Telecommunication Device Cybersecurity via Activity Log Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Telecommunication devices can become infected with malware without detection, posing a risk to sensitive information, and existing preventative measures can lead to false positives, rendering healthy devices non-functional.

Innovation Solution

The system analyzes activity log data from telecommunication devices to detect candidate events indicative of malware, and instead of immediately disabling services, adds them to a queue for potential disabling, allowing for further investigation to prevent false positives.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If telecommunication devices are disabled when candidate events are detected, then cybersecurity is improved, but false positives cause healthy devices to be rendered non-functional

Engineering Contradiction:
ImprovecybersecurityVSAvoiddevice functionality
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary actions by adding candidate services to a queue for disabling rather than immediately disabling them. This allows for further investigation and verification before taking the harsh action of disabling, thereby preventing false positives from rendering healthy devices non-functional while still maintaining security posture.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms by continuously monitoring activity log data and adjusting the disabling queue based on detected patterns. When candidate events are detected, the system feeds this information back into the evaluation process, allowing for iterative decision-making that reduces false positives while maintaining security.

Inventive Principle:
Principle #23Feedback

2Speed

If services are immediately disabled upon detecting candidate events, then response time is reduced, but investigation time is lost

Engineering Contradiction:
Improveresponse timeVSAvoidinvestigation time
Core Design Contradiction:
SpeedVSLoss of time

Solution Approach 1:

The system prepares for immediate action by maintaining a queue of candidate services that can be disabled rapidly if confirmed malicious. This preliminary organization allows the system to respond quickly to confirmed threats while still having time for investigation during the queue evaluation process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system dynamically adjusts the disabling process based on real-time analysis of activity log data. The queue mechanism allows the system to flex between immediate disabling (when confidence is high) and continued monitoring (when investigation is needed), optimizing both response time and investigation time.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20250103711A1System and method for improving cybersecurity for telecommunication devices
Publication Date: 2025.03.27 CAPITAL ONE SERVICES LLC
  • US20250103711A1 patent drawing
  • US20250103711A1 patent drawing
  • US20250103711A1 patent drawing

AI summary

Methods and systems are described herein for improvements for cybersecurity of telecommunication devices. For example, cybersecurity for telecommunication devices may be improved by analyzing activity log data of telecommunication devices for a candidate event (e.g., the uploading of malware) and disabling one or more services of a telecommunication device. By doing so, cybersecurity for telecommunication devices may be improved by detecting a possible malware intrusion attempt and disabling one or more services of the telecommunication devices. For example, activity log data of telecommunication devices may be obtained. A candidate event indicating malware may be detected in the activity log data. A number of proximate telecommunication devices satisfying a proximity threshold condition may be determined. The number of proximate telecommunication devices that satisfy a density threshold condition may be determined. Responsive to the number of telecommunication devices satisfying a density threshold condition, services of telecommunication devices may be disabled.