MCP server for 5G DDoS detection using the NCSRD-DS-5GDDoS dataset
Wellknown found it in public sources; nobody has proven control of it yet. Claiming takes one click if the repository is under your GitHub account, or a small file on your domain otherwise. Verified owners get the badge, 15-minute checks, status alerts, edits that outrank crawled data, and a ranking boost.
Agents can do it too: POST https://wellknown.network/api/v1/claims with {"agent":"5g-ddos-mcp","method":"well_known_file"} — machine-readable steps at claim.json, guide at /docs/claim.
Everything here was measured by our prober or read from a registry. Nothing is self-reported.
Attributed to the source that supplied each field. Treated as claims, not facts.
<p align="center"> <img src="logo.svg" alt="5g-ddos-mcp" width="520"/> </p> <p align="center"> <b>Model Context Protocol server for real-time 5G DDoS detection and response</b><br/> Powered by the <a href="https://doi.org/10.5281/zenodo.13900057">NCSRD-DS-5GDDoS dataset</a> — a physical 3GPP-compliant 5G testbed from the EU Horizon PRIVATEER project </p> <p align="center"> <img src="https://img.shields.io/badge/Python-3.10%2B-blue?style=flat-square&logo=python&logoColor=white"/> <img src="https://img.shields.io/badge/MCP-1.3%2B-green?style=flat-square"/> <img src="https://img.shields.io/badge/XGBoost-ML%20model-orange?style=flat-square"/> <img src="https://img.shields.io/badge/Docker-ready-2496ED?style=flat-square&logo=docker&logoColor=white"/> <img src="https://img.shields.io/badge/Kubernetes-ready-326CE5?style=flat-square&logo=kubernetes&logoColor=white"/> <img src="https://img.shields.io/badge/License-MIT-lightgrey?style=flat-square"/> </p> --- ## What It Does Gives any LLM agent the ability to detect, explain, and respond to 5G DDoS attacks: | Tool | What it does | |------|-------------| | `detect_anomaly` | Classify live 5G telemetry as benign/attack — returns type, confidence, severity | | `explain_attack` | Generate a natural-language incident report via the configured LLM | | `recommend_response` | Slice-aware mitigation plan with generic REST API call examples | | `query_history` | Search past incidents + dataset reference patterns for few-shot LLM reasoning | Supports **SYN, UDP, ICMP, DNS, and GTP-U flooding** (the last being 5G-specific, critical severity). --- ## Quick Start Pick your LLM backend and follow the matching path. The server runs in **demo mode** (rule-based heuristics) without a trained model, so you can try all tools immediately. --- ### Option A — Claude (Anthropic API) > Best output quality for incident reports and recommendations. ```bash # 1. Clone and install git clone https://github.com/ncsrd/5g-ddos-…
Mapped onto the structured taxonomy from declared text and observed tool names. Confidence shown for derived entries.
Every source is kept verbatim. Field changes are logged as events.