PFCP signaling anomaly detection method based on two-stage deep learning

Through a two-stage deep learning method of packet analysis, feature extraction and bidirectional session stream aggregation of PFCP signaling traffic, the limitations of 5G signaling detection in the prior art are solved, and the accuracy and pertinence of PFCP signaling abnormal detection are improved.

CN119997025APending Publication Date: 2025-05-13BEIJING UNIV OF POSTS & TELECOMM
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510236391.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-28
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

The existing Internet abnormal traffic detection methods lack the characteristic targeted for 5G signaling, and it is difficult to effectively detect abnormal PFCP signaling, resulting in low accuracy of detection results.

Method used

Using a two-stage deep learning method, PFCP signaling traffic is used to parse, feature extraction and bidirectional session stream aggregation. Through unsupervised training and supervised classification, the target encoder and classifier are obtained to realize abnormal detection of PFCP signaling.

Benefits of technology

The accuracy of PFCP signaling abnormal detection is improved, the limitations of the Internet abnormal traffic detection scheme are reduced, and targeted extraction of PFCP signaling content features is realized.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119997025A_ABST
    Figure CN119997025A_ABST
Patent Text Reader

Abstract

The invention provides a PFCP signaling anomaly detection method based on two-stage deep learning, and the method comprises the steps: carrying out the original package analysis of a first PFCP signaling flow, obtaining an analysis data package of the first PFCP signaling flow, carrying out the bidirectional session flow aggregation of the analysis data package, obtaining a bidirectional session flow corresponding to the analysis data package, and carrying out the detection of the PFCP signaling anomaly. Performing feature extraction on the bidirectional session flow to obtain a corresponding first basic statistical feature and a first PFCP signaling content feature, determining label flow data based on the first basic statistical feature and the first PFCP signaling content feature, and performing unsupervised training based on the label flow data to obtain a target encoder, and performing supervised classification under a target classification type based on the label traffic data to obtain a target classifier, obtaining an original second PFCP signaling traffic, classifying the second PFCP signaling traffic based on the target encoder and the target classifier, and obtaining a classification result of classifying the PFCP traffic.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of communication technology, and in particular to a PFCP signaling anomaly detection method based on two-stage deep learning. Background Art

[0002] With the development of 5G networks, its security risks have received more and more attention. As the interface between the user plane function (UPF) and the control plane function (SMF), the N4 interface is mainly responsible for user plane data transmission, session management, QoS (quality of service) management, etc. It faces security risks such as Dos attacks, session hijacking, and data leakage. PFCP is the application layer protocol of the N4 interface. Performing traffic detection on it is a security solution to protect the security of the N4 interface. In 5G, it involves traffic detection of 5G.

[0003] At present, there are fewer 5G traffic detection solutions than traditional abnormal traffic detection solutions. Therefore, the research on 5G traffic detection is inseparable from the Internet traffic detection solution. The traditional Internet abnormal traffic detection methods are roughly divided into four categories, namely, anomaly detection based on statistical analysis, anomaly detection based on classification, anomaly detection based on clustering, and anomaly detection based on information theory. The 5G traffic detection solutions proposed by the academic community are mostly based on the HTTP / 2 signaling protocol for detection.

[0004] However, the existing Internet abnormal traffic detection methods lack the characteristics of 5G signaling, so it is difficult to carry out targeted processing, resulting in certain limitations in the existing Internet abnormal traffic detection solutions. In addition, the 5G traffic detection solutions proposed by the academic community lack the detection of PFCP abnormal signaling. Even if it involves the detection of PFCP abnormal signaling, it lacks targeted feature extraction of PFCP signaling content, resulting in the general accuracy of the abnormal detection results. Summary of the invention

[0005] In view of this, the purpose of the present application is to provide a PFCP signaling anomaly detection method based on two-stage deep learning, by performing original packet parsing, feature extraction, two-way session flow aggregation and other processing on the first PFCP signaling traffic to obtain the first basic statistical characteristics and the first PFCP signaling content characteristics of the first PFCP signaling traffic, and performing two-stage unsupervised training and supervised classification on the first basic statistical characteristics and the first PFCP signaling content characteristics to obtain the trained target encoder and target classifier, and finally performing anomaly detection on the PFCP signaling traffic through the target encoder and the target classifier, which can perform targeted processing on 5G signaling, reducing the limitations of the Internet abnormal traffic detection scheme, and at the same time, realizing anomaly detection of PFCP signaling and targeted extraction of PFCP signaling content features, thereby improving the training effect and thus improving the accuracy of the results of PFCP signaling anomaly detection.

[0006] In a first aspect, an embodiment of the present application provides a PFCP signaling anomaly detection method based on two-stage deep learning, the method comprising:

[0007] Acquire the original first PFCP signaling traffic, and perform original packet parsing on the first PFCP signaling traffic to obtain a parsed data packet of the first PFCP signaling traffic;

[0008] Performing bidirectional conversation flow aggregation on the parsed data packet to obtain a bidirectional conversation flow corresponding to the parsed data packet, and performing feature extraction on the bidirectional conversation flow to obtain a corresponding first basic statistical feature and a first PFCP signaling content feature; wherein each parsed data packet corresponds to a bidirectional conversation flow;

[0009] Determine label traffic data based on the first basic statistical feature and the first PFCP signaling content feature, perform unsupervised training based on the label traffic data to obtain a target encoder, and perform supervised classification under a target classification type based on the label traffic data to obtain a target classifier;

[0010] Obtain the original second PFCP signaling traffic, classify the second PFCP signaling traffic based on the target encoder and the target classifier, and obtain a classification result for classifying the PFCP traffic; wherein the classification result represents the abnormality detection result of the second PFCP signaling traffic; the classification result corresponds to the target classification type.

[0011] In a possible implementation manner, performing original packet parsing on the first PFCP signaling traffic to obtain a parsed data packet of the first PFCP signaling traffic includes:

[0012] Parsing the first PFCP signaling traffic at the Mac layer to obtain corresponding timestamp information;

[0013] Parsing the first PFCP signaling traffic at the IP layer to obtain corresponding source IP and destination IP;

[0014] Parsing the first PFCP signaling traffic at the transport layer to obtain corresponding source Port and destination Port;

[0015] Parsing the first PFCP signaling traffic at the application layer to obtain corresponding PFCP signaling information;

[0016] Determine the corresponding parsed data packet based on the timestamp information, the source IP, the destination IP, the source Port, the destination Port and the PFCP signaling information; wherein the source IP and the destination IP represent IP information, and the source Port and the destination Port represent Port information.

[0017] In a possible implementation, the method further includes:

[0018] In response to determining that the first PFCP signaling traffic is a session-related process based on the PFCP signaling information, extracting a user permanent equipment identifier of the first PFCP signaling traffic;

[0019] In response to determining that the first PFCP signaling traffic is a response message based on the PFCP signaling information, extracting a response code of the first PFCP signaling traffic; wherein the response code represents the number of response successes or failures;

[0020] Determine a corresponding first parsed data packet based on the user permanent device identifier, the response code, the timestamp information, the source IP, the destination IP, the source Port, the destination Port and the PFCP signaling information.

[0021] In a possible implementation, the labeled traffic data includes labeled traffic data and unlabeled traffic data; the determining of the labeled traffic data based on the first basic statistical feature and the first PFCP signaling content feature, performing unsupervised training based on the labeled traffic data to obtain a target encoder, and performing supervised classification under a target classification type based on the labeled traffic data to obtain a target classifier includes:

[0022] Determine labeled traffic data and unlabeled traffic data based on the first basic statistical feature and the first PFCP signaling content feature, put the labeled traffic data and the unlabeled traffic data into an autoencoder for unsupervised training and feature dimension reduction, and obtain a target encoder;

[0023] The labeled traffic data is input into a preset CNN-based classifier through the target encoder to perform supervised classification under the target classification type, and a target classifier for classifying PFCP traffic is obtained; wherein the target classification types include binary classification and multi-classification.

[0024] In a possible implementation manner, the classifying the second PFCP signaling traffic based on the target encoder and the target classifier to obtain a classification result for classifying the PFCP traffic includes:

[0025] Similarly, after performing packet parsing, bidirectional flow aggregation, and feature extraction on the second PFCP signaling traffic, the corresponding second basic statistical features to be detected and the second PFCP signaling content features are obtained;

[0026] The second basic statistical feature and the second PFCP signaling content feature are input into the target encoder, and the output data of the target encoder is input into the target classifier to obtain a classification result for classifying the PFCP traffic; wherein each bidirectional conversation flow corresponds to a classification result.

[0027] In a possible implementation, the performing bidirectional conversation flow aggregation on the parsed data packet to obtain the bidirectional conversation flow corresponding to the parsed data packet includes:

[0028] Determine an interception time of the intercepted session flow based on the timestamp information, and determine a corresponding session based on the IP information and the Port information;

[0029] The session is intercepted based on the interception time to obtain a corresponding session flow, and the session flow is aggregated to obtain a bidirectional session flow corresponding to the parsed data packet.

[0030] In a possible implementation manner, the obtaining the original first PFCP signaling traffic includes:

[0031] Get basic 5G special data sets;

[0032] The basic 5G special data set is processed to obtain a corresponding target 5G special data set, and the original first PFCP signaling flow is determined based on the target 5G special data set.

[0033] In a second aspect, an embodiment of the present application further provides a PFCP signaling anomaly detection device based on two-stage deep learning, the device comprising:

[0034] A parsing module, used for acquiring an original first PFCP signaling flow, and performing original packet parsing on the first PFCP signaling flow to obtain a parsed data packet of the first PFCP signaling flow;

[0035] A first extraction module is used to perform bidirectional conversation flow aggregation on the parsed data packet to obtain a bidirectional conversation flow corresponding to the parsed data packet, and perform feature extraction on the bidirectional conversation flow to obtain a corresponding first basic statistical feature and a first PFCP signaling content feature; wherein each parsed data packet corresponds to a bidirectional conversation flow;

[0036] A training module, used for determining label traffic data based on the first basic statistical feature and the first PFCP signaling content feature, performing unsupervised training based on the label traffic data to obtain a target encoder, and performing supervised classification under a target classification type based on the label traffic data to obtain a target classifier;

[0037] A detection module is used to obtain the original second PFCP signaling traffic, classify the second PFCP signaling traffic based on the target encoder and the target classifier, and obtain a classification result for classifying the PFCP traffic; wherein the classification result represents the abnormal detection result of the second PFCP signaling traffic; the classification result corresponds to the target classification type.

[0038] In a possible implementation, the parsing module is specifically used to:

[0039] Parsing the first PFCP signaling traffic at the Mac layer to obtain corresponding timestamp information;

[0040] Parsing the first PFCP signaling traffic at the IP layer to obtain corresponding source IP and destination IP;

[0041] Parsing the first PFCP signaling traffic at the transport layer to obtain corresponding source Port and destination Port;

[0042] Parsing the first PFCP signaling traffic at the application layer to obtain corresponding PFCP signaling information;

[0043] Determine the corresponding parsed data packet based on the timestamp information, the source IP, the destination IP, the source Port, the destination Port and the PFCP signaling information; wherein the source IP and the destination IP represent IP information, and the source Port and the destination Port represent Port information.

[0044] In a possible implementation, the PFCP signaling anomaly detection device based on two-stage deep learning further includes:

[0045] a second extraction module, configured to extract a user permanent equipment identifier of the first PFCP signaling traffic in response to determining that the first PFCP signaling traffic is a session-related process based on the PFCP signaling information;

[0046] The third extraction module is used to extract the response code of the first PFCP signaling traffic in response to determining that the first PFCP signaling traffic is a response message based on the PFCP signaling information; wherein the response code represents the number of response successes or failures.

[0047] In a possible implementation manner, the labeled traffic data includes labeled traffic data and unlabeled traffic data; and the training module is specifically used to:

[0048] Determine labeled traffic data and unlabeled traffic data based on the first basic statistical feature and the first PFCP signaling content feature, put the labeled traffic data and the unlabeled traffic data into an autoencoder for unsupervised training and feature dimension reduction, and obtain a target encoder;

[0049] The labeled traffic data is input into a preset CNN-based classifier through the target encoder to perform supervised classification under the target classification type, and a target classifier for classifying PFCP traffic is obtained; wherein the target classification types include binary classification and multi-classification.

[0050] In a possible implementation manner, the detection module is specifically used to:

[0051] Similarly, after performing packet parsing, bidirectional flow aggregation, and feature extraction on the second PFCP signaling traffic, the corresponding second basic statistical features to be detected and the second PFCP signaling content features are obtained;

[0052] The second basic statistical feature and the second PFCP signaling content feature are input into the target encoder, and the output data of the target encoder is input into the target classifier to obtain a classification result for classifying the PFCP traffic; wherein each bidirectional conversation flow corresponds to a classification result.

[0053] In a possible implementation manner, the first extraction module is specifically configured to:

[0054] Determine an interception time of the intercepted session flow based on the timestamp information, and determine a corresponding session based on the IP information and the Port information;

[0055] The session is intercepted based on the interception time to obtain a corresponding session flow, and the session flow is aggregated to obtain a bidirectional session flow corresponding to the parsed data packet.

[0056] In a possible implementation, the parsing module is specifically used to:

[0057] Get basic 5G special data sets;

[0058] The basic 5G special data set is processed to obtain a corresponding target 5G special data set, and the original first PFCP signaling flow is determined based on the target 5G special data set.

[0059] In a third aspect, an embodiment of the present application provides an electronic device, comprising: a processor, a storage medium and a bus, wherein the storage medium stores machine-readable instructions executable by the processor, and when the electronic device is running, the processor communicates with the storage medium through the bus, and the processor executes the machine-readable instructions to perform the steps of the PFCP signaling anomaly detection method based on two-stage deep learning as described in any one of the first aspects.

[0060] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the PFCP signaling anomaly detection method based on two-stage deep learning as described in any one of the first aspects are executed.

[0061] The embodiment of the present application provides a PFCP signaling anomaly detection method based on two-stage deep learning, which obtains the original first PFCP signaling traffic, and performs original packet parsing on the first PFCP signaling traffic to obtain the parsed data packet of the first PFCP signaling traffic; performs bidirectional conversation flow aggregation on the parsed data packet to obtain the bidirectional conversation flow corresponding to the parsed data packet, and performs feature extraction on the bidirectional conversation flow to obtain the corresponding first basic statistical feature and the first PFCP signaling content feature; determines the label traffic data based on the first basic statistical feature and the first PFCP signaling content feature, and performs unsupervised training based on the label traffic data to obtain a target encoder, and performs supervised classification under the target classification type based on the label traffic data to obtain a target classifier; obtains the original second PFCP signaling traffic, classifies the second PFCP signaling traffic based on the target encoder and the target classifier, and obtains a classification result for classifying the PFCP traffic. In the present application, the first PFCP signaling traffic is subjected to original packet parsing, feature extraction, two-way conversation flow aggregation and other processing to obtain the first basic statistical feature and the first PFCP signaling content feature, and the first basic statistical feature and the first PFCP signaling content feature are subjected to two-stage unsupervised training and supervised classification to obtain the trained target encoder and target classifier, and finally the PFCP signaling traffic is subjected to anomaly detection through the target encoder and the target classifier, so that the 5G signaling can be processed in a targeted manner, thereby reducing the limitations of the Internet abnormal traffic detection scheme, and at the same time, anomaly detection of PFCP signaling and targeted extraction of PFCP signaling content features are realized, thereby improving the training effect and thus improving the accuracy of the results of PFCP signaling anomaly detection.

[0062] In order to make the above-mentioned objects, features and advantages of the present application more obvious and easy to understand, preferred embodiments are specifically cited below and described in detail with reference to the attached drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0063] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for use in the embodiments will be briefly introduced below. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying creative work.

[0064] Figure 1 It is a flowchart of a PFCP signaling anomaly detection method based on two-stage deep learning provided in an embodiment of the present application;

[0065] Figure 2 It is a schematic diagram of the training process of PFCP abnormal signaling detection based on two-stage deep learning;

[0066] Figure 3 It is a schematic diagram of the detection process of PFCP abnormal signaling detection based on two-stage deep learning;

[0067] Figure 4 It is a structural diagram of a PFCP signaling anomaly detection device based on two-stage deep learning provided according to an embodiment of the present application;

[0068] Figure 5 It is a structural schematic diagram of an electronic device provided according to an embodiment of the present application. DETAILED DESCRIPTION

[0069] To make the purpose, technical scheme and advantages of the embodiments of the present application clearer, the technical scheme in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. It should be understood that the drawings in the present application only serve the purpose of explanation and description and are not used to limit the scope of protection of the present application. In addition, it should be understood that the schematic drawings are not drawn in real proportion. The flowchart used in this application shows the operations implemented according to some embodiments of the present application. It should be understood that the operations of the flowchart can be implemented out of sequence, and the steps without logical context can be reversed in order or implemented simultaneously. In addition, those skilled in the art can add one or more other operations to the flowchart under the guidance of the content of the present application, or remove one or more operations from the flowchart.

[0070] In addition, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. The components of the embodiments of the present application described and shown in the drawings here can be arranged and designed in various configurations. Therefore, the following detailed description of the embodiments of the present application provided in the drawings is not intended to limit the scope of the application claimed for protection, but merely represents the selected embodiments of the present application. Based on the embodiments of the present application, all other embodiments obtained by those skilled in the art without making creative work belong to the scope of protection of the present application.

[0071] It should be noted that the term "comprising" will be used in the embodiments of the present application to indicate the existence of the features declared thereafter, but does not exclude the addition of other features.

[0072] Considering that with the development of 5G networks, its security risks have received more and more attention, the N4 interface, as the interface between the user plane function (UPF) and the control plane function (SMF), is mainly responsible for user plane data transmission, session management, QoS (quality of service) management, etc. It faces security risks such as Dos attacks, session hijacking, and data leakage. PFCP is the application layer protocol of the N4 interface. Performing traffic detection on it is a security solution to protect the security of the N4 interface. In 5G, it involves traffic detection of 5G.

[0073] At present, there are fewer 5G traffic detection solutions than traditional abnormal traffic detection solutions. Therefore, the research on 5G traffic detection is inseparable from the Internet traffic detection solution. The traditional Internet abnormal traffic detection methods are roughly divided into four categories, namely, anomaly detection based on statistical analysis, anomaly detection based on classification, anomaly detection based on clustering, and anomaly detection based on information theory. The 5G traffic detection solutions proposed by the academic community are mostly based on the HTTP / 2 signaling protocol for detection.

[0074] However, the existing Internet abnormal traffic detection methods lack the characteristics of 5G signaling, so it is difficult to carry out targeted processing, resulting in certain limitations in the existing Internet abnormal traffic detection solutions. In addition, the 5G traffic detection solutions proposed by the academic community lack the detection of PFCP abnormal signaling. Even if it involves the detection of PFCP abnormal signaling, it lacks targeted feature extraction of PFCP signaling content, resulting in the general accuracy of the abnormal detection results.

[0075] To address this problem, the present application provides a PFCP signaling anomaly detection method based on two-stage deep learning, which obtains the first basic statistical characteristics and the first PFCP signaling content characteristics of the first PFCP signaling traffic by performing original packet parsing, feature extraction, and two-way session flow aggregation on the first PFCP signaling traffic, and obtains the trained target encoder and target classifier by performing two-stage unsupervised training and supervised classification on the first basic statistical characteristics and the first PFCP signaling content characteristics. Finally, the PFCP signaling traffic is detected for anomalies through the target encoder and the target classifier, which can perform targeted processing on 5G signaling, reducing the limitations of the Internet abnormal traffic detection scheme. At the same time, it realizes anomaly detection of PFCP signaling and targeted extraction of PFCP signaling content characteristics, improves the training effect, and thus improves the accuracy of the results of PFCP signaling anomaly detection.

[0076] Figure 1 1 is a flow chart of a PFCP signaling anomaly detection method based on two-stage deep learning according to an embodiment of the present application. Figure 1 As shown, the PFCP signaling anomaly detection method based on two-stage deep learning in the embodiment of the present application may specifically include:

[0077] S101. Acquire original first PFCP signaling traffic, and perform original packet parsing on the first PFCP signaling traffic to obtain parsed data packets of the first PFCP signaling traffic.

[0078] S102: Perform bidirectional conversation flow aggregation on the parsed data packet to obtain a bidirectional conversation flow corresponding to the parsed data packet, and perform feature extraction on the bidirectional conversation flow to obtain a corresponding first basic statistical feature and a first PFCP signaling content feature.

[0079] S103. Determine the label traffic data based on the first basic statistical feature and the first PFCP signaling content feature, perform unsupervised training based on the label traffic data to obtain a target encoder, and perform supervised classification under a target classification type based on the label traffic data to obtain a target classifier.

[0080] S104: Acquire the original second PFCP signaling traffic, classify the second PFCP signaling traffic based on the target encoder and the target classifier, and obtain a classification result of classifying the PFCP traffic.

[0081] In the above-mentioned PFCP signaling anomaly detection method based on two-stage deep learning, the first PFCP signaling traffic is subjected to original packet parsing, feature extraction, two-way session flow aggregation and other processing to obtain the first basic statistical characteristics and the first PFCP signaling content characteristics. The first basic statistical characteristics and the first PFCP signaling content characteristics are subjected to two-stage unsupervised training and supervised classification to obtain the trained target encoder and target classifier. Finally, the PFCP signaling traffic is subjected to anomaly detection through the target encoder and the target classifier, which can perform targeted processing on 5G signaling, reduce the limitations of the Internet abnormal traffic detection scheme, and at the same time, realize anomaly detection of PFCP signaling and targeted extraction of PFCP signaling content characteristics, improve the training effect, and thus improve the accuracy of the results of PFCP signaling anomaly detection.

[0082] The above exemplary steps of the embodiment of the present application are described below with reference to specific examples:

[0083] S101, obtaining original first PFCP signaling traffic, and performing original packet parsing on the first PFCP signaling traffic to obtain parsed data packets of the first PFCP signaling traffic.

[0084] In the embodiment of the present application, PFCP signaling is a 5G signaling, the first PFCP signaling flow is the original PFCP signaling flow, the first PFCP signaling flow represents a 5G special data set, the parsed data packet is the data packet obtained after the original packet parsing of the first PFCP signaling flow, the original packet parsing of the obtained original first PFCP signaling flow is performed to obtain the parsed data packet of the first PFCP signaling flow for subsequent processing. For example, Figure 2 As shown, after the original data traffic, ie, the first PFCP signaling traffic, is acquired, PFCP traffic parsing is performed.

[0085] It will be understood by those skilled in the art that the original PFCP signaling traffic can be obtained by monitoring the traffic of the corresponding data port and capturing packets.

[0086] Optionally, original packet parsing is performed on the first PFCP signaling traffic at the Mac layer, IP layer, transport layer and application layer respectively.

[0087] Optionally, when obtaining the original first PFCP signaling traffic, a basic 5G special data set is obtained; the basic 5G special data set is processed to obtain a corresponding target 5G special data set, and the original first PFCP signaling traffic is determined based on the target 5G special data set. For example, the basic 5G special data set is processed by data enhancement and the corresponding target 5G special data set is obtained.

[0088] Therefore, this application realizes the use of 5G special data sets and reduces the limitations of abnormal traffic detection.

[0089] Optionally, when performing original packet parsing on the first PFCP signaling traffic to obtain the parsed data packet of the first PFCP signaling traffic, the first PFCP signaling traffic is parsed at the Mac layer to obtain the corresponding timestamp information; the first PFCP signaling traffic is parsed at the IP layer to obtain the corresponding source IP and destination IP; the first PFCP signaling traffic is parsed at the transport layer to obtain the corresponding source Port and destination Port; the first PFCP signaling traffic is parsed at the application layer to obtain the corresponding PFCP signaling information; the corresponding parsed data packet is determined based on the timestamp information, source IP, destination IP, source Port, destination Port and PFCP signaling information. Among them, the PFCP signaling information includes at least the message type and the message length; the source IP and the destination IP represent the IP information, and the source Port and the destination Port represent the Port information.

[0090] To continue, in response to determining that the first PFCP signaling flow is a session-related process based on the PFCP signaling information, the subscriber permanent equipment identifier (SEID) of the first PFCP signaling flow is extracted; in response to determining that the first PFCP signaling flow is a response message based on the PFCP signaling information, the response code of the first PFCP signaling flow is extracted; based on the user permanent equipment identifier SEID, the response code, the timestamp information, the source IP, the destination IP, the source port, the destination port and the PFCP signaling information, the corresponding first parsed data packet is determined. Among them, the response code represents the number of times the response succeeds or fails.

[0091] Specifically, the original packet parsing of the PFCP signaling traffic includes: parsing the timestamp information at the Mac layer; extracting the source IP and destination IP at the IP layer; parsing the source Port and destination Port at the transport layer, where the data packet parsing at the IP layer and the transport layer can be used for flow feature extraction; parsing the PFCP signaling information at the application layer, focusing on the message type and message length. If the signaling is a session-related process, the SEID is extracted. If it is a response message, the response success or failure code, that is, the number of response successes or failures, is extracted.

[0092] S102, performing bidirectional conversation flow aggregation on the parsed data packet to obtain a bidirectional conversation flow corresponding to the parsed data packet, and performing feature extraction on the bidirectional conversation flow to obtain a corresponding first basic statistical feature and a first PFCP signaling content feature.

[0093] In the embodiment of the present application, each parsed data packet corresponds to a two-way conversation flow, and the basic statistical features and PFCP signaling content features belong to the traffic features of the PFCP signaling traffic. The basic statistical features at least include the number of packets, packet flow rate, byte flow rate, maximum packet length, average packet length, maximum time interval, and average time interval; the PFCP signaling content features at least include the number of packets of each type of PFCP data packet and the packet frequency; the parsed data packet obtained in step S101 is subjected to two-way conversation flow aggregation to obtain the two-way conversation flow corresponding to the parsed data packet, and the feature extraction of the two-way conversation flow is performed to obtain the first basic statistical features and the first PFCP signaling content features for subsequent processing. For example, Figure 2 As shown, after PFCP traffic parsing, PFCP bidirectional flow aggregation and feature extraction are performed in sequence.

[0094] Specifically, feature extraction is performed on each aggregated two-way conversation flow, including two aspects: one is basic statistical features, and the other is PFCP signaling content features. Statistical features include the number of packets, packet flow rate, byte flow rate, maximum packet length, average packet length, maximum time interval, and average time interval. Each statistical feature is based on the two-way flow dimension and the total dimension; signaling content statistical feature extraction includes the number of packets of each data packet type of PFCP, packet frequency, number of SEIDs, etc.

[0095] Optionally, the PFCP signaling content feature of the SEID number is extracted based on the parsed user permanent equipment identifier SEID.

[0096] S103, determining the label traffic data based on the first basic statistical feature and the first PFCP signaling content feature, performing unsupervised training based on the label traffic data to obtain a target encoder, and performing supervised classification under a target classification type based on the label traffic data to obtain a target classifier.

[0097] In an embodiment of the present application, the target classification types include at least binary classification and multi-classification. The label traffic data is determined based on the first basic statistical features extracted in step S102 and the first PFCP signaling content features. Unsupervised training is performed based on the label traffic data to obtain a target encoder. Supervised classification under the target classification type is performed based on the label traffic data to obtain a target classifier, thereby obtaining a trained target encoder and target classifier for subsequent processing.

[0098] Among them, the target classification types include binary classification and multi-classification; binary classification means normal and abnormal classification, and multi-classification can represent not only normal and abnormal, but also abnormal types. The specific classification types depend on the needs. It can be added here that if the 0day detection capability of the model needs to be improved, the target classifier can be trained using binary classification.

[0099] It should be noted that the target classifier is a classifier based on a convolutional neural network, namely, a CNN classifier, and the target decoder is an encoder that can perform feature dimensionality reduction.

[0100] Among them, the labeled traffic data includes labeled traffic data (normal traffic data) and unlabeled traffic data (abnormal traffic data). Based on all the features extracted from the first basic statistical feature and the first PFCP signaling content feature, it is determined whether there is a label to obtain labeled traffic data and unlabeled traffic data.

[0101] In some embodiments, labeled traffic data and unlabeled traffic data are determined based on the first basic statistical feature and the first PFCP signaling content feature, and the labeled traffic data and the unlabeled traffic data are put into an autoencoder for unsupervised training and feature dimension reduction to obtain a target encoder; the labeled traffic data is input into a preset CNN-based classifier through the target encoder to perform supervised classification under the target classification type to obtain a target classifier for classifying PFCP traffic.

[0102] Specifically, all the extracted features, i.e., the first basic statistical features and the first PFCP signaling content features, are put into the autoencoder for unsupervised deep learning, with the purpose of learning the PFCP traffic features and performing feature dimensionality reduction, and finally obtaining an encoder, for example, Figure 2 As shown, the first stage of unsupervised training is performed. Next, the encoder obtained after unsupervised training of the labeled traffic data is input into the CNN-based classifier for classification training, and finally a classifier for classifying PFCP traffic is obtained. For example, Figure 2It can be added here that the original first PFCP signaling traffic of this application comes from the 5G special data set, and the current 5G special data set is insufficient in number and of average quality. This application achieves maximum utilization of the 5G special data set by performing semi-supervised learning based on the target 5G special data set.

[0103] Therefore, through two-stage deep learning, that is, obtaining the target encoder through unsupervised training in the first stage and obtaining the target classifier through supervised training in the second stage, the training of PFCP abnormal signaling detection based on two-stage deep learning was completed.

[0104] S104, obtaining the original second PFCP signaling traffic, classifying the second PFCP signaling traffic based on the target encoder and the target classifier, and obtaining a classification result of classifying the PFCP traffic.

[0105] Optionally, the second PFCP signaling traffic is classified under target classification based on the target encoder and the target classifier to obtain a classification result for classifying the PFCP traffic.

[0106] In an embodiment of the present application, the classification result represents the abnormal detection result of the second PFCP signaling traffic, that is, the abnormal traffic detection result of the second PFCP signaling. The classification result corresponds to the target classification type, that is, when the target classification type is binary, the corresponding classification results are two, namely normal and abnormal. After the target encoder and the target classifier are obtained in turn through two-stage deep learning in the above step S103, it indicates the end of training. At this time, the abnormal detection of the PFCP signaling traffic can be performed, that is, the original second PFCP signaling traffic is obtained, and the second PFCP signaling traffic is classified based on the target encoder and the target classifier to obtain the classification result of the PFCP traffic, thereby completing the abnormal detection of the PFCP signaling traffic.

[0107] Optionally, after performing packet parsing, bidirectional flow aggregation, and feature extraction on the second PFCP signaling traffic, the corresponding second basic statistical features and second PFCP signaling content features to be detected are obtained; the second basic statistical features and the second PFCP signaling content features are input into the target encoder, and the output data of the target encoder is input into the target classifier to obtain a classification result for classifying the PFCP traffic. Each bidirectional session flow corresponds to a classification result.

[0108] It should be noted that after the training process of the PFCP abnormal signaling detection based on two-stage deep learning is completed, the detection process of the PFCP abnormal signaling detection based on two-stage deep learning is performed. Specifically, Figure 3As shown, the original PFCP signaling traffic, i.e., the second PFCP signaling traffic, is obtained, and the original packet of the PFCP signaling traffic is parsed in the same way as the above training steps, and bidirectional session flow aggregation is performed based on IP information and Port information, and features are extracted for each aggregated flow. Then, all the extracted features to be detected are input into the trained target encoder to obtain the output data of the target encoder, and the output data of the target encoder is passed through the trained CNN classifier, i.e., the target classifier, to obtain the final result of classifying the PFCP traffic.

[0109] The PFCP signaling anomaly detection method based on two-stage deep learning provided in the embodiment of the present application obtains the original first PFCP signaling traffic, and performs original packet parsing on the first PFCP signaling traffic to obtain the parsed data packet of the first PFCP signaling traffic; performs bidirectional conversation flow aggregation on the parsed data packet to obtain the bidirectional conversation flow corresponding to the parsed data packet, and performs feature extraction on the bidirectional conversation flow to obtain the corresponding first basic statistical feature and the first PFCP signaling content feature; determines the label traffic data based on the first basic statistical feature and the first PFCP signaling content feature, and performs unsupervised training based on the label traffic data to obtain a target encoder, and performs supervised classification under the target classification type based on the label traffic data to obtain a target classifier; obtains the original second PFCP signaling traffic, classifies the second PFCP signaling traffic based on the target encoder and the target classifier, and obtains a classification result for classifying the PFCP traffic. The PFCP signaling anomaly detection method based on two-stage deep learning of the present application obtains the first basic statistical characteristics and the first PFCP signaling content characteristics of the first PFCP signaling traffic by performing original packet parsing, feature extraction, two-way session flow aggregation and other processing on the first PFCP signaling traffic, performs two-stage unsupervised training and supervised classification on the first basic statistical characteristics and the first PFCP signaling content characteristics to obtain the trained target encoder and target classifier, and finally performs anomaly detection on the PFCP signaling traffic through the target encoder and the target classifier, which can perform targeted processing on 5G signaling, reducing the limitations of the Internet abnormal traffic detection scheme, and at the same time, realizes anomaly detection of PFCP signaling and targeted extraction of PFCP signaling content characteristics, improves the training effect, and thus improves the accuracy of the results of PFCP signaling anomaly detection.

[0110] Furthermore, when the bidirectional conversation flow is aggregated for the parsed data packet to obtain the bidirectional conversation flow corresponding to the parsed data packet, the interception time of the conversation flow can be determined based on the timestamp information, and the corresponding session can be determined based on the IP information and the Port information; the session is intercepted based on the interception time to obtain the corresponding conversation flow, and the conversation flow is aggregated to obtain the bidirectional conversation flow corresponding to the parsed data packet.

[0111] Specifically, based on the IP information and Port information parsed from the packet, namely the source IP, destination IP, source Port and destination Port, bidirectional conversation flow aggregation is performed on the parsed data packet, wherein the timestamp information is used for classification or interception. For example, if the determined interception time is 30S, then a conversation flow is obtained by intercepting once every 30S, and the bidirectional conversation flow is aggregated to obtain the bidirectional conversation flow of the parsed data packet. One parsed data packet has only one bidirectional conversation flow; multiple parsed data packets have multiple bidirectional conversation flows.

[0112] Therefore, the present application extracts the flow features of PFCP signaling traffic, including basic statistical features and PFCP signaling content features, so that the algorithm model can more effectively learn the signaling content features in a two-way conversation flow; through two-stage deep learning, namely unsupervised feature learning in the first stage and supervised classification fine-tuning in the second stage, an efficient encoder that can perform feature dimensionality reduction and a classifier based on convolutional neural network are obtained, through which PFCP signaling traffic can be classified, that is, anomaly detection can be performed.

[0113] It should be noted that the present application provides a PFCP signaling anomaly detection method based on two-stage deep learning, that is, a PFCP signaling detection method based on two-stage deep learning, that is, a PFCP signaling traffic detection method based on two-stage deep learning.

[0114] Figure 4 Schematic diagram of the structure of a PFCP signaling anomaly detection device based on two-stage deep learning provided in an embodiment of the present application. Figure 4 As shown, the PFCP signaling anomaly detection device 400 based on two-stage deep learning in an embodiment of the present application may specifically include:

[0115] The parsing module 401 is used to obtain the original first PFCP signaling traffic, and perform original packet parsing on the first PFCP signaling traffic to obtain parsed data packets of the first PFCP signaling traffic.

[0116] The first extraction module 402 is used to perform bidirectional conversation flow aggregation on the parsed data packets to obtain the bidirectional conversation flow corresponding to the parsed data packets, and perform feature extraction on the bidirectional conversation flow to obtain the corresponding first basic statistical features and first PFCP signaling content features; wherein each parsed data packet corresponds to a bidirectional conversation flow.

[0117] The training module 403 is used to determine the label traffic data based on the first basic statistical feature and the first PFCP signaling content feature, and to perform unsupervised training based on the label traffic data to obtain a target encoder, and to perform supervised classification under a target classification type based on the label traffic data to obtain a target classifier.

[0118] The detection module 404 is used to obtain the original second PFCP signaling traffic, classify the second PFCP signaling traffic based on the target encoder and the target classifier, and obtain a classification result for classifying the PFCP traffic; wherein the classification result represents the abnormal detection result of the second PFCP signaling traffic; the classification result corresponds to the target classification type.

[0119] In a possible implementation, the parsing module is specifically used to:

[0120] Parse the first PFCP signaling traffic at the Mac layer to obtain corresponding timestamp information;

[0121] Parse the first PFCP signaling traffic at the IP layer to obtain the corresponding source IP and destination IP;

[0122] Parse the first PFCP signaling traffic at the transport layer to obtain the corresponding source port and destination port;

[0123] Parsing the first PFCP signaling traffic at the application layer to obtain corresponding PFCP signaling information;

[0124] The corresponding parsed data packet is determined based on the timestamp information, source IP, destination IP, source Port, destination Port and PFCP signaling information; wherein the source IP and destination IP represent IP information, and the source Port and destination Port represent Port information.

[0125] In a possible implementation, the PFCP signaling anomaly detection device based on two-stage deep learning further includes:

[0126] A second extraction module, configured to extract a user permanent equipment identifier of the first PFCP signaling traffic in response to determining that the first PFCP signaling traffic is a session-related process based on the PFCP signaling information;

[0127] The third extraction module is used to extract the response code of the first PFCP signaling traffic in response to determining that the first PFCP signaling traffic is a response message based on the PFCP signaling information; wherein the response code represents the number of response successes or failures.

[0128] In a possible implementation manner, the labeled traffic data includes labeled traffic data and unlabeled traffic data; and the training module is specifically used to:

[0129] Determine labeled traffic data and unlabeled traffic data based on the first basic statistical feature and the first PFCP signaling content feature, put the labeled traffic data and the unlabeled traffic data into the autoencoder for unsupervised training and feature dimension reduction, and obtain a target encoder;

[0130] The labeled traffic data is input into a preset CNN-based classifier through a target encoder to perform supervised classification under the target classification type, and a target classifier for classifying PFCP traffic is obtained; wherein the target classification types include binary classification and multi-classification.

[0131] In a possible implementation, the detection module is specifically used to:

[0132] Similarly, after performing packet parsing, bidirectional flow aggregation, and feature extraction on the second PFCP signaling traffic, the corresponding second basic statistical features to be detected and the second PFCP signaling content features are obtained;

[0133] The second basic statistical feature and the second PFCP signaling content feature are input into a target encoder, and the output data of the target encoder is input into a target classifier to obtain a classification result for classifying the PFCP traffic; wherein each bidirectional conversation flow corresponds to a classification result.

[0134] In a possible implementation, the first extraction module is specifically configured to:

[0135] Determine the interception time of the intercepted session flow based on the timestamp information, and determine the corresponding session based on the IP information and the port information;

[0136] The conversation is intercepted based on the interception time to obtain the corresponding conversation flow, and the conversation flow is aggregated to obtain the bidirectional conversation flow corresponding to the parsed data packet.

[0137] In a possible implementation, the parsing module is specifically used to:

[0138] Get basic 5G special data sets;

[0139] The basic 5G special data set is processed to obtain the corresponding target 5G special data set, and the original first PFCP signaling flow is determined based on the target 5G special data set.

[0140] The PFCP signaling anomaly detection device based on two-stage deep learning provided in the embodiment of the present application obtains the original first PFCP signaling traffic, and performs original packet parsing on the first PFCP signaling traffic to obtain the parsed data packet of the first PFCP signaling traffic; performs two-way conversation flow aggregation on the parsed data packet to obtain the two-way conversation flow corresponding to the parsed data packet, and performs feature extraction on the two-way conversation flow to obtain the corresponding first basic statistical feature and the first PFCP signaling content feature; determines the label traffic data based on the first basic statistical feature and the first PFCP signaling content feature, and performs unsupervised training based on the label traffic data to obtain a target encoder, and performs supervised classification under the target classification type based on the label traffic data to obtain a target classifier; obtains the original second PFCP signaling traffic, classifies the second PFCP signaling traffic based on the target encoder and the target classifier, and obtains a classification result for classifying the PFCP traffic. The PFCP signaling anomaly detection device based on two-stage deep learning of the present application obtains the first basic statistical characteristics and the first PFCP signaling content characteristics of the first PFCP signaling traffic by performing original packet parsing, feature extraction, two-way session flow aggregation and other processing on the first PFCP signaling traffic, and obtains the trained target encoder and target classifier by performing two-stage unsupervised training and supervised classification on the first basic statistical characteristics and the first PFCP signaling content characteristics. Finally, the PFCP signaling traffic is detected for anomalies through the target encoder and the target classifier, and 5G signaling can be processed in a targeted manner, reducing the limitations of the Internet abnormal traffic detection scheme. At the same time, anomaly detection of PFCP signaling and targeted extraction of PFCP signaling content characteristics are realized, thereby improving the training effect and thus improving the accuracy of the results of PFCP signaling anomaly detection.

[0141] like Figure 5 As shown, an electronic device 500 provided in an embodiment of the present application includes: a processor 501, a memory 502 and a bus, wherein the memory 502 stores machine-readable instructions executable by the processor 501. When the electronic device is running, the processor 501 communicates with the memory 502 through the bus, and the processor 501 executes the machine-readable instructions to perform the steps of the PFCP signaling anomaly detection method based on two-stage deep learning as described above.

[0142] Specifically, the above-mentioned memory 502 and processor 501 can be general-purpose memory and processor, which are not specifically limited here. When the processor 501 runs the computer program stored in the memory 502, it can execute the above-mentioned PFCP signaling anomaly detection method based on two-stage deep learning.

[0143] Corresponding to the above-mentioned PFCP signaling anomaly detection method based on two-stage deep learning, an embodiment of the present application also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the above-mentioned PFCP signaling anomaly detection method based on two-stage deep learning are executed.

[0144] Those skilled in the art can clearly understand that, for the convenience and simplicity of description, the specific working process of the system and device described above can refer to the corresponding process in the method embodiment, and will not be repeated in this application. In the several embodiments provided in this application, it should be understood that the disclosed system, device and method can be implemented in other ways. The device embodiments described above are merely schematic. For example, the division of the modules is only a logical function division. There may be other division methods in actual implementation. For example, multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some communication interfaces, indirect coupling or communication connection of devices or modules, which can be electrical, mechanical or other forms.

[0145] The modules described as separate components may or may not be physically separated, and the components shown as modules may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0146] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0147] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a non-volatile computer-readable storage medium that is executable by a processor. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art or the part of the technical solution, can be embodied in the form of a software product, which is stored in a storage medium and includes several instructions for a computer device (which can be a personal computer, server, or network device, etc.) to perform all or part of the steps of the deployment method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard drives, ROM, RAM, magnetic disks, or optical disks.

[0148] The above are only specific implementations of the present application, but the protection scope of the present application is not limited thereto. Any technician familiar with the technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.

Claims

1. A PFCP signaling anomaly detection method based on two-stage deep learning, characterized in that: The method comprises: Acquire the original first PFCP signaling traffic, and perform original packet parsing on the first PFCP signaling traffic to obtain a parsed data packet of the first PFCP signaling traffic; Performing bidirectional conversation flow aggregation on the parsed data packet to obtain a bidirectional conversation flow corresponding to the parsed data packet, and performing feature extraction on the bidirectional conversation flow to obtain a corresponding first basic statistical feature and a first PFCP signaling content feature; wherein each parsed data packet corresponds to a bidirectional conversation flow; Determine label traffic data based on the first basic statistical feature and the first PFCP signaling content feature, perform unsupervised training based on the label traffic data to obtain a target encoder, and perform supervised classification under a target classification type based on the label traffic data to obtain a target classifier; Obtain the original second PFCP signaling traffic, classify the second PFCP signaling traffic based on the target encoder and the target classifier, and obtain a classification result for classifying the PFCP traffic; wherein the classification result represents the abnormality detection result of the second PFCP signaling traffic; the classification result corresponds to the target classification type.

2. The method according to claim 1, characterized in that The performing original packet parsing on the first PFCP signaling traffic to obtain a parsed data packet of the first PFCP signaling traffic includes: Parsing the first PFCP signaling traffic at the Mac layer to obtain corresponding timestamp information; Parsing the first PFCP signaling traffic at the IP layer to obtain corresponding source IP and destination IP; Parsing the first PFCP signaling traffic at the transport layer to obtain corresponding source Port and destination Port; Parsing the first PFCP signaling traffic at the application layer to obtain corresponding PFCP signaling information; Determine the corresponding parsed data packet based on the timestamp information, the source IP, the destination IP, the source Port, the destination Port and the PFCP signaling information; wherein the source IP and the destination IP represent IP information, and the source Port and the destination Port represent Port information.

3. The method according to claim 2, characterized in that The method further comprises: In response to determining that the first PFCP signaling traffic is a session-related process based on the PFCP signaling information, extracting a user permanent equipment identifier of the first PFCP signaling traffic; In response to determining that the first PFCP signaling traffic is a response message based on the PFCP signaling information, extracting a response code of the first PFCP signaling traffic; wherein the response code represents the number of response successes or failures; Determine a corresponding first parsed data packet based on the user permanent device identifier, the response code, the timestamp information, the source IP, the destination IP, the source Port, the destination Port and the PFCP signaling information.

4. The method according to claim 3, characterized in that The labeled traffic data includes labeled traffic data and unlabeled traffic data; the determining of the labeled traffic data based on the first basic statistical feature and the first PFCP signaling content feature, performing unsupervised training based on the labeled traffic data to obtain a target encoder, and performing supervised classification under a target classification type based on the labeled traffic data to obtain a target classifier, including: Determine labeled traffic data and unlabeled traffic data based on the first basic statistical feature and the first PFCP signaling content feature, put the labeled traffic data and the unlabeled traffic data into an autoencoder for unsupervised training and feature dimension reduction, and obtain a target encoder; The labeled traffic data is input into a preset CNN-based classifier through the target encoder to perform supervised classification under the target classification type, and a target classifier for classifying PFCP traffic is obtained; wherein the target classification types include binary classification and multi-classification.

5. The method according to claim 4, characterized in that The classifying the second PFCP signaling traffic based on the target encoder and the target classifier to obtain a classification result for classifying the PFCP traffic includes: Similarly, after performing packet parsing, bidirectional flow aggregation, and feature extraction on the second PFCP signaling traffic, the corresponding second basic statistical features to be detected and the second PFCP signaling content features are obtained; The second basic statistical feature and the second PFCP signaling content feature are input into the target encoder, and the output data of the target encoder is input into the target classifier to obtain a classification result for classifying the PFCP traffic; wherein each bidirectional conversation flow corresponds to a classification result.

6. The method according to claim 5, characterized in that The step of performing bidirectional conversation flow aggregation on the parsed data packet to obtain a bidirectional conversation flow corresponding to the parsed data packet includes: Determine an interception time of the intercepted session flow based on the timestamp information, and determine a corresponding session based on the IP information and the Port information; The session is intercepted based on the interception time to obtain a corresponding session flow, and the session flow is aggregated to obtain a bidirectional session flow corresponding to the parsed data packet.

7. The method according to claim 1, characterized in that The obtaining of the original first PFCP signaling traffic includes: Get basic 5G special data sets; The basic 5G special data set is processed to obtain a corresponding target 5G special data set, and the original first PFCP signaling flow is determined based on the target 5G special data set.

8. A PFCP signaling anomaly detection device based on two-stage deep learning, characterized in that: The device comprises: A parsing module, used for acquiring an original first PFCP signaling flow, and performing original packet parsing on the first PFCP signaling flow to obtain a parsed data packet of the first PFCP signaling flow; A first extraction module is used to perform bidirectional conversation flow aggregation on the parsed data packet to obtain a bidirectional conversation flow corresponding to the parsed data packet, and perform feature extraction on the bidirectional conversation flow to obtain a corresponding first basic statistical feature and a first PFCP signaling content feature; wherein each parsed data packet corresponds to a bidirectional conversation flow; A training module, used for determining label traffic data based on the first basic statistical feature and the first PFCP signaling content feature, performing unsupervised training based on the label traffic data to obtain a target encoder, and performing supervised classification under a target classification type based on the label traffic data to obtain a target classifier; A detection module is used to obtain the original second PFCP signaling traffic, classify the second PFCP signaling traffic based on the target encoder and the target classifier, and obtain a classification result for classifying the PFCP traffic; wherein the classification result represents the abnormal detection result of the second PFCP signaling traffic; the classification result corresponds to the target classification type.

9. An electronic device, characterized in that: include: A processor, a memory and a bus, wherein the memory stores machine-readable instructions executable by the processor, and when the electronic device is running, the processor and the memory communicate via the bus, and when the machine-readable instructions are executed by the processor, the steps of the PFCP signaling anomaly detection method based on two-stage deep learning are performed.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, which, when executed by a processor, executes the steps of the PFCP signaling anomaly detection method based on two-stage deep learning as described in any one of claims 1 to 7.

Citation Information

Patent Citations

  • Network traffic classification method and system based on federal semi-supervised learning

    CN113705712A

  • Deep embedded self-learning system and method for detecting suspicious network behavior

    CN114205106A

  • Methods, systems, media, and apparatus for unsupervised action detection

    CN118194099A