SD-RAN Telemetry Stream for Anomalous Activity Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Higher generation cellular networks, such as 5G, face security challenges due to low economic and technical barriers for adversarial attacks, including malicious network devices and Man-in-the-Middle attacks, which compromise network security, privacy, and availability, with existing solutions being limited in detection and extensibility.

Innovation Solution

A software-defined radio access network (SD-RAN) with a data-plane security service module (SecSM) and a runtime intrusion detection system (IDS) called SPECTOR, which generates a telemetry stream to monitor and detect anomalous activities, leveraging modular extensions of the control and data planes with fine-grained audit capabilities and advanced security-focused xApps.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing network-based solutions with static defense mechanisms are used, then network security is maintained, but detection capability and adaptability to new attacks are poor

Engineering Contradiction:
Improvenetwork securityVSAvoiddetection capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent transforms static defense mechanisms into dynamic detection systems by implementing runtime monitoring that continuously adapts to new attack patterns. The system dynamically generates detection rules based on observed network behavior, enabling it to respond to evolving threats while maintaining security.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent segments the network monitoring function into independent, modular components that can be deployed and updated separately. This allows the detection system to be extended with new capabilities without compromising the core security infrastructure, improving both adaptability and maintainability.

Inventive Principle:
Principle #1Segmentation

2Reliability

If network device-centric defenses are implemented, then local security is improved, but ability to detect RAN-targeted attacks is limited

Engineering Contradiction:
Improvelocal securityVSAvoidRAN-targeted attack detection
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces a network-side intermediary monitoring system that observes communications between network devices and base stations. This intermediary provides a comprehensive view of RAN-targeted attacks without requiring changes to individual network devices, enabling detection of attacks that local defenses cannot detect.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent shifts the detection perspective from the device level to the network level, adding a new dimension of observation. This network-wide view enables detection of coordinated attacks and patterns that are invisible when only individual devices are monitored.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Measurement precision

If modular extensions with fine-grained audit capabilities are deployed, then detection precision is improved, but system complexity increases

Engineering Contradiction:
Improvedetection precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements a universal monitoring framework that handles multiple attack types and detection scenarios through a common architecture. This multi-functional approach achieves fine-grained detection precision while avoiding the complexity of separate specialized systems for each threat type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If runtime intrusion detection is implemented, then attack detection capability is enhanced, but processing overhead and latency increase

Engineering Contradiction:
Improveattack detection capabilityVSAvoidprocessing overhead
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements selective monitoring that focuses computational resources on suspicious or anomalous traffic patterns rather than uniformly analyzing all network communications. This partial action approach maintains high detection capability while reducing overall processing overhead and latency.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20240179577A1Systems and Methods for Monitoring and Detection of Anomalous Activity in Software-Defined Radio Access Networks
Publication Date: 2024.05.30 SRI INTERNATIONAL
  • US20240179577A1 patent drawing
  • US20240179577A1 patent drawing
  • US20240179577A1 patent drawing

AI summary

An example method for monitoring a software-defined radio access network (SD-RAN) includes receiving, by a computing device, data indicative of communications between a base station configured to provide radio access and one or more network devices. The method also includes generating, by the computing device and based on the data, a telemetry stream indicative of potential anomalous activity in the SD-RAN. The method further includes providing, by the computing device and based on the telemetry stream, an indication of the potential anomalous activity.