DOI: 10.3390/telecom7040094 ISSN: 2673-4001

AI-Driven Forensic Analysis and Threat Detection for Open RAN and 5G Core Vulnerabilities: An Experimental Study with srsRAN and Open5GS

Akhmet Tussupov, Yedil Nurakhov, Danil Lebedev, Madi Shayakhmetov, Leila Rzayeva, Ulykbek Shambulov, Ibraheem Shayea

(1) Background: The disaggregated and software-defined nature of fifth-generation (5G) core networks and the Open Radio Access Network (O-RAN) architecture increase the attack surface and produce large volumes of heterogeneous evidence that must be analyzed in real time to support incident reconstruction. Open-source 5G stacks (including Open5GS and srsRAN) have become reference platforms in the literature, yet recent research, such as the RANsacked study that reported 119 vulnerabilities and 97 unique CVEs across multiple LTE/5G implementations, have highlighted the pressing need for AI-based detection and forensic capabilities specific to these stacks. (2) Methods: We introduce an experimental framework consisting of a reproducible srsRAN+Open5GS testbed and an AI-driven forensic and detection pipeline. The pipeline receives control-plane (NAS, NGAP, F1AP) and Service-Based Interface (SBI) traffic, extracts protocol- and statistically grounded features and classifies traffic into seven attack types using a hybrid CNN–LSTM model. Integrity-protected and timeline-correlated forensic artifacts (PCAP, logs, memory dumps) assist in reconstructing an incident. (3) Results: The proposed hybrid model achieves a macro F1-score of 0.972 and an AUC-ROC of 0.995 (5-fold CV) and degrades gracefully under load. (4) Conclusions: We show that AI-based detection can be coupled with a scientifically sound evidence chain in open-source 5G stacks deployed as disaggregated mobile networks.

More from our Archive