Denial of service detection and mitigation in a multi-access edge computing environment
Abstract
A device includes a processor and a memory. The processor effectuates operations including monitoring enterprise network traffic associated with one or more user equipment (UE). The processor further effectuates operations including comparing the enterprise network traffic to a UE profile associated with each of the one or more UE. The processor further effectuates operations including determining whether the comparison indicates that a predetermined threshold has been exceeded. The processor further effectuates operations including in response to the indication that the predetermined threshold has been exceeded, generating an alert, wherein exceeding the predetermined threshold is indicative of a denial of service attack on an enterprise network or an attempt to remove enterprise data via the one or more UE.
Claims
exact text as granted — not AI-modified1 . A device, comprising:
a processor; and a memory coupled with the processor, the memory storing executable instructions that when executed by the processor, cause the processor to facilitate performance of operations comprising:
comparing attachment rates, detachment rates, and signal power measurements for a user equipment (UE) to a UE profile, resulting in a first comparison;
determining, based on the first comparison, that normal behavior for the UE has exceeded a threshold amount, wherein exceeding the threshold amount is indicative of a denial of service attack on a network or an attempt to remove data via the UE; and
based on the determining, generating an alert.
2 . The device of claim 1 , wherein the operations further comprise:
monitoring attachment rates of UE devices connecting to a radio access network; monitoring detachment rates of UE devices disconnecting from the radio access network; and monitoring signal power measurements of UE devices connected to the radio access network.
3 . The device of claim 2 , wherein the operations further comprise:
determining whether the UE is still connected to the radio access network; and determining whether the UE has reattached to the radio access network in an abnormal manner.
4 . The device of claim 3 , wherein the operations further comprise:
obtaining a UE profile associated with the UE; and comparing the attachment rates, the detachment rates, and the signal power measurements for UE to the UE profile associated with the UE.
5 . The device of claim 4 , wherein the operations further comprise:
obtaining UE profiles associated with all UE attached to the radio access network; comparing attachment rates, detachment rates, and signal power measurements for a predetermined subset of UE of all UE to a UE profile for each UE, resulting in a second comparison; and determining, based on the second comparison, that normal behavior for the UE has exceeded a threshold amount, wherein exceeding the threshold amount is indicative of a denial of service attack on a network or an attempt to remove data via the UE.
6 . The device of claim 1 , wherein the operations further comprise:
determining, based on the first comparison, that normal behavior for the UE has exceeded a threshold amount, wherein exceeding the threshold amount is indicative of a use of an intercepting device to obtain sensitive data for a person or an enterprise associated with the UE.
7 . The device of claim 6 , wherein the operations further comprise:
based on the determining, generating an alert, the alert indicating based on the first comparison.
8 . A non-transitory machine-readable medium, comprising executable instructions that, when executed by a processing system including a processor, facilitate performance of operations, the operations comprising:
monitoring attachment rates of user equipment (UE) devices connecting to a radio access network; monitoring detachment rates of UE devices disconnecting from the radio access network; and monitoring signal power measurements of UE devices connected to the radio access network. comparing the attachment rates, the detachment rates, and the signal power measurements for a user equipment (UE) to a UE profile, resulting in a first comparison; determining, based on the first comparison, that normal behavior for the UE has exceeded a threshold amount, wherein exceeding the threshold amount is indicative of a denial of service attack on a network or an attempt to remove data via the UE; and based on the determining, generating an alert.
9 . The non-transitory machine-readable medium of claim 8 , wherein the operations further comprise:
monitoring a connection status of the UE in the radio access network.
10 . The non-transitory machine-readable medium of claim 9 , wherein the monitoring the connection status of the UE comprises:
determining whether the UE is still connected to the radio access network; and determining whether the UE has reattached to the radio access network in an abnormal manner.
11 . The non-transitory machine-readable medium of claim 10 , wherein the determining whether the UE has reattached to the radio access network in an abnormal manner comprises:
determining the UE reattached to the radio access network at a rate that is at least three standard deviations or more from a measured network wide attach rate for UE devices in the radio access network.
12 . The non-transitory machine-readable medium of claim 8 , wherein the operations further comprise:
obtaining a UE profile associated with the UE; and comparing the attachment rates, the detachment rates, and the signal power measurements for the UE to the UE profile associated with the UE.
13 . The non-transitory machine-readable medium of claim 12 , wherein the operations further comprise:
obtaining UE profiles associated with all UE attached to the radio access network; comparing attachment rates, detachment rates, and signal power measurements for a predetermined subset of UE of all UE attached to the radio access network to a UE profile for each UE, resulting in a second comparison; and determining, based on the second comparison, that normal behavior for the UE has exceeded a threshold amount, wherein exceeding the threshold amount is indicative of a denial of service attack on a network or an attempt to remove data via the UE.
14 . The non-transitory machine-readable medium of claim 8 , wherein the operations further comprise:
determining, based on the first comparison, that normal behavior for the UE has exceeded a threshold amount, wherein exceeding the threshold amount is indicative of a use of an intercepting device to obtain sensitive data for a person or an enterprise associated with the UE.
15 . The non-transitory machine-readable medium of claim 14 , wherein the operations further comprise:
based on the determining that the normal behavior for the UE has exceeded a threshold amount, generating an alert, the alert indicating the use of the intercepting device and identifying the UE.
16 . A method, comprising:
receiving, by a processing system including a processor, information about attachment rates, information about detachment rates, and information about signal power measurements for a user equipment (UE) attached to a radio access network; comparing, by a processing system including a processor, the information about attachment rates, the information about detachment rates, and the information about signal power measurements for the UE to a UE profile associated with the UE, resulting in a first comparison; determining, by the processing system, based on the first comparison, that normal behavior for the UE has exceeded a threshold amount; and generating, by the processing system, an alert, wherein the generating the alert is based on the determining.
17 . The method of claim 16 , comprising:
identifying, by the processing system, a denial of service attack on the radio access network or an attempt to remove data via the UE, wherein the identifying is based on the determining that normal behavior for the UE has exceeded a threshold amount.
18 . The method of claim 17 , comprising:
obtaining, by the processing system, UE profiles associated with all UE attached to the radio access network; comparing, by the processing system, attachment rates, detachment rates, and signal power measurements for a predetermined subset of UE of all UE to a UE profile for each UE, resulting in a second comparison; and determining, based on the second comparison, that normal behavior for the UE has exceeded a threshold amount, wherein exceeding the threshold amount is indicative of a denial of service attack on a network or an attempt to remove data via the UE.
19 . The method of claim 16 , comprising:
determining, by the processing system, that normal behavior for the UE has exceeded a threshold amount, wherein exceeding the threshold amount is indicative of a use of an intercepting device to obtain sensitive data for a person or an enterprise associated with the UE, wherein the determining is based on the first comparison.
20 . The method of claim 19 , comprising:
generating, by the processing system, an alert indicative of the use of the intercepting device and identifying the UE.Join the waitlist — get patent alerts
Track US2022294820A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.