Security Scoring via Multi-Domain Telemetry Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Web and mobile applications face challenges in distinguishing between human and automated traffic, leading to increased user friction and security risks due to sophisticated attacks from bots, which can result in decreased usage and incomplete transactions.
Innovation Solution
A method involving instrumentation code that collects telemetry data from client computing devices, generating a security score based on identifying signal data to differentiate human users from automated software, thereby streamlining authentication processes and enhancing security without requiring additional hardware or software installations on web server systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multi-factor authentication and security safeguards are implemented, then security against bot attacks is improved, but user friction increases and transaction completion rates decrease
Solution Approach 1:
The system performs automatic bot detection and security assessment without requiring user intervention. The instrumentation code automatically collects telemetry data, and the server automatically generates security scores and makes authentication decisions, eliminating the need for users to manually complete CAPTCHAs or provide additional security factors.
Solution Approach 2:
The patent replaces manual security verification mechanisms (CAPTCHAs, multi-factor authentication challenges) with an automated telemetry-based security scoring system. The system uses programmatic collection and analysis of device telemetry data to automatically distinguish between human and bot users, substituting mechanical user actions with automated server-side analysis.
2Measurement precision
If CAPTCHAs and challenge-response tests are required, then differentiation between human users and automated software is improved, but user friction increases
Solution Approach 1:
The system automatically performs bot detection through instrumentation code that runs on the user's device. The telemetry data is collected and analyzed without requiring the user to interact with any challenge-response tests or CAPTCHAs, making the differentiation process transparent and frictionless for legitimate users.
Solution Approach 2:
The patent extracts the bot detection functionality from the user interaction flow and places it in the background instrumentation code. The security assessment is performed separately from the main transaction flow, allowing human-bot differentiation to occur without interrupting or complicating the user experience.
3Reliability
If re-authentication is required at various points, then security is improved, but usage and transaction completion decrease
Solution Approach 1:
The security score is dynamic and continuously updated based on incoming telemetry data. The system adjusts authentication requirements in real-time based on the current security assessment, allowing legitimate users with high security scores to proceed without re-authentication while maintaining security for suspicious activities.
Solution Approach 2:
The system continuously monitors telemetry data and provides feedback through updated security scores. This feedback mechanism allows the system to adapt authentication requirements based on ongoing user behavior patterns, maintaining security while minimizing friction for consistent, legitimate usage patterns.
Data Source
AI summary
A method, non-transitory compute r readable medium, device, and system that receives telemetry data collected based on instrumentation code executed at one of a plurality of client computing devices with a requested transaction with one of a plurality of web server systems. Identifying signal data (IDSD) usable to identify the one of client computing devices is determined based on the received telemetry data. Any matching telemetry data in a telemetry data set for a plurality of prior transactions between one or more of the client computing devices and one or more of the web server systems is identified based on any stored IDSDs that match the received IDSD. A security score associated with the one of the client computing devices is generated based on the identified matching telemetry data. A response to the requested transaction to the one of client computing devices is managed based on the generated security score.


