{"$schema":"https://wellknown.network/schemas/agent-record-v1.json","schemaVersion":"1","id":"ag_d5z2bswbks7v","handle":"5g-ddos-mcp","url":"https://wellknown.network/agents/5g-ddos-mcp","links":{"self":"https://wellknown.network/agents/5g-ddos-mcp/record.json","html":"https://wellknown.network/agents/5g-ddos-mcp","markdown":"https://wellknown.network/agents/5g-ddos-mcp/record.md","api":"https://wellknown.network/api/v1/agents/5g-ddos-mcp","status":"https://wellknown.network/api/v1/agents/5g-ddos-mcp/status","claim":"https://wellknown.network/agents/5g-ddos-mcp/claim","claimApi":"https://wellknown.network/api/v1/claims","claimDescriptor":"https://wellknown.network/agents/5g-ddos-mcp/claim.json","badge":"https://wellknown.network/agents/5g-ddos-mcp/badge.svg","openapi":"https://wellknown.network/openapi.json"},"ard":{"identifier":"urn:air::server:5g-ddos-mcp","type":"application/mcp-server-card+json"},"kind":"mcp_server","declared":{"name":"5g-ddos-mcp","summary":"MCP server for 5G DDoS detection using the NCSRD-DS-5GDDoS dataset","description":"<p align=\"center\">\n  <img src=\"logo.svg\" alt=\"5g-ddos-mcp\" width=\"520\"/>\n</p>\n\n<p align=\"center\">\n  <b>Model Context Protocol server for real-time 5G DDoS detection and response</b><br/>\n  Powered by the <a href=\"https://doi.org/10.5281/zenodo.13900057\">NCSRD-DS-5GDDoS dataset</a> — a physical 3GPP-compliant 5G testbed from the EU Horizon PRIVATEER project\n</p>\n\n<p align=\"center\">\n  <img src=\"https://img.shields.io/badge/Python-3.10%2B-blue?style=flat-square&logo=python&logoColor=white\"/>\n  <img src=\"https://img.shields.io/badge/MCP-1.3%2B-green?style=flat-square\"/>\n  <img src=\"https://img.shields.io/badge/XGBoost-ML%20model-orange?style=flat-square\"/>\n  <img src=\"https://img.shields.io/badge/Docker-ready-2496ED?style=flat-square&logo=docker&logoColor=white\"/>\n  <img src=\"https://img.shields.io/badge/Kubernetes-ready-326CE5?style=flat-square&logo=kubernetes&logoColor=white\"/>\n  <img src=\"https://img.shields.io/badge/License-MIT-lightgrey?style=flat-square\"/>\n</p>\n\n---\n\n## What It Does\n\nGives any LLM agent the ability to detect, explain, and respond to 5G DDoS attacks:\n\n| Tool | What it does |\n|------|-------------|\n| `detect_anomaly` | Classify live 5G telemetry as benign/attack — returns type, confidence, severity |\n| `explain_attack` | Generate a natural-language incident report via the configured LLM |\n| `recommend_response` | Slice-aware mitigation plan with generic REST API call examples |\n| `query_history` | Search past incidents + dataset reference patterns for few-shot LLM reasoning |\n\nSupports **SYN, UDP, ICMP, DNS, and GTP-U flooding** (the last being 5G-specific, critical severity).\n\n---\n\n## Quick Start\n\nPick your LLM backend and follow the matching path. The server runs in **demo mode** (rule-based heuristics) without a trained model, so you can try all tools immediately.\n\n---\n\n### Option A — Claude (Anthropic API)\n\n> Best output quality for incident reports and recommendations.\n\n```bash\n# 1. Clone and install\ngit clone https://github.com/ncsrd/5g-ddos-…","publisher":null,"homepage":null,"repository":null,"version":"1.0.0","license":"MIT","protocols":["mcp"],"tags":["5g","ai","ddos","mcp","privateer","security"],"pricing":null,"endpoints":[{"url":"pypi:5g-ddos-mcp","type":"package_pypi","auth":null,"probeable":false}],"skills":null,"tools":null,"extra":null,"attribution":{"kind":"pypi","name":"pypi","license":"pypi","summary":"pypi","version":"pypi","description":"pypi"}},"derived":{"capabilities":[{"slug":"infra.cloud","name":"Cloud Platforms","confidence":0.825,"provenance":"derived"},{"slug":"dev.version-control","name":"Version Control","confidence":0.745,"provenance":"derived"}],"categories":["dev","infra"],"language":"en"},"observed":{"status":"unknown","statusReason":"Distributed as a package to run locally; no network endpoint to check.","lastOkAt":null,"lastProbedAt":null,"statusComputedAt":null,"reliability30d":null,"latestObservations":[],"tools":null,"package":{"name":"5g-ddos-mcp","registry":"pypi","observedAt":"2026-09-09T08:22:12.877Z","publishedAt":"2026-03-21T16:45:12.103393Z","latestVersion":"1.0.0"}},"verification":{"claimed":false,"claimedAt":null,"proofs":[]},"provenance":{"sources":[{"source":"pypi","key":"5g-ddos-mcp","url":"https://pypi.org/project/5g-ddos-mcp/","firstSeenAt":"2026-09-09T08:19:56.794Z","fetchedAt":"2026-09-09T08:19:56.794Z","normalizedAt":"2026-09-09T08:19:56.794Z"}]},"firstSeenAt":"2026-09-09T08:19:56.794Z","updatedAt":"2026-09-09T08:22:12.877Z"}