NFV Security Defense Migration for Attack Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current techniques for providing network security in NFV-based communication networks are limited, necessitating a more effective approach to identify and mitigate security attacks.

Innovation Solution

A system and method that identifies security attacks, determines the affected hardware units, and initiates a security defense software program, potentially migrating functionality to alternative units and deploying security defense software in strategically located hardware units to manage and reduce load.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If current security techniques are used in NFV-based networks, then network security is provided, but security effectiveness is limited and cannot adequately identify and mitigate security attacks

Engineering Contradiction:
Improvenetwork securityVSAvoidsecurity attack identification and mitigation capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic security defense by migrating security defense software programs between different hardware units based on real-time attack detection. When an attack is identified on a first hardware unit, the security defense functionality is migrated to a second hardware unit, enabling adaptive response to evolving security threats rather than static defense mechanisms

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces a security management entity that acts as an intermediary between attacked hardware units and security defense resources. This entity coordinates the identification of attacks, selection of target hardware units for defense software deployment, and migration of security functionality, enabling centralized security orchestration across distributed NFV infrastructure

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security defense software is deployed on attacked hardware units, then security response is provided, but hardware unit load increases and may affect service continuity

Engineering Contradiction:
Improvesecurity defense capabilityVSAvoidhardware unit performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts security defense functionality from the attacked hardware unit by migrating the security defense software program to a different second hardware unit. This separation removes the computational burden of security defense operations from the compromised system, allowing the attacked unit to focus on its primary network functions while security processing occurs on a dedicated or alternative platform

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments security defense operations from network service operations by deploying security defense software on separate hardware units from those providing network services. This segmentation allows independent optimization of security processing and service delivery, preventing security operations from degrading service performance and enabling parallel operation of security and service functions

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9912679B1System, method, and computer program for managing security in a network function virtualization (NFV) based communication network
Publication Date: 2018.03.06 AMDOCS DEV LTD
  • US9912679B1 patent drawing
  • US9912679B1 patent drawing
  • US9912679B1 patent drawing

AI summary

A system, method, and computer program product are provided for providing security in a Network Function Virtualization based (NFV-based) communication network. In operation, a security attack is identified. Additionally, a first hardware unit attacked by the security attack is identified. Further, a hardware unit in which to initiate a security defense software program is identified. Moreover, the security defense software program is initiated in the identified hardware unit.