IP Library Granted Patent US 10,749,905
Granted Patent B2
US 10,749,905 · App. 16/044,442 · Granted Aug 18, 2020

System, method, and computer program providing security in network function virtualization (NFV) based communication networks and software defined networks (SDNS)

Inventors: Daniel Sela (Petah Tikva, IL); Ofer Hermoni (Plano, TX); Yosef Asaf Hermush (Tel Aviv, IL); Eyal Felstaine (Kfar Shmaryahu, IL)
Assignee: AMDOCS DEVELOPMENT LIMITED
H04L63/20H04L41/0813H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,749,905
App. No.
16/044,442
Granted
Aug 18, 2020
Kind
B2
Abstract

A system, method, and computer program product are provided for providing security in Network Function Virtualization (NFV) based communication networks and Software Defined Networks (SDNs). In use, a system implements one or more network changes or security configuration changes to an NFV based communication network or a SDN to change an attack surface. In one embodiment, implementing the one or more network changes or security configuration changes to the NFV based communication network or the SDN may occur periodically to change the attack surface. In another embodiment, implementing the one or more network changes or the security configuration changes to the NFV based communication network or the SDN to change the attack surface may occur based on detection of a malicious event or a suspicious event.

Claims (27)

1. A method, comprising:

detecting, by a system, a trigger to change an attack surface of an environment, the trigger being a time-based event utilized for periodically changing the attack surface of the environment as a function of time;

responsive to detecting the trigger, identifying, by the system, the attack surface of the environment, the attack surface including different points of the environment that are susceptible to an attack by an unauthorized user;

implementing, by the system, one or more network changes or security configuration changes to a Network Function Virtualization (NFV) based communication network or a Software Defined Network (SDN) to change the identified attack surface of the environment, including:

replacing a first asset of the environment with a second asset, wherein the second asset maintains service continuity by providing a same functionality as the first asset, and wherein the second asset includes properties that are different from properties of the first asset to render attacks via the attack surface ineffective;

wherein the first asset is a first type of webserver operating on a first port and the second asset is second type of webserver operating on a second port.

2. The method of claim 1 , further comprising:

remediating, by the system, a security issue associated with the NFV based communication network or the SDN.

3. The method of claim 1 , further comprising verifying that the one or more network changes or security configuration changes have been applied.

4. The method of claim 1 , wherein the NFV based communication network or the SDN are associated with a private cloud or a public cloud.

5. The method of claim 1 , wherein the one or more changes minimize the attack surface.

6. The method of claim 1 , wherein the one or more changes further include:

utilizing a different application;

utilizing a different protocol; and

utilizing different hardware.

7. A computer program product embodied on a non-transitory computer readable medium, comprising computer code for:

detecting, by a system, a trigger to change an attack surface of an environment, the trigger being a time-based event utilized for periodically changing the attack surface of the environment as a function of time;

responsive to detecting the trigger, identifying, by the system, the attack surface of the environment, the attack surface including different points of the environment that are susceptible to an attack by an unauthorized user;

implementing, by the system, one or more network changes or security configuration changes to a Network Function Virtualization (NFV) based communication network or a Software Defined Network (SDN) to change the identified attack surface of the environment, including:

replacing a first asset of the environment with a second asset, wherein the second asset maintains service continuity by providing a same functionality as the first asset, and wherein the second asset includes properties that are different from properties of the first asset to render attacks via the attack surface ineffective;

wherein the first asset is a first type of webserver operating on a first port and the second asset is second type of webserver operating on a second port.

8. A system, comprising one or more hardware processors, operable for:

detecting, by the system, a trigger to change an attack surface of an environment, the trigger being a time-based event utilized for periodically changing the attack surface of the environment as a function of time;

responsive to detecting the trigger, identifying, by the system, the attack surface of the environment, the attack surface including different points of the environment that are susceptible to an attack by an unauthorized user;

implementing, by the system, one or more network changes or security configuration changes to a Network Function Virtualization (NFV) based communication network or a Software Defined Network (SDN) to change the identified attack surface of the environment, including:

replacing a first asset of the environment with a second asset, wherein the second asset maintains service continuity by providing a same functionality as the first asset, and wherein the second asset includes properties that are different from properties of the first asset to render attacks via the attack surface ineffective;

wherein the first asset is a first type of webserver operating on a first port and the second asset is second type of webserver operating on a second port.

Assignments (2)
CORRECTIVE ASSIGNMENT TO CORRECT THE CONVEYING PARTY PREVIOUSLY RECORDED AT REEL: 046504 FRAME: 0644. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 14, 2018
From: SELA, DANIEL; HERMONI, OFER; HERMUSH, YOSEF ASAF; FELSTAINE, EYAL
To: AMDOCS DEVELOPMENT LIMITED
Reel/Frame 047090/0449 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 30, 2018
From: SELA, DANIEL; HERMONI, OFER; HERMUSH, YOSEF ASAF; FELSTAINE, EYAL
To: AMDOCS DEVELOPMENT LIMITED
Reel/Frame 046504/0644 →
Continuity (2)
Provisional Application 62539362 · Jul 31, 2017
Related Publication 20190036968A1 · Jan 31, 2019