SearcharxivSearch

arXiv subjects

Heiko Lehmann

Publications and source records attributed to Heiko Lehmann.

7 recordsLinked to original sources

A Unified E2E Energy Efficiency Testing Framework for Open RAN

Energy efficiency (EE) is one of the key challenges for contemporary and future mobile networks, including within the Open Radio Access Network (O-RAN) architecture. However, there is a significant gap in common procedures for comparing the EE of both hardware (HW) and software (SW) solutions offered by various vendors. Usually, EE improvements of both SW and HW solutions are demonstrated in a specific scenario defined by individual vendors avoiding comparisons and benchmarking under various network conditions. This paper outlines the need for unified end-to-end (E2E) EE testing for O-RAN. First, it analyzes the standards to identify missing parts. Based on the analysis, a novel O-RAN E2E EE Testing framework is proposed. The framework aims to test the EE of the xApp/rApp pair cooperating on the cell on/off switching using a commercial RAN emulator and real-world network topology data from a mobile network operator (MNO). The test results show up to 57% improvement in EE compared to the baseline.

cs.NI

Large-scale wireless network management via Open-RAN Tandem Apps: Cell on/off switching use case

With growing mobile-network complexity, management and optimization have become increasingly difficult. Centralized algorithms face high control-data overhead and computational load, while distributed approaches often perform far from optimally. The O-RAN architecture introduces two tiers of RAN Intelligent Controllers (RICs), enabling hierarchical network-management schemes. This work proposes Tandem Apps: a pair of tightly coupled optimization mechanisms running on both controllers. We show how to design Tandem Apps through architectural and functional splitting to achieve an agile, low-complexity solution that still preserves a global network view. As an example, we implement Tandem Apps for cell on/off switching and evaluate them in a large heterogeneous network using real network data. Although the Tandem Apps concept is new, it remains fully compliant with the O-RAN standard, as validated using commercial network software.

cs.NI

Predicting Conflict Impact on Performance in O-RAN

The O-RAN Alliance promotes the integration of intelligent autonomous agents to control the Radio Access Network (RAN). This improves flexibility, performance, and observability in the RAN, but introduces new challenges, such as the detection and management of conflicts among the intelligent autonomous agents. A solution consists of profiling the agents before deployment to gather statistical information about their decision-making behavior, then using the information to estimate the level of conflict among agents with different goals. This approach enables determining the occurrence of conflicts among agents, but does not provide information about the impact on RAN performance, including potential service degradation. The problem becomes more complex when agents generate control actions at different timescales, which makes conflict severity hard to predict. In this paper, we present a novel approach that fills this gap. Our solution leverages the same data used to determine conflict severity but extends its use to predict the impact of such conflicts on RAN performance based on the frequency at which each agent generates actions, giving more weight to faster applications, which exert control more frequently. Via a prototype, we demonstrate that our solution is viable and accurately predicts conflict impact on RAN performance.

cs.NI

Observability and Incident Response in Managed Serverless Environments Using Ontology-Based Log Monitoring

In a fully managed serverless environment, the cloud service provider is responsible for securing the cloud infrastructure, thereby reducing the operational and maintenance efforts of application developers. However, this environment limits the use of existing cybersecurity frameworks and tools, which reduces observability and situational awareness capabilities (e.g., risk assessment, incident response). In addition, existing security frameworks for serverless applications do not generalize well to all application architectures and usually require adaptation, specialized expertise, etc. for use in fully managed serverless environments. In this paper, we introduce a three-layer security scheme for applications deployed in fully managed serverless environments. The first two layers involve a unique ontology based solely on serverless logs which is used to transform them into a unified application activity knowledge graph. In the third layer, we address the need for observability and situational awareness capabilities by implementing two situational awareness tools that utilizes the graph-based representation: 1) An incident response dashboard that leverages the ontology to visualize and examine application activity logs in the context of cybersecurity alerts. Our user study showed that the dashboard enabled participants to respond more accurately and quickly to new security alerts than the baseline tool. 2) A criticality of asset (CoA) risk assessment framework that enables efficient expert-based prioritization in cybersecurity contexts.

cs.CR

PACIFISTA: Conflict Evaluation and Management in Open RAN

The O-RAN ALLIANCE is defining architectures, interfaces, operations, and security requirements for cellular networks based on Open Radio Access Network (RAN) principles. In this context, O-RAN introduced the RAN Intelligent Controllers (RICs) to enable dynamic control of cellular networks via data-driven applications referred to as rApps and xApps. RICs enable for the first time truly intelligent and self-organizing cellular networks. However, enabling the execution of many Artificial Intelligence (AI) algorithms making autonomous control decisions to fulfill diverse (and possibly conflicting) goals poses unprecedented challenges. For instance, the execution of one xApp aiming at maximizing throughput and one aiming at minimizing energy consumption would inevitably result in diametrically opposed resource allocation strategies. Therefore, conflict management becomes a crucial component of any functional intelligent O-RAN system. This article studies the problem of conflict mitigation in O-RAN and proposes PACIFISTA, a framework to detect, characterize, and mitigate conflicts generated by O-RAN applications that control RAN parameters. PACIFISTA leverages a profiling pipeline to tests O-RAN applications in a sandbox environment, and combines hierarchical graphs with statistical models to detect the existence of conflicts and evaluate their severity. Experiments on Colosseum and OpenRAN Gym demonstrate PACIFISTA's ability to predict conflicts and provide valuable information before conflicting xApps are deployed on production. We demonstrate that users can experience a 16% throughput loss even in the case of xApps with similar goals, and that applications with conflicting goals might cause instability and result in up to 30% performance degradation. We also show that PACIFISTA can help operators to identify conflicting applications and maintain performance degradation at bay.

cs.NI

Adversarial Machine Learning Threat Analysis and Remediation in Open Radio Access Network (O-RAN)

O-RAN is a new, open, adaptive, and intelligent RAN architecture. Motivated by the success of artificial intelligence in other domains, O-RAN strives to leverage machine learning (ML) to automatically and efficiently manage network resources in diverse use cases such as traffic steering, quality of experience prediction, and anomaly detection. Unfortunately, it has been shown that ML-based systems are vulnerable to an attack technique referred to as adversarial machine learning (AML). This special kind of attack has already been demonstrated in recent studies and in multiple domains. In this paper, we present a systematic AML threat analysis for O-RAN. We start by reviewing relevant ML use cases and analyzing the different ML workflow deployment scenarios in O-RAN. Then, we define the threat model, identifying potential adversaries, enumerating their adversarial capabilities, and analyzing their main goals. Next, we explore the various AML threats associated with O-RAN and review a large number of attacks that can be performed to realize these threats and demonstrate an AML attack on a traffic steering model. In addition, we analyze and propose various AML countermeasures for mitigating the identified threats. Finally, based on the identified AML threats and countermeasures, we present a methodology and a tool for performing risk assessment for AML attacks for a specific ML use case in O-RAN.

cs.CR

Evaluating the Security of Open Radio Access Networks

The Open Radio Access Network (O-RAN) is a promising RAN architecture, aimed at reshaping the RAN industry toward an open, adaptive, and intelligent RAN. In this paper, we conducted a comprehensive security analysis of Open Radio Access Networks (O-RAN). Specifically, we review the architectural blueprint designed by the O-RAN alliance -- A leading force in the cellular ecosystem. Within the security analysis, we provide a detailed overview of the O-RAN architecture; present an ontology for evaluating the security of a system, which is currently at an early development stage; detect the primary risk areas to O-RAN; enumerate the various threat actors to O-RAN; and model potential threats to O-RAN. The significance of this work is providing an updated attack surface to cellular network operators. Based on the attack surface, cellular network operators can carefully deploy the appropriate countermeasure for increasing the security of O-RAN.

cs.CR