Securing control and user plane separation in a mobile network
A security platform performs stateful inspection of PFCP messages to enforce security policies, addressing the challenge of separating control and user planes in mobile networks, enhancing security by preventing attacks and ensuring secure communication.
Patent Information
- Application Number
- JP2025182393
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2020-06-30
- Filing Date
- 2025-10-29
- Publication Date
- 2026-02-03
AI Technical Summary
Existing mobile networks face challenges in securing and verifying communication between control and user planes, particularly in 5G networks, necessitating improved techniques for monitoring network traffic and enforcing security policies to ensure separation.
Implementing a security platform that performs stateful inspection of Packet Forwarding Control Protocol (PFCP) messages across interfaces in 4G and 5G networks to extract information for setting up sessions and tracking control message flows, using techniques such as PFCP stateful inspection and DPI functionality to enforce security policies.
Ensures secure separation of control and user planes by detecting and preventing attacks like DoS and SEID spoofing, facilitating secure communications between cloud-based control infrastructure and distributed edge locations.
Smart Images

Figure 2026016633000001_ABST
Abstract
Description
[Background technology]
[0001] A firewall generally secures a network from unauthorized access while allowing authorized communications to pass through the firewall. A firewall is typically a device or set of devices, or software running on a device, such as a computer, that provides firewall functionality for network access. For example, a firewall can be integrated into the operating system of a device (e.g., a computer, smartphone, or other network-enabled appliance). A firewall can also be integrated into or run as software in a computer server, gateway, network / routing device (e.g., a network router), or data appliance (e.g., a security appliance or other special-purpose equipment).
[0002] Firewalls typically deny or allow network transmissions based on a set of rules. These sets of rules are often referred to as policies. For example, a firewall can filter inbound traffic by applying a set of rules or policies. A firewall can also filter outbound traffic by applying a set of rules or policies. A firewall can also perform basic routing functions. [Brief explanation of the drawings]
[0003] Various embodiments of the present invention are disclosed in the following detailed description and accompanying drawings. [Figure 1]FIG. 1 is a block diagram of a 5G wireless network architecture with a security platform for ensuring control and user plane separation in a mobile network, according to some embodiments. [Figure 2A] FIG. 2A is a block diagram of a 4G wireless network architecture with a security platform for ensuring control and user plane separation in a mobile network, according to some embodiments. [Figure 2B] FIG. 2B is another block diagram of a 4G wireless network architecture with a security platform for ensuring control and user plane separation in a mobile network, according to some embodiments. [Figure 2C] FIG. 2C is another block diagram of a 4G wireless network architecture with a security platform for ensuring control and user plane separation in a mobile network, according to some embodiments. [Figure 2D] FIG. 2D is another block diagram of a 4G wireless network architecture with a security platform for ensuring control and user plane separation in a mobile network, according to some embodiments. [Figure 3A] FIG. 3A is a protocol sequence diagram for the PFCP session establishment procedure. [Figure 3B] FIG. 3B is a protocol sequence diagram for the PFCP session modification procedure. [Figure 3C] FIG. 3C is a protocol sequence diagram for the PFCP session release procedure. [Figure 4] FIG. 4 is a functional diagram of hardware components of a network device for ensuring control and user plane separation in a mobile network, according to some embodiments. [Figure 5]FIG. 5 is a functional diagram of logical components of a network device for ensuring control and user plane separation in a mobile network, according to some embodiments. [Figure 6] FIG. 6 is a flow chart of a process for ensuring control and user plane separation in a mobile network, according to some embodiments. [Figure 7] FIG. 7 is another flow diagram of a process for ensuring control and user plane separation in a mobile network, according to some embodiments. DETAILED DESCRIPTION OF THE INVENTION
[0004] The present invention can be implemented in various ways, including as a processor, such as an apparatus, a system, an article of manufacture, a computer program product embodied in a computer-readable storage medium, and / or a processor configured to execute instructions stored in and / or provided by a memory coupled to the processor. In this specification, these implementations, or other forms the present invention may take, are referred to as techniques. In general, the order of steps in disclosed processes may be varied within the scope of the present invention. Unless otherwise specified, components, such as a processor or memory, described as being configured to perform a task may be implemented as general components temporarily configured to perform the task at a given time, or as specific components manufactured to perform the task. As used herein, the term “processor” refers to one or more devices, circuits, and / or processing cores configured to process data, such as computer program instructions.
[0005] A detailed description of one or more embodiments of the present invention is provided below along with accompanying figures that illustrate the principles of the invention. While the present invention will be described in connection with such embodiments, the invention is not limited to any embodiment. The scope of the present invention is limited only by the claims, and the present invention encompasses numerous alternatives, modifications, and equivalents. In the following description, numerous specific details are set forth to provide a thorough understanding of the present invention. These details are provided for the purpose of example, and the present invention may be practiced according to the claims without some or all of these specific details. For the purposes of clarity, technical material known in the art related to the present invention has not been described in detail so as not to unnecessarily obscure the present invention.
[0006] A firewall generally protects a network from unauthorized access while allowing authorized communications to pass through the firewall. A firewall is typically a device or set of devices, or software running on a device, that provides firewall functionality for network access. For example, a firewall can be integrated into the operating system of a device (e.g., a computer, smartphone, or other type of network-enabled device). Firewalls can also be integrated into or run as software on computer servers, gateways, network / routing devices (e.g., network routers), and data appliances (e.g., security appliances or other types of special-purpose devices).
[0007] Firewalls typically deny or allow network transmissions based on a set of rules. These sets of rules are often referred to as policies. For example, a firewall can filter inbound traffic by applying a set of rules or policies to prevent unwanted external traffic from reaching a protected device. A firewall can also filter outbound traffic by applying a set of rules or policies (e.g., allow, block, monitor, notify or log, and / or other actions can be specified in firewall / security rules or firewall / security policies, which can be triggered based on various criteria, as described herein). A firewall can also apply antivirus protection, malware detection / prevention, or intrusion protection by applying a set of rules or policies.
[0008] A security device (e.g., a security appliance, a security gateway, a security service, or other security device) can include various security functions (e.g., firewalls, anti-malware, intrusion prevention / detection, proxies, and / or other security functions), network functions (e.g., routing, quality of service (QoS), workload balancing of network-related resources, and other network functions), and / or other functions. For example, a routing function can be based on source information (e.g., a secure IP address and port), destination information (e.g., a destination IP address and port), and protocol information.
[0009] Basic packet filtering firewalls filter network communication traffic by inspecting individual packets sent over a network (e.g., packet filtering firewalls or first-generation firewalls, which are stateless packet filtering firewalls). Stateless packet filtering firewalls typically inspect the individual packets themselves and then apply rules based on the inspected packets (e.g., using a combination of the packet's source and destination address information, protocol information, and port numbers).
[0010] Application firewalls can also perform application layer filtering (e.g., using an application layer filtering firewall or second-generation firewall that operates at the application level of the TCP / IP stack). Application layer filtering firewalls or application firewalls can generally identify certain applications and protocols (e.g., web browsing using the Hypertext Transfer Protocol (HTTP), Domain Name System (DNS) requests, file transfers using the File Transfer Protocol (FTP), and various other types of applications and other protocols, such as Telnet, DHCP, TCP, UDP, and TFTP (GSS)). For example, an application firewall can block unauthorized protocols that attempt to communicate over standard ports (e.g., unauthorized / out-of-policy protocols trying to sneak in using non-standard ports for that protocol can generally be identified using an application firewall).
[0011] Stateful firewalls can also perform stateful-based packet inspection, where each packet is inspected within the context of the set of packets associated with that network transmission packet / packet flow (e.g., a stateful firewall or a third-generation firewall). This firewall technique is commonly referred to as stateful packet inspection because it keeps a record of all connections passing through the firewall and can determine whether a packet is the start of a new connection, part of an existing connection, or an invalid packet. For example, the state of a connection itself can be one of the criteria that triggers a rule in a policy.
[0012] Advanced or next-generation firewalls can perform stateless and stateful packet filtering and application layer filtering, as described above. Next-generation firewalls can also perform additional firewall techniques. For example, certain newer firewalls, sometimes referred to as advanced or next-generation firewalls, can also identify users and content. In particular, certain next-generation firewalls have expanded the list of applications they can automatically identify to thousands of applications. Examples of such next-generation firewalls are commercially available from Palo Alto Networks (e.g., Palo Alto Networks PA Series Next-Generation Firewalls and Palo Alto Networks VM Series Virtualized Next-Generation Firewalls).
[0013] For example, Palo Alto Networks' next-generation firewalls enable enterprises and service providers to identify and control applications, users, and content using a variety of identification technologies—not just ports, IP addresses, and packets. APP-ID for precise application identification TM (e.g., APP ID), User-ID for user identification (e.g., user or user group)TM (e.g., User ID), and Content-ID for real-time content scanning (e.g., web surfing control and data and file transfer restrictions) TM (e.g., Content ID). These identification technologies allow enterprises to securely enable applications using business-relevant concepts instead of following the traditional approach offered by traditional port-blocking firewalls. Additionally, special-purpose hardware for next-generation firewalls, such as those implemented as dedicated appliances, generally offers higher performance levels for application inspection than software running on general-purpose hardware (e.g., Palo Alto Networks' PA Series Next-Generation Firewalls, security appliances offered by Palo Alto Networks, utilize dedicated, function-specific processing tightly integrated with a single-pass software engine to maximize network throughput while minimizing latency).
[0014] Technical and Security Challenges in Today's Mobile Networks for Service Providers
[0015] Converged (mobile and fixed) network operators worldwide are currently in the process of deploying standalone 5G mobile network technologies. 5G mobile networks will provide connectivity to enterprise customers using control and user plane separation (CUPS). Thus, it is important to secure and verify communication between the control network functions in a 5G mobile network (e.g., a Session Management Function (SMF) located in the central packet core / cloud packet core and a User Plane Function (UPF) located at the customer premises / access sites / distribution sites).
[0016] Accordingly, service provider networks present technical and security challenges for devices within their mobile networks. Thus, what is needed are new and improved security techniques for devices in such service provider network environments (e.g., mobile networks). Specifically, what is needed are new and improved solutions for monitoring such network traffic and enforcing security policies (e.g., firewall policies) for devices communicating over service provider networks.
[0017] Overview of technologies for ensuring separation of control and user planes in mobile networks
[0018] Technical and security challenges exist in service provider networks to ensure separation of the control and user planes in mobile networks. Specifically, what is needed are new and improved techniques for ensuring separation of the control and user planes in mobile network environments (e.g., 4G and / or 5G mobile networks). More specifically, new and improved solutions are needed for monitoring mobile network traffic and enforcing security policies (e.g., security / firewall policies) to ensure separation of the control and user planes in mobile networks.
[0019] As further described below, PFCP is a 3GPP® protocol used at the Sx / N4 interface between the control plane and user plane functions (e.g., as specified in 3GPP Technical Specification (TS) 29.244 v15.7 for LTE; 5G; Interface between the Control Plane and the User Plane nodes (e.g., and later releases / versions)).
[0020] In some embodiments, to ensure control and user plane separation in mobile networks that can be performed by a security platform, new and improved techniques for Packet Forwarding Control Protocol (PFCP) stateful inspection are disclosed, as further described below.
[0021] For example, a new and improved technique of PFCP stateful inspection to ensure separation of control and user planes in a mobile network can be performed by a security platform in a 5G technology-based mobile network (e.g., a 5G mobile network) by analyzing PFCP messages across the N4 interface between a Session Management Function (SMF) and a User Plane Function (UPF) to extract certain information used to set up PFCP sessions and track control message flows.
[0022] As another example, a new and improved technique of PFCP stateful inspection to ensure separation of control and user planes in a mobile network may be performed by a security platform in a 4G technology-based mobile network (e.g., a 4G mobile network) by analyzing PFCP messages across the Sxa interface between a Serving Gateway (SG)-C and an SG-U, the Sxb interface between a Packet Data Network (PDN) Gateway-C and a PDN Gateway-U, and the Sxc interface between a Traffic Detection Function (TDF)-C and a TDF-U to extract predetermined information used to set up a PFCP session and track control message flow.
[0023] Thus, disclosed in accordance with some embodiments is a new and improved security solution that facilitates providing security (e.g., network-based security) using a security platform (e.g., a firewall (FW) / next-generation firewall (NGFW), a network sensor acting in place of a firewall, or another (virtual) device / component that can implement security policies using the disclosed techniques) within a mobile network (e.g., a 4G / 5G mobile network) on PFCP traffic. For example, the disclosed techniques for ensuring separation of control and user planes in a mobile network can provide identification and prevention of attacks, including Denial of Service (DoS), Session Endpoint Identifier (SEID) spoofing, and SEID guessing across Packet Forwarding Control Protocol (PFCP) in various 4G / 5G network locations, including local area data networks, core networks, multi-access distributed edge locations, enterprise networks with local User Plane Functions (UPFs), and / or various other 4G / 5G network locations.
[0024] As described further below, various techniques are disclosed for ensuring control and user plane separation in a mobile network. In some embodiments, a system / process / computer program product for ensuring control and user plane separation in a mobile network according to some embodiments includes monitoring network traffic in the mobile network at a security platform to identify a Packet Forwarding Control Protocol (PFCP) message associated with a new session, where the mobile network includes a 4G network or a 5G network, extracting a plurality of parameters from the PFCP message at the security platform (e.g., a 5-tuple + node ID (optional) associated with a PFCP association, as described further below), and enforcing a security policy at the security platform for the new session based on one or more of the plurality of parameters to ensure control and user plane separation in the mobile network.
[0025] For example, the security platform can parse the PFCP message to extract the source IP address, SEID 1, the destination IP address, SEID 2, and protocol parameters in use related to the PFCP association. As another example, the security platform can parse the PFCP message to extract the node ID associated with the PFCP association.
[0026] In one implementation, the security platform is configured with security policies to perform denial of service (DoS) attack detection and prevention to ensure separation of the control and user planes in mobile networks.
[0027] In another implementation, a security platform is configured with security policies to perform detection and prevention of session endpoint identifier (SEID) spoofing attacks to ensure separation of control and user planes in mobile networks.
[0028] The disclosed techniques for ensuring control and user plane separation in mobile networks can be applied to facilitate various secure mobile network solutions. As one example, a mobile network operator can use the disclosed techniques to secure communications between a cloud-based control infrastructure and distributed edge locations. As another example, an enterprise customer with private 4G / 5G connectivity can use the disclosed techniques to secure communications between a local user plane function (UPF) and a cloud-based control infrastructure.
[0029] These and other embodiments for ensuring control and user plane separation in mobile networks are described further below.
[0030] Exemplary System Architecture for Ensuring Control and User Plane Separation in Mobile Networks
[0031] Generally, 5G refers to the fifth generation of mobile communications systems. 3 rdThe Third Generation Partnership Project (3GPP) includes seven telecommunications standards development organizations (i.e., ARIB, ATIS, CCSA, ETSI, TSDSI, TTA, and TTC). The project covers cellular telecommunications network technologies, including radio access, core transport networks, and service functions. The specifications also address non-radio access to the core network and interworking with Wi-Fi networks, and provide hooks for other organizations developing 5G standards, including ITU, IETF, and ETSI. Some of the improvements in the new 5G network standards include multi-edge computing, low latency (e.g., approximately less than 10 milliseconds (MS)), high throughput (e.g., multi-Gbps), distribution, network function virtualization infrastructure, and orchestration, analytics, and automation.
[0032] The 5G architecture is defined in 3GPP TS 23.501 v16.4.0 (available at, for example, https: / / portal.3GPP.org / desktopmodules / Specifications / SpecificationDetails.aspx?specificationId=3144) (e.g., and later releases / versions) as service-based, and interactions between network functions (NFs) are expressed in two ways: (1) the service-based representation, where NFs in the control plane (CP) enable other authorized network functions to access services; and (2) the reference point representation, which focuses on interactions between pairs of NFs defined by point-to-point reference points between any two network functions.
[0033] In the 5G architecture, the user plane protocol stack between the access network and the core across the backbone network via the N3 interface (e.g., between the Radio Access Network (RAN) and the UPF element) is based on the GPRS Tunnel Protocol User Plane (GTP-U) over UDP protocol, and that across the N4 interface (e.g., between the UPF element and the SMF element) is also based on the Packet Forwarding Control Protocol (PFCP) over UDP protocol. The control plane NF of the 5G system architecture is based on a service-based architecture. HTTP / 2 is the protocol used across the service-based interface. The new 5G access network protocol is based on the Stream Control Transmission Protocol (SCTP).
[0034] Thus, in some embodiments, the disclosed technology includes providing a security platform configured to provide DPI functionality (e.g., including stateful inspection) related to GTP-U sessions and new HTTP / 2-based TCP sessions, facilitating correlation between monitored GTP-U tunnel sessions and new HTTP / 2-based TCP sessions, and, as another example, correlation between monitored GTP-U tunnels (e.g., on the N3 interface) and PFCP sessions (e.g., on the N4 / Sx interface), as described further below. (For example, the security functionality / platform can be implemented using a firewall (FW) / next-generation firewall (NGFW), a network sensor operating in place of a firewall, or another (virtual) device / component that can implement security policies using the disclosed techniques, such as a commercially available virtual / physical NGFW solution from Palo Alto Networks, or PANOS running on another security / NFGW.)
[0035] In some embodiments, the security platform is configured to provide the following DPI capabilities: stateful inspection of N3 GTP-U tunnels and / or N4 GTP-U tunnels, content inspection of N3 GTP-U tunnels (e.g., inspecting the contents of inner IP sessions of N3 GTP-U tunnels), and / or content inspection of N4 / Sx PFCP sessions (e.g., inspecting the contents of N4 / Sx PFCP sessions), support for 3GPP Technical Specification (TS) 29.274 v15.3.0 Release 15 (e.g., and later releases / versions) for Procedures for 5G Systems Supporting 5G Cellular Technologies, and support for 3GPP Technical Specification (TS) 29.281 v15.4.0 Release 14 (e.g., and later releases / versions) for GTP-U.
[0036] 1 is a block diagram of a 5G wireless network architecture including a security platform for ensuring control and user plane separation in a mobile network, according to some embodiments. Specifically, FIG. 1 illustrates an example of a 5G mobile network environment for ensuring control and user plane separation in a mobile network, including security platforms 102a and 102b for ensuring control and user plane separation (e.g., a security function / platform may be a firewall (FW) / next-generation firewall (NGFW), a network sensor operating in place of a firewall, or another (virtual) device / component that can implement security policies using the disclosed techniques), as described further below. As shown, the 5G mobile network environment also includes: Fixed / wired access, as indicated at 104, non-3GPP access such as Wi-Fi access, as indicated at 106, 5G Radio Access Network (RAN) access, as indicated at 108, 4G RAN access, as indicated at 110, and / or other networks (not shown in FIG. 1 ) for facilitating data communications for subscribers (e.g., using user equipment (UE) such as smartphones, laptops, computers (which may be at fixed locations), and / or other cellular-enabled computing devices / appliances or other network communication-enabled devices such as CIoT devices), including a central data network (e.g., the Internet) for accessing various applications, web services, content hosts, etc., and / or other networks. As shown in FIG. 1, each of the 5G network access mechanisms 104, 106, 108, and 110 communicates with 5G user plane functions 112a and 112b (e.g., via an S1-U interface), which passes through security platforms 102a and 102b to communicate with 5G user plane functions 112a and 112b, respectively.
[0037] 1, the illustrated N4 interface provides an interface between the UPF 112a / b and 5G core control / signaling functions, including a session management function (SMF) 130, via PFCP over UDP. The core network 140 includes the SMF 130 in communication with a 5G user plane function 132, which is in communication with the central data network 120.
[0038] 1, network traffic communications are monitored using security platforms 102a and 102b. As shown, network traffic communications are monitored / filtered in 5G networks using security platforms 102a and 102b (e.g., (virtual) devices / appliances each including a firewall (FW), a network sensor acting in place of a firewall, or another device / component that can implement security policies using the disclosed techniques) configured to perform the disclosed techniques for ensuring control and user plane separation in mobile networks, similar to those described above and further below.
[0039] Additionally, the security platforms 102a and 102b may also communicate with a cloud security service 122 (e.g., WildFire, a commercially available cloud security service provided by Palo Alto Networks) via the Internet or the like. TMThe network may also communicate with commercially available cloud-based security services, such as cloud-based malware analysis environments, which may include automated security analysis of malware samples as well as analysis by security experts, or similar solutions from other vendors. For example, cloud security services 122 may be used to provide the security platform with dynamic prevention signatures of malware, DNS, URL, CNC malware, and / or other malware, as well as to receive malware samples for further security analysis.
[0040] Referring to FIG. 1, in this example 5G mobile network environment, security platforms 102a and 102b perform PFCP stateful inspection by analyzing PFCP messages (e.g., PFCP over UDP) on the N4 interface between UPFs 112a and 112b and SMF 130, respectively, to extract specific information used to set up a PFCF session, and to track the control message flow described below.
[0041] As will become apparent, to promote security of the separation of the control and user planes in a mobile network, one or more security platforms for network traffic communications at various locations within the 5G network (e.g., a 5G network or a converged 5G network) can be used to monitor / filter network traffic communications.
[0042] 2A is a block diagram of a 4G wireless network architecture including a security platform for ensuring control and user plane separation in a mobile network, according to some embodiments. Specifically, FIG. 2A illustrates an exemplary 4G mobile network environment for ensuring control and user plane separation in a mobile network, including security platforms 202a and 202b (e.g., the security function / platform can be implemented using a firewall (FW) / next-generation firewall (NGFW), a network sensor acting in place of a firewall, or another (virtual) device / component that can implement security policies using the disclosed techniques) for ensuring control and user plane separation, as described further below. The 4G mobile network environment may also include fixed / wired access (not shown in FIG. 2A), non-3GPP access such as Wi-Fi access (not shown in FIG. 2A), 4G Radio Access Network (RAN) access as shown at 204, and / or other networks (not shown in FIG. 2A) that facilitate data communications for subscribers (e.g., using user equipment (UE) such as smartphones, laptops, computers (which may be at a fixed location), and / or other cellular-enabled computing devices / appliances such as CIoT devices, or other network communication-enabled devices), including via a central data network (e.g., the Internet) 220 for accessing various applications, web services, content hosts, etc., and / or other networks.
[0043] As shown in FIG. 2A, the 4G network access mechanism eNodeB 204 is in communication with user plane network elements including a combined Serving Gateway (SGW) and Packet Gateway (PGW) for user plane traffic shown as SGW-U+PGW-U 206, which passes through security platform 202a to communicate with SGW-U+PGW-U 206.
[0044] 2A , the core network 210 includes control plane network elements including a combined Serving Gateway (SGW) and Packet Data Network (PDN) Gateway (PGW) for control plane traffic, shown as SGW-C+PGW-C 214, which communicates with a PGW-U 216 through security platform 202b. The core network 210 also includes a PGW-U 216 for user plane traffic to facilitate access to a central data network 220. Specifically, an Sxa interface provides an interface between the SGW-C 214 and the SGW-U 206 via PFCP over UDP, and an Sxb interface provides an interface between the PGW-C 214 and the PGW-U 216 via PFCP over UDP.
[0045] As also shown, security platform 202a (e.g., and other security platforms may similarly communicate with security cloud services) also has network communication with security service 222 (e.g., a commercially available cloud-based security service such as the WildFire™ (WF) cloud-based malware analysis environment, a commercially available cloud security service from Palo Alto Networks, which includes automated security analysis of malware samples as well as analysis by security experts, or may utilize similar solutions from other vendors).
[0046] 2A, network traffic communications can be monitored using security platforms 202a and 202b (e.g., which can be located in various locations to monitor Sxa, Sxb, and / or other communications) in a manner similar to that described above with respect to FIG. 1 or as further described below. In this implementation, security platforms 202a and 202b are located in this exemplary 4G mobile network environment and monitor and analyze PFCF messages (e.g., PFCP over UDP) on the Sxa interface between a Serving Gateway-C, indicated at 214, and a Serving Gateway-U, indicated at 206, and the Sxb interface between a PDN Gateway-C, indicated at 21, and a PDN Gateway-U, indicated at 216, to extract predetermined information used to set up a PFCF session and to track control message flow as further described below.
[0047] 2B is another block diagram of a 4G wireless network architecture including security platforms for ensuring control and user plane separation in a mobile network, according to some embodiments. Specifically, FIG. 2B illustrates an exemplary 4G mobile network environment for ensuring control and user plane separation in a mobile network, including security platforms 202a, 202b, and 202c for ensuring control and user plane separation, as described further below (e.g., the security function / platform can be implemented using a firewall (FW) / next-generation firewall (NGFW), a network sensor acting in place of a firewall, or another (virtual) device / component that can implement security policies using the disclosed techniques). The 4G mobile network environment may also include fixed / wired access (not shown in FIG. 2B), non-3GPP access such as Wi-Fi access (not shown in FIG. 2B), 4G Radio Access Network (RAN) access as shown at 204, and / or other networks (not shown in FIG. 2B) that facilitate data communications for subscribers (e.g., using user equipment (UE) such as smartphones, laptops, computers (which may be at a fixed location), and / or other cellular-enabled computing devices / appliances such as CIoT devices, or other network communication-enabled devices), including via a central data network (e.g., the Internet) 220 for accessing various applications, web services, content hosts, etc., and / or other networks.
[0048] As shown in FIG. 2B, the 4G network access mechanism 204 is in communication with a combined user plane network element including a serving gateway (SGW) and a packet gateway (PGW) for user plane traffic shown as SGW-U+PGW-U 206, which passes through security platform 202a to communicate with SGW-U+PGW-U 206.
[0049] 2B , the 4G network access mechanism 204 communicates with the core network 210 (e.g., via an Sxa / Sxb interface), passing through the security platform 202a to access the core network 210. The core network 210 includes combined control plane network elements, including a serving gateway (SGW) and a packet data network (PDN) gateway (PGW) for control plane traffic, denoted as SGW-C+PGW-C 214. The core network 210 also includes a PGW-U 216 for user plane traffic to facilitate access to the central data network 220, which passes through security platform 202b to access the central data network via the PGW-U 216 and a Traffic Detection Function (TDF) for user plane traffic, denoted as TDF-U 224. Specifically, an Sxa interface provides an interface between the SGW-C 214 and the SGW-U 206 via PFCP over UDP, and an Sxb interface provides an interface between the PGW-C 214 and the PGW-U 216 via PFCP over UDP. The core network 210 also includes a Traffic Detection Function (TDF) for control plane traffic, denoted as TDF-C 226, and network traffic across the Sxc interface between the TDF-C 226 and the TDF-U 224 passes through security platform 202c.
[0050] Also as shown, security platform 202a (e.g., and other security platforms may communicate with security cloud services as well) may communicate with security service 222 (e.g., WildFire, a commercially available cloud security service offered by Palo Alto Networks, Inc.) for dynamic prevention signatures for malware, DNS, URL, command and control (C&C), and / or various other security updates, and / or cloud-based malware sample analysis. TM Commercially available cloud-based security services, such as a (WF) cloud-based malware analysis environment, may involve automated security analysis of malware samples as well as analysis by security experts, or may utilize similar solutions offered by other vendors.
[0051] 2B, as described above with respect to FIG. 2A and as further described below, security platforms 202a, 202b, and 202c (which may be located in various locations to monitor Sxa, Sxb, Sxc, and / or other communications) can be used to monitor network traffic communications. In this implementation, security platforms 202a, 202b, and 202c are located in this exemplary 4G mobile network environment and use the Sxa interface between Serving Gateway-C, indicated at 214, and Serving Gateway-U, indicated at 206, the Sxb interface between PDN Gateway-C, indicated at 214, and PDN Gateway-U, indicated at 206, and the Sxc interface between TDF-C, indicated at 226, and TDF-U, indicated at 224, to monitor and analyze PFCP messages (e.g., PFCP over UDP) to extract certain information used to set up a PFCF session and track control message flow, as further described below.
[0052] 2C is another block diagram of a 4G wireless network architecture including a security platform for ensuring control and user plane separation in a mobile network, according to some embodiments. Specifically, FIG. 2C illustrates an exemplary 4G mobile network environment for ensuring control and user plane separation in a mobile network, including a security platform 202 for ensuring control and user plane separation (e.g., the security function / platform can be implemented using a firewall (FW) / next-generation firewall (NGFW), a network sensor acting in place of a firewall, or another (virtual) device / component that can implement security policies using the disclosed techniques), as described further below. The 4G mobile network environment may also include fixed / wired access (not shown in FIG. 2C), non-3GPP access such as Wi-Fi access (not shown in FIG. 2C), 4G Radio Access Network (RAN) access as shown at 204, and / or other networks (not shown in FIG. 2C) that facilitate data communications for subscribers (e.g., using user equipment (UE) such as smartphones, laptops, computers (which may be at fixed locations), and / or other cellular-enabled computing devices / appliances such as CIoT devices, and / or other network communication-enabled devices) to access various applications, web services, content hosts, etc., and / or other networks.
[0053] As shown in FIG. 2C , the 4G network access mechanism 204 is in communication with a combined user plane network element including a serving gateway (SGW) and a packet gateway (PGW) for user plane traffic, shown as SGW-U+PGW-U 206, which passes through the security platform 202 to communicate with the SGW-U+PGW-U 206.
[0054] 2C , the 4G network access mechanism 204 communicates with the core network 210 (e.g., via an Sxa / Sxb interface) passing through the security platform 202 to access the core network 210. The core network 210 includes a combined control plane network element including a serving gateway (SGW) for control plane traffic and a packet data network (PDN) gateway (PGW), shown as SGW-C+PGW-C 214. Specifically, the Sxa interface provides an interface between the SGW-C 214 and the SGW-U 206 via PFCP over UDP, and the Sxb interface provides an interface between the PGW-C 214 and the PGW-U 206 via PFCP over UDP.
[0055] As also shown, the illustrated 202 may provide security services 222 (e.g., WildFire, a commercially available cloud security service offered by Palo Alto Networks) for dynamic preventative signatures for malware, DNS, URL, command and control (C&C), and / or various other security updates, and / or cloud-based malware sample analysis. TM Commercially available cloud-based security services, such as a (WF) cloud-based malware analysis environment, may involve automated security analysis of malware samples as well as analysis by security experts, or may utilize similar solutions offered by other vendors.
[0056] 2C, network traffic communications can be monitored using security platform 202 (which can be located in various locations to monitor Sxa, Sxb, and / or other communications) in a manner similar to that described above with respect to FIGURES 2A-2B and as further described below. In this implementation, security platform 202 is located in this exemplary 4G mobile network environment and monitors and analyzes PFCP messages (e.g., PFCP over UDP) on the Sxa interface between serving gateway-C, indicated at 214, and serving gateway-U, indicated at 206, and the Sxb interface between PDN gateway-C, indicated at 214, and PDN gateway yU, indicated at 206, to extract predetermined information used to set up a PFCF session and track control message flow, as further described below.
[0057] 2D is another block diagram of a 4G wireless network architecture including security platforms for ensuring control and user plane separation in a mobile network, according to some embodiments. Specifically, FIG. 2D illustrates an exemplary 4G mobile network environment for ensuring control and user plane separation in a mobile network, including security platforms 202a and 202b for ensuring control and user plane separation (e.g., the security function / platform can be implemented using a firewall (FW) / next-generation firewall (NGFW), a network sensor acting in place of a firewall, or another (virtual) device / component that can implement security policies using the disclosed techniques), as described further below. The 4G mobile network environment may also include fixed / wired access (not shown in FIG. 2D), non-3GPP access such as Wi-Fi access (not shown in FIG. 2D), 4G Radio Access Network (RAN) access as shown at 204, and / or other networks (not shown in FIG. 2D) that facilitate data communications for subscribers (e.g., using user equipment (UE) such as smartphones, laptops, computers (which may be at fixed locations), and / or other cellular-enabled computing devices / appliances such as CIoT devices, and / or other network communication-enabled devices) to access various applications, web services, content hosts, etc., and / or other networks.
[0058] 2D, the 4G network access mechanism 204 is in communication with user plane network elements including a serving gateway (SGW) for user plane traffic, denoted as SGW-U 208, and a packet gateway (PGW), denoted as PGW-U 206. The security platform 202b is disposed between the PGW-U 206 and a traffic detection function for user plane traffic, denoted as TDF-U 224, which passes through the security platform 202b and communicates with the TDF-U 224.
[0059] 2D , the 4G network access mechanism 204 communicates with the core network 210 (e.g., via an Sxa / Sxb interface), which passes through the security platform 202a to access the core network 210 for control plane traffic. The core network 210 includes control plane network elements including a serving gateway (SGW) for control plane traffic and a packet data network (PDN) gateway (PGW), denoted as the SGW-C 218 and the PGW-C 216, respectively. The core network 210 also includes a traffic detection function for control plane traffic, denoted as the TDF-C 234, which passes through the security platform 202b, as shown. Specifically, the Sxa interface provides an interface between the PGW-C 216 and the PGW-U 206 via PFCP over UDP, and the Sxb interface provides an interface between the SGW-C 218 and the SGW-U 208 via PFCP over UDP. Similarly, the Sxc interface provides an interface between the TDF-C 234 and the TDF-U 224 via PFCP over UDP.
[0060] Also as shown, security platform 202a (e.g., and other security platforms may communicate with security cloud services as well) may communicate with security services 222 (e.g., WildFire, a commercially available cloud security service offered by Palo Alto Networks, Inc.) for dynamic prevention signatures of malware, DNS, URL, command and control (C&C), and / or various other security updates, and / or cloud-based malware sample analysis. TM It also communicates with commercially available cloud-based security services, such as a (WF) cloud-based malware analysis environment, which may include automated security analysis of malware samples as well as analysis by security experts, or may utilize similar solutions offered by other vendors.
[0061] 2D, network traffic communications can be monitored using security platforms 202a and 202b (e.g., which can be located in various locations to monitor Sxa, Sxb, Sxc, and / or other communications) as described above with respect to Figures 2A-2C and as further described below. In this implementation, security platforms 202a and 202b are located in this exemplary 4G mobile network environment and use the Sxa interface between PDN Gateway-C, indicated at 216, and PDN Gateway-U, indicated at 206, the Sxb interface between Serving Gateway-C, indicated at 218, and Serving Gateway-U, indicated at 208, and the Sxc interface between TDF-C, indicated at 234, and TDF-U, indicated at 224, to monitor and analyze PFCP messages (e.g., PFCP over UDP) to extract certain information used to set up a PFCF session and track control message flow as further described below.
[0062] As will become apparent, to promote security of the separation of control and user planes in mobile networks, network traffic communications can be monitored / filtered using one or more security platforms for network traffic communications at various locations within a 4G network and / or a 5G network (e.g., a 5G network or a converged 5G network).
[0063] An exemplary security mechanism based on monitoring PFCP traffic to ensure security of control and user plane separation in mobile networks
[0064] Similar to what was described above, PFCP is used at the interface between control plane and user plane functions as specified in 3GPP Technical Specification (TS) 29.244 v15.7 for LTE; 5G; Interface Between Control Plane and User Plane Nodes (e.g., and later releases / versions).
[0065] Figure 3A is a protocol sequence diagram for the PFCP session establishment procedure. Referring to Figure 3A, the SMF 304 receives a trigger to establish a new PDU session or change the UPF of an established PDU session. At 310, the SMF 304 sends an N4 Session Establishment Request message to the UPF 302. At 320, the UPF 302 responds with an N4 Session Establishment Response message. The SMF 304 interacts with the network function that triggered this procedure (e.g., a 5G Core Access and Mobility Management Function (AMF) or a Policy Control Function (PCF)).
[0066] Figure 3B is a protocol sequence diagram for the PFCP session modification procedure. Referring to Figure 3B, the SMF 304 receives a trigger to modify an existing PDU session. At 330, the SMF 304 sends an N4 Session Modify Request message to the UPF 302. At 340, the UPF 302 responds with an N4 Session Modify Response message. The SMF 304 interacts with the network function (e.g., AMF or PCF) that triggered this procedure.
[0067] Figure 3C is a protocol sequence diagram for the PFCP session release procedure. Referring to Figure 3C, the SMF 304 receives a trigger to delete the N4 session context of a PDU session. At 350, the SMF 304 sends an N4 Session Release Request message to the UPF 302. The UPF 302 identifies the N4 session context to be deleted by the N4 session ID and deletes the entire session context. At 360, the UPF 302 responds with an N4 Session Release Response message (e.g., including any information the UPF needs to provide to the SMF). The SMF 304 interacts with the network function (e.g., AMF or PCF) that triggered this procedure.
[0068] In one implementation example, PFCF stateful inspection can be performed as follows based on a security platform deployment topology of a multi-access distributed edge 4G / 5G network or an enterprise private LTE network (e.g., the security platform deployments also shown in Figures 1 and 2A-2D).
[0069] First, using a security platform to monitor PFCP traffic, the security platform automatically builds a session based on a 5-tuple + node ID (optional) associated with the PFCP association (e.g., the 5-tuple may include the following parameters: source IP address, SEID 1; destination IP address, SEID 2; and the protocol in use, PFCP in this example), as further described below.
[0070] Second, the security platform is configured with a security policy to only allow PFCP session-related messages from control plane (CP) or user plane (UP) functions that match "active" sessions corresponding to existing PFCP associations.
[0071] Third, using a security platform to monitor PFCP traffic, the security platform can automatically build a PFCP session state machine to track the following states: create, update, and release states of a PFCP session based on a 5-tuple (e.g., the 5-tuple can include the following parameters: source IP address, SEID 1; destination IP address, SEID 2; and the protocol in use, PFCP in this example), as further described below with respect to Figures 3A-3C.
[0072] Fourth, the security platform is configured with a security policy to perform sequence number checking. For example, the security platform can check the sequence numbers in the PFCP request and response messages. In this example, the security platform is configured with a security policy to only allow PFCP response messages that have a sequence number that matches the PCFP request message (e.g., as specified in Section 6.4 of 3GPP TS 29.244 v15.7.0, a PCFP request and its response message have the same sequence number value).
[0073] The security platform may be configured to implement additional security mechanisms based on monitoring PFCP traffic. Various examples of such additional security mechanisms based on monitoring PFCP traffic are now described.
[0074] For example, a security platform can be configured with a security policy to perform user plane IP resource information checks. Specifically, additional security can be applied at the CUPS interface by checking the 'user plane IP resource information' exchanged between the user plane (UP) and control plane (CP) functions. During the PFCP association setup procedure, the 'PFCP Association Setup Request' message can optionally include a 'user plane IP resource information' information element (IE) containing IPv4 and / or IPv6 addresses and a TEID range that the CP function uses to assign GTP-U F-TEIDs to the UP function during PFCP association setup. In this example, the security platform can be configured with a security policy to store this information and only allow the setup of GTP-U tunnels that match the valid range of GTP-U F-TEIDs with the correct IPv4 and / or IPv6 addresses exchanged earlier during PFCP association setup.
[0075] As another example, the security platform may be configured with a security policy to perform overload protection—rate limiting of PFCP messages. Specifically, as described above with respect to Figures 3A-3C, the security platform may be configured with a security policy to monitor PFCP association setup requests, PFCP session establishment requests, and PFCP session deletion requests. This may be applied by the security platform to protect resources of various network functions in the 4G / 5G network, such as the UPF, the PGW-U, and / or other network functions in the 4G / 5G network.
[0076] Exemplary Security Enhancement Use Cases for Ensuring Control and User Plane Separation in Mobile Networks
[0077] The disclosed techniques for providing enhanced security for 4G / 5G mobile / service provider networks using a security platform for security policy enforcement can be applied to various additional example use case scenarios to facilitate enhanced security for 4G / 5G mobile / service provider network environments, including those for ensuring separation of control and user planes in mobile networks.
[0078] In one exemplary use case scenario, the PFCP protocol runs over UDP and inherently lacks a secure design, thus leaving mobile networks vulnerable to attacks such as denial of service (DoS) and / or spoofing attacks.
[0079] One exemplary attack can target one or more network functions, including a UPF and / or SMF network function, receiving a PFCP message for Session Endpoint Identifier (SEID) brute forcing (e.g., a 0 or false SEID).
[0080] Another example potential attack may target network functions, including UPF and / or SMF network functions, receiving spoofed PFCP messages with fake PFCP session modification requests and / or PFCP session deletion requests.
[0081] Yet another example potential attack can target PFCP node discovery, where an attacker with access to the Sxa / Sxb / N4 interface (e.g., other interfaces) can send valid PFCP messages to a network function (NF) and receive response messages with useful information about the NF (e.g., such information can be used by the attacker to launch attacks on 4G / 5G mobile networks).
[0082] The disclosed examples of potential attacks can be detected and / or prevented using the disclosed techniques, as described below.
[0083] DoS attacks against the UPF and / or SMF using brute force 0 or false SEIDs can be detected and prevented using PFCP stateful inspection performed by the security platform, similar to the above. DoS attacks and / or spoofing attacks against the UPF and / or SMF can also be detected and prevented by setting appropriate thresholds for rate limiting PFCP messages in the security policy applied by the security platform, similar to the above.
[0084] Spoofing and / or session / association hijacking attacks against the UPF and / or SMF using false PFCP session modification and / or PFCP session deletion requests can be detected and prevented using PFCP stateful inspection. Specifically, because the security platform maintains the state of PFCP associations, only valid PFCP association messages that match existing PFCP associations in the firewall tables can be allowed based on the security policy applied by the security platform, as described above. Similarly, because the security platform maintains the state of PFCP sessions, only valid PFCP session messages that match existing PFCP sessions in the firewall tables can be allowed based on the security policy applied by the security platform, as described above.
[0085] Finally, reconnaissance attacks that use PFCP messages to gather network capability information can be detected and prevented using both PFCP stateful inspection and PFCP message rate limiting, based on the security policies applied by the security platform, similar to those described above.
[0086] As will now be apparent to those skilled in the art, the disclosed techniques for providing enhanced security for 4G / 5G mobile / service provider networks using a security platform for security policy enforcement can be applied in a variety of additional use case scenarios, including those for ensuring separation of control and user planes in mobile networks, to detect / prevent these and other types of attacks to promote enhanced security in 4G / 5G mobile / service provider network environments.
[0087] Exemplary Hardware Components of a Network Device for Ensuring Control and User Plane Separation in a Mobile Network
[0088] 4 is a functional diagram of hardware components of a network device for ensuring control and user plane separation in a mobile network, according to some embodiments. The example shown is a representation of physical / hardware components that may be included in network device 400 (e.g., an appliance, gateway, or server that may implement the security platform disclosed herein). Specifically, network device 400 includes a high-performance multi-core CPU 402 and RAM 404. Network device 400 also includes storage 410 (e.g., one or more hard disks or solid-state storage units), which may be used to store policies and other configuration information, as well as signatures. In one embodiment, storage 410 stores predetermined information (e.g., a 5-tuple + node ID (optional) associated with a PFCP association, PFCP session state information for tracking the state of PFCP session creation, update, and release based on the 5-tuple + SEID, sequence numbers in PFCP request and response messages, etc.) extracted from PFCP traffic across various interfaces monitored to implement the disclosed security policy enforcement techniques for ensuring control and user plane separation in mobile networks using a security platform, similar to that described above with respect to FIGS. 1-3C. Network device 400 may also optionally include one or more hardware accelerators. For example, network device 400 may include a cryptographic engine 406 configured to perform encryption and decryption operations and one or more FPGAs 408 configured to perform signature verification, function as network processors, and / or perform other tasks.
[0089] Exemplary Logical Components of a Network Device for Ensuring Control and User Plane Separation in a Mobile Network
[0090] 5 is a functional diagram of logical components of a network device for ensuring control and user plane separation in mobile networks, according to some embodiments. The illustrated example is a representation of logical components that may be included in a network device 500 (e.g., a data appliance that implements the disclosed security functions / platform and can perform the disclosed techniques for ensuring control and user plane separation in mobile networks). As shown, network device 500 includes a management plane 502 and a data plane 504. In one embodiment, the management plane is responsible for managing user interactions, such as by providing a user interface for setting policies and displaying log data. The data plane is responsible for managing data, such as by performing packet processing and session handling.
[0091] Assume that a mobile device attempts to access a resource (e.g., a remote website / server, an MEC service, an IoT device such as a CIoT device, or other resource) using an encrypted session protocol such as SSL. The network processor 506 is configured to monitor packets from the mobile device and provide the packets to the data plane 504 for processing. Flow 508 identifies the packet as part of a new session and creates a new session flow. Subsequent packets are identified as belonging to the session based on the flow lookup. If applicable, SSL decryption is applied by the SSL decryption engine 510 using various techniques described herein. Otherwise, processing by the SSL decryption engine 510 is omitted. The application identification (APP ID) module 512 is configured to determine the type of traffic involved in the session (e.g., PFCP over UDP traffic between various monitored interfaces, as described above with respect to Figures 1-3C) and identify the user associated with the traffic flow (e.g., identify an application ID as described herein). For example, APP ID 512 can recognize a GET request in the received data and determine that the session requires an HTTP decoder 514. As another example, APP ID 512 can recognize a PFCP session establishment / modification / release message (e.g., an N4 session establishment request / response message, similar to those described above with respect to FIGS. 3A-3C) and determine that the session requires a PFCP decoder (e.g., extracting information exchanged in an N4 session establishment related message, including various parameters, similar to those described above with respect to FIGS. 1-3C). There is a corresponding decoder 514 for each type of protocol. In one embodiment, application identification is performed by an application identification module (e.g., an APP ID component / engine), and user identification is performed by a separate component / engine.Based on the determination made by APP ID 512, the packet is sent to the appropriate decoder 514. Decoder 514 is configured to assemble packets (e.g., which may be received out of order) into the correct order, perform tokenization, and extract information (e.g., to extract various information exchanged in N4 session establishment-related messages and / or PFCP messages across the N4 / Sxa / Sxb / Sxc / other interfaces, as described above and further below). Decoder 514 also performs signature matching to determine what happens to the packet. SSL encryption engine 516 performs SSL encryption using various techniques, as described herein, and the packet is then forwarded using forwarding component 518, as shown. Also, as shown, policy 520 is received and stored in management plane 502. In one embodiment, based on the monitored, decrypted, identified, and decoded session traffic flows, policy enforcement is applied as described herein with respect to various embodiments (e.g., a policy may include one or more rules, which may be specified using domain names and / or hostnames / server names, and the rules may apply one or more signatures or other matching criteria or heuristics, such as applying a security policy to subscriber / IP flows in a service provider network based on monitored HTTP / 2 messages and / or DPI of monitored PFCP and / or other protocol traffic, as disclosed herein).
[0092] 5, an interface (I / F) communicator 522 for security platform manager communication is also provided (e.g., via (REST) APIs, messages, or network protocol communications, or other communication mechanisms). In some cases, network communications of other network elements on the service provider network are monitored using the network device 500, and the data plane 504 supports decoding of such communications (e.g., the network device 500, including the I / F communicator 522 and decoder 514, can be configured to monitor and / or communicate at reference point interfaces, such as N4, Sxa, Sxb, Sxc, and / or other interfaces where wired and wireless network traffic flows exist). Thus, the network device 500, including the I / F communicator 522, can be used to implement the disclosed techniques for enforcing security policies in a mobile / service provider network environment, including MEC service security, as previously described and further described below.
[0093] Additional example processes of the disclosed techniques for ensuring control and user plane separation in mobile networks will now be described.
[0094] Exemplary Process for Ensuring Control and User Plane Separation in Mobile Networks
[0095] Figure 6 is a flow chart of a process for ensuring control and user plane separation in a mobile network, according to some embodiments. In some embodiments, process 600 as shown in Figure 6 is performed by a security platform and techniques similar to those described above, including the embodiments described above with respect to Figures 1-5. In one embodiment, process 600 is performed by a data appliance 400 as described above with respect to Figure 4, a network device 500 as described above with respect to Figure 5, a virtual appliance, an SDN security solution, a cloud security service, and / or a combination or hybrid implementation of the foregoing as described herein.
[0096] The process begins at 602, where monitoring of network traffic in a mobile network is performed at a security platform to identify Packet Forwarding Control Protocol (PFCP) messages associated with a new session, where the mobile network includes a 4G network or a 5G network. For example, the security platform (e.g., a firewall, a network sensor operating in place of a firewall, or another device / component capable of implementing a security policy) may monitor various protocols, such as PFCP traffic and / or other protocols, on the mobile network, and more specifically, may monitor various interfaces, such as the N4, Sxa, Sxb, and Sxc interfaces, as described above, by performing the disclosed techniques.
[0097] At 604, the security platform extracts a plurality of parameters from the PFCP message. For example, the security platform may parse the PFCP message to extract the source IP address, SEID 1, the destination IP address, SEID 2, and the protocol in use associated with the PFCP association, as described above. As another example, the security platform may parse the PFCP message to extract the node ID associated with the PFCP association, as described above.
[0098] At 606, a security policy is enforced at the security platform for the new session based on one or more of the plurality of parameters to ensure separation of the control and user planes in the mobile network. For example, to ensure separation of the control and user planes in 4G / 5G networks, detection and prevention of denial of service (DoS) attacks can be performed by the security platform in a similar manner as described above. As another example, to ensure separation of the control and user planes in 4G / 5G networks, detection and prevention of session endpoint identifier (SEID) spoofing attacks can be performed by the security platform in a similar manner as described above.
[0099] Figure 7 is another flow diagram of a process for ensuring control and user plane separation in a mobile network, according to some embodiments. In some embodiments, process 700 as shown in Figure 7 is performed by a security platform and techniques similar to those described above, including the embodiments described above with respect to Figures 1-5. In one embodiment, process 700 is performed by a data appliance 400 described above with respect to Figure 4, a network device 500 described above with respect to Figure 5, a virtual appliance, an SDN security solution, a cloud security service, and / or a combination or hybrid implementation of the foregoing described herein.
[0100] At 702, monitoring of network traffic in a mobile network at a security platform is performed to identify Packet Forwarding Control Protocol (PFCP) messages associated with the new session, where the mobile network includes a 4G network or a 5G network. For example, the security platform (e.g., a firewall, a network sensor operating in place of a firewall, or another device / component capable of implementing a security policy) may monitor various protocols, such as PFCP traffic and / or other protocols, on the mobile network, and more specifically, may monitor various interfaces, such as the N4, Sxa, Sxb, and Sxc interfaces, as described above, by performing the disclosed techniques.
[0101] At 704, extracting parameters from the monitored PCFP traffic is performed and building a session based on the 5-tuple + node ID (optional) associated with the PFCP association at the security platform (e.g., a 5-tuple can include the following parameters: source IP address, SEID 1, destination IP address, SEID 2, and the protocol in use, which in this example is PFCP), similar to what was described above, etc.
[0102] At 706, extracting parameters from the monitored PFCP traffic is performed to build a PFCP session state machine in the security platform. For example, the security platform may track the following states: creation, update, and release of PFCP sessions based on the 5-tuple + SEID, as previously described, etc.
[0103] At 708, enforcement of security policies is performed in the security platform to allow only PFCP session related messages from control plane (CP) or user plane (UP) functions that match "active" sessions corresponding to existing PFCP associations, as previously described, etc.
[0104] At 710, enforcing a security policy in a security platform is performed to perform a sequence number check. For example, the security platform may check the sequence numbers of the PFCP request and response messages. In this example, the security platform is configured with a security policy that only allows a PFCP response message with a sequence number that matches a PCFP request message (e.g., a PCFP request and its response message have the same sequence number value, as specified in section 6.4 of 3GPP TS 29.244 v 15.7.0). As previously described, and so on.
[0105] In view of the disclosed embodiments, it should now be apparent that network service providers / mobile operators (e.g., cellular service provider entities), device manufacturers (e.g., automotive entities, IoT device entities, and / or other device manufacturers), and / or system integrators can specify such security policies, which can be enforced by a security platform using the disclosed technology, to solve these and other technical network security challenges for ensuring control and user plane separation in mobile networks, including 4G and 5G networks.
[0106] Although the above embodiments have been described in some detail for clarity of understanding, the present invention is not limited to the details provided. There are many alternative ways of implementing the present invention. The disclosed embodiments are illustrative and not limiting.
Claims
1. 1. A system including a processor and a memory, The processor: monitoring network traffic in a mobile network with a security platform to identify a Packet Forwarding Control Protocol (PFCP) message associated with a new session, the mobile network including a 4G network or a 5G network; extracting, at the security platform, a plurality of parameters from the PFCP message; Enforcing a security policy in the security platform on the new session based on one or more of the plurality of parameters to ensure separation of control and user planes in the mobile network; Obtaining a user plane IP address and a tunnel endpoint identifier (TEID) from the network traffic; and Allowing the setup of GTP-U tunnels whose TEID ranges and IP addresses match; It is structured as follows: the memory is coupled to the processor and configured to provide instructions to the processor; system.
2. permitting the GTP-U tunnel comparing the IP address with a valid range for the TEID; The system of claim 1 , comprising:
3. Enforcing the security policy includes: determining whether the rate of PFCP messages is greater than or equal to a message rate threshold; and limiting the rate of the PFCP messages in response to determining that the rate of the PFCP messages is greater than or equal to the message rate threshold; The system of claim 1 , comprising:
4. In the security platform, the plurality of parameters extracted from the PFCP message further include a source IP address, a session endpoint identifier (SEID) 1, a destination IP address, a SEID 2, and a protocol in use; The system of claim 1 , comprising:
5. The security platform includes: configured with a plurality of security policies to ensure separation of control and user planes in the mobile network; The system of claim 1 .
6. The processor further comprises: and parsing the PFCP message to extract a source IP address, a session endpoint identifier (SEID) 1, a destination IP address, a SEID 2, and a protocol in use associated with the PFCP association. The system of claim 1 .
7. The processor further comprises: and parsing the PFCP message to extract a node ID associated with the PFCP association. The system of claim 6.
8. The security platform monitors network traffic to and / or within a core network of a 5G network to ensure separation of control and user planes in the mobile network. The system of claim 1 .
9. The security platform includes: configured to perform denial of service (DoS) attack detection and prevention to ensure separation of control and user planes in the mobile network; The system of claim 1 .
10. The security platform is configured to perform detection and prevention of session endpoint identifier (SEID) spoofing attacks to ensure separation of control and user planes in the mobile network. The system of claim 1 .
11. The processor further comprises: and blocking new sessions from accessing resources based on the security policy. The system of claim 1 .
12. The processor further comprises: and allowing the new session to access the resource based on the security policy. The system of claim 1 .
13. monitoring network traffic in a mobile network at a security platform to identify a Packet Forwarding Control Protocol (PFCP) message associated with a new session, the mobile network comprising a 4G network or a 5G network; extracting, at the security platform, a plurality of parameters from the PFCP message; enforcing a security policy at the security platform on the new session based on one or more of the plurality of parameters, ensuring separation of control and user planes in the mobile network; obtaining a user plane IP address and a tunnel endpoint identifier (TEID) from the network traffic; and allowing the setup of a GTP-U tunnel whose TEID range and IP address match; and A method comprising:
14. permitting the GTP-U tunnel comparing the IP address with a valid range for the TEID; 14. The method of claim 13, comprising:
15. The step of enforcing the security policy includes: determining whether the rate of PFCP messages is greater than or equal to a message rate threshold; and limiting the rate of the PFCP messages in response to determining that the rate of the PFCP messages is greater than or equal to the message rate threshold; 14. The method of claim 13, comprising:
16. In the security platform, the plurality of parameters extracted from the PFCP message further include a source IP address, a session endpoint identifier (SEID) 1, a destination IP address, a SEID 2, and a protocol in use; 14. The method of claim 13, comprising:
17. The security platform includes: configured with a plurality of security policies to ensure separation of control and user planes in the mobile network; The method of claim 13.
18. The method further comprises: parsing the PFCP message to extract a source IP address, a session endpoint identifier (SEID) 1, a destination IP address, SEID 2, and the protocol in use associated with the PFCP association; 14. The method of claim 13, comprising:
19. The method further comprises: parsing the PFCP message to extract a node ID associated with the PFCP association; 20. The method of claim 18, comprising:
20. 1. A system including a processor and a memory, The processor: monitoring network traffic in a mobile network with a security platform to identify a Packet Forwarding Control Protocol (PFCP) message associated with a new session, the mobile network including a 4G network or a 5G network; extracting, at the security platform, a plurality of parameters from the PFCP message; Enforcing a security policy in the security platform on the new session based on one or more of the plurality of parameters to ensure separation of control and user planes in the mobile network; Determine a number of PFCP messages to be monitored over a period of time; and If the number of PFCP messages monitored over a period of time exceeds a rate-limiting threshold, preventing additional PFCP messages from passing through the security platform; It is structured as follows: the memory is coupled to the processor and configured to provide instructions to the processor; system.
21. In the security platform, the plurality of parameters extracted from the PFCP message further include a source IP address, a session endpoint identifier (SEID) 1, a destination IP address, a SEID 2, and a protocol in use; 21. The system of claim 20, comprising:
22. The security platform includes: configured with a plurality of security policies to ensure separation of control and user planes in the mobile network; 21. The system of claim 20.
23. The processor further comprises: and parsing the PFCP message to extract a source IP address, a session endpoint identifier (SEID) 1, a destination IP address, a SEID 2, and a protocol in use associated with the PFCP association.
21. The system of claim 20.
24. The processor further comprises: and parsing the PFCP message to extract a node ID associated with the PFCP association.
24. The system of claim 23.
25. The security platform monitors network traffic to and / or within a core network of a 5G network to ensure separation of control and user planes in the mobile network.
21. The system of claim 20.
26. The security platform includes: configured to perform denial of service (DoS) attack detection and prevention to ensure separation of control and user planes in the mobile network; 21. The system of claim 20.
27. The security platform is configured to perform detection and prevention of session endpoint identifier (SEID) spoofing attacks to ensure separation of control and user planes in the mobile network.
21. The system of claim 20.
28. The processor further comprises: and blocking new sessions from accessing resources based on the security policy.
21. The system of claim 20.
29. The processor further comprises: and allowing the new session to access the resource based on the security policy.
21. The system of claim 20.
30. monitoring network traffic in a mobile network at a security platform to identify a Packet Forwarding Control Protocol (PFCP) message associated with a new session, the mobile network comprising a 4G network or a 5G network; extracting, at the security platform, a plurality of parameters from the PFCP message; enforcing a security policy at the security platform on the new session based on one or more of the plurality of parameters, ensuring separation of control and user planes in the mobile network; determining a number of PFCP messages to be monitored over a period of time; and preventing additional PFCP messages from passing through the security platform if the number of PFCP messages monitored over a period of time exceeds a rate-limiting threshold; and A method comprising:
31. In the security platform, the plurality of parameters extracted from the PFCP message further include a source IP address, a session endpoint identifier (SEID) 1, a destination IP address, a SEID 2, and a protocol in use; 31. The method of claim 30, comprising:
32. The security platform includes: configured with a plurality of security policies to ensure separation of control and user planes in the mobile network; 31. The method of claim 30.
33. The method further comprises: parsing the PFCP message to extract a source IP address, a session endpoint identifier (SEID) 1, a destination IP address, SEID 2, and the protocol in use associated with the PFCP association; 31. The method of claim 30, comprising:
34. The method further comprises: parsing the PFCP message to extract a node ID associated with the PFCP association; 34. The method of claim 33, comprising:
35. The security platform monitors network traffic to and / or within a core network of a 5G network to ensure separation of control and user planes in the mobile network.
31. The method of claim 30.
36. The security platform includes: configured to perform denial of service (DoS) attack detection and prevention to ensure separation of control and user planes in the mobile network; 31. The method of claim 30.
37. The security platform is configured to perform detection and prevention of session endpoint identifier (SEID) spoofing attacks to ensure separation of control and user planes in the mobile network.
31. The method of claim 30.
38. The method further comprises: allowing or preventing new sessions from accessing resources based on the security policy; 31. The method of claim 30, comprising: