arXiv:2507.17850cs.CRcs.AI2025-07

研究大规模5G核心网在攻击下的性能与防护,提出资源差异化配置方案。

Performance Evaluation and Threat Mitigation in Large-scale 5G Core Deployment

  • 通过模拟分布式拒绝服务攻击,分析不同网络功能的注册性能影响。
  • 发现多样化的资源分配策略是保障服务协议合规的关键。
  • 验证内核级监控可实现可扩展的安全威胁防御,适合运维人员参考。

大规模软件化5G核心网部署面临显著挑战,因其服务依赖于优化和智能的资源分配。本文研究了由分布式拒绝服务(DDoS)攻击引发的混沌工作负载对不同网络功能(NFs)上用户设备注册性能的影响。结果表明,在大规模5G核心部署中,为保障服务等级协议(SLA)合规性,必须采用多样化的资源配置策略。此外,对包捕获方法的分析显示,基于内核的监控具有实现可扩展安全防御的潜力。最后,实证评估为复杂场景下5G NF的高效部署提供了关键见解。

原文摘要 · Abstract (English)

The deployment of large-scale software-based 5G core functions presents significant challenges due to their reliance on optimized and intelligent resource provisioning for their services. Many studies have focused on analyzing the impact of resource allocation for complex deployments using mathematical models, queue theories, or even Artificial Intelligence (AI). This paper elucidates the effects of chaotic workloads, generated by Distributed Denial of Service (DDoS) on different Network Functions (NFs) on User Equipment registration performance. Our findings highlight the necessity of diverse resource profiles to ensure Service-Level Agreement (SLA) compliance in large-scale 5G core deployments. Additionally, our analysis of packet capture approaches demonstrates the potential of kernel-based monitoring for scalable security threat defense. Finally, our empirical evaluation provides insights into the effective deployment of 5G NFs in complex scenarios.

5G核心网安全防御资源分配

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。