Attack detection Model Deployement on Free5GC

i want to deploy ddos attack detection model in free5gc setup. Do anyone have any idea about architecture or where to deploy it.

Hi,

You could monitor traffic at the AMF or SMF to analyze whether there are anomalies in UE registration, NAS signaling, or PDU session requests. Additionally, you may deploy the model near the UPF to monitor the N3 and N6 interfaces for abnormal GTP-U traffic.

Best regards,
Peggy