Defending the 5G Wallet: Detecting W-EDoS and I-EDoS in Self-Organizing Networks
Detecting Workload-based and Instantiation-based Economic Denial of Sustainability on 5G environments
The paper introduces a specialized security architecture designed to detect Economic Denial of Sustainability (EDoS) attacks in 5G Self-Organizing Networks (SON). It formally defines and distinguishes between Workload-based EDoS (W-EDoS) and Instantiation-based EDoS (I-EDoS), achieving high detection accuracy (AUC up to 0.995) using a combination of Rènyi entropy, Double Exponential Smoothing, and DBSCAN clustering.
TL;DR
As 5G networks transition to Self-Organizing Networks (SON) and Network Function Virtualization (NFV), a new threat has emerged: Economic Denial of Sustainability (EDoS). Unlike traditional DDoS that aims to crash a server, EDoS aims to bankrupt the provider by tricking auto-scaling systems into over-provisioning resources. This paper introduces a sophisticated detection framework using Entropy analysis and DBSCAN clustering to unmask these stealthy fiscal attacks.
Problem & Motivation: The Price of Elasticity
The "cloud-native" nature of 5G is a double-edged sword. While auto-scaling allows networks to handle traffic spikes gracefully, it creates a loophole. Attackers can simulate legitimate-looking traffic that is computationally expensive, forcing the provider to spin up more Virtual Network Functions (VNFs).
The authors identify a critical gap: status-quo security tools are tuned for availability. They don't care if you spend $10,000 as long as the site stays up. This paper bridges that gap by focusing on Sustainability—the economic viability of the service.
Methodology: The Core Detection Engine
The researchers break down EDoS into two distinct "flavors" and offer a mathematical counter to each.
1. W-EDoS (Workload-based)
This attack uses "expensive" requests (e.g., complex database queries) that look like normal traffic but spike CPU usage.
- The Tech: The system calculates Rènyi Entropy on application response times. Entropy measures "disorder." If the randomness of response times shifts while traffic volume stays relatively stable, it signals an attack.
- Prediction: It uses Double Exponential Smoothing (DES) to forecast expected CPU behavior and flags deviations that fall outside a calculated Mahalanobis distance interval.
2. I-EDoS (Instantiation-based)
Here, the attacker exploits telemetry vulnerabilities (like poisoning RabbitMQ messages) to trick the orchestrator into thinking nodes are overloaded when they aren't.
- The Tech: The authors use DBSCAN (Density-Based Spatial Clustering). It groups VNFs by productivity. In a legitimate scenario, all instances should have similar productivity. In an I-EDoS attack, a "lazy group" appears—instances that exist (and cost money) but aren't actually doing useful work.
Figure 1: The proposed SON architecture integrating with ETSI-NFV standards.
Experiments & Results
The authors validated their approach using an OpenStack testbed (Controller and Compute nodes) and various attack intensities.
- W-EDoS Performance: At an attack intensity of 10% (where only 10% of requests were malicious), the system achieved an AUC of 0.995. This suggests the system is highly effective at identifying subtle workload shifts.
- I-EDoS Performance: The clustering method successfully isolated "lazy" instances even when the attacker managed to fake CPU readings. The ROC curves showed that as attack intensity increases (i.e., more fraudulent nodes), the system's precision actually improves because the "lazy cluster" becomes more statistically distinct.
Figure 2: ROC curve showing the high effectiveness of I-EDoS detection as attack intensity grows.
Critical Insight & Conclusion
This paper's greatest contribution is the formalization of the I-EDoS threat. While most literature focuses on "request flooding," this work acknowledges that the telemetry data bus (e.g., RabbitMQ, Ceilometer) is a primary attack vector in 5G.
Takeaway: As we move toward 6G, the industry must stop treating "Resource Management" and "Security" as two separate silos. If your auto-scaling logic isn't security-aware, your cloud bill becomes your biggest vulnerability.
Limitations: The paper currently does not address Mimicry attacks where an attacker purposefully varies their behavior to stay within the "normal" entropy bounds. Future work will likely need to incorporate specialized Reinforcement Learning to counter such adaptive adversaries.
