A real-time attack defense framework for 5G network slicing

被引:19
|
作者
Bonfim, Michel [1 ]
Santos, Marcelo [2 ]
Dias, Kelvin [1 ]
Fernandes, Stenio [1 ]
机构
[1] Univ Fed Pernambuco UFPE, Ctr Informat CIn, Av Jornalista Anibal Fernandes S-N,Cidade Univ, BR-50740560 Recife, PE, Brazil
[2] Inst Fed Educ Ciencia & Tecnol Sertao Pernambucan, Salgueiro, PE, Brazil
来源
SOFTWARE-PRACTICE & EXPERIENCE | 2020年 / 50卷 / 07期
基金
美国国家科学基金会;
关键词
5G; bloom filter; cybersecurity; network function virtualization; network slice; P4; SECURITY;
D O I
10.1002/spe.2800
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Network Slicing (NS) is a key enabler to support 5G network services on-demand. However, since NS is a result of the recent advancement in Software-Defined Networking and Network Function Virtualization, it introduces new security issues which include attacks against an NS instance within an operator network and interslice security threats. In this scenario, identifying and mitigating attacks in real-time is of paramount importance to improve security aspects. However, it is far from being straightforward. Therefore, this work proposes the FrameRTP4, a P4-based framework that aims to deliver real-time attack detection and mitigation mechanisms in 5G NS scenarios. For this, it provides a P4-based switch that implements an Service Function Chaining protocol layer, an efficient and scalable Access Control List for the detection and mitigation of known attacks, and a monitoring system aiming to reduce the overhead induced on the control channel. Furthermore, it delivers an orchestrator that aims to control all switches in order to enable lifecycle management of NS instances and P4 table rules. Besides, it also performs some autonomous tasks such as the wildcard rules generation and the detection of new threats by using machine learning algorithms. Preliminary results point to the potential benefits of FrameRTP4 to be part of a 5G NS infrastructure.
引用
收藏
页码:1228 / 1257
页数:30
相关论文
共 50 条
  • [21] A Scalable Monitoring Framework for Network Slicing in 5G and Beyond Mobile Networks
    Mekki, Mohamed
    Arora, Sagar
    Ksentini, Adlen
    [J]. IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2022, 19 (01): : 413 - 423
  • [22] Enhancing 5G network slicing for IoT traffic with a novel clustering framework
    Min, Ziran
    Gokhale, Swapna
    Shekhar, Shashank
    Mahmoudi, Charif
    Kang, Zhuangwei
    Barve, Yogesh
    Gokhale, Aniruddha
    [J]. PERVASIVE AND MOBILE COMPUTING, 2024, 104
  • [23] Stochastic Optimization and Control Framework for 5G Network Slicing with Effective Isolation
    Kasgari, Ali Taleb Zadeh
    Saad, Walid
    [J]. 2018 52ND ANNUAL CONFERENCE ON INFORMATION SCIENCES AND SYSTEMS (CISS), 2018,
  • [24] Network Slicing in 5G: Survey and Challenges
    Foukas, Xenofon
    Patounas, Georgios
    Elmokashfi, Ahmed
    Marina, Mahesh K.
    [J]. IEEE COMMUNICATIONS MAGAZINE, 2017, 55 (05) : 94 - 100
  • [25] Towards the quest for 5G Network Slicing
    Messaoudi, Farouk
    Bertin, Philippe
    Ksentini, Adlen
    [J]. 2020 IEEE 17TH ANNUAL CONSUMER COMMUNICATIONS & NETWORKING CONFERENCE (CCNC 2020), 2020,
  • [26] 5G Network Slicing for Digital Inclusion
    Noll, Josef
    Dixit, Sudhir
    Radovanovic, Danica
    Morshedi, Maghsoud
    Holst, Christine
    Winkler, Andrea S.
    [J]. 2018 10TH INTERNATIONAL CONFERENCE ON COMMUNICATION SYSTEMS & NETWORKS (COMSNETS), 2018, : 191 - 197
  • [27] NFV Enabling Network Slicing for 5G
    Chatras, Bruno
    Kwong, Steve Tsang U.
    Bihannic, Nicolas
    [J]. PROCEEDINGS OF THE 2017 20TH CONFERENCE ON INNOVATIONS IN CLOUDS, INTERNET AND NETWORKS (ICIN), 2017, : 219 - 225
  • [28] A Study on Secure Network Slicing in 5G
    Singh, Pranav Kumar
    Brahma, Maharaj
    Nath, Panchanan
    Ghosh, Uttam
    [J]. 2023 IEEE/ACM 23RD INTERNATIONAL SYMPOSIUM ON CLUSTER, CLOUD AND INTERNET COMPUTING WORKSHOPS, CCGRIDW, 2023, : 52 - 61
  • [29] Network Slicing for 5G: Challenges and Opportunities
    Li, Xin
    Samaka, Mohammed
    Chan, H. Anthony
    Bhamare, Deval
    Gupta, Lav
    Guo, Chengcheng
    Jain, Raj
    [J]. IEEE INTERNET COMPUTING, 2017, 21 (05) : 20 - 27
  • [30] Network slicing for 5G edge services
    Kourtis, Michail-Alexandros
    Sarlas, Thanos
    Anagnostopoulos, Themis
    Kuklinski, Slawomir
    Tomaszewski, Lechoslaw
    Wierzbicki, Michal
    Oikonomakis, Andreas
    Xilouris, George
    Chochliouros, Ioannis P.
    Yi, Na
    Kostopoulos, Alexandros
    Koumaras, Harilaos
    [J]. INTERNET TECHNOLOGY LETTERS, 2021, 4 (06)