Apparatus, method, and computer program
By configuring UE and NF to monitor and report security events, the solution addresses inefficiencies in existing systems, enabling effective security management and real-time risk mitigation.
Patent Information
- Application Number
- PCT/EP2025/050382
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-02-08
- Filing Date
- 2025-01-09
- Publication Date
- 2025-08-14
AI Technical Summary
Existing communication systems lack mechanisms for efficiently monitoring and reporting security events, such as integrity check failures, in user equipment (UE) and network functions (NF), leading to inefficient security management.
Implement mechanisms for configuring UE and NF to monitor security events and transmit security log reports (SLR) including security logs, using configuration information that specifies events to be monitored, reporting criteria, and security metrics, with support for different UE types and network functions.
Enhances the management of security events by enabling efficient monitoring and reporting, allowing for real-time analysis and risk mitigation, thereby improving overall system security.
Smart Images

Figure EP2025050382_14082025_PF_FP_ABST
Abstract
Description
[0001] APPARATUS, METHOD, AND COMPUTER PROGRAM
[0002] Field of the disclosure
[0003] The present disclosure relates to an apparatus, a method, and a computer program for managing security in a communication system.
[0004] Background
[0005] A communication system can be seen as a facility that enables communication sessions between two or more entities such as communication devices, base stations (BSs) and / or other nodes by providing carriers between the various entities involved in the communications path.
[0006] The communication system may be a wireless communication system. Examples of wireless systems comprise public land mobile networks (PLMN) operating based on radio standards such as those provided by 3GPP, satellite based communication systems and different wireless local networks, for example wireless local area networks (WLAN). The wireless systems can typically be divided into cells, and are therefore often referred to as cellular systems.
[0007] The communication system and associated devices typically operate in accordance with a given standard or specification which sets out what the various entities associated with the system are permitted to do and how that should be achieved. Communication protocols and / or parameters which shall be used for the connection are also typically defined. Examples of standards are the so-called 5G standards.
[0008] Summary
[0009] According to an aspect there is provided a method comprising: receiving configuration information for monitoring at least one security event and transmitting a security log report including at least one security log for the at least one security event, wherein the configuration information indicates the at least one security event to be monitored and a criterion to transmit the security log report including the at least one security log for the at least one security event; applying the configuration information; monitoring the at least one security event; and transmitting the security log report including the at least one security log for the at least one security event.
[0010] The configuration information may be received from a policy control function.
[0011] The configuration information may be received indirectly via at least one of an access management function or a base station. The configuration information may be received directly.
[0012] The security log report may be transmitted to a continuous security monitoring and analytics function or an edge computing server.
[0013] The security log report may be transmitted indirectly via at least one of a base station or an access management function. The security log report may be transmitted directly.
[0014] The continuous security monitoring and analytics function may be a network function or a third-party application function.
[0015] The configuration information may be further for computing a security metrics and transmitting the security metrics; and the method may comprise: computing the security metrics; and transmitting the security metrics.
[0016] The configuration information may further indicate at least one of: a parameter to be monitored; a layer to be monitored; an interface to be monitored; a level of details of the security log report; a format of the security log report; or a security metrics to be computed. The level of details of the security log report may indicate parameters to be included in the at least one security log.
[0017] The level of details of the security log report may indicate security logs to be included in the at least one security log report.
[0018] The level of details of the security log report may indicate security logs to be included in the at least one security log report.
[0019] The format may comprise a plurality of key value pairs including at least one of: a source identifier key value pair identifying a source; a destination identifier identifying a destination; a protocol key value pair indicating a protocol; a security event key value pair indicating a security event; or a confidence value key value pair indicating a confidence value that a security event occurred.
[0020] The criterion to transmit the security log report may comprise at least one of: a threshold; a periodicity; or a geographic area.
[0021] The method may be performed by a user equipment, a base station or a network function.
[0022] The method may be performed by a user equipment and the configuration information may be dependent on a type of the user equipment.
[0023] The method may comprise: transmitting, to the policy control function, capabilities information indicating a type of the user equipment; and receiving, from the policy control function, the configuration information dependent on the type of the user equipment.
[0024] The type of the user equipment may comprise: a smartphone; an Internet of things device; an extended reality device; or an unmanned aerial vehicle. The configuration information may be received after an access stratum security context is established, using access stratum security encryption and integrity protection keys.
[0025] The method may comprise: receiving updated configuration information for monitoring the at least one security event and transmitting a security log report including at least one security log for the at least one security event; applying the updated configuration information; monitoring the at least one security event; and transmitting the security log report including at least one security log for the at least one security event.
[0026] According to an aspect there is provided an apparatus comprising means for: receiving configuration information for monitoring at least one security event and transmitting a security log report including at least one security log for the at least one security event, wherein the configuration information indicates the at least one security event to be monitored and a criterion to transmit the security log report including the at least one security log for the at least one security event; applying the configuration information; monitoring the at least one security event; and transmitting the security log report including the at least one security log for the at least one security event.
[0027] The configuration information may be received from a policy control function.
[0028] The configuration information may be received indirectly via at least one of an access management function or a base station. The configuration information may be received directly.
[0029] The security log report may be transmitted to a continuous security monitoring and analytics function or an edge computing server.
[0030] The security log report may be transmitted indirectly via at least one of a base station or an access management function. The security log report may be transmitted directly. The continuous security monitoring and analytics function may be a network function or a third-party application function.
[0031] The configuration information may be further for computing a security metrics and transmitting the security metrics; and the apparatus may comprise means for: computing the security metrics; and transmitting the security metrics.
[0032] The configuration information may further indicate at least one of: a parameter to be monitored; a layer to be monitored; an interface to be monitored; a level of details of the security log report; a format of the security log report; or a security metrics to be computed.
[0033] The level of details of the security log report may indicate parameters to be included in the at least one security log.
[0034] The level of details of the security log report may indicate security logs to be included in the at least one security log report.
[0035] The level of details of the security log report may indicate security logs to be included in the at least one security log report.
[0036] The format may comprise a plurality of key value pairs including at least one of: a source identifier key value pair identifying a source; a destination identifier identifying a destination; a protocol key value pair indicating a protocol; a security event key value pair indicating a security event; or a confidence value key value pair indicating a confidence value that a security event occurred.
[0037] The criterion to transmit the security log report may comprise at least one of: a threshold; a periodicity; or a geographic area.
[0038] The apparatus may be a user equipment, a base station or a network function. The apparatus may be a user equipment and the configuration information may be dependent on a type of the user equipment.
[0039] The apparatus may comprise means for: transmitting, to the policy control function, capabilities information indicating a type of the user equipment; and receiving, from the policy control function, the configuration information dependent on the type of the user equipment.
[0040] The type of the user equipment may comprise: a smartphone; an Internet of things device; an extended reality device; or an unmanned aerial vehicle.
[0041] The configuration information may be received after an access stratum security context is established, using access stratum security encryption and integrity protection keys. the apparatus may comprise means for: receiving updated configuration information for monitoring the at least one security event and transmitting a security log report including at least one security log for the at least one security event; applying the updated configuration information; monitoring the at least one security event; and transmitting the security log report including at least one security log for the at least one security event.
[0042] According to an aspect there is provided an apparatus comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to: receive configuration information for monitoring at least one security event and transmitting a security log report including at least one security log for the at least one security event, wherein the configuration information indicates the at least one security event to be monitored and a criterion to transmit the security log report including the at least one security log for the at least one security event; apply the configuration information; monitor the at least one security event; and transmit the security log report including the at least one security log for the at least one security event. According to an aspect there is provided an apparatus comprising circuitry configured to: receive configuration information for monitoring at least one security event and transmitting a security log report including at least one security log for the at least one security event, wherein the configuration information indicates the at least one security event to be monitored and a criterion to transmit the security log report including the at least one security log for the at least one security event; apply the configuration information; monitor the at least one security event; and transmit the security log report including the at least one security log for the at least one security event.
[0043] According to an aspect there is provided a computer program comprising computer executable code which when run on at least one processor is configured to: receive configuration information for monitoring at least one security event and transmitting a security log report including at least one security log for the at least one security event, wherein the configuration information indicates the at least one security event to be monitored and a criterion to transmit the security log report including the at least one security log for the at least one security event; apply the configuration information; monitor the at least one security event; and transmit the security log report including the at least one security log for the at least one security event.
[0044] According to an aspect there is provided a method comprising: receiving security policies; translating the security policies into configuration information for configuring monitoring at least one security event and transmitting a security log report including at least one security log for the at least one security event, wherein the configuration information indicates the at least one security event to be monitored and a criterion to transmit the security log report including the at least one security log for the at least one security event; and transmitting the configuration information.
[0045] The security policies may be received from an operator or an operation administration and maintenance system. The configuration may be transmitted to a user equipment, a base station or a network function.
[0046] The configuration information may be transmitted indirectly via at least one of an access management function or a base station. The configuration information may be transmitted directly.
[0047] The method may be performed by a policy control function.
[0048] According to an aspect there is provided an apparatus comprising means for: receiving security policies; translating the security policies into configuration information for configuring monitoring at least one security event and transmitting a security log report including at least one security log for the at least one security event, wherein the configuration information indicates the at least one security event to be monitored and a criterion to transmit the security log report including the at least one security log for the at least one security event; and transmitting the configuration information.
[0049] The security policies may be received from an operator or an operation administration and maintenance system.
[0050] The configuration may be transmitted to a user equipment, a base station or a network function.
[0051] The configuration information may be transmitted indirectly via at least one of an access management function or a base station. The configuration information may be transmitted directly.
[0052] The apparatus may be a policy control function.
[0053] According to an aspect there is provided an apparatus comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to: receive security policies; translate the security policies into configuration information for configuring monitoring at least one security event and transmitting a security log report including at least one security log for the at least one security event, wherein the configuration information indicates the at least one security event to be monitored and a criterion to transmit the security log report including the at least one security log for the at least one security event; and transmit the configuration information.
[0054] According to an aspect there is provided an apparatus comprising circuitry configured to: receive security policies; translate the security policies into configuration information for configuring monitoring at least one security event and transmitting a security log report including at least one security log for the at least one security event, wherein the configuration information indicates the at least one security event to be monitored and a criterion to transmit the security log report including the at least one security log for the at least one security event; and transmit the configuration information.
[0055] According to an aspect there is provided a computer program comprising computer executable code which when run on at least one processor is configured to: receive security policies; translate the security policies into configuration information for configuring monitoring at least one security event and transmitting a security log report including at least one security log for the at least one security event, wherein the configuration information indicates the at least one security event to be monitored and a criterion to transmit the security log report including the at least one security log for the at least one security event; and transmit the configuration information.
[0056] According to an aspect, there is provided a computer readable medium comprising program instructions stored thereon for performing at least one of the above methods.
[0057] According to an aspect, there is provided a non-transitory computer readable medium comprising program instructions stored thereon for performing at least one of the above methods. According to an aspect, there is provided a non-volatile tangible memory medium comprising program instructions stored thereon for performing at least one of the above methods.
[0058] In the above, many different aspects have been described. It should be appreciated that further aspects may be provided by the combination of any two or more of the aspects described above.
[0059] Various other aspects are also described in the following detailed description and in the attached claims.
[0060] List of abbreviations
[0061] AF: Application Function
[0062] AMF: Access and Mobility Management Function
[0063] API: Application Programming Interface
[0064] AS: Access Stratum
[0065] BS: Base Station
[0066] CU: Centralized Unit
[0067] DU: Distributed Unit gNB: gNodeB loT : Internet of Things
[0068] LTE: Long Term Evolution
[0069] MAC-1: Message Authentication Code Integrity
[0070] MDAS: Management Data Analytics Function
[0071] MDT: Minimization of Drive Test
[0072] MS: Mobile Station
[0073] MTC: Machine Type Communication
[0074] NAS: Non-Access Stratum
[0075] NEF: Network Exposure Function
[0076] NMS: Network Management Function
[0077] NF: Network Function NR: New radio
[0078] NRF: Network Repository Function
[0079] NRF: Network Repository Function
[0080] NWDAF: Network Data Analytics Function
[0081] 0AM: Operation Administration and Maintenance
[0082] PCF: Policy Control Function
[0083] PDCP: Packet Data Convergence Protocol
[0084] ProSe: Proximity Service
[0085] RAM: Random Access Memory
[0086] RAN: Radio Access Network
[0087] RLF: Radio Link Failure
[0088] ROM: Read Only Memory
[0089] SD-ID: Structured Data Identifier
[0090] SD-PARAM: Structured Data Parameter
[0091] SLR: Security Log Report
[0092] SMF: Session Management Function
[0093] TS: Technical Specification
[0094] UE: User Equipment
[0095] 3GPP: 3rdGeneration Partnership Project
[0096] 5G: 5thGeneration
[0097] 5GC: 5G Core network
[0098] 5GS: 5G System
[0099] Brief Description of the Figures
[0100] Embodiments will now be described, by way of example only, with reference to the accompanying Figures in which:
[0101] Fig. 1 shows a schematic representation of a 5G system;
[0102] Fig. 2 shows a schematic representation of a control apparatus;
[0103] Fig. 3 shows a schematic representation of a user equipment; Fig. 4 shows a schematic representation of a user equipment and a base station transmitting, to a continuous security monitoring and analytics function, security log reports including security logs for security events;
[0104] Fig. 5 shows a signalling diagram of a process for managing security in a communication system;
[0105] Fig. 6 shows a block diagram of a method for managing security in a communication system, where the method is performed by a user equipment, a base station or a network function;
[0106] Fig. 7 shows a block diagram of a method for managing security in a communication system, where the method is performed by a policy control function; and
[0107] Fig. 8 shows a schematic representation of a non-volatile memory medium storing instructions which when executed by a processor allow a processor to perform one or more of the steps of the methods of Fig. 6 and Fig. 7.
[0108] Detailed Description of the Figures
[0109] In the following certain embodiments are explained with reference to mobile communication devices capable of communication via a wireless cellular system and mobile communication systems serving such mobile communication devices. Before explaining in detail the exemplifying embodiments, certain general principles of a wireless communication system, access systems thereof, and mobile communication devices are briefly explained with reference to Fig. 1 , Fig.2 and Fig.3 to assist in understanding the technology underlying the described examples.
[0110] FIG. 1 shows a schematic representation of a 5G system (5GS). The 5GS may comprises a user equipment (UE), a (radio) access network (RAN), a 5G core network (5GC), one or more application functions (AF) and one or more data networks (DN). The 5G RAN may comprise one or more gNodeBs (gNB). The one or more gNBs may comprise one or more distributed unit functions connected to centralized unit functions.
[0111] The 5G may comprise one or more edge computing servers.
[0112] The 5GC may comprise a policy control function (PCF), a network exposure function (NEF), a network repository function (NRF), a user data management (UDM), a network data analytics function (NWDAF) or management data analytics function (MDAF), an authentication server function (ALISF), an access and mobility management function (AMF), a session management function (SMF) or other network functions (NFs).
[0113] The 5GS may comprise a continuous security monitoring and analytics function (CSMAF). The CSMAF may be collocated with the NWDAF or MDAF, with a third-party application function (AF) or with an operation administration and maintenance (0AM) or network management system (NMS).
[0114] Fig. 2 illustrates an example of a control apparatus 200 for controlling a function of the RAN or the 5GC as illustrated on Fig. 1 . The control apparatus may comprise at least one random access memory (RAM) 211a, at least on read only memory (ROM) 211b, at least one processor 212, 213 and an input / output interface 214. The at least one processor 212, 213 may be coupled to the RAM 211a and the ROM 211 b. The at least one processor 212, 213 may be configured to execute an appropriate software code 215. The software code 215 may for example allow to perform one or more steps to perform one or more of the present aspects. The software code 215 may be stored in the ROM 211 b. The control apparatus 200 may be interconnected with another control apparatus 200 controlling another function of the 5G RAN or the 5GC. In some embodiments, each function of the RAN or the 5GC comprises a control apparatus 200. In alternative embodiments, two or more functions of the RAN or the 5GC may share a control apparatus. Fig. 3 illustrates an example of a UE 300, such as the UE illustrated on Fig. 1. The UE 300 may be provided by any device capable of sending and receiving radio signals. Non-limiting examples comprise a user equipment, a mobile station (MS) or mobile device such as a mobile phone or what is known as a ’smart phone’, a computer provided with a wireless interface card or other wireless interface facility (e.g., USB dongle), a personal data assistant (PDA) or a tablet provided with wireless communication capabilities, a machine-type communications (MTC) device, a Cellular Internet of things (CloT) device or any combinations of these or the like. The UE 300 may provide, for example, communication of data for carrying communications. The communications may be one or more of voice, electronic mail (email), text message, multimedia, data, machine data and so on.
[0115] The UE 300 may receive signals over an air or radio interface 307 via appropriate apparatus for receiving and may transmit signals via appropriate apparatus for transmitting radio signals. In Fig. 3 transceiver apparatus is designated schematically by block 306. The transceiver apparatus 306 may be provided for example by means of a radio part and associated antenna arrangement. The antenna arrangement may be arranged internally or externally to the mobile device.
[0116] The UE 300 may be provided with at least one processor 301 , at least one memory ROM 302a, at least one RAM 302b and other possible components 303 for use in software and hardware aided execution of tasks it is designed to perform, including control of access to and communications with access systems and other communication devices. The at least one processor 301 is coupled to the RAM 302b and the ROM 302a. The at least one processor 301 may be configured to execute an appropriate software code 308. The software code 308 may for example allow to perform one or more of the present aspects. The software code 308 may be stored in the ROM 302a.
[0117] The processor, storage and other relevant control apparatus can be provided on an appropriate circuit board and / or in chipsets. This feature is denoted by reference 304. The device may optionally have a user interface such as keypad 305, touch sensitive screen or pad, combinations thereof or the like. Optionally one or more of a display, a speaker and a microphone may be provided depending on the type of the device.
[0118] 3GPP standards provide mechanisms for configuring a UE to monitor minimization of drive test (MDT) events and transmitting an MDT log report including MDT logs for the MDT events and mechanisms for configuring a UE to monitor radio link failure (RLF) events and transmitting an RLF log report including RLF logs for the RLF events.
[0119] However, 3GPP standards do not provide mechanisms for configuring a UE to monitor security events and transmitting a security log report including security logs for the security events. As a result, the management of security events may be inefficient.
[0120] One or more aspects of this disclosure relate to providing mechanisms for configuring a UE, a BT or a NF to monitor security events and transmitting a security log report (SLR) including security logs for the security events.
[0121] An operator or the 0AM may transmit, to the PCF, security policies. The PCF may translate the security policies into configuration information. The configuration information may be for configuring the monitoring of security events. The configuration information may be for configuring the transmitting of a SLR including security logs for the security events.
[0122] The UE, BS or NF may receive, from the PCF, the configuration information.
[0123] The configuration information may indicate the security events (e.g., integrity check failures for a call, in particular message authentication code integrity (MAC-1) check failures) to be monitored. The configuration information may indicate the security events using enable and disable flags. For example, a security event with an enable flag is to be monitored whereas a security event with a disable flag is not to be monitored The configuration information may indicate layers associated with the security events to be monitored (e.g., packet data convergence protocol (PDPC) layer).
[0124] The configuration information may indicate parameters to be monitored (e.g., threshold for detecting a burst of packets).
[0125] The configuration information may indicate a level of details of the SLR. The level of details of the SLR may indicate parameters to be included in each security log. The level of details of the SLR may indicate security logs to be included in a SLR.
[0126] For example, a level 0 (high level of details) may indicate that all parameters associated with the security events may be included in the security logs for the security events. The level 0 (maximum level of details) may indicate that all security logs for the security events may be included in the SLR. Level 0 (maximum level of details) may be detrimental for performance but may be used at certain times of the day when the load on the network is low.
[0127] A level 1 (low level of details) may indicate that some parameters (e.g., more important parameters) associated the security events may be included in the security logs for the security events and other parameters (e.g., less important parameters) associated the security events may not be included in the security logs for the security events.
[0128] A level 2 (low level of details) may indicate that some security logs (e.g., more important security logs) for the security events may be included in the SLR and other security logs (e.g., less important security logs) for the security events may not be included in the SLR.
[0129] The configuration information may indicate a format of the SLR. The format may comprise a plurality of key value pairs. The plurality of key value pairs may be standardized. This may facilitate analysing the SLR using an artificial intelligence / machine learning model. The plurality of key value pairs may identify parameters associated with the security events.
[0130] The plurality of key value pairs may include a source identifier key value pair identifying a source (e.g., UE identifier used during a proximity service (ProSe) communication, API identifier used over a common API framework, gobally unique temporary UE identifier, BS identifier).
[0131] The plurality of key value pairs may include a destination identifier identifying a destination (e.g., UE identifier used during a proximity service (ProSe) communication), a protocol key value pair indicating a protocol (e.g., radio protocol, Bluetooth, near-field communication, common API framework, transport layer security), a security event key value pair indicating a security event (e.g., denial of service attack, replay attack)) or a confidence value key value pair indicating a confidence value that a security event occurred. The format may or may not comprise syslog (e.g., comma separated values).
[0132] The configuration information may indicate a criterion to transmit the SLR. The criterion to report the security log may comprise at least one of a threshold, a periodicity or a geographic area. For example, the UE may transmit the SLR when the number of occurrence of a security event is above a threshold. The UE may transmit the SLR every N minutes, where N is a positive integer. The UE may transmit the SLR when the UE is located within a geographic area.
[0133] The configuration information may be dependent on a type of the UE. That is, the configuration information received by a UE of a type may be different from the configuration information received by a UE of another type. A type of the UE may comprise a smartphone, an loT device, an extended reality device or an unmanned aerial vehicle.
[0134] For example, the configuration information received by a UE of the type loT device may be different from the configuration information received by a UE of the type unmanned aerial vehicle. The UE of a type loT device to transmit a SLR including security logs for the security events with a lower level of details and less frequently to save energy. This may allow the UE of the type unmanned aerial vehicle to transmit a SLR including security logs for the security events with a greater level of details and more frequently to ensure in-flight security.
[0135] The configuration information may further be for computing a security metrics and transmitting the security metrics. A security metrics may comprise a key performance indicator or a count. For example, a security metrics may comprise a count (i.e., a number) of occurrences of a security event that is monitored (e.g., a number of integrity verification failures on a PDCP layer during a time interval). The security metrics mat comprise a count (i.e., a number) of occurrences of a parameter that is monitored (e.g., number of message with a a same message sequence number received during a time interval).
[0136] The configuration information may indicate the security metrics.
[0137] The configuration information may indicate a criterion to transmit the security metrics. The criterion to report the security metrics may comprise a periodicity. For example, the UE may transmit the SLR when the number of occurrence of a security event is above a threshold. The UE may transmit the SLR every M minutes, where M is a positive integer. The periodicity to transmit the security metrics and the periodicity to transmit SLR may the same or may be different.
[0138] The UE, BS or NF may apply the configuration information. The UE, BS or NF may configure the monitoring of security events based on the configuration information. The UE, BS or NF may configure the transmitting, to the CSMAF, of a security log report including security logs for the security events.
[0139] The UE, BS or NF may monitor security events based on the configuration information. The UE, BS or NF may generate a SLR and may transmit, to the CSMAF or the edge computing server, a SLR based on the configuration information. The SLR may include security logs for the security events.
[0140] In an example, the UE may transmit, to the edge computing server, a SLR with a format that is not syslog. The edge computing server may convert the format of the SLR into syslog. The edge computing server may transmit the SLR to the CSMAF.
[0141] In another example, the UE may transmit, to the edge computing server, a SLR with a format that is or that is not syslog. The edge computing server may generate an analysis of the SLR. The edge computing server may transmit the analysis of the SLR to the CSMAF.
[0142] The SLR or analysis of the SLR may be transmitted, to the CSMAF, as a file or as a stream. The SLR or analysis of the SLR may be transmitted, to the CSMAF, using a transport layer security protocol or another safe protocol, when the CSMAF is collocated with a third-party application function.
[0143] The UE, BS or NF may compute the security metrics based on the configuration information.
[0144] The UE, BS or NF may transmit the security metrics based on the configuration information. The UE, BS or NF may transmit the security metrics along with the SLR or separately (i. e. , the security metrics may or may not be part of the SLR).
[0145] Fig. 4 shows a schematic representation of a UE and a BS transmitting, to the CSMAF, SLRs.
[0146] In an example, the configuration information received by a UE may comprise a generic part for all types of UEs and a specific part for the specific type of the UE. The generic part of the configuration information may indicate that the security events to be monitored comprise distributed denial of service attacks, replay attacks, structure query language injection attacks, distributed brute force attacks, attacks on web applications, domain name system spoofing attacks and native artificial intelligence attacks.
[0147] The generic part of the configuration information may indicate that the level of details for the SLR is level 0, level 1 or level 2.
[0148] The generic part of the configuration information may indicate that the format of the SLR is syslog.
[0149] The generic part of the configuration information may indicate that the criteria to transmit the SLR is a periodicity.
[0150] When the type of the UE is a smartphone, the specific part of the configuration information may indicate that the security events to be monitored further comprise application isolation violations, backdoor detections, privilege escalations in an operating system, false base station detections, crypto mining detections. The specific part of the configuration information may indicate that an interface to be monitored comprises a ProSe interface, a vehicle to everything interface or a RAN interface.
[0151] When the type of the UE is an loT device, the specific part of the configuration information may indicate that the security events to be monitored further comprise botnet detections, fast energy drains, frequent power resets, frequent factory recoveries, number of unexpected packets above a threshold, number of erroneous packets above a threshold, number of unexpected packets above a threshold or number of burst packets above a threshold.
[0152] When the type of the UE is an extended reality device, the specific part of the configuration information may indicate that the security events to be monitored further comprise biometric verification failures, avatar authorization failures, device authentication failures or user authorization failures.
[0153] When the type of the UE is an unmanned aerial vehicle, the specific part of the configuration information may indicate that the security events to be monitored further comprise flight deviation detections, attempts to take-off using invalid subscriber identity module, large delays in take-off or entries in military zone or restricted zone.
[0154] Syslog RFC 5424 defines structured data identifier (SD-ID) formats for syslog. Syslog RFC 5424 defines structure data parameters value pair (SD-PARAM value pairs), that is key value pairs, for syslog. For security logging, new SD-IDs and new SD-PARAM value pairs maybe defined.
[0155] In an example, new SD-IDs and new SD-PARAM value pairs maybe defined as follows. secSDID@00001 : For authentication failures secSDID@00002: For authorization failures secSDID@00003: For replay attack detection secSDID@00004: For distributed denial of access attack detection secSDID@00001 : For authentication failures
[0156] SD-PARAM value pairs (i.e., key value pairs): sourcelP=”1 .2.3.4” sourcePort=”8080” username-’sysadmin” ... etc. secSDID@00003: For replay attack detection
[0157] SD-PARAM-value pairs: sourcelD=”UE-SUCI-XXXX” messageReplaylD=”1234” messageSeqNum=”4321”... etc.
[0158] The secSID-IDs and the SD-PARAM value pairs for each security event may be standardized in future 3GPP standards. This will allow usage of syslog for continuous security monitoring and analytics. Alternatively, the secSID-IDs and the SD-PARAM value pairs for each security event be defined by operator to allow proprietary implementations. However, in such cases, interfaces to a third-party security information and event management for exposing security logs may need to be standardized.
[0159] Fig. 5 shows a signalling diagram of a process for transmitting, to the CSMAF, SLRs.
[0160] At step 1 , the operator or 0AM may transmit, to the PCF, the security policies. The PCF may translate the security policies into LIE configuration information for monitoring security events and transmitting SLRs including security logs for the security events, BS configuration information for monitoring security events and transmitting SLRs including security logs for the security events and NF configuration information for monitoring security events and transmitting SLRs including security logs for the security events.
[0161] The UE may perform authentication and registration with the 5GC. The UE may transmit, to the PCF via the BS and the AMF, capabilities information as part of non- access stratum (NAS) registration procedure. The capabilities information may indicate the type of the UE. Using the UE capabilities information, the PCF may adjust the UE configuration information based on the type of the UE. The AMF may maintain the NAS security context.
[0162] At step 2 and 3, the PCF may transmit, to the UE via the AMF and the BS, the UE configuration information for monitoring security events and transmitting SLRs including security logs for the security events. The UE configuration information may be transmitted after an access stratum (AS) security context is established, using AS security encryption and integrity protection keys. The UE may apply the UE configuration.
[0163] It will be understood that when the AS security context is updated, the UE configuration information may not be retransmitted using updated AS security encryption and integrity protection keys. In an example, the configuration information may indicate the security events to be monitored (e.g., distributed denial of service detections). The configuration information may indicate parameters associated with the security events to be monitored (e.g., threshold for detecting a burst of packets). The configuration information may indicate a periodicity to transmit SLRs (e.g., 5 min). The configuration information may indicate a format to be used (e.g., syslog).
[0164] At step 4, the PCF may transmit, to the BS, the BS configuration information for monitoring security events and transmitting SLRs including security logs for the security events. The BS may apply the BS configuration.
[0165] At step 5, the PCF may transmit, to the NF, the NF configuration information for monitoring security events and transmitting SLRs including security logs for the security events. The NF may apply the BS configuration.
[0166] At step 6 and 7, the UE may monitor the security events based on the UE configuration information. The UE may generate SLR including security logs for the security events. The UE may transmit, to the edge computing server via the BS, the SLR based on the UE configuration information. The edge computing server may analyse the SLR including security logs for the security events and may transmit, to the CSMAF, the analysis of the SLR.
[0167] Alternatively, the UE may transmit, to the CSMAF via the BS, the SLR based on the UE configuration information.
[0168] In an example, the SLR may comprise the following SLR logs.
[0169] <Timestamp> secSDID@00004 ProSesourcelD-1123456”
[0170] ProSeSourceApplD=“alpha23” MaxBurstSize=167 MinBurstSize=75 AvgBurstSize=110 <Timestamp> secSDID@00004 ProSesourcelD=“873465”
[0171] ProSeSourceApplD=“beta23” MaxBurstSize=231 MinBurstSize=115 AvgBurstSize=130
[0172] <Timestamp> secSDID@00004 ProSesourcelD=“129956”
[0173] ProSeSourceApplD=“gamma23” MaxBurstSize=267 M in Bursts ize= 175
[0174] AvgBurstSize=214
[0175] <Timestamp> secSDID@00004 ProSesourcelD=“123917”
[0176] ProSeSourceApplD=“theta23” MaxBurstSize=2167 Min Bursts ize=753
[0177] AvgBurstSize=1005
[0178] The analysis of the SLR may show that ProSeSourceApplD=”theta23” is an important source of bursts sent over the ProSe interface to the UE and that the UE may be the target of a distributed denial of service attack. The analysis of the SLR and the location of the UE may be used to identify the other UE in the vicinity of the UE that may also be the target of the distributed denial of service attack. In such case, it may be beneficial for the PCF to transmit, to the other UE, other UE configuration information for monitoring the security events and transmitting a SLR including security logs for the security events.
[0179] At step 8, the BS may monitor the security events based on the BS configuration information. The BS may generate a SLR including security logs for the security events The BS may transmit, to the CSMAF, the SLR based on the BS configuration information.
[0180] At step 9, the NF may monitor the security events based on the NF configuration information. The NF may generate a SLR including security logs for the security events The NF may transmit, to the CSMAF, the SLR based on the NF configuration information. At step 10, the CSMAF may compile the analysis of the SLR received from the edge computing server or the SLR received from the UE with the SLR received from the BS and the SLR received from the NF in a security monitoring report.
[0181] At step 11 , the CSMAF may transmit the security monitoring report to the operator or the 0AM. The operator or the 0AM may analyse the security monitoring report and may determine a risk. The operator or the 0AM may determine a recommendation to mitigate the risk. The operator or the operator or the 0AM may update the security policies based the recommendation. The PCF may determine updated UE configuration information, updated BS configuration information and / or updated NF configuration information and steps 2 to 10 may be repeated.
[0182] Alternatively, at step 12, the CSMAF may analyse the security monitoring report and may determine a risk. The CSMAF may determine a recommendation to mitigate the risk. The CSMAF may transmit, to the PCF, an indication of the recommendation. The PCF may determine updated UE configuration information, updated BS configuration information and / or updated NF configuration information based on the recommendation and steps 2 to 10 then may be repeated.
[0183] The PCF may determine that an additional UE, an additional BS or additional NF may need to monitor the security events and transmit a SLR including security logs for the security events based on the recommendation. The PCF may determine additional UE configuration information, additional BS configuration information or additional NF configuration information and steps 2 to 11 then may be repeated.
[0184] The recommendation may comprise updating the UE configuration information, updated BS configuration information and / or updated NF configuration information (e.g., increasing the level of details of the SLR received from the UE, when the confidence values of the security logs included in the SLR received from the UE are too low to accurately determine a risk). The recommendation may comprise configuring an additional UE, an additional BS or additional NF to monitor the security events and transmit a SLR including security logs for the security events (e.g., configuring an additional UE to monitor the security events and transmit a SLR including security logs for the security events, when the level of details of the SLR received from the UE is too low to accurately determine a risk).
[0185] Alternatively, at step 13 the CSMAF may analyse the security monitoring report and may determine a risk. The CSMAF may determine a recommendation to update the security policy. The CSMAF may transmit, to the PCF, an indication of the recommendation. The operator or the 0AM may determine an security policy based on the recommendation and steps 2 to 11 then may be repeated.
[0186] Fig. 6 shows a block diagram of a method for managing security in a communication system. The method may be performed by an apparatus, such as a UE, a BS or a NF.
[0187] At step 600, the apparatus may receive configuration information for monitoring at least one security event and transmitting a SLR including at least one security log for the at least one security event, wherein the configuration information indicates the at least one security event to be monitored and a criterion to transmit the SLR including the at least one security log for the at least one security event.
[0188] At step 602, the apparatus may apply the configuration information.
[0189] At step 604, the apparatus may monitor the at least one security event.
[0190] At step 606, the apparatus may transmit the SLR including the at least one security log for the at least one security event.
[0191] Fig. 7 shows a block diagram of a method for managing security in a communication system. The method is performed an apparatus, such as a PCF.
[0192] At step 700, the apparatus may receive security policies. At step 702, the apparatus may translate the security policies into configuration information for configuring monitoring at least one security event and transmitting a SLR including at least one security log for the at least one security event, wherein the configuration information indicates the at least one security event to be monitored and a criterion to transmit the SLR including the at least one security log for the at least one security event.
[0193] At step 704, the apparatus may transmit the configuration information.
[0194] Fig. 8 shows a schematic representation of non-volatile memory media 800 storing instructions which when executed by a processor allow the processor to perform one or more of the steps of the methods of Fig. 6 and Fig.7.
[0195] It is noted that while the above describes example embodiments, there are several variations and modifications which may be made to the disclosed solution without departing from the scope of the present invention.
[0196] It will be understood that although the above concepts have been discussed in the context of a 5GS, one or more of these concepts may be applied to other cellular systems.
[0197] The embodiments may thus vary within the scope of the attached claims. In general, some embodiments may be implemented in hardware or special purpose circuits, software, logic or any combination thereof. For example, some aspects may be implemented in hardware, while other aspects may be implemented in firmware or software which may be executed by a controller, microprocessor or other computing device, although embodiments are not limited thereto. While various embodiments may be illustrated and described as block diagrams, flow charts, or using some other pictorial representation, it is well understood that these blocks, apparatus, systems, techniques or methods described herein may be implemented in, as non-limiting examples, hardware, software, firmware, special purpose circuits or logic, general purpose hardware or controller or other computing devices, or some combination thereof.
[0198] The embodiments may be implemented by computer software stored in a memory and executable by at least one data processor of the involved entities or by hardware, or by a combination of software and hardware. Further in this regard it should be noted that any procedures, e.g., as in Fig. 6 and Fig. 7, may represent program steps, or interconnected logic circuits, blocks and functions, or a combination of program steps and logic circuits, blocks and functions. The software may be stored on such physical media as memory chips, or memory blocks implemented within the processor, magnetic media such as hard disk or floppy disks, and optical media such as for example DVD and the data variants thereof, CD.
[0199] The memory may be of any type suitable to the local technical environment and may be implemented using any suitable data storage technology, such as semiconductor-based memory devices, magnetic memory devices and systems, optical memory devices and systems, fixed memory and removable memory. The data processors may be of any type suitable to the local technical environment, and may include one or more of general purpose computers, special purpose computers, microprocessors, digital signal processors (DSPs), application specific integrated circuits (ASIC), gate level circuits and processors based on multi-core processor architecture, as non-limiting examples.
[0200] Alternatively or additionally some embodiments may be implemented using circuitry. The circuitry may be configured to perform one or more of the functions and / or method steps previously described. That circuitry may be provided in the base station and / or in the communications device.
[0201] As used in this application, the term “circuitry” may refer to one or more or all of the following:
[0202] (a) hardware-only circuit implementations (such as implementations in only analogue and / or digital circuitry); (b) combinations of hardware circuits and software, such as:
[0203] (i) a combination of analogue and / or digital hardware circuit(s) with software / firmware and
[0204] (ii) any portions of hardware processor(s) with software (including digital signal processor(s)), software, and memory(ies) that work together to cause an apparatus, such as the communications device or base station to perform the various functions previously described; and
[0205] (c) hardware circuit(s) and or processor(s), such as a microprocessor(s) or a portion of a microprocessor(s), that requires software (e.g., firmware) for operation, but the software may not be present when it is not needed for operation.
[0206] This definition of circuitry applies to all uses of this term in this application, including in any claims. As a further example, as used in this application, the term circuitry also covers an implementation of merely a hardware circuit or processor (or multiple processors) or portion of a hardware circuit or processor and its (or their) accompanying software and / or firmware. The term circuitry also covers, for example integrated device.
[0207] The foregoing description has provided by way of exemplary and non-limiting examples a full and informative description of some embodiments However, various modifications and adaptations may become apparent to those skilled in the relevant arts in view of the foregoing description, when read in conjunction with the accompanying drawings and the appended claims. However, all such and similar modifications of the teachings will still fall within the scope as defined in the appended claims.
Claims
CLAIMS1 . A method, the method comprising: receiving configuration information for monitoring at least one security event and transmitting a security log report including at least one security log for the at least one security event, wherein the configuration information indicates the at least one security event to be monitored and a criterion to transmit the security log report including the at least one security log for the at least one security event; applying the configuration information; monitoring the at least one security event; and transmitting the security log report including the at least one security log for the at least one security event.
2. The method of claim 1 , wherein the configuration information is received from a policy control function.
3. The method of claim 1 or claim 2, wherein the security log report is transmitted to a continuous security monitoring and analytics function or an edge computing server.
4. The method of claim 3, wherein the continuous security monitoring and analytics function is a network function or a third-party application function.
5. The method of any of claims 1 to 4, wherein the configuration information is further for computing a security metrics and transmitting the security metrics; and wherein the method comprises: computing the security metrics; and transmitting the security metrics.
6. The method of any of claims 1 to 5, wherein the configuration information further indicates at least one of: a parameter to be monitored;a layer to be monitored; an interface to be monitored; a level of details of the security log report; a format of the security log report; or a security metrics to be computed.
7. The method of claim 6, wherein the level of details of the security log report indicates parameters to be included in the at least one security log.
8. The method of claim 6 or claim 7, wherein the level of details of the security log report indicates security logs to be included in the at least one security log report.
9. The method of any of claims 6 to 8, wherein the level of details of the security log report indicates security logs to be included in the at least one security log report.
10. The method of any of claims 6 to 9, wherein the format comprises a plurality of key value pairs including at least one of: a source identifier key value pair identifying a source; a destination identifier identifying a destination; a protocol key value pair indicating a protocol; a security event key value pair indicating a security event; or a confidence value key value pair indicating a confidence value that a security event occurred.
11. The method of any of claims 6 to 10, wherein the criterion to transmit the security log report comprises at least one of: a threshold; a periodicity; or a geographic area.
12. The method of any of claims 1 to 11 , wherein the method is performed by a user equipment, a base station or a network function.
13. The method of claim 12, wherein the method is performed by a user equipment and the configuration information is dependent on a type of the user equipment.
14. The method of claim 13, comprising: transmitting, to the policy control function, capabilities information indicating a type of the user equipment; and receiving, from the policy control function, the configuration information dependent on the type of the user equipment.
15. The method of claim 13 or claim 14, wherein the type of the user equipment comprises: a smartphone; an Internet of things device; an extended reality device; or an unmanned aerial vehicle.
16. The method of any of claims 1 to 15, wherein the configuration information is received after an access stratum security context is established, using access stratum security encryption and integrity protection keys.
17. The method of any of claims 1 to 16, comprising: receiving updated configuration information for monitoring the at least one security event and transmitting a security log report including at least one security log for the at least one security event; applying the updated configuration information; monitoring the at least one security event; and transmitting the security log report including at least one security log for the at least one security event.
18. A method comprising: receiving security policies;translating the security policies into configuration information for configuring monitoring at least one security event and transmitting a security log report including at least one security log for the at least one security event, wherein the configuration information indicates the at least one security event to be monitored and a criterion to transmit the security log report including the at least one security log for the at least one security event; and transmitting the configuration information.
19. The method of claim 18, wherein the security policies are received from an operator or an operation administration and maintenance system.
20. The method of claim 18 or claim 19, wherein the configuration is transmitted to a user equipment, a base station or a network function.
21. The method of any of claims 18 to 20, wherein the method is performed by a policy control function.
22. An apparatus comprising means for: receiving configuration information for monitoring at least one security event and transmitting a security log report including at least one security log for the at least one security event, wherein the configuration information indicates the at least one security event to be monitored and a criterion to transmit the security log report including the at least one security log for the at least one security event; applying the configuration information; monitoring the at least one security event; and transmitting the security log report including the at least one security log for the at least one security event.
23. An apparatus comprising means for: receiving security policies; translating the security policies into configuration information for configuring monitoring at least one security event and transmitting a security log report includingat least one security log for the at least one security event, wherein the configuration information indicates the at least one security event to be monitored and a criterion to transmit the security log report including the at least one security log for the at least one security event; and transmitting the configuration information24. A computer program comprising computer executable instructions which when run on one or more processors perform the steps of the method of any of claims 1 to 21.
Citation Information
Patent Citations
5G network security protection method and system
CN112073969A
Security management of an autonomous vehicle
US20210194904A1