Assurance WorkspaceDemo sessionConsoleDTower Forensics
Cell-access reconstruction from persisted handover records, with detector findings attached per hop. This is a forensic evidence view — it never asserts that movement was unauthorized.
Last updated: Not refreshed
How cell access works — and why forensics matters
A device (UE) moves between radio cells through handovers — the network hands the session from one cell to another as signal changes. Operators declare a topology footprint (which cells and sites legitimately exist) and per-session scope (where a device or agent is allowed to attach). Forensic questions: did a handover land outside the declared scope, did a session chain exceed its baseline length, did the same device appear on cells an implausible distance apart inside a window, did an agent reach a cell outside its declared scope, or did a device land on a cell absent from the declared topology — a rogue-cell candidate.
HAIEC checks this via rules TOWER-001…005 (detector AR-69…AR-73), fed by ran_handover records and oam_topology declared snapshots. Hard locks: a handover is never unauthorized access by itself, a long chain is not an attack, implausibility is not spoofing, and a rogue-cell candidate is never confirmed. Absent scope evidence produces an honest skip — never a finding.
How this view was projected
- Handover records land as evidence envelopes (
ran_handover) with timestamps, caller-declared target ids (destination cell when supplied), and correlation keys. Raw record bodies — per-record scope cells, declared topology lists — are hash-preserved, not queryable. - The ingest sweep feeds these records to the tower detector alongside same-batch topology snapshots; findings persist into the detection-finding partition.
- This projection reads all tenant-scoped TOWER findings (no triage or evaluation filter drops them) and joins each finding to its source hop via the persisted
ingest://nativeRecordIdreference. - Hops are grouped into sessions only by persisted correlation keys (sessionId / correlationId / traceId). Never inferred from timing or adjacency — records without correlation keys group under their observed target cell instead.
No organization context
Tower forensics requires an active organization membership. Missing context does not establish that access records are absent – only that they cannot be read here.