Abnormal traffic interception method, device, equipment, medium and product

By determining the account type and selecting the appropriate target processing device upon receiving an account login request, and using analog communication network equipment to intercept abnormal traffic, the problem of the inability to intercept abnormal traffic in a timely manner in existing technologies is solved, thereby improving security.

CN118748601BActive Publication Date: 2026-03-31EVERSEC BEIJING TECH
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-06-17
Publication Date
2026-03-31

AI Technical Summary

Technical Problem

In existing technologies, abnormal traffic cannot be blocked in a timely manner when abnormal account behavior is detected, leading to security risks during account use.

Method used

When an account login request is received, the system determines the account type and selects an appropriate target processing device based on its status. It then uses devices such as simulated service gateways or simulated mobility management units to simulate communication network functions, thereby intercepting abnormal traffic. For example, it can provide feedback on failure information or interrupt routing during the routing allocation phase to block abnormal traffic.

Benefits of technology

It enables timely interception of abnormal traffic when abnormal account activity is detected, reducing security risks during account usage and improving security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118748601B_ABST
    Figure CN118748601B_ABST
Patent Text Reader

Abstract

The application discloses an abnormal traffic interception method, device, equipment, medium and product, wherein the method comprises the following steps: when an account login request is received, determining the account type of an account to be authenticated in the account login request; if the account to be authenticated corresponds to an abnormal account type, determining the traffic interception stage corresponding to the account to be authenticated and the target processing equipment corresponding to the account to be authenticated; and based on the target processing equipment, performing abnormal traffic interception on the account to be authenticated in the traffic interception stage. Different traffic interception stages are determined according to different use stages of the account, so that the abnormal traffic of the account can be intercepted more targetedly, the abnormal traffic of the account is intercepted in time when the account is detected to be abnormal, and therefore the problem of security risks in the use process of the account is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of internet security technology, and in particular to a method, apparatus, device, medium, and product for intercepting abnormal traffic. Background Technology

[0002] As the scale of internet usage grows larger, internet security and prevention become increasingly challenging.

[0003] Currently, abnormal user behavior during account usage is usually addressed through network security incident monitoring or early warning. However, such account security measures lack practical and effective management tools for users with low security awareness and cannot effectively intercept abnormal account traffic.

[0004] To solve the above problems, the methods for intercepting abnormal traffic need to be improved. Summary of the Invention

[0005] This invention provides a method, apparatus, device, medium, and product for intercepting abnormal traffic, in order to solve the problem in the prior art that when abnormal behavior of an account is detected, abnormal traffic cannot be intercepted in a timely manner, which may lead to security risks to the account during use.

[0006] In a first aspect, embodiments of the present invention provide a method for intercepting abnormal traffic, comprising:

[0007] Upon receiving an account login request, the account type of the account to be authenticated in the account login request is determined; wherein, the account type is a normal account or an abnormal account;

[0008] If the account to be authenticated corresponds to the abnormal account type, then the traffic interception stage corresponding to the account to be authenticated and the target processing device corresponding to the account to be authenticated are determined; wherein, the target processing device is a simulated service gateway corresponding to the service gateway, a simulated packet data gateway corresponding to the packet data gateway, or a simulated mobility management unit corresponding to the mobility management unit, and the service gateway and the mobility gateway are gateway devices in the communication system;

[0009] Based on the target processing device, abnormal traffic is intercepted for the account to be authenticated during the traffic interception phase.

[0010] Secondly, embodiments of the present invention also provide an abnormal traffic interception device, comprising:

[0011] The type determination module is used to determine the account type of the account to be authenticated in the account login request when the account login request is received; wherein the account type is a normal account or an abnormal account;

[0012] The device determination module is used to determine the traffic interception stage corresponding to the account to be authenticated and the target processing device corresponding to the account to be authenticated if the account to be authenticated corresponds to the abnormal account type; wherein, the target processing device is a simulated service gateway corresponding to the service gateway, a simulated packet data gateway corresponding to the packet data gateway, or a simulated mobility management unit corresponding to the mobility management unit, and the service gateway and the mobility gateway are gateway devices in the communication system;

[0013] The interception module is used to intercept abnormal traffic of the account to be authenticated during the traffic interception phase, based on the target processing device.

[0014] Thirdly, embodiments of the present invention also provide an electronic device, comprising:

[0015] At least one processor; and

[0016] A memory communicatively connected to the at least one processor; wherein,

[0017] The memory stores a computer program that can be executed by the at least one processor, which enables the at least one processor to perform the abnormal traffic interception method according to any embodiment of the present invention.

[0018] Fourthly, embodiments of the present invention also provide a computer-readable storage medium storing computer instructions, which are used to cause a processor to execute and implement the abnormal traffic interception method described in any embodiment of the present invention.

[0019] Fifthly, embodiments of the present invention also provide a computer program product, including a computer program that, when executed by a processor, implements the abnormal traffic interception method as described in any of the embodiments of the present invention.

[0020] The technical solution of this invention determines the account type of the account to be authenticated in the login request upon receipt. If the account to be authenticated corresponds to an abnormal account type, the traffic interception stage corresponding to the account to be authenticated and the target processing device corresponding to the account to be authenticated are determined. Based on the target processing device, abnormal traffic is intercepted for the account to be authenticated during the traffic interception stage. In this technical solution, after determining that the account to be authenticated is an abnormal account, the traffic interception stage corresponding to the account to be authenticated is determined by the routing allocation status corresponding to the account to be authenticated, thereby determining the target processing device used in the traffic interception stage. Then, the target processing device simulates the corresponding device function in the communication network to achieve traffic interception for the account to be authenticated. For example, in the routing allocation state, if the account to be authenticated has not yet been routed, a routing allocation failure message can be fed back to the mobility management unit based on the simulated service gateway, so that the mobility management unit can feed back the corresponding login failure message to the device to which the account to be authenticated belongs, thus intercepting the abnormal traffic of the account to be authenticated. In the state where a route has been allocated, a routing interruption command can be sent to the service gateway based on the simulated mobility management unit to interrupt the routing of the account to be authenticated, thereby blocking the abnormal traffic of the account to be authenticated. This invention addresses the problem in existing technologies where abnormal traffic cannot be blocked in a timely manner when abnormal account behavior is detected, potentially leading to security risks during account use. By determining different traffic blocking stages based on the different usage stages of the account, abnormal traffic can be blocked more effectively. This enables timely blocking of abnormal traffic when abnormal account behavior is detected, thereby reducing security risks during account use.

[0021] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description

[0022] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0023] Figure 1 This is a flowchart of an abnormal traffic interception method provided according to Embodiment 1 of the present invention;

[0024] Figure 2 This is a schematic diagram of an account type identification method provided according to Embodiment 1 of the present invention;

[0025] Figure 3 This is a schematic diagram of routing allocation for an account to be authenticated according to Embodiment 1 of the present invention;

[0026] Figure 4 This is a flowchart of an abnormal traffic interception method provided according to Embodiment 2 of the present invention;

[0027] Figure 5 This is a schematic diagram of the structure of an abnormal traffic interception device provided in Embodiment 3 of the present invention;

[0028] Figure 6 This is a schematic diagram of the structure of an electronic device that implements the abnormal traffic interception method of this invention. Detailed Implementation

[0029] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention. The acquisition, transmission, storage, use, and processing of data in the technical solutions of this application comply with the relevant provisions of national laws and regulations. It should be noted that in the embodiments of this application, certain software, components, or models and other existing solutions in the industry may be mentioned. These should be considered as exemplary, and their purpose is only to illustrate the feasibility of implementing the technical solutions of this application, but it does not mean that the applicant has or necessarily used such solutions.

[0030] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in sequences other than those illustrated or described herein.

[0031] Example 1

[0032] Figure 1This is a flowchart illustrating an abnormal traffic interception method provided in Embodiment 1 of the present invention. This embodiment is applicable to situations where abnormal behavior of an account is detected, a traffic interception stage corresponding to the account is determined, and a target processing device corresponding to the traffic interception stage is used to intercept abnormal traffic from the account. The target processing device is a simulated service gateway corresponding to a service gateway, a simulated packet data gateway corresponding to a packet data gateway, or a simulated mobility management unit corresponding to a mobility management unit. The service gateway and the mobility gateway are gateway devices in a communication system. This method can be executed by an abnormal traffic interception device, which can be implemented in hardware and / or software and can be configured in a computing device capable of executing the abnormal traffic interception method.

[0033] like Figure 1 As shown, the method includes:

[0034] S110. Upon receiving an account login request, determine the account type of the account to be authenticated in the account login request.

[0035] The account type is categorized as either a normal account or an abnormal account. An account awaiting verification can be understood as an account undergoing security risk detection. For example, if the account awaiting verification engages in normal phone calls or internet activities, it can be determined that the account type is normal. If the account awaiting verification logs into suspicious websites or links, or communicates with accounts exhibiting potential risks, it is determined that the account type is abnormal.

[0036] In practical applications, to ensure user security during network communication and internet access, it is necessary to constantly monitor the account types of accounts awaiting authentication. This is especially important for users with weak risk awareness, requiring stricter risk prevention measures during account risk detection. Specifically, each time a user logs in, they need to do so through a communication base station. Therefore, it is possible to periodically or in real-time obtain at least one account awaiting authentication from the communication base station over a certain period and identify the account type of each account.

[0037] Optionally, the account type of the account to be authenticated in the account registration request can be determined, including: if the pre-defined abnormal account table includes the account to be authenticated, then the account type corresponding to the account to be authenticated is determined to be an abnormal account type.

[0038] The abnormal account table can be understood as a pre-built information table used to record abnormal accounts. This table records not only the account code of the abnormal account, but also the user associated with the abnormal account and the device code of the terminal device used by the abnormal account.

[0039] In practical applications, to quickly determine whether an account to be authenticated is an abnormal account, after receiving at least one account to be authenticated, an abnormal account table can be used to check the account. Generally, based on a large number of historically collected account behaviors, abnormal accounts with potential risks can be identified. An abnormal account table is generated based on at least one abnormal account and updated as abnormal accounts are statistically summarized. Furthermore, after receiving at least one account to be authenticated, an account check is performed on the account to be authenticated based on the abnormal account table. If the abnormal account table contains the account to be authenticated, or account information associated with the account to be authenticated, then the account type corresponding to the account to be authenticated can be determined to be abnormal; otherwise, the account type can be determined to be normal.

[0040] In a specific example, such as Figure 2 As shown, upon receiving at least one account to be authenticated, the account is detected based on preset user identification characteristics (i.e., the abnormal account table). For example, the mobile phone number corresponding to the account, or the IMSI (Mobile Subscriber Identity) or IMEI (Mobile Equipment Identity) associated with the account is used for detection. After the account to be authenticated enters the network service range, the user needs to apply for account login using that account. In this technical solution, the login requests corresponding to each account to be authenticated can be periodically acquired. Upon receiving each login request, a registration failure request is sent to users whose preset user characteristics are matched, or an offline notification is sent to users whose preset user characteristics are matched (i.e., if the abnormal account table contains an account to be authenticated, then the account type of the account to be authenticated is determined to be an abnormal account type).

[0041] S120. If the account to be authenticated corresponds to an abnormal account type, then determine the traffic interception stage corresponding to the account to be authenticated, and the target processing device corresponding to the account to be authenticated.

[0042] The traffic interception phase includes the routing allocation phase and the account usage phase. The target processing device refers to the device used to intercept abnormal traffic from the account to be authenticated. It should be noted that in the network connection architecture, such as... Figure 3As shown, the communication system includes a Serving Gateway (SGW), a Packet Data Network Gateway (PGW), and a Mobility Management Entity (MME). The eNodeB represents the communication base station in the system, used to receive account login requests from user equipment. The SGW is a key element in the mobile communication network, responsible for handling user data transmission, such as user data traffic. The PGW is another key element in the mobile communication network, responsible for connecting the mobile network to external data networks, such as the Internet. The MME is a device used to receive account login requests sent by accounts to be authenticated. The target processing device is either a simulated Serving Gateway corresponding to the Serving Gateway, a simulated Packet Data Network Gateway corresponding to the Packet Data Network Gateway, or a simulated Mobility Management Entity corresponding to the Mobility Management Entity. The Serving Gateway and Mobility Gateway are gateway devices in the communication system. In other words, the target processing device is the device used for the functions of the gateway device or the Mobility Management Entity in the communication system.

[0043] Generally, an account awaiting authentication needs to undergo network authentication before it can access network or communication services. Each time the device is powered on or re-enters network coverage, a new route needs to be assigned to the account before it can access the network or communication services. Therefore, if an account is determined to be abnormal, traffic can be blocked during the route assignment phase to prevent it from accessing network services. It should be noted that, given the large number of accounts registered or logged in within a communication base station, if an abnormal account has already been assigned a route when it is identified as abnormal during periodic authentication, traffic blocking should be initiated as quickly as possible. This traffic blocking phase corresponds to the account usage phase.

[0044] Accordingly, the target processing device used for abnormal traffic interception of abnormal accounts differs at different traffic interception stages. Optionally, determining the traffic interception stage corresponding to the account to be authenticated and the target processing device corresponding to the account to be authenticated includes: after receiving the session creation request sent by the mobility management unit, determining the routing allocation status of the account to be authenticated; if the routing allocation status is unallocated, then determining the traffic interception stage as the routing allocation stage, and determining the target processing device corresponding to the account to be authenticated as the simulated service gateway.

[0045] In practical applications, after receiving an account login request from an account to be authenticated, the MME will send a session creation request to the SGW, which will then forward the request to the PGW so that the PGW can allocate routes for the account to be authenticated. Further, if a route is successfully allocated for the account to be authenticated, the PGW will send a route allocation success message to the SGW, which will then send the message back to the MME. The MME will then send a corresponding authentication success message to the device used by the account to be authenticated, allowing the user to communicate or access network services normally through the account.

[0046] If the account to be authenticated is an abnormal account, it is necessary to further determine whether the PGW has allocated the corresponding routing information to the account to be authenticated. If so, the routing allocation status of the account to be authenticated is allocated; otherwise, the routing allocation status is unallocated. Then, the routing allocation stage of the account to be authenticated is determined based on the routing allocation status, and the target processing device corresponding to the account to be authenticated is determined to be the simulated service gateway.

[0047] S130. Based on the target processing device, abnormal traffic is intercepted for the account to be authenticated during the traffic interception phase.

[0048] In practical applications, if the routing allocation status is unallocated, based on the target processing device, abnormal traffic interception is performed on the account to be authenticated during the traffic interception phase. This includes: sending routing allocation failure information to the mobility management unit in the communication system based on the simulated service gateway, so that during the routing allocation phase, the mobility management unit can intercept abnormal traffic on the account to be authenticated based on the first feedback information.

[0049] The first feedback information can be understood as a routing allocation failure information, which is sent by the simulated service gateway to the mobility management unit.

[0050] Based on the above example, the target processing device is a simulated service gateway. In this technical solution, the simulated service gateway can be used to simulate the service gateway feeding back routing allocation status information to the mobility management unit. If the routing allocation status information is routing allocation failure information, the mobility management unit will feed back login failure information to the communication device to which the account to be authenticated belongs. For example, the message fed back by the mobility management unit to the communication device is "The current network status is poor, and login cannot be completed normally. Please log in later."

[0051] In other words, when it is determined that the account to be authenticated is an abnormal account and the corresponding routing information has not yet been assigned to the account to be authenticated, the abnormal traffic of the account to be authenticated can be intercepted during the routing assignment stage, blocking the normal login of the account to be authenticated, thereby preventing the account to be authenticated from engaging in abnormal network behavior, such as abnormal website login, abnormal link login, abnormal transactions, and abnormal network communication.

[0052] The technical solution of this invention determines the account type of the account to be authenticated in the login request upon receipt. If the account to be authenticated corresponds to an abnormal account type, the traffic interception stage corresponding to the account to be authenticated and the target processing device corresponding to the account to be authenticated are determined. Based on the target processing device, abnormal traffic is intercepted for the account to be authenticated during the traffic interception stage. In this technical solution, after determining that the account to be authenticated is an abnormal account, the traffic interception stage corresponding to the account to be authenticated is determined by the routing allocation status corresponding to the account to be authenticated, thereby determining the target processing device used in the traffic interception stage. Then, the target processing device simulates the corresponding device function in the communication network to achieve traffic interception for the account to be authenticated. For example, in the routing allocation state, if the account to be authenticated has not yet been routed, a routing allocation failure message can be fed back to the mobility management unit based on the simulated service gateway, so that the mobility management unit can feed back the corresponding login failure message to the device to which the account to be authenticated belongs, thus intercepting the abnormal traffic of the account to be authenticated. In the state where a route has been allocated, a routing interruption command can be sent to the service gateway based on the simulated mobility management unit to interrupt the routing of the account to be authenticated, thereby blocking the abnormal traffic of the account to be authenticated. This invention addresses the problem in existing technologies where abnormal traffic cannot be blocked in a timely manner when abnormal account behavior is detected, potentially leading to security risks during account use. By determining different traffic blocking stages based on the different usage stages of the account, abnormal traffic can be blocked more effectively. This enables timely blocking of abnormal traffic when abnormal account behavior is detected, thereby reducing security risks during account use.

[0053] Example 2

[0054] Figure 4 The flowchart below shows a method for intercepting abnormal traffic according to Embodiment 2 of the present invention. Optionally, if the route allocation status is allocated, abnormal traffic interception is performed on the account to be authenticated during the traffic interception stage based on the target processing device. This includes: sending a route interruption command to the service gateway based on the simulated mobility management unit, so that the service gateway forwards the route interruption command to the packet data gateway, and the packet data gateway interrupts the current allocated route of the account to be authenticated, so as to intercept abnormal traffic of the account to be authenticated during the account usage stage.

[0055] like Figure 4 As shown, the method includes:

[0056] S210. Upon receiving an account login request, determine the account type of the account to be authenticated in the account login request.

[0057] S220. If the route allocation status is allocated, then the traffic interception stage is determined to be the account usage stage, and the target processing device is determined to be the simulated mobility management unit.

[0058] In this technical solution, if the routing allocation status of the account to be authenticated is "allocated," it means that the account has already connected to the communication system and can normally provide network services. At this point, if traffic interception of the account to be authenticated is desired, it can only be done during the account usage phase, and the target processing device for traffic interception of the account to be authenticated is identified as a simulated mobility management unit (MMU). Specifically, the simulated MMU is used by the mobility management unit in the communication system to send a route revocation command to the serving gateway, causing the serving gateway to send the route revocation command to the packet data gateway, thus interrupting the allocated route corresponding to the account to be authenticated.

[0059] S230: Based on the target processing device, abnormal traffic is intercepted for the account to be authenticated during the traffic interception phase.

[0060] In this technical solution, if the route allocation status is already allocated, based on the target processing device, abnormal traffic interception is performed on the account to be authenticated during the traffic interception phase. This includes: sending a route interruption command to the service gateway based on the simulated mobility management unit, so that the service gateway forwards the route interruption command to the packet data gateway, and the packet data gateway interrupts the current allocated route of the account to be authenticated, so as to intercept abnormal traffic of the account to be authenticated during the account usage phase.

[0061] Furthermore, this technical solution also includes: if the account to be authenticated moves from the first administrative region to the second administrative region, and the account to be authenticated is an abnormal account, then the routing allocation failure information is fed back to the simulation service gateway based on the simulation packet data gateway; the allocation failure information is sent to the mobility management unit based on the simulation service gateway, so that the mobility management unit can feed back the account login failure information to the device to which the account to be authenticated belongs.

[0062] In practical applications, users may engage in cross-regional activities while using an account to be authenticated. For example, they may move from one administrative region to another. Consequently, the administrative region to which the account to be authenticated belongs will also change. Since existing communication systems typically manage different administrative regions separately, it is necessary to reassign corresponding routing information to the account to be authenticated when it moves from one administrative region to another.

[0063] During this process, it's possible that an account to be authenticated might be classified as a normal account type in the first administrative region, but an abnormal account type in the second administrative region. In this case, if the account to be authenticated is determined to be an abnormal account, it's necessary to re-determine the traffic interception stage corresponding to the account based on its routing allocation status, and then use the appropriate target processing device to intercept abnormal traffic from the account to be authenticated during the corresponding traffic interception stage.

[0064] The technical solution of this invention determines the account type of the account to be authenticated in the login request upon receipt. If the account to be authenticated corresponds to an abnormal account type, the traffic interception stage corresponding to the account to be authenticated and the target processing device corresponding to the account to be authenticated are determined. Based on the target processing device, abnormal traffic is intercepted for the account to be authenticated during the traffic interception stage. In this technical solution, after determining that the account to be authenticated is an abnormal account, the traffic interception stage corresponding to the account to be authenticated is determined by the routing allocation status corresponding to the account to be authenticated, thereby determining the target processing device used in the traffic interception stage. Then, the target processing device simulates the corresponding device function in the communication network to achieve traffic interception for the account to be authenticated. For example, in the routing allocation state, if the account to be authenticated has not yet been routed, a routing allocation failure message can be fed back to the mobility management unit based on the simulated service gateway, so that the mobility management unit can feed back the corresponding login failure message to the device to which the account to be authenticated belongs, thus intercepting the abnormal traffic of the account to be authenticated. In the state where a route has been allocated, a routing interruption command can be sent to the service gateway based on the simulated mobility management unit to interrupt the routing of the account to be authenticated, thereby blocking the abnormal traffic of the account to be authenticated. This invention addresses the problem in existing technologies where abnormal traffic cannot be blocked in a timely manner when abnormal account behavior is detected, potentially leading to security risks during account use. By determining different traffic blocking stages based on the different usage stages of the account, abnormal traffic can be blocked more effectively. This enables timely blocking of abnormal traffic when abnormal account behavior is detected, thereby reducing security risks during account use.

[0065] Example 3

[0066] Figure 5 This is a schematic diagram of an abnormal traffic interception device provided in Embodiment 3 of the present invention. Figure 5 As shown, the device includes: a type determination module 310, a device determination module 320, and an interception module 330.

[0067] The type determination module 310 is used to determine the account type of the account to be authenticated in the account login request when the account login request is received; wherein the account type is a normal account or an abnormal account.

[0068] The device determination module 320 is used to determine the traffic interception stage corresponding to the account to be authenticated and the target processing device corresponding to the account to be authenticated if the account to be authenticated corresponds to an abnormal account type; wherein, the target processing device is a simulated service gateway corresponding to the service gateway, a simulated packet data gateway corresponding to the packet data gateway, or a simulated mobility management unit corresponding to the mobility management unit, and the service gateway and mobility gateway are gateway devices in the communication system;

[0069] The interception module 330 is used to intercept abnormal traffic of the account to be authenticated during the traffic interception phase, based on the target processing device.

[0070] The technical solution of this invention determines the account type of the account to be authenticated in the login request upon receipt. If the account to be authenticated corresponds to an abnormal account type, the traffic interception stage corresponding to the account to be authenticated and the target processing device corresponding to the account to be authenticated are determined. Based on the target processing device, abnormal traffic is intercepted for the account to be authenticated during the traffic interception stage. In this technical solution, after determining that the account to be authenticated is an abnormal account, the traffic interception stage corresponding to the account to be authenticated is determined by the routing allocation status corresponding to the account to be authenticated, thereby determining the target processing device used in the traffic interception stage. Then, the target processing device simulates the corresponding device function in the communication network to achieve traffic interception for the account to be authenticated. For example, in the routing allocation state, if the account to be authenticated has not yet been routed, a routing allocation failure message can be fed back to the mobility management unit based on the simulated service gateway, so that the mobility management unit can feed back the corresponding login failure message to the device to which the account to be authenticated belongs, thus intercepting the abnormal traffic of the account to be authenticated. In the state where a route has been allocated, a routing interruption command can be sent to the service gateway based on the simulated mobility management unit to interrupt the routing of the account to be authenticated, thereby blocking the abnormal traffic of the account to be authenticated. This invention addresses the problem in existing technologies where abnormal traffic cannot be blocked in a timely manner when abnormal account behavior is detected, potentially leading to security risks during account use. By determining different traffic blocking stages based on the different usage stages of the account, abnormal traffic can be blocked more effectively. This enables timely blocking of abnormal traffic when abnormal account behavior is detected, thereby reducing security risks during account use.

[0071] Optionally, a type determination module is used to determine the account type corresponding to the account to be authenticated as an abnormal account type if the preset abnormal account table includes an account to be authenticated.

[0072] Optionally, the device determination module includes: a route allocation status determination unit, used to determine the route allocation status of the account to be authenticated after receiving a session creation request sent by the mobility management unit;

[0073] The first target device determination module is used to determine that the traffic interception stage is the route allocation stage if the route allocation status is unallocated, and to determine that the target processing device corresponding to the account to be authenticated is the simulated service gateway.

[0074] The second target device determination module is used to determine that the traffic interception stage is the account usage stage and the target processing device is the simulated packet data gateway if the route allocation status is allocated.

[0075] Optionally, the interception module includes: a first interception unit, used to send a route allocation failure message to the mobility management unit in the communication system based on the simulated service gateway if the route allocation status is unallocated, so that the mobility management unit can intercept abnormal traffic of the account to be authenticated based on the first feedback information during the route allocation phase.

[0076] Optionally, the interception module includes: a first interception unit, used to send a route interruption command to the service gateway based on the simulated mobility management unit if the route allocation status is allocated, so that the service gateway forwards the route interruption command to the packet data gateway, and the packet data gateway interrupts the current allocated route of the account to be authenticated, so as to intercept abnormal traffic of the account to be authenticated during the account usage phase.

[0077] Optionally, the abnormal traffic interception device also includes: an information feedback module, used to send routing allocation failure information to the simulated service gateway based on the simulated packet data gateway if the account to be authenticated moves from the first administrative region to the second administrative region and the account to be authenticated is an abnormal account;

[0078] The traffic interception module is used to send allocation failure information to the mobility management unit based on the simulated service gateway, so that the mobility management unit can report account login failure information to the device to which the account to be authenticated belongs, and intercept abnormal traffic of the account to be authenticated.

[0079] The abnormal traffic interception device provided in this embodiment of the invention can execute the abnormal traffic interception method provided in any embodiment of the invention, and has the corresponding functional modules and beneficial effects of the method execution.

[0080] Example 4

[0081] Figure 6A schematic diagram of the structure of an electronic device 10 according to an embodiment of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device may also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (e.g., helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.

[0082] like Figure 6 As shown, the electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12 or a random access memory (RAM) 13, communicatively connected to the at least one processor 11. The memory stores computer programs executable by the at least one processor. The processor 11 can perform various appropriate actions and processes based on the computer program stored in the ROM 12 or loaded from storage unit 18 into the RAM 13. The RAM 13 may also store various programs and data required for the operation of the electronic device 10. The processor 11, ROM 12, and RAM 13 are interconnected via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.

[0083] Multiple components in electronic device 10 are connected to I / O interface 15, including: input unit 16, such as keyboard, mouse, etc.; output unit 17, such as various types of displays, speakers, etc.; storage unit 18, such as disk, optical disk, etc.; and communication unit 19, such as network card, modem, wireless transceiver, etc. Communication unit 19 allows electronic device 10 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.

[0084] Processor 11 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Processor 11 performs the various methods and processes described above, such as methods for intercepting abnormal traffic.

[0085] In some embodiments, the abnormal traffic interception method may be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed on electronic device 10 via ROM 12 and / or communication unit 19. When the computer program is loaded into RAM 13 and executed by processor 11, one or more steps of the abnormal traffic interception method described above may be performed. Alternatively, in other embodiments, processor 11 may be configured to perform the abnormal traffic interception method by any other suitable means (e.g., by means of firmware).

[0086] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.

[0087] Computer programs used to implement the abnormal traffic interception method of the present invention can be written in any combination of one or more programming languages. These computer programs can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The computer programs can be executed entirely on the machine, partially on the machine, as a standalone software package partially on the machine and partially on a remote machine, or entirely on a remote machine or server.

[0088] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0089] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).

[0090] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or computing systems that include middleware components (e.g., application servers), or computing systems that include frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.

[0091] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system to address the shortcomings of traditional physical hosts and VPS services, such as high management difficulty and weak business scalability.

[0092] Example 5

[0093] This invention also provides a computer program product, including a computer program that, when executed by a processor, implements the abnormal traffic interception method provided in any embodiment of this application.

[0094] In implementing the computer program product, computer program code for performing the operations of this invention can be written in one or more programming languages ​​or a combination thereof. Programming languages ​​include object-oriented programming languages ​​such as Java, Smalltalk, and C++, as well as conventional procedural programming languages ​​such as C or similar languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0095] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.

[0096] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.

Claims

1. An abnormal traffic interception method, characterized by, Comprising: Upon receiving an account login request, determining an account type of a to-be-authenticated account in the account login request; wherein the account type is a normal account or an abnormal account; If the to-be-authenticated account corresponds to the abnormal account type, determining a traffic interception stage corresponding to the to-be-authenticated account and a target processing device corresponding to the to-be-authenticated account; wherein the target processing device is an analog service gateway corresponding to a service gateway, an analog packet data gateway corresponding to a packet data gateway, or an analog mobility management unit corresponding to a mobility management unit, and the service gateway and the mobility management unit are devices in a communication system; Based on the target processing device, performing abnormal traffic interception on the to-be-authenticated account in the traffic interception stage; wherein the traffic interception stage includes a route allocation stage and an account stage; The determination of the traffic interception stage corresponding to the to-be-authenticated account and the target processing device corresponding to the to-be-authenticated account comprises: After receiving a session creation request sent by the mobility management unit, determining a route allocation state of the to-be-authenticated account; If the route allocation state is an unallocated state, determining that the traffic interception stage is the route allocation stage and the target processing device corresponding to the to-be-authenticated account is the analog service gateway; If the route allocation state is an allocated state, determining that the traffic interception stage is an account usage stage and the target processing device is the analog mobility management unit.

2. The method of claim 1, wherein, The determination of the account type of the to-be-authenticated account in the account login request comprises: If the to-be-authenticated account is included in a preset abnormal account table, it is determined that the account type corresponding to the to-be-authenticated account is an abnormal account type.

3. The method of claim 1, wherein, If the route allocation state is an unallocated state, the abnormal traffic interception on the to-be-authenticated account in the traffic interception stage based on the target processing device comprises: Based on the analog service gateway, sending route allocation failure information to the mobility management unit in the communication system, so that in the route allocation stage, the mobility management unit performs abnormal traffic interception on the to-be-authenticated account according to first feedback information.

4. The method of claim 1, wherein, If the route allocation state is an allocated state, the abnormal traffic interception on the to-be-authenticated account in the traffic interception stage based on the target processing device comprises: Based on the analog mobility management unit, sending a route interruption instruction to the service gateway, so that the service gateway forwards the route interruption instruction to the packet data gateway, and the packet data gateway interrupts the currently allocated route of the to-be-authenticated account to perform abnormal traffic interception on the to-be-authenticated account in the account usage stage.

5. The method of claim 1, wherein, Further comprising: If the to-be-authenticated account moves from a first administrative region to a second administrative region and the to-be-authenticated account is an abnormal account, feeding back route allocation failure information from the analog packet data gateway to the analog service gateway; The simulation service gateway sends the allocation failure information to the mobile management unit based on the simulation, so that the mobile management unit feeds back account login failure information to the device to which the to-be-authenticated account belongs, and performs abnormal traffic interception on the to-be-authenticated account.

6. An apparatus for intercepting abnormal traffic, characterized by comprising: Comprise: The type determination module is configured to determine the account type of the to-be-authenticated account in the account login request when the account login request is received; wherein the account type is a normal account or an abnormal account; The device determination module is configured to determine a traffic interception stage corresponding to the to-be-authenticated account and a target processing device corresponding to the to-be-authenticated account if the to-be-authenticated account corresponds to the abnormal account type; wherein the target processing device is a simulation service gateway corresponding to a service gateway, a simulation packet data gateway corresponding to a packet data gateway, or a simulation mobile management unit corresponding to a mobile management unit, and the service gateway and the mobile management unit are devices in a communication system; The interception module is configured to perform abnormal traffic interception on the to-be-authenticated account in the traffic interception stage based on the target processing device; Wherein, the traffic interception stage includes a route allocation stage and an account stage; The device determination module includes a route allocation state determination unit configured to determine the route allocation state of the to-be-authenticated account after receiving a session creation request sent by the mobile management unit; The first target device determination module is configured to determine that the traffic interception stage is the route allocation stage and determine that the target processing device corresponding to the to-be-authenticated account is the simulation service gateway if the route allocation state is the unallocated state; The second target device determination module is configured to determine that the traffic interception stage is the account usage stage and determine that the target processing device is the simulation mobile management unit if the route allocation state is the allocated state.

7. An electronic device, comprising: The electronic device comprises: At least one processor; and The memory is in communication connection with the at least one processor; wherein The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor to enable the at least one processor to execute the abnormal traffic interception method of any one of claims 1-5.

8. A computer-readable storage medium, characterized in that, The computer readable storage medium stores computer instructions for enabling the processor to execute the abnormal traffic interception method of any one of claims 1-5 when executed by the processor.

9. A computer program product comprising a computer program, characterized in that, The computer program, when executed by the processor, implements the abnormal traffic interception method of any one of claims 1-5.

Citation Information

Patent Citations

  • Abnormal internet traffic monitoring method, device and system and storage medium

    CN114978640A

  • Secure interaction method for network access and user authentication based on zero-trust system

    CN116192497A