Jadwal Sholat

Memuat jadwal sholat…

Ilmu Komputer & AI editorial

Open AccessOA2026

5G-Shark: A Network Security Auditor for 5G Subscriber Privacy and Unauthenticated Signalling Resilience

Distinguishing protocol-design limitations from implementation gaps in commercial 5G Standalone deployments
Oscar Lasierra; Gines Garcia-Aviles; Antonio Skarmeta; Xavier Costa-Pérez· 2026· DOI 10.48550/arXiv.2609.24656

The core problem

The fifth generation of mobile networks was standardised with an explicit mandate to close long-standing privacy and security gaps. Among the required guarantees are the concealment of the subscriber's permanent identity, resistance to generational downgrade, and protection against location tracking. Assessing whether these guarantees hold in operational networks, however, requires separating two sources of residual exposure that prior studies do not distinguish and do not evaluate in the wild: **protocol-design limitations**, which remain exploitable even against a fully specification-compliant deployment, and **implementation gaps**, which arise from incomplete or non-compliant implementations. This paper presents 5G-Shark, a security assessment tool and methodology that turns a legitimate mobility procedure against the subscriber. Rather than relying on active jamming or malformed-packet injection, 5G-Shark manipulates the standardised cell-reselection criterion to pull a target User Equipment (UE) onto a self-created rogue cell, establishing an attack vantage with minimal service disruption. The proposed methodology then performs the required interactions to expose the security

Innovation

The evaluation against commercial 5G SA deployments yielded several critical findings. First, 5G-Shark successfully requested subscriber identifiers from UEs in multiple networks. In some cases, the UE responded with its SUCI, but in others, it fell back to sending the SUPI in cleartext, indicating implementation gaps where the concealment mechanism was not properly enforced. Second, crafted Registration Reject messages with cause codes such as #7 (5GS services not allowed) and #22 (Congestion) forced UEs to attempt RAT downgrade to 4G/LTE. This exposes a protocol-design limitation: the standard permits reject messages that do not cryptographically protect the cause code, allowing an attacker to trigger downgrade without authentication. Third, repeated rejections induced DoS states in several UEs, which stopped attempting to access 5G services for extended periods.

Most notably, the authors provide empirical evidence that in several commercial deployments, temporary identifiers (e.g., 5G-GUTI) are re-allocated in near-sequential steps. For instance, successive values might differ by a small constant, making them linkable. This enables persistent user tracking even when the permane

The fifth generation of mobile networks was standardised with an explicit mandate to close long-standing privacy and security gaps. Among the required guarantees are the concealment of the subscriber's permanent identity, resistance to generational downgrade, and protection against location tracking. Assessing whether these guarantees hold in operational networks, however, requires separating two sources of residual exposure that prior studies do not distinguish and do not evaluate in the wild: **protocol-design limitations**, which remain exploitable even against a fully specification-compliant deployment, and **implementation gaps**, which arise from incomplete or non-compliant implementations. This paper presents 5G-Shark, a security assessment tool and methodology that turns a legitimate mobility procedure against the subscriber. Rather than relying on active jamming or malformed-packet injection, 5G-Shark manipulates the standardised cell-reselection criterion to pull a target User Equipment (UE) onto a self-created rogue cell, establishing an attack vantage with minimal service disruption. The proposed methodology then performs the required interactions to expose the security risks of the system under test, classifying them into the aforementioned categories. Built solely from open-source stacks and Software Defined Radio (SDR) hardware, and evaluated against commercial 5G Standalone (SA) deployments, 5G-Shark requests subscriber identifiers, forces Radio Access Technology (RAT) downgrade via crafted Registration Reject codes, and induces denial-of-service (DoS) states. For each vector, the authors attribute the root cause to protocol design or deployment non-compliance. They further provide empirical evidence that in several commercial deployments, temporary identifiers are re-allocated in near-sequential steps that keep successive values linkable, a weakness that enables persistent user tracking despite correct subscriber ID concealment.
5G-Shark is built entirely from open-source software stacks and SDR hardware, ensuring reproducibility and low cost. The core methodological innovation is the use of the standardised cell-reselection procedure as an attack primitive. Instead of jamming or injecting malformed packets, the tool manipulates the reselection criterion—typically based on signal strength and priority—to lure a target UE onto a rogue base station (gNB) created by the attacker. This approach minimises service disruption and avoids triggering common anomaly detection systems that look for radio jamming or protocol violations.

Why it matters

The findings highlight a fundamental tension in 5G security: even a fully specification-compliant deployment may remain vulnerable due to protocol-design limitations. For example, the lack of integrity protection for Registration Reject messages is a design choice that enables downgrade attacks. Similarly, the standard does not mandate that temporary identifiers be allocated with sufficient randomness; it only requires that they be unpredictable to a certain degree, which is often interpreted loosely by vendors. This suggests that the 3GPP specifications need to be tightened to require cryptographic protection for reject messages and to mandate a minimum entropy for temporary identifiers.

On the implementation side, the fallback to SUPI in some UEs indicates that the SUCI concealment procedure is not always correctly implemented. This could be due to misconfiguration, lack of support for the home network's public key, or software bugs. Network operators should audit their deployments using tools like 5G-Shark to identify and patch such gaps.

The methodology of using cell reselection as an attack vector is particularly insidious because it exploits a legitimate procedure and is hard to detect. Traditional anomaly detection may not flag a rogue cell that behaves according to the standard except for the reselection offset. This calls for new detection mechanisms that monitor for unusual reselection patterns or unexpected reject messages.

Finally, the near-sequential allocation of temporary identifiers is a stark reminder that privacy depends not only on cryptographic concealment but also on the statistical properties of identifier assignment. Operators must ensure that temporary identifiers are drawn from a large space with high entropy, and that re-allocation does not follow predictable patterns. The authors recommend that 3GPP consider specifying a minimum entropy requirement and that operators implement random allocation policies.

In summary, 5G-Shark provides a rigorous methodology to separate protocol-design limitations from implementation gaps, offering a path towards more resilient 5G networks. Future work includes extending the tool to 5G-Advanced and 6G, and integrating it with automated mitigation systems.

Who should read this

CS practitioners and researchers

Opening member content…