Communication Method and Device for Preventing Malicious Users from Accessing

By identifying and classifying wireless signal characteristics, using malicious signal models and random forest models to identify and reject malicious user access, the problem of malicious user access in 5G networks is solved, and the security and reliability of the communication system are improved.

CN112087756BActive Publication Date: 2025-07-08BEIJING UNIV OF POSTS & TELECOMM
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202010777310.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-08-05
Publication Date
2025-07-08
Estimated Expiration
2040-08-05

AI Technical Summary

Technical Problem

In 5G wireless communication networks, security problems caused by blurred network security boundaries are becoming increasingly prominent. Attackers can affect the normal use of legitimate users through various means. The existing technology is difficult to effectively prevent malicious users from accessing, resulting in paralysis of communication systems or inability to access normally.

Method used

By obtaining the wireless signal frequency table, identifying and extracting the target signal characteristics, using malicious signals to identify the model classification signal type, if it is a legal signal, terminal information detection is performed, if it is a malicious signal, access is refused, and malicious terminals are identified through the random forest model and core network authentication process, adding to the blacklist or rejecting its service request.

Benefits of technology

Malicious signals, terminals and user identification based on endogenous security mechanisms are realized, the security of the communication system is improved, malicious access is effectively prevented, and the efficient and high availability security needs of 5G and industrial Internet are met.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN112087756B_ABST
    Figure CN112087756B_ABST
Patent Text Reader

Abstract

The present application proposes a communication method and device for preventing malicious users from accessing. Among them, the method includes: obtaining wireless signals within the detection range, and determining target signals in a preset frequency band from the wireless signals according to a signal frequency table; extracting signal features of the target signals, processing the signal features according to a malicious signal recognition model, and obtaining the category of the target signals; if the category of the target signals is a legitimate signal, detecting terminal information according to a preset detection strategy; if the category of the target signals is a malicious signal, rejecting the access of the target signals. According to the present application, malicious users can be prevented from accessing, and communication security can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of communication technologies, and in particular, to a communication method and apparatus for preventing malicious users from accessing. Background Art

[0002] Wireless communication systems carry network communication tasks and provide users with various services such as voice, web browsing, and multimedia services. With the development of fifth-generation (5G) wireless communication and the increasing demand for wireless services, extensive research has been conducted on wireless communication networks to meet enhanced mobile broadband, ultra-reliable low-latency communication, and massive machine-type communication.

[0003] The 5G network is based on a software-defined slicing platform and edge computing, and uses the integration of artificial intelligence and big data mining to promote the deep integration of vertical industries and mobile networks to support diverse application scenarios. However, network marginalization and software virtualization have blurred the network security boundary, and the security issues caused by the network security architecture have become increasingly prominent. At the same time, wireless communication networks are easily targeted by attackers. Attackers can affect the normal use of other legitimate users by performing illegal operations, and even cause various security problems. For example, attackers will launch active attacks such as impersonation, forgery, tampering, and replay against users and networks, or launch passive attacks such as eavesdropping and tracking.

[0004] Currently, in response to the security protection requirements in the integrated fields such as 5G and industrial Internet, as well as problems such as the inability to access normally and the paralysis of the communication system caused by user attacks on the communication system, a secure and efficient communication solution is needed. Summary of the Invention

[0005] The present application aims to solve at least one of the technical problems in the related technologies to some extent.

[0006] To this end, the present application proposes a communication method, apparatus, device, and storage medium for preventing malicious users from accessing.

[0007] A first aspect embodiment of the present application proposes a communication method for preventing malicious users from accessing, including:

[0008] Obtain wireless signals within the detection range, and determine target signals in a preset frequency band from the wireless signals according to a signal frequency table;

[0009] Extract signal features of the target signals, process the signal features according to a malicious signal recognition model, and obtain the categories of the target signals;

[0010] If the category of the target signal is a legitimate signal, detect terminal information according to a preset detection strategy to perform communication according to the detection result of the terminal information;

[0011] If the category of the target signal is a malicious signal, access of the target signal is rejected.

[0012] In addition, the communication method for preventing malicious users from accessing according to the above embodiments of the present application may further have the following additional technical features:

[0013] Optionally, the detecting the terminal information according to a preset detection policy includes: obtaining power information of the terminal, and determining a target terminal in a preset power range according to the power information; obtaining a preamble corresponding to the target terminal, and if a preamble identifier identical to the preamble exists in the terminal response message of the target terminal, determining that the target terminal is a legitimate terminal and executing a user service identification process; if a preamble identifier identical to the preamble is not recognized in the terminal response message, resending the preamble and counting the number of retransmissions of the preamble; when the number of retransmissions is greater than a preset number, determining that the target terminal is a malicious terminal and rejecting a service request of the target terminal.

[0014] Optionally, the executing the user service identification process includes: obtaining statistical features of user service data, where the statistical features include data arrival interval and flow duration; inputting the statistical features into a random forest model for processing to obtain a user category; if the user category is a legitimate user, executing a core network authentication process; if the user category is a malicious user, notifying the core network to add the user to a malicious user blacklist.

[0015] Optionally, the executing the core network authentication process includes: identifying each user to be accessed, and comparing the malicious user blacklist with the identification result of the user to be accessed; if the user to be accessed is a malicious user, rejecting authorization and authentication of the user to be accessed; if the user to be accessed is not a malicious user, performing authentication through an authentication protocol based on a symmetric cryptosystem, and if the authentication is successful, allowing a communication link between the user to be accessed and a service system to be established.

[0016] Optionally, the signal features include bandwidth, center frequency, power peak value, statistical features of instantaneous phase, wavelet domain features, cyclostationary features, and higher-order statistics.

[0017] Optionally, the malicious signal recognition model is trained through the following steps: mapping signal features of sample signals to a low-dimensional space through unsupervised learning, clustering the sample signals in the subspace, and assigning a first category label to the clustering result; performing supervised learning according to the sample signals labeled with a second category label; comparing the first category label and the second category label for category matching, and training the malicious signal recognition model according to the matching result.

[0018] Optionally, the random forest model is trained through the following steps: samples are drawn from the original sample set in a randomly repeatable manner to obtain K training sets; decision trees are constructed based on the drawn samples, where the K training sets correspond to K decision tree models; the prediction results of each decision tree model in the K decision tree models are obtained, and the K decision tree models are trained according to the prediction results of each decision tree model.

[0019] The second aspect embodiment of the present application proposes a communication device for preventing malicious users from accessing, including:

[0020] An acquisition module, configured to acquire wireless signals within a detection range, and determine target signals in a preset frequency band from the wireless signals according to a signal frequency table;

[0021] A signal recognition module, configured to extract signal features of the target signals, process the signal features according to a malicious signal recognition model, and obtain the categories of the target signals;

[0022] A first signal processing module, configured to, if the category of the target signal is a legal signal, detect terminal information according to a preset detection strategy, so as to perform communication according to the detection result of the terminal information;

[0023] A second signal processing module, if the category of the target signal is a malicious signal, rejects the access of the target signal.

[0024] The third aspect embodiment of the present application proposes a computer device, including a processor and a memory; wherein, the processor runs a program corresponding to the executable program code by reading the executable program code stored in the memory, so as to implement the communication method for preventing malicious users from accessing as described in the first aspect embodiment.

[0025] The fourth aspect embodiment of the present application proposes a non-transitory computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, it implements the communication method for preventing malicious users from accessing as described in the first aspect embodiment.

[0026] One embodiment of the above application has the following advantages or beneficial effects: By acquiring wireless signals within a detection range, determining target signals in a preset frequency band from the wireless signals according to a signal frequency table; extracting signal features of the target signals, processing the signal features according to a malicious signal recognition model, and obtaining the categories of the target signals; if the category of the target signal is a legal signal, detecting terminal information according to a preset detection strategy; if the category of the target signal is a malicious signal, rejecting the access of the target signal. According to the present application, malicious signals can be identified based on a malicious signal recognition model and the access of malicious signals can be rejected, improving communication security.

[0027] Additional aspects and advantages of the present application will be given in part in the following description, become apparent in part from the following description, or be learned through the practice of the present application. Brief Description of the Drawings

[0028] Figure 1 A flowchart of a communication method for preventing malicious user access provided by an embodiment of the present application;

[0029] Figure 2 A flowchart of a signal recognition provided by an embodiment of the present application;

[0030] Figure 3 A flowchart of another communication method for preventing malicious user access provided by an embodiment of the present application;

[0031] Figure 4 A flowchart of a terminal information detection provided by an embodiment of the present application;

[0032] Figure 5 A flowchart of another communication method for preventing malicious user access provided by an embodiment of the present application;

[0033] Figure 6 A flowchart of a user service recognition provided by an embodiment of the present application;

[0034] Figure 7 A flowchart of a core network authentication provided by an embodiment of the present application;

[0035] Figure 8 A structural diagram of a communication device for preventing malicious user access provided by an embodiment of the present application. Detailed Description of the Embodiments

[0036] Embodiments of the present application will be described in detail below. Examples of the embodiments are shown in the drawings, where the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the drawings are exemplary and are intended to explain the present application and should not be construed as limiting the present application.

[0037] A communication method, device, and equipment for preventing malicious user access according to embodiments of the present application will be described below with reference to the drawings.

[0038] Figure 1 A flowchart of a communication method for preventing malicious user access provided by an embodiment of the present application, as Figure 1 shown, the method includes:

[0039] Step 101: Obtain the wireless signals within the detection range, and determine the target signals in the preset frequency band from the wireless signals according to the signal frequency table.

[0040] The communication method for preventing malicious users from accessing in the embodiments of the present application can be applied to a base station or an access point.

[0041] In this embodiment, the base station / access point identifies the wireless signals in the natural noise, and then dynamically detects the wireless signals within its own detection range. By comparing with the authorized signal frequency table approved by the radio management agency, it detects whether the signal is in the correct frequency band to determine the unauthorized signal, so as to achieve the detection of the unauthorized signal. Among them, for the target signals in the preset frequency band, the signal features of the target signals are further extracted; for the signals not in the preset frequency band, they are determined as unauthorized signals, and the base station / access point rejects the access of the unauthorized signals.

[0042] Step 102: Extract the signal features of the target signals, process the signal features according to the malicious signal recognition model, and obtain the category of the target signals.

[0043] In this embodiment, in the case where the target signals are abnormal due to illegal transmission, frequency shift transmission, over-level transmission, over-bandwidth transmission, etc., the signal features of the target signals are extracted, and the extracted signal features are subjected to dimensionality reduction processing, that is, redundant features are removed.

[0044] Among them, the signal features of the target signals include but are not limited to the bandwidth, center frequency, power peak value, statistical features of the instantaneous phase, wavelet domain features of the signal, cyclic stationary features, and high-order statistics.

[0045] In this embodiment, the signal features are processed according to the malicious signal recognition model to obtain the category of the target signals. The category of the target signals includes legal signals and malicious signals.

[0046] As a possible implementation manner, the malicious signal recognition model is implemented in the following way: The signal features of the sample signals are mapped to a low-dimensional space through unsupervised learning, and the sample signals are clustered in a random subspace, and the first category label is assigned to the clustering result; supervised learning is performed according to the sample signals marked with the second category label; the first category label and the second category label are compared for category matching, and the malicious signal recognition model is trained according to the matching result.

[0047] Specifically, S1: Randomly select k points from all sample points as the initial cluster centers, and divide each sample point into the cluster corresponding to the nearest initial cluster center point based on the Euclidean metric standard. Furthermore, the center points of all samples in each cluster are used as the new cluster centers to replace the original center points. When the center points remain unchanged or reach the predetermined number of iterations, the algorithm terminates by iteratively obtaining the minimum sum of squared errors within the cluster.

[0048] S2. Use a support vector machine to determine a classification hyperplane in the feature space. This classification hyperplane is used to separate samples and, when accurately dividing all training set samples, maximize the classification margin at the same time. Furthermore, obtain the global optimal solution through local convergence of extreme values.

[0049] S3. Use a small part of labeled data for supervised learning, and compare the supervised and unsupervised class labels for class matching, where the classes include malicious signals and legitimate signals.

[0050] Step 103. If the class of the target signal is a legitimate signal, detect the terminal information according to a preset detection strategy to communicate based on the detection result of the terminal information.

[0051] Step 104. If the class of the target signal is a malicious signal, reject the access of the target signal.

[0052] In this embodiment, if the class of the target signal is a legitimate signal, detect the terminal information according to a preset detection strategy; if the class of the target signal is a malicious signal, reject the access of the target signal. Specifically, the rejection of signal access is achieved in the following way: The base station / access point sends control information to minimize the uplink transmission power of the signal and initiate uplink random access with the longest delay time.

[0053] For example, as Figure 2 shown, the base station / access point identifies wireless signals in natural noise, determines authorized signals and unauthorized signals by referring to the authorized signal frequency table. For unauthorized signals, reject the access of the signal. For authorized signals, extract signal features and reduce the dimension, and determine whether the authorized signal is a malicious signal through a malicious signal recognition model. If so, reject the access of the signal; if not, perform terminal information detection.

[0054] The communication method for preventing malicious user access in the embodiment of this application identifies malicious signals in wireless signals through a malicious signal recognition model, performs terminal detection on legitimate signals, and rejects access to malicious signals. Compared with relying on "plug-in" and "patch" network security mechanisms, which only focus on the boundary security protection technology of wireless communication, it realizes signal recognition based on endogenous security, effectively meets the high-efficiency and high-availability security protection requirements in the integration fields such as 5G and industrial Internet, can prevent malicious signals from accessing, and improve communication security.

[0055] Based on the above embodiment, Figure 3 is a schematic flowchart of another communication method for preventing malicious user access provided by the embodiment of this application. As Figure 3 shown, after determining that the class of the target signal is a legitimate signal, the method further includes:

[0056] Step 201: Obtain the power information of the terminal, and determine the target terminal within the preset power range according to the power information.

[0057] In this embodiment, after determining that the category of the target signal is a legal signal, the terminal information is detected according to the preset detection strategy. Specifically, when the terminal requests uplink resources from the base station, it implicitly notifies the base station / access point about the UE's power level through MSG1, that is, in the preamble transmission, and detects the terminal information.

[0058] As an example, the UE power levels include: 23 dBm, 20 dBm, and 14 dBm. If the power information of the terminal is greater than 23 dBm or less than 14 dBm, then the terminal is determined to be an abnormal terminal; if the power information of the terminal is between 14 dBm and 23 dBm, then the terminal is used as the target terminal.

[0059] It should be noted that according to the power information of the terminal, when the terminal's own power is between 14 dBm and 23 dBm and the preamble sent by the terminal device is included in Msg2, the random access response is determined to be successful; otherwise, it is determined that the random access response is not received successfully and re-access is required.

[0060] Step 202: Obtain the preamble corresponding to the target terminal. If there is a preamble identifier in the terminal response message of the target terminal that is the same as the preamble, then determine that the target terminal is a legal terminal and execute the user service identification process.

[0061] In this embodiment, for different scenarios such as initial access, connection access, and handover, Msg3 may contain different contents. If a random access preamble identifier in the terminal response message is the same as the preamble sent by the base station / access point, then it is determined that the terminal is a legal terminal and the response is received successfully.

[0062] Step 203: If no preamble identifier the same as the preamble is recognized in the terminal response message, retransmit the preamble and count the retransmission times of the preamble.

[0063] In this embodiment, if no preamble identifier the same as the preamble is recognized in the terminal response message, the base station / access point retransmits the preamble, and the transmission times of the preamble sent are incremented by 1, and the retransmission times of the preamble are counted.

[0064] Optionally, if the terminal receives a response message but fails to correctly parse the response message and cannot recognize the preamble of the terminal, it is considered that the reception of this response message fails, and the base station / access point retransmits the preamble, and the transmission times of the preamble sent are incremented by 1.

[0065] Step 204: When the number of retransmissions is greater than a preset number, determine that the target terminal is a malicious terminal and reject the service request of the target terminal.

[0066] In this embodiment, if the number of retransmissions of the preamble is greater than the preset number, it is determined that the target terminal is a malicious terminal, and the service request of the target terminal is rejected. Specifically, a random access response is sent downward, and the random access response includes making the uplink transmission power of the malicious terminal the lowest and initiating an uplink access message at the longest delay time.

[0067] For example, as Figure 4 shown, the base station / access point detects terminal information during the random access process, and determines whether it is an abnormal terminal according to the power of the terminal. If it is an abnormal terminal, the service request of the terminal is rejected. If it is not an abnormal terminal, the number of retransmissions of the preamble sent by the base station / access point is obtained, and it is determined whether it is a malicious terminal according to the number of retransmissions. If so, the service request of the terminal is rejected. If not, user service identification is performed.

[0068] The communication method for preventing malicious users from accessing in the embodiment of the present application realizes terminal identification based on endogenous security, can identify malicious terminals and reject the service requests of malicious terminals, and further improves communication security.

[0069] Based on the above embodiment, Figure 5 is a schematic flowchart of another communication method for preventing malicious users from accessing provided by the embodiment of the present application. As Figure 5 shown, after determining that the target terminal is a legal terminal, the method further includes:

[0070] Step 301: Obtain the statistical characteristics of user service data.

[0071] Among them, the statistical characteristics include data arrival interval and flow duration.

[0072] In this embodiment, after determining that the target terminal is a legal terminal, a user service identification process is executed. Specifically, the base station / access point utilizes the storage capacity and data processing capacity of the network edge device to count statistical characteristics such as packet data arrival interval and flow duration.

[0073] Step 302: Input the statistical characteristics into a random forest model for processing to obtain the user category.

[0074] In this embodiment, classification and identification are realized by using the random forest algorithm in ensemble learning, and the user category includes legal users and malicious users.

[0075] As an example, if more than N identical wireless random access signals are received within a unit time and the average service duration after access is less than the preset duration, the user category is determined to be a malicious user; otherwise, the user category is determined to be a legal user.

[0076] In one embodiment of the present application, the random forest model is obtained in the following manner: samples are drawn from the original sample set by means of random and repeatable sampling to obtain K training sets; decision trees are constructed based on the drawn samples, where the K training sets correspond to K decision tree models; the prediction results of each decision tree model among the K decision tree models are obtained, and the K decision tree models are trained according to the prediction results of each decision tree model.

[0077] Specifically, N training samples are randomly and repeatably drawn from the original sample set based on the Bootstrap sampling method, and a total of K rounds of drawing are performed to obtain K training sets. Decision trees are constructed based on the samples selected through the above steps. The decision tree node division rule is as follows: d features are randomly selected without repetition, and according to the requirements of the objective function, the selected features are used to divide the nodes. The requirements of the objective function are, for example, to maximize the information gain. The above process is repeated 1 to 2000 times. The categories of each decision tree are summarized and a majority vote is conducted to generate the prediction results of the decision tree. The user category is generated from the mean of the prediction results of the K models. The user category includes malicious users and legitimate users.

[0078] Step 303, if the user category is a malicious user, notify the core network to add the user to the malicious user blacklist.

[0079] For example, as Figure 6 shown, the base station / access point statistics features such as the packet data arrival interval and flow duration, and identifies the user category through the random forest algorithm. If it is a malicious user, inform the core network to add the user to the blacklist. If it is not a malicious user, perform core network authentication.

[0080] Step 304, if the user category is a legitimate user, perform the core network authentication process.

[0081] In this embodiment, performing the core network authentication process includes: identifying each user to be accessed, and comparing according to the malicious user blacklist and the identification result of the user to be accessed; if the user to be accessed is a malicious user, reject the authorization and authentication of the user to be accessed; if the user to be accessed is not a malicious user, perform authentication through an authentication protocol based on the symmetric cryptosystem. If the authentication is successful, allow a communication link to be established between the user to be accessed and the service system. If the authentication fails, reject the provision of services.

[0082] As an example, when initiating a packet data service, the user sends the ciphertext SUCI (Subscription Concealed Identifier) encrypted with the public key to the base station, which is uploaded to the core network to identify the corresponding terminal of each user to be accessed on the core network side.

[0083] Specifically, in S1, the user sends a request to access the network to the base station, sending the SUCI, which is the encrypted SUPI (Subscription Permanent Identifier, user permanent identifier) or GUTI (Globally Unique Temporary UE Identity, temporary UE identifier).

[0084] In S2, after receiving the SUCI, the base station forwards it to the SEAF (Security Anchor Function) in the core network.

[0085] In S3, the SEAF receives and parses the signaling. If it parses the GUTI, it matches the corresponding SUPI. If it parses the SUCI, it does not decrypt it and calls the authentication algorithm from the AUSF (Authentication Server Function AU).

[0086] In S4, the decryption algorithm is called in the UDM to decrypt the SUCI into the SUPI, so as to identify the corresponding terminal of each user to be accessed on the core network side. Among them, the decryption algorithm of the SUCI is executed once and is set in the UDM of the core network.

[0087] In S5, by importing the blacklist of malicious users, it is compared with the identification result of the user's corresponding terminal. If it is a malicious user, the authorization and authentication of the malicious user are refused to prohibit the malicious user from initiating an access request to the base station again. If it is not a malicious user, it is authenticated through the authentication protocol based on the symmetric cryptosystem. If the authentication is successful, a communication link between the user to be accessed and the service system is allowed to be established. If the authentication fails, the establishment of a communication link between the user to be accessed and the service system is refused.

[0088] Optionally, the secondary authentication protocol based on the symmetric cryptosystem is implemented as follows:

[0089] In S441, a random number RAND is generated DN , and according to RAND DN and ID DN calculate M1, and then generate h1 according to M1 and RAND DN ;

[0090] Send (M1, h1) to the user;

[0091] In S442, decrypt the received M1 to obtain RAND DN and ID DN , and then according to RAND DN and ID DNCalculate h1 and compare the calculated h1 with the received h1. If the values are not equal, terminate the session. Otherwise, generate a random number RAND UE , according to RAND UE and ID UE calculate M2, and then calculate the message authentication code h2 based on M2 and RAND UE ;

[0092] Send (M2, h2) to the DN-AAA;

[0093] S443, decrypt the received M2 to obtain RAND UE and ID UE , and then calculate h2 based on RAND UE and ID UE and compare it with the received h2. If the values are not equal, the authentication fails. Otherwise, the authentication succeeds, and calculate M3 from RAND UE and generate h3 based on M3;

[0094] Send (M3, h3) to the user;

[0095] S444, decrypt the received M3 to obtain RAND UE , calculate h3 based on RAND UE and compare it with the received h3. If the values are not equal, the authentication fails; otherwise, the authentication succeeds, and send the authentication success message to the DN-AAA.

[0096] Thus, in this embodiment, for the 5G network to provide services for vertical industries, to meet the special security requirements of users in different industries, a secondary authentication is introduced before providing a data channel for a specific service, that is, the authentication performed after the user accesses the network to establish a data channel for a specific service. For example, when the 5G network is used to provide communication for a high-security service system, after the user passes the access authentication, further authenticate with the user terminal using service-related credentials, and allow the 5G network to establish a communication link with the high-security service system when the authentication is passed, thereby enhancing the protection of the service system.

[0097] Optionally, the core network imports a blacklist of malicious users, identifies and determines malicious users and rejects their requests for authorization authentication, and prohibits malicious users from initiating requests to re-access the base station / access point. The core network stores the blacklist of malicious users reported by the base station / access point in the local user blacklist database. The core network and the base station / access point exchange the newly added blacklist through a feedback link and update the locally stored blacklist database according to the exchanged information.

[0098] For example, such as Figure 7As shown in the figure, on the core network side, each user to be accessed is identified, and the blacklist of malicious users is imported for matching. If it is a malicious user, the authorization and authentication of the malicious user are rejected. If it is not a malicious user, secondary authentication is performed.

[0099] The communication method for preventing malicious users from accessing in the embodiments of the present application realizes user identification based on endogenous security, can identify malicious users and prevent malicious users from accessing, and further improves communication security. In summary, based on the unified authentication framework, the present application makes full use of the storage capacity and data processing capacity of network edge devices, comprehensively considers adding an endogenous security user access mechanism, and proposes a communication method process that can prevent malicious users from accessing. Based on the unified authentication framework, relying on aggregating different security protocols and security mechanisms to achieve "cohesive governance" of network security, it has the autonomous driving force for self-discovery and self-repair against general network attacks, ensures the security of the communication network, and provides a solution to promote the network to evolve into the "endogenous security" era. In addition, the method of the present invention is convenient to operate and has good promotion prospects.

[0100] To implement the above embodiments, the present application also proposes a communication device for preventing malicious users from accessing.

[0101] Figure 8 The structural schematic diagram of a communication device for preventing malicious users from accessing provided by the embodiments of the present application is as Figure 8 shown. The device includes: an acquisition module 10, a signal recognition module 20, a first signal processing module 30, and a second signal processing module 40.

[0102] Among them, the acquisition module 10 is used to acquire wireless signals within the detection range and determine target signals in a preset frequency band from the wireless signals according to the signal frequency table.

[0103] The signal recognition module 20 is used to extract the signal characteristics of the target signal, process the signal characteristics according to the malicious signal recognition model, and obtain the category of the target signal.

[0104] The first signal processing module 30 is used to, if the category of the target signal is a legal signal, detect the terminal information according to a preset detection strategy to perform communication according to the detection result of the terminal information.

[0105] The second signal processing module 40, if the category of the target signal is a malicious signal, rejects the access of the target signal.

[0106] In an embodiment of the present application, the device further includes: a terminal access module, configured to obtain the power information of a terminal, determine a target terminal within a preset power range according to the power information; obtain the preamble corresponding to the target terminal, and if a preamble identifier identical to the preamble exists in the terminal response message of the target terminal, determine that the target terminal is a legitimate terminal and execute a user service identification process; if a preamble identifier identical to the preamble is not recognized in the terminal response message, resend the preamble and count the number of retransmissions of the preamble; when the number of retransmissions is greater than a preset number, determine that the target terminal is a malicious terminal and reject the service request of the target terminal.

[0107] In an embodiment of the present application, the device further includes: a service access module, configured to obtain the statistical features of user service data, where the statistical features include data arrival interval and flow duration; input the statistical features into a random forest model for processing to obtain a user category; if the user category is a legitimate user, execute a core network authentication process; if the user category is a malicious user, notify the core network to add the user to a malicious user blacklist.

[0108] In an embodiment of the present application, the device further includes: an authentication module, configured to identify each user to be accessed, and compare the malicious user blacklist with the identification result of the user to be accessed; if the user to be accessed is a malicious user, reject the authorization and authentication of the user to be accessed; if the user to be accessed is not a malicious user, perform authentication through an authentication protocol based on a symmetric cryptosystem, and if the authentication is successful, allow a communication link to be established between the user to be accessed and a service system.

[0109] In an embodiment of the present application, the signal features include bandwidth, center frequency, power peak, statistical features of instantaneous phase, wavelet domain features, cyclostationary features, and higher-order statistics.

[0110] In an embodiment of the present application, the malicious signal recognition model is trained through the following steps: mapping the signal features of sample signals to a low-dimensional space through unsupervised learning, clustering the sample signals in the subspace, and assigning a first category label to the clustering result; performing supervised learning according to the sample signals labeled with a second category label; comparing the first category label and the second category label for category matching, and training the malicious signal recognition model according to the matching result.

[0111] In one embodiment of the present application, the random forest model is trained through the following steps: Samples are drawn from the original sample set in a randomly repeatable manner to obtain K training sets; decision trees are constructed based on the drawn samples, where the K training sets correspond to K decision tree models; the prediction results of each decision tree model among the K decision tree models are obtained, and the K decision tree models are trained based on the prediction results of each decision tree model.

[0112] The explanation of the communication method for preventing malicious user access in the foregoing embodiment is equally applicable to the communication device for preventing malicious user access in this embodiment, and will not be elaborated here.

[0113] The communication device for preventing malicious user access in the embodiments of the present application realizes malicious signal recognition, malicious terminal recognition, and malicious user recognition based on endogenous security, effectively meets the high-efficiency and high-availability security protection requirements in fusion fields such as 5G and industrial Internet, prevents malicious users from accessing, and improves communication security. Moreover, based on the unified authentication framework, the storage capacity and data processing capacity of network edge devices are fully utilized, and an access mechanism for users with increased endogenous security is comprehensively considered, and a communication method flow capable of preventing malicious users from accessing is proposed.

[0114] To implement the above embodiments, the present application also proposes a computer device, including a processor and a memory; wherein, the processor runs a program corresponding to the executable program code by reading the executable program code stored in the memory, so as to implement the communication method for preventing malicious user access as described in any of the foregoing embodiments.

[0115] To implement the above embodiments, the present application also proposes a computer program product, which implements the communication method for preventing malicious user access as described in any of the foregoing embodiments when the instructions in the computer program product are executed by a processor.

[0116] To implement the above embodiments, the present application also proposes a non-transitory computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, it implements the communication method for preventing malicious user access as described in any of the foregoing embodiments.

[0117] In the description of the present application, it should be understood that the terms "first" and "second" are only used for descriptive purposes, and cannot be construed as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include at least one of such features. In the description of the present application, "a plurality" means at least two, such as two, three, etc., unless otherwise specifically defined.

[0118] In the description of this specification, the descriptions with reference to the terms "one embodiment", "some embodiments", "example", "specific example", or "some examples", etc. mean that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of this application. In this specification, the schematic descriptions of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described may be combined in any one or more embodiments or examples in a suitable manner. In addition, without contradiction, those skilled in the art can combine and combine the different embodiments or examples described in this specification and the features of different embodiments or examples.

[0119] Although the embodiments of this application have been shown and described above, it can be understood that the above embodiments are exemplary and should not be construed as limitations on this application. Those of ordinary skill in the art can make changes, modifications, substitutions, and variations to the above embodiments within the scope of this application.

Claims

1. A communication method for preventing malicious users from accessing, characterized in that, including: Obtain wireless signals within the detection range, and determine target signals within a preset frequency band from the wireless signals according to a signal frequency table; Extract the signal features of the target signals, process the signal features according to a malicious signal recognition model, and obtain the categories of the target signals; If the category of the target signal is a legitimate signal, detect terminal information according to a preset detection strategy to perform communication based on the detection result of the terminal information. Specifically, obtain the power information of the terminal, determine target terminals within a preset power range according to the power information, obtain the preambles corresponding to the target terminals, and if there is a preamble identifier in the terminal response message of the target terminal that is the same as the preamble, determine that the target terminal is a legitimate terminal and execute the user service recognition process. If no preamble identifier in the terminal response message is the same as the preamble, resend the preamble and count the number of retransmissions of the preamble. When the number of retransmissions is greater than a preset number, determine that the target terminal is a malicious terminal and reject the service request of the target terminal; If the category of the target signal is a malicious signal, reject the access of the target signal.

2. The method according to claim 1, wherein The execution of the user service recognition process includes: Obtain the statistical features of user service data, where the statistical features include data arrival interval and flow duration; Input the statistical features into a random forest model for processing to obtain the user category; If the user category is a legitimate user, execute the core network authentication process; If the user category is a malicious user, notify the core network to add the user to the malicious user blacklist.

3. The method according to claim 2, wherein The execution of the core network authentication process includes: Identify each user to be accessed, and compare the recognition result with the malicious user blacklist; If the user to be accessed is a malicious user, reject the authorization and authentication of the user to be accessed; If the user to be accessed is not a malicious user, authenticate through an authentication protocol based on a symmetric cryptosystem. If the authentication is successful, allow a communication link to be established between the user to be accessed and the service system.

4. The method according to claim 1, wherein The signal features include bandwidth, center frequency, power peak, statistical features of instantaneous phase, wavelet domain features, cyclostationary features, and higher-order statistics.

5. The method according to claim 1, characterized in that, The malicious signal recognition model is trained through the following steps: Map the signal features of sample signals to a low-dimensional space through unsupervised learning, cluster the sample signals in the subspace, and assign a first category label to the clustering result; Perform supervised learning according to the sample signals labeled with a second category label; Compare the first category label and the second category label for category matching, and train the malicious signal recognition model according to the matching result.

6. The method according to claim 2, wherein The random forest model is trained through the following steps: Extract samples from the original sample set in a randomly repeatable manner to obtain K training sets; Construct decision trees according to the extracted samples, where the K training sets correspond to K decision tree models; Obtain the prediction results of each decision tree model in the K decision tree models, and train the K decision tree models according to the prediction results of each decision tree model.

7. A communication device for preventing malicious users from accessing, characterized in that, including: An acquisition module, configured to acquire wireless signals within a detection range, and determine target signals within a preset frequency band from the wireless signals according to a signal frequency table; A signal recognition module, configured to extract signal features of the target signals, process the signal features according to a malicious signal recognition model, and obtain the categories of the target signals; A first signal processing module, configured to, if the category of the target signal is a legitimate signal, detect terminal information according to a preset detection strategy, so as to perform communication according to a detection result of the terminal information, where power information of a terminal is acquired, a target terminal within a preset power range is determined according to the power information, a preamble corresponding to the target terminal is acquired, if a preamble identifier identical to the preamble exists in a terminal response message of the target terminal, the target terminal is determined to be a legitimate terminal, and a user service recognition process is executed, if a preamble identifier identical to the preamble is not recognized in the terminal response message, the preamble is retransmitted, and the retransmission times of the preamble are counted, when the retransmission times are greater than a preset number of times, the target terminal is determined to be a malicious terminal, and a service request of the target terminal is rejected; A second signal processing module, configured to, if the category of the target signal is a malicious signal, reject access of the target signal.

8. A computer device, characterized in that, It includes a processor and a memory; Wherein, the processor runs a program corresponding to the executable program code by reading the executable program code stored in the memory, so as to implement the communication method for preventing malicious user access according to any one of claims 1-6.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it implements the communication method for preventing malicious user access according to any one of claims 1-6.

Citation Information

Patent Citations

  • Internet of things terminal secure access method and system based on edge computing

    CN107770263A