5G Network Slice Threat Detection Using ML Ensemble

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for detecting network intrusions and attacks in 5G network slices are inadequate as they fail to detect multiple stages of ongoing multi-prong network attacks and cannot determine the type of sub-attack occurring.

Innovation Solution

The system combines network traffic information and system log information using multiple machine learning techniques, including Deep Neural Networks and ensemble methods, to detect and classify sub-attacks within a multi-stage attack framework.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a single machine learning algorithm is used to detect network attacks, then the system is simple to implement, but it cannot detect multiple types of sub-attacks equally well

Engineering Contradiction:
Improveability to detect multiple sub-attack typesVSAvoidcomplexity of detection system
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent divides the attack detection task into multiple specialized machine learning algorithms, each trained to detect specific types of network attacks. This segmentation allows each algorithm to excel at its specialized task while the ensemble combines their strengths to detect multiple attack types effectively.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent merges multiple machine learning algorithms into an ensemble system that combines their detection capabilities. By integrating the outputs of several specialized algorithms, the system achieves comprehensive detection of multiple sub-attack types while maintaining the simplicity of individual algorithm implementations.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If multiple machine learning algorithms are combined to detect multiple sub-attacks, then detection accuracy improves, but system complexity increases

Engineering Contradiction:
Improveaccuracy of sub-attack detectionVSAvoidcomplexity of algorithm combination
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies partial action by selecting and combining only the specific machine learning algorithms that are most effective for detecting particular attack types. Rather than using all possible algorithms, the system strategically combines a subset that provides sufficient detection accuracy while minimizing unnecessary complexity.

Inventive Principle:
Principle #16Partial or excessive action

3Productivity

If conventional machine learning approaches are used with narrow datasets, then training and testing is simpler, but the system cannot detect ongoing multi-prong network attacks at multiple stages

Engineering Contradiction:
Improvedetection of multiple attack stagesVSAvoidinability to determine attack type
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The patent performs preliminary action by training multiple machine learning algorithms on diverse datasets that cover various attack types and stages before deployment. This pre-training ensures that when the system encounters an ongoing multi-prong attack, it has already learned the patterns of multiple attack types and can accurately detect and classify them at different stages.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12289343B2Detecting malicious threats in a 5G network slice
Publication Date: 2025.04.29 CIENA CORP
  • US12289343B2 patent drawing
  • US12289343B2 patent drawing
  • US12289343B2 patent drawing

AI summary

Systems and methods for monitoring a network slice are provided. A method, according to one implementation, include extracting information from network traffic received from one or more User Plane Function (UPF) components of a network slice; examining the extracted information using Machine Learning (ML), and, in response to detecting of one or more malicious threats based on the examined extracted information by the ML, causing one or more actions to isolate the network traffic to protect at least the network slice from the one or more malicious threats.