Mobile Virtual Network Operators (MVNO) Security 325
accessible and visible to third‐party vNFs. Various security aspects for NFV are discussed in this chapter, but security requirements for each layer in the cloud are not
discussed. Tsai et al. [5] studied virtualization security issues and their impact on different cloud layers. Their study includes Virtual Machine (VM) hopping, VM mobility,
VM diversity and VM denial of service.
With VM hopping, an attacker can gain access from one VM to other VMs. VM mobility
emphasizes spread of vulnerable configuration. However, security management across
diverse domains is a challenge, but Service Level Agreements (SLAs) can help. Malicious
VMs may cause denial of service, but this can be mitigated by proper policy enforcement
on resource usage. Lin et al. [6] proposed an extended SDN architecture for NFV with a
case study on intrusion prevention. The architecture reduced traffic overhead towards
the controller. For this purpose, they redirected traffic to IPS vNF using service
chaining. Their research did not mention any specific threat for NFV. Jang et al. [7]
surveyed common interfaces for NFV‐based security services. For access networks,
security applications included traffic inspection, traffic manipulation and traffic
impersonation. Required functions for these applications are Deep Packet Inspection
(DPI), IPS, firewall, Virtual Private Network (VPN) and honeypots. In the mobile
network environment, security applications include security configuration, security
function negotiation and security request from a user device. For network security function,
this chapter concludes with the use of common interfaces, regardless of where they are
located and which operator they belong to in a cloud environment. Last but not least,
ETSI NFV has a working group focusing on security problems. They have categorized
security issues to host security, infrastructure security, vNF/tenant security, trust
management and regulatory concerns. Their work covers many if not all aspects of the
domain [8].
14.3 Cloudification of the Network Operators
According to the National Institute of Standard and Technology (NIST) [9], cloud
computing is a process to enable on‐demand access to a shared pool of configurable
resources such as storage, applications and services, which can be rapidly provisioned
and released with minimum provider interaction. On‐demand service, broad network
access, rapid provision, resource pooling and measured services are the main characteristics of this process.
The shift to cloud computing technology introduces diverse delivery models to telecom operators. In this transition, mobile operators can act as cloud network providers
and based on common characteristics such as geographical zone and availability, offer
networking services either to end users or other operators. For this purpose, we introduce a new functionality called TaaS. TaaS is a platform for creating functionalities to
be used for commercial MNO business. TaaS is composed of software, hardware and
application functions (also known as vNFs), as outlined by NFV industry standards.
The combination of these functions is proposed, as TaaS and could be sold as a service
product to emerging MNOs or MVNOs. The TaaS platform hosts various mobile
operators. Each mobile operator has interconnection with cloud layers (IaaS, PaaS and
SaaS), depending upon on the type of services it provides to the customers. Figure 14.1
shows the TaaS stacks in the cloud layers.
Précédent

- 367/483

Suivant