VNF Audit System Integrating Multi-Component Events

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing VNF audit methods have a high missed detection rate due to the complexity of network security management and the inability to comprehensively detect malicious VNFs, especially when vulnerabilities in the service component allow malicious VNFs to bypass components, leading to incomplete log generation and inefficient analysis.

Innovation Solution

A VNF audit method and apparatus that integrates events from authentication, authorization, and virtualized infrastructure components to create an event occurrence sequence, allowing for the detection of malicious VNFs by sorting and analyzing these events based on user identifiers, module sequences, execution durations, and operation types, thereby reducing the missed detection rate.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If network function virtualization is used to create VNFs flexibly, then adaptability and ease of expansion are improved, but device complexity and security management difficulty increase

Engineering Contradiction:
ImproveVNF flexibilityVSAvoidsecurity management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the security audit process into multiple independent components: authentication and authorization component, service component, and virtualized infrastructure component. Each component generates separate event logs that are later integrated, allowing complex security management to be divided into manageable segments while maintaining comprehensive monitoring capability

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary audit system that collects and integrates events from multiple platform components. This intermediary mechanism consolidates scattered security information into a unified view, reducing the complexity of security management while preserving the flexibility of VNF deployment

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If existing component-by-component log analysis is used, then ease of operation is maintained, but measurement precision and detection completeness deteriorate

Engineering Contradiction:
Improveaudit operation simplicityVSAvoidmalicious VNF detection accuracy
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent merges event logs from multiple platform components (authentication and authorization component, service component, virtualized infrastructure component) into a unified event sequence. This combination allows comprehensive detection of malicious VNFs that may bypass individual components, improving detection accuracy while maintaining automated operation

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent implements a feedback mechanism where the integrated event sequence is analyzed to detect anomalies and generate audit results. The system continuously monitors event patterns and provides feedback on malicious VNF detection, improving precision through iterative analysis of combined component events

Inventive Principle:
Principle #23Feedback

3Reliability

If comprehensive multi-component event integration is implemented, then detection completeness is improved, but device complexity and processing requirements increase

Engineering Contradiction:
Improvedetection completenessVSAvoidaudit system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the comprehensive audit system into three distinct functional modules: an authentication and authorization component that generates first events, a service component that generates second events, and a virtualized infrastructure component that generates third events. This segmentation allows complex multi-component monitoring to be implemented through manageable, independent modules that can be deployed and maintained separately

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal event integration mechanism that handles multiple types of events from different components through a unified processing approach. The system uses a common event sequence generation and analysis framework that works across all component types, reducing overall system complexity while achieving comprehensive detection

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10990670B2Virtual network function audit method and apparatus
Publication Date: 2021.04.27 HUAWEI TECH CO LTD
  • US10990670B2 patent drawing
  • US10990670B2 patent drawing
  • US10990670B2 patent drawing

AI summary

A virtual network function (VNF) audit method and apparatus, used to audit a VNF generated by a platform that includes an authentication and authorization component, a service component, and a virtualized infrastructure. The method includes receiving an event reported by the authentication and authorization component, receiving an event reported by the service component, and receiving an event reported by the virtualized infrastructure, obtaining an event occurrence sequence of each VNF according to all received events, and auditing the event occurrence sequence of each VNF to obtain an audit result of the VNF. According to the method, the events that are distributed in different components are integrated into one event occurrence sequence in order to visually and quickly detect a malicious VNF generated by bypassing a component, and more comprehensively detect the malicious VNF, thereby reducing a missed detection rate of a VNF operation audit.