Booz Allen recently completed a government-funded “offensive security assessment” of an open radio access network (RAN) system using a newly developed “fuzzing” tool that showed potential security issues with still evolving open RAN architectures and the usefulness of the new testing apparatus.
Joseph Bull, director of the project for Booz Allen, explained that the initiative was based on the need for the ecosystem to have a reliable tool that could help level the security playing field for players in the space. This is especially important for new entrants that might lack the embedded security market knowledge and processes that more established vendors enjoy.
“The challenge with in anything like that is a lot of the smaller companies may not have had the sophistication or the investment to be able to assess their products, and so that's sort of what we came into this is how can we help to identify a threat model to identify what is the attack surface of [open] RAN itself,” Bull said.
Traditional testing methods involve the use of penetration testing, something that Bull noted the project looked to build upon with a more advanced fuzzing tool. This approach had Booz Allen working with Virginia Tech in using government funding from the National Telecommunications and Information Administration (NTIA) Public Wireless Supply Chain Innovation Fund to develop that tool to test potential security issues at the APIs used to connect open RAN components from different vendors.
Bull noted that open RAN protocols themselves are “pretty well defined” but that “how a vendor implements them, there are some nuances.” This lack of concrete methodologies has been an ongoing interoperability challenge for open RAN, and is something that has evolved over the past several years.
The fuzzing tool is based on open-source standards, and, more importantly, allows for fine-tuning based on the attack types being used to test open RAN equipment. Bull explained that this allowed for the tool to provide greater insight into real-world vulnerabilities.
Testing results didn’t surprise Bull, who noted that “I’ve done security for a while, so nothing surprised me” and due to the fuzzing tool’s depth and breadth of capabilities “I was expecting things to break.” As an example, Bull noted that some early testing showed integration to be the sticking point.
“When we're integrating different products from different vendors in this more open environment, that's where we need to really ensure that both sides of it have been tested and they can integrate and implement those,” Bull said of those findings. “I'm hoping – because I care about security – is the optional parameters, and so that is a standard that we should be looking more toward given the environment that we're in today.”
Are vendors looking?
Despite that hope, Bull acknowledged that costs and optionality remain significant challenges toward that goal.
On the cost front, Bull noted that “at the end of the day, you think about a [mobile network operator], it’s all about revenue, and obviously protecting the user data.”
As for optionality, Bull admitted this was a deeper challenge.
“We have a team who runs a carrier-grade lab in our facility, and we do a lot of testing, and, for instance, we might not turn all the security features on so I can better analyze things,” Bull said. “I will tell you, I've talked with others in the field, and sometimes that is also still the case.”
This issue is becoming less of a challenge as security becomes a more important and complex part of the equation and is something that Bull said security teams are pivoting around.
“I think the message is being heard,” Bull said, adding, “I think it's just more of the balance of how much money they're spending on security,” though timing of that spend is also important.
“I think people get it now, that you need to have it integrated upfront and a lot of the things that we're also doing in 5G and in other things is application of zero trust. It can't be done after the fact. You have to work with the vendors. It has to be integrated,” Bull said. “The [open] RAN fuzzing and other applications that we've done are really helping them during the development process, prior to a product being released, that they're helping to fix now,” Bull said. “This is part of their research and development of a new product, and hence, it's awesome to see it's being integrated today.”
Comments