Towards Automated Fuzzing of 4G/5G Protocol Implementations Over the Air

Page view(s)
47
Checked on Sep 20, 2024
Towards Automated Fuzzing of 4G/5G Protocol Implementations Over the Air
Title:
Towards Automated Fuzzing of 4G/5G Protocol Implementations Over the Air
Journal Title:
IEEE Globecom 2022
DOI:
Publication Date:
08 December 2022
Citation:
M. E. Garbelini, Z. Shang, S. Chattopadhyay, S. Sun, and E. Kurniawan, & Towards Automated Fuzzing of 4G/5G Protocol Implementations Over the Air,& IEEE Globecom 2022, pp. 1-7, Rio de Janeiro, Brazil, December 2022.
Abstract:
Recent rise in the mobile network communication vulnerabilities highlights the need for systematic security testing frameworks for communication protocols. In this paper, we propose a real-time framework to fully manipulate the 4G and 5G data-link and network communication to the base station (eNB/gNB). This is for experimenting and testing the security of data-link protocols such as Media Access Control (MAC), Radio Link Control (RLC), Packet Data Convergence Protocol (PDCP) and network protocols such as Radio Resource Control (RRC) and Non-access stratum (NAS). Although we focus on the base station, our framework is equally applicable for manipulating the communication to the user equipment (UE). An appealing feature of our framework is that it automatically constructs the protocol state machine during normal communication. This allows us to validate the response from the base station when it is subjected to unexpected packet sequences. Our framework also exposes an application programming interfaces (APIs) for designers to install custom attack scenarios. We have implemented our framework and used it to generate several (adversarial) scenarios that include injection of malformed and out-of-order packets as well as flooding certain packets. Our evaluation revealed crashes in OpenAirInterface (OAI) UE and gNB, as well as in Open5GS core network. Additionally, we guide our validation via the automatically constructed state machine and have caught most adversarial scenarios during our evaluation. We envision our proposed framework to provide the foundation for automated security testing of 4G/5G data-link protocol implementation.
License type:
Publisher Copyright
Funding Info:
This research / project is supported by the A*STAR Graduate Academy - SINGA
Grant Reference no. : NA

This research / project is supported by the National Research Foundation - National Satellite of Excellence in Trustworthy Software Systems
Grant Reference no. : NSOE-TSS2021-01

This research / project is supported by the National Research Foundation - National Satellite of Excellence in Trustworthy Software Systems
Grant Reference no. : NSOE-TSS2020-03
Description:
© 2022 IEEE. Personal use of this material is permitted. Permission from IEEE must be obtained for all other uses, in any current or future media, including reprinting/republishing this material for advertising or promotional purposes, creating new collective works, for resale or redistribution to servers or lists, or reuse of any copyrighted component of this work in other works.
ISBN:
978-1-7281-8104-2
Files uploaded:

File Size Format Action
a15-garbelini-final.pdf 1.58 MB PDF Request a copy