Kabir, Kantola, and Llorente Santos
200
address assigned by the NAT by exchanging messages with a server in the Internet and
keeps that binding alive by keep‐alive signalling. Once the address is learned, it is passed
to the remote end on the application layer. The initial learning requires several tens of
messages, easily consuming tens of seconds and the learning algorithm needs to be
repeated from time to time. The approach makes NAT traversal an Application level
issue, which, in addition to consuming the device battery, deteriorates the architecture.
To summarize, the current state‐of‐the‐art in mobile networks and end‐system
security mostly follows the reactive approach. The prevalent culture in security is
such that Internet entities (i.e. networks or hosts) are responsible for their own secu‑
rity. However, in protecting the air interface against bandwidth saturation, mobile
networks to a certain extent also filter the attacks directed to the end systems. To that
end, mobile networks are more advanced than fixed broadband networks, which
generally leave the end‐user host exposed to the Internet. For end systems, some
security vendors are already today leveraging the tools of sharing vulnerability and
exposure information. Using the shared information, each vendor can update the
counter‐measures in its security solution; leaving it up to the users of the software to
install the security updates. According to a security specialist [5], the majority of the
security breaches in end systems are due to known vulnerabilities in the software
that is not updated in time.
9.2.1 Mobile Network Challenges and Principles of Security Framework
Besides the need to better handle the classical Internet threats, the future mobile
networks also have to tackle the challenges from introduction of new technologies,
such as Software Defined Networking (SDN) and Network Function Virtualization
(NFV), which are critical to the realization of 5G. For example, the adoption of SDN
enables pursuing a split of control and data plane in the mobile networks, such that
the network intelligence is gathered into a set of control nodes that actively monitor
traffic, generate flow rules, and due to global visibility of the network can diagnose
threats and mitigate the security challenges. The data plane consists of basic
forwarding nodes that enforce the rules generated by the controller. While SDN brings
the desired level of flexibility, it also presents the controller as a single point of
failure for mobile networks if the Internet‐borne attacks are not mitigated. The paper
in [6] identifies some of the challenges raised by the separation of planes and aggregation
of the control functionality into centralized nodes. We argue that in a broad context,
5G security can be categorized into: i) access‐network security; ii) virtualized‐ core
security; and iii) end‐system security. The CES framework is concerned with the end‐
system security and mitigation of the Internet‐borne threats on (Gi/SGi interface of
the) mobile networks.
Clearly, the existing and emerging Internet threats assert that mobile networks do
better than the state‐of‐the‐art to tackle the security challenges. In this context, we
present some of the learnings from Internet security and ambitions for 5G in terms of
security principles, and argue that future mobile networks shall:
● limit the flow acceptance to verifiable sources, to tackle the problem of source address
spoofing and traffic floods, and hence prevent the resource exhaustion;
200
address assigned by the NAT by exchanging messages with a server in the Internet and
keeps that binding alive by keep‐alive signalling. Once the address is learned, it is passed
to the remote end on the application layer. The initial learning requires several tens of
messages, easily consuming tens of seconds and the learning algorithm needs to be
repeated from time to time. The approach makes NAT traversal an Application level
issue, which, in addition to consuming the device battery, deteriorates the architecture.
To summarize, the current state‐of‐the‐art in mobile networks and end‐system
security mostly follows the reactive approach. The prevalent culture in security is
such that Internet entities (i.e. networks or hosts) are responsible for their own secu‑
rity. However, in protecting the air interface against bandwidth saturation, mobile
networks to a certain extent also filter the attacks directed to the end systems. To that
end, mobile networks are more advanced than fixed broadband networks, which
generally leave the end‐user host exposed to the Internet. For end systems, some
security vendors are already today leveraging the tools of sharing vulnerability and
exposure information. Using the shared information, each vendor can update the
counter‐measures in its security solution; leaving it up to the users of the software to
install the security updates. According to a security specialist [5], the majority of the
security breaches in end systems are due to known vulnerabilities in the software
that is not updated in time.
9.2.1 Mobile Network Challenges and Principles of Security Framework
Besides the need to better handle the classical Internet threats, the future mobile
networks also have to tackle the challenges from introduction of new technologies,
such as Software Defined Networking (SDN) and Network Function Virtualization
(NFV), which are critical to the realization of 5G. For example, the adoption of SDN
enables pursuing a split of control and data plane in the mobile networks, such that
the network intelligence is gathered into a set of control nodes that actively monitor
traffic, generate flow rules, and due to global visibility of the network can diagnose
threats and mitigate the security challenges. The data plane consists of basic
forwarding nodes that enforce the rules generated by the controller. While SDN brings
the desired level of flexibility, it also presents the controller as a single point of
failure for mobile networks if the Internet‐borne attacks are not mitigated. The paper
in [6] identifies some of the challenges raised by the separation of planes and aggregation
of the control functionality into centralized nodes. We argue that in a broad context,
5G security can be categorized into: i) access‐network security; ii) virtualized‐ core
security; and iii) end‐system security. The CES framework is concerned with the end‐
system security and mitigation of the Internet‐borne threats on (Gi/SGi interface of
the) mobile networks.
Clearly, the existing and emerging Internet threats assert that mobile networks do
better than the state‐of‐the‐art to tackle the security challenges. In this context, we
present some of the learnings from Internet security and ambitions for 5G in terms of
security principles, and argue that future mobile networks shall:
● limit the flow acceptance to verifiable sources, to tackle the problem of source address
spoofing and traffic floods, and hence prevent the resource exhaustion;
