Abro
68
3.2.5.1 Next Generation Threat Landscape for 5G
5G is not only going to be the next generation of mobile network, but it will still be a
platform to introduce the next generation of security threats. Next generation security
threats are foreseen to carry the following characteristics:
● Sophisticated: complex in nature, uses a multi‐staged mix of various attack vectors
and tools. For example, the Angler exploit kit that is packaged to exploit a multiple
vendor into a single attack;
● Obfuscatory: attacks that are obscured by multiple layers and very hard to detect;
● Evasive: hard to detect and ability to hide itself, e.g. ransomware cryptowall attack; and
● Persistent: such attacks are meant to be consistent and evolve themselves after every
failed attempt.
APTs (Advance Persistent Threats) are attacks that carry out the above characteristics,
are hard to mitigate and protect from and eventually become serious threats causing
great damage. APTs usually target crucial infrastructure facilities, large service providers
that serve masses and cause major disruption and multi‐dimensional impact.
3.2.5.2 IoT Threat Landscape
5G will serve as the network platform for future industrial systems, critical infrastructure
and IoT (Internet of things). Attacks targeting such critical networks are foreseen as
advanced in nature and will require a highly complex skillset and resources to execute.
Politically motivated and sponsored attacks will often be encountered in the 5G environment. Such attacks will have the potential to leverage the undisclosed system vulnerabilities, also called zero day flaws, and operated through a centralize command and control
(C&C) system. There will be no single tool or approach used for such attacks and it will
often be a mixture of threat techniques such as DDoS, phishing and advance rootkits. The
impact of these kinds of attacks is widespread and goes beyond economic damage and
may involve national security, public safety and loss of human life. As per US Presidential
Executive Order 13010, telecommunications is considered as a critical infrastructure and
states that: “it is so vital that their incapacity or destruction would have a debilitating
impact on the defense or economic security of the United States” [8].
Most of critical infrastructures today are using a centralize control system, such as
SCADA (Supervisory Control and Data Acquisition), which is further connected to a
network. All remote systems need to send regular signaling and health information
to the system for normal operation, so a malware type of threat can be used to disrupt
the control system and result in the loss of services. In the future, 5G is going to
serve these systems for the underlying network and connectivity services and will be
exposed to the threats to these systems.
3.2.5.3 5G Evolved Security Model
To protect 5G from advanced and complex threat landscapes, we need an evolved security model (as show in Figure 3.6) that offers in‐depth protection, not only from existing
threats but also from evolving and zero‐day threat types.
It will require a well‐defined security strategy and plan to protect the various
components for the 5G network, including the end devices and end users. An effective
security strategy can be designed based on telemetry data gained through a well‐
designed surveillance system. A security position plan would be needed to place the
security mechanisms in effective positions. Processes and tools need to be identified to
68
3.2.5.1 Next Generation Threat Landscape for 5G
5G is not only going to be the next generation of mobile network, but it will still be a
platform to introduce the next generation of security threats. Next generation security
threats are foreseen to carry the following characteristics:
● Sophisticated: complex in nature, uses a multi‐staged mix of various attack vectors
and tools. For example, the Angler exploit kit that is packaged to exploit a multiple
vendor into a single attack;
● Obfuscatory: attacks that are obscured by multiple layers and very hard to detect;
● Evasive: hard to detect and ability to hide itself, e.g. ransomware cryptowall attack; and
● Persistent: such attacks are meant to be consistent and evolve themselves after every
failed attempt.
APTs (Advance Persistent Threats) are attacks that carry out the above characteristics,
are hard to mitigate and protect from and eventually become serious threats causing
great damage. APTs usually target crucial infrastructure facilities, large service providers
that serve masses and cause major disruption and multi‐dimensional impact.
3.2.5.2 IoT Threat Landscape
5G will serve as the network platform for future industrial systems, critical infrastructure
and IoT (Internet of things). Attacks targeting such critical networks are foreseen as
advanced in nature and will require a highly complex skillset and resources to execute.
Politically motivated and sponsored attacks will often be encountered in the 5G environment. Such attacks will have the potential to leverage the undisclosed system vulnerabilities, also called zero day flaws, and operated through a centralize command and control
(C&C) system. There will be no single tool or approach used for such attacks and it will
often be a mixture of threat techniques such as DDoS, phishing and advance rootkits. The
impact of these kinds of attacks is widespread and goes beyond economic damage and
may involve national security, public safety and loss of human life. As per US Presidential
Executive Order 13010, telecommunications is considered as a critical infrastructure and
states that: “it is so vital that their incapacity or destruction would have a debilitating
impact on the defense or economic security of the United States” [8].
Most of critical infrastructures today are using a centralize control system, such as
SCADA (Supervisory Control and Data Acquisition), which is further connected to a
network. All remote systems need to send regular signaling and health information
to the system for normal operation, so a malware type of threat can be used to disrupt
the control system and result in the loss of services. In the future, 5G is going to
serve these systems for the underlying network and connectivity services and will be
exposed to the threats to these systems.
3.2.5.3 5G Evolved Security Model
To protect 5G from advanced and complex threat landscapes, we need an evolved security model (as show in Figure 3.6) that offers in‐depth protection, not only from existing
threats but also from evolving and zero‐day threat types.
It will require a well‐defined security strategy and plan to protect the various
components for the 5G network, including the end devices and end users. An effective
security strategy can be designed based on telemetry data gained through a well‐
designed surveillance system. A security position plan would be needed to place the
security mechanisms in effective positions. Processes and tools need to be identified to
