Applying subscriber ID-based security, device ID-based security, and / or network slice ID-based security using user IDs and SYSLOG messages in mobile networks
A security platform in mobile networks enforces context-based security policies by parsing syslog messages to address the challenges of deploying security solutions in 4G/LTE and 5G networks, enhancing threat prevention and application identification through subscriber, device, and network slice ID-based security.
Patent Information
- Application Number
- JP2025512588
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2022-08-31
- Filing Date
- 2023-07-26
- Publication Date
- 2025-09-17
- Estimated Expiration
- 2043-07-26
AI Technical Summary
Existing mobile networks, particularly 4G/LTE and 5G networks, face challenges in deploying context-based security solutions due to the lack of exposure of 3GPP interfaces, leading to concerns about latency and service outages, which hinder effective monitoring and enforcement of security policies for devices communicating over service provider networks.
Implementing a security platform that monitors network traffic, parses syslog messages using a user ID agent to enforce context-based security policies, including subscriber ID-based, device ID-based, and network slice ID-based security, across various interfaces in mobile networks, utilizing technologies like Palo Alto Networks' firewalls for enhanced security enforcement.
Facilitates enhanced context-based security in mobile networks, enabling effective monitoring and prevention of threats, application identification, and URL filtering across IP-based networks, including the Internet, by applying subscriber, device, and network slice ID-based security policies.
Smart Images

Figure 2025530746000001_ABST
Abstract
Description
[Background technology]
[0001] A firewall generally allows authorized communications to pass through the firewall while protecting a network from unauthorized access. A firewall is typically a device, a set of devices, or software running on a device that provides firewall functionality for network access. For example, a firewall can be integrated into the operating system of a device (e.g., a computer, a smartphone, or other type of network-enabled device). A firewall can also be integrated into or run as a software application on various types of devices or security devices, such as a computer server, a gateway, a network / routing device (e.g., a network router), or a data appliance (e.g., a security appliance or other type of special-purpose device).
[0002] Firewalls typically deny or allow network transmissions based on a set of rules. These sets of rules are often referred to as policies. For example, a firewall can filter inbound traffic by applying a set of rules or policies. A firewall can also filter outbound traffic by applying a set of rules or policies. A firewall can also perform basic routing functions. [Brief explanation of the drawings]
[0003] Various embodiments of the present invention are disclosed in the following detailed description and accompanying drawings. [Figure 1A]FIG. 1A is a block diagram of a 4G / LTE wireless network architecture with a security platform for applying subscriber ID-based security using user ID and syslog message networks in a mobile network, according to some embodiments. [Figure 1B] FIG. 1B is another block diagram of a 4G / LTE wireless network architecture with a security platform for applying subscriber ID-based security using user ID and syslog message networking in a mobile network, according to some embodiments. [Figure 1C] FIG. 1C is a block diagram of a 5G wireless network architecture with a security platform for applying subscriber ID-based security using user ID and syslog message networking in a mobile network, according to some embodiments. [Figure 1D] FIG. 1D is another block diagram of a 5G wireless network architecture with a security platform for applying subscriber ID-based security using user ID and syslog message networking in a mobile network, according to some embodiments. [Figure 2A] FIG. 2A is an example screen diagram of an interface of a security platform at an SGi interface in L3 mode receiving syslog messages from a PGW in a 4G / LTE network, according to some embodiments. [Figure 2B] FIG. 2B is an example screen shot of an interface of a security platform at the N6 interface in L3 mode receiving syslog messages from a UPF in a 5G network, according to some embodiments. [Figure 2C]FIG. 2C is another example screen shot of an interface of a security platform at an SGi interface in L3 mode receiving syslog messages from a PGW in a 4G / LTE network, according to some embodiments. [Figure 2D] FIG. 2D is another example screen shot of an interface of a security platform at the N6 interface in L3 mode receiving syslog messages from a UPF in a 5G network, according to some embodiments. [Figure 3] FIG. 3 is a functional diagram of hardware components of a network device for applying subscriber ID-based security, device ID-based security, and / or network slice ID-based security using user ID and syslog message networking in a mobile network, according to some embodiments. [Figure 4] FIG. 4 is a functional diagram of logical components of a network device for applying subscriber ID-based security, device ID-based security, and / or network slice ID-based security using user ID and syslog message networking in a mobile network, according to some embodiments. [Figure 5] FIG. 5 is a flow chart of a process for applying subscriber ID-based security, device ID-based security, and / or network slice ID-based security using user ID and syslog message networks in a mobile network, according to some embodiments. [Figure 6] FIG. 6 is another flow chart of a process for applying subscriber ID-based security, device ID-based security, and / or network slice ID-based security using user ID and syslog message networks in a mobile network, according to some embodiments. DETAILED DESCRIPTION OF THE INVENTION
[0004] The present invention can be implemented in numerous ways, including as a process, an apparatus, a system, a composition of matter, a computer program product embodied on a computer-readable storage medium, and / or a processor, such as instructions stored on a memory and / or a processor configured to execute instructions stored and / or provided by a memory coupled to the processor. These implementations, or any other form the present invention may take, may be referred to herein as techniques. In general, the order of steps in disclosed processes may be varied within the scope of the present invention. Unless otherwise specified, components, such as a processor or memory, described as configured to perform a task may be implemented as general-purpose components temporarily configured to perform the task at a given time, or as specific components manufactured to perform the task. As used herein, the term “processor” refers to one or more devices, circuits, and / or processing cores configured to process data, such as computer program instructions.
[0005] A detailed description of one or more embodiments of the present invention is provided below along with accompanying figures that illustrate the principles of the invention. While the present invention will be described in connection with such embodiments, the present invention is not limited to any embodiment. The scope of the present invention is limited only by the claims, and the present invention encompasses numerous alternatives, modifications, and equivalents. Numerous specific details are set forth in the following description to provide a thorough understanding of the present invention. These details are provided for the purpose of example, and the present invention may be practiced according to the claims without some or all of these specific details. For the purposes of clarity, technical material known in the art related to the present invention has not been described in detail so as not to unnecessarily obscure the present invention.
[0006] A firewall generally allows authorized communications to pass through the firewall while protecting a network from unauthorized access. A firewall is typically a device, a set of devices, or software running on a device that provides firewall functionality for network access. For example, a firewall can be integrated into the operating system of a device (e.g., a computer, a smartphone, or other type of network-enabled device). A firewall can also be integrated into or run as a software application on various types of devices or security devices, such as a computer server, a gateway, a network / routing device (e.g., a network router), or a data appliance (e.g., a security appliance or other type of special-purpose device).
[0007] Firewalls typically deny or allow network transmissions based on a set of rules. These sets of rules are often referred to as policies (e.g., network policies or network security policies). For example, a firewall can filter inbound traffic by applying a set of rules or policies to prevent unwanted external traffic from reaching a protected device. A firewall can also filter outbound traffic by applying a set of rules or policies (e.g., allow, block, monitor, notify, log, and / or other actions that may be specified in a firewall / security rule or firewall / security policy, which may be triggered based on various criteria, as described herein). A firewall may also apply antivirus protection, malware detection / prevention, or intrusion protection by applying a set of rules or policies.
[0008] Security devices (e.g., security appliances, security gateways, security services, and / or other security devices) may perform various security operations (e.g., firewalls, anti-malware, intrusion prevention / detection, proxies, and / or other security functions), network functions (e.g., routing, quality of service (QoS), workload balancing of network-related resources, and / or other network functions), and / or other security and / or network-related functions. For example, routing may be performed based on source information (e.g., source IP address and port), destination information (e.g., destination IP address and port), and protocol information.
[0009] Basic packet filtering firewalls filter network communication traffic by inspecting individual packets sent over the network (e.g., stateless packet filtering firewalls, or first-generation firewalls). Stateless packet filtering firewalls typically inspect the individual packets themselves and then apply rules based on the inspected packets (e.g., using a combination of the packet's source and destination address information, protocol information, and port numbers).
[0010] Application firewalls can also perform application-layer filtering (e.g., using an application-layer filtering firewall or a second-generation firewall that functions at the application level of the TCP / IP stack). Application-layer filtering firewalls or application firewalls can generally identify certain applications and protocols (e.g., web browsing using the Hypertext Transfer Protocol (HTTP), Domain Name System (DNS) requests, file transfers using the File Transfer Protocol (FTP), and various other types of applications and other protocols, such as Telnet, DHCP, TCP, UDP, and TFTP (GSS)). For example, an application firewall can block unauthorized protocols that attempt to communicate on standard ports (e.g., unauthorized / out-of-policy protocols that attempt to sneak through by using a non-standard port for that protocol can generally be identified using an application firewall).
[0011] Stateful firewalls can also perform stateful-based packet inspection, where each packet is inspected within the context of the set of packets associated with its network outgoing packet flow (e.g., a stateful firewall or third-generation firewall). This firewall technology is commonly referred to as stateful packet inspection because it keeps a record of all connections passing through the firewall and can determine whether a packet is the start of a new connection, part of an existing connection, or an invalid packet. For example, the state of a connection can itself be one of the criteria that triggers a rule in a policy.
[0012] Advanced or next-generation firewalls can perform stateless and stateful packet filtering and application layer filtering, as described above. Next-generation firewalls can also implement additional firewall technologies. For example, certain newer firewalls, often referred to as advanced or next-generation firewalls, can also identify users and content. In particular, certain next-generation firewalls have expanded the list of applications that they can automatically identify to thousands of applications. Examples of such next-generation firewalls are commercially available from Palo Alto Networks (e.g., Palo Alto Networks PA Series Firewalls, Palo Alto Networks VM Series Virtualized Next-Generation Firewalls, and CN Series Containerized Next-Generation Firewalls).
[0013] For example, Palo Alto Networks' next-generation firewalls use a variety of identification technologies to enable enterprises and service providers to identify and control applications, users, and content—not just ports, IP addresses, and packets. These technologies include App-ID for precise application identification. TM (e.g., App ID), User-ID for user identification (e.g., by user or user group) TM (e.g., User ID), and Content-ID for real-time content scanning TM These include technologies like Content ID (e.g., controlling web surfing and restricting data and file transfers). These identification technologies allow companies to safely enable application use using business-relevant concepts, instead of following the traditional approach offered by traditional port-blocking firewalls. Also, special-purpose hardware for next-generation firewalls, implemented as dedicated devices, typically offers higher performance levels for application inspection than software running on general-purpose hardware (e.g., security appliances from Palo Alto Networks, such as the PA Series Next-Generation Firewall, which utilize dedicated, function-specific processing tightly integrated with a single-pass software engine to minimize latency while maximizing network throughput).
[0014] Overview of techniques for applying subscriber ID-based security, device ID-based security, and / or network slice ID-based security using user IDs and Syslog messages in mobile networks
[0015] For devices in mobile networks (e.g., 4G / LTE and 5G mobile networks), technical and security challenges exist with service provider networks. For example, some private 4G / LTE and private 5G networks do not expose 3GPP interfaces between network functions, which prevents the deployment of security solutions (e.g., network gateway firewalls (NFGWs) or other security entities) on these interfaces to apply context-based security to network traffic. Furthermore, some mobile / service providers are reluctant to deploy such security solutions on various interfaces (e.g., 3GPP interfaces) due to concerns about potential latency and service outages.
[0016] Thus, what is needed are new and improved security techniques for devices communicating over such service provider network environments (e.g., mobile networks, including various 4G / LTE and 5G mobile networks). Specifically, what is needed are new and improved solutions for monitoring such network traffic and applying context-based security policies (e.g., security / firewall policies) for devices communicating over service provider networks, including those for applying subscriber ID-based security, device ID-based security, and / or network slice ID-based security using user IDs and syslog messages in mobile networks.
[0017] In some embodiments, a system / process / computer program product for applying subscriber ID-based security using user ID and syslog messages in a mobile network includes monitoring network traffic on the mobile network at a security platform to identify new sessions, extracting a plurality of parameters by parsing the syslog messages with a user ID agent at the security platform, and enforcing a security policy for the new session at the security platform based on one or more of the plurality of parameters including the subscriber ID to apply context-based security in the mobile network.
[0018] For example, the techniques described above may be performed to apply subscriber ID-based security over the N6 interface in a private 5G network and / or over the SGi interface in a private 4G / LTE network.
[0019] As another example, the above-described techniques may be performed to apply identification and prevention for known and unknown threats over the N6 interface in a 5G network and / or over the SGi interface in a 4G / LTE network.
[0020] As yet another example, the above-described techniques may be performed to apply application identification over an N6 interface in a 5G network and / or over an SGi interface in a 4G / LTE network.
[0021] As yet another example, the above-described techniques may be performed to apply URL filtering over the N6 interface in a 5G network and / or over the SGi interface in a 4G / LTE network.
[0022] Thus, service providers and / or enterprises can use the disclosed techniques and security platform to apply subscriber identity-based security across the boundaries of IP-based external networks (e.g., the Internet).
[0023] In some embodiments, a system / process / computer program product for enforcing device ID-based security using user ID and syslog messages in a mobile network includes monitoring network traffic on the mobile network at a security platform to identify new sessions, extracting a plurality of parameters by parsing the syslog messages using a user ID agent at the security platform, and enforcing a security policy for the new session at the security platform based on one or more of the plurality of parameters including the device ID to enforcing context-based security in the mobile network.
[0024] For example, the techniques described above may be performed to apply device ID-based security over an N6 interface in a private 5G network and / or over an SGi interface in a private 4G / LTE network.
[0025] As another example, the above-described techniques may be performed to apply identification and prevention for known and unknown threats over the N6 interface in a 5G network and / or over the SGi interface in a 4G / LTE network.
[0026] As yet another example, the above-described techniques may be performed to apply application identification over an N6 interface in a 5G network and / or over an SGi interface in a 4G / LTE network.
[0027] As yet another example, the above-described techniques may be performed to apply URL filtering over the N6 interface in a 5G network and / or over the SGi interface in a 4G / LTE network.
[0028] Thus, service providers and / or enterprises can use the disclosed techniques and security platform to apply device ID-based security across the boundaries of external IP-based networks (eg, the Internet).
[0029] In some embodiments, a system / process / computer program product for applying user ID and network slice ID-based security in a mobile network includes monitoring network traffic on the mobile network at a security platform to identify new sessions, extracting multiple parameters by parsing the syslog messages using a user ID agent at the security platform, and enforcing a security policy on the new session at the security platform based on one or more of the multiple parameters, including the network slice ID, to apply context-based security in the mobile network.
[0030] For example, the above-described techniques may be performed to apply network slice ID-based security over the N6 interface in a private 5G network.
[0031] As another example, the above-described techniques may be performed to apply identification and prevention for known and unknown threats via the N6 interface in a 5G network.
[0032] As yet another example, the techniques described above may be performed to apply application identification over the N6 interface in a 5G network.
[0033] As yet another example, the above-described techniques may be implemented to apply URL filtering via the N6 interface in a 5G network.
[0034] Thus, service providers and / or enterprises can use the disclosed techniques and security platform to apply network slice ID-based security across the boundaries of IP-based external networks (e.g., the Internet). Additionally, the disclosed techniques can be implemented using the security platform to apply subscriber ID-based security, device ID-based security, and / or network slice ID-based security using user IDs and syslog messages in the mobile network for security policy enforcement in the mobile network (including when the security platform is not inline with the core mobile network, such as, for example, private 4G networks, private 5G networks, etc.).
[0035] Thus, mobile network operators can use the disclosed techniques to apply subscriber ID-based security, device ID-based security, and / or network slice ID-based security using user IDs and syslog messages in mobile networks using such security platforms, as described further below. (For example, the security platform can also be configured to distinguish between deployment / operating environments for monitoring such network traffic and applying context-based security policies (e.g., security / firewall policies) for devices communicating on service provider networks, including applying subscriber ID-based security, device ID-based security, and / or network slice ID-based security using user IDs and syslog messages in mobile networks, including office deployment / operating environments, enterprise deployment / operating environments, and factory deployment / operating environments.)
[0036] Thus, the disclosed techniques facilitate enhanced context-based security in mobile networks. For example, security functions (e.g., security platforms) may be located closer to users / devices (e.g., UEs) to perform security policy analysis and enforcement. As another example, security functions may be implemented to facilitate security for selective industry verticals. As yet another example, security may be implemented in highly sensitive locations, such as government network environments, military network environments, and power plants or other critical infrastructure network environments.
[0037] Thus, novel and improved security solutions are disclosed, according to some embodiments, that facilitate applying security (e.g., network-based security) using a security platform for executing the disclosed techniques to apply subscriber ID-based security, device ID-based security, and / or network slice ID-based security using user IDs and syslog messages in mobile networks (e.g., 4G / 5G / 6G / later versions of mobile networks) over various interfaces and protocols in a mobile network environment (e.g., a firewall (FW) / next-generation firewall (NGFW), a network sensor operating in place of a firewall, or another (virtual) device / component that can implement security policies using the disclosed techniques, including, for example, Palo Alto Networks' PA Series Next-Generation Firewall, Palo Alto Networks' VM Series Virtualized Next-Generation Firewall, and CN Series Container Next-Generation Firewall, and / or other commercially available virtual-based or container-based firewalls, can similarly be implemented and configured to execute the disclosed techniques).
[0038] These and other embodiments and examples for applying subscriber ID-based security, device ID-based security, and / or network slice ID-based security using user ID and syslog message networks in mobile networks are further described below.
[0039] An exemplary system architecture for applying subscriber identity-based security using user identity and syslog messages in mobile networks
[0040] Accordingly, in some embodiments, the disclosed technology includes providing a security platform (e.g., the security functionality / platform may be implemented using a firewall (FW) / next-generation firewall (NGFW), a network sensor operating in place of a firewall, or a Palo Alto Networks firewall, including, for example, Palo Alto Networks' PA Series Next-Generation Firewall, Palo Alto Networks' VM Series Virtualized Next-Generation Firewall, and Palo Alto Networks' CN Series Containerized Next-Generation Firewall) configured to provide DPI capabilities (e.g., including stateful inspection) of, for example, GTP-U sessions (e.g., GTP-U traffic) via various interfaces (e.g., RESTful API, N3, N6, and / or other interfaces within a 4G / 5G / 6G core network) to apply security to user plane traffic based on policy (e.g., Layer 7 security and / or other security policy enforcement), as described further below. Other (virtual) devices / components capable of implementing security policies using the disclosed techniques, such as PANOS running on a commercially available virtual / physical NGFW solution from Cisco Systems, Inc., or another security platform / NFGW, may similarly be implemented and configured to perform the disclosed techniques.
[0041] 1A is a block diagram of a 4G / LTE wireless network architecture with a security platform for enforcing subscriber ID-based security using a user ID and a syslog message network in a mobile network, according to some embodiments. Specifically, FIG. 1A illustrates an exemplary 4G / LTE mobile network environment including a security platform 102 (e.g., the security function / platform may be implemented using a firewall (FW) / next-generation firewall (NGFW), a network sensor acting in place of a firewall, or another (virtual) device / component capable of implementing security policies using the disclosed techniques, including, for example, Palo Alto Networks' PA Series Next-Generation Firewall, Palo Alto Networks' VM Series Virtualized Next-Generation Firewall, and CN Series Containerized Next-Generation Firewall) for enforcing user ID and subscriber ID-based security using a syslog message network in a mobile network via various interfaces (e.g., SGi and / or other interfaces in a 4G / LTE core network and N6 and / or other interfaces in a 5G core network) in a mobile network (e.g., a 4G / LTE or later mobile network), as further described below.
[0042] As referred to herein, IMSI is a concept referred to by ITU-T as "International Mobile Subscription Identity." IMSI is a 14- or 15-digit number.
[0043] As referred to herein, SUPI is also a globally unique 5G "Subscription Permanent Identifier" assigned to each subscriber in a 5G system. In accordance with 3GPP TS 23.003 v16.9.0, the SUPI type may indicate an IMSI, a Network Access Identifier (NAI), a Global Line Identifier (GLI), or a Global Cable Identifier (GCI).
[0044] Also, as referred to herein, the International Mobile Equipment Identity (IMEI) is defined in 3GPP TS 23.003, available at https: / / portal.3GPP.org / desktopmodules / Specifications / SpecificationDetails.aspx?specificationId=729.
[0045] 1A, the 4G / LTE mobile network environment may also include 4G Radio Access Network (RAN) access, as shown at 106, and / or other networks, including, for example, Wi-Fi access and fixed access (not shown), which may facilitate data communications for subscribers (e.g., using user equipment (UE), such as smartphones, laptops, computers (which may be at fixed locations), and / or other cellular-enabled computing devices / appliances, such as IoT devices, as shown at 104A, and / or customer devices, as shown at 104B, or other network communication-enabled devices), including via a packet data network (PDN) (e.g., the Internet) 120 to access various applications, web services, content hosts, etc., and / or other networks. Each of the above-mentioned 4G / LTE network access mechanisms is in communication with a 4G core network 110, which includes a packet data network gateway (PGW) 112. The PGW 112 communicates with the PDN 120 via an SGi interface, where the security platform 102 is collocated between the PGW 112 and the PDN 120. The security platform 102 communicates with the PGW 112 (e.g., via the SGi interface, as shown) to access real-time syslog data with UE IP address and IMEI / IMSI information, as described further below.
[0046] 1A , network traffic communications are monitored / filtered within a 4G / LTE network using security platform 102. As shown, network traffic communications are monitored / filtered within a 4G / LTE network using security platform 102 (e.g., a (virtual) device / appliance including a firewall (FW), a network sensor acting in place of a firewall, or another device / component capable of implementing a security policy using the disclosed techniques), which is configured to perform the disclosed techniques for applying context-based security over various interfaces within a mobile network (e.g., the SGi and / or other interfaces within a 4G / LTE core network and the N6 and / or other interfaces within a 5G core network), as similarly described above and further described below.
[0047] In this exemplary implementation, the disclosed techniques for applying user identity and subscriber identity-based security using a syslog message network in a mobile network may be implemented using a security platform deployed in a 4G / LTE technology-based mobile network such as that shown in FIG. 1A. Specifically, the mobile network has network functions that can generate syslog messages for certain events, such as bearer creation and bearer deletion. These network functions may be configured to send syslog messages containing information about the bearer creation and deletion events. A user identity agent within the security platform may be configured to parse these messages. For example, the user identity agent may be configured to parse creation events to map user equipment (UE) IP addresses to subscriber identities and also to parse deletion events to delete stale mappings. Deleting stale mappings is generally useful in mobile networks where IP address assignments may change, for example, when a UE is rebooted or during various other scenarios. Thus, in some embodiments, syslog parsing profiles are used to parse syslog messages and integrate with network functionality from different equipment vendors that may send syslog messages in different formats (e.g., a user can create a custom profile for each format).
[0048] In some embodiments, the security platform is further configured to provide the following DPI capabilities: DPI of IP traffic over the SGi interface. In one exemplary implementation, the security platform is configured to provide DPI capabilities (e.g., including identifying APP ID, user ID, content ID, and performing URL filtering) of IP sessions over the SGi interface between the PGW 112 and the PDN 120, for example, and to apply security to user plane traffic based on policies (e.g., Layer 7 security and / or other security policy enforcement), as described further below.
[0049] Additionally, the security platform 102 may also access cloud security services 122 (e.g., WildFire, a commercially available cloud security service offered by Palo Alto Networks, Inc., that includes automated security analysis of malware samples as well as security expert analysis), such as over the Internet. TM The network may also be in communication with a commercially available cloud-based security service, such as a cloud-based malware analysis environment, or a similar solution provided by another vendor. For example, a cloud security service 122 may be used to provide the security platform with dynamic prevention signatures for malware, DNS, URL, CNC malware, and / or other malware, as well as to receive malware samples for further security analysis.
[0050] 2A is an example screen diagram of a security platform interface at the SGi interface in L3 mode receiving syslog messages from a PGW in a 4G / LTE network, according to some embodiments. In this example, the PGW sends an event syslog (e.g., a syslog message) to the security platform (e.g., NGFW 102) whenever a new default bearer is created or deleted. Each syslog contains different fields, key fields for highlighting: event type, IMSI, IMEI, APN, and Ue_IP.
[0051] Below is an example of a syslog message generated by the PGW.
[0052] Jan 9 08:12:14 {"pgw","type":"create_session","evt":{"imsi":"002002999971493","imei":"3526201120836534","apn":"apn2a6","user_addr":["172.16.15.159"]}}
[0053] The security platform (e.g., NGFW 102) receives the event syslog and creates a user ID / IP mapping. The user ID can be configured as the UE IMSI, for example, "002002999971493." The syslog with the event "create_session" can be configured as the user ID login action, while "delete_session" can be used as the logout action.
[0054] Referring to FIG. 2A, an example screenshot of a security platform interface at the SGi interface in L3 mode receiving syslog messages from a PGW in a 4G / LTE network provides an example of a security policy configured with a user ID as UE IMSI="002002999971493".
[0055] FIG. 1B is another block diagram of a 4G / LTE wireless network architecture with a security platform for applying subscriber ID-based security using user ID and syslog message networking in a mobile network, according to some embodiments. Specifically, FIG. 1B illustrates an exemplary 4G / LTE mobile network environment including a deployment of a security platform 102 in a 4G / LTE Mobile Edge Computing (MEC) 114 environment including multiple MEC applications (APPs) as shown in FIG. 1B (e.g., the security function / platform may be a firewall (FW) / Next Generation Firewall (NGFW), a network sensor operating in place of a firewall, or another (virtual) device / component that can implement security policies using the disclosed techniques, including, for example, Palo Alto Networks' PA Series Next Generation Firewall, Palo Alto Networks' VM Series Virtualized Next Generation Firewall, and CN Series Containerized Next Generation Firewall, and / or other commercially available virtual-based or container-based firewalls that can similarly be implemented and configured to perform the disclosed techniques), for enforcing subscriber ID-based security in a mobile network using user ID and syslog message networking via various interfaces in the mobile network (e.g., a 4G / LTE or later mobile network) (e.g., an SGi and / or other interfaces in a 4G / LTE core network, and an N6 interface and / or other interfaces in a 5G core network), as described further below.
[0056] 1B, the 4G / LTE mobile network environment may also include 4G Radio Access Network (RAN) access, as shown at 106, and / or other networks, including, for example, Wi-Fi access and fixed access (not shown), which may facilitate data communications for subscribers (e.g., using user equipment (UE), such as smartphones, laptops, computers (which may be at fixed locations), and / or other cellular-enabled computing devices / appliances, such as smart factories including UEs and IoT devices, as shown at 104C, or other network communication-enabled devices), including via a packet data network (PDN) (e.g., the Internet) 120 to access various applications, web services, content hosts, etc., and / or other networks. Each of the above-mentioned 4G / LTE network access mechanisms is in communication with a 4G core network 110 (e.g., shown in FIG. 1B as a Central Core Site). Also shown, the 4G RAN 106 is in network communication via an S1-U interface to a Serving Gateway User Plane Function (SGW-U) and a Packet Network Data Gateway Function (PGW-U), as shown at 116 in FIG. 1B. The SGW-U and PGW-U 116 are in communication with the PDN / Internet 120 via an SGi interface, where the security platform 102 is collocated between the SGW-U and PGW-U 116 and the PDN / Internet 120. The security platform 102 communicates with the SGW-U and PGW-U 116 (e.g., via the SGi interface, as shown) to access real-time syslog data using UE IP address and IMEI / IMSI information, as similarly described above and further described below. The SGW-U and PGW-U 116 also communicate with the 4G Core 110 via an Sxa / Sxb interface, as shown in FIG. 1B.
[0057] 1B , network traffic communications are monitored / filtered in a 4G / LTE network using security platform 102. As shown, network traffic communications are monitored / filtered in a 4G / LTE network using security platform 102 (e.g., a (virtual) device / appliance including a firewall (FW), a network sensor acting in place of a firewall, or another device / component capable of implementing a security policy using the disclosed techniques), which is configured to perform the disclosed techniques for applying context-based security over various interfaces in a mobile network (e.g., the SGi and / or other interfaces in a 4G / LTE core network and the N6 interface and / or other interfaces in a 5G core network), as similarly described above and further described below.
[0058] In this exemplary implementation, the disclosed techniques for applying user ID and subscriber ID-based security using a syslog message network in a mobile network may be performed using a security platform deployed in a 4G / LTE technology-based mobile network, such as that shown in FIG. 1B. Specifically, the mobile network has network functions that can generate syslog messages for predetermined events, such as bearer creation and bearer deletion. These network functions may be configured to send syslog messages containing information about the bearer creation and deletion events. A user ID agent in the security platform may be configured to parse those messages. For example, the user ID agent may be configured to parse creation events to map user equipment (UE) IP addresses to subscriber IDs and also parse deletion events to delete stale mappings. Deleting stale mappings is generally useful in mobile networks where IP address assignments may change, for example, when a UE is rebooted or during various other scenarios. Thus, in some embodiments, syslog parsing profiles are used to parse syslog messages to integrate with network functionality from different equipment vendors that may send syslog messages in different formats (e.g., users can create custom profiles for each format).
[0059] In some embodiments, the security platform is further configured to provide the following DPI capabilities: DPI of IP traffic over the SGi interface. In one exemplary implementation, the security platform is configured to provide DPI functionality (e.g., including identifying APP ID, user ID, content ID, and performing URL filtering) of IP sessions over the SGi interface between, for example, the SGW-U and PGW-U 116 and the PDN 120, and to apply security to user plane traffic based on policies (e.g., Layer 7 security and / or other security policy enforcement), as described further below.
[0060] Additionally, the security platform 102 may also access cloud security services 122 (e.g., WildFire, a commercially available cloud security service offered by Palo Alto Networks, Inc., that includes automated security analysis of malware samples as well as security expert analysis), such as over the Internet. TM The network may also be in communication with a commercially available cloud-based security service, such as a cloud-based malware analysis environment, or a similar solution provided by another vendor. For example, a cloud security service 122 may be used to provide the security platform with dynamic prevention signatures for malware, DNS, URL, CNC malware, and / or other malware, as well as to receive malware samples for further security analysis.
[0061] 1C is a block diagram of a 5G wireless network architecture with a security platform for enforcing subscriber ID-based security using a user ID and a syslog message network in a mobile network, according to some embodiments. Specifically, FIG. 1C illustrates an exemplary 5G mobile network environment including a security platform 102 for enforcing subscriber ID-based security using a user ID and a syslog message network in a mobile network (e.g., a 5G or later mobile network) via various interfaces (e.g., SGi and / or other interfaces in a 4G / LTE core network and an N6 interface and / or other interfaces in a 5G core network), as further described below. (For example, the security function / platform may be implemented using a firewall (FW) / next-generation firewall (NGFW), a network sensor acting in place of a firewall, or another (virtual) device / component capable of implementing security policies using the disclosed techniques, including, for example, Palo Alto Networks' PA Series Next-Generation Firewall, Palo Alto Networks' VM Series Virtualized Next-Generation Firewall, and CN Series Containerized Next-Generation Firewall.)
[0062] 1C, the 5G mobile network environment may also include 5G New Radio (NR) Radio Access Network (RAN) access, as shown at 108, and / or other networks, including, for example, Wi-Fi access and fixed access (not shown), which may facilitate data communications for subscribers (e.g., using UEs or other network communication-enabled devices, such as user equipment (UE), such as smartphones, laptops, computers (which may be at fixed locations), and / or other cellular-enabled computing devices / appliances, such as IoT devices, as shown at 104A, and / or customer devices, as shown at 104B), including via a packet data network (PDN) (e.g., the Internet) 120 to access various applications, web services, content hosts, etc., and / or other networks. Each of the above-mentioned 5G network access mechanisms is in communication with a 5G core network 118, which includes a 5G mobile core user plane function (UPF) 124. The UPF 124 communicates with the PDN 120 via the N6 interface, with the security platform 102 positioned side-by-side between the UPF 124 and the PDN 120. The security platform 102 communicates with the UPF 124 (e.g., via the N6 interface as shown) to access real-time syslog data with UE IP address and IMEI / IMSI information, as described further below.
[0063] 1C , network traffic communications are monitored using security platform 102. As shown, network traffic communications are monitored / filtered in the 5G network using security platform 102 (e.g., a (virtual) device / appliance including a firewall (FW), a network sensor acting in place of a firewall, or another device / component capable of implementing security policies using the disclosed techniques), which is configured to perform the disclosed techniques for applying context-based security over various interfaces in a mobile network (e.g., the SGi and / or other interfaces in a 4G / LTE core network and the N6 interface and / or other interfaces in a 5G core network), as similarly described above and further described below.
[0064] In this exemplary implementation, the disclosed techniques for applying user ID and subscriber ID-based security using a syslog message network in a mobile network may be performed using a security platform deployed in a 4G / LTE technology-based mobile network, such as that shown in FIG. 1C. Specifically, the mobile network has network functions that can generate syslog messages for predetermined events, such as bearer creation and bearer deletion. These network functions may be configured to send syslog messages containing information about the bearer creation and deletion events. A user ID agent in the security platform may be configured to parse those messages. For example, the user ID agent may be configured to parse creation events to map user equipment (UE) IP addresses to subscriber IDs and also parse deletion events to delete stale mappings. Deleting stale mappings is generally useful in mobile networks where IP address assignments may change, for example, when a UE is rebooted or during various other scenarios. Thus, in some embodiments, syslog parsing profiles are used to parse syslog messages to integrate with network functionality from different equipment vendors that may send syslog messages in different formats (e.g., users can create custom profiles for each format).
[0065] In some embodiments, the security platform is further configured to provide the following DPI capabilities: DPI of IP traffic over the N6 interface. In one exemplary implementation, the security platform is configured to provide DPI capabilities (e.g., including identifying APP ID, user ID, content ID, and performing URL filtering) for IP sessions over the N6 interface between the UPF 124 and the PDN 120 to apply security to user plane traffic based on policy (e.g., Layer 7 security and / or other security policy enforcement), as described further below.
[0066] Additionally, the security platform 102 may also access cloud security services 122 (e.g., WildFire, a commercially available cloud security service offered by Palo Alto Networks, Inc., that includes automated security analysis of malware samples as well as security expert analysis), such as over the Internet. TM The cloud security service 122 may be in network communication with a commercially available cloud-based security service, such as a cloud-based malware analysis environment, or a similar solution provided by another vendor. For example, the cloud security service 122 may be used to provide the security platform with dynamic prevention signatures for malware, DNS, URL, CNC malware, and / or other malware, as well as to receive malware samples for further security analysis.
[0067] 2B is an example screen shot of a security platform interface at the N6 interface in L3 mode receiving syslog messages from the UPF in a 5G network, according to some embodiments. In this example, the UPF sends an event syslog (e.g., a syslog message) to the security platform (e.g., NGFW 102) whenever a new PDU session is created or deleted. Each syslog contains different fields, key fields for highlighting: Event type, IMSI, IMEI, DNN, S-NSSAI, and Ue_IP.
[0068] Below is one example syslog message generated by UPF:
[0069] Jan 13 10:16:15 {"upf","type":"create_pdu_session","evt":{"imsi":"312333000222123","imei":"4441 221130832222","dnn":"dnn1bc4","s-nssai":"1:1000","user_addr":["172.16.15.171"]}}
[0070] The security platform (e.g., NGFW 102) receives the event syslog and creates a user ID / IP mapping. The user ID can be configured as the UE IMSI, for example, "312333000222123". The syslog with the event "create_session" can be configured as the user ID login action, while "delete_session" can be used as the logout action.
[0071] Referring to FIG. 2B, an example screenshot of an interface for a security platform at the N6 interface in L3 mode receiving syslog messages from a UPF in a 5G network provides an example of a security policy configured with a user ID as UE IMSI="312333000222123".
[0072] FIG. 1D is another block diagram of a 5G wireless network architecture with a security platform for applying subscriber ID-based security in a mobile network using user ID and syslog message networking in a mobile network, according to some embodiments. Specifically, FIG. 1D is an exemplary 5G mobile network environment including a deployment of a security platform 102 in a 5G mobile edge computing (MEC) 114 environment including multiple MEC applications (APPs) as shown in FIG. 1D for applying user ID and subscriber ID-based security using a syslog message network in a mobile network via various interfaces in the mobile network (e.g., a 5G or later mobile network) (e.g., SGi and / or other interfaces in a 4G / LTE core network and an N6 interface and / or other interfaces in a 5G core network), as described further below. (E.g., the security function / platform may be implemented using a firewall (FW) / next-generation firewall (NGFW), a network sensor acting in place of a firewall, or another (virtual) device / component that can implement security policies using the disclosed techniques, including, for example, Palo Alto Networks' PA Series Next-Generation Firewall, Palo Alto Networks' VM Series Virtualized Next-Generation Firewall, and CN Series Containerized Next-Generation Firewall.)
[0073] As shown in FIG. 1D , the 5G mobile network environment also includes 5G New Radio (NR) Radio Access Network (RAN) access, shown at 108, and / or other networks, including, for example, Wi-Fi access and fixed access (not shown), which can facilitate data communications for subscribers (e.g., using user equipment (UE) such as smartphones, laptops, computers (which may be at fixed locations), and / or other cellular-enabled computing devices / appliances, such as smart factories including UEs and IoT devices, as shown at 104C, or other network communication-enabled devices), including via a packet data network (PDN) (e.g., the Internet) 120 to access various applications, web services, content hosts, etc., and / or other networks. Each of the above-mentioned 5G network access mechanisms is in communication with a 5G core network 118 (e.g., shown as a central core site in FIG. 1D ). Also shown, the 5G NR RAN 108 is in network communication with the UPF via an N3 interface, shown at 124 in FIG. 1D . The UPF 124 communicates with the PDN / Internet 120 via an N6 interface, with the security platform 102 collocated between the UPF 124 and the PDN / Internet 120. The security platform 102 communicates with the UPF (e.g., via the N6 interface, as shown) to access real-time syslog data with UE IP addresses and IMEI / IMSI information, as also described above and further below. The UPF 124 also communicates with the 5G Core 118 via an N4 interface, as shown in FIG. 1D.
[0074] 1D , network traffic communications are monitored using security platform 102. As shown, network traffic communications are monitored / filtered in the 5G network using security platform 102 (e.g., a (virtual) device / appliance including a firewall (FW), a network sensor acting in place of a firewall, or another device / component that can implement security policies using the disclosed techniques) configured to perform the disclosed techniques for applying context-based security over various interfaces in the mobile network (e.g., the SGi and / or other interfaces in a 4G / LTE core network and the N6 interface and / or other interfaces in a 5G core network), as also described above and further below.
[0075] In this exemplary implementation, the disclosed techniques for applying user identity and subscriber identity-based security using a syslog message network in a mobile network may be executed using a security platform deployed in a 5G technology-based mobile network such as that shown in FIG. 1D. Specifically, the mobile network has network functions that can generate syslog messages for predetermined events, such as bearer creation and bearer deletion. These network functions may be configured to send syslog messages containing information about the bearer creation and deletion events. A user identity agent in the security platform may be configured to parse those messages. For example, the user identity agent may be configured to parse for creation events to map user equipment (UE) IP addresses to subscriber identities and also parse for deletion events to delete stale mappings. Deleting stale mappings is generally useful in mobile networks where IP address assignments may change, for example, when a UE is rebooted or during various other scenarios. Thus, in some embodiments, syslog parsing profiles are used to parse syslog messages and integrate with network functionality from different equipment vendors that may send syslog messages in different formats (e.g., a user can create a custom profile for each format).
[0076] In some embodiments, the security platform is further configured to provide the following DPI capabilities: DPI of IP traffic over the N6 interface. In one exemplary implementation, the security platform is configured to provide DPI capabilities (e.g., including identifying APP ID, user ID, content ID, and performing URL filtering) for N6 interface IP sessions between the UPF 124 and the PDN 120, and to apply security to user plane traffic based on policies (e.g., Layer 7 security and / or other security policy enforcement), as described further below.
[0077] Additionally, the security platform 102 may also access cloud security services 122 (e.g., WildFire, a commercially available cloud security service offered by Palo Alto Networks, Inc., that includes automated security analysis of malware samples as well as security expert analysis), such as over the Internet. TM The cloud security service 122 may be in network communication with a commercially available cloud-based security service, such as a cloud-based malware analysis environment, or a similar solution provided by another vendor. For example, the cloud security service 122 may be used to provide the security platform with dynamic prevention signatures for malware, DNS, URL, CNC malware, and / or other malware, as well as to receive malware samples for further security analysis.
[0078] For example, the techniques described above may be performed to apply subscriber ID-based security over the N6 interface in a private 5G network and / or over the SGi interface in a private 4G / LTE network.
[0079] As another example, the above-described techniques may be performed to apply identification and prevention for known and unknown threats over the N6 interface in a 5G network and / or over the SGi interface in a 4G / LTE network.
[0080] As yet another example, the above-described techniques may be performed to apply application identification over an N6 interface in a 5G network and / or over an SGi interface in a 4G / LTE network.
[0081] As yet another example, the above-described techniques may be performed to apply URL filtering over the N6 interface in a 5G network and / or over the SGi interface in a 4G / LTE network.
[0082] Thus, service providers and / or enterprises can use the disclosed techniques and security platform to apply subscriber identity-based security across the boundaries of IP-based external networks (e.g., the Internet).
[0083] An exemplary system architecture for applying user ID and device ID-based security using syslog messages in mobile networks
[0084] Accordingly, in some embodiments, the disclosed technology may involve a security platform (e.g., the security functionality / platform may be implemented using a firewall (FW) / next-generation firewall (NGFW), a network sensor operating in place of a firewall, or a Palo Alto Networks firewall, including, for example, Palo Alto Networks' PA Series Next-Generation Firewall, Palo Alto Networks' VM Series Virtualized Next-Generation Firewall, and CN Series Containerized Next-Generation Firewall) configured to provide DPI capabilities (e.g., including stateful inspection) of, for example, GTP-U sessions (e.g., GTP-U traffic) via various interfaces (e.g., RESTful API, N3, N6, and / or other interfaces within a 4G / 5G / 6G core network) to apply security to user plane traffic based on policy (e.g., Layer 7 security and / or other security policy enforcement), as described further below. This includes providing another (virtual) device / component that can implement security policies using the disclosed techniques, such as PANOS running on a virtual / physical NGFW solution commercially available from Cisco Systems, Inc., or another security platform / NFGW (which may also be implemented and configured to perform the disclosed techniques).
[0085] As referred to herein, the International Mobile Equipment Identity (IMEI) is defined in 3GPP TS 23.003, available at https: / / portal.3GPP.org / desktopmodules / Specifications / SpecificationDetails.aspx?specificationId=729. A mobile station device is uniquely defined by its IMEI or IMEISV. An IMEI is 15 digits long, and an IMEISV is 16 digits long (e.g., these values consist of only decimal digits).
[0086] As also referred to herein, in a 5G network environment, a Permanent Equipment Identifier (PEI) identifies a UE. According to 3GPP TS 23.003 v 16.9.0, the PEI type can indicate an IMEI or IMEISV, a MAC address, or an IEEE Extended Unique Identifier (EUI-64).
[0087] In some embodiments, applying user ID and device ID (e.g., including IMEI and / or PEI) based security using syslog messages in a mobile network is similarly performed using a security platform deployed across the SGi interface in a 4G / LTE network, as similarly described above with respect to Figures 1A and 1B, and / or across the N6 interface in a 5G network, as similarly described above with respect to Figures 1C and 1D.
[0088] In one example implementation, the disclosed techniques for applying user ID and device ID-based security in a mobile network using a syslog message network may be implemented using a security platform deployed in a 4G / LTE technology-based mobile network, similarly shown in FIGS. 1A and 1B , except that in this example, the security platform (e.g., NGFW 102) uses an N6 interface to obtain real-time syslogs with UE IP and IMEI information from the PGW 112 and from the SGW-U and PGW-U 116, respectively, and in a 5G technology-based mobile network, similarly shown in FIGS. 1C and 1D , except that the security platform (e.g., NGFW 102) uses an N6 interface to obtain real-time syslogs with UE IP and IMEI information from the UPF 124. Specifically, the mobile network has network functions that can generate syslog messages for predetermined events, such as bearer creation and bearer deletion. These network functions may be configured to send syslog messages containing information about bearer creation and deletion events. A user ID agent within the security platform may be configured to analyze those messages. For example, a user identity agent may be configured to parse creation events to map user equipment (UE) IP addresses to device identities, and also to parse deletion events to remove stale mappings. Removing stale mappings is generally useful in mobile networks where IP address assignments may change, for example, when a UE is rebooted, or during various other scenarios.Thus, in some embodiments, syslog parsing profiles are used to parse syslog messages to integrate with network functionality from different equipment vendors that may send syslog messages in different formats (e.g., users can create custom profiles for each format).
[0089] 2C is another example screen shot of a security platform interface at the SGi interface in L3 mode receiving syslog messages from a PGW in a 4G / LTE network, according to some embodiments. In this example, the PGW sends an event syslog (e.g., a syslog message) to the security platform (e.g., NGFW 102) whenever a new default bearer is created or deleted. Each syslog contains different fields, key fields for highlighting: event type, IMSI, IMEI, APN, and Ue_IP.
[0090] Below is one example syslog message generated by the PGW:
[0091] Jan 9 09:13:10 {"pgw","type":"create_session","evt":{"imsi":"002002999971493","imei":"3526201120836534","apn":"apn2a6","user_addr":["172.16.15.101"]}}
[0092] The security platform (e.g., NGFW 102) receives the event syslog and creates a user ID / IP mapping. The user ID can be configured as the UE IMEI, for example, "3526201120836534". The syslog with the event "create_session" can be configured as the user ID login action, and "delete_session" can be used as the logout action.
[0093] Referring to FIG. 2C, an example screenshot of the interface of the security platform at the SGi interface in L3 mode receiving syslog messages from a PGW in a 4G / LTE network provides an example of a security policy configured with a user ID as UE IMEI="3526201120836534".
[0094] For example, the techniques described above may be performed to apply device ID-based security over an N6 interface in a private 5G network and / or over an SGi interface in a private 4G / LTE network.
[0095] As another example, the above-described techniques may be performed to apply identification and prevention for known and unknown threats over the N6 interface in a 5G network and / or over the SGi interface in a 4G / LTE network.
[0096] As yet another example, the above-described techniques may be performed to apply application identification over an N6 interface in a 5G network and / or over an SGi interface in a 4G / LTE network.
[0097] As yet another example, the above-described techniques may be performed to apply URL filtering over the N6 interface in a 5G network and / or over the SGi interface in a 4G / LTE network.
[0098] Thus, service providers and / or enterprises can use the disclosed techniques and security platform to apply subscriber identity-based security across the boundaries of IP-based external networks (e.g., the Internet).
[0099] An exemplary system architecture for applying network slice ID-based security using user IDs and syslog messages in mobile networks
[0100] Accordingly, in some embodiments, the disclosed technology may involve a security platform (e.g., the security functionality / platform may be implemented using a firewall (FW) / next-generation firewall (NGFW), a network sensor operating in place of a firewall, or a Palo Alto Networks firewall, including, for example, Palo Alto Networks' PA Series Next-Generation Firewall, Palo Alto Networks' VM Series Virtualized Next-Generation Firewall, and CN Series Containerized Next-Generation Firewall) configured to provide DPI capabilities (e.g., including stateful inspection) of, for example, GTP-U sessions (e.g., GTP-U traffic) via various interfaces (e.g., RESTful API, N3, N6, and / or other interfaces within a 4G / 5G / 6G core network) to apply security to user plane traffic based on policy (e.g., Layer 7 security and / or other security policy enforcement), as described further below. This includes providing another (virtual) device / component that can implement security policies using the disclosed techniques, such as PANOS running on a virtual / physical NGFW solution commercially available from Cisco Systems, Inc., or another security platform / NFGW (which may also be implemented and configured to perform the disclosed techniques).
[0101] As will be described, in some embodiments, Network Slice ID / S-NSSAI (SST+SD) based security is performed using a security platform (e.g., NGFW102) deployed on the N6 interface in the 5G network.
[0102] To identify network slices end-to-end, the 5G standard uses information called Single Network Slice Selection Assistance Information (S-NSSAI). The S-NSSAI may include both the SST field and the SD field (e.g., in that case, the S-NSSAI length is 32 bits in total), or the SNSSAI may include only the SST field (e.g., in that case, the S-NSSAI length is only 8 bits).
[0103] The Slice / Service Type (SST) field can have standardized and non-standardized values. Values from 0 to 127 belong to the standardized SST range and are defined in 3GPP TS 23.501. According to the 5G standard, the following SSTs must be supported for all log types and security policies in the network slice column: SST values from 128 to 255 belong to an operator-specific range. Slice Differentiator (SD) refers to optional information that complements the slice / service type to distinguish between multiple network slices.
[0104] In some embodiments, applying network slice ID (e.g., including S-NSSAI) based security using user ID and syslog messages in a mobile network is similarly performed using a security platform deployed across the N6 interface in a 5G network, as similarly described above with respect to Figures 1C and 1D.
[0105] In one example implementation, the disclosed techniques for applying user ID and network slice ID-based security in a mobile network using a syslog message network may be performed using a security platform deployed in a 5G technology-based mobile network, similar to that shown in FIGS. 1C and 1D , except that in this example, the security platform (e.g., NGFW 102) uses an N6 interface to obtain real-time syslogs with UE IP and S-NSSAI information. Specifically, the mobile network has network functions that can generate syslog messages for predetermined events, such as bearer creation and bearer deletion. These network functions may be configured to send syslog messages containing information about the bearer creation and deletion events. A user ID agent in the security platform may be configured to parse these messages. For example, the user ID agent may be configured to parse creation events to map IP addresses (e.g., user equipment (UE) IP addresses) to network slice IDs, and also parse deletion events to delete old mappings. Deleting stale mappings is generally useful in mobile networks where IP address assignments may change, for example, when a UE is rebooted or during various other scenarios. Thus, in some embodiments, syslog parsing profiles are used to parse syslog messages to integrate with network functions from different equipment vendors that may send syslog messages in different formats (e.g., a user can create a custom profile for each format).
[0106] 2D is another example screen shot of a security platform interface at the N6 interface in L3 mode receiving syslog messages from the UPF in a 5G network, according to some embodiments. In this example, the UPF sends an event syslog (e.g., a syslog message) to the security platform (e.g., NGFW 102) whenever a new PDU session is created or deleted. Each syslog contains different fields, key fields for highlighting: event type, IMSI, IMEI, DNN, S-NSSAI, and Ue_IP.
[0107] Below is one example syslog message generated by UPF:
[0108] Jan 14 11:23:04 {"upf","type":"create_pdu_session","evt":{"imsi":"312444555717000","imei":"4442 332341119898","dnn":"dnn1bc4","s-nssai":"1:1000","user_addr":["172.16.15.112"]}}
[0109] The security platform (e.g., NGFW 102) receives the event syslog and creates a user ID / IP mapping. The user ID can be configured as an S-NSSAI, e.g., "1:1000." The syslog with the event "create_session" can be configured as the user ID login action, and "delete_session" can be used as the logout action.
[0110] Referring to FIG. 2D, an example screenshot of an interface of a security platform at the N6 interface in L3 mode receiving syslog messages from a UPF in a 5G network provides an example of a security policy configured with a user ID, where UE IMEI="1:1000".
[0111] For example, the above-described techniques may be performed to apply network slice ID-based security over the N6 interface in a private 5G network.
[0112] As another example, the above-described techniques may be performed to apply identification and prevention for known and unknown threats via the N6 interface in a 5G network.
[0113] As yet another example, the above-described techniques may be performed to apply application identification over an N6 interface in a 5G network.
[0114] As yet another example, the above-described techniques may be performed to apply URL filtering via the N6 interface in a 5G network.
[0115] Thus, service providers and / or enterprises can use the disclosed techniques and security platform to apply network slice ID-based security across the boundaries of IP-based external networks (e.g., the Internet).
[0116] Exemplary Use Cases Applying Subscriber ID-Based Security, Device ID-Based Security, and / or Network Slice ID-Based Security Using User IDs and Syslog Messages in Mobile Networks
[0117] The disclosed techniques for providing enhanced security for mobile / service provider networks using a security platform for security policy enforcement, including applying subscriber ID-based security, device ID-based security, and / or network slice ID-based security using user IDs and syslog messages in mobile networks, can be applied in various additional exemplary use case scenarios to facilitate enhanced security for mobile networks (e.g., 4G / 5G / 6G and later mobile networks), as will now be described with respect to various exemplary use cases.
[0118] As one exemplary use case for subscriber identity-based security using user identification and syslog messages in mobile networks, using the above-described techniques for applying subscriber identity-based security using user identification and syslog messages in mobile networks using a security platform for security policy enforcement, the following exemplary vulnerabilities may be detected and / or prevented for a group of enterprise 5G users: (1) CVE-2021-30860: Apple Multiple Products Integer Overflow Vulnerability, (2) CVE-2022-22620L Apple Safari Use-After-Free Vulnerability, (3) CVE-2022-22784: Zoom XMPP Stanza Smugling Vulnerability, and (4) CVE-2022-25235: Spring SecurityRegexRequestMatcher Authorization Bypass Vulnerability.
[0119] As one exemplary use case for device ID-based security using user identification and syslog messages in mobile networks, the following enhanced security actions can be performed using the above-described techniques for applying device ID-based security using user identification and syslog messages in mobile networks using a security platform for security policy enforcement: (1) detecting infected devices in a 5G network and blocking or restricting their network access, and (2) applying application control for enterprise 5G devices (e.g., allowing only trusted applications to communicate with intelligent sensors connected to a 5G network in a smart factory). Specifically, the following exemplary vulnerabilities can be detected and / or prevented for a group of enterprise 5G users using the above-described techniques for applying device ID-based security using user identification and syslog messages in mobile networks using a security platform for security policy enforcement: These vulnerabilities are: (1) CVE-2022-25845: FastJson Deserialization Vulnerability, (2) CVE-2019-7671: Prima Systems FlexAir Cross-Site Scripting Vulnerability, (3) CVE-2019-7667: Prima Systems FlexAir Brute Force Information Disclosure Vulnerability, and (4) CVE-2021-23282: Eaton Intelligent Power Management Stored Cross-Site Scripting Vulnerability.
[0120] As one exemplary use case for user identification and network slice ID-based security using syslog messages in mobile networks, using the above-described techniques for applying user identification and network slice ID-based security using syslog messages in mobile networks using a security platform for security policy enforcement, the following enhanced security actions can be performed: (1) investigating security events related to vertically related utilities, for example, to enterprise 5G customers of security services, and (2) a mobile network service provider offering bundled security with 5G services to different enterprise customers. Specifically, the following exemplary spyware may be detected and / or prevented for a group of enterprise 5G users using the above-described techniques that apply device ID-based security using user identification and syslog messages in mobile networks using a security platform for security policy enforcement: (1) Pingpull Command and Control Traffic, (2) APT34 Malicious Excel Downloader Traffic, (3) XANFPEZES Command and Control Traffic, and (4) Industroyer Command and Control Traffic.
[0121] As will now be apparent to those skilled in the art, the disclosed techniques for applying subscriber ID-based security, device ID-based security, and / or network slice ID-based security using user IDs and syslog messages using a security platform for security policy enforcement in mobile networks can be applied in a variety of additional example use case scenarios for detecting / preventing these and other types of attacks to promote enhanced security for various deployments and environments in mobile networks.
[0122] Exemplary Hardware Components of a Network Device for Applying Subscriber ID-Based Security, Device ID-Based Security, and / or Network Slice ID-Based Security Using User IDs and Syslog Messages in a Mobile Network
[0123] 3 is a functional diagram of hardware components of a network device for applying subscriber ID-based security, device ID-based security, and / or network slice ID-based security using user ID and syslog message networking in a mobile network, according to some embodiments. The illustrated example is a representation of physical / hardware components that may be included in network device 300 (e.g., an appliance, gateway, or server capable of implementing the security platform disclosed herein). Specifically, network device 300 includes a high-performance multi-core CPU 302 and RAM 304. Network device 300 also includes storage 310 (e.g., one or more hard disks or solid-state storage units) that may be used to store policies and other configuration information, as well as signatures. In one embodiment, storage 310 stores predetermined information (e.g., subscriber ID, device ID, and / or network slice ID along with parameters associated with / extracted from user ID and syslog messages) extracted from traffic monitored via various interfaces (e.g., SGi, N6, and / or other interfaces) to implement the disclosed security policy enforcement techniques for applying context-based security via various interfaces, including the disclosed techniques for applying subscriber ID-based security, device ID-based security, and / or network slice ID-based security using user ID and syslog messages in a mobile network using a security platform, as similarly described above with respect to Figures 1A-1D and 2A-2D. Network device 300 may also include one or more optional hardware accelerators.For example, network device 300 may include a cryptographic engine 306 configured to perform encryption and decryption operations, and one or more FPGAs 308 configured to perform signature matching, function as a network processor, and / or perform other tasks.
[0124] Exemplary logical components of a network device for applying subscriber ID-based security, device ID-based security, and / or network slice ID-based security using user IDs and syslog messages in a mobile network
[0125] 4 is a functional diagram of logical components of a network device for enforcing subscriber ID-based security, device ID-based security, and / or network slice ID-based security using user ID and syslog message networks in a mobile network, according to some embodiments. The illustrated example is a representation of logical components that may be included in network device 400 (e.g., a data appliance that implements the disclosed security features / platforms and can perform the disclosed techniques for enforcing subscriber ID-based security, device ID-based security, and / or network slice ID-based security using user ID and syslog message networks in a mobile network). As shown, network device 400 includes a management plane 402 and a data plane 404. In one embodiment, the management plane is responsible for managing user interactions, such as by configuring policies and providing a user interface for viewing log data. The data plane is responsible for managing data, such as by performing packet processing and session handling.
[0126] Assume that a mobile device attempts to access a resource (e.g., a remote website / server, an MEC service, an IoT device, or another resource) using an encrypted session protocol such as SSL. The network processor 406 is configured to monitor packets from the mobile device and provide the packets to the data plane 404 for processing. The flow 408 identifies the packet as part of a new session and creates a new session flow. Subsequent packets are identified as belonging to the session based on the flow lookup. If applicable, SSL decryption is applied by the SSL decryption engine 410 using various techniques as described herein. Otherwise, processing by the SSL decryption engine 410 is omitted. The application identification (APP ID) module 412 is configured to determine what type of traffic a session involves (e.g., IP traffic and / or other network protocols, such as GTP-U traffic, between the various monitored interfaces, as similarly described above with respect to FIGS. 1A-1D) and identify a user associated with the traffic flow (e.g., identify a user ID and application ID (APP-ID) as described herein). For example, the APP ID 412 may recognize a GET request in the received data and conclude that the session requires an HTTP decoder 414. As another example, the APP ID 412 may recognize a GTP-U session message carrying encapsulated IP traffic from the UE (e.g., via various interfaces, as similarly described above with respect to FIGS. 1A-1D) and conclude that the session requires a GTP-U decoder (e.g., to extract information exchanged in the GTP-U traffic session via the various interfaces, including various parameters, as similarly described above with respect to FIGS. 1A-1D and 2A-2D). For each type of protocol, there is a corresponding decoder 414.In one embodiment, application identification is performed by an application identification module (e.g., an APP ID component / engine), and user identification is performed by a separate component / engine. Based on the determination made by APP ID 412, the packet is sent to the appropriate decoder 414. Decoder 414 is configured to assemble packets (which may be received out of order, for example) into the correct order, perform tokenization, and extract information (e.g., to extract various information exchanged in GTP-U traffic over various interfaces, as also described above and further below). Decoder 414 also performs signature matching to determine what should happen to the packet. SSL encryption engine 416 performs SSL encryption using various techniques as described herein, and the packet is then forwarded using forwarding component 418, as shown. Also shown, policy 420 is received and stored in management plane 402. In one embodiment, policy enforcement (e.g., a policy may include one or more rules, which may be specified using domain and / or host / server names, and the rules may apply one or more signatures or other matching criteria or heuristics, such as for security policy enforcement on subscriber / IP flows on a service provider network based on monitored GTP-U / IP traffic and / or various extracted parameters / information from monitored GTP-U / IP and / or other protocol traffic, such as SGi / N6 / other interfaces, as similarly described above with respect to Figures 1A-1D) is applied based on the monitored, decoded, identified, and decoded session traffic flows as described herein with respect to various embodiments.
[0127] 4 , an interface (I / F) communicator 422 is also provided for security platform manager communication. In some cases, network communications of other network elements on the service provider network are monitored using the network device 400, and the data plane 404 supports decoding of such communications (e.g., the network device 400, including the I / F communicator 422 and the decoder 414, may be configured to monitor and / or communicate over reference point interfaces, such as, for example, SGi, N6, and / or other interfaces where wired and wireless network traffic flows exist). Thus, the network device 400, including the I / F communicator 422, may be used to implement the disclosed techniques for applying subscriber ID-based security, device ID-based security, and / or network slice ID-based security using user ID and syslog messages in mobile networks, as described above and further below.
[0128] Additional example processes for the disclosed techniques for applying subscriber ID-based security, device ID-based security, and / or network slice ID-based security using user IDs and syslog messages in mobile networks will now be described.
[0129] Exemplary Process for Applying Subscriber ID-Based Security, Device ID-Based Security, and / or Network Slice ID-Based Security Using User IDs and Syslog Messages in a Mobile Network
[0130] 5 is a flowchart of a process for employing subscriber ID-based security, device ID-based security, and / or network slice ID-based security using user ID and syslog message networking in a mobile network, according to some embodiments. In some embodiments, process 500 shown in FIG. 5 is performed by the security platforms and techniques also described above, including the embodiments described above with respect to FIGS. 1A through 4. In one embodiment, process 500 is performed by the data appliance 300 described above with respect to FIG. 3, the network device 400 described above with respect to FIG. 4, a virtual appliance (e.g., Palo Alto Networks' VM Series Virtualized Next-Generation Firewall, CN Series Container Next-Generation Firewall, and / or other commercially available virtual-based or container-based firewalls may be similarly implemented and configured to perform the disclosed techniques), an SDN security solution, a cloud security service, and / or a combination or hybrid implementation of the foregoing as described herein.
[0131] At 502, monitoring network traffic on the mobile network at a security platform to identify new sessions is performed. For example, the security platform (e.g., a firewall, a network sensor operating on behalf of a firewall, or another device / component capable of implementing a security policy) may in some cases monitor various protocols, such as GTP-U (e.g., via SGi, N6, and / or other interfaces) and / or other protocols on the mobile network, and more specifically, may monitor various interfaces, such as the SGi and N6 interfaces, as also described above with respect to Figures 1A-1D, by performing the disclosed techniques.
[0132] At 504, parsing the syslog message with a user ID agent in the security platform to extract a plurality of parameters may be performed, such as those similarly described above with respect to Figures 1A-1D and 2A-2D.
[0133] At 506, to apply context-based security in the mobile network, enforcing a security policy for the new session in the security platform based on one or more of a plurality of parameters including one or more of a subscriber ID, a device ID, and a network slice ID is performed. For example, enforcing the security policy may include allowing or blocking the session.
[0134] 6 is another flowchart of a process for applying subscriber ID-based security, device ID-based security, and / or network slice ID-based security using user ID and syslog message networking in a mobile network, according to some embodiments. In some embodiments, process 600 shown in FIG. 6 is performed by the security platforms and techniques also described above, including the embodiments described above with respect to FIGS. 1A through 4. In one embodiment, process 600 is performed by the data appliance 300 described above with respect to FIG. 3, the network device 400 described above with respect to FIG. 4, a virtual appliance (e.g., Palo Alto Networks' VM Series Virtualized Next-Generation Firewall, CN Series Container Next-Generation Firewall, and / or other commercially available virtual-based or container-based firewalls may be similarly implemented and configured to perform the disclosed techniques), an SDN security solution, a cloud security service, and / or a combination or hybrid implementation of the foregoing as described herein.
[0135] At 602, monitoring network traffic on the mobile network at a security platform to identify new sessions is performed. For example, the security platform (e.g., a firewall, a network sensor operating on behalf of a firewall, or another device / component capable of implementing a security policy) may in some cases monitor various protocols, such as GTP-U (e.g., via SGi, N6, and / or other interfaces) and / or other protocols on the mobile network, and more specifically, may monitor various interfaces, such as the SGi and N6 interfaces, as also described above with respect to FIGS. 1A-1D by performing the disclosed techniques.
[0136] At 604, parsing the syslog message with a user ID agent in the security platform to extract a plurality of parameters may be performed, such as those similarly described above with respect to Figures 1A-1D and 2A-2D.
[0137] At 606, selecting a security policy for applying subscriber ID-based security, device ID-based security, and / or network slice ID-based security using the user ID and the syslog message in the security platform is performed. For example, parameters such as those similarly described above with respect to Figures 1A-1D and 2A-2D can be extracted.
[0138] At 608, enforcing a security policy for the new session at the security platform based on one or more of a plurality of parameters including one or more of a subscriber ID, a device ID, and a network slice ID is performed to apply context-based security in the mobile network. For example, enforcing the security policy may include allowing or blocking the session.
[0139] Although the foregoing embodiments have been described in some detail for purposes of clarity of understanding, the invention is not limited to the details provided. There are many alternative ways of implementing the invention. The disclosed embodiments are illustrative and not limiting.
Claims
1. 1. A system including a processor and a memory, The processor: monitoring network traffic on the mobile network at a security platform to identify new sessions; extracting a plurality of parameters by parsing the syslog message using a user ID agent in the security platform; Enforcing a security policy for the new session in the security platform based on one or more of the plurality of parameters, including one or more of a subscriber ID, a device ID, and a network slice ID, to apply context-based security in the mobile network. It is structured as follows: the memory is coupled to the processor and configured to provide instructions to the processor; system.
2. the context-based security includes subscriber identity-based security; The system of claim 1 .
3. The context-based security includes device ID-based security. The system of claim 1 .
4. The context-based security includes network slice ID-based security. The system of claim 1 .
5. the security platform is configured with a plurality of security policies for applying subscriber ID-based security, device ID-based security, and / or network slice ID-based security in the mobile network. The system of claim 1 .
6. The processor further comprises: The security platform is configured to receive the syslog message from a 4G network entity and / or a 5G network entity. The system of claim 1 .
7. The processor further comprises: configured to receive, at the security platform, the syslog message from a 4G network entity; The mobile network is a private 4G network. The system of claim 1 .
8. The processor further comprises: The security platform is configured to receive the syslog message from a 5G network entity; The mobile network is a private 5G network. The system of claim 1 .
9. The processor further comprises: receiving, at the security platform, the syslog messages from a 4G network entity and / or a 5G network entity; and Extracting one or more parameters for performing subscriber ID-based security, device ID-based security, and / or network slice ID security; It is configured as follows: The system of claim 1 .
10. The processor further comprises: configured to perform level threat identification and prevention in the mobile network. The system of claim 1 .
11. The processor further comprises: configured to perform application identification and control in the mobile network. The system of claim 1 .
12. The processor further comprises: configured to perform URL filtering in the mobile network. The system of claim 1 .
13. The processor further comprises: and blocking the new session from accessing a resource based on the security policy. The system of claim 1 .
14. The processor further comprises: the new session is configured to allow access to resources based on the security policy. The system of claim 1 .
15. 1. A method comprising: monitoring network traffic on a mobile network at a security platform to identify new sessions; extracting a plurality of parameters by parsing the syslog message using a user ID agent in the security platform; implementing a security policy for the new session in the security platform based on one or more of the plurality of parameters including one or more of a subscriber ID, a device ID, and a network slice ID, thereby applying context-based security in the mobile network; A method comprising:
16. the context-based security includes subscriber identity-based security; 16. The method of claim 15.
17. The context-based security includes device ID-based security.
16. The method of claim 15.
18. The context-based security includes network slice ID-based security.
16. The method of claim 15.
19. The method further comprises: blocking the new session from accessing a resource based on the security policy; 16. The method of claim 15, comprising:
20. A computer program comprising a plurality of instructions, The computer program is stored in a non-transitory computer-readable storage medium, and when the instructions are executed by a processor, the computer monitoring network traffic on a mobile network at a security platform to identify new sessions; extracting a plurality of parameters by parsing the syslog message using a user ID agent in the security platform; implementing a security policy for the new session in the security platform based on one or more of the plurality of parameters including one or more of a subscriber ID, a device ID, and a network slice ID, thereby applying context-based security in the mobile network; To implement Computer program.
Citation Information
Patent Citations
Session information management method and session information management apparatus
JP2005110302A
Multi-access distributed edge security in mobile networks
JP2021513299A
Cellular internet of things battery drain prevention in mobile networks
US20210099487A1
Securing control and user plane separation in mobile networks
US20210409375A1
Security for cellular internet of things in mobile networks based on subscriber identity and application identifier
US20220201046A1