Detecting denial of service (DoS) attacks on upstream devices based on traffic characteristics
By analyzing the communication service characteristics between radio network nodes and user equipment, and using indicators in the protocol stack to detect DoS attacks, this approach solves the problem of defending against UDP flooding and TCP SYN flooding of IoT devices in existing technologies, achieving a defense effect of rapid response and resource optimization.
Patent Information
- Application Number
- CN202380096278.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-01-27
- Publication Date
- 2025-11-11
AI Technical Summary
Existing technologies are insufficient to effectively detect and defend against distributed denial-of-service (DoS) attacks, especially UDP flooding and TCP SYN flooding attacks targeting IoT devices, which can lead to network resource exhaustion and service interruption.
By analyzing the communication service characteristics between radio network nodes and user equipment, and utilizing service characteristic indicators in the protocol stack, such as PDU size distribution, uplink and downlink service ratio, and PDU duration statistics, the existence of DoS attacks can be detected, and signals can be sent to the radio network nodes to notify them or defensive measures can be taken.
It enables rapid detection and mitigation of DoS attacks at the radio network node level, reduces the attack load on upstream devices, improves the network's defense capabilities and resource utilization efficiency, and reduces the impact on the core network.
Smart Images

Figure CN120937304A_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of detecting denial-of-service (DoS) attacks, and more particularly, to a radio network node that detects DoS attacks against upstream devices based on service characteristics in a protocol stack for a radio access network. Background Technology
[0002] Distributed Denial-of-Service (DDoS) attacks are becoming increasingly common. A DDoS attack is based on an attacker gaining control of a large number of devices connected to the Internet, thus creating a botnet. The increasing prevalence of IoT devices, along with their potential security vulnerabilities and growing capacity, makes them a target for attackers creating botnets capable of launching DDoS attacks against targets residing on the Internet.
[0003] Several types of DDoS attacks exist. One example is a UDP flooding attack. The UDP protocol is commonly used for time-sensitive communications, such as voice, video, and gaming services. However, UDP can be used for flow-based attacks (called UDP flooding attacks) because no communication channel needs to be established to send UDP packets.
[0004] Similar to UDP flooding attacks, TCP SYN (synchronization message) flooding attacks result in high traffic volume, but they have different characteristics.
[0005] Traffic attacks are attacks with a high packet rate that attempt to exhaust the resources of a server and / or network link. UDP flood attacks are a type of DDoS attack in which a large number of UDP packets are sent to the target server with the aim of overwhelming the server's ability to receive, process, and / or respond to UDP packets. Summary of the Invention
[0006] One objective is to improve how to detect DoS attacks.
[0007] According to a first aspect, a method for detecting a denial-of-service (DoS) attack against an upstream device is provided. The method is performed in a radio network node. The method includes: obtaining service characteristics of communication between a user equipment (UE) and the radio network node, wherein the service characteristics are obtained for protocols in a protocol stack used for radio access network (RAN) communication between the UE and the radio network node; and determining, based on the service characteristics, that a DoS attack is being carried out towards an upstream device, wherein the upstream device is located upstream of the radio network node.
[0008] Determining that a DoS attack is in progress may include: identifying traffic volume that indicates a service characteristic exceeding a threshold.
[0009] Determining that a DoS attack is in progress may include: determining that the size distribution of Protocol Data Units (PDUs) in a service feature deviates from a reference size distribution by more than a threshold amount.
[0010] Determining that a DoS attack is in progress may include: determining that the relationship between uplink and downlink services in a service characteristic deviates from a reference value by more than a threshold amount.
[0011] Determining that a DoS attack is in progress may include: determining that the statistical deviation of the duration between PDUs from a reference duration exceeds a threshold amount.
[0012] Duration statistics can include the minimum duration between PDUs, the maximum duration between PDUs, and / or the average duration between PDUs.
[0013] A DoS attack can be determined based on multiple metrics based on business characteristics.
[0014] The method may also include: signaling an alert indicating that a DoS attack is in progress.
[0015] Determining that a DoS attack is in progress can be configured to detect flooding of User Datagram Protocol (UDP) packets.
[0016] Determining that a DoS attack is in progress can be configured to detect a flood of Transmission Control Protocol (TCP) synchronization SYN messages.
[0017] The protocol can be one of the following: Service Data Adaptation Protocol (SDAP), Packet Data Convergence Protocol (PDCP), and Radio Link Control Protocol (RLC).
[0018] Business characteristics can be based on user-plane business.
[0019] According to a second aspect, a radio network node is provided for detecting a denial-of-service (DoS) attack against an upstream device. The radio network node includes: a processor; and a memory storing instructions that, when executed by the processor, cause the radio network node to: obtain service characteristics of communication between a user equipment (UE) and the radio network node, wherein the service characteristics are obtained for protocols in a protocol stack for radio access network (RAN) communication between the UE and the radio network node; and, based on the service characteristics, determine that a DoS attack is being carried out towards an upstream device, wherein the upstream device is located upstream of the radio network node.
[0020] Instructions used to determine that a DoS attack is in progress may include instructions that, when executed by a processor, cause a radio network node to determine the amount of traffic whose traffic characteristics indicate a traffic volume greater than a threshold.
[0021] Instructions used to determine that a DoS attack is in progress may include instructions that, when executed by a processor, cause a radio network node to determine that the size distribution of Protocol Data Units (PDUs) in a service characteristic deviates from a reference size distribution by more than a threshold amount.
[0022] Instructions used to determine that a DoS attack is in progress may include instructions that, when executed by a processor, cause a radio network node to determine that the relationship between uplink and downlink traffic in a service characteristic deviates from a reference value by more than a threshold amount.
[0023] Instructions used to determine that a DoS attack is in progress may include instructions that, when executed by the processor, cause radio network nodes to determine that the statistical deviation of the duration between PDUs from a reference duration exceeds a threshold amount.
[0024] Duration statistics can include the minimum duration between PDUs, the maximum duration between PDUs, and / or the average duration between PDUs.
[0025] Instructions used to determine that a DoS attack is in progress may include instructions that, when executed by a processor, cause a radio network node to determine that a DoS attack is in progress based on multiple metrics based on service characteristics.
[0026] The radio network node may also include instructions that, when executed by the processor, cause the radio network node to signal an alert indicating that a DoS attack is in progress.
[0027] Instructions used to determine when a DoS attack is in progress may include instructions that, when executed by a processor, cause radio network nodes to detect a flood of User Datagram Protocol (UDP) packets.
[0028] Instructions used to determine when a DoS attack is in progress may include instructions that, when executed by a processor, cause radio network nodes to detect a flood of Transmission Control Protocol (TCP) synchronization SYN messages.
[0029] The protocol can be one of the following: Service Data Adaptation Protocol (SDAP), Packet Data Convergence Protocol (PDCP), and Radio Link Control Protocol (RLC).
[0030] Business characteristics can be based on user-plane business.
[0031] According to a third aspect, a computer program is provided for detecting a denial-of-service (DoS) attack against an upstream device. The computer program includes computer program code that, when executed on a radio network node, causes the radio network node to: obtain service characteristics of communication between a user equipment (UE) and the radio network node, wherein the service characteristics are obtained for protocols in a protocol stack used for radio access network (RAN) communication between the UE and the radio network node; and, based on the service characteristics, determine that a DoS attack is being carried out towards an upstream device, wherein the upstream device is located upstream of the radio network node.
[0032] According to a fourth aspect, a computer program product is provided, comprising the computer program as described in the third aspect and a computer-readable device, the computer-readable device including a non-transitory memory in which the computer program is stored.
[0033] Generally, all terms used in the claims shall be interpreted in accordance with their ordinary meaning in the technical field, unless otherwise expressly defined herein. All references to “a / an / the element, device, component, means, step, etc.” shall be openly interpreted as referring to at least one instance of that element, device, component, means, step, etc., unless otherwise expressly stated. The steps of any method disclosed herein need not be performed strictly in the order of disclosure, unless expressly stated otherwise. Attached Figure Description
[0034] Aspects and embodiments will now be described by way of example with reference to the accompanying drawings, in which:
[0035] Figure 1 This is a schematic diagram illustrating an environment in which the embodiments presented herein can be applied;
[0036] Figure 2 This is a schematic diagram illustrating an embodiment of a distributed implementation of radio network nodes;
[0037] Figure 3 The protocol stack is shown, which includes a set of protocols for RAN communication between the UE and radio network nodes;
[0038] Figures 4A to 4B This is a flowchart illustrating an embodiment of a method for detecting DoS attacks against upstream devices;
[0039] Figure 5 It is shown Figure 1 A schematic diagram of the components of a radio network node;
[0040] Figure 6 This illustrates an embodiment. Figure 1 A schematic diagram of the functional modules of a radio network node; and
[0041] Figure 7 An example of a computer program product that includes a computer-readable device is shown. Detailed Implementation
[0042] Various aspects of this disclosure will now be described more fully below with reference to the accompanying drawings, in which certain embodiments of the invention are illustrated. However, these aspects may be embodied in many different forms and should not be construed as limiting; rather, these embodiments are provided by way of example so that this disclosure will be thorough and complete, and will fully convey the scope of all aspects of the invention to those skilled in the art. Throughout the specification, the same numerals denote the same elements.
[0043] According to the embodiments presented herein, a method is provided for detecting traffic-based DoS attacks initiated by compromised UEs (e.g., IoT devices or any other type of UE) connected to a radio access network (RAN). The detection is performed by the radio network node providing the RAN. This detection is achieved by analyzing service characteristics relevant to the UE in question. Packet content is not evaluated; the DoS detection operates without requiring deep packet inspection. This detection allows DoS attacks that have been mitigated by the radio network node, as described in more detail below.
[0044] Figure 1 This is a schematic diagram illustrating an environment in which the embodiments proposed herein can be applied. The cellular communication network 8 includes a core network 3 and one or more radio network nodes 1 (also referred to as base stations) providing RAN for one or more UEs 2.
[0045] Radio network node 1 can be in the form of a radio base station, which is a gNode B (gNB) or an evolved Node B (also known as an eNode B or eNB). Radio network nodes can also take the form of Node B, BTS (Base Transceiver Station), and / or BSS (Base Station Subsystem), etc. Radio network node 1 uses the RAN to provide radio connectivity to one or more UE 2 devices on radio interfaces 4a-4b. Radio network node 1 can be implemented as a single hardware device or distributed across several devices, such as... Figure 2 As shown and explained below.
[0046] On the RAN's radio interface, downlink (DL) communication 4a occurs from radio network node 1 to UE 2, and uplink (UL) communication 4b occurs from UE 2 to radio network node 1. Due to factors such as attenuation, multipath propagation, and interference, the quality of the radio interface with each UE 2 can vary over time and depending on the location of UE 2.
[0047] The term "UE" is also known as mobile communication terminal, user equipment, mobile terminal, user terminal, user agent, wireless device, wireless terminal, machine-to-machine device, etc., and can be implemented by devices such as mobile phones, smartphones, IoT devices, or tablet / laptop computers with wireless connectivity.
[0048] Cellular communication network 8 may, for example, conform to any one or a combination of the following: 5G NR (Fifth Generation New Radio), LTE (Long Term Evolution), Advanced LTE, 6G (Sixth Generation), W-CDMA (Wideband Code Division Multiplexing), or any other current or future wireless network, provided that the principles described herein are applicable.
[0049] Radio network node 1 is connected to core network 3 for connectivity to network center functions and wide area network 9 (e.g., the Internet). Server 5 is also connected to the network. User plane and control plane data are transmitted via RAN's UL and DL links 4a / 4b.
[0050] An attacker could gain control of UE 2 to orchestrate a denial-of-service (DoS) attack, for example, targeting nodes and / or server 5 in the core network 3. When multiple devices (such as UE 2) are used in the same attack, it is called a distributed DoS (DDoS) attack. Although each UE 2 can be part of a DDoS attack in this way, it will be referred to as a DoS attack below.
[0051] When UE 2 has been compromised for a DoS purpose, this UE is referred to as a DoS UE. One form of DoS attack is UDP flooding, in which the attacker controls DoS UE 2 to send a large number of UDP packets to the target device. Another type of DoS attack is TCP SYN flooding. This attack works in the same way as UDP flooding because TCP SYN messages are the initial messages for establishing a TCP connection and can be sent to the server before the TCP connection is established and still adhere to the TCP protocol. This can be attractive from the attacker's perspective because both UDP packets and TCP SYN packets can be sent from the compromised UE, and these packets can be arbitrarily repeated. Both UDP flooding and TCP SYN flooding attacks are known as traffic attacks.
[0052] According to the embodiments presented herein, radio network node 1 detects a DoS attack against an upstream node (e.g., a node in core network 3 or server 5), wherein the DoS attack is (at least in part) based on traffic from UE 2. An upstream node will be interpreted as a node located more centrally than radio network node 1, i.e., in a different topological direction from the viewpoint of radio network node 1 and / or in the same topological direction as the core network or wide area network.
[0053] Figure 2 This is a schematic diagram illustrating an embodiment of a distributed implementation of radio network node 1. Radio network node 1 includes baseband node 6 and radio node 7.
[0054] Radio network node 1 includes a baseband node 10 as a baseband processing unit and one or more remote radio nodes 11. When applied in an O-RAN (Open RAN) architecture, the baseband node can be an O-DU (O-RAN Distributed Unit) node, and the radio node can be an O-RU (O-RAN Radio Unit) node. In 5G terminology, for example, according to a C-RAN (Centralized / Cloud Radio Access Network) architecture, the baseband node 10 can be a gNB-CU, and the radio node 11 can be a gNB-DU.
[0055] Baseband node 10 and radio node 11 can be located in different locations. Baseband node 10 is upstream of radio node 11, i.e., facing the core network 3. Therefore, radio node 11 can be downstream of baseband node 10, facing UE 2. One or more fronthaul links 18 exist between baseband node 10 and radio node 11. Fronthaul links 18 are bidirectional communication links. Fronthaul links 18 can be implemented using Common Public Radio Interface (CPRI) or eCPRI (evolved CPRI) and Ethernet. Multiple fronthaul links can be used in conjunction with... Figure 1 The topology shown is different from other topologies used. Multiple fronthaul links can also be represented as a fronthaul network. Baseband node 10 and radio node 11 can each implement a subset of RAN functions for radio communication with UE 2. In addition, some functions for radio communication can be virtualized, also known as cloud RAN.
[0056] Figure 3 Protocol stack 20 is shown, which includes Figure 1 A set of protocols 21, 22, 23, and 24 are used for RAN communication between UE 2 and radio network node 1. Protocol stack 20 is shown here for transmitting IP packets 10 over the RAN. The protocol stack includes Service Data Adaptation Protocol (SDAP) 21, Packet Data Convergence Protocol (PDCP) 22, and Radio Link Control (RLC) 23. At the lowest level, there is Media Access Control (MAC) protocol 24.
[0057] Each protocol 21-24 obtains Service Data Units (SDUs) 10, 11, 12, and 13 from a higher protocol layer to form payloads 11a, 12a, 13a, and 14a. Then, protocols 21-24 add protocol-specific control data, such as headers 11b, 12b, 13b, and 14b, to produce the corresponding Protocol Data Units (PDUs) 11, 12, 13, and 14. The PDUs are then provided to the next lower layer in the protocol stack 20 to form the SDUs used at that layer.
[0058] MAC layer 24 can combine multiple SDUs from RLC layer 23 into a single PDU 14 (including individual payloads 14a, 14'a and headers 14b, 14'b). In other words, a MAC PDU transport block is formed by one or more MAC PDUs. For SDAP, PDCP, and RLC, there is a one-to-one relationship between PDUs 11, 12, and 13 and IP packets 10.
[0059] Figures 4A to 4B This demonstrates the use of detection for upstream devices (such as...) Figure 1 A flowchart illustrating an embodiment of a DoS attack method targeting the core network 3 or server 5. The method is executed in radio network node 1. First, the method described by... Figure 4A The illustrated embodiment.
[0060] In step 40, which obtains service characteristics, radio network node 1 obtains service characteristics regarding the communication between UE 2 and radio network node 1. These service characteristics are protocols 21, 22, 23, and 24 (see [link to protocol stack 20]) in the protocol stack 20 used for RAN communication between UE 2 and radio network node 1. Figure 3 The service characteristics are obtained from one or more metrics derived from services occurring between UE 2 and radio network node 1 in the UL and / or DL. The protocol can be one of SDAP, PDCP, and RLC.
[0061] In one embodiment, the service characteristics include a metric that measures the duration between PDUs. The duration metric may include, for example, the minimum duration between PDUs, the maximum duration between PDUs, and / or the average duration between PDUs.
[0062] The service characteristics are based on user plane services, i.e., not RAN control plane services. User plane services may occur, for example, on the Uu interface provided by radio network node 1 to the UE. However, user plane services may include control signaling for higher protocols, such as TCP SYN messages. In any case, the embodiments presented herein do not rely on inspection of packet content.
[0063] In step 42 of the conditional DoS attack, radio network node 1 determines, based on service characteristics, whether a DoS attack is currently being carried out towards upstream device 3. The upstream device is located outside of radio network node 1 and is positioned upstream of radio network node 1.
[0064] DoS attacks can be detected based on traffic characteristics that indicate traffic volume exceeding a threshold. Traffic volume can be defined, for example, as the number of packets per unit of time (PDU), such as the number of packets per second.
[0065] One simulated example is a UDP flood attack generated from a DoS UE using a compute-constrained device such as a Raspberry Pi. In this simulation, the DoS UE can generate 4,504 PDCP PDUs. When retrieving web pages using the HTTP protocol, the number of PDCP PDUs generated is approximately 848 UL PDCP PDUs (this, of course, depends on the web page and its content, as well as the number of web pages rendered simultaneously). For IoT use cases, the UE generates 192 UL PDCP PDUs per second. Therefore, it is clear that in a DoS scenario, the UE generates significantly more traffic. The threshold can then be configured to a suitable number of PDUs per second.
[0066] Alternatively or additionally, DoS attacks can be detected based on determining that the size distribution of PDUs in a given business characteristic deviates from a reference size distribution by an amount exceeding a threshold. The size distribution can be measured, for example, using the standard deviation of PDUs or any other suitable measure of variation. When a DoS attack occurs, packets are typically very consistent in size, or even completely unchanged. In contrast, for normal business operations, packet sizes vary considerably.
[0067] Alternatively or additionally, DoS attacks can be detected based on determining that the relationship (e.g., ratio) between UL and DL services in a given service characteristic deviates from a reference value by a threshold amount. The relationship between UL and DL services can be expressed, for example, as the ratio between them, or the proportion of DL (or UL) services among all services. In a DoS attack, some upstream targets may not be responsive or may not even exist. Another possibility is that the IP address exists, but there is no service listening on the UDP port corresponding to the UDP packets of the DoS attack. Another possibility is that the source IP address of the upstream packet is spoofed, and return traffic from the upstream target is redirected to the spoofed IP address. Even if the upstream target is listening on the UDP port of the UDP packet, the target may not respond. In any case, the ratio between UL and DL packets is significantly higher in a DoS attack compared to regular services.
[0068] Alternatively or additionally, DoS attacks can be detected based on determining that the statistical deviation of the duration between PDUs exceeds a threshold. For example, for high packet rate services, i.e., in the case of a DoS attack, the time difference between packets will be very low. Therefore, by assessing the duration between PDUs, it is possible to deduce whether the uplink service is part of a DoS attack.
[0069] As mentioned above, an RLC PDU can contain one or more PDCP PDUs. This is a characteristic that can be used as an indicator of a DoS attack because high IP packet rates result in shorter intervals between PDCP PDUs, which increases the extent to which multiple PDCP PDUs can be cascaded within a single RLC PDU. This can be detected using the distribution of RLC PDU sizes over a given time period.
[0070] Alternatively or additionally, DoS attacks can be detected based on multiple metrics based on business characteristics. By combining multiple metrics, higher accuracy in DoS detection can be achieved.
[0071] Radio network node 1 can be configured to detect any traffic-based DoS attacks, such as flooding of UDP packets and / or flooding of TCP SYN messages.
[0072] If a DoS attack is not identified, the method returns to step 40, which involves obtaining business characteristics. If a DoS attack is identified, it can be used internally or externally, after which the method can either terminate or return to step 40, which involves obtaining business characteristics.
[0073] Now see Figure 4B ,and Figure 4A In contrast, only new or modified steps will be described.
[0074] In the optional signaling attack step 44, radio network node 1 signals an alert indicating that a DoS attack is in progress.
[0075] This signaling notification can occur locally within radio network node 1. In this scenario, radio network node 1 can act as a PEP (Policy Enforcement Point), for example, by denying (or restricting) radio resources for the DoS UE. Therefore, the DoS UE has no radio access, which prevents the DoS UE from sending any (or excessive) traffic. This provides a rapid response to detected attacks. Since the embodiments presented herein are implemented in radio network node 1, this node has scheduling capabilities, enabling rapid and effective response and mitigation of attacks.
[0076] Alternatively or additionally, a signal is sent notifying that a DoS attack is occurring from radio network node 1 to core network 3. In this case, radio network node 1 acts as the policy decision point (PDP), while network nodes within the core network act as the PEP. For example, the access and mobility management function (AMF) of the core network can act as the PEP. Thus, the AMF can take action using alerts, attack information, and DoS UE information provided from radio network node 1, and respond to the DoS UE by, for example, deregistering or isolating the DoS UE from the network.
[0077] The results of a simulation used to illustrate how a DoS attack can be detected will now be described. The simulated DoS attack is a UDP flood attack; however, the same principles apply to TCP SYN floods or other traffic-based DoS attacks. In the simulation, the UE is a Raspberry Pi, acting as a DoS UE in the form of an IoT controller, typically communicating with a robotic arm.
[0078] The UE has a specific service mode for benign services. This benign service has the following characteristics:
[0079] TCP protocol services send packets to the robot arm.
[0080] A packet of 160-320 bytes is sent every 10 milliseconds.
[0081] Several packets of 1514 bytes each are sent every 200-500 milliseconds.
[0082] Furthermore, the UE was simulated in a mixed-service scenario to send UDP flood attacks within a specific time period. Therefore, malicious and benign services were mixed over time. The simulation was configured to run for 30 seconds, with the attack period running for 10 seconds in the middle of the 30 seconds, targeting the / 24 subnet. The results were compared with those obtained by running only benign services.
[0083] First, a simulation with only benign business operations is described. The distribution of PDCP PDU sizes follows the business specifications of the use cases mentioned above. The minimum duration between PDCP PDUs is 0.018 milliseconds, the maximum duration is 241 milliseconds, and the average duration is 9.7 milliseconds. Furthermore, the total number of UL PDCP PDUs is 3126, and the ratio between UL PDCPs and DL PDCPs is 3126:2697. Therefore, UL PDCP PDUs constitute 54% of the total business operations, compared to 46% of DL PDCPs.
[0084] The results of a simulation of a mixed traffic flow, including both benign and malicious traffic, are now presented. The experiment ran for 30 seconds, with 10 seconds containing an attack with malicious traffic. The benign traffic type is the same as the benign traffic described above. The malicious traffic targets the / 24 subnet, where several targets respond on the service of interest. The UDP payload is set to a size of 512 bytes.
[0085] The PDCP PDU size distribution changed during the malicious traffic. Specifically, due to the uniform packet size of the UDP flood packets, the PDCP PDU size distribution (e.g., standard deviation) decreased significantly during the attack. Furthermore, the minimum time interval between PDCP PDUs decreased to 0.014 milliseconds during the attack, as the attacker sought to maximize the output of the UDP flood packets. Regarding the relationship between UL and DL traffic, during the attack, the number of PDCP UL PDUs increased to 46,807, constituting 89% of the total traffic, while the count of PDCP DL PDUs was 5,850, thus constituting only 11% of the total traffic. Therefore, it can be seen that the proportion of UL traffic increased significantly during the attack.
[0086] The embodiments presented herein do not inspect or analyze any IP packets being carried in the radio protocol. Instead, they inspect and analyze metrics of service characteristics. This enables DoS attack detection even when IP packets are hidden or obscured to radio network node 1, for example, through encryption.
[0087] Since the DoS attack is detected by radio network node 1, which is close to the compromised UE in the topology, the DoS attack can be detected faster and resolved better.
[0088] The detection capabilities of radio network node 1 also enable it to apply local response and mitigation actions. For example, in addition to mitigating attacks on upstream target devices, radio network node 1 can deny radio resources to DoS UEs, reducing the impact of DoS UEs on the RAN. Furthermore, telecommunications infrastructure can be protected, for example, by reducing or eliminating DoS traffic that might otherwise consume bandwidth from the backhaul network to the core network. Moreover, the embodiments presented herein address scalability issues in the network, thereby reducing the need for additional DoS detection solutions.
[0089] Figure 5 It is shown Figure 1A schematic diagram of the components of radio network node 1. A processor 60 capable of executing software instructions 67 stored in memory 64 is provided using any combination of one or more suitable central processing units (CPUs), graphics processing units (GPUs), multiprocessors, neural processing units (NPUs), microcontrollers, digital signal processors (DSPs), etc., which can therefore be a computer program product. The processor 60 can alternatively be implemented using application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), etc. The processor 60 can be configured to execute the above-referenced... Figure 4A and 4B The method described.
[0090] The memory 64 may be any combination of random access memory (RAM) and / or read-only memory (ROM). The memory 64 also includes non-transitory permanent storage devices, which may be any one or a combination of magnetic storage, optical storage, solid-state storage, or even remotely mounted storage.
[0091] A data memory 66 is also provided for reading and / or storing data during the execution of software instructions in the processor 60. The data memory 66 may be any combination of RAM and / or ROM.
[0092] Radio network node 1 also includes an I / O interface 62 for communicating with external and / or internal entities. Optionally, the I / O interface 62 also includes a user interface.
[0093] The transceiver 61 includes suitable analog and digital components to allow signal transmission and reception with the UE using one or more antennas 63.
[0094] Other components of radio network node 1 are omitted to avoid obscuring the concepts presented herein.
[0095] Figure 6 This illustrates an embodiment. Figure 1 A schematic diagram of the functional modules of radio network node 1. Modules are implemented using software instructions, such as computer programs executed in radio network node 1. Alternatively or additionally, modules are implemented using hardware, such as any one or more of an ASIC (Application-Specific Integrated Circuit), FPGA (Field-Programmable Gate Array), or discrete logic circuits. These modules correspond to... Figure 4A and Figure 4B The steps in the method shown.
[0096] The business characteristic acquirer 70 corresponds to step 40. The DoS attack determiner 72 corresponds to step 42, and the attack signal notifyr 74 corresponds to step 44.
[0097] Figure 7An example of a computer program product 90 including a computer-readable device is shown. On this computer-readable device, the computer program 91 can be stored in non-transitory memory. The computer program can cause a processor to perform methods according to the embodiments described herein. In this example, the computer program product takes the form of removable solid-state memory, such as a Universal Serial Bus (USB) drive. As mentioned above, the computer program product can also be embodied in the memory of a device, for example... Figure 5 Computer program product 64. Although computer program 91 is schematically shown herein as part of a removable solid-state storage device, the computer program may be stored in any manner suitable for a computer program product, such as another type of removable solid-state storage device or optical disc, such as CD (optical disc), DVD (digital versatile disc) or Blu-ray disc.
[0098] The aspects of this disclosure have been described above with reference to several embodiments. However, it will be readily understood by those skilled in the art that other embodiments besides those disclosed above are possible within the scope of the invention as defined by the appended claims. Therefore, while various aspects and embodiments have been disclosed herein, other aspects and embodiments will be apparent to those skilled in the art. The various aspects and embodiments disclosed herein are for illustrative purposes and not intended to be limiting, and the true scope and spirit are indicated by the appended claims.
Claims
1. A method for detecting a denial-of-service (DoS) attack against upstream devices (3, 5), the method being performed in a radio network node (1), the method comprising: Obtain (40) service characteristics of communication between the user equipment (2) UE and the radio network node (1), wherein the service characteristics are obtained for protocols (21, 22, 23, 24) in the protocol stack (20) for radio access network (RAN) communication between the UE (2) and the radio network node (1); and Based on the business characteristics, it is determined that (42) a DoS attack is being carried out toward the upstream device (3, 5), wherein the upstream device (3, 5) is located upstream of the radio network node (1).
2. The method according to claim 1, wherein, Determining (42) that a DoS attack is in progress includes: determining the volume of traffic that the service characteristics indicate is greater than a threshold volume.
3. The method according to claim 1 or 2, wherein, Determining (42) that a DoS attack is in progress includes: determining that the size distribution of Protocol Data Units (PDUs) in the service characteristics deviates from the reference size distribution by more than a threshold amount.
4. The method according to any one of the preceding claims, wherein, Determining (42) that a DoS attack is in progress includes: determining that the relationship between the uplink service and the downlink service in the service characteristics deviates from the reference value by more than a threshold amount.
5. The method according to any one of the preceding claims, wherein, Determining (42) that a DoS attack is in progress includes: determining that the statistical deviation of the duration between PDUs exceeds the threshold amount.
6. The method according to claim 5, wherein, The duration statistics include the minimum duration between PDUs, the maximum duration between PDUs, and / or the average duration between PDUs.
7. The method according to any one of the preceding claims, wherein, The determination (42) that a DoS attack is in progress is based on multiple metrics based on the business characteristics stated therein.
8. The method according to any one of the preceding claims further comprises: Signal notification (44) to indicate that the DoS attack is in progress.
9. The method according to any one of the preceding claims, wherein, The determination (42) DoS attack in progress was configured to detect the flooding of User Datagram Protocol (UDP) packets.
10. The method according to any one of the preceding claims, wherein, The determination (42) DoS attack in progress was configured to detect the flooding of Transmission Control Protocol TCP Synchronization SYN messages.
11. The method according to any one of the preceding claims, wherein, The protocol in question is one of the following: Service Data Adaptation Protocol (SDAP), Packet Data Convergence Protocol (PDCP), and Radio Link Control Protocol (RLC).
12. The method according to any one of the preceding claims, wherein, The aforementioned business characteristics are based on user-plane services.
13. A radio network node (1) for detecting denial-of-service (DoS) attacks against upstream devices (3, 5), the radio network node (1) comprising: Processor (60); as well as Memory (64), which stores instructions (67) that, when executed by the processor, cause the radio network node (1) to: Obtain service characteristics of communication between the user equipment (2) UE and the radio network node (1), wherein the service characteristics are obtained for protocols (21, 22, 23, 24) in the protocol stack (20) for radio access network (RAN) communication between the UE (2) and the radio network node (1); and Based on the aforementioned service characteristics, it is determined that a DoS attack is being carried out towards the upstream devices (3, 5), wherein the upstream devices (3, 5) are located upstream of the radio network node (1).
14. The radio network node (1) according to claim 13, wherein, Instructions for determining that a DoS attack is in progress include instructions (67) that, when executed by the processor, cause the radio network node (1) to determine the traffic volume indicating that the traffic characteristics are greater than a threshold traffic volume.
15. The radio network node (1) according to claim 13 or 14, wherein, Instructions for determining that a DoS attack is in progress include instructions (67) that, when executed by the processor, cause the radio network node (1) to determine that the size distribution of Protocol Data Units (PDUs) in the service feature deviates from the reference size distribution by more than a threshold amount.
16. The radio network node (1) according to any one of claims 13 to 15, wherein, Instructions for determining that a DoS attack is in progress include instructions (67) that, when executed by the processor, cause the radio network node (1) to determine that the relationship between the uplink and downlink services in the service characteristics deviates from a reference value by more than a threshold amount.
17. The radio network node (1) according to any one of claims 13 to 16, wherein, Instructions for determining that a DoS attack is in progress include instructions (67) that, when executed by the processor, cause the radio network node (1) to determine that the statistical deviation of the duration between PDUs exceeds a threshold amount.
18. The radio network node (1) according to claim 17, wherein, The duration statistics include the minimum duration between PDUs, the maximum duration between PDUs, and / or the average duration between PDUs.
19. The radio network node (1) according to any one of claims 13 to 18, wherein, Instructions for determining that a DoS attack is in progress include instructions (67) that, when executed by the processor, cause the radio network node (1) to determine that a DoS attack is in progress based on multiple metrics based on the service characteristics.
20. The radio network node (1) according to any one of claims 13 to 19 further includes an instruction (67) that, when executed by the processor, causes the radio network node (1) to signal an alert indicating that the DoS attack is in progress.
21. The radio network node (1) according to any one of claims 13 to 20, wherein, Instructions for determining that a DoS attack is in progress include instructions (67) that, when executed by the processor, cause the radio network node (1) to detect a flood of User Datagram Protocol (UDP) packets.
22. The radio network node (1) according to any one of claims 13 to 21, wherein, Instructions for determining that a DoS attack is in progress include instructions (67) that, when executed by the processor, cause the radio network node (1) to detect a flood of Transmission Control Protocol TCP Synchronization SYN messages.
23. The radio network node (1) according to any one of claims 13 to 22, wherein, The protocol in question is one of the following: Service Data Adaptation Protocol (SDAP), Packet Data Convergence Protocol (PDCP), and Radio Link Control Protocol (RLC).
24. The radio network node (1) according to any one of claims 13 to 23, wherein, The aforementioned business characteristics are based on user-plane services.
25. A computer program (67, 91) for detecting denial-of-service (DoS) attacks against upstream devices (3, 5), the computer program comprising computer program code that, when executed on a radio network node (1), causes the radio network node (1) to: Obtain service characteristics regarding the communication between the user equipment (2) UE and the radio network node (1), wherein, The service characteristics are obtained for protocols (21, 22, 23, 24) in the protocol stack (20) for radio access network (RAN) communication between the UE (2) and the radio network node (1); and Based on the aforementioned service characteristics, it is determined that a DoS attack is being carried out towards the upstream devices (3, 5), wherein the upstream devices (3, 5) are located upstream of the radio network node (1).
26. A computer program product (64, 90) comprising the computer program of claim 25 and a computer-readable device, the computer-readable device comprising a non-transitory memory in which the computer program is stored.