On Manipulating Routing Table to Realize Redirect Attacks in O-RAN by Malicious xApp

Chi-heng Tseng, Cheng-Feng Hung, Bing-Kai Hong, Shin‐Ming Cheng · 2023

Open Radio Access Network (O-RAN) collaborates through Radio Access Network Intelligent Controllers (RICs) and their associated xAPPs to collect real-time status information from underlying RAN components. This allows dynamically changing the system resources to optimize the RAN's overall performance. Unfortunately, there's no auditing mechanism for xAPP uploads and no adherence to proper permission management protocols. In this article, we implement a working O-RAN platform and discover that the lack of mutual authentication mechanisms between services in the Near-Real-Time RIC and the improper permission settings for xAPPs pose a serious threat. By altering the original routing table and launching redirection attacks, malicious xAPPs could exploit this vulnerability and render the entire RAN inoperable. We provide a detailed report on how the attack was carried out and the impact it caused.

Read the paper · More papers on PaperTik