Autonomic protection of multi-tenant 5G mobile networks against UDP flooding DDoS attacks

被引:18
|
作者
Mamolar, Ana Serrano [1 ]
Salva-Garcia, Pablo [2 ]
Chirivella-Perez, Enrique [3 ]
Pervez, Zeeshan [3 ]
Calero, Jose M. Alcaraz [3 ]
Wang, Qi [3 ]
机构
[1] Univ West Scotland, H2020 5G PPP Phase 1 SELFNET Project, Glasgow, Lanark, Scotland
[2] Univ West Scotland, H2020 5G PPP Phase 2 SELFNET Project, Glasgow, Lanark, Scotland
[3] Univ West Scotland, Glasgow, Lanark, Scotland
基金
欧盟地平线“2020”;
关键词
Self-managed networks; Autonomic control loop; 5G network; DDoS attack; Multi-tenancy; Self-protection; DEFENSE;
D O I
10.1016/j.jnca.2019.102416
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
There is a lack of effective security solutions that autonomously, without any human intervention, detect and mitigate DDoS cyber-attacks. The lack is exacerbated when the network to be protected is a 5G mobile network. 5G networks push multi-tenancy to the edge of the network. Both the 5G user mobility and multi-tenancy are challenges to be addressed by current security solutions. These challenges lead to an insufficient protection of 5G users, tenants and infrastructures. This research proposes a novel autonomic security system, including the design, implementation and empirical validation to demonstrate the efficient protection of the network against Distributed Denial of Service (DDoS) attacks by applying countermeasures decided on and taken by an autonomic system, instead of a human. The self-management architecture provides support for all the different phases involved in a DDoS attack, from the detection of an attack to its final mitigation, through making the appropriate autonomous decisions and enforcing actions. Empirical experiments have been performed to protect a 5G multi-tenant infrastructure against a User Datagram Protocol (UDP) flooding attack, as an example of an attack to validate the design and prototype of the proposed architecture. Scalability results show self-protection against DDoS attacks, without human intervention, in around one second for an attack of 256 simultaneous attackers with 100 Mbps bandwidth per attacker. Furthermore, results demonstrate the proposed approach is flow-, user- and tenant-aware, which allows applying different protection strategies within the infrastructure.
引用
收藏
页数:12
相关论文
共 50 条
  • [21] On Active, Fine-Grained RAN and Spectrum Sharing in Multi-Tenant 5G Networks
    Khan, Shah Nawaz
    Goratti, Leonardo
    Riggio, Roberto
    Hasan, Shahriar
    2017 IEEE 28TH ANNUAL INTERNATIONAL SYMPOSIUM ON PERSONAL, INDOOR, AND MOBILE RADIO COMMUNICATIONS (PIMRC), 2017,
  • [22] TCO Game in 5G Multi-Tenant Virtualized Mobile BackHaul (V-MBH) Network
    Haddaji, Nassim
    Kim-Khoa Nguyen
    Cheriet, Mohamed
    2019 15TH INTERNATIONAL WIRELESS COMMUNICATIONS & MOBILE COMPUTING CONFERENCE (IWCMC), 2019, : 1612 - 1618
  • [23] 5GTopoNet: Real-time topology discovery and management on 5G multi-tenant networks
    Sanchez-Navarro, Ignacio
    Mamolar, Ana Serrano
    Wang, Qi
    Calero, Jose M. Alcaraz
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2021, 114 : 435 - 447
  • [24] E2E Network Slice Management Framework for 5G Multi-tenant Networks
    Chirivella-Perez, Enrique
    Salva-Garcia, Pablo
    Sanchez-Navarro, Ignacio
    Alcaraz-Calero, Jose M.
    Wang, Qi
    JOURNAL OF COMMUNICATIONS AND NETWORKS, 2023, 25 (03) : 392 - 404
  • [25] SDN/NFV-based End to End Network Slicing for 5G Multi-tenant Networks
    Chartsias, P. K.
    Amiras, A.
    Plevrakis, I.
    Samaras, I.
    Katsaros, K.
    Kritharidis, D.
    Trouva, E.
    Angelopoulos, I.
    Kourtis, A.
    Siddiqui, M. S.
    Vines, A.
    Escalona, E.
    2017 EUROPEAN CONFERENCE ON NETWORKS AND COMMUNICATIONS (EUCNC), 2017,
  • [26] Secure Modular Smart Contract Platform for Multi-Tenant 5G Applications
    Pustisek, Matevz
    Turk, Jan
    Kos, Andrej
    IEEE ACCESS, 2020, 8 (08): : 150626 - 150646
  • [27] NetFPGA-based Firewall Solution for 5G Multi-Tenant architectures
    Ricart-Sanchez, Ruben
    Malagon, Pedro
    Alcaraz-Calero, Jose M.
    Wang, Qi
    2019 IEEE INTERNATIONAL CONFERENCE ON EDGE COMPUTING (IEEE EDGE), 2019, : 132 - 136
  • [28] Mutes: Multi-Tenant Switching for 5G Network Slice Revenue Maximization
    Balasubramanian, Venkatraman
    Aloqaily, Moayad
    Reisslein, Martin
    2022 INTERNATIONAL WIRELESS COMMUNICATIONS AND MOBILE COMPUTING, IWCMC, 2022, : 590 - 595
  • [29] Defending 5G Networks Against DDoS Attacks Using Quarantine Slice Manager Architecture
    Amogh, P. C.
    Vashistha, Ankush
    Rao, Yepuri Sudhakara
    Pei Yiyang
    Sun Sumei
    2024 IEEE VTS ASIA PACIFIC WIRELESS COMMUNICATIONS SYMPOSIUM, APWCS 2024, 2024,
  • [30] Enabling Technologies and Benefits of Multi-Tenant Multi-Service 5G Small Cells
    Giannoulakis, Ioannis
    Sayyad Khodashenas, Pouria
    Ruiz, Cristina
    Betzler, August
    Albanese, Antonino
    Oscar Fajardo, Jose
    Kafetzakis, Emmanouil
    Paolino, Michele
    Garcia Lloreda, Javier
    Perez-Romero, Jordi
    Goratti, Leonardo
    Riggio, Roberto
    2016 EUROPEAN CONFERENCE ON NETWORKS AND COMMUNICATIONS (EUCNC), 2016, : 42 - 46