Context-based security across interfaces in NG-RAN and O-RAN mobile networks

A security platform inspects and applies context-based security policies to XnAP, GTP-U, F1AP, and F1-U traffic in NG-RAN and O-RAN environments, addressing new security threats and enhancing security in 5G mobile networks.

JP7813945B2Active Publication Date: 2026-02-13PALO ALTO NETWORKS INC
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2025166014
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2022-02-25
Filing Date
2025-10-02
Publication Date
2026-02-13
Estimated Expiration
2043-01-31

AI Technical Summary

Technical Problem

The Next-Generation RAN (NG-RAN) and Open RAN (O-RAN) architectures in 5G mobile networks introduce new security threats through interfaces like Xn-U and F1-U, which are vulnerable to attacks from compromised autonomous vehicles and IoT devices, necessitating improved security techniques for monitoring and applying context-based security policies.

Method used

A security platform is configured to inspect and extract context information from XnAP and GTP-U traffic across Xn-C and Xn-U interfaces in NG-RAN environments, and F1AP and GTP-U traffic across F1-C and F1-U interfaces in O-RAN environments, applying Layer 7 security and correlating this information with user plane traffic to enforce context-based security policies.

Benefits of technology

Enhances security in NG-RAN and O-RAN environments by detecting and preventing threats, performing application identification and control, and filtering URLs, thereby securing node-to-node traffic and user plane communications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007813945000001
    Figure 0007813945000001
  • Figure 0007813945000002
    Figure 0007813945000002
  • Figure 0007813945000003
    Figure 0007813945000003
Patent Text Reader

Abstract

To provide a system, method and program for applying context-based security at an interface in an O-RAN environment in a mobile network.SOLUTION: The method comprises monitoring network traffic in a mobile network at a security platform to identify a GTP-U tunnel session setup message associated with a new session, extracting a plurality of parameters from the GTP-U tunnel session setup message and from F1AP traffic at the security platform, and enforcing a security policy at the security platform for the new session based on one or more of the plurality of parameters to apply context-based security.SELECTED DRAWING: Figure 8
Need to check novelty before this filing date? Find Prior Art

Description

[Background technology]

[0001] A firewall generally allows authorized communications to pass through the firewall while protecting a network from unauthorized access. A firewall is typically a device, a set of devices, or software running on a device that provides firewall functionality for network access. For example, a firewall can be integrated into the operating system of a device (e.g., a computer, a smartphone, or another type of network-enabled device). A firewall can also be integrated into or run as a software application on a computer server, a gateway, a network / routing device (e.g., a network router), or a data appliance (e.g., a security appliance or other type of special-purpose device).

[0002] Firewalls typically deny or allow network transmissions based on a set of rules. These sets of rules are often referred to as policies. For example, a firewall can filter inbound traffic by applying a set of rules or policies. A firewall can also filter outbound traffic by applying a set of rules or policies. A firewall can also perform basic routing functions. Similarly, local network (eg, intranet) traffic can be filtered by applying a set of rules or policies. [Brief explanation of the drawings]

[0003] Various embodiments of the present invention are disclosed in the following detailed description and accompanying drawings. [Figure 1]FIG. 1 is a block diagram of a 5G wireless network architecture having a security platform for applying context-based security across interfaces in an NG-RAN environment in a mobile network, according to some embodiments. [Figure 2A] FIG. 2A is a table of parameters extracted by a security platform from a handover request during setup of a GTP-U tunnel session, according to some embodiments. [Figure 2B] FIG. 2B is a table of parameters extracted by the security platform from a handover request during setup of a GTP-U tunnel session, according to some embodiments. [Figure 2C] FIG. 2C is a handover protocol sequence diagram for an NG-RAN environment in a mobile network. [Figure 3] FIG. 3 is a block diagram of a 5G wireless network architecture having a security platform for applying context-based security across interfaces in an O-RAN environment in a mobile network, according to some embodiments. [Figure 4A] FIG. 4A is a table of parameters extracted by the security platform from a handover request during setup of a GTP-U tunnel session, according to some embodiments. [Figure 4B] FIG. 4B is a table of parameters extracted by the security platform from a handover request during setup of a GTP-U tunnel session, according to some embodiments. [Figure 4C] FIG. 4C is a handover protocol sequence diagram for an O-RAN environment in a mobile network. [Figure 5]FIG. 5 is a functional diagram of hardware components of a network device for applying context-based security across interfaces in an NG-RAN and / or O-RAN environment in a mobile network, according to some embodiments. [Figure 6] FIG. 6 is a functional diagram of logical components of a network device for applying context-based security across interfaces in an NG-RAN and / or O-RAN environment in a mobile network, according to some embodiments. [Figure 7] FIG. 7 is a flow diagram of a process for applying context-based security across interfaces in an NG-RAN environment in a mobile network, according to some embodiments. [Figure 8] FIG. 8 is a flow diagram of a process for applying context-based security across interfaces in an O-RAN environment in a mobile network, according to some embodiments. DETAILED DESCRIPTION OF THE INVENTION

[0004] The present invention can be implemented in numerous ways, including as a process, an apparatus, a system, a composition of matter, a computer program product embodied on a computer-readable storage medium, and / or a processor, such as instructions stored on a memory and / or a processor configured to execute instructions stored and / or provided by a memory coupled to the processor. These implementations, or any other form the present invention may take, may be referred to herein as techniques. In general, the order of steps in disclosed processes may be varied within the scope of the present invention. Unless otherwise specified, components, such as a processor or memory, described as configured to perform a task may be implemented as general-purpose components temporarily configured to perform the task at a given time, or as specific components manufactured to perform the task. As used herein, the term “processor” refers to one or more devices, circuits, and / or processing cores configured to process data, such as computer program instructions.

[0005] A detailed description of one or more embodiments of the present invention is provided below along with accompanying figures that illustrate the principles of the invention. While the present invention will be described in connection with such embodiments, the present invention is not limited to any embodiment. The scope of the present invention is limited only by the claims, and the present invention encompasses numerous alternatives, modifications, and equivalents. Numerous specific details are set forth in the following description to provide a thorough understanding of the present invention. These details are provided for the purpose of example, and the present invention may be practiced according to the claims without some or all of these specific details. For the purposes of clarity, technical material known in the art related to the present invention has not been described in detail so as not to unnecessarily obscure the present invention.

[0006] A firewall generally allows authorized communications to pass through the firewall while protecting a network from unauthorized access. A firewall is typically a device, a set of devices, or software running on a device that provides firewall functionality for network access. For example, a firewall can be integrated into the operating system of a device (e.g., a computer, a smartphone, or other type of network-enabled device). A firewall can also be integrated into or run as a software application on various types of devices or security devices, such as a computer server, a gateway, a network / routing device (e.g., a network router), or a data appliance (e.g., a security appliance or other type of special-purpose device). do.

[0007] Firewalls typically deny or allow network transmissions based on a set of rules. These sets of rules are often referred to as policies (e.g., network policies or network security policies). For example, a firewall can filter inbound traffic by applying a set of rules or policies to prevent unwanted external traffic from reaching a protected device. A firewall can also filter outbound traffic by applying a set of rules or policies (e.g., allow, block, monitor, notify, or log, and / or other actions that may be specified in a firewall rule or firewall policy, which may be triggered based on various criteria, as described herein). A firewall can also filter local network (e.g., intranet) traffic by similarly applying a set of rules or policies.

[0008] Security devices (e.g., security appliances, security gateways, security services, and / or other security devices) may perform various security operations (e.g., firewalls, anti-malware, intrusion prevention / detection, proxies, and / or other security functions), network functions (e.g., routing, quality of service (QoS), workload balancing of network-related resources, and / or other network functions), and / or other functions. For example, routing may be performed based on source information (e.g., IP addresses and ports), destination information (e.g., IP addresses and ports), and protocol information.

[0009] Basic packet filtering firewalls filter network communication traffic by inspecting individual packets sent over the network (e.g., stateless packet filtering firewalls, or first-generation firewalls). Stateless packet filtering firewalls typically inspect the individual packets themselves and then apply rules based on the inspected packets (e.g., using a combination of the packet's source and destination address information, protocol information, and port numbers).

[0010] Application firewalls can also perform application-layer filtering (e.g., using an application-layer filtering firewall or a second-generation firewall that functions at the application level of the TCP / IP stack). Application-layer filtering firewalls or application firewalls can generally identify certain applications and protocols (e.g., web browsing using the Hypertext Transfer Protocol (HTTP), Domain Name System (DNS) requests, file transfers using the File Transfer Protocol (FTP), and various other types of applications and other protocols, such as Telnet, DHCP, TCP, UDP, and TFTP (GSS)). For example, an application firewall can block unauthorized protocols that attempt to communicate on standard ports (e.g., unauthorized / out-of-policy protocols that attempt to sneak through by using a non-standard port for that protocol can generally be identified using an application firewall).

[0011] Stateful firewalls can also perform stateful-based packet inspection, where each packet is inspected within the context of the set of packets associated with its network outbound packet flow. This firewall technique is commonly referred to as stateful packet inspection because it keeps a record of all connections passing through the firewall and can determine whether a packet is the start of a new connection, part of an existing connection, or an invalid packet. For example, the state of a connection can itself be one of the criteria that triggers a rule in a policy.

[0012] Advanced or next-generation firewalls can perform stateless and stateful packet filtering and application layer filtering, as described above. Next-generation firewalls can also implement additional firewall technologies. For example, certain newer firewalls, often referred to as advanced or next-generation firewalls, can also identify users and content. In particular, certain next-generation firewalls have expanded the list of applications that they can automatically identify to thousands of applications. Examples of such next-generation firewalls are commercially available from Palo Alto Networks (e.g., Palo Alto Networks PA Series Firewalls, Palo Alto Networks VM Series Virtualized Next-Generation Firewalls, and CN Series Containerized Next-Generation Firewalls).

[0013] For example, Palo Alto Networks' next-generation firewalls enable enterprises and service providers to identify and control applications, users, and content—not just ports, IP addresses, and packets—using a variety of identification technologies, including: App-ID for precise application identification; TM(e.g., App ID), User-ID for user identification (e.g., by user or user group) TM( User ID), and Content-ID for real-time content scanning (e.g., controlling web surfing and restricting data and file transfers). TM These identification technologies allow enterprises to secure application usage using business-relevant concepts instead of following the traditional approach offered by traditional port-blocking firewalls. Also, special-purpose hardware for next-generation firewalls, implemented as dedicated appliances, typically offers higher performance levels for application inspection than software running on general-purpose hardware. (For example, security appliances such as those offered by Palo Alto Networks' PA Series Next-Generation Firewalls utilize dedicated, function-specific processing tightly integrated with a single-pass software engine to maximize network throughput while minimizing latency.)

[0014] Overview of techniques for applying context-based security across interfaces in NG-RAN and / or O-RAN environments in mobile networks

[0015] The Next-Generation RAN (NG-RAN) architecture is a newly defined radio access network for 5G mobile networks. However, this new radio access network is vulnerable to new threat vectors. As one example, the NG-RAN architecture in mobile networks opens up new security threats across the Xn-U interface. Autonomous vehicles and industrial Internet of Things (IoT) applications generate significant traffic across Xn interfaces (e.g., including the Xn-C and Xn-U interfaces). As a result, an autonomous vehicle compromised / infected with malware could attack or infect other vehicles across these or other interfaces within a mobile network (e.g., 4G, 5G, 6G, or beyond).

[0016] Additionally, the Open Radio Access Network (O-RAN) is an evolution of the Next-Generation RAN (NG-RAN) architecture. However, this new architecture also opens up new threat vectors. As one example, the new O-RAN architecture in 5G mobile networks opens up new security threats, for example, across the F1-U interface. Autonomous vehicles and industrial Internet of Things (IoT) applications generate significant traffic across F1 interfaces (e.g., including the F1-C and F1-U interfaces). As a result, an autonomous vehicle compromised / infected with malware could attack or infect other vehicles across these or other interfaces within a mobile network (e.g., 4G, 5G, 6G, or later mobile networks).

[0017] Thus, for devices in mobile networks, technical and security challenges exist with service provider networks. Thus, what is needed are new and improved security techniques for devices in such service provider network environments (e.g., mobile networks). Specifically, what is needed are new and improved solutions for monitoring such network traffic and applying context-based security policies (e.g., firewall policies) for devices communicating on service provider networks. Communications include those over various NG-RAN-related interfaces (e.g., Xn interfaces, including Xn-C and Xn-U interfaces) in NG-RAN environments in mobile networks, and various O-RAN-related interfaces (e.g., F1 interfaces, including F1-C and F1-U interfaces) in O-RAN environments in mobile networks.

[0018] In one exemplary implementation, the security platform is configured to inspect XnAP traffic across an Xn-C interface between a source NG-RAN node and a target NG-RAN node to extract context information in an NG-RAN environment in a mobile network. The security platform can also inspect GTP-U traffic across an Xn-U interface between a source NG-RAN node and a target NG-RAN node to apply Layer 7 security to user plane traffic. The security platform can correlate the context information with user plane traffic to provide context-based security features for inter-node traffic in an NG-RAN environment in a mobile network (e.g., 4G, 5G, 6G, or later mobile network).

[0019] In some embodiments, the security platform is configured to provide the following DPI capabilities: stateful inspection of XnAP traffic over the Xn-C interface and stateful inspection of GTP-U traffic over the Xn-U interface, and to apply context-based security in an NG-RAN environment in mobile networks, as described further below.

[0020] In another exemplary implementation, a security platform is configured to inspect F1AP traffic across an F1-C interface between an O-RAN distributed unit (O-DU) and an O-RAN centralized unit control plane (O-CU-CP) to extract context information in an O-RAN environment in a mobile network. The security platform can also inspect GTP-U traffic across an F1-U interface between an O-DU and an O-RAN centralized unit data plane (O-CU-DP) to apply Layer 7 security to user plane (UP) traffic. The security platform can correlate the context information with user plane traffic to deliver context-based security features in an O-RAN environment in a mobile network (e.g., 4G, 5G, 6G, or later mobile network).

[0021] In some embodiments, the security platform is configured to provide the following DPI functions: stateful inspection of F1AP traffic over the F1-C interface between the O-DU and the O-CU-CP, and stateful inspection of GTP-U traffic over the F1-U interface to extract context information and apply context-based security in an O-RAN environment in a mobile network, as described further below.

[0022] Thus, the disclosed techniques facilitate enhanced security for NG-RAN environments in mobile networks and also for O-RAN environments in mobile networks. For example, security functions (e.g., security platforms) may be located closer to users / devices (e.g., UEs) to perform security policy analysis and enforcement. As another example, security functions may be implemented to facilitate security for selective industrial verticals. As yet another example, security may be implemented in highly sensitive locations, such as government network environments, military network environments, and power plant or other key infrastructure network environments.

[0023] In some embodiments, a system / process / computer program product for applying context-based security across an interface in an O-RAN environment in a mobile network includes monitoring network traffic in a mobile network at a security platform, identifying a GTP-U tunnel session setup message associated with a new session; extracting a plurality of parameters from the GTP-U tunnel session setup message and from F1AP traffic, extracting context information at the security platform; and enforcing a security policy at the security platform for the new session based on one or more of the plurality of parameters, applying context-based security to the network traffic transported between an O-RAN distributed unit (O-DU) node and an O-RAN centralized unit control plane (O-CU-CP) node in an O-RAN environment in the mobile network.

[0024] In some embodiments, a system / process / computer program product for applying context-based security across an interface in an O-RAN environment in a mobile network includes a security platform that extracts user plane (UP) transport layer information from a handover request message to set up the GTP-U tunnel session. Further, the security platform can be configured to apply the context-based security to the network traffic transported between the O-DU node and the O-CU-CP node in the O-RAN environment in the mobile network using a plurality of security policies.

[0025] In some embodiments, the system / process / computer program product for applying context-based security across an interface in an O-RAN environment in a mobile network further includes inspecting F1AP traffic across an F1-C interface between the O-DU node and the O-CU-CP node to extract the context information.

[0026] In some embodiments, the system / process / computer program product for applying context-based security across interfaces in an O-RAN environment in a mobile network further includes inspecting F1AP traffic across an F1-C interface between the O-DU node and the O-CU-CP node to extract the context information; and storing the context information locally in the security platform or in cloud-based storage.

[0027] In some embodiments, the system / process / computer program product for applying context-based security across an interface in an O-RAN environment in a mobile network further includes inspecting GTP-U traffic across an F1-U interface between a gNB-DU node and a gNB-CU node to apply Layer 7 security to user plane traffic, and correlating the context information with user plane traffic to perform context-based security on node-to-node traffic in the O-RAN environment.

[0028] In some embodiments, a system / process / computer program product for applying context-based security across an interface in an O-RAN environment in a mobile network includes monitoring network traffic on the mobile network at a security platform to identify a GTP-U tunnel session setup message associated with a new session, and extracting a plurality of parameters from the GTP-U tunnel session setup message and from F1AP traffic to extract context information at the security platform, wherein extracting a plurality of parameters from the GTP-U tunnel session setup message and from F1AP traffic to extract context information at the security platform further includes: extracting user plane (UP) transport layer information from a UE CONTEXT SETUP REQUEST message and a UE CONTEXT SETUP RESPONSE message exchanged between a gNB-DU node and a gNB-CU node during a UE context setup procedure for setting up a GTP-U tunnel session; inspecting F1AP traffic across an F1-C interface between an O-RAN distributed unit (O-DU) node and an O-RAN centralized unit control plane (O-CU-UP) node in an O-RAN environment in a mobile network to extract context information; and inspecting GTP-U traffic across an F1-U interface between an O-DU node and an O-RAN centralized unit user plane (O-CU-UP) node to apply Layer 7 security to the user plane (UP) traffic.And in the mobile network, implementing a security policy in the security platform for the new session based on one or more of the plurality of parameters to apply context-based security to network traffic transported between the O-DU node and the O-CU-CP node and between the O-DU node and the O-CU-UP node in the O-RAN environment.

[0029] For example, the security platform may be configured to perform context-based security across an F1-U interface in the O-RAN environment.

[0030] As another example, the security platform may be configured to perform detection and prevention of known and unknown threats across an F1-U interface in the O-RAN environment.

[0031] As yet another example, the security platform may be configured to perform application identification and control across an F1-U interface in the O-RAN environment.

[0032] As a further example, the security platform may be configured to perform URL filtering across an F1-U interface in the O-RAN environment.

[0033] In some embodiments, the system / process / computer program product for applying context-based security across interfaces in an O-RAN environment in a mobile network further includes blocking new sessions from accessing resources based on the security policy.

[0034] In some embodiments, the system / process / computer program product for applying context-based security across interfaces in an O-RAN environment in a mobile network further includes enabling the new session to access resources based on the security policy.

[0035] In some embodiments, a system / process / computer program product for applying context-based security across an interface in an NG-RAN environment in a mobile network includes monitoring network traffic in a mobile network at a security platform to identify a GTP-U tunnel session setup message associated with a new session, extracting a plurality of parameters from the GTP-U tunnel session setup message and from XnAP traffic to extract context information at the security platform, and implementing a security policy at the security platform for the new session based on one or more of the plurality of parameters to apply context-based security to the network traffic transported between NG-RAN nodes in an NG-RAN environment in the mobile network.

[0036] In some embodiments, a system / process / computer program product for applying context-based security across an interface in an NG-RAN environment in a mobile network further includes a security platform that extracts user plane (UP) transport layer information from a handover request message to set up the GTP-U tunnel session, and the security platform can be configured to apply the context-based security to the network traffic transported between the NG-RAN nodes in the NG-RAN environment in the mobile network using a plurality of security policies.

[0037] In some embodiments, the system / process / computer program product for applying context-based security across an interface in an NG-RAN environment in a mobile network further includes inspecting XnAP traffic across an Xn-C interface between a source NG-RAN node and a target NG-RAN node to extract said context information.

[0038] In some embodiments, the system / process / computer program product for applying context-based security across interfaces in an NG-RAN environment in a mobile network further includes inspecting XnAP traffic across an Xn-C interface between a source NG-RAN node and a target NG-RAN node to extract context information, and storing the context information locally in the security platform or in cloud-based storage.

[0039] In some embodiments, the system / process / computer program product for applying context-based security across an interface in an NG-RAN environment in a mobile network further includes inspecting GTP-U traffic across an Xn-U interface between a source NG-RAN node and a target NG-RAN node to apply Layer 7 security to user plane traffic, and correlating the context information with user plane traffic to perform context-based security for node-to-node traffic in the NG-RAN environment.

[0040] In some embodiments, a system / process / computer program product for applying context-based security across an interface in an NG-RAN environment in a mobile network includes monitoring network traffic on the mobile network at a security platform to identify a GTP-U tunnel session setup message associated with a new session, and extracting a plurality of parameters from the GTP-U tunnel session setup message and from XnAP traffic to extract context information at the security platform, wherein extracting a plurality of parameters from the GTP-U tunnel session setup message and from the XnAP traffic to extract context information at the security platform further includes inspecting the XnAP traffic across an Xn-C interface between a source NG-RAN node and a target NG-RAN node at the mobile network to extract the context information, and inspecting the GTP-U traffic across an Xn-U interface between the source NG-RAN node and the target NG-RAN node at the mobile network to apply Layer 7 security to the user plane traffic. and enforcing, in the mobile network, a security policy for the new session based on one or more of the plurality of parameters in the security platform to apply context-based security to network traffic transported between NG-RAN nodes in the NG-RAN environment.

[0041] For example, the security platform may be configured to perform context-based security across an Xn-U interface in the NG-RAN environment.

[0042] As another example, the security platform may be configured to perform detection and prevention of known and unknown threats across the Xn-U interface in the NG-RAN environment.

[0043] As yet another example, the security platform may be configured to perform application identification and control across an Xn-U interface in the NG-RAN environment.

[0044] As a further example, the security platform may be configured to perform URL filtering across an Xn-U interface in the NG-RAN environment.

[0045] In some embodiments, the system / process / computer program product for applying context-based security across interfaces in an NG-RAN environment in a mobile network further includes blocking the new session from accessing resources based on the security policy.

[0046] In some embodiments, the system / process / computer program product for applying context-based security across interfaces in an NG-RAN environment in a mobile network further includes enabling the new session to access resources based on the security policy.

[0047] Thus, novel and improved security solutions are disclosed, according to some embodiments, that facilitate applying security (e.g., network-based security) in mobile networks (e.g., 4G / 5G / 6G / and later versions of mobile networks) over various interfaces and protocols in NG-RAN and / or O-RAN environments using security platforms (e.g., firewalls (FW) / next-generation firewalls (NGFWs), network sensors acting in place of firewalls, or other (virtual) devices / components that can implement security policies using the disclosed technologies, including, for example, Palo Alto Networks' PA series next-generation firewalls, Palo Alto Networks' VM series virtualized next-generation firewalls, and CN series container next-generation firewalls, and / or other commercially available virtual-based or container-based firewalls similarly implemented and configured to execute the disclosed technologies).

[0048] Mo These and other embodiments and examples for applying context-based security across interfaces in NG-RAN and / or O-RAN environments in mobile networks are further described below.

[0049] An exemplary system architecture for applying context-based security across interfaces in NG-RAN environments in mobile networks

[0050] Thus, in some embodiments, the disclosed technology includes providing a security platform (e.g., the security function / platform may be implemented using a firewall (FW) / Next Generation Firewall (NGFW), a network sensor acting in place of a firewall, or another (virtual) device / component that can implement security policies using the disclosed technology, such as PANOS running on a commercially available virtual / physical NGFW solution from Palo Alto Networks, or another security platform / NFGW, including, for example, Palo Alto Networks' PA Series Next Generation Firewall, Palo Alto Networks' VM Series Virtualized Next Generation Firewall, and CN Series Containerized Next Generation Firewall) configured to apply security to user plane traffic based on policy (e.g., Layer 7 security and / or other security policy enforcement), as described further below. As another example, the security platform may be configured to correlate context information with user plane traffic to deliver context-based security capabilities for node-to-node traffic in NG-RAN based 5G networks.

[0051] 1 is a block diagram of a 5G wireless network architecture having a security platform for applying context-based security across interfaces in an NG-RAN environment in a mobile network, according to some embodiments. Specifically, FIG. 1 illustrates an exemplary 5G mobile network environment including a security platform 102 (e.g., a firewall (FW) / next-generation firewall (NGFW), a network sensor acting in place of a firewall, or another (virtual) device / component that can implement security policies using the disclosed techniques, including, for example, Palo Alto Networks' PA Series Next-Generation Firewall, Palo Alto Networks' VM Series Virtualized Next-Generation Firewall, and CN Series Containerized Next-Generation Firewall) for applying context-based security across interfaces in an NG-RAN environment in a mobile network (e.g., a 5G or later mobile network), as described further below.

[0052] As shown, the 5G mobile network environment may also include 5G Radio Access Network (RAN) access (e.g., gNB) as shown at 104A and 104B, and / or other networks (not shown in FIG. 1 ) for facilitating data communications for subscribers (e.g., using user equipment (UE) such as smartphones, laptops, computers (which may be at fixed locations), and / or other cellular enabled computing devices / appliances, such as IoT devices as shown at 106, or other network communication enabled devices), including through a central data network (e.g., the Internet) 120 for accessing various applications, web services, content hosts, etc., and / or other networks. As shown in FIG. 1, each of the 5G network access mechanisms 104A and 104B communicates with a 5G mobile core user plane (UP) function 114 (e.g., over an N3 interface) and with a 5G mobile core control plane (CP) function 112 (e.g., over an N2 interface), which in turn communicates with a central data network 120.

[0053] 1 , network traffic communications are monitored using a security platform 102. As shown, network traffic communications are monitored / filtered in a 5G network using security platforms 102 (e.g., (virtual) devices / appliances, each of which may include a firewall (FW), a network sensor operating in place of a firewall, or another device / component that may implement a security policy using the disclosed technology) configured to execute the disclosed techniques for applying context-based security across interfaces in an NG-RAN environment in a mobile network, as also described above and further below.

[0054] Specifically, the security platform 102 monitors the Xn-C and Xn-U interfaces. In some embodiments, the security platform is configured to provide the following DPI functions: stateful inspection of XnAP traffic across such Xn-C interfaces and GTP-U traffic across such Xn-U interfaces. In one exemplary implementation, the security platform is configured to provide DPI functions (e.g., including stateful inspection) of XnAP sessions (e.g., XnAP traffic) across the Xn-C interface and GTP-U sessions (e.g., GTP-U traffic) across the Xn-U interface, for example, between a source NG-RAN node and a target NG-RAN node, to apply security for user plane traffic based on policy (e.g., Layer 7 security and / or other security policy enforcement), as described further below. As another example, the security platform may be configured to correlate context information with user plane traffic to deliver context-based security capabilities for node-to-node traffic in an NG-RAN environment in a 5G network (see, e.g., 3GPP TS 38.423-v16.6.0 5G, NG-RAN, Xn Application Protocol (XnAP), available at https: / / www.etsi.org / deliver / etsi_ts / 138400_138499 / 138423 / 16.06.00_60 / ts_138423v160600p.pdf).

[0055] In one exemplary implementation, the security platform is configured to inspect XnAP traffic across an Xn-C interface between a source NG-RAN node and a target NG-RAN node to extract context information. The security platform can also inspect GTP-U traffic across an Xn-U interface between the source NG-RAN node and the target NG-RAN node to apply Layer 7 security to the user plane traffic. The security platform can correlate the context information with the user plane traffic to deliver context-based security features for node-to-node traffic in an NG-RAN environment in a 5G network.

[0056] In some embodiments, the security platform is configured to provide the following DPI capabilities: stateful inspection of XnAP traffic over the Xn-C interface and GTP-U traffic over the Xn-U interface, and apply context-based security as described herein.

[0057] Additionally, the security platform 102 may also provide a cloud security service 122 (e.g., WildFire, a commercially available cloud security service offered by Palo Alto Networks, Inc.), such as over the Internet. TMThe cloud security service 122 may also be in network communication with a commercially available cloud-based security service, such as a cloud-based malware analysis environment, which may include automated security analysis of malware samples as well as security expert analysis, or may utilize a similar solution provided by another vendor. For example, the cloud security service 122 may be used to provide the security platform with dynamic prevention signatures for malware, DNS, URL, CNC malware, and / or other malware, and to receive malware samples for further security analysis.

[0058] Referring to FIG. 1, the security platform 102 performs XnAP and GTP-U stateful inspection in this exemplary 5G mobile network environment by parsing XnAP session traffic on the Xn-C interface and GTP-U session traffic on the Xn-U interface, respectively, to extract predetermined information, as further described below with respect to FIGS. 2A and 2B.

[0059] As will become apparent, network traffic communications may be monitored / filtered using one or more security platforms for network traffic communications at various locations within a 5G network (e.g., a 5G network or an aggregated 5G network) to facilitate applying context-based security across interfaces in an NG-RAN environment in a mobile network.

[0060] 2A and 2B are tables of parameters extracted by the security platform from a handover request during the setup of a GTP-U tunnel session, according to some embodiments. This message is sent by a source NG-RAN node to a target NG-RAN node to request the preparation of resources for handover (e.g., direction: source NG-RAN node -> target NG-RAN node).

[0061] In some embodiments, the security platform is configured to use user plane (UP) transport layer information extracted from the "HANDOVER REQUEST" message to set up a GTP-U tunnel session. As shown in FIG. 2A, a "PDU Session Resources To Be Setup List" IE contains PDU session resource-related information used in UE context transfer between NG-RAN nodes. It contains uplink (UL) tunnel information for each PDU session resource. As also shown in FIG. 2A, "Masked IMEISV" information is also provided, and the security platform can extract the Type Allocation Code (TAC) to obtain the make and model of the 5G device. As shown in FIG. 2B, other information that may be extracted from the "PDU Session Resource Configuration Target List" IE includes "S-NSSAI," which indicates the S-NSSAI as defined in 3GPP TS 23.003 Version 16.3.0 Release 16 (available, for example, at https: / / www.etsi.org / deliver / etsi_ts / 123000_123099 / 123003 / 16.03.00_60 / ts_123003v160300p.pdf), "UL NG-U UP TNL Info at UPF," which indicates the UPF endpoint of the NG-U transport bearer for delivery of the UL PDU, and "Source DL NG-U TNL Info," which indicates the possibility of maintaining the NG-U GTP-U tunnel endpoint at the target NG-RAN node.

[0062] 2C is a handover protocol sequence diagram for an NG-RAN environment in a mobile network. As shown, a source NG-RAN node 210 sends a HANDOVER REQUEST message to a target NG-RAN node 220. The target NG-RAN node sends a response with a HANDOVER REQUEST ACKNOWLEDGE message, as shown in FIG. 2C.

[0063] Exemplary system architecture for applying context-based security across interfaces in an O-RAN environment in mobile networks

[0064] Generally, 5G refers to the fifth generation of mobile communication systems. The 3rd Generation Partnership Project (3GPP) includes seven telecommunications standards development organizations (i.e., ARIB, ATIS, CCSA, ETSI, TSDSI, TTA, and TTC). This project covers cellular telecommunications network technologies, including radio access, core transport networks, and service functions. This specification also provides hooks for non-wireless access to the core network, as well as Wi-Fi networks, and for interworking with other organizations developing 5G standards, including ITU, IETF, and ETSI. Some of the improvements in the new 5G network standards include, for example, the evolution of the Next Generation RAN (NG-RAN) architecture, commonly referred to as the Open Radio Access Network (O-RAN).

[0065] O-RAN (Open RAN) is a term used for industry-wide standards for RAN (Radio Access Network) interfaces that support interoperability between vendors' equipment and provide network flexibility at lower costs. The main goal of Open RAN is to have interoperability standards for RAN elements that include non-proprietary white-box hardware and software from different vendors. Network operators who choose RAN elements with standard interfaces can avoid being locked into one vendor's proprietary hardware and software.

[0066] The O-RAN Alliance's mission is to reshape the RAN industry towards more intelligent, open, virtualized, and fully interoperable mobile networks. New O-RAN standards will enable a more competitive and vibrant ecosystem of RAN suppliers with faster innovation to improve user experience. O-RAN-based mobile networks will simultaneously improve the efficiency of RAN deployments and operations by mobile operators.

[0067] The O-RAN architecture is based on standards defined by the O-RAN Alliance and fully supports and is complementary to standards driven by 3GPP and other industry standards organizations. It includes interfaces defined and maintained by O-RAN, including A1, O1, O2, E2, and open fronthaul interfaces. In addition, this architecture also includes 3GPP interfaces, including E1, F1-c, F1-u, NG-c, NG-u, X2-c, X2-u, X2-c, Xn-c, Xn-u, and Uu.

[0068] However, as also noted above, this new O-RAN architecture opens up new threat vectors. As one example, the new O-RAN architecture in 5G networks opens up new security threats across the Xn-U interface. Thus, various techniques for securing this new O-RAN environment in 5G networks are disclosed and will now be further described with respect to Figures 3 through 4B.

[0069] 3 is a block diagram of a 5G wireless network architecture having a security platform for applying context-based security across interfaces in an O-RAN environment in a mobile network, according to some embodiments. Specifically, FIG. 3 illustrates an exemplary 5G mobile network environment including a security platform 102 (e.g., a firewall (FW) / next-generation firewall (NGFW), a network sensor acting in place of a firewall, or another (virtual) device / component that can implement security policies using the disclosed techniques, including, for example, Palo Alto Networks' PA series next-generation firewall, Palo Alto Networks' VM series virtualized next-generation firewall, and CN series containerized next-generation firewall) for applying context-based security across interfaces in an O-RAN environment in a mobile network (e.g., a 5G or later mobile network), as described further below.

[0070] As shown, the 5G mobile network environment may also include 5G radio units (RUs) such as 304 (e.g., radio hardware units that convert radio signals to and from antennas into digital signals) and / or other networks (not shown in FIG. 3 ) to facilitate data communications for subscribers (e.g., using user equipment (UE) such as smartphones, laptops, computers (which may be at fixed locations), and / or other cellular-enabled computing devices / appliances such as IoT devices as shown at 106, or other network communication-enabled devices), including over a central data network (e.g., the Internet) 120 and / or other networks for accessing various applications, web services, content hosts, etc. As shown in FIG. 3 , the 5G network's access mechanism, the RU 304, is in communication with an O-RAN distributed unit (O-DU) 306 to facilitate network communications for UEs such as customer devices 302 (e.g., a network / wireless communication-enabled device such as a smartphone, or another device capable of network / wireless communication). The O-DU 306 communicates with an O-RAN Centralized Unit Control Plane (O-CU-CP) 308 (e.g., over an F1-C interface) and also with an O-RAN Centralized Unit User Plane (O-CU-UP) 310 (e.g., over an F1-U interface). The O-CU-CP 308 communicates with a 5G mobile core control plane (CP) function 112 (e.g., over an N2 interface). The O-CU-UP 310 communicates with a 5G mobile core user plane (UP) function 114 (e.g., over an N3 interface), which communicates with the Internet 120.

[0071] 3 , network traffic communications are monitored using security platform 102. As shown, network traffic communications are monitored / filtered in a 5G network using security platform 102 (e.g., (virtual) devices / appliances each including a firewall (FW), a network sensor operating in place of a firewall, or another device / component capable of implementing security policies using the disclosed technologies, including, for example, Palo Alto Networks' PA Series Next Generation Firewall, Palo Alto Networks' VM Series Virtualized Next Generation Firewall, and CN Series Container Next Generation Firewall, and / or other commercially available virtual-based or container-based firewalls may similarly be implemented and configured to execute the disclosed technologies), which is similarly described above and configured to execute the disclosed technologies for applying context-based security across interfaces in an O-RAN environment in a mobile network, as described further below.

[0072] Specifically, the security platform 102 monitors the F1-C and F1-U interfaces. In some embodiments, the security platform is configured to provide the following DPI functions: stateful inspection of F1AP traffic across such F1-C interfaces and GTP-U traffic across such F1-U interfaces. In one exemplary implementation, the security platform is configured to provide DPI functions (e.g., including stateful inspection) of F1AP sessions (e.g., F1AP traffic) across the F1-C interface between the O-DU and the O-CU-CP and GTP-U sessions (e.g., GTP-U traffic) across the F1-U interface between the O-DU and the O-CU-UP, and apply security to user plane traffic based on policies (e.g., Layer 7 security and / or other security policy enforcement), as described further below. As another example, the security platform may be configured to correlate context information with user plane traffic to deliver context-based security functions for node-to-node traffic in an O-RAN environment in a 5G network.

[0073] In one exemplary implementation, the security platform is configured to use UP transport layer information extracted from the "UE CONTEXT SETUP REQUEST" and "UE CONTEXT SETUP RESPONSE" messages exchanged between the gNB-DU and gNB-CU during the "UE Context Setup Procedure" to set up a GTP-U tunnel session. The UP transport layer information IE identifies the F1 transport bearer associated with the DRB. It includes a transport layer address and a GTP tunnel endpoint identifier. The transport layer address is an IP address used for F1 user plane transport. The GTP tunnel endpoint identifier is used for user plane transport between the gNB-CU and gNB-DU.

[0074] Additionally, in this exemplary implementation, the security platform is configured to inspect F1AP traffic across the F1-C interface between the O-DU and the O-CU-CP and extract context information. The security platform can also inspect GTP-U traffic across the F1-U interface between the O-DU and the O-CU-UP and apply Layer 7 security to user plane (UP) traffic (see, e.g., 3GPP TS 38.473-V16.6.0, 5G, NG-RAN, F1 Application Protocol (F1AP) (see 3GPP TS 38.473 Version 16.6.0 Release 16, available at https: / / www.etsi.org / deliver / etsi_ts / 138400_138499 / 138473 / 16.06.00_60 / ts_138473v160600p.pdf), and also 3GPP TS 38.470-V16.50, General Aspects and Principles of 5G, NG-RAN, F1 (see also 3GPP TS 38.470 Version 16.50, available at https: / / www.etsi.org / deliver / etsi_ts / 138400_138499 / 138470 / 16.05.00_60 / ts_138470v160500p.pdf). The security platform can correlate context information with user plane traffic to deliver context-based security capabilities in O-RAN-based mobile networks (e.g., 5G networks).

[0075] In some embodiments, the security platform is configured to provide the following DPI functionality: stateful inspection of F1 AP traffic across the F1-C interface between the O-DU and O-CU-CP to extract context information and apply context-based security, as described herein.

[0076] Additionally, the security platform 102 may also communicate, such as via the Internet, with cloud security services 122 (e.g., WildFire, a commercially available cloud security service platform offered by Palo Alto Networks, Inc., that includes automated security analysis of malware samples as well as security expert analysis). TM The cloud security service 122 may be in network communication with a commercially available cloud-based security service, such as a cloud-based malware analysis environment, or a similar solution provided by another vendor. For example, the cloud security service 122 may be used to provide the security platform with dynamic prevention signatures for malware, DNS, URL, CNC malware, and / or other malware, as well as to receive malware samples for further security analysis.

[0077] Referring to FIG. 3, the security platform 102 performs F1AP and GTP-U stateful inspection in this exemplary 5G mobile network environment by parsing F1AP session traffic on the F1-C interface and GTP-U session traffic on the F1-U interface, respectively, to extract predetermined information, as further described below with respect to FIGS. 4A and 4B.

[0078] As will become apparent, to facilitate applying context-based security across interfaces in O-RAN in a mobile network (e.g., including a distributed O-RAN environment), network traffic communications may be monitored / filtered using one or more security platforms for network traffic communications at various locations within a mobile network (e.g., a 5G network or a converged 5G network).

[0079] 4A and 4B are tables of parameters extracted by the security platform from a handover request during setup of a GTP-U tunnel session, according to some embodiments.

[0080] In some embodiments, the security platform is configured to use user plane (UP) transport layer information extracted from the "UE CONTEXT SETUP REQUEST" and "UE CONTEXT SETUP RESPONSE" messages to set up a GTP-U tunnel session. The UP transport layer information IE identifies the F1 transport bearer associated with the DRB. It includes a transport layer address and a GTP tunnel endpoint identifier. The transport layer address is an IP address used for F1 user plane transport. The GTP tunnel endpoint identifier is used for user plane transport between the gNB-CU and the gNB-DU.

[0081] Also shown in FIG. 4A is “Masked IMEISV” information, from which the security platform can extract the Type Allocation Code (TAC) to obtain the make and model of the 5G device. As shown in FIG. 4A, other information that can be extracted from the "UE CONTEXT SETUP REQUEST" includes "S-NSSAI," which indicates the S-NSSAI as defined in 3GPP TS 23.003 Version 16.3.0 Release 16 (available, for example, at https: / / www.etsi.org / deliver / etsi_ts / 123000_123099 / 123003 / 16.03.00_60 / ts_123003v160300p.pdf), "UL NG-U UP TNL Information at UPF," which indicates the UPF endpoint of the NG-U transport bearer for delivery of the UL PDU, and "UL UP TNL Information," which indicates the gNB-CU endpoint of the F1 transport bearer for delivery of the UL PDU. As shown in FIG. 4B, other information that can be extracted from the “UE CONTEXT SETUP RESPONSE” (e.g., this message is sent by the gNB-DU to confirm the setup of the UE context, gNB-DU -> gNB-CU) includes “DL UP TNL Information,” which indicates the gNB-DU endpoint of the F1 transport bearer for delivery of DL PDUs.

[0082] 4C is a handover protocol sequence diagram for an O-RAN environment in a mobile network. As shown, a gNB-DU node 410 sends a UE CONTEXT SETUP REQUEST message to a gNB-CU node 420. The gNB-CU node sends a response with a UE CONTEXT SETUP RESPONSE message, as shown in FIG. 4C.

[0083] Exemplary use cases for enhanced security to apply context-based security across interfaces in NG-RAN and O-RAN environments in mobile networks

[0084] The techniques disclosed for providing enhanced security for mobile / service provider networks using a security platform for security policy enforcement, including applying context-based security across interfaces in NG-RAN and / or O-RAN environments in mobile networks (e.g., including distributed O-RAN environments), can be applied in various additional example use case scenarios to facilitate enhanced security for NG-RAN and / or O-RAN environments in mobile networks (e.g., 4G / 5G / 6G and later mobile networks), as will now be described with respect to various example use cases.

[0085] As a first example use case, the disclosed techniques may be used to facilitate context-based security across interfaces in an NG-RAN environment in a mobile network (e.g., including context-based security across Xn-C and Xn-U interfaces in an NG-RAN environment in a 5G network) and / or context-based security in an O-RAN environment in a mobile network (e.g., including context-based security across F1-C and F1-U interfaces in an O-RAN environment in a 5G network).

[0086] As a second example use case, the disclosed techniques may be used to facilitate known and unknown threat identification across interfaces in an NG-RAN environment in a mobile network (e.g., including known and unknown threat identification across Xn-C and Xn-U interfaces in an NG-RAN environment in a 5G network) and / or across interfaces in an O-RAN environment in a mobile network (e.g., including known and unknown threat identification across F1-C and F1-U interfaces in an F1-RAN environment in a 5G network).

[0087] As a third exemplary use case, the disclosed techniques may be used to facilitate investigation of security events involving user equipment (UE) (e.g., autonomous vehicles, industrial IoT, etc.) exchanging user traffic across interfaces (e.g., Xn-C and / or Xn-U interfaces in an NG-RAN environment, or F1-C and / or F1-U interfaces in an O-RAN environment). For example, a Scada system infected with a vulnerability related to remote code execution (RCE) or remote information retrieval may be detected using the disclosed techniques.

[0088] Exemplary vulnerabilities applicable to, for example, the second and third exemplary use cases described above are listed below.

[0089] (1)Delta Industrial Automation DIAEnergie HandlerAlarmGroup.aspx SQL Injection Vulnerability CVE-2021-38393.

[0090] (2)Delta Industrial Automation CNCSoft ScreenEditor DPB Element Section Stack Buffer Vulnerability CVE-2021-2267.

[0091] (3)Advantech WebAccess SCADA bwrunmie.exe Policy Bypass Vulnerability CVE-2019-13552.

[0092] (4)Advantech WebAccess / SCADA Memory Corruption Vulnerability CVE-2019-10991.

[0093] (5)Advantech WebAccess SCADA bwrunrpt.exe Stack-based Buffer Overflow Vulnerability CVE-2019-13556.

[0094] (6)GE Industrial Solutions Remote Command Execution Vulnerability CVE-2016-0861.

[0095] As a fourth exemplary use case, the disclosed techniques can be used to facilitate advanced L7 security controls for user traffic exchanged over interfaces (e.g., Xn-C and / or Xn-U interfaces in an NG-RAN environment, or F1-C and / or F1-U interfaces in an O-RAN environment). For example, detecting and blocking command and control (C&C) traffic (e.g., IoT spyware C&C traffic and / or IoT malware C&C traffic) between industrial machines can be performed using the disclosed techniques when one machine is compromised / infected with C&C malware.

[0096] As a fifth exemplary use case, the disclosed techniques can be used to facilitate application (e.g., application layer) control over an interface (e.g., an Xn-C and / or Xn-U interface in an NG-RAN environment, or an F1-C and / or F1-U interface in an O-RAN environment). As an example, the following security solutions can be effectively and efficiently implemented using the disclosed technology: (a) allowing only trusted applications and protocols (e.g., modbus) for industrial robots / machines connected to a separate 5G base station (gNB) in a smart factory; (b) allowing only selected functions (e.g., modbus read / write register, modbus read coil, modbus input register, etc.) on trusted protocols for industrial robots / machines; and (c) blocking untrusted applications for industrial robots / machines connected to a separate 5G base station (gNB) in a smart factory.

[0097] As a sixth example use case, the disclosed techniques may be used to facilitate URL filtering across interfaces in an O-RAN environment (e.g., including URL filtering across the Xn-C and Xn-U interfaces in an O-RAN environment in a 5G network).

[0098] As a seventh exemplary use case, a security platform may be configured with security policies to perform denial of service (DoS) attack detection and prevention to apply context-based security across interfaces in an O-RAN environment in a mobile network.

[0099] As an eighth exemplary use case, the disclosed techniques can be applied to improve energy efficiency in 5G networks (e.g., O-RAN and / or distributed O-RAN environments). Specifically, the energy efficiency of 5G devices can be compromised by various types of malware attacks. For example, cryptocurrency mining is one example of an attack (e.g., devices can be compromised to be used for processing power for cryptocurrency mining operations using distributed computing resources, including the compromised 5G device). Thus, the disclosed techniques can facilitate detection and prevention of these malware attacks / threats that would otherwise compromise the energy efficiency of such 5G devices.

[0100] As a ninth exemplary use case, the disclosed techniques can be applied to improve the security of various new 5G sensors. For example, connected dairy cows in a 5G network, where dairy herds are outfitted with mobile-connected sensors that collect biometric information about the cows' temperature, pulse, and daily movements so that cows can graze further and milk production can be better managed, can also be compromised by malware. Thus, the disclosed techniques can facilitate the detection and prevention of these malware attacks / threats, including malware and remote code execution.

[0101] Exemplary vulnerabilities applicable to, for example, the third, fourth, eighth, and ninth exemplary use cases described above are listed below.

[0102] (1)Damstra Smart Asset SQL Injection Vulnerability CVE-2020-26525.

[0103] (2)CHIYU IoT Devices XSS Vulnerability CVE-2021-31250.

[0104] (3)InduSoft Web Studio and InTouch Machine Edition Remote Code Execution Vulnerability CVE-2018-10620.

[0105] (4)Ecava IntegraXor Human-Machine Interface Stack-based Buffer Overflow Vulnerability CVE-2010-4597.

[0106] As will now be apparent to those skilled in the art, the disclosed techniques for applying context-based security across interfaces in NG-RAN and / or O-RAN environments in mobile networks using a security platform for security policy enforcement can be applied in a variety of additional example use case scenarios for detecting / preventing these and other types of attacks to promote enhanced security for O-RAN / NG-RAN environments in mobile networks.

[0107] Exemplary hardware components of a network device for applying context-based security across interfaces in an NG-RAN and / or O-RAN environment in a mobile network

[0108] 5 is a functional diagram of hardware components of a network device for applying context-based security across interfaces in an NG-RAN and / or O-RAN environment in a mobile network, according to some embodiments. The example shown is a representation of physical / hardware components that may be included in network device 500 (e.g., an appliance, gateway, or server that may implement the security platform disclosed herein). Specifically, network device 500 includes a high-performance multi-core CPU 502 and RAM 504. Network device 500 also includes storage 510 (e.g., one or more hard disks or solid-state storage units) that may be used to store policies and other configuration information, as well as signatures. In one embodiment, storage 510 stores predetermined information (e.g., XnAP traffic information and / or GTP-U traffic information, as also described above) extracted from monitored traffic across various interfaces (e.g., XnAP traffic across an Xn-C interface and GTP-U traffic across an Xn-U interface) monitored to implement the disclosed security policy enforcement techniques for applying context-based security across interfaces in an O-RAN environment in a mobile network using a security platform, as also described above with respect to FIGS. 1 through 4B. Network device 500 may also include one or more optional hardware accelerators. For example, network device 500 may include a cryptographic engine 506 configured to perform encryption and decryption operations and one or more FPGAs 508 configured to perform signature matching, function as a network processor, and / or perform other tasks.

[0109] Exemplary logical components of a network device for applying context-based security across interfaces in an O-RAN environment in a mobile network

[0110] 6 is a functional diagram of logical components of a network device for applying context-based security across interfaces in an NG-RAN environment and / or an O-RAN environment in a mobile network, according to some embodiments. The example shown is a representation of logical components that may be included within a network device 600 (e.g., a data appliance that implements the disclosed security functions / platform and can perform the disclosed techniques for applying context-based security across interfaces in an O-RAN environment in a mobile network). As shown, network device 600 includes a management plane 602 and a data plane 604. In one embodiment, the management plane is responsible for managing user interaction, such as by providing a user interface for configuring policies and viewing log data. The data plane is responsible for managing data, such as by performing packet processing and session handling.

[0111] Assume that a mobile device attempts to access a resource (e.g., a remote website / server, an MEC service, an IoT device, or another resource) using an encrypted session protocol such as SSL. The network processor 606 is configured to monitor packets from the mobile device and provide the packets to the data plane 604 for processing. Flow 608 identifies the packet as part of a new session and creates a new session flow. Subsequent packets are identified as belonging to this session based on the flow lookup. If applicable, SSL decryption is applied by the SSL decryption engine 610 using various techniques as described herein. Otherwise, processing by the SSL decryption engine 610 is omitted. The application identification (APP ID) module 612 is configured to determine what type of traffic the session involves (e.g., PFCP over UDP traffic between various monitored interfaces, as similarly described above with respect to Figures 1 through 4B) and identify the user associated with the traffic flow (e.g., identify an application ID as described herein). For example, APP ID 612 may recognize a GET request in the received data and conclude that the session requires an HTTP decoder 614. As another example, APP ID 612 may recognize a GTP-U session establishment / modification / release message (e.g., across the Xn-C and Xn-U interfaces, as similarly described above with respect to Figures 1 through 4B) and conclude that the session requires a GTP-U decoder (e.g., to extract information exchanged in the GTP-U traffic session across the Xn-C and Xn-U interfaces, including various parameters, as similarly described above with respect to Figures 1 through 4B). For each type of protocol, there is a corresponding decoder 614.In one embodiment, application identification is performed by an application identification module (e.g., an APP ID component / engine), and user identification is performed by another component / engine. Based on the determination made by APP ID 612, the packet is sent to the appropriate decoder 614. Decoder 614 is configured to assemble packets (e.g., which may be received out of order) into the correct order, perform tokenization, and extract information (e.g., to extract various information exchanged in GTP-U traffic across Xn-C / Xn-U / other interfaces, as also described above and further below). Decoder 614 also performs signature matching to determine what should happen to the packet. SSL encryption engine 616 performs SSL encryption using various techniques as described herein, and the packet is then forwarded using forwarding component 618, as shown. Also shown, policy 620 is received and stored in management plane 602. In one embodiment, based on the monitored, deciphered, identified, and decrypted session traffic flows, policy enforcement is applied as described herein with respect to various embodiments (e.g., the policy may include one or more rules, which may be specified using domains and / or host / server names, and the rules may apply one or more signatures or other matching criteria or heuristics, such as to enforce security policies for subscriber / IP flows on the service provider network, based on various extracted parameters / information from monitored GTP-U traffic and / or DPI of the monitored GTP-U and / or other protocol traffic, such as XnAP traffic over the Xn-C interface, as disclosed herein).

[0112] 6 , an interface (I / F) communicator 622 is also provided for security platform manager communication (e.g., via (REST) ​​APIs, messages, or network protocol communications, or other communication mechanisms). In some cases, network communications of other network elements on the service provider network are monitored using the network device 600, and the data plane 604 supports decoding of such communications (e.g., the network device 600, including the I / F communicator 622 and decoder 614, may be configured to monitor and / or communicate over reference point interfaces, such as, for example, Xn-C, Xn-U, and / or other interfaces over which wired and wireless network traffic flows exist). Thus, the network device 600, including the I / F communicator 622, may be used to implement the disclosed techniques for security policy enforcement on a mobile / service provider network environment, including MEC service security, as described above and further below.

[0113] Additional example processes for the disclosed techniques for applying context-based security across interfaces in NG-RAN and / or O-RAN environments in mobile networks will now be described.

[0114] An exemplary process for applying context-based security across interfaces in an NG-RAN environment in a mobile network

[0115] Figure 7 is a flow diagram of a process for applying context-based security across interfaces in an NG-RAN environment in a mobile network, according to some embodiments. In some embodiments, process 700 shown in Figure 7 is performed by security platforms and techniques similarly described above, including the embodiments described above with respect to Figures 1 through 2B, 5, and 6. In one embodiment, process 700 is performed by a data appliance 500 such as described above with respect to Figure 5, a network device 600 such as described above with respect to Figure 6, a virtual appliance (e.g., Palo Alto Networks' VM-series virtualized next-generation firewall, CN-series containerized next-generation firewall, and / or other commercially available virtual-based or container-based firewalls may be similarly implemented and configured to perform the disclosed techniques), an SDN security solution, a cloud security service, and / or a combination or hybrid implementation of the foregoing as described herein.

[0116] At 702, monitoring network traffic in the mobile network at a security platform is performed to identify GTP-U tunnel session setup messages associated with the new session. For example, the security platform (e.g., a firewall, a network sensor acting on behalf of a firewall, or another device / component capable of implementing a security policy) may in some cases monitor various protocols, such as GTP-U (e.g., via an Xn-U interface), XnAP (e.g., via an Xn-C interface), and / or other protocols, on the mobile network, and more specifically, by performing the disclosed techniques, may monitor various interfaces, such as the Xn-C interface and the Xn-U interface, as also described above.

[0117] In some embodiments, the security platform inspects XnAP traffic across the Xn-C interface between the source NG-RAN node and the target NG-RAN node to extract context information (e.g., which can then be stored locally within the security platform or in cloud-based storage).

[0118] In some embodiments, the security platform inspects GTP-U traffic across the Xn-U interface between the source NG-RAN node and the target NG-RAN node and applies Layer 7 security to the user plane traffic.

[0119] At 704, extracting parameters from the GTP-U tunnel session setup message and from the XnAP traffic to extract context information is performed in the security platform. For example, the parameters can be extracted similarly to that described above with respect to Figures 2A and 2B.

[0120] In some embodiments, the security platform correlates context information with user plane traffic to perform context-based security for inter-node traffic in the NG-RAN environment.

[0121] At 706, enforcing a security policy in the security platform for the new session based on one or more of the plurality of parameters is performed to apply context-based security to network traffic transported between NG-RAN nodes in the NG-RAN environment in the mobile network. For example, enforcing the security policy may include allowing or blocking the session.

[0122] In some embodiments, the security platform performs context-based security across the Xn-U interface in the NG-RAN environment. Other examples of security policy enforcement include: (1) detection and prevention involving identification and prevention of known and unknown threats across the Xn-U interface in the NG-RAN environment, (2) application identification and control across the Xn-U interface in the NG-RAN environment, and (3) URL filtering across the Xn-U interface in the NG-RAN environment.

[0123] An exemplary process for applying context-based security across interfaces in an NG-RAN environment in a mobile network

[0124] Figure 8 is a flow diagram of a process for applying context-based security across interfaces in an O-RAN environment in a mobile network, according to some embodiments. In some embodiments, process 800 shown in Figure 8 is performed by security platforms and techniques similar to those described above, including the embodiments described above with respect to Figures 3 through 4B, 5, and 6. In one embodiment, process 800 is performed by a data appliance 500 such as those described above with respect to Figure 5, a network device 600 such as those described above with respect to Figure 6, a virtual appliance (e.g., Palo Alto Networks' VM Series Virtualized Next-Generation Firewall, CN Series Containerized Next-Generation Firewall, and / or other commercially available virtual-based or container-based firewalls may be similarly implemented and configured to perform the disclosed techniques), an SDN security solution, a cloud security service, and / or a combination or hybrid implementation of the foregoing as described herein.

[0125] The process begins at 802, where monitoring network traffic in a mobile network at a security platform is performed to identify GTP-U tunnel session setup messages associated with a new session. For example, the security platform (e.g., a firewall, a network sensor acting on behalf of a firewall, or another device / component capable of implementing a security policy) may, in some cases, monitor various protocols on the mobile network, such as GTP-U (e.g., via the F1-U interface), F1AP (e.g., via the F1-C interface), and / or other protocols, and more specifically, by performing the disclosed techniques, may monitor various interfaces, such as the F1-C interface and the F1-U interface, as also described above.

[0126] In some embodiments, the security platform inspects F1AP traffic across the F1-C interface between the O-DU node and the O-CU-CP node to extract context information (e.g., which can then be stored locally within the security platform or in cloud-based storage).

[0127] In some embodiments, the security platform inspects GTP-U traffic across the F1-U interface between the gNB-DU and gNB-CU nodes and applies Layer 7 security to user plane traffic.

[0128] At 804, extracting parameters from the GTP-U tunnel session setup message and from the F1AP traffic is performed at the security platform. For example, the parameters can be extracted similarly to that described above with respect to Figures 4A and 4B.

[0129] In some embodiments, the security platform correlates context information with user plane traffic to perform context-based security for inter-node traffic in an O-RAN environment.

[0130] At 806, enforcing a security policy in the security platform for the new session based on one or more of a plurality of parameters is performed to apply context-based security to network traffic transported between an O-RAN distributed unit (O-DU) node and an O-RAN centralized unit control plane (O-CU-CP) node in an O-RAN environment in the mobile network. For example, enforcing the security policy may include allowing or blocking the session.

[0131] In some embodiments, the security platform performs context-based security across the F1-U interface in the O-RAN environment. Other examples of security policy enforcement include: (1) detection and prevention involving identification and prevention of known and unknown threats across the F1-U interface in the O-RAN environment, (2) application identification and control across the F1-U interface in the O-RAN environment, and (3) URL filtering across the F1-U interface in the O-RAN environment.

[0132] As will become apparent in view of the disclosed embodiments, network service providers / mobile operators (e.g., cellular service provider entities), device manufacturers (e.g., automotive entities, IoT device entities, and / or other device manufacturers), and / or system integrators can specify such security policies, which can be enforced by a security platform using the disclosed technology, to solve these and other technical network security challenges for applying context-based security in NG-RAN and O-RAN environments (e.g., including distributed O-RAN environments) in mobile networks, including 4G networks, 5G networks, 6G networks, and / or later generations of mobile networks.

[0133] Although the foregoing embodiments have been described in some detail for purposes of clarity of understanding, the invention is not limited to the details provided. There are many alternative ways of implementing the invention. The disclosed embodiments are illustrative and not limiting.

Claims

1. 1. A system including a processor and a memory, The processor: Extracting a plurality of parameters from a setup message of a GTP-U tunnel session associated with a new session and from F1AP traffic to extract context information in a security platform for monitoring network traffic in the mobile network; Extracting a plurality of parameters from the GTP-U tunnel session setup message and from the F1AP traffic to extract context information in the security platform further includes: Inspecting F1AP traffic across an F1-C interface between an O-RAN Distributed Unit (O-DU) node and an O-RAN Centralized Unit Control Plane (O-CU-CP) node in an O-RAN environment in the mobile network to extract context information; and inspecting GTP-U traffic across an F1-U interface between the O-DU node and an O-RAN Centralized Unit User Plane (O-CU-UP) node to apply Layer 7 security to User Plane (UP) traffic; and implementing a security policy in the security platform for the new session based on one or more of the plurality of parameters to apply context-based security to the network traffic transported between the O-DU node and the O-CU-CP node and between the O-DU node and the O-CU-UP node in the O-RAN environment in the mobile network; It is structured as follows: the memory is coupled to the processor and configured to provide instructions to the processor; system.

2. The security platform extracts user plane (UP) transport layer information extracted from the handover request message to set up the GTP-U tunnel session. The system of claim 1 .

3. The security platform includes: applying the context-based security to the network traffic transported between the O-DU node and the O-CU-CP node in the O-RAN environment in the mobile network using a plurality of security policies; The system of claim 1 , configured to:

4. The processor further comprises: Obtaining user plane (UP) transport layer information from a UE CONTEXT SETUP REQUEST message and a UE CONTEXT SETUP RESPONSE message exchanged between a gNB-DU node and a gNB-CU node during a UE context setup procedure for setting up the GTP-U tunnel session; The system of claim 1 , configured to:

5. The processor further comprises: Inspecting F1AP traffic across an F1-C interface between the O-DU node and the O-CU-CP node to extract the context information; and storing the context information locally in the security platform or in cloud-based storage; The system of claim 1 , configured to:

6. The processor further comprises: Inspecting GTP-U traffic across the F1-U interface between the gNB-DU and gNB-CU nodes to enforce Layer 7 security on user plane traffic; and correlating the context information with user plane traffic and performing context-based security for inter-node traffic in the O-RAN environment; The system of claim 1 , configured to:

7. The security platform includes: Implementing context-based security across the F1-U interface in the O-RAN environment; The system of claim 1 , configured to:

8. The security platform includes: Performing detection and prevention of known and unknown threats across the F1-U interface in the O-RAN environment; The system of claim 1 , configured to:

9. The security platform includes: performing application identification and control across an F1-U interface in the O-RAN environment; The system of claim 1 , configured to:

10. The security platform includes:

10. The system of claim 1, wherein URL filtering is performed across an F1-U interface in the O-RAN environment.

11. The processor further comprises: blocking the new session from accessing resources based on the security policy; The system of claim 1 , configured to:

12. The processor further comprises: enabling the new session to access resources based on the security policy; The system of claim 1 , configured to:

13. 1. A method comprising: extracting, by a network processor, context information in the security platform for monitoring network traffic in the mobile network, the plurality of parameters from a GTP-U tunnel session setup message associated with the new session and from F1AP traffic; Extracting a plurality of parameters from the GTP-U tunnel session setup message and from the F1AP traffic to extract context information in the security platform further includes: Inspecting F1AP traffic across an F1-C interface between an O-RAN Distributed Unit (O-DU) node and an O-RAN Centralized Unit Control Plane (O-CU-CP) node in an O-RAN environment in the mobile network to extract context information; and Inspecting GTP-U traffic across an F1-U interface between the O-DU node and an O-RAN Centralized Unit User Plane (O-CU-UP) node to apply Layer 7 security to user plane (UP) traffic; Steps, and implementing, by the network processor, a security policy in the security platform for the new session based on one or more of the plurality of parameters, to apply context-based security to the network traffic transported between the O-DU node and the O-CU-CP node and between the O-DU node and the O-CU-UP node in the O-RAN environment in the mobile network; A method comprising:

14. The security platform extracts user plane (UP) transport layer information extracted from the handover request message to set up the GTP-U tunnel session. The method of claim 13.

15. The security platform includes: applying the context-based security to the network traffic transported between the O-DU node and the O-CU-CP node in the O-RAN environment in the mobile network using a plurality of security policies; The method of claim 13, wherein the method is configured as follows:

16. The method further comprises: inspecting F1AP traffic across an F1-C interface between the O-DU node and the O-CU-CP node, and extracting the context information; The method of claim 13.

17. The method further comprises: Inspecting GTP-U traffic across the F1-U interface between the gNB-DU node and the gNB-CU node, including applying Layer 7 security to user plane traffic. The method of claim 13.

18. The method further comprises: correlating the context information with user plane traffic to perform context-based security for node-to-node traffic in the O-RAN environment; The method of claim 13.

19. The method further comprises: performing context-based security over an F1-U interface in the O-RAN environment; The method of claim 13.

20. a computer program stored on a non-transitory computer-readable storage medium, the computer program comprising computer instructions; When executed, the instructions cause the computer to: Extracting a plurality of parameters from a setup message of a GTP-U tunnel session associated with a new session and from F1AP traffic to extract context information in a security platform for monitoring network traffic in the mobile network; Extracting a plurality of parameters from the GTP-U tunnel session setup message and from the F1AP traffic to extract context information in the security platform further includes: Inspecting F1AP traffic across an F1-C interface between an O-RAN Distributed Unit (O-DU) node and an O-RAN Centralized Unit Control Plane (O-CU-CP) node in an O-RAN environment in the mobile network to extract context information; and inspecting GTP-U traffic across an F1-U interface between the O-DU node and an O-RAN Centralized Unit User Plane (O-CU-UP) node to apply Layer 7 security to User Plane (UP) traffic; and implementing a security policy in the security platform for the new session based on one or more of the plurality of parameters to apply context-based security to the network traffic transported between the O-DU node and the O-CU-CP node and between the O-DU node and the O-CU-UP node in the O-RAN environment in the mobile network; A computer program that makes

Citation Information

Patent Citations

  • Transport layer signal security using next generation firewalls

    JP2021508994A

  • Multi-access distributed edge security in mobile networks

    JP2021513299A

  • Signalling storm mitigation in a secured radio access network

    US20210329456A1

  • Securing control and user plane separation in mobile networks

    WO2022005748A1

  • Reference signal beam configuration in a wireless communication network

    WO2022031209A1