A security control method, system, medium and product applied to communication base stations
By analyzing communication data in real time, positioning and isolating the hidden danger transmission channel, and switching to the substitute channel, it solves the problem of difficulty in time discovering and handling the hidden dangers of communication base stations in the prior art, and realizes the stability and security of communication services.
Patent Information
- Application Number
- CN202510104854.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-23
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2045-01-23
AI Technical Summary
The prior art is difficult to detect hidden dangers in communication base stations in a timely manner, resulting in the risk of communication network interruption and user data leakage.
By obtaining real-time communication data of the communication base station in real time, identifying communication characteristics, positioning the hidden danger transmission channel, and generating hidden danger isolation instructions, switching to the replacement transmission channel to ensure the continuity of communication services.
It realizes the rapid and accurate identification and isolation of hidden danger communication data, reduces the impact of communication hidden dangers on the network, and avoids communication interruptions and service quality declines.
Smart Images

Figure CN119545352B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of security control, and in particular, to a security control method, system, medium and product applied to a communication base station. Background Art
[0002] A communication base station is an important part of a communication network, undertaking important tasks such as signal transmission and data processing. If the security management of the base station is not in place, it may lead to the interruption of the communication network, affecting the normal use of users, and even may cause serious social problems. In addition, a large amount of user data and communication data are generally stored in a communication base station. If the security management of the communication base station is not good, it may lead to the leakage of user data and communication data, threatening user privacy. Therefore, it is particularly crucial to perform security control on the base station.
[0003] In related technologies, generally, relevant maintenance personnel conduct regular inspections and maintenance on communication base stations to ensure the normal operation and stability of the equipment. However, limited by the inspection frequency and coverage, all instantaneous hidden dangers during the communication process may not be captured. In addition, the technical levels of relevant maintenance personnel vary, which may result in limited capabilities in identifying and handling hidden dangers during the inspection process. Therefore, the timeliness and accuracy in identifying hidden dangers may be poor. Summary of the Invention
[0004] In order to facilitate the timely discovery of hidden dangers existing in the communication process and reduce the impact of communication hidden dangers on the communication network, the present application provides a security control method, system, medium and product applied to a communication base station.
[0005] In a first aspect, the present application provides a security control method applied to a communication base station, adopting the following technical solution:
[0006] A security control method applied to a communication base station includes:
[0007] Obtain real-time communication data of a communication base station to be controlled, and identify communication characteristics corresponding to the real-time communication data, where the real-time communication data includes real-time transmission data and real-time access data;
[0008] When the communication characteristics include preset hidden danger characteristics, determine the real-time communication data as hidden danger communication data;
[0009] Identify hidden danger transmission behaviors and hidden danger access behaviors corresponding to the hidden danger communication data, and determine a hidden danger transmission channel corresponding to the hidden danger communication data and an influence coverage area corresponding to the hidden danger transmission channel based on the hidden danger transmission behaviors and the hidden danger access behaviors;
[0010] Determine a backup transmission channel based on the hidden danger transmission channel and the historical communication requirements of the affected coverage area, and generate a hidden danger isolation instruction based on the backup transmission channel to isolate the affected transmission channel, and use the backup transmission channel to provide communication services for the affected coverage area.
[0011] By adopting the above technical solution, by real-time identifying and analyzing the communication characteristics contained in the communication data, it is convenient to timely discover the hidden danger characteristics, so as to facilitate the timely discovery of hidden danger communication data. By analyzing the hidden danger communication data, it is convenient to quickly and accurately locate the hidden danger transmission channel involved in the hidden danger communication data, without the need for personnel screening, thus facilitating the improvement of the response rate during subsequent repair or maintenance. In addition, after locating the hidden danger transmission channel, by quickly generating a hidden danger isolation instruction to isolate the hidden danger transmission channel, it is convenient to limit the development of the hidden danger situation and prevent its further spread, thus facilitating the reduction of the impact of communication hidden dangers on the entire communication network. Finally, by determining the backup transmission channel and continuing to provide communication services for the affected area based on the backup transmission channel, it is convenient to avoid communication interruption and service quality degradation caused by the hidden danger situation, thus facilitating the further reduction of the impact of communication hidden dangers on the communication network.
[0012] In a possible implementation manner, the determining a backup transmission channel based on the hidden danger transmission channel and the historical communication requirements of the affected coverage area includes:
[0013] Perform feature recognition on the hidden danger transmission channel to obtain the hidden danger relay point corresponding to the hidden danger transmission channel;
[0014] Based on the affected coverage area, determine at least one primary transmission channel, and screen the at least one primary transmission channel based on the hidden danger relay point to obtain at least one secondary transmission channel, and the secondary transmission channel does not include the hidden danger relay point;
[0015] Based on the historical communication requirements of the affected coverage area, evaluate each secondary transmission channel to obtain the channel score of each secondary transmission channel, and the historical communication requirements include historical traffic, historical communication rate, and historical communication security factor;
[0016] Based on the channel scores of each secondary transmission channel, determine the backup transmission channel from the at least one secondary transmission channel.
[0017] By adopting the above technical solution, when screening the secondary transmission channels, the transmission channels containing potential hazard relay points are excluded, so as to facilitate avoiding communication failures and security risks that may be brought by potential hazard relay points. In addition, by excluding potential hazard relay points, it is convenient to improve the security of the secondary transmission channels, thereby facilitating enhancing the defense ability of the entire communication network. The determined secondary transmission channels are evaluated based on historical communication requirements, and finally, alternative transmission channels are determined based on the evaluation results, which is convenient for the communication network to flexibly respond to changes in future communication requirements. At the same time, the existence of alternative transmission channels is also convenient for improving the fault tolerance of the entire communication network. Even if some transmission channels fail, communication continuity can be ensured by quickly switching to alternative channels.
[0018] In a possible implementation manner, when there is no secondary transmission channel, the method further includes:
[0019] Based on the at least one primary transmission channel and the potential hazard relay point, determine at least one alternative transmission channel, where the alternative transmission channels contain potential hazard relay points, and the number of potential hazard relay points included is lower than a preset hazard number;
[0020] Based on the historical communication requirements of the affected coverage area, determine the predicted communication requirements corresponding to a first preset time period;
[0021] Perform communication simulation on each alternative transmission channel based on the predicted communication requirements to obtain the simulated communication data corresponding to each alternative transmission channel, and determine the simulation score of each alternative transmission channel based on the type and quantity of simulated hazard characteristics appearing in each simulated communication data;
[0022] Based on the simulation scores of each alternative transmission channel, determine the alternative transmission channel corresponding to the first preset time period from the at least one alternative transmission channel.
[0023] By adopting the above technical solution, when there is no secondary transmission channel, alternative transmission channels can also be determined based on the primary transmission channels and potential hazard relay points. Although the alternative transmission channels contain potential hazard relay points, the number is lower than the preset hazard number, which is convenient for improving communication continuity on the premise of reducing the occurrence probability of communication failures and security risks. By performing communication simulation on each alternative transmission channel, it is convenient to select the alternative transmission channel with the best performance and highest security as the alternative transmission channel, thereby facilitating enhancing the reliability and stability of the communication network.
[0024] In a possible implementation manner, the method further includes:
[0025] Based on the simulated communication data of each alternative transmission channel, determine the simulated influence area corresponding to each alternative transmission channel, and the simulated degree of influence of each simulated influence area;
[0026] Determine the simulated affected layer of each alternative transmission channel based on the simulated influence area of the alternative transmission channels and the simulated affected degree of each simulated influence area;
[0027] Overlay each simulated affected layer to obtain a target simulated layer, and determine the concerned simulated area based on the target simulated layer;
[0028] Generate a defense reinforcement instruction based on the concerned simulated area, and feedback the defense reinforcement instruction.
[0029] By adopting the above technical solution, the simulated affected degree of each alternative transmission channel is presented in the form of a layer, which is convenient for intuitively comparing the affected degrees between different alternative transmission channels. Then, by overlaying each simulated affected layer to obtain a target simulated layer, the overall influence situation of all alternative transmission channels can be comprehensively evaluated, which is convenient for relevant maintenance personnel to pay attention to the key areas, and by timely feedbacking the defense reinforcement instruction, it is ensured that the security risks faced by the concerned simulated area within the first preset time period are effectively controlled.
[0030] In a possible implementation manner, determining the simulated influence area corresponding to the alternative transmission channel based on the simulated communication data of the alternative transmission channel includes:
[0031] Identify the hidden danger positions of each hidden danger relay point in the alternative transmission channel, where the hidden danger position of the hidden danger relay point is the sequential position of the hidden danger relay point among all the hidden danger relay points corresponding to the alternative transmission channel;
[0032] Determine the communication value level corresponding to each hidden danger relay point based on the simulated communication data of the alternative transmission channel;
[0033] Determine the relay point influence area corresponding to each hidden danger relay point based on the hidden danger position and the communication value level of each hidden danger relay point, and determine the simulated influence area of the alternative transmission channel based on each relay point influence area.
[0034] By adopting the above technical solution, by comprehensively analyzing the hidden danger position and the corresponding communication value level of each hidden danger relay point, it is convenient to improve the accuracy when determining the relay point influence area, and thus it is convenient to improve the accuracy when determining the simulated influence area.
[0035] In a possible implementation manner, before determining at least one alternative transmission channel based on the at least one primary transmission channel and the hidden danger relay point, the method further includes:
[0036] Obtain the defense data of each hidden danger relay point in the hidden danger transmission channel within the second preset time period, and identify the defense times and the defense success rate from each defense data;
[0037] Determine the defense score of each potential hazard relay point based on the corresponding number of defense operations and defense success rate of each potential hazard relay point;
[0038] Hide the potential hazard relay points with defense scores lower than the preset score.
[0039] By adopting the above technical solution, evaluate the defense capabilities of each potential hazard relay point through the defense operations of each potential hazard relay point within the historical time period, and then by comparing the defense scores of different relay points, it is convenient to preferentially select potential hazard relay points with higher safety performance and stronger defense capabilities as part of the alternative transmission channels, thereby facilitating the improvement of the reliability and security of the alternative transmission channels.
[0040] In a second aspect, the present application provides a control system, adopting the following technical solution:
[0041] A control system, the control system includes:
[0042] At least one processor;
[0043] A memory;
[0044] At least one application program, wherein the at least one application program is stored in the memory and is configured to be executed by at least one processor, and the at least one application program is configured to: execute the above-mentioned security control method applied to the communication base station.
[0045] In a third aspect, the present application provides a computer-readable storage medium, adopting the following technical solution:
[0046] A computer-readable storage medium, including: a computer program stored that can be loaded and executed by a processor to execute the above-mentioned security control method applied to the communication base station.
[0047] In a fourth aspect, the present application provides a computer program product, adopting the following technical solution:
[0048] A computer program product, including a computer program, and when the computer program is executed by a processor, it implements the above-mentioned security control method applied to the communication base station.
[0049] In summary, the present application includes at least one of the following beneficial technical effects:
[0050] By real-time identifying and analyzing communication features contained in communication data, it is convenient to timely discover potential hazard features, thus facilitating the timely discovery of communication data with potential hazards. By analyzing the communication data with potential hazards, it is convenient to quickly and accurately locate the potential hazard transmission channels involved in the communication data with potential hazards, without the need for personnel screening, thereby facilitating the improvement of the response rate during subsequent maintenance or repair. Additionally, after locating the potential hazard transmission channels, by quickly generating potential hazard isolation instructions to isolate the potential hazard transmission channels, it is convenient to limit the development of potential hazard situations, prevent their further spread, and thus facilitate reducing the impact of communication hazards on the entire communication network. Finally, by determining alternative transmission channels and continuously providing communication services to the affected areas based on the alternative transmission channels, it is convenient to avoid communication interruption and service quality degradation caused by potential hazard situations, and thus facilitate further reducing the impact of communication hazards on the communication network.
[0051] By presenting the simulated affected degree of each alternative transmission channel in the form of a layer, it is convenient to visually compare the affected degrees between different alternative transmission channels. Then, by superimposing each simulated affected layer to obtain a target simulated layer, the overall impact situation of all alternative transmission channels can be comprehensively evaluated, facilitating relevant maintenance personnel to pay attention to key areas, and by timely feedback of defense and reinforcement instructions, ensuring that the security risks faced by the concerned simulated area within the first preset time period are effectively controlled. Description of the Drawings
[0052] Figure 1 is a schematic flowchart of a security control method applied to a communication base station in an embodiment of the present application;
[0053] Figure 2 is a schematic flowchart of a method for determining defense and reinforcement instructions in an embodiment of the present application;
[0054] Figure 3 is a schematic structural diagram of a control system in an embodiment of the present application. Detailed Embodiments
[0055] The following is a further detailed description of the present application in conjunction with the attached Figures 1 to 3 drawings.
[0056] Those skilled in the art can make modifications without creative contributions to this embodiment according to their needs after reading this specification, but as long as they are within the scope of the claims of the present application, they are protected by the Patent Law.
[0057] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are some, but not all, of the embodiments of this application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in this application without creative efforts shall fall within the scope of protection of this application.
[0058] It should be noted that in the alternative embodiments of this application, for relevant data such as object information, when the embodiments in this application are applied to specific products or technologies, object permission or consent needs to be obtained, and the collection, use, and processing of relevant data need to comply with the relevant laws, regulations, and standards of the relevant countries and regions. That is to say, if the embodiments of this application involve data related to an object, it needs to be obtained under the authorization and consent of the object, the authorization and consent of the relevant department, and compliance with the relevant laws, regulations, and standards of the country and region. If personal information is involved in the embodiments, the acquisition of all personal information needs to obtain the consent of the individual. If sensitive information is involved, the separate consent of the information subject needs to be obtained, and the embodiments also need to be implemented under the authorization and consent of the object.
[0059] Specifically, the embodiments of this application provide a security control method applied to a communication base station, which is executed by a control system. The control system can be a server or a terminal device. Among them, the server can be an independent physical server, a server cluster or a distributed system composed of multiple physical servers, or a cloud server providing cloud computing services. The terminal device can be a smart phone, a tablet computer, a notebook computer, a desktop computer, etc., but is not limited thereto. The terminal device and the server can be directly or indirectly connected through wired or wireless communication methods, and this application does not limit this here.
[0060] Reference Figure 1 , Figure 1 is a schematic flowchart of a security control method applied to a communication base station in the embodiments of this application. The method includes steps S110 - S140, where:
[0061] Step S110: Obtain the real-time communication data of the communication base station to be controlled, and identify the communication characteristics corresponding to the real-time communication data. The real-time communication data includes real-time transmission data and real-time access data.
[0062] Specifically, the communication base stations to be controlled are those that require security control. Different communication base stations to be controlled have different coverage areas. The scope of the coverage area mainly depends on the base station type, transmission power, antenna characteristics, operating frequency band, etc. of the base station to be controlled. Among them, the base station type can be a macro base station, a micro base station, or a cellular base station; the transmission power is one of the key factors affecting the scope of the coverage area. The greater the transmission power, the larger the corresponding coverage area; the type and direction of the antenna may also affect the scope of the coverage area. A directional antenna can concentrate the signal in a specific direction, thereby increasing the coverage distance in a specific direction, while an omnidirectional antenna can provide a relatively uniform coverage in all directions; signals of different frequency bands have different propagation characteristics, so the coverage ranges of base stations using different frequency bands will also vary.
[0063] The real-time communication data is the communication behaviors of relevant users within the coverage area corresponding to the communication base stations to be controlled, including but not limited to real-time transmission data and real-time access data. Among them, real-time transmission data usually includes audio, video, text messages, or other types of data streams, the transmission rate, the amount of transmitted data, and the transmission time, etc. during the communication process. Real-time access data usually includes the access request frequency, access time, and access object, etc. initiated by relevant users during real-time communication. The real-time communication data can be obtained through communication logs, and after obtaining the authorization of relevant users, the real-time communication data of relevant users can also be obtained based on the API interface. The method of obtaining real-time communication data is not specifically limited in the embodiments of this application, as long as the communication behaviors of relevant users can be monitored based on the obtained real-time communication data. The communication characteristics in the real-time communication data can be identified based on a preset feature recognition algorithm. Among them, the communication characteristics include the transmission rate, the amount of transmitted data, the transmission time, the access request frequency, the access time, and the access object, etc. The specific communication characteristics and the preset feature recognition algorithm are not specifically limited in the embodiments of this application and can be determined by relevant staff based on historical experimental data and then uploaded to the control system.
[0064] Step S120: When the communication characteristics include preset hidden danger characteristics, determine that the real-time communication data is hidden danger communication data.
[0065] Specifically, by comparing communication features with preset potential risk features, it can be determined whether real-time communication data is potential risk communication data. The preset potential risk features include transmission rate higher than the preset rate, transmitted data volume higher than the preset data volume, transmission time outside the preset transmission period, access request frequency higher than the preset frequency, access time outside the preset access period, access object in the prohibited access list, etc. If the real-time communication data contains the preset potential risk features, it indicates that the real-time communication data may have potential security risks or hazards. Among them, if the transmission rate in the communication features is higher than the preset rate, it may indicate that the real-time communication data is undergoing large-scale data transmission, which may involve behaviors such as data leakage or illegal data sharing; if the transmitted data volume in the communication features is higher than the preset data volume, it may indicate that there are abnormal data transmission behaviors in the real-time communication data, which may involve behaviors such as transmission of sensitive data; if the transmission time in the communication features is outside the preset transmission period, it may indicate that there are unauthorized access or communication behaviors in the real-time communication data; if the access request frequency in the communication features is higher than the preset frequency, it may indicate that there are malicious behaviors in the real-time communication data, such as brute force cracking or vulnerability scanning; if the access time in the communication features is outside the preset access period, it may indicate that there are security risks in the real-time communication data; if the access object in the communication features is in the prohibited access list, it may indicate that there are network attacks or malicious behaviors in the real-time communication data. The prohibited access list can include malicious websites, malicious IPs, malicious domain names, etc. The specific prohibited access list can be determined by relevant staff based on historical security defense data and then uploaded to the control system.
[0066] Step S130: Identify the potential risk transmission behavior and potential risk access behavior corresponding to the potential risk communication data, and determine the potential risk transmission channel corresponding to the potential risk communication data and the influence coverage area corresponding to the potential risk transmission channel based on the potential risk transmission behavior and potential risk access behavior.
[0067] Specifically, the potential risk communication data is communication data containing preset potential risk features. The potential risk communication data includes potential risk transmitted data and potential risk access data. The potential risk transmission behavior in the potential risk communication data can be a transmission behavior involving potential risk transmission rate, potential risk transmitted data volume, and potential risk transmission time. Similarly, the potential risk access behavior can be an access behavior involving potential risk access request frequency, potential risk access time, and potential risk access object.
[0068] According to the identified hidden danger transmission behavior and hidden danger access behavior, the hidden danger transmission channel corresponding to the hidden danger communication data can be determined. Specifically, by analyzing network traffic logs, security event logs, etc., the specific occurrence times of the hidden danger transmission behavior and hidden danger access behavior can be identified. Then, based on the preset network topology and preset security policies, the possible transmission channels that the hidden danger communication data may pass through during transmission can be inferred. Among them, the preset network topology includes node devices such as data processing devices, data communication control devices, and data terminal devices in the communication network, and also includes the links and paths between each node device. The specific preset network topology can be uploaded to the control system in advance by relevant staff. The preset security policy refers to a series of rules and measures formulated to ensure network security, including but not limited to access control policies, encryption policies, firewall policies, intrusion detection and prevention policies, etc. The specific contents of the preset network topology and preset security policies are not specifically limited in the embodiments of the present application.
[0069] Different transmission channels serve different coverage areas. That is, devices or users within a certain coverage area can communicate with other devices or users through the corresponding transmission channel to achieve data interaction. Therefore, based on the hidden danger transmission channel, the corresponding affected coverage area can be determined. The affected coverage area corresponding to the hidden danger transmission channel can be determined based on the preset area mapping relationship. The preset area mapping relationship includes the coverage areas corresponding to each transmission channel, and the preset area mapping relationship can be determined by relevant staff according to historical experimental data and then uploaded to the control system. However, since data transmission may be affected by factors such as physical blockage, material characteristics, electromagnetic interference, and weather conditions, after the hidden danger transmission channel is determined, the area optimization value can be determined according to building parameters, material parameters, electromagnetic parameters, and weather parameters, and then the affected coverage area determined based on the preset area mapping relationship can be optimized based on the area optimization value. Among them, the building parameters, material parameters, electromagnetic parameters, and weather parameters can be imported into the trained optimization model, and the trained optimization model can directly output the area optimization value. The optimization model can be trained based on a large number of sample data including sample building parameters, sample material parameters, sample electromagnetic parameters, and sample weather parameters and the manually labeled area optimization values. The specific training method is not specifically limited in the embodiments of the present application. Among them, the area optimization value can be to reduce xx square meters or increase xx square meters.
[0070] Step S140: Determine a substitute transmission channel based on the historical communication requirements of the hidden danger transmission channel and the affected coverage area, and generate a hidden danger isolation instruction based on the substitute transmission channel to isolate the affected transmission channel and use the substitute transmission channel to provide communication services for the affected coverage area.
[0071] Specifically, since there may be security vulnerabilities or improper configurations in the hidden danger transmission channel, resulting in sensitive information being easily stolen or tampered with, after the hidden danger transmission channel is identified, the hidden danger transmission channel can be isolated to prevent external attacks or reduce content threats. The isolation of the hidden danger transmission channel can be achieved through physical isolation devices such as isolation network gates and unidirectional optical gates, and security isolation can also be achieved by configuring firewall rules, security gateways, etc. For example, when isolating the hidden danger transmission channel through the configuration of a firewall, the communication between the hidden danger transmission channel and other transmission channels can be restricted according to information such as the source address, target address, and port number of the hidden danger transmission channel. The specific method for isolating the hidden danger transmission channel is not specifically limited in the embodiments of the present application.
[0072] When the hidden danger communication data is detected, it only indicates that there is hidden danger communication data in the affected coverage area when communicating using the hidden danger transmission channel, or there is hidden danger communication data in the affected coverage area, but it does not mean that all the communication data in the affected coverage area has hidden dangers. At this time, in order to ensure the transmission of other non-hidden danger communication data in the affected coverage area, a substitute transmission channel can be determined for the affected coverage area based on the historical communication requirements of the affected coverage area, and the security level of the substitute transmission channel is higher than that of the hidden danger transmission channel. When determining the substitute transmission channel, in addition to considering the security level, it is also necessary to select from the idle transmission channels according to the historical communication requirements such as the historical communication volume and historical communication rate of the affected coverage area. The historical communication requirements include information such as the historical communication volume and historical communication rate corresponding to the affected coverage area in the historical time period. Specifically, the specific process of determining the substitute transmission channel based on the hidden danger transmission channel and the historical communication requirements of the affected coverage area may include:
[0073] Perform feature recognition on the hidden danger transmission channel to obtain the hidden danger relay point corresponding to the hidden danger transmission channel; determine at least one primary transmission channel based on the affected coverage area, and screen at least one primary transmission channel based on the hidden danger relay point to obtain at least one secondary transmission channel, and the secondary transmission channel does not include the hidden danger relay point; evaluate each secondary transmission channel based on the historical communication requirements of the affected coverage area to obtain the channel score of each secondary transmission channel, and the historical communication requirements include historical communication volume, historical communication rate, and historical communication security coefficient; determine the substitute transmission channel from at least one secondary transmission channel based on the channel score of each secondary transmission channel.
[0074] Specifically, a hidden danger relay point is a node in the hidden danger transmission channel for forwarding or amplifying signals. Since the hidden danger transmission channel may have been attacked by malicious websites or hackers, when communication data passes through these hidden danger relay points, it may be affected, resulting in problems such as degraded transmission quality, data loss, and security vulnerabilities. Therefore, when determining the alternative transmission channel, it is necessary to avoid the hidden danger relay points as much as possible. Among them, the hidden danger relay points in the hidden danger transmission channel can be identified based on a preset feature recognition algorithm, and then the secondary transmission channel can be determined from multiple idle primary transmission channels based on the hidden danger relay points. The specific feature recognition algorithm is not specifically limited in the embodiments of the present application. The number of primary transmission channels and secondary transmission channels is not specifically limited in the embodiments of the present application and can be limited by relevant staff.
[0075] Based on historical traffic, historical communication rate, and historical communication security factor, a simulated communication model can be constructed. By importing each secondary transmission channel into the constructed simulated communication model, the channel score of each secondary transmission channel can be obtained. The channel score is related to the type and quantity of simulated hidden danger features that appear during the simulation process. The higher the channel score, the more reliable the corresponding secondary transmission channel. The construction process of the simulated communication model is not specifically limited in the embodiments of the present application. By constructing the simulated communication model, it is convenient to evaluate the transmission capabilities of each secondary transmission channel. Just determine the secondary transmission channel with the highest channel score as the alternative transmission channel. Determining the alternative transmission channel based on the evaluation results facilitates enabling the communication network to flexibly respond to future changes in communication requirements. At the same time, the existence of the alternative transmission channel also helps to improve the fault tolerance of the entire communication network. Even if some transmission channels fail, communication continuity can be ensured by quickly switching to the alternative channel.
[0076] After determining the alternative transmission channel, after isolating the hidden danger transmission channel, the alternative transmission channel can be enabled to continue providing communication services to the affected coverage area. The management and control system can directly isolate the hidden danger transmission channel according to the hidden danger isolation instruction and start the alternative transmission channel, or it can also feedback the hidden danger isolation instruction to relevant management and control personnel and then be operated by the relevant management and control personnel.
[0077] For the embodiments of the present application, by real-time identifying and analyzing the communication features included in the communication data, it is convenient to timely discover the hidden danger features, so as to facilitate the timely discovery of the communication data with hidden dangers. By analyzing the communication data with hidden dangers, it is convenient to quickly and accurately locate the hidden danger transmission channels involved in the communication data with hidden dangers, without the need for personnel screening, thus facilitating the improvement of the response rate during subsequent maintenance or repair. In addition, after locating the hidden danger transmission channel, by quickly generating a hidden danger isolation instruction to isolate the hidden danger transmission channel, it is convenient to limit the development of the hidden danger situation and prevent its further spread, so as to facilitate reducing the impact of the communication hidden danger on the entire communication network. Finally, by determining the alternative transmission channel and continuing to provide communication services for the affected area based on the alternative transmission channel, it is convenient to avoid communication interruption and service quality degradation caused by the hidden danger situation, thus facilitating further reducing the impact of the communication hidden danger on the communication network.
[0078] Further, when there is no secondary transmission channel, the method provided by the embodiments of the present application further includes:
[0079] Based on at least one primary transmission channel and the hidden danger relay points, determine at least one alternative transmission channel. The alternative transmission channel includes the hidden danger relay points, and the number of hidden danger relay points included is lower than the preset number of hidden dangers; based on the historical communication requirements of the affected coverage area, determine the predicted communication requirements corresponding to the first preset time period; perform communication simulation on each alternative transmission channel based on the predicted communication requirements to obtain the simulated communication data corresponding to each alternative transmission channel, and based on the type and quantity of the simulated hidden danger features appearing in each simulated communication data, determine the simulated score of each alternative transmission channel; based on the simulated scores of each alternative transmission channel, determine the alternative transmission channel corresponding to the first preset time period from at least one alternative transmission channel.
[0080] Specifically, if there is currently no idle secondary transmission channel that does not include hidden danger relay points, the determination standard of the alternative transmission channel can be appropriately reduced, that is, the alternative transmission channel can be selected from the alternative transmission channels that include a small number of hidden danger relay points, where the number of hidden danger relay points included in the alternative transmission channel needs to be lower than the preset number of hidden dangers. The preset number of hidden dangers can be 2 or 3. The specific quantity is not specifically limited in the embodiments of the present application. After determining at least one alternative transmission channel, the alternative transmission channel can be determined from at least one alternative transmission channel according to the method of determining the alternative transmission channel from the secondary transmission channel in the above embodiments.
[0081] Different from the above method, it is necessary to first determine the predicted communication demand corresponding to the first preset time period based on historical communication demands, and then construct a predicted simulation communication model based on the predicted communication demand. The first preset time period is a period of time after the current moment, and the duration of the first preset time period is related to the waiting duration of the secondary transmission channel. For example, according to the working status of each transmission channel, it is determined that the waiting duration of the secondary transmission channel is 10 minutes, that is, there will be a secondary transmission channel after 10 minutes. At this time, it can be determined that the duration corresponding to the first preset time period is 10 minutes, and the first preset time period is 10 minutes after the current moment. Each alternative transmission channel is imported into the predicted simulation communication model to obtain the types and quantities of simulated hidden danger features that appear in the simulated communication process of each alternative transmission channel during the first preset time period. Based on the preset simulated score mapping relationship, the simulated score of each alternative transmission channel can be determined. The preset simulated score mapping relationship is the corresponding relationship between the combination of the type and quantity of simulated hidden danger features and the simulated score, and the specific content is not specifically limited in the embodiments of the present application. Finally, the alternative transmission channel with the highest simulated score can be determined as the substitute transmission channel corresponding to the first preset time period, that is, after the first preset time period, it is necessary to re-determine the substitute transmission channel based on the secondary transmission channel.
[0082] However, in order to improve the reliability and security of the alternative transmission channels, before determining at least one alternative transmission channel based on at least one primary transmission channel and hidden danger relay points, the method provided in the embodiments of the present application further includes:
[0083] Obtain the defense data of each hidden danger relay point in the hidden danger transmission channel during the second preset time period, and identify the number of defenses and the defense success rate from each defense data; determine the defense score of each hidden danger relay point based on the number of defenses and the defense success rate corresponding to each hidden danger relay point; perform a hiding process on the hidden danger relay points with defense scores lower than the preset score.
[0084] Specifically, the second preset time period is a period of time before the current moment. The duration corresponding to the second preset time period can be 10 days or 20 days, and the specific duration is not specifically limited in the embodiments of the present application. By analyzing the defense behaviors of each hidden danger relay point in the historical period, it is convenient to evaluate the defense capabilities of each hidden danger relay point. The defense data of each hidden danger relay point can be obtained from the defense log, and then based on the preset feature recognition algorithm, the total number of defenses triggered by each hidden danger relay point during the second preset time period and the proportion of successfully defended attacks are determined from the defense data corresponding to each hidden danger relay point. Based on the preset score mapping relationship, the defense score corresponding to any combination of the number of defenses and the defense success rate can be determined. The higher the number of defenses and the defense success rate, the higher the corresponding defense score. The specific content of the preset score mapping relationship is not specifically limited in the embodiments of the present application.
[0085] Hide the hidden relay points with defense scores lower than the preset score. The hiding process may include removing from the relay point list, marking as unavailable, or taking other measures to ensure that these relay points with scores lower than the preset score will not be selected into the alternative transmission channels. The specific preset score is not specifically limited in the embodiments of the present application.
[0086] Furthermore, the method provided in the embodiments of the present application further includes steps S210 - S240, as Figure 2 shown, where:
[0087] Step S210: Based on the simulated communication data of each alternative transmission channel, determine the simulated influence area corresponding to each alternative transmission channel and the simulated degree of influence of each simulated influence area.
[0088] Specifically, since the alternative transmission channels include hidden relay points, when communicating based on the alternative transmission channels, malicious websites or hackers may attack the alternative transmission channels through the hidden relay points for further network penetration or data theft, resulting in security risks when using the alternative transmission channels for communication. The simulated influence area corresponding to the alternative transmission channel is the area threatened by security after the alternative transmission channel is maliciously attacked. The simulated influence area can be determined according to the positions, quantities, and connection relationships of the relay points suffering from malicious attacks. The simulated degree of influence of the simulated influence area can be determined based on the percentage of the data transmission rate decrease and the increased delay duration within the simulated influence area. Specifically, based on the preset influence degree mapping relationship, the simulated degree of influence corresponding to any combination of the percentage of the data transmission rate decrease and the increased delay duration can be determined. The specific content of the preset influence degree mapping relationship is not specifically limited in the embodiments of the present application.
[0089] Furthermore, in order to improve the accuracy when determining the simulated influence area, based on the simulated communication data of the alternative transmission channel, determining the simulated influence area corresponding to the alternative transmission channel may specifically include:
[0090] Identify the hidden positions of each hidden relay point in the alternative transmission channel. The hidden position of the hidden relay point is the sequential position of the hidden relay point among all the hidden relay points corresponding to the alternative transmission channel; based on the simulated communication data of the alternative transmission channel, determine the communication value level corresponding to each hidden relay point; based on the hidden position and communication value level of each hidden relay point, determine the relay point influence area corresponding to each hidden relay point, and determine the simulated influence area of the alternative transmission channel based on each relay point influence area.
[0091] Specifically, for any alternative transmission channel, since there may be one or more potential hazard relay points in the alternative transmission channel, first, it is necessary to determine the sequential position of each potential hazard relay point among all potential hazard relay points according to the data transmission direction of the alternative transmission channel. Since the data to be transmitted passes through each relay point along the alternative transmission channel, if two potential hazard relay points are closely related in terms of physical connection, data transmission path, network topology structure, or security and defense strategy, etc., the hazard of one potential hazard relay point is likely to affect the other potential hazard relay point. Therefore, when determining the simulated influence area of the alternative transmission channel, it is necessary to consider and analyze the hazard positions of each potential hazard relay point.
[0092] At the same time, it is also necessary to consider and analyze the corresponding communication value levels at each potential hazard relay point. The higher the communication value level, the larger the influence area of the relay point. The communication value level corresponding to each potential hazard relay point can be determined by identifying the communication data characteristics included in the communication data flowing through the potential hazard relay point. There is a hierarchical correspondence relationship between the communication data characteristics and the communication value levels. Based on this hierarchical correspondence relationship, the communication value level corresponding to any potential hazard relay point can be determined. After obtaining the quantization scores by quantifying the hazard positions and communication value levels, the influence area corresponding to each potential hazard relay point can be determined based on the quantization scores. Specifically, the potential hazard relay point can be determined as the center of the area, then the area size can be determined according to the quantization scores, and finally, the influence area corresponding to the potential hazard relay point can be determined based on the center of the area and the area size. Different quantization scores correspond to different area sizes, and the correspondence relationship between the quantization scores and the area sizes can be determined by relevant staff according to historical experimental data.
[0093] Step S220: Determine the simulated affected layer of each alternative transmission channel based on the simulated influence area of the alternative transmission channel and the simulated affected degree of each simulated influence area.
[0094] Specifically, for any alternative transmission channel, first, the channel layer corresponding to each alternative transmission channel can be determined based on each alternative transmission channel, and then the range of the corresponding simulated display area can be determined according to each simulated influence area in the alternative transmission channel, that is, each simulated influence area is boxed out from the channel layer. Then, according to the preset color depth mapping relationship and the simulated affected degree of each simulated influence area, the corresponding display color depth is determined. The preset color depth mapping relationship is the correspondence relationship between the simulated affected degree and the display color depth, and the specific content is not specifically limited in the embodiments of the present application. Finally, based on the display color depths of each simulated influence area, the display color depth of the corresponding simulated display area range is adjusted, and thus the simulated affected layer of the alternative transmission channel can be obtained. The simulated affected layers of each alternative transmission channel can be obtained based on the above method.
[0095] Step S230: Superimpose each simulated affected layer to obtain a target simulated layer, and determine a concerned simulated area based on the target simulated layer.
[0096] Specifically, the superimposition of multiple simulated affected layers can be implemented based on GIS software or a preset programming environment. After the superimposition operation is completed, a target simulated layer containing all simulated affected layers will be generated, and the target simulated layer will display the simulated affected degree of each simulated affected area. To improve the accuracy of the target simulated layer, data normalization processing can be performed on all simulated affected layers before the superimposition operation. For example, convert the data values of all simulated affected layers into the range of 0 - 100. The concerned simulated area can be determined from the target simulated layer based on a preset display color depth threshold, that is, the display color depth corresponding to the concerned simulated area is higher than the preset display color depth threshold. The specific preset display color depth threshold is not specifically limited in the embodiments of the present application and can be determined by relevant staff according to historical experimental data. After determining the concerned simulated area, the visualization function of GIS software can be used to highlight the concerned simulated area on the target simulated layer.
[0097] Step S240: Generate a defense reinforcement instruction based on the concerned simulated area and feedback the defense reinforcement instruction.
[0098] Specifically, the concerned simulated area is an area where there are relatively large security risks regardless of using any alternative transmission channel as the substitute transmission channel corresponding to the first preset time period. On the premise that it is necessary to use any alternative transmission channel as the substitute transmission channel corresponding to the first preset time period, the data security index of the concerned simulated area can be improved by generating a defense reinforcement instruction, so as to ensure that when using any alternative transmission channel as the substitute transmission channel corresponding to the first preset time period, the security risks faced by the concerned simulated area are effectively controlled.
[0099] An embodiment of the present application provides a control system, as Figure 3 shown, Figure 3 The control system 300 shown includes: a processor 301 and a memory 303. Among them, the processor 301 and the memory 303 are connected, such as through a bus 302. Optionally, the control system 300 may further include a transceiver 304. It should be noted that in practical applications, the transceiver 304 is not limited to one, and the structure of the control system 300 does not constitute a limitation to the embodiments of the present application.
[0100] The processor 301 may be a CPU (Central Processing Unit), a general-purpose processor, a DSP (Digital Signal Processor), an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. It can implement or execute various exemplary logical blocks, modules, and circuits described in connection with the disclosure of this application. The processor 301 may also be a combination that implements computing functions, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, etc.
[0101] The bus 302 may include a path for transmitting information between the above components. The bus 302 may be a PCI (Peripheral Component Interconnect) bus or an EISA (Extended Industry Standard Architecture) bus, etc. The bus 302 may be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 3 only one line is shown in the figure, but it does not mean that there is only one bus or one type of bus.
[0102] The memory 303 may be a ROM (Read Only Memory) or other type of static storage device that can store static information and instructions, a RAM (Random Access Memory) or other type of dynamic storage device that can store information and instructions, or it may also be an EEPROM (Electrically Erasable Programmable Read Only Memory), a CD-ROM (Compact Disc Read Only Memory), or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), magnetic disk storage media, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto.
[0103] The memory 303 is used to store the application program code for executing the solution of this application, and is controlled and executed by the processor 301. The processor 301 is used to execute the application program code stored in the memory 303 to implement the content shown in the foregoing method embodiments.
[0104] Among them, the management and control system includes but is not limited to: mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Tablet Computers), PMPs (Portable Multimedia Players), vehicle-mounted terminals (such as vehicle-mounted navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc. It can also be a server, etc. Figure 3 The management and control system shown is only an example, and should not impose any restrictions on the functions and usage scope of the embodiments of this application.
[0105] The embodiments of this application provide a computer-readable storage medium, on which a computer program is stored. When it runs on a computer, it enables the computer to execute the corresponding content in the foregoing method embodiments.
[0106] The embodiments of this application provide a computer program product, which includes a computer program that implements the method in any of the above embodiments when executed by a processor.
[0107] It should be understood that although the steps in the flowchart of the accompanying drawings are shown in sequence according to the indication of the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless there is a clear indication in this article, the execution of these steps has no strict order restriction, and they can be executed in other orders. Moreover, at least a part of the steps in the flowchart of the accompanying drawings may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily executed at the same time, but can be executed at different times. Their execution order is not necessarily sequential, but can be executed alternately or alternately with at least a part of other steps or sub-steps or stages of other steps.
[0108] The above are only some implementation manners of this application. It should be noted that for those of ordinary skill in the art, without departing from the principle of this application, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of this application.
Claims
1. A security management and control method applied to a communication base station, characterized in that: include: Acquire real-time communication data of the communication base station to be controlled, and identify communication characteristics corresponding to the real-time communication data, wherein the real-time communication data includes real-time transmission data and real-time access data; When the communication feature includes a preset hidden danger feature, determining that the real-time communication data is hidden danger communication data; Identify the hidden danger transmission behavior and the hidden danger access behavior corresponding to the hidden danger communication data, and determine the hidden danger transmission channel corresponding to the hidden danger communication data and the affected coverage area corresponding to the hidden danger transmission channel based on the hidden danger transmission behavior and the hidden danger access behavior; Determine a backup transmission channel based on the hidden danger transmission channel and the historical communication demand of the affected coverage area, and generate a hidden danger isolation instruction based on the backup transmission channel to isolate the hidden danger transmission channel, and use the backup transmission channel to provide communication services for the affected coverage area; The step of determining a substitute transmission channel based on the hidden danger transmission channel and the historical communication demand of the affected coverage area includes: Performing feature recognition on the hidden danger transmission channel to obtain a hidden danger relay point corresponding to the hidden danger transmission channel; Determine at least one primary transmission channel based on the affected coverage area, and screen the at least one primary transmission channel based on the hidden danger relay point to obtain at least one secondary transmission channel, wherein the secondary transmission channel does not contain the hidden danger relay point; Based on the historical communication demand affecting the coverage area, each secondary transmission channel is evaluated to obtain a channel score of each secondary transmission channel, wherein the historical communication demand includes historical communication volume, historical communication rate, and historical communication safety factor; Based on the channel score of each secondary transmission channel, a substitute transmission channel is determined from the at least one secondary transmission channel.
2. According to claim 1, a security management and control method applied to a communication base station is characterized in that: When there is no secondary transmission channel, it also includes: Based on the at least one primary transmission channel and the hidden danger relay point, determining at least one candidate transmission channel, wherein the candidate transmission channel includes hidden danger relay points, and the number of the hidden danger relay points included is less than a preset number of hidden dangers; Determining a predicted communication demand corresponding to a first preset time period based on the historical communication demand affecting the coverage area; Performing communication simulation on each candidate transmission channel based on the predicted communication demand to obtain simulated communication data corresponding to each candidate transmission channel, and determining a simulation score for each candidate transmission channel based on the type and number of simulated hidden danger features appearing in each simulated communication data; Based on the simulation score of each candidate transmission channel, a substitute transmission channel corresponding to the first preset time period is determined from the at least one candidate transmission channel.
3. A security management and control method applied to a communication base station according to claim 2, characterized in that: Also includes: Determine, based on the simulated communication data of each candidate transmission channel, a simulated impact area corresponding to each candidate transmission channel and a simulated impact degree of each simulated impact area; Determine a simulated affected layer of each candidate transmission channel based on the simulated affected area of the candidate transmission channel and the simulated affected degree of each simulated affected area; Superimposing each simulated affected layer to obtain a target simulated layer, and determining a simulation area of interest based on the target simulated layer; A defense reinforcement instruction is generated based on the simulated area of interest, and the defense reinforcement instruction is fed back.
4. A security control method applied to a communication base station according to claim 3, characterized in that: Determining a simulated impact area corresponding to the candidate transmission channel based on simulated communication data of the candidate transmission channel includes: Identify the hidden danger position of each hidden danger relay point in the alternative transmission channel, where the hidden danger position of the hidden danger relay point is the sequential position of the hidden danger relay point in all the hidden danger relay points corresponding to the alternative transmission channel; Determine the communication value level corresponding to each hidden danger relay point based on the simulated communication data of the alternative transmission channel; Based on the hidden danger position and communication value level of each hidden danger relay point, the relay point influence area corresponding to each hidden danger relay point is determined, and based on each relay point influence area, the simulated influence area of the alternative transmission channel is determined.
5. A security management and control method applied to a communication base station according to claim 2, characterized in that: Before determining at least one candidate transmission channel based on the at least one primary transmission channel and the vulnerable relay point, the method further includes: Acquire defense data of each hidden danger relay point in the hidden danger transmission channel within a second preset time period, and identify the number of defense times and the defense success rate from each defense data; Determine the defense score of each hidden danger relay point based on the number of defenses and the defense success rate corresponding to each hidden danger relay point; Hidden hidden danger relay points whose defense scores are lower than the preset scores are processed.
6. A management and control system, characterized in that: The control system includes: at least one processor; Memory; At least one application, wherein the at least one application is stored in a memory and configured to be executed by at least one processor, and the at least one application is configured to: execute a security management and control method applied to a communication base station according to any one of claims 1-5.
7. A computer-readable storage medium, characterized in that: include: A computer program is stored which can be loaded by a processor and executed according to any one of claims 1 to 5, and is applied to a security management and control method for a communication base station.
8. A computer program product, characterized in that It includes a computer program, which, when executed by a processor, implements the steps of a security management and control method applied to a communication base station according to any one of claims 1 to 5.
Citation Information
Patent Citations
Network isolation method and device, electronic equipment and storage medium
CN111683040A
Satellite communication data transmission method and device, server and storage medium
CN117294340A