5G Network Intrusion Detection via Traffic Copy Comparison

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current mechanisms lack the ability to detect malicious network intrusions in 5G core networks, particularly when unauthorized entities impersonate network functions (NFs) to gain access and exploit vulnerabilities.

Innovation Solution

A network traffic analysis system that receives traffic copies from 5G network functions, compares them to identify matching traffic patterns, and issues security notifications when discrepancies indicate potential network intrusions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication and access control mechanisms are used in 5G core networks, then network operations can proceed normally, but the system becomes vulnerable to impersonation attacks and lacks intrusion detection capability

Engineering Contradiction:
Improvenetwork securityVSAvoiddetection system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a Network Repository Function (NRF) as an intermediary component that mediates between network functions and provides detection capabilities. The NRF receives topology data from multiple NFs and analyzes communication patterns to detect intrusions, thereby adding security without requiring complex modifications to existing NFs.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where the NRF continuously monitors communication between NFs, compares observed patterns against expected behavior, and triggers alerts when anomalies are detected. This feedback loop enables dynamic security monitoring without disrupting normal network operations.

Inventive Principle:
Principle #23Feedback

2Reliability

If no intrusion detection mechanism is implemented, then the system remains simple and operations are uninterrupted, but vulnerabilities can be exploited for extended periods causing serious harm

Engineering Contradiction:
Improvedetection capabilityVSAvoidintrusion detection difficulty
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements preliminary action by having network functions proactively report their topology data and communication patterns to the NRF before intrusions can cause significant harm. The NRF pre-establishes baseline behavior patterns and can detect deviations indicating intrusions early in the attack lifecycle.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system uses copying by creating simplified representations of network topology and communication patterns that the NRF can analyze without processing actual sensitive data. This allows effective intrusion detection while reducing the complexity of analyzing raw network traffic.

Inventive Principle:
Principle #26Copying

3Measurement precision

If comprehensive traffic monitoring is performed to detect all intrusions, then detection accuracy improves, but system complexity and processing requirements increase significantly

Engineering Contradiction:
Improveintrusion detection accuracyVSAvoidanalysis system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent extracts only the essential elements needed for intrusion detection - specifically topology data and communication pattern information - from the complex network traffic. The NRF focuses analysis on these extracted features rather than processing all network traffic, thereby maintaining detection accuracy while reducing system complexity.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system segments the intrusion detection task into distinct functions: NFs collect and report topology data, the NRF analyzes patterns and detects anomalies, and alerting mechanisms notify relevant parties. This segmentation allows each component to remain relatively simple while achieving comprehensive detection capability.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20250133095A1Network intrusion detection
Publication Date: 2025.04.24 ORACLE INT CORP
  • US20250133095A1 patent drawing
  • US20250133095A1 patent drawing
  • US20250133095A1 patent drawing

AI summary

Various embodiments of the present technology generally relate to systems and methods for network intrusion detection. In certain embodiments, a network traffic analysis system may comprise one or more processors, and a memory having stored thereon instructions. The instructions, upon execution, may cause the one or more processors to receive, from a first network function (NF) in a communication exchange on a 5G network, a first copy of traffic from the communication exchange, determine whether a second copy of traffic corresponding to the first copy of traffic has been received from a second NF in the communication exchange, and in response to not receiving the second copy of traffic, issue a security notification to the first NF indicating a network intrusion.