Touching the Untouchables: Dynamic Security Analysis of the LTE Control Plane
Hongil Kim, Jiho Lee, Eunkyu Lee, Yongdae Kim
摘要
This paper presents our extensive investigation of the security aspects of control plane procedures based on dynamic testing of the control components in operational Long Term Evolution (LTE) networks. For dynamic testing in LTE networks, we implemented a semi-automated testing tool, named LTEFuzz, by using open-source LTE software over which the user has full control. We systematically generated test cases by defining three basic security properties by closely analyzing the standards. Based on the security property, LTEFuzz generates and sends the test cases to a target network, and classifies the problematic behavior by only monitoring the device-side logs. Accordingly, we uncovered 36 vulnerabilities, which have not been disclosed previously. These findings are categorized into five types: Improper handling of (1) unprotected initial procedure, (2) crafted plain requests, (3) messages with invalid integrity protection, (4) replayed messages, and (5) security procedure bypass. We confirmed those vulnerabilities by demonstrating proof-of-concept attacks against operational LTE networks. The impact of the attacks is to either deny LTE services to legitimate users, spoof SMS messages, or eavesdrop/manipulate user data traffic. Precise root cause analysis and potential countermeasures to address these problems are presented as well. Cellular carriers were partially involved to maintain ethical standards as well as verify our findings in commercial LTE networks.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper41
- 5GReasoner: A Property-Directed Security and Privacy Analysis Framework for 5G Cellular Network ProtocolSyed Rafiul Hussain, Mitziu Echeverria, Imtiaz Karim, Omar Chowdhury 等CCS 2019 · 被引用 188 次
- DriveFuzz: Discovering Autonomous Driving Bugs through Driving Quality-Guided FuzzingSeulbae Kim, Major Liu, Junghwan John Rhee, Yuseok Jeon 等CCS 2022 · 被引用 65 次
- AdaptOver: adaptive overshadowing attacks in cellular networksSimon Erni, Martin Kotuliak, Patrick Leu, Marc Roeschlin 等MobiCom 2022 · 被引用 52 次
- Noncompliance as Deviant Behavior: An Automated Black-box Noncompliance Checker for 4G LTE Cellular DevicesSyed Rafiul Hussain, Imtiaz Karim, Abdullah Al Ishtiaq, Omar Chowdhury 等CCS 2021 · 被引用 41 次
- Hermes: Unlocking Security Analysis of Cellular Network Protocols by Synthesizing Finite State Machines from Natural Language SpecificationsAbdullah Al Ishtiaq, Sarkar Snigdha Sarathi Das, Syed Md. Mukit Rashid, Ali Ranjbar 等USENIX Security 2024 · 被引用 28 次
它引用的顶会 Paper3
- Practical Attacks Against Privacy and Availability in 4G/LTE Mobile Communication SystemsAltaf Shaik, Jean-Pierre Seifert, Ravishankar Borgaonkar, N. Asokan 等NDSS 2016 · 被引用 342 次
- LTEInspector: A Systematic Approach for Adversarial Testing of 4G LTESyed Rafiul Hussain, Omar Chowdhury, Shagufta Mehnaz, Elisa BertinoNDSS 2018 · 被引用 225 次
- Breaking LTE on Layer TwoDavid Rupprecht, Katharina Kohls, Thorsten Holz, Christina PöpperS&P 2019 · 被引用 219 次
相关 Paper
- DoLTEst: In-depth Downlink Negative Testing Framework for LTE DevicesCheolJun Park, Sangwook Bae, Beomseok Oh, Jiho Lee 等USENIX Security 2022
- RANsacked: A Domain-Informed Approach for Fuzzing LTE and 5G RAN-Core InterfacesNathaniel Bennett, Weidong Zhu, Benjamin Simon, Ryon Kennedy 等CCS 2024 · 被引用 9 次
- Stateful Analysis and Fuzzing of Commercial Baseband FirmwareAli Ranjbar, Tianchang Yang, Kai Tu, Saaman Khalilollahi 等S&P 2025
- CITesting: Systematic Testing of Context Integrity Violations in LTE Core NetworksMincheol Son, Kwangmin Kim, Beomseok Oh, CheolJun Park 等CCS 2025
- Instructions Unclear: Undefined Behaviour in Cellular Network SpecificationsDaniel Klischies, Moritz Schloegel, Tobias Scharnowski, Mikhail Bogodukhov 等USENIX Security 2023
