On Manipulating Routing Table to Realize Redirect Attacks in O-RAN by Malicious xApp
Chi-heng Tseng, Cheng-Feng Hung, Bing-Kai Hong, Shin‐Ming Cheng · 2023
Open Radio Access Network (O-RAN) collaborates through Radio Access Network Intelligent Controllers (RICs) and their associated xAPPs to collect real-time status information from underlying RAN components. This allows dynamically changing the system resources to optimize the RAN's overall performance. Unfortunately, there's no auditing mechanism for xAPP uploads and no adherence to proper permission management protocols. In this article, we implement a working O-RAN platform and discover that the lack of mutual authentication mechanisms between services in the Near-Real-Time RIC and the improper permission settings for xAPPs pose a serious threat. By altering the original routing table and launching redirection attacks, malicious xAPPs could exploit this vulnerability and render the entire RAN inoperable. We provide a detailed report on how the attack was carried out and the impact it caused.