发表机构
A*STAR Institute of Advanced Intelligence and Computing(新加坡科技研究局高级智能与计算研究所)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
该研究针对5G核心漏洞验证稀缺问题,提出AI主导的Drishti审计框架,经Open5GS和free5GC审计发现三项漏洞,其中一项已申请CVE,一项可致AMF快速OOM终止。
AI 中文摘要
开源漏洞的候选生成已不再稀缺,AI辅助代码审查能低成本产出缺陷候选,行业项目会将其与专家人工分类结合,剩余稀缺性在于验证与影响评估,且在5G核心这类关键基础设施软件中差距最大。验证涉及四类成本:验证性、可达性、影响性、修复完整性。本文提出Drishti,这是一个AI主导、人类指导的漏洞审计框架,包含四个对应上述成本的组件:(i)用于验证的反模式目录,(ii)用于可达性的关键路径分类,(iii)用于影响性的同心圆验证,(iv)用于修复完整性的补丁审查。在对Open5GS和free5GC的审计中,Drishti得出三项发现:第一项是Open5GS NRF多部分解析器中的预认证空解引用漏洞,已被上游修复并申请CVE;第二项是free5GC NGAP解码器中的ASN.1-PER内存放大漏洞,恶意gNodeB输入2字节可在6.2秒内导致AMF因OOM被终止;第三项是CVE-2025-69248的缺陷补丁,其纵深防御检查在认证前为死代码。
英文摘要
Candidate generation for open-source vulnerabilities is no longer scarce. AI-assisted code review now produces defect candidates cheaply, and industry programs pair them with expert human triage. The remaining scarcity is validation and impact assessment, and the gap is largest in critical-infrastructure software like 5G cores. Here, validation has four costs: verification, reachability, impact, and fix-completeness. We present Drishti, an AI-led human-directed vulnerability audit framework with four components, one per cost: (i) an anti-pattern catalog for verification, (ii) critical-path triage for reachability, (iii) concentric validation for impact, and (iv) patch-review for fix-completeness. Across audits of Open5GS and free5GC, Drishti produced three findings. The first is a pre-authentication NULL-dereference in the Open5GS NRF multipart parser, fixed upstream with a CVE requested. The second is an ASN.1-PER memory amplification in the free5GC NGAP decoder. A 2-byte input from a rogue gNodeB OOM-kills the AMF in 6.2 seconds. The third is a defective patch on CVE-2025-69248 whose defense-in-depth check is dead code before authentication.
Comments9 pages, 2 figures, 1 table, accepted for publication at ACM CCS workshop on CPSIoTSec 2026