Safety monitoring method and device for mobile communication private line
Through the security monitoring methods and devices for mobile communication dedicated lines, vulnerability scanning and log analysis are used to identify device vulnerabilities and attack behaviors, the problem of mobile communication dedicated lines relying on administrator level is solved, and efficient security monitoring of mobile communication dedicated lines is achieved.
Patent Information
- Application Number
- CN202510517843.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-24
- Publication Date
- 2025-05-30
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Mobile communication dedicated lines have great security risks and hidden dangers in terms of operational security, which mainly rely on the level of administrators, resulting in uncertain security.
It provides a security monitoring method and device for mobile communication dedicated lines. It checks vulnerability hazards of AAA and LNS devices through vulnerability scanning tools, obtains the device's logs, configurations and database information, analyzes and identifies operational security hazards and suspected attacks, and alerts the management system.
It realizes continuous monitoring of the operation security of mobile communication dedicated lines, can identify the device's own vulnerabilities, operational security risks and suspected attacks, and meets the high security needs of key industry applications.
Smart Images

Figure CN120075805A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of communication technologies, and in particular, to a security monitoring method and device for mobile communication dedicated lines. Background Art
[0002] Since the cellular mobile communication system is the largest public infrastructure on land, many key industry applications provide mobile office applications based on the mobile operator dedicated line method, and it has become the mainstream method for the cellular mobile communication network to face industry applications, as Figure 1 shown.
[0003] Based on the operator dedicated line mode, key industries usually add AAA (Authentication, Authorization, and Accounting) and LNS (LonWorks Network Service) at the application side entrance to provide secondary authentication and access control capabilities, and add VPN (Virtual Private Network) at the terminal side and application side to provide end-to-end transmission encryption capabilities for services.
[0004] From the perspective of the overall security of the system, in addition to relying on design security and implementation security, it is also necessary to ensure operational security. In the cellular mobile communication dedicated line mode, its design security and implementation security are relatively mature, while its operational security involves aspects such as AAA devices, LNS devices themselves, dedicated line configurations, and security policy configurations, all of which depend on the level of the administrator himself. When facing key industry applications, this kind of security mainly relies on the uncertainty and difference of the administrator's own level, and there are relatively large security risks and hidden dangers.
[0005] Therefore, there is an urgent need for a security detection method and device for mobile communication dedicated lines to provide security detection and continuous monitoring capabilities for the operational security of the mobile communication dedicated line mode. Summary of the Invention
[0006] In view of the above problems, the present invention provides a security monitoring method and device for mobile communication dedicated lines.
[0007] In a first aspect, the present invention provides a security monitoring method for mobile communication dedicated lines, and the security monitoring method includes an AAA security monitoring method; The AAA security monitoring method includes the following steps: Assume that the mobile communication dedicated line has been deployed and all devices are operating normally; The security monitoring device checks whether there are potential vulnerabilities in the AAA device through a vulnerability scanning tool; Obtain the log files, configuration files, and database information of the AAA device: Parse the obtained log files, configuration files, and database information of the AAA device, and extract the necessary information, including abnormal log information, LNS device address, tunnel information, legal user information, and AAA authentication information; Based on the tunnel information, legal user information, and AAA authentication information obtained from the AAA device, identify whether there are potential security risks in the operation of the AAA device; Based on the abnormal log information, LNS device address, tunnel information, and legal user information obtained from the AAA device, identify whether there are suspected attack behaviors; When it is found that the AAA device has potential vulnerabilities, operation security risks, and / or suspected attack behaviors, immediately alarm the management system.
[0008] In some embodiments, when obtaining the log files, configuration files, and database information of the AAA device: If a monitoring suite can be deployed on the AAA device, collect the log files, configuration files, and database information of the AAA device through the deployed monitoring suite; If a monitoring suite cannot be deployed on the AAA device, the security monitoring device remotely obtains the log files, configuration files, and database information of the AAA device through remote login.
[0009] In some embodiments, the potential security risks in the operation of the AAA device include incorrect device configuration, authentication-free, and / or weak passwords with authentication.
[0010] In some embodiments, the suspected attack behaviors of the AAA device include tunnel spoofing and / or unauthorized user access.
[0011] In a second aspect, the present invention provides a security monitoring method for mobile communication dedicated lines, and the security monitoring method includes an LNS security monitoring method; The LNS security monitoring method includes the following steps: Assume that the mobile communication dedicated line has been deployed and all devices are operating normally; The security monitoring device uses a vulnerability scanning tool to check whether there are potential vulnerabilities in the LNS device; Obtain the necessary information of the LNS device, including the identity of the peer LAC, abnormal log information, tunnel information, and access control information; Combine the tunnel information and AAA authentication information obtained from the AAA device, and compare and analyze them with the tunnel information and access control information obtained from the LNS to identify whether there are potential security risks in the operation; Based on the LNS device address obtained from the AAA device, compare and analyze it with the peer LAC identity, exception log information, and tunnel information obtained from the LNS device to identify whether there is a suspected attack behavior; When it is found that the LNS device has potential vulnerabilities in the device itself, operation security risks, and / or suspected attack behaviors, immediately alarm the management system.
[0012] In some embodiments, remotely access the LNS device through the remote login method, and obtain necessary information through the CLI and / or command line.
[0013] In some embodiments, the operation security risks existing in the LNS device include incorrect tunnel configuration and / or unauthenticated access control policies.
[0014] In some embodiments, the suspected attack behaviors existing in the LNS device include tunnel spoofing, tunnel peer impersonation, and / or DoS.
[0015] In a third aspect, the present invention provides a security monitoring method for a mobile communication dedicated line, including: Assume that the mobile communication dedicated line has been deployed and all devices are operating normally; The security monitoring device uses a vulnerability scanning tool to check whether there are potential vulnerabilities in the AAA device and the LNS device; The security monitoring device obtains log files, configuration files, and database information from the AAA device, and parses out its necessary information, including exception log information, LNS device address, tunnel information, legitimate user information, and AAA authentication information; obtains its necessary information from the LNS device, including peer LAC identity, exception log information, tunnel information, and access control information; The security monitoring device identifies whether there are operation security risks in the AAA device according to the tunnel information, legitimate user information, and AAA authentication information obtained from the AAA device; combines the tunnel information and AAA authentication information obtained from the AAA device, and compares and analyzes them with the tunnel information and access control information obtained from the LNS to identify whether there are operation security risks in the LNS device; The security monitoring device identifies whether there are suspected attack behaviors in the AAA device according to the exception log information, LNS device address, tunnel information, and legitimate user information obtained from the AAA device; based on the LNS device address obtained from the AAA device, compare and analyze it with the peer LAC identity, exception log information, and tunnel information obtained from the LNS device to identify whether there are suspected attack behaviors in the LNS device; When it is found that the AAA device and the LNS device have potential vulnerabilities in the device itself, operation security risks, and / or suspected attack behaviors, immediately alarm the management system.
[0016] Fourthly, the present invention provides a security monitoring device for mobile communication dedicated lines to execute the above-mentioned security monitoring method for mobile communication dedicated lines, including a monitoring suite and a security monitoring device; The monitoring suite is deployed and runs on the AAA device, and is used to obtain log files, configuration files, and database information from the AAA device; The security monitoring device is used to obtain necessary information from the AAA device and the LNS device, and identify whether there are potential vulnerabilities in the devices themselves, operation security risks, and / or suspected attack behaviors in the AAA device and the LNS device, and alarm the management system.
[0017] In summary, due to the adoption of the above technical solutions, the beneficial effects of the present invention are as follows: 1. The present invention can obtain information such as device self-vulnerabilities, dedicated line configuration policies, AAA authentication policies, and LNS access control policies from the AAA device and the LNS device of the mobile communication dedicated line, so as to realize the monitoring ability of the operation security of the mobile communication dedicated line and meet the high security requirements of key industry applications.
[0018] 2. The present invention is applicable to dedicated line scenarios of 3G, 4G, and 5G cellular mobile communication systems and satellite Internet. Brief Description of the Drawings
[0019] Figure 1 It is a schematic diagram of a typical usage scenario for 5G applications in vertical industries.
[0020] Figure 2 It is a flowchart of the AAA security monitoring method in a security monitoring method for mobile communication dedicated lines provided by an embodiment of the present invention.
[0021] Figure 3 It is a flowchart of the LNS security monitoring method in a security monitoring method for mobile communication dedicated lines provided by an embodiment of the present invention.
[0022] Figure 4 It is a schematic diagram of a security monitoring device for mobile communication dedicated lines provided by an embodiment of the present invention.
[0023] Figure 5 It is a schematic diagram of the application of an embodiment of the present invention in the case of 5G mobile communication dedicated lines / slices.
[0024] Figure 6 It is a schematic diagram of the application of an embodiment of the present invention in the case of 4G mobile communication dedicated lines / slices.
[0025] Figure 7 It is a schematic diagram of the application of an embodiment of the present invention in the case of 3G mobile communication dedicated lines / slices.
[0026] Figure 8 This is a schematic diagram of the application of the embodiment of the present invention in the case of a satellite Internet dedicated line.
[0027] Definitions in the accompanying drawings: PGW (PDN GateWay, PDN gateway); PDN (Public Data Network, public data network); UPF (User Plane Function, user plane function); GGSN (Gateway GPRS Supporting Node, GPRS gateway support node); GPRS (General Packet Radio Service, general packet radio service). Specific embodiments
[0028] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. Usually, the components of the embodiments of the present invention described and illustrated in the accompanying drawings here can be arranged and designed in various different configurations.
[0029] Therefore, the following detailed description of the embodiments of the present invention provided in the accompanying drawings is not intended to limit the scope of the claimed present invention, but merely represents selected embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the scope of protection of the present invention.
[0030] The embodiments of the present invention disclose a security monitoring method for a mobile communication dedicated line, including an AAA security monitoring method and an LNS security monitoring method.
[0031] As Figure 2 shown, the AAA security monitoring method includes the following steps: S110. Assume that the mobile communication dedicated line has been deployed and all devices are operating normally; S120. The security monitoring device checks whether there are potential vulnerabilities in the AAA device through a vulnerability scanning tool, such as whether unnecessary IP addresses and ports are open, etc.; S130. Obtain the log file, configuration file, and database information of the AAA device: S131. If a monitoring suite can be deployed on the AAA device, collect the log file, configuration file, and database information of the AAA device through the deployed monitoring suite; S132. If the monitoring suite cannot be deployed on the AAA device, the security monitoring device remotely obtains the log file, configuration file, and database information of the AAA device through remote login. S140. Analyze the obtained log file, configuration file, and database information of the AAA device, and extract necessary information, including abnormal log information, LNS device address, tunnel information, legitimate user information, and AAA authentication information. S150. Based on the tunnel information, legitimate user information, and AAA authentication information obtained from the AAA device, identify whether there are operation security risks in the AAA device, including device configuration errors, authentication exemption, weak passwords for authentication, etc. S160. Based on the abnormal log information, LNS device address, tunnel information, and legitimate user information obtained from the AAA device, identify whether there are suspected attack behaviors, including tunnel spoofing, unauthorized user access, etc. S170. When risks such as device vulnerability risks, operation security risks, and / or suspected attack behaviors are found in the AAA device, immediately alarm the management system.
[0032] As Figure 3 shown, the LNS security monitoring method includes the following steps: S210. Assume that the mobile communication dedicated line has been deployed and all devices are running normally. S220. The security monitoring device uses a vulnerability scanning tool to check whether there are device vulnerability risks in the LNS device, such as open unnecessary IP addresses and port ranges, etc. S230. Obtain the necessary information of the LNS device, including the identity of the peer LAC, abnormal log information, tunnel information, and access control information. Specifically, through remote login, remotely access the LNS device, and obtain the necessary information through CLI, command line, etc. S240. Combine the tunnel information and AAA authentication information obtained from the AAA device, and compare and analyze them with the tunnel information and access control information obtained from the LNS to identify whether there are operation security risks, including tunnel configuration errors, access control policies without authentication, etc.
[0033] S250. Based on the LNS device address obtained from the AAA device, compare and analyze it with the identity of the peer LAC, abnormal log information, and tunnel information obtained from the LNS device to identify whether there are suspected attack behaviors, including tunnel spoofing, tunnel peer impersonation, DoS, etc.
[0034] S260. When risks such as potential vulnerabilities in the LNS device itself, operation security risks, and / or suspected attack behaviors are detected, immediately alert the management system.
[0035] The present invention also discloses a security monitoring device for mobile communication dedicated lines to support the above-mentioned security monitoring method for mobile communication dedicated lines. The device includes a monitoring suite and a security monitoring device, as Figure 4 shown.
[0036] The monitoring suite is deployed and runs on the AAA device, and is used to obtain log files, configuration files, and database information from the AAA device; The security monitoring device is used to obtain necessary information from the AAA device (including the monitoring suite) and the LNS device, identify whether there are potential vulnerabilities in the AAA device and the LNS device itself, operation security risks, and / or suspected attack behaviors, and alert the management system.
[0037] The following are some embodiments of the above-mentioned security monitoring method and device for mobile communication dedicated lines.
[0038] Embodiment 1 In the cases of 5G mobile communication dedicated lines, dedicated slices, etc., applying the above-mentioned security monitoring method and device for mobile communication dedicated lines, the relevant functional entities include: 5G terminals, 5G base stations, 5G public networks, LNS devices, AAA devices, security monitoring devices, and VPN devices, as Figure 5 shown.
[0039] The security monitoring method for mobile communication dedicated lines includes the following steps: S1. Assume that the mobile communication dedicated line has been deployed and all devices are operating normally; S2. The security monitoring device uses a vulnerability scanning tool to check whether there are potential vulnerabilities in the AAA device and the LNS device itself, such as open unnecessary IP addresses and ports, etc.; S3. The security monitoring device obtains log files, configuration files, and database information from the AAA device and parses out its necessary information, including abnormal log information, LNS device address, tunnel information, legal user information, and AAA authentication information; obtains its necessary information from the LNS device, including the identity of the peer LAC, abnormal log information, tunnel information, and access control information; S4. The security monitoring device identifies whether there are potential security risks in the AAA device based on the tunnel information, legal user information, and AAA authentication information obtained from the AAA device, including situations such as device configuration errors, authentication exemption, weak passwords with authentication, etc.; combines the tunnel information and AAA authentication information obtained from the AAA device, and conducts a comparative analysis with the tunnel information and access control information obtained from the LNS to identify whether there are potential security risks in the LNS device, including tunnel configuration errors, access control policies without authentication, etc. S5. The security monitoring device identifies whether there are suspected attack behaviors such as tunnel spoofing and / or unauthorized user access in the AAA device based on the abnormal log information, LNS device address, tunnel information, and legal user information obtained from the AAA device; based on the LNS device address obtained from the AAA device, conducts a comparative analysis with the peer LAC identity, abnormal log information, and tunnel information obtained from the LNS device to identify whether there are suspected attack behaviors such as tunnel spoofing, tunnel peer impersonation, and / or DoS in the LNS device. S6. When risks such as potential device vulnerabilities, potential operation security risks, and suspected attack behaviors are found in the AAA device and the LNS device, an alarm is immediately sent to the management system.
[0040] Embodiment 2 In the case of a 4G mobile communication dedicated line, applying the above security monitoring method and device for a mobile communication dedicated line, the relevant functional entities include: a 4G terminal, a 4G base station, a 4G public network, an LNS device, an AAA device, a security monitoring device, and a VPN device, as Figure 6 shown.
[0041] The security monitoring method for a mobile communication dedicated line includes the following steps: S1. Assume that the mobile communication dedicated line has been deployed and all devices are operating normally. S2. The security monitoring device uses a vulnerability scanning tool to check whether there are potential device vulnerabilities in the AAA device and the LNS device, such as open unnecessary IP addresses and ports, etc. S3. The security monitoring device obtains the log file, configuration file, and database information from the AAA device and parses out its necessary information, including abnormal log information, LNS device address, tunnel information, legal user information, and AAA authentication information; obtains its necessary information from the LNS device, including peer LAC identity, abnormal log information, tunnel information, and access control information. S4. The security monitoring device identifies whether there are potential security risks in the AAA device based on the tunnel information, legal user information, and AAA authentication information obtained from the AAA device, including situations such as device configuration errors, authentication exemption, weak passwords with authentication, etc.; combines the tunnel information and AAA authentication information obtained from the AAA device, and conducts a comparative analysis with the tunnel information and access control information obtained from the LNS to identify whether there are potential security risks in the LNS device, including tunnel configuration errors, access control policies without authentication, etc. S5. The security monitoring device identifies whether there are suspected attack behaviors such as tunnel spoofing and / or unauthorized user access in the AAA device based on the abnormal log information, LNS device address, tunnel information, and legal user information obtained from the AAA device; based on the LNS device address obtained from the AAA device, conducts a comparative analysis with the peer LAC identity, abnormal log information, and tunnel information obtained from the LNS device to identify whether there are suspected attack behaviors such as tunnel spoofing, tunnel peer impersonation, and / or DoS in the LNS device. S6. When risks such as potential vulnerabilities, operational security risks, and suspected attack behaviors are found in the AAA device and the LNS device, an alarm is immediately sent to the management system.
[0042] Embodiment III In the case of a 3G mobile communication dedicated line, applying the above security monitoring method and device for mobile communication dedicated lines, the relevant functional entities include: 3G terminals, 3G base stations, 3G public networks, LNS devices, AAA devices, security monitoring devices, and VPN devices, as Figure 7 shown.
[0043] The security monitoring method for mobile communication dedicated lines includes the following steps: S1. Assume that the mobile communication dedicated line has been deployed and all devices are operating normally. S2. The security monitoring device uses a vulnerability scanning tool to check whether there are potential vulnerabilities in the AAA device and the LNS device, such as open unnecessary IP addresses and ports, etc. S3. The security monitoring device obtains the log files, configuration files, and database information from the AAA device and parses out the necessary information, including abnormal log information, LNS device address, tunnel information, legal user information, and AAA authentication information; obtains the necessary information from the LNS device, including peer LAC identity, abnormal log information, tunnel information, and access control information. S4. The security monitoring device identifies whether there are operation security risks in the AAA device based on the tunnel information, legal user information, and AAA authentication information obtained from the AAA device, including situations such as device configuration errors, authentication exemption, weak passwords with authentication, etc.; combines the tunnel information and AAA authentication information obtained from the AAA device, and conducts a comparative analysis with the tunnel information and access control information obtained from the LNS to identify whether there are operation security risks in the LNS device, including tunnel configuration errors, access control policies without authentication, etc. S5. The security monitoring device identifies whether there are suspected attack behaviors such as tunnel spoofing and / or unauthorized user access in the AAA device based on the abnormal log information, LNS device address, tunnel information, and legal user information obtained from the AAA device; based on the LNS device address obtained from the AAA device, conducts a comparative analysis with the peer LAC identity, abnormal log information, and tunnel information obtained from the LNS device to identify whether there are suspected attack behaviors such as tunnel spoofing, tunnel peer impersonation, and / or DoS in the LNS device. S6. When risks such as device self-vulnerability hazards, operation security risks, and suspected attack behaviors are found in the AAA device and the LNS device, an alarm is immediately sent to the management system.
[0044] Embodiment 4 In the case of a satellite Internet dedicated line, the above security monitoring method and device for mobile communication dedicated lines are applied. The relevant functional entities include: satellite Internet terminals, satellites, gateway stations, 5G core networks, LNS devices, AAA devices, security monitoring devices, and VPN devices, as Figure 8 shown.
[0045] The security monitoring method for mobile communication dedicated lines includes the following steps: S1. Assume that the mobile communication dedicated line has been deployed and all devices are operating normally. S2. The security monitoring device checks whether there are device self-vulnerability hazards in the AAA device and the LNS device through a vulnerability scanning tool, such as opening unnecessary IP addresses and ports, etc. S3. The security monitoring device obtains the log file, configuration file, and database information from the AAA device and parses out its necessary information, including abnormal log information, LNS device address, tunnel information, legal user information, and AAA authentication information; obtains its necessary information from the LNS device, including peer LAC identity, abnormal log information, tunnel information, and access control information. S4. The security monitoring device identifies whether there are operation security risks in the AAA device based on the tunnel information, legal user information, and AAA authentication information obtained from the AAA device, including situations such as device configuration errors, authentication exemption, weak passwords with authentication, etc.; combines the tunnel information and AAA authentication information obtained from the AAA device, and conducts a comparative analysis with the tunnel information and access control information obtained from the LNS to identify whether there are operation security risks in the LNS device, including tunnel configuration errors, access control policies without authentication, etc. S5. The security monitoring device identifies whether there are suspected attack behaviors such as tunnel spoofing and / or unauthorized user access in the AAA device based on the abnormal log information, LNS device address, tunnel information, and legal user information obtained from the AAA device; based on the LNS device address obtained from the AAA device, conducts a comparative analysis with the peer LAC identity, abnormal log information, and tunnel information obtained from the LNS device to identify whether there are suspected attack behaviors such as tunnel spoofing, tunnel peer impersonation, and / or DoS in the LNS device. S6. When risks such as device self-vulnerability hazards, operation security risks, and suspected attack behaviors are found in the AAA device and the LNS device, an alarm is immediately sent to the management system.
[0046] The above are only the preferred embodiments of the present invention and are not used to limit the present invention. For those skilled in the art, the present invention can have various changes and modifications. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A security monitoring method for mobile communication dedicated lines, characterized in that: The security monitoring method includes an AAA security monitoring method; The AAA security monitoring method comprises the following steps: Assume that the mobile communication dedicated line has been deployed and all equipment is operating normally; The security monitoring device uses vulnerability scanning tools to check whether the AAA device has any hidden vulnerabilities. Get the log files, configuration files, and database information of the AAA device: Parse the obtained AAA device log files, configuration files and database information to extract necessary information, including abnormal log information, LNS device address, tunnel information, legal user information and AAA authentication information; Based on the tunnel information, legal user information, and AAA authentication information obtained from the AAA device, identify whether the AAA device has operational security risks; Identify suspected attack behaviors based on abnormal log information, LNS device address, tunnel information, and legitimate user information obtained from AAA devices; When the AAA device is found to have its own vulnerabilities, operational security risks and / or suspected attack behaviors, an alarm will be immediately sent to the management system.
2. The security monitoring method for mobile communication dedicated lines according to claim 1, characterized in that: When obtaining the log files, configuration files, and database information of the AAA device: If a monitoring suite can be deployed on the AAA device, the deployed monitoring suite collects log files, configuration files, and database information of the AAA device; If the monitoring suite cannot be deployed on the AAA device, the security monitoring device can remotely obtain the log files, configuration files, and database information of the AAA device through remote login.
3. The security monitoring method for mobile communication dedicated lines according to claim 1, characterized in that: The operational security risks of AAA devices include device configuration errors, no authentication, and / or authentication but weak passwords.
4. The security monitoring method for mobile communication dedicated lines according to claim 1, characterized in that: The suspected attack behaviors existing in the AAA device include tunnel deception and / or unauthorized user access.
5. A security monitoring method for mobile communication dedicated lines, characterized in that: The safety monitoring method includes an LNS safety monitoring method; The LNS safety monitoring method comprises the following steps: Assume that the mobile communication dedicated line has been deployed and all equipment is operating normally; The security monitoring device uses vulnerability scanning tools to check whether the LNS device has any hidden vulnerabilities. Obtain necessary information about the LNS device, including peer LAC identity, exception log information, tunnel information, and access control information; Combine the tunnel information and AAA authentication information obtained from the AAA device with the tunnel information and access control information obtained from the LNS to identify whether there are any operational security risks; Compare and analyze the LNS device address obtained from the AAA device with the peer LAC identity, abnormal log information, and tunnel information obtained from the LNS device to identify whether there is suspected attack behavior; When an LNS device is found to have vulnerabilities, operational security risks, and / or suspected attacks, an alarm is immediately sent to the management system.
6. The security monitoring method for mobile communication dedicated lines according to claim 5, characterized in that: Remotely access the LNS device through remote login and obtain necessary information through CLI and / or command line.
7. The security monitoring method for mobile communication dedicated lines according to claim 5, characterized in that: The operational security risks existing in the LNS device include tunnel configuration errors and / or unauthenticated access control policies.
8. The security monitoring method for mobile communication dedicated lines according to claim 7, characterized in that: The suspected attack behaviors existing in the LNS device include tunnel spoofing, tunnel peer impersonation and / or DoS.
9. A security monitoring method for mobile communication dedicated lines, characterized in that: include: Assume that the mobile communication dedicated line has been deployed and all equipment is operating normally; The security monitoring device uses vulnerability scanning tools to check whether the AAA device and LNS device have any hidden vulnerabilities. The security monitoring device obtains log files, configuration files, and database information from the AAA device, and parses out the necessary information, including abnormal log information, LNS device address, tunnel information, legal user information, and AAA authentication information; obtains the necessary information from the LNS device, including the peer LAC identity, abnormal log information, tunnel information, and access control information; The security monitoring device identifies whether the AAA device has operational security risks based on the tunnel information, legal user information, and AAA authentication information obtained from the AAA device; Combine the tunnel information and AAA authentication information obtained from the AAA device with the tunnel information and access control information obtained from the LNS to compare and analyze, and identify whether there are any operational security risks in the LNS device; The security monitoring device identifies whether the AAA device has suspected attack behavior based on the abnormal log information, LNS device address, tunnel information and legal user information obtained from the AAA device; the security monitoring device compares and analyzes the LNS device address obtained from the AAA device with the peer LAC identity, abnormal log information and tunnel information obtained from the LNS device to identify whether the LNS device has suspected attack behavior; When AAA devices and LNS devices are found to have device vulnerabilities, operational security risks and / or suspected attack behaviors, an alarm is immediately sent to the management system.
10. A security monitoring device for mobile communication dedicated lines, characterized in that: Includes monitoring kits and safety monitoring equipment; The monitoring suite is deployed and runs on the AAA device, and is used to obtain log files, configuration files and database information from the AAA device; The security monitoring device is used to obtain necessary information from the AAA device and the LNS device, identify whether the AAA device and the LNS device have device vulnerability risks, operation security risks and / or suspected attack behaviors, and send an alarm to the management system.
Citation Information
Patent Citations
Network security protection security method and system based on unit cell
CN114978584A
Method and device for monitoring LNS network element in network access authentication
CN116170297A
Access method, system and device of virtual private dial-up network and storage medium
CN117040862A
Internet private line management method and device
CN117478370A
Security protection method and device based on industrial internet
US20250023922A1