SD-RAN Telemetry Stream for Anomalous Activity Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Higher generation cellular networks, such as 5G, face security challenges due to low economic and technical barriers for adversarial attacks, including malicious network devices and Man-in-the-Middle attacks, which compromise network security, privacy, and availability, with existing solutions being limited in detection and extensibility.
Innovation Solution
A software-defined radio access network (SD-RAN) with a data-plane security service module (SecSM) and a runtime intrusion detection system (IDS) called SPECTOR, which generates a telemetry stream to monitor and detect anomalous activities, leveraging modular extensions of the control and data planes with fine-grained audit capabilities and advanced security-focused xApps.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing network-based solutions with static defense mechanisms are used, then network security is maintained, but detection capability and adaptability to new attacks are poor
Solution Approach 1:
The patent transforms static defense mechanisms into dynamic detection systems by implementing runtime monitoring that continuously adapts to new attack patterns. The system dynamically generates detection rules based on observed network behavior, enabling it to respond to evolving threats while maintaining security.
Solution Approach 2:
The patent segments the network monitoring function into independent, modular components that can be deployed and updated separately. This allows the detection system to be extended with new capabilities without compromising the core security infrastructure, improving both adaptability and maintainability.
2Reliability
If network device-centric defenses are implemented, then local security is improved, but ability to detect RAN-targeted attacks is limited
Solution Approach 1:
The patent introduces a network-side intermediary monitoring system that observes communications between network devices and base stations. This intermediary provides a comprehensive view of RAN-targeted attacks without requiring changes to individual network devices, enabling detection of attacks that local defenses cannot detect.
Solution Approach 2:
The patent shifts the detection perspective from the device level to the network level, adding a new dimension of observation. This network-wide view enables detection of coordinated attacks and patterns that are invisible when only individual devices are monitored.
3Measurement precision
If modular extensions with fine-grained audit capabilities are deployed, then detection precision is improved, but system complexity increases
Solution Approach 1:
The patent implements a universal monitoring framework that handles multiple attack types and detection scenarios through a common architecture. This multi-functional approach achieves fine-grained detection precision while avoiding the complexity of separate specialized systems for each threat type.
4Reliability
If runtime intrusion detection is implemented, then attack detection capability is enhanced, but processing overhead and latency increase
Solution Approach 1:
The patent implements selective monitoring that focuses computational resources on suspicious or anomalous traffic patterns rather than uniformly analyzing all network communications. This partial action approach maintains high detection capability while reducing overall processing overhead and latency.
Data Source
AI summary
An example method for monitoring a software-defined radio access network (SD-RAN) includes receiving, by a computing device, data indicative of communications between a base station configured to provide radio access and one or more network devices. The method also includes generating, by the computing device and based on the data, a telemetry stream indicative of potential anomalous activity in the SD-RAN. The method further includes providing, by the computing device and based on the telemetry stream, an indication of the potential anomalous activity.


