Digital Forensics and Incident Response (DFIR) in O-RAN Implementations

Conference: Mobilkommunikation - 28. ITG-Fachtagung
05/15/2024 - 05/16/2024 at Osnabrück

Proceedings: ITG-Fb. 316: Mobilkommunikation – Technologien und Anwendungen

Pages: 6Language: englishTyp: PDF

Authors:
Wittemeier, Henrik; Karl, Thomas; Dieterich, Arn Jonas; Grebe, Andreas

Abstract:
For years a strong trend towards cloudification in the mobile communication industry as well as in all other IT-centric operation areas is observed. Several groups and companies including the Telecom Infra Project (TIP) and the O-RAN Alliance work on concepts for Open RAN comprising architectures and open interfaces as well as reference implementations, testbeds, and operational installations in mobile network operator (MNO) networks. The O-RAN Software Community (SC) creates a reference implementation of an Open RAN. In this paper, initially vulnerabilities and threats of the O-RAN SC reference implementation are analyzed and secondly an architecture and implementation for Digital Forensics and Incident Response (DFIR) is discussed, which can be adapted to usual Open RAN implementations.