CDN Fraud Detection Service Using ML Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing content delivery networks (CDNs) face challenges in detecting and mitigating fraudulent usage, particularly during live events, as fraudsters consume bandwidth and cause revenue loss, with current methods often failing to detect such activity in real-time.

Innovation Solution

A fraud detection service that analyzes CDN traffic, distribution characteristics, and account data using machine learning models to generate fraud scores, enabling rapid identification and response to fraudulent activities, such as throttling or terminating suspicious distributions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional CDN traffic monitoring methods are used, then system complexity is low, but fraud detection capability and real-time response are insufficient

Engineering Contradiction:
Improvefraud detection capabilityVSAvoiddetection system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent introduces a fraud detection service as an intermediary component between CDN traffic sources and the core CDN infrastructure. This service subscribes to distribution creation events and analyzes traffic patterns independently, allowing fraud detection capabilities to be added without modifying the core CDN system architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where the fraud detection service continuously monitors traffic patterns, generates fraud scores, and provides responses that trigger throttling or termination actions. This closed-loop feedback enables real-time fraud mitigation while maintaining system stability.

Inventive Principle:
Principle #23Feedback

2Loss of energy

If real-time fraud detection and response is implemented, then revenue loss from fraud is reduced, but processing time and computational resources increase

Engineering Contradiction:
Improverevenue loss from fraudVSAvoidprocessing time for fraud analysis
Core Design Contradiction:
Loss of energyVSLoss of time

Solution Approach 1:

The fraud detection service subscribes to distribution creation events in advance and begins analyzing traffic patterns immediately when distributions are created. By performing preliminary analysis before fraudulent activity can scale, the system reduces both revenue loss and the time needed to detect and respond to fraud.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system applies fraud detection and scoring to all distributions initially, then refines its focus based on fraud scores and patterns. This partial action approach ensures comprehensive coverage while optimizing computational resources by concentrating detailed analysis on high-risk distributions.

Inventive Principle:
Principle #16Partial or excessive action

3Object-affected harmful factors

If aggressive fraud mitigation actions are taken, then fraudulent bandwidth consumption is reduced, but legitimate traffic may be incorrectly affected

Engineering Contradiction:
Improvefraudulent bandwidth consumptionVSAvoidimpact on legitimate traffic
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The system dynamically adjusts traffic throttling parameters based on fraud scores, traffic patterns, and distribution characteristics. By changing parameters adaptively rather than applying fixed thresholds, the system can aggressively mitigate fraud while preserving legitimate traffic that exhibits normal usage patterns.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The fraud detection and mitigation system operates dynamically, continuously adapting its response based on real-time traffic analysis, fraud score changes, and pattern recognition. This dynamic approach allows the system to differentiate between fraudulent and legitimate traffic flows, applying mitigation only when and where fraud is detected.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11552971B1Detection of fraudulent use of content delivery network served byte streams
Publication Date: 2023.01.10 AMAZON TECH INC
  • US11552971B1 patent drawing
  • US11552971B1 patent drawing
  • US11552971B1 patent drawing

AI summary

Techniques for detection of the fraudulent use of content delivery network (CDN) served byte streams are described. A fraud detection service obtains CDN log data, distribution data, and account data and uses elements therefrom to perform a distribution-centric fraud analysis using machine learning techniques. Based on the likelihood of fraud determined by the analysis, the fraud detection service can rapidly perform actions to address the fraud, such as the termination of service for the distribution, throttling of resources provided for the distribution, or further investigation techniques.