Open RAN's disaggregated architecture introduces critical security complexity, as threats can propagate across components from different vendors. Manual response is too slow, risking lateral movement and service degradation. This workflow automates threat response by deploying specialized agents within the RAN Intelligent Controller (RIC) framework. These agents ingest telemetry from O-RAN interfaces, correlate signals, and execute coordinated containment actions—such as isolating a compromised Distributed Unit (DU) or updating access policies—directly through the Service Management and Orchestration (SMO) layer.




