5G Infrastructure Protocol Anomaly Detection

Detects anomalous device network activity involving 5G-specific protocol ports (e.g., GTP-U, SIP). The rule aggregates unique port usage per device over 1-hour intervals to identify potential network reconnaissance, scanning, or unauthorized control plane communication.