NAS Traffic Analysis for 5G DoS Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for detecting Denial-of-Service (DOS) attacks in 5G networks face challenges in accurately distinguishing between legitimate and malicious traffic, leading to false detection issues due to variations in DOS attack types, such as bogus UE registration messages and excessive PDU session modification messages.

Innovation Solution

The method involves network functions like NWDAF and AMF exchanging reports that include NAS message type identifiers and UE type information, allowing for the construction of detailed NAS traffic profiles to differentiate between normal and malicious activity, thereby reducing false positives and accurately identifying DOS attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional DOS attack detection methods are used to monitor all NAS traffic, then attack detection capability is improved, but false detection rate increases due to inability to distinguish legitimate from malicious traffic variations

Engineering Contradiction:
ImproveDOS attack detection capabilityVSAvoidTraffic pattern classification accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent segments NAS traffic into distinct categories (mobile-originated, mobile-terminated, roaming, handover) and applies specific detection thresholds and analysis methods to each segment. This allows the system to differentiate between legitimate traffic variations and actual DOS attacks by understanding normal behavior patterns for each traffic type, thereby reducing false detections while maintaining detection capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent dynamically adjusts detection parameters such as message rate thresholds, time window durations, and anomaly detection sensitivity based on network conditions and traffic patterns. By changing these parameters adaptively, the system can distinguish between legitimate traffic fluctuations and malicious DOS attacks, improving measurement precision without sacrificing detection reliability.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If detailed NAS traffic analysis is performed to reduce false positives, then detection precision is improved, but processing complexity increases

Engineering Contradiction:
ImproveMalicious traffic identification accuracyVSAvoidTraffic analysis system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent divides the complex task of NAS traffic analysis into manageable segments by categorizing traffic into specific types (MO, MT, roaming, handover) and applying targeted analysis rules to each. This segmentation reduces overall system complexity by allowing specialized, simpler detection logic for each category rather than requiring a single complex analysis framework for all traffic.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different levels of analysis depth and detection strictness to different traffic types based on their characteristics and risk profiles. For example, certain traffic types may use simpler threshold-based detection while others require more sophisticated analysis. This local quality approach reduces processing complexity by avoiding uniform high-complexity analysis across all traffic while maintaining high detection precision where needed.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20240292225A1Non-access stratum traffic analysis
Publication Date: 2024.08.29 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US20240292225A1 patent drawing
  • US20240292225A1 patent drawing
  • US20240292225A1 patent drawing

AI summary

A method performed by a first network function is provided. The method comprises receiving a request for Non-Access Stratum (NAS) traffic information. The request was transmitted by a second network function. The method further comprises after receiving the request, sending towards the second network function a report comprising: i) a NAS message type identifier identifying a type of NAS message and information indicating a number of received NAS messages of the identified type and/or ii) user equipment (UE) type information indicating a type of UE and information indicating a number of NAS messages transmitted by UEs of the indicated type.