{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,9,8]],"date-time":"2024-09-08T07:11:11Z","timestamp":1725779471124},"publisher-location":"New York, NY, USA","reference-count":41,"publisher":"ACM","funder":[{"name":"Einstein Foundation (Einstein Research Unit on Quantum Devices)"},{"name":"German Federal Ministry of Education and Research","award":["16KISK020K"]},{"name":"German Federal Ministry for Digital and Transport","award":["19OL22004C"]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,5,27]]},"DOI":"10.1145\/3643833.3656118","type":"proceedings-article","created":{"date-parts":[[2024,5,20]],"date-time":"2024-05-20T23:25:07Z","timestamp":1716247507000},"page":"277-287","update-policy":"http:\/\/dx.doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Security Testing The O-RAN Near-Real Time RIC & A1 Interface"],"prefix":"10.1145","author":[{"ORCID":"http:\/\/orcid.org\/0009-0006-1507-3896","authenticated-orcid":false,"given":"Kashyap","family":"Thimmaraju","sequence":"first","affiliation":[{"name":"Technische Universit\u00e4t Berlin, Berlin, Germany"}]},{"ORCID":"http:\/\/orcid.org\/0000-0003-2657-6975","authenticated-orcid":false,"given":"Altaf","family":"Shaik","sequence":"additional","affiliation":[{"name":"Technische Universit\u00e4t Berlin, Berlin, Germany"}]},{"ORCID":"http:\/\/orcid.org\/0009-0008-4352-6375","authenticated-orcid":false,"given":"Sunniva","family":"Fl\u00fcck","sequence":"additional","affiliation":[{"name":"Technische Universit\u00e4t Berlin & ETH Z\u00fcrich, Berlin, Germany"}]},{"ORCID":"http:\/\/orcid.org\/0009-0003-3958-6088","authenticated-orcid":false,"given":"Pere Joan Fullana","family":"Mora","sequence":"additional","affiliation":[{"name":"Technische Universit\u00e4t Berlin, Berlin, Spain"}]},{"ORCID":"http:\/\/orcid.org\/0009-0004-6938-5145","authenticated-orcid":false,"given":"Christian","family":"Werling","sequence":"additional","affiliation":[{"name":"Technische Universit\u00e4t Berlin, Berlin, Germany"}]},{"ORCID":"http:\/\/orcid.org\/0000-0002-5372-4825","authenticated-orcid":false,"given":"Jean-Pierre","family":"Seifert","sequence":"additional","affiliation":[{"name":"Technische Universit\u00e4t Berlin, Berlin, Germany"}]}],"member":"320","published-online":{"date-parts":[[2024,5,27]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"ORAN Alliance. 2022a. O-RAN.SFG.Non-RT-RIC-Security-TR-v01.00. ORAN Documentation (March 2022)."},{"key":"e_1_3_2_1_2_1","unstructured":"ORAN Alliance. 2022b. O-RAN.TIFG.E2E-Test.0-v04.00. ORAN Documentation (October 2022)."},{"key":"e_1_3_2_1_3_1","volume-title":"2023 a. O-RAN.WG11.Security-Near-RT-RIC-xApps-TR.0-R003-v03. ORAN Documentation (June","author":"Alliance ORAN","year":"2023","unstructured":"ORAN Alliance. 2023 a. O-RAN.WG11.Security-Near-RT-RIC-xApps-TR.0-R003-v03. ORAN Documentation (June 2023)."},{"key":"e_1_3_2_1_4_1","volume-title":"2023 b. O-RAN.WG11.Security-Requirements-Specification.O-R003-v06.00. ORAN Documentation (June","author":"Alliance ORAN","year":"2023","unstructured":"ORAN Alliance. 2023 b. O-RAN.WG11.Security-Requirements-Specification.O-R003-v06.00. ORAN Documentation (June 2023)."},{"key":"e_1_3_2_1_5_1","volume-title":"2023 c. O-RAN.WG11.Security-Test-Specifications.O-R003-v04.00. ORAN Documentation (June","author":"Alliance ORAN","year":"2023","unstructured":"ORAN Alliance. 2023 c. O-RAN.WG11.Security-Test-Specifications.O-R003-v04.00. ORAN Documentation (June 2023)."},{"key":"e_1_3_2_1_6_1","volume-title":"2023 d. O-RAN.WG11.Threat-Model.O-R003-v06.00. ORAN Documentation (June","author":"Alliance ORAN","year":"2023","unstructured":"ORAN Alliance. 2023 d. O-RAN.WG11.Threat-Model.O-R003-v06.00. ORAN Documentation (June 2023)."},{"key":"e_1_3_2_1_7_1","volume-title":"2023 e. O-RAN.WG1.O-RAN-Architecture-Description-v09.00. ORAN Documentation (June","author":"Alliance ORAN","year":"2023","unstructured":"ORAN Alliance. 2023 e. O-RAN.WG1.O-RAN-Architecture-Description-v09.00. ORAN Documentation (June 2023)."},{"key":"e_1_3_2_1_8_1","volume-title":"2023 f. O-RAN.WG2.A1AP-R003-v04.00. ORAN Documentation (March","author":"Alliance ORAN","year":"2023","unstructured":"ORAN Alliance. 2023 f. O-RAN.WG2.A1AP-R003-v04.00. ORAN Documentation (March 2023)."},{"key":"e_1_3_2_1_9_1","volume-title":"2023 g. O-RAN.WG2.A1GAP-R003-v03.01. ORAN Documentation (March","author":"Alliance ORAN","year":"2023","unstructured":"ORAN Alliance. 2023 g. O-RAN.WG2.A1GAP-R003-v03.01. ORAN Documentation (March 2023)."},{"key":"e_1_3_2_1_10_1","volume-title":"2023 h. O-RAN.WG2.A1TP-R003-v02.01. ORAN Documentation (March","author":"Alliance ORAN","year":"2023","unstructured":"ORAN Alliance. 2023 h. O-RAN.WG2.A1TP-R003-v02.01. ORAN Documentation (March 2023)."},{"key":"e_1_3_2_1_11_1","volume-title":"2023 i. O-RAN.WG3.RICARCH-R003-v04.00. ORAN Documentation (March","author":"Alliance ORAN","year":"2023","unstructured":"ORAN Alliance. 2023 i. O-RAN.WG3.RICARCH-R003-v04.00. ORAN Documentation (March 2023)."},{"volume-title":"Accessed","year":"2023","key":"e_1_3_2_1_12_1","unstructured":"Anchore. 2023. Grype: A Vulnerability Scanner for Container Images and Filesystems. https:\/\/github.com\/anchore\/grype. Accessed: September 27, 2023."},{"key":"e_1_3_2_1_13_1","unstructured":"Airhop Communications. 2023. AirHop Launches the Industry's First Comprehensive Portfolio of Field-proven xApps and rApps to Accelerate 4G and 5G Open RAN Deployments. https:\/\/www.airhopcomm.com\/news\/airhop-launches-the-industrys-first-comprehensive-portfolio-of-field-proven-xapps-and-rapps-to-accelerate-4g-and-5g-open-ran-deployments\/ Accessed: 21-08--2023."},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2023.3274487"},{"key":"e_1_3_2_1_15_1","unstructured":"drwetter. 2024. testssl.sh. https:\/\/github.com\/drwetter\/testssl.sh. Accessed: 26-01--2024."},{"key":"e_1_3_2_1_16_1","unstructured":"Stefan K\u00f6psell et al. 2022. Open RAN Risk Analysis. https:\/\/www.bsi.bund.de\/SharedDocs\/ Downloads\/EN\/BSI\/Publications\/Studies\/5G\/5GRAN-Risk-Analysis.pdf?__blob=publicationFile& v=7"},{"key":"e_1_3_2_1_17_1","volume-title":"The Cost of Securing O-RAN. In ICC 2023-IEEE International Conference on Communications. IEEE, 5444--5449","author":"Groen Joshua","year":"2023","unstructured":"Joshua Groen, Brian Kim, and Kaushik Chowdhury. 2023. The Cost of Securing O-RAN. In ICC 2023-IEEE International Conference on Communications. IEEE, 5444--5449."},{"key":"e_1_3_2_1_18_1","unstructured":"Ceki G\u00fclc\u00fc. 2003. The complete log4j manual. QOS. ch."},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1109\/GCWkshps56602.2022.10008543"},{"key":"e_1_3_2_1_20_1","unstructured":"KICS. 2024. KICS. https:\/\/kics.io. Accessed: 26-01--2024."},{"key":"e_1_3_2_1_21_1","volume-title":"Open or not open: Are conventional radio access networks more secure and trustworthy than Open-RAN? arXiv preprint arXiv:2204.12227","author":"Klement Felix","year":"2022","unstructured":"Felix Klement, Stefan Katzenbeisser, Vincent Ulitzsch, Juliane Kr\"amer, Slawomir Stanczak, Zoran Utkovski, Igor Bjelakovic, and Gerhard Wunder. 2022. Open or not open: Are conventional radio access networks more secure and trustworthy than Open-RAN? arXiv preprint arXiv:2204.12227 (2022)."},{"key":"e_1_3_2_1_22_1","volume-title":"BSI studies","author":"K\u00f6psell Stefan","year":"2022","unstructured":"Stefan K\u00f6psell, Andrey Ruzhanskiy, Andreas Hecker, Dirk Stachorra, and Norman Franchi. 2022. Open RAN Risk Analysis. Federal Office for Information Security, BSI studies (2022)."},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.23919\/IFIPNetworking.2018.8696597"},{"key":"e_1_3_2_1_24_1","unstructured":"Kubernetes. 2023 a. Configure a Security Context for a Pod or Container. https:\/\/kubernetes.io\/docs\/tasks\/configure-pod-container\/security-context\/"},{"key":"e_1_3_2_1_25_1","unstructured":"Kubernetes. 2023 b. Secrets. https:\/\/kubernetes.io\/docs\/concepts\/configuration\/secret\/"},{"key":"e_1_3_2_1_26_1","unstructured":"Leeon123. 2024. Stress-tester. https:\/\/github.com\/Leeon123\/Stress-tester. Accessed: 26-01--2024."},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jnca.2023.103621"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/1355734.1355746"},{"key":"e_1_3_2_1_29_1","volume-title":"Evaluating the security of open radio access networks. arXiv preprint arXiv:2201.06080","author":"Mimran Dudu","year":"2022","unstructured":"Dudu Mimran, Ron Bitton, Yehonatan Kfir, Eitan Klevansky, Oleg Brodt, Heiko Lehmann, Yuval Elovici, and Asaf Shabtai. 2022. Evaluating the security of open radio access networks. arXiv preprint arXiv:2201.06080 (2022)."},{"key":"e_1_3_2_1_30_1","unstructured":"onosproject. 2022. Github Rimedo Traffic Steering xApp. https:\/\/github.com\/onosproject\/rimedo-ts Accessed: 14-08--2023."},{"key":"e_1_3_2_1_31_1","unstructured":"onosprojects. 2023. Installation with RAN-Simulator and RIMEDO Labs Traffic Steering xAPP (rimedo-ts xApp). https:\/\/github.com\/onosproject\/sdran-in-a-box\/blob\/master\/docs\/Installation_RANSim_RIMDEO_TS.md Accessed: 30-08--2023."},{"key":"e_1_3_2_1_32_1","unstructured":"OpenSSF. 2024. OpenSSF Scorecard. https:\/\/github.com\/ossf\/scorecard. Accessed: 26-01--2024."},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"crossref","unstructured":"OSC. 2022. Release F. https:\/\/wiki.o-ran-sc.org\/display\/RICP\/2022-05--24ReleaseF Accessed: 25-08--2023.","DOI":"10.1055\/s-0042-1755828"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1109\/TMC.2022.3188013"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.23919\/ICACT53585.2022.9728862"},{"key":"e_1_3_2_1_36_1","unstructured":"Snyk. [n. d.]. Guide to Software Composition Analysis (SCA)."},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2017.21"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/3185467.3185468"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1109\/FNWF55208.2022.00071"},{"key":"e_1_3_2_1_40_1","unstructured":"Trivy. 2024. Trivy. https:\/\/github.com\/aquasecurity\/trivy. Accessed: 26-01--2024."},{"key":"e_1_3_2_1_41_1","unstructured":"Wikipedia. 2023. Heartbleed. https:\/\/github.com\/onosproject\/sdran-in-a-box Accessed: 25-08--2023. io"}],"event":{"name":"WiSec '24: 17th ACM Conference on Security and Privacy in Wireless and Mobile Networks","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control","SIGMOBILE ACM Special Interest Group on Mobility of Systems, Users, Data and Computing"],"location":"Seoul Republic of Korea","acronym":"WiSec '24"},"container-title":["Proceedings of the 17th ACM Conference on Security and Privacy in Wireless and Mobile Networks"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3643833.3656118","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,6,27]],"date-time":"2024-06-27T10:26:42Z","timestamp":1719484002000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3643833.3656118"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,5,27]]},"references-count":41,"alternative-id":["10.1145\/3643833.3656118","10.1145\/3643833"],"URL":"https:\/\/doi.org\/10.1145\/3643833.3656118","relation":{},"subject":[],"published":{"date-parts":[[2024,5,27]]},"assertion":[{"value":"2024-05-27","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}