Behavior Model for Automated Request Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security systems struggle to effectively differentiate between legitimate user requests and malicious automated requests, as attackers randomize browser property signals to bypass rule-based detection systems, necessitating frequent updates and posing a challenge in maintaining effective defense mechanisms.

Innovation Solution

A network security system that utilizes behavior data and deep learning techniques to generate behavior models, analyzing input events and sensor information to determine whether requests are initiated by human users or automated processes, allowing for real-time differentiation and adaptive countermeasures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If rule-based bot detection systems are used to identify malicious requests, then automated request detection capability is improved, but the system requires frequent manual updates to maintain effectiveness against evolving attack methods

Engineering Contradiction:
Improvebot detection effectivenessVSAvoidsystem maintenance complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system employs machine learning models that automatically learn and adapt to new bot detection patterns without requiring manual rule updates. The model continuously improves its detection capability by processing incoming requests and adjusting its parameters, enabling the system to self-update and maintain effectiveness against evolving bot techniques.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent transforms the detection approach from static rule-based parameters to dynamic machine learning parameters. The system uses configurable parameters such as confidence thresholds and decision boundaries that can be adjusted without rewriting detection rules, allowing flexible adaptation to new threat landscapes while maintaining system stability.

Inventive Principle:
Principle #35Parameter changes

2Difficulty of detecting and measuring

If attackers randomize browser property signals to bypass detection, then the difficulty of detecting and measuring malicious activity increases, but this creates opportunities for more sophisticated detection approaches

Engineering Contradiction:
Improvemalicious activity detection difficultyVSAvoiddetection system adaptability
Core Design Contradiction:
Difficulty of detecting and measuringVSAdaptability or versatility

Solution Approach 1:

The system transitions from static detection rules to dynamic machine learning models that can adapt their detection criteria in real-time. The model processes sequences of browser signals and dynamically adjusts its interpretation based on learned patterns, enabling it to detect randomized signals that would evade static rule-based systems.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent implements feedback mechanisms where the detection system continuously learns from incoming requests and adjusts its parameters accordingly. The machine learning model receives feedback from detection outcomes and uses this to refine its detection logic, creating a closed-loop system that improves over time and adapts to new evasion techniques.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11483324B2Detection of malicious activity using behavior data
Publication Date: 2022.10.25 SHAPE SECURITY INC
  • US11483324B2 patent drawing
  • US11483324B2 patent drawing
  • US11483324B2 patent drawing

AI summary

Techniques are provided for detection of malicious activity using behavior data. A behavior model is trained with behavior data generated in association with a plurality of requests. Data is received that describes a particular request from a particular client device to a server system hosting a website. The data includes particular behavior data generated at the particular client device in association with the particular request. The particular behavior data is analyzed using the behavior model to generate a behavior model result. An automation determination for the particular request is generated based on the behavior model result. The particular request is handled based on the automation determination for the particular request.