IP Library Granted Patent US 10,938,844
Granted Patent B2
US 10,938,844 · App. 15/217,279 · Granted Mar 2, 2021

Providing security through characterizing mobile traffic by domain names

Inventors: Jeffrey Bickford (Thornton, CO); Wei Wang (Weehawken, NJ)
Assignee: AT&T INTELLECTUAL PROPERTY I, L.P.
H04L63/1425H04W4/12H04W12/1208H04L47/2441H04L61/1511H04L63/1458
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,938,844
App. No.
15/217,279
Granted
Mar 2, 2021
Kind
B2
Abstract

A method, computer-readable medium, and apparatus for classifying mobile traffic for securing a network or a mobile user endpoint device are disclosed. For example, a method may include a processor for classifying mobile network traffic using a probabilistic model for a plurality of mobile software applications based on a distribution of domain names, detecting an anomaly associated with a mobile software application of the plurality of mobile software applications, and performing a remedial action to address the anomaly.

Claims (33)

1. A device comprising:

a processor; and

a computer-readable medium storing instructions which, when executed by the processor, cause the processor to perform operations, the operations comprising:

classifying mobile network traffic of a network as being associated with one or more mobile software applications of a plurality of mobile software applications using a probabilistic model for the plurality of mobile software applications, wherein the probabilistic model is based on a distribution of domain names;

detecting an anomaly associated with a mobile software application of the plurality of mobile software applications based on the mobile network traffic classified as being associated with the one or more mobile software applications, wherein the anomaly comprises at least one of: a security event or a performance issue;

verifying a set of one or more of the domain names is associated with the mobile software application in response to the detecting of the anomaly; and

performing one or more remedial actions to address the anomaly based on the verifying, wherein the one or more remedial actions comprise: sending a notification to a mobile endpoint device having the mobile software application, wherein the notification contains a request to a user of the mobile endpoint device having the mobile software application to deactivate or deinstall the mobile software application, blocking mobile traffic from a functional domain name correlated to the mobile software application, or throttling the mobile traffic from the functional domain name correlated to the mobile software application.

2. The device of claim 1 , wherein the one or more remedial actions further comprise sending a notification to a developer of the mobile software application.

3. The device of claim 1 , wherein the one or more remedial actions further comprise sending a notification to an entity responsible for the mobile endpoint device having the mobile software application.

4. The device of claim 3 , wherein the entity comprises a business entity, a governmental agency, a guardian or a parent.

5. The device of claim 1 , wherein the one or more remedial actions further comprise allocating an additional network resource to address the anomaly.

6. The device of claim 1 , wherein the one or more remedial actions further comprise blocking mobile traffic from the mobile endpoint device having the mobile software application.

7. The device of claim 1 , the operations further comprising:

retraining the probabilistic model on a periodic basis.

8. A method comprising:

classifying, by a processor, mobile network traffic as being associated with one or more mobile software applications of a plurality of mobile software applications using a probabilistic model for the plurality of mobile software applications, wherein the probabilistic model is based on a distribution of domain names;

detecting, by the processor, an anomaly associated with a mobile software application of the plurality of mobile software applications based on the mobile network traffic classified as being associated with the one or more mobile software applications, wherein the anomaly comprises at least one of: a security event or a performance issue;

verifying, by the processor, a set of one or more of the domain names is associated with the mobile software application in response to the detecting of the anomaly; and

performing, by the processor, one or more remedial actions to address the anomaly based on the verifying, wherein the one or more remedial actions comprise: sending a notification to a mobile endpoint device having the mobile software application, wherein the notification contains a request to a user of the mobile endpoint device having the mobile software application to deactivate or deinstall the mobile software application, blocking mobile traffic from a functional domain name correlated to the mobile software application, or throttling the mobile traffic from the functional domain name correlated to the mobile software application.

9. The method of claim 8 , wherein the one or more remedial actions further comprise sending a notification to a developer of the mobile software application.

10. The method of claim 8 , wherein the one or more remedial actions further comprise sending a notification to an entity responsible for the mobile endpoint device having the mobile software application.

11. The method of claim 10 , wherein the entity comprises a business entity, a governmental agency, a guardian or a parent.

12. The method of claim 8 , wherein the one or more remedial actions further comprise allocating an additional network resource to address the anomaly.

13. The method of claim 8 , wherein the one or more remedial actions further comprise blocking mobile traffic from the mobile endpoint device having the mobile software application.

14. A tangible computer-readable medium storing instructions which, when executed by a processor, cause the processor to perform operations, the operations comprising:

classifying mobile network traffic as being associated with one or more mobile software applications of a plurality of mobile software applications using a probabilistic model for the plurality of mobile software applications, wherein the probabilistic model is based on a distribution of domain names;

detecting an anomaly associated with a mobile software application of the plurality of mobile software applications based on the mobile network traffic classified as being associated with the one or more mobile software applications, wherein the anomaly comprises at least one of: a security event or a performance issue;

verifying a set of one or more of the domain names is associated with the mobile software application in response to the detecting of the anomaly; and

performing one or more remedial actions to address the anomaly based on the verifying, wherein the one or more remedial actions comprise: sending a notification to a mobile endpoint device having the mobile software application, wherein the notification contains a request to a user of the mobile endpoint device having the mobile software application to deactivate or deinstall the mobile software application, blocking mobile traffic from a functional domain name correlated to the mobile software application, or throttling the mobile traffic from the functional domain name correlated to the mobile software application.

15. The tangible computer-readable medium of claim 14 , wherein the one or more remedial actions further comprise sending a notification to a developer of the mobile software application.

16. The tangible computer-readable medium of claim 14 , wherein the one or more remedial actions further comprise sending a notification to an entity responsible for the mobile endpoint device having the mobile software application.

17. The tangible computer-readable medium of claim 14 , wherein the one or more remedial actions further comprise allocating an additional network resource to address the anomaly.

18. The tangible computer-readable medium of claim 14 , wherein the one or more remedial actions further comprise blocking mobile traffic from the mobile endpoint device having the mobile software application.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 26, 2016
From: BICKFORD, JEFFREY; WANG, WEI
To: AT&T INTELLECTUAL PROPERTY I, L.P.
Reel/Frame 040137/0580 →
Continuity (1)
Related Publication 20180027416A1 · Jan 25, 2018