Loading...

Alert Correlation in Cellular Mobile Nework

Amini, Hossein | 2016

438 Viewed
  1. Type of Document: M.Sc. Thesis
  2. Language: Farsi
  3. Document No: 49235 (19)
  4. University: Sharif University of Technology
  5. Department: Computer Engineering
  6. Advisor(s): Jalili, Rasool
  7. Abstract:
  8. As mobile networks have been expanded, the importance of subscribers' information security has become more and more evident. Despite mitigating known vulnerabilities of older mobile networks in newer generations, there are still some security flaws that can be exploited. In particular, as a common scenario, attackers can exploit "Use 2G mobile network if 3G/4G is unavailable" setting in order to force a subscriber to downgrade his/her mobile network to 2G; hence becoming vulnerable to known 2G attacks. Mobile networks have a heterogeneous and distributed architecture which make intrusion detection systems incapable of covering the entire network. In this dissertation, alongside with the literature review of mobile networks security, we report the design and implementation of a multi-layer architecture to detect attacks in mobile networks. The architecture proposes special sensors for mobile networks and also a method to cope with the scattering problem. This architecture receives sensor-generated logs, detecting basic independent attacks at the first level correlation. At the second level, basic attacks are correlated to detect more advanced and multi-step attacks. Finally, an appropriate response with regard to the condition of attacks is sent to the administrator. A set of rules are suggested in the architecture to generate logs, events, and incidents. We have also introduced some attack scenarios which can be detected by default rules. A prototype of the system has been implemented and evaluated in a mobile network laboratory
  9. Keywords:
  10. Correlation ; Mobile Networks ; Cellular Network ; Sentence Recognition ; Multilayer Architecture

 Digital Object List

 Bookmark

No TOC