Source-linked AI summary

CERTIoT-6G: Continuous Cybersecurity Certification for IoT Devices in 5G/6G Networks

Evangelos Lempesis, Fabio Palmese, Hamed Haddadi, Anna Maria Mandalari

arXiv:2608.23339v1cs.NIcs.CR

TL;DR

IoT ecosystems make static, manual certification difficult to scale while regulations require continuous cybersecurity assurance. CERTIoT-6G provides automated compliance analysis, traffic monitoring, adversarial testing, and regulatory reporting in 5G/6G networks. Validation across representative devices found encryption and DoS-resilience gaps while showing limited impact on live 5G traffic.

  • Problem

    Static, manual certification is difficult to scale across heterogeneous IoT ecosystems that require continuous cybersecurity and regulatory assurance.

  • Method

    CERTIoT-6G integrates regulatory interpretation, device identification, passive traffic monitoring, active adversarial testing, and compliance reporting as a 5G/6G SECaaS framework.

  • Results

    Validation across three representative device categories revealed critical gaps in traffic encryption and DoS resilience, while monitoring produced no application-layer loss and kept maximum latency increase below 10 ms.

  • Takeaways & Limitations

    Continuous certification can operate alongside production 5G traffic without material degradation of network quality while producing requirement-mapped compliance evidence.

Abstract

from arXiv · show

The massive adoption of Internet of Things (IoT) devices across critical domains such as healthcare, smart cities, industrial automation, and critical infrastructure introduces significant cybersecurity and regulatory challenges. Current and forthcoming European regulations, including the Cyber Resilience Act (CRA) and the NIS2 Directive, require manufacturers, operators, and other organizations to ensure secure-by-design devices, continuous vulnerability management, and resilient operation throughout the device lifecycle. Traditional certification mechanisms remain static, manual, and difficult to scale across heterogeneous IoT ecosystems. This paper presents CERTIoT-6G, a Security-as-a-Service (SECaaS) framework that enables automated cybersecurity certification and continuous compliance monitoring of IoT devices operating in 5G and future 6G networks. The framework integrates automated compliance analysis, real-time traffic monitoring, and adversarial testing capabilities. We validate the CERTIoT-6G framework on different IoT device categories operating in an advanced 5G testbed. Evaluation results reveal critical compliance gaps, particularly in traffic encryption and availability under unstable conditions, and demonstrate that the framework produces actionable verdicts mapped to regulatory requirements across heterogeneous device types. Furthermore, we show that the monitoring pipeline has a negligible impact on live 5G traffic.

I. INTRODUCTION

IoT growth across critical sectors expands cybersecurity risks while making manual, point-in-time certification impractical. CERTIoT-6G addresses this gap with continuous, automated compliance monitoring integrated into 5G infrastructure.

  • Motivation: IoT proliferation across healthcare, smart cities, and industrial automation expands the attack surface and makes manual assessment insufficient at 5G/6G scale.Heterogeneous devices generate continuous data streams but may expose personal information, enable unauthorized access, or support large-scale attacks.
  • Motivation: Existing certification remains largely manual and point-in-time, while only 52–70% of ETSI TS 103 701 tests can be automated with standard tooling.These limitations motivate certification that can scale across evolving device populations and security postures.
  • Contributions: CERTIoT-6G provides a Security-as-a-Service architecture for continuous cybersecurity certification of IoT devices in 5G and future 6G networks.The framework transforms certification from a static exercise into a continuous service embedded within network infrastructure.
  • Contributions: Its automated pipeline translates CRA, NIS2, and ETSI EN 303 645 requirements into network-level tests with per-requirement compliance verdicts.Reports are mapped to specific regulatory requirements, supporting evidence-based assessment.
  • Contributions: Early validation across three representative device categories revealed critical gaps in traffic encryption and denial-of-service resilience.The authors identify larger and more diverse device populations as a planned extension.

II. RELATED WORK

Prior work documents broad IoT weaknesses and develops automated gateway-level assessment, but certification remains constrained by manual conformance procedures and incomplete automation. CERTIoT-6G extends this line toward continuous evaluation in live 5G infrastructure.

  • Prior IoT security studies: Prior studies identify vulnerabilities spanning firmware, network, application, and cloud components and document personal-data exposure through insufficiently protected IoT traffic.Gateway traffic collection has also supported labeled datasets for large-scale smart-home security and privacy analysis.
  • Automated compliance assessment: COPSEC automatically probes devices at network gateways, extracts standards-based metrics, and reports compliance verdicts against security and privacy requirements.Its approach provides a direct precedent for automated, regulatory-grounded network assessment.
  • Automation gap: ETSI TS 103 701 defines comprehensive conformance assessment, but its procedure is designed for manual execution by accredited testing laboratories.The standard therefore provides requirements without making scalable operational automation straightforward.
  • Automation gap: Basic and advanced network-security tooling automates 52% and up to 70% of the 56 relevant network-attack test units, respectively.CERTIoT-6G addresses the remaining automation gap with a curated automated compliance-test pipeline.

D. IoT Security in 5G and 6G Networks

5G-enabled IoT introduces threats such as credential attacks, protocol vulnerabilities, and denial-of-service, while emerging AI-native networks increase demand for adaptive compliance services. CERTIoT-6G combines continuous live-network monitoring with active and passive assessment.

  • 5G/6G security context: 5G-enabled IoT security surveys identify credential attacks, protocol vulnerabilities, and denial-of-service as primary threats.The CERTIoT-6G validation engine exercises these threat classes through its security tests.
  • 5G/6G security context: 5G UPF and LBO mechanisms provide the network-edge integration point used to position CERTIoT-6G monitoring functions.This connects the framework’s compliance assessment to the user-plane traffic path.
  • 5G/6G security context: AI-native network management is expected to increase demand for adaptive compliance services beyond static certification.The passage frames this as a forward-looking requirement for evolving 6G infrastructures.
  • CERTIoT-6G positioning: Unlike local passive tools and laboratory conformance frameworks, CERTIoT-6G operates continuously inside live 5G infrastructure.It combines passive monitoring, active adversarial testing, and NLP-based personal-data detection into one pipeline with regulatory evidence bindings.

III. CERTIOT-6G FRAMEWORK

CERTIoT-6G is a four-part SECaaS framework that maps regulations to tests, identifies devices, executes passive and active validation, and reports requirement-bound verdicts. Its pipeline combines automated traffic analysis, adversarial probing, and expert-defined compliance tests.

  • Framework overview: CERTIoT-6G continuously monitors IoT devices on 5G or future 6G networks and verifies compliance with applicable cybersecurity regulations.The framework is organized around four functional components and their data flows.
  • Regulatory interpretation: The Regulatory Interpretation Engine decomposes CRA, NIS2, ETSI EN 303 645, ENISA, and NIST guidance into machine-readable requirement bindings.The mapping is many-to-many, allowing one test to provide evidence for multiple requirements.
  • Device identification: The Device Identification Engine passively discovers devices and uses the first 30 seconds of traffic plus DNS statistical features to classify device type.Derived category, vendor, model, and version attributes select device-specific compliance checks without manual onboarding.
  • Validation: The Validation Engine executes expert-defined passive and active tests, producing binary compliant or non-compliant verdicts with triggering evidence.Security experts define and validate tests so results remain legally defensible and technically grounded.
  • Passive monitoring: Passive monitoring computes encrypted-flow proportions and scans captured payloads for personally identifiable information using NLP-based detection.These tests are designed not to interfere with normal device operation, although observation windows must suit device behavior.
  • Active validation: Active probing checks unnecessary open ports, TLS certificate validation, authentication resilience, replay protection, and denial-of-service availability and recovery.The tests use scans, interception, brute-forcing, replay, and controlled flooding to assess corresponding security properties.

D. Reporting Engine

The Reporting Engine converts detected non-compliance into structured reports and web alerts, classifies severity, and recommends remediation while leaving enforcement authority with device owners.

  • The Reporting Engine generates structured compliance reports and web-based alerts when non-compliance is detected.
  • It documents non-compliance, classifies its severity, and provides actionable remediation recommendations instead of enforcing network-level mitigations.Examples include closing insecure ports, restricting exposed services, and applying firmware updates.

IV. INTEGRATION IN 5G TESTBEDS

CERTIoT-6G was integrated into the KAU CARL-W 5G Standalone testbed by steering selected IoT traffic through an edge analysis VM via UPF and LBO.

  • The framework was deployed in the KAU CARL-W 5G Standalone testbed at Karlstad University for network-level IoT evaluation.
  • IoT devices connect to the 5G network as UEs, while traffic is inspected at an analysis VM through LBO before Internet forwarding.The deployment architecture is shown in Figure 2.
  • The edge placement enables in-path inspection of live IoT traffic without modifying devices and avoids unnecessary traversal of remote cloud infrastructure.The local UPF anchors the user-plane traffic in Karlstad.

V. EXPERIMENTAL VALIDATION

The experimental validation used three representative IoT device categories in the 5G testbed and applied the applicable compliance-test suite to each device.

  • Setup and Device Set: Three representative device categories—surveillance, lighting, and environment—were selected to cover differing communication patterns, data sensitivity, and service exposure.The categories represent typical smart-home and smart-city deployments.
  • Setup and Device Set: The devices operated as 5G UEs, with traffic forwarded to the analysis VM through the 5G network and LBO path.
  • Setup and Device Set: Each device underwent the full battery of eight compliance tests where applicable.Replay Attack was limited to devices exposing locally reachable services, while Dictionary Attack was applied only to applicable devices.

B. Analysis and Key Findings

The evaluation found device-specific compliance differences, with particularly severe gaps in traffic encryption, availability under flooding, replay protection, and TLS certificate validation.

  • Security Findings: 100% of devices recovered fully after DoS probing, while only the environmental sensor passed the DoS Attack test during flooding.The camera and lighting device failed to maintain service continuity under flooding conditions.
  • Security Findings: All tested devices transmitted at least some information in cleartext, making Encrypted Traffic the most critical compliance failure.The finding exposes data to passive eavesdropping and violates mapped confidentiality requirements.
  • Security Findings: The camera and environmental sensor rejected replayed messages, but the lighting device allowed replication of previously sniffed on/off commands.
  • Privacy and Integrity: Two of three devices (67%) passed TLS Interception, while the lighting device accepted proxy-relayed traffic because certificate validation was absent or ineffective.The surveillance camera and environmental sensor resisted man-in-the-middle interception.
  • Device-Level Summary: The environmental sensor passed six of seven applicable tests, whereas the smart light had the weakest profile, failing TLS interception, encryption, DoS, and replay.The surveillance camera showed mixed results, with strong TLS and replay integrity but failures on encryption and privacy.

VI. NETWORK IMPACT AND FUTURE DIRECTIONS

The evaluation measures whether running the full CERTIoT-6G security suite alongside live 5G traffic degrades network quality. Across repeated baseline and monitored phases, the framework introduces minimal observed overhead.

  • Experimental design: The experiment compares a clean baseline with a monitored phase in which the full CERTIoT-6G test suite runs alongside continuous iperf3 traffic.The monitored suite includes port scanning, encrypted-traffic analysis, personal-information inspection, replay and dictionary attacks, recovery, DoS, and TLS interception.
  • Evaluation metrics: Four indicators—mean RTT, RTT standard deviation, packet retransmission rate, and throughput—are compared across 100 repetitions.Means and standard deviations across runs characterize central tendency and variability.
  • Results: Maximum observed increases in mean RTT and jitter remained below 10 ms between baseline and monitored conditions.The paper reports both measures remained within acceptable bounds.
  • Results: No application-level failures occurred, TCP retransmission rates showed no meaningful phase difference, and throughput matched the configured iperf3 rate in all runs.Throughput values were omitted because they exactly matched the configured transmission rate.

B. Benefits to the Certification Lifecycle

Automated compliance assessment addresses the lengthy, manual certification process by scaling evaluations across device populations and shortening the time to actionable verdicts.

  • Certification lifecycle: Traditional device compliance certification is typically manual and can require several months for full certification.The passage presents this as a characteristic of existing certification platforms.
  • Certification lifecycle: Automation can scale compliance assessment to larger device populations while reducing per-device cost and compressing decision time from months to under 48 hours.The shorter decision window is relevant to CRA vulnerability-response timescales.
  • Certification lifecycle: A portion of the proposed test suite can produce a compliance verdict in less than two minutes.This illustrates the efficiency of the solution for large-scale implementations.

C. Toward AI-Native Compliance Operations

CERTIoT-6G combines continuous certification with a deterministic validation core and identifies learning-based extensions for future 6G compliance operations. Early validation found both important security gaps and stable network coexistence.

  • Current validation and evolution: The current validation engine uses deterministic rule-based traffic analysis alongside a pre-trained NLP model for personal-data detection.The framework proposes preserving this auditable core while selectively adding learning-based capabilities.
  • Current validation and evolution: Future extensions target anomaly-driven detection for dynamic traffic and automated mapping of amended regulatory text to structured test bindings.These extensions are framed as incremental candidates for future 6G deployments.
  • Framework scope: The framework integrates regulatory interpretation, passive monitoring, adversarial testing, and structured reporting into a unified pipeline deployed at the 5G UPF.This design targets scalability and continuity gaps in conventional certification.
  • Early validation: Early validation across surveillance, lighting, and environment devices covered eight CRA- and NIS2-aligned security test categories and found gaps in traffic encryption and DoS resilience.The same validation found consistent strength in post-attack recovery, port hygiene, and authentication security.
Loading 2608.23339v1…