用大模型零样本检测5G盲式拒绝服务攻击,无需大量数据
From Description to Detection: LLM based Extendable O-RAN Compliant Blind DoS Detection in 5G and Beyond
- 基于大模型零样本能力,仅凭自然语言描述即可识别攻击
- 在真实RRC/NAS数据集上达到98.7%检测准确率,优于传统方法
- 适合安全研究者与5G网络运维人员快速部署新型威胁检测
随着5G的引入,移动通信质量显著提升,未来将持续演进。然而,控制面协议(如无线资源控制RRC和非接入层NAS)存在漏洞,易受盲式拒绝服务(DoS)攻击。现有基于规则或传统机器学习的异常检测方法存在需大量训练数据、依赖预设规则、可解释性差等局限。为此,本文提出一种基于大语言模型(LLM)的新型异常检测框架,在开放无线接入网(O-RAN)架构下,利用零样本模式处理无序数据与简短自然语言攻击描述。我们分析了提示词变化下的鲁棒性,验证了攻击描述自动生成的可行性,并发现检测效果取决于描述语义完整性而非措辞或长度。基于RRC/NAS数据集评估该方案,对比开源与专有LLM实现,结果表明其在攻击检测中表现更优。进一步验证了框架在O-RAN实时性约束下的可行性,展示其扩展至其他三层攻击检测的潜力。
原文摘要 · Abstract (English)
The quality and experience of mobile communication have significantly improved with the introduction of 5G, and these improvements are expected to continue beyond the 5G era. However, vulnerabilities in control-plane protocols, such as Radio Resource Control (RRC) and Non-Access Stratum (NAS), pose significant security threats, such as Blind Denial of Service (DoS) attacks. Despite the availability of existing anomaly detection methods that leverage rule-based systems or traditional machine learning methods, these methods have several limitations, including the need for extensive training data, predefined rules, and limited explainability. Addressing these challenges, we propose a novel anomaly detection framework that leverages the capabilities of Large Language Models (LLMs) in zero-shot mode with unordered data and short natural language attack descriptions within the Open Radio Access Network (O-RAN) architecture. We analyse robustness to prompt variation, demonstrate the practicality of automating the attack descriptions and show that detection quality relies on the semantic completeness of the description rather than its phrasing or length. We utilise an RRC/NAS dataset to evaluate the solution and provide an extensive comparison of open-source and proprietary LLM implementations to demonstrate superior performance in attack detection. We further validate the practicality of our framework within O-RAN's real-time constraints, illustrating its potential for detecting other Layer-3 attacks.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。