5G IoT Slice DDoS Detection via Network Extraction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current 5G networks face significant challenges in detecting and mitigating Distributed Denial of Service (DDoS) attacks in IoT slices due to the inherent insecurity and constrained resources of IoT devices, which can be exploited to create botnets that overwhelm network resources, leading to service disruptions and security vulnerabilities.
Innovation Solution
A lightweight, real-time DDoS attack detection and mitigation system is implemented using a combination of Intrusion Detection Systems (IDS) and honeypots within the 5G-IoT network architecture, which profiles IoT devices, monitors parameters for anomalies, and employs deep learning-based algorithms to identify and isolate compromised devices, thereby reducing computational and storage complexities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional DDoS detection methods are used in 5G IoT slices, then detection capability is provided, but computational complexity and storage requirements become excessive for constrained IoT devices
Solution Approach 1:
The patent extracts the DDoS detection and mitigation functions from the constrained IoT devices and relocates them to the network infrastructure (gNB and core network). The IoT devices simply report their status and receive instructions, while the network handles the computationally intensive tasks of traffic analysis, anomaly detection, and attack mitigation, thereby eliminating the complexity burden on device-end components.
Solution Approach 2:
The patent introduces the gNB and core network functions as intermediaries between the IoT devices and the DDoS detection system. These intermediaries collect data from IoT devices, perform sophisticated analysis using deep learning models, and execute mitigation strategies, serving as a mediator that handles complex computations while keeping IoT devices simple.
2Reliability
If security functions are implemented on constrained IoT devices, then local security protection is achieved, but device resources are overwhelmed
Solution Approach 1:
The patent extracts all security processing functions from the IoT devices and consolidates them in the network infrastructure. The devices only perform simple status reporting and receiving control instructions, while the gNB and core network handle encryption, traffic analysis, and attack response, thereby preserving device energy for core operational functions.
Solution Approach 2:
The network infrastructure provides self-service security protection by autonomously detecting attacks, analyzing traffic patterns using deep learning models, and executing mitigation strategies without requiring active participation or energy consumption from the IoT devices. The system serves itself through centralized intelligence.
3Measurement precision
If comprehensive security monitoring is implemented, then detection accuracy is improved, but storage requirements increase significantly
Solution Approach 1:
The patent implements preliminary actions by collecting and storing only essential device status parameters and traffic metadata at the gNB and core network, rather than capturing complete packet data. The system pre-processes and filters data to retain only anomaly-indicative information, reducing storage needs while maintaining detection accuracy through targeted monitoring of critical parameters.
Solution Approach 2:
The patent changes the parameters being monitored from comprehensive packet-level data to summarized statistical parameters and anomaly indicators. By transforming raw traffic data into aggregated metrics and focusing storage on critical anomaly markers rather than complete data streams, the system achieves high detection accuracy with reduced storage requirements.
Data Source
AI summary
An apparatus and lightweight method detects and prevents DDoS attacks in a 5G-IoT slice in real-time without putting the stress of security on the constrained IoT devices. The apparatus includes eight IoT devices, a gNB, and 5G core network. The core network includes of AMF, SMF, UPF, PCF, UDR, and Network Data Analytics Function (NWDAF). 5 IoT devices connected to an IoT slice via a gNB RAN and core network are loaded with DDoS code. The gNB gives the RAN part of the slice to the IoT devices while as core network functions provide the core network part of the slice. A real-time and lightweight method consisting of Intrusion Detection System (IDS) and honeypots is designed for DDoS attack detection in 5G IoT/mMTC slices. The system identifies the attack efficiently and is able to mitigate it with less computation and storage costs.


