Automated Activity Manager for Bot Detection and Service Modification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for managing network security are largely reactive and laborious, failing to prevent or mitigate illicit online activities such as bot infections, which consume resources and reduce profitability for service providers due to their manual processing and delayed identification of fraudulent activity.

Innovation Solution

A computerized system that aggregates data from multiple sources, uses algorithms to rate user security, and implements real-time analysis and management plans to detect and remediate illicit activity, including automated detection and pre-emptive measures, such as modifying services or terminating subscriptions, to prevent future infections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If manual processing and delayed identification methods are used for detecting illicit activity, then labor requirements are reduced, but detection speed and response time deteriorate

Engineering Contradiction:
Improvedetection speedVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by continuously monitoring and analyzing user activity data in real-time before illicit activities can spread. The activity manager proactively identifies potential bot infections and fraudulent activities through automated analysis of click patterns, browsing behavior, and device metrics, enabling early intervention before manual detection would be necessary

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces manual mechanical processing with automated computerized systems. The activity manager uses algorithms and machine learning models to automatically analyze user data, generate risk scores, and identify illicit activities without human intervention. This substitution of automated digital processing for manual review dramatically increases detection speed while managing system complexity through standardized automated workflows

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Speed

If automated detection systems are implemented, then detection speed improves, but resource consumption increases

Engineering Contradiction:
Improveresponse timeVSAvoidcomputational resources
Core Design Contradiction:
SpeedVSUse of energy by moving object

Solution Approach 1:

The system applies local quality by focusing computational resources on specific high-risk users or devices rather than uniformly processing all user data. The activity manager generates risk scores for individual users based on their specific activity patterns, allowing the system to concentrate analytical power where it is most needed. This selective approach enables fast response times for critical cases while conserving computational resources for lower-priority monitoring

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements partial action by monitoring only the most relevant activity metrics necessary for detecting illicit behavior. Rather than analyzing every possible user action, the system focuses on key indicators such as click rates, browsing patterns, and device performance metrics that are most predictive of bot infections. This selective monitoring reduces computational overhead while maintaining effective detection speed

Inventive Principle:
Principle #16Partial or excessive action

3Measurement precision

If real-time analysis is performed on all user data, then detection accuracy improves, but processing time increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary action by continuously collecting and pre-processing user activity data in the background before illicit activities manifest. The activity manager maintains ongoing profiles of user behavior patterns, device characteristics, and activity metrics, so that when suspicious behavior emerges, the analysis can be quickly completed using pre-established baseline data. This eliminates the need for time-consuming retrospective analysis while maintaining high detection accuracy

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses copying by creating simplified representations or models of user behavior patterns rather than analyzing raw data in full. The activity manager generates aggregated activity summaries, risk scores, and behavioral profiles that capture essential characteristics without requiring processing of every individual data point. These copied representations enable rapid comparison and accurate detection of anomalies while significantly reducing processing time

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11606380B2Apparatus and methods for data collection, analysis and service modification based on online activity
Publication Date: 2023.03.14 TIME WARNER CABLE ENTERPRISES LLC
  • US11606380B2 patent drawing
  • US11606380B2 patent drawing
  • US11606380B2 patent drawing

AI summary

Methods and apparatus for evaluating collected data relating to online activity, and modification of services within a service provider network. In one embodiment, a service provider collects data relating to the online activity of users of third-party services and correlates the data with subscribers of the service provider to generate useful products and analytics (e.g., classifications, behavioral models, etc.) containing information relating to the subscribers' online activity. The generated products may be used to determine whether and how to modify services provided to individual subscribers, exported for use by third parties, or for other purposes.