Web Page Spectroscopy for Unauthorized Tethering Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for identifying user activity in communication networks rely on Deep Packet Inspection (DPI) or device-local agents, which are ineffective due to encryption and prone to viruses, respectively.

Innovation Solution

The use of machine learning techniques to analyze communication network packets and identify unauthorized tethering without relying on DPI or device-local agents, by capturing and processing packet flows to detect behaviors and extract common parameters associated with web page displays.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If Deep Packet Inspection (DPI) is used to identify user activity, then measurement precision is improved, but reliability deteriorates due to encryption rendering DPI ineffective

Engineering Contradiction:
Improveuser activity identification accuracyVSAvoidmethod effectiveness
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent introduces a machine learning model as an intermediary that processes network packet data to infer user activities. Instead of directly inspecting encrypted packet contents (DPI), the system uses packet flow characteristics as intermediate features that the ML model analyzes to determine user behaviors, thereby bypassing the encryption limitation while maintaining identification accuracy

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical Deep Packet Inspection approach with a machine learning-based system. The ML model learns patterns from packet flow data and automatically identifies user activities without requiring direct content inspection, substituting the traditional mechanical DPI method with an intelligent system that is not defeated by encryption

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If device-local agents are deployed to monitor user activity, then measurement precision is improved, but object-generated harmful factors worsen due to virus susceptibility

Engineering Contradiction:
Improveuser activity detection accuracyVSAvoidvirus risk
Core Design Contradiction:
Measurement precisionVSObject-generated harmful factors

Solution Approach 1:

The patent extracts the monitoring function from the user's device and relocates it to the network infrastructure. By analyzing packet flows at the network level rather than deploying agents on user devices, the system eliminates the security risks associated with device-local agents while maintaining the ability to accurately identify user activities

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces network-based machine learning analysis as an intermediary between the user device and the monitoring system. This intermediary approach allows activity detection without requiring direct access to or installation of software on the user's device, thereby eliminating virus susceptibility while preserving measurement precision

Inventive Principle:
Principle #24Intermediary (Mediator)

3Device complexity

If traditional packet analysis methods are used, then device complexity is reduced, but measurement precision deteriorates due to inability to handle encrypted traffic

Engineering Contradiction:
Improvesystem simplicityVSAvoidactivity identification accuracy
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The patent changes the parameters being analyzed from encrypted packet contents to packet flow characteristics such as timing, size, and frequency patterns. This parameter transformation allows the use of relatively simple machine learning models that process less complex data while achieving high measurement precision in identifying user activities despite the presence of encryption

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20250071131A1Web page spectroscopy
Publication Date: 2025.02.27 AT&T INTELLECTUAL PROPERTY I L P
  • US20250071131A1 patent drawing
  • US20250071131A1 patent drawing
  • US20250071131A1 patent drawing

AI summary

Facilitating web page spectroscopy in a communications network is provided herein. A system can comprise a processor and a memory that stores executable instructions that, when executed by the processor, facilitate performance of operations. The operations can comprise receiving first data that describes a first communication packet flow and second data that describes a second communication packet flow. The operations can also comprise training a model based on the first data and the second data, as a result of which the model is trained to detect respective behaviors represented by the first data and the second. Further, the operations can comprise extracting a common parameter from third data that describes a third communication packet flow and fourth data that describes a fourth communication packet flow based on the model.