Towards a Multi-Layer Defence Framework for Securing Near-Real-Time Operations in Open RAN
Hamed Alimohammadi, Samara Mayhoub, Sotiris Chatzimiltis, Mohammad Shojafar, and Muhammad Nasir Mumtaz Bhutta

TL;DR
This paper introduces a multi-layer security framework for near-real-time Open RAN control operations, combining detection modules for message, data, and control logic threats to enhance runtime security with minimal latency impact.
Contribution
It presents a novel multi-layer defence framework with specific detection and mitigation modules tailored for near-RT RIC security in Open RAN environments.
Findings
Effective threat detection with low latency overheads
Framework operates within 80 ms delay for 500 UEs
Demonstrated practical integration on testbed
Abstract
Securing the near-real-time (near-RT) control operations in Open Radio Access Networks (Open RAN) is increasingly critical, yet remains insufficiently addressed, as new runtime threats target the control loop while the system is operational. In this paper, we propose a multi-layer defence framework designed to enhance the security of near-RT RAN Intelligent Controller (RIC) operations. We classify operational-time threats into three categories, message-level, data-level, and control logic-level, and design and implement a dedicated detection and mitigation component for each: a signature-based E2 message inspection module performing structural and semantic validation of signalling exchanges, a telemetry poisoning detector based on temporal anomaly scoring using an LSTM network, and a runtime xApp attestation mechanism based on execution-time hash challenge-response. The framework is…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsSoftware-Defined Networks and 5G · Vehicular Ad Hoc Networks (VANETs) · Smart Grid Security and Resilience
