Decoding 5G security: toward a hybrid threat ontology
R. Andrew Paskauskas · Open Research Europe · 2025
This Open Letter announces a new initiative, designed from the ground up, incorporating key cybersecurity standards while providing a novel framework for modelling hybrid threats in 5G infrastructure. The 5G Hybrid Threat Ontology is a structured framework designed to reduce risk and achieve sustainable resilience against hybrid threats targeting 5G infrastructure. As fifth-generation (5G) networks become integral to critical infrastructure, they introduce new vulnerabilities that adversaries can exploit through hybrid threats-multifaceted attacks spanning cyber, physical, and socio-political domains. Existing security approaches focus on specific technical vulnerabilities or predictive threat modelling but lack a unified framework to address hybrid threat scenarios systematically. This paper advances the study of 5G security by proposing an ontology-driven approach prioritising resilience through risk reduction rather than threat elimination or prediction. Developed using Semantic Web technologies, specifically the Resource Description Framework (RDF) in Turtle representation for structured threat modelling, the ontology ensures machine-readability, structured threat intelligence sharing, and validation through Shapes Constraint Language (SHACL). It integrates established frameworks, including the 5G Threat Taxonomy compiled by the European Union Agency for Cybersecurity (ENISA), the Structured Threat Information eXpression (STIX) standard, and other widely used cybersecurity standards. By formalising relationships between adversarial tactics, 5G vulnerabilities, and cascading risks, the ontology enables semantic reasoning using tools within the Protégé framework. Although still under development, the 5G Hybrid Threat Ontology demonstrates strong Description Logic (DL) expressivity, ensuring adaptability for evolving security challenges. This approach bridges high-level policy directives with operational cybersecurity needs, reinforcing a resilience-driven security posture. Future research will build on the phased development of the 5G Hybrid Threat Ontology to enhance adaptive threat modelling and dynamic risk assessment, ensuring that the ontology continues to evolve as a strategic tool for strengthening the resilience of 5G infrastructures against hybrid threats.