TR2021017334A2 - A DETECTION AND PREVENTION SYSTEM - Google Patents
A DETECTION AND PREVENTION SYSTEMInfo
- Publication number
- TR2021017334A2 TR2021017334A2 TR2021/017334A TR2021017334A TR2021017334A2 TR 2021017334 A2 TR2021017334 A2 TR 2021017334A2 TR 2021/017334 A TR2021/017334 A TR 2021/017334A TR 2021017334 A TR2021017334 A TR 2021017334A TR 2021017334 A2 TR2021017334 A2 TR 2021017334A2
- Authority
- TR
- Turkey
- Prior art keywords
- message
- hss
- operator
- call
- home subscriber
- Prior art date
Links
- 238000001514 detection method Methods 0.000 title description 6
- 230000002265 prevention Effects 0.000 title description 5
- 230000011664 signaling Effects 0.000 claims abstract description 10
- 230000001537 neural effect Effects 0.000 claims description 13
- 239000003795 chemical substances by application Substances 0.000 claims description 8
- 238000000034 method Methods 0.000 claims description 5
- 239000000969 carrier Substances 0.000 claims description 4
- 238000004891 communication Methods 0.000 claims description 2
- 230000002159 abnormal effect Effects 0.000 description 2
- 230000000903 blocking effect Effects 0.000 description 2
- 238000013475 authorization Methods 0.000 description 1
- 230000005540 biological transmission Effects 0.000 description 1
- 238000004590 computer program Methods 0.000 description 1
- 230000005764 inhibitory process Effects 0.000 description 1
- 210000005036 nerve Anatomy 0.000 description 1
- 238000012545 processing Methods 0.000 description 1
- 238000012552 review Methods 0.000 description 1
- 230000007704 transition Effects 0.000 description 1
Landscapes
- Mobile Radio Communication Systems (AREA)
Abstract
Bu buluş, Diameter sinyalleşmesiyle komşu ülkelerin şebekeleri üzerinden gelen atakların önlenebilmesini ve yanlışlıkla uluslararası dolaşım kapsamında sınır geçişlerinin zorlaştırılmasını sağlayan bir sistem (1) ile ilgilidir.The present invention relates to a system (1) that can prevent attacks coming over the networks of neighboring countries with Diameter signaling and make border crossings difficult within the scope of accidental international roaming.
Description
TARIFNAME BIR TESPIT VE ENGELLEME SISTEMI Teknik Alan Bu bulus, Diameter sinyallesmesiyle komsu ülkelerin sebekeleri üzerinden gelen ataklarin önlenebilmesini ve yanlislikla uluslararasi dolasim kapsaminda sinir geçislerinin zorlastirilmasini saglayan bir Sistem ile ilgilidir. Önceki Teknik Diameter protokolü LTE ve IMS sebekelerinde kimlik dogrulama, yetkilendirme ve muhasebe bilgilerini degis tokus etmek için kullanilan bir protokoldür ve mobil veri aglarina daha güvenilir ve esnek bir aktarim mekanizmasi saglamaktadir. DESCRIPTION A DETECTION AND PREVENTION SYSTEM Technical Area This invention is transmitted over the networks of neighboring countries with Diameter signaling. preventing attacks and limiting accidental international circulation. It is about a System that makes their transition difficult. Prior Art Diameter protocol Authentication, authorization in LTE and IMS networks It is a protocol used to exchange accounting and accounting information. It provides a more reliable and flexible transmission mechanism to data networks.
LTE sebekelerinde uluslararasi dolasiminin baslamasinin ardindan diameter protokolü üzerinden sinyallesme isleminde çesitli ataklar yapilmakta, söz konusu ataklar çesitli kategorilerde siniflandirilmakta ve her kategori için farkli engelleme yöntemleri kullanilmaktadir. Günümüzde gerçeklestirilen ataklar arasindaki en zor olani komsu ülke operatörleri üzerinden gelebilecek sahte sebeke seçim ataklaridir. Söz konusu ataklar teknigin bilinen durumunda mevcut olan uçus hiz kontrolü gibi gelismis kontroller ile çözülmemektedir. Bu nedenle günümüzde söz konusu ataklarin engellenmesine iliskin çözümlere ihtiyaç duyulmaktadir. dokümaninda, bir Diameter protokolünde saldiri amaçli gönderilen aldatici mesajlarin tespit edilmesini saglayan bir sistem ve yöntem açiklanmaktadir. Söz konusu bulus, bir teknik problemine göre bir Diameter protokol sahtekarligi saldiri tespit ekipmani içermekte olup, bir 5G çekirdek agindan elde edilen bir paketi almak için bir ag arayüzünü ve alinan paketi analiz etmek ve anormal bir paketi tespit etmek için bir program yükleyebilen ve yürütebilen bir bilgisayari içermekte; bilgisayar programi, bir Mobil Yönetim Varligindan (MME) ev aginin bir Ev Abone Sunucusuna (HSS) iletilen Diameter protokol Söa protokolünün bir paketinden normal bir lMSl (Uluslararasi Mobil Abone Kimligi) elde etmek için bir talimat saglamakta ve normal IMSI dahil edilen kaydi ilk oturum tablosuna eklemek için bir talimat içermekte; Mobil Yönetim Varligi (MME) tarafindan olusturulan CTP-C protokolünün Oturum Istegi Olustur mesajindan normal bir Uluslararasi Mobil Abone Kimligi (IMSI) elde etmek için bir talimat ve normal Diameter protokol Söa protokolünün bir IDR mesajina dahil olan ilk oturum tablosunu edinmekte; tablolarda arama yapmakta ve IDR mesajinin anormal bir Bulusun Kisa Açiklamasi Bu bulusun amaci, çalisma akisi gelen mesajin sinirdan geldiginin anlasilmasi ve kontrollerin gerçeklestirilmesinin ardindan abonenin kendi sebekesi üzerinden erisilebilir olup olmadiginin tespit edilmesini saglayarak komsu ülkelerin sebekeleri üzerinden gelen ataklarin önlenebilmesini ve yanlislikla uluslararasi dolasim kapsaminda sinir geçislerinin zorlastirilmasini saglayan bir sistem gerçeklestirmektir. After the start of international roaming in LTE networks, diameter Various attacks are made in the signaling process over the protocol, attacks are classified in various categories, and different blocking is available for each category. methods are used. The most difficult attack among the attacks carried out today. The one is fake network selection that can come from neighboring country operators. attacks. The said attacks are based on the flight speed available in the state of the art. It is not solved with advanced controls such as control. Therefore, nowadays There is a need for solutions to prevent these attacks. In the document, a deceptive sent attacker in a Diameter protocol A system and method for detecting messages is described. Promise The subject invention is a Diameter protocol fraud according to a technical problem. It contains intrusion detection equipment and is a source of a 5G core network. a network interface to receive the packet and analyze the received packet and detect an abnormal a computer that can install and execute a program to detect the packet includes; computer program, home network from a Mobile Management Entity (MME) a Diameter protocol Söa protocol transmitted to a Home Subscriber Server (HSS) to obtain a normal lMSl (International Mobile Subscriber Identity) from the package provides an instruction and the normal IMSI included record into the first session table contains an instruction to add; By Mobile Management Entity (MME) from the Create Session Request message of the created CTP-C protocol. An instruction to obtain an International Mobile Subscriber Identity (IMSI) and a normal Diameter protocol The first session of the Söa protocol included in an IDR message obtaining the table; It searches tables and shows an abnormal IDR message. Brief Description of the Invention The purpose of this invention is to understand that the incoming message in the work flow comes from the border and After the checks are carried out, the subscriber's own network by enabling it to be determined whether it is accessible or not. It is possible to prevent attacks coming over the network and to prevent accidental international a system that makes border crossings difficult within the scope of circulation is to perform.
Bulusun diger amaci, LTE sinyallesmesinin 4G ile birlikte 5G ve 3GPP Non- Standalone Architecture (NSA) mimarisinde kullanilmasi durumunda geçerli bir kontrol yöntemi saglayan bir sistem gerçeklestirmektir. Another object of the invention is that LTE signaling is combined with 4G as well as 5G and 3GPP Non- If used in a Standalone Architecture (NSA) is to implement a system that provides a control method.
Bulusun bir diger amaci, komsu ülkelerin sebekeleri üzerinden gelen ataklarin önlenmesi ve yanlislikla uluslararasi dolasim kapsaminda sinir geçislerinin zorlastirilmasinin saglanmasi ile telekomünikasyon operatörlerinin blokaj yetkinliklerinin artirilmasini ve yanlislikla uluslararasi dolasim yapma sebebiyle aboneler tarafinda olusabilecek ek ücretlendirme ve akabindeki müsteri memnuniyetsizligi sorunlarini azaltan bir sistem gerçeklestirmektir. Another aim of the invention is to prevent attacks from neighboring countries' networks. prevention and accidental border crossings within the scope of international circulation blockage of telecommunication operators by ensuring that increase their competence and due to accidental international circulation additional charges that may occur by the subscribers and the subsequent customer To implement a system that reduces the problems of dissatisfaction.
Bulusun baska amaci, komsu ülkelerin sebekeleri üzerinden gelen ataklarin önlenmesi ve yanlislikla uluslararasi dolasim kapsaminda sinir geçislerinin zorlastirilmasinin saglanmasi ile operatörlerin ücret iade süreçlerindeki sikintilari ve çagri merkezi trafigini hafifleten bir sistem gerçeklestirmektir. Another purpose of the invention is to prevent attacks from neighboring countries' networks. prevention and accidental border crossings within the scope of international circulation the difficulties of operators in wage reimbursement processes. and to implement a system that alleviates call center traffic.
Bulusun Ayrintili Açiklamasi Bu bulusun amacina ulasmak için gerçeklestirilen “Bir Tespit Ve Engelleme Sistemi” ekli sekilde gösterilmis olup, bu sekil; Sekil 1 Bulus konusu bir tespit ve engelleme sisteminin sematik görünüsüdür. Detailed Description of the Invention “A Detection and Blocking” carried out to achieve the purpose of this invention. System” is shown in the attached figure, this figure; Figure 1 The subject of the invention is a schematic view of a detection and inhibition system.
Sekilde yer alan parçalar tek tek numaralandirilmis olup, bu numaralarin karsiliklari asagida verilmistir: 1. Sistem 2. Uçajan birimi 3. Sinir güvenlik duvari Diameter sinyallesmesiyle komsu ülkelerin sebekeleri üzerinden gelen ataklarin önlenebilmesini ve yanlislikla uluslararasi dolasim kapsaminda sinir geçislerinin zorlastirilmasini saglayan bulus konusu sistem (1 l; -yabanci operatör sebeke seçim istek mesajlarini sinyaIIESme tasiyicilari üzerinden almak, istek mesajinin sinir operatöiünden geldigini tespit etmek ve ardindan yönlendirmeleri yapmak üzere yapilandirilan en az bir Diameter uç ajan birimi ve -sebeke seçimi istek mesajlarini Diameter uç biriminden (2) almak, bir ev abone sunucusu (HSS-home subscriber server) üzerinde arama (paging) yaparak gelen cevabi incelemek, aramaya cevap alinamadigi ya da hata alindigi durumda istek mesajini operatörün bir çekirdek sebekesine yönlendirmek ve aramaya cevap alindiginda ise mesaji operatörün bir çekirdek sebekesine gitmesini engellemek üzere yapilandirilan en az bir en az sinir güvenlik duvari (3) içermektedir. The parts in the figure are numbered one by one. are given below: 1. System 2. Aircraft unit 3. Neural firewall With Diameter signaling, attacks coming over the networks of neighboring countries preventing and accidental border crossings within the scope of international circulation. system (1 l; -Signal foreign operator network selection request messages over IIESme carriers receive, detect that the request message is coming from the nerve operator, and then at least one Diameter end agent unit configured to make referrals, and - receiving network selection request messages from the Diameter terminal (2), a home subscriber Incoming calls by paging on the HSS-home subscriber server. to examine the answer, request in case the call is not answered or an error is received. forwarding the message to a core network of the operator and answering the call When received, the message is to prevent the operator from going to a core network. It contains at least one at least a border firewall (3) configured to
Bulus konusu sistemde (1) Diameter uç ajan birimi (2) yabanci operatörlerden sebeke seçim isteklerini sinyallesme tasiyicilari üzerinde almak, yönlendirme ve kontrolleri yaparak mesaji islemek ve mesajin sinir operatöründen geldigini tespit etmek üzere yapilandirilmaktadir. Diameter uç ajan birimi (2) AIR, ULR mesajlarini almak ve mesajin Realm, Host bilgilerini bakarak istek mesajinin sinir operatöründen geldigini tespit etmek üzere yapilandirilmaktadir. In the inventive system (1) Diameter end agent unit (2) from foreign operators receiving network selection requests on signaling carriers, routing and processing the message by making checks and detecting that the message came from the neural operator. is configured to do so. Diameter end agent unit (2) AIR, ULR Receiving messages and looking at the Realm, Host information of the message, the limit of the request message It is configured to detect that it is coming from the operator.
Bulus konusu sistemde (1) sinir güvenlik duvari (3) Diameter uç ajan birimi (2) ile iletisimde olmak, kurulan bu iletisim üzerinden sinir operatöründen geldigi tespit edilen istek mesajini almak ve söz HSS üzerinde arama (paging) yapmak üzere yapilandirilmaktadir. Sinir güvenlik duvari (3) HSS üzerinden CS (Circuit switched) ve EPS etki alanlari (domain) için arama yapmak ve arama cevabini incelemek üzere yapilandirilmaktadir. Sinir güvenlik duvari (3) HSS üzerinden CS ve EPS etki alanlarina yapilan arama isteklerine cevap alinip alinamadigini ve cevap alinmasi durumunda ise alinan cevaplarin kaydedilmesini saglamak üzere yapilandirilmaktadir. In the inventive system (1) neural firewall (3) Diameter end agent unit (2) to be in contact with the neural operator through this communication. get the detected request message and paging on the promise HSS is configured to. Neural firewall (3) CS over HSS (Circuit switched) and EPS domains and to search for the call answer. is set up for review. Neural firewall (3) via HSS Whether search requests to CS and EPS domains were answered, and in case of a reply, to ensure that the answers received are recorded. is being configured.
Bulus konusu sistemde (1) sinir güvenlik duvari (3) HSS üzerinden yapilan aramaya cevap alinamadiginda ya da hata alindigi durumda arama sonucu gelen cevabin kaydedilmesini saglamak ve mesajin ev abone sunucusuna (HSS-home subscriber server) ulasmasina izin vermek üzere yapilandirilmaktadir. Sinir güvenlik duvari (3) aramaya cevap alinamadigi durumda cevabin kaydedilmesini saglamak, mesajin ev abone sunucusuna (HSS-home subscriber server) ulasmasini engellemek ve mesaji önceden belirlenen hata kodlari ile engellemek üzere yapilandirilmaktadir. In the inventive system (1) the border firewall (3) over the HSS When the call is not answered or an error is received, the incoming call result to record the response and send the message to the home subscriber server (HSS-home). subscriber server) Border firewall (3) to save the answer when the call is not answered. to enable the message to reach the home subscriber server (HSS-home subscriber server). to block and block the message with predetermined error codes. is being configured.
Bulus konusu sistemde (1) sinir güvenlik duvari (3) daha önceden abonenin durumuna ve konumuna iliskin bir bilgi olmasi durumunda CS veya EPS üzerinden arama tetiklemeden kayitli bilgileri kullanmak ve mesajin ev abone sunucusuna (HSS-home subscriber server) ulasmasini engellemek ya da Izin vermek üzere yapilandirilmaktadir. Bu sayede sebekedeki sinyallesme trafigi azaltilmaktadir. In the inventive system (1), the neural firewall (3) has previously been CS or EPS in case of information on its condition and location use the saved information without triggering a call via and subscribe to the home of the message To prevent access to the server (HSS-home subscriber server) or to allow is made to give. In this way, the signaling traffic in the network is being reduced.
Bulus konusu sistemde (1) siriir güvenlik duvari (3) arama cevaplarini kayit altinda tutan en az bir No-SQL veri tabani (Dll ile iletisimde olmak ve söz konusu veri tabaninda arama sonuçlarini kayit altinda tutulmasini saglamak üzere yapilandirilmaktadir. Sinir güvenlik duvari (3) ayrica sinir operatörlerinin bilgilerini, uygulama ayarlarini ve sistem islem kayitlarini tutan en az bir veri tabani (DZ) ile iletisimde olmak üzere yapilandirilmaktadir. In the subject system of the invention (1), the firewall (3) records the call answers. at least one No-SQL database (to communicate with the DLL and promise to ensure that the search results are recorded in the database in question. is being configured. The neural firewall (3) also allows neural operators to at least one piece of data that holds information, application settings, and system logs It is configured to communicate with its base (DZ).
Bulus konusu sistem (1) sayesinde Diameter sinyallesmesiyle komsu ülkelerin sebekeleri üzerinden gelen ataklarin önlenmekte ve yanlislikla uluslararasi dolasim kapsaminda sinir geçislerinin zorlastirilmasi saglanmaktadir. Bunun için bulus konusu sistemde (l) sebeke seçimi istem mesajlari kullanilarak bir ev abone sunucusu (HSS-home subscriber server) üzerinde arama (paging) yapilmakta, aramaya cevap alinamadigi ya da hata alindigi durumda istek mesaji operatörün bir çekirdek sebekesine yönlendirilmekte ve aramaya cevap alindiginda ise mesaj engellenmektedir. Thanks to the system (1), which is the subject of the invention, the neighboring countries are provided with Diameter signaling. The attacks coming through the networks are prevented and the international Within the scope of circulation, it is ensured that the border crossings are made difficult. For this In the inventive system (l), a home subscriber can be reached by using the network selection prompt messages. Searching (paging) is made on the server (HSS-home subscriber server), In case the call is not answered or an error is received, the request message is sent to the operator. it is routed to a core network and when the call is answered, the message is is blocked.
Bu temel kavramlar etrafinda, bulus konusu “Bir Tespit Ve Engelleme Sistemi (1)” ile ilgili çok çesitli uygulamalarin gelistirilmesi mümkün olup, bulus burada açiklanan örneklerle sinirlandirilamaz, esas olarak istemlerde belirtildigi gibidir. Around these basic concepts, the subject of the invention is “A Detection and Prevention System. It is possible to develop a wide variety of applications related to (1)", the invention being described here. not limited to the examples described, essentially as claimed in the claims.
Claims (11)
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
TR2021/017334A TR2021017334A2 (en) | 2021-11-08 | 2021-11-08 | A DETECTION AND PREVENTION SYSTEM |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
TR2021/017334A TR2021017334A2 (en) | 2021-11-08 | 2021-11-08 | A DETECTION AND PREVENTION SYSTEM |
Publications (1)
Publication Number | Publication Date |
---|---|
TR2021017334A2 true TR2021017334A2 (en) | 2021-11-22 |
Family
ID=85113295
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
TR2021/017334A TR2021017334A2 (en) | 2021-11-08 | 2021-11-08 | A DETECTION AND PREVENTION SYSTEM |
Country Status (1)
Country | Link |
---|---|
TR (1) | TR2021017334A2 (en) |
-
2021
- 2021-11-08 TR TR2021/017334A patent/TR2021017334A2/en unknown
Similar Documents
Publication | Publication Date | Title |
---|---|---|
US9419988B2 (en) | System and method for non-disruptive mitigation of messaging fraud | |
EP3437313B1 (en) | Method and system for detection of interconnect bypass using test calls to real subscribers | |
JPH07500955A (en) | Device for detecting and preventing cloning of subscriber numbers in cellular mobile telephone systems | |
Rao et al. | Unblocking stolen mobile devices using SS7-MAP vulnerabilities: Exploiting the relationship between IMEI and IMSI for EIR access | |
US11044356B2 (en) | Active call verification to prevent falsified caller information | |
CN113206814B (en) | Network event processing method and device and readable storage medium | |
CN101142805A (en) | Lawful interception of unauthorized subscribers and equipments | |
US8804932B2 (en) | Protection of services in mobile network against CLI spoofing | |
CA3013899A1 (en) | Methods, telecommunication switches and computer programs for processing call setup signalling | |
Guri et al. | 9-1-1 DDoS: attacks, analysis and mitigation | |
Puzankov | Stealthy SS7 attacks | |
WO2000076189A1 (en) | Automatic monitoring service for telecommunication networks | |
Yocam et al. | 5G mobile networks: reviewing security control correctness for mischievous activity | |
Guri et al. | 9-1-1 ddos: Threat, analysis and mitigation | |
TR2021017334A2 (en) | A DETECTION AND PREVENTION SYSTEM | |
CN110312221A (en) | Call forwarding setting method, home location register and block chain network system | |
Wang et al. | Dissecting Operational Cellular IoT Service Security: Attacks and Defenses | |
CN111246409B (en) | Communication service processing method and device | |
TR201619005A2 (en) | A SYSTEM AND METHOD FOR DETERMINING CALL TRANSMISSION FRAMING IN MOBILE COMMUNICATION NETWORKS | |
Kotte | Analysis and Experimental Verification of Diameter Attacks in Long Term Evolution Networks | |
US20230232232A1 (en) | Methods, systems, and computer readable media for providing call intelligence to a signaling firewall in a communications network | |
KR102440411B1 (en) | Method and apparatus for detecting abnormal roaming request | |
Song et al. | Towards standardized prevention of unsolicited communications and phishing attacks | |
TR2024010297A2 (en) | A SYSTEM THAT PREVENTS CLONING OF IOT DEVICES | |
CN101150447A (en) | Monitoring agent device for legal monitoring for public service of IP multimedia subsystem |