The current design of 5G Core Network (5G CN) adopts a cloud-native service-based architecture, where Network Functions (NFs) are exposed as services that can be dynamically composed and managed to achieve high flexibility. These NFs are interconnected via interfaces that Standardization Development Organizations (SDOs) like 3GPP have standardized. The complexity of the interconnections and data sensitivity make these interfaces vulnerable. In this letter, we advocate the use of extended Berkeley Packet Filter (eBPF) to monitor the 5G CN interfaces activities. eBPF programs run in kernel space of the host machine, thereby providing visibility of all programs and this is especially convenient for observability of 5G CN NFs. With a specific use case implemented in Open Air Interface (OAI), we demonstrate the benefits of the eBPF framework to identify session deletion attacks and mitigate associated risks.

Nunziati, G., Fiandrino, C., Foschini, L., Bellavista, P. (2025). Monitoring 5G Core Networks Vulnerabilities With eBPF. IEEE NETWORKING LETTERS, 7(3), 220-223 [10.1109/lnet.2025.3577184].

Monitoring 5G Core Networks Vulnerabilities With eBPF

Nunziati, Gabriele;Foschini, Luca;Bellavista, Paolo
2025

Abstract

The current design of 5G Core Network (5G CN) adopts a cloud-native service-based architecture, where Network Functions (NFs) are exposed as services that can be dynamically composed and managed to achieve high flexibility. These NFs are interconnected via interfaces that Standardization Development Organizations (SDOs) like 3GPP have standardized. The complexity of the interconnections and data sensitivity make these interfaces vulnerable. In this letter, we advocate the use of extended Berkeley Packet Filter (eBPF) to monitor the 5G CN interfaces activities. eBPF programs run in kernel space of the host machine, thereby providing visibility of all programs and this is especially convenient for observability of 5G CN NFs. With a specific use case implemented in Open Air Interface (OAI), we demonstrate the benefits of the eBPF framework to identify session deletion attacks and mitigate associated risks.
2025
Nunziati, G., Fiandrino, C., Foschini, L., Bellavista, P. (2025). Monitoring 5G Core Networks Vulnerabilities With eBPF. IEEE NETWORKING LETTERS, 7(3), 220-223 [10.1109/lnet.2025.3577184].
Nunziati, Gabriele; Fiandrino, Claudio; Foschini, Luca; Bellavista, Paolo
File in questo prodotto:
File Dimensione Formato  
ebpf_core_vulnerabilities-2.pdf

embargo fino al 05/06/2026

Tipo: Postprint / Author's Accepted Manuscript (AAM) - versione accettata per la pubblicazione dopo la peer-review
Licenza: Licenza per accesso libero gratuito
Dimensione 220.26 kB
Formato Adobe PDF
220.26 kB Adobe PDF   Visualizza/Apri   Contatta l'autore

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11585/1033628
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 0
  • ???jsp.display-item.citation.isi??? 0
social impact