Skip to content
Open access

DDoS Defense Model on 5G Network Slices

2026 · Computer Modeling in Engineering & Sciences · Vol 148, pp. 1-10 · 0 citations · 49 references

TL;DR

A 5G network slicing intrusion detection mechanism, called the DDoS Defense Model on 5G Network Slices (2D5NS) which integrates machine learning and real-time traffic monitoring techniques to detect and mitigate DDoS attacks within an O-RAN is proposed.

Abstract

: With the quick development of 5G networks, network slicing and Open Radio Access Network (O-RAN) have become key technologies for improving network resource-allocation efficiency and flexibility. However, network slicing also faces intrusion-detection challenges, particularly for detecting DDoS attacks, which are difficult to detect due to traffic being silently transmitted across multiple sub-slices. To address this problem, this paper proposes a 5G network slicing intrusion detection mechanism, called the DDoS Defense Model on 5G Network Slices (2D5NS) which integrates machine learning and real-time traffic monitoring techniques to detect and mitigate DDoS attacks within an O-RAN. This security system consists of a Random Forest (RF) classification model, which is deployed within the Service Management and Orchestration (SMO) of O-RAN to classify packets transmitted from UE to the RAN into eMBB, mMTC and uRLLC slices, and a detection approach comprising the XGBoost mechanism which monitors the traffic within each slice in real time to detect DDoS attacks issued by User Equipment (UE). Once traffic is abnormal, it triggers an Entropy Algorithm to identify the sources of the DDoS attacks. The simulation results of our second experiment show that the classification accuracies of RF classification model in its 3-fold Cross Validation (CV) for eMBB and mMTC training achieve 99.98%. In our third experiment, the detection accuracy of 2D5NS/XGBoost model on uRLLC reaches at least 93.43%. Several state-of-the-art systems are evaluated. Here, the conclusion is that the 2D5NS outperforms each of them and the 2D5NS can effectively mitigate and block DDoS attacks for network slices.

Read PDF

Similar papers

Open access Aug 2026

Mitigation of DDoS Attacks in the Data Plane of Software-Defined Networking Using ML Techniques

Distributed Denial-of-Service (DDoS) attacks remain one of the most significant cyber threats faced by Software-Defined Networking (SDN) architectures, essentially because of the salient decoupling of the control and data planes. This study examines the implications of DDoS attacks on the SDN data plane and evaluates the effectiveness of Machine Learning (ML) algorithms in detecting and addressing these attacks in real time. Using the Ryu controller, Mininet network emulator, and OpenFlow protocol, a realistic experimental environment was created to provide an accurate replica of the dynamic SDN behaviour under adverse circumstances. Empirical studies have demonstrated that distributed DDoS attacks, such as SYN, UDP, and ICMP flooding, substantially degrade network performance by reducing throughput, increasing packet loss, and exhausting switch flow table resources. To mitigate these effects, a suite of supervised machine learning classifiers, including Decision Tree, Random Forest, Support Vector Machine (SVM), K-Nearest Neighbors (KNN), and Naïve Bayes (NB), was instantiated and evaluated using traffic features captured on the emulated platform. The key performance indicators used to evaluate the classifiers included accuracy, precision, recall, and F1-score. The findings indicate that the Decision Tree and KNN models achieved detection rates above the 99% mark, with strong precision and recall scores, which in turn highlights their suitability for implementation in SDN-based security systems. This study provides experimental evidence that ML-based intrusion detection mechanisms can significantly enhance the resilience of SDNs to volumetric attacks. These results promote the implementation of adaptive and responsive security modules in SDN controllers, thereby increasing network resilience, particularly in large and dynamically programmable networks.

Kamal Singh, B. Kumar · 0 citations
Review Open access Aug 2026

Software-Defined Networking Security: Architecture, Attack Surface, and Resilient Mechanisms

Software-Defined Networking (SDN) is a new way of thinking about networking in which the networking function is split into two planes: control plane and data plane. The aim of SDN is to give network managers greater control over network configuration, increased programmability, flexibility, and efficient use of network resources. These features have driven the rapid-fire uptake of SDN in today's communications networks, cloud and data center. However, all these appealing features can create additional security problems, increasing the attack surface and putting critical elements at risk of breaches. With the rapid emergence of SDN, network security and resilience are emerging top topics of researchers' interests. This paper provides a comprehensive survey of the SDN security by covering its architecture, key benefits and potential vulnerabilities. It explores potential attacks on the data plane, attacks on the communication channels outside the control plane, security challenges in the control plane, and existing approaches and proposed countermeasures from the literature. Moreover, the paper presents a survey of existing work, lists open challenges, research gaps and future research directions and implements some new trends related to secure, scalable and resilient SDN environments.

AJIT Karki, V. R, H. A. Akarte et al. · 0 citations
Open access 2026

Data-Driven Detection of Multi-vector IoT DDoS Attacks across Network Layers

—As cyberattacks targeting Internet of Things (IoT) networks grow more sophisticated, the demand for models capable of accurately detecting and mitigating these threats becomes increasingly urgent existing detection systems often concentrate on a single attack surface which leads to critical blind spots in IoT network monitoring. This research introduces an intensive IoT attack-detection framework that addresses internal and external attack sources, leveraging multi-layer attack vectors across the application, transport, network, and data link layers. The proposed framework was evaluated in two phases. In the first phase, three datasets that simulate a distinct attack source were created: outbound, including Dynamic Host Configuration Protocol (DHCP) amplification and DHCP starvation; inbound attacks, including application-layer attacks, Synchronize (SYN) flood, User Datagram Protocol (UDP) flood, Internet Control Message Protocol (ICMP) Smurf, and ICMP direct; and internal Address Resolution Protocol (ARP) spoofing. Three machine learning models; Random Forest, Light Gradient-Boosting Machine (LightGBM), and Categorical Boosting (CatBoost) were evaluated using accuracy, precision, recall, F1-Score, and Receiver Operating Characteristic (ROC) curve. In the second phase, a new dataset was generated by combining all datasets from the first phase. On the combined dataset, LightGBM achieved the highest performance, with accuracy: 94.08%, precision: 93.94%, recall: 94.08%, and F1-Score: 93.90%. Random Forest and CatBoost showed comparable performance, with all metrics ranging from approximately 93.2% to 93.9%. LightGBM demonstrates a slight edge in overall detection performance compared to other models, which highlights its effectiveness in detecting diverse and complex attack patterns across multiple traffic directions.

Rania A. Al-Ali, Mohammad M. Alnabhan, Q. A. Al-Haija · 0 citations
Conference Open access 2026

Mitigating Security Challenges in 5G Wireless Networks

An AI-assisted, cross-layer security orchestration framework that integrates epoch-wise telemetry with ML-based risk estimation and formalizes mitigation as a Constrained Markov Decision Process (CMDP), and empirical evidence that adaptive mitigation can reduce security risk without sacrificing service guarantees is provided.

F. Philip-Kpae, A. Imoize, K. .. Okafor et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.