Virtualized Network Policy Verification for Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Automated policy generation in virtualized networks, such as those using NFV and SDN, introduces risks of improper network behavior, service degradation, and unauthorized data exposure due to cyberattacks or misconfigurations, which traditional methods fail to adequately address.

Innovation Solution

Implement a Policy Verifier Function (PVF) using AI/ML techniques to validate network policies before deployment, detecting anomalies through machine learning models trained on historical data to ensure authenticity and integrity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If automated policy generation is implemented in virtualized networks, then network configuration speed and adaptability are improved, but the risk of improper network behavior, service degradation, and unauthorized data exposure increases

Engineering Contradiction:
Improvenetwork configuration speedVSAvoidnetwork behavior reliability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies preliminary action by implementing a policy verification function that analyzes and validates policies before they are deployed to the network. The ML model performs anomaly detection on policy configurations in advance, identifying potential issues such as improper network behavior, service degradation risks, and unauthorized data exposure vulnerabilities before they can affect the actual network operation. This pre-validation approach allows automated policy generation to proceed quickly while maintaining reliability through prior security checks.

Inventive Principle:
Principle #10Preliminary action

2Device complexity

If traditional policy validation methods are used, then system complexity is kept low, but the ability to detect anomalies and ensure policy authenticity is insufficient

Engineering Contradiction:
Improvevalidation system complexityVSAvoidanomaly detection precision
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The patent replaces traditional mechanical or rule-based policy validation methods with a machine learning-based anomaly detection system. Instead of relying on simple checklist validations or manual reviews, the system employs ML models trained to recognize patterns of anomalous behavior in policies. This substitution significantly improves measurement precision in detecting subtle anomalies and ensuring policy authenticity, while the modular integration keeps the added complexity manageable through standardized interfaces and incremental deployment.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Measurement precision

If machine learning models are deployed for policy analysis, then anomaly detection capability is improved, but processing time and computational resources increase

Engineering Contradiction:
Improveanomaly detection capabilityVSAvoidpolicy validation time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies partial action by implementing a two-stage validation process: first, a lightweight filtering mechanism performs rapid preliminary assessment of policies to identify obvious anomalies, and second, the full ML model is applied only to policies that require deeper analysis. This approach maintains high anomaly detection capability for complex cases while reducing average processing time by avoiding full ML analysis on all policies. The system performs just enough validation effort for each policy based on its risk profile.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20250286790A1Techniques for detecting anomalous policies in a virtualized network
Publication Date: 2025.09.11 LENOVO UNITED STATES INC
  • US20250286790A1 patent drawing
  • US20250286790A1 patent drawing
  • US20250286790A1 patent drawing

AI summary

Various aspects of the present disclosure relate to techniques for detecting anomalous policies in a virtualized network. A network entity is configured to receive policy information associated with a policy for a network function virtualization (NFV)-enabled wireless network; analyze the policy information using a machine learning model to generate results, wherein the machine learning model is trained to identify anomalies in one or more policies; and transmit the results of the machine learning model analysis, the results comprising an indication of whether the policy comprises an anomaly.