CSAI: Open-Source Cellular Radio Access Network Security Analysis Instrument

05/18/2019
by   Thomas Byrd, et al.
0

This paper presents our methodology and toolbox that allows analyzing the radio access network security of laboratory and commercial 4G and future 5G cellular networks. We leverage a free open-source software suite that implements the LTE UE and eNB enabling real-time signaling using software radio peripherals. We modify the UE software processing stack to act as an LTE packet collection and examination tool. This is possible because of the openness of the 3GPP specifications. Hence, we are able to receive and decode LTE downlink messages for the purpose of analyzing potential security problems of the standard. This paper shows how to rapidly prototype LTE tools and build a software-defined radio access network (RAN) analysis instrument for research and education. Using CSAI, the Cellular RAN Security Analysis Instrument, a researcher can analyze broadcast and paging messages of cellular networks. CSAI is also able to test networks to aid in the identification of vulnerabilities and verify functionality post-remediation. Additionally, we found that it can crash an eNB which motivates equivalent analyses of commercial network equipment and its robustness against denial of service attacks.

READ FULL TEXT

page 3

page 4

page 5

research
01/16/2022

Evaluating the Security of Open Radio Access Networks

The Open Radio Access Network (O-RAN) is a promising RAN architecture, a...
research
01/03/2022

Handover Experiments with UAVs: Software Radio Tools and Experimental Research Platform

Mobility management is the key feature of cellular networks. When integr...
research
06/25/2020

On the Feasibility of Exploiting Traffic Collision Avoidance System Vulnerabilities

Traffic Collision Avoidance Systems (TCAS) are safety-critical systems r...
research
04/25/2023

HexRAN: A Programmable Multi-RAT Platform for Network Slicing in the Open RAN Ecosystem

In recent years, the Open Radio Access Network (O-RAN) architecture has ...
research
05/15/2020

BaseSAFE: Baseband SAnitized Fuzzing through Emulation

Rogue base stations are an effective attack vector. Cellular basebands r...
research
02/26/2021

GraphSense: A General-Purpose Cryptoasset Analytics Platform

There is currently an increasing demand for cryptoasset analysis tools a...
research
07/23/2019

FALCON: An accurate real-time monitor for client-based mobile network data analytics

Network data analysis is the fundamental basis for the development of me...

Please sign up or login with your details

Forgot password? Click here to reset