RAN Security Series: Part 2 of 4
In this second blog post of the Radio Access Network (RAN) Security series, different attack surfaces, attack vectors, and attack scenarios across the RAN are explored. The post aims to once again highlight the importance of assessing RAN security by explaining different categories of threats and attackers’ tactics, techniques, and procedures, supported by attack flow illustrations. Assessing the security of the RAN should not be limited to configuration review alone, but should also include active assessments, particularly on the radio interface.
This blogpost does not provide an exhaustive list of attacks and threats on the radio interface, only selecting a diverse set of attacks. The focus will be on those attacks relevant to 4G networks and will highlight which ones are still applicable to 5G SA (StandAlone) NR (New Radio) networks.
How a Subscriber Connects to a Network
A simplified mobile connection flow typically follows these steps:
- Cell Discovery: The phone scans for nearby cells and selects one.
- RRC Connection: The device requests radio resources from the base station.
- Attach & Authentication: The core verifies the subscriber and applies policies.
- Data Session: An IP address is assigned and traffic begins flowing.
Figure 1 below provides a simple map of this flow, which will be referenced throughout the attack discussion.

As seen, attackers commonly target the cell discovery phase, RRC handshake, and ability to force fallback to older technologies.
What is an Attack Surface on the Radio Interface?
The attack surface on the radio interface represents the collection of entry points and vulnerabilities within the wireless link between the User Equipment (UE) and the Base Station (eNB/gNB). Unlike traditional IT security, where the attack surface is often confined to firewalls or application endpoints, the radio interface attack surface is omnipresent and accessible to anyone within radio range.
This surface can be categorized into three primary layers:
1. The Physical Layer (L1) Surface
This is the raw radio frequency (RF) environment. Since radio waves propagate through open space, an adversary can access this layer without physical proximity to the network hardware.
- Vulnerability: The openness of the air interface.
- Exploitation: An attacker can use high-gain antennas to sniff downlink traffic from kilometers away or use low-cost Software Defined Radios (SDRs) to inject interference (Jamming).
2. The Protocol & Signaling Surface (L2/L3)
Modern cellular networks rely on a complex “handshake” of protocols (MAC, RLC, PDCP, and RRC) to manage connectivity.
- Vulnerability: Unauthenticated Broadcast Information. Before a phone even tries to log in, the base station broadcasts critical system information (SIBs) that is unencrypted and unauthenticated.
- Exploitation: Adversaries can spoof these broadcast messages to trick phones into connecting to fake cells or to manipulate how a phone behaves during handover and cell selection.
3. The Identity & State Surface
The network must keep track of which phones are connected and where they are. This “state” management creates a surface for tracking.
- Vulnerability: Temporary vs. Permanent Identifiers. While the network tries to use temporary IDs (GUTI/TMSI), certain protocol procedures force the device to reveal its permanent ID (IMSI/SUPI).
- Exploitation: An attacker can trigger specific protocol “paging” messages to force a device to respond, thereby confirming the presence of a specific user in a specific area.
Threats on the Radio Interface
The radio interface, known formally as the Uu interface, serves as the bridge between the UE and the RAN . Because this interface relies on open-air transmission, it is fundamentally different from a wired connection; it cannot be physically “locked away.” Any adversary with a capable transceiver can attempt to listen to, interfere with, or impersonate the signaling occurring on this link.
To understand the risk, how an exploit manifests must be looked at. The impact of radio interface-based threats can be categorized into three primary categories:
- Privacy Threats: These target the subscriber’s identity and metadata. Examples include unauthorized location tracking, IMSI catching, and eavesdropping on unencrypted signaling or user data.
- Availability Threats: These target the “uptime” of the connection. By exploiting protocol weaknesses or the physical medium itself, attackers can deny service to specific users or collapse the capacity of an entire cell (Denial of Service).
- Fraud Threats: These involve the unauthorized use of network resources. This includes bypassing billing systems, spoofing subscriber identities to access premium services, or manipulating the network to hide traffic consumption.
In each of the explained threats below, which category or set of categories a threat can be mapped to will be highlighted, providing a clear view of the risk to both the operator and the end-user.
Subscriber Privacy Threats: Fake Base Stations (Rogue eNodeB / IMSI Catchers)
In the taxonomy of modern telecom threats, the Fake Base Station (FBS) often referred to as an IMSI Catcher or Rogue eNodeB is a cornerstone technique. However, following the philosophy of the MITRE ATT&CK® framework (and its telecom-specific evolution, MITRE FiGHT™), a false base station is best defined as a tool or enabling platform rather than a standalone attack or technique .
As shown in Figure 2, the FBS as a tool exploits a fundamental design characteristic of cellular protocols: mobile devices are programmed to be “network seekers.” To ensure seamless connectivity, UEs constantly scan for the strongest cell signal. In the initial phases of cell selection (before the RRC connection is fully secured), devices often trust broadcast system information (MIBs and SIBs) with limited to no verification of the network’s authenticity.

By deploying a high-gain SDR and specialized open-source stacks (like srsRAN or Open5GS), an adversary can:
- Impersonate Legitimate Cells: Emit a signal with the same MCC/MNC as a local carrier but with a higher Reference Signal Received Power (RSRP) to force the UE to re-select the rogue cell.
- Exploit the Unauthenticated Identity Request: Before the core network authenticates the device, the rogue station can send an Identity Request message. The UE, following standard protocol, will respond with its permanent identity, such as the IMSI in 4G or the SUPI in 5G if the null scheme is used, allowing for targeted tracking.
- Force Protocol Downgrades: By spoofing a cell that supports only older, less secure generations (like 2G), an attacker can strip away modern encryption layers, making the device vulnerable to eavesdropping.
A successfully positioned Fake Base Station allows an adversary to:
- De-anonymize Subscribers: Link a physical person to their permanent hardware ID (IMSI/SUPI).
- Precision Location Tracking: Monitor when a specific target enters or leaves a “blast radius.”
- MitM Manipulation: Intercept or alter non-encrypted signaling and user-plane traffic.
Protocol-Based Attacks
This category of attacks focuses on the manipulation of the legitimate behavior, procedures and flows of the 3rd Generation Partnership Project (3GPP) radio protocols to disrupt the service, deny radio access to subscribers or resource exhaust the eNB or gNB in case of the 5G. This section provides just two examples, a full threat analysis on radio protocols is needed to provide more depth and understanding what are other possible attack surfaces.
Additionally, since most protocol based attack’s impact is related to resource exhaustion, an attempt was made to provide a formulation of the possible impacts and the parameters of the attack that can be factors to increase the impact.
1. Radio Resource Control Signaling Storms
The Radio Resource Control (RRC) protocol is responsible for creating and tearing down radio connections. Every connection request consumes radio and processing resources. This is usually referred to as the RRC Connection Setup, which is the essential procedure in radio communications to allow the UE to acquire resources on the radio interface and in turn connect and authenticate to the core network. A simplified procedure is illustrated below in Figure 3.

An RRC signaling storm occurs when manipulated devices rapidly generate connection requests, overwhelming the base station, with figure 4 below illustrating how small control-plane messages can create large-scale disruption.

The impact of attack is a function of the attack parameters used by the adversary
$$RrcAttackImpact\ =\ f(RateOfRequests, ProcedureDelay, EstablishmentCause)$$2. Scheduling Requests overload
In a mobile network, the Uplink (from phone to tower) is strictly managed by the base station to prevent devices from “talking” over one another. A mobile phone cannot simply transmit data whenever it wants; it must first be “granted” permission.
The Scheduling Request (SR) is the very first signal a device sends to the eNB/gNB to start this process. It tells the eNB/gNB scheduler: “I have data in my buffer that needs to be sent, please give me a time and frequency slot to send it.”, it is then sent over the PUCCH (Physical Uplink Control Channel). Unlike a data packet, the SR is often just a single bit (or a specific sequence). It doesn’t say how much data the phone has; it only signals the need for an initial resource grant. If the base station has capacity, it responds with an Uplink Grant, which tells the phone exactly which Physical Resource Blocks (PRBs) it can use to send its data (including its Buffer Status Report).
In short, the Scheduling Request is the foundational handshake for all uplink communication. If this request is blocked or manipulated, the device is effectively silenced. A simple illustration of the process is illustrated in Figure 5.

While RRC signaling storms target the control plane’s high-level logic, an SR Overload targets the very first heartbeat of radio resource allocation. This attack operates at the MAC (Medium Access Control) layer, making it faster to execute and harder to filter than higher-layer protocol attacks.
The base station has a finite amount of scheduler processing capacity and a limited number of PRBs that can be assigned in any given millisecond. An adversary can exploit these limitations by:
Simultaneous Triggering: Using a botnet of compromised or low-cost UE modules to send SRs at a massive frequency.
Request Without Payload: The devices send the request for resources but never actually send the data once the resource is granted.
Buffer Status Report (BSR) Manipulation: Sending fake reports indicating they have a massive “backlog” of data to send, forcing the scheduler to reserve large chunks of the radio spectrum for “ghost” traffic.
The result is resource exhaustion. Legitimate users may still observe a strong signal, but they are unable to obtain a “grant” to transmit their data. The scheduler becomes “congested” while attempting to process thousands of fake requests, leading to:
- Increased Latency: Delay in resource allocation for emergency or high-priority services.
- Total Cell Blocking: The eNB reaches its maximum capacity for active users, preventing any new devices from attaching to the cell.
The intensity of an SR Overload can be modeled by the pressure it puts on the scheduler’s capacity:
As 𝑇𝑜𝑡𝑎𝑙_𝑆𝑅𝑠_𝑅𝑒𝑐𝑒𝑖𝑣𝑒𝑑 increases, the processing latency spikes exponentially, eventually leading to a complete crash of the MAC-layer scheduling function.
Jamming Attacks: From Noise to Surgical Disruption
Jamming is a L1 attack that uses RF interference to degrade the Signal-to-Interference-plus-Noise Ratio (SINR). While traditional jamming is a “brute force” method, modern Smart Jamming is protocol-aware, targeting specific 3GPP physical channels with high efficiency.
1. Barrage Jamming
This is the most basic form of electronic warfare. The attacker transmits high-power white noise across the entire downlink or uplink frequency band.
- Mechanism: Drowns out the legitimate signal so the UE (User Equipment) cannot decode any data.
- Impact: Complete disruption of all downlink or uplink communications in the affected area. All users lose connectivity, and the network becomes unavailable until the jamming ceases. Though easily detected by O&M (Operations and Maintenance) systems as a spike in external interference, the immediate impact is total service disruption.
2. Pilot/Synchronization Channel Jamming
Instead of jamming the whole band, the adversary targets the PSS (Primary Synchronization Signal) and SSS (Secondary Synchronization Signal).
- Mechanism: If a phone cannot see the PSS/SSS, it cannot “see” the cell at all. These signals only occupy a small portion of the center of the bandwidth. By jamming just these few RBs, the attacker can render a 100MHz 5G carrier invisible using minimal power.
- Impact: Prevents Cell Discovery, the very first step of the connection flow.
3. Uplink Control Channel (PUCCH) Jamming
This is a sophisticated “denial of service” targeting the path from the phone to the base station.
- Mechanism: The attacker jams the PUCCH, which carries HARQ ACKs (confirmations that data was received).
- Impact: Even if the phone receives data perfectly, it cannot “tell” the base station it received it. The base station will keep re-transmitting the same data until the connection eventually times out and drops.
Conclusions and Takeaways
This blog post explored the diverse landscape of attacks on the RAN radio interface. It highlighted how various attack surfaces and vectors can be leveraged to compromise the very foundation of mobile connectivity. Since the RAN is the primary access point for any 3GPP capable device, the most immediate impact of these attacks is service disruption and loss of availability. However, as outlined earlier, the threats extend far beyond downtime, encompassing critical privacy breaches and complex fraud scenarios whether targeted at the subscriber or triggered by them.
RAN should no longer be treated as a “black box” assumed to be inherently secure. Modern, multi-vector attacks increasingly utilize the radio interface as a primary entry point. To defend against these evolving threats, organizations must move towards:
- Automated Configuration Compliance: Ensuring that no operational “drift” or misconfiguration inadvertently opens a new attack surface.
- Active Monitoring & SIEM Integration: Moving beyond basic fault management to true security visibility by integrating RAN-specific traffic patterns and data collectors into the Telecom SOC.
- Continuous Threat Analysis: Consistently analyzing threats and modelling what can possibly go wrong in the network.
The next blog post in this series will dive into the importance of threat analysis in the RAN and the specific methodologies required to stay ahead of the adversary.
Stay synced and secure!
References
[1] 3GPP TS 33.401: 3GPP System Architecture Evolution (SAE); Security architecture.
[2] 3GPP TS 38.300: NR; Overall description; Stage-2.
[3] 3GPP TS 36.331: Evolved Universal Terrestrial Radio Access (E-UTRA); Radio Resource Control (RRC); Protocol specification.
[4] 3GPP TS 36.321: Evolved Universal Terrestrial Radio Access (E-UTRA); Medium Access Control (MAC) protocol specification.
[5] MITRE FiGHT™ (Adversarial Tactics, Techniques, and Procedures for 5G): mitre.org.
[6] GSMA FS.31: 5G Security Guide.
[7] “Touching the Untouchable: Denial of Service Attacks on 4G LTE Control Plane” by J. Rupprecht et al.
[8] “Practical Attacks Against Privacy and Availability in 4G/LTE Mobile Communication Systems” by Shaik et al.
