Proxy Server Blacklist Generation for Monitoring Accuracy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing media monitoring systems face challenges in preventing illicit proxy communications from affecting monitoring results, as non-panelist users can exploit proxy servers to bypass restrictions, anonymize their identity, or manipulate traffic data, leading to inaccurate monitoring outcomes.

Innovation Solution

A system that utilizes a blacklist generated by a central facility to block illicit traffic by analyzing proxy logs, identifying patterns, and distinguishing between legitimate and illegitimate communications, ensuring only authorized traffic from registered panelists is monitored and recorded.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If proxy servers are used to monitor Internet traffic, then monitoring coverage is improved, but illicit communications from non-panelist users can manipulate traffic data and affect monitoring accuracy

Engineering Contradiction:
Improvemonitoring coverageVSAvoidmonitoring accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent introduces a central facility as an intermediary between proxy servers and monitoring systems. This central facility receives proxy logs, analyzes them to identify illicit communications, and generates blacklist files that are distributed back to proxy servers. The intermediary filters out non-panelist traffic before it can corrupt monitoring data, thus maintaining both broad monitoring coverage and high accuracy.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary analysis of proxy logs to identify potential illicit communications before they can affect monitoring results. By proactively generating blacklist files based on analyzed patterns (such as high volumes of requests from single IP addresses or unusual traffic behaviors), the system prevents contamination of monitoring data in advance.

Inventive Principle:
Principle #10Preliminary action

2Difficulty of detecting and measuring

If all proxy traffic is monitored and analyzed, then detection capability is improved, but processing resources and network bandwidth are consumed

Engineering Contradiction:
Improvedetection capabilityVSAvoidprocessing resources
Core Design Contradiction:
Difficulty of detecting and measuringVSUse of energy by moving object

Solution Approach 1:

Instead of analyzing every single proxy log entry in detail, the system applies partial action by focusing on key indicators of illicit behavior (such as request volume thresholds, unusual patterns, and blacklist matching). This selective analysis approach maintains high detection capability while significantly reducing processing resource consumption compared to exhaustive inspection of all traffic.

Inventive Principle:
Principle #16Partial or excessive action

3Measurement precision

If blacklist filtering is applied at the proxy server, then monitoring accuracy is improved, but device complexity increases

Engineering Contradiction:
Improvemonitoring accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent extracts the complex blacklist generation and analysis functions from individual proxy servers and consolidates them in a centralized facility. Proxy servers only need to implement simple functionality: receive blacklist files from the central facility and filter traffic against them. This extraction maintains high monitoring accuracy while minimizing the complexity burden on individual proxy servers.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11570270B2Methods and apparatus to prevent illicit proxy communications from affecting a monitoring result
Publication Date: 2023.01.31 THE NIELSEN CO (US) LLC
  • US11570270B2 patent drawing
  • US11570270B2 patent drawing
  • US11570270B2 patent drawing

AI summary

Methods, apparatus, systems and articles of manufacture to prevent illicit proxy communications from affecting a monitoring result are disclosed. An example method includes accessing a log of communications of a proxy server, the log of communications including a plurality of records, each of the plurality of records corresponding to a requesting device that transmitted a communication to the proxy server, identifying a first internet protocol (IP) address subnet in the log of communications, the first IP address subnet associated with a block of IP addresses, filtering the plurality of records for a first set of records associated with communications originating from the first IP address subnet, and in response to determining the first set of records does not include a record associated with a heartbeat communication, adding the first IP address subnet to a blacklist of the proxy server.