×

Systems and methods for identifying message payload bit fields in electronic communications

  • US 9,906,545 B1
  • Filed: 11/22/2016
  • Issued: 02/27/2018
  • Est. Priority Date: 11/22/2016
  • Status: Active Grant
First Claim
Patent Images

1. A computer-implemented method for identifying message payload bit fields in electronic communications, at least a portion of the method being performed by a computing device comprising at least one processor, the method comprising:

  • monitoring, at the computing device, messages transmitted via a network;

    selecting, at the computing device, a plurality of messages transmitted via the network, each of the plurality of messages comprising an identical message identifier corresponding to a specified message type having a payload;

    determining, at the computing device, for each bit position in the payload of the specified message type, a quasi-entropy value based on a proportion of occurrences of a first bit value and a proportion of occurrences of a second bit value at each corresponding bit position in the plurality of messages;

    identifying, at the computing device, at least one continuous bit field based on bit flip rate values in the payload;

    identifying, at the computing device, at least one of a near-random/periodic bit field and a constant bit field within the specified message type based on the determined quasi-entropy values, wherein identifying the near-random/periodic bit field comprises identifying a bit field comprising a plurality of adjacent bit positions each having a quasi-entropy value of 1 and wherein identifying the constant bit field comprise identifying a bit field comprising a plurality of adjacent bit positions each having a quasi-entropy value of 0;

    detecting, at the computing device, at least one additional message of the specified message type transmitted via the network; and

    identifying, at the computing device, at least one anomaly in at least one of the at least one of the near-random/periodic bit field and the constant bit field of the at least one additional message.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×