Third-Party Tag Risk Inference via Browser Mimicry

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The proliferation of third-party tags on websites poses challenges in protecting user data from unauthorized use and malicious activities, as these tags can forward data without permission, engage in malicious behavior, and complicate analysis due to their complex interactions, especially with JavaScript, forcing a trade-off between security and convenience.

Innovation Solution

A system that mimics a web browser to monitor and analyze third-party tags, constructing a hierarchical model to assign threat scores based on attributes, providing transparency to website owners about potential data leakage and allowing them to block non-compliant partners, thereby enhancing privacy compliance and monetization strategies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If third-party tags are added to websites for data collection and targeted advertising, then monetization and analytics accuracy are improved, but user data security and privacy protection deteriorate

Engineering Contradiction:
Improvemonetization efficiencyVSAvoiddata leakage risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary system that sits between third-party tags and user data, acting as a security gatekeeper. This intermediary monitors tag activities, enforces security policies, and controls data access without preventing the tags from functioning. The system mediates between the need for data collection (for monetization) and the need for data protection, allowing legitimate operations while blocking malicious ones.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If multiple third-party tags are deployed for comprehensive tracking, then analytics precision and advertising targeting are improved, but system complexity and difficulty of management increase

Engineering Contradiction:
Improveanalytics accuracyVSAvoidtag management complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent creates a universal management system that handles multiple third-party tags through a single interface and unified policy framework. Instead of requiring separate management for each tag, the system provides multi-functional capabilities including security policy enforcement, performance monitoring, and centralized control across all tags. This universal approach simplifies management while maintaining the analytical precision of individual tags.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If third-party tags are allowed to operate without restrictions, then ease of operation and website functionality are improved, but security vulnerabilities and malicious activity risks increase

Engineering Contradiction:
Improvewebsite operation simplicityVSAvoidsecurity reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements a self-service security model where the monitoring system automatically detects, analyzes, and responds to security threats without requiring manual intervention. The system self-adjusts security policies, automatically blocks malicious tags, and provides real-time security assessments. This self-service capability maintains ease of operation while significantly improving security reliability through automated protection mechanisms.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3047370B1Method and system for inferring risk of data leakage from third-party tags
Publication Date: 2019.10.30 LIVERAMP
  • EP3047370B1 patent drawingFigure 1
  • EP3047370B1 patent drawingFigure 2
  • EP3047370B1 patent drawingFigure 3

AI summary

A method and system for assessing the data leakage threat associated with third-party tags on a particular website, such as a content publisher site, is assessed by mimicking a standard web browser. Each third-party tag on the site is identified and investigated in a hierarchical manner, and a data leakage threat score is assigned to each third-party tag based on certain attributes associated with the tag and the resource linked by the third-party tag. A cumulative data leakage threat score is then calculated to determine if the site is a data leakage threat, such as a threat for misuse of a consumer's data.