{"id":138793,"date":"2019-05-29T17:39:59","date_gmt":"2019-05-29T09:39:59","guid":{"rendered":"https:\/\/www.mobileworldlive.com\/?p=246030"},"modified":"2019-05-29T17:39:59","modified_gmt":"2019-05-29T09:39:59","slug":"intelligence-brief-should-we-worry-about-5g-security","status":"publish","type":"post","link":"https:\/\/itteacheritfreelance.hk\/test\/wordpress\/2019\/05\/29\/intelligence-brief-should-we-worry-about-5g-security\/","title":{"rendered":"Intelligence Brief: Should we worry about 5G security?"},"content":{"rendered":"<p>        \tAs I\u2019ve highlighted a few times on my Data Point videos, I spent some time this week at the GSMA\u2019s Mobile360 Security for 5G event in The Hague.<\/p>\n<p>What did I do there? Ate some stroopwafels. Moderated the first two sets of keynotes. Did a taste test of different types of stoopwafels. Moderated a panel of security experts. Bought some stroopwafels to take home. I mean, the security stuff is super-important, sure. But\u2026priorities, right?<\/p>\n<p>In addition to weighing down my carry-on bag with delicious Dutch desserts, I did manage to pick up a few insights into the conference topic. If only thanks to osmosis, the caliber of the speakers and the frankness of the discussions, it would have been hard not to. And, all joking aside, anyone interested in 5G, either rolling out networks or services, needs to be concerned with how we\u2019ll secure it. While not necessarily exhaustive, here\u2019s what I\u2019m now paying more attention to.<\/p>\n<p>5G imperative. I kicked off the keynote panel with a simple question: \u201cWhy has 5G brought the question of security to the fore?\u201d What\u2019s different about 5G versus 4G or 3G that makes security so much more important? The panelists\u2019 answers centered on the attention 5G is getting from operators and regulators and consumers. The real answer, however, is implicit in that attention: it implies a massive amount of connected devices (potentially unsecure endpoints) as well as the critical digital systems expected to run on 5G.<\/p>\n<p>To worry or not. If we expect lots of critical systems to run on 5G (from connected cars to connected industries) then we need to be really worried about the security of 5G networks, right? Doomsday scenarios of power grid shutdowns and cars getting hijacked, are more than just abstract concepts, they\u2019re real world possibilities that should be keeping us all up at night. Maybe. While these might all be connected by 5G, it\u2019s silly to believe that the only security applied to them will be in the 5G network. The services running over the 5G networks will need to be secured as well. We hear a lot about multi-layer security architectures. If we believe that they are indeed necessary, then we can\u2019t pin all 5G security responsibilities on the 5G network alone.<\/p>\n<p>Dangerous cost cutting (aka, security RoI). I\u2019m cheap. Just ask my boss, my team, or my wife. So, when I went shopping for a home security camera on Amazon, I opted for the low-cost option, then wondered about how secure it would be and if I could trust its cloud services. The same applies to network security. Policies, products, and architectures optimised for costs may come with security risks. Or, rather, security policies, products and architectures optimised for costs may be ineffective, incurring their own costs. Ultimately, the issue is one of RoI, recognising that security outlays need to be seen as investments that deliver returns in terms of network protection, service integrity, and customer satisfaction.<\/p>\n<p>SOS (Same Old Skills gap). The concept of a \u201cskills gap\u201d among operators is not new. Years ago when I did some work on barriers to implementing virtualisation, a lack of internal skills was cited as critical. Fast forward and the same thing exists for security skills, forcing operators to rely on the skills of their vendor partners.<\/p>\n<p>Skills gap, meet innovation gap. Where a skills gap forces operators to rely on their vendors, we are forced to acknowledge a long-term evolution in the vendor landscape. Where there was once a large set of major mobile network vendors, the market is now largely concentrated amongst three main ones, especially in the RAN. Why is this a problem? Put aside theoretical arguments around the impact on pricing and incentives to innovate. If operators have a smaller set of vendors to choose from, then they have little option but to live with the decisions those vendors make around security (or how well they secure their own solutions).<\/p>\n<p>Deadly rotten eggs. Apparently, connected egg trays are a real thing. If you live in a civilised country where eggs are stored in the fridge, you might now worry about how long your eggs have been around. If you keep your eggs in the pantry like a Neanderthal, however, then a tray that lets you know how long they\u2019ve been around might make sense (note to self: Connected Neanderthal would be a great band name). But where the issue of 5G Security often revolves around critical infrastructure or connected industries, securing the lowly connected egg tray might seem unnecessary. I\u2019d thought we\u2019d got past that thinking, recognising that anything connected to the network becomes part of a potential attack surface. Regardless, potential threat examples ranging from light bulbs to aquarium heaters, to egg trays all got invoked as a reminder.<\/p>\n<p>Moving beyond generalities. If we need 5G security to be a topic that everyone pays attention to (everyone owns in some way), then we need a broad set of stakeholders at conferences, learning about it. Simple enough. But that means the way we talk about it (technical versus strategic) will need to accommodate them all. That\u2019s problematic, because talking about security in terms of broad trends and generalities won\u2019t result in real, on the ground, solutions to real problems. Does that mean we exclude the less technical folks (like myself) from these conversations? No. It means we need to all get smarter and become conversant in security the way we are for RAN or device specs.<\/p>\n<p>AI imperative. Another \u201cimperative,\u201d I know. But just as much as 5G has increased the profile of network security, network security has elevated the profile of AI. IBM highlighted this when noting the sheer volume of security notices, updates and research produced on a daily basis (around 7,000 pages). The takeaway: we need good AI tools to help us identify what matters and to help find the data we need when we need it. Beyond discovery, though, there\u2019s a role for AI in helping us adapt to evolving threat tactics and strategies.<\/p>\n<p>5G for good. In presenting the value that 5G and mobile networks can bring (and the importance of getting them right), the GSMA\u2019s Director General Mats Granryd pointed to the promise of enhanced connectivity combined with AI and Big Data to do things like mitigate or halt tuberculosis outbreaks. It\u2019s an important reminder, and not just because he\u2019s my bosses\u2019 boss. But, it also highlights an important knock-on requirement.<\/p>\n<p>Trust, trust, trust. Security is different from privacy. They are two different sets of issues with different requirements and associated risks. But if 5G will be connecting us all and leveraging data to do great things, then users need to have trust in the privacy of their data, or at least trust in the way that their data is being used. Again, these issues are different from security, and they may be more difficult to tackle, requiring consumers to pay attention. But, if we want to execute on the 5G promise, they may be the most important issues.<\/p>\n<p>\u2013\u00a0Peter Jarich\u00a0\u2013 head of GSMA Intelligence<\/p>\n<p>The editorial views expressed in this article are solely those of the author and will not necessarily reflect the views of the GSMA, its Members or Associate Members.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>As I&rsquo;ve highlighted a few times on my Data Point videos, I spent some time &#8230;<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/www.mobileworldlive.com\/blog\/intelligence-brief-should-we-worry-about-5g-security\/\">Intelligence Brief: Should we worry about 5G security?<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/www.mobileworldlive.com\/\">Mobile World Live<\/a>.<\/p>\n<p> <a href=\"https:\/\/itteacheritfreelance.hk\/test\/wordpress\/2019\/05\/29\/intelligence-brief-should-we-worry-about-5g-security\/\">\u95b1\u8b80\u5168\u6587 <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":180,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"slim_seo":[],"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","enabled":false}}},"categories":[2471,3921,2151,2,2075,7],"tags":[398,402,397,414,413,410,499,409,407,408,406,399,400,394,10,401,396,787,786,784,782,783,764,785,403,412,411,395,405,404,778,779,780,781],"jetpack_publicize_connections":[],"aioseo_notices":[],"jetpack_featured_media_url":"","jetpack_shortlink":"https:\/\/wp.me\/p7prtj-A6B","jetpack-related-posts":[],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/itteacheritfreelance.hk\/test\/wordpress\/wp-json\/wp\/v2\/posts\/138793"}],"collection":[{"href":"https:\/\/itteacheritfreelance.hk\/test\/wordpress\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/itteacheritfreelance.hk\/test\/wordpress\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/itteacheritfreelance.hk\/test\/wordpress\/wp-json\/wp\/v2\/users\/180"}],"replies":[{"embeddable":true,"href":"https:\/\/itteacheritfreelance.hk\/test\/wordpress\/wp-json\/wp\/v2\/comments?post=138793"}],"version-history":[{"count":1,"href":"https:\/\/itteacheritfreelance.hk\/test\/wordpress\/wp-json\/wp\/v2\/posts\/138793\/revisions"}],"predecessor-version":[{"id":138839,"href":"https:\/\/itteacheritfreelance.hk\/test\/wordpress\/wp-json\/wp\/v2\/posts\/138793\/revisions\/138839"}],"wp:attachment":[{"href":"https:\/\/itteacheritfreelance.hk\/test\/wordpress\/wp-json\/wp\/v2\/media?parent=138793"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/itteacheritfreelance.hk\/test\/wordpress\/wp-json\/wp\/v2\/categories?post=138793"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/itteacheritfreelance.hk\/test\/wordpress\/wp-json\/wp\/v2\/tags?post=138793"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}