Skip to content
Preprint

Towards Operator-Empowered Vulnerability Hotfixing for 5G Radio Access Networks

Aug 2026 · 0 citations · 65 references
Computer Science

TL;DR

Buckle is presented, a framework that enables an MNO to deploy temporary, local, and reversible hotfixes in its radio access network (RAN) during this exposure window and establishes operator-empowered hotfixing as a practical and portable interim defense and delineate the architectural limits of RAN-only prevention.

Abstract

Cellular protocol vulnerabilities can remain exploitable for months or years while standards bodies, vendors, and mobile network operators (MNOs) coordinate permanent fixes. We present Buckler, a framework that enables an MNO to deploy temporary, local, and reversible hotfixes in its radio access network (RAN) during this exposure window. Buckler places reusable hooks at standardized L2/L3 channel boundaries and exposes a closed, stateful match-action interface with three preventive actions: DROP, MODIFY, and RELEASE. We evaluate whether this bounded design provides useful coverage without requiring extensive changes to existing RANs. From 23 papers, we identify 64 attacks rooted in standard L2/L3 protocol behavior, of which 43 provide a preventive intervention point at the RAN, and we construct Buckler hotfixes for 20 of them. All 20 hotfixes use the same rule vocabulary and only five standardized channel hooks, while the unsupported attacks expose endpoint dependencies that a RAN cannot satisfy alone. We implement the five hooks on srsRAN and OpenAirInterface with small, structurally similar changes, and demonstrate all three actions against representative availability and privacy attacks. These results establish operator-empowered hotfixing as a practical and portable interim defense and delineate the architectural limits of RAN-only prevention.

View source

Similar papers

Preprint Aug 2026

Experimental Validation and Mitigation of RRC Storm Attacks in 5G Cellular Networks

The initial access phase of the 5G system remains sensitive because the base station (gNB) must allocate radio resources before the user is fully authenticated. In particular, the random access channel (RACH) procedure can be abused to generate large numbers of incomplete connection attempts, creating a signaling storm...

Abdallah Abou Hasna, A. El Falou · 0 citations
#software testing Preprint Sep 2026

5G-Shark: A Network Security Auditor for 5G Subscriber Privacy and Unauthenticated Signalling Resilience

5G-Shark is presented, a security assessment tool and methodology that turns a legitimate mobility procedure against the subscriber, and empirical evidence that in several commercial deployments, temporary identifiers are re-allocated in near-sequential steps that keep successive values linkable, a weakness that enable...

Oscar Lasierra, Gines Garcia-Aviles, A. Skarmeta et al. · 0 citations
Conference Open access 2026

Mitigating Security Challenges in 5G Wireless Networks

An AI-assisted, cross-layer security orchestration framework that integrates epoch-wise telemetry with ML-based risk estimation and formalizes mitigation as a Constrained Markov Decision Process (CMDP), and empirical evidence that adaptive mitigation can reduce security risk without sacrificing service guarantees is pr...

F. Philip-Kpae, A. Imoize, K. .. Okafor et al. · 0 citations
Preprint Sep 2026

rApp/xApp Attestation: A New Security Use Case for O-RAN

The disaggregation and softwarization introduced by the Open Radio Access Network (O-RAN) architecture enable multi-vendor innovation but also expose the RAN Intelligent Controller (RIC) ecosystem to new runtime security risks. Existing O-RAN specifications define strong safeguards for onboarding, authentication, ident...

Hamed Alimohammadi, B. Şahin, Arda Akman et al. · 0 citations
Open access Aug 2026

On the Resilience of Secure Remote-Access VPN Solutions: A System-Level Evaluation of WireGuard, OpenVPN and IPsec (strongSwan)

R resilience in remote-access VPNs should be interpreted as a system-level property emerging from the interaction of implementation architecture, endpoint characteristics, and deployment conditions, underline that resilience in remote-access VPNs should be interpreted as a system-level property emerging from the intera...

Rene Forsung, R. Pirmagomedov, A. Mezina et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.