AdaptiveMobile has identified a vulnerability in the of the Network Slicing mechanism implementation, which could disclose information about arbitrary network segments or cause a denial of service. The vulnerability was assigned the CVD-2021-0047 number. Federal Service for Technology and Export Control (FSTEC of Russia) introduced vulnerability to the bank of threats and determined the level of danger as medium. One of the trends for this vulnerability elimination in the 6G networks is formulation of the classification principles and filtering of the 6G transport network traffic for effective application of the Network Slicing mechanism.
The basic principles of collecting, filtering and traffic classification of the data transmission network are as follows:
- Traffic filtering and classification is based on the analysis of the header fields of the data protocol units of L2 — L4 levels;
- Each consumer and operator data protocol unit (PDU) should be subjected to filtering and classification;
- The filter along with the the classifier represent a combination of certain fields of the header of the L2-L4 level PDU with ranges indication of their possible values;
- The class may include the PDU that meets the criteria of different filters. The PDU satisfying one and the same filter may correspond to different classes. In the latter case, such PDU should be copied to the storage corresponding to the different classes;
- PDU of different classes should be stored separately in data processing and storage centers;
- Filtering policy forming, i.e. a specific set of filters and class attributes, corresponds to the function of the SDN controller applications, which can act as external applications for the SDN transport network controller;
- Filtering and Classification policies delivery is being performed in the in_band mode in the transport network via VPN channels;
- Regional (border) data processing and storage centers may add filtering rules to the filters of their domain, with the permission of the main data processing and storage center,;
- The PDU network users gathering should be performed covertly for them;
- The network services consumers should not receive any information about the monitoring system, which includes the traffic classification and filtering system by means of their data transmission network;
- Filtering and classification policies may be dynamically changed, if necessary, by the monitoring system administrator in each of the regions, provided that the consistency of classifiers in different regions is maintained.
The proposed principles and ways of solving the filtering and monitoring problem are aimed at eliminating the dangerous CVD-2021-0047 vulnerability.
