Login | Register

Intelligent Anomaly Detection for 5G & Beyond: Securing Service-Based Architecture Against HTTP/2-Driven Attacks

Title:

Intelligent Anomaly Detection for 5G & Beyond: Securing Service-Based Architecture Against HTTP/2-Driven Attacks

Wehbe, Nathalie (2025) Intelligent Anomaly Detection for 5G & Beyond: Securing Service-Based Architecture Against HTTP/2-Driven Attacks. PhD thesis, Concordia University.

[thumbnail of Wehbe_PhD_S2025.pdf]
Preview
Text (application/pdf)
Wehbe_PhD_S2025.pdf - Accepted Version
Available under License Spectrum Terms of Access.
5MB

Abstract

The Fifth Generation (5G) networks power diverse applications, from autonomous vehicles to smart cities, by enabling ultra-reliable low-latency communications, massive IoT connectivity, and enhanced mobile broadband. At the core of this advancement is the 5G Service-Based Architecture (SBA), which ensures scalability and flexibility through cloud-native deployment and virtualized Network Functions (NFs). The adoption of the Hypertext Transfer Protocol version 2 (HTTP/2) in the 5G SBA has become essential for enabling efficient communication between NFs. However, the adoption of HTTP/2 for NF communication introduces security risks, including stream multiplexing, slow-rate, and rapid-reset attacks, which can lead to Denial of Service (DoS) and disrupt critical services. Addressing these vulnerabilities is essential to maintaining the stability and security of 5G networks.
This thesis explores the impact of HTTP/2 vulnerabilities on the 5G SBA, identifying attack vectors that compromise the Quality of Service (QoS) of critical services. While prior studies largely assessed these threats theoretically, this research demonstrates the practical vulnerabilities of 5G networks to HTTP/2 attacks, such as Stream Multiplexing Attacks (SMAs). To address these challenges, the thesis introduces 5GShield, an application layer anomaly detection solution using autoencoder-based Machine Learning (ML). By profiling normal NF behavior with application-layer features, 5GShield effectively detects deviations indicative of SMAs. Building on this, 5GGuardian is proposed as a more advanced solution to detect nuanced variations of SMAs. Leveraging 5G-Stream features and a time-series transformer, 5GGuardian captures fine-grained NF behaviors and complex patterns in HTTP/2 streams, achieving superior accuracy for both stealthy and non-stealthy anomalies. Recognizing the limitations of single detection approaches, the research introduces an ensemble learning-based solution that leverages and combines the strengths of multiple ML models trained on different feature sets in order to provide superior detection performance of HTTP/2 attacks, including slow-rate and rapid-reset attacks. By providing scalable and advanced anomaly detection, this thesis strengthens 5G SBA security, ensuring reliable service delivery and supporting the secure growth of future communication networks.

Divisions:Concordia University > Gina Cody School of Engineering and Computer Science > Concordia Institute for Information Systems Engineering
Item Type:Thesis (PhD)
Authors:Wehbe, Nathalie
Institution:Concordia University
Degree Name:Ph. D.
Program:Information and Systems Engineering
Date:3 February 2025
Thesis Supervisor(s):Assi, Chadi and Assem Alameddine, Hyame
Keywords:5G networks, 5G security, HTTP/2, HTTP/2 attacks, 5G SBA security, 5G dataset, machine learning, anomaly detection, time series transformer, ensemble learning, application-layer features
ID Code:995162
Deposited By: Nathalie Wehbe
Deposited On:17 Jun 2025 14:58
Last Modified:01 Jul 2025 00:00
All items in Spectrum are protected by copyright, with all rights reserved. The use of items is governed by Spectrum's terms of access.

Repository Staff Only: item control page

Downloads per month over past year

Research related to the current document (at the CORE website)
- Research related to the current document (at the CORE website)
Back to top Back to top