IP Library Granted Patent US 11,582,264
Granted Patent B2
US 11,582,264 · App. 17/153,721 · Granted Feb 14, 2023

Network slice-based security in mobile networks

Inventors: Sachin Verma (Danville, CA); Leonid Burakovsky (Pleasanton, CA)
Assignee: Palo Alto Networks, Inc.
H04L63/205H04L63/02H04L63/10H04L63/1416H04L63/1458H04W12/009H04W12/088H04W12/121H04W24/08H04L67/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,582,264
App. No.
17/153,721
Granted
Feb 14, 2023
Kind
B2
Abstract

Techniques for providing network slice-based security in mobile networks (e.g., service provider networks for mobile subscribers) are disclosed. In some embodiments, a system/process/computer program product for network slice-based security in mobile networks in accordance with some embodiments includes monitoring network traffic on a service provider network at a security platform to identify a new session, wherein the service provider network includes a 5G network or a converged 5G network; extracting network slice information for user traffic associated with the new session at the security platform; and determining a security policy to apply at the security platform to the new session based on the network slice information.

Claims (37)

1. A system, comprising:

a processor configured to:

monitor network traffic on a service provider network at a security platform to identify a new session, wherein the service provider network includes a 5G network or a converged 5G network;

extract network slice information for user traffic associated with the new session at the security platform, wherein the extracting the network slice information further comprises to:

parse HTTP/2 messages to extract the network slice information from a create context request service operation or a create service operation in the network traffic, and wherein the network slice is identified by Single Network Slice Selection Assistance Information (S-NSSAI); and

determine a security policy to apply at the security platform to the new session based on the network slice information; and

a memory coupled to the processor and configured to provide the processor with instructions.

2. The system recited in claim 1 , wherein the security platform is configured with a plurality of security policies based on the network slice information.

3. The system recited in claim 1 , wherein the security platform monitors wireless interfaces including a plurality of interfaces for a control protocol and user data traffic in a mobile core network for a 4G and/or 5G network.

4. The system recited in claim 1 , wherein the security platform monitors wireless interfaces including a plurality of interfaces for a control protocol and user data traffic in a mobile core network for a 4G and/or 5G network to provide network slice-based security to subscribers and subscriber devices that connect to the service provider network using 5G radio access technology and handover from/to 5G radio access technologies to non-5G radio access technologies.

5. The system recited in claim 1 , wherein the security platform is configured to perform a firewall service using the network slice information to apply security for a customer with a plurality of subscribers, a plurality of mobile subscribers, and/or a plurality of subscriber's devices.

6. The system recited in claim 1 , wherein the security platform is configured to perform threat detection for known threats using the network slice information.

7. The system recited in claim 1 , wherein the security platform is configured to perform advanced threat detection for unknown threats using the network slice information.

8. The system recited in claim 1 , wherein the security platform is configured to perform Uniform Resource Link (URL) filtering using the network slice information.

9. The system recited in claim 1 , wherein the security platform is configured to perform application Denial of Service (DoS) detection using the network slice information.

10. The system recited in claim 1 , wherein the security platform is configured to perform application Denial of Service (DoS) prevention using the network slice information.

11. The system recited in claim 1 , wherein the processor is further configured to:

block the new session from accessing a resource based on the security policy.

12. A method, comprising:

monitoring network traffic on a service provider network at a security platform to identify a new session, wherein the service provider network includes a 5G network or a converged 5G network;

extracting network slice information for user traffic associated with the new session at the security platform, wherein the extracting the network slice information further comprises:

parsing HTTP/2 messages to extract the network slice information from a create context request service operation or a create service operation in the network traffic, and wherein the network slice is identified by Single Network Slice Selection Assistance Information (S-NSSAI); and

determining a security policy to apply at the security platform to the new session based on the network slice information.

13. The method of claim 12 , wherein the security platform is configured with a plurality of security policies based on the network slice information.

14. The method of claim 12 , wherein the security platform monitors wireless interfaces including a plurality of interfaces for a control protocol and user data traffic in a mobile core network for a 4G and/or 5G network to provide network slice-based security to subscribers and subscriber devices that connect to the service provider network using 5G radio access technology and handover from/to 5G radio access technologies to non-5G radio access technologies.

15. The method of claim 12 , wherein the security platform is configured to perform a firewall service using the network slice information to apply security for a customer with a plurality of subscribers, a plurality of mobile subscribers, and/or a plurality of subscriber's devices.

16. The method of claim 12 , wherein the security platform is configured to perform threat detection for known threats using the network slice information, advanced threat detection for unknown threats using the network slice information, Uniform Resource Link (URL) filtering using the network slice information, application Denial of Service (DoS) detection using the network slice information, and/or application Denial of Service (DoS) prevention using the network slice information.

17. The method of claim 12 , further comprising:

blocking the new session from accessing a resource based on the security policy.

18. A computer program product, the computer program product being embodied in a tangible non-transitory computer readable storage medium and comprising computer instructions for:

monitoring network traffic on a service provider network at a security platform to identify a new session, wherein the service provider network includes a 5G network or a converged 5G network;

extracting network slice information for user traffic associated with the new session at the security platform, wherein the extracting the network slice information further comprises:

parsing HTTP/2 messages to extract the network slice information from a create context request service operation or a create service operation in the network traffic, and wherein the network slice is identified by Single Network Slice Selection Assistance Information (S-NSSAI); and

determining a security policy to apply at the security platform to the new session based on the network slice information.

19. The computer program product recited in claim 18 , wherein the security platform is configured with a plurality of security policies based on the network slice information.

20. The computer program product recited in claim 18 , further comprising computer instructions for:

blocking the new session from accessing a resource based on the security policy.

Continuity (2)
Continuation 16144143 · Sep 27, 2018
Related Publication 20210144183A1 · May 13, 2021
Cited By (1)
US 12,271,385