A 5GC signaling security vulnerability automatic discovery method and system based on ontology modeling
By building a 5G parallel virtual platform and ontology modeling technology, 5G signaling vulnerabilities and defects are automatically inferred, and the problems of low efficiency and incomplete discovery of 5G signaling security vulnerabilities in the existing technology are solved, achieving efficient, comprehensive and automatic security vulnerability discovery and self-inference.
Patent Information
- Application Number
- CN202210494742.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-05-07
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2042-05-07
AI Technical Summary
The existing technology is inefficient and incomplete in the discovery of 5G signaling security vulnerabilities and defects. It mainly relies on human analysis and experience, and cannot fully discover all possible security vulnerabilities and defects.
By building a 5G parallel virtual platform, the signaling interaction process between network elements in the 5G mobile communication network is simulated, and the ontology modeling is performed based on the 5G parallel virtual platform, and new 5G protocol vulnerabilities and defects are automatically inferred using inference machines. The specific steps include ontology modeling based on the 5G protocol standard, generating 5G signaling instances, extracting the characteristics of known vulnerabilities, designing security inspection rules, and discovering 5G signaling vulnerabilities and defects through automatic inference.
It realizes self-discovery and self-inference of 5G signaling security risks, improves the efficiency and comprehensiveness of signaling vulnerabilities and defects, and can automatically deduce similar security risks in 5G networks, thereby reducing losses caused by signaling security vulnerabilities.
Smart Images

Figure CN115314900B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of 5G network security technology in mobile communication technology, and in particular to a method and system for automatically discovering 5GC (5G core network) signaling security vulnerabilities based on ontology modeling. Background Art
[0002] Extensive research has been conducted at home and abroad on 5G signaling security. On the one hand, 5G signaling security risks include problems that have been exposed in 3G / 4G mobile communication networks and have not been well resolved in 5G networks. On the other hand, they also include new signaling security issues brought about by new architectures and technologies proposed by 5G for application in more vertical industries. Signaling security risks that have been exposed in 3G / 4G mobile communication networks and have not been well resolved in 5G networks include fake base stations. There is a security risk of fake access points in 5G WiFi calls, that is, the terminal device UE finds that the WiFi mechanism is selected only based on wireless parameters (such as signal strength) without verifying the integrity and security level of the network. Attackers can use the above vulnerabilities to construct fake access points, induce users to access, and thus steal users' device parameters, privacy data, etc., or they can discard signaling flows to cause the user terminal to fail to successfully establish a session. For the 5G control plane, the 5G network protocol defines many key services such as initial registration, deregistration, and paging. Exploiting these service vulnerabilities may have serious consequences, such as the use of man-in-the-middle attacks, which intercept and tamper with the communication between the message sender and the receiver, causing the user to be unable to use the network normally; spoofing attacks, which cause the base station to release the connection with the victim user by spoofing the victim user to initiate an RRC request. New signaling security risks brought by the new architecture and new technologies of 5G, such as the new architecture for the microservices of the 5G core network, which proposes a variety of attack methods for the http / 2 protocol used for interactive information between 5G core network elements, including stream multiplexing attacks, which force the two network elements to re-establish a connection, thereby causing higher latency; flow control attacks, which request a large amount of resources from the victim network element through the attacker network element and set a relatively small flow window, which will cause the connection to occupy the resources of the victim network element for a long time, making it unable to provide services to other network elements, as well as priority attacks, compression header attacks, etc. For the new 5G network slicing technology, the 5G network allows user sessions to move from one network slice to another, and the service provider does not limit the number of access users. This signaling security vulnerability is exploited. By initiating a large number of requests to migrate in and out of the target slice in a short period of time, the traffic load in the target slice fluctuates, causing performance impacts. At the same time, it will also cause DDOS attacks on the AMF, SMF and other network elements that support slice selection and session establishment that serve the slice. Therefore, it is necessary to study the vulnerabilities and defects of 5G signaling.
[0003] Analysis of existing research shows that, first of all, most of the research on 5G signaling security vulnerabilities and defects is based on manual analysis of security vulnerabilities and defects exposed during the operation of 3GPP protocols or systems, which relies on human experience and randomness, resulting in low efficiency in signaling vulnerabilities and defects research. Secondly, the researchers have deep experience and only conduct in-depth research on existing security vulnerabilities and defects, and cannot comprehensively discover all possible security vulnerabilities and defects in signaling. Therefore, for 5G signaling vulnerabilities and defects, it is necessary to realize efficient, comprehensive and automatic discovery of potential security vulnerabilities and defects, and to implement methods to avoid vulnerabilities and defects in advance, so as to minimize the losses caused by signaling security vulnerabilities and defects.
[0004] Through research and analysis, it is found that the current analysis of security vulnerabilities and defects in signaling has the problems of low efficiency and incomplete analysis. The main reason is that it heavily relies on the knowledge level and judgment ability of researchers. Summary of the invention
[0005] Existing studies on signaling vulnerabilities and defects in 5G mobile communication networks are all based on methods that manually discover some individual security vulnerabilities, but this method has problems such as inefficiency and incompleteness. Therefore, in order to solve this problem, the present invention proposes a self-discovery method for signaling vulnerabilities and defects. By building a 5G parallel virtual platform, the signaling interaction process between network elements in the 5G mobile communication network is simulated. Then, based on the 5G parallel virtual platform, the initial security rules are formulated, and the inference engine is used to automatically infer new 5G protocol vulnerabilities and defects. Specifically, in response to the shortcomings of the prior art, the present invention proposes a 5GC signaling security vulnerability automatic discovery method based on ontology modeling, which includes:
[0006] Step 1: Based on the 5G protocol standard, ontology modeling is performed to obtain a 5G network element and a signaling interaction model between network elements, which is used as a 5G virtual platform and a 5G signaling instance is generated using the 5G virtual platform;
[0007] Step 2: Perform ontology modeling based on known 5G signaling security vulnerabilities and defects to obtain a vulnerability ontology model, and characterize the vulnerability exploitation behavior in the 5G signaling instance based on the vulnerability ontology model;
[0008] Step 3: Extract features of the known 5G signaling security vulnerabilities and defects, and design verification rules for security vulnerabilities and defects based on the feature extraction results;
[0009] Step 4: Based on the inspection rules, the semantic association between the 5G signaling instance and its vulnerability exploitation behavior is discovered to automatically reason and discover 5G signaling vulnerabilities and defects.
[0010] The automatic discovery method of 5GC signaling security vulnerabilities based on ontology modeling, wherein the 5G virtual platform adopts a hierarchical class definition architecture, including a top-level class, a first-order subclass, and a second-order subclass, and utilizes the inheritance relationship between top-level classes to achieve reuse of first-order and second-order subclasses;
[0011] According to the 5G protocol standard, three top-level class ontologies, namely, network element function, service and service content, are obtained; each top-level class ontology constructs its first-order subclasses through inheritance; only the first-order subclass of the service class has a second-order subclass for describing the corresponding specific service operations.
[0012] The automatic discovery method of 5GC signaling security vulnerabilities based on ontology modeling, wherein the attack source module and the attacked module in the vulnerability ontology model are respectively used as the attack source module class and the attacked module class; the network element instance of the attack source module has an attribute, which indicates that the network element instance of the attack source module and the corresponding attack method instance are in a usage relationship.
[0013] The automatic discovery method of 5GC signaling security vulnerabilities based on ontology modeling, wherein the inspection rules include two parts. The first part is to obtain the sending network element module breached by the attacker, the receiving network element module without security protection measures, and the information obtained by the attacker based on the currently known 5G signaling attacks; the second part is to deduce the signaling in the 5G virtual platform that is at risk of being attacked based on the first part.
[0014] The present invention also proposes a 5GC signaling security vulnerability automatic discovery system based on ontology modeling, which includes:
[0015] An ontology modeling module is used to perform ontology modeling based on the 5G protocol standard to obtain a signaling interaction model of 5G network elements and network elements, and use the 5G virtual platform as a 5G virtual platform to generate a 5G signaling instance; and perform ontology modeling based on known 5G signaling security vulnerabilities and defects to obtain a vulnerability ontology model, and characterize the vulnerability exploitation behavior in the 5G signaling instance based on the vulnerability ontology model;
[0016] The automatic reasoning module is used to extract features of the known 5G signaling security vulnerabilities and defects, and design verification rules for security vulnerabilities and defects based on the feature extraction results; and based on the verification rules, discover the semantic association between the 5G signaling instance and its vulnerability exploitation behavior, so as to automatically reason and discover 5G signaling vulnerabilities and defects.
[0017] The 5GC signaling security vulnerability automatic discovery system based on ontology modeling, wherein the 5G virtual platform adopts a hierarchical class definition architecture, including a top-level class, a first-order subclass, and a second-order subclass, and utilizes the inheritance relationship between the top-level classes to realize the reuse of the first-order and second-order subclasses;
[0018] According to the 5G protocol standard, three top-level class ontologies, namely, network element function, service and service content, are obtained; each top-level class ontology constructs its first-order subclasses through inheritance; only the first-order subclass of the service class has a second-order subclass for describing the corresponding specific service operations.
[0019] The 5GC signaling security vulnerability automatic discovery system based on ontology modeling, wherein the attack source module and the attacked module in the vulnerability ontology model are respectively used as the attack source module class and the attacked module class; the network element instance of the attack source module has an attribute, which indicates that the network element instance of the attack source module and the corresponding attack method instance are in a usage relationship.
[0020] The automatic discovery system of 5GC signaling security vulnerabilities based on ontology modeling, wherein the inspection rules include two parts. The first part is to obtain the sending network element module breached by the attacker, the receiving network element module without security protection measures, and the information obtained by the attacker based on the currently known 5G signaling attacks; the second part is to deduce the signaling in the 5G virtual platform that is at risk of being attacked based on the first part.
[0021] The present invention also proposes a storage medium for storing a program for executing any one of the 5GC signaling security vulnerability automatic discovery methods based on ontology modeling.
[0022] The present invention also proposes a client for use in any of the above-mentioned 5GC signaling security vulnerability automatic discovery systems based on ontology modeling.
[0023] It can be seen from the above scheme that the advantages of the present invention are:
[0024] The present invention realizes the self-discovery of 5G signaling security risks based on ontology modeling technology, and can effectively perform self-reasoning of security risks. And based on the built 5G signaling ontology model, it can be conveniently expanded for newly discovered security risks in the future, so as to discover the exploitable security risks in one signaling and automatically derive similar exploitable security vulnerabilities in all signalings of the 5G network. BRIEF DESCRIPTION OF THE DRAWINGS
[0025] Figure 1 The system architecture diagram for automatically discovering 5G signaling vulnerabilities and defects;
[0026] Figure 2 For 5G network architecture;
[0027] Figure 3 Design of three-layer class for 5G signaling virtual platform based on ontology modeling;
[0028] Figure 4 It is the top-level class of the ontology model;
[0029] Figure 5It is a network element ontology model diagram;
[0030] Figure 6 It is the service ontology model diagram;
[0031] Figure 7 This is the service content ontology model diagram;
[0032] Figure 8 To serve the second-order ontology model diagram;
[0033] Fig. 9 It is the attack ontology model diagram;
[0034] Fig.10 To obtain signaling content;
[0035] Fig.11 Inject attack signaling;
[0036] Fig.12 Reasoning results for known content for the attacker;
[0037] Fig.13 To reason about security risks;
[0038] Fig.14 Query the registration status of AMF network element;
[0039] Fig.15 Launch a deregistration attack for the attacker;
[0040] Fig.16 The AMF network element has been deregistered;
[0041] Fig.17 Initiate and register attack signaling for the attacker. DETAILED DESCRIPTION
[0042] The present invention aims to automatically and comprehensively discover signaling security vulnerabilities and defects in the 5G communication network, and designs the architecture of the 5G signaling vulnerability and defect automatic discovery system. First, based on the 3GPP 5G standard, the ontology modeling method is used to establish a signaling interaction model between 5G network elements and network elements, and model a 5G virtual platform; then, the ontology modeling method is used to model the exploitation of known vulnerabilities as vulnerability classes; then, the inspection rules for security vulnerabilities and defects are designed, called security rules, and formal modeling is performed using SWRL; finally, the 5G signaling virtual platform and the 5G signaling and its vulnerability instance based on the vulnerability ontology model instance are used to characterize the vulnerability exploitation behavior in the signaling instance based on the vulnerability ontology model, and based on the operation of security rules on 5G signaling and its vulnerability instance, the inference engine is used to realize the automatic discovery of new 5G signaling vulnerabilities and defects. To this end, the present invention mainly includes a 5G signaling security vulnerability automatic discovery system architecture based on ontology modeling, a 5G signaling virtual platform construction based on ontology modeling, known vulnerability modeling, and security rule design. Specifically as follows:
[0043] Key point 1: The 5G signaling security vulnerability automatic discovery system architecture based on ontology modeling mainly includes the 5G signaling virtual platform, 5G signaling vulnerability and defect inspection rules, and runs on the 5G signaling virtual platform based on the inspection rules to realize the automatic discovery of new 5G signaling vulnerabilities and defects;
[0044] Key point 2: 5G signaling virtual platform based on ontology modeling
[0045] a) The 5G signaling virtual platform mentioned in key point 1, through the analysis of 3GPP5G protocol, uses the ontology modeling method to model 5G network elements, the relationship between network element interactions (called services), and the core content carried in the interaction (called service content);
[0046] b) In the process of establishing a 5G signaling virtual platform based on ontology modeling, although it is possible to directly define network element classes to model network elements and define service entities and service content data attributes for each network element for signaling and data processing, the model is highly complex and inflexible. Therefore, a hierarchical class definition architecture is innovatively proposed, which includes three layers: top-level class, first-order subclass, and second-order subclass, such as Figure 3 As shown;
[0047] c) According to the 3GPP protocol, three top-level class ontologies are summarized: Network Functions, Services, and Services Context;
[0048] d) Each top-level class ontology can obtain its first-order subclasses through inheritance, among which the network element class includes multiple subclass network elements such as AMF, SMF, UDM, NRF, PCF, etc., the service class includes multiple service subclasses such as AMF_Services, SMF_Services, UDM_Services, NRF_Services, PCF_Services, etc., and the service content class includes multiple service content subclasses such as SUPI, SUCIor5GGUTI, NF ID, etc.;
[0049] e) A first-order subclass can obtain its second-order subclass through inheritance. Only the service subclass contains second-order subclasses, which are used to describe the corresponding specific service operations. For example, UDM_Services contains Nudm_SDM_Get, Nudm_SDM_Subscribe, etc.
[0050] f) Based on the hierarchical class definition architecture, the association relationship between top-level classes is used to achieve the reuse of first-order and second-order subclasses. To this end, the internal relationship between the three top-level classes is represented based on the attributes between the ontologies. The relationship between the network element class and the service class is receiving and sending, which is identified by the send / receive method. Its formal expression is NetworkFunctions send / receive Services, that is, the network element sends / receives services. The relationship between the service class and the service content class is inclusion, which is identified by the contains method. Its formal expression is Services containsServices Context, that is, the service contains service content. Based on this, the service second-order subclass can reuse the network element first-order subclass and the service content first-order subclass using the send / receive and contains methods.
[0051] Key point 3: Modeling known vulnerabilities
[0052] Modeling known vulnerabilities. The attacks caused by the vulnerabilities can be formally represented by the attack source module, the attacked module, and the attack method triple. Among them, the attack source module and the attacked module are 5G network elements, and the attack methods include illegal interception (Intercept), illegal tampering (Tamper) and illegal forgery (Counterfeit). Therefore, after the network element class defined in the 5G signaling virtual platform is instantiated, it is necessary to formally characterize whether it is an attack source module or an attacked module. Therefore, the attack source module and the attacked module are also innovatively defined as classes in the cost body modeling, respectively called the attack source module class and the attacked module class. Then in the network element instance, it can be indicated whether it belongs to the attack source module class or the attacked module class, and then the attack source module or the attacked module can be formally represented. At the same time, the attack source module needs to use the corresponding attack method to simulate the attack source, so for the network element instance as the attack source module, it is necessary to characterize the attack method used. To this end, it is further proposed to define the attack method as an attack method class and instantiate it, and add an attribute to the network element instance of the attack source module, which indicates that the network element instance of the attack source module and its corresponding attack method instance are in a usage relationship.
[0053] Key point 4, the design of security rules. The main idea of security rule design is to extract the features of known attacks, design an analogy method for attack features, generalize attack features, and automatically discover network elements and signaling with the same features. These network elements and signaling are considered to be potential security vulnerabilities and defects. The features extracted from known attacks mainly include the node status of the sender's network element, the node status of the receiver's network element, and the sensitive information carried in the interactive signaling between the two parties. The details are as follows:
[0054] (1) Characteristic analysis of the node status of the sender network element is mainly because some sender modules may be more vulnerable to attack. For example, small terminal sensor devices in the 5G large-scale Internet of Things have insufficient security protection due to their low cost and low power consumption requirements. They are more likely to be attacked by attackers and become zombie machines of attackers, launching attacks in the 5G mobile communication network.
[0055] (2) Analyze the characteristics of the receiving network element node status. This is mainly because some signaling receiving devices are not in the core protection area and there are no defense measures to clean and filter abnormal traffic, which allows attacks to occur.
[0056] (3) Feature analysis of sensitive information carried in the interactive signaling between the two parties is mainly because attackers may be more interested in certain information, such as the identity information of the terminal, the identity information of the user, the location information of the user, and the identity information of the network element. The attacker will have greater value after obtaining this information.
[0057] The analogy method of attack characteristics includes the following principles:
[0058] (1) If the sender network element of a certain signaling in the virtual platform is a subset of the sender network elements in the known attack, it is inferred that the signaling is also a potential risk point in the 5G system;
[0059] (2) If the receiving network element of a certain signaling in the virtual platform is a subset of the receiving network elements in the known attack, it is inferred that the signaling is also a potential risk point in the 5G system;
[0060] (3) If the sensitive information contained in a certain signaling in the virtual platform is a subset of the sensitive information carried in a known attack, it can be inferred that the signaling is also a potential risk point in the 5G system.
[0061] Key point 5: Security rules can be written in SWRL language, and the syntax and semantics of SWRL language are compatible in the ontology modeling platform. The basic form of SWRL rules is to express the deductive relationship between premise and conclusion. Both premise and conclusion can include single or multiple basic propositions, and the basic propositions are in a logical and relationship. Several principles of the analogy method of attack features are expressed using logical relationships. The details are as follows:
[0062] (1) Principle 1 can be expressed as follows: If the sender of signaling s is network element n, network element n belongs to a known attack source module a, and attack source module a uses attack method b, and the three logics are true, then it can be deduced that signaling s may be used by an attacker to launch attack b. If any of the premises is not true, then it can be deduced that signaling s is secure.
[0063] (2) Principle 2 can be expressed as follows: If the receiver of signaling s is network element n, network element n belongs to a known attacked module a, and the attacked module a uses attack method b, and the three logics are true, then it can be concluded that signaling s may be used by attackers to launch attack b. If any of the premises is not true, then it can be concluded that signaling s is safe.
[0064] (3) Principle 3 can be expressed as follows: If the information carried by signaling s is c, information c belongs to sensitive information a that is known to be vulnerable to attack, and attackers often use attack method b to obtain sensitive information a, and the three logics are true together, then it can be concluded that signaling s may be used by attackers to launch attack b. If any of the premises is not true, then it can be concluded that signaling s is safe.
[0065] In order to make the above features and effects of the present invention more clearly understood, embodiments are given below and described in detail with reference to the accompanying drawings.
[0066] The present invention proposes a method for automatically discovering 5G signaling vulnerabilities and defect risks based on ontology modeling, such as Figure 1 As shown. The present invention innovatively adopts an ontology modeling-based method to construct an ontology model of 5G signaling interaction and form a 5G parallel virtual platform. Based on the 5G parallel virtual platform, the signaling security features such as encryption, integrity protection and sensitive information of 5G signaling are extracted, and the signaling security features are introduced in the SWRL rule definition to design 5G signaling security vulnerability and defect discovery rules, thereby realizing efficient and comprehensive automated discovery of potential security risks of 5G signaling.
[0067] 1. 5G signaling security vulnerability automatic discovery system architecture based on ontology modeling
[0068] The 5G signaling security vulnerability automatic discovery system architecture based on ontology modeling, such as Figure 1 As shown in the figure, it mainly includes 5G signaling virtual platform, known vulnerability ontology model and security rules for 5G signaling vulnerabilities and defects. Using 5G signaling virtual platform and 5G signaling and its vulnerability instance based on vulnerability ontology model; characterizing vulnerability exploitation behavior in signaling instance based on vulnerability ontology model; based on the operation of security rules on 5G signaling and its vulnerability instance, realizing automatic discovery of new 5G signaling vulnerabilities and defects
[0069] 2. 5G signaling virtual platform based on ontology modeling
[0070] 5G network architecture Figure 2 As shown in the figure, it includes RAN, AMF, SMF, UPF, AUSF, AF, UDM, PCF, NRF, NEF, NSSF and other network elements. The functions of each network element are as follows: Figure 2 shown.
[0071] (1) RAN (Access Network): It consists of multiple gNB base stations and completes base station processing.
[0072] (2) AMF (Access and Mobility Management Function): As the core control plane node, it provides user registration and connection management, user reachability and mobility management functions for the 5G network, participates in security functions such as authentication and NAS signaling protection, and performs edge security anchor functions.
[0073] (3) SMF (Session Management Function): Mainly responsible for session management related functions, including establishment, modification and release. Specific functions include IP address allocation during session establishment, selection and control of user plane functions, configuration of service routing and UP traffic guidance, determination of SSC mode, configuration of UPF QoS policy, etc.
[0074] (4) UPF (User Plane Function): As the user plane node connected to the PDN network, it mainly provides user plane service processing functions, including service routing, packet forwarding, anchoring function, QoS mapping and execution, uplink identification and routing to the data network, downlink packet caching and downlink data arrival notification triggering, and connection with external data networks.
[0075] (5)AUSF (Authentication Server Function): implements user authentication and certification.
[0076] (6) AF (Application Layer Function): It realizes the influence of application processes on traffic routing, accesses network open functions, and interacts with the control policy framework. Based on operator deployment, it can allow application functions trusted by operators to interact directly with related network functions.
[0077] (7) UDM (Unified Data Management): The main functions are to manage various user contract data, user authentication data, user representation management, etc.
[0078] (8) PCF (Policy Control Function): PCF supports a unified policy framework to manage network behavior, provides policy rules for control plane functions, and accesses subscription information related to policy decisions in the unified data repository (UDR).
[0079] (9) NRF (Network Resource Repository Function): Supports service discovery and maintains NF profiles of available NF instances and their supported services.
[0080] (10) NEF (Network Service Presentation Function): enables the opening of network capabilities and events, provision of security information from external applications to the 3GPP network, analysis of internal and external information, and reception of information from other networks.
[0081] (11) NSSF (Network Slice Selection Function): Selects the set of network slice instances serving the UE, determines the set of allowed network slice identifiers, and determines the mapping to the contracted single network slice identifier when necessary, determines the configured set of network slice identifiers, and determines the mapping to the contracted single network slice identifier when necessary. In order to build a 5G signaling virtual platform, through the analysis of the 3GPP5G protocol, it is necessary to model the 5G network elements, the relationship between network element interactions (called services), and the core content carried in the interaction (called service content). 5G network elements, services, and service contents are based on the ontology modeling method. In the process of establishing a 5G signaling virtual platform based on ontology modeling, although network elements can be modeled by directly defining network element classes, and service entities and service content data attributes of network elements can be defined one by one for signaling and data processing, the model is highly complex and has poor flexibility. Therefore, an innovative hierarchical class definition architecture is proposed, which specifically includes three layers: top-level classes, first-order subclasses, and second-order subclasses, such as Figure 3 shown.
[0082] The top-level classes, first-order subclasses, and second-order subclasses are designed as follows.
[0083] 2.1 Top-level class design
[0084] In the TS 23.502 document released by the 3GPP organization in September 2020, it clearly defines the protocol interaction processes such as user registration, service request, configuration update, etc. The UML interaction diagram shows the dynamic collaboration between various network element node objects in the network through signaling interaction, and clearly explains the function and content format of each signaling. Figure 4 As shown in the figure, three top-level class ontologies, namely network function (NetworkFunctions), service (Services) and service content (Services Context), are summarized in the 5G signaling virtual platform based on ontology modeling.
[0085] 2.2 First-order subclass design
[0086] like Figure 5 , 6 As shown in Figure 7, each top-level class ontology can obtain its first-order subclasses through inheritance, where the network element class includes multiple subclass network elements such as AMF, SMF, UDM, NRF, PCF, etc., the service class includes multiple service subclasses such as AMF_Services, SMF_Services, UDM_Services, NRF_Services, PCF_Services, etc., and the service content class includes multiple service content subclasses such as SUPI, SUCIor5GGUTI, NF ID, etc.
[0087] 2.3 Second-order subclass design
[0088] like Figure 8 As shown, a first-order subclass can obtain its second-order subclass by inheritance, and only a service subclass contains a second-order subclass to describe the corresponding specific service operations. For example, UDM_Services contains Nudm_SDM_Get, Nudm_SDM_Subscribe, etc.
[0089] According to the 3GPP standard, NRF_Services includes Nnrf_NFManagement_services, Nnrf_NFDiscovery_services, and Nnrf_AccessToken_services subclass signaling, among which Nnrf_NFManagement_services will be further subdivided into Nnrf_NFManagement_NFRegiste, Nnrf_NFManagement_NFUpdate, Nnrf_NFManagement_NFDeregister, Nnrf_NFManagement_NFStatusSubscribe, and Nnrf_NFManagement_NFStatusNotify third-order subclass signaling. The signaling of other network elements will also be subdivided into multiple third-order subclass signaling.
[0090] Taking the signaling in the above Nnrf_NFManagement services class as an example, the content transmitted by the signaling mainly includes NF_IP_address (NF IP address), NF_Instance_ID (NF instance ID), PLMN_ID (public network ID), Callback_URL (callback uniform resource location) and Reason_Indication, etc. Among them, the content transmitted in the Nnrf_NFManagement_NFRegister sub-signaling mainly includes NF_Instance_ID, NF_IP_address, PLMN_ID, etc. The content transmitted in the Nnrf_NFManagement_NFUpdate sub-signaling mainly includes NF_Instance_ID. The Nnrf_NFManagement_NFDeregister signaling mainly includes NF_Instance_ID and Reason_Indication. The content transmitted in the three Nnrf_NFManagement_NFStatusNotify sub-signals mainly includes NF_Profile. Nnrf_NFManagement_NFStatusSubscribe signaling is used to subscribe to NF status information, so its transmission content is mainly Callback_URL, so that NRF can return the subscribed NF status information.
[0091] 2.4 Signaling Interaction Based on Three-Layer Class
[0092] Based on the hierarchical class definition architecture, the association relationship between top-level classes is used to achieve the reuse of first-order and second-order subclasses. To this end, the internal relationship between the three top-level classes is represented based on the attributes between the ontologies. The relationship between the network element class and the service class is receiving and sending, which is identified by the send / receive method. Its formal expression is NetworkFunctions send / receive Services, that is, the network element sends / receives services. The relationship between the service class and the service content class is inclusion, which is identified by the contains method. Its formal expression is Services containsServices Context, that is, the service contains service content. Based on this, the service second-order subclass can reuse the network element first-order subclass and the service content first-order subclass using the send / receive and contains methods.
[0093] 3. Modeling of known vulnerabilities
[0094] Man-in-the-middle attacks on 5G signaling can be divided into three categories: Intercept, which is to illegally intercept the content transmitted in the signaling; Tamper, which is to illegally tamper with the content transmitted in the signaling; and Counterfeit, which is to illegally impersonate network elements and initiate forged signaling. Fig. 9 shown.
[0095] In the process of generating instances, the calling relationship between ontologies is represented by the attributes between ontologies. Figure 4 As shown in , the relationship between the attack method and the signaling service is identified by attack, and its formal expression is Attack_Method attack Services, that is, use Attack_Method to attack Services.
[0096] 4. Safety rules design
[0097] The security rules mainly include two parts. The first part is to obtain the sender network element modules that are easy to be hacked by attackers, the receiver network element modules without security protection measures, and the sensitive information that attackers are interested in based on the currently known 5G signaling attacks. The second part is to deduce whether other signaling in the 5G signaling virtual platform is at risk of being attacked.
[0098] Part I:
[0099] (1) Based on the currently known 5G signaling attacks, we can obtain the sender network element module that is easy for attackers to break. Taking the example that attackers can use Registration_Request signaling to launch a DDOS attack, we can infer that the terminal that initiates Registration_Request signaling is the sender network element module that is easy for attackers to break.
[0100] Registration_Request(?s)^UE(?u)^send(?u,?s)^DDOS(?a)^ attacks(?a,?s)->Attacker_Control(?u)
[0101] (2) Based on the currently known 5G signaling attacks, the receiving network element module without security protection measures is obtained. Taking the example that the attacker can use the Registration_Request signaling to launch a DDOS attack, it can be inferred that the base station that receives the Registration_Request signaling is a receiving network element module without security protection measures.
[0102] Registration_Request(?s)^RAN(?r)^receive(?r,?s)^DDOS(?a)^ attacks(?a,?s)->No_Safety_Measures(?r)
[0103] (3) Based on the currently known 5G signaling attacks, the attacker can obtain sensitive information that the attacker is interested in. Taking the example of an attacker being able to forge and initiate Nnrf_NFManagement_NFDeregister, it can be inferred that the NF_instance_ID and Reason_Indication contained in the Nnrf_NFManagement_NFDeregister signaling are already content that the attacker can obtain.
[0104] Nnrf_NFManagement_NFDeregister(?s)^NF_instance_ID(?id)^ Reason_Indication(?reason)^contains(?s,?id)^contains(?s,?reason)^Counterfeit(?a)^attacks(?a,?s)->Attacker_Known_Context(?id)^ Attacker_Known_Context(?reason)
[0105] Part II:
[0106] (1) Based on the sender network element module that is easy for attackers to break into, deduce other signaling in the 5G signaling virtual platform that may be at risk of being attacked. Take the terminal that is easy for attackers to break into as an example, and the signaling Services_Request is also initiated by the terminal. Therefore, attackers can also use the Services_Request signaling to launch a DDOS attack.
[0107] Services_Request(?s)^Attacker_Control(?u)^send(?u,?s)^ DDOS(?a)->attacks(?a,?s)
[0108] (2) Based on the receiving network element module without security protection measures, deduce other signaling in the 5G signaling virtual platform that may be at risk of attack. Take the example of the base station receiving signaling without security protection measures, and the signaling Services_Request is also received by the base station. Therefore, attackers can also use the Services_Request signaling to launch a DDOS attack.
[0109] Services_Request(?s)^No_Safety_Measures(?r)^receive(?r,?s) ^DDOS(?a)->attacks(?a,?s)
[0110] (3) Based on the sensitive information that the attacker is interested in, deduce other signaling in the 5G signaling virtual platform that may be at risk of being attacked. For example, the attacker knows the content of NF_instance_ID (id) and Reason_Indication (reason), and the Nnrf_NFManagement_NFUpdate signaling only contains the content of NF_instance_ID. Therefore, the attacker can also initiate the Nnrf_NFManagement_NFUpdate signaling by impersonation.
[0111] Nnrf_NFManagement_NFUpdate(?s)^Attacker_Known_Context(?id)^ contains(?s,?id)^Counterfeit(?a)->attacks(?a,?s)
[0112] Based on the constructed 5GC parallel virtual platform and the established 5G signaling security rules, the inference engine is used to realize the automatic discovery of security vulnerabilities. The signaling security vulnerability self-discovery technology based on the inference engine can effectively discover the implicit semantic associations between entities (signaling services / attack operations) to effectively discover potential security risks. The present invention uses the Hermit inference engine for reasoning.
[0113] 5. Experimental results and analysis
[0114] According to the 5G signaling security vulnerability automatic discovery method and system based on ontology modeling designed by the present invention, a network element ontology model, a service ontology model, a service content ontology model and an attack ontology model are established. And the classes in the ontology model are instantiated to use attributes to define in detail the sender network element, the receiver network element and the service content contained in a service instance. And the signaling of a specific attack of an attack instance is defined in detail using attributes. After completing the configuration of the above experimental environment, the inference machine can be used to self-infer the relationship between the attack method and the signaling sender, receiver and content. Then, by judging whether the content contained in other signaling in the 5G virtual platform is a subset of the content that the attacker can obtain, whether other signaling senders are subsets of the sender network element modules that are easily broken by attackers, and whether other signaling receivers are subsets of the receiver network element modules without security protection measures, the remaining potential risk points in the 5G system can be inferred.
[0115] The experiment takes the example of an attacker spoofing the Nnrf_NFManagement_NFDeregister signaling and inferring more vulnerabilities based on the known attack as an example, and explains it in detail. The following specifically introduces the environment required for the experiment and analyzes the experimental reasoning results.
[0116] 5.1 Experimental Environment
[0117] This experiment is based on a PC running Win10. By installing the Protégé software platform and the Hermit inference engine on the PC, ontology modeling and rule reasoning for the 5G signaling virtual platform are realized. Protégé software is an ontology modeling software developed by Stanford University based on the Java language. Protégé provides the creation of ontology concept classes, relationships, attributes, and instances, and shields the specific ontology description language. Users only need to model the ontology at the conceptual level. Therefore, it is currently the most widely used ontology modeling tool. Hermit is an inference engine that uses the OWL language to write the ontology. Hermit can determine whether the ontology is consistent, identify the inclusion relationship between classes, etc. It realizes effective reasoning based on a calculus.
[0118] Based on the above-mentioned Protégé software platform, the content contained in the specific signaling entity in the NRF service signaling is defined, and the signaling attacked by impersonating a specific attack instance is taken as an example for specific explanation. Among them, the signaling entities involved mainly include Nnrf_NFManagement_NFDeregister signaling and Nnrf_NFManagement_NFUpdate signaling. Both belong to instances of the Nnrf_NFManagement second-order subclass in the NRF_Services first-order subclass in the Services top-level class. The experiment defines that the Nnrf_NFManagement_NFDeregister signaling contains NF_instance_ID and Reason_Indication content according to the 3GPP protocol. Nnrf_NFManagement_NFUpdate only contains NF_instance_ID content, such as Fig.10 shown.
[0119] 5.2 Experimental Results
[0120] In 5.1, the instantiation of signaling and attack was completed, and the reasoning and self-discovery of 5G signaling security vulnerabilities were performed based on the Hermit inference engine. After running the Hermit inference engine, the NF_instance_ID and Reason_Indication contents in the Nnrf_NFManagement_NFDeregister signaling are all divided into the Attacker_Known_Context, that is, the NF_instance_ID and Reason_Indication are already available to the attacker, as shown in Figure 12.
[0121] In addition, since Nnrf_NFManagement_NFUpdate only contains NF_instance_ID content, and through the above reasoning, it can be obtained that the NF_instance_ID content is obtainable by the attacker. Therefore, the attacker can also initiate the Nnrf_NFManagement_NFUpdate signaling by impersonation. Fig.13 As shown, it can be inferred that Counterfeit can also attack Nnrf_NFManagement_NFUpdate signaling.
[0122] The above-inferred 5G signaling security vulnerability is tested on actual equipment to verify that the vulnerability is real and feasible. The equipment required for the real experiment mainly includes the Free5GC platform for simulating the 5G core network and the wireshark packet capture software for reading the signaling interaction between network elements. The specific experimental steps are as follows:
[0123] 1. Before the attack, query the registration status and IP port information of amf through the NRF_discover service. Fig.14 shown.
[0124] 2. Use NRF_amf_dere service to illegally deregister amf, and then query no amf information. Fig.15 Fig.16 shown.
[0125] 3. Signaling packet capture, deregistration is initiated by the attacker instead of amf (comparing the ip and port, amf can be seen in step 1) Fig.17 shown.
[0126] 6. Summary
[0127] The present invention designs a 5G signaling security vulnerability automatic discovery method based on the ontology modeling method. First, by building a 5G signaling virtual platform and an ontology model of known vulnerabilities, the relationship between the two is modeled. Among them, the 5G signaling virtual platform mainly includes three top-level classes: network element, signaling, and signaling content. The top-level class is further divided into first-order and second-order subclasses according to the 3GPP protocol regulations. The ontology model of known vulnerabilities mainly includes three categories: interception, tampering, and counterfeiting. Then, security rules are designed, and rules for discovering new vulnerabilities are formulated according to the characteristics of known vulnerabilities, and the inference engine is used to finally realize the automatic discovery of 5G signaling security vulnerabilities. Experimental results show that the 5G signaling security vulnerability automatic discovery method based on ontology modeling of the present invention can effectively perform automatic reasoning and discovery of security vulnerabilities and defects.
[0128] The following is a system embodiment corresponding to the above method embodiment. This embodiment can be implemented in conjunction with the above embodiment. The relevant technical details mentioned in the above embodiment are still valid in this embodiment. In order to reduce repetition, they are not repeated here. Accordingly, the relevant technical details mentioned in this embodiment can also be applied in the above embodiment.
[0129] The present invention also proposes a 5GC signaling security vulnerability automatic discovery system based on ontology modeling, which includes:
[0130] An ontology modeling module is used to perform ontology modeling based on the 5G protocol standard to obtain a signaling interaction model of 5G network elements and network elements, and use the 5G virtual platform as a 5G virtual platform to generate a 5G signaling instance; and perform ontology modeling based on known 5G signaling security vulnerabilities and defects to obtain a vulnerability ontology model, and characterize the vulnerability exploitation behavior in the 5G signaling instance based on the vulnerability ontology model;
[0131] The automatic reasoning module is used to extract features of the known 5G signaling security vulnerabilities and defects, and design verification rules for security vulnerabilities and defects based on the feature extraction results; and based on the verification rules, discover the semantic association between the 5G signaling instance and its vulnerability exploitation behavior, so as to automatically reason and discover 5G signaling vulnerabilities and defects.
[0132] The 5GC signaling security vulnerability automatic discovery system based on ontology modeling, wherein the 5G virtual platform adopts a hierarchical class definition architecture, including a top-level class, a first-order subclass, and a second-order subclass, and utilizes the inheritance relationship between the top-level classes to realize the reuse of the first-order and second-order subclasses;
[0133] According to the 5G protocol standard, three top-level class ontologies, namely, network element function, service and service content, are obtained; each top-level class ontology constructs its first-order subclasses through inheritance; only the first-order subclass of the service class has a second-order subclass for describing the corresponding specific service operations.
[0134] The 5GC signaling security vulnerability automatic discovery system based on ontology modeling, wherein the attack source module and the attacked module in the vulnerability ontology model are respectively used as the attack source module class and the attacked module class; the network element instance of the attack source module has an attribute, which indicates that the network element instance of the attack source module and the corresponding attack method instance are in a usage relationship.
[0135] The automatic discovery system of 5GC signaling security vulnerabilities based on ontology modeling, wherein the inspection rules include two parts. The first part is to obtain the sending network element module breached by the attacker, the receiving network element module without security protection measures, and the information obtained by the attacker based on the currently known 5G signaling attacks; the second part is to deduce the signaling in the 5G virtual platform that is at risk of being attacked based on the first part.
[0136] The present invention also proposes a storage medium for storing a program for executing any one of the 5GC signaling security vulnerability automatic discovery methods based on ontology modeling.
[0137] The present invention also proposes a client for use in any of the above-mentioned 5GC signaling security vulnerability automatic discovery systems based on ontology modeling.
Claims
1. A 5GC signaling security vulnerability automatic discovery method based on ontology modeling, characterized in that: include: Step 1: Based on the 5G protocol standard, ontology modeling is performed to obtain a 5G network element and a signaling interaction model between network elements, which is used as a 5G virtual platform and a 5G signaling instance is generated using the 5G virtual platform; Step 2: Perform ontology modeling based on known 5G signaling security vulnerabilities and defects to obtain a vulnerability ontology model, and characterize the vulnerability exploitation behavior in the 5G signaling instance based on the vulnerability ontology model; Step 3: Extract features of the known 5G signaling security vulnerabilities and defects, and design verification rules for security vulnerabilities and defects based on the feature extraction results; Step 4: Based on the inspection rules, the semantic association between the 5G signaling instance and its vulnerability exploitation behavior is discovered to automatically reason and discover 5G signaling vulnerabilities and defects; The inspection rules include two parts. The first part is to obtain the sender network element module that has been breached by the attacker, the receiver network element module that has no security protection measures, and the information obtained by the attacker based on the currently known 5G signaling attacks. The second part is to deduce the signaling that is at risk of being attacked in the 5G virtual platform based on the first part; Specifically, the second part includes: If the sender of the current signaling s is network element n, and network element n belongs to a known attack source module a, and the attack source module a uses attack method b, then the current signaling s has vulnerabilities and defects that can be exploited by the attacker to launch attack b; If the receiver of the current signaling s is network element n, and network element n belongs to a known attacked module a, and the attacked module a uses attack method b, then the current signaling s has vulnerabilities and defects that are exploited by the attacker to launch attack b; If the current signaling s carries information c, and the information c belongs to sensitive information a that is known to be vulnerable to attack, and the attacker uses attack method b to obtain sensitive information a, then the current signaling s has vulnerabilities and defects that can be exploited by the attacker to launch attack b.
2. The 5GC signaling security vulnerability automatic discovery method based on ontology modeling according to claim 1 is characterized in that: The 5G virtual platform adopts a hierarchical class definition architecture, including top-level classes, first-order subclasses, and second-order subclasses, and uses the inheritance relationship between top-level classes to achieve the reuse of first-order and second-order subclasses; According to the 5G protocol standard, three top-level class ontologies, namely, network element function, service and service content, are obtained; each top-level class ontology constructs its first-order subclasses through inheritance; only the first-order subclass of the service class has a second-order subclass for describing the corresponding specific service operations.
3. The 5GC signaling security vulnerability automatic discovery method based on ontology modeling according to claim 1 is characterized in that: In the vulnerability ontology model, the attack source module and the attacked module are respectively used as the attack source module class and the attacked module class; the network element instance of the attack source module has an attribute, which indicates that the network element instance of the attack source module and the corresponding attack method instance are in a usage relationship.
4. A 5GC signaling security vulnerability automatic discovery system based on ontology modeling, characterized in that: include: An ontology modeling module is used to perform ontology modeling based on the 5G protocol standard to obtain a signaling interaction model of 5G network elements and network elements, and use the 5G virtual platform as a 5G virtual platform to generate a 5G signaling instance; and perform ontology modeling based on known 5G signaling security vulnerabilities and defects to obtain a vulnerability ontology model, and characterize the vulnerability exploitation behavior in the 5G signaling instance based on the vulnerability ontology model; The automatic reasoning module is used to extract features of the known 5G signaling security vulnerabilities and defects, and design verification rules for security vulnerabilities and defects based on the feature extraction results; and based on the verification rules, discover the semantic association between the 5G signaling instance and its vulnerability exploitation behavior, so as to automatically reason and discover 5G signaling vulnerabilities and defects; The inspection rules include two parts. The first part is to obtain the sender network element module that has been breached by the attacker, the receiver network element module that has no security protection measures, and the information obtained by the attacker based on the currently known 5G signaling attacks. The second part is to deduce the signaling that is at risk of being attacked in the 5G virtual platform based on the first part; Specifically, the second part includes: If the sender of the current signaling s is network element n, and network element n belongs to a known attack source module a, and the attack source module a uses attack method b, then the current signaling s has vulnerabilities and defects that can be exploited by the attacker to launch attack b; If the receiver of the current signaling s is network element n, and network element n belongs to a known attacked module a, and the attacked module a uses attack method b, then the current signaling s has vulnerabilities and defects that are exploited by the attacker to launch attack b; If the current signaling s carries information c, and the information c belongs to sensitive information a that is known to be vulnerable to attack, and the attacker uses attack method b to obtain sensitive information a, then the current signaling s has vulnerabilities and defects that can be exploited by the attacker to launch attack b.
5. The 5GC signaling security vulnerability automatic discovery system based on ontology modeling as claimed in claim 4 is characterized in that: The 5G virtual platform adopts a hierarchical class definition architecture, including top-level classes, first-order subclasses, and second-order subclasses, and uses the inheritance relationship between top-level classes to achieve the reuse of first-order and second-order subclasses; According to the 5G protocol standard, three top-level class ontologies, namely, network element function, service and service content, are obtained; each top-level class ontology constructs its first-order subclasses through inheritance; only the first-order subclass of the service class has a second-order subclass for describing the corresponding specific service operations.
6. The 5GC signaling security vulnerability automatic discovery system based on ontology modeling as claimed in claim 4 is characterized in that: In the vulnerability ontology model, the attack source module and the attacked module are respectively used as the attack source module class and the attacked module class; the network element instance of the attack source module has an attribute, which indicates that the network element instance of the attack source module and the corresponding attack method instance are in a usage relationship.
7. A storage medium for storing a program for executing a method for automatically discovering 5GC signaling security vulnerabilities based on ontology modeling as described in any one of claims 1 to 3.
8. A client, used for the 5GC signaling security vulnerability automatic discovery system based on ontology modeling as described in any one of claims 4 to 6.
Citation Information
Patent Citations
Core network security penetration test method, system and equipment based on ontology rule
CN114363903A