Nokia envisions a growing role in network security as it expands its reach across extended detection and response (XDR); security orchestration, automation and response (SOAR); endpoint detection and response (EDR); managed services; and consulting. 

The vendor leans heavily on data gleaned from its Threat Intelligence Lab and algorithms developed at Nokia Bell Labs to bolster its security apparatus for network operators and enterprises, according to Mary O’Neill, VP of security at Nokia. 

“There are so many security companies out there in the industry. Security is a really fragmented industry but we have decided that there is an opportunity for us and a need for us to play in security for fixed and mobile networks,” she said in a phone interview.

“Everything is driven by intelligence and machine learning,” including Nokia’s recently released NetGuard XDR Security Operations and other security products that pull data from Nokia’s threat intelligence outfit, O’Neill said.

Nokia Constructs Cybersecurity Dome

Cybersecurity Dome, a new product introduced this month by Nokia, uses a combination of machine learning, EDR, and SOAR, to allow communications service providers to monitor, detect, and automatically remediate security vulnerabilities. 

“What we are able to do is take a topology of a 5G network, which consists of the radio access network (RAN), core, and transport, and allow a service provider to visualize that network and overlay a threat index of what is happening in that network from a security perspective, and then enable them to take action,” O’Neill explained.

Nokia approaches security from three different angles, including standards that form the basis of fundamental security requirements and equipment vendors that also provide a level of security in their products, she said. 

Nokia’s security team addresses the third layer of security, focused on operating and maintaining the security of a network. This includes authentication, audits on network functions to ensure security parameters remain unchanged, and machine learning algorithms that detect anomalous behavior and allow operators to fix those problems, O’Neill explained.

Nokia currently monitors more than 200 million connected devices globally and publishes regular reports on malware activity in fixed and mobile networks. Kevin McNamee, security product manager at Nokia, runs the lab that has been monitoring threats in mobile networks for the last decade.

Increased Attack Surface Greets 5G Operators

5G is designed to improve the security stature of networks by using an HTML to web services type of interface to authenticate communication across control plane functions and network infrastructure, and allow for network segmentation via slicing, he said.

The mobile communications technology also secures user data, unified data management, access and mobility management, and session management functions with authentication, and introduces a security protection proxy that allows for more secure and controlled inter-carrier communications, McNamee explained. 

However, 5G also introduces new functions and services that increase the attack surface, he said.

Among those new surfaces, Nokia is particularly concerned and focused on preventing malware in IoT devices, distributed denial-of-service (DDoS) attacks, and security gaps in mobile edge computing, he said. 

Many small IoT devices have very little natural protection or visibility on the network, mobile edge computing puts services from multiple vendors out at the edge running in the cloud or small data centers, and increased bandwidth capabilities in 5G increase the threat surface for possible DDoS attacks, McNamee said.

All of this requires network operators to improve network monitoring and initiate automated responses to threats. “You have to enable your security operations team to be able to detect the threats as they occur and then take action immediately to prevent any incidents in the network,” he said. 

“Given the expanded footprint and attack surface, the ability for the security operations team to be able to visualize what's going on and take action, particularly automated action, is going to be very, very important, particularly for some of these new things like the mobile edge cloud,” he added. “That’s going to be a challenge with all those sort of multi-vendor applications hanging out at the edge of the network — [they] have to be managed, have to be secure.”

Nokia Stretches 5G Security Posture

Nokia also claims a unique position in the security market due to its central focus on mobile and fixed network architecture. 

“Within the security industry, there’s a lot of companies out there that can do a really good job of helping [carriers] with a breach. But the thing is, most of these companies, their background is enterprise IT network security, and sometimes the techniques that they would use or recommend do not necessarily apply in the mobile space,” McNamee said.

“If such an event does happen, and probably down the road this is going to occur, we provide the expertise to enable the service provider to fix the problem,” he added.

Nokia also strengthens its security services by partnering with firewall vendors, intrusion detection vendors, and security information and event management (SIEM) vendors to address common security problems, according to McNamee.

“We're not trying to do everything in the mobile space, so certainly it involves third-party vendors that supply firewalls and components like that. So when you combine that with the standards, plus the enhancements that Nokia brings, I think we can create a very secure network for our customers,” he said.