SIM Fraud Detection via Log-Based Security Controller

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Subscriber identity modules (SIMs) are vulnerable to fraudulent attacks, leading to unauthorized access and misuse of user accounts, which can result in data breaches and unauthorized transactions, causing network congestion and degrading user experience in cellular networks.

Innovation Solution

Implementing a system that utilizes a security controller, logging tool, and fraud manager to analyze log information and identify malicious activities, preventing and mitigating fraud by intercepting and managing requests associated with malicious actors, thereby reducing network congestion and improving signal transmission quality.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security control measures are implemented to protect user accounts from fraudulent attacks, then user account security is improved, but system complexity increases

Engineering Contradiction:
Improveuser account securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security system is divided into distinct functional modules: a logging tool that collects fraud indicators, a security controller that analyzes requests against logged data, and a fraud manager that executes mitigation actions. This segmentation allows each component to perform its specific function efficiently while maintaining overall system security without excessive complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary actions by logging fraud indicators and building security profiles before actual fraudulent attacks occur. The logging tool continuously collects information about malicious actors, and the security controller uses this pre-established data to quickly identify and block fraudulent requests in real-time, improving response effectiveness without adding operational complexity during critical moments.

Inventive Principle:
Principle #10Preliminary action

2Object-affected harmful factors

If fraud detection and mitigation operations are performed, then fraudulent activities are reduced, but processing time increases

Engineering Contradiction:
Improvefraudulent activitiesVSAvoidprocessing time
Core Design Contradiction:
Object-affected harmful factorsVSLoss of time

Solution Approach 1:

The logging tool continuously pre-processes and logs fraud indicators, device information, and request patterns before attacks occur. This preliminary data collection and organization enables the security controller to perform rapid matching and identification of fraudulent requests without time-consuming analysis during critical security events.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system creates simplified copies of fraud indicators and security profiles from complex original data. The logging tool extracts key identifying features from fraudulent requests and stores them as compact reference patterns, allowing the security controller to quickly compare incoming requests against these simplified copies without processing the full complexity of original attack vectors.

Inventive Principle:
Principle #26Copying

3Measurement precision

If comprehensive logging and analysis of request information is performed, then fraud detection accuracy is improved, but network bandwidth consumption increases

Engineering Contradiction:
Improvefraud detection accuracyVSAvoidnetwork bandwidth consumption
Core Design Contradiction:
Measurement precisionVSLoss of energy

Solution Approach 1:

The logging tool extracts only the most critical and relevant features from request information, such as device identifiers, request patterns, and temporal characteristics, while discarding redundant data. This selective extraction maintains high fraud detection accuracy by focusing on discriminative features while significantly reducing the volume of data that needs to be transmitted and processed over the network.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system applies partial logging strategies by continuously logging all fraud indicators during training phases but switching to selective logging of only suspicious or anomalous patterns during normal operation. This partial action approach maintains detection accuracy for critical threats while reducing overall network bandwidth consumption during periods of normal traffic.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11582610B1Automated security control using log information
Publication Date: 2023.02.14 T MOBILE US INC
  • US11582610B1 patent drawing
  • US11582610B1 patent drawing
  • US11582610B1 patent drawing

AI summary

Techniques, devices, and systems for receiving, from a mobile device, a request associated with a subscriber information module (SIM) are described herein. At least one of the mobile device, the SIM, or a communication identifier can be determined. A query can be transmitted, based on a difference between a first time associated with the query and a second time associated with a previous query meeting or exceeding a threshold amount of time. An action can be performed based on the query information being associated with the malicious activity information.