SearcharxivSearch

arXiv subjects

Loay Abdelrazek

Publications and source records attributed to Loay Abdelrazek.

5 recordsLinked to original sources

A Standardized Ontology for Intent-Based Security Management in Autonomous Networks

Modern 5G-Advanced and emerging 6G architectures face complex, multi-layered threat vectors that outpace traditional manual security configurations. Shifting security management towards autonomous, self-protecting operation requires formal semantic frameworks. This work specifies the TM Forum TR292I Security Ontology v4.0.0, a standardized Resource Description Framework Schema (RDFS) compliant vocabulary for declarative security management. By natively extending the TM Forum Intent Common Model (ICM), the ontology decouples high-level security goals from underlying technical controls. Crucially, it embeds resource cost mapping properties to ensure autonomous mitigation actions safeguard Service Level Agreements (SLAs). We validate this model-driven architecture through a formal semantic walkthrough of a distributed Denial of Service (DDoS) mitigation sequence on a disaggregated Next-Generation NodeB (gNB) slice using W3C Turtle and SPARQL. The results demonstrate that runtime constraint conflicts are resolved dynamically without human intervention, establishing a reproducible framework for standardized, intent-driven network security orchestration.

cs.CR

Dynamic Authorization for Knowledge-Base Agents in 6G

As 6G architectures transition toward decentralized Multi-Agent Systems (MAS), ensuring secure access to shared Knowledge Bases (KB) is critical. Traditional authorization models like RBAC fail to provide the granularity required for autonomous agents interacting with Semantic-based data. This work proposes a hybrid authorization framework that integrates roles and First-Order Logic (FOL) predicates to enforce zero-trust principles at the knowledge-graph level. We eliminate permission inheritance by enforcing authorization at the triple level (Subject-Predicate-Object), ensuring agents only access metadata required for their specific functional lifecycle.

cs.CR

Authorization of Knowledge-base Agents in an Intent-based Management Function

As networks move toward the next-generation 6G, Intent-based Management (IbM) systems are increasingly adopted to simplify and automate network management by translating high-level intents into low-level configurations. Within these systems, agents play a critical role in monitoring current state of the network, gathering data, and enforcing actions across the network to fulfill the intent. However, ensuring secure and fine-grained authorization of agents remains a significant challenge, especially in dynamic and multi-tenant environments. Traditional models such as Role-Based Access Control (RBAC), Attribute-Based Access Control (ABAC) and Relational-Based Access Control (RelBAC) often lack the flexibility to accommodate the evolving context and granularity required by intentbased operations. In this paper, we propose an enhanced authorization framework that integrates contextual and functional attributes with agent roles to achieve dynamic, policy-driven access control. By analyzing agent functionalities, our approach ensures that agents are granted only the minimal necessary privileges towards knowledge graphs.

cs.CR

Managing Differentiated Secure Connectivity using Intents

Mobile networks in the 5G and 6G era require to rethink how to manage security due to the introduction of new services, use cases, each with its own security requirements, while simultaneously expanding the threat landscape. Although automation has emerged as a key enabler to address complexity in networks, existing approaches lack the expressiveness to define and enforce complex, goal-driven, and measurable security requirements. In this paper, we propose the concept of differentiated security levels and leveraging intents as a management framework. We discuss the requirements and enablers to extend the currently defined intent-based management frameworks to pave the path for intent-based security management in mobile networks. Our approach formalizes both functional and non-functional security requirements and demonstrates how these can be expressed and modeled using an extended TM Forum (TMF) intent security ontology. We further discuss the required standardization steps to achieve intent-based security management. Our work aims at advance security automation, improve adaptability, and strengthen the resilience and security posture of the next-generation mobile networks.

cs.CR

Measuring Security in 5G and Future Networks

In today's increasingly interconnected and fast-paced digital ecosystem, mobile networks, such as 5G and future generations such as 6G, play a pivotal role and must be considered as critical infrastructures. Ensuring their security is paramount to safeguard both individual users and the industries that depend on these networks. An essential condition for maintaining and improving the security posture of a system is the ability to effectively measure and monitor its security state. In this work we address the need for an objective measurement of the security state of 5G and future networks. We introduce a state machine model designed to capture the security life cycle of network functions and the transitions between different states within the life cycle. Such a model can be computed locally at each node, or hierarchically, by aggregating measurements into security domains or the whole network. We identify three essential security metrics -- attack surface exposure, impact of system vulnerabilities, and effectiveness of applied security controls -- that collectively form the basis for calculating the overall security score. With this approach, it is possible to provide a holistic understanding of the security posture, laying the foundation for effective security management in the expected dynamic threat landscape of 6G networks. Through practical examples, we illustrate the real-world application of our proposed methodology, offering valuable insights for developing risk management and informed decision-making strategies in 5G and 6G security operations and laying the foundation for effective security management in the expected dynamic threat landscape of 6G networks.

cs.CR