IP Library Granted Patent US 12,500,899
Granted Patent B2
US 12,500,899 · App. 18/026,279 · Granted Dec 16, 2025

Satellite communications network intrusion detection systems and methods

Inventors: Dana Dalton (Reston, VA); Colby Moore (Reston, VA)
Assignee: SC Networks, Incorporated
H04L63/1408H04W12/121
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,500,899
App. No.
18/026,279
Granted
Dec 16, 2025
Kind
B2
Abstract

The present application at least describes an intrusion detection system. The system may include a non-transitory memory including a set of instructions. The system may also include a processor operably coupled to the non-transitory memory configured to execute the set of instructions. One of the instructions may include obtaining streaming metrics data from a satellite network management system. Another one of the instructions may include identifying a terminal in an intrusion detection database. Ye another one of the instructions may include determining, based on the streaming metrics data, whether a confidence score providing an indication of authenticity for the identified terminal meets or exceeds a predetermined threshold. A further one of the instructions may include generating an alert based upon the determination.

Claims (95)

1 . An intrusion detection system comprising:

a non-transitory memory including a set of instructions; and

a processor operably coupled to the non-transitory memory configured to execute the set of instructions including:

obtaining streaming metrics data from a satellite network management system;

identifying a very small aperture terminal (VSAT) in an intrusion detection database;

determining, based on the streaming metrics data, whether a confidence score providing an indication of authenticity for the identified VSAT meets or exceeds a predetermined threshold; and

generating an alert based upon the determination.

2 . The intrusion detection system of claim 1 , wherein the determination includes:

detecting the VSAT is in an online state after being in an offline state;

determining a prior transmit power for the VSAT before being in the offline state; and

determining a current transmit power for the VSAT in the online state,

wherein the confidence score is based on a difference between the prior transmit power and the current transmit power.

3 . The intrusion detection system of claim 1 , wherein the determination includes:

calculating, for the VSAT, a prior amplitude and a prior frequency of a prior periodic oscillating waveform representing a time-based variation of a timing offset during a prior period of time; and

calculating, for the VSAT, a current amplitude and a current frequency of a current periodic oscillating waveform representing a time-based variation of a timing offset during a current period of time,

wherein the confidence score is based on a difference between the prior amplitude and the current amplitude and/or the prior frequency and the current frequency.

4 . The intrusion detection system of claim 1 , wherein the determination includes:

determining a prior operating temperature for the VSAT at a prior period of time; and

determining a current operating temperature for the VSAT at a current period of time,

wherein the confidence score is based on a difference between the prior operating temperature and the current operating temperature and/or lack of a predetermined variation in the current operating temperature.

5 . The intrusion detection system of claim 1 , wherein the determination includes:

detecting the VSAT is an online state after being in an offline state;

determining a prior noise value for the VSAT prior to being in the offline state; and

determining a current noise value for the VSAT in the online state,

wherein the confidence score is based on a difference between the prior noise value and the current noise value, and

wherein the prior noise value and the current noise value are based on a ratio of carrier to noise or carrier to noise density.

6 . The intrusion detection system of claim 1 , wherein the determination includes:

detecting the VSAT is an online state after being in an offline state;

determining a prior equipment aspect for the VSAT prior to being in the offline state; and

determining a current equipment aspect for the VSAT in the online state,

wherein the confidence score is based on a difference between the prior equipment aspect and the current equipment aspect, and

wherein the prior equipment aspect and the current equipment aspect include one or more of a LAN port identifier, a modem link speed, a modem link state, a sensitivity of clock to temperature variation, and a feedhorn polarization setup.

7 . The intrusion detection system of claim 1 , wherein the determination includes:

determining a prior traffic attribute for the VSAT during a prior period of time; and

determining a current traffic attribute for the VSAT during a current period of time,

wherein the confidence score is based on a difference between the prior traffic attribute and the current traffic attribute, and

wherein the prior traffic attribute and the current traffic attribute include one or more of a relative composition of IP packet types, and an amount of traffic latency.

8 . The intrusion detection system of claim 1 , wherein the determination includes:

determining a prior pattern of life for the VSAT during a prior period of time; and

determining a current pattern of life for the VSAT during a current period of time,

wherein the confidence score is based on a difference between the prior pattern of life and the current pattern of life, and

wherein the prior pattern of life and the current pattern of life include one or more of a pattern of operating time and down time of the VSAT, and a pattern of IP traffic transmission of the VSAT.

9 . The intrusion detection system of claim 1 ,

wherein the intrusion detection database is populated with satellite footprint data and/or weather data, and

wherein the determination includes:

determining an actual noise value for the VSAT during a period of time; and

determining an expected noise value for the VSAT during the period of time, taking into account the satellite footprint data and/or the weather data,

wherein the confidence score is based on a difference between the actual noise value and the expected noise value, and

wherein the actual noise value and the expected noise value are based on a ratio of carrier to noise or carrier to noise density, and/or the weather data pertains to one or more of precipitation, cloudiness, and wind.

10 . The intrusion detection system of claim 1 , wherein the determination is performed by a predictive machine learning model.

11 . The intrusion detection system of claim 1 , wherein the confidence score is a sum of one or more weighted scores each based on a partial score.

12 . A method comprising:

populating, via an intrusion detection database, streaming metrics data obtained from a satellite network management system operably coupled to a hub station;

identifying a very small aperture terminal (VSAT) in the intrusion detection database;

determining, via a trained predictive machine learning model and the streaming metrics data, whether a confidence score providing an indication of authenticity for the identified VSAT meets or exceeds a predetermined threshold; and

updating the intrusion detection database in view of the determination.

13 . The method of claim 12 , wherein the determining step further includes:

detecting the VSAT is in an online state after being in an offline state;

determining a prior transmit power for the VSAT before being in the offline state; and

determining a current transmit power for the VSAT in the online state,

wherein the confidence score is based on a difference between the prior transmit power and the current transmit power.

14 . The method of claim 12 , wherein the determining step further includes:

calculating, for the VSAT, a prior amplitude and a prior frequency of a prior periodic oscillating waveform representing a time-based variation of a timing offset during a prior period of time; and

calculating, for the VSAT, a current amplitude and a current frequency of a current periodic oscillating waveform representing a time-based variation of a timing offset during a current period of time,

wherein the confidence score is based on a difference between the prior amplitude and the current amplitude and/or the prior frequency and the current frequency.

15 . The method of claim 12 , wherein the determining step further includes:

determining a prior operating temperature for the VSAT at a prior period of time; and

determining a current operating temperature for the VSAT at a current period of time,

wherein the confidence score is based on a difference between the prior operating temperature and the current operating temperature and/or lack of a predetermined variation in the current operating temperature.

16 . The method of claim 12 , wherein the determining step further includes:

detecting the VSAT is an online state after being in an offline state;

determining a prior noise value for the VSAT prior to being in the offline state; and

determining a current noise value for the VSAT in the online state,

wherein the confidence score is based on a difference between the prior noise value and the current noise value, and

wherein the prior noise value and the current noise value are based on a ratio of carrier to noise or carrier to noise density.

17 . The method of claim 12 , wherein the determining step further includes:

detecting the VSAT is an online state after being in an offline state;

determining a prior equipment aspect for the VSAT prior to being in the offline state; and

determining a current equipment aspect for the VSAT in the online state,

wherein the confidence score is based on a difference between the prior equipment aspect and the current equipment aspect, and

wherein the prior equipment aspect and the current equipment aspect include one or more of a LAN port identifier, a modem link speed, a modem link state, a sensitivity of clock to temperature variation, and a feedhorn polarization setup.

18 . The method of claim 12 , wherein the determining step further includes:

determining a prior traffic attribute for the VSAT during a prior period of time; and

determining a current traffic attribute for the VSAT during a current period of time,

wherein the confidence score is based on a difference between the prior traffic attribute and the current traffic attribute, and

wherein the prior traffic attribute and the current traffic attribute include one or more of a relative composition of IP packet types, and an amount of traffic latency.

19 . A non-transitory computer readable medium including program instructions which when executed by a processor effectuate:

causing streaming metrics data to be obtained from a satellite network management system;

identifying a very small aperture terminal (VSAT) in an intrusion detection database;

determining, via a trained predictive machine learning model and the streaming metrics data, whether a confidence score providing an indication of authenticity for the identified VSAT meets or exceeds a predetermined threshold; and

updating the intrusion detection database in view of the determination.

20 . The non-transitory computer readable medium of claim 19 , wherein the determining instructions include:

calculating, for the VSAT, a prior amplitude and a prior frequency of a prior periodic oscillating waveform representing a time-based variation of a timing offset during a prior period of time; and

calculating, for the VSAT, a current amplitude and a current frequency of a current periodic oscillating waveform representing a time-based variation of a timing offset during a current period of time,

wherein the confidence score is based on a difference between the prior amplitude and the current amplitude and/or the prior frequency and the current frequency.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 1, 2024
From: DALTON, DANA; MOORE, COLBY
To: SC NETWORKS, INCORPORATED
Reel/Frame 067282/0470 →
Continuity (2)
Provisional Application 63145419 · Feb 3, 2021
Related Publication 20230362173A1 · Nov 9, 2023
References Cited (13)
US 20050251570A1 · Heasman · 2005 [cited by examiner]
US 20150026809A1 · Altman · 2015 [cited by examiner]
US 20160269436A1 · Danielson · 2016 [cited by examiner]
US 20160366170A1 · Bell · 2016 [cited by applicant]
US 20170104658A1 · Sykes · 2017 [cited by applicant]
US 20180124096A1 · Schwartz · 2018 [cited by examiner]
US 20200100113A1 · Rognant · 2020 [cited by examiner]
US 20200412453A1 · Costello · 2020 [cited by examiner]
US 20210051177A1 · White · 2021 [cited by examiner]
EP 2743726A1 · 2014 [cited by examiner]
Bibik, Przemysław, et al. “Problems of detecting unauthorized satellite transmissions from the VSAT terminals.” 2012 Military Communications and Information Systems Conference (MCC). IEEE, 2012. (Year: 2012). [cited by examiner]
Zhu, Jianlong, and ChunFeng Wang. “Satellite networking intrusion detection system design based on deep learning method.” International conference in communications, signal processing, and systems. Singapore: Springer S… [cited by examiner]
Ali Broumandan et al.; “Demonstration of a Multi-Layer Spoofing Detection Implemented in a High Precision GNSS Receiver”; IEEE/Ion Position, Location And Navigation Symposium (Plans), Apr. 2020; pp. 538-547. [cited by applicant]