Networks running on completely cloud native and open radio access network (RAN) architecture have much to prove, and that includes the caliber of security.
The extent to which open RAN or cloud-native technologies impact the security of a 5G network isn’t so much the concern as how operators and their respective vendors approach and implement security overall, according to operator and RAN supplier executives.
Cloud native and open RAN are complementary, but not mutually exclusive so security must be adhered to both based on their specialized requirements, Nishant Batra, chief strategy and technology officer at Nokia, explained in a press briefing.
Nokia Identifies Unique Needs in Cloud Native, Open RAN“When you go cloud native, the security stature will not change just by going cloud native. The security stature will change as to where you put the workload. If you put that cloud native radio access software workload on the edge, the far edge, you have to make sure the right security parameters, the right firewalling,” are implemented, he said.
“If you’re going to put it on public cloud then that will require a huge change, a step change in the security infrastructure requirements for a 5G network,” Batra explained. Private clouds, distributed clouds, and public clouds all have unique characteristics that must be addressed from a security perspective, he added.
Security in open RAN, meanwhile, leans heavily on the profiles adopted and specialized services deployed across a network, Batra said. “When it comes to open RAN, I actually feel that here we have to make sure that we look at the different profiles, which are still fairly immature, and we’re investing a lot of Nokia effort to make sure that we contribute to that. And there in those profiles, one has to then go through rigorous proof of concepts to ensure that security is maintained.”
There is no silver bullet for security in any context, and that applies to open RAN and cloud native technologies all the same.
Concerns about security in a cloud native open RAN network aren’t heightened compared to traditional and more tightly integrated network architecture because any framework requires a resilient and proactive approach to security, Tommi Uitto, president of Nokia’s Mobile Networks unit, told SDxCentral in a recent phone interview.
“It doesn’t really make a difference whether it’s bare metal or cloud from that standpoint,” he said, adding that the level of development and interest in cloud technologies at large will benefit 5G open RAN by extension. “Of course there’s just so much focus anyway on cybersecurity in cloud computing that it really doesn’t make a big difference,” Uitto said.
Conversely, Nokia's closest competitor Ericsson has cited a series of what it describes as unresolved security challenges and shortcomings in open RAN. The Swedish vendor claims increased virtualization in the cloud and shared resources between different pieces of hardware will introduce new security risks.
Dish Embodies Zero Trust Under Glaring LightDish Network, a cloud native and open RAN pioneer in the U.S. that plans to deploy 5G service in its first city, Las Vegas, by this fall, effectively shares this assessment. The notion that open radio access network (RAN) architecture is also more broadly open to security threats is a bad misconception, Marc Rouanne, Dish’s EVP and chief network officer, told SDxCentral.
Rouanne said he views network security in contrasts — darkness and light. “Personally, I have a tendency to be more afraid and scared in darkness than in clear, visible light. Openness allows you to have visibility and it allows you to put your defense and your security where you see the threats might be coming,” Rouanne said.
Dish recently announced network security contracts with Allot for real-time threat detection and response, Nokia for security orchestration, and Palo Alto Networks for software-based firewalls at the container level of its network.
Traffic on 5G networks that are currently available in the U.S. is all mixed together on the same routes, “it’s not sliced,” Rouanne said. “So if there is a threat, it’s impacting everyone. Whereas with our sliced, orchestrated network, we can separate the traffic and isolate it even on different routes or hardware if needed.”
The operator is also, more broadly, fixated on maintaining unimpeded access to its software supply chain so it can source, test, challenge, scan, and constantly check the security stature of any piece of code that touches or interacts with its network, Rouanne explained. Dish also claims to have security embedded into its hardware because it’s brand new and features the latest technology on the market.
Dish’s Reinvisions Security on Untested Network“When I think of the existing networks that have been built over the last 20 years, I know because I was selling them, there are so many [pieces of] hardware that have no embedded security. It’s scary and that’s nothing we want to do. I don’t know how you can sleep at night with all that hardware in the field,” he said.
Dish’s security policy is strictly zero trust. “We trust nothing. We trust no vendor. We trust nobody. We just check everything and, once we check, we put security at every layer,” Rouanne said.
“Visibility is what makes you smarter when it comes to security,” and Dish is assuming all responsibility for the security of its network, he said. “I don’t like the term shared responsibility when it comes to security. I like zero trust. So we don’t trust our vendors, but we ask our vendors not to trust their supply chain, so we are auditing the vendors to make sure they also have zero trust, and that’s the way we qualify them.”
Every layer of the network has to adhere to a zero-trust approach, he said. “Everybody has to make sure that they are fully securing everything they can secure. Shared responsibility is very dangerous because at the end of the day you don’t know what you’re doing. … Visibility is what makes you smarter when it comes to security.”
Comments