Customer Edge Switching: A Security Framework for 5G 229
connection broker that exchanges and negotiates the policies/interests of the hosts or
applications, which it serves, with the remote hosts.
The adoption of CES offers multiple advantages over the state‐of‐the‐art in mobile
networks. For example, CES allows treating each user, host and application differently,
since the nature of communication can differ between host‐to‐host and application‐
to‑application. CES also supports several mechanisms to establish flow legitimacy, authen‑
ticate the sender, protect the network and its infrastructure against Internet attacks, and
provides these mechanisms as policy‐controlled features. This decision of applying a
particular security scheme is left to the network administrator, for example according to
the security conditions. In particular, the elimination of spoofing allows attributing the
misbehavior evidence back to the identity of the sender or its network, and lays the foun‑
dation for establishing the reputation of Internet entities, for example networks, particu‑
larly the ones that do not take corrective actions and hence keep forwarding the malicious
traffic. The aggregation of these evidences under a GTO can lead to generating white‐,
grey‐ and blacklists of sources and the CES firewall can accordingly admit, rate limit or
deny the traffic. The cooperative firewalling of CES can lead to filtering of malicious traf‑
fic close to the sender, upon receiving host misbehavior evidence from remote CES node
or information from GTO, and hence limit the extent of bandwidth‐saturation attacks on
(Gi/SGi interface of ) the mobile networks or the corporate networks.
The adoption of Software Defined Networks (SDN) facilitates deploying new services
in the network. Based on this, we have discussed the technology deployment in the
networks and proposed that CES function be integrated with PGW in 3GPP architec‑
ture. In combination with other network control nodes, that is, PCRF, HSS and P/S‐
GW, CES can enhance the traffic management and establish fine‐grained security to
safeguard the network against ills of the Internet: spoofing, botnets, network scans,
DNS floods and DDoS. We have also discussed the potential use cases of CES in mobile
broadband, corporate networks, national CERTs and Industrial Internet scenarios from
operation, security, scalability and reliability perspectives.
The evaluation of the security mechanisms reveals that CES can protect the networks
against classical Internet attacks at the cost of a negligible processing delay. CES can fur‑
ther harden its security offerings by leveraging a commercial firewall solution that uses
the best current practices for tackling Internet attacks. Unlike NATs, CES does not use
cumbersome NAT traversal protocols for admitting flows into the private network.
Instead it offers a solution that scales well to the battery‐powered mobile and wireless hosts.
Due to its support for a rich set of security mechanism that can trigger on both source
and destination addresses in a scalable manner, as well as many features of host behavior,
CES blends the boundary of closed and open networks effectively by executing security
at the network edge node. This can potentially relieve the Internet non‐default core
from supporting numerous Virtual Private Network routing tables that reside in the
high‐speed memory of the core BGP routers. Effectively, the necessary functionality is
executed at the edge nodes and the edge cloud. This can improve the scalability of the
non‐default core in the Internet.
CES adoption in networks does not require any changes in the existing hosts or
protocols and facilitates incremental (i.e. one‐step‐at‐a‐time) deployment of the tech‑
nology due to RGW functions. CES seeks to be mostly independent of the applications,
but where this is not possible, it continues to support the traditional methods of NAT
traversal.
Précédent

- 271/483

Suivant