Radio Access Network Vulnerability Assessment via UE Emulation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for assessing attack vulnerability of cellular radio access network equipment, such as simulations, are limited by the accuracy of simulated devices, which may not accurately represent real network behavior under attack conditions.

Innovation Solution

A method involving the emulation of both good and bad UEs to transmit traffic to a real air interface network device under test, monitoring its response, and generating output indicative of attack vulnerability, using a network equipment test device with a processor and memory that includes a good UE emulator, a bad UE emulator, and an attack vulnerability assessment module.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If simulations are used to assess attack vulnerability, then the assessment process is simplified and can be performed on simulated devices, but the accuracy of the vulnerability assessment deteriorates because simulated devices may not accurately represent real network behavior

Engineering Contradiction:
Improveease of assessmentVSAvoidaccuracy of vulnerability assessment
Core Design Contradiction:
Ease of manufactureVSMeasurement precision

Solution Approach 1:

The patent creates a virtual copy of the real network device that can be attacked in simulation while maintaining accurate behavioral models. This virtual copy is populated with attack patterns and allows vulnerability assessment without compromising the real device, thus maintaining both ease of assessment and accuracy by copying the essential characteristics of the real device into a testable virtual environment

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent introduces a vulnerability assessment module as an intermediary between the simulated attack and the real network device. This module receives attack patterns, translates them into appropriate test scenarios, and compares simulated results with actual device responses, thereby mediating between the simplicity of simulation and the accuracy of real-device behavior

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If real network devices are used for attack testing, then the accuracy of vulnerability assessment is improved, but the risk of actual network damage and service degradation increases

Engineering Contradiction:
Improveaccuracy of vulnerability assessmentVSAvoidnetwork damage and service degradation
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent prepares protective measures beforehand by creating virtual copies and controlled test environments before conducting any attack simulations. The system establishes baseline performance metrics and prepares rollback procedures in advance, cushioning the real network device from potential damage while enabling accurate vulnerability assessment through pre-configured safety mechanisms

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Solution Approach 2:

The patent creates virtual copies of network devices that can serve as test targets for attack simulations. These copies replicate the essential characteristics and vulnerabilities of real devices, allowing attackers to test attack patterns on the virtual copy without causing harm to the actual network infrastructure, thus maintaining assessment accuracy while eliminating network damage risk

Inventive Principle:
Principle #26Copying

Data Source

PatentUS9774618B2Methods, systems, and computer readable media for assessing attack vulnerability of radio access network equipment
Publication Date: 2017.09.26 KEYSIGHT TECH SINGAPORE (SALES) PTE LTD
  • US9774618B2 patent drawing
  • US9774618B2 patent drawing
  • US9774618B2 patent drawing

AI summary

The subject matter described herein relates to methods, systems, and computer readable media for assessing attack vulnerability of radio access network equipment. One method for assessing the attack vulnerability of a radio access network device includes emulating at least one good UE. The method further includes emulating at least one bad UE. The method further includes transmitting traffic from the emulated good and bad UEs to a non-simulated radio access network device under test. The method further includes monitoring a response of the radio access network device under test to the emulated good UEs. The method further includes generating output indicative of attack vulnerability of the device under test.