Towards a 5G Security Architecture: Articulating Software-Defined Security and Security as a Service

被引:5
|
作者
Blanc, Gregory [1 ]
Kheir, Nizar [2 ]
Ayed, Dhouha [2 ]
Lefebvre, Vincent [3 ]
de Oca, Edgardo Montes [4 ]
Bisson, Pascal [2 ]
机构
[1] Telecom SudParis, CNRS, SAMOVAR, Evry, France
[2] Thales Grp, Paris, France
[3] Tages SAS, Le Cannet, France
[4] Montimage, Paris, France
关键词
Network Slicing; Software-Defined Security; Security as a Service;
D O I
10.1145/3230833.3233251
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
5G is envisioned as a transformation of the communications architecture towards multi-tenant, scalable and flexible infrastructure, which heavily relies on virtualised network functions and programmable networks. In particular, orchestration will advance one step further in blending both compute and data resources, usually dedicated to virtualisation technologies, and network resources into so-called slices. Although 5G security is being developed in current working groups, slice security is seldom addressed. In this work, we propose to integrate security in the slice life cycle, impacting its management and orchestration that relies on the virtualization/ softwarisation infrastructure. The proposed security architecture connects the demands specified by the tenants through as-a-service mechanisms with built-in security functions relying on the ability to combine enforcement and monitoring functions within the software-defined network infrastructure. The architecture exhibits desirable properties such as isolating slices down to the hardware resources or monitoring service-level performance.
引用
收藏
页数:8
相关论文
共 50 条
  • [21] Dynamic Construction Scheme for Virtualization Security Service in Software-Defined Networks
    Lin, Zhaowen
    Tao, Dan
    Wang, Zhenji
    SENSORS, 2017, 17 (04)
  • [22] Programmable Security in the Age of Software-Defined Infrastructure
    Gu, Guofei
    PROCEEDINGS OF THE 2021 CLOUD COMPUTING SECURITY WORKSHOP, CCSW 2021, 2021, : 1 - 1
  • [23] Improving the Routing Security in Software-Defined Networks
    Ai, Jianjian
    Guo, Zehua
    Chen, Hongchang
    Cheng, Guozhen
    IEEE COMMUNICATIONS LETTERS, 2019, 23 (05) : 838 - 841
  • [24] Security in Software-Defined Networking: Threats and Countermeasures
    Zhaogang Shu
    Jiafu Wan
    Di Li
    Jiaxiang Lin
    Athanasios V. Vasilakos
    Muhammad Imran
    Mobile Networks and Applications, 2016, 21 : 764 - 776
  • [25] SOFTWARE-DEFINED NETWORKING SECURITY: PROS AND CONS
    Dabbagh, Mehiar
    Hamdaoui, Bechir
    Guizani, Mohsen
    Rayes, Ammar
    IEEE COMMUNICATIONS MAGAZINE, 2015, 53 : 73 - 79
  • [26] Security Challenges and Opportunities of Software-Defined Networking
    Dacier, Marc C.
    Koenig, Hartmut
    Cwalinski, Radoslaw
    Kargl, Frank
    Dietrich, Sven
    IEEE SECURITY & PRIVACY, 2017, 15 (02) : 96 - 100
  • [27] Semantic Security Tools in Software-Defined Networks
    Antoshina, E. Ju.
    Chalyy, D. Ju.
    AUTOMATIC CONTROL AND COMPUTER SCIENCES, 2018, 52 (07) : 605 - 607
  • [28] Security in Software-Defined Networking: Threats and Countermeasures
    Shu, Zhaogang
    Wan, Jiafu
    Li, Di
    Lin, Jiaxiang
    Vasilakos, Athanasios V.
    Imran, Muhammad
    MOBILE NETWORKS & APPLICATIONS, 2016, 21 (05): : 764 - 776
  • [29] Software-Defined Networking (SDN): the security review
    Hussein, A.
    Chadad, Louma
    Adalian, Nareg
    Chehab, Ali
    Elhajj, Imad H.
    Kayssi, Ayman
    Journal of Cyber Security Technology, 2020, 4 (01) : 1 - 66
  • [30] Security and design requirements for software-defined VANETs
    Ben Jaballah, Wafa
    Conti, Mauro
    Lal, Chhagan
    COMPUTER NETWORKS, 2020, 169 (169)