Cellular Security Slicing for Low-and-Slow DDoS Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Complex cellular networks face challenges in identifying and mitigating low and slow DDoS attacks, where malicious traffic is disguised as normal application traffic, and existing systems struggle to perform effective forensics on compromised devices.
Innovation Solution
A cellular network control system that instantiates network slices, identifies malicious traffic, transitions compromised user equipment to forensic slices for isolated analysis, and continues to provide service to uncompromised devices, using machine learning for pattern recognition and forensic tool automation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Object-affected harmful factors
If network blocks are applied to prevent DDoS attacks, then volumetric attacks can be blocked, but low and slow DDOS attacks cannot be identified and blocked effectively
Solution Approach 1:
The patent segments network traffic into different network slices based on security risk levels. High-risk traffic is isolated into separate slices for specialized analysis, while normal traffic continues on standard slices. This segmentation enables detailed inspection of low and slow attacks without blocking legitimate traffic, as each slice can be independently managed and analyzed for attack patterns.
Solution Approach 2:
The patent introduces network slices as intermediary structures between the user equipment and the core network. These slices act as mediators that can be configured with specific security policies, allowing traffic to be routed through controlled paths where low and slow attacks can be detected and analyzed before reaching the core network, enabling identification without immediate blocking.
2Object-affected harmful factors
If devices are blocked during security events, then malicious traffic can be stopped, but forensics on the cause becomes difficult to perform
Solution Approach 1:
The patent creates separate forensic network slices that are isolated from the main network. When devices are blocked for security events, their traffic is routed to these dedicated forensic slices where forensic analysis can be performed. This segmentation preserves forensic information by maintaining separate analysis channels that do not interfere with the blocking action, allowing both malicious traffic stopping and cause analysis to occur simultaneously.
Solution Approach 2:
The patent creates copies of network traffic and device states in isolated forensic slices. Instead of directly analyzing blocked devices in the main network, the system creates replicated traffic flows and device state information in separate forensic environments. This copying enables forensic analysis without affecting the blocking operation, as the copies can be examined in detail while the original malicious traffic is already blocked.
3Adaptability or versatility
If network slices are instantiated for external entities, then network access can be provided to user equipment, but security events require complex identification and isolation procedures
Solution Approach 1:
The patent segments security event handling into automated workflows that operate independently for each network slice. When security events are detected, the system automatically identifies affected slices and isolates them through predefined procedures. This segmentation reduces overall complexity by handling each slice independently through standardized automation, making the complex security response manageable and scalable across multiple slices.
Solution Approach 2:
The patent implements self-service automation where the network control system automatically detects security events, identifies affected network slices, and executes isolation procedures without manual intervention. The system monitors traffic patterns, detects anomalies, and autonomously manages slice isolation, reducing the operational complexity of security event handling while maintaining adaptability across different network configurations and external entities.
Data Source
AI summary
Systems, methods, and machine-readable media facilitate cellular network security. Communications corresponding to requested network access from an external entity may be processed. Configuration specifications to instantiate network slices may be generated. The network slices may be instantiated in accordance with the configuration specifications with network access provided to user equipment of the external entity, the cellular network consequently providing the network access to the user equipment of the external entity. Signals corresponding to detection of a security event mapped to network traffic of the network slices of the cellular network may be identified. The network traffic may correspond to communications from some of the user equipment that are detected as malicious traffic. A first subset of the user equipment using the network slices to be compromised user equipment may be determined. The first subset of the user equipment or a second subset of the user equipment may be transitioned.


