Abusive Traffic Detection via Graph Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing web-based digital content services face challenges in detecting fraudulent traffic, which leads to unfair royalty collection and increased network bandwidth usage, as fraudulent users simulate normal behavior to collect royalties, making it difficult to differentiate between genuine and fake traffic.
Innovation Solution
A system and method for detecting abusive traffic, comprising an abuse detection engine with modules for pre-processing, suspiciousness testing, graphing, analysis, and notification generation, which aggregates data, identifies suspicious users and content owners, models connections between them, and generates notifications for further investigation, optimized for distributed computation over large data sets.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If fraudulent users simulate normal behavior to collect royalties, then royalty collection increases for fraudulent accounts, but detection difficulty increases
Solution Approach 1:
The patent segments the detection process into multiple specialized modules: pre-processing module for data aggregation and cleaning, suspiciousness test module for initial fraud identification, graphing module for relationship mapping, analysis module for pattern recognition, and notification module for alert generation. This segmentation allows each module to focus on specific detection tasks, improving overall detection accuracy while managing system complexity through modular design.
Solution Approach 2:
The patent introduces an intermediary analysis layer that processes raw traffic data before final detection decisions. The pre-processing module acts as an intermediary that aggregates and cleans data, while the graphing module creates intermediate relationship representations. These intermediary structures enable more accurate fraud detection by transforming raw data into meaningful patterns without requiring the final detection system to handle all complexity directly.
2Productivity
If automated detection systems are implemented, then fraud detection speed improves, but computational resource usage increases
Solution Approach 1:
The patent applies preliminary action by implementing a pre-processing module that aggregates and cleans data before main detection analysis. The suspiciousness test module performs initial filtering to identify potentially fraudulent accounts early in the process. This preliminary processing reduces the volume of data requiring intensive computational analysis later, thereby improving detection speed while reducing overall computational resource consumption.
Solution Approach 2:
The patent implements partial action by focusing computational resources on suspicious accounts identified through preliminary testing rather than analyzing all accounts equally. The suspiciousness test module selectively identifies accounts warranting further investigation, allowing the system to apply more intensive analysis only where needed. This approach maintains high detection speed while optimizing computational resource usage by avoiding unnecessary processing of legitimate accounts.
3Reliability
If multi-account fraud is detected, then royalty payment accuracy improves, but false positive rate may increase
Solution Approach 1:
The patent implements feedback mechanisms where detection results from the analysis module feed back into refining detection thresholds and patterns. The notification module provides feedback by alerting administrators to detected fraud cases, allowing manual verification and system learning. This feedback loop enables the system to improve royalty payment accuracy over time while adjusting to reduce false positives based on verified case patterns.
Solution Approach 2:
The patent applies parameter changes by dynamically adjusting detection sensitivity thresholds based on analysis results and verification outcomes. The system can modify detection parameters such as suspiciousness score thresholds, relationship graph density requirements, and traffic pattern matching sensitivity. These parameter adjustments allow the system to maintain high royalty payment accuracy while reducing false positives by calibrating detection strictness based on actual fraud patterns observed.
Data Source
AI summary
Aspects of an abuse detection system for a web service include an abuse detection engine executing on a server. The abuse detection engine includes a pre-processing module for aggregating a data set for processing and analysis; a suspiciousness test module for identifying suspicious content owners and suspicious users; a graphing module for finding connections between suspicious content owners and suspicious users; an analysis module for determining which groups are constituted of fraudulent or abusive accounts; and a notification generation and output module for generating a list of abusive entities and a notification for output to at least one of: the abusive entity, a digital content distribution company associated with the abusive entity, and a legal department or other entity for further investigation or action. Additionally, royalties for content consumptions associated with abusive accounts may be held. Aspects of an abusive traffic detection method enable multi-account and multi-content owner fraud detection.


