5G Security Operations — SOC for 5G Core Networks · Pro
3GPP TS 33.501 defines the security architecture of the 5G system. From a SOC analyst's perspective, it is the defender's manual — it tells you what controls exist, what they protect, and where the spec mandates specific protections. Major components: authentication (5G-AKA and EAP-AKA'); key hierarchy (K → CK/IK → KAUSF → KAMF → KgNB → AS keys); NAS security (the encrypted control-plane between UE and AMF); AS security (the encrypted layer between UE and gNB); SUCI/SUPI privacy (subscriber identifier concealment); SBI security (mandatory TLS, optional mTLS, OAuth 2.0 tokens via NRF); lawful…