DNS Route Tampering Attack in 5G Application Layer
Zhiqian Xiao, Qian Sun, Lin Tian · 2024
5G user plane carries enhanced mobile broadband services and supports emerging vertical industry applications. Its security is directly related to the confidentiality and integrity of user data. However, 5G user plane protocol faces serious security threats. For example, attackers can construct malicious data packets through the packet parsing vulnerability of GTP-U( GPRS Tunnelling protocol-User plane) protocol, and use the vulnerability to perform network attacks such as remote code execution and denial of service, which will lead to serious threats to the availability of the core network and the confidentiality of user data, bringing serious security risks to operators and users. Therefore, it is necessary to design attack methods for application layer protocols and analyze their security risks. The key is to analyze and verify the vulnerability of 5G user plane protocols. The existing security research of user-plane protocols mainly focuses on the physical layer and network layer, and lacks of security analysis of user-plane application layer protocols. The DNS(Domain Name System) resolution process consists of the domain name resolution and IP address acquisition steps at the 5G user surface application layer. This paper focuses on the analysis and exploitation of security flaws in 5G user-plane DNS resolution. Through in-depth analysis of the DNS resolution process in 5G network, it is found that 5G network lacks the security flaws of validity verification of DNS query destination IP. A DNS query response access tampering attack method based on route tampering is proposed. The research and development tools are packet interception module, packet modification module and malicious DNS server module. The test is carried out in the self-developed 5G network security experimental platform, and the DNS IP is successfully tampered with, and the user is hijacked to the malicious site.