Hierarchical Anomaly Detection in 5G Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional intrusion detection techniques in 5G mobile networks are ineffective due to their centralized processing approach, leading to significant overhead that negatively impacts network performance and quality of service.
Innovation Solution
A hierarchical approach is implemented for anomaly and intrusion detection across multiple levels, considering the constraints of user equipment, network devices, and a security operations center, allowing for the deployment of tailored detection methods that optimize resource usage and reduce latency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If centralized processing approach is used for intrusion detection in 5G networks, then detection capability is improved, but network overhead increases and quality of service deteriorates
Solution Approach 1:
The patent divides the centralized intrusion detection system into distributed edge computing nodes deployed across multiple access points in the 5G network. Each edge node independently performs intrusion detection on local traffic, segmenting the detection workload from centralized core network processing. This segmentation reduces network overhead by eliminating the need to transmit all traffic to a central detection point while maintaining comprehensive detection coverage through distributed analysis.
2Reliability
If centralized processing approach is used for intrusion detection in 5G networks, then detection capability is improved, but quality of service deteriorates
Solution Approach 1:
The patent transitions the intrusion detection architecture from a two-dimensional centralized model (all traffic routed to single detection point) to a three-dimensional distributed model where detection nodes are spatially distributed across multiple access points throughout the network. This dimensional change enables parallel processing of traffic streams at different network locations, improving quality of service by reducing congestion at any single point while maintaining comprehensive detection capability through coordinated analysis across the distributed node network.
Data Source
AI summary
A method for processing, by a device in a network, an alert message received by user equipment connected to the network. The alert message indicates detection of an anomaly by the user equipment in traffic transmitted via the network. The processing method includes: obtaining from the alert message at least one piece of information which is representative of at least one user equipment constraint; processing, by means of an algorithm for detecting cyber attacks, traffic characteristics provided by the user equipment and associated with the detected anomaly, the algorithm for detecting cyber attacks being chosen and/or configured according to the at least one piece of information; and determining from the at least one piece of information, according to an outcome of the processing, and if a cyber attack is detected, a response to the user equipment regarding the detected anomaly.

