Hierarchical Anomaly Detection in 5G Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional intrusion detection techniques in 5G mobile networks are ineffective due to their centralized processing approach, leading to significant overhead that negatively impacts network performance and quality of service.

Innovation Solution

A hierarchical approach is implemented for anomaly and intrusion detection across multiple levels, considering the constraints of user equipment, network devices, and a security operations center, allowing for the deployment of tailored detection methods that optimize resource usage and reduce latency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If centralized processing approach is used for intrusion detection in 5G networks, then detection capability is improved, but network overhead increases and quality of service deteriorates

Engineering Contradiction:
Improveintrusion detection capabilityVSAvoidnetwork overhead
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent divides the centralized intrusion detection system into distributed edge computing nodes deployed across multiple access points in the 5G network. Each edge node independently performs intrusion detection on local traffic, segmenting the detection workload from centralized core network processing. This segmentation reduces network overhead by eliminating the need to transmit all traffic to a central detection point while maintaining comprehensive detection coverage through distributed analysis.

Inventive Principle:
Principle #1Segmentation

2Reliability

If centralized processing approach is used for intrusion detection in 5G networks, then detection capability is improved, but quality of service deteriorates

Engineering Contradiction:
Improveintrusion detection capabilityVSAvoidquality of service
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent transitions the intrusion detection architecture from a two-dimensional centralized model (all traffic routed to single detection point) to a three-dimensional distributed model where detection nodes are spatially distributed across multiple access points throughout the network. This dimensional change enables parallel processing of traffic streams at different network locations, improving quality of service by reducing congestion at any single point while maintaining comprehensive detection capability through coordinated analysis across the distributed node network.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS12160745B2Method and device for processing an alert message indicating the detection of an anomaly in traffic transmitted via a network
Publication Date: 2024.12.03 ORANGE SA
  • US12160745B2 patent drawing
  • US12160745B2 patent drawing

AI summary

A method for processing, by a device in a network, an alert message received by user equipment connected to the network. The alert message indicates detection of an anomaly by the user equipment in traffic transmitted via the network. The processing method includes: obtaining from the alert message at least one piece of information which is representative of at least one user equipment constraint; processing, by means of an algorithm for detecting cyber attacks, traffic characteristics provided by the user equipment and associated with the detected anomaly, the algorithm for detecting cyber attacks being chosen and/or configured according to the at least one piece of information; and determining from the at least one piece of information, according to an outcome of the processing, and if a cyber attack is detected, a response to the user equipment regarding the detected anomaly.