IP Library Granted Patent US 10,621,613
Granted Patent B2
US 10,621,613 · App. 15/147,503 · Granted Apr 14, 2020

Systems and methods for monitoring malicious software engaging in online advertising fraud or other form of deceit

Inventors: Hadi Shiravi Khozani (Fredericton, CA); Ehsan Mokhtari (Fredericton, CA); Sergei Frankoff (Fredericton, CA); Mohammad Ali Shiravi Khozani (Fredericton, CA)
Assignee: The Nielsen Company (US), LLC
G06Q30/0248G06F21/53H04L63/1425H04L2463/144
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,621,613
App. No.
15/147,503
Granted
Apr 14, 2020
Kind
B2
Abstract

Systems, methods, and devices for advertising fraud malicious software botnet detection. Systems, methods, and devices for advertising fraud infrastructure infiltration. Systems, methods, and devices for identifying non-organic traffic entities. Systems, methods, and devices for local instrumentation of advertising fraud malicious software.

Claims (46)

1. A method comprising:

identifying a communication process used by a compromised computing device to communicate with a control server providing access to advertising weblinks;

communicating, by a milker bot, a request for an advertising weblink to the control server, wherein the communicating includes using the communication process to mimic the compromised computing device;

receiving the requested advertising weblink from the control server, wherein the advertising weblink includes metadata identifying the control server; and

monitoring the control server based on the metadata.

2. The method of claim 1 , wherein the monitoring of the control server includes at least one of determining an internet protocol address of the control server, identifying a MAC address of the control server, or identifying a physical location of the control server.

3. The method of claim 1 , further including identifying an encryption process used by the compromised computing device, the bot implemented using the encryption process and the communication process.

4. The method of claim 1 , wherein the identifying of the communication process includes:

recording an instruction executed by the compromised computing device; and

analyzing the recorded instruction to determine if the instruction is associated with the communication process.

5. The method of claim 1 , wherein the identifying of the communication process includes:

executing a binary code associated with the compromised computing device in a controlled computing environment; and

analyzing information associated with the execution of the binary code to identify the communication process.

6. The method of claim 5 , wherein the controlled computing environment is a virtual instance of an operating system including sensors, the sensors to collect the information associated with the execution of the binary code.

7. The method of claim 1 , further including increasing a request rate of the milker bot by running a plurality of milker bots in parallel.

8. A non-transitory computer readable medium comprising instructions, which when executed, cause a processor to:

identify a communication process used by a compromised computing device to communicate with a control server providing access to advertising weblinks;

communicate, by a milker bot, a request for an advertising weblink to the control server, wherein the communicating includes using the communication process to mimic the compromised computing device;

receive the requested advertising weblink from the control server, wherein the advertising weblink includes metadata identifying the control server; and

monitor the control server based on the metadata.

9. The non-transitory computer readable medium of claim 8 , wherein the monitoring of the control server includes at least one of determining an internet protocol address of the control server, identifying a MAC address of the control server, or identifying a physical location of the control server.

10. The non-transitory computer readable medium of claim 8 , wherein the instructions, when executed, further cause the processer to identify an encryption process used by the compromised computing device, the milker bot implemented using the encryption process and the communication process.

11. The non-transitory computer readable medium of claim 8 , wherein instructions cause the processor to identify the communication process by:

record an instruction executed by the compromised computing device; and

analyze the recorded instruction to determine if the instruction is associated with the communication process.

12. The non-transitory computer readable medium of claim 8 , wherein instructions cause the processor to identify the communication process by:

execute a binary code associated with the compromised computing device in a controlled computing environment; and

analyze information associated with the execution of the binary code to identify the communication process.

13. The non-transitory computer readable medium of claim 12 , wherein the controlled computing environment is a virtual instance of an operating system including sensors, the sensors to collect the information associated with the execution of the binary code.

14. The non-transitory computer readable medium of claim 8 , wherein instructions cause the processor to identify the communication process by increasing a request rate of the milker bot by running a plurality of milker bots in parallel.

15. An apparatus comprising:

memory;

a processor to identify a communication process used by a compromised computing device to communicate with a control server providing access to advertising weblinks;

a network interface to:

communicate, by a milker bot, a request for an advertising weblink to the control server, wherein the communicating includes using the communication process to mimic the compromised computing device; and

receive the requested advertising weblink from the control server, wherein the advertising weblink includes metadata identifying the control server; and

the processor further to monitor the control server based on the metadata.

16. The apparatus of claim 15 , wherein the processor monitors the control server by at least one of (1) determining an internet protocol address of the control server, (2) identifying a MAC address of the control server, or (3) identifying a physical location of the control server.

17. The apparatus of claim 15 , wherein the processer is further to identify an encryption process used by the compromised computing device, the milker bot implemented using the encryption process and the communication process.

18. The apparatus of claim 15 , wherein the processor is further to:

record an instruction executed by the compromised computing device; and

analyze the recorded instruction to determine if the instruction is associated with the communication process.

19. The apparatus of claim 15 , wherein the processor is further to:

execute a binary code associated with the compromised computing device in a controlled computing environment; and

analyze information associated with the execution of the binary code to identify the communication process.

20. The apparatus of claim 19 , wherein the controlled computing environment is a virtual instance of an operating system including sensors, the sensors to collect the information associated with the execution of the binary code.

Assignments (10)
RELEASE (REEL 054066 / FRAME 0064) Recorded May 11, 2023
From: CITIBANK, N.A.
To: A. C. NIELSEN COMPANY, LLC; EXELATE, INC.; GRACENOTE, INC.; GRACENOTE MEDIA SERVICES, LLC; THE NIELSEN COMPANY (US), LLC; NETRATINGS, LLC
Reel/Frame 063605/0001 →
RELEASE (REEL 053473 / FRAME 0001) Recorded May 11, 2023
From: CITIBANK, N.A.
To: A. C. NIELSEN COMPANY, LLC; EXELATE, INC.; GRACENOTE, INC.; GRACENOTE MEDIA SERVICES, LLC; THE NIELSEN COMPANY (US), LLC; NETRATINGS, LLC
Reel/Frame 063603/0001 →
SECURITY INTEREST Recorded May 8, 2023
From: GRACENOTE DIGITAL VENTURES, LLC; GRACENOTE MEDIA SERVICES, LLC; GRACENOTE, INC.; TNC (US) HOLDINGS, INC.; THE NIELSEN COMPANY (US), LLC
To: ARES CAPITAL CORPORATION
Reel/Frame 063574/0632 →
SECURITY INTEREST Recorded Apr 28, 2023
From: GRACENOTE DIGITAL VENTURES, LLC; GRACENOTE MEDIA SERVICES, LLC; GRACENOTE, INC.; TNC (US) HOLDINGS, INC.; THE NIELSEN COMPANY (US), LLC
To: CITIBANK, N.A.
Reel/Frame 063561/0381 →
SECURITY AGREEMENT Recorded Jan 31, 2023
From: GRACENOTE DIGITAL VENTURES, LLC; GRACENOTE MEDIA SERVICES, LLC; GRACENOTE, INC.; TNC (US) HOLDINGS, INC.; THE NIELSEN COMPANY (US), LLC
To: BANK OF AMERICA, N.A.
Reel/Frame 063560/0547 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PATENTS LISTED ON SCHEDULE 1 RECORDED ON 6-9-2020 PREVIOUSLY RECORDED ON REEL 053473 FRAME 0001. ASSIGNOR(S) HEREBY CONFIRMS THE SUPPLEMENTAL IP SECURITY AGREEMENT. Recorded Oct 7, 2020
From: A.C. NIELSEN (ARGENTINA) S.A.; A.C. NIELSEN COMPANY, LLC; ACN HOLDINGS INC.; ACNIELSEN CORPORATION; ACNIELSEN ERATINGS.COM; AFFINNOVA, INC.; ART HOLDING, L.L.C.; ATHENIAN LEASING CORPORATION; CZT/ACN TRADEMARKS, L.L.C.; EXELATE, INC.; GRACENOTE, INC.; GRACENOTE DIGITAL VENTURES, LLC; GRACENOTE MEDIA SERVICES, LLC; NETRATINGS, LLC; NIELSEN AUDIO, INC.; NIELSEN CONSUMER INSIGHTS, INC.; NIELSEN CONSUMER NEUROSCIENCE, INC.; NIELSEN FINANCE CO.; NIELSEN FINANCE LLC; NIELSEN INTERNATIONAL HOLDINGS, INC.; NIELSEN MOBILE, LLC; NMR INVESTING I, INC.; TCG DIVESTITURE INC.; TNC (US) HOLDINGS, INC.; THE NIELSEN COMPANY (US), LLC; VIZU CORPORATION; VNU MARKETING INFORMATION, INC.; NMR LICENSING ASSOCIATES, L.P.; NIELSEN HOLDING AND FINANCE B.V.; THE NIELSEN COMPANY B.V.; VNU INTERNATIONAL B.V.
To: CITIBANK, N.A
Reel/Frame 054066/0064 →
SUPPLEMENTAL SECURITY AGREEMENT Recorded Jun 9, 2020
From: A. C. NIELSEN COMPANY, LLC; ACN HOLDINGS INC.; ACNIELSEN CORPORATION; ACNIELSEN ERATINGS.COM; AFFINNOVA, INC.; ART HOLDING, L.L.C.; ATHENIAN LEASING CORPORATION; CZT/ACN TRADEMARKS, L.L.C.; EXELATE, INC.; GRACENOTE, INC.; GRACENOTE DIGITAL VENTURES, LLC; GRACENOTE MEDIA SERVICES, LLC; NETRATINGS, LLC; NIELSEN AUDIO, INC.; NIELSEN CONSUMER INSIGHTS, INC.; NIELSEN CONSUMER NEUROSCIENCE, INC.; NIELSEN FINANCE CO.; NIELSEN FINANCE LLC; NIELSEN INTERNATIONAL HOLDINGS, INC.; NIELSEN MOBILE, LLC; NIELSEN UK FINANCE I, LLC; NMR INVESTING I, INC.; TCG DIVESTITURE INC.; TNC (US) HOLDINGS, INC.; THE NIELSEN COMPANY (US), LLC; VIZU CORPORATION; VNU MARKETING INFORMATION, INC.; NMR LICENSING ASSOCIATES, L.P.; NIELSEN HOLDING AND FINANCE B.V.; THE NIELSEN COMPANY B.V.; VNU INTERNATIONAL B.V.
To: CITIBANK, N.A.
Reel/Frame 053473/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE SECOND ASSIGNORS NAME PREVIOUSLY RECORDED AT REEL: 039001 FRAME: 0872. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded May 17, 2017
From: SHIRAVI KHOZANI, HADI; MOKHTARI, EHSAN; FRANKOFF, SERGEI; SHIRAVI KHOZANI, MOHAMMAD ALI
To: SENTRANT SECURITY INC.
Reel/Frame 042488/0952 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 12, 2017
From: SENTRANT SECURITY INC.
To: THE NIELSEN COMPANY (US), LLC
Reel/Frame 042360/0931 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 24, 2016
From: SHIRAVI KHOZANI, HADI; SHIRAVI KHOZANI, EHSAN; FRANKOFF, SERGEI; SHIRAVI KHOZANI, MOHAMMAD ALI
To: SENTRANT SECURITY INC.
Reel/Frame 039001/0872 →
Continuity (2)
Provisional Application 62157195 · May 5, 2015
Related Publication 20160328742A1 · Nov 10, 2016
Cited By (3)
US 12,511,392 US 12,688,278 US 12,719,883