Diameter Network Node Spoofing Detection via Session Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The Diameter protocol in telecommunication networks is vulnerable to spoofing attacks due to its hop-by-hop routing approach, leading to denial-of-service (DoS) attacks and revenue losses, as existing detection and prevention techniques fail to effectively address the specific vulnerabilities and often misconfigure filtering rules, causing legitimate messages to be blocked.
Innovation Solution
Implement a method where a network node verifies the validity of received requests by establishing a new session with the claimed sender, sending a modified copy of the request, and receiving a response to determine if it is a valid request, thereby detecting and preventing spoofing attacks before execution.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If hop-by-hop routing is used in Diameter protocol, then message routing flexibility is improved, but vulnerability to spoofing attacks increases
Solution Approach 1:
The patent applies preliminary action by establishing a new session with the claimed sender before processing the request. This preliminary session establishment allows the system to verify the sender's identity in advance, preventing spoofing attacks before they can execute harmful actions while maintaining the hop-by-hop routing flexibility.
Solution Approach 2:
The patent introduces an intermediary verification mechanism where a modified copy of the request is sent through a newly established session to verify the sender's identity. This intermediary step acts as a mediator between the routing flexibility and security requirements, allowing the system to maintain routing adaptability while adding security verification.
2Reliability
If filtering rules are implemented to detect spoofing, then security detection capability is improved, but legitimate messages may be blocked
Solution Approach 1:
The patent implements feedback by sending a modified copy of the request to the claimed sender and waiting for a response. This feedback mechanism provides positive verification of the sender's identity, allowing the system to distinguish between legitimate and spoofed messages accurately, thereby improving security detection without blocking legitimate traffic.
Solution Approach 2:
The system performs preliminary verification by establishing a new session and sending a modified request before processing the original message. This preliminary action ensures that legitimate messages are verified and allowed through, while spoofed messages are identified and blocked, thus improving both security and message delivery accuracy.
3Measurement precision
If session verification is performed for each request, then spoofing detection accuracy is improved, but processing time increases
Solution Approach 1:
The patent applies partial action by sending a modified copy of the request for verification purposes while the original request can be processed in parallel. This approach achieves accurate spoofing detection through session verification without significantly increasing overall processing time, as the verification and original processing can occur concurrently.
Data Source
AI summary
The solutions and methods are directed to spoofing detection approaches and post-spoofing attack prevention schemes. When a first network node such as a Mobility Management Entity, MME, receives a request from an attacker, the first network node sends a modified copy of the request to a second network node such as Home Subscriber Server, HSS, for verification of the request. When the first network node receives a response from the second node and finds that the request is a spoofed request, the first network may disregard the request. This example of the spoofing detection approaches may help the second network node to avoid disruptions of services such as Denial-of-Service, DoS, attacks that could have been caused by multiple Update Location Requests, ULRs, sent by multiple User Equipment, UE, after the spoofing attempted by the attacker becomes successful.


