Telecom Fraud Detection via User-Specific Profiling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for detecting fraudulent traffic in telecommunications systems face inefficiencies due to high CPU and memory resource consumption in deep packet inspection, as software programs deceive detection algorithms by misclassifying traffic to avoid charges, leading to incorrect classification and resource misuse.

Innovation Solution

A monitoring network node with a traffic monitor and fraud detector applies a user-specific fraud profile to identify fraudulent traffic, transmitting data to a profiling node for updates, allowing tailored monitoring and enforcement actions such as bandwidth limitation or session disconnection, thereby optimizing resource use and improving detection efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If deep packet inspection is used to detect fraudulent traffic, then detection capability is improved, but CPU and memory resource consumption increases

Engineering Contradiction:
Improvefraudulent traffic detection capabilityVSAvoidCPU and memory resource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent segments the fraud detection process into multiple components: signature-based detection for known fraud patterns, anomaly detection for behavioral analysis, and classification mechanisms. This segmentation allows the system to apply different detection strategies to different traffic types, reducing overall computational burden while maintaining detection effectiveness.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically changes detection parameters based on traffic characteristics, user profiles, and detected fraud patterns. By adjusting detection sensitivity, inspection depth, and resource allocation parameters in real-time, the system optimizes the balance between detection capability and resource consumption.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If comprehensive traffic monitoring is applied to all users, then fraud detection accuracy is improved, but system complexity and resource usage increase

Engineering Contradiction:
Improvefraud detection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements local quality by applying different monitoring strategies to different users based on their fraud risk profiles. High-risk users receive comprehensive monitoring with deep packet inspection, while low-risk users receive lighter monitoring. This differentiated approach maintains detection accuracy for critical cases while reducing overall system complexity.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system employs self-service mechanisms where users' historical behavior patterns automatically generate their monitoring profiles. The system learns from past traffic patterns and automatically adjusts monitoring intensity without requiring manual configuration, reducing operational complexity while maintaining accurate detection.

Inventive Principle:
Principle #25Self-service

3Reliability

If real-time fraud detection is implemented, then fraud prevention capability is improved, but processing time and computational load increase

Engineering Contradiction:
Improvefraud prevention capabilityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-computing user profiles, establishing baseline behavior patterns, and preparing detection rules before actual fraud detection is needed. This preliminary processing allows real-time detection to rely on pre-established data structures and patterns, significantly reducing processing time during actual fraud detection while maintaining prevention capability.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3025538B1Detecting fraudulent traffic in a telecommunications system
Publication Date: 2019.03.27 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • EP3025538B1 patent drawingFigure 1~2
  • EP3025538B1 patent drawingFigure 3~4
  • EP3025538B1 patent drawingFigure 5

AI summary

Methods and apparatus for detecting fraudulent traffic associated with a user of a telecommunications system. A system comprises a monitoring network node comprising a traffic monitor configured to monitor traffic transmitted to or from a user in the telecommunications system, a fraud detector configured to apply to the monitored traffic a fraud profile associated with the user to determine whether the monitored traffic comprises fraudulent traffic, a transmitter configured to transmit data to a receiver of a profiling network node notifying whether the monitored traffic comprises fraudulent traffic. The profiling network node further comprises a fraud profiler configured to determine an updated fraud profile associated with the user based at least on the received data and a transmitter configured to transmit data identifying the updated fraud profile to one or both of a receiver of a subscription profile repository and a receiver of the monitoring network node.