Method for detecting operation of a moving virtual base station

The method of measuring RSRP/RSRQ changes in wireless networks identifies moving VBS, addressing the complexity of existing detection methods and enhancing security by reducing false alarms and protecting against DoS attacks.

WO2025254566A1PCT designated stage Publication Date: 2025-12-11ZADOROZHNY ARTEM ANATOLYEVICH
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
PCT/RU2025/050156
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-06-04
Filing Date
2025-06-01
Publication Date
2025-12-11

AI Technical Summary

Technical Problem

Existing methods for detecting virtual base stations (VBS) in wireless communication networks are complex and require hardware and software modifications, making them impractical for widespread implementation.

Method used

A method involving continuous measurement of the Received Signal Strength Indication (RSRP) and Received Signal Quality (RSRQ) levels by subscriber devices, with a threshold of 30% change in RSRP/RSRQ used to identify moving VBS, utilizing gyroscopes or accelerometers for stability checks and incorporating analytical modules for data analysis.

Benefits of technology

Enhances information security by timely detection of VBS, reducing false alarms and ensuring robust protection against DoS attacks in wireless networks, particularly in sensitive facilities.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader

Abstract

The invention relates to the field of wireless communication networks. The technical result consists in increasing the level of information security by timely detection of weapons of attack on a wireless network. A method for detecting the operation of a moving virtual base station is characterized in that it is implemented using at least one subscriber device capable of determining the level of the strength of pilot signals received (RSRP) and / or the quality of pilot signals received (RSRQ) from base stations. The level of the RSRP and / or RSRQ is continuously measured for each base station over a time interval ti, the rate of change of the RSRP and / or RSRQ is calculated for each base station and then ranking is performed. If, within a time interval ti+1, the rate of change for the base station showing the highest rate of change differs from that of the second base station by a magnitude of the rate of change of the RSRP and / or RSRQ of more than 30%, it is determined that the base station showing the highest rate of change is a moving virtual base station.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Method for detecting the operation of a virtual base station in motion

[0002] DESCRIPTION OF THE INVENTION

[0003] Field of technology.

[0004] The object of the search relates to wireless communication networks, namely to methods of ensuring information security of subscribers of wireless communication systems (such as, for example, GSM, UMTS, LTE, NR, WiFi) [H04W 4 / 00, H04W 12 / 00, H04W 12 / 02, H04W 12 / 12, H04W 12 / 121, H04W 12 / 122, H04W 12 / 128, H04W 12 / 30, H04W 12 / 40, H04W 12 / 60, H04W 12 / 61, H04W 12 / 63, H04W 12 / 64, H04W 12 / 80, H04W 60 / 00, H04W 60 / 04]. A denial of service attack (hereinafter referred to as a DoS attack) carried out via a radio channel is understood to be any attack carried out using various technical means with the aim of completely or partially denying service to the attacked network (subscriber devices, base station).For example, after a successful attack, one or more network elements may completely lose the ability to connect to the base station or lose the ability to use a significant portion of the functionality provided by the operator / network developers (e.g., the ability to exchange data, access network resources, make outgoing calls, send SMS messages, etc.). Such attacks can be carried out by attackers using various technical means, such as virtual base stations and blockers.

[0005] There are many objective studies that have proven the vulnerability of 4G and 5G networks to attacks carried out using virtual base stations [S. Park, A. Shaik, R. Borgaonkar, A.C.Martin, and J. Seifert, "White-Stingray: Evaluating IMSI Catchers Detection Applications," [Electronic resource] / / Workshop on Offensive Technologies. Oxford University, Department of Computer Science http: / / www.cs.ox.ac.uk / , 2017. URL: http: / / www.cs.ox.ac.uk / files / 9192 / paper-final-woot-imsi.pdf (accessed: 05 / 29 / 2023); H. Alrashede and RA Shaikh, "IMSI Catcher Detection Method for Cellular Networks," 2019 2nd International Conference on Computer Applications & Information Security (ICCAIS), Riyadh, Saudi Arabia, 2019, pp. 1-6, doi: 10.1109 / CAIS.2019.8769507; Zadorozhny AA, Tikhonyuk AI. Analysis of known measures to counter some attacks in modern telecommunication networks. / / Security Director, Publishing House "Industry News" (Moscow), 2023, No. 2. - P. 72-76].Virtual base stations are defined as equipment that can emit various service commands that correspond to, and in some cases are absolutely identical to, the commands of legal base stations of mobile operators [Zadorozhny, A.A., Tikhonyuk, A.I. Analysis of known measures to counter certain attacks in modern telecommunications networks. / / Security Director, Publishing House "Industry News" (Moscow), 2023, No. 2. - Pp. 72-76]. Virtual base stations, in turn, can be classified according to the tasks they are used to solve by attackers, for example:.

[0006] - for the purpose of intercepting identifiers (IMSI-catcher or IMSI-traps);

[0007] - for the purpose of intercepting user data (traffic, user data, location);

[0008] - with the aim of deteriorating / completely denying service to a subscriber device / group of subscriber devices.

[0009] In addition to virtual base stations, DoS attacks can be carried out using so-called jamming or spoofers.

[0010] It is known that the Air Force can deploy air defense systems on a transport vehicle for attacks.

[0011] For example, from open sources, the BBC is known, located on BILA (action-inti .cot / imsi_catcher / 348.html).

[0012] A jamming attack involves jamming the communication channel through which elements of a facility's private LTE network (or a mobile operator's LTE network) communicate with base station 2 or with each other. The attack is classified as a physical attack, so it can lead to complete network disruption or the disconnection of one, two, or more elements (including subscriber devices), which may not be immediately detected.

[0013] There are various types of such equipment. Some, for example, emit interference continuously in a specific range, some emit interference briefly, and so on. In addition to radio frequency (RF) equipment, DoS attacks can also be carried out using so-called radio frequency (RF) signal spoofing. A spoofing attack is defined as an attack that involves transmitting a false signal, structurally similar to a genuine signal, with the aim of causing disruption (significant deterioration) in the operation of a telecommunications network.

[0014] Clearly, DoS attacks can cause significant damage, especially when used against network elements used in various sensitive facilities, including critical information infrastructure, manufacturing, government agencies, and so on. For example, increasingly, subscriber devices (IoT, IoTT) are being used, among other things, in manufacturing.

[0015] The Internet of Things (IoT) is a system that connects devices into a computer network and allows them to collect, analyze, process, and transmit data to other objects through software, applications, or hardware devices.

[0016] The Industrial Internet of Things (IoT) is used in manufacturing, warehouses, factories, and laboratories. Its purpose is to automate and simplify production processes, reduce production costs, and avoid losses.

[0017] Examples of PoT:

[0018] - sensors on equipment and machines that collect data on their operation and help prevent breakdowns, monitor the need for replacement, repair or maintenance;

[0019] - climate control systems that analyze temperature and humidity and automatically regulate the microclimate in a workshop or warehouse;

[0020] - sensors on products and parts that assist in inventory control and defect detection;

[0021] - remote control systems for production equipment, for example, remote start-up of machine tools;

[0022] - pollution sensors that analyze the company’s emissions and monitor compliance with environmental standards;

[0023] - beacons (tags) on transport that allow tracking of cargo in real time;

[0024] - sensors on vehicle systems that help monitor fuel consumption, engine wear, refrigerator temperature, and other parameters.

[0025] A DoS attack on subscriber devices used, for example, in production, can lead to significant negative consequences.

[0026] Furthermore, a degraded connection or outage due to a DoS attack can lead to significant financial losses for a mobile operator, as subscribers will be unable to access mobile services and will be unable to use important functionality provided by mobile operators, such as emergency calls.

[0027] Almost all organizations and enterprises today have various equipment, devices, and computers connected to a single wired and / or wireless corporate network, managed by the organization's server. Digital security is increasingly being addressed. In today's environment of centralized enterprise management, the use of high-tech equipment, and the digitalization of production and management processes, protecting enterprise computing systems from external destructive influences or attacks, such as DOS / DDOS attacks, is becoming increasingly important.

[0028] With the advent of increasingly powerful computing power and high-speed data exchange, attackers can organize large-scale operations, leading to an increase in the number of attacks and requiring more effective security systems. Attackers are constantly developing new methods and techniques for conducting attacks. Defense against attacks is an important aspect of information security, preventing serious breaches in the availability, security, and confidentiality of data.

[0029] Prior art.

[0030] There are methods for countering VBS. One of them has been chosen as a prototype: US Patent No. 11,070,981 B21 proposes a method for detecting VBS and protecting users from possible VBS interference in network operation. The method is based on the fact that a real base station (hereinafter referred to as BS) transmits an unencrypted service information block (MIB), which is intercepted by the VBS. The VBS then transmits the corrected information to the subscriber unit (hereinafter referred to as SU). In response, the SU sends an acknowledgement to the real BS in a protected format, which could, on the other hand, resend the MIB to the subscriber unit, but this time in a protected format. The AU compares both received MIBs and, if any discrepancies are detected, recognizes the MIB received in an unprotected format as the MIB from the VBS.1(1 Information protection to detect fake base stations. US patent US 11070981 B2. [Electronic resource] / / Official website of Google Patents patents.google.com, 2012-2013. URL: https: / / patents.google.com / patent / USl 1070981B2 / en (accessed March 22, 2023). The downside of the prototype is the complexity of implementation, namely, the need to make changes to the hardware and software of both the base station and the subscriber device.

[0031] The objective of the invention is to eliminate the shortcomings of the analogue and prototype.

[0032] Disclosure of invention.

[0033] The technical result of the invention consists in increasing the level of information security due to the timely detection of attack weapons on the wireless network.

[0034] The specified technical result is achieved due to the fact that the method for detecting the operation of a virtual base station in motion, characterized in that for its implementation, at least one subscriber device is used, which is capable of detecting the level of the average value of the power of the received pilot signals RSRP and / or the quality of the received pilot signals RSRQ of all base stations (one or all gsm / umts / lte / nr communication systems, all mobile operators) perform a continuous measurement of the RSRP and / or RSRQ level for each base station, calculates the rate of change (increase or decrease) of RSRP and / or RSRQ for each base station and if the rate of change of RSRP and / or RSRQ for the base station on which the maximum rate of change is recorded differs from the second base station in the value of the rate of change of RSRP and / or RSRQ of the base station by more than 30% (based on experiments), it is believed,that this base station is a moving virtual base station.,

[0035] Obviously, measurements taken at the same time should be compared.

[0036] It's preferable for the subscriber device to be in a "relatively motionless" state (obviously, achieving complete immobility when the subscriber device is held in the hands or on the body is virtually impossible). It's preferable for the user, for example, to avoid making sudden hand movements while holding the subscriber device. Avoid running, walking, etc.

[0037] Moreover, relative immobility can be calculated using gyroscopes or accelerometers (included in almost all modern smartphones). For increased accuracy, it's best to calculate such VBSs using multiple subscriber devices.

[0038] Specially manufactured sensors (e.g. based on smartphones, modems, etc.) can also be used, permanently placed, for example, inside the object or along its perimeter (it is preferable for sensors to be placed along the perimeter of the object to increase the detection range of such EBS).

[0039] The analysis of the received information can occur either on each subscriber device (e.g., a smartphone) or on the analytical module (e.g., a PC). In this case, a wired and / or wireless connection is required between the subscriber devices and the analytical module (in order to transmit the transmitters' information to the analytical module).

[0040] It is obvious that the RSRP signal level will not be constant even if the subscriber devices are stationary, but it will change within certain limits (as experiments show, the decrease and increase fluctuates by no more than 20-30%).

[0041] Obviously, if an attacker completely forges all the parameters of a “legal base station”, then the RSRP and / or RSRQ will still be different on each subscriber device.

[0042] If the attacker's VBS moves.

[0043] Such a move will also cause a sudden change in RSRP and / or RSRQ on one or more subscriber devices.

[0044] In case of appearance of “new” base stations in the area (with new identifiers), the physical cell identifier (PCI), and / or tracking area code (TAC), and / or absolute number of the downlink radio frequency channel (EARFCN-DL - eUTRAN) are used as data on the base stations, and it is also possible to draw a conclusion about the appearance of a VBS in the area.

[0045] The emergence of “new” base stations + the use of the proposed method will reduce the likelihood of “false alarms”.

[0046] To confirm the detection of a moving VBS, data on newly acquired cell identifiers (PCI) and / or tracking area codes (TACs) and / or absolute downlink radio frequency number (EARFCN-DL - eUTRAN) are also used. To increase the reception range, subscriber units can be elevated.

[0047] A method according to any of the points, characterized in that in order to increase the detection range (and this directly affects the technical result - the greater the distance at which the EBS is detected, the longer the time will be to respond to this threat), the subscriber device is predominantly raised to a height.

[0048] In this case, such lifting can be carried out, for example, by means of masts, aircraft (for example, lighter than air - an airship, a balloon, etc., UAVs, etc.).

[0049] In particular, subscriber devices are mounted permanently and have a constant power supply.

[0050] In particular, the analytical module is based on an electronic computing device.

[0051] A hardware and software complex called “SOTA”2 can be used as subscriber devices (2 SOTA Software / / npocolibri URL: https: / / npocolibri.ru / sota / (date accessed: 05 / 27 / 2024).).

[0052] The SOTA hardware and software complex is designed to collect technical information about base stations in 2G, 3G, 4G, and 5G cellular networks.

[0053] Purpose of the SOTA hardware and software complex:

[0054] Collection of parameters of base stations of cellular operators (including RSRP, RSRQ);

[0055] Calculation of the location of cellular base stations;

[0056] Analysis of technical information of cellular base stations;

[0057] Ensuring the security of using cellular communications.

[0058] A personal computer can be used as an analytical module.

[0059] The analytics module for collecting data from the sensors can be connected to them either wired or wirelessly. The analytics module must also be connected to the base station's control system to transmit commands to increase or decrease the power of a specific sector antenna.

[0060] Subscriber devices can be either custom-made devices (sensors) or any mobile subscriber devices (e.g., LTE or NR smartphones), although smartphones can also be used. The sensors are permanently mounted and have a constant power supply.

[0061] Also, information about RSRP and / or RSRQ for all subscriber devices served by the base station can be obtained using the so-called “measurement reports”.

[0062] Such RSRP and / or RSRQ information from all subscriber devices can be received by the base station and then transmitted to the analytical module, and the analytical module then makes a conclusion about the detection of the airborne force.

[0063] To obtain measurement reports containing the system's required parameters, the base station sends RRC messages to connected subscriber units. These messages contain a configuration of the required measurements, which includes a variety of parameters, including the most important information for detecting radio frequency interference (RFI), such as carrier frequencies, neighboring cell identifiers, and the signal strength and quality received from them.

[0064] 3GPP standards require that measurement reports be sent by specific sensors only after successfully completing security procedures. Therefore, such messages are encrypted, preventing unauthorized subscriber devices or analyzers from reading or modifying reports sent by an authenticated sensor.

[0065] Depending on the measurement configuration, the report may additionally contain measurements in serving and neighboring cells, indicating physical cell identifiers (PCI), received signal power (RSRP), received signal quality (RSRQ), and signal-to-interference ratio (SINR).

[0066] Implementation of the invention.

[0067] The essence of the invention is to ensure the protection of private wireless networks, including mobile communications such as LTE, NR networks, deployed at sites (organizations, enterprises) from external influences (including attacks using virtual base stations in motion).

[0068] This invention can also be used to protect wireless networks deployed on the territory of a restricted area facility.

[0069] In the present invention, a facility refers to buildings, structures, utility networks, and adjacent territory separated (isolated) from the outside. The primary distinguishing feature of such facilities is the presence of an access control system, meaning that access is permitted to specific individuals. Access is achieved through administrative and organizational measures (through security personnel) and technical measures (e.g., barriers, fences, and video cameras). External interference with the facility's radio network is then possible only from outside the facility's perimeter. A facility's radio network (wireless network) includes both a private (closed) radio network installed on the facility and a mobile operator's radio network.

[0070] Subscriber units can be either custom-made devices or any mobile communication devices (e.g., LTE or NR smartphones), although smartphones can also be used. These sensors are designed to communicate with one or more mobile base stations of various communication generations (GSM, UMTS, LTE, NR). Subscriber units can be permanently mounted and powered.

[0071] The analytical module may be based on an electronic computing device, such as a personal computer, laptop, etc., and may be mounted either inside or outside the facility. At least one communication module may be connected to the analytical module, capable of connecting the analytical module to sensors and / or a base station.

[0072] As an example, the Sota APCS, which, with the help of software, continuously monitors the RSRP and / or RSRQ of all base stations in the local area.

[0073] The rate of change of the signal level is defined as the change in RSRP or RSRQ over a certain period of time (to avoid false alarms, the time interval should not be too short - based on experiments, more than 0.5 sec). The software then calculates the rate of change (increase or decrease) of RSRP and / or RSRQ for each base station and ranks them. The range of RSRP and / or RSRQ change is also calculated for each of the surrounding base stations (the cell identifier (PCI), and / or tracking area code (TAC), and / or absolute downlink number (eUTRAN) are used for identification), and / or mobile country code (MCC), and / or mobile network code (MNC). This information is transmitted to the analytical module.

[0074] For example, if during the time period t+1, the RSRP for base station "1" changed by 60%, for base station "2" by 12%, for base station "3" by 8%, and for base station "4" by 5%. During this measurement, the subscriber device was in a relatively stationary state (this can be determined using an accelerometer and / or gyroscope and / or navigation module). To reduce false alarms, it is necessary for the subscriber device to be stationary (if it is in a person's clothing or belongings, it must be stationary).

[0075] Since the rate of change of this parameter at base station “1” is higher than at base station “2” by more than 30%, we consider base station “1” to be a moving air force.

Claims

CLAUSES OF THE INVENTION Method for detecting the operation of a virtual base station in motion 1. A method for identifying a virtual base station in motion, characterized in that at least one subscriber device is used that is capable of identifying the level of the received pilot signal power RSRP and / or the quality of the received pilot signals RSRQ of the base stations, while continuously measuring the level of RSRP and / or RSRQ for each base station in the time period ti, calculating the rate of change of RSRP and / or RSRQ for each base station and ranking them, and if in the time period ti+i the rate of change of RSRP and / or RSRQ for the base station for which the maximum rate of change is recorded differs from the second base station in the value of the rate of change of RSRP and / or RSRQ by more than 30%, a conclusion is made that the base station for which the maximum rate of change is recorded is a moving virtual base station.

2. The method according to item 1, characterized in that the subscriber device is in a stationary state.

3. The method according to item 2, characterized in that the immobility of the subscriber device is determined using a gyroscope and / or an accelerometer and / or a navigation module.

4. The method according to item 1, characterized in that it is carried out using several subscriber devices. 5 Method according to item 1, characterized in that, in order to confirm the detection of a moving VBS, data from the cell identifier (PCI) and / or the tracking area code (TAC) and / or the absolute number of the downlink radio frequency channel (EARFCN-DL) are also used.

6. The method according to item 1, characterized in that the subscriber device is raised to a height.

7. The method according to paragraph 1, characterized in that the subscriber device is mounted along the perimeter of the protected object.

8. The method according to item 6, characterized in that the subscriber device is raised to a height using masts.

9. The method according to item 6, characterized in that the subscriber device is raised to a height using aircraft. 11 SUBSTITUTE SHEET (RULE 26)

Citation Information

Patent Citations

  • Method and system for obtaining location of user equipment, management platform and virtual base station

    CN106792498A

  • Method of counteracting malicious attacks aimed at listening to paging messages transmitted to subscriber devices of wireless communication network

    RU2818276C1

  • Method for Handling Pseudo Base Station, Mobile Terminal, and Storage Medium

    US20210250769A1

  • Denial of service detection and mitigation in a multi-access edge computing environment

    US20210306372A1

  • Method of determining location for installing moveable base station and information processing apparatus

    US20230247441A1