Software Defined Security Monitoring in 5G Networks 235
On the one hand, the impact of virtualization on these technologies needs to be
assessed. For instance, security applications need to be able to monitor virtual connections. Virtualization can help isolate systems, but can also be used to introduce malicious
techniques that exploit software vulnerabilities or introduce compromised systems that
are difficult to detect. For instance, virtualization creates boundaries that could be
breached by exploiting vulnerabilities and bugs in the virtualization code (e.g. hypervisors); and whole systems actually become files that can more easily be stolen or replaced.
On the other hand, the security technologies need to cope with ever‐changing contexts and trade‐offs between the monitoring costs and risks involved. Here, virtualization, as well as SDN, facilitates changes making it necessary for security applications to
keep up with this dynamicity.
SIEM‐type solutions are necessary in order to gain security and status awareness. If
an incident occurs, the system should be able to determine the source, and recover and
protect against it in the future. It should be verified that everything that comes out of
the system is logged. Managers have centralized control over the network and it is necessary to log every change and treat it accordingly in a management solution. Log analysis and event correlation in SDN will fast become a “big data” issue. Tools also are
needed that can address all the forensics and compliance requirements.
With SDN, it is possible to create network monitoring applications that collect information and make decisions based on a network‐wide holistic view. This enables centralized event correlation on the network controller, and allows new ways of mitigating
network faults.
To design an effective monitoring system in 5G networks, improvements are needed
in the following main areas [2]:
● Information extraction: understanding how to deal with virtualization to obtain information on traffic flows, profiles and properties by means of extracted protocol metadata, measurements, data mining and machine learning techniques;
● Scalability and performance issues: the design of the monitoring architecture and the
location of the observation points need to be done in such a way as to assure scalability, and different monitoring use cases need to be studied to obtain the best balance
between performance, cost and completeness of the results. Furthermore, hardware
acceleration and packet pre‐processing technologies need to be integrated and controlled by applications and functions to obtain highly optimized solutions;
● Heterogeneity: analysis of different control and user plane traffic flows over the network domains and new interfaces between SDMN and existing networks and identification of related flows in different network domains;
● Dynamicity: changes in virtualized networks and applications become more easy and
frequent. Monitoring solutions need to be able to adapt to these changes.
10.5 Software‐Defined Monitoring Architecture
In order to solve the above issues, different architectural possibilities were studied and
proposed in the SIGMONA [6] project. The Software Defined Monitoring (SDM)
architecture was specified for 5G mobile networks. Figure 10.1 illustrates the SDM architecture for 5G Networks.
An extension of the OpenFlow type interface, referred to as the SDN/SDM Control
Interface in Figure 10.1, allows obtaining the packet and flow data and meta‐data
On the one hand, the impact of virtualization on these technologies needs to be
assessed. For instance, security applications need to be able to monitor virtual connections. Virtualization can help isolate systems, but can also be used to introduce malicious
techniques that exploit software vulnerabilities or introduce compromised systems that
are difficult to detect. For instance, virtualization creates boundaries that could be
breached by exploiting vulnerabilities and bugs in the virtualization code (e.g. hypervisors); and whole systems actually become files that can more easily be stolen or replaced.
On the other hand, the security technologies need to cope with ever‐changing contexts and trade‐offs between the monitoring costs and risks involved. Here, virtualization, as well as SDN, facilitates changes making it necessary for security applications to
keep up with this dynamicity.
SIEM‐type solutions are necessary in order to gain security and status awareness. If
an incident occurs, the system should be able to determine the source, and recover and
protect against it in the future. It should be verified that everything that comes out of
the system is logged. Managers have centralized control over the network and it is necessary to log every change and treat it accordingly in a management solution. Log analysis and event correlation in SDN will fast become a “big data” issue. Tools also are
needed that can address all the forensics and compliance requirements.
With SDN, it is possible to create network monitoring applications that collect information and make decisions based on a network‐wide holistic view. This enables centralized event correlation on the network controller, and allows new ways of mitigating
network faults.
To design an effective monitoring system in 5G networks, improvements are needed
in the following main areas [2]:
● Information extraction: understanding how to deal with virtualization to obtain information on traffic flows, profiles and properties by means of extracted protocol metadata, measurements, data mining and machine learning techniques;
● Scalability and performance issues: the design of the monitoring architecture and the
location of the observation points need to be done in such a way as to assure scalability, and different monitoring use cases need to be studied to obtain the best balance
between performance, cost and completeness of the results. Furthermore, hardware
acceleration and packet pre‐processing technologies need to be integrated and controlled by applications and functions to obtain highly optimized solutions;
● Heterogeneity: analysis of different control and user plane traffic flows over the network domains and new interfaces between SDMN and existing networks and identification of related flows in different network domains;
● Dynamicity: changes in virtualized networks and applications become more easy and
frequent. Monitoring solutions need to be able to adapt to these changes.
10.5 Software‐Defined Monitoring Architecture
In order to solve the above issues, different architectural possibilities were studied and
proposed in the SIGMONA [6] project. The Software Defined Monitoring (SDM)
architecture was specified for 5G mobile networks. Figure 10.1 illustrates the SDM architecture for 5G Networks.
An extension of the OpenFlow type interface, referred to as the SDN/SDM Control
Interface in Figure 10.1, allows obtaining the packet and flow data and meta‐data
