Customer Edge Switching: A Security Framework for 5G 221
presents the effectiveness of Bot‐detection method. The figure shows that Bot‐detection
is more reactive to high‐rate SYN floods and filters them earlier, as they quickly meet the
detection threshold. Bot‐detection constantly tracks the packets that are dropped for not
meeting any connection state, and once a sender exceeds a threshold, it is blacklisted
following a non‐spoofing test. As a result, subsequent packets from the hacker fail to
claim any state allocations in RGW and ration of legitimate connection rises. A more
detailed analysis of the Bot‐detection method and different influencing parameters for
RGW security is presented in [21].
To gain a more realistic view of security, hackers can be divided into: i) probing or scan‑
ning hackers; and ii) advanced hackers. A probing hacker scans the entire CPPA address
space and port range to discover the available services, IP addresses, ports or NAT map‑
pings. It is likely that such an attacker, due to its limited knowledge of the victim and thus
random network scanning, will fail to pose risk at RGW for SFQDN based traffic, as
shown in Test‐4 of Figure 9.9. In comparison, an advanced hacker may already know ser‑
vices/ports to target, via knowledge sharing among hackers or using botnets that perform
the service discovery. As a result, the hacker can target the SYN floods to the specific ports.
Clearly, the results show that RGW attains best‐case security against regular network
scans for SFQDN admitted traffic, where the hacker is not advanced and simply scans
the network for available services or IPs. Under the premise that the hacker targets the
served ports, it is possible that SFQDN naming is changed to new service ports. This
will force the attacker to restart its service/port discovery cycle and allow RGW to
regain its best case security. Such use of SFQDN is possible in cases where a single
administration owns or manages both the remote hosts and the RGW. For example, in
Internet of Things (IoT), both the communicating nodes and gateway can fall under a
single administration. In the absence of such a scheme, Figure 9.12 shows the security
of SFQDN admitted traffic against an advanced hacker.
100%
90%
80%
70%
60%
50%
40%
Hijacked connections
Successful connections
30%
20%
10%
0%
Connection percentage (%)
1
3
5
7
1
3
5
7
Size of Circular pool address space
Advanced hacker targetting SFQDN allocations, before and after security
(a)
(b)
Figure 9.12 Security of SFQDN allocations against advanced hackers: (a) without; and (b) with
RGW security.
presents the effectiveness of Bot‐detection method. The figure shows that Bot‐detection
is more reactive to high‐rate SYN floods and filters them earlier, as they quickly meet the
detection threshold. Bot‐detection constantly tracks the packets that are dropped for not
meeting any connection state, and once a sender exceeds a threshold, it is blacklisted
following a non‐spoofing test. As a result, subsequent packets from the hacker fail to
claim any state allocations in RGW and ration of legitimate connection rises. A more
detailed analysis of the Bot‐detection method and different influencing parameters for
RGW security is presented in [21].
To gain a more realistic view of security, hackers can be divided into: i) probing or scan‑
ning hackers; and ii) advanced hackers. A probing hacker scans the entire CPPA address
space and port range to discover the available services, IP addresses, ports or NAT map‑
pings. It is likely that such an attacker, due to its limited knowledge of the victim and thus
random network scanning, will fail to pose risk at RGW for SFQDN based traffic, as
shown in Test‐4 of Figure 9.9. In comparison, an advanced hacker may already know ser‑
vices/ports to target, via knowledge sharing among hackers or using botnets that perform
the service discovery. As a result, the hacker can target the SYN floods to the specific ports.
Clearly, the results show that RGW attains best‐case security against regular network
scans for SFQDN admitted traffic, where the hacker is not advanced and simply scans
the network for available services or IPs. Under the premise that the hacker targets the
served ports, it is possible that SFQDN naming is changed to new service ports. This
will force the attacker to restart its service/port discovery cycle and allow RGW to
regain its best case security. Such use of SFQDN is possible in cases where a single
administration owns or manages both the remote hosts and the RGW. For example, in
Internet of Things (IoT), both the communicating nodes and gateway can fall under a
single administration. In the absence of such a scheme, Figure 9.12 shows the security
of SFQDN admitted traffic against an advanced hacker.
100%
90%
80%
70%
60%
50%
40%
Hijacked connections
Successful connections
30%
20%
10%
0%
Connection percentage (%)
1
3
5
7
1
3
5
7
Size of Circular pool address space
Advanced hacker targetting SFQDN allocations, before and after security
(a)
(b)
Figure 9.12 Security of SFQDN allocations against advanced hackers: (a) without; and (b) with
RGW security.
