{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,14]],"date-time":"2026-01-14T00:49:53Z","timestamp":1768351793329,"version":"3.49.0"},"publisher-location":"New York, NY, USA","reference-count":60,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,6,19]],"date-time":"2024-06-19T00:00:00Z","timestamp":1718755200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100006374","name":"National Science Foundation","doi-asserted-by":"publisher","award":["CNS-2054911,CNS-2055014,CNS-1933208,23-605"],"award-info":[{"award-number":["CNS-2054911,CNS-2055014,CNS-1933208,23-605"]}],"id":[{"id":"10.13039\/501100006374","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,6,19]]},"DOI":"10.1145\/3626232.3653259","type":"proceedings-article","created":{"date-parts":[[2024,6,10]],"date-time":"2024-06-10T18:20:25Z","timestamp":1718043625000},"page":"43-54","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":2,"title":["Examining Cryptography and Randomness Failures in Open-Source Cellular Cores"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-3399-4027","authenticated-orcid":false,"given":"K. Virgil","family":"English","sequence":"first","affiliation":[{"name":"North Carolina State University, Raleigh, NC, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3315-938X","authenticated-orcid":false,"given":"Nathaniel","family":"Bennett","sequence":"additional","affiliation":[{"name":"University of Florida, Gainesville, Florida, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7907-2327","authenticated-orcid":false,"given":"Seaver","family":"Thorn","sequence":"additional","affiliation":[{"name":"North Carolina State University, Raleigh, NC, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7498-4239","authenticated-orcid":false,"given":"Kevin R. B.","family":"Butler","sequence":"additional","affiliation":[{"name":"University of Florida, Gainesville, Florida, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3043-8092","authenticated-orcid":false,"given":"William","family":"Enck","sequence":"additional","affiliation":[{"name":"Computer Science, North Carolina State University, Raleigh, NC, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7143-5189","authenticated-orcid":false,"given":"Patrick","family":"Traynor","sequence":"additional","affiliation":[{"name":"University of Florida, Gainesville, Florida, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2024,6,19]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"2023. All-in-One. 5G. https:\/\/www.rakwireless.com\/en-us\/5g"},{"key":"e_1_3_2_1_2_1","unstructured":"2023. Firecell. https:\/\/firecell.io\/"},{"key":"e_1_3_2_1_3_1","unstructured":"2023. Magma -- Linux Foundation Project. https:\/\/magmacore.org\/"},{"key":"e_1_3_2_1_4_1","first-page":"102","article-title":"3G security; Security architecture","volume":"33","author":"GPP.","year":"2020","unstructured":"3GPP. 2020. 3G security; Security architecture. Technical Specification (TS) 33.102. https:\/\/portal.3gpp.org\/desktopmodules\/Specifications\/ SpecificationDetails.aspx'specificationId=2262 Version 16.0.0.","journal-title":"Technical Specification (TS)"},{"key":"e_1_3_2_1_5_1","first-page":"105","article-title":"3G security; Security architecture","volume":"33","author":"GPP.","year":"2020","unstructured":"3GPP. 2020. 3G security; Security architecture. Technical Specification (TS) 33.105. https:\/\/portal.3gpp.org\/desktopmodules\/Specifications\/ SpecificationDetails.aspx'specificationId=2264 Version 16.0.0.","journal-title":"Technical Specification (TS)"},{"key":"e_1_3_2_1_6_1","first-page":"501","article-title":"Security architecture and procedures for 5G System (5GS)","volume":"33","author":"GPP.","year":"2020","unstructured":"3GPP. 2020. Security architecture and procedures for 5G System (5GS). Technical Specification (TS) 33.501. https:\/\/portal.3gpp.org\/desktopmodules\/Specifications\/ SpecificationDetails.aspx'specificationId=3169 Version 15.4.0.","journal-title":"Technical Specification (TS)"},{"key":"e_1_3_2_1_7_1","first-page":"301","article-title":"Non-Access-Stratum (NAS) protocol for Evolved Packet System (EPS); Stage 3","volume":"24","author":"GPP.","year":"2023","unstructured":"3GPP. 2023. Non-Access-Stratum (NAS) protocol for Evolved Packet System (EPS); Stage 3. Technical Standard (TS) 24.301. https:\/\/portal.3gpp.org\/desktopmodules\/ Specifications\/SpecificationDetails.aspx'specificationId=1072","journal-title":"Technical Standard (TS)"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSCN.2017.8088621"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/MCOMSTD.2018.1700063"},{"key":"e_1_3_2_1_10_1","volume-title":"Design Principles for 5G Security. A Comprehensive Guide to 5G Security","author":"Ahmad Ijaz","year":"2018","unstructured":"Ijaz Ahmad, Madhusanka Liyanage, Shahriar Shahabuddin, Mika Ylianttila, and Andrei Gurtov. 2018. Design Principles for 5G Security. A Comprehensive Guide to 5G Security (2018)."},{"key":"e_1_3_2_1_11_1","volume-title":"Proceedings of the ACM Conference on Computer and Communications Security (CCS). ACM.","author":"Akon Mujtahid","year":"2023","unstructured":"Mujtahid Akon, Tianchang Yang, Yilu Dong, and Syed Rafiul Hussain. 2023. Formal Analysis ofAccess Control Mechanism of 5G Core Network. In Proceedings of the ACM Conference on Computer and Communications Security (CCS). ACM."},{"key":"e_1_3_2_1_12_1","volume-title":"Proceedings of the IEEE Symposium on Security and Privacy (SP).","author":"Ami Amit Seal","year":"2013","unstructured":"Amit Seal Ami, Nathan Cooper, Kaushal Kafle, Kevin Moran, Denys Poshyvanyk, and Adwait Nadkarni. 2013. Why Crypto-Detectors Fail: A Systematic Evaluation of Cryptographic Misuse Detection Techniques. In Proceedings of the IEEE Symposium on Security and Privacy (SP)."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2014.23082"},{"key":"e_1_3_2_1_14_1","volume-title":"Proceedings of BlackHat.","author":"Argyros George","year":"2012","unstructured":"George Argyros and Aggelos Kiayias. 2012. PRNG: Pwning Random Number Generators. In Proceedings of BlackHat."},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"crossref","unstructured":"Elaine Barker. 2020. Guideline for Using Cryptographic Standards in the Federal Government: Cryptographic Mechanisms. Technical Report SP 800--175B Rev. 1. National Institute of Standards and Technology.","DOI":"10.6028\/NIST.SP.800-175Br1"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243846"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"crossref","unstructured":"Anastasios N Bikos and Nicolas Sklavos. 2012. LTE\/SAE Security Issues on 4G Wireless Networks. IEEE Security & Privacy 11 2 (2012).","DOI":"10.1109\/MSP.2012.136"},{"key":"e_1_3_2_1_18_1","volume-title":"Monitor. In Proceedings of Blackhat.","author":"Borgaonkar Ravishankar","year":"2017","unstructured":"Ravishankar Borgaonkar, Lucca Hirshi, Shinjo Park, Altaf Shaik, Andrew Martin, and Jean-Pierre Seifert. 2017. New Adventures in Spying 3G & 4G Users: Locate, Track, Monitor. In Proceedings of Blackhat."},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISSRE.2017.27"},{"key":"e_1_3_2_1_20_1","unstructured":"cplusplus. 2023. rand. https:\/\/cplusplus.com\/reference\/cstdlib\/rand\/."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23394"},{"key":"e_1_3_2_1_22_1","volume-title":"Rosario Giuseppe Garroppo, and Michele Pagano","author":"Dolente Filippo","year":"2024","unstructured":"Filippo Dolente, Rosario Giuseppe Garroppo, and Michele Pagano. 2024. A Vulnerability Assessment of Open-Source Implementations of Fifth-Generation Core Network Functions. Future Internet 16 (2024)."},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/2508859.2516693"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/2382196.2382205"},{"key":"e_1_3_2_1_25_1","unstructured":"FD.io. 2023. What is the Vector Packet Processor (VPP) - The Vector Packet Processor v24.02 documentation. https:\/\/s3-docs.fd.io\/vpp\/24.02\/"},{"key":"e_1_3_2_1_26_1","unstructured":"Open Networking Foundation. 2023. SD-Core. https:\/\/opennetworking.org\/sdcore\/."},{"key":"e_1_3_2_1_27_1","unstructured":"free5GC Project. 2023. free5GC. https:\/\/www.free5gc.org\/."},{"key":"e_1_3_2_1_28_1","unstructured":"GnuTLS. 2023. 5.13 Random Number Functions. https:\/\/gmplib.org\/manual\/ Integer-Random-Numbers."},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2006.5"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2022.23136"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23442"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354263"},{"key":"e_1_3_2_1_33_1","unstructured":"NextEPC Inc. 2019. NextEPC. https:\/\/nextepc.com\/."},{"key":"e_1_3_2_1_34_1","volume-title":"Cryptanalytic Attacks on Pseudorandom Number Generators. In International Workshop on Fast Software Encryption. Springer.","author":"Kelsey John","year":"1998","unstructured":"John Kelsey, Bruce Schneier, David Wagner, and Chris Hall. 1998. Cryptanalytic Attacks on Pseudorandom Number Generators. In International Workshop on Fast Software Encryption. Springer."},{"key":"e_1_3_2_1_35_1","volume-title":"Proceedings of the IEEE Symposium on Security and Privacy (SP).","author":"Kim Hongil","year":"2018","unstructured":"Hongil Kim, Jiho Lee, Eunkyu Lee, and Yongdae Kim. 2018. Touching the Untouchables: Dynamic Security Analysis of the LTE Control Plane. In Proceedings of the IEEE Symposium on Security and Privacy (SP)."},{"key":"e_1_3_2_1_36_1","article-title":"CrySL: An Extensible Approach to Validating the Correct Usage of Cryptographic Apis","volume":"47","author":"Kr\u00fcger Stefan","year":"2019","unstructured":"Stefan Kr\u00fcger, Johannes Sp\u00e4th, Karim Ali, Eric Bodden, and Mira Mezini. 2019. CrySL: An Extensible Approach to Validating the Correct Usage of Cryptographic Apis. IEEE Transactions on Software Engineering 47, 11 (2019).","journal-title":"IEEE Transactions on Software Engineering"},{"key":"e_1_3_2_1_37_1","volume-title":"Proceedings of the Network and Distributed Systems Security Symposium (NDSS)","author":"Kune Denis Foo","year":"2012","unstructured":"Denis Foo Kune, John Koelndorfer, Nicholas Hopper, and Yongdae Kim. 2012. Location Leaks on the GSM Air Interface. Proceedings of the Network and Distributed Systems Security Symposium (NDSS) (2012)."},{"key":"e_1_3_2_1_38_1","unstructured":"Sukchan Lee. 2023. Open5GS. https:\/\/open5gs.org\/."},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/3564625.3567989"},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-24174-6_24"},{"key":"e_1_3_2_1_41_1","unstructured":"MITRE. 2023. CWE-295: Improper Certificate Validation. https:\/\/cwe.mitre.org\/ data\/definitions\/295.html."},{"key":"e_1_3_2_1_42_1","unstructured":"MITRE. 2023. CWE-297: Improper Validation of Certificate with Host Mismatch. https:\/\/cwe.mitre.org\/data\/definitions\/297.html."},{"key":"e_1_3_2_1_43_1","unstructured":"OpenAirInterface.org. 2023. OpenAirInterface | 5G Software Alliance for Democratising Wireless Innovation. https:\/\/openairinterface.org\/."},{"key":"e_1_3_2_1_44_1","unstructured":"OpenAirInterface.org. 2023. OpenAirInterface Software Alliance. https:\/\/github. com\/openairinterface."},{"key":"e_1_3_2_1_45_1","unstructured":"OWASP. 2023. Testing forWeak SSL TLS Ciphers Insufficient Transport Layer Protection. https:\/\/owasp.org\/www-project-web-security-testing-guide\/stable\/4- Web_Application_Security_Testing\/09-Testing_for_Weak_Cryptography\/01- Testing_for_Weak_Transport_Layer_Security."},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1109\/GLOCOMW.2007.4437813"},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00010"},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3345659"},{"key":"e_1_3_2_1_49_1","unstructured":"J. Rizzo and T. Duong. 2011. Browser Exploit Against SSL\/TLS. https:\/\/ packetstormsecurity.com\/files\/105499\/Browser-Exploit-Against-SSL-TLS.html."},{"key":"e_1_3_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2018.2820728"},{"key":"e_1_3_2_1_51_1","volume-title":"Proceedings of the USENIX Workshop on Offensive Technologies (WOOT).","author":"Rupprecht David","year":"2016","unstructured":"David Rupprecht, Kai Jansen, and Christina P\u00f6pper. 2016. Putting {LTE} Security Functions to the Test: A Framework to Evaluate Implementation Correctness. In Proceedings of the USENIX Workshop on Offensive Technologies (WOOT)."},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00006"},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00006"},{"key":"e_1_3_2_1_54_1","article-title":"Exploiting GSM Vulnerabilities: An Experimental Setup And Procedure To Map TMSI And Mobile Number","volume":"8","author":"Saharan Sanjeev","year":"2017","unstructured":"Sanjeev Saharan and Jitender Kumar. 2017. Exploiting GSM Vulnerabilities: An Experimental Setup And Procedure To Map TMSI And Mobile Number. International Journal of Advanced Research in Computer Science 8, 5 (2017).","journal-title":"International Journal of Advanced Research in Computer Science"},{"key":"e_1_3_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1109\/DASC.2014.22"},{"key":"e_1_3_2_1_56_1","unstructured":"srsRAN Project. 2023. srsRAN Project - Open Source RAN. https:\/\/www.srsran. com\/."},{"key":"e_1_3_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1109\/MNET.011.1900635"},{"key":"e_1_3_2_1_58_1","volume-title":"Security for Telecommunications Networks","author":"Traynor Patrick","unstructured":"Patrick Traynor, Patrick McDaniel, and Thomas La Porta. 2008. Security for Telecommunications Networks. Vol. 40. Springer Science & Business Media."},{"key":"e_1_3_2_1_59_1","unstructured":"VulBusters. 2023. Exploring Go's math\/rand. https:\/\/medium.com\/@vulbsters\/ exploring-gos-math-rand-b4ef0e841591"},{"key":"e_1_3_2_1_60_1","volume-title":"Proceedings of the International Cryptology Conference (CRYPTO). Springer.","author":"Schneier Bruce","year":"1997","unstructured":"DavidWagner, Bruce Schneier, and John Kelsey. 1997. Cryptanalysis of the cellular message encryption algorithm. In Proceedings of the International Cryptology Conference (CRYPTO). Springer."}],"event":{"name":"CODASPY '24: Fourteenth ACM Conference on Data and Application Security and Privacy","location":"Porto Portugal","acronym":"CODASPY '24","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the Fourteenth ACM Conference on Data and Application Security and Privacy"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3626232.3653259","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3626232.3653259","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T19:50:12Z","timestamp":1755892212000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3626232.3653259"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,6,19]]},"references-count":60,"alternative-id":["10.1145\/3626232.3653259","10.1145\/3626232"],"URL":"https:\/\/doi.org\/10.1145\/3626232.3653259","relation":{},"subject":[],"published":{"date-parts":[[2024,6,19]]},"assertion":[{"value":"2024-06-19","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}