Application-Layer Intrusion Detection for VoIP over Open-Source 5G Standalone Networks
Cosmin-Sebastian Badea, Marian Alexandru, Andreea-Mihaela ComșițMany open-source 5G standalone testbeds emphasise deployment rather than continuous detection of application-layer abuse. This work presents a reproducible, RF-free, three-node testbed in which SIP signalling traverses a PDU session while a sensor correlates SIP transactions and Asterisk events with Open5GS session records, providing subscriber and data-network attribution. The detector combines a request-rate window with an unanswered-challenge ratio. A separate 5G-dependent rule determines whether SIP traffic attributed to the UE address pool has a corresponding active PDU session. Before execution, the experimental configurations and per-run ground-truth files were hashed; 67 of 70 runs passed the automated validity gates, and every exclusion is reported with its criterion. The detector identified all 60 attack episodes: REGISTER flooding at 2, 5, 10, and 20 requests/s and INVITE flooding at 10 and 20 requests/s. Median first-alert latency for REGISTER decreased from 11.403 s at 2 requests/s to 2.900 s at 20 requests/s; at the two matched rates, mean latencies for the two methods differed by, at most, 28.9 ms. Seven benign runs totalling 3.50 h produced no false alerts and a one-sided 95% Poisson upper bound of 0.86 alerts per hour, and 300 of 300 eligible alerts carried the expected subscriber identity.