Graph-based Anomaly Detection in 5G Core Networks - An Evaluation of Temporal Graph Neural Networks for detecting Multi-Step Attacks in Kubernetes-based 5G Core Networks
| dc.contributor.author | Sandell, Gustav | |
| dc.contributor.author | Nordin, Isak | |
| dc.contributor.department | Chalmers tekniska högskola / Institutionen för data och informationsteknik | sv |
| dc.contributor.department | Chalmers University of Technology / Department of Computer Science and Engineering | en |
| dc.contributor.examiner | Duvignau, Romaric | |
| dc.contributor.supervisor | Mansour Bahar, Atmane Ayoub | |
| dc.date.accessioned | 2026-08-31T11:21:50Z | |
| dc.date.issued | 2026 | |
| dc.date.submitted | ||
| dc.description.abstract | The increasing adoption of service-based and distributed architectures in 5G Core (5GC) networks has introduced new challenges for traditional intrusion detection systems (IDS), which often struggle to identify sophisticated, multi-stage attacks hidden within large volumes of network traffic. While many preventative measures exist to secure system perimeters, there are still scenarios where a malicious actor could gain access to a network. At the same time, Graph Neural Networks (GNNs) have demonstrated strong capabilities in modeling complex relationships and dependencies in networked graph structured data, making them a promising approach for detecting advanced cyber threats in highly interconnected systems. This thesis investigated the capability of GNN-based intrusion detection to identify multi-step attacks in the 5GC. Due to the lack of publicly available datasets containing such attacks in internal 5GC systems, a new dataset was developed by combining generated benign network traffic with a simulated multi-step attack targeting production components of the 5GC environment. A complete detection framework was designed and evaluated, including data pre processing, feature extraction, graph construction, and a GNN architecture. The model architecture consists of a Memory Module, Graph Convolutional Layers and a Edge-level Classification Head. Different architectures and configurations of the model were trained and tested on the data, with the highest stable scoring model having a median F1 Score of 99.55%, showing that it is possible for a graph-based model to detect attacks in a production-like 5GC test environment using simulated network data and a simulated multi-step attack. | |
| dc.identifier.coursecode | DATX05 | |
| dc.identifier.uri | https://hdl.handle.net/20.500.12380/312303 | |
| dc.language.iso | eng | |
| dc.setspec.uppsok | Technology | |
| dc.subject | Temporal Graph Neural Networks (TGN), Graph Neural Networks (GNN), Anomaly Detection, Intrusion Detection Systems (IDS), 5G Core Networks, Kubernetes, Cloud-Native Networks, Multi-Step Attack Detection | |
| dc.title | Graph-based Anomaly Detection in 5G Core Networks - An Evaluation of Temporal Graph Neural Networks for detecting Multi-Step Attacks in Kubernetes-based 5G Core Networks | |
| dc.type.degree | Examensarbete för masterexamen | sv |
| dc.type.degree | Master's Thesis | en |
| dc.type.uppsok | H | |
| local.programme | Computer systems and networks (MPCSN), MSc |
