IP Library › Granted Patent US 12,621,344
Granted Patent B2
US 12,621,344 · App. 18/678,578 · Granted May 5, 2026

Bot detection and mitigation using dynamic web flows built via machine learning

Inventor: Venkata Sai Kishore Modalavalasa (Santa Clara, CA)
Assignee: Akamai Technologies, Inc.
H04L63/1466H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,621,344
App. No.
18/678,578
Filed
May 30, 2024
Granted
May 5, 2026
Kind
B2
Art Unit
2436
USPC
726/23
Abstract

An overlay network bot detection service is augmented to include a content generation service that dynamically generates dummy web pages that are served (along with real site content) to a requesting user, This content is built using machine learning models trained on a target website's content, or that otherwise leverage generative AI to create site content that mimics the site's real content. The generated content is preferably built dynamically during an actual interaction session with the requesting user, is designed to “look” and “feel” like actual content of the website, and inclusion of the content acts to trap a requesting user's browser in one or more non-productive (fake) navigation loops within the site. This facilitates the overall bot detection because such content and such loops are not actually part of the real site, and thus the navigation of these unproductive pages is highly indicative of bot activity.

Claims (34)

1 . A method of protecting a website, comprising:

during an interaction with the website initiated by a requesting client:

serving a set of one or more first pages that constitute actual content of the website;

selectively serving a set of one or more second pages that differ from the set of one or more first pages in that the one or more second pages do not constitute the actual content of the website but are configured to appear to the requesting client as though the one or more second pages do constitute the actual content of the website, the one or more second pages having been built dynamically during the interaction and based at least in part on one or more machine learning content models associated with the website; and

based at least in part on receiving telemetry indicating navigation by the requesting client through the set of one or more second pages, characterizing the requesting client as a bot; and

taking a given mitigation action against the requesting client to protect the website.

2 . The method as described in claim 1 wherein the one or more machine learning content models comprises a set of models, wherein each of the set of models is trained on a category of content.

3 . The method as described in claim 2 , wherein the category of content is one of: text, images, page templates, and site metadata associated with site navigation.

4 . The method as described in claim 1 , wherein at least one second page of the set of one or more second pages has a page design that is generated based at least in part on a measure of visual similarity to at least a portion of a first page of the set of one or more first pages.

5 . The method as described in claim 1 , further including the one or more machine learning content models are trained out-of-band relative to the interaction.

6 . The method as described in claim 1 , wherein at least one machine learning content model of the one or more machine learning content models is built using generative-AI.

7 . The method as described in claim 1 , wherein at least one machine learning content model of the one or more machine learning content models is a neural network.

8 . The method as described in claim 7 , wherein the neural network is a graph neural network (GNN).

9 . The method as described in claim 1 , wherein at least one machine learning content model of the one or more machine learning content models is a model that has been updated out-of-band relative to the interaction.

10 . The method as described in claim 1 , wherein at least one machine learning content model of the one or more machine learning content models is trained on content of the website.

11 . The method as described in claim 1 , wherein the one or more first pages and the one or more second pages are served by an edge server of an overlay network.

12 . The method as described in claim 11 , wherein the given mitigation action is determined by a bot detection service associated with the overlay network.

13 . The method as described in claim 1 , wherein the requesting client is a page scrapper.

14 . The method as described in claim 1 , further including the website is configured for use without a captcha.

15 . The method as described in claim 1 , wherein the given mitigation action is one of: blocking an action requested by the requesting client, logging the interaction, issuing a notification, and tar-pitting or sand-boxing the requesting client.

16 . An apparatus configured to protect a website, comprising: one or more hardware processors;

computer memory holding computer program code executed by the one or more hardware processors, the computer program code configured during an interaction with the website initiated by a requesting client to:

serve a set of one or more first pages that constitute actual content of the website;

selectively serve a set of one or more second pages that differ from the set of one or more first pages in that the one or more second pages do not constitute the actual content of the website but are configured to appear to the requesting client as though the one or more second pages do constitute the actual content of the website, the one or more second pages having been built dynamically during the interaction and based at least in part on one or more machine learning content models associated with the website;

based at least in part on receiving telemetry indicating navigation by the requesting client through the set of one or more second pages, characterize the requesting client as a bot; and

take a given mitigation action against the requesting client to protect the website.

17 . The apparatus as described in claim 16 , wherein the given mitigation action is one of: blocking an action requested by the requesting client, logging the interaction, issuing a notification, and tar-pitting or sand-boxing the requesting client.

18 . A computer program product in a non-transitory computer-readable medium, the computer program product comprising computer program code executable by one or more hardware processors to protect a website, the computer program code configured during an interaction with the website initiated by a requesting client to:

serve a set of one or more first pages that constitute actual content of the website;

selectively serve a set of one or more second pages that differ from the set of one or more first pages in that the one or more second pages do not constitute the actual content of the website but are configured to appear to the requesting client as though the one or more second pages do constitute the actual content of the website, the one or more second pages having been built dynamically during the interaction and based at least in part on one or more machine learning content models associated with the website;

based at least in part on receiving telemetry indicating navigation by the requesting client through the set of one or more second pages, characterize the requesting client as a bot; and

take a given mitigation action against the requesting client to protect the website.

19 . The computer program product as described in claim 18 , wherein the given mitigation action is one of: blocking an action requested by the requesting client, logging the interaction, issuing a notification, and tar-pitting or sand-boxing the requesting client.

20 . The computer program product as described in claim 18 , wherein the given mitigation action is taken at an edge server of an overlay network.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 3, 2024
From: MODALAVALASA, VENKATA SAI KISHORE
To: AKAMAI TECHNOLOGIES, INC.
Reel/Frame 067590/0442 →
Continuity (1)
Related Publication 20250373655A1 · Dec 4, 2025
References Cited (27)
US 8806646B1 · Daswani et al. · 2014 [cited by applicant]
US 10587629B1 · Kurupati et al. · 2020 [cited by applicant]
US 10686818B2 · Kurupati · 2020 [cited by applicant]
US 10708281B1 · Modalavalasa · 2020 [cited by applicant]
US 11245722B1 · Senecal et al. · 2022 [cited by applicant]
US 11368483B1 · Senecal et al. · 2022 [cited by applicant]
US 11374945B1 · Senecal et al. · 2022 [cited by applicant]
US 11870804B2 · Kurupati · 2024 [cited by applicant]
US 12255916B2 · Costa et al. · 2025 [cited by applicant]
US 12316672B2 · Senecal et al. · 2025 [cited by applicant]
US 20100070620A1 · Awadallah et al. · 2010 [cited by applicant]
US 20160191554A1 · Kaminsky · 2016 [cited by examiner]
US 20170243003A1 · Rapaport et al. · 2017 [cited by applicant]
US 20180041527A1 · Call · 2018 [cited by examiner]
US 20180167412A1 · Barrett · 2018 [cited by examiner]
US 20190141057A1 · Burgis · 2019 [cited by applicant]
US 20200053121A1 · Wilcox · 2020 [cited by applicant]
US 20200396233A1 · Luo · 2020 [cited by examiner]
US 20210226987A1 · Summers et al. · 2021 [cited by applicant]
US 20220191241A1 · Vera-Schockner · 2022 [cited by applicant]
US 20230199023A1 · Kurupati · 2023 [cited by applicant]
US 20230224325A1 · Mautone · 2023 [cited by examiner]
US 20230336571A1 · Costa et al. · 2023 [cited by applicant]
KR 1020220078320A · 2022 [cited by applicant]
Fan et al (“HoneyDecoy: A Comprehensive Web-Based Parasitic Honeypot System for Enhanced Cybersecurity”, The 2023 IEEE International Conference on Privacy Computing and Data Security). (Year: 2023). [cited by examiner]
Lewandowski et al (“SpiderTrap—An Innovative Approach to Analyze Activity of Internet Bots on a Website”, IEEE Access, Special Section on Emerging Approaches to Cyber Security, 2020). (Year: 2020). [cited by examiner]
PCT/US2025/031528, International Search Report and Written Opinion, mailed Sep. 30, 2025, 9 pages. [cited by applicant]