TEE Security Module for Distributed NFV Anomaly Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In Network Function Virtualization (NFV) environments, the lack of traditional well-defined interfaces hinders the detection and response to security threats, as traditional mechanisms do not provide consistent visibility into all traffic, inhibiting the system's ability to ensure threat detection and prevention.
Innovation Solution
The system employs a Trusted Execution Environment (TEE) with platform-specific security policies to inspect packets and flows across virtualized systems, using microcode, hardware instructions, and proprietary APIs, enabling detailed monitoring and remedial actions, and hierarchical threat analysis across multiple platforms.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional network interfaces are used in virtualized environments, then system simplicity is maintained, but security threat detection capability deteriorates due to lack of visibility into traffic flows
Solution Approach 1:
The patent introduces a TEE-based security module as an intermediary component that sits between the virtualized network functions and the physical network interface. This module provides the necessary security inspection capabilities by intercepting and analyzing traffic flows without requiring fundamental changes to the virtualized architecture, thus resolving the contradiction between maintaining system simplicity and achieving reliable security threat detection
Solution Approach 2:
The security functionality is segmented into a separate TEE-based module rather than being integrated into the main virtualized network function. This segmentation allows the security detection capability to be added independently, improving reliability without significantly increasing the complexity of the core virtualized system
2Reliability
If comprehensive packet inspection is implemented across all virtualized systems, then security anomaly detection is improved, but processing time and system overhead increase
Solution Approach 1:
The TEE module performs preliminary security inspection and filtering of traffic flows before they reach the main processing pipeline. By conducting initial security checks in advance, the system can detect anomalies early without requiring all packets to undergo comprehensive inspection, thus improving security anomaly detection while minimizing processing time overhead
Solution Approach 2:
The system implements partial packet inspection by focusing security analysis on specific fields and protocols that are most relevant to detecting security anomalies. Rather than inspecting every byte of every packet, the TEE module selectively examines critical portions of traffic, achieving effective security detection with reduced processing time
3Reliability
If distributed security monitoring is deployed across multiple platforms, then system-wide threat detection is enhanced, but device complexity and coordination overhead increase
Solution Approach 1:
The TEE-based security module is designed with universal functionality that can be deployed across multiple different virtualized platforms and hardware architectures. This multi-functionality allows the same security mechanism to operate consistently across diverse systems, enhancing system-wide threat detection while minimizing coordination overhead through standardized interfaces and protocols
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Technologies for distributed detection of security anomalies include a computing device to establish a trusted relationship with a security server. The computing device reads one or more packets of at least one of an inter-virtual network function network or an inter-virtual network function component network in response to establishing the trusted relationship and performs a security threat assessment of the one or more packets. The computing device transmits the security threat assessment to the security server.