IP Library › Granted Patent US 11,431,638
Granted Patent B2
US 11,431,638 · App. 17/070,089 · Granted Aug 30, 2022

System and method for monitoring and managing video stream content

Inventors: Darrell Reginald May (Waterloo, CA); Bojja Krishna Chaitanya (Andhra Pradesh, IN); Srinivas Chintamaneni (Karnataka, IN)
H04L47/24H04L47/28H04L65/60
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,431,638
App. No.
17/070,089
Granted
Aug 30, 2022
Kind
B2
Abstract

A system and method for managing and monitoring video stream content. The method including: receiving a traffic flow; determining if the traffic flow is a video streaming traffic flow; if the traffic flow is a video streaming traffic flow; determine at least one attribute associated with the video streaming traffic flow; determine a probability that the traffic flow is fraudulent based on a heuristic analysis of the at least one associated attribute; if the probability is above a predetermined threshold, flag the traffic flow as a fraudulent video streaming traffic flow, otherwise allow the traffic flow to proceed to its destination without being flagged; if the traffic flow is not a video streaming traffic flow, allow the traffic flow to proceed to its destination.

Claims (69)

1. A method for monitoring and managing video stream content comprising:

receiving a traffic flow;

determining if the traffic flow is a video streaming traffic flow;

if the traffic flow is a video streaming traffic flow;

determine at least two attributes associated with the video streaming traffic flow, wherein the at least two attributes are detected from traffic flow level information;

determine a probability that the traffic flow is fraudulent based on a heuristic analysis of the at least two associated attributes based on a decision matrix;

if the probability is above a predetermined threshold, flag the traffic flow as a fraudulent video streaming traffic flow, otherwise allow the traffic flow to proceed to its destination without being flagged;

if the traffic flow is not a video streaming traffic flow, allow the traffic flow to proceed to its destination.

2. The method according to claim 1 wherein determining the at least two attributes associated with the traffic flow comprises:

retrieving at least one packet from the traffic flow;

determining at least one header of the at least one packet; and

determining the at least two attributes by determining at least two fields from within the at least one header.

3. The method according to claim 2 wherein the at least one header is selected from the group of Internet Protocol Header; Transmission Control Protocol Header; HyperText Transfer Protocol; Transport Layer Security/Secure Sockets Layer Header; and Domain Name Server Header.

4. The method according to claim 1 wherein determining at least two attributes associated with the traffic flow comprises:

determining a video frame of the video streaming traffic flow;

performing a hash of the video frame of the video streaming traffic flow;

retrieving a second hash of a video frame of a legitimate video stream; and

comparing the hash to the second hash to determine whether the hashes match.

5. The method according to claim 1 wherein determining a probability of that the traffic flow is fraudulent comprises:

retrieving at least one legitimate video stream attribute from a memory component;

performing a comparison between the at least one legitimate video stream attributes and one of the two attributes; and

determining a match probability of the legitimated video stream and the traffic flow based on the comparison.

6. The method according to claim 5 , wherein the at least two attributes are considered matched if the match probability is above 80%.

7. The method according to claim 1 , wherein determining a probability of that the traffic flow is fraudulent comprises:

retrieving legitimate video stream attributes from a memory component; and

performing a probabilistic matching algorithm with respect to the associated attributes of the video stream traffic flow with the retrieved legitimate video stream attributes.

8. The method according to claim 1 further comprising performing traffic actions on the video stream traffic flow if the probability that the traffic flow is fraudulent is above a second predetermined threshold.

9. The method according to claim 1 wherein determining the at least two attributes associated with the traffic flow comprises:

determining a packet timestamp associated with the video streaming traffic flow; and

updating the probability that the traffic flow is fraudulent based on the timestamp.

10. The method according to claim 1 , wherein determining the at least two attributes associated with the traffic flow comprises:

retrieving at least one packet from the traffic flow;

determining a packet payload from the at least one packet;

determining a channel name from the payload of the at least one packet; and

updating the probability that the traffic flow is fraudulent based on the channel name.

11. A system for monitoring and managing video stream video stream content comprising:

an analysis module configured to:

receive a traffic flow;

determine if the traffic flow is a video streaming traffic flow;

if the traffic flow is a video streaming traffic flow;

determine at least two attributes associated with the video streaming traffic flow, wherein the at least two attributes are detected from traffic flow level information;

a video module configured to determine a probability that the traffic flow is fraudulent based on a heuristic analysis of the at least two associated attributes based on a decision matrix; and

a reporting module configured to flag the traffic flow as a fraudulent video streaming traffic flow if the probability is above a predetermined threshold.

12. The system according to claim 11 , wherein the analysis module is further configured to:

retrieve at least one packet from the traffic flow;

determine at least one header of the at least one packet; and

determine at least two attributes by determining at least two fields from within the at least one header.

13. The system according to claim 12 wherein the at least one header is selected from the group of Internet Protocol Header; Transmission Control Protocol Header; HyperText Transfer Protocol; Transport Layer Security/Secure Sockets Layer Header; and Domain Name Server Header.

14. The system according to claim 11 wherein the analysis module is further configured to:

determine a video frame of the video streaming traffic flow;

perform a hash of the video frame of the video streaming traffic flow;

retrieve a second hash of a video frame of a legitimate video stream; and

compare the hash to the second hash to determine whether the hashes match.

15. The system according to claim 11 wherein the analysis module is further configured to:

retrieve at least one legitimate video stream attribute from a memory component;

perform a comparison between the at least one legitimate video stream attributes and one of the at least two traffic flow attributes; and

the video module is configured to determine a match probability of the legitimated video stream and the traffic flow based on the comparison.

16. The system according to claim 15 , wherein the at least two attributes are considered matched if the match probability is above 80%.

17. The system according to claim 11 , wherein the analysis module is further configured to:

retrieve legitimate video stream attributes from a memory component; and

perform a probabilistic matching algorithm with respect to the associated attributes of the video stream traffic flow with the retrieved legitimate video stream attributes.

18. The system according to claim 11 wherein the reporting module is further configured to perform traffic actions on the video stream traffic flow if the probability that the traffic flow is fraudulent is above a second predetermined threshold.

19. The system according to claim 11 wherein the analysis module is further configured to retrieve at least one packet from the video streaming traffic flow and determine a packet timestamp associated with the at least one packet; and

the video module is configured to update the probability that the traffic flow is fraudulent based on the timestamp.

20. The system according to claim 11 , wherein the analysis module is further configured to:

retrieve at least one packet from the traffic flow;

determine a packet payload from the at least one packet; and

determine a channel name from the payload of the at least one packet; and

the video module is configured to update the probability that the traffic flow is fraudulent based on the channel name.

Priority Claims (1)
IN 201911041534 · Oct 14, 2019 · national
Continuity (1)
Related Publication 20210112010A1 · Apr 15, 2021