IP Library Granted Patent US 11,301,894
Granted Patent B2
US 11,301,894 · App. 16/544,322 · Granted Apr 12, 2022

Systems, methods, and media for detecting suspicious activity

Inventors: Jason Lloyd Shaw (New York, NY); David William Luttrell (Philadelphia, PA); Arun Ahuja (Stamford, CT)
Assignee: Integral Ad Science, Inc.
G06Q30/0248
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,301,894
App. No.
16/544,322
Granted
Apr 12, 2022
Kind
B2
Abstract

Systems, methods, and media for detecting suspicious activity in connection with advertisement impressions are provided. In some embodiments, the method includes: collecting advertisement impression information associated with a plurality of pages; determining, from the collected advertisement impression information, an indication of whether a browser application detected that an advertisement displayed on a webpage was viewable in a browser window; determining, from the collected advertisement impression information, a plurality of viewability statistics for each of the plurality of pages, wherein each viewability statistic indicates a likelihood of whether an advertisement displayed on a webpage was viewable in a browser window; comparing the plurality of viewability statistics with the indication from the browser application; determining a viewability score for the advertisement impression based on the comparison; and identifying the advertisement impression as likely to be suspicious based on the determined viewability score.

Claims (49)

1. A method for detecting suspicious activity from a plurality of websites, the method comprising:

receiving, using a server that includes a hardware processor, advertisement impression information associated with a plurality of pages;

determining, by the server, from the received advertisement impression information, a never-in-view statistic for each of the plurality of pages, wherein the never-in-view statistic indicates a likelihood of whether an advertisement displayed on a webpage was never within a viewable area in a browser window rendered by a browser application;

determining, by the server, a viewability score for the advertisement impression based on the never-in-view statistic;

identifying, by the server, the advertisement impression as likely to be suspicious based on the determined viewability score; and

inhibiting, by the server, content associated with the advertisement impression identified as likely to be suspicious from being purchased for advertisement placement.

2. The method of claim 1 , further comprising transmitting information relating to the identified advertisement impression that inhibits an advertiser from associating with a corresponding website.

3. The method of claim 1 , wherein the never-in-view statistic comprises a fraction of advertisement impressions that was never in the viewable area of the browser window.

4. The method of claim 1 , further comprising identifying at least one website as likely to be suspicious based on the viewability score by determining that the never-in-view statistic exceeds a selected threshold value, wherein the selected threshold value indicates that the at least one website is engaging in suspicious activity.

5. The method of claim 1 , further comprising:

determining a portion of the plurality of pages corresponding to the website;

determining one or more advertisements presented on the portion of the plurality of pages; and

determining a plurality of browsers associated with advertisement calls for the one or more advertisements.

6. The method of claim 1 , further comprising:

extracting identification data associated with at least one website that is deemed suspicious;

searching for other websites having identification data that is similar to the extracted identification data; and

determining whether at least one of the other websites should be deemed as likely to be suspicious.

7. The method of claim 1 , further comprising:

receiving training data;

identifying features for differentiating suspicious websites from normal websites using the received training data; and

using a classifier with the identified features to identify the suspicious websites from a plurality of websites.

8. A system for detecting suspicious activity from a plurality of websites, the system comprising:

a server that includes a hardware processor that:

receives advertisement impression information associated with a plurality of pages;

determines, from the received advertisement impression information, a never-in-view statistic for each of the plurality of pages, wherein the never-in-view statistic indicates a likelihood of whether an advertisement displayed on a webpage was never within a viewable area in a browser window rendered by a browser application;

determines a viewability score for the advertisement impression based on the never-in-view statistic;

identifies the advertisement impression as likely to be suspicious based on the determined viewability score; and

inhibits content associated with the advertisement impression identified as likely to be suspicious from being purchased for advertisement placement.

9. The system of claim 8 , wherein the hardware processor is further configured to transmit information relating to the identified advertisement impression that inhibits an advertiser from associating with a corresponding website.

10. The system of claim 8 , wherein the never-in-view statistic comprises a fraction of advertisement impressions that was never in the viewable area of the browser window.

11. The system of claim 8 , wherein the hardware processor is further configured to identify at least one website as likely to be suspicious based on the viewability score by determining that the never-in-view statistic exceeds a selected threshold value, wherein the selected threshold value indicates that the at least one website is engaging in suspicious activity.

12. The system of claim 8 , wherein the hardware processor is further configured to:

determine a portion of the plurality of pages corresponding to the website;

determine one or more advertisements presented on the portion of the plurality of pages; and

determine a plurality of browsers associated with advertisement calls for the one or more advertisements.

13. The system of claim 8 , wherein the hardware processor is further configured to:

extract identification data associated with at least one website that is deemed suspicious;

search for other websites having identification data that is similar to the extracted identification data; and

determine whether at least one of the other websites should be deemed as likely to be suspicious.

14. The system of claim 8 , wherein the hardware processor is further configured to:

receive training data;

identify features for differentiating suspicious websites from normal websites using the received training data; and

use a classifier with the identified features to identify the suspicious websites from a plurality of websites.

15. A non-transitory computer-readable medium containing computer-executable instructions that, when executed by a processor, cause the processor to perform a method for detecting suspicious activity from a plurality of websites, the method comprising:

receiving advertisement impression information associated with a plurality of pages;

determining, from the received advertisement impression information, a never-in-view statistic for each of the plurality of pages, wherein the never-in-view statistic indicates a likelihood of whether an advertisement displayed on a webpage was never within a viewable area in a browser window rendered by a browser application;

determining a viewability score for the advertisement impression based on the never-in-view statistic;

identifying the advertisement impression as likely to be suspicious based on the determined viewability score; and

inhibiting content associated with the advertisement impression identified as likely to be suspicious from being purchased for advertisement placement.

Assignments (4)
RELEASE OF SECURITY INTEREST Recorded Jan 23, 2026
From: PNC BANK, NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
To: INTEGRAL AD SCIENCE, INC.
Reel/Frame 073560/0357 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL, RECORDED ON SEPTEMBER 29, 2021 AT REEL/FRAME 57673/0653 Recorded Jan 9, 2026
From: PNC BANK, NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
To: INTEGRAL AD SCIENCE, INC.
Reel/Frame 074280/0981 →
PATENT SECURITY AGREEMENT Recorded Jan 9, 2026
From: INTEGRAL AD SCIENCE, INC.
To: ROYAL BANK OF CANADA, AS ADMINISTRATIVE AGENT
Reel/Frame 074280/0900 →
PATENT SECURITY AGREEMENT Recorded Sep 29, 2021
From: INTEGRAL AD SCIENCE, INC.
To: PNC BANK, NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
Reel/Frame 057673/0653 →
Continuity (3)
Continuation 13909018 · Jun 3, 2013
Provisional Application 61654511 · Jun 1, 2012
Related Publication 20200043041A1 · Feb 6, 2020