Method and device for processing an alert indicating the detection of an anomaly in traffic transmitted over a network

DE602020051981T2Active Publication Date: 2025-05-28ORANGE SA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
DE602020051981
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Priority Date
2019-04-18
Filing Date
2020-04-15
Publication Date
2025-05-28
Estimated Expiration
2040-04-15

AI Technical Summary

Technical Problem

Traditional intrusion detection techniques are inappropriate and ineffective in 5G mobile networks due to their specificities and constraints, leading to performance issues and compromised cybersecurity.

Method used

A hierarchical approach is proposed for detecting anomalies and intrusions across multiple levels, including user equipment, network devices, and a security operations center, with detection techniques adapted to the resources and constraints of each level.

Benefits of technology

This approach enables rapid and reliable detection of computer attacks without impacting network performance, ensuring effective cybersecurity in 5G networks by leveraging the strengths of each hierarchical level.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader
Need to check novelty before this filing date? Find Prior Art

Description

Prior art

[0001] The invention relates to the general field of telecommunications.

[0002] It relates more specifically to a mechanism enabling the detection of computer attacks (or “cyber-attacks”) in an electronic communications network.

[0003] Prior art patent document US 2011 / 023119 A1 discloses technologies for mitigating topology-aware attacks.

[0004] No limitation is attached to the nature of the network. However, the invention applies in a preferred manner to mobile networks, and in particular to fifth generation mobile networks or 5G mobile networks.

[0005] 5G mobile networks, with the advanced communication techniques they implement and the new capabilities they offer in terms of speeds, information volumes and connections, open up new usage perspectives that pose real challenges in terms of cybersecurity. In previous years, numerous intrusion detection (IDS) and defense techniques have been developed, based on proactive approaches that allow, on the one hand, to anticipate and reduce vulnerabilities in IT systems, and on the other hand, to trigger effective mitigation responses when attacks or intrusions are detected in these IT systems.However, 5G, due to its specificities and constraints, makes traditional intrusion detection techniques inappropriate and ineffective if they are not adapted to take these specificities and constraints into account.

[0006] The paper by L. Fernandez Maimo et al., "A self-adaptive deep learning-based system for anomaly detection in 5G networks," IEEE Access, Special section on cyber-physical-social computing and networking, March 12, 2018, proposes an architecture for detecting cyber attacks in a 5G network, capable of automatically adapting to fluctuations in network traffic. The proposed system, which is based on a deep learning technique, can decide to deploy more computing resources (via virtualized network functions) or to adapt the learning approach or the applied detection model according to the current cyber defense context in which it finds itself, this context being identified by the system from the traffic behavior.

[0007] The architecture proposed in the paper by L. Fernandez Maimo et al. is based on the collection, by user equipment connected to the network, of different characteristics of the traffic generated by these user equipments, and the aggregation of these characteristics by an ASD (Anomaly Symptom Detection) module located at the access network level. The ASD module performs a rapid search for anomaly symptoms by inspecting the aggregated characteristics. The symptoms are then provided to a NAD (Network Anomaly Detection) module located in the core network.As soon as an anomaly is detected, it is notified to a monitoring and diagnostic module responsible for analyzing the causes of this anomaly and reporting these causes to a security policy manager able to quickly take appropriate actions, such as adapting the system configuration.

[0008] In the system proposed by L. Fernandez Maimo et al., intrusion detection, although carried out from the symptoms identified by the access networks by analyzing the traffic characteristics collected by the user equipment, is centralized at the core network level. It is in the core network that the main processing and calculations are carried out to conclude whether an intrusion is perpetrated against the network. This architecture results in a significant overhead (or surplus) in the network, which can have a negative impact on the quality of service and network performance. Statement of the invention

[0009] The invention makes it possible in particular to overcome this drawback by proposing a hierarchical approach according to which the detection of anomalies and intrusions is carried out at several levels, taking into account the constraints of the equipment belonging to these different levels. In the sense of the invention, the higher the hierarchical level, the more the equipment belonging to this hierarchical level has visibility on the network and resources: they are therefore able to carry out more reliable detection of intrusions linked to computer attacks. No limitation is attached to the nature of these computer attacks (viruses, trojans, etc.).

[0010] More specifically, the invention proposes to implement at the level of user equipment, at the level of network devices (belonging to the access network and / or to the core network) and at the level of a security operations center (also commonly referred to as SOC for "Security Operations Center" in English) supervising the network, intrusion and / or anomaly detection techniques adapted to the resources available at the level of each of these devices, and which take into account, during their execution, the constraints of the devices located at the lower level(s) in order to be able, if relevant, to provide them with appropriate feedback. Such constraints may in particular be constraints in terms of resources (for example memory, storage, or computing power) or constraints in terms of network performance (such as latency constraints, throughput, etc.).

[0011] Thus, in this way, the invention exploits the advantages offered at each level to enable rapid and reliable detection of computer attacks likely to affect a network and the user equipment connected to it, without impacting the performance of the network.

[0012] The invention is therefore based on three methods, and on the different equipment capable of implementing these methods, namely user equipment, a network device (which can be located indifferently in the access network or in the core of the network), and a security operations center supervising the network.

[0013] More specifically, the invention relates to a method for processing, by a network device, an alert message received from user equipment connected to the network, and notifying an anomaly detected by the user equipment in traffic transmitted via the network. The processing method comprises: a step of obtaining, from the alert message, at least one item of information representative of at least one constraint of the user equipment; a step of processing, by means of a computer attack detection algorithm, characteristics of the traffic provided by the user equipment and associated with the detected anomaly, the computer attack detection algorithm being selected and / or configured as a function of said at least one item of information; and a step of determining, as a function of a result of the processing step, and if a computer attack is detected, of said at least one item of information, a response to the user equipment concerning the detected anomaly.

[0014] Correlatively, the invention relates to a device of a network comprising: a receiving module, capable of receiving an alert message from a user equipment connected to the network, this alert message notifying an anomaly detected by the user equipment in traffic transmitted via the network; an obtaining module, configured to obtain from the alert message at least one piece of information representative of at least one constraint of the user equipment; a processing module, configured to process, by means of a computer attack detection algorithm, characteristics of the traffic provided by the user equipment and associated with the detected anomaly, the computer attack detection algorithm being selected and / or configured as a function of said at least one piece of information;and a determination module, configured to determine, based on a result of the processing step, and if a computer attack is detected, of said at least one piece of information, a response to the user equipment concerning the detected anomaly.;

[0015] The invention also relates to a supervision method, by a security operations center supervising at least one network, comprising: a step of receiving, from a network device, an alert message notifying an anomaly detected by user equipment connected to the network or by the network device in traffic transmitted via said network, this alert message comprising characteristics of the traffic obtained by the user equipment or by the network device associated with the detected anomaly, and at least one item of information representative of at least one constraint of the network device; a step of processing, by means of a computer attack detection algorithm, the characteristics of the traffic, the detection algorithm being selected and / or configured as a function of said at least one item of information; and a step of determining, as a function of a result of the processing step and, if an attack is detected, of said at least one item of information, a response to the network device and / or to the user equipment concerning the detected anomaly.

[0016] Correlatively, the invention relates to a security operations center supervising at least one network, comprising: a receiving module, capable of receiving from a network device an alert message notifying an anomaly detected by user equipment connected to the network or by the network device in traffic transmitted via the network, this alert message comprising characteristics of the traffic obtained by the user equipment or by the network device associated with the detected anomaly, and at least one item of information representative of at least one constraint of the network device; a processing module, configured to process, by means of a computer attack detection algorithm, the characteristics of the traffic, the detection algorithm being selected and / or configured as a function of said at least one item of information;and a determination module, configured to determine based on a result of the processing step and, if an attack is detected, on said at least one piece of information, a response to the network device and / or to the user equipment concerning the detected anomaly.;

[0017] The invention also relates to a notification method, by user equipment connected to a network, comprising: a step of detecting an anomaly in traffic transmitted via the network, from traffic characteristics obtained by the user equipment; if the user equipment is unable to determine whether the detected anomaly corresponds to normal behavior or to a computer attack, a step of sending, to a network device, an alert message notifying it of the detected anomaly, this alert message comprising the traffic characteristics and at least one item of information representative of at least one constraint of the user equipment; and a step of receiving a message from the network device concerning the detected anomaly developed according to said at least one item of information.

[0018] Correlatively, the invention relates to user equipment connected to a network, comprising: a detection module, configured to detect an anomaly in traffic transmitted via the network from traffic characteristics obtained by the user equipment; a sending module, activated if the user equipment is unable to determine whether the detected anomaly corresponds to normal behavior or to a computer attack, this sending module being configured to send to a network device an alert message notifying it of the detected anomaly, this alert message comprising the traffic characteristics and at least one item of information representative of at least one constraint of the user equipment; and a receiving module, capable of receiving a message from the network device concerning the detected anomaly developed according to said at least one item of information.

[0019] Finally, the invention also relates to a network monitoring system comprising: at least one user equipment according to the invention; at least one network device according to the invention (which may be located in the network access network or in the network core); and a security operations center according to the invention.

[0020] The invention therefore proposes to deploy in a hierarchical manner intrusion detection algorithms (or agents) at different levels which will cooperate with each other so as to improve their efficiency. This cooperation is advantageously done by taking into account the constraints present at each level, whatever the nature of these constraints (e.g. hardware, software, network performance, security, energy consumption, etc.).

[0021] Thus, for example, when considering a sensor-type user equipment, with low resources and strong constraints in terms of energy consumption, a relatively simple and lightweight intrusion detection algorithm will preferably be considered at the level of this user equipment, such as for example an algorithm based on searching in the traffic passing through or listened to by the user equipment for predetermined attack signatures and in a reduced number. Such an algorithm has known performance inferior to a machine learning algorithm, which consumes more resources (processing time, computing resources, etc.).

[0022] To compensate for this poorer performance (and a higher risk of poor detections), according to the invention, if the user equipment detects an anomaly in the traffic exchanged via the network and is unable to decide on the nature of this anomaly (in other words, to determine whether it is normal behavior or an attack), it notifies a device of the network according to the invention of the anomaly that it has detected so that the latter can carry out a more in-depth analysis, using more efficient detection algorithms. This device being located in the network (at the access network level or in the core of the network, in other words at a higher hierarchical level than the user equipment), it has more significant hardware resources than a user equipment, has better visibility of the traffic exchanged on the network, and does not strictly speaking present constraints in terms of energy consumption.It is therefore possible to use more efficient detection algorithms at the level of this network device, such as, for example, machine learning algorithms (e.g., deep learning algorithms), which can make it possible to decide on the nature of the anomaly detected by the user equipment.

[0023] Advantageously according to the invention, the choice and the parameterization of the algorithms used at the network device level are carried out taking into account the constraints of the user equipment; the same applies to the development of the response provided to the user equipment concerning the anomaly detected by the latter. Thanks to this arrangement, it is ensured that the user equipment benefits from a response adapted to its constraints when it detects an anomaly, that is to say, a rapid response if it has a high latency constraint, or requiring a low overhead (surplus of computing resources, signaling, etc.) if its resources are limited, etc.

[0024] It is noted that if the network device determines that the anomaly is linked to normal network behavior, it may refrain from responding to the alert message sent by the user equipment, in particular with a view to limiting the signaling exchanged on the network and further saving the resources of the user equipment (which therefore does not have to process a response message).

[0025] Similarly, if the network device is unable to determine, using the intrusion detection algorithm it uses, whether the anomaly reported to it is due to normal behavior or a computer attack, it requests a higher hierarchical level, namely a security operations center supervising the network (and possibly other networks managed by the same operator or by different operators). As is known per se, a security operations center or SOC is a platform allowing the supervision and administration of the security of one or more information systems, for example here, one or more communication networks. To this end, it relies on various tools for collecting, correlating events, analyzing activities on the networks and on the various equipment that composes them (e.g. databases, applications, servers, user equipment, etc.), as well as the expertise of analysts and security specialists; it may also have remote intervention resources. In other words, it is a trusted entity with extensive expertise and enabling precise and reliable detection of intrusions into a network.

[0026] The invention, based on the three aforementioned hierarchical levels, offers an effective solution for detecting intrusions into a network, particularly well-suited to 4G and 5G mobile networks and the diversity of user equipment likely to be connected to these networks. It makes it possible to react quickly and appropriately in the event of detection of an anomaly by user equipment.

[0027] The invention is also relatively easy to implement, and can be easily integrated into cyber security solutions such as, for example, SIEM (for “Security Information and Event Management”) type solutions.

[0028] The invention is very flexible and can more generally be applied to any type of network (2G, 3G, 4G, 5G, etc.) in order to protect them from cyberattacks, including when these are complex. It adapts to any type of terminal and more generally of user equipment, advantageously taking into account their constraints.

[0029] For example, in a particular embodiment of the processing method, said at least one piece of information obtained by the network device is representative of at least one constraint in terms of resources (hardware, software, etc.) and / or security and / or network performance of the user equipment.

[0030] Such a constraint in terms of resources may in particular be a constraint of energy consumption or available storage space. Such a constraint in terms of network performance may in particular be a constraint of latency, bandwidth, throughput, processing time of information provided to the user equipment or quantity of surplus information provided to the user equipment. Such a constraint in terms of security may be a rate of detection of computer attacks, a rate of false positives, or a critical nature of the user equipment (if it is a vehicle for example, the risk incurred by this vehicle due to the presence of a computer attack may be significant and require a rapid reaction adapted to the risk incurred).

[0031] These examples are given for illustrative purposes only, and no limitation is attached to the type of constraints to which the user equipment is subject since the network device is informed of these constraints and can thus take them into account to provide an appropriate response to the user equipment.

[0032] As mentioned previously, consideration of constraints can be done at the level of the computer attack detection algorithm selected and applied by the network device to analyze the anomaly reported by the user equipment.

[0033] Thus, in one embodiment, the computer attack detection algorithm used can be selected by the network device from: a detection algorithm based on computer attack signatures; and a machine learning detection algorithm.

[0034] A machine learning detection algorithm (for example, deep learning type) benefits, as is known, from a better detection rate and a lower false positive detection rate than a detection algorithm based on computer attack signatures, which is generally less complex and faster to implement. Of course, these examples are given for illustrative purposes only and other detection algorithms can be considered in the context of the invention.

[0035] In addition to the selection of the computer attack detection algorithm, it is also the sizing of the parameters of the selected algorithm that can advantageously take into account the constraints of the user equipment. Thus, in a particular embodiment, when a machine learning detection algorithm is selected during the processing step, the learning duration considered for this algorithm can be parameterized according to said at least one piece of information representative of the constraint(s) of the user equipment. For example, if the user equipment has strong constraints in terms of latency, a learning duration can be selected at the network device level that makes it possible to respect the latency supported by the user equipment.

[0036] Alternatively, when a detection algorithm based on computer attack signatures is considered, it is the number of signatures used which can be sized according to the constraints of the user equipment (to be able to respond more or less quickly according to these constraints).

[0037] In a particular embodiment of the treatment method: the processing step comprises the detection of a computer attack against user equipment connected to the network and / or against an element of the network; and the determining step comprises the evaluation of a so-called effectiveness function from at least one metric derived from said at least one piece of information and from a capacity for detecting attacks by the user equipment, the response being determined as a function of the value of the effectiveness function.

[0038] This embodiment makes it possible to provide a response to the user equipment concerning the detected anomaly (which in this case comes from an attack) which verifies a compromise between the constraints of the user equipment and the precision of the attack detection implemented by the latter, this compromise being modeled by the efficiency function. This efficiency function may in particular be a weighted sum of a first parameter evaluated from the constraint(s) of the user equipment and a second parameter reflecting the attack detection capacity achieved at the user equipment. Such a capacity is for example given by the ratio of the number of attacks detected by the network device to the number of anomalies reported by the user equipment on which it was not able to rule.

[0039] By evaluating the efficiency function, the network device balances the constraints of the user equipment with the accuracy of attack detection and develops a response to the user equipment regarding the attack it has detected, offering a compromise between these two parameters. In the case of an attack that the user equipment has not been able to detect, this response may in particular include new signatures and / or new attributes to be applied by the user equipment to improve its attack detection capability and in particular to be able to detect an attack of the type that caused the anomaly reported by the user equipment.

[0040] More particularly, in a particular embodiment, the response determined by the network device may comprise sending a message to the user equipment comprising N signatures and / or attributes of the attack obtained by the network device, N designating an integer depending on the value of the effectiveness function.

[0041] The number N can increase in particular with the value of the efficiency function. Thus, when the efficiency function has a value greater than a so-called high threshold, all the signatures and / or attributes of the attack detected by the network device known to it can be sent to the user equipment. Conversely, below a so-called low threshold, the network device can decide not to send any new signatures and no new attributes to the user equipment. Finally, if the value of the evaluated efficiency function is between the low threshold and the high threshold, the network device can decide to send only a subset of the signatures and / or attributes of the detected attack that it has, typically the most relevant signatures and / or attributes (i.e. those that occur most often or make it possible to identify an attack more easily) to allow an update of the user equipment.

[0042] In a particular embodiment, the number N may further depend on other factors, such as for example a cost factor provided by the user equipment.

[0043] This cost factor can be chosen by the UE manufacturer and reflect their requirements for addressing UE constraints. It provides additional flexibility by allowing additional weighting of the number of signatures returned to the UE based on constraints that are critical to the manufacturer.

[0044] It is noted that the signatures of the attack detected by the network device can be provided to it, for example, by a security operations center monitoring the network.

[0045] As mentioned previously, in a particular embodiment, if during the processing step, the network device is unable to determine whether the detected anomaly corresponds to normal behavior or to a computer attack, the processing method comprises a step of sending to a security operations center supervising the network, an alert message notifying it of the anomaly detected by the user equipment and comprising the characteristics of the traffic provided by the user equipment and associated with the detected anomaly and at least one item of information representative of a constraint of the network device.

[0046] This embodiment makes it possible to benefit from the expertise of the security operations center while taking into account the constraints imposed on the network device (whether these are constraints specific to it and in particular network constraints that it must respect, or whether these constraints are imposed on it indirectly by the user equipment).

[0047] Other scenarios can be considered where it is relevant for the network device to inform the security operations center of the anomaly detected by the user equipment.

[0048] This may be the case when the network device itself locally detects an anomaly on which it is not able to decide.

[0049] Thus, in a particular embodiment, the treatment method further comprises: a step of detection by the network device of an anomaly in traffic transmitted on the network from traffic characteristics obtained by the network device; a step of sending to a security operations center supervising the network for analysis of the anomaly detected by the network device, a notification message of this anomaly comprising said traffic characteristics obtained by the network device and at least one item of information representative of a constraint of the network device.

[0050] Notification to the Security Operations Center may also be for informational purposes, to enable the Security Operations Center to maintain up-to-date statistics on the network and the attacks it is subject to.

[0051] Thus, in a particular embodiment, the processing method further comprises, if during the processing step, the network device detects a computer attack against user equipment connected to the network and / or against a network element, a step of notifying a security operations center supervising the network of the detected attack.

[0052] In a particular embodiment of the invention, the processing method, the supervision method and / or the notification method are implemented by a computer.

[0053] The invention also relates to a first computer program on a recording medium, this program being capable of being implemented in a computer or more generally in a network device in accordance with the invention and comprising instructions adapted to the implementation of a processing method as described above.

[0054] The invention also relates to a second computer program on a recording medium, this program being capable of being implemented in a computer or more generally in a security operations center in accordance with the invention and comprising instructions adapted to the implementation of a supervision method as described above.

[0055] The invention finally relates to a third computer program on a recording medium, this program being capable of being implemented in a computer or more generally in user equipment in accordance with the invention and comprising instructions adapted to the implementation of a notification method as described above.

[0056] Each of these programs may use any programming language, and may be in the form of source code, object code, or code intermediate between source code and object code, such as in a partially compiled form, or in any other desirable form.

[0057] The invention also relates to an information medium or a recording medium readable by a computer, and comprising instructions of the first, second or third computer program mentioned above.

[0058] The information or recording media may be any entity or device capable of storing programs. For example, the media may include a storage medium, such as a ROM, for example a CD ROM or a microelectronic circuit ROM, or a magnetic recording medium, for example a hard disk, or a flash memory.

[0059] On the other hand, the information or recording media may be transmissible media such as an electrical or optical signal, which may be conveyed via an electrical or optical cable, by radio link, by wireless optical link or by other means.

[0060] The programs according to the invention can in particular be downloaded over an Internet-type network.

[0061] Alternatively, each information or recording medium may be an integrated circuit in which a program is incorporated, the circuit being adapted to execute or to be used in the execution of the communication method, in accordance with the invention, or of the selection method, in accordance with the invention.

[0062] It may also be envisaged, in other embodiments, that the processing method, the notification method, the supervision method, the network device, the user equipment, the security operations center and the monitoring system according to the invention have in combination all or part of the aforementioned characteristics. Brief description of the drawings

[0063] Other characteristics and advantages of the present invention will emerge from the description given below, with reference to the appended drawings which illustrate an exemplary embodiment thereof without any limiting character. In the figures: [ Fig. 1 ] there Figure 1 represents in its environment, a monitoring system in accordance with the invention in a particular embodiment; [ Fig. 2 ] there Figure 2 represents the main steps of a notification method according to the invention, in a particular embodiment; [ Fig. 3] there Figure 3 represents the main steps of a treatment method according to the invention, in a particular embodiment; and [ Fig. 4 ] there Figure 4 represents the main steps of a supervision method according to the invention, in a particular embodiment. Description of the invention

[0064] There Figure 1 illustrates, in its environment, a system 1 for monitoring an NW communications network, in accordance with the invention, in a particular embodiment.

[0065] In the example considered on the Figure 1, the NW network is a 5G (5th Generation) communications network comprising a CN core network to which the network users' equipment can connect via an access network, such as for example a cellular mobile access network. These hypotheses are however not limiting and the invention applies to other types of networks, such as for example 2G, 3G or even 4G networks.

[0066] As is known per se, 5G networks such as the NW network offer the possibility for a wide variety of user equipment (generally referred to here as UE) to benefit from connectivity (i.e. to be “connected”): vehicles (e.g. land-based or airborne), IoT objects (for “Internet of Things” in English or even Internet of Objects) such as sensors, watches, etc., smart terminals such as smartphones, digital tablets, laptops, etc. This user equipment is of very diverse nature, allows its users to access very diverse services as well, and may therefore have different hardware and network constraints.

[0067] For example, a connected object such as a sensor has relatively low storage, computing and energy resources compared to a computer or a vehicle.

[0068] Each of these user equipments UE is connected to the network NW via an access point to the access network, generally referred to in the following as AP. Such an access point can be, depending on the access network envisaged, a base station BS, an eNodeB node, a gNodeB node, etc. It is a device of the access network and a fortiori of the NW network within the meaning of the invention.

[0069] As mentioned previously, the invention proposes, in order to effectively protect the 5G NW network from computer attacks (intrusions, viruses, etc.), a hierarchical approach according to which the detection of anomalies and intrusions (or attacks) is carried out at several levels, taking into account the constraints of the equipment belonging to these different levels. More specifically, the invention proposes to implement at the level of the user equipment UE (level referred to as "local"), at the level of devices of the NW network (in the example envisaged in Figure 1, at the level of AP access points in particular) (level referred to as "global") and at the level of a security operations center SOC (Security Operation Center) supervising the NW network (level referred to as "central"), intrusion and / or anomaly detection techniques adapted to the resources available at the level of each of these devices, and which take into account, during their execution, the constraints of the devices located at the lower level(s). Such constraints may in particular be constraints in terms of resources (for example memory, storage, or computing power), constraints in terms of network performance (such as constraints of latency, throughput, processing time of information provided, quantity of excess information provided, etc.), or constraints in terms of security (such as an attack detection rate, or a false positive rate, etc.).

[0070] So, in the example considered on the Figure 1 , the user equipments UE connected to the NW network and the access points AP used by these user equipments to access the NW network are respectively user equipments and devices of the NW network in accordance with the invention. More specifically, the user equipments UE each embed a so-called “local” intrusion detection agent, L-IDA (for “Local Intrusion Detection Agent”), comprising means configured to implement the steps of a notification method according to the invention; each access point AP similarly embeds a so-called “global” intrusion detection agent, G-IDA (for “Global Intrusion Detection Agent”), comprising means configured to implement the steps of a processing method according to the invention.

[0071] In an alternative embodiment, only a portion of the user equipment UE and / or access points AP carry L-IDA and G-IDA agents respectively.

[0072] Furthermore, the security operations center SOC supervising the NW network is also in accordance with the invention, and here includes a so-called "central" intrusion detection agent, C-IDA (for "Central Intrusion Detection Agent"), comprising means configured to implement a supervision method according to the invention. It is noted that the security operations center SOC can also, in a particular embodiment, supervise networks other than the NW network.

[0073] More specifically, the Security Operations Center (SOC) supervises and administers the security of the NW network (and possibly other networks). To this end, it relies on various tools for collecting, correlating events, analyzing activities on networks and on the various equipment that composes them (e.g. databases, applications, servers, user equipment, etc.), as well as on the expertise of analysts and security specialists; it may also have remote intervention resources.

[0074] In the embodiment described here, the notification, processing and supervision methods according to the invention are implemented respectively within the L-IDA, G-IDA and C-IDA agents by means of software and / or hardware components defining different functional modules duly configured to implement the steps of the aforementioned methods (detection, sending and receiving modules in particular for the L-IDA agents; reception, obtaining, processing and determination modules in particular for the G-IDA agents; and reception, processing and determination modules in particular for the C-IDA agent). These functional modules can be grouped at the level of each IDA agent, within three more general categories of modules, namely: a monitoring module; an anomaly and / or attack detection module; and an intervention or reaction module.

[0075] The aforementioned software components may be integrated into a computer program according to the invention. The user equipment UE, the access points AP and / or the security operations center SOC according to the invention may have, for example, the hardware architecture of a computer, and may comprise in particular a processor, a random access memory, a read-only memory, a non-volatile flash memory, as well as communication means comprising one or more communication interfaces.In the embodiment described here, the read-only memory of the computer is a recording medium according to the invention, readable by the processor and on which is recorded a computer program according to the invention, which comprises, depending on the equipment considered, instructions for the implementation of a notification method according to the invention (if the equipment considered is user equipment), a processing method according to the invention (if the equipment considered is an access point or more generally a network device) and a supervision method (if the equipment considered is a security operations center).

[0076] It is noted that in another embodiment, other devices of the network NW, and in particular devices located in the core network CN, can embed G-IDA agents as mentioned above and implement the processing method according to the invention.

[0077] We will now describe, with reference to the Figures 2-4 , the main steps of a notification method, a processing method and a supervision method as implemented respectively, in a particular embodiment, by each user equipment UE, each access point AP and by the security operations center SOC of the Figure 1 in a particular embodiment.

[0078] In reference to the Figure 2 , in the embodiment described here, the L-IDA agent of each user equipment UE is configured to monitor the incoming and outgoing traffic (i.e., the incoming and outgoing data packets) of the user equipment UE (step E10). It is further configured here to monitor the incoming and / or outgoing traffic of other user equipments, located in its radio vicinity for example and which it can receive and listen to.

[0079] To carry out this monitoring, the L-IDA agent of the user equipment UE relies on a monitoring module configured to obtain, from the analysis of the incoming and outgoing data packets of the monitored equipment, a certain number of characteristics of the traffic exchanged via the NW network, such as for example the type of protocols or services corresponding to the packets exchanged, the duration of the communications, the number of failed connections, the number of lost packets, etc. Some characteristics can be extracted by the monitoring module directly from the data packets exchanged (such as for example the type of protocols or services corresponding to the packets exchanged or the duration of the communications); others can be obtained by calculation, such as for example the number of lost packets, the intensity of the received signal, the packet sending rate, the duration between two consecutive packets (also called "jitter" in English), etc.These various traffic characteristics are conventionally collected during the detection of intrusions in a network, and the way of obtaining these characteristics is known to those skilled in the art and is not described in detail here.

[0080] It is noted, however, that in accordance with the invention, the characteristics which are collected by the monitoring module of the L-IDA agent can be chosen and sized according to the constraints of the user equipment UE carrying the L-IDA agent. Thus, if the latter has only few computing and / or storage resources, the monitoring module can collect a reduced number of characteristics, judiciously selected, and / or limit the characteristics which need to be calculated.

[0081] The various traffic characteristics collected by the monitoring module are provided to an anomaly and / or computer attack detection module of the L-IDA agent. This detection module of the L-IDA agent applies to the various traffic characteristics provided, various security rules with which it has been configured which allow it to identify in the monitored traffic the presence of anomalies (for example by comparing certain characteristics to predefined alert thresholds) and / or malicious behaviors linked to computer attacks. For this purpose, it implements in particular a computer attack detection algorithm (also called an intrusion detection algorithm).

[0082] Different attack detection algorithms can be implemented by the L-IDA agent, such as a detection algorithm based on computer attack signatures, or a detection algorithm using machine learning.

[0083] Detection algorithms based on computer attack signatures rely on the analysis of incoming and outgoing network traffic: the exchanged data packets are compared, using pre-established security rules, with a database of signatures representative of known computer attacks. The security rules are defined by experts and can be updated over time, depending on the discovery of new attacks, new signatures, etc. Such algorithms are known per se and are described, for example, in the paper by J.Ma et al. entitled "Detecting Distributed Signature-based Intrusion: the Case of Multi-Path Routing Attacks", IEEE Infocom, pp. 558-566, 2015.

[0084] Machine learning detection algorithms are generally more complex than signature-based algorithms but have a better detection rate and a lower false positive rate. They can be classified into three categories: supervised, unsupervised, and reinforcement algorithms. Such algorithms are described in more detail in the paper by PVKlaine et al., “A Survey of Machine Learning Techniques Applied to Self-Organizing Cellular Networks,” IEEE Communications Surveys & Tutorials, vol. 19, no. 4, pp. 2392–2431, 2017.

[0085] The choice of applying one or other of these attack detection techniques at the L-IDA agent level is made, in accordance with the invention, as a function of the constraints of the user equipment UE embedding the L-IDA agent, and in particular its hardware constraints (available hardware resources, constraints in terms of energy consumption, etc.), its network constraints (low latency, etc.), and / or its security constraints (attack detection rate, false positive rate, etc.).

[0086] Thus, for example for a user equipment UE of the sensor type, the L-IDA agent preferentially applies a simple algorithm that consumes little computing resources such as a detection algorithm based on the search for predetermined computer attack signatures and / or predetermined security rules, previously provided to the user equipment and stored in one of its memories. If the user equipment UE has limited storage resources, only a reduced number of signatures and / or security rules is stored at the user equipment UE, typically the signatures that are most representative of known computer attacks (in other words most often encountered for these attacks) and likely to affect this type of user equipment.

[0087] Thus, not only the type of detection algorithm applied may differ depending on the user equipment, but also the parameterization of this algorithm, in order to achieve a compromise between the constraints of the user equipment and the level of security ensured. For example, it will be avoided to apply an unsupervised machine learning or reinforcement algorithm at the level of user equipment having strong constraints in terms of computing and storage resources such as a sensor, due to the complexity of such an algorithm.

[0088] On the other hand, at the level of user equipment such as a mobile terminal, the constraints in terms of energy consumption and storage of the mobile terminal not being too strong, one could consider the application of a lightweight (i.e. not very complex) supervised automatic learning algorithm such as for example a behavioral detection algorithm using a support vector machine (or SVM for Support Vector Machine in English) based on various behavioral attributes (e.g. number of packets deleted, number of packets sent, etc.) modeling known attacks stored at the level of the user equipment UE.

[0089] At the level of user equipment such as a vehicle, a more robust machine learning algorithm may be considered as an unsupervised machine learning algorithm or a reinforcement algorithm. However, the duration of the learning (parameter of the detection algorithm within the meaning of the invention) may vary depending on the user equipment and its network constraints, in particular the latency supported by the user equipment.

[0090] Table 1 below illustrates examples of trade-offs applied at the user equipment level between hardware, network and security constraints, and the envisaged configuration of the anomaly and / or attack detection module. [Table 1] User equipment Material constraints Network and security constraints Detection module configuration Mobile terminal (e.g. smartphone) Low power consumption, limited storage High bandwidth; High attack and false positive detection rates; Low latency Signature-based algorithms or lightweight machine learning algorithms (e.g. SVM) IoT connected object (e.g. sensor) Very low power consumption, very limited storage Low bandwidth; High attack and false positive detection rates; Low latency Signature-based algorithms with limited security rules Intelligent transportation system (e.g. autonomous vehicle) High attack and false positive detection rates; Ultra-low latency and low communication overhead Unsupervised or reinforcement learning machine algorithms

[0091] If the L-IDA agent does not detect any anomalies (no response in step E20), it continues its monitoring of the traffic exchanged on the NW network. It is noted that preferably, active (i.e. continuous) monitoring of the traffic is implemented by the L-IDA agent. However, this monitoring may be suspended temporarily (e.g. switching to standby mode) or permanently by the user equipment UE depending on the context, in particular if it is judged, for example by cybersecurity experts, that there is no risk of attacks at the NW network level.

[0092] If the L-IDA agent detects an anomaly in the traffic (yes response to step E20), two situations can then arise (test step E30): the L-IDA agent is able to manage this anomaly itself (yes answer to test step E30), in other words, the detection module of the L-IDA agent has identified that this anomaly is linked to a computer attack that the L-IDA agent knows how to process (for example, the anomaly corresponds to a signature of a computer attack that the detection module knows and the L-IDA agent is configured with an appropriate processing to apply to respond to this attack), or the detection module of the L-IDA agent has determined that the anomaly that it has detected is linked to normal behavior of the network: in this case, the L-IDA agent processes the detected anomaly itself (step E40), namely, if this anomaly is linked to an attack, it applies via its intervention module the processing with which it has been configured to respond to the detected attack, and if it is a normal behavior of the NW network, it does nothing and continues its monitoring of the traffic.It is noted that the processing applied by the intervention module in response to the detected attack may depend on the type of user equipment UE and / or the nature of the detected attack (typically its severity). Thus, for example, if the user equipment UE is an autonomous vehicle, a response to the attack implemented by the intervention module may consist of reducing the speed of the vehicle in order to avoid critical damage affecting the vehicle (e.g., crash of the vehicle, alteration of its speed); another response may be to disconnect the user equipment UE from the NW network, or to turn it off, etc. Preferably, the user equipment UE informs, via its intervention module, the access point AP of the NW network to which it is connected of the detection, if applicable, of an attack by indicating to it the nature of this attack as well as the characteristics of the traffic that allowed its detection.This allows the NW network device to update its detection statistics and in turn inform the SOC monitoring center of the detected attack. The latter can then decide, depending on the detected attack, on an action complementary to that applied by the user equipment UE.Alternatively, the user equipment UE can directly inform the SOC supervision center of the attack that it has detected; the L-IDA agent is not able to manage this anomaly itself (response no to test step E30), in other words, it does not know how to conclude on the nature of the anomaly that it has detected and is incapable of determining whether the detected anomaly corresponds to normal behavior of the network or to a computer attack: in this case, the intervention module of the L-IDA agent is configured to send an alert message, here named ALERT, to a device of the NW network equipped with a G-IDA module, namely here to the access point AP to which it is connected to access the NW network (step E50). Sending this alert message is done via the communication interface of the user equipment UE.

[0093] The ALERT alert message sent, where appropriate, by the intervention module of the L-IDA agent notifies the access point AP, and more particularly its G-IDA agent, of the anomaly detected by the L-IDA agent of the user equipment UE so that the latter can carry out a more in-depth analysis of this anomaly. The ALERT alert message comprises the characteristics of the traffic that enabled the L-IDA agent to detect an anomaly (i.e. associated with this anomaly), as well as, in accordance with the invention, at least one item of information representative of at least one constraint of the user equipment UE (e.g. hardware, network, security, etc.). It is noted that to inform the access point AP and / or the supervision center SOC of an attack that it has detected, where appropriate (see above), the user equipment UE can also use the ALERT message.

[0094] Said at least one piece of information representative of said at least one constraint of the user equipment may take different forms, in particular depending on the nature of the constraint(s) signaled by the user equipment UE.

[0095] In the embodiment described here, the intervention module of the L-IDA agent of the user equipment UE evaluates a threshold function, generally noted TFx(UE), for all or part of the constraints available to it: for example, a threshold function TFe(UE) for its constraints in terms of energy consumption, a threshold function TFm(UE) for its constraints in terms of storage and a constraint TFI(UE) for its constraints in terms of latency. These threshold functions here represent rates and have values ​​between 0 and 1. They respectively represent the maximum rates of energy, memory and latency that the G-IDA agent of the access point AP must respect for the user equipment UE for the detection of attacks. They reflect the constraints of the user equipment in terms of energy consumption, storage and latency that the access point and more particularly the G-IDA agent must take into account.

[0096] More particularly, in the embodiment described herein, the intervention module of the L-IDA agent of the user equipment UE calculates the values ​​of the following three linear threshold functions: TFe UE = a 1 . Te UE 1 − E UE / Etot UE + b 1 TFm UE = a 2 . Tm UE 1 − M UE / Mtot UE + b 2 TFI UE = a 3 . TI UE 1 − L UE / Ltot UE + b 3 where E(UE) denotes the energy consumed at a given time t at the user equipment UE for attack detection and Etot(UE) the total energy at the user equipment UE dedicated to attack detection, M(UE) denotes the memory consumed by the user equipment UE at time t for attack detection and Mtot(UE) the total memory at the user equipment UE dedicated to attack detection, L(UE) denotes the latency introduced at time t by attack detection at the user equipment UE and Ltot(UE) the maximum latency that can be supported at the user equipment UE for attack detection.It is noted that the instant t considered is chosen to reflect a current state of the consumption of the user equipment UE in terms of energy and memory and the current latency introduced at the level of the user equipment UE; it may be for example the instant of evaluation of the functions TFe(UE), TFm(UE) and TFI(UE) or the instant of detection of the anomaly by the user equipment UE.

[0097] The values ​​Te(UE), Tm(UE), and TI(UE) are fixed real values ​​also between 0 and 1: these are rates specific to each user equipment UE, and with which the user equipment UE may have been previously configured (for example statically by its manufacturer or dynamically by the NW network operator). These values ​​Te(UE), Tm(UE), and TI(UE) respectively define a maximum energy, memory and latency threshold that can be allocated at the user equipment UE for attack detection, taking into account the total energy, memory and latency available to the user equipment UE for this purpose. For example, if the total energy dedicated at the user equipment UE to attack detection is Etot(UE) (UE) = 100J (joules) and the energy consumed by the user equipment UE when detecting the anomaly is E(UE) = 25J (joules), Te(UE) = 85% (or 0.85) means that 85% of 75J (i.e.100J-25J) may still be allocated at the user equipment UE level for attack detection.

[0098] The factors a1, a2, a3, b1, b2 and b3 are real weighting factors chosen between 0 and 1 and so as to guarantee values ​​of the functions TFe(UE), TFm(UE) and TFI(UE) between 0 and 1. They can be determined by experimentation or by expertise. They are introduced here to reflect the importance of the energy consumption, storage and latency constraints for the user equipment UE considered, and can allow, depending on their choice, to prioritize these constraints between them. Thus, if the energy consumption constraint is a strong constraint for the user equipment UE considered, the factor a1 is chosen to be greater than the factor b1, and preferentially tends towards 1 while the factor b1 tends towards 0. Conversely, if the user equipment UE has only a fairly weak constraint in terms of energy consumption, a1 can be chosen to tend towards 0 while b1 tends towards 1.Note that if the user equipment UE has no constraints in terms of energy consumption, in this case we can take a1=b1=Te(UE)=0.

[0099] This example of the three threshold functions TFe(UE), TFm(UE) and TFI(UE) evaluated and provided by the user equipment UE is given for illustrative purposes only, considering that the energy consumption, storage and latency constraints are the most common constraints encountered at the user equipment level. Alternatively, other constraints (e.g. hardware, network and / or security) may be considered in addition to or instead of the aforementioned constraints. Furthermore, these constraints may take other forms than the threshold functions TFe(UE), TFm(UE) and TFI(UE) (e.g. we can have a1=a2=a3=1 and b1=b2=b3=0).

[0100] The intervention module of the L-IDA agent of the user equipment UE inserts the calculated values ​​of the functions TFe(UE), TFm(UE) and TFI(UE) into the ALERT message sent to the access point AP, as well as the values ​​of E(UE), Etot(UE), M(UE), Mtot(UE), L(UE) and Ltot(UE), for example in fields of the message provided for this purpose. These values ​​are information representative of constraints of the user equipment UE within the meaning of the invention.

[0101] Alternatively, the intervention module of the L-IDA agent of the user equipment UE may insert into the ALERT message sent to the access point the values ​​E(UE), Etot(UE), M(UE), Mtot(UE), L(UE) and Ltot(UE), Te(UE), Tm(UE), TI(UE) and the weighting factors a1, b1, a2, b2, a3, b3, and it is the access point AP which evaluates the functions TFe(UE), TFm(UE) and TFI(UE) from the information provided by the user equipment UE. In yet another alternative, the weighting factors a1, b1, a2, b2, a3, b3 may be accessible by the access point AP from a database and not be provided by the user equipment UE in the ALERT message.

[0102] Alternatively, the information representative of the constraints of the user equipment UE may take other forms. For example, the user equipment UE may specify in the ALERT message an indicator of the type of equipment to which it belongs, this indicator being associated in a pre-populated database, accessible by the access point AP, with one or more constraints of the user equipments of this type.

[0103] In reference to the Figure 3 , upon receipt by the access point AP of an ALERT alert message from a user equipment UE (step F10), the G-IDA agent of the access point AP activates its anomaly and attack detection module (step F20).

[0104] The access point AP module extracts from the received ALERT message the traffic characteristics collected by the user equipment UE and associated with the anomaly that the latter has detected (step F30).

[0105] It also obtains from the ALERT alert message received, information representative of the constraints of the user equipment UE at the origin of the message (step F30).

[0106] In the embodiment described here, this information is the values ​​of the threshold functions TFe(UE), TFm(UE) and TFI(UE) and the values ​​of E(UE), Etot(UE), M(UE), Mtot(UE), L(UE) and Ltot(UE) inserted by the user equipment in the ALERT message.

[0107] Alternatively, as mentioned previously, the G-IDA agent of the access point AP can obtain this information by comparing an indicator of the type of user equipment UE at the origin of the ALERT message contained in this message, with constraints to which user equipment of this type is subject, stored for example in a database accessible by the access point AP (located or not in the NW network).

[0108] Then the anomaly and attack detection module is configured according to the constraints thus identified for the user equipment UE (step F40). This configuration notably comprises the selection of an attack detection algorithm adapted to the constraints of the user equipment UE and / or a parameterization of the attack detection algorithm applied by the detection module adapted to these constraints.

[0109] It is noted that the attack detection algorithm used by the detection module is also adapted to the constraints of the access point AP. However, since the latter is located in the NW network, its constraints, at least hardware-wise, are generally less significant than those of the user equipment UE (in particular in terms of energy consumption, storage or even calculation). The access point AP can therefore apply a more complex and more robust attack detection algorithm than that applied by the user equipment UE, presenting better performances in terms of attack detection rate and / or false positive rate.

[0110] For example, when configuring the detection module, a fast detection algorithm to be executed may be selected if the user equipment UE has a significant or even ultra-significant constraint in terms of latency (estimated from the value of TFI(UE).[Ltot(UE)-L(UE)], for example by comparison with a threshold). Such an algorithm may be a signature-based algorithm whose number of signatures considered is chosen as a function of the maximum latency that can be supported by the user equipment UE (given by the value of TFI(UE).[Ltot(UE)-L(UE)]), or alternatively a machine learning detection algorithm parameterized as a function of the maximum latency given by the value TFI(UE).[Ltot(UE)-L(UE)]. An example of such parameterization consists for example in sizing the duration of the learning as a function of the value TFI(UE).[Ltot(UE)-L(UE)], to respect this maximum latency value supported by the user equipment UE while guaranteeing an acceptable level of security for the user equipment UE (in terms of detection rate for example or false positives). The parameter values ​​can be determined experimentally beforehand so as to verify a series of predefined compromises for example, and allow the G-IDA agent to quickly select the parameters adapted to the constraints in terms of security, network constraints and hardware resources of the user equipment UE.

[0111] The G-IDA agent detection module then processes the traffic characteristics extracted from the received ALERT message with the duly configured detection algorithm (step F50).

[0112] It is noted that during this processing, the detection module can also use traffic characteristics collected by the access point AP or reported by other user equipment connected to the access point AP, or by other AP access points of the NW network located for example in its vicinity and able to communicate with it. It can thus aggregate a large number of collected characteristics and strengthen the robustness of the detection implemented. Advantageously, the access point AP benefits from better visibility on the traffic exchanged via the NW network than each user equipment UE individually.

[0113] It is also noted that local detection can also be implemented independently by the access point AP via its detection module based on the characteristics collected by the access point AP, in order to detect anomalies occurring at the level of the NW network. There are thus two levels of detection operated by the access point AP: local detection of anomalies and attacks based on the characteristics of the traffic collected by the access point AP itself, and detection of attacks operated on the anomalies reported by the user equipment UE based on the characteristics collected by the latter. For local detection of anomalies and attacks based on the characteristics of the traffic collected by the access point AP itself, the detection module of the access point AP is configured taking into account its own constraints.The access point AP may alternatively be provided with two separate detection modules, one intended to operate on the characteristics of the traffic reported by the user equipment UE and configured according to the constraints of the user equipment UE as described previously, and one intended to operate on the characteristics of the traffic collected locally by the access point AP and configured according to the constraints of this access point AP.

[0114] Different situations may arise depending on the result of the processing carried out by the G-IDA agent detection module: the G-IDA agent is able to manage itself the anomaly reported by the user equipment UE (yes response to test step F60), in other words, the detection module of the G-IDA agent has identified that this anomaly is linked to a computer attack that the G-IDA agent knows how to process (for example, the anomaly corresponds to a signature of a computer attack that the detection module knows), or the detection module of the G-IDA agent has determined that the anomaly detected by the user equipment UE is linked to normal behavior of the network. In this case, the G-IDA agent processes the detected anomaly itself (step F70), namely: if this anomaly is linked to an attack (against a user equipment connected to the network or against an element of the network), it prepares via its intervention module a response intended for the user equipment UE to enable it to respond to this attack. The way in which the response is determined is described in more detail later.Furthermore, in the embodiment described here, the intervention module of the G-IDA agent sends a notification message of the detected attack to the security operations center SOC supervising the NW network. This message (which may be an ALERT message as described previously or another notification message) aims to alert the security operations center SOC of the attack in progress so that it updates the information it has on the NW network and the attacks perpetrated against this network, and thus enrich the databases and statistics it maintains on the network(s) it supervises. It may contain the characteristics of the traffic associated with the detected attack and collected by the user equipment UE, but also other types of information collected for example by the access point.The security operations center can also make a decision regarding the management of the detected attack and the action(s) that can be implemented to mitigate this attack: registration of the user equipment UE or more generally of the suspected target(s) of the attack on a blacklist, updating of cryptographic keys, deployment of IDA agents in the affected area, etc.; if this is normal behavior of the NW network, in the embodiment described here, the intervention module of the G-IDA agent does nothing, i.e. it does not respond to the user equipment UE in order to preserve the signaling exchanged with the latter and its response processing resources; the intervention module also does not inform the security operations center of the anomaly reported by the user equipment UE.Alternatively, if the anomaly detected by the user equipment UE is linked to a normal behavior of the NW network, the intervention module of the G-IDA agent responds to the user equipment UE by reporting this normal behavior to it; the G-IDA agent is not able to manage the anomaly itself (response no to test step F60), in other words, it does not know how to conclude on the nature of the anomaly that the user equipment UE has detected and in particular, it is unable to determine whether the detected anomaly corresponds to a normal behavior of the NW network or to a computer attack: in this case, the intervention module of the G-IDA agent is configured to send an ALERT alert message to the security operations center SOC supervising the NW network, for additional analysis of the anomaly (step F80). This alert message is sent via the communication interface of the access point AP.

[0115] When the detection module of the G-IDA agent detects an attack from the anomaly reported by the user equipment UE, the processing of the attack detected by the intervention module of the G-IDA agent and the response which is made to the user equipment UE concerning the anomaly which it has detected and reported, depends on several parameters such as in particular the nature and the seriousness of the attack, the target which one wishes to protect from this attack, etc.

[0116] Furthermore, in accordance with the invention, the intervention module of the G-IDA agent determines (i.e. develops) the response that it provides to the user equipment UE concerning the anomaly that it has detected based on the constraints of this user equipment UE.

[0117] Such a response may consist, for example, in sending in a response message to the user equipment UE, hereinafter called FEEDBACK, new signatures and / or new attack attributes (depending on the detection algorithm used by the L-IDA agent of the user equipment UE) intended to be applied by the user equipment UE to be able to detect attacks of the type detected by the G-IDA agent. These new signatures (for example for a signature-based detection algorithm) and / or these new attributes (for example for a behavioral detection algorithm based on machine learning) may be, for example, the signatures and / or the attributes which have been used or considered where appropriate by the detection module of the G-IDA agent to detect the attack.Alternatively, they may have been provided to the G-IDA agent by an external IDS (Intrusion Detection System) entity, such as the Security Operations Center (SOC).

[0118] The number of signatures and / or attributes provided in the FEEDBACK message can be sized by the G-IDA agent intervention module according to the constraints of the user equipment UE.

[0119] For this purpose, in the embodiment described here, the intervention module of the G-IDA agent evaluates an efficiency function noted EF(UE), between 0 and 1, and defined by the following weighted sum: EF UE = E a 4 . AD UE − b 4 . TF UE where E[] denotes the mathematical expectation, a4 and b4 are real weighting factors between 0 and 1 and determined experimentally taking into account for example the constraints on attack detection rate and other constraints of the user equipment, AD(UE) denotes the capacity (or effectiveness) of attack detection by the L-IDA agent of the user equipment UE, and: TF UE = Te UE + Tm UE + TI UE / TFe UE + TFm UE + TFI UE

[0120] The ability of the L-IDA agent of the user equipment UE to detect attacks (or new attacks) can be evaluated by the intervention module of the G-IDA agent from the inverse of the ratio of the number of anomalies reported by the user equipment UE (on which the user equipment UE was not able to conclude that there was an attack or normal behavior) and the number of attacks detected by the detection module of the G-IDA agent among these anomalies.

[0121] Alternatively, the attack detection capability of the L-IDA agent of the user equipment UE may be evaluated to also take into account the rate of false positives detected by the user equipment UE.

[0122] Note that TF(UE) may have been calculated by the user equipment UE and reported by it in the ALERT message sent to the access point AP (instead of or in addition to the values ​​of TFe(UE), TFm(UE) and TFI(UE)).

[0123] Using the efficiency function EF(AP), the G-IDA agent intervention module can adapt its response to the user equipment UE according to a chosen trade-off between the efficiency of the detection performed by the user equipment UE and the hardware / network / security constraints of this user equipment UE. The emphasis can be placed more on efficiency or on constraints via the choice of the weighting factors a4 and b4.

[0124] More particularly, in the embodiment described here, the intervention module of the G-IDA agent adapts the number N of signatures and / or the number of attributes (depending on the detection algorithm used by the L-IDA agent of the user equipment UE) sent to the user equipment UE in response to the anomaly detected by the latter according to the value taken by the efficiency function EF(AP). For example: if 0.7≤EF(AP)≤1: the intervention module sends to the user equipment UE all the new signatures of the attack known / obtained by the G-IDA agent in the FEEDBACK message (the emphasis in this case being on the attack detection capability of the user equipment UE that is to be improved); if 0.1≤EF(AP)<0.7: the intervention module sends to the user equipment UE only a subset of the new signatures and / or new attributes of the attack known / obtained by the G-IDA agent in the FEEDBACK message. The number of new signatures and / or new attributes sent is for example taken equal to (AD / x)*100 where x denotes a maximum cost factor borne by the user equipment UE, and provided by the latter (for example in the ALERT message). This cost factor is chosen here among the values ​​{2,3,4,5}; if EF(AP)<0.1: The intervention module does not send any new signature or new attribute to the user equipment UE. However, it can inform it in the FEEDBACK message that the anomaly detected by the latter is indeed linked to a computer attack so that the latter can take appropriate action.

[0125] This example of determining the response provided to the user equipment UE taking into account the constraints of the latter is given for illustrative purposes only, and is not limiting in itself. Thus, the determined response may take into account other constraints, such as for example constraints in terms of communication overhead, and the number of signatures / attributes may vary depending on this overhead.Of course, other types of responses may be sent to the user equipment UE, other than responses containing new signatures and / or new attributes where appropriate: these responses may include in particular update information allowing it to reconfigure itself to be more robust to the detected attack, or one or more actions to be implemented by the user equipment UE in response to the detected attack, this or these actions having been determined by the G-IDA agent taking into account the constraints of the user equipment UE (and its nature in particular), etc.

[0126] Furthermore, other ways of determining the response provided to the user equipment UE than by considering the aforementioned efficiency function EF(AP) may be envisaged. For example, the intervention module of the G-IDA agent may directly compare the values ​​of the functions AD(UE) and TF(UE) with each other.

[0127] In reference to the Figure 2, the FEEDBACK message is received by the user equipment UE (yes response in step E60), and the latter, via its intervention module, applies the actions contained in the message. Thus, by way of illustration, if the FEEDBACK message contains one or more new signatures, the L-IDA agent of the user equipment UE configures the intervention module to apply these new signatures during a future implementation.

[0128] In reference to the Figure 3, as mentioned previously, if the G-IDA agent is not able to rule on the anomaly reported by the user equipment UE, the intervention module of the G-IDA agent sends an ALERT alert message to the security operations center SOC during step F80. This ALERT alert message notifies the security operations center SOC of the anomaly detected by the user equipment UE and includes the traffic characteristics provided by the user equipment and associated with the detected anomaly. It also includes at least one item of information representative of a constraint of the access point AP.

[0129] For example, if the access point AP has a constraint in terms of latency (e.g. it supports a maximum latency TI(AP).[L(AP)-Ltot(AP) with the notations introduced previously for the user equipment UE transposed to the access point AP), this information is, in the embodiment described here, the value of a threshold function TF(AP) calculated by the access point AP and defined by: TF AP = TI AP / TFI AP with TFI(AP)=a5.TI(AP).[1-L(AP) / Ltot(AP)]+b5, where a5 and b5 are real weighting factors between 0 and 1, which can be determined experimentally and chosen so as to guarantee a value of TFI(AP) between 0 and 1.

[0130] Of course, this example is given for illustrative purposes only and is not limiting in itself. The constraints taken into account depend on the device of the network considered embedding the G-IDA agent, whether it is located in the access network or in the core network of the NW network, etc. As mentioned previously, the invention is not limited to embedding G-IDA agents at the access points of the access network of the NW network; such agents can be embedded in other devices of the NW network, in particular in sensitive elements of the network, such as for example at the level of servers, in the CN core network, in edge servers, etc.Table 2 below illustrates examples of network devices that can embed a G-IDA agent in accordance with the invention and of constraints (essentially network and security) encountered at the level of these devices, as well as the detection algorithms that can be implemented at the level of these devices by their detection modules. Everything that has been described previously and what is described later with reference to the G-IDA agent of the access point AP applies to each network device embedding such a G-IDA agent. Thus, for a server SERV of a network subscriber management platform, the function TF(SERV) can be a weighted sum taking into account the rate TFI(SERV) but also a rate corresponding to the flow rate that must be respected by the server as well as a rate corresponding to its bandwidth. [Table 2] Network devices Network and security constraints Detection module configuration Servers of a network subscriber management platform Very low latency, high speed and high bandwidth; Unsupervised and / or reinforcement learning machine algorithms Attack detection rate and false positives, detection time Communication overhead CSCF servers or application server of an IMS architecture Low latency, high speed and high bandwidth; Unsupervised and / or reinforcement learning machine algorithms Attack detection rate and false positives, detection time Communication overhead Mobile Edge Computing (MEC) Server Low latency, high bandwidth; Unsupervised and / or reinforcement learning machine algorithms Attack detection rate and false positives, detection time Communication overhead Core network gateway or server (e.g., Mobility Management Entity (MME) servers, SGW or PGW gateway) Very low latency, high speed and high bandwidth; Unsupervised and / or reinforcement learning machine algorithms Attack detection rate and false positives, detection time Communication overhead

[0131] It is noted that a similar ALERT alert message is sent by the intervention module of the G-IDA agent of the access point AP if the latter detects an anomaly from the characteristics that it has itself collected locally via its monitoring module and is not able to decide on this anomaly (i.e. determine whether it is an attack or normal behavior of the NW network). The ALERT alert message then sent to the security operations center SOC for further analysis of the anomaly detected by the detection module of the G-IDA agent includes the characteristics collected by the monitoring module of the G-IDA agent as well as the information TF(AP), L(AP) and Ltot(AP) representative of the constraints of the access point AP (constraint in terms of latency in the example considered here).

[0132] If the G-IDA agent is able to decide on the anomaly that it has detected locally, it processes this anomaly in a similar way to what was previously described for the L-IDA agent. In other words, if this anomaly is linked to an attack, it applies via its intervention module the processing with which it was configured to respond to the detected attack and notifies the security operations center of the detected attack, and if this is a normal behavior of the NW network, it does nothing and continues its monitoring of the traffic. Note that the processing applied by the intervention module in response to the detected attack may depend on the type of network device considered embedding the G-IDA agent and / or the nature of the detected attack (typically its severity).

[0133] In reference to the Figure 4, it is assumed that the security operations center SOC receives a message from a device of the NW network such as for example from the access point AP (step H10).

[0134] Several scenarios may arise: case (I): the message received is an ALERT message notifying the security operations center SOC of the detection of an anomaly by a user equipment UE connected to the access point AP (or managed by it) on which neither the user equipment nor the access point AP has been able to decide, in other words to determine whether it is an anomaly linked to an attack or to normal behavior of the NW network and the user equipments connected to it; case (II): the message is an ALERT message notifying the security operations center SOC of the detection of an anomaly by the access point AP on which the access point AP has not been able to decide; case (III): the message is a notification message of an attack detected by a user equipment or by an access point AP of the NW network.

[0135] In case (I), the received ALERT message contains the traffic characteristics associated with the anomaly detected by the user equipment UE and collected by the latter. It also contains at least one item of information representative of a constraint of the access point AP (for example a latency constraint given by the value TF(AP) previously described).

[0136] The detection module of the C-IDA agent embedded in the security operations center SOC is then configured according to said at least one information representative of the constraint of the access point (step H20). This configuration notably comprises the selection of an attack detection algorithm adapted to the constraints of the access point AP and / or a configuration of the attack detection algorithm applied by the detection module adapted to these constraints.

[0137] It is noted that the security operations center has an overview of the network(s) it supervises and does not strictly speaking have any hardware constraints in terms of storage, energy consumption or computing power. It can therefore apply an attack detection algorithm that is more complex and more robust than that applied by the user equipment UE and that applied by the access point AP (for example, detection algorithms based on deep learning, unsupervised or reinforcement learning), presenting better performances in terms of attack detection rate and / or false positive rate. It can also benefit from the expertise of analysts and security specialists, who can provide a human opinion on the anomalies detected via, for example, a user interface provided for this purpose, and in particular make it possible to reduce the rate of false positives detected.

[0138] The detection algorithm applied by the detection module can be advantageously parameterized taking into account the constraints of the access point AP. For example, if a latency constraint is provided in the ALERT message by the access point AP, and a machine learning algorithm is used by the detection module, the duration of the learning can be parameterized so as to respect the latency reported by the access point AP.

[0139] The C-IDA agent detection module then processes the traffic characteristics extracted from the received ALERT message with the duly configured detection algorithm (step H30).

[0140] It is noted that during this processing, the detection module can also use traffic characteristics reported by other user equipment connected to the AP access point, or by other AP access points or other devices in the NW network that it supervises. It can thus aggregate a large number of collected characteristics and strengthen the robustness of the detection implemented.

[0141] If, following processing of the traffic characteristics associated with the anomaly detected by the user equipment UE, the detection module of the C-IDA agent detects the presence of an attack (yes response to test step H40), the reaction module of the C-IDA agent determines a response to be transmitted to the access point AP concerning the anomaly based on the constraint information of the access point AP (step H50).

[0142] For example, if this constraint is a constraint in terms of latency, the intervention module of the C-IDA agent responds without delay to the access point AP by notifying it for example in a FEEDBACK message of the detected attack, and by inserting in its response at least one action to be implemented to mitigate the attack by the access point AP and / or by the user equipment UE. This action may consist for example of the use of one or more new signatures of the attack and / or new attributes provided by the security operations center, or other information intended to allow the access point AP to detect such an attack.

[0143] Another action may consist of disconnection of the user equipment by the access point, isolation of the malicious node (user equipment or other node of the NW network), updating of cryptographic keys, sending information to experts about the area infected by the attack, dissemination to other operators, notification sent to the user of the user equipment UE, etc.

[0144] Alternatively, if the constraint is a communication overhead or bandwidth constraint, the intervention module of the C-IDA agent can modulate the number of new signatures transmitted to the access point AP as a function of this constraint. To determine the number of new signatures to be transmitted, the intervention module of the C-IDA agent can proceed in a similar manner to what was described previously for the intervention module of the G-IDA agent, by evaluating an efficiency function EP(SOC) from the capacity AD(SOC) of detecting new attacks by the C-IDA agent and the constraint TF(AP), and by modulating the number of signatures to be transmitted as a function of the value of the efficiency function EP(SOC) obtained (x then designating a cost factor of the access point AP, included for example by the latter in the ALERT message).

[0145] If, on the other hand, the detection module of the C-IDA agent determines (for example via cyber-experts) that the detected anomaly is linked to normal behavior (response no to test step H40), then the intervention module of the C-IDA agent does not respond here to the alert message sent by the access point AP (step H60).

[0146] In reference to the Figure 3, if the access point AP receives from the security operations center SOC a FEEDBACK response message to its ALERT message concerning the anomaly reported by the user equipment UE (yes response in step F90), this means here that an attack has been detected by the security operations center SOC from this anomaly. The intervention module of the G-IDA agent of the access point AP extracts from the FEEDBACK message received the action(s) recommended by the security operations center SOC in response to the detected attack, and develops a response to the user equipment UE (FEEDBACK message) from this or these actions taking into account the constraints of the user equipment UE, as described previously (step F70).

[0147] If the access point AP does not receive any FEEDBACK response message to its ALERT message, then this means that the anomaly reported to the security operations center corresponds to normal behavior of the user equipment and / or the NW network. The reaction module of the G-IDA agent of the access point AP then does not transmit any response here to the ALERT message received from the user equipment UE in order to preserve the resources of the network and of the user equipment UE (step F100). Alternatively, it can signal to the user equipment UE that the anomaly detected by it is linked to normal behavior.

[0148] It is noted that the C-IDA agent intervention module can also transmit directly to the user equipment UE a FEEDBACK message similar to that transmitted to the access point AP in the event of detection of an attack. This direct communication between the security operations center SOC and the user equipment UE makes it possible to strengthen security within the NW network and to manage situations where the access point AP would itself be subject to an attack.

[0149] In reference to the Figure 4 , in case (II), the received ALERT message contains the traffic characteristics associated with the anomaly detected locally by the access point AP and collected by the latter. It also contains at least one piece of information representative of a constraint of the access point AP (for example a latency constraint given by the value TF(AP) previously described).

[0150] The detection module of the C-IDA agent embedded in the security operations center SOC is then configured according to said at least one information representative of the constraint of the access point in a manner similar or identical to that described previously with reference to step H20 (step H70). This configuration notably comprises the selection of an attack detection algorithm adapted to the constraints of the access point AP and / or a parameterization of the attack detection algorithm applied by the detection module adapted to these constraints.

[0151] The C-IDA agent detection module then processes the traffic characteristics extracted from the received ALERT message with the duly configured detection algorithm (step H80).

[0152] If, following processing of the traffic characteristics associated with the anomaly detected by the access point AP, the detection module of the C-IDA agent detects the presence of an attack (yes response to test step H90), the reaction module of the C-IDA agent determines a response to be transmitted to the access point AP concerning the anomaly based on the constraint information of the access point AP (step H100). It does this in a similar or identical manner to what was previously described for step H50.

[0153] If, on the other hand, the detection module of the C-IDA agent determines (for example via cyber-experts) that the detected anomaly is linked to normal behavior (response no to test step H90), then the intervention module of the C-IDA agent does not respond here to the alert message sent by the access point AP (step H110).

[0154] In reference to the Figure 3, if the access point AP receives from the security operations center SOC a FEEDBACK response message to its ALERT message concerning the anomaly that it detected locally and reported to the security operations center SOC (yes response in step F90), this means here that an attack was detected by the security operations center SOC from this anomaly. The intervention module of the G-IDA agent of the access point AP extracts from the FEEDBACK message received the action(s) recommended by the security operations center SOC in response to the detected attack, and implements these actions (step F70). Such an action may consist for example in updating the security rules applied by its attack detection module (e.g. signatures, detection thresholds, etc.).

[0155] If it does not receive a FEEDBACK response to its ALERT message concerning the anomaly it detected locally (no response to test step F90), it means that the anomaly it detected is linked to normal behavior (step F100). The AP access point continues its local monitoring of the traffic exchanged via the NW network.

[0156] In reference to the Figure 4, in case (III), the notification message received by the security operations center is used by the latter to update and enrich the databases and statistics that it maintains on the network(s) that it supervises (step H120). The security operations center SOC can also take a decision as to the management of the detected attack and the action(s) that can be implemented to mitigate this attack: registration of the user equipment UE or more generally of the suspected target(s) of the attack on a blacklist, updating of cryptographic keys, deployment of IDA agents in the affected area, etc. Where appropriate, one or more actions to be executed in order to mitigate the attack can be transmitted to the access point AP and / or to the user equipment UE, for example in a response message to the notification message.

[0157] The invention therefore proposes an innovative mechanism which relies on the hierarchical deployment at various levels of a network, of intrusion detection agents (IDA) configured to collaborate with each other in order to improve the security of the network, and this by allowing better detection (and mitigation) of internal and / or external computer attacks perpetrated against this network. The invention makes it possible to reliably and rapidly detect attacks in a network while taking into account the constraints, in particular hardware, network or security constraints, of the different equipment connected to this network or belonging to this network. It also makes it possible to provide an appropriate response to detected attacks which takes these constraints into account. The invention is therefore particularly well suited to 5th generation networks which offer connectivity to a wide variety of user equipment subject to very diverse constraints.

Claims

1. Method for processing, by way of a network (NW) device (AP), an alert message received from a user equipment (UE) connected to the network, said alert message notifying of an anomaly detected by the user equipment in traffic transmitted via the network, said processing method comprising: - a step (F30) of obtaining, from the alert message, at least one item of information representative of at least one constraint of the user equipment; - a step (F50) of processing, by way of a cyber attack detection algorithm, features of the traffic that are provided by the user equipment and associated with the detected anomaly, the cyber attack detection algorithm being selected and / or parameterized on the basis of said at least one item of information; and - a step (F70) of determining, on the basis of a result of the processing step, and if a cyber attack is detected, of said at least one item of information, a response to the user equipment concerning the detected anomaly.

2. Processing method according to Claim 1, wherein said obtained at least one item of information is representative of at least one constraint in terms of resources and / or network performance of the user equipment.

3. Processing method according to Claim 2, wherein: - the constraint in terms of resources is an energy consumption or available storage space constraint; - the constraint in terms of network performance is a latency, bandwidth, data rate, time to process information provided to the user equipment or surplus amount of information provided to the user equipment constraint.

4. Processing method according to any one of Claims 1 to 3, wherein the cyber attack detection algorithm is selected from among: - a detection algorithm based on cyber attack signatures; - a machine learning-based detection algorithm.

5. Processing method according to Claim 4, wherein, when a machine learning-based detection algorithm is selected in the processing step, a training duration under consideration for said algorithm is parameterized on the basis of said at least one item of information.

6. Processing method according to any one of Claims 1 to 5, wherein: - the processing step comprises detecting a cyber attack against a user equipment connected to the network and / or against a network element; and - the determination step comprises evaluating a function, called efficiency function, based on at least one metric derived from said at least one item of information and an attack detection efficiency of the user equipment, the response being determined on the basis of the value of the efficiency function.

7. Processing method according to Claim 6, wherein the determined response comprises sending a message to the user equipment comprising N signatures and / or attributes of the attack that are obtained by the network device, N denoting an integer dependent on the value of the efficiency function.

8. Processing method according to Claim 7, wherein N furthermore depends on a cost factor provided by the user equipment.

9. Processing method according to Claim 7 or 8, wherein the signatures and / or attributes of the attack are obtained by the network device from a security operations centre supervising said network.

10. Processing method according to any one of Claims 1 to 9, comprising, if, in the processing step, the network device is incapable of determining whether the detected anomaly corresponds to normal behaviour or to a cyber attack, a step (F80) of sending, to a security operations centre (SOC) supervising the network, an alert message notifying it of the anomaly detected by the user equipment and comprising the features of the traffic that are provided by the user equipment and associated with the detected anomaly and at least one item of information representative of a constraint of the network device.

11. Processing method according to any one of Claims 1 to 10, furthermore comprising: - a step of detection, by the network device, of an anomaly in traffic transmitted on the network from features of the traffic that are obtained by the network device; - a step of sending, to a security operations centre (SOC) supervising the network so as to analyse the anomaly detected by the network device, of a notification message notifying of this anomaly comprising said features of the traffic that are obtained by the network device and at least one item of information representative of a constraint of the network device.

12. Processing method according to any one of Claims 1 to 11, furthermore comprising, if, in the processing step, the network device detects a cyber attack against a user equipment connected to the network and / or against a network element, a step of notifying a security operations centre supervising the network of the detected attack.

13. Supervision method performed by a security operations centre (SOC) supervising at least one network, comprising: - a step (H10) of receiving, from a network device, an alert message notifying of an anomaly detected by a user equipment connected to the network or by the network device in traffic transmitted via said network, said alert message comprising features of the traffic that are obtained by the user equipment or by the network device and associated with the detected anomaly, and at least one item of information representative of at least one constraint of the network device; - a step (H30, H80) of processing, by way of a cyber attack detection algorithm, said features of the traffic, the detection algorithm being selected and / or parameterized on the basis of said at least one item of information; and - a step (H50, H100) of determining, on the basis of a result of the processing step and, if an attack is detected, of said at least one item of information, a response to the network device and / or to the user equipment concerning the detected anomaly.

14. Notification method performed by a user equipment (UE) connected to a network, comprising: - a step (E20) of detecting an anomaly in traffic transmitted via the network, from features of the traffic that are obtained by the user equipment; - if the user equipment is incapable of determining whether the detected anomaly corresponds to normal behaviour or to a cyber attack, a step (E50) of sending, to a network device, an alert message notifying it of the detected anomaly, said alert message comprising said features of the traffic and at least one item of information representative of at least one constraint of the user equipment; and - a step (E60) of receiving a message from the network device concerning the detected anomaly and created on the basis of said at least one item of information.

15. Network device (AP) comprising: - a reception module (G-IDA), able to receive an alert message from a user equipment connected to the network, this alert message notifying of an anomaly detected by the user equipment in traffic transmitted via the network; - an obtainment module (G-IDA), configured so as to obtain, from the alert message, at least one item of information representative of at least one constraint of the user equipment; - a processing module (G-IDA), configured so as to process, by way of a cyber attack detection algorithm, features of the traffic that are provided by the user equipment and associated with the detected anomaly, the cyber attack detection algorithm being selected and / or parameterized on the basis of said at least one item of information; and - a determination module (G-IDA), configured so as to determine, on the basis of a result of the processing step, and if a cyber attack is detected, of said at least one item of information, a response to the user equipment concerning the detected anomaly.

16. Security operations centre (SOC) supervising at least one network, comprising: - a reception module (C-IDA), able to receive, from a network device, an alert message notifying of an anomaly detected by a user equipment connected to the network or by the network device in traffic transmitted via said network, this alert message comprising features of the traffic that are obtained by the user equipment or by the network device and associated with the detected anomaly, and at least one item of information representative of at least one constraint of the network device; - a processing module (C-IDA), configured so as to process, by way of a cyber attack detection algorithm, said features of the traffic, the detection algorithm being selected and / or parameterized on the basis of said at least one item of information; and - a determination module (C-IDA), configured so as to determine, on the basis of a result of the processing step and, if an attack is detected, of said at least one item of information, a response to the network device and / or to the user equipment concerning the detected anomaly.

17. User equipment (UE) connected to a network, comprising: - a detection module (L-IDA), configured so as to detect an anomaly in traffic transmitted via the network from features of the traffic that are obtained by the user equipment; - a sending module (L-IDA), activated if the user equipment is incapable of determining whether the detected anomaly corresponds to normal behaviour or to a cyber attack, said sending module being configured so as to send, to a network device, an alert message notifying it of the detected anomaly, this alert message comprising said features of the traffic and at least one item of information representative of at least one constraint of the user equipment; and - a reception module (L-IDA), able to receive a message from the network device concerning the detected anomaly and created on the basis of said at least one item of information.

18. Monitoring system (1) for monitoring a network, comprising: - at least one user equipment (UE) according to Claim 17; - at least one network device (AP) according to Claim 15; and - a security operations centre (SOC) according to Claim 16.

19. Monitoring system according to Claim 18, wherein the network device is an equipment of an access network of the network.

20. Monitoring system according to Claim 18, wherein the network device is an equipment of a core network.