Skip to content
Open access

DDoS Defense Model on 5G Network Slices

2026 · Computer Modeling in Engineering & Sciences · Vol 148, pp. 1-10 · 0 citations · 49 references

TL;DR

A 5G network slicing intrusion detection mechanism, called the DDoS Defense Model on 5G Network Slices (2D5NS) which integrates machine learning and real-time traffic monitoring techniques to detect and mitigate DDoS attacks within an O-RAN is proposed.

Abstract

: With the quick development of 5G networks, network slicing and Open Radio Access Network (O-RAN) have become key technologies for improving network resource-allocation efficiency and flexibility. However, network slicing also faces intrusion-detection challenges, particularly for detecting DDoS attacks, which are difficult to detect due to traffic being silently transmitted across multiple sub-slices. To address this problem, this paper proposes a 5G network slicing intrusion detection mechanism, called the DDoS Defense Model on 5G Network Slices (2D5NS) which integrates machine learning and real-time traffic monitoring techniques to detect and mitigate DDoS attacks within an O-RAN. This security system consists of a Random Forest (RF) classification model, which is deployed within the Service Management and Orchestration (SMO) of O-RAN to classify packets transmitted from UE to the RAN into eMBB, mMTC and uRLLC slices, and a detection approach comprising the XGBoost mechanism which monitors the traffic within each slice in real time to detect DDoS attacks issued by User Equipment (UE). Once traffic is abnormal, it triggers an Entropy Algorithm to identify the sources of the DDoS attacks. The simulation results of our second experiment show that the classification accuracies of RF classification model in its 3-fold Cross Validation (CV) for eMBB and mMTC training achieve 99.98%. In our third experiment, the detection accuracy of 2D5NS/XGBoost model on uRLLC reaches at least 93.43%. Several state-of-the-art systems are evaluated. Here, the conclusion is that the 2D5NS outperforms each of them and the 2D5NS can effectively mitigate and block DDoS attacks for network slices.

Read PDF

Similar papers

Open access Aug 2026

Mitigation of DDoS Attacks in the Data Plane of Software-Defined Networking Using ML Techniques

Distributed Denial-of-Service (DDoS) attacks remain one of the most significant cyber threats faced by Software-Defined Networking (SDN) architectures, essentially because of the salient decoupling of the control and data planes. This study examines the implications of DDoS attacks on the SDN data plane and evaluates t...

Kamal Singh, Brijesh Kumar · 0 citations
Review Open access Aug 2026

Software-Defined Networking Security: Architecture, Attack Surface, and Resilient Mechanisms

A comprehensive survey of the SDN security by covering its architecture, key benefits and potential vulnerabilities, and explores potential attacks on the data plane, attacks on the communication channels outside the control plane, security challenges in the control plane, and existing approaches and proposed counterme...

AJIT Karki, V. R, H. A. Akarte et al. · 0 citations

V5GIDS: An ETSI NFV MANO-Aligned Federated Intrusion Detection Framework for 5G Networks

Experimental results show that V5GIDS achieves strong detection performance in the evaluated settings while improving deployment relevance through orchestration alignment, reduced telemetry exchange, and resource-aware distributed operation.

Sofian Ben Khalifa, Rahim Taheri, Ivan Jordanov · 0 citations
Open access 2026

Data-Driven Detection of Multi-vector IoT DDoS Attacks across Network Layers

—As cyberattacks targeting Internet of Things (IoT) networks grow more sophisticated, the demand for models capable of accurately detecting and mitigating these threats becomes increasingly urgent existing detection systems often concentrate on a single attack surface which leads to critical blind spots in IoT network...

Rania A. Al-Ali, Mohammad M. Alnabhan, Q. A. Al-Haija · 0 citations
Conference Open access 2026

Mitigating Security Challenges in 5G Wireless Networks

An AI-assisted, cross-layer security orchestration framework that integrates epoch-wise telemetry with ML-based risk estimation and formalizes mitigation as a Constrained Markov Decision Process (CMDP), and empirical evidence that adaptive mitigation can reduce security risk without sacrificing service guarantees is pr...

F. Philip-Kpae, A. Imoize, K. .. Okafor et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.