When the IPS Sensor is deployed in a mobile network it parses all the traffic flowing in the network. When it detects any malicious traffic, the Sensor raises alerts accordingly. The Sensor also looks for vulnerabilities in the mobile network, which could lead to an attacks in the future.
.png)
During GTP parsing, the Sensor is deployed either in inline or SPAN/TAP mode. The Sensor is deployed on the Gn/Gp interface to detect handset-to-handset malicious communication, internal or external attacks. The Sensor parses the traffic between SGSNs and GGSNs for any attack and also inspects the IP payload. The Sensor only parses the GTP-U traffic and drops the GTP-C traffic. The Sensor inspects the UDP header for the underlying protocol and the subscriber IPv4 or IPv6 traffic. Other subscriber traffic such as the IPSec, L2TP, PPP are bypassed and not inspected for attacks. IP datagrams transmitted from the internet can sometimes be fragmented. The Sensor defragments these datagrams for any malicious traffic. The Sensor is capable of handling high rate data of GTP traffic, upto 8Gbps because of the internal load balancing design.
The Sensor has ports connected to a SGSN’s Gn interface in either inline or SPAN/TAP modes and parses the GTP tunneled traffic. Any request from a mobile is first sent to the nearest tower which then connects to the Radio Network Controller (RNC). The RNC then encrypts the data packets before sending it to the nearest SGSN. The data packets are then transmitted to other SGSN or GGSN via the Gn interface or to other GGSNs via the Gp interface. The Sensor placed between the SGSN and the GGSN, that is connected to the Gn interface, inspects the packets for vulnerability or malicious contents before forwarding the packets.
.png)
In the inline mode, after the data packets are processed, the Gi interface forwards the packets to the internet to gather the requested information. The requested information packets are then forwarded back to the mobile. The Sensor deployment in inline mode is illustrated below:
.png)
Subscriber information from RADIUS regarding data usage is submitted to the Sensor together with the attacks seen on GTP-U traffic. The information extracted by RADIUS Accounting helps retrieve subscriber information as a part of the alerts/events.