5G-Shark: A Network Security Auditor for 5G Subscriber Privacy and Unauthenticated Signalling Resilience
5G-Shark audit tool pulls 5G phones onto rogue cells via cell-reselection manipulation, exposing identifier linkability and downgrade flaws in commercial networks.
The paper presents 5G-Shark, a security assessment tool and methodology built from open-source stacks and SDR hardware that manipulates the standardized cell-reselection criterion to pull a target User Equipment onto a self-created rogue cell with minimal service disruption. Evaluated against commercial 5G Standalone deployments, it requests subscriber identifiers, forces Radio Access Technology downgrade via crafted Registration Reject codes, and induces denial-of-service states. It distinguishes protocol-design limitations from implementation non-compliance, and provides empirical evidence that several commercial deployments re-allocate temporary identifiers in near-sequential steps, keeping successive values linkable and enabling persistent tracking despite correct subscriber ID concealment.
- Turns legitimate mobility procedure against subscriber by manipulating cell-reselection criterion
- Built from open-source stacks and SDR; evaluated against commercial 5G SA deployments
- Forces RAT downgrade via crafted Registration Reject codes and induces DoS states
- Near-sequential temporary identifiers in several deployments enable persistent user tracking
Full article246 words · extracted from arxiv.org · click to collapse
The fifth generation of mobile networks was standardised with an explicit mandate to close long-standing privacy and security gaps, mandating the concealment of the subscriber's permanent identity, resistance to generational downgrade, and protection against location tracking. Assessing whether these guarantees hold in operational networks, however, requires separating two sources of residual exposure that prior studies do not distinguish and do not evaluate in the wild: protocol-design limitations, which remain exploitable even against a fully specification-compliant deployment, and implementation gaps, which arise from incomplete or non-compliant implementations. We present 5G-Shark, a security assessment tool and methodology that turns a legitimate mobility procedure against the subscriber. Rather than relying on active jamming or malformed-packet injection, 5G-Shark manipulates the standardised cell-reselection criterion to pull a target User Equipment onto a self-created rogue cell, establishing an attack vantage with minimal service disruption. Then, the proposed methodology effectively performs the required interactions to expose the security risks of the system under test, classifying them into the aforementioned categories. Built solely from open-source stacks and Software Defined Radio hardware and evaluated against commercial 5G Standalone deployments, 5G-Shark requests subscriber identifiers, forces Radio Access Technology downgrade via crafted Registration Reject codes, and induces denial-of-service states. For each vector, we attribute the root cause to protocol design or deployment non-compliance. We further provide empirical evidence that in several commercial deployments, temporary identifiers are re-allocated in near-sequential steps that keep successive values linkable, a weakness that enables persistent user tracking despite correct subscriber ID concealment.
Text extracted automatically; images, tables and formatting may be missing. Original: https://arxiv.org/abs/2609.24656