arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

通过多智能体缺陷发现与分析理解核心承载网络中的隐式信任错误

Understanding Implicit Trust Errors in Core Carrier Networks through Multi-Agent Flaw Discovery and Analysis

Ziyu Lin, Ziting Wang, Xinfeng Li, Wei Dong, XiaoFeng Wang

arXiv 2607.10315首次发表:更新:

AI 中文总结

研究蜂窝核心网络向云原生部署过渡时出现的隐式信任错误问题,设计iFinder多智能体系统,通过总结已知缺陷形成检测模式来发现新漏洞,运行该系统发现多个未知漏洞,确认了会话劫持等问题。

AI 中文摘要

蜂窝核心网络是关键基础设施,但其内部安全模型历来依赖物理隔离。随着向云原生部署过渡,这一假设减弱,攻击面扩大。通过对开源CN实现中GitHub问题报告的安全缺陷进行根本原因分析,发现CN组件间存在盲目信任模式,导致隐式信任错误(iTrue)。为此设计了iFinder多智能体系统来检测iTrue并理解其安全影响,还构建创新策略抑制大语言模型幻觉,开发技术生成概念验证利用程序并迭代优化。在七个开源CN实现上运行iFinder发现84个未知漏洞,其中83个已确认,81个已获CVE编号,还在真实商业5G核心网络上确认了会话劫持漏洞。

英文摘要

Cellular core networks (CNs) are critical infrastructure, yet their internal security model has historically relied on physical isolation: interfaces between core components often operate within an assumed trust zone. As CNs transition to cloud-native deployments, this assumption weakens, expanding the attack surface and enabling external adversaries to reach previously internal interfaces. From a root-cause analysis of security flaws reported in GitHub issues for opensource CN implementations, we found a recurring pattern of blind trust among CN components. Components may omit syntactic validation, fail to enforce semantic invariants, or allocate resources without checking availability. Once internal interfaces become reachable, these weaknesses can lead to severe impacts such as denial of service and session hijacking. We call these vulnerabilities implicit trust errors (iTrue). To detect iTrues and understand their security impacts, we designed iFinder, an LLM-driven multi-agent system that summarizes known flaws, distills them into detection patterns, and applies them to discover new iTrues in CN implementations. To suppress hallucinations produced by large language models (LLMs), we built an innovative strategy that crosschecks both 3GPP specifications and CN code to capture existing protection missed by the agents. Further, we developed a technique that uses LLMs to generate proof-of-concept (PoC) exploits for potential iTrues and iteratively refine the PoCs by automatically executing them against CN implementations and analyzing results. Running iFinder on seven prominent open-source CN implementations, we discovered 84 previously unknown vulnerabilities. Among them, 83 have already been confirmed and 81 have been assigned CVEs. Importantly, a session-hijacking flaw has been confirmed on real-world commercial 5G core networks.

CommentsPublished in the Proceedings of the 35th USENIX Security Symposium (USENIX Security 2026). This is the final version

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑