Edge Appliance Network Traffic Legitimacy Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Illegitimate network interactions, such as those generated by botnets, lead to inappropriate payments in advertising revenue models, as existing systems fail to accurately distinguish between legitimate and fraudulent interactions.
Innovation Solution
An edge appliance monitors network traffic to analyze interactions by deriving information from TCP/IP and OSI layers 3-7, using models to assess legitimacy and report fraudulence, with the ability to correlate interactions across multiple points in the network, and communicate with third-party systems for scalability and independence.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If network interactions are monitored and analyzed to distinguish legitimate from illegitimate interactions, then payment accuracy is improved, but system complexity increases
Solution Approach 1:
An edge appliance is introduced as an intermediary component between the network traffic and the analysis system. This appliance captures network interactions and forwards them for analysis, separating the monitoring function from the core advertising platform and reducing overall system complexity while maintaining high detection accuracy
Solution Approach 2:
The system divides the network interaction analysis into multiple layers (OSI layers 3-7), analyzing different protocol levels separately. This segmentation allows complex interactions to be broken down into manageable components, improving detection accuracy without overwhelming the system with monolithic complexity
2Reliability
If detailed network traffic analysis is performed to assess interaction legitimacy, then fraud detection capability is improved, but processing time increases
Solution Approach 1:
The system performs preliminary analysis of network interactions at the edge appliance level, extracting key features and assessing basic legitimacy before full analysis. This preliminary action filters out obviously legitimate or illegitimate interactions early, reducing the time required for comprehensive fraud detection while maintaining high reliability
Solution Approach 2:
The system applies different levels of analysis depth based on risk assessment. For low-risk interactions, partial analysis is performed to maintain speed, while high-risk interactions receive excessive (comprehensive) analysis. This adaptive approach balances fraud detection capability with processing time requirements
3Productivity
If network interactions are monitored without interfering with traffic flow, then network performance is maintained, but measurement capability is reduced
Solution Approach 1:
The edge appliance acts as a transparent intermediary that mirrors network traffic to the analysis system without intercepting or blocking it. This allows comprehensive measurement of interactions while maintaining full network throughput, as the original traffic flow continues unimpeded while a copy is analyzed for legitimacy
Data Source
AI summary
Network interaction analysis is disclosed. Traffic is monitored including a network interaction. Monitoring includes monitoring at least one of TCP, HTTP, or IP layer information. The network interaction is analyzed based at least in part on a source of a transaction determined from the layer information.


