IP Library Granted Patent US 10,638,411
Granted Patent B2
US 10,638,411 · App. 16/029,037 · Granted Apr 28, 2020

Rogue base station router detection with machine learning algorithms

Inventors: Kerri Ann Stone (Lafayette, CO); Ronald Lance Justin (Denver, CO); Jennifer Lynn Ryan (Golden, CO)
H04W48/16G06F3/02G06K9/6219G06K9/6223G06N20/00H04L43/045H04L63/1425H04L63/1483H04W12/12H04W24/08H04W68/005H04L41/22H04L43/16H04W84/042H04W88/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,638,411
App. No.
16/029,037
Granted
Apr 28, 2020
Kind
B2
Abstract

This application is directed to a method for detecting a rogue device in a network. The method includes a step of surveying the network. The method also includes a step of collecting broadcast data from cellular towers in the network based on the survey. The method also includes a step of distilling the collected broadcast data into abstract syntax notation one (ASN.1)-encoded system information blocks (SIBs) associated with plural devices. The method further includes a step of featurizing the ASN.1-encoded SIBs. The method even further includes a step of running the featurized, ASN.1-encoded SIBs through an unsupervised machine learning algorithm. The algorithm is executed by a processor to analyze all cells in the survey for the rogue device. Yet even further, the method includes a step of determining, based on the run, anomalous cells exhibiting characteristics of the rogue device from all cells in the survey.

Claims (27)

1. A method for detecting a rogue device in a network comprising:

surveying the network;

collecting, based on the survey, broadcast data from cellular towers in the network;

distilling the collected broadcast data into abstract syntax notation one (ASN.1)-encoded system information blocks (SIBs) associated with plural devices;

featurizing the ASN.1-encoded SIBs;

determining, for each of the plural devices, the times of a first and a last occurrence of the device on the network;

running the featurized, ASN.1-encoded SIBs and the respective times of the first and last occurrences of the plural devices through an unsupervised machine learning algorithm, executed by a processor, to analyze all cells in the survey for the rogue device; and

determining, based on the run, anomalous cells exhibiting characteristics of the rogue device from all cells in the survey.

2. The method of claim 1 , wherein the collected broadcast data is based on a single radio access technology (RAT).

3. The method of claim 2 , wherein the collected broadcast data is based on a public land mobile network (PLMN).

4. The method of claim 2 , wherein the RAT is UMTS or LTE.

5. The method of claim 1 , wherein the machine learning algorithm is selected from a k-means clustering algorithm, an isolation forest anomaly detection algorithm, and an agglomerative hierarchical clustering algorithm.

6. The method of claim 5 , wherein the ASN.1-encoded SIBs include one or more of Universal Mobile Telecommunications System (UMTS) SIB 1, UMTS SIB 3 and UMTS SIB 5.

7. The method of claim 5 , wherein the ASN.1-encoded SIBs include one or more of Long-Term Evolution (LTE) SIB 1, LTE SIB 2 and LTE SIB 3.

8. The method of claim 1 , wherein

the determining step includes confirming a number of native cells of a commercial carrier is greater than a number of rogue cells, and

the determined cell is based on a single cellular scan of a geographic area.

9. The method of claim 1 , further comprising notifying users on the network of the rogue device.

10. The method of claim 1 , wherein the determined rogue device is a cellular tower or dynamic base station router.

11. The method of claim 1 , further comprising:

displaying, on a graphical user interface (GUI), a location of the rogue device in the network.

12. The method of claim 1 , further comprising:

displaying, on a GUI, the respective times of the first and last occurrences of the plural devices on the network; and

notifying users on the network of the rogue device based on the respective times of the first and last occurrences of the plural devices on the network.

13. The method of claim 1 , further comprising:

identifying a manufacturer, technologies in use, or combinations thereof of the rogue device.

14. The method of claim 13 , wherein the identifying step is based on use of at least one of a neural network and a support vector machine.

Assignments (4)
NOTICE OF GRANT OF SECURITY INTEREST IN PATENTS Recorded Jan 22, 2025
From: CACI LGS INNOVATIONS LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 069987/0444 →
CHANGE OF NAME Recorded Nov 4, 2024
From: LGS INNOVATIONS LLC
To: CACI LGS INNOVATIONS LLC
Reel/Frame 069293/0062 →
NOTICE OF GRANT OF SECURITY INTEREST IN PATENTS Recorded Dec 13, 2021
From: LGS INNOVATIONS LLC
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 058961/0065 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 25, 2018
From: JUSTIN, RONALD LANCE; STONE, KERRI ANN; RYAN, JENNIFER LYNN
To: LGS INNOVATIONS LLC
Reel/Frame 046459/0834 →