Logic Gone Astray: A Security Analysis Framework for the Control Plane Protocols of 5G Basebands
Kai Tu, Abdullah Al Ishtiaq, Syed Md. Mukit Rashid, Yilu Dong, Weixuan Wang, Tianwei Wu, Syed Rafiul Hussain
摘要
We develop 5GBaseChecker-an efficient, scalable, and dynamic security analysis framework based on differential testing for analyzing 5G basebands' control plane protocol interactions. 5GBaseChecker first captures basebands' protocol behaviors as a finite state machine (FSM) through blackbox automata learning. To facilitate efficient learning and improve scalability, 5GBaseChecker introduces novel hybrid and collaborative learning techniques. 5GBaseChecker then identifies input sequences for which the extracted FSMs provide deviating outputs. Finally, 5GBaseChecker leverages these deviations to efficiently identify the security properties from specifications and use those to triage if the deviations found in 5G basebands violate any properties. We evaluated 5GBaseChecker with 17 commercial 5G basebands and 2 open-source UE implementations and uncovered 22 implementation-level issues, including 13 exploitable vulnerabilities and 2 interoperability issues.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper11
- Finding SSH Strict Key Exchange Violations by State LearningFabian Bäumer, Marcel Maehren, Marcus Brinkmann, Jörg SchwenkCCS 2025 · 被引用 1 次
- SNI5GECT: A Practical Approach to Inject aNRchy into 5G NRShijie Luo, Matheus E. Garbelini, Sudipta Chattopadhyay, Jianying ZhouUSENIX Security 2025
- Stateful Analysis and Fuzzing of Commercial Baseband FirmwareAli Ranjbar, Tianchang Yang, Kai Tu, Saaman Khalilollahi 等S&P 2025
- CoreCrisis: Threat-Guided and Context-Aware Iterative Learning and Fuzzing of 5G Core NetworksYilu Dong, Tianchang Yang, Abdullah Al Ishtiaq, Syed Md. Mukit Rashid 等USENIX Security 2025
- LogicEval: A Systematic Framework for Evaluating Automated Repair Techniques for Logical Vulnerabilities in Real-World SoftwareSyed Md. Mukit Rashid, Abdullah Al Ishtiaq, Kai Tu, Yilu Dong 等ACL 2026
它引用的顶会 Paper20
- A Formal Analysis of 5G AuthenticationDavid A. Basin, Jannik Dreier, Lucca Hirschi, Sasa Radomirovic 等CCS 2018 · 被引用 428 次
- Practical Attacks Against Privacy and Availability in 4G/LTE Mobile Communication SystemsAltaf Shaik, Jean-Pierre Seifert, Ravishankar Borgaonkar, N. Asokan 等NDSS 2016 · 被引用 342 次
- LTEInspector: A Systematic Approach for Adversarial Testing of 4G LTESyed Rafiul Hussain, Omar Chowdhury, Shagufta Mehnaz, Elisa BertinoNDSS 2018 · 被引用 225 次
- 5GReasoner: A Property-Directed Security and Privacy Analysis Framework for 5G Cellular Network ProtocolSyed Rafiul Hussain, Mitziu Echeverria, Imtiaz Karim, Omar Chowdhury 等CCS 2019 · 被引用 188 次
- Touching the Untouchables: Dynamic Security Analysis of the LTE Control PlaneHongil Kim, Jiho Lee, Eunkyu Lee, Yongdae KimS&P 2019 · 被引用 174 次
相关 Paper
- Noncompliance as Deviant Behavior: An Automated Black-box Noncompliance Checker for 4G LTE Cellular DevicesSyed Rafiul Hussain, Imtiaz Karim, Abdullah Al Ishtiaq, Omar Chowdhury 等CCS 2021 · 被引用 41 次
- Formal Analysis of Access Control Mechanism of 5G Core NetworkMujtahid Akon, Tianchang Yang, Yilu Dong, Syed Rafiul HussainCCS 2023 · 被引用 21 次
- 5GC-Fuzz: Finding Deep Stateful Vulnerabilities in 5G Core Network with Black-Box FuzzingYu Sun, Xinyu Liu, Qian Sun, Jiaming Wang 等INFOCOM 2025 · 被引用 5 次
- BaseSpec: Comparative Analysis of Baseband Software and Cellular Specifications for L3 ProtocolsEunsoo Kim, Dongkwan Kim, CheolJun Park, Insu Yun 等NDSS 2021
- BLEDiff: Scalable and Property-Agnostic Noncompliance Checking for BLE ImplementationsImtiaz Karim, Abdullah Al Ishtiaq, Syed Rafiul Hussain, Elisa BertinoS&P 2023
