2026· E3S Web of Conferences· 0 citations· 2 references
TL;DR
An AI-assisted, cross-layer security orchestration framework that integrates epoch-wise telemetry with ML-based risk estimation and formalizes mitigation as a Constrained Markov Decision Process (CMDP), and empirical evidence that adaptive mitigation can reduce security risk without sacrificing service guarantees is provided.
Abstract
5G networks increasingly rely on key enabling technologies such as Software-Defined Networking (SDN), Network Function Virtualization (NFV), Multi-Access Edge Computing (MEC), and end-to-end network slicing to deliver heterogeneous services with strict quality-of-service (QoS) guarantees. However, programmability, multi-tenancy, and distributed edge–cloud operation significantly expand the attack surface. At the same time, traditional rule-based and reactive security mechanisms remain slow to adapt and may violate latency constraints during mitigation. This paper addresses the problem of QoS-compliant, closed-loop security control for sliced SDN/NFV infrastructures. We propose an AI-assisted, cross-layer security orchestration framework that integrates epoch-wise telemetry with ML-based risk estimation and formalizes mitigation as a Constrained Markov Decision Process (CMDP). The CMDP controller selects enforceable actions— slice isolation, rate limiting, traffic rerouting, and key reconfiguration—while explicitly satisfying latency/overhead constraints, and executes them via SDN flow-rule updates and NFV policy/VNF reconfiguration. Simulation results over 50 decision epochs demonstrate effective response to an injected high-risk event: risk spikes to 0.95 at epoch 15, after which the controller drives risk toward ≈0.10 while maintaining latency below the 40ms QoS bound (with a transient rise during mitigation and subsequent stabilization). The reward trajectory briefly degrades during disruption but recovers and converges to a positive long-term return, indicating stable constraint-aware operation. This work provides (i) a deployable cross-layer orchestration architecture for sliced networks, (ii) a QoS-constrained CMDP decision model that converts risk signals into actionable SDN/NFV controls, and (iii) empirical evidence that adaptive mitigation can reduce security risk without sacrificing service guarantees.
: With the quick development of 5G networks, network slicing and Open Radio Access Network (O-RAN) have become key technologies for improving network resource-allocation efficiency and flexibility. However, network slicing also faces intrusion-detection challenges, particularly for detecting DDoS attacks, which are difficult to detect due to traffic being silently transmitted across multiple sub-slices. To address this problem, this paper proposes a 5G network slicing intrusion detection mechanism, called the DDoS Defense Model on 5G Network Slices (2D5NS) which integrates machine learning and real-time traffic monitoring techniques to detect and mitigate DDoS attacks within an O-RAN. This security system consists of a Random Forest (RF) classification model, which is deployed within the Service Management and Orchestration (SMO) of O-RAN to classify packets transmitted from UE to the RAN into eMBB, mMTC and uRLLC slices, and a detection approach comprising the XGBoost mechanism which monitors the traffic within each slice in real time to detect DDoS attacks issued by User Equipment (UE). Once traffic is abnormal, it triggers an Entropy Algorithm to identify the sources of the DDoS attacks. The simulation results of our second experiment show that the classification accuracies of RF classification model in its 3-fold Cross Validation (CV) for eMBB and mMTC training achieve 99.98%. In our third experiment, the detection accuracy of 2D5NS/XGBoost model on uRLLC reaches at least 93.43%. Several state-of-the-art systems are evaluated. Here, the conclusion is that the 2D5NS outperforms each of them and the 2D5NS can effectively mitigate and block DDoS attacks for network slices.
Kun-Lin Tsai, Shih-Ting Chiu, Chihhsiong Shih et al.· Computer Modeling in Enginee...· 0 citations
Central governance and flexible network administration are made possible by Software Defined Networking (SDN); still, this architectural benefit also makes the control plane vulnerable to Distributed Denial of Service (DDoS) attacks. An extreme number of flow requests and packet-in events can significantly reduce controller effectiveness and interfere with network functions in the context of such attacks. In this work, we change and estimate an adaptive DDoS prevention framework based on knowledge gained from SDN emulation tests. Relatively than relying on predetermined mitigation thresholds, the framework dynamically adjusts mitigation strategies based on the attack's severity and the controller's present load. The proposed approach reduces unnecessary interactions in the control plane while maintaining service quality for authorized traffic by incorporating controller-aware decision-making. The adaptive outline lessens controller CPU utilization, speeds up mitigation response times, lowers end-to-end latency, and keeps higher throughput when compared to static mitigation procedures, according to experimental evaluations carried out in a precise SDN emulation environment
Nirzari Patel, H. Patel· International journal of com...· 0 citations
Legacy Distributed Network Protocol 3 (DNP3) communications remain widely used in modem smart grids, but they expose geographically distributed power infrastructure to coordinated cyberattacks that combine protocol-level command abuse with network-layer disruption. These threats require a defense framework that can detect multi-class attacks with low latency while also reasoning over source authorization, command semantics, and topology context to produce safe, auditable mitigation actions. This thesis presents GridCAD-LLM, a distributed software-defined networking framework for resilient DNP3 defense that integrates cloud-assisted multiclass traffic detection, source-aware event interpretation, and topology-grounded policy synthesis through a large language model. The framework combines distributed ONOS controllers, an Atomix-backed consensus layer, and a cloud-hosted multilayer perceptron to detect ten DNP3 attack classes and coordinate mitigation across grid regions. For administrative command-abuse events involving masteronly function codes, GridCAD-LLM uses DNP3 command semantics, victim-response evidence, and live ONOS topology context to generate validated SDN enforcement blueprints under explicit safety constraints. Evaluation in a geo-distributed AWS-based testbed shows 99.5 percent classification accuracy for routine attack classes, cloud-offloaded inference latency under 100 ms, and coordinated policy-update latency below 15 ms. Across 100 balanced command-abuse simulations, the policy-synthesis pipeline achieves 99 percent correctness with average inference latency below 2 s, while live retrieval-augmented updates improve heldout correctness from 94 percent to 100 percent. These results show that GridCAD-LLM provides a resilient, explainable, and scalable foundation for securing DNP3-based smart-grid communications.
An Adaptive SDN-Edge 5G Architecture (ASE-5G) is proposed that integrates SDN programmability with edge-assisted control-plane coordination while preserving compatibility with the 3rd Generation Partnership Project (3GPP) service-based architecture.
Vivi Monita, Naufal Hanan, Lutfianto et al.· 0 citations
5G-Advanced (3GPP Release 18) architectural changes include multi-access edge computing (MEC) architectural changes, network automation, and non-public networks (NPNs). It is important to note that even though these advancements provide substantial performance advantages, they destroy fixed-perimeter security models, providing a distributed attack surface. The use of current security assessment strategies, which are usually non-fluid and isolated, is inadequate to offer the required runtime security health assurance needed in such fluid environments. This study presents a new security assurance framework (SAF) that would be used to provide ongoing evidence-based protection on core, edge, and private network domains. This framework employs a four-layer architecture, including monitoring, analytics (LM), policy engine, and enforcement, to convert security periodically audited to a dynamic threat-control-metric evidence chain. A 96% attack detection rate and a 99.8% reduction in response time (with a mean of 20.1 s) are proven by validation on an emulated 5G-Advanced testbed (approximating Release 18 features using Open5GS (v2.7.2 Rel-17, community developed, Seoul, Republic of Korea and custom extensions) based on a design science research (DSR) paradigm. Although the overhead (13% CPU, 21.4% memory) is manageable, the findings prove that all-time, multi-domain assurance is crucial to the healthy functioning of 5G-Advanced and is a key roadmap to autonomous 6G security.
E. Egho-Promise, Ekereuke Udoh, Edita Gashi et al.· Information· 0 citations
Results prove the combination of adaptive intelligence, secure virtualization, and dynamic policy enforcement boosts cybersecurity defenses in unique ways for programmable SDN and DCN infrastructures.
Hasan Alkahtani· JOIV: International Journal...· 0 citations