Software Defined Security Monitoring in 5G Networks 233
2) Device Polling: a device‐centric approach that queries devices typically using SNMP
(Simple Network Management Protocol), collecting interface status information,
traffic volumes, device load, CPU, etc.;
3) Flow Collection: solutions that collect traffic information from network devices such
as routers/switches. Here traffic can be aggregated in flows using, e.g. Cisco Netflow
and stored on disk for post‐analysis. Flow data is easier to analyse and process than
packet data, but provides less granular information;
4) Packet Analysis: usually involves a SPAN port from a switch or a network tap and
extracts information from individual packets, including information from payloads
through DPI (Deep Packet Inspection);
5) Log Analysis: are solutions that collect machine generated data typically in the form
of log files (e.g. syslog) and present a query interface to correlate events across different types of systems, e.g. routers, web servers, load balancers.
Combining the above‐mentioned sources of information, we have what is called “Security
information and event management (SIEM)” technologies. SIEM provides, on the one
hand, security information management (SIM), and on the other hand, security event
management (SEM). SIEM technology aggregates event data produced by security devices,
network infrastructures, systems and applications. The primary data source is the log data,
but SIEM technology can also process other forms of data, such as NetFlow and packet
capture (DPI). Event data is combined with contextual information about users, assets,
threats and vulnerabilities. The data is normalized, so that events, data and contextual
information from disparate sources can be correlated and analysed for specific purposes,
such as network security event monitoring, user activity monitoring and compliance
reporting. This technology provides real‐time security monitoring, historical/trends analysis and other support for incident investigation (e.g. forensics) and compliance reporting.
10.3 Limitations of Current Monitoring Techniques
The legacy monitoring systems have a number of limitations that could be solved by
software defined monitoring systems. These limitations are in two‐fold. First, is the
limitation of the monitoring systems themselves, these include high complexity and
operational costs, as well as delays and overheads. For example, the currently used vendor‐specific monitoring systems come with hardwired operational logic in their firmware. This means that changes in the legacy monitoring system either require complex
configurations or changes in their firmware. As a result, these systems lack the flexibility needed and cannot cope with the dynamic changes in network conditions.
Similarly, there are inherent limitations in the monitoring systems used today. For
example, the required synchronization between observation beacons in passive measurement schemes increases the complexity of the system, as well as the delay in the
monitoring process. The active measurement methodology on the other hand, increases
network overhead by inducing additional packets. Thus, additional packets in the active
approaches influence the accuracy of measurements [5].
The second limitation is imposed by the operational environment, such as stagnant
behaviour of the network, bandwidth constraints, and complexity of the environment.
The currently used monitoring systems obtain network statistics or packet samples from
2) Device Polling: a device‐centric approach that queries devices typically using SNMP
(Simple Network Management Protocol), collecting interface status information,
traffic volumes, device load, CPU, etc.;
3) Flow Collection: solutions that collect traffic information from network devices such
as routers/switches. Here traffic can be aggregated in flows using, e.g. Cisco Netflow
and stored on disk for post‐analysis. Flow data is easier to analyse and process than
packet data, but provides less granular information;
4) Packet Analysis: usually involves a SPAN port from a switch or a network tap and
extracts information from individual packets, including information from payloads
through DPI (Deep Packet Inspection);
5) Log Analysis: are solutions that collect machine generated data typically in the form
of log files (e.g. syslog) and present a query interface to correlate events across different types of systems, e.g. routers, web servers, load balancers.
Combining the above‐mentioned sources of information, we have what is called “Security
information and event management (SIEM)” technologies. SIEM provides, on the one
hand, security information management (SIM), and on the other hand, security event
management (SEM). SIEM technology aggregates event data produced by security devices,
network infrastructures, systems and applications. The primary data source is the log data,
but SIEM technology can also process other forms of data, such as NetFlow and packet
capture (DPI). Event data is combined with contextual information about users, assets,
threats and vulnerabilities. The data is normalized, so that events, data and contextual
information from disparate sources can be correlated and analysed for specific purposes,
such as network security event monitoring, user activity monitoring and compliance
reporting. This technology provides real‐time security monitoring, historical/trends analysis and other support for incident investigation (e.g. forensics) and compliance reporting.
10.3 Limitations of Current Monitoring Techniques
The legacy monitoring systems have a number of limitations that could be solved by
software defined monitoring systems. These limitations are in two‐fold. First, is the
limitation of the monitoring systems themselves, these include high complexity and
operational costs, as well as delays and overheads. For example, the currently used vendor‐specific monitoring systems come with hardwired operational logic in their firmware. This means that changes in the legacy monitoring system either require complex
configurations or changes in their firmware. As a result, these systems lack the flexibility needed and cannot cope with the dynamic changes in network conditions.
Similarly, there are inherent limitations in the monitoring systems used today. For
example, the required synchronization between observation beacons in passive measurement schemes increases the complexity of the system, as well as the delay in the
monitoring process. The active measurement methodology on the other hand, increases
network overhead by inducing additional packets. Thus, additional packets in the active
approaches influence the accuracy of measurements [5].
The second limitation is imposed by the operational environment, such as stagnant
behaviour of the network, bandwidth constraints, and complexity of the environment.
The currently used monitoring systems obtain network statistics or packet samples from
