NWDAF Cyber-Attack Detection in 5G Core Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current 5G mobile communication systems lack effective mechanisms for detecting and mitigating cyber-attacks such as denial of service (DoS) and man-in-the-middle (MitM) attacks, which can compromise network security and user equipment (UE) operations.

Innovation Solution

The proposed solution involves a method and system using network data analytics functions (NWDAF) to collect and analyze user equipment (UE) related data from various network entities, deriving analytics to detect cyber-attacks and providing corresponding mitigation techniques, including identifying abnormal behavior and authentication failures to prevent DoS and MitM attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network data analytics functions are implemented to detect cyber-attacks, then network security is improved, but system complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a Network Data Analytics Function (NWDAF) as an intermediary component that collects, processes, and analyzes network data from multiple sources. This intermediary handles the complex analytics tasks separately, allowing the core network to maintain its existing structure while gaining enhanced security detection capabilities through the analytics function's insights and alerts.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Speed

If real-time analytics are performed on UE behavior data, then attack detection speed is improved, but processing requirements and energy consumption increase

Engineering Contradiction:
Improveattack detection speedVSAvoidenergy consumption
Core Design Contradiction:
SpeedVSUse of energy by moving object

Solution Approach 1:

The patent implements selective analytics processing where the NWDAF focuses on analyzing specific UE behavior parameters and events that are most indicative of cyber-attacks. Rather than processing all network data in real-time, the system prioritizes critical security-related events and anomalies, reducing overall processing requirements and energy consumption while maintaining effective attack detection speed.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12200492B2Method and system for detecting cyber-attacks using network analytics
Publication Date: 2025.01.14 SAMSUNG ELECTRONICS CO LTD
  • US12200492B2 patent drawing
  • US12200492B2 patent drawing
  • US12200492B2 patent drawing

AI summary

The disclosure relates to 5G or 6G communication systems for supporting higher data transmission rates.A method of detecting cyber-attacks using network analytics in a user equipment (UE) is provided. The method includes receiving, by a network data analytics function (NWDAF), a request for sharing analytics information associated with the UE from a consumer network function (NF), requesting the analytics information associated with the UE and causing the cyber-attack to at least one 5th generation core (5GC) network entity, receiving the analytics information associated with the UE and causing the cyber-attack from the at least one 5GC network entity, comparing an expected behavior of the UE with an actual behavior based on the analytics information provided by the at least one 5GC network entity, deriving analytics associated with the cyber-attack based on the analytics information and the comparison, and sending the analytics associated with the UE to the consumer NF.