Network Node Behavioral Verification for Virtualized Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Communication networks face challenges in detecting and managing malicious software attacks on virtualized network nodes, which can lead to compromised nodes behaving abnormally, potentially causing security breaches and service disruptions.
Innovation Solution
An apparatus and method that store run-time behavioural patterns of network nodes, perform behavioural determinations, and verify whether nodes are on a list of valid nodes, using processing cores to check for valid credentials, and automatically terminate nodes if they are not valid or exhibit suspicious behavior.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If virtualized network functions are deployed to simplify network maintenance and improve flexibility, then network adaptability and ease of operation are improved, but the network becomes more vulnerable to malicious software attacks and security breaches
Solution Approach 1:
The system performs preliminary behavioral pattern analysis and credential verification before fully activating virtualized network functions. By pre-establishing baseline behavioral patterns and pre- verifying credentials upon instantiation, the system proactively prevents malicious nodes from compromising the network, thus maintaining security while enabling virtualization benefits
Solution Approach 2:
The patent introduces an intermediary verification mechanism that acts as a mediator between virtualized network functions and the core network. This intermediary layer performs behavioral analysis and credential verification, allowing legitimate VNFs to operate while blocking malicious ones, thus resolving the security vulnerability introduced by virtualization
2Reliability
If automated behavioral determination and verification systems are implemented to detect malicious nodes, then network security and reliability are improved, but system complexity and processing overhead increase
Solution Approach 1:
The system implements self-service mechanisms where virtualized network functions automatically provide their own credentials and behavioral data for verification. The nodes self-report their identity information and operational behavior, eliminating the need for complex external verification infrastructure and reducing system complexity while maintaining security
Solution Approach 2:
The patent employs feedback mechanisms where behavioral patterns are continuously monitored and fed back to the verification system. This closed-loop approach allows the system to learn from observed behaviors and automatically adjust verification strategies, improving security while managing complexity through adaptive rather than static rules
3Measurement precision
If manual verification of network nodes is used, then credential accuracy is maintained, but response time to detect and isolate malicious nodes increases
Solution Approach 1:
The system performs credential verification as a preliminary action during the node instantiation phase, before the node becomes fully operational. This preliminary verification ensures credential accuracy is established upfront, and any malicious nodes are rejected before they can cause harm, eliminating the need for slower manual verification while maintaining precision
Solution Approach 2:
The patent implements periodic automated verification of running nodes' behavioral patterns and credentials. Instead of relying on slow manual verification, the system continuously and periodically checks node behavior against established patterns, enabling rapid detection and isolation of malicious nodes while maintaining credential accuracy through automated processes
Data Source
AI summary
According to an example aspect of the present invention, there is provided an apparatus comprising memory configured to store information characterizing at least one run-time behavioural pattern, at least one processing core configured to perform a behavioural determination based at least partly on the stored information, concerning a network node, and to verify, as a response to a result of the behavioural determination, whether the network node is comprised on a list of valid network nodes.


