Chu
350
constructing such an architecture, and some aspects of ETSI’s formulation are still
works in progress, let us use the ETSI framework at a high level to help us familiarize
ourselves with the functional components and vocabulary and thus gain some appreciation of NFV’s security challenges and opportunities.
A deep dive into the ETSI NFV Reference Framework is beyond the scope of this chapter; we refer interested readers to [4]. NFV is abstracting and automating many of the
operational and business processes by software, and as such it requires operators to
redefine trust relationships between many existing components and roles. For example,
in a physical infrastructure, creating a new private network may involve a request‐and‐
approval process – and potentially, employees with physical access permissions, and
additional testing procedures to finally deliver the requested private network. NFV enables an on‐demand service model where the equivalent private network can be delivered
immediately without any human intervention or physical rewiring. We therefore must
have an automated mechanism for approval, authentication and accounting, and for validating network topology and security policy configurations. Automation allows uniformed policy enforcement, nimbler ways of defending against attacks, and deploying
enforcement points to wherever they best fit the need. Like any other digitization of a
human process, it also opens up attack surfaces and methods that may not exist in the
physical world. These issues are similar to what we found in the IT cloud computing
world, as are the solutions. We will therefore not spend much time on these general
security questions. In Section 15.6, we will discuss this topic in more detail and also look
at some open‐source examples of how new generations of software mechanisms found
in NFV can help us minimize security threats and enhance delivered services.
OSS/BSS
Infra, VNF, Service descriptors/catalogs
EMS 1
VNF 1
Virtual
computing
Computing
hardware
Storage
hardware
Network
hardware
Virtual
storage
Virtualization
Virtual
network
Virtual
Infrastructure
Manager(s)
EMS 2
VNF 2
EMS 3
NFV
Orchestrator
VNF
Manager(s)
VNF 3
Figure 15.2 ETSI NFV reference framework.
350
constructing such an architecture, and some aspects of ETSI’s formulation are still
works in progress, let us use the ETSI framework at a high level to help us familiarize
ourselves with the functional components and vocabulary and thus gain some appreciation of NFV’s security challenges and opportunities.
A deep dive into the ETSI NFV Reference Framework is beyond the scope of this chapter; we refer interested readers to [4]. NFV is abstracting and automating many of the
operational and business processes by software, and as such it requires operators to
redefine trust relationships between many existing components and roles. For example,
in a physical infrastructure, creating a new private network may involve a request‐and‐
approval process – and potentially, employees with physical access permissions, and
additional testing procedures to finally deliver the requested private network. NFV enables an on‐demand service model where the equivalent private network can be delivered
immediately without any human intervention or physical rewiring. We therefore must
have an automated mechanism for approval, authentication and accounting, and for validating network topology and security policy configurations. Automation allows uniformed policy enforcement, nimbler ways of defending against attacks, and deploying
enforcement points to wherever they best fit the need. Like any other digitization of a
human process, it also opens up attack surfaces and methods that may not exist in the
physical world. These issues are similar to what we found in the IT cloud computing
world, as are the solutions. We will therefore not spend much time on these general
security questions. In Section 15.6, we will discuss this topic in more detail and also look
at some open‐source examples of how new generations of software mechanisms found
in NFV can help us minimize security threats and enhance delivered services.
OSS/BSS
Infra, VNF, Service descriptors/catalogs
EMS 1
VNF 1
Virtual
computing
Computing
hardware
Storage
hardware
Network
hardware
Virtual
storage
Virtualization
Virtual
network
Virtual
Infrastructure
Manager(s)
EMS 2
VNF 2
EMS 3
NFV
Orchestrator
VNF
Manager(s)
VNF 3
Figure 15.2 ETSI NFV reference framework.
