Mobile Virtual Network Operators (MVNO) Security 337
14.4.5 MVNO Security Benchmark
In order to propose a security framework for MVNOs in TaaS, an evolved benchmark
on threats and their mitigation mechanisms against security requirements is needed.
Therefore, in Table 14.2 and Figure 14.7, based on security requirements and for each
domain of a cloudified environment, the TaaS threats and their prevention mechanisms
are listed [36,38–40].
Some of the threats listed in Table 14.2 are described here:
1) Probing: is an attempt to monitor a computer or network and steal important information such as open ports and IP addresses for devices connected to a network.
Examples include port scanning and IP sweep attacks;
2) Remote to Local (R2L): this threat tries to access target machines without having an
account and permissions on that machine. Access is made possible by exploiting a
vulnerability and other related means. An example is the File Transfer Protocol
(FTP) write attack, which exploits a common anonymous FTP misconfiguration.
Other examples include dictionary attacks, Hyper‐Text Transfer Protocol (HTTP)
tunnel attacks and Xsnoop attacks;
3) User to Root (U2R): is an attempt to get administrator or super privilege access
while the user has only local access to a victim machine. A vulnerability in the victim
machine is exploited in order to gain root access. An example is the yaga attack,
which adds the attacker to the domain admins group by hacking the registry and can
crash a service on the victim’s machine. Other examples include ps‐attack and Xterm
attack. The vulnerability CVE‐2016‐0728 has been found in Linux kernels 3.6 and
later versions, which is a reference leak in the keyrings facility and occurs when an
error message is generated if a process tries to replace its current session keyring
with the same one [41];
4) Man‐in‐the middle attack: this attack occurs when an attacker gains access to the
communication channel established between two legitimate users. The attacker is
capable of performing unauthorized activities such as intercepting and modifying
communications including send and receive data that is meant for someone else. It is
a type of eavesdropping attack that occurs when a malicious actor inserts himself as
a relay/proxy into a communication session between people or systems. Examples
include man‐in‐the middle attack on HTTP and a poorly‐implemented Secure
Sockets Layer (SSL);
5) IP Spoofing: in this attack, a user/device creates IP packets with a false source IP
address, in order to hide the identity of sender or introduce itself as another device
and steal the data;
6) Phishing: in this attack, an attacker tries to learn account information or login credentials from a user by presenting himself/herself as a reputable and genuine entity
or person. The communication channels include email, phone call, instant message
and others. Typically, a web link is sent to the user, which looks safe and asks for user
credentials. Upon giving credentials, the credentials are forwarded to attacker;
7) Spyware: is all kinds of software that monitors computers and networks to collect
unauthorized information or steal credentials, such as passwords and credit card
numbers;
Précédent

- 379/483

Suivant