美国国家安全局-5G基础设施的潜在威胁(英文)-2021.5-16页_5mb
报告摘要
Summary of 5G Threat Vectors
Core Content
The document outlines the potential threat vectors to 5G infrastructure, emphasizing the risks associated with the transition to 5G technology. It identifies three main threat vectors: Policy and Standards, Supply Chain, and 5G Systems Architecture, each with associated sub-threats that could compromise the security, integrity, and availability of 5G networks.
The National Strategy to Secure 5G is highlighted as a U.S. government initiative aimed at securing 5G infrastructure both domestically and internationally. It includes four lines of effort, with the second line focusing on assessing and managing cybersecurity risks through the Enduring Security Framework (ESF) and the 5G Threat Model Working Panel.
The report serves as an initial analysis and is not exhaustive, but it provides a foundation for understanding the types of threats that may emerge with 5G adoption.
Main Threat Vectors
1. Policy and Standards Threat Scenarios
-
Nation-State Influence on 5G Standards
- Threat: Adversarial nations may exert undue influence on the development of 5G and related technologies (e.g., autonomous vehicles, edge computing, telemedicine) to limit the availability of trusted suppliers and create a disadvantage for the U.S.
- Scenario: A nation-state becomes a global leader in telesurgery and forces U.S. hospitals to adopt its untrusted technologies or those built to its de facto standards, potentially limiting U.S. market growth and security.
-
University Implementation of Optional 5G Security Controls
- Threat: Organizations that do not implement optional security controls may have significant cybersecurity gaps.
- Scenario: A university adopts 5G for its campus network but fails to implement all recommended security controls, leading to vulnerabilities that can be exploited by malicious actors.
2. Supply Chain Threat Scenarios
-
Implementation of Counterfeit Components
- Threat: Counterfeit components can be inserted into the supply chain to impact downstream users. These components may be substandard or contain malicious functionalities.
- Scenario: A government contractor unknowingly purchases and uses counterfeit components in its ICT systems, leading to potential system performance issues, loss of critical services, or data breaches.
-
Unintentional Adoption of Untrusted Components
- Threat: Malicious code can be introduced into software components through supply chain attacks, often remaining undetected for extended periods.
- Scenario: A trusted telecommunications provider acquires a core network management software that contains a compromised component, which may be used as part of a larger attack chain to access the core network and pivot to other attack vectors.
3. 5G Systems Architecture Threat Scenarios
-
Inherited Vulnerabilities from 4G Networks
- Threat: 5G may inherit vulnerabilities from 4G LTE networks, such as SS7 and Diameter protocol weaknesses.
- Scenario: A threat actor spoofs a 4G signal and forces a 5G network to downgrade to a vulnerable 4G configuration, allowing access to sensitive data and further infiltration into secure networks.
-
Firmware Vulnerability within the Multi-Access Edge Compute (MEC)
- Threat: MEC systems, which process and store data closer to the end user, may contain untrusted components or malware that can be used to clone devices and impersonate users.
- Scenario: A firmware vulnerability in the MEC allows a threat actor to maintain a persistent foothold, deny access to data, and impact the ultra-low latency required by 5G applications, ultimately enabling access to the Radio Access Network (RAN).
Key Information
-
The National Strategy to Secure 5G aims to secure U.S. 5G infrastructure and aligns with the National Cyber Strategy. It outlines four lines of effort, including the assessment of cybersecurity risks and the promotion of global secure 5G deployment.
-
The Enduring Security Framework (ESF) is a cross-sector working group that evaluates threats to U.S. national security systems. It plays a critical role in identifying and managing 5G-related risks.
-
5G Threat Model Working Panel was established to focus on identifying and prioritizing threat vectors, particularly those related to NSA (Non-Standalone) networks.
-
5G systems are more complex than previous generations due to increased use of ICT components, new technologies like software-defined networking (SDN), network slicing, and MEC. This complexity increases the attack surface and the potential for exploitation.
-
Legacy systems like 4G LTE still play a role in 5G deployment, and their vulnerabilities may persist or be exploited in 5G environments.
-
Supply chain risks are heightened by the global nature of 5G technology and the potential for counterfeit or untrusted components to be introduced at any stage of development or deployment.
-
Threat modeling is a critical tool in identifying potential vulnerabilities and attack vectors before they are exploited, allowing for proactive security measures.
Conclusion
The transition to 5G brings both opportunities and risks. While it enables new innovations and services, it also introduces vulnerabilities that could be exploited by nation-states, malicious actors, and supply chain threats. The U.S. government is actively working to mitigate these risks through strategic initiatives like the National Strategy to Secure 5G and the Enduring Security Framework (ESF). Continuous assessment and management of 5G threat vectors are essential to maintaining the security and integrity of 5G infrastructure.
试读结束,高清完整版pdf/doc/ppt,请点下载