Design Principles for 5G Security 79
techniques in such situations that can enable per‐user slice configuration to keep the
security policies and services intact whenever and wherever the user moves.
● DoS attacks on the Infrastructure: DoS and Distributed DoS (DDoS) attacks might circumvent the operation of devices controlling the critical infrastructure such as energy,
health, transportation, and telecommunications, causing life threatening consequences
with tremendous human and capital losses. DoS attacks are designed such that they
exhaust the physical and logical resources of the targeted devices. The challenge will be
more threatening due to the possibility of attacks from machines that are geographically dispersed in locations and in huge numbers. The network must be capable of
servicing the increasing number of connections caused by the increasing proliferation
of connected devices (e.g. IoT) with different operating capabilities and limitations.
4.2.3 Other Security Challenges
We can classify the security challenges on a high level into three domains, that is, security challenges in the access network, DoS Attacks, and security challenges in the core
network. Below we briefly describe each of them.
4.2.3.1 Security Challenges in the Access Network
Network access security provides secure access to the network and services with protection from vulnerabilities in the radio. For example, the user must be ensured security
from malicious network activities and the network must be secured from malicious
access. 5G will utilize a variety of access technologies and integrate different types of
access networks for extended coverage, higher throughput and lower latencies. To keep
the network working, 5G must improve the system robustness against jamming attacks
of the radio signals and channels. Furthermore, the security of small cell nodes must be
improved due to their geographical distribution and ease of access.
One of the key challenges in 5G will be the excessive nodes sending data and receiving
data simultaneously, practically jamming the radio interfaces. The challenge can be
exacerbated by malicious nodes sending excessive signaling traffic, causing availability
challenges or, in other words, leading to Denial of Service (DoS) attacks. Such signaling
traffic or attacks must be recognized early and stopped before the jamming the network.
3G and 4G provided cryptographic integrity protection of some signaling messages but
the user data plane was still not protected.
From 2G to 4G, the radio interface encryption keys are computed in the home core
network and are transmitted to the visited radio network over SS7 or Diameter signaling
links. These keys can be leaked, thus creating a clear point of exposure in the network [7].
Therefore, well designed key management protocols should be in place for 5G to reduce
the threats. The basic techniques include improving the SS7 and Diameter security by
introducing firewalls [7]. However, other approaches can be applied, such as using different secure control channels for distributing the keys. Some of these approaches are
described in Chapter 10. Security of the physical layer is described in Chapter 6.
4.2.3.2 DoS Attacks
DoS and DDoS attacks originating from large sets of connected devices will very likely
pose a real threat to 5G networks. These attacks can be either against the network infrastructure or the end user devices. Attacks against the infrastructure are designed to
techniques in such situations that can enable per‐user slice configuration to keep the
security policies and services intact whenever and wherever the user moves.
● DoS attacks on the Infrastructure: DoS and Distributed DoS (DDoS) attacks might circumvent the operation of devices controlling the critical infrastructure such as energy,
health, transportation, and telecommunications, causing life threatening consequences
with tremendous human and capital losses. DoS attacks are designed such that they
exhaust the physical and logical resources of the targeted devices. The challenge will be
more threatening due to the possibility of attacks from machines that are geographically dispersed in locations and in huge numbers. The network must be capable of
servicing the increasing number of connections caused by the increasing proliferation
of connected devices (e.g. IoT) with different operating capabilities and limitations.
4.2.3 Other Security Challenges
We can classify the security challenges on a high level into three domains, that is, security challenges in the access network, DoS Attacks, and security challenges in the core
network. Below we briefly describe each of them.
4.2.3.1 Security Challenges in the Access Network
Network access security provides secure access to the network and services with protection from vulnerabilities in the radio. For example, the user must be ensured security
from malicious network activities and the network must be secured from malicious
access. 5G will utilize a variety of access technologies and integrate different types of
access networks for extended coverage, higher throughput and lower latencies. To keep
the network working, 5G must improve the system robustness against jamming attacks
of the radio signals and channels. Furthermore, the security of small cell nodes must be
improved due to their geographical distribution and ease of access.
One of the key challenges in 5G will be the excessive nodes sending data and receiving
data simultaneously, practically jamming the radio interfaces. The challenge can be
exacerbated by malicious nodes sending excessive signaling traffic, causing availability
challenges or, in other words, leading to Denial of Service (DoS) attacks. Such signaling
traffic or attacks must be recognized early and stopped before the jamming the network.
3G and 4G provided cryptographic integrity protection of some signaling messages but
the user data plane was still not protected.
From 2G to 4G, the radio interface encryption keys are computed in the home core
network and are transmitted to the visited radio network over SS7 or Diameter signaling
links. These keys can be leaked, thus creating a clear point of exposure in the network [7].
Therefore, well designed key management protocols should be in place for 5G to reduce
the threats. The basic techniques include improving the SS7 and Diameter security by
introducing firewalls [7]. However, other approaches can be applied, such as using different secure control channels for distributing the keys. Some of these approaches are
described in Chapter 10. Security of the physical layer is described in Chapter 6.
4.2.3.2 DoS Attacks
DoS and DDoS attacks originating from large sets of connected devices will very likely
pose a real threat to 5G networks. These attacks can be either against the network infrastructure or the end user devices. Attacks against the infrastructure are designed to
