USENIX Security2024Top-tier venue
ORANalyst: Systematic Testing Framework for Open RAN Implementations
Tianchang Yang, Syed Md. Mukit Rashid, Ali Ranjbar, Gang Tan, Syed Rafiul Hussain
Abstract
We develop ORANalyst, the first systematic testing framework tailored for analyzing the robustness and operational integrity of Open RAN (O-RAN) implementations. O-RAN systems are composed of numerous microservice-based components. ORANalyst initially gains insights into these complex component dependencies by combining efficient static analysis with dynamic tracing. Applying these insights, ORANalyst crafts test inputs that effectively navigate these dependencies and thoroughly test each target component. We evaluate ORANalyst on two O-RAN implementations, O-RAN-SC and SD-RAN, and identify 19 previously undiscovered vulnerabilities. If exploited, these vulnerabilities could lead to various denial-of-service attacks, resulting from component crashes and disruptions in communication channels.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 0ed295df-1b5d-4c58-9cf9-7de98ba4d286Cited by top-tier papers4
- SIPConfusion: Exploiting SIP Semantic Ambiguities for Caller ID and SMS SpoofingQi Wang, Jianjun Chen, Jingcheng Yang, Jiahe Zhang et al.NDSS 2026 · 1 citation
- Stateful Analysis and Fuzzing of Commercial Baseband FirmwareAli Ranjbar, Tianchang Yang, Kai Tu, Saaman Khalilollahi et al.S&P 2025
- CoreCrisis: Threat-Guided and Context-Aware Iterative Learning and Fuzzing of 5G Core NetworksYilu Dong, Tianchang Yang, Abdullah Al Ishtiaq, Syed Md. Mukit Rashid et al.USENIX Security 2025
- Invariant-Guided Logical Testing of Open RAN ControllersTianchang Yang, Ali Ranjbar, Gang Tan, Syed Rafiul HussainUSENIX Security 2026
Builds on9
- SOK: (State of) The Art of War: Offensive Techniques in Binary AnalysisYan Shoshitaishvili, Ruoyu Wang, Christopher Salls, Nick Stephens et al.S&P 2016 · 1,085 citations
- Driller: Augmenting Fuzzing Through Selective Symbolic ExecutionNick Stephens, John Grosen, Christopher Salls, Andrew Dutcher et al.NDSS 2016 · 1,021 citations
- SAVIOR: Towards Bug-Driven Hybrid TestingYaohui Chen, Peng Li, Jun Xu, Shengjian Guo et al.S&P 2020 · 186 citations
- Systematic Fuzzing and Testing of TLS LibrariesJuraj SomorovskyCCS 2016 · 136 citations
- Android SmartTVs Vulnerability Discovery via Log-Guided FuzzingYousra Aafer, Wei You, Yi Sun, Yu Shi et al.USENIX Security 2021 · 35 citations
Related papers
- 5G-Spector: An O-RAN Compliant Layer-3 Cellular Attack Detection ServiceHaohuang Wen, Phillip A. Porras, Vinod Yegneswaran, Ashish Gehani et al.NDSS 2024
- Automated Model-Based Fuzzing for 5G O-RANSixu Tan, Zeyu Li, Zhutian Liu, Harsh Patel et al.MobiCom 2025
- Det-RAN: Data-Driven Cross-Layer Real-Time Attack Detection in 5G Open RANsAlessio Scalingi, Salvatore D'Oro, Francesco Restuccia, Tommaso Melodia et al.INFOCOM 2024 · 19 citations
- OrchestRAN: Network Automation through Orchestrated Intelligence in the Open RANSalvatore D'Oro, Leonardo Bonati, Michele Polese, Tommaso MelodiaINFOCOM 2022 · 114 citations
- Intender: Fuzzing Intent-Based Networking with Intent-State Transition GuidanceJiwon Kim, Benjamin E. Ujcich, Dave TianUSENIX Security 2023
