Security-Risk Admission Control for Network Utility Optimization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional admission control policies in communication networks fail to effectively manage security risks, such as malware spread and botnet attacks, due to information asymmetry and lack of cooperation among users, leading to inefficiencies and increased network vulnerabilities.

Innovation Solution

A security-risk based admission control method that assesses user devices based on reputation values and botnet damage estimation, optimizing the utility of admitted users by maximizing the sum utility while keeping expected damages below a threshold, using a constraint optimization approach that considers the security risks and utility associated with admitting user devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If traditional admission control policies are used to admit user devices into the network, then network connectivity and user access are maintained, but security risks such as malware spread and botnet attacks increase

Engineering Contradiction:
Improvenetwork connectivityVSAvoidsecurity risks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary security assessments, reputation checks, and botnet damage estimations on user devices before admitting them to the network. This advance evaluation prevents malicious devices from joining while maintaining connectivity for legitimate users, resolving the contradiction between network access and security protection.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The admission control system acts as an intermediary between user devices and the network, evaluating security risks through constraint optimization that considers utility, reputation values, and botnet damage estimates. This intermediary layer filters out malicious devices while allowing legitimate traffic, simultaneously maintaining connectivity and reducing security risks.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security assessments and constraint optimization are performed for each user device, then network security is improved, but computational complexity and processing time increase

Engineering Contradiction:
Improvenetwork securityVSAvoidcomputational complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system transforms the security assessment problem into a constraint optimization framework with defined parameters including utility functions, reputation values, and botnet damage estimates. By parameterizing the security evaluation, the system achieves reliable security decisions through mathematical optimization while managing computational complexity through structured parameter relationships.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

User devices provide self-information about their security status, reputation, and potential damage capabilities through the admission control process. This self-service approach reduces the computational burden on the network by having devices contribute their own security data, simplifying the overall assessment while maintaining high security reliability.

Inventive Principle:
Principle #25Self-service

3Productivity

If user devices with high utility are admitted to maximize network utility, then network performance improves, but the risk of botnet formation and network damage increases

Engineering Contradiction:
Improvenetwork utilityVSAvoidbotnet damage
Core Design Contradiction:
ProductivityVSObject-generated harmful factors

Solution Approach 1:

The system formulates admission control as a constraint optimization problem where the objective function maximizes network utility while constraints limit botnet damage and security risks. This mathematical framework allows the system to admit high-utility devices while preventing botnet formation, simultaneously achieving high network performance and damage prevention through optimized parameter selection.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8316428B2Method and apparatus for security-risk based admission control
Publication Date: 2012.11.20 NTT DOCOMO INC
  • US8316428B2 patent drawing
  • US8316428B2 patent drawing
  • US8316428B2 patent drawing

AI summary

A method and apparatus is disclosed herein for security risk-based admission control. In one embodiment, the method comprises: receiving a request from the user device to access the network; determining whether to admit the user device based on a security-based admission control policy that admits user devices based on a constraint optimization that attempts to maximize the sum utility of the currently admitted user devices in view of a security assessment of the user device and security risk imposed on the network and already admitted user devices if the user device is admitted to the network, wherein the constraint optimization is based on a utility associated with admitting the user device to the network, a reputation value associated with the user device, and a botnet damage estimation on the network associated with the user device; and admitting the user device to the network based on results of determining whether to admit the user device.