NETWORK DEVICE DETECTION AND VERIFICATION PROTOCOL
Certain embodiments of this disclosure describe techniques for detecting a spoofed network device and preventing the serving of content, such as advertisements, to the spoofed network device. In certain embodiments, a network security system is provided. The network security system can include hardware and/or software programmed to prevent the provision of content to a spoofed client device. The network security system can provide a mechanism for certifying to content providers, such as advertisers, whether or not a client is a legitimate mobile device or a spoofed device. Accordingly, content providers can prevent the delivery of content to fraudulent devices instead of relying on imprecise solutions that detect fraudulent activity after it has occurred.
1 . A system for determining whether computer network activity is spoofed, the system comprising:
a first network device configured to receive packets over a network from a spoofed network device, the first network device comprising a hardware processor programmed to:
inspect the packets received from the spoofed network device to identify a unique identifier inserted into the packets at the spoofed network device by browser tag code that is in communication with the first network device;
query the spoofed network device for a digital fingerprint indicative of a legitimate network device;
identify that the query does not result in receiving the digital fingerprint;
send a request to a third-party service along with the unique identifier to obtain an indication of whether the spoofed network device has transmitted the packets through a mobile network or a beacon network; and
subsequent to not receiving an indication from the third-party service that the spoofed network device has transmitted the packets through a mobile network or a beacon network, prevent a delivery of content packets to the spoofed network device.
2 . The system of claim 1 , wherein the first network device is further configured to record data associated with the identification in a distributed data structure.
3 . The system of claim 1 , wherein the third-party service is a location service or a cellular network service.
4 . The system of claim 1 , wherein the first network device is further configured to prevent the delivery of content packets to the spoofed network device by not supplying a certification of legitimacy of the spoofed network device to a content provider of the content packets, wherein the content provider is enabled to refrain from delivering the content packets to the spoofed network device despite receiving a request from the spoofed networked device to deliver the content packets to the spoofed network device.
5 . A system for determining whether computer network activity is spoofed, the system comprising:
a first network device configured to receive packets at a first time period over a network from a second network device, the first network device comprising a hardware processor programmed to:
inspect the packets received from the second network device to identify a unique identifier inserted into the packets at the second network device by browser tag code that is in communication with the first network device;
query the second network device for a digital fingerprint indicative of a legitimate network device;
identify that the query does not result in receiving the digital fingerprint;
send a request to a third-party service along with the unique identifier to obtain an indication of whether the second network device has transmitted the packets through a mobile network or a beacon network; and
subsequent to receiving an indication from the third-party service that the second network device has transmitted the packets through a mobile network or a beacon network, permit a delivery of content packets to the second network device.
6 . The system of claim 5 , wherein the first network device is further configured to permit the delivery of content packets to the second network device by sending a certification to a content provider, the content provider being a source of the content packets, the certification indicating that the second network device is a legitimate network device.
7 . The system of claim 6 , wherein the first network device is further configured to record data associated with the certification in a distributed data structure.
8 . The system of claim 5 , wherein the first network device is further configured to create a second digital fingerprint and store the second digital fingerprint at the second network device, subsequent to receiving the indication from the third-party service that the second network device has transmitted the packets through a mobile network or a beacon network.
9 . The system of claim 8 , wherein the first network device is further configured to store the second digital fingerprint in a browser cookie at the second device.
10 . The system of claim 8 , wherein the second digital fingerprint is a persistent identifier that is maintained on the second device for a threshold period of time.
11 . The system of claim 10 , wherein the threshold period of time is associated with a time-to-live value.
12 . The system of claim 11 , wherein the first network device is further configured to:
receive packets at a second time period from the second network device;
query the second network device for the second digital fingerprint;
identify that the query results in receiving the second digital fingerprint; and
provide an indication to the second network device that the second network device is a legitimate network device.
13 . The system of claim 12 , wherein the indication is provided to the browser tag code that is in communication with the first network device.
14 . The system of claim 12 , wherein the first network device is further configured to reset the time-to-live value at the second network device.
15 . The system of claim 10 , wherein the first network device is further configured to store the persistent identifier at a third network device subsequent to determining that packets received from the third network device identify the unique identifier inserted into the packets at the third network device.
16 . The system of claim 5 , wherein the indication comprises a hashed mobile device number.
17 . A method of determining whether computer network activity is not spoofed, the method comprising:
as implemented by a hardware processor of a network security system,
receiving a packet at a first time period from a client device associated with a session identifier responsive to the client device accessing a webpage from a content provider;
determining the session identifier from the packet;
providing the session identifier to a cellular network provider to determine whether the client device communicated with the content provider via a cellular network;
receiving an indication from the client network provider that the client device communicated with the content provider via the cellular network;
generating a digital fingerprint associated with the client device subsequent to receiving the indication that the client device communicated with the content provider via the cellular network; and
storing the digital fingerprint at the client device, wherein the digital fingerprint indicates that the client device is associated with an account at a cellular service provider associated with the cellular network.
18 . The method of claim 17 , further comprising assigning a time-to-live value to the digital fingerprint at the client device.
19 . The method of claim 17 , further comprising:
receiving a second packet at a second time period from the client device responsive to the client device accessing a second webpage from a second content provider;
querying the client device for the digital fingerprint;
receiving the digital fingerprint responsive to querying the client device for the digital fingerprint; and
providing an indication to the client device that the client device is associated with the account at the cellular service provider.
20 . The method of claim 17 , further comprising:
receiving a third packet at a third time period from the client device responsive to an application at the client device being used at a point-of-sale;
accessing a data store associated with the network security system to determine whether the digital fingerprint is associated with the client device;
determining that the digital fingerprint is associated with the client device;
storing the digital fingerprint in a memory location at the client device associated with the application; and
updating a profile associated with the client device at the data store to indicate usage of the client device at the point-of-sale.