Policy Node Rule Generation for 5G DDoS Attack Mitigation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
5G network architectures face challenges in efficiently managing and mitigating Distributed Denial-of-Service (DDoS) attacks, which can overwhelm applications and disrupt service, despite overprovisioning bandwidth, as existing solutions do not effectively detect or mitigate such attacks in real-time.
Innovation Solution
A method involving a user data node, policy node, and application node that exchange attack information including the type of attack, detection conditions, and mitigation actions, allowing the network to detect and respond to DDoS attacks by generating and applying rules to manage traffic and mitigate the attack effectively.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If overprovisioning bandwidth is used to prevent DDoS attacks, then application availability is improved, but network resource efficiency deteriorates
Solution Approach 1:
The patent applies preliminary action by establishing detection conditions and mitigation actions in advance through attack information provided by the application node. The user data node receives and stores these pre-configured rules, enabling immediate response to attacks without needing to overprovision bandwidth. The system prepares detection thresholds and mitigation strategies beforehand, allowing efficient real-time response that maintains availability while optimizing resource usage.
2Reliability
If real-time attack detection and mitigation is implemented, then service degradation is prevented, but device complexity increases
Solution Approach 1:
The patent uses an intermediary approach by introducing a structured information exchange mechanism between the application node and user data node. The attack information serves as an intermediary that carries detection conditions and mitigation actions from the application layer to the network layer. This intermediary structure simplifies the overall system by providing a standardized interface, reducing the complexity that would otherwise arise from direct complex interactions between multiple network functions.
3Adaptability or versatility
If attack information exchange between application node and network is enabled, then attack management capability is improved, but information security risks increase
Solution Approach 1:
The patent applies the taking out principle by extracting only the essential attack management information needed for mitigation. The attack information structure is designed to contain specifically detection conditions and mitigation actions, separating this critical information from other potentially sensitive data. This extraction approach enables effective attack management while minimizing information security risks by sharing only what is necessary for defense purposes.
Data Source
AI summary
Methods, a user data node (120), a policy node (150), an application node (170) and an operator network (101) for enabling management of an attack towards an application (190) hosted by the application node (170) are disclosed. The policy node (150) receives (3) attack information and an identifier of the application (190) to which the attack information applies. The attack information relates to the management of the attack and the attack information comprises a type of attack, a set of detection conditions relating to detection of attacks of the type of attack, and a mitigation action to be invoked when at least one detection condition of the set of detection conditions is fulfilled. In this manner, degeneration of the application (190) caused by the attacks of the type of attack is mitigatable. The policy node (150) generates (13) at least one rule based on the attack information. Moreover, the operator network (101) transfers (14, 15), from the policy node to the user data node (120), said at least one rule. The user data node (120) detects (18), in traffic towards the application (190), the attack while utilizing said at least one rule. Corresponding computer programs and computer program carriers are also disclosed.


