Gamification challenge to detect non-human users

By using a series of gamified challenges based on dynamic geometry and a risk engine monitoring system, the problem of cumbersome and time-consuming existing robot detection methods has been solved. This enables efficient non-human user detection across languages ​​and geographic locations, enhancing the fun and applicability of the challenges.

CN115053220BActive Publication Date: 2026-05-12MICROSOFT TECHNOLOGY LICENSING LLC
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
MICROSOFT TECHNOLOGY LICENSING LLC
Filing Date
2020-10-23
Publication Date
2026-05-12

AI Technical Summary

Technical Problem

Existing robot detection methods are cumbersome and time-consuming for human users, and some methods rely on language, physical location, and education, making them unsuitable for widespread use.

Method used

It employs gamified challenges, displaying random, variable-length sequences of colored and/or angle-oriented geometric objects through a dynamic geometric series of challenges. Combined with a risk engine that monitors user sessions and website usage metrics, the challenge difficulty is dynamically adjusted to detect non-human users.

Benefits of technology

It improves the efficiency and accuracy of robot inspection, reduces the burden on human users, is applicable to various languages ​​and geographical locations, and enhances the fun and appeal of the challenge.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115053220B_ABST
    Figure CN115053220B_ABST
Patent Text Reader

Abstract

When a user suspected of communicating with the website is a bot, present the user with a gamified challenge. The gamified challenge includes a dynamic sequence of sequentially displayed animated set objects that the user should interact with within an assigned amount of time. When the challenge fails and when features extracted from the user session indicate a high suspicion level that the gamified challenge was performed by a non-human user, increase the complexity of the gamified challenge.
Need to check novelty before this filing date? Find Prior Art

Description

Background Technology

[0001] Automated software programs, known as bots, web bots, or robot programs, typically run automated scripts to perform simple tasks faster than humans. Various types of bots exist. The most popular bots are web spiders or crawlers, used by search engines to search for website content in order to generate an index of that content for search engines. Chatbots converse with humans or other robots. Shopping bots search the internet for the best prices for goods.

[0002] However, bots have been used for malicious purposes. They have been used to register free email accounts every minute to send thousands of spam emails. They have been used to participate in online chat rooms to direct participants to advertisements. They have been used to participate in online polls to influence the results in a desired manner. Bots have also been used to impersonate humans to target and persuade people to relinquish or provide sensitive information.

[0003] To combat bots, procedures using assisted tests that can only be passed by human users are employed to detect them. However, some of these tests are cumbersome and time-consuming for humans. Other tests may depend on the user's language, physical location, and education, and are not universally applicable for widespread use. Summary of the Invention

[0004] This summary is provided to introduce, in a simplified form, the selection of concepts that will be further described in the detailed embodiments. This summary is not intended to identify key or essential features of the claimed subject matter, nor is it intended to limit the scope of the claimed subject matter.

[0005] The user interface uses gamification challenges to determine whether the input detected through the interface comes from a human or non-human user. In one aspect, the gamification challenge is based on a dynamic geometry series, displaying random, variable-length sequences of different types of geometric objects. The objects in the sequence are animated, colored, and / or oriented at specific angles. Users must participate in the gamification challenge by repeating the sequence of animated objects in the user interface or by engaging in a geometry-based challenge dynamically indicated by the challenge. For example, instructions might specify that the user only clicks on a jittery red object or a blue square. The challenge is dynamically constructed to ensure that the robot does not detect patterns within the challenge.

[0006] Gamified challenges are used when the user interface suspects that input may originate from a non-human user. This suspicion is based on a risk level that considers several features extracted from user sessions and website usage metrics. A risk engine associated with the website monitors user session communication behavior and usage metrics to generate a risk level based on that behavior.

[0007] Gamified challenges become increasingly difficult when the challenge is failed or when tracked features indicate that the challenge is being actively tampered with. The number of objects in the sequence can be increased, different types of animations can be used, additional geometric objects can be used, and / or the orientation of objects can be changed. Users are given a predetermined amount of time to complete the challenge and / or a pre-configured number of attempts. Within the allocated timeframe, if a user fails to complete the challenge due to a certain number of attempts or failures, the user will be denied any further interaction with the website and will be suspected of being a non-human user.

[0008] These and other features and advantages will become clear from the following detailed description and the accompanying drawings. It should be understood that the foregoing general description and the following detailed description are illustrative only and not limiting of the claimed aspects. Attached Figure Description

[0009] Figure 1 An exemplary system for using gamified challenges to detect non-human users is shown.

[0010] Figure 2 This is an example user interface display showing the creation of a new user account.

[0011] Figures 3A to 3G This is an example user interface display showing the various stages of a gamified challenge.

[0012] Figure 4 This is a flowchart illustrating an exemplary method for using gamified challenges to detect non-human users.

[0013] Figure 5 This is a flowchart illustrating an exemplary method for tracking user behavior and website usage metrics to determine risk levels.

[0014] Figure 6 This is a block diagram illustrating an exemplary operating environment. Detailed Implementation

[0015] Overview

[0016] The disclosed aspects involve various mechanisms for detecting non-human users interacting with a website. The website's user interface uses gamification challenges to determine whether input detected through the user interface comes from a human, a non-human user, or a bot. In one aspect, the gamification challenge is based on a dynamic geometric sequence, displaying a random, variable-length sequence of geometric objects of different types. The objects in the sequence are animated, colored, and / or oriented at specific angles. Users must complete the gamification challenge to gain access to resources or services from the website (such as obtaining a new user account).

[0017] Gamified challenges are used when the user interface suspects that input may be coming from a non-human user. This suspicion is based on a risk level considering factors associated with the user. The risk engine monitors user behavior when accessing website resources / services and overall website usage to determine whether a non-human user is interacting with the user interface.

[0018] The gamified challenge becomes increasingly difficult as the user fails. This can be achieved by increasing the number of objects in the sequence, using different types of animation, adding additional geometric objects, and / or changing the orientation of objects. A predetermined amount of time is given to the user to complete the challenge and / or a pre-configured number of attempts. Within the allocated timeframe, if the user fails the challenge after reaching a threshold number of attempts, the user will be denied any further interaction with the website and will be suspected of being a non-human user.

[0019] Gamified challenges incorporate game elements, making them more engaging and appealing to humans. Geometric objects are well-known shapes, unrestricted by specific languages ​​or geographical locations. Game elements make the challenge fun and enjoyable. The animation of game elements in a sequence is easily understood by human users but challenging for robots.

[0020] Gamification challenges include instructions that tell users how to interact with displayed geometric objects. For example, a gamification challenge might instruct a user to tap a jittery red or blue object or to tap a sequence of objects in a specific order.

[0021] Gamification is different from playing games online. Gamification involves using game design elements in situations that are not designed as games. For example, in one aspect, gamified challenges are used to serve new account requests. Gamified challenges are offered to anonymous users to ensure that the users are human and not bots.

[0022] Now let’s turn our attention to a further discussion of the systems, devices, components and methods used in code completion systems.

[0023] system

[0024] Figure 1A block diagram of an exemplary system 100 in which various aspects of the present invention can be practiced is illustrated. For example... Figure 1 As shown, system 100 includes one or more websites 104A to 104N communicatively coupled to one or more user-electronic devices (i.e., user equipment) 102, all of which are communicatively coupled to a global computer network 108 (such as the Internet). In one aspect, websites 104A to 104N may be part of a cloud service 110. Cloud service 110 may include a risk engine 112 that tracks activities performed within user sessions and websites to generate risk-level activities based on the tracked activities.

[0025] At least one website 104A utilizes gamified challenges during the new user account registration process. Website 104A provides resources and / or services to registered users via the Internet, requiring users to have an account on the website. Resources and / or services may include online software subscription services (e.g., Office 365, etc.), webmail services (e.g., Gmail, Outlook, Yahoo Mail), etc.

[0026] Website 104A includes a user account component 114, a user interface component 116, and a gamified challenge component 118. The user account component 114 maintains a repository of registered user accounts. The user interface component 116 interacts with the user through visual displays to obtain input data and display output data. The user interface component 116 may be part of an operating system. The user interface component 116 can generate web pages for the browser of user device 102 to facilitate communication between user device 102 and website 104A.

[0027] Gamified challenge component 118 interacts with the user to facilitate the challenge. Gamified challenge component 118 provides the user with one or more dynamic challenges, obtains responses from the user, and analyzes the responses. Gamified challenge component 118 can be part of a user interface component.

[0028] Risk Engine 112 monitors activity performed during user sessions and across all websites within the cloud service. The monitored activity is then characterized by several factors, such as the number of times a user challenge failed, the number of times a user exceeded the expected time to complete a challenge, the location of the client device participating in the user session, the reputation of the IP address used to communicate with the website, the browser and browser extensions used, and the time of day the communication was initiated. IP address reputation is based on factors such as the frequency of access to the cloud service from the IP address, the amount of spam generated by the IP address, and the number of DoS attacks attributed to the IP address.

[0029] User account component 114, user interface component 116, gamification challenge component 118, and risk engine 112 can be sequences of computer program instructions that, when executed by a processor, cause the processor to perform methods and / or operations according to a specified task. These components can be implemented as program code, programs, procedures, modules, code segments, program stacks, middleware, firmware, methods, routines, etc. Executable computer program instructions can be implemented according to predefined computer languages, methods, or syntaxes to instruct the computer to perform specific functions. Instructions can be implemented using any suitable high-level, low-level, object-oriented, visual, compiled, and / or interpreted programming language.

[0030] It should be noted that Figure 1 System components are shown in one aspect of an environment in which various aspects of the invention can be implemented. However, they may not be necessary. Figure 1 The exact configuration implementation of the components shown Figure 1 The various aspects and variations of the configuration shown, and the types of components that can be implemented without departing from the spirit or scope of the invention. For example, although Figure 1 It's for creating new user accounts, but Figure 1 The components shown can be applied to other scenarios involving access to resources provided by network-based computing devices, such as user login access, access to web forms, etc. Alternatively, the risk engine 112 can be configured outside of cloud service 110, and in other respects, the risk engine 112 can be part of each website.

[0031] Now let's turn our attention to an exemplary illustration of gamified challenges. In one instance, gamified challenges are used in the registration of new user accounts on a website. (See reference...) Figure 1 and Figure 2 The user interface component 116 receives a request to create a new user account for the website. In response to this request, the user interface component 116 generates a display 200 to obtain a unique personal identifier 202 from the user, such as the user's email address or phone number, which will be used as the account identifier for the user. Once the unique personal identifier 202 is entered, another display 204 is generated for the user to create a password for the account 206.

[0032] User interface component 116 sends a request to risk engine 112 to determine if there is any risk associated with the new account request. For example, the IP address associated with the request may have previously been associated with many failed login attempts, and in this case, gamification challenge component 118 presents the user with a first-level gamification challenge.

[0033] Figure 3A The illustration depicts an exemplary first-level gamified challenge. Figure 3AAs shown, the user display 300 can present a variable-length sequence of dynamically generated random geometric shapes 304, where each geometry is animated. In this particular challenge, the geometry is blinking. However, other animation techniques can also be used, such as bouncing up and down, rotating motion, checkerboard transition effects, ripple effects, lighting effects, horizontal image transition effects, stripe transition effects, or to display motion in some other way.

[0034] Furthermore, the geometric shapes can be displayed in different colors and with specific orientations. Instructions 302 explaining the gamification challenges are displayed on the user screen. For example, gamification challenge 308 appears, indicating that an animated sequence of geometric objects is presented in a specific order. The user must touch the "Start Game" icon 306 and repeat the sequence by touching / clicking each geometric shape in the same order as the shapes displayed in challenge 308.

[0035] like Figure 3A As shown, challenge sequence 308 includes the following geometric objects in the following order: square; circle; circle; hexagon; triangle; triangle; and triangle. Challenge 308 is displayed in the user interface by animing each of the objects shown in display 300 in a specific order. Once the user recognizes the order, the user presses the "Start Game" icon 306 and touches each of the geometric shapes in the same order as the shapes displayed in challenge 308.

[0036] Gamified challenge component 118 tracks sequences input by the user. If the order is correct, it generates a sequence like... Figure 3B The acceptance display 312 shown indicates that the challenge has been passed. (See reference.) Figure 3C If the user enters geometric objects in the wrong order, the gamified challenge component 118 displays an error indicator above the incorrect input 313. For example... Figure 3C As shown, the circle is entered out of order and therefore a large X character is displayed on the circle, and the user can retry 314.

[0037] Alternatively, a pre-configured time limit can be provided to the user to complete the gamified challenge. The time limit applied to the gamified challenge is based on the time typically required for a human user to complete the challenge. If the user does not complete the challenge within the allotted time, the gamified challenge component generates another error display 316, 320 (e.g., ...). Figure 3D (As shown), this indicates that the time limit of 318 has been exceeded. The user can retry at 322. At this point, the user is offered a challenge with an increased level of complexity.

[0038] Increased levels of complexity can include additional geometric objects, different animations, and longer challenge sequences, such as... Figure 3E As shown. Turning Figure 3EIn this display 322, sequence 324 includes seven geometric objects: a triangle; a circle; a square; a hexagon; a hexagon rotated 180 degrees; a triangle rotated 180 degrees; and a diamond shape. Challenge sequence 328 includes the following objects in the following order: a square; a circle; a circle; a hexagon; a hexagon rotated 180 degrees; a hexagon; a triangle; a triangle rotated 180 degrees; a diamond shape; and a square. The user is given another opportunity to initiate the "Start Game" icon 326 to enter the challenge.

[0039] Increased levels of complexity can also include the challenge of adjusting the orientation of geometric objects. Orientation is the angular position of an object relative to a Cartesian coordinate system. (Turn) Figure 3F The example shows user display 330, which has four shapes rotating at a 45-degree angle around the y-axis. Challenge 332 involves each of these rotating geometric objects in a specific sequence of animation processing. The challenge is for the user to identify the rendering order of each of these rotating geometric objects.

[0040] If the user passes the challenge, then... Figure 3B The system accepts and processes new user accounts as shown. If a user repeatedly fails at a geometry challenge beyond a certain number of attempts, the user request is rejected because it was performed by a non-human user. The system can present the user with... Figure 3G The user shown is prompted with error code 32 to notify them of their failed attempt. Error code 328 is displayed, informing the user to try again later. However, the risk engine tracks this user session as suspicious: it may have been performed by a non-human user.

[0041] method

[0042] Attention now turns to the description of various exemplary methods utilizing the systems and devices disclosed herein. The operation of these aspects can be further described with reference to various exemplary methods. It will be understood that, unless otherwise stated, the representative methods do not necessarily have to be performed in the order presented or in any particular order. Furthermore, the various activities described regarding the methods can be performed in a serial or parallel manner or any combination of serial and parallel operations. In one or more aspects, the methods illustrate operation with respect to the systems and devices disclosed herein.

[0043] Turn Figure 1 and Figure 4 An exemplary method 400 utilizing gamified challenges is illustrated. In one aspect, gamified challenges are used to process new user account requests at a website. However, it should be understood that the same techniques presented herein for processing new user account requests can be used in other situations, such as other types of user registration or website visits.

[0044] Website 104A receives a request to initiate a user session with user equipment 102 (box 402).

[0045] Turn Figure 5 A user session is initiated by the web browser of user device 102 through an HTTP request to website 104A. Website 104A generates a session identifier for use during this user session. The session identifier is a unique identifier and is stored as a cookie. Each time the user's browser interacts with the website, it passes the cookie to website 104A. (Collectively referred to as 502)

[0046] During a user session, Risk Engine 112 tracks certain characteristics from the information provided in each request and the actions performed by the requester. These characteristics may be recorded by session identifiers and / or IP addresses. These characteristics may include the IP address of the request source, the geographic location of the request source, the time of day the request was made, the type of browser or browser extension used to make the request, and the IP address reputation. IP addresses associated with malicious activities such as spam, denial-of-service attacks, and fraudulent account creation may be tracked by third-party services available to Risk Engine 112. Risk Engine uses IP addresses to obtain the IP address reputation of the current user session (collectively referred to as Box 504).

[0047] Because certain locations are more likely to be associated with malicious activity, the geographic location of the request source should be considered. The time of day the request is made is important, especially if requests are periodically made simultaneously over a time span. Typically, user-initiated requests are relatively random events without a clear pattern. Automated requests tend to exhibit periodic patterns that occur regularly over a certain time span. The type of browser is important because some browsers or browser extensions are known to have security vulnerabilities that make them easily exploitable. Furthermore, Risk Engine 112 tracks characteristics performed by the user during a user session. For example, Risk Engine 112 can track the number of challenges performed, the number of failed challenge attempts, and the number of timed-out challenge attempts (collectively referred to as Box 504).

[0048] In addition, Risk Engine 112 tracks usage metrics for websites and / or other websites within the cloud service. For example, Risk Engine 112 can collect the number of new account requests and failed login attempts, the number of failed challenges, and the frequency of access to the website by each IP address. These usage metrics are used to gain insights into the current processing load of the website. Repeated failed login attempts or repeated new account requests over a time span can indicate that automation is performing these activities (collectively referred to as Box 506).

[0049] Back Figure 1 and Figure 4Once a user session is established, the user interface component 116 generates a display to obtain the user data required to initiate a new user account. The user interface component 116 receives an email address and / or password from the input data. The new user account component 116 determines whether the email address or phone number associated with the request is already associated with an existing user account. If the email address or phone number is associated with an existing user account, an error message is displayed. (Collectively referred to as box 402)

[0050] Otherwise, when the email address or phone number is not associated with an existing user account and before a new user account is opened, the new user account component 116 checks the requester's reputation by obtaining a risk level from the risk engine 112. The risk level is used to identify the complexity of the gamified challenge.

[0051] (Collectively referred to as box 404).

[0052] Go to Figure 5 The risk level is used to determine the complexity of the challenge and whether it has been tampered with. Risk Engine 112 uses tracked features and metrics to determine the risk level associated with the requester. In one aspect, heuristics can be used to analyze these factors. For example, if the total number of challenges from the website is higher than normal, and these challenges originate from a specific location or IP address, the risk engine will indicate a high risk level. If the IP address associated with the request has been used in malicious activity before, the risk engine will indicate a high risk level. If the requester has made multiple requests over a time span and each challenge attempt has failed, the risk engine will indicate a high risk level. When the heuristic does not associate a high risk level with features and metrics, the risk engine will return a low risk level.

[0053] Alternatively, the risk engine 112 can use heuristics to identify patterns from features and metrics. For example, when new user account requests are routinely generated from the same IP address and the same geographic location at the same time of day, the risk engine will generate a high-risk rating indicating suspicion: the challenge is being tampered with or initiated by a non-human user.

[0054] Back Figure 4 When the risk level is associated with low (boxes 406-Yes, 408), the user account component 114 processes the request. When the risk level is high (boxes 406-No), a first-level gamification challenge is used to determine whether the request is from a non-human user (box 410).

[0055] User interface component 116 initiates gamified challenge component 118 to dynamically generate the first level of gamified challenge, such as Figure 3AThe gamification challenge is shown. If the user passes the first level of the gamification challenge (box 412 - Yes), the user account component 114 continues to process the request (box 408).

[0056] Otherwise (box 412 - No), if the user has not exceeded the threshold number of attempts (box 414 - No), the gamification challenge component 118 continues to add additional levels of complexity to the challenge (box 410). The gamification challenge component 118 can add additional geometry to the challenge, place all geometry in different orientations and / or animations, and increase the length of the challenge sequence. For example, it can use... Figure 3E and 3F Any of the challenges shown. The user is given a certain amount of time to complete the challenge. If the user completes the challenge within the allocated time and the allocated number of attempts (box 412 - Yes, 414 - No), then the user account component 114 continues to process new user account requests (box 408).

[0057] If the user fails the challenge after the assigned number of attempts (box 414 - Yes), the request is rejected (box 416). User interface component 116 can be configured as follows: Figure 3G The user is notified in the user display shown. Additionally, the risk engine 112 tracks rejections (box 416).

[0058] Exemplary operating environment

[0059] Now let’s turn our attention to the discussion of the exemplary operating environment. Figure 6 An exemplary operating environment 600 is illustrated, in which one or more computing devices 602 are used to facilitate gamified challenges. However, it should be noted that the aspects disclosed herein are not limited to any particular configuration of the devices. The computing device 602 may be configured as a cloud service to perform non-human user detection of gamified challenges. It should be noted that the operating environment is not limited to any particular configuration, and other configurations are possible.

[0060] Computing device 602 can be any type of electronic device, such as, but not limited to, mobile devices, personal digital assistants, mobile computing devices, smartphones, cellular phones, handheld computers, servers, server arrays or server farms, web servers, network servers, blade servers, internet servers, workstations, minicomputers, mainframes, supercomputers, network devices, web devices, distributed computing systems, multiprocessor systems, or combinations thereof. Operating environment 400 can be configured in a network environment, a distributed environment, a multiprocessor environment, or in a standalone computing device that can access remote or local storage devices.

[0061] Computing device 602 may include one or more processors 606, one or more communication interfaces 608, one or more storage devices 610, one or more input / output devices 612, and one or more memory devices 614. Processor 606 may be any commercially available or custom processor, possibly including dual-microprocessor and multiprocessor architectures. Communication interface 608 facilitates wired or wireless communication between computing device 602 and other devices. Storage device 610 may be a computer-readable medium that does not contain propagated signals such as modulated data signals transmitted via a carrier wave. Examples of storage devices 610 include, but are not limited to, RAM, ROM, EEPROM, flash memory or other memory technologies, CD-ROM, digital versatile disc (DVD) or other optical storage, magnetic tape cassettes, magnetic tape, disk storage, etc., all of which do not contain propagated signals (such as modulated data signals transmitted via a carrier wave). Multiple storage devices 610 may be present in computing device 602. Input / output devices 612 may include keyboards, mice, pens, voice input devices, touch input devices, displays, speakers, printers, etc., and any combinations thereof.

[0062] Storage device 614 can be any non-transitory computer-readable storage medium capable of storing executable processes, applications, and data. The computer-readable storage medium is not a propagating signal (such as a modulated data signal transmitted via a carrier wave). It can be any type of non-transitory storage device (e.g., random access memory, read-only memory, etc.), magnetic storage, volatile storage, non-volatile storage, optical storage, DVD, CD, floppy disk drive, etc., which is not a propagating signal (such as a modulated data signal transmitted via a carrier wave). Storage device 614 may also include one or more external storage devices or remote storage devices that are not propagating signals (such as modulated data signals transmitted via a carrier wave). Storage device 614 may include an operating system 616, a user account component 618, a user interface component 620, a gamification challenge component 622, a risk engine 624, and other applications and data 626.

[0063] Computing device 602 can be communicatively coupled to network 604. Network 604 can be configured as an ad hoc network, intranet, extranet, virtual private network (VPN), local area network (LAN), wireless LAN (WLAN), wide area network (WAN), wireless WAN (WWAN), metropolitan area network (MAN), the Internet, a portion of the public switched telephone network (PSTN), a conventional telephone service (POTS) network, a wireless network, etc. A network or any other type of network or combination of networks.

[0064] Network 604 may employ a variety of wired and / or wireless communication protocols and / or technologies. The various communication protocols and / or technologies that the network may employ may include, but are not limited to, Global System for Mobile Communications (GSM), General Packet Radio Service (GPRS), Enhanced Data GSM Environment (EDGE), Code Division Multiple Access (CDMA), Wideband Code Division Multiple Access (W-CDMA), Code Division Multiple Access 2000 (CDMA-2000), High-Speed ​​Downlink Packet Access (HSDPA), Long Term Evolution (LTE), Universal Mobile Telecommunications System (UMTS), Evolutionary Data Optimization (Ev-DO), Global Microwave Access Interoperability (WiMax), Time Division Multiple Access (TDMA), Orthogonal Frequency Division Multiplexing (OFDM), Ultra Wideband (UWB), Wireless Application Protocol (WAP), User Datagram Protocol (UDP), Transmission Control Protocol / Internet Protocol (TCP / IP), any part of the Open Systems Interconnection (OSI) model protocol, Session Initiation Protocol / Real-Time Transport Protocol (SIP / RTP), Short Message Service (SMS), Multimedia Messaging Service (MMS), or any other communication protocol and / or technology.

[0065] In one aspect, one or more computing devices in computing device 602 may be part of a cloud service. A cloud service is any service provided by a cloud service provider to a user on demand from the Internet, rather than to the user's local server. Cloud services include online data storage and backup solutions, web-based email services, hosted office suites, document collaboration services, database processing services, technical support services, and so on. Examples of cloud services include Microsoft Azure, Google Cloud, Amazon Web Services, and so on.

[0066] In one aspect, Risk Engine 628 can reside outside of a website or cloud service. In this regard, Risk Engine 628 can utilize additional characteristics and metrics to detect non-human users. Risk Engine 628 can leverage information from malware services tracking IP addresses of malicious activities. Risk Engine 628 can analyze network traffic entering websites and / or cloud services to detect patterns of suspicious activity.

[0067] in conclusion

[0068] Although the subject matter has been described in language specific to structural features and / or methodological actions, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or actions described above. Rather, the specific features and actions described above are disclosed as exemplary forms for implementing the claims.

[0069] A system having one or more processors and a memory is disclosed. The memory contains at least one program configured to be executed by one or more processors. The at least one program includes instructions for: tracking features from a request during a user session for a new user account; generating a risk level based on the tracked features; initiating a gamified challenge before processing the request based on a high risk level, the gamified challenge including a dynamically generated sequence of geometric objects having orientation, color, and animation effects, the gamified challenge having instructions for a user to interact with one or more geometric objects in a specific order over a time span; and rejecting the request after multiple failed attempts at the gamified challenge because the request was initiated by a non-human user.

[0070] In one aspect of the system, the traced features include one or more of the following: IP address, location associated with the IP address, time of day, browser used to initiate the request, or browser extension used by the browser.

[0071] In another aspect of the system, at least one program includes additional instructions for increasing the complexity of the gamification challenge after an attempt to perform the gamification challenge fails. The complexity of the gamification challenge is increased by: increasing the number of geometric objects in the sequence, associating one or more geometric objects in the sequence with different orientations, associating one or more geometric objects in the sequence with different animation effects, or adding different types of geometric objects to the sequence.

[0072] A method is disclosed, comprising: tracking features extracted from a user's request at a computing device providing resources; analyzing the tracked features to determine a risk level of a request associated with a non-human user; generating a gamified challenge based on the analysis indicating a high risk level, the gamified challenge comprising a sequence of geometric objects having orientation, color, and animation effects, the gamified challenge having instructions for a user to interact with one or more geometric objects in a specific order over a time span; and processing the user's request without generating the gamified challenge based on the analysis indicating a low risk level.

[0073] The method also includes increasing the complexity of the gamification challenge when a failed attempt is detected. Increasing the complexity of the gamification challenge further includes increasing the number of geometric objects in the sequence, adding objects of different geometric shapes to the sequence, associating one or more geometric objects in the sequence with different animation effects, or associating one or more geometric objects in the sequence with different orientations. The method also includes rejecting a request when the number of failed attempts at the gamification challenge exceeds a threshold.

[0074] In one aspect, the tracked features include one or more of the following: IP address, location associated with the IP address, time of day, browser used to initiate the request, or browser extensions used by the browser. In another aspect, the tracked features include metrics of computing device usage. The method further includes rejecting the request when the challenge is not completed within a specific time limit.

[0075] A device having a memory coupled to a processor is disclosed. The processor is configured to: receive a request to establish a user session with the device; track features extracted from the established user session; based on the tracked features, generate a first gamification challenge to determine whether a non-human user is communicating in the user session, the first gamification challenge including a first sequence of geometric objects having orientation, color, and animation effects, the first gamification challenge having a first set of instructions for the user to interact with one or more geometric objects in a specific order and within a time limit; if the first gamification challenge fails, generate a second gamification challenge having a different sequence than the first sequence, the different sequence having additional geometric objects and a second set of instructions different from the first set of instructions; and terminate the request if the second gamification challenge subsequently fails.

[0076] In one aspect, the features tracked include one or more of the following: IP address, location associated with the IP address, time of day, browser used to initiate the request, or browser extension used by the browser.

[0077] In one aspect, the second gamification challenge uses different animation effects for each geometric object within the geometric object set compared to the first gamification challenge. In another aspect, the second gamification challenge uses a different orientation to display each geometric object within the geometric object set compared to the first gamification challenge.

[0078] In one aspect, the processor is also configured to use extracted features to determine the risk level associated with the requesting user, with the risk level being high when the extracted features indicate a past history of malicious activity.

[0079] In one aspect, the processor is also configured to use extracted features to determine the risk level associated with the requesting user, with the risk level being high when the extracted features indicate a pattern of repeated failed attempts from a public IP address.

Claims

1. A system comprising: One or more processors; And memory; At least one program, wherein the at least one program is stored in the memory and configured to be executed by the one or more processors, the at least one program comprising instructions for performing the following actions: Receive a request to establish a user session for the new user account; Real-time tracking of features from the request, wherein the tracked features include one or more of the following: IP address, location associated with the IP address, time of day, browser used to initiate the request, browser extension used by the browser, or periodicity of the request over a certain time span; Risk levels are generated based on the features tracked in real time. Based on the high-risk level, a gamified challenge is initiated before processing the request. The gamified challenge includes a dynamically generated sequence of geometric objects displayed in a first order, each geometric object in the sequence having a geometric shape with orientation, color, and animation effects. The gamified challenge has instructions for selecting a chosen geometric object from the geometric objects in a second order, in which the selected geometric object is animated, wherein the second order is different from the first order. Detect interactions with one or more of the geometric objects within the time span; When the detected interaction differs from the second order, a failed attempt is indicated; After detecting multiple failed attempts at the gamified challenge, the request is rejected because it was initiated by a non-human user. as well as After detecting a low risk level, the request is processed without generating the gamified challenge.

2. The system of claim 1, wherein the selected geometric objects comprise common colors and / or common shapes.

3. The system of claim 1, wherein the at least one program includes additional instructions for performing the following actions: After a failed attempt at the gamification challenge, the complexity of the gamification challenge is increased by increasing the number of geometric objects in the sequence.

4. The system of claim 1, wherein the at least one program includes additional instructions for performing the following actions: After a failed attempt at the gamification challenge, the complexity of the gamification challenge is increased by associating one or more geometric objects in the sequence with different orientations.

5. The system of claim 1, wherein the at least one program includes additional instructions for performing the following actions: After a failed attempt at the gamification challenge, the complexity of the gamification challenge is increased by adding different types of geometric objects to the sequence.

6. A method comprising: The features extracted from the user's request are tracked in real time at the computing device that provides the resources; Analyze the features tracked in real time to determine the risk level of the request associated with a non-human user, wherein the tracked features include one or more of the following: IP address, location associated with the IP address, time of day, browser used to initiate the request, browser extension used by the browser, or periodicity of the request over a certain time span. Based on the analysis indicating a high-risk level of the request from a non-human user, a gamified challenge is generated, comprising a sequence of geometric objects displayed in a first order, the geometric objects in the sequence having orientation, color, and animation effects, the gamified challenge having instructions for the user to repeat a second order, in which the geometric objects in the sequence are animated over a time span, wherein the first order is different from the second order; as well as Based on the analysis indicating a low-risk level for the request from a non-human user, the user's request is processed without generating the gamified challenge.

7. The method according to claim 6, further comprising: When a failed attempt is detected at the gamification challenge, the complexity of the gamification challenge is increased.

8. The method of claim 7, wherein increasing the complexity of the gamified challenge further comprises: Increase the number of geometric objects in the sequence, add objects of different types of geometric shapes to the sequence, associate one or more geometric objects in the sequence with different animation effects, or associate one or more geometric objects in the sequence with different orientations.

9. The method according to claim 6, further comprising: The request is rejected when the number of failed attempts at the gamified challenge exceeds a threshold.

10. The method of claim 6, wherein the tracked features include usage metrics of the computing device.

11. The method of claim 6, further comprising: The request is rejected if the challenge is not completed within the stated time span.

12. An apparatus comprising: Memory, coupled to the processor; The processor is configured to perform the following actions: Receive a request to establish a user session with the device; Real-time tracking of features extracted from the established user sessions, wherein the tracked features include one or more of the following: IP address, location associated with the IP address, time of day, browser used to initiate the request, browser extension used by the browser, or periodicity of the request over a certain time span; Based on the features tracked in real time, the extracted features are used to determine the risk level of relevance to the user making the request; Based on a high-risk level, a first gamification challenge is generated to determine whether a non-human user is communicating in the established user session. The first gamification challenge includes a first sequence of geometric objects, each geometric object in the first sequence having orientation, color, and animation effects. The first gamification challenge has a first set of instructions for the user to interact sequentially with a first subset of the geometric objects, in which the first subset of the geometric objects is animated. After the first gamification challenge fails, a second gamification challenge with a different sequence from the first sequence is generated. The different sequence has additional geometric objects and a second set of instructions for the user to interact with a second subset of the geometric objects in sequence, in which the second subset of the geometric objects is animated. The request is terminated upon failure of the subsequent second gamified challenge; as well as After detecting a low risk level, the request is processed without generating the gamified challenge.

13. The device of claim 12, wherein the second gamification challenge uses different animation effects for each geometric object in a second subset of the geometric objects, wherein the first subset is different from the second subset.

14. The device of claim 12, wherein the second gamification challenge uses a different orientation than the first gamification challenge to display objects of each geometry among the objects of the geometry.

15. The device of claim 12, wherein the processor is further configured to perform the following actions: The risk level is high when the extracted features indicate a past history of malicious activity.

16. The device of claim 12, wherein the processor is further configured to perform the following actions: The risk level is high when the extracted features indicate a pattern of repeated failed attempts from public IP addresses.