Invade the Walled Garden: Evaluating GTP Security in Cellular Networks
Yiming Zhang, Tao Wan, Yaru Yang, Haixin Duan, Yichen Wang, Jianjun Chen, Zixiang Wei, Xiang Li
Abstract
Cellular backhaul and core networks have traditionally been considered as Walled Garden, with their security ensured by physical isolation. Therefore, prior security studies primarily focused on radio access networks with limited treatment of backhaul and core network interfaces. In this paper, we performed a security evaluation of real-world GPRS Tunnelling Protocol (GTP) deployments. GTP is the fundamental protocol for user traffic management between base stations and core networks (inside the Walled Garden) from 3G to 5G, thus often assumed inaccessible and non-exploitable from the Internet. However, our study reveals for the first time the troubling state of GTP access control in real-world deployments. Aided by a semi-automated tool, our measurements discovered around 749,000 valid GTP hosts accessible via the public Internet, spanning across 1,176 service providers in 162 countries. Our results demonstrate potential exposure of mobile core network infrastructures to external threats. We then evaluated the attack surface of exposed GTP infrastructures, and found out that as many as 38 types of GTP messages can be misused to launch various attacks such as denial-of-service and session hijacking. Our experiments using open source 4G and 5G projects in isolated lab environments further confirm the feasibility of those GTP-based attacks, including remote hijacking of user traffic sent through cellular core networks. In addition to threats against cellular networks and their subscribers, exposed GTP devices could also be weaponized to launch large-scale reflective denial-of-services (RDoS) attacks. We hope our findings will increase awareness of GTP vulnerabilities among operators and the security community, highlighting the urgent need to further strengthen security in cellular core networks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 50405a3f-d548-4ed7-90d3-1ac07b9d3674Cited by top-tier papers3
- Uncovering Hidden Paths in 5G: Exploiting Protocol Tunneling and Network Boundary BridgingAltaf Shaik, Robert Jaschek, Jean-Pierre SeifertCCS 2025 · 1 citation
- Small Cell, Big Risk: A Security Assessment of 4G LTE Femtocells in the WildYaru Yang, Yiming Zhang, Tao Wan, Haixin Duan et al.NDSS 2026 · 1 citation
- Understanding Implicit Trust Errors in Core Carrier Networks through Multi-Agent Flaw Discovery and AnalysisZiyu Lin, Ziting Wang, Xinfeng Li, Wei Dong et al.USENIX Security 2026
Builds on20
- LTEInspector: A Systematic Approach for Adversarial Testing of 4G LTESyed Rafiul Hussain, Omar Chowdhury, Shagufta Mehnaz, Elisa BertinoNDSS 2018 · 225 citations
- Breaking LTE on Layer TwoDavid Rupprecht, Katharina Kohls, Thorsten Holz, Christina PöpperS&P 2019 · 219 citations
- 5GReasoner: A Property-Directed Security and Privacy Analysis Framework for 5G Cellular Network ProtocolSyed Rafiul Hussain, Mitziu Echeverria, Imtiaz Karim, Omar Chowdhury et al.CCS 2019 · 188 citations
- Touching the Untouchables: Dynamic Security Analysis of the LTE Control PlaneHongil Kim, Jiho Lee, Eunkyu Lee, Yongdae KimS&P 2019 · 174 citations
- Privacy Attacks to the 4G and 5G Cellular Paging Protocols Using Side Channel InformationSyed Rafiul Hussain, Mitziu Echeverria, Omar Chowdhury, Ninghui Li et al.NDSS 2019 · 160 citations
Related papers
- IMS is Not That Secure on Your 5G/4G PhonesJingwen Shi, Sihan Wang, Min-Yue Chen, Guan-Hua Tu et al.MobiCom 2024 · 5 citations
- 5G-Spector: An O-RAN Compliant Layer-3 Cellular Attack Detection ServiceHaohuang Wen, Phillip A. Porras, Vinod Yegneswaran, Ashish Gehani et al.NDSS 2024
- On the Criticality of Integrity Protection in 5G Fronthaul NetworksJiarong Xing, Sophia Yoo, Xenofon Foukas, Daehyeok Kim et al.USENIX Security 2024 · 15 citations
- Diffie-Hellman Picture Show: Key Exchange Stories from Commercial VoWiFi DeploymentsGabriel Karl Gegenhuber, Florian Holzbauer, Philipp É. Frenzel, Edgar R. Weippl et al.USENIX Security 2024 · 8 citations
- IMP4GT: IMPersonation Attacks in 4G NeTworksDavid Rupprecht, Katharina Kohls, Thorsten Holz, Christina PöpperNDSS 2020
