5G Security System Using VRT Traffic Incubation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

5G wireless networks face increased vulnerabilities due to diverse device interconnectivity and resource-intensive conventional network hardening techniques are impractical for deployment across a massive network, posing security risks from unsecured and rogue communication sessions.

Innovation Solution

A 5G network security system that employs a vulnerability-risk-threat (VRT) framework to dynamically manage and prioritize network traffic, sorting it into categories based on security levels and implementing actions like blocking, quarantining, or redirecting suspicious traffic to mitigate cyberattacks, using a distributed security system with agent components and centralized information exchange.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional network hardening techniques are deployed across a massive diverse network of devices, then network security is improved, but deployment cost and resource consumption become prohibitive

Engineering Contradiction:
Improvenetwork securityVSAvoiddeployment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the network security approach by dividing devices into groups based on their security risk profiles and communication patterns. Instead of applying uniform hardening to all devices, the system creates segmented security zones where different protection strategies can be applied, reducing overall deployment complexity while maintaining security effectiveness.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by applying differentiated security measures to different parts of the network based on their specific characteristics. High-risk devices receive enhanced security protocols, while low-risk devices use standard protocols, optimizing resource allocation and reducing unnecessary deployment complexity across the entire network.

Inventive Principle:
Principle #3Local quality

2Reliability

If conventional network hardening techniques are applied uniformly across all devices, then network security coverage is improved, but resource consumption and cost increase significantly

Engineering Contradiction:
Improvenetwork security coverageVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent changes the parameter of security protocol intensity based on device risk assessment. Instead of using maximum security protocols for all devices, the system dynamically adjusts security parameters according to each device's threat level, communication type, and network role, significantly reducing overall resource consumption while maintaining adequate security coverage.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent applies partial action by implementing security measures only where necessary rather than uniformly across all devices. The system identifies critical network segments and devices that require enhanced security and applies hardening techniques selectively, avoiding wasteful resource consumption on devices that don't require such intensive protection.

Inventive Principle:
Principle #16Partial or excessive action

3Measurement precision

If security monitoring is performed on all network traffic, then detection precision is improved, but processing time and system load increase

Engineering Contradiction:
Improvethreat detection precisionVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-classifying devices and traffic into risk categories before actual security monitoring begins. This preliminary segmentation allows the system to apply appropriate monitoring intensity to each category, achieving high detection precision for critical traffic while reducing processing overhead for low-risk traffic.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary layer that filters and prioritizes network traffic before it reaches the deep inspection engine. This intermediary sorting mechanism directs only suspicious or high-risk traffic to intensive analysis, maintaining detection precision while significantly reducing overall processing time and system load.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11800361B2Security system with 5G network traffic incubation
Publication Date: 2023.10.24 T MOBILE US INC
  • US11800361B2 patent drawing
  • US11800361B2 patent drawing
  • US11800361B2 patent drawing

AI summary

The technology includes a method performed by a security system of a 5G network to thwart a cyberattack. The security system is instantiated to monitor and control network traffic at a perimeter of the 5G network in accordance with a security model based on a vulnerability parameter, a risk parameter, and a threat parameter. The security system can process the network traffic with the security model to output a vulnerability-risk-threat (VRT) score that characterizes the network traffic in relation to the parameters. Based on the VRT score, the system redirects the network traffic to a containment area that mimics an intended destination or related process of the network traffic to induce malicious VRT traffic. When malicious VRT traffic is detected, the security system can, for example, prevent the network traffic from being communicated the 5G network.