Controlling defensive agents in communication networks

A security controller in communication networks balances accuracy and resource consumption of distributed defense agents, addressing implementation challenges and malicious threats to ensure robust Zero Trust Architecture security.

JP2026506302APending Publication Date: 2026-02-24TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
JP2025537998
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-01-09
Publication Date
2026-02-24

AI Technical Summary

Technical Problem

Practical implementation of Zero Trust Architecture (ZTA) using distributed defense agents in communication networks is challenging due to the need to balance anomaly detection accuracy with resource consumption, and there is a risk of malicious defense agents compromising network security.

Method used

A security controller manages a set of distributed defense agents by balancing anomaly detection accuracy and resource consumption, identifying and isolating malicious agents, and controlling their operations to maintain network security.

Benefits of technology

The solution effectively manages resource usage while maintaining high anomaly detection accuracy and protects the network from malicious agents, ensuring robust security in line with Zero Trust Architecture principles.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026506302000001_ABST
    Figure 2026506302000001_ABST
Patent Text Reader

Abstract

According to certain embodiments, a security controller (18) is deployed for a communication network (10), in which a set of multiple defense agents (14) are distributed for anomaly detection in the communication network (10). The security controller (18) obtains one or more accuracy metrics (20) that characterize how accurately the set (14S) of multiple defense agents (14) detects anomalies in the communication network (10). The security controller (18) also obtains one or more resource consumption metrics (22) that characterize how much the set (14S) of multiple defense agents (14) consumes resources in the communication network (10). The security controller (18) controls the set (14S) of multiple defense agents (14) based on the one or more accuracy metrics (20) and the one or more resource consumption metrics (22).
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] TECHNICAL FIELD This application relates generally to communication networks, and more particularly to controlling defensive agents in such networks. [Background technology]

[0002] Traditional security measures for communication networks protect communication networks from unauthorized access and allow unrestricted access to network resources after initial authentication. This is based on the assumption that authenticated network entities can be trusted. In contrast, Zero Trust Architecture (ZTA) assumes that network entities cannot be trusted even after initial authentication. Therefore, ZTA individually authenticates each request for access to network resources, rather than unconditionally allowing the request simply because it comes from a previously authenticated network entity.

[0003] Some ZTA approaches deploy distributed agents within a communications network to defend it. For example, see the ZTA approach described in "Intelligent Zero Trust Architecture for 5G / 6G Tactical Networks: Principles, Challenges, and the Role of Machine Learning" by K. Ramezanpour et al., arXiv, 2021. Such distributed defense agents monitor different network entities for anomalies and determine whether the detected anomalies correspond to malicious activity. However, practical implementation of ZTA using distributed defense agents remains challenging. Summary of the Invention

[0004] In one embodiment of the present disclosure, a set of multiple defense agents for anomaly detection is distributed within a communications network, and the defense agents are controlled by practically considering (e.g., balancing) both anomaly detection accuracy and resource consumption. In some embodiments in this regard, a security controller controls whether and / or how each defense agent in the set performs one or more anomaly detection tasks based on metrics characterizing the defense agent's accuracy and resource consumption. For example, if multiple defense agents in the set consume excessive resources, the security controller controls the least accurate defense agent or agents to stop performing anomaly detection tasks, thereby reducing resource load without reducing accuracy as much as possible. In another example, the security controller allows defense agents to cooperate with each other to improve anomaly detection accuracy, but prohibits cooperation if the defense agents consume excessive resources. In these and other examples, the security controller takes into account the reality that network resource availability imposes practical constraints on distributed anomaly detection while appropriately protecting anomaly detection accuracy, such as is necessary to realize a zero trust architecture (ZTA). Part of the present embodiment provides anomaly detection that is robust to changing conditions that affect resource availability and achievable accuracy.

[0005] In other embodiments, the distributed defense agents themselves are inspected for maliciousness. The security controller determines that a defense agent is malicious if the defense agent exhibits abnormal resource consumption and / or anomaly detection accuracy. In this case, the security controller controls the malicious anomaly detector to not perform anomaly detection or isolates the malicious anomaly detector. In these and other embodiments, the security controller protects the communication network against malicious defense agents in accordance with a zero trust architecture (ZTA) rather than simply assuming that the defense agents are trustworthy.

[0006] More specifically, this embodiment includes, according to a particular embodiment, a method performed by a security controller for a communications network having a set of defense agents distributed across the communications network for detecting anomalies in the communications network. The method includes obtaining one or more accuracy metrics that characterize how accurately the set of defense agents detects anomalies in the communications network. The method also includes obtaining one or more resource consumption metrics that characterize how much the set of defense agents consumes resources in the communications network. The method further includes controlling the set of defense agents based on the one or more accuracy metrics and the one or more resource consumption metrics.

[0007] In some embodiments, the one or more accuracy metrics include a set-wide false positive rate comprising the rate at which the set of the plurality of defense agents incorrectly detects an anomaly, a set-wide false negative rate comprising the rate at which the set of the plurality of defense agents fails to detect an anomaly, and / or a set-wide false rate comprising a combination of the set-wide false positive rate and the set-wide false negative rate. Alternatively or additionally, the one or more accuracy metrics include, for each of the set of the plurality of defense agents, an agent-specific false positive rate comprising the rate at which the defense agent incorrectly detects an anomaly, an agent-specific false negative rate comprising the rate at which the defense agent fails to detect an anomaly, and / or an agent-specific false rate comprising a combination of the agent-specific false positive rate and the agent-specific false negative rate.

[0008] In some embodiments, controlling the set of the plurality of defensive agents includes controlling whether and / or how each defensive agent in the set performs each of one or more anomaly detection tasks based on the one or more accuracy metrics and the one or more resource consumption metrics.

[0009] In some embodiments, controlling the set of the plurality of defense agents includes, for each of one or more anomaly detection tasks, controlling which one or more defense agents of the set of the plurality of defense agents perform the anomaly detection task, and which one or more defense agents, if any, of the set of the plurality of defense agents do not perform the anomaly detection task, based on the one or more accuracy metrics and the one or more resource consumption metrics.

[0010] For example, in one embodiment, controlling the plurality of defense agents includes making a decision, for at least one of the one or more anomaly detection tasks, based on a comparison of a set-wide resource consumption metric and a set-wide resource consumption threshold for the anomaly detection task, to switch the set from an accuracy-enhancing mode, in which all defense agents in the set perform the anomaly detection task, to a resource-conserving mode, in which at least one defense agent in the set does not perform the anomaly detection task. Controlling the plurality of defense agents includes determining, based on the decision, which one or more defense agents in the set will continue to perform the anomaly detection task in the resource-conserving mode and which one or more defense agents in the set will not perform the anomaly detection task in the resource-conserving mode, based on an agent-specific accuracy metric for each defense agent.

[0011] In another embodiment, controlling the plurality of defensive agents includes making a decision for at least one of the one or more anomaly detection tasks to switch from a resource conservation mode, in which at least one defensive agent in the set does not perform the anomaly detection task, to an accuracy improvement mode, in which all defensive agents in the set perform the anomaly detection task, based on (i) a comparison of an overall set accuracy metric to an overall set accuracy threshold for the anomaly detection task, or (ii) a comparison of an overall set resource consumption metric to an overall set resource consumption threshold for the anomaly detection task.

[0012] In some embodiments, controlling the plurality of defense agents includes obtaining the set of defense agent utility metrics for defense agents as a function of the one or more accuracy metrics and the one or more resource consumption metrics; obtaining an attack utility metric as a function of the defense agent utility metric and an attack resource consumption metric that reflects a degree of resources required by an attacker to execute a coordinated attack against the communications network; and controlling whether the set of the plurality of defense agents performs one or more anomaly detection tasks based on a comparison of the defense agent utility metric and the attack utility metric.

[0013] In one such embodiment, the defensive agent utility metric is U D =α1 M D +α2·D D -α3·(P D +N D )-α3·C D is determined as M D is the rate at which the set of the plurality of defense agents determines each characteristic of an anomaly, D D is the rate at which the set of defense agents detects anomalies, P D is the false positive rate of the entire set, which includes the rate at which the set of multiple defense agents incorrectly detects anomalies, ND is the false negative rate of the entire set, which includes the rate at which the set of defense agents fails to detect anomalies, and C D is the resource consumption metric for the entire set, M D , D D , P D , N D and C D ∈[0,1], and α1, α2, α3∈[0,1] are weight parameters. In this case, the attack utility metric is U A =-(U D +β·C A ) and C A is the attack resource consumption metric, β is a weight parameter, and β∈[0,1].

[0014] In this case, controlling the plurality of defense agents involves determining the characteristics of each of the anomalies to be detected for a feature monitoring task: (i) α3·C D >α1·M D (ii) switching the set from an accuracy-enhancing mode, in which all defense agents in the set perform the feature monitoring task, to a resource-saving mode, in which at least one defense agent in the set does not perform the feature monitoring task, if D +N D )>α1·M D and if so, switching the set from a resource-saving mode in which at least one defense agent in the set does not perform the feature monitoring task to an accuracy-improving mode in which all defense agents in the set perform the feature monitoring task. Also, controlling includes, for a feature detection task including detecting the determined feature: (i) α3·C D >α2·D D (ii) switching the set from an accuracy-enhancing mode, in which all defense agents in the set perform the feature detection task, to a resource-saving mode, in which at least one defense agent in the set does not perform the feature detection task, if D +N D)>α2·D D If so, switching the set from a resource-saving mode, in which at least one defensive agent in the set does not perform the feature detection task, to an accuracy-improving mode, in which all defensive agents in the set perform the feature detection task. Further, controlling includes, for a decision-making task including making a decision about whether an anomaly exists based on the detected features: (i) α3 · (P D +N D )≦α1·M D +α2·D D (ii) switching the set from an accuracy-enhancing mode, in which all defense agents in the set perform the decision-making task, to a resource-saving mode, in which at least one defense agent in the set does not perform the decision-making task, if D +N D )>α1·M D +α2·D D if so, switching the set from a resource-saving mode, in which at least one defensive agent in the set does not perform the decision-making task, to an accuracy-improving mode, in which all defensive agents in the set perform the decision-making task.

[0015] In some embodiments, the one or more anomaly detection tasks include a feature monitoring task that includes determining features of each anomaly to be detected, a feature detection task that includes detecting the determined features, and / or a decision-making task that includes making a decision as to whether an anomaly exists based on the detected features.

[0016] In some embodiments, controlling the set of the plurality of defense agents alternatively or additionally includes controlling, based on the one or more accuracy metrics and the one or more resource consumption metrics, which one or more defense agents in the set operate in a collaborative mode to perform anomaly detection in cooperation with each other, and controlling which one or more defense agents in the set operate in a solo mode to perform anomaly detection without cooperation with each other.

[0017] In one such embodiment, the one or more accuracy metrics are obtained for each of the collaborative mode and the solo mode. In this case, the controlling includes controlling the set of multiple defense agents to operate in the collaborative mode if each of one or more collaborative mode trigger criteria are met, the one or more collaborative mode trigger criteria including a set-wide accuracy metric for the solo mode exceeding an accuracy threshold for the solo mode, the set-wide accuracy metric being a set-wide false rate metric. And, controlling may include controlling the set of multiple defense agents to operate in the solo mode if each of one or more solo mode trigger criteria are met, the one or more solo mode trigger criteria including a set-wide accuracy metric for the collaborative mode being below an accuracy threshold for the collaborative mode, the set-wide accuracy metric being a set-wide false rate metric. For example, in some embodiments, the accuracy threshold for the solo mode is a function of an anomaly detection rate for the set of the plurality of defense agents while they are operating in the solo mode, and / or the accuracy threshold for the collaborative mode is a function of an anomaly detection rate for the set of the plurality of defense agents while they are operating in the collaborative mode. Alternatively or additionally, the one or more resource consumption metrics are obtained for each of the collaborative mode and the solo mode, wherein the one or more solo mode trigger criteria further include the set of resource consumption metrics obtained for the collaborative mode exceeding a resource consumption threshold for the collaborative mode.

[0018] In some embodiments, the set of overall false rate metrics for the single mode is γ 2 ·(P L +N L ) and γ2 is a weighting parameter, P L is the false positive rate for the entire set for the single mode, N L is the false negative rate of the entire set for the single mode. Also, the false negative rate threshold for the single mode is γ1·D Lγ1 is a weight parameter, D L is the anomaly detection rate for the entire set while operating in the solo mode. Also, the false rate metric for the entire set for the collaborative mode is δ2·(P I +N I ) and δ2 is a weight parameter, P I is the set-wide false positive rate for the collaborative mode, N I is the false negative rate of the entire set for the collaborative mode. Also, the false negative rate threshold for the collaborative mode is δ1·D I δ1 is a weight parameter, D I is the overall set anomaly detection rate while operating in the cooperative mode.

[0019] In some embodiments, the plurality of defense agents includes a plurality of first-tier defense agents and one second-tier defense agent distributed within the communications network, each of the plurality of first-tier defense agents configured to determine characteristics of each anomaly within the communications network, detect the determined characteristics of the anomaly, and make a determination as to whether an anomaly exists based on the detected characteristics, and the second-tier defense agent configured to cooperate with the plurality of first-tier defense agents to assist in collaboratively determining whether an anomaly exists within the communications network.

[0020] In some embodiments, the controlling includes identifying a defense agent in the set as malicious based on the one or more accuracy metrics and the one or more resource consumption metrics, and controlling the identified defense agent to stop anomaly detection.

[0021] The present embodiment also includes corresponding apparatus, computer programs, and carriers for these computer programs. [Brief explanation of the drawings]

[0022] [Figure 1]FIG. 1 is a block diagram of a communication network 10 in accordance with some embodiments. [Figure 2A] FIG. 2A is a block diagram of a security controller that leverages an entire set of accuracy and / or resource consumption metrics in some embodiments. [Figure 2B] FIG. 2B illustrates a block diagram of a security controller that leverages agent-specific accuracy and / or resource consumption metrics in some embodiments. [Figure 3] FIG. 3 illustrates a block diagram of a security controller that identifies and controls malicious defense agents in some embodiments. [Figure 4] FIG. 4 illustrates a block diagram of an improved accuracy mode for a set of defensive agents in some embodiments. [Figure 5] FIG. 5 illustrates a block diagram of a resource conservation mode for a set of defensive agents in some embodiments. [Figure 6A] FIG. 6A illustrates a block diagram of a security controller for operating a set of defensive agents in a resource-conserving mode in some embodiments. [Figure 6B] FIG. 6B illustrates a block diagram of a security controller for operating a set of defensive agents in an accuracy-enhancing mode in some embodiments. [Figure 7] FIG. 7 is a block diagram of a set of defensive agents configured to perform different anomaly detection tasks in some embodiments. [Figure 8A] FIG. 8A is a block diagram of a suite of defensive agents in a refinement mode in another embodiment. [Figure 8B] FIG. 8B is a block diagram of a resource-saving mode for a set of defensive agents in another embodiment. [Figure 9A] FIG. 9A is a block diagram of a security controller controlling a set of defensive agents to operate in a resource-conserving mode in another embodiment. [Figure 9B] FIG. 9B is a block diagram of a security controller controlling a set of defensive agents to operate in an accuracy-enhancing mode in another embodiment. [Figure 10A] FIG. 10A is a block diagram of a set of defensive agents in a standalone mode in another embodiment. [Figure 10B] FIG. 10B is a block diagram of a security controller for operating a set of defensive agents in a cooperative mode in another embodiment. [Figure 11] FIG. 11 is a block diagram of a security controller for operating a set of defensive agents in a cooperative mode or a solo mode in another embodiment. [Figure 12] FIG. 12 illustrates a logic flow diagram of a method for a security controller to operate a set of defensive agents in a cooperative or independent mode in another embodiment. [Figure 13] FIG. 13 illustrates a block diagram of defensive agents arranged hierarchically within a communications network in accordance with some embodiments. [Figure 14] FIG. 14 illustrates a logic flow diagram of a method performed by a security controller in some embodiments. [Figure 15] FIG. 15 is a block diagram of a security controller in some embodiments. [Figure 16] FIG. 16 illustrates an example of a communication system according to some embodiments. [Figure 17] FIG. 17 is a block diagram of a host that may be an example of the host of FIG. 16 in accordance with various aspects described herein. DETAILED DESCRIPTION OF THE INVENTION

[0023] 1 illustrates a communication network 10 (e.g., a 5G+ network) in some embodiments. The communication network 10 provides communication services to one or more communication devices 12 (e.g., user equipment (UE)). The communication network 10 may, for example, provide wireless communication services to one or more communication devices 12.

[0024] The communication network 10 includes a plurality of defense agents 14-1...14-N (hereinafter collectively referred to as defense agents 14). Each defense agent 14-n (1≦n≦N) is an agent configured to defend the communication network 10, e.g., against attacks and other anomalies. A defense agent may be configured, for example, to detect anomalies in the communication network 10 and take appropriate action to protect the communication network 10 from such anomalies. As used herein, "anomaly" refers to a deviation from a standard, normal, or expected state in the communication network 10. Examples of anomalies include attacks on the communication network 10 (e.g., denial-of-service attacks) and the direct or indirect effects of such attacks (e.g., an increase in the rate of rejected access requests due to overload, a decrease in the number of connected devices, a decrease in system throughput, etc.). In such examples, the defense agents 14 are configured to detect the attacks themselves or the direct or indirect effects of such attacks. Generally, the defense agents 14 detect anomalies in the sense of detecting any deviation from a standard, normal, or expected state. For example, determining whether there is a deviation may be based on a machine learning model that reflects a typical, normal, or expected state.

[0025] Defense agents 14 may or may not understand the full meaning of a detected anomaly. For example, in one embodiment, if defense agent 14 detects an anomaly in an access request denial rate that is above the normal range, it may be configured to attribute the anomaly to an attack, but may not be configured to attribute the anomaly to a particular type of attack (e.g., a denial of service attack). Meanwhile, in another embodiment, the defense agent may detect the anomaly in the form of a particular type of attack.

[0026] Regardless of the specific form of anomaly that the defensive agent 14 is configured to detect, the defensive agent 14 detects anomalies at each target 16-1...16-N (hereinafter collectively referred to as targets 16) within the communications network 10. As used herein, a "target 16" refers to a network node or function that an anomaly detector examines for evidence of the presence of anomalies. In one embodiment, a defensive agent 14-n may be co-located with the target 16-n for which it detects anomalies. In this and other embodiments, the placement of the defensive agent 14 may reflect the placement of the target 16 for which it detects anomalies.

[0027] Defensive agents 14 and / or targets 16 may be distributed in one or more dimensions, such as geographic distribution or functional distribution. For example, in some embodiments, at least some of defensive agents 14 and / or targets 16 are located in geographically dispersed locations in communications network 10, e.g., in different parts of the communications network's coverage area. Alternatively, at least some defensive agents 14 and / or targets 16 may be functionally dispersed in communications network 10, e.g., to detect anomalies in different types of network functions or network equipment.

[0028] In some embodiments in this regard, defensive agents 14 are distributed across communications network 10 as part of a zero trust architecture (ZTA). See, for example, the ZTA approach described in K. Ramezanpour et al., "Intelligent Zero Trust Architecture for 5G / 6G Tactical Networks: Principles, Challenges, and the Role of Machine Learning," arXiv, 2021. In these and other embodiments, defensive agents 14 monitor and detect anomalies in communications network 10, assuming that targets 16 cannot be trusted even after initial authentication.

[0029] 1 are shown as elements of a set 14S of defensive agents. A set 14S may be defined as including defensive agents 14 configured to perform anomaly detection on a particular target 16, or as including defensive agents 14 distributed to perform anomaly detection in a particular geographic or functional area (e.g., what may be referred to as a "neighborhood"). Indeed, in some embodiments, communication network 10 may include multiple defensive agents 14 in set 14S that perform anomaly detection in different areas or neighborhoods. However, for simplicity of explanation, FIG. 1 focuses on multiple defensive agents 14 in a single set 14S.

[0030] In this context, FIG. 1 illustrates that a security controller 18 controls a set 14S of defense agents 14. The security controller 18 may be common to the defense agents 14 but centralized and / or separate from any of the defense agents 14 in the set 14S. Alternatively, the security controller 18 may be distributed across multiple distributed agents 14 and / or co-located with one or more of the distributed agents 14 in the set. In either case, the security controller 18 effectively controls one or more aspects of the operation of the defense agents 14 in the set 14S. For example, the security controller 18 controls whether and / or how each defense agent 14 in the set 14S performs anomaly detection or one or more tasks thereof.

[0031] In particular, the security controller 18 in this example utilizes metrics that characterize anomaly detection accuracy and anomaly detection resource consumption to control the defense agents 14. For example, the security controller 18 utilizes such metrics to achieve a desired balance between anomaly detection accuracy and anomaly detection resource consumption, such as may be necessary to achieve a Zero Trust Architecture (ZTA) in practice. Alternatively, in other embodiments, the security controller 18 utilizes such metrics to protect the communication network 10 even when the defense agents 14 become malicious, rather than simply assuming that the defense agents 14 are always trustworthy, such as in a manner consistent with ZTA.

[0032] In this regard, Figure 1 shows in more detail that the security controller 18 obtains one or more accuracy metrics 20 and one or more resource consumption metrics 22. The security controller 18 may obtain these metrics 20, 22 by receiving them from another node (not shown) in the communication network 10, or by calculating, deriving, or otherwise determining them itself.

[0033] One or more accuracy metrics 20 characterize the accuracy with which the defensive agents 14 in the set 14S detect anomalies in the communication network 10. The one or more accuracy metrics 20 positively characterize such accuracy based on how often the defensive agents 14 perform anomaly detection accurately (e.g., how often the defensive agents 14 correctly detect the presence of anomalies and how often they correctly detect the absence of anomalies). Alternatively, the one or more accuracy metrics 20 negatively characterize such accuracy based on how often the defensive agents 14 perform anomaly detection inaccurately (e.g., how often the defensive agents 14 incorrectly detect the presence of anomalies and how often they incorrectly detect the absence of anomalies). As examples of the latter, the one or more accuracy metrics 20 may include a rate of incorrectly detecting anomalies (false positive rate), a rate of failing to detect anomalies (false negative rate), and / or a false rate (a combination of the false positive rate and the false negative rate, e.g., a weighted sum of the false positive rate and the false negative rate).

[0034] One or more resource consumption metrics 22 characterize the extent to which the defensive agents 14 in the set 14S consume resources in the communication network 10, such as the extent of resource consumption due to anomaly detection. Consumable resources in this context may include energy resources, processing or computational resources, communication resources, and other consumable assets consumed by the performance of anomaly detection. A resource consumption metric 22 characterizing the extent to which the defensive agents 14 consume energy resources in performing anomaly detection may have a value indicative of, or proportional to, the number of kilowatt-hours (kWh) consumed by the defensive agents 14, for example. As another example, a resource consumption metric 22 characterizing the extent to which the defensive agents 14 consume communication resources in performing anomaly detection may have a value indicative of, or proportional to, the bitrate consumed by the defensive agents 14, for example.

[0035] Note that the accuracy metric 20 and / or resource consumption metric 22 may include a set-wide metric that characterizes the defense agents 14 in the set 14S as a whole, and an agent-specific metric that characterizes each individual agent. For example, as shown in FIG. 2A , the set-wide accuracy metric 20S characterizes the anomaly detection accuracy of the defense agents 14 in the set 14S as a whole (e.g., the false positive rate for the combination of defense agents 14), and the set-wide resource consumption metric 22S characterizes the resource consumption of the defense agents 14 in the set 14S as a whole (e.g., the total kWh consumed across the set 14S). Meanwhile, as shown in FIG. 2B , the agent-specific accuracy metric 20A characterizes the anomaly detection accuracy of the defense agents 14 for each individual agent (e.g., the false positive rate for each defense agent 14) and characterizes the accuracy metric for each agent (e.g., the false positive rate for each defense agent 14). Additionally, agent-specific resource consumption metrics 22A characterize the individual resource consumption of the defensive agents 14 (e.g., each agent's individual kWh). Note that while the arrows in Figures 2A-2B show metrics 20, 22 as "originating" from the set 14S or individual defensive agents 14 for illustrative purposes, metrics 20, 22 are not actually "received" from the set 14S or individual agents 14. Rather, metrics 20, 22 may be calculated or determined by security controller 18 or other nodes based on other information (e.g., anomaly reports) received from the set 14S or individual defensive agents 14.

[0036] In either case, the security controller 18 controls the defense agents 14 in the set 14S based on the accuracy metric 20 and the resource consumption metric 22. For example, based on the accuracy metric 20 and the resource consumption metric 22, the security controller 18 can control whether or how each defense agent 14 performs anomaly detection, or whether or how each defense agent 14 performs one or more anomaly detection tasks. The security controller 18 does this to protect the communication network 10 against malicious defense agents 14 as suggested by the metrics 20, 22, or as part of a strategy to balance anomaly detection accuracy and resource consumption.

[0037] FIG. 3 illustrates several examples in which the security controller 18 controls the defense agents 14 to protect against malicious defense agents 14. In this example, defense agent 14-1 is malicious. In this case, defense agent 14-1 may have been hijacked or otherwise compromised by a malicious actor, so that it is no longer functioning as intended to protect the communications network 10. Alternatively, a malicious actor may have injected defense agent 14-1 into communications network 10, where the defense agent 14-1 may masquerade as an operator-controlled defense agent. In either case, defense agent 14-1 is considered malicious in that it intends to disrupt the normal operation and privacy of communications network 10, such as through cyberattacks.

[0038] The security controller 18 shown in FIG. 3 utilizes an agent-specific accuracy metric 20A and / or an agent-specific resource consumption metric 22A to identify the defense agent 14-1 as malicious. In this regard, the security controller 18 includes a defense agent monitor 21 that obtains the accuracy metric 20A and / or the resource consumption metric 22A specific to each defense agent 14. The defense agent monitor analyzes these metrics 20A, 22A to determine whether any of the metrics 20A, 22A are anomalous. Based on the results of this analysis, the defense agent monitor 21 identifies the malicious defense agent 14. For example, the defense agent monitor 21 may identify the defense agent 14-1 as malicious because the accuracy metric 20A and / or the resource consumption metric 22A of the defense agent 14-1 are anomalous, either alone or compared to the accuracy metric 20A and / or the resource consumption metric 22A specific to the other defense agents 14-2, 14-3, and 14-4. The abnormal characteristic may be defined, for example, as a defensive agent 14-1's specific accuracy metric 20A and / or resource consumption metric 22A exhibiting a difference of more than a threshold value from the accuracy metric 20A and / or resource consumption metric 22A of each of the other defensive agents 14. In other embodiments, the abnormal characteristic may be defined based on the point at which the defensive agent 14-1's specific accuracy metric 20A and / or resource consumption metric 22A deviates outside a range defined as normal. In such embodiments, the accuracy metric 20A specific to any defensive agent 14 exhibits a false positive rate P D and the false negative rate N D , the defensive agent monitor 21 determines whether α3·(P D +N D )≫α2·D D If D, then the defensive agent 14 is identified as malicious. Dis the rate at which a given defensive agent 14 detects an anomaly, and α2, α3∈[0,1] are weighting parameters. In this case, the defensive agent monitor 21 calculates the false positive rate P D and the false negative rate P N is excessively disproportionate relative to the rate at which the defensive agent 14 detects anomalies, the defensive agent monitor 21 determines that the defensive agent 14 is malicious. In this and other cases, the defensive agent monitor 21 typically leverages agent-specific metrics 20A, 22A as evidence of maliciousness, for example, based on the assumption that malicious behavior targets or results in reduced anomaly detection accuracy and / or increased resource consumption.

[0039] Upon identifying a malicious defense agent 23, the defense agent monitor (21) notifies the defense agent controller (25) of the malicious defense agent 23. The defense agent controller 25 then takes appropriate action against the malicious defense agent 23. For example, in the case of a malicious defense agent 14-1, the defense agent controller 25 sends a disable signaling 27 to the defense agent 14-1. The disable signaling 27 may take action such as disabling or deleting the malicious defense agent 14-1, requesting that the malicious defense agent 14-1 only act as a normal node rather than a defense agent, revoking the privileges to use infrastructure resources on which the malicious defense agent 14-1 depends, or controlling the malicious defense agent 14-1 to stop detecting anomalies. The security controller 18 may alternatively or additionally take action to remove or isolate the malicious defense agent 14-1, such as ignoring anomaly detection (or lack thereof) from the malicious defense agent 14-1, performing a cryptographic key update, etc.

[0040] Generally, in some embodiments, the security controller 18 may screen the distributed defense agents 14 themselves for malicious intent based on accuracy and / or resource consumption metrics 20, 22. In these and other embodiments, the security controller 18 may advantageously protect the communications network 10 against malicious defense agents, even when operating the communications network 10 in accordance with, for example, ZTA, rather than simply assuming that the defense agents 14 are trusted.

[0041] Consider now other embodiments that control defense agents 14 based on accuracy and resource consumption metrics 20, 22. In some embodiments, security controller 18 controls whether each defense agent 14 in set 14S performs anomaly detection. That is, security controller 18 controls the defense agents 14 as a whole, e.g., all defense agents perform all or none of the aspects of anomaly detection. In this regard, FIG. 4 illustrates that in some embodiments, defense agents 14 in set 14S can operate in a so-called accuracy-enhancing mode, in which all defense agents 14 perform anomaly detection. That is, all defense agents 14 are “active” and perform anomaly detection. Meanwhile, FIG. 5 illustrates that defense agents in set 14S can operate in a “resource-saving mode,” in which at least one defense agent 14 does not perform anomaly detection. That is, at least one defense agent 14 is “inactive” and does not perform anomaly detection. In this case, the security controller 18 determines in which mode (accuracy-enhancing mode or resource-saving mode) the defensive agents of the set 14S should operate based on accuracy and resource consumption metrics 20, 22.

[0042] In the example shown in FIG. 6A , the set of defensive agents 14S is operating in an accuracy-enhancing mode. In this case, the security controller 18 includes a mode selector 18M that obtains a set-wide resource consumption metric 22S that characterizes the extent to which the set of defensive agents 14S consumes resources. The mode selector 18M compares the set-wide resource consumption metric 22S with a set-wide resource consumption threshold 22S-TH. If the set-wide resource consumption metric 22S exceeds the set-wide resource consumption threshold 22S-TH, the mode selector 18M makes a decision to switch the set of defensive agents 14S to a resource-saving mode 30R. Correspondingly, the mode controller 18C includes an agent selector 18A that selects one or more defensive agents 14 for which to continue anomaly detection and selects one or more defensive agents 14 for which to stop (i.e., disable) anomaly detection. The illustrated agent selector 18A makes this selection based on an agent-specific accuracy metric 20A for each defensive agent 14. For example, in one embodiment, the defensive agents 14 that the agent selector 18A selects to continue anomaly detection are those defensive agents 14 with the highest accuracy or accuracy above a threshold (e.g., defensive agents 14-1 and 14-3), as reflected in the agent-specific accuracy metric 20A. The defensive agents 14 that the agent selector 18A selects to stop anomaly detection are those defensive agents 14 with the lowest accuracy or accuracy below a threshold (e.g., defensive agents 14-2 and 14-4), as reflected in the agent-specific accuracy metric 20A. To achieve this selection, the agent selector 18A is shown sending enable signaling 32A to the defensive agents 14-1 and 14-3 that are to perform anomaly detection and sending disable signaling 32I to the defensive agents 14-2 and 14-4 that are not to perform anomaly detection.

[0043] 6B illustrates another example in which a set 14S of defensive agents 14 is operating in a resource-saving mode. In this case, the mode selector 18M obtains a set-wide accuracy metric 22A that characterizes the accuracy with which the set 14S of defensive agents 14 detect anomalies. The mode selector 18M compares the set-wide accuracy metric 22A with a set-wide accuracy threshold 22A-TH. Based on the results of this comparison (e.g., if unacceptably low accuracy is found), the mode selector 18M makes a decision to switch the set 14S of defensive agents to an accuracy-enhancing mode 30A. In response, the mode controller 18C controls the defensive agents 14 in the set 14S to operate in the accuracy-enhancing mode 30A. This can be achieved, for example, by sending an enable signaling 32A to all defensive agents 14 in the set 14S.

[0044] Thus, in this example, security controller 18 controls set 14S of defensive agents 14 to balance anomaly detection accuracy and resource consumption. Such control is performed on an agent-by-agent basis. However, in other embodiments where anomaly detection involves multiple tasks, control may be performed on a task-by-task basis.

[0045] For example, in some embodiments, each defensive agent 14 in the set 14S performs one or more tasks as part of anomaly detection, and such tasks are appropriately referred to as "anomaly detection tasks." In this case, the security controller 18 controls whether and / or how each defensive agent 14 performs each anomaly detection task. Figure 7 illustrates an example in which anomaly detection tasks include anomaly feature monitoring, feature detection, and decision-making.

[0046] In particular, FIG. 7 illustrates that each defensive agent 14-1...14-N includes a corresponding monitoring subsystem 24-1...24-N for performing a feature monitoring task as part of anomaly detection. The feature monitoring task involves identifying features of the anomaly being detected. These features may be, for example, machine learning (ML) features. For example, features of an anomaly in the form of a denial-of-service attack (DoS attack) may include excessive access requests and corresponding denials despite low load on the communications network 10 being attributed to authorized users. In this case, the feature monitoring task is to distinguish these features from other types of anomalies or the absence of anomalies and identify them as features of a denial-of-service attack. In any event, the combination of the monitoring subsystems 24-1...24-N across the set 14S of defensive agents 14-1...14-N forms an overall monitoring system 24. That is, the monitoring system 24 is deployed across the defensive agents 14 in the set 14S.

[0047] Similarly, Figure 7 shows that each defensive agent 14-1...14-N includes a corresponding detection subsystem 26-1...26-N for performing feature detection tasks as part of anomaly detection. The feature detection task is detecting features determined by the monitoring system 24, i.e., detecting the presence and absence of such features. The combination of the detection subsystems 26-1...26-N across the defensive agents 14-1...14-N in the set 14S forms an overall detection system 26. That is, the detection system 26 spans the defensive agents 14 in the set 14S.

[0048] 7 shows that each defensive agent 14-1...14-N includes a corresponding decision-making subsystem 28-1...28-N for performing a decision-making task as part of anomaly detection. The decision-making task is to determine whether an anomaly exists based on the features detected by the detection system 26. The combination of the decision-making subsystems 28-1...28-N across the defensive agents 14-1...14-N in the set 14S forms an overall decision-making system 28. That is, the decision-making system 28 spans the defensive agents 14 in the set 14S.

[0049] In this context, the security controller 18 determines which one or more of the defense agents 14 in the set 14S should perform each anomaly detection task and which one or more of the defense agents 14 in the set 14S should not perform each anomaly detection task based on the accuracy metric 20 and the resource consumption metric 22. The security controller 18 then controls the defense agents 14 appropriately.

[0050] 8A-8B illustrate examples focusing on the monitoring system 24 (other examples are omitted but are equally applicable to the detection system 26 and the decision-making system 28). FIG. 8A illustrates that, in some embodiments, the monitoring system 24 can operate in what is called a "precision-enhancing mode." In this mode, all monitoring subsystems 24-1...24-N of a set of defensive agents 14 perform feature monitoring tasks. That is, all monitoring subsystems 24-1...24-N of a defensive agent 14 are "active" in the sense of performing feature monitoring tasks. FIG. 8B, on the other hand, illustrates that the monitoring system 24 can operate in a so-called resource-saving mode in which at least one of the monitoring subsystems 24-1...24-N across the defensive agents 14 does not perform feature monitoring tasks. That is, all monitoring subsystems 24-1...24-N across the defensive agents 14 are "inactive" and do not perform feature monitoring tasks. In this case, the security controller 18 determines in which mode (accuracy-enhancing mode or resource-saving mode) the monitoring system 24 will operate based on accuracy and resource consumption metrics 20, 22.

[0051] While the monitoring system 24 has been described above as operating in either an accuracy-enhancing mode or a resource-conserving mode, the same concept can also be expressed as a set 14S of defensive agents 14 operating in either an accuracy-enhancing mode or a resource-conserving mode for a feature monitoring task. Thus, for each different anomaly detection task, a set 14S of defensive agents 14 operates in either an accuracy-enhancing mode or a resource-conserving mode for that task.

[0052] In any event, in the example shown in FIG. 9A , consider the case where the monitoring system 24 is operating in precision-enhancing mode, i.e., the set 14S of defensive agents are operating in precision-enhancing mode for the feature monitoring task. In this case, the security controller 18 includes a mode selector 18M that obtains a set-wide resource consumption metric 22S that characterizes the extent to which the set 14S of defensive agents consume resources. The mode selector 18M compares the set-wide resource consumption metric 22S with a set-wide resource consumption threshold 22S-TH. If the set-wide resource consumption metric 22S exceeds the set-wide resource consumption threshold 22S-TH, the mode selector 18M makes a decision to switch the set 14S of defensive agents to operate in a resource-saving mode 30R for the feature monitoring task. Correspondingly, the mode controller 18C includes a selector 18A that selects one or more defensive agents 14 (or corresponding monitoring subsystems 24) that will continue to perform the feature monitoring task and one or more defensive agents 14 (or corresponding monitoring subsystems 24) that will stop the feature monitoring task, i.e., be disabled for the feature monitoring task. The illustrated selector 18A makes this selection based on an agent-specific accuracy metric 20A for each defense agent 14. For example, in one embodiment, the defense agents 14 that selector 18A selects to continue performing feature monitoring tasks are those defense agents 14 (e.g., defense agents 14-1 and 14-3) with the highest accuracy or accuracy above a threshold, as reflected in agent-specific accuracy metric 20A. And, the defense agents 14 that agent selector 18A selects to stop feature monitoring tasks are those defense agents 14 (e.g., defense agents 14-2 and 14-4) with the lowest accuracy or accuracy below a threshold, as reflected in agent-specific accuracy metric 20A.To achieve such selection, the agent selector 18A sends an enable signaling 32A to the defensive agents 14-1, 14-3 (or corresponding monitoring subsystems 24-1, 24-3) that perform the feature monitoring task, and sends an disable signaling 32I to the defensive agents 14-2, 14-4 (or corresponding monitoring subsystems 24-2, 24-4), as shown in the figure.

[0053] 9B illustrates another example in which a set 14S of defensive agents 14 operates in a resource-saving mode for a feature monitoring task. In this case, a mode selector 18M obtains a set-wide accuracy metric 22A, which characterizes the accuracy with which the set 14S of defensive agents 14 detect anomalies. The mode selector 18M compares the set-wide accuracy metric 22A with a set-wide accuracy threshold 22A-TH. Based on the results of this comparison (e.g., if unacceptably low accuracy is found), the mode selector 18M makes a decision to switch the set 14S of defensive agents 14 to an accuracy-enhancing mode 30A for the feature monitoring task. Correspondingly, the mode controller 18C controls the set 14S of defensive agents 14 to operate in the accuracy-enhancing mode 30A for the feature monitoring task, for example, by sending an enable signaling 32A to all defensive agents 14 or corresponding monitoring subsystems 24-1...24-N in the set 14S.

[0054] 9A-9B, in one embodiment, security controller 18 decides to switch a set of defensive agents 14S from precision-improving mode to resource-saving mode in a feature monitoring task. D >α1·M D , the security controller 18 switches the set of defensive agents 14S from the precision-improving mode to the resource-saving mode. D is the resource consumption metric 22S for the entire set shown in Figure 9A (α3 is a weight parameter ∈ [0,1]), and α1·M Dis the resource consumption threshold 22S-TH(α1) of the entire set in Fig. 9A, and the weight parameter ∈ [0, 1] is M D is the rate at which the defensive agents 14 in the set 14S (monitoring system 24) each determine the characteristics of an anomaly). Meanwhile, the security controller 18 determines whether to switch the set 14S of defensive agents 14 from the resource saving mode to the accuracy improving mode in the feature monitoring task by using α3·(P D +N D )>α1·M D Determine if, where P D is the false positive rate for the entire set of defensive agents, 14S, and N D is the false negative rate for the entire suite of defensive agents, 14S.

[0055] When extended to the detection system 26, in some embodiments, the security controller 18 determines whether to switch the set of defensive agents 14S from an accuracy-enhancing mode to a resource-saving mode in a feature detection task using α3·C D >α2·D D In this case, a set of defensive agents 14S switches from accuracy-improving mode to resource-saving mode. Here, α3·C D is the resource consumption metric for the entire set, α2·D D is the resource consumption threshold 22S-TH for the entire set (where α2 is a weight parameter ∈ [0,1], and D D is the rate at which the defensive agents 14 in the set 14S (detection system 26) detect the feature determined by the monitoring system 24. Meanwhile, the security controller 18 determines whether to switch the set 14S of defensive agents 14 from resource saving mode to precision improving mode in the feature detection task by α3·(P D +N D )>α2·D D This is determined in the following cases.

[0056] Further, when extended to a decision-making system 28, the security controller 18 may use the set-wide accuracy metric 22A as a basis for mode selection instead of, or in addition to, the set-wide resource consumption metric. In some embodiments, for example, the security controller 18 determines whether to switch the set of defensive agents 14S from an accuracy-enhancing mode to a resource-saving mode in a decision task using α3·(P D +N D )≦α1·M D +α2·D D (where α3·(P D +N D ) is the overall accuracy metric22A of the set, where α1 M D +α2·D D is the accuracy threshold 22A-TH for the entire set), the security controller 18 switches the set of defensive agents 14S from the accuracy improvement mode to the resource saving mode for the decision task. That is, the security controller 18 decides to switch the set of defensive agents 14S to the resource saving mode when the weighted combination of the false positive rate and the false negative rate for the decision task is below the threshold, i.e., when sufficient accuracy is ensured to save resources. Meanwhile, the security controller 18 determines whether to switch the set of defensive agents 14S to the resource saving mode when the weighted combination of the false positive rate and the false negative rate for the decision task is below the threshold, i.e., when sufficient accuracy is ensured to save resources. D +N D )>α1·M D +α2·D D In the case where (where α1·M D +α2·D D is the accuracy threshold 22A-TH for the entire set), the set of defensive agents 14S switches from resource saving mode to accuracy improving mode for the decision-making task. That is, the security controller 18 decides to switch the set of defensive agents 14S to accuracy improving mode for the decision-making task if the weighted combination of the false positive rate and false negative rate is equal to or greater than a threshold, i.e., if the accuracy is low enough to justify increased resource consumption.

[0057] In general, as this example shows, the security controller 18 may decide to switch the set of defensive agents 14S to an accuracy improvement mode for an anomaly detection task based on either: (i) a comparison of the accuracy metrics of the entire set for the anomaly detection task with an accuracy threshold for the entire set; or (ii) a comparison of the resource consumption metrics of the entire set for the anomaly detection task with a resource consumption threshold for the entire set.

[0058] In some embodiments, the security controller 18 can effectively apply game theory to its decisions. In this approach, there are two types of players in the game: a defensive player and an attacking player. The defensive players in the game are the defensive agents 14 whose objectives are to improve anomaly detection accuracy and reduce resource consumption. The attacking players are malicious nodes or malicious defensive agents whose objectives are to reduce anomaly detection accuracy and increase resource consumption (thereby depleting resources available to legitimate defensive agents 14). In these embodiments, the security controller 18 calculates a defensive agent utility metric U for a set 14S of defensive agents 14. D as a function of the accuracy metric 20 and the resource consumption metric 22. The security controller 18 obtains the defense utility metric U D and an attack resource consumption metric C that reflects the amount of resources required by an attacker to perform a coordinated attack against the communication network 10. A As a function of A Next, the security controller 18 obtains the utility metric U D and the attack utility metric U A , and controls whether a defensive agent 14 in the set 14S performs one or more anomaly detection tasks.

[0059] For example, in some embodiments, the security controller 18 may calculate the utility metric U DU D =α1 M D +α2·D D -α3·(P D +N D )-α3·C D where M D is the rate at which the defensive agents 14 in the set 14S (monitoring systems 24) detect each characteristic of an anomaly, and D D is the rate at which the defensive agents 14 in a set 14S (detection system 26) detect anomalies, P D is the false positive rate of the entire set, including the rate at which the defense agents 14 in the set 14S falsely detect anomalies, N D is the false negative rate of the entire set, which includes the rate at which the defense agent 14 of a set 14S fails to detect an anomaly, and C D is the set of overall resource consumption metrics, expressed in the form of network cost percentages or the like, generated by the defense agent 14, M D , D D , P D , N D , and C D ∈[0,1], and α1, α2, α3∈[0,1] are weighting parameters. The security controller 18 calculates the attack utility metric U A U A =-(U D +β·C A ) where C A is the attack resource consumption metric, β is a weight parameter, and β∈[0,1].

[0060] Also, in some embodiments, the security controller 18 may determine the initial mode of the defensive agents in the set 14S based on the defensive agent utility metric U D and the attack utility metric U A For example, the initial mode (i.e., "starting") is controlled based on U D ≧U A, the security controller 18 is set to the accuracy-enhancing (active) mode. In this case, the security controller 18 first effectively activates the monitoring system 24, the detection system 26, and the decision-making system 28, and then adapts the mode of each system according to other embodiments herein. That is, in some embodiments, after the initial mode selection, the security controller 18 controls the set 14S of defensive agents 14 as follows: Switch the surveillance system to idle mode α3·C D >α1·M D in the case of Switch the surveillance system to active mode α3·(P D +N D )>α1·M D in the case of Switch the detection system to idle mode α3·C D >α2·D D in the case of Switch the detection system to active mode α3·(P D +N D )>α2·D D in the case of Switch the decision-making system to idle mode α3·(P D +N D )≦α1·M D +α2·D D in the case of Switch the decision monitoring system to active mode α3·(P D +N D )>α1·M D +α2·D D in the case of Here, the resource saving mode is referred to as the idle mode because some or all of the defense agents or subsystems are idle for a particular anomaly detection task, while the accuracy improvement mode is referred to as the active mode because all defense agents or subsystems are active for a particular anomaly detection task.

[0061] Generally, in some embodiments, the monitoring, detection, and decision-making systems 24, 26, 28 switch from active mode to idle mode to reduce resource consumption and switch back from idle mode to active mode if there is a sudden increase in the number of false positives and false negatives (e.g., in the vicinity of a suspected target). For example, in some embodiments, the monitoring, detection, and decision-making systems 24, 26, 28 switch from active mode to idle mode to reduce resource consumption and switch from idle mode to active mode if there is a high number of false positives and false negatives in the vicinity of a suspected target, thereby aiming to further reduce the false positive and false negative rates.

[0062] Next, consider other methods of controlling defense agents 14 in set 14S based on accuracy metric 20 and resource consumption metric 22. In some embodiments, security controller 18 controls whether and to what extent defense agents 14 in set 14S cooperate with each other when performing anomaly detection. In such embodiments, greater cooperation increases resource consumption but improves the accuracy of anomaly detection. Based on accuracy metric 20 and resource consumption metric 22, in some embodiments, security controller 18 controls whether and which defense agents 14 in set 14S operate in a so-called cooperative mode, where defense agents 14 cooperate with each other to perform anomaly detection, and also controls whether and which defense agents 14 in set 14S operate in a so-called solo mode, where defense agents 14 do not cooperate with each other to perform anomaly detection.

[0063] FIGS. 10A-10B illustrate solo and collaborative modes in some embodiments. As shown in FIG. 10A , in solo mode, each defense agent 14 independently performs anomaly detection tasks without collaborating with other defense agents 14 in the set 14S. In FIG. 10A , each defense agent's monitoring subsystem independently determines the characteristics of the anomaly to be detected, each defense agent's detection subsystem independently detects those characteristics, and each defense agent's decision-making subsystem independently determines whether an anomaly exists. In contrast, as shown in FIG. 10B , in collaborative mode, the monitoring subsystems 24-1...24-4 across defense agents 14 cooperate with each other to determine the characteristics 40 of the anomaly to be detected, and the detection subsystems 26-1...26-4 cooperate with each other to detect those characteristics 40. Furthermore, the decision-making subsystems 28-1...28-4 across defense agents 14 cooperate with each other to determine whether an anomaly exists based on the detected characteristics 42.

[0064] In this context, in some embodiments, the security controller 18 obtains accuracy metrics 20 and / or resource consumption metrics 22 for each of the solo and collaborative modes, and controls in which mode (solo mode or collaborative mode) the defensive agents 14 in the set 14S operate based on the obtained metrics 20, 22.

[0065] In one embodiment, the security controller 18 controls the defense agents 14 in the set 14S to operate in the collaborative mode if one or more collaborative mode trigger criteria are met. Conversely, the security controller 18 controls the defense agents 14 in the set 14S to operate in the solo mode if one or more solo mode trigger criteria are met. This allows the defense agents 14 to effectively switch between the solo mode and the collaborative mode as needed, for example, to maintain a desired balance between accuracy and resource consumption. An example is shown in FIG. 11.

[0066] As shown in FIG. 11 , the security controller 18 includes a mode selector 18M that obtains a set of overall accuracy metrics 20S-C for the cooperative mode (e.g., a set of overall false rate metrics) and a set of overall accuracy metrics 20S-S for the solo mode (e.g., a set of overall false rate metrics). The mode selector 18M compares these metrics 20S-C and 20S-S with accuracy thresholds 20C-TH and 20S-TH for each mode. In one embodiment, trigger criteria for triggering the cooperative mode include when the set of overall accuracy metrics 20S-S for the solo mode exceeds the solo mode accuracy threshold 20S-TH. For example, the cooperative mode is selected when the solo mode accuracy is low. Alternatively, trigger criteria for the solo mode include when the set of overall accuracy metrics (20S) for the cooperative mode (e.g., a set of overall error rate metrics) falls below the cooperative mode accuracy threshold (20C-TH). This allows the solo mode to be selected when the cooperative mode accuracy is sufficiently high to prioritize reducing resource consumption. However, in some embodiments, the trigger criteria for the solo mode may further include the resource consumption metric 22S-C of the entire collaborative mode set exceeding the collaborative mode resource consumption threshold 22C-TH. For example, the solo mode may be selected if the collaborative mode accuracy is sufficiently high and the collaborative mode resource consumption is excessive. In general, the mode selector 18M effectively allows the defense agents 14 to cooperate with each other to improve anomaly detection accuracy, but prohibits cooperation if the defense agents 14 consume excessive resources, e.g., to achieve a desirable trade-off between anomaly detection accuracy and resource consumption. In any case, if the mode selector 18M selects a mode 36 in which the set 14S of defense agents 14 should operate, the mode controller 18C controls the defense agents 14 to operate in the selected mode 36. For example, this may be achieved by sending mode control signaling 34 to the defense agents 14.

[0067] As a specific example, in some embodiments, the security controller 18 controls the defensive agents 14 as follows: Switch to collaborative mode γ2·(P L +N L )≫γ1·D L in the case of Switch to standalone mode δ2·(P I +N I )≪δ1·D I and δ3·C I ≫δ1·D I in the case of where γ2·(P L +N L ) is the accuracy metric 20S-S of the entire set in the single mode, and γ1·D L is the single mode accuracy threshold 20S-TH, δ2·(P I +N I ) is a set of overall accuracy metrics 20S-C, δ1·D in collaborative mode I represents both the accuracy threshold 20C-TH and the resource consumption threshold 22C-TH in the collaborative mode, and δ3·C I is the resource consumption metric 22S-C of the entire set of collaborative modes, where γ1, γ2, δ1, δ2, δ3 are weighting parameters, P L is the false positive rate for the entire set in the single mode, N L is the false negative rate of the entire set in the single mode, D L is the anomaly detection rate for the entire set in the single mode, P I is the false positive rate for the entire set in the collaborative mode, N I is the false negative rate of the entire set in the collaborative mode, D I is the anomaly detection rate for the entire set in the collaborative mode. Figure 12 shows the logic of mode selection in this case.

[0068] As shown in FIG. 12, the security controller 18 L , P L , N L (Block 100). The security controller 18 then calculates γ2·(P L +N L )≫γ1·D L If it is not satisfied (NO in block 110), the security controller 18 returns to block 100 and determines whether D L, P L , N L On the other hand, if it is satisfied (YES in block 110), the security controller 18 selects the collaboration mode and controls the defensive agents 14 in the set 14S to switch to the collaboration mode (block 120).

[0069] When the defensive agent 14 is in the collaborative mode, the security controller 18 I , P I , N I , C I (block 130). The security controller 18 calculates δ2·(P I +N I )≪δ1·D I and δ3·C I ≫δ1·D I If it is not satisfied (NO in block 140), the security controller 18 returns to block 130 and determines whether D I , P I , N I , C I If, on the other hand, it is satisfied (YES in block 140), the security controller 18 selects the solo mode and switches the defensive agents 14 in the set 14S to solo mode (block 150). The process then repeats.

[0070] In some embodiments, the security controller 18 selects between the solo mode and the collaborative mode in this manner based on a utility function representing the solo mode and the collaborative mode. For example, the utility function for the solo mode is U S =γ1 D L -[γ2·(P L +N L )+γ3·C L ]. On the other hand, the utility function for the collaborative mode is U C =δ1·D I -[δ2·(P I +N I )+δ3·C I ] can be expressed as

[0071] However, in some embodiments, the security controller 18 applies exceptions to the mode selection logic, allowing different systems 24, 26, 28 to operate in different modes. In particular, γ3·C L ≫γ1·D L , the security controller 18 selects the collaborative mode for the monitoring system 24, but the solo mode for the detection system 26 and the decision-making system 28. Conversely, when γ2·(P L +N L )≫γ1·D L and δ1·D I ≫δ3·C I In this case, the security controller 18 selects the standalone mode for the monitoring system 24 but selects the collaborative mode for the detection system 26 and the decision-making system 28 .

[0072] While the present example describes the defense agents 14 as being distributed throughout the communications network 10, it should be noted that the defense agents 14 in the set 14S may actually be distributed across different hierarchical levels. For example, as shown in FIG. 13 , the defense agents 14 in the set 14S may include one or more so-called “first layer of defense (FLD)” agents 14FLD-1...14FLD-X and one or more “second layer of defense (SLD)” agents 14SLD-1...14SLD-Y. The first layer 10A of the communications network 10 may be, for example, an edge network, a wireless access network, or a core network, and the second layer 10B of the communications network 10 may be a cloud network. In one such embodiment, there is a single SLD agent in the second layer 10B that serves as a common collaboration point for multiple FLD agents in the first layer 10A (e.g., FLD agents located at each edge server, each network function, etc.). This single SLD agent is a centralized defense agent covering the set 14S of defense agents that, for example, makes the final decision on whether an anomaly has been detected. In fact, that determination may require cooperation between the FLD agent and the SLD agent to determine whether the target is an attacker. The SLD agent further provides the FLD agent with recommended actions on how to respond to the detected anomaly. In some implementations, the FLD agent and the SLD agent cooperate with each other to ensure agreement on anomaly detection accuracy and resource consumption. The SLD agent may be implemented as a security information and event management (SIEM) entity.

[0073] Additionally, in some embodiments, the feature detection system herein may employ multiple detection techniques (e.g., binary detection and hybrid techniques). The binary detection techniques may be based on lightweight machine learning algorithms (e.g., binary support vector machines) or rule-based attack detection, and the output of the binary detection techniques is either an attack or normal (i.e., 1 or 0). Hybrid detection techniques are robust techniques based on a combination of rule-based detection techniques and machine learning algorithms, and their primary goal is to reduce false positive and false negative rates over time. However, this reduction may come at the expense of increased energy and computational resource consumption.

[0074] Generally, embodiments herein improve the accuracy of anomaly (e.g., attack) detection to enhance or harden the security of communications network 10. This is particularly useful in detection frameworks that generate high false positive and high false negative rates (e.g., complex, unknown attack scenarios, such as zero-day attacks). Indeed, in some embodiments, the accuracy of anomaly detection improves over time as security controller 18 learns the characteristics of the anomalies it detects. More importantly, some embodiments achieve a higher level of security at a lower network cost in terms of resource consumption compared to traditional detection frameworks.

[0075] 14 illustrates, as steps performed by a security controller 18, a method (according to a particular embodiment) for performing anomaly detection within a communications network 10 using defensive agents 14 distributed among a set 14S. The method includes obtaining (block 200) one or more accuracy metrics 20 that characterize the accuracy with which the defensive agents 14 in the set 14S detect anomalies in the communications network 10. The method further includes obtaining (block 210) one or more resource consumption metrics 22 that characterize the extent to which the defensive agents 14 in the set 14S consume resources in the communications network 10. The method further includes controlling (block 220) the defensive agents 14 in the set 14S based on the one or more accuracy metrics 20 and the one or more resource consumption metrics 22.

[0076] In some embodiments, the one or more accuracy metrics 20 include a set-wide false positive rate, which includes the rate at which the defensive agents 14 in the set 14S incorrectly detect anomalies, a set-wide false negative rate (the rate at which the defensive agents 14 in the set fail to detect anomalies), and / or a set-wide false rate (a combination of the set-wide false positive rate and the set-wide false negative rate). Alternatively or additionally, the one or more accuracy metrics 20 include, for each defensive agent 14 in the set 14S, a defensive agent-specific false positive rate (the rate at which the defensive agent incorrectly detects anomalies), a defensive agent-specific false negative rate (the rate at which the defensive agent fails to detect anomalies), and / or a defensive agent-specific false rate (a combination of the defensive agent-specific false positive rate and the defensive agent-specific false negative rate).

[0077] In some embodiments, controlling the defensive agents 14 in the set 14S includes controlling whether and / or how each defensive agent in the set 14S performs one or more anomaly detection tasks based on one or more accuracy metrics 20 and one or more resource consumption metrics 22.

[0078] In some embodiments, controlling the defensive agents 14 in the set 14S includes controlling, for each of one or more anomaly detection tasks, which one or more defensive agents 14 in the set 14S perform the anomaly detection task and which one or more defensive agents 14 (if any) in the set 14S do not perform the anomaly detection task based on one or more accuracy metrics 20 and one or more resource consumption metrics 22.

[0079] For example, in one embodiment, a method for controlling defensive agents 14 includes making a decision to switch the set, for at least one of one or more anomaly detection tasks, from an accuracy-enhancing mode, in which all of the defensive agents 14 in the set 14S perform the anomaly detection task, to a resource-saving mode, in which at least one of the defensive agents 14 in the set 14S does not perform the anomaly detection task, by comparing a resource consumption metric for the anomaly detection tasks of the entire set to a resource consumption threshold for the anomaly detection tasks of the entire set. Based on the decision, the control of defensive agents 14 determines which defensive agents 14 in the set 14S will perform the anomaly detection task in the resource-saving mode and which will not perform the anomaly detection task in the resource-saving mode based on the agent-specific accuracy metric of each defensive agent 14.

[0080] In another embodiment, controlling the defensive agents 14 includes making a decision to switch the set, for at least one anomaly detection task, from a resource-saving mode, in which at least one defensive agent 14 in the set 14S does not perform the anomaly detection task, to an accuracy-improving mode, in which all defensive agents 14 in the set 14S perform the anomaly detection task, based on either: (i) a comparison of an accuracy metric for the entire set in the anomaly detection task to an accuracy threshold for the entire set; or (ii) a comparison of a resource consumption metric for the entire set in the anomaly detection task to a resource consumption threshold for the entire set.

[0081] In some embodiments, controlling the defense agents 14 includes obtaining a defense agent utility metric for the set of defense agents 14 as a function of one or more accuracy metrics 20 and one or more resource consumption metrics 22, obtaining an attack utility metric as a function of the defense agent utility metric and an attack resource consumption metric that reflects the degree of resources required by an attacker to execute a coordinated attack against the communications network 10, and having the set 14S of defense agents 14 perform one or more anomaly detection tasks based on a comparison of the defense agent utility metric and the attack utility metric.

[0082] In one such embodiment, the utility metric of a defensive agent is U D =α1 M D +α2·D D -α3·(P D +N D )-α3·C D is determined as, where M D is the rate at which the defense agents 14 in a set 14S detect each feature of an anomaly, and D D is the rate at which a defense agent 14 in a set 14S detects an anomaly, P D is the false positive rate of the entire set, including the rate at which the defense agents 14 in the set 14S falsely detect anomalies, N Dis the false negative rate of the entire set, including the rate at which the defense agents 14 in the set 14S fail to detect anomalies, and C D is the resource consumption metric for the entire set, M D , D D , P D , N D and C D ∈[0,1], and α1,α2,α3∈[0,1] are weighting parameters. In this case, the attack utility metric is U A =-(U D +β·C A ) where C A is the attack resource consumption metric, β is a weight parameter, and β∈[0,1].

[0083] In this case, the control of the defensive agent 14 includes the following steps in the feature monitoring task to determine the respective features of the anomaly to be detected: (i) α3·C D >α1·M D , switch from an accuracy-enhancing mode in which all defense agents 14 in the set 14S perform feature monitoring tasks to a resource-saving mode in which at least one defense agent 14 in the set 14S does not perform feature monitoring tasks; or (ii) α3·(P D +N D )>α1·M D If , the set is switched from a resource-saving mode in which at least one of the defense agents 14 in the set 14S does not perform the feature monitoring task to a precision-improving mode in which all defense agents 14 in the set 14S perform the feature monitoring task. The control further D >α2·D D , switch the set from an accuracy-enhancing mode in which all defense agents 14 in the set 14S perform feature detection tasks to a resource-saving mode in which at least one defense agent 14 in the set 14S does not perform feature detection tasks; or (ii) α3·(P D +N D )>α2·D DIf , the set is switched from a resource saving mode in which at least one of the defense agents 14 in the set 14S does not perform the feature detection task to an accuracy improving mode in which all of the defense agents 14 in the set 14S perform the feature detection task. The control further includes the following steps in the decision making task of determining whether or not there is an anomaly based on the detected features: (i) α3·(P D +N D )≦α1·M D +α2·D D , switching from an accuracy-enhancing mode in which all defense agents 14 in the set 14S execute decisions to a resource-saving mode in which at least one defense agent 14 in the set 14S does not execute decisions; or (ii) α3·(P D +N D )>α1·M D +α2·D D If so, switch from a resource saving mode in which at least one of the defensive agents 14 in the set 14S does not perform a decision-making task to a precision improvement mode in which all defensive agents 14 in the set 14S perform a decision-making task.

[0084] In some examples, the one or more anomaly detection tasks include a feature monitoring task that determines features of each anomaly to be detected, a feature detection task that detects the determined features, and / or a decision-making task that determines whether or not an anomaly exists based on the detected features.

[0085] In some embodiments, the method for controlling the defense agents 14 in the set 14S controls whether or which defense agents 14 in the set 14S operate in a cooperative mode to cooperate with each other to perform anomaly detection, and whether or which defense agents 14 in the set 14S operate in a solo mode to perform anomaly detection without cooperating with each other, based on one or more accuracy metrics 20 and one or more resource consumption metrics 22.

[0086] In such an embodiment, one or more accuracy metrics 20 are obtained for each of the collaborative mode and the solo mode. In this case, the control includes operating the defense agents 14 in the set 14S in the collaborative mode if one or more collaborative mode trigger criteria are met, where the one or more collaborative mode trigger criteria include the solo mode set overall accuracy metric exceeding a solo mode accuracy threshold, and the set 14S overall accuracy metric is the set overall false positive rate metric. The control further includes controlling the defense agents 14 in the set 14S to operate in the solo mode if one or more of the solo mode trigger criteria are met, where one or more of the solo mode trigger conditions include the solo mode set overall accuracy metric in the collaborative mode falling below a collaborative mode accuracy threshold, and the set overall accuracy metric is the set overall false positive rate metric. In one embodiment, for example, the solo mode accuracy threshold is a function of the set-wide anomaly detection rate when the defensive agents 14 in the set 14S are operating in solo mode, and / or the collaborative mode accuracy threshold is a function of the set-wide anomaly detection rate when the defensive agents 14 in the set 14S are operating in collaborative mode. Or, further, if one or more resource consumption metrics 22 are obtained for each of the collaborative mode and the solo mode, the one or more solo mode trigger criteria further include the set-wide resource consumption metric obtained in collaborative mode exceeding the collaborative mode resource consumption threshold.

[0087] In some embodiments, the false positive rate metric for the entire suite of single modes is γ 2 · (P L +N L ) where γ2 is a weighting parameter, P L is the false positive rate for the entire set in the single mode, N L is the false negative rate of the entire set in the single mode. The false positive rate threshold for the single mode is γ1·D L where γ1 is a weight parameter and D Lis the anomaly detection rate for the entire set when operating in solo mode. The false positive rate metric for the entire set in collaborative mode is δ2·(P I +N I ), where δ2 is a weighting parameter, P I is the false positive rate for the entire set in the collaborative mode, N I is the false negative rate for the entire set in the collaborative mode. The false positive rate threshold for the collaborative mode is δ1·D I where δ1 is a weight parameter and D I is the anomaly detection rate for the entire set while operating in collaborative mode.

[0088] In some embodiments, the plurality of defense agents 14 includes a plurality of first tier defense agents 14 and one second tier defense agent distributed across the communications network 10. Each first tier defense agent 14 is configured to determine a respective characteristic of an anomaly within the communications network 10, detect the determined characteristic of the anomaly, and determine the presence or absence of the anomaly based on the detected characteristic. The second tier defense agent is configured to cooperate with the plurality of first tier defense agents 14 to assist in collaboratively determining whether an anomaly exists in the communications network 10.

[0089] In some embodiments, the control includes identifying defense agents in the set 14S as malicious based on one or more accuracy metrics 20 and one or more resource consumption metrics 22, and controlling the identified defense agents to stop anomaly detection.

[0090] The present embodiment also includes corresponding apparatus, for example, a security controller 18 configured to perform any of the steps of the security controller 18 described above.

[0091] This embodiment also includes a security controller 18 that includes a processing circuit and a power supply circuit. The processing circuit is configured to perform any of the steps of the security controller 18 described above. The power supply circuit is configured to provide power to the security controller 18.

[0092] Embodiments further include a security controller 18 including processing circuitry configured to perform any of the steps of any of the embodiments described above for security controller 18. In some embodiments, security controller 18 further includes communication circuitry.

[0093] The embodiment further includes a security controller 18 including a processing circuit and a memory, the memory including instructions executable by the processing circuit such that the security controller 18 is configured to perform any of the steps of any of the embodiments for the security controller 18 described above.

[0094] More specifically, the apparatus described above can perform the methods and other processes described herein by implementing any functional means, modules, units, or circuits. For example, in certain embodiments, the apparatus includes corresponding circuits or circuitry configured to perform steps illustrated in the method figures. The circuits or circuitry in this regard can include dedicated circuitry for performing specific functional processes and one or more microprocessors used in combination with memory. For example, the circuitry can include one or more microprocessors or microcontrollers and other digital hardware (e.g., digital signal processors (DSPs), dedicated digital logic, etc.). The processing circuitry is configured to execute program code stored in memory, and the memory can include one or more types of memory, such as read-only memory (ROM), random access memory, cache memory, flash memory devices, optical storage devices, etc. The program code stored in the memory may include program instructions for implementing one or more communication protocols (e.g., telecommunications and / or data communication protocols) and instructions for performing one or more techniques described herein. In embodiments employing memory, the memory stores program code that, when executed by one or more processors, performs the techniques described herein.

[0095] FIG. 15 illustrates a security controller 18 implemented in accordance with one or more embodiments. As shown, the security controller 18 includes a processing circuit 310 and a communication circuit 320. The communication circuit 320 is configured to transmit and / or receive information to and from one or more other nodes, for example, via any communication technology. The processing circuit 310 is configured to perform the processes described above, for example, by executing instructions stored in a memory 330, as shown in FIG. 14. In this regard, the processing circuit 310 may implement specific functional means, units, or modules.

[0096] Those skilled in the art will also appreciate that the present embodiment also includes a corresponding computer program.

[0097] The computer program includes instructions that, when executed on at least one processor of the security controller 18, cause the security controller 18 to perform any of the operations described above. In this regard, the computer program may include one or more code modules corresponding to the means or units described above.

[0098] Embodiments further include a carrier containing such a computer program, which may include any of an electronic, optical or radio signal or a computer-readable storage medium.

[0099] In this regard, the present embodiment further includes a computer program product recorded on a non-transitory computer-readable (recording or storage) medium that includes instructions that, when executed by a processor of security controller 18, cause security controller 18 to operate as described above.

[0100] Furthermore, the computer program product includes program code portions for performing the steps of any of the embodiments described herein when the computer program product is executed by the security controller 18. The computer program product can be recorded on a computer-readable recording medium.

[0101] FIG. 16 illustrates an example of a communication system 1600 to which an embodiment of the present disclosure can be applied.

[0102] In this example, the communications system 1600 includes a telecommunications network 1602 that includes an access network 1604 (e.g., a radio access network (RAN)) and a core network 1606 that includes one or more core network nodes 1608. The access network 1604 includes one or more access network nodes, including network nodes 1610a and 1610b (one or more of which are generally collectively referred to as network node 1610) or other similar Third Generation Partnership Project (3GPP) access nodes or non-3GPP access points. The network node 1610 enables direct or indirect connectivity of user equipment (UE), e.g., UEs 1612a, 1612b, 1612c, and 1612d (one or more of which are generally collectively referred to as UE 1612), to the core network 1606 via one or more wireless connections.

[0103] Examples of wireless communication of wireless connections include the transmission and / or reception of wireless signals using electromagnetic waves, radio waves, infrared waves, or other types of signals suitable for transmitting information without the use of wires, cables, or other material conductors. Additionally, in different embodiments, communication system 1600 can include wired or wireless networks, network nodes, UEs, and / or other components or systems that facilitate or participate in the communication of data and / or signals via wired or wireless connections. Communication system 1600 can include or interface with communication, telecommunications, data, cellular, wireless networks, and / or other similar types of systems.

[0104] The UE 1612 may be any of a variety of communications devices, including a wireless device, positioned, configured, or operable to communicate wirelessly with the network node 1610 and other communications devices. Similarly, the network node 1610 may be positioned, enabled, configured, and / or operative to communicate, directly or indirectly, with the UE 1612 and / or other network nodes or equipment within the telecommunications network 1602, to enable or provide network access (e.g., wireless network access), and / or to perform other functions, such as management, within the telecommunications network 1602.

[0105] In the illustrated example, the core network 1606 connects the network node 1610 to one or more hosts, such as the host 1616. These connections may be direct or indirect connections via one or more intermediary networks or devices. In other examples, the network nodes may be directly connected to the hosts. The core network 1606 includes one or more core network nodes (e.g., the core network node 1608) comprised of hardware and software components. The functionality of these components is substantially similar to that described with respect to the UEs, network nodes, and / or hosts, and therefore the descriptions are generally applicable to the corresponding components of the core network node 1608. Exemplary core network nodes include a Mobile Switching Center (MSC), a Mobility Management Entity (MME), a Home Subscriber Server (HSS), an Access and Mobility Management Function (AMF), a Session Management Function (SMF), an Authentication Server Function (AUSF), a Subscription Identifier Decryption Function (SIDF), a Unified Data Management (UDM), a Security Edge Protection Proxy (SEPP), a Network Exposure Function (NEF), and / or a User Plane Function (UPF) function.

[0106] The host 1616 may be owned or controlled by, or operated by, or on behalf of, a service provider other than the operator or provider of the access network 1604 and / or the telecommunications network 1602. The host 1616 may host a variety of applications to provide one or more services. Examples of such applications include live and pre-recorded audio / video content, data collection services that acquire and aggregate data about various environmental conditions detected by multiple UEs, analytics functions, social media, functions to control or operate remote devices, alarm and monitoring center functions, or other similar functions performed by a server.

[0107] 16 enables connectivity between UEs, network nodes, and hosts. In that sense, the communication system may be configured to operate according to a particular standard (e.g., including, but not limited to, Global System for Mobile Communications (GSM); Universal Mobile Telecommunications System (UMTS); Long Term Evolution (LTE) and / or other suitable 2G, 3G, 4G, 5G standards, or applicable future generation standards (e.g., 6G); Wireless Local Area Network (WLAN) standards, such as the Institute of Electrical and Electronics Engineers (IEEE) 802.11 standard (WiFi); and / or other suitable wireless communication standards (e.g., Worldwide Interoperability for Microwave Access (WiMax), Bluetooth, Z-Wave, Near Field Communications (NFC), ZigBee, LiFi, and / or Low Power Wide Area Network (LPWAN) standards (e.g., LoRa and Sigfox)).

[0108] In some examples, the communication network 1602 is a cellular network that implements functionality compliant with 3GPP standards. Thus, the communication network 1602 may support network slicing to provide different logical networks to different devices connected to the communication network 1602. For example, the communication network 1602 may provide Ultra-Reliable Low Latency Communications (URLLC) services to some UEs, enhanced Mobile Broadband (eMBB) services to other UEs, and massive machine-type communications (mMTC) / massive IoT services to still other UEs.

[0109] In some examples, the UE 1612 is configured to transmit and / or receive information without direct human interaction. For example, the UE may be designed to transmit information to the access network 1604 when triggered by an internal or external event or in response to a request from the access network 1604. Furthermore, the UE may be configured to operate in a single-RAT or multi-RAT mode, or a multi-standard mode. For example, the UE may be configured to operate with Wi-Fi, New Radio (NR), or LTE, or a combination thereof, and may support Multi-Radio Dual Connectivity (MR-DC), such as Evolved UMTS Terrestrial Radio Access Network (E-UTRAN) New Radio-Dual Connectivity (EN-DC).

[0110] In this example, the hub 1614 communicates with the access network 1604 and brokers indirect communications between one or more UEs (e.g., UEs 1612c and / or 1612d) and a network node (e.g., network node 1610b). In some examples, the hub 1614 may be a controller, a router, a content source, an analytics device, or any other communications device described herein with respect to a UE. For example, the hub 1614 may be a broadband router that allows the UE to access the core network 1606. In another example, the hub 1614 may be a controller that sends commands or instructions to one or more actuators in the UE. The commands or instructions may be received from executable code, scripts, processes, or other instructions in the UE, the network node 1610, or the hub 1614. As another example, the hub 1614 may be a data collector that serves as a temporary storage area for UE data and, in some examples, analyzes or otherwise processes the data. As another example, the hub 1614 may be a content source. For example, if the UE is a VR headset, display, speaker, or other media distribution device, the hub 1614 may obtain VR assets, video, audio, or other media or data related to sensory information via a network node, which the hub 1614 may then provide to the UE directly or after performing local processing or adding additional local content. In yet another example, the hub 1614 may act as a proxy server or orchestrator for the UEs, particularly if one or more UEs are low-power IoT devices.

[0111] The hub 1614 may maintain a constant / persistent or intermittent connection with the network node 1610b. The hub 1614 allows different communication schemes and / or schedules between the hub 1614 and the UEs (e.g., UEs 1612c and / or 1612d) and between the hub 1614 and the core network 1606. In other examples, the hub 1614 connects to the core network 1606 and / or one or more UEs via a wired connection. Furthermore, the hub 1614 may be configured to connect to an M2M service provider via the access network 1604 or to another UE via a direct connection. In some scenarios, a UE establishes a wireless connection with the network node 1610 while remaining connected via a wired or wireless connection through the hub 1614. In some embodiments, the hub 1614 is a dedicated hub, i.e., a hub whose primary function is to route communications between the UEs and the network node 1610b. In other embodiments, the hub 1614 may be a non-dedicated hub. That is, a device that has the functionality to route communications between the UE and the network node 1610b, but also has the ability to act as the start and / or end point of communications for a particular data channel.

[0112] 17 is a block diagram of a host 1700 in accordance with various aspects described herein, which may be an example of host 1616 in FIG. 16. As used herein, host 1700 may consist of or include various combinations of hardware and software, including processing resources in a single server, a blade server, a cloud-implemented server, a distributed server, a virtual machine, a container, or a server farm. Host 1700 may provide one or more services to one or more UEs.

[0113] Host 1700 includes processing circuitry 1702 operatively connected via bus 1704 to input / output interface 1706, network interface 1708, power supply 1710, and memory 1712. In other embodiments, other components may be included. The functionality of these components is substantially similar to the devices described in previous figures, such as Figures 17 and 18, and therefore the descriptions thereof are generally applicable to the corresponding components of host 1700.

[0114] Memory 1712 includes one or more computer programs (including host application programs 1714) and data 1716. Data 1716 includes, for example, user data, such as data generated by a UE for host 1700 or data generated by host 1700 for a UE. An embodiment of host 1700 may use a subset or all of the components shown. Host application programs 1714 are implemented in a container-based architecture and support video codecs (e.g., Versatile Video Coding (VVC), High Efficiency Video Coding (HEVC), Advanced Video Coding (AVC), MPEG, VP9) and audio codecs (e.g., FLAC, Advanced Audio Coding (AAC), MPEG, G.711), including transcoding for multiple different classes, types, or implementations of UE (e.g., mobile phones, desktop computers, wearable display systems, heads-up display systems). The host application program 1714 provides user authentication and license checks and periodically reports health status, route, and content availability to a central node, such as a device at the edge of the core network. Thus, the host 1700 can select and / or designate different hosts for over-the-top services for the UE. The host application program 1714 supports a variety of protocols, including HTTP Live Streaming (HLS) protocol, Real-Time Messaging Protocol (RTMP), Real-Time Streaming Protocol (RTSP), and Dynamic Adaptive Streaming over HTTP (MPEG-DASH).

[0115] While the computing devices (e.g., UEs, network nodes, hosts) described herein may include a combination of the illustrated hardware components, other embodiments may include computing devices with different combinations of components. These computing devices should be understood to include any appropriate hardware and / or software combination necessary to perform the tasks, functions, and methods disclosed herein. The determining, calculating, obtaining, or similar operations described herein may be performed by a processing circuit. The processing circuit processes information, for example, by transforming the obtained information into other information, comparing the obtained or transformed information with information stored in the network node, and / or performing one or more operations based on the obtained or transformed information, resulting in a decision. Furthermore, while components are depicted as a single box within a larger box or nested within multiple boxes, in reality, the computing device may be comprised of multiple different physical components that make up a single illustrated component, and functionality may be divided among the separate components. For example, a communication interface may be configured to include any of the components described herein, or the functionality of a component may be divided between a processing circuit and a communication interface. In another example, the less computationally intensive functions of such a component may be implemented in software or firmware, while the more computationally intensive functions may be implemented in hardware.

[0116] In certain embodiments, some or all of the functionality described herein is provided by a processing circuit executing instructions stored in a memory. This memory, in certain embodiments, may be a computer program product in the form of a non-transitory computer-readable storage medium. In other embodiments, some or all of the functionality is provided by the processing circuit without executing instructions stored on a separate or independent device-readable storage medium (e.g., hardwired). In any of these particular embodiments, the processing circuit can be configured to perform the described functionality regardless of whether it executes instructions stored on a non-transitory computer-readable storage medium. Benefits provided by such functionality are not limited to the processing circuit alone or other components of the computing device, but are enjoyed by the computing device as a whole, and / or by end users and wireless networks in general.

[0117] In particular, those skilled in the art may devise modifications and other embodiments of the present specification based on the teachings provided in the foregoing description and the associated drawings of the present specification. Therefore, the present specification is not limited to the specific embodiments disclosed, and modifications and other embodiments are understood to be included within the scope of the present specification. Even if specific terms are used herein, they are used in a generic and descriptive sense only and are not intended to be limiting.

Claims

1. A method performed by a security controller (18) for a communications network (10) having a set (14S) of multiple defense agents (14) distributed across the communications network (10) for anomaly detection in the communications network (10), the method comprising: obtaining (200) one or more accuracy metrics (20) that characterize how accurately the set (14S) of the plurality of defensive agents (14) detect anomalies in the communications network (10); obtaining (210) one or more resource consumption metrics (22) characterizing how the set (14S) of the plurality of defensive agents (14) consume resources of the communications network (10); controlling (220) the plurality of defense agents (14) of the set (14S) based on the one or more accuracy metrics (20) and the one or more resource consumption metrics (22); A method comprising:

2. The one or more accuracy metrics (20) are: a set-wide false positive rate, which includes the rate at which the set (14S) of the plurality of defense agents (14) erroneously detects an anomaly; a set-wide false negative rate, which includes the rate at which the set (14S) of the plurality of defense agents (14) fail to detect an anomaly; and / or a set-wide false rate, which includes a combination of the set-wide false positive rate and the set-wide false negative rate; and / or For each of the plurality of defense agents (14) in the set (14S), an agent-specific false positive rate comprising the rate at which the defense agent erroneously detects an anomaly, an agent-specific false negative rate comprising the rate at which the defense agent fails to detect an anomaly, and / or an agent-specific false rate comprising a combination of the agent-specific false positive rate and the agent-specific false negative rate. The method of claim 1 , comprising:

3. 3. The method of claim 1, wherein controlling the set of the plurality of defensive agents includes controlling whether and / or how each defensive agent in the set performs each of one or more anomaly detection tasks based on the one or more accuracy metrics and the one or more resource consumption metrics.

4. 4. The method of claim 1, wherein controlling the set of the plurality of defensive agents includes controlling, for each of one or more anomaly detection tasks, which one or more defensive agents of the set of the plurality of defensive agents perform the anomaly detection task and which one or more defensive agents, if any, of the set of the plurality of defensive agents do not perform the anomaly detection task based on the one or more accuracy metrics and the one or more resource consumption metrics.

5. The controlling includes, for at least one of the one or more anomaly detection tasks: making a decision to switch the set from an accuracy improvement mode, in which all of the defense agents (14) in the set (14S) perform the anomaly detection task, to a resource conservation mode, in which at least one defense agent (14) in the set (14S) does not perform the anomaly detection task, based on a comparison of the resource consumption metrics of the entire set and a resource consumption threshold for the anomaly detection task of the entire set; Based on the determination, determining which one or more defense agents (14) in the set (14S) will still perform the anomaly detection task in the resource conservation mode and which one or more defense agents (14) in the set (14S) will not perform the anomaly detection task in the resource conservation mode based on an agent-specific accuracy metric of each defense agent (14); The method of claim 4, comprising:

6. The controlling includes, for at least one of the one or more anomaly detection tasks: based on a comparison of the entire set of accuracy metrics to an overall set of accuracy thresholds for the anomaly detection task, or a comparison of the entire set of resource consumption metrics to an overall set of resource consumption thresholds for the anomaly detection task; 6. The method of claim 4, comprising making a decision to switch from a resource conservation mode, in which at least one defensive agent in the set does not perform the anomaly detection task, to an accuracy improvement mode, in which all defensive agents in the set perform the anomaly detection task.

7. The controlling comprises: obtaining the set of defense agent utility metrics for the defense agent (14) as a function of the one or more accuracy metrics (20) and the one or more resource consumption metrics (22); obtaining an attack utility metric as a function of the defensive agent utility metric and an attack resource consumption metric that reflects the degree of resources required by an attacker to perform a coordinated attack against the communication network; controlling whether the plurality of defensive agents (14) of the set (14S) perform one or more anomaly detection tasks based on a comparison of the defensive agent utility metric and the attack utility metric; 7. The method of claim 1, comprising:

8. The defensive agent utility metric is U D = α 1 ・M D +α 2 ・D D -α 3 ・(P D +N D ) -α 3 ・C D is determined as M D is the proportion of the set (14S) of the plurality of defense agents (14) that determine each characteristic of an anomaly, D D is the rate at which the plurality of defense agents (14) in the set (14S) detect anomalies, P D is the false positive rate of the entire set (14S), which includes the rate at which the plurality of defense agents (14) in the set (14S) falsely detect an anomaly; N D is the false negative rate of the entire set (14S), which includes the rate at which the plurality of defense agents (14) in the set (14S) fail to detect an anomaly; C D is the resource consumption metric for the entire set, M D , D D , P D , N D and C D ∈[0,1] and α 1 , α 2 , α 3 ∈[0,1] is a weight parameter, The attack utility metric is U A =-(U D +β・C A ) is determined as C A is the attack resource consumption metric, β is a weight parameter, and β∈[0,1]. The method of claim 7.

9. The controlling comprises: For the feature monitoring task, which involves determining the features of each of the anomalies to be detected: α 3 ・C D >α 1 ・M D If so, switching the set from an accuracy-enhancing mode, in which all defensive agents (14) in the set (14S) perform the feature monitoring task, to a resource-saving mode, in which at least one defensive agent (14) in the set (14S) does not perform the feature monitoring task; or α 3 ・(P D +N D ) > α 1 ・M D if so, switching the set from a resource-saving mode, in which at least one defensive agent (14) in the set (14S) does not perform the feature monitoring task, to an accuracy-enhancing mode, in which all defensive agents (14) in the set (14S) perform the feature monitoring task; For a feature detection task that includes detecting the determined features: α 3 ・C D >α 2 ・D D If so, switching the set from an accuracy-improving mode, in which all defensive agents (14) in the set (14S) perform the feature detection task, to a resource-saving mode, in which at least one defensive agent (14) in the set (14S) does not perform the feature detection task; or α 3 ・(P D +N D ) > α 2 ・D D if so, switching the set from a resource-saving mode, in which at least one defensive agent (14) in the set (14S) does not perform the feature detection task, to an accuracy-improving mode, in which all defensive agents (14) in the set (14S) perform the feature detection task; For decision-making tasks that involve making a decision about whether an anomaly exists based on detected features: α 3 ・(P D +N D ) ≦α 1 ・M D +α 2 ・D D If so, switching the set from an accuracy-enhancing mode, in which all defense agents (14) in the set (14S) perform the decision-making task, to a resource-saving mode, in which at least one defense agent (14) in the set (14S) does not perform the decision-making task; or α 3 ・(P D +N D ) > α 1 ・M D +α 2 ・D D if so, switching the set from a resource-saving mode, in which at least one defensive agent (14) in the set (14S) does not perform the decision-making task, to a precision-improving mode, in which all defensive agents (14) in the set (14S) perform the decision-making task; The method of claim 8, comprising:

10. The one or more anomaly detection tasks: a feature monitoring task that includes determining the features of each of the anomalies to be detected; and / or a feature detection task comprising detecting said determined features; and / or Decision-making tasks, including making a decision about whether an anomaly exists based on the detected features 10. The method of any one of claims 3 to 9, comprising:

11. Controlling the set (14S) of the plurality of defense agents (14) comprises:

11. The method of claim 1, further comprising: controlling, based on the one or more accuracy metrics and the one or more resource consumption metrics, which one or more defense agents in the set operate in a cooperative mode in which they cooperate with each other to perform anomaly detection; and controlling which one or more defense agents in the set operate in a solo mode in which they do not cooperate with each other to perform anomaly detection.

12. The one or more accuracy metrics (20), obtained for each of the cooperative mode and the solo mode, and the controlling includes: controlling the set (14S) of multiple defense agents (14) to operate in the collaborative mode when each of one or more collaborative mode trigger criteria is satisfied, wherein the one or more collaborative mode trigger criteria include a set-wide accuracy metric for the solo mode exceeding an accuracy threshold for the solo mode, and the set-wide accuracy metric is a set-wide false rate metric; controlling the set (14S) of multiple defense agents (14) to operate in the solo mode when each of one or more solo mode trigger criteria is satisfied, wherein the one or more solo mode trigger criteria include a set-wide accuracy metric for the collaborative mode being below an accuracy threshold for the collaborative mode, and the set-wide accuracy metric is a set-wide false rate metric; The method of claim 11 , comprising:

13. 13. The method of claim 12, wherein the accuracy threshold for the solo mode is a function of an anomaly detection rate for the entire set (14S) of the multiple defense agents (14) while they are operating in the solo mode, and / or the accuracy threshold for the collaborative mode is a function of an anomaly detection rate for the entire set (14S) of the multiple defense agents (14) while they are operating in the collaborative mode.

14. 14. The method of claim 12 or 13, wherein the one or more resource consumption metrics (22) are obtained for each of the collaborative mode and the solo mode, and the one or more solo mode trigger criteria further include an entire set of resource consumption metrics obtained for the collaborative mode exceeding a resource consumption threshold for the collaborative mode.

15. The set of overall false probability metrics for the single mode is γ 2 ・(P L +N L ) and γ 2 is a weight parameter, P L is the false positive rate for the entire set for the single mode, N L is the false negative rate for the entire set for the single mode, The false rate threshold for the single mode is γ 1 ・D L is equal to γ 1 is a weight parameter, D L is the overall set fault detection rate while operating in the standalone mode, The set-wide false rate metric for the cooperative mode is δ 2 ・(P I +N I ) and δ 2 is a weight parameter, P I is the set-wide false positive rate for the collaborative mode, N I is the set-wide false negative rate for the collaborative mode, The false rate threshold for the cooperative mode is δ 1 ・D I is equal to δ 1 is a weight parameter, D I is the overall anomaly detection rate for the set while operating in the cooperative mode; 15. The method according to any one of claims 12 to 14.

16. 16. The method of claim 1, wherein the plurality of defense agents (14) includes a plurality of first-tier defense agents (14) and one second-tier defense agent distributed within the communication network (10), each of the plurality of first-tier defense agents (14) configured to determine characteristics of each anomaly within the communication network (10), detect the determined characteristics of the anomaly, and make a determination as to whether an anomaly exists based on the detected characteristics, and the second-tier defense agent configured to cooperate with the plurality of first-tier defense agents (14) to assist in cooperatively determining whether an anomaly exists within the communication network (10).

17. The controlling comprises: identifying a defensive agent in the set (14S) as malicious based on the one or more accuracy metrics (20) and the one or more resource consumption metrics (22); controlling the identified defensive agent to stop detecting anomalies; 17. The method of any one of claims 1 to 16, comprising:

18. A security controller (18) for a communication network (10), wherein a set (14S) of multiple defense agents (14) are distributed in the communication network (10) for detecting anomalies in the communication network (10), the security controller (18) comprising: obtaining one or more accuracy metrics (20) that characterize how accurately the set (14S) of the plurality of defensive agents (14) detects anomalies in the communications network (10); obtaining one or more resource consumption metrics (22) characterizing how the set (14S) of the plurality of defensive agents (14) consume resources of the communications network (10); controlling the set (14S) of the plurality of defense agents (14) based on the one or more accuracy metrics (20) and the one or more resource consumption metrics (22); A security controller (18) configured to:

19. configured to carry out the method of any one of claims 2 to 17, A security controller (18) according to claim 18.

20. 18. A computer program comprising instructions which, when executed by at least one processor of a security controller (18), cause the security controller (18) to carry out the method of any one of claims 1 to 17.

21. 21. A carrier containing the computer program of claim 20, the carrier being one of an electrical signal, an optical signal, a radio signal, or a computer readable storage medium.

22. A security controller (18) for a communications network (10), the communications network (10) having a set (14S) of multiple defense agents (14) distributed therein for detecting anomalies in the communications network (10), the security controller (18) having a processing circuit (310), the processing circuit (310) comprising: obtaining one or more accuracy metrics (20) that characterize how accurately the set (14S) of the plurality of defensive agents (14) detects anomalies in the communications network (10); obtaining one or more resource consumption metrics (22) characterizing how the set (14S) of the plurality of defensive agents (14) consume resources of the communications network (10); controlling the set (14S) of the plurality of defense agents (14) based on the one or more accuracy metrics (20) and the one or more resource consumption metrics (22); A security controller (18) configured to:

23. The processing circuit (310) is configured to perform a method according to any one of claims 2 to 17. A security controller (18) according to claim 22.

Citation Information

Patent Citations

  • Device and program for detecting improper access

    JP2005250802A

  • Information protection method, information security management device, information security management system and information security management program

    JP2006023916A

  • Intrusion detecting and supervising system

    JP2006173781A

  • Automated deployment of protection agents to devices connected to distributed computer networks

    JP2009507454A

  • Computer defenses and counterattacks

    US20160182533A1