IP Library › Granted Patent US 12,598,201
Granted Patent B2
US 12,598,201 · App. 18/051,565 · Granted Apr 7, 2026

Multifaceted detection of fraudulent data usage

Inventors: Jacob Methner (Natick, MA); Khurram Abbas (Novi, MI); Kevin Michael Robinson (Port Richey, FL)
Assignee: Verizon Patent and Licensing Inc.
H04L63/1425H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,598,201
App. No.
18/051,565
Granted
Apr 7, 2026
Kind
B2
Abstract

A method, a network device, and a non-transitory computer-readable storage medium are described in relation to a multifaceted detection of fraudulent data usage service. The multifaceted detection of fraudulent data usage service may apply fraudulent detection to multiple facets of network usage including end device identifier analysis, end device registration analysis, traffic analysis, and end device examination analysis. The multifaceted detection of fraudulent data usage service may include weightings and scoring associated with the examinations.

Claims (67)

1 . A method comprising:

selecting, by a network device, an end device for examination of fraudulent activity;

examining, by the network device based on the selecting, an end device identifier of the end device;

examining, by the network device, registration information of the end device, wherein the registration information includes information indicating whether the end device registers and re-registers with an application layer network according to a prescribed schedule set by the application layer network and multiple registrations and attachments of the end device with a radio access network and a core network;

examining, by the network device, user traffic of the end device;

examining, by the network device, operational data of the end device, wherein the operational data includes a network port and associated network port number and usage of the network port and network port number relative to an application service at the end device;

determining, by the network device based on results of the examinations of the end device identifier, the registration information, the user traffic, and the operational data, whether the end device exhibits the fraudulent activity; and

assigning, by the network device based on determining that the end device exhibits the fraudulent activity, a static network address to the end device.

2 . The method of claim 1 , further comprising:

calculating, by the network device, an aggregate value based on the results of the examinations; and

comparing, by the network device, the aggregate value to a threshold value.

3 . The method of claim 1 , wherein the examining of the end device identifier comprises:

comparing, by the network device, at least a portion of the end device identifier to end device information that includes manufacturer and model information; and

determining, by the network device based on the comparing, whether the end device is an authorized device.

4 . The method of claim 1 , wherein the examining of the registration information comprises:

examining, by the network device, a capability report received from the end device during an initial registration with the core network.

5 . The method of claim 1 , wherein the examining of the user traffic comprises:

determining, by the network device, whether the end device connects to and disconnects from the core network a threshold number of times during a time period; and

determining, by the network device, whether the end device uses application layer services that do not relate to a device type of the end device.

6 . The method of claim 1 , wherein the examining of the user traffic comprises:

obtaining, by the network device from the user traffic, end device information including manufacturer, model number, and software version of the end device; and

determining, by the network device based on the end device information, whether the user traffic of the end device violates a data usage limit.

7 . The method of claim 1 , further comprising:

receiving, by the network device, from at least one of a radio access network device of the radio access network, a core device of the core network, or a probe device, the end device identifier, the registration information, the user traffic, and the operational data.

8 . The method of claim 1 , wherein the network device is a radio access network device of the radio access network, a core device of the core network, or a probe device.

9 . A network device comprising:

a processor that is configured to:

select an end device for examination of fraudulent activity;

examine, based on the selection, an end device identifier of the end device;

examine registration information of the end device, wherein the registration information includes information indicating whether the end device registers and re-registers with an application layer network according to a prescribed schedule set by the application layer network and multiple registrations and attachments of the end device with a radio access network and a core network;

examine user traffic of the end device;

examine operational data of the end device, wherein the operational data includes a network port and associated network port number and usage of the network port and network port number relative to an application service number and usage at the end device;

determine based on results of the examinations of the end device identifier, the registration information, the user traffic, and the operational data, whether the end device exhibits the fraudulent activity; and

assign, based on a determination that the end device exhibits the fraudulent activity, a static network address to the end device.

10 . The network device of claim 9 , wherein the processor is further configured to:

calculate an aggregate value based on the results of the examinations; and

compare the aggregate value to a threshold value.

11 . The network device of claim 9 , wherein when examining the end device identifier, the processor is further configured to:

compare at least a portion of the end device identifier to end device information that includes manufacturer and model information; and

determine, based on the comparison, whether the end device is an authorized device.

12 . The network device of claim 9 , wherein when examining the registration information, the processor is further configured to:

examine a capability report received from the end device during an initial registration with the core network.

13 . The network device of claim 9 , wherein when examining the user traffic, the processor is further configured to:

determine whether the end device connects to and disconnects from the core network a threshold number of times during a time period; and

determine whether the end device uses application layer services that do not relate to a device type of the end device.

14 . The network device of claim 9 , wherein when examining the user traffic, the processor is further configured to:

obtain, from the user traffic, end device information including manufacturer, model number, and software version of the end device; and

determine, based on the end device information, whether the user traffic of the end device violates a data usage limit.

15 . The network device of claim 9 , wherein the processor is further configured to:

receive from at least one of a radio access network device of the radio access network, a core device of the core network, or a probe device, the end device identifier, the registration information, the user traffic, and the operational data.

16 . The network device of claim 9 , wherein the network device is a radio access network device of the radio access network, a core device of the core network, or a probe device.

17 . A non-transitory computer-readable storage medium storing instructions executable by a processor of a network device, wherein the instructions are configured to:

select an end device for examination of fraudulent activity;

examine, based on the selection, an end device identifier of the end device;

examine registration information of the end device, wherein the registration information includes information indicating whether the end device registers and re-registers with an application layer network according to a prescribed schedule set by the application layer network and multiple registrations and attachments of the end device with a radio access network and a core network;

examine user traffic of the end device;

examine operational data of the end device, wherein the operational data includes a network port and associated network port number and usage of the network port and network port number relative to an application service number and usage at the end device;

determine based on results of the examinations of the end device identifier, the registration information, the user traffic, and the operational data, whether the end device exhibits the fraudulent activity; and

assign, based on a determination that the end device exhibits the fraudulent activity, a static network address to the end device.

18 . The non-transitory computer-readable storage medium of claim 17 , wherein the instructions are further configured to:

calculate an aggregate value based on the results of the examinations; and

compare the aggregate value to a threshold value.

19 . The non-transitory computer-readable storage medium of claim 17 , wherein the instructions are further configured to:

receive from at least one of a radio access network device of the radio access network, a core device of the core network, or a probe device, the end device identifier, the registration information, the user traffic, and the operational data.

20 . The non-transitory computer-readable storage medium of claim 17 , wherein the instructions are further configured to:

obtain, from the user traffic, end device information including manufacturer, model number, and software version of the end device; and

determine, based on the end device information, whether the user traffic of the end device violates a data usage limit.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 1, 2022
From: METHNER, JACOB; ABBAS, KHURRAM; ROBINSON, KEVIN MICHAEL
To: VERIZON PATENT AND LICENSING INC.
Reel/Frame 061609/0130 →
Continuity (1)
Related Publication 20240146750A1 · May 2, 2024
References Cited (5)
US 10872341B1 · Beckman · 2020 [cited by examiner]
US 12149559B1 · Fullen · 2024 [cited by examiner]
US 20200120458A1 · Aldana · 2020 [cited by examiner]
US 20220159022A1 · Aghamirzaei · 2022 [cited by examiner]
US 20220201010A1 · Tarsauliya · 2022 [cited by examiner]