Network Node Behavioral Verification for Virtualized Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Communication networks face challenges in detecting and managing malicious software attacks on virtualized network nodes, which can lead to compromised nodes behaving abnormally, potentially causing security breaches and service disruptions.

Innovation Solution

An apparatus and method that store run-time behavioural patterns of network nodes, perform behavioural determinations, and verify whether nodes are on a list of valid nodes, using processing cores to check for valid credentials, and automatically terminate nodes if they are not valid or exhibit suspicious behavior.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If virtualized network functions are deployed to simplify network maintenance and improve flexibility, then network adaptability and ease of operation are improved, but the network becomes more vulnerable to malicious software attacks and security breaches

Engineering Contradiction:
Improvenetwork adaptabilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary behavioral pattern analysis and credential verification before fully activating virtualized network functions. By pre-establishing baseline behavioral patterns and pre- verifying credentials upon instantiation, the system proactively prevents malicious nodes from compromising the network, thus maintaining security while enabling virtualization benefits

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary verification mechanism that acts as a mediator between virtualized network functions and the core network. This intermediary layer performs behavioral analysis and credential verification, allowing legitimate VNFs to operate while blocking malicious ones, thus resolving the security vulnerability introduced by virtualization

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If automated behavioral determination and verification systems are implemented to detect malicious nodes, then network security and reliability are improved, but system complexity and processing overhead increase

Engineering Contradiction:
Improvenetwork securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements self-service mechanisms where virtualized network functions automatically provide their own credentials and behavioral data for verification. The nodes self-report their identity information and operational behavior, eliminating the need for complex external verification infrastructure and reducing system complexity while maintaining security

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent employs feedback mechanisms where behavioral patterns are continuously monitored and fed back to the verification system. This closed-loop approach allows the system to learn from observed behaviors and automatically adjust verification strategies, improving security while managing complexity through adaptive rather than static rules

Inventive Principle:
Principle #23Feedback

3Measurement precision

If manual verification of network nodes is used, then credential accuracy is maintained, but response time to detect and isolate malicious nodes increases

Engineering Contradiction:
Improvecredential accuracyVSAvoidresponse time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs credential verification as a preliminary action during the node instantiation phase, before the node becomes fully operational. This preliminary verification ensures credential accuracy is established upfront, and any malicious nodes are rejected before they can cause harm, eliminating the need for slower manual verification while maintaining precision

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements periodic automated verification of running nodes' behavioral patterns and credentials. Instead of relying on slow manual verification, the system continuously and periodically checks node behavior against established patterns, enabling rapid detection and isolation of malicious nodes while maintaining credential accuracy through automated processes

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS11122039B2Network management
Publication Date: 2021.09.14 COMPTEL CORP
  • US11122039B2 patent drawing
  • US11122039B2 patent drawing
  • US11122039B2 patent drawing

AI summary

According to an example aspect of the present invention, there is provided an apparatus comprising memory configured to store information characterizing at least one run-time behavioural pattern, at least one processing core configured to perform a behavioural determination based at least partly on the stored information, concerning a network node, and to verify, as a response to a result of the behavioural determination, whether the network node is comprised on a list of valid network nodes.