GTP Session Management via Hash Buffer for IP Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems lack effective methods for managing and controlling GTP sessions in LTE networks, particularly in preventing IP attacks and managing traffic, due to limitations in monitoring and processing GTP tunnel data.

Innovation Solution

A method and apparatus that monitor tunnel creation requests and responses between a Serving Gateway (S-GW) and a PDN Gateway (P-GW) to create and manage GTP tunnels, extract user equipment information, and register it with a hash buffer, enabling session-based control and management of GTP packets to detect and block IP attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If data and signaling information are transferred through the GTP tunnel based on only a unique TEID, then the tunnel establishment is simple, but the capability to check the target of a GTP attack and perform control is limited

Engineering Contradiction:
Improvetunnel establishment complexityVSAvoidattack detection capability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the session identification by creating a session chain that links multiple TEIDs together through hash buffer entries. Each TEID is associated with session information including UE ID, APN, and other identifiers, allowing the system to track and identify attacks across multiple tunnel segments while maintaining simple TEID-based tunnel establishment

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a session management system as an intermediary between the GTP tunnel and the core network. This intermediary maintains hash buffers that map TEIDs to session information, enabling attack detection and control without modifying the underlying simple TEID-based tunnel mechanism

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a session management system monitors tunnel creation requests and responses to create session chains, then the control capability over GTP packets is enhanced, but the system complexity increases

Engineering Contradiction:
Improvesession control capabilityVSAvoidsession management system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent performs preliminary actions by pre-establishing session chains and populating hash buffers with session information before actual data transmission occurs. When tunnel creation requests and responses are monitored, the system proactively creates session entries and links TEIDs to session information in advance, enabling faster attack detection and control during actual operation

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates simplified copies of session information in hash buffers that can be quickly searched and matched against incoming packets. Instead of managing complex session states directly, the system maintains copied session data with key identifiers (UE ID, APN, TEIDs) that enable efficient matching and control decisions

Inventive Principle:
Principle #26Copying

Data Source

PatentUS9510377B2Method and apparatus for managing session based on general packet radio service tunneling protocol network
Publication Date: 2016.11.29 WINS CO LTD
  • US9510377B2 patent drawing
  • US9510377B2 patent drawing
  • US9510377B2 patent drawing

AI summary

The present invention includes creating a session in response to a session setup request for a general packet radio service (GPRS) application service, receiving GTP packet data using GPRS tunneling protocol (GTP) tunnel, performing decoding on the GTP packet data, determining whether there is an attack attributable to malicious behavior based on a predetermined management DB, identifying the type of the GTP packet data as the type of GTP packet for attacked GTP packet data and the type of GTP packet for non-attacked packet data based on a result of the determination, carrying out a predetermined policy for the identified type of GTP packet, performing the standardization of the packet data of each GTP version, determining whether the standardized packet data has been registered with a hash buffer in accordance with the type of pairing message for each command, and processing a session based on a result of the determination.