Mobile Virtual Network Operators (MVNO) Security 333
not yet been mitigated. In documentation, the plan is to cover these and a guide is being
collaboratively worked on, although most of it is covered in the OpenStack security
guide, even Kernel‐based Virtual Machine (KVM), etc. Secure boot, trusted compute,
etc., are covered in the OPNFV security guide, although it is still very much a work in
progress. Outside of that, it comes down to vendor implementation as to how they
configure the TPM to be harnessed by the host OS.
The application security domain has not been considered, since OPNFV concentrates
only on NFV Infrastructure (NFVI), VIM, and MANagement and Orchestration
(MANO).
Since OPNFV is about upstream code contributions, several parts are covered by
upstream projects. Therefore, it is not easy to make a direct comparison at a functional
level. In Table 14.1, five aspects of OPNFV security (virtualization, network virtualization, SDN controller framework, OpenStack and virtual storage) are compared with
TaaS security domains (data, hypervisor SDN/NFV and application).
In Table 14.1, none of the five aspects of OPNFV security covers application security,
only two aspects (network virtualization and SDN controller frame work) cover data
security and all five aspects cover hypervisor security. The comparison shows OPNFV
security does not cover application security; however, it partially covers data security
and considerably covers hypervisor, SDN and NFV security. Therefore, OPNFV security needs to be revised in areas of data and the application domain, especially to meet
the security requirements for TaaS [27].
14.4.3 Application Security in TaaS
Another aspect of virtualized network security refers to protection against threats that
are related to an application server or a web server connected to the Internet.
Based on the concept of SaaS, software applications should be accessible over the
Internet that makes security a very critical challenge for mobile operators. Beside the
mechanisms such as data encryption, access control and authentication, back up and
redundancy, the mobile operator could implement sensitive applications that do not
require end user intervention (i.e. billing application), by using PaaS that is accessible
only to limited professional users among mobile operators [35].
Table 14.1 OPNFV security focus.
Research domains
Data
Hypervisor,
SDN and NFV
Application
OPNFV Security
Virtualization (KVM, QEMU, XEN)
✓
Network Virtualization (DPDK, ODP, OVS)
✓
✓
SDN controller framework (ONOS, ODL, OpenFlow)
✓
✓
OpenStack
✓
Virtual storage
✓
not yet been mitigated. In documentation, the plan is to cover these and a guide is being
collaboratively worked on, although most of it is covered in the OpenStack security
guide, even Kernel‐based Virtual Machine (KVM), etc. Secure boot, trusted compute,
etc., are covered in the OPNFV security guide, although it is still very much a work in
progress. Outside of that, it comes down to vendor implementation as to how they
configure the TPM to be harnessed by the host OS.
The application security domain has not been considered, since OPNFV concentrates
only on NFV Infrastructure (NFVI), VIM, and MANagement and Orchestration
(MANO).
Since OPNFV is about upstream code contributions, several parts are covered by
upstream projects. Therefore, it is not easy to make a direct comparison at a functional
level. In Table 14.1, five aspects of OPNFV security (virtualization, network virtualization, SDN controller framework, OpenStack and virtual storage) are compared with
TaaS security domains (data, hypervisor SDN/NFV and application).
In Table 14.1, none of the five aspects of OPNFV security covers application security,
only two aspects (network virtualization and SDN controller frame work) cover data
security and all five aspects cover hypervisor security. The comparison shows OPNFV
security does not cover application security; however, it partially covers data security
and considerably covers hypervisor, SDN and NFV security. Therefore, OPNFV security needs to be revised in areas of data and the application domain, especially to meet
the security requirements for TaaS [27].
14.4.3 Application Security in TaaS
Another aspect of virtualized network security refers to protection against threats that
are related to an application server or a web server connected to the Internet.
Based on the concept of SaaS, software applications should be accessible over the
Internet that makes security a very critical challenge for mobile operators. Beside the
mechanisms such as data encryption, access control and authentication, back up and
redundancy, the mobile operator could implement sensitive applications that do not
require end user intervention (i.e. billing application), by using PaaS that is accessible
only to limited professional users among mobile operators [35].
Table 14.1 OPNFV security focus.
Research domains
Data
Hypervisor,
SDN and NFV
Application
OPNFV Security
Virtualization (KVM, QEMU, XEN)
✓
Network Virtualization (DPDK, ODP, OVS)
✓
✓
SDN controller framework (ONOS, ODL, OpenFlow)
✓
✓
OpenStack
✓
Virtual storage
✓
