Design Principles for 5G Security 83
services on the same hardware to reduce costs. However, decoupling the software and
hardware will require new security models for the whole system, since the platform‐
specific security will not suffice for a shared hardware platform. There will be a demand
for strong isolation mechanisms to secure each service running on the same hardware.
Virtualization enables multiple tenants or network users to share the same physical
network resources that can create security vulnerabilities. A literature study on security
implications of virtualization [9] shows that it has a positive effect on availability but
has threatening security challenges related to confidentiality, integrity, authenticity and
non‐repudiation. Virtual machines can be created, deleted and moved around a network
easily, hence tracking a malicious virtual machine would be much more complex.
Similarly, if a hypervisor is hijacked, the whole system can be compromised [10]. Another
major security challenge of NFV is to ensure trust among new elements such as hypervisors, virtual machines and management modules [54]. For instance, VNFs can store and
fetch executable code from any server anywhere in the world. Therefore, a trusted
mechanism is needed between the operator and cloud provider to ensure that the code
is safe and correct.
On the other hand, NFV can highly improve network and user security. For example,
secured network slicing can separate the communication of different parties, thus
alienating malicious traffic from the remainder. Similarly, distributed can be deployed to
resolve DoS and DDoS attacks, and with further intelligence, these VNFs can substantially improve self‐protection of 5G networks [14]. Network hypervisor, a program that
provides an abstraction layer for the network hardware, enables network engineers to
create virtual networks that are completely decoupled from the network hardware. In this
section, we outlined the importance of NFV and its security implications at a high level
to show its importance for future networks. More detailed analysis of the security threat
vectors and counter measures for VNFs and MVNOs is presented in Chapters 14 and 15.
4.3.2 Network Security Leveraging SDN
SDN separates the network control from the forwarding hardware and centralizes the
network control into software‐based controller platforms. The software‐based control
function will be centralized in high‐end servers. This will accelerate novelty in network
feature development, enhancement and rapid deployment. Therefore, the SDN‐based
wireless network has been a hot research topic and there are many proposals for SDN‐
based wireless networks [5]. The SDN architecture is vertically separated into three
functional layers with interfaces between the layers, as shown in Figure 4.3. OpenFlow
is the first viable implementation of SDN and also follows the three‐tier architecture of
SDN with OpenFlow applications, OpenFlow controller and OpenFlow switches.
The three logical planes are described as:
1) Application plane: consists of applications for various network functionalities such
as network management, QoS management and security services, etc.
2) Control plane: is the logically centralized network control platform running the
Network Operating System (NOS), having a global view of the network resources and
stats, and provides hardware abstractions to the applications in the application plane.
3) Infrastructure plane: also called the data plane that consists the data forwarding
elements that act on the instructions of the control plane for dealing with the data
packets or traffic flows.
Précédent

- 125/483

Suivant