ORCA - An Automated Threat Analysis Pipeline for O-RAN Continuous Development
Felix Klement, Alessandro Brighente, Michele Polese, Mauro Conti, Stefan Katzenbeisser

TL;DR
This paper introduces ORCA, an automated NLP-based threat analysis pipeline designed for continuous security assessment in O-RAN, reducing manual effort and increasing consistency in vulnerability evaluation.
Contribution
It presents the first automated, iterative threat assessment framework for O-RAN that maps vulnerabilities to threat lists and provides quantitative threat scores.
Findings
Effective integration into automated testing pipelines
Reduces manual effort and bias in threat analysis
Provides reliable threat scores for system components
Abstract
The Open-Radio Access Network (O-RAN) integrates numerous software components in a cloud-like deployment, opening the radio access network to previously unconsidered security threats. With the ever-evolving threat landscape, integrating security practices through a DevSecOps approach is essential for fast and secure releases. Current vulnerability assessment practices often rely on manual, labor-intensive, and subjective investigations, leading to inconsistencies in the threat analysis. To mitigate these issues, we establish an automated pipeline that leverages Natural Language Processing (NLP) to minimize human intervention and associated biases. By mapping real-world vulnerabilities to predefined threat lists with a standardized input format, our approach is the first to enable iterative, quantitative, and efficient assessments, generating reliable threat scores for both individual…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInformation and Cyber Security · Software-Defined Networks and 5G · Network Security and Intrusion Detection
