Wireless signal secrecy detection method and system based on spectral analysis
By building a spatiotemporal information map through spectrum analysis and hash algorithms, cross-operator collaborative detection of fake base stations solves the problem of insufficient fake base station detection under user privacy protection and achieves efficient and accurate risk wireless signal screening and alarm.
Patent Information
- Application Number
- CN202511084271.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-04
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2045-08-04
AI Technical Summary
Existing technologies make it difficult to effectively detect fake base stations while protecting user privacy, resulting in insufficient detection and inability to timely prevent wireless signal risks.
Through spectrum analysis and hash algorithms, the user terminal's identification information and abnormal event information are processed to build a spatiotemporal information map. The similarity and matching thresholds are matched to screen out risky wireless signals and terminals, realizing cross-operator collaborative detection.
It improves the accuracy and efficiency of fake base station detection, reduces errors, reduces the harmfulness of risky wireless signals, and protects user privacy.
Smart Images

Figure CN120769264A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of data processing technology suitable for management, supervision or prediction purposes, and in particular to a wireless signal confidentiality detection method and system based on spectrum analysis. Background Art
[0002] A wireless signal is an electrical signal transmitted via radio waves or other electromagnetic waves. It refers to the information transmitted in wireless communications and can be in various forms, such as sound, images, and data. Wireless signals can be used in various wireless communication systems, including broadcasting, mobile communications, satellite communications, and wireless local area networks.
[0003] With the development of wireless communication technology and the popularization of wireless communication terminals, wireless signals have become an indispensable communication medium in production and life. While wireless signals provide convenience to people, they can also become a means for criminals to commit illegal acts.
[0004] For example, a fake base station based on wireless signals. A fake base station, also known as a "fake base station," is an illegal radio communications device that exploits a flaw in GSM's one-way authentication. Consisting primarily of a host computer and a laptop computer, it can retrieve GSM mobile phone information within a certain radius and then forcibly send fraudulent, sales-related, and other spam text messages to users using someone else's phone number. These messages are typically sent from cars or secluded locations. When a fake base station is operating, a user's phone signal is forced to connect to the device, preventing them from connecting to the public telecommunications network. This can impact the user's normal use at best, or even cause losses.
[0005] In order to protect mobile phone users, operators will also carry out some detection work on fake base stations. However, due to the poor communication channels between operators and the anti-reconnaissance methods of fake base stations, the detection of fake base stations is inevitably insufficient.
[0006] How to detect risky wireless signals while protecting user privacy has become an urgent problem to be solved. Summary of the Invention
[0007] The embodiments of the present application provide a wireless signal confidentiality detection method and system based on spectrum analysis to at least partially solve the above technical problems.
[0008] The embodiments of this application adopt the following technical solutions: In a first aspect, an embodiment of the present application provides a wireless signal confidentiality detection method based on spectrum analysis, the method comprising: The detection end receives the identification information of the suspected terminal obtained by performing hash algorithm processing on the original information sent by each operation end, as well as the information of the abnormal event of the suspected terminal; For each of the suspected terminals, a spatiotemporal information map is constructed based on the information of its abnormal events; the nodes in the spatiotemporal information map are used to represent the time, geographical location and type of the abnormal event; Matching is performed on the spatiotemporal information graphs of different suspected terminals, and a node with a similarity greater than a preset similarity threshold is selected as the target node; Receive in real time the characteristic information and location information of each suspected wireless signal determined based on spectrum analysis from each operator, and identify those with a matching degree greater than a preset matching degree threshold as risky wireless signals; The identification information of the risk wireless signal and the identification information of the risk terminal are returned to the operation end, so that when the operation end determines that there is a suspected terminal among the suspected terminals that matches the location information of the risk wireless signal and determines that there is the risk terminal, the risk wireless signal is determined as the target wireless signal; the suspected terminal within the range of the target wireless signal is used as the first terminal, and then an alarm information is sent to the first terminal; the risk terminal is the suspected terminal corresponding to the spatiotemporal information graph to which the target node belongs; the similarity threshold is negatively correlated with the maximum number of times it has been determined as the first terminal in history.
[0009] In an optional embodiment of this specification, the method further includes: After determining the risk terminal, the detection end returns the identification information of the risk terminal to the operation end, so that the operation end sends a geographic location tracking permission to the risk terminal to obtain the authority to obtain the geographic location of the risk terminal.
[0010] In an optional embodiment of this specification, the method further includes: Determine a second terminal from the risk terminals; the second terminal is a risk terminal that has been historically determined to be the first terminal a number of times greater than a preset first number threshold; For the suspected terminal that appears for the first time in the update information received from the operation end, its spatiotemporal information map is matched with the spatiotemporal information map information of the second terminal.
[0011] In an optional embodiment of this specification, the method further includes: The identification information of the suspected terminal includes: IMSI and / or mobile phone number.
[0012] In an optional embodiment of this specification, the method further includes: The abnormal event includes: abnormal location update, and / or registration rejection.
[0013] In an optional embodiment of this specification, the method further includes: The characteristic information of the suspected wireless signal includes: an illegal base station identifier, and / or abnormal cell reselection parameters.
[0014] In an optional embodiment of this specification, the method further includes: The matching degree threshold is negatively correlated with the maximum number of times the wireless signal has been determined as a risky wireless signal in history.
[0015] In an optional embodiment of this specification, the method further includes: Based on the data returned by the operation end, the spatiotemporal information graph is updated; After each update, if it is detected that the geographic location information included in the corresponding abnormal event information has not been uniquely detected by a suspected terminal with a number of occurrences greater than a preset second threshold within a specified historical time period from the current moment, the geographic location information is determined as target information; The target information is returned to the operator, so that the operator receives a cell reselection parameter corresponding to the cell of the target information.
[0016] In an optional embodiment of this specification, the method further includes: The cell reselection parameters include a cell reselection bias parameter and / or a cell reselection hysteresis parameter.
[0017] In a second aspect, an embodiment of the present application further provides a wireless signal security detection system based on spectrum analysis, the system comprising a detection terminal: The detection terminal is configured to receive identification information of a suspected terminal obtained by performing hash algorithm processing on original information sent by each operation terminal, as well as information on abnormal events of the suspected terminal; For each of the suspected terminals, a spatiotemporal information map is constructed based on the information of its abnormal events; the nodes in the spatiotemporal information map are used to represent the time, geographical location and type of the abnormal event; Matching is performed on the spatiotemporal information graphs of different suspected terminals, and a node with a similarity greater than a preset similarity threshold is selected as the target node; Receive in real time the characteristic information and location information of each suspected wireless signal determined based on spectrum analysis from each operator, and identify those with a matching degree greater than a preset matching degree threshold as risky wireless signals; The identification information of the risk wireless signal and the identification information of the risk terminal are returned to the operation end, so that when the operation end determines that there is a suspected terminal among the suspected terminals that matches the location information of the risk wireless signal and determines that there is the risk terminal, the risk wireless signal is determined as the target wireless signal; the suspected terminal within the range of the target wireless signal is used as the first terminal, and then an alarm information is sent to the first terminal; the risk terminal is the suspected terminal corresponding to the spatiotemporal information graph to which the target node belongs; the similarity threshold is negatively correlated with the maximum number of times it has been determined as the first terminal in history.
[0018] In a third aspect, an embodiment of the present application further provides an electronic device, including: processor; and A memory arranged to store computer executable instructions which, when executed, cause the processor to perform the method steps of the first aspect.
[0019] In a fourth aspect, an embodiment of the present application further provides a computer-readable storage medium, which stores one or more programs. When the one or more programs are executed by an electronic device including multiple applications, the electronic device executes the method steps described in the first aspect.
[0020] At least one of the above technical solutions adopted in the embodiments of the present application can achieve the following beneficial effects: The method provided by the present application is executed by the detection end, which realizes the detection of illegal wireless signals from pseudo base stations under the premise of protecting the privacy of users. Even in scenarios where different operators cannot coordinate, detection can be effectively achieved. In addition, the method provided by the present application is based on the identification information of the user terminal to determine which users' identification information has been leaked, that is, risk terminals. The risk terminals are the focus of subsequent attack behaviors of pseudo base stations. The detection results of different operators and the performance of risk terminals can be combined to detect risk wireless signals to improve the accuracy of detection. Moreover, during the detection process, the detection end and the operation end collaborate to jointly realize risk monitoring, which is conducive to reducing errors. Afterwards, based on the monitoring results, an alarm is sent to the corresponding user to minimize the harmfulness of the risk results. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] Figure 1 A schematic diagram of a wireless signal security detection method based on spectrum analysis provided in an embodiment of this specification; Figure 2 This is a schematic diagram of the structure of an electronic device in an embodiment of this specification. DETAILED DESCRIPTION
[0022] The present invention will be further described in detail below with reference to the accompanying drawings by way of specific embodiments. Similar elements in different embodiments are numbered with associated similar elements. In the following embodiments, many detailed descriptions are provided to enable the present application to be better understood. However, those skilled in the art will readily appreciate that some of the features may be omitted under different circumstances, or may be replaced by other elements, materials, or methods. In some cases, some operations related to the present application are not shown or described in the specification. This is to avoid overwhelm the core of the present application with excessive descriptions, and for those skilled in the art, it is not necessary to describe these related operations in detail. They will fully understand the related operations based on the description in the specification and the general technical knowledge in the art.
[0023] In addition, the features, operations, or characteristics described in the specification may be combined in any appropriate manner to form various embodiments. Furthermore, the steps or actions in the method description may be reordered or adjusted in a manner readily apparent to those skilled in the art. Therefore, the various sequences in the specification and drawings are provided solely for the purpose of clearly describing a particular embodiment and are not intended to be mandatory, unless otherwise specified.
[0024] The serial numbers assigned to components herein, such as "first," "second," etc., are used solely to distinguish the objects being described and do not convey any sequential or technical meaning. References to "connection" and "coupling" herein, unless otherwise specified, include both direct and indirect connections (couplings).
[0025] The following describes in detail the technical solutions provided by various embodiments of the present application in conjunction with the accompanying drawings.
[0026] like Figure 1 As shown, the wireless signal confidentiality detection method based on spectrum analysis in this specification includes the following steps: S100: The detection end receives identification information of the suspected terminal obtained by performing hash algorithm processing on the original information, and information of abnormal events of the suspected terminal, which are sent by each operation end.
[0027] The technical solution described in this specification aims to accurately locate risky wireless signals through "bidirectional screening" between user terminals (a suspected terminal is a type of user terminal) and wireless signals. This process involves collaboration between the detection and operation terminals, who jointly undertake the detection function. Unless otherwise specified, the method steps described in this specification are explained from the perspective of the detection terminal.
[0028] The method described in this specification is based on a wireless signal security detection system based on spectrum analysis. The system includes a detection terminal and an operator terminal with communication connections. The operator terminal may not be unique. The detection terminal may be a distributed server. The operator terminal can provide communication services to the user's terminal, which is the operator's device performance.
[0029] The original information, which serves as the identifier of the suspected terminal, can be the International Mobile Subscriber Identity (IMSI) or mobile phone number. The International Mobile Subscriber Identity (IMSI) is a unique identifier used to distinguish different users on a cellular network. The mobile phone stores the IMSI in a 64-bit field and sends it to the network. The IMSI can be used to query user information in the Home Location Register (HLR) or Visitor Location Register (VLR).
[0030] Typically, original information is private and cannot be leaked. However, there are situations where this private information is leaked, allowing criminals to exploit it and launch attacks against users. For example, a rogue base station transmits an illegal wireless signal in cell A, which should cover the entire cell. However, only Zhang San receives a fraudulent text message. This is because only Zhang San's original information in cell A has been leaked, creating a risk. Others, whose original information has not been leaked, face a lower risk. Furthermore, the fact that Zhang San's original information has been leaked means that the risk of leakage to different criminals is the same. Even if the same criminal uses private information, it is not a one-time occurrence. In other words, the abnormal event will not occur only once, which provides conditions for tracking illegal wireless information.
[0031] As the operator, we are not authorized to disclose the user's original information to other parties. Therefore, the method described in this manual processes the user's information through a hash algorithm when it is needed. As a result, the detection end cannot obtain the original information, but the identification information with ciphertext characteristics can still be used in subsequent detection steps.
[0032] A hash algorithm is a mathematical function that converts input data of arbitrary length into an output (a hash value or digest) of fixed length. When discussing the natural laws of hash algorithms, we generally refer to the underlying principles and natural processes underlying their design. A hash algorithm is a function that converts an input of arbitrary length (also known as plaintext) into an output of fixed length, often called a hash value or digest. While hash algorithms are not solely based on natural laws, they do draw on certain natural phenomena and fundamental principles, including determinism, one-way hashing, collision resistance, and the avalanche effect. Determinism: The same input always produces the same hash value, ensuring data consistency. One-way hashing: The original input cannot be deduced from the hash value, ensuring data confidentiality. Collision resistance: It is extremely difficult to find two different inputs that produce the same hash value, and longer outputs reduce the likelihood of collisions. Avalanche effect: Slight changes in the input can result in significantly different hash values, enhancing the reliability of data integrity verification.
[0033] In the operator's local area, mapping relationship data between the original information and the identification information of the user terminal can be stored to facilitate subsequent search.
[0034] The information of abnormal events of suspected terminals in this specification includes but is not limited to abnormal location updates and registration rejections. Abnormal location update (TAU / LAC update): Fake base stations usually set tracking area codes (TAC) or location area codes (LAC) that are different from the existing network to induce terminals to frequently initiate location updates. Operators can discover a large number of abnormal location update requests in a short period of time through signaling monitoring systems (such as XDR data). Registration rejection (REGISTRATION REJECT): Fake base stations may frequently send registration rejection messages, and operators can identify such anomalies through NAS signaling parsing. See the technology for details. Other technical means that can be used to detect abnormal events are applicable to this specification when conditions permit. In order to implement subsequent steps, in addition to recording the information of the abnormal event itself, the operator also records the event and geographical location of the abnormal event (for example, the location of the cell) to provide conditions for the subsequent construction of the map.
[0035] The operator's detection of the user terminal's geographic location at this time is based on the detection of abnormal events and is aimed at network optimization (such as de-identification of MDT data). It is not a detection of the user's personal whereabouts, and there is no subjective intention to infringe on personal privacy. In other words, this determination of geographic location is based on positioning in normal standby or call scenarios. The operator has the right to obtain cell-level (hundred meters to kilometers), which is required by the default network and does not require user authorization.
[0036] In an optional embodiment of this specification, the operator can implement Cell ID (CellID) positioning based on the cellular network. The principle is: the mobile phone always communicates with the nearest base station, and the operator can know the cell ID (including LAC / TAC / CI, etc.) to which the user is currently connected. The accuracy is: Urban: 100 meters to 2 kilometers (depending on the base station density). Rural: several kilometers. Real-time updates (recorded every time the cell is switched). The operator can also implement Enhanced Cell ID (E-CID) based on the cellular network. The principle is: combining signal strength (RSSI / RSRP) and time advance (TA) to estimate the distance between the user and the base station. The accuracy is: 50-500 meters (base station support required).
[0037] Since an attack initiated by a fake base station may not only target user terminals provided by a certain operator, but also different user terminals provided by different operators, and it is impossible for operators to implement cross-network detection, the detection end in this step receives the data sent by each operator end, which can realize cross-network and cross-operator information integration without privacy leakage.
[0038] The term "suspected terminal" in this specification refers to a user terminal identified by the operator as potentially posing a privacy risk based on its own detection methods. Technical methods that enable operators to implement this detection are applicable to this specification, as conditions permit. Therefore, having the operator perform the initial screening of user terminals helps save computing power on the detection side in subsequent steps, thereby improving efficiency.
[0039] S102: For each of the suspected terminals, construct a spatiotemporal information map based on the information of its abnormal events.
[0040] In this step, the spatiotemporal information graph corresponds one-to-one with the suspected terminal. The spatiotemporal information graph is scalable and can be expanded based on subsequent data. The spatiotemporal information graph contains several nodes, each representing the time, geographic location, and type of abnormal event (e.g., registration rejection, abnormal location change). This manual does not specify how the nodes should be arranged; for example, they can be arranged in chronological order or by geographic location.
[0041] The spatiotemporal information map constructed for the suspected terminal is stored locally at the detection end and marked with the identification information of the suspected terminal.
[0042] S104: performing matching processing on the spatiotemporal information graphs of different suspected terminals, and taking a node that can be matched and has a similarity greater than a preset similarity threshold as a target node.
[0043] The matching in this step is mainly for the matching between nodes from different spatiotemporal information maps. In the related art, the technical means that can determine the matching degree between nodes based on the information of the nodes are applicable to this specification when conditions permit. If node a in spatiotemporal information map a matches node b in spatiotemporal information map b, it means that both have been interfered with by the same pseudo base station in a similar time period or a similar geographical location. Since the objects successfully interfered with by the pseudo base station are not unique, it shows that the pseudo base station does exist, and it also shows that the suspected terminals corresponding to the two spatiotemporal information maps have indeed had privacy leaks, and compared with other user terminals, there is still a risk of being attacked in the future. Thus, further screening of suspected terminals based on wireless signals is achieved, and user terminals with higher risks are identified. This process is executed by the detection end, which is conducive to the integration of information from different operators and protects the privacy of users.
[0044] In an optional embodiment of the present specification, the similarity threshold can be a preset empirical value determined based on expert experience. In another optional embodiment of the present specification, the similarity threshold is negatively correlated with the maximum number of times a terminal has been historically identified as the first terminal. A first terminal is a user terminal with a higher risk of attack. The step of determining whether a user terminal is a first terminal is performed by the operator (because the operator interacts with the user terminal more promptly, anomalies are discovered more promptly, and the operator's identification of the first terminal is also more timely. Furthermore, the basis for determining the first terminal also includes geographic location information. Performing this step by the operator further reduces the leakage of geographic location information to the detection terminal). Each time the operator identifies a first terminal, it sends its identification information (also hashed) to the detection terminal. This allows the detection terminal to calculate the similarity thresholds of different suspected terminals based on the accumulated number. In other words, the similarity threshold is determined by the detection terminal based on the data sent by the operator, in coordination with the operator and the detection terminal. Subsequent judgments based on the similarity threshold are based on the suspected terminal with the most historical identifications as the first terminal. Since the similarity threshold-based judgment is a pairwise comparison, it is possible that at least two comparisons use different similarity thresholds. This can increase the role played by the performance of user terminals that have been attacked by fake base stations in the past in the detection process, thereby improving accuracy.
[0045] S106: receiving in real time the feature information and location information of each suspected wireless signal determined based on spectrum analysis from each operator, and determining that the signal with a matching degree greater than a preset matching degree threshold is a risky wireless signal.
[0046] The risk wireless signal is a wireless signal with a high probability of being transmitted by a fake base station, and the probability of attack behavior to the user's terminal is high, and further screening is required. In this step, the detection end only receives the information of the wireless signal of the suspected fake base station sent by the operation end, rather than the real-time position information of the user terminal. On the one hand, the number of fake base stations is smaller than the number of user terminals, which is conducive to saving the data processing resources of the detection end; on the other hand, it is also conducive to the protection of the privacy of the user.
[0047] In the related art, the technical means capable of enabling the operation end to monitor the wireless signal of the suspected fake base station based on spectrum analysis are all applicable to the present specification under the condition of allowing.
[0048] In an optional embodiment of the present specification, the operation end can detect the suspected wireless signal through the following detection dimensions of spectrum analysis: 1. Abnormal frequency point and bandwidth: illegal frequency band occupation. The fake base station may use an unauthorized frequency band (such as privately occupying an unallocated frequency point of GSM 900MHz or LTE 1800MHz), and the operator monitors the frequency band occupation in real time through a spectrum scanner or an SDR device. Detection tool: frequency sweeper (such as R&S TSMA), software-defined radio (USRP+HackRF); non-standard bandwidth configuration. The signal bandwidth of the fake base station may not comply with the standard (such as an LTE fake base station using a non-standard 1.4MHz bandwidth instead of 20MHz).
[0049] 2. Abnormal signal strength (RSRP / RSSI): super high power transmission. The fake base station often attracts terminal access by increasing the transmission power (such as the LTE signal strength reaching-50dBm, far exceeding-80dBm of the surrounding legal base station). Detection method: find the area with abnormally high signal through MDT (minimization of drive test) data or the RSRP value reported by the user equipment. Fixed spectrum sensor network monitors power mutation, etc.
[0050] 3. Modulation quality defect: EVM (error vector magnitude) exceeds the standard. The fake base station has poor modulation quality due to its simple hardware (such as LTE EVM>8%, while the legal base station<3%), which can be detected by a vector signal analyzer (such as Keysight VSA); abnormal phase noise. The phase noise spectrum of the local oscillator of the fake base station may have additional harmonics (such as noise lifting at 1kHz offset).
[0051] 4. Abnormal timing characteristics: frame timing jitter. The fake base station lacks high-precision clock synchronization (such as no GPS / Beidou timing), resulting in subframe start time jitter (above ±5μs, legal base station within ±1μs); non-standard signal period: the fake base station may periodically broadcast system information (such as every 30 seconds), while the legal base station transmits continuously.
[0052] In addition, in other optional embodiments of the present specification, detection may be performed based on spectrum analysis combined with protocol decoding, or detection may be performed by comparing with a dynamic spectrum fingerprint library, which will not be described in detail here.
[0053] In one optional embodiment of this specification, the matching threshold is an empirical value based on expert experience. In another optional embodiment of this specification, the matching threshold is negatively correlated with the maximum number of times a signal has historically been identified as a risky wireless signal. Similar to the aforementioned similarity threshold determination process, this embodiment also determines the matching threshold based on interaction between the detection end and the operation end, and is not further described here.
[0054] In a further optional embodiment of this specification, when a suspected wireless signal is not detected for the first time, the matching threshold is negatively correlated with the maximum number of times it has been historically identified as a risky wireless signal. If one of these signals is detected for the first time, a fixed, preset matching threshold is used. This fixed matching threshold is typically set to a larger value than the matching threshold determined based on the number of detections to reduce noise.
[0055] The characteristic information and location information of the suspected wireless signal are both detected by the operator. The characteristic information of the suspected wireless signal has the attribute of identifying the wireless signal. In an optional embodiment of this specification, the characteristic information of the suspected wireless signal may include but is not limited to: wireless parameters (physical layer), such as signal strength (RSRP / RSSI), carrier frequency deviation (CFO), modulation quality (EVM), bandwidth; protocol parameters (signaling layer), such as system information (SIB), cell selection parameters, registration rejection rate; spatiotemporal behavior characteristics, such as location fixity, working hours, and user influence range. Parameters for identifying suspected wireless signals may include: hardware fingerprints (unforgeable features), such as carrier frequency deviation (CFO), phase noise spectrum, and signal burst period; protocol fingerprints, such as PCI+frequency combination, TAC / LAC conflict, and signaling sequence vulnerability; spatiotemporal fingerprints, such as movement trajectory and activation time period.
[0056] In addition, certain characteristic information can also identify wireless signals and can be used as wireless signal identification information. For example, characteristic information of suspected wireless signals includes at least one of the following: an illegal base station identifier (PCL / CID / LAC) and abnormal cell reselection parameters (such as cell reselection parameter C2 and cell reselection offset CR0).
[0057] S108: Return the identification information of the risky wireless signal and the identification information of the risky terminal to the operation end.
[0058] In this step, the detection end sends two types of information to the operation end: identification information of the risky wireless signal and identification information of the risky terminal. However, in actual application scenarios, the two may not be sent at the same time, and the timing of sending can be adjusted according to business needs. For example, after the risky terminal is determined, the identification information of the risky terminal can be immediately returned to the operation end from which it originated (instead of sending it to every operation end, that is, the communication service provided by the operation end is returned to the operation end). The identification information of the risky wireless signal is also returned to the operation end after its risk is detected, and it is returned to each operation end.
[0059] After the operation end receives the information sent by the detection end, the operation end determines that there is a suspected terminal that matches the location information of the risk wireless signal (indicating that the attack behavior of the risk wireless signal covers the suspected terminal and there is indeed a risk. This is a match of real-time data, that is, real-time location). When it is determined that there is a risk terminal (indicating that the attack behavior is likely to lead to negative consequences), the risk wireless signal is determined as the target wireless signal; the suspected terminal within the range of the target wireless signal is used as the first terminal, and then an alarm information is sent to the first terminal to enable the suspected user terminal to avoid risks; the risk terminal is the suspected terminal corresponding to the spatiotemporal information map to which the target node belongs.
[0060] In the "location matching" operation of this step, the operator needs to know the user's geographic location. In an optional embodiment of this specification, the operator can obtain the user's cell-level geographic location based on the default protocol. Optionally, the operator sends a geographic location tracking permission to the risk terminal to obtain the authority to obtain the geographic location of the risk terminal, so as to obtain a more accurate geographic location of the user, so as to lock the fake base station. In other words, the strategies for suspected terminals and risk terminals are different. Risk terminals are more likely to be attacked, and the attack behavior against them can also more accurately locate the fake base station.
[0061] The method provided by the present application is executed by the detection end, which realizes the detection of illegal wireless signals from pseudo base stations under the premise of protecting the privacy of users. Even in scenarios where different operators cannot coordinate, detection can be effectively achieved. In addition, the method provided by the present application is based on the identification information of the user terminal to determine which users' identification information has been leaked, that is, risk terminals. The risk terminals are the focus of subsequent attack behaviors of pseudo base stations. The detection results of different operators and the performance of risk terminals can be combined to detect risk wireless signals to improve the accuracy of detection. Moreover, during the detection process, the detection end and the operation end collaborate to jointly realize risk monitoring, which is conducive to reducing errors. Afterwards, based on the monitoring results, an alarm is sent to the corresponding user to minimize the harmfulness of the risk results.
[0062] In an optional embodiment of the present specification, in order to improve the efficiency and accuracy of detection, the detection end determines a second terminal from the risk terminal; the second terminal is a risk terminal that has been historically determined to be a first terminal more than a preset first number threshold (the operation end can send a corresponding message to the detection end each time a suspected terminal is determined to be a first terminal, so that the detection end can accumulate the count. The first number threshold can be an empirical value). The first appearing in the suspected terminal update information received from the operation end (the operation end can choose the time to update the suspected terminal list based on its own management logic and synchronize it to the detection end) is matched with the spatiotemporal information map of the second terminal. Since the second terminal is historically determined to have a higher probability of being attacked, this matching is conducive to improving efficiency and accuracy.
[0063] Afterward, the operator will continue to perform corresponding detections on base stations and user terminals. The detection end updates the spatiotemporal information map based on the data returned by the operator. After each update, if the geographic location information contained in the corresponding abnormal event information is detected, and within a specified historical time period from the current moment (this time period can be an empirical value; due to the highly targeted nature of fixed pseudo base stations, it can be negatively correlated with the updated number of abnormal events in the cell to identify whether a pseudo base station attack is truly occurring), and there is no unique suspected terminal, then this geographic location information is determined as target information (indicating a high likelihood of the presence of a fixed pseudo base station in the cell). This target information is then returned to the operator, causing the operator to adjust the cell reselection parameters (such as the cell reselection offset parameter (CRO) and the cell reselection hysteresis parameter (CRH)) for the cell corresponding to the target information.
[0064] Furthermore, this specification also provides a wireless signal security detection system based on spectrum analysis, the system comprising a detection terminal: The detection terminal is configured to receive identification information of a suspected terminal obtained by performing hash algorithm processing on original information sent by each operation terminal, as well as information on abnormal events of the suspected terminal; For each of the suspected terminals, a spatiotemporal information map is constructed based on the information of its abnormal events; the nodes in the spatiotemporal information map are used to represent the time, geographical location and type of the abnormal event; Matching is performed on the spatiotemporal information graphs of different suspected terminals, and a node with a similarity greater than a preset similarity threshold is selected as the target node; Receive in real time the characteristic information and location information of each suspected wireless signal determined based on spectrum analysis from each operator, and identify those with a matching degree greater than a preset matching degree threshold as risky wireless signals; The identification information of the risk wireless signal and the identification information of the risk terminal are returned to the operation end, so that when the operation end determines that there is a suspected terminal among the suspected terminals that matches the location information of the risk wireless signal and determines that there is the risk terminal, the risk wireless signal is determined as the target wireless signal; the suspected terminal within the range of the target wireless signal is used as the first terminal, and then an alarm information is sent to the first terminal; the risk terminal is the suspected terminal corresponding to the spatiotemporal information graph to which the target node belongs; the similarity threshold is negatively correlated with the maximum number of times it has been determined as the first terminal in history.
[0065] The system can execute the method in any of the aforementioned embodiments and can achieve the same or similar technical effects, which will not be described in detail here.
[0066] Figure 2 This is a schematic diagram of the structure of an electronic device according to an embodiment of the present application. Figure 2 At the hardware level, the electronic device includes a processor and, optionally, an internal bus, a network interface, and memory. The memory may include internal memory, such as high-speed random-access memory (RAM), or non-volatile memory, such as at least one disk drive. Of course, the electronic device may also include other hardware required for its services.
[0067] The processor, network interface, and memory can be interconnected via an internal bus, which can be an ISA (Industry Standard Architecture) bus, a PCI (Peripheral Component Interconnect) bus, or an EISA (Extended Industry Standard Architecture) bus. The bus can be divided into an address bus, a data bus, a control bus, and the like. For ease of representation, Figure 2 Only one bidirectional arrow is used in the diagram, but this does not mean that there is only one bus or one type of bus.
[0068] The memory is used to store programs. Specifically, the program may include program code, which includes computer operating instructions. The memory may include internal memory and non-volatile memory, and provides instructions and data to the processor.
[0069] The processor reads the corresponding computer program from the non-volatile memory into the internal memory and then runs it, logically forming a wireless signal security detection system based on spectrum analysis. The processor executes the program stored in the memory and is specifically configured to perform any of the aforementioned wireless signal security detection methods based on spectrum analysis.
[0070] The above application Figure 1The wireless signal privacy detection method based on spectrum analysis disclosed by the embodiment can be applied to a processor or implemented by the processor. The processor can be an integrated circuit chip with signal processing capability. In the implementation, the steps of the method can be completed by integrated logic circuits of hardware in the processor or instructions in the form of software. The processor can be a general processor, including a central processing unit (CPU), a network processor (NP), etc. It can also be a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components. The disclosed methods, steps and logic block diagrams in the embodiments of the present application can be implemented or executed. The general processor can be a microprocessor or any conventional processor. The steps of the method disclosed in combination with the embodiments of the present application can be directly embodied as a hardware decoding processor for execution, or a combination of hardware and software modules in the decoding processor for execution. The software module can be located in a random access memory, a flash memory, a read-only memory, a programmable read-only memory, an electrically erasable programmable memory, a register or other mature storage medium in the art. The storage medium is located in the memory, and the processor reads the information in the memory and combines the hardware to complete the steps of the method.
[0071] The electronic device can also execute Figure 1 a wireless signal privacy detection method based on spectrum analysis, and implement Figure 1 the functions of the embodiment, which will not be described here.
[0072] The embodiment of the present application also proposes a computer readable storage medium, which stores one or more programs including instructions, which when executed by an electronic device including a plurality of application programs, execute any of the foregoing wireless signal privacy detection methods based on spectrum analysis.
[0073] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware. Furthermore, the present application may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0074] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 a process or multiple processes and / or boxes Figure 1 A system that specifies the functions of a box or boxes.
[0075] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture including an instruction system that is implemented in the process. Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0076] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.
[0077] In a typical configuration, a computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory.
[0078] Memory may include non-permanent storage in a computer-readable medium, in the form of random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of a computer-readable medium.
[0079] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can be implemented using any method or technology to store information. Information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase-change RAM (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory computer-readable media such as modulated data signals and carrier waves.
[0080] It should also be noted that the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, commodity, or apparatus that includes a series of elements includes not only those elements but also other elements not explicitly listed, or includes elements inherent to such process, method, commodity, or apparatus. In the absence of further limitations, an element defined by the phrase "comprises a ..." does not exclude the presence of other identical elements in the process, method, commodity, or apparatus that includes the element.
[0081] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware. Furthermore, the present application may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0082] The foregoing is merely an embodiment of the present application and is not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application should all be included within the scope of the claims of the present application.
Claims
1. A wireless signal confidentiality detection method based on spectrum analysis, characterized in that: The method comprises: The detection end receives the identification information of the suspected terminal obtained by performing hash algorithm processing on the original information sent by each operation end, as well as the information of the abnormal event of the suspected terminal; For each of the suspected terminals, a spatiotemporal information map is constructed based on the information of its abnormal events; the nodes in the spatiotemporal information map are used to represent the time, geographical location and type of the abnormal event; Matching is performed on the spatiotemporal information graphs of different suspected terminals, and a node with a similarity greater than a preset similarity threshold is selected as the target node; Receive in real time the characteristic information and location information of each suspected wireless signal determined based on spectrum analysis from each operator, and identify those with a matching degree greater than a preset matching degree threshold as risky wireless signals; The identification information of the risk wireless signal and the identification information of the risk terminal are returned to the operation end, so that when the operation end determines that there is a suspected terminal among the suspected terminals that matches the location information of the risk wireless signal and determines that there is the risk terminal, the risk wireless signal is determined as the target wireless signal; the suspected terminal within the range of the target wireless signal is used as the first terminal, and then an alarm information is sent to the first terminal; the risk terminal is the suspected terminal corresponding to the spatiotemporal information graph to which the target node belongs; the similarity threshold is negatively correlated with the maximum number of times it has been determined as the first terminal in history.
2. The method according to claim 1, wherein: The method further comprises: After determining the risk terminal, the detection end returns the identification information of the risk terminal to the operation end, so that the operation end sends a geographic location tracking permission to the risk terminal to obtain the authority to obtain the geographic location of the risk terminal.
3. The method according to claim 1, wherein: The method further comprises: Determine a second terminal from the risk terminals; the second terminal is a risk terminal that has been historically determined to be the first terminal a number of times greater than a preset first number threshold; For the suspected terminal that appears for the first time in the update information received from the operation end, its spatiotemporal information map is matched with the spatiotemporal information map information of the second terminal.
4. The method according to claim 1, wherein: The method further comprises: The identification information of the suspected terminal includes: IMSI and / or mobile phone number.
5. The method according to claim 1, wherein: The method further comprises: The abnormal event includes: abnormal location update, and / or registration rejection.
6. The method according to claim 1, wherein: The method further comprises: The characteristic information of the suspected wireless signal includes: an illegal base station identifier, and / or abnormal cell reselection parameters.
7. The method according to claim 1, wherein: The method further comprises: The matching degree threshold is negatively correlated with the maximum number of times the wireless signal has been determined as a risky wireless signal in history.
8. The method according to claim 1, wherein: The method further comprises: Based on the data returned by the operation end, the spatiotemporal information graph is updated; After each update, if it is detected that the geographic location information included in the corresponding abnormal event information has not been uniquely detected by a suspected terminal with a number of occurrences greater than a preset second threshold within a specified historical time period from the current moment, the geographic location information is determined as target information; The target information is returned to the operator, so that the operator receives a cell reselection parameter corresponding to the cell of the target information.
9. The method according to claim 8, wherein: The method further comprises: The cell reselection parameters include a cell reselection bias parameter and / or a cell reselection hysteresis parameter.
10. A wireless signal security detection system based on spectrum analysis, characterized in that: The system includes a detection end: The detection terminal is configured to receive identification information of a suspected terminal obtained by performing hash algorithm processing on original information sent by each operation terminal, as well as information on abnormal events of the suspected terminal; For each of the suspected terminals, a spatiotemporal information map is constructed based on the information of its abnormal events; the nodes in the spatiotemporal information map are used to represent the time, geographical location and type of the abnormal event; Matching is performed on the spatiotemporal information graphs of different suspected terminals, and a node with a similarity greater than a preset similarity threshold is selected as the target node; Receive in real time the characteristic information and location information of each suspected wireless signal determined based on spectrum analysis from each operator, and identify those with a matching degree greater than a preset matching degree threshold as risky wireless signals; The identification information of the risk wireless signal and the identification information of the risk terminal are returned to the operation end, so that when the operation end determines that there is a suspected terminal among the suspected terminals that matches the location information of the risk wireless signal and determines that there is the risk terminal, the risk wireless signal is determined as the target wireless signal; the suspected terminal within the range of the target wireless signal is used as the first terminal, and then an alarm information is sent to the first terminal; the risk terminal is the suspected terminal corresponding to the spatiotemporal information graph to which the target node belongs; the similarity threshold is negatively correlated with the maximum number of times it has been determined as the first terminal in history.
Citation Information
Patent Citations
Method for detecting pseudo base station, terminal, data processor and system
CN105516986A
Pseudo base station detection method and device, terminal and computer readable storage medium
CN107911822A
Risk prediction method based on multi-modal data fusion
CN117708746A
Method for Identifying Pseudo Base Station, Apparatus, and Mobile Terminal
US20210250770A1