Title | Implementing a Security Policy Management for 5G Customer Edge Nodes |
Publication Type | Conference Paper |
Year of Publication | 2020 |
Authors | Kabir, H., Mohsin, M. H. Bin, Kantola, R. |
Conference Name | NOMS 2020 - 2020 IEEE/IFIP Network Operations and Management Symposium |
Date Published | April 2020 |
Publisher | IEEE |
ISBN Number | 978-1-7281-4973-8 |
Keywords | 5G, communication security policy, network edge, Policy Management, pubcrawl, reliability, resilience, Resiliency, Scalability, Security by Default, unwanted traffic |
Abstract | The upcoming 5th generation (5G) mobile networks need to support ultra-reliable communication for business and life-critical applications. To do that 5G must offer higher degree of reliability than the current Internet, where networks are often subjected to Internet attacks, such as denial of service (DoS) and unwanted traffic. Besides improving the mitigation of Internet attacks, we propose that ultra-reliable mobile networks should only carry the expected user traffic to achieve a predictable level of reliability under malicious activity. To accomplish this, we introduce device-oriented communication security policies. Mobile networks have classically introduced a policy architecture that includes Policy and Charging Control (PCC) functions in LTE. However, in state of the art, this policy architecture is limited to QoS policies for end devices only. In this paper, we present experimental implementation of a Security Policy Management (SPM) system that accounts communication security interests of end devices. The paper also briefly presents the overall security architecture, where the policies set for devices or services in a network slice providing ultra-reliability, are enforced by a network edge node (via SPM) to only admit the expected traffic, by default treating the rest as unwanted traffic. |
URL | https://ieeexplore.ieee.org/document/9110321/ |
DOI | 10.1109/NOMS47738.2020.9110321 |
Citation Key | kabir_implementing_2020 |