Abro
72
Similarly, app developers also send regular updates to their mobile apps to fill in for
any insecure features or code residing in their applications. Application patches and
updates are independent of OS updates and need to be handled separately by the mobile
users. Mobile OS vendor often make this process simple through their app stores, as for
custom application installations, it is challenging to keep those apps up to date.
3.3.3 Security Threat Analysis and Assessment
As we know, 5G networks will rely heavily on IP‐based network communication and
protocol and will be leveraging the new software defined mobile networks (SDMN). 5G is
planning to leverage the benefits of SDMN to separate the management plane, control
plane and data plane of mobile networks to simplify the networks and offer new and
improved services using new programmable networks. SDMN with its capabilities offers
new security challenges and can cause vulnerabilities on different planes (management,
control and data) of the network. Threat vectors for 5G‐ and SDMN‐based networks are
complex and can introduce network flaws dynamically at different points of mobile
networks.
Traditional security assessments and threat analysis techniques are based on the
static and simple nature of traditional mobile networks and do not address the challenges introduced with 5G‐ and SDMN‐based dynamic network behaviors. Security
assessment for SDMN networks need to cover and address all the components and
layers (planes) of the mobile network. New security assessment approaches are recommended that focus around the dynamic nature of SDMNs. Such new assessments
should use the attack graphs to cover all SDMN factors and levels, and also need to use
an Analytic Hierarchy Process (AHP) to build the structure [10].
3.3.4 Security Monitoring
With the evolution of mobile networks from LTE to LTE Adv. and now 5G, mobile RAN
and core networks technologies have also evolved and are superseded by new technologies
such as Cloud RAN, NFV and SDMN. It is critical for mobile operators to have a comprehensive visibility and knowledge for their network operators in a real‐time fashion, not only
to offer better service assurance but also protect their critical network infrastructures from
security threats. Legacy mobile security monitoring solutions were not designed to protect
SDN‐ or NFV‐based networks and had no or limited capability to integrate with the modern technological components of the mobile network and so need to be replaced with
security monitoring solutions that offer higher performance, scalability and the capability
to integrate and work with these new mobile technologies.
Security monitoring solutions for LTE and 5G networks should offer a capability to
monitor and inspect both signaling and data traffic at multiple network points, starting
from UE to RAN and all the way to LTE/5G core network components. The solution
should be able to not only inspect the IPv4 and IPv6, but also offer visibility to other
protocols such as TCP, UDP, GRE, etc. Instead of traditional packet‐based inspection,
5G networks could also leverage SDN control and data plane separation and perform
centralized network flow traffic monitoring for a deeper visibility and correlation of
traffic traversing inside the network.
Précédent

- 114/483

Suivant