Graph Neural Network Attack Prediction for 5G DDoS Response

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security solutions for 5G networks, such as intrusion detection mechanisms and behavioral analysis, are inadequate in addressing Distributed Denial of Service (DDoS) attacks from IoT devices, leading to high false positives and insufficient Quality of Service (QoS) protection.

Innovation Solution

A device and method utilizing a graph neural network (GNN) for proactive attack response, combining prediction and detection through a trained GNN model, inference rules, and a schema-based knowledge graph to identify attacks early and launch appropriate responses based on confidence levels and time differences.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional intrusion detection mechanisms are used, then security monitoring is provided, but the system cannot meet the QoS requirements of 5G networks and fails to effectively respond to DDoS attacks

Engineering Contradiction:
Improvesecurity monitoring effectivenessVSAvoidQoS requirement fulfillment
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies preliminary action by using a graph neural network to predict attacks before they fully manifest. The system proactively identifies potential DDoS attacks and triggers preventive responses before the attack impacts network services, thereby meeting QoS requirements while maintaining security monitoring effectiveness.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms where attack predictions and detected attacks are fed back into the graph neural network for continuous learning and model refinement. This feedback loop enables the system to improve its prediction accuracy over time, better fulfilling QoS requirements while enhancing security monitoring reliability.

Inventive Principle:
Principle #23Feedback

2Reliability

If behavioral analysis solutions are used, then attack detection is provided, but they produce a high rate of false positives reducing trustworthiness

Engineering Contradiction:
Improveattack detection capabilityVSAvoidfalse positive rate
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent changes the fundamental parameters of attack detection by transitioning from traditional behavioral analysis to graph neural network-based prediction. This parameter change enables the system to achieve high detection reliability while maintaining low false positive rates through sophisticated machine learning models that learn from network data patterns.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system replaces conventional mechanical behavioral analysis mechanisms with a graph neural network-based machine learning system. This substitution enables more accurate attack prediction and detection with fewer false positives, improving both reliability and measurement precision simultaneously.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Productivity

If graph neural network prediction is used, then proactive attack response is enabled, but the system complexity increases

Engineering Contradiction:
Improveattack response efficiencyVSAvoidsystem architecture complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent applies universality by designing a multi-functional graph neural network system that performs multiple tasks: attack prediction, attack detection, confidence level assessment, and trigger determination. This consolidation of functions into a single system reduces overall architectural complexity while maintaining high productivity in attack response.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system introduces an intermediary layer in the form of a graph neural network that mediates between raw network data and security responses. This intermediary simplifies the overall system architecture by providing a unified processing layer that handles prediction, detection, and decision-making, thereby reducing complexity while improving response efficiency.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Loss of time

If attack prediction with confidence levels is implemented, then proactive response timing is optimized, but the system requires continuous training and updates

Engineering Contradiction:
Improveresponse timing accuracyVSAvoidcontinuous training requirement
Core Design Contradiction:
Loss of timeVSProductivity

Solution Approach 1:

The patent applies self-service by implementing automated continuous training mechanisms where the graph neural network learns from new network data and attack patterns autonomously. This self-service capability enables the system to maintain optimal response timing accuracy while reducing the need for manual intervention in the training process.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system ensures continuity of useful action through ongoing model training and updates that occur continuously as new data becomes available. This continuous learning process maintains the system's ability to provide accurate prediction and timely responses without interruption, balancing time loss optimization with sustained productivity.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentEP4315665B1Device and method for generating a response to an attack in a communication network using machine learning
Publication Date: 2025.07.02 NOKIA TECHNOLOGIES OY
  • EP4315665B1 patent drawingFigure 1~8
  • EP4315665B1 patent drawingFigure 3~4
  • EP4315665B1 patent drawingFigure 5~6

AI summary

In a communication network, a device is configured to predict attacks and detect attacks from data logs received (71) from the network and generate (77, 81) a response to an attack upon prediction or detection of an attack. Graph representations of data logs are generated (72) based on a predefined schema. Attacks are detected (74) by applying inference rules to a graph representation of the data logs. Attacks are predicted (73) by using a graph neural network trained with subgraphs obtained by querying a graph representation of training data corresponding to normal traffic and attacks.