Real-time security threat detection and dynamic response at edge security operations center in o-ran systems
The edge SOC with a security management engine addresses O-RAN system vulnerabilities by enabling real-time threat detection and dynamic policy enforcement, enhancing security and responsiveness through localized threat response and continuous monitoring.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- RAKUTEN MOBILE INC
- Filing Date
- 2025-01-07
- Publication Date
- 2026-07-30
AI Technical Summary
The O-RAN system faces challenges in real-time security threat detection and response due to centralized security management delays, increased attack surfaces from multi-vendor deployments and network slicing vulnerabilities, and complex cloud platform configurations, leading to inefficient incident response and prolonged reaction times.
Implementing an edge security operations center (SOC) with a security management engine for real-time threat detection and dynamic policy enforcement, leveraging local processing power to collect and analyze data, and isolate compromised assets.
Enhances real-time threat detection and response, reducing latency and improving overall system security and operational performance by enabling continuous monitoring and proactive security management.
Smart Images

Figure US2025010608_30072026_PF_FP_ABST
Abstract
Description
REAL-TIME SECURITY THREAT DETECTION AND DYNAMIC RESPONSE AT EDGE SECURITY OPERATIONS CENTER IN O-RAN SYSTEMS
[0001] CROSS-REFERENCE TO RELATED APPLICATION (S)This application claims priority to Indian non-provisional application No.202441083323, filed on October 30, 2024, the entire contents of which is incorporated herein by reference.TECHNICAL FIELD
[0002] The present disclosure relates to real-time security threat detection and dynamic response at edge security operations center in open radio access network (O-RAN) systems.BACKGROUND
[0003] The information disclosed in this background section is only for enhancement of understanding of the general background of the disclosure and should not be taken as an acknowledgement or any form of suggestion that this information forms the prior art already known to a person skilled in the art.
[0004] In an open radio access network (O-RAN) system, a security operations center (SOC) plays an important role in ensuring the security of the network infrastructure and its components. The O-RAN system includes various data centers, edge data centers, far edge data centers (DCs), and regional DCs. All data related to security logs and events across the various DCs are collected, processed, and transferred to a central SOC. The central SOC monitors security events, conducts threat detection, and executes remediation plans.
[0005] The central SOC enables centralized control over security operations, allowing the network administrators to have a comprehensive view of the entire network’s security posture. The analysis, threat detection, and remediation are all performed from this central point, streamlining operations. The data collection of security events or logs from various data centers before analysis can cause delays, and the transfer oflogs increases the reaction time, potentially allowing critical events to go unnoticed for extended periods.
[0006] The 0-RAN system supports network slicing, enabling multiple network functions to run on shared physical or cloud infrastructure. However, the lack of robust isolation and security between network slices can lead to unauthorized access and cross-slice attacks. The central SOC may struggle to prevent unauthorized access and cross-slice attacks in real-time, leaving the system vulnerable to such exploits.
[0007] Accordingly, there is a need to detect real-time security threats and implement dynamic security policy in real-time at system level.SUMMARY
[0008] The present disclosure relates to a method comprising the steps of receiving input data by a security management engine deployed at an edge network entity from at least one target network entity associated with a communications network. Further, one or more parameters of the input data are compared with one or more corresponding reference parameters from a plurality of reference parameters by the security management engine. The reference parameters are pre-defined by the edge network entity associated with the communications network. Based on the comparison, an anomaly, corresponding to the at least one target network entity, is detected in realtime by the security management engine. Further, at least one of (i) a dynamic policy associated with the anomaly on a component and (ii) an isolation of the component is implemented corresponding to the anomaly in real-time.
[0009] The present disclosure also relates to an apparatus configured to receive, by a security management engine deployed at an edge network entity, input data from at least one target network entity associated with a communications network. Further, one or more parameters of the input data is compared with one or more corresponding reference parameters from a plurality of reference parameters by the security management engine. The reference parameters are pre-defined by the edge network entity associated with the communications network. Based on the comparison, an anomaly corresponding to the at least one target network entity, is detected in real-time by the security management engine. Further, at least one of (i) a dynamic policy associated with the anomaly on a component and (ii) an isolation of the component is implemented corresponding to the anomaly in real-time.
[0010] In an embodiment, there is a non-transitory computer readable medium including instructions stored thereon that when processed by at least one processor, causes the at least one processor to perform operations of receiving, by a security management engine deployed at an edge network entity, input data from at least one target network entity associated with a communications network. Further, one or more parameters of the input data is compared with one or more corresponding reference parameters from a plurality of reference parameters by the security management engine. The reference parameters are pre-defined by the edge network entity associated with the communications network. Based on the comparison, an anomaly corresponding to the at least one target network entity, is detected in real-time by the security management engine. Further, at least one of (i) a dynamic policy associated with the anomaly on a component and (ii) an isolation of the component is implemented corresponding to the anomaly in real-time.
[0011] As the O-RAN system generates vast amounts of data required for analysis, which needs to be processed by the central SOC, the volume of logs can overwhelm the central SOC, hindering its ability to efficiently detect and respond to security incidents quickly. There may be a delay in threat detection and prolonged response times which may affect the overall responsiveness of the system.
[0012] Furthermore, O-RAN’ s deployment on cloud platforms often comprises frequent configuration changes, which adds complexity to security monitoring and incident response. The central SOC may struggle to adapt to such rapid changes, making traditional security solutions less effective.
[0013] The O-RAN system allows multi-vendor deployments and often incorporates open-source software. At the edge DCs and the regional DCs, the attack surface may be increased where there is no real-time monitoring or runtime prevention mechanism in place. As a result, the central SOC may face difficulty responding to threats emerging from the edge DCs and the regional DCs.
[0014] The foregoing summary is illustrative only and is not intended to be in any way limiting. In addition to the illustrative aspects, embodiments, and features described above, further aspects, embodiments, and features will become apparent by reference to the drawings and the following detailed description.BRIEF DESCRIPTION OF THE DRAWINGS
[0015] Features, aspects, and advantages of embodiments of the disclosure will be described below with reference to the accompanying drawings, in which like reference numerals denote like elements, and wherein:
[0016] Fig. 1 illustrates an exemplary environment for detecting real-time security threats by an edge security operation center (SOC) in an open radio access network (0-RAN) system and implementing dynamic security policy in real-time and isolating services or components at system level, in accordance with some embodiments of the present disclosure.
[0017] Fig.2 is an exemplary environment for detecting non-real-time security threats by a central security operation center (SOC) in the O-RAN system, in accordance with an embodiment of the present disclosure.
[0018] Fig. 3 shows an exemplary flow chart illustrating method steps for exemplary environment for detecting real-time security threats by an edge security operation center (SOC) in an open radio access network (O-RAN) system and implementing dynamic security policy in real-time and isolating services or components at system level, in accordance with some embodiments of the present disclosure.
[0019] Fig. 4 illustrates an embodiment of a device wherein the method for exemplary environment for detecting real-time security threats by an edge security operation center (SOC) in the O-RAN system and implementing dynamic security policy in realtime and isolating services or components at system level, may be implemented, according to the embodiments as disclosed herein.
[0020] It should be appreciated by those skilled in the art that any block diagram herein represents conceptual views of illustrative systems embodying the principles of the present subject matter. Similarly, it will be appreciated that any flow charts, flowdiagrams, state transition diagrams, pseudo code, and the like represent various processes which may be substantially represented in computer readable medium and executed by a computer or processor, whether or not such computer or processor is explicitly shown.DETAILED DESCRIPTION OF THE DISCLOSURE
[0021] The following detailed description of example embodiments refers to the accompanying drawings. The foregoing disclosure provides illustration and description but is not intended to be exhaustive or to limit the implementations to the precise form disclosed. Modifications and variations are possible in light of the above disclosure or may be acquired from practice of the implementations. Further, one or more features or components of one embodiment may be incorporated into or combined with another embodiment (or one or more features of another embodiment). Additionally, the flowchart and description of operations provided below relate to one of the various embodiments. It should be noted that it is possible to make other embodiments that do not exactly match the flowchart and its description. It is understood that in other embodiments one or more operations may be omitted, one or more operations may be added, one or more operations may be performed simultaneously (at least in part).
[0022] It will be apparent that systems and / or methods described herein may be implemented in different forms of hardware, software, or a combination of hardware and software. The actual specialized control hardware or software code used to implement these systems and / or methods is not limiting the implementations. Thus, the operation and behavior of the systems and / or methods are described herein without reference to specific software code. It is understood that software and hardware may be designed to implement the systems and / or methods based on the description herein.
[0023] Even though particular combinations of features are recited in the claims and / or disclosed in the specification, these combinations are not intended to limit the disclosure of implementations. In fact, many of these features may be combined in ways not specifically recited in the claims and / or disclosed in the specification. Although each dependent claim listed below may directly depend on only one claim,the disclosure of implementations includes each dependent claim in combination with every other claim in the claim set.
[0024] No element, act, or instruction used herein should be construed as critical or essential unless explicitly described as such. Also, as used herein, the articles “a” and “an” are intended to include one or more items and may be used interchangeably with “one or more.” Also, as used herein, the terms “has,” “have,” “having,” “include,” “including,” or the like are intended to be open-ended terms. Further, the phrase “based on” is intended to mean “based, at least in part, on” unless explicitly stated otherwise. Furthermore, expressions such as “at least one of [A] and [B],” “[A] and / or [B],” or “at least one of [A] or [B]” are to be understood as including only A, only B, or both A and B.
[0025] The foregoing disclosure provides illustration and description but is not intended to be exhaustive or to limit the implementations to the precise form disclosed. Modifications and variations are possible in light of the above disclosure or may be acquired from practice of the implementations.
[0026] In general, providing centralized security management through a central security operations center (SOC) can offer control across the entire 0-RAN system. However, as stated earlier, in certain scenarios, the centralized security management presents challenges. For instance, the reaction time is very high as events or logs collected at the edge or regional data centers must be pushed to the central SOC for analysis, delaying the response to critical events. In such scenarios, the massive amounts of data generated by the O-RAN system cannot be managed by the central SOC to detect and respond to threats quickly. Further, the dynamic nature of 0-RAN deployments, especially on cloud platforms, where frequent changes in configurations and deployments occur, complicates security monitoring and incident response for the central SOC or traditional security solutions. The open nature of 0-RAN allows for multi-vendor deployments and includes open-source software, further increases the potential attack surface, particularly at the edge or regional data centers, where realtime monitoring and dynamic prevention mechanisms may be lacking. Furthermore, the 0-RAN’ s support for network slicing, where multiple network functions operateon a single infrastructure, introduces additional security risks due to inadequate isolation between slices, potentially leading to unauthorized access or cross-slice attacks in real-time.
[0027] The methods and systems of the present disclosure solve a technical problem of addressing security challenges in the 0-RAN system by enabling real-time threat detection and response at the edge SOC. The edge SOC provides continuous monitoring, real-time analysis, and dynamic security enforcement at the edge network entities, significantly reducing the reaction time compared to the central SOC. By deploying a security engine, such as a security xApp at the edge or far edge data centers, the edge SOC allows for the collection and processing of security events, logs, and performance metrics in real-time, thus addressing the delay issues associated with the central SOC and enhancing overall security in the 0-RAN.
[0028] The present disclosure solves this technical problem as described in the embodiments below by implementing the edge SOC that leverages local processing power for threat detection and mitigation. The system continuously collects and analyzes real-time data from distributed 0-RAN components, including virtual and containerized network functions (VNF / CNF), cloud infrastructure, and system-level events. Further, various embodiments disclosed herein allow for the implementation of dynamic security policies in real-time, restricting abnormal behavior and isolating compromised assets as necessary. Therefore, the present disclosure suggests techniques for enabling faster threat detection, localized threat response, and proactive security management, improving overall security and operational performance in O-RAN system.
[0029] Thus, the present disclosure enables real-time continuous monitoring, data collection, and anomaly detection at the edge, and dynamic security policy implementation to address detected threats. Thereby, overall system security, efficiency, and performance in O-RAN are improved, reducing latency, enhancing visibility into security threats, and ensuring secure, real-time handling of security incidents.
[0030] Fig. 1 illustrates an exemplary environment for detecting real-time security threats by an edge security operation center (SOC) in an open radio access network (0-RAN) system and implementing dynamic security policy in real-time and isolating services or components at system level, in accordance with some embodiments of the present disclosure.
[0031] As shown in Fig. 1, the exemplary environment 100 includes one or more edge network entities 102a, 102b,..,102n (also referred hereinafter collectively referred to as plurality of edge network entities 102), and one or more target network entities 104a, 104b ,.., 104n (also referred hereinafter collectively referred to as a plurality of target network entities 104).
[0032] In some embodiments, the plurality of edge network entities 102 may refer to components in the O-RAN system, for example, distributed units (DUs) or radio units (RUs). In some embodiments, the plurality of edge network entities 102 may refer to components in the O-RAN system, for example, Centralized Unit (CU), O-Cloud, Service Management and Orchestration (SMO), or one or more network applications. The plurality of edge network entities 102 of the present disclosure is communicably coupled to the plurality of target network entities 104.
[0033] The plurality of edge network entities 102 may receive input data via a communication network 106 from the plurality of target network entities 104. In one non-limiting example, each edge network entity 102 includes a functionality of an edge security operations center (SOC) in the O-RAN system. As a non-limiting example, each of the plurality of edge network entities 102 may be deployed with a security xApp on edge data centers (DCs).
[0034] In an embodiment, each of the plurality of edge network entities 102 may be communicably coupled to a central SOC through the communications network 106 for centralized security management.
[0035] In some embodiments the plurality of edge network entities 102 may be implemented using various computing systems, such as servers, cloud computing systems, network servers, or cloud-based servers. In an embodiment, the plurality ofedge network entities 102 may function as a dedicated or cloud-based server located at the edge DCs. Further, the plurality of edge network entities 102 may include a processor (not shown in FIG. 1), and VO interface (not shown in FIG. 1), and memory (not shown in FIG. 1). In some embodiments, the memory is communicatively coupled to the processor. The memory stores instructions, executable by the processor, which, on execution, may cause the plurality of edge network entities 102 to detect security threats and implement dynamic security policies in real-time, as disclosed in the present disclosure. In some embodiments, the dynamic security policies are applied through the SMO, or O-Cloud. In a non-limiting embodiment, the dynamic security policies are applied through a combination of the SMO and the O-Cloud.
[0036] According to an embodiment of the present disclosure, each of the plurality of target network entities 104 may refer to a far edge DC. The far edge DCs with the edge SOCs may handle real-time security events while coordinating with the central SOC for non-real-time data analysis and remediation of identified security threats.
[0037] In some embodiments, the plurality of target network entities 104 may be implemented on various computing systems, such as servers, cloud computing systems, network servers, or cloud-based servers, specifically acting as DUs or RUs in the O-RAN architecture. In an embodiment, the plurality of target network entities 104 may function as a dedicated server or cloud-based server responsible for managing communication traffic and network operations. Further, the plurality of target network entities 104 may include a processor (not shown in FIG. 1), and I / O interface (not shown in FIG. 1), and memory (not shown in FIG. 1). In some embodiments, the memory is communicatively coupled to the processor. The memory stores instructions, executable by the processor, which, on execution, may cause the plurality of target network entities 104 to manage communication traffic, optimize network functions, and ensure the seamless flow of data, as disclosed in the present disclosure.
[0038] In an embodiment the communication network 106 that connects the plurality of edge network entities 102 and the plurality of target network entities 104 may include, without limitation, New Radio (NR)-based networks, a direct interconnection, Local Area Network (LAN), Wide Area Network (WAN), wireless networks (e.g.,4G / 5G), and the Internet. The communication network 106 enables seamless data transfer between the plurality of edge network entities 102 (e.g., DUs, RUs) and the plurality of target network entities 104 or central network entities, ensuring efficient and secure communication across the O-RAN system.
[0039] Herein, the plurality of edge network entities 102 may be one or more near realtime Radio Access Network (RAN) Intelligent Controller (RIC) entities, one or more RAN nodes, and a Service Management and Orchestration (SMO) framework. The SMO layer includes a non-real-time Radio Access Network (RAN) Intelligent Controller (RIC), which manages broader orchestration and optimization tasks in the O-RAN system. In an example, the plurality of edge network entities 102 may be designed to run in a cloud environment based on communication traffic demand, offering flexibility and scalability to accommodate varying network loads.
[0040] In operation, the plurality of edge network entities 102 (also referred hereinafter as the edge network entity 102) may receive input data from at least one of the plurality of target network entities 104 associated with the communications network 106. In an example, a security management engine (not shown) may be deployed at the edge network entity 102 to monitor and analyze the input data in realtime. In an embodiment, the security management engine may be an Edge security operation center (SOC). In another embodiment, the security management engine may be configured with one or more edge security functions. In some embodiments, the edge network entity 102 may be an O-Cloud entity. The edge network entity 102 communicates with the target network entity 104 via a secure communication channel (not shown), ensuring the efficient transfer of security events and performance metrics for further analysis and action.
[0041] In an embodiment, the security management engine compares one or more parameters of the input data with one or more corresponding reference parameters from a plurality of reference parameters. The reference parameters are pre-defined by the edge network entity 102 associated with the communications network 106.
[0042] In an embodiment, based on the comparison, the security management engine detects an anomaly corresponding to the at least one of the plurality of target networkentities 104 in real time. In an embodiment, the security management engine implements at least one of (i) a dynamic policy associated with the anomaly on a component and (ii) an isolation of the component in real-time.
[0043] In an example, the input data includes real-time input data. The real-time input data may include at least one of a plurality of security events, logs, and performance metrics. The plurality of security events includes at least one of process execution events, file system events, network events, resource consumption events, and cloud specific events.
[0044] The security management engine may be transmitting non -real -time input data to a central security management engine from the at least one of the plurality of target network entities 104.
[0045] In another embodiment, the security management engine generates a report comprising information associated with the anomaly. The information includes a timestamp corresponding to the anomaly, a description of a type of the anomaly, a severity level of the anomaly, an alert notification, and data relevant for secondary analysis by a base-station Centralized Unit (CU) associated with the communications network 106.
[0046] In an embodiment, the security management engine trains a machine learning (ML) model by providing historical data pertaining to the security management engine. The historical data includes at least one of input data, reference parameters, deviations, anomalies, components associated with the anomalies and dynamic policies.
[0047] Thereafter, the security management engine predicts the anomaly and the component corresponding to the anomaly. The security management engine dynamically generates the dynamic policy associated with the anomaly to be implemented using trained machine learning model.
[0048] In an embodiment, the security management engine evaluates the dynamic policy corresponding to the anomaly. In some embodiments, the dynamic policy is to be implemented by applying predefined security policies stored at the plurality of edge network entities 102.
[0049] Fig.2 is an exemplary environment for detecting non-real-time security threats by a central security operation center (SOC) in open radio access network (O-RAN) system, in accordance with an embodiment of the present disclosure.
[0050] As shown in FIG. 2, the exemplary environment 200 includes one or more edge network entities 102a-n and one or more target network entities 104a-n. The edge network entities 102a-n may be referred as near real-time controllers in the O-RAN system, while the target network entities 104a-n manage communication traffic. The one or more edge network entities 102a-n may include corresponding one or more security management engines (not shown). In an embodiment, each edge network entity 102 communicably connected to a central security management engine (not shown) deployed in a Central Unit (CU), as shown by the central unit 202. The one or more target network entities 104a-n may handle communication traffic management, and the central SOC manages non-real-time security threats. The central SOC includes the central security management engine, which monitors the security events transmitted from the one or more edge network entities 102a-n.
[0051] The communication network 106 provides secure data transfer between the one or more edge network entities 102a-n and the one or more target network entities 104a-n. The security management engine of the one or more edge network entities 102a-n transmits non-real-time data from the at least one of the one or more target network entities 104a-n to the central SOC for further analysis and monitoring. The non-real-time data may include logs and performance metrics.
[0052] In an embodiment, the central security management engine includes a security information and event management (SIEM) component or a security orchestration, automation and response (SOAR).
[0053] The central security management engine implements the SIEM or the SOAR for non-real-time data analysis and threat detection. The central SOC focuses on analyzing non-real-time input data which may not require immediate action but are critical for overall network security and performance. The non-real-time data is analyzed centrally to detect and respond to potential threats that have been flagged by the one or more edge network entities 102a-n.
[0054] Fig. 3 shows an exemplary flow chart illustrating method steps for managing communication traffic between two or more communication devices associated with one or more services, in accordance with some embodiments of the present disclosure.
[0055] As illustrated in FIG. 3, the method 300 may comprise one or more steps. The method 300 may be described in the general context of computer executable instructions. Generally, computer executable instructions can include routines, programs, objects, components, data structures, procedures, and functions, which perform particular functions or implement particular abstract data types.
[0056] The order in which the method 300 is described is not intended to be construed as a limitation, and any number of the method blocks described can be combined in any order to implement the method. Additionally, individual blocks may be deleted from the methods without departing from the scope of the subject matter described herein. Furthermore, the method can be implemented in any suitable hardware, software, firmware, or combination thereof.
[0057] At step 302, input data from at least one target network entity associated with a communications network may be received by a security management engine deployed at an edge network entity. For example, the at least one target network entity comprises at least one of one or more distributed units (DUs), or one or more radio units (RUs). For example, the edge network entity comprises one or more distributed units (DUs) and a Service Management and Orchestration (SMO) layer entity. For example, the edge network entity comprises one of a near real-time Radio Access Network (RAN) Intelligent Controller (RIC) and a RAN node.
[0058] For example, the input data comprises real-time input data comprising at least one of a plurality of security events, logs, and performance metrics. The plurality of security events comprises at least one of process execution events, file system events, network events, resource consumption events, and cloud specific events
[0059] At step 304, one or more parameters of the input data are compared with one or more corresponding reference parameters from a plurality of reference parameters by the security management engine.
[0060] For example, the reference parameters are pre-defined by the edge network entity associated with the communications network. For example, the reference parameters may include CPU utilization limits, memory usage thresholds, network traffic patterns, file access frequency, process execution duration, authentication attempt success rates, network latency, packet loss rates, resource allocation benchmarks, or expected time-based behavior.
[0061] At step 306, based on the comparison, an anomaly corresponding to the at least one target network entity, in real-time may be detected by the security management engine. For example, the anomaly may be detected when the CPU utilization of a Distributed Unit (DU) exceeds the predefined threshold, indicating potential overloading or abnormal activity in the communications network.
[0062] At step 308, at least one of (i) a dynamic policy associated with the anomaly on a component and (ii) an isolation of the component may be implemented in realtime by the security management engine and corresponding to the anomaly. For example, if the CPU utilization anomaly is detected, the security management engine may apply a dynamic policy to limit resource usage for the affected process or service. Further, the component experiencing the anomaly, such as the DU, may be isolated from the rest of the communications network to prevent further impact, ensuring the integrity and stability of the overall network.
[0063] In a preferred embodiment, non-real-time input data from the at least one target network entity may be transmitted by the security management engine and to a central security management engine. The central security management engine is deployed at a base-station Central Unit (CU) associated with the communications network. The non-real-time input data is transmitted to the central security management engine for analyzing the non-real-time input data based on the one or more corresponding reference parameters and perform a non-real-time detection of an anomaly corresponding to the at least one target network entity. For example, the one or more corresponding reference parameters may include bandwidth usage, packet loss rate, latency, etc.
[0064] For example, the central security management engine analyzes collected non-real-time data of bandwidth usage with reference bandwidth usage. For example, the reference bandwidth usage may be 100-200 megabytes per second (Mbps) during peak hours. An unauthorized data transfer may be identified by the central security management engine if there is an identification of the bandwidth usage exceeding the reference bandwidth usage at the peak hours.
[0065] In an alternate embodiment, a report comprising information associated with the anomaly may be generated. The information comprises at least one of a timestamp corresponding to the anomaly, a description of a type of the anomaly, a severity level of the anomaly, an alert notification, and data relevant for secondary analysis by a base-station Central Unit (CU) associated with the communications network.
[0066] In an alternate embodiment, a machine learning (ML) model by providing historical data pertaining to the security management engine may be trained. The historical data comprises at least one of input data, reference parameters, deviations, anomalies, components associated with the anomalies and dynamic policies.
[0067] In an alternate embodiment, the anomaly and the component corresponding to the anomaly may be predicted. Thereafter, the dynamic policy associated with the anomaly to be implemented may be dynamically generated using trained machine learning model.
[0068] FIG. 4 illustrates an embodiment of a device 400 wherein the method for detecting real-time security threats by an edge security operation center (SOC) may be implemented, according to the embodiments as disclosed herein. It will be appreciated that the device 400 is associated with the edge network entity 102. As shown in FIG.4, the device 400 comprises a processor 410, a memory 420, a storage component 430, an input component 440, an output component 450, a communication interface 460, and a bus 470.
[0069] The processor 410, as used herein, means any type of computational circuit that may comprise hardware elements and software elements. The processor 410 may be embodied as a multi -core processor, a single core processor, or a combination of oneor more multi-core processors and / or one or more single core processors, a distributed processing system, or the like. The processor 410 may be a Central Processing Unit (CPU), a graphics processing unit (GPU), an accelerated processing unit (APU), an application-specific integrated circuit (ASIC), or another type of processing component.
[0070] Memory 420 includes a non-transitory computer readable medium. Memory 420 includes a random-access memory (RAM), a read only memory (ROM), and / or another type of dynamic or static storage device (e.g., a flash memory, a magnetic memory, and / or an optical memory) that stores information and / or instructions for use by processor 410. The memory 420 comprises machine-readable instructions which are executable by the processor 410. These machine-readable instructions when executed by the processor 410 cause the processor 410 to perform one or more method steps of an embodiment described above.
[0071] Storage component 430 stores information and / or software related to the operation and use of the device 400. For example, storage component 430 may include a hard disk (e.g., a magnetic disk, an optical disk, a magneto-optic disk, and / or a solid-state disk), a compact disc (CD), a digital versatile disc (DVD), a floppy disk, a cartridge, a magnetic tape, and / or another type of non-transitory computer-readable medium, along with a corresponding drive.
[0072] Input component 440 is configured to receive information, such as user input. For example, the input component 440 may include, but not be limited to, a touch screen display, a keyboard, a keypad, a mouse, a button, a switch, and / or a microphone. Additionally, or alternatively, the input component 440 may include a sensor for sensing information (e.g., a global positioning system (GPS), an accelerometer, a gyroscope, and / or an actuator).
[0073] Output component 450 is configured to provide output information from the device 400. For example, the output component 450 may be, but not limited to, a display, a speaker, instructions to an external device, and / or one or more light-emitting diodes (LEDs).
[0074] Communication interface 460 is an interface that provides a communication connection to other devices, such as external devices and internal devices. The connection by the communication interface 460 can be a wired connection, a wireless connection, or a combination of wired and wireless connections, and can be a direct connection or an indirect connection via a communication network that exists between the device 400 and other devices. In other words, the standard of the communication interface 460 is not limited.
[0075] The bus 470 acts as an interconnect between the processor 410, the memory 420, the storage component 430, the input component 440, the output component 450, and the communication interface 460 of the device 400. The bus 470 may include a wired interconnection or a wireless interconnection.
[0076] The number and arrangement of components shown in FIG. 4 are provided as an example. In practice, device 400 may include additional components, fewer components, different components, or differently arranged components than those shown in FIG. 4. Additionally, or alternatively, a set of components (e.g., one or more components) of device 400 may perform one or more functions described as being performed by another set of components of device 400. Further, one or more method steps described in any of the embodiments may be performed utilizing a plurality of devices 400 in communication with one another.
[0077] In an embodiment [1], a method comprising: receiving, by a security management engine deployed at an edge network entity, input data from at least one target network entity associated with a communications network; comparing, by the security management engine, one or more parameters of the input data with one or more corresponding reference parameters from a plurality of reference parameters, wherein the reference parameters are pre-defined by the edge network entity associated with the communications network; detecting, by the security management engine and based on the comparison, an anomaly corresponding to the at least one target network entity, in real-time; and implementing, in real-time and corresponding to the anomaly, at least one of (i) a dynamic policy associated with the anomaly on a component and (ii) an isolation of the component.
[0078] In an embodiment [2], the input data, as described in the embodiment [1], comprises real-time input data comprising at least one of a plurality of security events, logs, and performance metrics. Further, the plurality of security events comprises at least one of process execution events, file system events, network events, resource consumption events, and cloud specific events.
[0079] In an embodiment [3], the method described in the embodiment [1], comprises: transmitting, by the security management engine and to a central security management engine, non-real-time input data from the at least one target network entity, wherein the central security management engine is deployed at a base-station Central Unit (CU) associated with the communications network, wherein, the non-real-time input data is transmitted to the central security management engine for analyzing the non-real-time input data based on the one or more corresponding reference parameters and perform a non-real-time detection of an anomaly corresponding to the at least one target network entity.
[0080] In an embodiment [4], the method described in the embodiment [1], comprises: generating a report comprising information associated with the anomaly, wherein the information comprises at least one of a timestamp corresponding to the anomaly, a description of a type of the anomaly, a severity level of the anomaly, an alert notification, and data relevant for secondary analysis by a base-station Central Unit (CU) associated with the communications network.
[0081] In an embodiment [5], the method described in the embodiment [1], comprises: training a machine learning (ML) model by providing historical data pertaining to the security management engine, wherein the historical data comprises at least one of input data, reference parameters, deviations, anomalies, components associated with the anomalies and dynamic policies; and predicting the anomaly and the component corresponding to the anomaly and dynamically generating the dynamic policy associated with the anomaly to be implemented using trained machine learning model.
[0082] In an embodiment [6], the method described in the embodiment [1], comprises: evaluating, by the security management engine, the dynamic policy corresponding tothe anomaly, wherein the dynamic policy is to be implemented by applying predefined security policies stored at the edge network entity.
[0083] In an embodiment [7], the at least one target network entity, as described in the embodiment [1], comprises at least one of: one or more distributed units (DUs), and one or more radio units (RUs).
[0084] In an embodiment [8], the edge network entity comprises one of one or more distributed units (DUs), a Service Management and Orchestration (SMO) layer entity, a near real-time Radio Access Network Intelligent Controller (Near-RT RIC) and a Radio Access Network (RAN) node, wherein the SMO layer entity comprises a non-real-time Radio Access Network Intelligent Controller (Non-RT RIC).
[0085] In an embodiment [9], the central security management engine, as described in the embodiment [1], comprises one of a security information and event management (SIEM) component or a security orchestration, automation and response (SOAR).
[0086] In an embodiment
[0010] , an apparatus is configured to: receive, by a security management engine deployed at an edge network entity, input data from at least one target network entity associated with a communications network; compare, by the security management engine, one or more parameters of the input data with one or more corresponding reference parameters from a plurality of reference parameters, wherein the reference parameters are pre-defined by the edge network entity associated with the communications network; detect, by the security management engine and based on the comparison, an anomaly corresponding to the at least one target network entity, in real-time; and implement, in real-time and corresponding to the anomaly, at least one of (i) a dynamic policy associated with the anomaly on a component and (ii) an isolation of the component.
[0087] In an embodiment
[0011] , the input data, as described in the embodiment
[0010] , comprises real-time input data comprising at least one of a plurality of security events, logs, and performance metrics. The plurality of security events comprises at least one of process execution events, file system events, network events, resource consumption events, and cloud specific events.
[0088] In an embodiment
[0012] , the apparatus described in the embodiment
[0010] , is further configured to transmit, by the security management engine and to a central security management engine, non-real-time input data from the at least one target network entity, wherein the central security management engine is deployed at a basestation Central Unit (CU) associated with the communications network, wherein, the non-real-time input data is transmitted to the central security management engine for analyzing the non-real-time input data based on the one or more corresponding reference parameters and perform a non-real-time detection of an anomaly corresponding to the at least one target network entity.
[0089] In an embodiment
[0013] , the apparatus described in the embodiment
[0010] , is further configured to generate a report comprising information associated with the anomaly, wherein the information comprises at least one of a timestamp corresponding to the anomaly, a description of a type of the anomaly, a severity level of the anomaly, an alert notification, and data relevant for secondary analysis by a base-station Central Unit (CU) associated with the communications network.
[0090] In an embodiment
[0014] , the apparatus described in the embodiment
[0010] , is further configured to: train a machine learning (ML) model by providing historical data pertaining to the security management engine, wherein the historical data comprises at least one of input data, reference parameters, deviations, anomalies, components associated with the anomalies and dynamic policies; and predict the anomaly and the component corresponding to the anomaly and dynamically generating a dynamic policy associated with the anomaly to be implemented using trained machine learning model.
[0091] In an embodiment
[0015] , the apparatus described in the embodiment
[0010] , is configured to evaluate, by the security management engine, the dynamic policy corresponding to the anomaly, wherein the dynamic policy is to be implemented by applying predefined security policies stored at the edge network entity.
[0092] In an embodiment
[0016] , the at least one target network entity, as described in embodiment
[0010] , comprises at least one of: one or more distributed units (DUs), and one or more radio units (RUs).
[0093] In an embodiment
[0017] , the edge network entity, as described in embodiment
[0010] , comprises one of: one or more distributed units (DUs), a Service Management and Orchestration (SMO) layer entity, a near real-time Radio Access Network Intelligent Controller (RIC), and a Radio Access Network (RAN) node, wherein the SMO layer entity comprises a non-real-time Radio Access Network Intelligent Controller (Non-RT RIC).
[0094] In an embodiment
[0018] , the central security management engine, as described in embodiment
[0010] , comprises one of: a security information and event management (SIEM) component or a security orchestration, automation and response (SOAR).
[0095] In an embodiment
[0019] , a non-transitory computer-readable medium having program instructions stored thereon, executed by an apparatus for wireless communication, is disclosed. The program instructions may comprise: receiving, by a security management engine deployed at an edge network entity, input data from at least one target network entity associated with a communications network; comparing, by the security management engine, one or more parameters of the input data with one or more corresponding reference parameters from a plurality of reference parameters, wherein the reference parameters are pre-defined by the edge network entity associated with the communications network; detecting, by the security management engine and based on the comparison, an anomaly corresponding to the at least one target network entity, in real-time; and implementing, in real-time corresponding to the anomaly, at least one of (i) a dynamic policy associated with the anomaly on a component and (ii) an isolation of the component.
[0096] In a non-limiting embodiment of the present disclosure, one or more non-transitory computer-readable media may be utilized for implementing the embodiments consistent with the present disclosure. A computer-readable medium refers to any type of physical memory (such as the memory 420) on which information or data readable by a processor may be stored. Thus, a computer-readable media may store one or more instructions for execution by the at least one processor 410, including instructions for causing the at least one processor 410 to perform steps or stages consistent with the embodiments described herein. The term “computer-readablemedia” should be understood to include tangible items and exclude carrier waves and transient signals. By way of example, and not limitation, such computer-readable media can comprise Random Access Memory (RAM), Read-Only Memory (ROM), volatile memory, non-volatile memory, hard drives, Compact Disc (CD) ROMs, Digital Video Disc (DVDs), flash drives, disks, and any other known physical storage media.
[0097] Thus, certain aspects may comprise a computer program product for performing the operations presented herein. For example, such a computer program product may comprise a computer readable media having instructions stored (and / or encoded) thereon, the instructions being executable by one or more processors to perform the operations described herein. For certain aspects, the computer program product may include packaging material.
[0098] The various illustrative logical blocks, and operations described in connection with the present disclosure may be implemented or performed with a general-purpose processor, discrete gate or transistor logic, discrete hardware components or any combination thereof designed to perform the functions described herein. A general-purpose processor may include a microprocessor, but in the alternative, the processor may include any commercially available processor, controller, microcontroller, or state machine. A processor may also be implemented as a combination of computing devices, e.g., a plurality of microprocessors, or any other such configuration.
[0099] The foregoing description of the specific embodiments will so fully reveal the general nature of the embodiments herein that others can, by applying current knowledge, readily modify or adapt for various applications such specific embodiments without departing from the generic concept, and, therefore, such adaptations and modifications should and are intended to be comprehended within the meaning and range of equivalents of the disclosed embodiments. It is to be understood that the phraseology or terminology employed herein is for the purpose of description and not of limitation. Therefore, while the embodiments herein have been described in terms of preferred embodiments, those skilled in the art will recognize that theembodiments herein can be practiced with modification within the scope of the embodiments as described herein.
Claims
1. CLAIMSWe claim:
1. A method comprising:receiving, by a security management engine deployed at an edge network entity, input data from at least one target network entity associated with a communications network;comparing, by the security management engine, one or more parameters of the input data with one or more corresponding reference parameters from a plurality of reference parameters, wherein the reference parameters are pre-defined by the network entity associated with the communications network;detecting, by the security management engine and based on the comparison, an anomaly corresponding to the at least one target network entity, in real-time; and implementing, in real-time and corresponding to the anomaly, at least one of (i) a dynamic policy associated with the anomaly on the component and (ii) an isolation of the component.
2. The method as claimed in claim 1, wherein the input data comprises real-time input data comprising at least one of a plurality of security events, logs and performance metrics, and wherein the plurality of security events comprises at least one of process execution events, file system events, network events, resource consumption events, and cloud specific events.
3. The method as claimed in claim 1, wherein the method further comprises:transmitting, by the security management engine and to a central security management engine, non-real-time input data from the at least one target network entity, wherein the central security management engine is deployed at a base-station Central Unit (CU) associated with the communications network, wherein, the non- real-time input data is transmitted to the central security management engine for analyzing the non-real-time input data based on the one or more corresponding reference parameters and perform a non-real-time detection of an anomaly corresponding to the at least one target network entity.
4. The method as claimed in claim 1, wherein the method further comprises:generating a report comprising information associated with the anomaly, wherein the information comprises at least on of a timestamp corresponding to the anomaly, a description of a type of the anomaly, a severity level of the anomaly, an alert notification, and data relevant for secondary analysis by a base-station Central Unit (CU) associated with the communications network.
5. The method as claimed in claim 4, wherein the method further comprises:training a machine learning (ML) model by providing historical data pertaining to the security management engine, wherein the historical data comprises at least one of input data, reference parameters, deviations, anomalies, components associated with the anomalies and dynamic policies; andpredicting the anomaly and the component corresponding to the anomaly and dynamically generating a dynamic policy associated with the anomaly to be implemented using trained machine learning model.
6. The method as claimed in claim 5, wherein the method further comprises:evaluating, by the security management engine, the dynamic policy corresponding to the anomaly, wherein the dynamic policy is to be implemented by applying predefined security policies stored at the edge network entity.
7. The method as claimed in claim 1, wherein the at least one target network entity comprises at least one of: one or more distributed units (DUs), and one or more radio units (RUs).
8. The method as claimed in claim 1, wherein the edge network entity comprises one of: one or more distributed units (DUs), a Service Management and Orchestration (SMO) layer entity, a near real-time Radio Access Network Intelligent Controller (Near-RT RIC), and a Radio Access Network (RAN) node, wherein the SMO layer entity comprises a non-real-time Radio Access Network Intelligent Controller (Non-RT RIC).
9. The method as claimed in claim 1, wherein the central security management engine comprises one of: a security information and event management (SIEM) component or a security orchestration, automation and response (SOAR).
10. An apparatus configured to:receive, by a security management engine deployed at an edge network entity, input data from at least one target network entity associated with a communications network;compare, by the security management engine, one or more parameters of the input data with one or more corresponding reference parameters from a plurality of reference parameters, wherein the reference parameters are pre-defined by the network entity associated with the communications network;detect, by the security management engine and based on the comparison, an anomaly corresponding to the at least one target network entity, in real-time; and implement, in real-time and corresponding to the anomaly, at least one of (i) a dynamic policy associated with the anomaly on the component and (ii) an isolation of the component.
11. The apparatus as claimed in claim 10, wherein the input data comprises realtime input data comprising at least one of a plurality of security events, logs and performance metrics, and wherein the plurality of security events comprises at least one of process execution events, file system events, network events, resource consumption events, and cloud specific events.
12. The apparatus as claimed in claim 10, further configured to:transmit, by the security management engine and to a central security management engine, non-real-time input data from the at least one target network entity, wherein the central security management engine is deployed at a base-station Central Unit (CU) associated with the communications network, wherein, the non-real-time input data is transmitted to the central security management engine for analyzing the non-real-time input data based on the one or more corresponding reference parameters and perform a non-real-time detection of an anomaly corresponding to the at least one target network entity.
13. The apparatus as claimed in claim 10, further configured to:generate a report comprising information associated with the anomaly, wherein the information comprises at least on of a timestamp corresponding to theanomaly, a description of a type of the anomaly, a severity level of the anomaly, an alert notification, and data relevant for secondary analysis by a base-station Central Unit (CU) associated with the communications network.
14. The apparatus as claimed in claim 13, further configured to:train a machine learning (ML) model by providing historical data pertaining to the security management engine, wherein the historical data comprises at least one of input data, reference parameters, deviations, anomalies, components associated with the anomalies and dynamic policies; andpredict the anomaly and the component corresponding to the anomaly and dynamically generating a dynamic policy associated with the anomaly to be implemented using trained machine learning model.
15. The apparatus as claimed in claim 14, further configured to:evaluate, by the security management engine, the dynamic policy corresponding to the anomaly, wherein the dynamic policy is to be implemented by applying predefined security policies stored at the edge network entity .
16. The apparatus as claimed in claim 10, wherein the at least one target network entity comprises at least one of: one or more distributed units (DUs), and one or more radio units (RUs).
17. The apparatus as claimed in claim 10, wherein the edge network entity comprises one of: one or more distributed units (DUs), a Service Management and Orchestration (SMO) layer entity, a near real-time Radio Access Network Intelligent Controller (RIC), and a Radio Access Network (RAN) node, wherein the SMO layer entity comprises a non-real-time Radio Access Network Intelligent Controller (Non-RT RIC).
18. The apparatus as claimed in claim 10, wherein the central security management engine comprises one of: a security information and event management (SIEM) component or a security orchestration, automation and response (SOAR).
19. A non-transitory computer-readable medium having program instructions stored thereon, executed by an apparatus for wireless communication, for:receiving, by a security management engine deployed at an edge network entity, input data from at least one target network entity associated with a communications network;comparing, by the security management engine, one or more parameters of the input data with one or more corresponding reference parameters from a plurality of reference parameters, wherein the reference parameters are pre-defined by the network entity associated with the communications network;detecting, by the security management engine and based on the comparison, an anomaly corresponding to the at least one target network entity, in real-time; and implementing, in real-time and corresponding to the anomaly, at least one of (i) a dynamic policy associated with the anomaly on the component and (ii) an isolation of the component.