5G-Spector: An O-RAN Compliant Layer-3 Cellular Attack Detection Service
Haohuang Wen, Phillip A. Porras, Vinod Yegneswaran, Ashish Gehani, Zhiqiang Lin
Abstract
—Over the past several years, the mobile security community has discovered a wide variety of exploits against link and session-establishment protocols. These exploits can be implemented on software-defined radios (SDRs) that disrupt, spoof, or flood layer-3 (L3) messages to compromise security and privacy, which still apply to the latest 5G mobile network standard. Interestingly, unlike the prior generations of closed (proprietary) mobile network infrastructures, 5G networks are migrating toward a more intelligent and open-standards-based fully interoperable mobile architecture, called Open RAN or O-RAN . The implications of transitioning mobile infrastructures to a software-defined architectural abstraction are quite significant to the INFOSEC community, as it allows us to extend the mobile data plane and control plane with security-focused protocol auditing services and exploit detection. Based on this design, we present 5G-S PECTOR , the first comprehensive framework for detecting the wide spectrum of L3 protocol exploits on O-RAN. It features a novel security audit stream called M OBI F LOW that transfers fine-grained cellular network telemetry, and a programmable control-plane xApp called M OBIE X PERT . We present an extensible prototype of 5G-S PECTOR which can detect 7 types of cellular attacks in real-time. We also demonstrate its scalability to 11 unknown attacks as well as 31 real-world cellular traces, with effective performance (high accuracy, no false alarms) and low ( < 2% CPU, < 100 MB memory) overhead.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 91dbe50b-c0d3-4838-93d7-c7175110af86Cited by top-tier papers2
- Gotta Detect 'Em All: Fake Base Station and Multi-Step Attack Detection in Cellular NetworksKazi Samin Mubasshir, Imtiaz Karim, Elisa BertinoUSENIX Security 2025
- Magmaw: Modality-Agnostic Adversarial Attacks on Machine Learning-Based Wireless Communication SystemsJung-Woo Chang, Ke Sun, Nasimeh Heydaribeni, Seira Hidano et al.NDSS 2025
Builds on20
- A Formal Analysis of 5G AuthenticationDavid A. Basin, Jannik Dreier, Lucca Hirschi, Sasa Radomirovic et al.CCS 2018 · 428 citations
- Practical Attacks Against Privacy and Availability in 4G/LTE Mobile Communication SystemsAltaf Shaik, Jean-Pierre Seifert, Ravishankar Borgaonkar, N. Asokan et al.NDSS 2016 · 342 citations
- LTEInspector: A Systematic Approach for Adversarial Testing of 4G LTESyed Rafiul Hussain, Omar Chowdhury, Shagufta Mehnaz, Elisa BertinoNDSS 2018 · 225 citations
- Breaking LTE on Layer TwoDavid Rupprecht, Katharina Kohls, Thorsten Holz, Christina PöpperS&P 2019 · 219 citations
- 5GReasoner: A Property-Directed Security and Privacy Analysis Framework for 5G Cellular Network ProtocolSyed Rafiul Hussain, Mitziu Echeverria, Imtiaz Karim, Omar Chowdhury et al.CCS 2019 · 188 citations
Related papers
- Det-RAN: Data-Driven Cross-Layer Real-Time Attack Detection in 5G Open RANsAlessio Scalingi, Salvatore D'Oro, Francesco Restuccia, Tommaso Melodia et al.INFOCOM 2024 · 19 citations
- SNI5GECT: A Practical Approach to Inject aNRchy into 5G NRShijie Luo, Matheus E. Garbelini, Sudipta Chattopadhyay, Jianying ZhouUSENIX Security 2025
- Guardians of the Air: In-Device Detection of 5G Control-Plane ThreatsTianwei Wu, Abdullah Al Ishtiaq, Tianchang Yang, Yilu Dong et al.S&P 2026
- Uncovering Hidden Paths in 5G: Exploiting Protocol Tunneling and Network Boundary BridgingAltaf Shaik, Robert Jaschek, Jean-Pierre SeifertCCS 2025 · 1 citation
- Securing 5G OpenRAN with a Scalable Authorization Framework for xAppsTolga O. Atalay, Sudip Maitra, Dragoslav Stojadinovic, Angelos Stavrou et al.INFOCOM 2023 · 23 citations
