• Home
  • Nieuws
  • Programma 2022
  • Exposanten
  • Plattegrond 2022
  • Locatie QuTech/TU Delft
  • Micro Nano Symposium
  • Account
    • Login
  • Login
  • Zoeken

RF Technology

RF, HF, Radio Frequent, Hoog Frequent

Testing Times: Automation Is the Key to a Secure 5G Future

Testing Times: Automation Is the Key to a Secure 5G Future

13 juli 2022 door C.N. Rood

Automated security testing of the 5G control plane is a critical step in reducing network vulnerabilities.

In previous times, the cellular network was considered pretty secure. Essentially, it was an almost closed-loop environment based on a few vendors with highly proprietary systems; instances of hacking or attacks against carriers are almost impossible to find referenced within the news media. There are likely to have been several attempts over the years, but quantifiable breaches are like unicorns – they may not exist.

But things are changing. The arrival of 5G heralds not just more bandwidth and lower latency, but also a fundamental shift in how cellular networks are designed, operated, and interconnected with the wider world of ICT. Most operators are embracing expansive designs that utilize more vendors within software-defined and cloud-centric architecture. The exciting potential offered by 5G includes intelligent smart city applications, private enterprise 5G networks, and even the growing use of 5G to replace traditional emergency services radio networks.

Because of this increasingly open and flexible approach, cellular networks have become more exposed to potential bad actors. Within network security practices, most of the attention has focused on attacks through the user plane (or data plane), which carries the network traffic, but there also needs to be consideration on securing the control plane, which carries critical signalling traffic. The industry is recognizing the potential vulnerabilities and coalescing around agreed upon best practice counter measures.

Standard bearer

3GPP is at the heart of this push through several initiatives. At the top of the pyramid is the Network Equipment Security Assurance Scheme (NESAS), which defines security requirements and an assessment framework for secure product development and product lifecycle processes, as well as 3GPP-defined test cases for the security evaluation of network equipment.

This leads to the 3GPP Security Assurance Methodology (SECAM), which is developed from a purely industrial perspective, with a focus on the security of the Common Criteria (CC) and Common Criteria Recognition Arrangement (CCRA) framework and its implementation in the mobile network.

At the node level, we have the 5G Security Assurance Specification (SCAS) that defines security requirements and test cases for network equipment implementing one or more 3GPP network functions. This is the point where we need to run specific tests across elements including Access Mobility Management Functions (AMF), User Plane Functions (UPF), Session Management Functions (SMF), and many others. The nodes go through a series of tests based on the specification that include key elements such as vulnerability, compliance, and application testing.

Automation with CI/CD

However, this is not just a fire and forget process. The high frequency of updates and larger number of vendors means that the sedate pace of change found in 3G and 4G networks - where updates might be considered every few months - is instead replaced with a constant drumbeat of weekly or even daily changes.

This has made it essential for this NESAS, SECAM, and SCAS secure process chain to become both continuous and highly automated. This shift has been a focus of the development teams at Spirent. The 5G Core Security Automation Package, which just launched this month, is an addition to their industry-first subscription-based 5G Core Automation Platform – a wrap-around and end-to-end testing solution that is fully compliant with 3GPP testing methodologies. The new package is essentially a continually updated security test library that grows in step with the ongoing revisions and additions to the underlying SCAS specification.

Spirent has also gone further through the inclusion of security attack emulation tests for threats such as Distributed Denial of Service (DDoS) and Man-in-the-Middle (MITM) attacks.

Feedback for the 5G Core Automation Platform has been extremely positive, with one of the highlights being that the implementation can be dropped seamlessly into the continuous integration and continuous deployment (CI/CD) workflows that are becoming critical for effectively delivering 5G to market.

Automation is a major time saver when it comes to comprehensive testing. In theory, SCAS testing could be carried out manually, but automation is an order of magnitude more efficient and a critical piece of the CI/CD lifecycle – a must to maintain performance and functionality with the rapid pace of change in network updates. From day one with the 5G Core Automation Platform, customers benefit from a large (and growing) base of fully automated, ready-to-use test cases that captures years of expertise in 5G, automation, and security. This results in 80% cost savings and 60% improvement in time to market.

The last point to mention is that operators we speak to genuinely accept that security needs to be taken extremely seriously. Especially as 5G starts to become a critical infrastructure – for example as the backbone for running first responder communication, CCTV, or as part of autonomous vehicles’ design. The impact of a security breach that took down an entire network would be catastrophic to governments, consumers, and ultimately the reputation of the operator – and trust in 5G.

5G is a game changer for our industry and our wider society. Making sure it’s secure as it can possibly be might well become the most important element of turning the potential into a welcomed reality.

Contact CN Rood for more information!

  • Facebook Facebook
  • Twitter Twitter
  • LinkedIn LinkedIn

Gerelateerd:

  • Laird OptoTEC™ OTX/HTX-serie Laird OptoTEC™ OTX/HTX-serie
  • Nieuwe hoogrendementsventilatoren van ADDA Nieuwe hoogrendementsventilatoren van ADDA
  • Nieuwe TECHNOMET 10,5 Nieuwe TECHNOMET 10,5" geavanceerde desktop/draagbare rack-behuizingen
  • Superieure warmtegeleiding, zacht voor componenten Superieure warmtegeleiding, zacht voor componenten
Facebook LinkedIn Twitter
Email: info@cnrood.com
Website: http://cnrood.com

C.N. Rood

Degelijk.  Betrouwbaar. Kennispartner.

C.N. Rood is koploper in kennis en oplossingen op het gebied van test- en meetapparatuur. We onderscheiden ons met een persoonlijke en klantgerichte aanpak. Onze klanten zoeken vaak niet een product, maar een oplossing en wij hebben allemaal de gedrevenheid om mee te werken aan die oplossing. Wat wij het liefste doen: continu bezig zijn met de nieuwste ontwikkelingen op het gebied van test- en meetapparatuur. Nu, en in de toekomst. Want daar ligt nu eenmaal onze passie: het precies willen weten. Zo kunnen we onze klanten optimaal verder helpen.

Wij denken mee, adviseren en begeleiden onze klanten in het maken van de juiste keuze in hun test- en meetapparatuur. Mensen in verschillende sectoren vertrouwen op onze expertise en ons advies. We werken voor overheid, wetenschap, onderwijs, lucht- en ruimtevaart- en auto-industrie in Noord-Europa en de Benelux. Daaronder bevinden zich vele prestigieuze en vooraanstaande organisaties. Vanuit vestigingen in Stockholm (Zweden), Zoetermeer (Nederland) en Zellik (België) werken meer dan veertig toegewijde professionals aan oplossingen variërend van communicatie-testapparatuur en algemene test- en meetinstrumenten tot apparatuur voor data-acquisitie, logistieke automatisering, aangevuld met consultancy, training en turnkeyoplossingen.

We hebben een historie die teruggaat tot 1938. Onze oprichter, Cornelis Nicolaas Rood, was destijds een pionier in moderne elektronica. Onze mensen bevinden zich ook anno 2021 graag in de frontlinie van technologische ontwikkelingen. Op onze eigen manier leveren we zo een bijdrage aan belangrijke maatschappelijke vraagstukken. Bijvoorbeeld in energietransitie, quantum computing, medische technologie, de zelfrijdende auto, de auto op zonne-energie en alle andere deeptech die bijdraagt aan de schonere en betere wereld van morgen.

Daarom letten we ook op onze eigen impact op het milieu en klimaat. Aangezien wij vooral een adviserende functie hebben is onze eigen milieu-footprint gering. Vanzelfsprekend zien we wel toe op een zo duurzaam mogelijke productie van de apparatuur die wij verkopen en zorgen we voor een maatschappelijk verantwoorde bedrijfsvoering. Al onze producten kopen we uitsluitend in bij gecertificeerde fabrikanten die werken met herleidbare en verantwoorde grondstoffen. Gebruikte apparatuur wordt kosteloos opgehaald en gerecycled.

Het zijn maar een paar voorbeelden om duidelijk te maken dat we hechten aan een langetermijnvisie op de wereld om ons heen. Want juist met een geschiedenis van meer dan tachtig jaar kun je goed vooruitkijken. Daarom blijven we ook vooroplopen. Onze brede en diepe technische kennis van test- en meetapparatuur, in combinatie met onze persoonlijke connectie met onze klanten, maken ons uniek in de markt. C.N. Rood is uw degelijke en betrouwbare kennispartner voor test- en meetapparatuur!

-----

Dependable. Reliable. Knowledge Partner.

C.N. Rood is a leader in knowledge and solutions in the field of test and measurement equipment. Since 1938 we distinguish ourselves with a personal and customer-oriented approach. We think along with, advise and assist our customers in making the right choice in their test and measurement equipment. Amongst others we work for government, science, education, aerospace and automotive industries in Northern Europe and the Benelux. From offices in Stockholm (Sweden), Zoetermeer (Netherlands) and Zellik (Belgium), more than forty dedicated professionals work on solutions ranging from communication test equipment and general test and measurement instruments to equipment for data acquisition, logistics automation, complemented by consultancy, training and turnkey solutions.

Laatste nieuws

  • New 4-Channel 1000 X-Series Oscilloscope (prices start at less than € 900)
  • Examples of great IoT ideas that turns into customer success
  • Vijf aandachtspunten bij keuze van een draagbare warmtebeeldcamera
  • Uitleg over veelgebruikte antenne technologie (gelezen in Elektronica)
  • Characterize antenna pattern in under a second

Privacy statement
Disclaimer
Cookies

Copyright © 2022 · Onderdeel van FHI ·