Seeing the Forest for the Trees: Understanding Security Hazards in the 3GPP Ecosystem through Intelligent Analysis on Change Requests

Seeing the Forest for the Trees: Understanding Security Hazards in the 3GPP Ecosystem through Intelligent Analysis on Change Requests
复制标题

DOI:
--
复制
发表时间:
2022
期刊:
2022 2nd International Conference on Algorithms, High Performance Computing and Artificial Intelligence (AHPCAI)
影响因子:
--
通讯作者:
Yi Chen;Di Tang;Yepeng Yao;Mingming Zha;Xiaofeng Wang;Xiaozhong Liu;Haixu Tang;Dongfang Zhao
Yi Chen;Di Tang;Yepeng Yao;Mingming Zha;Xiaofeng Wang;Xiaozhong Liu;Haixu Tang;Dongfang Zhao
中科院分区:
其他
文献类型:
--
作者:
Yi Chen;Di Tang;Yepeng Yao;Mingming Zha;Xiaofeng Wang;Xiaozhong Liu;Haixu Tang;Dongfang Zhao

文献摘要

相似文献

随着最近关于3GPP规范中的错误内容导致现实世界漏洞的报道,人们不仅关注规范,而且关注制造商和运营商维护和采用它们的方式。在本文中,我们报告了对这个3GPP生态系统的首次研究,旨在了解其安全隐患。我们的研究利用了414,488个变更请求(CR),这些变更请求记录了从规范和拟议变更中发现的问题,这为3GPP生态系统的安全保证提供了有价值的信息。分析这些CR受到寻找安全相关CR(SR-CR)的挑战的阻碍,即使是人类专家也无法轻松建立其安全连接。为了识别它们,我们开发了一种新的NLP/ML管道,该管道利用一小组正标记的CR来恢复1,270个高置信度SR-CR。我们对它们的测量揭示了规范错误及其原因的严重后果,包括设计错误和演示问题,特别是在安全相关内容中不一致的描述(未对齐)的普遍性。同样重要的是发现了3GPP生态系统固有的安全漏洞,该生态系统在规范修复和相关系统修补之前很久就发布了SR-CR。这就打开了一个“攻击窗口”,时间可能长达11年!令人遗憾的是,我们发现最近报告的一些漏洞
With the recent report of erroneous content in 3GPP specifications leading to real-world vulnerabilities, attention has been drawn to not only the specifications but also the way they are maintained and adopted by manufacturers and carriers. In this paper, we report the first study on this 3GPP ecosystem, for the purpose of understanding its security hazards. Our research leverages 414,488 Change Requests (CRs) that document the problems discovered from specifications and proposed changes, which provides valuable information about the security assurance of the 3GPP ecosystem. Analyzing these CRs is impeded by the challenge in finding security-relevant CRs (SR-CRs), whose security connections cannot be easily established by even human experts. To identify them, we developed a novel NLP/ML pipeline that utilizes a small set of positively labeled CRs to recover 1,270 high-confidence SR-CRs. Our measurement on them reveals serious consequences of specification errors and their causes, including design errors and presentation issues, particularly the pervasiveness of inconsistent descriptions ( misalignment ) in security-relevant content. Also important is the discovery of a security weakness inherent to the 3GPP ecosystem, which publishes an SR-CR long before the specification has been fixed and related systems have been patched. This opens an “attack window”, which can be as long as 11 years! Interest-ingly, we found that some recently reported vulnerabilities