Hierarchical IP Reputation Profiling for Fraud Request Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems struggle to effectively identify fraudulent requests due to the frequent changing of IP addresses, especially with the advent of IPv6, which complicates per-IP address abuse rating and leads to significant financial losses in advertising fraud.
Innovation Solution
A multi-tier hierarchy of IP address groups is defined, with reputation scores determined for these groups to assess fraud risk, capturing broader behavioral patterns across multiple IP addresses, rather than relying on a single IP address.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If per-IP address reputation scoring is used, then fraud detection can be performed, but IP address changes (especially with IPv6) cause the system to fail in identifying fraudulent requests
Solution Approach 1:
The patent segments the reputation assessment into multiple hierarchical tiers (first-tier IP address groups, second-tier IP address groups, etc.). Instead of relying on a single IP address, the system divides the assessment across multiple levels of IP address grouping, where each tier represents a different scope of network identification. This segmentation allows the system to maintain fraud detection capability while adapting to IP address changes, as fraudulent behavior patterns can be detected across the hierarchy even when individual IP addresses change.
Solution Approach 2:
The patent transitions from a one-dimensional assessment (single IP address) to a multi-dimensional hierarchical structure (multiple tiers of IP address groups). By adding the dimension of hierarchical grouping, the system can assess reputation at multiple levels simultaneously. When an IP address changes, the system can still detect fraud by examining the broader hierarchical context, effectively moving the detection problem from a single point to a structured space with multiple reference points.
2Measurement precision
If a single IP address is monitored, then detailed tracking is possible, but fraud detection accuracy decreases due to frequent IP address changes
Solution Approach 1:
The patent merges multiple IP address assessments into hierarchical groups. First-tier IP address groups combine multiple individual IP addresses, and second-tier groups combine multiple first-tier groups. This merging creates a more robust assessment mechanism where the reputation of individual IP addresses is evaluated in the context of their group memberships. Fraud detection accuracy improves because the system can identify patterns across merged IP addresses, reducing the impact of any single IP address change.
Solution Approach 2:
The patent introduces IP address groups as intermediary structures between individual IP addresses and the fraud detection system. These groups act as mediators that aggregate and contextualize reputation information. Instead of directly monitoring individual IP addresses, the system uses these intermediary groups to assess reputation, providing a stable reference frame that persists even when individual IP addresses within the groups change.
3Reliability
If IP address groups of larger size are analyzed, then fraud risk assessment becomes more comprehensive, but the complexity of the system increases
Solution Approach 1:
The patent segments the large-scale IP address group analysis into manageable hierarchical tiers. Rather than analyzing all IP addresses simultaneously, the system divides them into first-tier groups, then second-tier groups, and potentially additional tiers. This segmentation reduces computational complexity by breaking down the large problem into smaller, more manageable sub-problems at each tier, while still achieving comprehensive fraud risk assessment through the aggregated hierarchical structure.
Solution Approach 2:
The patent organizes IP address groups into a hierarchical dimension structure with multiple tiers. This dimensional organization transforms the complexity management from a flat, monolithic structure to a layered architecture. Each tier operates at a different level of abstraction, allowing the system to manage complexity by processing information at appropriate hierarchical levels rather than treating all IP addresses uniformly.
Data Source
AI summary
In an example, first-tier Internet Protocol (IP) address reputation scores, including a first first-tier IP address reputation score associated with a first first-tier IP address group and a second first-tier IP address reputation score associated with a second first-tier IP address group, may be determined based upon a plurality of events. A second-tier IP address reputation score associated with a second-tier IP address group may be determined based upon the plurality of first-tier IP address reputation scores. The second-tier IP address group may include the first first-tier IP address group and the second first-tier IP address group. An IP address reputation profile may be generated based upon the first-tier IP address reputation scores and the second-tier IP address reputation score. Whether or not a request for content associated with a first IP address is fraudulent may be determined based upon the IP address reputation profile and the first IP address.


