A blockchain-assisted data eagle-eye network function
By introducing blockchain-assisted data eagle-eye network functions into the network, monitoring and recording the traffic of network devices, and using hash value comparison to detect malicious behavior, the problem of lack of high-reliability detection methods in existing technologies is solved, and effective monitoring of network devices and restoration of trust are achieved.
Patent Information
- Application Number
- CN202211073216.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-09-02
- Publication Date
- 2025-09-16
- Estimated Expiration
- 2042-09-02
AI Technical Summary
Existing technologies are difficult to efficiently and reliably detect whether network devices have malicious behavior, and lack high-reliability methods, which leads to the destruction of the trust triangle.
The blockchain-assisted Data Eagle Eye network function is introduced to monitor the traffic of gateway devices and store their records on the blockchain. The hash values of incoming and outgoing data packets are used for consistency comparison to detect malicious behavior of network devices.
A high-credibility digital forensics model has been established that can effectively detect malicious behavior of network devices, restore trust between equipment manufacturers and service providers, and promote in-depth cooperation among the three parties.
Smart Images

Figure CN115412922B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of wireless communication technologies, and in particular to a blockchain-assisted data eagle eye network function. Background Art
[0002] Trust is considered the cornerstone of information and communications technology (ICT) infrastructure. The next generation of mobile communication networks is envisioned to provide embedded trust, not just simple connectivity and transmission. Currently, ICT is evolving into a multi-sided platform with complex interactions. Establishing trust between these diverse groups presents unprecedented challenges for next-generation networks and ICT infrastructure. Customers, service providers, and equipment manufacturers play a key role in the telecommunications sector. The trust triangle formed by the relationships among customers, service providers, and equipment manufacturers is essential for fostering deep collaboration among these three parties. However, service providers often suspect that equipment manufacturers' network equipment may contain backdoors or unauthorized access, and present security issues. Potential risks posed by network equipment, such as data breaches, also impact the relationship between customers and service providers. Lack of trust in equipment manufacturers is undermining the entire trust triangle.
[0003] Existing research on detecting malicious behavior in network devices produced by device manufacturers can be summarized into three methods: trusted computing-based, hardware-software separation-based, and historical scoring-based, but each has its own problems. Solutions based on trusted computing provide an isolated environment to force devices to operate in a predictable manner, but the trust in trusted computing still comes from the device manufacturer. Solutions based on hardware-software separation require device manufacturers to release source code and deploy it on some general-purpose hardware. This method conflicts with the interests of device manufacturers, making the network more vulnerable to attacks, and still cannot guarantee the trustworthiness of the software. Historical scoring-based methods score network devices based on historical behavior and predict their future behavior, but the use of empirical data can often only be used to assess reputation values and is generally not a reliable way to evaluate trustworthiness.
[0004] In reality, even device manufacturers themselves cannot truly prove the absence of backdoors. Due to the lack of recognized standards, it is difficult for device manufacturers to prove the reliability and trustworthiness of their products, even if most device manufacturers are willing to do so. Therefore, a high-confidence method is urgently needed to detect potential malicious behavior in network devices. Summary of the Invention
[0005] The technical problem to be solved by the present invention is that, in order to solve the problem that the current method of detecting whether network equipment produced by equipment manufacturers has malicious behavior lacks high credibility, the present invention provides a blockchain-assisted data eagle eye network function. By introducing blockchain to build a decentralized digital forensics model of the trust triangle, digital evidence is obtained to judge whether network equipment has malicious behavior. The blockchain-assisted data eagle eye network function monitors gateway devices and stores their traffic records on the blockchain. The service provider submits the hash value of the network's incoming and outgoing traffic to the blockchain, and uses the consistency between the incoming and outgoing data packets to detect whether the network equipment has malicious behavior to evaluate its credibility. In addition, from the customer's perspective, a customer's important data protection and mystery customer detection solution are designed to establish a complete trust triangle. Through the present invention, a trust triangle is established between customers, service providers and equipment manufacturers to promote in-depth cooperation among the three, effectively improving the security and trust of 5G and the next generation of networks.
[0006] In order to solve the above problems, the present invention adopts the following technical solutions:
[0007] A blockchain-assisted data eagle-eye network function, including:
[0008] The specific methods of the Data Eagle Eye network function, its implementation under the 5G framework, the precise positioning mechanism of malicious behavior, the protection of important customer data and the mystery shopper detection solution, including:
[0009] The Data Hawkeye network function uses a specific method where a service provider monitors gateway devices provided by device manufacturers and stores their traffic records on a blockchain. The service provider submits hash values of incoming and outgoing network traffic to the blockchain, introducing the Data Hawkeye network function as a digital forensics model. Without disclosing private customer information, the service provider uses the consistency between incoming and outgoing data packets to determine whether a device is engaging in malicious activity. Due to the distributed nature of the blockchain, the hash value can be verified by multiple service providers and used as digital evidence. The entire process can be automated through predefined smart contracts.
[0010] The method comprises the following steps:
[0011] Step 1. The Data Hawkeye network function extracts all incoming and outgoing data packets of data flows between two nodes in different areas of the network, discards packet header change fields, such as the TTL field, performs hash operations on the processed incoming and outgoing data packets, and submits the incoming and outgoing traffic hash values to the blockchain;
[0012] Step 2. The Data Hawkeye network function compares the hash values of incoming and outgoing traffic on the blockchain. If the device exhibits malicious behavior, the Data Hawkeye network function will detect a mismatch between the incoming and outgoing packets and store the detection result as digital evidence on the blockchain.
[0013] in,
[0014] The blockchain-assisted Data Hawkeye network function is characterized in that the Data Hawkeye network function is a blockchain-based network function entity, which can use virtualization technology as a built-in software module of a network device to monitor the link traffic passing through an area or network device; it can also be implemented in independent hardware through a predefined communication protocol, and the hardware-based Data Hawkeye network function captures data from physical media.
[0015] In step 1, if multiple data flows from one link to another are monitored, two Merkle trees are constructed from the hash values of the incoming and outgoing traffic of all data flows, and the root hash of the Merkle tree is submitted to the blockchain. This further compresses the stored data on the blockchain.
[0016] In the 5G framework, as described above, user data packets originate from user equipment (UE) and are ultimately sent to their destination data network (DN) via multiple new 5G radio base stations (gNBs), intermediate user plane functions (I-UPFs), and user plane functions (UPFs). Leveraging software-defined networking (SDN), 5G network equipment is highly integrated with custom-designed solutions to support a variety of emerging requirements and applications. Therefore, the Data Hawkeye network function can be installed on gNBs, I-UPFs, and UPFs in 5G scenarios to monitor incoming and outgoing traffic.
[0017] in,
[0018] The implementation of the Data Hawkeye network function within the 5G framework consists of three key components: the Data Hawkeye network function blockchain built on the network, the Data Hawkeye network function smart contract, and an off-chain software backend. The off-chain software backend first collects data packets and processes them into a suitable form, such as a Merkle tree, before submitting the pre-processed data to the blockchain. Pre-defined smart contracts within the blockchain automatically monitor and compare traffic summaries. The Data Hawkeye network function blockchain permanently records the comparison results, forming a typical digital forensics model consisting of preparation, collection, processing, and presentation.
[0019] The precise positioning mechanism for malicious behavior, in its implementation under the 5G framework, uses the Data Eagle Eye network function to monitor cross-domain traffic and detect it at the gateway of each network. Once malicious behavior is detected, it is not possible to precisely locate the malicious device within the domain. Since the Data Eagle Eye network function can virtualize an easy-to-install local network application, in order to more accurately identify faults, a virtualized Data Eagle Eye network function can be deployed between every two connected physical devices within a domain to identify and locate malicious devices based on the detection results of intra-domain and inter-domain link traffic. In order to more conveniently locate malicious devices, the detection results are visualized as an error map. Considering that the precise positioning mechanism for malicious behavior will incur additional overhead and cost, the Data Eagle Eye network function within the domain can be activated after the malicious behavior on the boundary is detected.
[0020] The above-mentioned customer important data protection is an additional service of the service provider, which can provide additional protection for the customer's important data. The customer first encrypts the data that needs additional protection, then performs a hash operation, and submits the hash value to the blockchain. Through the data eagle eye network function, the customer can observe the information transmission path while ensuring the quality of service, and can audit the routing process and check whether there are new data packets generated in the forwarding area.
[0021] The mystery shopper detection solution can be initiated by any service provider, customer, or even a third party such as a government. It randomly sends specific data packets between source and destination nodes. These packets can be disguised as real data packets within the network. The forwarding process of these packets can be observed and tracked, and the number of packets that ultimately reach the destination can be checked. Furthermore, it can be used to verify the performance of the Data Hawkeye network function by checking whether any packets leak to other areas.
[0022] The advantages and effects of the present invention are as follows:
[0023] (1) The present invention can capture improper behavior of network devices with backdoors or hacked devices to build trust between device manufacturers and service providers.
[0024] (2) From the user's perspective, the present invention proposes an auxiliary mechanism for protecting important customer data and a mystery shopper detection scheme to help build a complete trust triangle. The mystery shopper detection scheme can be used as a cross-validation tool to help evaluate the effectiveness of the Data Hawkeye network function.
[0025] (3) The present invention does not rely on trusted computing, does not require device manufacturers to disclose source code, and does not use historical ratings, thereby establishing a complete trust triangle among customers, service providers, and device manufacturers, and promoting in-depth cooperation among the three parties.
[0026] (4) The present invention can be virtualized and deployed in large quantities in 5G networks at low cost. It can not only capture malicious behaviors of network devices, but also accurately locate malicious devices within the domain.
[0027] (5) The present invention introduces blockchain technology, giving full play to the advantages of blockchain technology such as distribution, openness, transparency, non-tamperability, and automatic execution of smart contracts, avoiding single point failures in traffic comparison, and realizing cross-service provider verification, establishing a digital forensics model, and ensuring the neutrality of the Data Hawkeye network function. BRIEF DESCRIPTION OF THE DRAWINGS
[0028] Figure 1 A diagram of a threat model for a network with multiple regions.
[0029] Figure 2 Schematic diagram of hash traffic comparison for a single data flow from source node S to terminal node D using the Data Hawkeye network function.
[0030] Figure 3 Traffic comparison diagram for constructing a Merkle tree by recording hash values of multiple data flows for the Data Hawkeye network function.
[0031] Figure 4 Schematic diagram of the implementation of Data Eagle Eye network functions under the 5G framework.
[0032] Figure 5 Schematic diagram showing how the detection success rate of the Data Eagle Eye network function changes with the maliciousness of the error forwarding behavior under different detection effectiveness.
[0033] Figure 6 Schematic diagram of the detection success rate of the Data Eagle Eye network function under different levels of malicious error forwarding behaviors as the detection time changes.
[0034] Figure 7 This figure shows how the detection success rate of the Data Eagle Eye network function changes with the maliciousness of the leaked data under different detection effectiveness.
[0035] Figure 8 Schematic diagram of the detection success rate of the Data Eagle Eye network function under different levels of malicious data leakage behaviors as the detection time changes.
[0036] Figure 9 Schematic diagram of the transmission success rate of three cases in the mystery shopper detection solution at different malicious levels.
[0037] Figure 10 Schematic diagram of information leakage probability under different malicious levels for three cases in the mystery shopper detection solution. DETAILED DESCRIPTION
[0038] The present invention is further illustrated below with reference to the accompanying drawings and specific embodiments. It should be understood that these examples are only used to illustrate the present invention and are not used to limit the scope of the present invention. After reading the present invention, modifications of various equivalent forms of the present invention made by those skilled in the art all fall within the scope defined in this application.
[0039] A blockchain-assisted data eagle-eye network function, including:
[0040] The specific methods of the Data Eagle Eye network function, its implementation under the 5G framework, the precise positioning mechanism of malicious behavior, the protection of important customer data and the mystery shopper detection solution, including:
[0041] The Data Hawkeye network function uses a specific method where a service provider monitors gateway devices provided by device manufacturers and stores their traffic records on a blockchain. The service provider submits hash values of incoming and outgoing network traffic to the blockchain, introducing the Data Hawkeye network function as a digital forensics model. Without disclosing private customer information, the service provider uses the consistency between incoming and outgoing data packets to determine whether a device is engaging in malicious activity. Due to the distributed nature of the blockchain, the hash value can be verified by multiple service providers and used as digital evidence. The entire process can be automated through predefined smart contracts.
[0042] The method comprises the following steps:
[0043] Step 1. The Data Hawkeye network function extracts all incoming and outgoing data packets of data flows between two nodes in different areas of the network, discards packet header change fields, such as the TTL field, performs hash operations on the processed incoming and outgoing data packets, and submits the incoming and outgoing traffic hash values to the blockchain;
[0044] Step 2. The Data Hawkeye network function compares the hash values of incoming and outgoing traffic on the blockchain. If the device exhibits malicious behavior, the Data Hawkeye network function will detect a mismatch between the incoming and outgoing packets and store the detection result as digital evidence on the blockchain.
[0045] in,
[0046] The blockchain-assisted Data Hawkeye network function is characterized in that the Data Hawkeye network function is a blockchain-based network function entity, which can use virtualization technology as a built-in software module of a network device to monitor the link traffic passing through an area or network device; it can also be implemented in independent hardware through a predefined communication protocol, and the hardware-based Data Hawkeye network function captures data from physical media.
[0047] In step 1, if multiple data flows from one link to another are monitored, two Merkle trees are constructed from the hash values of the incoming and outgoing traffic of all data flows, and the root hash of the Merkle tree is submitted to the blockchain. This further compresses the stored data on the blockchain.
[0048] In the 5G framework, as described above, user data packets originate from user equipment (UE) and are ultimately sent to their destination data network (DN) via multiple new 5G radio base stations (gNBs), intermediate user plane functions (I-UPFs), and user plane functions (UPFs). Leveraging software-defined networking (SDN), 5G network equipment is highly integrated with custom-designed solutions to support a variety of emerging requirements and applications. Therefore, the Data Hawkeye network function can be installed on gNBs, I-UPFs, and UPFs in 5G scenarios to monitor incoming and outgoing traffic.
[0049] in,
[0050] The implementation of the Data Hawkeye network function within the 5G framework consists of three key components: the Data Hawkeye network function blockchain built on the network, the Data Hawkeye network function smart contract, and an off-chain software backend. The off-chain software backend first collects data packets and processes them into a suitable form, such as a Merkle tree, before submitting the pre-processed data to the blockchain. Pre-defined smart contracts within the blockchain automatically monitor and compare traffic summaries. The Data Hawkeye network function blockchain permanently records the comparison results. The entire process embodies a typical digital forensics model, encompassing preparation, collection, processing, and presentation.
[0051] The precise positioning mechanism for malicious behavior, in its implementation under the 5G framework, uses the Data Eagle Eye network function to monitor cross-domain traffic and detect it at the gateway of each network. Once malicious behavior is detected, it is not possible to precisely locate the malicious device within the domain. Since the Data Eagle Eye network function can virtualize an easy-to-install local network application, in order to more accurately identify faults, a virtualized Data Eagle Eye network function can be deployed between every two connected physical devices within a domain to identify and locate malicious devices based on the detection results of intra-domain and inter-domain link traffic. In order to more conveniently locate malicious devices, the detection results are visualized as an error map. Considering that the precise positioning mechanism for malicious behavior will incur additional overhead and cost, the Data Eagle Eye network function within the domain can be activated after the malicious behavior on the boundary is detected.
[0052] The above-mentioned customer important data protection is an additional service of the service provider, which can provide additional protection for the customer's important data. The customer first encrypts the data that needs additional protection, then performs a hash operation, and submits the hash value to the blockchain. Through the data eagle eye network function, the customer can observe the information transmission path while ensuring the quality of service, and can audit the routing process and check whether there are new data packets generated in the forwarding area.
[0053] The mystery shopper detection solution can be initiated by any service provider, customer, or even third parties such as governments. It randomly sends specific data packets between source and destination nodes. These packets can be disguised as real data packets on the network. The forwarding process of these packets can be observed and tracked, and the number of packets that ultimately reach the destination can be checked. Furthermore, it can be used to verify the performance of the Data Hawkeye network function by checking whether any packets are leaking to areas where they should not be.
[0054] The technical solution of the present invention is further described in detail below with reference to the accompanying drawings and embodiments.
[0055] like Figure 1 As shown, most of the potential risks posed by untrusted infrastructure can be divided into three types based on data confidentiality (threats 1-4), integrity (threat 5), and availability (threats 6-7).
[0056] like Figure 2 As shown, the flow comparison method of a single data flow of the Data Hawkeye network function of the present invention includes the following steps:
[0057] (1) The Data Hawkeye network function extracts all packets of a single data flow from node A (S) in network area 1 to node B (D) in area 2, which are transmitted from area 1 and transmitted to area 2, and discards the changed fields in the packet header, such as the TTL field. The processed packets transmitted from area 1 and transmitted to area 2 are hashed to obtain hash values 1 and 2, respectively. The Data Hawkeye network function submits the records to the blockchain in the form of <data flow, source node, destination node, hash value>, i.e., <1→2, S, D, hash value 1> and <1→2, S, D, hash value 2>;
[0058] (2) The Data Hawkeye network function compares the hash values of incoming and outgoing traffic on the blockchain, that is, compares hash value 1 and hash value 2. If the device has malicious behavior, the Data Hawkeye network function will detect a mismatch between the incoming and outgoing data packets, that is, hash value 1 ≠ hash value 2, and store the detection result as digital evidence on the blockchain;
[0059] like Figure 3As shown, the data eagle network function of the present invention compares the traffic of multiple data flows from one link to another link, including the following steps:
[0060] (1) The Data Hawkeye network function extracts all data packets from the links from area 3 to area 2 and from area 2 to area 4 on the four data flows flowing into area 2, and performs hash operations on the changing fields in the data packet header, such as the TTL field, on the data packets of each processed data flow to obtain hash values 1, hash value 2, hash value 3, and hash value 4. A Merkle tree is constructed from these four hash values to obtain a root hash value, namely root hash 1. The Data Hawkeye network function submits the record to the blockchain in the form of <incoming data flow, outgoing data flow, root hash>, namely <3→2,2→4, root hash 1>. The same operation is performed on all data packets from the four data flows flowing out of area 2 on this link to obtain <3→2,2→4, root hash 2>, which is submitted to the blockchain;
[0061] (2) The Data Hawkeye network function compares the hash values of incoming and outgoing traffic on the blockchain, that is, compares root hash 1 and root hash 2. If the device has malicious behavior, the Data Hawkeye network function will detect a mismatch between the incoming and outgoing data packets, that is, root hash 1 ≠ root hash 2, and store the detection result as digital evidence on the blockchain;
[0062] Figure 4 This example illustrates the implementation of the Data Hawkeye network function within the 5G framework. A virtualized Data Hawkeye network function is embedded in the gNB, I-UPF, and UPF in Networks A and B, assuming a data leak occurs at the UPF in Network A. It can be seen that a malicious device at the UPF in Network A intends to create a new data packet containing private information (Threat 3) and send it to the destination network (DN) in Network B. Each network device along the route collects the data packet through an off-chain software backend, which pre-processes the packet and submits it to the blockchain. After the malicious device at the UPF in Network A forwards the packet outside of Network A, the Data Hawkeye network function smart contract detects a mismatch between the incoming and outgoing packets. The mismatch is recorded as digital evidence on the Data Hawkeye network function blockchain.
[0063] Figure 5-Figure 8 It reflects the performance of the Data Hawkeye network function under different detection effectiveness. Among them, the detection effectiveness is the probability of missing detection when the data flow passes through the Data Hawkeye network function. Figure 5It can be seen that higher detection effectiveness can capture less malicious nodes. If the detection effectiveness is 100%, all misbehaviors can be detected. Using the same detection time, it is easier to detect the misbehavior of malicious nodes. The ideal case of 100% detection effectiveness shows a performance upper limit of the Data Hawkeye network function. Even if the detection success rate is not equal to 1, it does not mean that the Data Hawkeye network function has failed, because the malicious node did not misbehave during the detection period. Figure 6 In the case where the detection effectiveness is less than 10%, the detection success rate eventually tends to 100%, that is, as long as the Data Eagle Eye network function continues to operate and detect, most misbehaviors can be captured. Figure 7 and Figure 8 Similar conclusions were drawn for threats 2-4, showing that the Data Eagle Eye network function is more sensitive to malicious acts of data leakage.
[0064] Figure 9 and Figure 10 This demonstrates the performance of the Data Hawkeye network-based function-assisted mystery shopper detection scheme. Three different configurations were used for three different cases, tracking a given set of data packets and evaluating the probability of successful transmission. As can be seen, the mystery shopper detection scheme effectively detects an increase in malicious behavior. Detection results vary depending on the number and location of malicious nodes.
[0065] The above is only a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present invention. These improvements and modifications should also be regarded as the scope of protection of the present invention.
Claims
1. A blockchain-assisted method for implementing the Data Hawkeye network function, characterized in that: It is used by service providers to monitor gateway devices provided by equipment manufacturers and store their traffic records on the blockchain. Service providers submit the hash values of network incoming and outgoing traffic to the blockchain, introducing the Data Eagle Eye network function as a digital forensics model. Without leaking customer private information, service providers use the consistency between incoming and outgoing data packets to determine whether the device has malicious behavior; through the distributed nature of the blockchain, the hash value is verified by multiple service providers and used as digital evidence; the entire process is automated through predefined smart contracts.
2. A blockchain-assisted data hawk eye network function implementation method according to claim 1, characterized in that: The method for implementing the data eagle eye network function includes the following steps: Step 1. The Data Hawkeye network function extracts all incoming and outgoing data packets of data flows between two nodes in different areas of the network, discards the changing fields in the packet header, performs hash operations on the processed incoming and outgoing data packets, and submits the incoming and outgoing traffic hash values to the blockchain; Step 2. The Data Hawkeye network function compares the hash values of incoming and outgoing traffic on the blockchain. If the device exhibits malicious behavior, the Data Hawkeye network function will detect a mismatch between the incoming and outgoing data packets and store the detection result as digital evidence on the blockchain.
3. A blockchain-assisted data hawk eye network function implementation method according to claim 2, characterized in that: The Data Hawkeye network function is a blockchain-based network function entity that uses virtualization technology as a built-in software module of a network device to monitor link traffic passing through an area or network device, or is implemented in independent hardware through a predefined communication protocol. The hardware-based Data Hawkeye network function captures data from physical media.
4. A blockchain-assisted data hawk eye network function implementation method according to claim 2, characterized in that: In step 1, if multiple data flows from one link to another are monitored, two Merkle trees are constructed based on the hash values of the incoming and outgoing traffic of all data flows, and the root hash of the Merkle tree is submitted to the blockchain.
5. The method for implementing a blockchain-assisted data hawk eye network function according to claim 1, characterized in that: The service provider provides customers with important data protection services. Customers first encrypt the data that requires additional protection, then perform hash operations and submit the hash value to the blockchain. Through the Data Eagle Eye network function, customers can observe the information transmission path while ensuring service quality, audit the routing process, and check whether there are new data packets generated in the forwarding area.
6. A blockchain-assisted data hawk eye network function implementation method according to claim 1, characterized in that: The service provider, customer or third party initiates a mystery shopper detection scheme, randomly sending specific data packets between some source nodes and destination nodes, which are disguised as real data packets in the network, or by observing and tracking the forwarding process of these data packets and checking the number of data packets that finally reach the destination.
7. The method for implementing a blockchain-assisted data eagle eye network function according to claim 1, characterized in that: The Data Hawkeye network function is installed on 5G wireless base stations, intermediate user plane functions, and user plane functions in 5G scenarios to monitor incoming and outgoing traffic.
8. A blockchain-assisted data hawk eye network function implementation method according to claim 7, characterized in that: The implementation of the Data Hawkeye network function under the 5G framework includes three key components: the Data Hawkeye network function blockchain built on the network, the Data Hawkeye network function smart contract and the off-chain software backend; the off-chain software backend first collects data packets and processes them into an appropriate form, and then submits the pre-processed data to the blockchain; the smart contract pre-defined in the blockchain automatically monitors and compares traffic summaries; the Data Hawkeye network function blockchain will permanently record the comparison results; the entire process is a typical digital forensics model that includes preparation, collection, processing and presentation.
9. The method for implementing a blockchain-assisted data hawk eye network function according to claim 1, characterized in that: A virtualized Data Hawkeye network function is deployed between every two connected physical devices in a domain. Rogue devices are identified and located based on the detection results of intra-domain and inter-domain link traffic. To more easily identify malicious devices, the detection results are visualized as an error graph.
10. A blockchain-assisted data eagle eye network function implementation method according to claim 9, characterized in that: After detecting malicious behavior at the border, the Data Eagle Eye network function within the domain is activated.