Thursday, September 24, 2026
Science
No Result
View All Result
  • Login
  • HOME
  • SCIENCE NEWS
  • CONTACT US
  • HOME
  • SCIENCE NEWS
  • CONTACT US
No Result
View All Result
Scienmag
No Result
View All Result
Home Science News Technology and Engineering

New Open-Source Simulator Generates Labeled DDoS Attack Data for 5G Networks

September 24, 2026
in Technology and Engineering
Hailey Crawford
By Hailey Crawford Scienmag Editorial Profile - Cybersecurity
Reading Time: 5 mins read
0
New Open-Source Simulator Generates Labeled DDoS Attack Data for 5G Networks

New Open-Source Simulator Generates Labeled DDoS Attack Data for 5G Networks

New Open-Source Simulator Generates Labeled DDoS Attack Data for 5G Networks

65
SHARES
587
VIEWS
Share on FacebookShare on Twitter
ADVERTISEMENT

Every connected car, smart meter, and industrial sensor riding on a 5G network is a potential foot soldier for a botnet. Distributed denial-of-service attacks, in which thousands of compromised devices flood a target with junk traffic, are among the most damaging threats to modern telecommunications infrastructure, and the machine-learning systems designed to catch them are only as good as the data they are trained on. Now, a researcher has released an open-source simulation framework that lets security teams manufacture realistic, precisely labeled DDoS attack datasets inside a fully simulated 5G network, without touching a single live base station.

The framework, called DDoSimu5G, is described in the journal SoftwareX by Karim Khalil, who reports support from the ELLIIT and WASP research programs. Version 2.0 of the tool is built as a layered extension of three established open-source platforms: the OMNeT++ discrete-event simulation kernel, the INET networking framework, and Simu5G, which models the 5G New Radio protocol stack including gNodeB base stations, NR-capable user equipment, and the User Plane Function with GTP-U tunneling. On top of that foundation, DDoSimu5G adds four new layers of its own: a common utilities layer, an application layer of benign and adversarial traffic generators, a controller layer that orchestrates attacks, and a configuration layer driven by declarative JSON files.

What makes the framework unusual is the care it takes with ground truth. Machine-learning intrusion detectors need to know, packet by packet, which traffic is benign and which is malicious, and existing approaches to obtaining that knowledge are awkward. Real 5G testbeds built on open-source stacks such as OpenAirInterface, Open5GS, or Free5GC offer high protocol fidelity but require external attack scripts, manual synchronization of attack periods, and post-hoc labeling. Standard simulators such as NS-3 and Simu5G are repeatable and controllable, but they do not natively support DDoS orchestration or integrated labeling. Tools like the Intrusion Detection Dataset Toolkit can inject malicious traffic into existing traces, but they depend on externally captured data rather than traffic generated inside a configurable 5G environment.

DDoSimu5G attacks the problem from both ends of the labeling pipeline. Every malicious packet carries an attack-type identifier directly in the IPv4 Type of Service field, a technique the author calls in-band labeling. Because the marker rides inside the packet header and survives GTP-U encapsulation, analysts can classify packets straight from the PCAP capture without relying on timestamp correlation, a process that becomes unreliable under scheduling variability or packet loss. In parallel, the framework writes out-of-band CSV annotations recording transmission direction, traffic type, spoofing status, and attack labels, preserving application-level context that cannot fit in a header. After the simulation, an offline script converts the TOS-marked captures into labeled CSVs and automatically zeroes the TOS, DSCP, and ECN fields, preventing the artificial ground-truth markers from leaking into the feature sets used to train detectors.

The framework also cleanly separates two concepts that are often conflated: attacks and infections. An attack is the traffic behavior executed by a compromised device, such as a UDP flood or a TCP SYN flood, while an infection is the moment a previously benign user equipment transitions to an adversarial state. Because these are configured independently, researchers can stage botnet-style campaigns in which devices turn hostile at staggered times, run multiple concurrent attack styles, and mix benign and adversarial traffic on the very same device. A centralized DataTrafficController reads an external infection timeline and schedules per-device state transitions at exact simulation times, instantiating the appropriate attack application from the device’s JSON profile.

Four attack models ship with the framework, reflecting behaviors observed in IoT malware families such as Bashlite and Satori: volumetric UDP floods, resource-exhausting TCP SYN floods, reflection-based DNS amplification, and application-layer HTTP floods. Each attack’s intensity over time is modeled as a configurable rate function, with constant, ramping, pulsing, and slow-rate temporal patterns, and transmission modes that determine whether benign traffic continues, stops, or is reduced during the attack. The framework even handles a subtle but important detail: it suppresses the artificial reply traffic that servers would otherwise generate in response to spoofed packets, such as DNS responses to forged queries or TCP reset packets to spoofed SYN segments, which would otherwise distort the captured traffic distributions.

To demonstrate the framework end to end, the paper walks through a 31-device scenario spanning five gNodeBs, a two-tier UPF architecture, and five backend servers, with devices playing roles ranging from industrial sensors and wearable health monitors to connected vehicles, drone controllers, and asset trackers. Thirteen of the devices carry both benign and adversarial profiles, while eighteen remain purely benign. Infections are staggered from 50 seconds to 340 seconds into the 600-second simulation, and each infected device is assigned one of the four attack types with a distinct temporal style and transmission mode. The result is a dataset of 336,751 packets and roughly 161 megabytes of traffic, of which 27.8 percent is malicious, all generated in 205 seconds of wall-clock time, about 2.93 times faster than real time, with peak memory usage below 132 megabytes.

The consistency checks are where the framework earns its credibility. Packet counts in the UPF capture matched application-layer label records to within 2.8 percent overall, with discrepancies attributable to ordinary TCP control behavior, retransmissions, and timing differences between capture points. More strikingly, because the gNodeB and the UPF observe the same uplink packets before and after GTP-U decapsulation, per-attack-type counts must agree across the two vantage points, and they did exactly: a ratio of 1.000 and a cosine similarity of 1.0000 across all four attack classes. The dual-vantage capture design itself is a research asset, letting analysts study how identical attack traffic appears at the radio edge and at the core network simultaneously.

The framework’s authors also showed that the output plugs directly into conventional intrusion-detection workflows. After stripping the PPP framing that Simu5G’s packet recorder emits, the sanitized UPF capture was processed with the Argus flow tool, yielding 21,125 bidirectional flows, every one of which was successfully matched to its ground-truth label using 5-tuple matching, for 100 percent label-mapping coverage. The per-class flow statistics tell intuitive stories: TCP SYN floods produce short single-packet flows with no return traffic, while HTTP, UDP, and DNS attacks produce distinctive packet counts, durations, and byte volumes, and benign communication shows traffic in both directions. Crucially, because the internal TOS marker is sanitized before feature extraction, the resulting flow records carry no trace of the framework’s artificial labeling channel.

The tool has honest limitations. Source-address spoofing is represented semantically in the CSV labels rather than by rewriting IPv4 headers, since the underlying network configurator binds each module’s address to its interface, a constraint that mirrors real 5G networks where the User Plane Function enforces uplink source verification; researchers who want spoofed headers must apply them as a separate post-processing step. The framework currently covers only unencrypted user-plane traffic and does not model 5G control-plane attacks such as PFCP exploitation or network-slicing abuse. Planned extensions include MQTT, CoAP, and QUIC traffic models and systematic quality comparisons against established benchmark datasets such as 5G-NIDD, CIC-DDoS2019, and UNSW-NB15. Even so, the release fills a genuine gap: rather than forcing security researchers to choose between fixed public datasets and laboriously orchestrated testbed experiments, DDoSimu5G lets them generate controlled, reproducible, and endlessly variable labeled DDoS datasets on demand, all under an LGPL-3.0 license with the code and a reproducible capsule publicly available.

Subject of Research: A simulation framework for generating labeled DDoS traffic datasets in 5G networks

Article Title: DDoSimu5G: A simulation framework for generating labeled DDoS traffic datasets in 5G network

Article References: Khalil, K. (2026). DDoSimu5G: A simulation framework for generating labeled DDoS traffic datasets in 5G network. SoftwareX, 36, Article 103053. https://doi.org/10.1016/j.softx.2026.103053

Image Credits: AI Generated

DOI: 10.1016/j.softx.2026.103053

Keywords: DDoS, 5G, network security, intrusion detection, simulation, OMNeT++, Simu5G, IoT, botnet, machine learning, open source, labeled datasets

Cite Scienmag News

Hailey Crawford. (September 24, 2026). New Open-Source Simulator Generates Labeled DDoS Attack Data for 5G Networks. Scienmag. https://scienmag.com/new-open-source-simulator-generates-labeled-ddos-attack-data-for-5g-networks/

Hailey Crawford. "New Open-Source Simulator Generates Labeled DDoS Attack Data for 5G Networks." Scienmag, 24 September 2026, https://scienmag.com/new-open-source-simulator-generates-labeled-ddos-attack-data-for-5g-networks/. Accessed 24 September 2026.

Hailey Crawford. "New Open-Source Simulator Generates Labeled DDoS Attack Data for 5G Networks." Scienmag. September 24, 2026. https://scienmag.com/new-open-source-simulator-generates-labeled-ddos-attack-data-for-5g-networks/

Tags: 5G5G network simulation5G protocol stack modelingbotnetDDoSDDoS attack detection in telecommunicationsdiscrete-event network simulation toolsindustrial IoT security and DDoS threatsintrusion detectionIoTlabeled cybersecurity datasets for machine learninglabeled datasetslayered simulation frameworks for 5GMachine learningmachine learning cybersecurity for 5Gmodeling botnet behavior in 5G networksnetwork securityOMNeT++open-sourceopen-source DDoS attack dataset generationopen-source network security research toolsrealistic network attack simulationSimu5Gsimulation
Share26Tweet16
Previous Post

Chinese Herbal Medicine Linked to Lower Death Risk in Acquired Hemolytic Anemia

Next Post

Buffalo Milk RNA Reveals the Metabolic Signature of High-Yield Dairy Animals

Related Posts

New Deterministic Algorithm Tames the Combinatorial Chaos of Regression Subset Selection
Technology and Engineering

New Deterministic Algorithm Tames the Combinatorial Chaos of Regression Subset Selection

September 24, 2026
Pregnancy Complications and Sex Reshape How Body Weight Drives Childhood Blood Pressure
Technology and Engineering

Pregnancy Complications and Sex Reshape How Body Weight Drives Childhood Blood Pressure

September 24, 2026
Teaching Machines to See and Say Defects: New AI Network Fuses Images with Language for Factory Inspections
Technology and Engineering

Teaching Machines to See and Say Defects: New AI Network Fuses Images with Language for Factory Inspections

September 24, 2026
Water Erodes the Hidden Glue Holding Tunnel Repairs Together, Study Finds
Technology and Engineering

Water Erodes the Hidden Glue Holding Tunnel Repairs Together, Study Finds

September 24, 2026
AI Agents Are Being Graded Wrong: Landmark Audit Finds No Benchmark Controls All Key Threats
Technology and Engineering

AI Agents Are Being Graded Wrong: Landmark Audit Finds No Benchmark Controls All Key Threats

September 24, 2026
Graphene’s Strange ‘Failed Superconductor’ Finally Caught in the Act
Medicine

Graphene’s Strange ‘Failed Superconductor’ Finally Caught in the Act

September 24, 2026
Next Post
Buffalo Milk RNA Reveals the Metabolic Signature of High-Yield Dairy Animals

Buffalo Milk RNA Reveals the Metabolic Signature of High-Yield Dairy Animals

  • Mothers who receive childcare support from maternal grandparents show more optimized

    Mothers who receive childcare support from maternal grandparents show more parental warmth, finds NTU Singapore study

    27656 shares
    Share 11059 Tweet 6912
  • University of Seville Breaks 120-Year-Old Mystery, Revises a Key Einstein Concept

    1061 shares
    Share 424 Tweet 265
  • Bee body mass, pathogens and local climate influence heat tolerance

    682 shares
    Share 273 Tweet 171
  • Researchers record first-ever images and data of a shark experiencing a boat strike

    546 shares
    Share 218 Tweet 137
  • Groundbreaking Clinical Trial Reveals Lubiprostone Enhances Kidney Function

    531 shares
    Share 212 Tweet 133
Science

Embark on a thrilling journey of discovery with Scienmag.com—your ultimate source for cutting-edge breakthroughs. Immerse yourself in a world where curiosity knows no limits and tomorrow’s possibilities become today’s reality!

RECENT NEWS

  • Neutrophil Traps and Inflammatory Macrophages Team Up in Failing Hearts
  • Sacred Lotus Gene Offers New Shield Against Cadmium’s Toxic Grip
  • New Deterministic Algorithm Tames the Combinatorial Chaos of Regression Subset Selection
  • Buffalo Milk RNA Reveals the Metabolic Signature of High-Yield Dairy Animals

Categories

  • Agriculture
  • Anthropology
  • Archaeology
  • Athmospheric
  • Biology
  • Biotechnology
  • Blog
  • Bussines
  • Cancer
  • Chemistry
  • Climate
  • Earth Science
  • Editorial Policy
  • Marine
  • Mathematics
  • Medicine
  • Pediatry
  • Policy
  • Psychology & Psychiatry
  • Science Education
  • Social Science
  • Space
  • Technology and Engineering

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 5,151 other subscribers

© 2025 Scienmag - Science Magazine

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • HOME
  • SCIENCE NEWS
  • CONTACT US

© 2025 Scienmag - Science Magazine

Discover more from Science

Subscribe now to keep reading and get access to the full archive.

Continue reading