USENIX Security2026Top-tier venue
Invariant-Guided Logical Testing of Open RAN Controllers
Tianchang Yang, Ali Ranjbar, Gang Tan, Syed Rafiul Hussain
Abstract
Open RAN (O-RAN) represents a fundamental shift in mobile network architecture, advancing interoperability and flexibility through open interfaces and software-driven components. While enabling programmability and innovation, this shift also makes the logical correctness of O-RAN components essential for the secure and reliable operation of the network. However, validating O-RAN's semantic correctness remains challenging due to system complexity, implementation diversity, and the absence of explicit correctness oracles. We present INVARAN, a systematic testing framework for detecting logical flaws in O-RAN implementations using dynamically inferred program invariants as proxies for expected behavior. To reduce false positives and focus on semantically meaningful behaviors, INVARAN classifies invariants into critical and non-critical categories based on their impact on program logic. Beyond traditional template-based invariant inference approaches that infer only limited semantic relations, INVARAN captures inter-variable correlations across execution traces to discover more expressive semantic linkage. We evaluate INVARAN on both platform components and xApps of two production-grade O-RAN controllers. IN-VARAN uncovers nine previously unknown issues, including seven logical and two memory vulnerabilities, demonstrating the effectiveness of invariant-guided testing in exposing subtle, specification-silent bugs in O-RAN systems. tions. Based on this, we design and implement INVARAN, the first systematic framework to infer likely program invariants and use them to detect logical errors in O-RAN components. More precisely, INVARAN automatically infers likely program invariants from regular executions and uses them as behavioral oracles to expose potential flaws. From execution traces generated by benign traffic, INVARAN extracts stable patterns of variable relationships and system states that serve as proxies for expected behavior. These invariants define a behavioral baseline that INVARAN subsequently validates through fuzz testing. Deviations from this baseline indicate semantic inconsistencies, allowing INVARAN to uncover logical vulnerabilities without requiring formal specifications.
A key challenge of this approach lies in the quality of the inferred invariants. Not all invariant violations indicate logical errors, as some merely capture benign input patterns rather than meaningful program semantics. To address this, INVARAN classifies invariants into critical and non-critical sets through program analysis. Invariants that come with preceding validations or influence significant downstream processing are treated as critical, as they are more likely to reveal flaws, while others are deprioritized to reduce false positives. Moreover, existing invariant inference tools rely on rigid, template-based rules that limit detection to simple relations within narrow program contexts. INVARAN overcomes this limitation by augmenting template-based inference with a correlation-based approach that captures inter-variable relationships across execution traces. By identifying variables that consistently change together, INVARAN infers higherlevel semantic relationships that generalize beyond lexical scopes and scale across entire program executions. Evaluation. We evaluate INVARAN on two widely adopted O-RAN implementations, covering both platform components and xApps. INVARAN uncovers 9 previously unknown issues (7 logical errors and 2 crashes), leading to component crashes, acceptance of falsified metrics, inconsistent internal states, and stealthy Denial-of-Service (DoS) conditions. Contributions. We make the following main contributions: • We design and implement INVARAN, the first systematic logical error detection framework for O-RAN components, using dynamically inferred invariants as behavioral oracles.
• We introduce critical invariant classification to reduce false positives and focus on semantically meaningful violations.
• We propose a scalable correlation-based invariant inference approach that captures inter-variable semantic relationships beyond template-based methods. • We evaluate INVARAN on two O-RAN platforms, uncovering 9 new logical and crashing issues, resulting in falsified metrics, inconsistent states, and stealthy DoS. 2 Background Open RAN (O-RAN). The O-RAN Alliance [16] standardizes a multi-supplier 5G and future-G O-RAN architecture (Figure 1) where equipment from various suppliers can be easily combined to form the RAN. O-RAN adopts a servicebased design, where functions are implemented as cloudnative microservices that communicate over network traffic. Each microservice can be independently developed, deployed, and scaled on general-purpose servers. Beyond RAN disaggregation, O-RAN introduces two RAN Intelligent Controllers (RICs). The Near-Real-Time RIC (Near-RT RIC) manages and optimizes the RAN in near real-time (10ms-1s) [59]. Its functionality is provided by modular xApps, often deve
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext bc64eb60-114a-4f83-97d1-fcd40eccd847Builds on14
- A Formal Analysis of 5G AuthenticationDavid A. Basin, Jannik Dreier, Lucca Hirschi, Sasa Radomirovic et al.CCS 2018 · 428 citations
- Can Large Language Models Reason about Program Invariants?Kexin Pei, David Bieber, Kensen Shi, Charles Sutton et al.ICML 2023 · 128 citations
- The Use of Likely Invariants as Feedback for FuzzersAndrea Fioraldi, Daniele Cono D'Elia, Davide BalzarottiUSENIX Security 2021 · 67 citations
- SFADiff: Automated Evasion Attacks and Fingerprinting Using Black-box Differential Automata LearningGeorge Argyros, Ioannis Stais, Suman Jana, Angelos D. Keromytis et al.CCS 2016 · 65 citations
- Fully automated functional fuzzing of Android apps for detecting non-crashing logic bugsTing Su, Yichen Yan, Jue Wang, Jingling Sun et al.OOPSLA 2021 · 58 citations
Related papers
- ORANalyst: Systematic Testing Framework for Open RAN ImplementationsTianchang Yang, Syed Md. Mukit Rashid, Ali Ranjbar, Gang Tan et al.USENIX Security 2024 · 10 citations
- Automated Model-Based Fuzzing for 5G O-RANSixu Tan, Zeyu Li, Zhutian Liu, Harsh Patel et al.MobiCom 2025
- 5G-Spector: An O-RAN Compliant Layer-3 Cellular Attack Detection ServiceHaohuang Wen, Phillip A. Porras, Vinod Yegneswaran, Ashish Gehani et al.NDSS 2024
- BASECOMP: A Comparative Analysis for Integrity Protection in Cellular Baseband SoftwareEunsoo Kim, Minwoo Baek, CheolJun Park, Dongkwan Kim et al.USENIX Security 2023
- inRAN: Interpretable Online Bayesian Learning for Network Automation in Open Radio Access NetworksMing Zhao, Yuru Zhang, Qiang Liu, Ahan Kak et al.INFOCOM 2026 · 1 citation
