VNF Audit System Integrating Multi-Component Events
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing VNF audit methods have a high missed detection rate due to the complexity of network security management and the inability to comprehensively detect malicious VNFs, especially when vulnerabilities in the service component allow malicious VNFs to bypass components, leading to incomplete log generation and inefficient analysis.
Innovation Solution
A VNF audit method and apparatus that integrates events from authentication, authorization, and virtualized infrastructure components to create an event occurrence sequence, allowing for the detection of malicious VNFs by sorting and analyzing these events based on user identifiers, module sequences, execution durations, and operation types, thereby reducing the missed detection rate.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If network function virtualization is used to create VNFs flexibly, then adaptability and ease of expansion are improved, but device complexity and security management difficulty increase
Solution Approach 1:
The patent segments the security audit process into multiple independent components: authentication and authorization component, service component, and virtualized infrastructure component. Each component generates separate event logs that are later integrated, allowing complex security management to be divided into manageable segments while maintaining comprehensive monitoring capability
Solution Approach 2:
The patent introduces an intermediary audit system that collects and integrates events from multiple platform components. This intermediary mechanism consolidates scattered security information into a unified view, reducing the complexity of security management while preserving the flexibility of VNF deployment
2Ease of operation
If existing component-by-component log analysis is used, then ease of operation is maintained, but measurement precision and detection completeness deteriorate
Solution Approach 1:
The patent merges event logs from multiple platform components (authentication and authorization component, service component, virtualized infrastructure component) into a unified event sequence. This combination allows comprehensive detection of malicious VNFs that may bypass individual components, improving detection accuracy while maintaining automated operation
Solution Approach 2:
The patent implements a feedback mechanism where the integrated event sequence is analyzed to detect anomalies and generate audit results. The system continuously monitors event patterns and provides feedback on malicious VNF detection, improving precision through iterative analysis of combined component events
3Reliability
If comprehensive multi-component event integration is implemented, then detection completeness is improved, but device complexity and processing requirements increase
Solution Approach 1:
The patent segments the comprehensive audit system into three distinct functional modules: an authentication and authorization component that generates first events, a service component that generates second events, and a virtualized infrastructure component that generates third events. This segmentation allows complex multi-component monitoring to be implemented through manageable, independent modules that can be deployed and maintained separately
Solution Approach 2:
The patent creates a universal event integration mechanism that handles multiple types of events from different components through a unified processing approach. The system uses a common event sequence generation and analysis framework that works across all component types, reducing overall system complexity while achieving comprehensive detection
Data Source
AI summary
A virtual network function (VNF) audit method and apparatus, used to audit a VNF generated by a platform that includes an authentication and authorization component, a service component, and a virtualized infrastructure. The method includes receiving an event reported by the authentication and authorization component, receiving an event reported by the service component, and receiving an event reported by the virtualized infrastructure, obtaining an event occurrence sequence of each VNF according to all received events, and auditing the event occurrence sequence of each VNF to obtain an audit result of the VNF. According to the method, the events that are distributed in different components are integrated into one event occurrence sequence in order to visually and quickly detect a malicious VNF generated by bypassing a component, and more comprehensively detect the malicious VNF, thereby reducing a missed detection rate of a VNF operation audit.


