Method and device for determining signaling adaptation environment, equipment and storage medium

By determining the signaling adaptation environment in the 5G network, the signaling test environment is constructed and the configuration vector is adjusted so that the signaling to be tested is adapted to the signaling test environment, which solves the problem of difficulty in dynamically simulating a diversified network environment in the prior art and improves the security of the 5G network.

CN120075804APending Publication Date: 2025-05-30CHINA TELECOM NETWORK SECURITY TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510128777.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-05
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

The existing technology is difficult to dynamically simulate diversified network environments, resulting in the undetected security risks and vulnerabilities in 5G networks.

Method used

By determining the signaling adaptation environment, a signaling test environment is constructed according to the intended entity, and by adjusting the configuration vectors to adapt the signaling to be tested to the signaling test environment, thus discovering more security risks and vulnerabilities.

Benefits of technology

It improves the security of 5G networks and can detect undiscovered security risks and vulnerabilities in different network environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120075804A_ABST
    Figure CN120075804A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of communication, in particular to a method and device for determining a signaling adaptation environment, equipment and a storage medium, and the method comprises the steps: determining one or more intention entities associated with an intention condition according to a first domain ontology, a second domain ontology and the intention condition, the intention condition being used for representing a communication security problem, each intention entity is constructed based on the first domain ontology and the second domain ontology; determining the signaling to be tested and an initial configuration vector of a signaling test environment according to the one or more intention entities, wherein the initial configuration vector of the signaling test environment indicates network resources related to the one or more intention entities; constructing the signaling test environment according to the initial configuration vector of the signaling test environment; and inputting the to-be-tested signaling into the signaling test environment, and adjusting the configuration vector of the signaling test environment to enable the to-be-tested signaling to be adaptive to the adjusted signaling test environment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technologies, and in particular, to a method, apparatus, device, and storage medium for determining a signaling adaptation environment. Background Art

[0002] With the wide deployment of the fifth-generation mobile communication technology (5G), network security has become a crucial issue. Although the characteristics of high speed and low latency of the 5G network bring unprecedented experiences to users, they also provide new ways for potential vulnerabilities and security risks.

[0003] Currently, the system security is usually evaluated under fixed and preset network conditions, and it is impossible to dynamically simulate the diverse network environments that attackers may exploit, resulting in many security risks and vulnerabilities remaining undetected. Summary of the Invention

[0004] Embodiments of this application provide a method, apparatus, device, and storage medium for determining a signaling adaptation environment, which are used to discover more potential security risks and vulnerabilities in the network environment.

[0005] In a first aspect, this application provides a method for determining a signaling adaptation environment, and the method includes:

[0006] Determine one or more intent entities associated with the intent condition according to a first domain ontology, a second domain ontology, and the intent condition, where the intent condition is used to characterize a communication security problem, and each intent entity is constructed based on the first domain ontology and the second domain ontology. The first domain ontology is used to represent the entities, attributes, and relationships involved in the signaling process, and the second domain ontology is used to represent the entities, attributes, and relationships involved in the network resources associated with the first domain ontology;

[0007] Determine an initial configuration vector of the signaling to be tested and the signaling test environment according to the one or more intent entities, where the initial configuration vector of the signaling test environment indicates the network resources involved in the one or more intent entities;

[0008] Construct the signaling test environment according to the initial configuration vector of the signaling test environment;

[0009] Input the signaling to be tested into the signaling test environment, and adapt the signaling to be tested to the adjusted signaling test environment by adjusting the configuration vector of the signaling test environment.

[0010] In the embodiments of the present application, first, one or more intent entities related to communication security issues are determined. Based on the intent entity, a signaling to be tested and an initial configuration vector are obtained. The initial vector is used to construct a signaling test environment, and the signaling to be tested is input into the signaling test environment to verify whether the signaling to be tested is adapted to the signaling test environment. Among them, by continuously adjusting the configuration vector, the signaling test environment changes continuously to adapt to the signaling to be detected. This method can discover more security hazards and vulnerabilities in different network environments, thereby improving the security of the 5G network.

[0011] In one possible embodiment, determining the signaling to be tested according to the one or more intent entities includes:

[0012] Determining the signaling to be tested according to the one or more intent entities and a preset protocol specification, where the signaling to be tested is a signaling flow that meets the preset protocol specification.

[0013] In this embodiment, the signaling to be tested obtained according to one or more intent entities and a preset protocol specification can meet the preset protocol specification and has a risk of communication security problems.

[0014] In one possible embodiment, making the signaling to be tested adapted to the signaling test environment by adjusting the configuration vector of the signaling test environment includes:

[0015] Determining a first configuration vector based on a preset algorithm, the initial configuration vector of the signaling test environment, and a preset configuration vector set;

[0016] Constructing an adjusted signaling test environment according to the first configuration vector;

[0017] Inputting the signaling to be tested into the adjusted signaling test environment;

[0018] If the communication security problem occurs in the adjusted signaling test environment, it is determined that the signaling to be tested is adapted to the adjusted signaling test environment.

[0019] In this embodiment, by using a preset algorithm and a preset configuration vector set, continuously adjusting the configuration vector can cover a wider range of network configurations, making the signaling test environment change continuously to adapt to the signaling to be detected, so as to discover vulnerabilities that are not easily found under static or fixed configurations.

[0020] In one possible embodiment, if the first configuration vector is not included in the preset configuration vector set, the first configuration vector is added to the preset configuration vector set.

[0021] In a possible embodiment, the first configuration vector indicates one or more of service elements, operating environments, network environments, configuration conditions, and security baselines.

[0022] In a possible embodiment, an analysis report for the communication security problem is generated based on the signaling to be tested and the adjusted signaling test environment.

[0023] In this embodiment, by recording the configuration vector that successfully triggers a communication security problem in the test environment and the status information of the system operation, an analysis report is generated. This can not only perform risk assessment on the discovered security hazards and vulnerabilities and optimize security policies, but also integrate this content into the knowledge graph in the signaling field to improve the knowledge base for subsequent 5G signaling attack identification, security event analysis, etc.

[0024] In a second aspect, an embodiment of the present application further provides a signaling adaptation environment determination device. The device includes a transceiver unit and a processing unit, and the processing unit controls the operations of the transceiver unit;

[0025] The processing unit is configured to determine one or more intent entities associated with the intent condition according to a first domain ontology, a second domain ontology, and an intent condition. The intent condition is used to characterize a communication security problem, and each intent entity is constructed based on the first domain ontology and the second domain ontology. The first domain ontology is used to represent the entities, attributes, and relationships involved in the signaling process, and the second domain ontology is used to represent the entities, attributes, and relationships involved in the network resources associated with the first domain ontology. The processing unit is further configured to determine an initial configuration vector of the signaling to be tested and the signaling test environment according to the one or more intent entities. The initial configuration vector of the signaling test environment indicates the network resources involved in the one or more intent entities. The processing unit is further configured to construct the signaling test environment according to the initial configuration vector of the signaling test environment. And the processing unit is configured to input the signaling to be tested into the signaling test environment and adapt the signaling to be tested to the adjusted signaling test environment by adjusting the configuration vector of the signaling test environment.

[0026] In a third aspect, the present application provides a signaling adaptation environment determination device, including:

[0027] A memory for storing program instructions;

[0028] A processor for calling the program instructions stored in the memory and executing the steps included in the method according to any one of the first aspect according to the obtained program instructions.

[0029] Fourthly, the present application provides a computer-readable storage medium storing a computer program, where the computer program includes program instructions that, when executed by a computer, cause the computer to execute the method according to any one of the first aspect.

[0030] Fifthly, the present application provides a computer program product, which includes computer program code that, when running on a computer, causes the computer to execute the method according to any one of the first aspect. Description of the Drawings

[0031] Figure 1 It is a flowchart of a method for determining a signaling adaptation environment provided by an embodiment of the present application;

[0032] Figure 2 It is a schematic structural diagram of a method for determining a signaling adaptation environment provided by an embodiment of the present application;

[0033] Figure 3 It is a schematic structural diagram of a device for determining a signaling adaptation environment provided by an embodiment of the present application Figure 1 ;

[0034] Figure 4 It is a schematic structural diagram of a device for determining a signaling adaptation environment provided by an embodiment of the present application Figure 2 。 Detailed Embodiments

[0035] In order to make the objectives, technical solutions, and advantages of the present invention clearer, the present invention will be further described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0036] For ease of understanding, the technical terms involved in the embodiments of the present application are first explained.

[0037] Signaling knowledge graph: It is a knowledge graph in the field of 5G signaling security, focusing on describing the relationships between signaling tasks, system functions, process mechanisms, and network environments. Among them, the signaling knowledge graph is composed of intent nodes, and the intent nodes can represent different elements of signaling tasks, such as purposes, routes, costs, activities, and results. The edges of the signaling knowledge graph can represent the relationships between these elements, such as causal relationships, time relationships, logical relationships, and selection relationships.

[0038] Signaling: Refers to signaling messages or a set of signaling flows carrying specific purposes, where the purposes include both regular process tasks and malicious attack attempts. It is generally used to transmit control messages between devices in a communication network to establish, manage, and release communication connections.

[0039] In the field of 5G security, technologies for addressing security risks and vulnerabilities are very limited. Currently, the security of systems is generally evaluated under fixed and preset network conditions, and it is unable to dynamically simulate the diverse network environments that attackers may exploit, resulting in many security risks and vulnerabilities remaining undetected.

[0040] Based on the above problems, as Figure 1 shown, a method for determining a signaling adaptation environment provided by an embodiment of the present invention specifically includes:

[0041] Step 100: The server determines one or more intent entities associated with the intent condition according to the first domain ontology, the second domain ontology, and the intent condition. The intent condition is used to characterize a communication security problem, and each intent entity is constructed based on the first domain ontology and the second domain ontology.

[0042] In specific implementation, first, the server constructs the first domain ontology and the second domain ontology.

[0043] Among them, the first domain ontology is used to represent the entities, attributes, and relationships involved in the signaling process, that is, a formal description method for characterizing the detailed task execution process of 5G signaling processes, which can further decompose various tasks and express the entities, attributes, and relationships therein.

[0044] Exemplarily, the entities can be User Equipment (UE), Session Management Function (SMF), Access and Mobility Management Function (AMF), etc. The attributes can include subject, object, method, purpose, input, output, condition, characteristic, etc. Attributes are information fragments attached to entities, providing detailed information about the entities, which is conducive to distinguishing different entities with similar characteristics. The relationship is the link connecting different entities, representing various interactions and connection methods between entities. The identification and classification of relationships are crucial for understanding the interactions between signaling intents and network environment elements. Among them, the relationships between various entities can include causal relationships, subordinate relationships, spatial relationships, temporal relationships, etc.

[0045] Exemplarily, taking the attributes as an example, the meanings of each content in the attributes are introduced below.

[0046] 1) Subject

[0047] The subject is the starting point of the intent and represents the initiator of the intent. It can be a resource instance in the network environment, other intent instances, or the attributes of the instance.

[0048] 2) Object

[0049] The object is the end point of the intent and represents the target object of the intent. The object has the same specific instance type range as the subject and is usually also a resource instance in the network environment, or other intent instances, or attributes of an instance.

[0050] 3) Methods

[0051] A method is an ordered set of network environment instances, intent instances, and the relationships between them that the subject relies on in completing a certain intention from the subject to the object. It can be associated with specific resources, processes, messages, operations, key values, etc.

[0052] 4) Purpose

[0053] The purpose is the expected result of the intention, including the state of the object, the response of the message, operation, etc., or the changes caused by the resources, key values, etc.

[0054] 5) Input

[0055] Input refers to the triggering conditions for the subject to initiate this intention, which is composed of other intent instances or sets of intent instances.

[0056] 6) Output

[0057] Output refers to the set of connecting actions after the end of this intention, which is composed of other intention instances or sets of intention instances.

[0058] 7) Conditions

[0059] Conditions are a set of constraints that affect the execution or success of an intention.

[0060] 8) Features

[0061] Characteristics are labels for the indirect effects of the intent, such as precision, deviation, reduction, amplification, high consumption, large range, low latency, etc.

[0062] Exemplarily, taking relationships as an example, the meaning of each relationship is introduced below.

[0063] 1) Causation

[0064] Causation is used to reveal how one entity affects or causes changes in another entity.

[0065] 2) Subordinate relationship

[0066] Affiliation is used to describe the affiliation or ownership relationship between entities.

[0067] 3) Spatial relationship

[0068] The spatial relationship is used to describe the relative positions or distributions of entities in space.

[0069] 4) Temporal relationship

[0070] The temporal relationship involves the sequence or duration of entities in time.

[0071] Among them, the second domain ontology is used to represent the entities, attributes, and relationships involved in the network resources associated with the first domain ontology, that is, a formal description method for representing the whole-process network entities of signaling intentions.

[0072] Exemplarily, the entity can be a network slice, network function, network service, network virtual resource, network physical resource, network isolation domain, network node, etc., and the attributes can include subject, object, method, purpose, input, output, condition, characteristic, etc. Among them, the attribute is an information segment attached to the entity, providing detailed information about the entity, which is beneficial to distinguishing different entities with similar characteristics. For the specific meaning, refer to the above content. The relationship is used to represent various interactions and connection methods between entities. For the specific meaning, refer to the above content.

[0073] After constructing the first domain ontology and the second domain ontology, the server needs to determine the intention conditions.

[0074] Among them, the intention condition is used to represent a communication security problem. For example, security vulnerabilities, attacks, etc. Each intention condition is constructed based on the first domain ontology and the second domain ontology.

[0075] Exemplarily, the intention condition can be a privilege escalation attack. Among them, the privilege escalation attack refers to a low-privilege user using various means to increase their system privileges.

[0076] After determining the intention condition, the server determines one or more intention entities associated with the intention condition according to the first domain ontology, the second domain ontology, and the intention condition.

[0077] Exemplarily, if the intention condition is a privilege escalation attack, one or more intention entities associated with the privilege escalation attack can be determined according to the constructed first domain ontology, second domain ontology, and the intention condition of the privilege escalation attack. Among them, the intention entity includes the process of gradually realizing the intention of the privilege escalation attack among various entities.

[0078] For example, according to the first domain ontology, the second domain ontology, and the intention condition of the privilege escalation attack, the determined multiple intention entities can be as follows:

[0079] Intention entity 1: UE1 accesses network 1 by sending a registration request message 1;

[0080] Intention Entity 2: Message 1 reaches Network Element 1 through the addressing process to complete the transmission;

[0081] Intention Entity 3: Network Element 1 completes the service registration for UE1 through the service registration process;

[0082] Intention Entity 4: Network Element 1 completes the service access through the access, provided that the authentication is completed;

[0083] Intention Entity 5: Network Element 1 completes the authentication by automatically matching the authentication data, provided that the service registration is completed, and the feature is information expansion;

[0084] Intention Entity 6: Message 2 completes the privilege escalation attack through information expansion.

[0085] Among them, each of the above intention entities clearly describes a specific signaling interaction or network behavior. Associating each intention entity can form a privilege escalation attack.

[0086] Step 110: The server determines the signaling to be tested and the initial configuration vector of the signaling test environment according to one or more intention entities. The initial configuration vector of the signaling test environment indicates the network resources involved in one or more intention entities.

[0087] In specific implementation, the signaling to be tested can be determined according to the obtained one or more intention entities and the preset protocol specifications. The signaling to be tested is a signaling flow that meets the preset protocol specifications. At the same time, the initial configuration vector of the signaling test environment can be determined according to the obtained one or more intention entities. Among them, the initial configuration vector of the signaling test environment indicates the network resources involved in one or more intention entities.

[0088] Exemplarily, assume that one or more intention entities are associated with a privilege escalation attack, and the preset protocol specification is the 3GPP technical specification. Among them, this specification is the international standard for 5G network communication, which details the structure, format, and mandatory fields of the signaling. According to the 3GPP technical specification, the relationships between the intention entities are first formally described accurately and unambiguously, corresponding to different elements of the signaling tasks, such as purpose, via, cost, activity, and result, etc. Then, the elements of various tasks are reset according to the 3GPP protocol specification to generate a signaling message framework, including a signaling message header, message body, key fields, parameter values, etc., and the non-critical parameters are fine-tuned and connection messages are added to form one or more signaling messages associated with the intention entities, that is, the signaling to be tested. Among them, this signaling has the risk of a privilege escalation attack, but at the same time meets the 3GPP technical specification.

[0089] It can be seen that based on the constructed first-domain ontology, second-domain ontology, and specific intent conditions, signaling carrying specific task intents can be automatically generated, improving the quality of data sources and facilitating the discovery of vulnerabilities in 5G systems.

[0090] In addition, the server can obtain an initial configuration vector based on network resources involved in one or more intent entities. Among them, all network resources in the intent entity can be identified, such as network slices, network functions, network services, network virtual resources, etc., and the initial configuration vector can be obtained based on this resource information.

[0091] Step 120: The server constructs a signaling test environment according to the initial configuration vector of the signaling test environment.

[0092] In a specific implementation, the server configures network parameters required for the signaling test environment according to the initial configuration vector to ensure that the test environment can simulate corresponding functions in the 5G network.

[0093] Exemplarily, the initial configuration vector indicates one or more of service elements, operating environments, network environments, configuration conditions, and security baselines, as specifically shown below:

[0094] 1) Service elements

[0095] Service elements include User Equipment (UE), Network Function Service (NF Service), Virtual Network Function (VNF), slices, and resource pools.

[0096] 2) Operating environment

[0097] The operating environment includes Points of Deployment (PODs), containers, virtual machines, physical hosts, and the association relationships between them.

[0098] 3) Network environment

[0099] The network environment includes ports, Internet Protocol (IP) addresses, Tunnel Endpoint Identifiers (TEIDs), Virtual Private Clouds (VPCs), and Virtual Local Area Networks (VLANs).

[0100] 4) Configuration conditions

[0101] Configuration conditions include network element function configuration, service logic configuration, policy rule configuration, security baseline configuration, etc.

[0102] 5) Security baseline

[0103] The security baseline includes authorization, passwords, security patches, certificates, vulnerabilities, network function configuration files, Access Control Lists (ACLs), and port open status.

[0104] Furthermore, according to the parameters of the initial configuration vector, ensure that the network components and functions in the signaling test environment can be securely connected and communicate. Among them, verify whether the test environment is accurately constructed according to the initial configuration vector by checking whether all network functions are running properly.

[0105] It can be seen that when starting the test based on the signaling test environment, selecting a suitable initial configuration vector can significantly affect the test efficiency, enabling the test to enter the state faster and better discover security hazards and vulnerabilities.

[0106] Step 130: The server inputs the signaling to be tested into the signaling test environment and adapts the signaling to be tested to the adjusted signaling test environment by adjusting the configuration vector of the signaling test environment.

[0107] In specific implementation, input the signaling to be tested into the constructed signaling test environment for testing, monitor the running state of the signaling test environment in real time, and collect relevant information that may trigger communication security problems in the signaling test environment. The test result of the signaling test environment can be obtained based on the collected information, and the test result indicates whether there are communication security problems in the signaling test environment.

[0108] Exemplarily, after the signaling to be tested is input into the signaling test environment for testing, the server can use the method of instrumentation to automatically monitor anomalies in the signaling test environment, that is, on the basis of ensuring the integrity of the original program logic in the signaling test environment, insert probes into the program, collect information in the program code through the probes, and insert code segments at specific positions to collect the dynamic context information during program operation. Among them, the collected information can be the sending time, receiving time of the signaling to be tested, and the processing time of each network element, etc. The test result of the signaling test environment is obtained through the collected information.

[0109] Further, if the test result indicates that there are no communication security issues in the signaling test environment, it means that the signaling to be tested is not compatible with the signaling test environment. The server can determine the first configuration vector based on a preset algorithm, the initial configuration vector of the signaling test environment, and a preset configuration vector set. Then, the server can construct an adjusted signaling test environment according to the first configuration vector. Here, the preset configuration vector set includes multiple configuration vectors. After that, input the signaling to be tested into the adjusted signaling test environment. If a communication security issue occurs in the adjusted signaling test environment, it is determined that the signaling to be tested is compatible with the adjusted signaling test environment. In addition, if the first configuration vector is not included in the preset configuration vector set, the first configuration vector can be added to the preset configuration vector set.

[0110] In a possible implementation manner, if the test result indicates that there are no communication security issues in the signaling test environment, the server can change a part of the content of the initial configuration vector based on a preset algorithm to form the first configuration vector, and readjust the signaling test environment according to the first configuration vector.

[0111] In a possible implementation manner, if the test result indicates that there are no communication security issues in the signaling test environment, the server can add a part of the configuration vectors in the preset configuration vector set to the initial configuration vector based on the preset configuration vector set to form the first configuration vector, and readjust the signaling test environment according to the first configuration vector.

[0112] In a possible implementation manner, if the test result indicates that there are no communication security issues in the signaling test environment, the server can change a part of the content of the initial configuration vector based on a preset algorithm and add a part of the configuration vectors in the preset configuration vector set to form the first configuration vector, and readjust the signaling test environment according to the first configuration vector.

[0113] The above three implementation manners can all implement the solution of this application, and this application does not make any limitations in this regard.

[0114] Exemplarily, taking the above third implementation manner as an example, if the signaling to be tested is related to a privilege escalation attack, when the signaling to be tested is not compatible with the signaling test environment, the server can change a part of the content of the initial configuration vector, such as parameter values, fields, etc., according to a mutation algorithm, and add a part of the configuration vectors in the preset configuration vector set to form the first configuration vector. Then, the server can construct an adjusted signaling test environment according to the first configuration vector. After that, input the signaling to be detected into the re-constructed signaling test environment, and continue to monitor the running state of the signaling test environment in real time. If the monitored test result indicates that a privilege escalation attack issue occurs in the signaling test environment, it means that the signaling to be tested is compatible with the adjusted signaling test environment. Here, if the first configuration vector is not included in the preset configuration vector set, the first configuration vector can be added to the preset configuration vector set.

[0115] It can be understood that if, when constructing an adjusted signaling test environment according to the first configuration vector, the test result indicates that there is no communication security problem in the signaling test environment, then the modification can continue based on the first configuration vector, and the signaling test environment can be adjusted accordingly. Then, the signaling to be detected is input into the re-adjusted signaling test environment for testing, and the running state is continuously monitored, and so on, until the test result indicates that there is a communication security problem in the signaling test environment.

[0116] After the signaling to be tested is adapted to the adjusted signaling test environment, the server can update the preset configuration vector set according to the configuration vector used to construct the signaling test environment. This may include removing some irrelevant configuration vectors to simplify the preset configuration vector set, or sorting some highly related configuration vectors by importance to ensure that key configuration vectors are optimized and considered when reconstructing the signaling test environment later.

[0117] In the above steps, the initial configuration vector can also be called the initial seed, and the preset configuration vector set can also be called the seed pool. Through the above steps, the updated seed pool is used as an alternative set. Through the preset algorithm and the seed pool, seed selection, construction of the signaling test environment, and testing are carried out until the optimal seed is found, so that the signaling to be tested is adapted to the adjusted signaling test environment.

[0118] In addition, the server can generate an analysis report on communication security problems based on the signaling to be tested and the adjusted signaling test environment.

[0119] Exemplarily, the server can record the configuration vector that successfully triggers an abnormality in the signaling test environment, and can also record the running state of the signaling test environment, the content of the signaling to be detected, the corresponding intention conditions, the timing sequence of the signaling to be detected, and various preconditions, etc. Then, the server generates an analysis report on communication security problems based on the recorded content. The analysis report mainly includes the signaling type, parameter values, network resources, test results, abnormal events, timestamps, etc. during the signaling test process.

[0120] After generating the analysis report, the server performs knowledge extraction based on the generated analysis report and fuses the extracted key information with the signaling knowledge in the existing knowledge base. In knowledge fusion, it is necessary to disambiguate, deduplicate, and resolve conflicts for the entities and relationships extracted from different data sources to form unified knowledge, and perform inconsistent detection verification and knowledge completion, so as to update the entities, attributes, and relationships involved in the signaling process in the existing knowledge base, that is, to construct a signaling intention graph. Constructing a signaling intention graph can help security operation personnel improve their skill reserves, research and discover vulnerabilities, and enhance the security of 5G.

[0121] Furthermore, the results of knowledge extraction and knowledge fusion can be used to update the first domain ontology and the second domain ontology, thereby forming one or more more accurate intent entities. The constructed signaling intent graph can be used to generate more accurate signaling to be tested and the initial configuration vector of the signaling test environment, thus improving the efficiency of detecting potential security hazards.

[0122] As Figure 2 shown, a structural schematic diagram for implementing a method for determining a signaling adaptation environment is provided. It can be generally divided into four parts, corresponding to the above steps 100, 110, 120, and 130 respectively. Looking from top to bottom, in the first part, it is mainly used to construct the first domain ontology, the second domain ontology, and intent conditions. For the specific implementation content, refer to the above step 100; in the second part, the ontology automatic instantiation module obtains one or more intent entities according to the first domain ontology, the second domain ontology, and the intent conditions. Then, the one or more intent entities are transmitted to the signaling construction module, which constructs the signaling to be tested. At the same time, the initial configuration vector of the signaling test environment is constructed according to the network resources involved in the one or more intent conditions. For the specific implementation content, refer to the above step 110; in the third part, the signaling test environment is constructed using the initial configuration vector, and the signaling to be tested is input into the signaling test environment, and the signaling test environment is continuously adjusted until the signaling to be tested is adapted to the adjusted signaling test environment. For the specific implementation content, refer to the above steps 120 and 130; in the fourth part, an analysis report for communication security issues is generated based on the signaling to be tested and the adjusted signaling test environment, and the key information is extracted and fused for constructing a signaling intent graph. For the specific implementation content, refer to the above step 130.

[0123] In summary, the present application provides a method for determining a signaling adaptation environment. First, one or more intent entities related to communication security issues are determined. Based on the intent entity, a signaling to be tested and an initial configuration vector are obtained. The initial vector is used to construct a signaling test environment, and the signaling to be tested is input into the signaling test environment to verify whether the signaling to be tested is adapted to the signaling test environment. Among them, by continuously adjusting the configuration vector, the signaling test environment changes continuously until it adapts to the signaling to be detected. This method can discover more security hazards and vulnerabilities in different network environments, thereby improving the security of the 5G network. Among them, based on the constructed first domain ontology, second domain ontology, and specific intent conditions, signaling carrying specific task intents can be automatically generated, effectively improving the quality of data sources and facilitating the discovery of vulnerabilities in the 5G system. In addition, the server can record the configuration vector that successfully triggers a communication security problem in the test environment and the status information of the system operation to generate an analysis report, which can not only perform risk assessment and optimize security policies for the discovered security hazards and vulnerabilities, but also integrate this content into the existing knowledge base to construct a knowledge graph in the signaling domain. The constructed knowledge graph can update one or more intent entities again, thereby constructing more accurate signaling to be detected and initial configuration vectors. This method effectively solves the problem of automatic improvement and supplementation of 5G security knowledge and is conducive to subsequent 5G signaling attack recognition, security event analysis, etc.

[0124] Figure 3 and Figure 4 FIG. is a schematic structural diagram of a possible signaling adaptation environment determination device provided by an embodiment of the present invention. The signaling adaptation environment determination device can be used to implement the functions of the server in the above method embodiments.

[0125] As Figure 3 shown, the signaling adaptation environment determination device 300 includes a transceiver unit 310 and a processing unit 320.

[0126] The processing unit 320 is used to control the operation of the transceiver unit 310.

[0127] The processing unit 320 is used to determine one or more intent entities associated with the intent condition according to the first domain ontology, the second domain ontology, and the intent condition. The intent condition is used to characterize a communication security problem. Each intent entity is constructed based on the first domain ontology and the second domain ontology. The first domain ontology is used to represent the entities, attributes, and relationships involved in the signaling process, and the second domain ontology is used to represent the entities, attributes, and relationships involved in the network resources associated with the first domain ontology.

[0128] The processing unit 320 is further configured to determine an initial configuration vector of the signaling to be tested and a signaling test environment according to the one or more intent entities, where the initial configuration vector of the signaling test environment indicates network resources involved in the one or more intent entities.

[0129] The processing unit 320 is further configured to construct the signaling test environment according to the initial configuration vector of the signaling test environment.

[0130] The processing unit 320 is further configured to input the signaling to be tested into the signaling test environment, and adapt the signaling to be tested to the adjusted signaling test environment by adjusting the configuration vector of the signaling test environment.

[0131] In a possible implementation manner, when determining the signaling to be tested according to the one or more intent entities, the processing unit 320 is further configured to determine the signaling to be tested according to the one or more intent entities and a preset protocol specification, where the signaling to be tested is a signaling flow that meets the preset protocol specification.

[0132] In a possible implementation manner, when adapting the signaling to be tested to the signaling test environment by adjusting the configuration vector of the signaling test environment, the processing unit 320 is configured to determine a first configuration vector based on a preset algorithm, the initial configuration vector of the signaling test environment, and a preset configuration vector set; is further configured to construct the adjusted signaling test environment according to the first configuration vector; is further configured to input the signaling to be tested into the adjusted signaling test environment; and is configured to determine that the signaling to be tested is adapted to the adjusted signaling test environment if the adjusted signaling test environment has the communication security problem.

[0133] In a possible implementation manner, if the preset configuration vector set does not include the first configuration vector, the processing unit 320 is further configured to add the first configuration vector to the preset configuration vector set.

[0134] In a possible implementation manner, the first configuration vector indicates one or more of service elements, operating environments, network environments, configuration conditions, and security baselines.

[0135] In a possible implementation manner, the processing unit 320 is further configured to generate an analysis report for the communication security problem based on the signaling to be tested and the adjusted signaling test environment.

[0136] For a more detailed description of the above transceiver unit 310 and processing unit 320, reference can be directly made to Figure 1 the relevant descriptions in the method embodiments shown, which will not be elaborated here.

[0137] As shown Figure 4 in the figure, it is determined that the signaling adaptation environment device 400 includes a processor 410 and a communication interface 420. The processor 410 and the communication interface 420 are coupled to each other. It can be understood that the communication interface 420 can be a transceiver or an input / output interface. Optionally, the signaling adaptation environment device 400 may further include a memory 430, which is used to store instructions executed by the processor 410 or input data required for the processor 410 to run instructions or data generated after the processor 410 runs instructions.

[0138] When the signaling adaptation environment device 300 is used to implement Figure 1 the method shown in the figure, the processor 410 is used to implement the functions of the above-mentioned processing unit 320, and the communication interface 420 is used to implement the functions of the above-mentioned transceiver unit 310.

[0139] The division of units in the embodiments of the present application is illustrative. It is only a logical function division. In actual implementation, there may be other division methods. In addition, in each embodiment of the present application, each functional unit may be integrated in a processor, may exist alone physically, or two or more units may be integrated in one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of a software functional unit.

[0140] Based on the same inventive concept, the embodiments of the present application provide a computer-readable storage medium. The computer program product includes: computer program code. When the computer program code runs on a computer, it causes the computer to execute the method for determining the signaling adaptation environment as described in any of the foregoing. Since the principle of solving problems by the above computer-readable storage medium is similar to that of the method for determining the signaling adaptation environment, the implementation of the above computer-readable storage medium can refer to the implementation of the method, and the repeated parts will not be described again.

[0141] Based on the same inventive concept, the embodiments of the present application further provide a computer program product. The computer program product includes: computer program code. When the computer program code runs on a computer, it causes the computer to execute the method for determining the signaling adaptation environment as described in any of the foregoing. Since the principle of solving problems by the above computer program product is similar to that of the method for determining the signaling adaptation environment, the implementation of the above computer program product can refer to the implementation of the method, and the repeated parts will not be described again.

[0142] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0143] The present application is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram, as well as the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate means for implementing the functions specified in Figure 1 one or more of the flows Figure 1 or blocks or the combination of blocks.

[0144] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including instruction means that implement the functions specified in Figure 1 one or more of the flows Figure 1 or blocks or the combination of blocks.

[0145] Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalent technologies, the present application is also intended to include these changes and modifications.

Claims

1. A method for determining a signaling adaptation environment, characterized in that: The method includes: Determine one or more intent entities associated with the intent condition according to the first domain ontology, the second domain ontology and the intent condition, wherein the intent condition is used to characterize a communication security problem, each intent entity is constructed based on the first domain ontology and the second domain ontology, the first domain ontology is used to characterize entities, attributes and relationships involved in the signaling process, and the second domain ontology is used to characterize entities, attributes and relationships involved in network resources associated with the first domain ontology; Determine, according to the one or more intent entities, an initial configuration vector of a signaling to be tested and a signaling test environment, wherein the initial configuration vector of the signaling test environment indicates network resources involved in the one or more intent entities; Constructing the signaling test environment according to the initial configuration vector of the signaling test environment; The signaling to be tested is input into the signaling test environment, and the configuration vector of the signaling test environment is adjusted so that the signaling to be tested is adapted to the adjusted signaling test environment.

2. The method according to claim 1, characterized in that Determining the signaling to be tested according to the one or more intent entities includes: The signaling to be tested is determined according to the one or more intent entities and a preset protocol specification, and the signaling to be tested is a signaling flow that meets the preset protocol specification.

3. The method according to claim 1 or 2, characterized in that The method of adjusting the configuration vector of the signaling test environment so that the signaling to be tested is adapted to the signaling test environment includes: Determine a first configuration vector based on a preset algorithm, an initial configuration vector of the signaling test environment, and a preset configuration vector set; constructing an adjusted signaling test environment according to the first configuration vector; Inputting the signaling to be tested into the adjusted signaling test environment; If the communication security problem occurs in the adjusted signaling test environment, it is determined that the signaling to be tested is adapted to the adjusted signaling test environment.

4. The method according to claim 3, characterized in that Also includes: If the preset configuration vector set does not include the first configuration vector, the first configuration vector is added to the preset configuration vector set.

5. The method according to claim 3, characterized in that The first configuration vector indicates one or more of a service element, an operating environment, a network environment, a configuration condition, and a security baseline.

6. The method according to claim 1, characterized in that Also includes: An analysis report for the communication security issue is generated based on the signaling to be tested and the adjusted signaling test environment.

7. A device for determining a signaling adaptation environment, characterized in that: The device comprises: a transceiver unit and a processing unit; The processing unit controls the operation of the transceiver unit; The processing unit is used to determine one or more intent entities associated with the intent condition based on a first domain ontology, a second domain ontology and an intent condition, wherein the intent condition is used to characterize a communication security issue, and each intent entity is constructed based on the first domain ontology and the second domain ontology, wherein the first domain ontology is used to characterize entities, attributes and relationships involved in a signaling process, and the second domain ontology is used to characterize entities, attributes and relationships involved in network resources associated with the first domain ontology; it is also used to determine an initial configuration vector of a signaling to be tested and a signaling test environment based on the one or more intent entities, wherein the initial configuration vector of the signaling test environment indicates network resources involved in the one or more intent entities; it is also used to construct the signaling test environment based on the initial configuration vector of the signaling test environment; and it is used to input the signaling to be tested into the signaling test environment, and adapt the signaling to be tested to the adjusted signaling test environment by adjusting the configuration vector of the signaling test environment.

8. A device for determining a signaling adaptation environment, characterized in that: include: A memory for storing program instructions; A processor is used to call the program instructions stored in the memory, and execute the steps included in any one of claims 1-6 according to the obtained program instructions.

9. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, wherein the computer program includes program instructions, and when the program instructions are executed by a computer, the computer executes the method according to any one of claims 1 to 6.

10. A computer program product, characterized in that The computer program product comprises: a computer program code, and when the computer program code is run on a computer, the computer is enabled to execute the method according to any one of claims 1 to 6.