Processing method and system for dealing with radio frequency band abnormity
By collecting historical data in radio frequency band abnormality detection, establishing a background database, dynamically adjusting the detection warning period and threshold, combining bandwidth and spectrum characteristic analysis, using clustering algorithms to identify frequency hopping signals, and dynamically adjusting the risk coefficients according to the abnormal signal characteristics, solving the problems of low efficiency and difficulty in judgment in the existing technology, and achieving efficient and accurate abnormal signal detection and risk assessment.
Patent Information
- Application Number
- CN202510485189.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-17
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2045-04-17
AI Technical Summary
The prior art has low efficiency in radio frequency band abnormal detection, insufficient spectrum characteristic analysis capability, and difficult to judge frequency hopping signals, resulting in frequent missed detection and misdetection of abnormal signals.
By collecting historical abnormal data, establishing a background database, collecting radio signals in real time, dynamically determining the detection warning period, and setting the detection warning threshold according to the average intensity of the signal. Combining bandwidth and spectrum characteristics, a clustering algorithm is used to identify the frequency hopping signal, and dynamically adjust the risk coefficient and detection and warning period according to the frequency of abnormal signal and the characteristics of the frequency hopping signal.
Adaptive adjustment of detection threshold is realized, monitoring sensitivity is improved, environmental noise is effectively filtered, false alarm rate is reduced, frequency hopping is accurately identified, detection accuracy is improved, and response strategies can be automatically adapted and adjusted when facing radio threats of different intensity and types.
Smart Images

Figure CN119996095A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of radio detection technology, and in particular to a method and system for processing radio frequency band anomalies. Background Art
[0002] Existing industrial control equipment is prone to malicious installation of remote-controlled transmitters, which will emit wireless signals when certain conditions are met. Such malicious transmitters may cause serious information leakage. Therefore, real-time monitoring of radio frequency bands and accurate identification of abnormal signals are crucial to ensure information security and stable system operation.
[0003] In the existing technology, abnormal signal detection is mainly carried out through manual observation and fixed-frequency monitoring, which cannot be carried out for a long time without human supervision. When the frequency of the radio signal changes rapidly, it is difficult for traditional equipment to capture the sudden frequency hopping signal in time. Especially in a complex electromagnetic environment, the diversity of signals increases the difficulty of monitoring, resulting in frequent missed detection and false detection of abnormal signals.
[0004] Therefore, it is necessary to design a method and system for dealing with radio frequency band anomalies to solve the problems existing in current technology. Summary of the invention
[0005] In view of this, the present invention proposes a method and system for dealing with radio frequency band anomalies, aiming to solve the current problems of low efficiency in signal anomaly detection, insufficient spectrum characteristic analysis capability and difficulty in judging frequency hopping signals.
[0006] In one aspect, the present invention provides a method for dealing with radio frequency band anomalies, comprising: Collect historical data without abnormalities to establish a background database, collect real-time data sets, and determine the detection and early warning cycle according to the data volume of the real-time data sets; Collect all radio signals within the detection and warning period and obtain the average strength of the radio signals, use the average strength of the radio signals as the detection and warning threshold, analyze the radio signals according to the detection and warning threshold and the background database, determine whether there is a suspected abnormal signal and mark it; When the suspected abnormal signal exists, the bandwidth and spectrum characteristics of each of the suspected abnormal signals are obtained, and whether the suspected abnormal signal is an abnormal signal is determined according to the bandwidth and spectrum characteristics. When the suspected abnormal signal is determined to be an abnormal signal, the initial risk coefficient is determined according to the frequency of the abnormal signal; Extract the abnormal signal and identify the signal frequency, modulation mode and envelope shape, use the envelope shape as a feature vector, perform cluster analysis on all the abnormal signals based on a clustering algorithm, and determine whether a frequency hopping signal exists according to the clustering result; When it is determined that a frequency hopping signal exists, an adjustment coefficient is determined according to the characteristics of the frequency hopping signal to adjust the initial risk coefficient, and the next detection warning cycle is adjusted.
[0007] Furthermore, when determining the detection warning cycle according to the data volume of the real-time data set, it includes: The data volume is compared with a first preset data volume and a second preset data volume respectively, and a detection warning period is determined according to the comparison results; the first preset data volume is smaller than the second preset data volume; When the data volume is less than or equal to a first preset data volume, the detection warning cycle is determined to be a first cycle; when the data volume is greater than the first preset data volume and less than or equal to a second preset data volume, the detection warning cycle is determined to be a second cycle; when the data volume is greater than the second preset data volume, the detection warning cycle is determined to be a third cycle; the first cycle is greater than the second cycle, and the second cycle is greater than the third cycle.
[0008] Further, when analyzing the radio signal according to the detection warning threshold and the background database to determine whether there is a suspected abnormal signal and marking it, it includes: Compare the signal frequencies of all the radio signals with those in the background database, and compare the signal strength of each radio signal with the average strength of the radio signals, and determine whether there is a suspected abnormal signal based on the comparison results and mark it; When the signal strength of the radio signal is greater than a times the average strength of the radio signal, the radio signal is determined to be a suspected abnormal signal and marked; When the signal frequency of the radio signal is not in the background database, the radio signal is determined to be a suspected abnormal signal and marked.
[0009] Further, judging whether the suspected abnormal signal is an abnormal signal according to the bandwidth and the spectrum characteristics includes: When the bandwidth of the suspected abnormal signal is different from the commonly used bandwidth in the background database, determining the suspected abnormal signal as an abnormal signal; The spectrum characteristic includes a spectrum graph form. When the spectrum graph form of the suspected abnormal signal presents an isolated spectrum peak, the suspected abnormal signal is determined to be an abnormal signal.
[0010] Furthermore, when determining the initial risk factor based on the frequency of abnormal signals, it includes: ; Wherein, R0 represents the initial risk coefficient, N represents the frequency of abnormal signals, Wi represents the bandwidth of the ith abnormal signal, and Wi0 represents the bandwidth of the background database closest to the bandwidth of the ith abnormal signal.
[0011] Further, clustering analysis is performed on all the abnormal signals based on a clustering algorithm, and judging whether a frequency hopping signal exists according to the clustering result, including: The envelope shape includes the number of envelope curve peaks and the rate of change of envelope curve amplitude; Determine the initial neighborhood radius through the k-distance graph and set MinPts to 2; Take the characteristic vector of each abnormal signal as a point, scan all points, and find the points whose number of points in the neighborhood is greater than or equal to MinPts as core points; Starting from each core point, check the points in its neighborhood; if the point in the neighborhood is a core point, continue to expand the cluster; if the point in the neighborhood is a boundary point, add it to the current cluster; if a point is not in the neighborhood of any core point and cannot form a cluster with other points, it is marked as a noise point; When there is a cluster including at least two abnormal signals and the signal frequencies of the abnormal signals are at least two frequencies, it is determined that the abnormal signals in the cluster are frequency hopping signals.
[0012] Further, when the adjustment coefficient is determined according to the characteristics of the frequency hopping signal to adjust the initial risk coefficient, it includes: The characteristics of the frequency hopping signal include the total number of frequency hopping signals and the modulation mode of each frequency hopping signal, and the modulation mode includes AM, FM, QPSK, and OFDM; Comparing the characteristics of the frequency hopping signal with the historical adjustment scheme, and determining the adjustment coefficient according to the comparison result to adjust the initial risk coefficient; the historical adjustment scheme includes characteristics of several historical frequency hopping signals and several historical adjustment coefficients, and each characteristic of the historical frequency hopping signal corresponds to a historical adjustment coefficient; Calculating the similarity between the characteristic of the frequency hopping signal and the characteristic of each historical frequency hopping signal; When there is data in the characteristics of the historical frequency hopping signal whose similarity with the characteristics of the frequency hopping signal is greater than a similarity threshold, a historical adjustment coefficient is determined as the adjustment coefficient according to the characteristics of the historical frequency hopping signal corresponding to the maximum similarity to adjust the initial risk coefficient; When the similarity between the characteristics of the historical frequency hopping signal and the characteristics of the frequency hopping signal is less than or equal to the similarity threshold, the adjustment coefficient is determined according to the total number of the frequency hopping signals to adjust the initial risk coefficient.
[0013] Further, when the adjustment coefficient is determined according to the total number of the frequency hopping signals to adjust the initial risk coefficient, it includes: The adjustment coefficient is proportional to the total number of the frequency hopping signals, and the adjustment coefficient has a value range of (1, 1.5].
[0014] Furthermore, when adjusting the next detection and warning cycle, it includes: The adjusted risk coefficient is obtained, and a period adjustment coefficient is determined according to the risk coefficient to adjust the next detection warning period. The period adjustment coefficient is inversely proportional to the adjusted risk coefficient, and the value range of the period adjustment coefficient is [0.5, 1).
[0015] Compared with the prior art, the beneficial effects of the present invention are as follows: by collecting historical data without abnormalities to establish a background database, and dynamically determining the detection and warning cycle based on real-time data, the detection threshold is adaptively adjusted, and a high monitoring sensitivity can be maintained in different environments; by collecting radio signals in real time and calculating the average strength as the detection and warning threshold, environmental noise can be effectively filtered and the false alarm rate can be reduced; by combining bandwidth and spectrum characteristics to analyze suspected abnormal signals, identify real abnormal signals, and calculate the initial risk coefficient according to the frequency of abnormal signals, a preliminary assessment of the signal threat level is achieved; by extracting the frequency, modulation mode and envelope shape characteristics of abnormal signals, and using a clustering algorithm to analyze the characteristic vectors of all abnormal signals, frequency hopping signals can be effectively identified in a complex electromagnetic environment, thereby improving the accuracy of frequency hopping signal detection; by determining the adjustment coefficient based on the characteristics of the frequency hopping signal, the risk coefficient and the detection and warning cycle are dynamically adjusted, and the response strategy can be automatically adapted and adjusted when facing radio threats of different intensities and types, early warning and effective prevention of malicious transmitting devices and potential risks of leakage are achieved, and the automation and intelligence level of radio frequency band monitoring is enhanced.
[0016] On the other hand, the present application also provides a system for processing radio frequency band anomalies, which is used to apply the above-mentioned method for processing radio frequency band anomalies, including: The collection unit is configured to collect historical data without abnormalities to establish a background database, collect real-time data sets, and determine a detection and warning period according to the data volume of the real-time data sets; collect all radio signals within the detection and warning period and obtain the average strength of the radio signals, and use the average strength of the radio signals as a detection and warning threshold; A judgment unit is configured to analyze the radio signal according to the detection warning threshold and the background database, determine whether there is a suspected abnormal signal and mark it; when the suspected abnormal signal exists, obtain the bandwidth and spectrum characteristics of each of the suspected abnormal signals, and determine whether the suspected abnormal signal is an abnormal signal according to the bandwidth and spectrum characteristics, and when the suspected abnormal signal is determined to be an abnormal signal, determine the initial risk coefficient according to the frequency of the abnormal signal; A processing unit is configured to extract the abnormal signal and identify the signal frequency, modulation mode and envelope shape, use the envelope shape as a feature vector, perform cluster analysis on all the abnormal signals based on a clustering algorithm, and determine whether a frequency hopping signal exists according to the clustering result; when it is determined that a frequency hopping signal exists, determine an adjustment coefficient according to the characteristics of the frequency hopping signal to adjust the initial risk coefficient, and adjust the next detection warning cycle; An early warning unit, configured to issue an early warning according to the adjusted risk factor and display the abnormal signal; The storage unit is configured to store abnormal signal records.
[0017] It is understandable that the above-mentioned methods and systems for dealing with radio frequency band anomalies have the same beneficial effects and will not be described in detail here. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] Various other advantages and benefits will become apparent to those of ordinary skill in the art by reading the detailed description of the preferred embodiments below. The accompanying drawings are only for the purpose of illustrating the preferred embodiments and are not to be considered as limiting the present invention. Moreover, the same reference symbols are used throughout the accompanying drawings to represent the same components. In the accompanying drawings: Figure 1 A flowchart of a method for dealing with radio frequency band anomalies provided by an embodiment of the present invention; Figure 2 A functional block diagram of a system for processing radio frequency band anomalies provided by an embodiment of the present invention; Figure 3 A schematic diagram of an early warning unit in a processing system for dealing with radio frequency band anomalies provided by an embodiment of the present invention; Figure 4 A schematic diagram of storage of a storage unit in a processing system for dealing with radio frequency band anomalies provided by an embodiment of the present invention; Figure 5 A schematic diagram of display contents of a storage unit in a processing system for dealing with radio frequency band anomalies provided by an embodiment of the present invention; DETAILED DESCRIPTION
[0019] Exemplary embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although exemplary embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments described herein. On the contrary, these embodiments are provided in order to enable a more thorough understanding of the present disclosure and to fully convey the scope of the present disclosure to those skilled in the art. It should be noted that, in the absence of conflict, the embodiments of the present invention and the features described in the embodiments can be combined with each other. The present invention will be described in detail below with reference to the accompanying drawings and in combination with the embodiments.
[0020] In some embodiments of the present application, see Figure 1 As shown, a method for dealing with radio frequency band anomalies includes: S100: Collect historical data without abnormalities to establish a background database, collect real-time data sets, and determine the detection and warning cycle according to the data volume of the real-time data sets.
[0021] S200: Collect all radio signals within the detection warning period and obtain the average strength of the radio signals, use the average strength of the radio signals as the detection warning threshold, analyze the radio signals according to the detection warning threshold and the background database, determine whether there is a suspected abnormal signal and mark it.
[0022] S300: When there is a suspected abnormal signal, obtain the bandwidth and spectrum characteristics of each suspected abnormal signal, and determine whether the suspected abnormal signal is an abnormal signal based on the bandwidth and spectrum characteristics. When the suspected abnormal signal is determined to be an abnormal signal, determine the initial risk coefficient based on the frequency of the abnormal signal.
[0023] S400: extract abnormal signals and identify signal frequency, modulation mode and envelope shape, use the envelope shape as a feature vector, perform cluster analysis on all abnormal signals based on a clustering algorithm, and determine whether a frequency hopping signal exists based on the clustering results.
[0024] S500: When it is determined that a frequency hopping signal exists, an adjustment coefficient is determined according to the characteristics of the frequency hopping signal to adjust the initial risk coefficient, and the next detection warning cycle is adjusted.
[0025] Specifically, the overall solution is to accurately identify abnormal signals, especially frequency-hopping signals, by dynamically detecting changes in radio frequency signals, combined with signal feature analysis and clustering algorithms, and adjust the system's risk assessment and detection strategies according to the characteristics of abnormal signals, so as to effectively respond to security threats that may be posed by malicious transmitters. The background database is established, signal anomaly detection, risk assessment, cluster analysis and frequency-hopping identification are implemented, and the detection and warning cycle is dynamically adjusted to form a closed-loop intelligent monitoring system.
[0026] Specifically, in S100, the background database is established using the historically collected radio signal data without abnormalities as a benchmark for determining whether the signal is abnormal. By analyzing the data volume of the real-time data set, the detection warning cycle is dynamically adjusted according to parameters such as the data collection speed and the signal change frequency, so as to realize adaptive control of the signal monitoring frequency. The detection cycle is extended when the signal is stable, and the detection cycle is shortened when the signal is complex or changes frequently. In S200, all radio signals are collected within the detection warning cycle, and the dynamic detection warning threshold is set by calculating the average strength of the signal, and the signal comparison and analysis is performed in combination with the background database. When the signal strength exceeds the threshold or the signal characteristics do not match the background database, the signal is marked as a suspected abnormal signal to realize the preliminary screening function. In S300, the bandwidth and spectral characteristics (such as spectrum peak, signal shape) of the suspected abnormal signal are obtained, and the bandwidth and spectral characteristics of the conventional signal in the background database are compared to determine whether it is an abnormal signal. When the bandwidth does not match the conventional signal or the spectrum graph shows an isolated peak, it is determined to be an abnormal signal. In S400, feature information is extracted from abnormal signals, including signal frequency, modulation mode (such as ASK, FSK, QAM, etc.) and envelope shape. The envelope shape is used as a feature vector, and clustering analysis is performed on all abnormal signals using a clustering algorithm. By calculating the similarity of the signal feature vectors, abnormal signals that may come from the same signal source are aggregated into the same category. When the clustering results show that signals appearing in different frequency bands or at different times are clustered together and exhibit frequency hopping characteristics, it can be determined that there is a frequency hopping signal. Identify situations where malicious transmitters use frequency hopping technology to conceal their own behavior. In S500, after identifying the frequency hopping signal, the adjustment coefficient is calculated to correct the initial risk coefficient. For example, the more frequency hopping signals there are, the higher the risk coefficient. At the same time, the next detection and warning cycle is dynamically adjusted to increase the monitoring frequency in a high-risk environment and reduce resource consumption in a low-risk environment.
[0027] It is understandable that by constructing a dynamic background database and adaptive detection and warning thresholds, intelligent screening of radio signals is achieved, environmental noise is effectively filtered, and the false alarm rate is reduced. Through bandwidth and spectrum characteristic analysis, accurate judgment of suspected abnormal signals is achieved; the feature vector analysis method based on clustering algorithm breaks through the limitations of traditional manual monitoring of frequency hopping signals, and can automatically identify frequency hopping signals with fast frequency changes and complex modulation methods, thereby improving the detection accuracy of frequency hopping signals; through the dual calculation mechanism of risk coefficient and adjustment coefficient, it has the ability to dynamically adjust the detection cycle, thereby realizing refined management of risk assessment; it can effectively respond to security threats that may be brought by malicious transmitting devices, maintain high efficiency and stability of monitoring in complex electromagnetic environments, reduce the workload and technical threshold of manual monitoring, and improve the intelligence level and security protection capabilities of radio frequency band monitoring.
[0028] In some embodiments of the present application, when determining the detection warning period according to the data volume of the real-time data set, it includes: comparing the data volume with the first preset data volume and the second preset data volume respectively, and determining the detection warning period according to the comparison result; the first preset data volume is less than the second preset data volume; Specifically, when the data volume is less than or equal to the first preset data volume, the detection warning cycle is determined to be the first cycle; when the data volume is greater than the first preset data volume and less than or equal to the second preset data volume, the detection warning cycle is determined to be the second cycle; when the data volume is greater than the second preset data volume, the detection warning cycle is determined to be the third cycle; the first cycle is greater than the second cycle, and the second cycle is greater than the third cycle.
[0029] It is understandable that by setting multi-level data volume thresholds, dynamic adaptive adjustment of the detection and warning cycle is achieved, and the monitoring frequency can be automatically switched according to the complexity of the radio signal environment. When the signal environment is simple, the monitoring frequency is reduced to save resources; when the signal environment is complex or there are potential security risks, the monitoring frequency is encrypted to quickly identify and locate abnormal signals. It effectively improves the monitoring efficiency and safety in complex electromagnetic environments, especially in scenarios with frequent frequency hopping signals and multi-terminal signal sources. This solution does not require human intervention and is suitable for long-term unattended automated monitoring scenarios, which reduces monitoring costs and improves response speed.
[0030] In some embodiments of the present application, when analyzing the radio signal according to the detection warning threshold and the background database to determine whether there is a suspected abnormal signal and marking it, it includes: The signal frequencies of all radio signals are compared with those in the background database, and the signal strength of each radio signal is compared with the average strength of the radio signals. Based on the comparison results, it is determined whether there are suspected abnormal signals and marked; When the signal strength of the radio signal is greater than a times the average strength of the radio signal, the radio signal is determined to be a suspected abnormal signal and marked; When the signal frequency of the radio signal is not in the background database, the radio signal is determined to be a suspected abnormal signal and marked.
[0031] In some embodiments of the present application, judging whether a suspected abnormal signal is an abnormal signal according to bandwidth and spectrum characteristics includes: When the bandwidth of the suspected abnormal signal is different from the commonly used bandwidth in the background database, the suspected abnormal signal is determined to be an abnormal signal; The spectrum characteristics include the spectrum graph shape. When the spectrum graph shape of the suspected abnormal signal presents an isolated spectrum peak, the suspected abnormal signal is determined to be an abnormal signal.
[0032] In some embodiments of the present application, when determining the initial risk coefficient according to the frequency of abnormal signals, it includes: ; Wherein, R0 represents the initial risk coefficient, N represents the frequency of abnormal signals, Wi represents the bandwidth of the ith abnormal signal, and Wi0 represents the bandwidth of the background database closest to the bandwidth of the ith abnormal signal.
[0033] It is understandable that commonly used bandwidths in the background database are, for example, 20MHz or 40MHz for Wi-Fi signals and 200kHz for FM broadcast signals. The frequency of abnormal signals is the total number of all abnormal signals that appear. Parameter a is the strength threshold coefficient, which can be dynamically set according to the environmental noise level and the historical signal fluctuation range. The preferred value of a is [1.5-3]. Malicious devices usually adopt special emission strategies, such as short-term high power, non-mainstream frequency bands, complex modulation methods, random intermittent emission, etc., in order to achieve concealment and avoid monitoring. In this embodiment, a multi-dimensional comprehensive judgment mechanism is provided in the detection of abnormal signals in the radio frequency band. The suspected abnormal signals are preliminarily screened by comparing the signal strength and frequency, and the abnormal signals are further screened and confirmed by the bandwidth and spectrum characteristics, thereby improving the accuracy and reliability of the detection. By dynamically calculating the initial risk coefficient, the quantitative risk assessment of abnormal signals is realized, and the monitoring strategy can be flexibly adjusted according to the risk level. The bandwidth deviation calculation method used makes it more adaptable when dealing with complex and changeable signal environments, and can quickly respond to potential security threats, especially in the case of frequency hopping signal detection and high-frequency abnormal signals. It can issue early warnings in time and increase the monitoring frequency, effectively preventing information security leaks.
[0034] In some embodiments of the present application, clustering analysis is performed on all abnormal signals based on a clustering algorithm, and judging whether a frequency hopping signal exists according to the clustering result includes: The envelope shape includes the number of envelope curve peaks and the rate of change of envelope curve amplitude; Determine the initial neighborhood radius through the k-distance graph and set MinPts to 2; Take the characteristic vector of each abnormal signal as a point, scan all points, and find the points with the number of points in the neighborhood greater than or equal to MinPts as the core points; Starting from each core point, check the points in its neighborhood; if the point in the neighborhood is a core point, continue to expand the cluster; if the point in the neighborhood is a boundary point, add it to the current cluster; if a point is not in the neighborhood of any core point and cannot form a cluster with other points, it is marked as a noise point; When there is a cluster including at least two abnormal signals and the signal frequencies of the abnormal signals are at least two frequencies, it is determined that the abnormal signals in the cluster are frequency hopping signals.
[0035] Specifically, the signal frequency of the abnormal signal in this embodiment refers to the center frequency of the abnormal signal.
[0036] It is understandable that by combining the density clustering algorithm with the radio signal feature analysis, efficient recognition of frequency hopping signals is achieved. Unlike traditional spectrum scanning or fixed frequency detection methods, automatic classification of multi-band signals through feature similarity clustering can effectively cope with the rapid frequency change characteristics of frequency hopping signals. By introducing the technical means of automatically determining the neighborhood radius by using the k-distance graph, the clustering process has strong adaptability and can accurately separate frequency hopping signals and noise signals in complex electromagnetic environments. The accuracy of abnormal signal detection is improved.
[0037] In some embodiments of the present application, when the adjustment coefficient is determined according to the characteristics of the frequency hopping signal to adjust the initial risk coefficient, it includes: The characteristics of the frequency hopping signal include the total number of frequency hopping signals and the modulation method of each frequency hopping signal, and the modulation methods include AM, FM, QPSK, and OFDM; Comparing the characteristics of the frequency hopping signal with the historical adjustment plan, and determining the adjustment coefficient according to the comparison result to adjust the initial risk coefficient; the historical adjustment plan includes characteristics of several historical frequency hopping signals and several historical adjustment coefficients, and each characteristic of the historical frequency hopping signal corresponds to a historical adjustment coefficient; Calculate the similarity between the characteristics of the frequency hopping signal and the characteristics of each historical frequency hopping signal; When there is data in the characteristics of the historical frequency hopping signal whose similarity with the characteristics of the frequency hopping signal is greater than the similarity threshold, the historical adjustment coefficient is determined as the adjustment coefficient according to the characteristics of the historical frequency hopping signal corresponding to the maximum similarity to adjust the initial risk coefficient; When the similarity between the characteristics of the historical frequency hopping signal and the characteristics of the frequency hopping signal is less than or equal to the similarity threshold, the adjustment coefficient is determined according to the total number of frequency hopping signals to adjust the initial risk coefficient.
[0038] In some embodiments of the present application, when the initial risk coefficient is adjusted by determining the adjustment coefficient according to the total number of frequency hopping signals, it includes: the adjustment coefficient is proportional to the total number of frequency hopping signals, and the adjustment coefficient has a value range of (1, 1.5].
[0039] In some embodiments of the present application, when adjusting the next detection warning cycle, it includes: obtaining the adjusted risk coefficient, determining the cycle adjustment coefficient according to the risk coefficient to adjust the next detection warning cycle, the cycle adjustment coefficient is inversely proportional to the adjusted risk coefficient, and the value range of the cycle adjustment coefficient is [0.5, 1).
[0040] Specifically, when the initial risk coefficient is adjusted by determining the adjustment coefficient based on the total number of frequency hopping signals, the adjusted risk coefficient is the product of the initial risk coefficient and the adjustment coefficient. When the next detection and warning cycle is adjusted, the next detection and warning cycle is the product of the current detection and warning cycle and the cycle adjustment coefficient. The frequency hopping signal characteristics are matched using similarity calculation, and the risk coefficient is dynamically adjusted based on historical experience. In the absence of sufficient historical data, an adaptive calculation method based on the total number of frequency hopping signals is provided, which effectively avoids the risk assessment blind spot caused by insufficient historical data. By introducing the inverse relationship between the adjusted risk coefficient and the detection and warning cycle into the control mechanism, the monitoring frequency can be automatically adjusted when the electromagnetic environment changes complexly, ensuring higher frequency monitoring in high-risk environments, while saving resources in low-risk situations, achieving a balance between detection efficiency and resource consumption.
[0041] In the above embodiment, by collecting historical data without abnormalities to establish a background database, and dynamically determining the detection warning cycle based on real-time data, the detection threshold is adaptively adjusted, and a high monitoring sensitivity can be maintained in different environments; by collecting radio signals in real time and calculating the average strength as the detection warning threshold, environmental noise can be effectively filtered and the false alarm rate can be reduced; by combining the bandwidth and spectrum characteristics to analyze suspected abnormal signals, identify real abnormal signals, and calculate the initial risk coefficient according to the frequency of abnormal signals, a preliminary assessment of the signal threat level is achieved; by extracting the frequency, modulation mode and envelope shape characteristics of abnormal signals, and using a clustering algorithm to analyze the characteristic vectors of all abnormal signals, frequency hopping signals are effectively identified in a complex electromagnetic environment, thereby improving the accuracy of frequency hopping signal detection; by determining the adjustment coefficient based on the characteristics of the frequency hopping signal, the risk coefficient and the detection warning cycle are dynamically adjusted, and the response strategy can be automatically adapted and adjusted when facing radio threats of different intensities and types, early warning and effective prevention of malicious transmitting devices and potential risks of leakage are achieved, and the automation and intelligence level of radio frequency band monitoring is enhanced.
[0042] In another preferred embodiment based on the above embodiment, refer to Figure 2 As shown, this embodiment provides a processing system for dealing with radio frequency band anomalies, which is used to apply the above-mentioned processing method for dealing with radio frequency band anomalies, including: The collection unit is configured to collect historical data without abnormalities to establish a background database, collect real-time data sets, and determine the detection and warning period according to the data volume of the real-time data sets; collect all radio signals within the detection and warning period and obtain the average strength of the radio signals, and use the average strength of the radio signals as the detection and warning threshold; The judgment unit is configured to analyze the radio signal according to the detection warning threshold and the background database, judge whether there is a suspected abnormal signal and mark it; when there is a suspected abnormal signal, obtain the bandwidth and spectrum characteristics of each suspected abnormal signal, judge whether the suspected abnormal signal is an abnormal signal according to the bandwidth and spectrum characteristics, and when the suspected abnormal signal is determined to be an abnormal signal, determine the initial risk coefficient according to the frequency of the abnormal signal; The processing unit is configured to extract abnormal signals and identify signal frequency, modulation mode and envelope shape, use the envelope shape as a feature vector, perform cluster analysis on all abnormal signals based on a clustering algorithm, and determine whether a frequency hopping signal exists according to the clustering result; when it is determined that a frequency hopping signal exists, determine an adjustment coefficient according to the characteristics of the frequency hopping signal to adjust the initial risk coefficient, and adjust the next detection warning cycle; An early warning unit is configured to issue an early warning based on the adjusted risk factor and display abnormal signals; The storage unit is configured to store abnormal signal records.
[0043] Specifically, see Figure 3 As shown, when the warning unit issues a warning, the signal list turns red and a sound alarm is issued.
[0044] Specifically, see Figure 4 As shown, the storage unit stores abnormal signal records, including up and down frequency conversion, level, peak frequency, trigger events, etc., and can switch to fixed frequency monitoring mode for the abnormal signal of focus, and can see the spectrum diagram and waterfall diagram in real time, and can monitor the audio in real time; record complete spectrum data, signal information, audio and 2M bandwidth baseband IQ data. And refer to Figure 5 As shown, the recorded data can be fully replayed. The left side of the figure is a list of signals triggered during the monitoring period; the upper right list in the figure shows the information corresponding to a continuously triggered signal; the lower right figure in the figure shows the trigger time and frequency relationship corresponding to all triggered signals in the monitoring period, where the vertical axis represents the trigger time and the horizontal axis represents the frequency of the trigger signal.
[0045] It can be understood that by collecting historical data without abnormalities to establish a background database, and dynamically determining the detection and warning cycle based on real-time data, the detection threshold can be adaptively adjusted, and a high monitoring sensitivity can be maintained in different environments; by collecting radio signals in real time and calculating the average strength as the detection and warning threshold, environmental noise can be effectively filtered and the false alarm rate can be reduced; by combining bandwidth and spectrum characteristics to analyze suspected abnormal signals, identify real abnormal signals, and calculate the initial risk coefficient based on the frequency of abnormal signals, a preliminary assessment of the signal threat level can be achieved; by extracting the frequency, modulation mode and envelope shape characteristics of abnormal signals, and using clustering algorithms to analyze the characteristic vectors of all abnormal signals, frequency hopping signals can be effectively identified in complex electromagnetic environments, thereby improving the accuracy of frequency hopping signal detection; by determining the adjustment coefficient based on the characteristics of the frequency hopping signal, the risk coefficient and the detection and warning cycle can be dynamically adjusted, and the response strategy can be automatically adapted and adjusted when facing radio threats of different intensities and types, achieving early warning and effective prevention of malicious transmitting devices and potential risks of leakage, and enhancing the automation and intelligence level of radio frequency band monitoring.
[0046] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems or computer program products. Therefore, the present application may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present application may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program codes.
[0047] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems) and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0048] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1A function specified in one or more boxes.
[0049] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0050] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the above embodiments, ordinary technicians in the relevant field should understand that the specific implementation methods of the present invention can still be modified or replaced by equivalents. Any modification or equivalent replacement that does not depart from the spirit and scope of the present invention should be covered within the scope of protection of the claims of the present invention.
Claims
1. A method for dealing with radio frequency band anomalies, characterized in that: include: Collect historical data without abnormalities to establish a background database, collect real-time data sets, and determine the detection and early warning cycle according to the data volume of the real-time data sets; Collect all radio signals within the detection and warning period and obtain the average strength of the radio signals, use the average strength of the radio signals as the detection and warning threshold, analyze the radio signals according to the detection and warning threshold and the background database, determine whether there is a suspected abnormal signal and mark it; When the suspected abnormal signal exists, the bandwidth and spectrum characteristics of each of the suspected abnormal signals are obtained, and whether the suspected abnormal signal is an abnormal signal is determined according to the bandwidth and spectrum characteristics. When the suspected abnormal signal is determined to be an abnormal signal, the initial risk coefficient is determined according to the frequency of the abnormal signal; Extract the abnormal signal and identify the signal frequency, modulation mode and envelope shape, use the envelope shape as a feature vector, perform cluster analysis on all the abnormal signals based on a clustering algorithm, and determine whether a frequency hopping signal exists according to the clustering result; When it is determined that a frequency hopping signal exists, an adjustment coefficient is determined according to the characteristics of the frequency hopping signal to adjust the initial risk coefficient, and the next detection warning cycle is adjusted.
2. The method for dealing with radio frequency band anomalies according to claim 1, characterized in that: When determining the detection and warning cycle according to the data volume of the real-time data set, it includes: The data volume is compared with a first preset data volume and a second preset data volume respectively, and a detection warning period is determined according to the comparison results; the first preset data volume is smaller than the second preset data volume; When the data volume is less than or equal to a first preset data volume, the detection warning cycle is determined to be a first cycle; when the data volume is greater than the first preset data volume and less than or equal to a second preset data volume, the detection warning cycle is determined to be a second cycle; when the data volume is greater than the second preset data volume, the detection warning cycle is determined to be a third cycle; the first cycle is greater than the second cycle, and the second cycle is greater than the third cycle.
3. The method for dealing with radio frequency band anomalies according to claim 2, characterized in that: When analyzing the radio signal according to the detection warning threshold and the background database to determine whether there is a suspected abnormal signal and marking it, it includes: Compare the signal frequencies of all the radio signals with those in the background database, and compare the signal strength of each radio signal with the average strength of the radio signals, and determine whether there is a suspected abnormal signal based on the comparison results and mark it; When the signal strength of the radio signal is greater than a times the average strength of the radio signal, the radio signal is determined to be a suspected abnormal signal and marked; When the signal frequency of the radio signal is not in the background database, the radio signal is determined to be a suspected abnormal signal and marked.
4. The method for dealing with radio frequency band anomalies according to claim 3, characterized in that: When judging whether the suspected abnormal signal is an abnormal signal according to the bandwidth and the spectrum characteristics, it includes: When the bandwidth of the suspected abnormal signal is different from the commonly used bandwidth in the background database, determining the suspected abnormal signal as an abnormal signal; The spectrum characteristic includes a spectrum graph form. When the spectrum graph form of the suspected abnormal signal presents an isolated spectrum peak, the suspected abnormal signal is determined to be an abnormal signal.
5. The method for dealing with radio frequency band anomalies according to claim 4, characterized in that: When determining the initial risk factor based on the frequency of abnormal signals, it includes: ; Wherein, R0 represents the initial risk coefficient, N represents the frequency of abnormal signals, Wi represents the bandwidth of the ith abnormal signal, and Wi0 represents the bandwidth of the background database closest to the bandwidth of the ith abnormal signal.
6. The method for dealing with radio frequency band anomalies according to claim 5, characterized in that: Performing cluster analysis on all the abnormal signals based on a clustering algorithm and determining whether a frequency hopping signal exists according to the clustering result includes: The envelope shape includes the number of envelope curve peaks and the rate of change of envelope curve amplitude; Determine the initial neighborhood radius through the k-distance graph and set MinPts to 2; Take the characteristic vector of each abnormal signal as a point, scan all points, and find the points whose number of points in the neighborhood is greater than or equal to MinPts as core points; Starting from each core point, check the points in its neighborhood; if the point in the neighborhood is a core point, continue to expand the cluster; if the point in the neighborhood is a boundary point, add it to the current cluster; if a point is not in the neighborhood of any core point and cannot form a cluster with other points, it is marked as a noise point; When there is a cluster including at least two abnormal signals and the signal frequencies of the abnormal signals are at least two frequencies, it is determined that the abnormal signals in the cluster are frequency hopping signals.
7. The method for dealing with radio frequency band anomalies according to claim 6, characterized in that: When the adjustment coefficient is determined according to the characteristics of the frequency hopping signal to adjust the initial risk coefficient, it includes: The characteristics of the frequency hopping signal include the total number of frequency hopping signals and the modulation mode of each frequency hopping signal, and the modulation mode includes AM, FM, QPSK, and OFDM; Comparing the characteristics of the frequency hopping signal with the historical adjustment scheme, and determining the adjustment coefficient according to the comparison result to adjust the initial risk coefficient; the historical adjustment scheme includes characteristics of several historical frequency hopping signals and several historical adjustment coefficients, and each characteristic of the historical frequency hopping signal corresponds to a historical adjustment coefficient; Calculating the similarity between the characteristic of the frequency hopping signal and the characteristic of each historical frequency hopping signal; When there is data in the characteristics of the historical frequency hopping signal whose similarity with the characteristics of the frequency hopping signal is greater than a similarity threshold, a historical adjustment coefficient is determined as the adjustment coefficient according to the characteristics of the historical frequency hopping signal corresponding to the maximum similarity to adjust the initial risk coefficient; When the similarity between the characteristics of the historical frequency hopping signal and the characteristics of the frequency hopping signal is less than or equal to the similarity threshold, the adjustment coefficient is determined according to the total number of the frequency hopping signals to adjust the initial risk coefficient.
8. The method for dealing with radio frequency band anomalies according to claim 7, characterized in that: When the adjustment coefficient is determined according to the total number of the frequency hopping signals to adjust the initial risk coefficient, it includes: The adjustment coefficient is proportional to the total number of the frequency hopping signals, and the adjustment coefficient has a value range of (1, 1.5].
9. The method for dealing with radio frequency band anomalies according to claim 8, characterized in that: When adjusting the next detection and warning cycle, include: The adjusted risk coefficient is obtained, and a period adjustment coefficient is determined according to the risk coefficient to adjust the next detection warning period. The period adjustment coefficient is inversely proportional to the adjusted risk coefficient, and the value range of the period adjustment coefficient is [0.5, 1).
10. A system for processing radio frequency band anomalies, used for applying the method for processing radio frequency band anomalies according to any one of claims 1 to 9, characterized in that: include: A collection unit is configured to collect historical data without abnormalities to establish a background database, collect real-time data sets, and determine a detection and early warning cycle according to the data volume of the real-time data sets; Collecting all radio signals within the detection and warning period and obtaining an average strength of the radio signals, and using the average strength of the radio signals as a detection and warning threshold; A judgment unit is configured to analyze the radio signal according to the detection warning threshold and the background database, determine whether there is a suspected abnormal signal and mark it; when the suspected abnormal signal exists, obtain the bandwidth and spectrum characteristics of each of the suspected abnormal signals, and determine whether the suspected abnormal signal is an abnormal signal according to the bandwidth and spectrum characteristics, and when the suspected abnormal signal is determined to be an abnormal signal, determine the initial risk coefficient according to the frequency of the abnormal signal; A processing unit is configured to extract the abnormal signal and identify the signal frequency, modulation mode and envelope shape, use the envelope shape as a feature vector, perform cluster analysis on all the abnormal signals based on a clustering algorithm, and determine whether a frequency hopping signal exists according to the clustering result; When it is determined that a frequency hopping signal exists, an adjustment coefficient is determined according to the characteristics of the frequency hopping signal to adjust the initial risk coefficient, and the next detection warning cycle is adjusted; An early warning unit, configured to issue an early warning according to the adjusted risk factor and display the abnormal signal; The storage unit is configured to store abnormal signal records.
Citation Information
Patent Citations
Urban public safety early warning system based on progressive early warning mode
CN113177873A
Real-time acquisition and detection method and system for frequency hopping signals
CN117560037A
Frequency hopping signal detection method based on discontinuous spectrum data
CN118264275A
Underground facility vibration monitoring method and system based on distributed sensor network
CN119147094A
Display device and driving method thereof
US20200234620A1