IP Library Granted Patent US 9,674,218
Granted Patent B2
US 9,674,218 · App. 15/210,221 · Granted Jun 6, 2017

Detection of click-fraud

Inventor: Avi Turgeman (Cambridge, MA)
Assignee: BioCatch Ltd.
H04L63/1458G06F3/041G06F3/0488G06F21/31G06F21/316G06F21/32G06F21/552G06F21/554G06Q30/0248G06Q30/0277H04L63/08H04L63/10H04L63/1408H04L67/22H04L67/306G06F2221/2133H04L2463/102H04L2463/144
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,674,218
App. No.
15/210,221
Granted
Jun 6, 2017
Kind
B2
Abstract

Devices, systems, and methods of detecting user identity, differentiating between users of a computerized service, detecting a cyber-attacker, and detecting click-fraud. An end-user device (a desktop computer, a laptop computer, a smartphone, a tablet, or the like) interacts and communicates with a server of a computerized server (a banking website, an electronic commerce website, or the like). The interactions are monitored, tracked and logged. User Interface (UI) interferences or irregularities are intentionally introduced to the communication session; and the server tracks the response or the reaction of the end-user to such communication interferences. The system determines whether the user is a legitimate human user, or a cyber-attacker or automated script posing as the legitimate human user. The system further detects click-fraud, and prevents or mitigates Application Distributed Denial-of-Service attacks.

Claims (59)

1. A method comprising:

detecting fraudulent clicks performed towards an on-screen advertisement; wherein the detecting comprises:

(a) presenting to a user of an electronic device, a screen comprising content and said on-screen advertisement;

(b) injecting a temporary input/output interference that causes an on-screen pointer, that is on route to click within said on-screen advertisement, to exhibit irregular behavior from its regular route;

wherein the injecting comprises:

injecting a temporary input/output interference that replaces the on-screen pointer with both: (I) a real on-screen pointer that is visible to human users and is detectable by computerized scripts, and (II) a fake on-screen pointer that is invisible to human users and is detectable by computerized scripts;

wherein said temporary input/output interference causes human users to click within said on-screen advertisement, and causes computerized scripts to click outside of said on-screen advertisement;

(c) tracking user interactions with an input unit in response to said temporary input/output interference;

(d) determining that said user did not perform sufficient manual correction operations that fix said temporary input/output interference;

(e) based on step (d), determining that a click performed within said on-screen advertisement, was performed by a click-fraud mechanism.

2. The method of claim 1 , wherein step (b) of injecting the temporary input/output interference comprises:

injecting a temporary input/output interference that causes an on-screen pointer, that is on route to click within said on-screen advertisement, to deviate from its expected on-screen route.

3. The method of claim 1 , wherein step (b) of injecting the temporary input/output interference comprises:

injecting a temporary input/output interference that causes an on-screen pointer, that is on route to click within said on-screen advertisement, to temporarily disappear.

4. The method of claim 1 , wherein step (b) of injecting the temporary input/output interference comprises:

injecting a temporary input/output interference that causes an on-screen pointer, that is on route to click within said on-screen advertisement, to disappear from a first on-screen location and to re-appear at a second, different, on-screen location.

5. The method of claim 1 , wherein step (b) of injecting the temporary input/output interference comprises:

injecting a temporary input/output interference that causes an on-screen pointer, that is on route to click within said on-screen advertisement, to appear at a pseudo-random offset relative to a regular non-interfered location of said on-screen pointer.

6. The method of claim 1 , wherein step (b) of injecting the temporary input/output interference comprises:

injecting a temporary input/output interference that causes an on-screen pointer to operate irregularly relative to pointer-controlling gestures that are inputted by said user while said user is attempting to move said on-screen pointer towards said advertisement.

7. The method of claim 1 , wherein step (b) of injecting the temporary input/output interference comprises:

injecting a temporary input/output interference that causes an on-screen pointer to operate irregularly relative to pointer-controlling gestures that are inputted by said user while said user is attempting to move said on-screen pointer towards said advertisement; wherein said temporary input/output interference is exhibited as anomaly between (i) user gestures via the input unit, and (ii) on-screen behavior of the on-screen pointer.

8. The method of claim 1 , wherein step (b) of injecting the temporary input/output interference comprises:

injecting a temporary input/output interference that causes an on-screen pointer to operate irregularly relative to pointer-controlling gestures that are inputted by said user while said user is attempting to move said on-screen pointer towards said advertisement;

wherein said temporary input/output interference is exhibited as anomaly between (i) user gestures via the input unit, and (ii) on-screen behavior of the on-screen pointer;

wherein the temporary input/output interference causes the on-screen pointer to reach an on-screen location that is external to said advertisement unless manual correction operations are performed via the input unit in response to said temporary input/output interference.

9. The method of claim 1 , wherein step (a) comprises:

presenting to said user of said electronic device, a web-page comprising said content and said on-screen advertisement.

10. The method of claim 1 , wherein step (a) comprises:

presenting to said user of said electronic device, a native mobile application comprising said content and said on-screen advertisement.

11. A method comprising: detecting fraudulent clicks performed towards an on-screen advertisement: wherein the detecting comprises:

(a) presenting to a user of an electronic device, a screen comprising content and said on-screen advertisement;

(b) injecting a temporary input/output interference that causes an on-screen pointer, that is on route to click within said on-screen advertisement, to exhibit irregular behavior from its regular route;

wherein the injecting comprises: injecting a temporary input/output interference that replaces the on-screen pointer with both: (I) a real on-screen pointer that is visible to human users and is detectable by computerized scripts, and (II) a fake on-screen pointer that is invisible to human users and is detectable by computerized scripts, wherein the real on-screen pointer is located at a constant on-screen offset distance relative to the fake on-screen pointer;

(c) tracking user interactions with an input unit in response to said temporary input/output interference;

(d) determining that said user did not perform sufficient manual correction operations that fix said temporary input/output interference

(e) based on step (d), determining that a click performed within said on-screen advertisement, was performed by a click-fraud mechanism.

12. A method comprising:

detecting fraudulent clicks performed towards an on-screen advertisement: wherein the detecting comprises:

(a) presenting to a user of an electronic device, a screen comprising content and said on-screen advertisement;

(b) injecting a temporary input/output interference that causes an on-screen pointer, that is on route to click within said on-screen advertisement, to exhibit irregular behavior from its regular route;

wherein the injecting comprises:

injecting a temporary input/output interference that replaces the on-screen pointer with both: (I) a real on-screen pointer that is visible to human users and is detectable by computerized scripts, and (II) a fake on-screen pointer that is invisible to human users and is detectable by computerized scripts,

wherein the real on-screen pointer is located at a dynamically-changing on-screen offset distance relative to the fake on-screen pointer;

(c) tracking user interactions with an input unit in response to said temporary input/output interference;

(d) determining that said user did not perform sufficient manual correction operations that fix said temporary input/output interference;

(e) based on step (d), determining that a click performed within said on-screen advertisement, was performed by a click-fraud mechanism.

13. A method comprising:

detecting fraudulent clicks performed towards an on-screen advertisement: wherein the detecting comprises:

(a) presenting to a user of an electronic device, a screen comprising content and said on-screen advertisement;

(b) injecting a temporary input/output interference that causes an on-screen pointer, that is on route to click within said on-screen advertisement, to exhibit irregular behavior from its regular route;

wherein the injecting comprises: injecting a temporary input/output interference that replaces the on-screen pointer with both: (I) a real on-screen pointer that is visible to human users and is detectable by computerized scripts, and (II) a fake on-screen pointer that is invisible to human users and is detectable by computerized scripts,

wherein said temporary input/output interference causes computerized scripts to click within said on-screen advertisement, and causes human users to click outside of said on-screen advertisement;

(c) tracking user interactions with an input unit in response to said temporary input/output interference:

(d) determining that said user did not perform sufficient manual correction operations that fix said temporary input/output interference;

(e) based on step (d), determining that a click performed within said on-screen advertisement, was performed by a click-fraud mechanism.

14. The method of claim 1 , wherein step (b) of injecting the temporary input/output interference comprises:

dynamically and pseudo-randomly modifying one or more parameters of said temporary input/output interference.

15. The method of claim 1 , wherein at least one of: step (a), step (b), step (c), step (d), and step (e), is performed by a hardware processor.

Assignments (6)
INTELLECTUAL PROPERTY SECURITY AGREEMENT TERMINATION UNDER REEL/FRAME: 049480/0823 Recorded Sep 14, 2020
From: KREOS CAPITAL VI (EXPERT FUND) LP
To: BIOCATCH LTD.
Reel/Frame 053769/0729 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT TERMINATION UNDER REEL/FRAME: 040233/0426 Recorded Sep 14, 2020
From: KREOS CAPITAL V (EXPERT FUND) L.P.
To: BIOCATCH LTD.
Reel/Frame 053770/0145 →
SECURITY INTEREST Recorded Jun 16, 2019
From: BIOCATCH LTD.
To: KREOS CAPITAL VI (EXPERT FUND) L.P.
Reel/Frame 049480/0823 →
CHANGE OF ADDRESS Recorded Jun 13, 2019
From: BIOCATCH LTD.
To: BIOCATCH LTD.
Reel/Frame 049459/0302 →
SECURITY INTEREST Recorded Nov 6, 2016
From: BIOCATCH LTD.
To: KREOS CAPITAL V (EXPERT FUND) L.P.
Reel/Frame 040233/0426 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 8, 2016
From: TURGEMAN, AVI
To: BIOCATCH LTD.
Reel/Frame 039360/0206 →
Continuity (16)
Continuation 14675768 · Apr 1, 2015
Continuation In Part 14566723 · Dec 11, 2014
Continuation 13922271 · Jun 20, 2013
Continuation In Part 13877676
Continuation In Part 14320653 · Jul 1, 2014
Continuation In Part 14320656 · Jul 1, 2014
Continuation In Part 14325393 · Jul 8, 2014
Continuation In Part 14325394 · Jul 8, 2014
Continuation 14325395 · Jul 8, 2014
Continuation In Part 14325396 · Jul 8, 2014
Continuation In Part 14325397 · Jul 8, 2014
Continuation In Part 14325398 · Jul 8, 2014
Provisional Application 61843915 · Jul 9, 2013
Provisional Application 61417479 · Nov 29, 2010
Provisional Application 61973855 · Apr 2, 2014
Related Publication 20160321689A1 · Nov 3, 2016