Subscriber Correlation in Mobile Networks via AAA Mapping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security solutions in mobile networks face challenges in efficiently correlating network events with subscriber information, particularly in identifying specific subscriber devices associated with detected events, which limits the ability to create and report behavioral profiles and respond to malware threats effectively.

Innovation Solution

A communication system that receives network traffic information, correlates it with subscriber data using a mapping table linking network addresses to subscriber device information, and utilizes a network threat behavior analysis engine to monitor flow records and identify network events, enabling the derivation of mobile phone numbers and other subscriber details for immediate remediation and behavior profiling.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional network security solutions are used in mobile networks, then network security monitoring is provided, but the ability to efficiently correlate network events with subscriber information is limited

Engineering Contradiction:
Improvenetwork securityVSAvoidsubscriber information correlation
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces an intermediary correlation system that includes a mapping table storing relationships between network addresses and subscriber identifiers, and a correlation module that queries this mapping table. This intermediary structure enables efficient linkage between network events and subscriber information without requiring intrusive methods on mobile devices, thereby resolving the contradiction between maintaining network security and preserving subscriber information correlation capability

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary actions by pre-establishing the mapping table that contains correlations between network addresses and subscriber identifiers before security events occur. This advance preparation enables rapid correlation when security events are detected, improving both the reliability of security monitoring and the completeness of subscriber information available for analysis

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If network address to subscriber device mapping is implemented, then identification of specific subscriber devices is improved, but system complexity increases

Engineering Contradiction:
Improvesubscriber device identificationVSAvoidmapping table maintenance
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The mapping table is automatically updated through interception and parsing of AAA (Authentication, Authorization, and Accounting) protocol messages exchanged between network elements. The system self-maintains the mapping information by extracting network addresses and subscriber identifiers from these protocol messages, eliminating the need for manual configuration or complex external management systems, thus reducing overall system complexity while maintaining precise subscriber device identification

Inventive Principle:
Principle #25Self-service

3Productivity

If behavior profiling is enabled for security analysis, then malware threat response is improved, but intrusion into subscriber privacy increases

Engineering Contradiction:
Improvemalware threat responseVSAvoidsubscriber privacy intrusion
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system uses the mapping table as an intermediary that enables behavior profiling by correlating network events with subscriber identifiers without requiring direct access to or analysis of subscriber device content. The correlation module queries the mapping table to link observed network behavior patterns with subscriber information, allowing malware threat response improvement while avoiding intrusive methods that would violate subscriber privacy

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs partial action by monitoring only network-level behavior patterns rather than examining complete subscriber device activity or content. This selective monitoring approach enables effective malware threat detection and response through behavior profiling while minimizing privacy intrusion by focusing only on necessary network traffic characteristics

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP2939454B1System and method for correlating network information with subscriber information in a mobile network environment
Publication Date: 2019.10.30 MCAFEE LLC
  • EP2939454B1 patent drawingFigure 1
  • EP2939454B1 patent drawingFigure 2
  • EP2939454B1 patent drawingFigure 3

AI summary

A method is provided in one example embodiment and includes receiving information for network traffic in a wireless network; correlating the information with a subscriber of a plurality of subscribers; and generating a behavior profile for the subscriber based on the information over a period of time.