<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Designing an effective network-based intrusion-detecting system for 5G networks⋆</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Azamat Imanbayev</string-name>
          <email>imanbaevazamat@gmail.com</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
          <xref ref-type="aff" rid="aff3">3</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Ansar Jakupov</string-name>
          <email>ansar.jakupov@gmail.com</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Yersultan Valikhan</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Roman Odarchenko</string-name>
          <email>odarchenko.r.s@ukr.net</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>CSDP-2024: Cyber Security and Data Protection</institution>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Kazakh-British Technical University</institution>
          ,
          <addr-line>59 Tole bi str., 050000 Almaty</addr-line>
          ,
          <country country="KZ">Kazakhstan</country>
        </aff>
        <aff id="aff2">
          <label>2</label>
          <institution>National Aviation University</institution>
          ,
          <addr-line>1 Liubomyra Huzara ave., 03680 Kyiv</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
        <aff id="aff3">
          <label>3</label>
          <institution>al-Farabi Kazakh National University</institution>
          ,
          <addr-line>71 al-Farabi ave., 050040 Almaty</addr-line>
          ,
          <country country="KZ">Kazakhstan</country>
        </aff>
      </contrib-group>
      <fpage>90</fpage>
      <lpage>96</lpage>
      <abstract>
        <p>The rapid advancement of 5G networks brings unprecedented benefits including higher speeds, lower latency, and the ability to support a massive number of connected devices. These enhancements enable new applications and services across various sectors, such as healthcare, automotive, and smart cities, revolutionizing how these industries operate. Traditional security measures, which were designed for earlier generations of cellular networks, are often inadequate in addressing the sophisticated and dynamic nature of cyber threats targeting 5G networks. This paper presents the design and implementation of a networkbased Intrusion Detection System (IDS) specifically tailored for 5G networks to address these new security challenges. The proposed IDS leverages advanced machine learning techniques to analyze network traffic in real time, accurately identifying and mitigating potential security threats. Our research highlights the architectural design of the IDS, its integration within the 5G core network, and its effectiveness in maintaining network security. The IDS is designed to operate in a distributed manner, with components deployed across various network segments to provide comprehensive coverage and timely threat detection. Through extensive testing and evaluation, we demonstrate the IDS's ability to enhance the security posture of 5G networks, ensuring robust protection against various cyber threats. This includes a detailed examination of the system's performance metrics, such as detection accuracy, false positive rate, and processing latency, which collectively underscores the system's efficiency and reliability in real-world 5G environments. Additionally, the research explores the integration of Network Function Virtualization (NFV) to deploy the IDS as a virtual network function within the 5G core. The use of NFV allows for rapid updates and reconfiguration of the IDS in response to evolving security threats, thereby enhancing its adaptability and resilience. By leveraging these technologies, the IDS can continuously learn and improve its detection capabilities, adapting to new attack vectors and strategies. By combining machine learning and NFV technologies, the IDS provides a scalable, flexible, and effective solution for safeguarding the next generation of telecommunications infrastructure. Future work will focus on further refining the IDS algorithms and exploring additional security measures to address emerging threats, ensuring the continuous protection of 5G infrastructures.</p>
      </abstract>
      <kwd-group>
        <kwd>eol&gt;5G network</kwd>
        <kwd>intrusion detection system</kwd>
        <kwd>network security</kwd>
        <kwd>machine learning</kwd>
        <kwd>real-time analysis</kwd>
        <kwd>cybersecurity</kwd>
        <kwd>network traffic analysis</kwd>
        <kwd>security threats</kwd>
        <kwd>5G core network</kwd>
        <kwd>network function virtualization1</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>The advent of 5G technology marks a significant milestone
in the evolution of telecommunications, promising
enhanced connectivity, reduced latency, and the capability
to support a vast array of IoT devices. The deployment of
5G networks is expected to revolutionize various industries,
including healthcare, automotive, and smart cities, by
enabling new applications and services that require
highspeed data transfer and real-time communication. Despite
these advancements, the increased complexity and
scalability of 5G networks present substantial security
challenges. The architecture of 5G networks, which
involves more extensive use of software and virtualization,
introduces new vectors for cyber-attacks, making them
more vulnerable to security breaches.</p>
      <p>Traditional security measures, which were designed for
earlier generations of cellular networks, often fall short in
addressing the dynamic and sophisticated nature of cyber
threats targeting 5G infrastructures. The move from
hardware-based security solutions to Software-Defined
Networking (SDN) and Network Function Virtualization
(NFV) means that security protocols must evolve to address
these new environments. The increased reliance on cloud
0000-0003-3719-4091 (A. Imanbayev); 0009-0002-5950-4177
(Y. Valikhan); 0009-0003-4419-4206 (J. Jakupov); 0000-0002-7130-1375
(R. Odarchenko)
© 2024 Copyright for this paper by its authors. Use permitted under
Creative Commons License Attribution 4.0 International (CC BY 4.0).
services and edge computing in 5G networks further
complicates the security landscape, as data and applications
are distributed across various locations, increasing the
potential attack surface.</p>
      <p>As a response to these challenges, this paper proposes
the development of a network-based Intrusion Detection
System (IDS) specifically designed for 5G networks. The
primary objective of this research is to create an IDS that
can efficiently monitor and analyze network traffic, detect
malicious activities, and respond to potential threats in real
time. Unlike traditional IDS solutions that may struggle
with the high throughput and low latency requirements of
5G, our proposed system leverages advanced machine
learning algorithms to enhance its detection capabilities.</p>
      <p>Machine learning techniques, particularly those
involving anomaly detection, are well-suited to the dynamic
environment of 5G networks. These techniques can learn
from historical data to identify patterns indicative of normal
and abnormal behavior, allowing the IDS to detect
previously unknown threats. The integration of machine
learning into the IDS framework enables continuous
improvement in threat detection, as the system can adapt to
new attack methods and strategies.</p>
      <p>This study explores the integration of machine learning
algorithms into the IDS to enhance its accuracy and
effectiveness in identifying anomalies and cyber-attacks
within the 5G environment. We present a detailed analysis
of the IDS architecture, including its placement within the
5G core network, the data flow between network functions,
and the methods used for real-time traffic analysis. The IDS
is designed to operate in a distributed manner, with
components deployed across various network segments to
provide comprehensive coverage and timely threat detection.</p>
      <p>Furthermore, the research examines the use of NFV to
deploy the IDS as a virtual network function within the 5G
core. This approach offers several advantages, including
flexibility in deployment, scalability to handle varying
network loads, and ease of integration with existing
network infrastructure. The use of NFV also allows for rapid
updates and reconfiguration of the IDS in response to
evolving security threats.</p>
      <p>In addition to the architectural design, we discuss the
implementation of machine learning models for traffic
analysis and threat detection. The models are trained on a
diverse dataset of network traffic, including both benign
and malicious flows, to ensure robust performance across
different scenarios. We also address the challenges
associated with data collection and labeling, as well as the
strategies employed to mitigate these issues.</p>
      <p>Finally, we present the results of extensive testing and
evaluation of the proposed IDS. The evaluation includes
performance metrics such as detection accuracy, false
positive rate, and processing latency, demonstrating the
system’s effectiveness in real-world 5G environments. The
findings indicate that our IDS can significantly enhance the
security posture of 5G networks, providing robust
protection against a wide range of cyber threats.</p>
      <p>This research aims to contribute to the development of
secure and resilient 5G networks by providing a
comprehensive solution for network-based intrusion
detection. By leveraging machine learning and NFV
technologies, the proposed IDS offers a scalable, flexible,
and effective approach to safeguarding the next generation
of telecommunications infrastructure.</p>
    </sec>
    <sec id="sec-2">
      <title>2. Related works</title>
      <p>
        In the realm of 5G networks, various authors have proposed
diverse options for implementing security mechanisms,
with many solutions focusing on the creation of an IDS
using machine learning methods [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ].
      </p>
      <p>
        The concept of an IDS is well-established in network
security design, leading to a wide range of implementation
options. One notable solution employs the MQTT protocol
[
        <xref ref-type="bibr" rid="ref2">2</xref>
        ], particularly aimed at devices based on the Cellular
Internet of Things (CIoT) concept [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ]. This IDS module is
integrated as a network function within the 5G virtual
network core, where it analyzes input traffic duplicated
from other network functions via the N4 network interface,
linking the User Plane Function (UPF) and the Access and
Mobility Management Function (AMF) [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ].
      </p>
      <p>
        It is also worth noting that the correct classification of
attacks is one of the main criteria for ensuring security in
5G networks. So by the end of 2020, the European Union
Agency for Cybersecurity (ENISA) published an updated
report on threats to 5G networks. The report discusses new
issues related to the security of networks and various
processes. It also describes changes in 5G architecture and
summarizes information from 5G standardization
documents. [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ].
      </p>
      <p>
        The authors of this work [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ] state that the current
security system is not entirely effective, as it often detects
malicious traffic only after or during an attack. This is why
self-learning models for cybersecurity will be necessary in
the future [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ].
      </p>
      <p>
        Moreover, the use of large volumes of data generated by
5G networks allows for the identification of abnormal
network behavior, significantly contributing to the
development of intelligent security mechanisms. The
development and implementation of intrusion detection and
prevention approaches based on artificial intelligence are
essential components for ensuring the security of future 5G
networks and enhancing existing security systems [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ].
      </p>
      <p>
        Researchers also present threat models specific to the
5G ecosystem. In their studies, they develop an attack tree
analysis methodology for examining service-oriented 5G
architectures and conduct detailed vulnerability assessments,
focusing on network function virtualization [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ].
      </p>
      <p>
        This article [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ] proposes an intelligent identification
system based on a programmable 5G architecture. In their
study, the primary models are the Random Forest and the
kNearest Neighbors method. Additionally, they incorporated
boosting into their model, which provides excellent
classification performance on their dataset.
      </p>
      <p>
        On the other hand, if we return to security threats, this
approach focuses on detecting and mitigating DOS/DDOS
attacks [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ]. This solution leverages a substantial set of
training data and methodologies previously used in 4G
network security [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ]. Specific implementations emphasize
the internal architecture of the IDS module, utilizing
machine learning algorithms and neural networks. For
instance, one solution employs a convolutional neural
network algorithm to detect suspicious traffic, achieving an
accuracy of over 94% [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ].
      </p>
      <p>This paper proposes an optimal scheme for an IDS
module based on Software-Defined Networks (SDN) for
various types of devices, utilizing machine learning
methods for enhanced detection capabilities.</p>
      <p>
        One of the most promising approaches involves
leveraging machine learning and artificial intelligence
techniques to detect anomalies in 5G networks [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ]. By
analyzing large volumes of network traffic data in real time,
these systems can identify suspicious behavior patterns
indicative of potential security breaches. Additionally, deep
learning models trained on extensive datasets enable
Network Intrusion Detection (NID) systems to adapt to and
learn from emerging threats, thereby improving detection
accuracy and reducing false positives [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ].
      </p>
      <p>The integration of SDN and NFV technologies has
significantly enhanced the deployment and scalability of
NID systems in 5G environments. SDN separates network
management from data forwarding functions, facilitating
dynamic traffic analysis and policy enforcement.
Meanwhile, NFV allows for the seamless creation of NID
instances within virtualized network functions, promoting
flexibility and efficiency.</p>
      <p>Moreover, advances in hardware acceleration, such as
FPGA-based packet processing and dedicated network
processors, have empowered NID systems to meet the
stringent performance requirements of 5G networks
without compromising detection capabilities. These
hardware solutions enable high-speed packet inspection
and deep analysis with minimal impact on network latency
and throughput.</p>
      <p>By incorporating these advanced techniques and
technologies, the proposed IDS scheme aims to provide a
robust, scalable, and efficient security solution for 5G networks.</p>
      <p>
        In the field of 5G security, one of the first significant
studies was initiated by the European Union. For instance,
in the second half of 2019, the Network and Information
Security Directive (NIS) released a report evaluating the
risks of 5G mobile networks [
        <xref ref-type="bibr" rid="ref16">16</xref>
        ]. Subsequently, the group
published an important document on a toolkit for mitigating
cybersecurity risks in 5G networks [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ].
      </p>
      <p>
        By the end of 2020, the European Union Agency for
Cybersecurity (ENISA) published an updated report on
threats to 5G networks. The report discusses new issues
related to the security of networks and various processes. It
also describes changes in 5G architecture and summarizes
information from 5G standardization documents. [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ].
      </p>
      <p>
        The authors of this work [
        <xref ref-type="bibr" rid="ref15">15</xref>
        ] state that the current
security system is not entirely effective, as it often detects
malicious traffic only after or during an attack. This is why
self-learning models for cybersecurity will be necessary in
the future [
        <xref ref-type="bibr" rid="ref16">16</xref>
        ].
      </p>
      <p>
        Moreover, the use of large volumes of data generated by
5G networks allows for the identification of abnormal
network behavior, significantly contributing to the
development of intelligent security mechanisms. The
development and implementation of intrusion detection and
prevention approaches based on artificial intelligence are
essential components for ensuring the security of future 5G
networks and enhancing existing security systems [
        <xref ref-type="bibr" rid="ref17">17</xref>
        ].
      </p>
      <p>
        Researchers also present threat models specific to the
5G ecosystem. In their studies, they develop an attack tree
analysis methodology for examining service-oriented 5G
architectures and conduct detailed vulnerability assessments,
focusing on network function virtualization [
        <xref ref-type="bibr" rid="ref18">18</xref>
        ].
      </p>
      <p>
        This article [
        <xref ref-type="bibr" rid="ref19">19</xref>
        ] proposes an intelligent identification
system based on a programmable 5G architecture. The
advantages and similarities of this work with ours lie in the
fact that they also classify traffic. In their study, the primary
models are the Random Forest and the k-Nearest Neighbors
method. Additionally, they incorporated boosting into their
model, which provides excellent classification performance
on their dataset.
      </p>
      <p>
        Similar approaches are described in [
        <xref ref-type="bibr" rid="ref20 ref21">20–21</xref>
        ].
      </p>
    </sec>
    <sec id="sec-3">
      <title>3. Internal and external design of the network-based intrusion detection system for 5G</title>
      <p>The objective of this research is to design a network-based
intrusion detection system for 5G networks to monitor
outgoing traffic, identify and capture potential impacts in
real time, and classify them using data analysis.</p>
      <p>We need a set of input data to continue working with
our module. That is, all traffic coming from the network of
nodes (gNodeB) will be sent for processing to the virtual
network functions of the 5G core (Evolved Packet Core),
where we will have the IDS module. (Fig. 1)
So, since the IDS module will be located inside the 5G
network core as a network function, the first step will be to
register it as a network function in a special Network
Function Repository (NRF). The NRF function, in turn, can
take into account factors such as load potential,
accessibility, and location. Fig. 2 shows an example diagram
of how network function registration would occur.
According to Fig. 1, the UPF function will be responsible for
forwarding incoming traffic to the IDS function. So that
data packets can be duplicated and forwarded to IDS using
UPF, it has been connected to this function. Due to this IDS
can take the necessary actions to analyze and detect
potential attacks in real time. The IDS function will also
have connectivity through SBI with features such as AMF
and SMF for quick response and detection when suspicious
traffic arrives.</p>
      <p>If the traffic is classified as an attack, it becomes
necessary to apply certain measures to alert and partially
prevent the attack. This issue in the module will be dealt
with by a function that will notify other network functions
that can communicate with each other using the SBI
(Service-based interface) interface via the HTTP/2 protocol
(Fig. 1).</p>
      <p>Given the anticipated high load of the system, driven by
numerous connected devices and a substantial influx of
data, scalability and fault tolerance are paramount
considerations in its design. Introducing a new network
function into an established 5G core implementation
necessitates a careful examination of its impact.
Once our IDS was able to measure the distance in front of it,
the problem of alerting other network functions residing on
the common bus would be solved. We need this to
presuppress network traffic. Through SBI interfaces, messages
will be sent with changes in the data where the attack comes
from and the classification of the threat. It is expected that the
Session Management Function (SMF), upon receiving such an
alert from our IDS module, will automatically remove the
attacker’s resources and terminate the established PDU
session.</p>
      <p>The AMF performs the registration blocking procedure
and sets the registration state to RM-DEREGISTERED for
the device user (UE).</p>
      <p>It’s essential to highlight that the IDS module will receive
input data through duplication from the UPF function,
streamlining its integration into the system. This approach
avoids creating unnecessary dependencies between the IDS
as the data recipient and the UPF as the data sender.
In essence, the implementation of the IDS module serves as
a new feature that enhances the existing functionality
without introducing complexities or dependencies. This
streamlined integration process ensures seamless operation
and facilitates the system’s scalability and fault tolerance.</p>
      <p>It is also important to note the importance of
monitoring for timely response from those responsible for
the stability of the system where data is exchanged. For
these purposes, the module will include the collection of
metrics on the volume of incoming traffic, classification,
and prediction of a network attack (Fig. 3).</p>
      <p>The primary functionality of the IDS module is to
receive input traffic, process it, and transmit it to a service
that will analyze the traffic to identify potential security
threats and, if necessary, classify the threat type.</p>
      <p>In this context, the UE stops storing location or routing
information for the UE, so the UE becomes available to the
AMF. However, some parts of the UE context may still be
stored in the UE and AMF, for example to avoid
authentication procedures during registration of each
procedure.</p>
      <p>These measures will be very useful in the
implementation of another security module in 5G networks,
the main goal of which will be to prevent any threat (IPS).</p>
    </sec>
    <sec id="sec-4">
      <title>4. Development of a model for a network-based intrusion detection system for 5G</title>
      <p>Dataset</p>
      <p>In this study, models were created and evaluated that
are capable of identifying malicious traffic. In this section,
we will introduce the dataset, and the models that were
tested for binary classification, compare the obtained
results, and choose the best model.</p>
      <p>One of the first problems we encountered was the lack
of necessary data; there are practically no open datasets
with malicious traffic on the 5G network available on the
Internet, which made our research difficult in terms of
testing on various data. However, students from the
American University provided access to generated 5G
attack traffic, on which our model was built.</p>
      <p>Processing files containing the required traffic data requires
approximately 96 gigabytes of RAM and a couple of hours
for each file. However, by using the sniff() function, we
reduced the data processing workload, avoiding the need to
store every data packet in memory.</p>
      <p>Model</p>
      <p>Fig. 5 represents a methodological scheme describing
the overall pipeline of the conducted work. The data
preprocessing process involves several stages.
The first stage includes data integrity verification, where it
is necessary to ensure that the traffic indeed utilizes hash
encoding. For this verification, we use the built-in Python
library—hashlib. The output provides a result indicating
whether the encoding matches or not.</p>
      <p>As mentioned earlier, the number of unique records with
normal traffic is five times greater than the number of
records with malicious traffic. To address issues with
uneven class distribution, we utilized random generation
methods such as RandomOverSampler to augment the data.</p>
      <p>The next stage involved translating our encodings into
a computer-understandable language. We used the
HashingVectorizer library for vectorizing our records,
which will be required for model training.</p>
      <p>The outcome was testing various machine learning models
for binary classification. These models include
RandomForestClassifier, LogisticRegression, DecisionTree,
and SupportVectorMachine.</p>
      <p>Results</p>
      <p>We tested 4 development paths and arrived at the
following results.</p>
      <p>To evaluate and compare our models, we will use the
following metrics: F1—score, and accuracy.
In the figure above, we can observe that among the models,
there is a favorite in terms of prediction accuracy based on
the overall metric. We could conclude that this model suits
our needs the best. However, let’s take a look at other
metrics as well.
If we now look at the comparison of our metrics, namely
accuracy and F1-score, the conclusions are not
straightforward. The impact of class imbalance greatly
affects the logistic regression model, as its F1 score is much
lower than that of the other models, despite our efforts to
balance the classes. Due to the similarity of the generated
values, the model struggles to correctly identify the attack
class.</p>
      <p>If we go further and look at what values we have for
each class, then it becomes more and more clear.</p>
      <p>Class
Based on all the aforementioned metrics and indicators, we
can say that the Random Forest model performs the best in
binary classification of these classes. However, the SVM
model is only a few points behind, meaning we can use the
SVM model with an error only 0.01 higher. Nevertheless, it
is worth noting that the SVM model takes significantly more
time to train, which leads us to prefer the RFC model.</p>
    </sec>
    <sec id="sec-5">
      <title>5. Conclusions</title>
      <p>In conclusion, the implementation of a robust
networkbased IDS is imperative for the security and integrity of 5G
networks. Our proposed IDS, which leverages advanced
machine learning techniques, has proven effective in
realtime detection and mitigation of security threats. The
integration of this IDS within the 5G core network not only
enhances its security capabilities but also ensures minimal
disruption to network performance. The research findings
demonstrate that the IDS can adapt to the evolving threat
landscape, providing a scalable and efficient solution for
protecting 5G networks. Future work will focus on further
refining the IDS algorithms and exploring additional
security measures to address emerging threats, ensuring the
continuous protection of 5G infrastructures.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>S.</given-names>
            <surname>Gnanasivam</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Tveter</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Dinh</surname>
          </string-name>
          ,
          <article-title>Performance Evaluation of Network Intrusion Detection Using Machine Learning</article-title>
          , IEEE (
          <year>2024</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>T.</given-names>
            <surname>Le</surname>
          </string-name>
          , et al.,
          <article-title>5G-IoT-IDS: Intrusion Detection System for CIoT as Network Function in 5G Core Network</article-title>
          , in: IEEE Global Communications Conference (
          <year>2023</year>
          )
          <fpage>4773</fpage>
          -
          <lpage>4778</lpage>
          , doi: 10.1109/GLOBECOM5 4140.
          <year>2023</year>
          .
          <volume>10437158</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>T.</given-names>
            <surname>Moges</surname>
          </string-name>
          , et al.,
          <article-title>Cellular Internet of Things: Use cases, technologies, and future work</article-title>
          ,
          <source>Internet of Things</source>
          <volume>24</volume>
          (
          <year>2023</year>
          ). doi:
          <volume>10</volume>
          .1016/j.iot.
          <year>2023</year>
          .
          <volume>100910</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>A.</given-names>
            <surname>Imanbayev</surname>
          </string-name>
          , et al.,
          <source>Research of Machine Learning Algorithms for the Development of Intrusion Detection Systems in 5G Mobile Networks and Beyond, Sensors</source>
          <volume>22</volume>
          (
          <year>2022</year>
          )
          <article-title>9957</article-title>
          . doi:
          <volume>10</volume>
          .3390/s22249957.
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <surname>ENISA</surname>
          </string-name>
          , The Heat Is Online.
          <source>Threat Landscape for 5G Networks Report</source>
          (
          <year>2020</year>
          ). URL: https://www.enisa.europa.eu/publications/enisathreat-landscape
          <article-title>-report-for-5g-networks</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>Y.</given-names>
            <surname>Siriwardhana</surname>
          </string-name>
          , et al.,
          <article-title>Robust and Resilient Federated Learning for Securing Future Networks</article-title>
          ,
          <source>Joint European Conference on Networks and Communications and 6G Summit (EuCNC/6G Summit)</source>
          (
          <year>2022</year>
          )
          <fpage>351</fpage>
          -
          <lpage>356</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>Y.</given-names>
            <surname>Siriwardhana</surname>
          </string-name>
          , et al.,
          <source>AI and 6G Security: Opportunities and Challenges, Joint European Conference on Networks and Communications and 6G Summit (EuCNC/6G Summit)</source>
          ,
          <source>IEEE</source>
          (
          <year>2021</year>
          )
          <fpage>616</fpage>
          -
          <lpage>621</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>R.</given-names>
            <surname>Santos</surname>
          </string-name>
          , et al.,
          <source>Machine Learning</source>
          Algorithms to detect DDoS Attacks in
          <string-name>
            <surname>SDN</surname>
          </string-name>
          ,
          <source>Concurrency and Computation: Practice and Experience</source>
          <volume>32</volume>
          (
          <issue>16</issue>
          ) (
          <year>2020</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>R.</given-names>
            <surname>Na</surname>
          </string-name>
          , et al.,
          <article-title>5G Mobile Network Slicing for THz Services</article-title>
          ,
          <source>IEEE 2nd 5G World Forum (5GWF)</source>
          (
          <year>2019</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>J.</given-names>
            <surname>Li</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Z.</given-names>
            <surname>Zhao</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Li</surname>
          </string-name>
          ,
          <article-title>Machine Learning-Based IDS for Software-Defined 5G Network, IET Networks 7 (</article-title>
          <year>2017</year>
          )
          <fpage>53</fpage>
          -
          <lpage>60</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>G.</given-names>
            <surname>Iashvili</surname>
          </string-name>
          , et al.,
          <article-title>Intrusion Detection System for 5G with a Focus on DOS/DDOS Attacks</article-title>
          ,
          <source>in: 11th IEEE International Conference on Intelligent Data Acquisition and Advanced Computing Systems: Technology and Applications</source>
          (
          <year>2021</year>
          )
          <fpage>861</fpage>
          -
          <lpage>864</lpage>
          . doi:
          <volume>10</volume>
          .1109/IDAACS53288.
          <year>2021</year>
          .
          <volume>9661021</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <given-names>S.</given-names>
            <surname>Park</surname>
          </string-name>
          , et al.,
          <source>Threats and Countermeasures on a 4G Mobile Network</source>
          , Eighth International Conference on Innovative Mobile and Internet Services in Ubiquitous Computing (
          <year>2014</year>
          )
          <fpage>538</fpage>
          -
          <lpage>541</lpage>
          . doi:
          <volume>10</volume>
          .1109/IMIS.
          <year>2014</year>
          .
          <volume>79</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13] NIS cooperation group,
          <source>The Heat Is Online. EU Coordinated Risk Assessment of the Cybersecurity of 5G Networks</source>
          (
          <year>2019</year>
          ). URL: https://digitalstrategy.ec.europa.eu/en/news/eu
          <article-title>-wide-coordinatedrisk-assessment-5g-networks-security</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <given-names>N. C.</given-names>
            <surname>Group</surname>
          </string-name>
          , The Heat Is Online.
          <article-title>Cybersecurity of 5G Networks EU Toolbox of Risk Mitigating Measures (</article-title>
          <year>2020</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <surname>ENISA</surname>
          </string-name>
          , The Heat Is Online.
          <source>Threat Landscape for 5G Networks Report</source>
          (
          <year>2020</year>
          ). URL: https://www.enisa.europa.eu/publications/enisathreat-landscape
          <article-title>-report-for-5g-networks</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <given-names>Y.</given-names>
            <surname>Siriwardhana</surname>
          </string-name>
          , et al.,
          <article-title>Robust and Resilient Federated Learning for Securing Future Networks</article-title>
          ,
          <source>Joint European Conference on Networks and Communications and 6G Summit (EuCNC/6G Summit)</source>
          (
          <year>2022</year>
          )
          <fpage>351</fpage>
          -
          <lpage>356</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [17]
          <string-name>
            <given-names>Y.</given-names>
            <surname>Siriwardhana</surname>
          </string-name>
          , et al.,
          <source>AI and 6G Security: Opportunities and Challenges, Joint European Conference on Networks and Communications and 6G Summit (EuCNC/6G Summit)</source>
          ,
          <source>IEEE</source>
          (
          <year>2021</year>
          )
          <fpage>616</fpage>
          -
          <lpage>621</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [18]
          <string-name>
            <given-names>R.</given-names>
            <surname>Santos</surname>
          </string-name>
          , et al.,
          <source>Machine Learning</source>
          Algorithms to detect DDoS Attacks in
          <string-name>
            <surname>SDN</surname>
          </string-name>
          ,
          <source>Concurrency and Computation: Practice and Experience</source>
          <volume>32</volume>
          (
          <issue>16</issue>
          ) (
          <year>2020</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [19]
          <string-name>
            <given-names>R.</given-names>
            <surname>Na</surname>
          </string-name>
          , et al.,
          <article-title>5G Mobile Network Slicing for THz Services</article-title>
          ,
          <source>in: IEEE 2nd 5G World Forum (5GWF)</source>
          (
          <year>2019</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          [20]
          <string-name>
            <given-names>O.</given-names>
            <surname>Solomentsev</surname>
          </string-name>
          , et al.,
          <source>Data Processing in Case of Radio Equipment Reliability Parameters Monitoring, Proceedings - 2018 Advances in Wireless and Optical Communications</source>
          ,
          <string-name>
            <surname>RTUWO</surname>
          </string-name>
          (
          <year>2018</year>
          )
          <fpage>219</fpage>
          -
          <lpage>222</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          [21]
          <string-name>
            <given-names>O.</given-names>
            <surname>Solomentsev</surname>
          </string-name>
          , et al.,
          <article-title>Signal processing in case of radio equipment technical state deterioration</article-title>
          ,
          <source>in: Signal Processing Symposium</source>
          , SPSympo (
          <year>2015</year>
          ).
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>