The current design of 5G Core Network (5G CN) adopts a cloud-native service-based architecture, where Network Functions (NFs) are exposed as services that can be dynamically composed and managed to achieve high flexibility. These NFs are interconnected via interfaces that Standardization Development Organizations (SDOs) like 3GPP have standardized. The complexity of the interconnections and data sensitivity make these interfaces vulnerable. In this letter, we advocate the use of extended Berkeley Packet Filter (eBPF) to monitor the 5G CN interfaces activities. eBPF programs run in kernel space of the host machine, thereby providing visibility of all programs and this is especially convenient for observability of 5G CN NFs. With a specific use case implemented in Open Air Interface (OAI), we demonstrate the benefits of the eBPF framework to identify session deletion attacks and mitigate associated risks.

Nunziati, G., Fiandrino, C., Foschini, L., Bellavista, P. (2025). Monitoring 5G Core Networks Vulnerabilities With eBPF. IEEE NETWORKING LETTERS, 7(3), 220-223 [10.1109/lnet.2025.3577184].

Monitoring 5G Core Networks Vulnerabilities With eBPF

Nunziati, Gabriele;Foschini, Luca;Bellavista, Paolo
2025

Abstract

The current design of 5G Core Network (5G CN) adopts a cloud-native service-based architecture, where Network Functions (NFs) are exposed as services that can be dynamically composed and managed to achieve high flexibility. These NFs are interconnected via interfaces that Standardization Development Organizations (SDOs) like 3GPP have standardized. The complexity of the interconnections and data sensitivity make these interfaces vulnerable. In this letter, we advocate the use of extended Berkeley Packet Filter (eBPF) to monitor the 5G CN interfaces activities. eBPF programs run in kernel space of the host machine, thereby providing visibility of all programs and this is especially convenient for observability of 5G CN NFs. With a specific use case implemented in Open Air Interface (OAI), we demonstrate the benefits of the eBPF framework to identify session deletion attacks and mitigate associated risks.
2025
Nunziati, G., Fiandrino, C., Foschini, L., Bellavista, P. (2025). Monitoring 5G Core Networks Vulnerabilities With eBPF. IEEE NETWORKING LETTERS, 7(3), 220-223 [10.1109/lnet.2025.3577184].
Nunziati, Gabriele; Fiandrino, Claudio; Foschini, Luca; Bellavista, Paolo
File in questo prodotto:
Eventuali allegati, non sono esposti

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11585/1033628
 Attenzione

Attenzione! I dati visualizzati non sono stati sottoposti a validazione da parte dell'ateneo

Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 0
  • ???jsp.display-item.citation.isi??? 0
social impact