Liyanage, Ahmad, Okwuibe, Montes de Oca, MAI, Perez, and Itzazelaia
232
programing multiple network equipment at run time. The SDN control plane has global
visibility and finer control over the packets traversing the network. Since the network is
controlled from centralized controllers and the network components have programmable interfaces, network monitoring is augmented to a higher level in terms of efficiency, cost and complexity. NFV is ETSI standardized architecture that separates
network functionality from the hardware. NFV means that network functions will be
running as a service in commercial off‐the‐shelf hardware.
On the one hand, the limitations of legacy monitoring systems to secure wireless
networks can be overcome by introducing novel monitoring architecture based on
SDN and NFV. On the other hand, the use of SDN and NFV bring new challenges
to network trouble shooting and monitoring. This chapter investigates the challenges introduced by SDN and NFV in 5G networks and how the 5G operators need to
tackle them by using efficient network monitoring solutions. Moreover, we highlight
new opportunities that will help achieve efficient SDN‐ and NFV‐based 5G network
monitoring.
10.2 Existing Monitoring Techniques
Several network monitoring techniques with different levels of capabilities exist in
today’s network management space [2]. First, we have router based monitoring protocols which allow gathering information supplied by NEs (Network Elements):
● Simple Network Monitoring Protocol (SNMP): for the management of NEs and high‐
level information on resource use (e.g. monitor bandwidth usage of routers and
switches port‐by‐port, device information like memory use, CPU load, etc.);
● Remote Monitoring (RMON): for the exchange of network monitoring data; and,
● Netflow or sFlow: for collecting information on IP network flows and bandwidth usage.
These protocols are mostly dedicated for performance analysis and network management, but they have also been used for detecting some security problems, for
instance NetFlow. Current networks are also using packet sniffing, DPI (Deep Packet
Inspection), DFI (Deep Flow Inspection), virus scanners, malware detectors and other
techniques for analysing network packet headers, complete packets or packet payloads.
They are used by NIDS (Network Intrusion Detection Systems), IDPS (Intrusion
Detection and Prevention Systems), firewalls, anti‐virus scanning appliances, content
filtering appliances, and when combined with different methods (e.g. statistics,
machine learning, behaviour analysis and pattern matching), to detect security
breaches (i.e. passive security appliances) or prevent/block detected security problems
(i.e. active security appliances).
Network monitoring solutions come in different variants, depending on what they
measure and how they collect the data:
1) Active Probing: a service‐centric approach that collects data based on synthetic
measurements, i.e. ICMP Echo Requests, HTTP GET requests or specially crafted
packets. Often these measurements are trying to analyze properties of the network
that would be impossible to capture from pure passive measurements and are arguably the only way to measure service availability.
232
programing multiple network equipment at run time. The SDN control plane has global
visibility and finer control over the packets traversing the network. Since the network is
controlled from centralized controllers and the network components have programmable interfaces, network monitoring is augmented to a higher level in terms of efficiency, cost and complexity. NFV is ETSI standardized architecture that separates
network functionality from the hardware. NFV means that network functions will be
running as a service in commercial off‐the‐shelf hardware.
On the one hand, the limitations of legacy monitoring systems to secure wireless
networks can be overcome by introducing novel monitoring architecture based on
SDN and NFV. On the other hand, the use of SDN and NFV bring new challenges
to network trouble shooting and monitoring. This chapter investigates the challenges introduced by SDN and NFV in 5G networks and how the 5G operators need to
tackle them by using efficient network monitoring solutions. Moreover, we highlight
new opportunities that will help achieve efficient SDN‐ and NFV‐based 5G network
monitoring.
10.2 Existing Monitoring Techniques
Several network monitoring techniques with different levels of capabilities exist in
today’s network management space [2]. First, we have router based monitoring protocols which allow gathering information supplied by NEs (Network Elements):
● Simple Network Monitoring Protocol (SNMP): for the management of NEs and high‐
level information on resource use (e.g. monitor bandwidth usage of routers and
switches port‐by‐port, device information like memory use, CPU load, etc.);
● Remote Monitoring (RMON): for the exchange of network monitoring data; and,
● Netflow or sFlow: for collecting information on IP network flows and bandwidth usage.
These protocols are mostly dedicated for performance analysis and network management, but they have also been used for detecting some security problems, for
instance NetFlow. Current networks are also using packet sniffing, DPI (Deep Packet
Inspection), DFI (Deep Flow Inspection), virus scanners, malware detectors and other
techniques for analysing network packet headers, complete packets or packet payloads.
They are used by NIDS (Network Intrusion Detection Systems), IDPS (Intrusion
Detection and Prevention Systems), firewalls, anti‐virus scanning appliances, content
filtering appliances, and when combined with different methods (e.g. statistics,
machine learning, behaviour analysis and pattern matching), to detect security
breaches (i.e. passive security appliances) or prevent/block detected security problems
(i.e. active security appliances).
Network monitoring solutions come in different variants, depending on what they
measure and how they collect the data:
1) Active Probing: a service‐centric approach that collects data based on synthetic
measurements, i.e. ICMP Echo Requests, HTTP GET requests or specially crafted
packets. Often these measurements are trying to analyze properties of the network
that would be impossible to capture from pure passive measurements and are arguably the only way to measure service availability.
