Dynamic Geo-Location Obfuscation Detection via Payload Fingerprinting

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for detecting fraudulent geo-location obfuscation through IP tunneling rely on static lists of IP addresses, which are inaccurate and outdated, failing to effectively differentiate between legitimate and fraudulent connections in real-time.

Innovation Solution

A dynamic detection method that uses payload size fingerprinting and round trip time analysis to identify IP tunneling, assessing the risk of fraudulent connections by comparing current connection metrics against benchmark values stored in databases, without relying on stateful firewalls or static lists.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If static lists of IP addresses are used for detection, then implementation simplicity is improved, but detection accuracy and reliability deteriorate over time due to outdated information

Engineering Contradiction:
Improveimplementation simplicityVSAvoiddetection accuracy
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The system transitions from static IP address lists to dynamic detection using stateless firewalls that analyze connection characteristics in real-time. The firewall evaluates multiple parameters including payload size, round trip time, and connection patterns without relying on pre-configured IP databases, enabling the system to adapt to new tunneling methods as they emerge.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The invention changes the detection parameters from static IP address matching to dynamic analysis of connection characteristics such as payload size fingerprints, round trip time variations, and TCP handshake patterns. This parameter transformation enables continuous detection accuracy without requiring updates to IP address databases.

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If conventional TCP connection detection is used, then ease of operation is improved, but detection capability deteriorates against IP tunneling obfuscation

Engineering Contradiction:
Improvedetection simplicityVSAvoidtunneling detection capability
Core Design Contradiction:
Ease of operationVSDifficulty of detecting and measuring

Solution Approach 1:

The system moves detection from the traditional TCP connection layer to additional dimensions including payload size analysis, round trip time measurement, and connection pattern evaluation. By analyzing connections across multiple dimensional parameters rather than just TCP handshake presence, the system achieves superior tunneling detection while maintaining operational simplicity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If real-time dynamic detection is implemented, then detection accuracy is improved, but computational complexity and resource usage increase

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The stateless firewall performs self-service detection by automatically evaluating connection characteristics without requiring external IP address databases or manual updates. The system independently analyzes payload sizes, measures round trip times, and compares patterns against embedded benchmarks, reducing operational complexity while maintaining high detection accuracy.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10659491B2Dynamic detection of geo-location obfuscation in of internet devices
Publication Date: 2020.05.19 PAYPAL INC
  • US10659491B2 patent drawing
  • US10659491B2 patent drawing
  • US10659491B2 patent drawing

AI summary

Methods and systems are disclosed for dynamic detection of geo-location spoofing by a networked device, such as fraudulent client connections to a server, in which the connection is made using an internet protocol (IP) tunneling as may be provided by a virtual private network (VPN) connection. A user of a client device may employ spoofing of IP-geo location mechanisms and IP classification for various reasons, such as gaining access to services that are not allowed in certain locations (e.g., certain movie and television content providers); browsing server data while maintaining a higher level of anonymity; and performing fraudulent actions on the server. Detecting a false geographic location (e.g. as indicated by IP address) is helpful for improving computer system security, and for evaluating whether access to particular digital resources should be provided.