Monshizadeh and Khatri
342
a secure and flexible 5G architecture. Also, it is important to define the security requirements for 5G networks at the initial stage. On the other hand, the proposed cloud
security model helps mobile operators to understand how to tradeoff and merge their
services based on the deployment and importance of the provided services. In
Figure 14.8, private deployment is assigned to Infrastructure as a Service (IaaS) that
requires highest security consideration.
For Software as a Service (SaaS), which is the closest layer to the end users, public
cloud is recommended. Some of the reasons for this recommendation come from application availability to a wide range of end users, scattered end users (geographic location)
and roaming condition. Finally, hybrid cloud is the proposed deployment for Platform as
a Service (PaaS) layer; that means private and public deployment could be considered for
provided platforms and based on their sensitivity and security concerns. The discussed
CFSO model is a combined security model that considers different threats and vulnerabilities for each layer, their modules, services and protocols, and helps TaaS to find the
best combination of deployment solution.
In addition, we reviewed three categories of Mobile Virtual Network Operator
(MVNO) attack profiles: intra‐MVNOs attacks, inter‐MVNOs attacks and end‐user
attacks and some of the Network Function Virtualization (NFV) specific threats and
their mitigation mechanisms for a cloudified MVNO were introduced. However, the
majority of cloudified MVNO threats and their mitigations are similar to traditional
networks, and still there are new threats introduced by virtual Network Functions
(vNF). Abuse of unremoved Virtual Machines (VM) data by new tenants, vNF malicious loops, malicious VMs, insufficient AAA mechanisms or non‐unique keys for
VMs, are some of these new threats. Furthermore, we reviewed TaaS security domains
(data, hypervisor and application) and applied three main security requirements (AAA,
availability and integrity) for each domain and addressed virtualized network threats
and their prevention mechanisms.
In addition, Open Platform for NFV (OPNFV) security activities has been discussed,
since OPNFV has been popular in the open source community for development
and Proof of Concepts (PoCs). Based on security key criterions, we showed that
the OPNFV security group does not cover data security partially and application
security. OPNFV uses OpenStack as a hypervisor platform and relies on its security to
cover hypervisor, SDN and NFV security. Considering the security requirements outlined for TaaS, OPNFV security needs to be revised to accommodate the cloudified
environment. While multiple open source projects are being released for cloud and
NFV, its security aspects from the mobile operator point of view should be investigated
and tuned to meet their demands in a cloudified environment.
References
1 Chiosi, M. and Wright, S. (2014) Network functions virtualisation – White paper # 3,
ETSI, Darmstadt, Germany. Available at: https://portal.etsi.org/Portals/0/TBpages/NFV/
Docs/NFV_White_Paper3.pdf
2 Monshizadeh, M., Yan, Z., Hippeläinen, L. and Khatri, V. (2015) Cloudification and
security implications of TaaS. Proceedings of the World Symposium on, Computer
Networks and Information Security (WSCNIS), pp. 1–8.
342
a secure and flexible 5G architecture. Also, it is important to define the security requirements for 5G networks at the initial stage. On the other hand, the proposed cloud
security model helps mobile operators to understand how to tradeoff and merge their
services based on the deployment and importance of the provided services. In
Figure 14.8, private deployment is assigned to Infrastructure as a Service (IaaS) that
requires highest security consideration.
For Software as a Service (SaaS), which is the closest layer to the end users, public
cloud is recommended. Some of the reasons for this recommendation come from application availability to a wide range of end users, scattered end users (geographic location)
and roaming condition. Finally, hybrid cloud is the proposed deployment for Platform as
a Service (PaaS) layer; that means private and public deployment could be considered for
provided platforms and based on their sensitivity and security concerns. The discussed
CFSO model is a combined security model that considers different threats and vulnerabilities for each layer, their modules, services and protocols, and helps TaaS to find the
best combination of deployment solution.
In addition, we reviewed three categories of Mobile Virtual Network Operator
(MVNO) attack profiles: intra‐MVNOs attacks, inter‐MVNOs attacks and end‐user
attacks and some of the Network Function Virtualization (NFV) specific threats and
their mitigation mechanisms for a cloudified MVNO were introduced. However, the
majority of cloudified MVNO threats and their mitigations are similar to traditional
networks, and still there are new threats introduced by virtual Network Functions
(vNF). Abuse of unremoved Virtual Machines (VM) data by new tenants, vNF malicious loops, malicious VMs, insufficient AAA mechanisms or non‐unique keys for
VMs, are some of these new threats. Furthermore, we reviewed TaaS security domains
(data, hypervisor and application) and applied three main security requirements (AAA,
availability and integrity) for each domain and addressed virtualized network threats
and their prevention mechanisms.
In addition, Open Platform for NFV (OPNFV) security activities has been discussed,
since OPNFV has been popular in the open source community for development
and Proof of Concepts (PoCs). Based on security key criterions, we showed that
the OPNFV security group does not cover data security partially and application
security. OPNFV uses OpenStack as a hypervisor platform and relies on its security to
cover hypervisor, SDN and NFV security. Considering the security requirements outlined for TaaS, OPNFV security needs to be revised to accommodate the cloudified
environment. While multiple open source projects are being released for cloud and
NFV, its security aspects from the mobile operator point of view should be investigated
and tuned to meet their demands in a cloudified environment.
References
1 Chiosi, M. and Wright, S. (2014) Network functions virtualisation – White paper # 3,
ETSI, Darmstadt, Germany. Available at: https://portal.etsi.org/Portals/0/TBpages/NFV/
Docs/NFV_White_Paper3.pdf
2 Monshizadeh, M., Yan, Z., Hippeläinen, L. and Khatri, V. (2015) Cloudification and
security implications of TaaS. Proceedings of the World Symposium on, Computer
Networks and Information Security (WSCNIS), pp. 1–8.
