Security Analysis of 5G Network Products

Author
Regulations

CRA

NIS 2

A 5G telecom network equipment OEM needed to assess the security of critical 5G network products and functions, and understand whether the implemented security controls were sufficient to support the expected assurance level under emerging EU regulatory pressure. These functions sit at the core of any 5G network — a vulnerability in any one of them can expose subscriber data, network availability, or lawful-intercept and billing integrity. That is why manufacturers increasingly need evidence-based security assessments rather than compliance checklists alone.

Definition

What are gNB, UDM, AMF, SMF and UPF?

These elements form the basic building blocks of the 5G network architecture, covering radio access, control-plane signaling, and user-plane data.

Client / Project Need

Objectives & drivers

Deliver an evidence-based security assessment of the manufacturer’s 5G network functions, confirming the assurance level, identifying priority improvements, and preparing the ground for GSMA NESAS, future EU 5G cybersecurity certification, and Cyber Resilience Act (CRA) / NIS 2 Directive compliance. The manufacturer needed more than a compliance checklist — it needed a defensible, evidence-based account of how its products would withstand realistic attacks, that could be presented to operators, evaluators, and regulators alike.

Challenge

Key hurdles

Translating telecom security requirements into concrete attack scenarios, vulnerabilities, and risk conclusions across diverse 5G assets, exposed interfaces, deployment models, and security controls, while staying aligned with recognised standards and assurance methodologies. The difficulty was compounded by the breadth of the attack surface: radio interfaces, inter-function signalling (N-interfaces), cloud-native deployment models, and virtualised network functions each carry different threat models, and no single existing standard covers all of them end-to-end. The team needed a methodology that could unify 3GPP and O-RAN telecom-specific requirements with more general security assurance frameworks like Common Criteria and NIST risk assessment.

Approach

What we did

01

Performed a structured security analysis of critical 5G network products and functions to identify applicable threats, vulnerabilities, security requirements and existing controls.

02

Reviewed relevant 5G security requirements and controls, derived realistic attack scenarios and identified associated vulnerabilities.

03

Assessed inherent and residual risks using NIST-based risk-assessment principles.

04

Applied the Common Criteria attack-potential methodology (effort, expertise, access, time, equipment) to characterise potential attackers and rate the difficulty of each attack path.

05

Combined 3GPP, O-RAN, GSMA NESAS, NIST, Common Criteria, and product-specific vulnerability analysis into a single, consistent assessment framework spanning the gNB, UDM, AMF, SMF, and UPF.

Key outcomes

Impact delivered

Lessons learned

What we took away

Security analysis of 5G products should not be limited to checking compliance with requirements — it should demonstrate how security controls actually reduce realistic attack paths and residual risks. A product-specific, risk-based and assurance-oriented approach is essential to support credible security conclusions, product hardening, and preparation for schemes such as GSMA NESAS or future European cybersecurity certification activities. For manufacturers building toward CRA and NIS 2 compliance, starting from concrete attack scenarios on real network functions — rather than a generic control checklist — produces evidence that holds up under regulatory and operator scrutiny alike.

Related materials

Keep exploring

ODSI: A Building-Block Approach to Secure Isolation

Read case study →

2IdO: Securing the Industrial Internet of Things

Read case study →

SECREDAS

SECREDAS: Building Trustworthy Automated Systems Across Critical Industries

Read case study →

Contact us

Request this document

We’ll send you access by email.