IP Library Granted Patent US 12,041,077
Granted Patent B2
US 12,041,077 · App. 17/160,164 · Granted Jul 16, 2024

Ai/ml approach for DDOS prevention on 5G CBRS networks

Inventors: Ohad Arnon (Beit Nir, IL); Dany Shapiro (Alfi Menashe, IL); Shiri Gaber (Beer Sheva, IL)
Assignee: EMC IP Holding Company LLC
H04L63/1458H04L41/16H04L63/1425H04L69/22
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,041,077
App. No.
17/160,164
Granted
Jul 16, 2024
Kind
B2
Abstract

One example method includes collecting, in a closed network, raw network traffic from one or more devices in the closed network, extracting metadata from the raw network traffic, processing the metadata, analyzing the metadata after the metadata has been processed, and based on the analyzing, determining whether or not an actual attack or attack threat is present in the closed network. If an attack or threat of attack is determined to exist, one or more remedial actions may then be taken.

Claims (32)

1. A method, comprising:

collecting, in a closed network, raw network traffic from one or more devices in the closed network;

extracting metadata from the raw network traffic;

creating aggregated data by aggregating the raw network traffic with the metadata;

processing the aggregated data into time series data;

inputting the time series data to an AI/ML model;

analyzing the time series data using the AI/ML model after the aggregated data has been processed; and

based on the analyzing, determining whether or not an actual attack or attack threat is present in the closed network.

2. The method as recited in claim 1 , wherein the method is performed by a VNF pod on an edge node of the closed network.

3. The method as recited in claim 1 , wherein the closed network is a 5G CBRS network.

4. The method as recited in claim 1 , wherein the extracted metadata comprises TCP headers.

5. The method as recited in claim 1 , wherein the determining indicates that an attack or attack threat is present in the closed network, and the method further comprises transmitting instructions to the one or more devices in the closed network not to accept calls from the one or more devices within the closed network which initiated the attack or present the attack threat.

6. The method as recited in claim 1 , wherein the one or more devices in the closed network were authorized to join the closed network, and one of the devices comprises an IoT device.

7. The method as recited in claim 1 , wherein the actual attack or attack threat comprises, respectively, a DOS attack or DOS attack threat.

8. The method as recited in claim 1 , further comprising identifying the one or more devices in the closed network which initiated the attack or present the attack threat.

9. The method as recited in claim 1 , wherein the raw network traffic is collected by way of a data plane through which all the raw network traffic passes.

10. A non-transitory storage medium having stored therein instructions that are executable by one or more hardware processors to perform operations comprising:

collecting, in a closed network, raw network traffic from one or more devices in the closed network;

extracting metadata from the raw network traffic;

creating aggregated data by aggregating the raw network traffic with the metadata;

processing the aggregated data into time series data;

inputting the time series data to an AI/ML model;

analyzing the time series data using the AI/ML model after the aggregated data has been processed; and

based on the analyzing, determining whether or not an actual attack or attack threat is present in the closed network.

11. The non-transitory storage medium as recited in claim 10 , wherein the operations are performed by a VNF pod on an edge node of the closed network.

12. The non-transitory storage medium as recited in claim 10 , wherein the closed network is a 5G CBRS network.

13. The non-transitory storage medium as recited in claim 10 , wherein the extracted metadata comprises TCP headers.

14. The non-transitory storage medium as recited in claim 10 , wherein the determining indicates that an attack or attack threat is present in the closed network, and the method further comprises transmitting instructions to the one or more devices in the closed network not to accept calls from the one or more devices within the closed network which initiated the attack or present the attack threat.

15. The non-transitory storage medium as recited in claim 10 , wherein the one or more devices in the closed network were authorized to join the closed network, and one of the devices comprises an IoT device.

16. The non-transitory storage medium as recited in claim 10 , wherein the actual attack or attack threat comprises, respectively, a DOS attack or DOS attack threat.

17. The non-transitory storage medium as recited in claim 10 , wherein the operations further comprise identifying the one or more devices in the closed network which initiated the attack or present the attack threat.

18. The non-transitory storage medium as recited in claim 10 , wherein the raw network traffic is collected by way of a data plane through which all the raw network traffic passes.

Assignments (9)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 12, 2024
From: ARNON, OHAD; SHAPIRO, DANY; GABER, SHIRI
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 067707/0647 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (055479/0051) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 062021/0663 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (056136/0752) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 062021/0771 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (055479/0342) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 062021/0460 →
RELEASE OF SECURITY INTEREST AT REEL 055408 FRAME 0697 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058001/0553 →
SECURITY INTEREST Recorded Mar 3, 2021
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 055479/0342 →
SECURITY INTEREST Recorded Mar 3, 2021
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 056136/0752 →
SECURITY INTEREST Recorded Mar 3, 2021
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 055479/0051 →
SECURITY AGREEMENT Recorded Feb 25, 2021
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 055408/0697 →