Mobile Virtual Network Operators (MVNO) Security 341
2) Fighting against governmental cyber war attacks is one of the common concerns
among potential target governments, privacy aware end users, and consequently
also service providers. Some governments are not financially restricted while preparing cyber‐attacks and espionage and they may sponsor cracker and hacktivists to
leverage their technological curiosity for ideological purposes. For this purpose, a
novel means is by at least detecting these attacks as early as possible, or even prevention appears necessary.
3) Cloud computing enables fast update cycles for software components such as VM
images. It should be investigated as to whether lowering quality assurance (testing)
effort of finding typical software bugs like buffer overruns is feasible or not. Lowering
quality assurance poses a risk of enabling vulnerabilities that can break into a system.
It is important that such breaches can be detected quickly and also their fixes are
distributed before any major damage occurs. On the other hand, it is worth considering if the possible development cost savings and profits from faster time to market,
exceed potential expenses caused by damages and bug fixing.
4) From the end user perspective, one main benefit for MNO cloudification is utilization
of a higher bandwidth for lower costs. It can also provide flexibility benefits such as
on‐demand services and dynamic charging patterns for bandwidth fluctuations, etc.
5) From the legacy perspective, legislation protecting end users against MNO/MVNOs
with malicious intentions may be needed in the future. Small capital lightweight
MVNO may be bought by the wrong people with malicious intent, and legislation
should be introduced to disconnect such malicious MVNOs.
We need to learn more about specifications and results of ongoing work at ETSI NFV.
Proposed TaaS will implement at least partial security requirements outlined in the
ETSI NFV specification. The TaaS concept needs to be analyzed further and compared
with NFV to find commonalities and also to understand how it can be positioned in
NFV context. ETSI NFV compliant open source software implementation OPNFV
release Colorado became available on September 26, 2016 [31,32], and it should be
analyzed as to how well it addresses security concerns outlined for TaaS. In addition,
OPNFV security needs to be revised to accommodate the cloudified environment.
While multiple open source projects are being released for cloud and NFV, its security
aspects from the mobile operator point of view should be investigated and tuned to
meet their demands in a cloudified environment.
14.7 Conclusion
Emerging traditional mobile operators who follow similar interests introduce potential
demand for a new service model in cloud computing called Telecommunication network as a Service (TaaS). According to a location‐based, customer‐based or service‐
based agreement, mobile operators could be grouped to considerably improve their
cost structure, time and quality efficiency and therefore their speed to market.
TaaS provides the possibility to understand mobile operator’s threats in a wide range
and based on their provided cloud layers. While the majority of earlier studies have
concentrated only on a few threats for a specific layer, this chapter has discussed the
mobile cloud threats for all layers of cloud and from an MVNO point of view towards
Précédent

- 383/483

Suivant