US2023209353A1PendingUtilityA1

Security system for directing 5g network traffic

Assignee: T MOBILE USA INCPriority: Jul 6, 2020Filed: Feb 24, 2023Published: Jun 29, 2023
Est. expiryJul 6, 2040(~13.9 yrs left)· nominal 20-yr term from priority
Inventors:Venson Shaw
H04L 63/20H04W 12/122H04L 63/1408H04W 28/0268G06N 20/00H04L 63/1433H04W 84/042H04L 63/105H04L 63/104
65
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

The technology includes a method performed by a security system of a 5G network. The security system is instantiated to sort incoming or outgoing network traffic at a perimeter of the 5G network into one of multiple groups that are each uniquely associated with one of multiple functions or applications and one of multiple security levels. The system can inspect portions of incoming network traffic that contain addressing information required for the network traffic to reach an intended application or function, sorting the incoming network traffic into the groups based in part on the inspection of the portions of the network traffic, and dynamically directing the network traffic for the 5G network based on a particular security level associated with a particular application or a particular function of each of the groups.

Claims

exact text as granted — not AI-modified
I/We claim: 
     
         1 . A security system for a wireless telecommunication network, the security system comprising:
 a traffic-inspection module configured to inspect addressing information associated with network traffic in the wireless telecommunication network, wherein the addressing information indicates a plurality of destination network functions within the wireless telecommunication network for the network traffic;   a traffic-sorting module configured to divide the network traffic into one or more traffic groups according to respective security levels corresponding to the plurality of destination network functions indicated for the network traffic; and   a traffic-routing module configured to dynamically route the one or more traffic groups based on the respective security levels according to which the one or more traffic groups are divided.   
     
     
         2 . The security system of  claim 1 , wherein the security system is configured to be instantiated at one or more edge devices of the wireless telecommunication network in response to a detection of suspicious network traffic. 
     
     
         3 . The security system of  claim 1 , wherein the traffic-routing module is configured to, for a given traffic group corresponding to a high security level, divert the given traffic group to an alternative network functions different than a destination network function indicated for the given traffic group. 
     
     
         4 . The security system of  claim 1 , wherein the traffic-routing module is configured to, for a given traffic group corresponding to a high security level, divert the given traffic group to a quarantine containment area that is communicatively separate from the wireless telecommunication network. 
     
     
         5 . The security system of  claim 1 , wherein the traffic-routing module is configured to, for a given traffic group, direct the given traffic group to a destination network function indicated for the given traffic group via an alternative network path. 
     
     
         6 . The security system of  claim 1 , further comprising:
 a security-scoring module configured to output one or more labels for the network traffic, each label indicating a security score based on a vulnerability parameter, a risk parameter, and a threat parameter,
 wherein the traffic-sorting module is configured to divide the network traffic into the one or more traffic groups further according to the one or more labels for the network traffic. 
   
     
     
         7 . The security system of  claim 1 , wherein the security system is configured to be terminated in response to a change in a security threat level associated with the wireless telecommunication network. 
     
     
         8 . A method for a wireless telecommunication network, the method comprising:
 inspecting, by a security system dynamically instantiated in the wireless telecommunication network, addressing information associated with network traffic in the wireless telecommunication network, wherein the addressing information indicates one or more destination network functions within the wireless telecommunication network for the network traffic;   sorting, by the security system, the network traffic into one or more traffic groups according to respective security levels corresponding to the one or more destination network functions; and   dynamically routing, by the security system, the one or more traffic groups based on the respective security levels corresponding to the one or more traffic groups.   
     
     
         9 . The method of  claim 8 , further comprising dynamically instantiating the security system at one or more edge devices of the wireless telecommunication network in response to a detection of suspicious network traffic. 
     
     
         10 . The method of  claim 8 , wherein dynamically routing the one or more traffic groups comprises, for a given traffic group corresponding to a high security level, diverting the given traffic group to an alternative network functions different than a destination network function indicated for the given traffic group. 
     
     
         11 . The method of  claim 8 , wherein dynamically routing the one or more traffic groups comprises, for a given traffic group corresponding to a high security level, diverting the given traffic group to a quarantine containment area that is communicatively separate from the wireless telecommunication network. 
     
     
         12 . The method of  claim 8 , wherein dynamically routing the one or more traffic groups comprises, for a given traffic group, direct the given traffic group to a destination network function indicated for the given traffic group via an alternative network path. 
     
     
         13 . The method of  claim 8 , further comprising:
 determining one or more labels for the network traffic, each label indicating a security score based on a vulnerability parameter, a risk parameter, and a threat parameter,
 wherein the network traffic is sorted into the one or more traffic groups further according to the one or more labels for the network traffic. 
   
     
     
         14 . The method of  claim 8 , further comprising terminating the security system in response to a change in a security threat level associated with the wireless telecommunication network. 
     
     
         15 . At least one non-transitory computer-readable storage medium storing instructions for execution by at least one processor, wherein execution of the instructions cause the at least one processor to:
 inspect addressing information associated with network traffic in a wireless telecommunication network, wherein the addressing information indicates one or more destination network functions within the wireless telecommunication network for the network traffic;   sort the network traffic into one or more traffic groups according to respective security levels corresponding to the one or more destination network functions; and   dynamically route the one or more traffic groups based on the respective security levels corresponding to the one or more traffic groups.   
     
     
         16 . The at least one non-transitory computer-readable storage medium of  claim 15 , further comprising dynamically instantiating an security system at one or more edge devices of the wireless telecommunication network in response to a detection of suspicious network traffic, wherein the security system is configured to dynamically route the one or more traffic groups. 
     
     
         17 . The at least one non-transitory computer-readable storage medium of  claim 15 , wherein dynamically routing the one or more traffic groups comprises, for a given traffic group corresponding to a high security level, diverting the given traffic group to an alternative network functions different than a destination network function indicated for the given traffic group. 
     
     
         18 . The at least one non-transitory computer-readable storage medium of  claim 15 , wherein dynamically routing the one or more traffic groups comprises, for a given traffic group corresponding to a high security level, diverting the given traffic group to a quarantine containment area that is communicatively separate from the wireless telecommunication network. 
     
     
         19 . The at least one non-transitory computer-readable storage medium of  claim 15 , wherein dynamically routing the one or more traffic groups comprises, for a given traffic group, direct the given traffic group to a destination network function indicated for the given traffic group via an alternative network path. 
     
     
         20 . The at least one non-transitory computer-readable storage medium of  claim 15 , further comprising:
 determining one or more labels for the network traffic, each label indicating a security score based on a vulnerability parameter, a risk parameter, and a threat parameter,
 wherein the network traffic is sorted into the one or more traffic groups further according to the one or more labels for the network traffic.

Join the waitlist — get patent alerts

Track US2023209353A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.