IP Library Granted Patent US 10,375,194
Granted Patent B2
US 10,375,194 · App. 14/928,610 · Granted Aug 6, 2019

Methods and apparatus to prevent illicit proxy communications from affecting a monitoring result

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,375,194
App. No.
14/928,610
Granted
Aug 6, 2019
Kind
B2
Abstract

Methods, apparatus, systems and articles of manufacture to prevent illicit proxy communications from affecting a monitoring result are disclosed. An example method includes accessing a log of communications from a proxy. A subnet represented in the log of communications is identified. The subnet is identified as having originated an illicit network communication if the log of communications does not include at least one record matching a signature of a mobile device heartbeat originating from the subnet. A blacklist of subnets not to be serviced by the proxy is generated, the blacklist including the subnet when the subnet is identified as having originated the illicit network communication. The blacklist is provided to the proxy. The blacklist is to prevent a subnet that originated the illicit network communication from affecting the monitoring result.

Claims (47)

1. A method to prevent illicit network communications from affecting a monitoring result of an audience measurement entity, the method comprising:

accessing, at the audience measurement entity, a log of communications from a proxy, the proxy to transmit a communication between a requesting device and a media provider;

identifying a subnet represented in the log of communications;

identifying, with a processor, the subnet as having a first address that originated an illicit network communication if the log of communications does not include at least one signature of a heartbeat message having a second address within the subnet, the heartbeat message identified by at least one of (1) comparing a user agent field of a record associated with the heartbeat message to user agent fields indicative of the record originating from a mobile device or (2) comparing a uniform resource locator field of the record to uniform resource locator fields indicative of the record originating from a mobile device, the heartbeat message associated with communication between the mobile device and a software provider, the illicit network communication indicating the record originated from a non-mobile device;

generating a blacklist of subnets not to be serviced by the proxy, the blacklist including the subnet when the subnet is identified as having originated the illicit network communication; and

providing the blacklist to the proxy, the blacklist to prevent a subnet that originated the illicit network communication from affecting the monitoring result of the audience measurement entity.

2. The method as disclosed in claim 1 , wherein the identifying of the subnet as having originated the illicit network communication includes identifying that there are at least a threshold number of records originating from the subnet in the log of communications.

3. The method as disclosed in claim 1 , further including:

determining whether there are less than a threshold number of unique user agents identified by records of the log of communications associated with the subnet; and

alerting an administrator of the subnet for manual inclusion in the blacklist.

4. The method as disclosed in claim 1 , further including:

determining whether there are greater than a threshold number of ports identified by records of the log of communications associated with the subnet; and

alerting an administrator of the subnet for manual inclusion in the blacklist.

5. The method as disclosed in claim 1 , further including:

excluding, with the processor, records from the log of communications associated with the subnet to form a log of legitimate communications; and

processing the log of legitimate communications to credit usage of mobile computing devices.

6. The method as disclosed in claim 1 , wherein the log of communications is a current log of communications, and the blacklist includes the subnet when the subnet was identified as having originated illicit network communications in a prior log of communications from the proxy.

7. The method as disclosed in claim 6 , wherein the prior log of communications corresponds to a first period of time immediately preceding a second period of time corresponding to the current log of communications from the proxy.

8. The method as disclosed in claim 1 , wherein the blacklist does not include the subnet when the subnet has not been identified as having originated the illicit network communication for more than a threshold period of time.

9. An apparatus to prevent illicit network communications from affecting a monitoring result of an audience measurement entity, the apparatus comprising:

a hardware logic circuit;

a proxy log filterer to access, at the audience measurement entity, a log of communications from a proxy, the proxy to transmit a communication between a requesting device and a media provider;

a heartbeat detector to identify a subnet within the log of communications as having a first address that originated an illicit network communication if the log of communications does not include at least one signature of a heartbeat message having a second address within the subnet, the heartbeat message identified by at least one of (1) comparing a user agent field of a record associated with the heartbeat message to user agent fields indicative of the record originating from a mobile device or (2) comparing a uniform resource locator field of the record to uniform resource locator fields indicative of the record originating from a mobile device, the heartbeat message associated with communication between the mobile device and a software provider, the illicit network communication indicating the record originated from a non-mobile device; and

a blacklist generator to generate a blacklist of subnets not to be serviced by the proxy, the blacklist including the subnet when the subnet is identified as having originated the illicit network communication, the blacklist generator to provide the blacklist to the proxy, the blacklist to prevent a subnet that originated the illicit network communication from affecting the monitoring result of the audience measurement entity, wherein at least one of the proxy log filterer, the heartbeat detector, or the blacklist generator is implemented via the hardware logic circuit.

10. The apparatus as disclosed in claim 9 , further including a crediting processor to generate the monitoring result using a subsequent log of communications created by the proxy, the subsequent log of communications excluding communications from the subnet identified in the blacklist.

11. The apparatus as disclosed in claim 9 , further including a proxy log parser to determine whether there are less than a threshold number of unique user agents identified by records of the log of communications associated with the subnet, the proxy log parser to identify the subnet to an administrator when there are less than the threshold number of unique user agents identified by the records of the log of communications associated with the subnet.

12. The apparatus as disclosed in claim 9 , further including a proxy log parser to determine whether there are greater than a threshold number of ports identified by records of the log of communications associated with the subnet, the proxy log parser to identify the subnet to an administrator when there are greater than the threshold number of ports identified by the records of the log of communications associated with the subnet.

13. The apparatus as disclosed in claim 9 , wherein the blacklist does not include the subnet when the subnet has not been identified as having originated the illicit network communication for more than a threshold period of time.

14. A non-transitory computer-readable medium comprising instructions which, when executed, cause a central facility of an audience measurement entity to at least:

access, at the central facility, a log of communications from a proxy, the proxy to transmit a communication between a requesting device and a media provider;

identify a subnet represented in the log of communications;

identify the subnet as having a first address that originated an illicit network communication if the log of communications does not include at least one signature of a heartbeat message having a second address within the subnet, the heartbeat message identified by at least one of (1) comparing a user agent field of a record associated with the heartbeat message to user agent fields indicative of the record originating from a mobile device or (2) comparing a uniform resource locator field of the record to uniform resource locator fields indicative of the record originating from a mobile device, the heartbeat message associated with communication between the mobile device and a software provider, the illicit network communication indicating the record originated from a non-mobile device;

generate a blacklist of subnets not to be serviced by the proxy, the blacklist including the subnet when the subnet is identified as having originated the illicit network communication; and

provide the blacklist to the proxy, the blacklist to prevent a subnet that originated the illicit network communication from affecting a monitoring result of the audience measurement entity.

15. The non-transitory computer-readable medium as disclosed in claim 14 , wherein the instructions, when executed, further cause the central facility to identify that there are at least a threshold number of records in the log of communications.

16. The non-transitory computer-readable medium as disclosed in claim 14 , wherein the instructions, when executed, further cause the central facility to at least:

determine whether there are less than a threshold number of unique user agents identified by records of the log of communications associated with the subnet; and

alert an administrator of the subnet for manual inclusion in the blacklist.

17. The non-transitory computer-readable medium as disclosed in claim 14 , wherein the instructions, when executed, further cause the central facility to at least:

determine whether there are greater than a threshold number of ports identified by records of the log of communications associated with the subnet; and

alert an administrator of the subnet for manual inclusion in the blacklist.

18. The non-transitory computer-readable medium as disclosed in claim 14 , wherein the instructions, when executed, further cause the central facility to at least:

exclude records from the log of communications associated with the subnet to form a log of legitimate communications; and

process the log of legitimate communications to credit usage of mobile computing devices.

19. The non-transitory computer-readable medium as disclosed in claim 14 , wherein the log of communications is a current log of communications, and the blacklist includes the subnet when the subnet was identified as having originated illicit network communications in a prior log of communications from the proxy.

20. The non-transitory computer-readable medium as disclosed in claim 19 , wherein the prior log of communications corresponds to a first period of time immediately preceding a second period of time corresponding to the current log of communications from the proxy.

21. The non-transitory computer-readable medium as disclosed in claim 14 , wherein the blacklist does not include the subnet when the subnet has not been identified as having originated the illicit network communication for more than a threshold period of time.

Assignments (8)
RELEASE (REEL 054066 / FRAME 0064) Recorded May 11, 2023
From: CITIBANK, N.A.
To: A. C. NIELSEN COMPANY, LLC; EXELATE, INC.; GRACENOTE, INC.; GRACENOTE MEDIA SERVICES, LLC; THE NIELSEN COMPANY (US), LLC; NETRATINGS, LLC
Reel/Frame 063605/0001 →
RELEASE (REEL 053473 / FRAME 0001) Recorded May 11, 2023
From: CITIBANK, N.A.
To: A. C. NIELSEN COMPANY, LLC; EXELATE, INC.; GRACENOTE, INC.; GRACENOTE MEDIA SERVICES, LLC; THE NIELSEN COMPANY (US), LLC; NETRATINGS, LLC
Reel/Frame 063603/0001 →
SECURITY INTEREST Recorded May 8, 2023
From: GRACENOTE DIGITAL VENTURES, LLC; GRACENOTE MEDIA SERVICES, LLC; GRACENOTE, INC.; TNC (US) HOLDINGS, INC.; THE NIELSEN COMPANY (US), LLC
To: ARES CAPITAL CORPORATION
Reel/Frame 063574/0632 →
SECURITY INTEREST Recorded Apr 28, 2023
From: GRACENOTE DIGITAL VENTURES, LLC; GRACENOTE MEDIA SERVICES, LLC; GRACENOTE, INC.; TNC (US) HOLDINGS, INC.; THE NIELSEN COMPANY (US), LLC
To: CITIBANK, N.A.
Reel/Frame 063561/0381 →
SECURITY AGREEMENT Recorded Jan 31, 2023
From: GRACENOTE DIGITAL VENTURES, LLC; GRACENOTE MEDIA SERVICES, LLC; GRACENOTE, INC.; TNC (US) HOLDINGS, INC.; THE NIELSEN COMPANY (US), LLC
To: BANK OF AMERICA, N.A.
Reel/Frame 063560/0547 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PATENTS LISTED ON SCHEDULE 1 RECORDED ON 6-9-2020 PREVIOUSLY RECORDED ON REEL 053473 FRAME 0001. ASSIGNOR(S) HEREBY CONFIRMS THE SUPPLEMENTAL IP SECURITY AGREEMENT. Recorded Oct 7, 2020
From: A.C. NIELSEN (ARGENTINA) S.A.; A.C. NIELSEN COMPANY, LLC; ACN HOLDINGS INC.; ACNIELSEN CORPORATION; ACNIELSEN ERATINGS.COM; AFFINNOVA, INC.; ART HOLDING, L.L.C.; ATHENIAN LEASING CORPORATION; CZT/ACN TRADEMARKS, L.L.C.; EXELATE, INC.; GRACENOTE, INC.; GRACENOTE DIGITAL VENTURES, LLC; GRACENOTE MEDIA SERVICES, LLC; NETRATINGS, LLC; NIELSEN AUDIO, INC.; NIELSEN CONSUMER INSIGHTS, INC.; NIELSEN CONSUMER NEUROSCIENCE, INC.; NIELSEN FINANCE CO.; NIELSEN FINANCE LLC; NIELSEN INTERNATIONAL HOLDINGS, INC.; NIELSEN MOBILE, LLC; NMR INVESTING I, INC.; TCG DIVESTITURE INC.; TNC (US) HOLDINGS, INC.; THE NIELSEN COMPANY (US), LLC; VIZU CORPORATION; VNU MARKETING INFORMATION, INC.; NMR LICENSING ASSOCIATES, L.P.; NIELSEN HOLDING AND FINANCE B.V.; THE NIELSEN COMPANY B.V.; VNU INTERNATIONAL B.V.
To: CITIBANK, N.A
Reel/Frame 054066/0064 →
SUPPLEMENTAL SECURITY AGREEMENT Recorded Jun 9, 2020
From: A. C. NIELSEN COMPANY, LLC; ACN HOLDINGS INC.; ACNIELSEN CORPORATION; ACNIELSEN ERATINGS.COM; AFFINNOVA, INC.; ART HOLDING, L.L.C.; ATHENIAN LEASING CORPORATION; CZT/ACN TRADEMARKS, L.L.C.; EXELATE, INC.; GRACENOTE, INC.; GRACENOTE DIGITAL VENTURES, LLC; GRACENOTE MEDIA SERVICES, LLC; NETRATINGS, LLC; NIELSEN AUDIO, INC.; NIELSEN CONSUMER INSIGHTS, INC.; NIELSEN CONSUMER NEUROSCIENCE, INC.; NIELSEN FINANCE CO.; NIELSEN FINANCE LLC; NIELSEN INTERNATIONAL HOLDINGS, INC.; NIELSEN MOBILE, LLC; NIELSEN UK FINANCE I, LLC; NMR INVESTING I, INC.; TCG DIVESTITURE INC.; TNC (US) HOLDINGS, INC.; THE NIELSEN COMPANY (US), LLC; VIZU CORPORATION; VNU MARKETING INFORMATION, INC.; NMR LICENSING ASSOCIATES, L.P.; NIELSEN HOLDING AND FINANCE B.V.; THE NIELSEN COMPANY B.V.; VNU INTERNATIONAL B.V.
To: CITIBANK, N.A.
Reel/Frame 053473/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 17, 2016
From: CIMINO, SUSAN; PAPAKOSTAS, ACHILLEAS
To: THE NIELSEN COMPANY (US), LLC
Reel/Frame 040356/0303 →