Method, a network function for threat modeling, a computer program and a computer program product

The runtime threat modeling approach addresses the limitations of static threat models by continuously monitoring RAN environments, identifying attack surfaces and security controls, and calculating threat scores, resulting in proactive and efficient threat mitigation.

WO2026071962A1PCT designated stage Publication Date: 2026-04-02TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
View PDF 5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-09-26
Publication Date
2026-04-02

AI Technical Summary

Technical Problem

Existing threat modeling methodologies fail to adapt to dynamic environments like Radio Access Networks (RAN), lacking granularity and failing to capture evolving threat landscapes, leading to outdated and inaccurate threat assessments.

Method used

A runtime threat modeling approach that continuously monitors environmental changes, identifies attack surfaces, threat vectors, and security controls, calculating a threat level score through automated logical reasoning and closed-loop feedback to proactively mitigate potential threats.

Benefits of technology

Enables proactive security by providing real-time threat assessments, reducing computing resources, and improving threat observability and prioritization, thus enhancing the security and efficiency of RAN systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure SE2025050854_02042026_PF_FP_ABST
    Figure SE2025050854_02042026_PF_FP_ABST
Patent Text Reader

Abstract

A computer implemented method for runtime threat modeling is provided. Event related information associated with an asset is obtained. Attack surface related information associated with the event related information is identified. Threat vector related information associated with the attack surface related information is identified. Security control related information associated with the threat vector related information is identified. An output based on at least one of the attack surface related information, the threat vector related information, or the security control related information is provided.
Need to check novelty before this filing date? Find Prior Art

Description

METHOD, A NETWORK FUNCTION FOR THREAT MODELING, A COMPUTER PROGRAM AND A COMPUTER PROGRAM PRODUCTTECHNICAL FIELD

[0001] Embodiments presented herein relate to a computer implemented method, a network function, a computer program and a computer program product for runtime threat modeling.BACKGROUND

[0002] Threat modeling is a structured approach for identifying and prioritizing potential threats to a system, application or network. It is an essential part of risk management process in cybersecurity and is used to assess and mitigate potential security risks.

[0003] The state of the art comprises different research publications that are relevant to threat modeling. They primarily focus on threat modelling using ontologies, providing probabilities and threat analysis for e.g. 5G networks using attack graphs. In addition, there are relevant industry approaches that try to provide observability of threats in the Cloud. Some examples include initiatives in Google Cloud, Amazon Web Services (AWS), and Microsoft Azure. In addition, GSMA has published the Mobile Threat Intelligence Principles, which introduce an MITRE-aligned threat framework for Telecommunication Networks.

[0004] The current state of threat modelling in cybersecurity primarily relies on vulnerabilities present within the environment, which may not apply uniformly across all attack surfaces. For instance, certain attack surfaces, such as in Radio Access Network (RAN), have unique characteristics that traditional models may fail to address.

[0005] Most of the existing work on threat modeling is based on simulation techniques, where attack scenarios are pre-constructed and automation tools simulate these attacks. While this approach provides a degree of insight into potential vulnerabilities, the validation of threats in real-time remains questionable. As systems evolve throughout their lifecycle, the operational environment changes, which in turn impacts the threat landscape. This evolving nature of environments is not fully captured in current models. As a result, the assumed attack surface during the design phase often becomes outdated and inaccurate.

[0006] Many current threat modeling methodologies leverage established threat knowledge bases, such as STRIDE (Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege), PASTA (Process for Attack Simulation and Threat Analysis), or MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge), to identify potential threats. While these knowledge bases are useful for modelingconventional attack surfaces, they often lack granularity, particularly when applied to specialized domains like RAN. These knowledge bases do not always reflect the specific techniques that sophisticated threat actors might use to target the RAN.SUMMARY

[0007] An object of embodiments herein is to address the above identified short-comings of the current threat modeling mechanisms, and to improve the threat modeling to be more adaptive to the environmental changes.

[0008] According to a first aspect, a computer implemented method for runtime threat modeling is provided. The method comprises obtaining event related information associated with an asset. The method comprises identifying attack surface related information associated with the event related information. The method comprises identifying threat vector related information associated with the attack surface related information. The method comprises identifying security control related information associated with the threat vector related information. The method comprises providing an output based on at least one of the attack surface related information, the threat vector related information, or the security control related information.

[0009] According to a second aspect, a network function for runtime threat modeling is provided. The network function comprises a processor and a memory, said memory containing instructions executable by said processor whereby said network function is operative to perform the actions. One action comprises identifying attack surface related information associated with the event related information. One action comprises identifying threat vector related information associated with the attack surface related information. One action comprises identifying security control related information associated with the threat vector related information. One action comprises providing an output based on at least one of the attack surface related information, the threat vector related information, or the security control related information.

[0010] According to a third aspect, a computer program for runtime threat modeling is provided. The computer program comprises computer readable code being configured such that, on execution by suitable computer or processor, the computer or processor is caused to perform the actions. One action comprises identifying attack surface related information associated with the event related information. One action comprises identifying threat vector related information associated with the attack surface related information. One action comprises identifying security control related information associated with the threat vectorrelated information. One action comprises providing an output based on at least one of the attack surface related information, the threat vector related information, or the security control related information.

[0011] According to a fourth aspect, a computer program product is provided. The computer program product comprises a computer readable medium having computer readable code embodied therein, the computer readable code being configured such that, on execution by suitable computer or processor, the computer or processor is caused to perform the actions. One action comprises identifying attack surface related information associated with the event related information. One action comprises identifying threat vector related information associated with the attack surface related information. One action comprises identifying security control related information associated with the threat vector related information. One action comprises providing an output based on at least one of the attack surface related information, the threat vector related information, or the security control related information. BRIEF DESCRIPTION OF DRAWINGS

[0012] The inventive concept is now described, by way of example, with reference to the accompanying drawings, in which:

[0013] Fig.l illustrates a schematic diagram of a runtime threat model according to an embodiment.

[0014] Fig.2 illustrates a workflow of a runtime threat model according to an embodiment.

[0015] Fig.3 illustrates interactions between components in a runtime threat model according to an embodiment.

[0016] Fig.4 shows a flowchart according to an embodiment.

[0017] Fig.5 illustrates relationships in a runtime threat model according to an embodiment.

[0018] Fig.6 shows an example of a runtime threat model generation according to an embodiment.

[0019] Fig.7 shows a concept of model-driven security according to some embodiments.

[0020] Fig.8 illustrates an example of a runtime threat model applied in O-RAN, according to an embodiment.

[0021] Fig.9 and Fig.10 illustrate examples of system model according to some embodiments.

[0022] Fig.11 and Fig.12 illustrate examples of event model according to some embodiments.

[0023] Fig.13 shows a radio attack surface according to an embodiment.

[0024] Fig.14 shows an example of attack surface model according to an embodiment.

[0025] Fig.15 represents the general graph or the ontology of a possible threat vector according to an embodiment.

[0026] Fig.16 shows a practical example of the ontology shown in Fig. 15.

[0027] Fig.17 shows an acyclic-directed graph that defines the relationships and interactions between the different models according to some embodiment of present disclosure.

[0028] Figs. l8a-b shows a signaling diagram involving human in the loop actuation according to an embodiment.

[0029] Figs.19a-b shows a signaling diagram involving close loop actuation according to an embodiment.

[0030] Fig.20 shows an example of calculating a threat level score according to an embodiment.

[0031] Fig.21 shows an example of an attack surface according to an embodiment.

[0032] Fig.22 illustrates an example of a threat vector according to an embodiment.

[0033] Fig.23 illustrates a use case according to an embodiment.

[0034] Fig.24 shows one example of the deployment according to some embodiments.

[0035] Fig.25 shows another example of deployment according to some embodiments.

[0036] Fig.26 illustrates a method according to an embodiment.

[0037] Fig. 27 shows an example of a communication system in accordance with some embodiments.

[0038] Fig. 28 shows a UE in accordance with some embodiments.

[0039] Fig. 29 shows a network node in accordance with some embodiments.

[0040] Fig. 30 is a block diagram illustrating a virtualization environment in which functions implemented by some embodiments may be virtualized.

[0041] Fig. 31 illustrates a schematic diagram of a network function according to an embodiment.

[0042] Fig. 32 illustrates a schematic diagram of a computer program product according to some embodiments.DETAILED DESCRIPTION

[0043] The inventive concept will now be described more fully hereinafter with reference to the accompanying drawings, in which certain embodiments of the inventive concept are shown. This inventive concept may, however, be embodied in many different forms and shouldnot be construed as limited to the embodiments set forth herein; rather, these embodiments are provided by way of example so that this disclosure will be thorough and complete, and will fully convey the scope of the inventive concept to those skilled in the art. Like numbers refer to like elements throughout the description. Any step or feature illustrated by dashed lines should be regarded as optional.

[0044] Ontology -based threat modeling, particularly those using knowledge graphs (KGs), shows promise by predicting associations between threat databases and network nodes. However, a missing element in the literature is the relationship between evolved threats and existing security controls that changed over time. Specifically, the effectiveness score of the security controls could be used as weights in the knowledge graph’s edges allowing for a more accurate representation of the risk level associated with each technique in the attack graph. Currently, no existing solution fully incorporates attack surface modelling and its inherent dynamicity as the core part of the threat modelling process.

[0045] The existing approaches to threat modelling fall short in several key areas. The reliance on static threat models and pre-existing knowledge bases limits their applicability, especially in dynamic environments like RAN. Therefore, there is a need for a runtime threat modelling approach that continuously adapts to the system’s changes, and evolving threat landscape, as well as integrating the effectiveness of security controls. In this invention, a runtime threat modelling approach will enable the RAN node to continuously monitor its environment and reiterate the threat modelling process, calculating a possible score on the attack level.

[0046] Threat Modelling is a form of risk assessment that models aspects of the attack and defense sides of a particular logical entity, such as a piece of data, an application, a host, a system, or an environment. It is deduced that a threat model consists collectively of attack models and the security controls attempting to disrupt those attack models on a target. Techniques refer to the behavior of a threat actor (i.e., where an attack model compromises one or more attack vectors), and all the attack vectors directly against a system are collectively known as attack surfaces. This gap highlights the need for runtime threat modeling, a dynamic approach that can adapt to environmental changes and continuously update the threat model throughout the system’s lifecycle.

[0047] The proposed invention provides a method to continuously evaluate the effect of changes in the environment (e.g., configuration, topology) and its effect on the threat level during the operations (i.e., runtime) of the system. In the invention, the RAN Network Function(i.e., eNB, gNB, Cloud Radio Access Network (C-RAN), Open Centralized Unit (O-CU), Open Distributed Unit (O-DU)) is able to continuously monitor its environment and reiterate the threat modelling process. By doing this, it allows continuously update the view of the suitable security controls needed to be implemented to mitigate the identified threats and allow the systems to be proactively ready to mitigate against threats. Taking into consideration the attack surface changes and the effectiveness of security controls in the runtime threat modeling is a new perspective that can provide a more effective threat modeling process to protect the asset, e g. RAN.

[0048] Hereafter, the solutions will be described by taking RAN scenario as an example. The solution calculates a possible score on the threat level impacting the RAN at a given time to prioritize the threats and mitigation controls that are required to be implemented. This approach helps classify those threats that have a higher score and should be prioritized for mitigation. The threat score, also referred to as the score of threat level, explains or provides an interpretation of the threat level, as well as gives an outlook of how well the security controls are working. The score shall provide more insights on additional configuration or security controls that are needed, providing a continuous loop that is dynamic.

[0049] The solution comprises analysing the attack surface and providing a score to indicate the level of the threats, and the increase or decrease of the attack surface leads to changes in threat levels. The score provides guidance on the readiness of the security controls to mitigate potential attacks. The solution is designed to be an RAN Application (rApp) in an Open RAN (0-RAN) deployment.

[0050] The core essence of the invention concept focuses on automating the evaluation of threat level of a network function using the process of threat modelling during runtime that is triggered by changes in the network or the network function’s environment. Also, it provides a threat modelling method to ensure continuous security of 0-RAN network functions. This solution utilizes a threat modelling method to identify the potential threats on a system or in the network. In particular, the threat modelling according to the present disclosures covers the following:

[0051] Identification of attack surface, including entry points: The method relies on identifying the possible entry points that an attacker can utilize to attack a system. The identification of the entry point is triggered by changes in the network or the environment of the system, for example, one change can be a new UE connected to the cell with a certain profile and specifications (e.g., NB-IoT device with an old software version) or a new cell thathas been added, or an update to the number of connected neighboring gNBs or Centralized Unit, CUs, etc.

[0052] Identification of attack vectors: The method then uses an attack-centric approach, where it identifies the possible attacker techniques and activity that can be used to exploit the attack surface, which is referred to as attack vectors or threat vectors. The attack surface is a composite definition that is formed of several metrics, including one for identifying the entry points an attacker can use, the channels used to transmit data, and what type of data can be used. The attack vectors denote the techniques that could be utilized by an attacker in a given attack surface. The solution models the attackers' techniques and procedures and the relationships between them using a semantic modelling approach that is machine readable, and which creates a knowledge graph of the possible attacking techniques and models the relationship with the attack surface.

[0053] Identification of security controls: To provide a better view of the potential risk and applicability of the potential threats, the method analyzes the current implemented security controls, if they are the right controls to mitigate the existing threats and, if they are correctly configured to mitigate the possible threats. The ability to analyze where the security controls fall short or how well they are performing provides a more accurate view of how a system can withstand the identified potential threats. The analysis is done by processing the configuration of the security controls and understanding the causality between the security control configuration and the expected threats and their conditions.

[0054] Event-based triggered: The threat modelling process is triggered by events or changes in the network that occur during the runtime or operations phase of the network functions. The aspect of being triggered by a runtime change or event enables the automation aspect of the modelling and analysis process during runtime. As mentioned earlier, changes can be topology changes, configuration changes, or traffic behavior or pattern changes.

[0055] Calculation of Threat level: The solution also provides a method to objectively calculate a score for the potential threat that can occur. This calculation defines a conditional probability of a threat to occur; where it is dependent on the attack surface exposure and the effectiveness of the security controls configured. This score will be able to provide an interpretation on what are the security controls that are not adequate to mitigate the identified threats, additionally, it provides a prioritized view of which entry points in a system require attention. The calculation of a score takes as input the below sub-metrics: Attack surface exposure metric, threat vector impact metric, and Security Control effectiveness metric.

[0056] Automated Logical Reasoning: The solution proposes a closed-loop logical reasoning system that leverages the captured real-time system events, a multi-level metrics, and an adaptive knowledge base to provide security control recommendations. This aims at adjusting security controls to proactively avoid potential threats. A closed-loop feedback mechanism ensures continuous monitoring and improvement by re-evaluating the effectiveness of the applied security controls and adjusting recommendations based on system status and evolving risks.

[0057] Continuous Knowledge Refinement: The proposed solution provides a continuous improvement of the security knowledge base, wherein the knowledge base is dynamically updated and refined through the capture and validation of real-time events based on the evolvement of threats and the changing configuration of the network. This process ensures that the knowledge base evolves in response to new information and intelligence leading to improving its ability to support decision-making and enhance system performance in run-time and over-time.

[0058] Certain embodiments may provide one or more of the following technical advantage(s).

[0059] The solution provides a method to continuously evaluate the effect of changes in the environment (e.g., configuration, topology) and its effect on the threat level during the operations (i.e., runtime) of the system.

[0060] The solution is event-based triggered mechanism, which enables immediate analysis of threats once the event is triggered. An event is any change in the environment, such as a new UE, new configuration, etc. Depending on the architectural considerations, events can be collected from RAN applications and probably other parts of the network (maybe the core network), as well as the platform and infrastructure.

[0061] The solution introduces an enhancement in the threat modelling process as it includes the analysis of the configured security controls, which provides a context for the threat modelling process, and provides an objective view of the current controls that can prevent possible threats.

[0062] The solution enables proactively securing the system by continuously recommending suitable mitigation techniques and controls as an output of the threat modelling process.

[0063] The solution enables a balanced utilization between computing resources and security controls, as the it only recommends the solutions that are suitable for mitigatingthreats, thus reducing excessive usage of non-needed controls, which eventually saves computing resources (e.g., CPU cycles, latency, bandwidth, etc.). By prioritizing threats, the proposed invention helps to improve the tradeoff between security and computing costs, hence contributing to a more sustainable and secure RAN.

[0064] The solution provides a score as an output of the threat modelling process which quantifies the potential threats that can occur in the system, which helps to improve the observability of threats and their quantification for prioritization. It also reduces alarm fatigue, improving accuracy.

[0065] The metrics quantified in this invention can be utilized as possible security requirements in the network, thus enabling leveraging automated management frameworks such as intent-based management, to simplify security management and allow for more automation.

[0066] The solution, if used as an rApp, would enable the prompt identification of threats in a multi-vendor environment, strengthening operational security in Open RAN deployments. By providing automated runtime threat modelling, other vendors may want to purchase the solution as a third-party rApp.

[0067] Figure 1 illustrates a schematic diagram of a runtime threat model according to an embodiment of present disclosure. It describes a solution to automate threat modelling during the runtime (i.e., operations) phase by taking an 0-RAN system 100 as an example. The solution continuously evaluates the effect of changes in the environment (e.g., configuration, topology, new devices connected to the network), evaluates the existing security control related mitigation techniques, recommends new or existing security controls if necessary, and evaluates the impact of the changes on the threat level during the operations (i.e., runtime).

[0068] The present disclosure uses the concept of model-driven security engineering to apply the threat modelling process. In principle in model-driven development, systems are specified using graphical modeling languages (e.g., Unified Modeling Language (UML), Web Ontology Language (OWL), Resource Description Framework (RDF)) and system artifacts such as code and configuration data are automatically generated from the models. Model- driven security is heavily used to ensure secure design, where design along with security requirements is provided into an automated code, and secure infrastructure is the output of the models.

[0069] Further, the present disclosure uses the paradigm differently to provide as input to the models for the system, the threats and controls, and the automated code that analyzesthreats. It provides as an output recommendation of the security requirements that should be in the infrastructure or the system, where requirements are in the form of the proposed mitigation controls. The embodiments are extended the concept to ensure continuous and secure systems during runtime in a continuous loop by automating the threat modelling in runtime.

[0070] In order to apply threat modelling with code and automate the process of analysis, this solution relies on one form of Artificial intelligence technology which is machine reasoning (i.e., logical rule-based inference), also referred to as automating reasoning. Automating reasoning uses declarative programming languages, one possible example is Programming in Logic (Prolog) which is a logic programming language used for the purpose of automated reasoning. Automated reasoning-based solutions have a main set of components that are used to implement the logic and run inference, these components comprise: a knowledge base 120, a reasoning engine 130, and a set of agents 140, 150, 160. Those agents may comprise a Data Collector agent 140, a Measurement agent 150, and a Recommendation agent 160. It is important to highlight that the proposed solution can also benefit from close loop, CL, actuation and / or human in the loop, HITL, actuation, so that the output / recommendations on security controls can be provided to managed resource 170 for further improvement.

[0071] The knowledge base 120 comprises different facts about the domain or the problem to be solved in a structured way. It is defined using an ontology representation and classifies knowledge in a formal, semantic framework. The ontology defines relationships between security concepts, such as vulnerabilities, threats, mitigation techniques, assets, and attack patterns.

[0072] The reasoning engine 130 uses the knowledge base 120, a set of rules, and received events to automatically infer conclusions on potential threats and therefore recommend actions based on formalized security knowledge. The engine 130 leverages the ontology to understand the structure of cybersecurity concepts and their relationships while applying a set of predefined rules (e.g., "if-then" logic (decision tree), policy constraints, or compliance requirements).

[0073] The reasoning engine 130 is responsible for running the inference rules using a machine reasoning technique and providing the output that is related to:- Proving if an asset is under potential threat or not,- Recommending and / or updating mitigation controls or the security control related parameters.

[0074] The agents 140, 150 and 160 are responsible for achieving the automation loop. Data Collection Agent 140 is responsible for events subscription and transferring the processed data to the knowledge base 120. Events are collected mainly from platforms and infrastructure including RAN applications and other parts of the network (e.g., core network). Measurement Agent 150 is responsible for measuring and calculating scores for the security control effectiveness metric, which is an input to calculating the overall threat level score. Recommendation Agent 160 is responsible for providing recommendations on the security control configurations that should be updated in order to reduce the threat level.

[0075] Moreover, a security management tool 110 is included as part of the solution as it has the responsibility of interfacing the output from the reasoning engine 130 and agents 140, 150 and 160 to a human operator. Also, updating new rules and models can be done manually or automatically via the security management tool 110. Additionally, enriching the knowledge base 120 with information about new threats using threat intelligence can be done automatically via the security management tool 110.

[0076] Figure 2 illustrates a workflow of a runtime threat model according to an embodiment of present disclosure. As shown in Figure 2, following the model-driven methodology, the threat modelling process in the solution takes as input several graphical models. Examples of the models could be those that represent the system or network function that will be evaluated (e.g., O-CU), and other set of models that represent the attack surfaces of the system, the threat vectors, and security controls. The models can either be manually updated or automatically generated from a higher layer (e.g., Graphical user interface, security requirements, etc.). It uses semantic model language, one example of a language used for modelling is the RDF.

[0077] Figure 3 illustrates interactions between components in a runtime threat model according to an embodiment of present disclosure. As illustrated in Figure 3, all agents 140, 150 and 160 push their output data as an RDF format towards the knowledge base 120 in order to update the facts and graphs in the knowledge base 120 with relevant data coming from the run-time. Dashed gray lines represent the logical interaction between agents. The knowledge base 120 is responsible for storing the graphs and models that are relevant for the usage, for example, models that represent the events to be triggered, including the attack surface models, the security controls models, and the threat vector models. The knowledge base 120 not only holds the facts that are generated by the agents or modeled by a domain expert, but also manages the relationships between the models. The knowledge base 120 also updates itselfcontinuously and represents the “source of truth”. One example could be the relationship between a triggered event (e.g., new UE connected to a cell, incomplete RRC procedure) and an attack surface (e.g., radio attack surface). Moreover, other relationships comprise the relationships between the attack surface, the threat vectors (e.g., RRC signaling storm), and the possible controls to be applied (e.g., admission control). The knowledge base 120 is updated on regular basics, either by a domain expert or internal / external threat intelligence data.

[0078] Figure 4 shows a flowchart according to an embodiment of present disclosure. It shows an example of a full closed automation loop where the network function itself is automating the phases of monitoring, analyzing, measuring, recommending and actuating on the recommendations. It may also rely on a human-in-the-loop concept, for the actuation of the proposed mitigation techniques. The human operator (e.g., expert, practitioner) receives the recommendations from the agents and provides the required actuation. As clarified above, it is important to highlight that the proposed solution can benefit from an Actuation Agent.

[0079] According to the embodiment, in response to an event is triggered in 401, the attack surface associated with the event is identified in 402, and the attack surface exposure is measured in 403. Then the threat vectors associated with the attack surface are identified in 404, and threat vector impact is measured in 405. Further, the security controls associated with the threat vectors are identified in 406, and the corresponding security control effectiveness are measured in 407. Based on those inputs, a threat level score is provided in 408. In response to the security control is effective in 409, there is no recommendation is provided in 410. In response to the security control is not effective in 409, further security controls are recommended in 411. Based on the inputs from 411, an actuation is performed in 412, and events are continuously monitored in 413.

[0080] In normal security practice during the development and design phases of an architecture or a feature, the process of threat modelling takes place. Threat Modeling is a form of risk assessment that models aspects of the attack and defense of a particular logical entity, such as a piece of data, an application, a host, a system, or an environment. The main output from the threat modelling process is to be able to identify the possible entry points that an attacker can utilize to compromise the system, what impact or what sort of threat that can be performed by a threat actor (e.g., Spoofing, Integrity violation, Privilege escalation, etc.) and recommend the possible controls and mitigation techniques that should be in place to prevent or reduce the threat. This process is normally done manually with assumptions drawn by the solution developers on what are the possible entry points.

[0081] Although there has been advancement in the literature on automating the process of design time threat modelling, it is still static in nature. Current threat modelling doesn’t take into context the possible scenarios and changes of the system and environment that can occur during runtime and what are the impact or changes on the types of threats that can be potential or what changes should be available to mitigate those arising threats. Thus, the main issue with current practice is that it has been built on static assumptions that follow the design of the feature or the system and doesn’t enrich that with the context of a changing environment, that is the runtime causality on the threat landscape. The solution aims to address this gap, so threat modelling actually reflects the current operator's configuration, in order to adequately assess their threat exposure.

[0082] According to some embodiments, a threat model consists collectively of Attack Models, and the Security controls attempting to disrupt those attack models on a given target. Where an attack model compromises one or more attack / threat vectors (techniques). All the attack vectors relate to the attack surface that is being threatened by an attacker.

[0083] Figure 5 illustrates relationships in a runtime threat model according to an embodiment of present disclosure. Figure 5 represents a directed acyclic graph of the threat modelling approach. It shows the attack vectors 531, 532 and 533, also referred to as the threat vectors, denoted as (AV) in the graph constitute a part of the attack surface 510, the attack vectors denote the techniques that could be utilized by an attacker in a given attack surface. Moreover, security controls 520 in place or implemented in the target or system being evaluated have the objective of reducing the attack surface by mitigating the threat vectors. Eventually, the threat model 500 is an illustration of the relationship of how the existing security controls are effectively reducing the attack surfaces 510 present in one system.

[0084] As a result, the embodiments leveraged the identification and analysis of relationships between attack surface 510, attack vectors 531-533, and security controls 520 to reduce the threat exposure of a system, illustrated in a threat model that is continuously updated. Those relationships are further illustrated in Figure 6, which shows an example of a runtime threat model generation according to an embodiment of present disclosure.

[0085] As illustrated in Figure 6, the triggered event can be utilized as an input, and the attack surface associated with the event, the threat vectors associated with the attack surface, and the mitigation / security controls associated with the threat vectors are further identified / analyzed to generate a threat model automatically as an output.

[0086] To automate the threat modelling process, the model-driven concept was used. In model-driven development, system designs are specified using graphical modeling languages like UML and system artifacts such as code and configuration data are automatically generated from the models. Model-driven security is a specialization of this paradigm, where system designs are modeled together with their security requirements and security infrastructures are directly generated from the models. Over the past decade, researchers have explored different facets of model-driven security. This research includes different modeling languages, code generators, model analysis tools, and even model transformations. For example, in multi-tier systems, researchers use model transformations to transform a security policy, formulated for a system’s data model, to a security policy governing the behavior of the system’s graphical user interface.

[0087] Model-driven security is a specialization of model-driven development, also called model-driven architecture, in the security domain. Models use different semantic languages to illustrate relationships between different entities of a system. Models can be used for the development of secure systems in several ways. In present disclosure, several models are used to automate threat modelling at runtime.

[0088] Figure 7 shows a concept of model-driven security. A fundamental building block of the threat modelling approach envisioned in present disclosure is using modelling techniques, specifically graphical modelling. Embodiments herein used the concept of ontologies to describe graphically the problem in hand that the solution is trying to solve and to model the relationships between the different concepts in the domain of threat modelling. There are several semantic languages that can be used to model ontologies, the embodiments described herein leverage RDF for modelling, as it is machine-readable and can be fed into the automated reasoning engine is widely used, and has extensive community support. RDF provides ways to instantiate directed labeled graphs. A logical way to view the results of parsing such data is that it produces a data structure with a series of statements, each with a predicate, subject, and object that can be formally represented as a tuple S, P, O). This data structure, henceforth called a graph, provides utility to applications when they have a mechanism for retrieving specific pieces of data and acting upon it.

[0089] The threat modelling according to some embodiments described herein, requires different concepts to be described and modelled, below are examples of the models that can be used.

[0090] Events Model: This is a model that describes the different changes or events in a system or a network that can be monitored and is expected to be an indicator for potential threats, and can be used to trigger the threat modelling process.

[0091] System Model: This is a model that is responsible for describing and representing the network functions (e.g., O-CU, O-DU) that are under evaluation, it represents its different components, interfaces, and functionalities. It is essential to have a system model in order to identify the threats.

[0092] Attack Surface Model: This is a model that is responsible for describing the different entry points, the channels used for transmitting or receiving a data, and the data, (including for example types of the data) that constitutes an attack surface on an evaluated system.

[0093] Threat Vector Model: This model describes the threat vectors that are linked eventually to an attack surface. The threat vector follows the principles of describing techniques, and procedures of an attacker that are used to compromise an attack surface. Techniques describe how an attacker achieves their objectives or goal by performing an action, for example, an attacker may perform an RRC signaling storm to achieve the goal of a gNB or O-CU resource exhaustion. Moreover, the procedure describes the detailed action and data being used to perform the technique, for example, an attacker uses EmergencyCalls(EM) or HighPriority Access (HP A) as an RRC request establishment cause to ensure acquiring high priority than other UEs and this will exhaust the resources rapidly.

[0094] Mitigation Controls Model: This model provides a description of the security controls that can be possibly available in a system or the asset under evaluation. Additionally, provides a description of the possible configuration that can be eventually updated as part of the automated actuation process or part of the recommendation process of new controls. Examples of controls can be Radio Admission controls, firewalls, IPsec, Radio encryption, etc.

[0095] Figure 8 illustrates an example of a runtime threat model applied in 0-RAN, according to an embodiment of present disclosure. As illustrated in Figure 8, it includes a O- DU / O-CU system model 810, radio attack surface model 820, radio threat vector model 830, and radio control model 840 and radio event model 850. The main model is an asset which describes the different components and functionalities of the 0-RAN network functions (e.g., O-DU, O-CU System Model 810). The models have certain dependencies and relationships with each other. For example, the Radio Events model 850 is coupled with the System model 810 that defines the different components and which component can produce which type ofevent. An example could be that the Radio Function in the system model produces counters for RRC's failed established procedure, which in turn defines one of Radio events that triggers the process of radio attack surface identification.

[0096] Consequently, the attack surface model 820 is dependent on the radio events model 850 which in turn will trigger the analysis of the attack surface model 820 to identify the relevant attack surfaces to be evaluated further for threats. Moreover, it is illustrated that the threat vector model 830 depends on the attack surface model 820, as the threat vector identification is the next step after identifying the relevant attack surfaces. Then eventually, the radio control model 840 are dependent on understanding the threat vectors of interest, because the analysis of the suitable controls takes place further, with the reasoning engine 130 to identify security controls. The dependency and chaining of the models and understanding the relationship is essential because then that will be input for the logical inference rules, which will be responsible for deducing new facts and reaching conclusions on whether there is a threat or not, and answering the graph queries initiated by the different agents in the solution.

[0097] Hereafter, different models will be described in detail in accordance with some embodiments of present disclosure.

[0098] System Model: The system model describes the asset under evaluation for threats and their different components, and functionalities. The model goes to a more granular level to capture the protocols used on the interface, their procedures, etc. This granularity captures accurately the threat vectors and eventually recommends suitable granular controls.

[0099] Figures 9 and 10 illustrate examples of system model according to some embodiments of present disclosure. An asset can be described by the functionality that it provides, for example, Radio function, synchronization function, transport function, management function, etc. Additionally, a system can be described with the type of interfaces it has. Some examples of the radio interfaces can be Xn, Radio Uu interface, the backhaul N2 and N3 interfaces, etc. Moreover, those interfaces can be further described with detail on the types of protocols and protocol stacks they leverage. For example, protocols can be RRC for the radio interface, and control plane and user plane for protocol stacks. Moreover, it describes if there are subscriber identifiers that are being used as part of the protocol. Additionally, it also describes what possible attack surface or at least entry point it can have. The model has properties (i.e., predicates) that can be used to find a relationship between the system model and the attack surface model, which will be explained later. A possible graphical model for the system and the relationships, is illustrated in Figures 9 and 10.

[0100] Events Model: The events model describes the events that are under observation and monitoring by the data collection agent 140. The events are described by which component or function produced the events(e.g., radio function, the type of an event (e.g., configuration change, topology change, traffic pattern change, etc.), the data source of events (e.g, Performance Management, PM, counter, PM event, Configuration Management, CM, data). Moreover, there could be additional contextual information needed that is related to the events and acquired from different domains of the network. For example, if an event is triggered because a new loT device of type Narrowband loT, NB-IoT, is connected to the cell if additional information that is required from the core network or a local repository in the network acquires the International Mobile Equipment Identity - Software Version Number (IMEI-SV) information to gain more insights if this NB-IoT has been performing software updates or not (as a device that does not perform an OS update is more likely to be compromised) hence is a possible risk to the network. Thus, this type of required information is also useful to describe the event.

[0101] Figures 11 and 12 illustrate examples of event model according to some embodiments of present disclosure. Figure 12 illustrates a model of the events for an example of traffic pattern change. The change or event is related to a possible increase in the number of incomplete RRC setup procedures and an increase in the number of RRC setup requests. As shown in the figure 12, this event is described that it is “producedby” the radio function in the O-CU-CP which is the Producer. It’s EventType is traffic change. The DataType of this event is PM counters related to the RRC procedure. In this type of event, there is no additional information required. A conclusion that can be deduced from this graph eventually, is that this event is related to the radio attack surface, since the event is triggered from the radio function component on the O-RAN Centralized Unit Control Plane (O-CU-CP). The reasoning engine 130 will then initiate the search process in the radio attack surface related graph.

[0102] Attack Surface Model: As described earlier, an attack surface is a composite definition that is formed of several metrics, including one for identifying the entry points an attacker can use, the channels used to transmit data, and what type of data can be used. Attack surface can formally be modelled as below:AS := {E, C, D)

[0103] Where AS is the attack surface, which is defined by the tuple of entrypoint (E), channel (C), and data (D).

[0104] To further visualize the concept of attack surface, we can take Figure 13 as an example. Figure 13 shows a radio attack surface according to an embodiment of present disclosure, where it has an example of two Attack surface profiles.Attack surface profile 1 :Entrypoint: 3 GPP Radio Uu InterfaceChannel: Control PlaneData: MAC Buffer status reportAttack surface profile 2:Entrypoint: 3 GPP Radio Uu Interface Channel: User plane Data: PDCP

[0105] It can be understood that one attack surface might have several constellations which is conditioned by the amount of channels and data that can be used to threaten a system.

[0106] The concept of attack surface can then be graphically modelled as shown in Figure 14, which shows an example of attack surface model according to an embodiment of present disclosure. It shows that an Attack Surface can have an Attack Surface Profile which is a list of the possible Entry Points, Channels and Data. Additionally, the ontology defines also the relationship between the attack surface components.

[0107] An example of possible facts that can be modelled using the attack surface ontology, can be described as follows:(O-CU-CP, has AttackSurface, 3GPP_Radio),(3GPP_Radio, hasEntryPoint, Uu Interface)(UU interface, hasAttackChannel, ControlPlane),(ControlPlane, hasAttackData, MAC BSR),(3GPP_Radio, hasAttackSurfaceProfile, [Uu, ControlPlane, MAC BSR] ).

[0108] Threat Vector Model: In order to provide an accurate and comprehensive modeling, we used the GSMA Mobile Threat Intelligence Framework (MoTIF) as a threat library input to systematically model attacks, threats, and their Tactics, Techniques and Procedure (TTPs). We modeled TTPs in RAN, specifically on the radio interface as an example to illustrate the workings of the invention, however other vectors related to the other attack surfaces and their threat vectors can be modelled the same way, examples of other attack surfaces can be: 3GPP network attack surface, Operations and Maintenance (O&M) attack surface, platform attack surface. A key aspect of this modeling is capturing the characteristics of possible attacks, suchas the methods used for initial access, persistence, privilege escalation, and data exfiltration. These characteristics are crucial for determining how security controls should be configured to defend against specific threats.

[0109] Threat vectors represent the techniques used by an attacker as part of an attack mode, to attempt to compromise an attack surface. Modeling graphs of threat libraries need to include the below examples of knowledge:Attacker techniqueAttacker sub-technique (if available)The procedure used (e.g, fake buffer status report, BSR, RRC signalling storm)- Possible impact (e.g, -50% control channel element, CCEs, -40% physical resource block, PRBs)- Used on which interface (for example, new radio, NR, Uu Radio, N3 interface, etc.)

[0110] Figure 15 represents the general graph or the ontology of a possible threat vector according to an embodiment of present disclosure, which describes the different actions an attacker can take and where it can be possibly used. In logical terms, relationships are called predicates (e.g., haslmpact) and they define the edge of the graphs, where the concept itself is a node in the graph (e.g., Procedure). The predicates are responsible for connecting nodes to define interactions or relationships between the different nodes. An example that can be seen of these relationships can be seen below:(Technique, appliedOn, Use),(Technique, hasSubTechnique, Sub-Technigue),(Sub -Technique, implements, Procedure).

[0111] Figure 16 shows a practical example of the ontology shown in Figure 15. It shows an example of possible modelling of a radio threat vector and its relationships, this example uses the MAC protocol fake BSR. The threat vector can be described as below, where the attacker is capable of compromising an attack surface:(Attack Surface, attackedBy , Exploit via Radio),(Exploit via Radio, appliedOn, NR Uu),(Exploit via Radio, hasSubTechnique, Exploit Control Plane Protocols),(Exploit Control Plane Protocols, implements, MAC Fake BSR),(MAC Fake BSR, haslmpact, -30% Prbs)

[0112] It can be understood then that an attacker used Exploit via Radio as his main technique, where this technique is used or applied on the NR Uu interface (i.e., radio interface).This technique also has several sub-actions each having different characteristics, one possible sub-technique is an action related to Exploit Control Plane Protocols, which in turn is implemented by leveraging a specific procedure which is sending MAC fake buffer status reports (BSR). If this type of threat vector would occur, then there is a possible impact on the utilization of physical resource blocks on the radio interface to be reduce by 30%.

[0113] Modelling relationships: As illustrated previously in Figure 8, it showed a high level of understanding of the dependency of the models on each other. The example of formalized relationships is illustrated in Figure 17. Figure 17 shows an acyclic-directed graph that defines the relationships and interactions between the different models according to some embodiment of present disclosure. The predicates (i.e., relationships, or sometimes called properties) are defined so as to identify how the different parts of the model work to provide the overall threat model, to further implement the inference rules.

[0114] As shown in the Figure 17, an instance of the Asset uses the predicate hasAttackSurface to define what type of attack surfaces it can refer to in the AttackSurface model, where the AttackSurface is triggered or “analyzedBy” the Events that are “producedBy” the Asset. Moreover, the AttackSurface has a relationship with the Threat Vector model that is defined using the predicate “attackedBy”, which defines which threat vectors are used to attack the attack surfaces of a system. Eventually, the Threat Vector is “mitigatedBy” security controls that are available where they have a relationship with the Asset as the Security Control “protects” the Asset.

[0115] Logical reasoning is a process where a system uses formal logic and predefined rules to infer conclusions, uncover patterns, and identify relationships between different data points. In the context of present disclosure, logical reasoning is leveraged to identify potential threats triggered by events and apply predicate rules that define specific conditions for threats. These rules take the form of logical statements, such as "if certain behaviors or indicators are observed, then a potential threat exists." The system can automatically scan through large events, apply these rules, and identify patterns that match known attack vectors or suspicious activity defined in the knowledge base. By applying logical reasoning, it is possible not only to identify potential threats but also to infer potential, previously unseen risks by considering how different factors impact the system in run-time.

[0116] This embodiment uses predicate logic as one example to represent the inference rules in human-readable mathematical semantics. One example of possible logic used in the invented system can be the following:VA3Z3T: hasAttackSurface(A, Z) A triggeredBy(Z, E) A attackedBy(Z, V) A mitigatedBy(V, C) A hasControl(A, C)

[0117] This example rule illustrates a conjunction of conditions to evaluate or infer if there is a potential threat to an asset. For the whole components of an asset under evaluation, there are some attack surfaces that are under threat. To evaluate this conclusion or to infer the knowledge, the reasoning engine 130 will search for the facts that satisfy the right-hand side of the rule, looking for the attacker surfaces (Z) on the assets (A), there had some event (E) that is related to the attack surface. Additionally, understanding if the attack surface has threat vectors (V) that are known in the threat vectors graph. Additionally, if the controls (C) required to mitigate the threat are available as part of the asset then we can conclude that the potential threat can be mitigated and the risk is low.

[0118] The above rule can be extended to include further conditions or goals, for example, it can be added that the security controls that have a security control effectiveness metric below 60% (0.6) are considered to be poorly configured and will not be able to prevent the threat when it occurs, and example can be shown below:VA3Z3T: hasAttackSurface(A, Z) A triggeredBy(Z, E) A attackedBy(Z, V) A mitigatedBy(V, C) A hasControl(A, C) A hasScore(SC, le(0.6))

[0119] The additional part in the rule states that as a condition in conjunction with other conditions, if the security control effectiveness metric (SC) is less than (le) the value 0.6, then this provides more intuition that there is a probable threat. With this example, it shows the strength of including the security controls in the inference and threat modelling process, because it provides more accurate situational awareness that does not provide a false sense of security (i.e., whether the system is secure or not secured).

[0120] Figures 18a and b shows a signaling diagram involving human in the loop actuation according to an embodiment of present disclosure. In this embodiment, the O-CU-CP is used as an example for the asset. The data collecting agent 140 collects one or more events occurred that are associated with CU-CP 170, in step 1. Then in step 2, data collecting agent 140 updates the knowledge base 120 based on the occurred events, for example, the event related information. In step 3, the reasoning engine 130 infers identification of attack surface to the knowledge base 120, based on the event related information. In step 3.1, the knowledge base 120 updates the attack surface graph and in step 3.2 the reasoning engine 130 invokes the measurement agent 150 to measure the attack surface exposure ASE.

[0121] The measurement agent 150, upon measuring the attack surface exposure, updates the attack surface graph in the knowledge base 120. In step 4, the reasoning engine 130 infersidentification of the threat vectors to the knowledge base 120, based on the attack surface related information. In step 4.1, the knowledge base 120 updates the threat vector graph and in step 4.2 the reasoning engine 130 invokes the measurement agent 150 to measure the threat vector impact TVi. The measurement agent 150, upon measuring the threat vector impact, updates the threat vector impact graph in the knowledge base 120.

[0122] In step 5, the reasoning engine 130 infers identification of the security controls to knowledge base 120. In step 5.1, the knowledge base 120 updates the security control graph and in step 5.2 the reasoning engine 130 invokes the measurement agent 150 to measure the security control effectiveness SCEFF. The measurement agent 150, upon measuring the security control effectiveness, updates the security control effectiveness graph in the knowledge base 120. In step 6, the reasoning engine 130 evaluates / analyzes the security control effectiveness state and if the security control effectiveness is smaller than a Threshold, in step 6.1 the reasoning engine 130 invokes the recommendation agent 160 and provides security control related recommendations. In step 6.2, The recommendation agent 160 analyzes the received information in step 6.1 and in step 6.3 instruct the knowledge base 120 to update the security control graph. In step 6.4, the reasoning engine 130 evaluates / analyzes the security control effectiveness and in step 6.5, the reasoning engine 130 provide the security control related recommendations to a human operator 180. In step 6.6, the human operator 180 provides the actuation configurations to the CU-CP 170. In another embodiment, in alternative step 6, the reasoning engine 130 evaluates / analyzes the security control effectiveness state and if the security control effectiveness is equal or larger than the Threshold, the reasoning engine 130 provides an indication to the human operator 180 that no updates or no recommendations for further actions / controls in alternative step 6.1.

[0123] Figures 19a and b shows a signaling diagram involving close loop actuation according to an embodiment of present disclosure. Most procedures in Figures 19a and b are identical to those in Figures 18a and b. The difference in comparing with Figures 18a and b, is in step 6.6 of Figures 19a and b, the reasoning engine 130, instead of the human operator 180, provides the actuation configuration to the CU-CP 170. Another difference is in alternative step 6.1 of Figures 19a and b, the reasoning engine 130 provides an indication to knowledge base 120, instead of the human operator 180, that no updates or no recommendations for further actions / controls.

[0124] The runtime threat model enables immediate analysis of threats once the event is triggered. An event might be any change in the environment, such as a new User Equipment(UE) connected to a cell, a new configuration, a change in the traffic behavior, etc. Depending on the architectural considerations, events can be collected from RAN applications and probably other parts of the network (e.g., core network, cloud network), as well as the platform and infrastructure.

[0125] According to an embodiment, once an event is triggered, the data collector agent 140 captures event related information and updates the knowledge base 120. The measurement agent 150 is then triggered and uses inference rules to calculate different metrics such as the attack surface exposure, threat vector impact, and security control effectiveness. The knowledge base 120 will also be updated with the new metrics. The reasoning engine 130 also uses inference rules to provide a recommendation and threat level score to the recommendation agent 160. It is important to highlight that at each step of identification / analyzation, the knowledge base 120 is updated with new facts that form updated graphs, which will be used by the measurement agent 150 to calculate the different metrics and produce an overall threat level score.

[0126] The agents 140, 150 and 160 communicate together through the knowledge base 120. That means that upon any of the agent has an output, this output is streamed to the knowledge base 120 where the graphs are updated. Another agent can then trigger a query to retrieve new information that is required for their functionality. Thus, the agents 140, 150 and 160 communicate together but via pulling and pushing new facts or information to the knowledge base 120.

[0127] Figure 20 shows an example of calculating a threat level score according to an embodiment of present disclosure. Threat level scoring is the process of assessing and assigning a numerical or categorical value to the severity or risk of a potential security threat. The scoring helps in prioritizing responses by quantifying the likelihood and potential impact of a threat and therefore enabling security teams to focus on the most critical threats first. In an embodiment, the threat level scoring is calculated based on attack surface, threat vectors, and migration controls, as illustrated in Figure 20.Attack Surface Exposure (ASExp) analyzing / identifying the attack surfaces based on events to be triggered or triggerd.Threat Vectors Impact (TVImp) analyzing / identifying the threat vectors associated with triggered events.Security Control Effectiveness (SCEff ) identifying / analyzing the security controls, recommending updates to the security controls.

[0128] Therefore, the threat level scoring is calculated as the conditional probability of the threat vectors impact given that the attack surface exposure and security control effectiveness are provided:

[0129] The threat level score is a value between 0 and 1, which can be transformed into a percentage as well. This score does not mean that there is an actual attack occurring in the network but more of a probability that an attack occurs in the system (probability of an attack).

[0130] The threat level scale can be divided into, for example, three ranges that determine the severity of the probability:Score value G [ 0, 0.39]: Low Threat Probability. - Score value G [4, 0.69 ]: Medium Threat ProbabilityScore value G[0.7, 1]: High Threat Probability

[0131] The closer the score value to 1 the more inclination that the asset is more susceptible to threats. In fact, this score provides guidance on the most exposed attack surface that requires further attention as well as guidance on the readiness of the security controls to mitigate the potential attacks.

[0132] Table 1 provides an example of the threat score interpretation along with possible actions and level of automation.

[0133] Table 1

[0134] The threat vector impact (TVimp) is a composite measure that describes the impact of the identified threat vectors of an attack surface, additionally, the effort required by an attacker to utilize the threat vector, where effort is described in the pre-conditions required for the threat vector to be utilized. The impact of an atomic (simplest, well-formed) threat vector can be analyzed from three different perspectives:- Environmental conditions required to utilize the threat vector, determine the effort required by an attacker (does require special procedures, authentication, etc.).- Execution of the threat vector atomically or requirement of chaining multiple threat vectors to achieve an impact.- Direct and propagate potential damage caused by leveraging the threat vector.

[0135] Finally, the order of magnitude determines the vast impact if a set of resources uses the threat vector (e.g., if the potential attacking UEs used the same threat vector). The threat vector impact is then calculated as:

[0136] where D represents the damage potential that can occur either directly or indirectly due to impact propagation, C represents the environmental conditions and threat vector chaining conditions, and OMRrepresents the radio order of magnitude.

[0137] The damage potential D can be represented by the dot product of the ratio of the sum of direct impact (damage) (£)d) and the ratio of propagated impact (damage) (£)p), over the total number of impacts that is related to the threat vector (Dr), and presented as:

[0138] The conditions (C) can be represented by the dot product of the ratio of the sum of environmental conditions (Ce), and the threat vector preconditionsover the total number of conditions that are related to the threat vector (Cr).

[0139] Figure 21 shows an example of an attack surface according to an embodiment of present disclosure. Figure 22 illustrates an example of a threat vector according to an embodiment of present disclosure.

[0140] Security control effectiveness (SCE^ ) is a measure of the appropriate security controls and mitigation mechanisms configured and to what extent are they correctly configured to ensure effective mitigation of a threat. The metric then can be calculated as the output of following dot product. ^Eff ^cv ' ^cr

[0141] Where Ccvis a vector represents the security control coverage which determines if the necessary controls to mitigate a potential threat exists (e.g., a RRC admission control is configured, Radio bearers rate limiting, etc.). Moreover, Ccris a vector that represents the quantification of the correctness of the implementation of the configured security controls and how adequately the implemented controls can mitigate the possible threats.

[0142] Input to the calculation of CCris dependent on the security control under evaluation, since each control may have requirements to ensure its correcteness and effectiveness. In this embodiment, mechanisms that are used for radio overload protection are used as an example and evaluate it to understand its effectiveness under a security threat.

[0143] Figure 23 illustrates a use case according to an embodiment of present disclosure. The use case is Modelling Potential RRC Signaling Storm Threat. In this use case, a concrete example on how the runtime threat model will react and how the previous concepts can be applied, are provided. The use case is to analyze potential RRC signaling storm threats that can occur in the radio network due to an excessive amount of RRC Connection Setup requests (MSG3). Typically, a characteristic of an attack or a possible threat would be that a malicious UE is sending high consecutive rates of MSG3 within a short time between each message, and not completing the full RRC procedure. Additionally, the steps explained herein will refer to the steps in the flowchart illustrated in Figure 4.

[0144] For this use case, the intended changes that the data collector agent 140 is monitoring, are of type “traffic pattern changes”, which means that a certain traffic behavior has changed unexpectedly. This could be done using analysis of historical data, or a pre-defined threshold where changes get triggered, or simply can be the analysis of the relevant PM counter or event during a duration of time.

[0145] Additionally, the reasoning engine 130 is equipped with three examples of inference rules categories. The first set of rules is related to the analysis and deduction ofthreats, and the second set of rules is used to invoke the relevant agent in the flow to work if there are some specific facts are being updated in the knowledge base. The third set of rules is used to deduce the possible security controls that can be used.

[0146] The third set of rules is related to inferring the possible available security controls that can be used to mitigate the possible threats if the controls are not already implemented in the system under evaluation. On the other hand, if the control is already implemented, then the rules will try to infer the possible set of configurations and values to be applied to enhance the readiness of the system towards potential threats. One example of presenting the rules in predicate logic can be:SC SN, M(0.7): hasControl(A, C) A hasScore(C, eq(0.7)

[0147] The previous logic determines that for some controls there are few configurations that achieve the purpose of having a metric (M) equal to efficiency of 0.7 is true. The logic can be achieved by one example, that the Asset has a control C implemented with certain configuration N and that this configuration should maintain a security control efficiency score of 0.7. Thus, the reasoning engine 130 will have to go to different previous values stored in the graph and try to infer the configuration values that ensures a control effectiveness of 0.7 or 70% for correctly and effectively configured control.

[0148] The data collector agent 140 collects PM events and probably PM counters from the O-CU-CP, this is depicted in 401 of Figure 4. For example, the data collector agent 140 is collecting PM counters or events and analyzing the failed RRC attempts and the changes in the number of RRC requests in a duration of time. The data collector agent 140 is responsible for processing the data to extract the useful information, in this case understanding how many failed or incomplete RRC request attempts in a duration of time period (t). An increase in the number of incomplete RRC procedures or the increase of RRC messages doesn’t mean per se an attack is occurring, rather the solution is using this information to analyze eventually what could go wrong because of the traffic behavior change and provide suitable controls for the O- CU-CP to be proactively ready if an attack would occur. The data collector agent 140 then processes the metrics and push the analyzed metrics to the knowledge base 120 using an RDF rule. The agents 140, 150 and 160 in general can communicate with the knowledge base 120 over Representational State Transfer Application Programing Interface (REST APIs), thus those agents can easily update the knowledge base 120 with new facts it gains after completing its functionality. An example of information of the data collector agent 140 that it can push to the knowledge base 120 can be seen below:{event: RrcIncompleteProcedure, producer: radioRRC, values: [IncompleteProcedures: 500. RrcCount: 1200]}

[0149] Since communication between agents 140, 150, 160 and the knowledge base 120 can occur over REST API components as an example, JSON as a serialization format of the data can be used to push and pull queries, rules, and results.

[0150] The reasoning engine 130 uses the first set of rules which is related to analyzing and identifying the attack surface. The purpose of the attack surface identification is to find the attack surface profile that is relevant to the triggered event. This is depicted in 402 of Figure 4. A possible example of a logical rule could be:VP(3E3C3D) : producedBy(E, A) A analysisOf(E, P) hasAttackSurface(A, P) A hasAttackData (P, D) A hasEntryPoint(P, E) A hasAttackChannel(P, C)

[0151] This rule describes a logic where the reasoning engine 130 is trying to identify the attack surface profile, that is a conclusion of the triggered event. The rule describes that if there are set of events E producedBy asset A and the events are used for the analysisOf attack surface profile P, this implies that the asset hasAttackSurface and that the attack surface has the entrypoint E, channel C and utilizes data D. There can be multiple results as an output. In our example, the entry point would be the Uu interface, the channel is the control plane, using the RRC setups request message as the data that could be potentially leveraged by an attacker. Additionally, the specific attributes of the protocol that may be used to conduct the attack, in our example the attribute is the establishmentcause, which can be manipulated by an attacker to be of a high priority request, which would lead to resource depletion.

[0152] In order to invoke an agent to start performing the intended functionality, The reasoning engine 130 uses the second set of rules which is related to invoking the relevant agents. For example, if there is a rule that matches and / or updates the facts that are related to event, shall then trigger a rule to invoke the measurement agent 150 to calculate the exposure metric of the relevant attack surface. This adds a requirement in the knowledge base 120 to include a graph about the known agents being used and their functionality. In this example, it is the radio attack surface, an example of a rule to match a pattern in a graph and trigger the measurement agent 150 can be shown as below, the rule is written in a human-readable predicate logic format:V X SY, Invoke(X): update(G, F)

[0153] This rule can be interpreted as the following, for all agents (X) there are some patterns (Y) if matched then Invoke(X) will be true and the agent will be invoked over the REST API to run its functionality. The conditions are if there is an update of a part of the graph (G) with some new facts (F) this will lead to triggering the corresponding agent that is responsible for the sub-graph that has been updated, for example, if it is the attack surface graph then this triggers the measurement agent 150 to start calculating the attack surface metric exposure and for the reasoner to identify the threat vectors.

[0154] After invoking, the measurement agent 150 then calculates the attack surface impact and sends the score results to the knowledge base 120. This is depicted in 403 of Figure 4 one example of the data output from the measurement agent 150 serialized in JSON is the array that can be shown below: { [ attacksurface: radio metric:attackSurfaceExposure value:0.66]}

[0155] This is now considered a new fact and is updated in the knowledge base 120, which updates the metric graph. The new facts availability triggers the inference rules for search process, then moves to the next step to identify the threat vectors based on the previously identified entry points, channels and data which represent the attack surface profile that is subject to analysis.

[0156] Step 404 of Figure 4, depicts the process of identifying the threat vectors, mainly the procedures that are relevant to leverage the data components of the attack surface in order to compromise the system. An example of a rule to identify the threat vectors can be presented as the following:VV( T P): attackedBy(A, T) A implements(T, P)

[0157] The rule represents the logic that aims at finding the set of techniques and procedures in all of the threat vectors that satisfy the conditions that the technique is used to attack the attack surface identified earlier, and that technique should implement the relevant procedure. The graph is then updated with the radio threat vectors, in this case the information updated can be the below arrays of information:{[ EntryPoint: Uu Channel :ControlPlane Data:RRC ][Technique: ExploitRadioProcedure:HighRrcRateAttributes:HighPriorityEstablishmentCause ]}

[0158] The reasoning engine 130 then invokes the measurement agent 150 to calculate a score for the threat vector impact depicted in 405 of Figure 4. Sequentially, the metrics graph is updated with the threat vector impact score.

[0159] Next step is to identify the suitable security / mitigation controls. In this case one example could be the Admission Control on the radio interface. Then a new score is calculated after checking its configuration attributes and understanding how effective they are. The benchmark of the correctness of the Admission control is to check if its configured to prevent the potential threat characteristics. For example, if the RRC signaling storm has an attack characteristic that an attacker sends a rate of 130 RRC Connection request step messages per second, the control needs to be configured to be able to prevent from such characteristic. The characteristic of the attack is one information that is not yet modelled in the threat vectors graph as well. The modeling of the characteristic helps on setting the requirements of correctness on the controls. The output score then updates the metric graphs. Eventually all scores are an input to calculate the threat level metric.

[0160] The recommendation agent 160 then recommends security control related recommendations, for example, new set of configuration values if the score of the control efficiency is below a requirement that is known, for example, a threshold, or if it can be inferred by the reasoning engine 130 that the current control configuration will not be able to prevent the attack characteristic.

[0161] This solution can be implemented as an rApp in an 0-RAN architecture. Present disclosure provides two examples of architectural and implementation options in such deployments. Those skilled in the art will understand other deployment options are also possible as long as those can achieve same or similar purposes.

[0162] Figure 24 shows one example of the deployment according to an embodiment of present disclosure. Figure 24 shows a deployment option 2400 which represents a possible disaggregation and distribution of the agents between the O-CU-CP network function 2540 and the SMO 2520. In this deployment option, one possible implementation could be that the Data collector agent 140 and the measurement agent 150 are deployed as part of the RAN logical function (e.g., O-CU-CP 2540), possible deployment as a separate pod that is responsible for data collection and observability. A need for this deployment option could be related to the rate of data generated or the granularity of data required that is not aggregated, or it could be thatthe agents may be used for other use cases as well. Then, the recommendation agent 160, knowledge base 120 and the reasoning engine 130 may be implemented as a rApp 2530 in the System Maintenance & Orchestration, SMO, 2520. Since the data are collected and process locally in the system, the solution will rely on the Al interface. The Al interface will be used to update the data collection policies of the data collector agent 140, it can be also used for invoking the agents to initiate their functionalities, it can also be used that the agents push their rules and queries to the knowledge base 120 and / or reasoning engine 130.

[0163] Figure 25 shows another example of deployment 2500 according to some embodiments of present disclosure. As illustrated in Figure 25, another option of the deployment is represented as a centralized deployment of the solution in an rApp 2530, which is part of the SMO 2520. In this deployment, the Al interface will be used to collect the relevant data sources (e.g., configurations, PM data, etc.).

[0164] In both deployment options 2400 and 2500, a security management function 2510 will have the responsibility to update the models, the inference rules, re-deploy the agents if needed. Additionally, it shall receive the recommendations from the recommendation agent 160, in order for a human operator to analyze further and actuate on the systems with the suitable configurations to reduce the threat.

[0165] Figure 26 illustrates a method 2600 according to an embodiment of present disclosure. In an embodiment, the method 2600 is performed by a network function, such as a network function 4000 described below. The network function may be an Open Radio Access Network, 0-RAN, function, a radio function, a cloud function, a synchronization function, a transport function, or a management function. The network function obtains event related information associated with an asset in 2610. The asset may comprise one or more components, and / or one or more functionalities of an Open Radio Access Network, 0-RAN, function, a radio function, a synchronization function, a transport function, or a management function. The event may comprise a change in a configuration, a topology, a network function, a system, a network function environment or a system environment. According to an embodiment, the obtaining 2610 may be performed by the data collecting agent 140 in the network function.

[0166] In 2620, the network function identifies / analyzes attack surface related information associated with the event related information. It may comprise measuring an attack surface exposure, wherein the attack surface related information comprises attack surface exposure. The attack surface related information or the attack surface exposure may be obtained based on at least one of an entry point, a channel, and / or a data. The attack surface exposure refers tothe attack surface exposure as illustrated in conjunction with Figure 20. An entry point refers to the points that the attacker can use to attack the system, a channel refers to the channel that data is transmitted or received, and the data refers to the data that is transmitted or received via the channel.

[0167] In 2630, the network function identifies / analyzes threat vector related information associated with the attack surface related information. It may comprise measuring a threat vector impact, wherein the threat vector related information comprises the threat vector impact. The threat vector related information or the threat vector impact may be obtained based on at least one of: an attacker technique, an attacker sub -technique, an applied procedure, an impact of an attack, or an applied interface. The threat vector impact refers to the threat factor impact as illustrated in conjunction with Figure 20. The attacker technique refers to the techniques that attacker may use to attack the system.

[0168] In 2640, the network function identifies / analyzes security control related information associated with the threat vector related information. It may comprise measuring a security control effectiveness related to the security control, wherein the security control related information comprises the security control effectiveness. The security control effectiveness refers to the security control effectiveness as illustrated in conjunction with Figure 20.

[0169] In an embodiment, the identifying 2620, 2630, 2640 is performed by the measurement agent 150, or the reasoning engine 130. The reasoning engine 130 may use logical reasoning mechanism that incorporates certain inference rules.

[0170] In 2660, the network function then provides an output based on at least one of the attack surface related information, the threat vector related information, or the security control related information. In an example, providing the output may comprise providing one or more security control related recommendations associated with the threat. In another example, providing the output may comprise providing one or more potential threats associated with the asset. In another example, providing the output may comprise providing a score associated with the threat.

[0171] The score of threat level may be obtained based on the attack surface related information, threat vector related information, and the security control related information. The obtained scores may be categorized into at least two categories. In one example, the scores may be categorized into low threat probability and high threat probability. In another example, the scores may be categorized into low threat probability, medium threat probability and highthreat probability as indicated in Table 1. In yet another example, providing the output may comprise providing an indication that no action is recommended. In an embodiment, the providing 2660 is performed by a recommendation agent, or a reasoning engine in the network function.

[0172] The method 2600 may further comprise actuating a resource associated with the asset based on the output, according to a close loop actuation or a human in the loop actuation. The method 2600 may further comprise updating a knowledge base 120, based on at least one of the event related information, the attack surface related information, the threat vector related information, the security control related information, or the output. The method 2600 then may further comprise providing an updated output in accordance with the updated knowledge base 120. The method 2600 may also comprise obtaining additional information from a knowledge base 120. According to an embodiment, the updating may be performed by the data collecting agent 140, the measurement agent 150, or the recommendation agent 160, the reasoning engine 130 in the network function.

[0173] In an embodiment, the providing 2660 may comprise providing the output to a security management function 110, a knowledge base 120, or a reasoning engine 130. The method 2600 may further comprise obtaining a new model or an inference rule from a security management function 110 based on the provided output. In an embodiment, the obtaining 2610, the identifying 2620, 2630, 2640, or the providing 2660 may be performed by applying at least one of the following models: an event model; a system / asset model; an attack surface model; a threat vector model; and / or a security control model. The model is connected to another model through the knowledge base 120 or the reasoning engine 130.

[0174] In an embodiment, the relationship of those models is provided. The event model may be used by the system model, and the attack surface model. The system model may be protected by the security control model, and may provide an attack surface to the attack surface model. The attack surface model may be used by the threat vector model. The threat vector model may be mitigated by the security control model.

[0175] The data collecting agent 140, the measurement agent 150 or the recommendation agent 160 may interact with the knowledge base 120 or the reasoning engine 130. The reasoning engine 130 may invoke one or more instructions to the knowledge base 120, the data collecting agent 140, the measurement agent 150 or the recommendation agent 160, based on the knowledge base 120 and / or one or more sets of rules.

[0176] According to an embodiment, the method 2600 may be performed by a function in Radio Access Network Intelligent Controller Application, or a function in Open Radio Access Network, O-RAN, Centralized Unit Control Plane, O-CU-CP. The network function may comprise one or more of the data collecting agent 140, the measurement agent 150, the recommendation agent 160, the knowledge base 120, or the reasoning engine 130.

[0177] Figure 27 shows an example of a communication system 2700 in accordance with some embodiments.

[0178] In the example, the communication system 2700 includes a telecommunication network 2720 that includes an access network 2750, such as a radio access network (RAN), and a core network 2730, which includes one or more core network nodes 2740. The access network 2750 includes one or more access network nodes, such as access network 2750a and 2750b (one or more of which may be generally referred to as access network 2750a, 2750b), or any other similar 3rdGeneration Partnership Project (3 GPP) access nodes or non-3GPP access points. Moreover, as will be appreciated by those of skill in the art, a network node is not necessarily limited to an implementation in which a radio portion and a baseband portion are supplied and integrated by a single vendor. Thus, it will be understood that network nodes include disaggregated implementations or portions thereof. For example, in some embodiments, the telecommunication network 2720 includes one or more Open-RAN (ORAN) network nodes. An ORAN network node is a node in the telecommunication network 2720 that supports an ORAN specification (e.g., a specification published by the O-RAN Alliance, or any similar organization) and may operate alone or together with other nodes to implement one or more functionalities of any node in the telecommunication network 2720, including one or more access network 2750a, 2750b and / or core network nodes 2740.

[0179] Examples of an ORAN network node include an open radio unit (O-RU), an open distributed unit (O-DU), an open central unit (O-CU), including an O-CU control plane (O- CU-CP) or an O-CU user plane (O-CU-UP), a RAN intelligent controller (near-real time or non-real time) hosting software or software plug-ins, such as a near-real time control application (e.g., xApp) or a non-real time control application (e.g., rApp), or any combination thereof (the adjective “open” designating support of an ORAN specification). The network node may support a specification by, for example, supporting an interface defined by the ORAN specification, such as an Al, Fl, Wl, El, E2, X2, Xn interface, an open fronthaul user plane interface, or an open fronthaul management plane interface. Moreover, an ORAN access node may be a logical node in a physical node. Furthermore, an ORAN network node may beimplemented in a virtualization environment (described further below) in which one or more network functions are virtualized. For example, the virtualization environment may include an O-Cloud computing platform orchestrated by a Service Management and Orchestration Framework via an 0-2 interface defined by the 0-RAN Alliance or comparable technologies. The access network 2750a, 2750b facilitate direct or indirect connection of user equipment (UE), such as by connecting UEs 2760a, 2760b, 2760c, and 2760d (one or more of which may be generally referred to as UEs 2760) to the core network 2730 over one or more wireless connections.

[0180] Example wireless communications over a wireless connection include transmitting and / or receiving wireless signals using electromagnetic waves, radio waves, infrared waves, and / or other types of signals suitable for conveying information without the use of wires, cables, or other material conductors. Moreover, in different embodiments, the communication system 2700 may include any number of wired or wireless networks, network nodes, UEs, and / or any other components or systems that may facilitate or participate in the communication of data and / or signals whether via wired or wireless connections. The communication system 2700 may include and / or interface with any type of communication, telecommunication, data, cellular, radio network, and / or other similar type of system.

[0181] The UEs 2760 may be any of a wide variety of communication devices, including wireless devices arranged, configured, and / or operable to communicate wirelessly with the access network 2750a, 2750b and other communication devices. Similarly, the access network 2750a, 2750b are arranged, capable, configured, and / or operable to communicate directly or indirectly with the UEs 2760 and / or with other network nodes or equipment in the telecommunication network 2720 to enable and / or provide network access, such as wireless network access, and / or to perform other functions, such as administration in the telecommunication network 2720.

[0182] In the depicted example, the core network 2730 connects the access network 2750a, 2750b to one or more host computing systems, such as host 2710. These connections may be direct or indirect via one or more intermediary networks or devices. In other examples, network nodes may be directly coupled to hosts. The core network 2730 includes one more core network nodes (e.g., core network node 2740) that are structured with hardware and software components. Features of these components may be substantially similar to those described with respect to the UEs, network nodes, and / or hosts, such that the descriptions thereof are generally applicable to the corresponding components of the core network node 2740. Example corenetwork nodes include functions of one or more of a Mobile Switching Center (MSC), Mobility Management Entity (MME), Home Subscriber Server (HSS), Access and Mobility Management Function (AMF), Session Management Function (SMF), Authentication Server Function (AUSF), Subscription Identifier De-concealing function (SIDF), Unified Data Management (UDM), Security Edge Protection Proxy (SEPP), Network Exposure Function (NEF), and / or a User Plane Function (UPF).

[0183] The host 2710 may be under the ownership or control of a service provider other than an operator or provider of the access network 2750 and / or the telecommunication network 2720. The host 2710 may host a variety of applications to provide one or more service. Examples of such applications include live and pre-recorded audio / video content, data collection services such as retrieving and compiling data on various ambient conditions detected by a plurality of UEs, analytics functionality, social media, functions for controlling or otherwise interacting with remote devices, functions for an alarm and surveillance center, or any other such function performed by a server.

[0184] As a whole, the communication system 2700 of Figure 27 enables connectivity between the UEs, network nodes, and hosts. In that sense, the communication system may be configured to operate according to predefined rules or procedures, such as specific standards that include, but are not limited to: Global System for Mobile Communications (GSM); Universal Mobile Telecommunications System (UMTS); Long Term Evolution (LTE), and / or other suitable 2G, 3G, 4G, 5G standards, or any applicable future generation standard (e.g., 6G); wireless local area network (WLAN) standards, such as the Institute of Electrical and Electronics Engineers (IEEE) 802.11 standards (WiFi); and / or any other appropriate wireless communication standard, such as the Worldwide Interoperability for Microwave Access (WiMax), Bluetooth, Z-Wave, Near Field Communication (NFC) ZigBee, LiFi, and / or any low-power wide-area network (LPWAN) standards such as LoRa and Sigfox.

[0185] In some examples, the telecommunication network 2720 is a cellular network that implements 3 GPP standardized features. Accordingly, the telecommunications network 2720 may support network slicing to provide different logical networks to different devices that are connected to the telecommunication network 2720. For example, the telecommunications network 2720 may provide Ultra Reliable Low Latency Communication (URLLC) services to some UEs, while providing Enhanced Mobile Broadband (eMBB) services to other UEs, and / or Massive Machine Type Communication (mMTC) / Massive loT services to yet further UEs.

[0186] In some examples, the UEs 2760 are configured to transmit and / or receive information without direct human interaction. For instance, a UE may be designed to transmit information to the access network 2750 on a predetermined schedule, when triggered by an internal or external event, or in response to requests from the access network 2750. Additionally, a UE may be configured for operating in single- or multi-RAT or multi-standard mode. For example, a UE may operate with any one or combination of Wi-Fi, NR (New Radio) and LTE, i.e. being configured for multi-radio dual connectivity (MR-DC), such as E-UTRAN (Evolved-UMTS Terrestrial Radio Access Network) New Radio - Dual Connectivity (EN- DC).

[0187] In the example, the hub 2770 communicates with the access network 2750 to facilitate indirect communication between one or more UEs (e.g., UE 2760c and / or 2760d) and network nodes (e.g., network node 2750). In some examples, the hub 2770 may be a controller, router, content source and analytics, or any of the other communication devices described herein regarding UEs. For example, the hub 2770 may be a broadband router enabling access to the core network 2730 for the UEs. As another example, the hub 2770 may be a controller that sends commands or instructions to one or more actuators in the UEs. Commands or instructions may be received from the UEs, access network 2750a, 2750b, or by executable code, script, process, or other instructions in the hub 2770. As another example, the hub 2770 may be a data collector that acts as temporary storage for UE data and, in some embodiments, may perform analysis or other processing of the data. As another example, the hub 2770 may be a content source. For example, for a UE that is a VR device, display, loudspeaker, or other media delivery device, the hub 2770 may retrieve VR assets, video, audio, or other media or data related to sensory information via a network node, which the hub 2770then provides to the UE either directly, after performing local processing, and / or after adding additional local content. In still another example, the hub 2770 acts as a proxy server or orchestrator for the UEs, in particular if one or more of the UEs are low energy loT devices.

[0188] The hub 2770may have a constant / persistent or intermittent connection to the network node 2750b. The hub 2770 may also allow for a different communication scheme and / or schedule between the hub 2770and UEs (e.g., UE 2760c and / or 2760d), and between the hub 2770 and the core network 2730. In other examples, the hub 2770 is connected to the core network 2730 and / or one or more UEs via a wired connection. Moreover, the hub 2770 may be configured to connect to an M2M service provider over the access network 2750 and / or to another UE over a direct connection. In some scenarios, UEs may establish a wirelessconnection with the access network 2750a, 2750b while still connected via the hub 2770 via a wired or wireless connection. In some embodiments, the hub 2770 may be a dedicated hub - that is, a hub whose primary function is to route communications to / from the UEs from / to the network node 2750b. In other embodiments, the hub 2770 may be a non-dedicated hub - that is, a device which is capable of operating to route communications between the UEs and network node 2750b, but which is additionally capable of operating as a communication start and / or end point for certain data channels.

[0189] Figure 28 shows a UE 2800 in accordance with some embodiments. The UE 2800 presents additional details of some embodiments of the UE 2760 of Figure 27. As used herein, a UE refers to a device capable, configured, arranged and / or operable to communicate wirelessly with network nodes and / or other UEs. Examples of a UE include, but are not limited to, a smart phone, mobile phone, cell phone, voice over IP (VoIP) phone, wireless local loop phone, desktop computer, personal digital assistant (PDA), wireless cameras, gaming console or device, music storage / playback device, wearable terminal device, wireless endpoint, mobile station, tablet, laptop, laptop-embedded equipment (LEE), laptop-mounted equipment (LME), an Augmented Reality (AR) or Virtual Reality (VR) device, wireless customer-premise equipment (CPE), vehicle, vehicle-mounted or vehicle embedded / integrated wireless device, etc. Other examples include any UE identified by the 3rd Generation Partnership Project (3 GPP), including a narrow band internet of things (NB-IoT) UE, a machine type communication (MTC) UE, and / or an enhanced MTC (eMTC) UE.

[0190] A UE may support device-to-device (D2D) communication, for example by implementing a 3 GPP standard for sidelink communication, Dedicated Short-Range Communication (DSRC), vehicle-to-vehicle (V2V), vehicle-to-infrastructure (V2I), orvehicle- to-everything (V2X). In other examples, a UE may not necessarily have a user in the sense of a human user who owns and / or operates the relevant device. Instead, a UE may represent a device that is intended for sale to, or operation by, a human user but which may not, or which may not initially, be associated with a specific human user (e.g., a smart sprinkler controller). Alternatively, a UE may represent a device that is not intended for sale to, or operation by, an end user but which may be associated with or operated for the benefit of a user (e.g., a smart power meter).

[0191] The UE 2800 includes processing circuitry 2810 that is operatively coupled via a bus 2840 to an input / output interface 2820, a power source 2830, a memory 2860, a communication interface 2870, and / or any other component, or any combination thereof.Certain UEs may utilize all or a subset of the components shown in Figure 28. The level of integration between the components may vary from one UE to another UE. Further, certain UEs may contain multiple instances of a component, such as multiple processors, memories, transceivers, transmitters, receivers, etc.

[0192] The processing circuitry 2810 is configured to process instructions and data and may be configured to implement any sequential state machine operative to execute instructions stored as machine-readable computer programs in the memory 2860. The processing circuitry 2810 may be implemented as one or more hardware-implemented state machines (e.g., in discrete logic, field-programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), etc.); programmable logic together with appropriate firmware; one or more stored computer programs, general-purpose processors, such as a microprocessor or digital signal processor (DSP), together with appropriate software; or any combination of the above. For example, the processing circuitry 2810 may include multiple central processing units (CPUs).

[0193] In the example, the input / output interface 2820 may be configured to provide an interface or interfaces to an input device, output device, or one or more input and / or output devices. Examples of an output device include a speaker, a sound card, a video card, a display, a monitor, a printer, an actuator, an emitter, a smartcard, another output device, or any combination thereof. An input device may allow a user to capture information into the UE 2800. Examples of an input device include a touch-sensitive or presence-sensitive display, a camera (e.g., a digital camera, a digital video camera, a web camera, etc.), a microphone, a sensor, a mouse, a trackball, a directional pad, a trackpad, a scroll wheel, a smartcard, and the like. The presence-sensitive display may include a capacitive or resistive touch sensor to sense input from a user. A sensor may be, for instance, an accelerometer, a gyroscope, a tilt sensor, a force sensor, a magnetometer, an optical sensor, a proximity sensor, a biometric sensor, etc., or any combination thereof. An output device may use the same type of interface port as an input device. For example, a Universal Serial Bus (USB) port may be used to provide an input device and an output device.

[0194] In some embodiments, the power source 2830 is structured as a battery or battery pack. Other types of power sources, such as an external power source (e.g., an electricity outlet), photovoltaic device, or power cell, may be used. The power source 2830 may further include power circuitry for delivering power from the power source 2830 itself, and / or an external power source, to the various parts of the UE 2800 via input circuitry or an interface such as an electrical power cable. Delivering power may be, for example, for charging of thepower source 2830. Power circuitry may perform any formatting, converting, or other modification to the power from the power source 2830 to make the power suitable for the respective components of the UE 2800 to which power is supplied.

[0195] The memory 2860 may be or be configured to include memory such as random access memory (RAM), read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), magnetic disks, optical disks, hard disks, removable cartridges, flash drives, and so forth. In one example, the memory 2860 includes one or more application programs 2861, such as an operating system, web browser application, a widget, gadget engine, or other application, and corresponding data 2862. The memory 2860 may store, for use by the UE 2800, any of a variety of various operating systems or combinations of operating systems.

[0196] The memory 2860 may be configured to include a number of physical drive units, such as redundant array of independent disks (RAID), flash memory, USB flash drive, external hard disk drive, thumb drive, pen drive, key drive, high-density digital versatile disc (HD- DVD) optical disc drive, internal hard disk drive, Blu-Ray optical disc drive, holographic digital data storage (HDDS) optical disc drive, external mini-dual in-line memory module (DIMM), synchronous dynamic random access memory (SDRAM), external micro-DIMM SDRAM, smartcard memory such as tamper resistant module in the form of a universal integrated circuit card (UICC) including one or more subscriber identity modules (SIMs), such as a USIM and / or ISIM, other memory, or any combination thereof. The UICC may for example be an embedded UICC (eUICC), integrated UICC (iUICC) or a removable UICC commonly known as ‘SIM card.’ The memory 2860 may allow the UE 2800 to access instructions, application programs and the like, stored on transitory or non-transitory memory media, to off-load data, or to upload data. An article of manufacture, such as one utilizing a communication system may be tangibly embodied as or in the memory 2860, which may be or comprise a device-readable storage medium.

[0197] The processing circuitry 2810 may be configured to communicate with an access network or other network using the communication interface 2870. The communication interface 2870 may comprise one or more communication subsystems and may include or be communicatively coupled to an antenna 2850. The communication interface 2870 may include one or more transceivers used to communicate, such as by communicating with one or more remote transceivers of another device capable of wireless communication (e.g., another UE ora network node in an access network). Each transceiver may include a transmitter 2871 and / or a receiver 2872 appropriate to provide network communications (e.g., optical, electrical, frequency allocations, and so forth). Moreover, the transmitter 2871 and receiver 2872 may be coupled to one or more antennas (e.g., antenna 2850) and may share circuit components, software or firmware, or alternatively be implemented separately.

[0198] In the illustrated embodiment, communication functions of the communication interface 2870 may include cellular communication, Wi-Fi communication, LPWAN communication, data communication, voice communication, multimedia communication, short-range communications such as Bluetooth, near-field communication, location-based communication such as the use of the global positioning system (GPS) to determine a location, another like communication function, or any combination thereof. Communications may be implemented in according to one or more communication protocols and / or standards, such as IEEE 802.11, Code Division Multiplexing Access (CDMA), Wideband Code Division Multiple Access (WCDMA), GSM, LTE, New Radio (NR), UMTS, WiMax, Ethernet, transmission control protocol / internet protocol (TCP / IP), synchronous optical networking (SONET), Asynchronous Transfer Mode (ATM), QUIC, Hypertext Transfer Protocol (HTTP), and so forth.

[0199] Regardless of the type of sensor, a UE may provide an output of data captured by its sensors, through its communication interface 2870, via a wireless connection to a network node. Data captured by sensors of a UE can be communicated through a wireless connection to a network node via another UE. The output may be periodic (e.g., once every 15 minutes if it reports the sensed temperature), random (e.g., to even out the load from reporting from several sensors), in response to a triggering event (e.g., when moisture is detected an alert is sent), in response to a request (e.g., a user initiated request), or a continuous stream (e.g., a live video feed of a patient).

[0200] As another example, a UE comprises an actuator, a motor, or a switch, related to a communication interface configured to receive wireless input from a network node via a wireless connection. In response to the received wireless input the states of the actuator, the motor, or the switch may change. For example, the UE may comprise a motor that adjusts the control surfaces or rotors of a drone in flight according to the received input or to a robotic arm performing a medical procedure according to the received input.

[0201] A UE, when in the form of an Internet of Things (loT) device, may be a device for use in one or more application domains, these domains comprising, but not limited to, citywearable technology, extended industrial application and healthcare. Non-limiting examples of such an loT device are a device which is or which is embedded in: a connected refrigerator or freezer, a TV, a connected lighting device, an electricity meter, a robot vacuum cleaner, a voice controlled smart speaker, a home security camera, a motion detector, a thermostat, a smoke detector, a door / window sensor, a flood / moisture sensor, an electrical door lock, a connected doorbell, an air conditioning system like a heat pump, an autonomous vehicle, a surveillance system, a weather monitoring device, a vehicle parking monitoring device, an electric vehicle charging station, a smart watch, a fitness tracker, a wearable for tactile augmentation or sensory enhancement, a water sprinkler, an animal- or item-tracking device, a sensor for monitoring a plant or animal, an industrial robot, an Unmanned Aerial Vehicle (UAV), and any kind of medical device, like a heart rate monitor or a remote controlled surgical robot. A UE in the form of an loT device comprises circuitry and / or software in dependence of the intended application of the loT device in addition to other components as described in relation to the UE 2800 shown in Figure 28.

[0202] As yet another specific example, in an loT scenario, a UE may represent a machine or other device that performs monitoring and / or measurements, and transmits the results of such monitoring and / or measurements to another UE and / or a network node. The UE may in this case be an M2M device, which may in a 3GPP context be referred to as an MTC device. As one particular example, the UE may implement the 3 GPP NB-IoT standard. In other scenarios, a UE may represent a vehicle, such as a car, a bus, a truck, a ship and an airplane, or other equipment that is capable of monitoring and / or reporting on its operational status or other functions associated with its operation.

[0203] In practice, any number of UEs may be used together with respect to a single use case. For example, a first UE might be or be integrated in a drone and provide the drone’s speed information (obtained through a speed sensor) to a second UE that is a remote controller operating the drone. When the user makes changes from the remote controller, the first UE may adjust the throttle on the drone (e.g. by controlling an actuator) to increase or decrease the drone’s speed. The first and / or the second UE can also include more than one of the functionalities described above. For example, a UE might comprise the sensor and the actuator, and handle communication of data for both the speed sensor and the actuators.

[0204] Figure 29 shows a network node 2900 in accordance with some embodiments. As used herein, network node refers to equipment capable, configured, arranged and / or operable to communicate directly or indirectly with a UE and / or with other network nodes or equipment,in a telecommunication network. Examples of network nodes include, but are not limited to, access points (APs) (e.g., radio access points), base stations (BSs) (e.g., radio base stations, Node Bs, evolved Node Bs (eNBs) and NR NodeBs (gNBs)), 0-RAN nodes or components of an 0-RAN node (e.g, 0-RU, 0-DU, O-CU).

[0205] Base stations may be categorized based on the amount of coverage they provide (or, stated differently, their transmit power level) and so, depending on the provided amount of coverage, may be referred to as femto base stations, pico base stations, micro base stations, or macro base stations. A base station may be a relay node or a relay donor node controlling a relay. A network node may also include one or more (or all) parts of a distributed radio base station such as centralized digital units, distributed units (e.g, in an 0-RAN access node) and / or remote radio units (RRUs), sometimes referred to as Remote Radio Heads (RRHs). Such remote radio units may or may not be integrated with an antenna as an antenna integrated radio. Parts of a distributed radio base station may also be referred to as nodes in a distributed antenna system (DAS).

[0206] Other examples of network nodes include multiple transmission point (multi-TRP) 5G access nodes, multi-standard radio (MSR) equipment such as MSR BSs, network controllers such as radio network controllers (RNCs) or base station controllers (BSCs), base transceiver stations (BTSs), transmission points, transmission nodes, multi-cell / multicast coordination entities (MCEs), Operation and Maintenance (O&M) nodes, Operations Support System (OSS) nodes, Self-Organizing Network (SON) nodes, positioning nodes (e.g. Evolved Serving Mobile Location Centers (E-SMLCs)), and / or Minimization of Drive Tests (MDTs).

[0207] The network node 2900 includes a processing circuitry 2970, a memory 2960, a communication interface 2920, and a power source 2950. The network node 2900 may be composed of multiple physically separate components (e.g, a NodeB component and a RNC component, or a BTS component and a BSC component, etc.), which may each have their own respective components. In certain scenarios in which the network node 2900 comprises multiple separate components (e.g, BTS and BSC components), one or more of the separate components may be shared among several network nodes. For example, a single RNC may control multiple NodeBs. In such a scenario, each unique NodeB and RNC pair, may in some instances be considered a single separate network node. In some embodiments, the network node 2900 may be configured to support multiple radio access technologies (RATs). In such embodiments, some components may be duplicated (e.g, separate memory 2960 for different RATs) and some components may be reused (e.g, a same antenna 2910 may be shared bydifferent RATs). The network node 2900 may also include multiple sets of the various illustrated components for different wireless technologies integrated into network node 2900, for example GSM, WCDMA, LTE, NR, WiFi, Zigbee, Z-wave, LoRaWAN, Radio Frequency Identification (RFID) or Bluetooth wireless technologies. These wireless technologies may be integrated into the same or different chip or set of chips and other components within network node 2900.

[0208] The processing circuitry 2970 may comprise a combination of one or more of a microprocessor, controller, microcontroller, central processing unit, digital signal processor, application-specific integrated circuit, field programmable gate array, or any other suitable computing device, resource, or combination of hardware, software and / or encoded logic operable to provide, either alone or in conjunction with other network node 2900 components, such as the memory 2960, to provide network node 2900 functionality.

[0209] In some embodiments, the processing circuitry 2970 includes a system on a chip (SOC). In some embodiments, the processing circuitry 2970 includes one or more of radio frequency (RF) transceiver circuitry 2971 and baseband processing circuitry 2972. In some embodiments, the radio frequency (RF) transceiver circuitry 2971 and the baseband processing circuitry 2972 may be on separate chips (or sets of chips), boards, or units, such as radio units and digital units. In alternative embodiments, part or all of RF transceiver circuitry 2971 and baseband processing circuitry 2972 may be on the same chip or set of chips, boards, or units.

[0210] The memory 2960 may comprise any form of volatile or non-volatile computer- readable memory including, without limitation, persistent storage, solid-state memory, remotely mounted memory, magnetic media, optical media, random access memory (RAM), read-only memory (ROM), mass storage media (for example, a hard disk), removable storage media (for example, a flash drive, a Compact Disk (CD) or a Digital Video Disk (DVD)), and / or any other volatile or non-volatile, non-transitory device-readable and / or computerexecutable memory devices that store information, data, and / or instructions that may be used by the processing circuitry 2970. The memory 2960 may store any suitable instructions, data, or information, including a computer program, software, an application including one or more of logic, rules, code, tables, and / or other instructions capable of being executed by the processing circuitry 2970 and utilized by the network node 2900. The memory 2960 may be used to store any calculations made by the processing circuitry 2970 and / or any data received via the communication interface 2920. In some embodiments, the processing circuitry 2970 and memory 2960 is integrated.

[0211] The communication interface 2920 is used in wired or wireless communication of signaling and / or data between a network node, access network, and / or UE. As illustrated, the communication interface 2920 comprises port(s) / terminal(s) 2940 to send and receive data, for example to and from a network over a wired connection. The communication interface 2920 also includes radio front-end circuitry 2930 that may be coupled to, or in certain embodiments a part of, the antenna 2910. Radio front-end circuitry 2930 comprises filters 2931 and amplifiers 2932. The radio front-end circuitry 2930 may be connected to an antenna 2910 and processing circuitry 2970. The radio front-end circuitry may be configured to condition signals communicated between antenna 2910 and processing circuitry 2970. The radio front-end circuitry 2930 may receive digital data that is to be sent out to other network nodes or UEs via a wireless connection. The radio front-end circuitry 2930 may convert the digital data into a radio signal having the appropriate channel and bandwidth parameters using a combination of filters 2931 and / or amplifiers 2932. The radio signal may then be transmitted via the antenna 2910. Similarly, when receiving data, the antenna 2910 may collect radio signals which are then converted into digital data by the radio front-end circuitry 2930. The digital data may be passed to the processing circuitry 2970. In other embodiments, the communication interface may comprise different components and / or different combinations of components.

[0212] In certain alternative embodiments, the network node 2900 does not include separate radio front-end circuitry 2930, instead, the processing circuitry 2970 includes radio front-end circuitry and is connected to the antenna 2910. Similarly, in some embodiments, all or some of the RF transceiver circuitry 2971 is part of the communication interface 2920. In still other embodiments, the communication interface 2920 includes one or more ports or terminals 2940, the radio front-end circuitry 2930, and the RF transceiver circuitry 2971, as part of a radio unit (not shown), and the communication interface 2920 communicates with the baseband processing circuitry 2972, which is part of a digital unit (not shown).

[0213] The antenna 2910 may include one or more antennas, or antenna arrays, configured to send and / or receive wireless signals. The antenna 2910 may be coupled to the radio frontend circuitry 2930 and may be any type of antenna capable of transmitting and receiving data and / or signals wirelessly. In certain embodiments, the antenna 2910 is separate from the network node 2900 and connectable to the network node 2900 through an interface or port.

[0214] The antenna 2910, communication interface 2920, and / or the processing circuitry 2970 may be configured to perform any receiving operations and / or certain obtaining operations described herein as being performed by the network node. Any information, dataand / or signals may be received from a UE, another network node and / or any other network equipment. Similarly, the antenna 2910, the communication interface 2920, and / or the processing circuitry 2970 may be configured to perform any transmitting operations described herein as being performed by the network node. Any information, data and / or signals may be transmitted to a UE, another network node and / or any other network equipment.

[0215] The power source 2950 provides power to the various components of network node 2900 in a form suitable for the respective components (e.g., at a voltage and current level needed for each respective component). The power source 2950 may further comprise, or be coupled to, power management circuitry to supply the components of the network node 2900 with power for performing the functionality described herein. For example, the network node 2900 may be connectable to an external power source (e.g., the power grid, an electricity outlet) via an input circuitry or interface such as an electrical cable, whereby the external power source supplies power to power circuitry of the power source 2950. As a further example, the power source 2950 may comprise a source of power in the form of a battery or battery pack which is connected to, or integrated in, power circuitry. The battery may provide backup power should the external power source fail.

[0216] Embodiments of the network node 2900 may include additional components beyond those shown in Figure 29 for providing certain aspects of the network node’s functionality, including any of the functionality described herein and / or any functionality necessary to support the subject matter described herein. For example, the network node 2900 may include user interface equipment to allow input of information into the network node 2900 and to allow output of information from the network node 2900. This may allow a user to perform diagnostic, maintenance, repair, and other administrative functions for the network node 2900. In some embodiments providing a core network node, such as core network node 2740 of FIG. 27, some components, such as the radio front-end circuitry 2930 and the RF transceiver circuitry 2971 may be omitted.

[0217] Figure 30 is a block diagram illustrating a virtualization environment 3000 in which functions implemented by some embodiments may be virtualized. In the present context, virtualizing means creating virtual versions of apparatuses or devices which may include virtualizing hardware platforms, storage devices and networking resources. As used herein, virtualization can be applied to any device described herein, or components thereof, and relates to an implementation in which at least a portion of the functionality is implemented as one or more virtual components. Some or all of the functions described herein may be implementedas virtual components executed by one or more virtual machines (VMs) implemented in one or more virtual environments 3000 hosted by one or more of hardware nodes, such as a hardware computing device that operates as a network node, UE, core network node, or host. Further, in embodiments in which the virtual node does not require radio connectivity (e.g., a core network node or host), then the node may be entirely virtualized. In some embodiments, the virtualization environment 3000 includes components defined by the O-RAN Alliance, such as an O-Cloud environment orchestrated by a Service Management and Orchestration Framework via an O-2 interface. Virtualization may facilitate distributed implementations of a network node, UE, core network node, or host.

[0218] Applications 3200 (which may alternatively be called software instances, virtual appliances, network functions, virtual nodes, virtual network functions, etc.) are run in the virtualization environment 3000 to implement some of the features, functions, and / or benefits of some of the embodiments disclosed herein.

[0219] Hardware 3600 includes processing circuitry, memory that stores software and / or instructions executable by hardware processing circuitry, and / or other hardware devices as described herein, such as a network interface, input / output interface, and so forth. Software may be executed by the processing circuitry to instantiate one or more virtualization layers 3500 (also referred to as hypervisors or virtual machine monitors (VMMs)), provide VMs 3300 and 3400 (one or more of which may be generally referred to as VMs), and / or perform any of the functions, features and / or benefits described in relation with some embodiments described herein. The virtualization layer 3500 may present a virtual operating platform that appears like networking hardware to the VMs 3300 and 3400.

[0220] The VMs 3300 and 3400 comprise virtual processing, virtual memory, virtual networking or interface and virtual storage, and may be run by a corresponding virtualization layer 3500. Different embodiments of the instance of a virtual appliance 3200 may be implemented on one or more of VMs 3300 and 3400, and the implementations may be made in different ways. Virtualization of the hardware is in some contexts referred to as network function virtualization (NFV). NFV may be used to consolidate many network equipment types onto industry standard high volume server hardware, physical switches, and physical storage, which can be located in data centers, and customer premise equipment.

[0221] In the context of NFV, a VM 3300 may be a software implementation of a physical machine that runs programs as if they were executing on a physical, non-virtualized machine. Each of the VMs 3300 and 3400, and that part of hardware 3600 that executes that VM, be ithardware dedicated to that VM and / or hardware shared by that VM with others of the VMs, forms separate virtual network elements. Still in the context of NFV, a virtual network function is responsible for handling specific network functions that run in one or more VMs 3300 and 3400 on top of the hardware 3600 and corresponds to the application 3200.

[0222] Hardware 3600 may be implemented in a standalone network node with generic or specific components. Hardware 3600 may implement some functions via virtualization. Alternatively, hardware 3600 may be part of a larger cluster of hardware (e.g. such as in a data center or CPE) where many hardware nodes work together and are managed via management and orchestration 3100, which, among others, oversees lifecycle management of applications 3200. In some embodiments, hardware 3600 is coupled to one or more radio units that each include one or more transmitters and one or more receivers that may be coupled to one or more antennas. Radio units may communicate directly with other hardware nodes via one or more appropriate network interfaces and may be used in combination with the virtual components to provide a virtual node with radio capabilities, such as a radio access node or a base station. In some embodiments, some signaling can be provided with the use of a control system 3700 which may alternatively be used for communication between hardware nodes and radio units.

[0223] Although the computing devices described herein (e.g., UEs, network nodes) may include the illustrated combination of hardware components, other embodiments may comprise computing devices with different combinations of components. It is to be understood that these computing devices may comprise any suitable combination of hardware and / or software needed to perform the tasks, features, functions and methods disclosed herein. Determining, calculating, obtaining or similar operations described herein may be performed by processing circuitry, which may process information by, for example, converting the obtained information into other information, comparing the obtained information or converted information to information stored in the network node, and / or performing one or more operations based on the obtained information or converted information, and as a result of said processing making a determination. Moreover, while components are depicted as single boxes located within a larger box, or nested within multiple boxes, in practice, computing devices may comprise multiple different physical components that make up a single illustrated component, and functionality may be partitioned between separate components. For example, a communication interface may be configured to include any of the components described herein, and / or the functionality of the components may be partitioned between the processing circuitry and the communication interface. In another example, non-computationally intensive functions of anyof such components may be implemented in software or firmware and computationally intensive functions may be implemented in hardware.

[0224] In certain embodiments, some or all of the functionality described herein may be provided by processing circuitry executing instructions stored on in memory, which in certain embodiments may be a computer program product in the form of a non-transitory computer- readable storage medium. In alternative embodiments, some or all of the functionalities may be provided by the processing circuitry without executing instructions stored on a separate or discrete device-readable storage medium, such as in a hard-wired manner. In any of those particular embodiments, whether executing instructions stored on a non-transitory computer- readable storage medium or not, the processing circuitry can be configured to perform the described functionality. The benefits provided by such functionality are not limited to the processing circuitry alone or to other components of the computing device, but are enjoyed by the computing device as a whole, and / or by end users and a wireless network generally.

[0225] Figure 31 illustrates a schematic diagram of a network function 4000 according to some embodiments of present disclosure. In some embodiments, the network function 4000 performs the method 2600 as described above. In some embodiments, the network function 4000 may comprise one or more of the knowledge base 120, the reasoning engine 130, the data collecting agent 140, the measurement agent 150, and a recommendation agent 160. The network function 4000 may further comprise an actuation agent.

[0226] Processing circuitry 3101 is provided using any combination of one or more of a suitable central processing unit (CPU), multiprocessor, microcontroller, digital signal processor (DSP), etc., capable of executing software instructions stored in a computer program product 3201 (as in Fig. 32), e.g. in the form of storage medium 3103. The processing circuity 3101 may further to be provided as at least one application specific integrated circuit (ASIC), or field programmable gate array (FPGA).

[0227] Particularly, the processing circuitry 3101 is configured to cause the network function 4000 to perform a set of operations, or steps, as disclosed above. For example, the storage medium 3103 may store the set of operations, and the processing circuitry 3101 may be configured to retrieve the set of operations from the storage medium 3102 to cause the network function 4000 to perform the set of operations. The set of operations may be provided as a set of executable instructions. Thus, the processing circuitry 3101 is thereby arranged to execute methods as herein disclosed. The storage medium 3103 may also comprise persistentstorage, which, for example, can be any single one or combination of magnetic memory, optical memory, solid state memory or even remotely mounted memory.

[0228] The network function 4000 may further comprise a communications interface 3102 for communications with other entities, functions, nodes, and devices, such as the receiver device 300. As such the communications interface 3102 may comprise one or more transmitters and receivers, comprising analogue and digital components. The processing circuitry 3101 controls the general operation of the network function 4000 e.g. by sending data and control signals to the communications interface 3102 and the storage medium 3103, by receiving data and reports from the communications interface 3102, and by retrieving data and instructions from the storage medium 3103. Other components, as well as the related functionality, of the network function 4000 are omitted in order not to obscure the concepts presented herein.

[0229] Fig. 32 shows one example of a computer program product 3201 comprising computer readable means 3202. On this computer readable means 3202, a computer program 3203 can be stored, which computer program 3203 can cause the processing circuitry 3101and thereto operatively coupled entities and devices, such as the communications interface 3102 and the storage medium 3103, to execute method 2600 according to embodiments described herein. The computer program 3202 and / or computer program product 3201 may thus provide means for performing any steps of the network function 4000 as herein disclosed. On this computer readable means 3202, a computer program 3203 can be stored, which computer program 3203 can cause the processing circuitry 3101 and thereto operatively coupled entities and devices, such as the communications interface 3102 and the storage medium 3103, to execute methods according to embodiments described herein.

[0230] The computer program 3203 and / or computer program product 3201 may thus provide means for performing any steps of the network function 4000 as herein disclosed. In the example of Figure 32, the computer program product 3201 is illustrated as an optical disc, such as a CD (compact disc) or a DVD (digital versatile disc) or a Blu-Ray disc. The computer program product 3201 could also be embodied as a memory, such as a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM), or an electrically erasable programmable read-only memory (EEPROM) and more particularly as a non-volatile storage medium of a device in an external memory such as a USB (Universal Serial Bus) memory or a Flash memory, such as a compact Flash memory. Thus, while the computer program 3203 is here schematically shown as a track on the depicted optical disk,the computer program 3203 can be stored in any way which is suitable for the computer program product 3201.

[0231] The inventive concept has mainly been described above with reference to a few embodiments. However, as is readily appreciated by a person skilled in the art, other embodiments than the ones disclosed above are equally possible within the scope of the inventive concept.EMBODIMENTSEmbodiment 1. A computer implemented method (2600) for runtime threat modeling, comprising: obtaining (2610) event related information associated with an asset; identifying (2620) attack surface related information associated with the event related information; identifying (2630) threat vector related information associated with the attack surface related information; identifying (2640) security control related information associated with the threat vector related information; and providing (2660) an output based on at least one of the attack surface related information, the threat vector related information, or the security control related information.Embodiment 2. The method (2600) according to embodiment 1, wherein the identifying the attack surface related information comprises: measuring an attack surface exposure, wherein the attack surface related information comprises attack surface exposure.Embodiment 3. The method (2600) according to any one of proceeding embodiments, wherein the identifying the threat vector related information comprises: measuring a threat vector impact, wherein the threat vector related information comprises the threat vector impact.Embodiment 4. The method (2600) according to any one of proceeding embodiments, wherein the identifying the security control related information comprises: measuring a security control effectiveness related to the security control, wherein the security control related information comprises the security control effectiveness.Embodiment 5. The method (2600) according to any one of proceeding embodiments, wherein the providing comprises at least one of: providing one or more security control related recommendations associated with the threat; providing one or more potential threats associated with the asset;providing a score associated with the threat; or providing an indication that no action is recommended.Embodiment 6. The method (2600) according to embodiment 5, wherein the providing the score associated with the threat, comprises: calculating the score based on a conditional probability of threat factor impact given attack surface exposure and security control effectiveness:wherein TLs corresponds to the score associated with the threat, TVIMP corresponds to the threat vector impact, ASEXP corresponds to the attack surface exposure, and SCEff corresponds to the security control effectiveness.Embodiment 7. The method (2600) according to embodiment 6, wherein the threat vector impact is calculated by following formula:wherein D represents a damage potential that can occur either directly or indirectly due to impact propagation, C represents environmental conditions and threat vector chaining conditions, and OMRrepresents a radio order of magnitude.Embodiment 8. The method (2600) according to embodiment 7, wherein the damage potential is represented by a dot product of a ratio of a sum of direct impact from a damage Ddand a ratio of propagated impact from the damage Dp, over a total number of impacts that is related to the threat vector Dr, and calculated by following formula: n=Dd• Dpl DrEmbodiment 9. The method (2600) according to embodiment 7 or 8, wherein the conditions C is represented by a dot product of a radio of a sum of environmental conditions Ce, and a threat factor preconditions CpreCond, over a number of conditions that are related to the threat vector Cr, and calculated by following formula:Embodiment 10. The method (2600) according to any of embodiments 6-9, wherein the security control effectiveness is calculated by following formula:wherein Ccvis a vector representing a security control coverage which determines if the necessary security controls to mitigate a potential threat exists, Ccris a vector representing a quantification of correctness of implementation of configured security controls and how adequately the implemented security controls mitigate the potential threat.Embodiment 11. The method (2600) according to any one of proceeding embodiments, wherein the attack surface related information or the attack surface exposure is obtained based on at least one of: an entry point, a channel, or a data.Embodiment 12. The method (2600) according to any one of proceeding embodiments, wherein the threat vector related information or the threat vector impact is obtained based on at least one of: an attacker technique, an attacker sub-technique, an applied procedure, an impact of an attack, an applied interface.Embodiment 13. The method (2600) of according to any one of proceeding embodiments, further comprising: updating a knowledge base (120), based on at least one of the event related information, the attack surface related information, the threat vector related information, the security control related information, or the output; or obtaining additional information from a knowledge base (120).Embodiment 14. The method (2600) of any one of embodiments 5-13, wherein the providing a score associated with the threat, comprises: obtaining the score based on the attack surface related information, threat vector related information, and the security control related information; or categorizing the score into at least two categories.Embodiment 15. The method (2600) according to any one of proceeding embodiments, wherein at least one of the followings are applied: obtaining (2610) is performed by a data collecting agent (140);identifying (2620, 2630, 2640) is performed by a measurement agent (150), or a reasoning engine (130); providing (2660) is performed by a recommendation agent (160), a measurement agent (150), or a reasoning engine (130).Embodiment 16. The method (2600) according to any one of embodiments 13-15, wherein the updating the knowledge base (120) is performed by the data collecting agent (140), the measurement agent (150), the recommendation agent (160), or the reasoning engine (130).Embodiment 17. The method (2600) according to any one of proceeding embodiments, wherein the event comprises a change in a configuration, a topology, a network function, a system, a network function environment or a system environment.Embodiment 18. The method (2600) according to any one of proceeding embodiments, wherein the providing an output comprises: providing the output to a security management function (110), a knowledge base (120), or a reasoning engine (130).Embodiment 19. The method (2600) according to any one of proceeding embodiments, further comprising: obtaining a new model or an inference rule from a security management function (110) based on the provided output.Embodiment 20. The method (2600) according to any one of proceeding embodiments, wherein the obtaining (2610), the identifying (2620, 2630, 2640), or the providing (2660) is performed by applying at least one of the following models: an event model; a system model; an attack surface model; a threat vector model; or a security control model.Embodiment 21. The method (2600) according to embodiment 20, wherein the at least one of the models is connected to another model through the knowledge base 120 or the reasoning engine 130.Embodiment 22. The method (2600) of embodiment 20 or 21, wherein at least one of the following applies: the event model is used by the system model, or used by the attack surface model; the system model is protected by the security control model, and provides an attack surface to the attack surface model; the attack surface model is used by the threat vector model; or the threat vector model is mitigated by the security control model.Embodiment 23. The method (2600) according to any of embodiments 15-22, wherein at least one of the following applies: the data collecting agent (140), the measurement agent (150) or the recommendation agent (160) interacts with the knowledge base (120) or the reasoning engine (130); or the reasoning engine (130) invokes one or more instructions to the knowledge base (120), the data collecting agent (140), the measurement agent (150) or the recommendation agent (160), based on the knowledge base (120) and / or one or more sets of rules.Embodiment 24. The method (2600) of any one of embodiments 13-23, further comprising: providing an updated output in accordance with the updated knowledge base (120).Embodiment 25. The method (2600) of any one of embodiments 15-24, wherein the reasoning engine (130) uses logical reasoning incorporating inference rules.Embodiment 26. The method (2600) according to any one of proceeding embodiments, wherein any of the obtaining (2610), identifying (2620, 2630, 2640), or providing (2660) is performed by a network function (4000) in Radio Access Network Intelligent Controller Application, or a network function (4000) in Open Radio Access Network, O-RAN, Centralized Unit Control Plane, O-CU-CP.Embodiment 27. The method (2600) according to any one of proceeding embodiments, wherein the asset comprises one or more components, and / or one or more functionalities ofan Open Radio Access Network, O-RAN, function, a radio function, a cloud function, a synchronization function, a transport function, or a management function.Embodiment 28. The method (2600) according to any one of proceeding embodiments, further comprising: actuating a resource (170) associated with the asset based on the output, according to a close loop actuation or a human in the loop actuation.Embodiment 29. The method (2600) according to embodiment 26, wherein one or more of a data collecting agent (140), a measurement agent (150), a recommendation agent (160), a knowledge base (120) or a reasoning engine (130) are comprised in the network function.Embodiment 30. A network function (4000) for runtime threat modeling, configured to perform the method of any of embodiments 1-29.Embodiment 31. A network function (4000) for runtime threat modeling, comprising a processor and a memory, said memory containing instructions executable by said processor whereby said network function is operative to perform the method of any embodiments 1-29.Embodiment 32. A computer program (3203) for runtime threat modeling, the computer program comprising computer readable code being configured such that, on execution by suitable computer or processor, the computer or processor is caused to perform the method of any of embodiments 1-29.Embodiment 33. A computer program product (3201) comprising a computer readable medium (3202) having computer readable code embodied therein, the computer readable code being configured such that, on execution by suitable computer or processor, the computer or processor is caused to perform the method of any of embodiments 1-29.REFERENCES1. Basin, David, Manuel Clavel, and Marina Egea. "A decade of model-driven security." Proceedings of the 16th ACM symposium on Access control models and technologies. 2011.Resource Description Framework, W3C, Semantic Web Standards, https: / / www.w3.org / RDF / F. De Rosa, N. Maunero, P. Prinetto, F. Talentino and M. Trussoni, "ThreMA: Ontology- Based Automated Threat Modeling for ICT Infrastructures," in IEEE Access, vol. 10, pp. 116514-116526, 2022, P. Johnson, A. Vernotte, M. Ekstedt and R. Lagerstrom, "pwnPr3d: An Attack-Graph- Driven Probabilistic Threat-Modeling Approach," 2016 11th International Conference on Availability, Reliability and Security (ARES), Salzburg, Austria, 2016, pp. 278-283 R. Pell, S. Moschoyiannis, E. Panaousis; “Multi-Stage Threat Modelling and Security Monitoring in 5GCN”, Aug 2021 GSMA, Mobile Threat Intelligence Framework Principles (vl.0), 2024

Claims

CLAIMS1. A computer implemented method (2600) for runtime threat modeling, comprising: obtaining (2610) event related information associated with an asset; identifying (2620) attack surface related information associated with the event related information; identifying (2630) threat vector related information associated with the attack surface related information; identifying (2640) security control related information associated with the threat vector related information; and providing (2660) an output based on at least one of the attack surface related information, the threat vector related information, or the security control related information.

2. The method (2600) according to claim 1, wherein the identifying the attack surface related information comprises: measuring an attack surface exposure, wherein the attack surface related information comprises attack surface exposure.

3. The method (2600) according to any one of the proceeding claims, wherein the identifying the threat vector related information comprises: measuring a threat vector impact, wherein the threat vector related information comprises the threat vector impact.

4. The method (2600) according to any one of the proceeding claims, wherein the identifying the security control related information comprises: measuring a security control effectiveness related to the security control, wherein the security control related information comprises the security control effectiveness.

5. The method (2600) according to any one of the proceeding claims, wherein the providing comprises at least one of: providing one or more security control related recommendations associated with the threat; providing one or more potential threats associated with the asset;providing a score associated with the threat; or providing an indication that no action is recommended.

6. The method (2600) according to claim 5, wherein the providing the score associated with the threat, comprises: calculating the score based on a conditional probability of threat factor impact given attack surface exposure and security control effectiveness:wherein TLs corresponds to the score associated with the threat, TVIMP corresponds to the threat vector impact, ASEXP corresponds to the attack surface exposure, and SCEff corresponds to the security control effectiveness.

7. The method (2600) according to claim 6, wherein the threat vector impact is calculated by following formula:wherein D represents a damage potential that can occur either directly or indirectly due to impact propagation, C represents environmental conditions and threat vector chaining conditions, and OMRrepresents a radio order of magnitude.

8. The method (2600) according to claim 7, wherein the damage potential is represented by a dot product of a ratio of a sum of direct impact from a damage Ddand a ratio of propagated impact from the damage Dp, over a total number of impacts that is related to the threat vector Dr, and calculated by following formula: n=Dd• Dpl Dr9. The method (2600) according to claim 7 or 8, wherein the conditions C is represented by a dot product of a radio of a sum of environmental conditions Ce, and a threat factor preconditions CpreCond, over a number of conditions that are related to the threat vector Cr, and calculated by following formula:

10. The method (2600) according to any of claims 6-9, wherein the security control effectiveness is calculated by following formula:wherein Ccvis a vector representing a security control coverage which determines if the necessary security controls to mitigate a potential threat exists, Ccris a vector representing a quantification of correctness of implementation of configured security controls and how adequately the implemented security controls mitigate the potential threat.

11. The method (2600) according to any one of the proceeding claims, wherein the attack surface related information or the attack surface exposure is obtained based on at least one of: an entry point, a channel, or a data.

12. The method (2600) according to any one of the proceeding claims, wherein the threat vector related information or the threat vector impact is obtained based on at least one of: an attacker technique, an attacker sub-technique, an applied procedure, an impact of an attack, an applied interface.

13. The method (2600) of according to any one of the proceeding claims, further comprising: updating a knowledge base (120), based on at least one of the event related information, the attack surface related information, the threat vector related information, the security control related information, or the output; or obtaining additional information from a knowledge base (120).

14. The method (2600) of any one of claims 5-13, wherein the providing a score associated with the threat, comprises: obtaining the score based on the attack surface related information, threat vector related information, and the security control related information; or categorizing the score into at least two categories.

15. The method (2600) according to any one of the proceeding claims, wherein at least one of the followings are applied: obtaining (2610) is performed by a data collecting agent (140);identifying (2620, 2630, 2640) is performed by a measurement agent (150), or a reasoning engine (130); providing (2660) is performed by a recommendation agent (160), a measurement agent (150), or a reasoning engine (130).

16. The method (2600) according to any one of claims 13-15, wherein the updating the knowledge base (120) is performed by the data collecting agent (140), the measurement agent (150), the recommendation agent (160), or the reasoning engine (130).

17. The method (2600) according to any one of the proceeding claims, wherein the event comprises a change in a configuration, a topology, a network function, a system, a network function environment or a system environment.

18. The method (2600) according to any one of the proceeding claims, wherein the providing an output comprises: providing the output to a security management function (110), a knowledge base (120), or a reasoning engine (130).

19. The method (2600) according to any one of the proceeding claims, further comprising: obtaining a new model or an inference rule from a security management function (110) based on the provided output.

20. The method (2600) according to any one of the proceeding claims, wherein the obtaining (2610), the identifying (2620, 2630, 2640), or the providing (2660) is performed by applying at least one of the following models: an event model; a system model; an attack surface model; a threat vector model; or a security control model.

21. The method (2600) according to claim 20, wherein the at least one of the models is connected to another model through the knowledge base 120 or the reasoning engine 130.

22. The method (2600) of claim 20 or 21, wherein at least one of the following applies: the event model is used by the system model, or used by the attack surface model; the system model is protected by the security control model, and provides an attack surface to the attack surface model; the attack surface model is used by the threat vector model; or the threat vector model is mitigated by the security control model.

23. The method (2600) according to any of claims 15-22, wherein at least one of the following applies: the data collecting agent (140), the measurement agent (150) or the recommendation agent (160) interacts with the knowledge base (120) or the reasoning engine (130); or the reasoning engine (130) invokes one or more instructions to the knowledge base (120), the data collecting agent (140), the measurement agent (150) or the recommendation agent (160), based on the knowledge base (120) and / or one or more sets of rules.

24. The method (2600) of any one of claims 13-23, further comprising: providing an updated output in accordance with the updated knowledge base (120).

25. The method (2600) of any one of claims 15-24, wherein the reasoning engine (130) uses logical reasoning incorporating inference rules.

26. The method (2600) according to any one of the proceeding claims, wherein any of the obtaining (2610), identifying (2620, 2630, 2640), or providing (2660) is performed by a network function (4000) in Radio Access Network Intelligent Controller Application, or a network function (4000) in Open Radio Access Network, O-RAN, Centralized Unit Control Plane, O-CU-CP.

27. The method (2600) according to any one of the proceeding claims, wherein the asset comprises one or more components, and / or one or more functionalities of an Open Radio Access Network, O-RAN, function, a radio function, a cloud function, a synchronization function, a transport function, or a management function.

28. The method (2600) according to any one of the proceeding claims, further comprising: actuating a resource (170) associated with the asset based on the output, according to a close loop actuation or a human in the loop actuation.

29. The method (2000) according to claim 26, wherein one or more of a data collecting agent (140), a measurement agent (150), a recommendation agent (160), a knowledge base (120) or a reasoning engine (130) are comprised in the network function.

30. A network function (4000) for runtime threat modeling, configured to perform the method of any of claims 1-29.

31. A network function (4000) for runtime threat modeling, comprising a processor and a memory, said memory containing instructions executable by said processor whereby said network function is operative to perform the method of any claims 1-29.

32. A computer program (3203) for runtime threat modeling, the computer program comprising computer readable code being configured such that, on execution by suitable computer or processor, the computer or processor is caused to perform the method of any of claims 1-29.

33. A computer program product (3201) comprising a computer readable medium (3202) having computer readable code embodied therein, the computer readable code being configured such that, on execution by suitable computer or processor, the computer or processor is caused to perform the method of any of claims 1-29.

Citation Information

Patent Citations

  • Dynamically adapting a security configuration for a data processing application at runtime using a causal network

    GB2506151A

  • Recombinant threat modeling

    US10216938B2

  • Similarity search for discovering multiple vector attacks

    US20170346839A1

  • Adaptive system for network and security management

    US20230396641A1

  • Security automation system

    WO2021028060A1