Protecting control and user plane separation in mobile networks
By using a security platform to parse PFCP messages and perform stateful checks in mobile networks, the security challenges of the separation of control and user planes in mobile networks are addressed, enabling the detection and prevention of DoS attacks and SEID spoofing, and improving the security of network communication.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- PALO ALTO NETWORKS INC
- Filing Date
- 2021-06-16
- Publication Date
- 2026-04-28
AI Technical Summary
In mobile networks, existing technologies struggle to effectively protect communication security when control and user planes are separated, especially in 5G and 4G mobile networks, where there are risks of DoS attacks, SEID spoofing, and PFCP protocol attacks, and a lack of effective security monitoring and policy applications.
The security platform extracts parameters by parsing PFCP messages, performs stateful inspections, detects and prevents DoS attacks and SEID spoofing, applies security policies to protect the separation of control and user planes in mobile networks, and uses firewalls or next-generation firewall technologies in conjunction with network sensors and cloud security services for real-time monitoring and analysis.
It achieves effective protection of the separation of control and user planes in mobile networks, prevents DoS attacks and SEID spoofing, improves the security and reliability of network communication, and is suitable for various environments of 5G and 4G networks.
Smart Images

Figure CN115989661B_ABST
Abstract
Description
Background Technology
[0001] Firewalls typically protect a network from unauthorized access while allowing authorized communication to pass through. A firewall is usually a device or set of devices that provides firewall functionality for network access, or software that runs on a device such as a computer. For example, a firewall may be integrated into the operating system of a device (e.g., a computer, smartphone, or other type of device with network communication capabilities). Firewalls may also be integrated into computer servers, gateways, network / routing devices (e.g., network routers), or data appliances (e.g., security appliances or other types of specialized devices), or run as software thereon.
[0002] Firewalls typically deny or allow network traffic based on sets of rules. These sets of rules are often called policies. For example, a firewall can filter inbound traffic by applying rules or policy sets. A firewall can also filter outbound traffic by applying rules or policy sets. Firewalls can also perform basic routing functions. Attached Figure Description
[0003] Various embodiments of the invention are disclosed in the following detailed description and accompanying drawings.
[0004] Figure 1 This is a block diagram of an architecture for a 5G wireless network with a secure platform for protecting the control and user planes in a mobile network, according to some embodiments.
[0005] Figure 2A This is a block diagram of an architecture for a 4G wireless network with a secure platform for protecting the control and user planes in a mobile network, according to some embodiments.
[0006] Figure 2B This is another block diagram of an architecture for a 4G wireless network with a secure platform for protecting the control and user planes in a mobile network, according to some embodiments.
[0007] Figure 2C This is another block diagram of an architecture for a 4G wireless network with a secure platform for protecting the control and user planes in a mobile network, according to some embodiments.
[0008] Figure 2D This is another block diagram of an architecture for a 4G wireless network with a secure platform for protecting the control and user planes in a mobile network, according to some embodiments.
[0009] Figure 3A This is a protocol sequence diagram used in the PFCP session establishment process.
[0010] Figure 3B This is a protocol sequence diagram used in the PFCP session modification process.
[0011] Figure 3C This is a protocol sequence diagram used in the PFCP session release process.
[0012] Figure 4 This is a functional diagram of hardware components for protecting network devices with separate control and user planes in mobile networks, according to some embodiments.
[0013] Figure 5 This is a functional diagram of the logical components of a network device with separated control and user planes in a mobile network, according to some embodiments.
[0014] Figure 6 This is a flowchart of a process for protecting the separation of control and user planes in a mobile network, according to some embodiments.
[0015] Figure 7 This is another flowchart of a process for protecting the separation of control and user planes in a mobile network, according to some embodiments. Detailed Implementation
[0016] This invention can be implemented in a variety of ways, including as a process; an apparatus; a system; a component of matter; a computer program product embodied on a computer-readable storage medium; and / or a processor, such as a processor configured to execute instructions stored on and / or provided by memory coupled to the processor. In this specification, these implementations or any other form in which the invention may take may be referred to as techniques. Generally, the order of steps of the disclosed processes may be varied within the scope of this invention. Unless otherwise stated, components such as processors or memory described as being configured to perform a task may be implemented as general components temporarily configured to perform the task at a given time, or manufactured as specific components to perform that task. As used herein, the term "processor" refers to one or more devices, circuits, and / or processing cores configured to process data such as computer program instructions.
[0017] The following provides a detailed description of one or more embodiments of the present invention, together with accompanying drawings illustrating the principles of the invention. The invention has been described in conjunction with such embodiments, but the invention is not limited to any particular embodiment. The scope of the invention is limited only by the claims, and the invention includes many alternatives, modifications, and equivalents. To provide a thorough understanding of the invention, numerous specific details are set forth in the following description. These details are provided for illustrative purposes, and the invention can be practiced according to the claims without requiring some or all of these specific details. For clarity, technical materials known in the art related to the invention have not been described in detail so as not to unnecessarily obscure the invention.
[0018] Firewalls typically protect networks from unauthorized access while allowing authorized communication to pass through. A firewall is generally a device, set of devices, or software running on a device that provides firewall functionality for network access. For example, a firewall can be integrated into the operating system of a device (e.g., a computer, smartphone, or other type of device with network communication capabilities). Firewalls can also be integrated into various types of devices or security devices, or implemented as software applications on various types of devices or security devices, such as computer servers, gateways, network / routing devices (e.g., network routers), or data appliances (e.g., security appliances or other types of dedicated devices).
[0019] Firewalls typically deny or allow network traffic based on sets of rules. These sets of rules are often referred to as policies (e.g., network policies or network security policies). For example, a firewall can filter inbound traffic by applying rules or policy sets to prevent unwanted external traffic from reaching a protected device. A firewall can also filter outbound traffic by applying rules or policy sets (e.g., allowing, blocking, monitoring, notifying, or logging and / or other actions can be specified in firewall / security rules or firewall / security policies, as described herein, actions that can be triggered based on various criteria). Firewalls can also apply antivirus protection, malware detection / prevention, or intrusion protection by applying rules or policy sets.
[0020] Security devices (e.g., security appliances, security gateways, security services, and / or other security devices) may include various security functions (e.g., firewalls, anti-malware, intrusion prevention / detection, proxies, and / or other security functions), networking functions (e.g., routing, Quality of Service (QoS), workload balancing of network-related resources, and / or other networking functions), and / or other functions. For example, routing functions may be based on source information (e.g., source IP address and port), destination information (e.g., destination IP address and port), and protocol information.
[0021] Basic packet-filtering firewalls filter network traffic by inspecting individual packets transmitted over the network (e.g., packet-filtering firewalls or first-generation firewalls, which are stateless packet-filtering firewalls). Stateless packet-filtering firewalls typically inspect the individual packets themselves and apply rules based on the inspected packets (e.g., using a combination of the packet's source and destination address information, protocol information, and port number).
[0022] Application firewalls can also perform application-layer filtering (e.g., using application-layer filtering firewalls or second-generation firewalls, which operate at the application level of the TCP / IP stack). Application-layer filtering firewalls or application firewalls can typically identify certain applications and protocols (e.g., web browsing using Hypertext Transfer Protocol (HTTP), Domain Name System (DNS) requests, file transfer using File Transfer Protocol (FTP), and various other types of applications and other protocols such as Telnet, DHCP, TCP, UDP, and TFTP (GSS)). For example, application firewalls can block unauthorized protocols that attempt to communicate through standard ports (e.g., unauthorized / policy-incompatible protocols attempting to sneak through using non-standard ports of the protocol can typically be identified using application firewalls).
[0023] Stateful firewalls can also perform state-based packet inspection, where each packet is examined within the context of a series of packets associated with a flow / packet stream of packets transmitted over the network (e.g., stateful firewalls or third-generation firewalls). This firewall technique is often referred to as stateful packet inspection because it maintains a record of all connections passing through the firewall and is able to determine whether a packet is the start of a new connection, part of an existing connection, or an invalid packet. For example, connection state itself can be one of the criteria for triggering rules within a policy.
[0024] As discussed above, advanced or next-generation firewalls can perform stateless and stateful packet filtering, as well as application-layer filtering. Next-generation firewalls can also perform additional firewall technologies. For example, some newer firewalls (sometimes referred to as advanced or next-generation firewalls) can also identify users and content. In particular, some next-generation firewalls are expanding the list of applications they can automatically identify to thousands of applications. Examples of such next-generation firewalls are commercially available from Palo Alto Networks (e.g., Palo Alto Networks' PA series next-generation firewalls and Palo Alto Networks' VM series virtualization next-generation firewalls).
[0025] For example, Palo Alto Networks' next-generation firewall enables enterprises and service providers to use a variety of identification technologies to identify and control applications, users, and content, rather than just ports, IP addresses, and packets. These identification technologies include, for example, App-IDs for accurate application identification. TM (e.g., application ID), User-ID used for user identification (e.g., by user or user group). TM (e.g., user ID), and Content-ID used for real-time content scanning (e.g., controlling web surfing and restricting data and file transfers). TM(For example, content ID). These identification technologies allow enterprises to securely enable application purposes using business-related concepts, rather than following the traditional approach provided by conventional port-blocking firewalls. Furthermore, dedicated hardware implemented as, for example, dedicated appliances, typically provides a higher level of performance for application inspection than software running on general-purpose hardware (e.g., security appliances such as those offered by Palo Alto Networks, which utilize dedicated, function-specific processing tightly integrated with a single-channel software engine to maximize network throughput while minimizing latency in Palo Alto Networks' PA Series next-generation firewalls).
[0026] Technical and security challenges for service providers in today's mobile networks
[0027] Converged (mobile and fixed) network operators worldwide are currently in the process of deploying standalone 5G mobile network technology. In 5G mobile networks, control and user plane separation (CUPS) will be used to provide connectivity for enterprise customers. Accordingly, securing and verifying communication between control network functions in the 5G mobile network (e.g., one or more Session Management Functions (SMFs) located in the Central Packet Core / Cloud Packet Core and one or more User Plane Functions (UPFs) located at the customer premises / access site / distribution site) will be crucial.
[0028] Therefore, service provider networks present technical and security challenges for devices within mobile networks. Accordingly, new and improved security technologies are needed for devices in such service provider network environments (e.g., mobile networks). Specifically, new and improved solutions are needed to monitor such network traffic and apply security policies (e.g., firewall policies) to devices communicating on service provider networks.
[0029] Overview of Control and User Plane Separation Techniques for Protecting Mobile Networks
[0030] Service provider networks face technical and security challenges in protecting the control and user plane separation in mobile networks. Specifically, new and improved technologies are needed to protect control and user plane separation in mobile network environments (e.g., 4G and / or 5G mobile networks). More specifically, new and improved solutions are needed for monitoring mobile network traffic and applying security policies (e.g., security / firewall policies) to protect control and user plane separation in mobile networks.
[0031] As will be further described below, PFCP is a 3GPP protocol used on the Sx / N4 interface between control plane and user plane functions (e.g., specified in 3GPP Technical Specification (TS) 29.244v15.7 for LTE; 5G; and the interface between control plane and user plane nodes (e.g., and newer releases / versions).
[0032] In some embodiments, new and improved techniques for protecting the stateful inspection of the Packet Forwarding Control Protocol (PFCP) with separation of control and user planes in mobile networks, which can be executed by a security platform, are disclosed, as will be further described below.
[0033] For example, a security platform in a 5G-based mobile network (e.g., a 5G mobile network) can extract certain information for establishing a PFCF session and tracking control message flow by parsing PFCP messages over the N4 interface between the Session Management Function (SMF) and the User Plane Function (UPF), thereby performing new and improved techniques for stateful checks of PFCP to protect the control and user plane separation in the mobile network.
[0034] As another example, a security platform in a 4G-based mobile network (e.g., a 4G mobile network) can extract certain information for establishing PFCF sessions and tracking control message flows by parsing PFCP messages over the Sxa interface between the Serving Gateway (SG)-C and SG-U, the Sxb interface between the Packet Data Network (PDN) Gateway-C and PDN Gateway-U, and the Sxc interface between the Service Detection Function (TDF)-C and TDF-U. This allows for the execution of new and improved techniques for stateful PFCP checks to protect the control and user plane separation in the mobile network.
[0035] Therefore, according to some embodiments, novel and improved security solutions are disclosed to facilitate the application of security (e.g., network-based security) to PFCP traffic using security platforms (e.g., firewalls (FW) / next-generation firewalls (NGFW), network sensors acting on behalf of firewalls, or another (virtual) device / component that can implement security policies using the disclosed techniques) in mobile networks (e.g., 4G / 5G mobile networks). For example, the disclosed techniques for protecting the separation of control and user planes in mobile networks can provide identification and prevention of attacks, including denial-of-service (DoS), session endpoint identifier (SEID) spoofing, and SEID guessing against Packet Forwarding Control Protocol (PFCP), in various 4G / 5G network locations, including local data networks, core networks, multi-access distributed edge locations, enterprise networks with local user plane functionality (UPF), and / or various other 4G / 5G network locations.
[0036] As further described below, various techniques for protecting control and user plane separation in mobile networks are disclosed. In some embodiments, a system / process / computer program product for protecting control and user plane separation in a mobile network, according to some embodiments, includes: monitoring network traffic on a mobile network at a security platform to identify Packet Forwarding Control Protocol (PFCP) messages associated with a new session, wherein the mobile network includes a 4G network or a 5G network; extracting multiple parameters from the PFCP messages at the security platform (e.g., a 5-tuple associated with the PFCP + node ID (optional), as further described below); and implementing a security policy on the new session at the security platform based on one or more of the multiple parameters to protect control and user plane separation in the mobile network.
[0037] For example, a security platform can parse PFCP messages to extract the following parameters: source IP address, SEID 1, destination IP address, SEID 2, and the protocol in use associated with PFCP. As another example, a security platform can parse PFCP messages to extract the node ID associated with PFCP.
[0038] In the example implementation, the security platform is configured with security policies to perform the detection and prevention of denial-of-service (DoS) attacks in order to protect the control and user plane separation in the mobile network.
[0039] In another example implementation, the security platform is configured with security policies to perform detection and prevention of Session Endpoint Identifier (SEID) spoofing attacks in order to protect the control and user plane separation in mobile networks.
[0040] The disclosed techniques for protecting the separation of control and user planes in mobile networks can be applied to facilitate a variety of protected mobile network solutions. As an example, mobile network operators can use the disclosed techniques to protect communication between cloud-based control infrastructure and distributed edge locations. As another example, enterprise customers with private 4G / 5G connectivity can use the disclosed techniques to protect communication between local user plane functions (UPFs) and cloud-based control infrastructure.
[0041] These and other embodiments and examples for protecting the separation of control and user planes in mobile networks will be further described below.
[0042] Example system architecture for protecting the separation of control and user planes in mobile networks
[0043] Typically, 5G refers to the fifth generation of mobile communication systems. The 3rd Generation Partnership Project (3GPP) comprises seven telecommunications standards development organizations (ARIB, ATIS, CCSA, ETSI, TSDSI, TTA, and TTC). This project covers cellular telecommunications network technologies, including radio access, core transport networks, and service capabilities. The specifications also provide hooks for non-radio access to the core network and for interaction with Wi-Fi networks and other organizations, including the ITU, IETF, and ETSI, which are developing 5G standards. Some improvements in the new 5G network standard include, for example, multi-edge computing, low latency (e.g., approximately less than 10 milliseconds (MS)), high throughput (e.g., multiple Gbps), distribution, network function virtualization infrastructure, and orchestration, analytics, and automation.
[0044] In 3GPP TS 23.501 v16.4.0, the 5G architecture (e.g., available at https: / / portal.3gPP.org / desktopmodules / Specifications / SpecificationDetails.aspx?specificationId=3144) (and newer releases / versions) is defined as service-based, and interactions between network functions (NFs) are represented in two ways: (1) a service-based representation, where NFs within the control plane (CP) enable other authorized network functions to access their services; and (2) a reference point representation, focusing on interactions between NF pairs defined by a point-to-point reference point between any two network functions.
[0045] In the 5G architecture, the user plane protocol stack between the access network and the core network above the backbone network will be based on the GPRS Tunneling Protocol User Plane (GTP-U) over UDP at the N3 interface (e.g., between the Radio Access Network (RAN) and UPF elements), and on the N4 interface (e.g., between UPF and SMF elements) on the Packet Forwarding Control Protocol (PFCP) over UDP. The control plane (NF) in the 5G system architecture should be based on a service-based architecture. HTTP / 2 will be the protocol used on top of the service-based interface. The new 5G access network protocol will be based on the Flow Control Transport Protocol (SCTP).
[0046] Therefore, in some embodiments, the disclosed techniques include providing a security platform (e.g., one or more security functions / one or more platforms may be implemented using a firewall (FW) / next-generation firewall (NGFW), a network sensor acting on behalf of the firewall, or another (virtual) device / component that may implement security policies using the disclosed techniques, such as PANOS implemented on a commercially available virtual / physical NGFW solution or another security platform / NFGW from Palo Alto Networks), which is configured to provide, for example, DPI capabilities (including stateful inspection) for GTP-U sessions and new HTTP / 2-based TCP sessions, which facilitate correlation between monitored GTP-U tunnel sessions and new HTTP / 2-based TCP sessions (as further described below), and, as another example, correlation between monitored GTP-U tunnels (e.g., on the N3 interface) and PFCP sessions (e.g., on the N4 / Sx interface).
[0047] In some embodiments, the security platform is configured to provide the following DPI capabilities: stateful inspection of N3 GTP-U tunnels and / or N4 GTP-U tunnels; content inspection of N3 GTP-U tunnels (e.g., inspecting the content of internal IP sessions within the N3 GTP-U tunnel) and / or N4 / Sx PFCP sessions (e.g., inspecting the content of N4 / Sx PFCP sessions); support for 3GPP Technical Specification (TS) 29.274 v15.3.0 Release 15 (e.g., and newer releases / versions) for processes used in 5G systems to support 5G cellular technology; and support for 3GPP Technical Specification (TS) 29.281 v15.4.0 Release 14 (e.g., and newer releases / versions) for the GTP-U protocol.
[0048] Figure 1 This is a block diagram of an architecture for a 5G wireless network with a secure platform for protecting the control and user planes in a mobile network, according to some embodiments. Specifically, Figure 1This is an example 5G mobile network environment for protecting the control and user plane separation in a mobile network, including security platforms 102a and 102b for protecting the control and user plane separation (e.g., one or more security functions / platforms may be implemented using a firewall (FW) / next-generation firewall (NGFW), a network sensor acting on behalf of the firewall, or another (virtual) device / component that may implement the security policy using the disclosed techniques), as further described below. As shown, the 5G mobile network environment may also include fixed / wired access as shown at 104, non-3GPP access such as Wi-Fi access as shown at 106, 5G radio access network (RAN) access as shown at 108, 4G RAN access as shown at 110, and / or other networks. Figure 1 (Not shown in the image) to facilitate data communications for subscribers (e.g., using user equipment (UE), such as smartphones, laptops, computers (which may be in a fixed location), and / or other cellular-enabled computing devices / equipment, such as CIoT devices, or other network-enabled devices), including access to various applications, web services, content hosting, and / or other networks via a central data network (e.g., the Internet) 120. Figure 1 As shown, each of the 5G network access mechanisms 104, 106, 108 and 110 communicates with 5G user plane functions 112a and 112b (e.g., via the S1-U interface), which communicate with 5G user plane functions 112a and 112b respectively through security platforms 102a and 102b.
[0049] Similarly, Figure 1 As shown, the N4 interfaces each provide an interface between the UPF 112a / b and the 5G core control / signaling functions, including a Session Management Function (SMF) 130 via PFCP over UDP. The core network 140 includes the SMF 130 communicating with the 5G user plane function 132, which in turn communicates with the central data network 120.
[0050] refer to Figure 1 Security platforms 102a and 102b are used to monitor network traffic communications. As shown, security platforms 102a and 102b (e.g., each including a firewall (FW), a network sensor acting on behalf of the firewall, or a (virtual) device / appliance of another device / component that can implement security policies using the disclosed techniques) monitor / filter network traffic communications in a 5G network. The security platforms 102a and 102b are configured to perform the disclosed techniques for protecting the control and user plane separation in mobile networks, as described above and further as described below.
[0051] Furthermore, security platforms 102a and 102b can also be connected via the Internet and cloud security services 122 (e.g., commercially available cloud-based security services such as WildFire). TM A cloud-based malware analysis environment, a commercially available cloud security service provided by Palo Alto Networks, includes automated security analysis of malware samples and analysis by security experts (or may utilize a similar solution from another vendor) for network communication. For example, cloud security service 122 can be used to provide dynamic preventative signatures against malware, DNS, URL, CNC malware, and / or other malware to a security platform, and to receive malware samples for further security analysis.
[0052] refer to Figure 1 Security platforms 102a and 102b perform stateful checks on PFCP messages (e.g., PFCP over UDP) on the N4 interface between UPF 112a and 112b and SMF 130, respectively, to extract certain information used to establish a PFCF session and to track control message flows, as will be further described below.
[0053] As will now become clear, one or more security platforms can be used to monitor / filter network traffic communications in various locations within a 5G network (e.g., a 5G network or a converged 5G network) to facilitate the separation of control and user planes in the mobile network.
[0054] Figure 2A This is a block diagram of an architecture for a 4G wireless network with a secure platform for protecting the control and user planes in a mobile network, according to some embodiments. Specifically, Figure 2A This is an example 4G mobile network environment for protecting the control and user plane separation in a mobile network. It includes security platforms 202a and 202b for protecting the control and user plane separation (e.g., one or more security functions / platforms may be implemented using a firewall (FW) / next-generation firewall (NGFW), a network sensor acting on behalf of the firewall, or another (virtual) device / component that can implement the security policy using the disclosed techniques), as further described below. The 4G mobile network environment may also include fixed / wired access (…). Figure 2A (not shown in the image), such as non-3GPP access such as Wi-Fi access (…). Figure 2A (not shown in the image), such as the 4G radio access network (RAN) shown at 204, and / or other networks ( Figure 2A(not shown in the image) to facilitate data communications for subscribers (e.g., using user equipment (UE), such as smartphones, laptops, computers (which may be in a fixed location), and / or other cellular-enabled computing devices / equipment, such as CIoT devices, or other devices enabling network communications), including access to various applications, web services, content hosting, etc., and / or other networks via a central data network (e.g., the Internet) 220.
[0055] like Figure 2A As shown, the 4G network access mechanism eNodeB 204 communicates with user plane network elements, including a combined serving gateway (SGW) and a packet gateway (PGW) for user plane traffic, shown as SGW-U+PGW-U 206, which communicates with SGW-U+PGW-U 206 through a security platform 202a.
[0056] For example Figure 2A As shown, the core network 210 includes control plane network elements, including a combined serving gateway (SGW) and a packet data network (PDN) gateway (PGW) for control plane traffic, shown as SGW-C+PGW-C 214, which communicate with PGW-U 216 via security platform 202b. The core network 210 includes PGW-U 216 for user plane traffic to facilitate access to the central data network 220. Specifically, the Sxa interface provides the interface between SGW-C 214 and SGW-U 206 via PFCP over UDP, and the Sxb interface provides the interface between PGW-C 214 and PGW-U 216 via PFCP over UDP.
[0057] As also shown, security platform 202a (e.g., and other security platforms may similarly communicate with security cloud services) also communicates with security service 222 (e.g., commercially available cloud-based security services, such as WildFire). TM (WF) is a cloud-based malware analysis environment, a commercially available cloud security service provided by Palo Alto Networks, which includes automated security analysis of malware samples and analysis by security experts (or may utilize similar solutions from another vendor) for network communications such as dynamic preventative signatures for malware, DNS, URLs, command and control (C&C), and / or various other security updates and / or cloud-based malware sample analysis.
[0058] refer to Figure 2ASecurity platforms 202a and 202b (e.g., which can be located in various locations to monitor Sxa, Sxb, and / or other communications) can be used to monitor network traffic communications, as referenced above. Figure 1 Similar descriptions and further descriptions below. In this example implementation, security platforms 202a and 202b, located in this example 4G mobile network environment, are used to monitor and parse PFCP messages (e.g., PFCP over UDP) on the Sxa interface between the Serving Gateway C shown at 214 and the Serving Gateway U shown at 206, and on the Sxb interface between the PDN Gateway C shown at 214 and the PDN Gateway U shown at 216, to extract certain information for establishing PFCF sessions and to track control message flows, as will be further described below.
[0059] Figure 2B This is another block diagram of an architecture for a 4G wireless network with a secure platform for protecting the control and user planes in a mobile network, according to some embodiments. Specifically, Figure 2B This is an example 4G mobile network environment for protecting the separation of control and user planes in a mobile network. It includes security platforms 202a, 202b, and 202c for protecting the separation of control and user planes (e.g., one or more security functions / platforms may be implemented using a firewall (FW) / next-generation firewall (NGFW), a network sensor acting on behalf of the firewall, or another (virtual) device / component that may implement the security policy using the disclosed techniques), as further described below. The 4G mobile network environment may also include fixed / wired access (…). Figure 2B (not shown in the image), such as non-3GPP access such as Wi-Fi access (…). Figure 2B (not shown in the image), such as the 4G radio access network (RAN) shown at 204, and / or other networks ( Figure 2B (not shown in the image) to facilitate data communications for subscribers (e.g., using user equipment (UE), such as smartphones, laptops, computers (which may be in a fixed location), and / or other cellular-enabled computing devices / equipment, such as CIoT devices, or other devices enabling network communications), including access to various applications, web services, content hosting, etc., and / or other networks via a central data network (e.g., the Internet) 220.
[0060] like Figure 2B As shown, the 4G network access mechanism 204 communicates with a combined user plane network element, including a Serving Gateway (SGW) and a Packet Gateway (PGW) for user plane traffic, shown as SGW-U+PGW-U 206, which communicates with SGW-U+PGW-U 206 via a security platform 202a.
[0061] For example Figure 2B As shown, the 4G network access mechanism 204 (e.g., via an Sxa / Sxb interface) communicates with the core network 210, which accesses the core network 210 through a security platform 202a. The core network 210 includes a combined control plane network element comprising a Serving Gateway (SGW) for control plane traffic and a Packet Data Network (PDN) Gateway (PGW), shown as SGW-C+PGW-C 214. The core network 210 also includes a PGW-U 216 for user plane traffic to facilitate access to the central data network 220, which accesses the central data network 220 through the security platform 202b via the PGW-U 216 and a Traffic Detection Function (TDF) for user plane traffic, shown as TDF-U 224. Specifically, the Sxa interface provides the interface between SGW-C 214 and SGW-U 206 via PFCP over UDP, and the Sxb interface provides the interface between PGW-C 214 and PGW-U 216 via PFCP over UDP. Core network 210 also includes a Traffic Detection Function (TDF), shown as TDF-C 226, for control plane traffic, and network traffic over the Sxc interface between TDF-C 226 and TDF-U 224 passes through security platform 202c.
[0062] As also shown, security platform 202a (e.g., and other security platforms may similarly communicate with security cloud services) also communicates with security service 222 (e.g., commercially available cloud-based security services, such as WildFire). TM (WF) is a cloud-based malware analysis environment, a commercially available cloud security service provided by Palo Alto Networks, which includes automated security analysis of malware samples and analysis by security experts (or may utilize similar solutions from another vendor) for network communications such as dynamic preventative signatures for malware, DNS, URLs, command and control (C&C), and / or various other security updates and / or cloud-based malware sample analysis.
[0063] refer to Figure 2BNetwork traffic communications can be monitored using security platforms 202a, 202b, and 202c (e.g., they can be located in various locations to monitor Sxa, Sxb, Sxc, and / or other communications), as described above with reference to Figure 2a and further below. In this example implementation, security platforms 202a, 202b, and 202c are located in this example 4G mobile network environment to monitor and parse PFCP messages (e.g., PFCP over UDP) on the Sxa interface between Serving Gateway-C shown at 214 and Serving Gateway-U shown at 206, on the Sxb interface between PDN Gateway-C shown at 214 and PDN Gateway-U shown at 206, and on the Sxc interface between TDF-C shown at 226 and TDF-U shown at 224, to extract certain information for establishing PFCF sessions and to track control message flows, as will be further described below.
[0064] Figure 2C This is another block diagram of an architecture for a 4G wireless network with a secure platform for protecting the control and user planes in a mobile network, according to some embodiments. Specifically, Figure 2C This is an example 4G mobile network environment for protecting the control and user plane separation in a mobile network. It includes a security platform 202 for protecting the control and user plane separation (e.g., one or more security functions / platforms may be implemented using a firewall (FW) / next-generation firewall (NGFW), a network sensor acting on behalf of the firewall, or another (virtual) device / component that can implement the security policy using the disclosed techniques), as further described below. The 4G mobile network environment may also include fixed / wired access (…). Figure 2C (not shown in the image), such as non-3GPP access such as Wi-Fi access (…). Figure 2C (not shown in the image), such as the 4G radio access network (RAN) shown at 204, and / or other networks ( Figure 2C (not shown in the image) to facilitate data communications for subscribers (e.g., using user equipment (UE), such as smartphones, laptops, computers (which may be in a fixed location), and / or other cellular-enabled computing devices / equipment, such as CIoT devices, or other network-enabled devices) to access various applications, web services, content hosting, and / or other networks.
[0065] like Figure 2C As shown, the 4G network access mechanism 204 communicates with a combined user plane network element, including a Serving Gateway (SGW) and a Packet Gateway (PGW) for user plane traffic, shown as SGW-U+PGW-U 206, which communicates with SGW-U+PGW-U 206 via a security platform 202.
[0066] For example Figure 2C As shown, the 4G network access mechanism 204 (e.g., via the Sxa / Sxb interface) communicates with the core network 210, accessing the core network 210 through the security platform 202. The core network 210 includes a combined control plane network element comprising a Serving Gateway (SGW) for control plane traffic and a Packet Data Network (PDN) Gateway (PGW), shown as SGW-C+PGW-C 214. Specifically, the Sxa interface provides the interface between SGW-C 214 and SGW-U 206 via PFCP over UDP, and the Sxb interface provides the interface between PGW-C 214 and PGW-U 206 via PFCP over UDP.
[0067] As also shown, security platform 202 is also associated with security service 222 (e.g., commercially available cloud-based security services such as WildFire). TM (WF) is a cloud-based malware analysis environment, a commercially available cloud security service provided by Palo Alto Networks, which includes automated security analysis of malware samples and analysis by security experts (or may utilize similar solutions from another vendor) for network communications such as dynamic preventative signatures for malware, DNS, URLs, command and control (C&C), and / or various other security updates and / or cloud-based malware sample analysis.
[0068] refer to Figure 2C Network traffic communications can be monitored using a security platform 202 (e.g., which can be located in various locations to monitor Sxa, Sxb, and / or other communications), as referenced above. Figure 2A -B is similarly described and further described below. In this example implementation, the security platform 202, located in the example 4G mobile network environment, is used to monitor and parse PFCP messages (e.g., PFCP over UDP) on the Sxa interface between the Serving Gateway-C shown at 214 and the Serving Gateway-U shown at 206, and on the Sxb interface between the PDN Gateway-C shown at 214 and the PDN Gateway-U shown at 206, to extract certain information for establishing PFCF sessions and to track control message flows, as will be further described below.
[0069] Figure 2D This is another block diagram of an architecture for a 4G wireless network with a secure platform for protecting the control and user planes in a mobile network, according to some embodiments. Specifically, Figure 2DThis is an example 4G mobile network environment for protecting the control and user plane separation in a mobile network. It includes security platforms 202a and 202b for protecting the control and user plane separation (e.g., one or more security functions / platforms may be implemented using a firewall (FW) / next-generation firewall (NGFW), a network sensor acting on behalf of the firewall, or another (virtual) device / component that can implement the security policy using the disclosed techniques), as further described below. The 4G mobile network environment may also include fixed / wired access (…). Figure 2D (not shown in the image), such as non-3GPP access such as Wi-Fi access (…). Figure 2D (not shown in the image), such as the 4G radio access network (RAN) shown at 204, and / or other networks ( Figure 2D (not shown in the image) to facilitate data communications for subscribers (e.g., using user equipment (UE), such as smartphones, laptops, computers (which may be in a fixed location), and / or other cellular-enabled computing devices / equipment, such as CIoT devices, or other network-enabled devices) to access various applications, web services, content hosting, and / or other networks.
[0070] like Figure 2D As shown, the 4G network access mechanism 204 communicates with user plane network elements including a Serving Gateway (SGW) and a Packet Gateway (PGW) for user plane traffic, shown as SGW-U 208 and PGW-U 206, respectively. A security platform 202b is located between PGW-U 206 and a traffic detection function for user plane traffic, shown as TDF-U 224, and communicates with TDF-U 224 via the security platform 202b.
[0071] For example Figure 2DAs shown, the 4G network access mechanism 204 (e.g., via the Sxa / Sxb interface) communicates with the core network 210, accessing the core network 210 via a security platform 202a for control plane traffic. The core network 210 includes control plane network elements, including a Serving Gateway (SGW) and a Packet Data Network (PDN) Gateway (PGW), shown as SGW-C 218 and PGW-C 216 respectively, for control plane traffic. The core network 210 also includes a traffic detection function for control plane traffic, shown as TDF-C 234, via the security platform 202b as shown. Specifically, the Sxa interface provides the interface between PGW-C 216 and PGW-U 206 via PFCP over UDP, and the Sxb interface provides the interface between SGW-C 218 and SGW-U 208 via PFCP over UDP. As also shown, the Sxc interface provides an interface between TDF-C 234 and TDF-U 224 via PFCP over UDP.
[0072] As also shown, security platform 202a (e.g., and other security platforms may similarly communicate with security cloud services) also communicates with security service 222 (e.g., commercially available cloud-based security services, such as WildFire). TM (WF) is a cloud-based malware analysis environment, a commercially available cloud security service provided by Palo Alto Networks, which includes automated security analysis of malware samples and analysis by security experts (or may utilize similar solutions from another vendor) for network communications such as dynamic preventative signatures for malware, DNS, URLs, command and control (C&C), and / or various other security updates and / or cloud-based malware sample analysis.
[0073] refer to Figure 2D Security platforms 202a and 202b (e.g., which can be located in various locations to monitor Sxa, Sxb, Sxc, and / or other communications) can be used to monitor network traffic communications, as referenced above. Figure 2A-C is similarly described and further described below. In this example implementation, security platforms 202a and 202b reside in this example 4G mobile network environment and are used to monitor and parse PFCP messages (e.g., PFCP over UDP) on the Sxa interface between PDN gateway-C shown at 216 and PDN gateway-U shown at 206, the Sxb interface between serving gateway-C shown at 218 and serving gateway-U shown at 208, and the Sxc interface between TDF-C shown at 234 and TDF-U shown at 224, to extract certain information for establishing PFCF sessions and to track control message flows, as will be further described below.
[0074] As will now become clear, one or more security platforms can be used to monitor / filter network traffic communications in various locations within 4G and / or 5G networks (e.g., 5G networks or converged 5G networks) to facilitate the separation of control and user planes in mobile networks.
[0075] Example security mechanism based on monitoring PFCP traffic for protecting control and user plane separation in mobile networks
[0076] As discussed above, PFCP will be used on the interface between control plane and user plane functions as specified in 3GPP Technical Specification (TS) 29.244 v15.7 for LTE; 5G; control plane and user plane nodes (e.g., and newer releases / versions).
[0077] Figure 3A This is a protocol sequence diagram used in the PFCP session establishment process. (Reference) Figure 3A SMF 304 receives a trigger from the UPF to establish a new PDU session or modify an existing PDU session. At 310, SMF 304 sends an N4 session establishment request message to UPF 302. At 320, UPF 302 responds with an N4 session establishment response message. SMF 304 interacts with the network function that triggered the process (e.g., 5G Core Access and Mobility Management Function (AMF) or Policy Control Function (PCF)).
[0078] Figure 3B This is a protocol sequence diagram used in the PFCP session modification process. (Refer to...) Figure 3B SMF 304 receives a trigger to modify an existing PDU session. At 330, SMF 304 sends an N4 session modification request message to UPF 302. At 340, UPF 302 responds with an N4 session modification response message. SMF 304 interacts with the network function (e.g., AMF or PCF) that triggered the process.
[0079] Figure 3C This is a protocol sequence diagram used in the PFCP session release process. (Refer to...) Figure 3C The SMF 304 receives a trigger to remove the N4 session context of the PDU session. At 350, the SMF 304 sends an N4 session release request message to the UPF 302. The UPF 302 identifies the N4 session context to be removed by the N4 session ID and removes the entire session context. At 360, the UPF 302 responds with an N4 session release response message (e.g., including any information that the UPF must provide to the SMF). The SMF 304 interacts with the network function that triggered the process (e.g., the AMF or PCF).
[0080] In the example implementation, a security platform deployment topology is based on a multi-access distributed edge 4G / 5G network or an enterprise private LTE network (e.g., such as...). Figure 1 China and still Figure 2A The security platform deployment shown in -D can perform PFCF stateful checks as described below.
[0081] First, a security platform is used to monitor PFCP traffic. The security platform automatically establishes sessions based on a 5-tuple associated with PFCP plus a node ID (optional). For example, the 5-tuple may include the following parameters: source IP address, SEID 1, destination IP address, SEID 2, and the protocol in use, which is PFCP in this example. These will be described further below.
[0082] Second, the security platform is configured with security policies to allow only PFCP session-related messages from control plane (CP) or user plane (UP) functions to match the “active” sessions corresponding to existing PFCP associations.
[0083] Third, use a security platform to monitor PFCP traffic. The security platform can automatically build a PFCP session state machine to track the following states: creating, updating, and releasing PFCP sessions based on 5-tuples (for example, a 5-tuple may include the following parameters: source IP address, SEID 1, destination IP address, SEID 2, and the protocol in use, which in this example is PFCP), as will be referenced below. Figure 3A -C is described further.
[0084] Fourth, the security platform is configured with security policies to perform sequence number checks. For example, the security platform can check the sequence numbers in PFCP request and response messages. In this example, the security platform is configured with a security policy to only allow PFCP response messages with sequence numbers to match PFCP request messages (e.g., as specified in Section 6.4 of 3GPP TS 29.244 v15.7.0, PFCP requests and their response messages should have the same sequence number value).
[0085] Security platforms can be configured to implement additional security mechanisms based on monitoring PFCP traffic. Various examples of such additional security mechanisms based on monitoring PFCP traffic will now be described.
[0086] For example, the security platform can be configured with security policies to perform user plane IP resource information checks. Specifically, additional security can be applied to the CUPS interface by checking the "User Plane IP Resource Information" exchanged between the User Plane (UP) and Control Plane (CP) functions. During the PFCP association establishment process, the "PFCP Association Establishment Request" message may optionally include an Information Element (IE) for the "User Plane IP Resource Information," which should contain IPv4 and / or IPv6 addresses along with a TEID range that the CP function will use to allocate a GTP-UF-TEID in the UP function during PFCP association establishment. In this example, the security platform can be configured with security policies to store this information and only allow the establishment of GTP-U tunnels that match the valid range of the GTP-UF-TEID and have the correct IPv4 and / or IPv6 addresses exchanged earlier during PFCP association establishment.
[0087] As another example, the security platform can be configured with security policies to perform overload protection—rate limiting of PFCP messages. Specifically, the security platform can be configured with security policies to monitor PFCP association establishment requests, PFCP session establishment requests, and PFCP session deletion requests, as referenced above. Figure 3A As described in -C, the security platform can apply the security policy to protect the resources of various network functions in 4G / 5G networks, such as UPF, PGW-U and / or other network functions in 4G / 5G networks.
[0088] Example use cases for enhanced security to protect control and user plane separation in mobile networks
[0089] The disclosed technologies for providing enhanced security for 4G / 5G mobile / service provider networks using a security platform for security policy implementation—including for protecting control and user plane separation in mobile networks—can be applied to a variety of additional example use case scenarios to promote enhanced security in 4G / 5G mobile / service provider network environments.
[0090] In the example use case scenario, the PFCP protocol runs on top of UDP and lacks inherent security design. As a result, mobile networks may be vulnerable to attacks such as denial-of-service (DoS) and / or spoofing attacks.
[0091] Example potential attacks could target one or more network functions, including UPF and / or SMF network functions that receive PFCP messages for brute-forcing Session Endpoint Identifiers (SEIDs) (e.g., 0 or a fake SEID).
[0092] Another example of a potential attack could be targeting network functions, including UPF and / or SMF network functions that receive spoofed PFCP messages with fake PFCP session modification requests and / or PFCP session deletion requests.
[0093] Another example of a potential attack could be PFCP node discovery, where an attacker with access to the Sxa / Sxb / N4 interface (e.g., or other interfaces) could send a valid PFCP message to the network function (NF) and receive a response message with useful information about the NF (e.g., such information could then be used by the attacker to launch an attack on a 4G / 5G mobile network).
[0094] The disclosed techniques can be used to detect and / or prevent the disclosed potential attack examples, as will be described below.
[0095] DoS attacks against UPF and / or SMF using brute-force 0 or fake SEIDs can be detected and prevented using PFCP stateful checks performed by a security platform, as similarly described above. Similarly, as described above, DoS attacks and / or spoofing attacks against UPF and / or SMF can also be detected and prevented by limiting the rate of PFCP messages by configuring appropriate thresholds in a security policy implemented by the security platform.
[0096] Stateful inspection using PFCP can detect and prevent spoofing and / or session / association hijacking attacks on UPF and / or SMF using fake PFCP session modification requests and / or PFCP session deletion requests. Specifically, because the security platform maintains the state of PFCP associations, based on the security policies implemented by the security platform, only valid PFCP association messages that match existing PFCP associations in the firewall table are allowed, as described above. Similarly, because the security platform maintains the state of PFCP sessions, based on the security policies implemented by the security platform, only valid PFCP association messages that match existing PFCP associations in the firewall table are allowed, as described above.
[0097] Finally, as similarly described above, reconnaissance attacks that use PFCP messages to collect network function information, based on security policies implemented by the security platform, can be detected and prevented using both PFCP stateful inspection and PFCP message rate limiting.
[0098] As will now be clear to those skilled in the art, the disclosed techniques for providing enhanced security for 4G / 5G mobile / service provider networks using a security platform for security policy implementation—including for protecting control and user plane separation in mobile networks—can be applied in a variety of additional example use case scenarios to detect / prevent these and other types of attacks in order to promote enhanced security in 4G / 5G mobile / service provider network environments.
[0099] Example hardware components for protecting network devices with separate control and user planes in mobile networks.
[0100] Figure 4This is a functional diagram of the hardware components of a network device for protecting the control and user plane separation in a mobile network, according to some embodiments. The examples shown are representations of physical / hardware components that may be included in network device 400 (e.g., appliances, gateways, or servers that may implement the security platforms disclosed herein). Specifically, network device 400 includes a high-performance multi-core CPU 402 and RAM 404. Network device 400 also includes a storage device 410 (e.g., one or more hard disks or solid-state storage units) that may be used to store policies and other configuration information, as well as signatures. In one embodiment, storage device 410 stores certain information (e.g., 5-tuple + node ID (optional) associated with PFCP, PFCP session state information for tracking the creation, updating, and release of PFCP sessions based on 5-tuple + SEID, sequence numbers in PFCP request and response messages, etc.) extracted from PFCP traffic over various interfaces monitored to implement the disclosed security policy enforcement techniques for using one or more security platforms to protect the control and user plane separation in a mobile network, as referenced above. Figure 1-3C Similar to the description. Network device 400 may also include one or more optional hardware accelerators. For example, network device 400 may include a cryptographic engine 406 configured to perform encryption and decryption operations, and one or more FPGAs 408 configured to perform signature matching, act as a network processor, and / or perform other tasks.
[0101] Example logic components for protecting network devices with separate control and user planes in mobile networks.
[0102] Figure 5 This is a functional diagram of the logical components of a network device for protecting the separation of control and user planes in a mobile network, according to some embodiments. The example shown is a representation of logical components that may be included in network device 500 (e.g., data appliances that implement the disclosed security functions / platforms and perform the disclosed techniques for protecting the separation of control and user planes in a mobile network). As shown, network device 500 includes a management plane 502 and a data plane 504. In one embodiment, the management plane is responsible for managing user interactions, such as by providing a user interface for configuring policies and viewing log data. The data plane is responsible for managing data, such as by performing packet processing and session processing.
[0103] Suppose a mobile device attempts to access a resource (e.g., a remote website / server, MEC service, IoT device such as a CIoT device, or another resource) using an encrypted session protocol such as SSL. Network processor 506 is configured to monitor packets from the mobile device and provide them to data plane 504 for processing. Process 508 identifies packets as part of a new session and creates a new session stream. Based on stream lookup, subsequent packets are identified as belonging to that session. If applicable, SSL decryption engine 510 applies SSL decryption using various techniques as described herein. Otherwise, processing by SSL decryption engine 510 is omitted. Application ID (APP ID) module 512 is configured to determine what type of traffic the session involves (e.g., as referenced above). Figure 1-3C Similar to the PFCP described above, which monitors UDP traffic between various interfaces, it identifies the user associated with the traffic flow (e.g., identifying the application ID as described herein). For example, APP ID 512 can identify GET requests in received data and infer that the session requires an HTTP decoder 514. As another example, APP ID 512 can identify PFCP session establishment / modification / release messages (e.g., N4 session establishment request / response messages, such as those referenced above). Figure 3A -C (similar description), and infers that the session requires a PFCP decoder (e.g., to extract information exchanged in N4 session establishment-related messages that include various parameters, such as those mentioned above). Figure 1-3C(Similar description). For each type of protocol, there is a corresponding decoder 514. In one embodiment, the application identifier is executed by the application identifier module (e.g., the APP ID component / engine), and the user identifier is executed by another component / engine. Based on the determination made by the APP ID 512, the packet is sent to the appropriate decoder 514. The decoder 514 is configured to assemble the packets (e.g., which may have been received out of order) into the correct order, perform tokenization, and extract information (e.g., to extract various information exchanged in N4 session establishment-related messages and / or various PFCP messages via N4 / Sxa / Sxb / Sxc / other interfaces, as similarly described above and further described below). The decoder 514 also performs signature matching to determine what processing should be performed on the packet. The SSL encryption engine 516 performs SSL encryption using various techniques as described herein, and then forwards the packet using the forwarding component 518 as shown. Also as shown, the policy 520 is received and stored in the management plane 502. In one embodiment, as described herein, policy enforcement is applied for various embodiments based on monitored, decrypted, identified, and decoded session traffic flows (e.g., a policy may include one or more rules that may be specified using domain names and / or host / server names, and the rules may apply one or more signatures or other matching criteria or heuristics, such as those disclosed herein, such as various parameters / information extracted from the DPI of monitored HTTP / 2 messages and / or monitored PFCP and / or (one or more) other protocol traffic, for security policy enforcement of subscriber / IP flows on a service provider network).
[0104] For example Figure 5 As shown, the interface (I / F) communicator 522 is also provided for communication with the security platform manager (e.g., via a (REST) API, messaging, or network protocol communication or other communication mechanisms). In some cases, network device 500 is used to monitor network communications of other network elements on the service provider network, and data plane 504 supports decoding of such communications (e.g., network device 500, including I / F communicator 522 and decoder 514, can be configured to monitor and / or communicate on reference point interfaces such as N4, Sxa, Sxb, Sxc, and / or other interfaces where wired and wireless network traffic flows). Accordingly, network device 500 including I / F communicator 522 can be used to implement the disclosed techniques for security policy enforcement in mobile / service provider network environments, including MEC service security, as described above and as will be further described below.
[0105] Additional example procedures for the disclosed techniques for protecting the separation of control and user planes in mobile networks will now be described.
[0106] Example procedure for protecting control and user plane separation in mobile networks
[0107] Figure 6 This is a flowchart illustrating a process for protecting the separation of control and user planes in a mobile network, according to some embodiments. In some embodiments, such as... Figure 6 The process 600 shown is performed by a security platform and technology similar to those described above, including the references above. Figure 1-5 The described embodiments. In one embodiment, as referenced above... Figure 4 The data device 400, as described above, is referenced. Figure 5 The network device 500, virtual appliances, SDN security solutions, cloud security services, and / or combinations or hybrid implementations as described herein are used to perform process 600.
[0108] The process begins at position 602. At position 602, network traffic on the mobile network is monitored at the security platform to identify Packet Forwarding Control Protocol (PFCP) messages associated with new sessions, where the mobile network includes 4G or 5G networks. For example, in some cases, the security platform (e.g., a firewall, a network sensor acting on behalf of the firewall, or another device / component that can implement security policies) can monitor various protocols on the mobile network, such as PFCP traffic and / or other protocols, and more specifically, by performing the disclosed techniques, various interfaces, such as N4, Sxa, Sxb, and Sxc interfaces, as described similarly above.
[0109] At 604, the security platform extracts multiple parameters from the PFCP message. For example, as described above, the security platform can parse the PFCP message to extract the source IP address, SEID 1, destination IP address, SEID 2, and the protocol in use associated with the PFCP. As another example, as described above, the security platform can parse the PFCP message to extract the node ID associated with the PFCP.
[0110] At point 606, a security policy is implemented on the new session at the security platform based on one or more of a plurality of parameters to protect the control and user plane separation in the mobile network. For example, as described above, the detection and prevention of denial-of-service (DoS) attacks to protect the control and user plane separation in 4G / 5G networks can be performed by the security platform. As another example, as described above, the detection and prevention of session endpoint identifier (SEID) spoofing attacks to protect the control and user plane separation in 4G / 5G networks can be performed by the security platform.
[0111] Figure 7This is another flowchart illustrating a process for protecting the separation of control and user planes in a mobile network, according to some embodiments. In some embodiments, such as Figure 7 The process 700 shown is performed by a security platform and technology similar to those described above, including the references above. Figure 1-5 The described embodiments. In one embodiment, as referenced above... Figure 4 The data device 400, as described above, is referenced. Figure 5 The network device 500, virtual appliance, SDN security solution, cloud security service and / or combination or hybrid implementation as described herein are used to perform process 700.
[0112] At 702, the security platform monitors network traffic on the mobile network to identify Packet Forwarding Control Protocol (PFCP) messages associated with new sessions, where the mobile network includes 4G or 5G networks. For example, in some cases, the security platform (e.g., a firewall, a network sensor acting on behalf of the firewall, or another device / component that can implement security policies) can monitor various protocols on the mobile network, such as PFCP traffic and / or other protocols, and more specifically, by performing the disclosed techniques, various interfaces, such as N4, Sxa, Sxb, and Sxc interfaces, as described similarly above.
[0113] At 704, the security platform performs a process to extract parameters from the monitored PFCP traffic to construct a session, as described above, based on a 5-tuple associated with PFCP plus an optional node ID (e.g., the 5-tuple may include the following parameters: source IP address, SEID 1, destination IP address, SEID 2, and the protocol in use, which is PFCP in this example).
[0114] At 706, the security platform extracts parameters from the monitored PFCP traffic to construct the PFCP session state machine. For example, the security platform may track the creation, updating, and release of PFCP sessions based on 5-tuples + SEID, as described above.
[0115] At 708, a security policy is implemented at the security platform to allow only PFCP session-related messages from control plane (CP) or user plane (UP) functions that match the “active” session associated with the existing PFCP, as described above.
[0116] At 710, a security policy is implemented at the security platform to perform sequence number checks. For example, the security platform can check the sequence numbers in PFCP request and response messages. In this example, the security platform is configured with a security policy to only allow PFCP response messages with sequence numbers to match PFCP request messages (e.g., as specified in Section 6.4 of 3GPP TS 29.244v15.7.0, PFCP requests and their response messages should have the same sequence number value), as described above.
[0117] In view of the disclosed embodiments, as will now be clear, network service providers / mobile operators (e.g., cellular service provider entities), equipment manufacturers (e.g., automotive entities, IoT device entities and / or other equipment manufacturers), and / or system integrators may specify security policies that can be implemented by a security platform using the disclosed technologies to address these and other technical cybersecurity challenges in order to protect the separation of control and user planes in mobile networks, including 4G and 5G networks.
[0118] Although the foregoing embodiments have been described in some detail for clarity of understanding, the invention is not limited to the details provided. Many alternative ways of implementing the invention exist. The disclosed embodiments are illustrative and not restrictive.
Claims
1. A system for protecting the separation of control and user planes in a mobile network, comprising: processor; as well as A memory, coupled to the processor and configured to provide instructions to the processor for performing the following operations: Monitor network traffic on the mobile network at the security platform to identify Packet Forwarding Control Protocol (PFCP) messages associated with new sessions, wherein the mobile network includes 4G or 5G networks; At the security platform, extract multiple parameters from the PFCP message, including IPv4 and / or IPv6 addresses, along with the Tunnel Endpoint Identifier (TEID) range; and Based on one or more of the parameters, a security policy is implemented on the new session at the security platform, including: Determine whether the TEID range of the multiple parameters and the IPv4 and / or IPv6 addresses match the TEID range and IPv4 and / or IPv6 addresses of the tunnel to be established; as well as In response to the determination of the TEID range of the plurality of parameters and the IPv4 and / or IPv6 address matching the TEID range of the tunnel to be established together with the IPv4 and / or IPv6 address, the establishment of the tunnel is permitted.
2. The system according to claim 1, wherein, The parameters extracted from the PFCP message at the security platform include the source IP address, the first session endpoint identifier (SEID), the destination IP address, the second SEID, and the protocol in use.
3. The system according to claim 1, wherein, The security platform is configured with multiple security policies.
4. The system according to claim 1, wherein, The processor is further configured to: Parse PFCP messages to extract the source IP address, first SEID, destination IP address, second SEID, and the protocol in use associated with PFCP.
5. The system according to claim 1, wherein, The processor is further configured to: Parse the PFCP message to extract the node ID associated with the PFCP.
6. The system according to claim 1, wherein, The security platform monitors network traffic destined for and / or within the core network used for 5G networks.
7. The system according to claim 1, wherein, The security platform is configured to perform the detection and prevention of denial-of-service (DoS) attacks.
8. The system according to claim 1, wherein, The security platform is configured to perform detection and prevention of SEID spoofing attacks.
9. The system according to claim 1, wherein, The processor is further configured to: New sessions are blocked from accessing resources based on security policies.
10. The system according to claim 1, wherein, The processor is further configured to: New sessions are allowed to access resources based on security policies.
11. A method for protecting a processor implementation of control and user plane separation in a mobile network, comprising: Monitor network traffic on the mobile network at the security platform to identify Packet Forwarding Control Protocol (PFCP) messages associated with new sessions, wherein the mobile network includes 4G or 5G networks; At the security platform, extract multiple parameters from the PFCP message, including IPv4 and / or IPv6 addresses, along with the Tunnel Endpoint Identifier (TEID) range; Based on one or more of the parameters, a security policy is implemented on the new session at the security platform, including: Determine whether the TEID range of the multiple parameters and the IPv4 and / or IPv6 addresses match the TEID range and IPv4 and / or IPv6 addresses of the tunnel to be established; as well as In response to the determination of the TEID range of the plurality of parameters and the IPv4 and / or IPv6 address matching the TEID range of the tunnel to be established together with the IPv4 and / or IPv6 address, the establishment of the tunnel is permitted.
12. The method according to claim 11, wherein, The parameters extracted from the PFCP message at the security platform include the source IP address, the first session endpoint identifier (SEID), the destination IP address, the second SEID, and the protocol in use.
13. The method according to claim 11, wherein, The security platform is configured with multiple security policies.
14. The method of claim 11, further comprising: Parse PFCP messages to extract the source IP address, first SEID, destination IP address, second SEID, and the protocol in use associated with PFCP.
15. The method of claim 11, further comprising: Parse the PFCP message to extract the node ID associated with the PFCP.
16. The method according to claim 11, wherein, The security platform monitors network traffic destined for and / or within the core network used for 5G networks.
17. The method according to claim 11, wherein, The security platform is configured to perform the detection and prevention of denial-of-service (DoS) attacks.
18. The method according to claim 11, wherein, The security platform is configured to perform detection and prevention of SEID spoofing attacks.
19. The method of claim 11, further comprising: Security policies may allow or block new sessions from accessing resources.
20. A computer program product embodied in a non-transitory computer-readable storage medium and comprising computer instructions that, when executed by a processor, cause the processor to perform the method according to any one of claims 11-19.
Citation Information
Patent Citations
Multi-access distributed edge security in mobile networks
US10574670B1