Method, apparatus and computer program for providing network packet-based user and behavior recognition and service corresponding thereto

Network packet analysis for user and behavior recognition addresses data utilization challenges, enabling effective personalized advertising and customized services while complying with privacy regulations, thus improving advertising industry and telecommunications company performance.

WO2025244190A1PCT designated stage Publication Date: 2025-11-27FAIRY INC
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/KR2024/012707
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-08-26
Filing Date
2024-08-26
Publication Date
2025-11-27

AI Technical Summary

Technical Problem

The advertising industry faces challenges in providing personalized advertising due to restricted data collection and usage, leading to decreased effectiveness, while telecommunications companies struggle with revenue decline despite 5G technology advancements, necessitating new data utilization methods that comply with personal information protection regulations.

Method used

A method and device for network packet-based user and behavior recognition that analyzes network packets to obtain user and behavior information, providing customized services while minimizing legal and PR risks, using a computing device with modules for packet collection, user identification, and behavior extraction, and data utilization.

Benefits of technology

Enables sophisticated user behavior analysis and customized service provision, balancing data utilization with personal information protection, thereby enhancing advertising effectiveness and telecommunications company competitiveness.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2024012707_27112025_PF_FP_ABST
    Figure KR2024012707_27112025_PF_FP_ABST
Patent Text Reader

Abstract

A method, an apparatus, and a computer program for providing network packet-based user and behavior recognition and a service corresponding thereto are provided. The method by which a computing device provides network packet-based user and behavior recognition and a service corresponding thereto, according to various embodiments of the present invention, comprises the steps of: obtaining a network packet transmitted to an Internet network; obtaining user information from the obtained network packet; obtaining behavior information from the obtained network packet; and providing a service corresponding to the obtained user information and the obtained behavior information.
Need to check novelty before this filing date? Find Prior Art

Description

Method, device and computer program for providing network packet-based user and behavior recognition and corresponding service

[0001] Various embodiments of the present disclosure relate to methods, devices and computer programs for providing network packet-based user and behavior recognition and corresponding services.

[0002] The advertising industry has recently faced a major turning point due to the rapidly increasing social demand for personal information protection. Previously, performance marketing, based on users' online behavioral data, dominated the market. This marketing approach boasted high efficiency by tracking users' online activities, analyzing that data, and delivering personalized advertisements. However, strengthened personal information protection has led to significant restrictions on the collection and use of user data, posing significant challenges, particularly for advertisers outside of the platform.

[0003] As data accessibility declines and both the quantity and quality of available data decline, the effectiveness of personalized advertising has significantly declined. The advertising industry is now faced with the imperative to discover new data and find ways to effectively utilize it. In particular, with strengthening data protection regulations, de-identifying user data is gaining attention, but this approach still entails numerous technical and legal challenges.

[0004] Meanwhile, internet service providers are collecting massive amounts of data through their networks, but converting this data into user behavioral data faces several obstacles. First, the quality of the collected data is inconsistent and contains a lot of noise. This noise hinders the accuracy of data analysis and prevents accurate reflection of users' actual behavior. Second, there is a legal and moral responsibility to protect users' personal information. Compliance with personal information protection laws is essential, and violations can result in significant legal penalties and public criticism, potentially leading to PR risks.

[0005] This situation presents a particularly significant challenge for telecommunications companies, which are experiencing slowing revenue growth due to lower-than-expected usage despite the introduction and proliferation of 5G technology. 5G technology offers ultra-high-speed data transmission and low latency, enabling the development of a variety of new services and applications. However, despite these technological possibilities, actual user usage is falling short of expectations. This is making it difficult for telecommunications companies to maintain competitiveness in existing service markets, forcing them to explore new business models and revenue streams.

[0006] The background technology described above is something that the inventor possessed or acquired in the process of deriving the contents of the present disclosure, and cannot necessarily be said to be a publicly known technology disclosed to the general public prior to the present application.

[0007] The problem to be solved by the present disclosure is to provide a method, device and computer program for providing network packet-based user and behavior recognition and corresponding services, which recognize users and behaviors by analyzing network packets transmitted through an Internet network for the purpose of solving the above-described conventional problems, and provide various services, functions and advertisements in response thereto, thereby minimizing legal and PR risks while enabling sophisticated user behavior analysis, and enabling not only the advertising industry but also various online service providers to provide customized services to users while complying with personal information protection regulations, and effectively achieving a balance between personal information protection and data utilization.

[0008] The problems to be solved by the present disclosure are not limited to the problems mentioned above, and other problems not mentioned will be clearly understood by those skilled in the art from the description below.

[0009] In order to solve the above-described problem, a method for providing network packet-based user and behavior recognition and corresponding service according to an embodiment of the present disclosure, performed by a computing device, may include the steps of: obtaining a network packet transmitted to an Internet network; obtaining user information from the obtained network packet; obtaining behavior information from the obtained network packet; and providing a service corresponding to the obtained user information and the obtained behavior information.

[0010] In various embodiments, the step of acquiring the network packet includes the step of acquiring the network packet from a DPI (Deep Packet Inspection) module of a telecommunications company, wherein the acquired network packet may be a duplicate network packet generated as the DPI module of the telecommunications company duplicates a network packet transmitted to the Internet network.

[0011] In various embodiments, the step of obtaining the network packet may include the step of obtaining a duplicate network packet generated by tapping a network packet transmitted and received between a packet gateway of a telecommunications company and the Internet network.

[0012] In various embodiments, the step of obtaining the network packet includes a step of receiving a network packet transmitted to the Internet network through a packet monitoring server separately provided outside the computing device, wherein the transmitted network packet is generated by filtering, through the packet monitoring server, a duplicate network packet generated by tapping a network packet transmitted and received between a DPI (Deep Packet Inspection) module of a telecommunications company or a packet gateway and the Internet network, and may include only information preset by the computing device.

[0013] In various embodiments, the step of obtaining the user information includes the step of obtaining, through a packet filter, address information of a user terminal corresponding to the obtained network packet from the obtained network packet, and the step of obtaining any one piece of user information that matches the obtained address information among a plurality of user information stored in advance, wherein the plurality of user information stored in advance is information that matches the address information of each of the plurality of user terminals as ID information of each of the plurality of user terminals corresponding to each of the plurality of users, and the address information of each of the plurality of user terminals may be information collected from a program installed in each of the plurality of user terminals at a preset interval or whenever the Internet is changed.

[0014] In various embodiments, the step of obtaining the user information includes the step of matching and storing a plurality of strings for each of a plurality of user terminals and a plurality of user information for each user of each of the plurality of user terminals; the step of matching and storing the plurality of strings and the plurality of address information by obtaining the plurality of strings and the plurality of address information for each of the plurality of user terminals from a packet filter; and the step of selecting any one string that matches the extracted specific address information among the plurality of strings when specific address information is extracted from the obtained network packet, and selecting any one user information selected from the plurality of user information, wherein the plurality of strings include random strings generated when the plurality of user terminals are connected to a base station or through a program installed in each of the plurality of user terminals at preset intervals, and the plurality of address information may be address information that is included in a packet generated by a program installed in each of the plurality of user terminals and transmitted to the packet filter, and that matches a random string generated in response to each of the plurality of user terminals.

[0015] In various embodiments, the step of obtaining the user information may include a step of obtaining address information of a user terminal corresponding to the obtained network packet from the obtained network packet through a packet filter, and a step of obtaining user information corresponding to the obtained address information from a telecommunications company, wherein the obtained user information includes at least one of a phone number and ID information corresponding to the user terminal.

[0016] In various embodiments, the step of obtaining the user information may include a step of obtaining address information of the user terminal from the obtained network packet as user information through a packet filter.

[0017] In various embodiments, the step of obtaining the behavior information may include a step of extracting at least one of domain information and IP address information of a destination server of the obtained network packet from the obtained network packet through a packet filter, and a step of obtaining information on the type and usage status of a service executed through a user terminal corresponding to the obtained network packet using the extracted information.

[0018] In various embodiments, the step of obtaining the behavior information may include extracting domain information from the obtained network packet through a packet filter, and, if the obtained network packet is determined to be encrypted traffic, analyzing the obtained network packet to identify a message transmitted from a user terminal corresponding to the obtained network packet, parsing server name indication information (SNI) from the identified message, and obtaining information on the type and usage status of a service executed through the user terminal using the parsed server name indication information.

[0019] In various embodiments, the step of providing the service may include a step of blocking traffic to a user terminal corresponding to the acquired user information or providing a warning notification to a user terminal corresponding to the acquired user information, if the acquired behavioral information is determined to be an entry into a phishing site.

[0020] In various embodiments, the step of providing the service may include the step of selecting at least one advertiser to provide the acquired behavioral information among a plurality of advertisers according to an attribute of the detected event when a preset event is detected based on the acquired behavioral information, and providing the acquired user information and the acquired behavioral information to the selected at least one advertiser.

[0021] In various embodiments, the step of providing the service may include the step of selecting a push token value that matches the address information of the user terminal included in the acquired user information from among a plurality of previously stored push token values, and transmitting a push message to the user terminal corresponding to the acquired user information using the selected push token value.

[0022] In various embodiments, the step of providing the service may include the step of sending an SMS message to a user terminal corresponding to the acquired user information using telephone number information included in the acquired user information.

[0023] A computing device for performing a method for providing network packet-based user and behavior recognition and corresponding service according to another embodiment of the present disclosure for solving the above-described problem includes a processor, a network interface, a memory, and a computer program loaded into the memory and executed by the processor, wherein the computer program may include an instruction for obtaining a network packet transmitted to the Internet, an instruction for obtaining user information from the obtained network packet, an instruction for obtaining behavior information from the obtained network packet, and an instruction for providing a service corresponding to the obtained user information and the obtained behavior information.

[0024] According to another embodiment of the present disclosure for solving the above-described problem, a computer program may be stored in a recording medium readable by a computing device to execute a method for providing network packet-based user and behavior recognition and corresponding service, the method including the steps of: obtaining a network packet transmitted to an Internet network; obtaining user information from the obtained network packet; obtaining behavior information from the obtained network packet; and providing a service corresponding to the obtained user information and the obtained behavior information.

[0025] Other specific details of the present disclosure are included in the detailed description and drawings.

[0026] According to various embodiments of the present disclosure, by analyzing network packets transmitted over the Internet, users and their behaviors are recognized, and various services, functions, and advertisements are provided in response to them, thereby minimizing legal and PR risks while enabling sophisticated user behavior analysis, enabling not only the advertising industry but also various online service providers to provide customized services to users while complying with personal information protection regulations, and effectively achieving a balance between personal information protection and data utilization.

[0027] The effects of the present disclosure are not limited to the effects mentioned above, and other effects not mentioned will be clearly understood by those skilled in the art from the description below.

[0028] The following drawings attached to this specification illustrate preferred embodiments of the present disclosure and, together with the detailed description of the invention, serve to further understand the technical idea of ​​the present disclosure, and therefore, the present disclosure should not be interpreted as being limited to matters described in such drawings.

[0029] FIG. 1 is a diagram illustrating a system that provides network packet-based user and behavior recognition and corresponding services according to one embodiment of the present disclosure.

[0030] FIG. 2 is a diagram illustrating a configuration of a computing device that provides network packet-based user and behavior recognition and corresponding services in various embodiments.

[0031] FIG. 3 is a diagram illustrating a hardware configuration of a computing device according to another embodiment of the present disclosure.

[0032] FIG. 4 is a flowchart of a method for providing network packet-based user and behavior recognition and corresponding services according to another embodiment of the present disclosure.

[0033] Figures 5 to 7 are diagrams illustrating a network packet collection process according to various embodiments.

[0034] FIG. 8 is a flowchart of a first method for obtaining user information from network packets in various embodiments.

[0035] FIGS. 9 and 10 are diagrams illustrating a process of obtaining user information according to the first method in various embodiments.

[0036] Figure 11 is a flowchart of a second method for obtaining user information from network packets.

[0037] Figures 12 and 13 are diagrams illustrating a process of obtaining user information according to the second method.

[0038] FIG. 14 is a flowchart illustrating a method for obtaining behavioral information from network packets in various embodiments.

[0039] FIG. 15 is a diagram illustrating a process for determining the service usage status through domain information matching in various embodiments.

[0040] FIG. 16 and FIG. 17 are diagrams illustrating a process of providing a service corresponding to user information and behavior information in various embodiments.

[0041] The advantages and features of the present disclosure, and methods for achieving them, will become clearer with reference to the embodiments described below in detail with the accompanying drawings. However, the present disclosure is not limited to the embodiments disclosed below and may be implemented in various different forms. These embodiments are provided solely to ensure that the disclosure is complete and to fully inform those skilled in the art of the scope of the present disclosure, and the present disclosure is defined solely by the scope of the claims.

[0042] The terminology used herein is for the purpose of describing embodiments and is not intended to limit the present disclosure. In this specification, singular forms also include plural forms, unless specifically stated otherwise. As used herein, the terms "comprises" and / or "comprising" do not exclude the presence or addition of one or more other components in addition to the components mentioned.

[0043] Throughout this specification, the same reference numerals refer to the same elements, and the term "and / or" includes each and every combination of the elements mentioned. Although terms such as "first," "second," etc. are used to describe various elements, these elements are not limited by these terms. These terms are merely used to distinguish one element from another. Accordingly, it should be understood that a first element mentioned below may also be a second element within the technical scope of the present disclosure.

[0044] The term "part" or "module" as used herein refers to a software or hardware component such as an FPGA or ASIC, and the "part" or "module" performs certain functions. However, the "part" or "module" is not limited to software or hardware. The "part" or "module" may be configured to reside on an addressable storage medium and may be configured to execute one or more processors. Thus, by way of example, the "part" or "module" includes components such as software components, object-oriented software components, class components, and task components, as well as processes, functions, attributes, procedures, subroutines, segments of program code, drivers, firmware, microcode, circuits, data, databases, data structures, tables, arrays, and variables. The functionality provided within the components and "parts" or "modules" may be combined into a smaller number of components and "parts" or "modules" or further separated into additional components and "parts" or "modules."

[0045] Spatially relative terms such as "below," "beneath," "lower," "above," and "upper" can be used to easily describe the relationship between one component and other components as depicted in the drawings. Spatially relative terms should be understood to include different orientations of the components during use or operation in addition to the orientations depicted in the drawings. For example, if a component depicted in the drawings were flipped over, a component described as "below" or "beneath" another component could end up "above" the other component. Thus, the exemplary term "below" can include both the above and below orientations. Components can also be oriented in other directions, and thus spatially relative terms can be interpreted accordingly.

[0046] As used herein, the expressions “first,” “second,” or “first,” “second,” etc., unless the context indicates otherwise, are used to refer to multiple similar objects and to distinguish one object from another, and do not limit the order or importance among the objects.

[0047] As used herein, the expressions "A, B, and C," "A, B, or C," "A, B, and / or C," or "at least one of A, B, and C," "at least one of A, B, or C," "at least one of A, B, and / or C," "at least one selected from A, B, and C," "at least one selected from A, B, or C," "at least one selected from A, B, and / or C," and the like can mean each listed item or all possible combinations of the listed items. For example, "at least one selected from A and B" can refer to (1) A, (2) at least one of A, (3) B, (4) at least one of B, (5) at least one of A and at least one of B, (6) at least one of A and B, (7) at least one of B and A, and (8) both A and B.

[0048] The expression "based on" as used herein is used to describe one or more factors that influence a decision, act of judgment, or action described in a phrase or sentence containing the expression, and this expression does not exclude additional factors that influence the decision, act of judgment, or action.

[0049] As used herein, the expression that a component (e.g., a first component) is “connected” or “connected” to another component (e.g., a second component) may mean that the component is directly connected or connected to the other component, as well as connected or connected via a new other component (e.g., a third component).

[0050] The expression "configured to" used herein may have the meanings of "set to", "having the ability to", "modified to", "made to", "capable of", etc., depending on the context. The expression is not limited to the meaning of "specifically designed in hardware", and for example, a processor configured to perform a specific operation may mean a generic-purpose processor that can perform the specific operation by executing software.

[0051] Unless otherwise defined, all terms (including technical and scientific terms) used herein may be used in their common sense to those of ordinary skill in the art to which this disclosure pertains. Furthermore, terms defined in commonly used dictionaries are not to be interpreted ideally or excessively unless explicitly and specifically defined otherwise.

[0052] In this specification, the term "computer" refers to any type of hardware device including at least one processor, and may also be understood to encompass software components operating on the hardware device, depending on the embodiment. For example, the term "computer" may be understood to encompass, but is not limited to, smartphones, tablet PCs, desktops, laptops, and all user clients and applications running on each device.

[0053] Hereinafter, embodiments of the present disclosure will be described in detail with reference to the attached drawings.

[0054] Although each step described in this specification is described as being performed by a computer, the subject of each step is not limited thereto, and at least some of each step may be performed by different devices depending on the embodiment.

[0055]

[0056] FIG. 1 is a diagram illustrating a system that provides network packet-based user and behavior recognition and corresponding services according to one embodiment of the present disclosure.

[0057] Referring to FIG. 1, a system for providing network packet-based user and behavior recognition and corresponding services according to one embodiment of the present disclosure may include a computing device (100), a user terminal (200), an external server (300), and a network (400).

[0058] Here, the system for providing network packet-based user and behavior recognition and corresponding services illustrated in FIG. 1 is according to one embodiment, and its components are not limited to the embodiment illustrated in FIG. 1, and may be added, changed, or deleted as needed.

[0059] In one embodiment, the computing device (100) can provide network packet-based user and behavior recognition and corresponding services. To this end, the computing device (100) may include, but is not limited to, a network packet collection module (110), a user / device identification module (120), a behavior information extraction module (130), and a data utilization module (140), as illustrated in FIG. 2 .

[0060] The network packet collection module (110) can acquire network packets transmitted to the Internet. Here, the network packets may include, but are not limited to, network packets transmitted from a PGW (Packet Gateway) to the Internet, network packets transmitted from a PGW to the Internet via a telecommunications company's DPI (Deep Packet Inspection) module (or a separate DPI server), and / or network packets transmitted from a Wi-Fi router to the Internet.

[0061] The user / device identification module (120) can obtain user information from network packets collected through the network packet collection module (110), and identify the user and / or device accordingly. For example, the user / device identification module (120) can extract address information from network packets, obtain the ID of the user / device corresponding to the extracted address information, and thereby specify the user and / or user terminal (200).

[0062] The behavioral information extraction module (130) can obtain behavioral information from network packets collected through the network packet collection module (110). For example, the behavioral information extraction module (130) can extract domain information from network packets, and based on the extracted domain information, can derive information regarding the type of service used by the user and the usage status of that service as user behavioral information.

[0063] The data utilization module (140) may provide services and / or functions corresponding to user information acquired through the user / device identification module (120) and behavioral information acquired through the behavioral information extraction module (130). For example, the data utilization module (140) may provide, but is not limited to, an anti-phishing service / function, a service / function for selling data as a DMP operator, a service / function for selling data to a DMP operator, and a notification service / function.

[0064] In various embodiments, the computing device (100) may be connected to a user terminal (200) via a network (400) and may provide network packet-based user and behavior recognition and corresponding services to the user terminal (200).

[0065] Here, the user terminal (200) may refer to any type of entity(ies) in a system having a mechanism for communicating with the computing device (100). For example, the user terminal (200) may include a personal computer (PC), a notebook, a mobile terminal, a smart phone, a tablet PC, a wearable device, etc., and may include all types of terminals capable of connecting to a wired / wireless network. In addition, the user terminal (200) may include any computing device implemented by at least one of an agent, an Application Programming Interface (API), and a plug-in. In addition, the user terminal (200) may include an application source and / or a client application.

[0066] In addition, here, the network (400) may refer to a connection structure that enables information exchange between each node, such as a plurality of terminals and servers. For example, the network (400) may include a local area network (LAN), a wide area network (WAN), the Internet (WWW), a wired and wireless data communication network, a telephone network, a wired and wireless television communication network, a controller area network (CAN), and Ethernet.

[0067] Wireless data communication networks may include, but are not limited to, 3G, 4G, 5G, 3GPP (3rd Generation Partnership Project), 5GPP (5th Generation Partnership Project), LTE (Long Term Evolution), WIMAX (World Interoperability for Microwave Access), Wi-Fi, the Internet, LAN (Local Area Network), Wireless LAN (Wireless Local Area Network), WAN (Wide Area Network), PAN (Personal Area Network), RF (Radio Frequency), Bluetooth network, NFC (Near-Field Communication) network, satellite broadcasting network, analog broadcasting network, DMB (Digital Multimedia Broadcasting) network, etc.

[0068] In various embodiments, the computing device (100) may be connected to an external server (300) via a network (400), and may receive various information and data necessary for performing user identification and behavioral data extraction using network packets and a service provision method utilizing the same from the external server (300).

[0069] For example, the external server (300) may be a telecommunications company server, and may receive network packets transmitted from user terminals (200) to the Internet network from the telecommunications company server and / or network packets received from the Internet network to the user terminals (200), or may be provided with information about a plurality of users and user terminals (200) of a plurality of users.

[0070] As another example, the external server (300) may be a packet monitoring server (e.g., FIG. 7) that monitors network packets transmitted and received over the Internet in real time and extracts only necessary information from the network packets or filters out unnecessary information.

[0071] As another example, the external server (300) may be a trigger server (e.g., FIG. 16) that stores events set by advertisers and advertiser information, selects advertisers to whom information extracted from network packets will be delivered based on events detected from network packets, and delivers information to the advertisers accordingly. However, the present invention is not limited thereto. Hereinafter, with reference to FIG. 3, a more detailed description will be given of the hardware configuration of a computing device (100) that performs a method for providing network packet-based user and behavior recognition and corresponding services.

[0072]

[0073] FIG. 3 is a diagram illustrating a hardware configuration of a computing device according to another embodiment of the present disclosure.

[0074] Referring to FIG. 3, in another embodiment of the present disclosure, a computing device (100) may include one or more processors (101), a memory (102) for loading a computer program (105A) to be executed by the processor (101), a bus (103), a communication interface (104), and a storage (105) for storing the computer program (105A).

[0075] Here, only components related to the embodiment of the present disclosure are illustrated in FIG. 3. Therefore, those skilled in the art will appreciate that other general components may be included in addition to the components illustrated in FIG. 3.

[0076] The processor (101) controls the overall operation of each component of the computing device (100). The processor (101) may be configured to include a CPU (Central Processing Unit), an MPU (Micro Processor Unit), an MCU (Micro Controller Unit), a GPU (Graphics Processing Unit), or any other type of processor well known in the art of the present disclosure.

[0077] Additionally, the processor (101) may perform operations for at least one application or program for executing a method according to embodiments of the present disclosure, and the computing device (100) may have one or more processors.

[0078] In various embodiments, the processor (101) may further include a Random Access Memory (RAM) (not shown) and a Read-Only Memory (ROM) (not shown) that temporarily and / or permanently store signals (or data) processed within the processor (101). In addition, the processor (101) may be implemented in the form of a System on Chip (SoC) that includes at least one of a graphics processing unit, RAM, and ROM.

[0079] The memory (102) stores various data, commands, and / or information. The memory (102) can load a computer program (105A) from the storage (105) to execute methods / operations according to various embodiments of the present disclosure. When the computer program (105A) is loaded into the memory (102), the processor (101) can perform the method / operation by executing one or more instructions constituting the computer program (105A). The memory (102) may be implemented as a volatile memory such as RAM, but the technical scope of the present disclosure is not limited thereto.

[0080] The bus (103) provides a communication function between components of the computing device (100). The bus (103) can be implemented as various types of buses such as an address bus, a data bus, and a control bus.

[0081] The communication interface (104) supports wired and wireless Internet communication of the computing device (100). Furthermore, the communication interface (104) may support various communication methods other than Internet communication. To this end, the communication interface (104) may be configured to include a communication module well known in the technical field of the present disclosure. In some embodiments, the communication interface (104) may be omitted.

[0082] Storage (105) can non-temporarily store a computer program (105A). When performing a process of providing network packet-based user and behavior recognition and corresponding services through a computing device (100), storage (105) can store various information necessary to provide a process of network packet-based user and behavior recognition and corresponding services.

[0083] Storage (105) may be configured to include non-volatile memory such as ROM (Read Only Memory), EPROM (Erasable Programmable ROM), EEPROM (Electrically Erasable Programmable ROM), flash memory, a hard disk, a removable disk, or any form of computer-readable recording medium well known in the art to which the present disclosure pertains.

[0084] The computer program (105A) may include one or more instructions that, when loaded into the memory (102), cause the processor (101) to perform a method / operation according to various embodiments of the present disclosure. That is, the processor (101) may perform the method / operation according to various embodiments of the present disclosure by executing the one or more instructions.

[0085] In one embodiment, the computer program (105A) may include one or more instructions for performing a method of network packet-based user and behavior recognition and providing a service corresponding thereto, including the steps of obtaining a network packet transmitted over an Internet network, obtaining user information from the obtained network packet, obtaining behavior information from the obtained network packet, and providing a service corresponding to the obtained user information and the obtained behavior information.

[0086] The steps of a method or algorithm described in connection with the embodiments of the present disclosure may be implemented directly in hardware, implemented as a software module executed by hardware, or implemented by a combination thereof. The software module may reside in a random access memory (RAM), a read only memory (ROM), an erasable programmable ROM (EPROM), an electrically erasable programmable ROM (EEPROM), a flash memory, a hard disk, a removable disk, a CD-ROM, or any other form of computer-readable recording medium well known in the art to which the present disclosure pertains.

[0087] The components of the present disclosure may be implemented as a program (or application) to be executed in conjunction with a computer as hardware and stored on a medium. The components of the present disclosure may be implemented as software programming or software elements, and similarly, the embodiments may be implemented in a programming or scripting language such as C, C++, Java, assembler, etc., including various algorithms implemented as a combination of data structures, processes, routines, or other programming components. Functional aspects may be implemented as algorithms executed on one or more processors. Hereinafter, with reference to FIGS. 4 to 17, a method for providing network packet-based user and behavior recognition and corresponding services performed by a computing device (100) will be described.

[0088]

[0089] FIG. 4 is a flowchart of a method for providing network packet-based user and behavior recognition and corresponding services according to another embodiment of the present disclosure.

[0090] Referring to FIG. 4, at step S110, the computing device (100) can obtain a network packet transmitted to the Internet network.

[0091] In various embodiments, the computing device (100) may obtain network packets transmitted to the Internet in an environment connected to a wireless network.

[0092] In various embodiments, the computing device (100) can obtain network packets transmitted over the Internet network in their original form.

[0093] For example, the computing device (100) can obtain a network packet from a DPI module of a telecommunications company, as illustrated in FIG. 5.

[0094] Here, the network packet obtained from the DPI module of the communication server (300) may be a duplicate network packet generated as the DPI module of the communication server (300) duplicates a network packet transmitted to the Internet network (400).

[0095] In addition, here, the DPI module may be a module that uses network traffic analysis technology to deeply inspect network packets to determine what type of data is being transmitted, and may be installed and operated by a telecommunications company, but is not limited thereto.

[0096] As another example, the computing device (100) can obtain network packets transmitted and received between a packet gateway of a telecommunications company and an Internet network (400), as illustrated in FIG. 6. For example, the computing device (100) can obtain duplicate network packets generated by tapping network packets transmitted and received between the packet gateway and the Internet network (400).

[0097] Here, tapping means intercepting and copying or monitoring data on the network, and the main methods include, but are not limited to, port mirroring, which replicates traffic from a specific port on a network switch to another port; network TAP (Test Access Point), which intercepts traffic by physically inserting a separate device into the network link; and packet sniffing, which receives packets and analyzes them on a network card.

[0098] In various embodiments, the computing device (100) can selectively obtain only the necessary portions from network packets transmitted over the Internet.

[0099] For example, the computing device (100) can receive network packets transmitted to the Internet network (400) through a packet monitoring server, as illustrated in FIG. 7.

[0100] Here, the packet monitoring server is separately provided outside the computing device (100) and may mean a server that monitors network packets transmitted and received between the DPI module or packet gateway of the communication company server (300) and the Internet network (400).

[0101] In addition, the network packets transmitted through the packet monitoring server may include only information preset by the computing device (100) by filtering through the packet monitoring server the duplicate network packets generated by tapping the network packets transmitted and received between the DPI module or packet gateway of the communication company server (300) and the Internet network (400). For example, the network packets filtered through the packet monitoring server may include, but are not limited to, Address (or Device ID), Packet Body (in case of UDP), IP Packet Header (in case of TCP), IP destination address, Protocol, Port # (Source, Destination).

[0102] Here, the computing device (100) is described as acquiring a network packet in a situation where a wireless network is connected, but is not limited thereto, and in the case of a wired network, a network packet can be acquired by replicating a network packet transmitted and received to and from the Internet network based on tapping.

[0103] In various embodiments, the computing device (100) may acquire network packets at predetermined intervals.

[0104] In various embodiments, the computing device (100) may continuously acquire network packets over a predetermined period of time.

[0105] In various embodiments, the computing device (100) acquires network packets at predetermined intervals, and when a network packet corresponding to a preset event is acquired, the computing device (100) can continuously acquire network packets for a predetermined period of time from the time the network packet is acquired.

[0106] At step S120, the computing device (100) can obtain user information from the network packet obtained through step S110. This will be described in more detail below with reference to FIGS. 8 to 13.

[0107]

[0108] FIG. 8 is a flowchart of a first method for obtaining user information from a network packet in various embodiments, and FIGS. 9 and 10 are diagrams illustrating a process for obtaining user information according to the first method in various embodiments.

[0109] Referring to FIGS. 8 to 10, in step S210, the computing device (100) can obtain address information of a user terminal (200) corresponding to a network packet from a network packet.

[0110] In addition, here, the address information of the user terminal (200) may be the address (e.g., IP Source Address and / or Mac Address) of the user terminal (200), but is not limited thereto, and the address information of the user terminal (200) may include all / part of the Port # and IP Packet header. For example, the address information of the user terminal (200) may include IP source address, IP destination address, source port, destination port, and protocol, which are called 5-tuple, but is not limited thereto.

[0111] In various embodiments, the computing device (100) can obtain address information of a user terminal (200) corresponding to a network packet from a network packet through a packet filter.

[0112] Here, a packet filter may mean a filter that analyzes network packets and extracts specific information from the network packets.

[0113] Such a packet filter is provided inside the computing device (100), and can be implemented in a form that analyzes network packets inside the computing device (100) and extracts address information of the user terminal (200) by obtaining network packets and control commands from the computing device (100). However, the packet filter is not limited thereto, and can be provided as a separate component outside the computing device (100), and can be implemented in a form that obtains network packets transmitted to the Internet, extracts address information of the user terminal (200) from the obtained network packets, and transmits only the extracted address information to the computing device (100).

[0114] At step S220, the computing device (100) can obtain user information corresponding to the address information obtained through step S210.

[0115] For example, as illustrated in FIG. 9, when address information of a user terminal (200) is obtained from a network packet, the computing device (100) may obtain one user information that matches the address information obtained from the network packet among a plurality of user information stored in a user / device ID mapping database (DB).

[0116] Here, user information may refer to information necessary for user identification. For example, user information may include, but is not limited to, a mobile phone number matched with the IP address of the user terminal (200), ID information of the user and / or the user terminal (200) (e.g., device ID or user ID information matched with the IP address of the user terminal (200) (e.g., Google ADID, Apple IDFA, UID2.0, etc.)).

[0117] In addition, here, the plurality of user information previously stored in the user / device ID mapping database (DB) may be information matching the address information of each of the plurality of user terminals (200) corresponding to each of the plurality of users, such as ID information of each of the plurality of user terminals (200).

[0118] In addition, here, the address information of each of the plurality of user terminals (200) may be information collected from a program installed in each of the plurality of user terminals (200) at a preset period or whenever the Internet is changed.

[0119] More specifically, first, the computing device (100) can obtain multiple user information about multiple users whenever a pre-set condition is satisfied from the user terminals (200) of multiple users. For example, the computing device (100) can obtain multiple user information about multiple users periodically and / or whenever the Internet changes through a software program based on an SDK (Software Development Kit) installed on each of the multiple user terminals (200) at a preset interval or whenever the Internet connected to the user terminals (200) changes.

[0120] Thereafter, the computing device (100) can match the plurality of user information collected from SDK-based software programs installed on each of the plurality of user terminals (200) with the address information of each of the plurality of user terminals (200) and store them in a separate DB (e.g., user / device ID mapping database (DB)).

[0121] Thereafter, when the address information (e.g., IP source address) of a specific user terminal (200) is acquired from a network packet, the computing device (100) may select user information (such as a mobile phone number, device ID, or user ID) that matches and is stored with the address information of the specific user terminal (200) among the plurality of user information previously stored in a separate DB. In addition, the computing device (100) may specify a user or user terminal (200) based on the selected user information. However, the present invention is not limited thereto.

[0122] As another example, when address information of a user terminal (200) is obtained from a network packet as illustrated in FIG. 10, the computing device (100) can obtain user information corresponding to the address information (e.g., a phone number and ID information corresponding to the user terminal (200)) from the telecommunications server (300).

[0123] Typically, since the telecommunications company is the entity that allocates IP addresses to user terminals (200), it knows in advance the mapping relationship between the address information (e.g., IP source address) of the user terminal (200) and user information (e.g., mobile phone number).

[0124] In addition, the telecommunications company can install a program that receives device IDs (Google ADID / Apple IDFA / UID2.0, etc.) from user terminals (200) used by its customers, and continuously collect the customers' device IDs through the program and store them by mapping them with the address information of the user terminal (200), or update the already stored information.

[0125] In consideration of these points, in the process of acquiring a network packet through the DPI module of the communication server (300), the computing device (100) may acquire from the communication server (300) not only the network packet but also information on the mapping relationship between user information and address information and / or user information derived based on the mapping relationship between user information and address information (e.g., user information corresponding to the user terminal (200) that transmitted the network packet).

[0126]

[0127] FIG. 11 is a flowchart of a second method for obtaining user information from a network packet, and FIGS. 12 and 13 are diagrams illustrating a process for obtaining user information according to the second method.

[0128] Referring to FIGS. 11 to 13, in step S310, the computing device (100) can obtain a plurality of strings for each of the plurality of user terminals (200) and a plurality of user information for each user of the plurality of user terminals, and can store the plurality of strings and the plurality of user information by matching them with each other.

[0129] More specifically, first, the computing device (100) can obtain a plurality of strings corresponding to each of the plurality of user terminals (200) and a plurality of user information for each user of each of the plurality of user terminals (200) from a program installed in each of the plurality of user terminals (200).

[0130] Here, the plurality of strings may be random strings generated by a program installed in each of the plurality of user terminals (200) when the plurality of user terminals (200) are connected to the base station or at preset intervals. That is, the program installed in a specific user terminal (200) generates a random string when the specific user terminal (200) is connected to the base station or at preset intervals, and provides the generated random string to the computing device (100) together with specific user information of the specific user terminal (200).

[0131] Here, arbitrary strings and user information may be directly transmitted from a program (SDK) installed in a user terminal (200) to a computing device (100) as illustrated in FIG. 12, but is not limited thereto, and may be implemented in a form in which a Heartbeat message including such information is transmitted from a program (SDK) installed in a user terminal (200) to a WIFI router / base station as illustrated in FIG. 13, and the WIFI router / base station transmits matching information (matching the corresponding device ID and URL) to the computing device (100) based on the Heartbeat message.

[0132] Thereafter, the computing device (100) can store multiple user information and multiple strings by matching them with each other.

[0133] At step S320, the computing device (100) can obtain a plurality of strings for each of the plurality of user terminals (200) and a plurality of address information for each of the plurality of user terminals (200), and can store the plurality of strings and the plurality of address information by matching them with each other.

[0134] More specifically, first, the computing device (100) can obtain a plurality of strings for each of the plurality of user terminals (200) and address information for each of the plurality of user terminals (200) through a packet filter.

[0135] Here, the plurality of strings and the plurality of address information obtained through the packet filter may be information extracted from a separate special packet by the packet filter, and the special packet may be generated through a program installed in each of the plurality of user terminals (200) and transmitted to the packet filter.

[0136] For example, a program installed in a specific user terminal (200) can generate a random string when the specific user terminal (200) is connected to a base station or at preset intervals, can match the random string with the address information of the specific user terminal (200) to generate a special packet, and can transmit the special packet to a packet filter.

[0137] The packet filter can extract address information of a specific user terminal (200) and an arbitrary string included in the special packet by obtaining a special packet from a specific user terminal (200), and can transmit the extracted arbitrary string and address information to the computing device (100).

[0138] Thereafter, the computing device (100) can store multiple address information and multiple strings by matching them with each other.

[0139] As described above, the computing device (100) can generate data defining a mapping relationship of "address information-string-user information" by matching and storing multiple user information and multiple strings, and by matching and storing multiple address information and multiple strings. Through this, an environment can be constructed in which strings and / or user information can be identified based on address information, address information and / or user information can be identified based on strings, or address information and / or strings can be identified based on user information.

[0140] At step S330, when the computing device (100) acquires a network packet transmitted to the Internet, it can extract address information from the network packet. Here, the address information extraction operation performed by the computing device (100) may be implemented in a form identical or similar to the operation at step S210 of FIG. 8, but is not limited thereto.

[0141] At step S340, the computing device (100) can select a string corresponding to the address information extracted through step S330.

[0142] In various embodiments, when specific address information is extracted from a network packet, the computing device (100) may select one of a plurality of previously stored strings that matches the specific address information.

[0143] At step S350, the computing device (100) can obtain user information corresponding to the selected string through step S340.

[0144] In various embodiments, the computing device (100) may select user information that matches one of the plurality of previously stored user information strings when one of the plurality of previously stored strings is selected that matches specific address information.

[0145] Here, the computing device (100) is described as obtaining the user's mobile phone number, the user's ID information (e.g., Google ADID, Apple IDFA, UID2.0, etc.) and / or the ID information of the user terminal (200) as user information, but is not limited thereto, and the address information of the user terminal (200) itself obtained from a network packet may be utilized as user information.

[0146]

[0147] Again, referring to FIG. 4, at step S130, the computing device (100) can obtain behavioral information from the network packet obtained through step S110. For example, the computing device (100)

[0148] In various embodiments, the computing device (100) can analyze network packets to determine the type of service being used by the user and the status of use of that service as behavioral information. This will be described in more detail below with reference to FIGS. 14 and 15.

[0149]

[0150] FIG. 14 is a flowchart illustrating a method for obtaining behavior information from network packets in various embodiments, and FIG. 15 is a diagram illustrating a process for determining a service usage status through domain information matching in various embodiments.

[0151] Referring to FIGS. 14 and 15, in step S410, the computing device (100) can extract domain information from a network packet. For example, since the network packet includes an http version, an http method type (e.g., POST, GET, etc.) and URL information, the computing device (100) can obtain URL information from the network packet and extract domain information corresponding to the service by parsing the URL information. However, the computing device (100) is not limited thereto, and the computing device (100) can extract IP address information of the destination server of the network packet from the network packet, but is not limited thereto.

[0152] Meanwhile, in order to determine the service usage status using domain information extracted from network packets, URL information called when using each service is required. However, each service has the characteristic that the URL called and its frequency vary depending on the type of operating system (e.g., Android, iOS) on which each service is run, the access method (e.g., own application, web browser, etc.), and the current usage status of each service.

[0153] Taking this into consideration, the computing device (100) can individually extract and collect domain information for each service in order to more accurately determine the usage status for each different service.

[0154] In addition, the computing device (100) can build a mapping table in advance in which domain information and service usage status information are mapped for each service in order to accurately distinguish the usage status for each service, and can perform optimization on the mapping table, such as continuously updating the pre-built mapping table.

[0155] In various embodiments, the computing device (100) can determine whether a network packet is a packet to be analyzed, and can extract domain information only from network packets determined to be packets to be analyzed.

[0156] In various embodiments, when a plurality of network packets are acquired, the computing device (100) can identify a packet to be analyzed among the plurality of network packets and extract domain information from the packet to be analyzed.

[0157] Here, the packets to be analyzed may be network packets related to the target service. For example, if the computing device (100) wishes to determine the attributes of a specific service, it may set the specific service as the target service and identify network packets related to this specific service as the packets to be analyzed.

[0158] At this time, the computing device (100) can exclude packets whose destination address of the network packet is a private IP address or a local host address from the packets to be analyzed.

[0159] In various embodiments, domain information can be extracted from network packets via a packet filter.

[0160] For example, when a packet filter is provided inside a computing device (100), network packets and control commands can be obtained from the computing device (100), thereby analyzing the network packets inside the computing device (100) and extracting domain information. Meanwhile, when the packet filter is provided as a separate component outside the computing device (100), the packet filter can obtain network packets transmitted to the Internet, extract domain information from the obtained network packets, and transmit only the extracted domain information to the computing device (100).

[0161] At step S420, the computing device (100) can determine the type of service executed on the user terminal (200) and the service usage status as behavioral information based on the domain information extracted through step S410.

[0162] In various embodiments, the computing device (100) can determine the properties of a service executed through the user terminal (200) based on a matching algorithm.

[0163] For example, the computing device (100) can determine the type of service corresponding to the domain information by matching the domain information extracted from the network packet with the domain information for each service stored in advance.

[0164] Here, the domain information for each service stored in advance means data that lists domain information corresponding to a service type in advance or data that lists information on the types of services that can be provided for each domain in advance. As described above, by matching the domain information for each service stored in advance with the domain information extracted from a network packet, the type of service corresponding to the domain information, i.e., the type of service being executed through the user terminal (200), can be specified.

[0165] As another example, the computing device (100) can determine the service usage status based on the result of matching multiple domain information extracted from multiple network packets with domain information for each service stored in advance.

[0166] More specifically, first, the computing device (100) can match and store a plurality of domain information extracted from a plurality of network packets generated as a service is executed through the user terminal (200) and domain information for each service stored in advance.

[0167] In various embodiments, the computing device (100) may store a preset number of domain information (e.g., up to N domain information) by matching the most recently extracted domain information among the plurality of domain information extracted from the plurality of network packets generated as the service is executed through the user terminal (200) with the pre-stored service-specific domain information, or may store a plurality of domain information extracted within a predetermined time period (e.g., domain information extracted during the last M hours) by matching the pre-stored service-specific domain information.

[0168] In various embodiments, the computing device (100) may store only the domain information of services for which the usage status is to be determined among the plurality of domain information extracted from each of the plurality of network packets by matching it with the domain information for each service stored in advance.

[0169] In various embodiments, the computing device (100) may recognize and filter patterns of domain information unrelated to service use among the plurality of domain information extracted from each of the plurality of network packets. Here, the patterns of domain information unrelated to service use may be common characteristics extracted through big data analysis of the plurality of domain information unrelated to service use, or predefined patterns, but are not limited thereto.

[0170] Thereafter, the computing device (100) can determine the service usage status by analyzing multiple domain information stored in accordance with the domain information for each service stored in advance.

[0171] Here, referring to FIG. 15, the domain information used to determine the service usage status includes domain, call time, number of calls, call frequency, type of domain called together, and platform information. The computing device (100) can selectively use the necessary information among this information depending on the service. Since it is often difficult to determine the service status with just one piece of information, in most cases, multiple pieces of information must be collected together. For example, if determination is made based on the domain alone, the domain can be called even in a background task, so the domain can be called even when the user is not actually using the service. Therefore, since the information used varies depending on each service, usage status, and platform, optimization may be necessary for each service and usage status to be recognized.

[0172] For example, the most basic way to determine the usage status of a service is to use the domain and call frequency. For example, if a domain called X is called Z or more times within Y seconds, it can be determined that a service has been run for the first time.

[0173] Additionally, if domain and call frequency alone are not sufficient for recognition, other information may be required. For example, to recognize a specific action in a service, a call to domain A may be required before a call to domain B.

[0174] Additionally, depending on the type of service, some can be recognized with just one domain, while others may require multiple domains for recognition. Therefore, the type and number of domains required to recognize a service may vary depending on the service. Furthermore, since multiple services may call the same domain, in such cases, a different method may be required to distinguish them. For example, assuming that service A calls domain X and service B calls X and Y, service B should be recognized only when domain X is called together with Y, and service A should be recognized when only X is called.

[0175] In consideration of the above-described contents, the computing device (100) can pre-define data regarding the properties of information (e.g., type, number, etc.) required for each type of service and the usage status of the service to be determined through domain analysis, and select at least one piece of information included in the domain information based on the type of service, the usage status to be determined, and the pre-defined data, that is, the information required to determine the usage status, and analyze the same to determine the usage status of the service as one of the service execution status, the service usage status, and the status of performing a specific action in the service.

[0176] Furthermore, even for the same service, criteria may vary depending on the OS or access method. For example, if service X can be accessed through three methods—an Android application, an iOS application, and a webpage accessed through Chrome—each of these methods may call a different domain, and the frequency of calls may also vary. Therefore, to ensure service recognition across all platforms, different optimizations may be required for each platform.

[0177] Considering these points, the computing device (100) can set a criterion for determining the service usage status by considering at least one of the operating system (OS) of the user terminal (200) and the service access method, and can determine the service usage status by analyzing domain information according to the criterion for determining the service usage status.

[0178] In various embodiments, the computing device (100) determines the usage status determination criteria for the service based on the type of service and the current usage status of the service, considering that the criteria for determining the usage status of the service are different depending on the type of service and the current usage status of the service, and analyzes a plurality of domain information stored in a matched manner with the domain information for each service stored in advance according to the usage status determination criteria, thereby determining the usage status of the service.

[0179] In various embodiments, the computing device (100) may extract domain information patterns as result data by analyzing domain information through an artificial intelligence model learned according to a machine learning-based learning method (e.g., various known machine learning algorithms such as CNN, RNN, DNN, LSTM, etc.) and determine the service usage status based on the domain information patterns.

[0180] Here, the domain information pattern may mean a common characteristic extracted by comparing domain information extracted from analysis target packets collected within a preset first number during a preset first time period.

[0181] In various embodiments, the computing device (100) extracts domain information from a network packet through a packet filter, and extracts behavioral information based on the extracted domain information. However, if the domain information cannot be extracted because the network packet is encrypted traffic, the computing device (100) can parse server name indication information (Server Name Indication, SNI), and obtain information on the type and usage status of a service executed through the user terminal (200) using the server name indication information.

[0182] The TLS (Transport Layer Security) handshake is a series of procedures performed by a client and a server to establish a secure connection. It includes the Client Hello, in which the client sends a connection request to the server; the Server Hello, in which the server responds to the client's request; the Server Certificate and Key Exchange, in which the server authenticates the client by sending its certificate to the client and transmits data for key exchange; the Client Key Exchange, in which the client generates a session key, encrypts it with the server's public key, and transmits it to the server; and the Finish Handshake and Start Encrypted Communication processes, in which the client and server communicate using a symmetric encryption method using a shared session key.

[0183] Here, Server Name Indication (SNI) is a TLS extension that allows servers hosting multiple domains to provide the correct certificate for each domain. SNI serves to convey the hostname the client is attempting to connect to to the server during the TLS handshake, allowing multiple SSL / TLS certificates to be used to host multiple domains on a single IP address.

[0184] TLS certificates are issued for specific domains. Therefore, in order for the server to provide the correct certificate to the client's request, it must know the domain the client is attempting to connect to. When a client attempts to connect to a server, it provides the name of the domain it is attempting to connect to via the SNI field. Based on this information, the server can select the appropriate TLS certificate and respond. Because the server must know the client's requested domain to provide the correct certificate, the SNI field is transmitted unencrypted.

[0185] Therefore, the SNI field can be used to determine the name of the domain the client is trying to connect to.

[0186] This SNI field is included in a message (ClientHello message) that the client sends to the server to initiate a TLS handshake. The computing device (100) can parse the SNI from this message, extract domain information based on the parsed SNI, and obtain behavior information using the extracted domain information.

[0187]

[0188] Again, referring to FIG. 4, at step S140, the computing device (100) can provide a service corresponding to the user information obtained through step S120 and the behavior information obtained through step S130.

[0189] For example, the computing device (100) may provide an anti-phishing service / function. For example, if the computing device (100) determines that behavioral information indicates entry into a phishing site, the computing device (100) may block traffic to a user terminal (200) corresponding to the identified user, or provide a warning notification to the user terminal (200) corresponding to the identified user.

[0190] As another example, the computing device (100) may provide data sales services as a DMP operator.

[0191] More specifically, referring to FIG. 16, first, the advertiser can register an event that he or she wishes to receive (e.g., entering a specific domain such as the Coupang site) as a real-time event trigger (①).

[0192] Thereafter, the computing device (100) extracts behavioral information from the network packet and stores the behavioral information in a separate DB (user behavioral information DB) (②), and can determine whether the behavioral information extracted from the network packet corresponds to an event trigger (③).

[0193] Thereafter, if the computing device (100) determines that the behavior information extracted from the network packet is a preset event, the computing device (100) can transmit the behavior information to the trigger server (300) (④).

[0194] Accordingly, the trigger server (300) can determine a target advertiser to provide information to based on an event corresponding to the behavioral information (⑤), and can provide the target advertiser with user information and behavioral information extracted from the network packet (⑥).

[0195] This method is similar to DMP PubSub (e.g. Data Consortium, which does not require partnerships) that supports real-time data publishing and subscription within a data management platform (DMP), allowing advertisers to receive event-related information via PubSub for any ID value (e.g. Device ID (Google ADID, Apple IDFA, UID2.0, etc.), mobile phone number, IP address, etc.).

[0196] For example, you can receive event information desired by clients / advertisers (e.g., information about your customers visiting Coupang, information about your customers reading real estate articles on the Chosun Ilbo website, etc.). Different costs can be set for each event. For example, a first cost may be charged for the first event (e.g., entering Coupang), while a second cost, which is lower than the first cost, may be charged for the second event (e.g., entering Kurly).

[0197] As another example, the computing device (100) may provide a data selling service to a DMP operator.

[0198] Rather than directly providing data as a DMP operator, the computing device (100) may provide the above information and data to a separate DMP operator. For example, the computing device (100) may provide the DMP operator with information related to what actions a user with a certain ID value (e.g., Device ID (Google ADID, Apple IDFA, UID2.0, etc.), mobile phone number, IP address, etc.) performed in real time (or at a specific point in time, within a predetermined time, etc.).

[0199] Here, DMP operators (DSPs / SSPs) can sell ads to advertisers who want to deliver ads based on this information when users perform specific actions. These ads can be SMS, push messages through specific applications, banners, or in-app ads displayed to users currently active on specific applications / websites.

[0200] For example, a computing device (100) identifies users who have entered a specific shopping site and transmits information about the users to a DMP operator based on the ID information of the user terminal (200). When the DMP operator transmits this information to a specific card operator, the specific card operator can send an advertising message (e.g., push message, SMS, etc.) to a user terminal (200) on which its application is installed, saying, "You can get an x% discount if you use a specific card at a specific shopping site."

[0201] In addition, if the computing device (100) obtains ID information corresponding to a user terminal (200) on which a specific card application is installed from a specific card operator, and if the behavior information includes entry into a specific shopping site and the user information includes ID information corresponding to a user terminal (200) on which a specific card application is installed, based on user information and behavior information extracted from a network packet, i.e., if a specific shopping site is executed by a user terminal (200) on which a specific card application is installed, this information can be provided to the specific card operator (directly and / or through a DMP operator) so that the specific card operator can directly send an advertising message (e.g., push message, SMS, etc.) to the user terminal (200).

[0202] As another example, the computing device (100) can provide a notification service.

[0203] More specifically, referring to FIG. 17, first, the advertiser can register an event that he or she wishes to receive (e.g., entering a specific domain such as the Coupang site) as a real-time event trigger (①).

[0204] Thereafter, the computing device (100) extracts behavioral information from the network packet and stores the behavioral information in a separate DB (user behavioral information DB) (②), and can determine whether the behavioral information extracted from the network packet corresponds to an event trigger (③).

[0205] Thereafter, if the computing device (100) determines that the behavior information extracted from the network packet is a preset event, the computing device (100) can transmit the behavior information to the trigger server (300) (④).

[0206] Accordingly, the trigger server (300) can determine a target advertiser to provide information to based on an event corresponding to the behavioral information (⑤), and can provide user information and behavioral information extracted from network packets to a target providing a notification service (e.g., a telecommunications company, a messenger service notification server, a separate notification server, etc.) (⑥).

[0207] Thereafter, the notification server can provide notifications through the advertiser application of the user terminal (200) based on user information and behavior information (⑦).

[0208] For example, the notification server matches and stores address information (e.g., IP address) and a plurality of push token values ​​for each of a plurality of user terminals (200) in advance, analyzes a network packet, and when address information of a specific user terminal (200) is identified, selects a push token value that matches the corresponding address information from among the plurality of previously stored push token values, and transmits a push message to be transmitted to a specific user terminal (200) to a program installed in the specific user terminal (200) using the selected push token value, thereby allowing a push message to be transmitted to the specific user terminal (200).

[0209] Here, the notification server is described as only mapping the address information (IP address) and the push token value for the user terminal (200), but it is not limited thereto, and in some cases, it may map not only the address information (IP address) but also the user information (e.g., a mobile phone number matched with the IP address of the user terminal (200), the ID information of the user and / or the user terminal (200) (e.g., device ID or user ID information matched with the IP address of the user terminal (200) (e.g., Google ADID, Apple IDFA, UID2.0, etc.)) and the push token value.

[0210] As another example, the computing device (100) may use the phone number information included in the user information to send an SMS message to the user terminal (200) corresponding to the user information.

[0211] As another example, information that a specific user has viewed an article in a specific field on a specific news site may be provided from a computing device (100) to advertisers who wish to sell / advertise products in a specific field, and the advertisers may provide advertisements to these users, so that when the user accesses the web or app in the future, advertisements for products related to the articles the user has viewed may be displayed.

[0212]

[0213] Here, the computing device (100) is described as acquiring network packets in a situation where a wireless network is connected, and providing user and behavior recognition and corresponding services based on the same, but is not limited thereto, and in the case of a wired network, data going to the Internet can be received and monitored based on tapping, and the above-described operations can be performed.

[0214] For example, it can be implemented in a way that identifies the user's behavior using the IP address as an ID, identifies the user's behavior information used for advertising, and provides various services / functions in response to this.

[0215] As another example, a program (SDK) installed on a user terminal (200) can register a change in the IP address in the computing device (100) whenever the IP address of the user terminal (200) changes, thereby defining mapping information between the Device ID and the IP address, and through this, all operations in the wireless network can be performed in the wired network as well.

[0216]

[0217] The method for providing network packet-based user and behavior recognition and corresponding services has been described with reference to the flowchart illustrated in the drawings. For simplicity, the method for providing network packet-based user and behavior recognition and corresponding services has been illustrated and described as a series of blocks. However, the present disclosure is not limited to the order of the blocks, and some blocks may be performed in a different order or simultaneously than those illustrated and described herein. Furthermore, new blocks not described in the present disclosure and drawings may be added, or some blocks may be deleted or modified.

[0218]

[0219] While the embodiments of the present disclosure have been described above with reference to the attached drawings, those skilled in the art will appreciate that the present disclosure can be implemented in other specific forms without altering the technical spirit or essential features thereof. Therefore, the embodiments described above should be understood to be illustrative in all respects and not restrictive.

Claims

1. In a method performed by a computing device, A step of obtaining a network packet transmitted over the Internet; A step of obtaining user information from the obtained network packet; A step of obtaining behavior information from the obtained network packet; and A step of providing a service corresponding to the acquired user information and the acquired behavior information, A method for providing network packet-based user and behavior recognition and corresponding services.

2. In paragraph 1, The step of acquiring the above network packet is: Including a step of acquiring network packets from a DPI (Deep Packet Inspection) module of a telecommunications company, The network packets obtained above are, A duplicate network packet generated as the DPI module of the above communication company duplicates a network packet transmitted to the Internet network. A method for providing network packet-based user and behavior recognition and corresponding services.

3. In paragraph 1, The step of acquiring the above network packet is: A step of obtaining a duplicate network packet generated by tapping a network packet transmitted and received between a packet gateway of a telecommunications company and the Internet network, A method for providing network packet-based user and behavior recognition and corresponding services.

4. In paragraph 1, The step of acquiring the above network packet is: A step of receiving a network packet transmitted to the Internet network through a packet monitoring server separately provided outside the computing device, The above-mentioned network packets are, A duplicate network packet generated by tapping a network packet transmitted and received between a communication company's DPI (Deep Packet Inspection) module or a packet gateway and the Internet network is filtered through the packet monitoring server, and contains only information preset by the computing device. A method for providing network packet-based user and behavior recognition and corresponding services.

5. In paragraph 1, The step of obtaining the above user information is: A step of obtaining address information of a user terminal corresponding to the obtained network packet from the obtained network packet through a packet filter; and Including a step of acquiring one user information that matches the acquired address information among multiple user information stored in advance, The above stored multiple user information is: ID information of each of the plurality of user terminals corresponding to each of the plurality of users, and information matching the address information of each of the plurality of user terminals, The address information of each of the above multiple user terminals is: Information collected from the programs installed on each of the multiple user terminals whenever a preset cycle or Internet change occurs. A method for providing network packet-based user and behavior recognition and corresponding services.

6. In paragraph 1, The step of obtaining the above user information is: A step of matching and storing a plurality of strings for each of a plurality of user terminals and a plurality of user information for each of the users of the plurality of user terminals; A step of obtaining the plurality of strings and the plurality of address information for each of the plurality of user terminals from a packet filter and storing the plurality of strings and the plurality of address information by matching them with each other; and In the case where specific address information is extracted from the obtained network packet, a step of selecting one string that matches the extracted specific address information among the plurality of strings and selecting one user information selected among the plurality of user information is included. The above multiple strings are, The plurality of user terminals include a random string generated when the plurality of user terminals are connected to the base station or through a program installed in each of the plurality of user terminals at preset intervals, The above multiple address information, Address information that is included in a packet generated by a program installed in each of the plurality of user terminals and transmitted to the packet filter, and that matches an arbitrary string generated corresponding to each of the plurality of user terminals. A method for providing network packet-based user and behavior recognition and corresponding services.

7. In paragraph 1, The step of obtaining the above user information is: A step of obtaining address information of a user terminal corresponding to the obtained network packet from the obtained network packet through a packet filter; and A step of obtaining user information corresponding to the address information obtained from the telecommunications company, wherein the obtained user information includes at least one of a phone number and ID information corresponding to the user terminal. A method for providing network packet-based user and behavior recognition and corresponding services.

8. In paragraph 1, The step of obtaining the above user information is: A step of obtaining address information of a user terminal from the obtained network packet as user information through a packet filter, A method for providing network packet-based user and behavior recognition and corresponding services.

9. In paragraph 1, The step of obtaining the above behavioral information is: A step of extracting at least one of domain information and IP address information of a destination server of the obtained network packet from the obtained network packet through a packet filter; and A step of obtaining information on the type and usage status of a service executed through a user terminal corresponding to the obtained network packet using the extracted information, A method for providing network packet-based user and behavior recognition and corresponding services.

10. In paragraph 1, The step of obtaining the above behavioral information is: A step of extracting domain information from the acquired network packet through a packet filter, and if the acquired network packet is determined to be encrypted traffic, analyzing the acquired network packet to identify a message transmitted from a user terminal corresponding to the acquired network packet, and parsing server name indication information (SNI) from the identified message; and A step of obtaining information on the type and usage status of a service executed through the user terminal using the parsed server name display information, A method for providing network packet-based user and behavior recognition and corresponding services.

11. In paragraph 1, The steps for providing the above service are: If the acquired behavioral information is determined to be an entry into a phishing site, a step of blocking traffic to a user terminal corresponding to the acquired user information or providing a warning notification to the user terminal corresponding to the acquired user information is included. A method for providing network packet-based user and behavior recognition and corresponding services.

12. In paragraph 1, The steps for providing the above service are: Including a step of selecting at least one advertiser to provide the acquired behavioral information among a plurality of advertisers according to the properties of the detected event when a preset event is detected based on the acquired behavioral information, and providing the acquired user information and the acquired behavioral information to the selected at least one advertiser. A method for providing network packet-based user and behavior recognition and corresponding services.

13. In paragraph 1, The steps for providing the above service are: A step of selecting a push token value that matches the address information of a user terminal included in the acquired user information among a plurality of previously stored push token values, and transmitting a push message to a user terminal corresponding to the acquired user information using the selected push token value, A method for providing network packet-based user and behavior recognition and corresponding services.

14. In paragraph 1, The steps for providing the above service are: A step of sending an SMS message to a user terminal corresponding to the acquired user information using the telephone number information included in the acquired user information, A method for providing network packet-based user and behavior recognition and corresponding services.

15. Processor; network interface; memory; and A computer program loaded into the above memory and executed by the above processor, The above computer program, An instruction to obtain a network packet transmitted over the Internet; An instruction for obtaining user information from the obtained network packet; An instruction for obtaining behavior information from the obtained network packet; and Including instructions for providing a service corresponding to the acquired user information and the acquired behavior information. A computing device that performs network packet-based user and behavior recognition and provides services corresponding thereto.

16. Combined with a computing device, A step of obtaining a network packet transmitted over the Internet; A step of obtaining user information from the obtained network packet; A step of obtaining behavior information from the obtained network packet; and A computer program stored in a recording medium readable by a computing device to execute a method for providing network packet-based user and behavior recognition and a service corresponding thereto, including a step of providing a service corresponding to the acquired user information and the acquired behavior information.

Citation Information

Patent Citations

  • Filtering device

    JP2009182480A

  • Method for providing targeting information based on customer behavior pattern and environmental data in on-line network

    KR1020170002246A

  • Black Composition for inlay using paddy soil and manufacturing method thereof

    KR102366265B1

  • Method and apparatus for presenting advertisements

    US20080033794A1

  • System and method for filtering advertising in a networking device

    US20130275228A1