TY - JOUR
T1 - CoCo
T2 - A CBOW-Based Framework for Synergistic Vulnerability Detection in Partial and Discontinuous Logs for NextG Communications
AU - Peng, Yifeng
AU - Li, Xinyi
AU - Arya, Sudhanshu
AU - Wang, Ying
N1 - Publisher Copyright:
© 2024 IEEE.
PY - 2024
Y1 - 2024
N2 - With the development of communication technology, protocol design, and infrastructure implementation have become more complex, bringing significant security challenges to 5G and NextG systems. Fuzz testing is widely used to detect system vulnerabilities and the health status under the condition of abnormal input. In this paper, we generate fuzz testing via the Man In The Middle Model (MITM) at various locations of the time sequence in the 5G authentication and authorization process and analyze the communication state transitions, which are recorded in the log files of fuzz testing cases. CoCo introduces a novel CBOW-based framework for synergistic vulnerability detection, addressing the challenge of partial log data and scalability in real-time environments, a significant advancement in the field of NextG communication security. CoCo can be applied to identifying the type of attacks or abnormal inputs from partial system profiling for the impacted behaviors. In particular, we show, for the first time, that by utilizing the CoCo, we can precisely detect the fuzzed layer using only a partial segment of the log file in real-time and identify the root cause of vulnerabilities with high accuracy. The results show that when we get only 40% portion of the entire log file, applying convolutional neural network (CNN) in the machine learning models can reach the Area under Curve (AUC) value of 92%. Furthermore, by strategically combining these segments, we enhanced the efficacy of vulnerability detection, demonstrating a synergistic effect where the combined impact is greater than the sum of individual parts, meanwhile reducing the time complexity by 6%.
AB - With the development of communication technology, protocol design, and infrastructure implementation have become more complex, bringing significant security challenges to 5G and NextG systems. Fuzz testing is widely used to detect system vulnerabilities and the health status under the condition of abnormal input. In this paper, we generate fuzz testing via the Man In The Middle Model (MITM) at various locations of the time sequence in the 5G authentication and authorization process and analyze the communication state transitions, which are recorded in the log files of fuzz testing cases. CoCo introduces a novel CBOW-based framework for synergistic vulnerability detection, addressing the challenge of partial log data and scalability in real-time environments, a significant advancement in the field of NextG communication security. CoCo can be applied to identifying the type of attacks or abnormal inputs from partial system profiling for the impacted behaviors. In particular, we show, for the first time, that by utilizing the CoCo, we can precisely detect the fuzzed layer using only a partial segment of the log file in real-time and identify the root cause of vulnerabilities with high accuracy. The results show that when we get only 40% portion of the entire log file, applying convolutional neural network (CNN) in the machine learning models can reach the Area under Curve (AUC) value of 92%. Furthermore, by strategically combining these segments, we enhanced the efficacy of vulnerability detection, demonstrating a synergistic effect where the combined impact is greater than the sum of individual parts, meanwhile reducing the time complexity by 6%.
KW - CBOW
KW - Machine learning
KW - NextG vulnerability detection
KW - Word2Vec
KW - fuzz testing
UR - https://www.scopus.com/pages/publications/85205784323
UR - https://www.scopus.com/inward/citedby.url?scp=85205784323&partnerID=8YFLogxK
U2 - 10.1109/OJCOMS.2024.3471709
DO - 10.1109/OJCOMS.2024.3471709
M3 - Article
AN - SCOPUS:85205784323
VL - 5
SP - 6381
EP - 6403
JO - IEEE Open Journal of the Communications Society
JF - IEEE Open Journal of the Communications Society
ER -