IP Library › Granted Patent US 11,729,283
Granted Patent B2
US 11,729,283 · App. 16/502,653 · Granted Aug 15, 2023

Apparatus for analysing online user behavior and method for the same

Inventors: Youngjin Kim (Seongnam-si, KR); Moweon Lee (Seongnam-si, KR)
Assignee: NAVER CORPORATION
H04L67/535G06F16/955G06F16/9535G06Q30/0631H04L67/146G06F21/316
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,729,283
App. No.
16/502,653
Granted
Aug 15, 2023
Kind
B2
Abstract

Method and apparatus for analyzing an online behavior of a user accessing a web server include: collecting, when a user terminal accesses a web server and forms a session, log data corresponding to a behavior performed by the user terminal in the session in real time; detecting log data corresponding to a trigger log among the log data; extracting, when the trigger log is detected, log data cumulated up to a detection time point of the trigger log from a start time point of the session and generating cumulative log data; and performing pattern analysis on the cumulative log data and generating behavior information corresponding to the behavior of the user terminal.

Claims (33)

1. A method for analyzing online behavior of a user accessing a web server through a user terminal, the method comprising:

collecting, every time the user terminal accesses the web server and forms a session having a start time, log data corresponding to behavior performed by the user terminal during progress of the session, the log data collected from the web server in real-time as the log data is generated by the web server;

detecting two or more trigger logs within the log data collected from the web server, wherein each of the two or more trigger logs correspond to one or more specified user behaviors set in advance; and

for each of the two or more trigger logs, at a time when the trigger log is detected:

extracting, from the log data collected from the web server, an inspection range of the log data from the start time of the session to a detection time of the trigger log;

generating cumulative log data from the start time to the detection time of the trigger log; and

in response to the generating of the cumulative log data, performing pattern analysis in real-time on the generated cumulative log data, wherein the pattern analysis is performed during the session by comparing the generated cumulative log data with an abnormal operation pattern and determining if the user terminal is performing an abnormal behavior based on the pattern analysis,

wherein the extracting, the generating and the performing pattern analysis are performed individually for each of the two or more trigger logs.

2. The method of claim 1 , wherein the log data includes at least one of

a uniform resource locator (URL) address and a page identifier (ID) of a web page which the user terminal accesses in the web server,

an input type and an input coordinate of an input which the user terminal applies in the web page, and

log-in information of the user terminal.

3. The method of claim 1 , wherein each of the two or more trigger logs include at least any one of an upload log corresponding to a behavior of uploading contents to the web server by the user terminal, a preference log corresponding to a behavior of inputting a preference for contents provided by the web server by the user terminal, a shopping access log corresponding to a behavior of accessing a shopping web page provided by the web server by the user terminal, and a settlement log corresponding to a cost settlement performed by the user terminal.

4. The method of claim 1 , wherein in the generating of the cumulative log data, when the two or more trigger logs are detected in one session, cumulative log data corresponding to respective trigger logs are individually generated.

5. The method of claim 4 , wherein the log data cumulated from the start time point of the session up to a detection time point of a most recent trigger log among the two or more trigger logs becomes the cumulative log data.

6. The method of claim 1 , further comprising:

determining whether the user terminal performs an abnormal behavior in the session by comparing each of the cumulative log data with an abnormal operation pattern,

wherein abnormal behavior information corresponding to the abnormal behavior performed by the user terminal is included in behavior information when the abnormal operation pattern corresponds to one of the cumulative log data.

7. The method of claim 1 , wherein when a shopping access log of accessing a shopping web page by the user terminal is included in one of the cumulative log data, the behavior information further includes product recommendation information corresponding to the shopping access log.

8. The method of claim 7 , wherein when a search log, performed by the user terminal before the shopping access log, is included in one of the cumulative log data, product recommendation information corresponding to the search log is included in the behavior information.

9. The method of claim 8 , wherein when there is no search log performed before the shopping access log in one of the cumulative log data, a search log performed in a previous session by the user terminal is extracted to generate product recommendation information corresponding to the search log performed in the previous session.

10. A non-transitory computer readable recording medium storing a computer program for executing, by a processor, the method for analyzing the online behavior of the user of claim 1 .

11. An apparatus for analyzing online behavior of a user accessing a web server through a user terminal, the apparatus comprising:

a processor; and

a memory coupled to the processor,

wherein the memory includes one or more modules configured to instruct the processor to execute steps including:

collecting, every time the user terminal accesses the web server and forms a session having a start time, log data corresponding to behavior performed by the user terminal during progress of the session, the log data collected from the web server in real-time as the log data is generated by the web server,

detecting two or more trigger logs within the log data collected from the web server, wherein each of the two or more trigger logs correspond to one or more specified user behaviors set in advance; and

for each of the two or more trigger logs, at a time when the trigger log is detected:

extracting, from the log data collected from the web server, an inspection range of the log data from the start time of the session to a detection time of the trigger log;

generating cumulative log data from the start time to the detection time of the trigger log, and

in response to the generating of the cumulative loci data, performing pattern analysis in real-time on the generated cumulative log data, wherein the pattern analysis is performed during the session by comparing the generated cumulative log data with an abnormal operation pattern and determining if the user terminal is performing an abnormal behavior based on the pattern analysis,

wherein the extracting, the generating and the performing pattern analysis are performed individually for each of the two or more trigger logs.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 3, 2019
From: KIM, YOUNGJIN; LEE, MOWEON
To: NAVER CORPORATION
Reel/Frame 049665/0040 →
Priority Claims (1)
KR 10-2018-0077339 · Jul 3, 2018 · national
Continuity (1)
Related Publication 20200014768A1 · Jan 9, 2020
Cited By (1)
US 12,726,496