MAC Layer Profiling for Rogue Device Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current approaches for detecting malicious devices in wireless networks, such as rogue or compromised IoT devices, are suboptimal due to reliance on device-level profiling without utilizing radio interface profiling, and fail to effectively identify static attackers using mobility data.
Innovation Solution
The method employs machine learning to derive activity profiles from Medium Access Control (MAC) layer data, creating co-occurrence and eigen matrices to identify abnormal behavior, enabling detection of malicious devices by analyzing deviations from normal interactions and traffic patterns.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Difficulty of detecting and measuring
If device-level profiling techniques are used to detect malware activity, then detection capability is improved, but detection accuracy deteriorates because radio interface profiling is not utilized
Solution Approach 1:
The patent combines device-level profiling with radio interface profiling by analyzing MAC layer protocol sequences alongside traditional device usage patterns. This merging of profiling approaches at different layers enables both detection capability improvement and accuracy enhancement, as the system now evaluates multiple dimensions of device behavior simultaneously.
Solution Approach 2:
The patent introduces a new dimension of analysis by examining radio interface protocol sequences at the MAC layer, which was previously unutilized. This dimensional expansion from device-level to radio interface-level profiling provides additional features for machine learning models, thereby improving both detection capability and accuracy.
2Difficulty of detecting and measuring
If mobility data is used to detect spoofed devices, then detection capability is improved, but detection accuracy deteriorates because static attackers cannot be detected
Solution Approach 1:
The patent changes the detection parameters from mobility-based patterns to radio interface protocol sequence patterns. By analyzing the sequence and timing of MAC layer protocol messages, the system can detect both mobile and static attackers, as the protocol sequence analysis remains valid regardless of device mobility status.
3Device complexity
If traditional voice and Mobile Broadband services are used, then network simplicity is maintained, but network versatility deteriorates due to lack of support for new deployment scenarios
Solution Approach 1:
The patent implements a universal activity profiling system that can detect various types of malicious devices across multiple service types and deployment scenarios. The machine learning model trained on MAC layer protocol sequences from FWA, Automotive, and Industry 4.0 scenarios enables the network to maintain simplicity while achieving versatility through a single, unified detection framework.
Data Source
AI summary
A method is performed by a network node for training of machine-learned models for detection of abnormal User Equipment, UE, behavior. The method comprises obtaining training data comprising a plurality of interaction logs for a respective plurality of training UEs and clustering each of the interaction logs of the training data into one or more activity clusters with a machine-learned behavior analysis model to learn one or more activities associated with at least one of the one or more activity clusters.


