Telecommunications Network Malicious Behavior Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for detecting malicious behavior in mobile telecommunications devices are inadequate as they rely solely on the device itself, raising concerns about the trustworthiness of detection when the device is infected with malware, and fail to effectively identify malware-induced excessive network resource usage from within the telecommunications network.

Innovation Solution

A system within the telecommunications network monitors data streams for excessive occurrences of specific signals indicative of malicious behavior, such as frequent authentication requests, continuous attach and detach, and unusual service requests, using counters and timers to detect and register when these exceed predetermined thresholds, allowing for the identification of potentially infected devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If detection is performed entirely within the mobile device itself, then the device can autonomously detect malicious behavior, but the detection cannot be trusted when the device is infected with malware

Engineering Contradiction:
Improveautonomous detection capabilityVSAvoidtrustworthiness of detection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces the telecommunications network as an intermediary between the mobile device and the detection process. The network monitors signaling data streams generated by the device, allowing detection to occur externally rather than within the potentially compromised device itself. This resolves the contradiction by maintaining autonomous detection capability while eliminating the trust issue through external observation of the device's signaling behavior.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the network monitors signaling data streams to detect malicious behavior, then the network can identify infected devices, but network resources are consumed by monitoring and processing

Engineering Contradiction:
Improvedetection accuracyVSAvoidnetwork resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent implements a mechanism where the mobile device itself generates the signaling data streams that are monitored by the network. The device's normal operations create authentication requests, attach/detach signals, and service requests that naturally reveal malicious behavior patterns. The network merely observes these self-generated signals rather than actively probing the device, reducing network resource consumption while maintaining detection accuracy.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The network monitors only specific signaling data streams that are indicative of malicious behavior (authentication requests, attach/detach sequences, service requests) rather than all network traffic. This selective monitoring approach allows the network to detect infections with minimal resource consumption by focusing only on the most relevant signaling patterns.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If the network monitors for excessive occurrences of specific signals, then malicious behavior can be detected, but false positives may occur from legitimate high-activity devices

Engineering Contradiction:
Improvemalware detection capabilityVSAvoidbehavior classification accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent employs dynamic threshold adjustment and temporal analysis of signaling patterns. Instead of using fixed thresholds, the system analyzes the rate of occurrence, timing patterns, and sequences of signaling events. Legitimate high-activity devices exhibit predictable patterns, while malware-induced activity shows anomalous temporal characteristics. This dynamic approach allows accurate differentiation between legitimate and malicious behavior, reducing false positives while maintaining detection reliability.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP2923511B1System to detect behaviour in a telecommunications network
Publication Date: 2021.04.21 KONINK KPN NV
  • EP2923511B1 patent drawingFigure 1
  • EP2923511B1 patent drawingFigure 2
  • EP2923511B1 patent drawingFigure 3

AI summary

A system is provided for detecting behaviour of a mobile telecommunications device in a telecommunications network. Malware in mobile devices can cause malicious behaviour in the device, for example sequential attaching and detaching of an infected device relative to a telecommunications network. A telecommunications network is provided which is configured to identify at least one mobile telecommunications device and to receive signals from the mobile telecommunications device and process the signals into data streams. The data streams include data of a first type arranged to cause an event of a first type within the telecommunications network. The network is arranged to monitor an occurrence in the data streams of the data of the first type and to register when the occurrence exceeds a level indicating acceptable behaviour of the mobile telecommunications device in the telecommunications network.A device for detection of mobile device behaviour is also described.