IP Library › Granted Patent US 10,320,628
Granted Patent B2
US 10,320,628 · App. 13/965,003 · Granted Jun 11, 2019

Confidence scoring of device reputation based on characteristic network behavior

Inventors: Jacob Wan (Victoria, CA); Greg Unrein (Portland, OR); Martin Kagan (Portland, OR)
Assignee: Citrix Systems, Inc.
H04L43/04H04L41/142H04L61/1511H04L63/1441H04L67/22H04L43/0864H04L67/02H04L67/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,320,628
App. No.
13/965,003
Granted
Jun 11, 2019
Kind
B2
Abstract

The technology disclosed relates to detection of anonymous proxies and bots making requests to a cloud based resource on the Internet, such as a web server or an App server. The technology can leverage one or more of: instrumentation of web pages that samples response times and other characteristics of communications by a requestor device over multiple network segments; lack of prior appearance of the requestor device across multiple, independently operated commercial web sites; and resolver usage by the requestor. These signals can be analyzed to score a requesting device's reputation. A location reported by a user device can be compared to a network characteristic determined location.

Claims (74)

1. A method of evaluating reputation of a requestor device that makes a request to a cloud-based resource on the internet, including:

providing an initial response to the requestor device making a request to a cloud-based resource on the internet, the initial response including an instrumented web page or instructions to be processed by an application running on the requestor device, wherein the initial response includes code adapted to:

collect data regarding at least internet round trip latency between the requestor device and four or more target addresses, each target address being different from one another, and

report the internet round trip latency for the target addresses;

compiling a characteristic vector for the requestor device including at least the reported internet round trip latency for the target addresses;

scoring the characteristic vector for similarity to expected characteristics of a first reference device at a first reference IP address expected to share internet round trip latency characteristics with the requestor device; and

storing, on a non-transitory computer-readable medium, at least one reputation score, wherein the reputation score is based at least in part on the scoring the characteristic vector and correlates with a likelihood that the requestor device is a bot or is operating through an anonymous proxy server.

2. The method of claim 1 , further including:

scoring the characteristic vector using a median of estimated probability measures of characteristics in the characteristic vector taken individually.

3. The method of claim 1 , further including:

scoring the characteristic vector by combining estimated variance from the expected round trip latency characteristics for the target addresses in the characteristic vector.

4. The method of claim 1 , further including:

scoring the characteristic vector using an estimated joint probability distribution that combines at least one characteristic from each of at least four target addresses, wherein the joint probability distribution is estimated from at least 1000 samples that combine the least one characteristic from the at least four target addresses.

5. The method of claim 1 , further including:

providing the code further adapted to:

collect data regarding at least availability of target addresses from the requestor device and

report the availability of the target addresses; and

compiling in the characteristic vector a reported availability of the target addresses to the requestor device; and

scoring the characteristic vector by determining whether the availability of targets in the characteristic vector is different than expected availability of the targets to a second reference device at a second reference IP address expected to share availability status with the requestor device.

6. The method of claim 5 , further including:

scoring the characteristic vector by requiring the same availability status as expected for all targets in the characteristic vector.

7. The method of claim 1 , further including:

providing the code further adapted to:

collect data regarding at least throughput rates between the requestor device and the target addresses and

report the throughput rates for the target addresses; and

compiling in the characteristic vector a reported throughput rates between the requestor device and the target addresses; and

scoring the characteristic vector for similarity to expected characteristics of a third reference requestor device at a third reference IP address expected to share throughput rate characteristics with the requestor device.

8. The method of claim 1 , further including: scoring the characteristic vector by combining estimated variances between throughput in the characteristic vector and expected throughput rate characteristics for the target addresses.

9. The method of claim 1 , further including:

providing the code further adapted to:

collect data regarding at least connection establishment times for connections between the requestor device and the target addresses and

report the connection establishment times for the target addresses; and

compiling in the characteristic vector a reported connection establishment times between the requestor device and the requestor device; and

scoring the characteristic vector for similarity to expected characteristics of a fourth reference requestor device at a fourth reference IP address expected to share connection establishment time characteristics with the requestor device.

10. The method of claim 1 , further including:

receiving requestor device characteristics including at least an IP address, browser type and version identifiers, and operating system type and version identifiers with a request from the requestor device;

looking up in a requestor history database, that reflects requests compiled from more than 100 independently operating servers, a frequency of requests made by devices sharing the requestor device characteristics; and

scoring the requestor device characteristics for frequency and/or diversity of requests made to the independently operating servers within a predetermined recent time.

11. The method of claim 1 , further including:

scoring requestor device characteristics using logarithmic scaling of the frequency and/or diversity of the requests made by devices sharing the requestor device characteristics.

12. The method of claim 1 , further including:

providing the code further adapted to:

collect data regarding a resolver used by the requestor device to find IP addresses corresponding to fully qualified domain names and

report the resolver used by the requestor device; and

scoring the characteristic vector for matching expected resolver usage of a reference requestor device at a reference IP address expected to share resolver usage characteristics with the requestor device and producing at least one reputation score.

13. The method of claim 1 , further including:

scoring the characteristic vector by combining estimated variance from resolver usage characteristics of the requestor device.

14. A method of evaluating reputation of a requestor device that makes a request to a web site over the internet, including:

receiving requestor device characteristics including at least an internet protocol address, browser type and version identifiers, and operating system type and version identifiers with a request from the requestor device making the request to the web site;

looking up in a requestor history database, that reflects requests compiled from more than 100 independently operating servers, a frequency of requests made by devices sharing the requestor device characteristics;

scoring the requestor device characteristics for frequency and/or diversity of requests made to the independently operating servers within a predetermined recent time; and

storing, on a non-transitory computer-readable medium, the scored requestor device characteristics, wherein the scored requestor device characteristics indicate whether the requestor device is a bot or is operating through an anonymous proxy server.

15. The method of claim 14 , further including:

scoring the requestor device characteristics using logarithmic scaling of the frequency and/or diversity of the requests made by devices sharing the requestor device characteristics.

16. The method of claim 14 , further comprising:

providing an initial response to a requestor device that includes an instrumented web page or instructions to be processed by an application running on the requestor device, wherein the initial response includes code adapted to:

collect data regarding at least availability of target addresses from the requestor device and

report the availability of the target addresses; and

compiling in a characteristic vector a reported availability of the target addresses to the requestor device; and

scoring the characteristic vector by determining whether the availability of targets in the characteristic vector is different than expected availability of a reference device at a reference internet protocol address expected to share availability status with the requestor device.

17. A method of evaluating reputation of a requestor device that makes a request to a web site, including:

responsive to a request from the requestor device making a request to the web site, providing an initial response to a requestor device that includes an instrumented web page or instructions to be processed by an application running on the requestor device, wherein the initial response includes code adapted to:

collect and compile in a characteristic vector data regarding a resolver used by the requestor device to find IP addresses corresponding to fully qualified domain names and

report the resolver used by the requestor device; and

scoring the characteristic vector for matching expected resolver usage of a reference requestor device at a reference internet protocol address expected to share resolver usage characteristics with the requestor device; and

storing, on a non-transitory computer-readable medium, at least one reputation score wherein the at least one reputation score correlates with a likelihood that the requestor device is a bot or is operating through an anonymous proxy server.

18. The method of claim 17 , further including:

scoring the characteristic vector by combining estimated variance from the resolver usage characteristics of the requestor device.

19. The method of claim 17 , further comprising:

providing the code further adapted to:

collect data regarding at least availability of target addresses from the requestor device and

report the availability of the target addresses; and

compiling in the characteristic vector a reported availability of the target addresses to the requestor device; and

scoring the characteristic vector by determining whether the availability of targets in the characteristic vector is different than expected availability of a reference device at a reference internet protocol address expected to share availability status with the requestor device.

Assignments (10)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 12, 2018
From: CEDEXIS, INC.
To: CITRIX SYSTEMS, INC.
Reel/Frame 044894/0879 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 13, 2014
From: WAN, JACOB; UNREIN, GREG; KAGAN, MARTIN
To: CEDEXIS, INC.
Reel/Frame 033097/0374 →
Continuity (2)
Provisional Application 61837073 · Jun 19, 2013
Related Publication 20140379902A1 · Dec 25, 2014
Cited By (1)
US 12,273,316