{"id":"https://openalex.org/W4398131543","doi":"https://doi.org/10.1145/3643833.3656118","title":"Security Testing The O-RAN Near-Real Time RIC & A1 Interface","display_name":"Security Testing The O-RAN Near-Real Time RIC & A1 Interface","publication_year":2024,"publication_date":"2024-05-20","ids":{"openalex":"https://openalex.org/W4398131543","doi":"https://doi.org/10.1145/3643833.3656118"},"language":"en","primary_location":{"is_oa":false,"landing_page_url":"https://doi.org/10.1145/3643833.3656118","pdf_url":null,"source":null,"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false},"type":"article","type_crossref":"proceedings-article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5088851494","display_name":"Kashyap Thimmaraju","orcid":"https://orcid.org/0009-0006-1507-3896"},"institutions":[{"id":"https://openalex.org/I4577782","display_name":"Technische Universit\u00e4t Berlin","ror":"https://ror.org/03v4gjf40","country_code":"DE","type":"education","lineage":["https://openalex.org/I4577782"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Kashyap Thimmaraju","raw_affiliation_strings":["Technische Universit\u00e4t Berlin, Berlin, Germany"],"affiliations":[{"raw_affiliation_string":"Technische Universit\u00e4t Berlin, Berlin, Germany","institution_ids":["https://openalex.org/I4577782"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5034768977","display_name":"Altaf Shaik","orcid":"https://orcid.org/0000-0003-2657-6975"},"institutions":[{"id":"https://openalex.org/I4577782","display_name":"Technische Universit\u00e4t Berlin","ror":"https://ror.org/03v4gjf40","country_code":"DE","type":"education","lineage":["https://openalex.org/I4577782"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Altaf Shaik","raw_affiliation_strings":["Technische Universit\u00e4t Berlin, Berlin, Germany"],"affiliations":[{"raw_affiliation_string":"Technische Universit\u00e4t Berlin, Berlin, Germany","institution_ids":["https://openalex.org/I4577782"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5098721593","display_name":"Sunniva Fl\u00fcck","orcid":"https://orcid.org/0009-0008-4352-6375"},"institutions":[{"id":"https://openalex.org/I4577782","display_name":"Technische Universit\u00e4t Berlin","ror":"https://ror.org/03v4gjf40","country_code":"DE","type":"education","lineage":["https://openalex.org/I4577782"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Sunniva Fl\u00fcck","raw_affiliation_strings":["Technische Universit\u00e4t Berlin & ETH Z\u00fcrich, Berlin, Germany"],"affiliations":[{"raw_affiliation_string":"Technische Universit\u00e4t Berlin & ETH Z\u00fcrich, Berlin, Germany","institution_ids":["https://openalex.org/I4577782"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5098714798","display_name":"Pere Joan Fullana Mora","orcid":"https://orcid.org/0009-0003-3958-6088"},"institutions":[],"countries":["ES"],"is_corresponding":false,"raw_author_name":"Pere Joan Fullana Mora","raw_affiliation_strings":["Technische Universit\u00e4t Berlin, Berlin, Spain"],"affiliations":[{"raw_affiliation_string":"Technische Universit\u00e4t Berlin, Berlin, Spain","institution_ids":[]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5050839776","display_name":"Christian Werling","orcid":"https://orcid.org/0009-0004-6938-5145"},"institutions":[{"id":"https://openalex.org/I4577782","display_name":"Technische Universit\u00e4t Berlin","ror":"https://ror.org/03v4gjf40","country_code":"DE","type":"education","lineage":["https://openalex.org/I4577782"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Christian Werling","raw_affiliation_strings":["Technische Universit\u00e4t Berlin, Berlin, Germany"],"affiliations":[{"raw_affiliation_string":"Technische Universit\u00e4t Berlin, Berlin, Germany","institution_ids":["https://openalex.org/I4577782"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5001159554","display_name":"Jean\u2010Pierre Seifert","orcid":"https://orcid.org/0000-0002-5372-4825"},"institutions":[{"id":"https://openalex.org/I4577782","display_name":"Technische Universit\u00e4t Berlin","ror":"https://ror.org/03v4gjf40","country_code":"DE","type":"education","lineage":["https://openalex.org/I4577782"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Jean-Pierre Seifert","raw_affiliation_strings":["Technische Universit\u00e4t Berlin, Berlin, Germany"],"affiliations":[{"raw_affiliation_string":"Technische Universit\u00e4t Berlin, Berlin, Germany","institution_ids":["https://openalex.org/I4577782"]}]}],"institution_assertions":[],"countries_distinct_count":2,"institutions_distinct_count":1,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":2.002,"has_fulltext":true,"fulltext_origin":"pdf","cited_by_count":1,"citation_normalized_percentile":{"value":0.821555,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":83,"max":92},"biblio":{"volume":null,"issue":null,"first_page":"277","last_page":"287"},"is_retracted":false,"is_paratext":false,"primary_topic":{"id":"https://openalex.org/T10714","display_name":"Software-Defined Networks and 5G","score":0.9974,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10714","display_name":"Software-Defined Networks and 5G","score":0.9974,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11005","display_name":"Radiation Effects in Electronics","score":0.9961,"subfield":{"id":"https://openalex.org/subfields/2208","display_name":"Electrical and Electronic Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10951","display_name":"Cryptographic Implementations and Security","score":0.9951,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/ran","display_name":"Ran","score":0.73910016},{"id":"https://openalex.org/keywords/interface","display_name":"Interface (matter)","score":0.48943344}],"concepts":[{"id":"https://openalex.org/C160704184","wikidata":"https://www.wikidata.org/wiki/Q18031028","display_name":"Ran","level":2,"score":0.73910016},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6232268},{"id":"https://openalex.org/C113843644","wikidata":"https://www.wikidata.org/wiki/Q901882","display_name":"Interface (matter)","level":4,"score":0.48943344},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.32316336},{"id":"https://openalex.org/C31258907","wikidata":"https://www.wikidata.org/wiki/Q1301371","display_name":"Computer network","level":1,"score":0.31672767},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.27202362},{"id":"https://openalex.org/C157915830","wikidata":"https://www.wikidata.org/wiki/Q2928001","display_name":"Bubble","level":2,"score":0.0},{"id":"https://openalex.org/C129307140","wikidata":"https://www.wikidata.org/wiki/Q6795880","display_name":"Maximum bubble pressure method","level":3,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"is_oa":false,"landing_page_url":"https://doi.org/10.1145/3643833.3656118","pdf_url":null,"source":null,"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false}],"best_oa_location":null,"sustainable_development_goals":[],"grants":[],"datasets":[],"versions":[],"referenced_works_count":11,"referenced_works":["https://openalex.org/W2147118406","https://openalex.org/W2575352857","https://openalex.org/W2790865812","https://openalex.org/W2940873049","https://openalex.org/W4220945180","https://openalex.org/W4285243919","https://openalex.org/W4294145071","https://openalex.org/W4315783203","https://openalex.org/W4323646108","https://openalex.org/W4328053442","https://openalex.org/W4375928268"],"related_works":["https://openalex.org/W4391375266","https://openalex.org/W404373762","https://openalex.org/W2980853820","https://openalex.org/W2748952813","https://openalex.org/W2504993638","https://openalex.org/W2186004379","https://openalex.org/W2132764178","https://openalex.org/W2083168956","https://openalex.org/W1766728438","https://openalex.org/W1668090144"],"abstract_inverted_index":{"Open-Radio":[0],"Access":[1],"Network":[2],"(O-RAN)":[3],"is":[4,333],"the":[5,16,29,36,48,62,85,91,95,103,121,131,155,203,236,245,262,271,277,280,283,296,300,324],"next":[6,40],"evolutionary":[7],"step":[8],"in":[9,28,55,178,206,261,270],"mobile":[10],"network":[11],"architecture":[12,31],"and":[13,15,39,81,108,115,137,165,173,180,186,224,233,318,330],"operations":[14],"Near-Real":[17],"Time":[18,251],"RAN":[19,252],"Intelligent":[20,253],"Controller":[21,254],"(Near-RT":[22],"RIC)":[23],"plays":[24],"a":[25,52,70,200,211,319,331],"central":[26],"role":[27],"O-RAN":[30,56,142],"as":[32,191],"it":[33],"interfaces":[34],"between":[35],"orchestration":[37],"layer":[38],"generation":[41],"eNodeBs.":[42],"In":[43,94,120],"this":[44],"paper":[45],"we":[46,101,124,159,215],"highlight":[47],"architectural":[49],"weakness":[50],"of":[51,75,90,98,106,130,183,202,222,231,279,309,321],"centralized":[53],"controller":[54],"by":[57,135,289,303],"first":[58,96],"drawing":[59],"parallels":[60],"with":[61,267],"Software-Defined":[63],"Networking":[64],"(SDN)":[65],"controller.":[66],"We":[67,170],"then":[68],"present":[69,125],"two":[71,76],"part":[72,97],"security":[73,128,212],"evaluation":[74],"open-source":[77,112,156],"Near-RT":[78,92,157,208,240,272,297],"RICs":[79,158,241,291],"(\u03bcONOS":[80],"OSC),":[82],"focused":[83],"on":[84],"newly":[86],"introduced":[87],"A1":[88,132,143,196,246,284,301],"interface":[89,197],"RIC.":[93,298],"our":[99,126,140],"evaluation,":[100],"evaluate":[102],"supply-chain":[104,149],"risks":[105,164,205],"\u03bcONOS":[107,136,179,234,304],"OSC":[109,138,181,232],"using":[110,139],"off-the-shelf":[111],"dependency":[113,163,176,204],"analysis":[114,118,151],"configuration":[116],"file":[117],"tools.":[119],"second":[122],"part,":[123],"run-time":[127,229],"testing":[129,230],"API":[133],"implemented":[134],"custom":[141],"Interface":[144],"Testing":[145],"Tool":[146],"(OAITT).":[147],"Our":[148,228],"risk":[150],"shows":[152],"that":[153,259],"both":[154,207,239],"evaluated":[160],"have":[161],"multiple":[162],"weak":[166],"or":[167,257],"insecure":[168],"configurations.":[169],"identified":[171,216],"211":[172],"285":[174],"known":[175],"vulnerabilities":[177],"respectively":[182],"which":[184,274],"82":[185],"190":[187],"dependencies":[188],"were":[189],"rated":[190],"high":[192],"CVSS":[193],"respectively.":[194],"The":[195],"contributed":[198],"to":[199,307],"majority":[201],"RICs.":[209],"From":[210],"misconfiguration":[213],"perspective,":[214],"issues":[217],"concerning":[218],"access":[219],"control,":[220],"lack":[221,242],"encryption":[223],"poor":[225],"secret":[226],"management.":[227],"revealed":[235],"following.":[237],"First,":[238],"TLS":[243],"for":[244,292,315],"interface.":[247],"Second,":[248],"malicious":[249],"Non-Real":[250],"(Non-RT":[255],"RIC)s":[256],"rApps":[258],"reside":[260],"Non-RT":[263,290],"RIC":[264,273],"could":[265,286],"tamper":[266],"policies":[268],"installed":[269],"can":[275],"impact":[276],"availability":[278],"O-RAN.":[281],"Third,":[282],"protocol":[285],"be":[287],"exploited":[288],"covert":[293],"communication":[294],"via":[295],"Fourth,":[299],"implementation":[302],"was":[305],"vulnerable":[306],"degradation":[308],"service":[310,322],"attacks":[311],"(10-60s":[312],"response":[313],"time":[314],"GET":[316],"requests)":[317],"denial":[320],"attack,":[323],"latter":[325],"has":[326],"been":[327],"ethically":[328],"reported":[329],"fix":[332],"underway.":[334]},"cited_by_api_url":"https://api.openalex.org/works?filter=cites:W4398131543","counts_by_year":[{"year":2024,"cited_by_count":1}],"updated_date":"2025-01-19T23:27:35.586159","created_date":"2024-05-21"}