Mobile Virtual Network Operators (MVNO) Security 329
1) Authentication, authorization and accounting: refers to a mechanism such as certificate‐based authentication that should be utilized to avoid unauthorized access. Keys
and signatures must be stored in a secure storage such as HSM [4] to make it invisible
to third parties. Hardening should be applied to the infrastructure layer and wherever needed to block any backdoor access. Virtual FWs must be used inside VMs and
proxy and traditional FWs must be used where needed to prevent unauthorized traffic. Backup must be maintained for all VMs, so that data can be restored in case of
failure. AAA should be maintained by logging actions from each VM and modules;
and logs should be stored in a safe storage so that in the case of attack or failure, the
logs will not be affected and could help to reveal the root cause. Encryption must be
used so that data is not readable to unintended parties, even if it is accessed without
authorization. Security policy should be enforced to make sure that all users in the
cloud have similar security policy and are in line with SLA [20].
2) Integrity: refers to protection against threats in the virtualized network. These
threats could vary from attacking different virtual machines such as virtual Mobility
Management Entity (vMME), vHSS, and their virtual functions, misconfigurations
or abuse of resources, corrupting operating systems, switches and management software (in SDN), and inducing any kind of malicious applications.
3) Availability: can be improved by applying techniques such as load balancing,
redundancy and data backup, as discussed earlier.
14.4.2.1 SDN Security in TaaS
In addition to the three main aspects of TaaS security (data security, hypervisor VM
security and application security), here we discuss other security and threats of cloud
computing, therefore TaaS.
It should be considered that introducing new technologies normally also brings new
security challenges. Except for the security issues of SDN that are new technologies for
supporting TaaS, other security threats and their detection‐prevention mechanisms are
almost similar to traditional networks. However, traditional network implementations
rely on dedicated hardware and private connections between network elements. Their
control plane connections are not exposed to the public, unless there is a configuration
error somewhere. The traditional network has survived quite well until today, and will
continue to survive with very little security awareness.
SDN is a new approach to separate UP and CP in mobile networks. As shown in
Figure 14.3, based on its functionality, SDN can be considered in IaaS (SDN switch) or
in PaaS (SDN controller). The SDN controller in mobile networks only carries CP
(MME, or Serving/Public Data Network Gateway (S/P GW) VMs), and is located in
PaaS. In this case, SDN is an interface between the infrastructure and application layer.
SDN in its switching functionality (S/P GW VM) only carries UP and considers part of
infrastructure layer. UP and CP use OpenFlow protocol for communications with each
other in SDN. The vNFs are running on virtual machines and they provide a certain
subsection of the whole functionality of a telecommunications network.
However, from the security point of view, SDN brings several advantages, such as [21]:
● Centralized management: simpler maintenance and debugging;
● Programmability: faster security solution implementation and easy feature deployment;
● Cost saving: with sharing security techniques and service chaining; and
● Centralized and virtualized function: centralized monitoring and detection techniques.
Précédent

- 371/483

Suivant