IP Library › Granted Patent US 12,289,343
Granted Patent B2
US 12,289,343 · App. 17/838,735 · Granted Apr 29, 2025

Detecting malicious threats in a 5G network slice

Inventors: Petar Djukic (Ottawa, CA); David Jordan Krauss (Centreville, VA); James P'ford't Carnes, III (Baltimore, MD); William Kaufmann (Chicago, IL); Balaji Subramaniam (San Jose, CA)
Assignee: Ciena Corporation
H04L63/20G06F21/6254H04L45/306H04L47/2475H04L63/1416H04W12/128
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,289,343
App. No.
17/838,735
Granted
Apr 29, 2025
Kind
B2
Abstract

Systems and methods for monitoring a network slice are provided. A method, according to one implementation, include extracting information from network traffic received from one or more User Plane Function (UPF) components of a network slice; examining the extracted information using Machine Learning (ML), and, in response to detecting of one or more malicious threats based on the examined extracted information by the ML, causing one or more actions to isolate the network traffic to protect at least the network slice from the one or more malicious threats.

Claims (36)

1. A non-transitory computer-readable medium configured to store computer logic having instructions that, when executed, enable a processing device to:

extract information from network traffic at one or more User Plane Function (UPF) components of a network slice,

examine the extracted information using Machine Learning (ML) of one or more threat detection components placed at the one or more UPF components where a transition between underlay and overlay traffic occurs in a data plane of the network slice, and

in response to detection of one or more malicious threats based on the examined extracted information by the ML, cause one or more actions to isolate the network traffic to protect at least the network slice from the one or more malicious threats.

2. The non-transitory computer-readable medium of claim 1 , wherein the network traffic is isolated by diverting network traffic to an isolated location in the network slice for further examination.

3. The non-transitory computer-readable medium of claim 2 , wherein the network slice includes one or more Session Management Function (SMF) components and one or more Policy Management Function (PMF) components, and wherein the instructions further enable the processing device to

cause the one or more SMF components and one or more PMF components to instruct the one or more UPF components to divert the network traffic to the isolated location when one or more malicious threats are detected.

4. The non-transitory computer-readable medium of claim 1 , wherein the network traffic is isolated by preventing the spread of the one or more malicious threats throughout the network slice.

5. The non-transitory computer-readable medium of claim 1 , wherein the ML include Deep Packet Inspection (DPI) performed by a DPI module.

6. The non-transitory computer-readable medium of claim 1 , wherein the extracted information includes one or more of 5-tuple Internet Protocol (IP) information and packet capture (PCAP) information.

7. The non-transitory computer-readable medium of claim 1 , wherein the instructions further enable the processing device to develop a ML model based on a dataset of Performance Metrics (PMs) of observed information from network traffic to establish a baseline of expected usage profiles.

8. The non-transitory computer-readable medium of claim 1 , wherein the instructions further enable the processing device to

apply the ML model to ongoing network traffic information to identify unexpected network usage that differs from the baseline of the expected usage profiles, and

utilize the identified unexpected network usage for detecting the one or more malicious threats.

9. The non-transitory computer-readable medium of claim 1 , wherein the one or more UPF components are arranged in the data plane of the network slice, and wherein the network slice further includes one or more Access and mobility Management Function (AMF) components and one or more Session Management Function (SMF) components arranged in a control plane of the network slice.

10. The non-transitory computer-readable medium of claim 1 , wherein the one or more UPF components are arranged between one or more devices and the Internet.

11. The non-transitory computer-readable medium of claim 10 , wherein at least one of the one or more devices includes a non-5G access device operating under one or more of Wi-Fi, Ethernet, Digital Subscriber Line (DSL), and Passive Optical Network (PON) protocols.

12. The non-transitory computer-readable medium of claim 10 , wherein each of the one or more end-user devices is one of a gNodeB (gNB) device, and a Radio Unit (RU), wherein each of the one or more devices includes at least a Centralized Unit (CU) and a Distributed Unit (DU).

13. A controller configured to monitor network slice, the controller comprising:

a processing device, and

a memory device configured to store computer logic having instructions that enable the processing device to

extract information from network traffic at one or more User Plane Function (UPF) components of a network slice,

examine the extracted information using Machine Learning (ML) of one or more threat detection components placed at the one or more UPF components where a transition between underlay and overlay traffic occurs in a data plane of the network slice, and

in response to detection of one or more malicious threats based on the examined extracted information by the ML, cause one or more actions to isolate the network traffic to protect at least the network slice from the one or more malicious threats.

14. The controller of claim 13 , wherein the network traffic is isolated by diverting network traffic to an isolated location in the network slice for further examination.

15. The controller of claim 13 , wherein the network traffic is isolated by preventing the spread of the one or more malicious threats throughout the network slice.

16. The controller of claim 13 , wherein the instructions further enable the processing device to develop a ML model based on a dataset of Performance Metrics (PMs) of observed information from network traffic to establish a baseline of expected usage profiles.

17. The controller of claim 13 , wherein the instructions further enable the processing device to

apply the ML model to ongoing network traffic information to identify unexpected network usage that differs from the baseline of the expected usage profiles, and

utilize the identified unexpected network usage for detecting the one or more malicious threats.

18. A method comprising steps of:

extracting information from network traffic at one or more User Plane Function (UPF) components of a network slice;

examining the extracted information using Machine Learning (ML) of one or more threat detection components placed at the one or more UPF components where a transition between underlay and overlay traffic occurs in a data plane of the network slice, and

in response to detecting of one or more malicious threats based on the examined extracted information by the ML, causing one or more actions to isolate the network traffic to protect at least the network slice from the one or more malicious threats.

19. The method of claim 18 , wherein the network traffic is isolated by diverting network traffic to an isolated location in the network slice for further examination.

20. The method of claim 18 , wherein the network traffic is isolated by preventing the spread of the one or more malicious threats throughout the network slice.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 13, 2022
From: DJUKIC, PETAR; KRAUSS, DAVID JORDAN; CARNES, JAMES P'FORD'T, III; KAUFMANN, WILLIAM; SUBRAMANIAM, BALAJI
To: CIENA CORPORATION
Reel/Frame 060182/0573 →
Continuity (3)
Continuation In Part 17571342 · Jan 7, 2022
Provisional Application 63150694 · Feb 18, 2021
Related Publication 20220330027A1 · Oct 13, 2022
References Cited (50)
US 8589503B2 · Alperovitch et al. · 2013 [cited by applicant]
US 8606910B2 · Alperovitch et al. · 2013 [cited by applicant]
US 9060292B2 · Callard et al. · 2015 [cited by applicant]
US 9152808B1 · Ramalingam et al. · 2015 [cited by applicant]
US 9397917B2 · Li et al. · 2016 [cited by applicant]
US 9432257B2 · Li et al. · 2016 [cited by applicant]
US 9503443B2 · Krauss et al. · 2016 [cited by applicant]
US 9602536B1 · Brown, Jr. et al. · 2017 [cited by applicant]
US 9819565B2 · Djukic et al. · 2017 [cited by applicant]
US 9825982B1 · Htay · 2017 [cited by applicant]
US 9838271B2 · Djukic et al. · 2017 [cited by applicant]
US 9838272B2 · Djukic et al. · 2017 [cited by applicant]
US 10038700B1 · Duchin et al. · 2018 [cited by applicant]
US 10148578B2 · Morris et al. · 2018 [cited by applicant]
US 10862749B1 · Kiyak et al. · 2020 [cited by applicant]
US 11049039B2 · Zimmer et al. · 2021 [cited by applicant]
US 11102238B2 · Ackerman et al. · 2021 [cited by applicant]
US 11165797B2 · Ackerman et al. · 2021 [cited by applicant]
US 20020059078A1 · Valdes et al. · 2002 [cited by applicant]
US 20040172557A1 · Nakae et al. · 2004 [cited by applicant]
US 20040213229A1 · Chang et al. · 2004 [cited by applicant]
US 20060101515A1 · Amoroso et al. · 2006 [cited by applicant]
US 20060259967A1 · Thomas et al. · 2006 [cited by applicant]
US 20070258437A1 · Bennett · 2007 [cited by applicant]
US 20070261112A1 · Todd et al. · 2007 [cited by applicant]
US 20120254951A1 · Munetoh et al. · 2012 [cited by applicant]
US 20130298192A1 · Kumar et al. · 2013 [cited by applicant]
US 20130305369A1 · Karta et al. · 2013 [cited by applicant]
US 20140096229A1 · Burns et al. · 2014 [cited by applicant]
US 20140244834A1 · Guedalia et al. · 2014 [cited by applicant]
US 20140328256A1 · Djukic et al. · 2014 [cited by applicant]
US 20150373043A1 · Wang · 2015 [cited by examiner]
US 20160006753A1 · McDaid et al. · 2016 [cited by applicant]
US 20160300227A1 · Subhedar et al. · 2016 [cited by applicant]
US 20170019315A1 · Tapia et al. · 2017 [cited by applicant]
US 20170034193A1 · Schulman et al. · 2017 [cited by applicant]
US 20170134405A1 · Ahmadzadeh et al. · 2017 [cited by applicant]
US 20170230267A1 · Armolavicius et al. · 2017 [cited by applicant]
US 20170353490A1 · Krauss et al. · 2017 [cited by applicant]
US 20170374090A1 · McGrew et al. · 2017 [cited by applicant]
US 20180139129A1 · Dowlatkhah · 2018 [cited by examiner]
US 20180191743A1 · Reddy et al. · 2018 [cited by applicant]
US 20180212928A1 · Gerber et al. · 2018 [cited by applicant]
US 20180225357A1 · Greco et al. · 2018 [cited by applicant]
US 20180285767A1 · Chew · 2018 [cited by applicant]
US 20190081983A1 · Teal · 2019 [cited by examiner]
US 20190141056A1 · Estabrooks et al. · 2019 [cited by applicant]
US 20190362072A1 · Kesarwani et al. · 2019 [cited by applicant]
US 20200019821A1 · Baracaldo-Angel et al. · 2020 [cited by applicant]
US 20220007194A1 · Shaw · 2022 [cited by examiner]
Cited By (1)
US 12,381,909