Method, apparatus, electronic device, and storage medium for screening user traffic
By creating a target database in the LTE core network and matching the uplink tunnel of the signaling traffic request packet, the problem of low screening and forwarding of the target user signaling traffic data in the existing technology is solved, and accurate screening and forwarding of the traffic data of the LTE core network is realized, and the efficiency and accuracy of data analysis are improved.
Patent Information
- Application Number
- CN202510088221.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-20
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2045-01-20
AI Technical Summary
The prior art is difficult to effectively screen and forward signaling traffic data of target users in the LTE core network, resulting in too large data received by the analysis system and increasing the difficulty of analysis.
By responding to the signaling traffic filtering instruction of the target user, obtain the target user's identity, determine the target control tunnel associated with the target user and its default bearer identity, create a target database, and forward it to the target analysis system when the uplink tunnel of the target signaling traffic request packet matches the control tunnel in the target database.
It realizes accurate screening and forwarding of LTE core network traffic data, reduces the amount of irrelevant data processed by the analysis system, and improves the efficiency and accuracy of data analysis.
Smart Images

Figure CN119562307B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of LTE core networks, and particularly to a method, apparatus, electronic device, and storage medium for screening user traffic. Background Art
[0002] The main interfaces of the LTE (Long Term Evolution) core network are S11, S1-U, S58-C, and S58-U. Among them, S11 and S58-C are control plane interfaces, and S1-U and S58-U are user plane interfaces. At present, the log retention system will simultaneously access the traffic of S11, S1-U, S58-C, and S58-U, parse the traffic of all users, generate logs for retention; at the same time, these data are accessed to the subsequent analysis system (this analysis system is only interested in the traffic data generated by certain users, for example, the location information of the target user), which will cause the analysis system to receive too much data and increase the analysis difficulty of the analysis system.
[0003] How to screen these traffic data and send them to the matching analysis system is a key issue studied in the industry. Summary of the Invention
[0004] The present invention provides a method, apparatus, electronic device, and storage medium for screening user traffic to screen the traffic data generated by the LTE core network and provide a basis for improving the efficiency and accuracy of subsequent data analysis work.
[0005] According to one aspect of the present invention, a method for screening user traffic is provided. The method includes:
[0006] In response to a screening instruction for the signaling traffic of a target user, obtain the target user identifier of the target user;
[0007] Determine a target control tunnel associated with the target user and at least one default bearer identifier belonging to the target control tunnel;
[0008] Create a target database based on the target control tunnel and the default bearer identifier belonging to the target control tunnel;
[0009] In response to a screening instruction for a target signaling traffic request packet, when it is determined that the target uplink tunnel of the target signaling traffic request packet matches each target control tunnel in the target database, forward the target signaling traffic request packet to the target analysis system.
[0010] According to another aspect of the present invention, a device for screening user traffic is provided. The device includes:
[0011] A target user identifier acquisition module, configured to acquire a target user identifier of the target user in response to a screening instruction for signaling traffic of the target user;
[0012] A target control tunnel determination module, configured to determine a target control tunnel associated with the target user and at least one default bearer identifier belonging to the target control tunnel;
[0013] A target database creation module, configured to create a target database based on the target control tunnel and the default bearer identifier belonging to the target control tunnel;
[0014] A signaling traffic forwarding module, configured to, in response to a screening instruction for a target signaling traffic request packet, forward the target signaling traffic request packet to a target analysis system when it is determined that a target uplink tunnel of the target signaling traffic request packet matches each target control tunnel in the target database.
[0015] According to another aspect of the present invention, there is provided an electronic device, including:
[0016] At least one processor; and
[0017] A memory communicatively connected to the at least one processor; wherein,
[0018] The memory stores a computer program executable by the at least one processor, and when the computer program is executed by the at least one processor, the at least one processor is enabled to execute the user traffic screening method according to any embodiment of the present invention.
[0019] According to another aspect of the present invention, there is provided a computer-readable storage medium storing computer instructions for causing a processor to implement the user traffic screening method according to any embodiment of the present invention when executed.
[0020] According to another aspect of the present invention, there is provided a computer program product including a computer program that implements the user traffic screening method according to any embodiment of the present invention when executed by a processor.
[0021] The technical solution of the embodiment of the present invention obtains the target user identifier of the target user by responding to the screening instruction of the signaling traffic of the target user; determines the target control tunnel associated with the target user and at least one default bearer identifier belonging to the target control tunnel; creates a target database based on the target control tunnel and the default bearer identifier belonging to the target control tunnel; and responds to the screening instruction of the target signaling traffic request packet, and forwards the target signaling traffic request packet to the target analysis system when it is determined that the target uplink tunnel of the target signaling traffic request packet matches each target control tunnel in the target database. It can screen the traffic data generated by the LTE core network and provide a basis for improving the efficiency and accuracy of subsequent data analysis work.
[0022] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present invention, nor is it used to limit the scope of the present invention. Other features of the present invention will become easily understood through the following description. Brief Description of the Drawings
[0023] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0024] Figure 1 It is a flowchart of a method for screening user traffic provided in Embodiment 1 of the present invention;
[0025] Figure 2 It is a flowchart of a method for screening user traffic provided in Embodiment 2 of the present invention;
[0026] Figure 3 It is a schematic diagram of the relationship between a control tunnel and a default bearer provided in Embodiment 2 of the present invention;
[0027] Figure 4 It is a schematic structural diagram of a device for screening user traffic provided in Embodiment 3 of the present invention;
[0028] Figure 5 It is a schematic structural diagram of an electronic device for implementing the method for screening user traffic in the embodiment of the present invention. Detailed Embodiments
[0029] To enable those skilled in the art to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative work shall fall within the protection scope of the present invention.
[0030] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present invention described here can be implemented in an order other than those illustrated or described here. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device including a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0031] Embodiment 1
[0032] Figure 1 is a flowchart of a method for screening user traffic provided according to Embodiment 1 of the present invention. This embodiment is applicable to the situation of screening traffic data generated by the LTE core network. This method can be executed by a user traffic screening device, and the user traffic screening device can be implemented in the form of hardware and / or software. The user traffic screening device can be configured in electronic devices such as computers, servers, or tablet computers. As Figure 1 shown, the method includes:
[0033] Step 110, in response to a screening instruction for the signaling traffic of a target user, obtain the target user identifier of the target user.
[0034] Among them, the target user can be any user accessing the LTE core network, and it is not limited in this embodiment.
[0035] Among them, the target user identifier of the target user can be the mobile phone number of the target user, or other parameters that can uniquely identify the target user. For example, the user name or registration identifier in the registration information of the target user, etc., and it is not limited in this embodiment.
[0036] It can be understood that in the LTE core network, signaling traffic containing information such as the user's location is transmitted in the control plane interface. Therefore, after receiving the screening instruction for the location information of the target user, the signaling traffic data transmitted by the LTE core network through the control plane interfaces S11 and S58-C can be obtained, and further, the screening or shunting processing can be performed on each signaling traffic data.
[0037] In this embodiment, the signaling traffic of the target user may include information such as the location information of the target user or the user's mobile phone number, etc., which is not limited in this embodiment.
[0038] In an alternative implementation manner of this embodiment, after receiving the screening instruction for the location information of the target user, the received screening instruction can be further parsed to obtain the target user identifier of the target user.
[0039] Optionally, in this embodiment, obtaining the target user identifier of the target user may include: obtaining the attachment request and / or PDN (Packet Data Network, creating a specific packet data network) connection request of the target user; determining the target user identifier of the target user based on the attachment request and / or PDN connection request.
[0040] In this embodiment, a mobile device, such as a mobile phone, will trigger the CreatSession process of the S11 and S58-C interfaces in the LTE core network during processes such as attachment and creating a PDN connection; information such as the mobile phone number, initial location, and default bearer identifier can be carried in the CreatSession process.
[0041] In an alternative implementation manner of this embodiment, after receiving the screening instruction for the signaling traffic of the target user, the attachment request related to the target user and the CreatSession process in the PDN connection request can be further obtained, and the request of the CreatSession process can be parsed to obtain the mobile phone number of the target user; further, the mobile phone number of the target user can be determined as the target user identifier of the target user.
[0042] Step 120, determine the target control tunnel associated with the target user, and at least one default bearer identifier belonging to the target control tunnel.
[0043] Optionally, in an alternative implementation of this embodiment, after receiving the screening instruction for the signaling traffic of the target user, the target control tunnel associated with the target user and the default bearer identifiers matching each target control tunnel may be further determined. It can be understood that one control tunnel may be associated with multiple default bearer identifiers, that is, multiple default bearer identifiers may belong to the target control tunnel at the same time. For example, there may be 2, 3, or 10, etc. This embodiment does not limit it.
[0044] In an alternative implementation of this embodiment, after receiving the screening instruction for the signaling traffic of the target user, the attachment request related to the target user and the create session process in the PDN connection request may be further obtained, and the response to the create session process may be parsed to obtain the information of the GW-side tunnel of the target user and the default bearer identifier.
[0045] Optionally, in this embodiment, determining the target control tunnel associated with the target user and at least one default bearer identifier matching the target control tunnel may include: obtaining a first create session process matching the attachment request, and determining the first uplink and downlink tunnel created in the first create session process and the first bearer identifier; determining the first uplink and downlink tunnel as the target control tunnel and the first bearer identifier as the default bearer identifier belonging to the target control tunnel; or obtaining a second create session process matching the PDN connection request, and determining the second uplink and downlink tunnel created in the second create session process and the second bearer identifier; determining the second uplink and downlink tunnel as the target control tunnel and the second bearer identifier as the default bearer identifier belonging to the target control tunnel.
[0046] In an alternative implementation of this embodiment, a first create session process matching the attachment request of the mobile device of the target user may be obtained. Specifically, when receiving the request and response of the first create session process, the user identifier may be extracted from the Create Session Request; the default bearer identifier (EBI) may be extracted from the Create Session Response. In this embodiment, this default bearer identifier is referred to as the first bearer identifier; and the GW-side tunnel information (such as TEID or creation time). In this embodiment, this GW-side tunnel is referred to as the first uplink and downlink tunnel. Further, the obtained first uplink and downlink tunnel may be determined as the target control tunnel, and the first bearer identifier may be determined as the default bearer identifier belonging to the target control tunnel.
[0047] In this embodiment, the control plane interfaces S11 and S58-C are not distinguished. The MME-C of S11 and the SGW-C of S58-C are replaced by the AC side, and the SGW-C of S11 and the PGW-C of S58-C are replaced by the GW side. In this embodiment, only the GW side tunnel is taken as an example for illustration, which is not a limitation to this embodiment.
[0048] In another optional implementation manner of this embodiment, a second session creation process matching the PDN connection request of the target user's mobile device can be obtained. Specifically, when receiving the request and response of the second session creation process, the user identifier can be extracted from the Create Session Request; the default bearer identifier (EBI) is extracted from the Create Session Response. In this embodiment, this default bearer identifier is referred to as the second bearer identifier; and the GW side tunnel information (for example, TEID or creation time). In this embodiment, this GW side tunnel is referred to as the second uplink and downlink tunnel. Further, the obtained second uplink and downlink tunnel can be determined as the target control tunnel, and the second bearer identifier is determined as the default bearer identifier belonging to the target control tunnel.
[0049] Step 130: Create a target database based on the target control tunnel and the default bearer identifier belonging to the target control tunnel.
[0050] In an optional implementation manner of this embodiment, after determining the target control tunnel and each default bearer identifier matching the target control tunnel, a target database can be further created according to the target control tunnel and each default bearer identifier matching the target control tunnel.
[0051] Optionally, in this embodiment, after determining the target control tunnel and each default bearer identifier matching the target control tunnel, the target control tunnel and each default bearer identifier matching the target control tunnel can be further stored in a target area, for example, in a folder with a set path or in a cloud database, so as to obtain the target database.
[0052] Step 140: In response to the screening instruction of the target signaling traffic request packet, when it is determined that the target uplink tunnel of the target signaling traffic request packet matches each target control tunnel in the target database, forward the target signaling traffic request packet to the target analysis system.
[0053] Optionally, in this embodiment, after receiving a target signaling traffic request packet through the control plane interface S11 or S58-C of the LTE core network, the target signaling traffic request packet may be parsed to obtain the target uplink tunnel of the target signaling traffic; further, the target uplink tunnel may be compared with each target control tunnel stored in the target database to determine whether the target database contains the target uplink tunnel; when it is determined that the target uplink tunnel of the target signaling traffic request packet matches each target control tunnel in the target database, that is, when it is determined that the target database contains the target uplink tunnel, it may be determined that the target signaling traffic request packet is signaling traffic related to the target user, and the target signaling traffic request packet may be forwarded to the target analysis system.
[0054] The technical solution of this embodiment obtains the target user identifier of the target user by responding to the screening instruction of the signaling traffic of the target user; determines the target control tunnel associated with the target user and at least one default bearer identifier belonging to the target control tunnel; creates a target database based on the target control tunnel and the default bearer identifier belonging to the target control tunnel; in response to the screening instruction of the target signaling traffic request packet, when it is determined that the target uplink tunnel of the target signaling traffic request packet matches each target control tunnel in the target database, forwards the target signaling traffic request packet to the target analysis system; can screen the traffic data generated by the LTE core network, providing a basis for improving the efficiency and accuracy of subsequent data analysis work.
[0055] Embodiment 2
[0056] Figure 2 is a flowchart of a method for screening user traffic according to Embodiment 2 of the present invention. This embodiment further refines the above technical solution, and the technical solution in this embodiment can be combined with each optional solution in one or more of the above embodiments. As Figure 2 shown, the method includes:
[0057] Step 210, receive a screening instruction for the signaling traffic of the target user.
[0058] Step 220, obtain the attachment request of the target user and / or the request for creating a specific packet data network (PDN) connection; determine the target user identifier of the target user based on the attachment request and / or the PDN connection request.
[0059] Step 230, determine the target control tunnel associated with the target user and at least one default bearer identifier that matches the target control tunnel.
[0060] Optionally, in this embodiment, while obtaining the first session creation procedure that matches the attachment request, determining the first uplink and downlink tunnels created in the first session creation procedure, and the first bearer identifier, and obtaining the second session creation procedure that matches the PDN connection request, and determining the second uplink and downlink tunnels created in the second session creation procedure, and the second bearer identifier, or, after obtaining the first session creation procedure that matches the attachment request, determining the first uplink and downlink tunnels created in the first session creation procedure, and the first bearer identifier, and obtaining the second session creation procedure that matches the PDN connection request, and determining the second uplink and downlink tunnels created in the second session creation procedure, and the second bearer identifier, it is also possible to obtain the first session deletion procedure that matches the attachment request, or obtain the second session deletion procedure that matches the PDN connection request; respectively obtain the attribute information of the first session creation procedure, the first session deletion procedure, the second session creation procedure, and the second session deletion procedure; determine the creation time and deletion time of each target control tunnel according to each piece of the attribute information.
[0061] Among them, the attribute information may include the user identifier, tunnel identifier, default bearer identifier, creation time or deletion time of each session, etc.; by way of example, the first session creation procedure may include: user identifier, tunnel identifier, at least one default bearer identifier, and the creation time of the first session creation procedure; the first session deletion procedure may include: user identifier, tunnel identifier, at least one default bearer identifier, and the deletion time of the first session deletion procedure.
[0062] In an optional implementation manner of this embodiment, during the process of determining the target control tunnel associated with the target user and each default bearer identifier that matches the target control tunnel, it is also possible to obtain the attribute information of each session creation or session deletion. Further, the creation time and deletion time of the target control tunnel can be determined according to the obtained attribute information.
[0063] By way of example, Figure 3 is a schematic diagram showing the relationship between a control tunnel and a default bearer according to Embodiment 2 of the present invention. As Figure 3 shown, the target control tunnel may include control tunnel 1 and control tunnel 2; among them, control tunnel 1 includes two default bearer identifiers, namely default bearer id = 5 and default bearer id = 6; control tunnel 2 includes one default bearer identifier, which is default bearer id = 5.
[0064] It should be noted that in the process of creating a session, during the attachment request process of the target user's mobile phone, the LTE core network will create uplink and downlink tunnels for the mobile phone on the control plane interfaces S11 and S58-C, and allocate a default bearer and an ID; for example: ID = 5. When the target user's mobile phone creates a PDN connection request, uplink and downlink tunnels of S11 and S58-C will be created for the mobile phone (in this process, the attachment process may be reused), and a default bearer ID will be allocated; for example: ID = 6; It can be understood that the same mobile phone of the target user may create multiple PDN connections; therefore, multiple default bearers may be hung under one control tunnel of S11 / S58-C.
[0065] It should also be noted that in the process of deleting a session, if the default bearer identifier is not carried, it means deleting all default bearers under the control tunnel and deleting the control tunnel; if the default bearer identifier is carried, it means deleting the default bearer with the default bearer identifier. When the deletion sessions with the default bearer identifier carried multiple times cause all default bearers to be deleted, the control tunnel needs to be automatically deleted.
[0066] It can be understood that the initial position of the mobile phone is in CreatSession; when the position of the mobile phone changes, it will be reflected in ModifyBear; from the creation of the control tunnel in CreatSession to the destruction of the control tunnel in DeleteSession, and the intermediate ModifyBear, cover all the signaling of the mobile phone including the position.
[0067] Step 240, create a target database based on the target control tunnel and the default bearer identifiers belonging to the target control tunnel.
[0068] In an alternative implementation of this embodiment, after obtaining each target control tunnel, the default bearer identifiers matching each target control tunnel, the creation time and deletion time of each target control tunnel, the target control tunnel (for example, the identifier of the target control tunnel), the default bearer identifiers belonging to the target control tunnel, the creation time and deletion time of the target control tunnel can be further stored in the target area to obtain the target database.
[0069] Step 250, parse the target signaling traffic request packet to obtain the identifier of the target uplink tunnel; determine whether the identifier of the target uplink tunnel matches the identifiers of the target control tunnels recorded in the target database; when it is determined that the identifier of the target uplink tunnel is consistent with the identifier of the target control tunnel, forward the target signaling traffic request packet to the target analysis system.
[0070] In an alternative implementation of this embodiment, after constructing the target database associated with the target user, if the control plane interface receives a target signaling traffic request packet, the target signaling traffic request packet can be further parsed to obtain the identifier of the target uplink tunnel in the target signaling traffic request packet; further, it can be determined whether the identifier of the target uplink tunnel matches the identifiers of the target control tunnels recorded in the target database; if it is determined that the identifier of the target uplink tunnel is consistent with the identifier of the target control tunnel, it can be determined that the identifier of the target uplink tunnel matches the identifiers of the target control tunnels recorded in the target database, and further, the target signaling traffic request packet can be forwarded to the target analysis system.
[0071] Exemplarily, the identifier of the target control tunnel can be the IP or teid of each target control tunnel, which is not limited in this embodiment.
[0072] Further, the target analysis system can perform subsequent analysis and processing on the received signaling traffic request packets; exemplarily, if the target signaling traffic request packets contain the location information of the target user, then the target analysis system can determine the location change trajectory of the target user by analyzing this location information.
[0073] Step 260, in the case where it is determined that the identifier of the target uplink tunnel is consistent with the identifier of the target control tunnel, determine the target signaling traffic response packet corresponding to the target signaling traffic request packet; forward the target signaling traffic response packet to the target analysis system.
[0074] In an alternative implementation of this embodiment, in the case where it is determined that the identifier of the target uplink tunnel is consistent with the identifier of the target control tunnel, that is, in the case where it is determined that the identifier of the target uplink tunnel matches the identifiers of the target control tunnels recorded in the target database, the target signaling traffic response packet corresponding to the target signaling traffic request packet can be further determined, and the target signaling traffic response packet can be forwarded to the target analysis system so that the target analysis system can process based on the target signaling traffic request packet and the target signaling traffic response packet to obtain a more accurate processing result.
[0075] Optionally, in this embodiment, the target signaling traffic response packet can be determined from multiple signaling traffic response packets according to the identifier or sequence number of the target signaling traffic request packet.
[0076] In the solution of this embodiment, after constructing the target database that matches the target user, the target signaling traffic request packet can be parsed to obtain the identifier of the target uplink tunnel; determine whether the identifier of the target uplink tunnel matches the identifiers of the target control tunnels recorded in the target database; when it is determined that the identifier of the target uplink tunnel is consistent with the identifier of the target control tunnel, forward the target signaling traffic request packet to the target analysis system; when it is determined that the identifier of the target uplink tunnel is consistent with the identifier of the target control tunnel, determine the target signaling traffic response packet corresponding to the target signaling traffic request packet; forward the target signaling traffic response packet to the target analysis system, and can screen each target signaling traffic request packet based on the target database, and the target data for the target analysis system to analyze can be obtained, providing a basis for quickly and accurately obtaining the analysis result subsequently.
[0077] To better understand the method for screening user traffic involved in this embodiment, the following uses a specific example to describe the implementation manner of this solution:
[0078] 1) Database:
[0079] Establish a database to store the uplink GW-side tunnels of the target user. One control tunnel may correspond to multiple default bearers.
[0080] 2) Addition:
[0081] Specifically, in the session creation process, check whether the mobile phone number in the CreateSessionReq is the target user; if so, learn the GW-side tunnel and default bearer id in the corresponding CreateSessionResp into the database, and forward the CreateSessionReq / Resp to the targeted analysis system; if not, do not further process.
[0082] 3) Modification:
[0083] Specifically, in ModifyBear, the downlink control tunnel is modified. Therefore, it can be not considered; it can be understood that the control tunnel is bidirectional and is distinguished between uplink and downlink. The downlink is easily modified. Therefore, we store the uplink tunnel; therefore, the tunnels in the database only involve addition and deletion, and do not involve modification.
[0084] 4) Deletion:
[0085] Specifically, in the deletion session process, a single default bearer, all default bearers, and the control tunnel are deleted. If the default bearer identifier is not carried, it means deleting all default bearers under the control tunnel and deleting the control tunnel. If the default bearer identifier is carried, it means deleting the default bearer with the default bearer identifier. When multiple deletion sessions with different default bearer identifiers cause all default bearers to be deleted, the control tunnel needs to be deleted.
[0086] 5) Traffic filtering:
[0087] Specifically, it can be checked whether the uplink tunnel of the signaling traffic request packet hits the database. If it hits, the request packet is forwarded to the directional analysis system, and the corresponding response packet is associated through the ip-pair + seqnum of the request packet and also forwarded to the directional analysis system. If it does not hit, no further processing is performed.
[0088] The solution of this embodiment can filter the signaling traffic containing the location of certain 4G users through the S11 and S58-C control interfaces and output it to the directional traffic analysis system, reducing the traffic processing pressure of the directional traffic analysis system.
[0089] Embodiment III
[0090] Figure 4 is a schematic structural diagram of a user traffic screening device provided according to Embodiment III of the present invention. As Figure 4 shown, the device includes: a target user identifier acquisition module 410, a target control tunnel determination module 420, a target database creation module 430, and a signaling traffic forwarding module 440.
[0091] Among them, the target user identifier acquisition module 410 is configured to acquire the target user identifier of the target user in response to a screening instruction for the signaling traffic of the target user;
[0092] The target control tunnel determination module 420 is configured to determine a target control tunnel associated with the target user and at least one default bearer identifier belonging to the target control tunnel;
[0093] The target database creation module 430 is configured to create a target database based on the target control tunnel and the default bearer identifier belonging to the target control tunnel;
[0094] The signaling traffic forwarding module 440 is configured to, in response to a screening instruction for a target signaling traffic request packet, forward the target signaling traffic request packet to the target analysis system when it is determined that the target uplink tunnel of the target signaling traffic request packet matches each target control tunnel in the target database.
[0095] In the solution of this embodiment, the target user identifier acquisition module responds to a screening instruction for the signaling traffic of the target user to obtain the target user identifier of the target user; the target control tunnel determination module determines a target control tunnel associated with the target user and at least one default bearer identifier belonging to the target control tunnel; the target database creation module creates a target database based on the target control tunnel and the default bearer identifiers belonging to the target control tunnel; the signaling traffic forwarding module responds to a screening instruction for a target signaling traffic request packet, and when it is determined that the target uplink tunnel of the target signaling traffic request packet matches each target control tunnel in the target database, forwards the target signaling traffic request packet to the target analysis system, so as to screen the traffic data generated by the LTE core network and provide a basis for improving the efficiency and accuracy of subsequent data analysis work.
[0096] In an alternative implementation of this embodiment, the target user identifier acquisition module 410 is specifically configured to obtain the attachment request of the target user and / or a request for creating a specific packet data network (PDN) connection;
[0097] Determine the target user identifier of the target user based on the attachment request and / or the PDN connection request.
[0098] In an alternative implementation of this embodiment, the target control tunnel determination module 420 is specifically configured to obtain a first session creation process that matches the attachment request, and determine the first uplink and downlink tunnels created in the first session creation process, and a first bearer identifier;
[0099] Determine the first uplink and downlink tunnels as the target control tunnel, and determine the first bearer identifier as the default bearer identifier belonging to the target control tunnel;
[0100] Or,
[0101] Obtain a second session creation process that matches the PDN connection request, and determine the second uplink and downlink tunnels created in the second session creation process, and a second bearer identifier;
[0102] Determine the second uplink and downlink tunnels as the target control tunnel, and determine the second bearer identifier as the default bearer identifier belonging to the target control tunnel.
[0103] In an alternative implementation of this embodiment, the target control tunnel determination module 420 is further specifically configured to obtain a first session deletion process that matches the attachment request, or obtain a second session deletion process that matches the PDN connection request;
[0104] Obtain the attribute information of the first session creation process, the first session deletion process, the second session creation process, and the first session deletion process respectively;
[0105] Determine the creation time and deletion time of each target control tunnel according to the respective attribute information.
[0106] In an alternative implementation manner of this embodiment, the target database creation module 430 is specifically configured to store the target control tunnel, the default bearer identifier belonging to the target control tunnel, the creation time and deletion time of the target control tunnel into a target area to obtain the target database.
[0107] In an alternative implementation manner of this embodiment, the signaling traffic forwarding module 440 is specifically configured to parse a target signaling traffic request packet to obtain the identifier of the target uplink tunnel;
[0108] Determine whether the identifier of the target uplink tunnel matches the identifiers of the target control tunnels recorded in the target database;
[0109] When it is determined that the identifier of the target uplink tunnel is consistent with the identifier of the target control tunnel, forward the target signaling traffic request packet to the target analysis system.
[0110] In an alternative implementation manner of this embodiment, the signaling traffic forwarding module 440 is further specifically configured to determine a target signaling traffic response packet corresponding to the target signaling traffic request packet when it is determined that the identifier of the target uplink tunnel is consistent with the identifier of the target control tunnel;
[0111] Forward the target signaling traffic response packet to the target analysis system.
[0112] The user traffic screening device provided by the embodiments of the present invention can execute the user traffic screening method provided by any embodiment of the present invention, and has the corresponding functional modules and beneficial effects for executing the method.
[0113] Embodiment Four
[0114] Figure 5The structural schematic diagram of an electronic device 10 that can be used to implement the embodiments of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or claimed herein.
[0115] As Figure 5 shown, the electronic device 10 includes at least one processor 11, and a memory communicatively connected to the at least one processor 11, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc. The memory stores a computer program executable by the at least one processor. The processor 11 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 into the random access memory (RAM) 13. In the RAM 13, various programs and data required for the operation of the electronic device 10 can also be stored. The processor 11, the ROM 12, and the RAM 13 are connected to each other via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.
[0116] A plurality of components in the electronic device 10 are connected to the I / O interface 15, including: an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a disk, an optical disc, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.
[0117] The processor 11 may be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The processor 11 executes the various methods and processes described above, such as the method for screening user traffic, which includes: in response to a screening instruction for the signaling traffic of a target user, obtaining the target user identifier of the target user; determining a target control tunnel associated with the target user and at least one default bearer identifier belonging to the target control tunnel; creating a target database based on the target control tunnel and the default bearer identifier belonging to the target control tunnel; and in response to a screening instruction for a target signaling traffic request packet, when determining that the target uplink tunnel of the target signaling traffic request packet matches each target control tunnel in the target database, forwarding the target signaling traffic request packet to a target analysis system.
[0118] In some embodiments, the method for screening user traffic may be implemented as a computer program tangibly embodied in a computer-readable storage medium, such as the storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed onto the electronic device 10 via the ROM 12 and / or the communication unit 19. When the computer program is loaded into the RAM 13 and executed by the processor 11, one or more steps of the method for screening user traffic described above may be executed. Alternatively, in other embodiments, the processor 11 may be configured to execute the method for screening user traffic in any other suitable manner (e.g., by means of firmware).
[0119] The various embodiments of the systems and technologies described above herein may be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-chip (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include: implemented in one or more computer programs executable and / or interpretable on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting the data and instructions to the storage system, the at least one input device, and the at least one output device.
[0120] A computer program for implementing the method of the present invention can be written in any combination of one or more programming languages. These computer programs can be provided to a processor of a general purpose computer, a special purpose computer, or other programmable data processing device, such that the computer programs, when executed by the processor, cause the functions / operations specified in the flowchart and / or block diagram to be implemented. The computer program can be executed entirely on the machine, partly on the machine, as a stand-alone software package partly on the machine and partly on a remote machine, or entirely on a remote machine or server.
[0121] In the context of the present invention, a computer-readable storage medium can be a tangible medium that can contain or store a computer program for use by or in connection with an instruction execution system, apparatus, or device. The computer-readable storage medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. Alternatively, the computer-readable storage medium can be a machine-readable signal medium. More specific examples of the machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0122] In order to provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the electronic device. Other kinds of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).
[0123] The systems and techniques described herein can be implemented in a computing system including backend components (e.g., as a data server), or a computing system including middleware components (e.g., an application server), or a computing system including frontend components (e.g., a user computer having a graphical user interface or a web browser through which a user can interact with an implementation of the systems and techniques described herein), or a computing system including any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected with each other by digital data communication in any form or medium (e.g., a communication network). Examples of communication networks include: local area network (LAN), wide area network (WAN), blockchain network, and the Internet.
[0124] A computing system can include a client and a server. The client and the server are generally remote from each other and typically interact through a communication network. The client-server relationship is created by computer programs running on respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or a cloud host, which is a host product in the cloud computing service system, solving the defects of difficult management and weak business scalability existing in traditional physical hosts and VPS services.
[0125] It should be understood that various forms of the processes shown above can be used, with steps reordered, added, or deleted. For example, the steps recited in the present invention can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present invention can be achieved, and no limitation is made herein.
[0126] The above specific embodiments do not constitute a limitation on the protection scope of the present invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention shall be included within the protection scope of the present invention.
Claims
1. A method for screening user traffic, characterized in that: include: In response to a filter instruction of the signaling traffic of the target user, obtaining a target user identifier of the target user; Determining a target control tunnel associated with the target user and at least one default bearer identifier belonging to the target control tunnel; Creating a target database based on the target control tunnel and a default bearer identifier belonging to the target control tunnel; In response to a screening instruction of a target signaling traffic request packet, forwarding the target signaling traffic request packet to a target analysis system when it is determined that a target uplink tunnel of the target signaling traffic request packet matches each target control tunnel in the target database; The step of creating a target database based on the target control tunnel and a default bearer identifier belonging to the target control tunnel includes: Determining a creation time and a deletion time of each of the target control tunnels; The target control tunnel, the default bearer identifier belonging to the target control tunnel, the creation time and the deletion time of the target control tunnel are stored in the target area to obtain the target database.
2. The method for screening user traffic according to claim 1, characterized in that: The step of obtaining a target user identifier of the target user includes: Obtaining an attachment request of the target user and / or a request to create a specific packet data network PDN connection; A target user identifier of the target user is determined based on the attach request and / or the PDN connection request.
3. The method for screening user traffic according to claim 2, characterized in that: The determining of a target control tunnel associated with the target user and at least one default bearer identifier belonging to the target control tunnel includes: Acquire a first session creation process that matches the attachment request, and determine a first uplink and downlink tunnel created in the first session creation process, and a first bearer identifier; Determine the first uplink and downlink tunnel as a target control tunnel, and determine the first bearer identifier as a default bearer identifier belonging to the target control tunnel; or, Acquire a second session creation process that matches the PDN connection request, and determine a second uplink and downlink tunnel created in the second session creation process, and a second bearer identifier; The second uplink and downlink tunnel is determined as a target control tunnel, and the second bearer identifier is determined as a default bearer identifier belonging to the target control tunnel.
4. The method for screening user traffic according to claim 3, characterized in that: The method further comprises: Acquire a first session deletion process that matches the attach request, or acquire a second session deletion process that matches the PDN connection request; Respectively obtain the attribute information of the first create session process, the first delete session process, the second create session process and the first delete session process; The creation time and deletion time of each target control tunnel are determined according to each attribute information.
5. The method for screening user traffic according to claim 1, characterized in that: The method of responding to the screening instruction of the target signaling traffic request packet and forwarding the target signaling traffic request packet to the target analysis system when it is determined that the target uplink tunnel of the target signaling traffic request packet matches each target control tunnel in the target database includes: Parse the target signaling traffic request packet to obtain the identifier of the target uplink tunnel; Determining whether the identifier of the target uplink tunnel matches the identifiers of each target control tunnel recorded in the target database; When it is determined that the target uplink tunnel identifier is consistent with the target control tunnel identifier, the target signaling traffic request packet is forwarded to a target analysis system.
6. The method for screening user traffic according to claim 5, characterized in that: The method further comprises: In the case where it is determined that the identifier of the target uplink tunnel is consistent with the identifier of the target control tunnel, determining a target signaling flow response packet corresponding to the target signaling flow request packet; The target signaling traffic response packet is forwarded to a target analysis system.
7. A user flow screening device, characterized in that: include: A target user identification acquisition module, used to obtain a target user identification of the target user in response to a screening instruction of the signaling traffic of the target user; A target control tunnel determination module, used to determine a target control tunnel associated with the target user, and at least one default bearer identifier belonging to the target control tunnel; A target database creation module, used to create a target database based on the target control tunnel and a default bearer identifier belonging to the target control tunnel; a signaling traffic forwarding module, configured to respond to a screening instruction of a target signaling traffic request packet, and forward the target signaling traffic request packet to a target analysis system when it is determined that a target uplink tunnel of the target signaling traffic request packet matches each target control tunnel in the target database; The target database creation module is specifically used to determine the creation time and deletion time of each target control tunnel; The target control tunnel, the default bearer identifier belonging to the target control tunnel, the creation time and the deletion time of the target control tunnel are stored in the target area to obtain the target database.
8. An electronic device, characterized in that: The electronic device comprises: at least one processor; and a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can perform the user traffic screening method according to any one of claims 1 to 6.
9. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the user traffic screening method according to any one of claims 1 to 6 when executed.
Citation Information
Patent Citations
Core network data collection system, method and apparatus, and terminal device
CN109688633A