NAS Traffic Analysis for 5G DoS Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for detecting Denial-of-Service (DOS) attacks in 5G networks face challenges in accurately distinguishing between legitimate and malicious traffic, leading to false detection issues due to variations in DOS attack types, such as bogus UE registration messages and excessive PDU session modification messages.
Innovation Solution
The method involves network functions like NWDAF and AMF exchanging reports that include NAS message type identifiers and UE type information, allowing for the construction of detailed NAS traffic profiles to differentiate between normal and malicious activity, thereby reducing false positives and accurately identifying DOS attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional DOS attack detection methods are used to monitor all NAS traffic, then attack detection capability is improved, but false detection rate increases due to inability to distinguish legitimate from malicious traffic variations
Solution Approach 1:
The patent segments NAS traffic into distinct categories (mobile-originated, mobile-terminated, roaming, handover) and applies specific detection thresholds and analysis methods to each segment. This allows the system to differentiate between legitimate traffic variations and actual DOS attacks by understanding normal behavior patterns for each traffic type, thereby reducing false detections while maintaining detection capability.
Solution Approach 2:
The patent dynamically adjusts detection parameters such as message rate thresholds, time window durations, and anomaly detection sensitivity based on network conditions and traffic patterns. By changing these parameters adaptively, the system can distinguish between legitimate traffic fluctuations and malicious DOS attacks, improving measurement precision without sacrificing detection reliability.
2Measurement precision
If detailed NAS traffic analysis is performed to reduce false positives, then detection precision is improved, but processing complexity increases
Solution Approach 1:
The patent divides the complex task of NAS traffic analysis into manageable segments by categorizing traffic into specific types (MO, MT, roaming, handover) and applying targeted analysis rules to each. This segmentation reduces overall system complexity by allowing specialized, simpler detection logic for each category rather than requiring a single complex analysis framework for all traffic.
Solution Approach 2:
The patent applies different levels of analysis depth and detection strictness to different traffic types based on their characteristics and risk profiles. For example, certain traffic types may use simpler threshold-based detection while others require more sophisticated analysis. This local quality approach reduces processing complexity by avoiding uniform high-complexity analysis across all traffic while maintaining high detection precision where needed.
Data Source
AI summary
A method performed by a first network function is provided. The method comprises receiving a request for Non-Access Stratum (NAS) traffic information. The request was transmitted by a second network function. The method further comprises after receiving the request, sending towards the second network function a report comprising: i) a NAS message type identifier identifying a type of NAS message and information indicating a number of received NAS messages of the identified type and/or ii) user equipment (UE) type information indicating a type of UE and information indicating a number of NAS messages transmitted by UEs of the indicated type.


