LOCATION-BASED IDENTIFICATION OF POTENTIAL SECURITY THREAT

In one example, a firewall obtains a first network packet that indicates a first mobile country code of a mobile subscriber at a first time and a first mobile network code of the mobile subscriber at the first time. The firewall obtains a second network packet that indicates a second mobile country...

Ausführliche Beschreibung

Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: THAI HIEN, NAIR PRAMOD, BEUMER HIDDE, TENG ANDREW
Format: Patent
Sprache:chi ; eng
Schlagworte:
Online-Zugang:Volltext bestellen
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
Beschreibung
Zusammenfassung:In one example, a firewall obtains a first network packet that indicates a first mobile country code of a mobile subscriber at a first time and a first mobile network code of the mobile subscriber at the first time. The firewall obtains a second network packet that indicates a second mobile country code of the mobile subscriber at a second time and a second mobile network code of the mobile subscriber at the second time. The firewall determines whether the first mobile country code is different from the second mobile country code or the first mobile network code is different from the second mobile network code. If so, the firewall determines whether a difference between the second time and the first time is less than a threshold difference. If so, the firewall associates the second network packet with a potential security threat. 在一个示例中,防火墙获取第一网络分组,该第一网络分组指示移动订户在第一时间的第一移动国家码以及移动订户在第一时间的第一移动网络码。防火墙获取第二网络分组,该第二网络分组指示移动订户在第二时间的第二移动国家码以及移动订户在第二时间的第二移动网络码。防火墙确定是否第一移动国家码与第二移动国家码不同或者第一移动网络码与第二移动网络码不同。如果是,则防火墙确定第二时间与