Gateway Packet Marking for Fraud Detection and Resource Optimization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current gateway technologies fail to effectively detect fraudulent behavior by local network terminals, such as generating voice over IP calls without proper protocol usage or evading authentication, leading to unauthorized access and resource consumption.
Innovation Solution
Implementing a traffic differentiation method where the gateway inserts marking information into packet headers to distinguish between packets generated by itself and those generated by local network terminals, allowing devices to process packets based on their origin and apply appropriate security measures.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the gateway routes all packets without differentiation, then network throughput is maintained, but fraudulent behavior cannot be detected
Solution Approach 1:
The gateway performs preliminary marking of packets at the source before they enter the network. By inserting identification information into packet headers at the gateway level, the system enables downstream devices to detect and respond to fraudulent behavior without requiring complex analysis at each network node.
Solution Approach 2:
The patent introduces an intermediary marking mechanism that bridges the gateway and network security functions. The marking information acts as a mediator that carries identification data through the network, enabling security devices to distinguish between legitimate and fraudulent packets without requiring the gateway to perform complex real-time analysis.
2Measurement precision
If marking information is inserted into every packet header, then packet origin identification is achieved, but processing overhead increases
Solution Approach 1:
The patent segments the packet identification function from the packet forwarding function. By separating the marking operation (performed by the gateway) from the identification operation (performed by receiving devices), the system achieves precise packet origin identification without requiring every device to perform complex analysis on every packet.
Solution Approach 2:
The gateway creates a simplified copy of identification information in the packet header rather than performing complex real-time analysis. This copying approach allows receiving devices to quickly extract and process identification data without significant time penalties.
3Reliability
If the gateway monitors all terminal traffic, then fraudulent activities are detected, but memory and calculation resources are consumed
Solution Approach 1:
The patent extracts the identification function from the gateway's core processing workload. By inserting simple marking information into packet headers rather than performing complex traffic analysis, the gateway achieves fraud detection capability without consuming significant memory or calculation resources.
Solution Approach 2:
The marking information serves as a lightweight, disposable identifier that can be quickly inserted and processed without requiring long-term storage or complex computation. This approach enables fraud detection while minimizing resource consumption at the gateway.
Data Source
Figure 1
Figure 2
Figure 3~4
AI summary
The method for differentiating traffic, implemented by the gateway (BX, Tcx) between a first (LAN) and a second (NET1) network, comprises the steps of: - inserting (E300, F300) a piece of marking information (iMRK1, iMRK2) into a label field of a packet (P, Q) transmitted by this gateway and intended to be routed to the second network (NET1) in order to differentiate whether: - the packet (Q) has been generated (F200) by the gateway, or whether - the packet (P) has been generated (E100) by a terminal (TRM) of the first network (LAN) connected to the gateway; and - sending (E400, F400) the packet (P, Q) to the second network (NET1).