Data-plane signaling in cellular IoT: attacks and defense

Data-plane signaling in cellular IoT: attacks and defense
复制标题

DOI:
10.1145/3447993.3483255
复制
发表时间:
2021-10
期刊:
Proceedings of the 27th Annual International Conference on Mobile Computing and Networking
影响因子:
--
通讯作者:
Zhaowei Tan;Boyan Ding;Jinghao Zhao;Yunqi Guo;Songwu Lu
Zhaowei Tan;Boyan Ding;Jinghao Zhao;Yunqi Guo;Songwu Lu
中科院分区:
其他
文献类型:
--
作者:
Zhaowei Tan;Boyan Ding;Jinghao Zhao;Yunqi Guo;Songwu Lu

文献摘要

相似文献

在本文中,我们设计了利用蜂窝物联网网络(即NB-IoT和Cat-M)中未受保护的数据平面信令的新攻击。我们发现,尽管在控制平面信令和数据平面分组转发上部署了安全机制,但新的数据平面信令攻击仍然是可行的。这种攻击表现出多种攻击形式,而不仅仅是简单的数据包爆破、拒绝服务(DoS)威胁,包括位置隐私泄露、数据包传递环路、延长数据传递、吞吐量限制、无线电资源耗尽和连接重置。我们的测试平台评估和运营网络验证证实了可行性。在3GPP C-IoT标准框架内,我们进一步提出了一种新的防御解决方案。
In this paper, we devise new attacks exploiting the unprotected data-plane signaling in cellular IoT networks (aka both NB-IoT and Cat-M). We show that, despite the deployed security mechanisms on both control-plane signaling and data-plane packet forwarding, novel data-plane signaling attacks are still feasible. Such attacks exhibit a variety of attack forms beyond simplistic packet-blasting, denial-of-service (DoS) threats, including location privacy breach, packet delivery loop, prolonged data delivery, throughput limiting, radio resource draining, and connection reset. Our testbed evaluation and operational network validation have confirmed the viability. We further propose a new defense solution within the 3GPP C-IoT standard framework.