Network Security

On Going

Overview

Network Security remains a fundamental challenge across both traditional and next-generation communication networks. It encompasses an adversary's ability to seize control of, intercept, or disrupt critical network services, either by exploiting architectural design vulnerabilities or by leveraging implementation gaps in deployed systems. Such adversaries range from individual threat actors to sophisticated, state-sponsored organizations that intend to compromise system integrity, availability, or confidentiality.

Details

The rapid evolution toward 5G networks introduces an expanded attack surface, driven by the proliferation of connected devices, network slicing, and the shift toward software-defined and cloud-native architectures. Unlike legacy systems, 5G's virtualized infrastructure blurs the boundary between cyber and physical security domains. This exposes the networks to a broader class of threats, including hypervisor attacks, API abuse, and cross-slice interference. The heterogeneous nature of 5G deployments further complicates consistent security policy enforcement across the entire network fabric.

Open Radio Access Network (O-RAN) architectures amplify these concerns by disaggregating traditionally closed, vendor-specific hardware into open, interoperable components. While this openness fosters innovation and reduces vendor lock-in, it also introduces new threat vectors at interfaces between key functional units, such as the RAN Intelligent Controller (RIC), the O-DU, and the O-CU. The xApp and rApp ecosystems running on the RIC present particularly novel risks, as third-party applications with privileged access to network intelligence could be weaponized or compromised. Securing these open interfaces demands rigorous mutual authentication, end-to-end encryption, zero-trust access principles, and real-time intrusion detection. Furthermore, countering sophisticated, long-term campaigns like Advanced Persistent Threats (APTs) requires moving beyond traditional passive security toward active defense frameworks that leverage temporal threat analysis and automated deception.

Problem Description
DoS using Fake Base Station Working on L3 and L2 FBS attacks as well as detecting them through threshold-based methods, as well as embedding intelligence via xApps.
Impact Analysis for Attacker and Defender Designing a cost-driven framework to quantify the operational and financial impact of network attacks, while systematically evaluating the corresponding efforts, resources, and countermeasures required by the defender to detect, mitigate, and recover from such threats.
Explainability for Mitigation Automating the strategies for providing timely fixes in the case of attacks.
Detecting and Mitigating Advanced Persistent Threats (APTs) Designing a closed-loop active defense framework to detect and neutralize multi-stage APTs using temporal threat analysis, adaptive trust scoring, and automated network deception.
Members:

Arpit Tripathi, Mohit Patil, Abdulla Ovais

Publications:

A. Tripathi, A. Rajput, A. K. Subudhi, K. Kondepu, A. Thakur and B. R. Tamma, "Denial of Service Attacks Targeting Layer 2 in 5G RAN," 2025 IEEE Future Networks World Forum (FNWF), Bangalore, India, 2025, pp. 1-6, doi: 10.1109/FNWF66845.2025.11317524.

Active Grants

Synergy: Taking openness to the next level in 6G Networks

Department of Science and Technology, Govt. of India

PI: Antony Franklin

Information Security Education Awareness (ISEA) Phase III

MeitY

PI: Antony Franklin

View All Grants →

Other Research Areas