Invariant-Guided Logical Testing of Open RAN Controllers
Tianchang Yang, Ali Ranjbar, Gang Tan, Syed Rafiul Hussain
摘要
Open RAN (O-RAN) represents a fundamental shift in mobile network architecture, advancing interoperability and flexibility through open interfaces and software-driven components. While enabling programmability and innovation, this shift also makes the logical correctness of O-RAN components essential for the secure and reliable operation of the network. However, validating O-RAN's semantic correctness remains challenging due to system complexity, implementation diversity, and the absence of explicit correctness oracles. We present INVARAN, a systematic testing framework for detecting logical flaws in O-RAN implementations using dynamically inferred program invariants as proxies for expected behavior. To reduce false positives and focus on semantically meaningful behaviors, INVARAN classifies invariants into critical and non-critical categories based on their impact on program logic. Beyond traditional template-based invariant inference approaches that infer only limited semantic relations, INVARAN captures inter-variable correlations across execution traces to discover more expressive semantic linkage. We evaluate INVARAN on both platform components and xApps of two production-grade O-RAN controllers. IN-VARAN uncovers nine previously unknown issues, including seven logical and two memory vulnerabilities, demonstrating the effectiveness of invariant-guided testing in exposing subtle, specification-silent bugs in O-RAN systems. tions. Based on this, we design and implement INVARAN, the first systematic framework to infer likely program invariants and use them to detect logical errors in O-RAN components. More precisely, INVARAN automatically infers likely program invariants from regular executions and uses them as behavioral oracles to expose potential flaws. From execution traces generated by benign traffic, INVARAN extracts stable patterns of variable relationships and system states that serve as proxies for expected behavior. These invariants define a behavioral baseline that INVARAN subsequently validates through fuzz testing. Deviations from this baseline indicate semantic inconsistencies, allowing INVARAN to uncover logical vulnerabilities without requiring formal specifications.
A key challenge of this approach lies in the quality of the inferred invariants. Not all invariant violations indicate logical errors, as some merely capture benign input patterns rather than meaningful program semantics. To address this, INVARAN classifies invariants into critical and non-critical sets through program analysis. Invariants that come with preceding validations or influence significant downstream processing are treated as critical, as they are more likely to reveal flaws, while others are deprioritized to reduce false positives. Moreover, existing invariant inference tools rely on rigid, template-based rules that limit detection to simple relations within narrow program contexts. INVARAN overcomes this limitation by augmenting template-based inference with a correlation-based approach that captures inter-variable relationships across execution traces. By identifying variables that consistently change together, INVARAN infers higherlevel semantic relationships that generalize beyond lexical scopes and scale across entire program executions. Evaluation. We evaluate INVARAN on two widely adopted O-RAN implementations, covering both platform components and xApps. INVARAN uncovers 9 previously unknown issues (7 logical errors and 2 crashes), leading to component crashes, acceptance of falsified metrics, inconsistent internal states, and stealthy Denial-of-Service (DoS) conditions. Contributions. We make the following main contributions: • We design and implement INVARAN, the first systematic logical error detection framework for O-RAN components, using dynamically inferred invariants as behavioral oracles.
• We introduce critical invariant classification to reduce false positives and focus on semantically meaningful violations.
• We propose a scalable correlation-based invariant inference approach that captures inter-variable semantic relationships beyond template-based methods. • We evaluate INVARAN on two O-RAN platforms, uncovering 9 new logical and crashing issues, resulting in falsified metrics, inconsistent states, and stealthy DoS. 2 Background Open RAN (O-RAN). The O-RAN Alliance [16] standardizes a multi-supplier 5G and future-G O-RAN architecture (Figure 1) where equipment from various suppliers can be easily combined to form the RAN. O-RAN adopts a servicebased design, where functions are implemented as cloudnative microservices that communicate over network traffic. Each microservice can be independently developed, deployed, and scaled on general-purpose servers. Beyond RAN disaggregation, O-RAN introduces two RAN Intelligent Controllers (RICs). The Near-Real-Time RIC (Near-RT RIC) manages and optimizes the RAN in near real-time (10ms-1s) [59]. Its functionality is provided by modular xApps, often deve
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper14
- A Formal Analysis of 5G AuthenticationDavid A. Basin, Jannik Dreier, Lucca Hirschi, Sasa Radomirovic 等CCS 2018 · 被引用 428 次
- Can Large Language Models Reason about Program Invariants?Kexin Pei, David Bieber, Kensen Shi, Charles Sutton 等ICML 2023 · 被引用 128 次
- The Use of Likely Invariants as Feedback for FuzzersAndrea Fioraldi, Daniele Cono D'Elia, Davide BalzarottiUSENIX Security 2021 · 被引用 67 次
- SFADiff: Automated Evasion Attacks and Fingerprinting Using Black-box Differential Automata LearningGeorge Argyros, Ioannis Stais, Suman Jana, Angelos D. Keromytis 等CCS 2016 · 被引用 65 次
- Fully automated functional fuzzing of Android apps for detecting non-crashing logic bugsTing Su, Yichen Yan, Jue Wang, Jingling Sun 等OOPSLA 2021 · 被引用 58 次
相关 Paper
- ORANalyst: Systematic Testing Framework for Open RAN ImplementationsTianchang Yang, Syed Md. Mukit Rashid, Ali Ranjbar, Gang Tan 等USENIX Security 2024 · 被引用 10 次
- Automated Model-Based Fuzzing for 5G O-RANSixu Tan, Zeyu Li, Zhutian Liu, Harsh Patel 等MobiCom 2025
- 5G-Spector: An O-RAN Compliant Layer-3 Cellular Attack Detection ServiceHaohuang Wen, Phillip A. Porras, Vinod Yegneswaran, Ashish Gehani 等NDSS 2024
- BASECOMP: A Comparative Analysis for Integrity Protection in Cellular Baseband SoftwareEunsoo Kim, Minwoo Baek, CheolJun Park, Dongkwan Kim 等USENIX Security 2023
- inRAN: Interpretable Online Bayesian Learning for Network Automation in Open Radio Access NetworksMing Zhao, Yuru Zhang, Qiang Liu, Ahan Kak 等INFOCOM 2026 · 被引用 1 次
