IP Library Granted Patent US 10,447,711
Granted Patent B2
US 10,447,711 · App. 15/061,604 · Granted Oct 15, 2019

System and method for identification of automated browser agents

Inventor: Daniel Kaminsky (San Francisco, CA)
Assignee: WHITE OPS INC.
H04L63/1416G06F21/31H04L63/14H04L63/1425G06F2221/2133H04L2463/144
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,447,711
App. No.
15/061,604
Granted
Oct 15, 2019
Kind
B2
Abstract

Disclosed herein are methods and systems for evaluating web browser behavior to report on human versus non-human activity, based on varying analyses of detectable properties. By passively detecting the code of a webpage engaged by a browsing user, the present invention evaluates the browsing user's activity in order to predict the type of user with a degree of confidence. The predictions are formed by acquiring information on how a user loads, navigates, and interacts with a webpage and comparing that information with known and unknown properties in various control groups. If the prediction yields a high likelihood of automated activity, additional active detection may be performed. Reports are compiled by analysis servers and made available to the operators of webpages. By compiling performance metrics and informing operators of fraudulent versus normal activity, the invention combats malicious automated traffic directed at any aspect of a given webpage.

Claims (26)

1. A method for detecting automated browser agents, comprising:

initiating a primary detection comprising passive probing, said primary detection comprising the steps of:

inserting a means for detecting information into a page code before a page is sent to a user's browser, sending said page to a user's browser, wherein said means sends emissions from one or more plugins via one or more channels, said emissions capturing client execution environment data without requiring a browser interaction and causing immediate and continued data collection of said client execution environment data,

transmitting via asynchronous posts said client execution environment data to an analysis server, wherein said analysis server compares said client execution environment data with a first database storing pattern characteristics for humans, a second database storing pattern characteristics for automated browser agents, and a third database storing pattern characteristics which are unclear as to whether performed by a human or a bot,

forming a report on automated browser agent activity based on a qualitative evaluation of performance metrics collected,

calculating a probability of the user being an automated browser agent, said probability being based on said report and said comparing with said three databases, and

initiating a secondary detection if said probability of the user being an automated browser agent guarantees a presence of automated agent activity, said secondary detection comprising active probing.

2. The method of claim 1 , further comprising calculating a second probability of the user being a human.

3. The method of claim 1 , wherein said secondary detection comprises detection of properties to classify automated agents by type.

4. The method of claim 1 , wherein said secondary detection comprises detection of non-native code modifying a function of a browser.

5. The method of claim 1 , wherein said secondary detection comprises detection of network-resident modifications to a function of a browser.

6. The method of claim 1 , wherein said secondary detection comprises detection of content injection.

7. The method of claim 1 , wherein said client execution environment data comprises emulated input.

8. The method of claim 1 , wherein said client execution environment data comprises JavaScript event loops.

9. The method of claim 1 , wherein said client execution environment data comprises a nature of character insertion.

10. The method of claim 1 , wherein said client execution environment data comprises optimization of JavaScript.

11. The method of claim 1 , wherein said client execution environment data comprises an ability to connect with a malware detection engine.

12. The method of claim 1 , wherein said client execution environment data comprises post-exploitation defenses.

13. The method of claim 1 , wherein said client execution environment data comprises data regarding a handling of cookies.

14. The method of claim 1 , wherein said client execution environment data comprises properties of TCP and UDP traffic.

15. The method of claim 1 , wherein said client execution environment data comprises an availability of server-side API technology.

16. The method of claim 1 , wherein said active probing comprises an active use of pop-ups.

17. The method of claim 1 , wherein said active probing comprises intrusive font detection.

18. The method of claim 1 , wherein said active probing comprises nonlinear sampling.

19. The method of claim 1 , wherein said active probing comprises forcing a bot to self-announce to arbitrary endpoints.

20. The method of claim 1 , wherein said secondary detection comprises detection of viewability modulation.

Assignments (9)
RELEASE OF SECURITY INTEREST Recorded Aug 5, 2025
From: ALTER DOMUS (US) LLC
To: HUMAN SECURITY, INC.; SINGULARITY BUYER LLC
Reel/Frame 071935/0384 →
RELEASE OF SECURITY INTEREST Recorded Aug 5, 2025
From: SILICON VALLEY BANK, A DIVISION OF FIRST-CITIZENS BANK & TRUST COMPANY
To: HUMAN SECURITY, INC.; SINGULARITY BUYER LLC; PERIMETERX, INC.
Reel/Frame 071935/0486 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jul 25, 2025
From: HUMAN SECURITY, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 072253/0310 →
SECURITY INTEREST Recorded Aug 9, 2022
From: HUMAN SECURITY, INC.; SINGULARITY BUYER LLC
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 060758/0288 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jul 29, 2022
From: HUMAN SECURITY, INC.; SINGULARITY BUYER LLC; PERIMETERX, INC.
To: SILICON VALLEY BANK
Reel/Frame 061006/0055 →
TERMINATION AND RELEASE OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jun 24, 2021
From: COMERICA BANK
To: WHITE OPS, INC.
Reel/Frame 056676/0040 →
CHANGE OF NAME Recorded Mar 31, 2021
From: WHITE OPS, INC.
To: HUMAN SECURITY, INC.
Reel/Frame 057170/0011 →
SECURITY INTEREST Recorded Aug 25, 2016
From: WHITE OPS, INC.
To: COMERICA BANK
Reel/Frame 039540/0048 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 21, 2016
From: KAMINSKY, DANIEL
To: WHITE OPS INC.
Reel/Frame 038971/0535 →
Continuity (3)
Continuation In Part 14057730 · Oct 18, 2013
Provisional Application 61715815 · Oct 18, 2012
Related Publication 20160191554A1 · Jun 30, 2016
Cited By (1)
US 12,316,635