CellSecInspector

CellSecInspector

Safeguarding Cellular Networks via Automated Security Analysis on Specifications

ACM MobiCom 2026

Overview

Automated Security Analysis of Cellular Specifications

3 + 2Full Specifications + Selected Sections Analyzed
9Foundational Security Properties
43Confirmed Vulnerabilities
7Previously Unreported Vulnerabilities

CellSecInspector transforms complex 3GPP specifications into structured procedural representations, connects distributed behaviors into function chains, checks them against foundational security properties, and generates grounded test cases for expert validation.

Our Method

CellSecInspector Pipeline

Figure 1: CellSecInspector system overview, from 3GPP specifications to SCA nodes, function chains, security analysis, and test cases

A Violation Example

Replay-Induced Service Integrity Violation

Node 2073Replay attackService Integrity

New Vulnerabilities

Seven Previously Unreported Vulnerabilities

43 vulnerabilities identified, including 7 previously unreported vulnerabilities.