IP Library Granted Patent US 11,700,268
Granted Patent B2
US 11,700,268 · App. 17/337,774 · Granted Jul 11, 2023

Systems and methods for providing shifting network security via multi-access edge computing

Inventor: Tin Zaw (Santa Monica, CA)
Assignee: Verizon Patent and Licensing Inc.
H04L63/1416H04L63/0209H04L63/0245H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,700,268
App. No.
17/337,774
Granted
Jul 11, 2023
Kind
B2
Abstract

Disclosed is a device for configuring and implementing network security for a connected network node, and for shifting the network security closer to the attack point of origin. In particular, the device may activate attack protections on different Multi-Access Edge Computing (“MEC”) devices that are physically located near or at the attack point of origin. The device may detect an attack signature based on one or more received data packets, and may provide a response with an extended header field, the attack signature, and/or other attack protection instructions. The responses may be passed to an address of a suspected attacker. MEC devices along the network path may detect and receive the responses, and implement attack protections in response. The responses may also be passed to a multicast or broadcast address that the MEC device may use to receive responses.

Claims (67)

1. A method comprising:

receiving a plurality of data packets via a first network path that connects to a first network point of access, and via a second network path that connects to a different second network point of access;

detecting that a first set of the plurality of data packets originating from the first network point of access do not satisfy an attack signature, and that a second set of the plurality of data packets originating from the second network point of access satisfy the attack signature based on the second set of data packets comprising irregular addressing or irregular request patterns;

retrieving an Internet Protocol (“IP”) address that is assigned to each user equipment (“UE”) of a set of UEs accessing a network via the second network point of access, and a network usage by each UE of the set of UEs;

determining a mismatch between the network usage by a particular UE of the set of UEs and a computed usage from a subset of the second set of data packets comprising the IP address that is assigned to the particular UE, wherein the network usage by the particular UE comprises an amount of bandwidth or network capacity utilized by the particular UE at the second network point of access, wherein the computed usage comprises an amount of bandwidth or network capacity utilized by the subset of the second set of data packets comprising the IP address that is assigned to the particular UE, and wherein determining the mismatch comprises determining that the amount of bandwidth or network capacity utilized by the particular UE at the second network point of access is greater than the amount of bandwidth or network capacity utilized by the subset of the second set of data packets; and

implementing attack protections against the particular UE by disabling network access, throttling network access, or blocking one or more data packets originating from the particular UE at the second network point of access using a unique identifier of the particular UE that is different than the IP address that is assigned to the particular UE.

2. The method of claim 1 further comprising:

registering the particular UE for access to the network based on the unique identifier of the particular UE; and

assigning the IP address to the particular UE in response to successfully registering the particular UE.

3. The method of claim 2 , wherein the unique identifier comprises one or more of:

an International Mobile Subscriber Identity (“IMSI”),

an International Mobile Equipment Identity (“IMEI”),

a Cell Radio Network Temporary Identifier (“C-RNTI”),

a Globally Unique Temporary Identifier (“GUTI”),

a Home Network Identity (“HNI”), or

a Media Access Control (“MAC”) address.

4. The method of claim 1 further comprising:

detecting that the particular UE is using one or more spoofed addresses based on the mismatch between the network usage by the particular UE and the computed usage.

5. The method of claim 4 , wherein implementing the attack protections comprises:

preventing data packets comprising the one or more spoofed addresses from passing beyond the second network point of access.

6. The method of claim 1 further comprising:

querying a network device using an identifier of the second network point of access; and

receiving the unique identifier of the particular UE and the IP address that is assigned to the particular UE in response to querying the network device using the identifier of the second network point of access.

7. The method of claim 6 ,

wherein the unique identifier of the particular UE comprises an identifier with which the particular UE registers for service with the network.

8. The method of claim 1 further comprising:

querying a network device using an identifier of the second network point of access; and

receiving the network usage by the particular UE at the second network point of access in response to querying the network device using the identifier of the second network point of access.

9. The method of claim 1 , wherein implementing the attack protections comprises:

preventing data packets comprising IP addresses that differ from the IP addresses that are assigned to the set of UEs from passing through the second network point of access.

10. A system comprising:

a first network point of access;

a second network point of access; and

one or more devices configured to:

receive a plurality of data packets via a first network path that connects to the first network point of access, and via a second network path that connects to the second network point of access;

detect that a first set of the plurality of data packets originating from the first network point of access do not satisfy an attack signature, and that a second set of the plurality of data packets originating from the second network point of access satisfy the attack signature based on the second set of data packets comprising irregular addressing or irregular request patterns;

retrieve an Internet Protocol (“IP”) address that is assigned to each user equipment (“UE”) of a set of UEs accessing a network via the second network point of access, and a network usage by each UE of the set of UEs;

determine a mismatch between the network usage by a particular UE of the set of UEs and a computed usage from a subset of the second set of data packets comprising the IP address that is assigned to the particular UE, wherein the network usage by the particular UE comprises an amount of bandwidth or network capacity utilized by the particular UE at the second network point of access, wherein the computed usage comprises an amount of bandwidth or network capacity utilized by the subset of the second set of data packets comprising the IP address that is assigned to the particular UE, and wherein determining the mismatch comprises determining that the amount of bandwidth or network capacity utilized by the particular UE at the second network point of access is greater than the amount of bandwidth or network capacity utilized by the subset of the second set of data packets; and

implement attack protections against the particular UE by disabling network access, throttling network access, or blocking one or more data packets originating from the particular UE at the second network point of access using a unique identifier of the particular UE that is different than the IP address that is assigned to the particular UE.

11. The system of claim 10 , wherein the one or more devices are further configured to:

register the particular UE for access to the network based on the unique identifier of the particular UE; and

assign the IP address to the particular UE in response to successfully registering the particular UE.

12. The system of claim 10 , wherein the one or more devices are further configured to:

detect that the particular UE is using one or more spoofed addresses based on the mismatch between the network usage by the particular UE and the computed usage.

13. The system of claim 12 , wherein implementing the attack protections comprises:

preventing data packets comprising the one or more spoofed addresses from passing beyond the second network point of access.

14. The system of claim 10 , wherein the one or more devices are further configured to:

query a network device using an identifier of the second network point of access; and

receive the unique identifier of the particular UE and the IP address that is assigned to the particular UE in response to querying the network device using the identifier of the second network point of access.

15. The system of claim 10 , wherein the one or more devices are further configured to:

query a network device using an identifier of the second network point of access; and

receive the network usage by the particular UE at the second network point of access in response to querying the network device using the identifier of the second network point of access.

16. The system of claim 10 , wherein implementing the attack protections comprises:

preventing data packets comprising IP addresses that differ from the IP addresses that are assigned to the set of UEs from passing through the second network point of access.

17. A non-transitory computer-readable medium, storing a set of processor-executable instructions, which, when executed by one or more processors, cause the one or more processors to:

receive a plurality of data packets via a first network path that connects to a first network point of access, and via a second network path that connects to a different second network point of access;

detect that a first set of the plurality of data packets originating from the first network point of access do not satisfy an attack signature, and that a second set of the plurality of data packets originating from the second network point of access satisfy the attack signature based on the second set of data packets comprising irregular addressing or irregular request patterns;

retrieve an Internet Protocol (“IP”) address that is assigned to each user equipment (“UE”) of a set of UEs accessing a network via the second network point of access, and a network usage by each UE of the set of UEs;

determine a mismatch between the network usage by a particular UE of the set of UEs and computed usage from a subset of the second set of data packets comprising the IP address that is assigned to the particular UE, wherein the network usage by the particular UE comprises an amount of bandwidth or network capacity utilized by the particular UE at the second network point of access, wherein the computed usage comprises an amount of bandwidth or network capacity utilized by the subset of the second set of data packets comprising the IP address that is assigned to the particular UE, and wherein determining the mismatch comprises determining that the amount of bandwidth or network capacity utilized by the particular UE at the second network point of access is greater than the amount of bandwidth or network capacity utilized by the subset of the second set of data packets; and

implement attack protections against the particular UE by disabling network access, throttling network access, or blocking one or more data packets originating from the particular UE at the second network point of access using a unique identifier of the particular UE that is different than the IP address that is assigned to the particular UE.

18. The non-transitory computer-readable medium of claim 17 , wherein the processor-executable instructions further include processor-executable instructions to:

detect that the particular UE is using one or more spoofed addresses based on the mismatch between the network usage by the particular UE and the computed usage.

19. The non-transitory computer-readable medium of claim 17 , wherein the processor-executable instructions to implement the attack protections comprises:

processor-executable instructions to prevent data packets comprising the one or more spoofed addresses from passing beyond the second network point of access.

20. The non-transitory computer-readable medium of claim 17 , wherein the processor-executable instructions further include processor-executable instructions to:

register the particular UE for access to the network based on the unique identifier of the particular UE; and

assign the IP address to the particular UE in response to successfully registering the particular UE.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 15, 2021
From: VERIZON MEDIA INC.
To: VERIZON PATENT AND LICENSING INC.
Reel/Frame 057518/0820 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 1, 2021
From: VERIZON DIGITAL MEDIA SERVICES INC.
To: VERIZON PATENT AND LICENSING INC.
Reel/Frame 057352/0057 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 3, 2021
From: ZAW, TIN
To: VERIZON DIGITAL MEDIA SERVICES INC.
Reel/Frame 056428/0606 →