O-RAN Security: From Standardization and Threat Modeling to Practical Security Testing
Abstract
The Open Radio Access Network (O-RAN) introduces openness and disaggregation to cellular networks, enabling innovation and multi-vendor interoperability. This article provides a comprehensive examination of O-RAN security with emphasis on two distinct contributions. First, we classify the O-RAN threat surface into three domains: infrastructure, open interfaces, and Radio Access Network (RAN) intelligence. This categorization provides a structured framework for analyzing vulnerabilities and attacks across the O-RAN architecture. Second, we survey state-of-the-art testing tools, including both open-source and commercial solutions, and map their capabilities to the identified threat surfaces. In addition, we review mitigation strategies, ongoing standardization efforts, and emerging defense mechanisms. Unresolved challenges and future research directions are highlighted to guide further research and development. This dual focus on systematic threat surface classification and security testing methodologies differentiates this article from prior work and provides a roadmap for researchers and practitioners securing O-RAN deployments.