Core Attacks: 5g core security, sba architecture vulnerabilities, nfv security research
Core network security research targeting 5G Service Based Architecture (SBA), including NFV/SDN bypasses, NF hijacking, and core signaling exploits.
Core network attacks target the 5G Service Based Architecture: rogue NF registration and NRF OAuth2 token abuse, SEPP N32 roaming downgrade, OAuth2 token manipulation, and lateral movement across AMF/SMF/UPF/UDM via REST APIs.
- 5G SBA exposes REST/HTTP2 APIs across network functions.
- NRF token abuse enables NF impersonation and data exfiltration.
- SEPP N32 downgrades expose roaming traffic in plaintext.
The 5G Standalone (SA) core adopts a Service-Based Architecture (SBA) where Network Functions communicate via HTTP/2 REST APIs over a flat internal service mesh. This cloud-native design brings familiar web-application attack classes — IDOR, API abuse, authentication bypass, JWT token manipulation — directly into the telecommunications domain for the first time.
The Network Repository Function (NRF) serves as the service discovery registry for all core NFs. Compromise of NRF trust — through rogue NF registration or OAuth2 token leakage — enables adversaries to intercept inter-function traffic, inject manipulated responses, or disrupt core service availability across the entire deployment. The AMF, SMF, and UPF are the highest-value targets: they manage subscriber registration, session establishment, and all user-plane traffic forwarding respectively. The NWDAF (Network Data Analytics Function) represents an emerging research frontier, as its analytics outputs can be manipulated to influence load-balancing and handover decisions.
Containerized 5G core deployments on Kubernetes introduce container escape paths, workload identity misconfigurations, and network policy gaps that enable lateral movement across network functions within the same cluster. Research in this domain bridges cloud-native security and telecommunications protocol knowledge — a combination that defenders and attackers alike are only beginning to master.
Defense standards for the 5G core include 3GPP TS 33.501, 3GPP TS 33.117, and ENISA's "ENISA Threat Landscape for 5G Networks" report. Security controls recommended for SBA deployments include NF mutual TLS (mTLS) with certificate pinning, OAuth2 token scope restriction per 3GPP TS 33.501, and continuous behavioral monitoring of NF-to-NF API call patterns to detect anomalous inter-function communication.
:: KEY THREAT VECTORS
:: INTELLIGENCE FEED














:: RELATED RESOURCES
READY TO MASTER CORE ATTACKS?
Access hands-on simulation environments, protocol fuzzers, and specialized labs mapping specifically to core attacks vulnerabilities.