Mobile Traffic Classification via Domain Name Probabilistic Models

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Securing mobile networks against malicious attacks and inefficient resource usage is challenging due to the large number of mobile software applications and the inability of existing methods to accurately identify specific applications causing security or performance issues, especially in large-scale networks.

Innovation Solution

A probabilistic model based on domain names is used to classify mobile traffic, allowing for efficient identification of mobile software applications and remedial actions, without the need for detailed packet inspection across large networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If detailed packet inspection is performed to identify mobile software applications, then measurement precision is improved, but device complexity and processing overhead increase significantly

Engineering Contradiction:
Improveapplication identification accuracyVSAvoidinspection system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent extracts only the essential identifying feature (domain names) from the complete packet data, avoiding the need to inspect entire packets. This selective extraction maintains application identification accuracy while dramatically reducing processing complexity and overhead.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent creates a simplified representation (copy) of application behavior through domain name patterns rather than analyzing complete packet contents. This copy captures the essential identifying characteristics while avoiding the computational burden of full packet inspection.

Inventive Principle:
Principle #26Copying

2Reliability

If comprehensive traffic analysis is performed across all mobile applications, then reliability of security detection is improved, but productivity of network operations decreases due to processing time

Engineering Contradiction:
Improvesecurity threat detection accuracyVSAvoidnetwork processing throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts only the critical domain name information from traffic packets, discarding redundant data. This extraction maintains the ability to reliably identify applications and detect security threats while significantly improving processing throughput and network productivity.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies partial action by focusing only on the necessary portion of packet data (domain names) rather than performing exhaustive analysis of all packet contents. This partial approach maintains sufficient reliability for security detection while dramatically improving processing speed and productivity.

Inventive Principle:
Principle #16Partial or excessive action

3Loss of information

If probabilistic modeling based on domain names is used to classify mobile traffic, then loss of information is reduced in identifying applications, but measurement precision may be compromised compared to full packet inspection

Engineering Contradiction:
Improveapplication identification completenessVSAvoidclassification accuracy
Core Design Contradiction:
Loss of informationVSMeasurement precision

Solution Approach 1:

The patent creates a probabilistic model that copies the essential behavioral patterns of applications through domain name usage. This model captures sufficient information to accurately classify applications while avoiding the need to process complete packet data, thus reducing information loss without significantly compromising precision.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent changes the parameter of analysis from complete packet contents to specific domain name patterns. This parameter change reduces the dimensionality of data required while maintaining classification accuracy through probabilistic modeling of application behavior patterns.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10938844B2Providing security through characterizing mobile traffic by domain names
Publication Date: 2021.03.02 AT&T INTELLECTUAL PROPERTY I L P
  • US10938844B2 patent drawing
  • US10938844B2 patent drawing
  • US10938844B2 patent drawing

AI summary

A method, computer-readable medium, and apparatus for classifying mobile traffic for securing a network or a mobile user endpoint device are disclosed. For example, a method may include a processor for classifying mobile network traffic using a probabilistic model for a plurality of mobile software applications based on a distribution of domain names, detecting an anomaly associated with a mobile software application of the plurality of mobile software applications, and performing a remedial action to address the anomaly.