AI 中文总结
研究5G NR中利用边信道的跨层服务质量拒绝攻击,提出DoSQ协议感知攻击,通过解码DCI注入干扰,跨层分类器估计受害用户吞吐量状态趋势,实验表明可降目标吞吐量50%,还提出对策并进行了实证测量。
AI 中文摘要
第三代合作伙伴计划(3GPP)的第五代新无线电(5G NR)对于支持关键任务服务至关重要。然而,5G系统容易受到智能干扰攻击,这种攻击可传播到运行在这些网络之上的应用程序(即跨层)。5G基站通过空中接口向合法用户设备广播资源调度信息,通常认为仅此表面信息不会透露有关用户设备的有用信息。但我们表明,利用下行控制信息(DCI)足以通过推断应用层吞吐量(即通过边信道分析)来降低应用层服务质量,即服务质量拒绝(DoSQ)。因此,我们提出了DoSQ,这是一种协议感知攻击,它解码每个时隙的DCI,以便在同一1毫秒时隙内向受害用户设备的物理资源块(PRB)注入干扰,同时跨层分类器仅根据DCI特征估计受害用户的吞吐量状态和趋势,而无需观察单个加密字节。在针对YouTube直播的专用5G NR测试平台上进行评估时,DoSQ在稀疏命中率下可将目标的吞吐量降低多达50%,而位于同一位置的非目标用户设备基本不受影响。此外,分类器在攻击即时置信度的前1%时达到0.87的精度,比基本速率提高了4.21倍。此外,我们提出了一种同步信号块频率-时间跳变对策,增加了攻击者的重新同步成本。结果是首次对任何协议感知对手都可利用的无线到应用边信道进行了实证测量。
英文摘要
The 3rd Generation Partnership Project (3GPP)'s Fifth Generation New Radio (5G NR) is critical to supporting mission-critical services. However, 5G systems are vulnerable to smart jamming attacks that can propagate to applications running on top of these networks (i.e., cross-layer). The 5G gNB broadcasts resource scheduling information for the legitimate UEs over the air interface, with a prevailing assumption that this surface alone reveals nothing useful about a user device. However, we show that using the Downlink Control Information (DCI) is sufficient to degrade Application layer service quality, i.e., Denial of Service Quality (DoSQ), by inferring the Application layer Goodput (i.e., via side-channel analysis). Therefore, we present DoSQ, a protocol-aware attack that decodes per-slot DCI to inject interference onto the victim UE's Physical Resource Blocks (PRBs) within the same 1 ms slot, while a cross-layer classifier estimates the victim's Goodput state and trend from DCI features alone, without observing a single encrypted byte. Evaluated on a private 5G NR testbed against YouTube Live, DoSQ drives the target's Goodput down by up to 50% at sparse hit-rates, while a co-located non-target UE remains largely unaffected. Moreover, the classifier achieves a precision of 0.87 at the top 1% of attack-now confidence, a 4.21 times lift over the base rate. Furthermore, we propose an SSB frequency-time-hopping countermeasure that increases the attacker's resynchronization cost. The result is the first empirical measurement of a radio-to-application side channel that any protocol-aware adversary can exploit.
Comments12 pages, 6 figures. Accepted at the 2026 IEEE Conference on Communications and Network Security (CNS)