Next generation 5G network technology is allowing mobile edge computing (MEC) to finally hit its operational stride, though specific security challenges tied to the distributed nature of these deployments still need to be surmounted.
Ashish Khanna, who is senior managing director for Verizon Business’ Security Consulting Services, told SDxCentral in an interview that 5G technology has been a boon to the edge computing and networking space, but that proliferation in turn has increased edge security challenges due to a greater attack surface.
“What it means is that every device, every server, and every node is then becoming a potential entry for attackers,” Khanna said, adding that this challenge is linked to the open and distributed nature of 5G-based edge network deployments.
Khanna noted that aspects like open radio access network (RAN) technology can open up that attack surface “because there are still system integration problems and security risks, which also causes privacy issues as well.”
Khanna assertion was echoed by a recent ABI Research report that noted mobile networks are becoming increasingly “convoluted as radio access networks are deployed,” which is putting greater pressure on security platforms.
“The already highly complex 5G landscape is exacerbated by the uptake in RAN sharing and roaming,” Georgia Cooke, research analyst at ABI Research, wrote. “A greater variety of operators are in business, making it imperative that security solutions are interoperable.”
Khanna explained that one way operators can better prepare their edge computing deployments is through user emulation attacks prior to deploying open RAN components. Operators can also tap into cryptography and wireless-link signatures that exist between legitimate users and illegitimate users or attackers.
“You can distinguish between them using the right identity controls and putting that fabric into your network itself,” Khanna said of this approach.
However, Khanna also noted that higher 5G speeds can also work in the other direction in countering attacks.
“Because you have good bandwidth, your edge compute can help you to do real-time monitoring like what you used to have on a wired network in previous years,” Khanna said, noting this enables “faster response times because you are not having latency in terms of detecting what's a legitimate user versus what an attack is. So those distinctions can be made very easily.”
There is also the ability to more quickly distribute protocols and fixes to these edge locations “because you can then deploy the same solution across multiple locations, thus improving the overall network resilience. And that’s what matters to people: the resilience of their business.”
Edge standardization challenges Khanna did note that standardization remains one of the big challenges in securing edge compute deployments, stating that “there is definitely a different view from the companies in the way they look at security from their perspective and also the models that they tend to align.”
This spills over into services being run on 5G networks, like network slicing where there might be mission-critical applications running alongside more general data.
There is also a growing need to standardize on a secure supply chain in support of the growing number of devices that can take advantage of edge networks. This also includes the software running within those devices and who has control over the testing and dissemination of software patches to those devices.
“Are they being patched properly? Are you making sure that the code that the coders put into that software is fit for purpose and they're not being downloaded from GitHub and might have a security hole in them,” Khanna said.
ABI Research highlighted this concern in a report that found most organizations had reported an IoT-device related security attack. That number is more concerning with tens-of-billions of more IoT devices expected to attach to networks in the coming years.
The edge is everywhere This surge in edge connections is also a geographic concern that overlaps with growing data integrity issues.
Khanna explained that the decentralized nature of edge deployments complicates the ability for operators to deal with regional security mandates targeted at data integrity.
This decentralized view of security allows for a “geographic view of every edge device” and the ability to “put a security framework on top of that to what resonates with a particular geo, or a particular company, or a particular user, or a particular workload,” Khanna said. “You can dissect it to the nth-degree of where you want to put your controls in.”
Khanna said that one way Verizon Business attempts to tackle these challenge is through what it calls edge orchestration.
“The edge orchestration models actually helps us to have a little distributed workloads across devices,” Khanna explained. “It optimizes the resource utilization and then it also gives us a seamless load balancing, so, in nutshell, what we are doing is we are doing a zero-trust network architecture because we are looking at a workload, we're looking at a workplace, we're looking at a user, which is the workforce, and we are also looking at the device, and underpinned through our network. All the pillars within the zero trust network architecture are primarily in alignment to what we are trying to do to overcome these challenges.”
And, of course, AI Artificial intelligence (AI) also plays a role in this process as it can help manage constrained edge compute and storage resources.
“It becomes more easy for these models to be trained to do real-time monitoring for a specific part of the edge compute, and look at that more deeply and do things like automated incident response, and can you go on sending the data back to the central server so that there is a proper formation of the activities and log,” Khanna said, adding that this sort of process is probably still a few years out.
Khanna explained that this can play a role with machine learning (ML) in helping to “focus on the areas that make a difference rather than the noise.”
“We train the models to go and find anything that they see outside the box and come back to the analyst to say, ‘hey, you know there's a massive requirement for this bandwidth at this point in time? Do you want to take an action and kill this? Or do you want me to do this?’ So we are building both the brain and muscle in a way where it should make various impacts,” Khanna said. “I think that all has been possible because of not having the problems with the latencies and not having the problems with the speed of execution to what demands us to get faster and done with the security space.”
Comments