Monitor Device for DoS Attack Detection in Mobile Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing threat of Denial of Service (DoS) attacks on mobile networks causes congestion and high processing loads, affecting not only individual mobile networks but also global roaming services, as malicious communication terminals repeatedly execute the ATTACH procedure to overwhelm the system.
Innovation Solution
A monitor device and base station system that estimates the number of rejected ATTACH procedures to identify attacking communication terminals and determines whether to execute the ATTACH procedure based on communication terminal identification information, reducing the load on the network by selectively allowing or rejecting registration requests.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the ATTACH procedure is executed for all communication terminals, then communication service availability is improved, but network load and processing burden increase due to DoS attacks
Solution Approach 1:
The base station performs preliminary monitoring of ATTACH procedure rejection counts before fully executing the ATTACH procedure. By pre-identifying communication terminals with abnormal rejection patterns (potential DoS attackers), the system can prevent excessive processing loads while maintaining service availability for legitimate users. The monitoring and threshold comparison actions are performed in advance to filter out malicious requests.
Solution Approach 2:
The invention applies different processing qualities to different communication terminals based on their ATTACH rejection history. Legitimate terminals receive full ATTACH procedure processing, while terminals identified as potential attackers (those exceeding rejection thresholds) receive restricted processing. This localized differentiation allows the network to maintain high service availability for normal users while reducing processing load by limiting services to suspicious terminals.
2Object-affected harmful factors
If the ATTACH procedure is rejected for terminals with high rejection counts, then network protection from DoS attacks is improved, but legitimate communication terminals may be incorrectly blocked
Solution Approach 1:
The base station implements a feedback mechanism by continuously monitoring ATTACH procedure rejection counts for each communication terminal and comparing them against predefined thresholds. This feedback loop allows the system to dynamically adjust its response: terminals exceeding thresholds are restricted, while those below thresholds continue normal processing. The feedback-based approach reduces false blocking of legitimate terminals by using objective, measured criteria rather than arbitrary restrictions.
Solution Approach 2:
The invention changes the parameter of ATTACH procedure execution based on the rejection count parameter. When the rejection count parameter exceeds a threshold, the system changes the state of ATTACH execution from permitted to restricted. This parameter-based control allows flexible adjustment of security thresholds to balance DoS protection with legitimate service, reducing harmful factors while minimizing false positives against legitimate terminals.
3Difficulty of detecting and measuring
If monitoring of ATTACH procedure rejections is performed, then detection of attacking terminals is improved, but device complexity and monitoring overhead increase
Solution Approach 1:
The base station performs self-monitoring of ATTACH procedure rejection counts using its own existing resources and capabilities. Rather than requiring external monitoring systems or additional complex infrastructure, the base station autonomously tracks rejection counts, compares them against thresholds, and makes processing decisions. This self-service approach improves attacking terminal detection while minimizing additional device complexity, as the monitoring functionality is integrated into the base station's existing operational procedures.
Data Source
AI summary
An object is to provide a monitor device capable of reducing threat of DoS attacks on a mobile network. A monitor device (10) according to the present invention includes a signal monitor unit (11) for estimating a specific base station communicating with a communication terminal (30) attacking a mobile network according to the number of times an ATTACH procedure is rejected, in which the ATTACH procedure is for registering information about a communication terminal (30) communicating with a base station (20) in a communication device (40) located in the mobile network, and a base station control unit (12) for causing the specific base station to determine whether to execute the ATTACH procedure related to a communication terminal served by the specific base station according to communication terminal identification information set in a signal transmitted from the communication terminal served by the specific base station.


