RAN Attack Detection Using Integrated Resource Signals

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increased complexity of 5G RAN architectures due to functional separation and openness to cyber attacks such as radio wave jamming and DDOS attacks poses challenges in accurately detecting and managing these threats across diverse communication devices, leading to potential service interruptions and information leakage.

Innovation Solution

An attack detection device integrates resource information from multiple communication devices within the RAN and core network to detect cyber attacks using AI-based analysis, employing hardware accelerators for efficient processing and handling.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a security appliance is inserted between specific communication devices of the RAN to detect cyber attacks, then detection capability is improved, but detection accuracy deteriorates because data regarding the cyber attack cannot be sufficiently acquired due to diverse specifications of communication devices

Engineering Contradiction:
Improvedetection capabilityVSAvoiddetection accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent merges resource information from multiple communication devices with diverse specifications into a unified dataset. By integrating resource information including CPU usage, memory usage, and bandwidth usage from multiple devices, the system creates a comprehensive view that compensates for the limitations of individual device specifications, thereby improving detection accuracy while maintaining enhanced detection capability.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a universal detection mechanism that works across diverse communication device specifications. The attack detection device is designed to handle multiple types of resource information from different device architectures, making the detection system universally applicable regardless of the specific communication device specifications, thus resolving the contradiction between detection capability and accuracy.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If resource information from multiple communication devices is integrated for cyber attack detection, then detection accuracy is improved, but system complexity increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent introduces an attack detection device as an intermediary that centralizes the integration and analysis of resource information from multiple communication devices. This intermediary component handles the complexity of data aggregation, normalization, and analysis, allowing individual communication devices to maintain their existing diverse specifications while achieving improved detection accuracy through centralized processing.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Loss of time

If distributed cyber attacks are detected at a single location of the network, then response time is improved, but detection accuracy deteriorates because the distributed nature of the attack cannot be fully captured

Engineering Contradiction:
Improveresponse timeVSAvoiddetection accuracy
Core Design Contradiction:
Loss of timeVSMeasurement precision

Solution Approach 1:

The patent adds a network-wide dimension to attack detection by simultaneously collecting and analyzing resource information from multiple communication devices located at different network positions. This multi-dimensional approach captures the distributed nature of cyber attacks while maintaining rapid response capability, as the centralized attack detection device processes information from all locations concurrently rather than sequentially.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS20250374057A1Attack Detection Device, Attack Detection System, Attack Detection Method, and Attack Detection Program
Publication Date: 2025.12.04 NT T INC
  • US20250374057A1 patent drawing
  • US20250374057A1 patent drawing
  • US20250374057A1 patent drawing

AI summary

An attack detection device detects a cyber attack in a mobile network that includes a RAN including RAN communication devices that perform wireless communication with a user terminal. The attack detection device includes an information integration unit and an attack detection unit. The information integration unit acquires pieces of resource information of the RAN communication devices and integrates the pieces of resource information. The attack detection unit detects the cyber attack based on the integrated pieces of resource information.