Anomaly Detection in 5G Network Slices via Modular Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The 5G mobile communication network architecture faces security and reliability challenges due to virtualization and automation, particularly in managing network slices, which are prone to attacks and failures that complicate fault management and service quality assurance.

Innovation Solution

A method for detecting anomalies in a telecommunications network that uses a generic anomaly detection module to identify resource usage anomalies, which are then validated by specific attack and failure detection modules, leveraging common measurement data to distinguish between attacks and failures and processing them separately while accounting for correlated occurrences.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If separate detection modules are used for attacks and failures, then detection specificity is improved, but device complexity increases

Engineering Contradiction:
Improvedetection specificityVSAvoiddevice complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The detection system is segmented into separate functional modules: a first detection module for anomalies, a second detection module for attacks, and a third detection module for failures. Each module processes specific types of data and performs specialized detection functions, allowing high specificity while maintaining modular architecture that manages complexity through functional separation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The first detection module serves multiple functions by processing both attack-related measurement data and failure-related measurement data through a unified anomaly detection mechanism. This multi-functionality reduces overall system complexity while maintaining the ability to detect both attack and failure anomalies with high precision.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Device complexity

If common measurement data is used for both attacks and failures, then device complexity is reduced, but measurement precision deteriorates

Engineering Contradiction:
Improvedevice complexityVSAvoidmeasurement precision
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

While using common measurement data infrastructure, the system applies local quality by processing attack and failure data through specialized detection modules that tailor their analysis to specific anomaly types. The second and third detection modules receive and process their respective specialized measurement data with focused detection algorithms, maintaining high precision for each anomaly type while sharing the common data collection framework.

Inventive Principle:
Principle #3Local quality

3Object-affected harmful factors

If network slices are strongly isolated, then security is improved, but fault management complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidfault management complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The coordination device acts as an intermediary that receives detection results from multiple anomaly detection devices across different network slices, validates them against predefined criteria, and coordinates the overall detection response. This intermediary layer enables strong isolation between slices while managing fault management complexity through centralized coordination and validation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20230291752A1Method for detecting anomalies in a communication network, method for coordinating anomaly detection, corresponding devices, router equipment, anomaly management system and computer programs.
Publication Date: 2023.09.14 ORANGE SA
  • US20230291752A1 patent drawing
  • US20230291752A1 patent drawing
  • US20230291752A1 patent drawing

AI summary

A method for detecting anomalies in a telecommunications network. The method includes implementing, by a first anomaly detection module: obtaining a plurality of first measurement data representing a resource usage of the network at a given time at a level of a target element; determining from the first measurement data at least one anomaly category from a plurality of anomaly categories a presence of attack, a presence of a fault and an absence of anomaly; requesting validation of the determined category to a second attack detection module and/or to a third fault detection module, depending on the determined anomaly category, the request including at least at the given time, an identifier of the target item, the determined anomaly category and the first measurement data; and on receipt of a response from the second and/or third module, deciding on a processing action to trigger in the network according to the response.