IP Library Granted Patent US 12,316,635
Granted Patent B1
US 12,316,635 · App. 18/589,792 · Granted May 27, 2025

Automated bot blocking

Inventors: Matthias Günther Keller (Winchester, MA); Algirdas Rascius (Kaunas, LT); Alexei Borisovich Fedotov (Natick, MA); Darius Prakaitis (Kaunas, LT)
Assignee: KAYAK Software Corporation
H04L63/10G06N5/04H04L63/1416H04L63/107H04L63/108H04L2463/144
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,316,635
App. No.
18/589,792
Granted
May 27, 2025
Kind
B1
Abstract

A system for limiting access to a digital resource based on detection of unauthorized scraping of the digital resource includes one or more processors configured to execute the instructions to detect, over a network, first data representing a plurality of first interactions by a client device with the digital resource hosted on a host system; extract, from the hardware storage device, second data representing a plurality of second interactions with digital resources, with the second interactions satisfy conditions for an interaction to be authorized; determine a confidence score based on comparing the first and second data, with the confidence score indicating a likelihood that an interaction is unauthorized; based on the determined confidence score indicating that the first interactions are unauthorized, detect, by one or more processing devices, unauthorized scraping of the digital resource; and limit access of the client device to the digital resource.

Claims (51)

1. A method comprising:

detecting, over a network, first data representing first interactions by a client device with a digital resource hosted on a host system;

determining second data representing second interactions with digital resources, the second interactions satisfying conditions for an interaction to be authorized;

determining, based at least in part on the first data and the second data, a first confidence score, the first confidence score associated with:

a first reference confidence score indicating a first likelihood that the interaction is unauthorized; and

a second reference confidence score indicating additional verification is merited;

responsive to determining that the first confidence score satisfies a first confidence score threshold associated with the second reference confidence score, receiving third data representing third interactions by the client device, the third interactions comprising a) one or more interactions with at least one of a CAPTCHA or the digital resource and b) interactions differing from the first interactions;

determining a second confidence score based at least in part on the third data and the second data;

based at least in part on the second confidence score satisfying a second confidence threshold associated with the first reference confidence score, detecting unauthorized scraping of the digital resource; and

limiting access of the client device to the digital resource.

2. The method of claim 1 , wherein the first interactions include receiving a plurality of requests associated with a travel reservation.

3. The method of claim 1 , wherein the second interactions with the digital resources include at least one of time attributes, location attributes, device attributes, client specific attributes, network attributes, or business attributes, the method further comprising:

in response to determining the second interactions satisfy conditions for an interaction to be authorized, updating a database configured to store the second interactions such that the database stores recent second interactions.

4. The method of claim 1 , wherein the second data representing the second interactions with the digital resources include time attributes, wherein the time attributes include at least one of session duration, time zone of the first interactions, time spent interacting with the digital resource, number of times the digital resource was accessed within a predetermined time period, number of travel requests received within a predetermined time period or travel schedule data.

5. The method of claim 1 , wherein the second data representing the second interactions with the digital resources include location attributes, wherein the location attributes include geographical location of a source of the first interactions, number of interactions received from a geographical location, travel route data, and travel itinerary data.

6. The method of claim 1 , wherein the second data representing the second interactions with the digital resources include device attributes, wherein the device attributes include at least one of type of the client device, to type and version of an internet browsers installed on the client device or type and version of operating system installed on the client device.

7. The method of claim 1 , wherein the second data representing the second interactions with the digital resources include client specific attributes, wherein the client specific attributes include at least one of number of clicks within a predetermined time period, number of external links accessed within a predetermined time period, sign in credentials of the client device, or search history of the client device.

8. The method of claim 1 , wherein the second data representing the second interactions with the digital resources include network attributes, wherein the network attributes include at least one of speed of network connection used by the client device, or type of communication network used the client device.

9. The method of claim 1 , wherein the second data representing the second interactions with the digital resources include business attributes, wherein the business attributes include at least one of revenue generated, estimated travel requests, or currency selected.

10. A system comprising:

one or more memory devices storing instructions; and

one or more processors in communication with one or more hardware storage devices configured to execute the instructions to:

detect, over a network, first data representing first interactions by a client device with a digital resource hosted on a host system;

determine second data representing second interactions with digital resources, the second interactions satisfying conditions for an interaction to be authorized;

determine, based at least in part on the first data and the second data, a first confidence score, the first confidence score associated with:

a first reference confidence score indicating a first likelihood that the interaction is unauthorized; and

a second reference confidence score indicating additional verification is merited;

responsive to determining that the first confidence score satisfies a first confidence score threshold associated with the second reference confidence score, receive third data representing third interactions by the client device, the third interactions comprising a) one or more interactions with at least one of a CAPTCHA or the digital resource and b) interactions differing from the first interactions;

determine a second confidence score based at least in part on the third data and the second data;

based at least in part on the second confidence score satisfying a second confidence threshold associated with the first reference confidence score, detecting unauthorized scraping of the digital resource; and

limit access of the client device to the digital resource.

11. The system of claim 10 , wherein the first interactions include receiving a plurality of requests, by the client device, associated with a travel reservation.

12. The system of claim 10 , wherein the second interactions with the digital resources are collected over a period of time, the second interactions include at least one of time attributes, location attributes, device attributes, client specific attributes, network attributes, or business attributes.

13. The system of claim 10 , wherein the second data representing the second interactions with the digital resources include time attributes, wherein the time attributes include at least one of session duration, time zone of the first interactions, time spent interacting with the digital resource, number of times the digital resource was accessed within a predetermined time period, number of travel requests received within a predetermined time period or travel schedule data.

14. The system of claim 10 , wherein the second data representing the second interactions with the digital resources include location attributes, wherein the location attributes include geographical location of a source of the first interactions, number of interactions received from a geographical location, travel route data, and travel itinerary data.

15. The system of claim 10 , wherein the second data representing the second interactions with the digital resources include device attributes, wherein the device attributes include at least one of type of the client device, to type and version of an internet browsers installed on the client device or type and version of operating system installed on the client device.

16. The system of claim 10 , wherein the second data representing the second interactions with the digital resources include client specific attributes, wherein the client specific attributes include at least one of number of clicks within a predetermined time period, number of external links accessed within a predetermined time period, sign in credentials of the client device, or search history of the client device.

17. The system of claim 10 , wherein the second data representing the second interactions with the digital resources include network attributes, wherein the network attributes include at least one of speed of network connection used by the client device, or type of communication network used the client device.

18. The system of claim 10 , wherein the second data representing the second interactions with the digital resources include business attributes, wherein the business attributes include at least one of revenue generated, estimated travel requests, or currency selected.

19. A non-transitory computer-readable medium storing instructions executable by one or more processors to perform operations for limiting access to a digital resource based on detection of unauthorized scraping of the digital resource, the operations comprising:

detecting, over a network, first data representing first interactions by a client device with a digital resource hosted on a host system;

determining second data representing second interactions with digital resources, the second interactions satisfying conditions for an interaction to be authorized;

determining, based at least in part on the first data and the second data, a first confidence score, the first confidence score associated with:

a first reference confidence score indicating a first likelihood that the interaction is unauthorized; and

a second reference confidence score indicating additional verification is merited;

responsive to determining that the first confidence score satisfies a first confidence score threshold associated with the second reference confidence score, receiving third data representing third interactions by the client device, the third interactions comprising a) one or more interactions with at least one of a CAPTCHA or the digital resource and b) interactions differing from the first interactions;

determining a second confidence score based at least in part on the third data and the second data;

based at least in part on the second confidence score satisfying a second confidence threshold associated with the first reference confidence score, detecting unauthorized scraping of the digital resource; and

limiting access of the client device to the digital resource.

20. The non-transitory computer-readable medium of claim 19 , wherein the second interactions with the digital resource include at least one of time attributes, location attributes, device attributes, client specific attributes, network attributes, or business attributes, the operations further comprising:

in response to determining the second interactions satisfy conditions for an interaction to be authorized, updating a database configured to store the second interactions such that the database stores recent authorized second interactions.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 16, 2024
From: KELLER, MATTHIAS GUNTHER; FEDOTOV, ALEXEI BORISOVICH; PRAKAITIS, DARIUS; RASCIUS, ALGIRDAS
To: KAYAK SOFTWARE CORPORATION
Reel/Frame 067432/0190 →
Continuity (1)
Continuation 17217733 · Mar 30, 2021
References Cited (16)
US 10178114B2 · Safruti · 2019 [cited by applicant]
US 10187394B2 · Bar · 2019 [cited by examiner]
US 10270792B1 · Shemesh · 2019 [cited by applicant]
US 10447711B2 · Kaminsky · 2019 [cited by applicant]
US 20160260182A1 · Garman · 2016 [cited by examiner]
US 20160359857A1 · Demirjian · 2016 [cited by examiner]
US 20170223049A1 · Kuperman · 2017 [cited by applicant]
US 20180350035A1 · Li · 2018 [cited by examiner]
US 20190005389A1 · Glyman · 2019 [cited by examiner]
US 20190102078A1 · Bhatt · 2019 [cited by applicant]
US 20190334940A1 · Bar Noy · 2019 [cited by examiner]
US 20190356684A1 · Sinha · 2019 [cited by applicant]
US 20210400065A1 · Herley · 2021 [cited by examiner]
US 20220301088A1 · Vemury · 2022 [cited by examiner]
WO WO2018071881A1 · 2018 [cited by applicant]
Office Action for U.S. Appl. No. 17/217,733, mailed on Sep. 8, 2023, Matthias Günther Keller, “Automated Bot Blocking”, 20 pages. [cited by applicant]