Diameter Network Node Spoofing Detection via Session Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The Diameter protocol in telecommunication networks is vulnerable to spoofing attacks due to its hop-by-hop routing approach, leading to denial-of-service (DoS) attacks and revenue losses, as existing detection and prevention techniques fail to effectively address the specific vulnerabilities and often misconfigure filtering rules, causing legitimate messages to be blocked.

Innovation Solution

Implement a method where a network node verifies the validity of received requests by establishing a new session with the claimed sender, sending a modified copy of the request, and receiving a response to determine if it is a valid request, thereby detecting and preventing spoofing attacks before execution.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If hop-by-hop routing is used in Diameter protocol, then message routing flexibility is improved, but vulnerability to spoofing attacks increases

Engineering Contradiction:
Improvemessage routing flexibilityVSAvoidvulnerability to spoofing attacks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by establishing a new session with the claimed sender before processing the request. This preliminary session establishment allows the system to verify the sender's identity in advance, preventing spoofing attacks before they can execute harmful actions while maintaining the hop-by-hop routing flexibility.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary verification mechanism where a modified copy of the request is sent through a newly established session to verify the sender's identity. This intermediary step acts as a mediator between the routing flexibility and security requirements, allowing the system to maintain routing adaptability while adding security verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If filtering rules are implemented to detect spoofing, then security detection capability is improved, but legitimate messages may be blocked

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidmessage delivery accuracy
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements feedback by sending a modified copy of the request to the claimed sender and waiting for a response. This feedback mechanism provides positive verification of the sender's identity, allowing the system to distinguish between legitimate and spoofed messages accurately, thereby improving security detection without blocking legitimate traffic.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs preliminary verification by establishing a new session and sending a modified request before processing the original message. This preliminary action ensures that legitimate messages are verified and allowed through, while spoofed messages are identified and blocked, thus improving both security and message delivery accuracy.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If session verification is performed for each request, then spoofing detection accuracy is improved, but processing time increases

Engineering Contradiction:
Improvespoofing detection accuracyVSAvoidrequest processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies partial action by sending a modified copy of the request for verification purposes while the original request can be processed in parallel. This approach achieves accurate spoofing detection through session verification without significantly increasing overall processing time, as the verification and original processing can occur concurrently.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20240147238A1Diameter spoofing detection and post-spoofing attack prevention
Publication Date: 2024.05.02 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US20240147238A1 patent drawing
  • US20240147238A1 patent drawing
  • US20240147238A1 patent drawing

AI summary

The solutions and methods are directed to spoofing detection approaches and post-spoofing attack prevention schemes. When a first network node such as a Mobility Management Entity, MME, receives a request from an attacker, the first network node sends a modified copy of the request to a second network node such as Home Subscriber Server, HSS, for verification of the request. When the first network node receives a response from the second node and finds that the request is a spoofed request, the first network may disregard the request. This example of the spoofing detection approaches may help the second network node to avoid disruptions of services such as Denial-of-Service, DoS, attacks that could have been caused by multiple Update Location Requests, ULRs, sent by multiple User Equipment, UE, after the spoofing attempted by the attacker becomes successful.