Scrubber for distributed denial of service attacks targetting mobile networks
Abstract
A device includes a processor and a memory. The processor effectuates operations including receiving signaling messages traversing a first interface or a second interface from the network traffic, translating the signaling messages into one or more events, detecting one or more anomalies by analyzing the one or more events, determining whether the one or more anomalies is indicative of an attack on a telecommunications network and performing a remediation action to the signaling messages resolving the attack when the one or more anomalies is indicative of an attack on the telecommunications network.
Claims
exact text as granted — not AI-modified1 . A device, comprising:
a processor; and a memory coupled with the processor, the memory storing executable instructions that, when executed by the processor, cause the processor to effectuate operations comprising: receiving, from network traffic, first signaling messages traversing a first interface of a core network and second signaling messages traversing a second interface of the core network, wherein the first signaling messages are intercepted by the processor prior to reaching a first function of the core network, and wherein the second signaling messages are intercepted by the processor prior to reaching a second function of the core network; identifying a network attack based on an analysis of the first signaling messages and the second signaling messages; based on the identifying the network attack, performing a remediation action to the first signaling messages and the second signaling messages to resolve the network attack; and sending the first signaling messages to the first function and the second signaling messages to the second function after the performing the remediation action.
2 . The device of claim 1 , wherein the processor is positioned in-line with the first interface and the second interface so as to intercept the first signaling messages and the second signaling messages, wherein the first signaling messages include user equipment (UE) registration and mobility information, and wherein the second signaling messages include user information.
3 . The device of claim 1 , wherein the identifying the network attack comprises identifying one or more anomalies, and wherein the processor further effectuates operations comprising classifying the one or more anomalies according to an attack type and implementing an action policy to perform the remediation action based on the attack type.
4 . The device of claim 3 , wherein the one or more anomalies comprise attaches per day, attaches per device, or attaches per day per equipment type exceeding a predetermined threshold.
5 . The device of claim 1 , wherein the first and second signaling messages are received at an edge router from one or more Internet-of-things (IoT) devices.
6 . The device of claim 1 , wherein the remediation action comprises denying all registration requests of a set of user equipment (UE) of a plurality of UE to connect to a telecommunications network, denying a set of UE of the plurality of UE from connecting to the telecommunications network while allowing another set of UE of the plurality of UE to connect to the telecommunications network, reducing a rate of control messages from the plurality of UE, or blocking attach requests from the plurality of UE associated with a determined attack type.
7 . The device of claim 1 , wherein the network traffic comprises a request to attach to a telecommunications network, a request to re-register to the telecommunications network, a request for authentication information, or a request for resource allocation information.
8 . The device of claim 1 , wherein the first interface is a N1 interface or a S1 interface and the second interface is a N11 interface or a S11 interface.
9 . A computer-implemented method comprising:
obtaining, by a processor, first signaling messages traversing a first interface associated with a first function of a core network and second signaling messages traversing a second interface associated with a second function of the core network, wherein the first signaling messages are intercepted by the processor prior to reaching the first function, and wherein the second signaling messages are intercepted by the processor prior to reaching the second function; determining, by the processor, and based on analyzing the first signaling messages and the second signaling messages, that a network attack is undergoing; responsive to the determining, performing, by the processor, a remediation action to the first signaling messages and the second signaling messages to resolve the network attack; and causing, by the processor, the first signaling messages to be transmitted to the first function and the second signaling messages to be transmitted to the second function.
10 . The computer-implemented method of claim 9 , wherein the first and second signaling messages are included in network traffic, wherein the processor is positioned in-line with the first interface and the second interface so as to intercept the first signaling messages and the second signaling messages, wherein the first signaling messages include user equipment (UE) registration and mobility information, and wherein the second signaling messages include user information.
11 . The computer-implemented method of claim 10 , wherein the network traffic comprises a request to attach to a telecommunications network, a request to re-register to the telecommunications network, a request for authentication information, or a request for resource allocation information.
12 . The computer-implemented method of claim 9 , wherein the determining comprises identifying one or more anomalies, and wherein the computer-implemented method further comprises classifying the one or more anomalies according to an attack type and implementing an action policy to perform the remediation action based on the attack type.
13 . The computer-implemented method of claim 12 , wherein the one or more anomalies comprise attaches per day, attaches per device, or attaches per day per equipment type exceeding a predetermined threshold.
14 . The computer-implemented method of claim 9 , wherein the first and second signaling messages are received at an edge router from one or more Internet-of-things (IoT) devices.
15 . The computer-implemented method of claim 9 , wherein the remediation action comprises denying all registration requests of a set of user equipment (UE) of a plurality of UE to connect to a telecommunications network, denying a set of UE of the plurality of UE from connecting to the telecommunications network while allowing another set of UE of the plurality of UE to connect to the telecommunications network, reducing a rate of control messages from the plurality of UE, or blocking attach requests from the plurality of UE associated with a determined attack type.
16 . The computer-implemented method of claim 9 , wherein the first interface is a N1 interface or a S1 interface and the second interface is a N11 interface or a S11 interface.
17 . A non-transitory computer-readable storage medium storing executable instructions that when executed by a processor causes said processor to effectuate operations comprising:
receiving, from network traffic originating from one or more user equipment (UEs), first signaling messages traversing a first interface associated with a first network function and second signaling messages traversing a second interface associated with a second network function, wherein the first signaling messages are intercepted by the processor prior to reaching the first network function, and wherein the second signaling messages are intercepted by the processor prior to reaching the second network function; identifying a denial-of-service (DoS) attack on a telecommunications network based on an analysis of the first signaling messages and the second signaling messages; performing a remediation action to the first signaling messages and the second signaling messages to resolve the DoS attack; and transmitting the first signaling messages to the first network function and the second signaling messages to the second network function after the performing the remediation action.
18 . The non-transitory computer-readable storage medium of claim 17 , wherein the processor is positioned in-line with the first interface and the second interface so as to intercept the first signaling messages and the second signaling messages, wherein the first signaling messages include UE registration and mobility information, and wherein the second signaling messages include user information.
19 . The non-transitory computer-readable storage medium of claim 17 , wherein the first interface is a N1 interface or a S1 interface and the second interface is a N11 interface or a S11 interface.
20 . The non-transitory computer-readable storage medium of claim 17 , wherein the first and second signaling messages are received at an edge router from one or more Internet-of-things (IoT) devices.Join the waitlist — get patent alerts
Track US2023054030A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.