TELECOM THREAT SHARING SYSTEM

TR202615524A2Pending Publication Date: 2026-09-21TURKCELL TEKNOLOJI ARASTIRMA & GELISTIRME AS
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
TR202615524
Authority / Receiving Office
TR · TR
Patent Type
Applications
Current Assignee / Owner
Filing Date
2026-09-10
Publication Date
2026-09-21

Smart Images

  • Figure 00000014_0000
    Figure 00000014_0000
Patent Text Reader

Abstract

This invention relates to a system (1) that enables the identification of operational and / or cyber threats by analyzing signal, connection and traffic data received from telecommunication networks, sharing and verifying records of these threats among telecommunication operators and operating the network.
Need to check novelty before this filing date? Find Prior Art

Description

1 TARIFF TELECOM THREAT SHARING SYSTEM Technical Area This invention analyzes signals, connections, and traffic received from telecommunication networks. Identifying operational and / or cyber threats by analyzing data, sharing records of threats among telecommunications operators, It relates to a system that enables verification and operation of the network. Previous Technique Today, the basis for ensuring the cybersecurity of telecommunications networks is... By analyzing communication data obtained from stations and network elements Security incidents are detected and the results are processed by SIEM (Security Information and Communication Technologies Authority). Event Management (Security Information and Event Management) systems is being evaluated. In current systems, evaluation processes are mostly done via IP. Internet Protocol (IPC) traffic, network logs, and alarms. This is done on central servers using records. However, RSRP (Reference Signal Received Power), RSRQ 20 (Reference Signal Received Quality) and jitter. – Telecommunications network-specific signal metrics such as latency variability analysis of threat information securely shared between different operators sharing and automated protection processes on the network against verified threats Implementation is not possible. Therefore, anomaly detection, threat sharing, and 25 to ensure that security interventions are carried out quickly and effectively shortcomings are emerging. Therefore, considering the studies and shortcomings in the current technique... When this is the case, the signal drop in telecommunication networks is 30 connection drops, increased packet loss, increased latency, and unusual data traffic. 2 By analyzing their movements, service interruption, attack or network problem Identifying whether there are any potential threats and, in the event of a threat, monitoring the network. It is clear that a system to ensure security is needed. United States Regulation 5, numbered US2023164567A1, which is included in the known state of the art. The patent document describes the integration of artificial intelligence with normal telecommunication networks. By analyzing abnormal network behavior, it detects cyber threats and takes automated action. The system in question is a telecommunications network. communications that take place on the control plane and / or management plane It monitors activities. 10 using unsupervised machine learning algorithms Self-learning artificial intelligence models are being used. These models, network by learning the normal behavioral pattern over time, normal behavior It creates profiles. Then, new communications that take place on the network are based on these profiles. This is compared with behavioral patterns. Deviations from normal behavior These situations are considered abnormal behavior. Within the system, 15 evaluation module, analysis module, data collection module, cyber threat analyst different artificial intelligence components together in the form of an automated response module and an autonomous response module. It is working. From sensors on the network, device logs, configuration Information is collected from records and packet data. The system also collects information from telecommunications. It performs deep packet inspection on protocols. Artificial intelligence 20 classifiers, link structures, routing information, time series, and data flow. Telecom evaluates packet behavior by analyzing its characteristics. Network-specific SCTP connections and multiple IP relationships are also included in the analysis process. The system not only detects attacks but also... It can also perform automatic defense actions when a threat is detected. 25 The autonomous response module can block, restrict access, or block networks based on the identified threat. They can implement procedures to change behavior. 3 Brief Description of the Invention The purpose of this invention is to integrate base stations and RANs (Radio Stations) in telecommunication networks. Access Network (Radio Access Network) devices and IoT (Internet of Things) Signal strength, signal quality, and connectivity obtained from Internet of Things (IoT) devices. 5 data on delays, packet loss, and traffic movements, where the data is generated by analyzing the situation near the point, deviations from the network's normal operating pattern Identifying operational and / or cyber threats, and reporting on the identified threats. Telecommunications anonymizes data that could identify a user, network, or location. a 10 that creates standard threat logs suitable for sharing among operators. The goal is to implement the system. Another purpose of this invention is to anonymize data from different telecommunications operators. threat logs run on the blockchain and belonging to the same or similar type of event. The records must be from more than 15 locations within the specified time period in the same or neighboring geographic region. a smart system that automatically checks if it has been reported by too many telecom operators Verifying and restricting network traffic using contracts, malicious Blocking connections, isolating suspicious traffic, or using an alternative network at least one of the processes of directing them to their paths automatically The goal is to create a system that enables its implementation. 20 Detailed Description of the Invention The "Telecommunications Threat Sharing" project was carried out to achieve the purpose of this invention. The "System" is shown in the attached figure; this figure is 25 Figure 1. Schematic view of the system described in the invention. The parts shown in the figure are individually numbered, and the corresponding numbers correspond to these numbers. The following are given below: 30 4 1. System 2. Data Collection Module 3. Database 4. Analytics Server 5. Blockchain Server 5 R. RAN (Radio Access Network) device B. Base station I. IoT (Internet of Things) device Analyzing signal, connection, and traffic data received from telecommunication networks 10 by identifying operational and / or cyber threats, and information about these threats sharing and verifying records among telecommunications operators, and The system in question, developed to ensure the operation of the network (1); - RAN (Radio Access Network) device (R), base station (B) RSRP 15 obtained from IoT (Internet of Things) device (I) (Reference Signal Received Power), RSRQ (Reference Signal Received Quality), SINR (Signal Signal-to-Interference and Noise Ratio (SIGNAL / INTERFERENCE and NOISE Ratio), delay change, delay, packet loss, SCTP (Stream Control Transmission Protocol – Flow Control Transmission Protocol) error rate and TCP (Transmission Control Protocol 20 – Transmission Control Protocol) raw signal and traffic in the form of retransmission rate at least one data collection system configured to collect data at time intervals module (2), - Raw signal and traffic data collected by the data collection module (2); event type, risk level, confidence score, anonymized region code, timestamp, and 25 threat logs and generated alarms associated with affected protocol information. at least one database structured to record its information (3), - Signal and traffic data collected by the data collection module (2), data By analyzing the network near the point of generation, the normal operation of the network Identifying operational and / or cyber threats that deviate from the established order, 30 to create standard threat logs by anonymizing threat records at least one configured analytics server (4), - anonymized threat logs generated by the analysis server (4) smart storage of similar threat records from different telecom operators Comparing and verifying using contracts, risk 5 for verified threats. to determine the level and autonomous defense according to the determined risk level at least one blockchain configured to enable the initiation of transactions It includes server (5). The data collection module (2) in the system (1) which is the subject of the invention, telecommunications 10 RAN devices (R) that enable radio communication of the network and base from stations (B) and IoT devices (I) that transmit data over the communication network Collecting the generated raw signal and traffic data at millisecond intervals, RSRP indicates the strength of the received reference signal, while RSRP indicates the quality of the received reference signal. RSRQ, which shows the ratio of useful signal to interference and noise, and SINR, which shows the ratio of useful signal to interference and noise, data 15 The latency variation (jitter) is the change in the transmission times of packets. Latency indicates the time it takes for data to travel from source to destination, and the time it takes for data to be sent. Packet loss is the percentage of data packets that do not reach their destination. It is configured to receive data. The data acquisition module (2) is configured to receive signals and traffic data with SCTP (Stream Control Transmission Protocol) The rate of errors occurring in connections established via the Transmission Protocol. and via TCP (Transmission Control Protocol) To sum up the percentage of data packets that are resent because they did not reach the destination. To correlate the collected data with information about when it was generated and telecommunications. 25 in identifying events that deviate from the normal operating procedure of the network to ensure that it is transferred to the analysis server (4) for use It is being structured. The database (3) and the data collection module (2) in the system (1) are the subject of the invention. 30 from RAN devices (R), base stations (B) and IoT devices (C) Collected RSRP, RSRQ, SINR, latency variation, latency, packet loss, SCTP error 6 raw signal and traffic data in the form of rate and TCP retransmission rate, word the subject is to record and analyze the data in relation to the time information when it was produced. The type of event generated as a result of the analyses performed by the server (4), Threat class, security score and risk level information; IMSI (International Mobile) Subscriber Identity (International Mobile Subscriber Identity), MSISDN (Mobile Station 5 International Subscriber Directory Number (Mobile Subscriber International Number) and extraction of IP (Internet Protocol) information, Cell-ID (Cell As a result of anonymizing location information using the Identifier (Cell ID). including the generated region code, timestamp, and affected protocol information. It is configured to store information in conjunction with standard threat logs. 10 The system in question (1) includes the analysis server (4), data collection module (2) The history of the raw signal and traffic data transmitted by is recorded in the database (3). By receiving network data, the data is processed at a location close to where it is generated. with the Edge AI (Edge Artificial Intelligence) approach that provides 15 to analyze raw signal and traffic data belonging to a telecommunications network filtering noisy recordings, learning the network's normal operating procedures, time to identify the changes occurring within and deviate from the normal operating procedure LSTM (Long Short-Term Memory) is used to detect deviant events. Isolation Forest 20 with a time series model based on (Temporary Memory) It is configured to use an anomaly detection algorithm based on analysis. server (4), detected anomalies signal jammer attack, connection disruption, abnormal traffic increase, or similar operational and / or cyber threats evaluating according to their categories, the results of the analysis performed for each event To create a trust score that demonstrates reliability and to define 25 for sharing. operational and / or cyber threat records exceeding the trust score threshold It is structured to guide the analysis towards anonymization processes. server (4), IMSI (International Mobile) of the events decided to be shared Subscriber Identity (International Mobile Subscriber Identity), MSISDN (Mobile Station International Subscriber Directory Number (Mobile Subscriber International Number) 30 and deleting IP (Internet Protocol) address information from the registry, 7 Cell-ID (Cell Identifier) ​​information is converted to SHA-256 (Secure Hash) Algorithm 256 – Secure Hash Algorithm 256) algorithm is used in a one-way manner. convert and use location information to MCC (Mobile Country Code) with MNC (Mobile Network Code) based area code It is configured to anonymize by converting. Analysis server (4), 5 Event type, confidence score, and risk for events where the anonymization process has been completed. level, anonymized region code, timestamp, and affected protocol information in JSON (JavaScript Object Notation) to make the created threat logs into a standard threat log, to enter the created threat logs into the database (3) 10 for transferring and performing verification processes between operators It is configured to transmit to the blockchain server (5). The blockchain server (5) in the system in question (1) does not communicate with any communication using the protocol data collection module (2), database (3), analysis server It is structured to communicate and exchange data with (4). 15 Blockchain server (5), analysis server (4) by IMSI, MSISDN, IP address, The type of event created as a result of anonymizing cell-ID and location information, risk level, anonymized region code, timestamp, and affected protocol obtaining standard threat logs containing this information, and then later using those logs to prevent alteration, to track the information when they are transferred to the blockchain 20 to ensure and enable the sharing of records between different telecommunications operators It is structured in such a way. The blockchain server (5) is configured to run conditions on the blockchain. Smart Contract that automatically executes linked decision rules using the type of incident in threat logs from different telecommunications operators, Comparing anonymized region code and timestamp information, the same 25 multiple identical or similar events related to the region code within the specified time interval to check whether it has been reported from more than one operator node and in question If the notifications are consistent, the incident may involve multiple operators. It is structured to verify that it has been detected by the blockchain. server (5), comparison of records from different telecommunication operators 30 to assess the risk level of the confirmed event, in relation to the same region 8 If similar notifications increase, the event will be classified as a critical or sectoral threat. To determine and provide early warning signals and alarm information based on the identified risk level. It is structured to create a blockchain server (5), risk level critical Threats identified as such, generated by smart contracts. Verification and risk assessment results will be implemented in the telecommunications network. converting commands into API (Application Programming Interface) commands Application Programming Interface) via HSS (Home Subscriber Server – Home Subscriber Server), HLR (Home Location Register), the router, forwards to the firewall and uses GTP (GPRS Tunnelling Protocol – GPRS Tunneling Protocol) or SCTP (Stream Control Transmission Protocol – 10 Flow Control Transmission Protocol (Flow Control) traffic restriction, malicious IP addresses blocking, isolating harmful traffic, or diverting traffic to a different network path. to enable the implementation of autonomous defense operations in the form of guidance. It is structured accordingly. Industrial Application of the Invention The invention system (1) enables mobile communication of telecommunication operators. Technical analysis of base stations and communication networks in their infrastructure By analyzing data, operational and cyber threats can be identified at an early stage. identification, threat information, and different operators without disclosing personal data. securely sharing information between them, verifying records relating to the same threat. and ensuring the network operates securely and uninterruptedly and is defended against verified threats. The processes are implemented automatically. Around these basic concepts, the subject of the invention is “Telecommunication Threat Sharing System (1)” It is possible to develop a wide variety of applications related to this, and the invention is presented here. It cannot be limited to the examples given; it is essentially as stated in the claims.

Claims

9 REQUESTS 1. Signal, connection, and traffic data received from telecommunication networks. by analyzing and identifying operational and / or cyber threats, sharing records of threats among telecommunications operators, 5 enabling verification and operation of the network; - RAN (Radio Access Network) device (R), base from station (B) and IoT (Internet of Things) device (I) obtained RSRP (Reference Signal Received Power) (Reception Power), RSRQ (Reference Signal Received Quality – Reference Signal 10 (Inception Quality), SINR (Signal to Interference plus Noise Ratio – Signal-to-Interference / Noise Ratio), delay variation, delay, packet loss, SCTP (Stream Control Transmission Protocol) The error rate of TCP (Transmission Control Protocol) and TCP (Transmission Control Protocol) Control Protocol) raw signal and traffic in the form of retransmission rate 15 at least one data set structured to collect data at time intervals collection module (2), - Raw signal and traffic collected by data collection module (2) data; event type, risk level, confidence score, anonymized region 20 associated with the code, timestamp, and affected protocol information to record threat logs and generated alarm information at least one structured database (3), - Signal and traffic data collected by the data collection module (2), By analyzing the data in close proximity to where it is generated, the network's normal operation Identifying operational and / or cyber threats that deviate from the work order, 25 By anonymizing records of identified threats, standard threat logs are created. at least one analytics server configured to create (4), - anonymized threat generated by the analysis server (4) Storing records of similar threats from different telecommunications operators comparing and verifying records using smart contracts, 30 To determine the risk level for verified threats and the identified risk To enable the initiation of autonomous defense operations according to the level of competence. with at least one blockchain server (5) configured to a characterized system (1).

2. RAN 5, which provides radio communication for the telecommunications network. data from devices (R) and base stations (B) and over the communication network raw signal and traffic data generated from IoT devices (I) summing up the strength of the received reference signal at millisecond intervals RSRP indicates the quality of the received reference signal, RSRQ indicates the quality of the reference signal, useful. SINR, which indicates the ratio of signal to interference and noise, is the transmission ratio of data packets. lag variation, which shows the change between the durations, from the source of the data delay indicating the time to reach the destination and from the data packets sent to obtain packet loss data showing the percentage of packets that do not reach their destination In Claim 1, characterized by the structured data collection module (2). such a system (1). 15 3. Problems occurring in connections established via SCTP with signal and traffic data. the rate of incoming errors and the fact that it did not reach the destination over TCP again to sum the rate of transmitted data packets, to collect the collected data according to where it was generated to associate with time information and the usual 20 of the telecommunication network to be used in identifying events that deviate from the work procedure data configured to be transferred to the analysis server (4) A system like the one in Claim 2, characterized by the collection module (2) (1).

4. Data collection module (2) by RAN devices (R), base stations (B) 25 RSRP, RSRQ, SINR, latency variation collected from IoT devices (I), latency, packet loss, SCTP error rate, and TCP retransmission rate. raw signal and traffic data in the form of, the data in question is generated recording in relation to time information, analysis server (4) The event type, identified as threat 30, was determined as a result of analyses performed by [company name]. Class, confidence score and risk level information; IMSI, MSISDN and IP 11 Extraction of data, anonymization of location information with Cell-ID The resulting region code, timestamp, and affected protocol. to store this information in conjunction with standard threat logs from the above requests characterized by the structured database (3) a system like any of them (1). 5 5. Raw signal and traffic data transmitted by the data collection module (2). Data is generated by taking historical network data recorded in the database (3). Analysis using the Edge AI approach, which enables processing at a near-point location. to do, 10 in raw signal and traffic data of the telecommunications network filtering noisy recordings, restoring the network's normal operating procedure. to learn, to identify changes that occur over time, and LSTM-based for detecting events that deviate from the normal operating procedure. an anomaly detection algorithm based on Isolation Forest using a time series model 15 characterized by the analysis server (4) configured for use a system like any of the above requests (1).

6. Detected anomalies include signal jamming attacks, connection interruptions, and abnormalities. based on traffic increase or similar operational and / or cyber threat classifications to evaluate, the result of the analysis performed for each event is 20 To create and share a trust score that demonstrates reliability. operational and / or cyber threats exceeding the defined security score threshold configured to direct records to anonymizing processes any of the above requests characterized by the analysis server (4) a system like one of them (1). 25 7. IMSI, MSISDN, and IP addresses of the events that have been decided to be shared. extracting the information from the record, uniquely extracting the Cell-ID information using the SHA-256 algorithm. transforming directionally and transferring location information to MCC and MNC-based zones. Analysis server 30 configured to anonymize by converting it to code 12 (4) like any of the above-mentioned claims characterized by system (1).

8. Event type, confidence score, and risk for events where the anonymization process is complete. level, anonymized region code, timestamp and affected 5 Converting protocol information into a standard threat log using JSON, transferring the generated threat logs to the database (3) and operators blockchain for performing verification processes between them analysis server configured to ensure transmission to the server (5) (4) like any of the above-mentioned claims characterized by 10 system (1).

9. Data collection module (2) using any communication protocol, data base (3), communicate with the analysis server (4) and exchange data 15 characterized by a blockchain server (5) configured to perform a system like any of the above-mentioned requests (1).

10. IMSI, MSISDN, IP address, Cell-ID and by the analysis server (4) The type of event created as a result of anonymizing location information is a risk. level, anonymized region code, timestamp, and affected 20 obtaining standard threat logs containing protocol information, the logs to prevent them from being altered later, when they are transferred to the blockchain to enable the monitoring of information and records across different telecommunications operators blockchain server configured to enable sharing among them (5) like any of the above claims characterized by 25 system (1).

11. Automatedly executing conditional decision rules on the blockchain. Threats from different telecom operators using Smart Contracts Event type, anonymized region code, and timestamp in the records 30 comparing information, identical or similar for the same area code 13 events from multiple operator nodes within a specified time interval to check whether notifications have been made and to verify those notifications if they are compatible, the incident will be handled by multiple operators with blockchain server (5) configured to verify that it has been detected A system like any of the above characterized claims 5 (1).

12. As a result of comparing records from different telecommunication operators. assessing the risk level of a confirmed event, in relation to the same region An increase in similar notifications would classify the event as a critical or sectoral threat. 10 to determine, and based on the determined risk level, to provide an early warning signal and with blockchain server (5) configured to generate alarm information a system like any of the above characterized claims (1).

13. For threats whose risk level is determined as critical, a smart contract will be used. The telecommunications company has created a threat verification and risk assessment result. converting commands into instructions to be executed on the network, executing the commands via API HSS, HLR, forwarding to router, firewall and GTP or SCTP restricting traffic, blocking malicious IP addresses, malicious 20 isolating traffic or redirecting traffic to a different network path to enable the implementation of autonomous defense operations in this manner the above characterized by the configured blockchain server (5) a system like any of the requests (1). 30