论文标题

软件启用安全架构和用于确保5G网络服务的机制

Software Enabled Security Architecture and Mechanisms for Securing 5G Network Services

论文作者

Varadharajan, Vijay, Tupakula, Uday, Karmakar, Kallol

论文摘要

5G网络系统正在发展,并具有复杂的网络基础架构。该领域有很多工作,重点是满足5G网络的严格服务要求。在这种情况下,安全要求起着至关重要的作用,因为5G网络可以支持一系列服务,例如医疗保健服务,财务和关键基础架构。 3GPP和ETSI一直在为5G网络开发安全框架。我们在5G安全方面的工作一直集中在安全体系结构和机制的设计上,以动态建立安全和可信赖的端到端服务以及开发机制,以主动检测和减轻虚拟化网络基础架构中的安全攻击。本文的重点是后者,即设施和机制,以及安全体系结构的设计提供了设施和机制,以检测和减轻特定的安全攻击。我们使用软件定义的网络(SDN)和网络功能虚拟化(NFV)技术开发并实施了安全体系结构的简化版本。本架构中开发的特定安全功能可以直接集成到5G核心网络设施中,从而增强其安全性。我们描述了安全体系结构的设计和实现,并演示了它如何有效地减轻特定类型的攻击。

The 5G network systems are evolving and have complex network infrastructures. There is a great deal of work in this area focused on meeting the stringent service requirements for the 5G networks. Within this context, security requirements play a critical role as 5G networks can support a range of services such as healthcare services, financial and critical infrastructures. 3GPP and ETSI have been developing security frameworks for 5G networks. Our work in 5G security has been focusing on the design of security architecture and mechanisms enabling dynamic establishment of secure and trusted end to end services as well as development of mechanisms to proactively detect and mitigate security attacks in virtualised network infrastructures. The focus of this paper is on the latter, namely the facilities and mechanisms, and the design of a security architecture providing facilities and mechanisms to detect and mitigate specific security attacks. We have developed and implemented a simplified version of the security architecture using Software Defined Networks (SDN) and Network Function Virtualisation (NFV) technologies. The specific security functions developed in this architecture can be directly integrated into the 5G core network facilities enhancing its security. We describe the design and implementation of the security architecture and demonstrate how it can efficiently mitigate specific types of attacks.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源