Mobile Virtual Network Operators (MVNO) Security 331
● Deep Packet Inspection (DPI);
● Deep Flow Inspection (DFI);
● Shallow Packet Inspection (SPI);
● Virus scanners;
● Intrusion Detection Systems (IDS);
● Firewall (FW);
● Security zones;
● Policy enforcement (PCRF) to define access rules and flow rules for access control
and authorization;
● Secure protocols, i.e. FlowTagging (flow tracking);
● Simple Network Monitoring Protocol (SNMP);
● Remote Monitoring (RMON);
● NetFlow or sFlow; and
● SDN Monitoring (SDNM).
14.4.2.2 NFV Security in TaaS
Virtualization is the main component in cloud services provided by mobile operators.
Multi‐tenancy, application sharing and open source software lead to security threats
such authentication, information leakage and data corruption in cloud environments,
including TaaS.
Usually, open source software may contain vulnerabilities, bugs and other security
holes and therefore not in line with enterprise security requirements. In a poorly
secured open‐source environment, attackers can easily have access to the system [22].
Some common vulnerabilities in open source include Heartbleed and ShellShock.
Heartbleed is a bug in the OpenSSL software library that allows theft of protected information. This bug has infected many web and email services [23–24]. ShellShock is a
vulnerability in bash that allows the non‐authorized user (hacker) to remotely execute
commands and take over the system [25–26]. These vulnerabilities were discovered
and then correction patches were applied, but if vulnerabilities are not detected early
enough, open‐source software brings security challenges. Considering similar cases,
open‐source software adds more security concerns to the cloudified environment, and
it should be carefully evaluated and tested before utilizing it.
NFV in TaaS refers to any network function that runs on mobile network equipment
over a hypervisor. There are three attack profiles in NFV [27]:
1) Intra‐MVNO attacks: include attacks on an MVNO by its own employee to occupy
and degrade network services;
2) Inter‐MVNO attack: refers to any type of attack from one MVNO towards another
MVNO(s), in order to extract the competitor’s information, corrupt or misuse their
services;
3) Attacks by end user: this category covers the attacks that are caused by mobile network
end users within the same MVNO or other MVNOs.
In a cloud environment with NFV, network functions will be deployed as vNFs that
bring security challenges. Different solutions, such as security zone and grouping, isolating applications by VMs and licensing are recommended for NFV security. NFV acts
in the hypervisor and other parties can see the encryption keys, therefore providing a
signature beside the keys [4]. FW and orchestration both are recommendations for
● Deep Packet Inspection (DPI);
● Deep Flow Inspection (DFI);
● Shallow Packet Inspection (SPI);
● Virus scanners;
● Intrusion Detection Systems (IDS);
● Firewall (FW);
● Security zones;
● Policy enforcement (PCRF) to define access rules and flow rules for access control
and authorization;
● Secure protocols, i.e. FlowTagging (flow tracking);
● Simple Network Monitoring Protocol (SNMP);
● Remote Monitoring (RMON);
● NetFlow or sFlow; and
● SDN Monitoring (SDNM).
14.4.2.2 NFV Security in TaaS
Virtualization is the main component in cloud services provided by mobile operators.
Multi‐tenancy, application sharing and open source software lead to security threats
such authentication, information leakage and data corruption in cloud environments,
including TaaS.
Usually, open source software may contain vulnerabilities, bugs and other security
holes and therefore not in line with enterprise security requirements. In a poorly
secured open‐source environment, attackers can easily have access to the system [22].
Some common vulnerabilities in open source include Heartbleed and ShellShock.
Heartbleed is a bug in the OpenSSL software library that allows theft of protected information. This bug has infected many web and email services [23–24]. ShellShock is a
vulnerability in bash that allows the non‐authorized user (hacker) to remotely execute
commands and take over the system [25–26]. These vulnerabilities were discovered
and then correction patches were applied, but if vulnerabilities are not detected early
enough, open‐source software brings security challenges. Considering similar cases,
open‐source software adds more security concerns to the cloudified environment, and
it should be carefully evaluated and tested before utilizing it.
NFV in TaaS refers to any network function that runs on mobile network equipment
over a hypervisor. There are three attack profiles in NFV [27]:
1) Intra‐MVNO attacks: include attacks on an MVNO by its own employee to occupy
and degrade network services;
2) Inter‐MVNO attack: refers to any type of attack from one MVNO towards another
MVNO(s), in order to extract the competitor’s information, corrupt or misuse their
services;
3) Attacks by end user: this category covers the attacks that are caused by mobile network
end users within the same MVNO or other MVNOs.
In a cloud environment with NFV, network functions will be deployed as vNFs that
bring security challenges. Different solutions, such as security zone and grouping, isolating applications by VMs and licensing are recommended for NFV security. NFV acts
in the hypervisor and other parties can see the encryption keys, therefore providing a
signature beside the keys [4]. FW and orchestration both are recommendations for
