SS7 Signalling Dialogue Identifier Monitoring for Fraud Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Detecting fraudulent and disruptive SS7 signalling traffic in telecommunications networks is challenging due to spoofing, where attackers hide their identity, making it difficult to differentiate malicious from legitimate traffic, especially when the traffic resembles normal signalling behavior.
Innovation Solution
A method that monitors signalling messages by comparing their dialogue identifiers with a list of known identifiers, categorizing them as suspicious if they do not match, and generating alerts if a threshold of suspicious messages with common characteristics is reached, allowing network operators to investigate and dispute charges.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional monitoring methods are used to detect fraudulent SS7 signalling traffic, then legitimate traffic can be processed normally, but malicious traffic cannot be reliably identified due to spoofing
Solution Approach 1:
Instead of monitoring only outgoing traffic from the attacked network, the invention monitors incoming response traffic at the spoofed network entity. This inversion of the monitoring direction allows detection of spoofing because responses sent to spoofed addresses will not be properly acknowledged or will show anomalies that reveal the fraud.
Solution Approach 2:
The invention introduces a monitoring entity that acts as an intermediary between the attacked network and the spoofed network. This intermediary monitors the signalling dialogue identifiers and compares them against expected patterns, enabling detection of malicious traffic without directly interfering with legitimate communications.
2Reliability
If all signalling messages are monitored and analyzed in detail, then fraudulent traffic can be detected, but network performance and processing speed deteriorate
Solution Approach 1:
The invention extracts only the critical signalling dialogue identifier from each message for monitoring purposes, rather than analyzing the complete message content. This selective extraction maintains detection capability while significantly reducing processing overhead and preserving network performance.
Solution Approach 2:
The monitoring system performs partial analysis by focusing only on specific message characteristics (dialogue identifiers) rather than complete message inspection. This partial action approach provides sufficient detection capability while avoiding the performance penalty of exhaustive analysis.
3Ease of operation
If monitoring is performed only at the attacked network, then outgoing malicious traffic can be detected, but spoofed responses cannot be identified
Solution Approach 1:
The invention places monitoring at the spoofed network entity rather than only at the attacked network. This inverted monitoring location enables detection of responses that are sent to spoofed addresses, as these responses will exhibit anomalous patterns that reveal the spoofing attempt.
Solution Approach 2:
The invention adds a new monitoring dimension by observing traffic from the perspective of the spoofed network entity rather than only from the attacked network. This dimensional shift in monitoring location enables detection of response anomalies that would be invisible from the traditional monitoring perspective.
Data Source
Figure 1
Figure 2
Figure 3A~3B
AI summary
Signalling messages may be monitored in a telecommunications network by receiving an indication of a signalling message for a network entity of the telecommunications network, the signalling message comprising a signalling dialogue identifier. The signalling dialogue identifier of the received signalling message is compared with a list of known signalling dialogue identifiers relating to the network entity and the signalling message is categorised based on a result of the step of comparing, for example as suspicious. If a number of signalling messages for a network entity of the telecommunications network categorised as suspicious and having a common additional characteristic is at least a threshold value, an alert may be generated.