Mobile Traffic Redirection for Malware Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern mobile devices are vulnerable to malware infections, posing threats to users and mobile operators, and existing security measures struggle to provide comprehensive protection across millions of users due to the complexity and cost of full coverage.

Innovation Solution

A system that redirects mobile traffic from infected user equipment to a security network node, utilizing a mobility session management node, an intelligent redirection node, and a security network node to identify and isolate infected devices, inspect malicious traffic, and provide remedial actions such as quarantining or removing malware.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If full coverage security measures are deployed for all mobile users, then network security is improved, but operational cost and infrastructure complexity increase significantly

Engineering Contradiction:
Improvenetwork securityVSAvoidinfrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments mobile users into two groups: those suspected of being infected (redirected to security network node for inspection) and those not suspected (allowed normal access). This segmentation enables targeted security measures rather than universal deployment, reducing infrastructure complexity while maintaining security effectiveness.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism (security network node and redirection system) that acts as a mediator between suspected infected devices and the core network. This intermediary handles security inspection, allowing the core network to maintain simplicity while still providing comprehensive security coverage through the intermediary layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If comprehensive security inspection is performed on all mobile traffic, then malware detection capability is improved, but processing time and network latency increase

Engineering Contradiction:
Improvemalware detection capabilityVSAvoidnetwork latency
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs partial security inspection by only redirecting and inspecting traffic from devices suspected of being infected, rather than inspecting all mobile traffic. This partial action approach maintains malware detection capability for high-risk traffic while avoiding the time penalty of universal inspection, thus reducing network latency.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system skips security inspection for traffic from devices not suspected of being infected, allowing such traffic to pass through the network rapidly without inspection delays. This skipping mechanism maintains high detection capability for suspicious traffic while minimizing overall network latency by rushing through safe traffic.

Inventive Principle:
Principle #21Skipping (Rushing through)

Data Source

PatentUS10887768B2Mobile traffic redirection system
Publication Date: 2021.01.05 T MOBILE US INC
  • US10887768B2 patent drawing
  • US10887768B2 patent drawing
  • US10887768B2 patent drawing

AI summary

The systems, devices, and methods discussed herein are directed to redirecting mobile traffic of an infected mobile device, or user equipment (UE), to a security network node, which provides a security action for the UE. A mobile session management node may identify the UE as an infected device based on a database maintained at an intelligent redirection node or a security posture indicator received from the UE. The mobile management entity may then create a session with a security network node which redirects mobile traffic of the infected UE to the security network node and provides a security action for the UE.