Monshizadeh and Khatri
324
Obviously, the mobile operators can benefit from cloudification by sharing physical
resources. The new technology can also make it easier for new companies to enter not
only the telecommunications service provider market place but also as software vendors
for virtualized network functions and perhaps also as cloud service providers. On the
other hand, with the help of network data intelligence, the operators can share the critical
information (i.e. customer segmentation) with third parties (with privacy preservation)
to extend their business in order to gain additional profits.
However, cloudification of mobile operators introduces several advantages, but security is still one of the largest challenges. It is assumed that 5G will follow the Software
Defined Networking (SDN) principles of separating the control and data planes as well
as using NFV for running network (control) functions on the cloud infrastructure,
which brings additional security challenges and increases attack surface.
Due to resource sharing, various internal or external cyber‐attacks (data leakage,
data corruption, etc.) can target MVNOs. Although traditional prevention mechanisms such as backup‐recovery, encryption, Intrusion Detection System (IDS),
Internet Protocol Security (IPSec) and secure protocols can be used, we still need
to confront new security challenges in a 5G cloudified network and therefore
implement TaaS [3].
In this chapter, we introduce the concept of cloudification of mobile operators and
present a new platform called TaaS in a cloud environment. In addition, we discuss the
security challenges of TaaS, the new threats it introduces, and also the prevention
mechanisms to resist these threats. Later, we discuss TaaS deployment and propose a
framework to mitigate deployment security, and based on the cloud deployment
model, we propose a security framework, Cloud Security Framework for Operators
(CSFO), in order to achieve TaaS security. The remainder of this chapter discusses
new threats introduced by NFV and mechanisms to prevent them. We also investigate
Open Platform for NFV (OPNFV) security group work and see how many security
requirements for TaaS have been covered by them. NFV security challenges, data
and application layer threats, as well as their mitigation mechanisms, will also be
investigated and NFV security requirements will be mapped to the TaaS platform.
Furthermore, we discuss OPNFV security group activities and finally the conclusion
is presented.
14.2 Related Work
Although some articles investigate security requirements of cloud as general, only a few
cover security requirements at each layer of the cloud environment for MVNOs.
However, our intent here is not to provide a complete survey of the previous studies, but
to select some related works that address the security challenges of a cloudified MVNO.
The Alcatel‐Lucent white paper [4] recommends security mechanisms, including
hypervisor introspection and centralized security management for NFV deployment.
Depending on the deployment model, identity and access management, security zones,
FireWalls (FWs), hypervisor introspection and hardening, must be applied to prevent
unauthorized access. Regarding Denial of Service (DoS) attacks, virtual load balancers
and virtual Domain Name System (DNS) servers should be utilized. A secure key storage should be provided using specialized Hardware Security Models (HSM), so it is not
324
Obviously, the mobile operators can benefit from cloudification by sharing physical
resources. The new technology can also make it easier for new companies to enter not
only the telecommunications service provider market place but also as software vendors
for virtualized network functions and perhaps also as cloud service providers. On the
other hand, with the help of network data intelligence, the operators can share the critical
information (i.e. customer segmentation) with third parties (with privacy preservation)
to extend their business in order to gain additional profits.
However, cloudification of mobile operators introduces several advantages, but security is still one of the largest challenges. It is assumed that 5G will follow the Software
Defined Networking (SDN) principles of separating the control and data planes as well
as using NFV for running network (control) functions on the cloud infrastructure,
which brings additional security challenges and increases attack surface.
Due to resource sharing, various internal or external cyber‐attacks (data leakage,
data corruption, etc.) can target MVNOs. Although traditional prevention mechanisms such as backup‐recovery, encryption, Intrusion Detection System (IDS),
Internet Protocol Security (IPSec) and secure protocols can be used, we still need
to confront new security challenges in a 5G cloudified network and therefore
implement TaaS [3].
In this chapter, we introduce the concept of cloudification of mobile operators and
present a new platform called TaaS in a cloud environment. In addition, we discuss the
security challenges of TaaS, the new threats it introduces, and also the prevention
mechanisms to resist these threats. Later, we discuss TaaS deployment and propose a
framework to mitigate deployment security, and based on the cloud deployment
model, we propose a security framework, Cloud Security Framework for Operators
(CSFO), in order to achieve TaaS security. The remainder of this chapter discusses
new threats introduced by NFV and mechanisms to prevent them. We also investigate
Open Platform for NFV (OPNFV) security group work and see how many security
requirements for TaaS have been covered by them. NFV security challenges, data
and application layer threats, as well as their mitigation mechanisms, will also be
investigated and NFV security requirements will be mapped to the TaaS platform.
Furthermore, we discuss OPNFV security group activities and finally the conclusion
is presented.
14.2 Related Work
Although some articles investigate security requirements of cloud as general, only a few
cover security requirements at each layer of the cloud environment for MVNOs.
However, our intent here is not to provide a complete survey of the previous studies, but
to select some related works that address the security challenges of a cloudified MVNO.
The Alcatel‐Lucent white paper [4] recommends security mechanisms, including
hypervisor introspection and centralized security management for NFV deployment.
Depending on the deployment model, identity and access management, security zones,
FireWalls (FWs), hypervisor introspection and hardening, must be applied to prevent
unauthorized access. Regarding Denial of Service (DoS) attacks, virtual load balancers
and virtual Domain Name System (DNS) servers should be utilized. A secure key storage should be provided using specialized Hardware Security Models (HSM), so it is not
