TIMESAFE: Timing Interruption Monitoring and Security Assessment for Fronthaul Environments

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Groen, Joshua, Di Valerio, Simone, Karim, Imtiaz, Villa, Davide, Zhang, Yiewi, Bonati, Leonardo, Polese, Michele, D'Oro, Salvatore, Melodia, Tommaso, Bertino, Elisa, Cuomo, Francesca, Chowdhury, Kaushik
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866915604977418240
author Groen, Joshua
Di Valerio, Simone
Karim, Imtiaz
Villa, Davide
Zhang, Yiewi
Bonati, Leonardo
Polese, Michele
D'Oro, Salvatore
Melodia, Tommaso
Bertino, Elisa
Cuomo, Francesca
Chowdhury, Kaushik
author_facet Groen, Joshua
Di Valerio, Simone
Karim, Imtiaz
Villa, Davide
Zhang, Yiewi
Bonati, Leonardo
Polese, Michele
D'Oro, Salvatore
Melodia, Tommaso
Bertino, Elisa
Cuomo, Francesca
Chowdhury, Kaushik
contents 5G and beyond cellular systems embrace the disaggregation of Radio Access Network (RAN) components, exemplified by the evolution of the fronthaul (FH) connection between cellular baseband and radio unit equipment. Crucially, synchronization over the FH is pivotal for reliable 5G services. In recent years, there has been a push to move these links to an Ethernet-based packet network topology, leveraging existing standards and ongoing research for Time-Sensitive Networking (TSN). However, TSN standards, such as Precision Time Protocol (PTP), focus on performance with little to no concern for security. This increases the exposure of the open FH to security risks. Attacks targeting synchronization mechanisms pose significant threats, potentially disrupting 5G networks and impairing connectivity. In this paper, we demonstrate the impact of successful spoofing and replay attacks against PTP synchronization. We show how a spoofing attack is able to cause a production-ready O-RAN and 5G-compliant private cellular base station to catastrophically fail within 2 seconds of the attack, necessitating manual intervention to restore full network operations. To counter this, we design a Machine Learning (ML)-based monitoring solution capable of detecting various malicious attacks with over 97.5% accuracy.
format Preprint
id arxiv_https___arxiv_org_abs_2412_13049
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle TIMESAFE: Timing Interruption Monitoring and Security Assessment for Fronthaul Environments
Groen, Joshua
Di Valerio, Simone
Karim, Imtiaz
Villa, Davide
Zhang, Yiewi
Bonati, Leonardo
Polese, Michele
D'Oro, Salvatore
Melodia, Tommaso
Bertino, Elisa
Cuomo, Francesca
Chowdhury, Kaushik
Networking and Internet Architecture
Cryptography and Security
Machine Learning
Systems and Control
C.2; C.4
5G and beyond cellular systems embrace the disaggregation of Radio Access Network (RAN) components, exemplified by the evolution of the fronthaul (FH) connection between cellular baseband and radio unit equipment. Crucially, synchronization over the FH is pivotal for reliable 5G services. In recent years, there has been a push to move these links to an Ethernet-based packet network topology, leveraging existing standards and ongoing research for Time-Sensitive Networking (TSN). However, TSN standards, such as Precision Time Protocol (PTP), focus on performance with little to no concern for security. This increases the exposure of the open FH to security risks. Attacks targeting synchronization mechanisms pose significant threats, potentially disrupting 5G networks and impairing connectivity. In this paper, we demonstrate the impact of successful spoofing and replay attacks against PTP synchronization. We show how a spoofing attack is able to cause a production-ready O-RAN and 5G-compliant private cellular base station to catastrophically fail within 2 seconds of the attack, necessitating manual intervention to restore full network operations. To counter this, we design a Machine Learning (ML)-based monitoring solution capable of detecting various malicious attacks with over 97.5% accuracy.
title TIMESAFE: Timing Interruption Monitoring and Security Assessment for Fronthaul Environments
topic Networking and Internet Architecture
Cryptography and Security
Machine Learning
Systems and Control
C.2; C.4
url https://arxiv.org/abs/2412.13049