Security and Privacy for Network Slicing and Slice-as-a-Service in 5G-Advanced and 6G Networks
Ehigiator Iyobor Egho-Promise, Ekereuke Udoh, Edita Gashi, Augustine O. Nwajana, Bamidele Ola, Hewa Balisane, Vijay ChennareddyThe shift from fifth-generation (5G) systems to new architectures based on the sixth-generation (6G) paradigm changes network slicing from a semi-static resource partitioning model to a fully dynamic Slice-as-a-Service (SlaaS) model. This model is characterized by instantiating, scaling, migrating, and terminating slices using cloud-native orchestration frameworks, which offer considerable operational flexibility at the cost of increased attack surface. The current security design, which is mainly based on authentication-based security and conventional isolation design principles that are standardized by the 3rd Generation Partnership Project (3GPP), fails to consider the risks of runtime behavioral drift, cross-slice lateral movement, as well as metadata inference in a multi-tenant environment of SlaaS in 5G-Advanced and 6G networks. This paper introduces Trust-Aware Security Orchestration (TASO), a probabilistic, runtime-responsive security scheme for SlaaS in 5G-Advanced and 6G. The TASO models treat cut integrity as a posterior trust probability based on multidimensional telemetry flows. Trust is updated via Bayesian inference, and its temporal dynamics are studied using the Markov stability model to ensure convergence and bounded behavior. The structure also integrates entropy-based monitoring controls to reduce privacy leakage during telemetry collection. Large-scale multi-tenant simulations with NS-3 yield statistically significant results compared to baselines of statistically isolated and machine-learning-only. TASO has a 94.6% detection rate, 96.2% smaller isolation attacks, 93.6% smaller inference leaks, and SLA-conformant latency. The findings confirm that probabilistic trust modeling is a potential, theoretically sound security mechanism for dynamic slicing in future 6G systems.