The widespread availability of cellular devices introduces new threat vectors that allow users or attackers to bypass security policies and physical barriers and bring unauthorized devices into sensitive areas. We identify a critical gap in this context: the absence of low-latency systems for high-quality and instantaneous monitoring of cellular transmissions. Such low-latency systems are crucial to allow for timely detection, decision, and disruption of unauthorized communication in sensitive areas. Operator-based monitoring systems, built for purposes such as people counting or tracking, lack real-time capability, require cooperation across multiple operators, and thus are hard to deploy. Operator-independent monitoring approaches proposed in the literature either lack low-latency capabilities or do not scale. We propose WaveTag, the first low-latency and scalable system designed to monitor 5G and LTE connections across all operators prior to any user data transmission. WaveTag consists of several downlink sniffers and a distributed network of uplink sniffers that measure both downlink protocol information and uplink signal characteristics at multiple locations to gain a detailed spatial image of uplink signals. WaveTag then aggregates the recorded information, processes it, and provides a decision about the connection--all done prior to the complete connection establishment of a UE. To evaluate WaveTag, we deployed it in the context of geofencing, where WaveTag was able to determine whether the signals originate from inside or outside of an area within 2.3 ms of the initial base station-to-device message, therefore enabling prompt and targeted suppression of communication before any user data was transmitted. WaveTag achieved 99.66% geofencing classification accuracy. Finally, we conduct a real-world uplink measurement evaluation on a commercial 5G SA network.
翻译:蜂窝设备的广泛普及引入了新的威胁向量,使得用户或攻击者能够绕过安全策略与物理屏障,将未经授权的设备带入敏感区域。在此背景下,我们识别出一个关键缺陷:缺乏能够对蜂窝传输进行高质量即时监控的低延迟系统。此类低延迟系统对于在敏感区域实现未经授权通信的及时检测、决策与阻断至关重要。运营商基于的监控系统(如用于人数统计或追踪目的)缺乏实时能力,需要跨多个运营商协作,因而难以部署。文献中提出的独立于运营商的监控方法,要么缺乏低延迟能力,要么无法扩展。我们提出了WaveTag,这是首个低延迟且可扩展的系统,旨在在任何用户数据传输之前,跨所有运营商监控5G和LTE连接。WaveTag由多个下行嗅探器和一个上行嗅探器分布式网络组成,通过在多位置测量下行协议信息与上行信号特征,获取上行信号的详细空间图像。随后,WaveTag聚合记录的信息,进行处理,并提供关于连接的决策——所有这些均在用户设备完成完整连接建立之前完成。为评估WaveTag,我们将其部署在地理围栏场景中。WaveTag能够在初始基站至设备消息发出后的2.3毫秒内,判断信号源自区域内部或外部,从而在用户数据传输前实现及时且有目标的通信抑制。WaveTag实现了99.66%的地理围栏分类准确率。最后,我们在商用5G SA网络上进行了真实世界的上行测量评估。