Software Service Security Analytics via Audit Log Processing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network operators in 5G networks face challenges in assessing the security and operational behavior of software services deployed on private and cloud-based platforms, as they rely on third-party providers for detection and mitigation of security issues and abnormal behavior, leading to potential delays and network vulnerabilities.

Innovation Solution

A data analytics producer system that receives software service metadata and audit logs to generate analytics for security and operational behavior assessments, enabling network operators to detect and predict security issues and abnormal behavior in real-time, allowing for proactive mitigation measures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network operators rely on third-party service providers for security and operational behavior assessment of software services, then the service providers can manage the assessment, but the network operator cannot independently evaluate security and operational behavior, leading to delayed detection and mitigation of security issues

Engineering Contradiction:
Improvesecurity assessment reliabilityVSAvoiddetection and mitigation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The network operator deploys a local assessment entity that independently performs security and operational behavior assessment of software services using locally collected audit logs and metadata, enabling self-service assessment without waiting for third-party providers

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system continuously collects and analyzes audit logs and metadata in advance, enabling early detection of security issues and abnormal behaviors before they impact the network, allowing proactive mitigation measures

Inventive Principle:
Principle #10Preliminary action

2Productivity

If network operators deploy assessment entities locally to independently assess software services, then real-time detection capability is improved, but the system complexity increases due to additional local infrastructure requirements

Engineering Contradiction:
Improveassessment speedVSAvoidassessment system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The assessment entity acts as an intermediary component that receives audit logs from software services and metadata from service providers, processing this data locally to generate assessment results without requiring complex end-to-end integration with third-party providers

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The assessment system is segmented into independent functional components: audit log collection, metadata reception, data analysis, and result generation, allowing modular deployment and management that reduces overall system complexity

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP4134848B1Devices and methods for security and operational behavior assessment of software services
Publication Date: 2024.02.14 NOKIA TECHNOLOGIES OY
  • EP4134848B1 patent drawingFigure 1
  • EP4134848B1 patent drawingFigure 2
  • EP4134848B1 patent drawingFigure 3

AI summary

A data analytics producer (102) configured to : - receive a request for data analytics related to one or more target software services; - receive input data comprising software service metadata associated with the target software services and one or more audit log files associated with the target software services, and - generate data analytics from the input data.