IP Library Granted Patent US 11,303,726
Granted Patent B2
US 11,303,726 · App. 16/111,305 · Granted Apr 12, 2022

Method and system for detecting and preventing abuse of an application interface

Inventors: Markandey Singh (San Jose, CA); Prabhakar Kasi (Cupertino, CA); Suchith Chandran (Cupertino, CA)
Assignee: YAHOO ASSETS LLC
H04L67/327H04L63/02H04L67/1002
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,303,726
App. No.
16/111,305
Granted
Apr 12, 2022
Kind
B2
Abstract

The present teaching relates to a method and system for reducing request traffic directed to a server. Upon receiving a request associated with an application in a time-window, an identifier that is to be associated with the request is generated. A first criterion associated with the request is evaluated based on the identifier, and the request is transmitted to a server based on a second criterion related to the time-window and the first criterion.

Claims (45)

1. A method, implemented on a machine having at least one processor, storage, and a communication platform capable of connecting to a network for reducing request traffic directed to a server, the method comprising:

receiving a request associated with an application;

generating an identifier to be associated with the request based on content thereof;

determining, based on the identifier associated with the request and an identifier associated with a previously received request, whether the request is similar to the previously received request;

determining whether the request is received within a first time-window from the time the previously received request is received; and

if the request is similar to the previously received request and is received within the first time-window, blocking the request from being transmitted to the server.

2. The method of claim 1 , wherein the step of determining whether the request is similar to the previously received request comprises determining whether the identifier associated with the request is the same as the identifier associated with the previously received request.

3. The method of claim 1 , further comprising:

if the request is not similar to the previously received request, transmitting the request to the server.

4. The method of claim 1 , further comprising:

if the request is similar to the previously received request and is received in a second time-window following the first time-window, transmitting the request to the server.

5. The method of claim 4 , wherein a duration of the first time-window is calibrated based at least on a number of requests received in the second time-window that are similar to the previously received request.

6. The method of claim 1 , further comprising:

transmitting, with an exponential delay, a response associated with the request to the application based on receiving the request in the first time-window and the request being similar to the previously received request.

7. The method of claim 1 , wherein the request is an unintentional request caused by one of a hardware malfunction of a device on which the application is being executed, an accidental user interaction with the device, and a bug in the application.

8. A system for reducing request traffic directed to a server, the system comprising:

a request handling unit implemented by a processor and configured to:

receive a request associated with an application,

generate an identifier to be associated with the request based on content thereof,

determine, based on the identifier associated with the request and an identifier associated with a previously received request, whether the request is similar to the previously received request, and

determine whether the request is received within a first time-window from the time the previously received request is received; and

a request processing unit implemented by the processor and configured to:

if the request is similar to the previously received request and is received within the first time-window, block the request from being transmitted to the server.

9. The system of claim 8 , wherein the request handling unit is implemented by the processor and further configured to determine whether the identifier associated with the request is the same as the identifier associated with the previously received request.

10. The system of claim 8 , wherein the request processing unit is implemented by the processor and further configured to:

if the request is not similar to the previously received request, transmit the request to the server.

11. The system of claim 8 , the request processing unit is implemented by the processor and further configured to:

if the request is similar to the previously received request and is received in a second time-window following the first time-window, transmit the request to the server.

12. The system of claim 11 , wherein a duration of the first time-window is calibrated based at least on a number of requests received in the second time-window that are similar to the previously received request.

13. The system of claim 8 , wherein the request processing unit is further configured to:

transmit, with an exponential delay, a response associated with the request to the application based on receiving the request in the first time-window and the request being similar to the previously received request.

14. The system of claim 8 , wherein the request is an unintentional request caused by one of a hardware malfunction of a device on which the application is being executed, an accidental user interaction with the device, and a bug in the application.

15. A non-transitory computer readable medium including computer executable instructions, wherein the instructions, when executed by a computer, cause the computer to perform a method for reducing request traffic directed to a server, the method comprising:

receiving a request associated with an application;

generating an identifier to be associated with the request based on content thereof;

determining, based on the identifier associated with the request and an identifier associated with a previously received request, whether the request is similar to the previously received request;

determining whether the request is received within a first time-window from the time the previously received request is received; and

if the request is similar to the previously received request and is received within the first time-window, blocking the request from being transmitted to the server.

16. The non-transitory computer readable medium of claim 15 , wherein the step of determining whether the request is similar to the previously received request comprises determining whether the identifier associated with the request is same as the identifier associated with the previously received request.

17. The non-transitory computer readable medium of claim 15 , wherein the instructions, when executed by the computer, cause the computer to further perform:

if the request is not similar to the previously received request, transmitting the request.

18. The non-transitory computer readable medium of claim 15 , wherein the instructions, when executed by the computer, cause the computer to further perform:

if the request is similar to the previously received request and is received in a second time-window following the first time-window, transmitting the request to the server.

19. The non-transitory computer readable medium of claim 18 , wherein a duration of the first time-window is calibrated based at least on a number of requests received in the second time-window that are similar to the previously received request.

20. The non-transitory computer readable medium of claim 15 , wherein the request is an unintentional request caused by one of a hardware malfunction of a device on which the application is being executed, an accidental user interaction with the device, and a bug in the application.

Assignments (4)
PATENT SECURITY AGREEMENT (FIRST LIEN) Recorded Sep 29, 2022
From: YAHOO ASSETS LLC
To: ROYAL BANK OF CANADA, AS COLLATERAL AGENT
Reel/Frame 061571/0773 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 16, 2021
From: YAHOO AD TECH LLC (FORMERLY VERIZON MEDIA INC.)
To: YAHOO ASSETS LLC
Reel/Frame 058982/0282 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 26, 2020
From: OATH INC.
To: VERIZON MEDIA INC.
Reel/Frame 054258/0635 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 24, 2018
From: SINGH, MARKANDEY; KASI, PRABHAKAR; CHANDRAN, SUCHITH
To: OATH INC.
Reel/Frame 046941/0643 →
Continuity (1)
Related Publication 20200068043A1 · Feb 27, 2020