Concurrent flooding and cloning attack mitigation
A wireless communication process can include obtaining a wireless communication message associated with a source identifier (ID); determining that the source ID is associated with a flooding attack. The process can include filtering, based on determining that the source ID is associated with a flooding attack, wireless communication messages associated with the source ID. Filtering the wireless communication messages includes alternating between a first filtering state and a second filtering state. The first filtering state and the second filtering state are associated with different amounts of filtering.
1 . A method of wireless communication, the method comprising:
obtaining a wireless communication message associated with a source identifier (ID);
determining that the source ID is associated with a flooding attack; and
filtering, based on determining that the source ID is associated with a flooding attack, wireless communication messages associated with the source ID, wherein filtering the wireless communication messages comprises alternating between a first filtering state and a second filtering state, wherein the first filtering state and the second filtering state are associated with different amounts of filtering, wherein the first filtering state comprises enabling filtering for a first portion of the first filtering state, disabling filtering for a second portion of the first filtering state, and enabling filtering for a third portion of the first filtering state, wherein the second portion of the first filtering state occurs between the first portion of the first filtering state and the third portion of the first filtering state.
2 . The method of claim 1 , further comprising:
transitioning, based on determining that a message load indicator associated with the flooding attack exceeds a message load threshold, from a first filtering state to a second filtering state.
3 . The method of claim 2 , wherein transitioning, based on determining that the message load indicator associated with the flooding attack exceeds the message load threshold, comprises changing operation of a message handling component from the first filtering state to the second filtering state.
4 . The method of claim 3 , wherein the message load threshold is associated with the second filtering state, and wherein the message load threshold is greater than an additional message load threshold associated with the first filtering state.
5 . The method of claim 2 , wherein the first filtering state is associated with filtering with a first duty cycle and the second filtering state is associated with filtering with a second duty cycle, the second duty cycle being greater than the first duty cycle.
6 . The method of claim 2 , wherein determining that the message load indicator associated with the flooding attack exceeds the message load threshold comprises determining that at least one of a utilization of a message handling module exceeds a utilization threshold or an operating temperature of the message handling module exceeds an operating temperature threshold.
7 . The method of claim 6 , wherein the operating temperature of the message handling module comprises a junction temperature of the message handling module, and wherein the operating temperature threshold comprises a predetermined junction temperature.
8 . The method of claim 6 , wherein the utilization of the message handling module comprises a numerical correspondence between a verification rate of the message handling module and a verification capacity of the message handling module.
9 . The method of claim 6 , wherein the utilization of the message handling module is evaluated during listening to messages from the source ID.
10 . The method of claim 6 , further comprising normalizing the utilization of the message handling module to a total duration of listening to messages from the source ID during an evaluation interval.
11 . The method of claim 2 , further comprising, prior to determining that the message load indicator associated with the flooding attack exceeds the message load threshold, determining, based on determining that a cumulative messaging rate of a plurality of wireless communication messages comprising the wireless communication message exceeds a cumulative message rate threshold, that the flooding attack is occurring.
12 . The method of claim 2 , further comprising generating, based on determining that a source-specific message rate associated with the source ID exceeds a source-specific message rate threshold, a filtering list comprising the source ID.
13 . The method of claim 2 , wherein determining that the message load indicator associated with the flooding attack originating from one or more flooding source IDs of one or more flooding UEs exceeds the message load threshold comprises evaluating the message load indicator over an evaluation interval.
14 . The method of claim 13 , wherein the evaluation interval comprises a plurality of command intervals.
15 . The method of claim 14 , wherein enabling filtering comprises ignoring messages from the one or more flooding source IDs and disabling filtering comprises listening to messages from the one or more flooding source IDs, wherein the first filtering state comprises applying different timing offsets to intervals of ignoring messages from the one or more flooding source IDs within individual command intervals of the evaluation interval.
16 . The method of claim 15 , wherein applying different timing offsets to the intervals of listening to messages from the one or more flooding source IDs within individual command intervals of the evaluation interval comprises listening to messages from the one or more flooding source IDs during different portions of individual command intervals.
17 . The method of claim 16 , wherein applying different timing offsets to the intervals of ignoring messages from the one or more flooding source IDs within individual command intervals of the evaluation interval comprises cumulatively listening to messages during every timing offset associated with command intervals of the evaluation interval.
18 . The method of claim 1 , further comprising determining, during intervals of listening to messages from the source ID, that the source ID comprises a cloned source ID.
19 . The method of claim 18 , further comprising, based on determining that the source ID comprises a cloned source ID, removing the source ID from a filtering list.
20 . The method of claim 18 , wherein determining that the source ID comprises a cloned source ID comprises identifying that the cloned source ID is associated with a UE based on one or more of historical data, location information, speed, heading, a local database, or crowdsourced information.
21 . An apparatus for wireless communication comprising:
a memory; and
one or more processors coupled to the memory and configured to:
obtain a wireless communication message associated with a source ID;
determine the source ID is associated with a flooding attack; and
filter, based on determining that the source ID is associated with a flooding attack, wireless communication messages associated with the source ID, wherein filtering the wireless communication messages comprises alternating between a first filtering state and a second filtering state, wherein the first filtering state and the second filtering state are associated with different amounts of filtering, wherein the first filtering state comprises enabling filtering for a first portion of the first filtering state, disabling filtering for a second portion of the first filtering state, and enabling filtering for a third portion of the first filtering state, wherein the second portion of the first filtering state occurs between the first portion of the first filtering state and the third portion of the first filtering state.
22 . The apparatus of claim 21 , the one or more processors further configured to:
transition, based on determining that a message load indicator associated with the flooding attack exceeds a message load threshold, from a first filtering state to a second filtering state.
23 . The apparatus of claim 22 , wherein the first filtering state is associated with filtering with a first duty cycle and the second filtering state is associated with filtering with a second duty cycle, the second duty cycle being greater than the first duty cycle.
24 . The apparatus of claim 22 , wherein determining that the message load indicator associated with the flooding attack originating from one or more flooding source IDs of one or more flooding UEs exceeds the message load threshold comprises evaluating the message load indicator over an evaluation interval.
25 . The apparatus of claim 24 , wherein enabling filtering comprises ignoring messages from the one or more flooding source ID and disabling filtering comprises listening to messages from the one or more flooding source IDs, wherein the first filtering state comprises applying different timing offsets to the intervals of ignoring messages from the one or more flooding source IDs within individual command intervals of the evaluation interval.
26 . The apparatus of claim 25 , wherein applying different timing offsets to the intervals of ignoring messages from the one or more flooding source IDs within individual command intervals of the evaluation interval comprises cumulatively listening to messages during every timing offset associated with command intervals of the evaluation interval.
27 . The apparatus of claim 22 , wherein to transition, based on determining that the message load indicator associated with the flooding attack exceeds the message load threshold, the one or more processors are further configured to change operation of a message handling component from the first filtering state to the second filtering state.
28 . The apparatus of claim 27 , wherein the message load threshold is associated with the second filtering state, and wherein the message load threshold is greater than an additional message load threshold associated with the first filtering state.
29 . The apparatus of claim 22 , wherein determining that the message load indicator associated with the flooding attack exceeds the message load threshold comprises determining that at least one of a utilization of a message handling module exceeds a utilization threshold or an operating temperature of the message handling module exceeds an operating temperature threshold.
30 . The apparatus of claim 21 , the one or more processors further configured to:
determine, during intervals of listening to messages from the source ID, that the source ID comprises a cloned source ID.