IP Library › Granted Patent US 12,389,229
Granted Patent B2
US 12,389,229 · App. 18/002,149 · Granted Aug 12, 2025

Monitoring of at least one slice of a communications network using a confidence index assigned to the slice of the network

Inventor: Hichem Sedjelmaci (Châtillon, FR)
Assignee: ORANGE
H04W12/122
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,389,229
App. No.
18/002,149
Granted
Aug 12, 2025
Kind
B2
Abstract

A monitoring system is described for monitoring at least one slice of a communications network using at least one access network, an edge network and a core network. The system, comprises, for each slice, a plurality of intrusion detection modules configured to monitor elements associated with said section and comprising at least a first module for detecting intrusions at the access network level, a second module for detecting intrusions at the edge network level, and at least a third module at the core network level, each of the modules being configured to provide a piece of information representative of a local confidence level assigned to the section according to a behaviour of at least one element that it monitors. One of the third modules is additionally configured to evaluate, from the provided information, an overall confidence level for this section and to trigger an intrusion mitigation action for this section depending on the value of this overall confidence level.

Claims (20)

1. A monitoring system for monitoring at least one slice of a communications network using at least one access network, an edge network and a core network, said system comprising, for each slice:

a plurality of intrusion detection modules configured to monitor elements associated with said slice and comprising at least:

a first module for detecting intrusions at the access network level,

a second module for detecting intrusions at the edge network level, and

at least one third module at the core network level, each of said modules being configured to provide a piece of information representative of a local confidence level assigned to said slice according to a behavior of at least one element that it monitors, said at least one third module also being configured to evaluate, from said information provided, a global confidence level for said slice and to trigger an intrusion mitigation action for said slice according to a value of said global confidence level.

2. The system of claim 1 , wherein said plurality of detection modules associated with said slice comprises a plurality of third modules associated, respectively, with separate active network functions of the core network.

3. The system of claim 2 , wherein said at least one third module configured to evaluate the global confidence level is selected from among said plurality of third modules on the basis of its proximity to the access network and/or to the edge network.

4. The system of claim 1 , wherein the global confidence level for said slice is a mean of local confidence levels provided by said plurality of detection modules.

5. The system of claim 1 , wherein at least one local confidence level is evaluated by a said detection module for said slice as a ratio between a subtraction of a number of normal behaviors of said at least one element monitored by this detection module and of a number of intrusions affecting said at least one element monitored by this detection module detected over a given period of time, by a sum of said numbers.

6. The system of claim 1 , wherein said intrusion mitigation action comprises, if the value of the global confidence level is below a given threshold, the isolation of said slice of the network and/or the removal of at least one element of the access network, of the edge network and/or of the core network identified as being targeted by an intrusion.

7. The system of claim 1 , wherein said first module is configured so that, on detecting an intrusion, it signals said detected intrusion to said second module and/or to said first module associated with another slice using said access network.

8. The system of claim 1 , wherein said second module is configured so that, on detecting an intrusion, it signals said detected intrusion to said at least one third module and/or triggers a mitigation action at the level of the access network and/or of the edge network.

9. The system of claim 1 , wherein at least one said detection module is configured to execute at least one action from among a deep analysis action, a notification action, and/or a mitigation action when it detects that a probability of executing this action is above a specified threshold.

10. The system of claim 9 , wherein said threshold is determined dynamically for said detection module on the basis of a number of false detections performed by said detection module.

11. A communications network configured to implement network slicing, said communications network comprising the system of claim 1 , configured for monitoring at least one slice of said network.

12. A method for monitoring at least one slice of a communications network using at least an access network, an edge network and a core network, said method comprising:

monitoring said slice by means of a plurality of intrusion detection modules configured to monitor elements associated with said slice and comprising at least a first module for detecting intrusions at the access network level, a second module for detecting intrusions at the edge network level, and at least one third module at the core network level;

providing, by means of each of said plurality of intrusion detection modules, a piece of information representative of a local confidence level assigned to said slice according to a behavior of at least one element monitored by said module;

evaluating, by means of said at least one third module, from said information provided, a global confidence level for said slice; and

triggering an intrusion mitigation action for said slice according to a value of said global confidence level.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 18, 2023
From: SEDJELMACI, HICHEM
To: ORANGE
Reel/Frame 065899/0291 →
Priority Claims (2)
FR 2006453 · Jun 19, 2020 · national
FR 2006454 · Jun 19, 2020 · national
Continuity (1)
Related Publication 20230232235A1 · Jul 20, 2023
References Cited (8)
US 11095533B1 · Hermoni · 2021 [cited by examiner]
US 20050039047A1 · Raikar et al. · 2005 [cited by applicant]
US 20170279848A1 · Vasseur · 2017 [cited by examiner]
US 20220361188A1 · Sun · 2022 [cited by examiner]
CN 105516177B · 2019 [cited by applicant]
WO WO2019115173A1 · 2019 [cited by applicant]
International Search Report and Written Opinion dated Sep. 1, 2021 for Application No. PCT/FR2021/051109. [cited by applicant]
Liu, et al., “A Dynamic Composition Mechanism of Security Service Chaining Oriented to SDN/NFV—Enabled Networks” IEEE Access, vol. 6. Sep. 17, 2018 (Sep. 17, 2018), pp. 53918-53929. [cited by applicant]
Cited By (1)
US 12,732,818