An Operational Framework for SOC-Integrated Attack Detection in 5G Standalone Networks
Abstract
The deployment of 5G standalone (SA) networks introduces cloud-native core architectures, service-based interfaces, and programmable radio access networks that substantially expand the mobile attack surface. Existing work has focused mainly on protocol-level vulnerabilities or isolated anomaly detection, with less attention to SOC-level monitoring, correlation, and investigation of 5G-specific threats. This paper presents a SOC-integrated, protocol-aware detection framework for 5G SA environments, combining structured telemetry ingestion, log normalization, decision-based detection logic, and analyst-oriented visualization within an Elastic-Stack-based SOC architecture. The approach is implemented on an experimental 5G SA testbed at Obuda University and evaluated using a dual-source design: controlled testbed scenarios complemented by an observational analysis of telemetry from an independent, large-scale international cyber-defense exercise whose adversarial complexity is difficult to reproduce synthetically. The evaluation exercises attack scenarios including rogue network element registration, authentication abuse, and control- and user-plane manipulation. The results indicate that embedding 5G-aware detection logic into SOC workflows supports situational awareness and structured incident investigation. A single-layer versus cross-layer ablation of the published detection rules quantifies where cross-layer correlation is strictly required for detection versus where it primarily enriches interpretation. This is extended with a limited generic-SIEM-style baseline check and a live, a priori repeated-trial sensitivity check (N=30, Wilson 95% CI [88.6%, 100%]). The framework offers a reproducible methodological foundation for operational 5G security monitoring and practical guidance for next-generation mobile network defense. Future work will extend controlled repeated-trial evaluation to the remaining detection rules, broaden the SIEM baseline comparison, and assess generalizability beyond Open5GS.