Monitoring of at least one section of a communications network using a confidence index assigned to that section of the network.
Patent Information
- Application Number
- DE602021048673
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2020-06-19
- Filing Date
- 2021-06-18
- Publication Date
- 2026-02-25
- Estimated Expiration
- 2041-06-18
AI Technical Summary
Existing 5G network slicing architectures face insufficient security against cyber-attacks due to individual management of intrusion detection functions, leading to potential false negative detection rates during massive attacks.
A distributed monitoring system with intrusion detection modules deployed across access, edge, and core networks, collaboratively assessing an overall confidence level to trigger targeted mitigation actions, utilizing techniques like anomaly detection, predefined rules, and machine learning to enhance security.
The system reduces false detection rates and improves overall network security by ensuring end-to-end monitoring and rapid response to cyber threats, maintaining high performance and resource efficiency.
Description
Technique antérieure
[0001] The invention relates to the general field of telecommunications and more particularly to the security of communication networks and the protection of these networks against computer attacks, also commonly known as cyber-attacks.
[0002] It has a privileged but not limiting application in the context of 5G (5th Generation) networks, and in particular 5G wireless networks based on architectures implementing a network slicing technique, more commonly known as "network slicing" in English.
[0003] The architecture of currently deployed or being deployed wireless telecommunications networks is defined by the standardization group known as 3GPP (Third Generation Partnership Project). This is particularly the case for so-called second-generation ("2G or GSM"), third-generation ("3G"), and fourth-generation ("4G") wireless networks.
[0004] Up to the fourth generation, network architectures defined by the 3GPP group most often rely on specific equipment, dedicated to precise functionalities, whether at the access network level or the core network level, particularly with regard to the transmission of packets from or to a mobile terminal.
[0005] The inherent lack of flexibility and scalability of this type of architecture has led the 3GPP group to consider adopting more flexible architectures for the next generation of wireless networks, known as "5G," in order to respond quickly to the extremely diverse demands in terms of traffic and / or quality of service anticipated by 5G networks (Internet of Things (IoT), broadband access in dense networks, etc.). It should be noted that 5G networks are intended to encompass both mobile and fixed networks.
[0006] Among the solutions considered, one of the most promising relies on a network slicing technique. This technique is described in particular in the 3GPP technical specification TS 23.501 v15.7.0, September 2019. It allows a network operator to create customized and independent end-to-end logical networks for its customers, from the same physical network infrastructure (access network(s), core network, etc.), capable of providing optimized solutions for various scenarios corresponding to diverse constraints in terms of functionality, performance, and quality of service.
[0007] More specifically, the concept of network slices allows the creation of multiple network instances, also called "network slices." A network slice is composed of network functions, hardware resources (e.g., storage and compute, access, etc.), and configurations to meet the requirements of the services, clients, and / or terminals connected to that slice.
[0008] For example, the figure 1 This represents a simplified view of an INF communications infrastructure comprising eight network slices, SL1, SL2, ..., SL8, each representing a wireless network. The network slices share RAN (Radio Access Network) infrastructure, MEC (Multiple-Access Edge Computing) infrastructure, and virtual network functions or groups of virtual network functions implemented in the core network (CN). Such virtual network functions include, for example, routing, addressing, data flow control, naming, and so on. In the example of the figure 1 , network slices SL1 to SL8 share, for illustrative purposes, functions of the CN core network including, in particular, AMF (Access and Mobility Management Function), SMF (Session Management Function), UPF (User Plane Function), and PCF (Policy Charging Function).
[0009] The different network slices SL1, ..., SL8 can provide access to separate data networks or to the same data network. Each network slice can be considered a distinct wireless network and is defined by the characteristics of the data flows passing through it. These flows share common features in terms of, for example, destination, routing, and security constraints, justifying shared management within the same network slice. Each slice is thus optimized for the needs of a specific type of service and / or client and / or terminal type. The same terminal can be connected to different network slices.
[0010] In this context of "network slicing", 5G wireless networks, due in particular to the advanced communication techniques implemented and the new capabilities offered in terms of speeds, information volumes and connection, open up unprecedented usage prospects which pose real challenges in terms of cybersecurity.
[0011] The document WO2019115173A1 concerns the field of cybersecurity for network communications and focuses on the control of probes used to detect intrusions into such a network. The document by Y. Khettab et al., entitled "Virtual Security as a Service for 5G Verticals," WCNC 2018, IEEE Wireless Communications and Networking Conference, proposes an architecture that leverages the concepts of network function virtualization and software-defined networking (SDN) to secure a network slice on demand.This architecture relies on the dynamic deployment in each network slice of several virtual functions including intrusion detection services (or IDS for "Intrusion Detection Service") and packet inspection services (or DPI for "Deep Packet Inspection"), monitoring their performance, and dynamically adapting the number of functions deployed taking into account predefined policies and metrics.
[0012] The architecture proposed in this document helps to meet the flexibility and elasticity requirements imposed on 5G networks by ensuring optimal allocation of resources dedicated to securing the network segment in question. However, due in particular to the individual management of each deployed IDS / DPI security function, its effectiveness in terms of security in the event of a massive cyberattack against the network may prove insufficient (especially with regard to the false negative detection rate).
[0013] There is therefore a need for an architecture adapted to the network slicing advocated in particular in 5G networks and offering better network security against the threat of cyber-attacks. Exposé de l'invention
[0014] The invention is defined by the independent claims. Preferred embodiments are defined by the dependent claims.
[0015] The invention addresses this need in particular by proposing, according to a first aspect, a monitoring system for at least one slice of a communications network using at least one access network, one edge network, and one core network. This system comprises, for each slice, a plurality of intrusion detection modules configured to monitor elements associated with said slice and including at least one first intrusion detection module at the access network level, a second intrusion detection module at the edge network level, and at least one third module at the core network level. Each of these modules is configured to provide information representative of a local confidence level assigned to said slice based on the behavior of at least one element it monitors. This third module is further configured to evaluate, based on the information provided,an overall confidence level for said tranche and to trigger an intrusion mitigation action for said tranche based on a value of this overall confidence level.
[0016] Correspondingly, the invention also relates to a method for monitoring at least one slice of a communications network using at least one access network, one edge network and one core network, said method comprising: a monitoring step of said slice by a plurality of intrusion detection modules configured to monitor elements associated with said slice and comprising at least a first intrusion detection module at the access network level, a second intrusion detection module at the edge network level, and at least a third module at the core network level; a provision step, by each of said modules, of information representative of a local confidence level assigned to said slice based on the behavior of at least one element monitored by said module; an evaluation step, by said third module, based on said information provided, of an overall confidence level for said slice; and a triggering step of an intrusion mitigation action for said slice based on a value of this overall confidence level.
[0017] No limitations are attached to the intrusion detection techniques implemented by the various intrusion detection modules involved in the implementation of the invention: these may include simple anomaly detection techniques based on predefined models of normal behavior, techniques based on predefined rules and / or signatures characterizing various known cyberattacks, supervised or unsupervised machine learning techniques, hybrid detection techniques using a combination of the aforementioned techniques, etc. Nor are there any limitations attached to the nature of the intrusions likely to affect the network: these may include distributed denial-of-service (DDoS) attacks, communication jamming, etc.
[0018] The invention thus proposes an architecture based on the deployment of several intrusion detection modules at various levels of each network slice (access network, edge network, core network), and on the collaboration of these detection modules to estimate an overall confidence index for each network slice, the value of this overall confidence index being taken into account to trigger, if necessary, an intrusion mitigation action at the level of said slice.
[0019] Such an action might be, for example, if the overall confidence level falls below a given threshold, isolating that segment of the network and / or removing at least one element of the access network, the edge network, and / or the core network identified as targeted by an intrusion. Of course, these examples of mitigation actions are only illustrative, and other mitigation actions may be considered, depending in particular on the nature of the detected intrusion, the confidence level, the severity of the intrusion, the anomaly information reported by the various intrusion detection modules, the element(s) targeted by the intrusion, etc.
[0020] By operating in a distributed manner at different levels of the network infrastructure supporting each network slice, and thanks to the proposed collaboration between the various detection modules, the invention makes it possible to limit the false detection rate (false negatives and / or false positives) for each detection module and to improve the overall security of the network slices compared to the prior art. The security of each slice is indeed ensured end-to-end, from the user terminal to the core network: the invention does not simply secure the access network or the core network, but monitors every part of the network for each slice considered. This results in enhanced security for the different network slices.
[0021] Furthermore, assessing an overall confidence index for the network segment allows us to determine how the segment is affected by any detected intrusion(s) and to trigger an appropriate response. This overall confidence index is advantageously calculated in the most secure part of the network, namely the network core, using information collected distributedly across different network segments. This results in a robust and reliable confidence index.
[0022] Furthermore, detection modules can be advantageously configured to exchange information about intrusions they detect within the network slice. This allows each module to benefit from detections made by others and also to update their knowledge of these intrusions. This "horizontal" collaboration within the same slice, in both the upstream (from the access network to the core network) and downstream (from the core network to the access network) directions, improves the accuracy and speed of detections performed by the modules.
[0023] In a particular embodiment, the plurality of detection modules associated with said slice comprises a plurality of third modules associated respectively with active network functions distinct from the core network.
[0024] In this embodiment, a detection module is advantageously deployed at the level of a plurality of network functions provided by the core network and activated for the considered bandwidth segment (for example, one detection module per active network function). Indeed, at any given time and for a given service, not all network functions present at the core network level are necessarily activated. This embodiment makes it possible to effectively protect these active network functions, and in particular the most critical functions for a given bandwidth segment, such as, for example, in the context of a 5G network, the AMF, UPF, and PCF functions mentioned previously.
[0025] Alternatively, a single intrusion detection module could be configured to simultaneously monitor several active network functions.
[0026] Regarding the first and second modules, one could, for example, consider an intrusion detection module deployed at the access network level (capable of monitoring the various entities on or connected to this access network), and an intrusion detection module deployed at the edge network level (capable of monitoring the various entities on this edge network). Of course, a configuration with more first and second modules is also possible.
[0027] Furthermore, it should be noted that the same detection module, regardless of the part of the network at which it is deployed, can be used to monitor multiple network slices simultaneously.
[0028] In the embodiment in which a plurality of third modules are deployed at various active network functions of the core network for said slice, the third module configured to evaluate the overall confidence level of a slice can be selected from among these third modules, for example, based on its proximity to the edge network(s) and access network(s) operated by said slice.
[0029] In this way, the risk of attacks is limited during the transfer of information between the modules located at the access network(s) and the edge network(s) and this third module. Such a module, in the example of a 5G network, is, for instance, an intrusion detection module embedded in an AMF or PCF function of the core network.
[0030] According to the invention, the overall index evaluated for a slice is calculated from the local indices reported by the first, second, and third detection modules. In a particular embodiment, the overall confidence level for a slice is, for example, an average of the local confidence levels provided by said plurality of detection modules.
[0031] Local confidence levels are assessed by the detection modules distributed throughout the network on each considered slice, based on the anomalies they observe. Several methods can be used to evaluate such a local confidence level.
[0032] For example, in a particular embodiment, at least one local confidence level is evaluated by a said detection module for a said slice as a ratio between a subtraction of a number of normal behaviors of said at least one element monitored by this detection module and a number of intrusions affecting said at least one element monitored by this detection module detected over a given period of time, by a sum of said numbers.
[0033] Such a local confidence level is easily assessed by the detection module in question, based on the monitoring it performs at the level where it is deployed. However, other ways of assessing a local confidence level for the slice can be considered. For example, the local confidence index can be calculated from a weighted sum of the two aforementioned numbers, or only one of them, and so on.
[0034] In a particular embodiment, said first module is configured to, upon detection of an intrusion, report said detected intrusion to said second module and / or to said first module associated with another slice using said access network.
[0035] This implementation proposes collaboration between detection modules, either horizontally, as discussed previously (i.e., between detection modules deployed on the same network slice), or vertically (i.e., between detection modules deployed on different network slices but using the same access network). The aim is to allow other network slices using the same physical infrastructure to benefit from information about intrusions detected on that infrastructure, such as the characteristics of these intrusions (also called "features") and their signatures (or "patterns"), thereby enriching the knowledge of the detection modules associated with these other slices.In this way, we improve the detection accuracy and responsiveness of detection modules to an attack deployed at the access network level, and where appropriate, the effectiveness of mitigation actions put in place in response to this attack.
[0036] This improves network security, and benefits the various segments of the network using the access network in question.
[0037] In a particular embodiment, the second module is configured to, upon detection of an intrusion, report said detected intrusion to at least a third module and / or trigger a mitigation action at the level of the access network and / or the perimeter network.
[0038] Information about detected intrusions is thus sent back to the core network, which allows the core network to have global visibility on intrusions targeting elements of the network slice.
[0039] In addition, a mitigation action can be triggered quickly as close as possible to the elements targeted by the intrusion (i.e. at the level of the access network and / or the perimeter network), and to fight the intrusion more effectively.
[0040] Each detection module, regardless of the network segment on which it is deployed, can be configured to perform a number of predetermined actions. These include monitoring the network segment on which it is deployed, performing in-depth traffic analysis when an intrusion is suspected, notifying other detection modules of the intrusion detection, triggering mitigation actions, and so on. These "logical" actions are configurable and can vary depending on the segment on which the module is deployed (depending on whether it is the first, second, or third module as defined in the invention), as well as other factors, such as the network slice on which it is deployed and its security sensitivity.
[0041] For example, in a particular embodiment, at least one said detection module is configured to execute at least one action among a deep traffic analysis action, a notification action, and / or a mitigation action when it detects that a probability of executing that action is greater than a determined threshold.
[0042] This threshold can be determined by experts, be static, vary depending on actions, etc.
[0043] Alternatively, it can be determined dynamically for and by said detection module based, for example, on a number of false detections made by the latter and by means of, for example, a machine learning algorithm.
[0044] Note that the notion of false detection is assessed here in relation to a validation of detected intrusions carried out at the core network level (for example by a third module within the meaning of the invention).
[0045] Such dynamic threshold adjustment allows for advantageous consideration of the changing environment of cyberattacks, in which characteristics can evolve rapidly or new attacks can emerge, as well as the performance of the detection module. Of course, the threshold can be adjusted based on other criteria.
[0046] The invention also relates to a communications network, configured to implement a slice-out, said communications network comprising a monitoring system according to the invention to monitor at least one slice of said network.
[0047] The network benefits from the same advantages mentioned above as the surveillance system according to the invention.
[0048] It can also be envisaged, in other embodiments, that the monitoring method, the monitoring system and the network according to the invention have in combination all or part of the aforementioned characteristics.
[0049] According to a second aspect, the invention proposes a monitoring system for at least one slice of a communications network using at least one access network, one edge network and one core network, said system comprising, for each slice, a plurality of intrusion detection modules configured to monitor elements associated with said slice and comprising at least one first intrusion detection module at the access network level, a second intrusion detection module at the edge network level, and at least one third module at the core network level, said detection modules being further configured to exchange information with each other on detected intrusions affecting elements they monitor, and at least one said detection module being configured to execute at least one action from among an in-depth analysis action of at least one anomaly detected on an element it monitors,an action of aggregating and / or correlating information received from at least one said detection module, an action of notifying said detection module of a detected intrusion, and / or an action of mitigating an intrusion when it determines that the probability of executing said action is greater than a given threshold.
[0050] Correspondingly, the invention also relates to a method for monitoring at least one slice of a communications network using at least one access network, one edge network and one core network, said method comprising: a monitoring step of said slice by a plurality of intrusion detection modules configured to monitor elements associated with said slice and comprising at least a first intrusion detection module at the access network level, a second intrusion detection module at the edge network level, and at least a third module at the core network level, said detection modules being further configured to exchange information with each other on detected intrusions affecting elements they monitor; a step of determining at least a probability of executing at least one action among an action of in-depth analysis of at least one anomaly detected on an element it monitors, an action of aggregation and / or correlation of information received from at least one said detection module, an action of notification of a said detection module of a detected intrusion, and / or an action of mitigation of an intrusion;and a step to execute said action if the probability of executing said action is greater than a given threshold.
[0051] The various intrusion detection modules involved in implementing the invention can employ different types of intrusion detection techniques. For example, they can use a simple anomaly detection technique (based, for instance, on a normal behavior model) combined with a more advanced in-depth analysis technique for anomalies detected, such as a technique based on predefined rules and / or signatures characterizing known cyberattacks, a supervised or unsupervised machine learning technique, etc. It should be noted that there are no limitations on the nature of the intrusions that can affect the network: these can include distributed denial-of-service (DDoS) attacks, communication jamming, etc.
[0052] According to this second aspect, the invention proposes a distributed architecture based on the deployment of several intrusion detection modules at different levels of the network (access network, edge network, core network), enabling end-to-end monitoring of each network slice. These detection modules are advantageously configured to exchange information about the intrusions they detect within the network slice, allowing each module to benefit from detections made by the others and also to update their knowledge of these intrusions. This "horizontal" collaboration within the same slice, in the upstream direction (from the access network to the core network) and / or downstream direction (from the core network to the access network), improves the accuracy and speed of detections performed by the detection modules.
[0053] Each detection module, regardless of the network segment at which it is deployed, can be configured to automatically perform a number of predetermined logical actions, namely monitoring the network segment on which it is deployed, of course, but also in-depth traffic analysis when an intrusion is suspected, notifying other detection modules to signal the detection of an intrusion, aggregating and / or correlating information received from other detection modules, triggering mitigation actions, etc.These actions are configurable at the level of each detection module and can vary depending on the segment on which the module in question is deployed (depending on whether it is a first, second or third module within the meaning of the invention), but also depending on other factors, such as the network slice on which it is deployed and its sensitivity in terms of security, etc.
[0054] According to the invention in its second aspect, such an action is performed by a detection module when the latter determines that the probability of executing this action is greater than a given threshold. This probability can be evaluated, for example, periodically by the detection module, or due to a particular event detected by the detection module.
[0055] The threshold associated with an action can be determined by experts, be static or dynamic, vary depending on the actions, etc. Taking such a threshold into account makes it possible to save network resources and those of each detection module, to improve network performance (for example in terms of Quality of Service (QoS), latency and / or overhead) and to limit the complexity of the monitoring system proposed by the invention: the aforementioned actions are only carried out by the detection module when they are deemed necessary with regard to the thresholds set for these actions.Thus, although the invention relies on the deployment of several detection modules on different segments of each network slice to ensure effective monitoring of that network slice, the complexity resulting from this distributed deployment and the planned exchanges between the detection modules is compensated by limiting the actions performed by the latter in the context of this monitoring (particularly when no attack is in progress), and by triggering the execution of these actions only when they are deemed useful and necessary to ensure the security of the network.
[0056] The invention therefore offers a compromise between security and quality of service, and provides a high-performance and resource-efficient solution for securing a network implementing a slicing technique.
[0057] In a particular embodiment, the threshold triggering the execution of an action is determined dynamically for and by said detection module by means of a machine learning algorithm.
[0058] For example, it can be determined based on at least one of the following parameters: a number of false detections of said detection module (the notion of false detection can for example be assessed in relation to a validation of detected intrusions carried out at the core network level, for example by a third module within the meaning of the invention, or by a trusted entity such as a security operations center (or SOC for Security Operation Center)); a number of intrusions detected by said detection module; at least one type of intrusion detected by said detection module; at least one type of elements monitored by said detection module.
[0059] This list of parameters is not exhaustive, however, and other parameters could be taken into account to dynamically determine the threshold.
[0060] Such dynamic threshold adjustment makes it possible to advantageously account for the changing environment of cyber intrusions (attacks), in which the characteristics of intrusions can evolve rapidly or new intrusions can appear, as well as for network slices (changes in the resources allocated to the network slice, etc.). In such a changing environment, the inventor has found that a dynamically set threshold makes it possible to ensure network security more effectively. This particular embodiment of the monitoring system according to the invention is therefore particularly well-suited for a dynamic network such as a 5G network implementing a network slicing technique.
[0061] Furthermore, adapting the threshold according to the aforementioned parameters also improves the performance of the detection module, since it takes into account parameters reflecting this performance (e.g., number of false detections).
[0062] In a particular embodiment, the machine learning algorithm is a Q-learning algorithm.
[0063] A machine learning algorithm is particularly effective at tracking changes in the environment where the detection module is deployed. As is well known to those skilled in the art, the Q-learning algorithm has the advantage of requiring no prior knowledge of the environment in which it is used. Other machine learning algorithms, such as a Support Vector Machine (SVM), can be considered as alternatives.
[0064] Note that the machine learning algorithm can be applied to each threshold individually, or, when the detection module is configured to perform multiple actions, each conditioned by a threshold, the thresholds can be determined jointly using the machine learning algorithm. This allows for the simultaneous consideration of various network constraints, not only in terms of security but also quality of service and complexity (latency, overhead, etc.).
[0065] In a particular embodiment, the Q-learning algorithm is a recursive algorithm comprising, at each iteration, an evaluation of a utility function and a reward function, said utility function reflecting an effect of an update of said threshold at a previous iteration on a detection performance of said detection module, a value of said reward function being increased at said iteration if a value of said utility function for said iteration is greater than a value of said utility function at a previous iteration and / or if an update of said threshold allows said detection module to detect a new type of intrusion, and decreased otherwise.
[0066] This embodiment allows the threshold to be updated to improve the accuracy of the detection performed by the detection module.
[0067] In a particular embodiment, the plurality of detection modules associated with said slice comprises a plurality of third modules associated respectively with active network functions distinct from the core network.
[0068] In this embodiment, a detection module is advantageously deployed at the level of multiple network functions provided by the core network and activated for the considered bandwidth segment (for example, one detection module per active network function). Indeed, at any given time and for a given service, not all network functions present at the core network level are necessarily activated. This embodiment makes it possible to effectively protect these active network functions, and in particular the most critical functions for a given bandwidth segment, such as, for example, in the context of a 5G network, the AMF, UPF, and PCF functions mentioned previously.
[0069] Alternatively, a single intrusion detection module could be configured to simultaneously monitor several active network functions.
[0070] Regarding the first and second modules, one could, for example, consider an intrusion detection module deployed at the access network level (capable of monitoring the various entities on or connected to this access network), and an intrusion detection module deployed at the edge network level (capable of monitoring the various entities on this edge network). Of course, a configuration with more first and second modules is also possible.
[0071] Furthermore, it should be noted that a single detection module, regardless of the network segment at which it is deployed, can be used to monitor multiple network segments simultaneously. In other words, the invention implements collaboration between detection modules on a horizontal plane.
[0072] According to the invention, the detection modules deployed to monitor the same network slice are configured to exchange information with each other about the intrusions they have detected and which affect the elements they are monitoring.
[0073] In a particular embodiment, said first module is configured to, upon detection of an intrusion, report said detected intrusion to said second module and / or to said first module associated with another slice using said access network.
[0074] In addition to horizontal collaboration, this implementation also allows for vertical collaboration, meaning collaboration between detection modules deployed on different network segments but using the same access network. This enables other network segments using the same physical infrastructure to benefit from information about intrusions detected on that infrastructure, such as the characteristics of these intrusions (also called "features") and their signatures (or "patterns"). This improves the detection accuracy and responsiveness of the detection modules to an attack deployed on the access network, and, where applicable, the effectiveness of the mitigation actions implemented in response to that attack.
[0075] This improves network security, and benefits the various segments of the network using the access network in question.
[0076] In a particular embodiment, the second module is configured to, upon detection of an intrusion, report said detected intrusion to at least a third module and / or trigger a mitigation action at the level of the access network and / or the perimeter network.
[0077] Information about detected intrusions is thus sent back to the core network, which allows the core network to have global visibility on intrusions targeting elements of the network slice.
[0078] In addition, a mitigation action can be triggered quickly as close as possible to the elements targeted by the intrusion (i.e. at the level of the access network and / or the perimeter network), and to fight the intrusion more effectively.
[0079] In a particular embodiment, the third module is configured to report said intrusion detected to said first and / or second detection modules, and / or trigger a mitigation action in the network.
[0080] This allows the first and second detection modules to benefit from the more advanced knowledge of the third module (because it is located in the core network and benefits from a more global view of the network, supported by the feedback from the different detection modules deployed in the access network and in the edge network) of intrusions affecting the network.
[0081] In a particular embodiment, each of said detection modules is configured to provide information representative of a local confidence level assigned to said slice based on the behavior of at least one element it monitors, a third module being further configured to evaluate, from said information provided, an overall confidence level for said slice and to trigger an intrusion mitigation action for said slice based on a value of this overall confidence level.
[0082] This embodiment implements a collaboration of these detection modules to estimate an overall confidence index for each network slice, the value of this overall confidence index being taken into account to trigger, if necessary, an intrusion mitigation action at the level of said slice.
[0083] Such an action might be, for example, if the overall confidence level falls below a given threshold, isolating that segment of the network and / or removing at least one element of the access network, the edge network, and / or the core network identified as targeted by an intrusion. Of course, these examples of mitigation actions are only illustrative, and other mitigation actions may be considered, depending in particular on the nature of the detected intrusion, the confidence level, the severity of the intrusion, the anomaly information reported by the various intrusion detection modules, the element(s) targeted by the intrusion, etc.
[0084] By operating in a distributed manner at different levels of the network infrastructure supporting each network slice, and thanks to the proposed collaboration between the various detection modules, the invention makes it possible to limit the false detection rate (false negatives and / or false positives) for each detection module and to improve the overall security of the network slices compared to the prior art. The security of each slice is indeed ensured end-to-end, from the user terminal to the core network: the invention does not simply secure the access network or the core network, but monitors every part of the network for each slice considered. This results in enhanced security for the different network slices.
[0085] Furthermore, assessing an overall confidence index for the network segment allows us to determine how the segment is affected by any detected intrusion(s) and to trigger an appropriate response. This overall confidence index is advantageously calculated in the most secure part of the network, namely the network core, using information collected distributedly across different network segments. This results in a robust and reliable confidence index.
[0086] According to the invention, the overall index evaluated for a slice is calculated from the local indices reported by the first, second, and third detection modules. In a particular embodiment, the overall confidence level for a slice is, for example, an average of the local confidence levels provided by said plurality of detection modules.
[0087] Local confidence levels are assessed by the detection modules distributed throughout the network on each considered slice, based on the anomalies they observe. Several methods can be used to evaluate such a local confidence level.
[0088] For example, in a particular embodiment, at least one local confidence level is evaluated by a said detection module for a said slice as a ratio between a subtraction of a number of normal behaviors of said at least one element monitored by this detection module and a number of intrusions affecting said at least one element monitored by this detection module detected over a given period of time, by a sum of said numbers.
[0089] Such a local confidence level is easily assessed by the detection module in question, based on the monitoring it performs at the level where it is deployed. However, other ways of assessing a local confidence level for the slice can be considered. For example, the local confidence index can be calculated from a weighted sum of the two aforementioned numbers, or only one of them...
[0090] In the embodiment in which a plurality of third modules are deployed at various active network functions of the core network for said slice, the third module configured to evaluate the overall confidence level of a slice can be selected from among these third modules, for example, based on its proximity to the edge network(s) and access network(s) operated by said slice.
[0091] In this way, the risk of attacks is limited during the transfer of information between the modules located at the access network(s) and the edge network(s) and this third module. Such a module, in the example of a 5G network, is, for instance, an intrusion detection module embedded in an AMF or PCF function of the core network.
[0092] The invention also relates to a communications network, configured to implement a slice-out, said communications network comprising a monitoring system according to the invention to monitor at least one slice of said network.
[0093] The network benefits from the same advantages mentioned above as the surveillance system according to the invention.
[0094] It can also be envisaged, in other embodiments, that the monitoring method, the monitoring system and the network according to the invention have in combination all or part of the aforementioned characteristics. Brève description des dessins
[0095] Other features and advantages of the present invention will become apparent from the description below, with reference to the accompanying drawings, which illustrate an example of an embodiment without being limiting in any way. In the figures: [ Fig. 1 ] there figure 1 , already described, represents a network implementing a network slicing technique; Fig. 2 ] there figure 2 represents, in its environment, a network according to the invention in a particular embodiment; [ Fig. 3 ] THE figures 3A et 3B schematically represent the functional architectures of two intrusion detection modules, SID and C-SID*, used to protect different segments of the network. figure 2 ; Fig. 4 ] there figure 4 illustrates, in flowchart form, the main steps of a surveillance method according to the invention, in a particular embodiment in which it is implemented by network intrusion detection modules. figure 2 . Description de l'invention
[0096] There figure 2 represents a communications network 1 conforming to the invention, in a particular embodiment.
[0097] For example, communication network 1 here is a 5G network using a network slicing technique.
[0098] As is well known, several distinct access networks can be used to access the core of a 5G network. There are no limitations attached here to the number or to the technology(ies) used by these access networks (GSM, UMTS, LTE, WLAN, etc.).
[0099] Furthermore, it is assumed here that network 1 uses an approach known as edge computing. This technology, based here on the MEC standard (for "Multi-access Edge Computing"), consists of moving the analysis, processing, and storage of certain data and / or applications to the edge of the network (in a so-called edge network) rather than performing these tasks in data centers or in a cloud, sometimes located thousands of kilometers from the sources of this data and / or applications.This decentralized processing, performed as close as possible to the data and / or application sources, offers the advantage of optimizing bandwidth requirements, limiting the transmission of large amounts of data and / or applications to data centers or the cloud (and consequently reducing leaks and / or security issues that can result from this transmission), and ensuring smooth and rapid response times. This reduces latency and delays associated with data and / or application processing, and delivers real-time performance, particularly for broadband applications. The result is a better user experience.
[0100] It is therefore clear that the use of such a peripheral network has a privileged interest in the context of 4G and 5G communication networks, and the Internet of Things (or IoT for "Internet of Things"), in which there is exponential growth in traffic and an explosion in the number of objects connected to the network.
[0101] In the example shown on the figure 2 We consider eight network slices (SL1, SL2, ..., SL8), each representing a wireless network and relying on the infrastructure of communications network 1. More specifically, the network slices share access network infrastructures (referred to as RAN in the figure), edge network infrastructures (referred to as MEC in the figure), as well as virtual network functions or groups of virtual network functions of the core network (CN for "Core Network") of communications network 1. Such virtual network functions are, for example, routing, addressing, data flow control, naming, etc. In the example of the figure 2 We are particularly considering the virtual network functions AMF, SMF, UPF and PCF already mentioned previously.
[0102] To secure network 1, and more specifically each network slice SL1,...,SL8 of network 1, the latter comprises, according to the invention, a monitoring system 2 including a plurality of intrusion detection modules deployed at the level of each network slice, and configured to monitor so-called "target" elements associated with that slice. In the embodiment described here, each intrusion (or cyberattack) detection module is a software module, generally referred to as SID (for "Software Intrusion Detection"). No limitations are attached to the nature of the techniques implemented by the SID intrusion detection modules to monitor the target elements attached to them. By intrusions, we mean here computer attacks or "cyberattacks" likely to affect various resources of network 1 (e.g., computing resources, servers, memory resources, etc.).), these attacks may originate from attackers internal or external to network 1. It is noted that the attacks in question may directly target the resources of network 1, or these may be indirect victims of the attacks.
[0103] In a particular embodiment, the detection of such attacks can rely indifferently on the detection of anomalies with regard to a normal behavior previously defined by means of a model (or "pattern"), or on the consideration of rules and / or signatures defining, for known attacks, a certain number of network characteristics symptomatic of these attacks, or on supervised or unsupervised learning algorithms, or on hybrid techniques, etc.
[0104] In the embodiment described here, we consider, as represented on the figure 3A , that each SID module includes: A data collection sub-module 3, configured to collect various predetermined characteristics of the traffic passing through the elements monitored by the SID module; an anomaly detection sub-module 4, configured to detect, from the data collected by the collection sub-module 3, an anomaly in the behavior of the monitored elements, for example, by comparing it to a model of normal behavior for these elements (i.e., in the absence of intrusions). An anomaly consists, for example, of an abnormal number of lost packets, flooding of network 1 with unwanted and repeated data, altered sensitive data, interrupted communication, failure to meet a latency imposed at the level of a network segment, etc.; and a depth analysis sub-module 5, configured to analyze, for example by means of a machine learning algorithm, or a detection algorithm based on known intrusion signatures (reflecting traffic characteristics symptomatic of these intrusions, for example), or a hybrid algorithm, an anomaly detected by the anomaly detection sub-module 4 and determine whether or not this anomaly is related to the presence of an intrusion.
[0105] For each SLi network slice, i=1,...,N using the infrastructure of network 1, N denoting an integer (equal to 8 in the example shown on the figure 2 The invention proposes to deploy a plurality SID(SLi) of intrusion detection modules in a distributed manner within this infrastructure. The detection modules associated with the SLi slice (i.e., deployed to ensure the security of the SLi slice) are denoted in the following description as SIDj(SLi) with j=1,...,K(SLi), K(SLi) denoting an integer that can vary from one SLi network slice to another. For the sake of simplicity, we consider the same number K of detection modules deployed for each slice, in other words, K(SLi)=K for all i=1,...,N.
[0106] The SIDj(SLi) detection modules with j=1,...,K associated with each SLi slice are deployed here at three levels of the network 1 infrastructure to monitor elements belonging to different segments of network 1, namely: at the level of the RAN access network(s) (for example at the level of base stations of the access network(s)) used by the SLi slice: the modules are then generally referenced by R-SID on the figure 2 for "Radio-SID" (or R-SIDj(SLi) for an SLi unit), and responsible for monitoring the various elements involved in radio communications; at the level of the MEC edge network used by the SLi unit: the modules are then generally referenced by E-SID on the figure 2 for "Edge-SID" (or E-SIDj(SLi) for an SLi slice), and responsible here for protecting edge servers from attacks; and at the core network CN level of network 1: the modules are then referenced by C-SID on the figure 2 for "Core-SID" 2 (or C-SIDj(SLi) for an SLi slice), and responsible for protecting the main components of the CN core network and in particular the virtual network functions AMF, SMF, PCF and UPF.
[0107] Note that there is no limitation attached to the nature of the elements monitored on each of the aforementioned network segments (access network, edge network, core network) by the SID detection modules: it can be any resource or set of resources belonging to or deployed on these network segments (e.g. user equipment, servers, network functions, cells, memory, network or computing resources, data, etc.).
[0108] Furthermore, there are no limitations on the type of equipment on which the SID detection modules are deployed (server, data center, base station, etc.). This equipment has the hardware architecture of a computer and includes, in particular, a processor, RAM, ROM, non-volatile memory, and communication means that enable them to support communication between SID detection modules. The ROM of such equipment on which an SID detection module is deployed is an information storage medium on which a computer program readable by the processor is stored, containing instructions for executing the various functions performed by that SID detection module.
[0109] In the embodiment described here, horizontal, upward, and downward collaboration is implemented within each SLi network slice between the SID modules deployed across the three aforementioned levels. More specifically, within each SLi network slice, the R-SID(SLi) modules transmit information to the E-SID(SLi) modules, which in turn transmit information to the C-SID(SLi) modules (horizontal upward or upward collaboration). This information relates, in particular, to intrusions (attacks) and / or anomalies detected by the SID modules, the location of the targets of these intrusions or the elements affected by them, the times of detection of these intrusions, the characteristics (or attributes) of these intrusions, etc.
[0110] Thanks to this horizontal collaboration, the R-SID, E-SID, and C-SID modules are also configured to monitor the information they receive and to leverage this information in their detection efforts. Typically, a C-SID module can, for example, analyze the characteristics of attacks detected by the E-SID modules it receives data from, to verify whether attacks are currently underway against them. The C-SID module's visibility across multiple E-SID modules allows it to precisely detect if some of them are malicious and / or the target of attacks.
[0111] This horizontal "upward" collaboration (from the access network to the core network) can be accompanied by horizontal "downward" collaboration, during which a C-SID module, informed of an intrusion detected by an E-SID or R-SID module, confirms or denies the presence of this intrusion (in other words, validates either positively or negatively the detection performed by the E-SID or R-SID module), and communicates its decision to the E-SID or R-SID module to allow it to improve its detection capabilities and, as detailed later, adapt certain operating parameters. It should be noted that a C-SID module can, in a particular embodiment, request information from a trusted authority such as a Security Operations Center (SOC, not shown in the diagram). figure 2 ), to validate its own detections and transmit the SOC's decisions to the E-SID and R-SID modules that report to it.
[0112] There is no limit to the number of SID modules deployed on each segment of each network slice (access network, edge network, and core network). In the following description, for the sake of simplicity, we assume that, for a given network slice, a single R-SID module is deployed at each access network, a single E-SID module is deployed at each edge network, and that several C-SIDs are deployed at the core network to monitor one or more active network functions distinct from the core network.
[0113] Note that a single SID module can monitor and / or protect one or more network slices simultaneously, and / or one or more elements. Thus, in the example illustrated in the figure 2 : An R-SID module is deployed at each base station (eNodeB) of the four access networks used by network slices SL1-SL2, SL3-SL4, SL5-SL6, and SL7-SL8, respectively. Each deployed R-SID module is configured to monitor a single network slice. For example, the R-SID module monitors the base station on which it is deployed; it can also be configured to monitor, in addition to the eNodeB base station, the various user devices connected to that base station and / or the network nodes communicating with it. An E-SID module is deployed at each of the two edge networks used by slices SL1-SL4 and SL5-SL8, respectively, to simultaneously monitor four network slices. For example, the E-SID module is configured to monitor the various nodes (e.g., servers, storage spaces, etc.).) of the edge network at which it is deployed; and a C-SID module is deployed at the AMF function of the core network and used to simultaneously monitor all eight SL1-SL8 network slices, while other C-SID modules are configured to monitor two or three network slices and multiple network functions simultaneously respectively (i.e., the SMF, PCF, and UPF functions in the example of the . figure 2 ).
[0114] In the embodiment described here, each SID detection module is configured to perform one or more actions during its monitoring. Thus, in addition to the action of monitoring data collected by the sub-module 3 and the action of in-depth analysis by sub-module 5 of anomalies detected during this monitoring, and the action of notification (or transmission of alerts to signal detected intrusions), which are common to each of the SID detection modules, these actions may include, for example, an action of aggregating and / or correlating information received, if applicable, from another SID detection module, an action of mitigating an intrusion (or reacting to an intrusion), etc. This list is provided for illustrative purposes only and is in no way limiting or exhaustive.
[0115] These actions are "logical" actions implemented via software, as described herein. They can be configured and instantiated at the level of each SID detection module by a cybersecurity expert, so that they can be executed automatically by that SID detection module. The choice of action(s) implemented at the level of each SID module may depend on various factors, such as the network segment on which the SID module is deployed, parameters to be optimized, etc.
[0116] In the embodiment described here, the actions chosen for each SID module differ depending on the network segment on which it is deployed. More specifically, R-SID detection modules are configured to perform monitoring and anomaly detection, in-depth analysis of detected anomalies, and notification of detected intrusions, if applicable, to other SID detection modules; E-SID and C-SID detection modules are configured to perform, in addition to the aforementioned actions, aggregation and / or correlation of intrusion information notified to them, if applicable, before transmitting it to another detection module, and intrusion mitigation.
[0117] These different actions are defined as follows: The monitoring and anomaly detection actions consist of collecting (using sub-module 3 of the figure 3A ) various predefined data concerning the traffic passing through the monitored elements and to be determined (using sub-module 4 of the figure 3A ) whether the data collected by the collection sub-module 3 suggests or does not indicate an anomaly; the in-depth analysis action consists of applying (by means of the previously mentioned sub-module 5) the figure 3A ) a machine learning algorithm to analyze in depth the data representing an anomaly and determine whether or not this anomaly is due to an intrusion. As mentioned previously, there are no limitations on the technique applied; it can be, for example, a supervised or unsupervised learning algorithm, a neural network, a support vector machine, etc.; the notification action consists of sending alert(s) when an intrusion has been detected by the SID module, typically to another SID module.Notification can be horizontal, as discussed previously, meaning within the same network slice (for example, an R-SID module notifies an E-SID module associated with the same slice, or an E-SID module notifies a C-SID module associated with the same slice, or a C-SID module notifies both R-SID and E-SID modules associated with the same slice), or vertical, for example, between R-SID modules associated with different network slices using the same access network. This alert can contain various pieces of information about the detected intrusion, such as the number of targets and the targets suspected of the intrusion (e.g., their location), the time the intrusion was detected, the characteristics of the intrusion (i.e., the attributes that led to its detection), and so on.The main purpose of this action is to enable the various SID modules to share information about detected intrusions, ensuring that the E-SID and C-SID modules are aware of intrusions detected on the network slice. This allows for dynamic improvement in the detection accuracy of these modules. The aggregation and / or correlation action involves collecting and aggregating notified alerts and, by correlating these alerts, removing redundant information. During this operation, the SID detection module essentially compresses the information to be transmitted to the other SID detection modules.In this way, the amount of information transmitted to the C-SID modules (and therefore the associated signaling (or overhead)) is limited, and the intrusion detection and mitigation process is accelerated. Intrusion mitigation involves triggering one or more actions to address or eliminate the detected intrusion, or at least render it inoperative on network 1. These actions may depend on the network segment to which the mitigation is applied. For example, at the E-SID module level, it is possible to isolate or exclude from network 1 the elements targeted by the intrusion located on the access or edge network (e.g., user equipment or MEC servers), so that they can no longer be involved in any communication or service offered by network 1.At the C-SID module level, mitigation actions can consist of isolating (i.e., removing or disabling) the network slice targeted by the intrusion, and creating a blacklist referencing the elements targeted by the intrusion located at the access network(s), edge network(s), and / or core network used by the infected slice. The isolation of a network slice can be decided, in particular, by taking into account an overall confidence level estimated for that slice, as detailed later.
[0118] Of course, other actions can be considered at the level of each SID detection module.
[0119] In the embodiment described here, the activation (i.e. execution) at the level of a SID detection module of all or part of the actions that it is able to execute is done automatically, when the SID detection module in question detects, via an activation sub-module 6 (cf. figure 3A ), that the probability of executing these actions is greater than a predetermined (i.e., given) threshold. This mechanism allows for system configuration and conserves the detection module's resources while effectively ensuring the security of the network segment it monitors. It should be noted that in the embodiment described here, each SID detection module is configured to continuously perform monitoring and anomaly detection actions as described above.
[0120] A different threshold can be considered depending on the nature of the action and / or the SID detection module and / or the type of SID detection module (R-SID, E-SID, or C-SID). For example, if pdeep(x), pagregco(x), pnotif(x), and pmitig(x) respectively represent the probabilities of executing a depth analysis action, an aggregation and / or correlation action, a notification action, and a mitigation action at the level of an SID detection module referenced by x (x designating an R-SID, E-SID, or C-SID module), these actions are triggered and executed respectively by the SID detection module if: p deep x > TH deep x p agregco x > TH agregco x p notif x > TH notif x p mitig x > TH mitig x where TH deep (x), TH agregco (x), TH notif (x) and TH mitig (x) respectively denote the thresholds set for each of the actions of depth analysis, aggregation and / or correlation, notification and mitigation.
[0121] It should be noted that different thresholds may apply to the various detection modules deployed to monitor the same network segment. Furthermore, different thresholds can be defined for each network slice considered.
[0122] In the embodiment described here, the probabilities pdeep(x), pagregco(x), pnotif(x), and pmi-tig(x) are calculated periodically by the activation sub-module 6 of the considered SID detection module as follows. Alternatively, they can be calculated upon detection of specific events (e.g., an intrusion detected by a detection module on another network segment, information received from the security operations center, etc.).
[0123] At the level of any SID detection module (R-SID, E-SID, C-SID), the probability p deep(x) is evaluated as the ratio of the number of ND intrusions detected by the SID detection module to the total number NA intrusions detected in the network slice under consideration. The total number of intrusions detected in the network slice corresponds to the intrusions confirmed by the core network (i.e., by a C-SID module) for R-SID and E-SID modules, or by the SOC for C-SID modules. It should be noted that the core network and the SOC, having greater visibility over network 1 and therefore over each network slice, and benefiting from the information reported by the various SID detection modules deployed on the different network segments, have better detection accuracy, so it can be assumed that NA ≥ ND.
[0124] At the level of an E-SID module, or a C-SID module respectively, the probability pagregco(x) is evaluated as the ratio of the number of intrusions detected at the access network level for the network slice considered by the R-SID module(s) and notified to the E-SID module, or at the edge network level(s) by the E-SID module(s) and notified to the C-SID module, to the total number of intrusions detected at the edge network level for the network slice considered by the E-SID module, or at the core network level by the C-SID module. It is again noted that the assumption is made that the E-SID module, or C-SID module, has better detection accuracy than the R-SID module, or E-SID module, respectively, so that the ratios thus calculated are well below or equal to 1.
[0125] At the level of an R-SID detection module, the probability p notif (x) is evaluated here in the same way as the probability p deep (x), i.e. p notif (x)=p deep (x).
[0126] At the level of the E-SID and C-SID modules, the probabilities p notif (x) and p mitig (x) are calculated as the ratio of the probability p desp (x) and the probability p agregco (x).
[0127] Of course, other methods or rules for determining the probabilities pdeep(x), pagregco(x), pnotif(x), and pmitig(x) can be applied. For example, when a neighboring SID detection module (in the sense that it has connectivity with the SID in question), belonging to the same network slice or access network, reports the detection of an intrusion to the SID detection module, it can decide to force the value of the probability pdeep(x) to 1. Other rules can be considered as alternatives. Each threshold against which a probability of triggering a given action is compared can be set statically, for example, by cybersecurity experts. Note that a threshold set to 0 is equivalent to not conditioning the execution of the action in question; that is, it is executed systematically whenever it is relevant (e.g., notification issued as soon as an intrusion is detected, in-depth analysis).These thresholds can be set in such a way as to optimize the resources of network 1 (“overhead” for notifications, computing resources, network load, etc.).
[0128] Alternatively, each threshold can be dynamically determined by and for the relevant SID detection module (for example, by its activation sub-module 6) based on various parameters, including the number of false positives it has made. Other parameters can be considered, such as the number of detected intrusions or cyber attackers, the network elements or segment monitored by the SID detection module, the type of intrusions detected, and so on. This dynamic updating of thresholds allows adaptation to the changing cyber intrusion environment and, in particular, the detection of new intrusions.
[0129] To dynamically update a threshold, the SID detection module can use a machine learning algorithm such as a recursive reinforcement learning algorithm, also commonly known as Q-learning, which is familiar to those skilled in the art. Of course, other algorithms can be used, such as a Support Vector Machine (SVM), etc.
[0130] In the embodiment described here, it is assumed that all thresholds associated with actions performed by a SID detection module are dynamically and jointly updated using the machine learning algorithm. This joint update leverages the impact of horizontal collaboration implemented by the SID detection modules on the detections they perform, and the correlation between the different actions that the SID detection modules are likely to execute.
[0131] For example, if the E-SID module detects numerous anomalies, it must be able to analyze all of them, efficiently aggregate the information it reports to a C-SID module (typically reporting all intrusion information if there are many intrusions, or conversely, spacing out the reports if intrusions are nonexistent or rare at the edge network), react quickly by triggering mitigation actions, and promptly notify the C-SID detection modules to which it reports. In other words, the thresholds associated with the in-depth analysis, notification, mitigation, and aggregation actions should be close to 0.
[0132] This joint update of the thresholds thus makes it possible to obtain a compromise between the accuracy of the detections carried out by the detection modules and the quality of service ensured by the network slice on which they are deployed (overhead, latency, etc.).
[0133] Alternatively, an individual determination of each of the thresholds can be considered.
[0134] More specifically, the initial values of the thresholds TH deep (x), TH agregco (x), TH notif (x) and TH mitig (x) can be set by cybersecurity experts or taken as any value, for example 0.5.
[0135] Then the SID detection module applies the Q-learning algorithm to recursively and jointly update the threshold values. For this purpose, it relies on a "utility" function, denoted U, evaluated at each iteration t of the algorithm and defined by: U t = ND t − NP t + NN t NA t with ND(t) the number of intrusions correctly detected at iteration t by the SID detection module, NP(t) the number of false positives detected by the SID detection module at iteration t (i.e., the number of anomalies perceived as intrusions by the SID detection module when they were actually normal behaviors), NN(t) the number of false negatives detected by the SID detection module at iteration t (i.e., the number of anomalies perceived as normal behaviors by the SID detection module when they were actually intrusions), and NA(t) the total number of intrusions affecting the considered slice of network 1 at iteration t. This number NA(t) can be estimated by the security operations center or by the core network, which have a global view of the network, and provided by the latter to the SID detection module (e.g., regularly).Note that the numbers of false positives and false negatives are determined by taking as a reference the results of the validations mentioned above, carried out on the detections made by the SID detection module (e.g. validation made by the C-SID module for an R-SID or E-SID module, and by the SOC for a C-SID module).
[0136] At each iteration t, if the current values of the thresholds are not all zero, the SID module calculates the utility value U(t) for iteration t and compares it to the utility value calculated at the previous iteration t-1.
[0137] It then updates, based on the result of the comparison, a reward value denoted R(t), initialized to 0. The reward value is incremented here by 1 when U(t) > U(t-1) and decremented by 1 otherwise.
[0138] Then the Q-learning algorithm's neural network is activated to jointly calculate new threshold values TH deep (x), TH agregco (x), TH notif (x) and TH mitig (x) (or only a part of these values depending on the actions performed by the SID module considered) by providing it here as inputs the current threshold values, the number of intrusions detected on the segment monitored by the SID detection module, the elements monitored by it, the type of intrusions detected, and the current reward value R(t) which has just been updated.
[0139] The newly calculated threshold values are provided to and used by the in-depth analysis module 5. If a new type of intrusion is detected with these new threshold values, the SID module again increments the reward value R(t) by 1. Otherwise, it decrements the reward value by 1.
[0140] It should be noted that in the embodiment described here, the value of the reward R(t) can advantageously be incremented twice during an iteration: firstly because the utility function is better than in the previous iteration following the update of the thresholds, and secondly because the update of the thresholds makes it possible to detect intrusions of a new type that could not be detected before.
[0141] The steps of the Q-learning algorithm that have just been described are iterated until the ratio ND(t) / NA(t) converges to 1, as summarized in Table 1 below for a conjugate update of all the thresholds TH deep (x), TH agregco (x), TH no-tir (x) and TH mitig (x) (a person skilled in the art would be able to adapt these steps without difficulty to an update of only a part of these thresholds).
[0142] It is also possible to consider that some thresholds are fixed statically and others dynamically.
[0143] With reference to the figure 4 According to the invention, the monitoring system 2 is configured to evaluate, for each network slice SLi, i=1,..,N, an overall confidence index, by applying the monitoring method according to the invention. figure 4 represents the main steps of such a process as implemented in a particular embodiment by monitoring system 2.
[0144] More specifically, according to the invention, each SIDj(SLi) detection module associated with (or deployed to monitor elements attached to) an SLi network slice comprises, in addition to the previously described sub-modules 3 to 6, an evaluation sub-module 7 (cf. figure 3A ), configured to evaluate, when monitoring the elements attached to the SIDj(SLI) detection module (step E10), a TLlocj(x,SLi) information here between 0 and 1 and representative of a local confidence level assigned to this network slice, x indicating as before whether the SIDj(SLi) detection module considered is an R-SID, E-SID or C-SID module.
[0145] This information measures the confidence of the SIDj(SLi) detection module in the elements it monitors, this confidence being determined based on the behavior of these elements, observed by the SIDj(SLi) detection module (notably via its monitoring sub-module 4). More specifically, in the embodiment described here, the information (or more simply the local confidence level) TLlocj(x,SLi) is evaluated as follows by the evaluation sub-module 7 of the SIDj(SLi) detection module (step E20): TLlocj x SLi = BOK − BNOK / BOK + BNOK where BNOK denotes the number of intrusions detected over a period T of time determined by the SIDj(SLi) detection module affecting the elements it monitors, and BOK denotes the number of "normal" behaviors observed by the SIDj(SLi) detection module on the elements it monitors over period T. The normality or abnormality of a monitored element's behavior can be estimated from predefined criteria or models of normal behavior such as those used by the anomaly detection sub-module 4. Note that the difference BOK-BNOK is assumed here to be positive. If this is not the case, the confidence index value is forced to 0.
[0146] Thus, if the elements monitored by a detection module SIDj(SLi) persist in having behaviors deemed "abnormal" (suggesting the presence of an intrusion), the local confidence index TLlocj(x,SLi) tends towards 0. Conversely, if normal behaviors are observed, the local confidence index TLlocj(x,SLi) tends towards 1. Note that the local confidence index TLlocj(x,SLi) is obtained by considering all the elements monitored by the detection module SIDj(SLi) (in other words, the average of the confidence indices individually associated with each monitored element).
[0147] Of course, other ways of estimating a local confidence index can be considered in the context of the invention, such as a weighted sum of the numbers BOK and BNOK, only one of these two numbers, or any other function of these two numbers, etc.
[0148] As mentioned above, a local trust level is evaluated by each SIDj(SLi) detection module deployed on the SLi network slice: in other words, each R-SIDj(SLi), E-SIDj(SLi), and C-SIDj(SLi) module deployed on the SLi network slice evaluates a local trust index based on the behavior of the elements they respectively monitor. The local trust indices thus evaluated for the SLi network slice are then provided to a C-SID*(SLi) detection module deployed at the core network level (step E30) for the SLi network slice. In the embodiment described here, this provisioning is assumed to be done securely, for example, by encrypting the messages containing the local trust indices; this encryption can be based, in particular, on a robust and lightweight cryptographic protocol such as the one described in the document by J. Ni et al.titled “Efficient, Secure and Privacy-preserving Network Slicing for 5G-enabled IoT Systems,” IEEE Journal on Selected Areas in Communications, vol. 36, issue 3, 2018.
[0149] In the embodiment described here, the C-SID*(SLi) detection module includes, in addition to the previously described sub-modules 3 to 7, a second evaluation sub-module 8 and a mitigation sub-module 9 (cf. figure 3BThe second evaluation sub-module 8 is configured to evaluate an overall confidence index for the SLi network slice, here between 0 and 1, based on representative information of the local confidence indices provided by all the SIDj(SLi) detection modules. More specifically, in the embodiment described here, the overall confidence index TL(SLi) for the SLi network slice is evaluated by sub-module 8 of the C-SID*(SLi) detection module as the average of the local confidence indices provided by all the SIDj(SLi) modules associated with the SLi slice (step E40).
[0150] Alternatively, the overall confidence index can be evaluated using a function other than the average of the local confidence indices, such as a standard deviation of the local confidence indices, a weighted sum with greater weight given to the local confidence indices estimated by the C-SID modules which have a more global view of the network, etc.
[0151] It should be noted that the local confidence indices evaluated by the R-SID modules can be collected by the E-SID modules in conjunction with the R-SID modules, and then provided by the R-SID modules to a C-SID module, which is itself connected to the C-SID module*. Alternatively, direct communication between the R-SID and E-SID modules and the C-SID module* can be considered.
[0152] The C-SID*(SLi) module is one of the C-SID*(SLi) detection modules deployed in the core network and responsible for monitoring one or more network functions enabled for the SLi network slice. In the embodiment described here, the C-SID*(SLi) module is chosen as the C-SID*(SLi) detection module. This module is deployed in the core network as close as possible to the edge network(s) and the access network(s), for example, the C-SID*(SLi) detection module responsible for monitoring the AMF network function (which corresponds to the "first" active core network function requested for access to the service provided by the SLi network slice). Alternatively, it could be the C-SID*(SLi) detection module responsible for monitoring another network function, such as the UPF function. Note that for the calculation of the overall confidence index, the chosen C-SID*(SLi) module also takes into account its own local confidence index.
[0153] Once the overall trust index is evaluated, the C-SID*(SLi) module, using its mitigation sub-module 9, determines whether a mitigation action should be triggered based on the index value (test step E50). To do this, it compares the evaluated overall trust index TL(SLi) with a given threshold, denoted here as THTL(SLi). This threshold can vary from one network slice to another (for example, be higher for network slices requiring increased security), or be the same for all network slices, depend on the services offered on the network slice, etc. It can be set by a cybersecurity expert for each of the network slices considered and can be configurable and evolve over time. For example, this threshold can be set to 0.8.
[0154] Due to the convention used here, if the overall confidence index evaluated TL(SLi) is below the THTL(SLi) threshold defined for this slice (yes answer in test step E50), then the mitigation sub-module 9 triggers an intrusion mitigation action for the SLi network slice (step E60). Different types of mitigation actions can be triggered: for example, the C-SID*(SLi) module can decide to isolate (i.e., remove or disable) the SLi network slice, particularly if the overall confidence index is below a low threshold (e.g., 0).3), or to isolate a network segment on which the SLi network slice relies, or to identify in a blacklist certain elements associated with this network slice considered malicious (the C-SID*(SLi) module can for this purpose rely on the information brought back by the different SID(SLi) modules deployed to monitor the network slice to identify such elements and / or the actions to be taken), so as to block traffic to or from these malicious elements, or to inform the security operations center SOC which can decide on the mitigation actions to be carried out in network 1, etc.It should be noted that the mitigation action triggered may also vary depending on the value of the global confidence index TL(SLi); similarly, the mitigation action may be decided by the C-SID*(SLi) module by analyzing local confidence indices, to determine where this action should be carried out or what action should be undertaken.
[0155] If the overall confidence index evaluated TL(SLi) is higher than the THTL(SLi) threshold (no response in test step E50), no mitigation action is taken (step E70). The C-SID*(SLi) module can inform other SID(SLi) modules associated with the SLi slice, particularly those generating low local confidence indices, and send them information enabling them to update, for example, the attributes used by their detection techniques.
[0156] It should be noted that other approaches can be considered to evaluate the local and global trust indices associated with a network slice. For example, an approach such as that described in the paper by B. Niu et al. entitled "5G Network Slice Security Trust Degree Calculation Model", 3rd IEEE International Conference on Computer and Communications, Chengdu, China, 2017, pp. 1150-1157, can be used as an alternative.
[0157] The invention thus proposes a solution that guarantees end-to-end security for network slices, based on a hybrid calculation technique combining both a distributed calculation of local confidence indices and a centralized calculation of a global confidence index for each network slice. The resulting global index is therefore more robust and allows, where necessary, for mitigation actions tailored to each network slice.
Claims
1. Monitoring system (2) for monitoring at least one slice (SL1, ..., SL8) of a communications network (1) using at least one access network, an edge network and a core network, said system comprising, for each slice, a plurality of intrusion detection modules (R-SID, E-SID, C-SID) configured to monitor elements associated with said slice and comprising at least a first module (R-SID) for detecting intrusions at the access network level, a second module (E-SID) for detecting intrusions at the edge network level, and at least a third module (C-SID) at the core network level, each of said modules being configured to provide a piece of information representative of a local confidence level assigned to said slice according to a behaviour of at least one element that it monitors, a said third module (C-SID*) also being configured to evaluate, from said information provided, a global confidence level for said slice and to trigger an intrusion mitigation action for said slice according to a value of this global confidence level.
2. Monitoring system (2) according to Claim 1, wherein said plurality of detection modules associated with said slice comprises a plurality of third modules (C-SID) associated, respectively, with separate active network functions of the core network.
3. Monitoring system (2) according to Claim 2, wherein said third module (C-SID*) configured to evaluate the global confidence level is selected from among said plurality of third modules on the basis of its proximity to the access network and / or to the edge network.
4. Monitoring system (2) according to any one of Claims 1 to 3, wherein the global confidence level for said slice is a mean of the local confidence levels provided by said plurality of detection modules.
5. Monitoring system (2) according to any one of Claims 1 to 4, wherein at least one local confidence level is evaluated by a said detection module for said slice as a ratio between a subtraction of a number of normal behaviours of said at least one element monitored by this detection module and of a number of intrusions affecting said at least one element monitored by this detection module detected over a given period of time, by a sum of said numbers.
6. Monitoring system (2) according to any one of Claims 1 to 5, wherein said mitigation action comprises, if the value of the global confidence level is below a given threshold, the isolation of said slice of the network and / or the removal of at least one element of the access network, of the edge network and / or of the core network identified as being targeted by an intrusion.
7. Monitoring system (2) according to any one of Claims 1 to 6, wherein said first module is configured so that, on detecting an intrusion, it signals said detected intrusion to said second module and / or to a said first module associated with another slice using said access network.
8. Monitoring system (2) according to any one of Claims 1 to 7, wherein said second module is configured so that, on detecting an intrusion, it signals said detected intrusion to said at least one third module and / or triggers a mitigation action at the level of the access network and / or of the edge network.
9. Monitoring system (2) according to any one of Claims 1 to 8, wherein at least one said detection module is configured to execute at least one action from among a deep analysis action, a notification action, and / or a mitigation action when it detects that a probability of executing this action is above a specified threshold.
10. Monitoring system (2) according to Claim 9, wherein said threshold is determined dynamically for said detection module on the basis of a number of false detections performed by said detection module.
11. Communications network (1) configured to implement network slicing, said communications network comprising a monitoring system according to any one of Claims 1 to 10, configured for monitoring at least one slice of said network.
12. Method for monitoring at least one slice (SL1, ..., SL8) of a communications network (1) using at least an access network, an edge network and a core network, said method comprising: - a step of monitoring (E10) said slice by means of a plurality of intrusion detection modules configured to monitor elements associated with said slice and comprising at least a first module for detecting intrusions at the access network level, a second module for detecting intrusions at the edge network level, and at least a third module at the core network level; - a step of providing (E30), by means of each of said modules (R-SID, E-SID, C-SID), a piece of information representative of a local confidence level assigned to said slice according to a behaviour of at least one element monitored by said module; - a step of evaluating (E40), by means of a said third module, from said information provided, a global confidence level for said slice; and - a step of triggering (E60) an intrusion mitigation action for said slice according to a value of this global confidence level.