Understanding Implicit Trust Errors in Core Carrier Networks through Multi-Agent Flaw Discovery and Analysis
Ziyu Lin, Ziting Wang, Xinfeng Li, Wei Dong, XiaoFeng Wang
摘要
Core network (CN) is at the center of a cellular system and was historically protected by physical isolation, but the shift to cloud-native deployments breaks this protection and introduces new attack interfaces. Indeed, from reported GitHub issues, we found that many security flaws within CNs can be attributed to blind trust underlying interactions across different CN components. Under such trust assumptions, one component may fail to properly verify the syntactic and semantic content of messages received from other internal components, and may also grant resources to requesters without validation of resource availability. These weaknesses, once coupled with the risks of exposing internal interfaces to unauthorized external parties, as observed in our research, will lead to serious consequences, including session hijacking and denial of services. In our research, we call these newly discovered weaknesses implicit trust errors or iTrue . To detect iTrues and understand their security impacts, we designed and implemented a multi-agent framework, dubbed iFinder . iFinder automatically analyzes and summarizes known security flaws, and uses them as ``seeds'' to detect related vulnerabilities from the CN simulators. To suppress hallucinations produced by large language models (LLMs), not only have we developed a Chain of Thought (CoT) reasoning to guide agents, but we also build an innovative strategy that cross-checks both 3GPP specifications and CN code to capture existing protection missed by the agents. Further, we developed a technique that uses LLMs to generate proof-of-concept (PoC) exploits for potential iTrues and iteratively refine the PoCs by automatically executing them against CN simulators and analyzing results. Running iFinder on 7 prominent simulators, we discovered 84 previously unknown vulnerabilities. Among them 70 have already been confirmed with 40 CVE assignments already awarded. Our findings highlight the pervasiveness of iTrue risks across the cellular core networks and the urgent needs for elevated protection within the original trust domains. We plan to make the service of iFinder publicly available to help enhance the security qualities of cellular core networks.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper30
- Chain-of-Thought Prompting Elicits Reasoning in Large Language ModelsJason Wei, Xuezhi Wang, Dale Schuurmans, Maarten Bosma 等NeurIPS 2022 · 被引用 22,562 次
- Evaluating Fuzz TestingGeorge Klees, Andrew Ruef, Benji Cooper, Shiyi Wei 等CCS 2018 · 被引用 753 次
- LTEInspector: A Systematic Approach for Adversarial Testing of 4G LTESyed Rafiul Hussain, Omar Chowdhury, Shagufta Mehnaz, Elisa BertinoNDSS 2018 · 被引用 225 次
- Breaking LTE on Layer TwoDavid Rupprecht, Katharina Kohls, Thorsten Holz, Christina PöpperS&P 2019 · 被引用 219 次
- PentestGPT: Evaluating and Harnessing Large Language Models for Automated Penetration TestingGelei Deng, Yi Liu, Víctor Mayoral Vilches, Peng Liu 等USENIX Security 2024 · 被引用 186 次
相关 Paper
- Bookworm Game: Automatic Discovery of LTE Vulnerabilities Through Documentation AnalysisYi Chen, Yepeng Yao, XiaoFeng Wang, Dandan Xu 等S&P 2021 · 被引用 57 次
- Instructions Unclear: Undefined Behaviour in Cellular Network SpecificationsDaniel Klischies, Moritz Schloegel, Tobias Scharnowski, Mikhail Bogodukhov 等USENIX Security 2023
- RANsacked: A Domain-Informed Approach for Fuzzing LTE and 5G RAN-Core InterfacesNathaniel Bennett, Weidong Zhu, Benjamin Simon, Ryon Kennedy 等CCS 2024 · 被引用 9 次
- CITesting: Systematic Testing of Context Integrity Violations in LTE Core NetworksMincheol Son, Kwangmin Kim, Beomseok Oh, CheolJun Park 等CCS 2025
- Intender: Fuzzing Intent-Based Networking with Intent-State Transition GuidanceJiwon Kim, Benjamin E. Ujcich, Dave TianUSENIX Security 2023
