Lune

USENIX Security2026顶会

Understanding Implicit Trust Errors in Core Carrier Networks through Multi-Agent Flaw Discovery and Analysis

Ziyu Lin, Ziting Wang, Xinfeng Li, Wei Dong, XiaoFeng Wang

2026年份

摘要

Core network (CN) is at the center of a cellular system and was historically protected by physical isolation, but the shift to cloud-native deployments breaks this protection and introduces new attack interfaces. Indeed, from reported GitHub issues, we found that many security flaws within CNs can be attributed to blind trust underlying interactions across different CN components. Under such trust assumptions, one component may fail to properly verify the syntactic and semantic content of messages received from other internal components, and may also grant resources to requesters without validation of resource availability. These weaknesses, once coupled with the risks of exposing internal interfaces to unauthorized external parties, as observed in our research, will lead to serious consequences, including session hijacking and denial of services. In our research, we call these newly discovered weaknesses implicit trust errors or iTrue . To detect iTrues and understand their security impacts, we designed and implemented a multi-agent framework, dubbed iFinder . iFinder automatically analyzes and summarizes known security flaws, and uses them as ``seeds'' to detect related vulnerabilities from the CN simulators. To suppress hallucinations produced by large language models (LLMs), not only have we developed a Chain of Thought (CoT) reasoning to guide agents, but we also build an innovative strategy that cross-checks both 3GPP specifications and CN code to capture existing protection missed by the agents. Further, we developed a technique that uses LLMs to generate proof-of-concept (PoC) exploits for potential iTrues and iteratively refine the PoCs by automatically executing them against CN simulators and analyzing results. Running iFinder on 7 prominent simulators, we discovered 84 previously unknown vulnerabilities. Among them 70 have already been confirmed with 40 CVE assignments already awarded. Our findings highlight the pervasiveness of iTrue risks across the cellular core networks and the urgent needs for elevated protection within the original trust domains. We plan to make the service of iFinder publicly available to help enhance the security qualities of cellular core networks.

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

它引用的顶会 Paper30

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖