Virtual Obfuscation Service for NFV Traffic Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network function virtualization (NFV) introduces security concerns as companies transition from physical on-premise systems to cloud-based virtual systems, particularly due to the potential for monitoring and analysis of traffic patterns, which can reveal sensitive information and facilitate attacks.

Innovation Solution

Implementing a virtual obfuscation service that includes obfuscation components in both physical and cloud-based portions of the network, which mark and encrypt communications, and can be initiated on demand to add a layer of security by obscuring traffic patterns and preventing timing attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If companies transition from physical on-premise systems to cloud-based virtual systems using NFV, then network flexibility and dynamicity are improved, but security concerns worsen due to potential monitoring and analysis of traffic patterns

Engineering Contradiction:
Improvenetwork flexibilityVSAvoidsecurity concerns
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an obfuscation service as an intermediary component between network traffic sources and destinations. This service marks packets with obfuscation identifiers and manipulates traffic patterns to prevent unauthorized monitoring while maintaining legitimate network operations. The intermediary nature of this service allows NFV benefits to be retained while mitigating security risks from traffic analysis.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes traffic parameters by introducing obfuscation markings and modifying traffic patterns. By altering packet identifiers, timing characteristics, and flow patterns through the obfuscation service, the system maintains network flexibility while making traffic analysis difficult for potential attackers.

Inventive Principle:
Principle #35Parameter changes

2Object-affected harmful factors

If obfuscation service components are implemented in both physical and cloud-based portions of the network, then security against monitoring and timing attacks is improved, but device complexity worsens

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent divides the obfuscation service into separate components: a first obfuscation service component in the physical network portion and a second obfuscation service component in the cloud-based virtual portion. Each component handles specific aspects of obfuscation independently, which manages complexity by localizing functions rather than creating a monolithic complex system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The obfuscation service components are designed to perform multiple functions: marking packets with obfuscation identifiers, preventing timing attacks through rate limiting, and maintaining network functionality. This multi-functionality reduces the need for separate specialized components, thereby managing overall system complexity while providing comprehensive security protection.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10164944B1System, method, and computer program for implementing a virtual obfuscation service in a network
Publication Date: 2018.12.25 AMDOCS DEV LTD
  • US10164944B1 patent drawing
  • US10164944B1 patent drawing
  • US10164944B1 patent drawing

AI summary

A system, method, and computer program product are provided for implementing a virtual obfuscation service in a network. In use, an obfuscation service component is initiated in a network system including one or more virtual services, the obfuscation service component including at least one of: at least one first obfuscation service component associated with a physical portion of the network system or at least one second obfuscation service component associated with a cloud-based virtual portion of the network system. Further, communication to be sent from the physical portion of the network system to the cloud-based virtual portion of the network system is identified. Additionally, the communication is directed from the physical portion of the network system to the first obfuscation service component associated with the physical portion of the network system. Furthermore, the communication is sent from the first obfuscation service component associated with the physical portion of the network system to the second obfuscation service component associated with the cloud-based virtual portion of the network system.