Improving the Reliability of Anomaly Detection for Encrypted OPC UA Traffic over Private 5G
Paper proposes control-plane-aware threshold adaptation that cuts false positives in encrypted OPC UA traffic anomaly detection on industrial private 5G.
The arXiv paper addresses false positives in payload-agnostic anomaly detection for encrypted OPC UA traffic over industrial private 5G networks. The authors build a temporal control-plane context from user-equipment-level indicators and apply a CP-specific threshold for four frozen IDS models, leaving the original threshold active outside that context. Evaluation on a real industrial private 5G testbed showed the adaptation reduces both global FPR and FPR within the CP context, with a configurable trade-off between FPR reduction and retained recall, all without retraining models.
- Benign 5G connectivity variations raise false positives for all four tested IDS models
- False positives concentrate in periods tied to control-plane activity
- CP-aware threshold adaptation requires no retraining or model changes
- Trade-off between false positive reduction and recall is configurable
Full article209 words · extracted from arxiv.org · click to collapse
Open Platform Communications Unified Architecture (OPC UA) is increasingly deployed over private 5G networks in industrial environments, where end-to-end encryption prevents payload inspection by network-based intrusion detection systems (IDSs). Although payload-agnostic statistical features extracted from encrypted traffic enable traffic-based anomaly detection, benign connectivity variations may alter observable user-plane (UP) behavior and increase the false-positive rate (FPR). This paper investigates this reliability problem and proposes a control-plane (CP)-aware decision adaptation for four frozen IDS models. CP indicators at the user equipment (UE) level are used to construct a temporal CP context in which a CP-specific threshold selected on adaptation validation data is applied, while the original threshold remains active outside the context. The traffic features, attack scores, preprocessing procedure, and trained model parameters remain unchanged. Evaluation on a real industrial private 5G testbed shows that benign connectivity variations increase the FPR for all four evaluated models and that false positives are concentrated within periods temporally associated with CP activity. The proposed CP-aware decision adaptation reduces both global FPR and FPR within the CP context while introducing a configurable trade-off between FPR reduction and retained recall over the complete attack campaign. These findings demonstrate that CP context can improve the operational reliability of encrypted-traffic intrusion detection without retraining the underlying models.
Text extracted automatically; images, tables and formatting may be missing. Original: https://arxiv.org/abs/2609.29745