Machine Learning Based Signaling DDoS Detection System for 5G Stand Alone Core Network

Author:

Park SeongminORCID,Cho Byungsun,Kim Dowon,You Ilsun

Abstract

Research to deal with distributed denial of service (DDoS) attacks was kicked off from long ago and has seen technological advancement along with an extensive 5G footprint. Prior studies, and still newer ones, in the realm of DDoS attacks in the 5G environment appear to be focused primarily on radio access network (RAN) and voice service network, meaning that there is no attempt to mitigate DDoS attacks targeted on core networks (CN) by applying artificial intelligence (AI) in modeling. In particular, such components of a CN as the Access and Mobility Management Function (AMF), Session Management Function (SMF), and User Plane Function (UPF), all being principal functions enabled to provide 5G services as base stations do, provide expansive connectivity with geographically very large area coverage that cannot be matched by the base stations. Moreover, to complete re-registration for one UE, required messages in protocols Packet Forwarding Control Protocol (PFCP) and HTTP/2 are approximately 40 in number. This implies that a DDoS attack targeting the CN has, once accomplished, a greater than expected impact, when compared to DDoS attacks targeting the RAN. Therefore, security mechanisms for the CN must be put into practice. This research proposes a method, along with a threat detection system, to mitigate signaling DDoS attacks targeted on 5G SA (standalone) CNs. It is verified that the use of fundamental ML classifiers together with preprocessing with entropy-based analysis (EBA) and statistics-based analysis (SBA) enables us to proactively react against signaling DDoS attacks. Additionally, the evaluation results manifest that the random forest achieves the best detection performance, with an average accuracy of 98.7%.

Funder

Institute of Information & Communications Technology Planning & Evaluation

Publisher

MDPI AG

Subject

Fluid Flow and Transfer Processes,Computer Science Applications,Process Chemistry and Technology,General Engineering,Instrumentation,General Materials Science

Reference33 articles.

1. (2022, September 14). Quarterly DDoS and Application Attack Report. Radware Ltd.. Available online: https://www.radware.com/getattachment/5a547ad1-9793-42ce-9fef-0f67fa047247/1108_DDos_1108_rev_enUS.pdf.

2. Denial-of-Service Attack (2022, September 14). Wikimedia Foundation, Inc.. Available online: https://en.wikipedia.org/wiki/Denial-of-service_attack.

3. (2022, September 14). Alert (TA14-017A), UDP-Based Amplification Attacks, US-CERT, CISA, Available online: https://www.cisa.gov/uscert/ncas/alerts/TA14-017A.

4. Newman, L.H. (2022, September 14). GitHub Survived the Biggest DDoS Attack Ever Recorded. Wired. Available online: https://www.wired.com/story/github-ddos-memcached/.

5. (2022, September 14). DDoS Attack Countermeasure Guide, KR-CERT, KISA. Available online: https://www.krcert.or.kr/data/guideView.do?bulletin_writing_sequence=36186.

Cited by 5 articles. 订阅此论文施引文献 订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献

1. Security in 5G Network Slices: Concerns and Opportunities;IEEE Access;2024

2. Mitigating Signaling Storms in 5G with Blockchain-assisted 5GAKA;2023 19th International Conference on Network and Service Management (CNSM);2023-10-30

3. 5G Spectrum Research;2023 IEEE 10th International Conference on Cyber Security and Cloud Computing (CSCloud)/2023 IEEE 9th International Conference on Edge Computing and Scalable Cloud (EdgeCom);2023-07

4. Detection of HTTP DDoS Attacks Using NFStream and TensorFlow;Applied Sciences;2023-05-30

5. Signaling Storm in O-RAN: Challenges and Research Opportunities;IEEE Communications Magazine;2023

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3