Cellular Security Slicing for Low-and-Slow DDoS Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Complex cellular networks face challenges in identifying and mitigating low and slow DDoS attacks, where malicious traffic is disguised as normal application traffic, and existing systems struggle to perform effective forensics on compromised devices.

Innovation Solution

A cellular network control system that instantiates network slices, identifies malicious traffic, transitions compromised user equipment to forensic slices for isolated analysis, and continues to provide service to uncompromised devices, using machine learning for pattern recognition and forensic tool automation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Object-affected harmful factors

If network blocks are applied to prevent DDoS attacks, then volumetric attacks can be blocked, but low and slow DDOS attacks cannot be identified and blocked effectively

Engineering Contradiction:
ImproveDDoS attack blocking capabilityVSAvoidLow and slow DDOS detection difficulty
Core Design Contradiction:
Object-affected harmful factorsVSDifficulty of detecting and measuring

Solution Approach 1:

The patent segments network traffic into different network slices based on security risk levels. High-risk traffic is isolated into separate slices for specialized analysis, while normal traffic continues on standard slices. This segmentation enables detailed inspection of low and slow attacks without blocking legitimate traffic, as each slice can be independently managed and analyzed for attack patterns.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces network slices as intermediary structures between the user equipment and the core network. These slices act as mediators that can be configured with specific security policies, allowing traffic to be routed through controlled paths where low and slow attacks can be detected and analyzed before reaching the core network, enabling identification without immediate blocking.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If devices are blocked during security events, then malicious traffic can be stopped, but forensics on the cause becomes difficult to perform

Engineering Contradiction:
ImproveMalicious traffic blockingVSAvoidForensic information availability
Core Design Contradiction:
Object-affected harmful factorsVSLoss of information

Solution Approach 1:

The patent creates separate forensic network slices that are isolated from the main network. When devices are blocked for security events, their traffic is routed to these dedicated forensic slices where forensic analysis can be performed. This segmentation preserves forensic information by maintaining separate analysis channels that do not interfere with the blocking action, allowing both malicious traffic stopping and cause analysis to occur simultaneously.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates copies of network traffic and device states in isolated forensic slices. Instead of directly analyzing blocked devices in the main network, the system creates replicated traffic flows and device state information in separate forensic environments. This copying enables forensic analysis without affecting the blocking operation, as the copies can be examined in detail while the original malicious traffic is already blocked.

Inventive Principle:
Principle #26Copying

3Adaptability or versatility

If network slices are instantiated for external entities, then network access can be provided to user equipment, but security events require complex identification and isolation procedures

Engineering Contradiction:
ImproveNetwork access provision capabilityVSAvoidSecurity event handling complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments security event handling into automated workflows that operate independently for each network slice. When security events are detected, the system automatically identifies affected slices and isolates them through predefined procedures. This segmentation reduces overall complexity by handling each slice independently through standardized automation, making the complex security response manageable and scalable across multiple slices.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements self-service automation where the network control system automatically detects security events, identifies affected network slices, and executes isolation procedures without manual intervention. The system monitors traffic patterns, detects anomalies, and autonomously manages slice isolation, reducing the operational complexity of security event handling while maintaining adaptability across different network configurations and external entities.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250287210A1Systems and methods for cellular network security slicing
Publication Date: 2025.09.11 BOOST SUBSCRIBERCO LLC
  • US20250287210A1 patent drawing
  • US20250287210A1 patent drawing
  • US20250287210A1 patent drawing

AI summary

Systems, methods, and machine-readable media facilitate cellular network security. Communications corresponding to requested network access from an external entity may be processed. Configuration specifications to instantiate network slices may be generated. The network slices may be instantiated in accordance with the configuration specifications with network access provided to user equipment of the external entity, the cellular network consequently providing the network access to the user equipment of the external entity. Signals corresponding to detection of a security event mapped to network traffic of the network slices of the cellular network may be identified. The network traffic may correspond to communications from some of the user equipment that are detected as malicious traffic. A first subset of the user equipment using the network slices to be compromised user equipment may be determined. The first subset of the user equipment or a second subset of the user equipment may be transitioned.