IP Address Size Anomaly Detection for Fraudulent Traffic
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Internet services face challenges in detecting and mitigating machine-generated traffic, such as botnet-based and proxy-based attacks, which distort traffic patterns and inflate click counts, leading to fraudulent activities that deceive advertisers and increase costs.
Innovation Solution
A system and method that utilize historical Internet Protocol Address (IPA) size information to detect anomalies in traffic patterns by estimating IPA sizes at different times and comparing them to thresholds, employing algorithms and statistical methods to identify deviations indicative of machine-generated traffic, allowing for real-time action to prevent fraudulent activities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional traffic monitoring methods are used, then basic traffic flow can be measured, but machine-generated attacks cannot be detected
Solution Approach 1:
The system performs preliminary actions by collecting historical IPA size data and establishing baseline patterns before attacks occur. This preparatory phase enables the system to compare current traffic against historical norms, allowing detection of anomalies without requiring complex real-time analysis during the attack itself.
Solution Approach 2:
The patent introduces IPA size as an intermediary metric that bridges raw traffic data and attack detection. Instead of directly analyzing complex traffic patterns, the system uses IPA size - the number of unique IP addresses - as a simplified intermediate measure that effectively reveals machine-generated traffic anomalies while maintaining system simplicity.
2Reliability
If historical IPA size data is collected and analyzed, then machine-generated traffic can be detected, but processing time and computational resources increase
Solution Approach 1:
The system applies partial action by focusing analysis on the specific metric of IPA size rather than examining all aspects of traffic data. This selective approach maintains high detection reliability for machine-generated traffic while minimizing unnecessary processing of other traffic characteristics, thereby reducing overall processing time.
3Object-affected harmful factors
If IPA size thresholds are set to detect attacks, then fraudulent traffic can be identified, but false positives may occur
Solution Approach 1:
The system implements dynamic threshold adjustment based on historical patterns and current traffic conditions rather than using fixed thresholds. This dynamic approach allows the detection system to adapt to legitimate traffic variations, reducing false positives while maintaining sensitivity to actual attacks, thereby improving both fraud detection and measurement precision.
Data Source
AI summary
A system and method is disclosed for affecting action associated with machine-generated traffic. First historical information associated with Internet traffic to an Internet service at a first time is accessed and a first Internet Protocol Address (“IPA”) size representing a first number of devices sharing at least one IP address that accessed the Internet service at the first time is determined. Second historical information associated with Internet traffic to the Internet service that occurred at a second time is accessed and a second IPA size is determined. An algorithm is applied that uses the first IPA size to estimate a third IPA size, representing a third number of devices sharing at least one IP address at the second time. A difference between the third and the second IPA sizes is computed, and evaluated to a threshold. An action is taken at a resource-provider system when the difference exceeds the threshold.


