IP Library Granted Patent US 12,651,178
Granted Patent B2
US 12,651,178 · App. 17/153,673 · Granted Jun 9, 2026

Machine learning techniques for associating network addresses with information object access locations

Inventors: Erik Gregory Matlick (Miami Beach, FL); Robert James Armstrong (Reno, NV); Benny Lin (New York, NY); Nicholaus Eugene Halecky (Reno, NV); Will Kurt (Boston, MA)
Assignee: BOMBORA, INC.
G06N5/04G06N20/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,651,178
App. No.
17/153,673
Granted
Jun 9, 2026
Kind
B2
Abstract

Disclosed embodiments includes a network classification system (NCS) that generates a set of machine learning (ML) features from information about information objects accessed by various users, and determines an organization (org) type associated with the network address based on the set of ML features. Obtained network events may include the information about the accessed information objects. A content consumption monitor (CCM) generates consumption scores for the network addresses based on the identified org types. The CCM can generate more accurate intent and consumption data by filtering out events unrelated to content consumption for that org type. The NCS and the CCM may be implemented as the same network function, or the NCS and CCM may be implemented as separate network functions. Other embodiments may be described and/or claimed.

Claims (73)

1 . One or more non-transitory computer readable media (NTCRM) comprising instructions for analyzing network events associated with a network address, wherein execution of the instructions by one or more processors is operable to cause a computing system to:

receive, from a service provider, network events including information about users accessing information objects from the network address;

generate, using a feature generator, a set of ML features from the information about the users accessing the information objects, wherein the set of ML features includes:

time-based features indicating percentages of the network events that occur at different time periods at respective locations, including ratios of events during business hours versus non-business hours,

duration-based features indicating an average amount of time individual users access the information objects at the respective locations,

event-based features indicating an average amount of the network events generated by individual users at the respective locations, and

device-based features indicating types of computing devices used for accessing the information objects at the respective locations;

train a ML model using labeled training data comprising known private organization locations, known public organization locations, and known non-organization locations;

determine an organization (org) type associated with the network address based on the set of ML features by classifying, using the trained ML model, the network address as associated with one of a private organization based at least on detecting when a ratio of events during business hours is above a threshold and a majority of the types of computing devices comprise desktop or laptop computers, a public organization based at least on detecting extended hours of activity and diverse device types, or a non-organization based at least on patterns distinct from private and public organizations;

calculate consumption scores for the network addresses based on the determined org;

filter network traffic based on the calculated consumption scores to improve network resource utilization; and

retrain, periodically, the ML model using newly received network events to improve classification accuracy.

2 . The one or more NTCRM of claim 1 , wherein to generate the set of ML features, execution of the instructions is further operable to cause the computing system to:

identify a time range associated with operation of each org type of a set of org types; and

determine, for each org type, a ratio of a number of the network events generated within the identified time range to a number of the network events generated outside of the identified time range,

wherein the ratio is generated to be at least one ML feature of the set of ML features.

3 . The one or more NTCRM of claim 2 , wherein execution of the instructions is further operable to cause the computing system to:

determine the org type to be a private org location when the ratio is above the threshold; and

determine the org type to be a public org location or a non-org location when the ratio is below the threshold.

4 . The one or more NTCRM of claim 1 , wherein to generate the set of ML features, execution of the instructions is further operable to cause the computing system to:

identify one or more days associated with operation of each org type of a set of org types; and

determine, for each org type, a ratio of a number of the network events generated on the one or more days to a number of the network events generated on other days different than the one or more days,

wherein the ratio is generated to be at least one ML feature of the set of ML features.

5 . The one or more NTCRM of claim 1 , wherein at least one ML feature of the set of ML features indicates a duration of the user accesses of the information objects, and execution of the instructions is further operable to cause the computing system to:

identify the org type associated with the network address based on the at least one ML feature indicating the duration of the user accesses.

6 . The one or more NTCRM of claim 1 , wherein at least one ML feature of the set of ML features indicates device types used to access the information objects from the network address, and execution of the instructions is further operable to cause the computing system to:

identify the org type based on the at least one ML feature indicating the device types.

7 . The one or more NTCRM of claim 6 , wherein execution of the instructions is further operable to cause the computing system to:

determine a number of laptop computers used to access the information objects from the network address, a number of desktop computers used to access the information objects from the network address, and a number of mobile devices used to access the information objects from the network address;

determine the org type to be a private org location when a ratio of the number of laptop computers and the number of desktop computers to the number of mobile devices is at or above a threshold; and

determine the org type to be a public org location when the ratio is below the threshold.

8 . The one or more NTCRM of claim 1 , wherein execution of the instructions is further operable to cause the computing system to:

identify a domain for the network address when the org type associated with the network address is identified as a private org location; and

generate a consumption score for the domain when the org type associated with the network address is identified as a private org location.

9 . An apparatus to be employed as network address classification system (NACS), the apparatus comprising:

at least one processor; and

a memory device communicatively coupled with the at least one processor, the memory device storing one or more sequences of instructions, and the at least one processor is configurable to:

operate a feature generator to generate a set of ML features based on aspects of user accesses to information objects indicated by received network session events from a service provider, the network session events indicating network addresses associated with locations from which the information objects are accessed by the users, wherein the set of ML features includes:

time-based features indicating percentages of the network events that occur at different time periods at respective locations, including ratios of events during business hours versus non-business hours,

duration-based features indicating an average amount of time individual users access the information objects at the respective locations,

event-based features indicating an average amount of the network events generated by individual users at the respective locations, and

device-based features indicating types of computing devices used for accessing the information objects at the respective locations;

train a ML model using labeled training data comprising known private organization locations, known public organization locations, and known non-organization locations

operate the ML model to determine organization (org) types associated with the locations from which the information objects are accessed based on the ML features by classifying the network address as associated with one of a private organization based at least on detecting when a ratio of events during business hours is above a threshold and a majority of the types of computing devices comprise desktop or laptop computers, a public organization based at least on detecting extended hours of activity and diverse device types, or a non-organization based at least on patterns distinct from private and public organizations;

calculate consumption scores for the network addresses based on the determined org type;

filter network traffic based on the calculated consumption scores to improve network resource utilization; and

retrain, periodically, the ML model using newly received network events to improve classification accuracy.

10 . The apparatus of claim 9 , wherein the network session events include timestamps indicating a time at which the users accessed the information objects, and the at least one processor is configurable to:

operate the feature generator to generate the set of ML features to include one or more time-based features, the one or more time-based features indicating a time of day when individual users accessed the information objects at the respective locations based on the timestamps and percentages of the events that occur at different time periods at the respective locations; and

operate the ML model to determine the org types associated with the network addresses based on the one or more time-based features.

11 . The apparatus of claim 10 , wherein the at least one processor is configurable to operate the ML model to:

determine the org type associated with the network addresses to be private org locations when the one or more time-based features indicate that some or all of the information objects were accessed outside of a specified time period.

12 . The apparatus of claim 9 , wherein the at least one processor is configurable to operate the ML model to:

determine the org type associated with the network addresses to be private org locations when the one or more duration-based features indicate that some or all of the information objects were accessed for a threshold amount of time.

13 . The apparatus of claim 9 , wherein the at least one processor is configurable to:

operate the ML model to determine the org types associated with the network addresses based on the one or more event-based features.

14 . The apparatus of claim 9 , wherein the at least one processor is configurable to:

operate the ML model to determine the org types associated with the network addresses based on the one or more device-based features.

15 . The apparatus of claim 9 , wherein to operate the ML model to determine the org types, the at least one processor is configurable to:

use a logistic regression model to determine the org types.

16 . The apparatus of claim 9 , wherein the at least one processor is configurable to operate a content consumption monitor to:

filter the network addresses based on the org types associated with the network addresses;

calculate consumption scores for the filtered network addresses;

identify a number of events associated with the network addresses over a series of time periods;

adjust the consumption scores based on changes in the number of events over the series of time periods; and

determine surge scores based on an increase in respective consumption scores within a predefined period of time.

17 . The one or more NTCRM of claim 1 , wherein execution of the instructions is further operable to cause the computing system to:

filter the network addresses to determine the network addresses classified as private organizations;

identify a number of events associated with the network addresses over a series of time periods;

adjust the consumption scores based on changes in the number of events over the series of time periods; and

determine topic scores and surge scores based on an increase in respective consumption scores within a predefined period of time.

18 . The one or more NTCRM of claim 1 further comprising, apply network security policies based on the determined org types to improve security.

19 . The apparatus of claim 9 further comprising, apply network security policies based on the determined org types to improve security.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 8, 2022
From: MATLICK, ERIK; ARMSTRONG, ROBERT JAMES; LIN, BENNY; HALECKY, NICHOLAUS EUGENE; KURT, WILL
To: BOMBORA, INC.
Reel/Frame 059196/0622 →
SECURITY INTEREST Recorded Mar 31, 2021
From: BOMBORA, INC.
To: RUNWAY GROWTH CREDIT FUND INC.
Reel/Frame 055790/0024 →
Continuity (4)
Continuation In Part 16163283 · Oct 17, 2018
Continuation In Part 14981529 · Dec 28, 2015
Continuation In Part 14498056 · Sep 26, 2014
Related Publication 20220230078A1 · Jul 21, 2022
References Cited (125)
US 7185065B1 · Holtzman · 2007 [cited by applicant]
US 7949646B1 · Bangalore · 2011 [cited by applicant]
US 8392252B2 · Kaufman · 2013 [cited by applicant]
US 8392543B1 · Singh · 2013 [cited by applicant]
US 8412847B2 · Longo · 2013 [cited by applicant]
US 8494897B1 · Dawson · 2013 [cited by applicant]
US 8566152B1 · Shaw · 2013 [cited by applicant]
US 8613089B1 · Holloway · 2013 [cited by applicant]
US 8725712B2 · Arrasvuori · 2014 [cited by applicant]
US 8745647B1 · Shin · 2014 [cited by applicant]
US 9092829B2 · Fleischman · 2015 [cited by applicant]
US 9152970B1 · Trahan · 2015 [cited by applicant]
US 9177142B2 · Montoro · 2015 [cited by applicant]
US 9419850B2 · Longo · 2016 [cited by applicant]
US 9514368B2 · Pitt · 2016 [cited by applicant]
US 9514461B2 · George · 2016 [cited by applicant]
US 9521157B1 · D'Aveta · 2016 [cited by applicant]
US 9560423B1 · Chang · 2017 [cited by applicant]
US 9667733B2 · Dhawan · 2017 [cited by applicant]
US 9706008B2 · Rajan · 2017 [cited by applicant]
US 9753923B2 · Fleischman · 2017 [cited by applicant]
US 9779144B1 · Hampson · 2017 [cited by applicant]
US 9940634B1 · Livhits · 2018 [cited by applicant]
US 10430806B2 · Chang · 2019 [cited by applicant]
US 10642889B2 · Reshef · 2020 [cited by applicant]
US 10810604B2 · Livhits · 2020 [cited by applicant]
US 11252537B2 · Delanghe et al. · 2022 [cited by examiner]
US 11416504B2 · Pelloin · 2022 [cited by examiner]
US 20020173971A1 · Stripe · 2002 [cited by applicant]
US 20030154398A1 · Eaton · 2003 [cited by applicant]
US 20040267723A1 · Bharat · 2004 [cited by applicant]
US 20060064411A1 · Gross · 2006 [cited by applicant]
US 20070124202A1 · Simons · 2007 [cited by applicant]
US 20070156392A1 · Balchandran · 2007 [cited by applicant]
US 20080126178A1 · Moore · 2008 [cited by applicant]
US 20080313019A1 · Jeffers · 2008 [cited by applicant]
US 20090216741A1 · Thrall · 2009 [cited by applicant]
US 20100100537A1 · Druzgalski · 2010 [cited by applicant]
US 20100161613A1 · Rao · 2010 [cited by applicant]
US 20100250341A1 · Hauser · 2010 [cited by applicant]
US 20100293057A1 · Haveliwala · 2010 [cited by applicant]
US 20110227699A1 · Seth · 2011 [cited by applicant]
US 20110252427A1 · Olston · 2011 [cited by applicant]
US 20110320715A1 · Ickman · 2011 [cited by applicant]
US 20120158693A1 · Papadimitriou · 2012 [cited by applicant]
US 20120209795A1 · Glickman · 2012 [cited by applicant]
US 20120215640A1 · Ramer · 2012 [cited by applicant]
US 20120314573A1 · Edwards · 2012 [cited by examiner]
US 20120324585A1 · Beckett, III · 2012 [cited by examiner]
US 20130066677A1 · Killoh · 2013 [cited by applicant]
US 20130067070A1 · Rowe · 2013 [cited by applicant]
US 20130073473A1 · Heath · 2013 [cited by applicant]
US 20130124193A1 · Holmberg · 2013 [cited by applicant]
US 20130132339A1 · Mirus · 2013 [cited by applicant]
US 20130151687A1 · Mooneyham · 2013 [cited by applicant]
US 20130159505A1 · Mason · 2013 [cited by applicant]
US 20130204663A1 · Kahlow · 2013 [cited by applicant]
US 20130216134A1 · Yu · 2013 [cited by applicant]
US 20130297338A1 · Urmann · 2013 [cited by applicant]
US 20140067831A1 · Swamidas · 2014 [cited by applicant]
US 20140095966A1 · Burkard · 2014 [cited by applicant]
US 20140096035A1 · Hall · 2014 [cited by applicant]
US 20140156681A1 · Lee · 2014 [cited by applicant]
US 20140201061A1 · Sivacki · 2014 [cited by applicant]
US 20140201240A1 · Andavarapu · 2014 [cited by applicant]
US 20140229164A1 · Martens · 2014 [cited by applicant]
US 20140236669A1 · Milton · 2014 [cited by applicant]
US 20140278308A1 · Liu · 2014 [cited by applicant]
US 20140278916A1 · Nukala · 2014 [cited by applicant]
US 20140278959A1 · Nukala · 2014 [cited by applicant]
US 20140280549A1 · Rajan · 2014 [cited by applicant]
US 20140280890A1 · Yi · 2014 [cited by applicant]
US 20140325030A1 · Maharajh · 2014 [cited by applicant]
US 20150074131A1 · Fernandez · 2015 [cited by applicant]
US 20150254555A1 · Williams, Jr. · 2015 [cited by examiner]
US 20150309965A1 · Brav · 2015 [cited by applicant]
US 20150373039A1 · Wang · 2015 [cited by examiner]
US 20160048880A1 · Linden · 2016 [cited by applicant]
US 20160050126A1 · Rubio · 2016 [cited by examiner]
US 20160132906A1 · Khavronin · 2016 [cited by applicant]
US 20160323239A1 · Cheng · 2016 [cited by examiner]
US 20160371725A1 · Nguyen · 2016 [cited by applicant]
US 20170031907A1 · Juang · 2017 [cited by applicant]
US 20170364931A1 · Khavronin · 2017 [cited by applicant]
US 20180101860A1 · Fleming · 2018 [cited by applicant]
US 20180174163A1 · Livhits · 2018 [cited by applicant]
US 20180218286A1 · Predovic et al. · 2018 [cited by examiner]
US 20180365710A1 · Halecky · 2018 [cited by applicant]
US 20190050874A1 · Matlick · 2019 [cited by examiner]
US 20190182749A1 · Breaux et al. · 2019 [cited by examiner]
US 20190260777A1 · Mehrotra et al. · 2019 [cited by examiner]
US 20190294642A1 · Matlick · 2019 [cited by applicant]
US 20200159690A1 · J et al. · 2020 [cited by examiner]
US 20200410514A1 · Livhits · 2020 [cited by applicant]
US 20210011967A1 · Rathod · 2021 [cited by examiner]
US 20210176726A1 · Vyunova et al. · 2021 [cited by examiner]
US 20210224274A1 · Swaminathan et al. · 2021 [cited by examiner]
CN 108713213A · 2018 [cited by applicant]
EP 3398146A1 · 2018 [cited by applicant]
EP 3398146A4 · 2019 [cited by applicant]
WO 2014054052A1 · 2014 [cited by applicant]
WO 2017116493A1 · 2017 [cited by applicant]
Anwar, T., Liao, K., Goyal, A., Sellis, T., Kayes, A. S. M., & Shen, H. (2020). Inferring location types with geo-social-temporal pattern mining. IEEE Access, 8, 154789-154799. (Year: 2020). [cited by examiner]
Sarmadi, S., Li, M., & Chellappan, S. (May 2018). A statistical framework to forecast duration and volume of internet usage based on pervasive monitoring of netflow logs. In 2018 IEEE 32nd International Conference on Ad… [cited by examiner]
Sidik, B. (2016). Spot the Hotspot: Wi-Fi Hotspot Classification from Internet Traffic. (Year: 2016). [cited by examiner]
Afanasyev, M., Chen, T., Voelker, G. M., & Snoeren, A. C. (Oct. 2008). Analysis of a mixed-use urban wifi network: when metropolitan becomes neapolitan. In Proceedings of the 8th ACM SIGCOMM conference on Internet measu… [cited by examiner]
PCT, International Search Report and Written Opinion of the International Searching Authority for International Application No. PCT/US16/35186, mailed Nov. 4, 2016, 23 pages. [cited by applicant]
Snoek et al., “Practical Bayesian Optimization of Machine Learning Algorithms”, Advances in neural information processing systems (Aug. 29, 2012); 12 pages. [cited by applicant]
McCallum et al., “A Comparison of Event Models for Naive Bayes Text Classification”, AAAI-98 workshop on Learning for Text Categorization, vol. 752, No. 1 (1998); 8 pages. [cited by applicant]
Mikolov et al., “Efficient Estimation of Word Representations in Vector Space”, arXiv preprint arXiv:1301.3781 (Jan. 16, 2013); 12 pages. [cited by applicant]
Burby et al., “Web Analytics Definitions” Web Analytics Association, version 4.0 (Aug. 23, 2007); XP055505869; retrieved from the Internet on Sep. 10, 2018 at: <https://www.digitalanalyticsassociation.org/Files/PDF_stan… [cited by applicant]
Extended European Search Report for EP App. No. 18190771.8 dated Oct. 22, 2018; 8 pages. [cited by applicant]
Extended European Search Report for EP App. No. 16882214.6 dated Jul. 4, 2019; 9 pages. [cited by applicant]
Zhang et al., “A Sensitivity Analysis of (and Practitioners' Guide to) Convolutional Neural Networks for Sentence Classification”, arXiv:1510.03820v4 [cs.CL] ( Apr. 6, 2016); 18 pages. [cited by applicant]
Zhou, “Ensemble Learning”, Encyclopedia of Biometrics, 1, pp. 270-273 (Jun. 2009), available at: https://cs.nju.edu.cn/zhouzh/zhouzh.files/publication/springerEBR09.pdf; 5 pages. [cited by applicant]
Kamar et al., “Combining Human and Machine Intelligence in Large-scale Crowdsourcing”, AAMAS, vol. 12, pp. 467-474 (Jun. 4, 2012), available at: http://www.erichorvitz.com/CrowdSynth.pdf; 8 pages. [cited by applicant]
Osanaiye et al., “Ensemble-based Multi-Filter Feature Selection Method for DDOS Detection in Cloud Computing”, EURASIP J. of Wirel. Comm. and Netw., vol. 2016, No. 1, p. 130, May 10, 2016, Dec. 1, 2016); available at: h… [cited by applicant]
Boutaba et al., “A comprehensive survey on machine learning for networking: evolution, applications and research opportunities”, J. of Internet Services and Applications, vol. 9, issue 1, article No. 16 (Dec. 1, 2018); … [cited by applicant]
Wu et al., “Hyperparameter Optimization for Machine Learning Models Based on Bayesian Optimization”, J. of Electronic Sci and Tech., vol. 17, No. 1, (Mar. 2019). [cited by applicant]
Withers, “What is Buyer Intent Data? A Guide for 2020”; dated Apr. 1, 2020; retrieved from the Internet at <https://blog.zoominfo.com/how-to-use-internet-data/>; 6 pages. [cited by applicant]
ZoomInfo Launches Intent Solution for Marketing and Sales, dated Apr. 9, 2020; retrieved from the Internet at <https://destinationcrm.com/...News/CRM-Across-the-Wire/ZoomInfo-Launches-Intent-Solution-for-Marketing-and-S… [cited by applicant]
ZoomInfo Launches ‘Intent’ Solution to Help B2B Companies Identify, Prioritize and Engage Sales Leads Based on Buying Signals dated Apr. 9, 2020; retrieved from the Internet at <https://www.businesswire.com/news/home/20… [cited by applicant]
Perozzi, et al., “DeepWalk: Online Learning of Social Representations” KDD'Aug. 24-27, 14, 2014, New York, NY, ACM 978-1-4503-2956-9/14/08; DOI 10.1145/2623330.2623732; 10 pages. [cited by applicant]
Tang, et al., “LINE: Large-scale Information Network Embedding” WWW 2015, May 18-22, 2015, Florence, Italy. ACM 978-1-4503-3469-3/15/05. DOI 10-1145/2736277.2741093; 11 pages. [cited by applicant]
Hamilton, et al., “Inductive Representation Learning on Large Graphs” 31st Conference on Neural Information Processing Systems (NIPS 2017), Long Beach, CA, USA; available on the Internet at <https://cs.stanford.edu/peop… [cited by applicant]