Chu
358
pipeline to enable much more agile and flexible operation and business models. For the
security domain, this is a great opportunity to create a threat intelligence pipeline,
through which new threats are detected and analyzed, then new security patches or
defenses are developed, tested and delivered through CI/CD routinely. The agility of
this pipeline must beat the new threats in this game to maintain security in the future.
NFV‐based CI/CD is an enabler for this fundamental capability that future 5G systems
must have.
The last stage of a VNF’s lifecycle is termination. Some of the tasks in a termination
phase are the removal of cryptographic material from the image, orderly archival and
removal of kept data records, etc.
Further discussions regarding the VNF’s lifecycle and security in each stage can be
found in ETSI NFV ISG’s TST working group publications such as [10].
To summarize, in this simpler, private NFV environment, a VNF’s lifecycle is standardized by a model VNF Descriptor (VNFD) and automated through VIM, VNFM and
service layer. This standardization and automation, coupled with rapid updating capability by CI/CD, will make security in NFV stronger than the manual system of today.
We often hear that the most common security vulnerabilities are due to human error or
human weakness exploitation. NFV‐based automation will change the dynamics and
allow operators to put their resources directly into defeating threats.
15.6.2 VNF Security in Operation
Managing a VNF’s lifecycle is only one aspect of VNF security. A VNF spends most of
its time in the operational state. Several important factors determine a VNF’s security
property.
First, let us remove one of the simplifications we made earlier: the assumption that a
VNF is a single entity, for example, a virtual machine. More commonly, a VNF consists
of a group of virtual machines with the same (a cluster) or different software images
(VNF Components or VNFCs). In either case, each virtual machine has a unique
identity and they are distributed to various computing units, not necessarily on the
same physical servers.
These virtual machines will need a network over which they can: (i) coordinate their
work by passing control messages among themselves, or (ii) pass around network packets
(traffic) between them for distributed or pipeline processing. This is similar to a backplane in physical systems where control modules and line modules are interconnected, or
there is an Ethernet‐based network fabric in a data center. Inside a VNF, this interconnection is provided by a virtual network created dynamically. This virtual private network
is provided on demand by virtual overlay such as VXLAN [11], a software abstraction
supported by the hypervisor or by a virtual switch (vSwitch in layer 2) or a virtual router
(vRouter in layer 3). Virtual networking or network slicing is a fundamental building
block of the NFV infrastructure, and must support two basic requirements:
1) Topology isolation; and
2) Security rules.
Topology isolation means the virtual network is private, with its accessibility to the
outside world fully controlled. Isolation alone is usually insufficient; security rules provide firewall‐like security to the virtual machines that reside inside the virtual network.
Précédent

- 400/483

Suivant