ZTE Communications ›› 2026, Vol. 24 ›› Issue (2): 93-102.DOI: 10.12142/ZTECOM.202602011
• Industry-Academia Co-Research • Previous Articles
Dong Congtang1, Xu Hang1, Sun Bin2,3(
), Ding Jianwen1, Wang Wei4
Received:2025-02-03
Online:2026-06-25
Published:2026-06-16
About author:Dong Congtang received his BE degree in communication engineering from Shandong Normal University, China in 2022. He is currently pursuing a master’s degree at the State Key Laboratory of Advanced Rail Autonomous Operation, Beijing Jiaotong University, China. His research interests include cyber security, AIOps and 5G-R.Supported by:Dong Congtang, Xu Hang, Sun Bin, Ding Jianwen, Wang Wei. 5G-R Core Network Cyber Security Assessment Method Based on Attack Graphs[J]. ZTE Communications, 2026, 24(2): 93-102.
Add to citation manager EndNote|Ris|BibTeX
URL: https://zte.magtechjournal.com/EN/10.12142/ZTECOM.202602011
| Level | Business Confidentiality | Business Integrity | Business Continuity |
|---|---|---|---|
| High | Serious threats to the business due to the leakage of critical information in the 5G-R core network | Illegal modification, destruction, or deletion of business data or system functions, seriously affecting business processes | Key business services unavailable for a long time, requiring an extended recovery period |
| Low | Minor leakage of non-critical business information, with relatively minor impacts | Minor unauthorized modification of business data or system functions | Temporary business interruption or delay |
| None | No information leakage | No modification of business data or system functions | No impact |
Table 1 Consequences of vulnerability exploitation on business security indicators in the 5G-R core network
| Level | Business Confidentiality | Business Integrity | Business Continuity |
|---|---|---|---|
| High | Serious threats to the business due to the leakage of critical information in the 5G-R core network | Illegal modification, destruction, or deletion of business data or system functions, seriously affecting business processes | Key business services unavailable for a long time, requiring an extended recovery period |
| Low | Minor leakage of non-critical business information, with relatively minor impacts | Minor unauthorized modification of business data or system functions | Temporary business interruption or delay |
| None | No information leakage | No modification of business data or system functions | No impact |
| Indicator Category | Indicator Level | Quantitative Value |
|---|---|---|
| Attack vector | Network, wireless access, adjacent network, local, physical | (0.85, 0.85, 0.62, 0.55, 0.20) |
| Attack complexity | Very high, High, Medium, Low | (0.22, 0.44, 0.56, 0.77) |
| Business confidentiality | High, Low, None | (0.27, 0.62, 0.85) |
| Business integrity | High, Low, None | (0.27, 0.62, 0.85) |
| Business continuity | High, Low, None | (0.27, 0.62, 0.85) |
Table 2 Vulnerability assessment indicator values
| Indicator Category | Indicator Level | Quantitative Value |
|---|---|---|
| Attack vector | Network, wireless access, adjacent network, local, physical | (0.85, 0.85, 0.62, 0.55, 0.20) |
| Attack complexity | Very high, High, Medium, Low | (0.22, 0.44, 0.56, 0.77) |
| Business confidentiality | High, Low, None | (0.27, 0.62, 0.85) |
| Business integrity | High, Low, None | (0.27, 0.62, 0.85) |
| Business continuity | High, Low, None | (0.27, 0.62, 0.85) |
| Indicator Category | Level | Classification Criteria |
|---|---|---|
| Technical maturity | High (H) | Widely used tools or methods exist; the attack process is fully automated, requiring no complex configuration. |
| Automatable (A) | Automated tools requiring basic configuration; attack scripts or code may have been developed and shared, needing minor modifications. | |
| Verified (V) | Verified in certain environments but not widely automated; requiring technical adjustments to existing tools. | |
| Unverified (Vu ) | Only proposed in theory; requiring highly customized development, involving complex research and testing. | |
| Mitigation level | Non-remediable (NR ) | Currently, no known patches or tools that can mitigate the risk. |
| Indirectly remediable (NDR ) | Although no direct remedy is available, the risk can be mitigated by implementing additional protective measures. | |
| Low remediation (LDR ) | Methods are available to address the vulnerability, but they either only partially alleviate the risk or are complex to implement. | |
| High remediation (HDR ) | The vulnerability can be effectively addressed with existing methods and tools; patches or remedial measures are already available. | |
| Report confidence | Confirmed (C) | Existence and details are verified through reliable means; it has been exploited in observed attacks or detailed reports provided by relevant organizations. |
| Unconfirmed (Cu ) | The report is not fully verified; it may originate from unverified third-party claims or automated scanning tools, requiring further verification. | |
| Unknown | There have been no reports related to this vulnerability. |
Table 3 Grading criteria for corresponding indicators
| Indicator Category | Level | Classification Criteria |
|---|---|---|
| Technical maturity | High (H) | Widely used tools or methods exist; the attack process is fully automated, requiring no complex configuration. |
| Automatable (A) | Automated tools requiring basic configuration; attack scripts or code may have been developed and shared, needing minor modifications. | |
| Verified (V) | Verified in certain environments but not widely automated; requiring technical adjustments to existing tools. | |
| Unverified (Vu ) | Only proposed in theory; requiring highly customized development, involving complex research and testing. | |
| Mitigation level | Non-remediable (NR ) | Currently, no known patches or tools that can mitigate the risk. |
| Indirectly remediable (NDR ) | Although no direct remedy is available, the risk can be mitigated by implementing additional protective measures. | |
| Low remediation (LDR ) | Methods are available to address the vulnerability, but they either only partially alleviate the risk or are complex to implement. | |
| High remediation (HDR ) | The vulnerability can be effectively addressed with existing methods and tools; patches or remedial measures are already available. | |
| Report confidence | Confirmed (C) | Existence and details are verified through reliable means; it has been exploited in observed attacks or detailed reports provided by relevant organizations. |
| Unconfirmed (Cu ) | The report is not fully verified; it may originate from unverified third-party claims or automated scanning tools, requiring further verification. | |
| Unknown | There have been no reports related to this vulnerability. |
| Value Range | Classification Criteria |
|---|---|
| 0.8–1.0 | Extensive impact scope: involves crucial data; failure causes a severe breakdown of the entire system. |
| 0.6–0.8 | Broad impact scope: involves highly sensitive data; failure may result in prolonged business interruption. |
| 0.4–0.6 | Moderate impact scope: components handle sensitive data; failure causes temporary business interruption. |
| 0.2–0.4 | Limited impact scope: data is moderately sensitive; failure has a minor impact on network stability. |
| 0.0–0.2 | Negligible impact scope: data is public or non-sensitive; failure has virtually no impact on the network. |
Table 4 Business criticality value classification
| Value Range | Classification Criteria |
|---|---|
| 0.8–1.0 | Extensive impact scope: involves crucial data; failure causes a severe breakdown of the entire system. |
| 0.6–0.8 | Broad impact scope: involves highly sensitive data; failure may result in prolonged business interruption. |
| 0.4–0.6 | Moderate impact scope: components handle sensitive data; failure causes temporary business interruption. |
| 0.2–0.4 | Limited impact scope: data is moderately sensitive; failure has a minor impact on network stability. |
| 0.0–0.2 | Negligible impact scope: data is public or non-sensitive; failure has virtually no impact on the network. |
| Value Range | Classification Criteria |
|---|---|
| 0.8–1.0 | Integrates advanced security protection technologies; physical security meets high standards, possessing comprehensive data backup and rapid recovery capabilities. |
| 0.6–0.8 | Adopts multi-layered protective technologies; physical security has advanced preventative measures, with strong data backup and recovery capabilities. |
| 0.4–0.6 | Deploys a range of defense technologies; moderate physical security measures are implemented, with certain data recovery capabilities. |
| 0.2–0.4 | Configured with basic security controls; physical security relies on generic solutions, lacking the ability for quick recovery. |
| 0.0–0.2 | Unprotected or features only basic default settings; lacks physical security controls, data backup, and recovery mechanisms. |
Table 5 Protective measure strength value classification criteria
| Value Range | Classification Criteria |
|---|---|
| 0.8–1.0 | Integrates advanced security protection technologies; physical security meets high standards, possessing comprehensive data backup and rapid recovery capabilities. |
| 0.6–0.8 | Adopts multi-layered protective technologies; physical security has advanced preventative measures, with strong data backup and recovery capabilities. |
| 0.4–0.6 | Deploys a range of defense technologies; moderate physical security measures are implemented, with certain data recovery capabilities. |
| 0.2–0.4 | Configured with basic security controls; physical security relies on generic solutions, lacking the ability for quick recovery. |
| 0.0–0.2 | Unprotected or features only basic default settings; lacks physical security controls, data backup, and recovery mechanisms. |
| Vulnerability Exploitability | Vulnerability Temporal Availability | Business Criticality | Strength of Protective Measures | |
|---|---|---|---|---|
| Vulnerability exploitability | (0.5, 0.5, 0.5) | (0.7, 0.8, 0.9) | (0.6, 0.7, 0.8) | (0.5, 0.6, 0.7) |
| Vulnerability temporal availability | (0.1, 0.2, 0.3) | (0.5, 0.5, 0.5) | (0.3, 0.3, 0.4) | (0.2, 0.3, 0.4) |
| Business criticality | (0.2, 0.3, 0.4) | (0.6, 0.6, 0.7) | (0.5, 0.5, 0.5) | (0.3, 0.5, 0.5) |
| Strength of protective measures | (0.3, 0.4, 0.5) | (0.6, 0.7, 0.8) | (0.6, 0.6, 0.8) | (0.5, 0.5, 0.5) |
Table 6 Fuzzy judgement matrix for atomic attack success probability
| Vulnerability Exploitability | Vulnerability Temporal Availability | Business Criticality | Strength of Protective Measures | |
|---|---|---|---|---|
| Vulnerability exploitability | (0.5, 0.5, 0.5) | (0.7, 0.8, 0.9) | (0.6, 0.7, 0.8) | (0.5, 0.6, 0.7) |
| Vulnerability temporal availability | (0.1, 0.2, 0.3) | (0.5, 0.5, 0.5) | (0.3, 0.3, 0.4) | (0.2, 0.3, 0.4) |
| Business criticality | (0.2, 0.3, 0.4) | (0.6, 0.6, 0.7) | (0.5, 0.5, 0.5) | (0.3, 0.5, 0.5) |
| Strength of protective measures | (0.3, 0.4, 0.5) | (0.6, 0.7, 0.8) | (0.6, 0.6, 0.8) | (0.5, 0.5, 0.5) |
| Indicator Category | Indicator | Quantitative Value |
|---|---|---|
| Technical maturity | High, automatable, verified, unverified | (1.00, 0.97, 0.94, 0.91) |
| Level of remediation | Non-remediable, indirectly remediable, low remediation level, high remediation level | (1.00, 0.97, 0.96, 0.95) |
| Report confidence | Confirmed, unconfirmed, unknown | (1.00, 0.96, 0.92) |
Table 7 Node reachability probability indicator values
| Indicator Category | Indicator | Quantitative Value |
|---|---|---|
| Technical maturity | High, automatable, verified, unverified | (1.00, 0.97, 0.94, 0.91) |
| Level of remediation | Non-remediable, indirectly remediable, low remediation level, high remediation level | (1.00, 0.97, 0.96, 0.95) |
| Report confidence | Confirmed, unconfirmed, unknown | (1.00, 0.96, 0.92) |
| Vulnerability | CVSS | 5G-R Core Network Vulnerability Assessment Method |
|---|---|---|
| CVE-2017-9445 | 7.5 | 8.8 |
| CVE-2019-13272 | 7.8 | 7.1 |
| CVE-2020-35658 | 5.3 | 5.6 |
| CVE-2020-8554 | 5.5 | 7.5 |
| CVE-2020-13777 | 7.5 | 7.5 |
| CVE-2020-3556 | 7.5 | 8.1 |
| CVE-2021-21985 | 9.8 | 9.8 |
| CVE-2021-1732 | 7.8 | 6.8 |
| CVE-2021-41794 | 7.5 | 8.1 |
| CVE-2023-23846 | 7.5 | 8.1 |
Table 8 Vulnerability comparison for the proposed method and CVSS
| Vulnerability | CVSS | 5G-R Core Network Vulnerability Assessment Method |
|---|---|---|
| CVE-2017-9445 | 7.5 | 8.8 |
| CVE-2019-13272 | 7.8 | 7.1 |
| CVE-2020-35658 | 5.3 | 5.6 |
| CVE-2020-8554 | 5.5 | 7.5 |
| CVE-2020-13777 | 7.5 | 7.5 |
| CVE-2020-3556 | 7.5 | 8.1 |
| CVE-2021-21985 | 9.8 | 9.8 |
| CVE-2021-1732 | 7.8 | 6.8 |
| CVE-2021-41794 | 7.5 | 8.1 |
| CVE-2023-23846 | 7.5 | 8.1 |
| [1] | Ding J W, Liu Y, Liao H J, et al. Statistical model of path loss for railway 5G marshalling yard scenario [J]. ZTE communications, 2023, 21(3): 117–122. DOI: 10.12142/ZTECOM.202303015 |
| [2] | He R S, Ai B, Zhong Z D, et al. 5G for railways: next generation railway dedicated communications [J]. IEEE communications magazine, 2022, 60(12): 130–136. DOI: 10.1109/mcom.005.2200328 |
| [3] | Sun Z T. Hierarchical and complex parallel network security threat situation quantitative assessment method [C]//The 6th International Conference on Computing Methodologies and Communication (ICCMC). IEEE, 2022: 276–279. DOI: 10.1109/ICCMC53470.2022.9753819 |
| [4] | Information technology—security techniques—information security management systems—overview and vocabulary [S] |
| [5] | Ritchey R W, Ammann P. Using model checking to analyze network vulnerabilities [C]//Symposium on Security and Privacy. IEEE, 2000: 156–165. DOI: 10.1109/SECPRI.2000.848453 |
| [6] | Lippmann R, Ingols K, Scott C, et al. Validating and restoring defense in depth using attack graphs [C]//IEEE Military Communications Conference. IEEE, 2006: 1–10. DOI: 10.1109/MILCOM.2006.302434 |
| [7] | Sheyner O, Wing J. Tools for generating and analyzing attack graphs [M]//Formal methods for components and objects. Berlin, Heidelberg: Springer, 2004: 344–371. |
| [8] | Ou X, Govindavajhala S, Appel A W. MulVAL: a logic-based cyber security analyzer [C]//The 14th USENIX security symposium. USENIX, 2005: 113–128. DOI: 10.5555/1251398.1251406 |
| [9] | Phillips C, Swiler L P. A graph-based system for network-vulnerability analysis [C]//The 1998 Workshop on New Security Paradigms. ACM, 1998: 71–79 |
| [10] | Jajodia S, Noel S, O’berry B. 2005. Topological analysis of network attack vulnerability [M]//Managing cyber threats: issues, approaches, and challenges. Boston: Springer US, 2005: 247–266 |
| [11] | Wang J F, Guo Y B. Cyber security risk assessment of physical information systems based on attack graphs [J]. Science technology and engineering, 2023, 23(28): 12175–12181. DOI: 10.12404/j.issn.1671-1815.2023.23.28.12175 |
| [12] | Pu J Y, Li Y H, Zhou C J. Method for cross-domain dynamic security risk analysis of industrial control systems based on probabilistic attack graphs [J]. Information cyber security, 2023, 23(9): 85–94. DOI: 10.3969/j.issn.1671-1122.2023.09.008 |
| [13] | Wang Z B, Zhang Y F, Chen Y L, et al. Method for discovering attack paths based on hierarchical task networks [J]. Computer science, 2023, 50(9): 35–43. DOI: 10.11896/jsjkx.230500025 |
| [14] | Wang S E, Liu C X, Liu S X, et al. A method for assessing 5G cyber security risk based on attack graphs [J]. Computer applications and software, 2023, 40(04): 289–296+335. DOI: 10.3969/j.issn.1000-386x.2023.04.046 |
| [15] | Zeng K L, Zhang N, Li W H, et al. Network asset security assessment model based on Bayesian attack graph [J]. Computer science, 2023, 50(12): 349–358. DOI: 10.11896/jsjkx.221000019 |
| [1] | XU Hang, SUN Bin, DING Jianwen, WANG Wei. Analysis of Feasible Solutions for Railway 5G Network Security Assessment [J]. ZTE Communications, 2025, 23(3): 59-70. |
| [2] | DING Jianwen, LIU Yao, LIAO Hongjian, SUN Bin, WANG Wei. Statistical Model of Path Loss for Railway 5G Marshalling Yard Scenario [J]. ZTE Communications, 2023, 21(3): 117-122. |
| Viewed | ||||||
|
Full text |
|
|||||
|
Abstract |
|
|||||