Monitor Device for DoS Attack Detection in Mobile Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing threat of Denial of Service (DoS) attacks on mobile networks causes congestion and high processing loads, affecting not only individual mobile networks but also global roaming services, as malicious communication terminals repeatedly execute the ATTACH procedure to overwhelm the system.

Innovation Solution

A monitor device and base station system that estimates the number of rejected ATTACH procedures to identify attacking communication terminals and determines whether to execute the ATTACH procedure based on communication terminal identification information, reducing the load on the network by selectively allowing or rejecting registration requests.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the ATTACH procedure is executed for all communication terminals, then communication service availability is improved, but network load and processing burden increase due to DoS attacks

Engineering Contradiction:
Improvecommunication service availabilityVSAvoidnetwork processing load
Core Design Contradiction:
ReliabilityVSPower

Solution Approach 1:

The base station performs preliminary monitoring of ATTACH procedure rejection counts before fully executing the ATTACH procedure. By pre-identifying communication terminals with abnormal rejection patterns (potential DoS attackers), the system can prevent excessive processing loads while maintaining service availability for legitimate users. The monitoring and threshold comparison actions are performed in advance to filter out malicious requests.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The invention applies different processing qualities to different communication terminals based on their ATTACH rejection history. Legitimate terminals receive full ATTACH procedure processing, while terminals identified as potential attackers (those exceeding rejection thresholds) receive restricted processing. This localized differentiation allows the network to maintain high service availability for normal users while reducing processing load by limiting services to suspicious terminals.

Inventive Principle:
Principle #3Local quality

2Object-affected harmful factors

If the ATTACH procedure is rejected for terminals with high rejection counts, then network protection from DoS attacks is improved, but legitimate communication terminals may be incorrectly blocked

Engineering Contradiction:
ImproveDoS attack impactVSAvoidlegitimate terminal service
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The base station implements a feedback mechanism by continuously monitoring ATTACH procedure rejection counts for each communication terminal and comparing them against predefined thresholds. This feedback loop allows the system to dynamically adjust its response: terminals exceeding thresholds are restricted, while those below thresholds continue normal processing. The feedback-based approach reduces false blocking of legitimate terminals by using objective, measured criteria rather than arbitrary restrictions.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The invention changes the parameter of ATTACH procedure execution based on the rejection count parameter. When the rejection count parameter exceeds a threshold, the system changes the state of ATTACH execution from permitted to restricted. This parameter-based control allows flexible adjustment of security thresholds to balance DoS protection with legitimate service, reducing harmful factors while minimizing false positives against legitimate terminals.

Inventive Principle:
Principle #35Parameter changes

3Difficulty of detecting and measuring

If monitoring of ATTACH procedure rejections is performed, then detection of attacking terminals is improved, but device complexity and monitoring overhead increase

Engineering Contradiction:
Improveattacking terminal detectionVSAvoidmonitoring system complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The base station performs self-monitoring of ATTACH procedure rejection counts using its own existing resources and capabilities. Rather than requiring external monitoring systems or additional complex infrastructure, the base station autonomously tracks rejection counts, compares them against thresholds, and makes processing decisions. This self-service approach improves attacking terminal detection while minimizing additional device complexity, as the monitoring functionality is integrated into the base station's existing operational procedures.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11190541B2Monitor device, base station, monitoring method, control method, and non-transitory computer readable medium
Publication Date: 2021.11.30 NEC CORP
  • US11190541B2 patent drawing
  • US11190541B2 patent drawing
  • US11190541B2 patent drawing

AI summary

An object is to provide a monitor device capable of reducing threat of DoS attacks on a mobile network. A monitor device (10) according to the present invention includes a signal monitor unit (11) for estimating a specific base station communicating with a communication terminal (30) attacking a mobile network according to the number of times an ATTACH procedure is rejected, in which the ATTACH procedure is for registering information about a communication terminal (30) communicating with a base station (20) in a communication device (40) located in the mobile network, and a base station control unit (12) for causing the specific base station to determine whether to execute the ATTACH procedure related to a communication terminal served by the specific base station according to communication terminal identification information set in a signal transmitted from the communication terminal served by the specific base station.