发明名称 DETECTION METHOD FOR SIGNALING DOS TRAFFIC IN MOBILE COMMUNICATION NETWORKS
摘要 A detection method for signaling DoS traffic in mobile communication networks according to the present invention comprises: a packet filtering engine for classifying RAB connections by collecting and analyzing GTP-C packets; an RAB connection detection unit for detecting, from the classified RAB connections, malicious RAB connections; and a signaling DoS attack detection unit for calculating the time interval of the detected malicious RAB connection, and determining whether a signaling DoS attack has occurred on the basis of the calculated time interval of the RAB connection. The present invention provides a system and an algorithm for detecting signaling DoS traffic attacks which can disable a mobile communication network by using a massive number of signaling messages which are generated through repeated malicious RAB connections and cancellations to the mobile communications network. The detection method for signaling DoS traffic according to the present invention can be used to respond the security threat of an actual mobile communications network, and, in module form, is expected to be used to supplement the capabilities of an existing management system of a mobile communications network.
申请公布号 WO2013065886(A1) 申请公布日期 2013.05.10
申请号 WO2011KR08357 申请日期 2011.11.04
申请人 KOREA INTERNET & SECURITY AGENCY;IM, CHAE TAE;OH, JOO HYUNG;KANG, DONG WAN;KIM, SE KWON;CHO, JUNG SIK 发明人 IM, CHAE TAE;OH, JOO HYUNG;KANG, DONG WAN;KIM, SE KWON;CHO, JUNG SIK
分类号 H04L12/22;G06F21/55;H04L12/26;H04L12/70 主分类号 H04L12/22
代理机构 代理人
主权项
地址