针对5G前传同步安全漏洞,提出基于机器学习的攻击检测方案。
TIMESAFE: Timing Interruption Monitoring and Security Assessment for Fronthaul Environments
- 利用机器学习分析时间同步数据流,实时识别异常
- 实测可97.5%准确检测欺骗与重放攻击,2秒内触发故障
- 适合关注5G前传网络安全部署的工程师与运营商
5G及未来移动系统采用无线接入网(RAN)组件解耦,前传(FH)链路连接基带与射频单元。同步性能对5G服务可靠性至关重要。近年来,前传链路逐步转向以太网包网络架构,依托时间敏感网络(TSN)标准,如精密时间协议(PTP)。然而,现有TSN标准侧重性能,缺乏安全性考量,使开放前传面临显著安全风险。针对同步机制的攻击可能严重破坏5G网络并导致通信中断。本文展示了针对PTP同步的欺骗与重放攻击的破坏力:在真实部署的O-RAN与5G合规私有基站上,攻击可在2秒内引发灾难性故障,需人工干预才能恢复。为此,我们设计了一种基于机器学习的监控方案,能以超过97.5%的准确率检测多种恶意攻击。
原文摘要 · Abstract (English)
5G and beyond cellular systems embrace the disaggregation of Radio Access Network (RAN) components, exemplified by the evolution of the fronthaul (FH) connection between cellular baseband and radio unit equipment. Crucially, synchronization over the FH is pivotal for reliable 5G services. In recent years, there has been a push to move these links to an Ethernet-based packet network topology, leveraging existing standards and ongoing research for Time-Sensitive Networking (TSN). However, TSN standards, such as Precision Time Protocol (PTP), focus on performance with little to no concern for security. This increases the exposure of the open FH to security risks. Attacks targeting synchronization mechanisms pose significant threats, potentially disrupting 5G networks and impairing connectivity. In this paper, we demonstrate the impact of successful spoofing and replay attacks against PTP synchronization. We show how a spoofing attack is able to cause a production-ready O-RAN and 5G-compliant private cellular base station to catastrophically fail within 2 seconds of the attack, necessitating manual intervention to restore full network operations. To counter this, we design a Machine Learning (ML)-based monitoring solution capable of detecting various malicious attacks with over 97.5% accuracy.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。