Method for generating and analyzing traffic statistical characteristics of signaling for NGAP protocol
Through the statistical feature generation and analysis method for NGAP protocol signaling traffic, the problem that traditional methods are difficult to deal with NGAP protocol signaling traffic is solved, the complete restoration of signaling sessions and accurate extraction of statistical features is achieved, the effect of data analysis and abnormal detection is improved, and communication security is ensured.
Patent Information
- Application Number
- CN202510165440.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-14
- Publication Date
- 2025-05-30
AI Technical Summary
Traditional traffic recombination, feature extraction and analysis methods are difficult to effectively handle NGAP protocol signaling traffic, and cannot completely restore signaling sessions or accurately extract statistical features unique to signaling streams, affecting the effects of data analysis and abnormal detection.
A statistical feature generation and analysis method for NGAP protocol signaling traffic is proposed, including collecting NGAP protocol signaling traffic, recombining NGAP protocol session signaling traffic in PCAP data packets, analyzing and generating CSV files, calculating signaling flow statistical features, and using fuzzy clustering algorithm to cluster the unique features of signaling flow.
By effectively reorganizing the signaling traffic of the NGAP protocol, the communication session can be completely restored, the accuracy of data analysis can be improved, the unique statistical characteristics of signaling traffic can be accurately extracted and analyzed, the understanding of network behavior and user activities can be improved, and abnormal behaviors in the network can be more effectively identified, ensuring communication security.
Smart Images

Figure CN120075869A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a method for generating and analyzing statistical features based on traffic recombination in the field of network traffic analysis, and particularly to a method for generating and analyzing statistical features of NGAP protocol signaling traffic. Background Art
[0002] In the 5G core network, the main task of the signaling network is to carry the control signaling of the core network, enabling communication between devices, network management, and scheduling of various services. Especially in the military field, the security and reliability of the signaling network are of particular importance because the military communication network is one of the important components determining combat capabilities and must be fast, accurate, concealed, and uninterrupted. Signaling traffic is transmitted using NGAP (Next Generation Application Protocol), which supports multi-homing and multi-stream characteristics, increasing the complexity and reliability of signaling transmission and ensuring communication continuity and stability in a highly dynamic battlefield environment. Signaling traffic contains rich user information and behavior data, which are highly valuable for data analysis and abnormal behavior detection. However, traditional traffic recombination, feature extraction, and analysis methods often have difficulty effectively processing signaling traffic for the NGAP protocol, unable to fully restore signaling sessions or accurately extract the unique statistical features of signaling flows for analysis, thus affecting the effectiveness of data analysis and anomaly detection. Therefore, methods for generating statistical features and analyzing signaling traffic recombination for the NGAP protocol are worthy of further exploration by researchers. Summary of the Invention
[0003] The present invention aims to solve the above problems of the prior art. A method for generating and analyzing statistical features of NGAP protocol signaling traffic is proposed. The technical solution of the present invention is as follows:
[0004] A method for generating and analyzing statistical features of NGAP protocol signaling traffic, comprising the following steps:
[0005] Step A. Collect NGAP (Next Generation Application Protocol) protocol signaling traffic in the 5G core network to obtain PCAP (Packet Capture) data packets;
[0006] Step B. Recombine the NGAP protocol session signaling traffic in the PCAP data packets;
[0007] Step C. Analyze the recombined NGAP protocol transmission signaling traffic and generate a CSV file;
[0008] Step D. Analyze the CSV file and calculate the generated signaling flow statistical features.
[0009] Step E. Use the fuzzy clustering algorithm to perform clustering analysis on the unique features of the signaling flow.
[0010] Further, the step A collects the NGAP protocol signaling traffic in the 5G core network to obtain PCAP data packets, including the following steps:
[0011] a1. Start the 5G core network console, set network element parameters, access the user equipment, and start Wireshark; (Wireshark is an open-source network protocol analysis tool widely used for network troubleshooting, performance monitoring, and security analysis. It can capture and detailedly analyze the data packets transmitted through the network, support multiple network protocols, and help users check network traffic, diagnose problems, and discover potential security vulnerabilities);
[0012] b1. Simulate signaling behavior and use Wireshark to capture the corresponding signaling data packets;
[0013] c1. Filter the signaling data packets to obtain the NGAP protocol transmission traffic. If the signaling data packets meet the preset conditions, proceed to step d1; otherwise, do not process.
[0014] d1. Export the signaling traffic as a PCAP file.
[0015] Further, the step B reorganizes the NGAP protocol session signaling traffic in the PCAP data packets, including the following steps:
[0016] a2. Use the fuzzy C-means clustering algorithm (the fuzzy C-means clustering algorithm is a clustering method based on fuzzy theory. Different from the traditional hard clustering method, the fuzzy C-means clustering algorithm allows each data point to belong to multiple clusters and represents its belonging degree to different clusters through membership) to perform intelligent clustering on the data packets with the same source, destination host, port, and protocol, and cache them;
[0017] b2. Merge the C2S stream and S2C stream in each buffer according to the time feature and the extracted key value to obtain the two-way signaling flow;
[0018] c2. Based on the session features and sequence association of the signaling flow, use different protocol signaling flow reorganization methods for different protocol signaling flows to reorganize the merged two-way signaling flow.
[0019] Further, caching the signaling flow in the step a2 includes the following steps:
[0020] Initialize the number of buffer areas m and the empty dictionary F for storing buffers;
[0021] Traverse each signaling flow, extract the identity identifier, and create a unique flow identifier for each buffer area;
[0022] Check whether the identity identifier exists in the initialized m buffer areas. If it exists, add the stream to the corresponding stream buffer area. If it does not exist, create a new stream buffer area and update the stream identifier;
[0023] Update the newly created buffer area to the buffer dictionary.
[0024] Furthermore, the merging of signaling streams in step b2 includes the following steps:
[0025] Traverse each signaling stream, and determine whether the signaling stream contains an IP layer. If it contains, extract the "source IP address", "source port", "destination IP address", "destination port", "timestamp", and "protocol" in the IP layer, and save them as the six-tuple identity information representing the signaling stream. If it does not contain, continue to traverse downwards;
[0026] Create a new stream grouping area, and determine whether the stream six-tuple information except the timestamp is within the stream grouping. If it exists, add the stream to the stream grouping;
[0027] If it does not exist, swap the source IP and destination IP in the six-tuple, and determine whether the swapped six-tuple information is within the stream grouping. If it exists, add the stream to the stream grouping;
[0028] If it does not exist, add the signaling stream corresponding to the tuple to the new stream grouping area.
[0029] Furthermore, the reorganization of bidirectional signaling streams in step c2 includes the following steps:
[0030] c21. Traverse each bidirectional signaling stream in the buffer area, and check whether the Info layer contains the INIT initialization request field. If it exists, continue to check whether the Info layer of the next signaling stream contains the INIT_ACK initialization response field. If it exists, continue to retrieve until the SHUTDOWN shutdown request field is found. Record the signaling stream number containing the SHUTDOWN COMPLETE shutdown completion field as n, and the signaling stream number containing the INIT field as m. If n is greater than m, import all signaling streams numbered from m to n into a new file and mark it as "started and ended". If it does not meet the requirements, go to step c22;
[0031] c22. Traverse each two-way signaling flow in the buffer, check whether the INIT field exists in the Info layer. If it exists, check whether the INIT_ACK field is included in the Info layer of the next signaling flow. If it exists, continue to traverse the signaling flow downward until a new INIT field appears in the Info layer. Record the No value of the signaling flow containing the new INIT field as n, and the No value of the signaling flow containing the first INIT field as m. If n is greater than m, input all the signaling flows from m to n into a new file and name it "started but not ended"; otherwise, go to step c23; c23. Traverse each two-way signaling flow in the buffer, check whether there is a SHUTDOWN field in the Info layer. Record the No value of the first signaling flow as n, and the No value of the signaling flow containing the first SHUTDOWN field as m. If n is greater than m, input all the signaling flows from m to n into a new file and name it "not started but ended"; otherwise, go to step c24;
[0032] c24. Traverse each two-way signaling flow in the buffer, check whether there are complete INIT and SHUTDOWN fields in the Info layer. Record the No value of the first signaling flow as n, and the No value of the last signaling flow as m. If n is greater than m, input all the signaling flows from m to n into a new file and name it "not started and not ended".
[0033] Further, the step C parses and reorganizes the NGAP protocol transmission signaling traffic and generates a CSV file, including the following steps:
[0034] Use Wireshark to parse the IP layer in the signaling flow, and save the fields of "ip.len", "ip.proto", "ip.src", and "ip.dst" in the IP layer for analyzing the size, protocol type, source IP address, and destination IP address of the network packet, so as to perform target identification and tracking;
[0035] Parse the SCTP layer in the signaling flow, and save the fields of "sctp.srcport", "sctp.dstport", "sctp.chunk_length", "sctp.verification_tag", and "sctp.checksum.status" in the SCTP layer for monitoring communication ports, data block lengths, verification tags, and checksum statuses to ensure the integrity and accuracy of communication;
[0036] Parse and save the fields of "ngap.NGAP_PDU", "ngap.procedureCode", and "ngap.value_element" in the NGAP layer.
[0037] Further, in step D, the CSV file is parsed to calculate and generate signaling flow statistical features, and the specific calculation features are as follows:
[0038] fw_pdum_flag: The number of occurrences of the "PDUSessionResourceModifyResponse" message, which is a PDU session resource modification response message in the NGAP layer of the packet;
[0039] fw_pduc_flag: The number of occurrences of the "PDUSessionResourceReleaseCommand" message, which is a command message for releasing PDU session resources in the NGAP layer of the packet;
[0040] fw_up_flag: The number of occurrences of the "UplinkNASTransport" message, which is a NAS data transmission command message sent from the terminal device to the 5G core network in the NGAP layer of the packet;
[0041] fw_do_flag: The number of occurrences of the "DownlinkNASTransport" message, which is a NAS data transmission command message sent from the 5G core network to the terminal device in the NGAP layer of the packet;
[0042] tot_nas_flag: The number of times the NAS message is carried in the Protocol field value of the packet;
[0043] fw_init_flag: The number of times the client sends an INIT message to the server in the SCTP layer of the packet;
[0044] tot_shut_flag: The number of times one endpoint sends a SHUTDOWN signal to another endpoint in the SCTP layer of the packet;
[0045] fw_ngre_flag: The number of occurrences of the "NGSetupRequest" message, which is a message for initiating the establishment of a new mobile network connection or configuring the mobile network in the NGAP layer of the packet;
[0046] bw_ngre_flag: The number of occurrences of the corresponding "NGSetupResponse" message in the NGAP layer of the packet.
[0047] Further, in step E, a fuzzy clustering algorithm is used to perform clustering analysis on the unique features of the signaling flow, including the following steps:
[0048] E1. Set the number of clusters C;
[0049] E2. Initialize the fuzzy factor m, the allowable error ε for iteration, the iteration count t = 0, and the membership matrix U(0);
[0050] E3. Calculate and update the membership matrix U according to the formula where k is the index of the cluster center, representing the cluster centers of other clusters, v k represents the cluster center of the k-th cluster, and n represents the number of data points in the dataset, i.e., the total number of data. And update the cluster center according to the formula where x i - v j is the distance from the data point x i to the cluster center v j .
[0051] E4. Check whether the change in the cluster center is less than a certain threshold or the maximum number of iterations is reached. If the termination condition is met, the iteration stops; if not, return to step E2 to continue the iteration;
[0052] E5. Output the final cluster center, output the membership matrix of each data point, and display their membership degrees to each cluster center.
[0053] The advantages and beneficial effects of the present invention are as follows:
[0054] By effectively reorganizing the signaling traffic of the real NGAP protocol, the present invention enables the complete restoration of communication sessions, thereby improving the accuracy of data analysis. By accurately extracting and analyzing the unique statistical features of the signaling traffic, the network behavior and user activities can be better understood. The present invention can more effectively identify abnormal behaviors in the network through the method for generating and analyzing the statistical features of the NGAP protocol signaling traffic, which is crucial for maintaining communication security, preventing service interruptions, etc.
[0055] Main innovations:
[0056] Reorganization and merging of signaling traffic:
[0057] In step B, the signaling traffic of the NGAP protocol in the re-PCAP file is reorganized, and different reorganization methods are adopted for different signaling flows. Among them, the packets with the same source, destination host, port, and protocol are merged through intelligent clustering, and the bidirectional signaling flow is reorganized according to the time characteristics and sequence association. The intelligent clustering method is used during the reorganization process to ensure the precise merging of the signaling flow. This method is more accurate than the traditional simple flow reorganization, can handle complex signaling behaviors, and ensures more accurate signaling data in network analysis.
[0058] Feature generation and statistics:
[0059] In steps C and, by parsing the reorganized signaling flow and generating a CSV file, statistical features of the signaling flow are calculated and generated (such as session modification, resource release, data transmission, etc.). This method conducts a detailed analysis of the signaling traffic through refined statistical features. These statistical features help to deeply understand the transmission mode of the NGAP protocol and provide support for subsequent data mining and anomaly detection.
[0060] Cluster analysis:
[0061] In step E, a fuzzy clustering algorithm is used to perform cluster analysis on the features of the signaling flow in order to identify and classify different types of signaling flow features. Using a fuzzy clustering algorithm instead of the traditional hard clustering method can handle the uncertainty and ambiguity in the signaling flow, thereby improving the flexibility and accuracy of clustering.
[0062] Beneficial effects: By accurately capturing, reorganizing, statistically analyzing, and clustering the signaling traffic of the NGAP protocol, the signaling flow features in the network can be more effectively identified and analyzed, optimizing network performance monitoring and fault troubleshooting. The fuzzy clustering algorithm provides a more flexible classification of signaling flows, avoiding the possible accuracy loss caused by the hard clustering method, contributing to the in-depth analysis of network behavior, and improving the accuracy of network traffic prediction.
[0063] Ingenuity and differences: By combining time features with the extracted key values for the merging of signaling flows, the accurate association between different signaling flows is ensured. This enables more refined classification and analysis of large-scale and complex network data sets, which traditional simple clustering methods often cannot handle due to this time correlation and complexity. Description of the drawings
[0064] Figure 1 is a schematic diagram of the overall functional structure of the preferred embodiment provided by the present invention.
[0065] Figure 2 is a flowchart of the signaling message reorganization of the NGAP protocol of the present invention.
[0066] Figure 3 is the determination accuracy rate of the present invention for the reorganization of signaling flows in various session states.
[0067] Figure 4 is the distribution trend of each signaling session of the present invention in the feature space of the extracted statistical characteristics.
[0068] Figure 5 is the cached signaling flow data.
[0069] Figure 6 is the merged signaling flow data.
[0070] Figure 7 is a flowchart for generating statistical features;
[0071] Figure 8 is the relationship diagram of features and samples;
[0072] Figure 9 is the cluster center value of the clustering result. Specific implementation manners
[0073] Next, the technical solutions in the embodiments of the present invention will be clearly and detailedly described with reference to the accompanying drawings in the embodiments of the present invention. The described embodiments are only a part of the embodiments of the present invention.
[0074] The technical solution for the present invention to solve the above technical problem is:
[0075] Embodiment 1: As Figure 1 shown, it is the overall structure schematic diagram of the present invention, and specifically includes the following steps:
[0076] Step A. Collect the NGAP protocol signaling traffic in the 5G core network to obtain PCAP data packets, which specifically includes the following steps:
[0077] a) Start the 5G core network console, set network element parameters, access the user equipment, and start Wireshark;
[0078] b) Simulate various signaling behaviors and use Wireshark to capture the corresponding signaling data packets;
[0079] c) Filter the signaling data packets to obtain the NGAP protocol transmission traffic. If the signaling data packets meet the preset conditions, go to step d; otherwise, do not process.
[0080] d) Export the qualified signaling traffic as a PCAP file.
[0081] Step B. Recombine the NGAP protocol session signaling traffic in the PCAP data packets, which specifically includes the following steps:
[0082] a) Intelligently cluster the data packets with the same source, destination host, port, and protocol, and cache them;
[0083] b) Merge the C2S stream and S2C stream in each buffer according to the time feature and the extracted key value to obtain a two-way signaling stream;
[0084] c) Based on the session feature and sequence association of the signaling stream, use different protocol signaling stream recombination methods for different protocol signaling streams to recombine the merged two-way signaling stream.
[0085] Step C. Analyze the recombined NGAP protocol transmission signaling traffic and generate a CSV file, including the following steps:
[0086] a) Use Wireshark to parse the IP layer in the signaling stream, and save the fields of "ip.len", "ip.proto", "ip.src", and "ip.dst" in the IP layer for analyzing the size, protocol type, source IP address, and destination IP address of network packets, so as to perform target identification and tracking;
[0087] b) Parse the SCTP layer in the signaling stream, and save the fields of "sctp.srcport", "sctp.dstport", "sctp.chunk_length", "sctp.verification_tag", and "sctp.checksum.status" in the SCTP layer for monitoring communication ports, data block lengths, verification tags, and checksum statuses to ensure the integrity and accuracy of communication;
[0088] c) Parse and save the fields of "ngap.NGAP_PDU", "ngap.procedureCode", and "ngap.value_element" in the NGAP layer.
[0089] Step D. Parse the CSV file and calculate the statistical features of the signaling stream. The specific calculation features are as follows:
[0090] a) fw_pdum_flag: The number of occurrences of the "PDUSessionResourceModifyResponse" message, which is a PDU session resource modification response message in the NGAP layer of the packet;
[0091] b) fw_pduc_flag: The number of occurrences of the "PDUSessionResourceReleaseCommand" message, which is a command message for releasing PDU session resources in the NGAP layer of the packet;
[0092] c) fw_up_flag: The number of occurrences of the "UplinkNASTransport" message, which is a NAS data transfer command message sent from the terminal device to the 5G core network in the NGAP layer of the packet;
[0093] d) fw_do_flag: The number of occurrences of the "DownlinkNASTransport" message, which is a NAS data transfer command message sent from the 5G core network to the terminal device in the NGAP layer of the packet;
[0094] e) tot_nas_flag: The number of times the Protocol field value carries NAS messages in the packet;
[0095] f) fw_init_flag: The number of times the client sends an INIT message to the server in the SCTP layer of the packet;
[0096] g) tot_shut_flag: The number of times an endpoint (e.g., the client) in the SCTP layer of the message sends a SHUTDOWN signal to another endpoint (e.g., the server);
[0097] h) fw_ngre_flag: The number of times the "NGSetupRequest" message for initiating the establishment of a new mobile network connection or configuring the mobile network appears in the NGAP layer of the message;
[0098] i) bw_ngre_flag: The number of times the corresponding "NGSetupResponse" message appears in the NGAP layer of the message.
[0099] Step E. Use the fuzzy clustering algorithm to perform clustering analysis on the unique features of the signaling flow, including the following steps:
[0100] a) Set the number of clusters C;
[0101] b) Initialize the fuzzy factor m, the allowable error ε for iteration, the number of iterations t = 0, and the membership matrix U(0);
[0102] c) According to the formula calculate and update the membership matrix U, and according to the formula update the cluster center, where x i -v j is the distance from the data point x i to the cluster center v j ;
[0103] d) Check whether the change in the cluster center is less than a certain threshold or reaches the maximum number of iterations. If the termination condition is met, the iteration stops; if not, return to step 2 to continue the iteration;
[0104] e) Output the final cluster center, output the membership matrix of each data point, and display their membership degrees to each cluster center.
[0105] Example 2: Taking the user online and offline services in the 5G core network as an example, the specific steps include:
[0106] Step 1: Collect the signaling traffic generated during the user online and offline signaling services in the core network and store it in a pcap file;
[0107] Step 2: Traverse each data packet, and perform intelligent clustering on the captured data packets according to the key information such as the source host, destination host, port, and protocol of the signaling data packet;
[0108] Step 3: For the merged two-way signaling flows in each buffer, based on the session characteristics and sequences of the signaling flows, different protocol signaling flow recombination methods are used for different protocol signaling flows to recombine the two-way signaling flows. The recombination flow chart is as shown in Figure 2 shown, and the recombination determination accuracy rate is as shown in Figure 3 shown;
[0109] Step 4: Analyze the recombined NGAP signaling flow to generate a CSV file;
[0110] Step 5: Analyze the CSV file to generate statistical features that can characterize the information of a signaling flow. The calculation process of the statistical features is as shown in Figure 4 shown, and the distribution trend of the signaling sessions in the extracted statistical feature space is as shown in Figure 5 shown;
[0111] Step 6: Use the fuzzy clustering algorithm to perform clustering analysis on the unique features of the signaling flows. The analysis result is as shown in 9. The higher the value, the more inclined the data point is to belong to the cluster, and the lower the value, the weaker the relationship between the data point and the cluster.
[0112] The systems, devices, modules or units illustrated in the above embodiments can be specifically implemented by computer chips or entities, or by products with certain functions.
[0113] It should also be noted that the term "including", "comprising" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, commodity or device. Without further limitation, an element defined by the statement "including a..." does not exclude the existence of another identical element in the process, method, commodity or device including the said element.
[0114] The above embodiments should be understood as being only used to illustrate the present invention and not to limit the protection scope of the present invention. After reading the content recorded in the present invention, those skilled in the art can make various changes or modifications to the present invention, and these equivalent changes and modifications also fall within the scope defined by the claims of the present invention.
Claims
1. A method for generating and analyzing NGAP protocol signaling traffic statistical features, characterized in that: The following steps are involved: Step A. Collect NGAP next generation application protocol signaling traffic in the 5G core network and obtain PCAP data packets to capture data packets; Step B. Reassemble the NGAP protocol session signaling traffic in the PCAP data packet; Step C. Parsing the reorganized NGAP protocol transmission signaling traffic and generating a CSV file; Step D: Parse the CSV file and calculate and generate signaling flow statistical features. Step E: Use fuzzy clustering algorithm to perform cluster analysis on the unique features of the signaling flow.
2. According to the method for generating and analyzing NGAP protocol signaling traffic statistics according to claim 1, it is characterized in that: The step A collects NGAP protocol signaling traffic in the 5G core network and obtains PCAP data packets, including the following steps: a 1. Start the 5G core network console, set network element parameters, access user equipment, and start Wireshark; Wireshark is an open source network protocol analysis tool that is widely used for network troubleshooting, performance monitoring, and security analysis. It can capture and analyze data packets transmitted over the network in detail, supports multiple network protocols, and helps users check network traffic, diagnose problems, and discover potential security vulnerabilities; b 1. Simulate signaling behavior and use Wireshark to capture the corresponding signaling data packets; c 1. Filter the signaling data packet to obtain the NGAP protocol transmission traffic. If the signaling data packet meets the preset conditions, proceed to step d1, otherwise no processing is performed; d 1. Export the signaling traffic as a PCAP file.
3. The method for generating and analyzing NGAP protocol signaling traffic statistics according to claim 1, characterized in that: The step B reassembles the NGAP protocol session signaling traffic in the PCAP data packet, including the following steps: a 2. The data packets with the same source, destination host, port and protocol are intelligently clustered using the fuzzy C-means clustering algorithm. The fuzzy C-means clustering algorithm is a clustering method based on fuzzy theory. Different from the traditional hard clustering method, the fuzzy C-means clustering algorithm allows each data point to belong to multiple clusters, and uses the membership degree to indicate its degree of belonging to different clusters, and caches them; b 2. Merge the C2S flow and S2C flow of each buffer area according to the time characteristics and the extracted key value to obtain a bidirectional signaling flow; c 2. Based on the session characteristics and sequence association of the signaling flow, different protocol signaling flow reorganization methods are used for different protocol signaling flows to reorganize the merged bidirectional signaling flows.
4. The method for generating and analyzing NGAP protocol signaling traffic statistics according to claim 3, characterized in that: The step a2 of caching the signaling flow includes the following steps: Initialize the number of buffers m and the empty dictionary F for storing the buffers; Traverse each signaling flow, extract the identity and create a unique flow identifier for each buffer; Check whether the identity exists in the initialized m buffers. If so, add the stream to the corresponding stream buffer. If not, create a new stream buffer and update the stream identifier. Update the buffer dictionary with the newly created buffer.
5. The method for generating and analyzing NGAP protocol signaling traffic statistics according to claim 3, characterized in that: The step b2 of merging the signaling flows includes the following steps: Traverse each signaling flow to determine whether the signaling flow contains an IP layer. If so, extract the "source IP address", "source port", "destination IP address", "destination port", "timestamp" and "protocol" in the IP layer and save them as the six-tuple identity information representing the signaling flow. If not, traverse downwards. Create a new flow grouping area, determine whether the flow six-tuple information excluding the timestamp is in the flow grouping, and if so, add the flow to the flow grouping; If it does not exist, swap the source IP and destination IP in the six-tuple, and determine whether the swapped six-tuple information is in the flow group. If it does, add the flow to the flow group; If it does not exist, the signaling flow corresponding to the tuple is added to the new flow grouping area.
6. The method for generating and analyzing NGAP protocol signaling traffic statistics according to claim 3, characterized in that: The step c2 reorganizes the bidirectional signaling flow, including the following steps: c21. Traverse each bidirectional signaling flow in the buffer area and check whether the Info layer contains the INIT initialization request field. If so, continue to check whether the Info layer of the next signaling flow contains the INIT_ACK initialization response field. If so, continue to search until the SHUTDOWN shutdown request field is found. Record the signaling flow containing the SHUTDOWN COMPLETE shutdown completion field as n, and the signaling flow containing the INIT field as m. If n is greater than m, import all signaling flows numbered from m to n into a new file and mark them as "started and ended". If not, go to step c22; c22. Traverse each bidirectional signaling flow in the buffer area and check whether the Info layer has an INIT field. If so, check whether the Info layer of the next signaling flow contains an INIT_ACK field. If so, continue to traverse the signaling flow until a new INIT field appears in the Info layer. Record that the No value of the signaling flow containing the new INIT field is n, and the No value of the signaling flow containing the first INIT field is m. If n is greater than m, enter all signaling flows from m to n into a new file and name it as started but not ended. Otherwise, go to step c23. c23. Traverse each bidirectional signaling flow in the buffer area, check whether there is a SHUTDOWN field in the Info layer, record the No value of the first signaling flow as n, and the No value of the signaling flow containing the first SHUTDOWN field as m. If n is greater than m, enter all signaling flows from m to n into a new file and name it as Not Started but Ended. Otherwise, go to step c24. c24. Traverse each bidirectional signaling flow in the cache area, check whether there are complete INIT fields and SHUTDOWN fields in the Info layer, record the No value of the first signaling flow is n, and the No value of the last signaling flow is m. If n is greater than m, enter all signaling flows from m to n into a new file and name it as Not Started and Not Ended.
7. The method for generating and analyzing NGAP protocol signaling traffic statistics according to claim 1, characterized in that: The step C parses the reorganized NGAP protocol transmission signaling traffic and generates a CSV file, including the following steps: Use Wireshark to parse the IP layer in the signaling stream and save the "ip.len", "ip.proto", "ip.src" and "ip.dst" fields in the IP layer to analyze the size, protocol type, source IP address and destination IP address of the network packet for target identification and tracking; Parse the SCTP layer in the signaling stream and save the "sctp.srcport", "sctp.dstport", "sctp.chunk_length", "sctp.verification_tag" and "sctp.checksum.status" fields in the SCTP layer to monitor the communication port, data block length, verification tag and checksum status to ensure the integrity and accuracy of the communication; Parse and save the "ngap.NGAP_PDU", "ngap.procedureCode" and "ngap.value_element" fields in the NGAP layer.
8. The method for generating and analyzing NGAP protocol signaling traffic statistics according to claim 1, characterized in that: The step D parses the CSV file and calculates and generates the statistical features of the signaling flow. The specific calculation features are as follows: fw_pdum_flag: the number of times the PDU session resource modification response message "PDUSessionResourceModifyResponse" appears in the NGAP layer of the message; fw_pduc_flag: the number of times the PDU session resource release command message "PDUSessionResourceReleaseCommand" appears in the NGAP layer of the message; fw_up_flag: the number of occurrences of the NAS data transmission command message "UplinkNASTransport" sent from the terminal device to the 5G core network in the NGAP layer of the message; fw_do_flag: the number of occurrences of the NAS data transmission command message "DownlinkNASTransport" sent by the 5G core network to the terminal device in the NGAP layer of the message; tot_nas_flag: the number of times the Protocol field value in the message carries a NAS message; fw_init_flag: The number of times the client sends an INIT message to the server in the SCTP layer of the message; tot_shut_flag: The number of times one endpoint sends a SHUTDOWN signal to another endpoint in the SCTP layer of the message; fw_ngre_flag: The number of times the "NGSetupRequest" message appears in the NGAP layer to initiate a new mobile network connection or configure the mobile network; bw_ngre_flag: The number of times the corresponding message "NGSetupResponse" appears in the NGAP layer of the message.
9. The method for generating and analyzing NGAP protocol signaling traffic statistics according to claim 1, characterized in that: The step E. uses a fuzzy clustering algorithm to perform cluster analysis on the unique features of the signaling flow, including the following steps: E1. Set the number of clusters C; E2, initialize the fuzzy factor m, the allowed error ε, the number of iterations t = 0 and the membership matrix U (0); E3. According to the formula Calculate and update the membership matrix U, where k is the index of the cluster center, representing the cluster center of other clusters, v k represents the cluster center of the kth cluster, n represents the number of data points in the data set, that is, the total number of data, and according to the formula Update the cluster center, where x i -v j is the data point x i To cluster center v j distance; E4, check whether the change of cluster center is less than a certain threshold or reaches the maximum number of iterations. If the termination condition is met, the iteration stops; if not, return to step E2 to continue iteration; E5. Output the final cluster center and the membership matrix of each data point, showing their membership to each cluster center.