Nokia is finding post-quantum computing-linked cyberattacks and network slicing an increasingly hot security topic among telecommunication operators looking to protect their 5G network deployments.
Rodrigo Brito, head of cybersecurity for Nokia’s Cloud and Network Services business, told SDxCentral in an interview ahead of the RSA Conference that those issues are key for operators in dealing with new potential security challenges with 5G technology.
“The No. 1 concern is if they are deploying a 5G network, how can they protect their 5G network because it's something new. It's new technology. It's a new paradigm with a completely different type of deployment of authentication in between the network functions. There are many things that change. How do I secure that network? That's a key topic,” Brito said.
Post-quantum takes that challenge a step further by bringing in the potential for attackers to more easily break current encryption standards. Brito said Nokia is being asked what it’s doing now to prepare for this situation and how can it help operators protect their network resources.
“The start that we advise is to have a crypto inventory or understanding of where they have digital certificates and which are the ciphers that are used on those digital certificates, and based on that they know if the ciphers are going to be safe or not,” Brito explained. “They have the power of knowing where they have the digital certificates and they have the possibility to automatically replace the certificates that have a cipher that is not quantum safe.”
Brito noted that the industry is still working through figuring out which certificates are quantum safe, but that issue is still a challenge by “store now, decrypt later” cyberattacks. These are attacks where a hacker sucks up certificates today and stores them for later when post-quantum computing could allow for those certificates to be breached.
“If there are ciphers that are now considered safe there is the fear that there are players and hacker groups that are storing data, knowing that they cannot decrypt that data now because the qubits of the quantum computers are not enough yet, but perhaps in 10 years from now they will be able to decrypt that data, and that creates a lot of uncertainty,” Brito said.
This is especially difficult for telecommunication operators that have to work through potentially millions of certificates tied to their geographically diverse network operations and customer equipment.
“If they have encryption used for all the base stations, if they have encryption used for the IoT devices that they have on their network, or for their set-top-boxes, it's not easy to go through the millions of digital certificates, it’s difficult without automation to keep track and replace those when needed,” Brito added.
Operators are actively attempting to prepare for this challenge.
Verizon conducted trials deploying a quantum key distribution (QKD) network and tested quantum-safe virtual private networks (VPNs), while internally preparing its networks against post-quantum threats. It also explored data protection methods using post-quantum cryptography (PQC).
AT&T is also working through the challenges, recently telling SDxCentral that it wants to be quantum ready by 2025.
Nokia finds 5G network slicing, API impact on securityRodrigo also pointed to cyberattack concerns tied to 5G-enabled network slicing services. Network slicing is the capability to dedicate specific spectrum channels in a 5G network to a specific customer or use case.
However, concerns have been raised that network slicing could open up attack vectors to private 5G network deployments if not properly instantiated and maintained.
Deloitte during a presentation at last year’s RSA Conference walked through research that showed the potential to breach a device running in one network slice to see if they could then work laterally into breaching a device running in an adjacent network slice.
Abdul Rahman, associate VP at Deloitte, explained that the thought process was that an attacker could look for vulnerabilities in low-level devices running in one slice, providing examples of home automation tools or gaming devices that users are typically slow to update. That attacker would then navigate up that network slice and look for other potential vulnerable devices running in nearby network slices to conduct a horizontal attack.
“Five minutes on Google and you can get default passwords on a lot of these vendor devices and can then basically run scripts through the infrastructure in grey spaces to be able to find and exploit what parts of this attack surface are actually misconfigured,” Rahman said.
Once breached, an attacker can run different attack probes to gain a virtual picture, or attack graph, of that network architecture. This will then allow them to hunt for other potential misconfigurations or weak points further up the stack or slice.
Brito noted that network slicing deployments have been slow to materialize, but operators remain concerned over opening up a potential security attack vector. This concern is heightened by the recent push toward further opening up network APIs to allow operators to better monetize their 5G network investments.
“When we expose the API's and with our strategy of enabling our customers to provide APIs to to allow them to monetize the network data and enable applications, we provide security controls that need to be in place so that those APIs are provided on a safe way,” Brito said of Nokia's security efforts.
Comments