提升私有5G上加密OPC UA流量异常检测的可靠性
Improving the Reliability of Anomaly Detection for Encrypted OPC UA Traffic over Private 5G
浏览论文内容
中文总结 AI 辅助
针对私有5G上加密OPC UA流量异常检测因良性连接变化导致误报率高的问题,提出控制面感知的决策自适应方法,在不重训练模型的情况下降低误报率并保持召回率。
中文摘要 AI 辅助
开放平台通信统一架构(OPC UA)越来越多地部署在工业环境中的私有5G网络上,其中端到端加密阻止了基于网络的入侵检测系统(IDS)进行载荷检查。尽管从加密流量中提取的与载荷无关的统计特征能够实现基于流量的异常检测,但良性的连接变化可能会改变可观测的用户面(UP)行为,并增加误报率(FPR)。本文研究了这一可靠性问题,并提出了一种针对四个冻结IDS模型的控制面(CP)感知决策自适应方法。利用用户设备(UE)级别的CP指标构建时间CP上下文,在该上下文中应用在自适应验证数据上选择的CP特定阈值,而原始阈值在上下文之外保持有效。流量特征、攻击评分、预处理过程和训练后的模型参数保持不变。在真实的工业私有5G测试平台上的评估表明,良性的连接变化增加了所有四个评估模型的FPR,并且误报集中在与CP活动时间相关的时段内。所提出的CP感知决策自适应降低了全局FPR和CP上下文内的FPR,同时在完整攻击活动中引入了FPR降低与保留召回率之间的可配置权衡。这些发现表明,CP上下文可以在不重新训练底层模型的情况下提高加密流量入侵检测的操作可靠性。
英文摘要
Open Platform Communications Unified Architecture (OPC UA) is increasingly deployed over private 5G networks in industrial environments, where end-to-end encryption prevents payload inspection by network-based intrusion detection systems (IDSs). Although payload-agnostic statistical features extracted from encrypted traffic enable traffic-based anomaly detection, benign connectivity variations may alter observable user-plane (UP) behavior and increase the false-positive rate (FPR). This paper investigates this reliability problem and proposes a control-plane (CP)-aware decision adaptation for four frozen IDS models. CP indicators at the user equipment (UE) level are used to construct a temporal CP context in which a CP-specific threshold selected on adaptation validation data is applied, while the original threshold remains active outside the context. The traffic features, attack scores, preprocessing procedure, and trained model parameters remain unchanged. Evaluation on a real industrial private 5G testbed shows that benign connectivity variations increase the FPR for all four evaluated models and that false positives are concentrated within periods temporally associated with CP activity. The proposed CP-aware decision adaptation reduces both global FPR and FPR within the CP context while introducing a configurable trade-off between FPR reduction and retained recall over the complete attack campaign. These findings demonstrate that CP context can improve the operational reliability of encrypted-traffic intrusion detection without retraining the underlying models.
发表机构
- Helmut-Schmidt-University(赫尔穆特·施密特大学)
- Technical University of Applied Sciences Augsburg(奥格斯堡应用技术大学)
- ipoque GmbH(ipoque有限公司)
机构由 AI 辅助整理,请以论文原文为准。