Session Management for Security Systems in 5G Standalone Network

As 5G telecom services evolve rapidly across a broad technological environment, network security in 5G landscape emerges as a critically challenging issue. One of typical network security tools is an intrusion prevention system (IPS) that monitors a network for malicious activity across the cyber-at...

Full description

Bibliographic Details
Main Authors: Seongmin Park, Sungmoon Kwon, Youngkwon Park, Dowon Kim, Ilsun You
Format: Article
Language:English
Published: IEEE 2022-01-01
Series:IEEE Access
Subjects:
Online Access:https://ieeexplore.ieee.org/document/9810284/
_version_ 1818478146580643840
author Seongmin Park
Sungmoon Kwon
Youngkwon Park
Dowon Kim
Ilsun You
author_facet Seongmin Park
Sungmoon Kwon
Youngkwon Park
Dowon Kim
Ilsun You
author_sort Seongmin Park
collection DOAJ
description As 5G telecom services evolve rapidly across a broad technological environment, network security in 5G landscape emerges as a critically challenging issue. One of typical network security tools is an intrusion prevention system (IPS) that monitors a network for malicious activity across the cyber-attack chain and takes action to prevent it. Vulnerabilities in 5G core networks become more varied and protocols become increasingly complex, whereby conventional Next Generation Firewall (NGFW) is not enough anymore to respond to cyber attacks. As a typical 5G vulnerability attack, PFCP-in-GTP and IPSec disable attack are highly complex to detect and cannot identify attackers without integrated session management. However, the 5G core network uses various protocols such as Non-Access Stratum (NAS), Hyper Text Transfer Protocol (HTTP), Packet Forwarding Control Protocol (PFCP), and GPRS Tunnelling Protocol (GTP), and packets of the interface used by each protocol are managed as identities that are difficult to identify. Analyzing the relationship of these interfaces in real time is an important key to integrated session management. In addition, unlike existing 4G, as 3rd Generation Partnership Project (3GPP) specs mandate encrypting 5G Standalone (SA) user IDs, it is much more difficult to identify from which user traffic has occurred in IPSs exclusive for cellular network. With regard to the above subject, this paper introduces an efficient session management scheme for users not affordable in conventional NFGW but necessarily useful for security systems in 5G SA. Furthermore, this study compared performances between conventional NGFWs and a 5G IPS system with the scheme employed, to ascertain that the scheme is feasibly implementable in 5G SA network. The actual test results show a detection rate of 99.7% and reasonable resource overhead (Memory usage 37.8%, CPU usage 42–44%).
first_indexed 2024-12-10T09:44:40Z
format Article
id doaj.art-665d667c1b8c4726a0de39758765edea
institution Directory Open Access Journal
issn 2169-3536
language English
last_indexed 2024-12-10T09:44:40Z
publishDate 2022-01-01
publisher IEEE
record_format Article
series IEEE Access
spelling doaj.art-665d667c1b8c4726a0de39758765edea2022-12-22T01:53:52ZengIEEEIEEE Access2169-35362022-01-0110734217343610.1109/ACCESS.2022.31870539810284Session Management for Security Systems in 5G Standalone NetworkSeongmin Park0https://orcid.org/0000-0002-2519-0707Sungmoon Kwon1Youngkwon Park2Dowon Kim3Ilsun You4https://orcid.org/0000-0002-0604-3445Korea Internet & Security Agency, Naju-si, South KoreaKorea Internet & Security Agency, Naju-si, South KoreaKorea Internet & Security Agency, Naju-si, South KoreaKorea Internet & Security Agency, Naju-si, South KoreaDepartment of Financial Information Security, Kookmin University, Seoul, South KoreaAs 5G telecom services evolve rapidly across a broad technological environment, network security in 5G landscape emerges as a critically challenging issue. One of typical network security tools is an intrusion prevention system (IPS) that monitors a network for malicious activity across the cyber-attack chain and takes action to prevent it. Vulnerabilities in 5G core networks become more varied and protocols become increasingly complex, whereby conventional Next Generation Firewall (NGFW) is not enough anymore to respond to cyber attacks. As a typical 5G vulnerability attack, PFCP-in-GTP and IPSec disable attack are highly complex to detect and cannot identify attackers without integrated session management. However, the 5G core network uses various protocols such as Non-Access Stratum (NAS), Hyper Text Transfer Protocol (HTTP), Packet Forwarding Control Protocol (PFCP), and GPRS Tunnelling Protocol (GTP), and packets of the interface used by each protocol are managed as identities that are difficult to identify. Analyzing the relationship of these interfaces in real time is an important key to integrated session management. In addition, unlike existing 4G, as 3rd Generation Partnership Project (3GPP) specs mandate encrypting 5G Standalone (SA) user IDs, it is much more difficult to identify from which user traffic has occurred in IPSs exclusive for cellular network. With regard to the above subject, this paper introduces an efficient session management scheme for users not affordable in conventional NFGW but necessarily useful for security systems in 5G SA. Furthermore, this study compared performances between conventional NGFWs and a 5G IPS system with the scheme employed, to ascertain that the scheme is feasibly implementable in 5G SA network. The actual test results show a detection rate of 99.7% and reasonable resource overhead (Memory usage 37.8%, CPU usage 42–44%).https://ieeexplore.ieee.org/document/9810284/Mobile network securityavailability attacksconfidentiality attacksintegrity attacksauthentication attacksimpersonation attacks
spellingShingle Seongmin Park
Sungmoon Kwon
Youngkwon Park
Dowon Kim
Ilsun You
Session Management for Security Systems in 5G Standalone Network
IEEE Access
Mobile network security
availability attacks
confidentiality attacks
integrity attacks
authentication attacks
impersonation attacks
title Session Management for Security Systems in 5G Standalone Network
title_full Session Management for Security Systems in 5G Standalone Network
title_fullStr Session Management for Security Systems in 5G Standalone Network
title_full_unstemmed Session Management for Security Systems in 5G Standalone Network
title_short Session Management for Security Systems in 5G Standalone Network
title_sort session management for security systems in 5g standalone network
topic Mobile network security
availability attacks
confidentiality attacks
integrity attacks
authentication attacks
impersonation attacks
url https://ieeexplore.ieee.org/document/9810284/
work_keys_str_mv AT seongminpark sessionmanagementforsecuritysystemsin5gstandalonenetwork
AT sungmoonkwon sessionmanagementforsecuritysystemsin5gstandalonenetwork
AT youngkwonpark sessionmanagementforsecuritysystemsin5gstandalonenetwork
AT dowonkim sessionmanagementforsecuritysystemsin5gstandalonenetwork
AT ilsunyou sessionmanagementforsecuritysystemsin5gstandalonenetwork