We gratefully acknowledge support from
the Simons Foundation and member institutions.
Full-text links:

Download:

Current browse context:

cs.CR

Change to browse by:

cs

References & Citations

DBLP - CS Bibliography

Bookmark

(what is this?)
CiteULike logo BibSonomy logo Mendeley logo del.icio.us logo Digg logo Reddit logo

Computer Science > Cryptography and Security

Title: Berserker: ASN.1-based Fuzzing of Radio Resource Control Protocol for 4G and 5G

Abstract: Telecom networks together with mobile phones must be rigorously tested for robustness against vulnerabilities in order to guarantee availability. RRC protocol is responsible for the management of radio resources and is among the most important telecom protocols whose extensive testing is warranted. To that end, we present a novel RRC fuzzer, called Berserker, for 4G and 5G. Berserker's novelty comes from being backward and forward compatible to any version of 4G and 5G RRC technical specifications. It is based on RRC message format definitions in ASN.1 and additionally covers fuzz testing of another protocol, called NAS, tunneled in RRC. Berserker uses concrete implementations of telecom protocol stack and is unaffected by lower layer protocol handlings like encryption and segmentation. It is also capable of evading size and type constraints in RRC message format definitions. Berserker discovered two previously unknown serious vulnerabilities in srsLTE -- one of which also affects openLTE -- confirming its applicability to telecom robustness.
Comments: 19 pages, 9 figures, 17 tables
Subjects: Cryptography and Security (cs.CR)
DOI: 10.1109/WiMob52687.2021.9606317
Cite as: arXiv:2107.01912 [cs.CR]
  (or arXiv:2107.01912v2 [cs.CR] for this version)

Submission history

From: Prajwol Kumar Nakarmi [view email]
[v1] Mon, 5 Jul 2021 10:06:25 GMT (835kb,D)
[v2] Thu, 2 Dec 2021 15:19:43 GMT (1189kb,D)

Link back to: arXiv, form interface, contact.