IP Address Size Anomaly Detection for Fraudulent Traffic

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Internet services face challenges in detecting and mitigating machine-generated traffic, such as botnet-based and proxy-based attacks, which distort traffic patterns and inflate click counts, leading to fraudulent activities that deceive advertisers and increase costs.

Innovation Solution

A system and method that utilize historical Internet Protocol Address (IPA) size information to detect anomalies in traffic patterns by estimating IPA sizes at different times and comparing them to thresholds, employing algorithms and statistical methods to identify deviations indicative of machine-generated traffic, allowing for real-time action to prevent fraudulent activities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional traffic monitoring methods are used, then basic traffic flow can be measured, but machine-generated attacks cannot be detected

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by collecting historical IPA size data and establishing baseline patterns before attacks occur. This preparatory phase enables the system to compare current traffic against historical norms, allowing detection of anomalies without requiring complex real-time analysis during the attack itself.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces IPA size as an intermediary metric that bridges raw traffic data and attack detection. Instead of directly analyzing complex traffic patterns, the system uses IPA size - the number of unique IP addresses - as a simplified intermediate measure that effectively reveals machine-generated traffic anomalies while maintaining system simplicity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If historical IPA size data is collected and analyzed, then machine-generated traffic can be detected, but processing time and computational resources increase

Engineering Contradiction:
Improvedetection reliabilityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system applies partial action by focusing analysis on the specific metric of IPA size rather than examining all aspects of traffic data. This selective approach maintains high detection reliability for machine-generated traffic while minimizing unnecessary processing of other traffic characteristics, thereby reducing overall processing time.

Inventive Principle:
Principle #16Partial or excessive action

3Object-affected harmful factors

If IPA size thresholds are set to detect attacks, then fraudulent traffic can be identified, but false positives may occur

Engineering Contradiction:
Improvefraudulent traffic impactVSAvoiddetection accuracy
Core Design Contradiction:
Object-affected harmful factorsVSMeasurement precision

Solution Approach 1:

The system implements dynamic threshold adjustment based on historical patterns and current traffic conditions rather than using fixed thresholds. This dynamic approach allows the detection system to adapt to legitimate traffic variations, reducing false positives while maintaining sensitivity to actual attacks, thereby improving both fraud detection and measurement precision.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9027127B1Methods for detecting machine-generated attacks based on the IP address size
Publication Date: 2015.05.05 GOOGLE LLC
  • US9027127B1 patent drawing
  • US9027127B1 patent drawing
  • US9027127B1 patent drawing

AI summary

A system and method is disclosed for affecting action associated with machine-generated traffic. First historical information associated with Internet traffic to an Internet service at a first time is accessed and a first Internet Protocol Address (“IPA”) size representing a first number of devices sharing at least one IP address that accessed the Internet service at the first time is determined. Second historical information associated with Internet traffic to the Internet service that occurred at a second time is accessed and a second IPA size is determined. An algorithm is applied that uses the first IPA size to estimate a third IPA size, representing a third number of devices sharing at least one IP address at the second time. A difference between the third and the second IPA sizes is computed, and evaluated to a threshold. An action is taken at a resource-provider system when the difference exceeds the threshold.