5G Security System Using VRT Traffic Incubation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
5G wireless networks face increased vulnerabilities due to diverse device interconnectivity and resource-intensive conventional network hardening techniques are impractical for deployment across a massive network, posing security risks from unsecured and rogue communication sessions.
Innovation Solution
A 5G network security system that employs a vulnerability-risk-threat (VRT) framework to dynamically manage and prioritize network traffic, sorting it into categories based on security levels and implementing actions like blocking, quarantining, or redirecting suspicious traffic to mitigate cyberattacks, using a distributed security system with agent components and centralized information exchange.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional network hardening techniques are deployed across a massive diverse network of devices, then network security is improved, but deployment cost and resource consumption become prohibitive
Solution Approach 1:
The patent segments the network security approach by dividing devices into groups based on their security risk profiles and communication patterns. Instead of applying uniform hardening to all devices, the system creates segmented security zones where different protection strategies can be applied, reducing overall deployment complexity while maintaining security effectiveness.
Solution Approach 2:
The patent implements local quality by applying differentiated security measures to different parts of the network based on their specific characteristics. High-risk devices receive enhanced security protocols, while low-risk devices use standard protocols, optimizing resource allocation and reducing unnecessary deployment complexity across the entire network.
2Reliability
If conventional network hardening techniques are applied uniformly across all devices, then network security coverage is improved, but resource consumption and cost increase significantly
Solution Approach 1:
The patent changes the parameter of security protocol intensity based on device risk assessment. Instead of using maximum security protocols for all devices, the system dynamically adjusts security parameters according to each device's threat level, communication type, and network role, significantly reducing overall resource consumption while maintaining adequate security coverage.
Solution Approach 2:
The patent applies partial action by implementing security measures only where necessary rather than uniformly across all devices. The system identifies critical network segments and devices that require enhanced security and applies hardening techniques selectively, avoiding wasteful resource consumption on devices that don't require such intensive protection.
3Measurement precision
If security monitoring is performed on all network traffic, then detection precision is improved, but processing time and system load increase
Solution Approach 1:
The patent implements preliminary action by pre-classifying devices and traffic into risk categories before actual security monitoring begins. This preliminary segmentation allows the system to apply appropriate monitoring intensity to each category, achieving high detection precision for critical traffic while reducing processing overhead for low-risk traffic.
Solution Approach 2:
The patent introduces an intermediary layer that filters and prioritizes network traffic before it reaches the deep inspection engine. This intermediary sorting mechanism directs only suspicious or high-risk traffic to intensive analysis, maintaining detection precision while significantly reducing overall processing time and system load.
Data Source
AI summary
The technology includes a method performed by a security system of a 5G network to thwart a cyberattack. The security system is instantiated to monitor and control network traffic at a perimeter of the 5G network in accordance with a security model based on a vulnerability parameter, a risk parameter, and a threat parameter. The security system can process the network traffic with the security model to output a vulnerability-risk-threat (VRT) score that characterizes the network traffic in relation to the parameters. Based on the VRT score, the system redirects the network traffic to a containment area that mimics an intended destination or related process of the network traffic to induce malicious VRT traffic. When malicious VRT traffic is detected, the security system can, for example, prevent the network traffic from being communicated the 5G network.


