Design Principles for 5G Security 93
However, automation has been used in a limited variety of networks even though
human errors cause many network security and traffic management problems [35]. In
today’s multi‐vendor networks, 62% of network downtime comes from human errors
and 80% of corporations’ IT budget is spent on maintenance and operations [36]. Stable
and robust security policy deployment requires global analysis of policy configuration
of all the networked elements to avoid conflicts and inconsistency in the security
procedures and to diminish the chances of serious security breaches and network vulnerabilities [33]. As a security concern, a small oversight can lead to a global security
problem such as placing a significant functionality on an unreliable system [34].
Therefore, automation of network and user security is highly important to avoid these
challenges.
However, there are many challenges that make it difficult to automate and deploy
automated security systems in today’s communication networks. For example, most of
the network systems used today are hardwired with specific control logic that require
manual configuration of individual boxes. Such independent control systems in
communication networks make it difficult to deploy consistent network‐wide security
policies throughout large networks that comprise a mix and match of control systems
for different functionalities. Therefore, there are many proposals for the redesign of the
communication systems and architectures.
Network security is an important and integral part of the network management that
must be considered from planning to the deployment and use of the network [32].
Similarly, consistent policies over the network are highly important to avoid policy
collusion that lead to security lapses. Among the proposals for such networks, SDN
enables consistent network‐wide policies through global visibility of the overall network systems and the policies implemented in each. By enabling programmability,
and abstracting away the low‐level configurations from individual boxes, SDN provides designing languages and network controllers that are capable of automatically
reacting to the changing network state [38,39]. By abolishing the need of individual
node configuration, taking the intelligence out of the networking components used to
forward data and abstracting the control from the networking nodes, SDN paves the
way for network security automation [40]. SDN enhances the automation of many
processes and pro cedures, including physical and virtual network management and
reconfiguration, and introduces the possibility of deploying new automated services.
As a result, there are already several proposals for network automation using the concepts of SDN.
Procera [41] is a network control framework for operators, which implements flexible
policies based on the network view. Procera maps high‐level event driven policies to
low‐level network configuration driven policies, thus abolishing the need for manual
configurations. The OpenFlow Management Infrastructure (OMNI) [42] simplifies
OpenFlow management and provides mechanisms for a responsive autonomic control
platform. Among the set of tools provided by OMNI, a web interface for the tools and a
multi‐agent system to autonomously control the network, OMNI tools for collecting
statistics of flows and another that probes the network to obtain the physical topology,
can be used for synchronizing the network traffic with the network security policies.
The flows can be migrated to different physical paths according to the QoS and security
requirement and without packet loss or security compromises. Using new technologies
such as mentioned above, security systems can be automated in 5G.
Précédent

- 135/483

Suivant