Dynamic Attack Surface Alteration in NFV Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current techniques for providing security in Network Function Virtualization (NFV) based communication networks are limited, necessitating the development of more effective security measures to address vulnerabilities and enhance network resilience.

Innovation Solution

The system implements periodic network changes and security configuration changes to alter the attack surface, including replacing assets with equivalent assets having different properties, instantiating new network elements, and applying tunneling protocols, while ensuring service continuity and verifying the effectiveness of these changes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If periodic network changes and security configuration changes are implemented to alter the attack surface, then security effectiveness is improved, but device complexity and operational complexity increase

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic security configurations that automatically change network parameters, asset properties, and security policies in response to detected attacks or on a periodic basis. This dynamic adaptation allows the system to maintain high security effectiveness while managing complexity through automation rather than static, manually-configured defenses.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system employs self-service mechanisms where the security infrastructure automatically identifies attacks, selects appropriate countermeasures, and implements changes without requiring constant human intervention. This automation handles the increased complexity internally while presenting a simplified interface to operators, resolving the contradiction between security effectiveness and operational complexity.

Inventive Principle:
Principle #25Self-service

2Reliability

If network changes are implemented frequently to change attack surface, then security resilience is improved, but loss of time for verification and service continuity increases

Engineering Contradiction:
Improvesecurity resilienceVSAvoidverification time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-configuring multiple security policies and countermeasures in advance. When an attack is detected or the periodic change interval is reached, the system can rapidly deploy pre-prepared security configurations without requiring time-consuming verification and testing of new security measures, thus maintaining security resilience while minimizing verification time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent incorporates feedback mechanisms that continuously monitor network security status, attack patterns, and the effectiveness of implemented countermeasures. This real-time feedback allows the system to verify security changes rapidly and adjust configurations based on actual performance data, reducing the time required for verification while maintaining high security resilience.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3662631B1System, method, and computer program providing security in network function virtualization (NFV) based communication networks and software defined networks (SDNS)
Publication Date: 2025.04.16 AMDOCS DEV LTD
  • EP3662631B1 patent drawingFigure 1
  • EP3662631B1 patent drawingFigure 2
  • EP3662631B1 patent drawingFigure 3

AI summary

A system, method, and computer program product are provided for providing security in Network Function Virtualization (NFV) based communication networks and Software Defined Networks (SDNs). In use, a system implements one or more network changes or security configuration changes to an NFV based communication network or a SDN to change an attack surface. In one embodiment, implementing the one or more network changes or security configuration changes to the NFV based communication network or the SDN may occur periodically to change the attack surface. In another embodiment, implementing the one or more network changes or the security configuration changes to the NFV based communication network or the SDN to change the attack surface may occur based on detection of a malicious event or a suspicious event.