5G IoT Slice DDoS Detection via Network Extraction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current 5G networks face significant challenges in detecting and mitigating Distributed Denial of Service (DDoS) attacks in IoT slices due to the inherent insecurity and constrained resources of IoT devices, which can be exploited to create botnets that overwhelm network resources, leading to service disruptions and security vulnerabilities.

Innovation Solution

A lightweight, real-time DDoS attack detection and mitigation system is implemented using a combination of Intrusion Detection Systems (IDS) and honeypots within the 5G-IoT network architecture, which profiles IoT devices, monitors parameters for anomalies, and employs deep learning-based algorithms to identify and isolate compromised devices, thereby reducing computational and storage complexities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional DDoS detection methods are used in 5G IoT slices, then detection capability is provided, but computational complexity and storage requirements become excessive for constrained IoT devices

Engineering Contradiction:
ImproveDDoS detection capabilityVSAvoidcomputational complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the DDoS detection and mitigation functions from the constrained IoT devices and relocates them to the network infrastructure (gNB and core network). The IoT devices simply report their status and receive instructions, while the network handles the computationally intensive tasks of traffic analysis, anomaly detection, and attack mitigation, thereby eliminating the complexity burden on device-end components.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces the gNB and core network functions as intermediaries between the IoT devices and the DDoS detection system. These intermediaries collect data from IoT devices, perform sophisticated analysis using deep learning models, and execute mitigation strategies, serving as a mediator that handles complex computations while keeping IoT devices simple.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security functions are implemented on constrained IoT devices, then local security protection is achieved, but device resources are overwhelmed

Engineering Contradiction:
Improvesecurity protectionVSAvoiddevice energy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts all security processing functions from the IoT devices and consolidates them in the network infrastructure. The devices only perform simple status reporting and receiving control instructions, while the gNB and core network handle encryption, traffic analysis, and attack response, thereby preserving device energy for core operational functions.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The network infrastructure provides self-service security protection by autonomously detecting attacks, analyzing traffic patterns using deep learning models, and executing mitigation strategies without requiring active participation or energy consumption from the IoT devices. The system serves itself through centralized intelligence.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If comprehensive security monitoring is implemented, then detection accuracy is improved, but storage requirements increase significantly

Engineering Contradiction:
Improvedetection accuracyVSAvoidstorage requirements
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent implements preliminary actions by collecting and storing only essential device status parameters and traffic metadata at the gNB and core network, rather than capturing complete packet data. The system pre-processes and filters data to retain only anomaly-indicative information, reducing storage needs while maintaining detection accuracy through targeted monitoring of critical parameters.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the parameters being monitored from comprehensive packet-level data to summarized statistical parameters and anomaly indicators. By transforming raw traffic data into aggregated metrics and focusing storage on critical anomaly markers rather than complete data streams, the system achieves high detection accuracy with reduced storage requirements.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20240223600A1METHOD AND APPARATUS FOR DDoS ATTACK DETECTION AND MITIGATION IN IoT NETWORK SLICES OF 5G NETWORKS
Publication Date: 2024.07.04 INDIAN INSTITUTE OF TECHNOLOGY
  • US20240223600A1 patent drawing
  • US20240223600A1 patent drawing
  • US20240223600A1 patent drawing

AI summary

An apparatus and lightweight method detects and prevents DDoS attacks in a 5G-IoT slice in real-time without putting the stress of security on the constrained IoT devices. The apparatus includes eight IoT devices, a gNB, and 5G core network. The core network includes of AMF, SMF, UPF, PCF, UDR, and Network Data Analytics Function (NWDAF). 5 IoT devices connected to an IoT slice via a gNB RAN and core network are loaded with DDoS code. The gNB gives the RAN part of the slice to the IoT devices while as core network functions provide the core network part of the slice. A real-time and lightweight method consisting of Intrusion Detection System (IDS) and honeypots is designed for DDoS attack detection in 5G IoT/mMTC slices. The system identifies the attack efficiently and is able to mitigate it with less computation and storage costs.