US2022294820A1PendingUtilityA1

Denial of service detection and mitigation in a multi-access edge computing environment

Assignee: AT & T IP I LPPriority: Mar 26, 2020Filed: May 31, 2022Published: Sep 15, 2022
Est. expiryMar 26, 2040(~13.7 yrs left)· nominal 20-yr term from priority
H04L 63/1425H04L 43/16H04L 63/205H04L 43/0876H04W 12/121H04L 41/06H04L 63/1458H04L 67/306G16Y 30/10
60
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A device includes a processor and a memory. The processor effectuates operations including monitoring enterprise network traffic associated with one or more user equipment (UE). The processor further effectuates operations including comparing the enterprise network traffic to a UE profile associated with each of the one or more UE. The processor further effectuates operations including determining whether the comparison indicates that a predetermined threshold has been exceeded. The processor further effectuates operations including in response to the indication that the predetermined threshold has been exceeded, generating an alert, wherein exceeding the predetermined threshold is indicative of a denial of service attack on an enterprise network or an attempt to remove enterprise data via the one or more UE.

Claims

exact text as granted — not AI-modified
1 . A device, comprising:
 a processor; and   a memory coupled with the processor, the memory storing executable instructions that when executed by the processor, cause the processor to facilitate performance of operations comprising:
 comparing attachment rates, detachment rates, and signal power measurements for a user equipment (UE) to a UE profile, resulting in a first comparison; 
 determining, based on the first comparison, that normal behavior for the UE has exceeded a threshold amount, wherein exceeding the threshold amount is indicative of a denial of service attack on a network or an attempt to remove data via the UE; and 
 based on the determining, generating an alert. 
   
     
     
         2 . The device of  claim 1 , wherein the operations further comprise:
 monitoring attachment rates of UE devices connecting to a radio access network;   monitoring detachment rates of UE devices disconnecting from the radio access network; and   monitoring signal power measurements of UE devices connected to the radio access network.   
     
     
         3 . The device of  claim 2 , wherein the operations further comprise:
 determining whether the UE is still connected to the radio access network; and   determining whether the UE has reattached to the radio access network in an abnormal manner.   
     
     
         4 . The device of  claim 3 , wherein the operations further comprise:
 obtaining a UE profile associated with the UE; and   comparing the attachment rates, the detachment rates, and the signal power measurements for UE to the UE profile associated with the UE.   
     
     
         5 . The device of  claim 4 , wherein the operations further comprise:
 obtaining UE profiles associated with all UE attached to the radio access network;   comparing attachment rates, detachment rates, and signal power measurements for a predetermined subset of UE of all UE to a UE profile for each UE, resulting in a second comparison; and   determining, based on the second comparison, that normal behavior for the UE has exceeded a threshold amount, wherein exceeding the threshold amount is indicative of a denial of service attack on a network or an attempt to remove data via the UE.   
     
     
         6 . The device of  claim 1 , wherein the operations further comprise:
 determining, based on the first comparison, that normal behavior for the UE has exceeded a threshold amount, wherein exceeding the threshold amount is indicative of a use of an intercepting device to obtain sensitive data for a person or an enterprise associated with the UE.   
     
     
         7 . The device of  claim 6 , wherein the operations further comprise:
 based on the determining, generating an alert, the alert indicating based on the first comparison.   
     
     
         8 . A non-transitory machine-readable medium, comprising executable instructions that, when executed by a processing system including a processor, facilitate performance of operations, the operations comprising:
 monitoring attachment rates of user equipment (UE) devices connecting to a radio access network;   monitoring detachment rates of UE devices disconnecting from the radio access network; and   monitoring signal power measurements of UE devices connected to the radio access network.   comparing the attachment rates, the detachment rates, and the signal power measurements for a user equipment (UE) to a UE profile, resulting in a first comparison;   determining, based on the first comparison, that normal behavior for the UE has exceeded a threshold amount, wherein exceeding the threshold amount is indicative of a denial of service attack on a network or an attempt to remove data via the UE; and   based on the determining, generating an alert.   
     
     
         9 . The non-transitory machine-readable medium of  claim 8 , wherein the operations further comprise:
 monitoring a connection status of the UE in the radio access network.   
     
     
         10 . The non-transitory machine-readable medium of  claim 9 , wherein the monitoring the connection status of the UE comprises:
 determining whether the UE is still connected to the radio access network; and   determining whether the UE has reattached to the radio access network in an abnormal manner.   
     
     
         11 . The non-transitory machine-readable medium of  claim 10 , wherein the determining whether the UE has reattached to the radio access network in an abnormal manner comprises:
 determining the UE reattached to the radio access network at a rate that is at least three standard deviations or more from a measured network wide attach rate for UE devices in the radio access network.   
     
     
         12 . The non-transitory machine-readable medium of  claim 8 , wherein the operations further comprise:
 obtaining a UE profile associated with the UE; and   comparing the attachment rates, the detachment rates, and the signal power measurements for the UE to the UE profile associated with the UE.   
     
     
         13 . The non-transitory machine-readable medium of  claim 12 , wherein the operations further comprise:
 obtaining UE profiles associated with all UE attached to the radio access network;   comparing attachment rates, detachment rates, and signal power measurements for a predetermined subset of UE of all UE attached to the radio access network to a UE profile for each UE, resulting in a second comparison; and   determining, based on the second comparison, that normal behavior for the UE has exceeded a threshold amount, wherein exceeding the threshold amount is indicative of a denial of service attack on a network or an attempt to remove data via the UE.   
     
     
         14 . The non-transitory machine-readable medium of  claim 8 , wherein the operations further comprise:
 determining, based on the first comparison, that normal behavior for the UE has exceeded a threshold amount, wherein exceeding the threshold amount is indicative of a use of an intercepting device to obtain sensitive data for a person or an enterprise associated with the UE.   
     
     
         15 . The non-transitory machine-readable medium of  claim 14 , wherein the operations further comprise:
 based on the determining that the normal behavior for the UE has exceeded a threshold amount, generating an alert, the alert indicating the use of the intercepting device and identifying the UE.   
     
     
         16 . A method, comprising:
 receiving, by a processing system including a processor, information about attachment rates, information about detachment rates, and information about signal power measurements for a user equipment (UE) attached to a radio access network;   comparing, by a processing system including a processor, the information about attachment rates, the information about detachment rates, and the information about signal power measurements for the UE to a UE profile associated with the UE, resulting in a first comparison;   determining, by the processing system, based on the first comparison, that normal behavior for the UE has exceeded a threshold amount; and   generating, by the processing system, an alert, wherein the generating the alert is based on the determining.   
     
     
         17 . The method of  claim 16 , comprising:
 identifying, by the processing system, a denial of service attack on the radio access network or an attempt to remove data via the UE, wherein the identifying is based on the determining that normal behavior for the UE has exceeded a threshold amount.   
     
     
         18 . The method of  claim 17 , comprising:
 obtaining, by the processing system, UE profiles associated with all UE attached to the radio access network;   comparing, by the processing system, attachment rates, detachment rates, and signal power measurements for a predetermined subset of UE of all UE to a UE profile for each UE, resulting in a second comparison; and   determining, based on the second comparison, that normal behavior for the UE has exceeded a threshold amount, wherein exceeding the threshold amount is indicative of a denial of service attack on a network or an attempt to remove data via the UE.   
     
     
         19 . The method of  claim 16 , comprising:
 determining, by the processing system, that normal behavior for the UE has exceeded a threshold amount, wherein exceeding the threshold amount is indicative of a use of an intercepting device to obtain sensitive data for a person or an enterprise associated with the UE, wherein the determining is based on the first comparison.   
     
     
         20 . The method of  claim 19 , comprising:
 generating, by the processing system, an alert indicative of the use of the intercepting device and identifying the UE.

Join the waitlist — get patent alerts

Track US2022294820A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.