Communication Network Threat Scoring for Real-Time Response

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication networks, particularly 5G and future 6G networks, lack effective methods to dynamically assess and respond to security threats in real-time, leading to potential vulnerabilities and unnecessary actions.

Innovation Solution

A method to calculate a threat score for each network entity by multiplying a base score indicating importance with a dynamic score reflecting security incidents, allowing for timely and targeted security actions based on the calculated threat score.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security monitoring methods are used in communication networks, then security incidents can be detected, but real-time dynamic assessment and targeted response are not achieved, leading to unnecessary actions and delayed responses

Engineering Contradiction:
Improvenetwork securityVSAvoidsecurity response efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies parameter changes by introducing a threat score parameter that dynamically changes based on base score (entity importance) and dynamic score (security incidents). This parameter transformation enables real-time assessment of network entities, allowing the system to prioritize responses effectively and avoid unnecessary actions while maintaining high security reliability.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If comprehensive security monitoring is implemented across all network entities, then security coverage is improved, but system complexity and computational overhead increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidsecurity system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies segmentation by dividing network entities into different threat score categories based on their base score and dynamic score. This segmentation allows the security system to focus resources on high-threat entities while reducing monitoring intensity for low-threat entities, thereby maintaining comprehensive coverage without proportionally increasing system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by assigning different monitoring and response levels to different network entities based on their specific threat scores. High-threat entities receive intensive monitoring and immediate response, while low-threat entities receive standard monitoring, optimizing the balance between security coverage and system complexity.

Inventive Principle:
Principle #3Local quality

3Measurement precision

If real-time threat assessment is performed for all network entities, then response accuracy is improved, but processing time and computational resources increase

Engineering Contradiction:
Improvethreat assessment accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies partial action by performing detailed real-time threat assessment only for network entities that exceed a certain threat score threshold. For entities below the threshold, the system uses pre-calculated base scores with minimal updates, thereby maintaining high assessment accuracy for critical entities while reducing overall processing time and computational resource consumption.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20250310771A1Security in communication networks
Publication Date: 2025.10.02 NOKIA SOLUTIONS & NETWORKS OY
  • US20250310771A1 patent drawing
  • US20250310771A1 patent drawing
  • US20250310771A1 patent drawing

AI summary

According to an example aspect of the present disclosure, there is provided a method, comprising determining, by an apparatus, a base score of a network entity, wherein the base score indicates importance of the network entity in a network, determining, by the apparatus, a dynamic score of the network entity, wherein the dynamic score indicates at least security incidents that have happened to the network entity, determining, by the apparatus, a threat score of the network entity based at least on the base score and the dynamic score and determining, by the apparatus, based on the threat score, whether to perform an action associated with the network entity.