5GMon: Enhancing Visibility and Security in 5G Network Deployments
Francesco Mancini, Angelo Tulumello, Giacomo Belocchi, Giuseppe Bianchi · 2025
Modern 5G and beyond networks enable flexible connectivity and support complex scenarios like industrial automation and IoT, but their complexity and hybrid deployments introduce new challenges for visibility and security. Traditional IP-based monitoring tools are ill-suited for this environment, as they rely on persistent IP addresses and cannot access 5G-native identifiers such as the IMSI, which are confined to the control plane. In this paper, we present a novel monitoring framework tailored for 5G infrastructures. Our approach decouples traffic acquisition from analysis and integrates native 5G protocols (NGAP, PFCP, GTP-U) to correlate control and data plane traffic. This enables precise session tracking and attribution of malicious behavior to specific user equipment (UE), even in the presence of NAT and dynamic addressing. We validate our framework using a real-world testbed comprising commercial UEs, Amarisoft RAN, and HPE's Athonet 5G Core Network, demonstrating its effectiveness in reconstructing sessions and detecting threats.