AI’s Impact on 5G Security – Six Five Podcast: The 5G Factor – EP74
Nokia’s new Threat Intelligence Report shows cyberattacks on telecom infrastructure are accelerating as cybercriminals increasingly use GenAI and automation to increase the speed, volume, and sophistication of their attacks. Next, Qualcomm’s AI Orchestrator aims to harmonize all AI functionalities to provide a meaningful interaction experience and improve security. Lastly, Vodafone highlights the use of data-driven APIs, such as its Scam Signal, to provide the mobile intelligence needed to push back on fraud across the telecom sector.
Transcript
Hello and welcome everyone to the 5G Factor. I'm Ron Westall, research director here at the TUM Group, and today, thankfully, I'm joined here by my distinguished colleague, Tom Hollingsworth, the networking nerd and event lead at Tech Fit Field Day here at the Futuring Group. Tom, how are you?
It's great to see you back on the show. I know, Ron, it's been a busy few weeks I've been out and about, but, uh, the good news is, is that I'm back and we've got some fun stuff to talk about today and, uh, it should be, uh, an interesting Friday. I I agree wholeheartedly.
In fact, I believe we're coming off a, to your point, very successful string of tech field day events over the last couple of weeks. And as such, I think this is good giving us some foundation, some good material for today's 5G Factor will look, be focusing on the major 5G ecosystem developments that have caught our eye. And so with that, let's jump right in.
And speaking of major developments in the 5G ecosystem, security is always paramount. I think that's understood, that's true across the entire networking realm. And what I think is of key importance is that Nokia recently released its 10th threat intelligence report, which shows that cyber attacks on telecom infrastructure is accelerating as cyber criminals increasingly hardest.
You guessed it, gen ai as well as automation to increase the speed, volume, and sophistication of these attacks. Now, among the reports, key findings is that DDoS or distributed denial of service attacks can quite simply overwhelm the telco infrastructure. The number and frequency are increasing dramatically, and so that can make, uh, a, you know, a network inoperable.
And I think, you know, the headlines, uh, caught that just over the last couple weeks where, for example, uh, Verizon had some, uh, network outage issues. And what is linked to this is that these attacks have grown from one or two a day to well over a hundred per day, and that's across, uh, all, uh, the networks. Almost also, bots or botnets continue to be primary sources of these D OS attacks, and they represent about 60% of the DDoS traffic monitored by Nokia from June of 23 to June of 24.
And during that time period, residential proxies became a prominent tool for more advanced application layer attacks. And this is something that is, you know, hitting more regions more than others. In a nutshell, north America has seen the highest number of these cyber attacks accounting for about one third of the total due to the concentration and scale of telecom infrastructure and large enterprises in the us.
Now, reflecting a trend of recent years, the growth in DDoS attacks has been fueled by the proliferation of hundreds of thousands of insecure iot devices ranging from smart refrigerators to smart watches, which often have lacked security protections and have gigabit and multi gigabit broad, uh, capacity that facilitate the spread of malware. The most common malware in telecommunications networks was found to be a bot that scans for vulnerable devices with weak encryption passwords or design laws. Now, this is something we've seen before, however, this proliferation of attacks is concerning.
Tom, you know, from your view, uh, what do you see, you know, what's different this time about cyber attacks on telecom infrastructure, including naturally 5G networks? I think that it's interesting because Nokia operates a DDoS protection service called Deep Field that they've done a really great job of trying to figure out what's going on. And I like this idea that they've narrowed it down to being a large percentage of the traffic coming from IOT botnet activity.
We've seen this for a while where, you know, things like insecure xmi, uh, webcams can be amplified to turn them into basically, you know, like packet generators. And the worst part is it's, is there were, there's two worst parts. One, you're not gonna expect to see a whole lot of extra traffic coming from a camera.
Like you're, you're gonna be looking for other things on your network. Like, oh, you know, my, my server got hacked, or, or something like that. You, you wouldn't think to look for the iot devices.
But the second thing that's even more insidious is, is that these systems have security baked in from the factory. Those certificates are generated and in rarely ever touched again, there are root passwords in some cases, I'm, I'm not saying it's the the camera specifically, but in some other iot devices are hardwired into the system. So the only way to fix it is basically to take it offline and junk it.
And, and the problem is, is that when you think about how many of these devices are insecure and capable of being used in these amplification attacks, I mean, Nokia has been sinking as in and collecting and dumping this traffic hundreds of gigs, if not terabits of traffic. I mean, some of the things that we're seeing out there are beyond the scale of anything that I could possibly have imagined in the past. And it's only gonna get worse as more and more iot devices have less and less security because security costs money.
And if my option is, is that I need to hit a device at a certain price point, then I'm going to leave out whatever I can to get to that point. You don't see these kinds of attacks coming from things like Honeywell thermostats or from, you know, larger like, I don't know, say like the, the digital signage, TVs on the wall because those are relatively expensive devices, which means they have a, a baseline of security built in. So we're gonna start relying more and more on companies like Nokia who are effectively offering like a sieve to drop that traffic because this isn't like the DDoS protections that you might've imagined from, you know, 10 years ago where we can prevent sin, floods and things like that from connecting and, and just basically preventing that kind of connection.
Like you mentioned, application layer attacks are becoming more and more prevalent, which means the underlying network infrastructure is relatively, uh, reasonably unchanged. It's the applications that are impacting that. And here's the other insidious thing about it.
Why would this be important for a company to want to defend against? Well, if you look at some of the latest actions going on, on a global stage, often massive DDoS attacks can proceed other kinds of actions. We saw one in Ukraine right before the invasion.
There was a massive DDoS attack that basically took a lot of things offline so that there was no way to coach to do, uh, command and control coordination amongst some of their forces. I'm not saying anybody's gonna be trying that in the US anytime soon, but one thing that we've learned over the last few months and possibly even the last year or so, is that coordinated attacks on infrastructure can cause a big problem. I agree wholeheartedly, and I think insidious is an apt term.
We can, uh, basically reboot that franchise, just, you know, looking at, you know, the increasing sophistication of these attacks. And I, I'm glad he brought out, uh, attention to, uh, the, the background here. IE it could be a supply chain, uh, factor.
In fact, uh, another uh, aspect here that the report brought out is that systems on chips or socks, hardware integrated circuits that are incorporating computer components and drive, you know, the high computing and network performance and also, uh, help minimize power consumption. Cyber criminals are increasingly targeting socks to exploit vulnerabilities in various components. And that includes s firmware software and hardware interfaces.
So it's really getting under the hood now. It's not just, okay, we found a vulnerable port or a poorly configured IOT device, you know, we are, you know, just that, uh, being able to attack, uh, in a new way that requires, you know, quite simply new defenses. And to top it all off, there's quantum computing, uh, coming into the picture.
And, uh, this is another example where threats are evolving rapidly. Organizations like the NIST, uh, which recently standardized the first algorithms, uh, these will form components of an approach to counter the potential threat of quantum computing and quite simply continuing to help shape overall strategies security strategies globally. And so when he boiled down, it's like in order to fight AI generated cybersecurity threats, yeah, that's enlist, you know, it ai, uh, as well as gin ai, and same thing with quantum.
So it's quantum fire, fire, uh, quantum fire. And, you know, hopefully the good guys will, uh, simply win more often than the bad guys. And, you know, this is, you know, uh, the newest chapter in terms of how threats are evolving and require quite simply new and more sophisticated responses and solutions.
And with that, let's look at something that can help with this. You know, I talked about AI and using AI to fight that ai, uh, cyber, uh, crime. Well, we saw that, uh, Qualcomm has come out with an AI orchestrator offering, and it's the new addition to the existing Qualcomm AI stack and what it is that it sits between the apps and the AI framework and runtimes, which can provide the orchestration needed for all functions that include certainly security.
Now, in terms of, you know, the evolving landscape, I see that Qualcomm AI orchestrator is poised to expand its capabilities including integration of device, device and also other, uh, situations like device to car configurations. Another interesting example of IOT. Now, what this orchestrator could do is leverage the best aspects of each device that generate the most compelling experience for the user.
And that includes certainly security. Now, these designs can enable the orchestrator to continually evolve, and that includes meeting these cybersecurity threats and also accommodate, you know, new improved AI capabilities. Because what's important here is that devices are integral to inferencing at the edge of the network, that it's ensuring that the AI workloads are secure.
They don't leave the device. You can do the inferencing right there on your device and avoid, you know, sending AI workloads across the wide area network to the cloud where vulnerabilities can occur. Now, this is different from AI training where you have, you know, the GPU clusters doing the heavy lifting of training the models, but once that's done, then you can have the ability to inference at a local or edge, uh, um, uh, perimeter.
And that will make a big difference, I believe, in terms of overall AI security, let alone respecting privacy. Now, what's also Fort, I think to note here is that the Qualcomm AI orchestrator harness harnesses AI functions and provides, you know, that personalized experience that I was just talking about, for example, on the smartphone, on the tablet, and also will be at other devices across the Snapdragon portfolio. And I think this is something that, uh, is good news quite simply for not only smart devices, but for, you know, making AI more user-friendly and fundamentally secure.
And so, uh, Tom, from your view, what do you see about this Qualcomm AI orchestrator announcement that could be a difference maker? I think that Qualcomm is one of those companies that's finally figuring out that there's a lot more power in their devices than they've been letting on. And they need a way to kind of coordinate how to leverage it to do more things.
And this is what we're talking about when you look at the push from companies like Apple to do more of the AI inferencing on device for security reasons, I think that a lot of people are gonna fall in line and start doing that same model, or maybe if they're not doing it on device, they're doing it on the edge close to the device so that they're not paying transit costs and things like that. So being able to orchestrate that at a, at a certain level is critical. I mean, look at it this way.
You, you everybody's seen in like in warehouses where they have those little handheld scanners, right? And they're generally now smart devices that connect via wifi, and when they're not doing scanning, they're just, they're kind of sitting there, right? What have you got a way to be able to leverage distributed computing to those devices and break these systems down so you can do inferencing when those systems are not in use?
Like, I don't know, when they're sitting on a charger at night. Um, that would be a huge motivation for a company wanna adopt this. When you basically say you're already using this technology, uh, you know, why not leverage it for more things?
Why not get more, uh, dollar revenue out of it per device? And I think Qualcomm's kind of on the leading edge of this because they provide so many chips for these edge solutions. You know, we're not talking about in Nvidia here that is building these kind of high performance water cooled nuclear powered systems to do this.
We're talking about Qualcomm who's like, Hey, we can do AI inferencing, maybe we're not gonna beat, you know, whatever the, the latest hopper chip is, but we're gonna do it on a budget that runs on a battery. So I, I think that they're on the right track here because they, they know that they can't compete with these monstrosity systems, so they're figuring out how best to approach it and make it usable for end users. Because I think what we're gonna see maybe within the next couple of years is the, this big shift to doing more things on device for security purposes.
Yes, and I think it's, uh, in general as well, I think, uh, we talk about the AI era. I think we're pretty much at the hybrid AI era where, you know, uh, training and, uh, inferencing, uh, is being more implemented, you know, at, you know, the premises or on the device. And this is something that will, again, to your point, Tom, benefit the entire ecosystem.
And this is something that I think we'll have direct bearing on the cybersecurity threat that we started off with. And let's now turn to a specific example of where cyber, uh, security can play an integral role. And that is certainly in fraud, uh, prevention.
And what we're seeing is that fraud is quite simply something that is been, uh, a major, uh, the, I guess you can say, uh, downside to, you know, some telecom services. And if you look at the UK specifically, a Vodafone reported that over 1 billion pounds has been a loss because, uh, UK consumers have been, you know, victims of fraud, or at least Vodafone has been the victim of fraud. So what we're looking at now is that using mobile network intelligence, certainly a good deal of it is AI driven can hopefully provide a solution that makes fraud, uh, prevention and detecting, uh, uh, fraud threat, uh, simply more automated and well more effective.
And so what they're pointing to is that, uh, when it comes to bank impersonation scams, what happens is someone will receive a call from another person pretending to work for their bank and then telling them to move funds to a trust trusted account. But then again, you know, the money ends up in a fraudster. So this is kind of a variation of, okay, you're getting an email that looks very convincing, but obviously it's, you know, this a variation of a phishing scam.
And, uh, these thefts are, you know, costing not just the uk but European banks, you know, all these, you know, hundreds of millions of pounds, uh, that has been cited. Now, when it comes to, uh, chargebacks, fraud occurs when an unethical customer makes a purchase online for a product with the credit card and then contacts a credit card issued issuer to say that the, the purchase was fraudulent. And, uh, this is something that is kind of on the flip side.
Now, it's the consumer who, or the customer that's per, uh, perpetrating the fraud. Uh, but, uh, I think we've seen, you know, reports of where this can run into, you know, tens of thousands of dollars before it's detected, especially when it's, uh, you know, international type scenario. So what's being proposed is to, you know, enlist APIs to really up the game for mobile operators that is using more intelligence to better understand, you know, these, uh, fraud scenarios as they're, you know, emerging that is, you know, prevent them before they blow up, nip them in the bud, uh, quite fundamentally.
So now what Vodafone is doing is investigating how data and the APIs that are aligned, uh, to, you know, their expanded data lakes that can be used to determine whether a user's making a purchase for malicious purposes. And so the next step here is that it's en enlisting various industries to better trust the entity behind the mobile number. And so, uh, when you're looking at social networks and so forth, you wanna remove, you know, okay, is this a phishing scan?
How can you, you know, prevent this from recurring? So as fraud is evolving, and you know, it's becoming, again, just like cyber attacks on telecom infrastructure, you know, more sophisticated, I foresee that by, you know, building these APIs that are dedicated to deducting fraud, to, you know, quite simply reducing, uh, the level of threats to, you know, not just the telecom infrastructure network itself, but also, uh, again, you know, mobile devices and mobile numbers themselves. And that can, uh, again, uh, enable operating across multiple data aggregators and sectors to, you know, uh, provide, you know, this critical data to make it, you know, safer for people to get online using their mobile devices and have confidence they're not being, uh, defrauded or the operator or the credit card company can have confidence that somebody's not defrauding them.
And so, again, variations of, you know, ai, you know, becoming a player here in cybercrime and alright, let's use AI to fight the cyber crime and in this particular use case, so Todd, do you see, you know, hopes for progress or this is something that can actually get worse? You know, I think it can, and and it kind of comes down to just doing the basics that we expect, right? It's doing, um, work on making sure that like we're authenticating sources of messages and things like that.
Because I'll tell you that it's getting a lot more complicated to figure this out. Uh, there was a story that I saw just a couple of days ago about someone who received an inbound phone call from a number that was from Chase Bank and, and they were asking him to authenticate and do some things. And, and luckily, you know, kind of that, that voice in the back of your head says, don't do this went off.
And so he is like, hold on, I'm gonna hang up and call you back. And he called the same number back, got a hold of the chase, uh, support line. And it turns out, of course, that they had initiated no such call and it was just basic caller ID spoofing, which is something we've known how to do for years.
But it's that combination of all of those things. It looks right, it sounds right. They have access to details and they've created AI scripts to kind of, um, you know, adjust for any potential, um, problems that could come up in the middle of this call.
So I like the fact that Vodafone is basically saying, we already have access to this data. Let's see if we can put two and two together to prevent this. I mean, we saw the same thing here recently when MasterCard purchased recorded future.
Uh, they, you know, they're one of the largest, uh, security intelligence firms out there and they were bought by a credit card company because according to MasterCard, if you read between the lines, they really are spending so much money fighting credit card fraud that it would be cheaper to buy a company to help them fight it than it would be to continue to pay that company to do it for them. And I think that that's something we're gonna see a lot more of when, you know, you have things like sim swapping attacks because most of the time you've got two, uh, categories of people. You've got the ones that are using it to do like some quick hit stuff, you know, like I, I wanna get a few hundred or a thousand or so dollars from people who are unsuspecting, but more insidiously, you've got people who are using these attacks to flip, to get more secure access to things, to be able to um, you know, grab two-factor authentication codes and stuff like that.
Which by the way, if you're still using text messages for your authentication for two factor, you need to move to an app-based solution because it's gonna be way more secure because it defeats particular problems like this. And, and as we start moving away from some of these more traditional things like, um, you know, NIST just released new guidance on passwords and, and now they're saying things like, you know, it doesn't need to be complex, but it needs to be longer. It needs to be something that is more easily, um, you know, remembered by you, but more difficult for people to break.
And we're moving to things like pass keys where my devices biometrics can authenticate my log into a website. Um, we, uh, you know, we're, we're seeing more and more companies start become more and more cagey about this because as we reduce the occurrences of incidental fraud, the problem is is that the people who can pull off the fraud are using methods that allow them to defraud for larger amounts. So this isn't a, a situation where like, you know, a thousand customers are, are contacting our helpline 'cause they got defrauded by a hundred dollars, it's because 10 customers all got defrauded for a hundred thousand dollars and now that's a bigger bill because well if you've got all the tools to make it look legit, go big or go home.
Yes, indeed. And I think that's a excellent point about, for example, biometrics playing a, a bigger role as well as using more app-based, uh, security technology such as zipper across, you know, the, uh, cloud fabrics. And I think this is, uh, something that was a surprisingly a major theme at Oracle Cloud world.
This is like, this is such a big deal now that you have, you know, major cloud database companies looking at how can we further the cause of better cyber security. And, you know, ultimately, uh, hopefully it will make a difference that we're just getting smarter about things like app-based security as well as biometrics just becoming more mainstream, more accessible, that uh, people will embrace it on a, a broader basis to cut down, uh, you know, just that to FB and uh, email and text fraud. And I think, uh, it's reminiscent of the movie that recently came out the beekeeper and that would be, I think, a good brand name for any anti-fraud uh, solution out there.
Uh, because as we know in that movie, uh, somebody was defrauded to the point that the beekeeper had to unleash this wrath on the bad guys. And well ultimately, uh, it won't come to those types of ventures. They'll just be smarter before we had to resort to a beekeeper type of response.
And so, uh, with that, uh, thank you again Tom for joining, uh, the 5G Factor. I know we got some tech field days coming up on the horizon and I think that they're gonna be, uh, important once we're all of us. Yeah, absolutely.
I'm, I'm gonna be doing the next Field day event in about a week and a half. We're gonna be doing Security Field Day out in San Francisco. com to learn more about that.
And while you're there, check out some of the events that we just finished up, like AI Data Infrastructure Field Day. Uh, we also did, uh, a special networking field day exclusive event with Nokia and more. And then Ron, you and I'll get to see each other the first week of November for our next networking Field Day event.
It's looking like it's gonna be a jam packed one right now. Uh, yes, you took the words out of my mouth, the plugs, uh, networking field day in November. And so yes, that I think is just that it will have, uh, lots of great information and certainly looking forward to that.
And on that positive note, thank you everybody again for joining the 5G Factor. As you know, you can bookmark us on the Future Group website and again, on this note, have a safe 5G day everyone.



