Software Defined Security Monitoring in 5G Networks 237
mirroring, traffic load balancing and aggregation) and accept requests from network functions and applications. SDM CTRLs are distributed following either a
peer‐to‐peer or hierarchical model. They interact with the management/monitoring/security function and act as distributed analysis or decision points for the
defined security policies (i.e. security SLAs);
– Network monitoring: a virtualization of the monitoring function (i.e. part of the
traffic analysis moved to the cloud);
– Traffic Mirroring and Analysis: a passive backhaul traffic monitoring device
required by different network functions.
● Interfaces:
– SDN/SDM Control Interface: an interface that allows controlling the use of the
monitoring resources, recuperating traffic or metadata for analysis. It allows performing monitoring requests and obtaining the status of the network links. In this
way, applications and network functions can send requests for monitoring‐based
information, and receive the status information they need.
By programming flexible switches and other network devices to act as packet interception and redirection points, it becomes possible to detect and mitigate a variety of
attacks. By introducing SDN‐driven security analysis, or Software Defined Monitoring
(SDM), SDN‐enabled switches, COTS packet processing and security appliances can
In the cloud
Application Layer
Virtual Network Layer
(Network Operating System)
Control Layer
Network Infrastructure Layer
SecApp
MonApp
VNE
MME
Orchestrator
Northbound Interface
SDN/SDM
CTRL
SDN/SDM
CTRL
Southbound Interface (e.g., OpenFlow)
Switches
Security
appliance
SDN/SDM
CTRL
IPs
VN
VN
VS
VS
VS
VS
VS
VS
IPs
VM:
Virtual Machine
SecApp:
Security Application
MonApp:
Monitoring Application
VNE:
Virtualised Network Element (NFV),
e.g., MME
IPs:
IP address
VN:
Virtual Network Slice
VS:
Virtual Switch
SDN/SDM CTRL: combined SD Networking and Monitoring
Controller
VM
VM
Figure 10.2 The deployment of the components of SDM architecture in a 5G Backhaul Network.
mirroring, traffic load balancing and aggregation) and accept requests from network functions and applications. SDM CTRLs are distributed following either a
peer‐to‐peer or hierarchical model. They interact with the management/monitoring/security function and act as distributed analysis or decision points for the
defined security policies (i.e. security SLAs);
– Network monitoring: a virtualization of the monitoring function (i.e. part of the
traffic analysis moved to the cloud);
– Traffic Mirroring and Analysis: a passive backhaul traffic monitoring device
required by different network functions.
● Interfaces:
– SDN/SDM Control Interface: an interface that allows controlling the use of the
monitoring resources, recuperating traffic or metadata for analysis. It allows performing monitoring requests and obtaining the status of the network links. In this
way, applications and network functions can send requests for monitoring‐based
information, and receive the status information they need.
By programming flexible switches and other network devices to act as packet interception and redirection points, it becomes possible to detect and mitigate a variety of
attacks. By introducing SDN‐driven security analysis, or Software Defined Monitoring
(SDM), SDN‐enabled switches, COTS packet processing and security appliances can
In the cloud
Application Layer
Virtual Network Layer
(Network Operating System)
Control Layer
Network Infrastructure Layer
SecApp
MonApp
VNE
MME
Orchestrator
Northbound Interface
SDN/SDM
CTRL
SDN/SDM
CTRL
Southbound Interface (e.g., OpenFlow)
Switches
Security
appliance
SDN/SDM
CTRL
IPs
VN
VN
VS
VS
VS
VS
VS
VS
IPs
VM:
Virtual Machine
SecApp:
Security Application
MonApp:
Monitoring Application
VNE:
Virtualised Network Element (NFV),
e.g., MME
IPs:
IP address
VN:
Virtual Network Slice
VS:
Virtual Switch
SDN/SDM CTRL: combined SD Networking and Monitoring
Controller
VM
VM
Figure 10.2 The deployment of the components of SDM architecture in a 5G Backhaul Network.
