IP Library Granted Patent US 9,166,950
Granted Patent B2
US 9,166,950 · App. 14/706,782 · Granted Oct 20, 2015

System and method for responding to aggressive behavior associated with wireless devices

Inventors: Daniel Collins (McKinney, TX); Jack McGwire (Sunnyvale, CA); Rakesh Kumar (Sunnyvale, CA); Terrence Poon (Fremont, CA); Scott Potter (Los Gatos, CA); Andrew Privett (Norfolk, GB); Dusko Zgonjanin (Palo Alto, CA)
Assignee: Jasper Technologies, Inc.
H04L63/0227H04L43/00H04L43/16H04L67/10H04L67/22H04W4/001H04W12/06H04W12/08H04W24/08H04W28/0215H04W48/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,166,950
App. No.
14/706,782
Granted
Oct 20, 2015
Kind
B2
Abstract

An embodiment of the invention describes a wireless device comprising a Subscriber Identity Module (SIM) further comprising a memory for storing program code for performing a plurality of operations, and a processor for processing the program code to execute the plurality of operations, the operations including receiving over-the-air instructions via a wireless network from a control center to create a rules set in the SIM, wherein the rules set defines an acceptable behavior of the wireless device, monitoring requests from a wireless modem of the wireless device for access files stored in the SIM, detecting an aggressive behavior of the wireless device based on the rules set, and blocking the wireless modem from generating traffic in the wireless network.

Claims (55)

1. A system comprising a control center server and a messaging gateway or a network firewall for managing aggressive behavior of a wireless device in a wireless network, the system comprising:

the control center server comprising:

a processor; and

a memory coupled with the processor, wherein the memory is configured to provide the processor with instructions which when executed cause the processor to perform operations to:

predetermine a wireless device signal behavior to develop a wireless device signature that defines an aggressive behavior of the wireless device indexed by a wireless device identifier, wherein the aggressive behavior of the wireless device is present when the wireless device repeatedly retries to perform a network signaling in a time frame such that a threshold for the retries is exceeded;

retrieve at least one data log from at least one network element comprising at least one of a diagnostic device, a Home Location Register (HLR), a Mobile Switching Center (MSC), a Gateway GPRS Support Node (GGSN), a Serving GPRS Support Node (SGSN), a Short Message Service Center (SMSC), the messaging gateway or the network firewall, and a Remote Authentication Dial In User Service (RADIUS) server by utilizing the wireless device identifier;

determine a rule set to modify the aggressive behavior, wherein the rule set is indexed by the wireless device identifier and comprises first logic to compare the wireless device signature to aggressive behavior data contained in the least one data log, and second logic to provision the messaging gateway or the network firewall to control a transmission function of the messaging gateway or the network firewall;

identify aggressive behavior signals transmitted from the wireless device in accordance with the rule set when the aggressive behavior signals correlates to the aggressive behavior data; and

transmit a provisioning instruction to provision the messaging gateway or the network firewall for real-time throttling, re-directing or blocking of the aggressive behavior signals transmitted from the wireless device to the messaging gateway or the network firewall, and

the messaging gateway or the network firewall comprising:

a processor; and

a memory coupled with the processor, wherein the memory is configured to provide the processor with the provisioning instruction which when executed cause the processor to perform operations to:

update data in a database utilizing the wireless device identifier;

receive, from the wireless device, signals indicating the aggressive behavior of the wireless device;

identify the data in the database utilizing the wireless device identifier; and

throttle, re-direct or block the transmission of the signals of the wireless device according to the data.

2. The system of claim 1 , wherein the wireless device identifier is an International Mobile Subscriber Identity (IMSI) or an MSISDN.

3. The system of claim 1 , wherein the at least one data log comprises at least one of: multiple GSM authorization requests, multiple MSC location updates, multiple SGSN location updates, multiple RADIUS logs, multiple SMS messages, multiple packet data protocol (PDP) sessions/reject messages, and multiple GPRS attach/reject messages.

4. The system of claim 1 , wherein the control center server identifies the aggressive behavior signals when the wireless device generates more than a threshold number of authentication failures per time unit.

5. The system of claim 1 , wherein the control center server identifies the aggressive behavior signals when the wireless device sends more than a threshold number of authentication requests in a time period towards a HLR.

6. The system of claim 1 , wherein the control center server identifies the aggressive behavior signals when the wireless device generates more than a threshold number of Packet Data GGSN Call Data Records (G-CDR) in a time period.

7. The system of claim 1 , wherein the rule set is adapted to different field behaviors of different categories of wireless devices.

8. The system of claim 1 , wherein the rule set specifies an allowable frequency and allowable successive number of times for the wireless device to retry for the network signaling.

9. The system of claim 1 , wherein the data in the database is a routing instruction.

10. A method of a control center server and a messaging gateway or a network firewall for managing aggressive behavior of a wireless device in a wireless network, the method comprising:

at the control center server:

predetermining a wireless device signal behavior to develop a wireless device signature that defines an aggressive behavior of the wireless device indexed by a wireless device identifier, wherein the aggressive behavior of the wireless device is present when the wireless device repeatedly retries to perform a network signaling in a time frame such that a threshold for the retries is exceeded;

retrieving at least one data log from at least one network element comprising at least one of a diagnostic device, a Home Location Register (HLR), a Mobile Switching Center (MSC), a Gateway GPRS Support Node (GGSN), a Serving GPRS Support Node (SGSN), a Short Message Service Center (SMSC), the messaging gateway or the network firewall, and a Remote Authentication Dial In User Service (RADIUS) server by utilizing the wireless device identifier;

determining a rule set to modify the aggressive behavior, wherein the rule set is indexed by the wireless device identifier and comprises first logic to compare the wireless device signature to aggressive behavior data contained in the least one data log, and second logic to provision the messaging gateway or the network firewall to control a transmission function of the messaging gateway or the network firewall;

identifying aggressive behavior signals transmitted from the wireless device in accordance with the rule set when the aggressive behavior signals correlates to the aggressive behavior data; and

transmitting a provisioning instruction to provision the messaging gateway or the network firewall for real-time throttling, re-directing or blocking of the aggressive behavior signals transmitted from the wireless device to the messaging gateway or the network firewall, and

at the messaging gateway or the network firewall:

updating data in a database utilizing the wireless device identifier;

receiving, from the wireless device, signals indicating the aggressive behavior of the wireless device;

identifying the data in the database utilizing the wireless device identifier; and

throttling, re-directing or blocking the transmission of the signals of the wireless device according to the data.

11. The method of claim 10 , wherein the data in the database is a routing instruction.

12. The method of claim 10 , wherein the wireless device identifier is an International Mobile Subscriber Identity (IMSI) or an MSISDN.

13. The method of claim 10 , wherein the at least one data log comprises at least one of: multiple GSM authorization requests, multiple MSC location updates, multiple SGSN location updates, multiple RADIUS logs, multiple SMS messages, multiple packet data protocol (PDP) sessions/reject messages, and multiple GPRS attach/reject messages.

14. The method of claim 10 , wherein the control center server identifies the aggressive behavior signals when the wireless device generates more than a threshold number of authentication failures per time unit.

15. The method of claim 10 , wherein the control center server identifies the aggressive behavior signals when the wireless device sends more than a threshold number of authentication requests in a time period towards a HLR.

16. The method of claim 10 , wherein the control center server identifies the aggressive behavior signals when the wireless device generates more than a threshold number of Packet Data GGSN Call Data Records (G-CDR) in a time period.

17. The method of claim 10 , wherein the rule set is adapted to different field behaviors of different categories of wireless devices.

18. The method of claim 10 , wherein the rule set specifies an allowable frequency and allowable successive numbers of times for the wireless device to retry for the network signaling.

19. A system for managing aggressive behavior of a wireless device in a wireless network, the system comprising:

a control center server comprising:

a processor; and

a memory coupled with the processor, wherein the memory is configured to provide the processor with instructions which when executed cause the processor to perform operations to:

predetermine a wireless device signal behavior to develop a wireless device signature that defines an aggressive behavior of the wireless device indexed by a wireless device identifier, wherein the aggressive behavior of the wireless device is present when the wireless device repeatedly retries to perform a network signaling in a time frame such that a threshold for the retries is exceeded;

retrieve at least one data log from at least one network element comprising at least one of a messaging gateway or a network firewall, a diagnostic device, a Home Location Register (HLR), a Mobile Switching Center (MSC), a Gateway GPRS Support Node (GGSN), a Serving GPRS Support Node (SGSN), a Short Message Service Center (SMSC), a Remote Authentication Dial In User Service (RADIUS) server by utilizing the wireless device identifier;

determine a rule set to modify the aggressive behavior, wherein the rule set is indexed by the wireless device identifier and comprises first logic to compare the wireless device signature to aggressive behavior data contained in the least one data log, and second logic to provision the messaging gateway or the network firewall to control a transmission function of the messaging gateway or the network firewall;

identify aggressive behavior signals transmitted from the wireless device in accordance with the rule set when the aggressive behavior signals correlates to the aggressive behavior data; and

transmit a provisioning instruction to provision the messaging gateway or the network firewall for real-time throttling, re-directing or blocking of the aggressive behavior signals transmitted from the wireless device to the messaging gateway or the network firewall.

20. The system of claim 19 , wherein the wireless device identifier is an International Mobile Subscriber Identity (IMSI) or an MSISDN.

21. The system of claim 19 , wherein the at least one data log comprises at least one of: multiple GSM authorization requests, multiple MSC location updates, multiple SGSN location updates, multiple RADIUS logs, multiple SMS messages, multiple packet data protocol (PDP) sessions/reject messages, and multiple GPRS attach/reject messages.

Assignments (3)
CHANGE OF NAME Recorded Feb 27, 2017
From: JASPER TECHNOLOGIES, INC.
To: JASPER TECHNOLOGIES LLC
Reel/Frame 041823/0259 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 27, 2017
From: JASPER TECHNOLOGIES LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 041823/0655 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 29, 2015
From: COLLINS, DANIEL; MCGWIRE, JACK; KUMAR, RAKESH; POON, TERRENCE; POTTER, SCOTT; PRIVETT, ANDREW; ZGONJANIN, DUSKO
To: JASPER TECHNOLOGIES, INC
Reel/Frame 035744/0826 →
Continuity (12)
Continuation 14604450 · Jan 23, 2015
Continuation 14320319 · Jun 30, 2014
Continuation 14189847 · Feb 25, 2014
Continuation 13948916 · Jul 23, 2013
Continuation In Part 13766622 · Feb 13, 2013
Continuation 12387962 · May 7, 2009
Continuation In Part 13544497 · Jul 9, 2012
Continuation In Part 13670191 · Nov 6, 2012
Continuation 12652694 · Jan 5, 2010
Provisional Application 61746468 · Dec 27, 2012
Provisional Application 61505951 · Jul 8, 2011
Related Publication 20150244676A1 · Aug 27, 2015