Kabir, Kantola, and Llorente Santos
202
9.2.2 Trust Domains and Trust Processing
The challenges of using trust and reputation concepts in mobile networks for improving
security include:
1) host generated evidence of misbehaviour cannot be trusted;
2) due to laws on communication privacy, ISPs cannot monitor the end‐user traffic
unless the whole network is under attack; and
3) corporations could be reluctant to share misbehaviour evidence, as it could damage
their business reputation and also reveal their weaknesses to even more attackers.
We have studied the ways to tackle the first challenge, for example in [8] and challenges
2 and 3 in [9].
Under the concepts of trust and reputation, to achieve a significantly higher level of
security in 5G (and in software‐defined sliced‐network connected systems) compared
to the state‐of‐the‐art in the end systems, we propose a new security principle
“all‑for‑one and one‐for‐all”. This principle suggests that the good guys join forces and
cooperate against the brotherhood of hackers. This can be implemented by deploying
elaborate methods of cooperation between networks and among end systems, for
processing of security attacks and incident information, mapping and automatically
containing the resources used for the attack as soon as detected.
This principle can be implemented by first introducing the concept of a trust domain.
A trust domain is a set of network entities and administrations that agree to share the
security incident information; follows some common rules in the area of security and
contains attacks with joint efforts. The security incident information is collected ubiq‑
uitously by all the end systems and network functions, aggregated in a secure manner
and validated by network‐based monitoring in the admitted traffic [8]. The results of
the aggregation are distributed to customer network gateways that act as cooperative
firewalls in the form of black lists, penalty lists, grey lists and white lists of the remote
(network) entities.
A trust domain can also be an operator’s network together with the end systems and
network entities serving a critical sector of economics. To improve defence against
Internet attacks, the larger is a trust domain, the better. Therefore, several administra‑
tions may decide to join and form multi‐administration trust domains based on a trust
alliance agreement. However, in state‐of‐the‐art, corporations do not prefer sharing of
the security incident information due to attached privacy concerns and fear of a bad repu‑
tation, which may damage the public image of the firm. Nevertheless, it is possible to set
up a trust domain by combining operations of most networks under one administration,
or one ISP, or by the use of regulation.
To encourage incident reporting within a trust domain, we propose the use of homo‑
morphic security [9] to encrypt the incident information from the customer end and
aggregating the evidence in an encrypted form at the serving eye‐ball ISP. The ISP will
anonymize the reports and send them to the cloud‐based global trust operator (GTO)
for final processing. The GTO will be able to decrypt the reports, because the end sys‑
tems use the GTO’s public key for encryption, but the GTO will see only the encrypted
identity of the reporting system. This allows keeping the customer‐to‐ISP relation a
business secret between the two parties. When GTO detects sufficient evidence of
Précédent

- 244/483

Suivant