面向工业智联网的5G风筝专网弹性安全预测模型

Elastic Security Prediction Model for 5G Kite Private Networks Oriented to Industrial Intelligent Internet

  • 摘要: 针对工业智联网体系中5G专网安全态势预测时,强周期性的生产节律往往掩蔽微弱攻击特征的难题,提出了一种基于ARIMA-LSTM的业务与安全语义分离预测架构。以实际部署于关键工业场景的5G风筝专网为对象,针对静态稳定与动态弹性两类运行场景,选取N4接口异常信令占比、会话管理功能(SMF)失败率等关键指标。不同于传统混合模型简单的加权组合,该机制创新性地利用自回归积分滑动平均(ARIMA)模型作为生产节律滤波器,精准剥离由工业流水线作业引发的合法确定性波动,构建动态业务基线;进而利用长短期记忆(LSTM)网络在剥离了业务噪声的纯净残差域中聚焦随机性攻击特征的学习。这种业务滤除与风险放大机制有效克服了工业高噪环境下早期威胁难以识别的痛点。基于真实专网数据的实验结果表明,该模型在静态场景下均方根误差(RMSE)与平均绝对百分比误差(MAPE)分别低至0.82和4.2%,较ARIMA、LSTM分别降低81.4%、66.2%以及78.9%、71.6%;在包含网元切换与信令攻击的动态场景下平均RMSE增幅仅19.5%,60 min长期预测衰减率为LSTM的48.2%,并在6类安全指标中均保持最优性能。实验结果验证了该模型在工业智联网专网中的预测稳定性与鲁棒性,可为工业智联网弹性安全防护与智能运维提供技术支撑。

     

    Abstract: To address the challenge of simultaneously capturing linear trends and nonlinear fluctuations in the security situation prediction of 5G private networks within the Industrial Internet of Intelligence, we propose an ARIMA-LSTM-based prediction architecture for semantic separation between business and security features. Focusing on the 5G kite private network deployed in key industrial scenarios, we target two types of operational conditions: static stability scenarios and dynamic elasticity scenarios. Key indicators, such as the proportion of abnormal signaling at the N4 interface and the session management function (SMF) session failure rate, are selected. The model extracts periodic linear features using the autoregressive integrated moving average (ARIMA) model and combines them with the long short-term memory (LSTM) network's ability to learn nonlinear patterns from sudden disturbances and random residuals, thereby constructing a collaborative prediction mechanism for communication data and security situational awareness. Experimental results based on real-world data show that in static scenarios, the root mean square error (RMSE) and mean absolute percentage error (MAPE) of the proposed model are as low as 0.82 and 4.2%, respectively. These figures represent reductions of 81.4% and 66.2% in RMSE, and 78.9% and 71.6% in MAPE, compared to standalone ARIMA and LSTM models, respectively. In dynamic scenarios involving network element handovers and signaling attacks, the average increase in RMSE is only 19.5%. Furthermore, the degradation rate for 60 min long-term prediction is only 48.2% of that observed in the LSTM model. The proposed model maintains optimal performance across 6 types of security indicators, verifying its stability and robustness. This research provides technical support for elastic security protection and intelligent operation and maintenance in the Industrial Internet of Intelligence.

     

/

返回文章
返回