Parallel Threat Detection for Mobile Network Latency Reduction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

High-bandwidth mobile networks, such as 5G, face challenges in protecting themselves against security threats like DDoS attacks due to increased complexity and potential latency introduced by threat detection processes, which can hinder data delivery to computing devices.

Innovation Solution

Implementing a threat detection system that performs threat analysis independently of data delivery by providing a copy of the data to a threat detection component, allowing data to be delivered to computing devices while threats are detected, thereby reducing latency and enabling real-time threat mitigation without impacting data delivery.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If threat detection is performed before data delivery, then network security is improved, but data delivery latency increases

Engineering Contradiction:
Improvenetwork securityVSAvoiddata delivery latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system separates threat detection from the data delivery path by creating a duplicate inspection path. The original data path delivers data directly to the computing device, while a copied path sends data to the threat detection component for analysis. This segmentation allows both security checking and data delivery to occur simultaneously without one blocking the other.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The threat detection component acts as an intermediary that receives copied data independently from the main delivery path. It analyzes the data for threats and can signal the network component to block delivery if threats are detected, but this intermediary process does not delay the original data delivery to the computing device.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Speed

If threat detection is performed independently from data delivery, then data delivery speed is improved, but threat detection effectiveness may be reduced

Engineering Contradiction:
Improvedata delivery speedVSAvoidthreat detection effectiveness
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The system creates a copy of the data for threat detection purposes while the original data proceeds through the delivery path. This copying allows the threat detection component to perform comprehensive analysis on the duplicate data without impacting the speed or efficiency of the original data delivery to the computing device.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The threat detection component provides feedback to the network component about detected threats. When threats are identified in the copied data, the threat detection component signals the network component to take appropriate actions such as blocking the data delivery or alerting the computing device, ensuring that threat detection effectiveness is maintained despite the independent processing path.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11197159B2Reducing latency associated with threat detection
Publication Date: 2021.12.07 T MOBILE US INC
  • US11197159B2 patent drawing
  • US11197159B2 patent drawing
  • US11197159B2 patent drawing

AI summary

Latency can be reduced within a network associated with a wireless service provider when detecting threats to the network. Instead of detecting threats before delivering data, data can be delivered to a computing device while threats to the network are detected. When data is received, as received data, at the network, a copy of the data can be provided to a threat detection component, while the received data can further be provided to the target computing device based on the current policies. The time it takes the threat detection component to examine the data and detect a possible threat to the mobile network does not impact the delivery of the data. Instead, the received data is provided to the target computing device while the threat detection component examines the data to identify any possible threats. The threat detection component signals a node within the network when a threat is detected.