Skip to content

Repository files navigation

FBS Detection

This repository contains code of the paper "Gotta Detect ’Em All: Fake Base Station and Multi-Step Attack Detection in Cellular Networks" for detecting Fake Base Stations (FBS) and Multi-Step Attacks (MSAs) from cellular network traces in the User Equipment (UE).

Repository Structure

.
├── app/
│ ├── app-release.apk
│ ├── note.txt
├── codes/
│ ├── classification-models.py
│ ├── cross-validation.py
│ ├── feature-names.py
│ ├── graph_models.py
│ ├── graphsage_metrics.py
│ ├── ml-stats.py
│ ├── stateful-lstm-w-attn.py
│ └── trace-level-classification.py
│
├── dataset/
│ ├── fbs_nas.csv
│ ├── fbs_rrc.csv
│ ├── msa_nas.csv
│ ├── msa_rrc.csv
│ ├── msa_nas_reshaped.csv
│ ├── msa_rrc_reshaped.csv
│ ├── plot_data.json
│
├── phoenix-implementation/
│ ├── dfa.py
│ ├── mm.py
│ ├── packet_utils.py
│ └── pltl.py
│
└── requirements.txt

Description

This project implements a machine learning-based approach for detecting fake base stations and multi-step attacks from cellular network traces.

Dataset Labels

The 1-1 mapping of categorical and encoded labels is given below

Attack NameLabel
Benign0
Energy Depletion attack1
NAS counter Desynch attack2
X2 signalling flood3
Paging channel hijacking attack4
Bidding down with AttachReject5
Incarceration with rrcReject and rrcRelease6
Panic Attack7
Stealthy Kickoff Attack8
Authentication relay attack9
Location tracking via measurement reports10
Capability Hijacking11
Lullaby attack using rrcReestablishRequest12
Mobile Network Mapping (MNmap)13
Lullaby attack with rrcResume14
IMSI catching15
Incarceration with rrcReestablishReject16
Handover hijacking17
RRC replay attack18
Lullaby attack with rrcReconfiguration19
Bidding down with ServiceReject20
Bidding down with TAUReject21

Requirements

  • Python 3.7+
  • PyTorch
  • TensorFlow
  • NumPy
  • Pandas
  • scikit-learn
  • networkx

See requirements.txt for details.

Note

See the following sections to reproduce the results in the paper. You can also use this notebook to do all of it together.

Create and Activate Virtual Environment [Optional]

We will create and activate a virtual environment for the project.

Create the virtual environment

python3 -m venv venv

Activate the virtual environment

source venv/bin/activate

Install Dependencies

pip install -r requirements.txt

Run Classification Models

The classification-models.py script trains and evaluates the following models:

  • Random Forest (rf)
  • Support Vector Machine (svm)
  • Decision Tree (dt)
  • XGBoost (xgb)
  • K-Nearest Neighbors (knn)
  • Naive Bayes (nb)
  • Logistic Regression (lr)
  • Convolutional Neural Network (cnn)
  • Feedforward Neural Network (fnn)
  • Long Short-Term Memory Network (lstm)

To run the classification-models.py script, use the following command:

python codes/classification-models.py <[fbs_nas/msa_nas/fbs_rrc/msa_rrc].csv>

Replace <[fbs_nas/msa_nas/fbs_rrc/msa_rrc].csv> with the path to your dataset file.

Example:

python codes/classification-models.py dataset/fbs_nas.csv

The script will load the dataset, train the models, and display the performance metrics for each model for the provided dataset.

Run Graph Models

The graph_models.py script trains and evaluates the following graph neural network models:

  • Graph Attention Network (GAT)
  • Graph Attention Network v2 (GATv2)
  • Graph Convolutional Network (GCN)
  • GraphSAGE
  • Graph Transformer

To run the graph_models.py script, use the following command:

python3 codes/graph_models.py <[dataset_path]>

Replace <dataset_path> with the path to your dataset file.

Example:

python3 codes/graph_models.py dataset/msa_nas.csv

Stateful LSTM with Attention

To run the stateful-lstm-w-attn.py script, use the following command:

python3 codes/stateful-lstm-w-attn.py <[dataset_path]>

Replace <dataset_path> with the path to your dataset file.

Example:

python3 codes/stateful-lstm-w-attn.py dataset/fbs_nas.csv 

This script implements our stateful LSTM model with attention mechanism and evaluates its performance.

Trace-Level Classification

python3 codes/trace-level-classification.py

This script performs trace-level classification using following machine learning models:

  • Logistic Regression
  • Support Vector Machine
  • K-Nearest Neighbors
  • Decision Tree
  • Random Forest
  • XGBoost

ML Stats

The ml-stats.py script plots various statistics related to the machine learning models.

To run the ml-stats.py script, use the following command:

python3 codes/ml-stats.py

This script generates the following plots:

  • Accuracy vs Sequence Length for NAS and RRC datasets
  • Time Consumption vs Number of Packets
  • Memory Consumption vs Number of Packets
  • Power Consumption vs Number of Packets

The plots are saved in the outputs/figures directory.

MSA Performance Breakdown (TP, TN, FP, FN)

The graphsage_metrics.py script calculates metrics for the GraphSAGE model.

To run the graphsage_metrics.py script, use the following command:

python3 codes/graphsage_metrics.py <[dataset_path]>

Replace <dataset_path> with the path to your dataset file.

Example:

python3 codes/graphsage_metrics.py dataset/msa_nas.csv

This script generates a tabular summary of the following metrics for each class:

  • True Positives (TP)
  • True Negatives (TN)
  • False Positives (FP)
  • False Negatives (FN)

The results are printed to the console.

Feature Names

python3 codes/feature-names.py

This script prints the feature names from the dataset in the outputs/column_names_output.txt file.

Cross-Validation

To run the cross-validation.py script, use the following command:

python3 codes/cross-validation.py <[dataset_path]>

Replace <dataset_path> with the path to your dataset file.

Example:

python3 codes/cross-validation.py dataset/msa_nas.csv

This script performs leave-one-class-out cross-validation and generates the following outputs:

  • Accuracy for each fold
  • Detailed results for each fold, including true and predicted labels
  • A pivot table summarizing the true and predicted labels across all folds

Phoenix Implementation

To run our implementation for PHOENIX's signature-based detection, run the following codes. Download PHOENIX's signatures and traces from their website and put in the dataset folder.

DFA

The dfa.py script detects anomalies using a Deterministic Finite Automaton (DFA) parsed from a DOT file.

To run the dfa.py script, use the following command:

python phoenix-implementation/dfa.py <state_machine.dot><trace.pcap>

Replace <state_machine.dot> with the path to your DOT file and <trace.pcap> with the path to your trace file.

Example:

python3 phoenix-implementation/dfa.py dataset/signatures/dfa/NAS/attach_reject/attach_reject_50_40.trace.dot dataset/NAS_PCAP_logs/attach_reject.pcap

Mealy Machine

The mm.py script processes events using a Mealy Machine parsed from a DOT file.

To run the mm.py script, use the following command:

python phoenix-implementation/mm.py <trace.pcap>

Replace <trace.pcap> with the path to your trace file.

Example:

python3 phoenix-implementation/mm.py dataset/NAS_PCAP_logs/attach_reject.pcap

PLTL

The pltl.py script checks events against Propositional Linear Temporal Logic (PLTL) signatures.

To run the pltl.py script, use the following command:

python phoenix-implementation/pltl.py <trace.pcap>

Replace <trace.pcap> with the path to your trace file.

Example:

python phoenix-implementation/pltl.py dataset/NAS_PCAP_logs/attach_reject.pcap

Citation

If you use this dataset, models, or code modules, please cite the following paper:

@misc{mubasshir2025gottadetectemall,
title={Gotta Detect 'Em All: Fake Base Station and Multi-Step Attack Detection in Cellular Networks}, author={Kazi Samin Mubasshir and Imtiaz Karim and Elisa Bertino},
year={2025},
eprint={2401.04958},
archivePrefix={arXiv},
primaryClass={cs.CR},
url={https://arxiv.org/abs/2401.04958}, }

About

This repository contains code of the paper "Gotta Detect ’Em All: Fake Base Station and Multi-Step Attack Detection in Cellular Networks" for detecting Fake Base Stations (FBS) and Multi-Step Attacks (MSAs) from cellular network traces in the User Equipment (UE).

Topics

Resources

Stars

4 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
GitHub - SysNetS/fbsdetector: This repository contains code of the paper "Gotta Detect ’Em All: Fake Base Station and Multi-Step Attack Detection in Cellular Networks" for detecting Fake Base Stations (FBS) and Multi-Step Attacks (MSAs) from cellular network traces in the User Equipment (UE). · GitHub
Skip to content

Repository files navigation

FBS Detection

This repository contains code of the paper "Gotta Detect ’Em All: Fake Base Station and Multi-Step Attack Detection in Cellular Networks" for detecting Fake Base Stations (FBS) and Multi-Step Attacks (MSAs) from cellular network traces in the User Equipment (UE).

Repository Structure

.
├── app/
│ ├── app-release.apk
│ ├── note.txt
├── codes/
│ ├── classification-models.py
│ ├── cross-validation.py
│ ├── feature-names.py
│ ├── graph_models.py
│ ├── graphsage_metrics.py
│ ├── ml-stats.py
│ ├── stateful-lstm-w-attn.py
│ └── trace-level-classification.py
│
├── dataset/
│ ├── fbs_nas.csv
│ ├── fbs_rrc.csv
│ ├── msa_nas.csv
│ ├── msa_rrc.csv
│ ├── msa_nas_reshaped.csv
│ ├── msa_rrc_reshaped.csv
│ ├── plot_data.json
│
├── phoenix-implementation/
│ ├── dfa.py
│ ├── mm.py
│ ├── packet_utils.py
│ └── pltl.py
│
└── requirements.txt

Description

This project implements a machine learning-based approach for detecting fake base stations and multi-step attacks from cellular network traces.

Dataset Labels

The 1-1 mapping of categorical and encoded labels is given below

Attack NameLabel
Benign0
Energy Depletion attack1
NAS counter Desynch attack2
X2 signalling flood3
Paging channel hijacking attack4
Bidding down with AttachReject5
Incarceration with rrcReject and rrcRelease6
Panic Attack7
Stealthy Kickoff Attack8
Authentication relay attack9
Location tracking via measurement reports10
Capability Hijacking11
Lullaby attack using rrcReestablishRequest12
Mobile Network Mapping (MNmap)13
Lullaby attack with rrcResume14
IMSI catching15
Incarceration with rrcReestablishReject16
Handover hijacking17
RRC replay attack18
Lullaby attack with rrcReconfiguration19
Bidding down with ServiceReject20
Bidding down with TAUReject21

Requirements

  • Python 3.7+
  • PyTorch
  • TensorFlow
  • NumPy
  • Pandas
  • scikit-learn
  • networkx

See requirements.txt for details.

Note

See the following sections to reproduce the results in the paper. You can also use this notebook to do all of it together.

Create and Activate Virtual Environment [Optional]

We will create and activate a virtual environment for the project.

Create the virtual environment

python3 -m venv venv

Activate the virtual environment

source venv/bin/activate

Install Dependencies

pip install -r requirements.txt

Run Classification Models

The classification-models.py script trains and evaluates the following models:

  • Random Forest (rf)
  • Support Vector Machine (svm)
  • Decision Tree (dt)
  • XGBoost (xgb)
  • K-Nearest Neighbors (knn)
  • Naive Bayes (nb)
  • Logistic Regression (lr)
  • Convolutional Neural Network (cnn)
  • Feedforward Neural Network (fnn)
  • Long Short-Term Memory Network (lstm)

To run the classification-models.py script, use the following command:

python codes/classification-models.py <[fbs_nas/msa_nas/fbs_rrc/msa_rrc].csv>

Replace <[fbs_nas/msa_nas/fbs_rrc/msa_rrc].csv> with the path to your dataset file.

Example:

python codes/classification-models.py dataset/fbs_nas.csv

The script will load the dataset, train the models, and display the performance metrics for each model for the provided dataset.

Run Graph Models

The graph_models.py script trains and evaluates the following graph neural network models:

  • Graph Attention Network (GAT)
  • Graph Attention Network v2 (GATv2)
  • Graph Convolutional Network (GCN)
  • GraphSAGE
  • Graph Transformer

To run the graph_models.py script, use the following command:

python3 codes/graph_models.py <[dataset_path]>

Replace <dataset_path> with the path to your dataset file.

Example:

python3 codes/graph_models.py dataset/msa_nas.csv

Stateful LSTM with Attention

To run the stateful-lstm-w-attn.py script, use the following command:

python3 codes/stateful-lstm-w-attn.py <[dataset_path]>

Replace <dataset_path> with the path to your dataset file.

Example:

python3 codes/stateful-lstm-w-attn.py dataset/fbs_nas.csv 

This script implements our stateful LSTM model with attention mechanism and evaluates its performance.

Trace-Level Classification

python3 codes/trace-level-classification.py

This script performs trace-level classification using following machine learning models:

  • Logistic Regression
  • Support Vector Machine
  • K-Nearest Neighbors
  • Decision Tree
  • Random Forest
  • XGBoost

ML Stats

The ml-stats.py script plots various statistics related to the machine learning models.

To run the ml-stats.py script, use the following command:

python3 codes/ml-stats.py

This script generates the following plots:

  • Accuracy vs Sequence Length for NAS and RRC datasets
  • Time Consumption vs Number of Packets
  • Memory Consumption vs Number of Packets
  • Power Consumption vs Number of Packets

The plots are saved in the outputs/figures directory.

MSA Performance Breakdown (TP, TN, FP, FN)

The graphsage_metrics.py script calculates metrics for the GraphSAGE model.

To run the graphsage_metrics.py script, use the following command:

python3 codes/graphsage_metrics.py <[dataset_path]>

Replace <dataset_path> with the path to your dataset file.

Example:

python3 codes/graphsage_metrics.py dataset/msa_nas.csv

This script generates a tabular summary of the following metrics for each class:

  • True Positives (TP)
  • True Negatives (TN)
  • False Positives (FP)
  • False Negatives (FN)

The results are printed to the console.

Feature Names

python3 codes/feature-names.py

This script prints the feature names from the dataset in the outputs/column_names_output.txt file.

Cross-Validation

To run the cross-validation.py script, use the following command:

python3 codes/cross-validation.py <[dataset_path]>

Replace <dataset_path> with the path to your dataset file.

Example:

python3 codes/cross-validation.py dataset/msa_nas.csv

This script performs leave-one-class-out cross-validation and generates the following outputs:

  • Accuracy for each fold
  • Detailed results for each fold, including true and predicted labels
  • A pivot table summarizing the true and predicted labels across all folds

Phoenix Implementation

To run our implementation for PHOENIX's signature-based detection, run the following codes. Download PHOENIX's signatures and traces from their website and put in the dataset folder.

DFA

The dfa.py script detects anomalies using a Deterministic Finite Automaton (DFA) parsed from a DOT file.

To run the dfa.py script, use the following command:

python phoenix-implementation/dfa.py <state_machine.dot><trace.pcap>

Replace <state_machine.dot> with the path to your DOT file and <trace.pcap> with the path to your trace file.

Example:

python3 phoenix-implementation/dfa.py dataset/signatures/dfa/NAS/attach_reject/attach_reject_50_40.trace.dot dataset/NAS_PCAP_logs/attach_reject.pcap

Mealy Machine

The mm.py script processes events using a Mealy Machine parsed from a DOT file.

To run the mm.py script, use the following command:

python phoenix-implementation/mm.py <trace.pcap>

Replace <trace.pcap> with the path to your trace file.

Example:

python3 phoenix-implementation/mm.py dataset/NAS_PCAP_logs/attach_reject.pcap

PLTL

The pltl.py script checks events against Propositional Linear Temporal Logic (PLTL) signatures.

To run the pltl.py script, use the following command:

python phoenix-implementation/pltl.py <trace.pcap>

Replace <trace.pcap> with the path to your trace file.

Example:

python phoenix-implementation/pltl.py dataset/NAS_PCAP_logs/attach_reject.pcap

Citation

If you use this dataset, models, or code modules, please cite the following paper:

@misc{mubasshir2025gottadetectemall,
title={Gotta Detect 'Em All: Fake Base Station and Multi-Step Attack Detection in Cellular Networks}, author={Kazi Samin Mubasshir and Imtiaz Karim and Elisa Bertino},
year={2025},
eprint={2401.04958},
archivePrefix={arXiv},
primaryClass={cs.CR},
url={https://arxiv.org/abs/2401.04958}, }

About

This repository contains code of the paper "Gotta Detect ’Em All: Fake Base Station and Multi-Step Attack Detection in Cellular Networks" for detecting Fake Base Stations (FBS) and Multi-Step Attacks (MSAs) from cellular network traces in the User Equipment (UE).

Topics

Resources

Stars

4 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - SysNetS/fbsdetector: This repository contains code of the paper "Gotta Detect ’Em All: Fake Base Station and Multi-Step Attack Detection in Cellular Networks" for detecting Fake Base Stations (FBS) and Multi-Step Attacks (MSAs) from cellular network traces in the User Equipment (UE). · GitHub
Skip to content

Repository files navigation

FBS Detection

This repository contains code of the paper "Gotta Detect ’Em All: Fake Base Station and Multi-Step Attack Detection in Cellular Networks" for detecting Fake Base Stations (FBS) and Multi-Step Attacks (MSAs) from cellular network traces in the User Equipment (UE).

Repository Structure

.
├── app/
│ ├── app-release.apk
│ ├── note.txt
├── codes/
│ ├── classification-models.py
│ ├── cross-validation.py
│ ├── feature-names.py
│ ├── graph_models.py
│ ├── graphsage_metrics.py
│ ├── ml-stats.py
│ ├── stateful-lstm-w-attn.py
│ └── trace-level-classification.py
│
├── dataset/
│ ├── fbs_nas.csv
│ ├── fbs_rrc.csv
│ ├── msa_nas.csv
│ ├── msa_rrc.csv
│ ├── msa_nas_reshaped.csv
│ ├── msa_rrc_reshaped.csv
│ ├── plot_data.json
│
├── phoenix-implementation/
│ ├── dfa.py
│ ├── mm.py
│ ├── packet_utils.py
│ └── pltl.py
│
└── requirements.txt

Description

This project implements a machine learning-based approach for detecting fake base stations and multi-step attacks from cellular network traces.

Dataset Labels

The 1-1 mapping of categorical and encoded labels is given below

Attack NameLabel
Benign0
Energy Depletion attack1
NAS counter Desynch attack2
X2 signalling flood3
Paging channel hijacking attack4
Bidding down with AttachReject5
Incarceration with rrcReject and rrcRelease6
Panic Attack7
Stealthy Kickoff Attack8
Authentication relay attack9
Location tracking via measurement reports10
Capability Hijacking11
Lullaby attack using rrcReestablishRequest12
Mobile Network Mapping (MNmap)13
Lullaby attack with rrcResume14
IMSI catching15
Incarceration with rrcReestablishReject16
Handover hijacking17
RRC replay attack18
Lullaby attack with rrcReconfiguration19
Bidding down with ServiceReject20
Bidding down with TAUReject21

Requirements

  • Python 3.7+
  • PyTorch
  • TensorFlow
  • NumPy
  • Pandas
  • scikit-learn
  • networkx

See requirements.txt for details.

Note

See the following sections to reproduce the results in the paper. You can also use this notebook to do all of it together.

Create and Activate Virtual Environment [Optional]

We will create and activate a virtual environment for the project.

Create the virtual environment

python3 -m venv venv

Activate the virtual environment

source venv/bin/activate

Install Dependencies

pip install -r requirements.txt

Run Classification Models

The classification-models.py script trains and evaluates the following models:

  • Random Forest (rf)
  • Support Vector Machine (svm)
  • Decision Tree (dt)
  • XGBoost (xgb)
  • K-Nearest Neighbors (knn)
  • Naive Bayes (nb)
  • Logistic Regression (lr)
  • Convolutional Neural Network (cnn)
  • Feedforward Neural Network (fnn)
  • Long Short-Term Memory Network (lstm)

To run the classification-models.py script, use the following command:

python codes/classification-models.py <[fbs_nas/msa_nas/fbs_rrc/msa_rrc].csv>

Replace <[fbs_nas/msa_nas/fbs_rrc/msa_rrc].csv> with the path to your dataset file.

Example:

python codes/classification-models.py dataset/fbs_nas.csv

The script will load the dataset, train the models, and display the performance metrics for each model for the provided dataset.

Run Graph Models

The graph_models.py script trains and evaluates the following graph neural network models:

  • Graph Attention Network (GAT)
  • Graph Attention Network v2 (GATv2)
  • Graph Convolutional Network (GCN)
  • GraphSAGE
  • Graph Transformer

To run the graph_models.py script, use the following command:

python3 codes/graph_models.py <[dataset_path]>

Replace <dataset_path> with the path to your dataset file.

Example:

python3 codes/graph_models.py dataset/msa_nas.csv

Stateful LSTM with Attention

To run the stateful-lstm-w-attn.py script, use the following command:

python3 codes/stateful-lstm-w-attn.py <[dataset_path]>

Replace <dataset_path> with the path to your dataset file.

Example:

python3 codes/stateful-lstm-w-attn.py dataset/fbs_nas.csv 

This script implements our stateful LSTM model with attention mechanism and evaluates its performance.

Trace-Level Classification

python3 codes/trace-level-classification.py

This script performs trace-level classification using following machine learning models:

  • Logistic Regression
  • Support Vector Machine
  • K-Nearest Neighbors
  • Decision Tree
  • Random Forest
  • XGBoost

ML Stats

The ml-stats.py script plots various statistics related to the machine learning models.

To run the ml-stats.py script, use the following command:

python3 codes/ml-stats.py

This script generates the following plots:

  • Accuracy vs Sequence Length for NAS and RRC datasets
  • Time Consumption vs Number of Packets
  • Memory Consumption vs Number of Packets
  • Power Consumption vs Number of Packets

The plots are saved in the outputs/figures directory.

MSA Performance Breakdown (TP, TN, FP, FN)

The graphsage_metrics.py script calculates metrics for the GraphSAGE model.

To run the graphsage_metrics.py script, use the following command:

python3 codes/graphsage_metrics.py <[dataset_path]>

Replace <dataset_path> with the path to your dataset file.

Example:

python3 codes/graphsage_metrics.py dataset/msa_nas.csv

This script generates a tabular summary of the following metrics for each class:

  • True Positives (TP)
  • True Negatives (TN)
  • False Positives (FP)
  • False Negatives (FN)

The results are printed to the console.

Feature Names

python3 codes/feature-names.py

This script prints the feature names from the dataset in the outputs/column_names_output.txt file.

Cross-Validation

To run the cross-validation.py script, use the following command:

python3 codes/cross-validation.py <[dataset_path]>

Replace <dataset_path> with the path to your dataset file.

Example:

python3 codes/cross-validation.py dataset/msa_nas.csv

This script performs leave-one-class-out cross-validation and generates the following outputs:

  • Accuracy for each fold
  • Detailed results for each fold, including true and predicted labels
  • A pivot table summarizing the true and predicted labels across all folds

Phoenix Implementation

To run our implementation for PHOENIX's signature-based detection, run the following codes. Download PHOENIX's signatures and traces from their website and put in the dataset folder.

DFA

The dfa.py script detects anomalies using a Deterministic Finite Automaton (DFA) parsed from a DOT file.

To run the dfa.py script, use the following command:

python phoenix-implementation/dfa.py <state_machine.dot><trace.pcap>

Replace <state_machine.dot> with the path to your DOT file and <trace.pcap> with the path to your trace file.

Example:

python3 phoenix-implementation/dfa.py dataset/signatures/dfa/NAS/attach_reject/attach_reject_50_40.trace.dot dataset/NAS_PCAP_logs/attach_reject.pcap

Mealy Machine

The mm.py script processes events using a Mealy Machine parsed from a DOT file.

To run the mm.py script, use the following command:

python phoenix-implementation/mm.py <trace.pcap>

Replace <trace.pcap> with the path to your trace file.

Example:

python3 phoenix-implementation/mm.py dataset/NAS_PCAP_logs/attach_reject.pcap

PLTL

The pltl.py script checks events against Propositional Linear Temporal Logic (PLTL) signatures.

To run the pltl.py script, use the following command:

python phoenix-implementation/pltl.py <trace.pcap>

Replace <trace.pcap> with the path to your trace file.

Example:

python phoenix-implementation/pltl.py dataset/NAS_PCAP_logs/attach_reject.pcap

Citation

If you use this dataset, models, or code modules, please cite the following paper:

@misc{mubasshir2025gottadetectemall,
title={Gotta Detect 'Em All: Fake Base Station and Multi-Step Attack Detection in Cellular Networks}, author={Kazi Samin Mubasshir and Imtiaz Karim and Elisa Bertino},
year={2025},
eprint={2401.04958},
archivePrefix={arXiv},
primaryClass={cs.CR},
url={https://arxiv.org/abs/2401.04958}, }

About

This repository contains code of the paper "Gotta Detect ’Em All: Fake Base Station and Multi-Step Attack Detection in Cellular Networks" for detecting Fake Base Stations (FBS) and Multi-Step Attacks (MSAs) from cellular network traces in the User Equipment (UE).

Topics

Resources

Stars

4 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - SysNetS/fbsdetector: This repository contains code of the paper "Gotta Detect ’Em All: Fake Base Station and Multi-Step Attack Detection in Cellular Networks" for detecting Fake Base Stations (FBS) and Multi-Step Attacks (MSAs) from cellular network traces in the User Equipment (UE). · GitHub
Skip to content

Repository files navigation

FBS Detection

This repository contains code of the paper "Gotta Detect ’Em All: Fake Base Station and Multi-Step Attack Detection in Cellular Networks" for detecting Fake Base Stations (FBS) and Multi-Step Attacks (MSAs) from cellular network traces in the User Equipment (UE).

Repository Structure

.
├── app/
│ ├── app-release.apk
│ ├── note.txt
├── codes/
│ ├── classification-models.py
│ ├── cross-validation.py
│ ├── feature-names.py
│ ├── graph_models.py
│ ├── graphsage_metrics.py
│ ├── ml-stats.py
│ ├── stateful-lstm-w-attn.py
│ └── trace-level-classification.py
│
├── dataset/
│ ├── fbs_nas.csv
│ ├── fbs_rrc.csv
│ ├── msa_nas.csv
│ ├── msa_rrc.csv
│ ├── msa_nas_reshaped.csv
│ ├── msa_rrc_reshaped.csv
│ ├── plot_data.json
│
├── phoenix-implementation/
│ ├── dfa.py
│ ├── mm.py
│ ├── packet_utils.py
│ └── pltl.py
│
└── requirements.txt

Description

This project implements a machine learning-based approach for detecting fake base stations and multi-step attacks from cellular network traces.

Dataset Labels

The 1-1 mapping of categorical and encoded labels is given below

Attack NameLabel
Benign0
Energy Depletion attack1
NAS counter Desynch attack2
X2 signalling flood3
Paging channel hijacking attack4
Bidding down with AttachReject5
Incarceration with rrcReject and rrcRelease6
Panic Attack7
Stealthy Kickoff Attack8
Authentication relay attack9
Location tracking via measurement reports10
Capability Hijacking11
Lullaby attack using rrcReestablishRequest12
Mobile Network Mapping (MNmap)13
Lullaby attack with rrcResume14
IMSI catching15
Incarceration with rrcReestablishReject16
Handover hijacking17
RRC replay attack18
Lullaby attack with rrcReconfiguration19
Bidding down with ServiceReject20
Bidding down with TAUReject21

Requirements

  • Python 3.7+
  • PyTorch
  • TensorFlow
  • NumPy
  • Pandas
  • scikit-learn
  • networkx

See requirements.txt for details.

Note

See the following sections to reproduce the results in the paper. You can also use this notebook to do all of it together.

Create and Activate Virtual Environment [Optional]

We will create and activate a virtual environment for the project.

Create the virtual environment

python3 -m venv venv

Activate the virtual environment

source venv/bin/activate

Install Dependencies

pip install -r requirements.txt

Run Classification Models

The classification-models.py script trains and evaluates the following models:

  • Random Forest (rf)
  • Support Vector Machine (svm)
  • Decision Tree (dt)
  • XGBoost (xgb)
  • K-Nearest Neighbors (knn)
  • Naive Bayes (nb)
  • Logistic Regression (lr)
  • Convolutional Neural Network (cnn)
  • Feedforward Neural Network (fnn)
  • Long Short-Term Memory Network (lstm)

To run the classification-models.py script, use the following command:

python codes/classification-models.py <[fbs_nas/msa_nas/fbs_rrc/msa_rrc].csv>

Replace <[fbs_nas/msa_nas/fbs_rrc/msa_rrc].csv> with the path to your dataset file.

Example:

python codes/classification-models.py dataset/fbs_nas.csv

The script will load the dataset, train the models, and display the performance metrics for each model for the provided dataset.

Run Graph Models

The graph_models.py script trains and evaluates the following graph neural network models:

  • Graph Attention Network (GAT)
  • Graph Attention Network v2 (GATv2)
  • Graph Convolutional Network (GCN)
  • GraphSAGE
  • Graph Transformer

To run the graph_models.py script, use the following command:

python3 codes/graph_models.py <[dataset_path]>

Replace <dataset_path> with the path to your dataset file.

Example:

python3 codes/graph_models.py dataset/msa_nas.csv

Stateful LSTM with Attention

To run the stateful-lstm-w-attn.py script, use the following command:

python3 codes/stateful-lstm-w-attn.py <[dataset_path]>

Replace <dataset_path> with the path to your dataset file.

Example:

python3 codes/stateful-lstm-w-attn.py dataset/fbs_nas.csv 

This script implements our stateful LSTM model with attention mechanism and evaluates its performance.

Trace-Level Classification

python3 codes/trace-level-classification.py

This script performs trace-level classification using following machine learning models:

  • Logistic Regression
  • Support Vector Machine
  • K-Nearest Neighbors
  • Decision Tree
  • Random Forest
  • XGBoost

ML Stats

The ml-stats.py script plots various statistics related to the machine learning models.

To run the ml-stats.py script, use the following command:

python3 codes/ml-stats.py

This script generates the following plots:

  • Accuracy vs Sequence Length for NAS and RRC datasets
  • Time Consumption vs Number of Packets
  • Memory Consumption vs Number of Packets
  • Power Consumption vs Number of Packets

The plots are saved in the outputs/figures directory.

MSA Performance Breakdown (TP, TN, FP, FN)

The graphsage_metrics.py script calculates metrics for the GraphSAGE model.

To run the graphsage_metrics.py script, use the following command:

python3 codes/graphsage_metrics.py <[dataset_path]>

Replace <dataset_path> with the path to your dataset file.

Example:

python3 codes/graphsage_metrics.py dataset/msa_nas.csv

This script generates a tabular summary of the following metrics for each class:

  • True Positives (TP)
  • True Negatives (TN)
  • False Positives (FP)
  • False Negatives (FN)

The results are printed to the console.

Feature Names

python3 codes/feature-names.py

This script prints the feature names from the dataset in the outputs/column_names_output.txt file.

Cross-Validation

To run the cross-validation.py script, use the following command:

python3 codes/cross-validation.py <[dataset_path]>

Replace <dataset_path> with the path to your dataset file.

Example:

python3 codes/cross-validation.py dataset/msa_nas.csv

This script performs leave-one-class-out cross-validation and generates the following outputs:

  • Accuracy for each fold
  • Detailed results for each fold, including true and predicted labels
  • A pivot table summarizing the true and predicted labels across all folds

Phoenix Implementation

To run our implementation for PHOENIX's signature-based detection, run the following codes. Download PHOENIX's signatures and traces from their website and put in the dataset folder.

DFA

The dfa.py script detects anomalies using a Deterministic Finite Automaton (DFA) parsed from a DOT file.

To run the dfa.py script, use the following command:

python phoenix-implementation/dfa.py <state_machine.dot><trace.pcap>

Replace <state_machine.dot> with the path to your DOT file and <trace.pcap> with the path to your trace file.

Example:

python3 phoenix-implementation/dfa.py dataset/signatures/dfa/NAS/attach_reject/attach_reject_50_40.trace.dot dataset/NAS_PCAP_logs/attach_reject.pcap

Mealy Machine

The mm.py script processes events using a Mealy Machine parsed from a DOT file.

To run the mm.py script, use the following command:

python phoenix-implementation/mm.py <trace.pcap>

Replace <trace.pcap> with the path to your trace file.

Example:

python3 phoenix-implementation/mm.py dataset/NAS_PCAP_logs/attach_reject.pcap

PLTL

The pltl.py script checks events against Propositional Linear Temporal Logic (PLTL) signatures.

To run the pltl.py script, use the following command:

python phoenix-implementation/pltl.py <trace.pcap>

Replace <trace.pcap> with the path to your trace file.

Example:

python phoenix-implementation/pltl.py dataset/NAS_PCAP_logs/attach_reject.pcap

Citation

If you use this dataset, models, or code modules, please cite the following paper:

@misc{mubasshir2025gottadetectemall,
title={Gotta Detect 'Em All: Fake Base Station and Multi-Step Attack Detection in Cellular Networks}, author={Kazi Samin Mubasshir and Imtiaz Karim and Elisa Bertino},
year={2025},
eprint={2401.04958},
archivePrefix={arXiv},
primaryClass={cs.CR},
url={https://arxiv.org/abs/2401.04958}, }

About

This repository contains code of the paper "Gotta Detect ’Em All: Fake Base Station and Multi-Step Attack Detection in Cellular Networks" for detecting Fake Base Stations (FBS) and Multi-Step Attacks (MSAs) from cellular network traces in the User Equipment (UE).

Topics

Resources

Stars

4 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' GitHub - SysNetS/fbsdetector: This repository contains code of the paper "Gotta Detect ’Em All: Fake Base Station and Multi-Step Attack Detection in Cellular Networks" for detecting Fake Base Stations (FBS) and Multi-Step Attacks (MSAs) from cellular network traces in the User Equipment (UE). · GitHub
Skip to content

Repository files navigation

FBS Detection

This repository contains code of the paper "Gotta Detect ’Em All: Fake Base Station and Multi-Step Attack Detection in Cellular Networks" for detecting Fake Base Stations (FBS) and Multi-Step Attacks (MSAs) from cellular network traces in the User Equipment (UE).

Repository Structure

.
├── app/
│ ├── app-release.apk
│ ├── note.txt
├── codes/
│ ├── classification-models.py
│ ├── cross-validation.py
│ ├── feature-names.py
│ ├── graph_models.py
│ ├── graphsage_metrics.py
│ ├── ml-stats.py
│ ├── stateful-lstm-w-attn.py
│ └── trace-level-classification.py
│
├── dataset/
│ ├── fbs_nas.csv
│ ├── fbs_rrc.csv
│ ├── msa_nas.csv
│ ├── msa_rrc.csv
│ ├── msa_nas_reshaped.csv
│ ├── msa_rrc_reshaped.csv
│ ├── plot_data.json
│
├── phoenix-implementation/
│ ├── dfa.py
│ ├── mm.py
│ ├── packet_utils.py
│ └── pltl.py
│
└── requirements.txt

Description

This project implements a machine learning-based approach for detecting fake base stations and multi-step attacks from cellular network traces.

Dataset Labels

The 1-1 mapping of categorical and encoded labels is given below

Attack NameLabel
Benign0
Energy Depletion attack1
NAS counter Desynch attack2
X2 signalling flood3
Paging channel hijacking attack4
Bidding down with AttachReject5
Incarceration with rrcReject and rrcRelease6
Panic Attack7
Stealthy Kickoff Attack8
Authentication relay attack9
Location tracking via measurement reports10
Capability Hijacking11
Lullaby attack using rrcReestablishRequest12
Mobile Network Mapping (MNmap)13
Lullaby attack with rrcResume14
IMSI catching15
Incarceration with rrcReestablishReject16
Handover hijacking17
RRC replay attack18
Lullaby attack with rrcReconfiguration19
Bidding down with ServiceReject20
Bidding down with TAUReject21

Requirements

  • Python 3.7+
  • PyTorch
  • TensorFlow
  • NumPy
  • Pandas
  • scikit-learn
  • networkx

See requirements.txt for details.

Note

See the following sections to reproduce the results in the paper. You can also use this notebook to do all of it together.

Create and Activate Virtual Environment [Optional]

We will create and activate a virtual environment for the project.

Create the virtual environment

python3 -m venv venv

Activate the virtual environment

source venv/bin/activate

Install Dependencies

pip install -r requirements.txt

Run Classification Models

The classification-models.py script trains and evaluates the following models:

  • Random Forest (rf)
  • Support Vector Machine (svm)
  • Decision Tree (dt)
  • XGBoost (xgb)
  • K-Nearest Neighbors (knn)
  • Naive Bayes (nb)
  • Logistic Regression (lr)
  • Convolutional Neural Network (cnn)
  • Feedforward Neural Network (fnn)
  • Long Short-Term Memory Network (lstm)

To run the classification-models.py script, use the following command:

python codes/classification-models.py <[fbs_nas/msa_nas/fbs_rrc/msa_rrc].csv>

Replace <[fbs_nas/msa_nas/fbs_rrc/msa_rrc].csv> with the path to your dataset file.

Example:

python codes/classification-models.py dataset/fbs_nas.csv

The script will load the dataset, train the models, and display the performance metrics for each model for the provided dataset.

Run Graph Models

The graph_models.py script trains and evaluates the following graph neural network models:

  • Graph Attention Network (GAT)
  • Graph Attention Network v2 (GATv2)
  • Graph Convolutional Network (GCN)
  • GraphSAGE
  • Graph Transformer

To run the graph_models.py script, use the following command:

python3 codes/graph_models.py <[dataset_path]>

Replace <dataset_path> with the path to your dataset file.

Example:

python3 codes/graph_models.py dataset/msa_nas.csv

Stateful LSTM with Attention

To run the stateful-lstm-w-attn.py script, use the following command:

python3 codes/stateful-lstm-w-attn.py <[dataset_path]>

Replace <dataset_path> with the path to your dataset file.

Example:

python3 codes/stateful-lstm-w-attn.py dataset/fbs_nas.csv 

This script implements our stateful LSTM model with attention mechanism and evaluates its performance.

Trace-Level Classification

python3 codes/trace-level-classification.py

This script performs trace-level classification using following machine learning models:

  • Logistic Regression
  • Support Vector Machine
  • K-Nearest Neighbors
  • Decision Tree
  • Random Forest
  • XGBoost

ML Stats

The ml-stats.py script plots various statistics related to the machine learning models.

To run the ml-stats.py script, use the following command:

python3 codes/ml-stats.py

This script generates the following plots:

  • Accuracy vs Sequence Length for NAS and RRC datasets
  • Time Consumption vs Number of Packets
  • Memory Consumption vs Number of Packets
  • Power Consumption vs Number of Packets

The plots are saved in the outputs/figures directory.

MSA Performance Breakdown (TP, TN, FP, FN)

The graphsage_metrics.py script calculates metrics for the GraphSAGE model.

To run the graphsage_metrics.py script, use the following command:

python3 codes/graphsage_metrics.py <[dataset_path]>

Replace <dataset_path> with the path to your dataset file.

Example:

python3 codes/graphsage_metrics.py dataset/msa_nas.csv

This script generates a tabular summary of the following metrics for each class:

  • True Positives (TP)
  • True Negatives (TN)
  • False Positives (FP)
  • False Negatives (FN)

The results are printed to the console.

Feature Names

python3 codes/feature-names.py

This script prints the feature names from the dataset in the outputs/column_names_output.txt file.

Cross-Validation

To run the cross-validation.py script, use the following command:

python3 codes/cross-validation.py <[dataset_path]>

Replace <dataset_path> with the path to your dataset file.

Example:

python3 codes/cross-validation.py dataset/msa_nas.csv

This script performs leave-one-class-out cross-validation and generates the following outputs:

  • Accuracy for each fold
  • Detailed results for each fold, including true and predicted labels
  • A pivot table summarizing the true and predicted labels across all folds

Phoenix Implementation

To run our implementation for PHOENIX's signature-based detection, run the following codes. Download PHOENIX's signatures and traces from their website and put in the dataset folder.

DFA

The dfa.py script detects anomalies using a Deterministic Finite Automaton (DFA) parsed from a DOT file.

To run the dfa.py script, use the following command:

python phoenix-implementation/dfa.py <state_machine.dot><trace.pcap>

Replace <state_machine.dot> with the path to your DOT file and <trace.pcap> with the path to your trace file.

Example:

python3 phoenix-implementation/dfa.py dataset/signatures/dfa/NAS/attach_reject/attach_reject_50_40.trace.dot dataset/NAS_PCAP_logs/attach_reject.pcap

Mealy Machine

The mm.py script processes events using a Mealy Machine parsed from a DOT file.

To run the mm.py script, use the following command:

python phoenix-implementation/mm.py <trace.pcap>

Replace <trace.pcap> with the path to your trace file.

Example:

python3 phoenix-implementation/mm.py dataset/NAS_PCAP_logs/attach_reject.pcap

PLTL

The pltl.py script checks events against Propositional Linear Temporal Logic (PLTL) signatures.

To run the pltl.py script, use the following command:

python phoenix-implementation/pltl.py <trace.pcap>

Replace <trace.pcap> with the path to your trace file.

Example:

python phoenix-implementation/pltl.py dataset/NAS_PCAP_logs/attach_reject.pcap

Citation

If you use this dataset, models, or code modules, please cite the following paper:

@misc{mubasshir2025gottadetectemall,
title={Gotta Detect 'Em All: Fake Base Station and Multi-Step Attack Detection in Cellular Networks}, author={Kazi Samin Mubasshir and Imtiaz Karim and Elisa Bertino},
year={2025},
eprint={2401.04958},
archivePrefix={arXiv},
primaryClass={cs.CR},
url={https://arxiv.org/abs/2401.04958}, }

About

This repository contains code of the paper "Gotta Detect ’Em All: Fake Base Station and Multi-Step Attack Detection in Cellular Networks" for detecting Fake Base Stations (FBS) and Multi-Step Attacks (MSAs) from cellular network traces in the User Equipment (UE).

Topics

Resources

Stars

4 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - SysNetS/fbsdetector: This repository contains code of the paper "Gotta Detect ’Em All: Fake Base Station and Multi-Step Attack Detection in Cellular Networks" for detecting Fake Base Stations (FBS) and Multi-Step Attacks (MSAs) from cellular network traces in the User Equipment (UE). · GitHub
Skip to content

Repository files navigation

FBS Detection

This repository contains code of the paper "Gotta Detect ’Em All: Fake Base Station and Multi-Step Attack Detection in Cellular Networks" for detecting Fake Base Stations (FBS) and Multi-Step Attacks (MSAs) from cellular network traces in the User Equipment (UE).

Repository Structure

.
├── app/
│ ├── app-release.apk
│ ├── note.txt
├── codes/
│ ├── classification-models.py
│ ├── cross-validation.py
│ ├── feature-names.py
│ ├── graph_models.py
│ ├── graphsage_metrics.py
│ ├── ml-stats.py
│ ├── stateful-lstm-w-attn.py
│ └── trace-level-classification.py
│
├── dataset/
│ ├── fbs_nas.csv
│ ├── fbs_rrc.csv
│ ├── msa_nas.csv
│ ├── msa_rrc.csv
│ ├── msa_nas_reshaped.csv
│ ├── msa_rrc_reshaped.csv
│ ├── plot_data.json
│
├── phoenix-implementation/
│ ├── dfa.py
│ ├── mm.py
│ ├── packet_utils.py
│ └── pltl.py
│
└── requirements.txt

Description

This project implements a machine learning-based approach for detecting fake base stations and multi-step attacks from cellular network traces.

Dataset Labels

The 1-1 mapping of categorical and encoded labels is given below

Attack NameLabel
Benign0
Energy Depletion attack1
NAS counter Desynch attack2
X2 signalling flood3
Paging channel hijacking attack4
Bidding down with AttachReject5
Incarceration with rrcReject and rrcRelease6
Panic Attack7
Stealthy Kickoff Attack8
Authentication relay attack9
Location tracking via measurement reports10
Capability Hijacking11
Lullaby attack using rrcReestablishRequest12
Mobile Network Mapping (MNmap)13
Lullaby attack with rrcResume14
IMSI catching15
Incarceration with rrcReestablishReject16
Handover hijacking17
RRC replay attack18
Lullaby attack with rrcReconfiguration19
Bidding down with ServiceReject20
Bidding down with TAUReject21

Requirements

  • Python 3.7+
  • PyTorch
  • TensorFlow
  • NumPy
  • Pandas
  • scikit-learn
  • networkx

See requirements.txt for details.

Note

See the following sections to reproduce the results in the paper. You can also use this notebook to do all of it together.

Create and Activate Virtual Environment [Optional]

We will create and activate a virtual environment for the project.

Create the virtual environment

python3 -m venv venv

Activate the virtual environment

source venv/bin/activate

Install Dependencies

pip install -r requirements.txt

Run Classification Models

The classification-models.py script trains and evaluates the following models:

  • Random Forest (rf)
  • Support Vector Machine (svm)
  • Decision Tree (dt)
  • XGBoost (xgb)
  • K-Nearest Neighbors (knn)
  • Naive Bayes (nb)
  • Logistic Regression (lr)
  • Convolutional Neural Network (cnn)
  • Feedforward Neural Network (fnn)
  • Long Short-Term Memory Network (lstm)

To run the classification-models.py script, use the following command:

python codes/classification-models.py <[fbs_nas/msa_nas/fbs_rrc/msa_rrc].csv>

Replace <[fbs_nas/msa_nas/fbs_rrc/msa_rrc].csv> with the path to your dataset file.

Example:

python codes/classification-models.py dataset/fbs_nas.csv

The script will load the dataset, train the models, and display the performance metrics for each model for the provided dataset.

Run Graph Models

The graph_models.py script trains and evaluates the following graph neural network models:

  • Graph Attention Network (GAT)
  • Graph Attention Network v2 (GATv2)
  • Graph Convolutional Network (GCN)
  • GraphSAGE
  • Graph Transformer

To run the graph_models.py script, use the following command:

python3 codes/graph_models.py <[dataset_path]>

Replace <dataset_path> with the path to your dataset file.

Example:

python3 codes/graph_models.py dataset/msa_nas.csv

Stateful LSTM with Attention

To run the stateful-lstm-w-attn.py script, use the following command:

python3 codes/stateful-lstm-w-attn.py <[dataset_path]>

Replace <dataset_path> with the path to your dataset file.

Example:

python3 codes/stateful-lstm-w-attn.py dataset/fbs_nas.csv 

This script implements our stateful LSTM model with attention mechanism and evaluates its performance.

Trace-Level Classification

python3 codes/trace-level-classification.py

This script performs trace-level classification using following machine learning models:

  • Logistic Regression
  • Support Vector Machine
  • K-Nearest Neighbors
  • Decision Tree
  • Random Forest
  • XGBoost

ML Stats

The ml-stats.py script plots various statistics related to the machine learning models.

To run the ml-stats.py script, use the following command:

python3 codes/ml-stats.py

This script generates the following plots:

  • Accuracy vs Sequence Length for NAS and RRC datasets
  • Time Consumption vs Number of Packets
  • Memory Consumption vs Number of Packets
  • Power Consumption vs Number of Packets

The plots are saved in the outputs/figures directory.

MSA Performance Breakdown (TP, TN, FP, FN)

The graphsage_metrics.py script calculates metrics for the GraphSAGE model.

To run the graphsage_metrics.py script, use the following command:

python3 codes/graphsage_metrics.py <[dataset_path]>

Replace <dataset_path> with the path to your dataset file.

Example:

python3 codes/graphsage_metrics.py dataset/msa_nas.csv

This script generates a tabular summary of the following metrics for each class:

  • True Positives (TP)
  • True Negatives (TN)
  • False Positives (FP)
  • False Negatives (FN)

The results are printed to the console.

Feature Names

python3 codes/feature-names.py

This script prints the feature names from the dataset in the outputs/column_names_output.txt file.

Cross-Validation

To run the cross-validation.py script, use the following command:

python3 codes/cross-validation.py <[dataset_path]>

Replace <dataset_path> with the path to your dataset file.

Example:

python3 codes/cross-validation.py dataset/msa_nas.csv

This script performs leave-one-class-out cross-validation and generates the following outputs:

  • Accuracy for each fold
  • Detailed results for each fold, including true and predicted labels
  • A pivot table summarizing the true and predicted labels across all folds

Phoenix Implementation

To run our implementation for PHOENIX's signature-based detection, run the following codes. Download PHOENIX's signatures and traces from their website and put in the dataset folder.

DFA

The dfa.py script detects anomalies using a Deterministic Finite Automaton (DFA) parsed from a DOT file.

To run the dfa.py script, use the following command:

python phoenix-implementation/dfa.py <state_machine.dot><trace.pcap>

Replace <state_machine.dot> with the path to your DOT file and <trace.pcap> with the path to your trace file.

Example:

python3 phoenix-implementation/dfa.py dataset/signatures/dfa/NAS/attach_reject/attach_reject_50_40.trace.dot dataset/NAS_PCAP_logs/attach_reject.pcap

Mealy Machine

The mm.py script processes events using a Mealy Machine parsed from a DOT file.

To run the mm.py script, use the following command:

python phoenix-implementation/mm.py <trace.pcap>

Replace <trace.pcap> with the path to your trace file.

Example:

python3 phoenix-implementation/mm.py dataset/NAS_PCAP_logs/attach_reject.pcap

PLTL

The pltl.py script checks events against Propositional Linear Temporal Logic (PLTL) signatures.

To run the pltl.py script, use the following command:

python phoenix-implementation/pltl.py <trace.pcap>

Replace <trace.pcap> with the path to your trace file.

Example:

python phoenix-implementation/pltl.py dataset/NAS_PCAP_logs/attach_reject.pcap

Citation

If you use this dataset, models, or code modules, please cite the following paper:

@misc{mubasshir2025gottadetectemall,
title={Gotta Detect 'Em All: Fake Base Station and Multi-Step Attack Detection in Cellular Networks}, author={Kazi Samin Mubasshir and Imtiaz Karim and Elisa Bertino},
year={2025},
eprint={2401.04958},
archivePrefix={arXiv},
primaryClass={cs.CR},
url={https://arxiv.org/abs/2401.04958}, }

About

This repository contains code of the paper "Gotta Detect ’Em All: Fake Base Station and Multi-Step Attack Detection in Cellular Networks" for detecting Fake Base Stations (FBS) and Multi-Step Attacks (MSAs) from cellular network traces in the User Equipment (UE).

Topics

Resources

Stars

4 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - SysNetS/fbsdetector: This repository contains code of the paper "Gotta Detect ’Em All: Fake Base Station and Multi-Step Attack Detection in Cellular Networks" for detecting Fake Base Stations (FBS) and Multi-Step Attacks (MSAs) from cellular network traces in the User Equipment (UE). · GitHub
Skip to content

Repository files navigation

FBS Detection

This repository contains code of the paper "Gotta Detect ’Em All: Fake Base Station and Multi-Step Attack Detection in Cellular Networks" for detecting Fake Base Stations (FBS) and Multi-Step Attacks (MSAs) from cellular network traces in the User Equipment (UE).

Repository Structure

.
├── app/
│ ├── app-release.apk
│ ├── note.txt
├── codes/
│ ├── classification-models.py
│ ├── cross-validation.py
│ ├── feature-names.py
│ ├── graph_models.py
│ ├── graphsage_metrics.py
│ ├── ml-stats.py
│ ├── stateful-lstm-w-attn.py
│ └── trace-level-classification.py
│
├── dataset/
│ ├── fbs_nas.csv
│ ├── fbs_rrc.csv
│ ├── msa_nas.csv
│ ├── msa_rrc.csv
│ ├── msa_nas_reshaped.csv
│ ├── msa_rrc_reshaped.csv
│ ├── plot_data.json
│
├── phoenix-implementation/
│ ├── dfa.py
│ ├── mm.py
│ ├── packet_utils.py
│ └── pltl.py
│
└── requirements.txt

Description

This project implements a machine learning-based approach for detecting fake base stations and multi-step attacks from cellular network traces.

Dataset Labels

The 1-1 mapping of categorical and encoded labels is given below

Attack NameLabel
Benign0
Energy Depletion attack1
NAS counter Desynch attack2
X2 signalling flood3
Paging channel hijacking attack4
Bidding down with AttachReject5
Incarceration with rrcReject and rrcRelease6
Panic Attack7
Stealthy Kickoff Attack8
Authentication relay attack9
Location tracking via measurement reports10
Capability Hijacking11
Lullaby attack using rrcReestablishRequest12
Mobile Network Mapping (MNmap)13
Lullaby attack with rrcResume14
IMSI catching15
Incarceration with rrcReestablishReject16
Handover hijacking17
RRC replay attack18
Lullaby attack with rrcReconfiguration19
Bidding down with ServiceReject20
Bidding down with TAUReject21

Requirements

  • Python 3.7+
  • PyTorch
  • TensorFlow
  • NumPy
  • Pandas
  • scikit-learn
  • networkx

See requirements.txt for details.

Note

See the following sections to reproduce the results in the paper. You can also use this notebook to do all of it together.

Create and Activate Virtual Environment [Optional]

We will create and activate a virtual environment for the project.

Create the virtual environment

python3 -m venv venv

Activate the virtual environment

source venv/bin/activate

Install Dependencies

pip install -r requirements.txt

Run Classification Models

The classification-models.py script trains and evaluates the following models:

  • Random Forest (rf)
  • Support Vector Machine (svm)
  • Decision Tree (dt)
  • XGBoost (xgb)
  • K-Nearest Neighbors (knn)
  • Naive Bayes (nb)
  • Logistic Regression (lr)
  • Convolutional Neural Network (cnn)
  • Feedforward Neural Network (fnn)
  • Long Short-Term Memory Network (lstm)

To run the classification-models.py script, use the following command:

python codes/classification-models.py <[fbs_nas/msa_nas/fbs_rrc/msa_rrc].csv>

Replace <[fbs_nas/msa_nas/fbs_rrc/msa_rrc].csv> with the path to your dataset file.

Example:

python codes/classification-models.py dataset/fbs_nas.csv

The script will load the dataset, train the models, and display the performance metrics for each model for the provided dataset.

Run Graph Models

The graph_models.py script trains and evaluates the following graph neural network models:

  • Graph Attention Network (GAT)
  • Graph Attention Network v2 (GATv2)
  • Graph Convolutional Network (GCN)
  • GraphSAGE
  • Graph Transformer

To run the graph_models.py script, use the following command:

python3 codes/graph_models.py <[dataset_path]>

Replace <dataset_path> with the path to your dataset file.

Example:

python3 codes/graph_models.py dataset/msa_nas.csv

Stateful LSTM with Attention

To run the stateful-lstm-w-attn.py script, use the following command:

python3 codes/stateful-lstm-w-attn.py <[dataset_path]>

Replace <dataset_path> with the path to your dataset file.

Example:

python3 codes/stateful-lstm-w-attn.py dataset/fbs_nas.csv 

This script implements our stateful LSTM model with attention mechanism and evaluates its performance.

Trace-Level Classification

python3 codes/trace-level-classification.py

This script performs trace-level classification using following machine learning models:

  • Logistic Regression
  • Support Vector Machine
  • K-Nearest Neighbors
  • Decision Tree
  • Random Forest
  • XGBoost

ML Stats

The ml-stats.py script plots various statistics related to the machine learning models.

To run the ml-stats.py script, use the following command:

python3 codes/ml-stats.py

This script generates the following plots:

  • Accuracy vs Sequence Length for NAS and RRC datasets
  • Time Consumption vs Number of Packets
  • Memory Consumption vs Number of Packets
  • Power Consumption vs Number of Packets

The plots are saved in the outputs/figures directory.

MSA Performance Breakdown (TP, TN, FP, FN)

The graphsage_metrics.py script calculates metrics for the GraphSAGE model.

To run the graphsage_metrics.py script, use the following command:

python3 codes/graphsage_metrics.py <[dataset_path]>

Replace <dataset_path> with the path to your dataset file.

Example:

python3 codes/graphsage_metrics.py dataset/msa_nas.csv

This script generates a tabular summary of the following metrics for each class:

  • True Positives (TP)
  • True Negatives (TN)
  • False Positives (FP)
  • False Negatives (FN)

The results are printed to the console.

Feature Names

python3 codes/feature-names.py

This script prints the feature names from the dataset in the outputs/column_names_output.txt file.

Cross-Validation

To run the cross-validation.py script, use the following command:

python3 codes/cross-validation.py <[dataset_path]>

Replace <dataset_path> with the path to your dataset file.

Example:

python3 codes/cross-validation.py dataset/msa_nas.csv

This script performs leave-one-class-out cross-validation and generates the following outputs:

  • Accuracy for each fold
  • Detailed results for each fold, including true and predicted labels
  • A pivot table summarizing the true and predicted labels across all folds

Phoenix Implementation

To run our implementation for PHOENIX's signature-based detection, run the following codes. Download PHOENIX's signatures and traces from their website and put in the dataset folder.

DFA

The dfa.py script detects anomalies using a Deterministic Finite Automaton (DFA) parsed from a DOT file.

To run the dfa.py script, use the following command:

python phoenix-implementation/dfa.py <state_machine.dot><trace.pcap>

Replace <state_machine.dot> with the path to your DOT file and <trace.pcap> with the path to your trace file.

Example:

python3 phoenix-implementation/dfa.py dataset/signatures/dfa/NAS/attach_reject/attach_reject_50_40.trace.dot dataset/NAS_PCAP_logs/attach_reject.pcap

Mealy Machine

The mm.py script processes events using a Mealy Machine parsed from a DOT file.

To run the mm.py script, use the following command:

python phoenix-implementation/mm.py <trace.pcap>

Replace <trace.pcap> with the path to your trace file.

Example:

python3 phoenix-implementation/mm.py dataset/NAS_PCAP_logs/attach_reject.pcap

PLTL

The pltl.py script checks events against Propositional Linear Temporal Logic (PLTL) signatures.

To run the pltl.py script, use the following command:

python phoenix-implementation/pltl.py <trace.pcap>

Replace <trace.pcap> with the path to your trace file.

Example:

python phoenix-implementation/pltl.py dataset/NAS_PCAP_logs/attach_reject.pcap

Citation

If you use this dataset, models, or code modules, please cite the following paper:

@misc{mubasshir2025gottadetectemall,
title={Gotta Detect 'Em All: Fake Base Station and Multi-Step Attack Detection in Cellular Networks}, author={Kazi Samin Mubasshir and Imtiaz Karim and Elisa Bertino},
year={2025},
eprint={2401.04958},
archivePrefix={arXiv},
primaryClass={cs.CR},
url={https://arxiv.org/abs/2401.04958}, }

About

This repository contains code of the paper "Gotta Detect ’Em All: Fake Base Station and Multi-Step Attack Detection in Cellular Networks" for detecting Fake Base Stations (FBS) and Multi-Step Attacks (MSAs) from cellular network traces in the User Equipment (UE).

Topics

Resources

Stars

4 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); GitHub - SysNetS/fbsdetector: This repository contains code of the paper "Gotta Detect ’Em All: Fake Base Station and Multi-Step Attack Detection in Cellular Networks" for detecting Fake Base Stations (FBS) and Multi-Step Attacks (MSAs) from cellular network traces in the User Equipment (UE). · GitHub
Skip to content

Repository files navigation

FBS Detection

This repository contains code of the paper "Gotta Detect ’Em All: Fake Base Station and Multi-Step Attack Detection in Cellular Networks" for detecting Fake Base Stations (FBS) and Multi-Step Attacks (MSAs) from cellular network traces in the User Equipment (UE).

Repository Structure

.
├── app/
│ ├── app-release.apk
│ ├── note.txt
├── codes/
│ ├── classification-models.py
│ ├── cross-validation.py
│ ├── feature-names.py
│ ├── graph_models.py
│ ├── graphsage_metrics.py
│ ├── ml-stats.py
│ ├── stateful-lstm-w-attn.py
│ └── trace-level-classification.py
│
├── dataset/
│ ├── fbs_nas.csv
│ ├── fbs_rrc.csv
│ ├── msa_nas.csv
│ ├── msa_rrc.csv
│ ├── msa_nas_reshaped.csv
│ ├── msa_rrc_reshaped.csv
│ ├── plot_data.json
│
├── phoenix-implementation/
│ ├── dfa.py
│ ├── mm.py
│ ├── packet_utils.py
│ └── pltl.py
│
└── requirements.txt

Description

This project implements a machine learning-based approach for detecting fake base stations and multi-step attacks from cellular network traces.

Dataset Labels

The 1-1 mapping of categorical and encoded labels is given below

Attack NameLabel
Benign0
Energy Depletion attack1
NAS counter Desynch attack2
X2 signalling flood3
Paging channel hijacking attack4
Bidding down with AttachReject5
Incarceration with rrcReject and rrcRelease6
Panic Attack7
Stealthy Kickoff Attack8
Authentication relay attack9
Location tracking via measurement reports10
Capability Hijacking11
Lullaby attack using rrcReestablishRequest12
Mobile Network Mapping (MNmap)13
Lullaby attack with rrcResume14
IMSI catching15
Incarceration with rrcReestablishReject16
Handover hijacking17
RRC replay attack18
Lullaby attack with rrcReconfiguration19
Bidding down with ServiceReject20
Bidding down with TAUReject21

Requirements

  • Python 3.7+
  • PyTorch
  • TensorFlow
  • NumPy
  • Pandas
  • scikit-learn
  • networkx

See requirements.txt for details.

Note

See the following sections to reproduce the results in the paper. You can also use this notebook to do all of it together.

Create and Activate Virtual Environment [Optional]

We will create and activate a virtual environment for the project.

Create the virtual environment

python3 -m venv venv

Activate the virtual environment

source venv/bin/activate

Install Dependencies

pip install -r requirements.txt

Run Classification Models

The classification-models.py script trains and evaluates the following models:

  • Random Forest (rf)
  • Support Vector Machine (svm)
  • Decision Tree (dt)
  • XGBoost (xgb)
  • K-Nearest Neighbors (knn)
  • Naive Bayes (nb)
  • Logistic Regression (lr)
  • Convolutional Neural Network (cnn)
  • Feedforward Neural Network (fnn)
  • Long Short-Term Memory Network (lstm)

To run the classification-models.py script, use the following command:

python codes/classification-models.py <[fbs_nas/msa_nas/fbs_rrc/msa_rrc].csv>

Replace <[fbs_nas/msa_nas/fbs_rrc/msa_rrc].csv> with the path to your dataset file.

Example:

python codes/classification-models.py dataset/fbs_nas.csv

The script will load the dataset, train the models, and display the performance metrics for each model for the provided dataset.

Run Graph Models

The graph_models.py script trains and evaluates the following graph neural network models:

  • Graph Attention Network (GAT)
  • Graph Attention Network v2 (GATv2)
  • Graph Convolutional Network (GCN)
  • GraphSAGE
  • Graph Transformer

To run the graph_models.py script, use the following command:

python3 codes/graph_models.py <[dataset_path]>

Replace <dataset_path> with the path to your dataset file.

Example:

python3 codes/graph_models.py dataset/msa_nas.csv

Stateful LSTM with Attention

To run the stateful-lstm-w-attn.py script, use the following command:

python3 codes/stateful-lstm-w-attn.py <[dataset_path]>

Replace <dataset_path> with the path to your dataset file.

Example:

python3 codes/stateful-lstm-w-attn.py dataset/fbs_nas.csv 

This script implements our stateful LSTM model with attention mechanism and evaluates its performance.

Trace-Level Classification

python3 codes/trace-level-classification.py

This script performs trace-level classification using following machine learning models:

  • Logistic Regression
  • Support Vector Machine
  • K-Nearest Neighbors
  • Decision Tree
  • Random Forest
  • XGBoost

ML Stats

The ml-stats.py script plots various statistics related to the machine learning models.

To run the ml-stats.py script, use the following command:

python3 codes/ml-stats.py

This script generates the following plots:

  • Accuracy vs Sequence Length for NAS and RRC datasets
  • Time Consumption vs Number of Packets
  • Memory Consumption vs Number of Packets
  • Power Consumption vs Number of Packets

The plots are saved in the outputs/figures directory.

MSA Performance Breakdown (TP, TN, FP, FN)

The graphsage_metrics.py script calculates metrics for the GraphSAGE model.

To run the graphsage_metrics.py script, use the following command:

python3 codes/graphsage_metrics.py <[dataset_path]>

Replace <dataset_path> with the path to your dataset file.

Example:

python3 codes/graphsage_metrics.py dataset/msa_nas.csv

This script generates a tabular summary of the following metrics for each class:

  • True Positives (TP)
  • True Negatives (TN)
  • False Positives (FP)
  • False Negatives (FN)

The results are printed to the console.

Feature Names

python3 codes/feature-names.py

This script prints the feature names from the dataset in the outputs/column_names_output.txt file.

Cross-Validation

To run the cross-validation.py script, use the following command:

python3 codes/cross-validation.py <[dataset_path]>

Replace <dataset_path> with the path to your dataset file.

Example:

python3 codes/cross-validation.py dataset/msa_nas.csv

This script performs leave-one-class-out cross-validation and generates the following outputs:

  • Accuracy for each fold
  • Detailed results for each fold, including true and predicted labels
  • A pivot table summarizing the true and predicted labels across all folds

Phoenix Implementation

To run our implementation for PHOENIX's signature-based detection, run the following codes. Download PHOENIX's signatures and traces from their website and put in the dataset folder.

DFA

The dfa.py script detects anomalies using a Deterministic Finite Automaton (DFA) parsed from a DOT file.

To run the dfa.py script, use the following command:

python phoenix-implementation/dfa.py <state_machine.dot><trace.pcap>

Replace <state_machine.dot> with the path to your DOT file and <trace.pcap> with the path to your trace file.

Example:

python3 phoenix-implementation/dfa.py dataset/signatures/dfa/NAS/attach_reject/attach_reject_50_40.trace.dot dataset/NAS_PCAP_logs/attach_reject.pcap

Mealy Machine

The mm.py script processes events using a Mealy Machine parsed from a DOT file.

To run the mm.py script, use the following command:

python phoenix-implementation/mm.py <trace.pcap>

Replace <trace.pcap> with the path to your trace file.

Example:

python3 phoenix-implementation/mm.py dataset/NAS_PCAP_logs/attach_reject.pcap

PLTL

The pltl.py script checks events against Propositional Linear Temporal Logic (PLTL) signatures.

To run the pltl.py script, use the following command:

python phoenix-implementation/pltl.py <trace.pcap>

Replace <trace.pcap> with the path to your trace file.

Example:

python phoenix-implementation/pltl.py dataset/NAS_PCAP_logs/attach_reject.pcap

Citation

If you use this dataset, models, or code modules, please cite the following paper:

@misc{mubasshir2025gottadetectemall,
title={Gotta Detect 'Em All: Fake Base Station and Multi-Step Attack Detection in Cellular Networks}, author={Kazi Samin Mubasshir and Imtiaz Karim and Elisa Bertino},
year={2025},
eprint={2401.04958},
archivePrefix={arXiv},
primaryClass={cs.CR},
url={https://arxiv.org/abs/2401.04958}, }

About

This repository contains code of the paper "Gotta Detect ’Em All: Fake Base Station and Multi-Step Attack Detection in Cellular Networks" for detecting Fake Base Stations (FBS) and Multi-Step Attacks (MSAs) from cellular network traces in the User Equipment (UE).

Topics

Resources

Stars

4 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages