Estimation device and method for estimation

The estimation device uses Bayesian estimation to differentiate between DDoS attacks and other causes of burst traffic, allowing for precise identification of affected subscriber IDs and enabling effective response strategies.

JP2025108165AActive Publication Date: 2025-07-23INTERNET INITIATIVE JAPAN INC
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024001897
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-01-10
Publication Date
2025-07-23
Estimated Expiration
2044-01-10

AI Technical Summary

Technical Problem

Existing technologies cannot distinguish between burst traffic caused by DDoS attacks and other causes, such as user communication patterns, leading to undifferentiated response strategies.

Method used

An estimation device using Bayesian estimation to calculate posterior distributions based on prior attack probabilities and observation data to determine the occurrence of DDoS attacks, identifying specific subscriber IDs involved in the attacks.

Benefits of technology

Accurately distinguishes between burst traffic caused by DDoS attacks and other factors, enabling targeted response strategies and identifying the source of attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025108165000001_ABST
    Figure 2025108165000001_ABST
Patent Text Reader

Abstract

To determine whether a burst traffic happened due to a specific attack or for another reason.SOLUTION: The present invention includes: a learning unit 14 for calculating, by Bayes' estimation, a posterior distribution showing the occurrence probability of a specific attack under a condition of occurrence of a burst traffic, the occurrence probability being obtained by providing observation data including first observation data and second observation data to a prior distribution showing the probability of occurrence of the specific attack; a determination unit 15 for determining the presence or absence of occurrence of a specific attack on the basis of the calculated value of the posterior distribution; and a presentation unit 17 for presenting the result of determination by the determination unit 15.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an estimation device and an estimation method.

Background Art

[0002] Conventionally, there has been reported an attack in which the IMSIs (International Mobile Subscriber Identities) of a plurality of communication terminals of legitimate users are intercepted, and a large number of location registration request signals are intentionally transmitted to a UDR (Unified Data Repository) to impose a high load (see Non-Patent Document 1). Such a DDoS attack may also cause burst traffic due to intentional location registration request signals.

[0003] Burst traffic due to location registration request signals may occur not only due to DDoS attacks, but also when communication concentrates at a specific time of day due to the usage status and movement of user communication. Regarding the analysis of burst traffic, for example, Patent Document 1 discloses a technique for determining whether or not the pattern of the values of a plurality of parameters included in a call connection request matches the characteristic pattern of a call connection request by application communication.

[0004] However, in the burst traffic analysis technique disclosed in Patent Document 1, although burst traffic caused by a call connection request due to a specific application communication can be identified, it is not possible to distinguish and identify whether the burst traffic is due to a DDoS attack.

Prior Art Documents

Patent Documents

[0005]

Patent Document 1

Non-Patent Documents

[0006]

Non-Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0007] Thus, according to the prior art, when burst traffic occurs, it is impossible to distinguish whether it is caused by a specific attack or by other causes.

[0008] The present invention has been made to solve the above-described problems, and an object thereof is to distinguish whether burst traffic is caused by a specific attack or by other causes when burst traffic occurs.

Means for Solving the Problems

[0009] To solve the above-described problems, an estimation device according to the present invention includes a first acquisition unit configured to acquire first observation data indicating the number of times burst traffic has occurred due to a location registration request signal, and among the occurrences of the burst traffic, the number of times the burst traffic has occurred whose history and trend match the history of the burst traffic that has occurred in the past is acquired as second observation data of burst traffic generated due to causes other than a specific attack on the core network. A second acquisition unit configured to perform the above, a learning unit configured to calculate, by Bayesian estimation, a posterior distribution indicating the occurrence probability of the specific attack under the condition that the burst traffic has occurred, the posterior distribution being obtained by giving the prior distribution of the occurrence probability of the specific attack and the observation data including the first observation data and the second observation data, and a determination unit configured to determine the presence or absence of the occurrence of the specific attack based on the value of the calculated posterior distribution, and a presentation unit configured to present the determination result by the determination unit.

[0010] Also, in the estimation device according to the present invention, further, when it is determined by the determination unit that the specific attack has occurred, from the transmission history of the location registration request signal for each subscriber identification number assigned to the communication terminal, which is stored in the integrated data repository provided in the core network, a specifying unit configured to specify the subscriber identification number involved in the specific attack is provided, and the presentation unit may present information regarding the subscriber identification number specified by the specifying unit.

[0011] In order to solve the above-described problems, the estimation device according to the present invention further includes a collection unit configured to collect, from the core network, the number of the location registration request signals transmitted for each subscriber identification number assigned to the communication terminal, which is the number of the location registration request signals for each set time, and a detection unit configured to detect the occurrence of burst traffic when the number of the location registration request signals for each set time collected exceeds a set number.

[0012] Also, in the estimation device according to the present invention, the specific attack may include an attack that targets a node in the control plane provided in the core network and intentionally transmits a large number of location registration request signals using the subscriber identification numbers of a plurality of communication terminals.

[0013] To solve the above problems, the estimation method according to the present invention includes: a first acquisition step of acquiring first observation data indicating the number of times burst traffic has occurred due to a location registration request signal; a second acquisition step of acquiring, as second observation data of burst traffic generated due to causes other than a specific attack on the core network, the number of times the burst traffic that matches the history and trend of the burst traffic generated in the past has occurred among the occurrences of the burst traffic; a learning step of calculating, by Bayesian estimation, a posterior distribution indicating the occurrence probability of the specific attack under the condition that the burst traffic has occurred, where the occurrence probability of the specific attack is used as a prior distribution and the observation data including the first observation data and the second observation data is given; a determination step of determining the presence or absence of the occurrence of the specific attack based on the value of the calculated posterior distribution; and a presentation step of presenting the determination result in the determination step.

[0014] Further, in the estimation method according to the present invention, when it is determined in the determination step that the specific attack has occurred, a specific step of identifying a subscriber identification number involved in the specific attack from the transmission history of the location registration request signal for each subscriber identification number assigned to a communication terminal, which is stored in an integrated data repository provided in the core network, may be provided, and the presentation step may present information regarding the subscriber identification number identified in the specific step.

[0015] Further, in the estimation method according to the present invention, a collection step of collecting, from the core network, the number of the location registration request signals transmitted for each subscriber identification number assigned to a communication terminal, which is the number of the location registration request signals for each set time, and a detection step of detecting the occurrence of burst traffic when the number of the location registration request signals for each set time collected exceeds a set number may be provided.

Advantages of the Invention

[0016] According to the present invention, the prior distribution is the occurrence probability of a specific attack, and the posterior distribution indicating the occurrence probability of the specific attack under the condition that burst traffic has occurred, which is obtained by providing observation data including first observation data and second observation data, is calculated by Bayesian estimation. Therefore, when burst traffic occurs, it is possible to distinguish whether it is caused by a specific attack or by other causes.

Brief Description of the Drawings

[0017]

Figure 1

Figure 2

Figure 3

Embodiments for Carrying Out the Invention

[0018] Hereinafter, preferred embodiments of the present invention will be described in detail with reference to FIGS. 1 to 3.

[0019] [Configuration of Estimation System] FIG. 1 is a block diagram showing the configuration of an estimation system including an estimation device 1 according to an embodiment of the present invention. The estimation system according to the present embodiment is provided in, for example, a 5G mobile communication network, and includes an estimation device 1, a communication terminal 2, a base station 3, and a core network 4. When burst traffic occurs due to a location registration request signal, the estimation system estimates the presence or absence of a DDoS attack on the core network 4, and further identifies the IMSI that may be involved in the DDoS attack.

[0020] The communication terminal 2 includes a SIM 20 and is realized as a mobile communication terminal such as a smartphone, a tablet computer, a laptop computer, or the like. In the present embodiment, there are a plurality of communication terminals 2.

[0021] The SIM 20 installed in the communication terminal 2 stores the user's contract profile. The contract profile of the SIM 20 stores the user's subscriber identification information, including identifiers such as the IMSI assigned to the mobile phone line contract, the user's phone number (MSISDN: Mobile Subscriber International Subscriber Directory Number), and the SIM card number (ICCID: Integrated Circuit Card Identifier). The communication terminal 2 is uniquely identified by the assigned IMSI.

[0022] The base station 3 is composed of radio base stations compliant with the 5G communication standard and relays communication between the communication terminal 2 present in the communication area and the core network 4. The base station 3 is connected to the core network 4 via a network L such as a backhaul link.

[0023] The core network 4 is connected to the estimation device 1 via a network NW such as a LAN or a WAN. The core network 4 includes an AMF (Access and Mobility Management Function) 40, a UDM (Unified Data Management) 41, and a UDR 42, which are nodes in the control plane (C-plane). The UDR 42 includes a communication interface 42a for communicating with the estimation device 1. Note that other functions of the core network 4 are not shown in the figure.

[0024] The AMF 40 is a node that provides a mobility control function and performs mobility control such as location registration, paging, and handover. The UDM 41 is a node that manages the user's contract information and authentication information.

[0025] UDR42 is a node that stores the subscriber profile holding the IMSI and location information of communication terminal 2. Also, UDR42 stores, as the outgoing call log, the time stamp of the location registration request signal transmitted for each IMSI of communication terminal 2.

[0026] When starting initial registration for communication or when crossing a communication area due to movement, communication terminal 2 transmits a location registration request signal to core network 4 via base station 3 in the communication area where it is located. Also, communication terminal 2 may transmit a location registration request signal to core network 4 via the base station 3 where it is located at a set period such as every second. The location registration request signal includes the IMSI assigned to the transmitting communication terminal 2.

[0027] The location registration request signal transmitted by communication terminal 2 reaches UDR42 via AMF40 and UDM41 from base station 3. When the location registration request signal reaches UDR42, the transmission time stamp of the location registration request signal for each IMSI is recorded, and the address information of AMF40 through which communication terminal 2 passed is written into the location information of the subscriber profile.

[0028] When a certain number or more of location registration request signals are transmitted from multiple communication terminals 2 in the same time zone, the load on the nodes installed in the control plane of core network 4 such as UDR42 may increase, and the processing speed may decrease. In some cases, if the processing capacity of nodes such as UDR42 is exceeded, it may enter a state of function stop.

[0029] The cause of such burst traffic can occur not only due to DDoS attacks but also due to the movement of communication terminal 2 by legitimate users or accidental concentration of communication. For example, burst traffic may occur even when normal mobile communication is being carried out during the morning commuting rush hour or during the day's communication congestion period.

[0030] On the one hand, as described above, burst traffic may occur due to a DDoS attack by the attacking terminal 5. The attacking terminal 5 intercepts the IMSI of the communication terminal 2 and further performs a DDoS attack of sending a large number of location registration request signals to the core network 4 using the intercepted IMSI. In the present embodiment, a specific attack includes a DDoS attack that targets nodes of the control plane included in the core network 4 and intentionally sends a large number of location registration request signals using the IMSIs of a plurality of communication terminals 2. Further, the specific attack includes a DDoS attack that sends a large number of location registration request signals in the same time period.

[0031] The attacking terminal 5, for example, randomly generates a value of an IMSI composed of 15 digits and intercepts the IMSI assigned to a legitimate user's communication terminal 2. The attacking terminal 5 sends a large number of location registration request signals using the plurality of intercepted IMSIs, thereby generating burst traffic and attacking the UDR 42 included in the core network 4.

[0032] In the estimation system according to the present embodiment, the probability of occurrence of a DDoS attack is used as a prior distribution, and the posterior distribution obtained by giving observation data related to the occurrence of burst traffic, that is, the probability of occurrence of a DDoS attack under the condition that burst traffic has occurred, is calculated by Bayesian estimation. Further, based on the value of the calculated posterior distribution, the presence or absence of the occurrence of a DDoS attack is determined.

[0033] [Functional Blocks of the Estimation Device] As shown in FIG. 1, the estimation device 1 includes a collection unit 10, a detection unit 11, a first acquisition unit 12, a second acquisition unit 13, a learning unit 14, a determination unit 15, a specification unit 16, a presentation unit 17, a first storage unit 18, and a second storage unit 19.

[0034] The collection unit 10 collects, from the core network 4, the number of location registration request signals transmitted for each IMSI, that is, the number of location registration request signals for each set time. More specifically, the collection unit 10 collects the transmission timestamps of the location registration request signals associated with the IMSI from the UDR 42. The collection unit 10 can collect, for example, the number of location registration request signals per second.

[0035] When the number of location registration request signals for each set time collected by the detection unit 11 exceeds the set number, the detection unit 11 detects the occurrence of burst traffic. For example, the detection unit 11 counts the number of location registration request signals transmitted by the communication terminal 2 per second, and when the set threshold is exceeded, it can detect that burst traffic has occurred. The specific value of the threshold can be set based on the occurrence history of past burst traffic, etc.

[0036] The first acquisition unit 12 acquires first observation data indicating the number of times burst traffic has occurred due to location registration request signals. The first acquisition unit 12 counts and acquires the number of times burst traffic is detected by the detection unit 11. The number of occurrences of burst traffic acquired by the first acquisition unit 12 is the number of occurrences of burst traffic caused by any reason. The first acquisition unit 12 can acquire the number of occurrences of burst traffic in an arbitrarily set period such as per month or per year.

[0037] The second acquisition unit 13 acquires, as second observation data of burst traffic generated due to reasons other than a specific attack on the core network 4, the number of times burst traffic has occurred whose history and trend match those of burst traffic that has occurred in the past among the occurrences of burst traffic.

[0038] More specifically, the second acquisition unit 13 acquires the number of occurrences of burst traffic that has been found to be caused by events other than DDoS attacks among the occurrences of burst traffic detected by the detection unit 11. Therefore, the second observation data is the number of occurrences of burst traffic that has been found to be caused by events other than DDoS attacks among the number of occurrences of burst traffic included in the first observation data.

[0039] As described above, it is known that the number of location registration request signals increases during time periods determined according to user behavior, such as the morning commuting rush hour or the lunchtime. The second acquisition unit 13 compares the time period of the occurrence of the burst traffic detected by the detection unit 11, etc., with the time period of the occurrence history of past burst traffic based on the analysis of the occurrence history of past burst traffic, and acquires the number of occurrences of burst traffic due to known causes other than DDoS attacks.

[0040] The learning unit 14 calculates, by Bayesian estimation, a posterior distribution indicating the occurrence probability of a DDoS attack under the condition that burst traffic has occurred, with the occurrence probability of the DDoS attack as a prior distribution and using the observation data including the first observation data and the second observation data. The Bayesian estimation adopted by the learning unit 14 is a method of obtaining the probability of an event under certain conditions from known probabilities and observation data. Hereinafter, the parameters of the probability model used by the learning unit 14 in Bayesian estimation will be described.

[0041] The learning unit 14 first sets event X as an event that has become a certain cause. Also, event Y is set as an event that is assumed to have occurred due to the cause. Events X and Y are treated as random variables. Specifically, event X is defined as the occurrence of a DDoS attack, and event Y is defined as the occurrence of burst traffic.

[0042] The learning unit 14 assumes the probability distribution P(X) of the occurrence of event X as the prior distribution which is the distribution of parameters before the observation data is given. Specifically, the learning unit 14 assumes a probability value based on rules of thumb or analysis of past history as the probability of a DDoS attack occurring. For example, it can be assumed that a DDoS attack occurs with a probability of 0.2 (= 20%) per month.

[0043] The learning unit 14 further sets the likelihood function P(Y|X) which is the expression method of the observation data. The likelihood function P(Y|X) represents how likely the observation data Y is to occur from the model when the value of the parameter is conditioned. Specifically, it is expressed as the probability of burst traffic occurring under the condition that a DDoS attack is occurring. For example, as an arbitrary value, a value such as 0.8 (= 80%) can be adopted. Note that the value 0.8 for the likelihood function P(Y|X) indicates that even when a DDoS attack occurs, a certain proportion of cases where burst traffic does not occur are included.

[0044] The learning unit 14 uses Bayes' theorem to calculate the posterior distribution P(X|Y) which is the probability of event X occurring under the condition that event Y has occurred, reflecting the information obtained from the likelihood function, prior distribution, and observation data. In this case, the posterior distribution P(X|Y) is the probability distribution of a DDoS attack occurring under the condition that burst traffic has occurred. In this embodiment, the posterior distribution P(X|Y) is calculated using the Bayes' estimation approximation formula represented by the following formula (2) based on Bayes' theorem of the following formula (1).

[0045]

Number

[0046] Substituting P(Y)=Σ X P(Y|X)P(X) into the denominator of the above formula (1), it is represented by the following formula (2).

[0047]

Number

[0048] In the denominator of the approximate formula in the lower part of the above formula (2), the "total number of times burst traffic has occurred" is the first observation data acquired by the first acquisition unit 12. Also, the "number of times burst traffic has occurred due to causes other than DDoS" is the second observation data acquired by the second acquisition unit 13.

[0049] Here, as described above, it is assumed that due to the assumption of the prior distribution P(X), the probability of a DDoS attack occurring is 0.2 (= 20%) per month. For example, when 1000 bursts of traffic occur in a month, 200 DDoS attacks occur, and the number of bursts of traffic caused by events other than DDoS attacks is 800 when simply calculated.

[0050] However, in the present embodiment, a value lower than 800 obtained by simple calculation is adopted in consideration of the number of times burst traffic has occurred due to causes other than DDoS attacks, even though the cause is known. Thus, for the probability distribution P(Y) of the event Y called evidence or marginal likelihood, a value adjusted based on the second observation data is used.

[0051] That is, in the above formula (2), the smaller the number of times burst traffic has occurred due to causes other than DDoS attacks, even though the cause is known, the more the posterior distribution and the prior distribution tend to be P(X|Y)>P(X).

[0052] The determination unit 15 determines the presence or absence of a DDoS attack based on the value of the posterior distribution calculated by the learning unit 14. Specifically, the determination unit 15 performs threshold processing and can determine the presence or absence of a DDoS attack. For example, 0.3 (= 30%) is adopted as the threshold, and when the value of the posterior distribution P(X|Y) exceeds the threshold, it can be determined that a DDoS attack has occurred.

[0053] When the determination unit 15 determines that a DDoS attack has occurred, the specific unit 16 identifies the IMSIs involved in the DDoS attack from the transmission history of location registration request signals for each IMSI stored in the UDR 42 included in the core network 4. More specifically, the specific unit 16 can identify the IMSIs that are abnormally transmitting location registration request signals from the subscriber profiles stored in the UDR 42. For example, it is possible to identify an IMSI that is continuously transmitting location registration request signals at short time intervals such as intervals of 1 ms as an IMSI involved in a DDoS attack.

[0054] The presentation unit 17 presents the determination result by the determination unit 15. In addition, the presentation unit 17 presents the information regarding the communication terminal 2 identified by the specific unit 16. The presentation unit 17 can transmit the determination result and the information of the communication terminal 2 to an external server or the like. Furthermore, the presentation unit 17 can display this information on the display device 107.

[0055] The first storage unit 18 stores Bayes' theorem (Equation (1)) and the Bayes estimation approximation formula (Equation (2)) used by the learning unit 14 for Bayes estimation. In addition, the first storage unit 18 stores setting information regarding the prior distribution and the likelihood function of the observation data.

[0056] The second storage unit 19 stores the history of burst traffic that has occurred in the past and the analysis information thereof.

[0057] [Hardware Configuration of the Estimation Device] Next, an example of the hardware configuration for realizing the estimation device 1 having the above-described functions will be described with reference to FIG. 2.

[0058] As shown in FIG. 2, the estimation device 1 can be realized, for example, by a computer including a processor 102, a main storage device 103, a communication interface 104, an auxiliary storage device 105, and an input / output I / O 106 connected via a bus 101, and a program for controlling these hardware resources. In addition, the estimation device 1 can include a display device 107 connected via the bus 101.

[0059] The main memory device 103 stores in advance a program for the processor 102 to perform various controls and operations. The functions of each part of the estimation device 1, such as the collection unit 10, the detection unit 11, the first acquisition unit 12, the second acquisition unit 13, the learning unit 14, the determination unit 15, and the specification unit 16 shown in FIG. 1, are realized by the processor 102 and the main memory device 103.

[0060] The communication interface 104 is an interface circuit for network-connecting the estimation device 1 and various external electronic devices.

[0061] The auxiliary storage device 105 is composed of a readable and writable storage medium and a driving device for reading and writing various information such as programs and data to and from the storage medium. As the storage medium, a semiconductor memory such as a hard disk or a flash memory can be used in the auxiliary storage device 105.

[0062] The auxiliary storage device 105 has a program storage area for storing the Bayesian estimation program executed by the estimation device 1. The first storage unit 18 and the second storage unit 19 described with reference to FIG. 1 are realized by the auxiliary storage device 105. Furthermore, for example, it may have a backup area for backing up the above-described data, programs, and the like.

[0063] The input / output I / O 106 is an input / output device that inputs signals from external devices and outputs signals to external devices.

[0064] The display device 107 is composed of an organic EL display, a liquid crystal display, or the like.

[0065] [Operation of the Estimation Device] Next, the operation of the estimation device 1 having the above-described configuration will be described with reference to the flowchart of FIG. 3.

[0066] First, the collection unit 10 collects the transmission timestamp of the location registration request signal associated with the IMSI assigned to the communication terminal 2 from the UDR 42 (step S1). Next, when the number of location registration request signals for each set time collected by the detection unit 11 exceeds the set threshold value, the detection unit 11 detects that burst traffic has occurred (step S2). The threshold value can be set based on the occurrence history of past burst traffic and the like.

[0067] Next, the first acquisition unit 12 acquires first observation data indicating the number of times burst traffic has occurred due to the location registration request signal (step S3). The first acquisition unit 12 can count and acquire the number of times burst traffic has occurred in an arbitrarily set period such as monthly or annually.

[0068] Next, the second acquisition unit 13 acquires, as second observation data, the number of times burst traffic has occurred due to events other than DDoS attacks among the occurrences of burst traffic detected in step S2 (step S4). The second acquisition unit 13 analyzes the occurrence history of past burst traffic and, when it is determined that the cause of the burst traffic occurring during the daytime or other time periods is due to a known cause other than a DDoS attack, acquires the number of times burst traffic has occurred due to the known cause among the detected burst traffic.

[0069] Next, the learning unit 14 calculates, by Bayesian estimation, the posterior distribution P(X|Y) indicating the occurrence probability of a DDoS attack under the condition that burst traffic has occurred, with the occurrence probability of the DDoS attack as the prior distribution P(X) and the observation data including the first observation data and the second observation data (step S5). More specifically, the learning unit 14 calculates the posterior distribution P(X|Y) based on the previously assumed prior distribution P(A) and the likelihood function P(Y|X) of the observation data using the Bayesian estimation approximation formula of the above formula (2).

[0070] Thereafter, the determination unit 15 performs threshold processing on the value of the posterior distribution calculated in step S5, and if it exceeds the threshold, determines that a DDoS attack has occurred (step S6). Next, when it is determined in step S6 that a DDoS attack has occurred, the identification unit 16 identifies the IMSI that has abnormally transmitted the location registration request signal from the subscriber profile stored in the UDR 42 (step S7).

[0071] The presentation unit 17 presents the determination result in step S6 and information regarding the IMSI of the communication terminal 2 identified in step S7 (step S8).

[0072] As described above, according to the estimation device 1 according to the present embodiment, the probability of occurrence of a DDoS attack is used as a prior distribution, and the posterior distribution indicating the probability of occurrence of a DDoS attack under the condition that burst traffic has occurred, which is obtained by providing observation data including first observation data and second observation data, is calculated by Bayesian estimation. Therefore, when burst traffic occurs, it is possible to distinguish whether it is caused by a DDoS attack or by other causes other than a DDoS attack.

[0073] Further, according to the estimation device 1 according to the present embodiment, when it is determined that a DDoS attack has occurred based on the value of the posterior distribution obtained by Bayesian estimation, the IMSI involved in the DDoS attack is identified from the subscriber profile of the UDR 42. Therefore, the source of the DDoS attack can be identified.

[0074] In the above-described embodiment, a case where the estimation system conforms to 5G is exemplified, but an estimation system conforming to 3G / LTE, 6G, or the like may also be used.

[0075] The embodiments of the estimation device and the estimation method of the present invention have been described above, but the present invention is not limited to the described embodiments, and various modifications conceivable by those skilled in the art can be made within the scope of the invention described in the claims.

Explanation of Reference Numerals

[0076] 1… Deduction device, 10… Collection unit, 11… Detection unit, 12… First acquisition unit, 13… Second acquisition unit, 14… Learning unit, 15… Judgment unit, 16… Identification unit, 17… Presentation unit, 18… First memory unit, 19… Second memory unit, 2… Communication terminal, 20… SIM, 3… Base station, 4… Core network, 5… Attack terminal, 40… AMF, 41… UDM, 42… UDR, 101… Bus, 102… Processor, 103… Main memory device, 42a, 104… Communication interface, 105… Auxiliary memory device, 106… Input / output I / O, 107… Display device, L, NW… Network.

Claims

1. A first acquisition unit configured to acquire first observation data indicating the number of times burst traffic has occurred due to a location registration request signal; A second acquisition unit configured to acquire, as second observation data of burst traffic generated due to causes other than a specific attack on the core network, the number of times the burst traffic that matches the history and trend of the burst traffic generated in the past has occurred among the occurrences of the burst traffic; A learning unit configured to calculate, by Bayesian estimation, a posterior distribution indicating the occurrence probability of the specific attack under the condition that the burst traffic has occurred, with the occurrence probability of the specific attack as a prior distribution and the observation data including the first observation data and the second observation data; A determination unit configured to determine the presence or absence of the occurrence of the specific attack based on the value of the calculated posterior distribution; A presentation unit configured to present the determination result by the determination unit An estimation device comprising.

2. In the estimation device according to Claim 1, Furthermore, when the determination unit determines that the specific attack has occurred, from the transmission history of the location registration request signal for each subscriber identification number assigned to the communication terminal, which is stored in the integrated data repository provided in the core network, a specifying unit configured to specify the subscriber identification number involved in the specific attack is provided, The presentation unit presents information regarding the subscriber identification number specified by the specifying unit The estimation device characterized by this.

3. In the estimation device according to Claim 1, Furthermore, a collection unit configured to collect, from the core network, the number of the location registration request signals transmitted for each subscriber identification number assigned to the communication terminal, which is the number of the location registration request signals for each set time; A detection unit configured to detect the occurrence of burst traffic when the number of the location registration request signals for each set time collected exceeds a set number An estimation device comprising.

4. In the estimation device according to any one of Claims 1 to 3, The specific attack includes an attack in which a large number of location registration request signals are intentionally transmitted using the subscriber identification numbers of a plurality of communication terminals, targeting the nodes of the control plane provided in the core network The estimation device characterized by this.

5. A first acquisition step of acquiring first observation data indicating the number of times burst traffic has occurred due to a location registration request signal; A second acquisition step of acquiring, as second observation data of burst traffic generated due to causes other than a specific attack on the core network, the number of times the burst traffic that matches the history and trend of the burst traffic that has occurred in the past among the occurrences of the burst traffic; A learning step of calculating, by Bayesian estimation, a posterior distribution indicating the occurrence probability of the specific attack under the condition that the burst traffic has occurred, where the occurrence probability of the specific attack is a prior distribution and the observation data includes the first observation data and the second observation data; A determination step of determining the presence or absence of the occurrence of the specific attack based on the value of the calculated posterior distribution; A presentation step configured to present the determination result in the determination step An estimation method comprising:

6. In the estimation method according to claim 5, further, in the determination step, when it is determined that the specific attack has occurred, a specific step of identifying a subscriber identification number involved in the specific attack from the transmission history of the location registration request signal for each subscriber identification number assigned to a communication terminal and stored in the integrated data repository provided in the core network is provided, the presentation step presenting information regarding the subscriber identification number identified in the specific step An estimation method characterized by the above.

7. In the estimation method according to claim 5, further, a collection step of collecting, from the core network, the number of the location registration request signals transmitted for each subscriber identification number assigned to a communication terminal, which is the number of the location registration request signals for each set time; a detection step of detecting the occurrence of burst traffic when the number of the location registration request signals for each set time collected exceeds a set number An estimation method comprising:

Citation Information

Patent Citations

  • Base station device and communication system

    JP2015220544A