Nokia doubled down on 5G network security, opening a new security testing and verification lab and launching a program to address 5G WAN security needs.

“What is very interesting is it’s not just 5G we have to deal with but it’s the cloud because the 5G core is going to be cloud-based,” said Kevin McNamee, director of Nokia’s Threat Intelligence Lab, in an earlier interview at MWC 2019 in Barcelona, Spain. “We at Nokia are putting together an end-to-end security story for 5G.”

Today’s announcement about the new 5G security lab and security program help flesh out that end-to-end story.

“First of all, there’s potentially a lot more bandwidth and a lot more devices — particularly IoT devices — that are going to be deployed on the network,” McNamee continued. “And they are not just communicating with the internet, they are communicating with each other, and that opens up a new attack surface.”

SDN with distributed cloud infrastructure and augmented intelligent control systems will allow 5G networks to scale to accommodate the projected billions of connected things, systems, machines, and people. However, open interfaces and commonly available technology also introduce new networking infrastructure security challenges, as does the addition of billons of unverified devices.

In fact, Nokia’s 2019 Threat Intelligence Report found IoT botnet activity represented 78% of malware detection events in communication service provider networks last year. This is more than double the rate in 2016, when botnets were first seen in significant numbers — IoT botnets accounted for 33% that year. And these types of attacks will likely become even worse as operators roll out 5G networks, McNamee said.

The new security program builds on Nokia’s earlier Design For Security (DFSEC) process that tests each product prior to commercial release. Nokia calls the new program DFSEC 2.0 and says it will focus on additional verification work specific to 5G end-to-end (E2E) identity management; network slicing and SDN security; virtualization; and operations, administration and management (OAM), including patch management.

Future X Security Lab

Also, Nokia is opening the Future X Security (FXSec) Lab as an extension of its Future X network lab in Nokia Bell Labs in Murray Hill, New Jersey. This 5G security lab will be open to communications service providers and industries to facilitate joint testing and verification of industrial automation products and technologies in private LANs and across public WANs.

In building its security approach for LAN and WAN, Nokia will incorporate Nokia Bell Labs’ research to create network slicing security solutions based on seven research areas:

  • Accountable security, which provides fail-proof identification of industrial IoT devices in mobile and dynamic environments.
  • Physical and virtual device integrity protection that provides scalable device attestation (hardware, firmware, and software) across the supply chain.
  • Artificial-intelligence (AI) enabled threat detection and mitigation for network slices.
  • Fine-grained security policy management, which dynamically tailors network slice elements to meet specified security requirements.
  • Dynamic data protection, which addresses the issue of data isolation across mobile devices, applications, and slices.
  • Microservice behavioral fingerprinting, which is a machine-learning based anomalous behavior detection of third-party and open-source 5G services.
  • Paradigm shift in design for security that provides run-time mitigation of potential security concerns with rapid feedback into development cycle using DevSecOps models.