Design of a Dockerised Vulnerability System over 5G
DOI:
https://doi.org/10.17979/ja-cea.2026.47.13829Keywords:
Secure networked control systems, Security, Monitoring, Experiment designAbstract
This paper presents the design of a testbed for the controlled generation of cybersecurity traffic in private 5G networks. The proposal combines a Firecell Labkit 40 infrastructure, radio connectivity, and a host machine running Dockerised vulnerable services based on Docker-Vulhub. The environment deploys known vulnerabilities, many of them documented through CVEs, routes the resulting traffic through the 5G SA network, and captures it from the core using tools such as tcpdump A proof of concept that captures a real attack against Apache Tomcat (CVE-2017-12615) from the core shows that the traffic is observable and reconstructable, and that a labelled dataset can be derived from it. The architecture is a modular and extensible basis for future dataset-generation campaigns. Its main objective is not to exhaustively evaluate each vulnerability, but to document a reproducible environment for generating useful traffic to evaluate IDS and machine learning models in private 5G networks.
References
Alsaedi, A., Moustafa, N., Tari, Z., Mahmood, A., Anwar, A., 2020. TON_IoT telemetry dataset: A new generation dataset of IoT and IIoT for data-driven intrusion detection systems. IEEE Access 8, 165130–165150. DOI: 10.1109/ACCESS.2020.3022862
Amponis, G., Radoglou-Grammatikis, P., Lagkas, T., Mallouli, W., Cavalli, A., Klonidis, D., Markakis, E., Sarigiannidis, P., 2022. Threatening the 5G core via PFCP DoS attacks: The case of blocking UAV communications. EURASIP Journal on Wireless Communications and Networking 2022. DOI: 10.1186/S13638-022-02204-5
Coldwell, C., Conger, D., Goodell, E., Jacobson, B., Petersen, B., Spencer, D., Anderson, M., Sgambati, M., 2022. Machine learning 5G attack detection in programmable logic. 2022 IEEE GLOBECOM Workshops, GC Wkshps 2022 - Proceedings, 1365–1370. DOI: 10.1109/GCWKSHPS56602.2022.10008647
Ferrag, M. A., Friha, O., Hamouda, D., Maglaras, L., Janicke, H., 2022. Edge-IIoTset: A new comprehensive realistic cyber security dataset of IoT and IIoT applications for centralized and federated learning. IEEE Access 10, 40281–40306. DOI: 10.1109/ACCESS.2022.3165809
Goldschmidt, P., Chudá, D., 2025. Network intrusion datasets: A survey, limitations, and recommendations. Computers & Security 156, 104510. DOI: 10.1016/j.cose.2025.104510
Hamroun, C., Fladenmuller, A., Pariente, M., Pujolle, G., 2025. Intrusion detection in 5G and Wi-Fi networks: A survey of current methods, challenges, and perspectives. IEEE Access 13, 40950–40976. DOI: 10.1109/ACCESS.2025.3546338
Khan, M. S., Farzaneh, B., Shahriar, N., Saha, N., Boutaba, R., 2022. SliceSecure: Impact and detection of DoS/DDoS attacks on 5G network slices. In: 2022 IEEE Future Networks World Forum (FNWF). pp. 639–642. DOI: 10.1109/FNWF55208.2022.00117
Koroniotis, N., Moustafa, N., Sitnikova, E., Turnbull, B., 2019. Towards the development of realistic botnet dataset in the Internet of Things for network forensic analytics: Bot-IoT dataset. Future Generation Computer Systems 100, 779–796. DOI: 10.1016/j.future.2019.05.041
Moustafa, N., Slay, J., 2015. UNSW-NB15: A comprehensive data set for network intrusion detection systems (UNSW-NB15 network data set). In: 2015 Military Communications and Information Systems Conference (MilCIS). pp. 1–6. DOI: 10.1109/MilCIS.2015.7348942
Narciandi-Rodríguez, D., Martínez-Martínez, G., Aveleira-Mata, J., Bayón Gutiérrez, M., Alfonso-Cendón, J., García-Rodríguez, I., 2026. Design and capture of a 5G SA traffic dataset under jamming conditions. In: Rojas, I., Joya, G., Català, A. (Eds.), Advances in Computational Intelligence. Springer Nature Switzerland, Cham, pp. 261–273.
Narciandi-Rodríguez, D., Aveleira-Mata, J., García-Ordás, M. T., Alfonso-Cendón, J., Benavides, C., Alaiz-Moretón, H., 2025a. A cybersecurity review in IoT 5G networks. Internet of Things 30, 101478. DOI: 10.1016/j.iot.2024.101478
Narciandi-Rodríguez, D., Martínez-Martínez, G., Aveleira-Mata, J., Bayón Gutiérrez, M., Alfonso-Cendón, J., García-Rodríguez, I., 2025b. 5G-RaaS-UAD 5G Ransomware as a Service Attack – Under Attack Dataset. URL: https://figshare.com/s/160750e5d36974bb4c71?file=59439863
Noor, K., Imoize, A. L., Li, C.-T., Weng, C.-Y., 2025. A review of machine learning and transfer learning strategies for intrusion detection systems in 5G and beyond. Mathematics 13 (7), 1088. DOI: 10.3390/math13071088
Sharafaldin, I., Lashkari, A. H., Ghorbani, A. A., 2018. Toward generating a new intrusion detection dataset and intrusion traffic characterization. In: Proceedings of the 4th International Conference on Information Systems Security and Privacy (ICISSP). pp. 108–116. DOI: 10.5220/0006639801080116
Siriwardhana, Y., Samarakoon, S., Porambage, P., Liyanage, M., Chang, S.-Y., Kim, J., Kim, J., Ylianttila, M., 2025. Descriptor: 5G wireless network intrusion detection dataset (5G-NIDD). IEEE Data Descriptions 2, 11098458. DOI: 10.1109/IEEEDATA.2025.3592888
Tavallaee, M., Bagheri, E., Lu, W., Ghorbani, A. A., 2009. A detailed analysis of the KDD Cup 99 data set. In: 2009 IEEE Symposium on Computational Intelligence for Security and Defense Applications. pp. 1–6. DOI: 10.1109/CISDA.2009.5356528
Thakkar, A., Lohiya, R., 2020. A review of the advancement in intrusion detection datasets. Procedia Computer Science 167, 636–645. DOI: 10.1016/j.procs.2020.03.330
Vulhub, 2026. Vulhub - open-source vulnerable Docker environments. URL: https://vulhub.org/
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Diego Narciandi Rodríguez, Jose Aveleira-Mata, María Teresa García-Ordás, Hugo Bernardo-Garmilla, Javier Alfonso-Cendón, Isaías García-Rodríguez

This work is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.