IP Library Patent Application 11251169
Patent Application
App. No. 11/251,169

System, apparatus and method for detecting malicious traffic in a communications network

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
11/251,169
Abstract

Monitoring apparatus has a pattern matching engine that analyses service usage in a network in order to identify traffic relating to malicious attacks. Optionally, the monitoring apparatus can also arrange for a counter-measure to be deployed upon detection of the malicious traffic.

Claims (24)

1 . A network monitoring apparatus for detecting malicious traffic in a communications network, the apparatus comprising:

an input for receiving service usage data derived, when in use, from signalling data, the signalling data originating, when in use, from a monitored signalling link; and

a data store for storing the service usage data; and

a processing resource to support a pattern matching engine for using a number of the stored data to identify, when in use, traffic patterns communicated to and/or from a communications terminal indicative of malicious traffic.

2 . An apparatus as claimed in claim 1 , wherein the service usage data is a feed of Service Usage Records (SURs).

3 . An apparatus as claimed in claim 1 , wherein the data stored from the at least one field of received usage records is stored as a database for serving as a resource for the identification of the traffic patterns.

4 . An apparatus as claimed in claim 1 , wherein the identification of the traffic patterns includes analysing a property of at least one field of at least one of the usage records.

5 . An apparatus as claimed in claim 1 , wherein the malicious traffic corresponds to a virus.

6 . An apparatus as claimed in claim 1 , wherein the malicious traffic corresponds to a worm.

7 . An apparatus as claimed in claim 1 , wherein the processing resource is arranged to generate, when in use, a message to indicate that malicious traffic has been detected.

8 . An apparatus as claimed in claim 7 , wherein the malicious traffic corresponds to a type of malicious attack, the message identifying the type of the malicious attack.

9 . An apparatus as claimed in claim 7 , wherein a counter-measure is communicated, when in use, to the communications terminal in response to the message.

10 . An apparatus as claimed in claim 7 , wherein a counter-measure is initiated in relation to the communications terminal in response to the message.

11 . An apparatus as claimed in claim 10 , wherein the counter-measure is prevention of the communications terminal from using one or more service supported by the communications network associated with the mobile terminal to communicate data.

12 . A network monitoring system including the network monitoring apparatus as claimed in claim 1 .

13 . A communications network comprising the apparatus as claimed in claim 1 .

14 . A communications network as claimed in claim 11 , further comprising a counter-measure service station for managing the deployment of the counter-measures.

15 . A method of detecting malicious traffic in a communications network, the method comprising:

receiving a feed of service usage data derived from signalling data, the signalling data originating from a monitored signalling link;

storing service usage data; and

using a number of the stored data to identify traffic patterns communicated to and/or from a communications terminal indicative of malicious traffic.

16 . A computer program element comprising computer program code means to make a computer execute the method as claimed in claim 15 .

17 . A computer program element as claimed in claim 16 , embodied on a computer readable medium.

18 . A use of a communications network monitoring system to detect communications to and/or from wireless terminals indicative of a malicious attack.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 25, 2010
From: AGILENT TECHNOLOGIES, INC.
To: JDS UNIPHASE CORPORATION
Reel/Frame 024433/0138 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 20, 2006
From: FORSYTH, JOHN WILLIAM
To: AGILENT TECHNOLOGIES, INC.
Reel/Frame 017043/0414 →