IP Library › Granted Patent US 11,799,908
Granted Patent B2
US 11,799,908 · App. 17/533,185 · Granted Oct 24, 2023

Bot detection in an edge network using transport layer security (TLS) fingerprint

Inventors: David Senecal (Santa Clara, CA); Andrew Kahn (San Francisco, CA); Ory Segal (Herzliya, IL); Elad Shuster (Herzliya, IL); Duc Nguyen (Santa Clara, CA)
Assignee: Akamai Technologies, Inc.
H04L63/1483G06N20/00H04L63/166H04L67/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,799,908
App. No.
17/533,185
Granted
Oct 24, 2023
Kind
B2
Abstract

A method of bot detection in a computer network leverages a machine learning system. The machine learning system receives a fingerprint derived at a server, the server having extracted a set of transport layer security parameters received from a client and processed the set parameters into the fingerprint. Based at least in part on the fingerprint, the learning system determines whether the client is likely to be a bot as opposed to a human user. The system generates and returns to the server as score having a first value when the fingerprint is determined to be associated with a good client, and having a second value when the fingerprint is determined to be associated with a bot. Based on the score received from the machine learning system, the server takes a configured action with respect to the client.

Claims (19)

1. A method of bot detection in a computer network, comprising:

receiving, at a machine learning system, a fingerprint, the fingerprint having been derived at a server by the server extracting a set of transport layer security parameters received from a client and processing the set of transport layer security parameters into the fingerprint, the set of transport layer security parameters having been generated at a client in association with execution of a script;

determining, by the machine learning system, and based at least in part on the fingerprint, whether the client is likely to be a bot as opposed to a human user;

generating, by the machine learning system, a score, wherein the score has a first value when the fingerprint is determined to be associated with a good client, and wherein the score has a second value when the fingerprint is determined to be associated with a bot; and

returning the score to the server for further action based on the score.

2. The method as described in claim 1 wherein the fingerprint is received at the machine learning system in association with a request flow between the client and the server.

3. The method as described in claim 1 wherein the fingerprint is received at the machine learning system out-of-band with respect to a request flow between the client and the server.

4. The method as described in claim 1 wherein the machine learning system uses supervised machine learning to generate a ruleset based at least in part on a set of generated scores that include the score.

5. The method as described in claim 1 further including the machine learning system generating and publishing a list of known bad signatures.

6. The method as described in claim 5 wherein a known bad signature is generated from information derived from the set of transport layer security parameters received.

7. The method as described in claim 6 wherein the known bad signature comprises a tuple: {the fingerprint, a header order, and a user-agent}.

8. The method as described in claim 1 wherein the fingerprint is derived at the server by applying a one-way hash function to the set of transport layer security parameters to produce the fingerprint.

9. An apparatus, comprising:

one or more processors;

computer memory holding computer program instructions executed by the one or more processors, the computer program instructions comprising program code configured as a machine learning system and configured to:

receive a fingerprint, the fingerprint having been derived at a server by the server extracting a set of transport layer security parameters received from a client and processing the set of transport layer security parameters into the fingerprint, the set of transport layer security parameters having been generated at a client in association with execution of a script;

determine, based at least in part on the fingerprint, whether the client is likely to be a bot as opposed to a human user;

generate a score, wherein the score has a first value when the fingerprint is determined to be associated with a good client, and wherein the score has a second value when the fingerprint is determined to be associated with a bot; and

return the score to the server for further action by the server based on the score.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 13, 2021
From: SENECAL, DAVID; KAHN, ANDREW; SEGAL, ORY; SHUSTER, ELAD; NGUYEN, DUC
To: AKAMAI TECHNOLOGIES, INC.
Reel/Frame 058372/0677 →
Continuity (3)
Continuation 15973585 · May 8, 2018
Provisional Application 62599845 · Dec 18, 2017
Related Publication 20220086186A1 · Mar 17, 2022