Aug 2026· Italian National Conference on Sensors· Vol 26· 0 citations· 21 references
Medicine
TL;DR
A stateful security verification methodology that combines stateful fuzzing with specification-guided security verification of the NG Application Protocol between the radio access network and the 5G core is proposed.
Abstract
As fifth-generation (5G) networks evolve toward open and software-based architectures, security verification of the NG Application Protocol (NGAP) between the radio access network and the 5G core has become increasingly important. This paper proposes a stateful security verification methodology that combines stateful fuzzing with specification-guided security verification. The methodology derives an Access and Mobility Management Function (AMF) state model, mutation types, and expected behaviors from Third Generation Partnership Project (3GPP) specifications. For each attack scenario, it establishes the required connection state through normal NGAP procedures, injects a mutated message, and compares the observed AMF responses and processing logs with the specification-defined expected behavior. We evaluated four open-source 5G core implementations using 324 attack scenarios per implementation, resulting in 1296 tests. Of these, 877 produced sufficient evidence to interpret the AMF processing outcome, yielding an interpretable outcome rate of 67.7%. The evaluation covered 27 of the 40 uplink NGAP message types and identified 32 specification violations, including 11 security vulnerabilities, none of which caused a core to crash. These results demonstrate the importance of jointly considering connection states and specification-defined behavior in NGAP security verification.
With the development of automotive intelligence and connectivity, the security vulnerabilities of the XCP protocol adopted by in-vehicle ECUs have become increasingly prominent. Conducting targeted penetration testing is crucial for safeguarding in-vehicle security. This paper takes the ECM engine controller as the res...
Ruo-Fei Xing, Ke-Xun He, Bai-Zheng Wang et al.· International Conference on...· 0 citations
AFLWalk is created, a variant of AFLNet, as an attempt to address the challenge of testing stateful protocols by focusing exclusively on message-sequence mutations to steer exploration through protocol state machines, rather than applying byte-level mutations such as bit-flipping.
Philip-Ricardo Schoots, Ir. Erik Poll, Frits W. Vaandrager· 0 citations
The deployment of 5G standalone (SA) networks introduces cloud-native core architectures, service-based interfaces, and programmable radio access networks that substantially expand the mobile attack surface. Existing work has focused mainly on protocol-level vulnerabilities or isolated anomaly detection, with less atte...
Miklós Orsós, A. Bánáti· Future Internet· 0 citations
Vuln_Box is proposed, a lightweight container-based Infrastructure-as-Code (IaC) laboratory powered by the kathará emulation engine that provides a granular behavioral threat model for defensive gap analysis and shows that the containerized approach drastically reduces resource overhead compared to traditional hypervis...
Working baseline levels of capability are provided with respect to current LLM-based solutions in 6G mission-critical and public safety contexts, and specific research directions to advance LLM-driven cybersecurity toward robust, adaptable, explainable, and life-safety-aware solutions are mapped out.
Siva Sai, Bhuvan Arora, Vineet Suri et al.· IEEE Open Journal of the Com...· 1 citation
The 5G EAP-TLS protocol is one of the three protocols standardised by 3GPP for use in 5G networks. Although this protocol inherently ensures security, authentication, and data integrity, recent studies have shown that it still faces several vulnerabilities, including Man-in-The-Middle attacks, user impersonation, and r...
Nga Thị Nguyệt Trần, Hung Quoc Nguyen, Giang Thu Bùi· Journal of Science and Techn...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.