Local data monitoring method, device, equipment and storage medium for 5G base station
By copying and sending local service data in the 5G base station to the DMZ monitoring device for detection, and aborting the session link when illegal information is discovered, the problems of low efficiency and security risks of local data monitoring in 5G base stations are solved, and efficient data monitoring and security management are achieved.
Patent Information
- Application Number
- CN202210806620.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-07-08
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2042-07-08
AI Technical Summary
The existing technology cannot effectively monitor the local data of 5G base stations, resulting in the data being unable to be reasonably controlled and poses security risks.
The 5G base station receives local service data transmitted between the user terminal and the MEC edge cloud, copy and sends it to the monitoring device set by the DMZ. The monitoring device detects the data illegal information. If illegal information is found, it sends a session link abort instruction to the 5G base station to abort the corresponding session link.
It realizes effective monitoring of local service data of 5G base stations, improves data security and management efficiency, and avoids security risks in data transmission.
Smart Images

Figure CN115278938B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of communication technologies, and particularly relates to a method, device, equipment, and storage medium for local data monitoring of a 5G base station. Background Art
[0002] In the 5G base station traffic splitting technology, the base station can identify local services based on traffic splitting strategies, such as through IP quintuples, slice IDs, DNS (Domain Name System for short), etc., and split local services to local service servers. Figure 1 As a schematic diagram of the existing network architecture based on 5G base station traffic splitting, the base station splits local data to the local MEC (Mobile Edge Computing) edge cloud, and sends the data transmitted to the public network through the UPF (User Plane Function) to the Internet. There is an existing legal monitoring device in the DMZ (Demilitarized Zone) passed through to monitor the data transmitted to the public network. In this existing network based on 5G base station traffic splitting, local data will be directly unloaded locally, resulting in the inability to reasonably control this part of the data and there are certain security risks. Summary of the Invention
[0003] The purpose of the present invention is to provide a method, device, equipment, and storage medium for local data monitoring of a 5G base station, aiming to solve the problem that due to the inability of the existing technology to provide an effective method for local data monitoring of a 5G base station, local data monitoring cannot be effectively monitored.
[0004] On the one hand, the present invention provides a method for local data monitoring of a 5G base station, and the method includes:
[0005] Receiving local service data transmitted between a user terminal and an MEC edge cloud, and replicating the local service data;
[0006] Sending the replicated local service data to a monitoring device set in the DMZ, so that the monitoring device detects whether there is illegal information in the local service data;
[0007] If it is detected that there is illegal information in the local service data, aborting the corresponding session link of the local service data between the user terminal and the MEC edge cloud.
[0008] On the other hand, the present invention provides a method for local data monitoring of a 5G communication system, and the method includes:
[0009] The 5G base station receives the local service data transmitted between the user terminal and the MEC edge cloud, replicates the local service data, and sends the replicated local service data to the monitoring device set in the DMZ;
[0010] The monitoring device detects whether there is illegal information in the local service data. If it detects that there is illegal information in the local service data, it sends a session link termination instruction to the 5G base station;
[0011] The 5G base station terminates the corresponding session link of the local service data according to the session link termination instruction.
[0012] On the other hand, the present invention provides a local data monitoring device for a 5G base station, and the device includes:
[0013] A data replication unit, configured to receive the local service data transmitted between the user terminal and the MEC edge cloud and replicate the local service data;
[0014] A first data sending unit, configured to send the replicated local service data to the monitoring device set in the DMZ, so that the monitoring device detects whether there is illegal information in the local service data; and
[0015] A first link termination unit, configured to terminate the corresponding session link of the local service data between the user terminal and the MEC edge cloud if it detects that there is illegal information in the local service data.
[0016] On the other hand, the present invention provides a local data monitoring device for a 5G communication system, and the device includes:
[0017] A second data sending unit, configured to receive the local service data transmitted between the user terminal and the MEC edge cloud by the 5G base station, replicate the local service data, and send the replicated local service data to the monitoring device set in the DMZ;
[0018] An instruction sending unit, configured to detect whether there is illegal information in the local service data by the monitoring device. If it detects that there is illegal information in the local service data, it sends a session link termination instruction to the 5G base station; and
[0019] A second link termination unit, configured to terminate the corresponding session link of the local service data by the 5G base station according to the session link termination instruction.
[0020] On the other hand, the present invention also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps of the above-described method are implemented.
[0021] On the other hand, the present invention also provides a computer-readable storage medium storing a computer program, and when the computer program is executed by a processor, the steps of the above-described method are implemented.
[0022] When the present invention receives local service data transmitted between a user terminal and an MEC edge cloud, it copies the local service data and sends the copied local service data to a listening device set in the DMZ, so that the listening device can detect whether there is illegal information in the local service data. If illegal information is detected in the local service data, the corresponding session link of the local service data between the user terminal and the MEC edge cloud is aborted, thereby realizing the monitoring of the local service data transmitted between the user terminal and the MEC edge cloud based on a 5G base station, and improving the monitoring efficiency of the local service data. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] Figure 1 is a schematic diagram of an existing network architecture based on 5G base station traffic splitting;
[0024] Figure 2 is a flowchart of the implementation of the local data monitoring method for a 5G base station provided in Embodiment 1 of the present invention;
[0025] Figure 3 is a flowchart of the implementation of the local data monitoring method for a 5G communication system provided in Embodiment 2 of the present invention;
[0026] Figure 4 is a schematic diagram of the structure of the local data monitoring device for a 5G base station provided in Embodiment 3 of the present invention;
[0027] Figure 5 is a schematic diagram of the structure of the local data monitoring device for a 5G communication system provided in Embodiment 4 of the present invention; and
[0028] Figure 6 is a schematic diagram of the structure of the electronic device provided in Embodiment 6 of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0029] In order to make the objectives, technical solutions and advantages of the present invention clearer, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention, and are not used to limit the present invention.
[0030] The specific implementation of the present invention will be described in detail in combination with specific embodiments as follows:
[0031] Example 1:
[0032] Figure 2 The implementation process of the local data monitoring method for a 5G base station provided in Embodiment 1 of the present invention is shown. For the sake of convenience of description, only the parts related to the embodiments of the present invention are shown and are described in detail as follows:
[0033] In step S201, receive the local service data transmitted between the user terminal and the MEC edge cloud, and copy the local service data;
[0034] The embodiments of the present invention are applicable to 5G base stations to monitor the service data sent by user terminals (UEs). After the 5G base station receives the local service data transmitted between the user terminal and the MEC edge cloud, it copies the local service data to obtain the copied local service data. Among them, the local service data transmitted between the user terminal and the MEC edge cloud can be the local service data sent by the user terminal to the MEC edge cloud, or the local service data sent by the MEC edge cloud to the user terminal. The MEC edge cloud is used to store local service data to improve the operation efficiency of the communication network and enhance the service distribution and transmission capabilities.
[0035] In a preferred embodiment, when receiving the local service data transmitted between the user terminal and the MEC edge cloud and copying the local service data, receive the terminal service data sending request of the user terminal, and determine whether the terminal service data is local service data or public network service data (for example, service data for accessing the Internet) according to the destination identification number in the terminal service data sending request. If it is determined that the terminal service data is local service data, send the terminal service data to the MEC edge cloud and copy the terminal service data, so as to copy the local service data sent by the user terminal to the MEC edge cloud while splitting the service data at the base station, providing a basis for subsequent monitoring of local service data. Among them, the destination identification number can be an IP five-tuple, a slice ID, a DNS, etc., for determining whether the terminal service data is local service data.
[0036] In another preferred embodiment, when receiving the local service data transmitted between the user terminal and the MEC edge cloud and copying the local service data, receive the local service data transmitted by the MEC edge cloud to the user terminal, send the local service data to the user terminal, and copy the local service data, so as to copy the local service data sent by the MEC edge cloud to the user terminal when the base station receives downlink service data, providing a basis for subsequent monitoring of local service data.
[0037] In step S202, the locally copied service data is sent to the monitoring device set in the DMZ so that the monitoring device can detect whether there is illegal information in the locally copied service data.
[0038] In the embodiment of the present invention, a monitoring device is set in the DMZ to ensure the security of the DMZ and the intranet data. After the 5G base station copies the locally copied service data, it sends it to the monitoring device set in the DMZ so that the monitoring device can detect whether there is illegal information in the locally copied service data, so that the monitoring device in the DMZ can uniformly monitor the locally copied service data and the public network service data. The illegal information can be harmful information such as porn, gambling, and drugs, or can be set according to the specific MEC edge cloud application scenario to achieve differentiated monitoring and improve the monitoring efficiency. Specifically, the 5G base station will be assigned an intranet IP address in the communication network. The monitoring device in the DMZ belongs to a public network device and will be assigned a public network IP address. When the base station forwards the locally copied service data to the monitoring device in the DMZ, it needs to go through internal IP conversion mapping in the base station before it can be forwarded to the monitoring device in the DMZ.
[0039] In step S203, if it is detected that there is illegal information in the locally copied service data, the corresponding session link of the locally copied service data between the user terminal and the MEC edge cloud is aborted.
[0040] In the embodiment of the present invention, if the monitoring device detects that there is illegal information in the locally copied service data, the 5G base station aborts the corresponding session link of the locally copied service data between the user terminal and the MEC edge cloud, thereby releasing the corresponding user terminal bearer and ensuring the data security of the user terminal and the security of the communication system where the 5G base station is located.
[0041] In one embodiment, if the monitoring device detects that there is illegal information in the locally copied service data, it sends a message indicating that illegal information has been detected in the locally copied service data to the 5G base station. At this time, the 5G base station aborts the corresponding session link of the locally copied service data between the user terminal and the MEC edge cloud, so that the 5G base station actively aborts the corresponding session link of the locally copied service data between the user terminal and the MEC edge cloud.
[0042] In another embodiment, if the monitoring device detects that there is illegal information in the locally copied service data, it sends a corresponding session link abort instruction to the 5G base station. When the 5G base station receives the corresponding session link abort instruction sent by the monitoring device, the 5G base station aborts the corresponding session link of the locally copied service data between the user terminal and the MEC edge cloud according to the session link abort instruction.
[0043] Specifically, when the base station receives a message indicating that illegal information exists in the local service data or a corresponding session link termination instruction, the base station maps the address information in the message or instruction fed back by the monitoring device in the DMZ to the user information connected to the base station, ensuring that a specific user and even the data session link of a specific user can be corresponded inside the base station, so as to accurately terminate the corresponding session link of the local service data between the user terminal and the MEC edge cloud.
[0044] In the embodiment of the present invention, when receiving the local service data transmitted between the user terminal and the MEC edge cloud, the local service data is copied, and the copied local service data is sent to the monitoring device set in the DMZ, so that the monitoring device can detect whether there is illegal information in the local service data. If it is detected that there is illegal information in the local service data, the corresponding session link of the local service data between the user terminal and the MEC edge cloud is terminated, thereby realizing the monitoring of the local service data transmitted between the user terminal and the MEC edge cloud based on the 5G base station, and improving the monitoring efficiency of the local service data.
[0045] Example 2:
[0046] Figure 3 The implementation process of the local data monitoring method of the 5G communication system provided by the second embodiment of the present invention is shown. For the sake of convenience of description, only the parts related to the embodiment of the present invention are shown and are described in detail as follows:
[0047] In step S301, the 5G base station receives the local service data transmitted between the user terminal and the MEC edge cloud, copies the local service data, and sends the copied local service data to the monitoring device set in the DMZ;
[0048] The embodiment of the present invention is applicable to a 5G communication system, which includes a 5G base station, an MEC edge cloud, and a monitoring device set in the DMZ to monitor the service data sent by a user terminal (UE). After receiving the local service data transmitted between the user terminal and the MEC edge cloud, the 5G base station copies the local service data to obtain the copied local service data, and sends the copied local service data to the monitoring device set in the DMZ, so that the monitoring device in the DMZ can uniformly monitor the local service data and the public network service data. Among them, the local service data transmitted between the user terminal and the MEC edge cloud can be the local service data sent by the user terminal to the MEC edge cloud, or the local service data sent by the MEC edge cloud to the user terminal. The MEC edge cloud is used to store the local service data to improve the operation efficiency of the communication network and enhance the service distribution and transmission capabilities.
[0049] In one embodiment, the 5G base station receives a terminal service data transmission request from a user terminal, and determines whether the terminal service data is local service data or public network service data (e.g., service data for accessing the Internet) according to the destination identification number in the terminal service data transmission request. If it is determined that the terminal service data is local service data, the 5G base station sends the terminal service data to the MEC edge cloud, copies the terminal service data, and sends the copied local service data to the monitoring device set in the DMZ. Thus, while the base station shunts the service data, it copies the local service data sent to the MEC edge cloud and sends it to the monitoring device, providing a basis for subsequent monitoring of local service data. The destination identification number can be an IP five-tuple, a slice ID, a DNS, etc., for determining whether the terminal service data is local service data.
[0050] In another preferred embodiment, the 5G base station receives local service data transmitted from the MEC edge cloud to the user terminal, sends the local service data to the user terminal, copies the local service data, and sends the copied local service data to the monitoring device set in the DMZ. Thus, when the base station receives downlink service data, it copies the local service data sent from the MEC edge cloud to the user terminal and sends it to the monitoring device set in the DMZ, providing a basis for subsequent monitoring of local service data.
[0051] In step S302, the monitoring device detects whether there is illegal information in the local service data. If it detects that there is illegal information in the local service data, it sends a session link termination instruction to the 5G base station;
[0052] In the embodiment of the present invention, a monitoring device is set in the DMZ to ensure the security of the DMZ and the internal network data. After receiving the copied local service data, the monitoring device detects whether there is illegal information in the local service data. If the monitoring device detects that there is illegal information in the local service data, it sends a session link termination instruction to the 5G base station. The illegal information can be harmful information such as porn, gambling, and drugs, or can be set according to the specific MEC edge cloud application scenario to achieve differentiated monitoring and improve the monitoring efficiency.
[0053] In step S303, the 5G base station terminates the corresponding session link of the local service data according to the session link termination instruction.
[0054] In the embodiment of the present invention, after receiving the session link termination instruction sent by the monitoring device, the 5G base station terminates the corresponding session link of the local service data according to the session link termination instruction, thereby releasing the corresponding user terminal bearer and ensuring the data security of the user terminal and the security of the communication system where the 5G base station is located.
[0055] After receiving the local service data transmitted between the user terminal and the MEC edge cloud in the 5G communication system according to an embodiment of the present invention, the 5G base station replicates the local service data, and sends the replicated local service data to the monitoring device set in the DMZ. The monitoring device detects whether there is illegal information in the local service data. If it detects that there is illegal information in the local service data, it sends a session link termination instruction to the 5G base station. The 5G base station terminates the corresponding session link of the local service data between the user terminal and the MEC edge cloud according to the session link termination instruction, thereby realizing the monitoring of the local service data transmitted between the user terminal and the MEC edge cloud based on the 5G base station, and improving the monitoring efficiency of the local service data.
[0056] Example 3:
[0057] Figure 4 The structure of the local data monitoring device of the 5G base station provided in Embodiment 3 of the present invention is shown. For the sake of convenience of description, only the parts related to the embodiments of the present invention are shown, including:
[0058] A data replication unit 41, configured to receive the local service data transmitted between the user terminal and the MEC edge cloud, and replicate the local service data;
[0059] A first data sending unit 42, configured to send the replicated local service data to the monitoring device set in the DMZ, so that the monitoring device detects whether there is illegal information in the local service data; and
[0060] A first link termination unit 43, configured to terminate the corresponding session link of the local service data between the user terminal and the MEC edge cloud if it is detected that there is illegal information in the local service data.
[0061] In one embodiment, the data replication unit 41 includes:
[0062] A service determination unit, configured to receive the terminal service data sending request of the user terminal, and determine whether the terminal service data is local service data according to the destination identification number in the terminal service data sending request; and
[0063] A data replication subunit, configured to send the terminal service data to the MEC edge cloud and replicate the terminal service data if it is determined that the terminal service data is local service data.
[0064] In another embodiment, the data replication unit 41 includes:
[0065] A data transmission unit, configured to receive the local service data transmitted by the MEC edge cloud to the user terminal; and
[0066] A data processing unit, configured to send the local service data to the user terminal and copy the local service data.
[0067] In one embodiment, the first link suspension unit 43 includes:
[0068] A first suspension subunit, configured to suspend the corresponding session link of the local service data between the user terminal and the MEC edge cloud if a message indicating that the local service data has illegal information is received; or
[0069] A second suspension subunit, configured to suspend the corresponding session link of the local service data between the user terminal and the MEC edge cloud if a corresponding session link suspension instruction sent by the monitoring device is received.
[0070] In the embodiments of the present invention, each unit of the local data monitoring device may be implemented by corresponding hardware or software units. Each unit may be an independent software or hardware unit, or may be integrated into a software or hardware unit, which is not used to limit the present invention here. The specific implementation manners of each unit may refer to the description of Embodiment 1 and will not be elaborated here.
[0071] Example 4:
[0072] Figure 5 The structure of the local data monitoring device of the 5G communication system provided in Embodiment 4 of the present invention is shown. For the sake of convenience of description, only the parts related to the embodiments of the present invention are shown, including:
[0073] A second data sending unit 51, configured to receive the local service data transmitted between the user terminal and the MEC edge cloud by the 5G base station, copy the local service data, and send the copied local service data to the monitoring device set in the DMZ;
[0074] An instruction sending unit 52, configured to detect whether the local service data has illegal information by the monitoring device, and send a session link suspension instruction to the 5G base station if it is detected that the local service data has illegal information; and
[0075] A second link suspension unit 53, configured to suspend the corresponding session link of the local service data by the 5G base station according to the session link suspension instruction.
[0076] In the embodiments of the present invention, each unit of the local data monitoring device may be implemented by corresponding hardware or software units. Each unit may be an independent software or hardware unit, or may be integrated into a software or hardware unit, which is not used to limit the present invention here. The specific implementation manners of each unit may refer to the description of Embodiment 2 and will not be elaborated here.
[0077] Example 5:
[0078] Figure 6 The structure of the electronic device provided in the fifth embodiment of the present invention is shown. For the sake of convenience of description, only the parts related to the embodiments of the present invention are shown.
[0079] The electronic device 6 in the embodiment of the present invention includes a processor 60, a memory 61, and a computer program 62 stored in the memory 61 and executable on the processor 60. When the processor 60 executes the computer program 62, the steps in the above-mentioned embodiments of each local data monitoring method are implemented, for example Figure 2 The steps S201 to S203 shown. Alternatively, when the processor 60 executes the computer program 62, the functions of each unit in the above-mentioned device embodiments are implemented, for example Figure 4 The functions of the units 41 to 43 shown.
[0080] After receiving the local service data transmitted between the user terminal and the MEC edge cloud, the 5G base station in the embodiment of the present invention replicates the local service data, and sends the replicated local service data to the monitoring device set in the DMZ, so that the monitoring device detects whether there is illegal information in the local service data. If illegal information is detected in the local service data, the corresponding session link of the local service data between the user terminal and the MEC edge cloud is aborted, thereby realizing the monitoring of the local service data transmitted between the user terminal and the MEC edge cloud based on the 5G base station, and improving the monitoring efficiency of the local service data.
[0081] The steps implemented when the processor 60 in the electronic device 6 executes the computer program 62 to implement the local data monitoring method can refer to the description of the foregoing method embodiments, and will not be elaborated here.
[0082] Example 6:
[0083] In the embodiment of the present invention, a computer-readable storage medium is provided. The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps in the above-mentioned embodiments of the local data monitoring method are implemented, for example, Figure 2 The steps S201 to S203 shown. Alternatively, when the computer program is executed by a processor, the functions of each unit in the above-mentioned device embodiments are implemented, for example Figure 4 The functions of the units 41 to 43 shown.
[0084] After receiving the local service data transmitted between the user terminal and the MEC edge cloud, the 5G base station according to an embodiment of the present invention replicates the local service data, and sends the replicated local service data to the monitoring device set in the DMZ, so that the monitoring device can detect whether there is illegal information in the local service data. If illegal information is detected in the local service data, the corresponding session link of the local service data between the user terminal and the MEC edge cloud is aborted, thereby realizing the monitoring of the local service data transmitted between the user terminal and the MEC edge cloud based on the 5G base station, and improving the monitoring efficiency of the local service data.
[0085] The computer-readable storage medium according to an embodiment of the present invention may include any entity or device, recording medium that can carry computer program code, for example, memories such as ROM / RAM, magnetic disks, optical disks, flash memories, etc.
[0086] The above are only the preferred embodiments of the present invention, and are not intended to limit the present invention. Any modifications, equivalent replacements, and improvements made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.
Claims
1. A method for local data monitoring of a 5G base station, characterized in that, The method includes: Receiving local service data transmitted between a user terminal and an MEC edge cloud, and replicating the local service data; Sending the replicated local service data to a monitoring device set in the DMZ after internal IP conversion mapping within the base station, so that the monitoring device detects whether there is illegal information in the local service data; If it is detected that there is illegal information in the local service data, then the address information in the message or instruction fed back by the monitoring device set in the DMZ is inverse-mapped with the user information connected to the base station, and the corresponding session link of the local service data between the user terminal and the MEC edge cloud is obtained and aborted, including: If a message indicating that there is illegal information in the local service data is received, then the corresponding session link of the local service data between the user terminal and the MEC edge cloud is aborted; If a corresponding session link abort instruction sent by the monitoring device is received, then the corresponding session link of the local service data between the user terminal and the MEC edge cloud is aborted.
2. The method according to claim 1, wherein The steps of receiving local service data transmitted between a user terminal and an MEC edge cloud and replicating the local service data include: Receiving a terminal service data sending request of the user terminal, and determining whether the terminal service data is local service data according to the destination identification number in the terminal service data sending request; If it is determined that the terminal service data is local service data, sending the terminal service data to the MEC edge cloud and replicating the terminal service data.
3. The method according to claim 1, wherein The steps of receiving local service data transmitted between a user terminal and an MEC edge cloud and replicating the local service data include: Receiving the local service data transmitted by the MEC edge cloud to the user terminal; Sending the local service data to the user terminal and replicating the local service data.
4. A method for local data monitoring in a 5G communication system, characterized in that, The method includes: A 5G base station receives local service data transmitted between a user terminal and an MEC edge cloud, replicates the local service data, and sends the replicated local service data to a monitoring device set in the DMZ after internal IP conversion mapping within the base station; The monitoring device detects whether there is illegal information in the local service data. If it is detected that there is illegal information in the local service data, then the address information in the message or instruction fed back by the monitoring device set in the DMZ is inverse-mapped with the user information connected to the base station, and a session link abort instruction is sent to the 5G base station; The 5G base station aborts the corresponding session link of the local service data according to the session link abort instruction, including: If a message indicating that there is illegal information in the local service data is received, then the corresponding session link of the local service data between the user terminal and the MEC edge cloud is aborted; If a corresponding session link abort instruction sent by the monitoring device is received, then the corresponding session link of the local service data between the user terminal and the MEC edge cloud is aborted.
5. A local data monitoring device for a 5G base station, characterized in that, The device includes: A data replication unit, configured to receive local service data transmitted between a user terminal and an MEC edge cloud, and replicate the local service data; A first data sending unit, configured to send the replicated local service data to a monitoring device set in the DMZ after internal IP conversion mapping in the base station, so that the monitoring device detects whether there is illegal information in the local service data; and A first link termination unit, configured to, if it is detected that there is illegal information in the local service data, perform inverse mapping on the address information in the message or instruction fed back by the monitoring device set in the DMZ and the user information connected to the base station, and obtain and terminate the corresponding session link of the local service data between the user terminal and the MEC edge cloud, including: If a message indicating that there is illegal information in the local service data is received, terminate the corresponding session link of the local service data between the user terminal and the MEC edge cloud; If a corresponding session link termination instruction sent by the monitoring device is received, terminate the corresponding session link of the local service data between the user terminal and the MEC edge cloud.
6. The device according to claim 5, characterized in that, The data replication unit includes: A service determination unit, configured to receive a terminal service data sending request of the user terminal, and determine whether the terminal service data is local service data according to the destination identification number in the terminal service data sending request; and A data replication subunit, configured to, if it is determined that the terminal service data is local service data, send the terminal service data to the MEC edge cloud and replicate the terminal service data.
7. A local data monitoring device for a 5G communication system, characterized in that, The device includes: A second data sending unit, configured to receive local service data transmitted between a user terminal and an MEC edge cloud by a 5G base station, replicate the local service data, and send the replicated local service data to a monitoring device set in the DMZ after internal IP conversion mapping in the base station; An instruction sending unit, configured to detect whether there is illegal information in the local service data by the monitoring device, and if it is detected that there is illegal information in the local service data, perform inverse mapping on the address information in the message or instruction fed back by the monitoring device set in the DMZ and the user information connected to the base station, and send a session link termination instruction to the 5G base station; and A second link termination unit, configured to terminate the corresponding session link of the local service data by the 5G base station according to the session link termination instruction, including: If a message indicating that there is illegal information in the local service data is received, terminate the corresponding session link of the local service data between the user terminal and the MEC edge cloud; If a corresponding session link termination instruction sent by the monitoring device is received, terminate the corresponding session link of the local service data between the user terminal and the MEC edge cloud.
8. An electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, the steps of the method according to any one of claims 1 to 4 are implemented.
9. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, the steps of the method according to any one of claims 1 to 4 are implemented.
Citation Information
Patent Citations
Network security protection method, network element device, system and computer storage medium
CN109428881A
Monitoring method and network equipment
CN111490962A