Front End Cyber Attack Processing Component for Selective Traffic Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional telecommunications carrier networks face inefficiencies in responding to cyber attacks, often resulting in slow or unselective reactions that can deny service to both infected and uninfected user equipment, and are hindered by delayed detection due to security systems being logically removed from the network front end.

Innovation Solution

The implementation of a front end cyber attack processing component (FECAP) that inspects traffic near the carrier network front end, dynamically determines responses to detected cyber attacks, and enables automated, selective actions such as filtering, disabling, or throttling of suspect traffic to mitigate attacks without disrupting uninfected equipment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual or individual profile updates are performed to deny specific devices access, then small-scale cyber attacks can be effectively countered, but large-scale attacks cannot be addressed in time due to cumulative response time delays

Engineering Contradiction:
Improvedetection precisionVSAvoidresponse time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system automatically performs profile updates and device blocking without manual intervention. The network element at the front end autonomously detects cyber attacks and executes response actions including updating device profiles to deny access, eliminating the time-consuming manual process while maintaining precise detection capabilities

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The network element is positioned at the front end of the carrier network to perform detection and response actions before attacks propagate deeply into the network. By establishing detection and response capabilities in advance at the network boundary, the system can quickly block malicious traffic and update device profiles before large-scale attacks accumulate

Inventive Principle:
Principle #10Preliminary action

2Reliability

If entire markets including attacking user equipment are shut down, then the effects of cyber attacks can be stopped or limited, but service is denied to uninfected user equipment as well

Engineering Contradiction:
Improvenetwork securityVSAvoidservice disruption
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system applies different security responses to different devices based on their infection status. Instead of uniformly shutting down entire markets, the network element individually evaluates each device's traffic patterns and applies selective blocking only to infected devices while allowing uninfected devices to continue normal service

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system segments the network traffic into infected and uninfected streams by analyzing individual device profiles and traffic patterns. This segmentation enables selective application of security measures to specific attacking devices while preserving service for legitimate users within the same market

Inventive Principle:
Principle #1Segmentation

3Device complexity

If security systems are logically removed from the carrier network front end, then system complexity is reduced, but detection of cyber attacks is delayed due to poor traffic information routing

Engineering Contradiction:
Improvesystem complexityVSAvoiddetection delay
Core Design Contradiction:
Device complexityVSLoss of time

Solution Approach 1:

The system extracts the cyber attack detection and response functionality from the core network and places it in a dedicated network element at the front end. This extraction maintains system simplicity by isolating security functions while enabling timely detection through direct access to traffic information at the network boundary

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS9876811B2Dynamic and selective response to cyber attack for telecommunications carrier networks
Publication Date: 2018.01.23 AT&T MOBILITY II LLC
  • US9876811B2 patent drawing
  • US9876811B2 patent drawing
  • US9876811B2 patent drawing

AI summary

A response to a cyber attack on a carrier network is provided. The response can be based on inspection of traffic flowing through a carrier network. The response can automatically adapt the traffic flow in response to a perceived threat. Traffic can be adapted by dynamically updating permission variables related to allowing access for user equipment (UE) to a carrier network, withdrawing or denying access to the carrier network for selected UEs. In other embodiments, signaling can be initiated at the carrier network to cause selected UEs to disable transmission of traffic contributing to the traffic flow. Determining a cyber attack condition can be based on predetermined rules associated with the traffic flow. Further, the determination can be performed at a front end of the carrier network to limit exposure of the carrier network to a detected cyber attack.