SS7 Signalling Dialogue Identifier Monitoring for Fraud Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Detecting fraudulent and disruptive SS7 signalling traffic in telecommunications networks is challenging due to spoofing, where attackers hide their identity, making it difficult to differentiate malicious from legitimate traffic, especially when the traffic resembles normal signalling behavior.

Innovation Solution

A method that monitors signalling messages by comparing their dialogue identifiers with a list of known identifiers, categorizing them as suspicious if they do not match, and generating alerts if a threshold of suspicious messages with common characteristics is reached, allowing network operators to investigate and dispute charges.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional monitoring methods are used to detect fraudulent SS7 signalling traffic, then legitimate traffic can be processed normally, but malicious traffic cannot be reliably identified due to spoofing

Engineering Contradiction:
Improvedetection reliabilityVSAvoidtraffic identification difficulty
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

Instead of monitoring only outgoing traffic from the attacked network, the invention monitors incoming response traffic at the spoofed network entity. This inversion of the monitoring direction allows detection of spoofing because responses sent to spoofed addresses will not be properly acknowledged or will show anomalies that reveal the fraud.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The invention introduces a monitoring entity that acts as an intermediary between the attacked network and the spoofed network. This intermediary monitors the signalling dialogue identifiers and compares them against expected patterns, enabling detection of malicious traffic without directly interfering with legitimate communications.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If all signalling messages are monitored and analyzed in detail, then fraudulent traffic can be detected, but network performance and processing speed deteriorate

Engineering Contradiction:
Improvefraud detection accuracyVSAvoidnetwork processing speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The invention extracts only the critical signalling dialogue identifier from each message for monitoring purposes, rather than analyzing the complete message content. This selective extraction maintains detection capability while significantly reducing processing overhead and preserving network performance.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The monitoring system performs partial analysis by focusing only on specific message characteristics (dialogue identifiers) rather than complete message inspection. This partial action approach provides sufficient detection capability while avoiding the performance penalty of exhaustive analysis.

Inventive Principle:
Principle #16Partial or excessive action

3Ease of operation

If monitoring is performed only at the attacked network, then outgoing malicious traffic can be detected, but spoofed responses cannot be identified

Engineering Contradiction:
Improvemonitoring simplicityVSAvoidspoofing detection capability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The invention places monitoring at the spoofed network entity rather than only at the attacked network. This inverted monitoring location enables detection of responses that are sent to spoofed addresses, as these responses will exhibit anomalous patterns that reveal the spoofing attempt.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The invention adds a new monitoring dimension by observing traffic from the perspective of the spoofed network entity rather than only from the attacked network. This dimensional shift in monitoring location enables detection of response anomalies that would be invisible from the traditional monitoring perspective.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentEP3018876B1Monitoring of signalling traffic
Publication Date: 2020.01.01 VODAFONE IP LICENSING LTD
  • EP3018876B1 patent drawingFigure 1
  • EP3018876B1 patent drawingFigure 2
  • EP3018876B1 patent drawingFigure 3A~3B

AI summary

Signalling messages may be monitored in a telecommunications network by receiving an indication of a signalling message for a network entity of the telecommunications network, the signalling message comprising a signalling dialogue identifier. The signalling dialogue identifier of the received signalling message is compared with a list of known signalling dialogue identifiers relating to the network entity and the signalling message is categorised based on a result of the step of comparing, for example as suspicious. If a number of signalling messages for a network entity of the telecommunications network categorised as suspicious and having a common additional characteristic is at least a threshold value, an alert may be generated.