IP Library Granted Patent US 11,445,060
Granted Patent B2
US 11,445,060 · App. 16/927,464 · Granted Sep 13, 2022

Method and apparatus for threat identification through analysis of communications signaling events, and participants

Inventor: Lance Douglas (Atlanta, GA)
Assignee: PINDROP SECURITY, INC.
H04M3/2281H04M3/2254H04M3/436H04L63/00H04L63/1408H04M7/0078H04M7/0093H04M2203/6027H04M2207/12H04Q2213/13139H04Q2213/13345H04Q2213/13515
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,445,060
App. No.
16/927,464
Granted
Sep 13, 2022
Kind
B2
Abstract

Aspects of the invention determining a threat score of a call traversing a telecommunications network by leveraging the signaling used to originate, propagate and terminate the call. Outer-edge data utilized to originate the call may be analyzed against historical, or third party real-time data to determine the propensity of calls originating from those facilities to be categorized as a threat. Storing the outer edge data before the call is sent over the communications network permits such data to be preserved and not subjected to manipulations during traversal of the communications network. This allows identification of threat attempts based on the outer edge data from origination facilities, thereby allowing isolation of a compromised network facility that may or may not be known to be compromised by its respective network owner. Other aspects utilize inner edge data from an intermediate node of the communications network which may be analyzed against other inner edge data from other intermediate nodes and/or outer edge data.

Claims (29)

1. A computer-implemented method for analyzing call signaling data at a network platform for calls being directed from originated carriers to terminating facilities via intermediate carriers, the method comprising:

receiving, by a computer of a network platform, first signaling data associated with a calling device that originated an inbound phone call, the first signaling data instructing a telephone transit network to route the inbound phone call to a terminating facility and comprising a first equipment identifier for the calling device and first line information identifying at least one of: an originating carrier, a line type, and an originating location;

receiving, by the computer from a database, second signaling data comprising a second equipment identifier and second line information associated with the calling device;

generating, by the computer, a threat score for the inbound phone call based at least in part upon a difference between the first signaling data and the second signaling data; and

transmitting, by the computer, a signal to a carrier associated with the first signaling data, the signal instructing the carrier to direct the inbound phone call based upon the threat score, wherein the carrier is at least one of the originating carrier and an intermediate carrier.

2. The method according to claim 1 , further comprising determining, by the computer, whether the threat score for the inbound call satisfies an authentication threshold.

3. The method according to claim 2 , further comprising authenticating, by the computer, the calling device that originated the inbound call in response to determining that the threat score satisfies the authentication threshold.

4. The method according to claim 2 , further comprising executing, by the computer, one or more remedial actions in response to determining that the threat score fails to satisfy the authentication threshold.

5. The method according to claim 1 , wherein the first signaling data is received via one or more switching devices in the telephone network, and wherein the first line information of the first signaling data indicates the originating switching device.

6. The method according to claim 1 , wherein the second signaling data received from the database indicates at least one switching device in the telephone network.

7. The method according to claim 1 , wherein the database is configured to store signaling data for calls associated with one or more carrier facilities.

8. The method according to claim 7 , wherein receiving the second signal data further comprises: retrieving, by the computer, the second signaling data from the database according to the first signaling data.

9. The method according to claim 1 , wherein the first signaling data is at least one of a camel application part (CAP), a mobile application part (MAP), an SS7, and an application program interface (API message).

10. The method according to claim 1 , further comprising transmitting, by the computer, the threat score to a device associated with a callee of the phone call.

11. A system for analyzing call signaling data at a network platform for calls being directed from originating carriers to terminating facilities via intermediate carriers, the system comprising:

a server of a network platform coupled to a processor configured to:

receive first signaling data associated with a calling device that originated an inbound phone call, the first signaling data instructing a telephone transit network to route the inbound phone call to a terminating facility and comprising a first equipment identifier for the calling device and first line information identifying at least one of: an originating carrier, a line type, and an originating location;

receive from a database, second signaling data comprising a second equipment identifier and second line information associated with the calling device;

generate a threat score for the inbound phone call based at least in part upon a difference between the first signaling data and the second signaling data; and

transmit a signal to a carrier associated with the first signaling data, the signal instructing the carrier to direct the inbound phone call based upon the threat score, wherein the carrier is at least one of the originating carrier and an intermediate carrier.

12. The system according to claim 11 , wherein the server is further configured to determine whether the threat score for the inbound call satisfies an authentication threshold.

13. The system according to claim 12 , wherein the server is further configured to authenticate the calling device that originated the inbound call in response to determining that the threat score satisfies the authentication threshold.

14. The system according to claim 12 , wherein the server is further configured to execute one or more remedial actions in response to determining that the threat score fails to satisfy the authentication threshold.

15. The system according to claim 11 , wherein the first signaling data is received via one or more switching devices in the telephone network, and wherein the first line information of the first signaling data indicates the originating switching device.

16. The system according to claim 11 , wherein the second signaling data received from the database indicates at least one switching device in the telephone network.

17. The system according to claim 11 , wherein the database is configured to store signaling data for calls associated with one or more carrier facilities.

18. The system according to claim 17 , wherein when receiving the second signal data the server is further configured to retrieve the second signaling data from the database according to the first signaling data.

19. The system according to claim 11 , wherein the first signaling data is at least one of a camel application part (CAP), a mobile application part (MAP), an SS7, and an application program interface (API message).

20. The system according to claim 11 , wherein the server is further configured to transmit the threat score to a device associated with a callee of the phone call.

Assignments (4)
SECURITY INTEREST Recorded Jun 26, 2024
From: PINDROP SECURITY, INC.
To: HERCULES CAPITAL, INC., AS AGENT
Reel/Frame 067867/0860 →
RELEASE OF SECURITY INTEREST Recorded Jun 26, 2024
From: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
To: PINDROP SECURITY, INC.
Reel/Frame 069477/0962 →
SECURITY INTEREST Recorded Jul 31, 2023
From: PINDROP SECURITY, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 064443/0584 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 13, 2020
From: DOUGLAS, LANCE
To: PINDROP SECURITY, INC.
Reel/Frame 053193/0079 →
Continuity (5)
Continuation 16522450 · Jul 25, 2019
Continuation 16200379 · Nov 26, 2018
Continuation 15666917 · Aug 2, 2017
Provisional Application 62370105 · Aug 2, 2016
Related Publication 20200344350A1 · Oct 29, 2020