IP Library › Granted Patent US 12,659,336
Granted Patent B2
US 12,659,336 · App. 18/943,639 · Granted Jun 16, 2026

Web page spectroscopy

Inventors: Arthur L. Zaifman (Millburn, NJ); John Mark Mocenigo (Califon, NJ)
Assignee: AT&T Intellectual Property I, L.P.
H04L63/1425G06F16/955G06N7/01G06N20/00H04L67/125H04L67/535
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,659,336
App. No.
18/943,639
Granted
Jun 16, 2026
Kind
B2
Abstract

Facilitating web page spectroscopy in a communications network is provided herein. A system can comprise a processor and a memory that stores executable instructions that, when executed by the processor, facilitate performance of operations. The operations can comprise receiving first data that describes a first communication packet flow and second data that describes a second communication packet flow. The operations can also comprise training a model based on the first data and the second data, as a result of which the model is trained to detect respective behaviors represented by the first data and the second. Further, the operations can comprise extracting a common parameter from third data that describes a third communication packet flow and fourth data that describes a fourth communication packet flow based on the model.

Claims (40)

1 . A method comprising:

based on first data that describes a first communication packet flow of a user equipment and second data that describes a second communication packet flow of the user equipment, identifying, by a device comprising a processor deployed in a communication network that is distinct from the user equipment, a parameter that is indicative of a behavior of uniform resource locators represented by the first data and the second data, wherein the uniform resource locators correlate to a plurality of different domain name systems, and wherein the behavior indicates a tethering at the user equipment when the behavior indicates overlapping web pages based on the plurality of different domain name systems; and

based on a determination that the tethering is not authorized at the user equipment, disabling, by the device, a tethering capability at the user equipment.

2 . The method of claim 1 , wherein the identifying comprises using a model trained to detect a group of behaviors comprising the behavior that indicates the tethering at the user equipment.

3 . The method of claim 2 , further comprising:

prior to the using the model, training, by the device, the model to detect respective fingerprints of first metadata associated with the first communication packet flow and second metadata associated with the second communication packet flow, wherein the training is based on stored fingerprints of previously analyzed metadata associated with previously received communication packet flows.

4 . The method of claim 1 , further comprising:

prior to the identifying, extracting, by the device, the parameter from the first data and the second data.

5 . The method of claim 1 , wherein the identifying comprises:

identifying the first data based on first fingerprint data of first metadata associated with the first communication packet flow; and

identifying the second data based on second fingerprint data of second metadata associated with the second communication packet flow.

6 . The method of claim 5 , wherein the first fingerprint data and the second fingerprint data comprise respective domain name system signatures of the plurality of different domain name systems that indicate properties determined to be stable properties.

7 . The method of claim 1 , wherein the behavior indicated by the parameter is associated with web page displays, and wherein the method further comprises:

determining, by the device, that overlapping web page displays of the overlapping web pages are associated with the user equipment based on an analysis of respective spectroscopic signatures associated with the web page displays.

8 . The method of claim 7 , wherein the overlapping web page displays comprise a first web page and a second web page, and wherein the respective spectroscopic signatures indicate interactions associated with the overlapping web page displays.

9 . A system comprising:

a processor; and

a memory that stores executable instructions that, when executed by the processor when deployed in a communication network, facilitate performance of operations, the operations comprising:

based on first data that describes a first communication packet flow of a user equipment and second data that describes a second communication packet flow of the user equipment, identifying a parameter that is indicative of a behavior of uniform resource locators represented by the first data and the second data, wherein the uniform resource locators correlate to a plurality of different domain name systems, and wherein the behavior indicates a tethering at the user equipment associated with the first communication packet flow and the second communication packet flow when the behavior indicates overlapping web pages based on the plurality of different domain name systems, wherein the system is distinct from the user equipment; and

based on a determination that the tethering is not authorized at the user equipment, disabling a tethering capability at the user equipment.

10 . The system of claim 9 , wherein the identifying comprises using a model trained to detect a group of behaviors comprising the behavior that indicates the tethering at the user equipment.

11 . The system of claim 10 , the operations further comprising:

prior to the using the model, training the model to detect respective fingerprints of first metadata associated with the first communication packet flow and second metadata associated with the second communication packet flow, wherein the training is based on stored fingerprints of previously analyzed metadata associated with previously received communication packet flows.

12 . The system of claim 9 , the operations further comprising:

prior to the identifying, extracting the parameter from the first data and the second data.

13 . The system of claim 9 , wherein the identifying comprises:

identifying the first data based on first fingerprint data of first metadata associated with the first communication packet flow; and

identifying the second data based on second fingerprint data of second metadata associated with the second communication packet flow.

14 . The system of claim 13 , wherein the first fingerprint data and the second fingerprint data comprise respective domain name system signatures of the plurality of different domain name systems that indicate properties determined to be stable properties.

15 . A non-transitory machine-readable medium, comprising executable instructions that, when executed by a processor when deployed in a communication network, facilitate performance of operations, the operations comprising:

extracting a common parameter from data that describes communication packet flows of a user equipment, wherein the common parameter is associated with uniform resource locators of web page displays and is an indication of concurrent usage via the user equipment, and wherein the uniform resource locators correlate to a plurality of different domain name systems, wherein the processor is distinct from the user equipment;

determining that a tethering is occurring at the user equipment based on a behavior that indicates overlapping web pages based on the plurality of different domain name systems, indicated by the common parameter, wherein the common parameter comprises an indication of overlapping web page displays of the overlapping web pages; and

deactivating the tethering at the user equipment based on the determining and based on the tethering being determined not to be authorized for the user equipment.

16 . The non-transitory machine-readable medium of claim 15 , wherein the overlapping web pages comprise a first web page and a second web page, and wherein respective spectroscopic signatures associated with the web pages indicate interactions associated with the overlapping web pages.

17 . The non-transitory machine-readable medium of claim 15 , wherein the extracting comprises:

identifying respective metadata associated with communication packet flows of the communication packet flows.

18 . The non-transitory machine-readable medium of claim 15 , wherein the extracting comprises:

identifying respective fingerprint data of communication packet flows of the communication packet flows.

19 . The non-transitory machine-readable medium of claim 18 , wherein the respective fingerprint data comprise respective domain name system signatures representative of properties determined to be stable properties.

20 . The non-transitory machine-readable medium of claim 15 , wherein the communication packet flows are packet flows transmitted via a fifth generation network communication protocol.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 17, 2025
From: ZAIFMAN, ARTHUR L.; MOCENIGO, JOHN MARK
To: AT&T INTELLECTUAL PROPERTY I, L.P.
Reel/Frame 070230/0318 →
Continuity (4)
Continuation 18159118 · Jan 25, 2023
Continuation 17061037 · Oct 1, 2020
Continuation 15960713 · Apr 24, 2018
Related Publication 20250071131A1 · Feb 27, 2025
References Cited (70)
US 7828679B2 · Tell et al. · 2010 [cited by applicant]
US 7961917B2 · Black · 2011 [cited by applicant]
US 8142318B2 · Palmer · 2012 [cited by applicant]
US 8985061B2 · Royals · 2015 [cited by applicant]
US 9178241B2 · Davidson et al. · 2015 [cited by applicant]
US 9213990B2 · Adjaoute · 2015 [cited by applicant]
US 9237028B1 · Rai · 2016 [cited by examiner]
US 9369476B2 · Chekina et al. · 2016 [cited by applicant]
US 9672355B2 · Titonis et al. · 2017 [cited by applicant]
US 9710752B2 · Salajegheh et al. · 2017 [cited by applicant]
US 9747603B2 · Foote et al. · 2017 [cited by applicant]
US 9762611B2 · Wallace et al. · 2017 [cited by applicant]
US 9769668B1 · Cui et al. · 2017 [cited by applicant]
US 9774614B2 · Patne et al. · 2017 [cited by applicant]
US 9787695B2 · Gantman et al. · 2017 [cited by applicant]
US 10140824B2 · Schultz · 2018 [cited by examiner]
US 10237183B2 · Srivastav · 2019 [cited by examiner]
US 10387795B1 · Oldridge et al. · 2019 [cited by applicant]
US 10694503B2 · Kiukkonen et al. · 2020 [cited by applicant]
US 20060215886A1 · Black · 2006 [cited by applicant]
US 20090229936A1 · Cuong et al. · 2009 [cited by applicant]
US 20090263438A1 · Melander et al. · 2009 [cited by applicant]
US 20100253476A1 · Poutiatine et al. · 2010 [cited by applicant]
US 20100302233A1 · Holland · 2010 [cited by applicant]
US 20110189743A1 · Yoshikuni et al. · 2011 [cited by applicant]
US 20120026992A1 · Navda et al. · 2012 [cited by applicant]
US 20120240197A1 · Tran et al. · 2012 [cited by applicant]
US 20130021933A1 · Kovvali · 2013 [cited by examiner]
US 20130153335A1 · Luminet · 2013 [cited by examiner]
US 20130159503A1 · Erman · 2013 [cited by examiner]
US 20130199251A1 · Taylor · 2013 [cited by examiner]
US 20140052538A1 · Foote et al. · 2014 [cited by applicant]
US 20140123289A1 · Hsiao et al. · 2014 [cited by applicant]
US 20140269430A1 · Erman et al. · 2014 [cited by applicant]
US 20140279793A1 · Wohlstadter · 2014 [cited by applicant]
US 20140282137A1 · Lin et al. · 2014 [cited by applicant]
US 20150045992A1 · Ashby et al. · 2015 [cited by applicant]
US 20150074197A1 · Brown et al. · 2015 [cited by applicant]
US 20150088760A1 · Meurs · 2015 [cited by applicant]
US 20150112857A1 · Gellis et al. · 2015 [cited by applicant]
US 20150149614A1 · Sinha · 2015 [cited by examiner]
US 20150201444A1 · Kiukkonen et al. · 2015 [cited by applicant]
US 20150220992A1 · Brown et al. · 2015 [cited by applicant]
US 20150242895A1 · Brown et al. · 2015 [cited by applicant]
US 20150262052A1 · Pahuja · 2015 [cited by applicant]
US 20150315581A1 · Han et al. · 2015 [cited by applicant]
US 20150332340A1 · Brown et al. · 2015 [cited by applicant]
US 20160165065A1 · Damstra · 2016 [cited by applicant]
US 20160227404A1 · Kollu et al. · 2016 [cited by applicant]
US 20170020540A1 · Chou et al. · 2017 [cited by applicant]
US 20170222960A1 · Agarwal · 2017 [cited by examiner]
US 20170227995A1 · Lee et al. · 2017 [cited by applicant]
US 20170236320A1 · Gribetz et al. · 2017 [cited by applicant]
US 20170366562A1 · Zhang et al. · 2017 [cited by applicant]
US 20180018590A1 · Szeto et al. · 2018 [cited by applicant]
US 20180090942A1 · Nunez et al. · 2018 [cited by applicant]
US 20180097729A1 · Srivastav · 2018 [cited by examiner]
US 20180242978A1 · Chou et al. · 2018 [cited by applicant]
US 20180292826A1 · DeFelice et al. · 2018 [cited by applicant]
US 20180318716A1 · Benedetto · 2018 [cited by applicant]
US 20190227528A1 · Abbott et al. · 2019 [cited by applicant]
US 20190327254A1 · Zaifman et al. · 2019 [cited by applicant]
US 20200005385A1 · Stout et al. · 2020 [cited by applicant]
US 20210388941A1 · Cheung · 2021 [cited by examiner]
Heath, “How AT&T Recognizes Unauthorized Tethering from Jailbroken iPhones,” May 8, 2011, 3 pages_ http:www.idownloadblog.com/2011/05/08/how-atl-recognizes-unaulhorized-tethering-from-jailbroken-iphones/. [cited by applicant]
Conti el al., “The Dark Side (—Channel) of Mobile Devices: A Survey on Network Traffic Analysis,” Aug. 12, 2017, arXiv:1708.03766v1 [cs.CR], 41 pages. [cited by applicant]
Non-Final Office Action received for U.S. Appl. No. 15/960,713 dated Jan. 10, 2020, 66 pages. [cited by applicant]
Nguyen, “A Survey of Techniques for Internet Traffic Classification using Machine Leaming”, 2008, IEEE. (Year: 2008). [cited by applicant]
Notice of Allowance received for U.S. Appl. No. 15/960,713 dated Jul. 8, 2020, 44 pages. [cited by applicant]
Notice of Allowance received for U.S. Appl. No. 17/061,037 dated Oct. 13, 2022, 58 pages. [cited by applicant]