Base Station Connection Request Regulation for DoS Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless access networks are vulnerable to Denial of Service (DoS) and Distributed Denial of Service (DDoS) attacks, where attackers occupy network resources by sending rapid network connection requests, preventing legitimate users from accessing the network.

Innovation Solution

A network connection request regulation method that sets a delay time and credibility for a UE initiating a connection, discards initial connection requests, and adjusts the credibility based on abnormal behavior, probabilistically discarding subsequent requests to mitigate attack impact.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the base station accepts all network connection requests from UEs, then legitimate users can access the network normally, but the base station becomes vulnerable to DoS attacks where attackers can occupy network resources by sending rapid connection requests

Engineering Contradiction:
Improvenetwork service availabilityVSAvoidvulnerability to DoS attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The base station performs preliminary actions by setting a delay time and initial credibility for UEs before processing their network connection requests. This preliminary setup allows the system to proactively prevent DoS attacks by controlling the timing and probability of accepting connection requests, rather than reacting after resources are exhausted.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system dynamically adjusts the credibility of UEs based on their connection request behavior. When abnormal behavior is detected (such as rapid successive requests), the credibility is reduced, which in turn reduces the probability of accepting subsequent connection requests. This dynamic adjustment allows the base station to adapt to attack patterns while maintaining normal service for legitimate users.

Inventive Principle:
Principle #15Dynamics

2Object-affected harmful factors

If the base station implements strict connection request filtering to prevent DoS attacks, then network resource protection is improved, but legitimate users may experience delayed access due to delay time requirements

Engineering Contradiction:
Improvenetwork resource protectionVSAvoiduser access delay
Core Design Contradiction:
Object-affected harmful factorsVSLoss of time

Solution Approach 1:

The system changes the parameter of connection request acceptance from a binary accept/reject decision to a probabilistic decision based on UE credibility. This parameter change allows flexible control where legitimate users with high credibility are accepted with high probability (minimal delay), while attackers with reduced credibility are rejected with high probability (resource protection).

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system implements feedback by continuously monitoring UE connection behavior and adjusting credibility scores accordingly. This feedback mechanism ensures that the delay and rejection probability are dynamically adapted to each UE's behavior pattern, minimizing impact on legitimate users while maintaining strong protection against attackers.

Inventive Principle:
Principle #23Feedback

3Reliability

If the base station processes every network connection request through authentication, then security is maintained, but the processing time and system complexity increase

Engineering Contradiction:
Improveconnection securityVSAvoidconnection processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system applies partial action by not requiring full authentication processing for every connection request. Instead, it uses a simplified credibility-based filtering mechanism that processes connection requests probabilistically based on UE behavior history. Full authentication is only triggered when necessary, reducing overall system complexity while maintaining security.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20250294365A1Regulation and control method for network connection request, controller, base station, and storage medium
Publication Date: 2025.09.18 ZTE CORP
  • US20250294365A1 patent drawing
  • US20250294365A1 patent drawing
  • US20250294365A1 patent drawing

AI summary

The present disclosure discloses a regulation and control method for a network connection request, a controller, a base station, and a storage medium. The regulation and control method may include: setting a lag duration and a current credibility for a terminal initiating a network connection request to a current base station for the first time; discarding the network connection request initiated by the terminal to the current base station for the first time, and replying an indication message to the terminal to instruct the terminal to initiate the network connection request again after the lag duration; and each time the network connection request initiated by the terminal is received by the terminal is abnormal within the lag duration, reducing the current credibility of the terminal according to a preset rule, and according to the current credibility, determining the probability of discarding the network connection request initiated by the terminal.