Base Station Connection Request Regulation for DoS Mitigation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless access networks are vulnerable to Denial of Service (DoS) and Distributed Denial of Service (DDoS) attacks, where attackers occupy network resources by sending rapid network connection requests, preventing legitimate users from accessing the network.
Innovation Solution
A network connection request regulation method that sets a delay time and credibility for a UE initiating a connection, discards initial connection requests, and adjusts the credibility based on abnormal behavior, probabilistically discarding subsequent requests to mitigate attack impact.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the base station accepts all network connection requests from UEs, then legitimate users can access the network normally, but the base station becomes vulnerable to DoS attacks where attackers can occupy network resources by sending rapid connection requests
Solution Approach 1:
The base station performs preliminary actions by setting a delay time and initial credibility for UEs before processing their network connection requests. This preliminary setup allows the system to proactively prevent DoS attacks by controlling the timing and probability of accepting connection requests, rather than reacting after resources are exhausted.
Solution Approach 2:
The system dynamically adjusts the credibility of UEs based on their connection request behavior. When abnormal behavior is detected (such as rapid successive requests), the credibility is reduced, which in turn reduces the probability of accepting subsequent connection requests. This dynamic adjustment allows the base station to adapt to attack patterns while maintaining normal service for legitimate users.
2Object-affected harmful factors
If the base station implements strict connection request filtering to prevent DoS attacks, then network resource protection is improved, but legitimate users may experience delayed access due to delay time requirements
Solution Approach 1:
The system changes the parameter of connection request acceptance from a binary accept/reject decision to a probabilistic decision based on UE credibility. This parameter change allows flexible control where legitimate users with high credibility are accepted with high probability (minimal delay), while attackers with reduced credibility are rejected with high probability (resource protection).
Solution Approach 2:
The system implements feedback by continuously monitoring UE connection behavior and adjusting credibility scores accordingly. This feedback mechanism ensures that the delay and rejection probability are dynamically adapted to each UE's behavior pattern, minimizing impact on legitimate users while maintaining strong protection against attackers.
3Reliability
If the base station processes every network connection request through authentication, then security is maintained, but the processing time and system complexity increase
Solution Approach 1:
The system applies partial action by not requiring full authentication processing for every connection request. Instead, it uses a simplified credibility-based filtering mechanism that processes connection requests probabilistically based on UE behavior history. Full authentication is only triggered when necessary, reducing overall system complexity while maintaining security.
Data Source
AI summary
The present disclosure discloses a regulation and control method for a network connection request, a controller, a base station, and a storage medium. The regulation and control method may include: setting a lag duration and a current credibility for a terminal initiating a network connection request to a current base station for the first time; discarding the network connection request initiated by the terminal to the current base station for the first time, and replying an indication message to the terminal to instruct the terminal to initiate the network connection request again after the lag duration; and each time the network connection request initiated by the terminal is received by the terminal is abnormal within the lag duration, reducing the current credibility of the terminal according to a preset rule, and according to the current credibility, determining the probability of discarding the network connection request initiated by the terminal.


