Wireless service security detection method and device, equipment and storage medium
By obtaining topological correlation information between the BBU device and the bearer device, determining the loop information of the bearer device, and conducting bearer security detection of wireless services, the problem of low accuracy in wireless service security judgment in the prior art is solved, and higher detection accuracy and network security are achieved.
Patent Information
- Application Number
- CN202311706799.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-12
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2043-12-12
AI Technical Summary
The prior art cannot accurately realize the accurate correlation between BBU equipment and the bearer equipment, resulting in low accuracy in wireless service security judgment results.
By acquiring topological association information between the BBU device and the multiple bearer devices, the loop information of each bearer device is determined, and the bearer security detection processing of wireless services is performed based on this information.
It improves the accuracy of wireless service security detection results, ensures the accurate correlation between BBU equipment and the bearer equipment, and enhances the robustness of the network and user perception.
Smart Images

Figure CN120151882A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technologies, and in particular, to a method, apparatus, device, and storage medium for detecting the security of wireless services. Background Art
[0002] In the 4G and 5G eras, with the application and popularization of large-capacity BBU devices and CRAN architectures (centralized deployment of BBU), the scale of BBU devices carried by the bearing devices in the wireless service access points and / or the BBU device concentration points gradually increases. The security of the bearing devices has a significantly increased impact on the robustness of the 4G and 5G wireless service networks and user perception. Therefore, the security situation of the BBU devices can be determined based on the ring formation situation of the bearing devices, and the security of the wireless services can be evaluated according to the security situation of the BBU devices.
[0003] In the prior art, manual annotation and physical computer room matching methods are mainly used to associate the ring formation situation of the bearing devices with the security situation of the BBU devices. Among them, the manual annotation method is to directly annotate the ring formation situation of the bearing devices on the BBU devices, or to annotate the ID of the BBU device carried on each bearing device port, so that the security situation of the BBU devices can be determined based on the ring formation situation of the bearing devices; the physical computer room matching method is to judge the security situation of the BBU devices according to the ring formation ratio of the bearing devices, where the bearing devices and the BBU devices are in the same computer room.
[0004] However, with the gradual evolution of the bearer network, both the manual annotation and the physical computer room matching method cannot accurately achieve the precise association between the BBU devices and the bearing devices, resulting in a low accuracy of the judgment result of the wireless service security. Summary of the Invention
[0005] This application provides a method, apparatus, device, and storage medium for detecting the security of wireless services, so as to solve the problem that due to the inability of both the manual annotation and the physical computer room matching method to accurately achieve the precise association between the BBU devices and the bearing devices, the accuracy of the judgment result of the wireless service security is low.
[0006] In a first aspect, this application provides a method for detecting the security of wireless services, including:
[0007] Obtain the topological association information between the BBU device and multiple bearing devices, where the topological association information includes: the association relationship between the BBU device and the bearing devices in the corresponding bearer network, and the connection relationship between the multiple bearing devices;
[0008] Determine the ring formation information of each bearing device according to the connection relationship between the multiple bearing devices, where the ring formation information is used to indicate whether the corresponding bearing device forms a ring;
[0009] Perform a bearer security detection process on the wireless services corresponding to the BBU device according to the ring formation information of multiple bearer devices.
[0010] Optionally, the obtaining of the topological association information between the BBU device and multiple bearer devices includes:
[0011] Obtain the first MAC address of the backhaul interface of the BBU device and the bearer device information of multiple candidate bearer devices, where the bearer device information is used to indicate the interface address and interface name of the corresponding candidate bearer device;
[0012] Determine the interface type of each candidate bearer device according to the interface names of multiple candidate bearer devices;
[0013] Determine multiple bearer devices associated with the BBU device from multiple candidate bearer devices according to the interface addresses, the interface type, and the first MAC address of multiple candidate bearer devices;
[0014] Obtain the connection relationship between multiple bearer devices according to the bearer device information of the multiple bearer devices.
[0015] Optionally, the interface type includes: physical interface type and virtual interface type. The determining of multiple bearer devices associated with the BBU device from multiple candidate bearer devices according to the interface addresses, the interface type, and the first MAC address of multiple candidate bearer devices includes:
[0016] If the interface type is a physical interface type, perform a parsing process on the interface address of the candidate bearer device to obtain the second MAC address of the candidate bearer device, where the interface address is an IP address;
[0017] When the first MAC address and the second MAC address are the same, determine the candidate bearer device as a bearer device associated with the BBU device;
[0018] If the interface type is a virtual interface type, determine the corresponding L2 VPN service instance according to the interface address of the candidate bearer device, and determine the bridging mode of the candidate bearer device according to the number of bridges corresponding to the L2 VPN service instance;
[0019] When the bridging mode is the first bridging mode, query the remote IP corresponding to the candidate bearer device according to the L2 VPN service instance, and when the remote IP matches the first MAC address, determine the candidate bearer device as a bearer device associated with the BBU device;
[0020] When the bridging mode is the second bridging mode, determine whether the L2 VPN service instance matches the first MAC address and the Loopback address of the candidate bearer device;
[0021] If they match, determine that the candidate bearer device is a bearer device associated with the BBU device.
[0022] Optionally, the determining the loop formation information of each bearer device according to the connection relationship between the multiple bearer devices includes:
[0023] Obtain the hierarchical position of the bearer device in the bearer network;
[0024] Perform loop identification on the multiple bearer devices according to the connection relationship between the multiple bearer devices and the hierarchical position, and determine whether each bearer device forms a loop.
[0025] Optionally, the determining the loop formation information of each bearer device according to the connection relationship between the multiple bearer devices includes:
[0026] Obtain the geographical location of the bearer device and the geographical location of the BBU device;
[0027] Determine whether the geographical location of the bearer device is the same as the geographical location of the BBU device;
[0028] When the geographical location of the bearer device is not the same as the geographical location of the BBU device, determine that the loop formation information of the bearer device is not in a loop.
[0029] Optionally, the performing bearer security detection processing on the wireless service corresponding to the BBU device according to the loop formation information of the multiple bearer devices includes:
[0030] When the bearer device forms a loop, determine whether the loop corresponding to the bearer device is identified as a large loop, where the large loop is used to indicate that the number of bearer devices on the loop is greater than the first preset number;
[0031] When the loop corresponding to the bearer device is identified as a large loop, determine that the bearer security detection result of the wireless service corresponding to the BBU device has a first security risk.
[0032] Optionally, the performing bearer security detection processing on the wireless service corresponding to the BBU device according to the loop formation information of the multiple bearer devices includes:
[0033] When the bearer device does not form a loop, determine that the bearer security detection result of the wireless service corresponding to the BBU device has a second security risk;
[0034] When the bearing device is not in a loop, determine whether the bearing device is identified as a long chain, where the long chain is used to indicate that the number of bearing devices under the same connection cable is greater than a second preset number;
[0035] If the single chain corresponding to the bearing device is identified as a long chain, determine that the wireless service bearing security detection result corresponding to the BBU device has a first security risk and the second security risk.
[0036] In a second aspect, the present application provides a wireless service security detection device, including:
[0037] An acquisition module, configured to acquire topology association information between a BBU device and a plurality of bearing devices, where the topology association information includes: the association relationship between the BBU device and the bearing devices in the corresponding bearing network and the connection relationship between the plurality of bearing devices;
[0038] A determination module, configured to determine the loop information of each bearing device according to the connection relationship between the plurality of bearing devices, where the loop information is used to indicate whether the corresponding bearing device is in a loop;
[0039] A processing module, configured to perform bearing security detection processing on the wireless service corresponding to the BBU device according to the loop information of the plurality of bearing devices.
[0040] Optionally, the acquisition module is further configured to acquire the first MAC address of the backhaul interface of the BBU device and the bearing device information of a plurality of candidate bearing devices, where the bearing device information is used to indicate the interface address and interface name of the corresponding candidate bearing device;
[0041] The determination module is further configured to determine the interface type of each candidate bearing device according to the interface names of the plurality of candidate bearing devices;
[0042] The determination module is further configured to determine a plurality of bearing devices associated with the BBU device from the plurality of candidate bearing devices according to the interface addresses, the interface type, and the first MAC address of the plurality of candidate bearing devices;
[0043] The determination module is further configured to obtain the connection relationship between the plurality of bearing devices according to the bearing device information of the plurality of bearing devices.
[0044] Optionally, the wireless service security detection device further includes: a judgment module;
[0045] The processing module is further configured to, if the interface type is a physical interface type, perform parsing processing on the interface address of the candidate bearing device to obtain the second MAC address of the candidate bearing device, where the interface address is an IP address;
[0046] The determining module is further configured to determine that the candidate bearer device is a bearer device associated with the BBU device when the first MAC address is the same as the second MAC address;
[0047] The determining module is further configured to, if the interface type is a virtual interface type, determine a corresponding L2 VPN service instance according to the interface address of the candidate bearer device, and determine the bridging mode of the candidate bearer device according to the number of bridges corresponding to the L2 VPN service instance;
[0048] The determining module is further configured to, when the bridging mode is the first bridging mode, query the remote IP corresponding to the candidate bearer device according to the L2 VPN service instance, and determine that the candidate bearer device is a bearer device associated with the BBU device when the remote IP matches the first MAC address;
[0049] The judging module is configured to judge whether the L2 VPN service instance matches the first MAC address and the Loopback address of the candidate bearer device when the bridging mode is the second bridging mode;
[0050] The determining module is further configured to determine that the candidate bearer device is a bearer device associated with the BBU device if the L2 VPN service instance matches the first MAC address and the Loopback address of the candidate bearer device.
[0051] Optionally, the obtaining module is further configured to obtain the hierarchical position of the bearer device in the bearer network;
[0052] The processing module is further configured to perform loop determination on the multiple bearer devices according to the connection relationship and the hierarchical position among the multiple bearer devices;
[0053] The judging module is further configured to judge whether each bearer device forms a loop.
[0054] Optionally, the obtaining module is further configured to obtain the geographical location of the bearer device and the geographical location of the BBU device;
[0055] The judging module is further configured to judge whether the geographical location of the bearer device is the same as the geographical location of the BBU device;
[0056] The determining module is further configured to determine that the loop formation information of the bearer device is non-looping when the geographical location of the bearer device is different from the geographical location of the BBU device.
[0057] Optionally, the determining module is further configured to, when the bearer device forms a loop, determine whether the loop corresponding to the bearer device is recognized as a large loop, where the large loop is used to indicate that the number of bearer devices on the loop is greater than a first preset number;
[0058] The determining module is further configured to, when the loop corresponding to the bearer device is recognized as a large loop, determine that the wireless service bearer security detection result corresponding to the BBU device has a first security risk.
[0059] Optionally, the determining module is further configured to, when the bearer device does not form a loop, determine that the wireless service bearer security detection result corresponding to the BBU device has a second security risk;
[0060] The determining module is further configured to, when the bearer device does not form a loop, determine whether the bearer device is recognized as a long chain, where the long chain is used to indicate that the number of bearer devices under the same connection cable is greater than a second preset number;
[0061] The determining module is further configured to, if the single chain corresponding to the bearer device is recognized as a long chain, determine that the wireless service bearer security detection result corresponding to the BBU device has the first security risk and the second security risk.
[0062] In a third aspect, the present application provides a wireless service security detection device, including:
[0063] A memory;
[0064] A processor;
[0065] Wherein, the memory stores computer execution instructions;
[0066] The processor executes the computer execution instructions stored in the memory to implement the wireless service security detection method as described in the first aspect and all possible implementations of the first aspect.
[0067] In a fourth aspect, the present application provides a computer storage medium, characterized in that the computer storage medium stores computer execution instructions, and when the computer execution instructions are executed by a processor, they are used to implement the wireless service security detection method as described in the first aspect and all possible implementations of the first aspect.
[0068] The wireless service security detection method provided by this application obtains the topological association information between the BBU device and multiple bearer devices. The topological association information includes: the association relationship between the BBU device and the bearer devices in the corresponding bearer network, and the connection relationship between the multiple bearer devices. According to the connection relationship between the multiple bearer devices, the loop information of each bearer device is determined. The loop information is used to indicate whether the corresponding bearer device forms a loop. According to the loop information of the multiple bearer devices, the bearer security detection process is performed on the wireless service corresponding to the BBU device. By establishing the topological relationship between the BBU device and the bearer devices, the accuracy of the wireless service security detection result is improved. BRIEF DESCRIPTION OF THE DRAWINGS
[0069] The accompanying drawings herein are incorporated into and constitute a part of this specification, showing embodiments consistent with the present application, and are used together with the specification to explain the principles of the present application.
[0070] Figure 1 is the flowchart of the wireless service security detection method provided by this application Figure 1 ;
[0071] Figure 2 is the flowchart of the wireless service security detection method provided by this application Figure 2 ;
[0072] Figure 3 is the flowchart of the wireless service security detection method provided by this application Figure 3 ;
[0073] Figure 4 is the structural schematic diagram of the wireless service security detection device provided by this application;
[0074] Figure 5 is the structural schematic diagram of the wireless service security detection equipment provided by this application.
[0075] Through the above-mentioned accompanying drawings, specific embodiments of the present application have been shown, and there will be more detailed descriptions hereinafter. These drawings and written descriptions are not intended to limit the scope of the concept of the present application in any way, but to illustrate the concept of the present application to those skilled in the art by referring to specific embodiments. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0076] Exemplary embodiments will be described in detail herein, and examples thereof are shown in the drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present application. On the contrary, they are merely examples of devices and methods consistent with some aspects of the present application as detailed in the appended claims.
[0077] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data that have been authorized by the user or fully authorized by all parties. Moreover, the collection, use, and processing of relevant data need to comply with relevant laws, regulations, and standards, and corresponding operation entrances are provided for users to choose to authorize or refuse.
[0078] 4. In the 5G era, with the application and popularization of large-capacity BBU devices and CRAN architectures (centralized deployment of BBU), the scale of BBU devices carried by wireless service access points and / or BBU device concentration points in the bearer device access gradually increases. The security of the bearer device has a significantly enhanced impact on the robustness of the 4G / 5G wireless service network and user perception. Therefore, the security situation of the BBU device can be determined based on the loop formation situation of the bearer device, and the security of the wireless service can be evaluated according to the security situation of the BBU device.
[0079] In the prior art, the loop formation situation of the bearer device and the security situation of the BBU device are mainly associated by using manual annotation and physical machine room matching methods. Among them, the manual annotation method is to directly annotate the loop formation situation of the bearer device on the BBU device, or annotate the ID of the BBU device carried on each bearer device port, so that the security situation of the BBU device can be determined based on the loop formation situation of the bearer device; the physical machine room matching method is to judge the security situation of the BBU device according to the loop formation ratio of the bearer device, where the bearer device and the BBU device are in the same machine room.
[0080] However, with the gradual evolution of the bearer network, both the manual annotation and physical machine room matching methods cannot accurately achieve the precise association between the BBU device and the bearer device, resulting in a problem of low accuracy of the wireless service security detection result.
[0081] To address the above problems, this application proposes a method for detecting the security of wireless services. By obtaining the association relationship between the BBU device and the bearer devices in the corresponding bearer network and the connection relationship between the multiple bearer devices, the loop formation information of each bearer device is determined according to the connection relationship between the multiple bearer devices. The loop formation information is used to indicate whether the corresponding bearer device forms a loop. Based on the loop formation information of multiple bearer devices, the bearer security detection process is performed on the wireless service corresponding to the BBU device. This method improves the accuracy of the wireless service security detection result by establishing the topological relationship between the BBU device and the bearer device.
[0082] The technical solution of the present application and how the technical solution of the present application solves the above-mentioned technical problems are described in detail below with specific embodiments. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present application will be described below in conjunction with the accompanying drawings.
[0083] Figure 1 The process of the wireless service security detection method provided in this application Figure 1 .like Figure 1 As shown, the wireless service security detection method shown in this embodiment includes:
[0084] S101: Acquire topology association information between a BBU device and multiple bearer devices, where the topology association information includes: an association relationship between the BBU device and a bearer device in a corresponding bearer network and a connection relationship between the multiple bearer devices.
[0085] The bearer network includes an access layer, an aggregation layer, and a core layer, and each layer corresponds to multiple bearer devices. The bearer device corresponding to the access layer is an access device, the bearer device corresponding to the aggregation layer is an aggregation device, and the bearer device corresponding to the core layer is a core device.
[0086] A bearer network is a network used to transmit business data. It can be composed of transmission equipment and bearer equipment. The transmission equipment can be: transmission media such as optical fiber, cable and microwave, and the bearer equipment can be: routers, switches, gateways and other equipment.
[0087] The BBU device is one of the main devices of the mobile base station, responsible for baseband digital signal processing. It generally includes two types of interfaces: fronthaul and backhaul. The fronthaul interface is connected to the RRU or AAU through optical fiber, and the backhaul interface is connected to the 4G and 5G core network elements through the bearer network equipment. This embodiment mainly takes 4G BBU devices and 5G BBU devices as examples for explanation.
[0088] At present, 4G BBU is mainly carried on the IPRAN network, and the IP address format is IPv4. The IPRAN network carrying solutions include end-to-end L3VPN layered carrying solution and end-to-end L2+L3 carrying solution (access layer L2+core aggregation layer L3, the aggregation device performs second and third layer bridging); 5G BBU is mainly carried on the intelligent metropolitan area network, adopting an end-to-end L3VPN layered carrying solution, and the IP address format is IPv6.
[0089] The association relationship between the BBU device and the bearer devices in the corresponding bearer network is determined by the network architecture and device configuration. Usually, the BBU device is part of a distributed base station architecture located between the access network and the switch, while the bearer network is a network used to transmit various voice and data services, usually using optical fiber as the transmission medium.
[0090] The connection relationship between multiple bearer devices is usually determined by network design and configuration. In the bearer network, the connection methods between bearer devices (such as routers, switches, SDH, etc.) can be flexibly configured according to factors such as network scale, topology structure, and service requirements.
[0091] The association relationship between the BBU device and the bearer devices in the corresponding bearer network is achieved through optical fiber connection. This connection method enables the mobile communication network to provide faster and more stable data transmission and communication services, thus meeting the needs of users.
[0092] S102: Determine the loop information of each bearer device according to the connection relationship between the multiple bearer devices, where the loop information is used to indicate whether the corresponding bearer device forms a loop.
[0093] Determining the loop information of each bearer device requires analyzing the connection relationship between multiple bearer devices. First, it is necessary to clarify the connection relationship between each bearer device, including: physical connection and virtual connection. Physical connection refers to the physical link connection between bearer devices, for example: optical fiber connection; virtual connection refers to the communication protocol and routing configuration between devices, for example: IP routing configuration.
[0094] According to the connection relationship between multiple bearer devices, judge whether there are conditions for forming a loop. If there are conditions for multiple devices to form a loop, then there is a loop; for the bearer devices with a loop, it is necessary to determine the starting point and ending point of the loop, the path of the loop, and the bandwidth of the loop.
[0095] Determining the loop information of each bearer device is crucial for network troubleshooting and optimization, which helps to improve the reliability and performance of the network. At the same time, corresponding network design and configuration can also be carried out according to the loop information to avoid potential network problems.
[0096] S103: Perform bearer security detection and processing on the wireless services corresponding to the BBU device according to the loop information of multiple bearer devices.
[0097] According to the loop information of multiple bearer devices, bearer security detection and processing can be performed on the wireless services corresponding to the BBU device. The detection can be carried out from the following aspects:
[0098] 1. Loop detection: By detecting the loop information of the bearing device, it is possible to determine whether there is a loop and perform corresponding processing according to the actual situation. For example: closing the loop and adjusting the network configuration, etc., to ensure the bearing security of wireless services.
[0099] 2. Network optimization: According to the loop information of the bearing device, the network can be optimized to improve the bearing efficiency and security of wireless services. For example: by adjusting the configuration of network devices, optimizing routing protocols and other measures, the performance and reliability of the network can be improved to meet the growing demand for wireless services.
[0100] 3. Security policy formulation: By analyzing the loop information of the bearing device, corresponding security policies can be formulated to protect the security of wireless services. For example: by setting up firewalls, implementing access control and other measures, unauthorized access and attacks can be prevented, and the data security and integrity of wireless services can be protected.
[0101] According to the loop information of multiple bearing devices, bearing security detection and processing can be performed on the wireless services corresponding to the BBU device. This processing can ensure the normal operation and security of wireless services, and improve the reliability and performance of the network.
[0102] The wireless service security detection method provided in this embodiment obtains the topological association information between the BBU device and multiple bearing devices by acquiring the topological association information between the BBU device and multiple bearing devices. The topological association information includes: the association relationship between the BBU device and the bearing devices in the corresponding bearing network and the connection relationship between the multiple bearing devices. According to the connection relationship between the multiple bearing devices, the loop information of each bearing device is determined. The loop information is used to indicate whether the corresponding bearing device is looped. According to the loop information of multiple bearing devices, bearing security detection and processing are performed on the wireless services corresponding to the BBU device; this method improves the accuracy of the wireless service security detection result by establishing the topological relationship between the BBU device and the bearing device.
[0103] Figure 2 This is the flow of the wireless service security detection method provided in this application Figure 2 As Figure 2 shown, this embodiment is based on the Figure 1 embodiment, and details the wireless service security detection method. The wireless service security detection method shown in this embodiment includes:
[0104] S201: Obtain the first MAC address of the backhaul interface of the BBU device and the bearing device information of multiple candidate bearing devices. The bearing device information is used to indicate the interface address and interface name of the corresponding candidate bearing device.
[0105] To obtain the first MAC address of the backhaul interface of a BBU device, you can connect to the BBU device through a command-line interface or a network management tool. In the command-line interface or network management tool of the BBU device, query the relevant information of the backhaul interface. The relevant information of the interface can include: the status of the interface, configuration information, MAC address, etc. According to the query result, find the first MAC address of the backhaul interface. This is usually one of the one or more MAC addresses displayed in the interface configuration information.
[0106] To obtain the interface address and interface name of a candidate bearer device, you can connect to the bearer device through a command-line interface or a network management tool. In the command-line interface or network management tool of the bearer device, query the relevant information of the interface. This may include: the status of the interface, configuration information, IP address, and interface name, etc. According to the query result, find the interface address and interface name of the bearer device. The interface address is usually displayed in the form of an IP address, and the interface name may be the physical interface name of the device or the virtual interface name.
[0107] S202: Determine the interface type of each candidate bearer device according to the interface names of multiple candidate bearer devices.
[0108] The interface type of a bearer device can be initially judged according to the interface name, because different interface types usually have different naming rules. Common bearer device interface types and their naming rules:
[0109] 1. Ethernet interface: The Ethernet interface is one of the most widely used network interfaces. Its naming usually starts with "Ethernet" or "eth", followed by a combination of numbers or letters. For example, "Ethernet 0 / 0 / 1" or "eth 0 / 0 / 1".
[0110] 2. Fiber interface: The fiber interface is usually used for high-speed data transmission. Its naming usually starts with "fiber" or "fibre", followed by a combination of numbers or letters. For example, "fiber 0 / 0 / 1" or "fibre 0 / 0 / 1".
[0111] 3. Wireless interface: The wireless interface is used for wireless communication. Its naming usually starts with "wlan" or "radio", followed by a combination of numbers or letters. For example, "wlan 0" or "radio 0".
[0112] 4. POS interface: The POS interface is an interface used for the SDH transmission network. Its naming usually starts with "pos", followed by a combination of numbers or letters. For example, "pos 1 / 1 / 1".
[0113] 5. Loopback interface: A loopback interface is a virtual interface used to test and simulate network connections. Its name usually starts with "loopback" followed by a number or letter combination, for example, "loopback 0".
[0114] S203: Determine, from among the multiple candidate bearer devices, multiple bearer devices that are associated with the BBU device according to the interface addresses of the multiple candidate bearer devices, the interface types, and the first MAC address.
[0115] According to the interface addresses, interface types and first MAC addresses of the multiple bearer devices, multiple bearer devices associated with the BBU device can be determined from the multiple bearer devices.
[0116] It can be understood that according to the first MAC address of the backhaul interface of the BBU device, the interface address of the bearer device matching the MAC address is screened out. This can be done by querying the MAC address table in the command line interface or network management tool of the bearer device; among the screened bearer devices, according to the interface type of the BBU device, the bearer device matching the interface type of the BBU device is further screened out; according to the interface address, interface type and first MAC address of the screened bearer device, multiple bearer devices associated with the BBU device can be determined.
[0117] S204: Obtain connection relationships between the multiple bearer devices according to the bearer device information of the multiple bearer devices.
[0118] Collect the bearer device information of each bearer device, such as the interface address, interface type, first MAC address, etc. This information can be obtained through network management tools, command line interface or other relevant documents.
[0119] Based on the collected bearer device information, the connection relationship between each bearer device can be analyzed. This includes physical connection and logical connection. Physical connection refers to the physical link connection between devices, such as optical fiber connection; virtual connection refers to the communication protocol and routing configuration between devices, such as IP routing configuration.
[0120] Based on the analysis results, the connection relationship between multiple bearer devices can be determined, including which devices are connected, the interface type of the connection, the connection path, etc.
[0121] S205: Obtain the hierarchical position of the bearer device in the bearer network.
[0122] First, you need to understand the architecture of the entire network, including the devices at each level and the connections between them. This helps you understand the position of the bearer equipment in the bearer network.
[0123] By analyzing the connection relationship between a bearer device and other devices, you can infer the hierarchical position it is in. For example, if a bearer device is connected to a convergence layer device, it may be located above the access layer.
[0124] You can obtain the hierarchical position of the bearer device in the bearer network by querying the device's configuration information or related documents, which may include: device interface information, routing configuration, QOS policy, etc.
[0125] Some network management tools can provide a visual interface to help administrators easily manage and monitor the entire network. Through these tools, the location and level of the bearer equipment in the bearer network can be intuitively viewed.
[0126] S206: According to the connection relationship between the multiple bearer devices and the hierarchical position, loop identification is performed on the multiple bearer devices, and it is determined whether each bearer device forms a ring.
[0127] The loop identification method is:
[0128] Taking into account the configuration standardization and protection switching of the network, this embodiment stipulates that the ring rules of the bearer network access layer equipment are as follows: the node can be connected to the upper-level node in two physical directions in a single-point or dual-point manner, but loops above the second level (excluding the second level) are not recognized as rings, and the main loop is identified based on the principle of minimum COST value.
[0129] Traverse all access devices connected to the aggregation device hop by hop. If the connected device type of the access device at the traversal termination point is "aggregation device", all nodes on the path are identified as "pending primary loops" and pending loops with the same access start and end points are grouped together.
[0130] The main loop is identified by the COST value configured in the IGP protocol. The sum of the COST values of each link in the "pending primary loop" is calculated, and the loop with the smallest COST value among all pending loops in the "pending primary loop group" is identified as the main loop, that is, the primary loop. All nodes on the ring are identified as primary loop nodes.
[0131] The identification of secondary loops is similar to that of primary loops. First, all access devices (defined as secondary access devices) hanging down in the primary loop nodes are traversed hop by hop. If the type of the secondary access device connected to the traversal end point is an "access device" on the primary loop, it is identified as a pending "secondary loop". The secondary pending loops with the same secondary access start and end points are grouped together.
[0132] The primary loop is identified through the COST values configured in the IGP protocol. Calculate the sum of the COST values of each link in the "pending secondary loop", and identify the loop with the smallest COST value among all the pending loops in the "pending secondary loop group" as the primary loop, that is, the secondary loop. All nodes on the loop are identified as secondary loop nodes.
[0133] The steps to determine whether each bearer device forms a loop can be as follows:
[0134] First, based on the connection relationships between the bearer devices collected, analyze the connection paths between each bearer device. This can be achieved by drawing a network topology diagram or using a network management tool.
[0135] According to the configuration information or relevant documents of each bearer device, determine its hierarchical position in the bearer network. This helps to judge whether the connections of the devices will form a loop.
[0136] When analyzing the connection relationships, it is necessary to pay attention to whether there are circular connection paths. If there is a loop, it means that the connections between some bearer devices form a circular structure.
[0137] For each bearer device, it can be judged whether it forms a loop based on its connection relationship and hierarchical position. If the bearer device is located in the loop, it is considered to form a loop; otherwise, it is considered not to form a loop.
[0138] S207: Obtain the geographical locations of the bearer device and the BBU device.
[0139] Check the labels or relevant documents on the bearer device and the BBU device. Usually, these devices record their geographical location information during installation.
[0140] If a device management system is used to monitor and manage network devices, the geographical location information of the bearer device and the BBU device can be found in this system. These systems usually record the physical location of the devices and other relevant information.
[0141] Refer to the network topology diagram, which usually shows the connection relationships and locations of the devices. By analyzing the topology diagram, the approximate geographical locations of the bearer device and the BBU device can be inferred.
[0142] If the bearer device and the BBU device support the GPS function, a GPS receiver can be used to obtain their accurate geographical location information. This requires enabling the GPS function on the devices and using appropriate software or tools for positioning.
[0143] S208: Judge whether the geographical locations of the bearer device and the BBU device are the same.
[0144] Compare geographical location information: After obtaining the geographical location information of the bearer device and the BBU device, compare them. If the bearer device and the BBU device are located in the same geographical location, it can be determined that their geographical locations are consistent.
[0145] Refer to the network topology diagram and observe the connection relationship between the bearer device and the BBU device. If they are on the same subnet or routing path and there are no obvious network latency or packet loss problems, then it can be inferred that their geographical locations are close or consistent.
[0146] Use a dedicated routing analysis tool to check the routing path in the network and the distance between devices. By analyzing the routing information, the distance between the bearer device and the BBU device and whether they are on the same routing path can be determined.
[0147] Check the network configuration file or relevant documents to determine whether the bearer device and the BBU device are in the same VLAN, subnet, or routing domain. If they are in the same network domain, then their geographical locations may be consistent.
[0148] S209: When the bearer device forms a loop, determine whether the loop corresponding to the bearer device is recognized as a large loop, and the large loop is used to indicate that the number of bearer devices on the loop is greater than the first preset number.
[0149] Among them, the first preset number can be 20. When the bearer device forms a loop, if the number of bearer devices on the loop is greater than 20, the loop corresponding to the bearer device is recognized as a large loop.
[0150] S210: When the loop corresponding to the bearer device is recognized as a large loop, determine that the wireless service bearer security detection result corresponding to the BBU device has a first security hazard.
[0151] Among them, the first security hazard is used to indicate that there is a relatively large security hazard in the wireless service bearer corresponding to the BBU device.
[0152] When the loop corresponding to the bearer device is recognized as a large loop, the wireless service bearer security detection result corresponding to the BBU device has a relatively large security hazard.
[0153] S211: When the bearer device does not form a loop, determine whether the bearer device is recognized as a long chain, and the long chain is used to indicate that the number of bearer devices under the same connection cable is greater than the second preset number.
[0154] Among them, the second preset number can be 3, and a single chain with the number of nodes on the same chain greater than 3 is recognized as a long chain.
[0155] S212: If the single link corresponding to the bearer device is determined to be a long link, determine that the security detection result of the radio service bearer corresponding to the BBU device has a first security risk and the second security risk.
[0156] Among them, the second security risk is used to indicate that there is a potential security risk in the radio service bearer corresponding to the BBU device.
[0157] When the bearer device is not in a loop, the security detection result of the radio service bearer corresponding to the BBU device has a potential security risk; if the single link corresponding to the bearer device is determined to be a long link, the security detection result of the radio service bearer corresponding to the BBU device has a major security risk and a potential security risk.
[0158] S213: When the geographical location of the bearer device is inconsistent with the geographical location of the BBU device, determine that the loop information of the bearer device is not in a loop.
[0159] Among them, the geographical location may include: the name of the computer room and the longitude and latitude information.
[0160] It can be understood that when the name of the computer room and / or the longitude and latitude information where the bearer device and the BBU device are located are inconsistent, it is determined that the bearer device is not in a loop.
[0161] S214: When the bearer device is not in a loop, determine that the security detection result of the radio service bearer corresponding to the BBU device has a second security risk.
[0162] When the name of the computer room and / or the longitude and latitude information where the bearer device and the BBU device are located are inconsistent, it is determined that the bearer device is not in a loop, indicating that the security detection result of the radio service bearer corresponding to the BBU device has a potential security risk.
[0163] The wireless service security detection method provided in this embodiment obtains the first MAC address of the backhaul interface of the BBU device, the interface addresses and interface names of multiple candidate bearer devices, determines the interface type of each candidate bearer device according to the interface names of the multiple candidate bearer devices, and determines, from the multiple candidate bearer devices, multiple bearer devices having an association relationship with the BBU device according to the interface addresses, the interface types, and the first MAC address of the multiple candidate bearer devices. The connection relationship between the multiple bearer devices is obtained according to the bearer device information of the multiple bearer devices, the hierarchical position of the bearer device in the bearer network is obtained, and loop determination is performed on the multiple bearer devices according to the connection relationship between the multiple bearer devices and the hierarchical position. When the bearer devices form a loop and the loop corresponding to the bearer device is determined to be a large loop, it is determined that the wireless service bearer security detection result corresponding to the BBU device has a first security risk. When the bearer devices do not form a loop and the loop corresponding to the bearer device is determined to be a long chain, it is determined that the wireless service bearer security detection result corresponding to the BBU device has a first security risk and a second security risk. When the geographical location of the bearer device is inconsistent with the geographical location of the BBU device, it is determined that the loop information of the bearer device is not in a loop, and it is determined that the wireless service bearer security detection result corresponding to the BBU device has a second security risk. By establishing the topological relationship between the BBU device and the bearer device, the accuracy of the wireless service security detection result is improved.
[0164] Figure 3 is the flow of the wireless service security detection method provided in this application Figure 3 。As Figure 3 shown, this embodiment is based on the Figure 2 embodiment and details the determination of multiple bearer devices having an association relationship with the BBU device from multiple candidate bearer devices. The wireless service security detection method shown in this embodiment includes:
[0165] S301: Determine the interface type of each candidate bearer device according to the interface names of the multiple candidate bearer devices.
[0166] Among them, step S301 is similar to step S202 and will not be elaborated here.
[0167] S302: If the interface type is a physical interface type, perform parsing processing on the interface address of the candidate bearer device to obtain the second MAC address of the candidate bearer device, where the interface address is an IP address.
[0168] When the interface type of the bearer device is a physical interface type, it can be determined that the wireless service accessing this interface is directly connected to the bearer network L3VPN, and this interface and device are the bearer interface and device directly accessed by the BBU. At this time, the second MAC address of the candidate bearer device can be obtained through the ARP protocol.
[0169] After the current network service cutover, there is a situation where the link is removed after the cutover but the port configuration is not deleted. If static IP address matching is used, there will be a situation where the same BBU matches multiple bearer devices of the end device, resulting in matching errors. Using the ARP dynamic protocol to avoid the matching error caused by service cutover can improve the matching success rate.
[0170] S303: When the first MAC address is the same as the second MAC address, determine that the candidate bearer device is the bearer device associated with the BBU device.
[0171] When the first MAC address and the second MAC address are the same, determine that the candidate bearer device is the bearer device associated with the BBU device.
[0172] S304: If the interface type is a virtual interface type, determine the corresponding L2 VPN service instance according to the interface address of the candidate bearer device, and determine the bridging mode of the candidate bearer device according to the number of bridges corresponding to the L2 VPN service instance.
[0173] If the interface type is a virtual interface type, it can be determined that the access mode of the wireless service is the L2+L3 mode, and the interface on the corresponding bearer device is the L3 VE interface. A PW tunnel can be established between the access device and the aggregation device to carry the backhaul service, and an L3VPN is established between the aggregation device and the core device to carry the backhaul service. The L2 and L3 bridging is realized on the aggregation device. The base station is physically connected to the access device, but the three-layer gateway is the L3 VE interface of the aggregation device connected to the access device. At this time, there are two modes:
[0174] 1) 1:1 mode, that is, the L3 VE of the aggregation device corresponds one-to-one with the L2 VE / PW channel, and each base station corresponds to one gateway;
[0175] 2) 1:N mode, one L3 VE corresponds to multiple L2 VEs and multiple PW channels. At this time, multiple base stations share one gateway, and this mode can save IP address resources.
[0176] On the aggregation device where the virtual interface type is located, obtain the interface name, VLAN ID, and peer MAC address of the L3 VE through the ARP protocol. Find the corresponding bridging group according to the L3 VE interface name, and then find the corresponding L2VE name and VLAN ID. Query the L2 VPN instance (VFI) according to the L2 VE name and VLAN ID information. Determine the two modes by querying the number of PWs under the VFI. If there is only one PW tunnel under the VFI, it is determined to be the 1:1 mode; otherwise, it is the 1:N mode.
[0177] S305: When the bridging mode is the first bridging mode, query the remote IP corresponding to the candidate bearer device according to the L2 VPN service instance, and when the remote IP matches the first MAC address, determine that the candidate bearer device is the bearer device associated with the BBU device.
[0178] Among them, the first bridging mode is the 1:1 mode. According to the detailed information of the L2 VPN instance, find the remote IP address corresponding to the PW instance. In the standard configuration scheme, the base station services are all carried by single-segment pseudowires, so the remote IP is the network element of the bearer network access device. Thus, obtain the association relationship table of 《BBU MAC address》 and 《Access device IP address》. Match and filter the 《BBU device ID》 queried by the radio network management with the 《BBU MAC address》, and the relationship table of 《BBU device ID》 and 《Access device IP address》 can be obtained, completing the topological association between the BBU device and the bearer network access device in the 1:1 mode of L2+L3.
[0179] S306: When the bridging mode is the second bridging mode, determine whether the L2 VPN service instance matches the first MAC address and the Loopback address of the candidate bearer device.
[0180] S307: If they match, determine that the candidate bearer device is the bearer device associated with the BBU device
[0181] Among them, the second bridging mode is the 1:N mode. When the 1:N mode is adopted, find the forwarding table corresponding to the VFI and match the BBU MAC with the Loopback address of the access layer device. Thus, obtain the association relationship table of 《BBU MAC address》 and 《Access device LoopBack address》. Match and filter the 《BBU device ID》 queried by the radio network management with the 《BBU MAC address》, and the relationship table of 《BBU device ID》 and 《Access device LoopBack address》 can be obtained, completing the topological association between the BBU device and the bearer device in the 1:N mode of L2+L3.
[0182] The wireless service security detection method provided in this embodiment determines the interface type of each candidate bearer device according to the interface names of multiple candidate bearer devices. If the interface type is a physical interface type, the interface address of the candidate bearer device is resolved to obtain the second MAC address of the candidate bearer device, where the interface address is an IP address. When the first MAC address is the same as the second MAC address, it is determined that the candidate bearer device is a bearer device associated with the BBU device. If the interface type is a virtual interface type, the corresponding L2 VPN service instance is determined according to the interface address of the candidate bearer device, and the bridging mode of the candidate bearer device is determined according to the number of bridges corresponding to the L2 VPN service instance. When the bridging mode is the first bridging mode, the remote IP corresponding to the candidate bearer device is queried according to the L2 VPN service instance, and when the remote IP matches the first MAC address, it is determined that the candidate bearer device is a bearer device associated with the BBU device. When the bridging mode is the second bridging mode and the L2 VPN service instance matches the first MAC address and the Loopback address of the candidate bearer device, it is determined that the candidate bearer device is a bearer device associated with the BBU device. By establishing the topological relationship between the BBU device and the bearer device, this method improves the accuracy of the wireless service security detection result.
[0183] Figure 4 It is a schematic structural diagram of the wireless service security detection device provided in this application. As Figure 4 shown, the wireless service security detection device 400 provided in this embodiment includes:
[0184] An obtaining module 401, configured to obtain topological association information between a BBU device and multiple bearer devices, where the topological association information includes: the association relationship between the BBU device and the bearer devices in the corresponding bearer network and the connection relationship between the multiple bearer devices;
[0185] A determining module 402, configured to determine the loop information of each bearer device according to the connection relationship between the multiple bearer devices, where the loop information is used to indicate whether the corresponding bearer device is looped;
[0186] A processing module 403, configured to perform bearer security detection processing on the wireless service corresponding to the BBU device according to the loop information of multiple bearer devices.
[0187] Optionally, the obtaining module 401 is further configured to obtain a first MAC address of a feedback interface of the BBU device and bearer device information of a plurality of candidate bearer devices, where the bearer device information is used to indicate an interface address and an interface name of a corresponding candidate bearer device;
[0188] The determining module 402 is further configured to determine an interface type of each candidate bearer device according to the interface names of the plurality of candidate bearer devices;
[0189] The determining module 402 is further configured to determine a plurality of bearer devices associated with the BBU device from the plurality of candidate bearer devices according to the interface addresses, the interface types, and the first MAC address of the plurality of candidate bearer devices;
[0190] The determining module 402 is further configured to obtain a connection relationship between the plurality of bearer devices according to the bearer device information of the plurality of bearer devices.
[0191] Optionally, the wireless service security detection device further includes: a judging module 404;
[0192] The processing module 403 is further configured to, if the interface type is a physical interface type, perform parsing processing on the interface address of the candidate bearer device to obtain a second MAC address of the candidate bearer device, where the interface address is an IP address;
[0193] The determining module 402 is further configured to determine that the candidate bearer device is a bearer device associated with the BBU device when the first MAC address is the same as the second MAC address;
[0194] The determining module 402 is further configured to, if the interface type is a virtual interface type, determine a corresponding L2 VPN service instance according to the interface address of the candidate bearer device, and determine a bridging mode of the candidate bearer device according to the number of bridges corresponding to the L2 VPN service instance;
[0195] The determining module 402 is further configured to, when the bridging mode is a first bridging mode, query a remote IP corresponding to the candidate bearer device according to the L2 VPN service instance, and determine that the candidate bearer device is a bearer device associated with the BBU device when the remote IP matches the first MAC address;
[0196] The judging module 404 is configured to judge whether the L2 VPN service instance matches the first MAC address and the Loopback address of the candidate bearer device when the bridging mode is a second bridging mode;
[0197] The determining module 402 is further configured to determine that the candidate bearer device is a bearer device associated with the BBU device if the L2 VPN service instance matches the first MAC address and the Loopback address of the candidate bearer device.
[0198] Optionally, the obtaining module 401 is further configured to obtain the hierarchical position of the bearer device in the bearer network;
[0199] The processing module 403 is further configured to perform loop identification on the multiple bearer devices according to the connection relationship and the hierarchical position among the multiple bearer devices;
[0200] The judging module 404 is further configured to judge whether each bearer device forms a loop.
[0201] Optionally, the obtaining module 401 is further configured to obtain the geographical location of the bearer device and the geographical location of the BBU device;
[0202] The judging module 404 is further configured to judge whether the geographical location of the bearer device is the same as the geographical location of the BBU device;
[0203] The determining module 402 is further configured to determine that the loop formation information of the bearer device is no loop when the geographical location of the bearer device is different from the geographical location of the BBU device.
[0204] Optionally, the judging module 404 is further configured to judge whether the loop corresponding to the bearer device is identified as a large loop when the bearer device forms a loop, where the large loop is used to indicate that the number of bearer devices on the loop is greater than a first preset number;
[0205] The determining module 402 is further configured to determine that the wireless service bearer security detection result corresponding to the BBU device has a first security risk when the loop corresponding to the bearer device is identified as a large loop.
[0206] Optionally, the determining module 402 is further configured to determine that the wireless service bearer security detection result corresponding to the BBU device has a second security risk when the bearer device does not form a loop;
[0207] The judging module 404 is further configured to judge whether the bearer device is identified as a long chain when the bearer device does not form a loop, where the long chain is used to indicate that the number of bearer devices under the same connection cable is greater than a second preset number;
[0208] The determining module 402 is further configured to determine that the wireless service bearer security detection result corresponding to the BBU device has the first security risk and the second security risk if the single chain corresponding to the bearer device is identified as a long chain.
[0209] Figure 5 This is a schematic structural diagram of the wireless service security detection device provided by this application. As Figure 5 shown, this application provides a wireless service security detection device. The wireless service security detection device 500 includes: a receiver 501, a transmitter 502, a processor 503, and a memory 504.
[0210] The receiver 501 is configured to receive instructions and data;
[0211] The transmitter 502 is configured to send instructions and data;
[0212] The memory 504 is configured to store computer-executable instructions;
[0213] The processor 503 is configured to execute the computer-executable instructions stored in the memory 504 to implement the various steps performed by the wireless service security detection method in the above embodiments. Specifically, reference can be made to the relevant descriptions in the foregoing embodiments of the wireless service security detection method.
[0214] Optionally, the above-mentioned memory 504 can be either independent or integrated with the processor 503.
[0215] When the memory 504 is independently provided, the electronic device further includes a bus for connecting the memory 504 and the processor 503.
[0216] This application also provides a computer-readable storage medium. The computer-readable storage medium stores computer-executable instructions. When the processor executes the computer-executable instructions, the wireless service security detection method performed by the above-mentioned wireless service security detection device is implemented.
[0217] It should be noted that for the foregoing method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that this application is not limited by the described action sequence, because according to this application, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all optional embodiments, and the actions and modules involved are not necessarily essential to this application.
[0218] Further, it should be noted that although the steps in the flowchart are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise clearly stated in this document, there is no strict order restriction for the execution of these steps, and these steps can be executed in other orders. Moreover, at least some of the steps in the flowchart may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily executed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be executed alternately or in turn with at least some of the other steps or sub-steps or stages of the other steps.
[0219] It should be understood that the above device embodiments are merely illustrative, and the devices of the present application can also be implemented in other ways. For example, the division of units / modules in the above embodiments is only a logical function division, and there can be other division methods in actual implementation. For example, multiple units, modules or components can be combined, or can be integrated into another system, or some features can be ignored or not executed.
[0220] In addition, unless otherwise specified, in each embodiment of the present application, each functional unit / module can be integrated in one unit / module, or each unit / module can exist physically alone, or two or more units / modules can be integrated together. The above integrated unit / module can be implemented in the form of hardware or in the form of a software program module.
[0221] When the integrated unit / module is implemented in the form of hardware, the hardware can be a digital circuit, an analog circuit, etc. The physical implementation of the hardware structure includes but is not limited to transistors, memristors, etc. Unless otherwise specified, the processor can be any suitable hardware processor, such as CPU, GPU, FPGA, DSP, and ASIC, etc. Unless otherwise specified, the storage unit can be any suitable magnetic storage medium or magneto-optical storage medium, such as resistive random access memory RRAM (Resistive Random Access Memory), dynamic random access memory DRAM (Dynamic Random Access Memory), static random access memory SRAM (Static Random-Access Memory), enhanced dynamic random access memory EDRAM (Enhanced Dynamic Random Access Memory), high-bandwidth memory HBM (High-Bandwidth Memory), hybrid memory cube HMC (Hybrid Memory Cube), etc.
[0222] When the integrated unit / module is implemented in the form of a software program module and sold or used as an independent product, it can be stored in a computer-readable memory. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a memory and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in various embodiments of the present application. The aforementioned memory includes: various media that can store program codes, such as USB flash drives, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), mobile hard disks, magnetic disks, or optical discs.
[0223] In the above embodiments, the descriptions of each embodiment have their own focuses. For the parts not detailed in a certain embodiment, reference can be made to the relevant descriptions of other embodiments. The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.
[0224] Those skilled in the art will readily think of other implementation schemes of the present application after considering the specification and practicing the invention disclosed herein. The present application aims to cover any variations, uses, or adaptive changes of the present application. These variations, uses, or adaptive changes follow the general principles of the present application and include common general knowledge or conventional technical means in the technical field not disclosed in the present application. The specification and embodiments are only regarded as exemplary, and the true scope and spirit of the present application are pointed out by the following claims.
[0225] It should be understood that the present application is not limited to the exact structure already described and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present application is only limited by the appended claims.
Claims
1. A method for detecting the security of wireless services, characterized in that, the method includes: Obtain the topological association information between the BBU device and multiple bearer devices, where the topological association information includes: the association relationship between the BBU device and the bearer devices in the corresponding bearer network, and the connection relationship between the multiple bearer devices; Determine the loop information of each bearer device according to the connection relationship between the multiple bearer devices, where the loop information is used to indicate whether the corresponding bearer device forms a loop; Perform bearer security detection processing on the wireless service corresponding to the BBU device according to the loop information of multiple bearer devices.
2. The method according to claim 1, characterized in that, the obtaining of the topological association information between the BBU device and multiple bearer devices includes: Obtain the first MAC address of the backhaul interface of the BBU device and the bearer device information of multiple candidate bearer devices, where the bearer device information is used to indicate the interface address and interface name of the corresponding candidate bearer device; Determine the interface type of each candidate bearer device according to the interface names of the multiple candidate bearer devices; Determine multiple bearer devices associated with the BBU device from the multiple candidate bearer devices according to the interface addresses, the interface type, and the first MAC address of the multiple candidate bearer devices; Obtain the connection relationship between the multiple bearer devices according to the bearer device information of the multiple bearer devices.
3. The method according to claim 2, characterized in that, the interface type includes: physical interface type and virtual interface type, and the determining of multiple bearer devices associated with the BBU device from the multiple candidate bearer devices according to the interface addresses, the interface type, and the first MAC address of the multiple candidate bearer devices includes: If the interface type is a physical interface type, perform parsing processing on the interface address of the candidate bearer device to obtain the second MAC address of the candidate bearer device, where the interface address is an IP address; When the first MAC address and the second MAC address are the same, determine that the candidate bearer device is a bearer device associated with the BBU device; If the interface type is a virtual interface type, determine the corresponding L2 VPN service instance according to the interface address of the candidate bearer device, and determine the bridging mode of the candidate bearer device according to the number of bridges corresponding to the L2 VPN service instance; When the bridging mode is the first bridging mode, query the remote IP corresponding to the candidate bearer device according to the L2 VPN service instance, and when the remote IP matches the first MAC address, determine that the candidate bearer device is a bearer device associated with the BBU device; When the bridging mode is the second bridging mode, determine whether the L2 VPN service instance matches the first MAC address and the Loopback address of the candidate bearer device; If it matches, determine that the candidate bearer device is a bearer device associated with the BBU device.
4. The method according to claim 1, wherein, determining the loop information of each bearer device according to the connection relationship between the multiple bearer devices includes: obtaining the hierarchical position of the bearer device in the bearer network; performing loop identification on the multiple bearer devices according to the connection relationship between the multiple bearer devices and the hierarchical position, and determining whether each bearer device forms a loop.
5. The method according to claim 1, wherein, determining the loop information of each bearer device according to the connection relationship between the multiple bearer devices includes: obtaining the geographical location of the bearer device and the geographical location of the BBU device; judging whether the geographical location of the bearer device is the same as the geographical location of the BBU device; when the geographical location of the bearer device is not the same as the geographical location of the BBU device, determining that the loop information of the bearer device is not in a loop.
6. The method according to claim 4 or 5, wherein, performing bearer security detection processing on the wireless service corresponding to the BBU device according to the loop information of the multiple bearer devices includes: when the bearer device forms a loop, judging whether the loop corresponding to the bearer device is recognized as a large loop, and the large loop is used to indicate that the number of bearer devices on the loop is greater than a first preset number; when the loop corresponding to the bearer device is recognized as a large loop, determining that the bearer security detection result of the wireless service corresponding to the BBU device has a first security risk.
7. The method according to claim 4 or 5, wherein, performing bearer security detection processing on the wireless service corresponding to the BBU device according to the loop information of the multiple bearer devices includes: when the bearer device is not in a loop, determining that the bearer security detection result of the wireless service corresponding to the BBU device has a second security risk; when the bearer device is not in a loop, judging whether the bearer device is recognized as a long chain, and the long chain is used to indicate that the number of bearer devices under the same connection cable is greater than a second preset number; if the single chain corresponding to the bearer device is recognized as a long chain, determining that the bearer security detection result of the wireless service corresponding to the BBU device has a first security risk and the second security risk.
8. A wireless service security detection device, wherein, comprising: an acquisition module, configured to acquire the topological association information between the BBU device and multiple bearer devices, and the topological association information includes: the association relationship between the BBU device and the bearer devices in the corresponding bearer network and the connection relationship between the multiple bearer devices; a determination module, configured to determine the loop information of each bearer device according to the connection relationship between the multiple bearer devices, and the loop information is used to indicate whether the corresponding bearer device forms a loop; a processing module, configured to perform bearer security detection processing on the wireless service corresponding to the BBU device according to the loop information of the multiple bearer devices.
9. A wireless service security detection device, wherein, comprising: a processor and a memory communicatively connected to the processor; the memory stores computer execution instructions; The processor executes the computer-executable instructions stored in the memory to implement the method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that the computer-readable storage medium stores computer-executable instructions, which are used to implement the method according to any one of claims 1 to 7 when being executed by a processor.
Citation Information
Patent Citations
Network fault analysis method and device, server and storage medium
CN111510331A
Fault positioning method, device and equipment and computer storage medium
CN111836288A
IPRAN network equipment fault alarm merging analysis processing method and device
CN111884840A
Network quality evaluation method and device, electronic equipment and storage medium
CN114173369A
Monitoring method for IP bearing network based on service and device for monitoring quality of IP service
WO2011137807A1