arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

面向运营商赋能的5G无线接入网漏洞热修复技术

Towards Operator-Empowered Vulnerability Hotfixing for 5G Radio Access Networks

Dong Hyeok Kim, Xin Zhe Khooi, Hocheol Nam, Seungjin Baek, Mun Choon Chan, CheolJun Park, Min Suk Kang

arXiv 2608.30615首次发表:更新:

发表机构

KAIST; National University of Singapore; Kyung Hee University(韩国科学技术院; 新加坡国立大学; 庆熙大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

该研究提出Buckler框架,可在5G RAN部署临时可逆转热修复,经23篇论文验证其可覆盖64种攻击中的20种,在两个开源平台实现且效果良好,为RAN漏洞提供实用临时防御。

AI 中文摘要

蜂窝协议漏洞在标准组织、厂商和移动网络运营商(MNO)协调永久修复的过程中,可能持续数月甚至数年仍可被利用。我们提出了Buckler框架,使MNO能在漏洞暴露窗口期间,在其无线接入网(RAN)中部署临时、本地且可逆转的热修复。Buckler在标准化的L2/L3信道边界处放置可复用钩子,并提供一个封闭的有状态匹配-动作接口,包含DROP(丢弃)、MODIFY(修改)和RELEASE(放行)三种预防动作。我们评估这种受限设计是否能提供有效覆盖,且无需对现有RAN进行大量改动。从23篇论文中,我们识别出64种源于标准L2/L3协议行为的攻击,其中43种在RAN处存在可预防的干预点,我们为其中20种构建了Buckler热修复。所有20种热修复均使用相同的规则词汇,仅使用5个标准化信道钩子;未被支持的攻击暴露了RAN无法单独满足的端点依赖。我们在srsRAN和OpenAirInterface上实现了这5个钩子,改动微小且结构相似,并针对代表性可用性和隐私攻击验证了全部三种动作。这些结果确立了运营商赋能的热修复是一种实用且可移植的临时防御手段,并明确了仅靠RAN预防的架构局限。

英文摘要

Cellular protocol vulnerabilities can remain exploitable for months or years while standards bodies, vendors, and mobile network operators (MNOs) coordinate permanent fixes. We present Buckler, a framework that enables an MNO to deploy temporary, local, and reversible hotfixes in its radio access network (RAN) during this exposure window. Buckler places reusable hooks at standardized L2/L3 channel boundaries and exposes a closed, stateful match-action interface with three preventive actions: DROP, MODIFY, and RELEASE. We evaluate whether this bounded design provides useful coverage without requiring extensive changes to existing RANs. From 23 papers, we identify 64 attacks rooted in standard L2/L3 protocol behavior, of which 43 provide a preventive intervention point at the RAN, and we construct Buckler hotfixes for 20 of them. All 20 hotfixes use the same rule vocabulary and only five standardized channel hooks, while the unsupported attacks expose endpoint dependencies that a RAN cannot satisfy alone. We implement the five hooks on srsRAN and OpenAirInterface with small, structurally similar changes, and demonstrate all three actions against representative availability and privacy attacks. These results establish operator-empowered hotfixing as a practical and portable interim defense and delineate the architectural limits of RAN-only prevention.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑