IP Library Granted Patent US 11,756,075
Granted Patent B2
US 11,756,075 · App. 17/716,838 · Granted Sep 12, 2023

Systems, methods, and media for detecting suspicious activity

Inventors: Jason Lloyd Shaw (New York, NY); David William Luttrell (Philadelphia, PA); Arun Ahuja (Stamford, CT)
Assignee: Integral Ad Science, Inc.
G06Q30/0248
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,756,075
App. No.
17/716,838
Granted
Sep 12, 2023
Kind
B2
Abstract

Systems, methods, and media for detecting suspicious activity in connection with advertisement impressions are provided. In some embodiments, the method includes: collecting advertisement impression information associated with a plurality of pages; determining, from the collected advertisement impression information, an indication of whether a browser application detected that an advertisement displayed on a webpage was viewable in a browser window; determining, from the collected advertisement impression information, a plurality of viewability statistics for each of the plurality of pages, wherein each viewability statistic indicates a likelihood of whether an advertisement displayed on a webpage was viewable in a browser window; comparing the plurality of viewability statistics with the indication from the browser application; determining a viewability score for the advertisement impression based on the comparison; and identifying the advertisement impression as likely to be suspicious based on the determined viewability score.

Claims (51)

1. A method for detecting suspicious activity from a plurality of websites, the method comprising:

receiving, using a server that includes a hardware processor, advertisement impression information associated with a plurality of pages;

determining, by the server, from the received advertisement impression information, a never-in-view statistic for each of the plurality of pages, wherein the never-in-view statistic indicates a likelihood of whether an advertisement displayed on a webpage was never within a viewable area in a browser window rendered by a browser application;

determining, by the server, a viewability score for the advertisement impression based on the never-in-view statistic;

identifying, by the server, the advertisement impression as likely to be suspicious based on the determined viewability score; and

transmitting, by the server, information relating to the advertisement identified as likely to be suspicious from being purchased for advertisement placement.

2. The method of claim 1 , further comprising inhibiting content associated with the advertisement impression identified as likely to be suspicious from being purchased for advertisement placement.

3. The method of claim 1 , further comprising transmitting information relating to the identified advertisement impression that inhibits an advertiser from associating with a corresponding website.

4. The method of claim 1 , wherein the never-in-view statistic comprises a fraction of advertisement impressions that was never in the viewable area of the browser window.

5. The method of claim 1 , further comprising identifying at least one website as likely to be suspicious based on the viewability score by determining that the never-in-view statistic exceeds a selected threshold value, wherein the selected threshold value indicates that the at least one website is engaging in suspicious activity.

6. The method of claim 1 , further comprising:

determining a portion of the plurality of pages corresponding to the website;

determining one or more advertisements presented on the portion of the plurality of pages; and

determining a plurality of browsers associated with advertisement calls for the one or more advertisements.

7. The method of claim 1 , further comprising:

extracting identification data associated with at least one website that is deemed suspicious;

searching for other websites having identification data that is similar to the extracted identification data; and

determining whether at least one of the other websites should be deemed as likely to be suspicious.

8. The method of claim 1 , further comprising:

receiving training data;

identifying features for differentiating suspicious websites from normal websites using the received training data; and

using a classifier with the identified features to identify the suspicious websites from the plurality of websites.

9. A system for detecting suspicious activity from a plurality of websites, the system comprising:

a server that includes a hardware processor that:

receives advertisement impression information associated with a plurality of pages;

determines, from the received advertisement impression information, a never-in-view statistic for each of the plurality of pages, wherein the never-in-view statistic indicates a likelihood of whether an advertisement displayed on a webpage was never within a viewable area in a browser window rendered by a browser application;

determines a viewability score for the advertisement impression based on the never-in-view statistic;

identifies the advertisement impression as likely to be suspicious based on the determined viewability score; and

transmits information relating to the advertisement identified as likely to be suspicious from being purchased for advertisement placement.

10. The system of claim 9 , wherein the hardware processor further inhibits content associated with the advertisement impression identified as likely to be suspicious from being purchased for advertisement placement.

11. The system of claim 9 , wherein the hardware processor further transmits information relating to the identified advertisement impression that inhibits an advertiser from associating with a corresponding website.

12. The system of claim 9 , wherein the never-in-view statistic comprises a fraction of advertisement impressions that was never in the viewable area of the browser window.

13. The system of claim 9 , wherein the hardware processor further identifies at least one website as likely to be suspicious based on the viewability score by determining that the never-in-view statistic exceeds a selected threshold value, wherein the selected threshold value indicates that the at least one website is engaging in suspicious activity.

14. The system of claim 9 , wherein the hardware processor further:

determines a portion of the plurality of pages corresponding to the website;

determines one or more advertisements presented on the portion of the plurality of pages; and

determines a plurality of browsers associated with advertisement calls for the one or more advertisements.

15. The system of claim 9 , wherein the hardware processor further:

extracts identification data associated with at least one website that is deemed suspicious;

searches for other websites having identification data that is similar to the extracted identification data; and

determines whether at least one of the other websites should be deemed as likely to be suspicious.

16. The system of claim 9 , wherein the hardware processor further:

receives training data;

identifies features for differentiating suspicious websites from normal websites using the received training data; and

uses a classifier with the identified features to identify the suspicious websites from the plurality of websites.

17. A non-transitory computer-readable medium containing computer-executable instructions that, when executed by a processor, cause the processor to perform a method for detecting suspicious activity from a plurality of websites, the method comprising:

receiving advertisement impression information associated with a plurality of pages;

determining, from the received advertisement impression information, a never-in-view statistic for each of the plurality of pages, wherein the never-in-view statistic indicates a likelihood of whether an advertisement displayed on a webpage was never within a viewable area in a browser window rendered by a browser application;

determining a viewability score for the advertisement impression based on the never-in-view statistic;

identifying the advertisement impression as likely to be suspicious based on the determined viewability score; and

transmitting, by the server, information relating to the advertisement identified as likely to be suspicious from being purchased for advertisement placement.

Assignments (3)
PATENT SECURITY AGREEMENT Recorded Jan 9, 2026
From: INTEGRAL AD SCIENCE, INC.
To: ROYAL BANK OF CANADA, AS ADMINISTRATIVE AGENT
Reel/Frame 074280/0900 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL, RECORDED ON SEPTEMBER 18, 2025 AT REEL/FRAME NO. 72916/0431 Recorded Jan 9, 2026
From: PNC BANK, NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
To: INTEGRAL AD SCIENCE, INC.
Reel/Frame 074281/0009 →
PATENT SECURITY AGREEMENT Recorded Sep 18, 2025
From: INTEGRAL AD SCIENCE, INC.
To: PNC BANK, NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
Reel/Frame 072916/0431 →
Continuity (4)
Continuation 16544322 · Aug 19, 2019
Continuation 13909018 · Jun 3, 2013
Provisional Application 61654511 · Jun 1, 2012
Related Publication 20220374938A1 · Nov 24, 2022