A processing method and system for coping with radio frequency band anomalies
By establishing a background database and dynamically adjusting the detection and warning cycle, combining signal strength, bandwidth and clustering algorithm analysis, the problem of low detection efficiency of abnormal detection in radio frequency bands is solved, and accurate identification and automated early warning of frequency hopping signals are achieved.
Patent Information
- Application Number
- CN202510485189.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-17
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2045-04-17
AI Technical Summary
In the prior art, the radio frequency band abnormal detection efficiency is low, making it difficult to identify frequency hopping signals, especially in complex electromagnetic environments, missed detection and missed detection are prone to occur.
By establishing a background database, dynamically adjusting the detection and warning cycle, combining signal strength, bandwidth, spectrum characteristics and clustering algorithm analysis, the risk coefficient is identified and adjusted to identify frequency hopping signals.
It realizes intelligent monitoring of the radio frequency band, reduces false alarm rates, improves the detection accuracy of frequency hopping signals, and can automatically adapt to and promptly warn of potential threats in complex environments.
Smart Images

Figure CN119996095B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of radio detection. Specifically, it relates to a method and system for dealing with abnormal radio frequency bands. Background Art
[0002] In existing industrial control devices, it is easy to maliciously install transmitting devices that can be remotely controlled. When specific conditions are met, they will transmit wireless signals outward. Such malicious transmitting devices may cause serious information leakage incidents. Therefore, the real-time monitoring of radio frequency bands and the accurate identification of abnormal signals are crucial for ensuring information security and the stable operation of the system.
[0003] In the prior art, abnormal signal detection is mainly carried out through manual observation and fixed-frequency monitoring, and unattended monitoring cannot be carried out for a long time. When the radio signal frequency changes rapidly, it is difficult for traditional devices to capture sudden frequency hopping signals in time. Especially in a complex electromagnetic environment, the signal diversity increases the monitoring difficulty, resulting in frequent missed detections and false detections of abnormal signals.
[0004] Therefore, it is necessary to design a method and system for dealing with abnormal radio frequency bands to solve the problems existing in the current technology. Summary of the Invention
[0005] In view of this, the present invention proposes a method and system for dealing with abnormal radio frequency bands, aiming to solve the problems of low efficiency of current signal abnormal detection, insufficient spectrum characteristic analysis ability, and difficulty in judging frequency hopping signals.
[0006] On the one hand, the present invention proposes a method for dealing with abnormal radio frequency bands, including:
[0007] Collect historical anomaly-free data to establish a background database, collect a real-time data set, and determine a detection and warning period according to the data volume of the real-time data set;
[0008] Collect all radio signals within the detection and warning period and obtain the average intensity of the radio signals. Use the average intensity of the radio signals as the detection and warning threshold, and analyze the radio signals according to the detection and warning threshold and the background database to judge whether there are suspected abnormal signals and mark them;
[0009] When there are the suspected abnormal signals, obtain the bandwidth and spectrum characteristics of each suspected abnormal signal, judge whether the suspected abnormal signal is an abnormal signal according to the bandwidth and spectrum characteristics, and when it is determined that the suspected abnormal signal is an abnormal signal, determine the initial risk coefficient according to the abnormal signal frequency;
[0010] Extract the abnormal signal and identify the signal frequency, modulation mode, and envelope shape. Use the envelope shape as a feature vector, and perform clustering analysis on all the abnormal signals based on a clustering algorithm. Determine whether there is a frequency-hopping signal according to the clustering result;
[0011] When it is determined that there is a frequency-hopping signal, determine an adjustment coefficient according to the characteristics of the frequency-hopping signal to adjust the initial risk coefficient, and adjust the next detection and early warning period.
[0012] Further, when determining the detection and early warning period according to the data volume of the real-time data set, it includes:
[0013] Compare the data volume with a first preset data volume and a second preset data volume respectively, and determine the detection and early warning period according to the comparison result; the first preset data volume is less than the second preset data volume;
[0014] When the data volume is less than or equal to the first preset data volume, determine that the detection and early warning period is the first period; when the data volume is greater than the first preset data volume and less than or equal to the second preset data volume, determine that the detection and early warning period is the second period; when the data volume is greater than the second preset data volume, determine that the detection and early warning period is the third period; the first period is greater than the second period, and the second period is greater than the third period.
[0015] Further, when analyzing the radio signal according to the detection and early warning threshold and the background database to determine whether there is a suspected abnormal signal and marking it, it includes:
[0016] Compare the signal frequencies of all the radio signals with those in the background database, and compare the signal intensity of each radio signal with the average radio signal intensity. Determine whether there is a suspected abnormal signal and mark it according to the comparison result;
[0017] When the signal intensity of the radio signal is greater than a times the average radio signal intensity, determine that the radio signal is a suspected abnormal signal and mark it;
[0018] When the signal frequency of the radio signal is not in the background database, determine that the radio signal is a suspected abnormal signal and mark it.
[0019] Further, when determining whether the suspected abnormal signal is an abnormal signal according to the bandwidth and spectral characteristics, it includes:
[0020] When the bandwidth of the suspected abnormal signal is different from the common bandwidth in the background database, determine that the suspected abnormal signal is an abnormal signal;
[0021] The spectral characteristics include the spectrogram morphology. When the spectrogram morphology of the suspected abnormal signal presents isolated spectral peaks, the suspected abnormal signal is determined to be an abnormal signal.
[0022] Further, when determining the initial risk coefficient according to the abnormal signal frequency, it includes:
[0023] ;
[0024] Among them, R0 represents the initial risk coefficient, N represents the abnormal signal frequency, Wi represents the bandwidth of the i-th abnormal signal, and Wi0 represents the bandwidth of the background database closest to the bandwidth of the i-th abnormal signal.
[0025] Further, when performing clustering analysis on all the abnormal signals based on the clustering algorithm and determining whether there is a frequency hopping signal according to the clustering result, it includes:
[0026] The envelope shape includes the number of peaks of the envelope curve and the amplitude change rate of the envelope curve;
[0027] Determine the initial neighborhood radius through the k-distance graph and determine MinPts as 2;
[0028] Take the feature vector of each abnormal signal as a point, scan all points, and find the points with the number of points in the neighborhood greater than or equal to MinPts as core points;
[0029] Starting from each core point, check the points in its neighborhood; if the points in the neighborhood are core points, continue to expand the cluster; if the points in the neighborhood are boundary points, add them to the current cluster; if a point is not in the neighborhood of any core point and cannot form a cluster with other points, it is marked as a noise point;
[0030] When there is a cluster that includes at least two abnormal signals and the signal frequencies of the abnormal signals are at least two frequencies, determine the abnormal signals in this cluster as frequency hopping signals.
[0031] Further, when adjusting the initial risk coefficient according to the characteristics of the frequency hopping signal to determine the adjustment coefficient, it includes:
[0032] The characteristics of the frequency hopping signal include the total number of frequency hopping signals and the modulation method of each frequency hopping signal. The modulation methods include AM, FM, QPSK, and OFDM;
[0033] Compare the characteristics of the frequency hopping signal with the historical adjustment scheme, and determine the adjustment coefficient to adjust the initial risk coefficient according to the comparison result; the historical adjustment scheme includes the characteristics of several historical frequency hopping signals and several historical adjustment coefficients, and each characteristic of the historical frequency hopping signal corresponds to a historical adjustment coefficient;
[0034] Calculate the similarity between the characteristics of the frequency-hopping signal and the characteristics of each historical frequency-hopping signal;
[0035] When there is data in the characteristics of the historical frequency-hopping signal whose similarity to the characteristics of the frequency-hopping signal is greater than the similarity threshold, determine the historical adjustment coefficient as the adjustment coefficient according to the characteristics of the historical frequency-hopping signal corresponding to the maximum similarity, and adjust the initial risk coefficient;
[0036] When the similarity between the characteristics of the historical frequency-hopping signal and the characteristics of the frequency-hopping signal is less than or equal to the similarity threshold, determine the adjustment coefficient according to the total number of the frequency-hopping signals to adjust the initial risk coefficient.
[0037] Further, when determining the adjustment coefficient according to the total number of the frequency-hopping signals to adjust the initial risk coefficient, it includes:
[0038] The adjustment coefficient is in a direct proportional relationship with the total number of the frequency-hopping signals, and the value range of the adjustment coefficient is (1, 1.5].
[0039] Further, when adjusting the next detection and early warning period, it includes:
[0040] Obtain the adjusted risk coefficient, determine the period adjustment coefficient according to the risk coefficient to adjust the next detection and early warning period, the period adjustment coefficient is in an inverse proportional relationship with the adjusted risk coefficient, and the value range of the period adjustment coefficient is [0.5, 1).
[0041] Compared with the prior art, the beneficial effects of the present invention are as follows: By collecting historical anomaly-free data to establish a background database and dynamically determining the detection and early warning period based on real-time data, the adaptive adjustment of the detection threshold is realized, and high monitoring sensitivity can be maintained in different environments; By collecting radio signals in real time and calculating the average intensity as the detection and early warning threshold, environmental noise can be effectively filtered and the false alarm rate can be reduced; By combining the bandwidth and spectrum characteristics to analyze the suspected abnormal signals, identify the real abnormal signals, and calculate the initial risk coefficient according to the abnormal signal frequency, the preliminary assessment of the signal threat level is realized; By extracting the frequency, modulation mode and envelope shape characteristics of the abnormal signals, and using the clustering algorithm to analyze the feature vectors of all abnormal signals, the frequency-hopping signals can be effectively identified in a complex electromagnetic environment, and the accuracy of frequency-hopping signal detection is improved; By determining the adjustment coefficient according to the characteristics of the frequency-hopping signal, dynamically adjusting the risk coefficient and the detection and early warning period, the response strategy can be automatically adapted and adjusted when facing different intensities and types of radio threats, the early warning and effective prevention of malicious transmitting devices and potential information leakage risks are realized, and the automation and intelligence level of radio frequency band monitoring are enhanced.
[0042] On the other hand, the present application also provides a processing system for dealing with abnormal radio frequency bands, which is used to apply the above-mentioned processing method for dealing with abnormal radio frequency bands, and includes:
[0043] An acquisition unit, configured to acquire historical anomaly-free data to establish a background database, acquire a real-time data set, and determine a detection and early warning cycle according to the data volume of the real-time data set; acquire all radio signals within the detection and early warning cycle and obtain the average radio signal intensity, and use the average radio signal intensity as the detection and early warning threshold;
[0044] A judgment unit, configured to analyze the radio signals according to the detection and early warning threshold and the background database, judge whether there are suspected abnormal signals and mark them; when there are the suspected abnormal signals, obtain the bandwidth and spectral characteristics of each suspected abnormal signal, and judge whether the suspected abnormal signal is an abnormal signal according to the bandwidth and spectral characteristics. When it is determined that the suspected abnormal signal is an abnormal signal, determine the initial risk coefficient according to the abnormal signal frequency;
[0045] A processing unit, configured to extract the abnormal signals and identify the signal frequency, modulation mode and envelope shape, use the envelope shape as a feature vector, perform clustering analysis on all the abnormal signals based on a clustering algorithm, and judge whether there are frequency hopping signals according to the clustering result; when it is determined that there are frequency hopping signals, determine an adjustment coefficient according to the characteristics of the frequency hopping signals to adjust the initial risk coefficient, and adjust the next detection and early warning cycle;
[0046] An early warning unit, configured to give an early warning according to the adjusted risk coefficient and display the abnormal signals;
[0047] A storage unit, configured to store abnormal signal records.
[0048] It can be understood that the above-mentioned processing method and system for dealing with abnormal radio frequency bands have the same beneficial effects, which will not be elaborated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0049] By reading the detailed description of the preferred embodiments below, various other advantages and benefits will become clear to those of ordinary skill in the art. The drawings are only for the purpose of showing the preferred embodiments and are not considered to limit the present invention. Moreover, throughout the drawings, the same reference numerals are used to represent the same components. In the drawings:
[0050] Figure 1 is a flowchart of the processing method for dealing with abnormal radio frequency bands provided by an embodiment of the present invention;
[0051] Figure 2 is a functional block diagram of the processing system for dealing with abnormal radio frequency bands provided by an embodiment of the present invention;
[0052] Figure 3 It is a warning schematic diagram of the warning unit in the processing system for coping with radio frequency band anomalies provided by the embodiments of the present invention;
[0053] Figure 4 It is a storage schematic diagram of the storage unit in the processing system for coping with radio frequency band anomalies provided by the embodiments of the present invention;
[0054] Figure 5 It is a display content schematic diagram of the storage unit in the processing system for coping with radio frequency band anomalies provided by the embodiments of the present invention; Detailed implementation manners
[0055] Hereinafter, exemplary embodiments of the present disclosure will be described in more detail with reference to the accompanying drawings. Although the exemplary embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided so that the present disclosure can be more thoroughly understood and the scope of the present disclosure can be completely conveyed to those skilled in the art. It should be noted that, without conflict, the embodiments in the present invention and the features in the embodiments can be combined with each other. Hereinafter, the present invention will be described in detail with reference to the drawings and in conjunction with the embodiments.
[0056] In some embodiments of the present application, referring to Figure 1 as shown, a method for dealing with radio frequency band anomalies includes:
[0057] S100: Collect historical anomaly-free data to establish a background database, collect a real-time data set, and determine a detection and warning period according to the data volume of the real-time data set.
[0058] S200: Collect all radio signals within the detection and warning period and obtain the average radio signal intensity, use the average radio signal intensity as the detection and warning threshold, analyze the radio signals according to the detection and warning threshold and the background database, and determine whether there are suspected abnormal signals and mark them.
[0059] S300: When there are suspected abnormal signals, obtain the bandwidth and spectral characteristics of each suspected abnormal signal, judge whether the suspected abnormal signal is an abnormal signal according to the bandwidth and spectral characteristics, and when it is determined that the suspected abnormal signal is an abnormal signal, determine the initial risk coefficient according to the abnormal signal frequency.
[0060] S400: Extract abnormal signals and identify the signal frequency, modulation mode and envelope shape, use the envelope shape as a feature vector, perform clustering analysis on all abnormal signals based on a clustering algorithm, and judge whether there are frequency hopping signals according to the clustering results.
[0061] S500: When it is determined that there is a frequency-hopping signal, the adjustment coefficient is determined according to the characteristics of the frequency-hopping signal to adjust the initial risk coefficient, and the next detection and warning period is adjusted.
[0062] Specifically, the overall solution is to dynamically detect the changes in radio frequency band signals, combine signal feature analysis and clustering algorithms to achieve accurate identification of abnormal signals, especially frequency-hopping signals, and adjust the risk assessment and detection strategies of the system according to the characteristics of abnormal signals, so as to effectively respond to the security threats that may be brought by malicious transmitting devices. The establishment of the background database, signal anomaly detection, risk assessment, clustering analysis and frequency-hopping identification, and dynamic adjustment of the detection and warning period are realized in sequence to form a closed-loop intelligent monitoring system.
[0063] Specifically, in S100, the background database is established using the historical collected radio signal data without anomalies as the benchmark for judging whether the signal is abnormal. By analyzing the data volume of the real-time data set, the detection and warning period is dynamically adjusted according to parameters such as the data collection speed and the signal change frequency to achieve adaptive control of the signal monitoring frequency. The detection period is extended when the signal is stable, and the detection period is shortened when the signal is complex or changes frequently. In S200, all radio signals are collected within the detection and warning period, and the dynamic detection and warning threshold is set by calculating the average intensity of the signal, and the signal comparison and analysis are carried out in combination with the background database. When the signal intensity exceeds the threshold or the signal characteristics do not match the background database, the signal is marked as a suspected abnormal signal to achieve the preliminary screening function. In S300, the bandwidth and spectral characteristics (such as spectral peak value, signal morphology) of the suspected abnormal signal are obtained, and it is judged whether it is an abnormal signal by comparing the bandwidth and spectral characteristics of the normal signal in the background database. When the bandwidth does not match the normal signal or the spectral pattern shows an isolated peak value, it is determined as an abnormal signal. In S400, the characteristic information of the abnormal signal is extracted, including signal frequency, modulation method (such as ASK, FSK, QAM, etc.) and envelope shape. The envelope shape is used as the feature vector, and the clustering algorithm is used to perform clustering analysis on all abnormal signals. By calculating the similarity of the signal feature vectors, the abnormal signals that may come from the same signal source are aggregated into the same class. When the clustering result shows that the signals appearing in different frequency bands or at different times are clustered together and show the frequency-hopping feature, it can be judged that there is a frequency-hopping signal. Identify the situation where a malicious transmitting device covers its own behavior through frequency-hopping technology. In S500, after identifying the frequency-hopping signal, the adjustment coefficient is calculated to correct the initial risk coefficient. For example, the more frequency-hopping signals, the higher the risk coefficient. At the same time, the next detection and warning period is dynamically adjusted, increasing the monitoring frequency in a high-risk environment and reducing resource consumption in a low-risk environment.
[0064] It can be understood that by constructing a dynamic background database and an adaptive detection and early warning threshold, the intelligent screening of radio signals is achieved, effectively filtering out environmental noise, reducing the false alarm rate, and through the analysis of bandwidth and spectral characteristics, the accurate judgment of suspected abnormal signals is realized; the eigenvector analysis method based on the clustering algorithm breaks through the limitations of traditional manual monitoring of frequency hopping signals, can automatically identify frequency hopping signals with fast frequency changes and complex modulation methods, and improves the detection accuracy of frequency hopping signals; through the dual calculation mechanism of risk coefficient and adjustment coefficient, it has the ability to dynamically adjust the detection period, realizing the refined management of risk assessment; effectively coping with the potential security threats that may be brought by malicious emission devices, being able to maintain the high efficiency and stability of monitoring in a complex electromagnetic environment, reducing the work intensity and technical threshold of manual monitoring, and enhancing the intelligent level and security protection ability of radio frequency band monitoring.
[0065] In some embodiments of the present application, when determining the detection and early warning period according to the data volume of the real-time data set, it includes: comparing the data volume with a first preset data volume and a second preset data volume respectively, and determining the detection and early warning period according to the comparison result; the first preset data volume is less than the second preset data volume;
[0066] Specifically, when the data volume is less than or equal to the first preset data volume, the detection and early warning period is determined to be the first period; when the data volume is greater than the first preset data volume and less than or equal to the second preset data volume, the detection and early warning period is determined to be the second period; when the data volume is greater than the second preset data volume, the detection and early warning period is determined to be the third period; the first period is greater than the second period, and the second period is greater than the third period.
[0067] It can be understood that by setting multiple levels of data volume thresholds, the dynamic adaptive adjustment of the detection and early warning period is achieved, and the monitoring frequency can be automatically switched according to the complexity of the radio signal environment. When the signal environment is simple, the monitoring frequency is reduced to save resources; while when the signal environment is complex or there are potential security risks, the monitoring frequency is encrypted to quickly identify and locate abnormal signals. It effectively improves the monitoring efficiency and security in a complex electromagnetic environment, especially showing significant advantages in scenarios with frequent frequency hopping signals and diverse signal sources. This solution does not require manual intervention, is suitable for long-term unattended automated monitoring scenarios, reduces the monitoring cost, and improves the response speed.
[0068] In some embodiments of the present application, when analyzing radio signals according to the detection and early warning threshold and the background database to determine whether there are suspected abnormal signals and mark them, it includes:
[0069] Compare the signal frequencies of all radio signals with those in the background database, and compare the signal strength of each radio signal with the average signal strength of radio signals. Determine whether there are suspected abnormal signals based on the comparison results and mark them;
[0070] When the signal strength of a radio signal is greater than a times the average signal strength of radio signals, determine that the radio signal is a suspected abnormal signal and mark it;
[0071] When the signal frequency of a radio signal is not in the background database, determine that the radio signal is a suspected abnormal signal and mark it.
[0072] In some embodiments of the present application, when determining whether a suspected abnormal signal is an abnormal signal according to the bandwidth and spectral characteristics, it includes:
[0073] When the bandwidth of a suspected abnormal signal is different from the common bandwidth in the background database, determine the suspected abnormal signal as an abnormal signal;
[0074] The spectral characteristics include the spectral pattern. When the spectral pattern of a suspected abnormal signal shows isolated spectral peaks, determine that the suspected abnormal signal is an abnormal signal.
[0075] In some embodiments of the present application, when determining the initial risk coefficient according to the abnormal signal frequency, it includes:
[0076] ;
[0077] Wherein, R0 represents the initial risk coefficient, N represents the abnormal signal frequency, Wi represents the bandwidth of the i-th abnormal signal, and Wi0 represents the bandwidth in the background database closest to the bandwidth of the i-th abnormal signal.
[0078] It is understandable that common bandwidths in the background database, such as the bandwidth of Wi-Fi signals being 20 MHz or 40 MHz, and that of FM broadcast signals being 200 kHz. The abnormal signal frequency is the total number of all abnormal signals that appear. The parameter a is the intensity threshold coefficient, which can be dynamically set according to the environmental noise level and the historical signal fluctuation range. Preferably, a is [1.5 - 3]. Malicious devices usually adopt special transmission strategies for the purpose of concealment and evading monitoring, such as short-time high power, non-mainstream frequency bands, complex modulation methods, random intermittent transmission, etc. In this embodiment, a multi-dimensional comprehensive judgment mechanism is provided for detecting abnormal signals in the radio frequency band. Suspected abnormal signals are initially screened through signal intensity and frequency comparison, and then abnormal signals are further screened and confirmed through bandwidth and spectrum characteristics, improving the accuracy and reliability of detection. By dynamically calculating the initial risk coefficient, a quantitative risk assessment of abnormal signals is achieved, and the monitoring strategy can be flexibly adjusted according to the risk level. The bandwidth deviation calculation method used has better adaptability when dealing with complex and changeable signal environments, can quickly respond to potential security threats, especially in the case of frequency hopping signal detection and the appearance of high-frequency abnormal signals, can issue early warnings in a timely manner and increase the monitoring frequency, effectively preventing information security leakage.
[0079] In some embodiments of the present application, when performing clustering analysis on all abnormal signals based on a clustering algorithm and determining whether there is a frequency hopping signal according to the clustering result, it includes:
[0080] The envelope shape includes the number of peaks of the envelope curve and the amplitude change rate of the envelope curve;
[0081] Determine the initial neighborhood radius through the k-distance graph and determine MinPts to be 2;
[0082] Take the feature vector of each abnormal signal as a point, scan all points, and find the points whose number of points in the neighborhood is greater than or equal to MinPts as core points;
[0083] Starting from each core point, check the points in its neighborhood; if the points in the neighborhood are core points, continue to expand the cluster; if the points in the neighborhood are boundary points, add them to the current cluster; if a point is not in the neighborhood of any core point and cannot form a cluster with other points, it is marked as a noise point;
[0084] When there is a cluster that includes at least two abnormal signals and the signal frequencies of the abnormal signals are at least two frequencies, determine that the abnormal signals in this cluster are frequency hopping signals.
[0085] Specifically, in this embodiment, the signal frequency of the abnormal signal refers to the center frequency of the abnormal signal.
[0086] It can be understood that by combining the density clustering algorithm with the radio signal feature analysis, the efficient recognition of frequency-hopping signals is achieved. Different from the traditional spectrum scanning or fixed-frequency detection methods, the automatic classification of multi-band signals is realized through feature similarity clustering, which can effectively cope with the fast frequency change characteristics of frequency-hopping signals. By introducing the technical means of automatically determining the neighborhood radius through the k-distance graph, the clustering process has strong adaptability and can accurately separate frequency-hopping signals and noise signals in a complex electromagnetic environment. The accuracy of abnormal signal detection is improved.
[0087] In some embodiments of the present application, when adjusting the initial risk coefficient according to the characteristics of the frequency-hopping signal to determine the adjustment coefficient, it includes:
[0088] The characteristics of the frequency-hopping signal include the total number of frequency-hopping signals and the modulation method of each frequency-hopping signal, and the modulation methods include AM, FM, QPSK, and OFDM;
[0089] Compare the characteristics of the frequency-hopping signal with the historical adjustment scheme, and adjust the initial risk coefficient according to the comparison result to determine the adjustment coefficient; the historical adjustment scheme includes the characteristics of several historical frequency-hopping signals and several historical adjustment coefficients, and each characteristic of the historical frequency-hopping signal corresponds to a historical adjustment coefficient;
[0090] Calculate the similarity between the characteristics of the frequency-hopping signal and the characteristics of each historical frequency-hopping signal;
[0091] When there is data in the characteristics of the historical frequency-hopping signal whose similarity with the characteristics of the frequency-hopping signal is greater than the similarity threshold, determine the historical adjustment coefficient as the adjustment coefficient according to the characteristics of the historical frequency-hopping signal corresponding to the maximum similarity, and adjust the initial risk coefficient;
[0092] When the similarity between the characteristics of the historical frequency-hopping signal and the characteristics of the frequency-hopping signal is less than or equal to the similarity threshold, adjust the initial risk coefficient according to the total number of frequency-hopping signals to determine the adjustment coefficient.
[0093] In some embodiments of the present application, when adjusting the initial risk coefficient according to the total number of frequency-hopping signals to determine the adjustment coefficient, it includes: the adjustment coefficient is directly proportional to the total number of frequency-hopping signals, and the value range of the adjustment coefficient is (1, 1.5].
[0094] In some embodiments of the present application, when adjusting the next detection and early warning cycle, it includes: obtaining the adjusted risk coefficient, and adjusting the next detection and early warning cycle according to the risk coefficient to determine the cycle adjustment coefficient. The cycle adjustment coefficient is inversely proportional to the adjusted risk coefficient, and the value range of the cycle adjustment coefficient is [0.5, 1).
[0095] Specifically, when adjusting the initial risk coefficient according to the total number of frequency-hopping signals to determine the adjustment coefficient, the adjusted risk coefficient is the product of the initial risk coefficient and the adjustment coefficient. When adjusting the next detection and warning cycle, the next detection and warning cycle is the product of the current detection and warning cycle and the cycle adjustment coefficient. The characteristics of the frequency-hopping signals are matched using similarity calculation, and the risk coefficient is dynamically adjusted based on historical experience. When there is a lack of sufficient historical data, an adaptive calculation method based on the total number of frequency-hopping signals is provided, effectively avoiding the risk assessment blind spot caused by insufficient historical data. By introducing the inverse relationship between the adjusted risk coefficient and the detection and warning cycle into the control mechanism, the monitoring frequency can be automatically adjusted when the electromagnetic environment changes complexly, ensuring higher-frequency monitoring in a high-risk environment and saving resources in a low-risk situation, achieving a balance between detection efficiency and resource consumption.
[0096] In the above embodiments, a background database is established by collecting historical anomaly-free data, and the detection and warning cycle is dynamically determined based on real-time data, realizing the adaptive adjustment of the detection threshold and being able to maintain a high monitoring sensitivity in different environments; by collecting radio signals in real time and calculating the average intensity as the detection and warning threshold, environmental noise can be effectively filtered and the false alarm rate can be reduced; by combining the bandwidth and spectral characteristics to analyze suspected abnormal signals, identifying real abnormal signals, and calculating the initial risk coefficient based on the frequency of abnormal signals, a preliminary assessment of the threat level of the signals is realized; by extracting the frequency, modulation mode, and envelope shape characteristics of abnormal signals and using the clustering algorithm to analyze the feature vectors of all abnormal signals, frequency-hopping signals can be effectively identified in a complex electromagnetic environment, improving the accuracy of frequency-hopping signal detection; by determining the adjustment coefficient based on the characteristics of the frequency-hopping signals, dynamically adjusting the risk coefficient and the detection and warning cycle, and being able to automatically adapt and adjust the response strategy when facing different intensities and types of radio threats, early warning and effective prevention of malicious transmission devices and potential risks of information leakage are realized, enhancing the automation and intelligence level of radio frequency band monitoring.
[0097] In another preferred manner based on the above embodiments, refer to Figure 2 As shown, this embodiment provides a processing system for dealing with radio frequency band anomalies, which is used to apply the above-mentioned processing method for dealing with radio frequency band anomalies, including:
[0098] An acquisition unit, configured to collect historical anomaly-free data to establish a background database, collect a real-time data set, determine the detection and warning cycle according to the data volume of the real-time data set; collect all radio signals within the detection and warning cycle and obtain the average intensity of the radio signals, and use the average intensity of the radio signals as the detection and warning threshold;
[0099] A judgment unit, configured to analyze radio signals according to a detection warning threshold and a background database, judge whether there are suspected abnormal signals and mark them; when there are suspected abnormal signals, obtain the bandwidth and spectral characteristics of each suspected abnormal signal, and judge whether the suspected abnormal signal is an abnormal signal according to the bandwidth and spectral characteristics. When it is determined that the suspected abnormal signal is an abnormal signal, determine the initial risk coefficient according to the abnormal signal frequency;
[0100] A processing unit, configured to extract abnormal signals and identify the signal frequency, modulation mode, and envelope shape, use the envelope shape as a feature vector, perform clustering analysis on all abnormal signals based on a clustering algorithm, and judge whether there are frequency-hopping signals according to the clustering result; when it is determined that there are frequency-hopping signals, determine an adjustment coefficient according to the characteristics of the frequency-hopping signals to adjust the initial risk coefficient, and adjust the next detection warning period;
[0101] An early warning unit, configured to give an early warning according to the adjusted risk coefficient and display the abnormal signals;
[0102] A storage unit, configured to store abnormal signal records.
[0103] Specifically, refer to Figure 3 As shown, when the early warning unit gives an early warning, the signal list turns red and a sound alarm is issued.
[0104] Specifically, refer to Figure 4 As shown, when the storage unit stores abnormal signal records, it includes recording up / down conversion, level, peak frequency point, trigger event, etc., and for the abnormal signals that need to be focused on, it can be switched to the fixed-frequency monitoring mode, and the spectrogram and waterfall diagram can be seen in real time, and the audio can be listened to in real time; record complete spectral data, signal information, and audio and 2M bandwidth baseband IQ data. And refer to Figure 5 As shown, the recorded data can be played back completely. On the left side of the figure is the signal list triggered during the monitoring period; the upper right list in the figure represents the information corresponding to a continuously triggered signal; the lower right figure in the figure represents the relationship between the trigger time and frequency of all triggered signals during the monitoring period, where the vertical axis represents the trigger time and the horizontal axis represents the frequency of the triggered signal.
[0105] It is understandable that by collecting historical anomaly-free data to establish a background database and dynamically determining the detection and early warning cycle based on real-time data, the adaptive adjustment of the detection threshold is achieved, and a high monitoring sensitivity can be maintained in different environments; by collecting radio signals in real time and calculating the average intensity as the detection and early warning threshold, environmental noise can be effectively filtered and the false alarm rate can be reduced; by analyzing suspected abnormal signals in combination with bandwidth and spectral characteristics, real abnormal signals can be identified, and the initial risk coefficient can be calculated based on the frequency of abnormal signals, realizing a preliminary assessment of the threat level of signals; by extracting the frequency, modulation mode, and envelope shape characteristics of abnormal signals and analyzing the feature vectors of all abnormal signals using a clustering algorithm, frequency-hopping signals can be effectively identified in a complex electromagnetic environment, improving the accuracy of frequency-hopping signal detection; by determining the adjustment coefficient based on the characteristics of frequency-hopping signals, the risk coefficient and detection and early warning cycle are dynamically adjusted, enabling automatic adaptation and adjustment of response strategies when facing different intensities and types of radio threats, realizing early warning and effective prevention of malicious transmission devices and potential risks of information leakage and disclosure, and enhancing the automation and intelligence level of radio frequency band monitoring.
[0106] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0107] The present application is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or block in the flowchart and / or block diagram can be implemented by computer program instructions, and the combination of processes and / or blocks in the flowchart and / or block diagram can also be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for implementing the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.
[0108] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device, and the instruction device implements the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1The functions specified in one or more boxes.
[0109] These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process. Thus, the instructions executed on the computer or other programmable device provide for implementing the steps of the functions specified in one Figure 1 one process or more processes and / or boxes Figure 1 or more boxes.
[0110] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Although the present invention has been described in detail with reference to the above embodiments, those of ordinary skill in the art should understand that: the specific implementation manners of the present invention can still be modified or equivalently replaced, and any modification or equivalent replacement that does not depart from the spirit and scope of the present invention shall be covered by the protection scope of the claims of the present invention.
Claims
1. A method for dealing with radio frequency band anomalies, characterized in that, Including: Collect historical anomaly-free data to establish a background database, collect real-time data sets, and determine the detection and warning period according to the data volume of the real-time data sets; Collect all radio signals within the detection and warning period and obtain the average radio signal intensity. Use the average radio signal intensity as the detection and warning threshold, and analyze the radio signals according to the detection and warning threshold and the background database to determine whether there are suspected abnormal signals and mark them; When there are the suspected abnormal signals, obtain the bandwidth and spectral characteristics of each suspected abnormal signal, and determine whether the suspected abnormal signals are abnormal signals according to the bandwidth and spectral characteristics. When it is determined that the suspected abnormal signals are abnormal signals, determine the initial risk coefficient according to the abnormal signal frequency; Extract the abnormal signals and identify the signal frequency, modulation mode, and envelope shape. Use the envelope shape as a feature vector, and perform clustering analysis on all the abnormal signals based on a clustering algorithm. Determine whether there are frequency-hopping signals according to the clustering results; The envelope shape includes the number of peaks of the envelope curve and the amplitude change rate of the envelope curve; Determine the initial neighborhood radius through the k-distance graph and determine MinPts to be 2; Take the feature vector of each abnormal signal as a point, scan all points, and find the points with the number of points in the neighborhood greater than or equal to MinPts as core points; Starting from each core point, check the points in its neighborhood; if the points in the neighborhood are core points, continue to expand the cluster; if the points in the neighborhood are border points, add them to the current cluster; if a point is not in the neighborhood of any core point and cannot form a cluster with other points, it is marked as a noise point; When there is a cluster that includes at least two abnormal signals and the signal frequencies of the abnormal signals are at least two frequencies, determine the abnormal signals in the cluster as frequency-hopping signals; When it is determined that there are frequency-hopping signals, determine an adjustment coefficient according to the characteristics of the frequency-hopping signals to adjust the initial risk coefficient and adjust the next detection and warning period.
2. The processing method for coping with radio frequency band anomalies according to claim 1, characterized in that When determining the detection and warning period according to the data volume of the real-time data sets, it includes: Compare the data volume with a first preset data volume and a second preset data volume respectively, and determine the detection and warning period according to the comparison results; the first preset data volume is less than the second preset data volume; When the data volume is less than or equal to the first preset data volume, determine the detection and warning period as the first period; when the data volume is greater than the first preset data volume and less than or equal to the second preset data volume, determine the detection and warning period as the second period; when the data volume is greater than the second preset data volume, determine the detection and warning period as the third period; the first period is greater than the second period, and the second period is greater than the third period.
3. The method for handling radio frequency band anomalies according to claim 2, wherein When analyzing the radio signals according to the detection and warning threshold and the background database to determine whether there are suspected abnormal signals and mark them, it includes: Compare the signal frequencies of all the radio signals with those in the background database, and compare the signal strength of each radio signal with the average signal strength of the radio signals. Determine whether there are suspected abnormal signals according to the comparison results and mark them; When the signal strength of the radio signal is greater than a times the average signal strength of the radio signals, determine that the radio signal is a suspected abnormal signal and mark it; When the signal frequency of the radio signal is not in the background database, determine that the radio signal is a suspected abnormal signal and mark it.
4. The processing method for coping with abnormal radio frequency bands according to claim 3, wherein When determining whether the suspected abnormal signal is an abnormal signal according to the bandwidth and spectral characteristics, it includes: When the bandwidth of the suspected abnormal signal is different from the common bandwidth in the background database, determine that the suspected abnormal signal is an abnormal signal; The spectral characteristics include the shape of the spectrogram. When the spectrogram of the suspected abnormal signal shows isolated spectral peaks, determine that the suspected abnormal signal is an abnormal signal.
5. The method for handling radio frequency band anomalies according to claim 4, wherein When determining the initial risk coefficient according to the frequency of abnormal signals, it includes: ; Among them, R0 represents the initial risk coefficient, N represents the frequency of abnormal signals, Wi represents the bandwidth of the i-th abnormal signal, and Wi0 represents the bandwidth in the background database closest to the bandwidth of the i-th abnormal signal.
6. The processing method for coping with radio frequency band anomalies according to claim 5, wherein, When determining the adjustment coefficient according to the characteristics of the frequency hopping signal to adjust the initial risk coefficient, it includes: The characteristics of the frequency hopping signal include the total number of frequency hopping signals and the modulation method of each frequency hopping signal. The modulation methods include AM, FM, QPSK, and OFDM; Compare the characteristics of the frequency hopping signal with the historical adjustment scheme, and determine the adjustment coefficient according to the comparison results to adjust the initial risk coefficient; the historical adjustment scheme includes the characteristics of several historical frequency hopping signals and several historical adjustment coefficients, and each characteristic of the historical frequency hopping signal corresponds to a historical adjustment coefficient; Calculate the similarity between the characteristics of the frequency hopping signal and the characteristics of each historical frequency hopping signal; When there is data in the characteristics of the historical frequency hopping signal whose similarity with the characteristics of the frequency hopping signal is greater than the similarity threshold, determine the historical adjustment coefficient corresponding to the maximum similarity as the adjustment coefficient to adjust the initial risk coefficient; When the similarity between the characteristics of the historical frequency hopping signal and the characteristics of the frequency hopping signal is less than or equal to the similarity threshold, determine the adjustment coefficient according to the total number of the frequency hopping signals to adjust the initial risk coefficient.
7. The processing method for coping with radio frequency band anomalies according to claim 6, wherein When determining the adjustment coefficient according to the total number of the frequency hopping signals to adjust the initial risk coefficient, it includes: The adjustment coefficient is in a direct proportional relationship with the total number of the frequency hopping signals, and the value range of the adjustment coefficient is (1, 1.5].
8. The processing method for coping with radio frequency band anomalies according to claim 7, characterized in that When adjusting the next detection and warning period, it includes: Obtain the adjusted risk coefficient, and determine the period adjustment coefficient according to the risk coefficient to adjust the next detection and warning period. The period adjustment coefficient is in an inverse proportional relationship with the adjusted risk coefficient, and the value range of the period adjustment coefficient is [0.5, 1).
9. A processing system for dealing with radio frequency band anomalies, which is used to apply the processing method for dealing with radio frequency band anomalies according to any one of claims 1-8, characterized in that, It includes: The acquisition unit is configured to acquire historical anomaly-free data to establish a background database, acquire a real-time data set, and determine a detection and early warning period according to the data volume of the real-time data set; Acquire all radio signals within the detection and early warning period and obtain the average radio signal intensity, and use the average radio signal intensity as the detection and early warning threshold; The judgment unit is configured to analyze the radio signals according to the detection and early warning threshold and the background database, judge whether there are suspected abnormal signals and mark them; when there are the suspected abnormal signals, obtain the bandwidth and spectral characteristics of each suspected abnormal signal, and judge whether the suspected abnormal signal is an abnormal signal according to the bandwidth and spectral characteristics. When it is determined that the suspected abnormal signal is an abnormal signal, determine the initial risk coefficient according to the abnormal signal frequency; The processing unit is configured to extract the abnormal signals and identify the signal frequency, modulation mode and envelope shape, use the envelope shape as a feature vector, perform clustering analysis on all the abnormal signals based on a clustering algorithm, and judge whether there are frequency hopping signals according to the clustering result; When it is determined that there are frequency hopping signals, determine an adjustment coefficient according to the characteristics of the frequency hopping signals to adjust the initial risk coefficient, and adjust the next detection and early warning period; The early warning unit is configured to give an early warning according to the adjusted risk coefficient and display the abnormal signals; The storage unit is configured to store abnormal signal records.
Citation Information
Patent Citations
Real-time acquisition and detection method and system for frequency hopping signals
CN117560037A
Frequency hopping signal detection method based on discontinuous spectrum data
CN118264275A