IP Library Granted Patent US 12,536,562
Granted Patent B2
US 12,536,562 · App. 18/244,502 · Granted Jan 27, 2026

Systems, methods, and media for detecting suspicious activity

Inventors: Jason Lloyd Shaw (New York, NY); David William Luttrell (Philadelphia, PA); Arun Ahuja (Stamford, CT)
Assignee: Integral Ad Science, Inc.
G06Q30/0248
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,536,562
App. No.
18/244,502
Granted
Jan 27, 2026
Kind
B2
Abstract

Systems, methods, and media for detecting suspicious activity in connection with advertisement impressions are provided. In some embodiments, the method includes: collecting advertisement impression information associated with a plurality of pages; determining, from the collected advertisement impression information, an indication of whether a browser application detected that an advertisement displayed on a webpage was viewable in a browser window; determining, from the collected advertisement impression information, a plurality of viewability statistics for each of the plurality of pages, wherein each viewability statistic indicates a likelihood of whether an advertisement displayed on a webpage was viewable in a browser window; comparing the plurality of viewability statistics with the indication from the browser application; determining a viewability score for the advertisement impression based on the comparison; and identifying the advertisement impression as likely to be suspicious based on the determined viewability score.

Claims (51)

1 . A method for detecting suspicious activity from a plurality of websites, the method comprising:

receiving, using a server that includes a hardware processor, advertisement impression information associated with a plurality of pages;

determining, by the server, from the received advertisement impression information, a viewability statistic for each of the plurality of pages, wherein the viewability statistic indicates a likelihood of whether an advertisement displayed on a webpage was never within a viewable area in a browser window rendered by a browser application;

determining, by the server, a viewability score for the advertisement impression based on the viewability statistic;

identifying, by the server, the advertisement impression as likely being suspicious based on the determined viewability score; and

intercepting, by the server, an advertisement call associated with a page on which the advertisement impression identified as likely being suspicious, wherein the advertisement call is modified with information relating to the advertisement impression identified as likely being suspicious that inhibits an advertiser from placing a bid to place one or more content items in a content inventory associated with the advertiser in a corresponding advertisement placement.

2 . The method of claim 1 , further comprising inhibiting content associated with the advertisement impression identified as likely to be suspicious from being purchased for advertisement placement.

3 . The method of claim 1 , further comprising transmitting information relating to the identified advertisement impression that inhibits the advertiser from associating with a corresponding website.

4 . The method of claim 1 , wherein the viewability statistic comprises a fraction of advertisement impressions that was never in the viewable area of the browser window.

5 . The method of claim 1 , further comprising identifying at least one website as likely to be suspicious based on the viewability score by determining that the viewability statistic exceeds a selected threshold value, wherein the selected threshold value indicates that the at least one website is engaging in suspicious activity.

6 . The method of claim 1 , further comprising:

determining a portion of the plurality of pages corresponding to the website;

determining one or more advertisements presented on the portion of the plurality of pages; and

determining a plurality of browsers associated with advertisement calls for the one or more advertisements.

7 . The method of claim 1 , further comprising:

extracting identification data associated with at least one website that is deemed suspicious;

searching for other websites having identification data that is similar to the extracted identification data; and

determining whether at least one of the other websites should be deemed as likely to be suspicious.

8 . The method of claim 1 , further comprising:

receiving training data;

identifying features for differentiating suspicious websites from normal websites using the received training data; and

using a classifier with the identified features to identify the suspicious websites from the plurality of websites.

9 . A system for detecting suspicious activity from a plurality of websites, the system comprising:

a server that includes a hardware processor that:

receives advertisement impression information associated with a plurality of pages;

determines, from the received advertisement impression information, a viewability statistic for each of the plurality of pages, wherein the viewability statistic indicates a likelihood of whether an advertisement displayed on a webpage was never within a viewable area in a browser window rendered by a browser application;

determines a viewability score for the advertisement impression based on the viewability statistic;

identifies the advertisement impression as likely being suspicious based on the determined viewability score; and

intercepts an advertisement call associated with a page on which the advertisement impression identified as likely being suspicious, wherein the advertisement call is modified with information relating to the advertisement impression identified as likely being suspicious that inhibits an advertiser from placing a bid to place one or more content items in a content inventory associated with the advertiser in a corresponding advertisement placement.

10 . The system of claim 9 , wherein the hardware processor further inhibits content associated with the advertisement impression identified as likely to be suspicious from being purchased for advertisement placement.

11 . The system of claim 9 , wherein the hardware processor further transmits information relating to the identified advertisement impression that inhibits the advertiser from associating with a corresponding website.

12 . The system of claim 9 , wherein the viewability statistic comprises a fraction of advertisement impressions that was never in the viewable area of the browser window.

13 . The system of claim 9 , wherein the hardware processor further identifies at least one website as likely to be suspicious based on the viewability score by determining that the viewability statistic exceeds a selected threshold value, wherein the selected threshold value indicates that the at least one website is engaging in suspicious activity.

14 . The system of claim 9 , wherein the hardware processor further:

determines a portion of the plurality of pages corresponding to the website;

determines one or more advertisements presented on the portion of the plurality of pages; and

determines a plurality of browsers associated with advertisement calls for the one or more advertisements.

15 . The system of claim 9 , wherein the hardware processor further:

extracts identification data associated with at least one website that is deemed suspicious;

searches for other websites having identification data that is similar to the extracted identification data; and

determines whether at least one of the other websites should be deemed as likely to be suspicious.

16 . The system of claim 9 , wherein the hardware processor further:

receives training data;

identifies features for differentiating suspicious websites from normal websites using the received training data; and

uses a classifier with the identified features to identify the suspicious websites from the plurality of websites.

17 . A non-transitory computer-readable medium containing computer-executable instructions that, when executed by a processor, cause the processor to perform a method for detecting suspicious activity from a plurality of websites, the method comprising:

receiving advertisement impression information associated with a plurality of pages;

determining, from the received advertisement impression information, a viewability statistic for each of the plurality of pages, wherein the viewability statistic indicates a likelihood of whether an advertisement displayed on a webpage was never within a viewable area in a browser window rendered by a browser application;

determining a viewability score for the advertisement impression based on the viewability statistic;

identifying the advertisement impression as likely being suspicious based on the determined viewability score; and

intercepting an advertisement call associated with a page on which the advertisement impression identified as likely being suspicious, wherein the advertisement call is modified with information relating to the advertisement impression identified as likely being suspicious that inhibits an advertiser from placing a bid to place one or more content items in a content inventory associated with the advertiser in a corresponding advertisement placement.

Assignments (3)
PATENT SECURITY AGREEMENT Recorded Jan 9, 2026
From: INTEGRAL AD SCIENCE, INC.
To: ROYAL BANK OF CANADA, AS ADMINISTRATIVE AGENT
Reel/Frame 074280/0900 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL, RECORDED ON SEPTEMBER 18, 2025 AT REEL/FRAME NO. 72916/0431 Recorded Jan 9, 2026
From: PNC BANK, NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
To: INTEGRAL AD SCIENCE, INC.
Reel/Frame 074281/0009 →
PATENT SECURITY AGREEMENT Recorded Sep 18, 2025
From: INTEGRAL AD SCIENCE, INC.
To: PNC BANK, NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
Reel/Frame 072916/0431 →
Continuity (5)
Continuation 17716838 · Apr 8, 2022
Continuation 16544322 · Aug 19, 2019
Continuation 13909018 · Jun 3, 2013
Provisional Application 61654511 · Jun 1, 2012
Related Publication 20230419360A1 · Dec 28, 2023
References Cited (57)
US 7657626B1 · Zwicky · 2010 [cited by applicant]
US 8655724B2 · Chow et al. · 2014 [cited by applicant]
US 8671057B1 · Zuili · 2014 [cited by applicant]
US 8732017B2 · Attenberg et al. · 2014 [cited by applicant]
US 9298845B2 · Belenguer · 2016 [cited by applicant]
US 10552878B2 · Lorimor et al. · 2020 [cited by applicant]
US 10783548B1 · Bhowmick et al. · 2020 [cited by applicant]
US 10929893B2 · Theodore · 2021 [cited by applicant]
US 11068931B1 · Luttrell et al. · 2021 [cited by applicant]
US 20010039523A1 · Iwamoto · 2001 [cited by applicant]
US 20070005417A1 · Desikan et al. · 2007 [cited by applicant]
US 20090012853A1 · Nolet et al. · 2009 [cited by applicant]
US 20090012867A1 · Lerman et al. · 2009 [cited by applicant]
US 20090043593A1 · Herbrich et al. · 2009 [cited by applicant]
US 20090254433A1 · Cao · 2009 [cited by applicant]
US 20100121676A1 · Jackson · 2010 [cited by examiner]
US 20110029393A1 · Apprendi et al. · 2011 [cited by applicant]
US 20110047006A1 · Attenberg et al. · 2011 [cited by applicant]
US 20110082755A1 · Itzhak · 2011 [cited by examiner]
US 20110137733A1 · Baird et al. · 2011 [cited by applicant]
US 20110137737A1 · Baird et al. · 2011 [cited by applicant]
US 20110173037A1 · Attenberg et al. · 2011 [cited by applicant]
US 20110196735A1 · von Sydow et al. · 2011 [cited by applicant]
US 20110251901A1 · Kwon · 2011 [cited by examiner]
US 20110296009A1 · Baranov et al. · 2011 [cited by applicant]
US 20120047203A1 · Brown et al. · 2012 [cited by applicant]
US 20120324098A1 · De Jager et al. · 2012 [cited by applicant]
US 20130126844A1 · Nishiyama · 2013 [cited by applicant]
US 20130185164A1 · Pottjegort · 2013 [cited by examiner]
US 20130305170A1 · De Souza et al. · 2013 [cited by applicant]
US 20140173086A1 · Carncross et al. · 2014 [cited by applicant]
US 20140281901A1 · Mostowy et al. · 2014 [cited by applicant]
US 20160125453A1 · Shukla et al. · 2016 [cited by applicant]
US 20160180374A1 · Cetintas et al. · 2016 [cited by applicant]
US 20170228762A1 · Riviello et al. · 2017 [cited by applicant]
US 20170316467A1 · Seiler et al. · 2017 [cited by applicant]
US 20170357998A1 · Scharf · 2017 [cited by applicant]
US 20170372380A1 · Candiotti · 2017 [cited by applicant]
US 20180218389A1 · Walker · 2018 [cited by examiner]
WO WO2014124417 · 2014 [cited by applicant]
Chong Wang, Achir Kalra, Cristian Borcea, and Yi Chen. 2015. Viewability Prediction for Online Display Ads. In Proceedings of the 24th ACM International on Conference on Information and Knowledge Management (CIKM '15). … [cited by examiner]
ADWeek Online, “AdSafe Media Announces the Release of Suspicious Activity Ratings”, Internet Wire, Jul. 17, 2012, pp. 1-6. [cited by applicant]
ADWeek Online, “DoubleVerify Aims to Police Web Ads”, Jul. 22, 2010, available at: https://dialog.proquest.com/professional/docview/738256735?accountid=131444, pp. 1-5. [cited by applicant]
Li, Ai-Chun et al., “Application of Web Mining Technology to Click Fraud Detection”, In Computer Engineering and Design, 33.3, Mar. 2012, pp. 957-962. [cited by applicant]
Notice of Allowance dated May 3, 2023 in U.S. Appl. No. 17/716,838, pp. 1-39. [cited by applicant]
Notice of Allowance dated Dec. 10, 2021 in U.S. Appl. No. 16/544,322, pp. 2-8. [cited by applicant]
Notice of Allowance dated Apr. 3, 2019 in U.S. Appl. No. 13/909,018, pp. 2-48. [cited by applicant]
Office Action dated Jan. 19, 2023 in U.S. Appl. No. 17/716,838, pp. 1-29. [cited by applicant]
Office Action dated Jan. 23, 2018 in U.S. Appl. No. 13/909,018, pp. 2-16. [cited by applicant]
Office Action dated Apr. 30, 2021 in U.S. Appl. No. 16/544,322, pp. 2-14. [cited by applicant]
Office Action dated May 19, 2017 in U.S. Appl. No. 13/909,018, pp. 1-34. [cited by applicant]
Office Action dated Aug. 31, 2018 in U.S. Appl. No. 13/909,018, pp. 2-85. [cited by applicant]
Office Action dated Sep. 9, 2016 in U.S. Appl. No. 13/909,018, pp. 2-41. [cited by applicant]
Office Action dated Oct. 28, 2015 in U.S. Appl. No. 13/909,018, pp. 1-50. [cited by applicant]
Office Action dated Dec. 17, 2020 in U.S. Appl. No. 16/544,322, pp. 2-12. [cited by applicant]
Press Release, “Mpire Adds Proactive Ad Block & RealTime Alert Capabilities to AdXpose Suite Ad Analytics Solutions; AudienceScience Leverages AdXpos to Protect Clients' Brands: Mpire Partners w/ comScore Enhance AdXpos… [cited by applicant]
Sullivan, L. “Study: Half of Ad Impressions, 95 Percent of Clicks Fraudulent”, Sep. 17, 2009, available at: http://www.mediapost.com/publications/article/113734/study-half-of-ad-impressions-95-perecent-of-click.html?edi… [cited by applicant]