RAN Node Mitigating Internet Attack Impact via Dynamic Capacity Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Internet attacks on Radio Access Networks (RAN) using Internet transport services pose challenges in maintaining service quality due to the inability of Intrusion Prevention Systems (IPS) to effectively mitigate attacks without compromising network capacity, leading to reduced end-user performance and Quality of Experience (QoE).
Innovation Solution
A method and device in a network node within the RAN using Internet transport that obtains intrusion detection information to select and perform mitigation actions such as handover of User Equipments (UEs) to neighboring nodes, increasing signal strength thresholds, decreasing cell size, and reporting attacks to neighboring nodes, thereby mitigating the impact of Internet attacks on service levels.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If IPS drops traffic from Internet attackers, then attack impact is reduced, but network capacity for legitimate users is limited
Solution Approach 1:
The patent segments the network capacity into two distinct parts: capacity reserved for legitimate RAN traffic and capacity that may be consumed by Internet attacks. This segmentation allows the system to protect legitimate user traffic by ensuring dedicated capacity allocation, while allowing IPS to drop attack traffic without impacting the reserved capacity for RAN services.
Solution Approach 2:
The patent introduces an intermediary mechanism (capacity monitoring and coordination between IPS and RAN nodes) that mediates between the IPS attack mitigation actions and the RAN service delivery. This intermediary monitors the actual impact of IPS actions on RAN capacity and coordinates responses to ensure legitimate traffic is not affected.
2Productivity
If RBS serves full capacity UEs assuming full Internet transport capacity, then network resource utilization is maximized, but end-user performance degrades under attack
Solution Approach 1:
The patent implements a feedback mechanism where RAN nodes continuously monitor the actual available Internet transport capacity and report this information to the RBS. The RBS uses this feedback to dynamically adjust the number of UEs it serves, ensuring that the sum of capacity required by served UEs does not exceed the actual available capacity. This prevents over-provisioning and maintains end-user service quality even when attacks reduce available capacity.
Solution Approach 2:
The patent makes the RAN system dynamic by enabling the RBS to adjust its served UE population in real-time based on actual Internet transport capacity conditions. When attacks reduce available capacity, the RBS dynamically reduces the number of served UEs or adjusts resource allocation to match the reduced capacity, thereby maintaining service quality. When capacity is abundant, the RBS can serve more UEs to maximize resource utilization.
3Reliability
If RBS reduces served UE count to match limited capacity, then end-user service quality is maintained, but network resource utilization decreases
Solution Approach 1:
The feedback mechanism continuously monitors Internet transport capacity and enables the RBS to optimize the balance between served UE count and service quality. When capacity is abundant (no attacks), the RBS serves the maximum number of UEs to maximize resource utilization. When capacity is reduced due to attacks, the feedback triggers a reduction in served UE count only to the extent necessary to maintain service quality, thereby minimizing the impact on resource utilization while protecting user experience.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The present disclosure relates to methods and devices for mitigating the impact from Internet attacks in a Radio Access Network, RAN, using Internet transport. This object is obtained by a method performed in network node in a RAN, using Internet transport. The method comprises obtaining intrusion detection information informing the network node that the RAN is under attack. The method further comprises selecting, based on the intrusion detection information, a mitigation action, the mitigation action mitigating the impact of the attack on the RAN service. Further the method comprises performing the selected mitigation action to mitigate the impact on the RAN service level.