Correlating Security Events with Subscriber Data in Mobile Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security solutions in mobile networks lack the ability to efficiently correlate malware attacks with specific subscriber devices, limiting administrators' capacity to identify and remediate problematic devices effectively.

Innovation Solution

A communication system that receives subscriber accounting packets, maps network addresses to subscriber device information, and correlates security events with subscriber data, enabling the identification of specific devices associated with security incidents through a mapping table and deep packet inspection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network security solutions are implemented in mobile networks, then security monitoring capability is improved, but the ability to correlate security events with specific subscriber devices deteriorates

Engineering Contradiction:
Improvesecurity monitoring capabilityVSAvoidcorrelation between security events and subscriber devices
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces a mapping table as an intermediary data structure that correlates network addresses with subscriber device information. This mapping table acts as a mediator between the security monitoring system and subscriber data, enabling the system to associate security events with specific subscribers without directly accessing subscriber databases, thus resolving the contradiction between security monitoring capability and information correlation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If subscriber device information is stored and mapped, then the ability to identify specific devices is improved, but system complexity increases

Engineering Contradiction:
Improvedevice identification accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the system into distinct functional components: a mapping table for storing correlations between network addresses and subscriber information, a deep packet inspection engine for detecting security events, and a correlation module for matching events with subscriber data. This segmentation allows each component to perform its specific function independently, improving device identification accuracy while managing system complexity through modular architecture.

Inventive Principle:
Principle #1Segmentation

3Reliability

If deep packet inspection is performed on all subscriber data traffic, then security event detection is improved, but processing time and resources increase

Engineering Contradiction:
Improvesecurity event detectionVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by pre-establishing the mapping table that correlates network addresses with subscriber device information before security event detection occurs. This pre-processing allows the deep packet inspection engine to quickly match detected events with subscriber data without performing complex correlations in real-time, thus improving security event detection while reducing processing time.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9338657B2System and method for correlating security events with subscriber information in a mobile network environment
Publication Date: 2016.05.10 MCAFEE LLC

AI summary

A method is provided in one example embodiment and includes receiving a subscriber accounting start packet for a subscriber device in a mobile network environment. The method also includes extracting, from the subscriber accounting start packet, subscriber device information and a network address of the subscriber device. The method further includes mapping the network address to the subscriber device information, and then correlating the subscriber device information and a security event when the security event is detected in subscriber data network traffic associated with the subscriber device. In a specific embodiment, the subscriber device information includes at least one of an International Mobile Equipment Identity (IMEI), an International Mobile Subscriber Identity (IMSI), a Mobile Station International Subscriber Directory Number (MSISDN), and an access point name (APN). In further embodiments, an identification of the security event and one or more items of the subscriber device information are provided to a user.