Customer Edge Switching: A Security Framework for 5G 197
host can send packets to another Internet host, and often the interest of the receiver
differs from the interest of the sender by an amount called unwanted traffic. In addi‑
tion, CES overcomes the classical weaknesses of the Internet, namely source address
spoofing and DoS prior to admitting a flow.
b) CES (can also act) as a cooperative firewall, which in addition to attack detection
can also attribute the misbehaviour to the sender network and filter the malicious
(non‐cooperative) hosts and their activities due to the cooperation of networks. In
this context, CES is essentially an extension of the classical firewall functionality
into a cooperative firewall, such that in addition to the typical accept or drop deci‑
sion on a packet, CES can issue additional queries to the packet sender to eliminate
spoofing and assert identities prior to making a final decision. In particular, the
elimination of spoofing enables attributing the misbehaviour evidence back to the
identity of the sender, and lays the foundation for
c) sharing and aggregating evidences across the Internet, for example via an Internet‐
wide trust management system, that is, to limit the scope of attack strategies and to
better tackle the evolving Internet threats. However, we generally consider the latter
beyond the scope for this chapter.
The particular advantages of our approach are that it can be deployed one network at
a time; the costs of deployment are well aligned with the benefits and the system suits
the needs of mobile and wireless devices. The deployment of CES happens at network
edges, where it replaces NAT. The adoption of CES does not require any changes in the
end‐hosts, since CES limits all the changes to the edge network, thus minimizing
the deployment challenge. To fulfil the need for incremental deployment, CES supports
the Realm Gateway (RGW) function, which allows communication between the legacy
Internet and hosts in the private network, behind CES. In addition, it overcomes the
drawbacks of the classical NAT traversal solutions that do not scale well to the battery‐
powered mobile devices.
The rest of this chapter is structured as follows: Section 9.2 describes the state‐of‐the‐
art in mobile network security; Section 9.3 briefly describes the CES framework and
implemented security mechanisms; Section 9.4 presents an evaluation of the security
mechanisms; Section 9.5 considers the deployment aspects and presents different use
cases for CES deployment; and finally Section 9.6 concludes.
9.2 State‐of‐the‐art in Mobile Networks Security
Mobile networks are continuously evolving and are becoming platforms for various
services. The upgrade to 5G mobile networks and expected support for new technologi‑
cal evolutions, such as IoT and Industrial Internet, requires careful consideration of
mobile network security. This section discusses the state‐of‐the‐art in mobile network
security, and how it may evolve to support 5G and its requirements.
Figure 9.2 presents the state‐of‐the‐art in current mobile networks, which connect
via the Gi/SGi interface to external packet‐data networks, such as the public Internet or
other corporate networks. Clearly, the Gi/SGi interface of the mobile networks is
susceptible to attacks from the Internet and external packet data networks, such as
customer networks connected to the PGW (for LTE/4G networks) or GGSN (for 3G
networks). This section presents some of the most common threats to the Gi/SGi
host can send packets to another Internet host, and often the interest of the receiver
differs from the interest of the sender by an amount called unwanted traffic. In addi‑
tion, CES overcomes the classical weaknesses of the Internet, namely source address
spoofing and DoS prior to admitting a flow.
b) CES (can also act) as a cooperative firewall, which in addition to attack detection
can also attribute the misbehaviour to the sender network and filter the malicious
(non‐cooperative) hosts and their activities due to the cooperation of networks. In
this context, CES is essentially an extension of the classical firewall functionality
into a cooperative firewall, such that in addition to the typical accept or drop deci‑
sion on a packet, CES can issue additional queries to the packet sender to eliminate
spoofing and assert identities prior to making a final decision. In particular, the
elimination of spoofing enables attributing the misbehaviour evidence back to the
identity of the sender, and lays the foundation for
c) sharing and aggregating evidences across the Internet, for example via an Internet‐
wide trust management system, that is, to limit the scope of attack strategies and to
better tackle the evolving Internet threats. However, we generally consider the latter
beyond the scope for this chapter.
The particular advantages of our approach are that it can be deployed one network at
a time; the costs of deployment are well aligned with the benefits and the system suits
the needs of mobile and wireless devices. The deployment of CES happens at network
edges, where it replaces NAT. The adoption of CES does not require any changes in the
end‐hosts, since CES limits all the changes to the edge network, thus minimizing
the deployment challenge. To fulfil the need for incremental deployment, CES supports
the Realm Gateway (RGW) function, which allows communication between the legacy
Internet and hosts in the private network, behind CES. In addition, it overcomes the
drawbacks of the classical NAT traversal solutions that do not scale well to the battery‐
powered mobile devices.
The rest of this chapter is structured as follows: Section 9.2 describes the state‐of‐the‐
art in mobile network security; Section 9.3 briefly describes the CES framework and
implemented security mechanisms; Section 9.4 presents an evaluation of the security
mechanisms; Section 9.5 considers the deployment aspects and presents different use
cases for CES deployment; and finally Section 9.6 concludes.
9.2 State‐of‐the‐art in Mobile Networks Security
Mobile networks are continuously evolving and are becoming platforms for various
services. The upgrade to 5G mobile networks and expected support for new technologi‑
cal evolutions, such as IoT and Industrial Internet, requires careful consideration of
mobile network security. This section discusses the state‐of‐the‐art in mobile network
security, and how it may evolve to support 5G and its requirements.
Figure 9.2 presents the state‐of‐the‐art in current mobile networks, which connect
via the Gi/SGi interface to external packet‐data networks, such as the public Internet or
other corporate networks. Clearly, the Gi/SGi interface of the mobile networks is
susceptible to attacks from the Internet and external packet data networks, such as
customer networks connected to the PGW (for LTE/4G networks) or GGSN (for 3G
networks). This section presents some of the most common threats to the Gi/SGi
