Wireless service security detection method, device, equipment and storage medium
By acquiring the topology association information between the BBU device and the bearer device, the loop information of the bearer device is determined, which solves the problem of inaccurate association between the BBU device and the bearer device in the prior art, and improves the accuracy of wireless service security detection and network reliability.
Patent Information
- Application Number
- CN202311706799.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-12
- Publication Date
- 2025-12-05
- Estimated Expiration
- 2043-12-12
AI Technical Summary
In existing technologies, manual labeling and physical room matching methods cannot accurately associate BBU devices with bearer devices, resulting in low accuracy of wireless service security assessment results.
By acquiring the topology association information between the BBU device and multiple bearer devices, including association and connection relationships, the loop information of each bearer device is determined, and wireless service security detection is performed based on the loop information.
It improves the accuracy of wireless service security detection results, ensures the normal operation and security of wireless services, and enhances network reliability and performance.
Smart Images

Figure CN120151882B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of communication, in particular to a wireless service security detection method and device, equipment and storage medium. BACKGROUND
[0002] In the 4, 5G era, with the application and promotion of large-capacity BBU equipment and CRAN architecture (BBU centralized deployment), the scale of BBU equipment accessed by the bearing equipment in the wireless service access point and / or BBU equipment centralized point gradually increases, and the security of the bearing equipment significantly improves the robustness and user perception of the 4, 5G wireless service network. Therefore, the security of the BBU equipment can be determined by the loop condition of the bearing equipment, and the wireless service security can be evaluated according to the security of the BBU equipment.
[0003] In the prior art, artificial marking and physical machine room matching method are mainly used to associate the loop condition of the bearing equipment and the security of the BBU equipment. The artificial marking method directly marks the loop condition of the bearing equipment on the BBU equipment, or marks the ID of the BBU equipment bearing on each bearing equipment port, so that the security of the BBU equipment can be determined by the loop condition of the bearing equipment. The physical machine room matching method determines the security of the BBU equipment according to the bearing equipment loop proportion, wherein the bearing equipment and the BBU equipment are in the same machine room.
[0004] However, with the gradual evolution of the bearing network, artificial marking and physical machine room matching method cannot accurately realize the precise association of BBU equipment and bearing equipment, and there is a problem of low accuracy of wireless service security judgment result. SUMMARY
[0005] The present application provides a wireless service security detection method, device, equipment and storage medium to solve the problem of low accuracy of wireless service security judgment result due to the fact that artificial marking and physical machine room matching method cannot accurately realize the precise association of BBU equipment and bearing equipment.
[0006] In a first aspect, the present application provides a wireless service security detection method, comprising:
[0007] Obtaining topology association information between a BBU equipment and a plurality of bearing equipment, the topology association information comprising: an association relationship between the BBU equipment and the bearing equipment in the corresponding bearing network, and a connection relationship between the plurality of bearing equipment;
[0008] According to the connection relationship between the plurality of bearing equipment, determining the loop information of each bearing equipment, the loop information being used to indicate whether the corresponding bearing equipment is looped;
[0009] According to the loop information of the plurality of bearer devices, wireless service corresponding to the BBU device is subjected to bearer security detection processing.
[0010] Optionally, the topology association information between the BBU device and the plurality of bearer devices comprises:
[0011] The first MAC address of the backhaul interface of the BBU device and bearer device information of the plurality of candidate bearer devices are acquired, the bearer device information being used to indicate the interface address and the interface name of the corresponding candidate bearer device;
[0012] According to the interface name of the plurality of candidate bearer devices, the interface type of each candidate bearer device is determined;
[0013] According to the interface address of the plurality of candidate bearer devices, the interface type and the first MAC address, the plurality of bearer devices having the association relationship with the BBU device are determined from the plurality of candidate bearer devices;
[0014] According to the bearer device information of the plurality of bearer devices, the connection relationship between the plurality of bearer devices is obtained.
[0015] Optionally, the interface type comprises a physical interface type and a virtual interface type, and the plurality of bearer devices having the association relationship with the BBU device are determined from the plurality of candidate bearer devices according to the interface address of the plurality of candidate bearer devices, the interface type and the first MAC address, comprising:
[0016] If the interface type is the physical interface type, the interface address of the candidate bearer device is subjected to parsing processing to obtain the second MAC address of the candidate bearer device, wherein the interface address is an IP address;
[0017] When the first MAC address and the second MAC address are consistent, the candidate bearer device is determined as the bearer device having the association relationship with the BBU device;
[0018] If the interface type is the virtual interface type, according to the interface address of the candidate bearer device, the corresponding L2 VPN service instance is determined, and according to the bridge quantity corresponding to the L2 VPN service instance, the bridge mode of the candidate bearer device is determined;
[0019] When the bridge mode is a first bridge mode, according to the L2 VPN service instance, the remote IP corresponding to the candidate bearer device is queried, and when the remote IP matches the first MAC address, the candidate bearer device is determined as the bearer device having the association relationship with the BBU device;
[0020] determining whether the L2 VPN service instance matches the first MAC address and a Loopback address of the candidate carrying device when the bridge mode is a second bridge mode;
[0021] If the match is found, the candidate carrying device is determined as a carrying device having an association relationship with the BBU device.
[0022] Optionally, the determining of the loop information of each carrying device according to the connection relationship among the plurality of carrying devices comprises:
[0023] obtaining a hierarchical position of the carrying device in a carrying network;
[0024] performing loop identification on the plurality of carrying devices according to the connection relationship among the plurality of carrying devices and the hierarchical position, and determining whether each carrying device is looped.
[0025] Optionally, the determining of the loop information of each carrying device according to the connection relationship among the plurality of carrying devices comprises:
[0026] obtaining a geographical position of the carrying device and a geographical position of the BBU device;
[0027] determining whether the geographical position of the carrying device is consistent with the geographical position of the BBU device;
[0028] when the geographical position of the carrying device is inconsistent with the geographical position of the BBU device, determining that the loop information of the carrying device is not looped.
[0029] Optionally, the performing of the carrying security detection processing on the wireless service corresponding to the BBU device according to the loop information of the plurality of carrying devices comprises:
[0030] when the carrying device is looped, determining whether a loop corresponding to the carrying device is identified as a large loop, the large loop being used to indicate that a number of carrying devices on the loop is greater than a first preset number;
[0031] when the loop corresponding to the carrying device is identified as the large loop, determining that a wireless service carrying security detection result corresponding to the BBU device is a first security risk.
[0032] Optionally, the performing of the carrying security detection processing on the wireless service corresponding to the BBU device according to the loop information of the plurality of carrying devices comprises:
[0033] when the carrying device is not looped, determining that a wireless service carrying security detection result corresponding to the BBU device is a second security risk.
[0034] determining whether the bearer device is identified as a long chain, the long chain being used to indicate that a number of bearer devices under the same trunk cable is greater than a second preset number, when the bearer device is not in a loop;
[0035] If the single chain corresponding to the bearer device is identified as a long chain, it is determined that the wireless service bearer security detection result corresponding to the BBU device is that there is a first security risk and the second security risk.
[0036] In a second aspect, the present application provides a wireless service security detection device, comprising:
[0037] An acquisition module is configured to acquire topology association information between a BBU device and a plurality of bearer devices, the topology association information comprising an association relationship between the BBU device and bearer devices in a corresponding bearer network and a connection relationship between the plurality of bearer devices;
[0038] A determination module is configured to determine loop information of each bearer device according to the connection relationship between the plurality of bearer devices, the loop information being used to indicate whether the corresponding bearer device is in a loop;
[0039] A processing module is configured to perform bearer security detection processing on wireless services corresponding to the BBU device according to the loop information of the plurality of bearer devices.
[0040] Optionally, the acquisition module is further configured to acquire a first MAC address of a backhaul interface of the BBU device and bearer device information of a plurality of candidate bearer devices, the bearer device information being used to indicate an interface address and an interface name of the corresponding candidate bearer device;
[0041] The determination module is further configured to determine an interface type of each candidate bearer device according to the interface name of the plurality of candidate bearer devices;
[0042] The determination module is further configured to determine, from the plurality of candidate bearer devices, a plurality of bearer devices having an association relationship with the BBU device according to the interface address, the interface type and the first MAC address of the plurality of candidate bearer devices;
[0043] The determination module is further configured to obtain a connection relationship between the plurality of bearer devices according to the bearer device information of the plurality of bearer devices.
[0044] Optionally, the wireless service security detection device further comprises a judgment module.
[0045] The processing module is further configured to, if the interface type is a physical interface type, perform parsing processing on the interface address of the candidate bearer device to obtain a second MAC address of the candidate bearer device, wherein the interface address is an IP address.
[0046] The determining module is further configured to determine that the candidate carrying device is a carrying device having an association relationship with the BBU device when the first MAC address and the second MAC address are consistent.
[0047] The determining module is further configured to, if the interface type is a virtual interface type, determine a corresponding L2 VPN service instance according to an interface address of the candidate carrying device, and determine a bridging mode of the candidate carrying device according to a number of bridges corresponding to the L2 VPN service instance.
[0048] The determining module is further configured to, when the bridging mode is a first bridging mode, query a remote IP corresponding to the candidate carrying device according to the L2 VPN service instance, and determine that the candidate carrying device is a carrying device having an association relationship with the BBU device when the remote IP matches the first MAC address.
[0049] The judging module is configured to, when the bridging mode is a second bridging mode, judge whether the L2 VPN service instance matches the first MAC address and a Loopback address of the candidate carrying device.
[0050] The determining module is further configured to determine that the candidate carrying device is a carrying device having an association relationship with the BBU device if the L2 VPN service instance matches the first MAC address and the Loopback address of the candidate carrying device.
[0051] Optionally, the obtaining module is further configured to obtain a hierarchical position of a carrying device in a carrying network.
[0052] The processing module is further configured to identify a loop of the plurality of carrying devices according to a connection relationship among the plurality of carrying devices and the hierarchical position.
[0053] The judging module is further configured to judge whether each carrying device is in a loop.
[0054] Optionally, the obtaining module is further configured to obtain a geographic position of a carrying device and a geographic position of the BBU device.
[0055] The judging module is further configured to judge whether the geographic position of the carrying device and the geographic position of the BBU device are consistent.
[0056] The determining module is further configured to determine that loop information of the carrying device is not in a loop when the geographic position of the carrying device and the geographic position of the BBU device are not consistent.
[0057] Optionally, the judgment module is further configured to determine whether the ring corresponding to the carrying device is identified as a large ring when the carrying device forms a ring, wherein the large ring is used to indicate that the number of carrying devices on the ring is greater than a first preset number;
[0058] The determining module is further configured to determine that the security detection result of the wireless service bearer corresponding to the BBU device is a first security risk when the ring corresponding to the bearer device is identified as a large ring.
[0059] Optionally, the determining module is further configured to determine that the security detection result of the wireless service bearer corresponding to the BBU device is that there is a second security risk when the bearer device is not in a loop;
[0060] The judgment module is also used to determine whether the carrier device is identified as a long chain when the carrier device is not in a loop. The long chain is used to indicate that the number of carrier devices under the same connecting cable is greater than the second preset number.
[0061] The determining module is further configured to determine, if the single chain corresponding to the bearer device is identified as a long chain, that the wireless service bearer security detection result corresponding to the BBU device is that there is a first security vulnerability and a second security vulnerability.
[0062] Thirdly, this application provides a wireless service security detection device, comprising:
[0063] Memory;
[0064] processor;
[0065] The memory stores computer-executed instructions;
[0066] The processor executes computer execution instructions stored in the memory to implement the wireless service security detection method as described in the first aspect and various possible implementations of the first aspect.
[0067] Fourthly, this application provides a computer storage medium, characterized in that the computer storage medium stores computer execution instructions, which, when executed by a processor, are used to implement the wireless service security detection method as described in the first aspect and various possible implementations of the first aspect.
[0068] The wireless service security detection method provided in the application comprises the following steps: obtaining topology association information between a BBU device and a plurality of bearing devices, wherein the topology association information comprises an association relationship between the BBU device and bearing devices in a corresponding bearing network and a connection relationship between the plurality of bearing devices; determining loop information of each bearing device according to the connection relationship between the plurality of bearing devices, wherein the loop information is used for indicating whether the corresponding bearing device is looped; and performing bearing security detection processing on wireless services corresponding to the BBU device according to the loop information of the plurality of bearing devices. The method improves the accuracy of the wireless service security detection result by establishing the topology relationship between the BBU device and the bearing device. BRIEF DESCRIPTION OF DRAWINGS
[0069] The accompanying drawings, which are incorporated herein and constitute part of the specification, illustrate embodiments consistent with the application and, together with the description, further serve to explain the principles of the application.
[0070] Figure 1 The flow of the wireless service security detection method provided in the application Figure 1 ;
[0071] Figure 2 The flow of the wireless service security detection method provided in the application Figure 2 ;
[0072] Figure 3 The flow of the wireless service security detection method provided in the application Figure 3 ;
[0073] Figure 4 The structure diagram of the wireless service security detection device provided in the application;
[0074] Figure 5 The structure diagram of the wireless service security detection device provided in the application.
[0075] The specific embodiments of the application have been shown and described in the above-described drawings, and will be described in more detail hereinafter. These drawings and the written description are not intended to restrict the scope of the inventive concept in any way, but to illustrate the inventive concept by reference to specific embodiments. DETAILED DESCRIPTION
[0076] The exemplary embodiments will be described in detail herein with reference to the attached drawings. The following description is made with reference to the accompanying drawings in which like reference numerals represent like elements, unless the context of use indicates otherwise. The following description of exemplary embodiments is not representative of all embodiments consistent with the present application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of the present application as detailed in the appended claims.
[0077] It should be noted that the user information (including but not limited to user equipment information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the present application are all information and data authorized by the user or authorized by all parties, and the collection, use and processing of related data need to comply with relevant laws, regulations and standards, and provide corresponding operation portal for user to choose authorization or refusal.
[0078] 4、5G era, with the application and promotion of large-capacity BBU equipment and CRAN architecture (BBU centralized deployment), the scale of BBU equipment accessed by the bearing equipment in the wireless service access point and / or BBU equipment centralized point gradually increases, and the security of the bearing equipment significantly improves the robustness of the 4, 5G wireless service network and the user perception, therefore, the security of the BBU equipment can be determined by the loop condition of the bearing equipment, and the wireless service security is evaluated according to the security of the BBU equipment.
[0079] In the prior art, artificial marking and physical machine room matching method are mainly used to associate the loop condition of the bearing equipment and the security condition of the BBU equipment, wherein the artificial marking method is to directly mark the loop condition of the bearing equipment on the BBU equipment, or mark the ID of the BBU equipment bearing on each bearing equipment port, so that the security of the BBU equipment can be determined by the loop condition of the bearing equipment; the physical machine room matching method is to judge the security of the BBU equipment according to the loop proportion of the bearing equipment, wherein the bearing equipment and the BBU equipment are in the same machine room.
[0080] However, with the gradual evolution of the bearing network, artificial marking and physical machine room matching method cannot accurately realize the precise association of BBU equipment and bearing equipment, and there is a problem of low accuracy of wireless service security detection result.
[0081] To solve the above problems, the present application provides a wireless service security detection method, which determines the loop information of each bearing equipment according to the connection relationship between the BBU equipment and the corresponding bearing equipment in the bearing network and the connection relationship between the plurality of bearing equipment, the loop information is used to indicate whether the corresponding bearing equipment is looped, and the wireless service corresponding to the BBU equipment is subjected to bearing security detection processing according to the loop information of the plurality of bearing equipment; this method improves the accuracy of the wireless service security detection result by establishing the topological relationship between the BBU equipment and the bearing equipment.
[0082] The technical solutions of the present application and how the technical solutions of the present application solve the above technical problems will be described in detail below with specific examples. The following specific examples can be combined with each other, and the same or similar concepts or processes can not be described again in some examples. The embodiments of the present application will be described below with reference to the drawings.
[0083] Figure 1 The flow of the wireless service security detection method provided by the present application Figure 1 As shown in Figure 1 , the wireless service security detection method shown in the embodiment includes:
[0084] S101: Obtain the topology association information between the BBU device and the plurality of bearer devices, the topology association information including: the association relationship between the BBU device and the bearer devices in the corresponding bearer network, and the connection relationship between the plurality of bearer devices.
[0085] Wherein, the bearer network includes an access layer, a convergence layer and a core layer, each layer corresponding to a plurality of bearer devices. Among them, the access layer corresponding bearer device is access device, the convergence layer corresponding bearer device is convergence device, and the core layer corresponding bearer device is core device.
[0086] The bearer network is a network for transmitting service data, which can be composed of transmission devices and bearer devices, wherein the transmission devices can be: optical fiber, cable and microwave transmission medium, and the bearer devices can be: router, switch and gateway.
[0087] The BBU device is one of the mobile base station master devices, responsible for baseband digital signal processing, generally including two types of interfaces: front transmission and back transmission. The front transmission interface completes the connection with RRU or AAU through optical fiber, and the back transmission interface realizes the connection with 4, 5G core network elements through bearer network devices. In this embodiment, 4G BBU device and 5G BBU device are taken as examples for description.
[0088] At present, 4G BBU is mainly carried on IPRAN network, and the IP address format is IPv4. The IPRAN network bearer scheme includes end-to-end L3VPN hierarchical bearer scheme and end-to-end L2+L3 bearer scheme (access layer L2+core convergence layer L3, convergence device performs two or three layer bridging); 5G BBU is mainly carried on intelligent metropolitan area network, and adopts end-to-end L3VPN hierarchical bearer scheme, and the IP address format is IPv6.
[0089] The association between the BBU device and the bearer device in the corresponding bearer network is determined by the network architecture and device configuration. Generally, the BBU device is part of a distributed base station architecture located between the access network and the switch, while the bearer network is a network for transmitting various voice and data services, usually using optical fiber as the transmission medium.
[0090] The connection relationship between multiple bearer devices is usually determined by network design and configuration. In the bearer network, the connection between bearer devices (such as routers, switches, SDH, etc.) can be flexibly configured according to network size, topology, service demand, etc.
[0091] The association between the BBU device and the bearer device in the corresponding bearer network is achieved through fiber connection. This connection enables the mobile communication network to provide faster and more stable data transmission and communication services, thus meeting the needs of users.
[0092] S102: According to the connection relationship between the multiple bearer devices, determine the loop information of each bearer device, which indicates whether the corresponding bearer device is looped.
[0093] Determining the loop information of each bearer device requires analyzing the connection relationship between multiple bearer devices. First, the connection relationship between each bearer device needs to be clarified, including physical connection and virtual connection. Physical connection refers to the physical link connection between bearer devices, such as fiber connection; virtual connection refers to the communication protocol and routing configuration between devices, such as IP routing configuration.
[0094] According to the connection relationship between multiple bearer devices, it is determined whether there is a condition to form a loop. If there are multiple devices forming a loop, there is a loop; for the bearer devices with a loop, the starting point and ending point of the loop, the path of the loop, and the bandwidth of the loop need to be determined.
[0095] Determining the loop information of each bearer device is crucial for network troubleshooting and optimization, which helps to improve the reliability and performance of the network. At the same time, network design and configuration can also be carried out according to the loop information to avoid potential network problems.
[0096] S103: According to the loop information of the multiple bearer devices, perform bearer security detection processing on the wireless service corresponding to the BBU device.
[0097] According to the loop information of the multiple bearer devices, the wireless service corresponding to the BBU device can be subjected to bearer security detection processing. The detection can be carried out from the following aspects:
[0098] 1. Loop Detection: By detecting loop information in the carrying equipment, it is possible to determine whether a loop exists and take appropriate action based on the actual situation. For example, closing the loop and adjusting network configuration can ensure the security of wireless service carrying.
[0099] 2. Network Optimization: Based on the loop information of the bearer devices, the network can be optimized to improve the efficiency and security of wireless service delivery. For example, by adjusting the configuration of network devices and optimizing routing protocols, network performance and reliability can be improved to meet the ever-increasing demands of wireless services.
[0100] 3. Security Policy Formulation: By analyzing the loop information of the bearer devices, corresponding security policies can be formulated to protect the security of wireless services. For example, measures such as setting up firewalls and implementing access control can prevent unauthorized access and attacks, protecting the data security and integrity of wireless services.
[0101] Based on the loop information of multiple bearer devices, bearer security detection can be performed on the wireless services corresponding to the BBU device. This process ensures the normal operation and security of wireless services, improving network reliability and performance.
[0102] The wireless service security detection method provided in this embodiment obtains topology association information between a BBU device and multiple bearer devices. This topology association information includes the association relationship between the BBU device and bearer devices within the corresponding bearer network, as well as the connection relationship between the multiple bearer devices. Based on the connection relationship between the multiple bearer devices, loop formation information for each bearer device is determined. This loop formation information indicates whether the corresponding bearer device is looping. Based on the loop formation information of multiple bearer devices, bearer security detection processing is performed on the wireless service corresponding to the BBU device. This method improves the accuracy of wireless service security detection results by establishing the topology relationship between the BBU device and the bearer devices.
[0103] Figure 2 The process of the wireless service security detection method provided in this application Figure 2 .like Figure 1 As shown, this embodiment is... Figure 3 Based on the embodiments, the wireless service security detection method is described in detail. The wireless service security detection method shown in this embodiment includes:
[0104] S201: Obtain the first MAC address of the backhaul interface of the BBU device and the bearer device information of multiple candidate bearer devices, wherein the bearer device information is used to indicate the interface address and interface name of the corresponding candidate bearer device.
[0105] The first MAC address of the backhaul interface of the BBU device can be obtained by connecting to the BBU device through a command line interface or a network management tool, querying the relevant information of the backhaul interface in the command line interface or the network management tool of the BBU device, and the relevant information of the interface can include the state, configuration information, MAC address, etc. of the interface. According to the query result, the first MAC address of the backhaul interface is found. This is usually one of the MAC addresses displayed in the interface configuration information.
[0106] The interface address and interface name of the candidate bearer device can be obtained by connecting to the bearer device through a command line interface or a network management tool, querying the relevant information of the interface in the command line interface or the network management tool of the bearer device. This can include the state, configuration information, IP address, and interface name of the interface, etc. According to the query result, the interface address and interface name of the bearer device are found. The interface address is usually displayed in the form of an IP address, and the interface name can be the physical interface name of the device or a virtual interface name.
[0107] S202: Determine the interface type of each candidate bearer device according to the interface name of the plurality of candidate bearer devices.
[0108] The interface type of the bearer device can be preliminarily judged according to the interface name, because different interface types usually have different naming rules. Common interface types of bearer devices and their naming rules are as follows:
[0109] 1. Ethernet interface: Ethernet interface is one of the most widely used network interfaces, and its name usually starts with "Ethernet" or "eth", followed by a combination of numbers or letters. For example, "Ethernet 0 / 0 / 1" or "eth 0 / 0 / 1".
[0110] 2. Fiber interface: Fiber interface is usually used for high-speed data transmission, and its name usually starts with "fiber" or "fibre", followed by a combination of numbers or letters. For example, "fiber 0 / 0 / 1" or "fibre 0 / 0 / 1".
[0111] 3. Wireless interface: Wireless interface is used for wireless communication, and its name usually starts with "wlan" or "radio", followed by a combination of numbers or letters. For example, "wlan 0" or "radio 0".
[0112] 4. POS interface: POS interface is an interface for SDH transmission network, and its name usually starts with "pos", followed by a combination of numbers or letters. For example, "pos 1 / 1 / 1".
[0113] 5. Loopback Interface: The loopback interface is a virtual interface used to test and simulate network connections. Its name usually begins with "loopback" followed by a combination of numbers or letters. For example, "loopback 0".
[0114] S203: Based on the interface addresses of multiple candidate bearer devices, the interface type, and the first MAC address, determine multiple bearer devices that are associated with the BBU device from among the multiple candidate bearer devices.
[0115] Based on the interface addresses, interface types, and first MAC addresses of multiple bearer devices, multiple bearer devices that are associated with the BBU device can be identified from among the multiple bearer devices.
[0116] Understandably, based on the first MAC address of the BBU device's backhaul interface, the interface addresses of the bearer devices that match that MAC address are filtered out. This can be done by querying the MAC address table in the bearer device's command-line interface or network management tool. Among the filtered bearer devices, further filters are made based on the BBU device's interface type to identify bearer devices that match the BBU device's interface type. Based on the interface address, interface type, and first MAC address of the filtered bearer devices, multiple bearer devices that are associated with the BBU device can be determined.
[0117] S204: Based on the carrier device information of the multiple carrier devices, obtain the connection relationship between the multiple carrier devices.
[0118] Collect information about each bearer device, including its interface address, interface type, and first MAC address. This information can be obtained through network management tools, command-line interfaces, or other relevant documentation.
[0119] Based on the collected information about the bearer devices, the connection relationships between each bearer device can be analyzed. This includes both physical connections and logical connections. Physical connections refer to the physical link connections between devices, such as fiber optic connections; virtual connections refer to the communication protocols and routing configurations between devices, such as IP routing configurations.
[0120] Based on the analysis results, the connection relationships between multiple carrier devices can be determined. This includes which devices are connected, the interface types of the connections, and the connection paths.
[0121] S205: Obtain the hierarchical position of the bearer device in the bearer network.
[0122] First, it's necessary to understand the overall network architecture, including the devices at each layer and their interconnections. This helps in understanding the location of the bearer devices within the network.
[0123] By analyzing the connection relationship between the carrier device and other devices, its hierarchical position can be inferred. For example, if a carrier device is connected to a convergence layer device, it may be one level above the access layer.
[0124] The hierarchical position of the carrier device in the carrier network can be obtained by querying the configuration information or related documents of the device. This can include: interface information of the device, routing configuration, QOS policy, etc.
[0125] Some network management tools can provide a visual interface to help administrators easily manage and monitor the entire network. Through these tools, the position and hierarchy of the carrier device in the carrier network can be intuitively viewed.
[0126] S206: According to the connection relationship between the plurality of carrier devices and the hierarchical position, the plurality of carrier devices are loop identified, and it is judged whether each carrier device is in a loop.
[0127] The method for loop identification is:
[0128] Considering the configuration specification and protection switching of the network, this embodiment specifies that the access layer device of the carrier network loop rule is: nodes can be connected to the upper node in a single-point or double-point manner through two physical directions, but loops of two levels or more (not including two levels) are not identified as loops, and the main loop is identified according to the principle of minimum COST value.
[0129] All access devices under the convergence device are traversed hop by hop, and if the termination point access device is connected to a "convergence device", all nodes on the path are identified as "pending first-level loop", and access start and end points consistent with the pending loop are coded as a group.
[0130] The main loop is identified by the COST value configured in the IGP protocol, the sum of the COST values of each link in the "pending first-level loop" is calculated, and the loop with the minimum COST value in the "pending first-level loop group" is identified as the main loop, i.e. the first-level loop. All nodes on the loop are identified as first-level loop nodes.
[0131] The second-level loop identification method is similar to the first-level loop identification method. First, all access devices (defined as second-level access devices) under the first-level loop nodes are traversed hop by hop, and if the termination point of the second-level access device is connected to an "access device" on the first-level loop, it is identified as a pending "second-level loop", and the second-level access start and end points consistent with the second-level pending loop are coded as a group.
[0132] The main loop is determined by the COST value configured in the IGP protocol, and the sum of the COST values of each link in the "pending secondary loop" is calculated. The loop with the minimum COST value in the "pending secondary loop group" is determined as the main loop, i.e. the secondary loop. All nodes on the loop are determined as secondary loop nodes.
[0133] The step of determining whether each bearing device forms a loop can be:
[0134] First, analyze the connection paths between each bearing device based on the collected connection relationships between bearing devices. This can be achieved by drawing a network topology diagram or using network management tools.
[0135] Determine the hierarchical position of each bearing device in the bearing network based on its configuration information or related documents. This helps determine whether the device's connection will form a loop.
[0136] When analyzing the connection relationship, pay attention to whether there is a loop connection path. If there is a loop, it means that the connection between some bearing devices forms a loop structure.
[0137] For each bearing device, determine whether it forms a loop based on its connection relationship and hierarchical position. If the bearing device is in the loop, it is considered to form a loop; otherwise, it is considered not to form a loop.
[0138] S207: Obtain the geographical position of the bearing device and the geographical position of the BBU device.
[0139] Check the labels or related documents on the bearing device and BBU device. Usually, these devices will record their geographical position information during installation.
[0140] If a device management system is used to monitor and manage network devices, the geographical position information of the bearing device and BBU device can be found in the system. These systems usually record the physical location and other related information of the devices.
[0141] Refer to the network topology diagram, which usually shows the connection relationship and position of the devices. By analyzing the topology diagram, the approximate geographical position of the bearing device and BBU device can be inferred.
[0142] If the bearing device and BBU device support GPS function, the precise geographical position information of them can be obtained by using GPS receiver. This requires enabling GPS function on the device and using appropriate software or tools for positioning.
[0143] S208: Determine whether the geographical position of the bearing device and the geographical position of the BBU device are consistent.
[0144] Compare the geographical location information: After obtaining the geographical location information of the bearer device and the BBU device, compare them. If the bearer device and the BBU device are located in the same geographical location, it can be judged that their geographical locations are consistent.
[0145] Reference the network topology diagram to observe the connection relationship between the bearer device and the BBU device. If they are located in the same subnet or routing path, and there is no obvious network delay or packet loss problem, it can be inferred that their geographical locations are close or consistent.
[0146] Use a special routing analysis tool to check the routing path and distance between devices in the network. By analyzing the routing information, the distance between the bearer device and the BBU device and whether they are located in the same routing path can be determined.
[0147] Check the network configuration file or related documents to determine whether the bearer device and the BBU device are located in the same VLAN, subnet or routing domain. If they are located in the same network domain, their geographical locations may be consistent.
[0148] S209: When the bearer device forms a ring, determine whether the ring corresponding to the bearer device is identified as a large ring, the large ring indicating that the number of bearer devices on the ring is greater than a first preset number.
[0149] Wherein, the first preset number can be 20, when the bearer device forms a ring, the number of bearer devices on the ring is greater than 20, the ring corresponding to the bearer device is identified as a large ring.
[0150] S210: When the ring corresponding to the bearer device is identified as a large ring, it is determined that the wireless service bearer security detection result corresponding to the BBU device is that there is a first security risk.
[0151] Wherein, the first security risk indicates that the wireless service bearer corresponding to the BBU device has a large security risk.
[0152] When the ring corresponding to the bearer device is identified as a large ring, the wireless service bearer security detection result corresponding to the BBU device is that there is a large security risk.
[0153] S211: When the bearer device does not form a ring, determine whether the bearer device is identified as a long chain, the long chain indicating that the number of bearer devices under the same cable is greater than a second preset number.
[0154] Wherein, the second preset number can be 3, and a single chain with more than 3 nodes on the same chain is identified as a long chain.
[0155] S212: If the single chain corresponding to the bearer device is identified as a long chain, it is determined that the wireless service bearer security detection result corresponding to the BBU device exists the first security risk and the second security risk.
[0156] The second security risk is used to indicate that the wireless service bearer corresponding to the BBU device exists a potential security risk.
[0157] When the bearer device is not in a loop, the wireless service bearer security detection result corresponding to the BBU device exists a potential security risk; when the single chain corresponding to the bearer device is identified as a long chain, the wireless service bearer security detection result corresponding to the BBU device exists a greater security risk and a potential security risk.
[0158] S213: When the geographical position of the bearer device and the geographical position of the BBU device are inconsistent, it is determined that the loop information of the bearer device is not in a loop.
[0159] The geographical position can include a machine room name and latitude and longitude information.
[0160] It can be understood that when the machine room name and / or the latitude and longitude information of the bearer device and the BBU device are inconsistent, it is determined that the bearer device is not in a loop.
[0161] S214: When the bearer device is not in a loop, it is determined that the wireless service bearer security detection result corresponding to the BBU device exists the second security risk.
[0162] When the machine room name and / or the latitude and longitude information of the bearer device and the BBU device are inconsistent, it is determined that the bearer device is not in a loop, indicating that the wireless service bearer security detection result corresponding to the BBU device exists a potential security risk.
[0163] The wireless service security detection method provided in the embodiment comprises the following steps.
[0164] Figure 3 The wireless service security detection method provided in the embodiment comprises the following steps. Figure 2 As shown in Figure 4 , the embodiment is based on the embodiment, and the multiple bearer devices associated with the BBU device are determined in detail. Figure 4 The wireless service security detection method provided in the embodiment comprises the following steps.
[0165] S301: Determine the interface type of each candidate bearer device according to the interface names of the multiple candidate bearer devices.
[0166] The step S301 is similar to the step S202, and thus is not described herein.
[0167] S302: If the interface type is a physical interface type, perform parsing processing on the interface address of the candidate bearer device to obtain a second MAC address of the candidate bearer device, wherein the interface address is an IP address.
[0168] When the interface type of the bearing device is a physical interface type, it can be determined that the wireless service accessed through the interface is accessed to the L3 VPN in a direct connection manner, and the interface and the device are the bearing interface and the device directly accessed by the BBU. At this time, the second MAC address of the candidate bearing device can be obtained through the ARP protocol.
[0169] After the current network service is cut, there is a case that the link is removed after cutting but the port configuration is not deleted. If IP address static matching is used, there may be a case that multiple end device bearing devices of the same BBU are matched, causing matching errors. Using the ARP dynamic protocol can avoid matching errors caused by service cutting, and can improve the matching success rate.
[0170] S303: When the first MAC address and the second MAC address are consistent, it is determined that the candidate bearing device is a bearing device having an association relationship with the BBU device.
[0171] When the first MAC address and the second MAC address are consistent, it is determined that the candidate bearing device is a bearing device having an association relationship with the BBU device.
[0172] S304: If the interface type is a virtual interface type, the corresponding L2 VPN service instance is determined according to the interface address of the candidate bearing device, and the bridge mode of the candidate bearing device is determined according to the number of bridges corresponding to the L2 VPN service instance.
[0173] If the interface type is a virtual interface type, it can be determined that the access manner of the wireless service is an L2+L3 manner, and the interface on the corresponding bearing device is an L3 VE interface. The PW tunnel manner can be used to establish a backhaul service between the access device and the aggregation device, the L3 VPN manner can be used to establish a backhaul service between the aggregation device and the core device, the aggregation device can realize L2 and L3 bridging, and the base station is physically connected to the access device, but the three-layer gateway is the L3 VE interface of the aggregation device connected to the access device. At this time, there are two modes:
[0174] 1) 1:1 mode, that is, the L3 VE of the aggregation device and the L2 VE / PW channel are one-to-one corresponding, and each base station corresponds to one gateway;
[0175] 2) 1:N mode, one L3 VE corresponds to multiple L2 VE and multiple PW channels, at this time, multiple base stations share one gateway, and this mode can save IP address resources.
[0176] The interface name, VLAN ID and opposite end MAC address of the L3 VE are obtained on the aggregation device where the virtual interface type is located through the ARP protocol, the corresponding bridge group is found according to the L3 VE interface name, and then the corresponding L2 VE name and VLAN ID are found, the L2 VPN instance (VFI) is queried according to the L2 VE name and VLAN ID information, and the number of PWs under the VFI is queried to determine the two modes, if there is only one PW tunnel under the VFI, it is determined as the 1:1 mode, otherwise, it is the 1:N mode.
[0177] S305: When the bridge mode is the first bridge mode, the remote IP corresponding to the candidate bearing device is queried according to the L2 VPN service instance, and when the remote IP matches the first MAC address, it is determined that the candidate bearing device is a bearing device having an association relationship with the BBU device.
[0178] The first bridge mode is the 1:1 mode. According to the L2 VPN instance detailed information, the remote IP address corresponding to the PW instance is found. In the standard configuration scheme, the base station service is a single segment pseudo-wire bearing, so the remote IP is the bearing network access device network element. Thus, the association relationship table of the BBU MAC address and the access device IP address is obtained, the BBU device ID queried by the wireless network management is matched and screened with the BBU MAC address, and the relationship table of the BBU device ID and the access device IP address is obtained, and the topology association of the BBU device and the bearing network access device in the 1:1 mode is completed.
[0179] S306: When the bridge mode is the second bridge mode, it is judged whether the L2 VPN service instance matches the first MAC address and the Loopback address of the candidate bearing device.
[0180] S307: If matched, it is determined that the candidate bearing device is a bearing device having an association relationship with the BBU device
[0181] The second bridge mode is the 1:N mode. When the 1:N mode is adopted, the forwarding table corresponding to the VFI is found, and the BBU MAC and the access layer device Loopback address are matched. Thus, the association relationship table of the BBU MAC address and the access device Loopback address is obtained, the BBU device ID queried by the wireless network management is matched and screened with the BBU MAC address, and the relationship table of the BBU device ID and the access device Loopback address is obtained, and the topology association of the BBU device and the bearing device in the 1:N mode is completed.
[0182] The wireless service security detection method provided by the embodiment determines the interface type of each candidate bearing device according to the interface name of the plurality of candidate bearing devices, performs parsing processing on the interface address of the candidate bearing device if the interface type is a physical interface type, to obtain the second MAC address of the candidate bearing device, wherein the interface address is an IP address, and when the first MAC address and the second MAC address are consistent, it is determined that the candidate bearing device is a bearing device having an association relationship with the BBU device, if the interface type is a virtual interface type, according to the interface address of the candidate bearing device, the corresponding L2 VPN service instance is determined, and according to the bridge quantity corresponding to the L2 VPN service instance, the bridge mode of the candidate bearing device is determined, when the bridge mode is a first bridge mode, according to the L2 VPN service instance, the remote IP corresponding to the candidate bearing device is queried, and when the remote IP matches the first MAC address, it is determined that the candidate bearing device is a bearing device having an association relationship with the BBU device, when the bridge mode is a second bridge mode and the L2 VPN service instance matches the first MAC address and the Loopback address of the candidate bearing device, it is determined that the candidate bearing device is a bearing device having an association relationship with the BBU device; the method establishes the topological relationship between the BBU device and the bearing device, and improves the accuracy of the wireless service security detection result.
[0183] Figure 5 The structure diagram of the wireless service security detection device provided by the present application is shown in the figure. Figure 5 The wireless service security detection device 400 provided by the embodiment includes:
[0184] The acquisition module 401 is configured to acquire the topological association information between the BBU device and the plurality of bearing devices, wherein the topological association information includes the association relationship between the BBU device and the bearing device in the corresponding bearing network and the connection relationship between the plurality of bearing devices.
[0185] The determination module 402 is configured to determine the loop information of each bearing device according to the connection relationship between the plurality of bearing devices, wherein the loop information is used to indicate whether the corresponding bearing device is looped.
[0186] The processing module 403 is configured to perform bearing security detection processing on the wireless service corresponding to the BBU device according to the loop information of the plurality of bearing devices.
[0187] Optionally, the acquisition module 401 is further configured to acquire a first MAC address of a backhaul interface of the BBU device and backhaul device information of a plurality of candidate backhaul devices, the backhaul device information being used to indicate an interface address and an interface name of a corresponding candidate backhaul device.
[0188] The determination module 402 is further configured to determine an interface type of each candidate backhaul device according to the interface names of the plurality of candidate backhaul devices.
[0189] The determination module 402 is further configured to determine, from the plurality of candidate backhaul devices, a plurality of backhaul devices having an association relationship with the BBU device according to the interface addresses of the plurality of candidate backhaul devices, the interface types and the first MAC address.
[0190] The determination module 402 is further configured to obtain a connection relationship between the plurality of backhaul devices according to the backhaul device information of the plurality of backhaul devices.
[0191] Optionally, the wireless service security detection apparatus further includes a judgment module 404.
[0192] The processing module 403 is further configured to, if the interface type is a physical interface type, perform parsing processing on the interface address of the candidate backhaul device to obtain a second MAC address of the candidate backhaul device, wherein the interface address is an IP address.
[0193] The determination module 402 is further configured to determine that the candidate backhaul device is a backhaul device having an association relationship with the BBU device if the first MAC address and the second MAC address are consistent.
[0194] The determination module 402 is further configured to, if the interface type is a virtual interface type, determine a corresponding L2 VPN service instance according to the interface address of the candidate backhaul device, and determine a bridging mode of the candidate backhaul device according to a number of bridges corresponding to the L2 VPN service instance.
[0195] The determination module 402 is further configured to, if the bridging mode is a first bridging mode, query a remote IP corresponding to the candidate backhaul device according to the L2 VPN service instance, and determine that the candidate backhaul device is a backhaul device having an association relationship with the BBU device if the remote IP matches the first MAC address.
[0196] The judgment module 404 is configured to, if the bridging mode is a second bridging mode, judge whether the L2 VPN service instance matches the first MAC address and a Loopback address of the candidate backhaul device.
[0197] The determining module 402 is further configured to determine that the candidate carrying device is a carrying device having an association relationship with the BBU device if the L2 VPN service instance matches the first MAC address and a Loopback address of the candidate carrying device.
[0198] Optionally, the obtaining module 401 is further configured to obtain a hierarchical position of a carrying device in a carrying network.
[0199] The processing module 403 is further configured to determine a loop of the plurality of carrying devices according to the connection relationship among the plurality of carrying devices and the hierarchical position.
[0200] The judging module 404 is further configured to judge whether each carrying device is looped.
[0201] Optionally, the obtaining module 401 is further configured to obtain a geographical position of a carrying device and a geographical position of the BBU device.
[0202] The judging module 404 is further configured to judge whether the geographical position of the carrying device is consistent with the geographical position of the BBU device.
[0203] The determining module 402 is further configured to determine that the loop information of the carrying device is not looped when the geographical position of the carrying device is not consistent with the geographical position of the BBU device.
[0204] Optionally, the judging module 404 is further configured to judge whether a loop corresponding to the carrying device is determined as a large loop when the carrying device is looped, the large loop being used to indicate that a quantity of carrying devices on the loop is greater than a first preset quantity.
[0205] The determining module 402 is further configured to determine that the wireless service carrying security detection result corresponding to the BBU device has a first security risk when the loop corresponding to the carrying device is determined as the large loop.
[0206] Optionally, the determining module 402 is further configured to determine that the wireless service carrying security detection result corresponding to the BBU device has a second security risk when the carrying device is not looped.
[0207] The judging module 404 is further configured to judge whether the carrying device is determined as a long chain when the carrying device is not looped, the long chain being used to indicate that a quantity of carrying devices under a same cable is greater than a second preset quantity.
[0208] The determining module 402 is further configured to determine that the wireless service carrying security detection result corresponding to the BBU device has the first security risk and the second security risk if a single chain corresponding to the carrying device is determined as the long chain.
[0209] The structure schematic diagram of the wireless service security detection device provided by the present application is shown. As shown in the figure, the present application provides a wireless service security detection device 500, which comprises a receiver 501, a transmitter 502, a processor 503 and a memory 504.
[0210] The receiver 501 is used for receiving instructions and data.
[0211] The transmitter 502 is used for transmitting instructions and data.
[0212] The memory 504 is used for storing computer execution instructions.
[0213] The processor 503 is used for executing the computer execution instructions stored in the memory 504, so as to realize each step executed by the wireless service security detection method in the above-mentioned embodiments. For details, please refer to the related description in the foregoing wireless service security detection method embodiments.
[0214] Optionally, the memory 504 can be independent or integrated with the processor 503.
[0215] When the memory 504 is independently arranged, the electronic device further comprises a bus for connecting the memory 504 and the processor 503.
[0216] The present application also provides a computer readable storage medium, which stores computer execution instructions. When the processor executes the computer execution instructions, the wireless service security detection method executed by the wireless service security detection device is realized.
[0217] It should be noted that, for the foregoing method embodiments, in order to simply describe, they are all expressed as a series of action combinations, but those skilled in the art should know that the present application is not limited to the action order described, because according to the present application, certain steps can be performed in other order or simultaneously. Secondly, those skilled in the art should know that the embodiments described in the specification all belong to optional embodiments, and the actions and modules involved are not necessarily required by the present application.
[0218] It should be further noted that although the steps in the flowchart are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowchart may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the sub-steps or stages of other steps.
[0219] It should be understood that the above-described device embodiments are merely illustrative, and the device of this application can also be implemented in other ways. For example, the division of units / modules in the above embodiments is only a logical functional division, and there may be other division methods in actual implementation. For example, multiple units, modules, or components may be combined, or integrated into another system, or some features may be ignored or not executed.
[0220] Furthermore, unless otherwise specified, the functional units / modules in the various embodiments of this application can be integrated into one unit / module, or each unit / module can exist physically separately, or two or more units / modules can be integrated together. The integrated units / modules described above can be implemented in hardware or as software program modules.
[0221] When integrated units / modules are implemented in hardware, the hardware can be digital circuits, analog circuits, etc. The physical implementation of the hardware structure includes, but is not limited to, transistors, memristors, etc. Unless otherwise specified, the processor can be any suitable hardware processor, such as a CPU, GPU, FPGA, DSP, and ASIC, etc. Unless otherwise specified, the storage unit can be any suitable magnetic or magneto-optical storage medium, such as Resistive Random Access Memory (RRAM), Dynamic Random Access Memory (DRAM), Static Random Access Memory (SRAM), Enhanced Dynamic Random Access Memory (EDRAM), High-Bandwidth Memory (HBM), Hybrid Memory Cube (HMC), etc.
[0222] If the integrated units / modules are implemented in the form of software program modules and sold or used as independent products, they can be stored in a computer readable memory. Based on such understanding, the technical solutions of the present application essentially or the part that contributes to the prior art or the whole or part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a memory and includes a number of instructions for causing a computer device (which can be a personal computer, a server or a network device, etc.) to execute all or part of the steps of the embodiments of the method of the present application. The aforementioned memory includes: a U disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a mobile hard disk, a magnetic disk or an optical disk, and various media that can store program codes.
[0223] In the above embodiments, the description of each embodiment has its own focus, and the parts not described in detail in a certain embodiment can be referred to the related description of other embodiments. The technical features of the above embodiments can be combined arbitrarily. In order to make the description concise, not all possible combinations of the technical features in the above embodiments are described, however, as long as the combinations of the technical features do not exist contradictory, they should be considered as the scope of the present application
[0224] Other embodiments of the application will be apparent to those skilled in the art from consideration of the specification and practice of the application disclosed herein. The application is intended to cover any variations, uses or adaptations of the application following, in general, the principles of the application and including such departures from the present disclosure as come within known or customary practice in the art to which the application pertains or can relate. The specification and examples are to be regarded as exemplary only, and the true scope and spirit of the application are indicated by the following claims.
[0225] It should be understood that the application is not limited to the precise construction that has been described above and shown in the accompanying drawings, and that various modifications and changes can be made by those skilled in the art without departing from the scope of the application. The scope of the application is limited only by the appended claims.
Claims
1. A method of detecting security of wireless service, characterized by, The method comprises: obtaining topology association information between a BBU device and a plurality of bearer devices, the topology association information comprising: an association relationship between the BBU device and a bearer device in a corresponding bearer network and a connection relationship between the plurality of bearer devices; determining ring information of each bearer device according to the connection relationship between the plurality of bearer devices, the ring information being used to indicate whether the corresponding bearer device is in a ring; performing bearer security detection processing on wireless services corresponding to the BBU device according to the ring information of the plurality of bearer devices.
2. The method of claim 1, wherein, The obtaining of the topology association information between the BBU device and the plurality of bearer devices comprises: obtaining a first MAC address of a backhaul interface of the BBU device and bearer device information of a plurality of candidate bearer devices, the bearer device information being used to indicate an interface address and an interface name of a corresponding candidate bearer device; determining an interface type of each candidate bearer device according to the interface name of the plurality of candidate bearer devices; determining a plurality of bearer devices having an association relationship with the BBU device from the plurality of candidate bearer devices according to the interface address, the interface type and the first MAC address of the plurality of candidate bearer devices; obtaining a connection relationship between the plurality of bearer devices according to the bearer device information of the plurality of bearer devices.
3. The method of claim 2, wherein, The interface type comprises a physical interface type and a virtual interface type, and the determining of the plurality of bearer devices having an association relationship with the BBU device from the plurality of candidate bearer devices according to the interface address, the interface type and the first MAC address of the plurality of candidate bearer devices comprises: if the interface type is the physical interface type, performing parsing processing on the interface address of the candidate bearer device to obtain a second MAC address of the candidate bearer device, wherein the interface address is an IP address; if the first MAC address and the second MAC address are consistent, determining that the candidate bearer device is a bearer device having an association relationship with the BBU device; if the interface type is the virtual interface type, determining a corresponding L2 VPN service instance according to the interface address of the candidate bearer device, and determining a bridging mode of the candidate bearer device according to a number of bridges corresponding to the L2 VPN service instance; if the bridging mode is a first bridging mode, querying a remote IP corresponding to the candidate bearer device according to the L2 VPN service instance, and if the remote IP matches the first MAC address, determining that the candidate bearer device is a bearer device having an association relationship with the BBU device; if the bridging mode is a second bridging mode, judging whether the L2 VPN service instance matches the first MAC address and a Loopback address of the candidate bearer device; if the match is found, determining that the candidate bearer device is a bearer device having an association relationship with the BBU device.
4. The method of claim 1, wherein, The determining of the ring information of each bearer device according to the connection relationship between the plurality of bearer devices comprises: obtaining a hierarchical position of the bearer device in the bearer network; According to the connection relationship among the plurality of carrying devices and the hierarchical position, loop identification is performed on the plurality of carrying devices, and it is determined whether each carrying device is in a loop.
5. The method of claim 1, wherein, The determination of the loop information of each carrying device according to the connection relationship among the plurality of carrying devices comprises: Obtaining the geographical position of the carrying device and the geographical position of the BBU device; Determining whether the geographical position of the carrying device and the geographical position of the BBU device are consistent; When the geographical position of the carrying device and the geographical position of the BBU device are inconsistent, it is determined that the loop information of the carrying device is not in a loop.
6. The method according to claim 4 or 5, characterized in that, The carrying safety detection processing of the wireless service corresponding to the BBU device according to the loop information of the plurality of carrying devices comprises: When the carrying device is in a loop, it is determined whether the loop corresponding to the carrying device is identified as a large loop, and the large loop is used to indicate that the number of carrying devices in the loop is greater than a first preset number; When the loop corresponding to the carrying device is identified as a large loop, it is determined that the wireless service carrying safety detection result corresponding to the BBU device has a first security risk.
7. The method according to claim 4 or 5, characterized in that, The carrying safety detection processing of the wireless service corresponding to the BBU device according to the loop information of the plurality of carrying devices comprises: When the carrying device is not in a loop, it is determined that the wireless service carrying safety detection result corresponding to the BBU device has a second security risk; When the carrying device is not in a loop, it is determined whether the carrying device is identified as a long chain, and the long chain is used to indicate that the number of carrying devices under the same cable is greater than a second preset number; If the single chain corresponding to the carrying device is identified as a long chain, it is determined that the wireless service carrying safety detection result corresponding to the BBU device has a first security risk and a second security risk.
8. A wireless service security detection device, characterized in that, Comprise: The acquisition module is used for acquiring the topology association information between the BBU device and the plurality of carrying devices, and the topology association information comprises the association relationship between the BBU device and the carrying device in the corresponding carrying network and the connection relationship among the plurality of carrying devices; The determination module is used for determining the loop information of each carrying device according to the connection relationship among the plurality of carrying devices, and the loop information is used to indicate whether the corresponding carrying device is in a loop; The processing module is used for performing carrying safety detection processing on the wireless service corresponding to the BBU device according to the loop information of the plurality of carrying devices.
9. A wireless service security detection apparatus characterized by comprising: Comprise: A processor and a memory connected with the processor in communication; The memory stores computer execution instructions; The processor executes the computer execution instructions stored in the memory to realize the method in any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, The computer readable storage medium stores computer execution instructions, and the computer execution instructions are executed by the processor to realize the method in any one of claims 1 to 7.
Citation Information
Patent Citations
Network fault analysis method and device, server and storage medium
CN111510331A
Fault positioning method, device and equipment and computer storage medium
CN111836288A