5G-Advanced (3GPP Release 18) architectural changes include multi-access edge computing (MEC) architectural changes, network automation, and non-public networks (NPNs). It is important to note that even though these advancements provide substantial performance advantages, they destroy fixed-perimeter security models, providing a distributed attack surface. The use of current security assessment strategies, which are usually non-fluid and isolated, is inadequate to offer the required runtime security health assurance needed in such fluid environments. This study presents a new security assurance framework (SAF) that would be used to provide ongoing evidence-based protection on core, edge, and private network domains. This framework employs a four-layer architecture, including monitoring, analytics (LM), policy engine, and enforcement, to convert security periodically audited to a dynamic threat-control-metric evidence chain. A 96% attack detection rate and a 99.8% reduction in response time (with a mean of 20.1 s) are proven by validation on an emulated 5G-Advanced testbed (approximating Release 18 features using Open5GS (v2.7.2 Rel-17, community developed, Seoul, Republic of Korea and custom extensions) based on a design science research (DSR) paradigm. Although the overhead (13% CPU, 21.4% memory) is manageable, the findings prove that all-time, multi-domain assurance is crucial to the healthy functioning of 5G-Advanced and is a key roadmap to autonomous 6G security.
The increasing connectivity of automotive systems through Vehicle-to-Everything (V2X) communication and Mobile Ad Hoc Networks (MANETs) has created new vulnerabilities to Distributed Denial of Service (DDoS) attacks, threatening the availability of safety-critical vehicle communications and infrastructure services. This research addresses the challenge of protecting MANET-based automotive infrastructure by developing an integrated security architecture combining Network Detection and Response (NDR), Security Information and Event Management (SIEM), and Security Orchestration, Automation, and Response (SOAR) capabilities. Risk analysis was conducted using the NIST Cybersecurity Framework 2.0, mapping security controls across its six core functions. A laboratory proof of concept validated the architecture using CYBERQUEST (SIEM) and NETALERT (NDR) platforms to detect and automatically mitigate a simulated volumetric DDoS attack against a static network node. The integrated detection chain successfully identified abnormal connection volumes, correlated alerts across multiple sources, and executed automated blacklisting responses without human intervention. The results demonstrate that commercially available security platforms can be effectively adapted for MANET environments when properly integrated, providing rapid automated response capabilities aligned with European regulatory requirements including the NIS2 Directive and UNECE Regulation No. 155.
C. Ene, Marius Minea· European Conference on Artif...· 0 citations
Software-Defined Networks (SDNs) and Data Center Networks (DCNs) are becoming fundamental components in cloud computing and other large-scale digital services. SDNs and DCNs pose new security challenges due to their centralized control plane, network virtualization, dynamic orchestration of resources, and other novel features. Cybersecurity risks associated with SDNs and DCNs include DDoS and other types of attacks, resource exploitation, traffic diversion, and data leakage. Most other types of traditional intrusion detection systems do not adapt or provide real-time protection for high-scale programmable networks. Our research proposes a multi-layer adaptive security approach that fuses Dynamic Threat Detection (DTD), Adaptive Access Control (AAC), Secure Network Virtualization (SNV), Behavior-based Anomaly Detection (BAD), and Policy-Driven Security (PSF). The security framework created using fusion proposes deep learning-based anomaly detection, entropic (entropy) access control, fusion of virtualization protection over homomorphic encryption, and command-based dynamic orchestration as protective mechanisms to secure multiple levels of one or more networks. This new approach achieved a detection rate of 97. 8%, precision as 97. 2%, recall as 96. 9%, and an F1 score of 97. 0 with a ROC-AUC of 0.987. The model achieved detection latency (6.4 ms) under 20 Gbps throughput with strong scalability and high bandwidth. The proposed framework shows improved detection performance, fewer false positives, and better resilience for the network in comparison to CNN-LSTM, Transformer-based, and federated learning intrusion detection systems. Results prove the combination of adaptive intelligence, secure virtualization, and dynamic policy enforcement boosts cybersecurity defenses in unique ways for programmable SDN and DCN infrastructures.
Hasan Alkahtani· JOIV: International Journal...· 0 citations
5G networks increasingly rely on key enabling technologies such as Software-Defined Networking (SDN), Network Function Virtualization (NFV), Multi-Access Edge Computing (MEC), and end-to-end network slicing to deliver heterogeneous services with strict quality-of-service (QoS) guarantees. However, programmability, multi-tenancy, and distributed edge–cloud operation significantly expand the attack surface. At the same time, traditional rule-based and reactive security mechanisms remain slow to adapt and may violate latency constraints during mitigation. This paper addresses the problem of QoS-compliant, closed-loop security control for sliced SDN/NFV infrastructures. We propose an AI-assisted, cross-layer security orchestration framework that integrates epoch-wise telemetry with ML-based risk estimation and formalizes mitigation as a Constrained Markov Decision Process (CMDP). The CMDP controller selects enforceable actions— slice isolation, rate limiting, traffic rerouting, and key reconfiguration—while explicitly satisfying latency/overhead constraints, and executes them via SDN flow-rule updates and NFV policy/VNF reconfiguration. Simulation results over 50 decision epochs demonstrate effective response to an injected high-risk event: risk spikes to 0.95 at epoch 15, after which the controller drives risk toward ≈0.10 while maintaining latency below the 40ms QoS bound (with a transient rise during mitigation and subsequent stabilization). The reward trajectory briefly degrades during disruption but recovers and converges to a positive long-term return, indicating stable constraint-aware operation. This work provides (i) a deployable cross-layer orchestration architecture for sliced networks, (ii) a QoS-constrained CMDP decision model that converts risk signals into actionable SDN/NFV controls, and (iii) empirical evidence that adaptive mitigation can reduce security risk without sacrificing service guarantees.
F. Philip-Kpae, A. Imoize, K. C. Okafor et al.· E3S Web of Conferences· 0 citations
The large language models (LLMs) are beginning to provide tangible changes to the practice of network security: better threat detection; tighter enforcement of policy; and faster incident response. This survey provides a practitioner’s perspective on the use of LLMs in each of the key areas of network security, with a focus on 6G-enabled mission-critical communication systems, including public safety networks, emergency response coordination, and resilient infrastructure supporting URLLC, non-terrestrial networks (NTN), and edge deployments; these include traffic analysis, anomaly detection, threat intelligence, intrusion detection, vulnerability management, access control, compliance auditing, and security training. The survey documents specific improvements provided by LLMs with respect to context-aware classification, parsing of logs at a fine level of granularity, translating high-level policies to executable rules, and scripting of realistic threat scenarios to test against. We show how the combination of prompt engineering, multimodal embeddings, federated learning, and retrieval-augmented generation (RAG) can be used to expand the capabilities of the Security Operations Center (SOC), and automated defense. We also identify some of the risks associated with the use of LLMs, which include hallucination in output, leakage of sensitive information, and creation of new attack vectors through integration with the model; we also note some of the safeguards that have begun to emerge. We further analyze concrete public safety and emergency response scenarios - including LLM-assisted disaster-zone threat detection and emergency communication prioritization under adversarial overload - examining the specific vulnerabilities introduced by NTN-enabled 6G architectures and the stringent latency requirements of URLLC deployments. In conclusion, we provide working baseline levels of capability with respect to current LLM-based solutions in 6G mission-critical and public safety contexts, and map out specific research directions to advance LLM-driven cybersecurity toward robust, adaptable, explainable, and life-safety-aware solutions.
Siva Sai, Bhuvan Arora, Vineet Suri et al.· IEEE Open Journal of the Com...· 1 citation
Modern enterprises increasingly struggle to manage cloud security architecture, infrastructure resilience, SIEM operations, and regulatory compliance as isolated disciplines, resulting in operational inefficiencies, increased cyber risk, and costly audit processes. This paper presents a comprehensive five-level maturity model that unifies these traditionally disconnected domains into a cohesive framework for enterprise cybersecurity transformation. The proposed maturity model comprising Fragmented, Instrumented, Correlated, Automated, and Adaptive stages provides organizations with a practical roadmap for assessing current capabilities and systematically advancing toward intelligent, self-optimizing security operations. Unlike conventional reference architectures that assume green field deployments, the framework addresses the realities of heterogeneous enterprise environments spanning multi-cloud platforms, storage infrastructures, backup systems, security information and event management (SIEM) solutions, and compliance programs. The study further introduces diagnostic decision flows, capability maps, maturity transition guidance, and comparative operational metrics demonstrating improvements in incident detection, containment, backup resilience, compliance coverage, and automation maturity. By emphasizing the convergence of cloud infrastructure, cybersecurity operations, data protection, and governance through automation and cross-functional collaboration, the proposed framework enables organizations to reduce operational complexity, strengthen cyber resilience, accelerate regulatory compliance, and establish adaptive security capabilities suitable for modern cloud-native enterprises.
Lakshmi Kiran Meesala· International Journal of Art...· 0 citations
Computer-based testing (CBT) platforms have transformed education and certification by enabling scalable, efficient, and accessible examinations. However, these systems face significant cybersecurity risks, including unauthorized access, denial-of-service (DoS) attacks, and digital cheating, which threaten fairness and reliability. This study proposes a network-based security information system (NBSIS) designed specifically for CBT environments. The framework integrates layered defense, including pfSense firewalls (FW), Snort intrusion detection, Splunk security information and event management (SIEM), and artificial intelligence (AI)-powered analytics, into a unified architecture. A human-centered dashboard ensures usability for non-technical exam administrators, providing real-time alerts and intuitive controls. Validation through simulated attack scenarios demonstrated strong resilience, with high detection accuracy, reduced false positives, and rapid response times. Comparative analysis against intrusion detection system (IDS)-only and SIEM-only systems confirmed superior performance. The findings highlight NBSIS as a robust, scalable, and adaptive solution that safeguards exam integrity while remaining practical for diverse organizational contexts. This research contributes to computer science by advancing secure architecture, applying AI-driven anomaly detection, and integrating human-computer interaction principles into cybersecurity for education.