Customer Edge Switching: A Security Framework for 5G 199
interface, for example: address spoofing, traffic floods, unwanted traffic, viruses,
network scans, botnets and DoS, and their mitigations by the mobile network opera‑
tors. If these ills of today’s Internet are not properly addressed, network operators may
incur huge losses in terms of customer loyalty and trust, due to frequent end‐system
and network compromises and service disruptions. Network operators typically employ
Carrier Grade NAT (CGNAT), stateful firewalls, IPSec, intrusion detection system
(IDS) and Intrusion Prevention Systems (IPS) to mitigate these attacks [4].
For example, hackers may send TCP SYNs from spoofed source addresses as well as
from the botnets to one or more publicly reachable addresses of the network (or served
devices). Similarly, by sending spoofed DNS queries, hackers can use the responses
from DNS servers (or mobile infrastructure) to launch reflection and amplification
attacks. Besides hogging the capacity of Gi/SGi interface, a response from one of the
public addresses allows hacker to learn of an open port, and thus subject the corre‑
sponding service or connection state to attack. Networks typically mitigate these attacks
by employing an integrated stateful inspection firewall and IPS engine, which either
respond by rate‐limiting or resetting such connections. For all the attack traffic that
bypasses the network filters or firewalls, it consumes the network capacity, clogs up the
precious radio spectrum, and affects the battery consumption of the wireless device by
disturbing its sleep cycle. By keeping the radio spectrum in continuous use, the hacker
denies the use of network resources for legitimate users and needs.
In addition to bandwidth saturation attacks, hackers also subject the security infra‑
structure, for example Gi/SGi firewall and IPS to attacks. Firewall and IPS are stateful
inline devices and thus are inherently vulnerable to DDoS, which can overwhelm the
state capacity of these systems. Networks typically handle the bandwidth attacks by
enforcing bandwidth policing, which limits each class of traffic in the admitted band‑
width. This ensures that each traffic type gets required resources to ensure a minimal
level of quality of service (QoS) at all times. Moreover, some traffic types, such as IPSec,
can be prioritized over others, to ensure the promised QoS to customer networks.
Similar rate limits on the inbound traffic prevent DoS on the security systems, such as
Firewalls and IDS/IPS.
Besides exposure to Internet malpractices, mobile networks also face challenges from
connected mobile devices. In particular, hackers can compromise a weak device, a vul‑
nerable service on the end device, or may trick a careless user into becoming part of a
botnet. These infected devices are then used to launch attacks on other devices or the
mobile network itself. Mobile operators employ multi‐stage detection methods to filter
botnet traffic. This typically involves combining and triangulating the information from
searching attack signatures, the application context and limiting the connection rates.
In general, the mobile networks employ Carrier Grade NAT (CGNAT), Deep packet
Inspection (DPI), proxy agents, web‐content filtering, anti‐spam filters, and applica‑
tion‐specific filters to secure the network and their hosts against Internet attacks and
compromises.
Network Address Translation (NAT) and NAT traversal are of particular interest in
the state‐of‑the art. The communication from host in the private network to a public
host in Internet is trivially based on the NAT, which follows the pattern of communica‑
tion and establishes a NAT binding to admit the responses. In the opposite direction,
the traversal method recommended by IETF is based on self‐address fixing, that is, the
server behind a NAT (e.g. an App that can receive calls) learns the NAT outbound
Précédent

- 241/483

Suivant