Automated Vulnerability Testing and Detection Digital Twin Framework for 5G Systems

被引:11
作者
Dauphinais, Danielle [1 ]
Zylka, Michael [1 ]
Spahic, Harris [1 ]
Shaik, Farhan [1 ]
Yang, Jingda [1 ]
Cruz, Isabella [1 ]
Gibson, Jakob [1 ]
Wang, Ying [1 ]
机构
[1] Stevens Inst Technol, Hoboken, NJ 07030 USA
来源
2023 IEEE 9TH INTERNATIONAL CONFERENCE ON NETWORK SOFTWARIZATION, NETSOFT | 2023年
关键词
5G Security; Testing Framework; Digital Twin; Assembly-Level; Fuzzing;
D O I
10.1109/NetSoft57336.2023.10175496
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Efficient and precise detection of vulnerabilities in 5G protocols and implementations is crucial for ensuring the security of its application in critical infrastructures. However, with the rapid evolution of 5G standards and the trend towards softwarization and virtualization, this remains a challenge. In this paper, we present an automated Fuzz Testing Digital Twin Framework that facilitates systematic vulnerability detection and assessment of unintended emergent behavior, while allowing for efficient fuzzing path navigation. Our framework utilizes assembly-level fuzzing as an acceleration engine and is demonstrated on the flagship 5G software stack: srsRAN. The introduced digital twin solution enables the simulation, verification, and connection to 5G testing and attack models in real-world scenarios. By identifying and analyzing vulnerabilities on the digital twin platform, we significantly improve the security and resilience of 5G systems, mitigate the risks of zero-day vulnerabilities, and provide comprehensive testing environments for current and newly released 5G systems.
引用
收藏
页码:308 / 310
页数:3
相关论文
共 7 条
[1]  
Google, GOOGL OSS FUZZ OSS F
[2]  
Hintjen P, 2022, OMQ GUIDE
[3]  
Microsoft, MICR ON SELF HOST FU
[4]   Berserker: ASN.1-based Fuzzing of Radio Resource Control Protocol for 4G and 5G [J].
Potnuru, Srinath ;
Nakarmi, Prajwol Kumar .
2021 17TH INTERNATIONAL CONFERENCE ON WIRELESS AND MOBILE COMPUTING, NETWORKING AND COMMUNICATIONS (WIMOB 2021), 2021, :295-300
[5]  
S. R. Systems, 2022, SRSRAN 22 10 DOC
[6]  
Salazar Z., 2021, ACM INT C PROCEEDING, V8
[7]   5G RRC Protocol and Stack Vulnerabilities Detection via Listen-and-Learn [J].
Yang, Jingda ;
Wang, Ying ;
Tran, Tuyen X. ;
Pan, Yanjun .
2023 IEEE 20TH CONSUMER COMMUNICATIONS & NETWORKING CONFERENCE, CCNC, 2023,