Correlating Security Events with Subscriber Data in Mobile Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security solutions in mobile networks lack the ability to efficiently correlate malware attacks with specific subscriber devices, limiting administrators' capacity to identify and remediate problematic devices effectively.
Innovation Solution
A communication system that receives subscriber accounting packets, maps network addresses to subscriber device information, and correlates security events with subscriber data, enabling the identification of specific devices associated with security incidents through a mapping table and deep packet inspection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network security solutions are implemented in mobile networks, then security monitoring capability is improved, but the ability to correlate security events with specific subscriber devices deteriorates
Solution Approach 1:
The patent introduces a mapping table as an intermediary data structure that correlates network addresses with subscriber device information. This mapping table acts as a mediator between the security monitoring system and subscriber data, enabling the system to associate security events with specific subscribers without directly accessing subscriber databases, thus resolving the contradiction between security monitoring capability and information correlation.
2Measurement precision
If subscriber device information is stored and mapped, then the ability to identify specific devices is improved, but system complexity increases
Solution Approach 1:
The patent segments the system into distinct functional components: a mapping table for storing correlations between network addresses and subscriber information, a deep packet inspection engine for detecting security events, and a correlation module for matching events with subscriber data. This segmentation allows each component to perform its specific function independently, improving device identification accuracy while managing system complexity through modular architecture.
3Reliability
If deep packet inspection is performed on all subscriber data traffic, then security event detection is improved, but processing time and resources increase
Solution Approach 1:
The patent performs preliminary actions by pre-establishing the mapping table that correlates network addresses with subscriber device information before security event detection occurs. This pre-processing allows the deep packet inspection engine to quickly match detected events with subscriber data without performing complex correlations in real-time, thus improving security event detection while reducing processing time.
Data Source
AI summary
A method is provided in one example embodiment and includes receiving a subscriber accounting start packet for a subscriber device in a mobile network environment. The method also includes extracting, from the subscriber accounting start packet, subscriber device information and a network address of the subscriber device. The method further includes mapping the network address to the subscriber device information, and then correlating the subscriber device information and a security event when the security event is detected in subscriber data network traffic associated with the subscriber device. In a specific embodiment, the subscriber device information includes at least one of an International Mobile Equipment Identity (IMEI), an International Mobile Subscriber Identity (IMSI), a Mobile Station International Subscriber Directory Number (MSISDN), and an access point name (APN). In further embodiments, an identification of the security event and one or more items of the subscriber device information are provided to a user.