5G Positioning: Security and Privacy Aspects 291
13.5 Survey of Security Threats and Privacy Issues
in 5G Positioning
We have seen so far the main players in 5G positioning and the main positioning technologies for 5G. In what follows, we will address the security and privacy threats according to each of the 5G positioning players, as shown in Figure 13.1. We group here the
security‐related vulnerabilities in 5G into two main classes:
● vulnerabilities related to the reliability and integrity of the positioning solution in
the presence of interferers, attacks or unintentional errors. We will refer to this
class under the generic name of “security threats” and they are addressed in
Section 13.3.1.
● vulnerabilities related to the privacy of the users’ location solution. We will refer to
this class under the generic name of “privacy concerns” and they are addressed in
Section 13.3.2.
13.5.1 Security Threats in 5G Positioning
Security threats can be further divided according to the 5G positioning player in the
block diagram of Figure 13.1. LIC and the end‐user are treated jointly, as these security
threats are common to both. Also, some of the security threats are common to several
players.
13.5.1.1 Security Threats Affecting Several or All Players
These kinds of security threats are also common to other wireless networks, not only to
5G, and both from the communication and localization aspects. In general, the information threats to wireless devices can be classified into passive and active attacks. The
passive attacks consist of situations when attackers in the wireless networks attempt to
grasp information via exploiting the network vulnerability, while the active attacks are
those when the attacker is attempting to disrupt the network communication and also
affect the user productivity in a network. Listed below are some of the most common
types of security threats as discussed in [83,103]:
● A Denial of Service attack (DoS): these are active attacks attempting to inhibit or
prevent legitimate use of the wireless navigation or communication services;
● Distributed DoS (DDoS): a distributed DoS is another active attack that occurs when
multiple systems are used to flood the resources or bandwidth of a group of servers
or one single server, such as LISP or LBSP from Figure 13.1. The main purpose of this
attack is to saturate a resource so that it is no longer available for its legitimate use. It
is often used as a decoy to hide a more malicious attack, which attempts to steal sensitive information or other data;
● Man in the Middle (MiM) attack: this is an active attack where an attacker intercepts
the path of communications or positioning signaling between two legitimate parties,
thereby obtaining authentication credentials and other data. A subclass of MiM is the
Message Modification (MM), when an attacker actively alters a legitimate message by
deleting, adding to, changing or reordering it. The message can be, for example, the
positioning signaling message between LISP and the end user;
Précédent

- 333/483

Suivant