IP Library › Granted Patent US 12,732,818
Granted Patent B2
US 12,732,818 · App. 18/465,766 · Granted Sep 8, 2026

Cyber attack detection function

Inventor: Abhijeet Kolekar (Portland, OR)
Assignee: Intel Corporation
H04W12/121
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,732,818
App. No.
18/465,766
Granted
Sep 8, 2026
Kind
B2
Abstract

Various embodiments herein provide techniques related to a cellular network. Specifically, a cyber attack detection function (CDAF) of the cellular network may be configured to: identify operation state data from an analytics logical function (AnLF), wherein the operation state data corresponds to an analytics output of the AnLF; identify, based on the operation state data, a cyber-attack of at least one element of the cellular network; and transmit, based on the identification of the cyber-attack, a report that includes an indication of the cyber-attack. Other embodiments may be described and/or claimed.

Claims (34)

1 . One or more non-transitory computer-readable media (NTCRM) comprising instructions that, upon execution of the instructions by one or more processors of one or more electronic devices, are to cause a cyber attack detection function (CADF) of a cellular network to:

identify operation state data from an analytics logical function (AnLF), wherein the operation state data corresponds to an analytics output of the AnLF;

identify, based on the operation state data, a cyber-attack of at least one element of the cellular network; and

transmit, based on identification of the cyber-attack, a report that includes an indication of the cyber-attack.

2 . The one or more NTCRM of claim 1 , wherein the instructions are to cause the CADF to transmit the report as an output of the CADF to an operations, administration, and maintenance (OAM) function of the cellular network.

3 . The one or more NTCRM of claim 2 , wherein the instructions are to cause the CADF to transmit the report as an output of the CADF to the OAM based on a Nnwdaf_AnalyticsInfo_Request service operation received from the OAM.

4 . The one or more NTCRM of claim 3 , wherein the instructions are to cause the CADF to transmit the report as an output of the CADF to the OAM in a Nnwdaf_AnalyticsInfo_Request response.

5 . The one or more NTCRM of claim 2 , wherein the instructions are to cause the CADF to transmit the report as an output to the CADF to the OAM based on a Nnwdaf_AnalyticsSubscription_Subscribe service operation received from the OAM.

6 . The one or more NTCRM of claim 5 , wherein the instructions are to cause the CADF to transmit the report as an output of the CADF to the OAM based on a Nnwdaf_AnalyticsSubscription_Subscribe response.

7 . The one or more NTCRM of claim 1 , wherein the AnLF is to send the operation state data based on a subscription request provided by the CADF to the AnLF.

8 . The one or more NTCRM of claim 1 , wherein the instructions are to cause the CADF to identify the cyber-attack based at least in part on:

identifying occurrence of an event based on the operation state data;

comparing a characteristic of the event to one or more characteristics of one or more previous events; and

identifying, based on the comparing, that the event is related to a cyber-attack.

9 . The one or more NTCRM of claim 8 , wherein the CADF is to compare the characteristic of the event to the one or more characteristics of the one or more previous events based at least in part on a machine-learning algorithm.

10 . The one or more NTCRM of claim 8 , wherein the CADF is to identify, based on the comparing, that the event is related to a cyber-attack based at least in part on a machine-learning algorithm.

11 . An electronic device comprising:

one or more processors to implement a cyber-attack detection function (CADF) of a cellular network; and

one or more non-transitory computer-readable media comprising instructions that, upon execution of the instructions by the one or more processors, are to cause the CADF to:

identify operation state data from an analytics logical function (AnLF), wherein the operation state data corresponds to an analytics output of the AnLF;

identify, based on the operation state data, a cyber-attack of at least one element of the cellular network; and

transmit, based on identification of the cyber-attack, a report that includes an indication of the cyber-attack.

12 . The electronic device of claim 11 , wherein the instructions are to cause the CADF to transmit the report as an output of the CADF to an operations, administration, and maintenance (OAM) function of the cellular network.

13 . The electronic device of claim 12 , wherein the instructions are to cause the CADF to transmit the report as an output of the CADF to the OAM based on a Nnwdaf_AnalyticsInfo_Request service operation received from the OAM.

14 . The electronic device of claim 13 , wherein the instructions are to cause the CADF to transmit the report as an output of the CADF to the OAM in a Nnwdaf_AnalyticsInfo_Request response.

15 . The electronic device of claim 12 , wherein the instructions are to cause the CADF to transmit the report as an output of the CADF to the OAM based on a Nnwdaf_AnalyticsSubscription_Subscribe service operation received from the OAM.

16 . The electronic device of claim 15 , wherein the instructions are to cause the CADF to transmit the report as an output of the CADF to the OAM based on a Nnwdaf_AnalyticsSubscription_Subscribe response.

17 . The electronic device of claim 11 , wherein the AnLF is to send the operation state data based on a subscription request provided by the CADF to the AnLF.

18 . The electronic device of claim 11 , wherein the instructions are to cause the CADF to identify the cyber-attack based at least in part on:

identifying occurrence of an event based on the operation state data;

comparing a characteristic of the event to one or more characteristics of one or more previous events; and

identifying, based on the comparing, that the event is related to a cyber-attack.

19 . The electronic device of claim 18 , wherein the CADF is to compare the characteristic of the event to one or more characteristics of one or more previous events based at least in part on a machine-learning algorithm.

20 . The electronic device of claim 18 , wherein the CADF is to identify, based on the comparing, that the event is related to a cyber-attack based at least in part on a machine-learning algorithm.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 11, 2026
From: INTEL CORPORATION
To: INTEL PRODUCTS IP LLC
Reel/Frame 075990/0451 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 12, 2023
From: KOLEKAR, ABHIJEET
To: INTEL CORPORATION
Reel/Frame 064880/0083 →
Continuity (2)
Provisional Application 63411455 · Sep 29, 2022
Related Publication 20230422038A1 · Dec 28, 2023
References Cited (11)
US 9628994B1 · Gunyel · 2017 [cited by examiner]
US 9736706B2 · Salyers · 2017 [cited by examiner]
US 9817969B2 · Lee · 2017 [cited by examiner]
US 11265700B2 · Huber · 2022 [cited by examiner]
US 11323884B2 · Lifshitz · 2022 [cited by examiner]
US 12160745B2 · Sedjelmaci · 2024 [cited by examiner]
US 12200492B2 · Sasi · 2025 [cited by examiner]
US 12389229B2 · Sedjelmaci · 2025 [cited by examiner]
US 20220264307A1 · Sasi · 2022 [cited by examiner]
3GPP, “Technical Specification Group Services and System Aspects; Architecture enhancements for 5G System (5GS) to support network data analytics services (Release 17),” 3GPP TS 23.288 V17.6.0 (Sep. 2022), 5G, 208 pages. [cited by applicant]
3GPP, “Technical Specification Group Services and System Aspects; Study on enablers for network automation for the 5G System (5GS); Phase 2 (Release 17),” 3GPP TR 23.700-91 V17.0.0 (Dec. 2020), 5G, 382 pages. [cited by applicant]