Poster: Towards an Automated Security Testing Framework for Industrial UEs

📅 2025-05-22
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
Industrial 5G user equipment (UE), such as robotic systems, lacks comprehensive, automated security assessment methodologies. Method: This paper proposes the first end-to-end automated security testing framework for industrial 5G UEs. It jointly verifies the correctness of high-layer security protocols (e.g., TLS) and conformance to 3GPP protocol stack specifications, integrating protocol fuzzing, specification-compliance checking, TLS handshake behavior analysis, and a plugin-based extensible engine. Contribution/Results: Unlike fragmented existing approaches, our framework enables integrated, full-stack security validation of industrial UEs. Experimental evaluation demonstrates its effectiveness in identifying diverse protocol implementation flaws and configuration deviations, achieving significantly improved test coverage and execution efficiency. To the best of our knowledge, this work is the first to bridge the critical gap in holistic security evaluation of industrial 5G endpoints.

Technology Category

Application Category

📝 Abstract
With the ongoing adoption of 5G for communication in industrial systems and critical infrastructure, the security of industrial UEs such as 5G-enabled industrial robots becomes an increasingly important topic. Most notably, to meet the stringent security requirements of industrial deployments, industrial UEs not only have to fully comply with the 5G specifications but also implement and use correctly secure communication protocols such as TLS. To ensure the security of industrial UEs, operators of industrial 5G networks rely on security testing before deploying new devices to their production networks. However, currently only isolated tests for individual security aspects of industrial UEs exist, severely hindering comprehensive testing. In this paper, we report on our ongoing efforts to alleviate this situation by creating an automated security testing framework for industrial UEs to comprehensively evaluate their security posture before deployment. With this framework, we aim to provide stakeholders with a fully automated-method to verify that higher-layer security protocols are correctly implemented, while simultaneously ensuring that the UE's protocol stack adheres to 3GPP specifications.
Problem

Research questions and friction points this paper is trying to address.

Ensuring security of 5G-enabled industrial UEs
Automating comprehensive security testing for industrial devices
Verifying correct implementation of higher-layer security protocols
Innovation

Methods, ideas, or system contributions that make the work stand out.

Automated security testing for industrial UEs
Comprehensive evaluation of security protocols
Verification of 3GPP specification compliance
🔎 Similar Papers
No similar papers found.
S
Sotiris Michaelides
Security and Privacy in Industrial Cooperation, RWTH Aachen University, Germany
D
Daniel Eguiguren Chavez
Security and Privacy in Industrial Cooperation, RWTH Aachen University, Germany
Martin Henze
Martin Henze
RWTH Aachen University and Fraunhofer FKIE
Industrial SecurityCyber-physical System SecurityIndustrial Internet of ThingsSmart Grids