Access Point Fraud Detection via Traffic Flow Comparison
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current mechanisms are ineffective in detecting and preventing fraud that exploits IP flow rebound mechanisms in telecommunications networks, particularly where hackers use software to usurp user identities and access services without the user's consent.
Innovation Solution
Implementing a monitoring method at access points that analyzes data flows using an address association table to detect similarities in incoming and outgoing traffic patterns, allowing for the identification of potentially fraudulent activities by comparing characteristics such as application protocols, packet numbers, and periodicity, and taking corrective actions such as deleting suspicious entries or notifying users.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional firewall and parental control mechanisms are used, then basic network security is provided, but they are ineffective against IP flow rebound fraud
Solution Approach 1:
The patent applies preliminary action by proactively monitoring and analyzing traffic flow characteristics before fraud can be executed. The system continuously compares incoming and outgoing flow patterns, packet sizes, and timing to detect suspicious rebound behavior in advance, enabling preventive rather than reactive security measures.
Solution Approach 2:
The patent introduces an intermediary monitoring system that sits between the firewall and the network traffic. This intermediary layer analyzes flow characteristics and acts as a mediator that can block suspicious traffic while allowing legitimate traffic to pass through, enhancing security without replacing existing firewall mechanisms.
2Measurement precision
If detailed traffic analysis is performed to detect fraud, then detection precision improves, but processing time and computational resources increase
Solution Approach 1:
The patent applies partial action by selectively analyzing only specific characteristics of traffic flows that are most indicative of fraud, such as packet size patterns, timing intervals, and flow direction ratios. Rather than performing complete deep packet inspection on all traffic, the system focuses on key metrics that provide sufficient detection precision with minimal processing overhead.
Solution Approach 2:
The patent changes parameters by monitoring multiple dynamic characteristics of traffic flows simultaneously, including packet size distribution, inter-arrival times, flow duration, and direction ratios. By adjusting and monitoring multiple parameters rather than relying on a single metric, the system achieves high detection precision while maintaining efficient processing through standardized measurement approaches.
3Measurement precision
If comprehensive flow characteristic monitoring is implemented, then fraud detection accuracy improves, but system resource consumption increases
Solution Approach 1:
The patent applies segmentation by dividing the monitoring task into distinct functional modules: flow characteristic extraction, pattern comparison, anomaly detection, and response generation. Each module handles specific aspects of analysis independently, allowing the system to achieve comprehensive monitoring accuracy while optimizing resource usage through modular, efficient processing of each segment.
Data Source
Figure 1~2
Figure 3~4
Figure 5
AI summary
The invention relates to a monitoring method implemented by an access point for a network that can maintain an address association table, and comprises: a step (F20) of selecting at least two entries in the address association table; a step (F30) of storing at least one predetermined characteristic obtained over a predefined period of time for each inflow and each outflow associated with the selected entries; a step (F40) of comparing, for at least one pair of selected entries, at least one stored characteristic for an inflow associated with one of the entries of the pair with said at least one corresponding stored characteristic for an outflow associated with the other entry of the pair; and if, for at least one pair of entries, the comparison step indicates that an inflow associated with one of the entries of the pair transports an application content of the same nature as an outflow associated with the other entry of the pair, a step (F70) of detecting a risk of fraud.