A satellite direct connection communication-oriented distributed cooperative wireless access security method
By introducing distributed cooperative drones into the satellite direct communication network for local clustering and incremental clustering, the problems of poor attack detection reliability and high computational overhead in the satellite direct communication network are solved, and low-cost and efficient attack detection is achieved.
Patent Information
- Application Number
- CN202411241433.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-05
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2044-09-05
AI Technical Summary
Satellite direct communication networks suffer from problems such as poor attack detection reliability, high computational overhead, and inability to continuously detect attacks. Existing technologies are particularly difficult to effectively detect wireless attacks in highly dynamic and resource-constrained environments.
A distributed collaborative wireless access security method is adopted, drones are used for local clustering and channel feature detection, and an incremental clustering algorithm is combined for attack detection to reduce computational complexity and achieve continuous detection.
Through distributed collaboration and incremental clustering, the computational and communication overheads are reduced, the reliability and accuracy of attack detection are improved, and it is suitable for satellite direct communication scenarios.
Smart Images

Figure CN118972852B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The application belongs to the technical field of satellite communication, and particularly relates to a distributed cooperative wireless access security method for satellite direct connection communication. BACKGROUND
[0002] In a satellite direct connection mobile communication network, the satellite node has a large coverage area, a large number of service terminals, and a long wireless propagation link, and faces very serious problems of wireless attacks such as interference, fraud, and Distributed Denial of Service (DDoS). However, the satellite node has limited processing capacity and coverage time, and there are challenges in attack detection and protection capability and efficiency.
[0003] Currently, some research proposes an attack detection technology based on upper-layer network features, that is, based on the traffic in the upper-layer network, important features that increase relevance and reduce complexity are selected from the data set using sequential forward and other feature selection methods, and then a model is trained using machine learning, deep learning, and other methods to distinguish between abnormal and normal activities. In addition, some research attempts to use physical layer features for attack detection, that is, hardware features such as Carrier Frequency Offset (CFO) or channel features such as Channel State Information (CSI) are used, and whether it exceeds the threshold value is compared with the reference value of the legal user to determine whether the user is legal or illegal. However, single physical layer features have low reliability, and the physical layer features used for detection gradually expand from single-dimensional physical layer features to multi-dimensional physical layer features. Further attack detection research proposes to use centralized machine learning methods to replace traditional threshold-based methods, effectively increasing detection accuracy and reliability.
[0004] The above research all uses the ground control center to implement attack detection. Since the new generation of satellite nodes have certain processing capabilities, they are called regenerative mode satellites, and if satellite local attack detection can be supported, better real-time performance can be achieved. Moreover, under the trend of space-air-ground integration, satellite nodes can further cooperate with unmanned aerial vehicles (UAVs) that are flexible, mobile, and sensitive. Existing research shows that unmanned aerial vehicles (UAVs) can be used as quantum relays to effectively enhance the security of long-distance model transmission using a quantum authorization federated learning framework.
[0005] Currently, the existing technical solutions and their technical problems are as follows:
[0006] (1) Attack detection scheme based on upper-layer network features
[0007] Attack detection solutions based on upper-layer network features use data selection algorithms to select the most relevant features from a large number of traffic features, increasing computational cost and complexity. Furthermore, as the number of network service terminals increases in the future, attacks will become more concealed. Existing attack detection solutions based on upper-layer traffic features will struggle to effectively detect attacks, and even if they do, it will take a long time.
[0008] (2) Attack detection scheme based on physical layer characteristics
[0009] Attack detection solutions based on physical layer features utilize centralized machine learning to replace traditional threshold-based methods to increase the accuracy and reliability of attack detection. However, existing attack detection based on physical layer features is difficult to apply in satellite-based mobile communication networks. This is due to two reasons: First, the long transmission distance of the link makes it difficult to accurately measure physical layer features, resulting in poor reliability and accuracy in attack detection; second, due to the limited resources of satellite nodes, existing attack detection technologies based on centralized machine learning have high computational overhead, making them difficult to implement in resource-constrained networks.
[0010] (3) Both of the above-mentioned existing technical solutions use a ground control center to implement attack detection. However, in order to obtain the corresponding data, multiple communication transmissions are required, resulting in high communication overhead and computational complexity. In addition, most existing attack detection technologies focus on attack detection solutions for static nodes and do not consider the problem of frequent node switching. As a result, existing attack detection solutions are unable to collect sufficient data, resulting in a decrease in detection accuracy and increasing the difficulty of real-time continuous detection.
[0011] In summary, this patent proposes a distributed collaborative wireless access security solution for satellite direct communication, which fundamentally solves the problems of poor attack detection reliability, inability to continuously detect, and high computational overhead caused by long-distance and high-dynamic characteristics in the mobile phone direct communication environment. Summary of the Invention
[0012] In view of the problems existing in the prior art, the present invention provides a distributed collaborative wireless access security method for satellite direct communication.
[0013] The technical solutions adopted by the present invention to solve the technical problems are as follows:
[0014] A distributed collaborative wireless access security method for satellite direct communication of the present invention comprises the following steps:
[0015] S1: Model training and updating stage;
[0016] S1.1: When the user is communicating with the satellite base station normally, N u The drone moves at a constant speed according to the pre-set trajectory, monitors the user access situation, and collects data at the time Ttw Collect user signals and calculate the detection sample S(t) composed of RSS and CFO;
[0017] S1.2: The drone uses the detection sample S(t) as local data and uses the local clustering algorithm to combine the K nearest neighbor kernel density and high density nearest neighbor to generate local clustering k l Atomic clusters;
[0018] S1.3: Based on the clustered atomic clusters, the drone uses Gaussian model parameter estimation to generate a Gaussian model corresponding to each atomic cluster. The mean, covariance, and number of samples of the Gaussian model form a local model and send the local model to the aggregation center.
[0019] S1.4: The aggregation center aggregates the local models into a global model and obtains K cluster sets;
[0020] S1.5: The aggregation center is a drone or a satellite. If the aggregation center is a drone, the global model needs to be sent to the satellite. If the aggregation center is a satellite, the global model does not need to be sent to the satellite.
[0021] S1.6: The satellite obtains the final K cluster sets C'={C'1,C'2,...,C' based on the global model K}, C' K ={μ' K ,∑' K ,n' K}, μ' K ,∑' K 、n' K Represent the mean, covariance and number of samples of the K-th cluster respectively;
[0022] S1.7: When a satellite switch occurs, the source satellite will detect the attacker's global model parameter I 0 The target satellite uses the incremental clustering algorithm to update the global model and obtain the updated global model parameters I update ;
[0023] S2: attack detection phase;
[0024] S2.1: The satellite detects the occurrence of an attack and estimates the number of attackers through binary hypothesis testing;
[0025] S2.2: When a satellite switch occurs, the source satellite will detect the attacker’s global model parameter I 0 The target satellite uses the incremental clustering algorithm in step S1.7 to update the global model and obtain the updated global model parameters I update ,Then perform attack detection and attacker number estimation according to step S2.1;
[0026] S2.3: When the number of UAVs N u is greater than or equal to 3, the positioning of the attacker can be realized.
[0027] Further, in step S1.2, in the local clustering process, the detection samples S(t) are automatically divided into different clusters, and the detection samples in the same cluster are considered as samples from the same user.
[0028] Further, the specific implementation process of the local clustering algorithm is as follows:
[0029] ①All sample points in the UAV data set use K-neighbor kernel density to represent the local density of each sample point, and high-density neighbor points are found according to the local density, and core objects are determined;
[0030] ②All sample points in the UAV data set are based on high-density neighbor points to construct a graph g=(V, A), where the vertex V represents the sample point, and each directed edge in A is from a non-core object to its high-density neighbor point, and a core object and its child nodes form an atomic cluster.
[0031] Further, in step S1.3, the mean, covariance and sample number of all Gaussian models are constructed into a local model x represents the detection sample of the user, μ i represents the mean of the i-th atomic cluster, ∑ i represents the covariance of the i-th atomic cluster.
[0032] Further, in step S1.4, the specific implementation process of the aggregation center for aggregating the local model into a global model is as follows:
[0033] ①The aggregation center calculates the model correlation value of each two Gaussian models i and j in the local model based on the KS statistic, and the model correlation value of Gaussian models i and j is α i,j = Sup x |F i (x)-F j (x)|, where F i (x) and F j (x) represent the distribution functions of Gaussian models i and j, respectively;
[0034] ②The aggregation center obtains a correlation value matrix of size S 2 by pairwise calculating the model correlation value; if two model correlation values satisfy , then the two Gaussian models belong to the same distribution, and the two Gaussian models are merged, where α represents the significance level, , then the mean of the merged Gaussian model is μ ij =(ni μ i +n j μj ) / (n i +n j ), the combined covariance is n i and n j Respectively represent the number of samples of the i-th and j-th Gaussian models, μ i and μ j Represent the means of the i-th and j-th Gaussian models, ∑ i and ∑ j denote the covariance of the i-th and j-th Gaussian models respectively.
[0035] Furthermore, in step S1.7, the specific implementation process of the incremental clustering algorithm is as follows:
[0036] ① The UAV is based on the source global model parameter I 0 Get the source global model represents the mean of the i-th cluster, Denote the covariance of the i-th cluster and use this source global model as the new local model;
[0037] ②When a new sample x is collected q When , the UAV classifies the new data based on the source global model;
[0038] ③ The drone identifies outliers based on CB-MONNAD and records all outliers within the data collection time as O A ;
[0039] ④ The outlier O collected by the drone A As local data, we obtain the local clustering algorithm in step S1.2. Gaussian model of the new cluster set;
[0040] ⑤ The drone updates and optimizes the parameters of the original cluster based on the non-outlier part of the new data to obtain an updated set of local model parameters;
[0041] ⑥ The aggregation center aggregates the local model to obtain the updated global model parameters. If the aggregation center is a drone, the updated local model parameter set is transmitted between adjacent drones. The UAV performs local model aggregation to obtain updated global model parameters I update , and then transmit the global model to the satellite; if the aggregation center is a satellite, the drone will update the local model parameter set Sent to the satellite, the satellite performs local model aggregation to obtain the updated global model parameters I update .
[0042] Furthermore, in step ②, when a new sample x is collected q When , the specific implementation process of the drone classifying new data based on the source global model is as follows:
[0043] Calculate sample x q The posterior probability generated by each cluster set, sample x q The probability of being generated by the j-th cluster set is represents the mean of the j-th cluster set, represents the covariance of the j-th cluster set, λ q For sample x q The cluster number of the sample x q according to into the corresponding cluster, y qj Represents x q The probability of being generated by the j-th cluster set.
[0044] Furthermore, in step ③, the specific implementation process of the drone identifying outliers based on CB-MONNAD is as follows:
[0045] Assumptions is a cluster λ q The dataset, the class-based K-distance is the dataset Sample x q and sample x p The distance between It satisfies the following two conditions: there are at least K samples So that dist(x q ,x' p )≤dist(x q ,x p )∧x' p ∈λ q , and there are at most K samples, so that dist(x q ,x' p ) <dist(x q ,x p )∧x' p ∈λ q ,dist(x q ,x' p ) represents the sample x q and sample x' p The distance between them, dist(x q ,x p ) represents the sample x q and sample x p the distance between them;
[0046] Sample xq The class-based K-distance field contains samples x q The distance between The sample is expressed as:
[0047]
[0048] Sample x q The class-based local reachability density lrd(x q ) is expressed as:
[0049]
[0050] Sample x q The class-based local outlier factor LOF is expressed as:
[0051]
[0052] Drone calculates sample x based on LOF q The specific calculation formula of the CB-MONNAD score is as follows:
[0053]
[0054] If the CB-MONNAD score of the newly collected sample exceeds the specified threshold m , then mark it as an outlier, and record all outliers within the data collection time as O A .
[0055] Furthermore, the specific implementation process of step S2.1 is as follows:
[0056] When the attack is a DDoS attack, if the number of samples of the received cluster is greater than the threshold θ, the cluster is a DDoS attack cluster, and the total number of DDoS attack clusters is regarded as the number of DDoS attackers, which is described as:
[0057] H0:n′ K ≤θ,
[0058] H1:n′ K >θ,
[0059] Among them, H0 represents the legitimate user, H1 represents the attacker, and the number of clusters that meet the attacker H1 condition is the number of attackers, n' K Indicates the number of samples of the received cluster;
[0060] When the attack is other attacks, the signal characteristics of the legitimate user are known, and the identity signature reference vector of the Kth legitimate user is A K , then the attack detection process is transformed into the clustering model mean and the reference vector A KFor comparison, it is expressed as:
[0061] H0:d(μ′ K ,A K )≤τ,
[0062] H1:d(μ ′ K,A K )>τ,
[0063] Where d(μ' K ,A K )=(μ' K ,A K )(∑' K ) -1 μ' K ,A K ) T, μ' K represents the mean of the received clusters, τ represents the threshold; the total number of deceptive clusters can be regarded as the number of deceptive attackers.
[0064] Furthermore, the threshold θ is related to the number of preambles sent by legitimate users and attackers during the data collection period, [T tw / T in ]<θ<[T tw / T ain ], T in and T ain T represents the time interval between two preamble transmissions of the legitimate user and the attacker, respectively. tw Indicates the data collection time.
[0065] The beneficial effects of the present invention are:
[0066] The key point of this invention is to introduce distributed clustering and multi-UAV collaboration to assist satellites in attack detection, and further design an incremental clustering method to achieve continuous detection under conditions of frequent satellite switching.
[0067] Compared with the prior art, the present invention has the following advantages:
[0068] (1) Compared with the current attack detection scheme based on upper-layer network features, the present invention uses the inherent channel feature Received Signal Strength (RSS) in communication and the feature CFO based on device defects. It does not require a large amount of computational overhead and has low computational overhead. It can effectively detect attackers when the number of service terminals increases.
[0069] (2) Compared to current attack detection solutions based on physical layer features, this invention uses multi-node collaboration for data collection, enhancing accuracy. Furthermore, using distributed nodes to collaborate on training effectively reduces computational overhead and addresses the issue of limited satellite resources.
[0070] (3) Compared to current solutions that use ground control centers for attack detection, this invention implements attack detection on satellites, reducing communication overhead and computational complexity. Considering the problem of frequent satellite switching, an incremental clustering algorithm is proposed. When a satellite switches, training can continue on the previously trained clustering model. This greatly simplifies the clustering model retraining process when switching satellites, reduces computational overhead, and enables continuous detection, increasing detection reliability.
[0071] (4) The present invention utilizes multiple drones to perform local clustering based on multiple physical layer features. The drones or satellites aggregate all local models and then use binary hypothesis testing based on the attacker's density characteristics to determine the legitimacy or illegitimacy of the user. Physical layer features and multiple drones assist in data collection and feature estimation, enabling accurate measurement of physical layer features and increasing detection reliability.
[0072] (5) The present invention is suitable for attack detection of communication equipment in satellite direct communication scenarios. It has low cost, small computational overhead and delay, and can effectively detect attackers and achieve continuous detection. BRIEF DESCRIPTION OF THE DRAWINGS
[0073] Figure 1 A distributed collaborative wireless access security solution for direct satellite communications.
[0074] Figure 2 This is a distributed collaborative wireless access security solution process for satellite direct communication.
[0075] Figure 3 This is the incremental clustering algorithm process. DETAILED DESCRIPTION
[0076] The present invention is further described in detail below with reference to the accompanying drawings.
[0077] like Figure 1As shown, in a distributed collaborative wireless access security method for satellite direct communication provided by the present invention, ground users are divided into attackers and legitimate users, and legitimate users communicate with satellite base stations through wireless channels (i.e., the communication link in the figure). At the same time, there are attackers who attack satellites through attack links. Attackers may send deceptive signals to satellites in the identity of legitimate users (i.e., the hijacked legitimate users in the figure) in an attempt to access the wireless network. They may also interfere with the satellite by sending large amounts of signaling or user data, and even cause satellite resources to be exhausted, causing the satellite base station to be attacked by denial of service, resulting in wireless network congestion or even collapse. Multiple drones are responsible for continuous monitoring in a certain area and collecting signals sent by ground users through detection links, and assisting satellites in attack detection. Satellites communicate with ground users (hereinafter referred to as users) as base stations, detect attackers, and deny attackers access to the wireless network.
[0078] The distributed cooperative wireless access security method for satellite direct communication of the present invention is mainly divided into two stages, namely, a model training and updating stage, and an attack detection stage.
[0079] like Figure 2 As shown, the present invention is a distributed cooperative wireless access security method for satellite direct communication, and its specific implementation process is as follows:
[0080] 1. Model training and updating stage;
[0081] (1) When the user communicates normally with the satellite base station, N u Each drone moves at a constant speed according to a pre-set trajectory to assist in monitoring the access status of users within its cell coverage and collect data at the time T tw The user's signal is collected in the channel to calculate the detection sample S(t) composed of the received signal strength (RSS) and carrier frequency offset (CFO) inherent in the communication channel characteristics.
[0082] (2) The drone uses the calculated detection sample S(t) as local data and generates k using the local clustering algorithm l The clustering process automatically divides the detection samples S(t) into different clusters. The detection samples in the same cluster can be regarded as samples from the same user. The local clustering algorithm combines the principles of K-nearest neighbor kernel density and high-density neighbor for local clustering. The specific implementation process is as follows:
[0083] All sample points in the UAV dataset use K-neighbor kernel density to represent the local density of each sample point, and high-density neighbors are found according to the local density, and core objects are determined. Among them, the core object refers to a sample point that has no high-density neighbor within K-neighbor or is a density maximum point within K-neighbor.
[0084] All sample points in the UAV dataset are based on high-density neighbors to construct a graph G=(V, A), where the vertex V represents the sample point, and each directed edge in A is from a non-core object to its high-density neighbor, and a core object and its child nodes form an atomic cluster.
[0085] (3) Based on the clustered atomic clusters, the UAV uses Gaussian model parameter estimation to generate a Gaussian model corresponding to each atomic cluster, and the mean, covariance and sample number of all Gaussian models are constructed into a local model x represents the user's detection sample, μ i represents the mean of the i-th atomic cluster, ∑ i represents the covariance of the i-th atomic cluster; and the local model is sent to the aggregation center. The aggregation center can be a certain UAV or a satellite.
[0086] (4) The aggregation center aggregates the local model into a global model to obtain K clustering sets. The global model parameter set is I 0 ={μ 0 ,∑w,...,n 0}, wherein, I 0 represents the global model parameter set of the K clustering sets, μ 0 represents the mean set of the K clustering sets, represents the mean of each clustering set, ∑ 0 represents the covariance set of the K clustering sets, represents the covariance of each clustering set, n 0 represents the sample number set of the K clustering sets, represents the sample number of each clustering set.
[0087] Among them, the specific implementation process of the aggregation center aggregating the local model into a global model is as follows:
[0088] ① The aggregation center calculates the model correlation value of each two Gaussian models i and j in the local model based on the KS statistic, and the model correlation value of the Gaussian models i and j is α i,j =Sup x |F i (x)-F j (x)|, wherein F i (x), Fj (x) represents the distribution function of Gaussian models i and j respectively.
[0089] ② The aggregation center calculates the correlation value of the model by pairwise calculation, and obtains the size S 2 The correlation value matrix of the two models. If the correlation value of the two models satisfies Then the two Gaussian models belong to the same distribution. The two Gaussian models are merged, where α represents the significance level. The combined mean is μ ij =(n i μ i +n j μ j ) / (n i +n j ), the combined covariance is Among them, n i and n j Respectively represent the number of samples of the i-th and j-th Gaussian models, μ i and μ j Represent the means of the i-th and j-th Gaussian models, ∑ i and ∑ j denote the covariance of the i-th and j-th Gaussian models respectively.
[0090] (5) If the aggregation center is a UAV, the global model needs to be sent to the satellite. If the aggregation center is a satellite, the global model does not need to be sent to the satellite.
[0091] (6) The satellite obtains the final K cluster sets C'={C'1, C'2, ..., C' K}, where C' K ={μ' K ,∑' K ,n' K}, where μ' K ,∑' K 、n' K They represent the mean, covariance and number of samples of the K-th cluster respectively.
[0092] (7) When the satellite switches, the source satellite will detect the attacker’s global model parameter I 0 (i.e., source global model parameters) are sent to the target satellite and UAV, and the target satellite uses the incremental clustering algorithm to update the global model to obtain the updated global model parameters I update .
[0093] Among them, Figure 3 As shown in Figure 2, the specific implementation process of the incremental clustering algorithm is as follows:
[0094] ① The UAV updates the source global model parameters I 0 according to the source global model μi represents the mean of the i-th cluster, and the source global model is taken as the new local model.
[0095] ② When a new sample x q is collected, the UAV classifies the new data based on the source global model. The specific implementation steps are as follows: calculate the posterior probability of the sample x q generated by each cluster set, and the sample x q is classified into the cluster set j with the highest probability. μj represents the mean of the j-th cluster set, σj represents the covariance of the j-th cluster set, and λ q is the cluster number of the sample x q , the sample x q is classified into the corresponding cluster according to , and y qj represents the sample x q generated by the j-th cluster set.
[0096] ③ The UAV identifies outliers based on CB-MONNAD, and the specific implementation process is as follows:
[0097] Assume that is the data set of cluster λ q , and the class-based K-distance is the distance between sample x q and sample x p in the data set , denoted as It satisfies the following two conditions: at least K samples make dist(x q ,x' p )≤dist(x q ,x p )∧x' p ∈λ q , and at most K samples make dist(x q ,x' p )<dist(x q ,x p )∧x' p ∈λ q . Where dist(x q ,x' p ) represents the distance between sample x q and sample x' p , and dist(x q ,x p ) represents the distance between sample xq and sample x p The distance between them.
[0098] Sample x q The class-based K-distance field contains samples x q The distance between The sample is expressed as:
[0099]
[0100] Sample x q The class-based local reachability density lrd(x q ) can be expressed as:
[0101]
[0102] Sample x q The class-based local outlier factor LOF is given by:
[0103]
[0104] Drone calculates sample x based on LOF q The specific calculation formula of the CB-MONNAD score is as follows:
[0105]
[0106] If the CB-MONNAD score of the newly collected sample exceeds the specified threshold m , then mark it as an outlier, and record all outliers within the data collection time as O A .
[0107] ④ The outlier O collected by the drone A As local data, we obtain the local clustering algorithm in step (2) Gaussian model for the new set of clusters.
[0108] ⑤ The drone updates and optimizes the parameters of the original cluster based on the non-outlier part of the new data to obtain an updated local model parameter set. It can be expressed as in, μ update represents the updated local model mean set, Respectively represent the updated The mean of the clusters, ∑ update represents the updated local model covariance set, Respectively represent the updated covariance of the k1 clusters, n update denote the updated global model mean set, denote the updated k1 cluster means, respectively, denote the updated k1 cluster sample numbers.
[0109] 6. The aggregation center aggregates the local models to obtain updated global model parameters, if the aggregation center is a UAV, then the adjacent UAVs transmit the updated local model parameter set to each other The UAV aggregates the local models to obtain updated global model parameters I update , and then transmits the global model to the satellite. If the aggregation center is a satellite, the UAV transmits the updated local model parameter set to the satellite, and the satellite aggregates the local models to obtain updated global model parameters I update , assuming that the aggregation center obtains k1 clusters after aggregation, I update ={μ 1 ,∑ 1 ,n 1}, wherein, μ 1 denote the updated global model mean set, denote the updated k1 cluster means, respectively, ∑ 1 denote the updated global model covariance set, denote the updated k1 cluster covariances, n 1 denote the new global model sample number set, denote the updated k1 cluster sample numbers.
[0110] The incremental clustering algorithm adopted by the application can continue training on the previously trained clustering model when the satellite switches, greatly simplifying the clustering model retraining process when the satellite switches, reducing the calculation overhead, and realizing continuous detection, thereby increasing the network reliability.
[0111] Meanwhile, the distributed clustering algorithm of multiple UAVs and satellites adopted by the application, in which multiple UAVs perform local clustering and the UAV or satellite aggregates all local models to form a global model, significantly reduces the communication overhead and calculation complexity related to transmission of a large amount of original data, and solves the problem of limited satellite resources.
[0112] 2. Attack detection phase;
[0113] (1) The satellite detects attack occurrence and estimates the number of attackers through binary hypothesis testing;
[0114] If it is a DDoS attack, the attack detection method is described as follows: if the number of samples of the received cluster set is greater than the threshold θ, the cluster set is a DDoS attack cluster set, and the total number of DDoS attack cluster sets can be regarded as the number of DDoS attackers. The process can be described as:
[0115] H0:n' K ≤θ,
[0116] H1:n' K >θ,
[0117] wherein H0 represents a legitimate user, H1 represents an attacker, the number of clusters satisfying the condition of the attacker H1 is the number of attackers, and n' K represents the number of samples of the received cluster set. The threshold θ is related to the number of preambles sent by legitimate users and attackers within the data collection time, [T tw / T in ]<θ<[T tw / T ain ], wherein T in and T ain respectively represent the time interval of twice preamble transmission of legitimate users and attackers, and T tw represents the data collection time.
[0118] If it is other attacks (for example, a spoofing attack), the signal characteristics of legitimate users are known, and the attack detection method is described as follows: the identity signature reference vector of the Kth legitimate user is A K , and the clustering model mean reflects the statistical characteristics of the user detection sample and is a stable observation value. Then, the attack detection process is converted into a comparison between the clustering model mean and the reference vector A K , and is expressed as:
[0119] H0:d(μ' K ,A K )≤τ,
[0120] H1:d(μ' K ,A K )>v,
[0121] wherein d(u' K ,A K )=(μ' K ,A K )(∑' K ) -1 (μ' K ,A K ) T , μ' K represents the mean of the received cluster set, τ represents a threshold. The total number of spoofing cluster sets can be regarded as the number of spoofing attackers.
[0122] (2) When the satellite switches, the source satellite will send the global model parameters I 0 to the target satellite and the UAV, and the target satellite updates the global model using the incremental clustering algorithm in step (7) of the model training and updating phase to obtain updated global model parameters I update , and then performs attack detection and attacker number estimation according to step (1) of the attack detection phase.
[0123] (3) When the number of UAVs N u is greater than or equal to 3, the location of the attacker can be realized.
[0124] Finally, it should be noted that: the above embodiments are only used to illustrate the technical solutions of the present application, and not to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand: it can still modify the technical solutions recorded in the foregoing embodiments, or make equivalent replacement for part of the technical features, but these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application.
Claims
1. A distributed collaborative wireless access security method for satellite direct communication, characterized in that: The following steps are involved: S1: Model training and updating stage; S1.1: When the user is communicating with the satellite base station normally, N u The drone moves at a constant speed according to the pre-set trajectory, monitors the user access situation, and collects data at the time T tw Collect user signals and calculate the detection sample S(t) composed of RSS and CFO; S1.2: The drone uses the detection sample S(t) as local data and uses the local clustering algorithm to combine the K nearest neighbor kernel density and high density nearest neighbor to generate local clustering k l Atomic clusters; S1.3: Based on the clustered atomic clusters, the drone uses Gaussian model parameter estimation to generate a Gaussian model corresponding to each atomic cluster. The mean, covariance, and number of samples of the Gaussian model form a local model and send the local model to the aggregation center. S1.4: The aggregation center aggregates the local models into a global model and obtains K cluster sets; S1.5: The aggregation center is a drone or a satellite. If the aggregation center is a drone, the global model needs to be sent to the satellite. If the aggregation center is a satellite, the global model does not need to be sent to the satellite. S1.6: The satellite obtains the final K cluster sets C'={C'1,C'2,...,C' based on the global model K }, C' K ={μ' K ,∑' K ,n' K }, μ' K ,∑' K 、n' K Represent the mean, covariance and number of samples of the K-th cluster respectively; S1.7: When a satellite switch occurs, the source satellite will detect the attacker's global model parameter I 0 The target satellite uses the incremental clustering algorithm to update the global model and obtain the updated global model parameters I update ; The specific implementation process of the incremental clustering algorithm is as follows: ① The UAV is based on the source global model parameter I 0 Get the source global model represents the mean of the i-th cluster, Denote the covariance of the i-th cluster and use this source global model as the new local model; ②When a new sample x is collected q When , the UAV classifies the new data based on the source global model; ③ The drone identifies outliers based on CB-MONNAD and records all outliers within the data collection time as O A ; The specific implementation process of the drone to identify outliers based on CB-MONNAD is as follows: Assumptions is a cluster λ q The dataset, the class-based K-distance is the dataset Sample x q and sample x p The distance between It satisfies the following two conditions: there are at least K samples So that dist(x q ,x' p )≤dist(x q ,x p )∧x' p ∈λ q , and there are at most K samples, so that dist(x q ,x' p ) <dist(x q ,x p )∧x' p ∈λ q ,dist(x q ,x' p ) represents the sample x q and sample x' p The distance between them, dist(x q ,x p ) represents the sample x q and sample x p the distance between them; Sample x q The class-based K-distance field contains samples x q The distance between The sample is expressed as: Sample x q The class-based local reachability density lrd(x q ) is expressed as: Sample x q The class-based local outlier factor LOF is expressed as: Drone calculates sample x based on LOF q The specific calculation formula of the CB-MONNAD score is as follows: If the CB-MONNAD score of the newly collected sample exceeds the specified threshold m , it is marked as an outlier, and all outliers within the data collection time are recorded as O A ; ④ The outlier O collected by the drone A As local data, we obtain the local clustering algorithm in step S1.
2. Gaussian model of the new cluster set; ⑤ The drone updates and optimizes the parameters of the original cluster based on the non-outlier part of the new data to obtain an updated set of local model parameters; ⑥ The aggregation center aggregates the local model to obtain the updated global model parameters. If the aggregation center is a drone, the updated local model parameter set is transmitted between adjacent drones. The UAV performs local model aggregation to obtain updated global model parameters I update , and then transmit the global model to the satellite; if the aggregation center is a satellite, the drone will update the local model parameter set Sent to the satellite, the satellite performs local model aggregation to obtain the updated global model parameters I update ; S2: attack detection phase; S2.1: The satellite detects the occurrence of an attack and estimates the number of attackers through binary hypothesis testing; S2.2: When a satellite switch occurs, the source satellite will detect the attacker’s global model parameter I 0 The target satellite uses the incremental clustering algorithm in step S1.7 to update the global model and obtain the updated global model parameters I update ,Then perform attack detection and attacker number estimation according to step S2.1; S2.3: When the number of drones N u When it is greater than or equal to 3, the attacker can be located.
2. A distributed collaborative wireless access security method for satellite direct communication according to claim 1, characterized in that: In step S1.2, in the local clustering process, the detection samples S(t) are automatically divided into different clusters, and the detection samples in the same cluster are regarded as samples from the same user.
3. The distributed collaborative wireless access security method for satellite direct communication according to claim 1, characterized in that: The specific implementation process of the local clustering algorithm is as follows: ① All sample points in the drone dataset use K-nearest neighbor kernel density to represent the local density of each sample point, find high-density neighboring points based on the local density, and determine the core object; ② All sample points in the drone dataset are constructed into a graph g = (V, A) based on high-density neighboring points. Vertex V represents the sample point, and each directed edge in A is from a non-core object to its high-density neighboring point. A core object and its child nodes form an atomic cluster.
4. The distributed collaborative wireless access security method for satellite direct communication according to claim 1, characterized in that: In step S1.3, the mean, covariance and number of samples of all Gaussian models are used to form a local model x represents the user's detection sample, μ i represents the mean of the i-th atomic cluster, ∑ i represents the covariance of the i-th atomic cluster.
5. The distributed collaborative wireless access security method for satellite direct communication according to claim 1, characterized in that: In step S1.4, the specific implementation process of the aggregation center aggregating the local models into the global model is as follows: ① The aggregation center calculates the model correlation value for each two Gaussian models i and j in the local model based on the KS statistic. The model correlation value of Gaussian models i and j is α i,j =Sup x |F i (x)-F j (x)|, where F i (x), F j (x) represents the distribution function of Gaussian models i and j respectively; ② The aggregation center calculates the correlation value of the model by pairwise calculation, and obtains the size S 2 The correlation value matrix of the two models; if the correlation value of the two models satisfies Then the two Gaussian models belong to the same distribution. The two Gaussian models are merged, where α represents the significance level. The combined mean is μ ij =(n i μ i +n j μ j ) / (n i +n j ), the combined covariance is n i and n j Respectively represent the number of samples of the i-th and j-th Gaussian models, μ i and μ j Represent the means of the i-th and j-th Gaussian models, ∑ i and ∑ j denote the covariance of the i-th and j-th Gaussian models respectively.
6. The distributed collaborative wireless access security method for satellite direct communication according to claim 1, characterized in that: In step ②, when a new sample x is collected q When , the specific implementation process of the drone classifying new data based on the source global model is as follows: Calculate sample x q The posterior probability generated by each cluster set, sample x q The probability of being generated by the j-th cluster set is represents the mean of the j-th cluster set, represents the covariance of the j-th cluster set, λ q For sample x q The cluster number of the sample x q according to into the corresponding cluster, y qj Represents sample x q The probability of being generated by the j-th cluster set.
7. The distributed collaborative wireless access security method for satellite direct communication according to claim 1, characterized in that: The specific implementation process of step S2.1 is as follows: When the attack is a DDoS attack, if the number of samples of the received cluster is greater than the threshold θ, the cluster is a DDoS attack cluster, and the total number of DDoS attack clusters is regarded as the number of DDoS attackers, which is described as: H0:n' K ≤θ, H1:n' K >i, Among them, H0 represents the legitimate user, H1 represents the attacker, and the number of clusters that meet the attacker H1 condition is the number of attackers, n' K Indicates the number of samples of the received cluster; When the attack is other attacks, the signal characteristics of the legitimate user are known, and the identity signature reference vector of the Kth legitimate user is A K , then the attack detection process is transformed into the clustering model mean and the reference vector A K For comparison, it is expressed as: H0:d(μ' K ,A K )≤τ, H1:d(m' K ,A K )>t, Where d(μ' K ,A K )=(μ' K ,A K )(∑' K ) -1 (μ' K ,A K ) T , μ' K represents the mean of the received clusters, τ represents the threshold; the total number of deceptive clusters can be regarded as the number of deceptive attackers.
8. The distributed collaborative wireless access security method for satellite direct communication according to claim 7, characterized in that: The threshold θ is related to the number of preambles sent by legitimate users and attackers during the data collection period. tw / T in ]<θ<[T tw / T ain ], T in and T ain T represents the time interval between two preamble transmissions of the legitimate user and the attacker, respectively. tw Indicates the data collection time.