MEC Security Component for DoS Detection via UE Profile Comparison
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Software-defined networks (SDNs) and mobile devices are vulnerable to attacks, particularly in Multi-Access Edge Computing (MEC) environments, where IoT devices can be compromised to launch denial-of-service (DoS) or distributed denial-of-service (DDoS) attacks, compromising network security and performance.
Innovation Solution
A security component within the MEC architecture monitors and processes network traffic to detect anomalies by comparing user equipment (UE) behavior to established profiles, generating alerts when thresholds are exceeded, and implementing mitigation actions such as blocking connections or rate limiting to prevent attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network traffic monitoring and analysis are implemented to detect DoS attacks, then network security is improved, but system complexity increases
Solution Approach 1:
The patent introduces a security component as an intermediary element within the MEC architecture that specializes in traffic monitoring and attack detection. This component acts as a mediator between network traffic and the core network, concentrating security functions in a dedicated module rather than distributing complexity throughout the entire system. The security component monitors traffic, compares it against UE profiles, and generates alerts without requiring complex modifications to existing network infrastructure.
2Speed
If real-time traffic monitoring is performed to detect attacks promptly, then detection speed is improved, but processing overhead increases
Solution Approach 1:
The patent implements partial monitoring by focusing specifically on traffic patterns that deviate from established UE profiles rather than analyzing every packet in detail. The security component compares traffic against predefined profiles and thresholds, performing full analysis only when anomalies are detected. This approach enables timely attack detection while minimizing continuous processing overhead during normal operation.
3Measurement precision
If UE profiles are established and compared for each device, then measurement precision is improved, but device complexity increases
Solution Approach 1:
The patent establishes UE profiles in advance before attacks occur. The security component pre-configures expected traffic patterns, volume thresholds, and behavioral characteristics for each user equipment. When monitoring begins, the system simply compares incoming traffic against these pre-established profiles rather than creating and analyzing profiles in real-time. This preliminary preparation enables precise attack detection while reducing the computational complexity during active monitoring.
Data Source
AI summary
A device includes a processor and a memory. The processor effectuates operations including monitoring enterprise network traffic associated with one or more user equipment (UE). The processor further effectuates operations including comparing the enterprise network traffic to a UE profile associated with each of the one or more UE. The processor further effectuates operations including determining whether the comparison indicates that a predetermined threshold has been exceeded. The processor further effectuates operations including in response to the indication that the predetermined threshold has been exceeded, generating an alert, wherein exceeding the predetermined threshold is indicative of a denial of service attack on an enterprise network or an attempt to remove enterprise data via the one or more UE.


