Kabir, Kantola, and Llorente Santos
196
connecting to the Internet. For example, the advent of Industrial Internet (II) and Internet
of Things (IoT) would connect many previously unconnected devices as well as com‑
pletely new ones to the Internet, increasing the attack surface. The ubiquitous reliance of
users on smart mobile devices and in particular 5G, makes end devices more lucrative for
hackers. Very often these end systems run poorly developed software and have unpatched
vulnerabilities that put the system and its network at risk [3]. As a result, networks suffer
from persistent hacking attempts to the end systems, service compromises, fraud, theft
of information and DoS. Mobile networks already today rate availability as their top
concern [4]. The evolved threat landscape of 5G will further stress this concern, and
challenge the thriving potential of new services that would rely on 5G for ubiquitous
connectivity. For example, 5G aims to support massive machine‐to‐machine communi‑
cations and ultra‐high reliability, such as in life‐critical automotive applications. There is
a concern that 5G will put more value (e.g. human life) at stake, and that hackers can
compromise more value than before, if efforts to better security are not made.
Besides the evolution of a threat landscape, the Internet has yet to address challenges
from some of the classical Internet weaknesses, such as address spoofing, unwanted traffic,
network scans, traffic floods and DoS. We recognize that much of the traditional Internet
weaknesses are the result of any‐to‐any communication paradigm in the Internet, which
allows any host in the Internet to send flows to another Internet host. Hackers often abuse
this paradigm to target their victims, and leverage poor identification of hosts, possibility
of spoofing and the lack of authentication mechanisms in the Internet to their advantage,
and as a result invalidate the network auditing. Consequently, the volume of malicious
activities, such as network scans, DoS and unwanted traffic is on the rise [3], which often
result in network outages, computing downtime and waste of resources. Often the hackers
use these classical Internet weaknesses as a launch pad for more advanced attacks.
From the security perspective, it is pertinent that 5G addresses the challenges from
the classical Internet weaknesses, as well as deploys mechanisms for better tackling the
evolving threat landscape. In particular, 5G must ensure better than state‐of‐the‐art
security to achieve its goals of provisioning the ubiquitous access and ultra‐reliable
services. 5G security can be broadly categorized into three categories:
1) Access security (subscriber‐operator relation);
2) SDN‐style virtualized‐core security (function‐to‐function relation); and
3) End‐system security.
This chapter in particular is concerned with the latter, using various network‐based
methods. The chapter introduces a security framework called Customer Edge Switching
(CES) (Figure 9.1), to address the challenges from the classical Internet weaknesses and
to contribute towards better handling of the emerging threat landscape. It promotes:
a) policy‐based communication, whereby the interests of the receiver are met with the
interests of the sender. This is unlike the traditional best‐effort Internet, where any
Customer
Network
Customer
Network
CES/Firewall
CES/Firewall
Internet
Figure 9.1 Customer Edge Switching.
196
connecting to the Internet. For example, the advent of Industrial Internet (II) and Internet
of Things (IoT) would connect many previously unconnected devices as well as com‑
pletely new ones to the Internet, increasing the attack surface. The ubiquitous reliance of
users on smart mobile devices and in particular 5G, makes end devices more lucrative for
hackers. Very often these end systems run poorly developed software and have unpatched
vulnerabilities that put the system and its network at risk [3]. As a result, networks suffer
from persistent hacking attempts to the end systems, service compromises, fraud, theft
of information and DoS. Mobile networks already today rate availability as their top
concern [4]. The evolved threat landscape of 5G will further stress this concern, and
challenge the thriving potential of new services that would rely on 5G for ubiquitous
connectivity. For example, 5G aims to support massive machine‐to‐machine communi‑
cations and ultra‐high reliability, such as in life‐critical automotive applications. There is
a concern that 5G will put more value (e.g. human life) at stake, and that hackers can
compromise more value than before, if efforts to better security are not made.
Besides the evolution of a threat landscape, the Internet has yet to address challenges
from some of the classical Internet weaknesses, such as address spoofing, unwanted traffic,
network scans, traffic floods and DoS. We recognize that much of the traditional Internet
weaknesses are the result of any‐to‐any communication paradigm in the Internet, which
allows any host in the Internet to send flows to another Internet host. Hackers often abuse
this paradigm to target their victims, and leverage poor identification of hosts, possibility
of spoofing and the lack of authentication mechanisms in the Internet to their advantage,
and as a result invalidate the network auditing. Consequently, the volume of malicious
activities, such as network scans, DoS and unwanted traffic is on the rise [3], which often
result in network outages, computing downtime and waste of resources. Often the hackers
use these classical Internet weaknesses as a launch pad for more advanced attacks.
From the security perspective, it is pertinent that 5G addresses the challenges from
the classical Internet weaknesses, as well as deploys mechanisms for better tackling the
evolving threat landscape. In particular, 5G must ensure better than state‐of‐the‐art
security to achieve its goals of provisioning the ubiquitous access and ultra‐reliable
services. 5G security can be broadly categorized into three categories:
1) Access security (subscriber‐operator relation);
2) SDN‐style virtualized‐core security (function‐to‐function relation); and
3) End‐system security.
This chapter in particular is concerned with the latter, using various network‐based
methods. The chapter introduces a security framework called Customer Edge Switching
(CES) (Figure 9.1), to address the challenges from the classical Internet weaknesses and
to contribute towards better handling of the emerging threat landscape. It promotes:
a) policy‐based communication, whereby the interests of the receiver are met with the
interests of the sender. This is unlike the traditional best‐effort Internet, where any
Customer
Network
Customer
Network
CES/Firewall
CES/Firewall
Internet
Figure 9.1 Customer Edge Switching.
