Towards a 5G Security Architecture: Articulating Software-Defined Security and Security as a Service

被引:5
|
作者
Blanc, Gregory [1 ]
Kheir, Nizar [2 ]
Ayed, Dhouha [2 ]
Lefebvre, Vincent [3 ]
de Oca, Edgardo Montes [4 ]
Bisson, Pascal [2 ]
机构
[1] Telecom SudParis, CNRS, SAMOVAR, Evry, France
[2] Thales Grp, Paris, France
[3] Tages SAS, Le Cannet, France
[4] Montimage, Paris, France
关键词
Network Slicing; Software-Defined Security; Security as a Service;
D O I
10.1145/3230833.3233251
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
5G is envisioned as a transformation of the communications architecture towards multi-tenant, scalable and flexible infrastructure, which heavily relies on virtualised network functions and programmable networks. In particular, orchestration will advance one step further in blending both compute and data resources, usually dedicated to virtualisation technologies, and network resources into so-called slices. Although 5G security is being developed in current working groups, slice security is seldom addressed. In this work, we propose to integrate security in the slice life cycle, impacting its management and orchestration that relies on the virtualization/ softwarisation infrastructure. The proposed security architecture connects the demands specified by the tenants through as-a-service mechanisms with built-in security functions relying on the ability to combine enforcement and monitoring functions within the software-defined network infrastructure. The architecture exhibits desirable properties such as isolating slices down to the hardware resources or monitoring service-level performance.
引用
收藏
页数:8
相关论文
共 50 条
  • [11] A Policy-Based Security Architecture for Software-Defined Networks
    Varadharajan, Vijay
    Karmakar, Kallol
    Tupakula, Uday
    Hitchens, Michael
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2019, 14 (04) : 897 - 912
  • [12] A Security Architecture for 5G Networks
    Arfaoul, Ghada
    Bisson, Pascal
    Blom, Rolf
    Borgaonkar, Ravishankar
    Englund, Hakan
    Felix, Edith
    Klaedtke, Felix
    Nakarmi, Prajwol Kumar
    Naslund, Mats
    O'Hanlon, Piers
    Papay, Juri
    Suomalainen, Jani
    Surridge, Mike
    Wary, Jean-Philippe
    Zahariev, Alexander
    IEEE ACCESS, 2018, 6 : 22466 - 22479
  • [13] Orchestration of Software-Defined Security Services
    Luo, Song
    Ben Salem, Malek
    2016 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS WORKSHOPS (ICC), 2016, : 436 - 441
  • [14] Software-Defined Mobile Networks Security
    Min Chen
    Yongfeng Qian
    Shiwen Mao
    Wan Tang
    Ximin Yang
    Mobile Networks and Applications, 2016, 21 : 729 - 743
  • [15] Security Evaluation in Software-Defined Networks
    Ivkic, Igor
    Thiede, Dominik
    Race, Nicholas
    Broadbent, Matthew
    Gouglidis, Antonios
    CLOUD COMPUTING AND SERVICES SCIENCE, CLOSER 2022, CLOSER 2023, 2024, 1845 : 66 - 91
  • [16] Software-Defined Mobile Networks Security
    Chen, Min
    Qian, Yongfeng
    Mao, Shiwen
    Tang, Wan
    Yang, Ximin
    MOBILE NETWORKS & APPLICATIONS, 2016, 21 (05): : 729 - 743
  • [17] On Security in Software-Defined Vehicular Cloud
    Kim, Myeongsu
    Jang, Insun
    Choo, Sukjin
    Pack, Sangheon
    2016 INTERNATIONAL CONFERENCE ON INFORMATION AND COMMUNICATION TECHNOLOGY CONVERGENCE (ICTC 2016): TOWARDS SMARTER HYPER-CONNECTED WORLD, 2016, : 1259 - 1260
  • [18] Security Analysis of a Software-Defined Radar
    Yerkes, Blake
    Ramsey, Benjamin
    Rice, Mason
    Pecarina, John
    Dunlap, Stephen
    PROCEEDINGS OF THE 12TH INTERNATIONAL CONFERENCE ON CYBER WARFARE AND SECURITY (ICCWS 2017), 2017, : 386 - 395
  • [19] 5G and Security Service Innovation
    Marukawa K.
    Kyokai Joho Imeji Zasshi/Journal of the Institute of Image Information and Television Engineers, 2020, 74 (03): : 428 - 433
  • [20] A Security Controller-based Software Defined Security Architecture
    Qiu, Xiaofeng
    Cheng, Fangyuan
    Wang, Weijia
    Zhang, Gang
    Qiu, Yangjun
    PROCEEDINGS OF THE 2017 20TH CONFERENCE ON INNOVATIONS IN CLOUDS, INTERNET AND NETWORKS (ICIN), 2017, : 191 - 195