Policy Node Rule Generation for 5G DDoS Attack Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

5G network architectures face challenges in efficiently managing and mitigating Distributed Denial-of-Service (DDoS) attacks, which can overwhelm applications and disrupt service, despite overprovisioning bandwidth, as existing solutions do not effectively detect or mitigate such attacks in real-time.

Innovation Solution

A method involving a user data node, policy node, and application node that exchange attack information including the type of attack, detection conditions, and mitigation actions, allowing the network to detect and respond to DDoS attacks by generating and applying rules to manage traffic and mitigate the attack effectively.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If overprovisioning bandwidth is used to prevent DDoS attacks, then application availability is improved, but network resource efficiency deteriorates

Engineering Contradiction:
Improveapplication availabilityVSAvoidnetwork resource efficiency
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent applies preliminary action by establishing detection conditions and mitigation actions in advance through attack information provided by the application node. The user data node receives and stores these pre-configured rules, enabling immediate response to attacks without needing to overprovision bandwidth. The system prepares detection thresholds and mitigation strategies beforehand, allowing efficient real-time response that maintains availability while optimizing resource usage.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If real-time attack detection and mitigation is implemented, then service degradation is prevented, but device complexity increases

Engineering Contradiction:
Improveservice continuityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses an intermediary approach by introducing a structured information exchange mechanism between the application node and user data node. The attack information serves as an intermediary that carries detection conditions and mitigation actions from the application layer to the network layer. This intermediary structure simplifies the overall system by providing a standardized interface, reducing the complexity that would otherwise arise from direct complex interactions between multiple network functions.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If attack information exchange between application node and network is enabled, then attack management capability is improved, but information security risks increase

Engineering Contradiction:
Improveattack management capabilityVSAvoidinformation security risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies the taking out principle by extracting only the essential attack management information needed for mitigation. The attack information structure is designed to contain specifically detection conditions and mitigation actions, separating this critical information from other potentially sensitive data. This extraction approach enables effective attack management while minimizing information security risks by sharing only what is necessary for defense purposes.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11765200B2Methods, nodes and operator network for enabling management of an attack towards an application
Publication Date: 2023.09.19 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US11765200B2 patent drawing
  • US11765200B2 patent drawing
  • US11765200B2 patent drawing

AI summary

Methods, a user data node (120), a policy node (150), an application node (170) and an operator network (101) for enabling management of an attack towards an application (190) hosted by the application node (170) are disclosed. The policy node (150) receives (3) attack information and an identifier of the application (190) to which the attack information applies. The attack information relates to the management of the attack and the attack information comprises a type of attack, a set of detection conditions relating to detection of attacks of the type of attack, and a mitigation action to be invoked when at least one detection condition of the set of detection conditions is fulfilled. In this manner, degeneration of the application (190) caused by the attacks of the type of attack is mitigatable. The policy node (150) generates (13) at least one rule based on the attack information. Moreover, the operator network (101) transfers (14, 15), from the policy node to the user data node (120), said at least one rule. The user data node (120) detects (18), in traffic towards the application (190), the attack while utilizing said at least one rule. Corresponding computer programs and computer program carriers are also disclosed.