NCSRD-DS-5GDDoS: 5G Radio and Core metrics containing sporadic DDoS attacks
收藏资源简介:
NCSRD-DS-5GDDoS is a comprehensive dataset recorded in a real-world 5G testbed that aligns with the 3GPP specifications. The dataset captures Distributed Denial of Service (DDoS) attacks initiated by malicious connected UEs. The setup comprises of 2 cells with a total of 9 UEs connected to the same core network. The 5G network is implemented by the Amarisoft Callbox Mini solution, and we further employ a second cell using the Amarisoft Classic, that also hosts the 5G core. The setup utilizes a broad set of UE devices comprising a set of smart phones (Huawei P40), microcomputers (Raspberry Pi 4 - Waveshare 5G Hat M2), industrial 5G routers (Industrial Waveshare 5G Router), a WiFi-6 mobile hotspot (DWR-2101 5G Wi-Fi 6 Mobile Hotspot) and a CPE box (Waveshare 5G CPE Box). All UEs are being operated by subsidiary hosts which are responsible for the traffic generation, occurring from scheduled communications times. All identifiers are artificially generated and do not represent or based on personal data. We identify each UE through its ‘imeisv’ ID, that corresponds to the device in use, due to vendor implementation, that uses the same IMSI for all UEs. There are 8 attacker UEs in the testbed and 1 benign user with imeisv = 8609960480666910. The benign user streams YouTube traffic, while the malicious users are performing two DDoS attacks (UDP floods using hping3); the first attack takes place on 24-01-2024 between 14:48:30-14:58:30 and the second one on 25-01-2014 between 14:05:00-14:10:00. Throughout the recording session, handover events also take place. The dataset is recorded through the use of a data collector that interfaces with the 5G network and gathers data regarding UEs, gNBs and the Core Network. The data are recorded in an InfluxdB and pre-processed into three separate tabular .csv files for more efficient processing: “amari_ue_data.csv”, “enb_counters.csv” and “mme_counters.csv”. The ”amari_ue_data.csv” consists of 56 features, providing information on the UEs regarding identification (“imeisv”, “5g_tmsi”, “rnti”), IP addressing, bearer information, cell information (“tac”, “ran_plmn”), and cell information (“cell_X_ul_bitrate”, “cell_X_dl_bitrate”, “cell_id”, retransmissions per user per cell “cell_X_ul_retx” as well as aggregated bit rates for each cell). The ”enb_counters.csv” focuses on cell-level information, providing downlink and uplink bitrates, usage ratio per user, cpu load of the gNB. The “mme_counters.csv” provides information on the Non-Access Stratum (NAS) of the 5G Network and focuses on session status reports (e.g., number of PDU session establishments, paging, context setup. This part gives an overview of the connection management throughout the recording session, and provides information on features suggested by 3GPP for abnormal user behaviour, as we summarized in Table II of this work. A description of the majority of features below can be found in https://tech-academy.amarisoft.com/ See README.TXT for the list of features in each file.
NCSRD-DS-5GDDoS是一款贴合3GPP规范、基于真实5G测试床搭建的综合性数据集。该数据集捕获了由恶意联网用户设备(UE,User Equipment)发起的分布式拒绝服务(DDoS,Distributed Denial of Service)攻击流量。 本次测试搭建包含2个蜂窝小区,总计9台用户设备接入同一核心网络。该5G网络采用Amarisoft Callbox Mini方案实现,此外还额外使用Amarisoft Classic搭建了第二个蜂窝小区,同时承载5G核心网功能。 本次测试使用了多样化的用户设备终端,包括华为P40智能手机、树莓派4(搭载Waveshare 5G Hat M2扩展板)微型计算机、工业级Waveshare 5G路由器、DWR-2101 5G Wi-Fi 6移动热点,以及Waveshare 5G CPE盒式终端。所有用户设备均由附属主机驱动,按照预设通信时序生成测试流量。 所有标识均为人工生成,未关联真实个人数据。由于厂商实现逻辑,本次测试中所有用户设备使用相同的国际移动用户识别码(IMSI,International Mobile Subscriber Identity),因此通过"imeisv"标识来区分每台用户设备,该标识对应实际使用的终端设备。 本次测试中共包含8台恶意攻击用户设备与1台良性用户设备,其imeisv值为8609960480666910。良性用户设备播放YouTube流量,恶意用户则通过hping3工具发起两种DDoS攻击(UDP洪泛攻击):首次攻击发生于2024年1月24日14:48:30至14:58:30,第二次攻击发生于2014年1月25日14:05:00至14:10:00。在整个数据采集周期内,测试床还发生了蜂窝小区切换事件。 该数据集通过与5G网络对接的数据采集终端完成录制,采集内容涵盖用户设备、下一代基站(gNB,next generation Node B)以及核心网络的相关数据。采集数据先存储于InfluxDB时序数据库,随后预处理为三个独立的表格式CSV文件以提升后续处理效率,分别为"amari_ue_data.csv"、"enb_counters.csv"与"mme_counters.csv"。 "amari_ue_data.csv"包含56项特征,涵盖用户设备标识相关信息(如"imeisv"、"5g_tmsi"、"rnti")、IP地址配置、承载网信息、蜂窝小区信息(如"tac"、"ran_plmn")、单小区上下行比特速率("cell_X_ul_bitrate"、"cell_X_dl_bitrate")、小区标识("cell_id")、单用户单小区重传次数("cell_X_ul_retx")以及各蜂窝小区的聚合比特速率等内容。 "enb_counters.csv"聚焦于蜂窝小区级别的数据,提供上下行比特速率、单用户资源占用率以及下一代基站CPU负载等信息。 "mme_counters.csv"涵盖5G网络的非接入层(NAS,Non-Access Stratum)相关信息,重点关注会话状态报告(如PDU会话建立次数、寻呼次数、上下文建立次数等)。该部分记录了整个采集周期内的连接管理状态,并提供了3GPP规范中提及的异常用户行为相关特征,对应本文表II中的汇总内容。 大部分特征的详细说明可参考https://tech-academy.amarisoft.com/,各文件包含的特征列表请参阅README.TXT。




