{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,9,8]],"date-time":"2024-09-08T07:11:25Z","timestamp":1725779485921},"publisher-location":"New York, NY, USA","reference-count":58,"publisher":"ACM","funder":[{"DOI":"10.13039\/https:\/\/doi.org\/10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["CNS-1943079"],"id":[{"id":"10.13039\/https:\/\/doi.org\/10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,5,27]]},"DOI":"10.1145\/3643833.3656129","type":"proceedings-article","created":{"date-parts":[[2024,5,20]],"date-time":"2024-05-20T23:25:07Z","timestamp":1716247507000},"page":"254-264","update-policy":"http:\/\/dx.doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["PROV5GC: Hardening 5G Core Network Security with Attack Detection and Attribution Based on Provenance Graphs"],"prefix":"10.1145","author":[{"ORCID":"http:\/\/orcid.org\/0000-0002-1971-2599","authenticated-orcid":false,"given":"Harsh Sanjay","family":"Pacherkar","sequence":"first","affiliation":[{"name":"Department of Computer Science, Binghamton University, Binghamton, New York, USA"}]},{"ORCID":"http:\/\/orcid.org\/0000-0001-7482-4043","authenticated-orcid":false,"given":"Guanhua","family":"Yan","sequence":"additional","affiliation":[{"name":"Department of Computer Science, Binghamton University, Binghamton, New York, USA"}]}],"member":"320","published-online":{"date-parts":[[2024,5,27]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"https:\/\/www.p1sec.com\/corp\/2021\/12\/31\/pentesting-5g-core-networks\/."},{"key":"e_1_3_2_1_2_1","unstructured":"https:\/\/www.softeq.com\/blog\/how-to-ensure-5g-supply-chain-security."},{"key":"e_1_3_2_1_3_1","unstructured":"CVE-2021--45462. https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2021- 45462."},{"key":"e_1_3_2_1_4_1","unstructured":"CVE-2022--43677. https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2022- 43677."},{"key":"e_1_3_2_1_5_1","unstructured":"Docker Stats: Endpoint for live stream of a container's resource usage statistics. https:\/\/docs.docker.com\/engine\/api\/v1.41\/tag\/Container\/operation\/Contain erStats."},{"key":"e_1_3_2_1_6_1","unstructured":"open5gs. https:\/\/www.open5gs.org\/."},{"key":"e_1_3_2_1_7_1","unstructured":"Openairinterface. https:\/\/www.openairinterface.org\/."},{"key":"e_1_3_2_1_8_1","unstructured":"Snort. https:\/\/www.snort.org\/."},{"key":"e_1_3_2_1_9_1","unstructured":"srsRAN - Your own mobile network. https:\/\/www.srsran.com\/."},{"key":"e_1_3_2_1_10_1","unstructured":"UERANSIM: An Open Source State-of-the-Art 5G UE and RAN (gNodeB) Simulator . https:\/\/github.com\/aligungr\/UERANSIM."},{"key":"e_1_3_2_1_11_1","unstructured":"Zeek. https:\/\/zeek.org\/."},{"key":"e_1_3_2_1_12_1","unstructured":"ZeroMQ: An open-source universal messaging library. https:\/\/zeromq.org."},{"key":"e_1_3_2_1_13_1","unstructured":"3GPP. 5G; 5G System; Common Data Types for Service Based Interfaces; Stage 3 (3GPP TS 29.571 version 16.6.0 Release 16). https:\/\/www.etsi.org\/deliver\/etsi_ts\/ 129500_129599\/129571\/16.06.00_60\/ts_129571v160600p.pdf."},{"key":"e_1_3_2_1_14_1","unstructured":"3GPP. 5G; NG-RAN; NG Application Protocol (NGAP) (3GPP TS 38.413 version 16.7.0 Release 16). https:\/\/www.etsi.org\/deliver\/etsi_ts\/138400_138499\/138413\/16. 07.00_60\/ts_138413v160700p.pdf."},{"key":"e_1_3_2_1_15_1","unstructured":"3GPP. 5G;Security architecture and procedures for 5G System (3GPP TS 33.501 version 16.3.0 Release 16). https:\/\/www.etsi.org\/deliver\/etsi_ts\/133500_133599\/ 133501\/16.03.00_60\/ts_133501v160300p.pdf."},{"key":"e_1_3_2_1_16_1","unstructured":"AdaptiveMobile Security. A slice in time: Slicing security in 5G core networks. https:\/\/info.adaptivemobile.com\/5g-network-slicing-security."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3623113"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1186\/s13638-022-02204-5"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/2382196.2382221"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243846"},{"key":"e_1_3_2_1_21_1","first-page":"319","volume-title":"24th USENIX Security Symposium (USENIX Security 15)","author":"Bates A.","year":"2015","unstructured":"A. Bates, D. J. Tian, K. R. Butler, and T. Moyer. Trustworthy whole-system provenance for the Linux kernel. In 24th USENIX Security Symposium (USENIX Security 15), pages 319--334, 2015."},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/3558482.3590194"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-94-015-8163-9"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/3317549.3324927"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/3427228.3427256"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23394"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/1102120.1102171"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/3395351.3399347"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1145\/2046614.2046618"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-35170-9_6"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1002\/sim.8088"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23141"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23349"},{"key":"e_1_3_2_1_34_1","first-page":"487","volume-title":"Proceedings of USENIX Security Symposium","author":"Hossain M. N.","year":"2017","unstructured":"M. N. Hossain, S. M. Milajerdi, J. Wang, B. Eshete, R. Gjomemo, R. Sekar, S. D. Stoller, and V. Venkatakrishnan. SLEUTH: Real-time attack scenario reconstruction from COTS audit data. In Proceedings of USENIX Security Symposium, pages 487--504, 2017."},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00064"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354263"},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179405"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2021.3098977"},{"key":"e_1_3_2_1_39_1","volume-title":"Security for 5G service-based architecture: What you need to know. https:\/\/www.ericsson.com\/en\/blog\/2020\/8\/security-for-5g-servicebased- architecture","author":"Jost C.","year":"2020","unstructured":"C. Jost and B. Smeets. Security for 5G service-based architecture: What you need to know. https:\/\/www.ericsson.com\/en\/blog\/2020\/8\/security-for-5g-servicebased- architecture, 2020."},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2899254"},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00038"},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1145\/3317549.3323416"},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2016.23350"},{"volume-title":"Event Tracing for Windows (ETW). https:\/\/learn.microsoft.com\/enus\/ windows-hardware\/drivers\/devtest\/event-tracing-for-windows--etw-","year":"2021","key":"e_1_3_2_1_44_1","unstructured":"Microsoft. Event Tracing for Windows (ETW). https:\/\/learn.microsoft.com\/enus\/ windows-hardware\/drivers\/devtest\/event-tracing-for-windows--etw-, 2021."},{"key":"e_1_3_2_1_45_1","volume-title":"Network time protocol version 4: Protocol and algorithms specification. https:\/\/datatracker.ietf.org\/doc\/html\/draftietf- ntp-ntpv4-algorithms-01","author":"Mills D.","year":"2010","unstructured":"D. Mills, J. Martin, J. Burbank, and W. Kasch. Network time protocol version 4: Protocol and algorithms specification. https:\/\/datatracker.ietf.org\/doc\/html\/draftietf- ntp-ntpv4-algorithms-01, 2010."},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1145\/3127479.3129249"},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243776"},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660346"},{"key":"e_1_3_2_1_49_1","unstructured":"Positive Technologies. 5G standardalone core security research. https:\/\/positivetech. com\/knowledge-base\/research\/5g-sa-core-security-research\/."},{"key":"e_1_3_2_1_50_1","volume-title":"5G Core Networks: Powering Digitalization","author":"Rommer S.","year":"2019","unstructured":"S. Rommer, P. Hedman, M. Olsson, L. Frid, S. Sultana, and C. Mulligan. 5G Core Networks: Powering Digitalization. Academic Press, 2019."},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00006"},{"key":"e_1_3_2_1_52_1","volume-title":"Proceedings of the Network and Distributed System Security Symposium","author":"Shaik A.","year":"2015","unstructured":"A. Shaik, R. Borgaonkar, N. Asokan, V. Niemi, and J.-P. Seifert. Practical attacks against privacy and availability in 4G\/LTE mobile communication systems. Proceedings of the Network and Distributed System Security Symposium, 2015."},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243829"},{"key":"e_1_3_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23282"},{"key":"e_1_3_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1145\/3546096.3546111"},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1109\/CCNC51644.2023.10059624"},{"key":"e_1_3_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1145\/2043556.2043584"},{"key":"e_1_3_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1145\/3539605"}],"event":{"name":"WiSec '24: 17th ACM Conference on Security and Privacy in Wireless and Mobile Networks","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control","SIGMOBILE ACM Special Interest Group on Mobility of Systems, Users, Data and Computing"],"location":"Seoul Republic of Korea","acronym":"WiSec '24"},"container-title":["Proceedings of the 17th ACM Conference on Security and Privacy in Wireless and Mobile Networks"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3643833.3656129","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,6,27]],"date-time":"2024-06-27T10:29:11Z","timestamp":1719484151000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3643833.3656129"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,5,27]]},"references-count":58,"alternative-id":["10.1145\/3643833.3656129","10.1145\/3643833"],"URL":"https:\/\/doi.org\/10.1145\/3643833.3656129","relation":{},"subject":[],"published":{"date-parts":[[2024,5,27]]},"assertion":[{"value":"2024-05-27","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}