Edge Appliance Network Traffic Legitimacy Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Illegitimate network interactions, such as those generated by botnets, lead to inappropriate payments in advertising revenue models, as existing systems fail to accurately distinguish between legitimate and fraudulent interactions.

Innovation Solution

An edge appliance monitors network traffic to analyze interactions by deriving information from TCP/IP and OSI layers 3-7, using models to assess legitimacy and report fraudulence, with the ability to correlate interactions across multiple points in the network, and communicate with third-party systems for scalability and independence.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If network interactions are monitored and analyzed to distinguish legitimate from illegitimate interactions, then payment accuracy is improved, but system complexity increases

Engineering Contradiction:
Improveinteraction legitimacy detection accuracyVSAvoidmonitoring system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

An edge appliance is introduced as an intermediary component between the network traffic and the analysis system. This appliance captures network interactions and forwards them for analysis, separating the monitoring function from the core advertising platform and reducing overall system complexity while maintaining high detection accuracy

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system divides the network interaction analysis into multiple layers (OSI layers 3-7), analyzing different protocol levels separately. This segmentation allows complex interactions to be broken down into manageable components, improving detection accuracy without overwhelming the system with monolithic complexity

Inventive Principle:
Principle #1Segmentation

2Reliability

If detailed network traffic analysis is performed to assess interaction legitimacy, then fraud detection capability is improved, but processing time increases

Engineering Contradiction:
Improvefraud detection capabilityVSAvoidinteraction processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary analysis of network interactions at the edge appliance level, extracting key features and assessing basic legitimacy before full analysis. This preliminary action filters out obviously legitimate or illegitimate interactions early, reducing the time required for comprehensive fraud detection while maintaining high reliability

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system applies different levels of analysis depth based on risk assessment. For low-risk interactions, partial analysis is performed to maintain speed, while high-risk interactions receive excessive (comprehensive) analysis. This adaptive approach balances fraud detection capability with processing time requirements

Inventive Principle:
Principle #16Partial or excessive action

3Productivity

If network interactions are monitored without interfering with traffic flow, then network performance is maintained, but measurement capability is reduced

Engineering Contradiction:
Improvenetwork traffic throughputVSAvoidinteraction analysis accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The edge appliance acts as a transparent intermediary that mirrors network traffic to the analysis system without intercepting or blocking it. This allows comprehensive measurement of interactions while maintaining full network throughput, as the original traffic flow continues unimpeded while a copy is analyzed for legitimacy

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS7685275B2Network interaction analysis
Publication Date: 2010.03.23 ANCHOR INTELLIGENCE
  • US7685275B2 patent drawing
  • US7685275B2 patent drawing
  • US7685275B2 patent drawing

AI summary

Network interaction analysis is disclosed. Traffic is monitored including a network interaction. Monitoring includes monitoring at least one of TCP, HTTP, or IP layer information. The network interaction is analyzed based at least in part on a source of a transaction determined from the layer information.