A data security analysis system and method applied to wireless communication equipment

Through the combination of neural network algorithm and ARIMA model, the normal communication behavior pattern of wireless communication devices is established, and the problem of misjudging legal communication as anomalies in the prior art is solved, and more accurate abnormality detection and rapid response are achieved.

CN119583216BActive Publication Date: 2025-05-06SHENZHEN UNICAIR COMM TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510119799.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-25
Publication Date
2025-05-06
Estimated Expiration
2045-01-25

AI Technical Summary

Technical Problem

When analyzing the data security of wireless communication devices, it is difficult to effectively capture the correlation between the context information of communication behavior and the device, resulting in the legal but non-compliant communication traffic being misjudged as abnormal, affecting the normal development of enterprise business.

Method used

A neural network algorithm is used to combine the ARIMA model to perform data preprocessing, mode establishment and abnormal detection on the wireless communication device data set, establish normal communication behavior patterns, and automatically record event information when abnormalities are detected and security measures are taken.

Benefits of technology

It improves the accuracy of abnormal detection, not only pays attention to network traffic data, but also analyzes the relationship between equipment and mobile trajectory and business applications, has a complete security response mechanism, and can quickly locate and troubleshoot problems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119583216B_ABST
    Figure CN119583216B_ABST
Patent Text Reader

Abstract

The present invention discloses a data security analysis system and method applied to wireless communication equipment, belonging to the field of artificial intelligence technology. The present invention records the wireless communication equipment information in the enterprise, obtains the enterprise wireless network architecture, performs data flow monitoring, and sends the wireless communication equipment data set in combination with the wireless communication equipment information and the network topology diagram; establishes a normal communication behavior pattern through the ARIMA model; for mobile devices in the wireless communication equipment, establishes an association with the mobile trajectory in the enterprise park, and for fixed equipment, establishes an association with the business application; adopts a neural network algorithm, trains the neural network model, learns the normal communication behavior pattern, and identifies the abnormal pattern in the wireless communication equipment data set; when an abnormal pattern is detected, automatically records the detailed information of the abnormal event, takes corresponding measures for the abnormal equipment according to the preset security policy, and sends an alarm notification to the enterprise's security management team.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of artificial intelligence technology, and in particular to a data security analysis system and method applied to wireless communication equipment. Background Art

[0002] With the acceleration of digital transformation of enterprises, wireless communication technology is increasingly used in enterprise operations. Enterprises use a large number of wireless communication devices, such as smartphones, tablets, wireless office equipment, etc., to achieve information exchange and data sharing between employees and connection with internal servers and cloud services. This convenient wireless communication method greatly improves the work efficiency and flexibility of enterprises, but it also brings severe data security challenges.

[0003] As enterprises launch new online businesses or introduce new mobile office applications, the original rule set is difficult to cover all possible normal communication behaviors, which can easily lead to false alarms. When some legal communication traffic appears but does not comply with the established rules, such as new cloud service data synchronization operations, it may be misjudged as abnormal, affecting the normal operation of the enterprise business. Some existing technologies only focus on simple statistical analysis of network traffic, such as monitoring traffic size, number of connections and other indicators. This analysis method ignores the contextual information of communication behavior and the correlation between devices. In the enterprise campus, there is a potential correlation between the movement trajectory of mobile devices and communication behavior, but most existing technologies fail to fully explore this relationship. Summary of the invention

[0004] The object of the present invention is to provide a data security analysis system and method applied to wireless communication equipment to solve the problems raised in the prior art.

[0005] To achieve the above object, the present invention provides the following technical solutions:

[0006] A data security analysis method applied to a wireless communication device, the method comprising the following steps:

[0007] S100, record the wireless communication device information within the enterprise, including the device model, MAC address, IP address and device status; obtain the enterprise wireless network architecture, including access point distribution, network frequency band and wireless communication protocol, and draw a network topology map; perform data flow monitoring, and send a wireless communication device data set in combination with the wireless communication device information and the network topology map;

[0008] S200, based on the wireless communication device data set and according to the historical data of the enterprise communication behavior, a normal communication behavior pattern is established through an ARIMA model; for mobile devices in the wireless communication devices, an association is established with the movement trajectory within the enterprise park, and for fixed devices, an association is established with business applications, to form a wireless communication device association data set;

[0009] S300, using a neural network algorithm, dividing the data set into a training set, a validation set, and a test set; the training set is used to train the neural network model to learn normal communication behavior patterns, the validation set is used to adjust the hyperparameters of the model to prevent overfitting, and the test set is used to evaluate the performance of the model, which can identify abnormal patterns in the wireless communication device data set after training;

[0010] S400. When an abnormal pattern is detected, the detailed information of the abnormal event is automatically recorded, including the wireless communication device involved, the specific manifestation of the abnormality and the time of occurrence; according to the preset security policy, corresponding measures are taken against the abnormal device to prevent it from continuing to access the enterprise wireless network, and an alarm notification is sent to the enterprise's security management team.

[0011] According to step S100, the network scanning tool Nmap is used to scan the wireless communication device information being used in the enterprise network, including the model, MAC address, IP address and device status of the device, wherein the device status includes online, offline and busy; a wireless communication device information database is established, and the collected wireless communication device information is classified and stored according to the dimension of the department;

[0012] Use the wireless network survey tool Ekahau Site Survey to check the company's wireless network, draw a distribution map of access points, mark the location, signal coverage and signal strength of each access point, and form the distribution of access points; obtain the network frequency band used by the company's wireless network to determine whether it is 2.4GHz band, 5GHz band or a mixture of 2.4GHz and 5GHz; obtain the wireless communication protocol used by the company, and draw the company's network topology map based on the access point distribution, network frequency band and wireless communication protocol; in the network topology map, show the connection relationship between access points and network devices, as well as the connection path between each wireless communication device and access point.

[0013] According to step S100, in the enterprise wireless network environment, a traffic collection probe is set on the mirror port of the core switch to obtain a copy of all data traffic flowing through the core switch in the wireless network;

[0014] The traffic collection probe captures the packet header information and payload information of the network data packet, wherein the packet header information includes the source IP address, destination IP address, source MAC address, destination MAC address, protocol type and port number; collects traffic data at predetermined time intervals, timestamps each data packet in the order of collection time, and associates and marks traffic data from the same source device.

[0015] According to the MAC address in the flow data, the corresponding wireless communication device information is queried in the wireless communication device information database, and is associated and integrated with the flow data, so that each flow data record is attached with the corresponding device identity and status description;

[0016] Using the information in the network topology diagram, determine the position of each wireless communication device in the network architecture and its connection relationship with other network devices; obtain the transmission path of traffic data in the network, specifically starting from the source device, passing through which intermediate network devices, and finally reaching the destination device; form a wireless communication device data set that includes traffic data, wireless communication device information and transmission path.

[0017] According to step S200, the wireless communication device data set is preprocessed, and the communication traffic time series diagram of different wireless communication devices is drawn to obtain the traffic changes under different time scales; the ADF test is used to test the stability of the time series data. If the data is not stable, the data is differentially processed until the data reaches a stable state;

[0018] Calculate the autocorrelation function and partial autocorrelation function of the stationary time series and determine the order of the ARIMA model; use the AIC and BIC information criteria to evaluate and select ARIMA models with different parameter combinations, and select the model parameter combination that minimizes the AIC or BIC value; use the ARIMA model with determined parameters to train the training data so that the model learns the time series laws of normal communication behavior; use the test data to evaluate the trained ARIMA model and calculate the model's prediction error index; use the laws learned by the ARIMA model that has been trained and evaluated as a normal communication behavior pattern.

[0019] According to step S200, assume that the signal strength received by the i-th base station from the mobile device m at time t is ; Through the preliminary signal strength calibration experiment, the logarithmic distance path loss model is used to establish the relationship model between signal strength and distance:

[0020] ;

[0021] in, is the reference distance The signal strength at , n is the path loss exponent, is the distance from mobile device m to the i-th base station at time t, is a random noise term;

[0022] According to the signal strength information received by several base stations, the coordinates of the mobile device m at time t are calculated using the triangulation positioning algorithm. ; Assume there are N base stations in the park, and the coordinates of base station i are , the mobile device position is determined by solving the following set of equations:

[0023] ;

[0024] in, are the coordinates of base station 1, are the coordinates of base station 2, are the coordinates of base station N, is the distance from mobile device m to the first base station at time t, is the distance from mobile device m to the second base station at time t, is the distance from mobile device m to the Nth base station at time t;

[0025] Record a series of coordinate points of mobile device m in sequence of time t , forming a moving trajectory ; Monitor the communication behavior data of mobile device m on the network side, including the source IP address , Destination IP address , Traffic size and communication protocols ; Associate the mobile trajectory data with the communication behavior data according to the timestamp, and set the associated data set Each record in for .

[0026] According to step S200, a traffic monitoring tool is deployed on the core switch of the enterprise network to identify the network traffic of different fixed devices; for each fixed device f, the traffic generated by the business application used by it is monitored; set the business application The traffic sequence generated on the fixed device f is , where t represents time; computing business applications Flow characteristics at fixed equipment f, including average flow , flow variance , where T is the length of the observation time window;

[0027] Determine business applications The communication port number set on the fixed device f , and the destination IP address set , obtained by analyzing the packet header information in the network traffic;

[0028] Fix the device model of device f 、MAC address and IP address Combine and associate with business applications, set up associated data sets Each record in for .

[0029] According to step S300, the wireless communication device associated data set is divided into a training set, a validation set and a test set according to a specific ratio; for the training set, the neural network model mines the features and rules in the data based on the normal communication behavior data therein; during the model training process, the data of the validation set is continuously input into the model, and the model makes predictions based on the learned parameters; by comparing the prediction results with the real data in the validation set, the evaluation index is calculated; based on the evaluation index, when overfitting occurs, the hyperparameters of the model are adjusted; the hyperparameters include the number of layers of the neural network, the number of neurons in each layer, the learning rate and the regularization coefficient;

[0030] The trained and optimized model uses the test set for performance evaluation. The model predicts the wireless communication device data in the test set and calculates the accuracy, error rate and F1 value by comparing with the real labels of the test set. If the model can identify normal and abnormal communication behavior patterns on the test set, the training is completed and the abnormal patterns in the wireless communication device data set can be identified.

[0031] The model is initialized based on the selected neural network architecture, and the initial hyperparameter settings are determined, including the number of neural network layers, the number of neurons in each layer, the learning rate, and the regularization coefficient. Subsequently, the wireless communication device data in the training set is input into the neural network model batch by batch. When each batch of data is input, the model processes the data according to the current parameter settings, calculates the prediction results through the forward propagation algorithm, and compares them with the true labels in the training data to obtain the loss value. Then, the back-propagation algorithm is used to adjust the model's weights and biases according to the loss value to gradually reduce the value of the loss function.

[0032] During this process, the model continuously mines deep-level features and patterns in the training data, such as identifying the traffic pattern between fixed devices and specific servers when operating specific business applications, and the correlation pattern between the communication behavior characteristics and movement trajectories of mobile devices in specific areas of the campus. As training continues, the model gradually builds a complex and accurate internal representation of normal communication behavior patterns, enabling it to accurately predict and classify normal communication data.

[0033] According to step S400, when the neural network model detects an abnormal pattern when performing real-time monitoring and analysis on the wireless communication device data set, an abnormal event recording mechanism is activated; the wireless communication device involved is determined, and the MAC address of the device is searched and matched in the device information database to obtain the wireless communication device information of the device, the department to which it belongs, and the location of the device in the enterprise network;

[0034] Based on the preset security policies, disposal measures are implemented for abnormal devices to prevent abnormal devices from continuing to access the enterprise wireless network. The network access rights of abnormal devices are revoked by dynamically adjusting the access control policy at the network access layer. Alarm notifications are automatically generated and sent to the enterprise's security management team.

[0035] Enterprises formulate detailed security policies in advance based on their own security needs, network architecture, and business operation characteristics. These policies are stored in a dedicated security policy database in the form of a rule set, and each rule contains trigger conditions and corresponding disposal actions. For example, a rule may stipulate that when the traffic of a wireless communication device exceeds 200% of the normal threshold within a specific time period and establishes connections with multiple unknown external IP addresses, it will be judged as an abnormal device and the disposal measures of blocking access and isolation will be executed.

[0036] After determining the matching security policy rules, the system will automatically interact with the device management system of the enterprise network access layer. In the network access layer, key devices such as wireless access points (APs), network firewalls, and identity authentication servers are mainly involved. For wireless access points, the system will send instructions to require them to dynamically update the access control list (ACL) based on the MAC address of the abnormal device. Add a rule to the ACL to explicitly deny any network connection request from the MAC address of the abnormal device, thereby revoking the wireless access rights of the abnormal device. For example, in the configuration of wireless access points based on the IEEE 802.11 standard, the MAC address of the abnormal device is added to the prohibited access list through a specific management interface command, so that it can no longer establish an association with the wireless access point and obtain network services.

[0037] For network firewalls, if the enterprise network uses a firewall for border protection, the system will also send configuration update instructions to the firewall. In the firewall's access control policy, add a deny rule for the IP address of the abnormal device. This rule can be set in the firewall's inbound or outbound policy, depending on whether the abnormal behavior of the abnormal device involves an attack to the intranet or an attempt to leak data to the extranet. For example, if the abnormal device is suspected of uploading sensitive corporate data to an external malicious server, the firewall will block all external connection attempts of the device in the outbound policy to ensure that the data cannot flow out of the corporate network.

[0038] A data security analysis system applied to a wireless communication device, comprising:

[0039] Equipment and network information collection module: including: equipment information recording unit, network architecture acquisition unit and data flow monitoring and sending unit; the equipment information recording unit records the wireless communication equipment information within the enterprise, including the equipment model, MAC address, IP address and equipment status; the network architecture acquisition unit obtains the enterprise wireless network architecture, including access point distribution, network frequency band and wireless communication protocol, and draws a network topology map; the data flow monitoring and sending unit monitors data flow and sends the wireless communication equipment data set in combination with the wireless communication equipment information and the network topology map;

[0040] Communication behavior pattern establishment module: including: ARIMA model building unit, mobile device association unit, fixed device association unit and association data set generation unit; wherein, the ARIMA model building unit is based on the wireless communication device data set, according to the historical data of the enterprise communication behavior, and establishes a normal communication behavior pattern through the ARIMA model; the mobile device association unit establishes an association between the mobile devices in the wireless communication devices and the movement tracks in the enterprise park, the fixed device association unit establishes an association between the fixed devices and the business applications, and the association data set generation unit forms an association data set for wireless communication devices;

[0041] Anomaly detection module: including: data set division unit, neural network training unit, model verification and optimization unit and anomaly identification unit; wherein, the data set division unit adopts a neural network algorithm to divide the data set into a training set, a verification set and a test set; the neural network training unit uses the training set to train the neural network model to learn the normal communication behavior pattern; the model verification and optimization unit uses the verification set to adjust the hyperparameters of the model to prevent overfitting; the anomaly identification unit uses the test set to evaluate the performance of the model, and after training, it can identify abnormal patterns in the wireless communication device data set;

[0042] Abnormal response module: including: abnormal event recording unit, device isolation unit and alarm notification unit; wherein, when the abnormal event recording unit detects an abnormal pattern, it automatically records the detailed information of the abnormal event, including the wireless communication device involved, the specific manifestation of the abnormality and the time of occurrence; the device isolation unit takes corresponding measures against the abnormal device according to the preset security policy to prevent it from continuing to access the enterprise wireless network, and the alarm notification unit sends an alarm notification to the enterprise's security management team.

[0043] Compared with the prior art, the present invention has the following beneficial effects:

[0044] 1. The present invention adopts a neural network algorithm combined with an ARIMA model for anomaly detection. The neural network algorithm can automatically learn the complex normal communication behavior patterns in the wireless communication device data set, and the ARIMA model focuses on the analysis of the communication behavior time series data, which can effectively capture the rules and trends of traffic data in the time dimension. The combination of the two improves the accuracy of anomaly detection.

[0045] 2. The present invention not only focuses on network traffic data, but also deeply analyzes the association between wireless communication devices and mobile trajectories and business applications in the enterprise park. For mobile devices, by establishing an association with the mobile trajectory, the security monitoring strategy can be dynamically adjusted according to the location changes of the device in the park.

[0046] 3. When an abnormal pattern is detected, the present invention has a complete security response mechanism that can automatically record detailed information about the abnormal event, including comprehensive information about the wireless communication equipment involved, the specific manifestation of the abnormality, and the time of occurrence, providing the security management team with detailed and accurate event clues, facilitating rapid location and troubleshooting of problems. BRIEF DESCRIPTION OF THE DRAWINGS

[0047] Figure 1 It is a schematic diagram of the steps of a data security analysis method applied to a wireless communication device according to the present invention;

[0048] Figure 2 The present invention is a system structure diagram of a data security analysis system applied to wireless communication equipment. DETAILED DESCRIPTION

[0049] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0050] Example: Figure 1-Figure 2As shown, the present invention provides a technical solution.

[0051] According to one embodiment of the present invention, Figure 1 A data security analysis method applied to a wireless communication device is shown in a schematic diagram of steps. A data security analysis method applied to a wireless communication device comprises the following steps:

[0052] S100, record the wireless communication device information within the enterprise, including the device model, MAC address, IP address and device status; obtain the enterprise wireless network architecture, including access point distribution, network frequency band and wireless communication protocol, and draw a network topology map; perform data flow monitoring, and send a wireless communication device data set in combination with the wireless communication device information and the network topology map;

[0053] S200, based on the wireless communication device data set and according to the historical data of the enterprise communication behavior, a normal communication behavior pattern is established through an ARIMA model; for mobile devices in the wireless communication devices, an association is established with the movement trajectory within the enterprise park, and for fixed devices, an association is established with business applications, to form a wireless communication device association data set;

[0054] S300, using a neural network algorithm, dividing the data set into a training set, a validation set, and a test set; the training set is used to train the neural network model to learn normal communication behavior patterns, the validation set is used to adjust the hyperparameters of the model to prevent overfitting, and the test set is used to evaluate the performance of the model, which can identify abnormal patterns in the wireless communication device data set after training;

[0055] S400. When an abnormal pattern is detected, the detailed information of the abnormal event is automatically recorded, including the wireless communication device involved, the specific manifestation of the abnormality and the time of occurrence; according to the preset security policy, corresponding measures are taken against the abnormal device to prevent it from continuing to access the enterprise wireless network, and an alarm notification is sent to the enterprise's security management team.

[0056] According to step S100, the network scanning tool Nmap is used to scan the wireless communication device information being used in the enterprise network, including the model, MAC address, IP address and device status of the device, wherein the device status includes online, offline and busy; a wireless communication device information database is established, and the collected wireless communication device information is classified and stored according to the dimension of the department;

[0057] Use the wireless network survey tool Ekahau Site Survey to check the company's wireless network, draw a distribution map of access points, mark the location, signal coverage and signal strength of each access point, and form the distribution of access points; obtain the network frequency band used by the company's wireless network to determine whether it is 2.4GHz band, 5GHz band or a mixture of 2.4GHz and 5GHz; obtain the wireless communication protocol used by the company, and draw the company's network topology map based on the access point distribution, network frequency band and wireless communication protocol; in the network topology map, show the connection relationship between access points and network devices, as well as the connection path between each wireless communication device and access point.

[0058] According to step S100, in the enterprise wireless network environment, a traffic collection probe is set on the mirror port of the core switch to obtain a copy of all data traffic flowing through the core switch in the wireless network;

[0059] The traffic collection probe captures the packet header information and payload information of the network data packet, wherein the packet header information includes the source IP address, destination IP address, source MAC address, destination MAC address, protocol type and port number; collects traffic data at predetermined time intervals, timestamps each data packet in the order of collection time, and associates and marks traffic data from the same source device.

[0060] According to the MAC address in the flow data, the corresponding wireless communication device information is queried in the wireless communication device information database, and is associated and integrated with the flow data, so that each flow data record is attached with the corresponding device identity and status description;

[0061] Using the information in the network topology diagram, determine the position of each wireless communication device in the network architecture and its connection relationship with other network devices; obtain the transmission path of traffic data in the network, specifically starting from the source device, passing through which intermediate network devices, and finally reaching the destination device; form a wireless communication device data set that includes traffic data, wireless communication device information and transmission path.

[0062] According to step S200, the wireless communication device data set is preprocessed, and the communication traffic time series diagram of different wireless communication devices is drawn to obtain the traffic changes under different time scales; the ADF test is used to test the stability of the time series data. If the data is not stable, the data is differentially processed until the data reaches a stable state;

[0063] Calculate the autocorrelation function and partial autocorrelation function of the stationary time series and determine the order of the ARIMA model; use the AIC and BIC information criteria to evaluate and select ARIMA models with different parameter combinations, and select the model parameter combination that minimizes the AIC or BIC value; use the ARIMA model with determined parameters to train the training data so that the model learns the time series laws of normal communication behavior; use the test data to evaluate the trained ARIMA model and calculate the model's prediction error index; use the laws learned by the ARIMA model that has been trained and evaluated as a normal communication behavior pattern.

[0064] We selected 5 representative wireless communication devices in the enterprise, marked as device A, device B, device C, device D and device E, and collected the communication traffic data within one month as the experimental data set. The data collection time interval is to record the traffic value (in bytes) once every hour. The data visualization tool Python's matplotlib library is used to draw a time series graph of the communication traffic of the 5 devices. From the figure, we can intuitively see that the traffic of device A has certain fluctuations during the daily working hours (9:00-18:00), and the traffic is higher on certain specific dates (busy business days); the traffic of device B is relatively stable, but there is a clear downward trend on weekends; the traffic of device C shows periodic peaks, which may be related to the regular data synchronization of specific business applications.

[0065] At the same time, we analyze the traffic changes at different time scales. For example, by summarizing the traffic data by day, we can see that the total daily traffic of device A is higher on the 10th and 20th days; by summarizing the traffic data by week, we find that the traffic of device B is relatively large from Monday to Wednesday every week.

[0066] ADF test was performed on the traffic time series data of each device. Taking device A as an example, the ADF test was performed using Python's statsmodels library. The results showed that the ADF statistic of its original data was greater than the critical value, indicating that the data was not stable. Then the data of device A was processed by first-order difference and the ADF test was performed again. At this time, the ADF statistic was less than the critical value and the data reached a stable state. The same method was used to process other devices. Device B needed to be processed by second-order difference to achieve stability, device C was stable after first-order difference, device D was stable after second-order difference, and device E was stable after first-order difference.

[0067] Calculate the autocorrelation function (ACF) and partial autocorrelation function (PACF): Take device A as an example, calculate the ACF and PACF of its first-order difference data after stabilization. From the ACF graph, we can see that the autocorrelation coefficient gradually decays after lag 1, and the PACF graph is truncated after lag 2. The possible ARIMA model order is preliminarily determined to be ARIMA(p,1,q), where p may be 2 and q may be 1.

[0068] Use AIC and BIC information criteria to evaluate and select model parameter combinations: Try different parameter combinations of ARIMA(1,1,1), ARIMA(2,1,1), ARIMA(1,1,2), ARIMA(2,1,2) to fit the data of device A. The results show that the AIC and BIC values ​​of the ARIMA(2,1,1) model are the smallest, so this model is selected as the best ARIMA model parameter combination for device A. The same method is used to select model parameters for other devices: ARIMA(1,2,1) is selected for device B, ARIMA(2,1,2) is selected for device C, ARIMA(1,2,2) is selected for device D, and ARIMA(2,1,1) is selected for device E.

[0069] Use the ARIMA model with determined parameters to train the training data of each device. Take device A as an example and use the ARIMA model class in Python's statsmodels library for training. During the training process, the model continuously adjusts internal parameters to learn the time series laws of device A's normal communication behavior, such as periodic changes in traffic, trend changes, and associations with working days and business applications.

[0070] The model was evaluated. From the evaluation results, it can be seen that the ARIMA model of each device has a certain prediction error on the test data, but it is generally within an acceptable range, indicating that the model can learn the normal communication behavior pattern of the device well. The rules learned by these models can be used as normal communication behavior patterns for subsequent anomaly detection tasks. For example, if the actual traffic of device A at a certain moment deviates from the normal traffic value predicted by the ARIMA (2,1,1) model by more than a certain threshold (such as 3 times MAE), it can be determined as abnormal communication behavior and trigger the corresponding safety mechanism.

[0071] Three base stations are deployed in an enterprise park, marked as base station A, base station B and base station C, with coordinates of A (0, 0), B (100, 0), and C (50, 86.6) (unit: meters). = Signal strength at 1 meter =-30dBm, path loss index n = 2.5. There is a mobile device M moving in the park, and we monitor its positioning and communication behavior.

[0072] According to the logarithmic distance path loss model, the distance from the mobile device to each base station is calculated. Taking the time as 1 minute as an example, , for base station A:

[0073] ;

[0074] ;

[0075] ;

[0076] Similarly, , ;

[0077] Use the triangulation positioning algorithm to solve the coordinates of the mobile device M at the time 1 minute. Assume the coordinates of the mobile device M are (x, y), then there is the equation group:

[0078] ;

[0079] By solving rice, rice;

[0080] The coordinates of other time points are calculated in the same way to obtain the moving trajectory of the mobile device M.

[0081] Monitor the communication behavior data of mobile device m on the network side, including the source IP address , Destination IP address , Traffic size and communication protocols ; Associate the mobile trajectory data with the communication behavior data according to the timestamp, and set the associated data set Each record in for .

[0082] According to step S200, a traffic monitoring tool is deployed on the core switch of the enterprise network to identify the network traffic of different fixed devices. There is a fixed device F in the enterprise network, whose device model is "HP ProDesk 600 G6", MAC address is "00:11:22:33:44:55", and IP address is "192.168.1.200". The device runs two business applications, namely, the file sharing application (marked as App1) and the email client application (marked as App2) within the enterprise. The network traffic data of the fixed device F is monitored within one hour.

[0083] Calculate the traffic characteristics of App1: the observation time window T = 60 minutes, the average traffic is calculated to be 105 bytes, and the traffic variance is approximately equal to 25. Similarly, the average traffic of App2 is approximately 55 bytes, and the traffic variance is approximately 16.

[0084] Determine business applications The communication port number set on the fixed device f , and the destination IP address set , obtained by analyzing the packet header information in the network traffic;

[0085] Fix the device model of device f 、MAC address and IP address Combine and associate with business applications, set up associated data sets Each record in for .

[0086] According to step S300, the wireless communication device associated data set is divided into a training set, a validation set and a test set according to a specific ratio; for the training set, the neural network model mines the features and rules in the data based on the normal communication behavior data therein; during the model training process, the data of the validation set is continuously input into the model, and the model makes predictions based on the learned parameters; by comparing the prediction results with the real data in the validation set, the evaluation index is calculated; based on the evaluation index, when overfitting occurs, the hyperparameters of the model are adjusted; the hyperparameters include the number of layers of the neural network, the number of neurons in each layer, the learning rate and the regularization coefficient;

[0087] The trained and optimized model uses the test set for performance evaluation. The model predicts the wireless communication device data in the test set and calculates the accuracy, error rate and F1 value by comparing with the real labels of the test set. If the model can identify normal and abnormal communication behavior patterns on the test set, the training is completed and the abnormal patterns in the wireless communication device data set can be identified.

[0088] According to step S400, when the neural network model detects an abnormal pattern when performing real-time monitoring and analysis on the wireless communication device data set, an abnormal event recording mechanism is activated; the wireless communication device involved is determined, and the MAC address of the device is searched and matched in the device information database to obtain the wireless communication device information of the device, the department to which it belongs, and the location of the device in the enterprise network;

[0089] Based on the preset security policies, disposal measures are implemented for abnormal devices to prevent abnormal devices from continuing to access the enterprise wireless network. The network access rights of abnormal devices are revoked by dynamically adjusting the access control policy at the network access layer. Alarm notifications are automatically generated and sent to the enterprise's security management team.

[0090] A data security analysis system applied to a wireless communication device, comprising:

[0091] Equipment and network information collection module: including: equipment information recording unit, network architecture acquisition unit and data flow monitoring and sending unit; the equipment information recording unit records the wireless communication equipment information within the enterprise, including the equipment model, MAC address, IP address and equipment status; the network architecture acquisition unit obtains the enterprise wireless network architecture, including access point distribution, network frequency band and wireless communication protocol, and draws a network topology map; the data flow monitoring and sending unit monitors data flow and sends the wireless communication equipment data set in combination with the wireless communication equipment information and the network topology map;

[0092] Communication behavior pattern establishment module: including: ARIMA model building unit, mobile device association unit, fixed device association unit and association data set generation unit; wherein, the ARIMA model building unit is based on the wireless communication device data set, according to the historical data of the enterprise communication behavior, and establishes a normal communication behavior pattern through the ARIMA model; the mobile device association unit establishes an association between the mobile devices in the wireless communication devices and the movement tracks in the enterprise park, the fixed device association unit establishes an association between the fixed devices and the business applications, and the association data set generation unit forms an association data set for wireless communication devices;

[0093] Anomaly detection module: including: data set division unit, neural network training unit, model verification and optimization unit and anomaly identification unit; wherein, the data set division unit adopts a neural network algorithm to divide the data set into a training set, a verification set and a test set; the neural network training unit uses the training set to train the neural network model to learn the normal communication behavior pattern; the model verification and optimization unit uses the verification set to adjust the hyperparameters of the model to prevent overfitting; the anomaly identification unit uses the test set to evaluate the performance of the model, and after training, it can identify abnormal patterns in the wireless communication device data set;

[0094] Abnormal response module: including: abnormal event recording unit, device isolation unit and alarm notification unit; wherein, when the abnormal event recording unit detects an abnormal pattern, it automatically records the detailed information of the abnormal event, including the wireless communication device involved, the specific manifestation of the abnormality and the time of occurrence; the device isolation unit takes corresponding measures against the abnormal device according to the preset security policy to prevent it from continuing to access the enterprise wireless network, and the alarm notification unit sends an alarm notification to the enterprise's security management team.

[0095] The enterprise has a wireless network environment with 50 wireless communication devices (including smartphones, tablets and wireless office equipment). The network is covered by wireless access points based on the 802.11ac standard and connected to the external network through a firewall. The preset security policy stipulates that when a wireless communication device continuously sends more than 100MB of data to the external network within 5 minutes or establishes connections with more than 10 unknown IP addresses, it is judged as an abnormal device and needs to be isolated and the security management team is notified.

[0096] In one test, it was found that the tablet computer with device number 25 (device model: iPad Pro, MAC address: 00:12:34:56:78:9A, IP address: 192.168.1.25) had abnormal behavior. Within 3 minutes, the device continued to send data to multiple external IP addresses, with a total sending volume of 150MB, and 15 of the IP addresses were not in the enterprise's trusted list.

[0097] The abnormal event recording unit immediately records the details of the abnormal event:

[0098] Wireless communication device involved: iPad Pro (MAC: 00:12:34:56:78:9A, IP: 192.168.1.25); Specific manifestations of the anomaly: within 3 minutes, the amount of data sent to the external network reached 150MB, and connections were established with 15 unknown IP addresses; Time of occurrence: 2024 - 11 - 22 10:30:00 (accurate to seconds).

[0099] After the device isolation unit detects an abnormal event, it quickly interacts with the wireless access point and firewall according to the preset security policy. In the configuration of the wireless access point, the MAC address of device 25 is added to the deny list of the access control list (ACL) to prevent it from continuing to connect to the wireless access point. At the same time, in the outbound rules of the firewall, a blocking rule for the IP address of device 25 (192.168.1.25) is added to prohibit all external network connections. After the isolation operation, the network connection status was checked and it was found that device 25 could no longer access the enterprise wireless network and could not interact with any data with the external network, successfully achieving the isolation of the abnormal device.

[0100] The alarm notification unit generates detailed alarm information including:

[0101] Overview of abnormal events: Device 25 (iPad Pro) abnormally sent a large amount of data to the external network and connected to multiple unknown IP addresses;

[0102] Device information involved: iPad Pro (MAC: 00:12:34:56:78:9A, IP: 192.168.1.25);

[0103] Abnormal performance: 150MB outbound traffic in 3 minutes, 15 unknown IP connections;

[0104] Time of occurrence: 2024 - 11 - 22 10:30:00.

[0105] A preliminary risk assessment is conducted on the abnormal event. Since a large amount of data is transmitted outward, there may be a risk of data leakage, and the risk level is assessed as high. Then an alarm notification is sent to the enterprise's security management team in various ways, such as sending an email to the security management team's dedicated mailbox with the subject "Enterprise Wireless Network Abnormal Event Alarm - Device 25" and the content of the email containing the above alarm information; at the same time, a text message notification is sent to the mobile phones of the security management team members, prompting them to check the email and handle the abnormal event.

[0106] After receiving the notification, the security management team can quickly locate the abnormal device based on the alarm information and initiate the corresponding emergency response process based on the risk assessment results, such as further investigating whether the device is infected with malware, checking whether the data has been leaked, and other follow-up operations.

[0107] It will be apparent to those skilled in the art that the invention is not limited to the details of the exemplary embodiments described above and that the invention can be implemented in other specific forms without departing from the spirit or essential features of the invention. Therefore, the embodiments should be considered exemplary and non-limiting in all respects, and the scope of the invention is defined by the appended claims rather than the foregoing description, and it is intended that all variations falling within the meaning and scope of the equivalent elements of the claims be included in the invention. Any reference numeral in a claim should not be considered as limiting the claim to which it relates.

Claims

1. A data security analysis method applied to a wireless communication device, characterized in that: The method comprises the following steps: S100, record the wireless communication device information within the enterprise, including the device model, MAC address, IP address and device status; obtain the enterprise wireless network architecture, including access point distribution, network frequency band and wireless communication protocol, and draw a network topology map; perform data flow monitoring, and send a wireless communication device data set in combination with the wireless communication device information and the network topology map; S200, based on the wireless communication device data set and according to the historical data of the enterprise communication behavior, a normal communication behavior pattern is established through an ARIMA model; for mobile devices in the wireless communication devices, an association is established with the movement trajectory within the enterprise park, and for fixed devices, an association is established with business applications, to form a wireless communication device association data set; According to step S200, the wireless communication device data set is preprocessed, and the communication traffic time series diagram of different wireless communication devices is drawn to obtain the traffic changes under different time scales; the ADF test is used to test the stability of the time series data. If the data is not stable, the data is differentially processed until the data reaches a stable state; Calculate the autocorrelation function and partial autocorrelation function of the stationary time series and determine the order of the ARIMA model; use the AIC and BIC information criteria to evaluate and select ARIMA models with different parameter combinations, and select the model parameter combination that minimizes the AIC or BIC value; use the ARIMA model with determined parameters to train the training data so that the model learns the time series laws of normal communication behavior; use the test data to evaluate the trained ARIMA model and calculate the prediction error index of the model; use the laws learned by the ARIMA model that has been trained and evaluated as the normal communication behavior pattern; S300, using a neural network algorithm, dividing the data set into a training set, a validation set, and a test set; the training set is used to train the neural network model to learn normal communication behavior patterns, the validation set is used to adjust the hyperparameters of the model to prevent overfitting, and the test set is used to evaluate the performance of the model, which can identify abnormal patterns in the wireless communication device data set after training; S400. When an abnormal pattern is detected, the detailed information of the abnormal event is automatically recorded, including the wireless communication device involved, the specific manifestation of the abnormality and the time of occurrence; according to the preset security policy, corresponding measures are taken against the abnormal device to prevent it from continuing to access the enterprise wireless network, and an alarm notification is sent to the enterprise's security management team.

2. A data security analysis method applied to wireless communication equipment according to claim 1, characterized in that: According to step S100, the network scanning tool Nmap is used to scan the wireless communication device information being used in the enterprise network, including the model, MAC address, IP address and device status of the device, wherein the device status includes online, offline and busy; a wireless communication device information database is established, and the collected wireless communication device information is classified and stored according to the dimension of the department; Use the wireless network survey tool Ekahau Site Survey to check the company's wireless network, draw a distribution map of access points, mark the location, signal coverage and signal strength of each access point, and form the distribution of access points; obtain the network frequency band used by the company's wireless network, and determine whether it is 2.4GHz band, 5GHz band or a mixture of 2.4GHz and 5GHz; obtain the wireless communication protocol used by the company, and draw the company's network topology map based on the access point distribution, network frequency band and wireless communication protocol; The network topology diagram shows the connection relationship between the access point and the network devices, as well as the connection path between each wireless communication device and the access point.

3. A data security analysis method applied to wireless communication equipment according to claim 2, characterized in that: According to step S100, in the enterprise wireless network environment, a traffic collection probe is set on the mirror port of the core switch to obtain a copy of all data traffic flowing through the core switch in the wireless network; The traffic collection probe captures the packet header information and payload information of the network data packet, wherein the packet header information includes the source IP address, destination IP address, source MAC address, destination MAC address, protocol type and port number; collects traffic data at predetermined time intervals, timestamps each data packet in the order of collection time, and associates and marks traffic data from the same source device.

4. A data security analysis method applied to wireless communication equipment according to claim 3, characterized in that: According to the MAC address in the flow data, the corresponding wireless communication device information is queried in the wireless communication device information database, and is associated and integrated with the flow data, so that each flow data record is attached with the corresponding device identity and status description; Using the information in the network topology diagram, determine the location of each wireless communication device in the network architecture and its connection relationship with other network devices; obtain the transmission path of traffic data in the network, specifically starting from the source device, passing through which intermediate network devices, and finally reaching the destination device; A wireless communication device data set is formed including traffic data, wireless communication device information and transmission paths.

5. The data security analysis method applied to wireless communication equipment according to claim 1, characterized in that: According to step S200, assume that the signal strength received by the i-th base station from the mobile device m at time t is ; Through the preliminary signal strength calibration experiment, the logarithmic distance path loss model is used to establish the relationship model between signal strength and distance: ; in, is the reference distance The signal strength at , n is the path loss exponent, is the distance from mobile device m to the i-th base station at time t, is a random noise term; According to the signal strength information received by several base stations, the coordinates of the mobile device m at time t are calculated using the triangulation positioning algorithm. ; Assume there are N base stations in the park, and the coordinates of base station i are , the mobile device position is determined by solving the following set of equations: ; in, are the coordinates of base station 1, are the coordinates of base station 2, are the coordinates of base station N, is the distance from mobile device m to the first base station at time t, is the distance from mobile device m to the second base station at time t, is the distance from mobile device m to the Nth base station at time t; Record a series of coordinate points of mobile device m in sequence of time t , forming a moving trajectory ; Monitor the communication behavior data of mobile device m on the network side, including the source IP address , Destination IP address , Traffic size and communication protocols ; Associate the mobile trajectory data with the communication behavior data according to the timestamp, and set the associated data set Each record in for .

6. A data security analysis method applied to wireless communication equipment according to claim 5, characterized in that: According to step S200, a traffic monitoring tool is deployed on the core switch of the enterprise network to identify the network traffic of different fixed devices; for each fixed device f, the traffic generated by the business application used by it is monitored; set the business application The traffic sequence generated on the fixed device f is , where t represents time; computing business applications Flow characteristics at fixed equipment f, including average flow , flow variance , where T is the length of the observation time window; Determine business applications The communication port number set on the fixed device f , and the destination IP address set , obtained by analyzing the packet header information in the network traffic; Fix the device model of device f 、MAC address and IP address Combine and associate with business applications, set up associated data sets Each record in for .

7. The data security analysis method applied to wireless communication equipment according to claim 1, characterized in that: According to step S300, the wireless communication device associated data set is divided into a training set, a validation set and a test set according to a specific ratio; for the training set, the neural network model mines the features and rules in the data based on the normal communication behavior data therein; During the model training process, the data of the validation set is continuously input into the model, and the model makes predictions based on the learned parameters; the evaluation index is calculated by comparing the prediction results with the real data in the validation set; based on the evaluation index, when overfitting occurs, the hyperparameters of the model are adjusted; the hyperparameters include the number of layers of the neural network, the number of neurons in each layer, the learning rate and the regularization coefficient; The trained and optimized model uses the test set for performance evaluation. The model predicts the wireless communication device data in the test set and calculates the accuracy, error rate and F1 value by comparing with the real labels of the test set. If the model can identify normal and abnormal communication behavior patterns on the test set, the training is completed and the abnormal patterns in the wireless communication device data set can be identified.

8. The data security analysis method applied to wireless communication equipment according to claim 1, characterized in that: According to step S400, when the neural network model detects an abnormal pattern when performing real-time monitoring and analysis on the wireless communication device data set, an abnormal event recording mechanism is activated; the wireless communication device involved is determined, and the MAC address of the device is searched and matched in the device information database to obtain the wireless communication device information of the device, the department to which it belongs, and the location of the device in the enterprise network; Based on the preset security policies, disposal measures are implemented for abnormal devices to prevent abnormal devices from continuing to access the enterprise wireless network. The network access rights of abnormal devices are revoked by dynamically adjusting the access control policy at the network access layer. Alarm notifications are automatically generated and sent to the enterprise's security management team.

9. A data security analysis system applied to a wireless communication device, using a data security analysis method applied to a wireless communication device according to any one of claims 1 to 8, characterized in that: include: Equipment and network information collection module: including: equipment information recording unit, network architecture acquisition unit and data flow monitoring and sending unit; the equipment information recording unit records the wireless communication equipment information within the enterprise, including the equipment model, MAC address, IP address and equipment status; the network architecture acquisition unit obtains the enterprise wireless network architecture, including access point distribution, network frequency band and wireless communication protocol, and draws a network topology map; the data flow monitoring and sending unit monitors data flow and sends the wireless communication equipment data set in combination with the wireless communication equipment information and the network topology map; Communication behavior pattern establishment module: including: ARIMA model building unit, mobile device association unit, fixed device association unit and association data set generation unit; wherein, the ARIMA model building unit is based on the wireless communication device data set, according to the historical data of the enterprise communication behavior, and establishes a normal communication behavior pattern through the ARIMA model; the mobile device association unit establishes an association between the mobile devices in the wireless communication devices and the movement tracks in the enterprise park, the fixed device association unit establishes an association between the fixed devices and the business applications, and the association data set generation unit forms an association data set for wireless communication devices; Anomaly detection module: including: data set division unit, neural network training unit, model verification and optimization unit and anomaly identification unit; wherein, the data set division unit adopts a neural network algorithm to divide the data set into a training set, a verification set and a test set; the neural network training unit uses the training set to train the neural network model to learn the normal communication behavior pattern; the model verification and optimization unit uses the verification set to adjust the hyperparameters of the model to prevent overfitting; the anomaly identification unit uses the test set to evaluate the performance of the model, and after training, it can identify abnormal patterns in the wireless communication device data set; Abnormal response module: including: abnormal event recording unit, device isolation unit and alarm notification unit; wherein, when the abnormal event recording unit detects an abnormal pattern, it automatically records the detailed information of the abnormal event, including the wireless communication device involved, the specific manifestation of the abnormality and the time of occurrence; the device isolation unit takes corresponding measures against the abnormal device according to the preset security policy to prevent it from continuing to access the enterprise wireless network, and the alarm notification unit sends an alarm notification to the enterprise's security management team.

Citation Information

Patent Citations

  • Transmission anti-leakage method and system based on enterprise research and development core data

    CN117478364A

  • Intelligent data management system and method based on 5G communication

    CN118760845A