CoreCrisis: Threat-Guided and Context-Aware Iterative Learning and Fuzzing of 5G Core Networks
Yilu Dong, Tianchang Yang, Abdullah Al Ishtiaq, Syed Md Mukit Rashid, Ali Ranjbar, Kai Tu, Tianwei Wu, Md Sultan Mahmud, Syed Rafiul Hussain
34th USENIX Security Symposium · Day 1
The rapid evolution of 5G cellular networks, driven by a new service-based architecture (SBA), introduces unprecedented flexibility and scalability but also presents complex security challenges. The paper "CoreCrisis: Threat-Guided and Context-Aware Iterative Learning and Fuzzing of 5G Core Networks" addresses these challenges by presenting **CoreCrisis**, a novel stateful black-box fuzz-testing framework designed to uncover implementation flaws in 5G Core (5GC) networks. Developed by researchers at The Pennsylvania State University, CoreCrisis moves beyond the limitations of previous static and manually-driven security analysis methods by employing a dynamic, two-step iterative learning and fuzzing approach.
AI review
Solid systems security work that actually advances 5GC fuzzing beyond the usual 'we ran AFL on it' papers. The divide-and-conquer FSM learning and property-driven equivalence checking are genuine contributions, and finding 8 CVEs across commercial and open-source cores proves the approach works. Not revolutionary, but this is the kind of methodical research that moves the field.