Statistical Signalling Traffic Detection for SS7 Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Detecting undesirable SS7 signalling traffic in telecommunications networks is challenging due to its ability to be hidden within legitimate traffic, making it difficult to identify malicious sources, especially with the introduction of IP as an alternative transport layer, which has led to abuses like HLR lookup, location tracking, and Anti-Steering of Roaming, and existing solutions like firewalls and ACLs provide limited protection.
Innovation Solution
A method that evaluates signalling traffic patterns against predetermined profiles using statistical methods, such as Chi-Squared tests, to identify unusual patterns and detect undesirable behaviour, including 'zero-day' exploits, by learning profiles from known sources and comparing them to unknown sources, enabling the creation of a database for categorization and action on suspicious nodes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional firewalls and ACLs are used to protect against SS7 signalling abuse, then network security is improved, but device complexity and cost increase while providing limited protection against new threats
Solution Approach 1:
The patent changes the detection parameters from simple address-based filtering to statistical analysis of signalling traffic patterns. By monitoring parameters such as message frequency, source-destination pairs, and temporal patterns, the system dynamically identifies malicious traffic without requiring complex rule sets or multiple specialized devices.
2Measurement precision
If multiple anti-fraud techniques are implemented to combat different threats, then detection capability is improved, but cost and complexity increase significantly
Solution Approach 1:
The patent creates a universal detection system that can identify multiple types of SS7 abuses (HLR lookup, location tracking, Anti-Steering of Roaming, M2M abuse) using a single statistical analysis approach. The system adapts to different threat types by analyzing traffic patterns rather than requiring separate specialized techniques for each threat.
Solution Approach 2:
The system performs preliminary learning during a monitoring phase to establish baseline statistical profiles of normal signalling traffic from different network elements. This preliminary action enables the system to detect deviations indicating malicious activity without requiring pre-configured rules for each potential threat.
3Measurement precision
If statistical analysis of signalling traffic patterns is performed, then detection accuracy for malicious traffic is improved, but processing requirements increase
Solution Approach 1:
The patent applies statistical analysis selectively rather than to all traffic uniformly. The system focuses on analyzing traffic from specific sources or patterns that deviate from established baselines, performing detailed statistical examination only where needed rather than continuously processing all signalling traffic at full depth.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Undesirable signalling traffic received at a telecommunications network is detected by establishing at least one statistical parameter in respect of signalling traffic received at the telecommunications network from at least one specific source and evaluating the established at least one statistical parameter against one or more predetermined statistical profiles.