arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

一种基于图的可查询O-RAN安全分析框架

A Queryable Graph-Based Security Analysis Framework for O-RAN

Corban Villa, Michele Guerra, Syed Khandker, Evangelos Bitsikas, Aanjhan Ranganathan, Christina Pöpper

arXiv 2609.06855首次发表:更新:

发表机构

University of California, Berkeley; New York University Abu Dhabi; Northeastern University(加州大学伯克利分校; 纽约大学阿布扎比分校; 东北大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

提出基于图的O-RAN安全分析框架,将静态语料转为可查询数据库,含350+节点和1250+关系,结合LLM提取,揭示关键基础设施威胁、内存安全弱点和模糊测试发现。

AI 中文摘要

开放无线接入网(O-RAN)用模块化、可互操作的架构取代了供应商锁定的无线接入网,促进了竞争并加速了创新。这种开放性带来了更高的复杂性和更大的攻击面,使安全性成为关键问题。目前,评估O-RAN安全性需要手动交叉参考数十份规范、供应商白皮书和学术研究,这种方法容易出错且是静态的。在本文中,我们提出了一种基于图的框架,将这一静态语料库转换为一个单一、可查询的数据库。我们的图表示包含超过350个节点和超过1250条关系,这些内容从规范、学术论文、开源项目和漏洞数据库中提炼而来。为了保持该资源的时效性,我们集成了一条混合数据提取流水线,该流水线将结构化规范的确定性解析与用于不断演进的规范和非结构化文献的大语言模型(LLM)辅助提取相结合。查询该图在我们的精选语料库中揭示了三个可操作发现:关键基础设施(如O-DU、SMO和O-Cloud)承载着数十个规范级威胁,但几乎没有或根本没有实证覆盖;内存安全弱点占所分析CVE关联的21个CWE出现中的11个;模糊测试发现了归因于研究论文的20个CVE中的18个。我们将数据库、流水线和查询作为开源工件提供。

英文摘要

The Open Radio Access Network (O-RAN) replaces vendor-locked RANs with a modular and interoperable architecture that fosters competition and accelerates innovation. With this openness comes increased complexity and a larger attack surface, making security a critical concern. Today, assessing O-RAN security requires manually cross-referencing dozens of specifications, vendor whitepapers, and academic studies, which is error-prone and static. In this paper, we present a graph-based framework that transforms this static corpus into a single, queryable database. Our graph representation contains over 350 nodes and more than 1,250 relationships, distilled from specifications, academic papers, open-source projects, and vulnerability databases. To keep this resource current, we integrate a hybrid data extraction pipeline that couples deterministic parsing of structured specifications with Large Language Model (LLM)-assisted extraction for evolving specifications and unstructured literature. Querying the graph reveals three actionable findings within our curated corpus: critical infrastructure such as the O-DU, SMO, and O-Cloud carries dozens of specification-level threats yet has little or no empirical coverage; memory-safety weaknesses account for 11 of the 21 CWE occurrences associated with the analyzed CVEs; and fuzzing uncovered 18 of the 20 CVEs attributed to research papers. We provide the database, pipeline, and queries as open-source artifacts.

Comments17 pages, 12 figures, 5 tables, and 11 code listings

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑