A real-time attack defense framework for 5G network slicing

被引:19
|
作者
Bonfim, Michel [1 ]
Santos, Marcelo [2 ]
Dias, Kelvin [1 ]
Fernandes, Stenio [1 ]
机构
[1] Univ Fed Pernambuco UFPE, Ctr Informat CIn, Av Jornalista Anibal Fernandes S-N,Cidade Univ, BR-50740560 Recife, PE, Brazil
[2] Inst Fed Educ Ciencia & Tecnol Sertao Pernambucan, Salgueiro, PE, Brazil
来源
SOFTWARE-PRACTICE & EXPERIENCE | 2020年 / 50卷 / 07期
基金
美国国家科学基金会;
关键词
5G; bloom filter; cybersecurity; network function virtualization; network slice; P4; SECURITY;
D O I
10.1002/spe.2800
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Network Slicing (NS) is a key enabler to support 5G network services on-demand. However, since NS is a result of the recent advancement in Software-Defined Networking and Network Function Virtualization, it introduces new security issues which include attacks against an NS instance within an operator network and interslice security threats. In this scenario, identifying and mitigating attacks in real-time is of paramount importance to improve security aspects. However, it is far from being straightforward. Therefore, this work proposes the FrameRTP4, a P4-based framework that aims to deliver real-time attack detection and mitigation mechanisms in 5G NS scenarios. For this, it provides a P4-based switch that implements an Service Function Chaining protocol layer, an efficient and scalable Access Control List for the detection and mitigation of known attacks, and a monitoring system aiming to reduce the overhead induced on the control channel. Furthermore, it delivers an orchestrator that aims to control all switches in order to enable lifecycle management of NS instances and P4 table rules. Besides, it also performs some autonomous tasks such as the wildcard rules generation and the detection of new threats by using machine learning algorithms. Preliminary results point to the potential benefits of FrameRTP4 to be part of a 5G NS infrastructure.
引用
收藏
页码:1228 / 1257
页数:30
相关论文
共 50 条
  • [1] Real-time Dynamic Network Slicing for the 5G Radio Access Network
    Maule, Massimiliano
    Mekikis, Prodromos-Vasileios
    Ramantas, Kostas
    Vardakas, John
    Verikoukis, Christos
    [J]. 2019 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2019,
  • [2] Real-time maintenance of latency-sensitive 5G services through network slicing
    Rafael Montero
    Fernando Agraz
    Albert Pagès
    Salvatore Spadaro
    [J]. Photonic Network Communications, 2020, 40 : 221 - 232
  • [3] Real-time maintenance of latency-sensitive 5G services through network slicing
    Montero, Rafael
    Agraz, Fernando
    Pages, Albert
    Spadaro, Salvatore
    [J]. PHOTONIC NETWORK COMMUNICATIONS, 2020, 40 (03) : 221 - 232
  • [4] A programmable and adaptive framework for 5G Network Slicing
    Seetharaman, Swaminathan
    Krishnaswamy, Dilip
    [J]. 2019 IEEE 2ND 5G WORLD FORUM (5GWF), 2019, : 553 - 559
  • [5] A Real-Time Visualization Defense Framework for DDoS Attack
    Jin, Yiqiao
    Liang, Qidi
    Zhang, Jian
    Jin, Ou
    [J]. DATA SCIENCE, PT 1, 2017, 727 : 341 - 351
  • [6] Automated Attack and Defense Framework toward 5G Security
    Sun, Yanbin
    Tian, Zhihong
    Li, Mohan
    Zhu, Chunsheng
    Guizani, Nadra
    [J]. IEEE NETWORK, 2020, 34 (05): : 247 - 253
  • [7] An extensible network slicing framework for satellite integration into 5G
    Drif, Youssouf
    Chaput, Emmanuel
    Lavinal, Emmanuel
    Berthou, Pascal
    Tiomela Jou, Boris
    Gremillet, Olivier
    Arnal, Fabrice
    [J]. INTERNATIONAL JOURNAL OF SATELLITE COMMUNICATIONS AND NETWORKING, 2021, 39 (04) : 339 - 357
  • [8] A Base Station Agnostic Network Slicing Framework for 5G
    Tseliou, Georgia
    Adelantado, Ferran
    Verikoukis, Christos
    [J]. IEEE NETWORK, 2019, 33 (04): : 82 - 88
  • [9] A Design Framework of Automatic Deployment for 5G Network Slicing
    Lai, Wen-Ping
    Lai, Hong-Lun
    Lai, Ming-Jay
    [J]. 2020 ASIA-PACIFIC SIGNAL AND INFORMATION PROCESSING ASSOCIATION ANNUAL SUMMIT AND CONFERENCE (APSIPA ASC), 2020, : 1571 - 1577
  • [10] Service-aware real-time slicing for virtualized beyond 5G networks
    Tsourdinis, Theodoros
    Chatzistefanidis, Ilias
    Makris, Nikos
    Korakis, Thanasis
    Nikaein, Navid
    Fdida, Serge
    [J]. COMPUTER NETWORKS, 2024, 247