MEC Security Controller for Edge Network Attack Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network security devices are ineffective in detecting and mitigating sophisticated attacks, such as distributed denial of service attacks, which can overwhelm targeted nodes and disrupt network access for other users due to spoofed traffic that appears to originate from diverse User Equipment (UEs), leading to congestion and resource diversion away from valid traffic.

Innovation Solution

Implementing a Multi-Access Edge Computing (MEC) security controller that shifts network security closer to the attack origin by configuring MEC devices along network paths to detect and block attack traffic, using security activation messages to enforce custom attack protections and prevent spoofed traffic from entering the network, thereby reducing the load on targeted nodes and improving network performance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network security devices are located at gateway to inspect traffic, then targeted nodes are protected from attack traffic, but attack traffic still propagates through the network causing congestion and affecting other nodes

Engineering Contradiction:
Improveprotection of targeted nodeVSAvoidnetwork access for other users
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the centralized security function into distributed security functions deployed at multiple network edges. Instead of one security device at the gateway, multiple security functions are distributed across different network locations, allowing localized inspection and blocking of attack traffic before it propagates through the network.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a new dimension of security enforcement by deploying security functions at the network edge rather than only at the gateway. This spatial redistribution allows security operations to occur closer to attack origins, creating multiple layers of defense that prevent traffic propagation issues.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If network security device blocks attack traffic at gateway, then targeted node is protected, but attack traffic load still consumes network resources and causes congestion

Engineering Contradiction:
Improvesecurity protection effectivenessVSAvoidnetwork resource consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent implements preliminary security actions at network edges closer to attack origins. Security functions detect and mitigate attacks before they fully propagate through the network, performing protective actions in advance to prevent resource consumption by malicious traffic.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces security functions as intermediary elements distributed at network edges. These intermediaries intercept and neutralize attack traffic locally, preventing it from consuming network resources during propagation and reducing the load on both network infrastructure and protected nodes.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If network security device inspects traffic from diverse spoofed UEs, then attack detection accuracy improves, but individual spoofed UE traffic appears insufficient to trigger protections

Engineering Contradiction:
Improveattack detection accuracyVSAvoidtraffic inspection complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies local quality by enabling each distributed security function to independently inspect and evaluate traffic in its local context. Rather than requiring centralized analysis of all spoofed addresses, each security function locally detects patterns and coordinates with others, reducing the complexity burden on any single device while maintaining detection accuracy.

Inventive Principle:
Principle #3Local quality

4Reliability

If centralized security device protects targeted node, then node security is improved, but response time to valid traffic increases due to load from spoofed attack traffic

Engineering Contradiction:
Improvenode security protectionVSAvoidresponse time to valid traffic
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary security actions at distributed network edges that intercept and neutralize attack traffic before it reaches the targeted node. This preliminary mitigation reduces the attack load on the node, allowing it to respond more quickly to valid traffic while maintaining security protection.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces distributed security functions as intermediaries that filter and mitigate attack traffic before it reaches the targeted node. These intermediaries reduce the burden on the node, improving its ability to respond to legitimate traffic while maintaining security protections.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11700268B2Systems and methods for providing shifting network security via multi-access edge computing
Publication Date: 2023.07.11 VERIZON PATENT & LICENSING INC
  • US11700268B2 patent drawing
  • US11700268B2 patent drawing
  • US11700268B2 patent drawing

AI summary

Disclosed is a device for configuring and implementing network security for a connected network node, and for shifting the network security closer to the attack point of origin. In particular, the device may activate attack protections on different Multi-Access Edge Computing (“MEC”) devices that are physically located near or at the attack point of origin. The device may detect an attack signature based on one or more received data packets, and may provide a response with an extended header field, the attack signature, and/or other attack protection instructions. The responses may be passed to an address of a suspected attacker. MEC devices along the network path may detect and receive the responses, and implement attack protections in response. The responses may also be passed to a multicast or broadcast address that the MEC device may use to receive responses.