An AI-based 5G network protection and supervision system and method

Through artificial intelligence-based methods, real-time monitoring and analysis of historical data of 5G networks and establishing threshold intervals and scoring systems, the problem that traditional systems cannot process and analyze data in 5G networks is solved, dynamic adjustment and abnormal detection of network security are achieved, and network security and user experience are improved.

CN117499924BActive Publication Date: 2025-07-18BEIJING SHUNHETONGDA DIGITAL NETWORK TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311455709.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-11-02
Publication Date
2025-07-18
Estimated Expiration
2043-11-02

AI Technical Summary

Technical Problem

Traditional network protection supervision systems cannot effectively cope with the high-speed, high capacity, and low latency characteristics of 5G networks, and cannot process and analyze large amounts of data in real time, resulting in missed reports, false alarms and insufficient network security, making it difficult to adjust security protection levels in real time according to network status and user operation behavior.

Method used

Using an artificial intelligence-based method, we collect and preprocess the historical data of 5G networks, analyze network status and user operation behavior, establish threshold intervals and scoring systems, monitor and adjust network security protection levels in real time, and provide visual correlation display.

Benefits of technology

Real-time security threat detection and rapid response to abnormal situations of 5G networks is achieved, false alarms and false interception are reduced, network security resources are allocated reasonably, and user satisfaction and experience are improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117499924B_ABST
    Figure CN117499924B_ABST
Patent Text Reader

Abstract

The present invention discloses a 5G network protection and supervision system and method based on artificial intelligence, belonging to the technical field of network supervision. The system of the present invention includes a data collection module, a network status analysis module, a user operation behavior analysis module, a real-time monitoring module, a security protection level adjustment module, and a visualization display module; the data collection module is responsible for collecting historical data; the network status analysis module determines whether the network status is normal according to the collected data; the user operation behavior analysis module analyzes the user operation behavior and determines whether the user operation is normal; the real-time monitoring module collects real-time data and determines whether the current network status and user operation behavior are normal; the security protection level adjustment module determines the corresponding network security protection level according to the scoring result; the visualization display module visually displays the association relationship between the network security status and the user operation behavior to the administrator.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of network supervision, and particularly to a 5G network protection and supervision system and method based on artificial intelligence. Background Art

[0002] With the rapid development and wide application of 5G networks, network security issues have become more prominent; traditional network protection methods are no longer sufficient to meet the requirements of 5G networks, so a new and intelligent network protection and supervision system is needed to effectively address security threats in 5G networks.

[0003] Existing network protection and supervision systems can meet current requirements to a certain extent, but there are still certain deficiencies, specifically reflected in: traditional network security monitoring methods cannot effectively cope with the characteristics of 5G networks such as high speed, high capacity, and low latency. In 5G networks, the amount of data is huge, and traditional security monitoring systems often cannot process and analyze this data in real time, resulting in problems such as missed reports and false alarms; traditional networks are difficult to adjust the network security protection level in real time according to the current network status and actual user operation behaviors, leading to insufficient network security. Summary of the Invention

[0004] The purpose of the present invention is to provide a 5G network protection and supervision system and method based on artificial intelligence to solve the problems raised in the above background art.

[0005] To solve the above technical problems, the present invention provides the following technical solutions:

[0006] A 5G network protection and supervision method based on artificial intelligence, the method comprising the following steps:

[0007] S100. Collect historical data from the 5G network and preprocess the collected historical data, including data cleaning, denoising, and format conversion operations; the historical data includes network metrics, security event logs, and user operation behaviors;

[0008] S200. Analyze the preprocessed historical data, judge the network status according to the security event logs, so as to obtain the network metrics corresponding to normal network status, obtain the threshold interval Q1 of normal network status by analyzing the network metrics, and calculate the scoring interval A of normal network status according to the threshold interval Q1;

[0009] S300. Obtain the user operation behavior data when the network status is normal in the historical data, screen out the abnormal user operation behavior data and retain the normal user operation behavior data, so as to obtain the threshold interval Q2 of normal user operation behavior, and calculate the normal user operation behavior scoring interval B according to the threshold interval Q2;

[0010] S400. Collect current network metric data in real time, and compare it successively with the threshold interval Q1 and the scoring interval A of the normal network state in the historical data to determine whether the current network state is normal; obtain real-time user operation behavior data, and compare it successively with the threshold interval Q2 and the scoring interval B of the normal user operation behavior in the historical data to determine whether the current user behavior is normal;

[0011] S500. According to the judgment results of the current network state and user operation behavior scores, adjust the network security protection level in real time; continuously collect and monitor network metric data and user operation behaviors, and provide the administrator with a visual image of the correlation between the real-time network security state and user operation behaviors. Further, step S200 includes:

[0012] S201. Extract security event logs from the preprocessed historical data, and obtain the timestamp of each security event; the security event log refers to the record of security-related events that occur in the system, network, or application, and these events can include security threat events such as malware infections, network intrusion attempts, abnormal login behaviors, data leaks, etc.;

[0013] Arrange the security events in chronological order of the timestamps, and mark the network metric data at the corresponding time points according to the security event timestamps; in this way, the security events and the corresponding network metric data can be associated, providing accurate data for subsequent analysis; the network metric data includes packet loss rate, bandwidth utilization rate, and latency data;

[0014] S202. Screen out the network metric data with marks, calculate the average value μ1 and standard deviation σ1 of the screened network metric data, and obtain the network metric threshold interval Q1 for normal network states, and Q1 = [μ1 - ασ1, μ1 + ασ1], where α is a coefficient, and the specific value of α is obtained according to the data distribution;

[0015] S203. Calculate the threshold intervals of all network metric data for normal network states, and perform normalization, and Q1 = {q1, q2, q3}, where q1 represents the threshold interval of the packet loss rate, q2 represents the threshold interval of the bandwidth utilization rate, and q3 represents the threshold interval of the latency data; perform weighted average according to the calculation results to obtain the scoring interval A, and A = w1q1 + w2q2 + w3q3, where w1 represents the weighting coefficient of q1, w2 represents the weighting coefficient of q2, w3 represents the weighting coefficient of q3, and the weighting coefficients are obtained from the analysis of historical data, and w1 + w2 + w3 = 1.

[0016] Normalization can map the threshold intervals of different metrics to the same numerical range, facilitating subsequent weighted average calculations. Then, based on the weighted coefficients obtained from historical data analysis, a weighted average is performed on the normalized threshold intervals to obtain a scoring interval, which can be used to determine whether the network status is normal.

[0017] Further, step S300 includes:

[0018] S301. Screen out the time periods during which the network status is normal from the historical data, and obtain the network status scores and user operation behavior data for these time periods. This can associate the network status scores with the user operation behavior data and be used for subsequent correlation analysis. The user operation behavior data includes user login frequency, data transfer volume, and user access frequency.

[0019] S302. Calculate the average value μ2 and standard deviation σ2 of the user operation behavior data, and obtain the threshold interval Q2 for normal user operation behavior data, where Q2 = [μ2 - βσ2, μ2 + βσ2], and β is a coefficient, and the specific value of β is obtained according to the data distribution.

[0020] S303. Calculate the threshold intervals for all normal user operation behavior data and perform normalization, and Q2 = {p1, p2, p3}, where p1 represents the threshold interval for user login frequency, p2 represents the threshold interval for data transfer volume, and p3 represents the threshold interval for user access frequency. Perform correlation analysis between the network status scores and the normalized normal user operation behavior data. The specific correlation analysis is as follows:

[0021] Take the network status score as the 1st axis, the user login frequency as the 2nd axis, the data transfer volume as the 3rd axis, and the user access frequency as the 4th axis. The four axes evenly divide the plane rectangular coordinate system, that is, the four axes have an intersection point, and the included angle between adjacent axes is 45°. Take the x-axis as the 1st axis, and mark the 2nd axis, 3rd axis, and 4th axis in counterclockwise order. According to the positive direction of the x-axis, mark the positive directions in turn. Obtain the set of network status scores and the normalized user operation behavior data for the same time period, including the data sets corresponding to user login frequency, data transfer volume, and user access frequency. Record the corresponding data points on the respective axes according to the time sequence.

[0022] For the data points on the 1st axis of the network status score and the 2nd axis of the user login frequency, connect the two data points with the same time sequence, calculate the slope k of all the connected data point line segments, and through analysis, if it satisfies k i+1 = tk i, it indicates that the network status score is related to the user login frequency, where i represents the data number, taking positive integers greater than or equal to 1; t is the correlation coefficient; the correlation analysis of other axes with the 1st axis is the same as the above analysis content;

[0023] S304. According to the analysis results of the correlation, calculate the normal behavior score of the user operation, so as to obtain the normal score range B of the user operation behavior;

[0024] If both the network status score and the user operation behavior data satisfy the correlation relationship, the normal behavior score range of the user operation is calculated according to the following formula: B = t1p1 + t2p2 + t3p3, where t1 is the correlation coefficient between the 1st axis and the 2nd axis, t2 is the correlation coefficient between the 1st axis and the 3rd axis, and t3 is the correlation coefficient between the 1st axis and the 4th axis;

[0025] If the network status score and the user operation behavior data do not all satisfy the correlation relationship or both do not satisfy the correlation relationship, the calculation formula for the normal behavior score range B of the user operation is: B = t1p1 + t2p2 + t3p3, where t1 represents the weighting coefficient of p1, t2 represents the weighting coefficient of p2, t3 represents the weighting coefficient of p3, and t1 + t2 + t3 = 1.

[0026] The calculation process of the weighting coefficient is as follows: Since in step S303, the threshold range of the normal data of the user operation behavior has been normalized, then sum the historical data in the threshold range p1 of the user login frequency, the threshold range p2 of the data transmission volume, and the threshold range p3 of the user access frequency, and perform proportional calculation according to the summation result to obtain the weighting coefficients of the three threshold ranges.

[0027] Further, step S40 includes:

[0028] S401. Collect the current network metric data in real time and compare it with the threshold range Q1; if there is a situation where the current network metric data does not belong to the threshold range Q1, it indicates that the current network status is abnormal, output a first-level network status signal, and calculate the deviation value between the current network metric data and the threshold range Q1. The specific formula is: offset = (|x - x min | + |x - x max |) * (1 / 2), where x min and x max represent the minimum value and the maximum value of the threshold range Q1 respectively, and x represents the current network metric data; perform marking assignment according to the deviation value;

[0029] If all current network metric data belong to the threshold range Q1, it only indicates that the network metric data is within the normal range. To prevent some network threats from mimicking normal network states and further improve the detection ability for abnormal situations, normalization processing is performed, and then the current network state score is calculated and compared with the score range A of the normal network state in historical data. If the current network state score does not belong to the score range A, it means the current network state is abnormal, a secondary network state signal is output, and the deviation value between the current network state score and the score range A is calculated, and corresponding marking assignments are made according to the deviation value. If the current network state score belongs to the score range A, it means the current network state is normal, a normal network state signal is output, marking is performed, and the value is assigned as 0; and the priority of secondary anomalies is higher than that of primary anomalies.

[0030] S402. Real-time collect the current user operation behavior data and compare it with the threshold range Q2. If there is a situation where the current user operation behavior data does not belong to the threshold range Q2, it means the user operation behavior is abnormal, a primary user operation behavior signal is output, and the deviation value between the current user operation behavior data and the threshold range Q2 is calculated, and corresponding marking assignments are made according to the deviation value.

[0031] If all current user operation behavior data belong to the threshold range Q2, to prevent abnormal operations from mimicking normal user behavior operations, further analysis is needed. Normalization processing is performed, and then the current user operation behavior score is calculated and compared with the normal user operation behavior score range B in historical data. If the current user operation behavior score does not belong to the score range B, it means the current user operation behavior is abnormal, a secondary network state signal is output, and the deviation value between the current user operation behavior score and the score range B is calculated, and corresponding marking assignments are made according to the deviation value. If the current user operation behavior score belongs to the score range B, it means the current user operation behavior is normal, a normal user operation behavior signal is output, marking is performed, and the value is assigned as 0.

[0032] Further, step S500 includes:

[0033] S501. According to the judgment results of the current network state and user operation behavior scores, obtain signal marks, calculate according to the signal marks to obtain the signal mark calculation result set C, and C = {c1, c2,..., c n}, where n is the number of signal mark calculation results, taking a positive integer, c n represents the nth signal mark calculation result; corresponding network security protection levels are determined according to the signal mark calculation result set, and as the value increases, the network security protection level is higher;

[0034] S502. Continuously collect and monitor network metric data and user operation behavior data, and continuously update historical data; display the correlation between network security status and user operation behavior to the administrator in a visual manner to monitor the network security status and user operation behavior in real time.

[0035] A 5G network protection and supervision system based on artificial intelligence, which includes a data collection module, a network status analysis module, a user operation behavior analysis module, a real-time monitoring module, a security protection level adjustment module, and a visual display module;

[0036] The data collection module is responsible for collecting metric data, security event logs, and user operation behavior data of the 5G network; the network status analysis module determines whether the network status is normal based on the collected network metric data and security event logs, and calculates a network status score; the user operation behavior analysis module analyzes the operation behavior of users in the 5G network, determines whether the user operation is normal, and calculates a user operation behavior score; the real-time monitoring module collects the current network metric data and user operation behavior data in real time to determine whether the current network status and user operation behavior are normal; the security protection level adjustment module calculates a signal flag based on the results of the network status and user operation behavior scores, and then determines the corresponding network security protection level; the visual display module displays the correlation between the network security status and user operation behavior to the administrator in a visual manner.

[0037] Furthermore, the data collection module includes a network monitoring device unit, a security event log unit, and a user operation behavior unit;

[0038] The network monitoring device unit is responsible for providing network performance data and monitoring the network health status; the security event log unit records the log data of security events occurring in the network; the user operation behavior unit collects the operation behavior data of users on the network;

[0039] The network status analysis module includes a security event log extraction unit, a network status judgment unit, and a network status scoring unit;

[0040] The security event log extraction unit extracts security event logs from the collected historical data; the network status judgment unit determines whether the network is in a normal operating state by analyzing network metric data and security event logs; the network status scoring unit calculates a network status score based on the network status judgment result.

[0041] Furthermore, the user operation behavior analysis module includes a time period screening unit, a user operation behavior judgment unit, and a user operation behavior scoring unit;

[0042] The time period screening unit screens out the time period data with normal network status; the user operation behavior judgment unit judges whether the user operation is normal according to the user operation behavior data; the user operation behavior scoring unit calculates the user operation behavior score according to the user operation behavior judgment result;

[0043] The real-time monitoring module includes a real-time data collection unit, a network status judgment unit, and a user operation behavior judgment unit;

[0044] The real-time data collection unit collects the current network metric data and user operation behavior data in real time; the network status judgment unit judges whether the current network status is normal by comparing the real-time network metric data with a threshold; the user operation behavior judgment unit judges whether the current user operation is normal by comparing the real-time user operation behavior data with a threshold.

[0045] Furthermore, the security protection level adjustment module includes a signal marking calculation unit and a protection level unit;

[0046] The signal marking calculation unit calculates a signal mark according to the results of the network status and the user operation behavior score; the protection level unit determines the corresponding network security protection level according to the signal mark calculation result;

[0047] The visualization display module includes a network security status display unit and a user operation behavior display unit; the network security status display unit displays the network security protection status to the administrator in a visual manner; the user operation behavior display unit displays the user's operation behavior on the network in a visual manner and associates it with the network security status.

[0048] Compared with the prior art, the beneficial effects achieved by the present invention are as follows: by real-time monitoring the current network status and user operation behavior, the system can discover potential security threats and abnormal situations more quickly. When the network status or user behavior is abnormal, the system can immediately take corresponding security measures for protection, thereby reducing the risk of security vulnerabilities being exploited; under different network environments and user behaviors, the requirements for network security will also be different. By real-time adjusting the network protection level, the problem of over-allocation or under-allocation of resources can be avoided, thereby making more reasonable use of network security resources; by adjusting the network security protection level according to the actual operation behavior of the user, the phenomenon of false alarms and false interceptions can be effectively reduced, which can avoid unnecessary restrictions and interferences on the normal operations of legitimate users, thereby improving the satisfaction and experience of users. BRIEF DESCRIPTION OF THE DRAWINGS

[0049] The drawings are used to provide a further understanding of the present invention, and constitute a part of the specification. They are used together with the embodiments of the present invention to explain the present invention, and do not constitute a limitation to the present invention. In the drawings:

[0050] Figure 1 It is a schematic flow chart of a 5G network protection and supervision method based on artificial intelligence according to the present invention. Specific implementation manners

[0051] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0052] Please refer to Figure 1 , the present invention provides a technical solution:

[0053] A 5G network protection and supervision method based on artificial intelligence, the method includes the following steps:

[0054] S100. Collect historical data from the 5G network and preprocess the collected historical data, including data cleaning, denoising, and format conversion operations; the historical data includes network metrics, security event logs, and user operation behaviors;

[0055] S200. Analyze the preprocessed historical data, judge the network status according to the security event logs, so as to obtain the network metrics corresponding to the normal network status, obtain the threshold interval Q1 of the normal network status by analyzing the network metrics, and calculate the scoring interval A of the normal network status according to the threshold interval Q1;

[0056] S201. Extract the security event logs from the preprocessed historical data, obtain the time stamps of each security event; arrange the security events in the order of the time stamps, and mark the network metric data at the corresponding time points according to the security event time stamps; in this way, the security events can be associated with the corresponding network metric data, providing accurate data for subsequent analysis; the network metric data includes packet loss rate, bandwidth utilization rate, and delay data;

[0057] S202. Screen out the marked network metric data, calculate the average value μ1 and standard deviation σ1 of the screened network metric data, obtain the network metric threshold interval Q1 of the normal network status, and Q1 = [μ1 - ασ1, μ1 + ασ1], where α is a coefficient, and the specific value of α is obtained according to the distribution of the data;

[0058] S203. Calculate the threshold intervals of all network metric data with normal network status, normalize them, and let Q1 = {q1, q2, q3}, where q1 represents the threshold interval of the packet loss rate, q2 represents the threshold interval of the bandwidth utilization rate, and q3 represents the threshold interval of the delay data; perform weighted averaging based on the calculation results to obtain the scoring interval A, and A = w1q1 + w2q2 + w3q3, where w1 represents the weighting coefficient of q1, w2 represents the weighting coefficient of q2, w3 represents the weighting coefficient of q3, and the weighting coefficients are obtained from the analysis of historical data, and w1 + w2 + w3 = 1.

[0059] Normalization can map the threshold intervals of different metrics to the same numerical range, facilitating subsequent weighted average calculations; then, perform weighted averaging on the normalized threshold intervals according to the weighting coefficients obtained from historical data analysis to obtain the scoring interval, which can be used to determine whether the network status is normal.

[0060] In this embodiment, the following example data is given:

[0061] Security event log:

[0062] Security event 1 - Timestamp: 2023-09-14 10:00:00,

[0063] Network metric data:

[0064] Packet loss rate: [0.2, 0.3, 0.4], bandwidth utilization rate: [80, 70, 90], delay data: [10, 15, 12];

[0065] Sort the security events according to the steps in S201, and mark the network metric data at the corresponding time points according to the timestamps;

[0066] The sequence of security events sorted by timestamp: Security event 1;

[0067] The corresponding marked network metric data:

[0068] Security event 1 - Packet loss rate: 0.2, bandwidth utilization rate: 80, delay data: 10;

[0069] Next, according to S202, filter out the marked network metric data, and calculate the average value μ1 and standard deviation σ1 of the filtered network metric data;

[0070] The filtered network metric data:

[0071] Packet loss rate: [0.3, 0.4], bandwidth utilization rate: [70, 90], delay data: [15, 12];

[0072] Average value:

[0073] μ1 (Packet loss rate) = (0.3 + 0.4) / 2 = 0.35,

[0074] μ1 (Bandwidth utilization) = (70 + 90) / 2 = 80,

[0075] μ1 (Delay data) = (15 + 12) / 2 = 13.5;

[0076] Standard deviation:

[0077] σ1 (Packet loss rate) = √(((0.3 - μ1)²+(0.4 - μ1)²) / 2), σ1 (Bandwidth utilization) = √(((70 - μ1)²+(90 - μ1)²) / 2),

[0078] σ1 (Delay data) = √(((15 - μ1)²+(12 - μ1)²) / 2);

[0079] Next, according to S203, calculate the threshold intervals of all network metric data with normal network status and perform normalization:

[0080] Threshold intervals:

[0081] q1 = [μ1 (Packet loss rate) - ασ1 (Packet loss rate), μ1 (Packet loss rate) + ασ1 (Packet loss rate)],

[0082] q2 = [μ1 (Bandwidth utilization) - ασ1 (Bandwidth utilization), μ1 (Bandwidth utilization) + ασ1 (Bandwidth utilization)],

[0083] q3 = [μ1 (Delay data) - ασ1 (Delay data), μ1 (Delay data) + ασ1 (Delay data)];

[0084] Perform normalization. The normalized threshold intervals:

[0085] q1' = (q1 - min(q1)) / (max(q1) - min(q1)),

[0086] q2' = (q2 - min(q2)) / (max(q2) - min(q2)),

[0087] q3' = (q3 - min(q3)) / (max(q3) - min(q3));

[0088] Finally, perform weighted average according to the calculation results to obtain the scoring interval A:

[0089] Scoring interval: A = w1q1' + w2q2' + w3q3'.

[0090] S300. Obtain the user operation behavior data when the network status is normal in the historical data, screen out the abnormal user operation behavior data, and retain the normal user operation behavior data, so as to obtain the threshold interval Q2 of the normal user operation behavior, and calculate the normal score interval B of the user operation behavior according to the threshold interval Q2;

[0091] S301. Screen out the time period when the network status is normal from the historical data, and obtain the network status score and user operation behavior data of the time period; in this way, the network status score can be associated with the user operation behavior data and used for subsequent correlation analysis; the user operation behavior data includes user login frequency, data transmission volume, and user access frequency;

[0092] S302. Calculate the average value μ2 and standard deviation σ2 of the user operation behavior data, and obtain the threshold interval Q2 of the normal user operation behavior data, and Q2 = [μ2 - βσ2, μ2 + βσ2], where β is a coefficient, and the specific value of β is obtained according to the data distribution;

[0093] S303. Calculate the threshold intervals of all normal user operation behavior data and perform normalization, and Q2 = {p1, p2, p3}, where p1 represents the threshold interval of user login frequency, p2 represents the threshold interval of data transmission volume, and P3 represents the threshold interval of user access frequency; perform correlation analysis on the network status score and the normalized normal user operation behavior data. The specific correlation analysis is as follows:

[0094] Take the network status score as the 1st axis, the user login frequency as the 2nd axis, the data transmission volume as the 3rd axis, and the user access frequency as the 4th axis. The four axes evenly divide the plane rectangular coordinate system, that is, the four axes have an intersection point, and the included angle between adjacent axes is 45°. Take the x-axis as the 1st axis, and mark the 2nd axis, 3rd axis, and 4th axis counterclockwise in sequence. According to the positive direction of the x-axis, mark the positive direction in sequence; obtain the network status score set in the same time period, and the normalized user operation behavior data, including the data sets corresponding to user login frequency, data transmission volume, and user access frequency; record the corresponding data points on the respective axes according to the time sequence.

[0095] For the data points on the 1st axis of the network status score and the 2nd axis of the user login frequency, connect the two data points at the same time point, calculate the slope k of all the connected data point line segments, and through analysis, if it satisfies k i+1 = tk i , it means that the network status score is related to the user login frequency, where i represents the data number, taking positive integers greater than or equal to 1; t is the correlation coefficient, taking a constant; the correlation analysis between other axes and the 1st axis is the same as the above analysis content;

[0096] S304. Calculate the normal behavior score of user operations based on the analysis results of relevance, so as to obtain the normal score range B of user operation behavior;

[0097] If both the network status score and the user operation behavior data satisfy the correlation relationship, the normal behavior score range of user operations is calculated according to the following formula: B = t1p1 + t2p2 + t3p3, where t1 is the correlation coefficient between axis 1 and axis 2, t2 is the correlation coefficient between axis 1 and axis 3, and t3 is the correlation coefficient between axis 1 and axis 4;

[0098] If the network status score and the user operation behavior data do not fully satisfy the correlation relationship or both do not satisfy the correlation relationship, the calculation formula for the normal behavior score range B of user operations is: B = t1p1 + t2p2 + t3p3, where t1 represents the weighting coefficient of p1, t2 represents the weighting coefficient of p2, t3 represents the weighting coefficient of p3, and t1 + t2 + t3 = 1;

[0099] The calculation process of the weighting coefficient is as follows: Since in step S303, the threshold range of the normal data of user operation behavior has been normalized, then the data in the threshold range p1 of user login frequency, the threshold range p2 of data transmission volume, and the threshold range p3 of user access frequency are summed, and proportional calculation is performed according to the summation result, so as to obtain the weighting coefficients of the three threshold ranges.

[0100] S400. Collect the current network metric data in real time, and compare it with the threshold range Q1 and the network normal status score range A in the historical data in sequence to determine whether the current network status is normal; obtain the real-time user operation behavior data, and compare it with the threshold range Q2 and the normal behavior score range B of user operations in the historical data in sequence to determine whether the current user behavior is normal;

[0101] S401. Collect the current network metric data in real time and compare it with the threshold range Q1; if there is a situation where the current network metric data does not belong to the threshold range Q1, it means that the current network status is abnormal, output the first-level signal of the network status, and calculate the deviation value between the current network metric data and the threshold range Q1. The specific formula is: offset = (|x - x min | + |x - x max |) * (1 / 2), where x min and x max represent the minimum value and the maximum value of the threshold range Q1 respectively, and x represents the current network metric data; perform label assignment according to the deviation value;

[0102] If all the current network metric data fall within the threshold range Q1, it only indicates that the network metric data is within the normal range. To prevent certain network threats from mimicking normal network states and to further improve the detection ability for abnormal situations, normalization processing is performed, and then the current network state score is calculated and compared with the score range A of the normal network state in the historical data. If the current network state score does not fall within the score range A, it means that the current network state is abnormal, a secondary network state signal is output, and the deviation value between the current network state score and the score range A is calculated, and corresponding marking assignments are made according to the deviation value. If the current network state score falls within the score range A, it means that the current network state is normal, a normal network state signal is output, marking is performed, and the value is assigned as 0; and the priority of secondary anomalies is higher than that of primary anomalies.

[0103] In this embodiment, assume the following data:

[0104] Current network metric data:

[0105] Packet loss rate: 0.35, bandwidth utilization: 85, latency data: 13;

[0106] Assume the threshold ranges: q1 = [0.2, 0.5], q2 = [60, 90], q3 = [10, 15];

[0107] Weighting coefficients: w1 = 0.4, w2 = 0.3, w3 = 0.3;

[0108] Score range of the normal network state in the historical data: A = [0.6, 0.9];

[0109] Now calculate according to the steps of S401:

[0110] Compare the current network metric data with the threshold range Q1:

[0111] The packet loss rate (0.35) belongs to q1, the bandwidth utilization (85) belongs to q2, and the latency data (13) belongs to q3;

[0112] Perform normalization processing and calculate the current network state score:

[0113] q1' = (0.35 - 0.2) / (0.5 - 0.2) = 0.5,

[0114] q2' = (85 - 60) / (90 - 60) = 0.83,

[0115] q3' = (13 - 10) / (15 - 10) = 0.6;

[0116] Current network status score = w1 * q1' + w2 * q2' + w3 * q3' = 0.4 * 0.5 + 0.3 * 0.83 + 0.3 * 0.6 = 0.629;

[0117] Compare the current network status score with the score range A. The current network status score (0.629) is within the score range A [0.6, 0.9], indicating that the current network status is normal.

[0118] S402. Collect the current user operation behavior data in real time and compare it with the threshold range Q2; if there is a situation where the current user operation behavior data does not belong to the threshold range Q2, it means that the user operation behavior is abnormal, output the first-level signal of the user operation behavior, and calculate the deviation value between the current user operation behavior data and the threshold range Q2, and perform corresponding marking assignment according to the deviation value;

[0119] If all the current user operation behavior data belongs to the threshold range Q2, to prevent abnormal operations from imitating normal user behavior operations, further analysis is required. Therefore, perform normalization processing, then calculate the current user operation behavior score, and compare it with the normal score range B of the user operation behavior in the historical data; if the current user operation behavior score does not belong to the score range B, it means that the current user operation behavior is abnormal, output it as the second-level signal of the network status, and calculate the deviation value between the current user operation behavior score and the score range B, and perform corresponding marking assignment according to the deviation value; if the current user operation behavior score belongs to the score range B, it means that the current user operation behavior is normal, output the normal signal of the user operation behavior, perform marking, and assign a value of 0.

[0120] S500. According to the judgment results of the current network status and the user operation behavior score, adjust the network security protection level in real time; continuously collect and monitor network metric data and user operation behavior, and provide the administrator with a visual image of the correlation between the real-time network security status and the user operation behavior.

[0121] S501. According to the judgment results of the current network status and the user operation behavior score, obtain the signal marks, perform calculations based on the signal marks to obtain the set C of signal mark calculation results, and C = {c1, c2,..., c n}, where n is the number of signal mark calculation results, taking a positive integer, c n represents the nth signal mark calculation result; corresponding to the set of signal mark calculation results, the corresponding network security protection level, and as the value increases, the network security protection level is higher;

[0122] Assume that the network security protection level is M level, obtain the maximum value c max in the set of signal mark calculation results, calculate the level division gradient △c, that is, △c = [cmax / M], then the division interval for each level is as follows:

[0123] The first level is [0, △c], the second level is (△c, 2△c], the third level is (2△c, 3△c],..., the Mth level is ((M - 1)△c, M△c]; when c max > M△c, then change the interval of the Mth level to ((M - 1)△c, c max .

[0124] S502. Continuously collect and monitor network metric data and user operation behavior data, and continuously update historical data; display the correlation between network security status and user operation behavior to the administrator in a visual manner, and monitor the network security status and user operation behavior in real time.

[0125] It should be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, article or device.

[0126] Finally, it should be noted that the above are only preferred embodiments of the present invention and are not used to limit the present invention. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.

Claims

1. An AI-based 5G network protection and supervision method, characterized in that: The method includes the following steps: S100. Collect historical data from the 5G network and preprocess the collected historical data, including data cleaning, denoising, and format conversion operations; the historical data includes network metrics, security event logs, and user operation behaviors; S200. Analyze the preprocessed historical data, judge the network status according to the security event logs, so as to obtain the network metrics corresponding to the normal network status, obtain the threshold interval Q1 of the normal network status by analyzing the network metrics, and calculate the scoring interval A of the normal network status according to the threshold interval Q1; S300. Obtain the user operation behavior data when the network status is normal in the historical data, screen out the abnormal user operation behavior data and retain the normal user operation behavior data, so as to obtain the threshold interval Q2 of the normal user operation behavior, and calculate the scoring interval B of the normal user operation behavior according to the threshold interval Q2; S400. Collect the current network metric data in real time and compare it with the threshold interval Q1 and the scoring interval A of the normal network status in the historical data in sequence to judge whether the current network status is normal; obtain the real-time user operation behavior data and compare it with the threshold interval Q2 and the scoring interval B of the normal user operation behavior in the historical data in sequence to judge whether the current user behavior is normal; S500. According to the judgment results of the current network status and user operation behavior scores, adjust the network security protection level in real time; continuously collect and monitor network metric data and user operation behaviors, and provide the administrator with a visual image of the correlation between the real-time network security status and user operation behaviors.

2. The method for 5G network protection and supervision based on artificial intelligence according to claim 1, wherein: The step S200 includes: S201. Extract the security event logs from the preprocessed historical data, obtain the time stamp of each security event; arrange the security events in the order of the time stamps, and mark the network metric data at the corresponding time points according to the security event time stamps; the network metric data includes packet loss rate, bandwidth utilization rate, and delay data; S202. Screen out the marked network metric data, calculate the average value μ1 and standard deviation σ1 of the screened network metric data, obtain the network metric threshold interval Q1 of the normal network status, and Q1 = [μ1 - ασ1, μ1 + ασ1], where α is a coefficient, and the specific value of α is obtained according to the data distribution; S203. Calculate the threshold intervals of all network metric data with normal network status and perform normalization, and Q1 = {q1, q2, q3}, where q1 represents the threshold interval of the packet loss rate, q2 represents the threshold interval of the bandwidth utilization rate, and q3 represents the threshold interval of the delay data; perform weighted average according to the calculation results to obtain the scoring interval A, and A = w1q1 + w2q2 + w3q3, where w1 represents the weighting coefficient of q1, w2 represents the weighting coefficient of q2, w3 represents the weighting coefficient of q3, and the weighting coefficients are obtained according to the analysis of the historical data, and w1 + w2 + w3 = 1.

3. A 5G network protection and supervision method based on artificial intelligence according to claim 2, characterized in that: The step S300 includes: S301. Screen out the time periods when the network status is normal from historical data, and obtain the network status scores and user operation behavior data during these time periods; the user operation behavior data includes user login frequency, data transmission volume, and user access frequency; S302. Calculate the average value μ2 and standard deviation σ2 of the user operation behavior data, and obtain the threshold interval Q2 of the normal user operation behavior data, and Q2 = [μ2 - βσ2, μ2 + βσ2], where β is a coefficient, and the specific value of β is obtained according to the data distribution; S303. Calculate the threshold intervals of all normal user operation behavior data and perform normalization, and Q2 = {p1, p2, p3}, where p1 represents the threshold interval of user login frequency, p2 represents the threshold interval of data transmission volume, and P3 represents the threshold interval of user access frequency; perform a correlation analysis on the network status score and the normalized normal user operation behavior data. The specific correlation analysis is as follows: Use the network status score as the 1st axis, the user login frequency as the 2nd axis, the data transmission volume as the 3rd axis, and the user access frequency as the 4th axis. The four axes evenly divide the plane rectangular coordinate system, that is, the four axes have an intersection point, and the included angle between adjacent two axes is 45°. Use the x-axis as the 1st axis, and mark the 2nd axis, 3rd axis, and 4th axis in counterclockwise order, and mark the positive directions in turn according to the positive direction of the x-axis; obtain the set of network status scores during the same time period, and the normalized user operation behavior data, including the data sets corresponding to user login frequency, data transmission volume, and user access frequency; record the corresponding data points on the respective axes according to the time sequence. For the data points on the 1st axis of network status score and the 2nd axis of user login frequency, connect two data points in the same chronological order, calculate the slope k of all the connected data point segments, and through analysis, if it satisfies k i+1 = tk i , it means that there is an association between the network status score and the user login frequency, where i represents the data number and takes positive integers greater than or equal to 1; t is the correlation coefficient; the correlation analysis between other axes and the 1st axis is the same as the above analysis content; S304. Calculate the normal user operation behavior score according to the analysis result of the correlation, so as to obtain the normal user operation behavior score interval B; If both the network status score and the user operation behavior data satisfy the correlation relationship, the normal user operation behavior score interval is calculated according to the following formula: B = t1p1 + t2p2 + t3p3, where t1 is the correlation coefficient between the 1st axis and the 2nd axis, t2 is the correlation coefficient between the 1st axis and the 3rd axis, and t3 is the correlation coefficient between the 1st axis and the 4th axis; If the network status score and the user operation behavior data do not all satisfy the correlation relationship or both do not satisfy the correlation relationship, the calculation formula for the normal user operation behavior score interval B is: B = t1p1 + t2p2 + t3p3, where t1 represents the weighting coefficient of p1, t2 represents the weighting coefficient of p2, t3 represents the weighting coefficient of p3, and t1 + t2 + t3 = 1.

4. A 5G network protection and supervision method based on artificial intelligence according to claim 3, characterized in that: The step S400 includes: S401. Collect current network metric data in real time and compare it with the threshold range Q1. If there is a situation where the current network metric data does not belong to the threshold range Q1, it indicates that the current network state is abnormal. Output a first-level network state signal and calculate the deviation value between the current network metric data and the threshold range Q1. The specific formula is: offset = (|x - x min | + |x - x max |) * (1 / 2), where x min and x max represent the minimum and maximum values of the threshold range Q1 respectively, and x represents the current network metric data. Assign a label according to the deviation value; If all current network metric data belong to the threshold range Q1, perform normalization processing, then calculate the current network status score, and compare it with the score range A of the normal network status in the historical data; if the current network status score does not belong to the score range A, it indicates that the current network status is abnormal, output a secondary network status signal, calculate the deviation value between the current network status score and the score range A, and perform corresponding marking assignment according to the deviation value; if the current network status score belongs to the score range A, it indicates that the current network status is normal, output a normal network status signal, perform marking, and assign a value of 0; and the priority of secondary anomalies is higher than that of primary anomalies. S402. Continuously collect the current user operation behavior data and compare it with the threshold range Q2; if there is a situation where the current user operation behavior data does not belong to the threshold range Q2, it indicates that the user operation behavior is abnormal, output a primary user operation behavior signal, calculate the deviation value between the current user operation behavior data and the threshold range Q2, and perform corresponding marking assignment according to the deviation value. If all current user operation behavior data belong to the threshold range Q2, perform normalization processing, then calculate the current user operation behavior score, and compare it with the normal user operation behavior score range B in the historical data; if the current user operation behavior score does not belong to the score range B, it indicates that the current user operation behavior is abnormal, output it as a secondary network status signal, calculate the deviation value between the current user operation behavior score and the score range B, and perform corresponding marking assignment according to the deviation value; if the current user operation behavior score belongs to the score range B, it indicates that the current user operation behavior is normal, output a normal user operation behavior signal, perform marking, and assign a value of 0.

5. The 5G network protection and supervision method based on artificial intelligence according to claim 4, characterized in that: The step S500 includes: S501. Obtain a signal tag according to the judgment result scored based on the current network state and user operation behavior, perform calculations based on the signal tag to obtain a set C of signal tag calculation results, and C = {c1, c2,..., c n}, where n is the number of signal tag calculation results, taking a positive integer, c n represents the nth signal tag calculation result; corresponding to the set of signal tag calculation results, the corresponding network security protection level; S502. Continuously collect and monitor network metric data and user operation behavior data, and continuously update the historical data; display the correlation between the network security status and the user operation behavior to the administrator in a visual manner, and monitor the network security status and user operation behavior in real time.

6. A 5G network protection and supervision system based on artificial intelligence, characterized in that: The system includes a data collection module, a network status analysis module, a user operation behavior analysis module, a real-time monitoring module, a security protection level adjustment module, and a visual display module; The data collection module is responsible for collecting the metric data of the 5G network, security event logs, and user operation behavior data; The network status analysis module determines whether the network status is normal based on the collected network metric data and security event logs, and calculates the network status score; the user operation behavior analysis module analyzes the operation behavior of the user in the 5G network, determines whether the user operation is normal, and calculates the user operation behavior score; The real-time monitoring module continuously collects the current network metric data and user operation behavior data, and determines whether the current network status and user operation behavior are normal; the security protection level adjustment module calculates signal markings based on the results of the network status and user operation behavior scores, and then determines the corresponding network security protection level; The visual display module displays the correlation between the network security status and the user operation behavior to the administrator in a visual manner.

7. An AI-based 5G network protection and supervision system according to claim 6, characterized in that: The data collection module includes a network monitoring device unit, a security event log unit, and a user operation behavior unit; The network monitoring device unit is responsible for providing network performance data and monitoring the network health status; The security event log unit records the log data of security events occurring in the network; the user operation behavior unit collects the operation behavior data of users on the network; The network status analysis module includes a security event log extraction unit, a network status judgment unit, and a network status scoring unit; The security event log extraction unit extracts security event logs from the collected historical data; the network status judgment unit determines whether the network is in a normal operating state by analyzing network metric data and security event logs; the network status scoring unit calculates a network status score based on the network status judgment result.

8. An AI-based 5G network protection and supervision system according to claim 6, characterized in that: The user operation behavior analysis module includes a time period screening unit, a user operation behavior judgment unit, and a user operation behavior scoring unit; The time period screening unit screens out the time period data when the network status is normal; the user operation behavior judgment unit determines whether the user operation is normal based on the user operation behavior data; the user operation behavior scoring unit calculates a user operation behavior score based on the user operation behavior judgment result. The real-time monitoring module includes a real-time data collection unit, a network status judgment unit, and a user operation behavior judgment unit; The real-time data collection unit collects the current network metric data and user operation behavior data in real time; The network status judgment unit determines whether the current network status is normal by comparing the real-time network metric data with a threshold; the user operation behavior judgment unit determines whether the current user operation is normal by comparing the real-time user operation behavior data with a threshold.

9. The 5G network protection and supervision system based on artificial intelligence according to claim 6, wherein: The security protection level adjustment module includes a signal marking calculation unit and a protection level unit; The signal marking calculation unit calculates a signal mark based on the results of the network status and the user operation behavior score; the protection level unit determines the corresponding network security protection level based on the signal mark calculation result. The visualization display module includes a network security status display unit and a user operation behavior display unit; the network security status display unit visually displays the network security protection status to the administrator; the user operation behavior display unit visually displays the operation behavior of users on the network and associates it with the network security status.

Citation Information

Patent Citations

  • Network dynamic defense system and method

    CN109347830A

  • Computer information security monitoring method and system and storage medium

    CN116488939A