In the rapidly evolving landscape of telecommunications, the integration of commercial 5G solutions and the rise of edge computing have reshaped service delivery, emphasizing the customization of requirements through network slices. However, the heterogeneity of devices and technologies in 5G and beyond networks poses significant challenges, particularly in terms of security management. Addressing this complexity, our work adopts the Zero-touch network and Service Management (ZSM) reference architecture to enable end-to-end automation of security and service management in Beyond 5G networks. This paper introduces the ZSM-based framework, which harnesses software-defined networking, network function virtualization, end-to-end slicing, and orchestration paradigms to autonomously enforce and preserve security service level agreements (SSLAs) across multiple domains that make up a 5G network. The framework autonomously manages end-to-end security slices through intent-driven closed loops at various logical levels, ensuring compliance with ETSI end-to-end network slice management standards for 5G communication services. The paper elaborates with an SSLA-triggered use case comprising two phases: proactive, wherein the framework deploys and configures an end-to-end security slice tailored to the security service level agreement specifications, and reactive, where machine learning-trained security mechanisms autonomously detect and mitigate novel beyond 5G attacks exploiting open-sourced 5G core threat vectors. Finally, the results of the implementation and validation are presented, demonstrating the practical application of this research. Interestingly, these research results have been integrated into the ETSI ZSM Proof of Concept #6: ’Security SLA Assurance in 5G Network Slices’, highlighting the relevance and impact of the study in the real world.
Although the softwarization of network infrastructures through the use of Software Defined Networking (SDN) and Network Function Virtualization (NFV) has set the foundations of future communication architectures, the efficient handling of high throughput traffic while maintaining latency requirements still remains a challenge. In this work, we explore two arising technologies that aim at reducing networking tasks’ latency while dealing with high levels of traffic volume, namely, Programming Protocol-independent Packet Processors (P4) and the extended Berkeley Packet Filter (eBPF). We present a review of the latest advances in the use of both technologies and we provide a discussion on their advantages and disadvantages. As the main contribution of the paper, we showcase an extensive performance evaluation of these technologies under different traffic conditions. To do so, we implement a fast traffic processing network function operating in a real 5G Stand Alone (SA) network. Obtained results confirm, as expected, the high performance attained using dedicated hardware programmed by P4, in contrast to eBPF-based solution’s poorer results while handling similar throughputs. Nevertheless, eBPF allows similar packet-processing times than P4, therefore qualifying it as a perfectly scalable solution on commodity hardware even as a virtual function, which paves the way for the realization of autonomous, flexible and cost-effective next-generation network infrastructures.
Research on vehicle-to-everything (V2X) is attracting significant attention nowadays, driven by the recent advances in beyond-5G (B5G) networks and the multi-access edge computing (MEC) paradigm. However, the inherent heterogeneity of B5G combined with the security vulnerabilities of MEC infrastructure in dynamic V2X scenarios introduces unprecedented challenges. Efficient resource and security management in multi-domain V2X environments is vital, especially with the growing threat of distributed denial-of-service (DDoS) attacks against critical V2X services within MEC. Our approach employs the zero-touch network and service management (ZSM) standard, integrating autonomous security into end-to-end (E2E) slicing management. We consider an entire 5G network, including vehicular user equipment, radio access networks, MEC, and core components, in the presence of DDoS targeting V2X services. Our framework complies with security service-level agreements (SSLAs) and policies, autonomously deploying and interconnecting security sub-slices across domains. Security requirements are continuously monitored and, upon DDoS detection, our framework reacts with a coordinated E2E strategy. The strategy mitigates DDoS at the MEC and deploys countermeasures in neighboring domains. Performance assessment reveals effective DDoS detection and mitigation with low latency, aligned with the mission-critical nature of certain V2X services. This work is part of ETSI ZSM PoC “security SLA assurance in 5G network slices”.
The utilization of IP over wavelength division multiplexing (IPoWDM) boxes in optical networks introduces coordination issues at the control plane level between the optical and packet domains. Indeed, IPoWDM boxes are technically packet devices, but the configuration of coherent optical pluggables requires knowledge of optical network state information (e.g., wavelength availability). MANTRA (metaverse ready architectures for open transport) aims to define a new SDN control architecture for managing IPoWDM, enhancing coordination between the packet and optical controllers. Within MANTRA, two distinct architectures were presented: Dual and Single. However, only the roles related to controller management are defined, while clear procedures are not specified for dealing with resource provisioning and failure recovery. This leads to the need for the definition and implementation of tailored procedures. Besides the characterization of the coherent optical pluggables performance, this paper presents and compares three procedures based on MANTRA to coordinate and control IPoWDM nodes in a multi-layer network performing failure recovery. The considered solutions have been designed and experimentally validated with a focus on the achievable traffic recovery performance considering IPoWDM configuration and communication within the SDN control architecture. An experimental testbed, comprising a sliced IPoWDM node running an extended version of the open-source SONiC network operating system, has been deployed to validate these solutions, with a comprehensive analysis of the time required to recover a real traffic flow that spans both the packet and optical domains.
As 5th Generation (5G) and Beyond 5G (B5G) networks become increasingly prevalent, ensuring not only network security but also the security and reliability of the applications, the so-called network applications, becomes of paramount importance. This paper introduces a novel integrated model architecture, combining a network application validation framework with an AI-driven reactive system to enhance security in real-time. The proposed model leverages machine learning (ML) and artificial intelligence (AI) to dynamically monitor and respond to security threats, effectively mitigating potential risks before they impact the network infrastructure. This dual approach not only validates the functionality and performance of network applications before their real deployment but also enhances the network's ability to adapt and respond to threats as they arise. The implementation of this model, in the shape of an architecture deployed in two distinct sites, demonstrates its practical viability and effectiveness. Integrating application validation with proactive threat detection and response, the proposed model addresses critical security challenges unique to 5G infrastructures. This paper details the model, architecture's design, implementation, and evaluation of this solution, illustrating its potential to improve network security management in 5G environments significantly. Our findings highlight the architecture's capability to ensure both the operational integrity of network applications and the security of the underlying infrastructure, presenting a significant advancement in network security.
Download This Paper Open PDF in Browser Add Paper to My Library Share: Permalink Using these links will ensure access to this page indefinitely Copy URL Copy DOI
A great lack of 5G design is the traditional bottom-up development of network evolution, which has not effectively considered the requirements of applications and, particularly, vehicle to everything (V2X) applications. This paper provides a service-centric approach towards 6G V2X, with a concise overview of the upcoming hyper-connected vehicular ecosystem and its integration in the whole 6G fabric, analysing its particular infrastructure needs, as a way to reach key performance indicators (KPIs). We also present a 6G-oriented platform design able to manage the life-cycle of V2X applications across different domains by means of intelligent orchestration decisions.
Smart-campuses are an emerging ecosystem that permit to enhance the performance and efficiency of academic facilities. Besides, they are also adopted as research, development, and testing platforms for the integration of novel management and governance mechanisms in complex ICT infrastructures. In this line, they are considered as small smart-city-like scenarios which can be used as a playground prior to large-scale deployments. This work presents the GAIA 5G smart-campus, located in the Espinardo campus of the University of Murcia (Spain). In the first place, its technological architecture is presented, detailing the multi-access platform that provides 5G, Internet of Things (IoT), and vehicular communications connectivity. Also, the virtualized computation environment is described. Thanks to these two pillars, GAIA 5G has the potential to host diverse use cases in multiple verticals, such as 5G connectivity, Network Function Virtualization (NFV) management and orchestration, or cybersecurity, which are also described. As discussed along the paper, GAIA 5G is an operative smart-campus infrastructure ready to support state-of-the-art research and accommodate novel 5Gand-beyond (B5G) test cases.
This demo presents a comprehensive framework exploiting effective cooperation of packet-optical nodes, at the edge of packet and optical domains, managed by the BGP and OSPF protocols and a Hierarchical Control Architecture. The framework enables orchestrated provisioning and soft failure recovery across a multi-layer metro network.
Background Gene set enrichment analysis (detecting phenotypic terms that emerge as significant in a set of genes) plays an important role in bioinformatics focused on diseases of genetic basis. To facilitate phenotype-oriented gene set analysis, we developed PhenoExam, a freely available R package for tool developers and a web interface for users, which performs: (1) phenotype and disease enrichment analysis on a gene set; (2) measures statistically significant phenotype similarities between gene sets and (3) detects significant differential phenotypes or disease terms across different databases. Results PhenoExam generates sensitive and accurate phenotype enrichment analyses. It is also effective in segregating gene sets or Mendelian diseases with very similar phenotypes. We tested the tool with two similar diseases (Parkinson and dystonia), to show phenotype-level similarities but also potentially interesting differences. Moreover, we used PhenoExam to validate computationally predicted new genes potentially associated with epilepsy. Conclusions We developed PhenoExam, a freely available R package and Web application, which performs phenotype enrichment and disease enrichment analysis on gene set G, measures statistically significant phenotype similarities between pairs of gene sets G and G′ and detects statistically significant exclusive phenotypes or disease terms, across different databases. We proved with simulations and real cases that it is useful to distinguish between gene sets or diseases with very similar phenotypes. Github R package URL is https://github.com/alexcis95/PhenoExam . Shiny App URL is https://alejandrocisterna.shinyapps.io/phenoexamweb/ .
5G mobile communications are bringing a plethora of applications that are challenging existing network infrastructures. These services demand a dynamic, flexible and adaptive infrastructure capable of fulfilling the rigorous requirements they need to operate correctly. Another key point is the need of real-time reactions in the architecture configurations to effectively satisfy changes in the user's behavior. To address these issues, Network Function Virtualization (NFV) and Software-Defined Networking (SDN) paradigms arise as enablers of the network infrastructures of the future. These technologies will permit the design and development of a new set of network applications that will be dynamically managed and orchestrated over multiple domains in an effortless way. In this work, we present an architecture that interconnects two facilities located in Spain and Japan, which permits the deployment of distributed applications. Besides, we detail how the control and data planes are managed to enable the operation of the system.
Although the government issued electronic identities (eID) in Europe appeared more than 20 years ago, their adoption so far has been very low. This is even more the case in cross-border settings, where private service providers (SP) from one EU Member State needs trusted eID services from identity provider located in another state. LEPS project aims to validate and facilitate the connectivity options to recently established eIDAS ecosystem, which provides this trusted environment with legal, organisational and technical guarantees already in place. Strategies have been devised to reduce SP implementation costs for this connectivity to eIDAS technical infrastructure. Based on the strategy, architectural options and implementation details have been worked out. Finally, actual integration and validation have been done in two countries: Spain and Greece. In parallel, market analysis and further options are considered both for LEPS project results and for e-IDAS compliant eID services.
One great challenge of modern networks is how to select paths and react to highly variable and demanding traffic patterns. In recent years, emerging networking languages and architectures, such as P4/PISA, have created unprecedented opportunities for rapidly prototyping disruptive solutions in programmable data planes. In this direction, source routing (SR) is a prominent alternative to conventional table-based routing, since it reduces the convergence time of building distributed routing tables. In particular, PolKA explores the polynomial residue number system (RNS) for a fully stateless SR, i.e., no state update on packet headers needs to be conveyed along the route. This paper reports the deployment of PolKA in a continental testbed composed of P4 programmable switches. Results for end-to-end throughput and forwarding latency show that PolKA matches the data plane performance of traditional approaches, while paving the way for further innovative applications by exploring RNS properties in dynamic scenarios.
Gene set based phenotype enrichment analysis (detecting phenotypic terms that emerge as significant in a set of genes) can improve the rate of genetic diagnoses amongst other research purposes. To facilitate diverse phenotype analysis, we developed PhenoExam, a freely available R package for tool developers and a web interface for users, which performs: (1) phenotype and disease enrichment analysis on a gene set; (2) measures statistically significant phenotype similarities between gene sets and (3) detects significant differential phenotypes or disease terms across different databases. PhenoExam achieves these tasks by integrating databases or resources such as the HPO, MGD, CRISPRbrain, CTD, ClinGen, CGI, OrphaNET, UniProt, PsyGeNET, and Genomics England Panel App. PhenoExam accepts both human and mouse genes as input. We developed PhenoExam to assist a variety of users, including clinicians, computational biologists and geneticists. It can be used to support the validation of new gene-to-disease discoveries, and in the detection of differential phenotypes between two gene sets (a phenotype linked to one of the gene set but no to the other) that are useful for differential diagnosis and to improve genetic panels. We validated PhenoExam performance through simulations and its application to real cases. We demonstrate that PhenoExam is effective in distinguishing gene sets or Mendelian diseases with very similar phenotypes through projecting the disease-causing genes into their annotation-based phenotypic spaces. We also tested the tool with early onset Parkinson’s disease and dystonia genes, to show phenotype-level similarities but also potentially interesting differences. More specifically, we used PhenoExam to validate computationally predicted new genes potentially associated with epilepsy. Therefore, PhenoExam effectively discovers links between phenotypic terms across annotation databases through effective integration. The R package is available at https://github.com/alexcis95/PhenoExam and the Web tool is accessible at https://snca.atica.um.es/PhenoExamWeb/.
5G improves previous generations not only in terms of radio access but the whole infrastructure and services paradigm. Automation, dynamism and orchestration are now key features that allow modifying network behaviour, such as Virtual Network Functions (VNFs), and resource allocation reactively and on demand. However, such dynamic ecosystem must pay special attention to security while ensuring that the system actions are trustworthy and reliable. To this aim, this paper introduces the integration of the Manufacturer Usage Description (MUD) standard alongside a Trust and Reputation Manager (TRM) into the INSPIRE-5GPlus framework, enforcing security properties defined by MUD files while the whole infrastructure, virtual and physical, as well as security metrics are continuously audited to compute trust and reputation values. These values are later fed to enhance trustworthiness on the zero-touch decision making such as the ones orchestrating end-to-end security in a closed-loop.
The importance of HTTP in today's networks isundisputed. As a solution to enhance QoS and enhance scalability CDN networks have been designed and deployed. Recently, anew paradigm known as ICN has been envisioned focusing the network routing on the content itself instead of the geographical attachment of addresses. Software Defined Networkings (SDNs) have been researched for the last 10 years as enablers of FutureInternet (FI) architectures in general and of ICN in particular. We have already proposed the Information Centric Network as a Service (ICNaaS) architecture to provide with end-to-endHTTP ICN alike transmission with HTTP in-network caching which has been thoroughly evaluated in this paper. This paper also proposes a nouveau mechanism, which we have named prefetching mechanism, to enhance data transmission rates for first requesters that can usually not benefit from previous access to the same content. To evaluate and demonstrate the possibilities offered by the proposal H.264/SVC video streaming with DASH has been employed.
More and more people are concerned about data privacy and this is applicable to vehicular scenarios in which onboard units (OBU) and user devices are exposed to traceability across different access networks and service domains. General Data Protection Regulation (GDPR) in European countries indicates the way to proceed to guarantee privacy and access to sensitive data, however, applying these laws is not straightforward and may vary from country to country. Last advances in 5G communications, such as virtualisation and Multi-Access Edge Computing (MEC) can enable the proper management of data considering local GDPR regulations by using edge services. In this paper we propose the treatment of personal data in virtual OBUs (vOBU) instantiated at the edge of the network on the move. This way, vehicles and occupants benefit from GDPR guarantees compliant with current country regulations as they move across European borders.
main functional blocks and their role in enabling intelligent closed-loop security operations. To illustrate how the INSPIRE-5Gplus framework can be applied as a zero-touch security management solution for 5G systems, the White Paper presents a representative set of advanced security use cases. The presented use cases cover different advanced security problems, including: (i) trustworthy composition of network slices using Blockchains (DLT) and secure deployment of E2E network slices in compliance with agreed SSLAs for automotive verticals; (ii) detection of network attacks over encrypted traffic in Service-Based Architectures; (iii) enforcement of E2E encryption policies while leveraging TEE to enable trustworthy execution of encryption-decryption operations; (iv) reactive and proactive protection of E2E network slices using, respectively, anomaly detection and Moving Target Defense mechanisms.
This demo presents the instantiation of a high level architecture proposed by INSPIRE-5Gplus to manage secured End-to-End (E2E) Network Slices. Network Slices are associated with Security Service Level Agreement (SSLA) to enhance the security on the virtual deployed resources, thus securing the created E2E Secure Network Slices. The proposed secured network slicing architecture is validated against a vehicular scenario, based on Anticipated Cooperative Collision Avoidance use case. In this scenario, we propose to detect false vehicular messages through a novel SSLA based on an Intrusion Detection System. The demo provides measurement of significant metrics such as mean time to detect, mean time to contain, and transaction speed.
Afrodite Sevasti合作论文数Network Services Development at the Greek Research and Technology Network (GRNET) S.A.3