Cellular Network Security Slicing for Compromised Device Forensics
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Complex cellular networks, such as those in 5G and future deployments, face challenges in effectively handling and testing attacks and intrusions, particularly due to the difficulty in identifying low and slow DDOS attacks and performing forensic analysis on blocked devices.
Innovation Solution
The implementation of a method and system for cellular network security slicing, which involves a cellular network control system that receives communications for network access, generates configuration specifications for network slices, instantiates these slices, and identifies security events to transition compromised user equipment to forensic slices for isolated analysis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network traffic is monitored and devices are blocked upon detection of malicious traffic, then network security is improved, but it becomes difficult to perform forensics on the blocked devices and analyze the cause of attacks
Solution Approach 1:
The network is segmented into multiple slices: a security slice for monitoring and blocking malicious traffic, and a forensic slice for isolated analysis of compromised devices. This segmentation allows simultaneous security enforcement and forensic investigation without interference between the two functions.
Solution Approach 2:
A control system acts as an intermediary that manages device transitions between slices. When malicious traffic is detected, the control system moves the device from the security slice to the forensic slice, enabling forensic analysis while maintaining security controls.
2Productivity
If multiple security analysis functions are performed simultaneously on the same network infrastructure, then security response time is improved, but system complexity increases
Solution Approach 1:
The network infrastructure is divided into distinct slices that can independently execute security functions. The security slice handles real-time threat detection and blocking, while the forensic slice performs detailed analysis, allowing parallel operation without resource conflicts.
Solution Approach 2:
The patent introduces a temporal dimension to security operations by using state transitions between slices. Devices move from a monitoring state in the security slice to an analysis state in the forensic slice, enabling multiple security functions to operate simultaneously in different temporal states.
3Reliability
If compromised devices are isolated from the network, then network security is protected, but the ability to collect operational data for forensic analysis is reduced
Solution Approach 1:
The control system serves as an intermediary that maintains controlled connectivity between the forensic slice and the security slice. This allows operational data to be collected from compromised devices in the forensic slice while preventing unauthorized access to the broader network.
Solution Approach 2:
The forensic slice provides a specialized local environment with specific connectivity characteristics tailored for forensic analysis. Within this local context, compromised devices maintain necessary connectivity for data collection while being isolated from the general network.
Data Source
AI summary
Systems, methods, and machine-readable media facilitate cellular network security. Communications corresponding to requested network access from an external entity may be processed. Configuration specifications to instantiate network slices may be generated. The network slices may be instantiated in accordance with the configuration specifications with network access provided to user equipment of the external entity, the cellular network consequently providing the network access to the user equipment of the external entity. Signals corresponding to detection of a security event mapped to network traffic of the network slices of the cellular network may be identified. The network traffic may correspond to communications from some of the user equipment that are detected as malicious traffic. A first subset of the user equipment using the network slices to be compromised user equipment may be determined. The first subset of the user equipment or a second subset of the user equipment may be transitioned.


