Design Principles for 5G Security 91
Gateways (SecGWs) to secure the controller and IPsec Encapsulating Security Payload
(ESP) Bounded‐End‐to‐End‐Tunnel (BEET) mode tunnels to secure the control and
data channels communication. Moreover, the Identity‐Based Cryptography (IBC)
protocol‐based security mechanism is also proposed to secure the inter‐controller and
control channel traffic in a general multi‐controller SDN networks [58].
4.4.3 Traffic Monitoring
Traffic monitoring can be used to detect intrusions and prevent them. Intrusion
Detection Systems (IDS) and Intrusion Prevention Systems (IPS) observe network traffic according to different security policies, find vulnerabilities, threats and attacks, and
use countermeasures to secure the network. In traditional networks, the control planes
of network elements are loosely coupled with limited communication between their
control planes. Hence, IDS and IPS technologies in each network domain are independently configured to deal with the challenges in its domain. This makes the current
systems hard to update with newly identified types of attacks and threat vectors. SDN
takes a different path by enabling applications to retrieve switch statistics or extract
samples of packets from flows for security analysis. After security analysis, the applications can direct the controller to either drop the packets or forward them to security
systems or middle boxes for further investigation. Therefore, SDN makes traffic monitoring rather simple by enabling global visibility of the network traffic behavior and
network programmability.
4.4.4 Access Control
Traditional access control mechanisms use firewalls deployed on network boundaries to
examine the incoming or outgoing packets to prevent attacks and unauthorized access.
Therefore, insiders are considered as trusted partners. This can lead to serious security
breaches, since in‐zone users could launch attacks or circumvent the security mechanisms. Furthermore, the changes in network policies and traffic conditions require complex configuration of the firewalls, that make it further complex to keep the security in
place. SDN enables automation through programmability and centralizes the network
control that achieves global visibility of the network traffic behavior. Thus, traffic coming
from the outside and traffic originated inside the network can be easily monitored. For
example, the network ingress ports in OpenFlow switches can be dynamically configured
from the controller to forward packets to a firewall in a separate middle box or an SDN
firewall application. Similarly, traffic originating within the network can also be easily
checked by updating the flow tables of the switch, in the same way as traffic coming from
outside of the network. A number of firewall applications are already developed for
SDNs, such as FLOWGUARD [24] and OpenFlow firewall [25].
4.4.5 Network Resilience
Network resilience mechanisms help the network to operate in the presence of
diverse challenges, such as cyber‐attacks, wrong configurations, operational overload, or equipment failures. The network must be capable to provide services to
users when such challenges occur. Basic resilience strategies include Defend, Detect,
Gateways (SecGWs) to secure the controller and IPsec Encapsulating Security Payload
(ESP) Bounded‐End‐to‐End‐Tunnel (BEET) mode tunnels to secure the control and
data channels communication. Moreover, the Identity‐Based Cryptography (IBC)
protocol‐based security mechanism is also proposed to secure the inter‐controller and
control channel traffic in a general multi‐controller SDN networks [58].
4.4.3 Traffic Monitoring
Traffic monitoring can be used to detect intrusions and prevent them. Intrusion
Detection Systems (IDS) and Intrusion Prevention Systems (IPS) observe network traffic according to different security policies, find vulnerabilities, threats and attacks, and
use countermeasures to secure the network. In traditional networks, the control planes
of network elements are loosely coupled with limited communication between their
control planes. Hence, IDS and IPS technologies in each network domain are independently configured to deal with the challenges in its domain. This makes the current
systems hard to update with newly identified types of attacks and threat vectors. SDN
takes a different path by enabling applications to retrieve switch statistics or extract
samples of packets from flows for security analysis. After security analysis, the applications can direct the controller to either drop the packets or forward them to security
systems or middle boxes for further investigation. Therefore, SDN makes traffic monitoring rather simple by enabling global visibility of the network traffic behavior and
network programmability.
4.4.4 Access Control
Traditional access control mechanisms use firewalls deployed on network boundaries to
examine the incoming or outgoing packets to prevent attacks and unauthorized access.
Therefore, insiders are considered as trusted partners. This can lead to serious security
breaches, since in‐zone users could launch attacks or circumvent the security mechanisms. Furthermore, the changes in network policies and traffic conditions require complex configuration of the firewalls, that make it further complex to keep the security in
place. SDN enables automation through programmability and centralizes the network
control that achieves global visibility of the network traffic behavior. Thus, traffic coming
from the outside and traffic originated inside the network can be easily monitored. For
example, the network ingress ports in OpenFlow switches can be dynamically configured
from the controller to forward packets to a firewall in a separate middle box or an SDN
firewall application. Similarly, traffic originating within the network can also be easily
checked by updating the flow tables of the switch, in the same way as traffic coming from
outside of the network. A number of firewall applications are already developed for
SDNs, such as FLOWGUARD [24] and OpenFlow firewall [25].
4.4.5 Network Resilience
Network resilience mechanisms help the network to operate in the presence of
diverse challenges, such as cyber‐attacks, wrong configurations, operational overload, or equipment failures. The network must be capable to provide services to
users when such challenges occur. Basic resilience strategies include Defend, Detect,
