Enforcement of subscriber ID-based security, device ID-based security, and / or network slice ID-based security using user IDs and SYSLOG messages in mobile networks.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-07-26
- Publication Date
- 2026-08-13
Smart Images

Figure 0007904985000001 
Figure 0007904985000002 
Figure 0007904985000003
Abstract
Description
Background Art
[0001] A firewall generally permits authorized communications to pass through the firewall while protecting the network from unauthorized access. A firewall is typically a device, a set of devices, or software executed on a device that provides a firewall function for network access. For example, a firewall can be integrated into the operating system of a device (such as a computer, a smartphone, or other types of network - communicable devices). A firewall can also be integrated or executed as a software application on various types of devices or security devices, such as a computer server, a gateway, a network / routing device (such as a network router), or a data appliance (such as a security device or other types of special - purpose devices).
[0002] A firewall typically rejects or permits network transmissions based on a set of rules. This set of rules is often referred to as a policy. For example, a firewall can filter inbound traffic by applying a set of rules or policies. A firewall can also filter outbound traffic by applying a set of rules or policies. A firewall can also perform basic routing functions.
Brief Description of Drawings
[0003] Various embodiments of the present invention are disclosed in the following detailed description and the accompanying drawings. [Figure 1A]Figure 1A is a block diagram relating to the architecture of a 4G / LTE wireless network with a security platform for applying subscriber ID-based security using user IDs and a syslog message network in a mobile network, according to several embodiments. [Figure 1B] Figure 1B is another block diagram relating to the architecture of a 4G / LTE radio network with a security platform for applying subscriber ID-based security using user IDs and a syslog message network in a mobile network, according to several embodiments. [Figure 1C] Figure 1C is a block diagram relating to the architecture of a 5G wireless network with a security platform for applying user ID and subscriber ID-based security using a syslog message network in a mobile network, according to several embodiments. [Figure 1D] Figure 1D is another block diagram relating to the architecture of a 5G wireless network with a security platform for applying user ID and subscriber ID-based security using a syslog message network in a mobile network, according to several embodiments. [Figure 2A] Figure 2A is an illustrative screen diagram of an interface related to a security platform on an SGi interface in L3 mode that receives syslog messages from a PGW in a 4G / LTE network, according to several embodiments. [Figure 2B] Figure 2B is an illustrative screen diagram of an interface relating to a security platform on an N6 interface in L3 mode for receiving syslog messages from UPF in a 5G network, according to several embodiments. [Figure 2C]Figure 2C is another illustrative screen view of an interface relating to a security platform on an SGi interface in L3 mode that receives syslog messages from a PGW in a 4G / LTE network, according to several embodiments. [Figure 2D] Figure 2D is another illustrative screen view of an interface relating to a security platform on an N6 interface in L3 mode receiving syslog messages from UPF in a 5G network, according to several embodiments. [Figure 3] Figure 3 is a functional diagram of hardware components for network devices that apply subscriber ID-based security, device ID-based security, and / or network slice ID-based security using user IDs and syslog message networks in a mobile network, according to several embodiments. [Figure 4] Figure 4 is a functional diagram of logical components relating to a network device for applying subscriber ID-based security, device ID-based security, and / or network slice ID-based security using user IDs and syslog message networks in a mobile network, according to several embodiments. [Figure 5] Figure 5 is a flowchart illustrating the process for applying subscriber ID-based security, device ID-based security, and / or network slice ID-based security using user IDs and syslog message networks in a mobile network, according to several embodiments. [Figure 6] Figure 6 is another flowchart relating to the process of applying subscriber ID-based security, device ID-based security, and / or network slice ID-based security using user IDs and syslog message networks in a mobile network, according to several embodiments. [Modes for carrying out the invention]
[0004] The present invention can be implemented in numerous ways, including processes, apparatus, systems, compositions, computer program products embodied on computer-readable storage media, and / or instructions stored in memory, and / or processors configured to execute instructions stored and / or provided by memory coupled to the processor. In this specification, these implementations, or any other forms the present invention may take, may be referred to as techniques. Generally, the order of the steps of the disclosed process may be modified within the scope of the invention. Unless otherwise specified, components such as processors or memory described as configured to perform a task may be implemented as general-purpose components temporarily configured to perform a task at a given time, or as specific components manufactured to perform a task. As used herein, the term “processor” refers to one or more devices, circuits, and / or processing cores configured to process data, such as computer program instructions.
[0005] A detailed description of one or more embodiments of the present invention, along with accompanying drawings illustrating the principles of the present invention, is provided below. While the present invention is described in relation to such embodiments, it is not limited to any embodiment. The scope of the present invention is limited only by the claims, and the present invention encompasses numerous alternatives, modifications, and equivalents. To provide a complete understanding of the present invention, numerous specific details are provided below. These details are provided for illustrative purposes, and the present invention may be carried out in accordance with the claims without some or all of these specific details. For clarity, technical materials known in the art related to the present invention are not described in detail so as not to unnecessarily obscure the present invention.
[0006] A firewall generally allows authorized communications to pass through while protecting the network from unauthorized access. Typically, a firewall is a device, a set of devices, or software running on a device that provides firewall functionality for network access. For example, a firewall can be integrated into the operating system of a device (e.g., a computer, smartphone, or other type of network-enabled device). Firewalls can also be integrated or run as software applications on various types of devices or security devices, such as computer servers, gateways, network / routing devices (e.g., network routers), or data appliances (e.g., security equipment or other types of special-purpose devices).
[0007] A firewall typically denies or allows network transmissions based on a set of rules. These sets of rules are often referred to as policies (e.g., network policies or network security policies). For example, a firewall can filter inbound traffic by enforcing a set of rules or policies to prevent unwanted external traffic from reaching the protected device. A firewall can also filter outbound traffic by enforcing a set of rules or policies (e.g., allow, block, monitor, notify, log, and / or other actions that may be specified in firewall / security rules or firewall / security policies, which can be triggered based on various criteria, as described here). A firewall can also apply antivirus protection, malware detection / prevention, or intrusion protection by enforcing a set of rules or policies.
[0008] Security devices (e.g., security equipment, security gateways, security services, and / or other security devices) can perform a variety of security operations (e.g., firewalls, anti-malware, intrusion prevention / detection, proxies, and / or other security functions), network functions (e.g., routing, quality of service (QoS), workload balancing of network-related resources, and / or other network functions), and / or other security and / or network-related functions. For example, routing can be performed based on source information (e.g., source IP address and port), destination information (e.g., destination IP address and port), and protocol information.
[0009] A basic packet filtering firewall filters network communication traffic by inspecting individual packets transmitted over the network (e.g., a stateless packet filtering firewall, a packet filtering firewall, or a first-generation firewall). A stateless packet filtering firewall typically inspects the individual packets themselves and then applies rules based on the inspected packets (e.g., using a combination of source and destination address information, protocol information, and port number).
[0010] An application firewall can also perform application layer filtering (for example, using an application layer filtering firewall or a second-generation firewall that operates at the application level of the TCP / IP stack). An application layer filtering firewall or application firewall can generally identify a given application and protocol (e.g., web browsing using Hypertext Transfer Protocol (HTTP), Domain Name System (DNS) requests, file transfers using File Transfer Protocol (FTP), and various other types of applications and protocols such as Telnet, DHCP, TCP, UDP, and TFTP (GSS)). For example, an application firewall can block unauthorized protocols attempting to communicate on standard ports (for example, unauthorized / unauthorized policy protocols attempting to sneak through by using non-standard ports for that protocol can generally be identified using an application firewall).
[0011] A stateful firewall can also perform stateful-based packet inspection, where each packet is examined within the context of its network transmission packet flow and associated set of packets (e.g., a stateful firewall, or third-generation firewall). This firewall technique is commonly referred to as stateful packet inspection because it maintains a record of all connections passing through the firewall and can determine whether a packet is the start of a new connection, part of an existing connection, or an invalid packet. For example, the state of a connection can itself be one of the criteria that trigger rules in a policy.
[0012] Advanced or next-generation firewalls, as described above, can perform stateless and stateful packet filtering and application layer filtering. Next-generation firewalls can also perform additional firewall technologies. For example, a given new firewall, often referred to as an advanced or next-generation firewall, can also identify users and content. In particular, a given next-generation firewall extends the list of applications these firewalls can automatically identify to thousands. Examples of such next-generation firewalls are commercially available from Palo Alto Networks (e.g., Palo Alto Networks' PA series firewalls, Palo Alto Networks' VM series virtualization next-generation firewalls, and CN series container next-generation firewalls).
[0013] For example, Palo Alto Networks' next-generation firewalls use various identification technologies to enable enterprises and service providers to identify and control applications, users, and content—not just ports, IP addresses, and packets. These various identification technologies include App-ID for precise application identification. TM (For example, App ID), User-ID for user identification (for example, by user or user group) TM (For example, User ID), and Content-ID for real-time content scanning. TM (For example, Content ID) (For example, controlling web surfing and restricting data and file transfers). These identification technologies allow businesses to securely enable application use using business-related concepts, instead of following the conventional approach provided by traditional port-blocking firewalls. Also, for example, purpose-specific hardware for next-generation firewalls, implemented as dedicated devices, generally provides a higher level of performance for application inspection than software running on general-purpose hardware (for example, security devices offered by Palo Alto Networks, which utilize dedicated, function-specific processing tightly integrated with a single-path software engine to minimize latency while maximizing network throughput for Palo Alto Networks' PA Series next-generation firewalls).
[0014] An overview of techniques for applying subscriber ID-based security, device ID-based security, and / or network slice ID-based security using user IDs and Syslog messages in mobile networks.
[0015] Regarding devices on mobile networks (e.g., 4G / LTE and 5G mobile networks), technical and security challenges exist concerning service provider networks. For example, some private 4G / LTE and private 5G networks do not expose 3GPP® interfaces between network functions, which prevents the deployment of security solutions (e.g., network gateway firewalls (NFGWs) or other security entities) on these interfaces to apply context-based security to network traffic. Furthermore, some mobile / service providers are reluctant to deploy such security solutions on various interfaces (e.g., 3GPP interfaces) due to concerns about potential latency and service disruption.
[0016] Thus, what is needed are new and improved security techniques for devices communicating over such service provider network environments (e.g., mobile networks including various 4G / LTE and 5G mobile networks). Specifically, what is needed are new and improved solutions for monitoring such network traffic and for applying context-based security policies (e.g., security / firewall policies) for devices communicating over service provider networks, including for applying subscriber ID-based security using user IDs and syslog messages, device ID-based security, and / or network slice ID-based security in mobile networks.
[0017] In some embodiments, a system / process / computer program product for applying subscriber ID-based security using user IDs and syslog messages in a mobile network monitors network traffic on the mobile network in a security platform to identify a new session, extracts a plurality of parameters by parsing syslog messages using a user ID agent in the security platform, and enforces a security policy on the new session in the security platform based on one or more of the plurality of parameters including the subscriber ID to apply context-based security in the mobile network.
[0018] For example, the techniques described above can be executed to apply subscriber ID-based security via the N6 interface in a private 5G network and / or via the SGi interface in a private 4G / LTE network.
[0019] As another example, the techniques described above can be executed to apply identification and prevention for known and unknown threats via the N6 interface in a 5G network and / or via the SGi interface in a 4G / LTE network.
[0020] As yet another example, the techniques described above can be executed to apply application identification via the N6 interface in a 5G network and / or via the SGi interface in a 4G / LTE network.
[0021] As yet another example, the techniques described above can be executed to apply URL filtering via the N6 interface in a 5G network and / or via the SGi interface in a 4G / LTE network.
[0022] Thus, service providers and / or enterprises can use the disclosed techniques and security platforms to enforce subscriber identity-based security across the boundaries of IP-based external networks (e.g., the Internet).
[0023] In some embodiments, a system / process / computer program product for applying device ID-based security using user IDs and syslog messages on a mobile network includes: monitoring network traffic on the mobile network in a security platform to identify a new session; extracting several parameters by parsing syslog messages using a user ID agent in the security platform; and enforcing a security policy on the new session in the security platform based on one or more of the several parameters, including a device ID, in order to apply context-based security on the mobile network.
[0024] For example, the techniques described above can be used to enforce device ID-based security via the N6 interface in a private 5G network and / or via the SGi interface in a private 4G / LTE network.
[0025] As another example, the techniques described above can be applied to identify and prevent known and unknown threats via the N6 interface in 5G networks and / or via the SGi interface in 4G / LTE networks.
[0026] As yet another example, the techniques described above can be used to apply application identification via the N6 interface in a 5G network and / or via the SGi interface in a 4G / LTE network.
[0027] As yet another example, the techniques described above can be used to apply URL filtering via the N6 interface in a 5G network and / or via the SGi interface in a 4G / LTE network.
[0028] Thus, service providers and / or enterprises can use the disclosed techniques and security platforms to enforce device ID-based security across the boundaries of IP-based external networks (e.g., the Internet).
[0029] In some embodiments, a system / process / computer program product for applying network slice ID-based security using user IDs and syslog messages in a mobile network includes: monitoring network traffic on the mobile network in a security platform to identify new sessions; extracting multiple parameters by parsing syslog messages using a user ID agent in the security platform; and enforcing a security policy on the new session in the security platform based on one or more of the multiple parameters, including a network slice ID, in order to apply context-based security in the mobile network.
[0030] For example, the techniques described above can be used to enforce network slice ID-based security via the N6 interface in a private 5G network.
[0031] As another example, the techniques described above can be applied to identify and prevent known and unknown threats via the N6 interface in a 5G network.
[0032] As yet another example, the techniques described above can be implemented to apply application identification via the N6 interface in a 5G network.
[0033] As yet another example, the techniques described above can be used to apply URL filtering via the N6 interface in a 5G network.
[0034] Thus, service providers and / or enterprises can use the disclosed techniques and security platform to enforce network slice ID-based security across the boundaries of IP-based external networks (e.g., the Internet). Furthermore, the disclosed techniques can be used with the security platform to enforce subscriber ID-based security, device ID-based security, and / or network slice ID-based security in mobile networks for security policy enforcement in mobile networks (including cases where the security platform is not inline with the core mobile network, such as private 4G networks, private 5G networks, etc.).
[0035] Thus, mobile network operators can use such security platforms to apply the disclosed techniques for enforcing subscriber ID-based security, device ID-based security, and / or network slice ID-based security on mobile networks, as further described below (for example, the security platform may also be configured to differentiate between deployments / operating environments, including office deployments / operating environments, enterprise deployments / operating environments, and factory deployments / operating environments, including monitoring such network traffic for devices communicating on service provider networks and applying context-based security policies (e.g., security / firewall policies)).
[0036] Thus, the disclosed techniques facilitate enhanced context-based security in mobile networks. For example, security functions (e.g., security platforms) can be positioned closer to users / devices (e.g., UEs) to perform security policy analysis and enforcement. As another example, security functions can be implemented to facilitate security in selective industry verticals. As yet another example, security can be implemented in highly sensitive locations such as government network environments, military network environments, and power plants or other critical infrastructure network environments.
[0037] Thus, novel and improved security solutions are disclosed, according to several embodiments, that facilitate the application of security (e.g., network-based security) using a security platform for performing techniques disclosed to apply subscriber ID-based security, device ID-based security, and / or network slice ID-based security using user IDs and syslog messages in mobile networks (e.g., 4G / 5G / 6G / later versions of mobile networks) on various interfaces and protocols in a mobile network environment (e.g., firewalls (FW) / next-generation firewalls (NGFW), network sensors acting in place of a firewall, or other (virtual) devices / components capable of implementing security policies using the disclosed techniques, including, for example, Palo Alto Networks' PA Series Next Generation Firewalls, Palo Alto Networks' VM Series Virtualized Next Generation Firewalls, and CN Series Container Next Generation Firewalls, and / or other commercially available virtual-based or container-based firewalls, which may be similarly implemented and configured to perform the disclosed techniques).
[0038] These and other embodiments and examples for applying subscriber ID-based security, device ID-based security, and / or network slice ID-based security using user IDs and syslog message networks in mobile networks are described further below.
[0039] Exemplary system architecture for applying subscriber ID-based security using user IDs and syslog messages in mobile networks
[0040] Accordingly, in some embodiments, the disclosed technology includes providing a security platform configured to provide DPI capabilities (e.g., including stateful inspection) of, for example, GTP-U sessions (e.g., GTP-U traffic) via various interfaces (e.g., RESTful API, N3, N6, and / or other interfaces in the 4G / 5G / 6G core network) to apply security to user plane traffic based on policies (e.g., Layer 7 security, and / or implementation of other security policies), as further described below (for example, the security function / platform is implemented using a firewall (FW) / next-generation firewall (NGFW), a network sensor acting in place of a firewall, or, for example, Palo Alto Networks' PA Series Next Generation Firewall, Palo Alto Networks' VM Series Virtualization Next Generation Firewall, and Palo Alto Networks' CN Series Container Next Generation Firewall, etc. Other (virtual) devices / components that can implement security policies using the disclosed techniques, such as PANOS running on a commercially available virtual / physical NGFW solution from Networks or another security platform / NFGW, may also be implemented and configured to perform the disclosed techniques.
[0041] Figure 1A is a block diagram relating to the architecture of a 4G / LTE radio network with a security platform for applying subscriber ID-based security using user ID and syslog message networks in a mobile network, according to several embodiments. Specifically, Figure 1A is an exemplary 4G / LTE mobile network environment, including a security platform 102 for applying subscriber ID-based security using user ID and syslog message networks in a mobile network via various interfaces within the mobile network (e.g., SGi and / or other interfaces in the 4G / LTE core network, and N6 and / or other interfaces in the 5G core network), as will be further described below. (For example, the security function / platform may be implemented using a firewall (FW) / next-generation firewall (NGFW), a network sensor acting as a firewall, or another (virtual) device / component that can implement security policies using disclosed techniques, including, for example, Palo Alto Networks' PA Series Next Generation Firewall, Palo Alto Networks' VM Series Virtualized Next Generation Firewall, and CN Series Container Next Generation Firewall.)
[0042] As referred to herein, IMSI is a concept called “International Mobile Subscription Identity” by the ITU-T. IMSI is a 14-digit or 15-digit number.
[0043] As referred to herein, SUPI is also a globally unique 5G “Subscription Permanent Identifier” assigned to each subscriber within a 5G system. According to 3GPP TS 23.003 v16.9.0, the SUPI type may represent an IMSI, Network Access Identifier (NAI), Global Line Identifier (GLI), or Global Cable Identifier (GCI).
[0044] Furthermore, as referred to herein, the International Mobile Equipment Identifier (IMEI) is defined in 3GPP TS 23.003, which is available at https: / / portal.3GPP.org / desktopmodules / Specifications / SpecificationDetails.aspx?specificationId=729.
[0045] As shown in Figure 1A, the 4G / LTE mobile network environment also includes 4G radio access network (RAN) access as shown in 106, and / or other networks including, for example, Wi-Fi access and fixed access (not shown), and can facilitate data communications for subscribers, including accessing various applications, web services, content hosts, etc., and / or other networks via a packet data network (PDN) (e.g., the Internet) 120 (e.g., using user equipment (UE) such as smartphones, laptops, computers (which may be in a fixed location), and / or other cellular-enabled computing devices / equipment such as IoT devices as shown in 104A, and / or customer devices as shown in 104B, or other network communication-enabled devices). Each of the above 4G / LTE network access mechanisms communicates with the 4G core network 110, which includes a packet data network gateway (PGW) 112. PGW112 communicates with PDN120 via an SGi interface, which the security platform 102 is positioned side-by-side between PGW112 and PDN120. The security platform 102 communicates with PGW112 (for example, via the SGi interface, as illustrated) to access real-time syslog data, including UE IP addresses and IMEI / IMSI information, as will be further described below.
[0046] Referring to Figure 1A, network traffic communications are monitored using security platform 102. As shown, network traffic communications are monitored / filled within the 4G / LTE network using security platform 102 (e.g., a (virtual) device / appliance including a firewall (FW), a network sensor acting in place of a firewall, or another device / component capable of implementing security policies using the disclosed techniques, respectively), configured to perform techniques disclosed to enforce context-based security across various interfaces within the mobile network (e.g., SGi and / or other interfaces within the 4G / LTE core network, and N6 and / or other interfaces within the 5G core network), as similarly described above and further described below.
[0047] In this exemplary implementation, the techniques disclosed for applying subscriber ID-based security using user IDs and syslog message networks in a mobile network can be performed using a security platform deployed in a 4G / LTE technology-based mobile network as shown in Figure 1A. Specifically, the mobile network has network capabilities that can generate syslog messages for predetermined events such as bearer creation and bearer deletion. These network capabilities may be configured to send syslog messages containing information about bearer creation and deletion events. User ID agents within the security platform may be configured to parse these messages. For example, the user ID agent may be configured to parse creation events to map user equipment (UE) IP addresses to subscriber IDs, and also to parse deletion events to delete old mappings. Deleting old mappings is generally useful in mobile networks where IP address assignments may change, for example, when a UE is rebooted or during various other scenarios. Thus, in some embodiments, syslog parsing profiles are used to parse syslog messages and integrate with network functions from different equipment vendors, enabling them to send syslog messages in different formats (for example, a user can create a custom profile for each format).
[0048] In some embodiments, the security platform is further configured to provide the following DPI capabilities: namely, DPI of IP traffic over the SGi interface. In one exemplary implementation, the security platform is configured to apply security to user plane traffic based on policies (e.g., Layer 7 security and / or other security policy enforcement), for example, by providing DPI capabilities for IP sessions over the SGi interface between PGW112 and PDN120 (including, for example, identifying APP ID, user ID, content ID, and performing URL filtering), as further described below.
[0049] In addition, the security platform 102 also provides cloud security services 122 (for example, WildFire, a commercially available cloud security service provided by Palo Alto Networks, which includes automated security analysis of malware samples and security expert analysis) via the internet. TM It may also communicate with a cloud-based malware analysis environment, a commercially available cloud-based security service, or a similar solution provided by another vendor. For example, the cloud security service 122 may be used to provide the security platform with dynamic prevention signatures for malware, DNS, URL, CNC malware, and / or other malware, as well as to receive malware samples for further security analysis.
[0050] Figure 2A is an exemplary screen diagram of an interface relating to a security platform on an SGi interface in L3 mode receiving syslog messages from a PGW in a 4G / LTE network, according to several embodiments. In this example, the PGW sends an event syslog (e.g., a syslog message) to the security platform (e.g., NGFW102) whenever a new default bearer is created or deleted. Each syslog contains different fields, key fields for highlighting, namely, event type, IMSI, IMEI, APN, and Ue_IP.
[0051] The following is an example of a syslog message generated by PGW.
[0052] Jan 9 08:12:14 {"pgw","type":"create_session","evt":{"imsi":"002002999971493","imei":"3526201120836534","apn":"apn2a6","user_addr":["172.16.15.159"]}}
[0053] The security platform (e.g., NGFW102) receives event syslog and creates a user ID / IP mapping. The user ID may be configured as a UE IMSI, for example, "002002999971493". A syslog entry with the event "create_session" may be configured as a user ID login action, while "delete_session" may be used as a logout action.
[0054] Referring to Figure 2A, an illustrative screen diagram of the interface related to the security platform on the SGi interface in L3 mode, which receives syslog messages from the PGW in the 4G / LTE network, provides an example of a security policy configured using a user ID, with UE IMSI=“002002999971493”.
[0055] Figure 1B is another block diagram relating to the architecture of a 4G / LTE radio network with a security platform for applying subscriber ID-based security using user IDs and a syslog message network in a mobile network, according to several embodiments. Specifically, Figure 1B is an exemplary 4G / LTE mobile network environment including the deployment of a security platform 102 in a 4G / LTE mobile edge computing (MEC) 114 environment including multiple MEC applications (APPs) as shown in Figure 1B (for example, the security function / platform may implement and configure other (virtual) devices / components that can implement security policies using disclosed techniques, including, for example, Palo Alto Networks' PA Series Next Generation Firewall, Palo Alto Networks' VM Series Virtualized Next Generation Firewall, and CN Series Container Next Generation Firewall, and / or other commercially available virtual-based or container-based firewalls, to apply subscriber ID-based security to the mobile network using user ID and syslog message networks via various interfaces in the mobile network (such as 4G / LTE and later mobile networks) (for example, SGi and / or other interfaces in the 4G / LTE core network, and N6 interface and / or other interfaces in the 5G core network, etc.), as will be further described below.
[0056] As shown in Figure 1B, the 4G / LTE mobile network environment also includes 4G radio access network (RAN) access, as shown in 106, and / or other networks, including, for example, Wi-Fi access and fixed access (not shown), and can facilitate data communications for subscribers, including via a packet data network (PDN) (e.g., the Internet) 120 to access various applications, web services, content hosts, etc. (e.g., using user equipment (UEs) such as smartphones, laptops, computers (which may be in a fixed location), and / or other cellular-enabled computing devices / equipment, or other network communication-enabled devices, such as smart factories including UEs and IoT devices as shown in 104C). Each of the above 4G / LTE network access mechanisms communicates with the 4G core network 110 (e.g., shown as the Central Core Site in Figure 1B). Furthermore, as illustrated, the 4G RAN 106 communicates with the network via the S1-U interface to the Serving Gateway User Plane function (SGW-U) and the Packet Network Data Gateway function (PGW-U), as shown in Figure 1B, 116. The SGW-U and PGW-U 116 communicate with the PDN / Internet 120 via the SGi interface, where the security platform 102 is positioned between the SGW-U and PGW-U 116 and the PDN / Internet 120. The security platform 102 communicates with the SGW-U and PGW-U 116 (for example, via the SGi interface as illustrated) and accesses real-time syslog data using UE IP addresses and IMEI / IMSI information, as similarly described above and further described below. The SGW-U and PGW-U 116 also communicate with the 4G core 110 via the Sxa / Sxb interface, as shown in Figure 1B.
[0057] Referring to Figure 1B, network traffic communications are monitored using security platform 102. As shown, network traffic communications are monitored / filled in the 4G / LTE network using security platform 102 (e.g., a (virtual) device / appliance including a firewall (FW), a network sensor acting in place of a firewall, or another device / component that can implement security policies using the disclosed techniques, respectively), configured to perform techniques disclosed to enforce context-based security over various interfaces in the mobile network (e.g., SGi and / or other interfaces in the 4G / LTE core network, and N6 and / or other interfaces in the 5G core network), as similarly described above and further described below.
[0058] In this exemplary implementation, the disclosed techniques for applying subscriber ID-based security using user IDs and a syslog message network in a mobile network can be performed using a security platform deployed in a 4G / LTE technology-based mobile network, as shown in Figure 1B. Specifically, the mobile network has network capabilities that can generate syslog messages for predetermined events such as bearer creation and bearer deletion. These network capabilities may be configured to send syslog messages containing information about bearer creation and deletion events. A user ID agent within the security platform may be configured to parse these messages. For example, the user ID agent may be configured to parse creation events to map user equipment (UE) IP addresses to subscriber IDs, and also to parse deletion events to delete old mappings. Deleting old mappings is generally useful in mobile networks where IP address assignments may change, for example, when a UE is rebooted or during various other scenarios. Thus, in some embodiments, a syslog parsing profile is used to parse syslog messages in order to integrate with network functions from different equipment vendors that can send syslog messages in different formats (for example, a user can create a custom profile for each format).
[0059] In some embodiments, the security platform is further configured to provide the following DPI capability: DPI of IP traffic over the SGi interface. In one exemplary implementation, the security platform is configured to provide DPI functionality for IP sessions over the SGi interface between the SGW-U and PGW-U 116 and the PDN120 (including, for example, identifying APP ID, user ID, content ID, performing URL filtering), and to apply security to user plane traffic based on policies (e.g., Layer 7 security, and / or other security policy enforcement), as further described below.
[0060] In addition, the security platform 102 also provides cloud security services 122 (for example, WildFire, a commercially available cloud security service provided by Palo Alto Networks, which includes automated security analysis of malware samples and security expert analysis) via the internet. TM It may also communicate with a cloud-based malware analysis environment (commercial cloud-based security services or similar solutions provided by other vendors may be used). For example, cloud security service 122 may be used to provide the security platform with dynamic prevention signatures for malware, DNS, URL, CNC malware, and / or other malware, as well as to receive malware samples for further security analysis.
[0061] Figure 1C is a block diagram relating to the architecture of a 5G radio network with a security platform for applying subscriber ID-based security using user ID and syslog message networks in a mobile network, according to several embodiments. Specifically, Figure 1C is an exemplary 5G mobile network environment, including a security platform 102 for applying subscriber ID-based security using user ID and syslog message networks in a mobile network (e.g., 5G or later mobile network) via various interfaces in the mobile network (e.g., SGi and / or other interfaces in the 4G / LTE core network, and N6 interface and / or other interfaces in the 5G core network) (e.g., the security function / platform may be implemented using a firewall (FW) / next-generation firewall (NGFW), a network sensor acting in place of a firewall, or another (virtual) device / component that can implement security policies using disclosed techniques, including, for example, Palo Alto Networks' PA Series Next Generation Firewall, Palo Alto Networks' VM Series Virtualized Next Generation Firewall, and CN Series Container Next Generation Firewall).
[0062] As shown in Figure 1C, the 5G mobile network environment also includes 5G New Radio (NR) Radio Access Network (RAN) access, as shown in 108, and / or other networks, including, for example, Wi-Fi access and fixed access (not shown), which can facilitate data communications for subscribers, including via a Packet Data Network (PDN) (e.g., the Internet) 120 to access various applications, web services, content hosts, etc. (using UEs or other network communication-enabled devices, such as user equipment (UEs), such as smartphones, laptops, computers (which may be in a fixed location), and / or other cellular-enabled computing devices / equipment, such as IoT devices, as shown in 104A, and / or customer devices, as shown in 104B). Each of the above 5G network access mechanisms communicates with the 5G core network 118, which includes a 5G mobile core user plane function (UPF) 124. UPF124 communicates with PDN120 via the N6 interface, where security platform 102 is positioned side-by-side between UPF124 and PDN120. Security platform 102 communicates with UPF124 (e.g., via the N6 interface as shown in the diagram) to access real-time syslog data with UE IP address and IMEI / IMSI information, as will be further described below.
[0063] Referring to Figure 1C, network traffic communications are monitored using security platform 102. As shown, network traffic communications are monitored / filled in the 5G network using security platform 102 (e.g., a (virtual) device / appliance including a firewall (FW), a network sensor acting in place of a firewall, or another device / component that can implement security policies using the disclosed techniques, respectively), configured to perform techniques disclosed to apply context-based security over various interfaces in the mobile network (e.g., SGi and / or other interfaces in the 4G / LTE core network, and N6 and / or other interfaces in the 5G core network), as similarly described above and further described below.
[0064] In this exemplary implementation, the disclosed techniques for applying subscriber ID-based security using user IDs and a syslog message network in a mobile network can be performed using a security platform deployed in a 4G / LTE technology-based mobile network, as shown in Figure 1C. Specifically, the mobile network has network capabilities that can generate syslog messages for predetermined events such as bearer creation and bearer deletion. These network capabilities may be configured to send syslog messages containing information about bearer creation and deletion events. A user ID agent within the security platform may be configured to parse these messages. For example, the user ID agent may be configured to parse creation events to map user equipment (UE) IP addresses to subscriber IDs, and also to parse deletion events to delete old mappings. Deleting old mappings is generally useful in mobile networks where IP address assignments may change, for example, when a UE is rebooted or during various other scenarios. Thus, in some embodiments, a syslog parsing profile is used to parse syslog messages in order to integrate with network functions from different equipment vendors that can send syslog messages in different formats (for example, a user can create a custom profile for each format).
[0065] In some embodiments, the security platform is further configured to provide the following DPI capability: DPI of IP traffic over the N6 interface. In one exemplary implementation, the security platform is configured to provide DPI capability (including, for example, identifying APP ID, user ID, content ID, and performing URL filtering) over IP sessions over the N6 interface between UPF124 and PDN120 in order to apply security to user plane traffic based on policies (e.g., Layer 7 security and / or other security policy enforcement), as further described below.
[0066] In addition, the security platform 102 also provides cloud security services 122 (for example, WildFire, a commercially available cloud security service provided by Palo Alto Networks, which includes automated security analysis of malware samples and security expert analysis) via the internet. TM It can communicate with a cloud-based malware analysis environment (commercial cloud-based security services, or similar solutions provided by other vendors, may be used). For example, cloud security service 122 may be used to provide the security platform with dynamic prevention signatures for malware, DNS, URL, CNC malware, and / or other malware, as well as to receive malware samples for further security analysis.
[0067] Figure 2B is an exemplary screen diagram of an interface relating to a security platform on an N6 interface in L3 mode receiving syslog messages from a UPF in a 5G network, according to several embodiments. In this example, the UPF sends an event syslog (e.g., a syslog message) to the security platform (e.g., NGFW102) whenever a new PDU session is created or deleted. Each syslog contains different fields, key fields for highlighting: namely, Event type, IMSI, IMEI, DNN, S-NSSAI, and Ue_IP.
[0068] The following is an example syslog message generated by UPF.
[0069] Jan 13 10:16:15 {"upf","type":"create_pdu_session","evt":{"imsi":"312333000222123","imei":"4441 221130832222","dnn":"dnn1bc4","s-nssai":"1:1000","user_addr":["172.16.15.171"]}}
[0070] The security platform (e.g., NGFW102) receives event syslog and creates a user ID / IP mapping. The user ID may be configured as a UE IMSI, for example, "312333000222123". A syslog event with "create_session" can be configured as a user ID login action, while "delete_session" can be used as a logout action.
[0071] Referring to Figure 2B, an illustrative screen diagram of the interface related to the security platform on the N6 interface in L3 mode receiving syslog messages from the UPF within the 5G network provides an example of a security policy configured using a user ID, with UE IMSI=“312333000222123”.
[0072] Figure 1D is another block diagram relating to an architecture of a 5G wireless network with a security platform for applying subscriber ID-based security using user IDs and a syslog message network in a mobile network, according to several embodiments. Specifically, Figure 1D is an exemplary 5G mobile network environment that includes the deployment of a security platform 102 in a 5G mobile edge computing (MEC) 114 environment, including multiple MEC applications (APPs) as shown in Figure 1D for applying subscriber ID-based security using user ID and syslog message networks in a mobile network via various interfaces in the mobile network (e.g., SGi and / or other interfaces in the 4G / LTE core network, and N6 interface and / or other interfaces in the 5G core network), as will be further described below (for example, the security function / platform may be implemented using a firewall (FW) / next-generation firewall (NGFW), a network sensor acting as a substitute for a firewall, or another (virtual) device / component that can implement security policies using disclosed techniques, including, for example, Palo Alto Networks' PA Series Next Generation Firewall, Palo Alto Networks' VM Series Virtualized Next Generation Firewall, and CN Series Container Next Generation Firewall).
[0073] As shown in Figure 1D, the 5G mobile network environment also includes, respectively, 5G New Radio (NR) Radio Access Network (RAN) access shown in 108, and / or other networks including, for example, Wi-Fi access and fixed access (not shown), which can facilitate data communications for subscribers, including via a Packet Data Network (PDN) (e.g., the Internet) 120 to access various applications, web services, content hosts, etc. (e.g., using user equipment (UEs) such as smartphones, laptops, computers (which may be in a fixed location), and / or other cellular-enabled computing devices / equipment or other network communication-enabled devices such as smart factories including UEs and IoT devices as shown in 104C). Each of the 5G network access mechanisms described above communicates with the 5G core network 118 (e.g., shown as the central core site in Figure 1D). Also, as shown, the 5G NR RAN 108 communicates with the UPF via the N3 interface, as shown in 124 in Figure 1D. UPF124 communicates with the PDN / Internet 120 via the N6 interface, where the security platform 102 is positioned side-by-side between UPF124 and the PDN / Internet 120. The security platform 102 communicates with the UPF (e.g., via the N6 interface, as illustrated) to access real-time syslog data with UE IP addresses and IMEI / IMSI information, as similarly described above and further described below. UPF124 also communicates with the 5G core 118 via the N4 interface, as shown in Figure 1D.
[0074] Referring to Figure 1D, network traffic communications are monitored using security platform 102. As shown, network traffic communications are monitored / filled within the 5G network using security platform 102 (e.g., a (virtual) device / appliance including a firewall (FW), a network sensor acting in place of a firewall, or another device / component that can implement security policies using the disclosed techniques, respectively) configured to perform disclosed techniques for applying context-based security via various interfaces within the mobile network (e.g., SGi and / or other interfaces in the 4G / LTE core network, and N6 interface and / or other interfaces in the 5G core network), as similarly described above and further described below.
[0075] In this exemplary implementation, the techniques disclosed for applying subscriber ID-based security using user IDs and syslog message networks in a mobile network can be performed using a security platform deployed in a 5G technology-based mobile network as shown in Figure 1D. Specifically, the mobile network has network capabilities that can generate syslog messages for predetermined events such as bearer creation and bearer deletion. These network capabilities may be configured to send syslog messages containing information about bearer creation and deletion events. A user ID agent within the security platform may be configured to parse these messages. For example, the user ID agent may be configured to parse creation events to map user equipment (UE) IP addresses to subscriber IDs, and also to parse deletion events to delete old mappings. Deleting old mappings is generally useful in mobile networks where IP address assignments may change, for example, when a UE is rebooted or during various other scenarios. Thus, in some embodiments, syslog parsing profiles are used to parse syslog messages and integrate with network functions from different equipment vendors, enabling them to send syslog messages in different formats (for example, a user can create a custom profile for each format).
[0076] In some embodiments, the security platform is further configured to provide the following DPI capabilities: namely, DPI of IP traffic over the N6 interface. In one exemplary implementation, the security platform is configured to provide DPI capabilities for the N6 interface IP session between UPF124 and PDN120 (including, for example, identifying APP ID, user ID, content ID, and performing URL filtering) to apply security to user plane traffic based on policies (e.g., Layer 7 security and / or other security policy enforcement), as further described below.
[0077] In addition, the security platform 102 also provides cloud security services 122 (for example, WildFire, a commercially available cloud security service provided by Palo Alto Networks, which includes automated security analysis of malware samples and security expert analysis) via the internet. TM It can communicate with a network (commercial cloud-based security services, or similar solutions provided by other vendors, such as a cloud-based malware analysis environment, may be used). For example, cloud security service 122 may be used to provide the security platform with dynamic prevention signatures for malware, DNS, URL, CNC malware, and / or other malware, as well as to receive malware samples for further security analysis.
[0078] For example, the techniques described above can be used to enforce subscriber ID-based security via the N6 interface in a private 5G network and / or via the SGi interface in a private 4G / LTE network.
[0079] As another example, the techniques described above can be applied to identify and prevent known and unknown threats via the N6 interface in 5G networks and / or via the SGi interface in 4G / LTE networks.
[0080] As yet another example, the techniques described above can be used to apply application identification via the N6 interface in a 5G network and / or via the SGi interface in a 4G / LTE network.
[0081] As yet another example, the techniques described above can be used to apply URL filtering via the N6 interface in a 5G network and / or via the SGi interface in a 4G / LTE network.
[0082] Thus, service providers and / or enterprises can use the disclosed techniques and security platforms to enforce subscriber identity-based security across the boundaries of IP-based external networks (e.g., the Internet).
[0083] An exemplary system architecture for applying device ID-based security using user IDs and syslog messages in mobile networks.
[0084] Accordingly, in some embodiments, the disclosed technology is configured to provide DPI capabilities (e.g., including stateful inspection) of GTP-U sessions (e.g., GTP-U traffic) via various interfaces (e.g., RESTful API, N3, N6, and / or other interfaces in the 4G / 5G / 6G core network) to apply security to user plane traffic based on policies (e.g., Layer 7 security, and / or implementation of other security policies), as will be further described below. The security function / platform is implemented using a firewall (FW) / next-generation firewall (NGFW), a network sensor acting in place of a firewall, or, for example, Palo Alto Networks' PA Series Next Generation Firewall, Palo Alto Networks' VM Series Virtualization Next Generation Firewall, and Palo Alto Networks' CN Series Container Next Generation Firewall. This includes providing another (virtual) device / component (which may be similarly implemented and configured to perform the disclosed techniques) that can implement security policies using the disclosed techniques, such as PANOS running on a virtual / physical NGFW solution commercially available from Networks, or another security platform / NFGW.
[0085] As referred to herein, the International Mobile Equipment Identifier (IMEI) is defined in 3GPP TS 23.003, available at https: / / portal.3GPP.org / desktopmodules / Specifications / SpecificationDetails.aspx?specificationId=729. Mobile station equipment is uniquely identified by its IMEI or IMEISV. The IMEI is 15 digits long, and the IMEISV is 16 digits long (for example, these values consist only of decimal digits).
[0086] Furthermore, as also mentioned herein, in a 5G network environment, a Permanent Equipment Identifier (PEI) identifies the UE. According to 3GPP TS 23.003 v 16.9.0, the PEI type can represent an IMEI or IMEISV, a MAC address, or an IEEE Extended Unique Identifier (EUI-64).
[0087] In some embodiments, applying device ID (e.g., including IMEI and / or PEI)-based security using user IDs and syslog messages in a mobile network is similarly performed using a deployed security platform across SGi interfaces in 4G / LTE networks, as similarly described above with respect to Figures 1A and 1B, and / or across N6 interfaces in 5G networks, as similarly described above with respect to Figures 1C and 1D.
[0088] In one exemplary implementation, the disclosed technique for applying device ID-based security using user ID and syslog message networks in a mobile network can be performed using a security platform deployed in a 4G / LTE technology-based mobile network, as similarly shown in Figures 1A and 1B, except that the security platform (e.g., NGFW102) uses the N6 interface to obtain real-time syslog containing UE IP and IMEI information from PGW112 and SGW-U and PGW-U 116, respectively; and in a 5G technology-based mobile network, as similarly shown in Figures 1C and 1D, except that the security platform (e.g., NGFW102) uses the N6 interface to obtain real-time syslog containing UE IP and IMEI information from UPF124. Specifically, the mobile network has network capabilities that can generate syslog messages for predetermined events such as bearer creation and bearer deletion. These network capabilities may be configured to send syslog messages containing information about bearer creation and deletion events. A user ID agent within the security platform may be configured to parse these messages. For example, a user ID agent may be configured to parse create events to map user device (UE) IP addresses to device IDs, and also to parse delete events to remove old mappings. Removing old mappings is generally useful in mobile networks where IP address assignments may change, for example, when a UE is rebooted or during various other scenarios.Thus, in some embodiments, a syslog parsing profile is used to parse syslog messages in order to integrate with network functions from different equipment vendors that can send syslog messages in different formats (for example, a user can create a custom profile for each format).
[0089] Figure 2C is another exemplary screen view of an interface relating to a security platform on an SGi interface in L3 mode receiving syslog messages from a PGW in a 4G / LTE network, according to several embodiments. In this example, the PGW sends an event syslog (e.g., a syslog message) to the security platform (e.g., NGFW102) whenever a new default bearer is created or deleted. Each syslog contains different fields, key fields for highlighting: namely, event type, IMSI, IMEI, APN, and Ue_IP.
[0090] The following is an example syslog message generated by PGW.
[0091] Jan 9 09:13:10 {"pgw","type":"create_session","evt":{"imsi":"002002999971493","imei":"3526201120836534","apn":"apn2a6","user_addr":["172.16.15.101"]}}
[0092] The security platform (e.g., NGFW102) receives event syslog and creates user ID / IP mappings. The user ID may be configured as a UE IMEI, for example, "3526201120836534". A syslog event with "create_session" can be configured as a user ID login action, and "delete_session" can be used as a logout action.
[0093] Referring to Figure 2C, an illustrative screen diagram of the interface related to the security platform on the SGi interface in L3 mode, receiving syslog messages from the PGW in the 4G / LTE network, provides an example of a security policy configured using a user ID, with UE IMEI=“3526201120836534”.
[0094] For example, the techniques described above can be used to enforce device ID-based security via the N6 interface in a private 5G network and / or via the SGi interface in a private 4G / LTE network.
[0095] As another example, the techniques described above can be applied to identify and prevent known and unknown threats via the N6 interface in 5G networks and / or via the SGi interface in 4G / LTE networks.
[0096] As yet another example, the techniques described above can be used to apply application identification via the N6 interface in a 5G network and / or via the SGi interface in a 4G / LTE network.
[0097] As yet another example, the techniques described above can be used to apply URL filtering via the N6 interface in a 5G network and / or via the SGi interface in a 4G / LTE network.
[0098] Thus, service providers and / or enterprises can use the disclosed techniques and security platforms to enforce subscriber identity-based security across the boundaries of IP-based external networks (e.g., the Internet).
[0099] Exemplary system architecture for applying network slice ID-based security using user IDs and syslog messages in mobile networks
[0100] Accordingly, in some embodiments, the disclosed technology is configured to provide DPI capabilities (e.g., including stateful inspection) of GTP-U sessions (e.g., GTP-U traffic) via various interfaces (e.g., RESTful API, N3, N6, and / or other interfaces in the 4G / 5G / 6G core network) to apply security to user plane traffic based on policies (e.g., Layer 7 security, and / or implementation of other security policies), as will be further described below. The security function / platform is implemented using a firewall (FW) / next-generation firewall (NGFW), a network sensor acting in place of a firewall, or, for example, Palo Alto Networks' PA Series Next Generation Firewall, Palo Alto Networks' VM Series Virtualization Next Generation Firewall, and Palo Alto Networks' CN Series Container Next Generation Firewall. This includes providing another (virtual) device / component (which may be similarly implemented and configured to perform the disclosed techniques) that can implement security policies using the disclosed techniques, such as PANOS running on a virtual / physical NGFW solution commercially available from Networks, or another security platform / NFGW.
[0101] As will be described below, in some embodiments, network slice ID / S-NSSAI (SST+SD) based security is performed using a security platform (e.g., NGFW102) deployed on the N6 interface within the 5G network.
[0102] To identify network slices end-to-end, the 5G standard uses information called Single Network Slice Selection Assistance Information (S-NSSAI). S-NSSAI may contain both SST and SD fields (for example, in which case the S-NSSAI length is 32 bits in total), or SNSSAI may contain only the SST field (for example, in which case the S-NSSAI length is only 8 bits).
[0103] The Slice / Service Type (SST) field can have standardized and non-standardized values. Values from 0 to 127 belong to the standardized SST range and are defined in 3GPP TS 23.501. In accordance with the 5G standard, the following SSTs must be supported in all log types and security policies in the network slice column. SST values from 128 to 255 belong to the operator-specific range. The Slice Differentiator (SD) refers to optional information that complements the Slice / Service Type to distinguish between multiple network slices.
[0104] In some embodiments, applying network slice ID (e.g., S-NSSAI)-based security using user IDs and syslog messages in a mobile network is similarly performed using a security platform deployed across N6 interfaces in a 5G network, as similarly described above with respect to Figures 1C and 1D.
[0105] In one exemplary implementation, the disclosed technique for applying network slice ID-based security using user IDs and syslog message networks in a mobile network can be performed using a security platform deployed in a 5G technology-based mobile network, as similarly shown in Figures 1C and 1D, except that in this example, the security platform (e.g., NGFW102) uses an N6 interface to obtain real-time syslog containing UE IP and S-NSSAI information. Specifically, the mobile network has network capabilities that can generate syslog messages for predetermined events such as bearer creation and bearer deletion. These network capabilities may be configured to send syslog messages containing information about bearer creation and deletion events. A user ID agent within the security platform may be configured to parse these messages. For example, the user ID agent may be configured to parse creation events to map IP addresses (e.g., user equipment (UE) IP addresses) to network slice IDs, and also to parse deletion events to delete old mappings. Deleting outdated mappings is generally useful in mobile networks where IP address assignments may change, for example, when the UE is rebooted or during various other scenarios. Thus, in some embodiments, syslog parsing profiles are used to parse syslog messages in order to integrate with network functions from different equipment vendors that can send syslog messages in different formats (for example, a user can create custom profiles for each format).
[0106] Figure 2D is another exemplary screen view of an interface relating to a security platform on an N6 interface in L3 mode receiving syslog messages from a UPF in a 5G network, according to several embodiments. In this example, the UPF sends an event syslog (e.g., a syslog message) to the security platform (e.g., NGFW102) whenever a new PDU session is created or deleted. Each syslog contains different fields, key fields for highlighting: Event Type, IMSI, IMEI, DNN, S-NSSAI, and Ue_IP.
[0107] The following is an example syslog message generated by UPF.
[0108] Jan 14 11:23:04 {"upf","type":"create_pdu_session","evt":{"imsi":"312444555717000","imei":"4442 332341119898","dnn":"dnn1bc4","s-nssai":"1:1000","user_addr":["172.16.15.112"]}}
[0109] The security platform (e.g., NGFW102) receives event syslog and creates user ID / IP mappings. User IDs can be configured as S-NSSAI, for example, "1:1000". Syslog events with "create_session" can be configured as user ID login actions, and "delete_session" can be used as logout actions.
[0110] Referring to Figure 2D, the illustrative screen diagram of the interface related to the security platform on the N6 interface in L3 mode receiving syslog messages from the UPF within the 5G network provides an example of a security policy configured using a user ID, with UE IMEI=“1:1000”.
[0111] For example, the techniques described above can be used to enforce network slice ID-based security via the N6 interface in a private 5G network.
[0112] As another example, the techniques described above can be applied to identify and prevent known and unknown threats via the N6 interface in a 5G network.
[0113] As yet another example, the techniques described above can be used to apply application identification via the N6 interface in a 5G network.
[0114] As yet another example, the techniques described above can be used to apply URL filtering via the N6 interface in a 5G network.
[0115] Thus, service providers and / or enterprises can use the disclosed techniques and security platforms to enforce network slice identity-based security across the boundaries of IP-based external networks (e.g., the Internet).
[0116] Exemplary use cases for applying subscriber ID-based security, device ID-based security, and / or network slice ID-based security using user IDs and syslog messages in mobile networks.
[0117] The disclosed techniques for providing enhanced security for mobile / service provider networks using a security platform for security policy enforcement, including applying subscriber ID-based security, device ID-based security, and / or network slice ID-based security using user IDs and syslog messages in mobile networks, may be applied in various additional exemplary use case scenarios to promote enhanced security for mobile networks (e.g., 4G / 5G / 6G and later mobile networks), as will be described below with respect to various exemplary use cases.
[0118] As an exemplary use case for subscriber-based security using user identification and syslog messages in mobile networks, the following exemplary vulnerabilities may be detected and / or prevented for a group of enterprise 5G users using the aforementioned techniques to apply subscriber-based security using user identification and syslog messages in mobile networks, using a security platform for security policy enforcement: namely, (1) CVE-2021-30860: Apple Multiple Products Integer Overflow Vulnerability, (2) CVE-2022-22620L: Apple Safari Use-After-Free Vulnerability, (3) CVE-2022-22784: Zoom XMPP Stanza Smugling Vulnerability, and (4) CVE-2022-25235: Spring SecurityRegexRequestMatcher Authorization Bypass Vulnerability.
[0119] As an exemplary use case for device ID-based security using user identification and syslog messages in mobile networks, the following enhanced security actions can be performed using the aforementioned techniques to apply device ID-based security using user identification and syslog messages in mobile networks with a security platform for security policy enforcement: namely, (1) detecting infected devices in the 5G network and blocking or restricting their network access, and (2) applying application control to enterprise 5G devices (e.g., allowing only trusted applications to communicate with intelligent sensors connected to the 5G network in a smart factory). Specifically, the following exemplary vulnerabilities can be detected and / or prevented for a group of enterprise 5G users using the aforementioned techniques to apply device ID-based security using user identification and syslog messages in mobile networks with a security platform for security policy enforcement. These are (1) CVE-2022-25845: FastJson Desrialization Vulnerability, (2) CVE-2019-7671: Prima Systems FlexAir Cross-Site Scripting Vulnerability, (3) CVE-2019-7667: Prima Systems FlexAir Brute Force Information Disclosure Vulnerability, and (4) CVE-2021-23282: Eaton Intelligent Power Management Stored Cross-Site Scripting Vulnerability.
[0120] As an exemplary use case for network slice ID-based security using user identification and syslog messages in mobile networks, the following enhanced security actions can be performed using the aforementioned techniques to apply network slice ID-based security using user identification and syslog messages in mobile networks, using a security platform for security policy enforcement: namely, (1) investigating security events related to vertically related utilities for enterprise 5G customers of security services, and (2) enabling mobile network service providers to provide security bundled with 5G services to different enterprise customers. Specifically, the following exemplary spyware can be detected and / or prevented for a group of enterprise 5G users using the aforementioned techniques, which apply device ID-based security using user identification and syslog messages on mobile networks, using a security platform for security policy enforcement: namely, (1) Pingpull Command and Control Traffic, (2) APT34 Malicious Excel Downloader Traffic, (3) XANFPEZES Command and Control Traffic, and (4) Industroyer Command and Control Traffic.
[0121] As will now be apparent to those skilled in the art, the disclosed techniques for applying subscriber ID-based security, device ID-based security, and / or network slice ID-based security using user IDs and syslog messages with a security platform for enforcing security policies in mobile networks can be applied in a variety of additional exemplary use case scenarios to detect and prevent these and other types of attacks in order to promote enhanced security for various deployments and environments in mobile networks.
[0122] Exemplary hardware components for network devices that apply subscriber ID-based security, device ID-based security, and / or network slice ID-based security using user IDs and syslog messages in a mobile network.
[0123] Figure 3 is a functional diagram of hardware components relating to a network device for applying subscriber ID-based security, device ID-based security, and / or network slice ID-based security using user ID and syslog message networks in a mobile network, according to several embodiments. The embodiments shown are representations of physical / hardware components that may be included in the network device 300 (e.g., an appliance, gateway, or server that can implement the security platform disclosed herein). Specifically, the network device 300 includes a high-performance multi-core CPU 302 and RAM 304. The network device 300 also includes storage 310 (e.g., one or more hard disks or solid-state storage units) which may be used to store policies and other configuration information, as well as signatures. In one embodiment, storage 310 stores predetermined information (e.g., subscriber ID, device ID, and / or network slice ID, along with / extracted parameters related to user ID and syslog messages) extracted from traffic monitored via various interfaces (e.g., SGi, N6, and / or other interfaces), which is monitored to implement disclosed security policy enforcement techniques for applying context-based security via various interfaces, including techniques disclosed for applying subscriber ID-based security, device ID-based security, and / or network slice ID-based security using user ID and syslog messages in a mobile network using a security platform, as similarly described above with respect to Figures 1A to 1D and Figures 2A to 2D. The network device 300 may also include one or more arbitrary hardware accelerators.For example, the network device 300 may include a cryptographic engine 306 configured to perform encryption and decryption operations, and one or more FPGAs 308 configured to perform signature matching, function as a network processor, and / or perform other tasks.
[0124] Exemplary logical components relating to network devices for applying subscriber ID-based security, device ID-based security, and / or network slice ID-based security using user IDs and syslog messages in mobile networks.
[0125] Figure 4 is a functional diagram of logical components relating to a network device for applying subscriber ID-based security, device ID-based security, and / or network slice ID-based security using user IDs and syslog messages in a mobile network, according to several embodiments. The embodiments shown are representations of logical components that may be included in the network device 400 (e.g., a data appliance that implements the disclosed security functions / platform and can implement the disclosed techniques for applying subscriber ID-based security, device ID-based security, and / or network slice ID-based security using user IDs and syslog messages in a mobile network). As shown, the network device 400 includes a management plane 402 and a data plane 404. In one embodiment, the management plane is responsible for managing user interactions, such as configuring policies and providing a user interface for viewing log data. The data plane is responsible for managing data, such as performing packet processing and session processing.
[0126] Assume a mobile device attempts to access a resource (e.g., a remote website / server, MEC service, IoT device, or another resource) using an encrypted session protocol such as SSL. The network processor 406 is configured to monitor packets from the mobile device and provide the packets to the data plane 404 for processing. Flow 408 identifies the packet as part of a new session and creates a new session flow. Subsequent packets are identified as belonging to the session based on the flow lookup. Where applicable, SSL decryption is performed by the SSL decryption engine 410 using various techniques as described herein. Otherwise, processing by the SSL decryption engine 410 is omitted. The Application Identification (APP ID) module 412 is configured to determine what type of traffic a session involves (e.g., other network protocols of traffic, such as IP traffic and / or GTP-U traffic between various monitored interfaces, as similarly described above with respect to Figures 1A to 1D) and to identify the user associated with the traffic flow (e.g., to identify the User ID and Application ID (APP-ID) as described herein). For example, APP ID 412 may recognize a GET request in the received data and conclude that the session requires an HTTP decoder 414. As another example, APP ID 412 may recognize a GTP-U session message carrying encapsulated IP traffic from the UE (e.g., via various interfaces, as similarly described above with respect to Figures 1A to 1D) and conclude that the session requires a GTP-U decoder (e.g., to extract information exchanged in the GTP-U traffic session via various interfaces, including various parameters, as similarly described above with respect to Figures 1A to 1D and Figures 2A to 2D). For each type of protocol, there is a corresponding decoder 414.In one embodiment, application identification is performed by an application identification module (e.g., APP ID component / engine), and user identification is performed by another component / engine. Based on the decision made by APP ID 412, the packet is sent to the appropriate decoder 414. The decoder 414 is configured to assemble the packet (e.g., which may be received out of order) into the correct order, perform tokenization, and extract information (e.g., to extract various information exchanged in GTP-U traffic through various interfaces, as similarly described above and further described below). The decoder 414 also performs signature matching to determine what should happen to the packet. The SSL cryptography engine 416 performs SSL encryption using various techniques as described herein, and the packet is then forwarded using the forwarding component 418 as shown. Also, as illustrated, the policy 420 is received and stored in the management plane 402. In one embodiment, policy enforcement (for example, a policy may include one or more rules, which may be specified using a domain and / or host / server name, and the rules may apply one or more signatures, or other matching criteria, or heuristics, for security policy enforcement on subscriber / IP flows on a service provider network, based on various extracted parameters / information from monitored GTP-U / IP traffic and / or monitored GTP-U / IP and / or other protocol traffic, such as SGi / N6 / other interfaces as similarly described above with respect to Figures 1A to 1D) is monitored, decrypted, identified, and applied as described herein with respect to various embodiments, based on the session traffic flow.
[0127] As also shown in Figure 4, the interface (I / F) communicator 422 is also provided for security platform manager communications. In some cases, network communications of other network elements on the service provider network are monitored using the network device 400, and the data plane 404 supports decoding of such communications (for example, the network device 400, including the I / F communicator 422 and decoder 414, may be configured to monitor and / or communicate on a reference interface, such as SGi, N6, and / or other interfaces where wired and wireless network traffic flows reside). Thus, the network device 400, including the I / F communicator 422, may be used to implement the disclosed techniques for applying subscriber ID-based security, device ID-based security, and / or network slice ID-based security using user ID messages and syslog messages in a mobile network, as described above and further described below.
[0128] Additional exemplary processes for the disclosed techniques for applying subscriber ID-based security, device ID-based security, and / or network slice ID-based security using user IDs and syslog messages in mobile networks will be described below.
[0129] Exemplary processes for applying subscriber ID-based security, device ID-based security, and / or network slice ID-based security using user IDs and syslog messages in mobile networks.
[0130] Figure 5 is a flowchart relating to a process for applying subscriber ID-based security, device ID-based security, and / or network slice ID-based security using user IDs and syslog message networks in a mobile network, according to several embodiments. In some embodiments, the process 500 shown in Figure 5 is performed by security platforms and techniques similarly described above, including embodiments described with respect to Figures 1A to 4. In one embodiment, the process 500 is performed by the data appliance 300 described with respect to Figure 3, the network device 400 described with respect to Figure 4, virtual appliances (e.g., Palo Alto Networks' VM Series virtualized next-generation firewalls, CN Series container next-generation firewalls, and / or other commercially available virtual-based or container-based firewalls may be similarly implemented and configured to perform the techniques disclosed), SDN security solutions, cloud security services, and / or combinations or hybrid implementations of the foregoing as described herein.
[0131] In 502, monitoring of network traffic on the mobile network is performed on the security platform to identify new sessions. For example, the security platform (e.g., a firewall, a network sensor acting in place of a firewall, or another device / component that can implement security policies) can in some cases monitor various protocols on the mobile network, such as GTP-U (e.g., via SGi, N6, and / or other interfaces) and / or other protocols, and more specifically, by performing the disclosed techniques, it can monitor various interfaces, such as the SGi and N6 interfaces, as similarly described above with respect to Figures 1A to 1D.
[0132] In 504, the security platform uses a user ID agent to parse syslog messages, thereby extracting multiple parameters. For example, the same parameters described above can be extracted from Figures 1A to 1D and Figures 2A to 2D.
[0133] In 506, to enforce context-based security in a mobile network, the security platform enforces a security policy on new sessions based on one or more parameters, including one or more of the subscriber ID, device ID, and network slice ID. For example, the enforcement of a security policy may include allowing or blocking the session.
[0134] Figure 6 is another flowchart relating to a process for applying subscriber ID-based security, device ID-based security, and / or network slice ID-based security using user IDs and syslog message networks in a mobile network, according to several embodiments. In some embodiments, the process 600 shown in Figure 6 is performed by security platforms and techniques similarly described above, including embodiments described with respect to Figures 1A to 4. In one embodiment, the process 600 is performed by the data appliance 300 described with respect to Figure 3, the network device 400 described with respect to Figure 4, virtual appliances (e.g., Palo Alto Networks' VM Series virtualized next-generation firewalls, CN Series container next-generation firewalls, and / or other commercially available virtual-based or container-based firewalls may be similarly implemented and configured to perform the techniques disclosed), SDN security solutions, cloud security services, and / or combinations or hybrid implementations of the foregoing as described herein.
[0135] In 602, the security platform monitors network traffic on the mobile network to identify new sessions. For example, the security platform (e.g., a firewall, a network sensor acting in place of a firewall, or another device / component that can implement security policies) can, in some cases, monitor various protocols on the mobile network, such as GTP-U (e.g., via SGi, N6, and / or other interfaces), and / or other protocols, and more specifically, by performing the disclosed techniques, it can monitor various interfaces, such as the SGi and N6 interfaces, as similarly described above with respect to Figures 1A to 1D.
[0136] In 604, the security platform uses a user ID agent to parse syslog messages, thereby extracting multiple parameters. For example, the same parameters described above can be extracted from Figures 1A to 1D and Figures 2A to 2D.
[0137] In 606, the security platform selects a security policy to apply subscriber ID-based security, device ID-based security, and / or network slice ID-based security using user IDs and syslog messages. For example, the same parameters described above can be extracted with respect to Figures 1A to 1D and Figures 2A to 2D.
[0138] In 608, to enforce context-based security in a mobile network, the security platform enforces a security policy on new sessions based on one or more parameters, including one or more of the subscriber ID, device ID, and network slice ID. For example, the enforcement of a security policy may include allowing or blocking the session.
[0139] While the embodiments described above are explained in some detail for the purpose of clarifying understanding, the present invention is not limited to the details provided. Many alternative methods exist for carrying out the present invention. The disclosed embodiments are illustrative and not limiting.
Claims
1. A system including a processor and memory, The aforementioned processor, To identify new sessions, the security platform monitors network traffic, including syslog messages on the mobile network. In the security platform, the user ID agent is used to parse the syslog message and extract multiple parameters. In order to apply context-based security in the mobile network, the security platform implements a security policy for the new session based on one or more of the parameters, the one or more of which include a subscriber ID, a device ID, and a network slice ID. It is configured in such a way, The memory is coupled to the processor and configured to provide instructions to the processor. The aforementioned context-based security includes device ID-based security or network slice ID-based security. system.
2. The security platform is configured using multiple security policies for applying subscriber ID-based security, device ID-based security, and network slice ID-based security in the mobile network. The system according to claim 1.
3. The aforementioned processor further, The security platform is configured to receive the syslog messages from 4G network entities and / or 5G network entities. The system according to claim 1.
4. The aforementioned processor further, The security platform is configured to receive the syslog messages from the 4G network entity. The aforementioned mobile network is a private 4G network. The system according to claim 1.
5. The aforementioned processor further, The security platform is configured to receive the syslog message from the 5G network entity. The aforementioned mobile network is a private 5G network. The system according to claim 1.
6. The aforementioned processor further, In the security platform, the syslog message is received from the 4G network entity and / or the 5G network entity, Extract one or more parameters for performing subscriber ID-based security, device ID-based security, and / or network slice ID security. It is structured in such a way. The system according to claim 1.
7. The aforementioned processor further, The aforementioned mobile network is configured to identify and prevent threats, The system according to claim 1.
8. The aforementioned processor further, The aforementioned mobile network is configured to perform application identification and control. The system according to claim 1.
9. The aforementioned processor further, The mobile network is configured to perform URL filtering. The system according to claim 1.
10. The aforementioned processor further, Based on the aforementioned security policy, the system is configured to block the new session from accessing the resource. The system according to claim 1.
11. The aforementioned processor further, The new session is configured to allow access to resources based on the security policy. The system according to claim 1.
12. It is a method, This involves a step in the security platform to monitor network traffic, including syslog messages on the mobile network, and to identify new sessions. In the security platform, the steps include extracting multiple parameters by parsing the syslog message using a user ID agent, A step of implementing a security policy for the new session in the security platform based on one or more of the aforementioned parameters, wherein the one or more parameters include a subscriber ID, a device ID, and a network slice ID, and a step of applying context-based security in the mobile network. Includes, The aforementioned context-based security includes device ID-based security or network slice ID-based security. method.
13. The above method further, Based on the security policy, the steps include blocking the new session from accessing the resource, The method according to claim 12, including the method described in claim 12.
14. A computer program that includes multiple instructions, The computer program is stored in a non-temporary computer-readable storage medium, and when the processor executes the plurality of instructions, the computer... This involves a step in the security platform to monitor network traffic, including syslog messages on the mobile network, and to identify new sessions. In the security platform, the steps include extracting multiple parameters by parsing the syslog message using a user ID agent, A step of implementing a security policy for the new session in the security platform based on one or more of the aforementioned parameters, wherein the one or more parameters include a subscriber ID, a device ID, and a network slice ID, and a step of applying context-based security in the mobile network. They will implement this, The aforementioned context-based security includes device ID-based security or network slice ID-based security. Computer program.
Citation Information
Patent Citations
Session information management method and session information management apparatus
JP2005110302A
Multi-access distributed edge security in mobile networks
JP2021513299A
Cellular internet of things battery drain prevention in mobile networks
US20210099487A1
Securing control and user plane separation in mobile networks
US20210409375A1
Security for cellular internet of things in mobile networks based on subscriber identity and application identifier
US20220201046A1