Context-based security in mobile networks using APIs and data stores
A system using APIs and data stores to enforce context-based security in mobile networks addresses latency concerns, enabling effective security policy application and enhancing security in mobile networks by using local and cloud-based databases to maintain user-IP mappings.
Patent Information
- Application Number
- JP2025533140
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-01-30
- Filing Date
- 2023-12-18
- Publication Date
- 2026-02-04
AI Technical Summary
Existing mobile networks, particularly 4G/LTE and 5G networks, face challenges in deploying context-based security solutions due to concerns about latency impacts and service outages, preventing the effective application of security policies using firewalls like NGFWs on 3GPP interfaces.
A system that monitors network traffic using APIs and data stores to identify sessions, determines user-to-IP mapping information, and enforces security policies based on this mapping, utilizing local and cloud-based databases to maintain user-IP mapping tables and update them through batch operations via gRPC, enabling context-based security in mobile networks.
Facilitates enhanced context-based security in mobile networks by allowing security functions to be closer to users, promoting security in sensitive environments, and implementing security platforms like Palo Alto Networks' firewalls to enforce policies effectively.
Smart Images

Figure 2026504265000001_ABST
Abstract
Description
[Background technology]
[0001] A firewall generally protects a network from unauthorized access while allowing authorized communications to pass through the firewall. A firewall is typically a device or set of devices, or software running on a device, such as a computer, that provides firewall functionality for network access. For example, a firewall may be integrated into the operating system of a device (e.g., a computer, smartphone, or other type of network-enabled device). A firewall may also be integrated into or run as software on a computer server, gateway, network / routing device (e.g., a network router), or data appliance (e.g., a security appliance or other type of dedicated device).
[0002] Firewalls typically deny or allow network transmissions based on a set of rules. These sets of rules are often called policies. For example, a firewall can filter inbound traffic by applying a set of rules or policies. A firewall can also filter outbound traffic by applying a set of rules or policies. A firewall can also perform basic routing functions. [Brief explanation of the drawings]
[0003] Various embodiments of the present invention are disclosed in the following detailed description and accompanying drawings. [Figure 1A]FIG. 1A is a block diagram of a 5G wireless network architecture having a security platform for applying context-based security in mobile networks using APIs and data stores, according to some embodiments. [Figure 1B] FIG. 1B is a block diagram of an architecture of a 4G / LTE wireless network having a security platform for applying context-based security in mobile networks using APIs and data stores, according to some embodiments. [Figure 1C] FIG. 1C is another block diagram of a 5G wireless network architecture having a security platform for applying context-based security in mobile networks using APIs and data stores, according to some embodiments. [Figure 1D] FIG. 1D is another block diagram of an architecture of a 4G / LTE wireless network having a security platform for applying context-based security in mobile networks using APIs and a data store, according to some embodiments. [Figure 1E] FIG. 1E is yet another block diagram of a 5G wireless network architecture having a security platform for applying context-based security in mobile networks using APIs and data stores, according to some embodiments. [Figure 1F] FIG. 1F is yet another block diagram of an architecture of a 4G / LTE wireless network having a security platform for applying context-based security in mobile networks using APIs and a data store, according to some embodiments. [Figure 2]FIG. 2 illustrates a data storage architecture for a 5G Core, including a Unified Data Repository (UDR) and an Unstructured Data Storage Function (UDSF), according to some embodiments. [Figure 3] FIG. 3 is a functional diagram of hardware components of a network device for applying context-based security in mobile networks using APIs and data stores, according to some embodiments. [Figure 4] FIG. 4 is a functional diagram of logical components of a network device for applying context-based security in a mobile network using APIs and data stores, according to some embodiments. [Figure 5] FIG. 5 is a flow chart of a process for applying context-based security in a mobile network using APIs and data stores, according to some embodiments. [Figure 6] FIG. 6 is another flow diagram of a process for applying context-based security in a mobile network using APIs and data stores, according to some embodiments. [Figure 7] FIG. 7 is another flow diagram of a process for applying context-based security in a mobile network using APIs and a data store, according to some embodiments. DETAILED DESCRIPTION OF THE INVENTION
[0004] The present invention can be implemented in numerous ways, including as a process, an apparatus, a system, a composition of matter, a computer program product embodied on a computer-readable storage medium, and / or a processor, such as instructions stored on a memory and / or a processor configured to execute instructions stored and / or provided by a memory coupled to the processor. These implementations, or any other form the present invention may take, may be referred to herein as techniques. In general, the order of steps in disclosed processes may be varied within the scope of the present invention. Unless otherwise specified, components, such as a processor or memory, described as configured to perform a task may be implemented as general-purpose components temporarily configured to perform the task at a given time, or as specific components manufactured to perform the task. As used herein, the term “processor” refers to one or more devices, circuits, and / or processing cores configured to process data, such as computer program instructions.
[0005] A detailed description of one or more embodiments of the present invention is provided below along with accompanying figures that illustrate the principles of the invention. While the present invention will be described in connection with such embodiments, the present invention is not limited to any embodiment. The scope of the present invention is limited only by the claims, and the present invention encompasses numerous alternatives, modifications, and equivalents. Numerous specific details are set forth in the following description to provide a thorough understanding of the present invention. These details are provided for the purpose of example, and the present invention may be practiced according to the claims without some or all of these specific details. For purposes of clarity, technical material known in the art related to the present invention has not been described in detail so as not to unnecessarily obscure the present invention.
[0006] A firewall generally allows authorized communications to pass through the firewall while protecting a network from unauthorized access. A firewall is typically a device, a set of devices, or software running on a device that provides firewall functionality for network access. For example, a firewall can be integrated into the operating system of a device (e.g., a computer, a smartphone, or other type of network-enabled device). A firewall can also be integrated into or run as a software application on various types of devices or security devices, such as a computer server, a gateway, a network / routing device (e.g., a network router), or a data appliance (e.g., a security appliance or other type of special-purpose device).
[0007] Firewalls typically deny or allow network transmissions based on a set of rules. These sets of rules are often referred to as policies (e.g., network policies or network security policies). For example, a firewall can filter inbound traffic by applying a set of rules or policies to prevent unwanted external traffic from reaching a protected device. A firewall can also filter outbound traffic by applying a set of rules or policies (e.g., allow, block, monitor, notify, log, and / or other actions that may be specified in a firewall / security rule or firewall / security policy, which may be triggered based on various criteria, as described herein). A firewall can also apply antivirus protection, malware detection / prevention, or intrusion protection by applying a set of rules or policies.
[0008] Security devices (e.g., security appliances, security gateways, security services, and / or other security devices) may perform various security operations (e.g., firewalls, anti-malware, intrusion prevention / detection, proxies, and / or other security functions), network functions (e.g., routing, quality of service (QoS), workload balancing of network-related resources, and / or other network functions), and / or other security and / or network-related functions. For example, routing may be performed based on source information (e.g., source IP address and port), destination information (e.g., destination IP address and port), and protocol information.
[0009] Basic packet filtering firewalls filter network communication traffic by inspecting individual packets sent over the network (e.g., stateless packet filtering firewalls, or first-generation firewalls). Stateless packet filtering firewalls typically inspect the individual packets themselves and then apply rules based on the inspected packets (e.g., using a combination of the packet's source and destination address information, protocol information, and port numbers).
[0010] Application firewalls can also perform application-layer filtering (e.g., using an application-layer filtering firewall or a second-generation firewall that functions at the application level of the TCP / IP stack). Application-layer filtering firewalls or application firewalls can generally identify certain applications and protocols (e.g., web browsing using the Hypertext Transfer Protocol (HTTP), Domain Name System (DNS) requests, file transfers using the File Transfer Protocol (FTP), and various other types of applications and other protocols, such as Telnet, DHCP, TCP, UDP, and TFTP (GSS)). For example, an application firewall can block unauthorized protocols that attempt to communicate on standard ports (e.g., unauthorized / out-of-policy protocols that attempt to sneak through by using a non-standard port for that protocol can generally be identified using an application firewall).
[0011] Stateful firewalls can also perform stateful-based packet inspection, where each packet is inspected within the context of a set of packets associated with its network outgoing packet flow (e.g., a stateful firewall or third-generation firewall). This firewall technology is commonly referred to as stateful packet inspection because it keeps a record of all connections passing through the firewall and can determine whether a packet is the start of a new connection, part of an existing connection, or an invalid packet. For example, the state of a connection can itself be one of the criteria that triggers a rule in a policy.
[0012] Advanced or next-generation firewalls can perform stateless and stateful packet filtering and application layer filtering, as described above. Next-generation firewalls can also implement additional firewall technologies. For example, certain newer firewalls, sometimes referred to as advanced or next-generation firewalls, can also identify users and content. In particular, certain next-generation firewalls have expanded the list of applications they can automatically identify to thousands of applications. Examples of such next-generation firewalls are commercially available from Palo Alto Networks (e.g., Palo Alto Networks PA Series Next-Generation Firewalls, Palo Alto Networks VM Series Virtualized Next-Generation Firewalls, and CN Series Containerized Next-Generation Firewalls).
[0013] For example, Palo Alto Networks' next-generation firewalls use a variety of identification technologies to enable enterprises and service providers to identify and control applications, users, and content—not just ports, IP addresses, and packets. These include App-ID for precise application identification. TM (e.g. App ID), User-ID for user identification TM (e.g., User ID) (e.g., user or user group) and Content-ID for real-time content scanning (e.g., controlling web surfing and restricting data and file transfers) TM These identification technologies include security features (e.g., Content ID). These technologies allow enterprises to securely enable applications using business-relevant concepts, instead of following the traditional approach offered by traditional port-blocking firewalls. Also, special-purpose hardware for next-generation firewalls (e.g., implemented as dedicated devices) typically offers higher performance levels for application inspection than software running on general-purpose hardware (e.g., security appliances from Palo Alto Networks, which utilize dedicated, function-specific processing tightly integrated with a single-pass software engine to minimize latency while maximizing network throughput, as in the case of Palo Alto Networks' PA Series Next-Generation Firewalls).
[0014] A Overview of Techniques for Applying Context-Based Security in Mobile Networks Using PI and Data Stores
[0015] Technical and security challenges exist for service provider networks for devices in mobile networks (e.g., 4G / LTE and 5G mobile networks). For example, some 4G / LTE and 5G networks (e.g., including private and public cloud-based 4G / LTE and 5G networks) do not expose 3GPP interfaces between network functions, which prevents the deployment of security solutions (e.g., firewalls such as NGFWs) on these interfaces to apply context-based security to network traffic on such 4G / LTE and 5G networks. Specifically, some mobile service providers are reluctant to deploy such security solutions on 3GPP interfaces due to concerns about potential latency impacts and service outages.
[0016] Thus, what is needed are new and improved security techniques for devices communicating over such service provider network environments (e.g., mobile networks, including various 4G / LTE and 5G mobile networks). Specifically, what is needed are new and improved solutions for monitoring such network traffic and applying context-based security (e.g., security / firewall policies) in mobile networks using APIs and data stores (e.g., databases or other data stores) for devices communicating over service provider networks (including, for example, those using IMSI, IMEI, RAT type, network slice, DNN / APN, location, user-IP, and / or other context-based information to apply context-based security in mobile networks).
[0017] In some embodiments, a system / process / computer program product for applying context-based security in a mobile network using an API and a data store includes monitoring network traffic on the mobile network at a security platform to identify new sessions, determining user-to-IP mapping information associated with the new sessions using the API and the data store, and enforcing a security policy for the new sessions at the security platform based on the user-to-IP mapping information to apply context-based security in the mobile network.
[0018] In some embodiments, a system / process / computer program product for applying context-based security in a mobile network using an API and a data store includes monitoring network traffic on the mobile network at a security platform to identify a new session; determining user-IP mapping information associated with the new session by performing at least one of the following: querying a local user-IP mapping table stored at the security platform using an IP address of packets associated with the new session; and, if the IP address is not stored in the local user-IP mapping table, querying a cloud-based data store using the IP address of packets associated with the new session; and, if the IP address is not stored in the cloud-based data store, sending an API query to another data store containing user context information; and enforcing a security policy on the new session at the security platform based on the user-IP mapping information to apply context-based security in the mobile network.
[0019] Specifically, context-based security can be applied using a security platform within a mobile network, including 4G / LTE and 5G mobile networks, by using APIs and databases. In this example, the mobile network can include a database that stores context information related to subscribers / users, including IMSI, IMEI, RAT type, network slice, DNN / APN, location, user-IP, and / or other context information. The security platform can be deployed, for example, on the SGi interface in a 4G / LTE network and the N6 interface in a 5G network.
[0020] In some embodiments, a data store (e.g., a cloud-based database) maintains a global user-IP mapping table, and the security platform maintains a subset of the user-IP mapping table. For a packet, the security platform uses the packet's IP address to query a local user-IP mapping table stored on the security platform. Corresponding user information is then fetched, and the fetched user information can be used to apply security policies. If the user-IP mapping does not exist in the local user-IP mapping table stored on the security platform, the security platform queries a cloud-based global user-IP mapping database to obtain the user-IP mapping information, as described further below with respect to FIGS. 1A-1B. In one exemplary implementation, user-IP mapping queries using the cloud-based database can be performed using batch operations at periodic intervals using gRPC to facilitate high performance. If the cloud-based global user-IP mapping database does not have the queried user-IP mapping, it sends an API query with the IP information to another database that stores user context information, including, for example, IMSI / SUPI, IMEI / PEI, S-NSSAI, APN / DNN, RAT type, and location within the mobile network. Examples of such databases in 5G include the Unified Data Repository (UDR) and the Unstructured Data Storage Function (UDSF), as described further below with respect to various embodiments.
[0021] In some embodiments, as also described below with respect to FIGS. 1A-1B and 2, a data store (e.g., a cloud-based database) maintains a global user-IP mapping table, and the security platform maintains a subset of the user-IP mapping table. However, in these embodiments, as further described below with respect to FIGS. 1C-1D, entities including the database, network function, and management system trigger APIs based on certain events, such as UE attach and UE detach events. Specifically, the APIs can be used to push user context information, including UE IP and user context information, including, for example, IMSI / SUPI, IMEI / PEI, S-NSSAI, APN / DNN, RAT type, and location information within the mobile network, to the cloud-based database. The cloud-based database pushes new and updated user-IP mappings to the security platform using batch operations at regular intervals using gRPC to achieve high performance. The APIs can also be used to push user-IP mappings to the security platform.
[0022] In some embodiments, the security platform maintains a user-IP mapping table, as also described below with respect to Figures 1A-1B and 2, except in this example, the security platform maintains the complete (not a subset) user-IP mapping table. Thus, in these embodiments, entities including databases, network functions, and management systems trigger APIs based on certain events, such as UE attach and UE detach events, as further described below with respect to Figures 1E-1F. Specifically, the APIs can be used to push user context information to the security platform, including UE IP and user context information, including, for example, IMSI / SUPI, IMEI / PEI, S-NSSAI, APN / DNN, RAT type, and location information within the mobile network.
[0023] For example, the techniques described above may be performed to apply context-based (e.g., subscriber ID-related, device ID-related, network slice-related, etc.) security using customer-provided user-IP mapping over the SGi interface in 4G / LTE networks and over the N6 interface in 5G networks.
[0024] As another example, the techniques described above may be performed to apply context-based (e.g., device ID-related) known and unknown threat identification and prevention over the SGi interface in 4G / LTE networks and over the N6 interface in 5G networks.
[0025] As yet another example, the techniques described above may be performed to apply context-based (e.g., subscriber ID-related) application identification over the SGi interface in a 4G / LTE network and over the N6 interface in a 5G network.
[0026] As yet another example, the techniques described above may be performed to apply context-based (e.g., subscriber ID-related) URL filtering over the SGi interface in a 4G / LTE network and over the N6 interface in a 5G network.
[0027] Thus, service providers and / or businesses can use the disclosed technology and security platform to apply subscriber identity-based security.
[0028] Thus, the disclosed techniques facilitate enhanced context-based security in mobile networks. For example, security functions (e.g., security platforms) may be located closer to users / devices (e.g., UEs) to perform security policy analysis and enforcement. As another example, security functions may be implemented to promote security for select industry verticals. As yet another example, security may be implemented in highly sensitive locations, such as government network environments, military network environments, and power plants or other critical infrastructure network environments.
[0029] Thus, according to some embodiments, a new and improved security solution is disclosed that facilitates applying security (e.g., network-based security) in mobile networks (e.g., 4G / 5G / 6G / later versions of MobileNet) for various interfaces and protocols in a mobile network environment using a security platform for executing the disclosed techniques to apply context-based security in mobile networks using APIs and data stores (e.g., the security platform may be implemented using a firewall (FW) / next-generation firewall (NGFW), a network sensor operating in place of a firewall, or another (virtual) device / component that may enforce security policies using the disclosed techniques, including, for example, Palo Alto Networks' PA Series Next-Generation Firewall, Palo Alto Networks' VM Series Virtualized Next-Generation Firewall, and CN Series Container Next-Generation Firewall, and / or other commercially available virtual-based or container-based firewalls).
[0030] These and other embodiments and examples for applying context-based security in mobile networks using APIs and data stores (including, for example, for applying context-based security in mobile networks using IMSI, IMEI, RAT type, network slice, DNN / APN, location, user IP, and / or other context-based information) are further described below.
[0031] Exemplary System Architecture for Applying Context-Based Security in Mobile Networks Using APIs and Data Stores
[0032] Thus, in some embodiments, the disclosed technology includes providing a security platform (e.g., the security function / platform may be implemented using a firewall (FW) / next-generation firewall (NGFW), a network sensor acting in place of a firewall, or another (virtual) device / component that can implement security policies using the disclosed technology, such as PANOS running on a commercially available virtual / physical NGFW solution from Palo Alto Networks, or another security platform / NFGW, including, for example, Palo Alto Networks' PA Series Next-Generation Firewall, Palo Alto Networks' VM Series Virtualized Next-Generation Firewall, and CN Series Container Next-Generation Firewall, and / or other commercially available virtual-based or container-based firewalls may be similarly implemented and configured to execute the disclosed technology), which may provide various interfaces (e.g., RESTful, FTP, FTP, FTPS ... For example, the 4G / 5G / 6G core network may be configured to provide DPI capabilities (e.g., including stateful inspection) of GTP-U sessions (e.g., GTP-U traffic) via the 4G / 5G / 6G core network (e.g., API, SGi, N6, and / or other interfaces in the 4G / 5G / 6G core network).
[0033] Specifically, as will now be described with respect to various system embodiments, context-based security can be applied using a security platform in mobile networks, including 4G / LTE and 5G mobile networks, by using APIs and databases. In this example, the mobile network can include a database that stores context information related to subscribers / users, including IMSI, IMEI, RAT type, network slice, DNN / APN, location, user-IP, and / or other context information. The security platform can be deployed, for example, on the SGi interface in 4G / LTE networks and the N6 interface in 5G networks.
[0034] A cloud-based data store maintains a global user-IP mapping table, and the security platform maintains a subset of the user-IP mapping table.
[0035] In some embodiments, a data store (e.g., a cloud-based database) maintains a global user-IP mapping table, and the security platform maintains a subset of the user-IP mapping table. For a packet, the security platform uses the packet's IP address to query a local user-IP mapping table stored on the security platform. Corresponding user information is then fetched, and the fetched user information may be used to apply security policies. If a user-IP mapping does not exist in the local user-IP mapping table stored on the security platform, the security platform queries a cloud-based global user-IP mapping database to obtain the user-IP mapping information. In one exemplary implementation, user-IP mapping queries using the cloud-based database may be performed using batch operations at periodic intervals using gRPC to facilitate high performance. If the cloud-based global user-IP mapping database does not have the queried user-IP mapping, it sends the API query along with the IP information to another database that stores user context information, including, for example, IMSI / SUPI, IMEI / PEI, S-NSSAI, APN / DNN, RAT type, and location within the mobile network. Examples of such databases in 5G include a Unified Data Repository (UDR) and an Unstructured Data Storage Function (UDSF) as shown in FIG. 2, as further described below with respect to various embodiments.
[0036] FIG. 1A is a block diagram of a 5G wireless network architecture having a security platform for applying context-based security in mobile networks using APIs and data stores, according to some embodiments. Specifically, FIG. 1A illustrates an exemplary 5G mobile network environment including a security platform 102 for applying subscriber-ID-based security in a mobile network with a user-ID and syslog message network via various interfaces (e.g., SGi and / or other interfaces in a 4G / LTE core network and N6 interface and / or other interfaces in a 5G core network) within a mobile network (e.g., a 4G / LTE or later mobile network). (For example, the security function / platform may be implemented using a firewall (FW) / next-generation firewall (NGFW), a network sensor operating in place of a firewall, or another (virtual) device / component that can implement security policies using the disclosed technology, such as Palo Alto Networks' PA Series Next-Generation Firewall, Palo Alto Networks' VM Series Virtualized Next-Generation Firewall, and CN Series Container Next-Generation Firewall, and / or other commercially available virtual-based or container-based firewalls, and / or other commercially available virtual-based or container-based firewalls may be similarly implemented and configured to execute the disclosed technology.)
[0037] As referred to herein, IMSI is a concept referred to by ITU-T as "International Mobile Subscription Identity." IMSI is a 14 or 15 digit number.
[0038] Also referred to herein, SUPI is a globally unique 5G "Subscription Permanent Identifier" assigned to each subscriber in a 5G system. In accordance with 3GPP TS 23.003 v 16.9.0, the SUPI type may indicate an IMSI, a Network Access Identifier (NAI), a Global Line Identifier (GLI), or a Global Cable Identifier (GCI).
[0039] Also, as referred to herein, the International Mobile Equipment Identifier (IMEI) is defined in 3GPP TS 23.003, available at https: / / portal.3GPP.org / desktopmodules / Specifications / SpecificationDetails.aspx?specificationId=729.
[0040] As shown in FIG. 1A, the 5G mobile network environment may also include 5G New Radio (NR) access, such as that shown at 106, and / or other networks, including, for example, Wi-Fi access and fixed access (not shown), facilitating data communications for subscribers using user equipment (UE), such as smartphones, laptops, computers (which may be at fixed locations), and / or other cellular-enabled computing devices / appliances, such as IoT devices shown at 104A, and / or customer devices shown at 104B, including via a packet data network (PDN) (e.g., the Internet) 120, to access various applications, web services, content hosts, etc., and / or other networks.
[0041] 1A , network traffic communications are monitored using security platform 102. As shown, network traffic communications are monitored / filtered in the 5G network using security platform 102 (e.g., a (virtual) device / appliance that includes a firewall (FW), a network sensor functioning in place of a firewall, or another device / component that can implement security policies using the disclosed techniques) configured to execute the disclosed techniques for applying context-based security over various interfaces in the mobile network (e.g., SGi and / or other interfaces in a 4G / LTE core network and N6 and / or other interfaces in a 5G core network), as also described above and further below.
[0042] In this exemplary implementation, the disclosed techniques for applying context-based security in a mobile network using an API and a data store may be executed using a security platform deployed in a 5G technology-based mobile network, such as that shown in FIG. 1A. Specifically, a cloud-based database 124 maintains a global user-IP mapping table, and the security platform 102 maintains a subset of the user-IP mapping table stored in the security platform. For a packet, the security platform uses the packet's IP address to query the local user-IP mapping table. Corresponding user information is then fetched, and the fetched user information can be used to apply security policies. If a user-IP mapping does not exist in the local user-IP mapping table stored in the security platform, the security platform queries the cloud-based global user-IP mapping database to obtain the user-IP mapping information. In one exemplary implementation, user-IP mapping queries using the cloud-based database may be executed using batch operations at periodic intervals using gRPC to facilitate high performance. If the cloud-based global user-IP mapping database 124 does not have the queried user-IP mapping, it sends the API query with the IP information to another database, shown as 5G database 126, which stores user context information including, for example, IMSI / SUPI, IMEI / PEI, S-NSSAI, APN / DNN, RAT type, and location within the mobile network. Examples of such databases in 5G include a Unified Data Repository (UDR) and an Unstructured Data Storage Function (UDSF), as shown in FIG. 2, as described further below.
[0043] In some embodiments, the security platform is further configured to provide the following DPI capabilities: DPI of IP traffic over the N6 interface: In one exemplary implementation, the security platform is configured to provide DPI capabilities (e.g., including identifying APP ID, user ID, content ID, performing URL filtering, etc.) of IP sessions over the N6 interface between, for example, the UPF 112 and the PDN 120, to apply security to user plane traffic based on policy (e.g., Layer 7 security and / or other security policy enforcement), as described further below.
[0044] Additionally, the security platform 102 may also access cloud security services 122 (e.g., WildFire, a commercially available cloud security service offered by Palo Alto Networks, Inc., that includes automated security analysis of malware samples as well as security expert analysis), such as over the Internet. TM The security platform may also be in network communication with a commercially available cloud-based security service, such as a cloud-based malware analysis service, or a similar solution provided by another vendor. For example, a cloud security service 122 may be used to provide dynamic prevention signatures of malware, DNS, URL, CNC malware, and / or other malware to the security platform, as well as to receive malware samples for further security analysis.
[0045] Figure 2 illustrates a data storage architecture of a 5G Core, including a Unified Data Repository (UDR) and an Unstructured Data Storage Function (UDSF), according to some embodiments. Referring to Figure 2, a Unified Data Manager (UDM) 204, a Policy Control Function (PCF) 206, a Network Publishing Function (NEF) 208, a Network Repository Function (NRF) 210, a Service Communication Proxy (SCP) 212, and a Steering of Roaming Application Function (SOR-AF) 214 are in communication with the Unified Data Repository (UDR) and the Unstructured Data Storage Function (UDSF) 202, as shown in Figure 2. Also, as shown, the UDR can store subscription data, policy data, structured data for publishing, application data, and group ID mapping data.
[0046] In one example implementation, an example API for UDSF, such as the Nudsf_DataRepository API, can be sent to a UDSF network function in a 5G network to look up information in the database. One example search expression in an API query to Nudsf to query IP mapping information for 10.10.121.99 is as follows: {"op":"EQ","tag":"ueIp","value":"10.10.121.99"}
[0047] 1B is a block diagram of a 4G / LTE wireless network architecture having a security platform for applying context-based security in a mobile network using APIs and a data store, according to some embodiments. Specifically, FIG. 1B illustrates an exemplary 4G / LTE mobile network including a security platform 102 for applying subscriber ID-based security in a mobile network with user ID and syslog message networking via various interfaces (e.g., SGi and / or other interfaces in a 4G / LTE core network and N6 and / or other interfaces in a 5G core network) in a mobile network (e.g., a 4G / LTE or later mobile network), as further described below. (For example, security functions may be implemented using a firewall (FW) / next-generation firewall (NGFW), a network sensor operating in place of a firewall, or another (virtual) device / component that can implement security policies using the disclosed techniques, including, for example, Palo Alto Networks' PA Series Next-Generation Firewall, Palo Alto Networks' VM Series Virtualized Next-Generation Firewall, and CN Series Containerized Next-Generation Firewall.)
[0048] 1B, the 4G / LTE mobile network environment may also include evolved Node B (eNB) access as shown at 106 and / or other networks including, for example, Wi-Fi access and fixed access (not shown) to facilitate data communications for subscribers (e.g., using user equipment (UE) such as smartphones, laptops, computers (which may be at fixed locations), and / or other cellular-enabled computing devices / appliances such as IoT devices as shown at 104A, and / or customer devices as shown at 104B), including via a packet data network (PDN) (e.g., the Internet) 120 to access various applications, web services, content hosts, etc., and / or other networks. Each of the above 4G / LTE network access mechanisms is in communication with a mobility management entity (MME) 111 (e.g., a private LTE server) and a serving packet data network gateway (S-PGW) 113. The S-PGW 113 communicates with the PDN (Internet) 120 via an SGi interface, where the security platform 102 is located in line between the S-PGW 113 and the PDN 120. The security platform 102 communicates with the S-PGW 113 (e.g., via the N6 interface as shown) to access the UE IP, IMEI, IMSI, and / or other context information, as described further below.
[0049] 1B , network traffic communications are monitored using security platform 102. As shown, network traffic communications are monitored / filtered within the 4G / LTE network using security platform 102 (e.g., a (virtual) device / appliance, each of which may include a firewall (FW), a network sensor acting in place of a firewall, or another device / component that can implement security policies using the disclosed techniques) configured to perform the disclosed techniques for applying context-based security over various interfaces within the mobile network (e.g., SGi and / or other interfaces within the 4G / LTE core network and N6 and / or other interfaces within the 5G core network), as also described above and further below.
[0050] In this exemplary implementation, the disclosed techniques for applying context-based security in a mobile network using APIs and data stores may be executed using a security platform deployed in a 4G / LTE technology-based mobile network, such as that shown in FIG. 1B. As similarly described above with respect to FIG. 1A, the cloud-based database 124 maintains a global user-IP mapping table, and the security platform 102 maintains a subset of the user-IP mapping table stored in the security platform. For a packet, the security platform uses the packet's IP address to query the local user-IP mapping table. Corresponding user information is then fetched, and the fetched user information can be used to apply security policies. If a user-IP mapping does not exist in the local user-IP mapping table stored in the security platform, the security platform queries the cloud-based global user-IP mapping database to obtain the user-IP mapping information. In one exemplary implementation, user-IP mapping queries using the cloud-based database may be executed using batch operations at periodic intervals using gRPC to facilitate high performance. If the cloud-based global user-IP mapping database 124 does not have the queried user-IP mapping, it sends the API query with the IP information to another database, shown as 4G database 126, which stores user context information including, for example, IMSI / SUPI, IMEI / PEI, S-NSSAI, APN / DNN, RAT type, and location within the mobile network. Examples of such databases in 5G include the Unified Data Repository (UDR) and Unstructured Data Storage Function (UDSF), as shown in FIG. 2 described above.
[0051] In some embodiments, the security platform is further configured to provide the following DPI capabilities: DPI of IP traffic over the SGi interface. In one exemplary implementation, the security platform is configured to provide DPI capabilities (e.g., including identifying APP ID, user ID, content ID, performing URL filtering, etc.) of IP sessions over the SGi interface between, for example, S-PGW 113 and PDN 120, to apply security to user plane traffic based on policy (e.g., Layer 7 security and / or other security policy enforcement), as described further below.
[0052] Additionally, the security platform 102 may also access cloud security services 122 (e.g., WildFire, a commercially available cloud security service offered by Palo Alto Networks, Inc., that includes automated security analysis of malware samples as well as security expert analysis), such as over the Internet. TM The cloud security service 122 may also be in network communication with a commercially available cloud-based security service, such as cloud-based malware analysis, or a similar solution provided by another vendor. For example, the cloud security service 122 may be used to provide dynamic prevention signatures for malware, DNS, URL, CNC malware, and / or other malware to the security platform, as well as to receive malware samples for further security analysis.
[0053] The cloud-based data store maintains a global user-IP mapping table, and the security platform maintains a subset of the user-IP mapping table using an API to push user context information to the cloud-based data store.
[0054] In some embodiments, similar to those described above with respect to FIGS. 1A-1B and 2, a data store (e.g., a cloud-based database) maintains a global user-IP mapping table, and the security platform maintains a subset of the user-IP mapping table. However, in these embodiments, as further described below with respect to FIGS. 1C-1D, entities including the database, network function, and management system trigger APIs based on predetermined events, such as UE attach and UE detach events. Specifically, the APIs can be used to push user context information, including UE IP and user context information, including, for example, IMSI / SUPI, IMEI / PEI, S-NSSAI, APN / DNN, RAT type, and location information in the mobile network, to the cloud-based database. The cloud-based database pushes new and updated user-IP mappings to the security platform using batch operations at regular intervals using gRPC to achieve high performance. The APIs can also be used to push user-IP mappings to the security platform.
[0055] 1C is another block diagram of an architecture of a 5G wireless network having a security platform for applying context-based security in a mobile network using APIs and a data store, according to some embodiments. Referring to FIG. 1C, this architecture is similar to the architecture of a 5G wireless network having a security platform for applying context-based security in a mobile network using APIs and a data store described above with respect to FIG. 1A, except that it includes an entity 128 (which may include, for example, a database, a network function, and a management system) that triggers the API based on predetermined events, such as UE attach and UE detach events. Specifically, the API can be used to push user context information, including UE IP and user context information, including, for example, IMSI / SUPI, IMEI / PEI, S-NSSAI, APN / DNN, RAT type, and location information in the mobile network, to a cloud-based database 124. The cloud-based database pushes new and updated user-IP mappings to the security platform (e.g., periodically / based on an event trigger) using batch operations using gRPC to achieve high performance. The API can also be used to push user-IP mappings to the security platform.
[0056] 1D is another block diagram of an architecture of a 4G / LTE wireless network having a security platform for applying context-based security in a mobile network using APIs and a data store, according to some embodiments. Referring to FIG. 1D , this architecture is similar to the architecture of a 4G / LTE wireless network having a security platform for applying context-based security in a mobile network using APIs and a data store described above with respect to FIG. 1B , except that it includes an entity 128 (which may include, for example, a database, a network function, and a management system) that triggers the API based on predetermined events, such as UE attach and UE detach events. Specifically, the API can be used to push user context information, including UE IP and user context information, including, for example, IMSI / SUPI, IMEI / PEI, S-NSSAI, APN / DNN, RAT type, and location information in the mobile network, to a cloud-based database 124. The cloud-based database pushes new and updated user-IP mappings to the security platform (e.g., periodically / based on an event trigger) using batch operations using gRPC to achieve high performance. The API can also be used to push user-IP mappings to the security platform.
[0057] The security platform maintains a user-IP mapping table using APIs to push user context information to the security platform based on events.
[0058] In some embodiments, the security platform maintains a user-IP mapping table similar to that described above with respect to Figures 1A-1B and 2, except that in this example, the security platform maintains the complete (not a subset) user-IP mapping table. Thus, in these embodiments, entities including databases, network functions, and management systems trigger APIs based on predetermined events, such as UE attach and UE detach events, as further described below with respect to Figures 1E-1F. Specifically, the APIs can be used to push user context information to the security platform, including UE IP and user context information, including, for example, IMSI / SUPI, IMEI / PEI, S-NSSAI, APN / DNN, RAT type, and location information within the mobile network.
[0059] 1D is yet another block diagram of an architecture of a 5G wireless network having a security platform for applying context-based security in a mobile network using APIs and a data store, according to some embodiments. Referring to FIG. 1E, this architecture is similar to the architecture of a 5G wireless network having a security platform for applying context-based security in a mobile network using APIs and a data store described above with respect to FIG. 1A, except that it includes an entity 130 (which may include, for example, a database, a network function, and a management system) that triggers the API based on predetermined events, such as UE attach and UE detach events. Specifically, the API may be used to push user context information to the security platform, including UE IP and user context information, for example, including IMSI / SUPI, IMEI / PEI, S-NSSAI, APN / DNN, RAT type, and location information in the mobile network.
[0060] 1F is yet another block diagram of an architecture of a 4G / LTE wireless network having a security platform for applying context-based security in a mobile network using APIs and a data store, according to some embodiments. Referring to FIG. 1F, this architecture is similar to the architecture of a 4G / LTE wireless network having a security platform for applying context-based security in a mobile network using APIs and a data store described above with respect to FIG. 1B, except that it includes an entity 130 (which may include, for example, a database, a network function, and a management system) that triggers the API based on predetermined events, such as UE attach and UE detach events. Specifically, the API may be used to push user context information to the security platform, including, for example, UE IP and user context information, including IMSI / SUPI, IMEI / PEI, S-NSSAI, APN / DNN, RAT type, and location information in the mobile network.
[0061] Thus, service providers and / or enterprises can use the disclosed technology and security platform to apply context-based security in mobile networks using APIs and data stores (e.g., databases or other data stores).
[0062] Example use cases for applying context-based security in mobile networks using APIs and data stores
[0063] The disclosed techniques for providing enhanced security for mobile / service provider networks using a security platform for security policy enforcement, including applying context-based security using APIs and data stores, may be applied in various additional example use case scenarios to facilitate enhanced security for mobile networks (e.g., 4G / 5G / 6G and later mobile networks), as will now be described with respect to various example use cases.
[0064] As a first exemplary use case, the disclosed techniques for applying context-based security in mobile networks using APIs and data stores can be used to protect enterprise 5G users from threats that exploit open source vulnerabilities. Examples of such open source vulnerabilities include: These vulnerabilities are: (1) CVE-2022-26245 - Open-Falcon Falcon-Plus SQL Injection Vulnerability, (2) CVE-2022-1178 - OpenEMR Stored Cross-Site Scripting Vulnerability, (3) CVE-2021-43829 - Patrowl Manager Unrestricted File Upload Vulnerability, (4) CVE-2022-29036 - Jenkins Credentials Plugin Stored Cross-Site Scripting Vulnerability, (5) CVE-2022-1429 - Pimcore GridHelperService.php SQL Injection Vulnerability, (6) CVE-2020-13937 - Apache Kylin REST API Admin Configuration Information Disclosure Vulnerability, and (7) CVE-2022-24706 - Apache CouchDB Remote Code Execution Vulnerability.
[0065] As a second exemplary use case, the disclosed techniques for applying context-based security in mobile networks using APIs and data stores can be used to provide advanced L7 security control for critical infrastructure devices connected to 4G / LTE and / or 5G networks. Examples of related vulnerabilities include: (1) CVE-2021-33550 - Geutebruck Command Injection Vulnerability (camera devices), (2) CVE-2021-43982 - Delta Industrial Automation CNCSoft Screen Editor Stack Buffer Overflow Vulnerability, (3) CVE-2022-26833 - Open Automation Software OAS Platform Authentication Bypass Vulnerability, and (4) CVE-2022-24315 - Schneider Electric IGSS Out-of-Bounds Read Vulnerability.
[0066] As a third exemplary use case, the disclosed techniques for applying context-based security in mobile networks using APIs and data stores can be used to provide advanced threat prevention services to manufacturing vertical enterprise 4G / LTE and / or 5G customers. Examples of related vulnerabilities include: (1) CVE-2022-26501 - Veeam Backup and Replication Authentication Bypass Vulnerability, (2) CVE-2022-22972 - VMware Workspace Authentication Bypass Vulnerability, and (3) CVE-2022-22960 - VMware Workspace Privilege Escalation Vulnerability. Examples of related spyware include: (1) Daxin Command and Control Traffic, (2) Reevenge RAT Command and Control Traffic, (3) Fragtor Command and Control Traffic, (4) Vundo Command and Control Traffic, and (5) KRBanker Command and Control Traffic.
[0067] As will now be apparent to those skilled in the art, the disclosed techniques for applying context-based security in mobile networks using APIs and data stores can be applied in a variety of additional example use case scenarios to detect / prevent these and other types of attacks to promote enhanced security for various deployments and environments in mobile networks.
[0068] Exemplary Hardware Components of a Network Device for Applying Context-Based Security in Mobile Networks Using APIs and Data Stores
[0069] 3 is a functional diagram of hardware components of a network device for applying context-based security in mobile networks using APIs and data stores, according to some embodiments. The example shown is a representation of physical / hardware components that may be included in network device 300 (e.g., an appliance, gateway, or server that may implement the security platform disclosed herein). Specifically, network device 300 includes a high-performance multi-core CPU 302 and RAM 304. Network device 300 also includes storage 310 (e.g., one or more hard disks or solid-state storage units) that may be used to store policies and other configuration information, as well as signatures. In one embodiment, storage 310 stores predetermined information (e.g., subscriber ID, device ID, and / or network slice ID along with user ID and syslog message related / extracted parameters) extracted from traffic monitored via various interfaces (e.g., SGi, N6, and / or other interfaces) to implement the disclosed security policy enforcement techniques for applying context-based security via various interfaces, including the disclosed techniques for applying subscriber ID-based security, device ID-based security, and / or network slice ID-based security using user ID and syslog messages in a mobile network using a security platform as described herein. Network device 300 may also include one or more optional hardware accelerators. For example, network device 300 may include a crypto engine 306 configured to perform encryption and decryption operations and one or more FPGAs 308 configured to perform signature matching, act as a network processor, and / or perform other tasks.
[0070] Exemplary logical components of a network device for applying context-based security in a mobile network using an API and a data store
[0071] 4 is a functional diagram of logical components of a network device for applying context-based security in mobile networks using APIs and data stores, according to some embodiments. The illustrated example is a representation of logical components that may be included in network device 400 (e.g., a data appliance that implements the disclosed security features / platforms and can perform the disclosed techniques for applying subscriber ID-based security, device ID-based security, and / or network slice ID-based security using user IDs and syslog messages in mobile networks). As shown, network device 400 includes a management plane 402 and a data plane 404. In one embodiment, the management plane is responsible for managing user interactions, such as by configuring policies and providing a user interface for viewing log data. The data plane is responsible for managing data, such as by performing packet processing and session manipulation.
[0072] Assume that a mobile device attempts to access a resource (e.g., a remote website / server, an MEC service, an IoT device, or another resource) using an encrypted session protocol such as SSL. The network processor 406 is configured to monitor packets from the mobile device and provide the packets to the data plane 404 for processing. The flow 408 identifies the packet as part of a new session and creates a new session flow. Subsequent packets are identified as belonging to that session based on the flow lookup. If applicable, SSL decryption is applied by the SSL decryption engine 410 using various techniques as described herein. Otherwise, processing by the SSL decryption engine 410 is omitted. The application identification (APP ID) module 412 is configured to determine what type of traffic a session involves (e.g., IP traffic, such as GTP-U traffic, and / or other network protocols between various monitored interfaces, as similarly described above with respect to FIGS. 1A-1F) and to identify a user associated with the traffic flow (e.g., identifying a user ID and an application ID (APP-ID), as described herein). For example, the APP ID 412 may recognize a GET request in the received data and conclude that the session requires an HTTP decoder 414. As another example, the APP ID 412 may recognize a GTP-U session message carrying encapsulated IP traffic from the UE (e.g., via various interfaces, as similarly described above with respect to FIGS. 1A-1F) and conclude that the session requires a GTP-U decoder (e.g., to extract information exchanged in the GTP-U traffic session via various interfaces, including various parameters, as similarly described above with respect to FIGS. 1A-1F).For each type of protocol, there is a corresponding decoder 414. In one embodiment, application identification is performed by an application identification module (e.g., an APP ID component / engine), and user identification is performed by another component / engine. Based on the determination made by APP ID 412, the packet is sent to the appropriate decoder 414. The decoder 414 is configured to assemble packets (e.g., which may be received out of order) into the correct order, perform tokenization, and extract information (e.g., extract various information exchanged in GTP-U traffic over various interfaces, as also described above and further below). The decoder 414 also performs signature matching to determine what should happen to the packet. The SSL encryption engine 416 performs SSL encryption using various techniques as described herein, and the packet is then forwarded using a forwarding component 418 as shown. Also as shown, a policy 420 is received and stored in the management plane 402. In one embodiment, policy enforcement is applied based on the monitored, decoded, identified, and decoded session traffic flows as described herein with respect to various embodiments (e.g., a policy may include one or more rules, which may be specified using domains and / or host / server names, and the rules may apply one or more signatures or other matching criteria or heuristics, such as enforcement of security policies for subscriber / IP flows on the service provider network and / or other protocol traffic, such as SGi / N6 / other interfaces, as similarly described above with respect to Figures 1A-1F, based on various extracted parameters / information from the monitored GTP-U / IP traffic and / or DPI of the monitored GTP-U / IP).
[0073] 4, an interface (I / F) communicator 422 is also provided for security platform manager communication. In some cases, network communications of other network elements on the service provider network are monitored using network device 400, and data plane 404 supports decoding of such communications (e.g., network device 400, including I / F communicator 422 and decoder 414, may be configured to monitor and / or communicate over reference point interfaces, such as SGi, N6, and / or other interfaces where wired and wireless network traffic flows exist). Thus, network device 400, including I / F communicator 422, may be used to implement the disclosed techniques for applying context-based security in mobile networks using APIs and data stores, as described above and further below.
[0074] Additional example processes for the disclosed techniques for applying context-based security in mobile networks using APIs and data stores will now be described.
[0075] Exemplary Process for Applying Context-Based Security in a Mobile Network Using APIs and Data Stores
[0076] 5 is a flowchart of a process for applying context-based security in a mobile network using APIs and data stores, according to some embodiments. In some embodiments, process 500 as shown in FIG. 5 is performed by security platforms and techniques similar to those described above, including the embodiments described above with respect to FIGS. 1A-4. In one embodiment, process 500 is performed by a data appliance 300 as described above with respect to FIG. 3, a network device 400 as described above with respect to FIG. 4, a virtual appliance (e.g., Palo Alto Networks' VM Series Virtualized Next-Generation Firewall, CN Series Container Next-Generation Firewall, and / or other commercially available virtual-based or container-based firewalls may be similarly implemented and configured to perform the disclosed techniques), an SDN security solution, a cloud security service, and / or a combination or hybrid implementation of the foregoing as described herein.
[0077] At 502, monitoring network traffic on the mobile network is performed at a security platform to identify new sessions. For example, the security platform (e.g., a firewall, a network sensor operating on behalf of a firewall, or another device / component capable of implementing a security policy) may monitor various protocols, such as GTP-U (e.g., via SGi, N6, and / or other interfaces) and / or other protocols, in some cases on the mobile network. And, more specifically, by performing the disclosed techniques, various interfaces, such as the SGi and N6 interfaces, may be monitored, as similarly described above with respect to FIGS. 1A-1B.
[0078] At 504, determining user-IP mapping information associated with the new session is performed. For example, the user-IP mapping information associated with the new session may be performed by performing at least one of the following, as similarly described above with respect to FIGS. 1A-1B and 2: querying a local user-IP mapping table stored in the security platform using the IP address of packets associated with the new session; querying a cloud-based data store using the IP address of packets associated with the new session if the IP address is not stored in the local user-IP mapping table; and sending an API query including user context information to another data store if the IP address is not stored in the cloud-based data store.
[0079] At 506, enforcing a security policy for the new session in the security platform based on the user-IP mapping information is performed to apply context-based security in the mobile network. For example, enforcing the security policy may include allowing or blocking the session.
[0080] 6 is another flowchart of a process for applying context-based security in a mobile network using APIs and a data store, according to some embodiments. In some embodiments, process 600 as shown in FIG. 6 is performed by security platforms and techniques similar to those described above, including the embodiments described above with respect to FIGS. 1A-4. In one embodiment, process 600 is performed by a data appliance 300 as described above with respect to FIG. 3, a network device 400 as described above with respect to FIG. 4, a virtual appliance (e.g., Palo Alto Networks' VM Series Virtualized Next-Generation Firewall, CN Series Container Next-Generation Firewall, and / or other commercially available virtual-based or container-based firewalls may be similarly implemented and configured to perform the disclosed techniques), an SDN security solution, a cloud security service, and / or a combination or hybrid implementation of the foregoing as described herein.
[0081] At 602, monitoring network traffic on the mobile network at a security platform to identify new sessions is performed. For example, the security platform (e.g., a firewall, a network sensor operating on behalf of a firewall, or another device / component capable of implementing a security policy) may monitor various protocols, such as GTP-U (e.g., via SGi, N6, and / or other interfaces) and / or other protocols, on the mobile network in some cases. And, more specifically, by performing the disclosed techniques, various interfaces, such as the SGi and N6 interfaces, may be monitored, as similarly described above with respect to FIGS. 1A-1B and 1C-1D.
[0082] At 604, pushing new and updated user-IP mapping information from an entity to a cloud-based data store based on the event is performed. The entity, which may include, for example, a database, a network function, and a management system, can trigger an API based on events such as UE attach and UE detach events to push context information updates (e.g., user context information including UE IP, IMSI / SUPI, IMEI / PEI, S-NSSAI, APN / DNN, RAT type, and location within the mobile network) to the cloud-based data store, as similarly described above with respect to FIGS. 1C-1D and 2.
[0083] Pushing new and updated user-IP mapping information from the cloud-based data store to the security platform is performed at 606. For example, the cloud-based database can push new and updated user-IP mappings to the security platform using batch operations at periodic intervals using gRPC and / or other APIs, as also described above with respect to FIGS. 1C-1D.
[0084] At 608, determining user-IP mapping information associated with the new session stored in the security platform is performed, for example, the user-IP mapping information associated with the new session is pushed to the security platform's local storage based on an event, as similarly described above with respect to FIGS.
[0085] At 610, enforcing a security policy for the new session in the security platform based on the user-IP mapping information is performed to apply context-based security in the mobile network. For example, enforcing the security policy may include allowing or blocking the session.
[0086] 7 is another flowchart of a process for applying context-based security in a mobile network using APIs and a data store, according to some embodiments. In some embodiments, process 700 as shown in FIG. 7 is performed by security platforms and techniques similar to those described above, including the embodiments described above with respect to FIGS. 1A-4. In one embodiment, process 700 is performed by a data appliance 300 as described above with respect to FIG. 3, a network device 400 as described above with respect to FIG. 4, a virtual appliance (e.g., Palo Alto Networks' VM Series Virtualized Next-Generation Firewall, CN Series Container Next-Generation Firewall, and / or other commercially available virtual-based or container-based firewalls may be similarly implemented and configured to perform the disclosed techniques), an SDN security solution, a cloud security service, and / or a combination or hybrid implementation of the foregoing as described herein.
[0087] At 702, monitoring network traffic on the mobile network at a security platform to identify new sessions is performed. For example, the security platform (e.g., a firewall, a network sensor operating on behalf of a firewall, or another device / component capable of implementing a security policy) may monitor various protocols, such as GTP-U (e.g., via SGi, N6, and / or other interfaces) and / or other protocols, on the mobile network in some cases. And, more specifically, by performing the disclosed techniques, various interfaces, such as the SGi and N6 interfaces, may be monitored, as similarly described above with respect to FIGS. 1A-1B and 1E-1F.
[0088] At 704, pushing new and updated user-IP mapping information from an entity to the security platform based on the event is performed. For example, the entity, which may include a database, a network function, and a management system, can trigger an API based on events such as a UE attach event and a UE detach event to push context information updates (e.g., user context information including UE IP, IMSI / SUPI, IMEI / PEI, S-NSSAI, APN / DNN, RAT type, and location within the mobile network) to the security platform, as also described above with respect to FIGS. 1E-1F and 2.
[0089] Determining user-IP mapping information associated with the new session stored in the security platform is performed at 706. For example, the user-IP mapping information associated with the new session may be pushed to the security platform's local storage based on an event, as similarly described above with respect to FIGS.
[0090] At 708, enforcing a security policy for the new session in the security platform based on the user-IP mapping information is performed to apply context-based security in the mobile network. For example, enforcing the security policy may include allowing or blocking the session.
[0091] Although the foregoing embodiments have been described in some detail for purposes of clarity of understanding, the invention is not limited to the details provided. There are many alternative ways of implementing the invention. The disclosed embodiments are illustrative and not limiting.
Claims
1. 1. A system including a processor and a memory, The processor: monitoring network traffic on the mobile network at a security platform to identify new sessions; determining user-to-IP mapping information associated with the new session by performing at least one of the following: querying a local user-to-IP mapping table maintained at the security platform using the IP address of the packet associated with the new session; querying a cloud-based data store using the IP address of the packet associated with the new session if the IP address is not stored in the local user-IP mapping table; and If the IP address is not stored in the cloud-based data store, sending an API query to another data store containing user context information, and enforcing a security policy for the new session in the security platform based on the user-IP mapping information to apply context-based security in the mobile network; It is structured as follows: The memory includes: a processor coupled to the processor and configured to provide instructions to the processor; system.
2. the context-based security includes subscriber identity-based security; The system of claim 1 .
3. The context-based security includes device ID-based security. The system of claim 1 .
4. The context-based security includes network slice ID-based security. The system of claim 1 .
5. The security platform is configured with a plurality of security policies to apply subscriber ID-based security, device ID-based security, and / or network slice ID-based security in the mobile network. The system of claim 1 .
6. The processor further comprises: performing level threat identification and prevention in the mobile network; The system of claim 1 , configured to:
7. The processor further comprises: performing application identification and control in the mobile network; The system of claim 1 , configured to:
8. The processor further comprises: performing URL filtering in the mobile network; The system of claim 1 , configured to:
9. The processor further comprises: blocking the new session from accessing resources based on the security policy; The system of claim 1 , configured to:
10. The processor further comprises: permitting the new session to access resources based on the security policy; The system of claim 1 , configured to:
11. 1. A method comprising: monitoring network traffic on the mobile network at a security platform to identify new sessions; determining user-to-IP mapping information associated with the new session; querying a local user-to-IP mapping table maintained at the security platform using the IP address of the packet associated with the new session; querying a cloud-based data store using the IP address of the packet associated with the new session if the IP address is not stored in the local user-IP mapping table; and If the IP address is not stored in the cloud-based data store, sending an API query to another data store containing user context information, and enforcing a security policy for the new session in the security platform based on the user-IP mapping information to apply context-based security in the mobile network; determining by performing at least one of: A method comprising:
12. the context-based security includes subscriber identity-based security; The method of claim 11.
13. The context-based security includes device ID-based security. The method of claim 11.
14. The context-based security includes network slice ID-based security. The method of claim 11.
15. The method further comprises: blocking the new session from accessing a resource based on the security policy; The method of claim 11 , comprising:
16. 1. A computer program comprising a plurality of computer instructions, The computer program is stored in a non-transitory computer-readable storage medium, and when the instructions are executed by a processor, monitoring network traffic on the mobile network at a security platform to identify new sessions; determining user-to-IP mapping information associated with the new session; querying a local user-to-IP mapping table maintained at the security platform using the IP address of the packet associated with the new session; querying a cloud-based data store using the IP address of the packet associated with the new session if the IP address is not stored in the local user-IP mapping table; and If the IP address is not stored in the cloud-based data store, sending an API query to another data store containing user context information, and enforcing a security policy for the new session in the security platform based on the user-IP mapping information to apply context-based security in the mobile network; determining by performing at least one of: A computer program that implements the above.
17. the context-based security includes subscriber identity-based security; 17. A computer program according to claim 16.
18. The context-based security includes device ID-based security.
17. A computer program according to claim 16.
19. The context-based security includes network slice ID-based security.
17. A computer program according to claim 16.
20. The computer program further comprises: blocking the new session from accessing a resource based on the security policy.
17. A computer program according to claim 16.
21. 1. A system including a processor and a memory, The processor: monitoring network traffic on the mobile network at a security platform to identify new sessions; Pushing new and updated user-to-IP mapping information from a cloud-based data store to the security platform; determining user-to-IP mapping information associated with the new session stored in the security platform; and implementing a security policy for the new session in the security platform based on the user-IP mapping information to apply context-based security in the mobile network; It is structured as follows: The memory includes: a processor coupled to the processor and configured to provide instructions to the processor; system.
Citation Information
Patent Citations
Multi-access distributed edge security in mobile networks
JP2021513299A
Network Slice-Based Security in Mobile Networks
JP2022502913A
Service-based security per data network name in mobile networks
US10462653B1
Security platform for service provider network environments
US10601776B1
Mobile user identity and / or SIM-based IoT identity and application identity based security enforcement in service provider networks
US20180367571A1
Cited By
Self-ordering order management system, control method, and program with access scope control function.
JP7905632B1