Graph-based Anomaly Detection in 5G Core Networks - An Evaluation of Temporal Graph Neural Networks for detecting Multi-Step Attacks in Kubernetes-based 5G Core Networks

dc.contributor.authorSandell, Gustav
dc.contributor.authorNordin, Isak
dc.contributor.departmentChalmers tekniska högskola / Institutionen för data och informationstekniksv
dc.contributor.departmentChalmers University of Technology / Department of Computer Science and Engineeringen
dc.contributor.examinerDuvignau, Romaric
dc.contributor.supervisorMansour Bahar, Atmane Ayoub
dc.date.accessioned2026-08-31T11:21:50Z
dc.date.issued2026
dc.date.submitted
dc.description.abstractThe increasing adoption of service-based and distributed architectures in 5G Core (5GC) networks has introduced new challenges for traditional intrusion detection systems (IDS), which often struggle to identify sophisticated, multi-stage attacks hidden within large volumes of network traffic. While many preventative measures exist to secure system perimeters, there are still scenarios where a malicious actor could gain access to a network. At the same time, Graph Neural Networks (GNNs) have demonstrated strong capabilities in modeling complex relationships and dependencies in networked graph structured data, making them a promising approach for detecting advanced cyber threats in highly interconnected systems. This thesis investigated the capability of GNN-based intrusion detection to identify multi-step attacks in the 5GC. Due to the lack of publicly available datasets containing such attacks in internal 5GC systems, a new dataset was developed by combining generated benign network traffic with a simulated multi-step attack targeting production components of the 5GC environment. A complete detection framework was designed and evaluated, including data pre processing, feature extraction, graph construction, and a GNN architecture. The model architecture consists of a Memory Module, Graph Convolutional Layers and a Edge-level Classification Head. Different architectures and configurations of the model were trained and tested on the data, with the highest stable scoring model having a median F1 Score of 99.55%, showing that it is possible for a graph-based model to detect attacks in a production-like 5GC test environment using simulated network data and a simulated multi-step attack.
dc.identifier.coursecodeDATX05
dc.identifier.urihttps://hdl.handle.net/20.500.12380/312303
dc.language.isoeng
dc.setspec.uppsokTechnology
dc.subjectTemporal Graph Neural Networks (TGN), Graph Neural Networks (GNN), Anomaly Detection, Intrusion Detection Systems (IDS), 5G Core Networks, Kubernetes, Cloud-Native Networks, Multi-Step Attack Detection
dc.titleGraph-based Anomaly Detection in 5G Core Networks - An Evaluation of Temporal Graph Neural Networks for detecting Multi-Step Attacks in Kubernetes-based 5G Core Networks
dc.type.degreeExamensarbete för masterexamensv
dc.type.degreeMaster's Thesisen
dc.type.uppsokH
local.programmeComputer systems and networks (MPCSN), MSc

Ladda ner

Original bundle

Visar 1 - 1 av 1
Hämtar...
Bild (thumbnail)
Namn:
CSE 26-165 GS IN.pdf
Size:
4.05 MB
Format:
Adobe Portable Document Format

License bundle

Visar 1 - 1 av 1
Hämtar...
Bild (thumbnail)
Namn:
license.txt
Size:
2.35 KB
Format:
Item-specific license agreed upon to submission
Description: