Service Classification of Network Traffic in 5G Core Networks using Machine Learning

Service Classification of Network Traffic in 5G Core Networks using Machine Learning
复制标题

DOI:
10.1109/edge60047.2023.00053
复制
发表时间:
2023-07
期刊:
2023 IEEE International Conference on Edge Computing and Communications (EDGE)
影响因子:
--
通讯作者:
R. Pell;M. Shojafar;Dimitrios Kosmanos;S. Moschoyiannis
R. Pell;M. Shojafar;Dimitrios Kosmanos;S. Moschoyiannis
中科院分区:
其他
文献类型:
--
作者:
R. Pell;M. Shojafar;Dimitrios Kosmanos;S. Moschoyiannis

文献摘要

相似文献

第五代移动网络 (5G) 利用边缘计算的力量使重要服务更接近最终用户。由于关键的 5G 核心网络组件位于边缘,因此需要检测恶意信令流量,以减轻分布式网络功能 (NF) 之间潜在的信令攻击。检测异常信令的先决条件是用于识别和分类正常流量概况的网络流量数据集。为此,我们利用 5G 核心网络 (5GC) 模拟器来执行不同 5G 程序的测试场景,并使用捕获的网络流量以数据包捕获的形式生成规范化服务交互的数据集。然后,我们应用机器学习技术(监督学习)并使用流量元数据中的三个特征对准确性进行比较分析。我们的结果表明,通过应用机器学习技术来识别 5G 服务使用情况,为仅根据网络流量元数据对正常服务进行分类提供了可行的解决方案。这在预测动态 5GC 环境中资源分配的服务需求方面具有潜在优势,并为执行 NF 通信异常检测以检测 5G 基于服务的架构 (SBA) 内的恶意流量提供基线。
Fifth generation mobile networks (5G) leverage the power of edge computing to move vital services closer to end users. With critical 5G core network components located at the edge there is a need for detecting malicious signalling traffic to mitigate potential signalling attacks between the distributed Network Functions (NFs). A prerequisite for detecting anomalous signalling is a network traffic dataset for the identification and classification of normal traffic profiles. To this end, we utilise a 5G Core Network (5GC) simulator to execute test scenarios for different 5G procedures and use the captured network traffic to generate a dataset of normalised service interactions in the form of packet captures. We then apply machine learning techniques (supervised learning) and do a comparative analysis on accuracy, which uses three features from the traffic meta-data. Our results show that the identification of 5G service use by applying ML techniques offer a viable solution to classifying normal services from network traffic metadata alone. This has potential advantages in forecasting service demand for resource allocation in the dynamic 5GC environment and provide a baseline for performing anomaly detection of NF communication for detecting malicious traffic within the 5G Service Based Architecture (SBA).