Securing interface of communication system
A central vFML model secures communication system interfaces by detecting and responding to anomalies across multiple layers, addressing security risks in distributed architectures and meeting zero trust requirements.
Patent Information
- Application Number
- PCT/IB2024/056429
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-07-01
- Publication Date
- 2026-01-08
AI Technical Summary
The distributed multiple-owner layer system architecture in communication systems increases security risks due to malicious attacks through command line interfaces (CLIs) and application programming interfaces (APIs) by both external and internal attackers, compromising system integrity and availability.
Implement a central vertical federated machine learning (vFML) model that monitors actions via service exposure interfaces, predicts anomalies, and triggers alarms or notifications across multiple layers to secure the system, utilizing a broader and varied dataset from hardware, virtualization, and software layers.
The vFML model enhances security by efficiently detecting and responding to anomalies, reducing technical effort and resources required for network operation and compliance with zero trust requirements, while ensuring robustness and compliance with government standards.
Smart Images

Figure IB2024056429_08012026_PF_FP_ABST
Abstract
Description
SECURING INTERFACE OF COMMUNICATION SYSTEMTECHNICAL FIELD
[0001] The present disclosure is related to methods and apparatus for securing an interface of a service exposure in a communication system including a plurality of layers, using a central machine learning (ML model). The central ML model may be a vertical federated machine learning (vFML) model.BACKGROUND
[0002] Figure 1 shows an overview of a Third Generation Partnership Project (3GPP) fifth generation (5G) network architecture. As shown in Figure 1, network functions (NFs), such as Network Routing Function (NRF), Access Management Function (AMF), Session Management Function (SMF), Policy Control Function (PCF), etc., are deployed behind a network exposure function (NEF). A NEF provides authentication and authorization functionalities for controlling both internal and external access towards the NFs. Detailed information regarding such a 5G system can be found in 3GPP TS 23.501 vlS.4.0., “System Architecture for the 5G System” Stage 2 (Dec. 2023), for example.SUMMARY
[0003] A distributed multiple-owner layer system architecture may increase security risks in operation and maintenance (0AM) interfaces that provide a command line interface(s) (CLI(s)) and / or application programming interface(s) (API(s)), for example. External hackers may compromise trusted user devices and perform malicious attacks on a layer(s) of the system architecture. Such attacks also may be performed by internal attackers who have been successfully authenticated and authorized for a given time period.
[0004] Certain aspects of the disclosure and their embodiments may provide solutions to these or other challenges. In some embodiments, a computer implemented method is provided for securing an interface of a service exposure in a communication system including a plurality of layers. The method includes monitoring an action directed to the communication system via the interface of the service exposure and at least one of the layers of the plurality of layers. The method further includes predicting, with a central ML model, that the action includes an anomaly; and triggering an alarm or notification to the service exposure and at least some of the plurality of layers responsive to the anomaly.
[0005] According to other embodiments, a computing device is provided. The computing device is configured to secure an interface of a service exposure in a communication systemincluding a plurality of layers. The computing device includes processing circuitry, and memory coupled with the processing circuitry. The memory includes instructions that when executed by the processing circuitry causes the computing device to perform operations. The operations include to monitor an action directed to the communication system via the interface of the service exposure and at least one of the layers of the plurality of layers. The operations further include to predict, with a central ML model, that the action includes an anomaly; and to trigger an alarm or notification to the service exposure and at least some of the plurality of layers responsive to the anomaly.
[0006] In yet other embodiments, a non-transitory computer readable medium is provided. The non-transitory computer readable medium includes program code to be executed by processing circuitry of a computing device configured to secure an interface of a service exposure in a communication system including a plurality of layers. Execution of the program code causes the program code to perform operations. The operations include to monitor an action directed to the communication system via the interface of the service exposure and at least one of the layers of the plurality of layers. The operations further include to predict, with a central ML model, that the action includes an anomaly; and to trigger an alarm or notification to the service exposure and at least some of the plurality of layers responsive to the anomaly.
[0007] Certain embodiments may provide one or more of the following technical advantages. Embodiments herein may address how to secure a service exposure interface for a communication system. Based on the monitoring, an alarm or notification may be triggered responsive to prediction of the anomaly. As a consequence of securing the service exposure interface and / or the alarm / notification, technical effort and resources may be saved on behalf of a network operation and / or service provider to secure their service offerings. Additionally or alternatively, a platform of the communications system on which different applications are deployed may be secured, e.g., to meet zero trust requirements of a government body. Moreover, the central ML model may be robust as it may benefit from a broader and varied dataset from, e.g., a hardware layer, virtualization layer, software, applications, etc. in the communications system.BRIEF DESCRIPTION OF THE DRAWINGS
[0008] The accompanying drawings, which are included to provide a further understanding of the disclosure and are incorporated in and constitute a part of this application, illustrate certain non-limiting embodiments of inventive concepts. In the drawings:
[0009] Figure 1 is a block diagram illustrating an overview of a 3GPP 5G network architecture;
[0010] Figure 2 is a block diagram illustrating an overview of an open-radio access network (O-RAN) architecture;
[0011] Figure 3 is a block diagram illustrating an overview of a service management and orchestration (SMO) architecture;
[0012] Figure 4 is a block diagram illustrating an overview of an SMO service architecture under a zero trust architecture (ZTA);
[0013] Figures 5A, 5B, and 5C are block diagrams illustrating differences between horizontal federated learning, vertical federated learning, and federated transfer learning, respectively;
[0014] Figure 6 is a block diagram illustrating an example overview of CLIs and APIs to a system via a service exposure;
[0015] Figure 7 is a block diagram illustrating an example of layer access;
[0016] Figure 8 is a block diagram illustrating an example communication system in accordance with some embodiments;
[0017] Figure 9 is a block diagram illustrating an example deployment view of central ML model training in accordance with some embodiments;
[0018] Figure 10 is a block diagram illustrating an example deployment view of central ML model prediction in accordance with some embodiments;
[0019] Figure 11 is a sequence diagram illustrating an example flow of building a data pipeline for encoded features of vertical federated machine learning (vFML) for a central ML model in accordance with some embodiments;
[0020] Figure 12 is a block diagram illustrating an example fusion layer as multi-modal representations of heterogenous data in accordance with some embodiments;
[0021] Figure 13 is a block diagram illustrating an example attention process in accordance with some embodiments;
[0022] Figure 14 is a block diagram of an example architecture in accordance with some embodiments;
[0023] Figure 15 is a block diagram illustrating an example of vFML local anomalies prediction and global anomalies prediction in accordance with some embodiments;
[0024] Figure 16 is a flow chart illustrating an example of operations performed by a computing device in accordance with some embodiments;
[0025] Figure 17 is a block diagram of a communication system in accordance with some embodiments;
[0026] Figure 18 is a block diagram of a computing device in accordance with some embodiments; and
[0027] Figure 19 is a block diagram of a virtualization environment in accordance with some embodiments.DETAILED DESCRIPTION
[0028] Some of the embodiments contemplated herein will now be described more fully with reference to the accompanying drawings. Embodiments are provided by way of example to convey the scope of the subject matter to those skilled in the art, in which examples of embodiments of the present disclosure are shown. The present disclosure may, however, be embodied in many different forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided so that this disclosure will be thorough and complete, and will fully convey the scope of present inventive concepts to those skilled in the art. It should also be noted that these embodiments are not mutually exclusive. Components from one embodiment may be tacitly assumed to be present / used in another embodiment.
[0029] In a 3GPP core network, a service based architecture (SBA) may be recommended to implement the NFs. Implementation of a SBA may be done through a mesh framework, for example. Referring to Figure 1, for example, the NFs are exposed to internal users, external users, or applications (e.g., application functions (AFs) via NEF. Access to NFs via NEF is authenticated and authorized. After authentication and authorization, the entity is trusted for a given period of time.
[0030] Figure 2 illustrates an overview of an open-radio access network (O-RAN) architecture. As shown in Figure 2, a SMO framework can provide intelligence for slice management, non-real time radio intelligence controller (RIC) and 0AM.
[0031] For SMO in an O-RAN, a SBA may be recommended to implement service and data management functions, as shown in the Example in Figure 3. The service and data management functions are exposed to internal or external users or AFs via a data management exposure (DME) and / or service management exposure (SME). The entry point for SMO can be either the DME or the SME. DME and / or SME is a service exposure entity through which the management of those SMO functions can be performed. Access to NFs via DME / SME is authenticated and authorized. After authentication and authorization, the entity is trusted in a given period of time.
[0032] For SBA scenarios discussed with reference to Figures 1-3, in order to secure a SMO service architecture under a ZTA, an authentication and authorization mechanism towards actions performed through a CLI and API is shown in the example in Figure 4. In Figure 4, the authentication and authorization mechanism is based on policy management and monitoring.
[0033] In standardization such as 3GPP 5G core network (5GC), for example, the authentication and authorization are done when an initial service request via a CLI or API isreceived. After the user / client entity is successfully authenticated, such as basic HTTP authentication, API keys, or OAuth 2.0, etc., the user / client entity is trusted and allowed to access the system for a given period of time. This mechanism may be used in the majority of commercial systems (large or small) implemented through SBA to protect the operation and maintenance from malicious attacks.
[0034] Federated machine learning (FML) includes three categories: Horizontal FML (hFML), vFML, and federated transfer learning (FTL). Figure 5A regarding hFML, Figure 5B regarding vFML, and Figure 5C regarding (FTL) are block diagrams that distinguish the three categories based on the relationship between features and data samples.
[0035] vFML refers to a FML setting where a dataset shares the samples / users while holding different features. For instance, a bank may utilize vFML to collaborate with an invoice agency to build financial risk models for the bank’s enterprise customers. Information on how vFML works can be found in Liu, Yang, Kang, Yan, Zou, Tianyuan, et al. Vertical federated learning: Concepts, advances, and challenges. IEEE Transactions on Knowledge and Data Engineering, 2024, for example.
[0036] The mechanism of the authentication and authorization discussed above may not be secure enough if an attacker comes from inside users or external users who have been hacked. This is because in the time period during which an access token is granted, the compromised user or internal attacker can still perform a malicious operation towards the system via CLIs or operational APIs.
[0037] On the other hand, those CLIs and operational APIs are key components from which trusted users operate the system according to their roles. Malicious attacks through those interfaces may lead to system interruption or crash which, in tune, may have a business impact on the system operator’s commitment on the offering service availability, its reputation and / or revenue.
[0038] Figure 6 is a block diagram illustrating an example overview of CLIs and operational APIs to a system via a service exposure (SE). Referring to Figure 6, a system (distributed environment 608) is deployed behind SE 606 that controls management operations towards the system 608. SE 606 typically provides CLIs and APIs 604. User devices 402 or an automation tool 600 goes through SE 606 to access the system 608. A user device 402 may be an internal system administrator or technical support device. A user device 402 also may provide limited management functions to external administrators and / or support persons for a customer who consumes the services. Those internal or external user devices 402 may use automation tools 600, such as scripts with or without an artificial intelligence (AI) / machine learning (ML) model (AAAM 602). An attacker may create an adversarial attack by learning call patterns usinga generative adversarial network (GAN) based ML models after hacking a user’s credentials successfully, for example.
[0039] In the system 608 behind SE 606 in Figure 6, the implementation of the system 608 follows a layer architecture, which may provide the flexibility and openness for different vendors / manufactures to offer the corresponding services, infrastructures and supports.Typically, the system 608 may be deployed among several devices or hardware across different locations or a same location.
[0040] As shown in Figure 6, four layers may normally be used in the SBA: service / applications layer 610; service framework (FW) layer 612; virtualization layer 614; and hardware layer 616.
[0041] Each layer 610, 612, 614, 616 can provide life-cycle management functionalities related to 0AM for the services or frameworks residing on its upper layer. Each layer 610, 612, 614, 616 may be configured to support one or multiple entities, for instance, on the same hardware; and can host two different virtual machines or containers. One virtual machine or container also can be configured across multiple devices as shown in Figure 6.
[0042] Due to the deployment of multiple instances / entities at each layer 610, 612, 614, 616, for example, the owners of those entities can be different. Figure 7 is a block diagram illustrating an example of layer access from the view of ownership under the protected system. Administrative and technical support from an infrastructure provider 702 A (IPA) can access its owned hardware HWi via CLIs to operate and monitor. At the same time, an administrator for IPB can access its infrastructure HW2 and HW3. Following the same business logic, a Platform as a service (PaaS) provider 700 PPy allows its administration and support engineers to access its own virtual platform VM4 and VMs. The same mechanism discussed above is applied to all the layers shown in Figure 6.
[0043] In addition to the complexity of the layer ownership in a distributed environment, there is interaction between layers, such as the virtualization layer and the hardware layer as illustrated by the arrows in Figure 7. An entity at the virtualization layer can call the API given by the lower hardware layer to invoke specific operations, e.g. configure network connectivity at physical layer.
[0044] Thus, such a distributed multi-owner layer system architecture may increase the security risk significantly in such traditional 0AM interfaces that provide CLIs and APIs. External hackers 712 may compromise the trusted user devices 704a-704e, 706a-706e, 708a- 708c and do malicious attacks 710, 714 on the corresponding virtualization or hardware layer in this example, which can have an impact on the other up or down layer(s). Those attacks 710,714 can also be performed by the internal attackers, who have been successfully authenticated and authorized.
[0045] Catching a malicious attack efficiently and quickly in such a sophisticated system can be challenging.
[0046] Examples herein address such a security issue based on monitoring 410 (e.g., near continuous / continuous monitoring) of a system as shown in the example in Figure 8 in a ZTA. Through monitoring 410 (e.g., continuous monitoring) on 0AM activities via an interface, such as a CLI and / or API, offered by a SE 412, as well as on layers in the system, an anomaly detection model may detect abnormal behavior in the system. The anomaly detection model may use vFML 800.
[0047] The example in Figure 8 is based on vFME 800, which takes a dataset 416 from different sources at different layers, e.g., laaS, PaaS, containers, serverless etc., and also the dataset collected at SE 412. Each layer contributes its own features. As indicated, the dataset from the exposure entity 412 also is used as one input for vFML 800.
[0048] When abnormal behavior is detected or predicted by vFML 800, a notification or alarm is sent to each layer in the system, e.g., to laaS, PaaS, containers, serverless etc., as well as to the service exposure 412. A trigger for notification can be stored and can be used for risk assessment 410a, to build threat intelligence 410b, a response 410c, and / or detection / forensics 410d etc. This information can be used to update the policy management 408, including governance 408a, compliance 408b, security posture 408c, and / or productivity 408d. The information also can be used to enforce the policy 408 to eliminate or mitigate such attacks. For instance, upon anomaly detection, a trigger to re-authenticate and re-authorize 406 the user device 402 can be initiated. If needed, ongoing operation activities can be suspended pending further investigation.
[0049] Figure 9 is a block diagram of a deployment view of an example of ML model training. As shown, the example in Figure 9 includes: (1) an agent, vFML- agent-model app 900a, to prepare the data that contains the features at the application layer 610; (2) an agent, vFML-agent-model-FW 900e, to prepare the data that contains the features at the service FW layer 612; (3) an agent, vFML-agent-model-PL 900c, to prepare the data that contains the features at the virtualization platform layer 614; (4) an agent, vFML-agent-model-HW 900d, to prepare the data that contains the features at the hardware layer 616; (5) an agent, vFML-agent- model-SE 900b, to prepare the data that contains the features at service exposure 606; (6) a vertical-FML-FW 904 for training the vFML 800. The vertical-FML-FW 904 in this example includes a messaging FW, a data pipeline, and vFML 800; and (7) a central ML model 906 to predict abnormal behavior of the clients via an interface, CLIs and APIs 604 in this example.
[0050] The agents 900a-900e from different layers 610, 612, 614, 616 and SE 606 send encoded features to the central vFML framework 904. According to vFML 800, those individual encoded features are fused into one vector as an input to train the central ML model 906. Central ML model may be a convolutional neural network (CNN), long short-term memory (LSTM), recurrent neural network (RNN), among others.
[0051] To train the central ML model 906 in a supervised way, an alarm or notification event may be used as a label 902 to indicate the time when the abnormal behavior of the system occurs.
[0052] After the central ML model 906 is trained, it is deployed to perform anomaly detection on activities via an interface, such as CLIs or APIs, towards the system as shown in the example in Figure 10. If abnormal behavior is detected, the outcome of central ML model 906 can be sent to a controller 1002. The controller 1002 may raise the alarm or notification 1004 to a receiver agent 1000 at each layer 610, 612, 614, 616 and SE 606.
[0053] As discussed herein, certain embodiments may provide one or more of the following technical advantages. Embodiments herein may address how to secure a service exposure interface for a communication system. For example, securing the service exposure interface, such as under ZTA, may comply with United States government zero trust requirements. Moreover, based on monitoring of the system (e.g., near continuous monitoring), the method herein can trigger a notification / alarm responsive to prediction of the anomalous behavior. As a consequence of securing the service exposure interface and / or the notification / alarm, technical effort and / or resources may be saved on behalf of a network operation and / or service provider to secure their service offerings under, e.g., a ZTA. Additionally, or alternatively, a platform on which different applications are deployed may be secured, which may, e.g., meet ZT requirements of a government body. Moreover, the central ML model may be robust in contrast to other approaches because the central ML model may benefit from a broader and varied dataset (e.g., from a hardware layer, virtualization layer, software, applications, etc.).
[0054] Figure 11 is a sequence diagram illustrating an example flow of building a data pipeline for encoded features of vFML for the central ML model. Since each layer in this example is going to contribute different client features to the central ML model based on vFML, this example process builds the feature encoding properly and passes them to a framework located in a central cloud.
[0055] In the flow shown in Figure 11 , agent-HW-IPA 900d of hardware infrastructure locates the vFML FW 904 and builds its data pipeline to hook into vFML FW 904.
[0056] At operation 1, agent-HW-IPA 900d sends a request to a domain name server (DNS) 1100 for vFML via CLIs / APIs 604 for NFX. DNS 1100, in operation 2, responds to agent-HW- IPA 900d with a uniform resource locator (URL) for a vFML service.
[0057] In operation 3, agent-HW-IPA 900d sends a request for vFML with client-layer at HW-IPA to vFML-FW 904 (via CLIs / APIs 604 for NFX). vFML-FW 904, in operation 4, locates the client data format for the HW layer; and responds to agent-HW-IPA 900d approving the request for vFML. The response includes a data format and message framework.
[0058] In operation 5, agent-HW-IPA 900d builds the data processing pipeline according th the required data format.
[0059] Agent-HW-IPA 900d, in operation 6, sets up, with messaging FW 1102, the data pipeline to send encoded features. In operation 7, messaging FW 1102 responds to agent-HW- IPA 900d that the data pipeline was successfully set up.
[0060] Agent-HW-IPA 900d, in operation 8, sends to vFML-FW 904, notification on the client-side data collection at HW-IPA. In response in operation 9, vFML-FW 904 sends an acknowledgement to agent-HW-IPA 900d.
[0061] In operation 10, vFML-FW 904 retrieves the dataset for HW-IPA via messaging FW 1102. In operation 11, vFML-FW 904 receives the dataset via messaging FW 1102.
[0062] Operations 1 through 11 are repeated to set up the data pipeline for encoded features at additional layers, such as virtualization layer 614 operated by PPA.
[0063] The process shown in Figure 11 can accommodate different infrastructure owners as well as different service providers who contribute their components or services into the system.
[0064] Figure 12 is a block diagram illustrating an example fusion layer 1200 as multimodal representations of heterogenous data. For better capture of features at different perspectives, the multi-modal approach of Figure 12 may be used to fuse heterogeneous data collected from different localities. Such an approach may capture a more comprehensive representation that combines different aspects of collected data. The collected data can be preprocessed to be used on a ML / Al workload defined by vFML 800. Given that the data is heterogeneous, fusion of embeddings 1202 (from fused embeddings 1204, 1206, 1208) of float features 1210, mappings 1212, and embedding features 1214, respectively) may enable the central ML model 906 to effectively handle the characterization of information from multiple sources. Moreover, embeddings learned from one task or domain can be transferred to another task or domain.
[0065] In this example, a dataset at hardware layer 616 including hardware footprints during execution of CLIs / APIs 604 may be captured. The dataset may include for example:• Processors’ hardware performance counters, such as LI cache hit / misses, L2 cache hit / misses, L3 cache hit / misses, all branches retired, branches mispredicted, bus request (BR) nontaken conditional, BR taken conditional, taken indirect near call microoperation (uOps) retired.All, instruction (Inst) retired.All, Inst retired.any data translation look-aside buffer (DTLB) load misses, DTLB store misses, instruction translation lookaside buffer (ITLB) misses, etc.• Disk counters, such as raw read error rate, throughput performance, power on hours, airflow temperature, power-off retract count, load cycle count, temperature, total logical block addresses (LB As), etc.
[0066] In this example, a dataset at virtualization layer 614 including virtualization footprints during execution of CLIs / APIs 604 may be captured. The dataset may include for example:• Virtual machines: central processing unit (CPU) usage, memory usage, disk usage, Hypervisor, VM type, operating system (OS), throughput, bandwidth, packet loss, system logs, etc.• Management and orchestration (e.g., K8S): Server request latency, scheduling latency, server request rate, ingress controller connections, scheduler preemption attempts, pod network packets, scheduling failed pods, workqueue depth, pod CPU utilization, pod memory utilization, pod network inputs / output (I / O), pod disk I / O, etc.
[0067] In this example, cloud native services implemented through virtual applications (e.g., containers) may be collected. The dataset may include, for example, a container image, environment variables, startup commands, volume mounts, containers scheduling, network interfaces, etc.
[0068] Further, in this example, data related to service exposure may be collected. The dataset may include, for example, URLs, protocols, data format, user, role, CLI, timestamp, etc.
[0069] In the vFML architecture, the underlying features discussed above are included for the sake of illustration and can include different or other features, and can be subject to prior pre-processing, normalization, and alignment padding. An attention process can be used to characterize features from different perspectives.
[0070] Figure 13 is a block diagram illustrating an example attention process 1300. The attention process 1300 can capture representations of data through keys ki-kn, queries q, and values mappings vi-vn. In this example, a query, q, can be a unique CLI / API embedding representation through word2vec or a set of CLIs / APIs represented through Doc2Vec, or sequence traces captured through LSTM embeddings, for example. A key, k, can be a role (e.g., group) representing a set of user devices, a unique user device, or an application. A value, v, caninclude embeddings representing features collected on each perspective; attention weights are represented by a(q, k); and the output includes attention pooling.
[0071] Given a generic ground truth: GT = { k1, v^, (k2, v2), (kn, vn)}, where keys can be user devices, roles, or applications, attention is defined over a collected ground truth as: Attention( , GT) =k^Vi, where a(q, k[) E R(i = 1, ... , ri) are attention weights, q is a query that can be applied over the ground truth, which is a CLI or API event in this example. A goal is to obtain a linear combination of values representing the different features found in the ground truth.
[0072] Attention pooling can be used to characterize contextual representation of data collected at different perspectives with respect to the mappings between queries (e.g., CLIs / APIs) and keys (e.g., user devices, applications). To apply attention pooling, Nadaraya- Watson regression can be applied, for example, which generates weights to data points based on their distance from the query and normalizes the weights to generate a weighted sum of the values indexed per keys. However, other options like self-attention, among others, may be used to compute weights.
[0073] As such, Figure 14 is a block diagram of an example architecture where each perspective 1404, 1406, 1408, 1410, 1412 has its own attention module 1414 that computes local attention pooling outputs 1-5, which represents contextual relationships between keys, and queries in each perspective 1404, 1406, 1408, 1410, 1412. Each unique attention pooling output 1-5 is directed towards related local attention-based detection mechanism. For instance, service exposure attention pooling 1 is sent to a SE attention-based detection mechanism. Similarly, other perspectives’ attention pooling outputs 1-4 are used as inputs to local attention-based detection mechanisms (e.g., hardware attention based anomaly detection).
[0074] To identify potential propagation of anomalies between perspectives 1404, 1406, 1408, 1410, 1412, different attention pooling outputs 1-5 are fused through Multi-Layer Perceptron (MLP) implemented with an attention-based aggregator fusion layer 1416. Thus, encodings representing different perspectives may be obtained and used to identify global anomaliesl - 4 (e.g., SE / hardware attention-based anomaly detection). The model aggregates multi-modal attention weights for each potential key, query pair 1402 to represent a global snapshot of multiple layers (service exposure, hardware, virtualization, framework, service, and application). After a certain number of training propagation rounds R, the aggregator 1416 takes a set of attention pooling hq output indexed per key input and computes the representation of a certain context C (e.g., service exposure / hardware). The computation, in this example, is:
[0075] A single linear layer can be used for the node transformation MLP and the gating MLPgate- Thus, the output of this linear layer can have the needed dimensionality for a context related to a key (e.g., user device) by aggregating over queries set (e.g., API), a is the logistic sigmoid function and O is the element-wise product. After the weighted sum, anotherMLP with one hidden layer can be used to transform the context / key embedding. The hidden layer can have the same size as the output, with a ReLU nonlinearity. To train a context matching model, attention weights can be computed between normal contexts considering the same key, as in the following example:where d hc k, hci k) represents the distance between two contexts C, C traces considering a certain key k. Functions like Euclidean distance — || / tx— hy|| or the dot-product similarity hxThy, for example, can be considered as distance functions. The context-based attention weights are considered as a distribution reference for normal contexts.
[0076] The prediction of anomalies can take advantage of the computation of local and global attention-based weights used to capture normal behavior of the system by considering different perspectives. Figure 15 is a block diagram illustrating an example of vFML local anomalies prediction and global anomalies prediction.
[0077] To infer local anomalies, in this example, a maximum attention probability (MAP) is applied on a cross -model attention:where a is a cross-modal attention layer in each perspective; Aj y is the attention score between i-th key (e.g., user device) and j-th query (e.g., API entry); k and qy are the features of the i-th key and j-th query; and K and M are the numbers of keys and queries. A temperature parameter, T, is increased only when detecting anomalies because increasing T affects the prediction results. In-distribution attention weights 1500 are used to find out if a key (e.g., user device) and query (e.g., API entry) are relevant to each other, which represents a normal case. In contrast, when either a key or a query is from out-of-distribution 1502, the density of the input pair is expected to be low; therefore, inferring / predicting an anomaly.
[0078] For a key (e.g., user device), a reference final embedding contained trained attention weight values can be created by computing an average vector. Similarly, for a query (e.g., CLI, API event), a reference final embedding can be created that can be used during the inference phase. The reference final embedding can represent the context captured between the query and corresponding key. To identify anomalies, the new candidate embedding can be compared with reference embedding values by computing the distance attention-based weights. Those weights can be compared to the weights computed during training phase. If the weights are out-of- distribution 1502, an anomaly can be raised.
[0079] Since the target system can be a SBA based system, the method of the present disclosure may be applicable for cloud implementation to provide security on operations, administration, and maintenance (0AM) interfaces, such as CLI / API, under ZTA compliance.
[0080] As SBA may be recommended for SMO in O-RAN, the method of the present disclosure also may be applied to SMO.
[0081] Operations of a computing device 1800 (implemented using the structure of Figure 18) will now be discussed with reference to the flow chart of Figure 16 according to some embodiments of the present disclosure. For example, modules may be stored in memory 1804 of Figure 18, and these modules may provide instructions so that when the instructions of a module are executed by respective computing device processing circuitry 1802, computing device 1800 performs respective operations of the flow chart.
[0082] In some embodiments, a computer-implemented method is provided for securing an interface of a service exposure in a communication system including a plurality of layers. The method includes monitoring 1602 an action directed to the communication system via the interface of the service exposure and at least one of the layers of the plurality of layers. The method further includes predicting 1604, with a central ML model, that the action includes an anomaly; and triggering 1606 an alarm or notification to the service exposure and at least some of the plurality of layers responsive to the anomaly.
[0083] Monitoring 1602 may include continuous monitoring of a plurality of actions directed to the communication system via the interface of the service exposure and the plurality of layers.
[0084] The plurality of layers may respectively include a local ML model in a vFML framework.
[0085] In some embodiments, the central ML model is a vFML model, and the method further includes training 1600 the central ML model to predict the anomaly based on vFML.. In other embodiments, the central ML model may be a central ML model in a central cloud; and raw data from different layers is sent to the central ML model in, e.g., a central server in thecentral cloud. The training 1600 may include (i) receiving input data including heterogenous features from the service exposure and at least some of the plurality of layers, (ii) fusing the input data into a vector, (iii) predicting an anomaly in the vector, and (iv) labelling the anomaly. Fusing may include an aggregation of the heterogenous features.
[0086] Training 1600 may include (i) characterizing the heterogeneous features based on an attention process that captures representations of the input data through keys, queries, and value mappings over a ground truth comprising attention weights, where the ground truth includes an action at the interface, (ii) applying a query over the ground truth, and (iii) obtaining a linear combination of values that represent the heterogenous features found in the ground truth. The attention weights may include a respective weight to a respective data point in the input data based on a respective distance of the respective data point from a query.
[0087] The attention process may further include computing a plurality of respective attention pooling outputs with a respective attention module for a respective layer from the plurality of layers. The respective attention pooling output may include a representation of a contextual relationship between a key and the query. The plurality of respective attention pooling outputs may be fused and used to identify the anomaly.
[0088] The attention weights may include a local-attention based weight and a global- attention based weight, and the training 1600 may be based on an in-distribution versus out-of- distribution analysis of the attention weights.
[0089] A key may include a user equipment and a query may include an action at the interface.
[0090] Predicting 1604 may include comparing the monitored action to reference data based on distance attention-based weights computed in a training phase. The anomaly may be predicted when the distance attention-based weights are out-of-distribution.
[0091] Additionally, or alternatively, the method further includes storing 1610 the triggering of the alarm or notification; and using 1612 the triggering for risk management.
[0092] In other embodiments, the method further includes labelling 1608 the alarm or notification to indicate at least one of (i) an indication of a type of the anomaly, and (ii) a time when the anomaly occurred.
[0093] The interface may include at least one of a CLI and an API.
[0094] The plurality of layers may include at least a hardware layer, a virtualization layer, a service framework layer, and an applications / services layer.
[0095] Various operations from the flow chart of Figure 16 may be optional with respect to some embodiments of computing devices configured to secure an interface of a service exposurein a communication system including a plurality of layers. For example, the operations of blocks 1600 and 1608-1612 may be optional in some embodiments.
[0096] Figure 17 shows an example of a communication system 1700 in accordance with some embodiments.
[0097] In the example, the communication system 1700 includes a telecommunication network 1702 that includes an access network 1704, such as a radio access network (RAN), and a core network 1706, which includes one or more core network nodes 1708 such as a first network node of embodiments herein. The access network 1704 includes one or more access network nodes, such as network nodes 1710a and 1710b (one or more of which may be generally referred to as network nodes 1710), or any other similar 3GPP access node or non- 3GPP access point. Moreover, as will be appreciated by those of skill in the art, the network nodes 1710 are not necessarily limited to an implementation in which a radio portion and a baseband portion are supplied and integrated by a single vendor. Thus, it will be understood that the network nodes 1710 may include disaggregated implementations or portions thereof. For example, in some embodiments, the telecommunication network 1702 includes one or more open-RAN (ORAN) network nodes (e.g., computing device 180). An ORAN network node is a node in the telecommunication network 1702 that supports an ORAN specification (e.g., a specification published by the O-RAN Alliance, or any similar organization) and may operate alone or together with other nodes to implement one or more functionalities of any node in the telecommunication network 1702, including one or more network nodes 1710 and / or core network nodes 1708.
[0098] As discussed herein, examples of an ORAN network node include an O-RU, an O- DU, an O-CU, including an O-CU-CP or an O-CU-UP, a RAN intelligent controller (near-real time or non-real time) hosting software or software plug-ins, such as a near-real time RAN control application (e.g., xApp) or a non-real time RAN automation application (e.g., rApp), or any combination thereof (the adjective “open” designating support of an ORAN specification). The network node may support a specification by, for example, supporting an interface defined by the ORAN specification, such as an Al, Fl, Wl, El, E2, X2, Xn interface, an open fronthaul user plane interface, or an open fronthaul management plane interface. Intents and content- aware notifications described herein may be communicated from a 3GPP network node or an ORAN network node over 3GPP-defined interfaces (e.g., N2, N3) and / or ORAN Alliance- defined interfaces (e.g., Al, 01). Moreover, an ORAN network node may be a logical node in a physical node. Furthermore, an ORAN network node may be implemented in a virtualization environment (described further below) in which one or more network functions are virtualized. For example, the virtualization environment may include an O-Cloud computing platformorchestrated by a SMO framework via an 0-2 interface defined by the 0-RAN Alliance. The network nodes 1710 facilitate direct or indirect connection of UE, such as by connecting wireless devices 1712a, 1712b, 1712c, and 1712d (one or more of which may be generally referred to as UEs 1712) to the core network 1706 over one or more wireless connections. The network nodes 1710 facilitate direct or indirect connection of UE, such as by connecting UEs 1712a, 1712b, 1712c, and 1712d (one or more of which may be generally referred to as UEs 1712) to the core network 1706 over one or more wireless connections. The computing device 1800 may be a cloud-based device communicatively coupled to the telecommunications network 1702.
[0099] Example wireless communications over a wireless connection include transmitting and / or receiving wireless signals using electromagnetic waves, radio waves, infrared waves, and / or other types of signals suitable for conveying information without the use of wires, cables, or other material conductors. Moreover, in different embodiments, the communication system 1700 may include any number of wired or wireless networks, network nodes, UEs, and / or any other components or systems that may facilitate or participate in the communication of data and / or signals whether via wired or wireless connections. The communication system 1700 may include and / or interface with any type of communication, telecommunication, data, cellular, radio network, and / or other similar type of system.
[0100] The UEs 1712 may be any of a wide variety of communication devices, including wireless devices arranged, configured, and / or operable to communicate wirelessly with the network nodes 1710 and other communication devices. Similarly, the network nodes 1710 are arranged, capable, configured, and / or operable to communicate directly or indirectly with the UEs 1712 and / or with other network nodes or equipment in the telecommunication network 1702 to enable and / or provide network access, such as wireless network access, and / or to perform other functions, such as administration in the telecommunication network 1702.
[0101] In the depicted example, the core network 1706 connects the network nodes 1710 to one or more hosts, such as host 1716. These connections may be direct or indirect via one or more intermediary networks or devices. In other examples, network nodes may be directly coupled to hosts. The core network 1706 includes one more core network nodes (e.g., core network node 1708) that are structured with hardware and software components. Features of these components may be substantially similar to those described with respect to the UEs, network nodes, and / or hosts, such that the descriptions thereof are generally applicable to the corresponding components of the core network node 1708. Example core network nodes include functions of one or more of a Mobile Switching Center (MSC), Mobility Management Entity (MME), Home Subscriber Server (HSS), Access and Mobility Management Function (AMF),Session Management Function (SMF), Authentication Server Function (AUSF), Subscription Identifier De-concealing function (SIDF), Unified Data Management (UDM), Security Edge Protection Proxy (SEPP), NEF, and / or a User Plane Function (UPF).
[0102] The host 1716 may be under the ownership or control of a service provider other than an operator or provider of the access network 1704 and / or the telecommunication network 1702, and may be operated by the service provider or on behalf of the service provider. The host 1716 may host a variety of applications to provide one or more service. Examples of such applications include live and pre-recorded audio / video content, data collection services such as retrieving and compiling data on various ambient conditions detected by a plurality of UEs, analytics functionality, social media, functions for controlling or otherwise interacting with remote devices, functions for an alarm and surveillance center, or any other such function performed by a server.
[0103] As a whole, the communication system 1700 of Figure 17 enables connectivity between the UEs, network nodes, and hosts. In that sense, the communication system may be configured to operate according to predefined rules or procedures, such as specific standards that include, but are not limited to: GSM; Universal Mobile Telecommunications System (UMTS); LTE, and / or other suitable 2G, 3G, 4G, 5G standards, or any applicable future generation standard (e.g., 6G); wireless local area network (WLAN) standards, such as the Institute of Electrical and Electronics Engineers (IEEE) 802.11 standards (WiFi); and / or any other appropriate wireless communication standard, such as the Worldwide Interoperability for Microwave Access (WiMax), Bluetooth, Z-Wave, Near Field Communication (NFC) ZigBee, LiFi, and / or any low-power wide-area network (LPWAN) standards such as LoRa and Sigfox.
[0104] In some examples, the telecommunication network 1702 is a cellular network that implements 3GPP standardized features. Accordingly, the telecommunications network 1702 may support network slicing to provide different logical networks to different devices that are connected to the telecommunication network 1702. For example, the telecommunications network 1702 may provide URLLC services to some UEs, while providing eMBB services to other UEs, and / or mMTC / Massive loT services to yet further UEs.
[0105] In some examples, the UEs 1712 are configured to transmit and / or receive information without direct human interaction. For instance, a UE may be designed to transmit information to the access network 1704 on a predetermined schedule, when triggered by an internal or external event, or in response to requests from the access network 1704. Additionally, a UE may be configured for operating in single- or multi-RAT or multi- standard mode. For example, a UE may operate with any one or combination of Wi-Fi, NR (New Radio) and LTE,i.e. being configured for multi-radio dual connectivity (MR-DC), such as E-UTRAN (Evolved- UMTS Terrestrial Radio Access Network) New Radio - Dual Connectivity (EN-DC).
[0106] In the example, the hub 1714 communicates with the access network 1704 to facilitate indirect communication between one or more UEs (e.g., UE 1712c and / or 1712d) and network nodes (e.g., network node 1710b). In some examples, the hub 1714 may be a controller, router, content source and analytics, or any of the other communication devices described herein regarding UEs. For example, the hub 1714 may be a broadband router enabling access to the core network 1706 for the UEs. As another example, the hub 1714 may be a controller that sends commands or instructions to one or more actuators in the UEs. Commands or instructions may be received from the UEs, network nodes 1710, or by executable code, script, process, or other instructions in the hub 1714. As another example, the hub 1714 may be a data collector that acts as temporary storage for UE data and, in some embodiments, may perform analysis or other processing of the data. As another example, the hub 1714 may be a content source. For example, for a UE that is a VR headset, display, loudspeaker or other media delivery device, the hub 1714 may retrieve VR assets, video, audio, or other media or data related to sensory information via a network node, which the hub 1714 then provides to the UE either directly, after performing local processing, and / or after adding additional local content. In still another example, the hub 1714 acts as a proxy server or orchestrator for the UEs, in particular in if one or more of the UEs are low energy loT devices.
[0107] The hub 1714 may have a constant / persistent or intermittent connection to the network node 1710b. The hub 1714 may also allow for a different communication scheme and / or schedule between the hub 1714 and UEs (e.g., UE 1712c and / or 1712d), and between the hub 1714 and the core network 1706. In other examples, the hub 1714 is connected to the core network 1706 and / or one or more UEs via a wired connection. Moreover, the hub 1714 may be configured to connect to an M2M service provider over the access network 1704 and / or to another UE over a direct connection. In some scenarios, UEs may establish a wireless connection with the network nodes 1710 while still connected via the hub 1714 via a wired or wireless connection. In some embodiments, the hub 1714 may be a dedicated hub - that is, a hub whose primary function is to route communications to / from the UEs from / to the network node 1710b. In other embodiments, the hub 1714 may be a non-dedicated hub - that is, a device which is capable of operating to route communications between the UEs and network node 1710b, but which is additionally capable of operating as a communication start and / or end point for certain data channels.
[0108] Figure 18 shows a computing device 1800 in accordance with some embodiments. As used herein, computing device refers to equipment capable, configured, arranged and / oroperable to secure an interface of a service exposure in a communication system including a plurality of layers. Examples of computing devices include computers, servers, network nodes including, but are not limited to, access points (APs) (e.g., radio access points), core nodes, base stations (BSs) (e.g., radio base stations, Node Bs, eNBs and New Radio (NR) NodeBs (gNBs)), O-RAN nodes or components of an O-RAN node (e.g., O-RU, O-DU, O-CU).
[0109] The computing device 1800 includes processing circuitry 1802, a memory 1804 including program code, a central ML model 904, a communication interface 1808, and a power source 1810. It is noted that the central ML model 904 may be included in memory 1804, or may be external computing device 1800 and communicatively connected to computing device 1800. The computing device 1800 may be composed of multiple physically separate components, which may each have their own respective components. In certain scenarios in which the computing device 1800 comprises multiple separate components, one or more of the separate components may be shared among several computing devices. In some embodiments, the computing device 1800 may be configured to support multiple radio access technologies (RATs). In such embodiments, some components may be duplicated (e.g., separate memoryl804 for different RATs) and some components may be reused. The computing device 1800 may also include multiple sets of the various illustrated components for different wireless technologies integrated into computing device 1800, for example Global System for Mobile Communication (GSM), Wideband Code Division Multiple Access (WCDMA), Long Term Evolution (LTE), NR, WiFi, Zigbee, Z-wave, LoRaWAN, Radio Frequency Identification (RFID) or Bluetooth wireless technologies. These wireless technologies may be integrated into the same or different chip or set of chips and other components within computing device 1800.
[0110] The processing circuitry 1802 may comprise a combination of one or more of a microprocessor, controller, microcontroller, central processing unit, digital signal processor, application-specific integrated circuit, field programmable gate array, or any other suitable computing device, resource, or combination of hardware, software and / or encoded logic operable to provide, either alone or in conjunction with other computing device 1800 components, such as the memory 1804, to provide computing device 1800 functionality.
[0111] In some embodiments, the processing circuitry 1802 includes a system on a chip (SOC). In some embodiments, the processing circuitry 1802 includes one or more of radio frequency (RF) transceiver circuitry and baseband processing circuitry. In some embodiments, the radio frequency (RF) transceiver circuitry and the baseband processing circuitry may be on separate chips (or sets of chips), boards, or units, such as radio units and digital units. In alternative embodiments, part or all of RF transceiver circuitry and baseband processing circuitry may be on the same chip or set of chips, boards, or units.
[0112] The memory 1804 may comprise any form of volatile or non-volatile computer- readable memory including, without limitation, persistent storage, solid-state memory, remotely mounted memory, magnetic media, optical media, random access memory (RAM), read-only memory (ROM), mass storage media (for example, a hard disk), removable storage media (for example, a flash drive, a Compact Disk (CD) or a Digital Video Disk (DVD)), and / or any other volatile or non-volatile, non-transitory device-readable and / or computer-executable memory devices that store information, data, and / or instructions that may be used by the processing circuitry 1802. The memory 1804 may store any suitable instructions, data, or information, including a computer program, software, an application including one or more of logic, rules, code, tables, and / or other instructions capable of being executed by the processing circuitry 1802 and utilized by the computing device 1800. The memory 1804 may be used to store any calculations made by the processing circuitry 1802 and / or any data received via the communication interface 1808. In some embodiments, the processing circuitry 1802 and memory 1804 are integrated.
[0113] The communication interface 1808 is used in wired or wireless communication of signaling and / or data between a computing device, another device, a network node, access network, and / or UE. The communication interface 1808 can comprise port(s) / terminal(s) to send and receive data, for example to and from a computing device or other device over a wired connection. The communication interface 1808 also can include radio front-end circuitry that may be coupled to, or in certain embodiments a part of, an antenna. A radio signal may then be transmitted via the antenna. Similarly, when receiving data, the antenna may collect radio signals which are then converted into digital data by the radio front-end circuitry. The digital data may be passed to the processing circuitry 1802. In other embodiments, the communication interface may comprise different components and / or different combinations of components.
[0114] In certain alternative embodiments, the computing device 1800 does not include separate radio front-end circuitry, instead, the processing circuitry 1802 includes radio front-end circuitry and is connected to an antenna. Similarly, in some embodiments, all or some of the RF transceiver circuitry is part of the communication interface 1808. In still other embodiments, the communication interface 1808 includes one or more ports or terminals, the radio front-end circuitry, and the RF transceiver circuitry, as part of a radio unit (not shown), and the communication interface 1808 communicates with baseband processing circuitry, which is part of a digital unit (not shown).
[0115] The power source 1810 provides power to the various components of computing device 1800 in a form suitable for the respective components (e.g., at a voltage and current level needed for each respective component). The power source may further comprise, or be coupledto, power management circuitry to supply the components of the computing device 1800 with power for performing the functionality described herein. For example, the computing device 1800 may be connectable to an external power source (e.g., the power grid, an electricity outlet) via an input circuitry or interface such as an electrical cable, whereby the external power source supplies power to power circuitry of the power source. As a further example, the power source may comprise a source of power in the form of a battery or battery pack which is connected to, or integrated in, power circuitry. The battery may provide backup power should the external power source fail.
[0116] Embodiments of the computing device 1800 may include additional components beyond those shown in Figure 18 for providing certain aspects of the computing device’s functionality, including any of the functionality described herein and / or any functionality necessary to support the subject matter described herein. For example, the computing device 1800 may include user interface equipment to allow input of information into the computing device 1800 and to allow output of information from the computing device 1800. This may allow a user to perform diagnostic, maintenance, repair, and other administrative functions for the computing device 1800.
[0117] Figure 19 is a block diagram illustrating a virtualization environment 1900 in which functions implemented by some embodiments may be virtualized. In the present context, virtualizing means creating virtual versions of apparatuses or devices which may include virtualizing hardware platforms, storage devices and networking resources. As used herein, virtualization can be applied to any device described herein, or components thereof, and relates to an implementation in which at least a portion of the functionality is implemented as one or more virtual components. Some or all of the functions described herein may be implemented as virtual components executed by one or more virtual machines (VMs) implemented in one or more virtual environments 1900 hosted by one or more of hardware nodes, such as a hardware computing device that operates as a network node, UE, core network node, or host. Further, in embodiments in which the virtual node does not require radio connectivity (e.g., a core network node or host), then the node may be entirely virtualized. In some embodiments, the virtualization environment 1900 includes components defined by the O-RAN Alliance, such as an O-Cloud environment orchestrated by a Service Management and Orchestration Framework via an O-2 interface.
[0118] Applications 1902 (which may alternatively be called software instances, virtual appliances, network functions, virtual nodes, virtual network functions, etc.) are run in the virtualization environment 1900 to implement some of the features, functions, and / or benefits of some of the embodiments disclosed herein.
[0119] Hardware 1904 includes processing circuitry, memory that stores software and / or instructions executable by hardware processing circuitry, and / or other hardware devices as described herein, such as a network interface, input / output interface, and so forth. Software may be executed by the processing circuitry to instantiate one or more virtualization layers 1906 (also referred to as hypervisors or virtual machine monitors (VMMs)), provide VMs 1908a and 1908b (one or more of which may be generally referred to as VMs 1908), and / or perform any of the functions, features and / or benefits described in relation with some embodiments described herein. The virtualization layer 1906 may present a virtual operating platform that appears like networking hardware to the VMs 1908.
[0120] The VMs 1908 comprise virtual processing, virtual memory, virtual networking or interface and virtual storage, and may be run by a corresponding virtualization layer 1906. Different embodiments of the instance of a virtual appliance 1902 may be implemented on one or more of VMs 1908, and the implementations may be made in different ways. Virtualization of the hardware is in some contexts referred to as network function virtualization (NFV). NFV may be used to consolidate many network equipment types onto industry standard high volume server hardware, physical switches, and physical storage, which can be located in data centers, and customer premise equipment.
[0121] In the context of NFV, a VM 1908 may be a software implementation of a physical machine that runs programs as if they were executing on a physical, non- virtualized machine. Each of the VMs 1908, and that part of hardware 1904 that executes that VM, be it hardware dedicated to that VM and / or hardware shared by that VM with others of the VMs, forms separate virtual network elements. Still in the context of NFV, a virtual network function is responsible for handling specific network functions that run in one or more VMs 1908 on top of the hardware 1904 and corresponds to the application 1902.
[0122] Hardware 1904 may be implemented in a standalone network node with generic or specific components. Hardware 1904 may implement some functions via virtualization.Alternatively, hardware 1904 may be part of a larger cluster of hardware (e.g. such as in a data center or CPE) where many hardware nodes work together and are managed via management and orchestration 1910, which, among others, oversees lifecycle management of applications 1902. In some embodiments, hardware 1904 is coupled to one or more radio units that each include one or more transmitters and one or more receivers that may be coupled to one or more antennas. Radio units may communicate directly with other hardware nodes via one or more appropriate network interfaces and may be used in combination with the virtual components to provide a virtual node with radio capabilities, such as a radio access node or a base station. Insome embodiments, some signaling can be provided with the use of a control system 1912 which may alternatively be used for communication between hardware nodes and radio units.
[0123] Although computing devices described herein may include the illustrated combination of hardware components, other embodiments may comprise computing devices with different combinations of components. It is to be understood that these computing devices may comprise any suitable combination of hardware and / or software needed to perform the tasks, features, functions, and methods disclosed herein. Determining, calculating, obtaining or similar operations described herein may be performed by processing circuitry, which may process information by, for example, converting the obtained information into other information, comparing the obtained information or converted information to information stored in the network node, and / or performing one or more operations based on the obtained information or converted information, and as a result of said processing making a determination.
[0124] Moreover, while components are depicted as single boxes located within a larger box, or nested within multiple boxes, in practice, computing devices may comprise multiple different physical components that make up a single illustrated component, and functionality may be partitioned between separate components. For example, a communication interface may be configured to include any of the components described herein, and / or the functionality of the components may be partitioned between the processing circuitry and the communication interface. In another example, non-computationally intensive functions of any of such components may be implemented in software or firmware and computationally intensive functions may be implemented in hardware.
[0125] In certain embodiments, some or all of the functionality described herein may be provided by processing circuitry executing instructions stored on in memory, which in certain embodiments may be a computer program product in the form of a non-transitory computer- readable storage medium. In alternative embodiments, some or all of the functionality may be provided by the processing circuitry without executing instructions stored on a separate or discrete device-readable storage medium, such as in a hard-wired manner. In any of those particular embodiments, whether executing instructions stored on a non-transitory computer- readable storage medium or not, the processing circuitry can be configured to perform the described functionality. The benefits provided by such functionality are not limited to the processing circuitry alone or to other components of the computing device, but are enjoyed by the computing device as a whole, and / or by end users and a wireless network generally.
Claims
CLAIMSWhat is Claimed is:
1. A computer-implemented method for securing an interface of a service exposure in a communication system comprising a plurality of layers, the method comprising: monitoring (1602) an action directed to the communication system via the interface of the service exposure and at least one of the layers of the plurality of layers; predicting (1604), with a central machine learning (ML) model, that the action comprises an anomaly; and triggering (1606) an alarm or notification to the service exposure and at least some of the plurality of layers responsive to the anomaly.
2. The method of Claim 1, wherein the monitoring (1602) comprises continuous monitoring of a plurality of actions directed to the communication system via the interface of the service exposure and the plurality of layers.
3. The method of any one of Claims 1 to 2, wherein the plurality of layers respectively comprise a local ML model in a vertical federated ML framework.
4. The method of any one of Claims 1 to 3, wherein the central ML model comprises a vertical federated ML model and the method further comprising: training (1600) the central ML model to predict the anomaly based on vertical federated ML.
5. The method of Claim 4, wherein the training (1600) comprises (i) receiving input data comprising heterogenous features from the service exposure and at least some of the plurality of layers, (ii) fusing the input data into a vector, (iii) predicting an anomaly in the vector, and (iv) labelling the anomaly.
6. The method of Claim 5, wherein the fusing comprises an aggregation of the heterogenous features.
7. The method of any one of Claims 5 to 6, wherein the training (1600) comprises (i) characterizing the heterogeneous features based on an attention process that captures representations of the input data through keys, queries, and value mappings over a ground truth comprising attention weights, wherein the ground truth comprises an action at the interface, (ii) applying a query over the ground truth, and (iii) obtaining a linear combination of values that represent the heterogenous features found in the ground truth.
8. The method of Claim 7, wherein the attention weights comprise a respective weight to a respective data point in the input data based on a respective distance of the respective data point from a query.
9. The method of any one of Claims 7 to 8, wherein the attention process further comprises computing a plurality of respective attention pooling outputs with a respective attention module for a respective layer from the plurality of layers.
10. The method of Claim 9, wherein the respective attention pooling output comprises a representation of a contextual relationship between a key and the query.
11. The method of any one of Claims 9 and 10, wherein the plurality of respective attention pooling outputs are fused and used to identify the anomaly.
12. The method of any one of Claims 7 to 11, wherein the attention weights comprise a local-attention based weight and a global-attention based weight, and wherein the training (1600) is based on an in-distribution versus out-of-distribution analysis of the attention weights.
13. The method of any one of Claims 7 to 12, wherein a key comprises a user equipment and a query comprises an action at the interface.
14. The method of any one of Claims 1 to 13, wherein the predicting (1604) comprises comparing the monitored action to reference data based on distance attention-based weights computed in a training phase.
15. The method of Claim 14, wherein the anomaly is predicted when the distance attention-based weights are out-of-distribution.
16. The method of any one of Claims 1 to 15, further comprising: storing (1610) the triggering of the alarm or notification; and using (1612) the triggering for risk management.
17. The method of any one of Claims 1 to 16, further comprising: labelling (1608) the alarm or notification to indicate at least one of (i) an indication of a type of the anomaly, and (ii) a time when the anomaly occurred.
18. The method of any one of Claims 1 to 17, wherein the interface comprises at least one of a command line interface and an application programming interface.
19. The method of any one of Claims 1 to 18, wherein the plurality of layers comprise at least a hardware layer, a virtualization layer, a service framework layer, and an applications / services layer.
20. A computing device (1800) configured to secure an interface of a service exposure in a communication system comprising a plurality of layers, the computing device comprising: processing circuitry (1802); memory (1804) coupled with the processing circuitry, wherein the memory includes instructions that when executed by the processing circuitry causes the computing device to perform operations comprising monitor an action directed to the communication system via the interface of the service exposure and at least one of the layers of the plurality of layers; predict, with a central machine learning (ML) model, that the action comprises an anomaly; and trigger an alarm or notification to the service exposure and at least some of the plurality of layers responsive to the anomaly.
21. The computing device of Claim 20, wherein the operations further comprise any of the operations of Claims 2 to 19.
22. A non-transitory computer readable medium (1804) including program code to be executed by processing circuitry (1802) of a computing device (1800) configured to secure an interface of a service exposure in a communication system comprising a plurality of layers, whereby execution of the program code causes the program code to perform operations comprising: monitor an action directed to the communication system via the interface of the service exposure and at least one of the layers of the plurality of layers; predict, with a central machine learning (ML) model, that the action comprises an anomaly; and trigger an alarm or notification to the service exposure and at least some of the plurality of layers responsive to the anomaly.
23. The non-transitory computer readable medium (1804) of Claim 22, the operations further comprising any of the operations of Claims 2 to 19.
Citation Information
Patent Citations
Securing an Anomaly Detection System for Microservice-Based Applications
US20230412629A1
IOT Blockchain DDOS Detection and Countermeasures
US20240039938A1