IP Library Granted Patent US 9,460,286
Granted Patent B1
US 9,460,286 · App. 14/572,723 · Granted Oct 4, 2016

System, method, and computer program for managing security in a network function virtualization (NFV) based communication network

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,460,286
App. No.
14/572,723
Granted
Oct 4, 2016
Kind
B1
Abstract

A system, method, and computer program product are provided for providing security in a Network Function Virtualization based (NFV-based) communication network. In operation, a security attack is identified. Additionally, a first hardware unit attacked by the security attack is identified. Further, a hardware unit in which to initiate a security defense software program is identified. Moreover, the security defense software program is initiated in the identified hardware unit.

Claims (27)

1. A method, comprising:

identifying, by a first hardware unit in a Network Function Virtualization based (NFV-based) network, that a security attack has occurred within the first hardware unit;

responsive to identifying the security attack, identifying by the first hardware unit a second hardware unit in the NFV-based network that is operative to replace the first hardware unit;

initiating, by the first hardware unit, a migration of functionality of the first hardware unit to the identified second hardware unit; and

after the functionality of the first hardware unit is migrated to the second hardware unit, executing a security defense software program in the first hardware unit to cleanse the first hardware unit; and

after the first hardware unit is cleansed, reinitiating the migrated functionality at the first hardware unit.

2. The method of claim 1 , wherein initiating the migration of functionality of the first hardware unit to the identified second hardware unit includes:

determining whether the identified second hardware unit already includes code to perform the functionality;

responsive to determining that the identified second hardware unit does not already include the code, initiating installation of the code on the second hardware unit;

determining whether the identified second hardware unit already includes data required to execute the functionality without causing a session and/or service discontinuity otherwise resulting from the migrating;

responsive to determining that the identified second hardware unit does not already include the data, initiating a provisioning of the data to the second hardware unit from a mirroring facility or a backup facility;

once the second hardware unit has the code and the data, configuring the second hardware unit according to parameters of the first hardware unit; and

after the configuring, diverting communications incoming to the first hardware unit to the second hardware unit.

3. A computer program product embodied in a computer storage device having computer code, when executed by a computer hardware processor, to perform functions of:

identifying, by a first hardware unit in a Network Function Virtualization based (NFV-based) network, that a security attack has occurred within the first hardware unit;

responsive to identifying the security attack, identifying by the first hardware unit a second hardware unit in the NFV-based network that is operative to replace the first hardware unit;

initiating, by the first hardware unit, a migration of functionality of the first hardware unit to the identified second hardware unit; and

after the functionality of the first hardware unit is migrated to the second hardware unit, executing a security defense software program in the identified first hardware unit to cleanse the first hardware unit; and

after the first hardware unit is cleansed, reinitiating the migrated functionality at the first hardware unit.

4. A system comprising:

a memory system of a first hardware unit in a Network Function Virtualization based (NFV-based) network; and

one or more hardware processing cores of the first hardware unit that are coupled to the memory system and that are each configured to:

identify, by the first hardware unit, that a security attack has occurred within the first hardware unit;

responsive to identifying the security attack, identify by the first hardware unit a second hardware unit in the NFV-based network that is operative to replace the first hardware unit;

initiate, by the first hardware unit, a migration of functionality of the first hardware unit to the identified second hardware unit; and

after the functionality of the first hardware unit is migrated to the second hardware unit, execute a security defense software program in the first hardware unit to cleanse the first hardware unit; and

after the first hardware unit is cleansed, reinitiate the migrated functionality at the first hardware unit.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 8, 2016
From: AMDOCS SOFTWARE SYSTEMS LIMITED; AMDOCS DEVELOPMENT LIMITED
To: AMDOCS DEVELOPMENT LIMITED
Reel/Frame 040257/0817 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 4, 2016
From: AMDOCS SOFTWARE SYSTEMS LIMITED
To: AMDOCS DEVELOPMENT LIMITED; AMDOCS SOFTWARE SYSTEMS LIMITED
Reel/Frame 039695/0965 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 16, 2015
From: FELSTAINE, EYAL; HERMONI, OFER; SANDLERMAN, NIMROD
To: AMDOCS SOFTWARE SYSTEMS LIMITED
Reel/Frame 036115/0445 →