UDC 004.056.5:004.8:621.396
HIERARCHICAL METHOD FOR DISTRIBUTED DETECTION OF COMPROMISE AND ATTACKS IN DIAMETER SIGNALING NETWORKS
I. L. Vinogradova, Dr. in technical sciences, Professor, Department of Telecommunication Systems. Ufa
University of Science and Technology, Ufa, Russia;
e-mail: This email address is being protected from spambots. You need JavaScript enabled to view it.
N. Kh. Sadykov, Postgraduate Student, Department of Computer Engineering and Engineering Cybernetics.
Ufa State Petroleum Technological University, Ufa, Russia;
orcid.org/0009-0007-0882-3537, e-mail: This email address is being protected from spambots. You need JavaScript enabled to view it.
A method for distributed security monitoring of Diameter signaling networks in LTE has been developed.
The aim of this work is to enhance the information security of operational LTE networks by detecting
attacks on Diameter signaling using a hierarchical master-slave architecture and intelligent anomaly analysis.
To achieve this aim, the following objectives have been accomplished: the selection of a hierarchical
monitoring architecture with two-level feature extraction has been justified; cascade and ensemble detection
models have been developed; an experimental evaluation of detection effectiveness for five types of Diameter
attacks has been conducted. The relevance of this task is driven by the insufficient protection provided by
existing mechanisms (signaling firewalls) in LTE networks, as well as the fundamental inability of centralized
monitoring approaches to detect the compromise of internal network nodes. Without comparing the behavior
of a node against the median values of its zone, a compromised node is shown to be indistinguishable
from a normal one. A two-level feature extraction system is proposed – 35 observable features at slave node
level and 21 control unit features with zone-based contextualization at master level. Based on a simulation
model of 17 nodes (86,400 records), meta-ensemble achieves F1 = 0,9934 with FPR = 0,0001; cascade detector provides 99,4% compromise detection. An ablation study confirmed that removing hierarchical architecture features reduces compromise detection from 98,5 % to 2,2 %. A direct comparison of supervised and unsupervised models in terms of compromise detection accuracy is not considered valid due to the use of
fundamentally different algorithms with different input data characteristics.
Key words: Diameter protocol, LTE, anomaly detection, denial of service, node compromise, hierarchical
architecture, meta-ensemble, signaling firewall.
