5G-Spector: An O-RAN Compliant Layer-3 Cellular Attack Detection Service

5G-Spector: An O-RAN Compliant Layer-3 Cellular Attack Detection Service
复制标题

DOI:
10.14722/ndss.2024.24527
复制
发表时间:
2024
期刊:
Proceedings 2024 Network and Distributed System Security Symposium
影响因子:
--
通讯作者:
Haohuang Wen;Phillip Porras;V. Yegneswaran;Ashish Gehani;Zhiqiang Lin
Haohuang Wen;Phillip Porras;V. Yegneswaran;Ashish Gehani;Zhiqiang Lin
中科院分区:
其他
文献类型:
--
作者:
Haohuang Wen;Phillip Porras;V. Yegneswaran;Ashish Gehani;Zhiqiang Lin

文献摘要

相似文献

- 在过去的几年中,移动的安全社区已经发现了各种各样的针对链接和会话建立协议的漏洞。这些漏洞可以在软件定义无线电(SDR)上实现,这些软件定义无线电(SDR)会破坏、欺骗或淹没第3层(L3)消息,从而损害安全性和隐私性,这些安全性和隐私性仍然适用于最新的5G移动的网络标准。有趣的是,与前几代封闭的(专有的)移动的网络基础设施不同,5G网络正在向更智能、基于开放标准的完全可互操作的移动的架构迁移,称为Open RAN或O-RAN。将移动的基础设施过渡到软件定义的架构抽象对INFOSEC社区来说意义重大,因为它允许我们通过以安全为中心的协议审计服务和漏洞检测来扩展移动的数据平面和控制平面。基于这种设计,我们提出了5G-S PECTOR,这是第一个用于检测O-RAN上广泛的L3协议漏洞的综合框架。它具有一个名为M OBI F LOW的新型安全审计流,可以传输细粒度的蜂窝网络遥测,以及一个名为M OBIE X PERT的可编程控制平面xApp。我们提出了一个可扩展的原型5G-S PECTOR,它可以实时检测7种类型的蜂窝攻击。我们还展示了它的可扩展性,以11个未知的攻击以及31个真实世界的蜂窝跟踪,有效的性能(高精度,无误报)和低(< 2%的CPU,< 100 MB的内存)开销。
—Over the past several years, the mobile security community has discovered a wide variety of exploits against link and session-establishment protocols. These exploits can be implemented on software-defined radios (SDRs) that disrupt, spoof, or flood layer-3 (L3) messages to compromise security and privacy, which still apply to the latest 5G mobile network standard. Interestingly, unlike the prior generations of closed (proprietary) mobile network infrastructures, 5G networks are migrating toward a more intelligent and open-standards-based fully interoperable mobile architecture, called Open RAN or O-RAN . The implications of transitioning mobile infrastructures to a software-defined architectural abstraction are quite significant to the INFOSEC community, as it allows us to extend the mobile data plane and control plane with security-focused protocol auditing services and exploit detection. Based on this design, we present 5G-S PECTOR , the first comprehensive framework for detecting the wide spectrum of L3 protocol exploits on O-RAN. It features a novel security audit stream called M OBI F LOW that transfers fine-grained cellular network telemetry, and a programmable control-plane xApp called M OBIE X PERT . We present an extensible prototype of 5G-S PECTOR which can detect 7 types of cellular attacks in real-time. We also demonstrate its scalability to 11 unknown attacks as well as 31 real-world cellular traces, with effective performance (high accuracy, no false alarms) and low ( < 2% CPU, < 100 MB memory) overhead.