IP Library Granted Patent US 12,192,221
Granted Patent B2
US 12,192,221 · App. 18/244,498 · Granted Jan 7, 2025

Methods, systems, and media for detecting fraudulent activity based on hardware events

Inventor: Yossef Oren (New York, NY)
Assignee: Integral Ad Science, Inc.
H04L63/1425H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,192,221
App. No.
18/244,498
Granted
Jan 7, 2025
Kind
B2
Abstract

Mechanisms for detecting fraudulent activity based on hardware events are provided. In accordance with some embodiments of the disclosed subject matter, the method comprises: receiving a request for advertising content to be placed on a website; receiving data describing physical activity at one or more user input hardware devices; receiving data describing interactions with the website; correlating the data describing interactions with the website with the data describing physical activity at one or more user input hardware devices; determining whether at least a portion of the interactions with the website are indicative of fraudulent behavior based on the correlation; and responding to the request for advertising content on the website by inhibiting the advertising content to be transmitted to the website in response to the determination that at least a portion of the interactions with the website indicates fraudulent behavior.

Claims (29)

1. A method for detecting fraudulent activity on a webpage, the method comprising:

detecting, using a hardware processor of a user device that executes hardware event detector code, a plurality of hardware events and a plurality of interactions with a page, wherein each of the plurality of interactions is associated with a corresponding output from the hardware event detector code;

determining, using the hardware processor, whether a correlation exists between each of the plurality of interactions with the page and one or more of the plurality of hardware events detected by the hardware event detector code and whether the correlation indicates suspicious activity based on at least a portion of the interactions that do not correlate with one or more of the plurality of hardware events; and

responding, using the hardware processor, to a request for content associated with the page by inhibiting the content from being transmitted to the page based on the determination that the correlation indicates suspicious activity.

2. The method of claim 1 , wherein the plurality of hardware events includes user hardware activity on the user device being used to interact with the page within a particular period of time.

3. The method of claim 1 , further comprising receiving the request for the content to be placed on the page, wherein the page is being presented on a display associated with the user device.

4. The method of claim 1 , wherein the content is advertising content.

5. The method of claim 1 , further comprising generating a tag associated with web content that, when implemented on the user device, stores the plurality of hardware events that include user hardware activity on the user device being used to interact with the page and stores the plurality of interactions with the page.

6. The method of claim 1 , wherein each of the plurality of hardware events is performed by one or more user input hardware devices associated with the user device, wherein the one or more user input hardware devices is a pointer device associated with the user device, wherein the plurality of hardware events includes times at which the pointing device has been moved by a user of the pointing device, and wherein the plurality of interactions with the page includes locations corresponding to movement of a cursor across the page.

7. The method of claim 1 , wherein each of the plurality of hardware events is performed by one or more user input hardware devices associated with the user device, wherein the one or more user input hardware devices is a pointer device associated with the user device, wherein the plurality of hardware events includes relative position or relative movement information of the pointer device, and wherein the plurality of interactions with the page includes locations corresponding to movement of a cursor across the page.

8. The method of claim 1 , wherein each of the plurality of hardware events is performed by one or more user input hardware devices associated with the user device, wherein the one or more user input hardware devices is a keyboard device associated with the user device, wherein the plurality of hardware events includes times at which characters have been selected on the keyboard device and, for each time, an identification of which character was selected, and wherein the plurality of interactions with the page includes at least one of entries into text fields on the page and characters entered while viewing the page.

9. The method of claim 1 , wherein each of the plurality of hardware events is performed by one or more user input hardware devices associated with the user device, wherein the plurality of interactions with the page is correlated with the plurality of hardware events at one or more user input hardware devices by performing a regression analysis and wherein the at least a portion of the interactions with the page are determined to be indicative of suspicious activity based on a regression-based threshold value.

10. A system for detecting fraudulent activity on a webpage, the system comprising:

a hardware processor of a user device that, when executing hardware event detector code, is configured to:

detect a plurality of hardware events and a plurality of interactions with a page, wherein each of the plurality of interactions is associated with a corresponding output from hardware event detector code;

determine whether a correlation exists between each of the plurality of interactions with the page and one or more of the plurality of hardware events detected by the hardware event detector code and whether the correlation indicates suspicious activity based on at least a portion of the interactions that do not correlate with one or more of the plurality of hardware events; and

respond to a request for content associated with the page by inhibiting the content from being transmitted to the page based on the determination that the correlation indicates suspicious activity.

11. The system of claim 10 , wherein the plurality of hardware events includes user hardware activity on the user device being used to interact with the page within a particular period of time.

12. The system of claim 10 , wherein the hardware processor is further configured to receive the request for the content to be placed on the page, wherein the page is being presented on a display associated with the user device.

13. The system of claim 10 , wherein the content is advertising content.

14. The system of claim 10 , wherein the hardware processor is further configured to generate a tag associated with web content that, when implemented on the user device, stores the plurality of hardware events that include user hardware activity on the user device being used to interact with the page and stores the plurality of interactions with the page.

15. The system of claim 10 , wherein each of the plurality of hardware events is performed by one or more user input hardware devices associated with the user device, wherein the one or more user input hardware devices is a pointer device associated with the user device, wherein the plurality of hardware events includes times at which the pointing device has been moved by a user of the pointing device, and wherein the plurality of interactions with the page includes locations corresponding to movement of a cursor across the page.

16. The system of claim 10 , wherein each of the plurality of hardware events is performed by one or more user input hardware devices associated with the user device, wherein the one or more user input hardware devices is a pointer device associated with the user device, wherein the plurality of hardware events includes relative position or relative movement information of the pointer device, and wherein the plurality of interactions with the page includes locations corresponding to movement of a cursor across the page.

17. The system of claim 10 , wherein each of the plurality of hardware events is performed by one or more user input hardware devices associated with the user device, wherein the one or more user input hardware devices is a keyboard device associated with the user device, wherein the plurality of hardware events includes times at which characters have been selected on the keyboard device and, for each time, an identification of which character was selected, and wherein the plurality of interactions with the page includes at least one of entries into text fields on the page and characters entered while viewing the page.

18. The system of claim 10 , wherein each of the plurality of hardware events is performed by one or more user input hardware devices associated with the user device, wherein the plurality of interactions with the page is correlated with the plurality of hardware events at one or more user input hardware devices by performing a regression analysis and wherein the at least a portion of the interactions with the page are determined to be indicative of suspicious activity based on a regression-based threshold value.

19. A non-transitory computer-readable medium containing computer executable instructions that, when executed by a processor, cause the processor to perform a method for detecting fraudulent activity on a website, the method comprising:

detecting, using a hardware processor of a user device that executes hardware event detector code, a plurality of hardware events and a plurality of interactions with a page, wherein each of the plurality of interactions is associated with a corresponding output from the hardware event detector code;

determining, using the hardware processor, whether a correlation exists between each of the plurality of interactions with the page and one or more of the plurality of hardware events detected by the hardware event detector code and whether the correlation indicates suspicious activity based on at least a portion of the interactions that do not correlate with one or more of the plurality of hardware events; and

responding, using the hardware processor, to a request for content associated with the page by inhibiting the content from being transmitted to the page based on the determination that the correlation indicates suspicious activity.

Assignments (3)
PATENT SECURITY AGREEMENT Recorded Jan 9, 2026
From: INTEGRAL AD SCIENCE, INC.
To: ROYAL BANK OF CANADA, AS ADMINISTRATIVE AGENT
Reel/Frame 074280/0900 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL, RECORDED ON SEPTEMBER 18, 2025 AT REEL/FRAME NO. 72916/0431 Recorded Jan 9, 2026
From: PNC BANK, NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
To: INTEGRAL AD SCIENCE, INC.
Reel/Frame 074281/0009 →
PATENT SECURITY AGREEMENT Recorded Sep 18, 2025
From: INTEGRAL AD SCIENCE, INC.
To: PNC BANK, NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
Reel/Frame 072916/0431 →
Continuity (5)
Continuation 17734746 · May 2, 2022
Continuation 16852009 · Apr 17, 2020
Continuation 15338739 · Oct 31, 2016
Provisional Application 62248126 · Oct 29, 2015
Related Publication 20230421591A1 · Dec 28, 2023
References Cited (30)
US 7657626B1 · Zwicky · 2010 [cited by applicant]
US 7917491B1 · Sack · 2011 [cited by applicant]
US 8321269B2 · Linden · 2012 [cited by examiner]
US 9565205B1 · Fleyder et al. · 2017 [cited by applicant]
US 10630707B1 · Oren · 2020 [cited by applicant]
US 11323468B1 · Oren · 2022 [cited by examiner]
US 11757910B2 · Oren · 2023 [cited by examiner]
US 20060136294A1 · Linden et al. · 2006 [cited by applicant]
US 20080162202A1 · Khanna · 2008 [cited by examiner]
US 20080301090A1 · Sadagopan et al. · 2008 [cited by applicant]
US 20090024460A1 · Willner · 2009 [cited by examiner]
US 20090024461A1 · Willner · 2009 [cited by examiner]
US 20090024971A1 · Willner · 2009 [cited by examiner]
US 20110113388A1 · Eisen et al. · 2011 [cited by applicant]
US 20120084146A1 · Zwicky · 2012 [cited by examiner]
US 20130226692A1 · Kouladjie et al. · 2013 [cited by applicant]
US 20140115662A1 · Johnson et al. · 2014 [cited by applicant]
US 20140149208A1 · Zwicky · 2014 [cited by examiner]
US 20140325645A1 · Turgeman et al. · 2014 [cited by applicant]
US 20150032533A1 · Raab et al. · 2015 [cited by applicant]
US 20150178771A1 · Linden · 2015 [cited by examiner]
US 20160080405A1 · Schler et al. · 2016 [cited by applicant]
US 20170032412A1 · Scharber et al. · 2017 [cited by applicant]
Notice of Allowance dated Jan. 5, 2022 in U.S. Appl. No. 16/852,009, pp. 1-35. [cited by applicant]
Notice of Allowance dated Apr. 27, 2023 in U.S. Appl. No. 17/734,746, pp. 1-28. [cited by applicant]
Notice of Allowance dated Dec. 13, 2019 in U.S. Appl. No. 15/338,739, pp. 1-29. [cited by applicant]
Office Action dated Jan. 19, 2023 in U.S. Appl. No. 17/734,746, pp. 1-22. [cited by applicant]
Office Action dated May 8, 2019 in U.S. Appl. No. 15/338,739, pp. 1-24. [cited by applicant]
Office Action dated Jul. 20, 2018 in U.S. Appl. No. 15/338,739, pp. 1-22. [cited by applicant]
Office Action dated Sep. 15, 2021 in U.S. Appl. No. 16/852,009, pp. 2-5. [cited by applicant]