12-08-2021 дата публикации
Номер: US20210250381A1
Принадлежит:
Techniques for location based security in service provider networks (e.g., service provider networks for mobile subscribers) are disclosed. A system/process/computer program product for location based security in service provider networks includes monitoring network traffic on a service provider network at a security platform to identify a location for a new session; associating the location with the new session at the security platform; and determining a security policy to apply at the security platform to the new session based on the location. 1. A system , comprising: [ identify, within the network traffic in a mobile network, a create Packet Data Protocol (PDP) request message or a create session request message to create the new session; and', 'extract the location and the device identifier from the create PDP request message or the create session request message, wherein the location is a location identifier, and wherein the location identifier includes a Cell Global Identifier (CGI), Service Area Identifier (SAI), Routing Area Identifier (RAI), Tracking Area Identifier (TAI), E-UTRAN Cell Global Identifier (ECGI), Location Area Identifier (LAC), or any combination thereof;, 'monitor network traffic on a service provider network at a security platform to identify a location and a device identifier for a new session, comprising, 'monitor, via deep packet inspection, tunneled user traffic after the new session has been created to obtain the application identifier, wherein the application identifier relates to web browsing using HyperText Transfer Protocol (HTTP), a Domain Name System (DNS) request, a file transfer using File Transfer Protocol (FTP), Telnet, Dynamic Host Configuration Protocol (DHCP), Transmission Control Protocol (TCP), User Datagram Protocol (UDP), Trivial File Transfer Protocol (TFTP), or any combination thereof, and wherein the tunneled user traffic includes GPRS Tunneling Protocol User Plane (GTP-U) traffic;', 'determine an application ...
Подробнее