[论文解读] 5G System Security Analysis
本文采用STRIDE威胁模型对5G网络进行了系统的风险分析,识别出非独立(NSA)和独立(SA)5G架构中的12个关键威胁场景。研究评估了从4G继承而来的安全弱点,尤其是在NSA部署中,针对无线接入、核心网络功能和密钥管理中的漏洞提出了缓解措施,强调了端到端加密和强认证机制在保护用户隐私和系统完整性方面的重要性。
Fifth generation mobile networks (5G) are currently being deployed by mobile operators around the globe. 5G acts as an enabler for various use cases and also improves the security and privacy over 4G and previous network generations. However, as recent security research has revealed, the standard still has security weaknesses that may be exploitable by attackers. In addition, the migration from 4G to 5G systems is taking place by first deploying 5G solutions in a non-standalone (NSA) manner where the first step of the 5G deployment is restricted to the new radio aspects of 5G, while the control of the user equipment is still based on 4G protocols, i.e. the core network is still the legacy 4G evolved packet core (EPC) network. As a result, many security vulnerabilities of 4G networks are still present in current 5G deployments. This paper presents a systematic risk analysis of standalone and non-standalone 5G networks. We first describe an overview of the 5G system specification and the new security features of 5G compared to 4G. Then, we define possible threats according to the STRIDE threat classification model and derive a risk matrix based on the likelihood and impact of 12 threat scenarios that affect the radio access and the network core. Finally, we discuss possible mitigations and security controls. Our analysis is generic and does not account for the specifics of particular 5G network vendors or operators. Further work is required to understand the security vulnerabilities and risks of specific 5G implementations and deployments.
研究动机与目标
- 分析5G网络的安全态势,特别关注保留传统4G核心网络的非独立(NSA)部署。
- 使用STRIDE威胁分类模型对5G系统中的威胁进行识别和评估,涵盖无线接入和核心网络组件。
- 评估4G安全弱点在5G NSA部署中持续存在所带来的影响,特别是针对认证、密钥管理和加密机制。
- 为识别出的威胁提出实用的缓解措施和安全控制,包括端到端加密、安全启动机制和网络功能加固。
- 突出在低功耗M2M和超可靠低时延通信(URLLC)场景中的风险,其中用户干预有限,安全控制可能被削弱。
提出的方法
- 应用STRIDE威胁模型(欺骗、篡改、抵赖、信息泄露、拒绝服务、权限提升)对5G系统中的12个威胁场景进行分类。
- 将威胁场景映射到具体的5G网络组件,包括UICC、gNB、5GC网络功能以及N2、N3和N4等接口。
- 基于每种威胁场景的可能性和影响评分构建风险矩阵,采用对可利用性和系统影响的定性评估。
- 评估5G中的加密机制,包括AES、ECDH、ECIES和AEAD,并评估其在NAS和RRC层的实现。
- 分析IPSec和安全启动在保护网络功能间通信方面的作用,特别是在虚拟化5GC环境中。
- 提出使用SDR测试平台和配备仪器的用户设备(UE)进行验证的方法,以评估完整性保护和加密等安全控制在实际部署中的实现情况。
实验结果
研究问题
- RQ1由于依赖传统EPC核心网络,4G安全弱点在5G非独立(NSA)部署中持续存在的程度如何?
- RQ2与4G相比,5G新功能(如网络切片和虚拟化网络功能)如何引入新型攻击向量?
- RQ3通过gNB、UE或5GC网络功能中的硬件或软件漏洞进行密钥提取攻击的风险影响有多大?
- RQ4当前5G安全控制(如NAS和RRC完整性保护)在防止身份泄露和追踪方面的有效性如何?
- RQ5运营商控制的加密和完整性设置在真实5G部署中对用户隐私和数据机密性有何影响?
主要发现
- 许多5G NSA部署仍易受4G时代威胁的影响,例如IMEI/PEI追踪和认证密钥泄露,原因在于持续使用EPC核心网络。
- 若未正确实现硬件安全模块(HSM)或安全启动机制,设备密钥提取(TS_03)和gNB固件被攻破(TS_08)等威胁场景是可行的。
- 控制平面消息(如NAS和RRC)缺乏端到端加密和完整性保护,即使用户平面数据已加密,仍可能导致用户身份追踪和欺骗。
- 运营商可能为提升性能而禁用安全控制(如NAS完整性保护),从而增加IMEI暴露和用户追踪的风险。
- 仅依赖物理网络安全性保护网络功能间通信的系统易受中间人攻击,尤其在未强制实施IPSec时。
- 验证真实网络中安全控制的实现需要使用基于SDR的测试UE和配备仪器的网络探测器进行主动测试,以检测配置错误和缺失保护措施。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。