IP Library Granted Patent US 11,757,910
Granted Patent B2
US 11,757,910 · App. 17/734,746 · Granted Sep 12, 2023

Methods, systems, and media for detecting fraudulent activity based on hardware events

Inventor: Yossef Oren (New York, NY)
Assignee: Integral Ad Science, Inc.
H04L63/1425H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,757,910
App. No.
17/734,746
Granted
Sep 12, 2023
Kind
B2
Abstract

Mechanisms for detecting fraudulent activity based on hardware events are provided. In accordance with some embodiments of the disclosed subject matter, the method comprises: receiving a request for advertising content to be placed on a website; receiving data describing physical activity at one or more user input hardware devices; receiving data describing interactions with the website; correlating the data describing interactions with the website with the data describing physical activity at one or more user input hardware devices; determining whether at least a portion of the interactions with the website are indicative of fraudulent behavior based on the correlation; and responding to the request for advertising content on the website by inhibiting the advertising content to be transmitted to the website in response to the determination that at least a portion of the interactions with the website indicates fraudulent behavior.

Claims (32)

1. A method for detecting fraudulent activity on a website, the method comprising:

detecting, using a hardware processor of a user device that executes hardware event detector code, a plurality of hardware events and a plurality of website interactions with a webpage, wherein each of the plurality of website interactions is associated with a corresponding output from the hardware event detector code;

determining, using the hardware processor, whether a correlation exists between each of the plurality of website interactions with the webpage and one or more of the plurality of hardware events detected by the hardware event detector code;

determining, using the hardware processor, whether the correlation indicates suspicious activity based on at least a portion of the website interactions that do not correlate with one or more of the plurality of hardware events; and

responding, using the hardware processor, to a request for content on the webpage by inhibiting the content from being transmitted to the webpage based on the determination that the correlation indicates suspicious activity.

2. The method of claim 1 , wherein the plurality of hardware events includes user hardware activity on the user device being used to interact with the webpage within a particular period of time.

3. The method of claim 1 , further comprising receiving the request for the content to be placed on the webpage, wherein the webpage is being presented on a display associated with the user device.

4. The method of claim 1 , wherein the content is advertising content.

5. The method of claim 1 , further comprising generating a tag associated with web content that, when implemented on the user device, stores the plurality of hardware events that include user hardware activity on the user device being used to interact with the webpage and stores the plurality of interactions with the webpage.

6. The method of claim 1 , wherein each of the plurality of hardware events is performed by one or more user input hardware devices associated with the user device, wherein the one or more user input hardware devices is a pointer device associated with the user device, wherein the plurality of hardware events includes times at which the pointing device has been moved by a user of the pointing device, and wherein the plurality of interactions with the webpage includes locations corresponding to movement of a cursor across the webpage.

7. The method of claim 1 , wherein each of the plurality of hardware events is performed by one or more user input hardware devices associated with the user device, wherein the one or more user input hardware devices is a pointer device associated with the user device, wherein the plurality of hardware events includes relative position or relative movement information of the pointer device, and wherein the plurality of interactions with the webpage includes locations corresponding to movement of a cursor across the webpage.

8. The method of claim 1 , wherein each of the plurality of hardware events is performed by one or more user input hardware devices associated with the user device, wherein the one or more user input hardware devices is a keyboard device associated with the user device, wherein the plurality of hardware events includes times at which characters have been selected on the keyboard device and, for each time, an identification of which character was selected, and wherein the plurality of interactions with the webpage includes at least one of entries into text fields on the webpage and characters entered while viewing the webpage.

9. The method of claim 1 , wherein each of the plurality of hardware events is performed by one or more user input hardware devices associated with the user device, wherein the plurality of interactions with the webpage is correlated with the plurality of hardware events at one or more user input hardware devices by performing a regression analysis and wherein the at least a portion of the interactions with the webpage are determined to be indicative of suspicious activity based on a regression-based threshold value.

10. A system for detecting fraudulent activity on a website, the system comprising:

a hardware processor of a user device that, when executing hardware event detector code, is configured to:

detect a plurality of hardware events and a plurality of website interactions with a webpage, wherein each of the plurality of website interactions is associated with a corresponding output from the hardware event detector code;

determine whether a correlation exists between each of the plurality of website interactions with the webpage and one or more of the plurality of hardware events detected by the hardware event detector code;

determine whether the correlation indicates suspicious activity based on at least a portion of the website interactions that do not correlate with one or more of the plurality of hardware events; and

respond to a request for content on the webpage by inhibiting the content from being transmitted to the webpage based on the determination that the correlation indicates suspicious activity.

11. The system of claim 10 , wherein the plurality of hardware events includes user hardware activity on the user device being used to interact with the webpage within a particular period of time.

12. The system of claim 10 , wherein the hardware processor is further configured to receive the request for the content to be placed on the webpage, wherein the webpage is being presented on a display associated with the user device.

13. The system of claim 10 , wherein the content is advertising content.

14. The system of claim 10 , wherein the hardware processor is further configured to generate a tag associated with web content that, when implemented on the user device, stores the plurality of hardware events that include user hardware activity on the user device being used to interact with the webpage and stores the plurality of interactions with the webpage.

15. The system of claim 10 , wherein each of the plurality of hardware events is performed by one or more user input hardware devices associated with the user device, wherein the one or more user input hardware devices is a pointer device associated with the user device, wherein the plurality of hardware events includes times at which the pointing device has been moved by a user of the pointing device, and wherein the plurality of interactions with the webpage includes locations corresponding to movement of a cursor across the webpage.

16. The system of claim 10 , wherein each of the plurality of hardware events is performed by one or more user input hardware devices associated with the user device, wherein the one or more user input hardware devices is a pointer device associated with the user device, wherein the plurality of hardware events includes relative position or relative movement information of the pointer device, and wherein the plurality of interactions with the webpage includes locations corresponding to movement of a cursor across the webpage.

17. The system of claim 10 , wherein each of the plurality of hardware events is performed by one or more user input hardware devices associated with the user device, wherein the one or more user input hardware devices is a keyboard device associated with the user device, wherein the plurality of hardware events includes times at which characters have been selected on the keyboard device and, for each time, an identification of which character was selected, and wherein the plurality of interactions with the webpage includes at least one of entries into text fields on the webpage and characters entered while viewing the webpage.

18. The system of claim 10 , wherein each of the plurality of hardware events is performed by one or more user input hardware devices associated with the user device, wherein the plurality of interactions with the webpage is correlated with the plurality of hardware events at one or more user input hardware devices by performing a regression analysis and wherein the at least a portion of the interactions with the webpage are determined to be indicative of suspicious activity based on a regression-based threshold value.

19. A non-transitory computer-readable medium containing computer executable instructions that, when executed by a processor, cause the processor to perform a method for detecting fraudulent activity on a website, the method comprising:

detecting, using a hardware processor of a user device that executes hardware event detector code, a plurality of hardware events and a plurality of website interactions with a webpage, wherein each of the plurality of website interactions is associated with a corresponding output from the hardware event detector code;

determining, using the hardware processor, whether a correlation exists between each of the plurality of website interactions with the webpage and one or more of the plurality of hardware events detected by the hardware event detector code;

determining, using the hardware processor, whether the correlation indicates suspicious activity based on at least a portion of the website interactions that do not correlate with one or more of the plurality of hardware events; and

responding, using the hardware processor, to a request for content on the webpage by inhibiting the content from being transmitted to the webpage based on the determination that the correlation indicates suspicious activity.

Assignments (3)
PATENT SECURITY AGREEMENT Recorded Jan 9, 2026
From: INTEGRAL AD SCIENCE, INC.
To: ROYAL BANK OF CANADA, AS ADMINISTRATIVE AGENT
Reel/Frame 074280/0900 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL, RECORDED ON SEPTEMBER 18, 2025 AT REEL/FRAME NO. 72916/0431 Recorded Jan 9, 2026
From: PNC BANK, NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
To: INTEGRAL AD SCIENCE, INC.
Reel/Frame 074281/0009 →
PATENT SECURITY AGREEMENT Recorded Sep 18, 2025
From: INTEGRAL AD SCIENCE, INC.
To: PNC BANK, NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
Reel/Frame 072916/0431 →
Continuity (4)
Continuation 16852009 · Apr 17, 2020
Continuation 15338739 · Oct 31, 2016
Provisional Application 62248126 · Oct 29, 2015
Related Publication 20230057917A1 · Feb 23, 2023
Cited By (1)
US 12,192,221