Designing and vib[code]ing into the future.

SecureRAN
Designing for new security discoveries into the day-to-day workflow of network operators.
DESCRIPTION
Rethinking how we protect our network services so the humans behind the screens can find real threats quickly without losing their minds.
MY ROLE
User Research
Product Design
Visual Design
Interaction Design
TOOLS
Miro
Notion
Figma
TIMELINE
2023
TEAMMATES
Product Managers
Jason, Zora
Developers
Sam, Jean, Jun-Yan, Benson,
Nelson, Pomelo, Poeple, Coda
OVERVIEW
An opportunity to help
Keeping our cellular networks safe is pretty chaotic.
Traditionally, network operators are forced to buy every single part from one giant vendor. The next-generation network can now offer a mixture of the best parts (radio unit, software, hardware...) from different companies to build exactly what they need (O-RAN). But more building blocks also means more security gaps hackers can wiggle into.
💡 SecureRAN is a software solution that helps the people who run the flexible yet complex next-gen mobile network catch and prevent security breaches instantly.

PROBLEM DISCOVERY
New Technologies = Complex Risks
In a legacy, closed network, one vendor owns everything. So if a breach happens, operators know who to call.
But because O-RAN mixes and matches hardware and software from different vendors, security breaches within the network can be extremely catastrophic: Network speed drops, complete signal blackouts, severing mission-critical connections, pausing automated factories... on and on (and on and on).
Security alerts don't explain the network impact, so operators get confused and respond too slowly during an attack.
/ INFO MISMATCH /
Operators do not have the time and security training to look for threats, leaving the system unprotected.
/ OPERATIONAL (UN)REDINESS /
When an attack happens, operators can't see how it moves through the network. They're stuck fixing individual problems one by one instead of finding and closing the attacker's entry point(s).
/ BLIND SPOTS /
QUESTIONS FOR PURPOSE
The "So What?"
Asking a bunch of hard questions allowed me to narrow the mining field to find our priority objectives.

After recognising the 3 main gaps being excessive cognitive load, unfamiliar language, confusing actionability - it helped me define the objectives and able to attack the problem systematically.
USER-CENTRIC OBJECTIVES
How might we design an observability layer so operators can instantly deal with a breach?
Yes, the goal of SecureRAN is to automatically detect and respond to security abnormalities in the background, and transforming the overwhelmed operator from a data-miner into a confident decision-maker, allowing them to secure the network in <3 clicks rather than 3 hours by:
1.
Defining alerts that respects the operators' time. Do the heavy lifting for obvious attacks, quietly monitors the suspicious activities, and only interrupts the operator when human judgment is needed. Bypassing alert fatigue by only surfacing a single, high-confidence incident instead of a flood of red lights.

2.
When there's a change in the network behaviour, operators shouldn't have to guess why and where.
Straightforward explanation and direction on the incidents will help operators make decisions quickly without requiring deep cybersecurity expertise.
Error 409 in RIC API

3.
Transform text-based threat logs into visual network locations so operators can instantly see the exact node under attack and immediately understand its physical place in the network topology.

BUILDING PROCESS
Info Architecture + Design System
SecureRAN will be hosted in a management console along with other solutions. By mapping out exactly how local features connect to future rollouts now, we build a system that scales for what's coming next.

Performance & Consistency:
The components are engineered to handle high-frequency datas, guaranteeing fluid responsiveness and visual unity across the entire platform.
Semantic Colour System:
To reduce cognitive load, colours are meticulously calibrated to give users immediate clarity on threat levels and neutral states.

SOLUTION OVERVIEW
3 main problems, 3 main features

Threats at a Glance
To combat alert fatigue, I designed a quiet-by-default architecture. By using progressive disclosure, I kept the top level view restricted to immediate threats, the UI absorbs the complexity and only surfaces the narrative the operator actually needs to see.
❇️ Result: Operators are no longer paralyzed by a sea of red lights. They are presented with a focused, pre-triaged list of vulnerabilities they can act on immediately.

Clear Network Relationship
I realised text-based threat logs were not beneficial to a network engineer. To solve this, I designed a spatial mental model. I translated abstract O-RAN Protocols into a physical, visual topology, mapping the exact relationships between nodes, pods, and devices.
❇️ Result: Operators instantly see the blast radius of an attack. They can visually locate the compromised node and understand its physical place in the system.

*Concept prototype - not final design
Actionable Notifications
Changing the traditional alert framework from being a passive alarm to an active remediation tool. Baking clear calls-to-actions directly into the notification component. The design forces the system to prescribe the immediate next step, placing the solution exactly where the problem is announced.
❇️ Result: Alerts became actionable directives. Operators experienced reduced alert fatigue and can prioritise where their attention is most needed.
Other features

Guided Onboarding
By breaking a massive technical checklist into bite-sized, human-readable decisions, the interface holds the user's hand and prevents them from making critical configuration errors.
❇️ Result: Operators reduced onboarding time by 30% & eliminated most manual errors.

Role-Based Access Controls
A clean, visual tier system that makes it instantly clear who has the keys to which doors. The UI simplifies role management so admins can assign permissions intuitively.
❇️ Result: Drastically reduced the risk of accidental data exposure by ensuring only authorised personnel can access sensitive functions.

Controlled System Updates
Allows operators to keep threat detection patterns up to date through flexible version rollback options.
❇️ Result: Ensures continuous protection against emerging threats while giving operators full control and transparency over the update process.

Interactive Health Diagnostics
Translating dense vulnerability scans into a simple statuses. The report let operators drill directly to the specifics and trigger a remediation action right from the page.
❇️ Result: Turned a static diagnostic report into an interactive repair tool, empowering operators to patch vulnerabilities without hunting down the specific error codes.
IMPACTS
Measuring Success
42% reduced time to detect & respond to threats (QA test feedback).
During beta testing, we observed a change in operator behavior. Because the UI handled the prioritization, operators stopped instinctively exporting logs to Excel to filter the data themselves. We reduced the initial threat triage from a multi-minute manual sorting task to a 10-second visual confirmation.
Pioneered as the reference interface for O-RAN security by 4 major telecom operators.
By rendering the map directly in the console, we kept operators 100% in-platform during the critical investigation phase.
WHAT'S NEXT?
Looking Ahead
Transforming the console into an intelligent platform that leverages AI summarization to detect historic trends and predict future events.
IDEATING CONCEPT WIREFRAMES

In-depth Detection Mapping
Auto detection of an anomaly indicating potential unauthorized access. It correlates this with recent integrity issues in specific nodes, alerting the user to a possible security breach.

Predictive Analytics
Auto-prediction of an increased risk of vulnerabilities in specific software components due to recent updates, advising users to prioritize security patches.

Further Diagnoses
Auto extraction of critical information about recent vulnerabilities and behavioural changes, presenting a summary that highlights key threats and recommended actions.
Adaptive Learning
Learn historic pattern and trends of vulnerabilities. Providing increasingly accurate and relevant insights, and enhancing user satisfaction and security effectiveness.
Project Takeaways
As a problem solver, it's difficult to choose.
I inherently want to solve all problems at once. But with the amount of data we're handling here, that's physically impossible. So I had to adjust my scope and prioritisation on what the business goal was at each development stage.
Talking to people is absolutely necessary.
My ideas for constructing SecureRAN's IA came from chats with PM and stakeholders. But to really get a grasp of how people operate on security products, research and talking to actual operators is just as, if not more, helpful.
Don't reinvent the wheel when it works.
As there are no O-RAN specific security products in the market (right now), this development was like building a flying car using modern cars as reference. We had to work with some heavy research-based hypothesis and blank blueprints! Using what already works in similar security products can save an immense amount of time while saving energy on working with new inventions.

Final Notes
This project experienced significant changes in direction due to shifts in research findings, requiring us to rethink the approach several times. Designing for a global scale, aiming to serve large telecom operators, was a crucial factor throughout. Although the level of polish and craft of the product hasn't fully achieve its potential yet, my aim is to demonstrate the high-level of vision and problem-solving skills I can bring to a project.
SecureRAN represents a very new security technology with no existing solutions like it on the market. This makes it challenging to fully understand the pain points without time. However, I believe we can create a groundbreaking platform that offers unparalleled insights and security measures, setting a new standard in the industry.



