Threat Level Engine for Zero Trust Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security schemes, including those in 5G networks and zero trust network environments, do not efficiently utilize available data for security-centric analytic metric determinations and remediations, leading to inadequate security threat identification and mitigation.

Innovation Solution

A threat level engine (TLE) is introduced into the network architecture, which receives security data from various sources, processes it using a machine learning model, and determines security-related events, threat impact levels, and remediation actions to effectively identify and mitigate security threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional network security schemes are used, then network operations can continue with existing infrastructure, but security threat identification and mitigation are inadequate and inefficient

Engineering Contradiction:
Improvesecurity threat protectionVSAvoidsecurity threat identification efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

A security analytics function is introduced as an intermediary component between network elements and security policies. This function collects security data from multiple sources, performs analytics processing, and generates security policy decisions, thereby improving threat identification efficiency without disrupting existing network operations

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Traditional rule-based security mechanisms are replaced with data-driven security analytics. The system uses collected security data from control plane and user plane traffic to dynamically determine security policies, replacing static mechanical security rules with adaptive analytics-based decisions

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If more security data is collected from multiple sources, then security analytics accuracy improves, but system complexity and data processing requirements increase

Engineering Contradiction:
Improvesecurity metric determination accuracyVSAvoidsecurity analytics system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The security analytics function is segmented into distinct components: data collection from multiple sources, data processing, analytics execution, and policy generation. This segmentation allows each component to handle specific tasks efficiently, managing system complexity while maintaining high measurement precision through specialized processing at each stage

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The security analytics function serves multiple purposes: collecting data from diverse sources, processing various types of security data, executing different analytics algorithms, and generating security policies. This multi-functional design consolidates complexity into a single universal component rather than requiring separate systems for each function

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12218958B2Security threat mitigations in a zero trust network architecture
Publication Date: 2025.02.04 T MOBILE INNOVATIONS LLC
  • US12218958B2 patent drawing
  • US12218958B2 patent drawing
  • US12218958B2 patent drawing

AI summary

A method comprises receiving, by a threat level engine (TLE) in the network, security data from a plurality of different sources, wherein the security data comprises data regarding traffic related to a security threat occurring in the network, determining, by the TLE, a security related event indicating a security threat occurring at network elements in the network based on security key performance indicators and the security data, when a threat impact level of the security related event exceeds a threshold, determining, by the TLE, a remediation action for the security related event based on the threat impact level, transmitting, by the TLE to a policy decision point, an instruction to generate and store a rule based on the remediation action for the security related event, and transmitting, to a policy enforcement point, an authorization to create the secure tunnel between the one or more network elements and another endpoint.