Skip to main navigation Skip to search Skip to main content

From Detection to Policy: Calibrated and Explainable Closed-Loop DDoS Management in 5G/B5G Networks

Research output: Contribution to journalArticlepeer-review

Abstract

Closed-loop Distributed Denial-of-Service (DDoS) mitigation in Fifth Generation (5G) networks must balance attack blocking with operational safety by minimizing collateral damage to benign users. Network operators using the Network Data Analytics Function (NWDAF) face a dilemma: existing Machine Learning (ML)-based security solutions provide binary classifications but lack a mechanism to translate model outputs into quantifiable, proportional, and automated mitigation actions. This paper proposes a two-stage management framework that maps network analytics to graduated mitigation decisions using a risk-calibrated decision gate and severity-based policy thresholds. First, Isotonic Regression calibrates model outputs and triggers mitigation only for high-confidence detections, reducing falsepositive harm. Second, for admitted threats, the Dynamic Mitigation Severity Score (DMSS) quantifies severity by aggregating normalized Shapley Additive exPlanations (SHAP) contributions of key 5G features. Thresholds optimized to minimize benign terminations select one of three actions: Terminate, Throttle, or Monitor. Experiments on a public 5G DDoS testbed show that, unlike deep learning baselines prone to severe collateral damage, the framework maintains high threat coverage while nearly eliminating benign terminations. Calibration further reduces Expected Calibration Error (ECE) and improves probability reliability. The DMSS ranks volumetric floods as the most severe attacks, and sensitivity analysis shows stable policy thresholds across operating points. The resulting 3rd Generation Partnership Project (3GPP)-aligned framework supports closed-loop mitigation and explicit control of the trade-off between security coverage and operational safety in 5G/Beyond 5G (B5G) networks.

Original languageEnglish
Pages (from-to)5155-5167
Number of pages13
JournalIEEE Transactions on Network and Service Management
Volume23
DOIs
StatePublished - 2026

Bibliographical note

Publisher Copyright:
© 2026 IEEE. All rights reserved,

Keywords

  • 5G/B5G security
  • DDoS mitigation
  • closed-loop automation
  • explainable AI
  • policy optimization

ASJC Scopus subject areas

  • Computer Networks and Communications
  • Electrical and Electronic Engineering

Fingerprint

Dive into the research topics of 'From Detection to Policy: Calibrated and Explainable Closed-Loop DDoS Management in 5G/B5G Networks'. Together they form a unique fingerprint.

Cite this