Customer Edge Switching: A Security Framework for 5G 203
malicious activity, it will authorize the serving ISP to monitor the offending (remote)
system. Once the ISP, using network monitoring, observes conclusive evidence of
malicious activity, it will report back to the GTO that will blacklist the infected system.
This kind of multi‐stage detection of malicious activity is justified by several factors:
1) it does not solely rely on the end systems, since they cannot be trusted to report
accurately; and
2) ISPs cannot simply monitor human‐to‐human traffic at will, because of communica‑
tion privacy laws, unless the whole network or its customers are under attack.
Under the premise of a global GTO, the blacklists are distributed within the trust
domain to all cooperative firewalls and IPS. The cooperative firewall hosting the
infected system will put the device into a sandbox where it can do no harm to other
systems, and gets cleaned of viruses, Trojans and installs software upgrades to patch the
vulnerabilities.
Trust processing must be accurate, efficient and robust [8], such that the probability
of false positives is (nearly) zero. Efficiency means that malicious activity is detected
quickly, while robustness comes from the fact that it is resistant to system attacks that
try to submit false evidences. The way to achieve robustness is that trust processing at
both the ISP and GTO maintains the reporting credibility of the reporting entity. This
value gives a likelihood that the entity is reporting honestly and in a timely manner.
We studied the question of robustness, for example in [8].
The starting point for all the evidence collection is that a suspected entity must be
identified reliably. Evidence that does not point to a reliable identity is not actionable
and therefore not very useful. Since IP addresses can be spoofed and most end systems
either use a dynamic IP address or are NATted, an alternate and more reliable identity
is needed. In our proposed system, we make use of different types of end‐system identi‑
fiers, such as Fully Qualified Domain Names (FQDN) for end‐system identification. It
is a requirement that cooperative firewalls maintain reliable and traceable identification
of all the communicating entities.
9.3 CES Security Framework
CES is a proposed replacement of Network Address Translators (NAT) at the network
edges. NAT effectively hides the private network from the Internet, and connects the hosts
located in its network to the Internet via a translation of public and private IP addresses. By
default, NAT allows outbound connections to the Internet and creates a flow state to admit
the respective inbound flows in the private network. However, the Internet‐originated
inbound connections towards private hosts are typically dropped, due to absence of a prior
state in NAT for flow admission. As a consequence, inbound connections to private hosts
are accepted following the officially recommended NAT‐Traversal methods [10], which
are cumbersome and do not scale well to the battery‐powered mobile hosts.
In contrast, the deployment of CES separates the customer network from the public
Internet, such that CES:
1) acts as NAT for outbound connection to legacy Internet hosts; and
Précédent

- 245/483

Suivant