Security agent device and a method therefor

A set of security agents in the communication network monitors each other, using honeypot agents to entice malicious behaviors and evaluate metrics for accurate detection, addressing the vulnerability of NWDAF compromise and zero-day attacks.

WO2025165269A1PCT designated stage Publication Date: 2025-08-07TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
PCT/SE2024/050086
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-02-01
Publication Date
2025-08-07

AI Technical Summary

Technical Problem

Existing network security systems, such as the Network Data Analytics Function (NWDAF) in 5G communication networks, are vulnerable to compromise by attackers collaborating to infect the NWDAF, leading to widespread cyber-attacks, especially with zero-day attacks that are unknown to the network.

Method used

Deploy a set of security agents in the communication network that mutually monitor each other, with some acting as honeypot agents to entice malicious behaviors, and evaluate behaviors using metrics to detect unknown attacks, including a first metric for accuracy and a second metric for detection rate, to safeguard against compromised agents.

Benefits of technology

Enables robust detection of unknown attacks while securing the network against compromised security agents, effectively identifying and mitigating zero-day attacks through a zero-trust architecture.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure SE2024050086_07082025_PF_FP_ABST
    Figure SE2024050086_07082025_PF_FP_ABST
Patent Text Reader

Abstract

A security agent device (14D) hosts a centralized or leader security agent (14LC) included in a set (14S) of security agents (14) for a communication network (10) The device (14D) controls the one or more of the security agent(s) (14) to operate as honeypot security agent(s) (14H) that attempt to entice an attack (13). The device (14D) evaluates each monitored security agent (14) for behaviors characteristic of an unknown attack (13U). For each monitored security agent (14M) in this regard, the device (14D) obtains first and second metrics (19-1, 19- 2) and decides based on those metrics (19-1, 19-2) whether behaviors of the monitored security agent (14M) are features of an unknown attack (13U). The first metric (19-1) reflects how accurately or inaccurately the security agents (14) cooperatively detect behaviors of the monitored security agent (14M) as being features of an attack (13). The second metric (19-2) reflects a rate at which the security agents (14) cooperatively detect behaviors of the monitored security agent (14M) as being features of an attack (13).
Need to check novelty before this filing date? Find Prior Art

Description

[0001] SECURITY AGENT DEVICE AND A METHOD THEREFOR

[0002] TECHNICAL FIELD

[0003] The present application relates generally to a method performed by a security agent device for a communication network, security agent devices, a non-transitory computer- readable storage medium, a computer program and a carrier.

[0004] BACKGROUND

[0005] In a 5G communication network, a Network Data Analytics Function (NWDAF) analyzes data from the network in order to generate insights and take appropriate actions, e.g., to enhance end-user experience. The 3rdGeneration Partnership Project (3GPP) Technical Report (TR) 23.700-91 V17.0.0 has identified one use of the NWDAF in this regard as detecting cyber-attacks by monitoring events and data packets in user equipments (UEs) and the network, with the support of machine-learning algorithms. To detect cyber-attacks, the NWDAF can collaborate with UEs and other network functions (NFs) to collect data as input and provide alerts of anomaly events as outputs to Operation and Maintenance (OAM) and other NFs which have subscribed to the alerts so that they can take proper action. Furthering the NWDAF’s role in cyber-attack detection, Y. Yuan, et. al, “Insight of Anomaly Detection with NWDAF in 5G”, IEEE CITS, 2022, proposes a collaborative NWDAF framework for abnormal behavior detection in order to improve 5G network security against network attacks.

[0006] Problematically, though, these known approaches to network security assume the NWDAF is trusted and fail to account for the possibility that the NWDAF may itself be compromised. Known approaches for example prove vulnerable to a more complex or sophisticated attack where attackers collaborate between each other in order to infect the NWDAF, leading to the NWDAF itself behaving as a malicious NF. An infected NDWAF could then cause widespread compromise of cyber-attack detection in the network. The vulnerability of known approaches proves true especially with regard to new attacks that the network has not detected before and are therefore unknown to the network, e.g., so-called zero-day attacks. Challenges therefore remain as to how to exploit an NWDAF for detecting cyberattacks while securing the network against a compromised NWDAF, even with regard to zero-day attacks or other attacks unknown to the network.

[0007] SUMMARY

[0008] An object of the invention is to enable attack detection in a communication network which is robust as against internal network compromise and as against attacks like zero-day attacks that are unknown to the network.

[0009] Towards this end, some embodiments deploy a set of security agents in a communication network for attack detection, but account for the possibility that one or more of those security agents might be compromised from a security perspective. Indeed, rather than outright trusting each other, the security agents in the set monitor one another for malicious behaviors. In fact, one or more so-called honeypot agents in the set aim to entice malicious behaviors out of any security agents in the set that might be compromised, with the goal of ferreting out zero-day attacks or other attacks not yet known to the network. The behaviors of each monitored security agent in this regard are scrutinized for whether or not they constitute features of an unknown attack. Such scrutiny may be performed on the basis of metrics obtained for a monitored security agent reflecting the accuracy with which, and the rate at which, the security agents in the set cooperatively detect behaviors of the monitored security agent as being features of an attack. Some embodiments thereby advantageously enable even unknown attack detection via security agents while safeguarding against security agent compromise.

[0010] More particularly, embodiments herein include a method performed by a security agent device configured to host a centralized or leader security agent included in a set of security agents for a communication network. The security agents in the set mutually monitor each other. The method comprises controlling one or more security agents in the set to operate as one or more honeypot security agents that attempt to entice an attack on the communication network. The method also comprises evaluating each of one or more monitored security agents in the set for behaviors characteristic of an unknown attack on the communication network. An unknown attack is a type of attack that the security agents have not detected before. In some embodiments, evaluating each of one or more monitored security agents in the set comprises, for each of the one or more monitored security agents, obtaining a first metric for the monitored security agent, obtaining a second metric for the monitored security agent, and deciding, based on the first metric and the second metric, whether or not behaviors of the monitored security agent are features of an unknown attack on the communication network. The first metric for a monitored security agent reflects how accurately or inaccurately the security agents in the set cooperatively detect behaviors of the monitored security agent as being features of an attack on the communication network. And the second metric for a monitored security agent reflecting a rate at which the security agents in the set cooperatively detect behaviors of the monitored security agent as being features of an attack on the communication network.

[0011] In some embodiments, deciding whether or not behaviors of a monitored security agent are features of an unknown attack on the communication network is based on whether or not the second metric for the monitored security agent exceeds the first metric for the monitored security agent.

[0012] In some embodiments, the second metric for a monitored security agent reflects an attack detection rate for the monitored security agent, a known attack feature determination rate for the monitored security agent, and an unknown attack feature determination rate for the monitored security agent. The attack detection rate for the monitored security agent is the rate at which the security agents in the set cooperatively detect behaviors of the monitored security agent as being features of an attack on the communication network. The known attack feature determination rate for the monitored security agent comprises a rate at which the security agents in the set cooperatively determine features of known attacks from monitoring behaviors of the monitored security agent, where a known attack is a type of attack that the security agents has detected before. The unknown attack feature determination rate for the monitored security agent comprises a rate at which the security agents in the set cooperatively determine features of unknown attacks from monitoring behaviors of the monitored security agent.

[0013] In some embodiments, deciding whether or not behaviors of a monitored security agent are features of an unknown attack on the communication network is based on the first metric for the monitored security agent, the second metric for the monitored security agent, the known attack feature determination rate for the monitored security agent, and the unknown attack feature determination rate for the monitored security agent.

[0014] In some embodiments, deciding whether or not behaviors of a monitored security agent are features of an unknown attack on the communication network comprises deciding that behaviors of the monitored security agent are features of an unknown attack on the communication network if the first metric for the monitored security agent exceeds the second metric for the monitored security agent and the unknown attack feature determination rate for the monitored security agent exceeds the known attack feature determination rate for the monitored security agent.

[0015] In some embodiments, said evaluating further comprises evaluating each of the one or more monitored security agents for behaviors characteristic of a known attack on the communication network. In some embodiments, evaluating each of the one or more monitored security agents comprises, for each of the one or more monitored security agents, deciding that behaviors of the monitored security agent are features of a known attack on the communication network if the first metric for the monitored security agent exceeds the second metric for the monitored security agent and the known attack feature determination rate for the monitored security agent exceeds the unknown attack feature determination rate for the monitored security agent.

[0016] In some embodiments, a weighted attack detection rate for a monitored security agent is the attack detection rate for the monitored security agent as weighted by a weight parameter. In some embodiments, said evaluating further comprises, for each of the one or more monitored security agents, deciding that behaviors of the monitored security agent are benign if the second metric for the monitored security agent exceeds the first metric for the monitored security agent. In some embodiments, the second metric for a monitored security agent is obtained as UCDS= al * D +a2 +a3 * F, where KF is the known attack feature determination rate for the monitored security agent, NF is the unknown attack feature determination rate for the monitored security agent, AD is the attack detection rate for the monitored security agent, and a- , a 2 are each a weight parameter G [0,1] .

[0017] In some embodiments, the first metric for a monitored security agent is a function of a false positive rate and / or a false negative rate for the monitored security agent. In some embodiments, the false positive rate for the monitored security agent is a rate at which the security agents in the set incorrectly detect behaviors of the monitored security agent as being features of an attack on the communication network, and the false negative rate is a rate at which the security agents in the set fail to detect behaviors of the monitored security agent as being features of an attack on the communication network.

[0018] In some embodiments, the first metric for a monitored security agent is obtained as FN, where FP is the false positive rate for the monitored security agent and FN is the false negative rate for the monitored security agent, and e and e g are each a weight parameter G [0,1] .

[0019] In some embodiments, said evaluating is performed during each of multiple evaluation intervals, and the method comprises, in between at least some evaluation intervals, adapting one or more security parameters of one or more of the security agents in the set as needed to increase the second metric for the monitored security agent and / or decrease the first metric for the monitored security agent.

[0020] In some embodiments, one or more security agents in the set are deployed at one or more respective radio network nodes in the communication network. In other alternative or additional embodiments, one or more security agents in the set are deployed at one or more respective edge computing servers in the communication network. In yet other alternative or additional embodiments, one or more security agents in the set are deployed at one or more network data analytics functions, NWDAFs, in the communication network. In still yet other alternative or additional embodiments, one or more security agents in the set are deployed at one or more access and mobility management functions, AMFs, in the communication network.

[0021] In some embodiments, the security agents in the set include the one or more honeypot security agents that each attempt to entice an unknown attack on the communication network, by intentionally attracting an attack on the honeypot security agent or by mimicking malicious cooperation with the monitored security agent, and that each monitor the monitored security agent to determine features of unknown attacks. In some embodiments, one or more follower security agents that each monitor the monitored security agent to determine features of known attacks according to a rule-based algorithm that defines features of known attacks in terms of one or more rules. In some embodiments, a leader security agent that executes a hybrid attack detection algorithm to detect an attack on the communication network based on features determined by the one or more honeypot security agents and the one or more follower security agents. In some embodiments, according to the hybrid attack detection algorithm the leader security agent selects between (i) a machine learning algorithm trained, using training data, to detect attacks by the monitored security agent; and (ii) a rule-based algorithm that detects attacks by the monitored security agent based on one or more rules.

[0022] In some embodiments, the method further comprises, for each of the one or more monitored security agents, controlling with which role, if any, the monitored security agent operates for detecting attacks in the communication network, based on the first metric and the second metric for the monitored security agent.

[0023] In some embodiments, controlling with which role, if any, a monitored security agent operates comprises activating the monitored security agent in one of multiple possible roles if the second metric for the monitored security agent exceeds the first metric for the monitored security agent. In other embodiments, controlling with which role, if any, a monitored security agent operates comprises deactivating the monitored security agent from operating in any of the multiple possible roles if the first metric for the monitored security agent exceeds the second metric for the monitored security agent.

[0024] In some embodiments, activating a monitored security agent in one of the multiple possible roles comprises activating the monitored security agent in a role as a honeypot security agent if a weighted attack detection rate for the monitored security agent exceeds the first metric for the monitored security agent. In some embodiments, an attack detection rate for the monitored security agent is the rate at which the security agents in the set cooperatively detect behaviors of the monitored security agent as being features of an attack on the communication network. In some embodiments, the weighted attack detection rate for the monitored security agent is the attack detection rate for the monitored security agent as weighted by a weight parameter.

[0025] In some embodiments, activating a monitored security agent in one of the multiple possible roles comprises activating the monitored security agent in a role as a follower security agent if a known attack feature determination rate for the monitored security agent exceeds an unknown attack feature determination rate for the monitored security agent. In some embodiments, the known attack feature determination rate for the monitored security agent comprises a rate at which the security agents in the set cooperatively determine features of known attacks from monitoring behaviors of the monitored security agent. In some embodiments, a known attack is a type of attack that the security agents has detected before, and the unknown attack feature determination rate for the monitored security agent comprises a rate at which the security agents in the set cooperatively determine features of unknown attacks from monitoring behaviors of the monitored security agent.

[0026] In some embodiments, activating a monitored security agent in one of the multiple possible roles comprises activating the monitored security agent in a role as a leader security agent if an unknown attack feature determination rate for the monitored security agent exceeds a known attack feature determination rate for the monitored security agent. In some embodiments, the known attack feature determination rate for the monitored security agent comprises a rate at which the security agents in the set cooperatively determine features of known attacks from monitoring behaviors of the monitored security agent. In some embodiments, a known attack is a type of attack that the security agents has detected before, and the unknown attack feature determination rate for the monitored security agent comprises a rate at which the security agents in the set cooperatively determine features of unknown attacks from monitoring behaviors of the monitored security agent.

[0027] Other embodiments herein include a security agent device configured to host a centralized or leader security agent included in a set of security agents for a communication network. In some embodiments, the security agents in the set mutually monitor each other. The security agent device is configured to control one or more security agents in the set to operate as one or more honeypot security agents that attempt to entice an attack on the communication network. In some embodiments, the security agent device is configured to evaluate each of one or more monitored security agents in the set for behaviors characteristic of an unknown attack on the communication network. An unknown attack is a type of attack that the security agents have not detected before. In some embodiments, evaluating each of one or more monitored security agents in the set comprises, for each of the one or more monitored security agents, obtaining a first metric for the monitored security agent, obtaining a second metric for the monitored security agent, and deciding, based on the first metric and the second metric, whether or not behaviors of the monitored security agent are features of an unknown attack on the communication network. The first metric for a monitored security agent reflects how accurately or inaccurately the security agents in the set cooperatively detect behaviors of the monitored security agent as being features of an attack on the communication network. And the second metric for a monitored security agent reflecting a rate at which the security agents in the set cooperatively detect behaviors of the monitored security agent as being features of an attack on the communication network.

[0028] In some embodiments, the security agent device is configured to perform the steps described above for a security agent device configured to host a centralized or leader security agent included in a set of security agents for a communication network.

[0029] In some embodiments, a computer program comprising instructions which, when executed by at least one processor of a security agent device, causes the security agent device to perform the steps described above for a security agent device configured to host a centralized or leader security agent included in a set of security agents for a communication network. In some embodiments, a carrier containing the computer program is one of an electronic signal, optical signal, radio signal, or computer-readable storage medium.

[0030] Other embodiments herein include a security agent device configured to host a centralized or leader security agent included in a set of security agents for a communication network, wherein the security agents in the set mutually monitor each other. In some embodiments, the security agent device comprises processing circuitry configured to control one or more security agents in the set to operate as one or more honeypot security agents that attempt to entice an attack on the communication network. In some embodiments, the security agent device comprises processing circuitry configured to evaluate each of one or more monitored security agents in the set for behaviors characteristic of an unknown attack on the communication network. An unknown attack is a type of attack that the security agents have not detected before. In some embodiments, evaluating each of one or more monitored security agents in the set comprises, for each of the one or more monitored security agents, obtaining a first metric for the monitored security agent, obtaining a second metric for the monitored security agent, and deciding, based on the first metric and the second metric, whether or not behaviors of the monitored security agent are features of an unknown attack on the communication network. The first metric for a monitored security agent reflects how accurately or inaccurately the security agents in the set cooperatively detect behaviors of the monitored security agent as being features of an attack on the communication network. And the second metric for a monitored security agent reflecting a rate at which the security agents in the set cooperatively detect behaviors of the monitored security agent as being features of an attack on the communication network.

[0031] In some embodiments, the processing circuitry is configured to perform the steps described above for a security agent device configured to host a centralized or leader security agent included in a set of security agents for a communication network.

[0032] Other embodiments herein include a non-transitory computer-readable storage medium on which is stored a computer program comprising instructions. In some embodiments, the computer program, when executed by a processor of a security agent device configured to host a centralized or leader security agent included in a set of security agents that mutually monitor each other in a communication network, causes the security agent device to control one or more security agents in the set to operate as one or more honeypot security agents that attempt to entice an attack on the communication network. In some embodiments, the computer program, when executed by a processor of the security agent device, causes the security agent device to evaluate each of one or more monitored security agents in the set for behaviors characteristic of an unknown attack on the communication network. An unknown attack is a type of attack that the security agents have not detected before. In some embodiments, evaluating each of one or more monitored security agents in the set comprises, for each of the one or more monitored security agents, obtaining a first metric for the monitored security agent, obtaining a second metric for the monitored security agent, and deciding, based on the first metric and the second metric, whether or not behaviors of the monitored security agent are features of an unknown attack on the communication network. The first metric for a monitored security agent reflects how accurately or inaccurately the security agents in the set cooperatively detect behaviors of the monitored security agent as being features of an attack on the communication network. And the second metric for a monitored security agent reflecting a rate at which the security agents in the set cooperatively detect behaviors of the monitored security agent as being features of an attack on the communication network.

[0033] Of course, the present disclosure is not limited to the above features and advantages. Indeed, those skilled in the art will recognize additional features and advantages upon reading the following detailed description, and upon viewing the accompanying drawings.

[0034] BRIEF DESCRIPTION OF THE DRAWINGS

[0035] Figure 1 is a block diagram of security agents for a communication network according to some embodiments.

[0036] Figure 2 is a block diagram of security agents that operate with different roles according to some embodiments.

[0037] Figure 3 is a block diagram of a centralized or leader security agent according to some embodiments.

[0038] Figure 4 is a block diagram of a centralized or leader security agent for unknown attack detection according to some embodiments.

[0039] Figure 5 is a block diagram of a centralized or leader security agent for known attack detection according to some embodiments.

[0040] Figure 6 is a block diagram of a centralized or leader security agent for benign agent detection according to some embodiments.

[0041] Figure 7 is a logic flow diagram of zero-day attack detection according to some embodiments.

[0042] Figure 8 is a block diagram of a centralized security agent, a leader security agent, follower security agent(s), and honeypot security agent(s) according to some embodiments.

[0043] Figure 9 is a block diagram of a distribution of security agents in a communication network according to some embodiments.

[0044] Figure 10 is a logic flow diagram of a method performed by a security agent device according to some embodiments. Figure 11 is a block diagram of a security agent device according to some embodiments.

[0045] DETAILED DESCRIPTION

[0046] Figure 1 shows a communication network 10 (e.g., a 5G+ network) according to some embodiments. The communication network 10 provides communication service to one or more communication devices 12, e.g., user equipment (UE). The communication network 10 may for example provide wireless communication service to the one or more communication devices 12.

[0047] The communication network 10 includes a set 14S of security agents 14-1 ... 14-N, generally referred to as security agents 14, where N > 1. The security agents 14 in the set 14S may be distributed in one or more dimensions, which may for example include geography and / or functionality. In some embodiments, for instance, at least some of the security agents 14 are geographically distributed in the communication network 10, e.g., at different parts of the communication network’s coverage area. For example, at least some of the security agents 14 may be distributed at different respective radio access nodes, at different respective edge computing servers, and / or at different respective core network nodes in the communication network 10. Alternatively or additionally, at least some of the security agents 14 may be functionally distributed in the communication network 10, e.g., for detecting anomalies at different types of network functions or network equipment. In another example, at least some of the security agents 14 may be distributed at different Network Data Analytics Functions (NWDAFs) in the communication network 10 and / or at different Access and Mobility Functions (AMFs) in the communication network 10. As another example, at least some of the security agents 14 may be distributed at different instances of a core network function such as an Access and Mobility Management Function (AMF), Session Management Function (SMF), Network Slice Selection Function (NSSF), Policy Control Function (PCF), or Unified Data Management (UDM) in a 5G network.

[0048] Despite the potentially distributed nature of the security agents 14, the security agents 14 nonetheless cooperate with one another to detect attacks 13 on the communication network 10. An attack 13 on the communication network 10 refers to a malicious attempt to disrupt, damage, or gain unauthorized access to the communication network 10 or to information or resources of the communication network 10, e.g., for compromising the confidentiality, integrity, or availability of the communication service or digital assets in the communication network 10. In some cases, for example, the security agents 14 may detect an attack based on detecting features in the communication network 10 that the security agents 14 understand as characterizing such an attack. A feature as used herein is an individual measurable property or attribute, e.g., access request rejection rate, data rate, CPU consumption, signal strength intensity, jitter, etc. Features characteristic of an attack may, individually or in combination, reflect deviations from what is standard, normal, or expected in the communication network 10, e.g., a higher rate of access request rejection due to overloading, a lower number of connected devices, lower system throughput, a high Signal Strength Intensity (SSI) from a jamming attack, a certain number of packets sent and / or dropped from a botnet attack, etc.

[0049] The security agents 14 in this regard may cooperate with one another to determine which features are characteristic of which types of attacks. For example, each security agent 14 may report to other security agents 14 which features characterize which types of attacks, e.g., where such reports may be based upon the security agent 14 having formed its own independent assessment using feature engineering or feature learning. In particular, a report may include the kind of detected attack, time of detection and the related attack’s features. The exchange of feature reports amongst the security agents 14 advantageously provides each security agent 14 with more robust information about how to detect attacks 13 on the communication network 10. Moreover, each security agent 14 may verify if the detected attack corresponds really to a cyber / network attack.

[0050] Some embodiments herein nonetheless account for the possibility that one or more of the security agents 14 might be or become compromised from a security perspective. Some embodiments for example recognize that a compromised security agent 14 infected by a security attack could behave maliciously, e.g., by broadcasting inaccurate feature reports or by withholding feature reports, so as to pollute or otherwise degrade the feature reporting that benign security agents rely on for attack detection. A compromised security agent may however try to evade detection, such as by sometimes acting maliciously but sometimes not. This may make it more difficult to know whether or not any given security agent can be trusted. Rather than outright trusting each security agent 14, then, some embodiments effectively scrutinize each security agent’s behaviors, e.g., according to a zero-trust architecture (ZTA) in which the security agents 14 do not trust each other.

[0051] As shown in Figure 1 in this regard, the security agents 14 in the set 14S mutually monitor each other, e.g., for malicious behaviors characteristic of an attack on the communication network 10. From the perspective of any given security agent, then, the other security agent(s) 14 that it monitors may be referred to as a ‘monitored’ security agent 14. If any monitored security agent 14 engages in behaviors characteristic of an attack, action may be taken against that security agent 14 to safeguard the communication network 10 from it. For example, a malicious security agent engaging in behaviors characteristic of an attack may be deactivated in the sense that it is no longer recognized as a security agent by the other security agents 14 and is therefore no longer influential in attack detection.

[0052] Within this architecture, embodiments herein target the detection of zero-day attacks or other attacks that are not yet known to the communication network 10 because they have not yet been detected by the communication network 10. In a zero-day attack, for example, an attacker spots a vulnerability first, quickly creates an exploit, and uses it for an attack, all before or on the first day that parties interested in mitigating the vulnerability become aware of it. In these and other instances, then, a so-called unknown attack as used herein refers to a type of attack that the security agents 14 in the communication network 10 have not detected before. That is, the security agents 14 are not aware of which features are characteristic of such an attack. An unknown attack may also be referred to as a new attack, since it is new to the security agents 14.

[0053] Some embodiments herein aim to lure any potentially compromised security agent 14 to engage in malicious behavior, with the goal of enticing an unknown attack so that the security agents 14 can observe the attack, learn which features characterize the attack, and thereby better protect the communication network 10 against it. Figure 2 illustrates one or more embodiments in this regard.

[0054] According to the embodiments in Figure 2, one of the security agents 14 in the set 14S operates as a centralized or leader security agent 14LC. That is, the centralized or leader security agent 14LC operates in a role as a leader security agent 14L and / or in a role as a centralized security agent 14C. As such, the centralized or leader security agent 14LC controls the roles of other security agents 14 in the set 14S. The centralized or leader security agent 14LC may for example control one or more other security agents 14 to operate as one or more follower security agents 14F that monitor for features of known attacks that are already known to the security agents 14. Notably with regard to unknown attacks, though, the centralized or leader security agent 14LC controls one or more security agents 14 in the set 14S to operate as one or more honeypot security agents 14H that monitor for features of unknown attacks 13U that are unknown to the security agents 14, e.g., by identifying behaviors that are malicious but that do not correspond to features of any known attack. It is the honeypot security agent(s) 14H that attempt to entice an attack on the communication network 10, with the goal of enticing an unknown attack 13U by any compromised security agent 14C.

[0055] In some embodiments, the honeypot security agent(s) 14H may attempt to entice an attack by intentionally attracting an attack on the honeypot security agent(s) 14H, i.e., with an irresistible ‘honeypot’. The honeypot security agent(s) 14H may do so by pretending to be a legitimate system but deliberately exposing security vulnerabilities that make the honeypot security agent(s) 14H attractive as a target for an attack, e.g., with unpatched software, misconfigurations, default passwords, or other security flaws. Alternatively or additionally, the honeypot security agent(s) 14H may attempt to entice an attack by themselves mimicking malicious behavior so as to invite cooperation with any compromised security agent 14C. For example, the honeypot security agent(s) 14H may actively engage in malicious acts such as dropping packets, but minimize the impact of those acts on the communication network 10, e.g., to avoid meaningful degradation of service. Because the honeypot security agent(s) 14H entice an attack in these or other ways, they are more likely to be an early target of a zero-day attack or other unknown attack 13U. If or when such an unknown attack 13U occurs by a compromised security agent 14C, the centralized or leader security agent 14LC is ready for it.

[0056] In particular, the centralized or leader security agent 14LC evaluates each of one or more monitored security agents 14 in the set 14S for behaviors characteristic of an unknown attack 13U on the communication network 10. The centralized or leader security agent 14LC does so by obtaining certain metrics reflecting a monitored security agent’s behaviors and then deciding based on those metrics whether or not the behaviors of the monitored security agent 14 are features of an unknown attack 13U. Figure 3 shows an example for one monitored security agent 14.

[0057] As shown in Figure 3, some of the security agents 14 in the set 14S monitor another security agent 14M in the set 14S, i.e., the monitored security agent 14M. The security agents 14 that monitor the monitored security agent 14M are shown in this example as including one or more follower security agents 14F and / or one or more honeypot security agents 14H, as described above. Regardless, each security agent 14 monitors the monitored security agent 14M for behaviors that the security agent 14 understands as being features of an attack, e.g., according to feature engineering or feature learning performed using its local observations. If a security agent 14 identifies behaviors of the monitored security agent 14M that are features of an attack, the security agent 14 reports this to the centralized or leader security agent 14LC by sending a security message 17. The security message 17 may for instance report whether and / or which behaviors of the monitored security agent 14M are features of which type of attack. With regard to an unknown attack, though, a security message 17 may report features that are detected as being association with some sort of attack (e.g., based on those features meaningfully deviating from benign norms), but indicate that the features do not correspond to those of any attack known to the reporting security agent. The centralized or leader security agent 14LC may then take into account any security messages 17 from the security agents 14 in deciding whether or not the monitored security agent’s behaviors represent an attack. The centralized or leader security agent 14LC may for example make the decision in accordance with a consensus of the security agents 14M. As one example of such an implementation, if the consensus among the security agents 14 is that the monitored security agent’s behaviors do not represent an attack, then the centralized or leader security agent’s decision may be the same as that consensus, e.g., even if a minority of the security agents 14 report the monitored security agent’s behaviors as being features of an attack.

[0058] Within this context, Figure 3 shows that the centralized or leader security agent 14LC includes a metric obtainer 16. The metric obtainer 16 obtains metrics 19 for the monitored security agent 14M reflecting the monitored security agent’s behaviors, e.g., as characterized by security message(s) 17 from the security agents 14 monitoring the monitored security agent 14M. The metrics 19 are shown as including a first metric 19-1 and a second metric 19-2 for the monitored security agent 14M. These first and second metrics 19-1 , 19-2 may also be referred to herein as utility metrics, as they are metrics obtained for their utility in deciding whether or not an unknown attack 13U is detected.

[0059] The first metric 19-1 reflects how accurately or inaccurately the security agents 14 in the set 14S cooperatively detect behaviors of the monitored security agent 14M as being features of an attack 13 on the communication network 10. The first metric 19-1 may for example be a function of a false positive rate FP and / or a false negative rate FN for the monitored security agent 14. In this case, the false positive rate FP is the rate at which the security agents 14 incorrectly detect behaviors of the monitored security agent 14M as being features of an attack 13 on the communication network, e.g., computed as the number of false positives attributable to a set of security messages 17 divided by the number of security messages 17 in that set. Similarly, the false negative rate FN is the rate at which the security agents 14 fail to detect behaviors of the monitored security agent 14M as being features of an attack 13 on the communication network 10, e.g., computed as the number of false negatives attributable to a set of security messages 17 divided by the number of security messages 17 in that set. In such embodiments where the first metric 19-1 is a function of the false positive rate FP and / or the false negative rate FN, the value of the first metric 19-1 may increase as the inaccuracy with which the security agents 14 detect attack features rises. Because an attacker aims to increase the value of the first metric 19-1 in this case, the first metric 19-1 may also be referred to in some embodiments as an attack utility metric.

[0060] The second metric 19-1 by contrast reflects the rate at which the security agents 14 cooperatively detect (rightly or wrongly) behaviors of the monitored security agent 14M as being features of an attack 13 on the communication network 10. The second metric 19-2 may for example be a function of an attack detection rate AD for the monitored security agent 14. Here, the attack detection rate AD is the rate at which the security agents 14 cooperatively detect behaviors of the monitored security agent 14 as being features of an attack 13, whether known or unknown. The attack detection rate AD may for instance be computed as the number of known and unknown attacks 13 detected and confirmed by the centralized or leader security agent 14LC from a set of security messages 17, divided by the number of security messages 17 in that set. In these and other embodiments, the value of the second metric 19-2 may increase with the rate at which the security agents 14 detect attack. Because the security agents 14 defending the communication network 10 aim to increase the value of the second metric 19-2 in this case, the second metric 19-2 may also be referred to in some embodiments as a defense utility metric. With the first and second metrics 19-1 , 19-2 obtained as described above, an unknown attack decision maker 18U at the centralized or leader security agent 14LC uses those metrics 19-1, 19-2 to make a decision 20U about whether or not behaviors of the monitored security agent 14M are features of an unknown attack 13U. For example, the unknown attack decision maker 18U may decide whether or not behaviors of the monitored security agent 14D are features of an unknown attack 13U, based on whether or not the second metric 19-2 exceeds the first metric 19-1.

[0061] Figure 4 shows additional details of how the centralized or leader security agent 14LC makes the decision 20U about whether or not behaviors of the monitored security agent 14M are features of an unknown attack 13U, according to some embodiments. As shown in this example, the metric obtainer 16 includes a first metric obtainer 16-1 that obtains the first metric 19-1 , shown as the attack utility metric U(j^, and further includes a second metric obtainer 16- 2 that obtains the second metric 19-2, shown as the defense utility metric

[0062] The first metric obtainer 16-1 obtains the first metric 19-1 as a function of the false positive rate FP and the false negative rate FN for the monitored security agent 14M, as described above. For example, the first metric 19-1 may be obtained as: CAS = 4 * FP + a * * FN,

[0063] Where FP is the false positive rate for the monitored security agent 14M, FN is the false negative rate for the monitored security agent 14M, and a are each a weight parameter G [0,1] .

[0064] The second metric obtainer 16-2 as shown obtains the second metric 19-2 as a function of the attack detection rate AD, described above, as well as a known attack feature determination rate KF and an unknown attack feature determination rate NF. Here, the known attack feature determination rate KF is the rate at which the security agents 14 cooperatively determine features of known attacks from monitoring behaviors of the monitored security agent 14M, e.g., computed as the number of features of known attacks that have led to a correct attack detection over a number of security messages 17 that have reported features of known attacks. And the unknown attack feature determination rate NF is the rate at which the security agents 14 cooperatively determine features of unknown attacks 13U from monitoring behaviors of the monitored security agent 14M, e.g., computed as the number of features of unknown attacks that have led to a correct attack detection over a number of security messages 17 that have reported features of unknown attacks. In one embodiment, as an example, the second metric 19-2 may be obtained as: where KF is the known attack feature determination rate, NF is the unknown attack feature determination rate, AD is the attack detection rate, and a- , a2 and a are each a weight parameter e [0,1]- With the attack detection rate AD being weighted by a weight parameter a^, the value * AD may also be referred to as the weighted attack detection rate.

[0065] With the first and second metrics 19-1 , 19-2 obtained, the unknown attack decision maker 18U makes the decision 20U about whether or not behaviors of the monitored security agent 14M are features of an unknown attack 13U based on the first metric 19-1 and the second metric 19-2, as well as the known attack feature determination rate KF and the unknown attack feature determination rate NF. For example, as shown, the unknown attack decision maker 18U may decide that behaviors of the monitored security agent 14M are features of an unknown attack 13U if both (i) the first metric 19-1 exceeds the second metric 19-2; and (ii) the unknown attack feature determination rate NF exceeds the known attack feature determination rate KF. That is, the unknown attack decision maker 18U may decide that behaviors of the monitored security agent 14M are features of an unknown attack 13U if:

[0066] UCDS <UCASand NF>KF-

[0067] Indeed, based on the first metric 19-1 exceeding the second metric 19-2, the monitored security agent 14M is deemed as having been compromised and / or as behaving maliciously. And, based on the security agents 14 detecting unknown attack features at a greater rate than that at which they detect known attack features, the decision 20U is that the behaviors of the monitored security agent 14M are features of an unknown attack 13U.

[0068] In some embodiments, the centralized or leader security agent 14LC exploits these metrics 19-1 , 19-2 also to evaluate the monitored security agent 14M for behaviors characteristic of a known attack. Figure 5 shows one example.

[0069] As shown in Figure 5, the centralized or leader security agent 14LC also includes a known attack decision maker 18K, in addition to the unknown attack decision maker 18U (not shown) in Figure 4. The known attack decision maker 18K makes a decision 20K of whether or not behaviors of the monitored security agent 14M are features of a known attack 13K based on the first metric 19-1 and the second metric 19-2, as well as the known attack feature determination rate KF and the unknown attack feature determination rate NF. For example, as shown, the known attack decision maker 18K may decide that behaviors of the monitored security agent 14M are features of a known attack 13K if both (i) the first metric UCAS 19-1 exceeds the second metric 19-2; and (ii) the known attack feature determination rate KF exceeds the unknown attack feature determination rate NF. That is, the known attack decision maker 18K may decide that behaviors of the monitored security agent 14M are features of a known attack 13K if:

[0070] UCDS <UCASand NF<KF- Indeed, based on the first metric 19-1 exceeding the second metric 19-2, the monitored security agent 14M is deemed as having been compromised and / or as behaving maliciously. And, based on the security agents 14 detecting known attack features at a greater rate than that at which they detect unknown attack features, the decision 20K is that the behaviors of the monitored security agent 14M are features of a known attack 13K.

[0071] Alternatively or additionally, the centralized or leader security agent 14LC may exploit these metrics 19-1, 19-2 also to evaluate whether behaviors of the monitored security agent 14M are benign, i.e. , not an attack. Figure 6 shows one example. As shown, the centralized or leader security agent 14LC also includes a benign decision maker 18B, in addition to the unknown attack decision maker 18U (not shown) in Figure 4. The benign decision maker 18B as exemplified decides that behaviors of the monitored security agent 14M are benign if the second metric 19-2 for the monitored security agent 14B exceeds the first metric 19-1 for the monitored security agent 14B. That is, the benign decision maker 18B may decide that behaviors of the monitored security agent 14M are benign if:

[0072] UCDS >uCAS-

[0073] By exploiting these metrics 19-1, 19-2, then, the centralized or leader security agent 14LC is able to distinguish between a compromised security agent and a benign security agent, as well as between a compromised security agent that executes a known attack and a compromised security agent that executes an unknown attack. Some embodiments thereby advantageously enable even unknown attack detection via security agents while safeguarding against security agent compromise.

[0074] Consider now exemplary rationale underlying some embodiments herein, explained in terms of a game system. In such a game system, the security agents 14 cooperate with one another to defend against attacks and may thereby be referred to as a Cooperative Defense System (CDS). And attackers cooperate with each other to launch attacks without being detected by the security agents 14, and may thereby be referred to as a Cooperative Attack System (CAS). Because the CDS and CAS do not cooperate with each other, the game system may be said to be non-cooperative.

[0075] In such a game system, the CDS aims to identify behaviors that are features of known and unknown attacks and hence detect attacks at a high rate. That is, the CDS over time aims to maximize the second metric 19-2 referred to as the defense utility metric When the defense utility metric is a function of the attack detection rate AD, the known attack feature determination rate KF, and the unknown attack feature determination rate NF, this means that the CDS over time aims to maximize the defense utility metric by maximizing the attack detection rate AD, the known attack feature determination rate KF, and the unknown attack feature determination rate NF. Conversely, the CAS aims to disrupt the ability of the CDS to identify behaviors that are features of known and unknown attacks and hence decrease the accuracy with which the CAS detects attacks. That is, the CAS over time aims to maximize the first metric 19-1 referred to as the attack utility metric When the attack utility metric is a function of the false positive rate FP and the false negative rate FN, this means that the CAS over time aims to maximize the attack utility metric by maximizing the false positive rate FP and the false negative rate FN.

[0076] Taking U = defense utility metric and the attack utility metric CASmaYa'sob® expressed as below:

[0077] As shown in equations 3 and 4, the Nash equilibrium state is reached where the CDS aims to detect the maximum number of attacks and CAS aims to lead the security agents 14 to generate a high number of false positives FP and false negatives FN. As a result, the CDS detects a monitored security agent 14M as an attacker that executes an unknown attack 13U (e.g., a zero-day attack) when the following condition is reached:

[0078] UCDS <UCASand NF<KF-

[0079] Consider an example. The CDS detects that a first monitored security agent 14M executes a known attack based on the first monitored security agent 14M dropping 8 packets. Here, 8 packets dropped is feature of such a known attack, so that it contributes to the known attack feature determination rate KF. Meanwhile, the honeypot security agent(s) 14H mimic malicious cooperation with a second monitored security agent 14M, by sending 2 unwanted packets, to see if the second monitored security agent 14M exhibits a new misbehavior that has not been observed before. If the second monitored security agent 14M drops the sent packets and sends more than 2 packets, the CDS in this example detects a zero-day attack as such misbehavior is a newfound attack. Here, more than 2 packets sent by the second monitored security agent is a feature of an unknown attack, so that it contributes to the unknown attack feature determination rate NF.

[0080] Figure 7 illustrates a logic flow diagram for processing according to one or more such embodiments where an unknown attack takes the form of a zero-day attack. As shown, the security agents 14 work to establish the CDS, e.g., when occurrence of an unknown attack is suspected (Block 100). If the CDS is establishment (YES at Block 110), the CDS monitors and computes the defense utility metric Upp)^ (Block 120). If the defense utility metric is not zero (YES at Block 130), then the CDS estimates the attack utility metric Up AS (Block 140). If the attack utility metric 's not zero(YES at Block 150), the CDS checks if < UCASand NF < KF (Block 160). If UCDS< UCASand NF < KF (YES at Block 160), the CDS decides that the monitored CAS, as represented by the monitored security agent 14M, exhibits a zero-day attack (Block 170). Otherwise (NO at Block 160), the CDS performs additional iterations (starting at Block 120) to continue monitoring for a zero-day attack.

[0081] To this point, in some embodiments, the leader or centralized security agent 14LC performs the evaluation described above during each of multiple evaluation intervals over time, i.e., iterations. The first and second metrics 19-1 , 19-2 may thereby be computed on an interval by interval basis. In some embodiments, though, the leader or centralized security agent 14LC may apply filtering across evaluation intervals, e.g., so that the metrics 19-1 , 19-2 in one interval impact the metrics 19-1 , 19-2 in a subsequent interval.

[0082] In any event, in between at least some evaluation intervals, the leader or centralized security agent 14LC may adapt one or more security parameters of one or more of the security agents 14 in the set 14S, as needed to increase the second metric 19-2 for the monitored security agent 14M and / or decrease the first metric 19-1 for the monitored security agent 14M. The security parameter(s) adapted may for example govern any underlying model used for attack feature identification and / or govern any underlying rules used for attack detection. Such may lead the security agents 14 to improve attack detection over time, e.g., by decreasing false positives FP and / or false negatives FN.

[0083] Alternatively or additionally to the leader or centralized security agent 14LC evaluating monitored security agents 14M for behaviors characteristic of an unknown attack 13U, the leader or centralized security agent 14LC may control with which role, if any, each security agent 14 operates for detecting attacks in the communication network 10. For each security agent 14 in the set 14S, for instance, the leader or centralized security agent 14LC may activate the security agent 14 in one of multiple possible roles (e.g., follower, honeypot, or leader as described above). Or, the leader or centralized security agent 14LC may deactivate that security agent 14 from operating in any of the multiple possible roles, i.e., so that the security agent 14 no longer contributes to attack detection. In this way, the leader or centralized security agent 14LC may control which entities operate as security agents 14 and / or control in which roles each security agent 14 operates.

[0084] The multiple possible roles, as described above, may include a leader security agent, a follower security agent, and a honeypot security agent, as explained above. A follower security agent monitors for features of known attacks 13K, e.g., according to a rule-based algorithm that defines features of known attacks 13K in terms of rule(s). A honeypot security agent monitors for features of unknown attacks 13U, e.g., in conjunction with attempting to entice such an attack. A leader security agent may perform attack detection based on features determined by honeypot security agent(s) and the follower security agent(s). The leader security agent in this regard may implement a hybrid attack detection algorithm, which is a combination (i.e., hybrid) of a machine learning algorithm and a rule-based algorithm. The machine learning algorithm detects attacks based on a machine learning model that is trained, using training data, to detect attacks. The machine learning algorithm may for example be a reinforcement federated learning algorithm. By contrast, the rule-based algorithm detects attacks based on rule(s). One advantage of such a hybrid detection technique is low generation of false positives thanks to the rule-based algorithm and high attack detection rate thanks to the machine learning algorithm. Specifically, the machine learning algorithm has the ability to detect attacks with a high attack detection rate. However, high false positives could be generated specifically when the number of attacks is high or / and the used attacks’ features are not relevant for the detection. The rule-based algorithm aims to reduce false positives generated by the machine learning algorithm, thanks to rules which may be updated by a security expert over time. Regardless, the leader security agent may dynamically select between the machine learning algorithm and the rule-based algorithm, e.g., to realize a tradeoff between detection accuracy and resource consumption.

[0085] In some embodiments, the leader or centralized security agent 14LC controls with which role, if any, each security agent 14 operates for detecting attacks in the communication network 10, based on the first and second metrics 19-1 , 19-2 for that security agent 14. For example, in some embodiments, the leader or centralized security agent 14LC activates a security agent 14 in one of the possible roles if the second metric 19-2 for that security agent 14 exceeds the first metric 19-1 for that security agent 14. By contrast, if the first metric 19-1 for the security agent 14 exceeds the second metric 19-2, the leader or centralized security agent 14LC deactivates the security agent 14 from operating in any of the possible roles, e.g., since the first metric 19-1 exceeding the second metric 19-2 suggests that the security agent 14 is malicious.

[0086] If the second metric 19-2 for a security agent 14 exceeds the first metric 19-1 for that security agent 14m the leader or centralized security agent 14LC decides in which role the security agent 14 is to operate.

[0087] If the weighted attack detection rate for the security agent 14 exceeds the first metric 19-1 for the security agent 14, the leader or centralized security agent 14LC activates the security agent 14 in the role as a honeypot security agent 14H. That is, if: 1 * AD > UCAS, where = aA* FP + erg * FN, the leader or centralized security agent 14LC activates the security agent 14 in the role as a honeypot security agent 14H.

[0088] If the known attack feature determination rate KF for the security agent 14 exceeds an unknown attack feature determination rate NF for the security agent 14, the leader or centralized security agent 14LC activates the security agent 14 in the role as a follower security agent 14F. That is, if:

[0089] KF > NF, the leader or centralized security agent 14LC activates the security agent 14 in the role as a follower security agent 14F.

[0090] By contrast, if the unknown attack feature determination rate NF for the security agent 14 exceeds the known attack feature determination rate KF for the security agent 14, the leader or centralized security agent 14LC activates the security agent 14 in the role as a leader security agent. That is, if:

[0091] NF > KF, the leader or centralized security agent 14LC activates the security agent 14 in the role as a leader security agent.

[0092] Some embodiments thereby control security agents’ roles activation in a way that avoids always-on operation, as such could degrade the accuracy of attack detection (e.g., increase the false positive rate) and could impact network cost (e.g., increase both the computation and communication overhead). One or more embodiments according provide optimal activation of security agents’ roles considering the tradeoff between the accuracy of attack detection and network cost.

[0093] Figure 8 illustrates one example hierarchical architecture that includes a separate centralized security agent 14C that supervises a leader security agent 14L which controls the follower security agent(s) 14F and honeypot security agent(s) 14H. This architecture may also be referred to as a robust zero-trust framework (RZTF).

[0094] In this example, the centralized security agent 14C may handle a large number of attack data sets and execute a sophisticated attack detection algorithm such as the hybrid detection algorithm described herein. The centralized security agent 14C may also verify one or more of the metrics described herein, as initially computed by the leader security agent 14L. The centralized security agent 14C may implement the above role assignment, e.g., independently or in cooperation with the leader security agent 14L.

[0095] The leader security agent 14L collects security information (i.e. , attacks’ features) from the follower and honeypot agents 14F, 14H, aggregates this security information, executes the hybrid attack detection algorithm described above, and then makes a decision toward a monitored security agent 14. The leader security agent 14L feeds the honeypot security agent(s) 14H with detected attacks and their related attack features in order to enrich the attack database of the honeypot security agent(s) 14H. The leader security agent 14L generally may be said to perform cooperative attacks detection and detection rules’ update.

[0096] A follower security agent 14F monitors each of one or more targets within range that are suspected to behave maliciously. A follower security agent 14F may execute the rule- based algorithm described above and determine known attack features related to the monitored target(s). The follower agents 14F may collaborate between each other to determine accurately the correct attacks’ features and hence reduce the false positive rate. It is noted that the hybrid detection technique executed by the Leader agent may update over time the rules used by the rule-based algorithm, with the goal to improve over time the correct determination of attacks’ features.

[0097] A honeypot security agent 14H the honeypot security agent(s) 14H determine features of new attacks, such as zero-day attacks. In addition, the honeypot security agent(s) 14H execute false attacks, and in doing so try not to be detected by the attackers. As such, the honeypot security agent(s) 14H each play the role of malicious agent with a goal to solicitate attackers to cooperate with it to launch an attack and hence determine the relevant features of a new attack. The identity of the honeypot security agent 14H is known by the leader and follower security agents 14L, 14F, to avoid false categorization of the honeypot security agent as an attacker. The honeypot security agent 14H may actually execute one or more attacks, to entice any actually malicious security agent to execute an unknown attack, so that the honeypot security agent 14H can then determine the features of that unknown attack. In executing attack(s), though, the honeypot security agent 14H minimizes the impact that the attack(s) have on the quality of service and quality of experience provided in the communication network 10, e.g., dropping some messages sent from a legitimate device to an edge server but without degrading the quality of service of the edge computing network, or jamming the communication between devices but without impacting the quality of experience of a wireless network.

[0098] In some embodiments, the follower and honeypot agents may be activated at radio access network (RAN) nodes of the communication network, whereas the leader security agent may be activated at a mobile edge computing server. The centralized security agent 14C, where present, may be activated at Security Information and Event Management (SIEM Figure 9 illustrates another concrete example in a 5G service-based architecture (SBA). Here, the leader security agent (L.A.) 14L is activated at the NWDAF, the honeypot security agent(s) (H.A.) 14H are activated at the Access and Mobility Management Function (AMF), and the follower security agent(s) (F.A.) 14F are activated at the edge NWDAF. In this context, user data is generated by a user equipment (UE) and sent to the 5G network’s SBA. The NWDAF gathers this user data sent from the UE and from related network functions (NFs). The leader security agent 14L at the NWDAF determines detection values (e.g., AD, NF and FP) related to the honeypot security agent(s) 14H and the follower security agent(s) 14F, e.g., through hybrid detection and decision-making modules) and produces specific actions for the security agents 14. For example, the leader security agent 14L may request the activation and / or deactivation of honeypot and / or follower security agents. Generally, then, some embodiments may provide a robust zero trust framework (RZTF) based on a set 14S of security agents 14 that cooperate to activate dynamically their security roles, with a goal to detect attacks taking into account false positive and false negative issues. Some embodiments may dynamically activate or deactivate security roles of security agents based on monitoring security parameters and utility functions while considering the tradeoff between the accuracy of determining relevant attacks’ features and detection of attackers, and the false detection issues.

[0099] Some embodiments thereby advantageously exploit security agents 14 in order to harden the network’s security against known and unknown attacks (such as zero-day attacks) and reduce false detection over time (including false positive and false negative rates).

[0100] Note that a security agent 14 herein may constitute hardware, software, or a combination thereof. A security agent 14 may for example constitute dedicated hardware or equipment configured with circuitry and / or computer program instructions for performing the functionality described, where the hardware or equipment may be centralized or distributed. In another embodiment, a security agent 14 constitutes a specific virtualized instance of such hardware or equipment. In these and other embodiments, then, a security agent 14, whether in the form of hardware, software, or a combination thereof, may be hosted on or by a security agent device 14D.

[0101] In view of the modifications and variations herein, Figure 10 depicts a method performed by a security agent device 14D configured to host a centralized or leader security agent 14LC included in a set 14S of security agents 14 for a communication network 10 in accordance with particular embodiments. The security agents 14 in the set 14S monitor each other. The method includes controlling one or more security agents 14 in the set 14S to operate as one or more honeypot security agents 14H that attempt to entice an attack 13 on the communication network 10 (Block 200).

[0102] The method also includes evaluating each of one or more monitored security agents 14M in the set 14S for behaviors characteristic of an unknown attack 13U on the communication network 10 (Block 210). In some embodiments, evaluating each of one or more monitored security agents 14M in the set 14S comprises, for each of the one or more monitored security agents 14M, obtaining a first metric 19-1 for the monitored security agent 14M reflecting how accurately or inaccurately the security agents 14 in the set 14S cooperatively detect behaviors of the monitored security agent 14M as being features of an attack 13 on the communication network 10 (Block 220). In some embodiments, evaluating each of one or more monitored security agents 14M in the set 14S further comprises, for each of the one or more monitored security agents 14M, obtaining a second metric 19-2 for the monitored security agent 14M reflecting a rate at which the security agents 14 in the set 14S cooperatively detect behaviors of the monitored security agent 14M as being features of an attack 13 on the communication network 10 (Block 230). In some embodiments, evaluating each of one or more monitored security agents 14M in the set 14S also comprises, for each of the one or more monitored security agents 14M, deciding, based on the first metric 19-1 and the second metric 19-2, whether or not behaviors of the monitored security agent 14M are features of an unknown attack 13U on the communication network 10, where an unknown attack 13U is a type of attack 13 that the security agents 14 have not detected before (Block 240).

[0103] In some embodiments, deciding whether or not behaviors of a monitored security agent 14M are features of an unknown attack 13U on the communication network 10 is based on whether or not the second metric 19-2 for the monitored security agent 14M exceeds the first metric 19-1 for the monitored security agent 14M.

[0104] In some embodiments, the second metric 19-2 for a monitored security agent 14M reflects (i) an attack detection rate for a monitored security agent 14M comprising the rate at which the security agents 14 in the set 14S cooperatively detect behaviors of the monitored security agent 14M as being features of an attack 13 on the communication network 10; (ii) a known attack feature determination rate for the monitored security agent 14M comprising a rate at which the security agents 14 in the set 14S cooperatively determine features of known attacks from monitoring behaviors of the monitored security agent 14M, wherein a known attack is a type of attack 13 that the security agents 14 has detected before; and (iii) an unknown attack feature determination rate for the monitored security agent 14M comprising a rate at which the security agents 14 in the set 14S cooperatively determine features of unknown attacks 13U from monitoring behaviors of the monitored security agent 14M.

[0105] In some embodiments, deciding whether or not behaviors of a monitored security agent 14M are features of an unknown attack 13U on the communication network 10 is based on the first metric 19-1 for the monitored security agent 14M, the second metric 19-2 for the monitored security agent 14M, the known attack feature determination rate for the monitored security agent 14M, and the unknown attack feature determination rate for the monitored security agent 14M.

[0106] In some embodiments, deciding whether or not behaviors of a monitored security agent 14M are features of an unknown attack 13U on the communication network 10 comprises deciding that behaviors of the monitored security agent 14M are features of an unknown attack 13U on the communication network 10 if the first metric 19-1 for the monitored security agent 14M exceeds the second metric 19-2 for the monitored security agent 14M and the unknown attack feature determination rate for the monitored security agent 14M exceeds the known attack feature determination rate for the monitored security agent 14M.

[0107] In some embodiments, said evaluating further comprises evaluating each of the one or more monitored security agents 14M for behaviors characteristic of a known attack on the communication network 10. In some embodiments, evaluating each of the one or more monitored security agents 14M comprises, for each of the one or more monitored security agents 14M, deciding that behaviors of the monitored security agent 14M are features of a known attack on the communication network 10 if the first metric 19-1 for the monitored security agent 14M exceeds the second metric 19-2 for the monitored security agent 14M and the known attack feature determination rate for the monitored security agent 14M exceeds the unknown attack feature determination rate for the monitored security agent 14M.

[0108] In some embodiments, said evaluating further comprises, for each of the one or more monitored security agents 14M, deciding that behaviors of the monitored security agent 14M are benign if the second metric 19-2 for the monitored security agent 14M exceeds the first metric 19-1 for the monitored security agent 14M.

[0109] In some embodiments, the second metric 19-2 for a monitored security agent 14M is obtained as +a3 * NF, where KF is the known attack feature determination rate for the monitored security agent 14M, where NF is the unknown attack feature determination rate for the monitored security agent 14M, where AD is the attack detection rate for the monitored security agent 14M, and where a- , a 2 are each a weight parameter G [0,1] .

[0110] In some embodiments, the first metric 19-1 for a monitored security agent 14M is a function of a false positive rate and / or a false negative rate for the monitored security agent 14M. In some embodiments, the false positive rate for the monitored security agent 14M is a rate at which the security agents 14 in the set 14S incorrectly detect behaviors of the monitored security agent 14M as being features of an attack 13 on the communication network 10, and the false negative rate is a rate at which the security agents 14 in the set 14S fail to detect behaviors of the monitored security agent 14M as being features of an attack 13 on the communication network 10.

[0111] In some embodiments, the first metric 19-1 for a monitored security agent 14M is obtained as * FP + e g * FN, where FP is the false positive rate for the monitored security agent 14M, where FN is the false negative rate for the monitored security agent 14M, and where and erg are each a weight parameter G [0,11-

[0112] In some embodiments, said evaluating is performed during each of multiple evaluation intervals, and the method comprises, in between at least some evaluation intervals, adapting one or more security parameters of one or more of the security agents in the set as needed to increase the second metric 19-2 for the monitored security agent 14M and / or decrease the first metric 19-1 for the monitored security agent 14M.

[0113] In some embodiments, one or more security agents 14 in the set 14S are deployed at one or more respective radio network nodes in the communication network 10. In other alternative or additional embodiments, one or more security agents 14 in the set 14S are deployed at one or more respective edge computing servers in the communication network 10. In yet other alternative or additional embodiments, one or more security agents 14 in the set 14S are deployed at one or more network data analytics functions, NWDAFs, in the communication network 10. In still yet other alternative or additional embodiments, one or more security agents 14 in the set 14S are deployed at one or more access and mobility management functions, AMFs, in the communication network 10.

[0114] In some embodiments, the security agents 14 in the set 14S include the one or more honeypot security agents 14H that each attempt to entice an unknown attack 13U on the communication network 10, by intentionally attracting an attack 13 on the honeypot security agent 14H or by mimicking malicious cooperation with the monitored security agent 14M, and that each monitor the monitored security agent 14M to determine features of unknown attacks 13U. In some embodiments, one or more follower security agents 14F that each monitor the monitored security agent 14M to determine features of known attacks according to a rulebased algorithm that defines features of known attacks in terms of one or more rules. In some embodiments, a centralized or leader security agent 14LC that executes a hybrid attack detection algorithm to detect an attack 13 on the communication network 10 based on features determined by the one or more honeypot security agents 14H and the one or more follower security agents 14F. In some embodiments, according to the hybrid attack detection algorithm the centralized or leader security agent selects 14LC between a machine learning algorithm trained, using training data, to detect attacks 13 by the monitored security agent 14M. In some embodiments, according to the hybrid attack detection algorithm the centralized or leader security agent 14LC selects between a rule-based algorithm that detects attacks 13 by the monitored security agent 14M based on one or more rules.

[0115] In some embodiments, the method further comprises, for each of the one or more monitored security agents 14M, controlling with which role, if any, the monitored security agent 14M operates for detecting attacks 13 in the communication network 10, based on the first metric 19-1 and the second metric 19-2 for the monitored security agent 14M (Block 250).

[0116] In some embodiments, controlling with which role, if any, a monitored security agent 14M operates comprises activating the monitored security agent 14M in one of multiple possible roles if the second metric 19-2 for the monitored security agent 14M exceeds the first metric 19- 1 for the monitored security agent 14M. In other embodiments, controlling with which role, if any, a monitored security agent 14M operates comprises deactivating the monitored security agent 14M from operating in any of the multiple possible roles if the first metric 19-1 for the monitored security agent 14M exceeds the second metric 19-2 for the monitored security agent 14M. In some embodiments, activating a monitored security agent 14M in one of the multiple possible roles comprises activating the monitored security agent 14M in a role as a honeypot security agent 14H if a weighted attack detection rate for the monitored security agent 14M exceeds the first metric 19-1 for the monitored security agent 14M. In some embodiments, an attack detection rate for the monitored security agent 14M is the rate at which the security agents 14 in the set 14S cooperatively detect behaviors of the monitored security agent 14M as being features of an attack 13 on the communication network 10. In some embodiments, the weighted attack detection rate for the monitored security agent 14M is the attack detection rate for the monitored security agent 14M as weighted by a weight parameter.

[0117] In some embodiments, activating a monitored security agent 14M in one of the multiple possible roles comprises activating the monitored security agent 14M in a role as a follower security agent 14F if a known attack feature determination rate for the monitored security agent 14M exceeds an unknown attack feature determination rate for the monitored security agent 14M. In some embodiments, the known attack feature determination rate for the monitored security agent 14M comprises a rate at which the security agents 14 in the set 14S cooperatively determine features of known attacks from monitoring behaviors of the monitored security agent 14M. In some embodiments, a known attack is a type of attack 13 that the security agents 14 has detected before, and the unknown attack feature determination rate for the monitored security agent 14M comprises a rate at which the security agents 14 in the set 14S cooperatively determine features of unknown attacks 13U from monitoring behaviors of the monitored security agent 14M.

[0118] In some embodiments, activating a monitored security agent 14M in one of the multiple possible roles comprises activating the monitored security agent 14M in a role as a centralized or leader security agent 14LC if an unknown attack feature determination rate for the monitored security agent 14M exceeds a known attack feature determination rate for the monitored security agent 14M. In some embodiments, the known attack feature determination rate for the monitored security agent 14M comprises a rate at which the security agents 14 in the set 14s cooperatively determine features of known attacks from monitoring behaviors of the monitored security agent 14M. In some embodiments, a known attack is a type of attack 13 that the security agents 14 has detected before, and the unknown attack feature determination rate for the monitored security agent 14M comprises a rate at which the security agents 14 in the set 14S cooperatively determine features of unknown attacks 13U from monitoring behaviors of the monitored security agent 14M.

[0119] Embodiments herein also include corresponding apparatuses. Embodiments herein for instance include a security agent device 14D configured to perform any of the steps of any of the embodiments described above for the security agent device 14D. Embodiments also include a security agent device 14D comprising processing circuitry and power supply circuitry. The processing circuitry is configured to perform any of the steps of any of the embodiments described above for the security agent device 14D. The power supply circuitry is configured to supply power to the security agent device 14D.

[0120] Embodiments further include a security agent device 14D comprising processing circuitry. The processing circuitry is configured to perform any of the steps of any of the embodiments described above for the security agent device 14D. In some embodiments, the security agent device 14D further comprises communication circuitry.

[0121] Embodiments further include a security agent device 14D comprising processing circuitry and memory. The memory contains instructions executable by the processing circuitry whereby the security agent device 14D is configured to perform any of the steps of any of the embodiments described above for the security agent device 14D.

[0122] More particularly, the apparatuses described above may perform the methods herein and any other processing by implementing any functional means, modules, units, or circuitry. In one embodiment, for example, the apparatuses comprise respective circuits or circuitry configured to perform the steps shown in the method figures. The circuits or circuitry in this regard may comprise circuits dedicated to performing certain functional processing and / or one or more microprocessors in conjunction with memory. For instance, the circuitry may include one or more microprocessor or microcontrollers, as well as other digital hardware, which may include digital signal processors (DSPs), special-purpose digital logic, and the like. The processing circuitry may be configured to execute program code stored in memory, which may include one or several types of memory such as read-only memory (ROM), random-access memory, cache memory, flash memory devices, optical storage devices, etc. Program code stored in memory may include program instructions for executing one or more telecommunications and / or data communications protocols as well as instructions for carrying out one or more of the techniques described herein, in several embodiments. In embodiments that employ memory, the memory stores program code that, when executed by the one or more processors, carries out the techniques described herein.

[0123] Figure 11 for example illustrates a security agent device 14D as implemented in accordance with one or more embodiments. As shown, the security agent device 14D includes processing circuitry 310 and communication circuitry 320. The communication circuitry 320 is configured to transmit and / or receive information to and / or from one or more other nodes, e.g., via any communication technology. The processing circuitry 310 is configured to perform processing described above, e.g., in Figure 10, such as by executing instructions of a computer program 335 stored in a computer-readable storage medium 330. The processing circuitry 310 in this regard may implement certain functional means, units, or modules. Those skilled in the art will also appreciate that embodiments herein further include corresponding computer programs.

[0124] A computer program 335 comprises instructions which, when executed on at least one processor of a security agent device 14D, cause the security agent device 14D to carry out any of the respective processing described above. A computer program 335 in this regard may comprise one or more code modules corresponding to the means or units described above.

[0125] Embodiments further include a carrier containing such a computer program. This carrier may comprise one of an electronic signal, optical signal, radio signal, or computer-readable storage medium 330.

[0126] In this regard, embodiments herein also include a computer program product stored on a non-transitory computer readable (storage or recording) medium 330 and comprising instructions that, when executed by a processor of a security agent device 14D, cause the security agent device 14D to perform as described above.

[0127] Embodiments further include a computer program product comprising program code portions for performing the steps of any of the embodiments herein when the computer program product is executed by a security agent device 14D. This computer program product may be stored on a computer-readable recording medium 330.

[0128] Although the computing devices described herein (e.g., security agent device) may include the illustrated combination of hardware components, other embodiments may comprise computing devices with different combinations of components. It is to be understood that these computing devices may comprise any suitable combination of hardware and / or software needed to perform the tasks, features, functions and methods disclosed herein. Moreover, while components are depicted as single boxes located within a larger box, or nested within multiple boxes, in practice, computing devices may comprise multiple different physical components that make up a single illustrated component, and functionality may be partitioned between separate components. For example, a communication interface may be configured to include any of the components described herein, and / or the functionality of the components may be partitioned between the processing circuitry and the communication interface. In another example, non- computationally intensive functions of any of such components may be implemented in software or firmware and computationally intensive functions may be implemented in hardware.

[0129] In certain embodiments, some or all of the functionality described herein may be provided by processing circuitry executing instructions stored on in memory, which in certain embodiments may be a computer program product in the form of a non-transitory computer- readable storage medium. In alternative embodiments, some or all of the functionality may be provided by the processing circuitry without executing instructions stored on a separate or discrete device-readable storage medium, such as in a hard-wired manner. In any of those particular embodiments, whether executing instructions stored on a non-transitory computer- readable storage medium or not, the processing circuitry can be configured to perform the described functionality. The benefits provided by such functionality are not limited to the processing circuitry alone or to other components of the computing device, but are enjoyed by the computing device as a whole, and / or by end users and a wireless network generally.

Claims

CLAIMS1. A method performed by a security agent device (14D) configured to host a centralized or leader security agent (14LC) included in a set (14S) of security agents (14) for a communication network (10), wherein the security agents (14) in the set (14S) mutually monitor each other, the method comprising: controlling (200) one or more security agents (14) in the set (14S) to operate as one or more honeypot security agents (14H) that attempt to entice an attack (13) on the communication network (10); and evaluating (210) each of one or more monitored security agents (14M) in the set (14S) for behaviors characteristic of an unknown attack (13U) on the communication network (10), by, for each of the one or more monitored security agents (14M): obtaining (220) a first metric (19-1) for the monitored security agent (14M) reflecting how accurately or inaccurately the security agents (14) in the set (14S) cooperatively detect behaviors of the monitored security agent (14M) as being features of an attack (13) on the communication network (10); obtaining (230) a second metric (19-2) for the monitored security agent (14M) reflecting a rate at which the security agents (14) in the set (14S) cooperatively detect behaviors of the monitored security agent (14M) as being features of an attack (13) on the communication network (10); and deciding (240), based on the first metric (19-1) and the second metric (19-2), whether or not behaviors of the monitored security agent (14M) are features of an unknown attack (13U) on the communication network (10), wherein an unknown attack (13U) is a type of attack (13) that the security agents (14) have not detected before.

2. The method of claim 1 , wherein deciding whether or not behaviors of a monitored security agent (14M) are features of an unknown attack (13U) on the communication network (10) is based on whether or not the second metric (19-2) for the monitored security agent (14M) exceeds the first metric (19-1) for the monitored security agent (14M).

3. The method of any one of claims 1-2, wherein the second metric (19-2) for a monitored security agent (14M) reflects: an attack detection rate for a monitored security agent (14M) comprising the rate at which the security agents (14) in the set (14S) cooperatively detect behaviors of the monitored security agent (14M) as being features of an attack (13) on the communication network (10);a known attack feature determination rate for the monitored security agent (14M) comprising a rate at which the security agents (14) in the set (14S) cooperatively determine features of known attacks from monitoring behaviors of the monitored security agent (14M), wherein a known attack is a type of attack (13) that the security agents (14) has detected before; and an unknown attack feature determination rate for the monitored security agent (14M) comprising a rate at which the security agents (14) in the set (14S) cooperatively determine features of unknown attacks (13U) from monitoring behaviors of the monitored security agent (14M).

4. The method of claim 3, wherein deciding whether or not behaviors of a monitored security agent (14M) are features of an unknown attack (13U) on the communication network (10) is based on: the first metric (19-1) for the monitored security agent (14M); the second metric (19-2) for the monitored security agent (14M); the known attack feature determination rate for the monitored security agent (14M); and the unknown attack feature determination rate for the monitored security agent (14M).

5. The method of claim 4, wherein deciding whether or not behaviors of a monitored security agent (14M) are features of an unknown attack (13U) on the communication network (10) comprises deciding that behaviors of the monitored security agent (14M) are features of an unknown attack (13U) on the communication network (10) if: the first metric (19-1) for the monitored security agent (14M) exceeds the second metric (19-2) for the monitored security agent (14M); and the unknown attack feature determination rate for the monitored security agent (14M) exceeds the known attack feature determination rate for the monitored security agent (14M).

6. The method of any one of claims 3-5, wherein said evaluating further comprises evaluating each of the one or more monitored security agents (14M) for behaviors characteristic of a known attack on the communication network (10), by, for each of the one or more monitored security agents (14M), deciding that behaviors of the monitored security agent (14M) are features of a known attack on the communication network (10) if: the first metric (19-1) for the monitored security agent (14M) exceeds the second metric (19-2) for the monitored security agent (14M); andthe known attack feature determination rate for the monitored security agent (14M) exceeds the unknown attack feature determination rate for the monitored security agent (14M).

7. The method of any one of claims 3-6, wherein said evaluating further comprises, for each of the one or more monitored security agents (14M), deciding that behaviors of the monitored security agent (14M) are benign if the second metric (19-2) for the monitored security agent (14M) exceeds the first metric (19-1) for the monitored security agent (14M).

8. The method of any one of claims 3-5, wherein the second metric (19-2) for a monitored security agent (14M) is obtained as+a3 * NF, where:KF is the known attack feature determination rate for the monitored security agent (14M);NF is the unknown attack feature determination rate for the monitored security agent (14M);AD is the attack detection rate for the monitored security agent (14M); and a- , c 2 andare each a weight parameter G [0,1] .

9. The method of any of claims 1-8, wherein the first metric (19-1) for a monitored security agent (14M) is a function of a false positive rate and / or a false negative rate for the monitored security agent (14M), wherein the false positive rate for the monitored security agent (14M) is a rate at which the security agents (14) in the set (14S) incorrectly detect behaviors of the monitored security agent (14M) as being features of an attack (13) on the communication network (10), and wherein the false negative rate is a rate at which the security agents (14) in the set (14S) fail to detect behaviors of the monitored security agent (14M) as being features of an attack (13) on the communication network (10).

10. The method of claim 9, wherein the first metric (19-1) for a monitored security agent(14M) is obtainederg * FN, where:FP is the false positive rate for the monitored security agent (14M);FN is the false negative rate for the monitored security agent (14M); and c 4 and erg are each a weight parameter G [0,1] .11 . The method of any one of claims 1 -10, wherein said evaluating is performed during each of multiple evaluation intervals, and wherein the method comprises, in between at least some evaluation intervals, adapting one or more security parametersof one or more of the security agents (14) in the set (14S) as needed to increase the second metric (19-2) for the monitored security agent (14M) and / or decrease the first metric (19-1) for the monitored security agent (14M).

12. The method of any one of claims 1 -1 1 , wherein: one or more security agents (14) in the set (14S) are deployed at one or more respective radio network nodes in the communication network (10); one or more security agents (14) in the set (14S) are deployed at one or more respective edge computing servers in the communication network (10); one or more security agents (14) in the set (14S) are deployed at one or more network data analytics functions, NWDAFs, in the communication network (10); and / or one or more security agents (14) in the set (14S) are deployed at one or more access and mobility management functions, AMFs, in the communication network (10).

13. The method of any one of claims 1-12, wherein the security agents (14) in the set (14S) include: the one or more honeypot security agents (14H) that each attempt to entice an unknown attack (13U) on the communication network (10), by intentionally attracting an attack (13) on the honeypot security agent (14H) or by mimicking malicious cooperation with the monitored security agent (14M), and that each monitor the monitored security agent (14M) to determine features of unknown attacks (13U); one or more follower security agents (14F) that each monitor the monitored security agent (14M) to determine features of known attacks according to a rule-based algorithm that defines features of known attacks in terms of one or more rules; and a centralized or leader security agent (14LC) that executes a hybrid attack detection algorithm to detect an attack (13) on the communication network (10) based on features determined by the one or more honeypot security agents (14H) and the one or more follower security agents (14F), wherein according to the hybrid attack detection algorithm the centralized or leader security agent (14LC) selects between: a machine learning algorithm that detects attacks by the monitored security agent (14M) based on a machine learning model trained, using training data, to detect attacks (13); and a rule-based algorithm that detects attacks (13) by the monitored security agent (14M) based on one or more rules.

14. The method of any of claims 1-13, further comprising, for each of the one or more monitored security agents (14M), controlling (250) with which role, if any, the monitored security agent (14M) operates for detecting attacks (13) in the communication network (10), based on the first metric (19-1) and the second metric (19-2) for the monitored security agent (14M).

15. The method of claim 14, wherein controlling with which role, if any, a monitored security agent (14M) operates comprises: activating the monitored security agent (14M) in one of multiple possible roles if the second metric (19-2) for the monitored security agent (14M) exceeds the first metric (19-1) for the monitored security agent (14M); or deactivating the monitored security agent (14M) from operating in any of the multiple possible roles if the first metric (19-1) for the monitored security agent (14M) exceeds the second metric (19-2) for the monitored security agent (14M).

16. The method of claim 15, wherein activating a monitored security agent (14M) in one of the multiple possible roles comprises activating the monitored security agent (14M) in a role as a honeypot security agent (14H) if a weighted attack detection rate for the monitored security agent (14M) exceeds the first metric (19-1) for the monitored security agent (14M), wherein an attack detection rate for the monitored security agent (14M) is the rate at which the security agents (14) in the set (14S) cooperatively detect behaviors of the monitored security agent (14M) as being features of an attack (13) on the communication network (10), wherein the weighted attack detection rate for the monitored security agent (14M) is the attack detection rate for the monitored security agent (14M) as weighted by a weight parameter.

17. The method of any one of claims 15-16, wherein activating a monitored security agent (14M) in one of the multiple possible roles comprises activating the monitored security agent (14M) in a role as a follower security agent (14F) if a known attack feature determination rate for the monitored security agent (14M) exceeds an unknown attack feature determination rate for the monitored security agent (14M), wherein the known attack feature determination rate for the monitored security agent (14M) comprises a rate at which the security agents (14) in the set (14S) cooperatively determine features of known attacks from monitoring behaviors of the monitored security agent (14M), wherein a known attack is a type of attack (13) that the security agents (14) has detected before, and wherein the unknown attack feature determination rate for the monitored security agent (14M) comprises a rate at which the security agents (14) in the set (14S) cooperatively determine features of unknown attacks (13U) from monitoring behaviors of the monitored security agent (14M).

18. The method of any one of claims 15-17, wherein activating a monitored security agent (14M) in one of the multiple possible roles comprises activating the monitored security agent (14M) in a role as a centralized or leader security agent (14LC) if an unknown attack feature determination rate for the monitored security agent (14M) exceeds a known attack feature determination rate for the monitored security agent (14M), wherein the known attack feature determination rate for the monitored security agent (14M) comprises a rate at which the security agents (14) in the set (14S) cooperatively determine features of known attacks from monitoring behaviors of the monitored security agent (14M), wherein a known attack is a type of attack (13) that the security agents (14) has detected before, and wherein the unknown attack feature determination rate for the monitored security agent (14M) comprises a rate at which the security agents (14) in the set (14S) cooperatively determine features of unknown attacks (13U) from monitoring behaviors of the monitored security agent (14M).

19. A security agent device (14D) configured to host a centralized or leader security agent (14LC) included in a set (14S) of security agents (14) for a communication network (10), wherein the security agents (14) in the set (14S) mutually monitor each other, the security agent device (14D) configured to: control one or more security agents (14) in the set (14S) to operate as one or more honeypot security agents (14H) that attempt to entice an attack (13) on the communication network (10); and evaluate each of one or more monitored security agents (14M) in the set (14S) for behaviors characteristic of an unknown attack (13U) on the communication network (10), by, for each of the one or more monitored security agents (14M): obtaining a first metric (19-1) for the monitored security agent (14M) reflecting how accurately or inaccurately the security agents (14) in the set (14S) cooperatively detect behaviors of the monitored security agent (14M) as being features of an attack (13) on the communication network (10); obtaining a second metric (19-2) for the monitored security agent (14M) reflecting a rate at which the security agents (14) in the set (14S) cooperatively detect behaviors of the monitored security agent (14M) as being features of an attack (13) on the communication network (10); and deciding, based on the first metric (19-1) and the second metric (19-2), whether or not behaviors of the monitored security agent (14M) are features of an unknown attack (13U) on the communication network (10), wherein an unknown attack (13U) is a type of attack (13) that the security agents (14) have not detected before.

20. The security agent device (14D) of claim 19, configured to perform the method of any one of claims 2-16.

21. A computer program (335) comprising instructions which, when executed by at least one processor of a security agent device (14D), causes the security agent device (14D) to perform the method of any one of claims 1-18.

22. A carrier containing the computer program (335) of claim 21 , wherein the carrier is one of an electronic signal, optical signal, radio signal, or computer-readable storage medium (330).

23. A security agent device (14D) configured to host a centralized or leader security agent (14LC) included in a set (14S) of security agents (14) for a communication network (10), wherein the security agents (14) in the set (14S) mutually monitor each other, the security agent device (14D) comprising: processing circuitry (310); and memory (330) containing instructions executable by the processing circuitry (310) whereby the security agent device (14D) is configured to: control one or more security agents (14) in the set (14S) to operate as one or more honeypot security agents (14H) that attempt to entice an attack (13) on the communication network (10); and evaluate each of one or more monitored security agents (14M) in the set (14S) for behaviors characteristic of an unknown attack (13U) on the communication network (10), by, for each of the one or more monitored security agents (14M): obtaining a first metric (19-1) for the monitored security agent (14M) reflecting how accurately or inaccurately the security agents (14) in the set (14S) cooperatively detect behaviors of the monitored security agent (14M) as being features of an attack (13) on the communication network (10); obtaining a second metric (19-2) for the monitored security agent (14M) reflecting a rate at which the security agents (14) in the set (14S) cooperatively detect behaviors of the monitored security agent (14M) as being features of an attack (13) on the communication network (10); and deciding, based on the first metric (19-1) and the second metric (19-2), whether or not behaviors of the monitored security agent (14M) are features of an unknown attack (13U) on the communicationnetwork (10), wherein an unknown attack (13U) is a type of attack (13) that the security agents (14) have not detected before.

24. The security agent device (14D) of claim 23, the memory (330) containing instructions executable by the processing circuitry (310) whereby the security agent device (14D) is further configured to perform the method of any one of claims 2-18.

25. A non-transitory computer-readable storage medium (330) on which is stored a computer program (335) comprising instructions that, when executed by a processor of a security agent device (14D) configured to host a centralized or leader security agent (14LC) included in a set (14S) of security agents (14) that mutually monitor each other in a communication network (10), causes the security agent device (14D) to: control one or more security agents (14) in the set (14S) to operate as one or more honeypot security agents (14H) that attempt to entice an attack (13) on the communication network (10); and evaluate each of one or more monitored security agents (14M) in the set (14S) for behaviors characteristic of an unknown attack (13U) on the communication network (10), by, for each of the one or more monitored security agents (14M): obtaining a first metric (19-1) for the monitored security agent (14M) reflecting how accurately or inaccurately the security agents (14) in the set (14S) cooperatively detect behaviors of the monitored security agent (14M) as being features of an attack (13) on the communication network (10); obtaining a second metric (19-2) for the monitored security agent (14M) reflecting a rate at which the security agents (14) in the set (14S) cooperatively detect behaviors of the monitored security agent (14M) as being features of an attack (13) on the communication network (10); and deciding, based on the first metric (19-1) and the second metric (19-2), whether or not behaviors of the monitored security agent (14M) are features of an unknown attack (13U) on the communication network (10), wherein an unknown attack (13U) is a type of attack (13) that the security agents (14) have not detected before.

Citation Information

Patent Citations

  • A collaborative security process

    WO2023153990A1

  • Security framework for a network

    WO2024012681A1