Lawful Interception Adulteration Detection and Correction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for detecting adulterated packets in communication networks fail to provide real-time detection and correction, especially when adulteration occurs at the network or higher layers, and do not comply with legal and regulatory requirements without using probe packets.

Innovation Solution

A method and system for performing lawful interception that detects adulteration in communication data by comparing adulteration parameters with thresholds, analyzes the feasibility of correcting adulterated content based on predefined criteria, and selectively corrects the content in real-time using network devices, which can adapt thresholds based on feedback for future communication sessions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional offline analysis methods are used to detect adulterated packets, then detection can be performed with simple mechanisms, but real-time detection capability is lost and TCP-only support limits versatility

Engineering Contradiction:
Improvedetection accuracyVSAvoidreal-time detection capability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary actions by pre-configuring multiple protocol-specific detection mechanisms (TCP, UDP, ICMP, HTTP, HTTPS, FTP, SMTP) before adulteration occurs. Each protocol has its own validation rules ready to be applied immediately when packets arrive, enabling real-time detection without requiring offline analysis

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system changes parameters by implementing protocol-specific detection parameters for different communication protocols. Instead of using a single generic detection method, it adapts detection parameters to match each protocol's characteristics (e.g., TCP sequence numbers, UDP port validation, HTTP header checking), thereby achieving both real-time detection and broad protocol support

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If CDF sensitivity is enhanced to collect all information for detection, then detection capability improves, but device complexity increases and probe packets are required

Engineering Contradiction:
Improvedetection sensitivityVSAvoidnetwork node complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system extracts only the essential validation rules and parameters needed for each protocol from the complex set of all possible network information. Instead of collecting and analyzing all network data, it selectively extracts and applies only the specific rules relevant to detecting adulteration in each protocol type, thereby maintaining high detection sensitivity while reducing complexity

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system uses disposable, protocol-specific validation rules that are lightweight and easy to apply. Each protocol has its own set of simple validation criteria that can be quickly checked and discarded, rather than maintaining complex, long-lived detection mechanisms. This approach achieves high detection precision without requiring complex network nodes or probe packets

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Loss of information

If adulterated packets are removed based on offline analysis, then data integrity improves, but the method is not suitable for online real-time detection

Engineering Contradiction:
Improvedata integrityVSAvoidreal-time processing capability
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The system ensures continuity of useful action by implementing continuous real-time validation of packets as they pass through the network. Instead of periodic offline analysis, the protocol-specific detection mechanisms operate continuously on every packet, maintaining both data integrity and real-time processing capability simultaneously

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The system performs preliminary validation actions on packets before they are forwarded or processed further. By applying protocol-specific rules in advance during real-time packet processing, it prevents adulterated packets from propagating while maintaining continuous operation and real-time performance

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3151469B1Methods and systems for performing lawful interception in communication networks
Publication Date: 2020.07.15 WIPRO LTD
  • EP3151469B1 patent drawingFigure 1
  • EP3151469B1 patent drawingFigure 2
  • EP3151469B1 patent drawingFigure 3

AI summary

This disclosure relates generally to lawful interception and more particularly to methods and systems for lawful interception. In one embodiment, a method for lawful interception in a communication network is disclosed. The method includes detecting in real-time, via at least one network device, adulteration in communication data based on comparison of a set of adulteration parameters derived from the communication data with associated thresholds within a set of thresholds. The method further includes analyzing, via the at least one network device, adulterated content in the communication data to determine feasibility of correcting the adulterated content based on satisfaction of predefined criteria. Moreover, the method includes correcting, selectively, the adulterated content based on satisfaction of the predefined criteria.