Request Analysis System with Multi-Level Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Online social networks face challenges in maintaining security without unduly restricting users, as some users engage in unauthorized activities like spamming or scraping, while legitimate large-scale page requests are also common, making it difficult to balance security and user activity.

Innovation Solution

A programmatic method for automatic monitoring and real-time access restriction analysis of user requests, using parameter counters and multiple levels of checks to apply tailored access restrictions, optimizing resource use through data aggregation and storage techniques.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If per user request limits are implemented to prevent unauthorized activity, then security is improved, but legitimate large-scale requests are unduly restricted

Engineering Contradiction:
ImprovesecurityVSAvoiduser activity flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system segments the request analysis into multiple levels: a first level check that is not computationally intensive, and a second level check that is more resource-intensive. This segmentation allows the system to efficiently handle the majority of requests with minimal overhead while applying more rigorous analysis only when necessary, thus maintaining security without unduly restricting legitimate user activity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies different analysis depths to different requests based on their characteristics. Requests that appear legitimate or low-risk undergo only the first level check, while suspicious requests trigger the second level check. This local quality approach ensures that security resources are concentrated where needed while allowing legitimate traffic to flow freely.

Inventive Principle:
Principle #3Local quality

2Measurement precision

If comprehensive request monitoring is implemented to detect unauthorized activity, then security detection capability is improved, but system resource consumption increases

Engineering Contradiction:
Improveunauthorized activity detectionVSAvoidsystem resource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The monitoring system is divided into two distinct levels of checks. The first level check provides rapid, low-resource screening of all requests, while the second level check provides comprehensive analysis only for suspicious requests. This segmentation enables precise detection of unauthorized activity while keeping average resource consumption low by avoiding exhaustive analysis of every request.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs partial monitoring on all requests (first level check) and excessive/comprehensive monitoring only on suspicious requests (second level check). This partial or excessive action strategy ensures that detection precision is maintained for unauthorized activities while resource consumption is optimized by applying full monitoring only when necessary.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If per user request limits are enforced to prevent spamming, then network security is improved, but users may circumvent by creating multiple accounts

Engineering Contradiction:
Improvenetwork securityVSAvoidaccount management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system introduces an intermediary analysis layer that sits between the user and the request limits. Instead of simply counting requests per user account, the system analyzes the characteristics of requests and their patterns to identify coordinated activity across multiple accounts. This intermediary approach maintains security by detecting circumvention attempts while avoiding the need for complex account management rules.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The request analysis system serves multiple functions simultaneously: it enforces request limits, detects unauthorized activity patterns, identifies coordinated multi-account behavior, and allows legitimate large-scale requests. This multi-functionality reduces the need for separate complex account management mechanisms while maintaining network security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10044729B1Analyzing requests to an online service
Publication Date: 2018.08.07 MICROSOFT TECHNOLOGY LICENSING LLC
  • US10044729B1 patent drawing
  • US10044729B1 patent drawing
  • US10044729B1 patent drawing

AI summary

Computerized methods enable automatic monitoring of requests to an online service and apply access restrictions, as appropriate, to servicing of requests in real-time or near real-time. For each request received by the online service, a plurality of parameters associated with the request are identified, and counters corresponding to the particular values of the plurality of parameters associated with the request are incremented to track the number of times a parameter value appears or occurs in connection with requests to the online service. A first level check or analysis is performed to determine whether a second level check or analysis is required. The first level check or analysis comprises an initial screening that is not computationally intensive. The second level check or analysis is more resource-intensive and is triggered depending on the outcome of the first level check or analysis.