5GC-SDP: Security Enhancement of 5G Core Networks with Zero Trust

Zeqing Yan,Guangxi Yu,Mengqi Zhan,Yan Zhang,Jiaxi Hu
DOI: https://doi.org/10.1109/cscwd61410.2024.10580371
2024-01-01
Abstract:The 5G core network (5GC) architecture based on Service-Based Architecture (SBA) has brought unprecedented flexibility and innovation. However, this architecture also comes with potential security challenges. The integration of different signaling protocols and the complexity of virtualization in 5GC have increased security risks within the core network. The concept of zero trust is considered a new solution, and Software-Defined Perimeter (SDP) represents a best practice for zero trust. In this paper, we propose a 5GC-SDP architecture that provides secure communication within the core network through authentication-based methods. Single Package Authorization (SPA) is the key technology of this study. Only Network Functions (NF) that have been authenticated and authorized by SPA can access each other. To the best of our knowledge, this is the first study to combine SDP with StandAlone (SA) 5GC. At the same time, we fully consider that although SPA technology can withstand most DoS attacks, DoS attacks caused by SPA packets will still become a problem. Therefore, we design a SPA enhancement module, and machine learning algorithms are used for SPA-DoS detection. We have conducted practical exploration on the proposed 5GC-SDP architecture and implemented testing on port scanning, DoS, and DDoS attacks. The experiments have shown that 5GC-SDP achieves enhanced protection of the core network by limiting network exposure and implementing fine-grained access control.
What problem does this paper attempt to address?