← Back to Tools Directory
OpenAirInterface
5G NR / 4G LTEFull 3GPP-compliant 5G NR and 4G LTE software radio stack implementing gNodeB, eNodeB, nrUE, and core network functions for RF security research.
OpenAirInterface — 5G/LTE Software Radio Security Stack
OpenAirInterface (OAI) is a 3GPP-compliant open-source software radio platform implementing the full 5G NR and 4G LTE protocol stack. Within TelcoChisel, OAI provides real over-the-air gNodeB/eNodeB transmission capability for testing rogue base station scenarios, RRC protocol fuzzing, and NAS authentication bypass attacks using SDR hardware.
Key Capabilities & Security Vectors
- Rogue gNodeB / eNodeB Deployment: Stand up unauthorized base stations on target frequency bands to test UE camping and redirection attacks.
- RRC Protocol Fuzzing: Inject malformed RRC Setup, Reconfiguration, and Security Mode Command messages to crash or exploit UE stacks.
- NAS Authentication Testing: Test AKA (Authentication and Key Agreement) implementation flaws including SUPI/IMSI exposure via null cipher attacks.
- Downlink NAS Replay: Capture and replay NAS signaling to test anti-replay counter implementations in commercial UEs.
TelcoChisel Execution Cheatsheet
1. Launch 5G SA gNodeB
# Start 5G NR Standalone gNodeB with USRP B210
cd /opt/oai/cmake_targets/ran_build/build
sudo ./nr-softmodem -O /opt/oai/targets/PROJECTS/GENERIC-NR-LTE/CONF/gnb.sa.band78.conf --sa
2. Launch 5G NR UE Emulator
# Start NR UE softmodem for controlled testing
sudo ./nr-uesoftmodem -O /opt/oai/targets/PROJECTS/GENERIC-NR-LTE/CONF/ue.conf --sa --nokrnmod
3. Capture Over-the-Air NR Signaling
# Live capture NR-ARFCN signaling via T tracer
sudo tshark -i oaitun_ue1 -Y "ngap || nas-5gs" -T fields -e frame.time -e nas_5gs.mm.message_type
No community field notes posted yet. Be the first telecom engineer to leave feedback!