Abstract
Closed-loop Distributed Denial-of-Service (DDoS) mitigation in Fifth Generation (5G) networks must balance attack blocking with operational safety by minimizing collateral damage to benign users. Network operators using the Network Data Analytics Function (NWDAF) face a dilemma: existing Machine Learning (ML)-based security solutions provide binary classifications but lack a mechanism to translate model outputs into quantifiable, proportional, and automated mitigation actions. This paper proposes a two-stage management framework that maps network analytics to graduated mitigation decisions using a risk-calibrated decision gate and severity-based policy thresholds. First, Isotonic Regression calibrates model outputs and triggers mitigation only for high-confidence detections, reducing falsepositive harm. Second, for admitted threats, the Dynamic Mitigation Severity Score (DMSS) quantifies severity by aggregating normalized Shapley Additive exPlanations (SHAP) contributions of key 5G features. Thresholds optimized to minimize benign terminations select one of three actions: Terminate, Throttle, or Monitor. Experiments on a public 5G DDoS testbed show that, unlike deep learning baselines prone to severe collateral damage, the framework maintains high threat coverage while nearly eliminating benign terminations. Calibration further reduces Expected Calibration Error (ECE) and improves probability reliability. The DMSS ranks volumetric floods as the most severe attacks, and sensitivity analysis shows stable policy thresholds across operating points. The resulting 3rd Generation Partnership Project (3GPP)-aligned framework supports closed-loop mitigation and explicit control of the trade-off between security coverage and operational safety in 5G/Beyond 5G (B5G) networks.
| Original language | English |
|---|---|
| Pages (from-to) | 5155-5167 |
| Number of pages | 13 |
| Journal | IEEE Transactions on Network and Service Management |
| Volume | 23 |
| DOIs | |
| State | Published - 2026 |
Bibliographical note
Publisher Copyright:© 2026 IEEE. All rights reserved,
Keywords
- 5G/B5G security
- DDoS mitigation
- closed-loop automation
- explainable AI
- policy optimization
ASJC Scopus subject areas
- Computer Networks and Communications
- Electrical and Electronic Engineering
Fingerprint
Dive into the research topics of 'From Detection to Policy: Calibrated and Explainable Closed-Loop DDoS Management in 5G/B5G Networks'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver