Intelligent Risk Analysis and Testing of Non-Access Stratum Protocol Based on Natural Language Processing
Zixuan Zhang, Baojiang Cui, Jun Yang, Jie Xu · 2025
With the continuous development and update of the 3rd Generation Partnership Project (3GPP) standards, the protocols themselves have become more complex and diverse, leading to various unknown logical vulnerabilities and security risks, especially for the Non-Access Stratum (NAS) protocol, which handles critical signaling procedures such as authentication and session management, making it a prime target for potential attacks. Previous approaches primarily depend on manual risk identification driven by human experience for analyzing complex and numerous protocols. Alternatively, fuzz testing methods are often used, but they fail to account for real-world scenarios and are unable to detect logical vulnerabilities. Therefore, in this work, we implement effective and intelligent risk identification and analysis testing for the NAS protocol. The protocol process description statements in the 3GPP standard are used to complete the testing of the protocol. The workflow we designed is divided into three main steps: First, we identify and locate risk description within the 3GPP standard documentation. Next, we reconstruct the network interaction state by building process paths based on the context of the statements. Finally, by applying rule mapping techniques, we generate corresponding test cases and execute them within our developed testing system, enabling automated NAS protocol testing. Specifically, we found Four protocol implementation issues of different mobile phone manufacturers in this paper.