首页> 外文会议>IEEE Symposium on Security and Privacy >Touching the Untouchables: Dynamic Security Analysis of the LTE Control Plane
【24h】

Touching the Untouchables: Dynamic Security Analysis of the LTE Control Plane

机译:碰碰不到的人:LTE控制平面的动态安全性分析

获取原文

摘要

This paper presents our extensive investigation of the security aspects of control plane procedures based on dynamic testing of the control components in operational Long Term Evolution (LTE) networks. For dynamic testing in LTE networks, we implemented a semi-automated testing tool, named LTEFuzz, by using open-source LTE software over which the user has full control. We systematically generated test cases by defining three basic security properties by closely analyzing the standards. Based on the security property, LTEFuzz generates and sends the test cases to a target network, and classifies the problematic behavior by only monitoring the device-side logs. Accordingly, we uncovered 36 vulnerabilities, which have not been disclosed previously. These findings are categorized into five types: Improper handling of (1) unprotected initial procedure, (2) crafted plain requests, (3) messages with invalid integrity protection, (4) replayed messages, and (5) security procedure bypass. We confirmed those vulnerabilities by demonstrating proof-of-concept attacks against operational LTE networks. The impact of the attacks is to either deny LTE services to legitimate users, spoof SMS messages, or eavesdrop/manipulate user data traffic. Precise root cause analysis and potential countermeasures to address these problems are presented as well. Cellular carriers were partially involved to maintain ethical standards as well as verify our findings in commercial LTE networks.
机译:本文基于对运营长期演进(LTE)网络中控制组件的动态测试,对控制平面过程的安全性方面进行了广泛的研究。对于LTE网络中的动态测试,我们通过使用开源LTE软件来实施半自动化测试工具,该工具名为LTEFuzz,用户可以对其进行完全控制。我们通过仔细分析标准定义了三个基本的安全属性,系统地生成了测试用例。基于安全属性,LTEFuzz生成测试案例并将其发送到目标网络,并仅通过监视设备端日志来对有问题的行为进行分类。因此,我们发现了36​​个漏洞,这些漏洞以前没有公开。这些发现可分为五类:(1)未受保护的初始过程的不当处理;(2)精心设计的简单请求;(3)具有无效完整性保护的消息;(4)重播的消息;以及(5)安全过程绕过。我们通过演示针对运营LTE网络的概念验证攻击来证实了这些漏洞。攻击的影响是拒绝向合法用户提供LTE服务,欺骗SMS消息或窃听/操纵用户数据流量。还介绍了精确的根本原因分析和解决这些问题的潜在对策。蜂窝运营商部分参与维护道德标准以及验证我们在商用LTE网络中的发现。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号