5G Base Station Cyber-Attack Mitigation via Beam Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current solutions for mitigating DDoS attacks in 5G networks focus on the user plane after device connection and do not effectively identify malicious user equipment before they impact the control plane.
Innovation Solution
A computer-implemented method that involves receiving a message from user equipment for network attachment, determining the location area based on transmission beam and timing advance values, analyzing user equipment behavior for potential cyber-attacks, and preventing communications from reaching the core network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If current DDoS mitigation solutions are applied after device connection focusing on user plane, then user plane traffic management is improved, but control plane security and early attack detection are worsened
Solution Approach 1:
The patent applies preliminary action by detecting and analyzing user equipment behavior during the attachment procedure before the device fully connects to the network. The base station monitors registration requests and location area information in advance, identifying potential malicious devices before they can flood the control plane with invalid or repeated registration requests. This early detection prevents DDoS attacks from impacting the control plane while maintaining normal user plane operations.
2Loss of energy
If DDoS attacks are detected and mitigated after connection establishment, then network resources are conserved, but attack response time and impact are worsened
Solution Approach 1:
The system performs attack detection during the attachment procedure, which occurs before full connection establishment. By analyzing user equipment behavior at this early stage and using location area determination, the system identifies malicious devices before they can launch large-scale DDoS attacks, significantly reducing response time and preventing extensive network resource consumption.
Solution Approach 2:
The patent implements preliminary anti-action by blocking or rejecting registration requests from identified malicious user equipment during the attachment procedure. This preventive measure stops potential DDoS attacks before they can execute, rather than reacting after the attack has begun, thereby minimizing both response time and network resource impact.
3Measurement precision
If location area determination is performed for every user equipment, then attack detection precision is improved, but processing complexity and time are worsened
Solution Approach 1:
The patent applies local quality by determining location areas specifically for user equipment that exhibits suspicious behavior or meets certain criteria during the attachment procedure, rather than performing location determination for all devices uniformly. This selective approach maintains high detection precision for malicious devices while reducing overall processing complexity and computational burden on the base station.
Data Source
Figure 1~2
Figure 3A~3B
Figure 4A~4B
AI summary
The invention concerns a method for mitigating a cyber-attack in a telecommunication system comprising a user equipment and a base station connected to a core network of a telecommunication network. The method comprises : receiving, from the user equipment, a message for attachment of the user equipment to the telecommunication network; determining a location area of the user equipment from a transmission beam selected by the user equipment for transmitting the received message, and from a timing advance value associated to the received message; determining, from a user equipment's behavior analysis, a possible start of the cyber-attack from at least one user equipment of the determined location area ; and, as a result of the determining, preventing communications associated to the user equipment to reach the core network.