Method and device for detecting illegal access network element of DRA equipment based on signaling fusion analysis technology

Through a method based on signaling fusion analysis technology, combined with the DRA device link configuration table and network element access frequency detection method, the gap in DRA device illegal access detection is solved, efficient and accurate illegal access identification is achieved, and the security of the telecommunications network is improved.

CN119967416AActive Publication Date: 2025-05-09Chinese People's Liberation Army Cyberspace Force Information Engineering University
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510124136.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-26
Publication Date
2025-05-09
Estimated Expiration
2045-01-26

AI Technical Summary

Technical Problem

The prior art lacks effective detection methods for illegal access of DRA equipment, which has led to the threat of the security and reliability of the telecommunications network.

Method used

Using a method based on signaling fusion analysis technology, the new link is identified through the link configuration table of the DRA device, the signaling data of the new link is detected by threat behavior, and the access frequency of the network element is calculated. According to the indirect access characteristics, whether it is illegal access is finally made, and the two detection methods are fusion.

Benefits of technology

It realizes timely discovery and accurate identification of illegal access to DRA equipment, improves detection efficiency and accuracy, and enhances the security and reliability of the telecommunications network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119967416A_ABST
    Figure CN119967416A_ABST
Patent Text Reader

Abstract

The invention belongs to the field of mobile communication networks, and provides a method and device for detecting illegal access network elements of DRA equipment based on a signaling fusion analysis technology. According to the method, a newly-added link is identified according to a DRA link configuration table, threat behavior detection is carried out on signaling data on the link to judge whether the access is illegal or not, meanwhile, the access frequency of a network element is calculated, whether the access is illegal or not is judged according to indirect access characteristics, and finally comprehensive judgment is carried out by fusing the two detection means. According to the DRA illegal access detection method and device, the illegal access behavior can be found in time by detecting the newly added link through the DRA link configuration table, detection is carried out according to the indirect access characteristic of the illegal access network element, and the reliability and accuracy of DRA illegal access detection can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of mobile communication networks, and in particular relates to a method and device for detecting illegal access of DRA equipment to network elements based on signaling fusion analysis technology. Background Art

[0002] DRA equipment is a device or functional entity used to route and forward Diameter signaling messages in mobile communication networks. It can efficiently process Diameter signaling interactions between different network elements to ensure that the signaling can reach the target node accurately. Illegal personnel infiltrate the management equipment of the telecommunications network through the Internet, add a virtual network element identity on the DRA equipment, use the disguised identity information to establish a signaling link with the DRA equipment, and then use the loopholes in the Diameter protocol itself to send carefully constructed signaling messages to the target network element, so as to threaten and detect the target network element with a legitimate identity. When the task is completed, all operation records are generally deleted, including configuration records, fixed-line records, data change reminder records, etc., so that the administrator cannot find that the configuration data has been tampered with, and thus cannot determine whether the DRA device has been illegally accessed. Illegal access to DRA equipment may lead to multiple serious consequences such as information leakage, service interruption, and tariff fraud.

[0003] At present, there is a lack of research on DRA device illegal access detection technology in this field. There is an urgent need for an efficient and accurate DRA device illegal access detection method to fill the gap in this research direction and improve the security and reliability of telecommunication networks. Summary of the invention

[0004] In view of the lack of research on DRA device illegal access detection technology in the existing field, the present invention provides a DRA device illegal access network element detection method and device based on signaling fusion analysis technology, which identifies new links based on the DRA link configuration table, performs threat behavior detection on the signaling data of the new links, and determines whether it is illegal access; at the same time, calculates the access frequency of the network element, determines whether it is illegal access according to the indirect access characteristics, and finally integrates the two detection methods to comprehensively determine whether it is illegal access behavior.

[0005] In a first aspect, the present invention provides a method for detecting illegal access of a DRA device to a network element based on signaling fusion analysis technology, comprising:

[0006] Step 1: Collect and store Diameter signaling data flowing through the DRA device, and obtain a link configuration table of the DRA device;

[0007] Step 2: extracting link information from the Diameter signaling data collected and flowing into the DRA device, and comparing it with the link configuration table; if the link information is not in the link configuration table, it is determined to be a newly added link, and the Diameter signaling data on the newly added link is output; if the link information already exists in the link configuration table, it is determined to be a normal link;

[0008] Step 3: Perform threat behavior detection on the Diameter signaling data on the newly added link. If the Diameter signaling data is threat behavior signaling, determine that the newly added link is an illegal access link of the DRA device, and extract network element information according to the illegal access link of the DRA device and input it into the first illegal access network element set set1;

[0009] Step 4: By analyzing the Diameter signaling data flowing through the DRA device, extracting the network element access time information and performing statistical analysis, the network element access frequency within the specified time is calculated; and the access frequency of each network element is judged. If there is a network element access frequency lower than the set threshold, it is marked as an indirect access network element, and the network element information is extracted to obtain the second illegal access network element set set2;

[0010] Step 5: performing an intersection operation on the first illegally accessed network element set and the second illegally accessed network element set to obtain a final illegally accessed network element set.

[0011] Furthermore, the step 1 adopts a full collection method to collect the Diameter signaling data flowing into and out of the DRA device in real time, parses the Diameter signaling data through a signaling parsing device, and stores the parsed data in a HIVE data warehouse according to data field specifications, and stores them in partitions by day.

[0012] Further, obtaining the link configuration table of the DRA device in step 1 includes: logging into the DRA device management platform through an administrator account to directly obtain the link configuration table of the DRA device;

[0013] The method also includes: restoring the link configuration table of the DRA device by analyzing the Diameter signaling data and adopting a DRA device link information extraction algorithm.

[0014] Furthermore, the link configuration data in the link configuration table includes link type, source IP address, destination IP address, source port, destination port, source host name, destination host name, and link establishment time and shutdown time.

[0015] Further, threat behavior detection is performed on the Diameter signaling data on the newly added link, specifically including: constructing a threat behavior detection rule table, and detecting the Diameter signaling data on the newly added link according to the threat behavior detection rule table.

[0016] Further, the extracting of network element access time information and performing statistical analysis to calculate the network element access frequency within a specified time period includes: calculating the number of times N the ith network element accesses within the specified time period. i With the total number of access times N and access time T i The ratio of the total access time T to obtain the access frequency f of the i-th network element i :

[0017] f i =(N i / N)*(T i / T).

[0018] In a second aspect, the present invention provides a DRA device illegal access to a network element detection device based on signaling fusion analysis technology, comprising:

[0019] A Diameter signaling data collection unit, used to collect and store Diameter signaling data flowing through the DRA device, and obtain a link configuration table of the DRA device;

[0020] A newly added link detection unit of the DRA device is used to extract link information from the Diameter signaling data collected and flowing into the DRA device, and compare it with the link configuration table. If the link information is not in the link configuration table, it is determined to be a newly added link, and the Diameter signaling data on the newly added link is output; if the link information already exists in the link configuration table, it is determined to be a normal link;

[0021] a signaling data threat behavior detection unit, configured to perform threat behavior detection on the Diameter signaling data on the newly added link, and if the Diameter signaling data is threat behavior signaling, determine that the newly added link is a DRA device illegal access link, and extract network element information according to the DRA device illegal access link and input it into a first illegal access network element set set1;

[0022] an indirect access feature calculation unit, configured to extract network element access time information and perform statistical analysis by analyzing the Diameter signaling data flowing through the DRA device, and calculate the network element access frequency within a specified time; and to judge the access frequency of each network element, and if there is a network element access frequency lower than a set threshold, mark it as an indirect access network element, and extract network element information to obtain a second illegal access network element set set2;

[0023] The DRA device illegal access comprehensive judgment unit is used to perform an intersection operation on the first illegal access network element set and the second illegal access network element set to obtain a final illegal access network element set set.

[0024] The beneficial effects of the present invention are:

[0025] (1) The present invention detects newly added links of the DRA device based on the link configuration table of the DRA device, and performs threat behavior detection on the signaling data on the newly added links, identifies the illegally accessed network elements on the DRA device, and promptly discovers the threat behavior of the illegally accessed network elements, thereby improving the detection efficiency of the DRA illegal access.

[0026] (2) The present invention is based on the characteristics of illegally accessed network elements. Illegal access to network elements usually occurs indirectly and is non-periodic. By analyzing the access frequency of network elements and setting thresholds, the indirect access characteristics are identified, thereby improving the detection accuracy.

[0027] (3) The present invention avoids the limitations of a single detection method by integrating illegal access detection based on the DRA link configuration table and illegal access detection based on indirect access characteristics, effectively reduces the probability of missed judgment, false judgment, etc., and improves the reliability and accuracy of illegal access detection of DRA equipment. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] Figure 1 A flow chart of a method for detecting illegal access of a DRA device to a network element based on signaling fusion analysis technology provided by an embodiment of the present invention;

[0029] Figure 2 A schematic diagram of collecting Diameter signaling data flowing through a DRA device provided by an embodiment of the present invention;

[0030] Figure 3 A structural schematic diagram of a DRA device illegal access detection device based on signaling fusion analysis technology provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0031] In order to make the purpose, technical solution and advantages of the present invention clearer, the technical solution in the embodiment of the present invention will be clearly described below in conjunction with the drawings in the embodiment of the present invention. Obviously, the described embodiment is a part of the embodiment of the present invention, not all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0032] As a routing forwarding point in the mobile communication network, the DRA device plays an important role in routing and forwarding Diameter signaling data. By illegally accessing the DRA device, criminals can detect and threaten the target network element, which seriously affects the security of the communication network. In view of the lack of methods for detecting illegal access to DRA devices in the current field, the present invention proposes a DRA illegal access detection method based on signaling fusion analysis. The method identifies the newly added link according to the DRA link configuration table, and performs threat behavior detection on the signaling data on the link to determine whether it is an illegal access. At the same time, it calculates the access frequency of the network element, and determines whether it is an illegal access based on the indirect access characteristics. Finally, a comprehensive judgment is made by integrating the two detection methods. The method can detect new links through the DRA link configuration table to detect illegal access behaviors in a timely manner, and detects according to the indirect access characteristics of the illegally accessed network element to improve the accuracy of DRA illegal access detection.

[0033] like Figure 1 As shown, an embodiment of the present invention provides a method for detecting illegal access of a DRA device to a network element based on signaling fusion analysis technology, including:

[0034] Step 1: Collect Diameter signaling data and obtain the link configuration table of the DRA device. Collect and store the Diameter signaling data flowing through the DRA device, and obtain the link configuration table of the DRA device.

[0035] Specifically, Figure 2 As shown in the figure, the full collection method is adopted to collect the Diameter signaling data flowing into and out of the DRA device in real time, and the Diameter signaling data is parsed by the signaling parsing device, and the parsed data is stored in the HIVE data warehouse according to the data field specification, and is partitioned and stored by day. There are two ways to obtain the link configuration table of the DRA device. Method 1: Log in to the DRA device management platform through the administrator account and directly obtain the link configuration table of the DRA device, including link type, source IP address, destination IP address, source port, destination port, source host name, destination host name, and link establishment time and shutdown time. Method 2: By analyzing the collected historical Diameter signaling data, the DRA device link information extraction algorithm is used to restore the link configuration table of the DRA device. The DRA device link information extraction algorithm mainly aggregates and counts the Diameter signaling data according to the link type, source IP address, destination IP address, source port, destination port, source host name, destination host name and other fields, performs correlation analysis on the results of multiple days, eliminates abnormal link data, and restores the link configuration table of the DRA device.

[0036] Step 2: Extract link information from the Diameter signaling data collected and flowing into the DRA device, and compare it with the link configuration table. If the link information is not in the link configuration table, it is determined to be a newly added link, and the Diameter signaling data on the newly added link is output; if the link information already exists in the link configuration table, it is determined to be a normal link;

[0037] Step 3: Perform threat behavior detection on the Diameter signaling data on the newly added link. If the Diameter signaling data is a threat behavior signaling, the newly added link is determined to be an illegal access link of the DRA device, and the network element information is extracted according to the illegal access link of the DRA device and input into the first illegal access network element set set1 = {ne1,ne2…,ne j}, where ne1 is the first illegal network element in the first illegal access network element set.

[0038] Specifically, threat behavior detection is performed on Diameter signaling data on the newly added link, specifically including: constructing a threat behavior detection rule table, and detecting Diameter signaling data on the newly added link according to the threat behavior detection rule table; wherein, the construction of the threat behavior detection rule table includes: storing rule data according to the detected threat behavior type, which is used to define and identify various threat behaviors so that the system can automatically detect and respond to potential security threats. For example, a threat behavior detection rule table is constructed according to fields such as Command-code, ApplicationId, Flags, Visited-PLMN-Id, and IDR-Flags for detection.

[0039] Step 4: By analyzing the Diameter signaling data flowing through the DRA device, extract the network element access time information and perform statistical analysis to calculate the network element access frequency within the specified time; and judge the access frequency of each network element. If there is a network element access frequency lower than the set threshold, it is marked as an indirect access network element, and the network element information is extracted to obtain the second illegal access network element set set2 = {ne1,ne2…,ne j}, where ne1 is the first illegal network element in the second set of illegal access network elements

[0040] The network element access time information is extracted and statistically analyzed to calculate the network element access frequency within the specified time, specifically including: calculating the number of times N the ith network element accesses within the specified time period i With the total number of access times N and access time T i The ratio of the total access time T to obtain the access frequency f of the i-th network element i :

[0041] f i =(N i / N)*(T i / T).

[0042] The access frequency of each network element is compared with a set threshold. If the access frequency is lower than the threshold δ, it is marked as an indirect access network element, and the set of all indirect access network elements is the second illegal access network element set2.

[0043] Step 5: Perform an intersection operation on the first set of illegally accessed network elements and the second set of illegally accessed network elements to obtain a final set of illegally accessed network elements set:

[0044] set=set1∩set2

[0045] The method provided by the present invention identifies a newly added link according to a DRA link configuration table, and performs threat behavior detection on the signaling data on the link to determine whether it is illegal access, and at the same time calculates the access frequency of the network element, determines whether it is illegal access according to the indirect access characteristics, and finally performs a comprehensive judgment by integrating the two detection means. The method can detect illegal access behaviors in time by performing newly added link detection through the DRA link configuration table, and detects according to the indirect access characteristics of the illegally accessed network element, so as to improve the accuracy of DRA illegal access detection.

[0046] like Figure 3 As shown, the embodiment of the present invention also provides a DRA device illegal access detection device based on signaling fusion analysis technology, including:

[0047] A Diameter signaling data collection unit, used to collect the Diameter signaling data flowing through the DRA device for storage, and obtain the link configuration table of the DRA device;

[0048] The newly added link detection unit of the DRA device is used to extract link information from the Diameter signaling data collected and flowing into the DRA device, and compare it with the link configuration table. If the link information is not in the link configuration table, it is determined to be a newly added link and the Diameter signaling data on the newly added link is output; if the link information already exists in the link configuration table, it is determined to be a normal link;

[0049] a signaling data threat behavior detection unit, configured to perform threat behavior detection on the Diameter signaling data on the newly added link, and if the Diameter signaling data is threat behavior signaling, determine that the newly added link is an illegal access link of the DRA device, and extract network element information according to the illegal access link of the DRA device and input it into the first illegal access network element set set1;

[0050] The indirect access feature calculation unit is used to extract the network element access time information and perform statistical analysis by analyzing the Diameter signaling data flowing through the DRA device, and calculate the network element access frequency within the specified time; and judge the access frequency of each network element, if there is a network element access frequency lower than the set threshold, it is marked as an indirect access network element, and the network element information is extracted to obtain the second illegal access network element set set2;

[0051] The DRA device illegal access comprehensive judgment unit is used to perform an intersection operation on the first illegal access network element set and the second illegal access network element set to obtain a final illegal access network element set.

[0052] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method for detecting illegal access of DRA equipment to network elements based on signaling fusion analysis technology, characterized in that: include: Step 1: Collect and store Diameter signaling data flowing through the DRA device, and obtain a link configuration table of the DRA device; Step 2: extracting link information from the Diameter signaling data collected and flowing into the DRA device, and comparing it with the link configuration table; if the link information is not in the link configuration table, it is determined to be a newly added link, and the Diameter signaling data on the newly added link is output; if the link information already exists in the link configuration table, it is determined to be a normal link; Step 3: Perform threat behavior detection on the Diameter signaling data on the newly added link. If the Diameter signaling data is threat behavior signaling, determine that the newly added link is an illegal access link of the DRA device, and extract network element information according to the illegal access link of the DRA device and input it into the first illegal access network element set set1; Step 4: By analyzing the Diameter signaling data flowing through the DRA device, extracting the network element access time information and performing statistical analysis, the network element access frequency within the specified time is calculated; and the access frequency of each network element is judged. If there is a network element access frequency lower than the set threshold, it is marked as an indirect access network element, and the network element information is extracted to obtain the second illegal access network element set set2; Step 5: performing an intersection operation on the first illegally accessed network element set and the second illegally accessed network element set to obtain a final illegally accessed network element set.

2. According to claim 1, a method for detecting illegal access of DRA equipment to network elements based on signaling fusion analysis technology, characterized in that: The step 1 adopts a full collection method to collect the Diameter signaling data flowing into and out of the DRA device in real time, parse the Diameter signaling data through a signaling parsing device, and store the parsed data in a HIVE data warehouse according to data field specifications, and partition and store them by day.

3. According to claim 1, a method for detecting illegal access of DRA equipment to network elements based on signaling fusion analysis technology, characterized in that: Obtaining the link configuration table of the DRA device in step 1 includes: logging into the DRA device management platform through an administrator account to directly obtain the link configuration table of the DRA device; The method also includes: restoring the link configuration table of the DRA device by analyzing the Diameter signaling data and adopting a DRA device link information extraction algorithm.

4. According to the method for detecting illegal access of DRA equipment to network elements based on signaling fusion analysis technology in claim 1, it is characterized in that: The link configuration data in the link configuration table includes link type, source IP address, destination IP address, source port, destination port, source host name, destination host name, and link establishment time and shutdown time.

5. The method for detecting illegal access of DRA equipment to network elements based on signaling fusion analysis technology according to claim 1, characterized in that: Performing threat behavior detection on the Diameter signaling data on the newly added link specifically includes: constructing a threat behavior detection rule table, and detecting the Diameter signaling data on the newly added link according to the threat behavior detection rule table.

6. The method for detecting illegal access of DRA equipment to network elements based on signaling fusion analysis technology according to claim 1, characterized in that: The extracting of network element access time information and performing statistical analysis to calculate the network element access frequency within a specified time period includes: calculating the number of times N the ith network element accesses within the specified time period. i With the total number of access times N and access time T i The ratio of the total access time T to obtain the access frequency f of the i-th network element i : f i =(N i / N)*(T i / T)。 7. A DRA device illegal access detection device based on signaling fusion analysis technology, characterized in that: include: A Diameter signaling data collection unit, used to collect and store Diameter signaling data flowing through the DRA device, and obtain a link configuration table of the DRA device; A newly added link detection unit of the DRA device is used to extract link information from the Diameter signaling data collected and flowing into the DRA device, and compare it with the link configuration table. If the link information is not in the link configuration table, it is determined to be a newly added link, and the Diameter signaling data on the newly added link is output; if the link information already exists in the link configuration table, it is determined to be a normal link; a signaling data threat behavior detection unit, configured to perform threat behavior detection on the Diameter signaling data on the newly added link, and if the Diameter signaling data is threat behavior signaling, determine that the newly added link is a DRA device illegal access link, and extract network element information according to the DRA device illegal access link and input it into a first illegal access network element set set1; an indirect access feature calculation unit, configured to extract network element access time information and perform statistical analysis by analyzing the Diameter signaling data flowing through the DRA device, and calculate the network element access frequency within a specified time; and to judge the access frequency of each network element, and if there is a network element access frequency lower than a set threshold, mark it as an indirect access network element, and extract network element information to obtain a second illegal access network element set set2; The DRA device illegal access comprehensive judgment unit is used to perform an intersection operation on the first illegal access network element set and the second illegal access network element set to obtain a final illegal access network element set set.

Citation Information

Patent Citations

  • Signaling data acquisition method

    CN103209423A

  • Diameter flooding attack detection device and method

    CN109040127A

  • 4G mobile communication network HSS signaling protection method and device

    CN113115314A

  • Diameter signaling transmission method and device

    WO2017108009A1