Register$3,299.00
Date | Day | Time | Duration |
25 Nov | Monday | 09:00 to 17:00 GST/GMT+4 | 8 Hours |
26 Nov | Tuesday | 09:00 to 17:00 GST/GMT+4 | 8 Hours |
27 Nov | Wednesday | 09:00 to 17:00 GST/GMT+4 | 8 Hours |
Through practical exercises and case studies, hackathon experiences, participants will learn about new ways to attack core networks by exploiting device and network authentication issues, vulnerabilities in network slicing, by deploying rogue network functions, container breakouts, and invesitgate the potential for data interception and manipulation. This hands-on experience is achieved entirely in an ethically controlled test environment with security testing tools and techniques, including reconnaissance, penetration testing and vulnerability scanning. The training will also cover advanced topics such as fuzzing the service based and Telecom APIs.
By the end of this training, participants will be equipped with the technical expertise to design, implement, and maintain secure 5G core networks. They will have the confidence to tackle the security challenges posed by 5G technology and ensure the availability, integrity and confidentiality of their networks.
• Pentesting tools custom-made for recon, core intrusion, & PFCP testing
• Access to 5G virtual lab that models a multitude of threats inside a sliced core network • 5G Network traffic monitoring and analysis tools for core and devices
• Case studies and real-world example like exploits for IoT service platforms, API traffic • Virtual machine files packaged with all proprietary test, audit and evaluation tools
Key Learning Objectives
Module 1: 5G architecture and security
• 5G architecture and network IDs
• 5G Security Requirements by 3GPP for UE, AMF, SEAF, UDM • SUCI, 5G-AKA, EAP-AKA, NAS and AS crypto
• 33.501 standards and NIST guidelines for 5G security
• Security over backhaul, interconnect SEPP, private 5g, MEC
• Authentication, authorization and crypto for network functions
Module 2: Threat Modeling and Risk Assessment
• Security challenges, risks for 5G core
• MITRE FiGHT framework for attack tactics, and techniques
• New attack patterns for 5G sliced networks (MEC, NFV)
• 5G core and RAN assessment strategies and 5G EU toolbox
• Security compliance and assurance from 3GPP SCAS/SECAM • Auditing – network equipment security assurance (NESAS)
Module 3: 5G System Vulnerability Analysis:
• 5G System and network attacks
• Stages of core exploitation, & entry points
• Attacks on User-to-network interfaces and network-to-network interfaces • Reconnaissance, exploitation, persistence
• Rogue network functions, rogue APIs, & spoofed slices
• Protocol tunneling, MEC
• Exploiting public facing applications
• Supply chain security for network function containers
Module 4: 5G Security Pentesting:
• Tools and techniques for pentesting 5G interfaces, endpoints • Probing network functions over HTTP/2
• Fuzzing 3GPP core interfaces NGAP (N1/N2)
• Fuzzing core service based APIs
• Core network intrusion (via N1/N2, SEPP), and container breakouts • IoT service platform application security (Northbound APIs)
Module 5: Hands-On Exercises:
• Simulate end-to-end 5G multi-slice network
• Network recon, intrusion to an on-site 5G core network testbed • 5G core vulnerability scanning
• Inter-slice compromise attacks via NRF/AMF/SEAF/UDM
• Insider data theft on UPF/UDR
• 5G AMF auditing using SECAM 33.512
• PFCP exposure, DoS, & hijacking
Module 6: Defense-in-Depth Strategies:
• Network function (container) access and monitoring rules • Network border firewall rules for MNO interconnect
• 5G network analytics and log monitoring (NWAF)
• Secure communication proxy for 5G core
• NEF/SCEF security via Telecom API Top 10 • Supply chain security testing and monitoring
Module 7: Case studies:
• 5G core network protocol security assessment
• Intrusion to 5G core via commercial exposure function (NEF/SCEF) • 5G private core configurations and security settings
Overall, this advanced 5G practical security training will provide attendees with a comprehensive understanding of the security risks and vulnerabilities associated with 5G networks, as well as the knowledge and tools to implement effective security measures to protect their networks and data.