Network slicing may sound as if it means deploying an Exacto knife to make physical cuts in a cable wire, but in the context of IT, networking slicing means a lot more than that. It is considered one of the key architectural features of a 5G stand alone (SA) deployment. The technology allows an operator to set up siloed virtual networks that act as independent networks and can support revenue-generating premium services, among many other use cases.

A network slice provides specified network capabilities and characteristics – or multiple, isolated virtual networks – to fit a user’s needs. Although multiple network slices run on a single physical network, network slice users are sometimes (depending upon the access level of the individual) authenticated for only one network level, enabling data and security isolation and a much higher degree of security. Individuals can be sanctioned for more than network level.

[ Related: The 5G paradox: Why increasing IoT efficiency creates new security risks ]

Each slice spans multiple connected components that form a network, components that include physical computing, storage and networking infrastructure. These are virtualized, and protocols are set in place to create a specific network slice for each user or application. This means that varying types of 5G traffic, such as video streaming, industrial automation and mission-critical applications, all can be accommodated on the same network, yet each has its own dedicated resources and performance guarantees.

How 5G security works

5G network slicing is a network architecture that enables the multiplexing of virtualized and independent logical networks on the same physical network infrastructure. Network slicing in 5G networks can improve security by substantially reducing the attack surface. This is because network slicing involves the separation of virtual networks within a physical network, allowing for each slice to have its own security policies and enforcement mechanisms. This aims to ensure that any security breaches or attacks on one slice will not affect the security of other slices.

Moreover, the separation of the network slices can also limit the scope of any potential attack, thereby reducing the impact of such attacks. As a result, network slicing can help enhance the overall security posture of 5G networks, especially when deployed for private or dedicated networks.

These logically isolated networks inside the same physical infrastructure can be shared by multiple tenants (5G operators), who can all deploy their own security processes.

In 5G, the control planes (CP) and user planes (UP) are split — this is known as control and user plane separation (CUPS) and deployed in a new service-based architecture. CUPS for evolved packet core (EPC) functions enable operators to gain increased control – including that of security – over the data packets management in the network and provide additional services at the network edge. This provides the flexibility to deliver user plane functionality at the edge and the network core, allowing the user plane function to be co-located with local and central data centers.

Given the requirements of various vertical environments, differentiated connectivity is the key enabler for these applications/services. Network slicing is a secure, expedient and cost-effective way to accomplish this on an enterprise scale, Ericsson Director of Software Technology Shahzada Rasool wrote in a white paper.

Network slicing is going to increasingly come to the fore with 5G SA networks, which have a more intelligent and dynamic 5G Core, as opposed to those based on 4G. In North America, T-Mobile, Verizon, Rogers and Dish have live 5G SA networks, with other operators also readying their launches.

Network slicing not without its cost

Network slicing deployments, while promising great potential for many enterprises, have been slow to initiate and implement in the last couple of years. The complexity of the technology requires a significant investment in time and resources to deploy, which has made it a challenge for operators to get started. There also is a perceived lack of business cases; while there are a number of potential benefits to network slicing, it is not yet apparent to many operators how they can monetize these benefits. This has made it difficult for them to justify the investment in network slicing.

For example, the cost of a network slicing initiative for a company with 1,000 employees will vary depending on a number of factors, including the size and complexity of the network, the type of network slicing being deployed and the vendor or vendors that are being used. In fact, estimating the cost for any given network slicing initiative is a complicated process. However, a ballpark cost estimate for a basic network slicing initiative for a company with 1,000 employees could easily be in the millions-of-dollars range.

Security remains an ongoing concern

From a security standpoint, the resources of one 5G network slice ostensibly are isolated from other network slices to ensure confidentiality, integrity and availability; but security remains an ongoing issue.

Recurring security problems include the potential for unauthorized access to network slices, the risk of data breaches and the possibility of denial-of-service attacks. These issues have made operators reluctant to deploy 5G network slicing until they can be addressed. As with any new technology, time and testing will play a big role in getting slicing into the mainstream.

Other security concerns include tampering with slice-specific data usage, which could be done by an attacker to disrupt or deny service to a particular slice; misconfiguration of slice-specific information; and unauthorized access to network slices.

For example, Abdul Rahman, associate VP at Deloitte, told SDxCentral in an earlier interview that an attacker could look for vulnerabilities in low-level devices running in one slice, providing examples of home automation tools or gaming devices that users are typically slow to update. That attacker would then navigate up that network slice and look for other potentially vulnerable devices running in nearby network slices to conduct a horizontal attack.

“Five minutes on Google and you can get default passwords on a lot of these vendor devices and can then basically run scripts through the infrastructure in gray spaces to be able to find and exploit what parts of this attack surface are actually misconfigured,” Rahman said.

Network slicing security guidance from NSA, CISA

The National Security Agency (NSA) and Cybersecurity and Infrastructure Security Agency (CISA) have co-published 5G Network Slicing: Security Considerations for Design, Deployment, and Maintenance. This guidance presents recommendations to address some identified threats to 5G standalone network slicing and provides industry-recognized practices for the design, deployment, operation and maintenance of a hardened 5G standalone network slices, including the following:

  • Ensure that controls implemented by the 5G system cannot be bypassed using direct access to cloud resources.
  • Establish that necessary network connections between the components of the 5G system are established and permit no other connections.
  • Protect data storage used by the 5G system from access, tampering, or deletion by any unauthorized parties.
  • Establish and maintain mechanisms for monitoring the operation of the 5G system, especially resource usage, actions of authorized cloud administrators, and network traffic flows. This supports both real-time and forensic analysis of cloud operation to support assurance for the 5G services.

This is Part 2 of a three-part SDxCentral series on 5G and security. Part 1 is about 5G and the IoT, and Part 3 will discuss 5G and private networking.