Core Network Node Identifies Malicious Data Flows

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current 5G wireless communication systems face challenges in protecting against Denial of Service (DoS) attacks, particularly from Internet of Things (IoT) devices, which can exhaust access node resources by sending malicious data packets, compromising the quality of service and internet access for legitimate users.

Innovation Solution

A method where the core network node identifies potentially malicious service data flows and assigns a specific identifier value to indicate that associated data packets should be handled according to a packet handling rule, allowing access nodes and communication devices to discard or monitor these packets, thereby mitigating DoS attacks without requiring significant changes to existing signaling mechanisms or QoS frameworks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the access node processes all incoming data packets from IoT devices, then the quality of service for legitimate users is maintained, but the access node resources are exhausted by malicious DoS attack packets

Engineering Contradiction:
Improvequality of serviceVSAvoidaccess node resource capacity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The core network node performs preliminary identification of potentially malicious service data flows before packets reach the access node. By assigning a special identifier value to marked packets at the core network level, the system prepares for efficient filtering at the access node without requiring complex real-time analysis, thus protecting resources in advance while maintaining QoS for legitimate traffic

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The harmful malicious packets are extracted and separated from the legitimate traffic flow by marking them with a specific identifier value. The access node then discards only these marked packets while continuing to process unmarked packets normally, effectively removing the harmful element without affecting the overall service quality for legitimate users

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If the access node monitors and filters malicious data packets, then system security is improved, but the device complexity and processing overhead increase

Engineering Contradiction:
Improvesystem securityVSAvoidaccess node processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system changes the parameter approach by using a simple identifier value marking mechanism instead of complex packet inspection. The core network node assigns a specific identifier value to malicious packets, transforming the security problem from complex content analysis to simple identifier matching at the access node, thereby improving security while minimizing processing complexity

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

Instead of creating complex filtering logic at the access node, the system uses a simplified copy of the malicious flow identification (just the identifier value) that is easily recognizable and actionable. This copied identifier approach allows the access node to handle security threats with minimal complexity by simply checking for the presence of the marked identifier

Inventive Principle:
Principle #26Copying

3Object-affected harmful factors

If IoT devices continue to transmit malicious data packets, then the attack impact on the network is maintained, but the battery drainage in IoT devices increases

Engineering Contradiction:
Improvenetwork attack impactVSAvoidIoT device battery consumption
Core Design Contradiction:
Object-affected harmful factorsVSUse of energy by moving object

Solution Approach 1:

The system converts the harmful continuous transmission behavior into a beneficial outcome by having the access node discard marked malicious packets. This causes the malicious transmission to become self-defeating - the more packets the compromised device sends, the more quickly they are discarded, and the faster the device exhausts its battery, ultimately neutralizing the threat while consuming the attacker's resources

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Data Source

PatentUS11895502B2Methods, communication device and nodes for enabling handling of data packets in a wireless communication system
Publication Date: 2024.02.06 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US11895502B2 patent drawing
  • US11895502B2 patent drawing
  • US11895502B2 patent drawing

AI summary

The present disclosure relates to a method performed by a core network node for enabling handling of data packets in a wireless communication system. The core network node identifies a potentially malicious service data flow associated with a communication device. The core network node assigns, to the potentially malicious service data flow, an identifier value to an identifier. The identifier value indicates that data packets associated with the potentially malicious service data flow should be handled according to a packet handling rule for potentially malicious data packets. The core network node provides an identifier comprising the identifier value towards the communication device towards at least one of an access node that serves the communication device in the access network, and a second core network node that processes data packets to and from the communication device.