scieee AI-readable full text Open interactive document viewer

SoK: Evaluating 5G Protocols Against Legacy and Emerging Privacy and Security Attacks

Eleftherakis, Stavros; Giustiniano, Domenico; Kourtellis, Nicolas

Abstract

Ensuring user privacy remains a critical concern within mobile cellular networks, particularly given the proliferation of interconnected devices and services. In fact, a lot of user privacy issues have been raised in 2G, 3G, 4G/LTE networks. Recognizing this general concern, 3GPP has prioritized addressing these issues in the development of 5G, implementing numerous modifications to enhance user privacy since 5G Release 15. In this systematization of knowledge paper, we first provide a framework for studying privacy and security related attacks in cellular networks, setting as privacy objective the User Identity Confidentiality defined in 3GPP standards. Using this framework, we discuss existing privacy and security attacks in pre-5G networks, analyzing the weaknesses that lead to these attacks. Furthermore, we thoroughly study the security characteristics of 5G up to the new Release 19, and examine mitigation mechanisms of 5G to the identified pre-5G attacks. Afterwards, we analyze how recent 5G attacks try to overcome these mitigation mechanisms. Finally, we identify current limitations and open problems in security of 5G, and propose directions for future work.

Full text

SoK: Evaluating 5G Protocols Against Legacy and Emerging Privacy and Security Attacks Stavros Eleftherakis [email protected] Imdea Networks Institite Universidad Carlos III de Madrid Madrid, Spain Domenico Giustiniano [email protected] Imdea Networks Institite Madrid, Spain Nicolas Kourtellis [email protected] Telefonica Research Barcelona, Spain Abstract Ensuring user privacy remains a critical concern within mobile cellular networks, particularly given the proliferation of interconnected devices and services. In fact, a lot of user privacy issues have been raised in 2G, 3G, 4G/LTE networks. Recognizing this general concern, 3GPP has prioritized addressing these issues in the development of 5G, implementing numerous modifications to enhance user privacy since 5G Release 15. In this systematization of knowledge paper, we first provide a framework for studying privacy and security related attacks in cellular networks, setting as privacy objective the User Identity Confidentiality defined in 3GPP standards. Using this framework, we discuss existing privacy and security attacks in pre-5G networks, analyzing the weaknesses that lead to these attacks. Furthermore, we thoroughly study the security characteristics of 5G up to the new Release 19, and examine mitigation mechanisms of 5G to the identified pre-5G attacks. Afterwards, we analyze how recent 5G attacks try to overcome these mitigation mechanisms. Finally, we identify current limitations and open problems in security of 5G, and propose directions for future work. Keywords privacy, security, identifiers, adversaries, cellular networks 1 Introduction In the digital society of today, the widespread use of smartphones has become an integral part of our daily lives. In fact, the number of smartphone mobile network subscriptions worldwide reached almost 6.4 billion in 2022, and is forecast to exceed 7.7 billion by 2028 [ 1 ]. Indeed, this large number of subscribers can be justified by the evolution of cellular technologies. The latest, 5th Generation of Cellular Networks (5G) offers faster data speeds, lower latency, and increased capacity than its predecessors, enabling innovations such as the Internet of Things (IoT), massive MIMO and Millimeter Wave and Terahertz Communications [ 2 , 3 ]. However, the fact that smartphones and cellular networks have become a fundamental aspect of our lives raises an important question: How do we protect the privacy of cellular network users? Vast literature (see [ 4 – 7 ] for some surveys) demonstrated how 4G/LTE networks and their predecessors (2G, 3G) are vulnerable to various privacy attacks for the User Equipment (UE). Specifically, attacks were shown to violate different properties of UE Identity Confidentiality (Sec. 5.1 of [ 8 , 9 ]), such as identity disclosure [ 10 – 12 ], and location privacy [ 13 – 15 ]. Some attacks were demonstrated in 5G early versions [ 16 , 17 ] and even with cheap commodity equipment and open-source code implementations, thus, increasing the privacy risks since access to such tools can be easy. Indeed, it is a challenge for the current and future 5G networks to improve or mitigate the pre-5G networks’ vulnerabilities, therefore, enhancing user privacy [ 5 , 18 – 23 ]. Consequently, the 3rd Generation Partnership Project (3GPP), the international body that is responsible for cellular networks standardization, has considered the aforementioned problems after 5G Release 15, thus, introducing significant changes in the related 5G Security Technical Specification [ 24 ]. That said, recent surveys on the topic [ 5 , 20 , 22 , 25 ] include only theoretical ideas about 5G privacy mechanisms, since they were written before or concurrently with the older, 5G Release 15. Other surveys focused on specific use cases, such as the application of Machine Learning algorithms in 5G Physical layer [ 26 ], the security of the Early Data Transmission 5G mechanism [ 27 ], or the security of alternative computing paradigms (e.g., catalytic computing) in 5G [ 28 ]. Finally, [ 23 , 29 ] analyzed previous cellular generations’ attacks and studied corresponding mitigation mechanisms offered by 5G. In general, past papers on the topic were written in earlier 5G specifications, thus, not being informed about newer Releases of 3GPP documents, recent 5G measurement studies [30–32] and new privacy attacks [12, 33, 34]. In fact, an in-depth study of current literature on this topic raised more unanswered questions: 1) What vulnerabilities did the attacks in past cellular generations exploit, and what were the privacy implications of each? 2) What mitigation mechanisms have been introduced in the new release of 5G to overcome such weaknesses? 3) What gaps still remain for future exploration in the topic of 5G Security? 4) How recent 5G specific attacks take advantage of them? In order to answer these questions, we perform this systemization of knowledge (SoK) paper. We first propose a framework to study the efficiency of current cellular generation security aspects, given wellstudied adversaries demonstrated in past cellular generations, under specific user privacy objectives. Second, we examine the resilience of new 5G security features up to Release 19, called 5G-Advanced, with respect to attacks on previous generations. Third, we examine their adaptability in terms of operators’ implementation, classifying them as ‘optional’ or ‘mandatory’. Fourth, we raise open questions and gaps for future work. With this SoK, our contributions are as follows: • We define a framework for analyzing privacy-related attacks, setting the User Identity Confidentiality defined in 3GPP as our privacy objective (Sec. 3). • We describe 12 existing pre-5G attacks (2G, 3G, 4G/LTE) that violate User Identity Confidentiality, and highlight 12 vulnerabilities or weaknesses that lead to them (Sec. 4). Stavros Eleftherakis, Domenico Giustiniano, and Nicolas Kourtellis • We discuss security enhancements of 5G and mention 10 mitigation mechanisms that are proposed against the aforementioned attacks (Sec. 5). • We describe 7recent 5G attacks along with their corresponding 7vulnerabilities, and the degree they are mitigated by the existing 5G MMs (Sec. 6). • We give a didactic summary of our results from Sec. 4, 5 and 6 in Table. 1. • We discuss key takeaways of our work and outline future research directions (Sec. 7). 2 Background In this section, first, we provide basic information about the Cellular Network infrastructure and its key entities and functionalities (Sec. 2.1). Second, we discuss the properties of different UE identifiers (Sec. 2.2) and UE Capabilities (Sec. 2.3). Then, we cover the 5G registration procedure with its corresponding protocols and mechanisms (Sec. 2.4). We also provide a brief analysis of the paging procedure (Sec. 2.5). 2.1 5G Cellular Network Infrastructure Here, we give an overview of the Cellular Network infrastructure, referring to the main entities and their properties. User Equipment (UE): The UE consists of the Mobile Equipment (ME) and USIM card. It is used by consumers to access mobile services and applications. Radio Access Network (RAN): The Radio Access Network consists of the different Base Stations that are separated into different Tracking Areas (TAs). It is responsible for managing radio resources, enabling handovers, providing wireless connectivity, and facilitating communication between UEs and the Core Network. The RAN comprises base stations (e.g., gnBs in 5G), antennas, and various hardware and software components that enable radio communication. The establishment, maintenance, and release of radio connections between the UE and the RAN is facilitated by the RRC (Radio Resource Control) protocol [35]. Core Network (CN): The Core Network consists of different entities called Network Functions (NFs), that are responsible for a variety of network services and functionalities. For instance, mobility management, authentication, subscriber data management, session management, charging control and connection to external networks are, among others, some important services provided by the CN via these functions. The signaling procedures and messages between the UE and the CN, including functions like registration, authentication, and mobility management are facilitated by the Non-Access Stratum (NAS) protocol [36]. 2.2 Identifiers in 5G Cellular Networks There are various identifiers used in the Cellular Network, responsible for the identification of different entities participating in the system, and especially of the UE at hand. Among the different generations of cellular networks, there are differences between their structure and their name, but their role has been similar. In general, they are divided into permanent and temporary identifiers. To begin with, the International Mobile Subscriber Identity (IMSI) and International Mobile Equipment Identity (IMEI) are the most important permanent identifiers. The first is the identifier of the USIM card used by the UE. This identifier helps the CN identify the specific UE through time and networks. It is used mainly for the initial authentication of the UE to the network and in the past generations 2G, 3G and 4G, it was submitted in plaintext over the wireless channel. As for the IMEI, it is the identifier of the Mobile Equipment (ME), manufactured on the device during its production. Both of them are permanent, global and are considered as extremely sensitive in terms of privacy. 5G introduced Subscription Permanent Identifier (SUPI) in the clause 5.9.2 of the 3GPP 5G technical specifications for security architecture and procedures [ 37 ]. While intuitively SUPI is the same as IMSI, as we will see in the next paragraph regarding temporary identifiers, there is an important difference in the initial authentication: SUPI must never be submitted plaintext, except for emergency cases, as denoted in the clause 5.2.5 of the same 3GPP 5G technical specifications [ 24 ]. As for the IMEI, the terminology of the Permanent Equipment Identifier (PEI) is used in 5G, as analyzed in Sec. 6.4 of [38]. The other important category of identifiers are the temporary ones. First, Subscription Concealed Identifier (SUCI) is introduced in 5G (clause 5.9.2a in [ 37 ]). SUCI is an elliptic cryptography-based concealed version of SUPI that is constructed by the USIM card. Furthermore, the CN assigns a temporary identifier to the UE for the communication between the UE and the CN (e.g., Service Request, paging procedures). In the past, many terminologies have been used for this: Temporary Mobile Subscriber Identity (TMSI) in 2G and 3G, Globally Unique Temporary Identity (GUTI) or TMSI in 4G and 5G Globally Unique Temporary Identity (5G-GUTI) in 5G. For the rest of this paper, we denote it as TMSI for 3G and 4G, and 5G-GUTI for 5G. 5G-GUTI is defined in the clause 5.9.4 of [ 37 ], where the reader can also find information about how 5G-GUTI is constructed. Finally, the UE is also assigned a temporary identifier called Cell Radio Network Temporary Identity (C-RNTI) from the RAN, facilitating the communication between the UE and the RAN. 2.3 UE Capabilities The capabilities of a UE can be separated into Core Network (CN) capabilities [ 36 ] and Radio Access capabilities [ 39 ]. The CN capabilities indicate general UE characteristics, such as the security algorithms supported by the UE for integrity and ciphering protection, and are transmitted as a NAS message. The Radio Access capabilities contain information regarding the radio capabilities of the UE, such as the supported frequency bands of the UE, and are transmitted as an RRC message. As explained in the following section, the UE reports its capabilities to the network during the registration procedure. [ 40 , 41 ] provides further information about UE capabilities. 2.4 UE Registration & Authentication Procedure Figure 1 illustrates the basic message exchange flow with regards to some critical procedures in 5G, as introduced in the 3GPP 5G specifications [ 24 ]. As shown in the figure, the UE sends a registration request including a subscriber identity (SUCI or 5G-GUTI) and the security capabilities. If the 5G-GUTI was sent and the CN cannot resolve it, it sends to the UE an Identity Request message. After that, the UE sends the SUCI in a Identity Response, and then the Authentication and Key Agreement Protocol (AKA) is initiated by SoK: Evaluating 5G Protocols Against Legacy and Emerging Privacy and Security Attacks Figure 1: UE Registration & Authentication signal flow in 5G. the CN. We highlight that both EPS-AKA (Evolved Packet System Authentication and Key Agreement) and 5G-AKA (5G Authentication and Key Agreement) can be used, but since the differences are out of scope for this paper, 5G-AKA (Sec. 6.1.3.2 of [ 24 ]) is used in this work. In a nutsell, the network sends a random number (RAND) and an authentication token (AUTN) to the UE. The UE first verifies the validity of RAND and the freshness of AUTN and if the verification is not successful, it sends a MAC failure or Sync Failure respectively. If both of them are verified successfully, the UE uses the RAND and its permanent key to generate a response (RES) and sends it to the network as its Authentication Response. The network verifies the validity of RES and, if it is valid, the authentication is successful. Further information about the 5G-AKA protocol can be found in [ 42 – 45 ]. After a successful authentication response sent by the UE, NAS Security Command is transmitted in order to activate a secure channel for the NAS protocol messages, providing integrity and ciphering protection. The same procedure is followed for the RRC messages, exchanged between the UE and the gnB, for the activation of a secure channel for them as well. Afterwards, the UE radio capabilities are transmitted to the 5G network, after the establishment of a secure channel (see Figure 1). This is in contrast to prior cellular generations, where radio capabilities were sent before the establishment of a secure channel between the EU and the radio access network. Finally, User Plane (UP) ciphering and integrity is activated through the RRC Reconfiguration message. 2.5 Paging Mechanism The purpose of the paging mechanism is to inform the recipient UE for incoming data transmissions or a phone call. Paging messages are mainly sent by the Base Station (RRC paging), by broadcasting the identity of the UE, that is the recipient of incoming data or a call on the paging channel. In case of incoming data or an SMS, the paging procedure is initiated and all UEs within the cell listen to the paging channel and react to a message if their identity is received. In case of a phone call, the same procedure takes place in a TA level. As explained later, the paging mechanism was a major Passive Sniffer UE Radio Connection Legitimate Base Station (a) Passive adversary. Passive Sniffer Radio Connection UE Legitimate Base Station (b) Semi-passive adversary. Thanks! I am connecting. I offer excellent signal strength Rogue Base Station Jammer Phone Sniffer Optional Equipment UE Legitimate Base Station (c) Active adversary. Figure 2: Different types of adversaries in wireless networks. privacy problem for many cellular generations, since IMSI was used for it, facilitating adversaries to steal the UE’s permanent identity. 3 Methodology In this section, we describe the methodology of our work. First, in Sec. 3.1, we define what User Identity Confidentiality is, and the properties that define it. Then, we give an overview of the different types of adversaries that try to violate the properties of User Identity Confidentiality (Sec. 3.2). Finally, Sec. 3.3 provides an overview of the Framework used for the systematization of the knowledge acquired by the various papers and other documents analyzed pertaining to this topic. 3.1 User Identity Confidentiality Taking into consideration the number of interconnected devices in today networks, and the wide range of sensitive data that are transmitted, it is important to define some privacy objectives about the confidentiality of the user identity. Starting from 3G and 4G cellular networks, the Sec. 5.1.1 of both [ 8 ] and [ 9 ] refers to the security objective of the user identity confidentiality and its corresponding properties. In a nutshell, the protection of users’ identity (IMSI), location and delivered services are of paramount importance. User identity confidentiality requirements are still relevant in 5G as stated in [ 43 ]. For example, the Sec. 5.2.5 of [ 24 ] refers to the user identity confidentiality, by mentioning the SUPI and PEI protection, 5G related identifiers that are equal to IMSI and IMEI in previous generations as mentioned before in the Sec. 2.2. In fact, UE identity confidentiality, as defined in the Sec. 5.1.1 of both [ 8 , 9 ], has been taken into consideration in numerous previous works [ 23 , 46 – 49 ]. Based on the above, UE identity confidentiality is considered as the privacy objective in this work and the following properties are necessary for its protection: Stavros Eleftherakis, Domenico Giustiniano, and Nicolas Kourtellis Challenged by UE Confidentiality (Sec. 3.1) Attacks Adversaries (Sec. 3.2) Protocol Weaknesses •Literature •3GPP Specifications & Reports 5G Security Characteristics Mitigation Analysis Section 5: 5G System Security Sections 4 & 6: Pre-5G and 5G Attacks Section 7 Discussion Exploit Evaluation Privacy Objectives Inform Figure 3: General Framework of our Systematization. • UE Identity Privacy: "the permanent user identity (IMSI) of a user to whom a services is delivered cannot be eavesdropped on the radio access link". • UE Location Privacy: "the presence or the arrival of a user in a certain area cannot be determined by eavesdropping on the radio access link". • UE Untraceability: "an intruder cannot deduce whether different services are delivered to the same user by eavesdropping on the radio access link". 3.2 Adversaries We focus on types of adversaries reported in literature and classified as passive, semi-passive and active, as also proposed in [40]. Next, we provide an overview for each (Fig. 2 illustrates each attack): (1) Passive adversary: It has the ability of eavesdropping radio signals within a specific range, using channel sniffers [ 50 ]. It can receive, decode and store these radio signals, thereby managing to extract valuable and sensitive information for the UE. As it is passive, it is difficult to be detected. (2) Semi-Passive adversary: This is a passive adversary that can also somehow ping its target. The most common example is a passive adversary, that also sends some (silent) messages, or makes some (silent) calls [14] to its victim. (3) Active adversary: This adversary is capable of sending radio signals and messages to its target (e.g., [ 16 , 51 ]) or modify messages that were sent from or to the victim [ 34 ]. Most of the times, it is consisted of a fake base station that offers excellent signal strength [ 52 ]. An active adversary may also have access to sniffers [ 53 ], another UE, or jammer devices [ 54 , 55 ]. It is usually referred to as a “Man-in-theMiddle” (MiTM) adversary [29]. We mention that nowadays, the equipment needed for such attacks can be both affordable and easily deployable. For example, a rogue base station can be constructed by using a Universal Software Radio Peripheral (USRP) [ 56 ] with a modified code of open-source projects like OpenLTE [ 57 ], srsRAN [ 58 , 59 ], gr-LTE [ 60 , 61 ] and OAI [ 62 , 63 ], or by using a shorter range base station called femtocell [ 64 ]. Furthermore, there are available open-source tools for channel sniffers, such as [ 50 , 53 , 65 – 67 ], that are capable of decoding downlink traffic. Finally, jammers can be implemented using commodity equipment [68, 69]. 3.3 Framework In this section, we explain the framework that is used for the systematization of the knowledge analyzed in this paper, as depicted in Figure 3. The very first step is to select the privacy requirements or objectives that should be met by the network system, in order to protect the different stakeholders. We study relevant scientific literature and 3GPP documents, in order to set as privacy objective the UE Identity Confidentiality, as analyzed earlier in Sec. 3.1. Then, we assume that the adversaries denoted in Sec. 3.2 try to challenge the UE Identity Confidentiality, by performing relevant attacks. Thus, in the next Section 4, we overview existing attacks mounted on 2G, 3G and LTE networks, obtaining information from the available literature. During this process of attack review, we identify the weaknesses that lead to each attack, thus increasing our understanding for the contributing factors of each attack. In the next step, as explained in Section 5, we refer again to the available scientific literature and 3GPP documents, but now focusing on 5G Systems (5GS) and their security characteristics. We first analyze these characteristics, compare them to the ones previously mentioned for the past cellular generations (Sec. 4) and their corresponding privacy related weaknesses, and evaluate if these are mitigated in 5G; if yes, we also discuss to which degree. As mentioned before, the 2G, 3G, and 4G related attacks exploited the weaknesses we highlight. Thus, it is straightforward that the (complete or partial) mitigation of these weaknesses contributes to the (complete or partial) mitigation of the related attacks as well in 5G. The same process is applied for recent 5G attacks in Sec. 6, highlighting their weaknesses and verifying if they can be mitigated by 5G mechanisms. To facilitate the reader’s understanding of the perspective of this work, we give a concrete example of our framework with the IMSI Catching. This is a well-known attack (Sec. 4.1.1.1), performed by an active adversary, that violates all of the three properties of the UE Idenity Confidentiality, thus breaking the system’s privacy objectives. The weakness behind this attack in 2G, 3G, and 4G is the plaintext transmission of the USIM permanent identifier IMSI (UE identifiers were analyzed in Sec. 2.2). As a fix to this problem, a new 5G Security characteristic has been introduced, which is the SUCI mechanism (Sec. 5.1), that encrypts the permanent USIM identifier. So, evaluating this new 5G security characteristic called SUCI, we conclude that the previously mentioned weakness, that led to IMSI catching attack, is mitigated. Finally, in the last section, we refer to some limitations of this specific 5G security enhancement due to the lack of available 5G stand-alone (SA) networks, and not strict 3GPP regulations (SUCI is an optional feature). 4 Pre-5G Cellular Generation Attacks In this section, following our framework as defined in Sec. 3.3, we analyze a variety of different attacks that are available in the scientific literature offering different layers of categorization. First, the different attacks are categorized into privacy and security attacks. Then, privacy attacks are further separated into permanent and temporary identifiers-based attacks, protocol exploitation attacks and measurement data exploitation attacks. Regarding security attacks, they are categorized into Data Manipulation attacks and Protocol Downgrade ones. Further, we analyze the type of adversaries that can perform these attacks and evaluate their impact, in terms of UE Confidentiality as defined in Sec. 3.1. Finally, the weaknesses that led to these attacks are outlined (in Italic font) and enumerated SoK: Evaluating 5G Protocols Against Legacy and Emerging Privacy and Security Attacks from 𝑊 1to 𝑊 12. We summarize our findings on all attacks and weaknesses they take advantage of in Table 1. 4.1 User Privacy attacks 4.1.1 Attacks based on Permanent Identifiers 4.1.1.1 IMSI Catching: IMSI Catching [ 51 , 70 – 75 ], which aims to steal the IMSI of the USIM, was one of the first practical attacks in 2G [ 76 ] and has also been persistent in 3G [ 77 ] and 4G [ 78 ]. The attacker uses a device called IMSI Catcher, which as shown in [ 52 , 79 – 81 ] is easily deployable and affordable. IMSI catchers operate in active mode as fake (rogue) base stations [ 11 , 82 , 83 ], sometimes empowered by additional equipment, such as jammers [ 16 ]. First, the IMSI catcher takes advantage of the phone’s behavior to connect to the Cell that offers the strongest signal power. Thus, the IMSI catcher is an active rogue base station that tries to make the victim UE connect to it, by offering better signal quality. When the UE connects to the IMSI catcher device, the adversary sends an Identity Request message. Then, the UE answers with an Identity Response message, including the IMSI without encryption (plaintext), thus, leading to UE identity disclosure, UE traceability and location tracking, consequences that break the UE Confidentiality, as defined in Sec 3.1. Furthermore, IMSI catchers can work in conjunction with a variety of different attacks, such as SIM card cloning [ 84 ], DoS attacks [ 85 , 86 ], stealing of the UE’s phone number [ 87 ]. Evidently, the plaintext IMSI transmission was characterized as a key vulnerability in the clause 6.1.3 of 3GPP Specifications [ 9 ]. When the IMSI of the UE has been obtained, the adversary can work in passive mode and only track the Person of Interest through their IMSI. The passive version described above is referred to as IMSI probing [ 88 ] and has been characterized as low risk in 3GPP TS 33.846 [ 89 ], so it is not analyzed further in this paper. Many different proposals have been made, aiming to stop IMSI Catchers. One one hand, there are five different sets of solutions working on the network side. A first set of solutions proposed either the usage of multiple IMSIs [ 90 , 91 ] per UE, or a new pseudonym instead of the IMSI [ 92 – 94 ]. However, both of them suffer from synchronization problems between the USIM and the network as described in [ 95 , 96 ]. Second, [ 97 – 102 ] proposed significant changes both in the AKA protocol messages and the entities of the mobile network, thus making their implementations impractical. In addition, [ 11 , 103 – 106 ] proposed network-based solutions, examining possible abnormalities (e.g., strange frequencies, unusual Cell locations and Cell IDs, signal noise level, unusual network parameters) that could have been created by the existence of an IMSI Catcher. It is unclear if any operator has implemented such a detection framework. Besides, [ 107 – 109 ] showed the feasibility of applying Machine Learning techniques for IMSI catcher detection but neither an exact framework was proposed nor issues like computational complexity and accuracy were analyzed. Last but not least, SeaGlass [ 110 ] is a sensor-based approach where vehicles with portable sensors collect network measurements over a long period of time, trying to find anomalies caused by the presence of IMSI catchers. On the other hand, different applications were released [ 111 – 115 ], aiming to solve the problem from the subscribers’ side, but they faced limitations such as the low IMSI Catcher detection accuracy and the need of rooting permission to the user’s phone, as analyzed in [ 116 – 118 ]. Summarizing, IMSI catching takes advantage of Weakness #1 (W1): W1: The plaintext IMSI transmission during UE authentication. 4.1.1.2 IMSI Extractor and UE Localization: The goal of the signal overshadowing attack is to disrupt the wireless communication by replacing legitimate signals over the air. This attack requires time and frequency synchronization with the legitimate Base Station (BS), offering signal strength slightly stronger [ 119 ] or slightly weaker [ 120 ] than the legitimate one. In fact, this attack is stealthier compared to the traditional fake BS ones, since it uses a normal signal strength, thus making its detection evenmore difficult. Although most of the existing works use signal overshadowing for Denial of Service (DoS) attacks [ 86 , 119 , 120 ], a recent work [ 12 ] implements it for IMSI catching and UE passive localization. LTrack [ 12 ] is an adversary that uses a fake BS with slightly increased signal strength and perfect synchronization with the legitimate BS and just sends one adversarial message (Identity Request) to the victim. Then, the attacker uses an UL passive sniffer to record the Identity Response message, thus extracting the plaintext IMSI. This attack is called IMSI Extractor [ 12 , 86 ], in order to be differentiated by the traditional IMSI Catchers that do not use signal overshadowing techniques. Based on the definitions given in Sec. 3.2, this adversary is active but if we consider that it transmits only one adversarial message, without neither increasing the signal strength of its rogue BS nor establishing a connection with the victim, there is a difference with the majority of existing attacks. Since the target of this attack is accomplished mainly with the Uplink (UL) and Downlink (DL) sniffers, we characterize this attack as passive in order to show how stealthy is compared to the traditional rogue BS attacks. Finally, the adversary records the timing advance (TA), a parameter that is transmitted without encryption [ 121 ] in LTE, thereby managing to locate the victim with a localization error of around 6 meters. This is a standard weakness due to the message flow in 3G and LTE, since the TA is transmitted before the PCDP layer so the encryption has not been activated yet. On the contrary as stated in [ 122 ], in 2G the TA eavesdropping problem did not exist since the signal flow was different and the TA was transmitted after the activation of encryption. For this reason, this attack is considered as partially applicable in 2G caused only by the plaintext IMSI transmission. Concluding, the two weaknesses behind this attack are W1 and a new, Weakness #2 (W2): W2: The lack of ciphering in MAC messages. 4.1.1.3 IMSI Paging: Another important problem comes from the paging procedures. Paging (Sec. 2.5) is initiated when the network searches for a UE in order to deliver a service to it, such as a phone call or an SMS. In general, the temporary identifier (TMSI) is used for paging, but in some cases (e.g., TMSI cannot be resolved by the network) IMSI can be used as well [ 123 ]. The fact that IMSI could be sent cleartext in paging messages made the paging process vulnerable to many semi-passive adversaries in 2G [ 124 – 126 ], 3G [ 127 , 128 ] and 4G [ 40 , 129 ]. In this type of attack, the adversary already knows some information about the victim UE (e.g., phone number or social network accounts) and tries to take advantage of the paging process weaknesses to track the victim’s location and Stavros Eleftherakis, Domenico Giustiniano, and Nicolas Kourtellis also learn the UE’s IMSI. The attacker initiates the paging process by sending (silent) messages, or making (silent) calls to the victim and at the same time they use a sniffer to observe the unencrypted downlink paging messages to identify the IMSI of the victim’s UE. More information about silent calls and messages can be found in [ 14 , 130 ], but in summary, it is a call or message that activates the paging mechanism without the recipient to get notified. This attack violates the whole set of User Identity’s Confidentiality properties, since it catches the IMSI (identity disclosure) and through the paging messages sniffing, also breaks the location and untraceability privacy, as well. Based on the above, the cause behind this attack is Weakness #3 (W3): W3: Paging procedure with plaintext IMSI transmission. 4.1.1.4 ToRPEDO: Another problem of previous generations of cellular networks is that the Paging Occasions (POs) of a UE are correlated to the IMSI [ 131 , 132 ]. A PO is a specific time interval during which a UE is expected to monitor the paging channel for incoming paging messages. More specifically, one of the parameters of the PO is the Paging Frame Index (PFI) of a UE that is estimated using the IMSI ( 𝑃𝐹𝐼 =𝐼𝑀𝑆𝐼 mod 1024) (Sec. 7 of [ 133 ]). The ToRPEDO semi-passive adversary [ 131 ] observes the unencrypted and fixed PFI of a UE, thereby managing to obtain synchronization between the UE and its corresponding paging delay. Finally, ToRPEDO obtains information about the IMSI from the fixed PFI managing to learn 7 bits of the victim’s IMSI, leading to partial User identity leakage among with location tracking and traceability. In a nutshell, the vulnerability that leads to this attack is Weakness #4 (W4): W4: Estimate of fixed POs based on IMSI. 4.1.1.5 IMEI Catching: As mentioned earlier in Sec. 2.2, IMEI is another sensitive permanent identifier, corresponding to the Mobile Equipment (ME). In 2G and 3G, the cleartext transmission of this identifier was permitted as a response to an Identity Request Message. Thus, an active adversary using a fake base station, similar to IMSI catchers’ adversaries, could send an Identity Request using the IMEI instead of the IMSI, and steal the IMEI of the ME [ 11 , 103 ]. LTE standard specification identified this problem and changed the standard appropriately so that IMEI can be sent only after the activation of a secure channel, as mentioned in [ 9 ] and [ 80 ]. The analysis made in [ 134 ] verified the privacy enhancement of LTE in terms of IMEI privacy and as shown in [ 78 , 135 ] only some old 4G MEs are vulnerable to the IMEI Catching attack. Based on the fact that this vulnerability in 4G/LTE comes from mistaken implementation in the ME side and not protocol vulnerability, IMEI catching is considered as solved in LTE. Concluding, the cause of this attack is Weakness #5 (W5): W5: Plaintext IMEI transmission. 4.1.2 Attacks based on Temporary Identifiers 4.1.2.1 TMSI Anonymity: The main reason for using the temporary identifier (TMSI) is the minimization of IMSI transmissions, offering better anonymity to the UE. In theory, TMSI has to be periodically updated by the network to avoid UE be easily tracked and identified [ 136 ]. However, as shown in [ 127 , 136 ] the TMSI remained constant even for three days, in 2G and 3G networks during experiments that took place in different European countries. Similar results were obtained in LTE networks [ 14 , 40 , 137 ]. More in detail, in [ 14 ] the evidence for the mistaken GUTI refreshment rules is really strong. Detailed experiments in 11 countries and 28 different operators showed that even when the TMSI value was refreshed, the new value was predictable. A semi-passive adversary, consisting of a passive sniffer and a phone that sends some (silent) calls or messages to the victim’s UE, leads to linkability of the victim’s phone number with its TMSI. As a consequence, location tracking and traceability in 2G [ 124 , 138 ], 3G [ 14 ] and LTE [ 14 , 40 ] was achieved, thus breaking two of the three privacy objectives defined in Sec. 3.1. The main weakness behind TMSI Deanonymity attack is Weakness #6 (W6): W6: Not frequent or missconfigured update policy of TMSI. 4.1.2.2 C-RNTI tracking: C-RNTI based attacks is another potential danger for the UE location privacy [ 139 – 145 ] and untraceability [ 146 ]. C-RNTI is local to the users’ serving Base Station (BS) and is used for the communication between the UE and the RAN. C-RNTIs can be found in both UL and DL control plane messages. [ 139 ] passively analyzed the traffic in LTE and found that the C-RNTI is included without encryption in the header of every single packet, regardless of whether it is signaling or user traffic. Linkability between C-RNTI and the victim’s phone number or a social network account (e.g., Telegram or WhatsApp) can be easily done by a semi-passive adversary with some silent messages or calls, as described in [ 14 ]. In terms of decoding the DL messages including the C-RNTI, passive sniffers are available [ 50 , 53 , 67 ], thus, breaking the UE location privacy and untraceability properties. The main vulnerability behind this attack is Weakness #7 (W7): W7: The lack of ciphering in RRC messages. 4.1.3 Protocol Exploitation attacks 4.1.3.1 AKA Protocol Linkability: As mentioned in Sec. 2.4, Authentication and Key Agreement (AKA) protocols are used for the mutual authentication between the UE and CN from 3G and beyond. When the authentication is not successful, there are two failure reasons: MAC Failure or Sync Failure. An active adversary [ 127 , 128 , 147 ] first observes an AKA session of the target user and records the Authentication Request including the authentication challenge (RAND) and token (AUTN). Then, the RAND and AUTN can be replayed by the adversary each time it wants to verify the presence of the target in a specific area. Indeed, thanks to the unencrypted failure messages (Sync or MAC failure), the adversary can distinguish other users from the target user who is the one the Authentication Request was originally sent to. The answer of the target user on the replayed (RAND, AUTN) is a Sync failure, whereas all the other users answer with MAC failure. Thus, linking two AKA sessions compromises the UE location privacy and traceability. We highlight that both 3G-AKA and 4G-AKA (EPS-AKA) did not solve the problem of linkability of AKA failure messages, since failure messages continue being transmitted in cleartext [ 148 , 149 ]. Solutions to the AKA linkability problems were proposed both in 3G [ 127 , 128 ] and 4G [ 102 , 148 , 150 ], but their compatibility with current deployments is limited due to wide changes to the AKA SoK: Evaluating 5G Protocols Against Legacy and Emerging Privacy and Security Attacks protocols, high computational overhead and high communication cost. In a nutshell, this attack exploits Weakness #8 (W8): W8: AKA session failure cause is exposed in plaintext. 4.1.3.2 Device Fingerprinting: Device fingerprinting attack was proposed in LTE networks by Shaik et. all [ 41 ]. The adversary constructed a database of different devices’ Core Network and Radio capabilities. They propose both a passive and an active version for their attack. First, a passive adversary eavesdrops on the first NAS message which up to LTE included the whole set of Core Network Capabilities (e.g., security algorithms supported, telephony features, power saving features, etc). Then the adversary uses the fingerprinting database to understand the device model and the service delivered to the user. Besides, an active version of this adversary transmits a UE Capabilities Inquiry message to the victim, exploiting the Weakness 12 as described later in the Sec. 4.2.2.1, and thus cheating the Radio Capabilities of the UE. As a result, the device fingerprinting attack is more accurate at this time since the adversary obtained both the Core Network and the Radio Capabilities of the UE. This attack breaks the location and untraceability properties and potentially the identity disclosure property as well, since the IMSI is transmitted in the first NAS message. The causes behind this attack is the W12 and a new one, Weakness #9 (W9): W9: Transmission of the whole set of Core Network capabilities in the initial NAS message. 4.1.4 Measurement Data Exploitation Attacks 4.1.4.1 UE measurement reports tracking: In cellular networks, UE performs network measurements and sends them to the Base Station (BS) when requested as an RRC message [ 151 , 152 ]. Specifically, UE measurements report includes signal characteristics (e.g., signal strength of nearby BSs) facilitating the handover procedure and the maintenance of Radio Access Networks. An active attacker using a rogue base station with high signal quality can make the victim to connect to it, and ask for the UE measurements, managing to estimate the UE’s location with triangulation [ 40 , 153 ]. Furthermore, [ 80 ] proposes a passive version of this attack, by simply decoding the plaintext RRC messages including the UE measurement reports among with the user’s C-RNTI. The above-mentioned papers refer to 4G networks, but this kind of attack is similar to 2G and 3G [ 154 ]. We mention that LTE standards mandated that the UE measurement reports should be transmitted after the activation of an RRC secure channel in the Release 13 (LTE advanced) of TS. 36.331 [ 155 ] and as a result, the active version of this attack is mitigated. On the other hand, the passive version of this attack can be mitigated only if the ciphering of RRC messages is activated, something that is operator’s specific since the ciphering of RRC messages is optional [ 9 ]. Based on the above the UE measurements reports attack is considered as partially applicable in LTE networks as shown in Table 1. The vulnerabilities behind this problem are W7 and a new one, Weakness #10 (W10): W10 (up to LTE Release 13):Transmission of UE measurements reports before the establishment of a secure channel. 4.2 User Security Attacks 4.2.1 Data Manipulation Attacks 4.2.1.1 ALTER and IMP4GT attacks: Data manipulation attacks are performed by active adversaries that exploit the lack of integrity in user plane messages, thus managing to redirect the victim UE to a malicious server or impersonate him [ 141 , 156 ]. More in detail, the ALTER attack [ 141 ] allows to redirect a victim to a malicious website by manipulating the destination address of IP packets. The adversary intercepts and modifies the Uplink DNS request message, so that this message reaches an adversarial DNS server instead of the intended one. Then, the adversary also modifies accordingly the Downlink DNS response of the server, so that the attack is not noticed by the victim UE. Furthermore, IMPersonation in 4G neTworks (IMP4GT) attack [ 156 ] is a dangerous extension of the ALTER attack that is able to impersonate not only the UE but the cellular network as well. The cause of Data Manipulation attack is Weakness #11 (W11): W11: Lack of integrity in user plane messages. 4.2.2 Protocol Downgrade attacks 4.2.2.1 Radio Capabilities Bidding-Down attack: Bidding-Down attacks [ 34 , 40 , 41 ] aim to downgrade the UE to a lower cellular technology. The lower the cellular generation the weaker the privacy mechanisms (e.g., 2G has no AKA protocol), therefore, this kind of attack can potentially facilitate all the attacks mentioned in Sec. 4. More in detail, [ 40 , 41 ] analyzes an attack based on the UE radio capabilities. An active adversary (rogue-base station) intercepts the UE Capability Enquiry message, including the radio capabilities of the UE, that was transmitted up to 4G before the establishment of a secure channel, so no integrity protection had been activated. The adversary modifies appropriately the radio capabilities’ characteristics (e.g., modify the frequencies supported by the UE Modem), thus managing to downgrade the UE to a lower cellular generation. Location privacy is directly violated since the adversary intercepts the victim’s message, whereas identity privacy and untraceability properties may be potentially violated as well. The cause of this attack is Weakness #12 (W12): W12: Transmission of UE Radio Capabilities before the establishment of a secure RRC channel. 5 5G Systems Security In this section, we analyze the security protocols and mechanisms proposed for 5G in the related 3GPP document [ 24 ], aiming to minimize or eliminate the problems and security risks of Sec. 4. These improvements stand as mitigation mechanisms, as mentioned in our Framework in Sec. 3.3 and are enumerated clearly in the end of each subsection. Further, we evaluate their potential efficiency in terms of privacy enhancement, matching them to the weaknesses (𝑊1−𝑊12) mentioned in Sec. 4. Finally, their complete or partial adaptability (optional or mandatory mechanisms) to the current 5G networks is considered. The last two columns of Table 1 summarize our findings for 5G. Stavros Eleftherakis, Domenico Giustiniano, and Nicolas Kourtellis Attack Name Privacy Implications Adversary Type Pre 5G Generation 5G Security Characteristics Identity Disclosure Location Tracking Traceability Active Semi-Passive Passive 2G 3G 4G Weakness Exploited Mitigation Mechanisms Optional or Mandatory IMSI Catching [10, 11, 16, 52, 70–72, 77, 78, 80] W1 (Sec. 4.1.1.1) MM1 (Sec. 5.1) MM10 (Sec. 5.6) O O IMSI Extractor and Localization [12, 86] W1 (Sec. 4.1.1.1) W2 (Sec. 4.1.1.2) MM1 (Sec. 5.1) MM10 (Sec. 5.6) O O IMSI Paging [40, 124, 128, 129] W3 (Sec. 4.1.1.3) MM3 (Sec. 5.2.2) M ToRPEDO [131] W4 (Sec. 4.1.1.4) MM4 (Sec. 5.2.2) M IMEI Catching [11, 78, 80, 135] W5 (Sec. 4.1.1.5) Solved since LTE M TMSI Anonymity [14, 124, 127, 136] W6 (Sec. 4.1.2.1) MM2 (Sec. 5.2.1) M C-RNTI tracking [139–141, 146] W7 (Sec. 4.1.2.2) MM6 (Sec. 5.3) O AKA Protocol Linkability [127, 128, 147, 148] W8 (Sec. 4.1.3.1) No MM - Device Fingerprinting [41] W12 (Sec. 4.2.2.1) W9 (Sec. 4.1.3.2) MM9 (Sec. 5.5) MM8 (Sec. 5.4) M M UE Measurements reports [40, 80, 153, 154] W7 (Sec. 4.1.2.2) W10 (Sec. 4.1.4.1) MM6 (Sec. 5.3) Solved since LTE O M Data Manipulation [141, 156] W11 (Sec. 4.2.1.1) MM7 (Sec. 5.3) MM10 (Sec. 5.6) O O Radio Capabilities bidding down attack [34, 40, 41] W12 (Sec. 4.2.2.1) MM9 (Sec. 5.5) M Quantum SUCI [157] W13 (Sec. 6.1.1.1) MM5 (Sec. 5.3) O CSI Reports localization attack [158] W14 (Sec. 6.1.2.1) No MM - ISAC based tracking attack [159–162] W15 (Sec. 6.1.2.2) No MM - Satellite and NTN tracking attack [163, 164] W16 (Sec. 6.1.2.3) No MM - PRS spoofing attack [33, 165] W17 (Sec. 6.2.1.1) MM10 (Sec. 5.6) O Ambient-IoT device spoofing attack [166, 167] W18 (Sec. 6.2.1.2) No MM - 5G Bidding Down attack [17] W19 (sec. 6.2.2.1) MM10 (Sec. 5.6) O : Applicable, : Partially Applicable, : Not Applicable. Table 1: Top part: Overview of pre-5G (2G-4G) attacks against UE Confidentiality, corresponding weakness (W#) exploited, and any mitigation method (MM#) proposed. Bottom part: Overview of new 5G attacks, corresponding weakness exploited and any mitigation method proposed. SoK: Evaluating 5G Protocols Against Legacy and Emerging Privacy and Security Attacks 5.1 Improved UE Identity Privacy based on SUCI As mentioned in Sec. 2.2, SUPI is the corresponding Identifier to IMSI in 5G networks. In order to avoid the plaintext transmission of SUPI, Subscriber Unique Concealed Identifier (SUCI) is introduced as an encrypted form of SUPI, based on elliptic cryptography. In fact, SUCI can be mainly used for authentication if the temporary identifier, 5G-GUTI, is not available. We highlight that the implementation of SUCI is of paramount importance for the UE’s privacy, since it mitigates the attacks imposed by the IMSI plaintext transmission as described in Sections 4.1.1.1 and 4.1.1.2. Therefore, we understand that SUCI mechanism can really improve UE identity privacy. However, its implementation is still optional based on [ 24 ]. In summary, the mitigation mechanism #1 (MM1) is: MM1: Concealment of SUPI using SUCI. 5.2 Improvements on 5G-GUTI 5.2.1 Strict 5G-GUTI update mechanism 5G Global Unique Temporary Identifier (5G-GUTI) is the corresponding identifier to TMSI in previous cellular network generations. As analyzed in Sec. 4.1.2.1, previous generations faced serious privacy problems due to the infrequent or miss-configured refreshment of this temporary identifier [ 14 ]. Based on this outlook, 5G strictly defines when the 5G-GUTI should be updated or refreshed by the Core Network in the clause 6.12.3 of [24]: • Upon receiving Registration Request message of type "initial registration" or "mobility registration update" from UE. • Upon receiving Service Request message sent by the UE in response to a Paging message. • Upon receiving Registration Request message of type "periodic registration update" from a UE. • Upon receiving an indication from lower layers the RRC connection has been resumed for a UE in 5GMM IDLE mode with suspend indication in response to a Paging message. •Even more frequently, based on operator implementation. In addition, it is denoted in the same 3GPP document that 5G-GUTI should be generated in an unpredictable way, bringing us to the Mitigation Mechanism #2 (MM2): MM2: Frequent and unpredictable 5G-GUTI update. 5.2.2 5G-S-TMSI-based paging and POs estimate Another important improvement of 5G compared to previous generations is the decoupling of the IMSI/SUPI from the paging mechanisms. In 5G, paging takes place with a shortened version of 5G-GUTI, called 5G-S-TMSI (5G S-Temporary Mobile Subscription Identifier) as mentioned in Sec. 2.10.1 of [ 38 ]. 5G-S-TMSI is derived from 5G-GUTI, so its strict update mechanism that was analyzed in the previous section holds for 5G-S-TMSI as well. Based on this outlook, 5GGUTI-based paging eliminates the IMSI paging attack as analyzed in Sec. 4.1.1.3. Thus, another mitigation mechanism #3 (MM3) is: MM3: Decoupling of IMSI from paging. Furthermore, the Paging Frame Index (PFI) is now estimated based on 5G-S-TMSI, as mentioned in Sec. 7.1 of [ 168 ] instead of the IMSI. Based on this, the ToRPEDO attack (Sec. 4.1.1.4) is not applicable anymore. We highlight privacy Mitigation Mechanism #4 (MM4): MM4: Decoupling of IMSI from POs’ estimate. 5.3 Improved Integrity & Confidentiality Protection Integrity and confidentiality in 5G networks has many similarities with the status of LTE. First, current 5G Systems are expected to implement the same 128-bit security algorithms with LTE systems: New Radio Encryption Algorithm (NEA) 0, 128-NEA1 and 128-NEA2 for confidentiality (ciphering) and New Radio Integrity Algorithm (NIA) 0, 128-NIA1 and 128-NIA2 for integrity protection, as outlined in Secs. 5.2.2 and 5.2.3 of [ 24 ]. On the other hand, the potential use of 256-bit keys has been introduced as an optional feature in 5G [ 24 , 169 ] to mitigate potential quantum attacks, such as the Quantum SUCI attack (Sec. 6.1.1.1). So, the 5G Mitigation Mechanism #5 (MM5) is: MM5: 256-bit algorithm support for quantum adversary mitigation. Furthermore, in terms of specific messages protection, it is stated that RRC and NAS integrity are mandatory, whereas NAS and RRC ciphering are optional, something that is similar to LTE. As shown in Sec. 4, the attacks described in Secs. 4.1.2.2 and 4.1.4.1 can be mitigated by the RRC ciphering so it is added as the Mitigation Mechanism #6 (MM6) in order to match with these attacks, stating that MM6 is similar in LTE as well: MM6 (similar in LTE): Ciphering of RRC messages. Moreover, another 5G enhancement compared to LTE is the optional integrity protection of User Plane (UP) messages, as introduced in Sec. 5.3 of [ 24 ] that mitigates the Data Manipulation attacks (Sec. 4.2.1.1). So, the Mitigation Mechanism #7 (MM7) is: MM7: Integrity protection of user plane messages. 5.4 Privacy of the initial NAS message Another important and mandatory 5G security mechanism is the privacy of the initial NAS message as described in the section 6.4.6 of [ 24 ]. In contrast to previous generations that the whole set of UE Core network capabilities were transmitted plaintext in the initial NAS message, in 5G only the security capabilities are transmitted. The rest of the UE capabilities are transmitted after the activation of a secure NAS channel. This mitigates the Device fingerprinting attack, as described in Sec. 4.1.3.2. Concluding, the Mitigation Mechanism #8 (MM8) is: MM8:Enhanced privacy for the initial NAS message. 5.5 Secured Radio Capabilities transmission As analyzed in Sec. 4.2.2.1, the UE radio Capabilities were transmitted before the establishment of the RRC security channel, enabling bidding down attacks. This mistaken flow was corrected in 5G, as already mentioned in Sec. 2.4, and depicted in Fig. 1. This is because the RRC UE Capability Inquiry is transmitted after the RRC Security Mode Complete, when integrity protection is enabled. Based on this outlook, the bidding-down attacks based on UE Radio capabilities are eliminated by the mandatory Mitigation Mechanism #9 (MM9): MM9: Radio Capabilities transmission in a secure RRC channel. 5.6 Fake Base Station Detection Framework Fake (rogue) base stations (FBS) were responsible for many different attacks in the previous cellular generations, as described in Sec. 4. 3GPP specifications, for the first time, included an optional Stavros Eleftherakis, Domenico Giustiniano, and Nicolas Kourtellis [134] S. F. Mjølsnes and R. F. Olimid, “Experimental Assessment of Private Information Disclosure in LTE Mobile Networks.,” in SECRYPT, pp. 507–512, 2017. [135] C. Park, S. Bae, B. Oh, J. Lee, E. Lee, I. Yun, and Y. Kim, “ { DoLTEst } : In-depth downlink negative testing framework for { LTE } devices,” in 31st USENIX Security Symposium (USENIX Security 22), pp. 1325–1342, 2022. [136] M. Arapinis, L. I. Mancini, E. Ritter, and M. Ryan, “Privacy through Pseudonymity in Mobile Telephony Systems.,” in NDSS, 2014. [137] C. Sørseth, S. X. Zhou, S. F. Mjølsnes, and R. F. Olimid, “Experimental analysis of subscribers’ privacy exposure by lte paging,” Wireless Personal Communications, vol. 109, pp. 675–693, 2019. [138] S. Saharan and J. Kumar, “Exploiting GSM Vulnerabilities: An Experimental Setup And Procedure To Map TMSI And Mobile Number.,” International Journal of Advanced Research in Computer Science, vol. 8, no. 5, 2017. [139] R. P. Jover, “LTE security, protocol exploits and location tracking experimentation with low-cost software radio,” arXiv preprint arXiv:1607.05171, 2016. [140] R. P. Jover, “LTE security and protocol exploits,” Shmoocon 2016, 2016. [141] D. Rupprecht, K. Kohls, T. Holz, and C. Pöpper, “Breaking LTE on layer two,” in 2019 IEEE Symposium on Security and Privacy (SP), pp. 1121–1136, IEEE, 2019. [142] K. Kohls, D. Rupprecht, T. Holz, and C. Pöpper, “Lost traffic encryption: fingerprinting LTE/4G traffic on layer two,” in Proceedings of the 12th Conference on Security and Privacy in Wireless and Mobile Networks, pp. 249–260, 2019. [143] T. Oh, S. Bae, J. Ahn, Y. Lee, D.-T. Hoang, M. S. Kang, N. O. Tippenhauer, and Y. Kim, “Enabling Physical Localization of Uncooperative Cellular Devices,” arXiv preprint arXiv:2403.14963, 2024. [144] I. Bang, T. Kim, H. S. Jang, and D. K. Sung, “Impact of Uplink Power Control on User Location Tracking Attacks in Cellular Networks,” in ICC 2021-IEEE International Conference on Communications, pp. 1–6, IEEE, 2021. [145] D. Yu and W. Wen, “Non-access-stratum request attack in E-UTRAN,” in 2012 Computing, Communications and Applications Conference, pp. 48–53, IEEE, 2012. [146] D. Rupprecht, K. Kohls, T. Holz, and C. Pöpper, “Call me maybe: Eavesdropping encrypted { LTE } calls with { ReVoLTE } ,” in 29th USENIX security symposium (USENIX security 20), pp. 73–88, 2020. [147] M. S. A. Khan and C. J. Mitchell, “Another look at privacy threats in 3G mobile telephony,” in Australasian Conference on Information Security and Privacy, pp. 386–396, Springer, 2014. [148] C. Hahn, H. Kwon, D. Kim, K. Kang, and J. Hur, “A privacy threat in 4th generation mobile telephony and its countermeasure,” in Wireless Algorithms, Systems, and Applications: 9th International Conference, WASA 2014, Harbin, China, June 23-25, 2014. Proceedings 9, pp. 624–635, Springer, 2014. [149] I. Karim, S. R. Hussain, and E. Bertino, “Prochecker: An automated security and privacy analysis framework for 4g lte protocol implementations,” in 2021 IEEE 41st International Conference on Distributed Computing Systems (ICDCS), pp. 773–785, IEEE, 2021. [150] T. Fei and W. Wang, “The vulnerability and enhancement of AKA protocol for mobile authentication in LTE/5G networks,” Computer Networks, vol. 228, p. 109685, 2023. [151] M. M. Saeed, M. K. Hasan, A. J. Obaid, R. A. Saeed, R. A. Mokhtar, E. S. Ali, M. Akhtaruzzaman, S. Amanlou, and A. Z. Hossain, “A comprehensive review on the users’ identity privacy for 5G networks,” IET Communications, vol. 16, no. 5, pp. 384–399, 2022. [152] M. Svensson, N. Paladi, and R. Giustolisi, “5G: Towards secure ubiquitous connectivity beyond 2020,” 2015. [153] D. Forsberg, H. Leping, K. Tsuyoshi, and S. Alanara, “Enhancing security and privacy in 3GPP E-UTRAN radio interface,” in 2007 IEEE 18th International Symposium on Personal, Indoor and Mobile Radio Communications, pp. 1–5, IEEE, 2007. [154] E. Bitsikas and C. Pöpper, “Don’t hand it over: Vulnerabilities in the handover procedure of cellular telecommunications,” in Annual Computer Security Applications Conference, pp. 900–915, 2021. [155] “3GPP TS 36.331, “Group Radio Access Network; Evolved Universal Terrestrial Radio Access (E-UTRA); Radio Resource Control (RRC); Protocol specification,” version 18.1.0 Rel. 18.” https://www.3gpp.org/, 2024. Accessed: 2024-05. [156] D. Rupprecht, K. Kohls, T. Holz, and C. Pöpper, “IMP4GT: IMPersonation Attacks in 4G NeTworks.,” in NDSS, 2020. [157] V. Q. Ulitzsch, S. Park, S. Marzougui, and J.-P. Seifert, “A post-quantum secure subscription concealed identifier for 6g,” in Proceedings of the 15th ACM Conference on Security and Privacy in Wireless and Mobile Networks, pp. 157–168, 2022. [158] N. Ludant, M. Vomvas, and G. Noubir, “Unprotected 4G/5G Control Procedures at Low Layers Considered Dangerous,” arXiv preprint arXiv:2403.06717, 2024. [159] S. Lu, F. Liu, Y. Li, K. Zhang, H. Huang, J. Zou, X. Li, Y. Dong, F. Dong, J. Zhu, et al., “Integrated sensing and communications: Recent advances and ten open challenges,” IEEE Internet of Things Journal, 2024. [160] J. Wang, N. Varshney, C. Gentile, S. Blandino, J. Chuang, and N. Golmie, “Integrated sensing and communication: Enabling techniques, applications, tools and data sets, standardization, and future directions,” IEEE Internet of Things Journal, vol. 9, no. 23, pp. 23416–23440, 2022. [161] F. Liu, Y. Cui, C. Masouros, J. Xu, T. X. Han, Y. C. Eldar, and S. Buzzi, “Integrated Sensing and Communications: Toward Dual-Functional Wireless Networks for 6G and Beyond,” IEEE Journal on Selected Areas in Communications, vol. 40, no. 6, pp. 1728–1767, 2022. [162] Z. Liu, C. Xu, Y. Xie, E. Sie, F. Yang, K. Karwaski, G. Singh, Z. L. Li, Y. Zhou, D. Vasisht, et al., “Exploring practical vulnerabilities of machine learning-based wireless systems,” in 20th USENIX Symposium on Networked Systems Design and Implementation (NSDI 23), pp. 1801–1817, 2023. [163] J. Pavur and I. Martinovic, “Sok: Building a launchpad for impactful satellite cyber-security research,” arXiv preprint arXiv:2010.10872, 2020. [164] E. Jedermann, M. Strohmeier, V. Lenders, and J. Schmitt, “RECORD: A RECeption-Only region determination attack on LEO satellite users,” in 33rd USENIX Security Symposium (USENIX Security 24), (Philadelphia, PA), pp. 6113– 6130, USENIX Association, Aug. 2024. [165] K. Gao, H. Wang, and H. Lv, “Surgical Strike on 5G Positioning: Selective-PRSSpoofing Attacks and Its Defence,” IEEE Journal on Selected Areas in Communications, 2024. [166] R. Narayanan, A. Varshney, and P. Papadimitratos, “Harvestprint: Securing battery-free backscatter tags through fingerprinting,” in Proceedings of the 20th ACM Workshop on Hot Topics in Networks, pp. 178–184, 2021. [167] T. Jiang, Y. Zhang, W. Ma, M. Peng, Y. Peng, M. Feng, and G. Liu, “Backscatter communication meets practical battery-free Internet of Things: A survey and outlook,” IEEE Communications Surveys & Tutorials, 2023. [168] “3GPP TS 38.304, “NR; User Equipment (UE) procedures in Idle mode and RRC Inactive state,” version 17.7.0 Rel. 17.” https://www.3gpp.org/, 2023. Accessed: 2024-05. [169] “3GPP TR 33.841, “Study on the support of 256-bit algorithms for 5G,” version 16.1.0 Rel. 16.” https://www.3gpp.org/, 2019. Accessed: 2024-02. [170] “3GPP TS 38.809, “Study on 5G security enhancements against False Base Stations (FBS),” version 18.1.0 Rel. 18.” https://www.3gpp.org/, 2023. Accessed: 2024-05. [171] C. J. Mitchell, “The impact of quantum computing on real-world security: A 5G case study,” Computers & Security, vol. 93, p. 101825, 2020. [172] V.-L. Nguyen, P.-C. Lin, B.-C. Cheng, R.-H. Hwang, and Y.-D. Lin, “Security and privacy for 6G: A survey on prospective technologies and challenges,” IEEE Communications Surveys & Tutorials, vol. 23, no. 4, pp. 2384–2428, 2021. [173] J. Yang and T. Johansson, “An overview of cryptographic primitives for possible use in 5G and beyond,” Science China Information Sciences, vol. 63, no. 12, p. 220301, 2020. [174] T. C. Clancy, R. W. McGwier, and L. Chen, “Post-quantum cryptography and 5g security: tutorial,” in Proceedings of the 12th Conference on Security and Privacy in Wireless and Mobile Networks, pp. 285–285, 2019. [175] M. Chlosta, D. Rupprecht, C. Pöpper, and T. Holz, “5G SUCI-Catchers: Still catching them all?,” in Proceedings of the 14th ACM Conference on Security and Privacy in Wireless and Mobile Networks, pp. 359–364, 2021. [176] F. Liu, L. Su, B. Yang, H. Du, M. Qi, and S. He, “Security Enhancements to Subscriber Privacy Protection Scheme in 5G Systems,” in 2021 International Wireless Communications and Mobile Computing (IWCMC), pp. 451–456, IEEE, 2021. [177] “3GPP TS 38.214, “NR; Physical layer procedures for data,” version 18.2.0 Rel. 18.” https://www.3gpp.org/, 2024. Accessed: 2024-05. [178] “WaveJudge Wireless Analyzer Solutions.” https://www.keysight.com/us/en/ products/wireless-analyzers/wavejudge-wireless-analyzer-solutions.html, Keysight Technologies:. [179] “pCR to 33.809 – New solution for KI #7 and KI #5, based on modified CSI reports,”.” https://www.3gpp.org/dynareport?code=Meetings-S3.htm/, 2020. Accessed: 2024-05. [180] “3GPP TS 22.837, “Feasibility Study on Integrated Sensing and Communication ” version 19.3.0 Rel. 19.” https://www.3gpp.org/, 2024. Accessed: 2024-05. [181] F. Adib and D. Katabi, “See through walls with WiFi!,” in Proceedings of the ACM SIGCOMM 2013 conference on SIGCOMM, pp. 75–86, 2013. [182] U. Ha, S. Madani, and F. Adib, “WiStress: Contactless stress monitoring using wireless signals,” Proceedings of the ACM on Interactive, Mobile, Wearable and Ubiquitous Technologies, vol. 5, no. 3, pp. 1–37, 2021. [183] Y. Gu, Y. Zhang, J. Li, Y. Ji, X. An, and F. Ren, “Sleepy: Wireless channel data driven sleep monitoring via commodity WiFi devices,” IEEE Transactions on Big Data, vol. 6, no. 2, pp. 258–268, 2018. [184] D. Vasisht, A. Jain, C.-Y. Hsu, Z. Kabelac, and D. Katabi, “Duet: Estimating user position and identity in smart homes using intermittent and incomplete RF-data,” Proceedings of the ACM on Interactive, Mobile, Wearable and Ubiquitous Technologies, vol. 2, no. 2, pp. 1–21, 2018. [185] Z. Wei, F. Liu, C. Masouros, N. Su, and A. P. Petropulu, “Toward multi-functional 6G wireless networks: Integrating sensing, communication, and security,” IEEE Communications Magazine, vol. 60, no. 4, pp. 65–71, 2022. [186] W. Sun, T. Chen, and N. Gong, “SoK: Secure Human-centered Wireless Sensing,” Proceedings on Privacy Enhancing Technologies, 2024. [187] H. M. Furqan, M. S. J. Solaija, H. Türkmen, and H. Arslan, “Wireless communication, sensing, and REM: A security perspective,” IEEE Open Journal of the SoK: Evaluating 5G Protocols Against Legacy and Emerging Privacy and Security Attacks Communications Society, vol. 2, pp. 287–321, 2021. [188] N. Su, F. Liu, C. Masouros, and A. Al Hilli, “Security and privacy in ISAC systems,” in Integrated Sensing and Communications, pp. 477–506, Springer, 2023. [189] A. Blanco, N. Ludant, P. J. Mateo, Z. Shi, Y. Wang, and J. Widmer, “Performance evaluation of single base station ToA-AoA localization in an LTE testbed,” in 2019 IEEE 30th annual international symposium on personal, Indoor and Mobile Radio Communications (PIMRC), pp. 1–6, IEEE, 2019. [190] M. Kotaru, K. Joshi, D. Bharadia, and S. Katti, “Spotfi: Decimeter level localization using wifi,” in Proceedings of the 2015 ACM conference on special interest group on data communication, pp. 269–282, 2015. [191] S. Eleftherakis, G. Santaromita, M. Rea, X. Costa-Pérez, and D. Giustiniano, “SPRING+: Smartphone Positioning from a Single WiFi Access Point,” IEEE Transactions on Mobile Computing, 2024. [192] F. Adib, H. Mao, Z. Kabelac, D. Katabi, and R. C. Miller, “Smart homes that monitor breathing and heart rate,” in Proceedings of the 33rd annual ACM conference on human factors in computing systems, pp. 837–846, 2015. [193] X. Fang, W. Feng, T. Wei, Y. Chen, N. Ge, and C.-X. Wang, “5G embraces satellites for 6G ubiquitous IoT: Basic models for integrated satellite terrestrial networks,” IEEE Internet of Things Journal, vol. 8, no. 18, pp. 14399–14417, 2021. [194] M. Giordani and M. Zorzi, “Non-terrestrial networks in the 6G era: Challenges and opportunities,” IEEE network, vol. 35, no. 2, pp. 244–251, 2020. [195] F. Rinaldi, H.-L. Maattanen, J. Torsner, S. Pizzi, S. Andreev, A. Iera, Y. Koucheryavy, and G. Araniti, “Non-terrestrial networks in 5G & beyond: A survey,” IEEE access, vol. 8, pp. 165178–165200, 2020. [196] M. M. Azari, S. Solanki, S. Chatzinotas, O. Kodheli, H. Sallouha, A. Colpaert, J. F. M. Montoya, S. Pollin, A. Haqiqatnejad, A. Mostaani, et al., “Evolution of non-terrestrial networks from 5G to 6G: A survey,” IEEE communications surveys & tutorials, vol. 24, no. 4, pp. 2633–2672, 2022. [197] S. Kota and G. Giambene, “6G integrated non-terrestrial networks: Emerging technologies and challenges,” in 2021 IEEE International Conference on Communications Workshops (ICC Workshops), pp. 1–6, IEEE, 2021. [198] A. Vanelli-Coralli, A. Guidotti, T. Foggi, G. Colavolpe, and G. Montorsi, “5G and Beyond 5G Non-Terrestrial Networks: trends and research challenges,” in 2020 IEEE 3rd 5G World Forum (5GWF), pp. 163–169, IEEE, 2020. [199] O. Kodheli, E. Lagunas, N. Maturo, S. K. Sharma, B. Shankar, J. F. M. Montoya, J. C. M. Duncan, D. Spano, S. Chatzinotas, S. Kisseleff, et al., “Satellite communications in the new space era: A survey and future challenges,” IEEE Communications Surveys & Tutorials, vol. 23, no. 1, pp. 70–109, 2020. [200] “3GPP TS 38.300, “NR; NR and NG-RAN Overall Description; Stage 2,” version 18.2.0 Rel. 18.” https://www.3gpp.org/, 2024. Accessed: 2024-09. [201] “3GPP TS 38.821, “Solutions for NR to support non-terrestrial networks (NTN),” version 16.2.0 Rel. 16.” https://www.3gpp.org/, 2023. Accessed: 2024-09. [202] “3GPP TR 22.865, “Study on satellite access Phase 3," version 19.2.0, Release 19.” https://www.3gpp.org/, 2023. Accessed: 2024-09. [203] “3GPP TR 23.700-29, “Study on integration of satellite components in the 5G architecture; Phase 3 ," version 19.0.0, Release 19.” https://www.3gpp.org/, 2024. Accessed: 2024-09. [204] P. Tedeschi, S. Sciancalepore, and R. Di Pietro, “Satellite-based communications security: A survey of threats, solutions, and research challenges,” Computer Networks, vol. 216, p. 109246, 2022. [205] R. Singh, I. Ahmad, and J. Huusko, “The role of physical layer security in satellite-based networks,” in 2023 Joint European Conference on Networks and Communications & 6G Summit (EuCNC/6G Summit), pp. 36–41, IEEE, 2023. [206] M. Vaezi, A. Azari, S. R. Khosravirad, M. Shirvanimoghaddam, M. M. Azari, D. Chasaki, and P. Popovski, “Cellular, wide-area, and non-terrestrial IoT: A survey on 5G advances and the road toward 6G,” IEEE Communications Surveys & Tutorials, vol. 24, no. 2, pp. 1117–1174, 2022. [207] I. Ahmad, J. Suomalainen, P. Porambage, A. Gurtov, J. Huusko, and M. Höyhtyä, “Security of satellite-terrestrial communications: Challenges and potential solutions,” IEEE Access, vol. 10, pp. 96038–96052, 2022. [208] D. Margaria, B. Motella, M. Anghileri, J.-J. Floch, I. Fernandez-Hernandez, and M. Paonni, “Signal structure-based authentication for civil GNSSs: Recent solutions and perspectives,” IEEE signal processing magazine, vol. 34, no. 5, pp. 27–37, 2017. [209] F. Chiti, R. Picchi, and L. Pierucci, “A survey on non-terrestrial quantum networking: Challenges and trends,” Computer Networks, p. 110668, 2024. [210] M. Manulis, C. P. Bridges, R. Harrison, V. Sekar, and A. Davis, “Cyber security in new space: analysis of threats, key enabling technologies and challenges,” International Journal of Information Security, vol. 20, pp. 287–311, 2021. [211] J. Pavur, M. Strohmeier, V. Lenders, and I. Martinovic, “Qpep: An actionable approach to secure and performant broadband from geostationary orbit,” Internet Society, 2021. [212] J. Huwyler, J. Pavur, G. Tresoldi, and M. Strohmeier, “QPEP in the Real World: A Testbed for Secure Satellite Communication Performance.,” in SpaceSec, 2023. [213] J. Pavur, D. Moser, M. Strohmeier, V. Lenders, and I. Martinovic, “A tale of sea and sky on the security of maritime VSAT communications,” in 2020 IEEE Symposium on Security and Privacy (SP), pp. 1384–1400, IEEE, 2020. [214] A. Iqbal, M.-L. Tham, Y. J. Wong, G. Wainer, Y. X. Zhu, T. Dagiuklas, et al., “Empowering non-terrestrial networks with artificial intelligence: A survey,” IEEE Access, 2023. [215] P. Kumar, R. Kumar, A. N. Islam, S. Garg, G. Kaddoum, and Z. Han, “Distributed AI and Blockchain for 6G-assisted terrestrial and non-terrestrial networks: Challenges and future directions,” IEEE Network, vol. 37, no. 2, pp. 70–77, 2023. [216] G. Fontanesi, F. Ortíz, E. Lagunas, V. M. Baeza, M. Vázquez, J. Vásquez-Peralvo, M. Minardi, H. Vu, P. Honnaiah, C. Lacoste, et al., “Artificial intelligence for satellite communication and non-terrestrial networks: A survey,” arXiv preprint arXiv:2304.13008, 2023. [217] S. Mahboob and L. Liu, “Revolutionizing future connectivity: A contemporary survey on AI-empowered satellite-based non-terrestrial networks in 6G,” IEEE Communications Surveys & Tutorials, 2024. [218] M. Rath and S. Mishra, “Security approaches in machine learning for satellite communication,” Machine learning and data mining in aerospace technology, pp. 189–204, 2020. [219] L. Junzhi, L. Wanqing, F. Qixiang, and L. Beidian, “Research progress of GNSS spoofing and spoofing detection technology,” in 2019 IEEE 19th International Conference on Communication Technology (ICCT), pp. 1360–1369, IEEE, 2019. [220] S. Han, J. Li, W. Meng, M. Guizani, and S. Sun, “Challenges of physical layer security in a satellite-terrestrial network,” IEEE Network, vol. 36, no. 3, pp. 98– 104, 2022. [221] B. Li, Z. Fei, C. Zhou, and Y. Zhang, “Physical-layer security in space information networks: A survey,” IEEE Internet of things journal, vol. 7, no. 1, pp. 33–52, 2019. [222] F. Formaggio and S. Tomasin, “Authentication of satellite navigation signals by wiretap coding and artificial noise,” EURASIP Journal on Wireless Communications and Networking, vol. 2019, pp. 1–17, 2019. [223] J. Liu, J. Wang, W. Liu, Q. Wang, and M. Wang, “A novel cooperative physical layer security scheme for satellite downlinks,” Chinese Journal of Electronics, vol. 27, no. 4, pp. 860–865, 2018. [224] N. Hosseinidehaj, Z. Babar, R. Malaney, S. X. Ng, and L. Hanzo, “Satellite-based continuous-variable quantum communications: State-of-the-art and a predictive outlook,” IEEE Communications Surveys & Tutorials, vol. 21, no. 1, pp. 881–919, 2018. [225] R. Bedington, J. M. Arrazola, and A. Ling, “Progress in satellite quantum key distribution,” npj Quantum Information, vol. 3, no. 1, p. 30, 2017. [226] G. Focarelli, S. Zanini, G. Bianchi, and S. Bartoletti, “Physical Layer Threats to 5G Positioning: Impact on TOA-Based Methods,” in 2024 IEEE International Conference on Communications Workshops (ICC Workshops), pp. 926–931, IEEE, 2024. [227] “3GPP TS 22.369, “Service requirements for ambient power-enabled IoT; Stage 1” version 19.1.0 Rel. 19.” https://www.3gpp.org/, 2024. Accessed: 2024-05. [228] “3GPP TS 38.769, “Study on solutions for ambient IoT (Internet of Things);” version 19.0.1 Rel. 19.” https://www.3gpp.org/, 2024. Accessed: 2024-05. [229] A. Varshney, O. Harms, C. Pérez-Penichet, C. Rohner, F. Hermans, and T. Voigt, “LoRea: A backscatter architecture that achieves a long communication range,” in Proceedings of the 15th ACM Conference on Embedded Network Sensor Systems, pp. 1–14, 2017. [230] V. Talla, M. Hessar, B. Kellogg, A. Najafi, J. R. Smith, and S. Gollakota, “Lora backscatter: Enabling the vision of ubiquitous connectivity,” Proceedings of the ACM on interactive, mobile, wearable and ubiquitous technologies, vol. 1, no. 3, pp. 1–24, 2017. [231] V. Liu, A. Parks, V. Talla, S. Gollakota, D. Wetherall, and J. R. Smith, “Ambient backscatter: Wireless communication out of thin air,” ACM SIGCOMM computer communication review, vol. 43, no. 4, pp. 39–50, 2013. [232] “3GPP TSG RAN WG1 #116-bis, "Ambient IoT Device Architecture,”.” https: //www.3gpp.org/dynareport?code=Meetings-S3.htm/, 2024. Accessed: 2024-05. [233] N. Van Huynh, D. T. Hoang, X. Lu, D. Niyato, P. Wang, and D. I. Kim, “Ambient backscatter communications: A contemporary survey,” IEEE Communications surveys & tutorials, vol. 20, no. 4, pp. 2889–2922, 2018. [234] D. Zanetti, B. Danev, and S. Capkun, “Physical-layer identification of UHF RFID tags,” in Proceedings of the sixteenth annual international conference on Mobile computing and networking, pp. 353–364, 2010. [235] A. Scalingi, S. D’Oro, F. Restuccia, T. Melodia, D. Giustiniano, et al., “Det-RAN: Data-Driven Cross-Layer Real-Time Attack Detection in 5G Open RANs,” in IEEE International Conference on Computer Communications, pp. 1–10, 2024. [236] T. Heijligenberg, G. Knips, C. Böhm, D. Rupprecht, and K. Kohls, “BigMac: Performance Overhead of User Plane Integrity Protection in 5G networks,” in Proceedings of the 16th ACM Conference on Security and Privacy in Wireless and Mobile Networks, pp. 145–150, 2023. [237] M. M. Saeed, R. A. Saeed, R. A. Mokhtar, H. Alhumyani, and E. S. Ali, “A novel variable pseudonym scheme for preserving privacy user location in 5G networks,” Security and Communication Networks, vol. 2022, 2022. [238] M. M. Saeed, R. A. Saeed, and E. Saeid, “Identity division multiplexing based location preserve in 5G,” in 2021 International Conference of Technology, Science and Administration (ICTSA), pp. 1–6, IEEE, 2021. [239] A. Koutsos, “The 5G-AKA authentication protocol privacy,” in 2019 IEEE European symposium on security and privacy (EuroS&P), pp. 464–479, IEEE, 2019. Stavros Eleftherakis, Domenico Giustiniano, and Nicolas Kourtellis [240] “3GPP TS 33.846, “Study on authentication enhancements in the 5G System (5GS),” version 17.0.0 Rel. 17.” https://www.3gpp.org/, 2021. Accessed: 2024-05. [241] A. Lotto, V. Singh, B. Ramasubramanian, A. Brighente, M. Conti, and R. Poovendran, “BARON: Base-Station Authentication Through Core Network for Mobility Management in 5G Networks,” in Proceedings of the 16th ACM Conference on Security and Privacy in Wireless and Mobile Networks, pp. 133–144, 2023. [242] S. R. Hussain, M. Echeverria, A. Singla, O. Chowdhury, and E. Bertino, “Insecure connection bootstrapping in cellular networks: the root of all evil,” in Proceedings of the 12th conference on security and privacy in wireless and mobile networks, pp. 1–11, 2019. [243] A. Singla, R. Behnia, S. R. Hussain, A. Yavuz, and E. Bertino, “Look before you leap: Secure connection bootstrapping for 5g networks to defend against fake base-stations,” in Proceedings of the 2021 ACM Asia Conference on Computer and Communications Security, pp. 501–515, 2021. [244] Y. Li, S. Liu, Z. Yan, and R. H. Deng, “Secure 5G positioning with truth discovery, attack detection, and tracing,” IEEE Internet of Things Journal, vol. 9, no. 22, pp. 22220–22229, 2021. [245] P. K. Nakarmi, M. A. Ersoy, E. U. Soykan, and K. Norrman, “Murat: Multi-rat false base station detector,” arXiv preprint arXiv:2102.08780, 2021. [246] K. S. Mubasshir, I. Karim, and E. Bertino, “FBSDetector: Fake Base Station and Multi Step Attack Detection in Cellular Networks using Machine Learning,” arXiv preprint arXiv:2401.04958, 2024. [247] P. K. Nakarmi, J. Sternby, and I. Ullah, “Applying machine learning on rsrp-based features for false base station detection,” in Proceedings of the 17th International Conference on Availability, Reliability and Security, pp. 1–7, 2022. [248] M. Saedi, A. Moore, P. Perry, and C. Luo, “RBS-MLP: A Deep Learning based Rogue Base Station Detection Approach for 5G Mobile Networks,” IEEE Transactions on Vehicular Technology, 2024. [249] M. Polese, L. Bonati, S. D’oro, S. Basagni, and T. Melodia, “Understanding ORAN: Architecture, interfaces, algorithms, security, and research challenges,” IEEE Communications Surveys & Tutorials, vol. 25, no. 2, pp. 1376–1411, 2023. [250] S. Park, D. Kim, Y. Park, H. Cho, D. Kim, and S. Kwon, “5G security threat assessment in real networks,” Sensors, vol. 21, no. 16, p. 5524, 2021. [251] S. Park, I. You, H. Park, and D. Kim, “Analyzing RRC Replay Attack and Securing Base Station with Practical Method,” in Proceedings of the 17th International Conference on Availability, Reliability and Security, pp. 1–8, 2022. [252] Z. Cheng, M. Ordean, F. D. Garcia, B. Cui, and D. Rys, “Watching your call: Breaking VoLTE privacy in LTE/5G networks,” arXiv preprint arXiv:2301.02487, 2023. [253] S. Kwon, S. Park, H. Cho, Y. Park, D. Kim, and K. Yim, “Towards 5G-based IoT security analysis against Vo5G eavesdropping,” Computing, vol. 103, pp. 425–447, 2021. [254] M. S. Wani, M. Rademacher, T. Horstmann, and M. Kretschmer, “Security Vulnerabilities in 5G Non-Stand-Alone Networks: A Systematic Analysis and Attack Taxonomy,” Journal of Cybersecurity and Privacy, vol. 4, no. 1, pp. 23–40, 2024. [255] G. Holtrup, W. Lacube, D. P. David, A. Mermoud, G. Bovet, and V. Lenders, “5g system security analysis,” arXiv preprint arXiv:2108.08700, 2021. [256] G. Holtrup, W. Blonay, M. Strohmeier, A. Mermoud, J.-P. Chavanne, and V. Lenders, “Modeling 5G Threat Scenarios for Critical Infrastructure Protection,” in 2023 15th International Conference on Cyber Conflict: Meeting Reality (CyCon), pp. 161–180, IEEE, 2023. [257] E. Bitsikas, S. Khandker, A. Salous, A. Ranganathan, R. Piqueras Jover, and C. Pöpper, “UE Security Reloaded: Developing a 5G Standalone User-Side Security Testing Framework,” in Proceedings of the 16th ACM Conference on Security and Privacy in Wireless and Mobile Networks, pp. 121–132, 2023.