Systems and methods for artificial network traffic detection
Patent Information
- Application Number
- BR112025020716
- Authority / Receiving Office
- BR · BR
- Patent Type
- Applications
- Publication Date
- 2026-08-25
Smart Images

Figure 00000000_0000_ABST
Description
1 / 44 “SYSTEMS AND METHODS FOR DETECTING ARTIFICIAL NETWORK TRAFFIC” Cross-reference to related requests
[0001] This application claims priority over U.S. Provisional Application No. 63 / 493,351 filed March 31, 2025, the full disclosure of which is incorporated herein by reference in its entirety. TECHNICAL FIELD
[0002] Several embodiments of the present disclosure generally relate to the identification of risk associated with communications traffic and, more specifically, to the determination of risk scores for destination addresses (e.g., telephone numbers). BACKGROUND
[0003] Communication databases often include a large volume of recipient addresses (e.g., telephone numbers) that can be added to the communication databases from various sources. Frequently, such recipient addresses include valid recipient addresses (e.g., corresponding to user devices) as well as artificial addresses (e.g., corresponding to non-user devices, spoofed addresses, fraudulent addresses, etc.). Transmitting communication to such artificial addresses can be resource-intensive and / or may reduce the trust rating of an entity transmitting such messages.
[0004] The background description provided in the present invention is for the purpose of generally presenting the context of the disclosure. Unless otherwise indicated in the present invention, the materials described in this section are not prior art with respect to the claims in this application and are not admitted to be prior art or suggestions of prior art by inclusion in this section. SUMMARY OF THE DISCLOSURE
[0005] In accordance with certain aspects of the disclosure, methods and systems are revealed to identify risk associated with communication traffic. Petition 870250107395, dated 11 / 24 / 2025, page 7 / 57 2 / 44
[0006] In one aspect, an exemplary embodiment of a method for analyzing communication traffic might include receiving message events; aggregating the message events to generate aggregated message events; receiving a destination address; performing traffic analysis for the destination address based on the aggregated message events, wherein the traffic analysis comprises determining an analyzer score for each of the message events associated with the destination address; calculating a risk score based on the analyzer score for each of the message events associated with the destination address; and performing a risk action for the destination address based on the risk score.
[0007] In another aspect, an exemplary embodiment of a system may include a data storage device that stores processor-readable instructions and a processor operatively connected to the data storage device and configured to execute the instructions to perform operations that may include receiving message events; aggregating the message events to generate aggregated message events; receiving a destination address, performing traffic analysis for the destination address based on the aggregated message events, wherein the traffic analysis comprises determining an analyzer score for each of the message events associated with the destination address; calculating a risk score based on the analyzer score for each of the message events associated with the destination address and performing a risk action for the destination address based on the risk score.
[0008] In another aspect, an exemplary embodiment of a method for managing traffic might include receiving a request for a risk score for a destination address; identifying message events stored in a database and associated with the destination address; receiving parser scores for each of the message events, each parser score being transmitted by a general machine learning model, the general machine learning model transmitting the Petition 870250107395, dated 11 / 24 / 2025, page 8 / 57 3 / 44 parser scores based on outputs from a plurality of criterion machine learning models; calculate a risk score for the destination address based on parser scores for each of the message events; and provide the risk score through an application programming interface (API).
[0009] It should be understood that both the general description above and the following detailed description are merely illustrative and explanatory and are not restrictive of the modalities disclosed, as claimed. BRIEF DESCRIPTION OF THE DRAWINGS
[0010] The attached drawings, which are incorporated into and form part of this descriptive report, illustrate various exemplary embodiments and, together with the description, serve to explain the principles of the embodiments disclosed.
[0011] Figure 1A represents an exemplary system diagram for communication traffic analysis, according to one or more modes.
[0012] Figure 1B represents another illustrative system diagram for communication traffic analysis, according to one or more modes.
[0013] Figure 2 represents a system environment for communication traffic analysis, according to one or more modes.
[0014] Figure 3A represents a flowchart for communication traffic analysis, according to one or more modes.
[0015] Figure 3B represents a flowchart for managing traffic data, according to one or more modalities.
[0016] Figure 4 represents a flow diagram for training a machine learning model, according to one or more modalities.
[0017] Figure 5 represents an example of a computing system, according to one or more modalities. DETAILED DESCRIPTION OF MODALITIES
[0018] In accordance with certain aspects of the disclosure, methods and systems are revealed for traffic analysis to analyze risk associated with traffic of Petition 870250107395, dated 11 / 24 / 2025, page 9 / 57 4 / 44 Communication. As disclosed in the present invention, a risk score can be calculated for one or more communication addresses. The one or more communication addresses can be associated with destination nodes (e.g., recipient). Destination nodes can include valid nodes (e.g., user nodes, user devices, mobile devices, computer devices, personal devices, wearable devices, etc.) and / or artificial nodes (e.g., non-user devices, bot addresses, spoofed addresses, fraudulent addresses, etc.). A risk score can be used to distinguish valid nodes from artificial nodes, as disclosed in the present invention.
[0019] Although telephone numbers are generally discussed in the present invention, the subject matter disclosed in the present invention may apply to any applicable destination address such as, but not limited to, mobile telephone numbers, landline telephone numbers, voice over IP (VOIP) numbers, non-numeric destination addresses, device identifiers, system identifiers, account identifiers, provider identifiers or the like, or a combination thereof.
[0020] According to disclosed implementations, a streaming system can receive and transmit message events to a collector (e.g., a data aggregator). The streaming system can receive message events (e.g., associated with Short Message Service (SMS) messages, mobile messages, push messages, pull messages, in-app messages, etc.) from one or more communication streams that can provide real-time or near-real-time message events to the collector. Message events can include attributes about each respective message event such as, but not limited to, an address (e.g., a phone number) associated with a message, a time associated with a message, source information, or similar, or a combination thereof. The streaming system can be a single data system (e.g., a data broker) or a grouping of data systems (e.g., data brokers).The streaming system can index message events in real time or near real time. Petition 870250107395, dated 11 / 24 / 2025, page 10 / 57 5 / 44 real-time data received from one or more streams and can transmit indexed message events to the collector.
[0021] The collector can aggregate received message events and store them in a database. The database can include current and historical message events in an indexed and / or searchable format so that current and / or historical message events can be accessed by a traffic analyzer. The database can be a structured database (e.g., a Structured Query Language (SQL) based database such as PostgreSQL). The traffic analyzer can analyze the stored message events according to the techniques disclosed in the present invention. The traffic analyzer can provide an analyzer score for a given message event based on the analysis, and the analyzer score can be stored in the database.The parser score for a given message event can be stored in such a way that the parser score is associated with the respective message event (e.g., based on a stored location, a pointer, etc.). Each message event can have a message attribute associated with the message event. For example, each message event can correspond to one or more destination addresses (e.g., phone number, phone numbers, etc.). Therefore, the parser score for a message event can be associated with the message attribute (e.g., destination score) corresponding to the message event.
[0022] According to implementations of the disclosed matter, a client component (e.g., a device, a program, a server, a database, a platform, etc.) can transmit a request for a risk score associated with a destination address. The client component can transmit the request via an application programming interface (API). The API can receive the transmitted request and access a risk calculation service to retrieve the risk score associated with the destination address. The risk calculation service can request the analyzer scores associated with the address. Petition 870250107395, dated 11 / 24 / 2025, page 11 / 57 6 / 44 destination from the database. The database can provide each or a subset of the analyzer scores associated with the destination address to the risk calculation service, based on the request. The risk calculation service can determine a risk score for the destination address based on the analyzer scores provided by the database and associated with the destination address. Therefore, according to the techniques disclosed in the present invention, risk scores for a given destination address can be determined based on one or more analyzer scores associated with the destination address.
[0023] According to other implementations of the disclosed matter, a risk calculation service may request the analyzer scores associated with a destination address from the database. The database may provide each or a subset of the analyzer scores associated with the destination address to the internal risk calculation service, based on the request. The risk calculation service may determine a risk score for the destination address, based on the analyzer scores provided by the database and associated with the destination address. If the risk score exceeds a threshold risk score, communication with the destination address may be blocked (e.g., the destination address may be added to a blacklist).If the risk score is below a second threshold risk score, or below the threshold risk score, communication with the destination address may be enabled without further review (for example, the destination address may be added to a whitelist). A risk score between the second threshold score and the threshold score may cause the destination address to be designated as a monitored address. Communication associated with a monitored address may be restricted, may be further evaluated, or may be flagged as such. For example, one or more additional fraud or risk filters may be applied to such a report before its release.
[0024] Reference to any particular activity is provided in this disclosure. Petition 870250107395, dated 11 / 24 / 2025, p. 12 / 57 7 / 44 for convenience only and not intended to limit disclosure. A person with ordinary skill in the art would recognize that the concepts underlying the devices and methods disclosed can be used in any suitable activity. Disclosure may be understood with reference to the following description and the accompanying drawings, in which similar elements are mentioned with the same reference numerals.
[0025] The terminology used in the present invention may be interpreted in its broadest reasonable manner, although it is being used in combination with a detailed description of certain specific examples of the present disclosure. Indeed, certain terms may even be emphasized below; however, any terminology intended to be interpreted in any restricted manner will be openly and specifically defined as such in this Detailed Description section. Both the general description above and the following detailed description are illustrative and explanatory only and are not restrictive of the features as claimed.
[0026] In this revelation, the term “based on” means “based at least in part on.” The singular forms “a,” “an,” and “the” include plural referents unless the context dictates otherwise. The term “exemplifier” is used in the sense of “example” rather than “ideal.” The terms “comprises,” “comprising,” “includes,” “including,” or other variations thereof are intended to encompass a non-exclusive inclusion, so that a process, method, or product comprising a list of elements does not necessarily include only those elements, but may include other elements not expressly listed or inherent to such process, method, article, or apparatus. The term “or” is used disjunctively, so that “at least one of A or B” includes (A), (B), (A and A), (A and B), etc. Relative terms, such as “substantially,” “approximately,” and “generally,” are used to indicate a possible variation of ±10% from a mentioned or understood value.In this revelation, the term "higher" refers to more, greater than, or even. In this revelation, the term "lower" refers to below, smaller than, or downward. Petition 870250107395, dated 11 / 24 / 2025, p. 13 / 57 8 / 44
[0027] As used in the present invention, a “machine learning model” generally comprises instructions, data, and / or a model configured to receive input and apply one or more weights, biases, classifications, or analyses to the input to generate an output. The output may include, for example, a classification of the input, an analysis based on the input, a design, process, prediction, or recommendation associated with the input, or any other suitable type of output. A machine learning model is generally trained using training data, for example, experiential data and / or input data samples, which are fed into the model to establish, tune, or modify one or more aspects of the model, for example, weights, biases, criteria for forming classifications or groupings, or the like.The aspects of a machine learning model can operate on an input linearly, in parallel, through a network (e.g., a neural network), or through any suitable configuration. The output from a first machine learning model can be provided as an input to a second machine learning model so that the first and second machine learning models can both be used to generate an output.
[0028] The execution of the machine learning model may include the deployment of one or more machine learning techniques, such as linear regression, logistic regression, Random Forest, gradient intensification machine (GBM), deep learning, and / or a deep neural network. Supervised and / or unsupervised training may be employed. For example, supervised learning may include providing training data and labels corresponding to the training data, for example, as ground truth. Unsupervised approaches may include clustering, classification, or similar. K-means or K-nearest neighbors clustering may also be used, which may be supervised or unsupervised. Combinations of K-nearest neighbors and an unsupervised clustering technique may also be used. Any suitable type of training may be used, for example, stochastic, intensification Petition 870250107395, dated 11 / 24 / 2025, page 14 / 57 9 / 44 gradient, random seed, recursive, batch-based or epoch-based, etc.
[0029] Figure 1A represents an exemplary system 100 for analyzing communication traffic using a traffic analyzer 104, according to one or more embodiments, and which can be used with the techniques presented in the present invention. The system 100 may include system components including an external source 120, a streaming system 102, a network 125, a traffic analyzer 104, an API 106, a risk calculation service 108, an analyzer 110, a collector 114 and / or a database 112. Although only one of each of these system components is represented, two or more of any or each of these system components may be implemented according to the techniques disclosed in the present invention. It will be understood that the techniques disclosed in the present invention can be implemented with all or a subset of the system components (e.g., system 100) disclosed herein.
[0030] One or more system components may be connected via a 125 network, using one or more standard communication protocols. The 125 network may be a single network or a combination thereof, including the Internet, a local area network, a private network, or another network. The same 125 network or different 125 networks may facilitate communication between two or more system components, and such communication or networks are not limited by the example shown in the 100 system.
[0031] Some or all of the system components shown in system 100 or system 160 of Figure 1B, as further discussed in the present invention, may include a processor, memory, and / or a network interface. The system components may be or may be implemented using a computer, a system of computers (e.g., rack server(s) and / or a cloud service computer system). Some or all of the system components may run, by one or more processors, an operating system (O / S). A given memory of some or all of the system components may also store one or more instances of a machine learning model (e.g., safe machine learning model, risk machine learning model, sanitation model, etc.) as well as one or Petition 870250107395, dated 11 / 24 / 2025, page 15 / 57 10 / 44 plus model states. Some or all system components may include a network interface which may be a TCP / IP network interface for, for example, Ethernet or wireless communications with the network 125.
[0032] In various embodiments, the 125 network may be a Wide Area Network (“WAN”), a Local Area Network (“LAN”), a Personal Area Network (“PAN”), or similar. In some embodiments, the 125 electronic network includes the Internet, and information and data provided between various systems occurs online. “Online” may mean connecting to or accessing source data or information from a remote location from other devices or networks connected to the Internet. Alternatively, “online” may refer to connecting to or accessing an electronic network (wired or wireless) through a mobile communication device or network. The Internet is a WorldWide system of computer networks – a network of networks in which a party on a computer or other device connected to the network can obtain information from any other computer and communicate with parties on other computers or devices.The most widely used part of the Internet is the World Wide Web (often abbreviated “WWW” or called “the Web”). A “website page” generally encompasses a location, data store, or similar that is, for example, hosted and / or operated by a computer system in order to be accessible online and that may include data configured to cause a program such as a web browser to perform operations such as sending, receiving, or processing data, generating a visual display and / or an interactive interface, or similar.
[0033] Although represented as separate system components in Figure 1A and Figure 1B, it should be understood that a component or portion of a component in exemplary system 100 and / or exemplary system 160 may, in some embodiments, be integrated with or incorporated into one or more other components. Any suitable arrangement and / or integration of the various systems and devices of exemplary system 100 or system 160 may be used.
[0034] Returning to Figure 1A, external sources such as external source 120 can each be different communication flows. Each external source can be associated with one or more types of communication (e.g., SMS messages, Petition 870250107395, dated 11 / 24 / 2025, page 16 / 57 (11 / 44 mobile messages, VOIP messages, internet-based messages, push messages, pull messages, in-app messages, etc.). External sources, such as external source 120, can feed message events to streaming system 102 (e.g., via network 125). Streaming system 102 can provide the message events to collector 114 of traffic analyzer 104. Streaming system 102 can transmit raw message event data to collector 114. Alternatively or in addition, streaming system 102 can perform an action or otherwise transform message events before providing the message events to collector 114. For example, streaming system 102 can index the message events or configure the message events to index before providing the message events to collector 114.
[0035] Collector 114 can aggregate message events received from streaming system 102 (e.g., received via network 125). Collector 114 can store the message events in database 112. Database 112 can be, for example, a relational database and can index and store the message events. As an example, the database can index the message events so that they are stored as associated with one or more message attributes. The message events can be stored so that they are associated with corresponding addresses (e.g., source addresses, destination addresses, etc.) associated with the message events.
[0036] Analyzer 110 can receive indexed message events stored in database 112 and perform traffic analysis based on the indexed message events. Analyzer 110 can analyze the indexed message events to determine an analyzer score for each message event. Analyzer 110 can determine an analyzer score for each message event based on the indexed data associated with the message event, based on indexed data associated with other message events, based on indexed data associated with events. Petition 870250107395, dated 11 / 24 / 2025, page 17 / 57 12 / 44 message having associated or overlapping message properties (e.g., destination addresses, source addresses, timing associated with one or more messages, etc.) and / or similar.
[0037] According to one implementation, analyzer 110 can determine an analyzer score based on a received address count as a received MSISDN_RECEIVED_COUNT (Mobile Station Integrated Services Digital Network) (MSISDN) count. A received MSISDN count can be a count of the number of message events associated with (e.g., received from, transmitted to, or a combination thereof) a given MSISDN. For example, the received MSISDN count can be a count of the number of messages associated with a given MSISDN within a threshold time period (e.g., 24 hours). According to one implementation, a higher MSISDN count or an MSISDN count above a threshold value can result in a higher risk analyzer score.
[0038] According to another implementation, parser 110 can determine a parser score based on a PREFIX_RECEIVED_COUNT. The received prefix count can correspond to the number of message events associated with a given prefix of an address (e.g., an MSISDN). An address prefix can be a given number of initial digits for a given address type (e.g., an MSISDN). For example, an MSISDN might include fifteen digits, and an MSISDN prefix could be the first twelve digits of those fifteen digits. Therefore, the received prefix count can correspond to the number of messages associated with MSISDNs having the first twelve digits of the fifteen-digit MSISDN. The received prefix count can be associated with each of the message events that have the same prefix as an address.According to one implementation, a higher received prefix count or a received prefix count above a threshold value may result in a higher risk analyzer score. Petition 870250107395, dated 11 / 24 / 2025, page 18 / 57 13 / 44
[0039] According to another implementation, parser 110 can determine a parser score based on a PREFIX_ERROR_RATE (prefix error rate). The prefix error rate can be determined for each of the message events associated with a given prefix of an address (e.g., an MSISDN). The prefix error rate can correspond to the number of errors (e.g., undelivered messages, unknown address flag, flagged routing information, etc.) detected for a group of prefix addresses. According to the fifteen-digit MSISDN example provided above, the prefix error count can correspond to the number of errors associated with MSISDNs having the first twelve digits of the fifteen-digit MSISDN. The prefix error rate can be associated with each of the message events that have the same prefix as an address.According to one implementation, a higher prefix error rate or a prefix error rate above a threshold value may result in a higher risk analyzer score.
[0040] According to another implementation, parser 110 can determine a parser score based on an address classification. Parser 110 or another system component of system 100 or system 160 can receive an address classification for an address associated with a message event from an address classification database. The address classification database can be an external source (e.g., external source 120) that can maintain address classifications. An address classification can be, for example, an address classification (e.g., a premium classification, a standard classification, etc.), an address type (e.g., a user address, a user device address, an entity address, etc.), or similar. For example, the address classification for a given address (e.g., a phone number, an MSISDN, etc.)This may indicate that the given address is classified as an entity address (e.g., not associated with a user and / or not configured to receive communication). Consequently, the given address may be associated with a higher risk analyzer score based on the address being a given address. Petition 870250107395, dated 11 / 24 / 2025, page 19 / 57 14 / 44 classified as an entity address.
[0041] An analyzer score for a given message event may be based on one or more analyses performed by analyzer 110. For example, an analyzer score for a given message event may be based on one or more of a received MSISDN count, a received prefix count, a prefix error rate, and / or an address classification. It will be understood that although specific analyses performed by analyzer 110 are disclosed in the present invention, analyzer 110 is not limited to these analyses and one or more other analyses may be performed to determine an analyzer score for a message event. According to one implementation, an analyzer score and / or risk score may be provided by a user or a system component (e.g., through a manual override).In addition to the techniques discussed above, parser scores can be determined based on one or more message types, a certainty (e.g., a certainty score based on a confidence associated with a message event), a timestamp, a customer or entity (e.g., based on a metric provided by the customer, based on association with a customer, etc.), one or more weights, decline (e.g., using a decline coefficient determined based on the length of time a message event is queried and a message timestamp, the decline of which may cause the relevance of the parser score for a given message event to decrease over time), or similar.
[0042] The analyzer score can be determined by incorporating a time factor, which may consider the event time and a decline metric. For example, the time factor may be a product or result of another relationship between the event time mark and a predetermined decline value. The time factor may be modified by a certainty score, for example, as a sum or product with the time factor. The resulting time factor / certainty score metric may be further modified by a weight, for example. Petition 870250107395, dated 11 / 24 / 2025, page 20 / 57 15 / 44 example, using a product, to generate a share of an event. A sum of shares for each relevant event can be the final analyzer score.
[0043] As an example, a parser score for a given message event can be determined based on a corresponding base parser score (e.g., 70, as determined by parser 110), a timestamp (e.g., 5 days prior), a decay coefficient (e.g., -1.11), and weight (e.g., 60). According to this example, a parser score for the given message event can be calculated as: (70 + (5 * -1.11)) * (60 / 100) = 38.67 (Example Calculation 1)
[0044] In Example Calculation 1, the value 70 corresponds to the baseline parser score, the value 5 corresponds to the number of days elapsed based on the time mark, the value -1.11 corresponds to the decay coefficient (e.g., as it can be predetermined or transmitted by a machine learning model), and the value 60 corresponds to the weight (e.g., as it can be determined or transmitted by a machine learning model). As an example, the parser score can be reset after or relative to a time threshold period (e.g., 90 days). Therefore, the parser score can decrease relative to the time threshold period (e.g., decrease to 0 after 90 days).With certain implementations, an analyzer score can decrease faster (e.g., the decline coefficient can be increased) or slower (e.g., the decline coefficient can be decreased) based on given behavior (e.g., actions with negative or undesirable associations).
[0045] According to another example, an analyzer score based on a number of base analyzer scores can be determined based on the following: po nina çã o = ΣΓ=1(peo0ι ' (cin^liseι — de clíni0ι ' Perí0d0i)) (Equation of Example 1)
[0046] In Example Equation 1, n corresponds to the number of analyses of Petition 870250107395, dated 11 / 24 / 2025, page 21 / 57 16 / 44 base that contribute to an analyzer score, weight corresponds to a weight coefficient for iaanalysis, analysis corresponds to the iaanalysis score, decline corresponds to a decline coefficient for iaanalysis, period corresponds to a period (e.g., time that has passed) after the iaanalysis was calculated and / or stored, and can be expressed, for example, as a quantity of time (e.g., days, hours, etc.).
[0047] According to one implementation, if a given parser score exceeds a threshold score, the parser score can be determined to be the threshold score. For example, a parser score determined according to Example Calculation 1 or Example Equation 1 that is greater than 99 can be decreased to or maintained at 99.
[0048] Depending on the implementation, a parser score can be determined based on one or more other factors such as trusted destinations, traffic behavior, etc. For example, if a client confirms that a given destination address is trusted, the score associated with that destination and / or client might be 0. As another example, if the traffic associated with a given time period and / or a given location increases beyond an expected traffic amount by a threshold amount, parser scores for message events based on traffic might be decreased. As another example, if there are unexplained and / or unexpected traffic increases for a given location or network, parser scores for message events associated with such traffic might be increased.
[0049] As used in the present invention, a decline coefficient can determine the rate of decrease of a given analyzer score (e.g., based on a duration of time). For example, a decline coefficient of 1.11 can cause (e.g., linearly) an analyzer score of 100 to decrease to 0 in 90 days.
[0050] As used in the present invention, a weighting coefficient can determine the extent to which a given baseline analyzer score contributes to an analyzer score. A baseline analyzer score can be Petition 870250107395, dated 11 / 24 / 2025, page 22 / 57 17 / 44 multiplied by its corresponding weighting coefficient. For example, if a baseline analyzer score is 80 and its corresponding weighting coefficient is 0.7, then that baseline analyzer score can contribute 56 points to the analyzer score.
[0051] Other weights and / or coefficients may be applied when determining a parser score. For example, a network coefficient may increase or decrease a base parser score based on a target network. A brand coefficient may increase or decrease a base parser score based on a given brand associated with a message event.
[0052] According to implementations, one or more coefficients can be statistically determined based on, for example, traffic patterns and / or behavior. Such coefficients can be based on fraudulent behavior and / or analysis indicating a duration of time during which such behavior is considered fraudulent. One or more coefficients can be determined using machine learning, as discussed in the present invention. For example, one or more weight coefficients can be transmitted by a machine learning model trained to transmit linear or non-linear weight coefficients. The machine learning model can be trained based on historical or simulated data that can be tagged or untagged.
[0053] According to disclosed matter implementations, analyzer 110 can determine an analyzer score based on one or more of the criteria provided below. The following criteria can be used to generate a weight to adjust an analyzer score or a coefficient to adjust a risk score that is based on one or more analyzer scores. As discussed below, one or more criterion machine learning models can be used to transmit criterion-specific weights and / or coefficients.
[0054] Traffic burst, for example, based on a high increase in traffic volume for a given brand and / or mobile network operator (MNO) in a short period of time, a burst score during that period for that Petition 870250107395, dated 11 / 24 / 2025, page 23 / 57 18 / 44 brand and / or MNO may be unfavorable. The traffic volume for a given brand and / or MNO can be determined based on monitoring traffic tagged as being associated with that brand and / or MNO. For example, a brand identifier and / or MNO identifier can be associated with respective messages from a brand and / or MNO. One or more of the components disclosed in the present invention can monitor a number of instances of a respective brand identifier and / or MNO identifier for one or more given time periods (e.g., one hour, one day, one week, one month, etc.). The number of instances can be used to identify traffic volume for the given brand and / or MNO. A weight or coefficient can be transmitted based on the traffic volume. For example, a machine learning model can transmit weight or coefficient based on the number of instances, historical number of instances, expected number of instances, and / or the like.
[0055] Prefix ranges exist or there are sequences within ranges: for example, prefixes (e.g., MSISDN prefixes, as discussed in the present invention) with a high count of distinct destinations or prefixes with destinations having a sequence may indicate artificial traffic and may result in an unfavorable parser score.
[0056] Conversion rate drop: For example, when a conversion rate for a given brand is lower than normal, a conversion rate score may be unfavorable for some destinations for that given brand. Conversion rates can be provided by a brand or MNO and can be fed into a machine learning model trained to assign a weight or coefficient based on them. The machine learning model can assign the weight or coefficient based on the conversion rate, historical conversion rates, expected conversion, conversion rates for one or more other bands, and / or similar.
[0057] Delivery rate drop: for example, when a delivery rate drops due to messages being sent to illegitimate destinations (e.g., fraudulent, artificial, etc.), these destinations may be associated with a score. Petition 870250107395, dated 11 / 24 / 2025, page 24 / 57 19 / 44 unfavorable analyzer. Delivery rates may be determined by a component disclosed in the present invention and / or may be provided by a brand or MNO. Delivery rates may be provided to a machine learning model trained to transmit a weight or coefficient based thereon. The machine learning model may transmit the weight or coefficient based on a delivery rate, historical delivery rates, expected delivery rates, delivery rates for one or more other bands, and / or the like.
[0058] Message destination time clustering: for example, when multiple destinations receive an equal number of messages from a given brand at similar times (e.g., approximately 20 destinations receive approximately 10 messages in approximately 30 minutes), parser scores for such destinations may be unfavorable. Such a number of messages may be determined by a component disclosed in the present invention and / or may be provided by a brand or MNO. Such a number of messages may be provided to a machine learning model trained to transmit a weight or coefficient based thereon. The machine learning model may transmit the weight or coefficient based on a number of such messages, historical messages, expected message numbers, message numbers for one or more other bands, and / or the like.
[0059] Destinations with the same number of messages: for example, destinations with the same number of messages received from a given brand may be associated with an unfavorable analyzer score. Such a number of messages may be determined by a component disclosed in the present invention and / or may be provided by a brand or MNO. Such a number of messages may be provided to a machine learning model trained to transmit a weight or coefficient based on them. The machine learning model may transmit the weight or coefficient based on a number of such messages, historical messages, expected message numbers, message numbers for one or more other bands and / or the like. Petition 870250107395, dated 11 / 24 / 2025, p. 25 / 57 20 / 44
[0060] Message frequency per destination: For example, when messages are sent from a given brand to given destinations repeatedly during a threshold period of time (e.g., destinations that receive a message every day for a week), those destinations may be associated with an unfavorable parser score. Such a number of messages may be determined by a component disclosed in the present invention and / or may be provided by a brand or MNO. Such a number of messages may be provided to a machine learning model trained to transmit a weight or coefficient based on them. The machine learning model may transmit the weight or coefficient based on a number of such messages, historical messages, expected message numbers, message numbers for one or more other bands, and / or the like.
[0061] Destinations in existing suspect bands: for example, destinations that contributed to unfavorable prefix analyses may be associated with a more unfavorable analyzer score than those destinations from that prefix that did not have traffic. Such prefix analyses may be determined by a component disclosed in the present invention and / or may be provided by a brand or MNO. Such prefix analysis may be provided to a machine learning model trained to transmit a weight or coefficient based thereon. The machine learning model may transmit the weight or coefficient based on prefix analysis scores, historical prefix analysis scores, expected prefix analysis scores, prefix analysis scores for one or more other bands, and / or similar.
[0062] Suspicious Destination Types: For example, destinations can be classified into different types based on external sources. Some destination types may be considered suspicious (for example, if a given destination type is classified as premium rate, such destinations should not receive SMS messages). Destinations that correspond to a suspicious type may be associated with unfavorable parser scores. A destination type may be determined by a component disclosed in the present invention and / or may be provided by a brand. Petition 870250107395, dated 11 / 24 / 2025, page 26 / 57 21 / 44 or MNO. Such target type(s) can be provided to a machine learning model trained to transmit a weight or coefficient based on the same. The machine learning model can transmit the weight or coefficient based on target type(s), historical target types, expected target types, target types for one or more other targets, and / or similar.
[0063] Traffic to foreign countries: For example, if there is a significant volume of traffic to foreign countries, or certain predetermined foreign countries, such message events may be associated with unfavorable parser scores. A destination location may be determined by a component disclosed in the present invention and / or may be provided by a brand or MNO. Such destination location(s) may be provided to a machine learning model trained to transmit a weight or coefficient based thereon. The machine learning model may transmit the weight or coefficient based on destination location(s), historical destination locations, expected destination locations, destination locations for one or more other destinations, and / or similar.
[0064] Network-level anomaly: for example, when there is an increase in traffic on a given MNO compared to the market share of that given MNO, destinations associated with that MNO may be associated with unfavorable analyzer scores. Such traffic can be analyzed according to the techniques disclosed in the present invention.
[0065] Available phone numbers: for example, certain websites may provide available phone numbers that change over time. Such phone numbers may be considered fraudulent. Destinations marked as available (e.g., by a third party) may be associated with unfavorable parser scores. Such destination types can be determined according to the techniques disclosed in the present invention.
[0066] Multiple brand interaction: for example, certain websites may provide available phone numbers that rotate over time. One way to detect such rotating phone numbers or such websites may be Petition 870250107395, dated 11 / 24 / 2025, page 27 / 57 22 / 44 based on a sudden jump in the number of messages in relation to multiple brands. Such detected destinations may be associated with unfavorable parser scores. Such types of detected destinations can be determined according to the techniques disclosed in the present invention.
[0067] Port destinations: Port destinations may be considered less risky. For example, destinations that have recently switched their MNO (e.g., are ported to another MNO) may be considered less risky as they are associated with a valid user. Such destinations may be associated with unfavorable parser scores. Such destination types may be determined according to the techniques disclosed in the present invention.
[0068] Destinations with initiated messages: Destinations with initiated messages may be considered lower risk. For example, destinations that have previously sent messages through a trusted platform or had traffic through a trusted client portal may be considered lower risk as they can be associated with a valid user. Such destinations may be associated with a favorable parser score. Such destination types can be determined according to the techniques disclosed in the present invention.
[0069] Conversion information: For example, when the destination has previously reacted / converted based on a message from a given brand, that destination may be considered less risky for future messages, and corresponding parser scores may be favorable. Conversion information for a given destination and / or brand can be determined based on traffic monitoring and traffic interaction by one or more components disclosed in the present invention. For example, a conversion identifier may be associated with respective messages from a brand and / or MNO. One or more of the components disclosed in the present invention may monitor a number of instances of a given conversion identifier (e.g., opened, interacted with, deleted, not opened, etc.) for one or more given time periods (e.g., one hour, one day, one week, one month, etc.). The number of instances can be used to identify conversion rates for the Petition 870250107395, dated 11 / 24 / 2025, page 28 / 57 23 / 44 destination and / or given brand. A weight or coefficient can be transmitted based on conversion rates. For example, a machine learning model can transmit the weight or coefficient based on the number of each type of conversion, historical conversions, expected conversions, and / or similar.
[0070] Destination classified by client as trustworthy: for example, when a trusted client provides information that a given destination belongs to a valid end user, then other scores for those destinations can be ignored and they can be associated with a favorable analyzer score (e.g., 0). Such destination classifications can be determined according to the techniques disclosed in the present invention.
[0071] An analyzer score, as discussed in the present invention, can be a positive or negative analyzer score (e.g., an analyzer score between 0 and 100, an analyzer score between -10 and +10, or any predefined range, etc.). For example, a low received MSISDN count may contribute to a lower analyzer score (e.g., lower risk) whereas a high received MSISDN count may contribute to a higher analyzer score (e.g., higher risk).
[0072] A parser score, as discussed in the present invention, can be transmitted by a machine learning model. The machine learning model can be trained as discussed in the present invention. The machine learning model can be trained to transmit a parser score and / or components that contribute to a parser score. The machine learning model can transmit parser scores or components of parser scores based on inputs including one or more message events, index attributes associated with one or more message events, or similar or a combination thereof. The machine learning model can be trained, for example, based on historical parser scores, historical message events, simulated parser scores, simulated message events, and / or similar. A general machine learning model can receive outputs from one or Petition 870250107395, dated 11 / 24 / 2025, page 29 / 57 24 / 44 plus machine learning models (e.g., one or more criterion machine learning models discussed above). The overall machine learning model can be configured to transmit an overall weight or coefficient based on one or more of the criterion machine learning models.
[0073] According to one implementation, a parser score for a given message event or one associated with a destination address can be calculated if a threshold calculation value is reached. Each type of analysis performed by parser 110 (for example, one or more of a received MSISDN count, a received Prefix count, a Prefix error rate, and / or an address classification) can have a corresponding threshold calculation value. For example, a threshold calculation value for a received MSISDN count might be 3, so if the received MSISDN count is less than 3, then the received MSISDN count may not be considered when determining a parser score for the message event. However, if the received MSISDN count is 3 or higher, then the received MSISDN count may be considered when determining a parser score for the message event.
[0074] Analyzer scores determined by analyzer 110 can be stored in database 112 and can be associated with each message event and / or respective address corresponding to the analyzer scores. Risk calculation service 108 can receive a request to transmit a risk score to a destination address from a client via API 106. Risk calculation service 108 can request the analyzer scores associated with each of the event messages associated with the destination address from database 112. In response, database 112 can transmit the analyzer scores associated with each of the event messages associated with the destination address to risk calculation service 108.
[0075] The 108 risk calculation service can determine a risk score for the destination address based on the analyzer scores associated with the destination address. The risk score can be determined by Petition 870250107395, dated 11 / 24 / 2025, page 30 / 57 25 / 44 aggregate or average each of the analyzer scores associated with the destination address. Alternatively, or in addition, different weights may be applied to different analyzer scores, and a risk score may be determined based on the weighted analyzer scores. For example, the 108 risk calculation service may apply a higher weight to analyzer scores corresponding to the most recent message events and a lower weight to analyzer scores corresponding to less recent message events. Other factors that may determine a weight applied to analyzer scores may include those criteria discussed above and may additionally include customer feedback, observed and / or detected fraud, reported fraud, deviation from expected traffic (e.g., over a period of time), comparison to the same or similar, or a combination thereof.
[0076] According to one implementation, parser scores and / or associated indexed message event information can be provided as inputs to a machine learning model. The machine learning model can be trained to transmit a risk score based on the parser scores and / or associated indexed message event information. The machine learning model can be trained based on, for example, historical parser scores, historical associated indexed message event information, simulated parser scores, simulated associated indexed message event information, or similar.
[0077] Analyzer scores and / or bait scores may be numerical values (e.g., 0-100, 1-10, 0-1, etc.), ratios, percentages, levels (e.g., high, medium, low), or any other applicable designations that may be distinguished from each other based on a risk level. A risk score may be based on analyzer scores associated with a given target address, as disclosed in the present invention. A risk score for an addressed target may be limited to a maximum value (e.g., 100) and / or a minimum value (e.g., 0), such that Petition 870250107395, dated 11 / 24 / 2025, p. 31 / 57 26 / 44 may not exceed the maximum and / or minimum value. A risk score may be a normalized or otherwise manipulated version (e.g., averaged, transformed, summed, etc.) of the combination of analyzer scores associated with a destination address.
[0078] A risk score for a given destination address can be updated based on new message events associated with the risk score. For example, a new message event associated with a destination address might be received in database 112. Analyzer 110 can analyze the new message event (e.g., in combination with other related message events) and can determine an analyzer score for the new message event. Risk calculation service 108 can request updated analyzer scores corresponding to the given destination address and can receive the analyzer score for the new message event. Consequently, a new risk score can be calculated at least in part based on the analyzer score for the new message event.An existing parser score for a message event stored in database 112 can be updated based on new data from streaming system 102. According to one implementation, an existing message event and / or a parser score associated with the existing message event can only be updated if a new parser score is greater than a previous decreased score associated with the message event.
[0079] Figure 1B represents an exemplary system 160 for analyzing communication traffic using traffic analyzer 104, according to one or more modalities and which can be used with the techniques presented in the present invention. System 160 is similar to system 100 of Figure 1A and includes some components that were previously described in reference to system 100. The example provided through system 160 uses an example Kafka streaming system. Although the Kafka streaming system is provided as an example, it will be understood that the subject matter disclosed in the present invention is not limited to Kafka. Petition 870250107395, dated 11 / 24 / 2025, page 32 / 57 27 / 44 and any applicable streaming system 102 can be used to implement the matter disclosed in the present invention.
[0080] As shown, system 160 includes a Kafka Message Events Topic component 120A that can receive message events from external sources (e.g., external source 120 from Figure 1A). The Kafka Message Events Topic component 120A can provide the message events to the streaming system 102 and, more specifically, to a MessageLog-KafkaConsumer component 102A. The MessageLogKafkaConsumer component 102A can communicate with a TrafficFilterService 102B to filter message events based on one or more criteria from streaming system 102. Streaming system 102 can provide message events (e.g., as SignalMessageEvent) to a Kafka SignalsMessage-Events Topic component 102C, which can generate a messageLog and provide the messageLog to the traffic analyzer 104.
[0081] Traffic analyzer 104 can receive the messageLog in a MessageLogQueue 105A which can transmit the messageLog to VolumetricsDequeuer 105B. VolumetricsDequeuer 105B can communicate with BrandDetailsService 105C to determine if the message events included in the messageLog correspond to a given brand. If the message events included in the messageLog correspond to a given brand, then VolumetricsDequeuer 105B can associate the given brand with the message events in the messageLog in an extended messageLog. According to an implementation of the disclosed matter, message events associated with the same brand (e.g., customer, customer ID, an account identifier, etc.) can be analyzed as part of the same brand pool. Therefore, message events associated with distributed services of a given brand can be individually associated with the same brand pool to allow brand-level analysis.Additionally, multiple brands can join a shared event pool so that message events corresponding to brands that are part of the shared pool can each be... Petition 870250107395, dated 11 / 24 / 2025, p. 33 / 57 28 / 44 one, analyzed in light of other message events associated with brands that are part of the shared pool.
[0082] VolumetricsDequeuer 105B can communicate with TrustedTrafficService 105D to determine if the message events included in the messageLog include trusted traffic (e.g., based on a trusted address, trusted content, etc.). VolumetricsDequeuer 105B can associate a trust factor with the message events in the messageLog in the extended messageLog. The extended messageLog can be provided to database 112 in message_log 112H. VolumetricsDequeuer 105B can include input components to determine the MSISDN type (e.g., a premium number, a VoIP number, a landline number, etc.). Communication with VolumetricsDequeuer 105B and / or TrustedTrafficService 105D can be unidirectional.
[0083] Message_log 112H can provide the received extended messageLog to MessageLogProcessingService 104A, which can aggregate and / or index the message events included in the extended messageLog. MessageLogProcessingService 104A can extract prefix information for addresses associated with message events and store it in the Prefix_Range component 112G. MessageLogProcessingService 104A can extract MSISDN information for addresses associated with message events and store it in the Subscriber component 112F. MessageLogProcessingService 104A can aggregate and process the event messages and provide them to the Analysis_Aggregate component 112E, which can provide them to the analyzer 110 and a daily_analysis_aggregate component 112B, as further discussed in the present invention.
[0084] Analyzer 110 can analyze event messages according to the techniques discussed in the present invention. Analyzer 110 can generate analyzer scores associated with message events and can provide the analyzer scores to the Monitored_entity_analysis_event component 112D. Monitored_entity_analysis_event component 112D. It can provide the analyzer scores to the risk calculation service 108 which can Petition 870250107395, dated 11 / 24 / 2025, page 34 / 57 29 / 44 determine risk scores for destination addresses according to the techniques disclosed in the present invention. The risk calculation service 108 can provide risk scores to a client 130 via API 106, as discussed in the present invention. The client 130 can clear a destination address database based on the risk score (e.g., it can remove a destination based on its risk score exceeding a threshold risk score) and / or it can designate a given destination address for future monitoring.
[0085] As discussed in the present invention, traffic to a given destination address can be automatically blocked based on a risk score associated with the destination address. Referring back to Figure 1B, the risk calculation service 108 can provide calculated risk scores to the risk analysis component 112C, which may include a risk_score_results_log and / or a risk_score_analysis_event_log. The risk analysis component 112C can store and / or analyze risk scores that can be used, for example, to train or update a machine learning model. The risk scores can be applied to automatically block outbound traffic by preventing outbound messages from being sent to destination addresses having a risk score higher than a threshold risk score.
[0086] The Daily_analysis_aggegate 112B, as discussed in the present invention, can provide processed event messages to the InternalRiskScoringService 108A. InternalRiskScoringService 108A can also receive analyzer scores from the Monitored_entity_analysis_event component 112D. InternalRiskScoringService 108A can determine internal risk scores for destination addresses. Internal risk scores can be calculated in the same or similar manner to risk scores calculated by the risk calculation service 108. For example, internal risk scores can be calculated based on internal thresholds, whereas risk scores can be calculated based on client-specific thresholds. Internal risk scores can be stored in the internal risk scoring component 112A, which can include an internal_risk_score_history, a Petition 870250107395, dated 11 / 24 / 2025, page 35 / 57 30 / 44 internal_risk_score_event_history, an internal_risk_score_summary and / or similar. Internal risk scores can also be provided to a Kafka Internal Risk Score (IRS) Topics component 102D which can cause them to be stored in clickhouse 102E which may include an internal_risk_score_history, an internal_risk_score_event_history, an internal_risk_score_summary and / or similar.
[0087] Table 1 includes example objects, object types, and object descriptions for objects discussed in the present invention and / or how they can be used to implement the techniques disclosed herein. It will be understood that the objects, object types, and object descriptions in Table 1 are examples only and the implementations disclosed in the present invention are not limited to these example objects, object types, and object descriptions. Object Type Description Monitored entity - entities of interest - MSISDN or prefix range (e.g., approximately 1000 MSISDN numbers) monitored_entity TABLE Parent table for subscriber and prefix_range subscriber TABLE Contains MSISDN entries prefix_range TABLE Contains records for prefix ranges (e.g., approximately the last 3 digits crossed out), so to reach the prefix range entry there may be up to, for example, approximately 1000 subscriber entries. Petition 870250107395, dated 11 / 24 / 2025, page 36 / 57 31 / 44 Message Log / Processing - Log of entries from Kafka and related processing procedures. `message_log` TABLE: Log of filtered and enriched messages from Kafka with a relatively short retention period. `message_log_processing` TABLE: Temporary table for processing messages from the message_log. `copy_message_logs_to_message_log_processing` PROC: Copies message from the message_log to message_log_processing as the first part of message log processing. `create_missing_prefixes` PROC: Part of message log processing, creates a prefix_range entry if it doesn't exist. `create_missing_subscribers` PROC: Part of message log processing, creates a subscriber entry if it doesn't exist. Analysis Aggregate - Aggregated values from ML used to perform analysis. `analysis_aggregate` TABLE: Contains aggregated messages from the message_log and used as an entry point for analysis. Petition 870250107395, dated 11 / 24 / 2025, page 37 / 57 32 / 44 aggregate_message_logs PROC Transform entries from message_log_processing into the analysis_aggregate table as part of scheduled message log processing work. analysis_details TABLE Configurable values for each analysis (weight, decline, etc.) brand_details TABLE Details about brand (e.g., pool type). Internal risk score - pre-formed score daily internally for monitoring and information purposes. daily_analysis_aggregate TABLE Temporary table for IRS containing analysis_aggregate values for the day being analyzed. internal_risk_score_history TABLE Contains all subscriber / MSISDNs with calculated scores grouped by day as a result of IRS. internal_risk_score_summary TABLE Summaries for each day of IRS from internal_risk_score_history - message and subscriber counts, suspicious message and subscriber counts.... Petition 870250107395, dated 11 / 24 / 2025, page 38 / 57 33 / 44 internal_risk_score_event_history TABLE Contains events that were contributing to the score for entries in internal_risk_score_history fill_daily_analysis_aggregate PROC Inserts data from analysis_aggregate into daily_analysis_aggregate as part of internal risk scoring fill_internal_risk_score_summary PROC Generates aggregated entries in the internal_risk_score_summary table based on internal_risk_score_history process_daily_analysis_aggregate_all PROC Entry point function for internal risk scoring that will handle batch organizing and populating internal_risk_score_history based on the daily_analysis_aggregate table Events and analysis - events used for scoring and analysis that generate events Petition 870250107395, dated 11 / 24 / 2025, page 39 / 57 34 / 44 TABLE monitored_entity_analysis_event Events used to calculate scoring; each entry relates to one of the monitored_entity records, referring to MSISDN or prefix range. PROCEDURE analyzes events in the monitored_entity_analysis_event table based on the number of messages received by MSISDN. TABLE analyzes_prefix_error_rate Analysis that generates events in the monitored_entity_analysis_event table based on the number of errors in a prefix range. PROCEDURE analyzes events in the monitored_entity_analysis_event table based on the number of messages received in the prefix range. TABLE risk_score_analysis_event_log related events from risk_score_result_log that contributed to the final score. Petition 870250107395, dated 11 / 24 / 2025, pp. 40 / 57 35 / 44 risk_score_result_log TABLE The final score is recorded in this table for each request so that it can be indented by signal_id column cleanup_analysis_events PROC Deletes all (decayed) events that are no longer relevant from monitored_entity_analysis_event save_analysis_event PROC Inserts or updates monitored_entity_analysis_event Another scheduled_job_reservation TABLE Utility table for synchronizing scheduled jobs decayed_score PROC Up to the function that calculates decayed score value calculate_score_internal PROC Calculates and returns score for single MSISDN Table 1
[0088] Figure 2 represents a system environment 200 for analyzing communication traffic according to the matter disclosed in the present invention. As shown, client 130 can request a risk score via API 106 which communicates with a platform 150. The platform 150 can be a client 130 facing the component used to analyze traffic and / or generate events based on detected patterns. The platform 150 can be connected to external sources 120 such as an SMS firewall component 120B, an MNO partner. Petition 870250107395, dated 11 / 24 / 2025, pp. 41 / 57 36 / 44 120C, an MNO 120D, other third-party sources 120E and / or clients 120F. The platform 150 may receive data from and / or transmit data to external sources 120. Such data may include, but is not limited to, fraudulent numbers 150A, subscriber attributes 150B, subscriber attributes from third-party sources 160C, feedback and trusted users 150D (e.g., feedback that a blocked destination address should not be blocked) or similar.
[0089] Platform 150 can communicate with traffic analyzer 104 which can communicate with streaming system 102, as discussed in the present invention. Unusual behavior 162 (e.g., detection of high-risk destination address score) can be signaled to platform 150 which can communicate the same with client 130 and / or external sources 120.
[0090] Figure 3A represents a flowchart 300 for communication traffic analysis, according to the techniques disclosed in the present invention. In step 302, message events can be received. For example, message events can be received in the traffic analyzer 104 from the streaming system 102, as shown in Figure 1A.
[0091] In step 304, message events can be aggregated. For example, message events can be aggregated in MessageLogProcessingService 104A of Figure 1B. The aggregated message events can be stored in a database (e.g., database 112). The database (e.g., database 112) can associate message events with respective parser scores, as further discussed in the present invention. A parser score association can be linked to a respective message event so that the parser score for the respective message can be transmitted together with the message event and / or message event attributes.
[0092] In step 306, traffic analysis can be performed based on aggregated message events. Traffic analysis can be performed by analyzer 110 of figures 1A and 1B. Analyzer 110 can apply one or more types Petition 870250107395, dated 11 / 24 / 2025, pp. 42 / 57 37 / 44 of analyses to generate analyzer scores based on traffic analysis, as disclosed in the present invention. Analyzer scores can be stored in database 112 and can be associated with respective message events. As discussed in the present invention, one or more machine learning models can be used to transmit an analyzer score for a given message event or multiple analyzer scores for each message event, where multiple analyzer scores are used to transmit the analyzer score for the given message event.
[0093] In step 308, a risk score can be calculated based on the traffic analysis from step 306. For example, a risk score for a destination address can be calculated based on each of the analyzer scores associated with the destination address. A risk score can be generated based on a request received (e.g., via API 106) from a client. Alternatively, or in addition, a risk score can be generated based on an internal trigger. The risk score can be updated periodically, as discussed in the present invention. The risk score can be updated automatically (e.g., after a given amount of time has elapsed), it can be updated based on a trigger event (e.g., receiving a new message event associated with a destination), and / or it can be updated at a rate transmitted by a machine learning model.For example, a rate-update machine learning model can determine a frequency for updating a risk score for a given destination based on attributes associated with the given destination, a risk score for a destination, and / or based on message events associated with the given destination. For example, a given destination having a risk score higher than a risk score threshold might be flagged for more frequent risk score updates compared to a destination having a risk score lower than the risk score threshold. The rate-update machine learning model can be... Petition 870250107395, dated 11 / 24 / 2025, pp. 43 / 57 38 / 44 trained based on historical or simulated destinations, message events, risk scores and / or similar.
[0094] In step 310, a risk action can be performed based on the calculated risk scores. For example, the risk action might include providing the risk score to a customer (e.g., via API 106). As another example, the risk action might include automatically blocking messages from being sent to a destination address based on the risk score. As yet another example, the risk action might include flagging the destination address for future or more frequent risk score review above a current frequency. For example, a risk score above a more stringent threshold might automatically trigger blocking messages to be sent to a respective destination address based on the risk score.A risk score between the first risk score threshold and a less stringent (e.g., lower) risk score threshold may result in the respective destination address being flagged for more frequent risk score analysis above a current frequency. The frequency of risk score analysis can be determined based on a scale ranging from the second risk score threshold to the first risk score threshold. According to this implementation, a destination having a risk score closer in value to the more stringent risk score threshold may correspond to a higher frequency of risk score analysis compared to the frequency of analysis for a destination having a risk score closer in value to the less stringent (e.g., lower) risk score threshold.
[0095] Figure 3B represents a flowchart 320 for managing traffic data. In step 322, a request for a risk score for a destination address can be received. The request can be provided by client 130 of Figure 2, via API 106. The request can be received in the traffic analyzer 104 of Figures 1A-2, as discussed in the present invention.
[0096] In response to receiving the request in step 322, message events are stored in a database (e.g., database 112 Petition 870250107395, dated 11 / 24 / 2025, pp. 44 / 57 39 / 44 of figures 1A and 1B) and associated with the destination address can be identified in step 324. Message events can be identified by querying the database based on the destination address or properties associated with the destination address.
[0097] In step 326, analyzer scores for each of the message events identified in step 324 can be received. The analyzer scores can be received in the risk calculation service 108 of figures 1A and 1B. As discussed in the present invention, each analyzer score of the analyzer scores can be transmitted by a general machine learning model. The general machine learning model can transmit the analyzer scores based on outputs from a plurality of criterion machine learning models.The plurality of criterion machine learning models can generate a criterion machine learning output based on one or more of the following: a traffic burst, a prefix range, a conversion information, a delivery rate, a message destination time grouping, a message destination number, a message frequency, a suspect range, a destination type, a destination location, a network anomaly, a tag interaction, a port destination, an initiated message, and / or a client classification, as discussed in the present invention.
[0098] In step 328, a risk score for the destination address can be calculated based on the parser scores for each of the message events. The risk score can be transmitted by a machine learning model configured to transmit risk scores based on one or more parser scores for a given destination address. The risk score can be based on one or more weights, coefficients, declines, etc., as discussed in the present invention.
[0099] In step 330, the risk score calculated in step 328 can be provided to a customer or component. The risk score can be provided via API 106, as discussed in the present invention. The risk score can be updated based on receiving updated analyzer scores for Petition 870250107395, dated 11 / 24 / 2025, pp. 45 / 57 40 / 44 one or more of the message events and calculation of an updated risk score based on the updated analyzer scores. An updated risk score can be provided, for example, via API 106.
[0100] According to one implementation, the calculation of the updated risk score can be triggered in response to receiving updated parser scores for one or more of the message events. For example, database 112 can be updated to include new message events associated with the destination address. Based on the receipt of the new message events, new parser scores can be received (e.g., in step 326) and an updated risk score can be determined (e.g., in step 328). According to another implementation, an updated risk score can be determined periodically, such as based on the end of a predetermined time. The predetermined time can be transmitted by a machine learning model and can be based on a first risk threshold, a second risk threshold, and / or a current risk score, as discussed in the present invention.
[0101] One or more implementations disclosed in the present invention can be applied using a machine learning model. A machine learning model as disclosed in the present invention can be trained using system 100 of Figure 1A, system 160 of Figure 1B, environment 200 of Figure 2, flowchart 300 of Figure 3A and / or flowchart 320 of Figure 3B. As shown in flowchart 410 of Figure 4, training data 412 may include one or more of the stage inputs 414 and known results 418 related to a machine learning model to be trained. The stage inputs 414 may be from any applicable source including a component or assembly shown in Figures 1A-3. The known results 418 may be included for machine learning models generated based on supervised or semi-supervised training.For example, training data can be tagged (e.g., by one or more users, using an algorithm, based on customer feedback, etc.) as being associated with... Petition 870250107395, dated 11 / 24 / 2025, pp. 46 / 57 41 / 44 Fraud or authorized traffic. The tagged data can be used as annotations to train one or more machine learning models. For example, a first model could be trained using known fraudulent traffic, while a second machine learning model could be trained using known genuine traffic. An unsupervised machine learning model may not be trained using known results 481. Known results 418 may include known or desired outputs for future inputs similar to or in the same category as stage 414 inputs that do not have corresponding known outputs.
[0102] Training data 412 and a training algorithm 420 can be provided to a training component 430 which can apply the training data 412 to the training algorithm 420 to generate a trained machine learning model 450. According to one implementation, the training component 430 may have comparison results 416 that compare a previous output of the corresponding machine learning model to apply the previous result to retrain the machine learning model. The comparison results 416 can be used by the training component 430 to update the corresponding machine learning model.The 420 training algorithm can utilize machine learning networks and / or models including, but not limited to, deep learning networks such as Deep Neural Networks (DNNs), Convolutional Neural Networks (CNNs), Fully Convolutional Networks (FCNs), and Recurrent Neural Networks (RCNs), probabilistic models such as Bayesian Networks and Graphical Models, and / or discriminative models such as Decision Forests and maximum margin methods or similar. The output of the 410 flowchart can be a trained 450 machine learning model.
[0103] It should be understood that the modalities in this disclosure are merely illustrative, and that other modalities may include various combinations of features from other modalities, as well as additional features or fewer features. Petition 870250107395, dated 11 / 24 / 2025, pp. 47 / 57 42 / 44
[0104] In general, any process or operation discussed in this disclosure may be computer-implementable, such as the processes illustrated in Figure 3A, Figure 3B, or Figure 4, and may be executed by one or more processors of a computer system, such as any of the systems or devices in Example System 100 of Figure 1A or Example System 160 of Figure 1B, as described above. A process or process step executed by one or more processors may also be referred to as an operation. The one or more processors may be configured to execute such processes by having access to instructions (e.g., software or computer-readable code) which, when executed by one or more processors, cause the one or more processors to execute the processes. The instructions may be stored in a computer system memory.A processor can be a central processing unit (CPU), a graphics processing unit (GPU), or any suitable type of processing unit.
[0105] A computer system, such as a system or device implementing a process or operation in the examples above, may include one or more computing devices, such as one or more of the systems or devices in Figure 1A and / or Figure 1B. One or more processors of a computer system may be included in a single computing device or distributed among a plurality of computing devices. A computer system memory may include the respective memory of each computing device in the plurality of computing devices.
[0106] Figure 5 is a simplified functional block diagram of a computer system 500 that can be configured as a device to perform the techniques disclosed in the present invention, according to exemplary embodiments of the present disclosure. The computer system 500 can generate resources, statistics, analysis and / or other systems according to exemplary embodiments of the present disclosure. In various embodiments, any of the systems (e.g., computer system 500) disclosed in the present invention can be a hardware assembly including, for example, an interface of Petition 870250107395, dated 11 / 24 / 2025, pp. 48 / 57 43 / 44 data communication 520 for packet data communication. The computer system 500 may also include a central processing unit (“CPU”) 502, in the form of one or more processors, to execute program instructions 524. The computer system 500 may include an internal communication bus 508 and a storage unit 506 (such as ROM, HDD, SSD, etc.) that may store data on a computer-readable medium 522, although the computer system 500 may receive programming and data via network communications (e.g., through a network 125). The computer system 500 may also have a memory 504 (such as RAM) that stores instructions 524 to execute techniques presented in the present invention, although the instructions 524 may be stored temporarily or permanently in other modules of the computer system 500 (e.g., processor 502 and / or computer-readable medium 522).The 500 computer system may also include 512 input / output ports and / or a 510 display for connecting to input / output devices such as keyboards, mice, touch screens, monitors, displays, etc. The various functions of the system may be implemented in a distributed manner across a number of similar platforms to distribute the processing load. Alternatively, the systems may be implemented by appropriate programming of a computer hardware platform.
[0107] Program aspects of technology can be thought of as “products” or “manufactured goods,” typically in the form of executable code and / or associated data that are loaded into or embedded in some type of machine-readable medium. “Storage” media include any and all of the tangible memory of computers, processors, or similar devices, or associated modules thereof, such as various semiconductor memories, tape drives, disk drives, and the like, which can provide non-transient storage at any time for software programming. All or portions of the software can sometimes be communicated via the Internet or various other telecommunication networks. Such communications, for example, can allow software to be loaded from one computer or processor to another, for example, from Petition 870250107395, dated 11 / 24 / 2025, pp. 49 / 57 44 / 44 from a management server or host computer of the mobile communication network on a server's computer platform and / or from a server to the mobile device. Thus, another type of media that may contain the software elements includes optical, electrical, and electromagnetic waves, as used through physical interfaces between local devices, through wired and fixed-number networks, optical networks, and through various air-links. The physical elements that carry such waves, such as wired or wireless links, optical links, or similar, may also be considered as media containing the software. As used in the present invention, unless limited to tangible, non-transient “storage” media, terms such as “machine-readable media” or “computer-readable media” refer to any medium that participates in providing instructions to a processor for execution.
[0108] Although the methods, devices, and systems currently disclosed are described by way of example for transmitting data, it should be recognized that the embodiments currently disclosed may be applicable to any environment, such as a desktop or laptop computer, a mobile device, a wearable device, an application, or the like. Furthermore, the embodiments currently disclosed may be applicable to any type of internet protocol.
[0109] It will be evident to those skilled in the art that various modifications and variations can be made to the disclosed devices and methods without departing from the scope of the disclosure. Other aspects of the disclosure will be evident to those skilled in the art from consideration of the descriptive report and practice of the features disclosed in the present invention. The descriptive report and examples are intended to be considered as illustrative only. Petition 870250107395, dated 11 / 24 / 2025, pp. 50 / 57
Claims
1 / 4 CLAIMS 1. A method for analyzing traffic data, the method being characterized in that it comprises: Receiving message events; Aggregating message events to generate aggregated message events; Receiving a destination address; Performing traffic analysis for the destination address based on the aggregated message events, wherein the traffic analysis comprises determining an analyzer score for each of the message events associated with the destination address; Calculating a risk score based on the analyzer score for each of the message events associated with the destination address; and Performing a risk action for the destination address based on the risk score.
2. A method according to claim 1, characterized in that message events are received from a streaming system.
3. A method according to claim 1, characterized in that the aggregation of message events comprises indexing the message events and storing the indexed message events in a database.
4. A method according to claim 1, characterized in that the aggregation of message events comprises associating at least one subset of the message events with a respective tag.
5. Method, according to claim 1, characterized in that the execution of the risk action comprises transmitting the risk score to a client.
6. Method, according to claim 1, characterized in that the execution of the risk action comprises automatically blocking a destination address based on a risk score that exceeds a risk score threshold.
7. Method, according to claim 1, characterized in that the execution of the risk action comprises signaling a destination address for risk score calculation more frequently than a current frequency.
8. A system, characterized by comprising: A data storage device that stores processor-readable instructions; and A processor operatively connected to the data storage device and configured to execute instructions to perform operations that include: Receiving message events; Aggregating message events to generate aggregated message events; Receiving a destination address; Performing traffic analysis for the destination address based on the aggregated message events, wherein the traffic analysis comprises determining an analyzer score for each of the message events associated with the destination address; Calculating a risk score based on the analyzer score for each of the message events associated with the destination address; and Performing a risk action for the destination address based on the risk score.
9. System according to claim 8, characterized in that message events are received from a streaming system.
10. System according to claim 8, characterized in that the aggregation of message events comprises indexing the message events and storing the indexed message events in a database.
11. System, according to claim 8, characterized in that the aggregation of message events comprises associating at least a subset of the message events with a respective tag.
12. System, according to claim 8, characterized in that the execution of the risk action comprises transmitting the risk score to a client.
13. System, according to claim 8, characterized in that the execution of the risk action comprises automatically blocking a destination address based on a risk score that exceeds a risk score threshold.
14. Method for managing traffic data, the method being characterized by comprising: Receiving a request for a risk score for a destination address; Identifying message events stored in a database and associated with the destination address; Receiving parser scores for each of the message events, each parser score from parser scores issued by a general machine learning model, the general machine learning model issuing parser scores based on outputs from a plurality of criterion machine learning models; Calculating a risk score for the destination address based on the parser scores for each of the message events; and Providing the risk score through an application programming interface (API).
15. Method, according to claim 14, characterized in that the plurality of criterion machine learning models is configured to generate a criterion machine learning output based on one or more of a traffic burst, a prefix range, a conversion information, a delivery rate, a message destination time grouping; a number of destination messages, a message frequency, a suspect range, a destination type; a destination location, a network anomaly, a tag interaction, a port destination, an initiated message or a client classification.
16. A method according to claim 14, characterized in that one or more general machine learning models or a plurality of criteria machine learning models are trained based on historical or simulated data.
17. Method, according to claim 14, characterized in that the request for a risk score is received through the API.
18. A method according to claim 14, characterized in that it comprises: Receiving updated scores from the analyzer for one or more message events; Calculating an updated risk score based on the updated scores from the analyzer; and Providing the updated risk score via the API.
19. Method, according to claim 18, characterized in that the calculation of the updated risk score is triggered in response to receiving the updated scores from the analyzer for one or more of the message events.
20. Method, according to claim 18, characterized in that the calculation of the updated risk score is triggered in response to a predetermined time end. Petition 870250087396, dated 09 / 26 / 2025, pp. 15 / 24