Network Node False Base Station Detection via Protocol Timing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current telecommunication systems are vulnerable to false base station attacks, where non-legitimate devices intercept traffic between wireless devices and network nodes, making it difficult to prevent such attacks without significant modifications to radio protocols, and existing intrusion detection systems are ineffective in detecting these attacks targeting end users.
Innovation Solution
A detecting node in the communications network that analyzes protocol events and time instances to identify communications with non-legitimate devices, allowing the network to determine if a wireless device has been connected to a false base station without requiring modifications to the wireless device or significant hardware upgrades, by using existing network nodes and software updates.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing intrusion detection systems are used, then network infrastructure security can be monitored, but they are ineffective in detecting attacks targeting end users
Solution Approach 1:
Instead of having the wireless device detect the non-legitimate device itself, the patent inverts the detection approach by having the network node detect protocol events and time instances from the wireless device's communications to determine if it has been communicating with a non-legitimate device. This inversion allows the detection capability to be embedded in the network infrastructure where it can effectively monitor all end users.
2Reliability
If radio protocols are modified to prevent false base station attacks, then security can be improved, but significant modifications to radio protocols are required
Solution Approach 1:
The patent introduces an intermediary detection mechanism at the network node that analyzes protocol events and time instances without requiring modification of the existing radio protocols between the wireless device and network. The network node acts as a mediator that interprets existing protocol interactions to detect non-legitimate devices, thereby improving security while maintaining protocol compatibility.
3Reliability
If wireless devices are equipped with detection capabilities, then they can identify non-legitimate devices, but modifications to the wireless device are required
Solution Approach 1:
Instead of equipping wireless devices with detection capabilities, the patent inverts the approach by having the network node perform the detection based on protocol events from the device. This eliminates the need for complex modifications to wireless devices while achieving the same security objective through network-side analysis.
4Measurement precision
If comprehensive monitoring is implemented, then detection accuracy improves, but operational costs increase
Solution Approach 1:
The patent implements partial monitoring by focusing detection efforts on specific protocol events and time instances that are indicative of non-legitimate device communications, rather than monitoring all communications comprehensively. This selective approach maintains detection precision while reducing the operational burden and costs associated with comprehensive monitoring of all network traffic.
Data Source
AI summary
Embodiments herein relate to a method performed by a detecting node (101) in a communications network (100), for detecting that a wireless device, WD, (120) associated with a first domain of the communications network (100) has been communicating with a non-legitimate device (150). The non-legitimate device (150) is a device associated with a second domain of the communications network (100). The non-legitimate device (150) impersonates a network node (110, 111, 140) of a first domain of the communications network (100). The detecting node (101) obtains information regarding one or more protocol events related to the communication between the WD (120) and a first network node (110, 111, 140). The information comprises a time instance related to the one or more protocol events. The detecting node (101) determines, based on the time instance and a set of time limits related to the one or more protocol events, that the WD (120) has been communicating with the non-legitimate device (150).


