Method and apparaus for detecting and mitigating DDOS attacks in communication network system
An ML-based framework with adaptive firewalls dynamically adjusts traffic rates to mitigate DDoS attacks in CP CIoT networks, addressing vulnerabilities in basic electronic devices and ensuring network resilience.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- SAMSUNG ELECTRONICS CO LTD
- Filing Date
- 2025-11-14
- Publication Date
- 2026-05-21
Smart Images

Figure KR2025018821_21052026_PF_FP_ABST
Abstract
Description
METHOD AND APPARAUS FOR DETECTING AND MITIGATING DDOS ATTACKS IN COMMUNICATION NETWORK SYSTEM
[0001] The present disclosure is related to the field of a communication network system. More particularly, the present disclosure is related to detection and mitigation of distributed denial-of-service (DDoS) attacks in a control plane of a telecommunication network system.
[0002] In contemporary telecommunications networks, control plane traffic within core and access networks predominantly includes signaling traffic that exhibits consistent and predictable patterns. This signaling traffic is essential for the management and coordination of network activities. However, the landscape of control plane traffic has evolved with the introduction of control plane cellular Internet of Things (CP CIoT) optimizations in Releases 16 and 17 of the 3rd Generation Partnership Project (3GPP) specifications. These optimizations enable basic electronic devices to transmit user data via the control plane, thereby expanding the utility and functionality of such devices within cellular networks.
[0003] Despite these advancements, the integration of CP CIoT optimizations has unveiled several vulnerabilities inherent to basic electronic devices. These devices, due to their limited computational and security capabilities, are particularly susceptible to exploitation. This susceptibility renders them potential targets for Distributed Denial of Service (DDoS) attacks. The 3GPP specifications aim to support a high density of electronic devices per square kilometer, thereby amplifying the potential impact of any security breach on the control plane infrastructure.
[0004] The risk posed by DDoS attacks has become more pronounced with the CP CIoT optimization. Compromised electronic devices that are already authenticated within a network can be leveraged by attackers to execute DDoS attacks. These attacks can lead to a substantial increase in traffic, which has the potential to overwhelm the control plane infrastructure. Fast path applications manage the external interfaces of control plane nodes and employ static logic for packet rate limiting. However, this rate limiting mechanism is traffic agnostic and reactive. It applies a uniform rate limiting policy to all traffic, irrespective of its nature, and struggles to adapt effectively during DDoS attacks. Consequently, in scenarios where commercial networks face millions of requests per second, the control plane infrastructure can experience severe degradation.
[0005] These circumstances underscore a significant risk to the control plane infrastructure of network operators. Hence, is desirable to address the above mentioned problems and disadvantages or at least provide a useful alternative.
[0006] An object of the embodiments herein is to provide a system and method for detecting and mitigating distributed denial-of-service (DDoS) attacks in a control plane of a telecommunication network system.
[0007] An object of the embodiments herein is to provide a machine learning (ML) framework aimed at the proactive prevention of DDoS attacks within an encrypted control plane interface connecting the RAN and Core or NGAP interface, addressing threats that can arise from authenticated IoT / electronic devices within the network.
[0008] An object of the embodiments herein is to provide a mechanism to identify and compose a list of compromised electronic devices.
[0009] An object of the embodiments herein is to provide an adaptive firewall that applies dynamic rate limiting to incoming traffic for a duration determined heuristically by a machine learning engine.
[0010] An object of the embodiments herein is to enable the ML engine to determine if the traffic from compromised electronic devices needs to be blocked in order to mitigate attacks without the need for human intervention.
[0011] An object of the embodiments herein is to provide a framework for implementing adaptive firewalls at an O-RAN with the help of an ML-based attack detection and mitigation in an AMF of the core network.
[0012] In an aspect, a method for detecting and mitigating distributed denial-of-service (DDoS) attacks by a network apparatus in a communication network system is provided. The method may comprise receiving data from a plurality of electronic devices through a control plane interface. The method may comprise monitoring one or more key performance indicators (KPIs) based on the data received from the plurality of electronic devices. The method may comprise determining one or more anomalies in the received data based on the monitored one or more KPIs. The method may comprise detecting at least one DDoS attack based on the one or more anomalies using a DDoS detection ML model. The method may comprise generating a DDoS control policy for mitigating the at least one DDoS attack using a DDoS mitigation ML model.
[0013] The generated DDoS control policy may be used by an adaptive firewall to control the rate of data received through the control plane interface from the plurality of electronic devices identified as compromised by the DDoS mitigation ML model.
[0014] The one or more KPIs may comprise at least one of a network pattern, traffic flow statistics, a packet header, a packet length variance and content, a number of packets flow, a flow duration ratio, a total payload per session, or control plane (CP) cellular internet of things (CIoT) traffic KPIs statistics.
[0015] Detecting the at least one DDoS attack may comprise determining data statistics based on the monitored one or more KPIs and metadata based to a plurality of parameters at multiple regular intervals. Detecting the at least one DDoS attack may comprise determining a DDoS prediction score using the DDoS detection ML model (606) based on the data statistics determined. The DDoS prediction score may represent a confidence level of an occurrence of the at least one DDoS attack.
[0016] Generating the DDoS control policy may comprise determining one or more dynamic rate limiting parameters per session for mitigation of the at least one DDoS attack. Generating the DDoS control policy may comprise determining a list of compromised electronic devices from the plurality of electronic devices for dynamic rate limiting generated by the DDoS mitigation ML model based on the DDoS prediction score determined along with the data statistics associated with the data. Generating the DDoS control policy may comprise determining whether the DDoS prediction score determined is greater than a predefined threshold. Generating the DDoS control policy may comprise generating the DDoS control policy for the list of compromised electronic devices determined when the DDoS prediction score is greater than the predefined threshold.
[0017] The method may comprise generating one or more alarms for notifying an operator associated with the list of compromised electronic devices for each DDoS attack detected.
[0018] Generating the DDoS control policy for the list of compromised electronic devices determined when the DDoS prediction score is greater than the predefined threshold may comprise updating a firewall rule in a firewall policy database of an adaptive firewall of the network apparatus based on the generated DDoS control policy for the list of compromised electronic devices to mitigate impending DDoS attacks. Generating the DDoS control policy for the list of compromised electronic devices determined when the DDoS prediction score is greater than the predefined threshold may comprise determining whether a current rate of data traffic of each compromised electronic device in the list of compromised electronic devices is greater than a maximum allowed data transmission rate. Generating the DDoS control policy for the list of compromised electronic devices determined when the DDoS prediction score is greater than the predefined threshold may comprise allowing the network apparatus to forward one or more data packets from at least one compromised electronic device of the list of compromised electronic devices if the current rate of the data traffic is not greater than the maximum allowed data transmission rate. Generating the DDoS control policy for the list of compromised electronic devices determined when the DDoS prediction score is greater than the predefined threshold may comprise dropping the one or more data packets from at least one compromised electronic device of the list of compromised electronic devices if the current rate of the data traffic is greater than the maximum allowed data transmission rate.
[0019] Dynamic rate limiting may be performed for a predicted time duration associated with the generated DDoS control policy.
[0020] The adaptive firewall of the network apparatus may be implemented in one of an Access and Mobility Management Function (AMF) where data is filtered at an entry point of the AMF (106), and in an open radio access network (O-RAN).
[0021] Detection of the DDoS attacks by the DDoS detection ML model and generation of the DDOS control policy by the DDoS mitigation ML model may be performed in the AMF, and wherein the AMF transmits the generated DDoS control policy to the O-RAN.
[0022] The method may comprise determining a time duration within which a comparison process of the current rate of the data traffic with the maximum allowed data transmission rate for each compromised electronic device is to be performed. The method may comprise updating the firewall policy database after expiration of the time duration.
[0023] In an aspect, a network apparatus for detecting and mitigating distributed denial-of-service (DDoS) attacks in a communication network system is provided. The network apparatus may comprise memory storing instructions; and at least one processor operably coupled to the memory. The instructions, when executed by the at least one processor individually or collectively, may cause the network apparatus to receive data from a plurality of electronic devices through a control plane interface. The instructions, when executed by the at least one processor individually or collectively, may cause the network apparatus to monitor one or more key performance indicators (KPIs) based on the data received from the plurality of electronic devices. The instructions, when executed by the at least one processor individually or collectively, may cause the network apparatus to determine one or more anomalies in the received data based on the monitored one or more KPIs. The instructions, when executed by the at least one processor individually or collectively, may cause the network apparatus to detect at least one DDoS attack based on the one or more anomalies using a DDoS detection ML model. The instructions, when executed by the at least one processor individually or collectively, may cause the network apparatus to generate a DDoS control policy for mitigating the at least one DDoS attack using a DDoS mitigation ML model.
[0024] In an aspect, a non-transitory computer readable storage medium storing instructions is provided. The instructions, when executed by at least one processor of a network apparatus individually or collectively, may cause the network apparatus to receive data from a plurality of electronic devices through a control plane interface. The instructions, when executed by the at least one processor individually or collectively, may cause the network apparatus to monitor one or more key performance indicators (KPIs) based on the data received from the plurality of electronic devices. The instructions, when executed by the at least one processor individually or collectively, may cause the network apparatus to determine one or more anomalies in the received data based on the monitored one or more KPIs. The instructions, when executed by the at least one processor individually or collectively, may cause the network apparatus to detect at least one DDoS attack based on the one or more anomalies using a DDoS detection ML model. The instructions, when executed by the at least one processor individually or collectively, may cause the network apparatus to generate a DDoS control policy for mitigating the at least one DDoS attack using a DDoS mitigation ML model.
[0025] These and other aspects of the embodiments herein will be better appreciated and understood when considered in conjunction with the following description and the accompanying drawings. It should be understood, however, that the following descriptions, while indicating preferred embodiments and numerous specific details thereof, are given by way of illustration and not of limitation. Many changes and modifications be made within the scope of the embodiments herein.
[0026] These and other features, aspects, and advantages of the present embodiments are illustrated in the accompanying drawings, throughout which like reference letters indicate corresponding parts in the various figures. The embodiments herein will be better understood from the following description with reference to the drawings, in which:
[0027] Fig. 1 is a block diagram that illustrates a CP CIoT 5GS Optimization according to the prior art.
[0028] Fig. 2A is a block diagram that illustrates a schematic of a network apparatus implemented to carry out the disclosed subject matter according to an embodiment as disclosed herein.
[0029] Fig. 2B is a block diagram that illustrates an exploded view of the DDoS attack detection controller of the network apparatus of Fig. 2A according to an embodiment as disclosed herein.
[0030] Fig. 2C is a block diagram that illustrates an exploded view of the DDoS attack mitigation controller of the network apparatus of Fig. 2A according to an embodiment as disclosed herein.
[0031] Fig. 2D is a block diagram that illustrates an exploded view of the adaptive firewall of the network apparatus of Fig. 2A implemented in a core network according to an embodiment as disclosed herein.
[0032] Fig. 2E is a block diagram that illustrates an exploded view of the adaptive firewall of the network apparatus of Fig. 2A implemented in an O-RAN CU according to an embodiment as disclosed herein.
[0033] Fig. 3 is a sequence diagram that illustrates a scenario where the network apparatus is in a unified mode according to an embodiment as disclosed herein.
[0034] Fig. 4 is a sequence diagram that illustrates a scenario where the network apparatus is in a distributed mode according to an embodiment as disclosed herein.
[0035] Fig. 5A and Fig. 5B are flow diagrams that illustrate a method for detecting and mitigating DDoS attacks in a communication network system according to an embodiment as disclosed herein.
[0036] The embodiments herein and the various features and advantageous details thereof are explained more fully with reference to the non-limiting embodiments that are illustrated in the accompanying drawings and detailed in the following description. Descriptions of well-known components and processing techniques are omitted so as to not unnecessarily obscure the embodiments herein. Also, the various embodiments described herein are not necessarily mutually exclusive, as some embodiments can be combined with a plurality of other embodiments to form new embodiments. The term "or" as used herein, refers to a non-exclusive or, unless otherwise indicated. The examples used herein are intended merely to facilitate an understanding of ways in which the embodiments herein can be practiced and to further enable those skilled in the art to practice the embodiments herein. Accordingly, the examples are not be construed as limiting the scope of the embodiments herein.
[0037] As is existing in the field, embodiments are described and illustrated in terms of blocks that carry out a described function or functions. These blocks, which referred to herein as managers, units, modules, hardware components or the like, are physically implemented by analog and / or digital circuits such as logic gates, integrated circuits, microprocessors, microcontrollers, memory circuits, passive electronic components, active electronic components, optical components, hardwired circuits, and the like, and optionally be driven by firmware and software. The circuits, for example, be embodied in a plurality of semiconductor chips, or on substrate supports such as printed circuit boards, and the like. The circuits constituting a block be implemented by dedicated hardware, or by a processor (e.g., a plurality of programmed microprocessors and associated circuitry), or by a combination of dedicated hardware to perform some functions of the block and a processor to perform other functions of the block. Each block of the embodiments be physically separated into two or more interacting and discrete blocks without departing from the scope of the proposed method. Likewise, the blocks of the embodiments be physically combined into more complex blocks without departing from the scope of the proposed method.
[0038] The accompanying drawings are used to help easily understand various technical features and it is understood that the embodiments presented herein are not limited by the accompanying drawings. As such, the proposed method is construed to extend to any alterations, equivalents and substitutes in addition to those which are particularly set out in the accompanying drawings. Although the terms first, second, etc. used herein to describe various elements, these elements are not be limited by these terms. These terms are generally used to distinguish one element from another.
[0039] Fig. 1 is a block diagram that illustrates a CP CIoT 5GS Optimization according to the prior art. As shown, the block diagram includes a plurality of electronic devices (102A-N), a radio access network (RAN) (104), an AMF (106), a session management function (SMF) (108), a user plane function (UPF) (110), an extended data network (112), and an IoT application server (AS) / application function (AF) (114). For instance, the plurality of electronic devices (102A-N) includes, but not be limited to, a smartphone, a personal computer (PC), a laptop, a tablet, a personal device assistant, a camera, an IoT device, and the like.
[0040] The RAN (104) connects the plurality of electronic devices (102A-N) to the core network. The RAN (104) is crucial for ensuring reliable connectivity and managing the radio resources needed for effective data transmission. The AMF (106) is responsible for handling user access to the network and managing mobility. The AMF (106) is essential for maintaining continuous service and optimizing resource allocation. The SMF (108) manages the establishment, modification, and termination of sessions for data transfer. The SMF (108) ensures that the data flows smoothly between the electronic devices (102A-N) and the network, optimizing the use of network resources and maintaining quality of service. The UPF (110) is responsible for the actual data forwarding and routing within the network. The UPF (110) handles the user data traffic, ensuring that data packets are transmitted efficiently between the electronic devices (102A-N) and the extended data network (112). The extended data network (112) represents the broader network infrastructure that supports various data services and applications. The data services / applications includes cloud services, data storage, and processing capabilities that enable advanced analytics and real-time data processing for IoT applications run by the IoT AS / AF (114).
[0041] The newly introduced CP CIoT 5GS Optimization in 3GPP Release 16 enables the integration of CIoT data within control plane messages exchanged between the plurality of electronic devices (102A-N) and the AMF (106). This innovation minimizes the need for dedicated user plane allocation for small payloads. The electronic devices (102A-N) operate with basic applications largely driven by the necessity for efficient power management to extend battery life. Technologies such as CIoT, NB-IoT, and other forms of massive machine-type communication (mMTC) face strict resource limitations, including low power consumption, reduced data rates, and constrained processing capabilities. However, these technologies provide significant benefits, including enhanced coverage, prolonged battery life, and cost efficiency for IoT implementations. Nonetheless, they also present challenges: limited processing power, lower bandwidth data rates, simplified protocol stacks, resource constraints, and inadequate security measures, rendering them vulnerable to exploitation as potential attack vectors. These vulnerabilities can be exploited by off-path attackers to facilitate DDoS attacks.
[0042] Malicious entities can take advantage of this optimization to execute a targeted DDoS attack using a multitude of compromised low-capability devices directed at an interface of the AMF (106), resulting in service disruptions at the AMF (106). These attacks can be initiated from various CUs located in different geographical regions by off-path attackers, converging at the core network, particularly at the AMF (106), which serves as the entry point for Core CP. Such scenarios could lead to the AMF (106) becoming overloaded, thereby causing interruptions in network services for mobile devices. This can result in failures in registration of the electronic devices (102A-N), mobility management issues, session establishment failures, security vulnerabilities such as authentication failures, and negative effects on overall network management.
[0043] The proposed solution discloses a next-generation AI-powered (NGAP) armour that utilizes a machine learning-based adaptive firewall to defend against DDoS attacks executed through compromised electronic devices targeting the NGAP interface of the AMF (106). The NGAP armour can be referred to as a network apparatus. Both terms have been used interchangeably and have the same meaning.
[0044] The 3GPP is working towards enabling support for up to 1 million electronic devices (102A-N) per square kilometres. However, the presence of basic firmware in these electronic devices (102A-N) presents a significant risk to the control plane infrastructure. The large number of electronic devices (102A-N) and the aggregation of control plane traffic in the AMF (106) necessitate an ML-based approach to detect anomalies in traffic patterns within milliseconds of a coordinated attack, allowing for timely mitigation. The proposed solution features a DDoS detection ML model designed to identify potential DDoS attacks targeting the control plane infrastructure.
[0045] The fast path application, which oversees external interfaces, is already gathering numerous key performance indicators (KPIs) related to packet statistics. These KPIs are utilized to train the DDoS detection ML model that discerns traffic trends and differentiates between legitimate and malicious traffic. The solution aims to minimize computational and memory overhead by utilizing two distinct ML models. The DDoS detection model is specifically designed to quickly predict the likelihood of an impending DDoS attack. It has been trained to recognize various types of DDoS attacks affecting the control plane. Meanwhile, the DDoS mitigation ML model focuses on identifying session-specific anomalies in traffic patterns and compiling a list of compromised electronic devices involved in launching attacks against the control plane infrastructure.
[0046] The DDoS mitigation ML model helps in mitigation of DDoS attacks in a control plane by generating an adaptive rate control policy which can be applied to the firewall rules. An ML-powered firewall implements the adaptive rate control policy where dynamic rate limiting of control plane messages can be applied for all suspicious connections, which are compromised electronic devices identified by their unique NGAP ID. Two possible solutions are proposed for implementing the firewall rules.
[0047] Proposal 1 involves a Unified Mode NGAP Armour ML-powered DDoS detection and attack mitigation with an adaptive firewall in the AMF (106).
[0048] Proposal 2 suggests a Distributed Mode NGAP Armour ML-powered DDoS detection in the AMF (106) and attack mitigation with a distributed adaptive firewall at O-RAN.
[0049] In the proposal 2, the AMF (106) utilizes the ML models to identify DDoS attacks and generate a list of compromised electronic devices. This list is subsequently shared with the O-RAN to facilitate the implementation of an adaptive firewall within the CU. The RIC (RAN Intelligent Controller) of the O-RAN is equipped to execute custom applications known as xApps. The solution proposed by the AMF (106) interacts with a firewall configuration manager (xApp) through the CU-RIC E2 interface, enabling the ML Powered Adaptive firewall with dynamic rate limiting for the identified compromised electronic devices. Consequently, this solution offers an automated approach to detect and isolate compromised electronic devices, minimizing the need for human intervention. Further, it can send notification alerts to operators for potential manual intervention during DDoS attacks.
[0050] Fig. 2A is a block diagram that illustrates a schematic of the network apparatus (202) implemented to carry out the disclosed subject matter according to an embodiment as disclosed herein. The NGAP armor refers to the network apparatus (202). Both terms have been used interchangeably and have the same meaning.
[0051] The network apparatus (202) includes various hardware and software components that facilitate communication between user equipment and network infrastructure. Examples of the network apparatus (202) can include, but is not limited to Base Stations (such as macro cells, small cells, femtocells, picocells) for wireless communication, Antennas and RF Units (e.g., MIMO, beamforming) to enhance signal coverage and data throughput, Core Network Equipment (e.g., MMEs, S-GWs, P-GWs in 4G; AMFs, UPFs in 5G) for data routing, mobility, and session control, Network Function Virtualization (NFV) and Software-Defined Networking (SDN) for dynamic resource allocation and scalability, Edge Computing Nodes (e.g., MEC servers) for low-latency processing, Backhaul and Transport Equipment (e.g., fiber-optic links, microwave relays, Ethernet switches) to connect base stations to the core network, Network Management Systems (NMS) and Operation Support Systems (OSS) for network configuration, fault management, and optimization, Radio Network Controllers (RNCs) in 3G, Distributed Units (DUs), and Centralized Units (CUs) in 5G, Network Slicing Components for virtualized resource allocation, Security elements (e.g., Firewalls, IDS, AAA Servers) for secure communication.
[0052] Examples of the wireless communication network system include, but are not limited to, Cellular Networks (such as 2G, 3G, 4G, 5G, Beyond 5G (B5G) / 6G, or advanced cellular networks), Local Area Networks (LANs) (such as Wi-Fi, Li-Fi, etc.), Personal Area Networks (PANs) (such as Bluetooth, Zigbee, Z-Wave, etc.), Wide Area Networks (WANs) (such as Satellite Communication Networks, Long Range Wide Area Network, Narrowband IoT, Low-bandwidth communication for IoT, etc.), Metropolitan Area Networks (MANs), Machine-to-Machine (M2M), Ad Hoc and Mesh Networks, Emerging and Advanced Networks.
[0053] Examples of the electronic device (102) can include, but are not limited to, Consumer Electronics (such as Mobile Phones and Smartphones), Tablets, Wearable Devices, Computing Devices (such as Laptops, Notebooks, Desktops, Workstations, etc.), IoT Devices, Automotive Systems (such as connected cars, Autonomous Vehicles, Vehicle-to-Everything (V2X) communication devices, etc.), Enterprise Devices such as robotics, Specialized Equipment (such as Medical Devices, Public Safety Devices, etc.), Media Devices (such as Gaming Consoles, Streaming Devices, etc.).
[0054] In an embodiment, Fig. 2, the network apparatus (202) includes a processor (204), a memory (206), an I / O interface (208), a traffic analyzer controller (210), a DDoS attack detection controller (212), a DDoS attack mitigation controller (214), and an adaptive firewall (216) coupled to the processor (204) and the memory (206). The components are explained in further detail below.
[0055] The processor (204) communicates with the memory (206), the I / O interface (208), the traffic analyzer controller (210), the DDoS attack detection controller (212), and the DDoS attack mitigation controller (214). The processor (204) is configured to execute instructions stored in the memory (206) and to perform various processes. The processor (204) includes one or a plurality of processors, is a general-purpose processor such as a central processing unit (CPU), an application processor (AP), or the like, a graphics-only processing unit such as a graphics processing unit (GPU), a visual processing unit (VPU), and / or an Artificial Intelligence (AI) dedicated processor such as a neural processing unit (NPU).
[0056] The memory (206) includes storage locations to be addressable through the processor (204). The memory (206) is not limited to a volatile memory and / or a non-volatile memory. Further, the memory (206) includes a plurality of computer-readable storage media. The memory (206) includes non-volatile storage elements. For example, non-volatile storage elements includes magnetic hard disks, optical disks, floppy disks, flash memories, or forms of electrically programmable memories (EPROM) or electrically erasable and programmable (EEPROM) memories. The memory (206) may store instructions which, when executed by the processor (204) cause the network apparatus (202) to be operated as described herein.
[0057] The I / O interface (208) transmits the information between the memory (206) and external peripheral devices. The peripheral devices are the input-output devices associated with the electronic device (102). Further, the traffic analyzer controller (210), the DDoS attack detection controller (212), and the DDoS attack mitigation controller (214) communicate with the I / O interface (208) and the memory (206). The traffic analyzer controller (210), the DDoS attack detection controller (212), and the DDoS attack mitigation controller (214) is coupled to the memory (206) and the processor (204). The traffic analyzer controller (210), the DDoS attack detection controller (212), and the DDoS attack mitigation controller (214) are innovative hardware that are realized through the physical implementation of both analog and digital circuits, including logic gates, integrated circuits, microprocessors, microcontrollers, memory circuits, passive and active electronic components, as well as optical components.
[0058] In an embodiment, the traffic analyzer controller (210) receives data from the plurality of electronic devices (102A-N) through a control plane interface. For instance, the data refers to traffic data.
[0059] In an embodiment, the traffic analyzer controller (210) monitors one or more key performance indicators (KPIs). The KPI data can be based on the data received from the electronic devices (102A-N) and on the AMF (106). The KPIs are not limited to traffic statistics from end points, and can also be specific to the AMF (106). The KPIs are derived from the data collected from the electronic devices (102A-N), which includes a variety of metrics that provide insights into network behavior and performance. For instance, the one or more KPIs includes, but are not limited to, a network pattern, traffic flow statistics, a packet header, a packet length variance and content, a number of packets flow, a flow duration ratio, a total payload per session, and CP CIoT traffic KPIs statistics.
[0060] Analyzing the overall behavior of the communication network system, the network pattern involves identifying trends and determining anomalies in data transmission. Understanding network patterns can help in optimizing performance and enhancing security measures. The traffic flow statistics assess the volume and direction of data traffic within the network. These statistics helps in identifying bottlenecks, understanding user behavior, and ensuring that resources are allocated efficiently. The traffic analyzer controller (210) examines the headers of data packets to gather information about the source and destination of the packets, as well as the protocols being used. This information is used for making routing decisions and for ensuring that data is transmitted correctly. By monitoring changes in packet length and the type of content being transmitted, the traffic analyzer controller (210) monitors the KPI data and shares it with the respective ML models.
[0061] The volume of packet flows measures the total number of packets being transmitted over a specific period. High volumes of packet flows can indicate increased user activity or potential network issues that need to be addressed. The flow duration ratio assesses the duration of data flows, providing insights into how long data sessions last. Understanding flow duration can help in optimizing network resources and improving user experience. The total payload per session measures the total amount of data transmitted during a single session. Analyzing payload sizes can help in understanding user behavior and in identifying trends in data usage.
[0062] Further, the DDoS attack detection controller (212) also monitors specific KPIs related to the CP CIoT traffic. This includes metrics that assess the performance and reliability of CIoT communications. In an embodiment, the DDoS attack detection controller (212) determines one or more anomalies in the data received based on the one or more KPIs monitored. To identify anomalies, the DDoS attack detection controller (212) employs a range of analytical techniques. These includes statistical analysis, machine learning models, or predefined thresholds that help in recognizing patterns and deviations from expected behavior. The identification of anomalies is essential for decision-making and timely interventions. For instance, if a KPI shows a sudden spike or drop that deviates from its normal range, the DDoS attack detection controller (212) flags this as an anomaly.
[0063] In an embodiment, the DDoS attack detection controller (212) detects at least one DDoS attack from a plurality of DDoS attacks based on the anomalies determined. For instance, the at least one DDoS attack is identified by inputting the one or more anomalies into a DDoS detection ML model. The table 1 below illustrates various types of attacks that is detected by the DDoS detection ML model:
[0064] Type of DDoS AttackDescriptionDrDoS_NTPIt is a reflection-based volumetric DDoSattack in which attacker exploits a Network Time Protocol (NTP) serverin order to overwhelm a target system with an amplified amount of UDP traffic, rendering the target and its surrounding infrastructure inaccessible to regular traffic.TFTPIt works by sending large volumes of spoofed packets to the target server (exploiting Trivial FileTransfer Protocol), causing it to become overwhelmed and unable to handle normal user requests.DrDoS_UDPIt works by sending large volumes of spoofed packets to the target server, causing it to become overwhelmed and unable to handle normal user requests.UDP-lagThe UDP-Lag attack is an attempt to break the connection between the client and the server.DrDoS_MSSQLIt works by flooding the target MSSQLdatabase server with requests, causing it to become overwhelmed and unable to handle normal user requests.DrDoS_DNSAttackers can leverage DNS by sending more information than can be handled by the device, thereby causing a DDoS conditionDrDoS_LDAPDDoS amplification attack exploiting LDAP directory services serversDrDoS_NetBIOSReflection based DDoS attack makes the victim system unavailable to communication other NetBIOS hostsSYN FloodingThe attacker sends many TCP SYN request packets either from a spoofed IP address or from a server set up to ignore responses.WebDDoSIttargets websites and web applications. It works by flooding the target website with requests, causing it to become overwhelmed and unable to handle normal user requests.HTTP Flood attacksAnattack that targets websites and web applications that use HTTP as their communication protocol.SlowlorisTargets websites and web applications that use HTTP as the as many sessions as possible for as long as possibleSession AttackA session attack uses a number of web applications that use HTsource IP range and initiates legitimate TCP sessions with the target serverbut the attack then delays ACK packets to chew up bandwidth and exhaust resources to maintain the empty sessions.IP Null AttackP Null Attack then delays ACK packets to chew up bandwidth and exhaust resources to maintain the empty sessions.
[0065] The DDoS detection ML model receives multiple inputs. For instance, the multiple inputs includes an NGAP ID of the electronic devices (102A-N), a flow throughput, number of flows, packet length variance, flow duration, mean flow size, packet payload header ratio, packet header length, packet payload length, packet inter-arrival time, DDoS prediction probability, and the like. All data fed into the ML model is provided as vector input. Utilizing this input, the DDoS detection ML model can recognize harmful traffic patterns and signatures, as well as forecast potential DDoS attacks. For the purpose of DDoS detection, the model uses a Deep Neural Network (DNN), Convolutional Neural Network (CNN), Recurrent Neural Network (RNN), or a hybrid neural network. The selection of the suitable neural network is determined by factors such as the deployment context, computational complexity, memory limitations, inference duration, and available computational resources at the AMF (106).
[0066] The neural network is composed of basic processing units that are intricately linked. The processing occurs within the hidden layers through a network of weighted connections. Nodes in these hidden layers integrate data from the input layer using a set of coefficients and assign appropriate weights to the inputs. When the input to the neural network is a straightforward feature map, a DNN is applicable. For feature maps with higher dimensions, a CNN is utilized, while an RNN is employed for time series analysis of input parameters. Long Short-Term Memory (LSTM) networks are specifically designed to capture long-term dependencies through gating mechanisms (forget gate, input gate, output gate) that regulate the flow of information, enabling the network to retain information over extended periods, which is used for identifying patterns in DDoS attacks. The output layer has 1 node for DDoS prediction, denoting the probability of a DDoS attack (it is basically a single value ∈ [0, 1]).
[0067] In an embodiment, the DDoS attack detection controller (212) determines data statistics based on the KPIs monitored and metadata based on a plurality of parameters at multiple regular intervals. The DDoS attack detection controller (212) includes a DDoS attack detection ML model, which identifies anomalies from the current traffic pattern and accordingly predicts impending DDoS attacks based on trends in the traffic pattern. By monitoring these KPIs, which includes metrics such as traffic volume, packet loss, latency, and connection rates, the DDoS attack detection controller (212) identifies any anomalies or deviations from the established norms. The use of various parameters enhances the ability of the DDoS attack detection controller (212) to detect potential DDoS attacks as it can evaluate multiple aspects of network performance simultaneously. For instance, it analyzes the rate of incoming requests, the geographical distribution of traffic sources, and the types of protocols being used. This analysis enables the DDoS attack detection controller (212) to differentiate between appropriate spikes in traffic and malicious activities indicative of a DDoS attack.
[0068] In an embodiment, the DDoS attack detection controller (212) determines a DDoS prediction score using the DDoS detection ML model based on the KPI data statistics and metadata determined. The DDoS prediction score serves as an indicator of the confidence level regarding the likelihood of at least one DDoS attack occurring within a specified timeframe. A higher score reflects a greater probability of a DDoS attack, while a lower score suggests a more stable and secure network environment. This prediction score is used by network administrators and security teams as it enables them to prioritize their response efforts, allocate resources effectively, and implement preventive measures to mitigate the impact of potential DDoS attacks.
[0069] In an embodiment, the DDoS attack mitigation controller (214) enables the adaptive firewall (216) to mitigate the at least one DDoS attack based on a generated DDoS control policy by a DDoS mitigation ML model. The DDoS control policy generated is used by the adaptive firewall (216) to control the rate of the data received through the control plane interface from the plurality of electronic devices (102A-N) identified as compromised by the DDoS mitigation ML model. The DDoS mitigation ML model receives multiple inputs. For instance, the multiple inputs includes an NGAP ID of the electronic devices (102A-N), a flow throughput, number of flows, packet length variance, flow duration, mean flow size, packet payload header ratio, packet header length, packet payload length, packet inter-arrival time, a DDoS prediction probability, and the like. All data fed into the ML model is provided as vector input.
[0070] For DDoS mitigation, the ML model utilizes various types of neural networks, including DNN, CNN, RNN, and the like. The selection of the suitable neural network is determined by factors such as the specific deployment scenario, computational complexity, memory limitations, inference time, and the computational resources available at the AMF (106).
[0071] In an embodiment, the DDoS attack mitigation controller (214) determines one or more dynamic rate limiting parameters per session for mitigation of the at least one DDoS attack. The dynamic rate limiting is performed for a predicted time duration associated with the DDoS control policy. For instance, the dynamic rate limiting parameters includes a volume of requests, a frequency of connections, a source of the traffic, and the like. The dynamic nature of these rate limiting parameters enables the adaptive firewall (216) to respond swiftly and fine-tune its defenses as the situation evolves.
[0072] In an embodiment, the DDoS attack mitigation controller (214) determines a list of compromised electronic devices from the plurality of electronic devices (102A-N) for dynamic rate limiting generated by the DDoS mitigation ML model. The list of compromised electronic devices is determined based on the DDoS prediction score determined along with the data statistics associated with the data.
[0073] In an embodiment, the DDoS attack mitigation controller (214) determines whether the DDoS prediction score determined is greater than a predefined threshold. The DDoS attack mitigation controller (214) then generates the DDoS control policy for the list of compromised electronic devices determined when the DDoS prediction score is greater than the predefined threshold.
[0074] In an embodiment, the DDoS attack mitigation controller (214) generates one or more alarms for notifying an operator associated with the list of compromised electronic devices for each DDoS attack detected. The alarms provide operators with real-time information about the status of the compromised electronic device and the nature of the ongoing DDoS attack(s). The alarms or alerts includes details such as the type of DDoS attack, the affected devices, and recommended actions for the operators to take in order to further mitigate the DDoS attack.
[0075] In an embodiment, the DDoS attack mitigation controller (214) updates a firewall rule in a firewall policy database of an adaptive firewall of the network apparatus based on the generated DDoS control policy for the list of compromised electronic devices to mitigate impending DDoS attacks. For instance, updating the firewall rules involves altering existing firewall rules or adding new ones that restrict or filter traffic originating from the compromised electronic devices. By implementing these changes, the adaptive firewall can effectively block malicious traffic and prevent it from affecting the network resources, thereby safeguarding the integrity and availability of the services offered by the control plane in the telecommunication network system.
[0076] In an embodiment, the DDoS attack mitigation controller (214) determines a time duration within which a comparison process of the current rate of the data traffic with the maximum allowed data transmission rate for the compromised electronic device is to be performed. The time duration serves as a window for monitoring and analyzing the behavior of data traffic originating from the compromised electronic devices within the network. Further, the DDoS attack mitigation controller (214) updates the firewall policy database after expiration of the time duration.
[0077] As shown, Fig. 2A also includes a traffic analyzer (218), core network functions (220), an operator alarm monitoring dashboard (224), and a public data network (222). The traffic analyzer (218) shares the real-time traffic KPI statistics / metadata with the DDoS attack detection controller (212) and the DDoS attack mitigation controller (214). The traffic analyzer (218) further communicates filtered traffic to the core network functions (220). The DDoS attack detection controller (212) generates a DDoS prediction / DDoS prediction score based on the real-time traffic KPI statistics / metadata received and communicates this score to the DDoS attack mitigation controller (214). The DDoS attack mitigation controller (214) generates a DDoS control policy based on the compromised electronic devices identified and communicates this to the adaptive firewall (216). Further, the operator alarm monitoring dashboard (224) displays the alarms generated by the DDoS attack mitigation controller (214) upon detection of the DDoS attacks for the compromised electronic devices.
[0078] Fig. 2B is a block diagram that illustrates an exploded view of the DDoS attack detection controller (212) of the network apparatus (202) of Fig. 2A according to an embodiment as disclosed herein. The DDoS attack detection controller (212) is responsible for the detection of impending DDoS attacks by using an ML model. As shown, the DDoS attack detection controller (212) includes a feature pre-processing component (602), a data collection component (604), and a DDoS detection ML model (606).
[0079] The feature pre-processing component (602) prepares the data, specifically real-time traffic KPI statistics and metadata obtained from the traffic analyzer (218), for subsequent analysis. The data collection component (604) is tasked with gathering and consolidating the information received from the feature pre-processing component (602). The DDoS detection ML model (606) utilizes the processed traffic data features and overall flow statistics related to KPIs sourced from the traffic analyzer (218). The traffic analyzer (218) monitors real-time traffic, collecting KPI and metadata concerning traffic load at various regular intervals. This data is then transmitted to the DDoS attack detection controller (212) to enhance the accuracy of predicting potential DDoS attacks.
[0080] The DDoS detection ML model (606) generates a DDoS_PREDICTION Score, a floating-point value ranging from 0 to 1, which indicates the likelihood or confidence of a DDoS attack occurring. This score is then transmitted to the DDoS attack mitigation controller (214). The traffic statistics collected by the traffic analyzer (218) are pre-processed and stored within the DDoS attack detection controller (212) to facilitate self-evaluation and updates of the ML model. The DDoS detection ML model (606) is periodically re-evaluated and trained to adapt to changing traffic patterns by utilizing the stored traffic statistics. Further, the DDoS attack detection controller (212) is implemented within the AMF (106), serving as the initial aggregation point for control plane traffic.
[0081] Fig. 2C is a block diagram that illustrates an exploded view of the DDoS attack mitigation controller (214) of the network apparatus (202) of Fig. 2A according to an embodiment as disclosed herein. The DDoS attack mitigation controller (214) is responsible for generating the DDoS control policy. As shown, the DDoS attack mitigation controller (214) includes a data feature processing component (608), a DDoS Mitigation ML Model (610), and a mitigation policy constructor (612). The main objective of the DDoS attack mitigation controller (214) is to generate a list of compromised electronic devices identified by the DDoS Mitigation ML Model (610) along with the maximum permissible flow rate and duration for constraint. Further, the list of compromised electronic devices is propagated to the adaptive firewall (216) via a DDoS control policy block (614) in order to mitigate the impending DDoS attack.
[0082] The data feature processing component (608) transmits real-time session-based data traffic statistics, metadata, payload distribution information, and similar data to the DDoS attack mitigation controller (214). This real-time information is pre-processed and forwarded to the trained DDoS Mitigation ML Model (610), accompanied by the DDoS_PREDICTION score produced by the DDoS attack detection controller (212). Further, a data collector within the DDoS attack mitigation controller (214) archives this shared data for self-assessment and future enhancements of the DDoS Mitigation ML Model (610). The DDoS Mitigation ML Model (610) analyzes the processed real-time statistics and the DDoS_PREDICTION score to identify the compromised electronic devices and determine dynamic rate-limiting parameters / configurations.
[0083] The DDoS Mitigation ML Model (610) produces several outputs, including a list of compromised electronic devices, each identified by a unique NGAP ID, a maximum rate limit for incoming traffic from these devices per session, and the duration for which this rate limiting should be enforced. The mitigation policy constructor (612) is tasked with creating the DDoS control policy, which can then be communicated to the adaptive firewall (216). The generation of this policy occurs when the DDoS_PREDICTION score exceeds the predetermined threshold (PRED_THRESH). Once the DDoS control policy is formulated, the DDoS control policy is transmitted to the adaptive firewall (216) to enforce dynamic rate limiting on the identified compromised electronic devices. Further, the DDoS Mitigation ML Model (610) is subject to periodic evaluation and self-updating based on accumulated traffic statistics and metadata. Furthermore, the DDoS attack mitigation controller (214) should be integrated within the AMF (106) as it serves as the initial aggregation point for control plane traffic in the 5G Core network.
[0084] Fig. 2D is a block diagram that illustrates an exploded view of the adaptive firewall (216) of the network apparatus (202) of Fig. 2A implemented in a core network according to an embodiment as disclosed herein. Fig. 2E is a block diagram that illustrates an exploded view of the adaptive firewall (216) of the network apparatus (202) of Fig. 2A implemented in an O-RAN CU according to an embodiment as disclosed herein. The adaptive firewall (216) is responsible for dynamic rate limiting of traffic from the identified compromised electronic devices shared in the DDoS control policy. As shown, the adaptive firewall (216) includes the firewall configuration manager (802) and the adaptive rate control engine (804).
[0085] The firewall configuration manager (802) utilizes the DDoS control policy to modify the firewall rules within the firewall policy database, aiming to counteract potential DDoS attacks. Once updated, these firewall rules are applied within the adaptive rate control engine (804) to facilitate dynamic rate limiting. This engine regulates the data traffic directed towards the core control plane from compromised electronic devices. The rate limiting serves as a temporary measure established for a duration determined heuristically by the DDoS mitigation ML model (706). If the data traffic from a compromised device exceeds the predefined maximum rate, any additional packets from that device are discarded. Upon the conclusion of the specified duration, the rate limiting rule is removed, and the firewall policy database is refreshed. If manual intervention is necessary, an operator can delete the firewall rule by submitting a delete request that includes the policy ID of the relevant rule to the firewall configuration manager (802).
[0086] In an embodiment, the adaptive rate control engine (804) determines whether a current rate of data traffic of the compromised electronic device is greater than a maximum allowed data transmission rate based on the generated DDoS control policy by the DDoS attack mitigation controller (214). The adaptive rate control engine (804) allows forwarding of the one or more data packets from at least one compromised electronic device if the current rate of the data traffic is not greater than the maximum allowed data transmission rate. Else, the adaptive rate control engine (804) drops the one or more data packets from at least one compromised electronic device if the current rate of the data traffic is greater than the maximum allowed data transmission rate. By allowing or dropping the data packets based on the current traffic rate, the DDoS attack mitigation controller (214) enables the adaptive firewall (216) to effectively mitigate the risks associated with compromised electronic devices while ensuring that legitimate users can access network resources without interruption.
[0087] There are two deployment options. In Proposal 1, as shown in Fig. 2D, the adaptive firewall (216) is implemented in the AMF (106) and filters traffic at the entry point of the AMF (106). The DDoS detection engine provides ML-based DDoS attack prediction in the Core Network AMF. Additionally, the DDoS mitigation controller offers ML-based DDoS attack mitigation in the Core Network AMF. The adaptive firewall (216) implements rules generated by the DDoS attack mitigation controller (214) in the AMF (106) ingress interfaces.
[0088] In proposal 2, as shown in Fig. 2E, the adaptive firewall (216) is implemented in the O-RAN. The DDoS detection engine utilizes ML-based DDoS attack prediction in the Core Network AMF. The DDoS mitigation controller employs ML-based DDoS attack mitigation in the Core Network AMF. The O-RAN RIC (RAN Intelligent Controller) has the provision to run custom applications (xApps). The DDoS attack mitigation controller (214) on the AMF (106) communicates with the firewall configuration manager (802) xApp via the CU-RIC E2 interface. In an embodiment, dynamic rate limiting is performed in CU for the list of compromised electronic devices.
[0089] Fig. 3 is a sequence diagram that illustrates a scenario where the network apparatus (202) is in a unified mode according to an embodiment as disclosed herein. As shown in the sequence diagram, a traffic analyzer (218), the network apparatus (202) (NGAP Armor), and an alarm monitor (304) are in communication with each other. In the unified mode, the AMF (106) of the network apparatus (202) includes the DDoS attack detection controller (212), the DDoS attack mitigation controller (214), and an adaptive firewall (216). The adaptive firewall (216) includes a firewall configuration manager (802) and an adaptive rate control engine (804).
[0090] At step 1, the traffic analyzer (218) transmits real-time traffic KPI statistics / metadata to the DDoS attack detection controller (212). At step 2, the traffic analyzer (218) transmits real-time session-wise traffic KPI statistics / metadata to the DDoS attack mitigation controller (214). At step 3, the DDoS attack detection controller (212) performs a traffic analysis of the real-time traffic KPI information received from the traffic analyzer (218). This analysis involves comparing the current traffic patterns against known patterns of DDoS attacks. The detection engine uses advanced algorithms and machine learning techniques to identify any deviations from normal traffic behavior. At step 4, the DDoS attack detection controller (212) determines whether a DDoS attack is detected based on the traffic analysis of the real-time traffic KPI information. If yes, then the DDoS attack detection controller (212) transmits this DDoS attack detection information to the DDoS attack mitigation controller (214).
[0091] At step 5, the DDoS attack mitigation controller (214) determines a list of compromised electronic devices and communicates this list along with the DDoS control policy to the firewall configuration manager (802). For instance, the DDoS control policy includes information such as policy IDs, unique NGAP IDs of the electronic devices (102A-N) identified as compromised by the DDoS attack mitigation ML model, update rules for each policy ID / NGAP ID, a maximum rate of the data packets, a duration of the DDoS control policy, and the like. The mitigation controller uses the information from the detection engine and session-wise traffic statistics / KPIs to pinpoint the sources of the attack and formulate a targeted response. At step 6, the firewall configuration manager (802) updates a DDoS mitigation firewall upon receiving the list of compromised electronic devices and the DDoS control policy.
[0092] At step 7, the firewall configuration manager (802) shares this DDoS Control Policy in an update notification (Adaptive_Rate_Policy_Update / Adaptive_Rate_Policy_Apply) with the adaptive rate control engine (804). This ensures that the rate control engine is aware of the new policies and can enforce them effectively. At step 8, the adaptive rate control engine (804) updates (Rate_Policy_Update_Success) this information received from the firewall configuration manager (802). The adaptive rate control engine (804) adjusts the rate of incoming and outgoing traffic based on the updated policies, ensuring that the network remains functional while mitigating the impact of the DDoS attack. At step 9, the DDoS attack mitigation controller (214) transmits a DDoS_Detected_Notification message to the alarm monitor (304). This notification serves as an alert to the network administrators, informing them of the detected attack and the actions taken to mitigate it.
[0093] Fig. 4 is a sequence diagram that illustrates a scenario where the network apparatus (202) is in a distributed mode according to an embodiment as disclosed herein. As shown in the sequence diagram, the traffic analyzer (218), the network apparatus (202) (NGAP Armor), and the alarm monitor (304) are in communication with each other. In the distributed mode, the AMF (106) and the adaptive firewall (216) are separate and not integrated like in the unified mode. The AMF (106) includes the DDoS attack detection controller (212) and the DDoS attack mitigation controller (214). The adaptive firewall (216) includes the adaptive rate control engine (804) implemented on a CU and the firewall configuration manager (802) implemented on a xApp (near-RT RIC).
[0094] At step 1, the traffic analyzer (218) transmits real-time traffic KPI statistics / metadata to the DDoS attack detection controller (212). At step 2, the traffic analyzer (218) transmits real-time session-wise traffic KPI statistics / metadata to the DDoS attack mitigation controller (214).. The DDoS attack detection controller (212) then performs a detailed traffic analysis at step 3, examining the real-time traffic KPI information received from the traffic analyzer (218). This analysis involves identifying patterns that are indicative of a DDoS attack, such as sudden spikes in traffic, abnormal packet sizes, or traffic sources.
[0095] At step 4, the DDoS attack detection controller (212) determines whether a DDoS attack is detected based on the traffic analysis of the real-time traffic KPI information. If an attack is detected, the DDoS attack detection controller (212) transmits this DDoS attack detection information to the DDoS attack mitigation controller (214). The DDoS attack mitigation controller (214) then takes over at step 5, determining a list of compromised electronic devices and communicating this list along with the DDoS control policy to the firewall configuration manager (802). The DDoS control policy includes various parameters such as policy IDs, unique NGAP IDs, update rules for the policy ID / NGAP ID, a maximum rate of the data packets, a duration of the data packets, and the like.
[0096] At step 6, the firewall configuration manager (802) updates a DDoS mitigation firewall upon receiving the list of compromised electronic devices and the DDoS control policy. This update ensures that the firewall is configured to block or limit traffic from the compromised devices, thereby mitigating the impact of the DDoS attack.
[0097] At step 7, the firewall configuration manager (802) shares the DDoS Control Policy in an update notification (Adaptive_Rate_Policy_Update / Adaptive_Rate_Policy_Apply) with the adaptive rate control engine (804). The adaptive rate control engine (804) then updates (Rate_Policy_Update_Success) this information received from the firewall configuration manager (802) at step 8, ensuring that the rate control policies are enforced across the network.
[0098] Further, at step 9, the DDoS attack mitigation controller (214) transmits a DDoS_Detected_Notification message to the alarm monitor (304). This notification ensures that network administrators are alerted to the presence of a DDoS attack, allowing them to take any additional actions that is necessary to protect the network. The alarm monitor (304) can also log the incident for future reference and analysis, helping to improve the network's defenses against future attacks.
[0099] Figs. 5A-5B are flow diagrams illustrating a method for detecting and mitigating DDoS attacks in a communication network system according to an embodiment disclosed herein. The method includes steps (502-532), each of which is explained in further detail below.
[0100] At step (502), the network apparatus (202) receives data from a plurality of electronic devices (102A-N) through a control plane interface. This data refers to traffic data. The control plane interface facilitates the efficient and accurate collection of data
[0101] In step (504), the network apparatus (202) monitors KPIs based on the data received from the electronic devices (102A-N). These KPIs are derived from the collected data and includes various metrics that provide insights into network behavior and performance. For instance, the KPIs includes, but are not limited to, network pattern traffic flow statistics, packet header information, packet length variance and content, number of packets flow, flow duration ratio, total payload per session, and control plane CIoT traffic KPIs statistics.
[0102] Analyzing network patterns entails a comprehensive examination of the communication network system's overall behavior, allowing for the identification of trends and detection of anomalies in data transmission. Insights gained from these patterns for optimizing network performance and strengthening security protocols. Traffic flow statistics assess the volume and direction of data traffic, which can help pinpoint bottlenecks, understand user behavior, and ensure efficient resource allocation. The network apparatus (202) scrutinizes data packet headers to extract information regarding their source, destination, and the protocols in use. This data is used for making informed routing decisions and ensuring accurate data transmission. By observing variations in packet length and the nature of the transmitted content, the network apparatus (202) can detect unusual patterns that signals issues such as network congestion or potential security vulnerabilities.
[0103] The volume of packet flows quantifies the aggregate number of packets transmitted within a designated timeframe. Elevated packet flow volumes signifies heightened user engagement or potential network complications that require attention. The flow duration ratio evaluates the length of data flows, offering insights into the lifespan of data sessions. Understanding flow duration is used for optimizing network resources and enhancing user experience. The total payload per session calculates the cumulative amount of data exchanged during an individual session. Examining payload sizes can provide information regarding user behavior and assist in recognizing trends in data consumption. Additionally, the network apparatus (202) monitors specific KPIs associated with the control plane of CIoT traffic, including metrics that evaluate the performance and dependability of CIoT communications.
[0104] At step (506), the network apparatus (202) determines one or more anomalies in the data received based on the monitored KPIs. Various analytical methods, such as statistical evaluations, machine learning algorithms, or set thresholds, are utilized to detect anomalies. By analyzing current data in relation to historical patterns and recognized standards, the network apparatus (202) can identify irregularities that signals potential problems or areas requiring attention. For example, if a key performance indicator experiences an increase or decrease outside its typical range, the network apparatus (202) recognizes this as an anomaly.
[0105] In step (508), the network apparatus (202) detects at least one DDoS attack from a plurality of DDoS attacks based on the determined anomalies. The at least one DDoS attack is identified by inputting the anomalies into the DDoS detection ML model (606).
[0106] At step (510), the network apparatus (202) determines data statistics based on the monitored KPIs and metadata based on a plurality of parameters at multiple regular intervals. By tracking these key performance indicators, which can encompass metrics like traffic volume, packet loss, latency, and connection rates, the DDoS attack detection controller (212) can recognize any irregularities or deviations from established benchmarks. The incorporation of diverse parameters enhances the capacity of the DDoS attack detection controller (212) to identify potential DDoS attacks by assessing various facets of network performance concurrently. For example, it evaluates the frequency of incoming requests, the geographical distribution of traffic origins, and the types of protocols in use. This comprehensive analysis allows the DDoS attack detection controller (212) to distinguish between legitimate traffic surges and harmful activities that suggest a DDoS attack.
[0107] In step (512), the network apparatus (202) determines a DDoS prediction score using the DDoS detection ML model (606) based on the determined data statistics. The DDoS prediction score acts as a gauge of the confidence level concerning the probability of experiencing at least one DDoS attack within a designated period. A higher score indicates an increased likelihood of such an attack, whereas a lower score implies a more secure and stable network environment. This prediction score is used by network administrators and security teams as it allows them to prioritize their response strategies, allocate resources efficiently, and adopt preventive measures to lessen the potential impact of DDoS attacks.
[0108] In step (514), the network apparatus (202) determines one or more dynamic rate limiting parameters per session for mitigating the at least one DDoS attack. Dynamic rate limiting is implemented for a forecasted time frame linked to the DDoS control policy. For example, the parameters for dynamic rate limiting can encompass the volume of requests, connection frequency, traffic sources, and similar factors. The flexible characteristics of these rate limiting parameters allow the DDoS attack mitigation controller (214) to quickly adjust and enhance its defenses as circumstances change. This level of adaptability is crucial during a DDoS attack, as attackers frequently alter their strategies to circumvent existing security protocols.
[0109] In step (516), the network apparatus (202) determines a list of compromised electronic devices from the plurality of electronic devices (102A-N) for dynamic rate limiting, generated by the DDoS mitigation ML model (706). This list is determined based on the DDoS prediction score, along with the data statistics associated with the data. This decision represents advancement in the deployment of dynamic rate limiting aimed at safeguarding the network against the detrimental impacts of DDoS attacks while ensuring uninterrupted service for legitimate users.
[0110] In step (518), the network apparatus (202) determines a time duration within which a comparison process of the current rate of the data traffic with the maximum allowed data transmission rate for each compromised electronic device is to be performed. This time duration serves as a window for monitoring and analyzing the behavior of data traffic originating from the compromised electronic devices within the network. Upon expiration of the time duration, the DDoS attack mitigation controller (214) updates the firewall policy database.
[0111] In step (520), the network apparatus (202) determines whether the DDoS prediction score is greater than a predefined threshold. If the score exceeds the threshold, in step (522), the network apparatus (202) generates the DDoS control policy for the list of compromised electronic devices.
[0112] In step (524), the network apparatus (202) generates one or more alarms to notify an operator associated with the list of compromised electronic devices for the detected DDoS attack. These alarms function as notifications, providing operators with immediate insights into the condition of the affected devices and the specifics of the ongoing DDoS attack(s). The alarms includes information such as the type of DDoS attack, the devices impacted, and suggested measures for operators to implement to effectively reduce the impact of the DDoS attack.
[0113] In step (526), the network apparatus (202) updates a firewall rule in a firewall policy database of an adaptive firewall (216) based on the generated DDoS control policy for the list of compromised electronic devices to mitigate impending DDoS attacks. Updating the firewall rules can involve altering existing rules or adding new ones that restrict or filter traffic originating from the compromised electronic devices. Through these modifications, the adaptive firewall (216) can successfully prevent DDoS attacks from impacting network resources, thus ensuring the integrity and availability of the services provided by the telecommunications network.
[0114] In step (528), the network apparatus (202) determines whether the current rate of data traffic of the compromised electronic device is greater than the maximum allowed data transmission rate. At step (530), the DDoS attack mitigation controller (214) allows the forwarding of one or more data packets from at least one compromised electronic device if the current rate of data traffic is not greater than the maximum allowed data transmission rate. Else, at step (532), the DDoS attack mitigation controller (214) drops the one or more data packets from at least one compromised electronic device if the current rate of data traffic is greater than the maximum allowed data transmission rate. By selectively allowing or dropping data packets according to the current traffic rate, the DDoS attack mitigation controller (214) effectively manages the risks posed by the compromised electronic devices, thereby ensuring uninterrupted access to network resources for legitimate users.
[0115] The foregoing description of the specific embodiments will so fully reveal the general nature of the embodiments herein that others can, by applying current knowledge, readily modify and or adapt for various applications such specific embodiments without departing from the generic concept, and, therefore, such adaptations and modifications are intended to be comprehended within the meaning and range of equivalents of the disclosed embodiments. It is to be understood that the phraseology or terminology employed herein is for the purpose of description and not of limitation. Therefore, while the embodiments herein have been described in terms of preferred embodiments, those skilled in the art will recognize that the embodiments herein can be practiced with modification within the scope of the embodiments as described herein.
Claims
1.A method for detecting and mitigating distributed denial-of-service, DDoS, attacks by a network apparatus (202) in a communication network system, the method comprising:receiving data from a plurality of electronic devices (102A-N) through a control plane interface;monitoring one or more key performance indicators, KPIs, based on the data received from the plurality of electronic devices (102A-N);determining one or more anomalies in the received data based on the monitored one or more KPIs;detecting at least one DDoS attack based on the one or more anomalies using a DDoS detection machine learning, ML, model (606); andgenerating a DDoS control policy for mitigating the at least one DDoS attack using a DDoS mitigation ML model (706).2.The method of claim 1, wherein the generated DDoS control policy is used by an adaptive firewall (216) to control the rate of data received through the control plane interface from the plurality of electronic devices identified as compromised by the DDoS mitigation ML model (706).3.The method of claim 1, wherein the one or more KPIs comprise at least one of a network pattern, traffic flow statistics, a packet header, a packet length variance and content, a number of packets flow, a flow duration ratio, a total payload per session, or control plane (CP) cellular internet of things (CIoT) traffic KPIs statistics.4.The method of claim 1, wherein detecting the at least one DDoS attack comprises:determining data statistics based on the monitored one or more KPIs and metadata based to a plurality of parameters at multiple regular intervals; anddetermining a DDoS prediction score using the DDoS detection ML model (606) based on the data statistics determined, wherein the DDoS prediction score represents a confidence level of an occurrence of the at least one DDoS attack.5.The method of claim 4, wherein generating the DDoS control policy comprises:determining one or more dynamic rate limiting parameters per session for mitigation of the at least one DDoS attack;determining a list of compromised electronic devices from the plurality of electronic devices (102A-N) for dynamic rate limiting generated by the DDoS mitigation ML model (706) based on the DDoS prediction score determined along with the data statistics associated with the data;determining whether the DDoS prediction score determined is greater than a predefined threshold; andgenerating the DDoS control policy for the list of compromised electronic devices determined when the DDoS prediction score is greater than the predefined threshold.6.The method of claim 5, further comprising:generating one or more alarms for notifying an operator associated with the list of compromised electronic devices for each DDoS attack detected.7.The method of claim 5, wherein generating the DDoS control policy for the list of compromised electronic devices determined when the DDoS prediction score is greater than the predefined threshold comprises:updating a firewall rule in a firewall policy database of an adaptive firewall (216) of the network apparatus (202) based on the generated DDoS control policy for the list of compromised electronic devices to mitigate impending DDoS attacks;determining whether a current rate of data traffic of each compromised electronic device in the list of compromised electronic devices is greater than a maximum allowed data transmission rate;allowing the network apparatus to forward one or more data packets from at least one compromised electronic device of the list of compromised electronic devices if the current rate of the data traffic is not greater than the maximum allowed data transmission rate; anddropping the one or more data packets from at least one compromised electronic device of the list of compromised electronic devices if the current rate of the data traffic is greater than the maximum allowed data transmission rate.8.The method of claim 7, wherein the dynamic rate limiting is performed for a predicted time duration associated with the generated DDoS control policy.9.The method of claim 7, wherein the adaptive firewall (216) of the network apparatus (202) is implemented in one of an Access and Mobility Management Function, AMF, (106) where data is filtered at an entry point of the AMF (106), and in an open radio access network, O-RAN.10.The method of claim 9, wherein detection of the DDoS attacks by the DDoS detection ML model (606) and generation of the DDOS control policy by the DDoS mitigation ML model (706) are performed in the AMF (106), and wherein the AMF (106) transmits the generated DDoS control policy to the O-RAN.11.The method of claim 7, further comprising:determining a time duration within which a comparison process of the current rate of the data traffic with the maximum allowed data transmission rate for each compromised electronic device is to be performed; andupdating the firewall policy database after expiration of the time duration.12.A network apparatus (202) for detecting and mitigating distributed denial-of-service, DDoS, attacks in a communication network system, comprising:memory (206) storing instructions; andat least one processor (204) operably coupled to the memory (206), wherein the instructions, when executed by the at least one processor (204) individually or collectively, cause the network apparatus (202) to:receive data from a plurality of electronic devices (102A-N) through a control plane interface;monitor one or more key performance indicators, KPIs, based on the data received from the plurality of electronic devices (102A-N); anddetermine one or more anomalies in the received data based on the monitored one or more KPIs;detect at least one DDoS attack based on the one or more anomalies using a DDoS detection machine learning, ML, model (606); andgenerate a DDoS control policy for mitigating the at least one DDoS attack using a DDoS mitigation ML model (706).13.The network apparatus of claim 12, wherein the instructions, when executed by the at least one processor (204) individually or collectively, cause the network apparatus (202) to be operated according to one of claims 2 to 11.14.A non-transitory computer readable storage medium storing instructions which, when executed by at least one processor (204) of a network apparatus (202) individually or collectively, cause the network apparatus to:receive data from a plurality of electronic devices (102A-N) through a control plane interface;monitor one or more key performance indicators, KPIs, based on the data received from the plurality of electronic devices (102A-N); anddetermine one or more anomalies in the received data based on the monitored one or more KPIs;detect at least one DDoS attack based on the one or more anomalies using a DDoS detection machine learning, ML, model (606); andgenerating a DDoS control policy for mitigating the at least one DDoS attack using a DDoS mitigation ML model (706).15.The non-transitory computer readable storage medium of claim 14, wherein the instructions, when executed by the at least one processor (204) individually or collectively, cause the network apparatus (202) to be operated according to one of claims 2 to 11.