Ilmu Komputer & AI editorial
5G-Shark: A Network Security Auditor for 5G Subscriber Privacy and Unauthenticated Signalling Resilience
The core problem
Innovation
The evaluation against commercial 5G SA deployments yielded several critical findings. First, 5G-Shark successfully requested subscriber identifiers from UEs in multiple networks. In some cases, the UE responded with its SUCI, but in others, it fell back to sending the SUPI in cleartext, indicating implementation gaps where the concealment mechanism was not properly enforced. Second, crafted Registration Reject messages with cause codes such as #7 (5GS services not allowed) and #22 (Congestion) forced UEs to attempt RAT downgrade to 4G/LTE. This exposes a protocol-design limitation: the standard permits reject messages that do not cryptographically protect the cause code, allowing an attacker to trigger downgrade without authentication. Third, repeated rejections induced DoS states in several UEs, which stopped attempting to access 5G services for extended periods.
Most notably, the authors provide empirical evidence that in several commercial deployments, temporary identifiers (e.g., 5G-GUTI) are re-allocated in near-sequential steps. For instance, successive values might differ by a small constant, making them linkable. This enables persistent user tracking even when the permane
Why it matters
The findings highlight a fundamental tension in 5G security: even a fully specification-compliant deployment may remain vulnerable due to protocol-design limitations. For example, the lack of integrity protection for Registration Reject messages is a design choice that enables downgrade attacks. Similarly, the standard does not mandate that temporary identifiers be allocated with sufficient randomness; it only requires that they be unpredictable to a certain degree, which is often interpreted loosely by vendors. This suggests that the 3GPP specifications need to be tightened to require cryptographic protection for reject messages and to mandate a minimum entropy for temporary identifiers.
On the implementation side, the fallback to SUPI in some UEs indicates that the SUCI concealment procedure is not always correctly implemented. This could be due to misconfiguration, lack of support for the home network's public key, or software bugs. Network operators should audit their deployments using tools like 5G-Shark to identify and patch such gaps.
The methodology of using cell reselection as an attack vector is particularly insidious because it exploits a legitimate procedure and is hard to detect. Traditional anomaly detection may not flag a rogue cell that behaves according to the standard except for the reselection offset. This calls for new detection mechanisms that monitor for unusual reselection patterns or unexpected reject messages.
Finally, the near-sequential allocation of temporary identifiers is a stark reminder that privacy depends not only on cryptographic concealment but also on the statistical properties of identifier assignment. Operators must ensure that temporary identifiers are drawn from a large space with high entropy, and that re-allocation does not follow predictable patterns. The authors recommend that 3GPP consider specifying a minimum entropy requirement and that operators implement random allocation policies.
In summary, 5G-Shark provides a rigorous methodology to separate protocol-design limitations from implementation gaps, offering a path towards more resilient 5G networks. Future work includes extending the tool to 5G-Advanced and 6G, and integrating it with automated mitigation systems.
Who should read this
Opening member content…