Kabir, Kantola, and Llorente Santos
224
9.5.1 Use Case 1: Mobile Broadband
9.5.1.1 Deployment and Operations
A mobile operator decides on the adoption of Customer Edge Switching independent
of the others. Within the operator network, the deployment progresses one network
segment at a time. CES complements the Packet Data Gateway (PGW) in the mobile
core network.
The mobile operator has millions to hundreds of millions of subscribers, as well as
many supporting systems such as edge computing platforms and connections to con‑
tent providers. Therefore, the mobile operator may also deploy network‐based security
monitoring, security incident aggregation and trust processing for the end system secu‑
rity. Using these systems, a mobile operator defends all its subscribers from the rest of
the world based on a uniform, dynamic policy that makes use of all evidence collected
by its own and the subscriber‐owned devices. In addition, the mobile operator may have
contracts with security software vendors that will deploy regular security updates, and
may limit the policies applicable to the mobile devices. This gives the option of patching
vulnerable applications on a network level before a proper application software update
is available and has been deployed by the end users.
Initially, the policies for CES, RGW and host could be simple. Improved security is
achieved gradually, as more fine‐grained policies are deployed using the different
repositories for sourcing the policies and policy constraints. For the purpose of
improved heuristics, CES and RGW can treat differently the DNS servers that make
queries to the mobile operator DNS service. Servers that reveal the source of DNS
query, that is, via DNS extensions, and apply strict ingress filtering, can be preferred
compared to DNS servers that serve any query and any sender. For corporate custom‑
ers, the mobile operator can use the policies defined by the corporate admin in a suitable
policy database, fully administered by the corporation.
The mobile operator may allow its subscribers to define a policy for each of its users
within some constraints set into the mobile‐operator‐administered policy database.
The updates from the security software companies can also feed this database, with the
security perspective. A subscriber fundamentally selects its desired services (i.e.
subscription) from a set of operator offered packages, which can be translated into user
policies. The principle of allowing the user to modify policies is that a user can always
make its policy more restrictive as well as deploy new Apps that imply a certain
policy – template for such a policy should be given in the App license agreement. For
example, a user can employ a service “me and my gadgets”. It would allow limiting access
to the subscriber‐owned sensors or servers to a set of devices that can provide an
identity defined in the policy.
9.5.1.2 Security Benefits
Ultimately, each mobile device can have its own security policy that admits traffic only
to applications that are actually deployed on the device. If some device is running an
outdated software or application, and its network traffic can be identified by the
deployed CES release, all traffic to and from the application on the device can be
restricted. Such restriction can be based on the type of subscription the user has.
This possibility may be of particular interest to corporate customers who may want to
handle the policy management by themselves, possibly in cooperation with one or
224
9.5.1 Use Case 1: Mobile Broadband
9.5.1.1 Deployment and Operations
A mobile operator decides on the adoption of Customer Edge Switching independent
of the others. Within the operator network, the deployment progresses one network
segment at a time. CES complements the Packet Data Gateway (PGW) in the mobile
core network.
The mobile operator has millions to hundreds of millions of subscribers, as well as
many supporting systems such as edge computing platforms and connections to con‑
tent providers. Therefore, the mobile operator may also deploy network‐based security
monitoring, security incident aggregation and trust processing for the end system secu‑
rity. Using these systems, a mobile operator defends all its subscribers from the rest of
the world based on a uniform, dynamic policy that makes use of all evidence collected
by its own and the subscriber‐owned devices. In addition, the mobile operator may have
contracts with security software vendors that will deploy regular security updates, and
may limit the policies applicable to the mobile devices. This gives the option of patching
vulnerable applications on a network level before a proper application software update
is available and has been deployed by the end users.
Initially, the policies for CES, RGW and host could be simple. Improved security is
achieved gradually, as more fine‐grained policies are deployed using the different
repositories for sourcing the policies and policy constraints. For the purpose of
improved heuristics, CES and RGW can treat differently the DNS servers that make
queries to the mobile operator DNS service. Servers that reveal the source of DNS
query, that is, via DNS extensions, and apply strict ingress filtering, can be preferred
compared to DNS servers that serve any query and any sender. For corporate custom‑
ers, the mobile operator can use the policies defined by the corporate admin in a suitable
policy database, fully administered by the corporation.
The mobile operator may allow its subscribers to define a policy for each of its users
within some constraints set into the mobile‐operator‐administered policy database.
The updates from the security software companies can also feed this database, with the
security perspective. A subscriber fundamentally selects its desired services (i.e.
subscription) from a set of operator offered packages, which can be translated into user
policies. The principle of allowing the user to modify policies is that a user can always
make its policy more restrictive as well as deploy new Apps that imply a certain
policy – template for such a policy should be given in the App license agreement. For
example, a user can employ a service “me and my gadgets”. It would allow limiting access
to the subscriber‐owned sensors or servers to a set of devices that can provide an
identity defined in the policy.
9.5.1.2 Security Benefits
Ultimately, each mobile device can have its own security policy that admits traffic only
to applications that are actually deployed on the device. If some device is running an
outdated software or application, and its network traffic can be identified by the
deployed CES release, all traffic to and from the application on the device can be
restricted. Such restriction can be based on the type of subscription the user has.
This possibility may be of particular interest to corporate customers who may want to
handle the policy management by themselves, possibly in cooperation with one or
