SENTINEL: Self Protecting 5G Core Control Plane from DDoS Attacks for High Availability Service

被引:3
作者
Chilukuri, Aditya [1 ]
Vittal, Shwetha [1 ]
Franklin, Antony A. [1 ]
机构
[1] Indian Inst Technol Hyderabad, Dept Comp Sci & Engn, Hyderabad, Telangana, India
来源
2023 15TH INTERNATIONAL CONFERENCE ON COMMUNICATION SYSTEMS & NETWORKS, COMSNETS | 2023年
关键词
D O I
10.1109/COMSNETS56262.2023.10041318
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Current advancements in the 5G network slicing admit a huge number of users avail a variety of services from the 5G Core network (5GC). While this is impressive, it opens the doors to security threats that could harm the smooth functioning of the 5GC as well as the legitimate users availing its services. This paper presents SENTINEL - a novel self protecting 5GC in the control plane by leveraging the Self Organizing Network (SON) paradigm. SENTINEL is fabricated as an autonomous framework, which protects itself in the control plane operations of 5GC from Distributed Denial of Service (DDoS) attack attempts by malicious users. Precisely, we build it as an Artificial Intelligence-based Hierarchical Temporal Memory (HTM) framework along with eXpress Data Path (XDP) and extended Berkeley Packet Filter (eBPF) based slice aggregator to aid in protecting the slice when the malicious users attempt a DDoS attack. While the attack is aimed at the 5GC control plane, the SENTINEL isolates the suspected malicious users with a sensitivity of '85.59%' from the 5GC. Thereby, it keeps the High Availability (HA) service for legitimate users intact, without incurring additional resources.
引用
收藏
页数:9
相关论文
共 33 条
[1]  
3GPP, 2021, 3rd Generation Partnership Project (3GPP), Technical Specification (TS) 23.501
[2]  
Ahmad S., 2016, Biological and machine intelligence
[3]   Unsupervised real-time anomaly detection for streaming data [J].
Ahmad, Subutai ;
Lavin, Alexander ;
Purdy, Scott ;
Agha, Zuha .
NEUROCOMPUTING, 2017, 262 :134-147
[4]  
[Anonymous], 2018, 3GPP Standard TS 33.501
[5]  
[Anonymous], 2018, 2018 IEEE GLOBAL COM
[6]  
[Anonymous], 2018, 23502 3GPP TS
[7]  
[Anonymous], 2016, CORE NETWORK TRANSMI
[8]  
apriorit, DDOS ATT TECHN OV MI
[9]  
cloudflare, WHAT IS DDOS MIT
[10]   Network slicing security: Challenges and directions [J].
Cunha, Vitor A. ;
da Silva, Eduardo ;
de Carvalho, Marcio B. ;
Corujo, Daniel ;
Barraca, Joao P. ;
Gomes, Diogo ;
Granville, Lisandro Z. ;
Aguiar, Rui L. .
INTERNET TECHNOLOGY LETTERS, 2019, 2 (05)