A cloud security-based 5G core network security vulnerability detection method

CN122621906APending Publication Date: 2026-08-21BEIJING CHILI YONGXIANG TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610878470.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-06-17
Publication Date
2026-08-21

AI Technical Summary

Technical Problem

[0003]但是,现有技术在云化部署的5G核心网安全漏洞检测场景中,仍然存在云安全风险与核心网业务风险关联不足的问题

Benefits of technology

[0052]本发明通过采集云化部署的5G核心网安全检测关联数据并进行标准化处理,将核心网网元部署数据、云承载资源状态数据、服务接口配置数据、网元调用日志、访问权限数据、安全告警数据和漏洞扫描数据纳入统一处理流程,形成5G核心网安全检测基础数据集,在此基础上生成核心网云安全对象集合,使核心网网元、云承载资源、服务接口和安全事件能够在同一对象体系下进行关联分析,避免云资源风险、接口调用风险和安全事件分散处理导致的漏洞识别割裂问题。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122621906A_ABST
    Figure CN122621906A_ABST
Patent Text Reader

Abstract

The application discloses a 5G core network security vulnerability detection method based on cloud security and relates to the technical field of communication network security, and comprises the following steps: collecting 5G core network security detection associated data and performing standardized processing to generate a 5G core network security detection basic data set; identifying core network network elements, cloud bearing resources, service interfaces and security events to generate a core network cloud security object set; constructing a core network cloud gateway association chain; detecting and marking cloud bearing resource risks and core network interface calling risks to generate a core network cloud gateway association chain with risk marks; constructing a core network cloud security heterogeneous graph; identifying attack entry reachable states, permission satisfaction states, service exposure states and key network element influence states to generate a vulnerability exploitable condition set; performing path constraint propagation identification to generate a 5G core network security vulnerability detection result. The application can improve vulnerability positioning accuracy and influence path identification integrity.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of communication network security technology, and in particular to a method for detecting security vulnerabilities in 5G core networks based on cloud security. Background Technology

[0002] In recent years, with the development of 5G core network service-oriented architecture, cloud-native deployment, virtualization, and containerized operation technologies, core network elements have gradually shifted from dedicated hardware devices to software-based deployments within cloud resources. Current 5G core network security testing typically involves collecting and processing core network element deployment data, service interface configuration data, network element call logs, access permission data, security alarm data, and vulnerability scanning data. Through vulnerability scanning, configuration verification, log analysis, interface access detection, and alarm correlation, it identifies security risks in core network elements, service interfaces, or cloud resources and outputs security alarms or vulnerability lists. Some solutions also combine cloud platform resource status, container runtime status, and access permission configurations to detect configuration defects, service exposures, and abnormal permissions in the cloud environment.

[0003] However, existing technologies for detecting security vulnerabilities in cloud-deployed 5G core networks still suffer from insufficient correlation between cloud security risks and core network service risks. On the one hand, cloud bearer resource risks, core network interface call risks, and security events are typically detected in a fragmented manner, making it difficult to form a unified core network-cloud network association chain based on the deployment and bearer status between core network elements and cloud bearer resources, and the service call status between core network elements. This results in a lack of clear correlation between vulnerability locations and service impact paths. On the other hand, existing detection results mostly remain at the level of single-point vulnerabilities or single-item alerts, lacking identification of attack entry reachability status, permission satisfaction status, service exposure status, and critical network element impact status based on the heterogeneous graph of core network cloud security. This makes it difficult to determine whether vulnerabilities have the conditions for actual exploitation, and also makes it difficult to accurately determine the location, impact path, and risk level of security vulnerabilities. Summary of the Invention

[0004] One objective of this invention is to propose a cloud-based method for detecting security vulnerabilities in the 5G core network. This invention fully utilizes cloud security analysis, 5G core network service-oriented call correlation modeling, and heterogeneous graph path constraint propagation technology to correlate and detect risks of cloud-bearing resources, core network interface call risks, and vulnerability exploitability conditions. It accurately determines the location of security vulnerabilities, the path of vulnerability impact, and the risk level, and has the advantages of accurate vulnerability location, clear impact path, and targeted risk management.

[0005] A method for detecting security vulnerabilities in a 5G core network based on cloud security, according to an embodiment of the present invention, includes the following steps:

[0006] Collect and standardize the associated data of 5G core network security detection deployed in the cloud, and generate a basic dataset for 5G core network security detection.

[0007] Based on the 5G core network security detection basic dataset, core network elements, cloud bearer resources, service interfaces and security events are identified, and a core network cloud security object set is generated.

[0008] Organize the deployment and carrying status between core network elements and cloud carrying resources, as well as the service call status between core network elements, and construct a core network-cloud-network association chain that includes cloud resource carrying paths and network element service call paths;

[0009] Based on the core network cloud network association chain, cloud bearer resource risks and core network interface call risks are detected. The detected risks are marked to the cloud resource bearer path, core network element and network element service call path, respectively, and a core network cloud network association chain with risk marking is generated.

[0010] Based on the core network-cloud network interconnection chain with risk labels, construct a core network-cloud security heterogeneous graph;

[0011] Based on the heterogeneous graph of core network cloud security, the attack entry point reachability status, permission satisfaction status, service exposure status, and key network element impact status are identified to generate a set of exploitable vulnerability conditions.

[0012] Based on the set of exploitable conditions, path constraint propagation identification is performed to determine the location of security vulnerabilities, the path of vulnerability impact, and the risk level, thereby generating 5G core network security vulnerability detection results.

[0013] Optionally, the 5G core network security detection associated data includes core network element deployment data, cloud bearer resource status data, service interface configuration data, network element call logs, access permission data, security alarm data, and vulnerability scanning data. The standardization processing includes data format unification, timestamp alignment, object identification unification, call direction marking, deployment attribution marking, risk type marking, duplicate record merging, abnormal record removal, and missing field completion.

[0014] Optionally, the generation of the core network cloud security object set includes:

[0015] Using the object identifiers in the 5G core network security detection basic dataset as indexes, the core network element deployment data is merged by network element name, network element instance identifier and running status to generate core network element objects;

[0016] The cloud bearer resource status data is merged according to resource identifier and bearer location to generate cloud bearer resource objects;

[0017] The service interface configuration data is matched with the network element call logs according to the interface identifier and call direction to generate a service interface object;

[0018] Security alert data and vulnerability scan data are merged according to risk type, occurrence time, and affected objects to generate security event objects;

[0019] The core network element objects, cloud bearer resource objects, service interface objects, and security event objects are associated based on object identifiers to generate a core network cloud security object set.

[0020] Optionally, the construction of the core network-cloud network interconnection chain includes:

[0021] Based on the core network element objects and cloud bearer resource objects in the core network cloud security object set, a matching record of network element resources is generated by matching according to object identifier, deployment ownership mark and bearer location;

[0022] The core network element objects, cloud bearer resource objects, and deployment bearer status in the network element resource matching record are associated and organized to generate cloud resource bearer paths;

[0023] Based on the core network element objects and service interface objects in the core network cloud security object set, a matching record for the network element is generated by matching according to the interface identifier, the network element to which the interface belongs, and the calling direction.

[0024] The network element interface matching records are associated and organized to generate network element service call paths by associating and organizing the initiating network element, receiving network element, service interface object and service call status.

[0025] Connect the cloud resource carrying path and the network element service calling path according to the same core network element object to build a core network cloud network association chain.

[0026] Optionally, the generation of the core network-cloud network association chain with risk markers includes:

[0027] Based on the cloud resource bearing path in the core network cloud network association chain, verify the running status, access permission status and service exposure status of cloud bearing resource objects, and generate cloud bearing resource risks;

[0028] Based on the deployment and carrying status in the cloud resource carrying path, the cloud carrying resource risk is marked to the cloud carrying resource object and the core network element object connected to it;

[0029] Based on the network element service call path in the core network cloud network association chain, verify the call direction of the service interface object, the current access status of the interface and the service call status, and generate core network interface call risks.

[0030] Based on the call direction in the network element service call path, the core network interface call risk is marked to the service interface object and the core network element object it is connected to;

[0031] The cloud resource bearer path and the network element service call path that have completed risk marking are written into the core network cloud-network association chain to generate a core network cloud-network association chain with risk marking.

[0032] Optionally, the construction of the core network cloud security heterogeneous graph includes:

[0033] Based on the cloud bearer resource object, core network element object, service interface object, and security event object in the core network cloud-network association chain with risk labeling, cloud bearer resource nodes, core network element nodes, service interface nodes, and security event nodes are generated respectively.

[0034] Connect cloud resource nodes and core network element nodes according to the cloud resource carrying path to generate resource carrying edges;

[0035] Connect the core network element node, service interface node and core network element node corresponding to the calling network element and the calling receiving network element according to the network element service call path to generate service call edge;

[0036] Based on the marked positions of cloud bearer resource risks and core network interface call risks, security event nodes are connected to the corresponding cloud bearer resource nodes, core network element nodes, and service interface nodes to generate risk-marked edges;

[0037] The cloud-borne resource nodes, core network element nodes, service interface nodes, security event nodes, resource-borne edges, service call edges, and risk-marking edges are encapsulated into a graph structure to generate a core network cloud security heterogeneous graph.

[0038] Optionally, the generation of the exploitable condition set includes:

[0039] Using the security event nodes in the core network cloud security heterogeneous graph as indexes, organize the cloud bearer resource nodes, core network element nodes, service interface nodes and risk marker edges connected to the security event nodes to generate security event association records;

[0040] Based on the risk marker edge, service call edge, and call direction in the security event association record, determine whether the security event node can be reached by external access or internal lateral access, and generate the attack entry point reachability status;

[0041] Based on the access permission status in the security event association record and the deployment ownership mark of the core network element node, determine the permission satisfaction status of the associated object of the security event node;

[0042] Based on the current access status, service exposure status, and service call edge of the service interface node, determine the service exposure status of the interface associated with the security event node;

[0043] The impact status of key network elements is determined based on the location of core network element nodes in the network element service call path and the connection position of risk-marked edges.

[0044] The attack entry point reachability status, permission fulfillment status, service exposure status, and critical network element impact status are written into the same security event node to generate a set of exploitable vulnerability conditions.

[0045] Optionally, the generation of the 5G core network security vulnerability detection results includes:

[0046] Starting with the security event node in the vulnerability exploitability set, check the attack entry point reachability status, permission satisfaction status, service exposure status, and critical network element impact status to generate a propagable security event.

[0047] Risky connection nodes are identified based on risk-marked edges of propagable security event connections. The path propagation starting point is determined according to the reachability status of the attack entry point, the type of risky connection node, and the call direction of the service call edge. Propagation matching is performed along the resource carrying edge and the service call edge according to the carrying direction and the call direction. Connections that meet the requirements of attack entry point reachability, permission satisfaction, service exposure reachability, and critical network elements being affected are retained to generate vulnerability impact paths.

[0048] The location of the security vulnerability is determined based on the connection positions of security event nodes, cloud bearer resource nodes, core network element nodes, and service interface nodes in the vulnerability impact path;

[0049] The risk level is determined based on the connection length of the vulnerability's impact path, the number of affected core network element nodes, and the impact status of critical network elements.

[0050] By associating the location of security vulnerabilities, the path of their impact, and their risk level, the detection results for 5G core network security vulnerabilities are generated.

[0051] The beneficial effects of this invention are:

[0052] This invention collects and standardizes security detection data from cloud-deployed 5G core networks, incorporating core network element deployment data, cloud bearer resource status data, service interface configuration data, network element call logs, access permission data, security alarm data, and vulnerability scanning data into a unified processing flow. This forms a basic dataset for 5G core network security detection. Based on this dataset, a core network cloud security object set is generated, enabling core network elements, cloud bearer resources, service interfaces, and security events to be analyzed in a unified object system. This avoids the fragmented vulnerability identification problem caused by the scattered processing of cloud resource risks, interface call risks, and security events.

[0053] This invention further constructs a core network-cloud-network association chain that includes cloud resource carrying paths and network element service call paths. It marks cloud resource carrying risks and core network interface call risks onto the cloud resource carrying paths, core network elements, and network element service call paths. Based on this risk-marked core network-cloud-network association chain, a core network-cloud security heterogeneity graph is constructed, enabling security risks to be expressed along resource carrying edges, service call edges, and risk-marked edges. This processing method clarifies the connection status between the vulnerable object and cloud carrying resources, core network elements, and service interfaces, ensuring that vulnerability detection results are no longer limited to single-point alerts or isolated vulnerability lists.

[0054] This invention identifies the reachability of attack entry points, permission fulfillment status, service exposure status, and impact status of key network elements based on the heterogeneous graph of core network cloud security. It generates a set of exploitable vulnerability conditions and, combined with path constraint propagation identification, determines the location, impact path, and risk level of security vulnerabilities. This enables the determination of whether security vulnerabilities have practical exploitability conditions and whether they will affect key core network elements, thereby improving the accuracy of vulnerability location in cloud-based 5G core networks, the rationality of risk level determination, and the targeted nature of security measures. Attached Figure Description

[0055] The accompanying drawings are provided to further illustrate the invention and form part of the specification. They are used in conjunction with embodiments of the invention to explain the invention and do not constitute a limitation thereof. In the drawings:

[0056] Figure 1 This is an overall flowchart of a cloud-based 5G core network security vulnerability detection method proposed in this invention;

[0057] Figure 2 This is a schematic diagram illustrating the generation of a vulnerability exploitation condition set for a cloud-based 5G core network security vulnerability detection method proposed in this invention.

[0058] Figure 3 This diagram illustrates the generation of 5G core network security vulnerability detection results using a cloud-based 5G core network security vulnerability detection method proposed in this invention. Detailed Implementation

[0059] The present invention will now be described in further detail with reference to the accompanying drawings. These drawings are simplified schematic diagrams, illustrating only the basic structure of the invention, and therefore only show the components relevant to the invention.

[0060] refer to Figures 1-3 A cloud-based method for detecting security vulnerabilities in 5G core networks includes the following steps:

[0061] Collect and standardize the associated data of 5G core network security detection deployed in the cloud, and generate a basic dataset for 5G core network security detection.

[0062] Based on the 5G core network security detection basic dataset, core network elements, cloud bearer resources, service interfaces and security events are identified, and a core network cloud security object set is generated.

[0063] Organize the deployment and carrying status between core network elements and cloud carrying resources, as well as the service call status between core network elements, and construct a core network-cloud-network association chain that includes cloud resource carrying paths and network element service call paths;

[0064] Based on the core network cloud network association chain, cloud bearer resource risks and core network interface call risks are detected. The detected risks are marked to the cloud resource bearer path, core network element and network element service call path, respectively, and a core network cloud network association chain with risk marking is generated.

[0065] Based on the core network-cloud network interconnection chain with risk labels, construct a core network-cloud security heterogeneous graph;

[0066] Based on the heterogeneous graph of core network cloud security, the attack entry point reachability status, permission satisfaction status, service exposure status, and key network element impact status are identified to generate a set of exploitable vulnerability conditions.

[0067] Based on the set of exploitable conditions, path constraint propagation identification is performed to determine the location of security vulnerabilities, the path of vulnerability impact, and the risk level, thereby generating 5G core network security vulnerability detection results.

[0068] In this embodiment, the 5G core network security detection associated data includes core network element deployment data, cloud bearer resource status data, service interface configuration data, network element call logs, access permission data, security alarm data, and vulnerability scanning data. Standardization processing includes data format unification, timestamp alignment, object identification unification, call direction marking, deployment attribution marking, risk type marking, duplicate record merging, abnormal record removal, and missing field completion.

[0069] In this embodiment, the generation of the core network cloud security object set includes:

[0070] Using the object identifiers in the 5G core network security detection basic dataset as indexes, the core network element deployment data is merged by network element name, network element instance identifier and running status to generate core network element objects;

[0071] The generation of core network element objects is as follows: Using the object identifier in the 5G core network security detection basic dataset as an index, core network element deployment data is grouped to generate element deployment grouping results; in each element deployment grouping result, the element name, element instance identifier, running status, deployment attribution flag, and timestamp under the same object identifier are aggregated to generate basic attribute records for the element; the basic attribute records are merged according to the element name and element instance identifier to generate merged element instance records; the running status in the merged element instance records is sequentially arranged according to the timestamp, retaining the running status under the current timestamp to generate current element status records; the element instance identifier, element name, deployment attribution flag, and current element status records are written under the same object identifier to generate a core network element attribute table; records in the core network element attribute table that are missing object identifiers, missing element instance identifiers, or missing element names are removed to generate a valid core network element attribute table; each record in the valid core network element attribute table is encapsulated into a core network element object to generate a core network element object set.

[0072] The cloud bearer resource status data is merged according to resource identifier and bearer location to generate cloud bearer resource objects;

[0073] The generation of cloud bearer resource objects is specifically as follows: Using resource identifiers in the 5G core network security detection basic dataset as indexes, cloud bearer resource status data is grouped to generate cloud bearer resource grouping results; within each cloud bearer resource grouping result, resource type, bearer location, operating status, deployment attribution marker, and timestamp under the same resource identifier are aggregated to generate cloud bearer resource basic attribute records; the cloud bearer resource basic attribute records are merged according to bearer location to generate cloud bearer resource location merging records; and the cloud bearer resource location merging records are matched with core network element objects based on deployment attribution markers to generate cloud bearer resource bearer matching records. The process involves: matching records; organizing the operational status of cloud-based resources according to timestamps, retaining the operational status under the current timestamp, and generating a current status record for cloud-based resources; writing the resource identifier, resource type, hosting location, deployment attribution flag, and current status record of the cloud-based resources under the same resource identifier to generate a cloud-based resource attribute table; removing records in the cloud-based resource attribute table that are missing resource identifiers, resource types, or hosting locations to generate a valid cloud-based resource attribute table; and encapsulating each record in the valid cloud-based resource attribute table into a cloud-based resource object to generate a collection of cloud-based resource objects.

[0074] The service interface configuration data is matched with the network element call logs according to the interface identifier and call direction to generate a service interface object;

[0075] The generation of service interface objects is specifically as follows: Using the interface identifier in the 5G core network security detection basic dataset as an index, the service interface configuration data is grouped to generate interface configuration grouping results; within the interface configuration grouping results, the interface name, network element to which the interface belongs, interface access address, interface access method, and interface activation status under the same interface identifier are aggregated to generate interface configuration attribute records; using the interface identifier and call direction as a combined index, the network element call logs are grouped to generate call log grouping results; within the call log grouping results, the call initiating network element, call receiving network element, call timestamp, call result, and access status under the same combined index are aggregated to generate call log attribute records; the interface configuration attribute records and call log attribute records are then grouped according to the interface identifier... The system performs matching and writes the call direction into the matched record to generate an interface call matching record. It then organizes the call results and access status in the interface call matching record according to the call timestamp, retaining the access status under the current timestamp to generate a record of the current access status of the interface. The system writes the interface identifier, the network element to which the interface belongs, the network element that initiated the call, the network element that received the call, the call direction, the interface access address, and the current access status of the interface under the same interface identifier to generate a service interface attribute table. Records in the service interface attribute table that are missing an interface identifier, a network element to which the interface belongs, or a call direction are removed to generate a valid service interface attribute table. Finally, each record in the valid service interface attribute table is encapsulated into a service interface object to generate a collection of service interface objects.

[0076] Security alert data and vulnerability scan data are merged according to risk type, occurrence time, and affected objects to generate security event objects;

[0077] The generation of security event objects is specifically as follows: Security alarm data is grouped using the risk type in the 5G core network security detection basic dataset as an index, generating security alarm grouping results; within the security alarm grouping results, alarm sources, alarm content, occurrence time, affected objects, and alarm status under the same risk type are aggregated to generate security alarm attribute records; vulnerability scanning data is grouped using the risk type and affected objects as a combined index, generating vulnerability scanning grouping results; within the vulnerability scanning grouping results, vulnerability names, vulnerability locations, scan times, vulnerability status, and affected objects under the same combined index are aggregated to generate vulnerability scanning attribute records; and security alarms are grouped... Attribute records and vulnerability scan attribute records are matched according to risk type and affected objects to generate security event matching records; the security event matching records are then arranged chronologically according to occurrence time and scan time to generate security event time records; risk type, occurrence time, affected objects, alarm status, and vulnerability status are written into the same security event time record to generate a security event attribute table; records in the security event attribute table that are missing risk type, occurrence time, or affected objects are removed to generate a valid security event attribute table; each record in the valid security event attribute table is encapsulated as a security event object to generate a security event object set.

[0078] The core network element objects, cloud bearer resource objects, service interface objects, and security event objects are associated based on object identifiers to generate a core network cloud security object set.

[0079] In this embodiment, the construction of the core network-cloud network interconnection chain includes:

[0080] Based on the core network element objects and cloud bearer resource objects in the core network cloud security object set, a matching record of network element resources is generated by matching according to object identifier, deployment ownership mark and bearer location;

[0081] The core network element objects, cloud bearer resource objects, and deployment bearer status in the network element resource matching record are associated and organized to generate cloud resource bearer paths;

[0082] The generation of cloud resource bearer paths is as follows: Network element resource matching records are grouped according to the same core network element object to generate network element resource grouping records; the network element instance identifier, network element name, and operating status of the core network element object are organized in the network element resource grouping records to generate network element endpoint records; the resource identifier, resource type, bearer location, and operating status of the cloud bearer resource object are organized in the same network element resource grouping records to generate resource endpoint records; the network element endpoint records and resource endpoint records are connected according to the deployment attribution marker to generate network element resource connection records; based on the operating status of the core network element object, the operating status of the cloud bearer resource object, and the deployment attribution marker in the network element resource matching records, the deployment bearer status is organized to generate deployment bearer status; the resource endpoint record is used as the bearer start point, the network element endpoint record is used as the bearer end point, and the deployment bearer status is written between the bearer start point and the bearer end point to generate a single resource bearer path record; the single resource bearer path records are summarized according to the same core network element object to generate a cloud resource bearer path.

[0083] Based on the core network element objects and service interface objects in the core network cloud security object set, a matching record for the network element is generated by matching according to the interface identifier, the network element to which the interface belongs, and the calling direction.

[0084] The network element interface matching records are associated and organized to generate network element service call paths by associating and organizing the initiating network element, receiving network element, service interface object and service call status.

[0085] The generation of network element service call paths is as follows: Network element interface matching records are grouped according to the same initiating network element and the same receiving network element to generate network element call group records; the network element instance identifier, network element name, and running status of the initiating network element are organized in the network element call group records to generate a call start point record; the network element instance identifier, network element name, and running status of the receiving network element are organized in the same network element call group records to generate a call end point record; the interface identifier, network element to which the interface belongs, call direction, and current access status of the interface in the service interface object are organized to generate an interface connection record; the call start point record, interface connection record, and call end point record are connected sequentially according to the call direction to generate a network element interface connection record; the service call status is organized according to the current access status of the interface, the call result, and the call timestamp to generate a service call status record; the service call status record is written between the call start point record and the call end point record in the network element interface connection record to generate a single network element call path record; the single network element call path records are summarized according to the same initiating network element, the same receiving network element, and the same service interface object to generate a network element service call path.

[0086] The cloud resource bearer paths and network element service call paths are connected according to the same core network element object to construct a core network-cloud network association chain. Specifically, the cloud resource bearer paths are grouped using the core network element objects in the cloud resource bearer paths as bearer association points, generating bearer path grouping records. The network element service call paths are grouped using the call initiating network element and the call receiving network element in the network element service call path as call association points, generating call path grouping records. The core network element objects in the bearer path grouping records are matched with the call initiating network element and the call receiving network element in the call path grouping records to generate network element path matching records. The process involves: 1. Retaining cloud resource bearer paths and network element service call paths involving the same core network element object in the network element path matching record, generating a cloud-network path connection record; 2. Arranging the cloud bearer resource object, deployment bearer status, core network element object, service interface object, and service call status in the cloud-network path connection record according to the bearer direction and call direction, generating a single cloud-network association chain record; 3. Summarizing the single cloud-network association chain records according to the same core network element object, organizing the cloud resource bearer paths, network element service call paths, deployment bearer status, and service call status associated with the same core network element object, generating a core network cloud-network association chain.

[0087] In this embodiment, the generation of the core network-cloud network association chain with risk markers includes:

[0088] Based on the cloud resource bearing path in the core network cloud network association chain, verify the running status, access permission status and service exposure status of cloud bearing resource objects, and generate cloud bearing resource risks;

[0089] The generation of cloud-borne resource risks specifically involves: determining cloud-borne resource objects according to the cloud resource bearing path; organizing the resource identifier, resource type, bearing location, and operation records of the cloud-borne resource objects to generate resource operation records; merging the start status, stop status, restart status, abnormal exit status, and resource occupancy status in the resource operation records to generate resource operation status; matching the resource operation status with security alarm data, marking operation interruption, abnormal restart, resource unavailability, and alarm association, and generating operation status verification results; organizing access permission data according to cloud-borne resource objects to generate resource permission records; merging permissions according to the access subject, access object, permission scope, and permission usage records in the resource permission records to generate access permission status; and assigning access rights... The system matches the core network element objects connected to the cloud resource bearer path with the restricted status, marking situations such as missing permissions, out-of-bounds permissions, unauthorized access, and abnormal permission usage, generating access permission status verification results; it organizes service interface configuration data according to cloud bearer resource objects to generate resource service records; it merges exposure statuses based on service access addresses, service ports, interface enable status, and access source range in the resource service records to generate service exposure statuses; it matches service exposure statuses with security event objects, marking situations such as unauthorized exposure, abnormal openness, external reachability, and vulnerability association, generating service exposure status verification results; and it writes the runtime status verification results, access permission status verification results, and service exposure status verification results under the same cloud bearer resource object to generate cloud bearer resource risks.

[0090] Based on the deployment and carrying status in the cloud resource carrying path, the cloud carrying resource risk is marked to the cloud carrying resource object and the core network element object connected to it;

[0091] Based on the network element service call path in the core network cloud network association chain, verify the call direction of the service interface object, the current access status of the interface and the service call status, and generate core network interface call risks.

[0092] The generation of core network interface call risks specifically involves: determining the service interface object according to the network element service call path; organizing the interface identifier, network element to which the interface belongs, initiating network element, receiving network element, and call direction of the service interface object; generating an interface call direction record; verifying whether the access direction between the initiating network element and the receiving network element is consistent with the network element to which the service interface object belongs based on the interface call direction record, marking reverse calls, unauthorized calls, and unauthorized calls, and generating a call direction verification result; organizing the interface activation status, access address, access source range, and interface access result of the service interface object, and generating an interface current access status record; and verifying whether the interface is in a state of readiness based on the interface current access status record. The system checks the accessibility status, whether the access source falls within the allowed range, and whether there are any abnormal failures or successes in the interface access results, generating a current access status verification result for the interface. It also compiles the call timestamps, call results, access status, and continuous call information in the network element service call path, generating a service call status record. Based on the service call status record, it verifies the call continuity, call failure concentrations, and abnormal access concentrations of the same service interface object under the same call direction, generating a service call status verification result. Finally, it writes the call direction verification result, the current access status verification result, and the service call status verification result to the same service interface object and its connected core network element object, generating a core network interface call risk.

[0093] Based on the call direction in the network element service call path, the core network interface call risk is marked to the service interface object and the core network element object it is connected to;

[0094] The cloud resource bearer path and the network element service call path that have completed risk marking are written into the core network cloud-network association chain to generate a core network cloud-network association chain with risk marking.

[0095] In this embodiment, the construction of the core network cloud security heterogeneous graph includes:

[0096] Based on the cloud bearer resource object, core network element object, service interface object, and security event object in the core network cloud-network association chain with risk labeling, cloud bearer resource nodes, core network element nodes, service interface nodes, and security event nodes are generated respectively.

[0097] Connect cloud resource nodes and core network element nodes according to the cloud resource carrying path to generate resource carrying edges;

[0098] Connect the core network element node, service interface node and core network element node corresponding to the calling network element and the calling receiving network element according to the network element service call path to generate service call edge;

[0099] Based on the marked positions of cloud bearer resource risks and core network interface call risks, security event nodes are connected to the corresponding cloud bearer resource nodes, core network element nodes, and service interface nodes to generate risk-marked edges;

[0100] The cloud-borne resource nodes, core network element nodes, service interface nodes, security event nodes, resource-borne edges, service call edges, and risk-marking edges are encapsulated into a graph structure to generate a core network cloud security heterogeneous graph.

[0101] In this embodiment, the generation of the exploitable condition set includes:

[0102] Using the security event nodes in the core network cloud security heterogeneous graph as indexes, organize the cloud bearer resource nodes, core network element nodes, service interface nodes and risk marker edges connected to the security event nodes to generate security event association records;

[0103] Based on the risk marker edge, service call edge, and call direction in the security event association record, determine whether the security event node can be reached by external access or internal lateral access, and generate the attack entry point reachability status;

[0104] The generation of attack entry point reachability status specifically involves: using security event nodes in the security event association record as the processing object, reading the risk-marked edges connected to the security event node, determining the cloud bearer resource node, core network element node, or service interface node connected to the risk-marked edge, and generating a risk object location result; filtering records connected to service interface nodes in the risk object location result, and combining the service call edges to organize the connection order between service interface nodes and core network element nodes, generating an interface connection order record; based on the call direction in the interface connection order record, marking connections from external access sources to service interface nodes or core network element nodes as external access reach records; and based on the call direction in the interface connection order record... The connection from one core network element node to another core network element node via a service interface node is marked as an internal lateral access reach record. External access reach records and internal lateral access reach records are associated with security event nodes to generate security event reach records. When an external access reach record exists in the security event reach record, the attack entry point is marked as externally reachable. When no external access reach record exists in the security event reach record but an internal lateral access reach record exists, the attack entry point is marked as internally laterally reachable. When neither external nor internal lateral access reach records exist in the security event reach record, the attack entry point is marked as unreachable.

[0105] Based on the access permission status in the security event association record and the deployment ownership mark of the core network element node, determine the permission satisfaction status of the associated object of the security event node;

[0106] The determination of permission fulfillment status specifically involves: using security event nodes in the security event association record as the processing object, organizing the access subject, access object, authorized interface, and permission effectiveness status according to the access permission status to generate a permission scope record; organizing the initiating network element, receiving network element, interface identifier, call direction, and current access status of the interface according to the service interface node and network element service call path to generate an actual call record; matching the access subject with the initiating network element, the access object with the receiving network element, and the authorized interface with the interface identifier, and combining this with the permission effectiveness status to generate a permission scope verification result; when the access subject, access object, and... When all authorized interfaces match and the permission status is valid, the permission scope check result is "permission scope satisfied"; otherwise, the permission scope is not satisfied. The call direction is compared with the order from the access subject to the accessed object, and the permission usage check result is generated based on the current access status of the interface. When the call direction is consistent and the current access status of the interface is "successful access," the permission usage check result is "permission usage consistent"; otherwise, the permission usage is inconsistent. When the permission scope check result is "permission scope satisfied" and the permission usage check result is "permission usage consistent," the permission satisfied status is marked as "permission satisfied"; otherwise, the permission satisfied status is marked as "permission not satisfied."

[0107] Based on the current access status, service exposure status, and service call edge of the service interface node, determine the service exposure status of the interface associated with the security event node;

[0108] The determination of service exposure status is as follows: Using the security event node in the security event association record as the processing object, identify the service interface node connected to that security event node and generate an associated interface record; based on the interface enable status, access address, and access source range in the associated interface record, determine whether the service interface node is in an open access state and generate an interface open verification result; based on the successful access, failed access, and abnormal access status in the current access status of the interface, determine whether the service interface node can form a valid access and generate an interface access verification result; based on the call direction in the service call edge, determine whether the access source can reach the service interface node and generate a call source verification result; when the interface open verification result is open access, the interface access verification result is valid access, and the call source verification result is reachable, the service exposure status is marked as exposed and reachable; when the interface open verification result is open access and the interface access verification result is invalid access, the service exposure status is marked as exposed and restricted; when the interface open verification result is not open access, the service exposure status is marked as not exposed.

[0109] The impact status of key network elements is determined based on the location of core network element nodes in the network element service call path and the connection position of risk-marked edges.

[0110] The determination of the impact status of critical network elements is as follows: Using the security event nodes in the security event association record as the processing object, the affected core network element nodes are determined based on the risk marking edges; the affected core network element nodes are determined to be at the call initiation position, call receiving position, or call aggregation position based on the network element service call path; when the affected core network element node is at the call aggregation position, or connected to two or more network element service call paths, the critical network element impact status is marked as critical network element affected; when the affected core network element node is only at the call initiation position or call receiving position in a single network element service call path, the critical network element impact status is marked as ordinary network element affected; when the risk marking edge does not connect to a core network element node, the critical network element impact status is marked as no core network element affected.

[0111] The attack entry point reachability status, permission fulfillment status, service exposure status, and critical network element impact status are written into the same security event node to generate a set of exploitable vulnerability conditions.

[0112] In this embodiment, the generation of 5G core network security vulnerability detection results includes:

[0113] Starting with the security event node in the vulnerability exploitability set, check the attack entry point reachability status, permission satisfaction status, service exposure status, and critical network element impact status to generate a propagable security event.

[0114] Risk connection nodes are determined based on risk-marked edges of propagable security event connections. The path propagation starting point is determined according to the attack entry point's reachability status, the risk connection node type, and the service call edge's call direction. Specifically, using the risk-marked edges of propagable security event connections as indexes, the cloud bearer resource nodes, core network element nodes, or service interface nodes connected to the risk-marked edges are identified, generating risk connection nodes. When the attack entry point's reachability status is externally reachable and the risk connection node is a service interface node, that service interface node is determined as the path propagation starting point. When the attack entry point's reachability status is externally reachable and the risk connection node is a cloud bearer resource node, that cloud bearer resource node is determined as the path propagation starting point. When the attack entry point's reachability status is internally horizontally reachable, the core network element node corresponding to the calling network element is determined according to the service call edge's call direction, and that core network element node is determined as the path propagation starting point. When the risk connection node is a core network element node and that core network element node is connected to a network element service call path, that core network element node is determined as the path propagation starting point.

[0115] Propagation and matching are performed along the resource carrying edge and service calling edge according to the carrying direction and calling direction, retaining connections that meet the requirements of attack entry reachability, permission satisfaction, service exposure reachability, and critical network elements being affected, and generating vulnerability impact paths;

[0116] The location of the security vulnerability is determined based on the connection positions of security event nodes, cloud bearer resource nodes, core network element nodes, and service interface nodes in the vulnerability impact path;

[0117] The determination of security vulnerability locations is as follows: Taking the vulnerability impact path as the processing object, the connection positions of security event nodes, cloud bearer resource nodes, core network element nodes, and service interface nodes are organized according to the order from the path propagation start point to the path end point, generating a path node sequence record; the risk-directly affected nodes are determined based on the risk-marked edges connected to the security event nodes, generating a risk-affected location record; when the risk-directly affected node is a cloud bearer resource node, the cloud bearer resource node and its connected core network element nodes are marked as cloud-side candidate vulnerability locations; when the risk-directly affected node is a service interface node, the service interface node and its connected initiating and receiving network elements are marked as interface-side candidate vulnerability locations; when the risk-directly affected node is a core network element node, the core network element node is marked as a network element-side candidate vulnerability location; the cloud-side candidate vulnerability locations, interface-side candidate vulnerability locations, and network element-side candidate vulnerability locations are matched with the impact status of key network elements in the vulnerability impact path, retaining the candidate vulnerability locations of key network elements affected, and generating security vulnerability locations;

[0118] The risk level is determined based on the connection length of the vulnerability's impact path, the number of affected core network element nodes, and the impact status of critical network elements.

[0119] The risk level is determined as follows: Taking the vulnerability's impact path as the processing object, the number of resource-bearing edges and service-calling edges traversed between the path's propagation start point and end point is counted to generate the connection length; the number of core network element nodes connected to the risk-marked edges in the vulnerability's impact path is counted to generate the number of affected core network element nodes; the impact status of key network elements corresponding to the vulnerability's impact path is read to generate a network element impact judgment result; when the connection length is not less than three edges, the number of affected core network element nodes is not less than two, and the network element impact judgment result indicates that key network elements are affected, the risk level is determined as high risk; when the connection length is two edges, the number of affected core network element nodes is one, and the network element impact judgment result indicates that ordinary network elements are affected, the risk level is determined as medium risk; when the connection length is one edge, the number of affected core network element nodes is 0, and the network element impact judgment result indicates that no core network elements are affected, the risk level is determined as low risk; when the connection length is one edge, the number of affected core network element nodes is one, and the network element impact judgment result indicates that ordinary network elements are affected, the risk level is determined as low risk.

[0120] By associating the location of security vulnerabilities, the path of their impact, and their risk level, the detection results for 5G core network security vulnerabilities are generated.

[0121] Example 1: To verify the feasibility of this invention in implementation, it was applied to a cloud-based 5G core network security testing scenario in the core network security operation and maintenance center of a city operator. This core network covers the central urban area and two edge areas, operating in one central cloud resource pool and two edge cloud resource pools. It involves 36 software-defined network element instances, including AMF, SMF, UPF, AUSF, UDM, and NRF, and 214 associated cloud hosts, container instances, and virtual network resources, with 128 open or internally called service interfaces. During continuous testing, the security operation and maintenance center collected core network element deployment data, cloud bearer resource status data, service interface configuration data, network element call logs, access permission data, security alarm data, and vulnerability scanning data, accumulating approximately 280,000 original records. Traditional security tools can provide alerts for cloud resource anomalies, interface access anomalies, permission configuration anomalies, and vulnerability scanning during this period. However, these results are scattered across cloud platforms, core network management, log auditing, and vulnerability scanning interfaces. Security personnel need to manually determine whether a risk to a certain cloud-bearing resource affects a specific core network element, and they also need to manually trace whether interface anomalies affect authentication, session, or forwarding processes along the service call path. The handling process suffers from unclear vulnerability impact paths and inaccurate risk priority judgments.

[0122] When applying this invention in this scenario, the system preprocesses the collected 5G core network security detection associated data to generate a basic dataset for 5G core network security detection. Based on this basic dataset, it identifies core network elements, cloud bearer resources, service interfaces, and security events, generating a core network cloud security object set. It then organizes the deployment and bearer status between core network elements and cloud bearer resources, as well as the service call status between core network elements, constructing a core network-cloud-network association chain containing cloud resource bearer paths and network element service call paths. Based on this association chain, the system detects risks to cloud bearer resources and core network interface calls, marking the detected risks to cloud resource bearer paths, core network elements, and network element service call paths, generating a risk-marked core network-cloud-network association chain. Subsequently, it constructs a core network cloud security heterogeneous graph and identifies the attack entry point reachability, permission fulfillment, service exposure, and key network element impact status based on this graph, generating a vulnerability exploitability condition set. Finally, based on the vulnerability exploitability condition set, it performs path constraint propagation identification to determine the location, impact path, and risk level of security vulnerabilities, generating 5G core network security vulnerability detection results.

[0123] During a security operation and maintenance center, multiple abnormal access records were found in a cloud-bearing resource object in the edge cloud resource pool. This cloud-bearing resource object also carried an SMF-related network element instance. Traditional tools only marked this situation as a cloud resource service exposure alarm, failing to directly indicate whether the alarm affected core network services. Using this invention, the security event is written into the security event node of the core network cloud security heterogeneity graph and connected to the corresponding cloud-bearing resource node and service interface node via risk-marked edges. The system identifies the connection between the cloud-bearing resource node and the SMF-related core network element node along the resource-bearing edge, and further identifies network element service call paths between the SMF-related core network element node and the AMF-related and UPF-related core network element nodes along the service call edge. Since this security event simultaneously satisfies the conditions of attack entry point reachability, permission fulfillment, and service exposure reachability, and the affected core network element node is connected to multiple network element service call paths, the system marks the critical network element impact status as critical network element affected and outputs the security vulnerability location, vulnerability impact path, and risk level in the 5G core network security vulnerability detection results.

[0124] Through the above applications, security operations personnel can view the location, impact path, and risk level of security vulnerabilities in the same detection result, eliminating the need for repeated comparisons between the cloud resource management interface, the core network management interface, and vulnerability scanning records. For cloud-borne resource risks, the system can locate the core network element objects connected to the cloud resource along the cloud resource's bearer path; for core network interface call risks, the system can locate the service interface object, the initiating network element, and the receiving network element along the network element service call path; for security events that simultaneously possess attack entry points, permission conditions, service exposure conditions, and affect critical core network elements, the system can provide a clear vulnerability impact path and handling basis. Therefore, this invention can unify and correlate cloud-borne resource risks, core network interface call risks, and vulnerability impact paths in cloud-based 5G core networks, solving the problems of isolated detection results, unclear impact paths, and inaccurate high-risk vulnerability location in existing technologies.

[0125] Table 1 Performance Comparison of 5G Core Network Security Vulnerability Detection Methods

[0126] Accuracy rate of security vulnerability location (%) 82.4 88.6 Vulnerability-affected path integrity identification rate (%) 74.8 83.7 Impact of key network elements on identification accuracy (%) 79.5 86.2 Consistency rate of risk level assessment (%) 80.8 86.5 High-risk alarm false alarm rate (%) 18.7 13.4 Composite risk false negative rate (%) 11.6 8.1 Average analysis time (min) for a single security incident 12.8 8.6

[0127] Regarding the accuracy of security vulnerability location, the traditional method achieves 82.4%, while the method of this invention achieves 88.6%. This improvement is due to the fact that traditional methods often rely on vulnerability scan results or security alert records to locate risky objects. When the same security event involves cloud resources, core network elements, and service interfaces simultaneously, the location of the vulnerability can become unclear. This invention first generates a set of core network cloud security objects, and then associates core network element objects, cloud resource objects, service interface objects, and security event objects. This allows the location of security vulnerabilities to be pinpointed to specific cloud resources, core network elements, or service interfaces, resulting in a location result closer to the actual affected object.

[0128] Regarding the completeness of vulnerability impact path identification, traditional methods achieve 74.8%, while the method of this invention achieves 83.7%. Traditional methods can typically identify individual vulnerabilities or single alerts, but lack the ability to continuously express whether a vulnerability affects core network elements along the cloud resource bearer path or continues to affect other core network elements along the network element service call path. This invention constructs a core network-cloud network association chain, processing the cloud resource bearer path and the network element service call path in the same link. Based on the core network-cloud network association chain with risk marking, it constructs a core network-cloud security heterogeneous graph, enabling the vulnerability impact path to be traced along the resource bearer edge, service call edge, and risk-marked edge, thus improving path completeness.

[0129] Regarding the accuracy of identifying the impact on critical network elements, the traditional method achieves 79.5%, while the method of this invention achieves 86.2%. This improvement mainly comes from the identification of the position of core network element nodes in the network element service call path. Traditional methods often only determine the scope of impact based on alarm level or vulnerability severity, while this invention combines the connection position of risk-marked edges, the position of core network element nodes in the call path, and whether the core network element node is connected to multiple network element service call paths to determine whether a security event affects critical network elements.

[0130] Regarding the consistency rate of risk level determination, the traditional method achieves 80.8%, while the method of this invention achieves 86.5%. Traditional methods typically rely on vulnerability database levels, scanning tool scores, or alert rules, which fail to adequately reflect the actual impact of vulnerabilities in the cloud-based 5G core network. This invention, when determining the risk level, combines the connection length of the vulnerability's impact path, the number of affected core network element nodes, and the impact status of key network elements. This ensures that the risk level reflects not only the vulnerability itself but also its propagation within cloud resource carrying relationships and core network service call relationships, thus achieving higher consistency with manual review results.

[0131] Regarding the false positive rate of high-risk alerts, the traditional method has a false positive rate of 18.7%, while the method of this invention reduces it to 13.4%. The reason for this reduction is that this invention does not directly classify vulnerability scan results or interface anomaly records as high-risk. Instead, it further identifies the reachability of attack entry points, the fulfillment of permissions, the exposure of services, and the impact on critical network elements. For security events that generate alerts but do not result in valid access, fail to meet permission conditions, or do not affect critical network elements, this invention can reduce their risk level and mitigate the problem of inflated high-risk alert levels.

[0132] Regarding the false negative rate of composite risks, the traditional method has a false negative rate of 11.6%, while the method of this invention reduces it to 8.1%. Traditional methods tend to handle cloud resource risks and core network interface call risks separately, leading to the fragmentation of composite risks involving cloud resources, service interfaces, and core network elements. This invention marks cloud resource risks and core network interface call risks onto the core network-cloud network association chain and expresses the connection relationships between different objects through a core network-cloud security heterogeneity graph, making composite risks across cloud resources, interfaces, and network elements easier to identify.

[0133] Regarding the average analysis time for a single security incident, the traditional method takes 12.8 minutes, while the method of this invention takes only 8.6 minutes. This change mainly stems from the improvement in the way the detection results are presented. The 5G core network security vulnerability detection results generated by this invention simultaneously include the location of the security vulnerability, the path of its impact, and the risk level. Security personnel can directly view the cloud bearer resource nodes, core network element nodes, service interface nodes, and related paths connected to the security incident based on the detection results, eliminating the need for repeated comparisons between the cloud resource management platform, core network management system, log auditing system, and vulnerability scanning system, thus reducing the analysis time.

[0134] The above are merely preferred embodiments of the present invention, but the scope of protection of the present invention is not limited thereto. Any equivalent substitutions or modifications made by those skilled in the art within the scope of the technology disclosed in the present invention, based on the technical solution and inventive concept of the present invention, should be covered within the scope of protection of the present invention.

Claims

1. A method for detecting security vulnerabilities in 5G core networks based on cloud security, characterized in that, Includes the following steps: Collect and standardize the associated data of 5G core network security detection deployed in the cloud, and generate a basic dataset for 5G core network security detection. Based on the 5G core network security detection basic dataset, core network elements, cloud bearer resources, service interfaces and security events are identified, and a core network cloud security object set is generated. Organize the deployment and carrying status between core network elements and cloud carrying resources, as well as the service call status between core network elements, and construct a core network-cloud-network association chain that includes cloud resource carrying paths and network element service call paths; Based on the core network cloud network association chain, cloud bearer resource risks and core network interface call risks are detected. The detected risks are marked to the cloud resource bearer path, core network element and network element service call path, respectively, and a core network cloud network association chain with risk marking is generated. Based on the core network-cloud network interconnection chain with risk labels, construct a core network-cloud security heterogeneous graph; Based on the heterogeneous graph of core network cloud security, the attack entry point reachability status, permission satisfaction status, service exposure status, and key network element impact status are identified to generate a set of exploitable vulnerability conditions. Based on the set of exploitable conditions, path constraint propagation identification is performed to determine the location of security vulnerabilities, the path of vulnerability impact, and the risk level, thereby generating 5G core network security vulnerability detection results.

2. The 5G core network security vulnerability detection method based on cloud security according to claim 1, characterized in that, The 5G core network security detection associated data includes core network element deployment data, cloud bearer resource status data, service interface configuration data, network element call logs, access permission data, security alarm data, and vulnerability scanning data. The standardization processing includes data format unification, timestamp alignment, object identification unification, call direction marking, deployment attribution marking, risk type marking, duplicate record merging, abnormal record removal, and missing field completion.

3. The 5G core network security vulnerability detection method based on cloud security according to claim 1, characterized in that, The generation of the core network cloud security object set includes: Using the object identifiers in the 5G core network security detection basic dataset as indexes, the core network element deployment data is merged by network element name, network element instance identifier and running status to generate core network element objects; The cloud bearer resource status data is merged according to resource identifier and bearer location to generate cloud bearer resource objects; The service interface configuration data is matched with the network element call logs according to the interface identifier and call direction to generate a service interface object; Security alert data and vulnerability scan data are merged according to risk type, occurrence time, and affected objects to generate security event objects; The core network element objects, cloud bearer resource objects, service interface objects, and security event objects are associated based on object identifiers to generate a core network cloud security object set.

4. The 5G core network security vulnerability detection method based on cloud security according to claim 1, characterized in that, The construction of the core network-cloud-network interconnection chain includes: Based on the core network element objects and cloud bearer resource objects in the core network cloud security object set, a matching record of network element resources is generated by matching according to object identifier, deployment ownership mark and bearer location; The core network element objects, cloud bearer resource objects, and deployment bearer status in the network element resource matching record are associated and organized to generate cloud resource bearer paths; Based on the core network element objects and service interface objects in the core network cloud security object set, a matching record for the network element is generated by matching according to the interface identifier, the network element to which the interface belongs, and the calling direction. The network element interface matching records are associated and organized to generate network element service call paths by associating and organizing the initiating network element, receiving network element, service interface object and service call status. Connect the cloud resource carrying path and the network element service calling path according to the same core network element object to build a core network cloud network association chain.

5. The 5G core network security vulnerability detection method based on cloud security according to claim 1, characterized in that, The generation of the core network-cloud-network interconnection chain with risk markers includes: Based on the cloud resource bearing path in the core network cloud network association chain, verify the running status, access permission status and service exposure status of cloud bearing resource objects, and generate cloud bearing resource risks; Based on the deployment and carrying status in the cloud resource carrying path, the cloud carrying resource risk is marked to the cloud carrying resource object and the core network element object connected to it; Based on the network element service call path in the core network cloud network association chain, verify the call direction of the service interface object, the current access status of the interface and the service call status, and generate core network interface call risks. Based on the call direction in the network element service call path, the core network interface call risk is marked to the service interface object and the core network element object it is connected to; The cloud resource bearer path and the network element service call path that have completed risk marking are written into the core network cloud-network association chain to generate a core network cloud-network association chain with risk marking.

6. The 5G core network security vulnerability detection method based on cloud security according to claim 1, characterized in that, The construction of the core network cloud security heterogeneous graph includes: Based on the cloud bearer resource object, core network element object, service interface object, and security event object in the core network cloud-network association chain with risk labeling, cloud bearer resource nodes, core network element nodes, service interface nodes, and security event nodes are generated respectively. Connect cloud resource nodes and core network element nodes according to the cloud resource carrying path to generate resource carrying edges; Connect the core network element node, service interface node and core network element node corresponding to the calling network element and the calling receiving network element according to the network element service call path to generate service call edge; Based on the marked positions of cloud bearer resource risks and core network interface call risks, security event nodes are connected to the corresponding cloud bearer resource nodes, core network element nodes, and service interface nodes to generate risk-marked edges; The cloud-borne resource nodes, core network element nodes, service interface nodes, security event nodes, resource-borne edges, service call edges, and risk-marking edges are encapsulated into a graph structure to generate a core network cloud security heterogeneous graph.

7. The 5G core network security vulnerability detection method based on cloud security according to claim 1, characterized in that, The generation of the exploitable condition set includes: Using the security event nodes in the core network cloud security heterogeneous graph as indexes, organize the cloud bearer resource nodes, core network element nodes, service interface nodes and risk marker edges connected to the security event nodes to generate security event association records; Based on the risk marker edge, service call edge, and call direction in the security event association record, determine whether the security event node can be reached by external access or internal lateral access, and generate the attack entry point reachability status; Based on the access permission status in the security event association record and the deployment ownership mark of the core network element node, determine the permission satisfaction status of the associated object of the security event node; Based on the current access status, service exposure status, and service call edge of the service interface node, determine the service exposure status of the interface associated with the security event node; The impact status of key network elements is determined based on the location of core network element nodes in the network element service call path and the connection position of risk-marked edges. The attack entry point reachability status, permission fulfillment status, service exposure status, and critical network element impact status are written into the same security event node to generate a set of exploitable vulnerability conditions.

8. The 5G core network security vulnerability detection method based on cloud security according to claim 1, characterized in that, The generation of the 5G core network security vulnerability detection results includes: Starting with the security event node in the vulnerability exploitability set, check the attack entry point reachability status, permission satisfaction status, service exposure status, and critical network element impact status to generate a propagable security event. Risky connection nodes are identified based on risk-marked edges of propagable security event connections. The path propagation starting point is determined according to the reachability status of the attack entry point, the type of risky connection node, and the call direction of the service call edge. Propagation matching is performed along the resource carrying edge and the service call edge according to the carrying direction and the call direction. Connections that meet the requirements of attack entry point reachability, permission satisfaction, service exposure reachability, and critical network elements being affected are retained to generate vulnerability impact paths. The location of the security vulnerability is determined based on the connection positions of security event nodes, cloud bearer resource nodes, core network element nodes, and service interface nodes in the vulnerability impact path; The risk level is determined based on the connection length of the vulnerability's impact path, the number of affected core network element nodes, and the impact status of critical network elements. By associating the location of security vulnerabilities, the path of their impact, and their risk level, the detection results for 5G core network security vulnerabilities are generated.