Detecting Unauthorized Tethering via Short-Lived Data Flow Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Unauthorized tethering by wireless devices leads to increased network resource consumption and congestion, causing unfairness among subscribers as network operators do not allocate resources for unauthorized tethering, resulting in disproportionate bandwidth usage.
Innovation Solution
Detecting unauthorized tethering by monitoring the number of short-lived data flows from wireless devices and identifying those exceeding a data flow threshold, which indicates tethering activity, allowing for subsequent adjustments in data flow or connection limitations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If wireless devices share network access with other devices (tethering), then network connectivity and service availability are improved, but network resource consumption increases and causes congestion
Solution Approach 1:
The patent performs preliminary detection of tethering activity by monitoring data flow patterns before significant resource consumption occurs. The system identifies short-lived data flows and counts them during an observation time period, detecting unauthorized tethering early to prevent excessive network resource usage.
Solution Approach 2:
The patent implements a feedback mechanism where the access node continuously monitors data flows from wireless devices, compares the observed patterns against expected patterns, and takes corrective action when unauthorized tethering is detected. This closed-loop control prevents resource exhaustion by responding to detected anomalies.
2Ease of operation
If network operators allocate resources proportionally to data transferred, then fairness among authorized subscribers is improved, but unauthorized tethering devices exploit the system and consume disproportionate resources
Solution Approach 1:
The system performs preliminary detection of unauthorized tethering by analyzing data flow patterns before significant resource consumption occurs. By identifying short-lived data flows and counting them during an observation period, the system detects tethering activity early to prevent unfair resource consumption.
Solution Approach 2:
The patent converts the harmful effect of unauthorized tethering into a detectable pattern. By monitoring for short-lived data flows characteristic of tethering activity, the system identifies and can subsequently block or throttle these connections, transforming the resource exploitation problem into a detectable and manageable condition.
3Reliability
If the access node monitors and inspects packets to detect unauthorized tethering, then network control and fairness are improved, but processing complexity and computational load increase
Solution Approach 1:
The patent applies local quality by focusing monitoring efforts on specific characteristics of data flows rather than analyzing all packet content. The system specifically looks for short-lived data flows with particular patterns, applying detailed inspection only where needed rather than uniformly across all traffic.
Solution Approach 2:
The system changes parameters by monitoring aggregate flow characteristics (duration, frequency, count) rather than individual packet contents. By counting short-lived data flows during an observation time period and comparing against a threshold, the system achieves reliable detection with reduced processing complexity.
Data Source
AI summary
In systems and methods of detecting a wireless device utilizing unauthorized tethering, it is determined that a number of wireless devices in active communication with the access node meets a connections criteria, and that an access node loading meets a loading criteria. Packets received at the access node from the wireless devices are inspected to identify at least one short-lived data flow and a source wireless device of the at least one short-lived data flow. It is determined for the source wireless device a number of short-lived data flows during an observation time period, and the source wireless device is identified as performing unauthorized tethering when the number of short-lived data flows during the first time period meets a data flow threshold.


