Dynamic Attack Surface Alteration in NFV Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current techniques for providing security in Network Function Virtualization (NFV) based communication networks are limited, necessitating the development of more effective security measures to address vulnerabilities and enhance network resilience.
Innovation Solution
The system implements periodic network changes and security configuration changes to alter the attack surface, including replacing assets with equivalent assets having different properties, instantiating new network elements, and applying tunneling protocols, while ensuring service continuity and verifying the effectiveness of these changes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If periodic network changes and security configuration changes are implemented to alter the attack surface, then security effectiveness is improved, but device complexity and operational complexity increase
Solution Approach 1:
The patent implements dynamic security configurations that automatically change network parameters, asset properties, and security policies in response to detected attacks or on a periodic basis. This dynamic adaptation allows the system to maintain high security effectiveness while managing complexity through automation rather than static, manually-configured defenses.
Solution Approach 2:
The system employs self-service mechanisms where the security infrastructure automatically identifies attacks, selects appropriate countermeasures, and implements changes without requiring constant human intervention. This automation handles the increased complexity internally while presenting a simplified interface to operators, resolving the contradiction between security effectiveness and operational complexity.
2Reliability
If network changes are implemented frequently to change attack surface, then security resilience is improved, but loss of time for verification and service continuity increases
Solution Approach 1:
The system performs preliminary actions by pre-configuring multiple security policies and countermeasures in advance. When an attack is detected or the periodic change interval is reached, the system can rapidly deploy pre-prepared security configurations without requiring time-consuming verification and testing of new security measures, thus maintaining security resilience while minimizing verification time.
Solution Approach 2:
The patent incorporates feedback mechanisms that continuously monitor network security status, attack patterns, and the effectiveness of implemented countermeasures. This real-time feedback allows the system to verify security changes rapidly and adjust configurations based on actual performance data, reducing the time required for verification while maintaining high security resilience.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A system, method, and computer program product are provided for providing security in Network Function Virtualization (NFV) based communication networks and Software Defined Networks (SDNs). In use, a system implements one or more network changes or security configuration changes to an NFV based communication network or a SDN to change an attack surface. In one embodiment, implementing the one or more network changes or security configuration changes to the NFV based communication network or the SDN may occur periodically to change the attack surface. In another embodiment, implementing the one or more network changes or the security configuration changes to the NFV based communication network or the SDN to change the attack surface may occur based on detection of a malicious event or a suspicious event.