Inherited Threat Reproduction on Open Source 5G Testbed
Toshiro Sawamoto, Mio Suzuki, Yutaro Osako, Takahiro Kasama, Daisuke Inoue, Koji Nakao · 2024
The fifth-generation mobile communication system(5G) is being rolled out worldwide. 5G system introduces a whole new technology and concept to fulfill harsh requirements such as Enhanced Mobile Broadband (eMBB), Ultra-reliable and Low Latency Communications (URLLC), and Massive Machine-type Communications (mMTC) while following some legacy protocols. This brings a new experience to customers, improves the flexibility of building systems and operations, and has the advantage of providing game-changing services. Still, it has the potential to expand attack surfaces to a malicious attacker simultaneously and reproduce the vulnerabilities in the legacy protocols inherited to 5G. In this study, we focus on the potential vulnerabilities caused by the AKA protocol inherited to 5G. The AKA protocol is applied for mutual authentication between user equipment (UE) and the network and has been taken over as 5G-AKA in the form of some enhanced features of EPS-AKA in the 4G. Here, we have verified whether the threats reported in EPS-AKA are still reproduced in 5G networks on actual equipment using the open source software (OSS). More specifically, we observed that a DoS attack that replayed and exploited the Registration Request resulted in an unauthorized increment of the SQN managed on the network side. This indicates that the threat of mutual authentication being thwarted, which was noted in 4G, was reproduced on the actual 5G network. Furthermore, it was found that the reproduction of the vulnerability triggered significant behavior that severely compromised the availability of the 5G network. This paper shows that these threats are reproduced and caused by the original philosophy of the AKA protocol. The paper presents detailed scenarios of DoS attacks and threat reproduction mechanisms on the OSS 5G network. High-level recommendations for wireless operators, as well as related works introducing essential modification ideas for AKA protocol, to prevent these threats from replaying in 5G networks are proposed. The paper also discusses what is required for 5G security verification going forward from three perspectives: standardization around 5G, use cases, and 5G security testbeds.