AI 中文总结
研究工业专用5G网络中良性连接变化对加密OPC UA流量的机器学习入侵检测系统的影响,通过实验发现合法连接事件会增加误报,且异常分数升高与控制平面活动有关,强调解释入侵检测输出时考虑控制平面上下文的重要性。
AI 中文摘要
基于机器学习的入侵检测系统越来越多地用于监控加密的工业通信。然而,在实际专用5G运行条件下其行为仍未得到充分理解。本文研究了良性连接变化对工业专用5G网络中加密的开放平台通信统一架构(OPC UA)流量的基于机器学习的入侵检测系统的影响。实验结果表明,合法连接事件在无攻击时也会显著增加误报活动。此外,入侵检测系统异常分数升高常与这些事件相关的控制平面活动期一致。研究结果凸显了在工业专用5G环境中解释入侵检测系统输出时考虑控制平面上下文的重要性。
英文摘要
Machine learning (ML)-based intrusion detection systems (IDSs) are increasingly used to monitor encrypted industrial communication. However, their behavior under realistic private 5G operating conditions remains insufficiently understood. This paper investigates the impact of benign connectivity variations on ML-based IDSs for encrypted Open Platform Communications Unified Architecture (OPC UA) traffic in industrial private 5G networks. Experimental results show that legitimate connectivity events can noticeably increase false positive activity despite the absence of attacks. Furthermore, elevated IDS anomaly scores frequently coincide with periods of control-plane (CP) activity associated with these events. The findings highlight the importance of considering CP context when interpreting IDS outputs in industrial private 5G environments.
Comments7 pages, 2 figures, 3 tables. Accepted for presentation at the 31st IEEE International Conference on Emerging Technologies and Factory Automation (ETFA 2026)