From Description to Detection: LLM based Extendable O-RAN Compliant Blind DoS Detection in 5G and Beyond

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Dayaratne, Thusitha, Pham, Ngoc Duy, Vo, Viet, Lai, Shangqi, Abuadbba, Sharif, Suzuki, Hajime, Yuan, Xingliang, Rudolph, Carsten
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866914080309116928
author Dayaratne, Thusitha
Pham, Ngoc Duy
Vo, Viet
Lai, Shangqi
Abuadbba, Sharif
Suzuki, Hajime
Yuan, Xingliang
Rudolph, Carsten
author_facet Dayaratne, Thusitha
Pham, Ngoc Duy
Vo, Viet
Lai, Shangqi
Abuadbba, Sharif
Suzuki, Hajime
Yuan, Xingliang
Rudolph, Carsten
contents The quality and experience of mobile communication have significantly improved with the introduction of 5G, and these improvements are expected to continue beyond the 5G era. However, vulnerabilities in control-plane protocols, such as Radio Resource Control (RRC) and Non-Access Stratum (NAS), pose significant security threats, such as Blind Denial of Service (DoS) attacks. Despite the availability of existing anomaly detection methods that leverage rule-based systems or traditional machine learning methods, these methods have several limitations, including the need for extensive training data, predefined rules, and limited explainability. Addressing these challenges, we propose a novel anomaly detection framework that leverages the capabilities of Large Language Models (LLMs) in zero-shot mode with unordered data and short natural language attack descriptions within the Open Radio Access Network (O-RAN) architecture. We analyse robustness to prompt variation, demonstrate the practicality of automating the attack descriptions and show that detection quality relies on the semantic completeness of the description rather than its phrasing or length. We utilise an RRC/NAS dataset to evaluate the solution and provide an extensive comparison of open-source and proprietary LLM implementations to demonstrate superior performance in attack detection. We further validate the practicality of our framework within O-RAN's real-time constraints, illustrating its potential for detecting other Layer-3 attacks.
format Preprint
id arxiv_https___arxiv_org_abs_2510_06530
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle From Description to Detection: LLM based Extendable O-RAN Compliant Blind DoS Detection in 5G and Beyond
Dayaratne, Thusitha
Pham, Ngoc Duy
Vo, Viet
Lai, Shangqi
Abuadbba, Sharif
Suzuki, Hajime
Yuan, Xingliang
Rudolph, Carsten
Cryptography and Security
Emerging Technologies
Machine Learning
Networking and Internet Architecture
The quality and experience of mobile communication have significantly improved with the introduction of 5G, and these improvements are expected to continue beyond the 5G era. However, vulnerabilities in control-plane protocols, such as Radio Resource Control (RRC) and Non-Access Stratum (NAS), pose significant security threats, such as Blind Denial of Service (DoS) attacks. Despite the availability of existing anomaly detection methods that leverage rule-based systems or traditional machine learning methods, these methods have several limitations, including the need for extensive training data, predefined rules, and limited explainability. Addressing these challenges, we propose a novel anomaly detection framework that leverages the capabilities of Large Language Models (LLMs) in zero-shot mode with unordered data and short natural language attack descriptions within the Open Radio Access Network (O-RAN) architecture. We analyse robustness to prompt variation, demonstrate the practicality of automating the attack descriptions and show that detection quality relies on the semantic completeness of the description rather than its phrasing or length. We utilise an RRC/NAS dataset to evaluate the solution and provide an extensive comparison of open-source and proprietary LLM implementations to demonstrate superior performance in attack detection. We further validate the practicality of our framework within O-RAN's real-time constraints, illustrating its potential for detecting other Layer-3 attacks.
title From Description to Detection: LLM based Extendable O-RAN Compliant Blind DoS Detection in 5G and Beyond
topic Cryptography and Security
Emerging Technologies
Machine Learning
Networking and Internet Architecture
url https://arxiv.org/abs/2510.06530