5G Penetration Testing

5G penetration testing assesses the attack surface introduced by the 5G Service-Based Architecture from an attacker's perspective. Unlike 2G/3G/4G testing, the targets are HTTP/2 + JSON service-based interfaces (SBI), OAuth2-protected NF-to-NF calls, and the N32 interconnect between Security Edge Protection Proxies (SEPPs). The methodology is anchored in 3GPP TS 33.501 (5G System security architecture) and the GSMA 5G security guidelines, and the deliverable answers a specific question per network function: what can an attacker reaching this NF or its SBI endpoint actually achieve against a real 5G subscriber base?

Scope on a 5G standalone (SA) core normally covers: SEPP and N32 (TLS termination, JSON path filtering on N32-c and N32-f, PRINS protection, IPX-modification handling); NRF (service-registration abuse, NF-profile spoofing, discovery manipulation); AMF (NAS handling, registration and mobility flows, slice selection, paging); SMF and UPF (session establishment, QoS manipulation, GTP-U handling on N9); AUSF and UDM (5G-AKA / EAP-AKA' flow tampering, SUPI/SUCI concealment integrity, authentication-vector handling); NEF (northbound API exposure, capability-exposure abuse); and slice isolation (cross-slice access from a tenant or compromised NF). On 5G NSA the LTE/EPC attack surface remains in scope and is tested with the same rigour.

Engagements combine lab testing against a representative 5G core (where destructive cases — SEPP bypass attempts, NRF deregistration storms, malformed SBI fuzzing — can be exercised without subscriber impact) with controlled live testing against the production perimeter from a simulated roaming partner. Reports map every finding to TS 33.501 / FS.36 / FS.37, give a reproducible PoC, the subscriber and operator impact, and the configuration or code change that closes it. The same evidence base is what regulators expect under NIS2 and equivalent regimes. For the underlying 5G security architecture, see the 5G Security hub; the broader engagement framework is in the Telecom Penetration Testing guide; hands-on team enablement is covered by 5G security training.

Related glossary terms

  • 3GPP TS 33.501 5G System Security Architecture
  • IPUPS Inter-PLMN UP Security
  • SEAF SEcurity Anchor Function
  • Network Slice 5G Network Slice
  • N3 N3 Reference Point (gNB to UPF)
  • N11 N11 Reference Point (AMF to SMF)
  • N12 N12 Reference Point (AMF to AUSF)
  • SEPP Security Security Edge Protection Proxy Security

Browse the full telecom security glossary

More on 5g Penetration Testing

Browse all topic hubs, the Ultimate Guide to Mobile Network Security and the TelcoSec Glossary.