From 5G Sniffing to Harvesting Leakages of Privacy-Preserving Messengers
Norbert Ludant, Pieter Robyns, Guevara Noubir
摘要
We present the first open-source tool capable of efficiently sniffing 5G control channels, 5GSniffer and demonstrate its potential to conduct attacks on users privacy. 5GSniffer builds on our analysis of the 5G RAN control channel exposing side-channel leakage. We note that decoding the 5G control channels is significantly more challenging than in LTE, since part of the information necessary for decoding is provided to the UEs over encrypted channels. We devise a set of techniques to achieve real-time control channels sniffing (over three orders of magnitude faster than brute-forcing). This enables, among other things, to retrieve the Radio Network Temporary Identifiers (RNTIs) of all users in a cell, and perform traffic analysis. To illustrate the potential of our sniffer, we analyse two privacy-focused messengers, Signal and Telegram. We identify privacy leaks that can be exploited to generate stealthy traffic to a target user. When combined with 5GSniffer, it enables stealthy exposure of the presence of a target user in a given location (solely based on their phone number), by linking the phone number to the RNTI. It also enables traffic analysis of the target user. We evaluate the attacks and our sniffer, demonstrating nearly 100% accuracy within 30 seconds of attack initiation.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper9
- CloudRIC: Open Radio Access Network (O-RAN) Virtualization with Shared Heterogeneous ComputingLeonardo Lo Schiavo, Gines Garcia-Aviles, Andres Garcia-Saavedra, Marco Gramaglia 等MobiCom 2024 · 被引用 25 次
- Demystifying Privacy in 5G Stand Alone NetworksStavros Eleftherakis, Timothy Otim, Giuseppe Santaromita, Almudena Díaz-Zayas 等MobiCom 2024 · 被引用 10 次
- YinYangRAN: Resource Multiplexing in GPU-Accelerated Virtualized RANsLeonardo Lo Schiavo, Jose A. Ayala-Romero, Andres Garcia-Saavedra, Marco Fiore 等INFOCOM 2024 · 被引用 10 次
- Deep Learning-based Modulation Classification of Practical OFDM Signals for Spectrum SensingByungjun Kim, Christoph F. Mecklenbräuker, Peter GerstoftINFOCOM 2024 · 被引用 7 次
- RANBooster: Democratizing advanced cellular connectivity through fronthaul middleboxesXenofon Foukas, Tenzin Samten Ukyab, Bozidar Radunovic, Sylvia Ratnasamy 等SIGCOMM 2025 · 被引用 4 次
它引用的顶会 Paper12
- A Formal Analysis of 5G AuthenticationDavid A. Basin, Jannik Dreier, Lucca Hirschi, Sasa Radomirovic 等CCS 2018 · 被引用 428 次
- Practical Attacks Against Privacy and Availability in 4G/LTE Mobile Communication SystemsAltaf Shaik, Jean-Pierre Seifert, Ravishankar Borgaonkar, N. Asokan 等NDSS 2016 · 被引用 342 次
- LTEInspector: A Systematic Approach for Adversarial Testing of 4G LTESyed Rafiul Hussain, Omar Chowdhury, Shagufta Mehnaz, Elisa BertinoNDSS 2018 · 被引用 225 次
- Breaking LTE on Layer TwoDavid Rupprecht, Katharina Kohls, Thorsten Holz, Christina PöpperS&P 2019 · 被引用 219 次
- Touching the Untouchables: Dynamic Security Analysis of the LTE Control PlaneHongil Kim, Jiho Lee, Eunkyu Lee, Yongdae KimS&P 2019 · 被引用 174 次
相关 Paper
- SNI5GECT: A Practical Approach to Inject aNRchy into 5G NRShijie Luo, Matheus E. Garbelini, Sudipta Chattopadhyay, Jianying ZhouUSENIX Security 2025
- 5GDescrambler: Locating, Descrambling, and Decoding 5G Scheduling InformationFritz Windisch, Thorsten StrufeCCS 2026
- Hope of Delivery: Extracting User Locations From Mobile Instant MessengersTheodor Schnitzler, Katharina Kohls, Evangelos Bitsikas, Christina PöpperNDSS 2023
- A Stealthy Location Identification Attack Exploiting Carrier Aggregation in Cellular NetworksNitya Lakshmanan, Nishant Budhdev, Min Suk Kang, Mun Choon Chan 等USENIX Security 2021 · 被引用 21 次
- LTrack: Stealthy Tracking of Mobile Phones in LTEMartin Kotuliak, Simon Erni, Patrick Leu, Marc Röschlin 等USENIX Security 2022
