Customer Edge Switching: A Security Framework for 5G 201
● eliminate source address spoofing, to establish grounds for attributing misbehavior
evidence to the identity of the sender or the network serving it;
● make it possible to aggregate misbehavior evidences under a stable source identity:
– Such aggregation can contribute towards building and employing the reputation of
the Internet sources/networks, and demote the networks that do not take corrective
actions and hence keep forwarding the malicious traffic;
– The aggregation of misbehavior evidences can also present an overview of the
developing threats, and thus contribute to better preparedness against attacks, by
generating indicators for trusted network monitoring.
● under network stress, grant resources based on the source reputation;
● meet the interests of the sender with the interests of the receiver, to tackle the prob‑
lem of unwanted traffic;
● allow defining dynamic (reachability) policies for hosts, applications and services. The
management and control of the policies could be in the cloud while enforcement
takes place in standard data‐plane nodes, as well as control nodes on trust boundaries.
This is in contrast to the current mobile networks where policies are tightly coupled to
the physical resources and are not scalable to services/applications;
● deploy a security solution that does not require changes in the end‑hosts or protocols,
and limits all the changes to edge nodes, to minimize the adoption cost.
In addition, the mobile networks can leverage the current state‐of‐the‐art and future
adoptions of technology to strengthen their security. For example, the future mobile
networks shall:
● leverage the mechanisms in state‐of‐the‐art security to harden defence against known
attacks, in particular, to protect the controller from the Internet‐borne attacks;
● present a multi‐tier approach to end‐system security, where at least the mass‐attacks
are handled by a user’s agent in the network, such as a cooperative firewall; while the
application‐level security can either stay in the end devices or can be also delegated to
a set of cloud‐based security entities, such as Web Application Firewalls or virus
detection environments;
● analyse and manage the policy configuration of the data‐plane elements, to deploy
a robust and uniform security policy across the network. The logically centralized
controller can provide a global view of different network device configurations and
hence mitigate the conflicts and inconsistencies in the network security procedures.
In summary, these principles address the classical Internet weaknesses, such as spoof‑
ing, unwanted traffic, malicious flows and DoS. The ability to attribute misbehaviour in
particular allows identifying the malicious sources and contributes to filtering the mali‑
cious traffic close to the sender, due to the cooperation of networks. Such cooperation
of networks is possible due to aggregation of the misbehaviour attributed to a source,
under a trusted entity such as a trust management system, and reflecting the corre‑
sponding sender reputation in the network admission decisions. We argue that the goal
shall be to locate the malicious sources and early filtering of attacks, thus making
defection or hacking a less favourable/practiced strategy in the Internet [7]. This is
unlike the traditional security, which only drops the malicious traffic after it has reached
the destination or its network.
● eliminate source address spoofing, to establish grounds for attributing misbehavior
evidence to the identity of the sender or the network serving it;
● make it possible to aggregate misbehavior evidences under a stable source identity:
– Such aggregation can contribute towards building and employing the reputation of
the Internet sources/networks, and demote the networks that do not take corrective
actions and hence keep forwarding the malicious traffic;
– The aggregation of misbehavior evidences can also present an overview of the
developing threats, and thus contribute to better preparedness against attacks, by
generating indicators for trusted network monitoring.
● under network stress, grant resources based on the source reputation;
● meet the interests of the sender with the interests of the receiver, to tackle the prob‑
lem of unwanted traffic;
● allow defining dynamic (reachability) policies for hosts, applications and services. The
management and control of the policies could be in the cloud while enforcement
takes place in standard data‐plane nodes, as well as control nodes on trust boundaries.
This is in contrast to the current mobile networks where policies are tightly coupled to
the physical resources and are not scalable to services/applications;
● deploy a security solution that does not require changes in the end‑hosts or protocols,
and limits all the changes to edge nodes, to minimize the adoption cost.
In addition, the mobile networks can leverage the current state‐of‐the‐art and future
adoptions of technology to strengthen their security. For example, the future mobile
networks shall:
● leverage the mechanisms in state‐of‐the‐art security to harden defence against known
attacks, in particular, to protect the controller from the Internet‐borne attacks;
● present a multi‐tier approach to end‐system security, where at least the mass‐attacks
are handled by a user’s agent in the network, such as a cooperative firewall; while the
application‐level security can either stay in the end devices or can be also delegated to
a set of cloud‐based security entities, such as Web Application Firewalls or virus
detection environments;
● analyse and manage the policy configuration of the data‐plane elements, to deploy
a robust and uniform security policy across the network. The logically centralized
controller can provide a global view of different network device configurations and
hence mitigate the conflicts and inconsistencies in the network security procedures.
In summary, these principles address the classical Internet weaknesses, such as spoof‑
ing, unwanted traffic, malicious flows and DoS. The ability to attribute misbehaviour in
particular allows identifying the malicious sources and contributes to filtering the mali‑
cious traffic close to the sender, due to the cooperation of networks. Such cooperation
of networks is possible due to aggregation of the misbehaviour attributed to a source,
under a trusted entity such as a trust management system, and reflecting the corre‑
sponding sender reputation in the network admission decisions. We argue that the goal
shall be to locate the malicious sources and early filtering of attacks, thus making
defection or hacking a less favourable/practiced strategy in the Internet [7]. This is
unlike the traditional security, which only drops the malicious traffic after it has reached
the destination or its network.
