Mobile networks are essential for modern societies. The most recent generation of mobile networks will be even more ubiquitous than previous ones. Therefore, the security of these networks as part of the critical infrastructure with essential communication services is of the uttermost importance. However, these systems are still vulnerable to being compromised, as showcased in the recent discussion on supply chain security and other challenges. This work addresses problems arising from compromised 5G core network components. The investigations reveal how attacks based on command and control communication can be designed so that they cannot be detected or prevented. This way, various attacks against the security and privacy of subscribers can be performed for which no effective countermeasures are available.
翻译:移动网络对现代社会至关重要。最新一代移动网络将比以往各代更为普及。因此,这些作为关键基础设施组成部分、提供基本通信服务的网络安全具有极端重要性。然而,正如近期关于供应链安全及其他挑战的讨论所示,这些系统仍易遭受攻击。本文针对受损的5G核心网组件所引发的问题展开研究。研究揭示如何设计基于命令与控制通信的攻击,使其无法被检测或阻止。通过这种方式,可实施针对用户安全与隐私的各种攻击,且目前尚无有效的应对措施。