Telecommunications giant Vodafone is working with the European-based technology research center i2CAT Foundation to tap open radio access network (RAN) automation principles to help power multi-vendor cybersecurity systems, with an initial focus on a security information and event management (SIEM) system.
The work is looking to use open RAN principles of open interfaces that can support plug-and-play interoperability between hardware and software from multiple vendors. This would allow for greater use of automated and virtualized architectures that can replace manual tasks associated with traditional networks.
Specifically, Vodafone and i2CAT are using machine learning (ML) to manage and analyze multi-vendor open RAN network logs. This information can provide insight into interactions like successful login or failed access attempts “that can be used to enhance security and detect threats,” the firms noted.
This work will initially be targeted at the design of a SIEM systems that can flag potential security threats like unauthorized access, distributed denial-of-service (DDoS) attacks or “man-in-the-middle interceptions.” They plan on testing the ability to parse through different log types to classify and manage potential threats.
That insight can then be integrated with a SIEM platform and main open RAN components, including the RAN intelligence controller (RIC) “to fix faults and respond to cyberthreats faster and more cheaply.”
RIC in the middle of open RAN
The RIC operates in the middle of an open RAN deployment as a kind of linkage to the wider network. It allows operators to deploy xApps and rApps that then allow operators to design and control RAN functions, providing administrative RAN sovereignty over functions that are typically implemented as proprietary features on base stations. These “apps” are microservice-based applications operating in near-real time (xApps) and non-real time (rApps) that provide an operator with more control over their open RAN environments.
The Vodafone and i2CAT efforts will include a proof-of-concept (PoC) that includes log management of automated rApps used for applications like traffic steering and energy management. Results of the test will be shared with the O-RAN Alliance industry trade and standards group.
Vodafone has been working for years on RIC testing for its own ambitious open RAN plans.
The combined efforts, which is dubbed the “Holistic ORAN Logging and Metrics Security Shield” (HOLMES), will be based out of Vodafone’s recently opened Malaga, Spain, facility that is targeted at developing open RAN silicon. The operator pledged to invest $250 million into the facility over the next several years, and gained ecosystem participation from players like Arm, Broadcom, Dell Technologies, Intel, Qualcomm and Xilinx.
That location is also close to the Barcelona, Spain-based i2CAT Foundation, which is a research and innovation center. It was formed in 2003 to tap into local and European-wide research and development projects focused on 5G, 6G, IoT, immersive technologies, cybersecurity, artificial intelligence (AI) and blockchain to help design and build new digital platforms.
Vodafone said it expects this work to provide it with a unified multi-vendor dashboard where it can control open RAN “events over a wide geographical area.” The systems is also expected to provide operational cost savings by automating the processing and analysis of multi-vendor logs; strengthen security by being able to more quickly detect and mitigate threats across different vendor environments; and make it easier to satisfy compliance with regulatory and industry standards.
“It will enable us to automate more manual tasks associated with traditional networks to respond even faster to fluctuations in demand, manage energy consumption more effectively, launch new features quicker and keep ahead of the ever-changing threat landscape,” Francisco Martin, head of open RAN at Vodafone, noted in a statement.
SIEM security for network slicing?
This could be increasingly important as operators look to attract revenue-generating enterprise applications onto their expensive 5G network deployments. One of the more oft-cited examples is the use of network slicing technology to support dedicated enterprise traffic.
Despite recent efforts, network slicing security remains an ongoing concern.
Rodrigo Brito, head of cybersecurity for Nokia’s Cloud and Network Services business, told SDxCentral in an interview last year that network slicing deployments have been slow to materialize as operators remain concerned over opening up a potential security attack vector. This concern is heightened by the recent push toward further opening up network APIs to allow operators to better monetize their 5G network investments.
Deloitte during a presentation at the 2022 RSA Conference walked through research that showed the potential to breach a device running in one network slice to see if they could then work laterally into breaching a device running in an adjacent network slice.
Abdul Rahman, associate VP at Deloitte, explained that the thought process was that an attacker could look for vulnerabilities in low-level devices running in one slice, providing examples of home automation tools or gaming devices that users are typically slow to update. That attacker would then navigate up that network slice and look for other potential vulnerable devices running in nearby network slices to conduct a horizontal attack.
“Five minutes on Google and you can get default passwords on a lot of these vendor devices and can then basically run scripts through the infrastructure in grey spaces to be able to find and exploit what parts of this attack surface are actually misconfigured,” Rahman said.
Once breached, an attacker can run different attack probes to gain a virtual picture, or attack graph, of that network architecture. This will then allow them to hunt for other potential misconfigurations or weak points further up the stack or slice.
Comments