Monshizadeh and Khatri
338
8) Cookie poisoning attack: when a user visits a webpage in a web browser, personal
information of the user along with session information is stored in a cookie. In this
attack, a cookie is modified by an attacker to gain unauthorized information about
the user for identity theft purposes;
9) Service injection attack: injection attacks targeting a service belong to this category.
Examples include Structured Query Language (SQL) injection attack, eXtensible
Markup Language (XML) injection attack and cross‐site scripting attack;
10) Botnet: a group of connected vulnerable computers in a network, which are remotely
controlled by a master computer (hacker). Similar to robots, they automatically
perform some functions that are predefined by the botmaster and forward information like viruses to target computers, which can cause denial of service. Botnets
often use basic applications like Internet Relay Chat (IRC) and HTTP, and communications among them are encrypted that makes it difficult to detect them;
11) Malware: refers to all kinds of software codes, i.e. viruses, worms, Trojans and
drive‐by download. These attacks are programmed to perform malicious operations on a networked device;
12) Adware: all kinds of software that use some form of advertising delivery system to
replace banner ads on web pages with those of other content providers;
13) Ransomware: any kind of software that locks a computer and demands some form
of payment to make the computer unlock.
14.5 TaaS Deployment Security
What matters in cloud computing is the combination of layers and deployment to
propose a new security model. Our proposed platform Cloud Security Framework
for Operators (CSFO) not only recommends for each layer a proper deployment but
also emphasizes on specific detection‐prevention mechanism for different layers [42].
Figure 14.8 shows our proposed security framework for TaaS:
14.5.1 IaaS
1) Layer point of view: Since infrastructures are fully managed by a mobile cloud provider, the security mechanism is also responsibility of the provider. The tenants
usually have minimum control and interaction on the network elements. They do
not have access to the control plane VMs, even though they still could reach some
of the network elements, such as Home Location Register (HLR) or the Policy
Control and Charging Function (PCRF) server, to pull their subscribers’ information (i.e. subscriber profile, billing information). However, IaaS is less accessible
by customers (end users or tenants); still insider attackers need to be highly
considered.
For this layer, techniques such as data isolation through VMs, ciphering to protect
data against unauthorized access, backup and recovery for data reliability and IDS
for preventing malicious attacks should be considered by the cloud provider.
2) Deployment point of view: Considering high security requirements for infrastructures, limited accessibility, geographic location and high cost of network elements,
mobile operators are recommended to use a private cloud for this layer.
338
8) Cookie poisoning attack: when a user visits a webpage in a web browser, personal
information of the user along with session information is stored in a cookie. In this
attack, a cookie is modified by an attacker to gain unauthorized information about
the user for identity theft purposes;
9) Service injection attack: injection attacks targeting a service belong to this category.
Examples include Structured Query Language (SQL) injection attack, eXtensible
Markup Language (XML) injection attack and cross‐site scripting attack;
10) Botnet: a group of connected vulnerable computers in a network, which are remotely
controlled by a master computer (hacker). Similar to robots, they automatically
perform some functions that are predefined by the botmaster and forward information like viruses to target computers, which can cause denial of service. Botnets
often use basic applications like Internet Relay Chat (IRC) and HTTP, and communications among them are encrypted that makes it difficult to detect them;
11) Malware: refers to all kinds of software codes, i.e. viruses, worms, Trojans and
drive‐by download. These attacks are programmed to perform malicious operations on a networked device;
12) Adware: all kinds of software that use some form of advertising delivery system to
replace banner ads on web pages with those of other content providers;
13) Ransomware: any kind of software that locks a computer and demands some form
of payment to make the computer unlock.
14.5 TaaS Deployment Security
What matters in cloud computing is the combination of layers and deployment to
propose a new security model. Our proposed platform Cloud Security Framework
for Operators (CSFO) not only recommends for each layer a proper deployment but
also emphasizes on specific detection‐prevention mechanism for different layers [42].
Figure 14.8 shows our proposed security framework for TaaS:
14.5.1 IaaS
1) Layer point of view: Since infrastructures are fully managed by a mobile cloud provider, the security mechanism is also responsibility of the provider. The tenants
usually have minimum control and interaction on the network elements. They do
not have access to the control plane VMs, even though they still could reach some
of the network elements, such as Home Location Register (HLR) or the Policy
Control and Charging Function (PCRF) server, to pull their subscribers’ information (i.e. subscriber profile, billing information). However, IaaS is less accessible
by customers (end users or tenants); still insider attackers need to be highly
considered.
For this layer, techniques such as data isolation through VMs, ciphering to protect
data against unauthorized access, backup and recovery for data reliability and IDS
for preventing malicious attacks should be considered by the cloud provider.
2) Deployment point of view: Considering high security requirements for infrastructures, limited accessibility, geographic location and high cost of network elements,
mobile operators are recommended to use a private cloud for this layer.
