Opens in a new tab
vmblog logo 2024 wht (updated)

Boosting 5G Core with runtime security

Share: 

David Marshall | Published: October 30, 2023

By László Békefi, Core Security Architect, Cloud and Network Services at Nokia

In recent years, the telecommunications industry has witnessed a profound transformation driven by the adoption of cloud technologies and the relentless rise of cybersecurity risks. As communication service providers (CSPs) migrate critical infrastructure to the cloud, they confront a challenging landscape.

Among the key strategies employed to address these challenges, runtime security is a linchpin in safeguarding 5G core networks; and one that comes at a critical time, given the shift to an ever-evolving multi-cloud landscape.

The shift in infrastructure security

The advent of cloud adoption has reshaped the way we think about infrastructure security. Traditional “walled-garden” approaches are no longer sufficient to defend against sophisticated cyber threats. Instead, a paradigm shift has occurred, emphasizing defense in depth and zero-trust principles. CSPs have the responsibility of securing the underlying components of cloud services, while application developers are tasked with safeguarding the applications and data processed and stored in the cloud.

The security architecture of 5G core adheres to the specifications outlined by the 3rd Generation Partnership Project (3GPP), encompassing a comprehensive set of security requirements. Building upon the security foundation of 4G systems, the architecture of 5G integrates equivalent security measures fortified by enhanced protections against evolving security threats.

Deploying applications across multiple cloud environments introduces a host of complex challenges. While development teams often integrate robust security controls into the development pipeline, these controls may fall. Factors contributing to cloud security failures include many things we’ve heard and seen before: misconfigured cloud services; use of vulnerable software components; insider threats; lack of encryption; and inadequate authentication and authorization mechanisms. In this, runtime security plays a role.

Runtime security: a proactive approach

Runtime security is a proactive cybersecurity approach that involves continuous monitoring of applications and systems during their execution. Its primary objective is to detect any abnormal or malicious behavior that could signify a security threat. The concept of runtime security evolved with the introduction of intrusion detection systems (IDS) and intrusion prevention systems (IPS) in the early 2000s.

The demand for upgraded 5G cybersecurity models will only continue to rise. As a result, the 5G network transitions and the development of Virtual Network Functions (VNF) and Container Network Functions (CNF) will present new challenges for telecom infrastructure. A telecom-optimized detection and response solution should incorporate a lightweight agent to continuously monitor network activity and swiftly identify threats.

In a 5G network infrastructure, a telco-specialized Extended Detection and Response (XDR) can detect vulnerabilities and attacks on the 5G core, RAN, transport or slice lifecycle. Unlike older Endpoint Detection and Response (EDR) or XDR systems designed for enterprise IT, the modern XDR brings a telco-specific toolbox of procedures and playbooks that enable CSPs to react to security and privacy emergency events.

To illustrate the effectiveness of such runtime security, consider a scenario where a malicious actor attempts to exploit a vulnerability in a 5G core network deployed across multiple CNFs. Traditional security controls may not immediately detect this threat.

However, a telco-optimized EDR system uses an agent-based approach to monitor network activity and detect threats in runtime. The collected network data is consolidated, indexed and analyzed to identify intrusions and behavioral anomalies. With its modular architecture, telecom networks can benefit from runtime monitoring, fast automated incident response and increased security against the evolving threat landscape.

This proactive detection allows security teams to respond swiftly, mitigating the risk of data breaches and cyberattacks.

Tailoring security to the 5G core

While commercial XDR solutions come with predefined detection rules, these may not always align with the specific needs of a particular software product or operational process. However, modern XDR solutions tailored for CSPs offer a variety of procedures and choices that enable them to respond effectively to security and privacy events.

By incorporating custom detection rules and leveraging advanced detection and response techniques, runtime telco-optimized runtime detection and response security filters out noise, reduces false positives and fortifies overall security. As CSPs navigate the multi-cloud landscape and confront ever-evolving cybersecurity risks, runtime security will play an indispensable role in protecting 5G core networks and the sensitive data they carry.

##

ABOUT THE AUTHOR

László Békefi, Core Security Architect, Cloud and Network Services at Nokia

Laszlo Bekefi 

As a Core Security Architect within Nokia’s Cloud and Network Services, László Békefi focuses on container runtime security, application of zero-trust principles in relation to FOSS, shift-left security in DevSecOps and open-source vulnerability management. He previously worked in product management roles, developing evolution strategy to cloud-native products for Nokia.