5G云基础设施安全指南第I部分20211028-13页_416kb
报告摘要
5G Cloud Security Guidance Summary
Core Content
This document provides guidance on securing 5G cloud infrastructures with a focus on preventing and detecting lateral movement. It is part of a four-part series developed by the Enduring Security Framework (ESF) in collaboration with government and industry experts. The guidance is based on the Potential Threat Vectors to 5G Infrastructure white paper, and it supports the May 2021 Presidential Executive Order on Improving the Nation's Cybersecurity.
The primary objective is to help service providers, system integrators, core network equipment vendors, cloud service providers, and mobile network operators (MNOs) build and maintain hardened 5G cloud environments. It emphasizes the Zero Trust security model, which assumes that no entity inside or outside the network can be trusted without verification.
Main Recommendations
1. Implement Secure Identity and Access Management (IdAM)
- Assign unique identities to all elements and interfaces in the 5G network.
- Ensure authentication and authorization for all resource access (e.g., API, CLI).
- Use X.509 certificates from a trusted CA instead of username/passwords where possible.
- Enable multi-factor authentication (MFA) if passwords are necessary.
- Use automated credential management and certificate pinning to enhance security.
- Log all access to resources, including time, resource, requesting entity, location, and access result.
- Deploy analytics to detect potentially malicious access patterns.
2. Keep 5G Cloud Software Up-to-Date
- Patch publicly known vulnerabilities as quickly as possible (ideally within 15 days for critical, 60 days for others).
- Monitor third-party applications and libraries for reported vulnerabilities.
- Integrate source code scanning and patching into the software development and deployment lifecycle.
- Maintain secure software development practices to reduce the risk of exploitation.
3. Securely Configure Networking
- Create security groups per Kubernetes Pod to manage network compliance.
- Use private networking for microservices/network functions.
- Configure default firewall rules and ACLs to block unnecessary inbound and outbound connections.
- Leverage Kubernetes Network Policies for granular control.
- Use Service Meshes to provide end-to-end encryption and authentication for node-to-node traffic.
4. Lock Down Communications Among Isolated Network Functions
- Ensure secure authentication for all communication sessions across the control, user, and management planes.
- Use mutually-authenticated TLS v1.2+ with X.509 certificates for identity verification.
- Enforce policies that separate network resources within the same security group based on secure authorization.
5. Monitor for Adversarial Lateral Movement
- Continuously monitor for signs of exploitation and lateral movement.
- Look for unusual scanning behaviors, unexpected port openings, and anomalous user behavior (e.g., atypical usage times or types).
- Monitor Pod/container logging for unexpected system calls.
- Use machine learning and AI-enabled security auditing to detect anomalies that may indicate new or unanticipated threats.
Key Information
- Lateral movement is a significant risk in 5G cloud environments due to the increased use of virtualization and containerization.
- Zero Trust is a core principle in securing 5G cloud infrastructures, requiring explicit verification and continuous monitoring of all network activities.
- The guidance is applicable to cloud providers, MNOs, and customers.
- The series includes four parts:
- Prevent and Detect Lateral Movement
- Securely Isolate Network Resources
- Protect Data in Transit, In-Use, and at Rest
- Ensure Integrity of Infrastructure
Conclusion
Securing 5G cloud infrastructures against lateral movement is a shared responsibility among cloud providers, network operators, MNOs, and customers. The guidance provided in this part of the series, along with the others, aims to harden 5G cloud environments by implementing secure IdAM, up-to-date software, secure networking configurations, restricted communication paths, and continuous monitoring and analytics. These measures support the broader goal of building a more resilient and secure 5G network.
试读结束,高清完整版pdf/doc/ppt,请点下载