System and method for detecting GTP (GPRS Tunnel Protocol) attack
A technology of attacking packets and monitoring units, applied in transmission systems, electrical components, wireless communications, etc., can solve problems such as service interruption, firewalls that cannot filter GTP attacks, disconnection, etc., to achieve the effect of resisting GTP attacks
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
Embodiment 1
[0037] The system for detecting GTP attacks provided by this embodiment is mainly used for in-depth detection of GTP layer features of GTP control plane data packets, and its internal structure is as follows: image 3 As shown, that is, in the present embodiment, the above-mentioned GTP feature information monitoring unit 1 includes: a GTP monitoring module 11, which is used to monitor the GTP control plane data packet on the Gp interface of the GPRS network, and record the GTP control plane data packet monitored. GTP layer characteristics.
[0038] At this point, the GTP attack analysis and alarm unit 2 includes: a first judging module 21 for judging whether the monitored GTP control plane data packet is a GTP attack packet according to the GTP layer characteristics of the GTP control plane data packet reported by the GTP monitoring module 11.
[0039] Specifically, the above-mentioned GTP monitoring module 11 can capture the GTP control plane data packet on the Gp interface ...
Embodiment 2
[0065] The system for detecting GTP attacks provided by this embodiment is mainly used for in-depth detection of IP layer characteristics of GTP control plane data packets, and its internal structure is as follows: Figure 5 As shown, that is, in the present embodiment, the above-mentioned GTP characteristic information monitoring unit 1 includes: an IP monitoring module 12, which is used to monitor the GTP control plane data packets on the Gp interface of the GPRS network, and record the monitored GTP control plane data packets IP layer characteristics.
[0066] At this point, the GTP attack analysis and alarm unit 2 includes: a second judging module 22 for judging whether the monitored GTP control plane data packets are GTP attack packets according to the IP layer characteristics of the GTP control plane data packets reported by the IP monitoring module 12.
[0067] Specifically, the above-mentioned IP monitoring module 12 can capture the GTP control plane data packet on the...
Embodiment 3
[0080] The system for detecting GTP attacks provided by this embodiment is mainly used for in-depth detection of the flow behavior of GTP control plane data packets, and its internal structure is as follows: Figure 7 As shown, that is, in the present embodiment, the above-mentioned GTP characteristic information monitoring unit 1 includes: a traffic behavior monitoring module 13, which is used to monitor the GTP control plane data packets on the Gp interface of the GPRS network, and record the monitored GTP control plane data packets traffic behavior characteristics.
[0081] At this point, the GTP attack analysis and alarm unit 2 includes: a third judging module 23, for judging whether the monitored GTP control plane data packet is a GTP attack according to the traffic behavior characteristics of the GTP control plane data packet reported by the traffic behavior monitoring module 13 Bag.
[0082] Wherein, the traffic behavior monitoring module 13 calculates the sending freq...
PUM
Abstract
Description
Claims
Application Information
- R&D Engineer
- R&D Manager
- IP Professional
- Industry Leading Data Capabilities
- Powerful AI technology
- Patent DNA Extraction
Browse by: Latest US Patents, China's latest patents, Technical Efficacy Thesaurus, Application Domain, Technology Topic, Popular Technical Reports.
© 2024 PatSnap. All rights reserved.Legal|Privacy policy|Modern Slavery Act Transparency Statement|Sitemap|About US| Contact US: help@patsnap.com