Demo Paper: Caught in my Radio Net - Experiment with Honeypots in Radio Access Networks

Nizar Kheir, Loay Abdelrazek, Daniel Cho · 2022

5G embraces digitalization and cloud-native support as two design principles, providing increased flexibility, faster delivery, and greater scalability to support purpose-built 5G networks. Such convergence between the Telco and IT domains has also expanded the attack surface facing the Telco industry. New attack vectors have made their way in, urging the Telco providers to explore new mechanisms to enhance security of their Radio and Core Network products. Honeypot systems are one example of such security mechanisms. They divert attackers away from the genuine assets to be protected, while sustaining long-lived interactions with them to learn more about their tactics. While honeypots have been extensively used in the IT security field, their application in the Telco filed is still faced with limitations that are inherent to the design and operation of Telco networks. We experiment the use of honeypots to enhance security of Radio Access Networks (RAN) against insider threats. We explore the security use-cases that can be supported by a honeypot operating within a Cloud-Native RAN environment. Then it introduces a novel way how honeypot systems can be implemented and operated within a Cloud-Native RAN setup and demonstrates its usage through selected attack scenarios.

Read the paper · More papers on PaperTik