发表机构
i2CAT Foundation; University of Murcia; NEC Laboratories Europe; ICREA(i2CAT基金会; 穆尔西亚大学; NEC欧洲实验室; 加泰罗尼亚高级研究院)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
5G-Shark通过操纵小区重选准则建立攻击观察点,区分协议设计缺陷与实现差距,评估商用5G网络隐私风险,并发现临时标识符可关联导致用户可被持续跟踪。
AI 中文摘要
第五代移动网络在标准化时被明确要求弥合长期存在的隐私和安全漏洞,强制要求隐藏用户的永久身份、抵抗跨代降级攻击以及防止位置跟踪。然而,要评估这些保证在运营网络中是否成立,需要区分先前研究未加区分且未在真实环境中评估的两种残余暴露来源:协议设计局限性(即使针对完全符合规范的部署也可被利用)和实现差距(源于不完整或不合规的实现)。我们提出了5G-Shark,一种安全评估工具和方法论,它将合法的移动性过程转而用于对抗用户。5G-Shark不依赖主动干扰或畸形数据包注入,而是操纵标准化的小区重选准则,将目标用户设备拉入自建的恶意小区,从而以最小的服务中断建立攻击观察点。随后,所提出的方法论有效地执行必要的交互以暴露被测系统的安全风险,并将其分类到上述类别中。5G-Shark完全基于开源软件栈和软件定义无线电硬件构建,并针对商用5G独立组网部署进行评估,它请求用户标识符,通过精心构造的注册拒绝码强制无线接入技术降级,并诱导拒绝服务状态。对于每个攻击向量,我们将根本原因归因于协议设计或部署不合规。我们进一步提供了经验证据,表明在多个商用部署中,临时标识符以近乎连续的步长重新分配,使得连续值可关联,这一弱点即使在正确隐藏用户ID的情况下也能实现持续的用户跟踪。
英文摘要
The fifth generation of mobile networks was standardised with an explicit mandate to close long-standing privacy and security gaps, mandating the concealment of the subscriber's permanent identity, resistance to generational downgrade, and protection against location tracking. Assessing whether these guarantees hold in operational networks, however, requires separating two sources of residual exposure that prior studies do not distinguish and do not evaluate in the wild: protocol-design limitations, which remain exploitable even against a fully specification-compliant deployment, and implementation gaps, which arise from incomplete or non-compliant implementations. We present 5G-Shark, a security assessment tool and methodology that turns a legitimate mobility procedure against the subscriber. Rather than relying on active jamming or malformed-packet injection, 5G-Shark manipulates the standardised cell-reselection criterion to pull a target User Equipment onto a self-created rogue cell, establishing an attack vantage with minimal service disruption. Then, the proposed methodology effectively performs the required interactions to expose the security risks of the system under test, classifying them into the aforementioned categories. Built solely from open-source stacks and Software Defined Radio hardware and evaluated against commercial 5G Standalone deployments, 5G-Shark requests subscriber identifiers, forces Radio Access Technology downgrade via crafted Registration Reject codes, and induces denial-of-service states. For each vector, we attribute the root cause to protocol design or deployment non-compliance. We further provide empirical evidence that in several commercial deployments, temporary identifiers are re-allocated in near-sequential steps that keep successive values linkable, a weakness that enables persistent user tracking despite correct subscriber ID concealment.