ITU-T X.805 - Security Architecture for End-to-End Communications
X.805 Security Planes

ITU-T X.805 - Security Architecture for End-to-End Communications X805-Planes-Management-Control-EndUser-OAM-Signalling-Network-Element-Subscriber-Data: ITU-T X.805 Security Planes - Management Plane + Control Plane + End-User Plane + OAM Operations-Administration-Maintenance + Signalling + Routing + Network Element Activity + Subscriber Data Flows + Cross-Layer Application

Security Planes per X.805 Clause 7.4: A Security Plane represents a certain type of network activity protected by Security Dimensions and applied across all 3 Security Layers. X.805 defines 3 Security Planes that represent the 3 types of protected activities on networks: (1) Management Plane per X.805 Clause 7.4.1: addresses Operations Administration Maintenance and Provisioning (OAM and P) functions of network elements + transmission facilities + back office systems (Operations Support Systems OSS + Business Support Systems BSS + and the like) + the data centers that house these systems. Management Plane activities include device configuration + network monitoring + statistics gathering + provisioning + accounting + activation + change management + fault detection + backup/restore. (a) Northbound interfaces - OSS/BSS to NEM Network Element Management Layer + Service Provider tools; (b) Southbound interfaces - NEM to Network Elements + Devices; (c) Element Management System (EMS) + Network Management System (NMS) + Manager-of-Managers (MoM); (d) Standards - SNMP v3 + NETCONF over SSH + RESTCONF over HTTPS + gNMI + YANG + TMN/M.3010; (e) Use cases - Element provisioning + Performance management + Fault management + Configuration management + Accounting management + Security management (FCAPS). (2) Control Plane per X.805 Clause 7.4.2: deals with activities that enable efficient delivery of information + services + applications across the network. Generally this consists of machine-to-machine communications between network elements (signalling + routing + network state distribution). Control Plane activities include routing protocol exchange + signalling for call setup + tear-down + handover + QoS reservation + admission control. (a) Telecom Signalling - SS7 + SIGTRAN + Diameter + SIP + ISUP + MAP + CAP; (b) IP Routing - BGP + OSPF + IS-IS + EIGRP + RIP; (c) IP Signalling - SIP + RSVP + DiffServ + GMPLS + LDP; (d) Mobile Signalling - GTP-C + S1AP + NGAP + N2 + MAP + Diameter S6a/S9/Sd/Gx/Gy + 5G SBI HTTP/2; (e) Network Element control - SDN OpenFlow + ONOS + ODL OpenDaylight + P4Runtime; (f) Cloud control - K8s API + AWS Control Plane + Azure ARM + GCP API. (3) End-User Plane per X.805 Clause 7.4.3: addresses security of access to network from end-user perspective and access of end-user to network resources + storage + content + applications. End-User Plane activities include subscriber service consumption + data flow between users + content delivery + transactions. (a) Subscriber Data - Voice + Video + Data sessions; (b) User Plane Function (UPF) in 5G; (c) S/P/SGW User Plane in LTE; (d) Carrier Data Path - GTP-U + IP forwarding + MPLS LSP + L2 switching; (e) Content delivery - CDN + IPTV + OTT video; (f) End-to-End user data flows. (4) Plane Separation Principle: X.805 mandates STRICT logical and ideally physical separation between Management + Control + End-User Planes to prevent cross-plane attacks. Compromise of one plane (e.g. management plane) must not enable compromise of others. (a) Out-of-band management network (separate physical or VLAN-isolated); (b) Control Plane Policing (CoPP); (c) Control Plane Protection (CoPP) ACLs; (d) Plane separation per device + per chassis + per region; (e) Defense-in-depth between planes; (f) Microsegmentation per Plane. (5) Plane Specific Threats: (a) Management Plane - admin credential theft + privileged escalation + lateral movement + ransomware targeting OSS + supply chain via NEM; (b) Control Plane - signalling abuse (SS7 attacks + Diameter attacks + GTP attacks + SIP attacks + BGP hijacking + DNS cache poisoning + Routing protocol attacks); (c) End-User Plane - subscriber data theft + content piracy + DDoS amplification + traffic interception + side-channel + Lawful Intercept abuse. (6) Plane Specific Security Measures: (a) Management Plane - MFA mandatory + PAM + Just-In-Time + audit logging + change ticketing + signed configuration + out-of-band management; (b) Control Plane - Signalling firewall + STIR/SHAKEN + BGP RPKI + DNSSEC + OSPF/IS-IS Authentication + Anti-Spoofing + LFA Loop-Free Alternatives + microloop avoidance + GSMA SS7/Diameter signaling protection; (c) End-User Plane - DPI Deep Packet Inspection + content filtering + subscriber-level firewalls + carrier-grade NAT security + Lawful Intercept gateway security. (7) Plane x Layer Matrix: X.805 explicitly creates a 9-cell matrix: (a) Management at Infrastructure (e.g. SNMPv3 to switches); (b) Management at Services (e.g. IMS HSS management); (c) Management at Applications (e.g. Email server management); (d) Control at Infrastructure (e.g. BGP between routers); (e) Control at Services (e.g. SIP between SBC); (f) Control at Applications (e.g. application orchestration); (g) End-User at Infrastructure (e.g. user data via fibre); (h) End-User at Services (e.g. user data via IMS); (i) End-User at Applications (e.g. user request to web app). Each of these 9 cells is then evaluated against the 8 Security Dimensions yielding 72 distinct security perspectives. (8) Modern Evolution: (a) SDN Software-Defined Networking separates Control Plane explicitly; (b) NFV Network Functions Virtualization on Commercial Off-The-Shelf (COTS); (c) Open RAN O-RAN Control Plane + Management Plane; (d) Network Slicing for tailored Plane policies; (e) 5G SBA Service-Based Architecture flattens traditional plane separation; (f) Zero Trust Network Architecture applied per Plane; (g) Cloud-Native Network Functions (CNFs); (h) Edge Computing pushes Planes to network edge; (i) Open RAN O-CU/O-DU/O-RU separation + RIC. Coordinates with X.805 Layer 1/2/3 + 8 Dimensions + Threats All-5 + ITU-T M.3010 TMN + M.3400 TMN Management Functions + Y.2701 NGN + ETSI NFV + ETSI MEC + 3GPP TS 33.117 SCAS + GSMA SS7/Diameter Firewall + ETSI SDN + O-RAN Alliance Working Groups + ISO/IEC 27033-Series Network Security. ITU-T X.805 Security Planes apply.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.