Telecom Signaling Network DoS Detection via Traffic Rate Imbalance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Telecommunications signaling networks are vulnerable to denial of service attacks due to the lack of security mechanisms, as they were traditionally closed and not equipped to handle external threats, unlike Internet protocol networks.

Innovation Solution

A method is implemented to detect and mitigate denial of service attacks by collecting per link traffic rate information, identifying traffic imbalances between signaling links, and signaling a denial of service event to operators, who can then configure firewalls to block malicious packets.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional closed network architecture is maintained, then physical security is preserved, but vulnerability to external attacks increases

Engineering Contradiction:
Improvenetwork securityVSAvoidattack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary security measures by deploying detection mechanisms and firewall rules before attacks can successfully compromise the network. The system proactively monitors traffic patterns, establishes baseline behavior, and prepares mitigation strategies in advance, transforming the reactive security model into a proactive one that prevents attacks before they can cause damage.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary security layer between the signaling network and external traffic sources. This intermediary component analyzes incoming traffic, identifies malicious patterns, and filters attacks before they reach core network elements. The intermediary acts as a buffer that protects the closed network architecture while allowing legitimate traffic to pass through.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Difficulty of detecting and measuring

If per link traffic monitoring is implemented, then attack detection capability is improved, but system complexity increases

Engineering Contradiction:
Improveattack detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The patent divides the monitoring function into separate, modular components that track traffic on individual signaling links independently. Each link monitor operates as a discrete unit that collects and analyzes traffic data for its specific link, then reports findings to a central coordination system. This segmentation allows the complex monitoring task to be distributed across multiple simple, manageable units rather than requiring a single complex system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a multi-functional monitoring system that serves multiple purposes: detecting denial of service attacks, identifying traffic anomalies, establishing baseline behavior, and providing data for firewall rule generation. By designing the monitoring infrastructure to perform multiple functions simultaneously, the system reduces overall complexity compared to having separate specialized systems for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS7774849B2Methods, systems, and computer program products for detecting and mitigating denial of service attacks in a telecommunications signaling network
Publication Date: 2010.08.10 TEKELEC GLOBAL INC
  • US7774849B2 patent drawing
  • US7774849B2 patent drawing
  • US7774849B2 patent drawing

AI summary

Methods, systems, and computer program products for detecting and mitigating a denial of service attack in a telecommunications signaling network are provided. According to one method, traffic rate information is monitored on at least two of a plurality of signaling links. If the traffic rate on one of the signaling links exceeds the rate on at least another of the signaling links by a predetermined threshold, a denial of service attack is indicated. In response to indicating a denial of service attack, a user may take mitigating action, such as updating a firewall function to block packets associated with the offending source.