Concealed threat sensing method and system based on side channel signal

By using a covert threat perception system based on side-channel signals, combined with network prediction models and time-frequency feature analysis, the problem of difficult-to-detect covert attacks in modern communication systems has been solved, achieving comprehensive security for communication systems.

CN121333831AActive Publication Date: 2026-01-13CHENGDU CHUANGXIN HUATONG INFORMATION TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202511902101.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-17
Publication Date
2026-01-13
Estimated Expiration
2045-12-17

Smart Images

  • Figure CN121333831A_ABST
    Figure CN121333831A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of communication, and discloses a hidden threat sensing method and system based on a side channel signal, and the system comprises an acquisition processing module which determines a signal fluctuation amplitude based on a network prediction signal model and a first side channel signal, the communication environment is judged according to the relation between the signal fluctuation amplitude and the second side channel signal, the time delay analysis module determines the data transmission time delay of the second side channel signal based on the communication time sequence information, and determines a time delay index value according to the standard data transmission time delay and the data transmission time delay; the time domain analysis module determines a frequency domain parameter of the second side channel signal based on the frequency domain amplitude spectrum and carries out fusion processing on the time domain parameter and the frequency domain parameter, and the threat sensing module compares the multi-dimensional feature vector with a historical time frequency library and judges whether to send out a threat early warning alarm based on a threat index value and a time delay index value. According to the method, the data transmission time delay and the time frequency characteristics are determined, so that the hidden threat sensing reliability of the communication system is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of communication technology, and more specifically, to a method and system for detecting covert threats based on side-channel signals. Background Technology

[0002] During the operation of modern communication systems, various forms of side-channel signals are generated, including electromagnetic radiation signals, acoustic signals, and clock jitter signals. Side-channel signals are typically related to communication behavior and the external electromagnetic environment. With the expansion of communication networks and the increasing sophistication of attack methods, more and more attacks utilize side-channel characteristics to carry out data theft, communication interference, link manipulation, or spoofing. These types of attacks typically do not directly alter the communication content, making them difficult to detect in a timely manner using traditional security detection methods based on the protocol layer, traffic layer, or content layer. Furthermore, these covert attacks are accompanied by anomalies in communication link timing, such as changes in packet transmission delay, transmission cycle offsets, or the spread of timing jitter. Existing threat detection methods only perform delay analysis at the protocol layer, making it difficult to jointly judge delay changes with the physical characteristics of side-channel signals, thus failing to perceive the impact of attacks on the communication state.

[0003] Therefore, it is necessary to design a covert threat perception method and system based on side-channel signals to solve the problems existing in the current technology. Summary of the Invention

[0004] In view of this, the present invention proposes a covert threat perception method and system based on side channel signals, aiming to solve the problems that communication networks cannot detect attack threats in a timely manner, and that it is difficult to jointly judge the time delay changes and side channel physical signal characteristics, and thus cannot perceive the impact of attack behavior on the communication status.

[0005] In one aspect, the present invention proposes a covert threat perception system based on side-channel signals, comprising: The acquisition and processing module is configured to acquire the first side channel signal at the previous moment and the second side channel signal at the current moment, determine the signal fluctuation amplitude based on the network prediction signal model and the first side channel signal, and determine the communication environment based on the relationship between the signal fluctuation amplitude and the second side channel signal. The delay analysis module is configured to determine the communication timing information of the second-side channel signal when the communication environment is unqualified, determine the data transmission delay of the second-side channel signal based on the communication timing information, and determine the delay index value according to the standard data transmission delay and the data transmission delay. The time-domain analysis module is configured to extract the time-domain parameters of the second-side channel signal, perform spectral transformation on the second-side channel signal to determine the frequency domain amplitude spectrum, determine the frequency domain parameters of the second-side channel signal based on the frequency domain amplitude spectrum, and fuse the time-domain parameters and frequency domain parameters to determine the multi-dimensional feature vector. The threat perception module is configured to compare multidimensional feature vectors with a historical time-frequency database, determine the number of times the multidimensional feature vectors appear in the historical time-frequency database based on the comparison results, or derive a threat index value based on the relationship between the multidimensional feature vectors and historical multidimensional feature vectors, and determine whether to issue a threat warning alarm based on the threat index value and the latency index value.

[0006] Furthermore, when determining the signal fluctuation amplitude based on the network-predicted signal model and the first side-channel signal, the following steps are included: The acquisition and processing module obtains the set of operating parameters and divides the set of operating parameters into a model training set and a model test set. The random forest model is built by finding the construction parameters of the model based on grid search, trained on the model training set, and the accuracy is determined by substituting the model test set into the trained random forest model. When the accuracy is greater than or equal to the accuracy threshold, the trained random forest model is determined as the network prediction signal model. When the accuracy is less than the accuracy threshold, the random forest model is rebuilt and trained by expanding the search range of the construction parameters through grid search. The signal from the first side channel is substituted into the network prediction signal model to determine the signal fluctuation amplitude.

[0007] Furthermore, when determining the communication environment based on the relationship between signal fluctuation amplitude and the second-side channel signal, the following is included: When the signal fluctuation of the second-side channel signal is greater than or equal to the signal fluctuation amplitude, the acquisition and processing module determines that the communication environment is unqualified. When the signal fluctuation of the second-side channel signal is less than the signal fluctuation amplitude, the acquisition and processing module determines that the communication environment is qualified.

[0008] Furthermore, when determining the communication timing information of the second-side channel signal, determining the data transmission delay of the second-side channel signal based on the communication timing information, and determining the delay index value according to the standard data transmission delay and the data transmission delay, the process includes: The delay analysis module calls the communication log corresponding to the second-side channel signal, extracts the data transmission delay from the communication log, obtains the standard data transmission delay corresponding to the data transmission delay, and determines the difference between the data transmission delay and the corresponding standard data transmission delay as the delay index value.

[0009] Furthermore, when extracting the time-domain parameters of the second-side channel signal, performing spectral transformation on the second-side channel signal to determine the frequency-domain amplitude spectrum, determining the frequency-domain parameters of the second-side channel signal based on the frequency-domain amplitude spectrum, and fusing the time-domain and frequency-domain parameters to determine the multi-dimensional feature vector, the process includes: Time-domain parameters include time-domain statistical characteristics and time-domain instantaneous characteristics; The time-domain statistical characteristics include the peak value, mean value, and peak-to-average power ratio of the second-side channel signal, while the time-domain instantaneous characteristics include the rising edge slope and pulse width of the second-side channel signal. The time-domain analysis module performs a fast Fourier transform on the second-side channel signal to determine the frequency domain amplitude spectrum, extracts the frequency domain statistical features of the frequency domain amplitude spectrum, and determines the frequency domain statistical features as the frequency domain parameters of the second-side channel signal. The frequency domain statistical features include peak frequency and spectral flatness. The time-domain parameters and frequency-domain parameters are fused to determine the time-frequency feature vector, and the time-frequency feature vector is reduced in dimensionality based on the principal component analysis algorithm to determine the multidimensional feature vector.

[0010] Furthermore, when comparing multidimensional feature vectors with historical time-frequency databases to determine the frequency of occurrence of multidimensional feature vectors in the historical time-frequency database based on the comparison results, or deriving threat index values ​​based on the relationship between multidimensional feature vectors and historical multidimensional feature vectors, this includes: The historical time-frequency database includes several historical multidimensional feature vectors; When a historical multidimensional feature vector with the same appearance as the multidimensional feature vector exists in the historical time-frequency database, the threat perception module determines the threat index value based on the number of times the multidimensional feature vector appears in the historical time-frequency database. When there is no historical multidimensional feature vector in the historical time-frequency database that is the same as the multidimensional feature vector, the threat perception module determines the threat index value based on the relationship between the multidimensional feature vector and the historical multidimensional feature vector.

[0011] Furthermore, when a historical multidimensional feature vector identical to the multidimensional feature vector exists in the historical time-frequency database, the threat perception module determines the threat index value based on the frequency of occurrence of the multidimensional feature vector in the historical time-frequency database, including: The threat perception module determines the number of times a historical multidimensional feature vector, which is identical to the multidimensional feature vector, has appeared in history, and records the number of appearances as the threat index value.

[0012] Furthermore, when no historical multidimensional feature vector exists in the historical time-frequency database that matches the multidimensional feature vector, the threat perception module determines the threat index value based on the relationship between the multidimensional feature vector and the historical multidimensional feature vector, including: The threat perception module extracts historical multidimensional feature vectors from the historical time-frequency database, and generates several candidate item sets based on the extracted historical multidimensional feature vectors and the multidimensional feature vectors using the Eclat algorithm. The number of candidate item sets is positively correlated with the extracted historical multidimensional feature vectors. Frequent itemsets are determined based on the support of the candidate item sets, and the association results between the multidimensional feature vectors and the extracted historical multidimensional feature vectors are determined based on the frequent itemsets. The number of associations in the association results is counted, and the number of associations is recorded as the threat index value.

[0013] Furthermore, when determining whether to issue a threat warning alert based on threat indicator values ​​and latency indicator values, the following factors are considered: The threat perception module performs a weighted calculation of threat indicator values ​​and latency indicator values ​​to determine the threat alert value; When the threat alert value is greater than or equal to the threat alert threshold, a threat warning alert is issued. If the threat alert value is less than the threat alert threshold, it is determined that no threat warning alert will be issued.

[0014] Compared with existing technologies, the beneficial effects of this invention are as follows: The acquisition and processing module obtains the first and second side-channel signals, combines them with a network prediction signal model to determine the signal fluctuation amplitude, and judges the communication environment, thus achieving screening of the communication environment dimension and improving the overall perception efficiency of the system. The delay analysis module analyzes communication timing information to determine data transmission delay when the communication environment is unqualified, avoiding the limitations of delay analysis only at the protocol layer, and providing delay data support for threat judgment. The time domain analysis module integrates time domain parameters and frequency domain parameters to form a multi-dimensional feature vector, which more comprehensively characterizes the characteristics of the side-channel signal compared to single-parameter analysis, thereby uncovering deep-seated abnormal features of the signal, avoiding threat omissions due to missing features, and improving the stability and reliability of the communication system. The threat perception module determines the threat index value through the multi-dimensional feature vector and combines it with the delay index value to determine whether to issue a threat warning alarm, realizing a comprehensive threat assessment with multiple dimensions and multiple indicators, thereby improving the accuracy of hidden threat perception, providing comprehensive security for the communication system, and reducing the risks of data theft and communication interference caused by covert attacks.

[0015] On the other hand, this application also provides a covert threat perception method based on side-channel signals, which, when applied to the aforementioned covert threat perception system based on side-channel signals, includes: The system acquires the first side channel signal from the previous moment and the second side channel signal from the current moment, determines the signal fluctuation amplitude based on the network prediction signal model and the first side channel signal, and judges the communication environment based on the relationship between the signal fluctuation amplitude and the second side channel signal. When the communication environment is unqualified, determine the communication timing information of the second-side channel signal, determine the data transmission delay of the second-side channel signal based on the communication timing information, and determine the delay index value according to the standard data transmission delay and the data transmission delay. The time-domain parameters of the second-side channel signal are extracted, and the second-side channel signal is subjected to spectrum transformation to determine the frequency domain amplitude spectrum. Based on the frequency domain amplitude spectrum, the frequency domain parameters of the second-side channel signal are determined. The time-domain parameters and frequency domain parameters are fused to determine the multi-dimensional feature vector. The multidimensional feature vector is compared with the historical time-frequency database. The number of times the multidimensional feature vector appears in the historical time-frequency database is determined based on the comparison results. Alternatively, the threat index value is derived based on the relationship between the multidimensional feature vector and the historical multidimensional feature vector. The threat index value and the latency index value are used to determine whether to issue a threat warning alarm.

[0016] It is understandable that the aforementioned method and system for detecting covert threats based on side-channel signals have the same beneficial effects, and will not be elaborated further here. Attached Figure Description

[0017] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0018] Figure 1 A functional block diagram of a covert threat perception system based on side-channel signals provided in an embodiment of the present invention; Figure 2 A flowchart illustrating a covert threat perception method based on side-channel signals, provided in an embodiment of the present invention. Detailed Implementation

[0019] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0020] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments.

[0021] See Figure 1 As shown in some embodiments of this application, a covert threat perception system based on side-channel signals includes: The acquisition and processing module is configured to acquire the first side channel signal at the previous moment and the second side channel signal at the current moment, determine the signal fluctuation amplitude based on the network prediction signal model and the first side channel signal, and determine the communication environment based on the relationship between the signal fluctuation amplitude and the second side channel signal.

[0022] The delay analysis module is configured to determine the communication timing information of the second-side channel signal when the communication environment is unqualified, determine the data transmission delay of the second-side channel signal based on the communication timing information, and determine the delay index value according to the standard data transmission delay and the data transmission delay.

[0023] The time-domain analysis module is configured to extract the time-domain parameters of the second-side channel signal, perform spectral transformation on the second-side channel signal to determine the frequency domain amplitude spectrum, determine the frequency domain parameters of the second-side channel signal based on the frequency domain amplitude spectrum, and fuse the time-domain parameters and frequency domain parameters to determine the multi-dimensional feature vector.

[0024] The threat perception module is configured to compare multidimensional feature vectors with a historical time-frequency database, determine the number of times the multidimensional feature vectors appear in the historical time-frequency database based on the comparison results, or derive a threat index value based on the relationship between the multidimensional feature vectors and historical multidimensional feature vectors, and determine whether to issue a threat warning alarm based on the threat index value and the latency index value.

[0025] Specifically, side-channel signals are inactive transmission signals generated during the operation of a communication system, such as electromagnetic radiation signals, acoustic signals, and clock jitter signals. The acquisition and processing module synchronously acquires the first side-channel signal from the previous moment and the second side-channel signal from the current moment at a fixed time interval. It also records metadata such as the acquisition timestamps and communication scenario tags corresponding to both sets of signals. The network predictive signal model is a model pre-trained on the corresponding side-channel signals and time sequences under various normal communication scenarios. It can output the fluctuation amplitude of the signal at the current moment based on the characteristic patterns of the signal from the previous moment. The signal fluctuation amplitude is the side-channel signal amplitude under normal communication conditions. The amplitude variation range of the channel signal caused by factors such as equipment load changes and slight environmental interference is determined by the acquisition and processing module based on the first side channel signal and the network prediction signal model. After determining the signal fluctuation amplitude, the module compares it with the second side channel signal to determine the current communication environment. This avoids over-analysis of normal signals, thereby improving the overall efficiency of the system's perception. When the communication environment is unqualified, the delay analysis module focuses on digging out communication timing anomalies behind the side channel signal, which are potential attack threats. Communication timing information is the time dimension data (data packet sending / receiving timestamps) corresponding to the communication operation during the acquisition of the second side channel signal. Since covert threats are accompanied by communication link timing anomalies (such as changes in data packet transmission delay and transmission cycle offset), after determining the specific communication behavior corresponding to the second side channel signal, the delay analysis module extracts the data transmission delay based on the characteristic that the side channel signal changes synchronously with the communication operation. That is, the time difference between the data packet being sent from the sender and the receiver confirming receipt. The standard data transmission delay is a delay baseline constructed based on the normal communication and data packet transmission process of the communication system, which can reflect the normal delay in this communication scenario. The delay analysis module determines the delay index value by calculating the degree of deviation between the current data transmission delay and the standard data transmission delay. The larger the delay index value, the more obvious the timing anomaly. This breaks through the limitation of traditional threat perception, which only performs delay analysis at the protocol layer. At the same time, it correlates the delay anomaly with the side channel signal, capturing the physical layer timing changes caused by covert threats.

[0026] Understandably, the time-domain analysis module first extracts time-domain parameters from second-side channel signals with substandard communication environments. These parameters, such as peak signal value and mean signal value, reflect the overall variation of signal amplitude. Subsequently, a spectrum transformation is performed on the second-side channel signal to obtain the frequency-domain amplitude spectrum. The frequency-domain amplitude spectrum is a distribution curve of signal amplitude as a function of frequency, showcasing the energy distribution characteristics of the signal at different frequency components. Based on the frequency-domain amplitude spectrum, frequency-domain parameters, including the peak frequency, are extracted. These parameters can capture anomalies in specific frequency components caused by potential threats. The time-domain analysis module then fuses the extracted time-domain and frequency-domain parameters to form a multi-dimensional feature vector. This multi-dimensional feature vector integrates the time-frequency characteristics of the second-side channel signal, thus comprehensively characterizing the signal's attributes. Single-dimensional features are insufficient to fully depict the risk of a threat; through time-frequency feature fusion, feature support is provided for accurate threat assessment. The historical time-frequency database is a pre-built feature database of the system. It stores a large number of multi-dimensional feature vectors representing potential threats in various communication scenarios. This database is accumulated through the following methods: simulating typical side-channel attacks (such as data theft and communication interference) in a laboratory environment; collecting side-channel signals during the attack process and extracting time-frequency features to form multi-dimensional feature vectors; and importing side-channel feature samples from publicly available industry attack cases. The threat perception module compares the multi-dimensional feature vectors with the historical time-frequency database and determines the threat index value using two methods based on the comparison results. One method is to count the number of times the multi-dimensional feature vector appears in the historical time-frequency database; the other is to determine the threat index value by utilizing the relationship between the multi-dimensional feature vector and historical multi-dimensional feature vectors. For example, a certain type of data theft attack will simultaneously increase the time-domain variance of the side-channel signal and increase the proportion of specific peak values ​​in the frequency domain. This combination is not random but a necessary impact of the attack on the communication physical layer. By mining the derived correlations between the multi-dimensional feature vector and historical multi-dimensional feature vectors, the threat level of the multi-dimensional feature vector to communication is quantified, thereby determining the threat index value. The threat perception module determines whether to issue a threat warning based on both threat index value and latency index value. It realizes the joint judgment of side channel time-frequency physical characteristics and communication timing anomalies, thereby capturing hidden threats in the communication process and ensuring the security of the communication system.

[0027] In some embodiments of this application, when determining the signal fluctuation amplitude based on the network prediction signal model and the first side channel signal, the process includes: the acquisition and processing module acquiring a set of operating parameters and dividing the set of operating parameters into a model training set and a model test set; establishing a random forest model by searching for the model's construction parameters using a grid search; training the random forest model based on the model training set; and substituting the model test set into the trained random forest model to determine the accuracy. When the accuracy is greater than or equal to an accuracy threshold, the trained random forest model is determined as the network prediction signal model. When the accuracy is less than the accuracy threshold, the random forest model is re-established and trained by expanding the search range of the construction parameters through a grid search; and the first side channel signal is substituting into the network prediction signal model to determine the signal fluctuation amplitude.

[0028] Specifically, the operational parameter set includes data such as the operating load of communication equipment under normal communication scenarios (e.g., the number of simultaneous communication connections, data transmission rate), communication protocol type (e.g., IoT communication protocol, industrial control protocol), data transmission type (e.g., command interaction, file transfer, real-time data stream), environment type of communication equipment deployment (e.g., industrial workshop, office area, outdoor scene), environmental electromagnetic interference intensity, and side-channel signals collected at corresponding times. The acquisition and processing module divides the operational parameter set into a model training set and a model test set in a 4:1 ratio to ensure the model's generalization ability. The model training set is used for model learning to capture relationships between data, while the model test set is used to verify model performance. Grid search involves traversing and constructing parameter combinations (construction parameters include structural parameters such as the number and depth of decision trees in the random forest model) to select parameter combinations that fit the data features, thereby establishing the random forest model. The random forest model is a learning model ensembled from multiple decision trees; the stability and accuracy of predictions are improved through voting or averaging the outputs of multiple trees. The random forest model is trained using the training set to learn the patterns between data. After training, the test set is substituted into the trained random forest model to calculate the accuracy of the prediction results. The accuracy threshold is preferably 0.9. This threshold is the minimum standard set by the system to measure model performance. When the accuracy is greater than or equal to the threshold, the model's prediction accuracy meets the standard, and it is identified as a network prediction signal model. When the accuracy is less than the threshold, it indicates that the model cannot capture the correlation between data after training. In this case, a new parameter combination is generated by expanding the search range of the construction parameters through grid search, and a new random forest model is built. This training and testing process is repeated until the model's accuracy is greater than or equal to the accuracy threshold. The signal fluctuation amplitude output by the network prediction signal model lays the foundation for determining the communication environment.

[0029] In some embodiments of this application, when determining the communication environment based on the relationship between the signal fluctuation amplitude and the second side channel signal, the following steps are taken: when the signal fluctuation of the second side channel signal is greater than or equal to the signal fluctuation amplitude, the acquisition and processing module determines that the communication environment is unqualified; when the signal fluctuation of the second side channel signal is less than the signal fluctuation amplitude, the acquisition and processing module determines that the communication environment is qualified.

[0030] Specifically, signal fluctuation amplitude is the threshold of normal fluctuation amplitude of the signal output from the first side channel signal in the network prediction signal model. It reflects the amplitude change of the side channel signal due to other factors (such as changes in equipment load or slight environmental interference) when there are no threats or abnormal interference in the communication system. Signal fluctuation of the second side channel signal is the actual amplitude change of the second side channel signal at the current moment compared to the first side channel signal at the previous moment. When the signal fluctuation of the second side channel signal is greater than or equal to the signal fluctuation amplitude, it indicates that the current signal change exceeds the allowable range, and there may be threats or abnormal interference. The acquisition and processing module determines that the communication environment is unqualified. When the signal fluctuation of the second side channel signal is less than the signal fluctuation amplitude, it indicates that the signal change is within a normal fluctuation range, and the communication environment is determined to be qualified. A qualified communication environment means that the communication system has high security and is generally not subject to covert attacks. Based on the fluctuation situation predicted by the model, the quantitative judgment of the communication environment status is realized. This avoids misjudging normal fluctuations caused by other factors as abnormalities and can promptly capture potential communication threats that exceed the normal range, thus ensuring the security and reliability of the communication system.

[0031] In some embodiments of this application, when determining the communication timing information of the second side channel signal, determining the data transmission delay of the second side channel signal based on the communication timing information, and determining the delay index value according to the standard data transmission delay and the data transmission delay, the following steps are included: the delay analysis module calls the communication log corresponding to the second side channel signal, extracts the data transmission delay from the communication log, obtains the standard data transmission delay corresponding to the data transmission delay, and determines the difference between the data transmission delay and the corresponding standard data transmission delay as the delay index value.

[0032] Specifically, communication timing information refers to the time-dimensional data (data packet sending / receiving timestamps) corresponding to the communication operations during the acquisition of the second-side channel signal. This time-dimensional data is recorded in the communication log of the communication system. The communication log is a detailed operational data automatically recorded during the operation of the communication system, containing the timestamp of the communication event, data packet identifier, sender and receiver information, operation type, etc., which can completely reflect the communication process corresponding to the second-side channel signal. The delay analysis module uses timestamp matching to call the communication log that is consistent with the acquisition time of the second-side channel signal, and extracts the data packet sending time and receiving acknowledgment time corresponding to the communication event from the communication log. The time difference between the two is the data transmission delay, which is the actual time consumed from the sending end to the receiving end completing the receiving acknowledgment of the data packet. The standard data transmission delay is a delay baseline constructed by the system for different communication scenarios (such as data transmission type, link status, device load). It is obtained by statistical analysis of data transmission delay in historical normal communication logs and represents the normal range of communication timing under a specific scenario. The latency analysis module obtains the corresponding standard data transmission latency based on the scenario information of the current data transmission event. The standard data transmission latency can be dynamically set for this communication event based on the communication link type (e.g., wireless link, wired link), data transmission type, communication protocol type, communication device load status, and transmission distance. The difference between the current data transmission latency and the standard data transmission latency is calculated and defined as the latency index value. A larger difference indicates a more significant deviation from the normal timing of the current data transmission. By calling the communication system's communication logs and extracting the data transmission latency, the reliability of the latency index value is ensured, thereby guaranteeing the security of the communication system.

[0033] In some embodiments of this application, when extracting the time-domain parameters of the second side-channel signal, performing a spectrum transformation on the second side-channel signal to determine the frequency-domain amplitude spectrum, determining the frequency-domain parameters of the second side-channel signal based on the frequency-domain amplitude spectrum, and fusing the time-domain parameters and frequency-domain parameters to determine the multi-dimensional feature vector, the process includes: the time-domain parameters include time-domain statistical features and time-domain instantaneous features; the time-domain statistical features include the signal peak value, signal mean value, and peak-to-average power ratio of the second side-channel signal; the time-domain instantaneous features include the rising edge slope and pulse width of the second side-channel signal; the time-domain analysis module performs a fast Fourier transform on the second side-channel signal to determine the frequency-domain amplitude spectrum, extracts the frequency-domain statistical features of the frequency-domain amplitude spectrum, and determines the frequency-domain statistical features as the frequency-domain parameters of the second side-channel signal; the frequency-domain statistical features include the peak frequency and spectral flatness; the time-domain parameters and frequency-domain parameters are fused to determine the time-frequency feature vector; and the time-frequency feature vector is dimensionality-reduced based on the principal component analysis algorithm to determine the multi-dimensional feature vector.

[0034] Specifically, the time-domain analysis module first extracts time-domain features. Time-domain parameters include time-domain statistical features and time-domain instantaneous features. Among them, the time-domain statistical features quantify the overall amplitude pattern of the second-side channel signal in the time dimension. The signal peak value is the maximum amplitude of the second-side channel signal at the acquisition time. The signal mean value represents the average level of the amplitude of the second-side channel signal. The peak-to-average power ratio (PAPR) represents the ratio of the signal peak value to the signal mean value of the second-side channel signal. The time-domain instantaneous features capture the instantaneous change pattern of the second-side channel signal. The rising edge slope is the rate at which the signal amplitude of the second-side channel signal changes from a low-proportion peak value to a high-proportion peak value. The pulse width is the duration of the pulse from the 50% amplitude point of the rising edge to the 50% amplitude point of the falling edge. Secondly, the time-domain analysis module performs a Fast Fourier Transform (FFT) on the second-side channel signal. The FFT transforms the signal's time dimension information into frequency-amplitude distribution information, thus obtaining the frequency-domain amplitude spectrum. Based on this spectrum, frequency-domain statistical features are extracted as frequency-domain parameters. The peak frequency is the frequency point with the largest amplitude in the frequency-domain amplitude spectrum, and spectral flatness represents the ratio of the geometric mean to the arithmetic mean of the spectrum. The time-domain analysis module fuses the time-domain and frequency-domain parameters to form a time-frequency feature vector. The fusion process is lengthy and well-established, and will not be detailed here. Principal Component Analysis (PCA) is used to reduce the dimensionality of the time-frequency feature vector. PCA retains the core features of the time-frequency feature vector while eliminating redundant information, ultimately determining a multi-dimensional feature vector. By extracting the time-domain and frequency-domain parameters, the time-domain and frequency-domain characteristics of the second-side channel signal are fully characterized, improving the accuracy of detecting hidden threats in the communication system.

[0035] In some embodiments of this application, when comparing a multidimensional feature vector with a historical time-frequency database and determining the number of times the multidimensional feature vector appears in the historical time-frequency database based on the comparison results, or deriving a threat index value based on the relationship between the multidimensional feature vector and historical multidimensional feature vectors, the following steps are taken: the historical time-frequency database includes several historical multidimensional feature vectors; when there is a historical multidimensional feature vector in the historical time-frequency database that is the same as the multidimensional feature vector, the threat perception module determines to derive a threat index value based on the number of times the multidimensional feature vector appears in the historical time-frequency database; when there is no historical multidimensional feature vector in the historical time-frequency database that is the same as the multidimensional feature vector, the threat perception module determines to derive a threat index value based on the relationship between the multidimensional feature vector and historical multidimensional feature vectors.

[0036] Specifically, the historical time-frequency database is a database that stores several historical multidimensional feature vectors. Moreover, the historical time-frequency database records the complete occurrence records of each historical multidimensional feature vector, including the corresponding time of each occurrence. Therefore, the historical time-frequency database records a large number of multidimensional feature vectors that pose potential threats in communication scenarios, which are historical multidimensional feature vectors. Furthermore, when constructing the historical time-frequency database, the occurrence frequency, occurrence time, and other characteristics of each historical multidimensional feature vector are also recorded in the historical time-frequency database. The threat perception module performs a one-to-one matching and comparison between the current multidimensional feature vector and all historical multidimensional feature vectors in the historical time-frequency database. When a historical multidimensional feature vector with the exact same appearance exists in the database, it indicates that the feature combination has been recorded in history. The threat perception module then determines the threat index value based on the frequency of occurrence of the multidimensional feature vector in the historical time-frequency database. When no historical multidimensional feature vector with the same appearance exists in the database, it indicates that the feature combination is appearing for the first time and has not been recorded. The threat perception module then determines the threat index value based on the relationship between the multidimensional feature vector and historical multidimensional feature vectors. By dynamically selecting the method for determining the threat index value based on the historical existence of multidimensional feature vectors, the module achieves rapid and accurate identification of known threats by utilizing the frequency of occurrence of identical feature vectors, and determines the threat index value of newly appearing or variant threats by using the relationship between the multidimensional feature vector and historical multidimensional feature vectors. This balances the efficiency and comprehensiveness of threat perception, thereby improving the communication system's ability to perceive different types of covert threats.

[0037] In some embodiments of this application, when a historical multidimensional feature vector identical to the multidimensional feature vector exists in the historical time-frequency database, the threat perception module determines the threat index value based on the number of times the multidimensional feature vector appears in the historical time-frequency database. This includes: the threat perception module determining the historical occurrence count of the historical multidimensional feature vector identical to the multidimensional feature vector and recording the historical occurrence count as the threat index value.

[0038] Specifically, the existence of identical historical multidimensional feature vectors indicates that these feature vectors have appeared repeatedly in the communication scenario. The threat perception module first uses a full-scale matching search to locate historical multidimensional feature vectors in the historical time-frequency database that are completely identical to the current multidimensional feature vector. Then, it counts the historical occurrences of these identical historical multidimensional feature vectors—that is, the number of times each historical multidimensional feature vector appears in the historical time-frequency database—and uses this historical occurrence count as the threat index value. Since the more times a historical feature vector corresponding to a threat scenario appears repeatedly, the stronger the correlation between that feature combination and the covert threat, the higher the threat index value. Using the historical occurrence count to quantify the threat index value improves the efficiency of identifying known threat features and further enhances the system's accuracy in perceiving covert threats.

[0039] In some embodiments of this application, when there is no historical multidimensional feature vector in the historical time-frequency database that is identical to the multidimensional feature vector, the threat perception module determines the threat index value based on the relationship between the multidimensional feature vector and the historical multidimensional feature vector. This includes: the threat perception module extracts the historical multidimensional feature vector from the historical time-frequency database, and generates several candidate item sets based on the extracted historical multidimensional feature vector and the multidimensional feature vector using the Eclat algorithm. The number of candidate item sets is positively correlated with the extracted historical multidimensional feature vector. Frequent itemsets are determined based on the support of the candidate item sets, and the association results between the multidimensional feature vector and the extracted historical multidimensional feature vector are determined based on the frequent itemsets. The association count of the association results is counted, and the association count is recorded as the threat index value.

[0040] Specifically, when no historical multidimensional feature vector exists in the historical time-frequency database that matches the multidimensional feature vector, the threat perception module uses the Eclat algorithm to mine the relationship between historical multidimensional feature vectors and multidimensional feature vectors. The Eclat algorithm is a frequent itemset mining algorithm based on a vertical data format, which can efficiently mine the correlation between features. The threat perception module uses the Eclat algorithm to generate several candidate itemsets from the extracted historical multidimensional feature vectors and multidimensional feature vectors. The number of candidate itemsets is positively correlated with the number of extracted historical multidimensional feature vectors; the more historical multidimensional feature vectors there are, the richer the combination of potential features, and the more candidate itemsets there are. The support of each candidate itemset is calculated. Support is the proportion of a candidate itemset appearing in the extracted historical multidimensional feature vectors. Candidate itemsets whose support reaches the support threshold are identified as frequent itemsets. The support threshold can be dynamically set according to the number of frequent itemsets. For example, if the total number of frequent itemsets is small, the support threshold is set to the minimum number of occurrences. If the total number of frequent itemsets is large, such as 100 frequent itemsets, the support threshold can be set to 3 times. If the frequent itemsets are 1000, the support threshold can be set to 5 times. Frequent itemsets represent frequently occurring feature combinations. Based on frequent itemsets, the association results between the current multidimensional feature vector and the extracted historical multidimensional feature vector are analyzed. Whenever a historical multidimensional feature vector and a multidimensional feature vector establish an association relationship, the number of these association results is counted (i.e., the number of associations). The more associations, the stronger the association between the current feature and the historical threat feature, and the higher the threat index value. By mining the associations between features through the Eclat algorithm, the communication system's ability to perceive unknown and hidden threats is improved.

[0041] In some embodiments of this application, when determining whether to issue a threat warning alarm based on threat indicator values ​​and latency indicator values, the following steps are taken: the threat perception module performs a weighted calculation on the threat indicator values ​​and latency indicator values ​​to determine a threat alarm value. When the threat alarm value is greater than or equal to the threat alarm threshold, it is determined that a threat warning alarm should be issued. When the threat alarm value is less than the threat alarm threshold, it is determined that no threat warning alarm should be issued.

[0042] Specifically, the threat index value is a quantitative value of threat level derived by comparing the side-channel time-frequency characteristics (multi-dimensional feature vector) with the historical time-frequency database, reflecting anomalies at the physical level of the side-channel signal. The delay index value reflects anomalies at the communication timing level. The threat perception module first assigns weights to the threat index value and the delay index value, with weights selected as (0,1]. The product of the threat index value and the weight is added to the product of the delay index value and the weight, and the sum is the threat alarm value. The threat alarm value integrates the dual threat information of side-channel physical characteristic anomalies and communication timing anomalies. The threat alarm threshold is a pre-set security judgment boundary of the system, reflecting the maximum acceptable threat level of the communication system. The threat alarm threshold can be dynamically set according to the load capacity of the communication equipment. Threat warnings are dynamically issued based on the relationship between the threat alarm value and the threat alarm threshold, avoiding misjudgments or omissions caused by judging from a single dimension, ensuring the reliability of the perception of hidden threats, and thus improving the security of the communication system.

[0043] In the above embodiments, the acquisition and processing module obtains the first and second side-channel signals, combines them with a network prediction signal model to determine the signal fluctuation amplitude, and judges the communication environment. This achieves screening of the communication environment dimension, improving the overall perception efficiency of the system. The delay analysis module analyzes communication timing information to determine data transmission delay when the communication environment is unqualified, avoiding the limitations of delay analysis only at the protocol layer and providing delay data support for threat judgment. The time domain analysis module integrates time domain parameters and frequency domain parameters to form a multi-dimensional feature vector, which more comprehensively characterizes the characteristics of the side-channel signal compared to single-parameter analysis, thereby uncovering deep-seated abnormal features of the signal and avoiding threat omissions due to missing features, thus improving the stability and reliability of the communication system. The threat perception module determines threat index values ​​through multi-dimensional feature vectors and combines them with delay index values ​​to determine whether to issue a threat warning alarm. This achieves comprehensive threat assessment across multiple dimensions and indicators, thereby improving the accuracy of hidden threat perception, providing comprehensive security for the communication system, and reducing the risks of data theft and communication interference caused by covert attacks.

[0044] In another preferred embodiment based on the above embodiments, see [reference] Figure 2As shown, this embodiment provides a covert threat perception method based on side-channel signals. The covert threat perception system based on side-channel signals described above includes: S100: Obtain the first side channel signal from the previous moment and the second side channel signal from the current moment, determine the signal fluctuation amplitude based on the network prediction signal model and the first side channel signal, and determine the communication environment based on the relationship between the signal fluctuation amplitude and the second side channel signal.

[0045] S200: When the communication environment is unqualified, determine the communication timing information of the second-side channel signal, determine the data transmission delay of the second-side channel signal based on the communication timing information, and determine the delay index value according to the standard data transmission delay and the data transmission delay.

[0046] S300: Extract the time-domain parameters of the second-side channel signal, perform spectrum transformation on the second-side channel signal to determine the frequency domain amplitude spectrum, determine the frequency domain parameters of the second-side channel signal based on the frequency domain amplitude spectrum, fuse the time-domain parameters and frequency domain parameters to determine the multi-dimensional feature vector.

[0047] S400: Compare the multidimensional feature vector with the historical time-frequency database, determine the number of times the multidimensional feature vector appears in the historical time-frequency database based on the comparison results, or derive the threat index value based on the relationship between the multidimensional feature vector and the historical multidimensional feature vector, and determine whether to issue a threat warning alarm based on the threat index value and the latency index value.

[0048] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program goods according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0049] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit it. Although the present invention has been described in detail with reference to the above embodiments, those skilled in the art should understand that modifications or equivalent substitutions can still be made to the specific implementation of the present invention. Any modifications or equivalent substitutions that do not depart from the spirit and scope of the present invention should be covered within the scope of protection of the claims of the present invention.

Claims

1. A covert threat perception system based on side-channel signals, characterized in that, include: The acquisition and processing module is configured to acquire the first side channel signal at the previous moment and the second side channel signal at the current moment, determine the signal fluctuation amplitude based on the network prediction signal model and the first side channel signal, and determine the communication environment based on the relationship between the signal fluctuation amplitude and the second side channel signal. The delay analysis module is configured to determine the communication timing information of the second side channel signal when the communication environment is unqualified, determine the data transmission delay of the second side channel signal based on the communication timing information, and determine the delay index value according to the standard data transmission delay and the data transmission delay. The time-domain analysis module is configured to extract the time-domain parameters of the second side-channel signal, perform spectrum transformation on the second side-channel signal to determine the frequency domain amplitude spectrum, determine the frequency domain parameters of the second side-channel signal based on the frequency domain amplitude spectrum, and fuse the time-domain parameters and frequency domain parameters to determine a multi-dimensional feature vector. The threat perception module is configured to compare the multidimensional feature vector with a historical time-frequency database, determine the number of times the multidimensional feature vector appears in the historical time-frequency database based on the comparison result, or derive a threat index value based on the relationship between the multidimensional feature vector and the historical multidimensional feature vector, and determine whether to issue a threat warning alarm based on the threat index value and the latency index value.

2. The covert threat perception system based on side-channel signals according to claim 1, characterized in that, When determining the signal fluctuation amplitude based on the network-predicted signal model and the first side-channel signal, the following are included: The acquisition and processing module obtains the set of operating parameters and divides the set of operating parameters into a model training set and a model test set. A random forest model is built by finding the model construction parameters based on grid search. The random forest model is trained based on the model training set, and the accuracy is determined by substituting the model test set into the trained random forest model. When the accuracy is greater than or equal to the accuracy threshold, the trained random forest model is determined as the network prediction signal model. When the accuracy is less than the accuracy threshold, the random forest model is rebuilt and trained by expanding the search range of the construction parameters through grid search. The first side-channel signal is substituted into the network prediction signal model to determine the signal fluctuation amplitude.

3. The covert threat perception system based on side-channel signals according to claim 2, characterized in that, When determining the communication environment based on the relationship between the signal fluctuation amplitude and the second-side channel signal, the following is included: When the signal fluctuation of the second side channel signal is greater than or equal to the signal fluctuation amplitude, the acquisition and processing module determines that the communication environment is unqualified. When the signal fluctuation of the second side channel signal is less than the signal fluctuation amplitude, the acquisition and processing module determines that the communication environment is qualified.

4. The covert threat perception system based on side-channel signals according to claim 3, characterized in that, When determining the communication timing information of the second side channel signal, determining the data transmission delay of the second side channel signal based on the communication timing information, and determining the delay index value according to the standard data transmission delay and the data transmission delay, the process includes: The delay analysis module calls the communication log corresponding to the second side channel signal, extracts the data transmission delay from the communication log, obtains the standard data transmission delay corresponding to the data transmission delay, and determines the difference between the data transmission delay and the corresponding standard data transmission delay as the delay index value.

5. The covert threat perception system based on side-channel signals according to claim 4, characterized in that, When extracting the time-domain parameters of the second side-channel signal, performing spectral transformation on the second side-channel signal to determine the frequency-domain amplitude spectrum, determining the frequency-domain parameters of the second side-channel signal based on the frequency-domain amplitude spectrum, and fusing the time-domain parameters and frequency-domain parameters to determine the multi-dimensional feature vector, the process includes: The time-domain parameters include time-domain statistical features and time-domain instantaneous features; The time-domain statistical features include the signal peak value, signal mean value, and peak-to-average power ratio of the second side channel signal, and the time-domain instantaneous features include the rising edge slope and pulse width of the second side channel signal; The time-domain analysis module performs a fast Fourier transform on the second side channel signal to determine the frequency domain amplitude spectrum, extracts the frequency domain statistical features of the frequency domain amplitude spectrum, and determines the frequency domain statistical features as the frequency domain parameters of the second side channel signal. The frequency domain statistical features include peak frequency and spectral flatness. The time-domain parameters and frequency-domain parameters are fused to determine the time-frequency feature vector, and the time-frequency feature vector is reduced in dimensionality based on the principal component analysis algorithm to determine the multidimensional feature vector.

6. The covert threat perception system based on side-channel signals according to claim 5, characterized in that, When comparing the multidimensional feature vector with a historical time-frequency database and determining the frequency of occurrence of the multidimensional feature vector in the historical time-frequency database based on the comparison results, or deriving a threat index value based on the relationship between the multidimensional feature vector and historical multidimensional feature vectors, the process includes: The historical time-frequency database includes several historical multidimensional feature vectors; When a historical multidimensional feature vector with the same appearance as the multidimensional feature vector exists in the historical time-frequency database, the threat perception module determines the threat index value based on the number of times the multidimensional feature vector appears in the historical time-frequency database. When there is no historical multidimensional feature vector in the historical time-frequency database that is the same as the multidimensional feature vector, the threat perception module determines the threat index value based on the relationship between the multidimensional feature vector and the historical multidimensional feature vector.

7. The covert threat perception system based on side-channel signals according to claim 6, characterized in that, When a historical multidimensional feature vector identical to the multidimensional feature vector exists in the historical time-frequency database, the threat perception module determines a threat index value based on the frequency of occurrence of the multidimensional feature vector in the historical time-frequency database, including: The threat perception module determines the number of times a historical multidimensional feature vector identical to the multidimensional feature vector has appeared in history, and records the number of times it has appeared in history as the threat index value.

8. The covert threat perception system based on side-channel signals according to claim 7, characterized in that, When no historical multidimensional feature vector identical to the stated multidimensional feature vector exists in the historical time-frequency database, the threat perception module determines a threat index value based on the relationship between the stated multidimensional feature vector and the historical multidimensional feature vector, including: The threat perception module extracts historical multidimensional feature vectors from the historical time-frequency database, and generates several candidate item sets based on the extracted historical multidimensional feature vectors and the multidimensional feature vectors using the Eclat algorithm. The number of candidate item sets is positively correlated with the extracted historical multidimensional feature vectors. Frequent itemsets are determined based on the support of the candidate item sets, and the association results between the multidimensional feature vectors and the extracted historical multidimensional feature vectors are determined based on the frequent itemsets. The number of associations in the association results is counted, and the number of associations is recorded as the threat index value.

9. The covert threat perception system based on side-channel signals according to claim 8, characterized in that, When determining whether to issue a threat warning alert based on the threat indicator value and the latency indicator value, the following steps are included: The threat perception module performs a weighted calculation of the threat indicator value and the latency indicator value to determine the threat alarm value; When the threat alarm value is greater than or equal to the threat alarm threshold, a threat warning alarm is issued. If the threat alarm value is less than the threat alarm threshold, it is determined that no threat warning alarm will be issued.

10. A method for detecting covert threats based on side-channel signals, employing the covert threat detection system based on side-channel signals as described in any one of claims 1-9, characterized in that, include: The first side channel signal at the previous moment and the second side channel signal at the current moment are obtained. The signal fluctuation amplitude is determined based on the network prediction signal model and the first side channel signal. The communication environment is judged based on the relationship between the signal fluctuation amplitude and the second side channel signal. When the communication environment is unqualified, the communication timing information of the second side channel signal is determined, the data transmission delay of the second side channel signal is determined based on the communication timing information, and the delay index value is determined according to the standard data transmission delay and the data transmission delay. Extract the time-domain parameters of the second side channel signal, perform spectrum transformation on the second side channel signal to determine the frequency domain amplitude spectrum, determine the frequency domain parameters of the second side channel signal based on the frequency domain amplitude spectrum, and fuse the time-domain parameters and frequency domain parameters to determine a multi-dimensional feature vector; The multidimensional feature vector is compared with the historical time-frequency database. Based on the comparison result, the number of times the multidimensional feature vector appears in the historical time-frequency database is determined. Alternatively, a threat index value is derived based on the relationship between the multidimensional feature vector and the historical multidimensional feature vector. Based on the threat index value and the delay index value, it is determined whether to issue a threat warning alarm.

Citation Information

Patent Citations

  • Mechanical arm spoofing attack side channel detection method and system based on acoustic characteristics

    CN118721277A

  • Network security situation awareness method and device for multi-source data fusion, equipment and medium

    CN120415841A

  • Device and method for anomaly detection and for training a model for anomaly detection

    DE102018221684A1

  • Authorized side-channel monitoring

    WO2024023548A1