The growing demand for enhanced network capabilities, driven by the exponential increase in connected devices, has led to the widespread adoption of Fifth-Generation (5G) networks. While these networks significantly improve speed, latency, and scalability, they remain susceptible to evolving cyber threats. Despite security advancements introduced by 5G, such as robust authentication methods like 5G-AKA and improved user identity protection through Subscription Permanent Identifiers and Subscription Concealed Identifiers, critical vulnerabilities persist. Particularly, attacks targeting the User Plane Function via the Packet Forwarding Control Protocol can modify packet forwarding rules, manipulate or disrupt user sessions, and degrade network services, posing substantial risks to operators and end-users. To address this challenge while enabling the analysis of adversarial behavior, this work proposes a mechanism based on a Moving Target Defense (MTD) strategy. The proposed approach isolates malicious actors within a honeynet environment, thereby enhancing threat detection and mitigation. By leveraging MTD principles, the proposed framework enhances network resilience, reduces the impact of the attacks, and strengthens overall 5G security. Additionally, it ensures adaptive protection against evolving threats, supporting the reliable and robust delivery of next-generation network services. The effectiveness of the proposed framework is evaluated through a testbed simulating a 5G environment, demonstrating that the additional latency introduced by the security mechanisms is limited and does not compromise overall network performance. Thus, the proposed solution provides effective and adaptive protection against evolving threats, supporting reliable and robust delivery of next-generation network services.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Mitigation of PFCP Attacks in 5G Networks: Dynamic Defense Through Moving Target Defense and Honeynets

  • Aitor Landa-Arrue,
  • Jasone Astorga,
  • Iñaki Garitano,
  • Aitor Urbieta

摘要

The growing demand for enhanced network capabilities, driven by the exponential increase in connected devices, has led to the widespread adoption of Fifth-Generation (5G) networks. While these networks significantly improve speed, latency, and scalability, they remain susceptible to evolving cyber threats. Despite security advancements introduced by 5G, such as robust authentication methods like 5G-AKA and improved user identity protection through Subscription Permanent Identifiers and Subscription Concealed Identifiers, critical vulnerabilities persist. Particularly, attacks targeting the User Plane Function via the Packet Forwarding Control Protocol can modify packet forwarding rules, manipulate or disrupt user sessions, and degrade network services, posing substantial risks to operators and end-users. To address this challenge while enabling the analysis of adversarial behavior, this work proposes a mechanism based on a Moving Target Defense (MTD) strategy. The proposed approach isolates malicious actors within a honeynet environment, thereby enhancing threat detection and mitigation. By leveraging MTD principles, the proposed framework enhances network resilience, reduces the impact of the attacks, and strengthens overall 5G security. Additionally, it ensures adaptive protection against evolving threats, supporting the reliable and robust delivery of next-generation network services. The effectiveness of the proposed framework is evaluated through a testbed simulating a 5G environment, demonstrating that the additional latency introduced by the security mechanisms is limited and does not compromise overall network performance. Thus, the proposed solution provides effective and adaptive protection against evolving threats, supporting reliable and robust delivery of next-generation network services.