Artificial intelligence based distributed denial of service attack mitigation

WO2026182721A1PCT designated stage Publication Date: 2026-09-03RAKUTEN SYMPHONY INC +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/US2025/017320
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-02-26
Publication Date
2026-09-03

Smart Images

  • Figure US2025017320_03092026_PF_FP_ABST
    Figure US2025017320_03092026_PF_FP_ABST
Patent Text Reader

Abstract

Example embodiments of the present disclosure relate to artificial intelligence based distributed denial of service attack mitigation. According to example embodiments, a method may include receiving a dataset recorded from a network comprising first network data and second network data of a different data type than the first network data; calculating, based on comparing current values of the first network data and current values of the second network data with predefined benchmark values of the first network data and predefined benchmark values of the second network data respectively, a probability of a fault occurring; and based on the calculated fault probability, applying a fault mitigation policy to the network.
Need to check novelty before this filing date? Find Prior Art

Description

ARTIFICIAL INTELLIGENCE BASED DISTRIBUTED DENIAL OF SERVICE ATTACK MITIGATIONTECHNICAL FIELD

[0001] The present disclosure relates to artificial intelligence based distributed denial of service attack mitigation.BACKGROUND

[0002] The information disclosed in this background section is only for the enhancement of understanding of the general background of the disclosure and should not be taken as an acknowledgement or any form of suggestion that this information forms the prior art already known to a person skilled in the art.

[0003] In the related art, a distributed denial of service attack (DDoS) is a malicious attempt to disrupt the normal operation of a server, service, or network / infrastructure thereof by flooding the target with internet traffic. A DDoS attack may intend to prevent or deny legitimate users access to the targeted host.

[0004] A DDoS attack may be achieved by using a large number of computing devices along with any connected devices thereof (e.g., a desktop computer, laptop, loT devices, etc.), which may have been accessed using malware. The collection of computing devices may form a bot-net, which the attacker may control using a bot master or the like. Since each computing device in the bot-net may be considered as a legitimate device, it is generally difficult to isolate attack traffic from normal traffic. Further techniques such as IP and IP subnet spoofing may make it more difficult to isolate the traffic.

[0005] DDoS attacks may be further classified as either being a network layer attack (e.g., TCP flooding, UDP flooding, ICMP flooding), or application layer attacks (HTTP GET flooding, SIP Flooding, DNS flooding, etc.).

[0006] In a telecommunications network, network functions (NF’s) may also be affected by DDoS attacks. In particular, a NF such as a Central Unit (CU) and Distributed Unit (DU) may be targeted, such that network performance of the telecommunications network may be affected.SUMMARY

[0007] Systems in the related art for DDoS attack mitigation may struggle with predictive analysis to prevent a DDoS attack before it occurs. Most DDoS attack mitigation techniques in the related art are performed when the attack is already underway. Furthermore, such techniques are not typically applied to NF and telecommunication networks.

[0008] Accordingly, there is a need for a solution which has improved performance for predictive analysis and mitigation techniques for DDoS attacks.

[0009] According to example embodiments, a method may be provided, the method including: receiving a dataset recorded from a network including first network data and second network data of a different data type than the first network data; calculating, based on comparing current values of the first network data and current values of the second network data with predefined benchmark values of the first network data and predefined benchmark values of the second network data respectively, a probability of a fault occurring; and based on the calculated fault probability, applying a fault mitigation policy to the network.

[0010] According to example embodiments, an apparatus may be provided, the apparatus configured to receive a dataset recorded from a network including first network data and secondnetwork data of a different data type than the first network data; calculate, based on comparing current values of the first network data and current values of the second network data with predefined benchmark values of the first network data and predefined benchmark values of the second network data respectively, a probability of a fault occurring; and based on the calculated fault probability, apply a fault mitigation policy to the network.

[0011] According to example embodiments, a non-transitory computer-readable recording medium having recorded thereon instructions executable to perform a method may be provided, the method including: receiving a dataset recorded from a network including first network data and second network data of a different data type than the first network data; calculating, based on comparing current values of the first network data and current values of the second network data with predefined benchmark values of the first network data and predefined benchmark values of the second network data respectively, a probability of a fault occurring; and based on the calculated fault probability, applying a fault mitigation policy to the network.

[0012] Additional aspects will be set forth in part in the description that follows and, in part, will be apparent from the description, or may be realized by practice of the presented embodiments of the disclosure.BRIEF DESCRIPTION OF THE DRAWINGS

[0013] Features, aspects, and advantages of embodiments of the disclosure will be described below with reference to the accompanying drawings, in which like reference numerals denote like elements, and wherein:

[0014] FIG. 1 illustrates a system architecture diagram according to one or more example embodiments;

[0015] FIG. 2, illustrates an example method for fault detection, according to one or more example embodiments;

[0016] FIG. 3 illustrates a block diagram of an example device for implementing one or more example embodiments; and

[0017] FIG. 4 illustrates a block diagram of an example environment for implementing one or more example embodiments.DETAILED DESCRIPTION

[0018] The following detailed description of example embodiments refers to the accompanying drawings. The foregoing disclosure provides illustration and description, but is not intended to be exhaustive or to limit the implementations to the precise forms disclosed. Modifications and variations are possible in light of the above disclosure or may be acquired from practice of the implementations. Further, one or more features or components of one embodiment may be incorporated into or combined with another embodiment (or one or more features of another embodiment). Additionally, the flowchart and description of operations provided below relate to one of the various embodiments. It should be noted that it is possible to make other embodiments that do not exactly match the flowchart and its description. It is understood that in other embodiments one or more operations may be omitted, one or more operations may be added, one or more operations may be performed simultaneously (at least in part).

[0019] It will be apparent that systems and / or methods, described herein, may be implemented in different forms of hardware, firmware, or a combination of hardware and software. The actual specialized control hardware or software code used to implement these systems and / or methods is not limited to the described implementations. Thus, the operation and behavior of thesystems and / or methods are described herein without reference to specific software code. It is understood that software and hardware may be designed to implement the systems and / or methods based on the description herein.

[0020] Even though particular combinations of features are disclosed in the claims and / or in the specification, these combinations are not intended to limit the disclosure of implementations. In fact, many of these features may be combined in ways not specifically recited in the claims and / or disclosed in the specification. Although each dependent claim listed below may directly depend on only one claim, the disclosure of implementations includes each dependent claim in combination with every other claim in the claim set.

[0021] No element, act, or instruction used herein should be construed as critical or essential unless explicitly described as such. Also, as used herein, the articles “a” and “an” are intended to include one or more items, and may be used interchangeably with “one or more.” Also, as used herein, the terms “has,” “have,” “having,” “include,” “including,” or the like are intended to be open-ended terms. Further, the phrase “based on” is intended to mean “based, at least in part, on” unless explicitly stated otherwise. Furthermore, expressions such as “at least one of [A] and [B]”, “[A] and / or [B]”, or “at least one of [A] or [B]”, are to be understood as including only A, only B, or both A and B.

[0022] In the present disclosure, specific tasks may be performed using AI / ML (Artificial Intelligence / Machine Learning) models. An AI / ML model is a model generated using one or more Al technologies, one or more ML algorithm or both, and generates output data based on input data. This output data is used to perform tasks. Tasks performed using AI / ML models include thosegenerally referred to as intellectual tasks, such as classification, prediction, natural language processing, etc.

[0023] Although Al and ML are explained separately, ML is a technology included in Al. In ML, instead of being explicitly programmed for a specific task, systems can improve their performance over time by identifying patterns and making inferences from training data. Typically, the generation of ML models includes data collection, model training, and model inference. Data collection involves gathering and preprocessing data to be used for training and inference. Model training involves developing and validating models using the collected data. Model inference involves applying the trained models to new data to generate new output data and perform tasks.

[0024] Machine learning includes various types of learning methods such as supervised learning, unsupervised learning, reinforcement learning, semi-supervised learning, self-supervised learning, transductive learning, transfer learning, meta learning, and the like. These types of learning methods can be appropriately selected according to the embodiments. Unless otherwise specified, the application of types not mentioned in this description is not precluded. Additionally, the structure of ML models may vary depending on the embodiments and learning methods, and is not limited to the methods disclosed. Furthermore, ML includes deep learning, which uses models that include neural networks. Deep learning models may include, for example, deep neural networks (DNNs), convolutional neural networks (CNNs), etc.

[0025] It should be noted that the AI / ML models presented hereinafter are examples and are not limited to the illustrated AI / ML models. They can be modified or altered by using different Al or ML algorithms. The configuration of the neural network is not limited to the configuration disclosed in the present disclosure and can be modified. It is contemplated that features, advantages,and significances of example embodiments described hereinabove are merely a portion of the present disclosure, and are not intended to be exhaustive or to limit the scope of the present disclosure. Further descriptions of the features, components, configuration, operations, and implementations of the example embodiments of the present disclosure are provided in the following.

[0026] According to example embodiments, a method for DDoS attack detection and mitigation may be provided. The method may include collecting and formatting traffic data, determining the likelihood of a DDoS attack based on the formatted data using a machine-learning based algorithm, notifying the system of a potential DDoS attack based on the determined likelihood, and applying a mitigation policy if the DDoS attack likelihood is high enough (for example, passes a threshold).

[0027] Accordingly, it can be understood that example embodiments allow for a more accurate and predictive method of DDoS detection and mitigation. Since factors of number of calls and memory utilization are considered in the algorithm, it is also possible to implement the system in telecommunications networks.

[0028] Although below embodiments are described primarily with reference to DDoS attacks, it should be appreciated that other faults (such as DoS attacks) may be predicted, and mitigated based on the example method described below.

[0029] FIG. 1 illustrates a system architecture diagram according to one or more example embodiments.

[0030] Network traffic data 100 may be received and provided to at least one of the learning module 110, detection module 120, anomaly detection 130, and mitigation control module140. Network traffic data 100 may include data describing one or more network packets at a given frame, that is, at a specific instance in time (described in detail with reference to TABLE 1 below). Network traffic data 100 may be formatted, for example, as a datasheet, a table, and may be stored in a database or other storage methods, depending on the specific implementation.

[0031] Learning module 110 may be responsible for collecting, processing, and / or recording network traffic data 100. In particular, learning module 110 may use previous / historical data at a given timeframe (for example, 1 minute) prior to the current data, and use it to generate a “benchmark” dataset. This may be stored in benchmark dataset 111. The term “benchmark”, as used herein, may refer to predetermined “past” data relative to the current network traffic data 100.

[0032] Detection module 120 may be responsible for obtaining the “current” traffic data from the datasheet, and compared with “previous’Vbenchmark data (e.g., received from learning module 110) in order to determine the likelihood (probability) of a DDoS attack. This may be done using an Al or ML approach, which may be implemented, for example, using logistic regression with the benchmark data. The specific detection logic 121 may be configured, for example, by comparing benchmark vs current data for one or more param eters / data types from the network traffic data 100.

[0033] As an example, detection logic 121 may be configured to implement an ML approach using logistic regression (using a sigmoid function), in conjunction with supervised learning to determine / predict the probability of a fault (such as the DDoS attack) occurring based on input parameters. According to example embodiments, memory utilization in conjunction with the number of active call or connection requests may be used (an example is described withreference to the formulas (l)-(4) below). This sigmoid function may be used as an activation function for the supervised learning.

[0034] Anomaly detection module 130 may be configured to receive the determined probability from detection module 120, and may be configured to predict whether there is a likelihood of a fault (such as DDoS attack) occurring. According to embodiments, this may be based on a predetermined threshold value for a probability percentage (for example, if the probability received from detection module 120 is greater than 20%, then there is a strong likelihood).

[0035] Anomaly detection module 130 may be configured to send a notification 131 to the network operator based on whether there is a strong likelihood of a fault occurring or not.

[0036] Mitigation control module 140 may be configured to receive an instruction / message from anomaly detection module that a fault has occurred, and will accordingly implement a policy 141 to control unfiltered network traffic 101 to output clean network traffic by mitigating network faults at 102 (e.g., without any malicious traffic data).

[0037] Examples of policies 141 which may be applied may include, but are not necessarily limited to, rate limiting (limiting the number of requests, a server will accept over a certain time window is also a way of mitigating denial-of-service attacks as first level of attack prevention) and restrict ping request (to overcome ICMP flood type DDoS attack, any host should be allowing ping request up to some limited counts). Other policies may be included, depending on the specific implementation.

[0038] An example network datastore table according to one or more example embodiments is shown in TABLE 1 below. The network datastore table may indicate one or moredata which may be related to one or more parameters associated with the network. Examples of the one or more parameters are described herein.> &&TABLE 1: Example Network Datastore Table

[0039] The network datastore table may be stored in a database, or some other form of memory / storage. The network datastore table may be updated in realtime, or it may also be updated in “chunks” (e.g., blocks of multiple packets spanning a timeframe may be written).

[0040] Example parameters which may be implemented in the network datastore table are described as follows:

[0041] 1 Time: This may include any measurement of time (e.g., milliseconds, seconds, minutes, etc.)

[0042] 2 Frame Number: This may be the specific identifier / number of packets. For example, packets 1, 2, and 3 are shown in TABLE 1.

[0043] 3. Frame Length: This may be the size of the packet. In the illustrated example, packet 1 is 64 bytes, packet 2 is 2978 bytes, packet 3 is 64 bytes.

[0044] 4. Source IP: This is the IP address of the source. Although IPv4 is illustrated in TABLE 1, IP addresses used herein may also include IPv6, and all other relevant formats of IP addresses.

[0045] 5. Destination IP: This is the IP address of the destination.

[0046] 6. Source Port: This is the source TCP port of the packet.

[0047] 7. Destination Port: This is the destination TCP port of the packet.

[0048] 8. Protocol: Protocol name of the connection request. Typically, this may be TCP, but other protocols may be specified, depending on the specific implementation and type of network traffic.

[0049] 9. Active Call / Connection: Number of active calls or connections. In the illustrated example, packet 1 has 1 active call / connection, packet 2 has 11, and packet 3 has 22.

[0050] 10. Available System Resource (Memory): This specifies the current memory utilization. This may be described as how much memory is still remaining, in a unit such as, for example, kilobytes. However, it should be appreciated that according to embodiments, the current utilized memory itself may also be specified.

[0051] It should be appreciated that the above list of parameters which may be implemented in the network datastore table is non-exhaustive, and other parameters may be added / removed depending on the specific implementation.

[0052] According to an embodiment, anomaly detection module 130 may be configured with logic using example probability functions as described below. Formulas (1) and (2) describe ratios of system memory utilization and system active calls, which may be utilized as parameters for determining the probability.. . . > „ „ > > ... . ^Benchmark Memory Utilization(Mb Mb (1) Ratio of System Memory utilization (M) = = —^Current Memory Utilization(Mc) Me (2) Ratio of System Active Call (C) =>

[0053] An example formula (3) and (4) which implements a sigmoid function for linear regression, which may be used for the probability of a fault (such as a DDoS attack) may be given by:(3) Probability of DDoS Attack Occurrence (P) % = [{l-(l / (l+e (- ) ))}*2]*100(4) X = [{(Mh / Mc)*(Cb / Cc)}*F] + b

[0054] Wherein:

[0055] Mb = the total summation of benchmark memory utilization (benchmark refers to the “previous” timeframe)

[0056] Me = the total summation of current memory utilization

[0057] Cb = the total summation of benchmark active calls / connections

[0058] Cc = the total summation of current active calls / connections

[0059] F = the maximum number of non-zero values (this may be obtained by solving for X in eA( X) for a non-zero value up until a given decimal point. For example, 15 decimal points would result in a value of X of 35. Accordingly, for examples described herein, F may be 35).

[0060] b = intercept value (may typically be zero).

[0061] Example scenarios with reference to the above formula illustrated in FIG. 3 are described below.

[0062] Example 1: the ratio of Mb / Mc and Cb / Cc are both 1. This means that there is no change in the memory utilization and number of calls / connections since the current and benchmark / learning datasets are identical. It may be assumed that, for example, active calls is 100, and total memory utilization is 1000 MB for both current and benchmark / learning datasets.

[0063] In example 1, given F=35 and b=0, X = 35, and P=0.0000000000002%

[0064] Accordingly, the system would conclude the likelihood of a fault / DDoS attack is low.

[0065] Example 2: the ratio of Mb / Mc and Cb / Cc are 1 / 1000. This means that there is a 1000 times increase in memory utilization and number of calls / connections.

[0066] In example 2, given F=35 and b=0, X = 0.000035, and P=99.99%.

[0067] Accordingly, the system would conclude the likelihood of a fault / DDoS attack is almost certain. In this scenario, the system may send a notification after the prediction. However, in the case that it is certain, the system may send an alert instead to the network, such that mitigation measurements can be taken ahead of time.

[0068] Example 3: the ratio ofMb / Mc and Cb / Cc are 1000. This means that there is a 1000 times decrease in memory utilization and number of calls / connections.

[0069] In example 3, given F=35 and b=0, X=35000000, and P=0%. Accordingly, the system would conclude there is no possibility of a DDoS attack.

[0070] It should be appreciated that the above descriptions using logistic regression are merely an example, and other implementations to use active calls / connections and memory utilization for a machine-learning based method for predicting DDoS attacks is possible. Furthermore, other models for using other data types (e g., other parameters as described with reference to TABLE 1) may also be included according to some implementations.

[0071] FIG. 2, illustrates an example method 200 for fault detection, according to one or more example embodiments. It should be appreciated that while it is described with reference to a “fault”, it may be used to implement DDoS or DoS detection / mitigation.

[0072] At operation S210, a network dataset comprising a first network data and a second network data (which is a different type than the first network data) may be received. The dataset may include at least one or more of: a timestamp; an identifier of a packet; a size of the packet in bytes; a source IP address; a destination IP address; a source TCP port; a destination TCP port; and a protocol name of the connection request.

[0073] At operation S220, the probability of a fault occurring based on comparing current and benchmark data from the network dataset may be calculated. In particular, it may be based on comparing current values of the first network data and current values of the second network data with predefined benchmark values of the first network data and predefined benchmark values of the second network data respectively. Calculating the probability of the fault occurring may be based on a sigmoid function as an activation function for supervised learning using a machine learning (ML) model.

[0074] According to example embodiments, the first network data may include memory utilization and the second network data may include number of active connections, wherein the sigmoid function is based on a first ratio of the predefined benchmark values compared to the current values of the first network data, and a second ratio of the predefined benchmark values compared to the current values of the second network data. According to embodiments, the benchmark data can be refreshed at every time interval (e.g., every minute, such that n-1 minute data is captured as benchmark data, and compared with n minute data for the current data, wherein n is the current minute).

[0075] At operation S230, the calculated probability in operation S220 may be compared with a threshold value (e.g., a predetermined percentage probability) to determine / predict the likelihood of a fault occurring. This may include comparing the calculated fault probability with a threshold probability value. Based on the calculated fault probability being greater than or equal to the threshold probability value, the system may send a notification to the network operator that the fault is likely to occur, whereas based on the calculated fault probability being less than the threshold probability value fFor example, this may be a percentage threshold value ranging from0-30%, although the specific range can depend on the specific implementation), the system may send a notification to the network operator that the fault is unlikely to occur. The threshold probability value may be obtained using artificial intelligence (Al) based on historical fault data.

[0076] At operation S240, the mitigation policy for the fault may be applied based on the calculated probability in operation S220, or the likelihood from operation S230. The fault may include, for example, one of a Distributed Denial of Service (DDoS) or a Denial of Service (DoS) attack, and the fault mitigation policy may include at least one of rate limiting and restricting ping requests.

[0077] Accordingly, it can be understood that the above embodiments allow for a more accurate and predictive method of DDoS detection and mitigation. Since factors of number of calls and memory utilization are considered in the algorithm, it is also possible to implement the system in telecommunications networks.

[0078] FIG. 3 illustrates a block diagram of an example device 300 for implementing one or more example embodiments. As shown in FIG. 3, the device 300 includes processor 310, a memory 320, a storage component 330, an input component 340, an output component 350, a communication interface 360, and a bus 370.

[0079] The processor 310, as used herein, means any type of computational circuit that may comprise hardware elements and software elements. The processor 310 may be embodied as a multi-core processor, a single core processor, or a combination of one or more multi-core processors and / or one or more single core processors, a distributed processing system, or the like. The processor 310 may be a Central Processing Unit (CPU), a graphics processing unit (GPU), anaccelerated processing unit (APU), an application-specific integrated circuit (ASIC), or another type of processing component.

[0080] Memory 320 includes a non-transitory computer readable medium. Memory 320 includes a random-access memory (RAM), a read only memory (ROM), and / or another type of dynamic or static storage device (e.g., a flash memory, a magnetic memory, and / or an optical memory) that stores information and / or instructions for use by processor 310. The memory 320 comprises machine-readable instructions which are executable by the processor 310. These machine-readable instructions when executed by the processor 310 cause the processor 310 to perform one or more method steps of an embodiment described above.

[0081] Storage component 330 stores information and / or software related to the operation and use of the device 300. For example, storage component 330 may include a hard disk (e.g., a magnetic disk, an optical disk, a magneto-optic disk, and / or a solid-state disk), a compact disc (CD), a digital versatile disc (DVD), a floppy disk, a cartridge, a magnetic tape, and / or another type of non-transitory computer-readable medium, along with a corresponding drive.

[0082] Input component 340 is configured to receive information, such as user input. For example, the input component 340 may include, but not be limited to, a touch screen display, a keyboard, a keypad, a mouse, a button, a switch, and / or a microphone. Additionally, or alternatively, the input component 340 may include a sensor for sensing information (e.g., a global positioning system (GPS), an accelerometer, a gyroscope, and / or an actuator).

[0083] Output component 350 is configured to provide output information from the device 300. For example, the output component 350 may be, but not limited to, a display, a speaker, an instruction device to an external device, and / or one or more light-emitting diodes (LEDs).

[0084] Communication interface 360 is an interface that provides a communication connection to other devices, such as external devices and internal devices. The connection by the communication interface 360 can be a wired connection, a wireless connection, or a combination of wired and wireless connections, and can be a direct connection or an indirect connection via a communication network that exists between the device 300 and other devices. In other words, the standard of the communication interface 360 is not limited.

[0085] The bus 370 acts as an interconnect between the processor 310, the memory 320, the storage component 330, the input component 340, the output component 350, and the communication interface 360 of the device 300. The bus 370 may include a wired interconnection or a wireless interconnection.

[0086] The number and arrangement of components shown in FIG. 3 are provided as an example. In practice, device 300 may include additional components, fewer components, different components, or differently arranged components than those shown in FIG. 3. Additionally, or alternatively, a set of components (e.g., one or more components) of device 300 may perform one or more functions described as being performed by another set of components of device 300. Further, one or more method steps described in any of the embodiments may be performed utilizing a plurality of devices 300 in communication with one another.Example Implementation Environment

[0087] Example embodiments of the present disclosure may be implemented in any suitable type of environment. In the following, an example environment (in which the example embodiments may be implemented) is described.

[0088] FIG. 4 illustrates a block diagram of an example environment 400 for implementing in which systems and / or method, described herein, may be implemented. The implementation environment 400 includes a UE (User equipment) 410, a service environment 420, and a network 430. The service environment 420 include one or more sub-environments 421. To illustrate this, FIG. 4 shows, for convenience, examples of a 1st sub-environment 421-1, a 2nd sub-environment 421-2, and an N-th sub-environment 421-N (where N is any natural number).

[0089] The UE 410 is connected to the network 430, and the network 430 is connected to the service environment 420. The connections may be wired, wireless, or a combination of both wired and wireless. The UE 410 and the service environment 420 are connected via the network 430.

[0090] The UE 410 is a device that communicates with the service environment 420. The UE 410 receives information from the service environment 420 and / or sends information to the service environment 420. Also, the UE 410 may generate and / or store information to be transmitted, as necessary. Also, the UE 410 may store and / or process information that is received, as necessary.

[0091] The example figure 4 refers to the “UE”. However, it should be understood by those skilled in the art that general terms such as “user device,” “terminal,” “terminal device,” “communication device,” and “communication terminal” can be used interchangeably with the term “UE.”

[0092] For example, the UE 410 may include a computing device (e.g., a desktop computer, a laptop computer, a tablet computer, a handheld computer, a smart speaker, a server, etc.), amobile phone (e.g., a smart phone, a radiotelephone, etc.), a wearable device (e.g., a pair of smart glasses or a smart watch), or a similar device.

[0093] The service environment 420 is an environment that communicates with the UE 410 to provide one or more services. The service environment 420 receives information from the UE 410 and / or sends information to the UE 410. Also, the service environment 420 may generate and / or store information to be transmitted, as necessary. Also, the service environment 420 may store and / or process information that is received, as necessary. For example, the service environment 420 may provide computing resources as one of the services. It should be noted that the service is not limited to being provided to the UE; it may also be provided to devices other than the UE. For example, based on communication from the UE, the service may perform processes such as anomaly detection or traffic analysis and notify the results to a predetermined destination.

[0094] The example FIG. 4 refers to the “service environment”. The term "service environment" is used to refer to the broader context within which services operate. For example, cloud environments, platforms, computing systems, network systems, and cloud systems generally represent the environments in which services are conducted, and these are included within the "service environment." However, the "service environment" is not limited to these examples. Additionally, the specific types of environments within the "service environment" are not restricted. For instance, cloud environments and cloud systems can be categorized as private cloud, public cloud, hybrid cloud, or multi-cloud, all of which are included within the "service environment."

[0095] The one or more services provided by the service environment 420 is not specifically limited and can be adjusted according to the embodiments. For example, the servicesmay include a service that provides information to the UE 410, a service that stores information from the UE 410, or a service that performs processing based on information from the UE 410 and returns the results of the processing.

[0096] In an embodiment, the Service Environments 420 may also provide computing resources as the service. The computing resources can be hardware resources and / or software resources. For example, applications, processors, memory, and storage can be included in the provided computing resources. Each computing resource can communicate with other computing resources via wired connections, wireless connections, or a combination of wired and wireless connections.

[0097] The provided computing resources can be actual resources (also referred to as physical resources) and / or virtual resources. Furthermore, means of virtualization for virtual resources can be selected as appropriate. That is, in this disclosure, the use of adjectives such as "Virtual" or "Virtualized" to describe names does not imply that they are virtualized by a specific means of virtualization. For example, “virtual machine” refers to software that operates like an actual computer, realized through means of virtualization, and it is not intended to exclude those realized by specific means of virtualization such as Hypervisors or Containers. Conversely, when means of virtualization such as Hypervisors or containers are mentioned in this disclosure, it is merely cited as a general method of implementation. It should also be interpreted that embodiments implemented with other virtualization means are also disclosed. Also, the services may also be provided using resources virtualized by different means.

[0098] The service environment 420 includes one or more devices, such as servers and network devices, which provide services or perform processes. The placement of these deviceswithin the service environment 420 can be determined as appropriate. Additionally, if the service environment 420 includes one or more sub-environments 421, the placement of devices can be determined based on predetermined policies for each sub-environment 421. For example, devices related to the first service may be placed in the 1st sub-environment 421-1, and devices related to the second service may be placed in the 2nd sub -environment 421-2. In another example, devices expected to have a higher load than a predetermined threshold may be placed in the 1st subenvironment 421-1, while devices expected to have a lower load than the predetermined threshold may be placed in the 2nd sub-environment 421-2. In this way, specific devices can be placed in specific sub -environments 421. Conversely, each sub-environment 421 can be specialized for a particular purpose.

[0099] In an embodiment, all processes executed in a single service may run within a single service environment, or in multiple service environments. Multiple processes executed in a single service could be provided by different service environments.

[0100] The network 430 is a network that exchanges information between the UE 410 and the service environment 420. The network 430 includes one or more wired and / or wireless networks.

[0101] For example, the network 430 may include a cellular network (e.g., a fifth generation (5G) network, a long-term evolution (LTE) network, a third generation (3G) network, a code division multiple access (CDMA) network, etc ), a public land mobile network (PLMN), a local area network (LAN), a wide area network (WAN), a metropolitan area network (MAN), a telephone network (e.g., the Public Switched Telephone Network (PSTN)), a private network, anad hoc network, an intranet, the Internet, a fiber optic-based network, or the like, a non-terrestrial network (NTN), and / or a combination of these or other types of networks.

[0102] The network 430 can be a part of a network. For example, in a 5G network that includes a RAN, a transport network, and a core network, the network 430 can be at least one of the RAN, the transport network, or the core network. For example, the service environment 420 could be in the core network, in which case the network 430 could correspond to a network that is a combination of a RAN and a transport network and is part of the 5G network.

[0103] The number and arrangement of devices and networks shown in FIG. 4 are provided as an example. It should be understood that any changes that may be implemented by those skilled in the art, such as the addition or rearrangement of well-known devices or networks at the time of implementation, are included in this disclosure.Various Aspects of Embodiments

[0104] It is contemplated that the example embodiments described hereinabove with reference to FIG. 1 to FIG. 4 are merely examples of possible embodiments of the present disclosure, and are not intended to limit or restrict the scope of the present disclosure.

[0105] Specifically, the foregoing disclosure provides illustration and description, but is not intended to be exhaustive or to limit the implementations to the precise form disclosed. Modifications and variations are possible in light of the above disclosure or may be acquired from practice of the implementations.

[0106] Some embodiments may relate to a device (e.g., node, etc.), a system, a method, and / or a computer-readable medium at any possible technical detail level of integration. Further, one or more of the above components described above may be implemented as instructions storedon a computer-readable medium and executable by at least one processor (and / or may include at least one processor). The computer-readable medium may include a computer-readable non-transitory storage medium (or media) having computer-readable program instructions thereon for causing a processor to carry out operations.

[0107] The computer-readable storage medium can be a tangible device that can retain and store instructions for use by an instruction execution device. The computer-readable storage medium may be, for example, but is not limited to, an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination of the foregoing. A non-exhaustive list of more specific examples of the computer-readable storage medium includes the following: a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), electrically erasable programmable read-only memory (EEPROM), a static random access memory (SRAM), a portable compact disc read-only memory (CD-ROM), a digital versatile disk (DVD), a memory stick, a floppy disk, a mechanically encoded device such as punch-cards or raised structures in a groove having instructions recorded thereon, and any suitable combination of the foregoing. A computer-readable storage medium, as used herein, is not to be construed as being transitory signals per se, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through a waveguide or other transmission media (e.g., light pulses passing through a fiber-optic cable), or electrical signals transmitted through a wire.

[0108] Computer-readable program instructions described herein can be downloaded to respective computing / processing devices from a computer-readable storage medium or to anexternal computer or external storage device via a network, for example, the Internet, a local area network, a wide area network and / or a wireless network. The network may comprise copper transmission cables, optical transmission fibers, wireless transmission, routers, firewalls, switches, gateway computers, and / or edge servers. A network adapter card or network interface in each computing / processing device receives computer-readable program instructions from the network and forwards the computer-readable program instructions for storage in a computer-readable storage medium within the respective computing / processing device.

[0109] Computer-readable program code / instructions for carrying out operations may be assembler instructions, instruction-set-architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state-setting data, configuration data for integrated circuitry, or either source code or object code written in any combination of one or more programming languages, including an object-oriented programming language such as Smalltalk, C++, or the like, and procedural programming languages, such as the "C" programming language or similar programming languages.

[0110] The computer-readable program instructions may execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer or entirely on the remote computer or server. In the latter scenario, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection may be made to an external computer (for example, through the Internet using an Internet Service Provider). In some embodiments, electronic circuitry including, for example, programmable logic circuitry, field-programmable gate arrays (FPGA), or programmable logic arrays (PLA) mayexecute the computer-readable program instructions by utilizing state information of the computer-readable program instructions to personalize the electronic circuitry, in order to perform aspects or operations.[0U1] These computer-readable program instructions may be provided to a processor of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks. These computer-readable program instructions may also be stored in a computer-readable storage medium that can direct a computer, a programmable data processing apparatus, and / or other devices to function in a particular manner, such that the computer-readable storage medium having instructions stored therein comprises an article of manufacture including instructions which implement aspects of the function / act specified in the flowchart and / or block diagram block or blocks.

[0112] The computer-readable program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other devices to cause a series of operational steps to be performed on the computer, other programmable apparatus or other devices to produce a computer-implemented process, such that the instructions which execute on the computer, other programmable apparatus, or other device implement the functions / acts specified in the flowchart and / or block diagram block or blocks.

[0113] The flowchart and block diagrams in the Figures illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer-readable media according to various embodiments. In this regard, each block in the flowchart orblock diagrams may represent a module, segment, or portion of instructions, which comprises one or more executable instructions for implementing the specified logical function(s). The method, computer system, and computer-readable medium may include additional blocks, fewer blocks, different blocks, or differently arranged blocks than those depicted in the Figures. In some alternative implementations, the functions noted in the blocks may occur out of the order noted in the Figures. For example, two blocks shown in succession may, in fact, be executed concurrently or substantially concurrently, or the blocks may sometimes be executed in the reverse order, depending upon the functionality involved. It will also be noted that each block of the block diagrams and / or flowchart illustration, and combinations of blocks in the block diagrams and / or flowchart illustration, can be implemented by special purpose hardware-based systems that perform the specified functions or acts or carry out combinations of special purpose hardware and computer instructions.

[0114] It will be apparent that systems and / or methods, described herein, may be implemented in different forms of hardware, firmware, or a combination of hardware and software. The actual specialized control hardware or software code used to implement these systems and / or methods is not limited to the implementations. Thus, the operation and behavior of the systems and / or methods were described herein without reference to specific software code — it is understood that software and hardware may be designed to implement the systems and / or methods based on the description herein.

[0115] In view of the above, various further respective aspects and features of embodiments of the present disclosure may be defined by the following items:Item [1]: A method including: receiving a dataset recorded from a network including first network data and second network data of a different data type than the first network data; calculating, based on comparing current values of the first network data and current values of the second network data with predefined benchmark values of the first network data and predefined benchmark values of the second network data respectively, a probability of a fault occurring; and based on the calculated fault probability, applying a fault mitigation policy to the network.Item [2]: The method according to Item [1], wherein the first network data comprises memory utilization and the second network data comprises number of active connections, wherein calculating the probability of the fault occurring is based on a sigmoid function based on a first ratio of the predefined benchmark values compared to the current values of the first network data, and a second ratio of the predefined benchmark values compared to the current values of the second network data.Item [3]: The method according to any one of Items [l]-[2], wherein determining the fault probability includes: comparing the calculated fault probability with a threshold probability value; based on the calculated fault probability being greater than or equal to the threshold probability value, sending a notification to the network that the fault is likely to occur; and based on the calculated fault probability being less than the threshold probability value, sending a notification to the network that the fault is unlikely to occur.Item [4]: The method according to Item [3], wherein the threshold probability value is obtained using artificial intelligence (Al) based on historical fault data, wherein the predefined benchmark values of the first network data and predefined benchmark values of the second network data are updated after at a predetermined time interval has elapsed, based on the current values of the first network data and the current values of the second network data respectively.Item [5]: The method according to any one of Items [I]-[4], wherein the dataset may comprise at least one or more of: a timestamp; an identifier of a packet; a size of the packet in bytes; a source IP address; a destination IP address; a source TCP port; a destination TCP port; and a protocol name of the connection request.Item [6]: The method according to any one of Items [I]-[5], wherein the fault includes one of a Distributed Denial of Service (DDoS) or a Denial of Service (DoS) attack, and wherein the fault mitigation policy may comprise at least one of rate limiting and restricting ping requests.Item [7]: The method according to any one of Items [l]-[6], wherein the sigmoid function is an activation function for supervised learning using a machine learning (ML) model.Item [8] An apparatus configured to receive a dataset recorded from a network including first network data and second network data of a different data type than the first network data; calculate, based on comparing current values of the first network data and current values of the second network data with predefined benchmark values of the first network data and predefined benchmark values of the second network data respectively, a probability of a fault occurring; and based on the calculated fault probability, apply a fault mitigation policy to the network.Item [9]: The apparatus according to Item [8], wherein the first network data comprises memory utilization and the second network data comprises number of active connections, wherein calculating the probability of the fault occurring is based on a sigmoid function based on a first ratio of the predefined benchmark values compared to the current values of the first network data, and a second ratio of the predefined benchmark values compared to the current values of the second network data.Item

[0010] : The apparatus according to any one of Items [8]-[9], wherein the apparatus is configured to determine the fault probability by: comparing the calculated fault probability with a threshold probability value; based on the calculated fault probability being greater than or equal to the threshold probability value, sending a notification to the network that the fault is likely to occur; and based on the calculated fault probability being less than the threshold probability value, sending a notification to the network that the fault is unlikely to occur.Item

[0011] : The apparatus according to Item

[0010] , wherein the threshold probability value is obtained using artificial intelligence (Al) based on historical fault data, wherein the predefined benchmark values of the first network data and predefined benchmark values of the second network data are updated after at a predetermined time interval has elapsed, based on the current values of the first network data and the current values of the second network data respectively.Item

[0012] : The apparatus according to any one of Items [8]-[l 1] wherein the dataset may comprise at least one or more of: a timestamp; an identifier of a packet; a size of the packet in bytes; a source IP address; a destination IP address; a source TCP port; a destination TCP port; a protocol name of the connection request.Item

[0013] : The apparatus according to any one of Items [8]-

[0012] , wherein the fault includes one of a Distributed Denial of Service (DDoS) or a Denial of Service (DoS) attack, and wherein the fault mitigation policy may comprise at least one of rate limiting and restricting ping requests.Item

[0014] : The apparatus according to any one of Items [8]-[l 1], wherein the sigmoid function is an activation function for supervised learning using a machine learning (ML) model.Item

[0015] : A non-transitory computer-readable recording medium having recorded thereon instructions executable to perform a method including: receiving a dataset recorded from a network including first network data and second network data of a different data type than the first network data; calculating, based on comparing current values of the first network data and current values of the second network data with predefined benchmark values of the first network data and predefined benchmark values of the second network data respectively, a probability of a fault occurring; and based on the calculated fault probability, applying a fault mitigation policy to the network.Item

[0016] : The non-transitory computer-readable recording medium according to Item

[0015] , wherein the first network data comprises memory utilization and the second network data comprises number of active connections, wherein calculating the probability of the fault occurring is based on a sigmoid function based on a first ratio of the predefined benchmark values compared to the current values of the first network data, and a second ratio of the predefined benchmark values compared to the current values of the second network data.Item

[0017] : The non-transitory computer-readable recording medium according to Item

[0016] , wherein determining the fault probability comprises: comparing the calculated fault probability with a threshold probability value; based on the calculated fault probability being greater than or equal to the threshold probability value, sending a notification to the network that the fault is likely to occur; and based on the calculated faultprobability being less than the threshold probability value, sending a notification to the network that the fault is unlikely to occur.Item

[0018] : The non-transitory computer-readable recording medium according to Item

[0017] , wherein the threshold probability value is obtained using artificial intelligence (Al) based on historical fault data, wherein the predefined benchmark values of the first network data and predefined benchmark values of the second network data are updated after at a predetermined time interval has elapsed, based on the current values of the first network data and the current values of the second network data respectively.Item

[0019] The non-transitory computer-readable recording medium according to any one of Items

[0015] -

[0018] , wherein the dataset may comprise at least one or more of: a timestamp; an identifier of a packet; a size of the packet in bytes; a source IP address; a destination IP address; a source TCP port; a destination TCP port; and a protocol name of the connection request.Item

[0020] The non-transitory computer-readable recording medium according to any one of Items

[0015] -

[0019] , wherein the sigmoid function is an activation function for supervised learning using a machine learning (ML) model.

[0116] It can be understood that numerous modifications and variations of the present disclosure are possible in light of the above teachings. It will be apparent that within the scope ofthe appended clauses, the present disclosures may be practiced otherwise than as specifically described herein.

Claims

What is claimed is:

1. A method comprising:receiving a dataset recorded from a network comprising first network data and second network data of a different data type than the first network data;calculating, based on comparing current values of the first network data and current values of the second network data with predefined benchmark values of the first network data and predefined benchmark values of the second network data respectively, a probability of a fault occurring; andbased on the calculated fault probability, applying a fault mitigation policy to the network.

2. The method as claimed in claim 1, wherein the first network data comprises memory utilization and the second network data comprises number of active connections, wherein calculating the probability of the fault occurring is based on a sigmoid function based on a first ratio of the predefined benchmark values compared to the current values of the first network data, and a second ratio of the predefined benchmark values compared to the current values of the second network data.

3. The method as claimed in claim 1, wherein determining the fault probability comprises:comparing the calculated fault probability with a threshold probability value;based on the calculated fault probability being greater than or equal to the threshold probability value, sending a notification to the network that the fault is likely to occur; andbased on the calculated fault probability being less than the threshold probability value, sending a notification to the network that the fault is unlikely to occur.

4. The method as claimed in claim 3, wherein the threshold probability value is obtained using artificial intelligence (Al) based on historical fault data, wherein the predefined benchmark values of the first network data and predefined benchmark values of the second network data are updated after at a predetermined time interval has elapsed, based on the current values of the first network data and the current values of the second network data respectively.

5. The method as claimed in claim 1, wherein the dataset may comprise at least one or more of:a timestamp;an identifier of a packet;a size of the packet in bytes;a source IP address;a destination IP address;a source TCP port;a destination TCP port; anda protocol name of the connection request.

6. The method as claimed in claim 1, wherein the fault comprises one of a Distributed Denial of Service (DDoS) or a Denial of Service (DoS) attack, and wherein the fault mitigation policy may comprise at least one of rate limiting and restricting ping requests.

7. The method as claimed in claim 1, wherein the sigmoid function is an activation function for supervised learning using a machine learning (ML) model.

8. An apparatus configured toreceive a dataset recorded from a network comprising first network data and second network data of a different data type than the first network data;calculate, based on comparing current values of the first network data and current values of the second network data with predefined benchmark values of the first network data and predefined benchmark values of the second network data respectively, a probability of a fault occurring; andbased on the calculated fault probability, apply a fault mitigation policy to the network.

9. The apparatus as claimed in claim 8, wherein the first network data comprises memory utilization and the second network data comprises number of activeconnections, wherein calculating the probability of the fault occurring is based on a sigmoid function based on a first ratio of the predefined benchmark values compared to the current values of the first network data, and a second ratio of the predefined benchmark values compared to the current values of the second network data.

10. The apparatus as claimed in claim 8, wherein the apparatus is configured to determine the fault probability by:comparing the calculated fault probability with a threshold probability value; based on the calculated fault probability being greater than or equal to the threshold probability value, sending a notification to the network that the fault is likely to occur; andbased on the calculated fault probability being less than the threshold probability value, sending a notification to the network that the fault is unlikely to occur.

11. The apparatus as claimed in claim 10, wherein the threshold probability value is obtained using artificial intelligence (Al) based on historical fault data, wherein the predefined benchmark values of the first network data and predefined benchmark values of the second network data are updated after at a predetermined time interval has elapsed, based on the current values of the first network data and the current values of the second network data respectively.

12. The apparatus as claimed in claim 8, wherein the dataset may comprise at least one or more of:a timestamp;an identifier of a packet;a size of the packet in bytes;a source IP address;a destination IP address;a source TCP port;a destination TCP port; anda protocol name of the connection request.

13. The apparatus as claimed in claim 8, wherein the fault comprises one of a Distributed Denial of Service (DDoS) or a Denial of Service (DoS) attack, and wherein the fault mitigation policy may comprise at least one of rate limiting and restricting ping requests.

14. The apparatus as claimed in claim 8, wherein the sigmoid function is an activation function for supervised learning using a machine learning (ML) model.

15. A non-transitory computer-readable recording medium having recorded thereon instructions executable to perform a method comprising:receiving a dataset recorded from a network comprising first network data and second network data of a different data type than the first network data;calculating, based on comparing current values of the first network data and current values of the second network data with predefined benchmark values of the first network data and predefined benchmark values of the second network data respectively, a probability of a fault occurring; andbased on the calculated fault probability, applying a fault mitigation policy to the network.

16. The non-transitory computer-readable recording medium as claimed in claim 15, wherein the first network data comprises memory utilization and the second network data comprises number of active connections, wherein calculating the probability of the fault occurring is based on a sigmoid function based on a first ratio of the predefined benchmark values compared to the current values of the first network data, and a second ratio of the predefined benchmark values compared to the current values of the second network data.

17. The non-transitory computer-readable recording medium as claimed in claim 15, wherein determining the fault probability comprises:comparing the calculated fault probability with a threshold probability value;based on the calculated fault probability being greater than or equal to the threshold probability value, sending a notification to the network that the fault is likely to occur; and based on the calculated fault probability being less than the threshold probability value, sending a notification to the network that the fault is unlikely to occur.

18. The non-transitory computer-readable recording medium as claimed in claim 17, wherein the threshold probability value is obtained using artificial intelligence (Al) based on historical fault data, wherein the predefined benchmark values of the first network data and predefined benchmark values of the second network data are updated after at a predetermined time interval has elapsed, based on the current values of the first network data and the current values of the second network data respectively.

19. The non-transitory computer-readable recording medium as claimed in claim 15, wherein the dataset may comprise at least one or more ofa timestamp;an identifier of a packet;a size of the packet in bytes;a source IP address;a destination IP address;a source TCP port;a destination TCP port; anda protocol name of the connection request.

20. The non-transitory computer-readable recording medium as claimed in claim 15, wherein the sigmoid function is an activation function for supervised learning using a machine learning (ML) model.