Front End Cyber Attack Processing Component for Selective Traffic Filtering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional telecommunications carrier networks face inefficiencies in responding to cyber attacks, often resulting in slow or unselective reactions that can deny service to both infected and uninfected user equipment, and are hindered by delayed detection due to security systems being logically removed from the network front end.
Innovation Solution
The implementation of a front end cyber attack processing component (FECAP) that inspects traffic near the carrier network front end, dynamically determines responses to detected cyber attacks, and enables automated, selective actions such as filtering, disabling, or throttling of suspect traffic to mitigate attacks without disrupting uninfected equipment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual or individual profile updates are performed to deny specific devices access, then small-scale cyber attacks can be effectively countered, but large-scale attacks cannot be addressed in time due to cumulative response time delays
Solution Approach 1:
The system automatically performs profile updates and device blocking without manual intervention. The network element at the front end autonomously detects cyber attacks and executes response actions including updating device profiles to deny access, eliminating the time-consuming manual process while maintaining precise detection capabilities
Solution Approach 2:
The network element is positioned at the front end of the carrier network to perform detection and response actions before attacks propagate deeply into the network. By establishing detection and response capabilities in advance at the network boundary, the system can quickly block malicious traffic and update device profiles before large-scale attacks accumulate
2Reliability
If entire markets including attacking user equipment are shut down, then the effects of cyber attacks can be stopped or limited, but service is denied to uninfected user equipment as well
Solution Approach 1:
The system applies different security responses to different devices based on their infection status. Instead of uniformly shutting down entire markets, the network element individually evaluates each device's traffic patterns and applies selective blocking only to infected devices while allowing uninfected devices to continue normal service
Solution Approach 2:
The system segments the network traffic into infected and uninfected streams by analyzing individual device profiles and traffic patterns. This segmentation enables selective application of security measures to specific attacking devices while preserving service for legitimate users within the same market
3Device complexity
If security systems are logically removed from the carrier network front end, then system complexity is reduced, but detection of cyber attacks is delayed due to poor traffic information routing
Solution Approach 1:
The system extracts the cyber attack detection and response functionality from the core network and places it in a dedicated network element at the front end. This extraction maintains system simplicity by isolating security functions while enabling timely detection through direct access to traffic information at the network boundary
Data Source
AI summary
A response to a cyber attack on a carrier network is provided. The response can be based on inspection of traffic flowing through a carrier network. The response can automatically adapt the traffic flow in response to a perceived threat. Traffic can be adapted by dynamically updating permission variables related to allowing access for user equipment (UE) to a carrier network, withdrawing or denying access to the carrier network for selected UEs. In other embodiments, signaling can be initiated at the carrier network to cause selected UEs to disable transmission of traffic contributing to the traffic flow. Determining a cyber attack condition can be based on predetermined rules associated with the traffic flow. Further, the determination can be performed at a front end of the carrier network to limit exposure of the carrier network to a detected cyber attack.


