MAC Layer Profiling for Rogue Device Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current approaches for detecting malicious devices in wireless networks, such as rogue or compromised IoT devices, are suboptimal due to reliance on device-level profiling without utilizing radio interface profiling, and fail to effectively identify static attackers using mobility data.

Innovation Solution

The method employs machine learning to derive activity profiles from Medium Access Control (MAC) layer data, creating co-occurrence and eigen matrices to identify abnormal behavior, enabling detection of malicious devices by analyzing deviations from normal interactions and traffic patterns.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Difficulty of detecting and measuring

If device-level profiling techniques are used to detect malware activity, then detection capability is improved, but detection accuracy deteriorates because radio interface profiling is not utilized

Engineering Contradiction:
Improvedetection capabilityVSAvoiddetection accuracy
Core Design Contradiction:
Difficulty of detecting and measuringVSMeasurement precision

Solution Approach 1:

The patent combines device-level profiling with radio interface profiling by analyzing MAC layer protocol sequences alongside traditional device usage patterns. This merging of profiling approaches at different layers enables both detection capability improvement and accuracy enhancement, as the system now evaluates multiple dimensions of device behavior simultaneously.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces a new dimension of analysis by examining radio interface protocol sequences at the MAC layer, which was previously unutilized. This dimensional expansion from device-level to radio interface-level profiling provides additional features for machine learning models, thereby improving both detection capability and accuracy.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Difficulty of detecting and measuring

If mobility data is used to detect spoofed devices, then detection capability is improved, but detection accuracy deteriorates because static attackers cannot be detected

Engineering Contradiction:
Improvedetection capabilityVSAvoiddetection accuracy
Core Design Contradiction:
Difficulty of detecting and measuringVSMeasurement precision

Solution Approach 1:

The patent changes the detection parameters from mobility-based patterns to radio interface protocol sequence patterns. By analyzing the sequence and timing of MAC layer protocol messages, the system can detect both mobile and static attackers, as the protocol sequence analysis remains valid regardless of device mobility status.

Inventive Principle:
Principle #35Parameter changes

3Device complexity

If traditional voice and Mobile Broadband services are used, then network simplicity is maintained, but network versatility deteriorates due to lack of support for new deployment scenarios

Engineering Contradiction:
Improvenetwork simplicityVSAvoidnetwork versatility
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent implements a universal activity profiling system that can detect various types of malicious devices across multiple service types and deployment scenarios. The machine learning model trained on MAC layer protocol sequences from FWA, Automotive, and Industry 4.0 scenarios enables the network to maintain simplicity while achieving versatility through a single, unified detection framework.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20240334193A1Systems and methods for machine learned network activity profiling of devices
Publication Date: 2024.10.03 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US20240334193A1 patent drawing
  • US20240334193A1 patent drawing
  • US20240334193A1 patent drawing

AI summary

A method is performed by a network node for training of machine-learned models for detection of abnormal User Equipment, UE, behavior. The method comprises obtaining training data comprising a plurality of interaction logs for a respective plurality of training UEs and clustering each of the interaction logs of the training data into one or more activity clusters with a machine-learned behavior analysis model to learn one or more activities associated with at least one of the one or more activity clusters.