Network Authentication Counter for Mobile Traffic Anomaly Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current mobile terminals are vulnerable to viruses that can lead to abnormal behavior, such as uncontrollable SMS transmission and resource consumption, causing financial and operational issues in radiocommunication networks, necessitating rapid detection and mitigation of such anomalies.
Innovation Solution
A method that collaborates with the radiocommunication network's location register to monitor and detect traffic anomalies, using authentication counters and alert messages to identify and address abnormal behavior, including the possibility of virus infections, allowing for quick reactive measures to minimize adverse effects.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If mobile terminals implement complex operating systems with increased functionality, then the versatility and capability of the terminal improve, but the vulnerability to virus infections and malicious attacks increases
Solution Approach 1:
The patent introduces an intermediary detection system consisting of network elements (GGSN, SGSN, HLR) that monitor authentication traffic between the mobile terminal and the network. This intermediary system detects abnormal authentication patterns caused by viruses without requiring changes to the terminal's operating system, thus maintaining terminal versatility while mitigating virus threats through network-side monitoring
2Measurement precision
If the network monitors traffic from each mobile terminal to detect anomalies, then the detection precision improves, but the complexity of the network system increases
Solution Approach 1:
The patent merges the anomaly detection functionality into existing network elements (GGSN, SGSN, HLR) that are already part of the radiocommunication network infrastructure. By combining detection tasks with existing network functions rather than adding separate dedicated detection systems, the patent achieves precise monitoring of authentication traffic while minimizing additional system complexity
Solution Approach 2:
The network elements (particularly the HLR and authentication mechanisms) perform multiple functions: they authenticate legitimate users, manage subscriber data, and simultaneously detect abnormal authentication patterns caused by viruses. This multi-functionality allows precise anomaly detection without requiring dedicated single-purpose detection devices, thus reducing overall system complexity
3Loss of time
If the network rapidly detects and responds to abnormal behavior, then the loss of time is reduced, but the need for automated monitoring and response systems increases device complexity
Solution Approach 1:
The patent implements a feedback mechanism where network elements continuously monitor authentication requests and automatically compare them against established thresholds. When abnormal patterns are detected (e.g., excessive authentication failures or unusual traffic patterns), the system automatically generates alerts and can trigger blocking actions. This automated feedback loop enables rapid detection and response without requiring complex manual monitoring systems
Solution Approach 2:
The detection system leverages the existing self-service nature of authentication protocols. The network elements automatically perform detection, analysis, and response actions without external intervention. The system serves itself by using its own authentication infrastructure to detect anomalies and automatically initiate corrective measures, reducing the need for complex external monitoring apparatus
Data Source
Figure 1
Figure 2
AI summary
The method involves incrementing an authentication count (CA) assigned to a mobile terminal (TM), over a predetermined time interval, by an evaluation module (ME) of a warning device (DA) when security data (DS) are transmitted to an entity of a radiocommunication network (RR) e.g. Global System for Mobile communicationsnetwork, for authenticating the terminal. The authentication count is compared with a predefined threshold (SP) so as to detect an anomaly of traffic transmitted by the mobile terminal if the count exceeds the threshold. An independent claim is also included for a device communicating with a location register of a radiocommunication network for detecting an anomaly of traffic transmitted from a mobile terminal in the radiocommunication network.