Vulnerability Analysis of eBPF-enabled Containerized Deployments of 5G Core Networks
Yash Deshpande, Samaresh Bera

TL;DR
This paper investigates security vulnerabilities in eBPF-enabled 5G core network deployments, demonstrating potential exploits and proposing mitigation techniques to enhance security in containerized environments.
Contribution
It provides a detailed vulnerability analysis of eBPF in 5G networks, including attack scenarios, experimental validation, and mitigation strategies.
Findings
Vulnerabilities in eBPF-enabled 5G deployments can be exploited by attackers.
Attack scenarios include tracing, DoS, information theft, and bash injection.
Mitigation techniques can reduce security risks in such deployments.
Abstract
The extended Berkeley Packet Filter (eBPF) is useful for faster packet processing and network monitoring in softwarized deployments. Similarly, softwarized deployments of 5G core network services adopted eBPF to meet the stringent latency and bandwidth requirements of underlying applications. While the existing studies focused on network performance, security concerns over eBPF-enabled platforms are overlooked. In this paper, we study the vulnerability analysis of 5G core network deployments that use eBPF for packet processing and traffic monitoring. In particular, we consider the following aspects: a) tracing, b) denial-of-service (DoS), c) stealing information, and d) bash injection. We present the detailed attack scenarios with step-by-step implementation of containerized and eBPF-enabled 5G network functions using Open5GS. The experiment results show that the aforementioned…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsSoftware-Defined Networks and 5G · Network Traffic and Congestion Control · Advanced Optical Network Technologies
