0. Reference

Legal & Ethical Notice — US Law

This document is for educational and defensive security research purposes only.

All techniques described herein are analyzed in a controlled lab environment using your own equipment and licensed test SIMs. Applying any of these techniques to real-world cellular infrastructure, third-party devices, or spectrum you do not own is illegal under US federal law, including:

  • 47 U.S.C. § 333 — Prohibits interference with radio communications. RF jamming is illegal for all private parties and state/local law enforcement with no exceptions. The FCC has imposed fines exceeding $34 million for marketing jamming devices.
  • 47 U.S.C. § 301 — Requires an FCC license to transmit on licensed spectrum. Operating a fake base station (eNodeB/gNB) on live cellular frequencies without authorization violates this statute.
  • 47 U.S.C. § 605 — Prohibits unauthorized interception of radio communications not intended for the recipient.
  • 18 U.S.C. § 2511 (Wiretap Act) — Prohibits intentional interception of electronic communications, including voice (VoLTE/RTP) and data.
  • 18 U.S.C. § 1029 — Prohibits fraud involving access devices. SIM cards are federally defined access devices; cloning, unauthorized key extraction, and related acts are federal crimes.
  • 18 U.S.C. § 1030 (CFAA) — Prohibits unauthorized access to computer systems, including telecom signaling infrastructure (Diameter, GTP, SBI APIs).

Lab use requirements: All radio experiments must be conducted in an RF-shielded environment (Faraday cage) using test SIMs provisioned in your own Open5GS/srsRAN lab. No transmission on live cellular bands is permitted without an FCC experimental license.

This document does not constitute legal advice. Consult a licensed attorney before conducting any security research involving radio spectrum or telecommunications infrastructure.

For a hands‑on, lab‑oriented understanding of 3G/4G/5G (similar to Open5GS docs), use resources that combine architecture explanations with runnable cores/RAN and realistic topologies.open5gs

Open‑source core & RAN stacks

Lab‑focused 4G/5G tutorials

Cloud‑native / Kubernetes deployments

Advanced core topics

LTE/EPC and interworking specifics

If helpful, a next step could be a staged path like: UERANSIM+Open5GS on a single VM → add srsRAN/OAI with SDR → migrate to k8s with the gradiant charts/operator, tying each lab back to the 3GPP architecture concepts.

  1. https://open5gs.org/open5gs/docs/
  2. https://open5gs.org/open5gs/docs/guide/01-quickstart/
  3. https://medium.com/rahasak/5g-core-network-setup-with-open5gs-and-ueransim-cd0e77025fd7
  4. https://gitlab.eurecom.fr/oai/openairinterface5g/-/tree/develop/doc
  5. https://github.com/aligungr/UERANSIM/wiki/Tutorials-and-Other-Resources
  6. https://docs.srsran.com/en/latest/
  7. https://github.com/aligungr/UERANSIM
  8. https://github.com/niloysh/open5gs-k8s
  9. https://gradiant.github.io/5g-charts/
  10. https://github.com/open5gs/open5gs/discussions/2259
  11. https://docs.loxilb.io/perf/
  12. https://docs.loxilb.io/main/
  13. https://docs.fra.me/platform/networking/sga/sga-install/
  14. https://qiita.com/s5uishida/items/fc5f4e1c394c9f5dd181
  15. https://www.lcnpl.com/downloads/LCN-DRA.pdf