Data processing method, device, electronic device and storage medium
By analyzing the index data in international roaming scenarios and generating early warning prompt information, the problem of poor accuracy of abnormal signaling detection in the prior art is solved, and efficient abnormal signaling detection is achieved.
Patent Information
- Application Number
- CN202210281176.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-03-21
- Publication Date
- 2025-08-22
- Estimated Expiration
- 2042-03-21
AI Technical Summary
In the prior art, abnormal signaling detection methods based on communication protocol specifications are difficult to identify abnormal signaling caused by high-level forgery technology, resulting in poor accuracy of detection results and easily causing losses.
By analyzing the data in international roaming scenarios, the index data carried by the request, including the user identity, source host address, request operation code and network element traffic, determine whether the target detection result is abnormal, and generate warning prompt information.
Improve the accuracy of abnormal signaling detection, prevent abnormal request signaling missed detection, enhance detection strength, and ensure network security.
Smart Images

Figure CN114567882B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to computer processing technology, and more particularly to a data processing method, device, electronic device, and storage medium. Background Art
[0002] With the development of the Internet economy, international roaming has become an important business area in mobile communications. However, since international network communications are usually fragile and easy to be hacked, the problem of network security risks is becoming increasingly prominent. Therefore, it is necessary to monitor the transmission signaling during international roaming in real time to prevent intrusive signaling from damaging domestic networks and causing significant losses.
[0003] Currently, in international roaming scenarios, abnormal signaling in the network is typically detected by checking the communication protocol specifications. For example, if the length of the transmission protocol corresponding to the signaling is not the preset length, the signaling is considered abnormal. However, advanced forgery techniques can imitate the transmission protocol to make the protocol parameters and protocol flow conform to the standard protocol specifications. In this way, even abnormal signaling is difficult to detect, which can easily cause significant losses. Summary of the Invention
[0004] The embodiments of the present invention provide a data processing method, device, electronic device and storage medium to enhance the strength of anomaly detection and achieve the technical effect of improving the accuracy of detection result determination.
[0005] In a first aspect, an embodiment of the present invention provides a data processing method, the method comprising:
[0006] Upon receiving at least one data acquisition request and determining that the roaming type corresponding to the data acquisition request is an incoming roaming type, acquiring the data to be detected carried by the data acquisition request; wherein the data to be detected includes at least one indicator data item corresponding to at least one indicator item including a user identity identifier, a source host address, a request operation code, and a network element traffic;
[0007] By analyzing and testing the various indicator data in the data to be tested, the target detection results corresponding to the various indicator data are obtained;
[0008] If the target detection result is an abnormal detection result, a warning prompt message is generated and displayed based on the indicator item data corresponding to the target detection result.
[0009] In a second aspect, an embodiment of the present invention further provides a data processing device, the device comprising:
[0010] a data to be detected determining module, configured to, upon receiving at least one data acquisition request and determining that the roaming type corresponding to the data acquisition request is an incoming roaming type, acquire the data to be detected carried by the data acquisition request; wherein the data to be detected includes at least one indicator data item corresponding to at least one indicator item including a user identity identifier, a source host address, a request operation code, and a network element traffic;
[0011] The target detection result determination module is used to obtain the target detection result corresponding to each indicator data by analyzing and detecting each indicator data in the data to be detected;
[0012] The early warning prompt information generation module is used to generate and display early warning prompt information based on the indicator item data corresponding to the target detection result if the target detection result is an abnormal detection result.
[0013] In a third aspect, an embodiment of the present invention further provides an electronic device, comprising:
[0014] one or more processors;
[0015] a storage device for storing one or more programs,
[0016] When the one or more programs are executed by the one or more processors, the one or more processors implement the data processing method as described in any one of the embodiments of the present invention.
[0017] In a fourth aspect, an embodiment of the present invention further provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the data processing method as described in any one of the embodiments of the present invention.
[0018] The technical solution of the embodiment of the present invention, when receiving at least one data acquisition request and determining that the roaming type corresponding to the data acquisition request is a roaming type, obtains the data to be detected carried by the data acquisition request, and obtains the target detection results corresponding to the various indicator data by analyzing and detecting the various indicator data in the data to be detected. If the target detection result is an abnormal detection result, early warning prompt information is generated and displayed based on the indicator item data corresponding to the target detection result. This solves the problem in the prior art of performing abnormal detection on signaling based on communication protocol specifications, resulting in poor accuracy in determining the detection results. When receiving each data acquisition request, the indicator data corresponding to at least one indicator item including the user identity identifier, the source host address, the request operation code, and the network element traffic in the data acquisition request of the roaming type is analyzed and detected, greatly enhancing the detection strength. If the target detection result corresponding to any indicator data is an abnormal detection result, early warning prompt information can be generated to issue an alarm prompt, thereby achieving the technical effect of preventing the occurrence of missed detection of abnormal requests and improving the accuracy of the detection result determination. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] To more clearly illustrate the technical solutions of the exemplary embodiments of the present invention, the following briefly introduces the drawings required for describing the embodiments. Obviously, the drawings introduced here only illustrate some of the embodiments to be described by the present invention, and are not exhaustive. A person skilled in the art can derive other drawings based on these drawings without inventive effort.
[0020] Figure 1 A flowchart of a data processing method provided in Example 1 of the present invention;
[0021] Figure 2 A schematic diagram of the process of abnormal request monitoring provided by the second embodiment of the present invention;
[0022] Figure 3 A schematic diagram of the roaming scene structure provided by the second embodiment of the present invention;
[0023] Figure 4 A schematic diagram of the roaming registration service process provided in the second embodiment of the present invention;
[0024] Figure 5 A schematic diagram of the user location acquisition service process provided in the second embodiment of the present invention;
[0025] Figure 6 A schematic diagram of the shutdown service process provided in the second embodiment of the present invention;
[0026] Figure 7 A schematic diagram of a data processing method provided in the second embodiment of the present invention;
[0027] Figure 8 A schematic diagram of a data processing method provided in the second embodiment of the present invention;
[0028] Figure 9 This is a structural block diagram of a data processing device provided in Embodiment 3 of the present invention;
[0029] Figure 10 This is a structural diagram of an electronic device provided in Example 4 of the present invention. DETAILED DESCRIPTION
[0030] The present invention will be further described in detail below with reference to the accompanying drawings and examples. It will be understood that the specific embodiments described herein are intended only to illustrate the present invention and are not intended to limit the present invention. It should also be noted that, for ease of description, the accompanying drawings only illustrate portions relevant to the present invention, not all structures.
[0031] Example 1
[0032] Figure 1 This is a flow chart of a data processing method provided in Embodiment 1 of the present invention. This embodiment is applicable to situations where signaling is monitored. This method can be executed by a data processing device in an embodiment of the present invention. The device can be implemented using software and / or hardware. Optionally, it can be implemented by an electronic device, such as a mobile terminal, a PC, or a server. The device can be configured in a computing device. The data processing method provided in this embodiment specifically includes the following steps:
[0033] S110: When at least one data acquisition request is received and it is determined that the roaming type corresponding to the data acquisition request is an inbound type, acquire the to-be-detected data carried by the data acquisition request.
[0034] The data acquisition request may be a Diameter protocol type request, and the Diameter protocol may include but is not limited to the S6a interface protocol and the S6d interface protocol. The S6a interface protocol is a protocol between the MME (Mobility Management Entity) network element and the HSS (Home Subscriber Server) network element, and the S6d interface protocol is a protocol between the SGSN (Serving GPRS Support Node) network element and the HSS network element. Roaming types may include inbound and outbound types. For example, in actual applications, the service information of user 1 corresponding to a mobile device is stored in the HSS of the user's home location. When the mobile device roams from service area A where it is locally registered to another service area B, the HSS of the user's location B does not have the service information of user 1. At this time, the mobile device may send a request to the HSS of the user's home location, and the data request at this time may be treated as an inbound data request. For example, at the international communication interface, for service area A, the data request sent by the device in service area A to the other service areas can be regarded as an outbound data request, and the data request sent by the other service areas to service area A can be regarded as an inbound data request. The data to be detected includes at least one indicator data, and the indicator data corresponds to at least one indicator item including the user identity, the source host address, the request operation code, and the network element traffic. The user identity can be used to characterize the uniqueness of the user identity. For example, in 4G and / or 5G networks, the mobile phone number or IMSI (International Mobile Subscriber Identity) can be used as an identity. The source host address can be understood as the source address generated by the data request, and the source host address can include the HSS address or the MME address. The request operation code can be used to characterize the request operation action, such as location update, authentication, data insertion, shutdown, and other operations.
[0035] In this embodiment, a data acquisition request can be generated based on a user triggering operation on a terminal device. For example, a data acquisition request can be considered received when the terminal device is powered on, powered off, moved, or a page is triggered. For example, when the device is powered on, the data acquisition request can be an authentication request. When determining the roaming type corresponding to the data acquisition request, the source address information of the request carried in the data acquisition request can be detected. For example, assuming area 1 as an example, if the source address information is area 2, it can be determined that the data acquisition request is transmitted from an area other than area 1, and the roaming type of the data acquisition request can be considered as an inbound roaming type. If the source address information is area 1, it can be determined that the data acquisition request is transmitted from area 1 to an area other than area 1, and the roaming type of the data acquisition request can be considered as an outbound roaming type. Furthermore, indicator data corresponding to at least one indicator item including a user identity, source host address, request operation code, and network element traffic carried in the inbound data acquisition request can be obtained, and the data to be detected can be obtained accordingly. For example, assuming that in an international roaming scenario, a Diameter protocol data request can be obtained at the international roaming interface as a data acquisition request, and then it is determined whether the Diameter data request is received from the international roaming interface, that is, whether it is a Diameter data request transmitted from a non-local area. In this case, the Diameter data request can be in the format of offline data, online data, or XDR call records. If so, the Diameter data request can be cleaned and processed and saved in a database to enable subsequent determination of whether these Diameter data requests are abnormal requests.
[0036] Specifically, when a data acquisition request is received at the communication interface, the roaming type corresponding to the data acquisition request can be determined based on the source address information that generates the data acquisition request. If the source address information corresponds to a local preset area, it can be used as a roaming type of data acquisition request, and then the data to be detected carried on the data acquisition request can be obtained.
[0037] It should be noted that, when receiving at least one data acquisition request and determining that the data acquisition request corresponds to a roaming type, and obtaining the data to be detected carried by the data acquisition request, the request source address corresponding to the data acquisition request can also be compared with a preset local area address. If the two are inconsistent, the roaming type of the data acquisition request can be regarded as the roaming type, or the request source address can be compared with a preset foreign area address. If the two are consistent, the roaming type of the data acquisition request can be regarded as the roaming type, and the data to be detected carried by the data acquisition request can be obtained.
[0038] Optionally, when at least one data acquisition request is received and it is determined that the roaming type corresponding to the data acquisition request is a roaming type, the data to be detected carried by the data acquisition request is obtained, including: when at least one data acquisition request is received, obtaining the source protocol address corresponding to each data acquisition request; if the source protocol address is not within a preset protocol address range, determining that the roaming type of the corresponding data acquisition request is a roaming type; and parsing the data acquisition request to obtain the data to be detected carried by the data acquisition request.
[0039] The source protocol address can be used to indicate the location where the data acquisition request is generated.
[0040] In this embodiment, upon receiving a data retrieval request, the source IP (Internet Protocol) address (i.e., source protocol address) of the data retrieval request can be obtained. The source protocol address can be compared with preset protocol addresses. If the source protocol address is not within the preset protocol address range, the request is from abroad, and the roaming type of the data retrieval request can be considered as incoming roaming. For example, the source IP address field of the Diameter data request (data retrieval request) can be extracted to determine the source IP address. The source IP address can be compared with the IP address segment of the domestic and international ports or the IP address range of the domestic and international ports. If the source IP address does not match the IP address segment allowed by the domestic and international ports, the request is a roaming request, i.e., the roaming type is incoming roaming. Alternatively, the source IP address can be determined to be within the IP address range. If it is not within the IP address range, the request is a roaming request, which can be international roaming. Furthermore, the data retrieval request with the incoming roaming type can be parsed to obtain the data to be tested carried in the data retrieval request.
[0041] S120 , analyzing and detecting various indicator data in the data to be detected to obtain target detection results corresponding to the various indicator data.
[0042] The target detection result can be either an abnormal detection result or a normal detection result. The abnormal detection result can be used to characterize request anomalies. For example, communication protocol forgery, incomplete business process, etc. can all be represented as request anomalies.
[0043] In actual applications, the indicator data corresponding to various indicator items including user identity, source host address, request operation code and network element traffic in the data to be detected can be analyzed and detected to obtain the target detection results corresponding to each indicator data. There are many ways to determine the target detection results. The following is a detailed description of each implementation method.
[0044] It should be noted that when the target detection results corresponding to the various indicator data are obtained by analyzing and detecting the various indicator data in the test data, the target detection results can be determined based on the preset international roaming rules. For example, the international roaming rules can be the IMSI and the affiliated HSS consistency principle, the IMSI and the affiliated HSS uniqueness principle, etc. It can be understood that: if the IMSI corresponding to the request and the affiliated HSS belong to the same area (country / region), there may be a case of fake affiliated HSS, and the request can be considered abnormal at this time. If the IMSI corresponding to the request and the affiliated HSS do not belong to the same area (country / region), there is a situation where the IMSI has multiple affiliated HSSs, and the request can be considered abnormal.
[0045] Optionally, by analyzing and detecting each indicator data in the data to be detected, the target detection results corresponding to each indicator data are obtained, including: if the header field in the indicator data corresponding to the user identity identifier is consistent with the preset field, then the device type corresponding to the indicator data corresponding to the source host address is determined; if the device type is a home contracted device, then the target detection result corresponding to the source host address is determined to be an abnormal detection result; or, if the device type is a mobile management device, then the location field contained in the source host address is obtained, and if the location field is consistent with the preset field, then the target detection result corresponding to the source host address is determined to be an abnormal detection result.
[0046] The preset field can be used to indicate the user's home region. Optionally, the preset field can be 460, which can represent Country A. The device type can be understood as the type of host initiating the request. Optionally, it can be HSS (Home Subscriber Service) or MME (Mobility Management Equipment). The location field can indicate the location information of the region to which the mobility management device belongs. For example, a value of 460 in the location field can indicate Country A to which the mobility management device belongs.
[0047] It should be noted that when a data acquisition request of roaming type is received, if the user corresponding to the data acquisition request is a user in the preset area, then the data acquisition request can be detected for abnormalities. If the user corresponding to the data acquisition request is not a user in the preset area, then the data acquisition request can be not detected for abnormalities, thereby improving the efficiency of signaling detection.
[0048] In this embodiment, the received data acquisition request of the roaming type can be filtered based on the preset field. If the header field of the user identity carried in the data acquisition request is consistent with the preset field, the user identity can be considered to be an identity in the home area. For example, in an international roaming scenario, the data acquisition request can be considered to be a request containing a domestic user identity transmitted from abroad. Furthermore, the device type corresponding to the source host address carried in the data acquisition request can be determined. For example, if the source host address is an HSS address, the device type is a home contract device. If the source host address is an MME address, the device type is a mobile management device. Furthermore, if the device type is a home contract device, the data acquisition request at this time can be considered to be an abnormal request because there is no HSS server corresponding to the user terminal abroad, so the request is abnormal. The target detection result corresponding to the source host address is an abnormal detection result. To clearly understand the specific cause of the abnormality, it is optionally possible to determine whether the source host address contains a preset field. If so, this indicates that the HSS corresponding to the source host address and the user identity belong to the same region. For example, if both are domestic, it can be considered that the HSS is impersonating. If not, this indicates that the HSS corresponding to the source host address and the user identity belong to different regions. For example, if the user identity is domestic and the HSS is international, it can be considered that there is an abnormal location. If the device type is a mobility management device, the location field contained in the source host address can be obtained. If the location field is inconsistent with the preset field, it can be considered that the MME corresponding to the source host address is inconsistent with the user identity region. In other words, the user terminal is located in an international MME sending a request to the domestic MME. In this case, the request is normal. If the location field is consistent with the preset field, it can be considered an abnormal request. This is because a roaming data acquisition request is a request sent from a domestic MME to the domestic MME, which does not comply with international roaming regulations. This may indicate an MME impersonation. Therefore, the target detection result corresponding to the source host address is determined to be an abnormal detection result.
[0049] It should be noted that when analyzing and testing the various indicator data in the test data to obtain the target detection results corresponding to the various indicator data, the target detection results can also be determined based on the preset international roaming rules. For example, the international roaming rules can be to meet the preset business processes. For example, in actual applications, the user terminal is first turned on, user authentication and user location update are performed, and the user registration process is completed before cancellation of registration, insertion of user data, user shutdown and other operations can be initiated. If there is no registration process, other operations are initiated, then it can be judged that the user's business process is abnormal and it is an abnormal request.
[0050] Optionally, by analyzing and detecting each indicator data in the data to be detected, the target detection results corresponding to each indicator data are obtained, and it also includes: if the header field in the indicator data corresponding to the user identity identifier is consistent with the preset field, then determining whether the indicator data corresponding to the request operation code is consistent with the preset operation code; if so, obtaining the operation attribute value corresponding to the request operation code within the first preset time length; if the operation attribute value is greater than the preset operation threshold, then determining that the target detection result corresponding to the request operation code is an abnormal detection result.
[0051] The preset operation code may include, but is not limited to, authentication operations, location updates, etc. The first preset duration may be understood as a preset duration, for example, 5 seconds or 5 minutes. The operation attribute value may be understood as the frequency of the operation. The preset operation threshold may be understood as the preset operation frequency.
[0052] In this embodiment, if the header field in the indicator data corresponding to the user identity identifier is consistent with the preset field, it can be further determined whether the request operation code carried on the data acquisition request is consistent with the preset operation code. Optionally, the request operation code can be an operation code corresponding to an authentication operation or a location update operation. If so, the operation frequency corresponding to the request operation code within the first preset time length, that is, the operation attribute value, can be obtained. If the operation attribute value is greater than the preset operation threshold, the target detection result can be considered to be an abnormal detection result. For example, in actual applications, it can be determined whether the data acquisition request is an authentication request or a location update request. If so, the number of times the user terminal authenticates and updates its location in different areas within a unit time can be counted as the operation attribute value, and the judgment is made based on dimensions such as time and space. If the operation attribute value does not meet the actual preset operation threshold, the request is abnormal, that is, the target detection result is an abnormal detection result. A roaming abnormality alarm based on time and space judgment can also be sent;
[0053] It should be noted that if the request operation code carried in the data acquisition request is inconsistent with the preset operation code, it may indicate that the business operation corresponding to the data acquisition request may not be a necessary business operation in the business process, to prevent abnormal execution of the request jump operation. Assuming that the user terminal has not undergone the authentication process, the user data is inserted, and there may be problems such as malicious tampering or loss of user data. The above-mentioned necessary business operations can be detected to determine whether the user terminal has completed these business operations.
[0054] Optionally, the method further includes: if the indicator data corresponding to the request operation code is inconsistent with the preset operation code, obtaining feedback data corresponding to the preset operation code; if the target feedback result in the feedback data is inconsistent with the preset feedback result, determining that the target detection result corresponding to the request operation code is an abnormal detection result;
[0055] The preset feedback result may be authentication success or location update success.
[0056] In this embodiment, when the indicator data corresponding to the request operation code is inconsistent with the preset operation code, feedback data corresponding to the preset operation code can be obtained, for example, feedback data corresponding to an authentication operation or a location update operation. The target feedback result in the feedback data can be compared with the preset feedback result. If the two results are inconsistent, it can be indicated that the user terminal has not performed authentication or location update, or that authentication or location update has failed. In this case, the request is abnormal, that is, the target detection result is an abnormal detection result. For example, in actual applications, if the data acquisition request is not an authentication request or a location update request, it can be determined whether the user terminal has sent an authentication or location update process. If it has, the service is normal. If it has not, the request is abnormal, and a service process abnormality alarm can be sent.
[0057] It should be noted that when analyzing and testing the various indicator data in the test data to obtain the target detection results corresponding to the various indicator data, judgments can also be made based on the business traffic. For example, historical network element business traffic can be counted to calculate the maximum business traffic of the network element. The traffic threshold of the network element can be set, such as the maximum business traffic × 2. When the business traffic initiated by the MME network element or HSS network element within the preset time range exceeds the traffic threshold, it can be determined that the request is abnormal.
[0058] Optionally, by analyzing and detecting each indicator data in the data to be detected, the target detection results corresponding to each indicator data are obtained, which also includes: if the header field in the indicator data corresponding to the user identity identifier is consistent with the preset field, then determining whether the indicator data corresponding to the network element traffic within the second preset time period is greater than the preset traffic threshold; if so, determining that the target detection result corresponding to the network element traffic is an abnormal detection result.
[0059] In this embodiment, when the user identity carried in the data acquisition request is a domestic user identity, the service traffic initiated by the MME network element or HSS network element within the second preset time period, that is, the network element traffic, can be counted to form a traffic threshold statistics table of the network element. When the network element traffic exceeds the preset traffic threshold, the target detection result corresponding to the network element traffic can be considered as an abnormal detection result.
[0060] S130: If the target detection result is an abnormal detection result, generate and display early warning information based on the indicator item data corresponding to the target detection result.
[0061] In this embodiment, after determining that the target detection result is an abnormal detection result, the indicator item data corresponding to the target detection result can be used as early warning prompt information and displayed.
[0062] It should be noted that in order to accurately notify and prompt request anomalies and improve monitoring efficiency, when generating early warning prompt information based on the indicator item data corresponding to the abnormal detection results, the indicator item data corresponding to the abnormal detection results can be processed, such as enlarging the font of the indicator item data and highlighting the color. The processed indicator item data can be used as early warning prompt information, and then the early warning prompt information can be displayed on the system page, so that users can intuitively discover abnormal request signaling in time based on the early warning prompt information displayed on the system page, and determine the source of the abnormality based on the indicator item data in the early warning prompt information.
[0063] Optionally, if the target detection result is an abnormal detection result, an early warning prompt message is generated and displayed based on the indicator item data corresponding to the target detection result, including: if the target detection result is an abnormal detection result, the indicator item data corresponding to the target detection result is filled into the preset prompt template, an early warning prompt message is generated, and the early warning prompt message is sent to the monitoring page for display, so that the target user can determine the network maintenance method based on the indicator item data in the early warning prompt message.
[0064] Specifically, when the target detection result is an anomaly, the indicator data corresponding to the anomaly detection result can be entered into a preset prompt template to generate an early warning prompt message. For example, assuming the indicator data corresponds to network element traffic, the early warning prompt message may be that the authentication operation traffic exceeds a threshold. The early warning prompt message can be sent to the monitoring page for display, allowing users to locate the anomaly based on the indicator data in the early warning prompt message and promptly determine the network maintenance method.
[0065] The technical solution of this embodiment, when receiving at least one data acquisition request and determining that the roaming type corresponding to the data acquisition request is a roaming type, obtains the data to be detected carried by the data acquisition request, and obtains the target detection results corresponding to the various indicator data by analyzing and detecting the various indicator data in the data to be detected. If the target detection result is an abnormal detection result, an early warning prompt information is generated and displayed based on the indicator item data corresponding to the target detection result. This solves the problem in the prior art of performing abnormal detection on signaling based on communication protocol specifications, resulting in poor accuracy in determining the detection results. When receiving each data acquisition request, the indicator data corresponding to at least one indicator item including the user identity identifier, the source host address, the request operation code and the network element traffic in the data acquisition request of the roaming type is analyzed and detected, which greatly enhances the detection strength. If the target detection result corresponding to any indicator data is an abnormal detection result, an early warning prompt information can be generated, thereby preventing the occurrence of missed detection of abnormal request signaling and improving the accuracy of the detection result.
[0066] Example 2
[0067] As an alternative embodiment to the above embodiment, in order to make those skilled in the art further understand the technical solution of the embodiment of the present invention, a specific application scenario example is given. For details, please refer to the following specific content.
[0068] like Figure 2The diagram below can be used as a flowchart for abnormal request monitoring. For example, in an international roaming request monitoring scenario, a Diameter data request (i.e., a data acquisition request) can be obtained from the international roaming interface. Furthermore, a determination is made as to whether the Diameter data request is received from the international roaming interface. Optionally, determining whether the Diameter data request is received or sent can include obtaining the source IP address (i.e., the source protocol address) carried in the Diameter data request. If the source protocol address is not in the same network segment as the IP address of the domestic or international gateway, the request is a roaming request, i.e., the roaming type is roaming. Alternatively, a determination can be made as to whether the source protocol address is within the IP address range of the domestic or international gateway. If it is not within the IP address range of the domestic or international gateway, the request is a roaming request, i.e., the roaming type is roaming. If the data acquisition request is of the roaming type, the received data acquisition request can be evaluated based on the characteristics of international roaming. If the data acquisition request does not conform to the international roaming scenario and service logic, an alert can be issued. Specifically, the rules for monitoring abnormal requests on the international roaming interface can be as follows: (1) The consistency principle of IMSI and home HSS. For example, a roaming-type data acquisition request is a service operation request initiated to the HSS, such as canceling location registration, inserting user data, deleting user data, and restarting the device. If it is determined that the IMSI and HSS do not belong to the same country, the request is abnormal. (2) The uniqueness principle of IMSI and home HSS. For example, a roaming-type data acquisition request is a service operation request initiated to the HSS, such as canceling location registration, inserting user data, deleting user data, and restarting the device. If it is determined that the IMSI has multiple home HSSs, the request is abnormal. (3) Determine if the MME and HSS are abnormal based on the international roaming scenario. For example, in the scenario where a domestic user terminal roams from abroad to China, the domestic user's IMSI starts with 460 and the HSS starts with 86. In this case, the HSS is located in China and the MME is located abroad. Therefore, if the HSS enters China from abroad, the HSS is counterfeited for service operation requests such as canceling location registration, inserting user data, deleting user data, and restarting the device, and the request is abnormal. For operations such as user authentication, user location update, user shutdown, and user notification initiated by the MME, the request message should be received from abroad for domestic user terminals roaming. If the request message is sent from China to abroad, it does not meet the service scenario and the MME may be counterfeited, and the request is abnormal. (4) Judging the frequency of user roaming switching based on the business scenario, for example, a domestic user roams abroad, and a user frequently switches between multiple countries within a period of time (for example, 1 hour). This can be understood as the operation attribute value corresponding to the request operation code within the first preset time period being greater than the preset operation threshold, that is, the time and space judgments are not in line with reality, and it can be judged that the user is roaming abnormally, that is, the request is abnormal.(5) Abnormal business process. For example, the user terminal must first be powered on, authenticated, and updated to complete the user registration process before operations such as deregistration, inserting user data, and shutting down the user can be initiated. If there is no registration process and other operations are initiated, then the user business process is judged to be abnormal, that is, the request is abnormal. (6) Judgment based on business traffic. For example, historical network element business traffic can be counted to calculate the maximum business traffic of the network element, and the network element traffic threshold can be set to the maximum business traffic × 2. When the business traffic initiated by the MME network element or HSS network element within the time range exceeds the traffic threshold, the request is abnormal.
[0069] In order to make those skilled in the art further understand the technical solution of the embodiment of the present invention, a roaming scenario example is given. Figure 3 , which can be represented as a roaming scenario structure diagram, where the user's HSS is located in the network of their home country or home country, and the MME / SGSN is located in the user's current region. If the MME / SCSN is located in the user's home country, but not in the home country of the user's HSS, it is domestic roaming. If the MME / SCSN is not located in the user's home country, and therefore not in the home country of the user's HSS, it is international roaming. For example, if the user's IMSI is 46000XXXXXXXXXX, it indicates that the user is a domestic user, the HSS home country is country 1, and if the MME / SCSN is located abroad, it is international roaming.
[0070] Furthermore, in order to make those skilled in the art further understand the technical solution of the embodiment of the present invention, an example of a shutdown service process is given, which includes a domestic user roaming registration service process, a domestic user location acquisition service process, and a domestic user shutdown service process. Figure 4, which can be represented as a roaming registration service process diagram. For example, after a user roams from China to a foreign country, the user initiates an AIR (Authentication-Information-Request) under the new foreign MME (New_MME). The AIR carries the user's IMSI and is sent to the user's home HSS through the international port. The HSS returns an AIA (Authentication-Information-Answer) through the international port, that is, returns the user's authentication parameters to the New_MME. After the New_MME and the user terminal are authenticated, the New_MME can An ULR (Update-Location-Request) is initiated and sent to the HSS to which the user belongs through the international port. After the HSS receives the ULR from the New_MME, it returns a ULA (Update-Location-Answer) to the New_MME, sends a CLR (Cancel-Location-Request) to the old MME (Old_MME), records the new service MME information, and sends a CLA (Cancel-Location-Answer) corresponding to the successful location update to the New_MME.
[0071] Based on the above technical solution, see Figure 5 , which can be represented as a diagram of the business process for obtaining user location. For example, the domestic HSS can send an IDR (Insert-Subscriber-Data-Request) to the MME serving the target user through IDRA (international interface routing agent node). The IDR carries the user location identification parameter, that is, requests the current location of the target user. The MME receives the IDR, obtains the location of the target user, and sends an IDA (Insert-Subscriber-Data-Answer) carrying the target user's location information back to the home HSS.
[0072] Based on the above technical solution, see Figure 6 , which can be represented as a shutdown service process diagram. For example, the serving MME initiates a user PUR (Purge-UE-Request), which is sent to the affiliated HSS through the international port. The serving HSS modifies the user's status in the HSS and sends a PUA (Purge-UE-Answer) corresponding to a successful shutdown back to the serving MME through the international port.
[0073] In order to make those skilled in the art further understand the technical solutions of the embodiments of the present invention, specific application scenario examples are given, for example, see Figure 7 , which can be represented as a schematic diagram of the data processing method. Diameter protocol data acquisition requests can be obtained on the international roaming interface. These data may be offline data, online data, or XDR call records. After cleaning and processing, they are saved in the database. Furthermore, the source IP address, i.e., the source protocol address, in the data acquisition request is extracted and compared with the IP address segment or the domestic and international interface IP address range. If the source protocol address is not an IP address allowed by the domestic and international interfaces, the message is received through roaming, i.e., the roaming type is roaming-in. If it is not received through roaming, the message is sent through roaming, i.e., the roaming type is roaming-out. Messages sent through roaming are not monitored or analyzed. For messages received through roaming, key information such as the IMSI, source host address, destination host address, and operation code carried in the data acquisition request can be obtained. It can be determined whether the user's IMSI begins with the 460 field. If not, no monitoring or analysis is performed. If so, the user is a domestic user. If the user is a domestic user, the system determines whether the source host address is an HSS. If so, the system determines whether the HSS host address location code is 460. If so, an HSS impersonation alarm is issued; if not, an alarm indicating an abnormality between the user and the home HSS region is issued. If the source host address is not an HSS but an MME, the system determines whether the MME host address location code is 460. If so, an MME impersonation alarm is issued. If the MME source host address location code is not 460, the system determines whether the data acquisition request is an authentication request or a location update request. If so, the system counts the number of authentication and location updates performed by the user in different locations (countries) within a first preset time period, i.e., the operation attribute value. This is then determined based on time and space. If the value does not meet the preset operation threshold, a roaming abnormality alarm based on time and space is issued. If the data acquisition request is not an authentication request or a location update request, the system determines whether the MME has previously sent an authentication or location update procedure. If so, service is normal; if not, a service abnormality alarm is issued.
[0074] On the basis of the above technical solution, for example, see Figure 8, this technical solution can be implemented by a signaling data management module, an abnormal signaling monitoring module, and an alarm display module. Among them, the signaling data management module is used for the management of data sources. For example, offline data, online data or XDR (X Detailed Record, the lowest level detailed record) call records can be sorted and saved in a database. The indicators of XDR call record data may include the number of signaling connections, air interface time, traffic, destination or source IP, destination or source port number, number of data packets and / or application service type. Online data can be collected and analyzed to form XDR call records and saved in a database. The abnormal signaling monitoring module is used to analyze the data stored in the database according to the abnormal signaling monitoring rules, generate early warning prompt information for possible attacks, and send it to the alarm display module. The alarm display module is used to receive the early warning prompt information sent by the abnormal signaling monitoring module and display the early warning content on the console.
[0075] The technical solution of this embodiment, when receiving at least one data acquisition request and determining that the roaming type corresponding to the data acquisition request is a roaming type, obtains the data to be detected carried by the data acquisition request, and obtains the target detection results corresponding to the various indicator data by analyzing and detecting the various indicator data in the data to be detected. If the target detection result is an abnormal detection result, an early warning prompt information is generated and displayed based on the indicator item data corresponding to the target detection result. This solves the problem in the prior art of performing abnormal detection on signaling based on communication protocol specifications, resulting in poor accuracy in determining the detection results. When receiving each data acquisition request, the indicator data corresponding to at least one indicator item including the user identity identifier, the source host address, the request operation code and the network element traffic in the data acquisition request of the roaming type is analyzed and detected, which greatly enhances the detection strength. If the target detection result corresponding to any indicator data is an abnormal detection result, an early warning prompt information can be generated, thereby preventing the occurrence of missed detection of abnormal request signaling and improving the accuracy of the detection result.
[0076] Example 3
[0077] Figure 9 This is a structural block diagram of a data processing device provided by Embodiment 3 of the present invention. The device comprises: a to-be-detected data determination module 210 , a target detection result determination module 220 , and a warning prompt information generation module 230 .
[0078] Among them, the module 210 for determining the data to be detected is used to obtain the data to be detected carried by the data acquisition request when receiving at least one data acquisition request and determining that the roaming type corresponding to the data acquisition request is a roaming type; wherein the data to be detected includes at least one indicator data, and the indicator data corresponds to at least one indicator item including user identity identification, source host address, request operation code and network element traffic; the target detection result determination module 220 is used to obtain the target detection result corresponding to each indicator data by analyzing and detecting each indicator data in the data to be detected; the early warning prompt information generation module 230 is used to generate and display early warning prompt information based on the indicator item data corresponding to the target detection result if the target detection result is an abnormal detection result.
[0079] The technical solution of this embodiment, when receiving at least one data acquisition request and determining that the roaming type corresponding to the data acquisition request is a roaming type, obtains the data to be detected carried by the data acquisition request, and obtains the target detection results corresponding to the various indicator data by analyzing and detecting the various indicator data in the data to be detected. If the target detection result is an abnormal detection result, an early warning prompt information is generated and displayed based on the indicator item data corresponding to the target detection result. This solves the problem in the prior art of performing abnormal detection on signaling based on communication protocol specifications, resulting in poor accuracy in determining the detection results. When receiving each data acquisition request, the indicator data corresponding to at least one indicator item including the user identity identifier, the source host address, the request operation code and the network element traffic in the data acquisition request of the roaming type is analyzed and detected, which greatly enhances the detection strength. If the target detection result corresponding to any indicator data is an abnormal detection result, an early warning prompt information can be generated, thereby preventing the occurrence of missed detection of abnormal request signaling and improving the accuracy of the detection result.
[0080] On the basis of the above device, optionally, the to-be-detected data determining module 210 includes a source protocol address determining unit, a flooding type determining unit and a to-be-detected data determining unit.
[0081] a source protocol address determining unit, configured to, upon receiving at least one data acquisition request, acquire a source protocol address corresponding to each data acquisition request;
[0082] a roaming type determining unit, configured to determine that the roaming type of the corresponding data acquisition request is a roaming type if the source protocol address is not within a preset protocol address range;
[0083] The data to be detected determining unit is used to parse the data acquisition request to obtain the data to be detected carried by the data acquisition request.
[0084] On the basis of the above-mentioned device, optionally, the target detection result determination module 220 includes a device type determination unit and a target detection result determination first unit.
[0085] a device type determining unit, configured to determine a device type corresponding to the indicator data corresponding to the source host address if a header field in the indicator data corresponding to the user identity identifier is consistent with a preset field;
[0086] The target detection result determining unit is used to determine that the target detection result corresponding to the source host address is an abnormal detection result if the device type is a home contracted device; or, if the device type is a mobile management device, obtain the location field contained in the source host address, and if the location field is consistent with the preset field, determine that the target detection result corresponding to the source host address is an abnormal detection result.
[0087] On the basis of the above-mentioned device, optionally, the target detection result determination module 220 further includes a request operation code determination unit, an operation attribute value determination unit and a second target detection result determination unit.
[0088] a request operation code determining unit, configured to determine whether the indicator data corresponding to the request operation code is consistent with a preset operation code if the header field in the indicator data corresponding to the user identity identifier is consistent with the preset field;
[0089] an operation attribute value determining unit, configured to obtain an operation attribute value corresponding to the request operation code within a first preset time period;
[0090] The target detection result determining unit 2 is configured to determine that the target detection result corresponding to the request operation code is an abnormal detection result if the operation attribute value is greater than a preset operation threshold.
[0091] On the basis of the above device, optionally, the target detection result determination module 220 further includes a feedback data determination unit and a third target detection result determination unit.
[0092] a feedback data determining unit, configured to obtain feedback data corresponding to the preset operation code if the indicator data corresponding to the request operation code is inconsistent with the preset operation code;
[0093] The target detection result determining third unit is configured to determine that the target detection result corresponding to the request operation code is an abnormal detection result if the target feedback result in the feedback data is inconsistent with a preset feedback result.
[0094] On the basis of the above device, optionally, the target detection result determination module 220 further includes a network element traffic determination unit and a fourth target detection result determination unit.
[0095] a network element traffic determining unit, configured to determine whether the indicator data corresponding to the network element traffic within a second preset time period is greater than a preset traffic threshold if the header field in the indicator data corresponding to the user identity identifier is consistent with the preset field;
[0096] The target detection result determining fourth unit is used to determine that if yes, the target detection result corresponding to the network element traffic is an abnormal detection result.
[0097] On the basis of the above device, optionally, the warning prompt information generation module 230 includes a warning prompt information generation unit.
[0098] The early warning prompt information generation and determination unit is used to fill the indicator item data corresponding to the target detection result into the preset prompt template if the target detection result is an abnormal detection result, generate early warning prompt information, and send the early warning prompt information to the monitoring page for display, so that the target user can determine the network maintenance method based on the indicator item data in the early warning prompt information.
[0099] The data processing device provided by the embodiment of the present invention can execute the data processing method provided by any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the execution method.
[0100] It is worth noting that the various units and modules included in the above-mentioned device are only divided according to functional logic, but are not limited to the above-mentioned division, as long as the corresponding functions can be achieved; in addition, the specific names of the functional units are only for the convenience of distinguishing each other, and are not used to limit the scope of protection of the embodiments of the present invention.
[0101] Example 4
[0102] Figure 10 This is a structural diagram of an electronic device provided in Example 4 of the present invention. Figure 10 A block diagram of an exemplary electronic device 30 suitable for implementing exemplary embodiments of the present invention is shown. Figure 10 The electronic device 30 shown is only an example and should not limit the functionality and scope of use of the embodiments of the present invention.
[0103] like Figure 10 As shown, electronic device 30 is a general-purpose computing device. Components of electronic device 30 may include, but are not limited to, one or more processors or processing units 301, system memory 302, and a bus 303 connecting various system components (including system memory 302 and processing unit 301).
[0104] Bus 303 represents one or more of several types of bus structures, including a memory bus or memory controller, a peripheral bus, an accelerated graphics port, a processor, or a local bus using any of a variety of bus architectures. Examples of these architectures include, but are not limited to, the Industry Standard Architecture (ISA) bus, the Micro Channel Architecture (MAC) bus, the Enhanced ISA bus, the Video Electronics Standards Association (VESA) local bus, and the Peripheral Component Interconnect (PCI) bus.
[0105] The electronic device 30 typically includes a variety of computer system readable media. These media can be any available media that can be accessed by the electronic device 30, including volatile and non-volatile media, removable and non-removable media.
[0106] System memory 302 may include computer system readable media in the form of volatile memory, such as random access memory (RAM) 304 and / or cache memory 305. Electronic device 30 may further include other removable / non-removable, volatile / non-volatile computer system storage media. By way of example only, storage system 306 may be used to read and write non-removable, non-volatile magnetic media ( Figure 10 Not shown, often called a "hard drive"). Although Figure 10 Not shown, a disk drive for reading and writing to a removable non-volatile disk (e.g., a "floppy disk"), and an optical disk drive for reading and writing to a removable non-volatile optical disk (e.g., a CD-ROM, DVD-ROM, or other optical media) may be provided. In these cases, each drive may be connected to bus 303 via one or more data medium interfaces. Memory 302 may include at least one program product having a set (e.g., at least one) of program modules configured to perform the functions of various embodiments of the present invention.
[0107] A program / utility 308 having a set (at least one) of program modules 307 may be stored, for example, in memory 302. Such program modules 307 include, but are not limited to, an operating system, one or more application programs, other program modules, and program data, each of which, or some combination thereof, may include an implementation of a network environment. Program modules 307 generally implement the functions and / or methods of the embodiments described herein.
[0108] The electronic device 30 may also communicate with one or more external devices 309 (e.g., keyboard, pointing device, display 310, etc.), and may also communicate with one or more devices that enable a user to interact with the electronic device 30, and / or any device that enables the electronic device 30 to communicate with one or more other computing devices (e.g., network card, modem, etc.). Such communication may be performed through an input / output (I / O) interface 311. Furthermore, the electronic device 30 may also communicate with one or more networks (e.g., a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) through a network adapter 312. As shown, the network adapter 312 communicates with other modules of the electronic device 30 via the bus 303. It should be understood that although Figure 10 Not shown, other hardware and / or software modules may be used in conjunction with the electronic device 30, including but not limited to microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.
[0109] The processing unit 301 executes various functional applications and data processing by running programs stored in the system memory 302, such as implementing the data processing method provided by the embodiment of the present invention.
[0110] Example 5
[0111] A fifth embodiment of the present invention further provides a storage medium containing computer-executable instructions, wherein the computer-executable instructions, when executed by a computer processor, are used to perform a data processing method. The method includes:
[0112] Upon receiving at least one data acquisition request and determining that the roaming type corresponding to the data acquisition request is an incoming roaming type, acquiring the data to be detected carried by the data acquisition request; wherein the data to be detected includes at least one indicator data item corresponding to at least one indicator item including a user identity identifier, a source host address, a request operation code, and a network element traffic;
[0113] By analyzing and testing the various indicator data in the data to be tested, the target detection results corresponding to the various indicator data are obtained;
[0114] If the target detection result is an abnormal detection result, a warning prompt message is generated and displayed based on the indicator item data corresponding to the target detection result.
[0115] The computer storage medium of the embodiment of the present invention may adopt any combination of one or more computer-readable media. The computer-readable medium may be a computer-readable signal medium or a computer-readable storage medium. The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or component, or any combination thereof. More specific examples (a non-exhaustive list) of computer-readable storage media include: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In this document, a computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in combination with an instruction execution system, device or device.
[0116] A computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, which carries computer-readable program code. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium that can transmit, propagate, or transport a program for use by or in conjunction with an instruction execution system, apparatus, or device.
[0117] Program code embodied on a computer readable medium may be transmitted using any appropriate medium, including but not limited to wireless, wireline, optical fiber cable, RF, etc., or any suitable combination of the foregoing.
[0118] The computer program code for performing the operations of the embodiments of the present invention can be written in one or more programming languages or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, C++, and conventional procedural programming languages such as "C" or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a separate software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving a remote computer, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0119] Note that the above are only preferred embodiments of the present invention and the technical principles employed. Those skilled in the art will understand that the present invention is not limited to the specific embodiments described herein, and that various obvious changes, readjustments, and substitutions can be made by those skilled in the art without departing from the scope of protection of the present invention. Therefore, although the present invention has been described in detail through the above embodiments, the present invention is not limited to the above embodiments and may include many other equivalent embodiments without departing from the concept of the present invention. The scope of the present invention is determined by the scope of the appended claims.
Claims
1. A data processing method, characterized in that: include: Upon receiving at least one data acquisition request and determining that the roaming type corresponding to the data acquisition request is an incoming roaming type, acquiring the data to be detected carried by the data acquisition request; wherein the data to be detected includes at least one indicator data item corresponding to at least one indicator item including a user identity identifier, a source host address, a request operation code, and a network element traffic; By analyzing and testing the various indicator data in the data to be tested, the target detection results corresponding to the various indicator data are obtained; If the target detection result is an abnormal detection result, generating and displaying early warning information based on the indicator item data corresponding to the target detection result; The step of receiving at least one data acquisition request and determining that the roaming type corresponding to the data acquisition request is an incoming roaming type, acquiring the data to be detected carried by the data acquisition request, includes: Upon receiving at least one data acquisition request, obtaining a source protocol address corresponding to each data acquisition request; If the source protocol address is not within the preset protocol address range, determining that the roaming type of the corresponding data acquisition request is a roaming type; Parsing the data acquisition request to obtain the data to be detected carried by the data acquisition request; The target detection results corresponding to the various indicator data are obtained by analyzing and detecting the various indicator data in the data to be detected, including: If the header field in the indicator data corresponding to the user identity identifier is consistent with the preset field, determining the device type corresponding to the indicator data corresponding to the source host address; If the device type is a home contracted device, determining that the target detection result corresponding to the source host address is an abnormal detection result; or, If the device type is a mobile management device, the location field contained in the source host address is obtained, and if the location field is consistent with the preset field, it is determined that the target detection result corresponding to the source host address is an abnormal detection result.
2. The method according to claim 1, characterized in that The method of analyzing and detecting each indicator data in the data to be detected to obtain target detection results corresponding to each indicator data further includes: If the header field in the indicator data corresponding to the user identity identifier is consistent with the preset field, determining whether the indicator data corresponding to the request operation code is consistent with the preset operation code; If yes, obtaining the operation attribute value corresponding to the request operation code within the first preset time period; If the operation attribute value is greater than a preset operation threshold, it is determined that the target detection result corresponding to the request operation code is an abnormal detection result.
3. The method according to claim 2, characterized in that Also includes: If the indicator data corresponding to the request operation code is inconsistent with the preset operation code, obtaining feedback data corresponding to the preset operation code; If the target feedback result in the feedback data is inconsistent with the preset feedback result, it is determined that the target detection result corresponding to the request operation code is an abnormal detection result.
4. The method according to claim 1, wherein The method of analyzing and detecting each indicator data in the data to be detected to obtain target detection results corresponding to each indicator data further includes: If the header field in the indicator data corresponding to the user identity identifier is consistent with the preset field, determining whether the indicator data corresponding to the network element traffic within the second preset time period is greater than a preset traffic threshold; If so, it is determined that the target detection result corresponding to the network element traffic is an abnormal detection result.
5. The method according to claim 1, wherein If the target detection result is an abnormal detection result, generating and displaying early warning information based on the indicator item data corresponding to the target detection result includes: If the target detection result is an abnormal detection result, the indicator item data corresponding to the target detection result is filled into the preset prompt template to generate early warning prompt information, and the early warning prompt information is sent to the monitoring page for display, so that the target user can determine the network maintenance method based on the indicator item data in the early warning prompt information.
6. A data processing device, characterized in that: include: a data to be detected determining module, configured to, upon receiving at least one data acquisition request and determining that the roaming type corresponding to the data acquisition request is an incoming roaming type, acquire the data to be detected carried by the data acquisition request; wherein the data to be detected includes at least one indicator data item corresponding to at least one indicator item including a user identity identifier, a source host address, a request operation code, and a network element traffic; The target detection result determination module is used to obtain the target detection result corresponding to each indicator data by analyzing and detecting each indicator data in the data to be detected; A warning prompt information generation module is used to generate and display warning prompt information based on the indicator item data corresponding to the target detection result if the target detection result is an abnormal detection result; The module for determining data to be detected includes a source protocol address determining unit, an influx type determining unit and a unit for determining data to be detected; a source protocol address determining unit, configured to, upon receiving at least one data acquisition request, acquire a source protocol address corresponding to each data acquisition request; a roaming type determining unit, configured to determine that the roaming type of the corresponding data acquisition request is a roaming type if the source protocol address is not within a preset protocol address range; a data-to-be-detected determining unit, configured to parse the data acquisition request to obtain the data-to-be-detected carried in the data acquisition request; The target detection result determination module includes a device type determination unit and a target detection result determination first unit; a device type determining unit, configured to determine a device type corresponding to the indicator data corresponding to the source host address if a header field in the indicator data corresponding to the user identity identifier is consistent with a preset field; The target detection result determining unit is used to determine that the target detection result corresponding to the source host address is an abnormal detection result if the device type is a home contracted device; or, if the device type is a mobile management device, obtain the location field contained in the source host address, and if the location field is consistent with the preset field, determine that the target detection result corresponding to the source host address is an abnormal detection result.
7. An electronic device, characterized in that: The device comprises: one or more processors; a storage device for storing one or more programs, When the one or more programs are executed by the one or more processors, the one or more processors implement the data processing method according to any one of claims 1 to 5.
8. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the data processing method according to any one of claims 1 to 5 is implemented.
Citation Information
Patent Citations
Signaling attack preventing method and device thereof
CN107800664A