Network User Identification Using Behavioral Event Distributions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for distinguishing human users from non-human accounts, such as bots, in network communications are inefficient and unreliable, often requiring time-consuming data generation and validation, and have low success rates in accurately identifying human and non-human activity.
Innovation Solution
A system and method that analyzes network data by determining event frequency thresholds, generating distributions, and cross-referencing with known human user lists to identify human users based on consistent and human-like behavior patterns, using variables like IP addresses, device usage, and interaction patterns.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional abuse detection techniques are used to identify human users, then the detection process can be performed, but the accuracy of distinguishing human users from non-human accounts is low
Solution Approach 1:
The patent segments user identification into multiple independent behavioral dimensions (login patterns, device usage, interaction frequency, time-based activity) rather than relying on a single metric. Each dimension is evaluated separately and combined to form a comprehensive human-like behavior score, improving both accuracy and reliability of detection.
Solution Approach 2:
The patent transforms the detection approach by changing from static threshold-based identification to dynamic parameter analysis. It uses multiple varying parameters (event frequency, time intervals, device diversity metrics) that adapt to different user behaviors, enabling more accurate differentiation between human and non-human accounts while maintaining reliable detection.
2Productivity
If simple detection methods are used, then the process is fast and easy to implement, but the success rate of accurately identifying human and non-human activity is low
Solution Approach 1:
The patent performs preliminary analysis by pre-establishing human-like behavior benchmarks and patterns from training data before actual detection. Common behavioral patterns are pre-identified and stored as reference profiles, allowing the system to quickly compare new user activities against these pre-computed standards, maintaining fast detection speed while improving identification success rate.
Solution Approach 2:
The patent creates simplified copies or representations of complex human behavior patterns through behavioral profiles and signatures. Instead of analyzing every raw data point in detail, it uses compressed behavioral representations that capture essential human-like characteristics, enabling fast comparison and accurate identification without sacrificing detection speed.
3Measurement precision
If comprehensive behavioral analysis is performed to improve identification accuracy, then more accurate results are achieved, but the complexity of the detection system increases
Solution Approach 1:
The patent divides the complex behavioral analysis into modular segments, each handling a specific aspect (login behavior, device patterns, interaction styles). This segmentation allows the system to process complex information through manageable, independent modules that can be developed, tested, and maintained separately, reducing overall system complexity while maintaining comprehensive analysis capability.
Solution Approach 2:
The patent designs a universal behavioral analysis framework that handles multiple types of user activities and detection scenarios through a single unified system. The same core analysis engine processes different behavioral data types using consistent methods, reducing complexity compared to having separate specialized systems for each detection task.
Data Source
AI summary
Systems and methods are disclosed for identifying human users on a network. One method includes receiving network data comprising data transmitted over a network over predetermined time period, the network data comprising a plurality of usernames and a plurality of events, wherein each of the plurality of events is associated with at least one of the plurality of usernames; determining a plurality of pairs, each pair of the plurality of pairs comprising a username of the plurality of usernames and an associated event of the plurality of events; determining qualifying pairs of the plurality of pairs, the qualifying pairs corresponding to a subset of the plurality of pairs that meet or exceed one or more predetermined event frequency thresholds; determining non-qualifying pairs of the plurality of pairs, the non-qualifying pairs corresponding to the subset of the plurality of pairs that do not meet or exceed one or more predetermined event frequency thresholds; generating at least one distribution associated with the qualifying pairs and non-qualifying pairs; and based on the at least one distribution, determining if at least one username of the plurality of usernames is associated with a human user or a non-human user.


