Automated Model-Based Fuzzing for 5G O-RAN
Sixu Tan, Zeyu Li, Zhutian Liu, Harsh Patel, Zhaowei Tan
Abstract
The evolution of 5G and future-G technologies has led to the development of an open, distributed, and multi-vendor architecture known as Open Radio Access Network (O-RAN). While O-RAN offers greater flexibility and stimulates innovation, it also introduces potential issues such as bugs, inconsistencies, and vulnerabilities. In this paper, we present a novel model-based fuzzing system, ARCANE, to address these challenges. Unlike existing fuzzing techniques that struggle with the complexity and dynamism of O-RAN, ARCANE distinguishes itself by employing a smart, model-based approach. It first analyzes O-RAN specifications using a Large Language Model (LLM) and incorporates a unique method that integrates passive model learning to refine the model. With this refined model, ARCANE designs an O-RAN-aware, model-based fuzzing scheme that maintains high efficiency by adhering to O-RAN's specific semantics and syntax. We implement ARCANE and evaluate it on the OAI5G. It finds 9 root bugs from three categories, all having serious security implications. ARCANE has shown superior efficiency and coverage compared to state-of-the-arts.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 29b50098-1778-4c5a-9b94-451fb4e56ca6Related papers
- 5GC-Fuzz: Finding Deep Stateful Vulnerabilities in 5G Core Network with Black-Box FuzzingYu Sun, Xinyu Liu, Qian Sun, Jiaming Wang et al.INFOCOM 2025 · 5 citations
- SemFuzz: A Semantics-Aware Fuzzing Framework for Network Protocol ImplementationsYanbang Sun, Quan Luo, Yuelin Wang, Qian Chen et al.WWW 2026
- Invariant-Guided Logical Testing of Open RAN ControllersTianchang Yang, Ali Ranjbar, Gang Tan, Syed Rafiul HussainUSENIX Security 2026
- ELFuzz: Efficient Input Generation via LLM-driven Synthesis Over Fuzzer SpaceChuyang Chen, Brendan Dolan-Gavitt, Zhiqiang LinUSENIX Security 2025
- CoreCrisis: Threat-Guided and Context-Aware Iterative Learning and Fuzzing of 5G Core NetworksYilu Dong, Tianchang Yang, Abdullah Al Ishtiaq, Syed Md. Mukit Rashid et al.USENIX Security 2025
