Telecommunications Network Malicious Behavior Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for detecting malicious behavior in mobile telecommunications devices are inadequate as they rely solely on the device itself, raising concerns about the trustworthiness of detection when the device is infected with malware, and fail to effectively identify malware-induced excessive network resource usage from within the telecommunications network.
Innovation Solution
A system within the telecommunications network monitors data streams for excessive occurrences of specific signals indicative of malicious behavior, such as frequent authentication requests, continuous attach and detach, and unusual service requests, using counters and timers to detect and register when these exceed predetermined thresholds, allowing for the identification of potentially infected devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If detection is performed entirely within the mobile device itself, then the device can autonomously detect malicious behavior, but the detection cannot be trusted when the device is infected with malware
Solution Approach 1:
The patent introduces the telecommunications network as an intermediary between the mobile device and the detection process. The network monitors signaling data streams generated by the device, allowing detection to occur externally rather than within the potentially compromised device itself. This resolves the contradiction by maintaining autonomous detection capability while eliminating the trust issue through external observation of the device's signaling behavior.
2Reliability
If the network monitors signaling data streams to detect malicious behavior, then the network can identify infected devices, but network resources are consumed by monitoring and processing
Solution Approach 1:
The patent implements a mechanism where the mobile device itself generates the signaling data streams that are monitored by the network. The device's normal operations create authentication requests, attach/detach signals, and service requests that naturally reveal malicious behavior patterns. The network merely observes these self-generated signals rather than actively probing the device, reducing network resource consumption while maintaining detection accuracy.
Solution Approach 2:
The network monitors only specific signaling data streams that are indicative of malicious behavior (authentication requests, attach/detach sequences, service requests) rather than all network traffic. This selective monitoring approach allows the network to detect infections with minimal resource consumption by focusing only on the most relevant signaling patterns.
3Reliability
If the network monitors for excessive occurrences of specific signals, then malicious behavior can be detected, but false positives may occur from legitimate high-activity devices
Solution Approach 1:
The patent employs dynamic threshold adjustment and temporal analysis of signaling patterns. Instead of using fixed thresholds, the system analyzes the rate of occurrence, timing patterns, and sequences of signaling events. Legitimate high-activity devices exhibit predictable patterns, while malware-induced activity shows anomalous temporal characteristics. This dynamic approach allows accurate differentiation between legitimate and malicious behavior, reducing false positives while maintaining detection reliability.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A system is provided for detecting behaviour of a mobile telecommunications device in a telecommunications network. Malware in mobile devices can cause malicious behaviour in the device, for example sequential attaching and detaching of an infected device relative to a telecommunications network. A telecommunications network is provided which is configured to identify at least one mobile telecommunications device and to receive signals from the mobile telecommunications device and process the signals into data streams. The data streams include data of a first type arranged to cause an event of a first type within the telecommunications network. The network is arranged to monitor an occurrence in the data streams of the data of the first type and to register when the occurrence exceeds a level indicating acceptable behaviour of the mobile telecommunications device in the telecommunications network.A device for detection of mobile device behaviour is also described.