IEEE Access (Jan 2023)

RAIN: Risk Assessment Framework Based on an Interdependent-Input Propagation Network for a 5G Network

  • Che-Tsung Kuo,
  • Hong-Yen Chen,
  • Tsung-Nan Lin

DOI
https://doi.org/10.1109/ACCESS.2023.3281560
Journal volume & issue
Vol. 11
pp. 54881 – 54896

Abstract

Read online

It is essential for mobile network operators to provide effective protective measures for assets in 5G networks to mitigate various threats, and risk assessment plays an important role in decision-making for protective measures. Organizations refer to risk assessment to determine the priority for protective measures, and multiple studies have proposed assessments that take various aspects and methodologies into consideration. Nevertheless, these efforts are not sufficiently useful in a practical sense. Existing studies lack numerical results to make cost-efficient decisions and cannot be automatically updated when the security policy is altered. Finally, a unified assessment framework is necessary. Hence, we propose a quantitative risk assessment framework, RAIN, to solve these problems for the 5G network. A customized weighted network combined with an interdependent-input weighting method enables the framework to provide holistic and quantitative assessment results and can be used for any scenario in a 5G network. With the assessment results, organizations can prioritize the implementation of protective measures for the target assets. In addition, the framework is flexible for policy changes and suitable for different systems in 5G networks. We implement our framework on a 5G stand alone core network system with different scenarios.

Keywords