IP Library Granted Patent US 10,778,711
Granted Patent B2
US 10,778,711 · App. 16/205,919 · Granted Sep 15, 2020

Systems and methods for network traffic analysis

Inventors: Lachlan A. Maxwell (Ashburn, VA); Donald J. McQueen (Leesburg, VA)
Assignee: Oath Inc.
H04L63/1425H04L63/14H04L63/1408H04L63/1416H04L63/1441H04W12/00503
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,778,711
App. No.
16/205,919
Granted
Sep 15, 2020
Kind
B2
Abstract

Systems and methods are disclosed for identifying malicious traffic associated with a website. One method includes receiving website traffic metadata comprising a plurality of variables, the website traffic metadata being associated with a plurality of website visitors to the website; determining a total number of occurrences associated with at least two of the plurality of variables of the website traffic metadata; generating a plurality of pairs comprising combinations of the plurality of variables of the website traffic metadata; determining a total number of occurrences associated with each pair of the plurality of pairs of combinations of the plurality of variables of the website traffic metadata; determining a plurality of visitor actions associated with the plurality of variables of the website traffic metadata; clustering each of the plurality of pairs and the plurality of visitor actions associated with the plurality of variables of the website traffic metadata into groups; and determining, based on the clustering of the plurality of pairs and the plurality of visitor actions, whether each of the plurality of website visitors are malicious visitors.

Claims (55)

1. A computer-implemented method for identifying malicious traffic associated with a website, comprising:

receiving website traffic data comprising a plurality of variables, the website traffic data being associated with a plurality of website visitors to the website;

determining a total number of occurrences associated with at least two of the plurality of variables of the website traffic data;

generating a plurality of pairs comprising combinations of the plurality of variables of the website traffic data;

clustering each of the plurality of pairs into groups; and

determining, based on the clustering of the plurality of pairs, whether each of the plurality of website visitors are malicious visitors.

2. The method of claim 1 , wherein clustering each of the plurality of pairs into groups and determining whether each of the plurality of website visitors are malicious visitors further comprise:

determining a total number of occurrences associated with each pair of the plurality of pairs of combinations of the plurality of variables of the website traffic data;

determining a plurality of visitor actions associated with the plurality of variables of the website traffic data;

clustering each of the plurality of pairs and the plurality of visitor actions associated with the plurality of variables of the website traffic data; and

determining, based on the clustering of the plurality of pairs and the plurality of visitor actions, whether each of the plurality of website visitors are malicious visitors.

3. The method of claim 2 , wherein clustering each of the plurality of pairs and the plurality of visitor actions comprises:

generating a plurality of multi-dimensional vectors for each of the plurality of pairs of combinations of the plurality of variables of the website traffic data; and

executing a clustering algorithm on the vectors to generate the groups.

4. The method of claim 1 , wherein determining whether each of the plurality of website visitors are malicious visitors comprises cross-referencing each member of the groups with known trusted visitors.

5. The method of claim 1 , wherein determining whether each of the plurality of website visitors are malicious visitors comprises cross-referencing each member of the groups with known malicious visitors.

6. The method of claim 1 , further comprising labeling values of each of the plurality of variables based upon the determination whether each of the plurality of website visitors are malicious visitors.

7. The method of claim 1 , further comprising determining a proportion of malicious traffic to the website based on the determined malicious visitors.

8. The method of claim 1 , wherein the plurality of variables comprise at least one of a country of origin of data packets associated with the plurality of website visitors, geographic area of origin of data packets associated with the plurality of website visitors, an Internet Protocol (IP) address of data packets associated with the plurality of website visitors, a browser identifier associated with the plurality of website visitors, and Uniform Resource Locator (URL) base directory associated with the plurality of website visitors.

9. A system for identifying malicious traffic associated with a website, the system including:

a data storage device that stores instructions for identifying malicious traffic associated with a website; and

a processor configured to execute the instructions to perform a method including:

receiving website traffic data comprising a plurality of variables, the website traffic data being associated with a plurality of website visitors to the website;

determining a total number of occurrences associated with at least two of the plurality of variables of the website traffic data;

generating a plurality of pairs comprising combinations of the plurality of variables of the website traffic data;

clustering each of the plurality of pairs into groups; and

determining, based on the clustering of the plurality of pairs, whether each of the plurality of website visitors are malicious visitors.

10. The system of claim 9 , wherein clustering each of the plurality of pairs into groups and determining whether each of the plurality of website visitors are malicious visitors further comprise:

determining a total number of occurrences associated with each pair of the plurality of pairs of combinations of the plurality of variables of the website traffic data;

determining a plurality of visitor actions associated with the plurality of variables of the website traffic data;

clustering each of the plurality of pairs and the plurality of visitor actions associated with the plurality of variables of the website traffic data; and

determining, based on the clustering of the plurality of pairs and the plurality of visitor actions, whether each of the plurality of website visitors are malicious visitors.

11. The system of claim 10 , wherein clustering each of the plurality of pairs and the plurality of visitor actions further comprises:

generating a plurality of multi-dimensional vectors for each of the plurality of pairs of combinations of the plurality of variables of the website traffic data; and

executing a clustering algorithm on the vectors to generate the groups.

12. The system of claim 9 , wherein determining whether each of the plurality of website visitors are malicious visitors comprises cross-referencing each member of the groups with known trusted visitors.

13. The system of claim 9 , wherein determining whether each of the plurality of website visitors are malicious visitors comprises cross-referencing each member of the groups with known malicious visitors.

14. The system of claim 9 , further comprising labeling values of each of the plurality of variables based upon the determination whether each of the plurality of website visitors are malicious visitors.

15. The system of claim 9 , further comprising determining a proportion of malicious traffic to the website based on the determined malicious visitors.

16. The system of claim 9 , wherein the plurality of variables comprise at least one of a country of origin of data packets associated with the plurality of website visitors, geographic area of origin of data packets associated with the plurality of website visitors, an Internet Protocol (IP) address of data packets associated with the plurality of website visitors, a browser identifier associated with the plurality of website visitors, and Uniform Resource Locator (URL) base directory associated with the plurality of website visitors.

17. A non-transitory computer-readable medium storing instructions that, when executed by a computer, cause the computer to perform a method for identifying malicious traffic associated with a website, the method including:

receiving website traffic data comprising a plurality of variables, the website traffic data being associated with a plurality of website visitors to the website;

determining a total number of occurrences associated with at least two of the plurality of variables of the website traffic data;

generating a plurality of pairs comprising combinations of the plurality of variables of the website traffic data;

clustering each of the plurality of pairs into groups; and

determining, based on the clustering of the plurality of pairs, whether each of the plurality of website visitors are malicious visitors.

18. The computer-readable medium of claim 17 , wherein clustering each of the plurality of pairs into groups and determining whether each of the plurality of website visitors are malicious visitors further comprise:

determining a total number of occurrences associated with each pair of the plurality of pairs of combinations of the plurality of variables of the website traffic data;

determining a plurality of visitor actions associated with the plurality of variables of the website traffic data;

clustering each of the plurality of pairs and the plurality of visitor actions associated with the plurality of variables of the website traffic data; and

determining, based on the clustering of the plurality of pairs and the plurality of visitor actions, whether each of the plurality of website visitors are malicious visitors.

19. The computer-readable medium of claim 18 , wherein clustering each of the plurality of pairs and the plurality of visitor actions further comprises:

generating a plurality of multi-dimensional vectors for each of the plurality of pairs of combinations of the plurality of variables of the website traffic data; and

executing a clustering algorithm on the vectors to generate the groups.

20. The computer-readable medium of claim 17 , wherein determining whether each of the plurality of website visitors are malicious visitors comprises cross-referencing each member of the groups with known trusted visitors.

Assignments (5)
PATENT SECURITY AGREEMENT (FIRST LIEN) Recorded Sep 29, 2022
From: YAHOO ASSETS LLC
To: ROYAL BANK OF CANADA, AS COLLATERAL AGENT
Reel/Frame 061571/0773 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 16, 2021
From: YAHOO AD TECH LLC (FORMERLY VERIZON MEDIA INC.)
To: YAHOO ASSETS LLC
Reel/Frame 058982/0282 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 26, 2020
From: OATH INC.
To: VERIZON MEDIA INC.
Reel/Frame 054258/0635 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 30, 2018
From: MAXWELL, LACHLAN A.; MCQUEEN, DONALD J.
To: AOL INC.
Reel/Frame 047641/0697 →
CHANGE OF NAME Recorded Nov 30, 2018
From: AOL INC.
To: OATH INC.
Reel/Frame 048174/0102 →