Proxy Server Blacklist Generation for Monitoring Accuracy
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing media monitoring systems face challenges in preventing illicit proxy communications from affecting monitoring results, as non-panelist users can exploit proxy servers to bypass restrictions, anonymize their identity, or manipulate traffic data, leading to inaccurate monitoring outcomes.
Innovation Solution
A system that utilizes a blacklist generated by a central facility to block illicit traffic by analyzing proxy logs, identifying patterns, and distinguishing between legitimate and illegitimate communications, ensuring only authorized traffic from registered panelists is monitored and recorded.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If proxy servers are used to monitor Internet traffic, then monitoring coverage is improved, but illicit communications from non-panelist users can manipulate traffic data and affect monitoring accuracy
Solution Approach 1:
The patent introduces a central facility as an intermediary between proxy servers and monitoring systems. This central facility receives proxy logs, analyzes them to identify illicit communications, and generates blacklist files that are distributed back to proxy servers. The intermediary filters out non-panelist traffic before it can corrupt monitoring data, thus maintaining both broad monitoring coverage and high accuracy.
Solution Approach 2:
The system performs preliminary analysis of proxy logs to identify potential illicit communications before they can affect monitoring results. By proactively generating blacklist files based on analyzed patterns (such as high volumes of requests from single IP addresses or unusual traffic behaviors), the system prevents contamination of monitoring data in advance.
2Difficulty of detecting and measuring
If all proxy traffic is monitored and analyzed, then detection capability is improved, but processing resources and network bandwidth are consumed
Solution Approach 1:
Instead of analyzing every single proxy log entry in detail, the system applies partial action by focusing on key indicators of illicit behavior (such as request volume thresholds, unusual patterns, and blacklist matching). This selective analysis approach maintains high detection capability while significantly reducing processing resource consumption compared to exhaustive inspection of all traffic.
3Measurement precision
If blacklist filtering is applied at the proxy server, then monitoring accuracy is improved, but device complexity increases
Solution Approach 1:
The patent extracts the complex blacklist generation and analysis functions from individual proxy servers and consolidates them in a centralized facility. Proxy servers only need to implement simple functionality: receive blacklist files from the central facility and filter traffic against them. This extraction maintains high monitoring accuracy while minimizing the complexity burden on individual proxy servers.
Data Source
AI summary
Methods, apparatus, systems and articles of manufacture to prevent illicit proxy communications from affecting a monitoring result are disclosed. An example method includes accessing a log of communications of a proxy server, the log of communications including a plurality of records, each of the plurality of records corresponding to a requesting device that transmitted a communication to the proxy server, identifying a first internet protocol (IP) address subnet in the log of communications, the first IP address subnet associated with a block of IP addresses, filtering the plurality of records for a first set of records associated with communications originating from the first IP address subnet, and in response to determining the first set of records does not include a record associated with a heartbeat communication, adding the first IP address subnet to a blacklist of the proxy server.


