IP Library Granted Patent US 8,582,457
Granted Patent B2
US 8,582,457 · App. 12/836,094 · Granted Nov 12, 2013

Determining usage predictions and detecting anomalous user activity through traffic patterns

Inventors: Jaan Leemet (Dollard-des-Ormeaux, CA); Daniel Rudich (Dollard-des-Ormeaux, CA)
Assignee: Tangoe Canada, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,582,457
App. No.
12/836,094
Granted
Nov 12, 2013
Kind
B2
Abstract

The present invention concerns a system for selecting and monitoring data plans for telecommunications systems, and methods of determining, learning and estimating usage patterns in-order to predict usage and tie this to cost and the overlaying of plan selection for cost optimization. Further, additional methods are applied to determine anomalous user behaviors and raise security and data leakage related events.

Claims (81)

1. A method of detecting anomalies in the data traffic of a mobile device, comprising the steps of:

collecting at a server and from the mobile device, data traffic statistics for a given time period;

comparing the data traffic statistics against threshold values;

if a statistic of the data traffic statistic exceeds a corresponding threshold of the threshold values, flagging an anomaly;

updating the threshold values based on a running average of each statistic of the data traffic statistics based on formula I,

T

0

=

T

0

+

Max

[

T

0

×

Δ

max

100

,

T

0

-

(

i

=

1

N

T

i

-

Max

(

T

1

,

,

T

N

)

)

N

-

1

]

wherein T 0 is a current threshold value;

Δ max is the maximum change of the threshold value, expressed as a percentage;

T i is the value of a corresponding data traffic statistic i time periods prior to the current period; and

N is the number of time periods used to compute the updated threshold.

2. The method of claim 1 , wherein the collecting step comprises:

reading, at a first interval, data traffic statistics from a network interface on the mobile device;

adding the data traffic statistics to running totals on the mobile device.

3. The method of claim 1 , wherein the given time period corresponds to a data plan period.

4. The method of claim 2 , wherein the collecting step further comprises:

when the running totals exceed a delivery threshold,

sending the running totals to the server; and

resetting the running totals.

5. The method of claim 1 , wherein the collecting step further comprises:

when a delivery timer expires,

sending the running totals to the server; and

resetting the running totals.

6. The method of claim 1 , wherein threshold values include a data size limit for the given time period.

7. The method of claim 1 , wherein the mobile device is configured to identify office-related data traffic and non-office-related data traffic.

8. The method of claim 7 , wherein threshold values include a data size limit for non-office data traffic.

9. The method of claim 7 , wherein threshold values include a minimum time of day for office data traffic.

10. The method of claim 1 , wherein threshold values include a maximum time of day for office data traffic.

11. The method of claim 1 , further comprising the steps of:

extrapolating data traffic statistics to the end of the given time period;

if a statistic of the extrapolated data traffic statistics exceeds a corresponding threshold value of the threshold values, flagging an anomaly.

12. The method of claim 1 , wherein Δ max is 10 and N is 12.

13. The method of claim 1 , further comprising the steps of:

maintaining a list of every flagged anomaly, each anomaly being associated to a type of anomaly, a day of the week, and a week of the month;

if the list of every flagged anomaly includes more than a threshold of known anomalies, wherein known anomalies have the same of at least one of the type of anomaly, the day of the week and the week of the month,

preventing known anomalies from being flagged.

14. The method of claim 1 , wherein the collecting step comprises the step of:

sending, from the mobile device, at least one of a machine name, a user name, and a mobile device identifier.

Assignments (2)
CHANGE OF NAME Recorded Aug 1, 2012
From: ANOMALOUS NETWORKS INC.
To: TANGOE CANADA, INC.
Reel/Frame 028701/0654 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 23, 2010
From: LEEMET, JAAN; RUDICH, DANIEL
To: ANOMALOUS NETWORKS INC.
Reel/Frame 025068/0979 →
Priority Claims (1)
CA 2673135 · Jul 17, 2009 · national
Continuity (1)
Related Publication 20110019566A1 · Jan 27, 2011