5g vulnerability intelligent fuzzing method based on protocol analysis
Patent Information
- Application Number
- CN202611134868.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-29
- Publication Date
- 2026-09-29
AI Technical Summary
[0003]本发明目的在于提供一种基于协议解析的5G漏洞智能模糊测试方法及系统,用于解决当前5G网络信息安全领域中无法主动、动态地遍历5G协议复杂的交互参数和状态转移路径、无法主动发现未知漏洞和深层逻辑缺陷的问题
[0011]本发明优点在于提出了一种主动的、智能的5G核心网协议模糊测试方法,能够对5G核心网协议进行深度解析与状态建模,动态生成和注入海量变异测试用例,有效识别5G网元设备实现与3GPP协议标准之间的偏差,补齐从“标准协议”到“现网运行”之间的安全验证环节;实现对未知漏洞的高效、深度挖掘;漏洞智能发现后,能够快速联动控制面、用户面与管理面,形成协同的主动防御响应闭环,提升5G网络的实战化安全防护水平。
Smart Images

Figure CN122846128A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network information security technology, and is particularly applicable to a smart fuzz testing method for 5G vulnerabilities based on protocol parsing. Background Technology
[0002] 5G networks have been deeply integrated into key areas such as industrial control, energy dispatch, and government private networks. As a critical information infrastructure, the security of 5G networks is of paramount importance. Currently, security audits of 5G core network protocols (such as PFCP, NAS, NGAP, GTP-U, etc.) mainly rely on experts manually analyzing predefined rules and traditional automated testing tools (such as pattern matching scanning based on known vulnerability signature libraries). These methods suffer from several drawbacks: a narrow detection range, difficulty in discovering new vulnerabilities or zero-day vulnerabilities arising from complex interactions and state dependencies in 5G core protocols; a superficial understanding of 5G core protocols such as PFCP, NAS, and NGAP, lacking in-depth modeling of protocol state machines and dynamic interaction simulation capabilities, thus failing to effectively trigger deep-seated logical defects; a lack of proactive discovery capabilities to actively generate abnormal test inputs and dynamically detect unknown security vulnerabilities in real large / private network environments; and an inability to form a closed-loop, interconnected protection system from threat discovery to policy issuance and rapid isolation. Summary of the Invention
[0003] The purpose of this invention is to provide a 5G vulnerability intelligent fuzz testing method and system based on protocol parsing, which can solve the problem in the current field of 5G network information security that it is impossible to actively and dynamically traverse the complex interaction parameters and state transition paths of the 5G protocol, and to actively discover unknown vulnerabilities and deep logical defects.
[0004] To achieve the above objectives, the intelligent fuzz testing method for 5G vulnerabilities based on protocol parsing described in this invention includes the following steps: S1, captures or imports target network element device protocol traffic and device information in real time; S2 performs syntax and semantic analysis on the captured protocol data packets, parsing the meaning of fields, constraints, and interaction logic; S3, based on the parsing results of step S2, constructs a protocol state machine model covering 5G protocol interaction scenarios; S4, based on the protocol state machine model, adopts a syntax and semantic awareness mutation strategy to automatically generate test cases that can traverse the complex parameters and state combinations of the 5G protocol. S5 will inject the generated test cases into the protocol interaction process of the target network element through 5G test instruments or simulators to dynamically simulate the attack surface. S6 monitors the target network element's response status, log output, and resource consumption to test cases in real time, and identifies suspicious behaviors; S7 performs in-depth analysis of suspicious behavior to verify whether it constitutes an exploitable vulnerability, and conducts root cause analysis and proof of concept. S8 automatically generates temporary or long-term defense strategies based on the characteristics of vulnerabilities verified as exploitable. Through standardized interfaces, the defense strategies are pushed in real time to the management plane, control plane, and third-party security protection devices of the 5G network.
[0005] Furthermore, it also includes using the test results of test cases and the characteristics of exploitable vulnerabilities as optimization factors to construct the protocol state machine model and generate test cases.
[0006] Furthermore, it supports PFCP, NAS, NGAP, and GTP-U protocols for AMF, UPF, and SMF target network element devices.
[0007] Furthermore, mutation strategies include field boundary value testing, type obfuscation, and invalid value insertion.
[0008] Furthermore, suspicious behaviors include crashes, assertion failures, abnormal logs, memory leaks, and abnormal protocol states.
[0009] Furthermore, the defense strategy includes policy control session modification, firewall rule updates, and security policy hardening recommendations.
[0010] This invention also provides a 5G vulnerability intelligent fuzz testing system based on protocol parsing, which implements the 5G vulnerability intelligent fuzz testing method based on protocol parsing, including a data capture and perception module, a protocol deep parsing module, a protocol state machine modeling engine, an intelligent test case generation engine, a fuzz test executor, an abnormal behavior monitoring module, a vulnerability verification module, and a policy generation and distribution module; The data capture and perception module is used to capture or import target network element protocol traffic and device information in real time; the protocol deep parsing module is used to perform syntax and semantic analysis on the captured protocol data packets, parsing the meaning of fields, constraints, and interaction logic; the protocol state machine modeling engine is used to construct a protocol state machine model covering 5G protocol interaction scenarios based on the parsing results; the intelligent test case generation engine is used to automatically generate test cases that can traverse complex parameters and state combinations of 5G protocols based on the protocol state machine model and using a syntax and semantic awareness mutation strategy; the fuzz test executor is used to process the generated test cases through... A 5G test instrument or simulator is injected into the protocol interaction process of the target network element to dynamically simulate the attack surface; the abnormal behavior monitoring module is used to monitor the response status, log output, and resource consumption of the target network element to test cases in real time and identify suspicious behaviors; the vulnerability verification module is used to perform in-depth analysis of suspicious behaviors to verify whether they constitute exploitable vulnerabilities and to perform root cause analysis and proof of concept; the policy generation and distribution module is used to automatically generate temporary or long-term defense policies based on the characteristics of verified exploitable vulnerabilities, and push the defense policies to the management plane, control plane, and third-party security protection equipment of the 5G network in real time through standardized interfaces.
[0011] The advantages of this invention lie in proposing a proactive and intelligent fuzz testing method for 5G core network protocols. This method can perform in-depth analysis and state modeling of 5G core network protocols, dynamically generate and inject massive amounts of variant test cases, effectively identify deviations between 5G network element implementations and 3GPP protocol standards, and fill the security verification gap between "standard protocols" and "live network operation." It also enables efficient and in-depth mining of unknown vulnerabilities. After intelligent vulnerability discovery, it can quickly link the control plane, user plane, and management plane to form a collaborative proactive defense response closed loop, thereby improving the practical security protection level of 5G networks. Attached Figure Description
[0012] Figure 1 This is a flowchart of the intelligent fuzz testing method for 5G vulnerabilities based on protocol parsing described in this invention. Detailed Implementation
[0013] The technical solutions in the embodiments of the present invention will be clearly and completely described below. Obviously, the described embodiments are only a part of the embodiments of the present invention, and not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of the present invention.
[0014] The present invention describes a 5G vulnerability intelligent fuzzing testing method based on protocol parsing, such as... Figure 1 As shown, it includes the following steps: S1 can capture or import protocol traffic and device information of target network elements such as AMF, UPF, and SMF in real time in 5G large network or private network environments, including PFCP, NAS, NGAP, and GTP-U.
[0015] S2 performs syntax and semantic analysis on the captured protocol data packets, parsing the meaning of fields, constraints, and interaction logic.
[0016] S3, based on the analysis results of step S2, constructs an accurate protocol state machine model that covers 5G protocol interaction scenarios.
[0017] S4, based on the protocol state machine model, employs syntax and semantic awareness mutation strategies, such as field boundary value testing, type obfuscation, and invalid value insertion, to automatically generate a large number of test cases that can traverse the complex parameters and state combinations of the 5G protocol.
[0018] Protocol state machine models not only understand the static format (syntax) of protocol messages, but also gain a deeper understanding of the dynamic interaction logic and state transition rules between various entities in the protocol—that is, semantic understanding. This enables vulnerability testing to purposefully and with high coverage (target >95%) generate and trigger test cases involving abnormal timing, illegal state transitions, and inconsistent contexts. This allows for systematic and penetrating detection of deep logical flaws, achieving a qualitative leap in vulnerability discovery capabilities from simply enabling communication to ensuring secure communication.
[0019] S5 precisely injects the generated test cases into the protocol interaction process of the target network element through 5G test instruments or simulators, dynamically simulating the attack surface. By deeply analyzing the 5G core network protocol, modeling the state machine, and linking with 5G test instrument tools to generate and inject massive amounts of random or mutated abnormal data, it completely abandons the passive mode that relies on existing knowledge.
[0020] S6 monitors the target network element's response status, log output, and resource consumption to test cases in real time, identifying suspicious behaviors such as crashes, assertion failures, abnormal logs, memory leaks, and abnormal protocol states. These behaviors can serve as points for locating potential vulnerabilities.
[0021] S7 performs in-depth analysis of suspicious behavior to verify whether it constitutes an exploitable vulnerability, and conducts root cause analysis and proof of concept.
[0022] S8 automatically generates temporary or long-term defense strategies based on the characteristics of vulnerabilities verified as exploitable, such as policy control session modifications, firewall rule updates, and security policy hardening suggestions. Through standardized interfaces, the defense strategies are pushed in real time to the management plane, control plane, and third-party security protection devices of the 5G network, realizing a closed loop of vulnerability detection-verification-defense.
[0023] The test results of test cases and the characteristics of exploitable vulnerabilities can also be used as optimization factors to build protocol state machine models and generate test cases, continuously optimize test strategies and protocol model coverage, and form a self-evolving intelligent testing system.
[0024] In traditional vulnerability monitoring models, security tools or testing platforms are often isolated from network operation systems. After a vulnerability is discovered, manual intervention is required for analysis and verification, followed by coordination among various functional departments to manually adjust network policies. This results in a lengthy response chain and poor real-time performance. This invention deeply integrates intelligent vulnerability discovery with a security defense system. When a potential vulnerability is discovered in a production / pre-production environment, it can quickly perform hazard verification and path analysis, and automatically and in real-time generate defense strategies. These strategies are proactively pushed to the management plane, control plane, and third-party security protection devices of the 5G network in real time. This constructs a collaborative 5G vulnerability real-time defense system that integrates the control plane, user plane, and management plane, achieving closed-loop security and realizing a systemic transformation from passive single-point diagnosis to proactive collaborative defense, thereby improving real-time protection and emergency response levels.
[0025] The following example, using the testing of a vendor's 5G core network user plane functional element (UPF), illustrates the entire process of the present invention's intelligent fuzz testing method for 5G vulnerabilities based on protocol parsing.
[0026] First, real traffic related to the target UPF is captured through the switch's mirror port, particularly PFCP signaling packets on the N4 interface and GTP-U packets on the N3 interface. The captured PFCP packets are decapsulated to identify key Interfaces (IEs) such as PDU Session ID, user plane IP address, and QoS rules (QER), and the legal values and structural dependencies between IEs are analyzed. Based on the parsing results, a simplified PFCP session state model is automatically constructed, defining core states and state transition paths. Based on the protocol state machine model, a syntax- and semantic-aware mutation strategy is used to automatically generate a large number of test cases capable of traversing complex protocol parameters and state combinations. These generated test cases are precisely injected into the N4 interface of the UPF under test using 5G testing instruments to dynamically simulate the attack surface. The response status, log output, and resource consumption of the UPF under test when processing fuzzy test cases are monitored in real time, identifying suspicious behaviors such as crashes, assertion failures, abnormal logs, memory leaks, and abnormal protocol states as potential vulnerability locations. In-depth analysis is performed on detected abnormal behaviors to verify whether they constitute exploitable vulnerabilities, and root cause analysis and Proof-of-Concept (PoC) verification are completed. Based on the verified vulnerability characteristics, temporary or long-term mitigation strategies are automatically generated, such as policy control session modifications, firewall rule updates, and security hardening recommendations. Defense strategies are pushed in real-time to the 5G network's management plane, control plane, and third-party security devices through standardized interfaces, achieving a closed loop of "detection-verification-defense." Feedback on test results and vulnerability distribution characteristics can be used to continuously optimize test strategies and protocol model coverage, forming a self-evolving intelligent testing system.
[0027] This invention also provides a 5G vulnerability intelligent fuzz testing system based on protocol parsing, which implements the 5G vulnerability intelligent fuzz testing method based on protocol parsing, including a data capture and perception module, a protocol deep parsing module, a protocol state machine modeling engine, an intelligent test case generation engine, a fuzz test executor, an abnormal behavior monitoring module, a vulnerability verification module, and a policy generation and distribution module; The data capture and perception module is used to capture or import target network element protocol traffic and device information in real time; the protocol deep parsing module is used to perform syntax and semantic analysis on the captured protocol data packets, parsing the meaning of fields, constraints, and interaction logic; the protocol state machine modeling engine is used to construct a protocol state machine model covering 5G protocol interaction scenarios based on the parsing results; the intelligent test case generation engine is used to automatically generate test cases that can traverse complex parameters and state combinations of 5G protocols based on the protocol state machine model and using a syntax and semantic awareness mutation strategy; the fuzz test executor is used to process the generated test cases through... A 5G test instrument or simulator is injected into the protocol interaction process of the target network element to dynamically simulate the attack surface; the abnormal behavior monitoring module is used to monitor the response status, log output, and resource consumption of the target network element to test cases in real time and identify suspicious behaviors; the vulnerability verification module is used to perform in-depth analysis of suspicious behaviors to verify whether they constitute exploitable vulnerabilities and to perform root cause analysis and proof of concept; the policy generation and distribution module is used to automatically generate temporary or long-term defense policies based on the characteristics of verified exploitable vulnerabilities, and push the defense policies to the management plane, control plane, and third-party security protection equipment of the 5G network in real time through standardized interfaces.
[0028] This invention, as a standardized and scalable intelligent fuzz testing and verification tool for 5G vulnerabilities, can seamlessly adapt to at least three types of 5G core network elements, support routine, non-destructive security assessments in live networks and private networks, and provide exportable standardized security services for operators and vertical industries (government, power, industrial manufacturing), helping customers verify their network resilience and equipment reliability.
Claims
1. A 5G vulnerability intelligent fuzzing method based on protocol parsing, characterized in that, Includes the following steps: S1, captures or imports target network element device protocol traffic and device information in real time; S2 performs syntax and semantic analysis on the captured protocol data packets, parsing the meaning of fields, constraints, and interaction logic; S3, based on the parsing results of step S2, constructs a protocol state machine model covering 5G protocol interaction scenarios; S4, based on the protocol state machine model, adopts a syntax and semantic awareness mutation strategy to automatically generate test cases that can traverse the complex parameters and state combinations of the 5G protocol. S5 will inject the generated test cases into the protocol interaction process of the target network element through 5G test instruments or simulators to dynamically simulate the attack surface. S6 monitors the target network element's response status, log output, and resource consumption to test cases in real time, and identifies suspicious behaviors; S7 performs in-depth analysis of suspicious behavior to verify whether it constitutes an exploitable vulnerability, and conducts root cause analysis and proof of concept. S8 automatically generates temporary or long-term defense strategies based on the characteristics of vulnerabilities verified as exploitable. Through standardized interfaces, the defense strategies are pushed in real time to the management plane, control plane, and third-party security protection devices of the 5G network.
2. The intelligent fuzz testing method for 5G vulnerabilities based on protocol parsing as described in claim 1, characterized in that: It also includes using the test results of test cases and the characteristics of exploitable vulnerabilities as optimization factors to build the protocol state machine model and generate test cases.
3. The intelligent fuzz testing method for 5G vulnerabilities based on protocol parsing as described in claim 1, characterized in that: Supports PFCP, NAS, NGAP, and GTP-U protocols for AMF, UPF, and SMF target network element devices.
4. The intelligent fuzz testing method for 5G vulnerabilities based on protocol parsing as described in claim 1, characterized in that: Mutation strategies include field boundary value testing, type obfuscation, and invalid value insertion.
5. The intelligent fuzz testing method for 5G vulnerabilities based on protocol parsing according to claim 1, characterized in that: Suspicious behaviors include crashes, assertion failures, abnormal logs, memory leaks, and abnormal protocol states.
6. The intelligent fuzz testing method for 5G vulnerabilities based on protocol parsing according to claim 1, characterized in that: Defense strategies include policy control session modifications, firewall rule updates, and security policy hardening recommendations.
7. A 5G vulnerability intelligent fuzzing system based on protocol parsing, implementing the 5G vulnerability intelligent fuzzing method based on protocol parsing as described in claims 1-6, characterized in that: It includes a data capture and perception module, a deep protocol parsing module, a protocol state machine modeling engine, an intelligent test case generation engine, a fuzz test executor, an abnormal behavior monitoring module, a vulnerability verification module, and a policy generation and distribution module; The data capture and sensing module is used to capture or import target network element device protocol traffic and device information in real time; the protocol deep parsing module is used to perform syntax and semantic analysis on the captured protocol data packets, and parse the meaning of fields, constraint relationships and interaction logic; The protocol state machine modeling engine is used to construct a protocol state machine model covering 5G protocol interaction scenarios based on the parsing results; the intelligent test case generation engine is used to automatically generate test cases that can traverse complex parameters and state combinations of the 5G protocol based on the protocol state machine model and using a syntax and semantic awareness mutation strategy. The fuzz test executor is used to inject the generated test cases into the protocol interaction process of the target network element through a 5G test instrument or simulator to dynamically simulate the attack surface; the abnormal behavior monitoring module is used to monitor the response status, log output and resource consumption of the target network element to the test cases in real time and identify suspicious behaviors. The vulnerability verification module is used to perform in-depth analysis of suspicious behaviors, verify whether they constitute exploitable vulnerabilities, and perform root cause analysis and proof of concept. The policy generation and distribution module is used to automatically generate temporary or long-term defense policies based on the characteristics of vulnerabilities verified as exploitable, and push the defense policies to the management plane, control plane and third-party security protection equipment of the 5G network in real time through standardized interfaces.