MEC Security Component for DoS Detection via UE Profile Comparison

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Software-defined networks (SDNs) and mobile devices are vulnerable to attacks, particularly in Multi-Access Edge Computing (MEC) environments, where IoT devices can be compromised to launch denial-of-service (DoS) or distributed denial-of-service (DDoS) attacks, compromising network security and performance.

Innovation Solution

A security component within the MEC architecture monitors and processes network traffic to detect anomalies by comparing user equipment (UE) behavior to established profiles, generating alerts when thresholds are exceeded, and implementing mitigation actions such as blocking connections or rate limiting to prevent attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network traffic monitoring and analysis are implemented to detect DoS attacks, then network security is improved, but system complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a security component as an intermediary element within the MEC architecture that specializes in traffic monitoring and attack detection. This component acts as a mediator between network traffic and the core network, concentrating security functions in a dedicated module rather than distributing complexity throughout the entire system. The security component monitors traffic, compares it against UE profiles, and generates alerts without requiring complex modifications to existing network infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Speed

If real-time traffic monitoring is performed to detect attacks promptly, then detection speed is improved, but processing overhead increases

Engineering Contradiction:
Improvedetection speedVSAvoidprocessing overhead
Core Design Contradiction:
SpeedVSUse of energy by moving object

Solution Approach 1:

The patent implements partial monitoring by focusing specifically on traffic patterns that deviate from established UE profiles rather than analyzing every packet in detail. The security component compares traffic against predefined profiles and thresholds, performing full analysis only when anomalies are detected. This approach enables timely attack detection while minimizing continuous processing overhead during normal operation.

Inventive Principle:
Principle #16Partial or excessive action

3Measurement precision

If UE profiles are established and compared for each device, then measurement precision is improved, but device complexity increases

Engineering Contradiction:
Improvetraffic analysis precisionVSAvoidprofiling complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent establishes UE profiles in advance before attacks occur. The security component pre-configures expected traffic patterns, volume thresholds, and behavioral characteristics for each user equipment. When monitoring begins, the system simply compares incoming traffic against these pre-established profiles rather than creating and analyzing profiles in real-time. This preliminary preparation enables precise attack detection while reducing the computational complexity during active monitoring.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11381594B2Denial of service detection and mitigation in a multi-access edge computing environment
Publication Date: 2022.07.05 AT&T INTELLECTUAL PROPERTY I L P
  • US11381594B2 patent drawing
  • US11381594B2 patent drawing
  • US11381594B2 patent drawing

AI summary

A device includes a processor and a memory. The processor effectuates operations including monitoring enterprise network traffic associated with one or more user equipment (UE). The processor further effectuates operations including comparing the enterprise network traffic to a UE profile associated with each of the one or more UE. The processor further effectuates operations including determining whether the comparison indicates that a predetermined threshold has been exceeded. The processor further effectuates operations including in response to the indication that the predetermined threshold has been exceeded, generating an alert, wherein exceeding the predetermined threshold is indicative of a denial of service attack on an enterprise network or an attempt to remove enterprise data via the one or more UE.