRT), a light emitting diode (LED) display (such as an OLED display), or other suitable display.
[0050] In some embodiments, during the installation process, the application may be transferred from the input device 118 and / or the network 140 to the memory 114. When the computing device 100 is running or preparing to run the application 130, the processor 112 may retrieve instructions from the memory 114 via the communication bus 110.
[0051] III. Example apparatus and method for analyzing user activity
[0052] Figure 22 is a block diagram illustrating an example computing device 200. Computing device 200 may have any of the features described above for computing device 100. Computing device 200 includes a report obtainer 202, a list generator 204, and an analyzer 206. Computing device 200 is operable to perform a method of analyzing user activity.
[0053] Figure 3 is a flow chart illustrating an example method 300 of analyzing user activity performed by computing device 200 .
[0054] Method 300 includes, at block 302, obtaining, by report obtainer 202, a first set of event reports and a second set of event reports. Each event report in the first set of event reports represents a corresponding event that occurred for a first object. Each event report in the second set of event reports represents a corresponding event that occurred for a second object different from the first object. The first object and the second object may be objects for which various types of user activities may occur. For example, the first object and the second object may be objects for which users in a network (such as a communication network) may take various actions. A given event report records detailed information about an event. An event may or may not involve a user action. For example, an event may occur due to an action by a third party in the network, rather than by the user whose activity is being analyzed. The detailed information about the event recorded by the event report may include one or more of the type of event, the time of occurrence of the event, the identity of the user associated with the event, the identity of the object associated with the event, and any further details related to the event.
[0055] In some examples, the user activities represented by the events recorded in the event reports of the first event report set and the second event report set are activities of the same single user. However, in other examples, the user activities may include activities of different users. For example, the user activities may include activities of multiple users that form a given user group. In some such examples, events occurring with respect to the first object and events occurring with respect to the second object may be events related to different users. The user activities may include activities of one or more human users. Alternatively or additionally, the user activities may include activities of one or more machine users.
[0056] In some examples, the first set of event reports and the second set of event reports relate to events that occurred over the same predetermined elapsed time period. Thus, method 300 can allow for analysis of user activity over a predetermined elapsed time period. For example, an event can be an event that occurred over a predetermined elapsed time period of a fixed length or a predetermined time period for a given user activity session. In one example, the time period can be a 24-hour elapsed time period, such as the 24-hour period immediately preceding the acquisition of the first set of event reports and the second set of event reports.
[0057] Method 300 also includes, at block 304, generating, by list generator 204, a list of events that occurred for a composite object including a first object and a second object using the first set of event reports and the second set of event reports. Generating the event list may include extracting events represented by the first set of event reports and the second set of event reports, and generating the event list based on the extracted events. In some examples, where the event reports indicate a time of occurrence of an event to which the event reports relate, generating the event list includes generating a timeline of the events. For example, the events represented by the event reports in the first set of event reports and the events represented by the event reports in the second set of event reports may be arranged into a time-ordered series. Arranging the events into a time-ordered series may be implemented, for example, using a merge sort algorithm to sort the events based on their timestamps. For example, the events may be arranged in ascending or descending chronological order in the event list. Arranging the event list into a time-ordered series may allow the events to be analyzed taking into account the chronological order in which the events occurred, which may allow for efficient detection of patterns in user activity.
[0058] Method 300 also includes, at block 306, generating, by analyzer 206 and using the event list, an analysis of user activity for the composite object by performing an analysis process on the events in the event list. The characteristics of the analysis process may depend on the type of analysis of user activity to be generated. For example, the analysis of user activity may involve determining whether the user activity corresponds to an estimate of a given type of user behavior, and the characteristics of the analysis process may vary depending on the given type of user behavior. An example of an analysis process performed on a list of events occurring for a composite object is described in more detail below.
[0059] In addition to the first object and the second object, the composite object may also include one or more additional objects. In such an example, at block 302, in addition to the first set of event reports and the second set of event reports, a corresponding additional set of event reports may also be obtained. The one or more additional objects may, for example, be objects related to one or both of the first object and the second object. Thus, in such an example, it may be advantageous for the composite object to include one or more additional objects so that analysis of the composite object provides analysis of composite user activity related to the one or more related objects.
[0060] In some examples, the first object and the second object may be selected for inclusion in the composite object due to predetermined factors (such as knowing that the first object and the second object are related to each other). In other examples, method 300 includes performing a selection process to select the first event report set and the second event report set from a plurality of event report sets including the first event report set and the second event report set. In some examples, as described in more detail below, method 300 includes selecting the first event report set and the second event report set.
[0061] IV. Example of generating a list of events related to a composite object
[0062] Figure 4A 、 Figure 4B and Figure 4C The implementation of blocks 302 and 304 of method 300 is shown by way of example.
[0063] Figure 4A is a block diagram illustrating a first event report set 402 including event reports related to events occurring for a first object and a second event report set 404 including event reports related to events occurring for a second object.
[0064] Figure 4B 4 is a diagram illustrating a first event set 410 represented by event reports in a first event report set 402 and a second event set 420 represented by event reports in a second event report set 404. The first event set 410 includes a first event 411 (only the first event thereof is labeled for clarity), while the second event set 420 includes a second event 421 (similarly, only the first event thereof is labeled for clarity). Figure 4B A first set of events 410 and a second set of events 420 are shown, each set of events being arranged as a time-ordered series with time increasing from left to right along a horizontal axis. The timelines of the first set of events 410 and the second set of events 420 are aligned such that equal horizontal positions on the timeline represent equal times of occurrence.
[0065] Figure 4C 4 is a diagram showing an event list 430 related to a composite object including a first object and a second object. The event list 430 has been generated by a computing device based on the first set 402 of event reports and the second set 404 of event reports obtained. In particular, the event list 430 can be generated by Figure 4B The two time-ordered series are merged into a single time-ordered list 430 including the first event 411 and the second event 421 to generate.
[0066] V. Example Analysis Process
[0067] Figure 5 is a list of events related to a composite object (such as Figure 4C 430) is shown in FIG. 431. The analysis process 500 is a flowchart of an example analysis process 500 performed in FIG. Figure 3 An example of the analysis process performed at block 306 of method 300 is provided.
[0068] At block 502, analysis process 500 includes performing a clustering process on the events in event list 430. The clustering process generates one or more clusters, each cluster including one or more events. A given cluster may represent a collection of related events occurring for a given object, which may be analyzed to provide an analysis of user activity with respect to the object. For example, in the case of a continuous set of related events, a cluster may represent a minimum level of user activity that may be analyzed to identify a particular characteristic of the user activity, such as a given behavior.
[0069] The characteristics of the clustering process can depend on the type of analysis of user activity to be generated. For example, the characteristics of the clustering process can differ depending on the type of user behavior to be identified. Furthermore, the characteristics of the clustering process can differ depending on factors such as the identity of the object to which the clustering process is to be applied. For example, different types of user behavior may typically occur on different time scales, involve different numbers of user-initiated events, or involve different time intervals between events. Similarly, the characteristics of user activity corresponding to a given type of user behavior can differ depending on the objects involved in the behavior. Thus, the clustering process can operate differently depending on the type of user behavior to be detected, so as to take into account typical characteristics of the event clusters corresponding to the behavior to be detected.
[0070] The clustering process can include generating one or more clusters based on the respective occurrence times of the events. The clustering process can operate to group events that may be related to each other, for example, due to their temporal proximity. The clusters can vary in duration and the number of events included in the cluster. For example, the duration of a cluster can vary from a fraction of a second to one or more minutes, and the number of events in a cluster can vary from one event to one hundred or more events.
[0071] In some examples, features of events other than their respective times of occurrence are considered in the clustering process. For example, one or more statistical metrics of the events forming a candidate cluster can be compared to a threshold to determine whether the candidate cluster should be accepted or rejected as a cluster to be analyzed.
[0072] In some examples, the clustering process can involve applying a window function to a time-ordered series of events. The application of the window function can involve counting a number of consecutive events and measuring one or more attributes of the consecutive events. This can allow for the generation of candidate clusters that can be evaluated against one or more criteria to determine whether to accept or reject a given candidate cluster as a cluster to be analyzed. Figure 6A An example of this situation is described in more detail.
[0073] In some examples, the clustering process is deterministic and based on the application of one or more rule-based algorithms. In other examples, the clustering process can involve applying a trained machine learning model to the event list.
[0074] At block 504 , the analysis process 500 includes analyzing the clusters to generate an analysis of user activity with respect to the composite object.
[0075] In some examples, analyzing the clusters includes performing a classification process on the clusters generated by the clustering process to generate corresponding classifications for the clusters.A given classification for a given cluster may indicate an estimate of whether the given cluster represents a given type of user activity.
[0076] The classification process may include computing features of a given cluster to be provided to a classification model. The classification model may then take the features of the cluster as input and provide a classification of the cluster as output. The classification model may, for example, include a machine learning model. Alternatively or additionally, the classification model may include one or more rule-based algorithms.
[0077] In a manner similar to that described above for the clustering process, clusters may be analyzed in different ways depending on the type of analysis to be generated. For example, during analysis of clusters, the features calculated and the classification models used may differ depending on the type of analysis to be generated.
[0078] As an example, the analysis of user activity generated by analysis process 500 may include an indication that user activity with respect to a composite object corresponds to a given type of behavior intended to manipulate the state of one or more objects included in the composite object. In such an example, a clustering process operates to identify clusters of events associated with the composite object that may be associated with a given type of manipulation behavior. Similarly, analysis of the clusters involves calculating features that allow an assessment of whether the clusters correspond to a given type of manipulation behavior to be determined, and classifying the clusters based on those features.
[0079] In some examples, the analysis process involves determining an estimate of the probability that a given cluster will be labeled as corresponding to a given type of behavior. For example, one or more clusters of activity may have previously been labeled as corresponding to a given type of behavior, for example, by a human expert. During the analysis process, the probability that a given cluster being analyzed will be labeled by a human expert as corresponding to a given type of behavior can be estimated. For example, the probability can be estimated by inputting the calculated features of the given cluster into a model that provides a probability as an output. In some such examples, the model can be a machine learning model that has been trained on clusters labeled by experts. In other examples, the model can be a deterministic, rule-based model. The probability value can form part of the analysis of user activity output by the method.
[0080] VI. Example of parsing a list of events related to a composite object
[0081] Figure 6A and Figure 6B An implementation of the example analysis process 500 is shown by way of example. Figure 6A It shows the Figure 4C FIG. 4 is a schematic diagram of an example of a clustering process performed on the events 411 and 421 of the event list 430 shown in FIG.
[0082] Figure 6A A first cluster 632, a second cluster 634, a third cluster 636, and a fourth cluster 638 are shown, each of which has been identified by a query for Figure 4C The clustering process performed on the events in the event list 430 is generated. In this example, the clustering process used to generate clusters 632, 634, 636, and 638 includes identifying clusters based on the time of occurrence of the events in the list 430. In particular, each of the clusters 632, 634, 636, and 638 includes a series of temporally consecutive events. In this example, the clusters 632, 634, 636, and 638 are formed such that the time interval between consecutive events in a given cluster is no greater than a predetermined time interval. In terms of the number of events in the series, a cluster can be determined as the longest series of consecutive events, where each event in the series is separated from a consecutive event in the series by less than a predetermined time interval.
[0083] Clusters 632, 634, 636, 638 can be generated by forming candidate clusters and evaluating those candidate clusters such that a candidate cluster is only selected as a cluster to be analyzed if it represents the longest continuous series of events such that the time interval between each event in the candidate cluster is less than a predetermined interval. For example, Figure 6A It is shown how the first cluster 632 is generated by determining that the first six events in the list 430 form the longest series of events, where the interval between events is less than a predetermined interval.
[0084] To further illustrate this process, candidate cluster 639 is shown, which has been generated and evaluated as part of the process, but has not yet been selected as one of clusters 632, 634, 636, and 638 to be analyzed. Candidate cluster 639 includes six events from first cluster 632 and, in addition, events from second cluster 634. The events from second cluster 634 included in candidate cluster 639 are the earliest occurring events in second cluster 634. Each event in first cluster 632 occurs within a predetermined time interval of the previous event. However, the time interval 640 between the latest event in first cluster 632 and the earliest event in second cluster 634 exceeds the predetermined time interval. Therefore, candidate cluster 639 is rejected as a cluster to be analyzed, and a candidate cluster including only events from first cluster 632 is selected as first cluster 632. Once first cluster 632 is generated, the clustering process continues to determine the next series of consecutive events separated by less than a predetermined time interval, thereby identifying second cluster 634. The clustering process proceeds in this manner, generating and evaluating candidate clusters to produce a third cluster 636 and a fourth cluster 638 .
[0085] Figure 6B An example implementation of block 504 of the analysis process 500 is shown performed for the third cluster 636 . Figure 6B Shown Figure 6A A set 650 of features of a given cluster in the clusters 632, 634, 636, and 638 is provided. In this example, the set 650 of features represents features of the third cluster 636. The features of the third cluster 636 may include, for example, statistical features of the cluster, such as the number of events in the cluster, the average time interval between events in the cluster, or the total duration of the cluster. The features of the cluster 636 may also include features of the individual events in the cluster 636 (such as the type of event, or the state of the composite object after a given event occurs).
[0086] The set of features 650 is provided as input to the model 660. The model 660 provides a classification 670 of the third cluster 636 as output. The model 660 operates to generate an analysis of user activity with respect to the composite object. In particular, the model 660 operates to generate an analysis of user activity of a given type with respect to the composite object.
[0087] Can be used with Figure 6B Each of the other clusters 632, 634, 638 is analyzed in a manner similar to that shown in to produce corresponding classifications for the other clusters 632, 634, 638. Steps 650, 660, and 670 are repeated for each of the clusters 632, 634, 638, as shown in Figure 6B638 and the classification of the clusters can together form an output 670 of the analysis process. For example, the output 670 can include detailed information about the event clusters 632, 634, 636, 638, including the events included in those clusters, and additional classifications of the clusters 632, 634, 636, 638 indicating an estimate that the clusters 632, 634, 636, 638 correspond to a given type of user behavior.
[0088] Output 670 provides an analysis of user activity for the composite object. Output 670 may be provided to one or more users, which may include the user to whom the user activity corresponds and / or one or more additional users. For example, if output 670 indicates that one or more analyzed clusters are estimated to correspond to a given type of user behavior, the user may be alerted to this fact.
[0089] VII. Select the objects to include in the compound object
[0090] Figure 7 is a flow chart illustrating an example selection process 700 for selecting objects (including a first object and a second object) to be included in a composite object. The selection process 700 may be performed based on Figure 3 For example, the selection process 700 may be performed before block 302 to select the first object and the second object. Based on the results of the selection process 700, the method 300 may continue by obtaining the first event report set and the second event report set at block 302.
[0091] For example, a selection process may be performed to identify one or more objects where user activity across those objects may be related. This may allow for efficient determination of which objects should be included in a composite object. For example, the selection process may involve determining that a user exhibited a given behavior with respect to a first object at a similar time as when the user took an action with respect to a second object. For example, if analysis of a user's behavior with respect to a first object indicates that the user may have attempted to manipulate the state of the first object, the fact that the user simultaneously took an action with respect to a second object may indicate that the activities are related. For example, it may be the case that the user activity corresponds to behavior that is intended to manipulate the state of both the first object and the second object. Thus, the first object and the second object may be treated as composite objects to allow this type of related user activity across multiple objects to be analyzed.
[0092] The selection process may involve comparing user activity across multiple different combinations of objects to determine which objects may be relevant. Those objects for which user activity is considered relevant may be included in one or more corresponding composite objects to be analyzed. Figure 8A and Figure 8BA more detailed example describing the selection process.
[0093] exist Figure 7 In the selection process 700 of , at box 702, the selection process 700 performs a first analysis process on the events represented by the event reports in the first event report set to generate a first analysis of user activity for the first object. The first analysis process can, for example, involve analyzing user activity for the first object to estimate whether a cluster of activities represents a given type of user behavior, such as behavior involving manipulating the state of the first object. The first analysis process can include any of the features described above with respect to the analysis process performed on the events in the event synthesis list. For example, the first analysis process can include performing a clustering process on the events of the first event report set to generate one or more clusters, calculating features of the one or more clusters and analyzing the clusters to generate the first analysis.
[0094] At box 704, the selection process 700 includes performing a second analysis process on the events represented by the event reports in the second event report set to generate a second analysis of user activity for the second object. Similar to the first analysis process, the second analysis process may include any of the features described above with respect to the analysis process performed on the events in the event synthesis list. The second analysis process may, for example, involve analyzing user activity for the second object to estimate whether clusters of user activity correspond to the same type of user activity that the first analysis process is configured to detect. For example, the second analysis process may include performing a clustering process on the events represented by the event reports in the second event report set to generate a second set of event clusters, calculating features of one or more clusters, and analyzing the clusters to generate the second analysis.
[0095] At box 706, the selection process 700 includes selecting a first event report set and a second event report set based on the first analysis and the second analysis. The selection performed at box 706 may include comparing one or more clusters generated based on the events of the first event report set with one or more clusters generated based on the events of the second event report set. For example, in some examples, one or more clusters in the first cluster set and one or more clusters in the second cluster set may each span a corresponding time period. The comparison between the one or more clusters in the first cluster set and the one or more clusters in the second cluster set may include determining whether the corresponding time period of the one or more clusters in the first cluster set overlaps in time with the corresponding time period of the one or more clusters in the second cluster set. For example, activity clusters on different objects that overlap with each other can be analyzed to determine whether they indicate potentially related user activity across different objects.
[0096] In some examples, the comparison between one or more clusters in the first set of clusters and one or more clusters in the second set of clusters includes: determining a corresponding classification of a given cluster in the first set of clusters and a given cluster in the second set of clusters that temporally overlaps with the given cluster in the first set of clusters; and determining whether the corresponding classification of at least one of the overlapping clusters meets a predetermined criterion. For example, the predetermined criterion may be a cluster estimated to correspond to a given type of user behavior (such as behavior involving manipulating a state of one of the objects).
[0097] The classification of the clusters can be determined in a manner similar to that described above for the clustering of events in the event list. For example, each cluster in the first set of clusters can be analyzed to determine the classification of the cluster. Similarly, each cluster in the second set of clusters can be analyzed to determine the classification of the cluster. Clusters in the first set of clusters that overlap with clusters in the second set of clusters can be determined. The classification of any overlapping clusters can then be evaluated to determine whether any of them meet a predetermined criterion. For example, as described above, the predetermined criterion can be that a given cluster has a classification indicating that the given cluster represents a given type of user behavior, such as a given behavior corresponding to the manipulation of a state of one of the objects.
[0098] In some examples, if it is determined that at least one cluster in the overlapping cluster group meets a predetermined criterion, this provides an indication that user activity on the first object and the second object is related. For example, if analysis of the user activity cluster for the first object indicates that the user may have attempted to manipulate the state of the first object, the fact that the user activity cluster is simultaneously on the second object can indicate that the activities of the two overlapping clusters are related. Based on this indication, the first object and the second object can be selected to be included in the composite object so that the composite user activity for the related first and second objects can be analyzed. The user activity across the two related objects can then be analyzed as a composite user activity, for example, to estimate whether it corresponds to a given manipulation behavior.
[0099] In some examples, the comparison of the first set of clusters and the second set of clusters can involve an evaluation with respect to additional criteria. For example, if all clusters in the given set of overlapping clusters meet a given predetermined criterion (such as a criterion indicating that the clusters are related to a given type of user activity), then the given set of overlapping clusters can be determined to indicate related user activity across the first object and the second object. In another example, if more than one set of overlapping clusters is determined to indicate related user activity, the comparison can be performed to indicate related activity across the first object and the second object.
[0100] VIII. Example of selecting objects to include in a compound object
[0101] Figure 8A and Figure 8BAn example method of selecting a first set of event reports and a second set of event reports is shown. In an example implementation of method 300, Figure 8A and 8B The example method shown in FIG. 3 may be used, for example, to determine a first set of event reports and a second set of event reports to be obtained at block 302 .
[0102] Figure 8A is a schematic diagram illustrating a plurality of event report sets 800. The plurality of event report sets 800 includes a first event report set 802, a second event report set 804, a third event report set 806, and a fourth event report set 808. The event report sets 802, 804, 806, 808 include event reports representing events that occurred for respective first, second, third, and fourth objects. In the example method, the sets of event reports are analyzed against each other to determine whether the objects to which they relate should be included in the composite object to be analyzed.
[0103] exist Figure 8A and Figure 8B In the example shown, a first event report set 802 and a second event report set 804 are selected. However, in other examples, two or more other sets of sets 802, 804, 806, 808 may be selected. For example, if the selection process determines that the first object and the third object should be included in the composite object, the first event report set 802 and the third event report set 806 may be selected. The first event report set 802 and the second event report set 806 may then be obtained and used to generate an analysis of user activity for the composite object, as described above with reference to FIG. Figure 3 The method 300 has been described. In other examples, if three or more of the objects are determined to be related, the composite object may include those three or more objects, and the corresponding three or more event report sets for those objects are selected through a selection process.
[0104] Figure 8B 8 is a diagram showing a first event set 810 represented by event reports of a first event report set 802 and a second event set 820 represented by a second event report set 804. Figure 4B In the example of FIG, first event set 810 includes first event 811 (for clarity, only the first event in the second event set 820 is labeled), and second event set 820 includes second event 821 (for clarity, again, only the first event in the second event set 820 is labeled). First event set 810 and second event set 820 are each arranged as a time-ordered series, with time increasing from left to right. The timelines of first event set 810 and second event set 820 are aligned so that equal horizontal positions on the timeline represent the same time of occurrence.
[0105] In this example, first event set 810 includes four clusters: first cluster 812, second cluster 814, third cluster 816, and fourth cluster 818. Second event set 820 includes three clusters: first cluster 822, second cluster 824, and third cluster 826. Clusters 812, 814, 816, 818, 822, 824, and 826 have been determined by a clustering process applied separately to first event set 810 and second event set 820. The clustering process has the same characteristics as described above for the clustering process applied to event list 430. That is, the clustering process can determine clusters of events relevant to analyzing a given type of user activity. Clusters 812, 814, 816, and 818 have been identified by the clustering process as event clusters suitable for analyzing a given type of user activity for the first object. Similarly, clusters 822, 824, and 826 have been identified by the clustering process as event clusters suitable for analyzing a given type of user activity for the second object.
[0106] As part of the selection process, a set of overlapping clusters is determined. In this example, each cluster is determined to span a respective time period that begins at the time of occurrence of the earliest event in the cluster and ends at the time of occurrence of the latest event in the cluster. Whether two or more clusters overlap can be determined by determining whether the respective time periods spanned by the clusters overlap. Figure 8B In the example shown, two sets of overlapping clusters have been determined. A first set of overlapping clusters 832 includes a first cluster 812 of events related to a first object and a first cluster 822 of events related to a second object. A second set of overlapping clusters 834 includes a second cluster 814 and a third cluster 816 related to the first object, and a second cluster 824 related to the second object. A fourth cluster 818 related to the first object and a third cluster 826 related to the second object each do not overlap with any other clusters and, therefore, do not form part of a set of overlapping clusters.
[0107] Furthermore, as part of the selection process, clusters are analyzed and classified for a given type of user activity. For example, each of clusters 812, 814, 816, and 818 can be analyzed to assess whether they correspond to a given type of user behavior for a first object. Similarly, each of clusters 822, 824, and 826 can be analyzed to assess whether they correspond to a given type of user behavior for a second object.
[0108] For each of the sets 832, 834 of overlapping clusters, an analysis of the corresponding cluster in the overlapping set is used to generate an analysis of the overlapping set. In the example, the corresponding classifications of the clusters 812, 822 in the first overlapping set 832 are analyzed to determine whether at least one of the classifications meets a predetermined criterion. For example, if at least one of the classifications of the clusters 812, 822 indicates that the user activity for the first object or the second object is a given type of user behavior, an output is provided indicating that the first overlapping set indicates that the user activity related to the first object and the second object may be related and should be analyzed as a composite user activity. Similarly, if at least one of the clusters 814, 816, 824 in the second overlapping set 834 indicates that the user activity for the first object or the second object is a given type of user behavior, an output is provided indicating that the second overlapping set indicates that the user activity related to the first object and the second object may be related and should be analyzed as a composite user activity.
[0109] As described above, in other examples, different or additional criteria can be used to determine whether a first object and a second object should be included in a composite object based on a set of overlapping clusters. For example, overlapping clusters can be used only to indicate related behaviors across two objects, where all overlapping clusters have been individually classified as corresponding to a given type of behavior.
[0110] IX. Sample Electronic Trading System
[0111] Figure 9 A block diagram is illustrated representing an example electronic trading system 900 in which certain embodiments may be employed. System 900 includes a trading device 910, a gateway 920, and an exchange 930. Trading device 910 communicates with gateway 920. Gateway 920 communicates with exchange 930. As used herein, the phrase "in communication with" encompasses direct communication and / or indirect communication through one or more intermediary components. Trading device 910, gateway 920, and / or exchange 930 may include Figure 1 One or more computing devices 100. Figure 9 The exemplary electronic transaction system 900 depicted in FIG. 9 may communicate with additional components, subsystems, and elements to provide additional functionality and capabilities without departing from the teachings and disclosure provided herein.
[0112] In operation, trading device 910 may receive market data from exchange 930 via gateway 920. Trading device 910 may also send messages to exchange 930 via gateway 920. A user may utilize trading device 910 to monitor market data and / or make decisions based on sending buy or sell order messages to exchange 930 regarding one or more tradable objects. Trading device 910 may use market data to take trading actions, such as sending order messages to exchange 930. For example, the trading device may execute an algorithm that uses market data as input and outputs a trading action (such as sending an order message to exchange 930). The algorithm may or may not require input from the user in order to take a trading action.
[0113] Market data may include data about the market for a tradable asset. For example, market data may include the internal market, market depth, last traded price ("LTP"), last traded quantity ("LTQ"), or a combination thereof. The internal market refers to the highest available bid (best bid) and lowest available ask (best ask or best offer) in the market for a tradable asset at a specific point in time (as the internal market may vary over time). Market depth refers to the quantity available at price levels both within and away from the internal market. Market depth may have "gaps" due to the absence of prices based on the number of orders in the market.
[0114] Price levels associated with internal markets and market depth can be provided as value levels, which can include a price and a derived and / or calculated value representation. For example, a value level can be displayed as the net change relative to the opening price. As another example, a value level can be provided as a value calculated based on prices in two other markets. In another example, a value level can include a consolidated price level.
[0115] A tradable object is anything that can be traded. For example, a certain quantity of a tradable object can be bought or sold at a specific price. Tradable objects may include, for example, financial instruments, stocks, options, bonds, futures contracts, currencies, warrants, fund derivatives, securities, commodities, swaps, interest rate products, index-based products, trading events, goods, or any combination thereof. Tradable objects may include products listed and / or managed by an exchange, user-defined products, a combination of real or synthetic products, or any combination thereof. Synthetic tradable objects may exist that correspond to and / or are similar to real tradable objects.
[0116] An order message is a message that includes a trade order. A trade order can be, for example, an order to buy or sell a tradable object; an order to initiate a management order based on a defined trading strategy; an order to change, modify, or cancel an order; an instruction to an electronic exchange related to an order; or a combination thereof.
[0117] Trading device 910 may include one or more electronic computing platforms. For example, trading device 910 may include a desktop computer, a handheld device, a laptop computer, a server, a portable computing device, a trading terminal, an embedded trading system, a workstation, an algorithmic trading system such as a "black box" or "gray box" system, a computer cluster, or a combination thereof. As another example, trading device 910 may include a single-core or multi-core processor in communication with a memory or other storage medium configured to accessibly store one or more computer programs, applications, libraries, computer-readable instructions, etc. for execution by the processor.
[0118] By way of example, trading device 910 may comprise a computing device (such as a personal computer or mobile device) in communication with one or more servers, where the computing device and the one or more servers collectively constitute trading device 910. For example, trading device 910 may comprise a computing device and one or more servers that together run the TT® platform, an electronic trading platform provided by Trading Technologies International, Inc. ("Trading Technologies") of Chicago, Illinois. For example, one or more servers may run a portion of the TT platform (such as a portion that provides a web server), and the computing device may run another portion of the TT platform (such as a portion that provides user interface functionality within a web browser). The computing device and servers may communicate with each other using, for example, browser session requests and responses or network sockets to implement the TT platform. As another example, trading device 910 may comprise a computing device (such as a personal computer or mobile device) running an application such as TT® Desktop or TT® Mobile, both of which are electronic trading applications also provided by Trading Technologies. As another example, the trading device 910 can be one or more servers running trading tools such as ADL®, AUTOSPREADER®, AUTOTRADER™ and / or MD TRADER®, also provided by Trading Technologies.
[0119] Trading device 910 may be controlled or otherwise used by a user. As used herein, the term "user" may include, but is not limited to, a person (e.g., a trader), a trading group (e.g., a group of traders), or an electronic trading device (e.g., an algorithmic trading system). One or more users may be involved in the control or other use of a trading device.
[0120] Trading device 910 may include one or more trading applications. As used herein, a trading application is an application that facilitates or improves electronic trading. A trading application provides one or more electronic trading tools. For example, a trading application stored by the trading device may be executed to arrange and display market data in one or more trading windows. In another example, a trading application may include an automated spread trading application that provides spread trading tools. In yet another example, a trading application may include an algorithmic trading application that automatically processes algorithms and performs certain actions (such as placing orders, modifying existing orders, and deleting orders). In yet another example, a trading application may provide one or more trading screens. A trading screen may provide one or more trading tools that allow interaction with one or more markets. For example, a trading tool may allow a user to obtain and view market data, set order entry parameters, submit order messages to an exchange, deploy trading algorithms, and / or monitor positions while implementing various trading strategies. The electronic trading tools provided by the trading application may be always available or may only be available in certain configurations or operating modes of the trading application.
[0121] The trading application may be implemented using computer-readable instructions stored in a computer-readable medium and executable by a processor. Computer-readable media may include various types of volatile and non-volatile storage media, including, for example, random access memory, read-only memory, programmable read-only memory, electrically programmable read-only memory, electrically erasable read-only memory, flash memory, any combination thereof, or any other tangible data storage device. As used herein, the term non-transitory or tangible computer-readable medium is expressly defined to include any type of computer-readable storage medium and to exclude propagating signals.
[0122] One or more components or modules of the transaction application can be loaded into the computer-readable medium of transaction device 910 from another computer-readable medium. For example, the transaction application (or updates to the transaction application) can be stored by the manufacturer, developer, or publisher on one or more CDs, DVDs, or USB drives, which can then be loaded onto transaction device 910 or onto a server from which transaction device 910 retrieves the transaction application. As another example, transaction device 910 can receive the transaction application (or updates to the transaction application) from a server, for example, via the Internet or an intranet. Transaction device 910 can receive the transaction application or updates upon request by transaction device 910 (e.g., "pull distribution") and / or without request by transaction device 910 (e.g., "push distribution").
[0123] The trading device 910 may be adapted to send an order message. For example, the order message may be sent to the exchange 930 via the gateway 920. As another example, the trading device 910 may be adapted to send an order message to a simulated exchange in a simulated environment that does not implement real-world trading.
[0124] An order message can be sent at the user's request. For example, a trader can use trading device 910 to send an order message or manually enter one or more parameters for a trade order (e.g., order price and / or quantity). As another example, an automated trading tool provided by a trading application can calculate one or more parameters for a trade order and automatically send an order message. In some cases, the automated trading tool may prepare an order message for sending but may not actually send the order message without confirmation from the user.
[0125] The order message may be sent in one or more data packets or via a shared memory system. For example, the order message may be sent from trading device 910 to exchange 930 via gateway 920. Trading device 910 may communicate with gateway 920 using a local area network, wide area network, multicast network, wireless network, virtual private network, intranet, cellular network, peer-to-peer network, point of presence, dedicated line, the Internet, a shared memory system, and / or a proprietary network.
[0126] The gateway 920 may include one or more electronic computing platforms. For example, the gateway 920 may be implemented as one or more desktop computers, handheld devices, laptop computers, servers, portable computing devices, trading terminals, embedded trading systems, workstations with single-core or multi-core processors, algorithmic trading systems such as "black box" or "grey box" systems, computer clusters, or any combination thereof.
[0127] The gateway 920 facilitates communication. For example, the gateway 920 can perform protocol conversion on data communicated between the trading device 910 and the exchange 930. For example, the gateway 920 can process order messages received from the trading device 910 into a data format understood by the exchange 930. Similarly, for example, the gateway 920 can convert market data received from the exchange 930 in an exchange-specific format into a format understood by the trading device 910. Figure 10 As described in more detail, in some examples, gateway 920 may communicate with a cloud service that may support the functionality of gateway 920 and / or transaction device 910 .
[0128] Gateway 920 may include a trading application that facilitates or improves electronic trading, similar to the trading applications discussed above. For example, gateway 920 may include a trading application that tracks orders from trading device 910 and updates the status of the orders based on trade confirmations received from exchange 930. As another example, gateway 920 may include a trading application that consolidates market data from exchange 930 and provides it to trading device 910. In yet another example, gateway 920 may include a trading application that provides risk processing, calculates implied terms, handles order processing, handles market data processing, or a combination thereof.
[0129] In some embodiments, gateway 920 communicates with exchange 930 using a local area network, a wide area network, a multicast network, a wireless network, a virtual private network, an intranet, a cellular network, a peer-to-peer network, a point of presence, a dedicated line, the Internet, a shared memory system, and / or a proprietary network.
[0130] Exchange 930 may be owned, operated, controlled, or used by an exchange entity. Example exchange entities include CME Group, CBOE, Intercontinental Exchange, and Singapore Exchange. Exchange 930 may be an electronic exchange that includes an electronic matching system, such as a computer, server, or other computing device, adapted to allow tradable items offered for trading by the exchange to be bought and sold. Exchange 930 may include separate entities, some of which list and / or manage tradable items, while others receive and match orders. Exchange 930 may include, for example, an electronic communications network ("ECN").
[0131] Exchange 930 is adapted to receive order messages and match counterparty trade orders to buy and sell tradable items. Exchange 930 may list unmatched trade orders for trading. Once an order to buy or sell a tradable item is received and confirmed by the exchange, it is considered a valid order until it is filled or canceled. If only a portion of the order quantity is matched, the partially filled order remains a valid order. Trade orders may include, for example, trade orders received from trading device 910 or other devices in communication with exchange 930. For example, exchange 930 typically communicates with various other trading devices (which may be similar to trading device 910) that also provide trade orders for matching.
[0132] Exchange 930 is adapted to provide market data. Market data may be provided in one or more messages or data packets, or via a shared memory system. For example, exchange 930 may publish a data feed to a subscribing device (e.g., trading device 910 or gateway 920). The data feed may include market data.
[0133] System 900 may include additional, different, or fewer components. For example, system 900 may include multiple transaction devices, gateways, and / or exchanges. In another example, system 900 may include other communication devices (such as middleware, firewalls, hubs, switches, routers, servers, switch-specific communication equipment, modems, security managers, and / or encryption / decryption devices).
[0134] X. Specific example electronic transaction system
[0135] Figure 10 A block diagram of an example electronic trading system 1000 in which certain embodiments may be employed is shown. The electronic trading system 1000 includes a trading device 1010, a hybrid cloud system 1020, and an exchange 1030. The trading device 1010 may be similar to the one described above. Figure 9 The exchange 1030 may be the same as or similar to the trading device 910 described above. Figure 9 The hybrid cloud system 1020 or one or more of its components may provide the same or similar exchange 930 described above. Figure 9 One or more functions of the gateway 920 described above. Figure 9 The functionality of the described gateway 920 , or one or more portions of that functionality, may be included within the hybrid cloud system 1020 .
[0136] The hybrid cloud system 1020 includes a cloud service 1040 and a data center 1060. Figure 10 In the illustrated example, cloud service 1040 and its components are separate from data center 1060. However, in other examples (not shown), one or more or all of the components and / or functions of cloud service 1040 may instead be implemented in data center 1060. In such an example, or in addition, electronic transaction system 1000 may not include cloud service 1040. In such an example, the above reference to Figure 9 One or more of the functions described for gateway 920 may be provided solely by data center 1060 or one or more components thereof.
[0137] To provide lower latency for time-sensitive processes, data center 1060 can be co-located with or located near switch 1030. Thus, functions of hybrid cloud system 1020 that are time-sensitive or otherwise benefit from the lower latency of switch 1030 can be performed by data center 1060. Generally, functions of hybrid cloud system 1020 that are not time-sensitive or do not benefit from the lower latency of switch 1030 can be performed by cloud services 1040. Hybrid cloud system 1020 allows electronic trading system 1000 to be scalable for non-time-critical functions while still providing relatively low latency for switch 1030.
[0138] exist Figure 10 In the example, transaction device 1010 communicates with cloud service 1040 via a first network 1071. For example, first network 1071 can be a wide area network (such as the Internet using Hypertext Transfer Protocol (HTTP)). Transaction device 1010 communicates with data center 1060 via a second network 1072. For example, transaction device 1010 can communicate with data center 1060 via a virtual private network (VPN) using secure network sockets or a TCP connection. First network 1071 and second network 1072 can be the same network. Data center 1060 communicates with cloud service 1040 via a third network 1073. For example, data center 1060 can communicate with cloud service 1040 via a private network or a virtual private network (VPN) tunnel. Third network 1073 can be the same as first network 1071 and / or second network 1072. Data center 1060 communicates with switch 1030 via a fourth network 1074. For example, the data center 1060 can communicate with the switch 1030 using a local area network, a wide area network, a multicast network, a wireless network, a virtual private network, an intranet, a cellular network, a peer-to-peer network, a point of presence, a dedicated line, the Internet, a shared storage system, and / or a proprietary network. The fourth network 1074 can be the same as the first network 1071, the second network 1072, and / or the third network 1073.
[0139] Cloud service 1040 may be implemented as a virtual private cloud that may be provided by a logically isolated portion of the overall network service cloud. In this example, cloud service 1040 includes a network database 1041 and associated network server 1042, a product database 1043 and associated product data server (PDS) 1044, a user settings database 1045 and associated user settings server 1046, and a transaction database 1047 and associated transaction server 1048.
[0140] Trading device 1010 can communicate with web server 1042. As an example, trading device 1010 can run a web browser, referred to herein as a browser, which establishes a browsing session with web server 1042. This can occur after the appropriate domain name is resolved to the IP address of cloud service 1040 and / or after trading device 1010 (or its user) is properly authenticated with cloud service 1040. The browser sends a request to web server 1042, and web server 1042 provides a response to the browser, for example, using the Hypertext Transfer Protocol (HTTP) or Hypertext Transfer Protocol Secure (HTTPS). Web server 1042 can provide a user interface to the browser, through which a user can interact with the electronic trading platform. The user interface can display market data and / or allow for the placement of trade orders. As another example, trading device 1010 can run an application that communicates with web server 1042 (such as via an application programming interface (API)) to allow the user to interact with the electronic trading platform. The application can provide a user interface through which the user can interact with the electronic trading platform.
[0141] Trading device 1010 can communicate with PDS 1044. PDS 1044 interfaces with product database 1043. Product database 1043 stores definitions of tradable objects and user permissions to place trade orders on these objects. This information can be provided to trading device 1010. The user interface of trading device 1010 can use this information to determine which tradable objects a given user of trading device 1010 is permitted to place trade orders on.
[0142] The trading device 1010 can communicate with a user settings server 1046. The user settings server 1046 interfaces with a user settings database 1045, which stores user settings, preferences, and other information associated with the user's account. This information can be provided to the user settings server 1046 by the trading device 1010 when the user registers, or at some time thereafter, and the user settings server 1046 can store the information in the user settings database 1045. This information can be provided to the trading device 1010. The user interface of the trading device 1010 can use this information to determine which market data to display and in what format.
[0143] Trade database 1047 stores information about trades executed using electronic trading system 1000. Trade database 1047 may store all trade orders submitted by users and all corresponding order execution reports provided by exchange 1030 when trade orders are executed. Trade server 1048 may query trade database 1047 to generate, for example, an audit trail 1049 for a given user. This audit trail 1049 may be provided to trading device 1010 (or another device) to allow for review and / or analysis of the given user's trading activity.
[0144] Data center 1060 includes a multicast bus 1061, a price server 1062, an edge server 1063, a risk server 1064, a ledger uploader server 1065, an order connector 1066, and a strategy engine server 1067. Various components within data center 1060 communicate with each other using multicast bus 1061. This allows for efficient and scalable communication between components within data center 1060. For example, information provided by one component can be received by multiple other components within the data center 1060. Sending this information over multicast bus 1061, to which other components subscribe, allows the information to be sent in a single message, regardless of how many components may receive it.
[0145] Price server 1062 receives market data from exchange 1030. Price server 1062 converts this information into a format and / or syntax associated with (e.g., used by) electronic trading system 1000. Price server 1062 transmits the converted information as one or more multicast messages over multicast bus 1061. Specifically, price server 1062 multicasts this information over first multicast bus A for receipt by price clients. Edge server 1063 and policy engine server 1067 subscribe to first multicast bus A and receive market data from price server 1062. Price server 1062 can communicate with cloud service 1040. For example, price server 1062 can provide information about products or tradable objects to PDS server 1044 for use in defining tradable objects.
[0146] Edge server 1063 communicates with trading device 1010. For example, trading device 1010 can communicate with edge server 1063 via a secure network socket or TCP connection. Edge server 1063 can terminate the network (and / or mobile) connection (network socket) with trading device 1010. In some examples, edge server 1063 can be implemented as a server cluster. The number of servers in the cluster can be determined and scaled as needed based on utilization. Edge server 1063 receives market data via a first multicast bus A and routes the market data to trading device 1010. Users of trading device 1010 can decide to place trade orders based on the market data. Edge server 1063 routes the trade orders from trading device 1010 to exchange 1030. Specifically, when edge server 1063 receives an order message from trading device 1010, it multicasts the order message (or at least a portion thereof) on a second multicast bus B for receipt by order clients. The risk server 1064 subscribes to the second multicast bus B and receives the order message from the edge server 1063 .
[0147] Risk server 1064 is responsible for determining the pre-trade risk of a given trade order contained in a given order message. For example, for a given trade order, risk server 1064 may determine whether the user placing the trade order is permitted to do so. Risk server 1064 may determine whether the user is permitted to trade the quantity of the tradable object specified in the trade order. Risk server 1064 may prevent the placement of unauthorized trade orders. Risk server 1064 receives order messages from edge server 1063 via second multicast bus B and processes the order messages to determine the risk of the trade order in the message. If risk server 1064 determines that the trade order should not be placed (e.g., because the risk associated with the trade order exceeds a threshold), risk server 1064 prevents the trade order from being placed. For example, in this case, risk server 1064 may not transmit the order message to order connector 1066, but instead may transmit a message indicating to the user that the trade order was not placed. If risk server 1064 determines that the trade order should be placed (e.g., because the risk associated with the trade order is below a threshold), risk server 1064 forwards the order message to order connector 1066. Specifically, the risk server 1064 multicasts the order message on the second multicast bus B. The order connector 1066 and the ledger uploader 1065 subscribe to the second multicast bus B and receive the order message from the risk server 1064 .
[0148] The ledger uploader server 1065 communicates with the transaction database 1047 of the cloud service 1040. The ledger uploader server 1065 receives the order message from the risk server 1064 and sends the order message to the transaction database 1047. The transaction database 1047 then stores the order message (or at least a portion of its content) in the ledger stored in the transaction database 1047.
[0149] Order connector 1066 communicates with exchange 1030. Order connector 1066 receives order messages from risk server 1064, processes the order messages for transmission to exchange 1030, and then sends the processed order messages to exchange 1030. Specifically, processing includes converting the order messages into a data format understood by exchange 1030. If the trade order within the order message is executed by exchange 1030, exchange 1030 sends a corresponding execution report message to order connector 1066. The execution report message includes an execution report detailing the execution of the trade order. Order connector 1066 applies processing to the execution report message. Specifically, processing includes converting the execution report message into a data format understood by the electronic trading system and trading device 1010. Order connector 1066 multicasts the processed execution report message on a third multicast bus C for reception by execution report clients. Edge server 1063 and ledger uploader 1065 subscribe to third multicast bus C and receive the processed execution report message. Ledger uploader 1065 communicates with trade database 1047 to update the ledger with the execution report message (or at least a portion of its contents). Edge server 1063 forwards the execution report message to trade device 1010. Trade device 1010 may display information based on the execution report message to indicate that the trade order has been executed.
[0150] In some examples, order messages may be submitted by strategy engine server 1067. For example, strategy engine server 1067 may implement one or more strategy engines using an algorithmic strategy engine and / or an automated spreader strategy engine. Strategy engine 1067 receives market data from price server 1062 (via first multicast bus A) and automatically generates order messages based on the market data and appropriately configured algorithms. Strategy engine server 1067 sends the order message to order connector 1066 (via risk server 1064 and second multicast bus B), which processes the order message in the same manner as described above. Similarly, when exchange 1030 executes an order, strategy engine 1067 receives the corresponding order execution report message from order connector 1066 (via third multicast bus C). The order message and execution report message are sent to ledger uploader 1065 in a similar manner to that described above, so that ledger uploader 1065 can update the ledger stored by trade database 1047.
[0151] In some examples, the trade orders sent by trading device 1010 may not be submitted by a human. For example, trading device 1010 may be a computing device running an algorithmic trading application. In these examples, trading device 1010 may not communicate with network server 1042, PDS 1044, and / or user settings server 1046, and may not utilize a browser or user interface to submit trades. An application running on trading device 1010 may communicate with an adapter associated with edge server 1063. For example, the application and adapter may communicate using Financial Information Exchange (FIX) messages. In these examples, the adapter may be a FIX adapter. The application running on trading device 1010 may receive market data in FIX format (provided by price server 1062 and converted to FIX format by a FIX adapter associated with edge server 1063). The application running on trading device 1010 may generate a trade order based on the received market data and send the order message in FIX format to the FIX adapter associated with edge server 1063. A FIX adapter associated with edge server 1063 may process order messages received in FIX format into a format understood by components of data center 1060 .
[0152] It should be understood that the electronic trading system 1000 is merely an example and other electronic trading systems may be used. As an example, the electronic trading system 1000 does not necessarily need to include the cloud service 1040. As another example, the data center 1060 may include more than the above referenced Figure 10 More or fewer components may be described. As another example, forms of messaging between components of data center 1060 other than multicast messaging may be used.
[0153] XI. Specific example system for analyzing user activity
[0154] Figure 11 A specific example of a system 1100 for analyzing user activity on a composite object is shown. The system 1100 may form part of an electronic transaction system (such as the one described above with reference to FIG. Figure 9 and Figure 10 In one specific example, the system 1100 may be formed as Figure 10 For example, the computing device 1110 may be configured to provide a user with an audit trail of transaction activity (such as Figure 10 1049 ) to analyze user activity.
[0155] System 1100 includes a computing device 1110. Computing device 1110 may have any of the features of computing device 100 and computing device 200 described above. Computing device 1110 is configured to perform a method for analyzing user activities for composite activities, which may include features of any of the example methods described above.
[0156] The system 1100 may also include one or more of a product database 1143 and a product server 1144, a user setting DB 1145 and a user setting server 1146, a transaction database 1147 and a transaction server 1148. Each of these may have the same Figure 10 Any of the features of the corresponding components of the described system 1000. In addition, the system 1110 also includes a configuration database 1150, a storage device 1160, an alarm server 1162 and a viewing server 1164.
[0157] The computing device 1110 is operable to obtain a set of event reports, perform analysis of user activities based on the event reports, and output results of the analysis. The computing device 1110 is operable to obtain a first set of event reports and a second set of event reports, wherein each event report in the first set of event reports represents a corresponding event occurring for a first object, and wherein each event report in the second set of event reports represents a corresponding event occurring for a second object different from the first object.
[0158] In this example, the first object and the second object are respective tradable objects, that is, they can be traded by a user in an electronic trading system such as Figure 9 and Figure 10 Event reports can record actions taken by a given user with respect to a given tradable object (such as actions related to an order to buy or sell the tradable object). For example, a given event report can record the placement, removal, or modification of an order to buy or sell the tradable object. For example, a given event report can indicate that a given user placed an order to buy a first tradable object at a given time. A given event report can include further details about the event (such as the quantity of the object specified in the order or the price of the object). In some examples, event reports can be referred to as execution reports or trade reports. Event reports can also indicate events related to orders that were not user-activated (such as the execution, partial execution, or cancellation of a previously placed order by a user by a third party). User activity can include trading activity by one or more human users and / or one or more machine users (such as one or more automated trading tools).
[0159] The first object and the second object may, for example, be related tradable objects. The first object and the second object may be related such that trading activity on one of the first object and the second object can affect the price of the other object. For example, the prices of the first object and the second object may be correlated. In some examples, the first object and the second object may be different financial instruments related to the same or similar products. Multiple instruments may be associated with each given product. For example, the first object and the second object may each be a futures contract for a given product (such as corn). For example, the first object and the second object may represent different corn futures contracts for different corresponding months.
[0160] Computing device 1110 is operable to obtain event reports for a given elapsed time period. For example, the elapsed time period may be an elapsed transaction session for a tradable object related to the event report. Computing device 1110 may, for example, be configured to obtain a first set of event reports and a second set of event reports after a transaction session in which transactions occurred on a first object and a second object has closed. This process may be performed as part of a review of an audit trail, for example, to determine compliance with regulatory requirements by users in a trading system, or to otherwise determine whether certain types of user activity are identifiable.
[0161] User activity directed to a composite object comprising a first object and a second object can be analyzed by computing device 1110 to determine whether the user activity corresponds to certain types of behavior that can be considered destructive or manipulative. For example, user activity can be analyzed to detect destructive or manipulative trading behaviors such as deception, front-running, hype tactics, abusive messaging, hype tactics, pinging, and wash trading. In some cases, user activity can involve more than one user. For example, collusive behavior (such as collusive deception) involving two or more users can be detected by analyzing event reports related to the composite instrument, where the event reports include an event report indicating an event initiated by a first user and an event report indicating an event initiated by one or more other users.
[0162] The analysis of user activity may include any of the features of the example methods described above. For example, events related to a tradable composite object may be clustered by applying a clustering process configured to identify clusters of activity that may be associated with a given type of behavior (e.g., fraud). For example, the clustering process may be as described above with reference to Figure 5 Frame 502 and reference Figure 6A After the clustering process, for example, by Figure 5 Frame 504 and reference Figure 6BClusters can be analyzed using the described process. For example, features of the clusters can then be determined to provide to a model configured to estimate whether the cluster represents a given type of behavior. For example, if the given type of behavior is fraudulent, features associated with the fraudulent behavior can be calculated for a given cluster and input into the model. The model can then use the calculated features to estimate the probability that an expert human analyst would binary-label the given cluster as potentially fraudulent. The model can, for example, be a machine learning model trained on clusters labeled by expert human analysts. The calculated features of the clusters can vary depending on the type of behavior being analyzed. In some examples, features can include the time intervals between events in the cluster, the types of events in the cluster, such as whether they represent a user placing, modifying, or canceling an order, and whether those orders are buy or sell orders. Furthermore, events can represent actions that occurred with respect to an order previously placed by the user, such as the execution or partial execution of an order, or the cancellation of an order. Such actions can be initiated by another entity in the electronic trading system (e.g., exchange 1030). Furthermore, features representing the state of the composite object may be computed, including, for example, the distribution of outstanding orders for the composite object according to their respective volumes and prices and whether the order is a buy order or a sell order.
[0163] In one example, computing device 1110 obtains data indicating the status of entities in the electronic transaction system from user settings server 1146. Entities may include users, companies, and transaction accounts. Computing device 1110 then writes this data to storage device 1160. For example, computing device 1110 may write the data to a file, such as a CSV file, on a memory (not shown) of computing device 1110 and copy the file to storage device 1160. Storage device 1160 may, for example, include a cloud-based storage server, which may include an AWS S3 (Simple Storage Service) server.
[0164] The computing device 1110 then queries the configuration database 1150 to retrieve the configuration from the database 1150. The configuration may include details of a model for analyzing the event represented by the event report, such as a model to be used in a classification process and / or a model to be used in an analysis process, each of which may have any of the characteristics described above.
[0165] Computing device 1110 may identify companies and associated accounts from the data obtained from user settings server 1146 and perform analysis of user activity on user settings server 1146. For example, computing device 1110 may be configured to analyze user activity occurring only for certain companies and accounts indicated in the data obtained from user settings server 1146. Event reports obtained by computing device 1112 may then be based on information regarding the identification of companies and accounts for which computing device 1110 is able to analyze user activity.
[0166] Computing device 1110 can obtain additional information (such as product names and prices) from product server 1144. Furthermore, in some examples, computing device 1110 can obtain additional information (such as order book market data, instrument price chart data, and the opening and closing times of a given exchange or instrument) from one or more additional servers (not shown) as needed. In some examples, this data can be used to analyze user activity, for example, to determine characteristics of event clusters by reference to historical price information of objects associated with the analyzed events.
[0167] After obtaining the event report and any additional data to be used in the analysis, the computing device 1110 proceeds to analyze the data. Figures 2 to 8B Any features described in any of the example methods described. For example, the computing device 1110 can analyze user activity related to one or more tradable objects, including one or more tradable composite objects. In examples where the computing device 1110 is configured to perform a selection process, the selection process can include the above-referenced Figure 7 as well as Figure 8A and Figure 8B any features described. For example, the selection process may include first generating analyses of individual tradable objects and then using those analyses to determine which individual objects should be included in one or more composite objects. The determination of which objects should be included in a given composite object may vary depending on the type of activity being analyzed. For example, two or more objects may be at risk of being manipulated by a given type of behavior. The two or more objects may then be included in the composite object to be analyzed to detect that given type of behavior. However, those same two or more objects may be at lower risk or no risk of being manipulated by a different type of behavior and, therefore, may not be included in the composite tool used to detect that different type of behavior. For example, an analysis may involve analyzing user activity across two specific objects to detect potential fraudulent behavior across those two objects. However, for a different type of behavior (such as front-running), the same two objects may not be suitable for analysis as a composite object.
[0168] The output of the method performed by computing device 1110 includes the results of the analysis performed on the set of event reports, which may include a respective classification for each relevant cluster of user activity identified in the analysis. Computing device 1110 outputs the results of the analysis, for example, to storage device 1160.
[0169] In some examples, computing device 1110 may be operable to provide notifications to alarm server 1162 under certain circumstances. For example, computing device 1110 may evaluate, based on a predetermined alarm configuration, whether the results of the analysis indicate that a notification should be sent to the alarm server. Computing device 1110 may obtain the predetermined alarm configuration, for example, from configuration database 1150 or from alarm database 1162. For example, the alarm configuration may specify that a notification should be sent to alarm server 1162 if the results of the analysis indicate that one or more clusters are classified as corresponding to a given type of behavior. As described above, in some examples, the classification includes a score indicating the likelihood that a cluster will be labeled by an expert as corresponding to a given type of behavior. This may be referred to as a risk score. In some examples, the risk score may range from 0 to 100. Alarm server 1162 may send an alert to one or more recipients (e.g., recipients who have subscribed to receive alerts of a given type). The alert may include an email or other type of electronic message. In some examples, the alert may include information regarding the analysis results for the one or more clusters involved in the alert. In some examples, the alert may include a hyperlink allowing the recipient to view the analysis results for one or more related clusters in more detail.
[0170] In some examples, computing device 1110 may perform post-processing of the analysis results, such as to generate summary statistics, e.g., the number of clusters having risk scores from 75 to 100. Computing device 1110 may write this information to storage 1160 and / or configuration database 1150 .
[0171] View server 1164 can be configured to query results from storage 1160 for display on a client device (not shown). The client device can be a device operated by a user involved in the analysis (e.g., a trader). Alternatively, the client device can be operated by someone monitoring the trading activity of users in the network, such as a regulator or regulatory compliance officer of a given organization. View server 1164 can subscribe to receive notifications when the results of the analysis process are uploaded to storage 1160. View server 1164 can then update its in-memory state and cache to obtain the new results of the analysis for presentation to the client device.
[0172] As used herein, the phrases "configured to" and "adapted to" encompass that an element, structure or apparatus has been modified, arranged, changed or adapted to perform a particular function or for a particular purpose.
[0173] Some of the described figures depict example block diagrams, systems, and / or flow diagrams representing methods that may be used to implement all or part of certain embodiments. For example, one or more of the components, elements, blocks, and / or functions of the example block diagrams, systems, and / or flow diagrams may be implemented, alone or in combination, in hardware, firmware, discrete logic, as a set of computer-readable instructions stored on a tangible computer-readable medium, and / or any combination thereof.
[0174] For example, the example block diagrams, systems, and / or flow charts may be implemented using any combination of application specific integrated circuits (ASICs), programmable logic devices (PLDs), field programmable logic devices (FPLDs), discrete logic, hardware, and / or firmware. In addition, for example, some or all of the example methods may be implemented manually or in combination with the aforementioned techniques.
[0175] For example, the example block diagrams, systems, and / or flow charts can be executed using one or more processors, controllers, and / or other processing devices. For example, the examples can be implemented using coded instructions (e.g., computer-readable instructions) stored on a tangible computer-readable medium. Tangible computer-readable media can include various types of volatile and non-volatile storage media, including, for example, random access memory (RAM), read-only memory (ROM), programmable read-only memory (PROM), electrically programmable read-only memory (EPROM), electrically erasable read-only memory (EEPROM), flash memory, hard drives, optical media, magnetic tape, file servers, any other tangible data storage devices, or any combination thereof. Tangible computer-readable media are non-transitory.
[0176] Furthermore, although example block diagrams, systems, and / or flow diagrams have been described above with reference to the accompanying drawings, other implementations may be employed. For example, the order in which components, elements, blocks, and / or functions are executed may be changed and / or some of the components, elements, blocks, and / or functions described may be changed, eliminated, subdivided, or combined. Additionally, any or all of the components, elements, blocks, and / or functions may be executed sequentially and / or in parallel, for example, by separate processing threads, processors, devices, discrete logic, and / or circuits.
[0177] Although embodiments have been disclosed, various changes may be made and equivalents may be substituted. In addition, many modifications may be made to adapt to particular circumstances or materials. Therefore, it is intended that the disclosed technology is not limited to the specific embodiments disclosed, but is intended to include all embodiments falling within the scope of the appended claims.
[0178] XII. Terms
[0179] 1. A method comprising: obtaining, by a computing device: a first event report set, wherein each event report in the first event report set represents a corresponding event occurring for a first object; and a second event report set, wherein each event report in the second event report set represents a corresponding event occurring for a second object different from the first object; generating, by the computing device and using the first event report set and the second event report set, a list of events occurring for a composite object including the first object and the second object; and generating, by the computing device and using the event list, an analysis of user activities for the composite object by performing an analysis process for events in the event list.
[0180] 2. A method according to clause 1, wherein: the event reports in the first event report set and the event reports in the second event report set indicate the corresponding occurrence times of the events represented by the event reports in the first event report set and the event reports in the second event report set; and generating the event list includes sorting the events based on the corresponding occurrence times of the events.
[0181] 3. A method according to clause 1 or clause 2, wherein the analysis process includes: performing a clustering process on the events in the event list to generate one or more event clusters; and analyzing the clusters to generate the analysis of the user activity on the composite object.
[0182] 4. The method of clause 3, wherein the clustering process comprises generating the one or more event clusters based on respective occurrence times of the events.
[0183] 5. A method according to clause 3 or clause 4, wherein analyzing the clusters includes: performing a classification process to determine corresponding classifications of the one or more event clusters, wherein a given classification of a given event cluster indicates whether the given event cluster represents an estimate of a given type of user activity.
[0184] 6. A method according to clause 5, wherein the classification process includes: calculating corresponding features of the one or more event clusters; and determining corresponding classifications of the one or more event clusters based on the corresponding features of the one or more event clusters by using a classification model.
[0185] 7. A method according to any one of clauses 3 to 6, wherein the clustering process is based on an analysis of the user activity of a given type to be generated, and wherein analyzing the clusters includes analyzing the clusters based on the analysis of the user activity of the given type.
[0186] 8. A method according to any one of clauses 1 to 7, wherein one or more features of the analysis process are based on the analysis of a given type of user activity to be generated.
[0187] 9. The method according to any one of clauses 1 to 8 comprises: performing a selection process to select the first event report set and the second event report set from a plurality of event report sets including the first event report set and the second event report set for obtaining and generating the event list.
[0188] 10. A method according to clause 9, wherein the selection process includes: performing a first analysis process on the event represented by the event report in the first event report set to generate a first analysis of user activities for the above-mentioned first object; performing a second analysis process on the event represented by the event report in the second event report set to generate a second analysis of user activities for the second object; and selecting the first event report set and the second event report set based on the first analysis and the second analysis.
[0189] 11. A method according to clause 10, wherein: the first analysis process includes performing a clustering process on the events represented by the event reports in the first event report set to generate a first event cluster set; the second analysis process includes performing a clustering process on the events represented by the event reports in the second event report set to generate a second event cluster set; and the selection of the first event report set and the second event report set is based on a comparison between one or more clusters in the first cluster set and one or more clusters in the second cluster set.
[0190] 12. A method according to clause 11, wherein the one or more clusters in the first cluster set and the one or more clusters in the second cluster set each span a corresponding time period, and wherein the comparison between the one or more clusters in the first cluster set and the one or more clusters in the second cluster set includes determining whether the corresponding time period of the one or more clusters in the first cluster set overlaps in time with the corresponding time period of the one or more clusters in the second cluster set.
[0191] 13. A method according to clause 12, wherein the comparison between the one or more clusters in the first cluster set and the one or more clusters in the second cluster set includes: determining the corresponding classification of a given cluster in the first cluster set and a given cluster in the second cluster set that temporally overlaps with the given cluster in the first cluster set; and determining whether the corresponding classification of at least one overlapping cluster in the overlapping clusters meets a predetermined criterion.
[0192] 14. The method of any one of clauses 1 to 13, wherein the event occurring for the first object and the event occurring for the second object are events occurring over the same predetermined elapsed time period.
[0193] 15. The method of clause 14, wherein the predetermined elapsed period is a fixed-length period or a period of a user activity session.
[0194] 16. The method of any one of clauses 1 to 15, wherein the analysis of the user activity with respect to the composite object comprises an indication of whether the user activity corresponds to an estimate of a particular user behavior.
[0195] 17. A method according to any one of clauses 1 to 16, wherein the first object and the second object are respective first tradable objects and second tradable objects, and wherein the event represented by the event report in the first event report set relates to an order with respect to the first tradable object, and the event represented by the event report in the second event report set relates to an order with respect to the second tradable object.
[0196] 18. The method of clause 17, wherein the given user behavior comprises market manipulation behavior, such as spoofing, front-running, or hype tactics.
[0197] 19. A tangible computer-readable storage medium comprising instructions that, when executed, cause a computing device to: obtain: a first set of event reports, wherein each event report in the first set of event reports represents a corresponding event that occurred for a first object; and a second set of event reports, wherein each event report in the second set of event reports represents a corresponding event that occurred for a second object different from the first object; use the first set of event reports and the second set of event reports to generate a list of events that occurred for a composite object including the first object and the second object; and use the event list to generate an analysis of user activities for the composite object by performing an analysis process on the events in the event list.
[0198] 20. A tangible computer-readable storage medium according to clause 19, wherein: the event reports in the first event report set and the event reports in the second event report set indicate the corresponding occurrence times of the events represented by the event reports in the first event report set and the event reports in the second event report set; and generating the event list includes sorting the events based on the corresponding occurrence times of the events.
[0199] 21. A tangible computer-readable storage medium according to clause 19 or clause 20, wherein the analysis process includes: performing a clustering process on the events in the event list to generate one or more event clusters; and analyzing the clusters to generate the analysis of the user activity on the composite object.
[0200] 22. The tangible computer-readable storage medium of clause 21, wherein the clustering process comprises generating the one or more event clusters based on respective occurrence times of the events.
[0201] 23. A tangible computer-readable storage medium according to clause 21 or clause 22, wherein analyzing the clusters includes: performing a classification process to determine corresponding classifications of the one or more event clusters, wherein a given classification of a given event cluster indicates whether the given event cluster represents an estimate of a given type of user activity.
[0202] 24. A tangible computer-readable storage medium according to clause 23, wherein the classification process includes: calculating corresponding features of the one or more event clusters; and determining corresponding classifications of the one or more event clusters based on the corresponding features of the one or more event clusters by using a classification model.
[0203] 25. A tangible computer-readable storage medium according to any one of clauses 21 to 24, wherein the clustering process is based on an analysis of the user activity of a given type to be generated, and wherein analyzing the clusters includes analyzing the clusters based on the analysis of the user activity of the given type.
[0204] 26. The tangible computer-readable storage medium of any one of clauses 20 to 25, wherein one or more features of the analysis process are based on the analysis of a given type of the user activity being generated.
[0205] 27. A tangible computer-readable storage medium according to any one of clauses 20 to 26, comprising: performing a selection process to select the first event report set and the second event report set from a plurality of event report sets including the first event report set and the second event report set for obtaining and generating the event list.
[0206] 28. A tangible computer-readable storage medium according to clause 27, wherein the selection process includes: performing a first analysis process on the event represented by the event report in the first event report set to generate a first analysis of user activities for the first object; performing a second analysis process on the event represented by the event report in the second event report set to generate a second analysis of user activities for the second object; and selecting the first event report set and the second event report set based on the first analysis and the second analysis.
[0207] 29. A tangible computer-readable storage medium according to clause 28, wherein: the first analysis process includes performing a clustering process on the events represented by the event reports in the first event report set to generate a first event cluster set; the second analysis process includes performing a clustering process on the events represented by the event reports in the above-mentioned second event report set to generate a second event cluster set; and the selection of the first event report set and the second event report set is based on a comparison between one or more clusters in the first cluster set and one or more clusters in the second cluster set.
[0208] 30. A tangible computer-readable storage medium according to clause 29, wherein the one or more clusters in the first cluster set and the one or more clusters in the second cluster set each span a corresponding time period, and wherein the comparison between the one or more clusters in the first cluster set and the one or more clusters in the second cluster set includes determining whether the corresponding time period of the one or more clusters in the first cluster set overlaps in time with the corresponding time period of the one or more clusters in the second cluster set.
[0209] 31. A tangible computer-readable storage medium according to clause 30, wherein the comparison between the one or more clusters in the first cluster set and the one or more clusters in the second cluster set includes: determining the corresponding classification of a given cluster in the first cluster set and a given cluster in the second cluster set that temporally overlaps with the given cluster in the first cluster set; and determining whether the corresponding classification of at least one of the overlapping clusters meets a predetermined criterion.
[0210] 32. The tangible computer-readable storage medium of any one of clauses 20 to 31, wherein the event occurring for the first object and the event occurring for the second object are events occurring over the same predetermined elapsed time period.
[0211] 33. The tangible computer-readable storage medium of clause 32, wherein the predetermined elapsed period is a fixed-length period or a period of a user activity session.
[0212] 34. The tangible computer-readable storage medium of any one of clauses 20 to 33, wherein the analysis of the user activity with respect to the composite object comprises an indication of whether the user activity corresponds to an estimation of a particular user behavior.
[0213] 35. A tangible computer-readable storage medium according to any one of clauses 20 to 34, wherein the first object and the second object are respective first tradable objects and second tradable objects, and wherein the event represented by the event report in the first event report set involves an order with respect to the first tradable object, and the event represented by the event report in the second event report set involves an order with respect to the second tradable object.
[0214] 36. The tangible computer-readable storage medium of clause 35, wherein the given user behavior comprises market manipulation behavior, such as spoofing, front running, or hype tactics.
[0215] 37. A computing device, comprising: a report obtainer for obtaining: a first event report set, wherein each event report in the first event report set represents a corresponding event occurring for a first object; and a second event report set, wherein each event report in the second event report set represents a corresponding event occurring for a second object different from the first object; a list generator for using the first event report set and the second event report set to generate a list of events occurring for a composite object including the first object and the second object; and an analyzer for using the event list to generate an analysis of user activities for the composite object by performing an analysis process on the events in the event list.
[0216] 38. A computing device according to clause 37, wherein: the event reports in the first event report set and the event reports in the second event report set indicate the corresponding occurrence times of the events represented by the event reports in the first event report set and the event reports in the second event report set; and generating the event list includes sorting the events based on the corresponding occurrence times of the events.
[0217] 39. A computing device according to clause 37 or clause 38, wherein the analysis process includes: performing a clustering process on the events in the event list to generate one or more event clusters; and analyzing the clusters to generate the analysis of the user activity on the composite object.
[0218] 40. The computing device of clause 39, wherein the clustering process comprises generating the one or more event clusters based on respective occurrence times of the events.
[0219] 41. A computing device according to clause 39 or clause 40, wherein analyzing the clusters includes: performing a classification process to determine corresponding classifications for one or more event clusters, wherein a given classification for a given event cluster indicates whether the given event cluster represents an estimate of a given type of user activity.
[0220] 42. A computing device according to clause 41, wherein the classification process includes: calculating corresponding features of the one or more event clusters; and determining corresponding classifications of the one or more event clusters based on the corresponding features of the one or more event clusters by using a classification model.
[0221] 43. A computing device according to any one of clauses 39 to 42, wherein the clustering process is based on an analysis of the user activity of a given type to be generated, and wherein analyzing the clusters includes analyzing the clusters based on an analysis of the user activity of the given type.
[0222] 44. A computing device as described in any of clauses 37 to 43, wherein one or more features of the analysis process are based on the analysis of a given type of user activity to be generated.
[0223] 45. A computing device according to any one of clauses 37 to 44, comprising: performing a selection process to select the first event report set and the second event report set from a plurality of event report sets including the first event report set and the second event report set for obtaining and generating the event list.
[0224] 46. A computing device according to clause 45, wherein the selection process includes: performing a first analysis process for the event represented by the event report in the first event report set to generate a first analysis of user activity for the first object; performing a second analysis process for the event represented by the event report in the second event report set to generate a second analysis of user activity for the second object; and selecting the first event report set and the second event report set based on the first analysis and the second analysis.
[0225] 47. A computing device according to clause 46, wherein: the first analysis process includes performing a clustering process on the events represented by the event reports in the first event report set to generate a first event cluster set; the second analysis process includes performing a clustering process on the events represented by the event reports in the second event report set to generate a second event cluster set; and the selection of the first event report set and the second event report set is based on a comparison between one or more clusters in the first cluster set and one or more clusters in the second cluster set.
[0226] 48. A computing device according to clause 47, wherein the one or more clusters in the first cluster set and the one or more clusters in the second cluster set each span a corresponding time period, and wherein the comparison between the one or more clusters in the first cluster set and the one or more clusters in the second cluster set includes determining whether the corresponding time period of the one or more clusters in the first cluster set overlaps in time with the corresponding time period of the one or more clusters in the second cluster set.
[0227] 49. A computing device according to clause 48, wherein the comparison between the one or more clusters in the first cluster set and the one or more clusters in the second cluster set includes: determining the corresponding classification of a given cluster in the first cluster set and a given cluster in the second cluster set that temporally overlaps with the given cluster in the first cluster set; and determining whether the corresponding classification of at least one of the overlapping clusters meets a predetermined criterion.
[0228] 50. The computing device of any one of clauses 37 to 49, wherein the event occurring for the first object and the event occurring for the second object are events occurring over the same predetermined elapsed time period.
[0229] 51. The computing device of clause 50, wherein the predetermined elapsed period is a fixed-length period or a period of a user activity session.
[0230] 52. The computing device of any one of clauses 37 to 51, wherein the analysis of the user activity with respect to the composite object comprises an indication of an estimate of whether the user activity corresponds to a particular user behavior.
[0231] 53. A computing device according to any one of clauses 37 to 52, wherein the first object and the second object are respectively a first tradable object and a second tradable object, and wherein the event represented by the event report in the first event report set involves an order with respect to the first tradable object, and the event represented by the event report in the second event report set involves an order with respect to the second tradable object.
[0232] 54. A computing device according to clause 53, wherein the given user behavior includes market manipulation behavior, such as spoofing, front running, or hype tactics.
Claims
1. A method comprising: Obtained by the computing device: a first set of event reports, wherein each event report in the first set of event reports represents a corresponding event occurring for a first object; and a second set of event reports, wherein each event report in the second set of event reports represents a corresponding event occurring for a second object different from the first object; generating, by the computing device and using the first event report set and the second event report set, a list of events that occurred for a composite object including the first object and the second object; and An analysis of user activity for the composite object is generated, by the computing device and using the event list, by performing an analysis process for the events in the event list.
2. The method according to claim 1, wherein: The event reports in the first event report set and the event reports in the second event report set indicate respective occurrence times of events represented by the event reports in the first event report set and the event reports in the second event report set; as well as Generating the event list includes sorting the events based on the respective occurrence times of the events.
3. The method according to claim 1, wherein The analysis process includes: performing a clustering process on the events in the event list to generate one or more event clusters; and Clusters are analyzed to generate the analysis of the user activity for the composite object.
4. The method according to claim 3, wherein: The clustering process includes generating the one or more event clusters based on the respective occurrence times of the events.
5. The method according to claim 3, wherein Analyzing the clusters includes: A classification process is performed to determine a corresponding classification for the one or more event clusters, wherein a given classification for a given event cluster indicates whether the given event cluster represents an estimate of a given type of user activity.
6. The method according to claim 5, wherein: The classification process includes: calculating corresponding features of the one or more event clusters; and By using a classification model, respective classifications of the one or more event clusters are determined based on respective features of the one or more event clusters.
7. The method according to claim 3, wherein: The clustering process is based on an analysis of the user activity of a given type to be generated, and wherein analyzing the clusters comprises analyzing the clusters based on the analysis of the user activity of the given type.
8. The method according to claim 1, wherein One or more features of the analysis process are based on the analysis of a given type of user activity to be generated.
9. The method according to claim 1, comprising: A selection process is performed to select the first event report set and the second event report set from a plurality of event report sets including the first event report set and the second event report set for use in obtaining and generating the event list.
10. The method according to claim 9, wherein: The selection process includes: performing a first analysis process on the events represented by the event reports in the first set of event reports to generate a first analysis of user activity on the first object; performing a second analysis process on the events represented by the event reports in the second set of event reports to generate a second analysis of user activity for the second object; and The first set of event reports and the second set of event reports are selected based on the first analysis and the second analysis.
11. The method according to claim 10, wherein: The first analysis process includes performing a clustering process on the events represented by the event reports in the first set of event reports to generate a first set of event clusters; The second analysis process includes performing a clustering process on the events represented by the event reports in the second set of event reports to generate a second set of event clusters; as well as The selection of the first set of event reports and the second set of event reports is based on a comparison between one or more clusters in the first set of clusters and one or more clusters in the second set of clusters.
12. The method according to claim 11, wherein The one or more clusters in the first cluster set and the one or more clusters in the second cluster set each span a corresponding time period, and wherein the comparison between the one or more clusters in the first cluster set and the one or more clusters in the second cluster set includes determining whether the corresponding time period of the one or more clusters in the first cluster set overlaps in time with the corresponding time period of the one or more clusters in the second cluster set.
13. The method according to claim 12, wherein: The comparison between the one or more clusters in the first set of clusters and the one or more clusters in the second set of clusters comprises: determining respective classifications of a given cluster in the first set of clusters and a given cluster in the second set of clusters that temporally overlaps with the given cluster in the first set of clusters; and It is determined whether a corresponding classification of at least one of the overlapping clusters satisfies a predetermined criterion.
14. The method according to claim 1, wherein The event occurring for the first object and the event occurring for the second object are events occurring over the same predetermined elapsed period.
15. The method according to claim 14, wherein The predetermined elapsed period is a period of fixed length or a period of a user activity session.
16. The method according to claim 1, wherein The analysis of the user activity with respect to the composite object includes an indication of whether the user activity corresponds to an estimation of specific user behavior.
17. The method according to claim 1, wherein The first object and the second object are respective first tradable objects and second tradable objects, and wherein the events represented by the event reports in the first event report set relate to orders on the first tradable object, and the events represented by the event reports in the second event report set relate to orders on the second tradable object.
18. The method according to claim 17, wherein: Given user behavior includes market manipulation behaviors such as spoofing, front-running, or hype strategies.
19. A tangible computer-readable storage medium comprising instructions that, when executed, cause a computing device to: get: First incident report set, where Each event report in the first event report set represents a corresponding event occurring for the first object; as well as a second set of event reports, wherein each event report in the second set of event reports represents a corresponding event occurring for a second object different from the first object; generating a list of events occurring for a composite object including the first object and the second object using the first event report set and the second event report set; and Using the event list, an analysis of user activity for the composite object is generated by performing an analysis process for the events in the event list.
20. A computing device comprising: Report obtainer, used to obtain: a first set of event reports, wherein each event report in the first set of event reports represents a corresponding event occurring for a first object; and a second set of event reports, wherein each event report in the second set of event reports represents a corresponding event occurring for a second object different from the first object; a list generator for generating a list of events occurring for a composite object including the first object and the second object using the first event report set and the second event report set; and An analyzer is configured to use the event list to generate an analysis of user activities for the composite object by executing an analysis process for the events in the event list.