LTE network control plane vulnerability analysis method and system based on software radio

Through the LTE network control plane vulnerability analysis method based on software radio, an attack model is built and the attack process is simulated, and the availability and privacy security vulnerabilities in the LTE network control plane protocol stack are detected, which solves the problem of vulnerability to LTE networks and improves security and stability.

CN114553459BActive Publication Date: 2025-05-02NANJING UNIV OF SCI & TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202111547942.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-16
Publication Date
2025-05-02
Estimated Expiration
2041-12-16

AI Technical Summary

Technical Problem

The LTE network control plane protocol stack has potential security vulnerabilities in availability and privacy, which are vulnerable to attacks, resulting in user identity information leakage or network service downgrade.

Method used

The LTE network control plane vulnerability analysis method based on software radio is adopted to build privacy and availability attack models, simulate the attack process, collect information from mobile devices and core networks, judge abnormal status, and detect potential security vulnerabilities.

Benefits of technology

It can dynamically test the operating LTE network control plane components, comprehensively detect security vulnerabilities in the availability and privacy of the LTE network control plane protocol stack, and improve the security and stability of mobile communications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114553459B_ABST
    Figure CN114553459B_ABST
Patent Text Reader

Abstract

The present invention proposes a method and system for analyzing the vulnerability of the LTE network control plane based on software radio, selects availability and privacy as indicators for determining the security attributes of the LTE control plane; constructs a privacy attack model and an availability attack model; selects a mobile device for vulnerability analysis to test the SIM card and the user server on the core network side, and writes test data; simulates the attack process, collects information on the mobile device, the simulated base station and the simulated core network, obtains the status information of the mobile device and the signaling information on the core network side; performs abnormal state judgment to determine whether the availability and privacy are attacked. The present invention can perform comprehensive detection and testing on potential security vulnerabilities in the LTE network control plane protocol stack.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of mobile communication security technology, and in particular to a method and system for analyzing vulnerabilities in an LTE network control plane based on software radio. Background Art

[0002] The global information age has arrived, and the total amount of data has exploded. People's demand for data information services is increasing day by day. These services go beyond traditional voice and short message services, including high-bandwidth data communications. In order to continuously optimize wireless communication technology to meet customers' higher requirements for wireless communication, LTE networks came into being. LTE is characterized by a great enhancement of the radio access network (RAN), increasing capacity in bits per second / hertz (bps / Hz), and redesigning the cellular core network (enhanced packet core-EPC), moving towards an all-IP system.

[0003] Although LTE has achieved huge capacity and system enhancements, the inherent vulnerability of mobile networks still makes them vulnerable to security attacks. Hundreds of millions of users rely on cellular networks every day, so vulnerabilities in LTE networks can have very serious consequences. Even if they are not the target of an attack, they may be affected by service degradation. The signaling defined by the LTE control plane protocol stack undertakes important functions such as status exchange between the terminal and the core network, releasing links, switching updates, and initiating paging. Therefore, the security analysis and research of the LTE control plane protocol stack is of great significance to the security and stability of mobile communications. The relevant research on the LTE control plane protocol stack has always been a hot topic in the field of mobile communication security technology. Summary of the invention

[0004] The purpose of the present invention is to provide a method and system for analyzing LTE network control plane vulnerabilities based on software radio.

[0005] The technical solution to achieve the purpose of the present invention is: a method for analyzing LTE network control plane vulnerabilities based on software radio, comprising the following steps:

[0006] In the first step, availability and privacy are selected as indicators for determining the security attributes of the LTE control plane;

[0007] The second step is to build privacy attack models and availability attack models;

[0008] The third step is to select the mobile device used for vulnerability analysis to test the SIM card and the user server on the core network side, and write the test data;

[0009] The fourth step is to simulate the attack process, collect information from mobile devices, simulated base stations and simulated core networks, and obtain status information of mobile devices and signaling information on the core network side;

[0010] The fifth step is to make an abnormal status judgment to determine whether availability and privacy are attacked.

[0011] Furthermore, in the second step, we build a privacy attack model and an availability attack model, specifically:

[0012] Privacy attack models include:

[0013] 1) Sniffing IMSI based on TAU process:

[0014] Put the test UE into idle state and turn on the eNB so that the UE enters a new tracking area;

[0015] The test UE initiates the TAU procedure and performs random access, and initiates an RRC connection request;

[0016] The core network responds to the RRC connection request and sends a TAUReject signaling to the UE;

[0017] The UE receives the TAUReject signaling and sends an attach_request signaling including the UE's IMSI number to the eNB;

[0018] Use Wireshark to monitor the S1 interface between the eNB and the MME to obtain the control plane signaling data packets, and obtain the UE's IMSI number in the InitialUEMessage data packet;

[0019] 2) Obtain location information based on RRC connection and TAU process:

[0020] Prepare two eNB1 and eNB2 with different cell IDs and turn on eNB1;

[0021] After the UE establishes a connection with eNB1, it turns off eNB1 and waits for the UE's T310 timer to expire before turning on eNB2 with higher power.

[0022] eNB2 sends RRCConnectionReconfiguration signaling to UE;

[0023] The UE receives the RRCConnectionReconfiguration signaling and calculates the frequency and signal strength from the neighboring cell;

[0024] The UE sends a measurement report (MeasurementReport) to eNB2, and retrieves the locationInfo-r10 field in the measurement report, which contains the GPS coordinates of the UE;

[0025] Availability attack models include:

[0026] 1) eNB resource consumption based on RRC connection:

[0027] Use srsUE to simulate malicious UE and write several IMSI numbers into the core network database;

[0028] Performing a random access procedure using a UE with a different IMSI number to generate an RRC connection;

[0029] The core network identifies the UE's attach_request and sends NASAuthentication signaling;

[0030] After receiving the NASAuthentication signaling from the core network, the UE restarts the random access process and establishes a new RRC connection;

[0031] 2) Service denial based on the detachment process:

[0032] Connect the test UE to the core network and read the UE's IMSI number;

[0033] The core network sends the decath_request signaling;

[0034] The UE receives the decath_request signaling and disconnects from the core network;

[0035] 3) Service degradation based on TAU process:

[0036] Test that the UE establishes a connection with the core network and sends an RRC connection request;

[0037] UE initiates the TAU procedure and sends RRCConnectionSetupComplet signaling;

[0038] The core network sends TAUReject signaling;

[0039] The UE receives TAUReject signaling and is expelled from the 4G network;

[0040] The UE is forced to search for and access the 3G or GSM network.

[0041] Furthermore, in the third step, the test data written includes IMSI and key information.

[0042] Furthermore, in the fourth step, the attack process is simulated to collect information from mobile devices, simulated base stations and simulated core networks. The specific method is as follows:

[0043] Use the SCAT tool to collect baseband diagnostic information from mobile devices;

[0044] Use the Wireshark tool to capture data packets on the Uu interface, X2 interface, S1 interface, and S6a interface.

[0045] Furthermore, in the fourth step, the status information of the mobile device and the signaling information on the core network side are obtained, wherein the status information of the mobile device includes: 1) whether the UE can search for the core network and register normally; 2) whether the UE can use the LTE network service normally with real-time network speed; 3) whether the UE is displayed as connected to the LTE network instead of the 3G or GSM network; the signaling information on the core network side includes: 1) ConnectionSetup signaling; 2) attach_request(IMSI,UE'securitycapabilities) signaling; 3) authentication signaling; 4) paging(GUTI / IMSI) signaling.

[0046] Furthermore, in the fifth step, abnormal status judgment is performed to determine whether availability and privacy are under attack. The specific method is as follows:

[0047] If all of the following conditions are met, the availability is considered to be under attack:

[0048] 1) The mobile device status shows no service; 2) The mobile device status shows connected to the 3G or GSM network; 3) The atchedUEs and connectedUEs on the core network side do not match the actual number of connected UEs;

[0049] If all of the following conditions are met, the privacy is considered to be attacked:

[0050] 1) The UE's IMSI number is stored in the InitialUEMessage data packet obtained from the S1 interface; 2) The locationInfo-r10 field is retrieved from the measurement report (MeasurementReport) sent by the UE to the eNB2.

[0051] Furthermore, the software radio-based LTE network control plane vulnerability analysis method also includes a display process, which generates a two-dimensional signaling diagram from the status information of the mobile device and the signaling information on the core network side for real-time visual display.

[0052] A software radio-based LTE network control plane vulnerability analysis system implements software radio-based LTE network control plane vulnerability analysis based on the software radio.

[0053] Compared with the prior art, the present invention has the following significant advantages: potential security issues can be studied by dynamically testing the running LTE network control plane components, and comprehensive detection and testing can be performed on potential security vulnerabilities in availability and privacy in the LTE network control plane protocol stack. BRIEF DESCRIPTION OF THE DRAWINGS

[0054] Figure 1 The figure is a schematic diagram of the processing flow of the LTE network control plane vulnerability analysis system based on software radio.

[0055] Figure 2 Schematic diagram of the LTE network control plane vulnerability analysis system based on software radio.

[0056] Figure 3 This is the main signaling flow chart of the LTE network control plane vulnerability analysis system based on software radio.

[0057] Figure 4 This is the TAU signaling diagram in the LTE network control plane vulnerability analysis system based on software radio. DETAILED DESCRIPTION

[0058] In order to make the purpose, technical solution and advantages of the present application more clearly understood, the present application is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0059] The present invention proposes a LTE network control plane vulnerability analysis system based on software radio, including a security attribute extraction module, an attack model construction module, a reading and writing module, an information collection module, a signaling analysis module, and an abnormal state judgment module, which are respectively introduced as follows:

[0060] (1) Security attribute extraction module

[0061] After extensive analysis of the LTE control plane protocol stack, the RRC protocol and NAS protocol of the LTE system network layer were selected for key research because 1) these two protocols are used to execute key control plane processes between the UE and the core network; 2) these processes can be captured on the UE and core network sides, which can be analyzed more conveniently; 3) the vulnerabilities identified in these protocols will directly affect the UE and the network.

[0062] A security analysis was conducted on the four key control plane processes of attachment, paging, detachment and location update in the RRC protocol and NAS protocol, and it was found that the vulnerabilities in the LTE control plane protocol stack may lead to the following security attacks: 1) The identity information of the UE, such as IMSI and GUTI, may be leaked due to malicious sniffing; 2) The location information of the cell where the UE is located or the precise geographic location information may be leaked; 3) The energy resources of the UE or the connectable resources of the core network are maliciously consumed; 4) A normal communication link cannot be established between the UE and the core network; 5) The network service of the UE is maliciously downgraded to a non-LTE network. Based on the above points, it was found that the security vulnerabilities of the LTE control plane may cause the leakage of user identity information or location information, or make the UE unable to use LTE network services normally. Based on this, the present invention summarizes the security attributes of the LTE control plane into two points: privacy and availability.

[0063] (2) Attack model construction module

[0064] Five SDR-based attack models are constructed according to the availability and privacy that mobile networks and mobile devices must comply with, as obtained in the security attribute extraction module, and the four basic signaling processes of attach, paging, detach and location update in the RRC protocol and NAS protocol.

[0065] Privacy attack models include:

[0066] 1) Sniffing IMSI based on TAU process:

[0067] Step 1: Put the test UE into idle state and turn on the eNB, so that the UE enters a new tracking area;

[0068] Step 2: The test UE initiates a TAU procedure and performs random access, and initiates an RRC connection request;

[0069] Step 3: The core network responds to the RRC connection request and sends a TAUReject signaling to the UE;

[0070] Step 4: The UE receives the TAUReject signaling and sends an attach_request signaling including the UE's IMSI number to the eNB;

[0071] Step 5: Use Wireshark to monitor the S1 interface between the eNB and MME to obtain the control plane signaling data packet, and obtain the UE's IMSI number in the InitialUEMessage data packet.

[0072] 2) Obtain location information based on RRC connection and TAU process:

[0073] Step 1: Prepare two eNB1 and eNB2 with different cell IDs and turn on eNB1;

[0074] Step 2: After the UE establishes a connection with eNB1, it turns off eNB1 and waits for the UE's T310 timer to time out before turning on eNB2 with higher power.

[0075] Step 3: eNB2 sends RRCConnectionReconfiguration signaling to UE;

[0076] Step 4: The UE receives the RRCConnectionReconfiguration signaling and calculates the frequency and signal strength from the neighboring cell;

[0077] Step 5: The UE sends a measurement report (MeasurementReport) to eNB2, and retrieves the locationInfo-r10 field in the measurement report, which contains the GPS coordinates of the UE.

[0078] Availability attack models include:

[0079] 1) eNB resource consumption based on RRC connection:

[0080] Step 1: Use srsUE to simulate malicious UE and write several IMSI numbers into the core network database;

[0081] Step 2: Use a UE with a different IMSI number to perform a random access procedure and generate an RRC connection;

[0082] Step 3: The core network identifies the UE's attach_request and sends NASAuthentication signaling;

[0083] Step 4: After receiving the NASAuthentication signaling from the core network, the UE restarts the random access process and establishes a new RRC connection.

[0084] 2) Service denial based on the detachment process:

[0085] Step 1: Connect the test UE to the core network and read the UE's IMSI number;

[0086] Step 2: The core network sends a decath_request signaling;

[0087] Step 3: The UE receives the decath_request signaling and disconnects from the core network.

[0088] 3) Service degradation based on TAU process:

[0089] Step 1: Test that the UE establishes a connection with the core network and sends an RRC connection request;

[0090] Step 2: UE initiates the TAU procedure and sends RRCConnectionSetupComplet signaling;

[0091] Step 3: The core network sends TAUReject signaling;

[0092] Step 4: The UE receives TAUReject signaling and is expelled from the 4G network;

[0093] Step 5: UE is forced to search for and access the 3G or GSM network.

[0094] (3) Reading and writing modules

[0095] Used to read or write test data related to the mobile device test SIM card and the core network side user database, including IMSI and key keys.

[0096] (4) Information collection module

[0097] The corresponding attack process is executed based on the constructed attack model, and information is collected during the process.

[0098] 1) Use the SCAT tool to collect baseband diagnostic information of mobile devices;

[0099] 2) Use the Wireshark tool to capture data packets on the Uu interface, X2 interface, S1 interface, and S6a interface.

[0100] (5) Signaling Analysis Module

[0101] The information obtained by the information collection module is filtered through fuzzy search to find the key status information of the mobile device and the signaling information of the four processes of attachment, paging, detachment and location update on the core network side.

[0102] Key status information of UE: 1) UE searches for the core network and registers normally; 2) UE uses LTE network services normally with real-time network speed; 3) UE shows that it is connected to the LTE network instead of the 3G or GSM network;

[0103] Key signaling information on the core network side: 1) ConnectionSetup signaling; 2) attach_request (IMSI, UE'securitycapabilities) signaling; 3) authentication signaling; 4) paging (GUTI / IMSI) signaling;

[0104] (6) Abnormal state judgment module

[0105] like Figure 2As shown, the abnormal state is judged based on the state information of the mobile device and the signaling information on the core network side screened by the signaling analysis module. Specifically:

[0106] If 1) the mobile device status shows no service; 2) the mobile device status shows connected to the 3G or GSM network; 3) the atchedUEs and connectedUEs on the core network side do not match the actual number of connected UEs, it is judged that the availability is under attack.

[0107] If 1) the UE's IMSI number is stored in the InitialUEMessage data packet obtained from the S1 interface; 2) the locationInfo-r10 field is retrieved from the measurement report (MeasurementReport) sent by the UE to the eNB2, it is determined that the privacy is attacked.

[0108] The system of the present invention is used to implement LTE network control plane vulnerability analysis based on software radio. The specific analysis process is as follows:

[0109] In the first step, the security attribute extraction module creates the security attributes that the network and mobile devices need to follow, namely availability and privacy, by analyzing the LTE control plane RRC and NAS protocols.

[0110] In the second step, according to the security properties obtained in the first step, corresponding SDR-based attack models are constructed for availability and privacy respectively.

[0111] The third step is to write the test data into the SIM card of the mobile device used for vulnerability analysis and the user server on the core network side. The specific information written is IMSI and related keys.

[0112] The fourth step is to select the security attributes to be analyzed, namely availability and privacy, and import the constructed attack model information.

[0113] The fifth step is to prepare the mobile device, the test SIM card in the third step, and the LTE base station and core network based on software radio simulation. According to the attack model constructed in the second step, simulate the attack process. In this process, collect information on the mobile device, simulated base station and simulated core network. Collect the baseband diagnostic information of the mobile device through the SCAT tool to determine its operating status, including the connection status between the mobile device and the core network, the real-time network connection speed, whether service degradation has occurred, etc.; collect information on the core network through the log data of the simulated base station and simulated core network and the data packets intercepted by the Wireshark tool, including the key signaling information of MME, HSS and eNB.

[0114] The sixth step is to filter the signaling information obtained by the information collection module to find the key status information of the mobile device and the real-time interaction information between the mobile device and each component of the core network.

[0115] The seventh step is to judge the abnormal status. According to the analysis results of the selected security attributes and signaling analysis module, if the mobile device, simulated base station or simulated core network is not operating normally, the cause of the abnormality is further judged and the related signaling causing the abnormality is analyzed.

[0116] In the eighth step, a two-dimensional signaling diagram is generated based on the key signaling obtained by the signaling collection module and the signaling analysis module to visualize the real-time status information of the mobile device and the core network.

[0117] In summary, the system of the present invention studies potential security issues by dynamically testing the running LTE network control plane components, and can perform comprehensive detection and testing on potential security vulnerabilities of availability and privacy in the LTE network control plane protocol stack.

[0118] The technical features of the above embodiments may be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0119] The above-mentioned embodiments only express several implementation methods of the present application, and the descriptions thereof are relatively specific and detailed, but they cannot be understood as limiting the scope of the invention patent. It should be pointed out that, for a person of ordinary skill in the art, several variations and improvements can be made without departing from the concept of the present application, and these all belong to the protection scope of the present application. Therefore, the protection scope of the patent of the present application shall be subject to the attached claims.

Claims

1. A method for analyzing LTE network control plane vulnerabilities based on software radio, characterized in that: The steps include: In the first step, availability and privacy are selected as indicators for determining the security attributes of the LTE network control plane; The second step is to build privacy attack models and availability attack models; The third step is to select the mobile device used for vulnerability analysis to test the SIM card and the user server on the core network side, and write the test data; The fourth step is to simulate the attack process, collect information from mobile devices, simulated base stations and simulated core networks, and obtain status information of mobile devices and signaling information on the core network side; The fifth step is to judge the abnormal status and determine whether the availability and privacy are attacked; The second step is to build a privacy attack model and an availability attack model, specifically: Privacy attack models include: 1) Sniffing IMSI based on TAU process: Put the test UE into idle state and turn on the eNB so that the UE enters a new tracking area; The test UE initiates the TAU procedure and performs random access, and initiates an RRC connection request; The core network responds to the RRC connection request and sends a TAU Reject signaling to the UE; The UE receives the TAU Reject signaling and sends an attach_request signaling including the UE's IMSI number to the eNB; Use Wireshark to monitor the S1 interface between the eNB and the MME to obtain the control plane signaling data packets, and obtain the UE's IMSI number in the InitialUEMessage data packet; 2) Obtain location information based on RRC connection and TAU process: Prepare two eNB1 and eNB2 with different cell IDs and turn on eNB1; After the UE establishes a connection with eNB1, it turns off eNB1 and waits for the UE's T310 timer to expire before turning on eNB2 with higher power. eNB2 sends RRC Connection Reconfiguration signaling to UE; The UE receives the RRC Connection Reconfiguration signaling and calculates the frequency and signal strength from the neighboring cell; The UE sends a measurement report to eNB2 and retrieves the locationInfo-r10 field in the measurement report, which contains the GPS coordinates of the UE. Availability attack models include: 1) eNB resource consumption based on RRC connection: Use srsUE to simulate malicious UE and write several IMSI numbers into the core network database; Performing a random access procedure using a UE with a different IMSI number to generate an RRC connection; The core network identifies the UE's attach_request and sends NAS Authentication signaling; After receiving the NAS Authentication signaling from the core network, the UE restarts the random access process and establishes a new RRC connection; 2) Service denial based on the detachment process: Connect the test UE to the core network and read the UE's IMSI number; The core network sends the decath_request signaling; The UE receives the decath_request signaling and disconnects from the core network; 3) Service degradation based on TAU process: Test that the UE establishes a connection with the core network and sends an RRC connection request; The UE initiates the TAU procedure and sends the RRC Connection Setup Complete signaling; The core network sends TAU Reject signaling; The UE receives TAU Reject signaling and is expelled from the 4G network; The UE is forced to search for and access the 3G or GSM network.

2. The method for analyzing LTE network control plane vulnerabilities based on software radio according to claim 1, characterized in that: In the third step, the test data written includes IMSI and key information.

3. The method for analyzing LTE network control plane vulnerabilities based on software radio according to claim 1, characterized in that: The fourth step is to simulate the attack process and collect information from mobile devices, simulated base stations and simulated core networks. The specific methods are as follows: Use the SCAT tool to collect baseband diagnostic information from mobile devices; Use the Wireshark tool to capture data packets on the Uu interface, X2 interface, S1 interface, and S6a interface.

4. The method for analyzing LTE network control plane vulnerabilities based on software radio according to claim 1, characterized in that: The fourth step is to obtain the status information of the mobile device and the signaling information on the core network side, where the status information of the mobile device includes: 1) whether the UE can search the core network and register normally; 2) whether the UE can use the LTE network service normally with real-time network speed; 3) whether the UE is displayed as connected to the LTE network instead of the 3G or GSM network; The signaling information on the core network side includes: 1) Connection Setup signaling; 2) attach_request (IMSI, UE'security capabilities) signaling; 3) authentication signaling; 4) paging (GUTI / IMSI) signaling.

5. The method for analyzing LTE network control plane vulnerabilities based on software radio according to claim 1, characterized in that: The fifth step is to judge the abnormal status and determine whether the availability and privacy are attacked. The specific method is as follows: If all of the following conditions are met, the availability is considered to be under attack: 1) The mobile device status shows no service; 2) The mobile device status shows connected to the 3G or GSM network; 3) The atched UEs and connected UEs on the core network side do not match the actual number of connected UEs; If all of the following conditions are met, the privacy is considered to be attacked: 1) The UE's IMSI number is stored in the InitialUEMessage data packet obtained from the S1 interface; 2) The locationInfo-r10 field is retrieved from the measurement report sent by the UE to the eNB2.

6. The method for analyzing LTE network control plane vulnerabilities based on software radio according to claim 1, characterized in that: It also includes a display process, which generates a two-dimensional signaling diagram from the status information of the mobile device and the signaling information on the core network side for real-time visual display.