5G core network element device with safety control function

By integrating data acquisition, global security analysis and unified decision-making control modules in the 5G core network element device, the problem of lack of global security correlation analysis and unified security handling decision-making in the existing technology is solved, and efficient security management and rapid response capabilities for the 5G communication network are achieved.

CN120151892AActive Publication Date: 2025-06-13INSTITUTE OF INFORMATION ENGINEERING CHINESE ACADEMY OF SCIENCES
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510210983.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-25
Publication Date
2025-06-13
Estimated Expiration
2045-02-25

AI Technical Summary

Technical Problem

The existing 5G communication network security protection measures lack the ability to analyze global security correlation and unified security handling decision-making and implementation capabilities, and it is difficult to effectively deal with complex network security threats.

Method used

Design a 5G core network element device with security control functions, including data acquisition and processing module, global security analysis module and unified decision-making control module to realize the overall security event correlation analysis of the 5G communication network and the unified formulation, issuance and implementation of security handling decisions.

Benefits of technology

It significantly improves the security management capabilities and efficiency of the 5G communication network, realizes monitoring and analysis of the global security situation of the 5G communication network, and can quickly respond to and handle security events.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120151892A_ABST
    Figure CN120151892A_ABST
Patent Text Reader

Abstract

The invention discloses a 5G core network element device with a security control function, which is characterized by comprising a data acquisition and processing module, a global security analysis module and a unified decision control module, the data acquisition and processing module acquires security monitoring data of the base station, the core network and the terminal and stores the security monitoring data in the database; the global security analysis module performs association analysis on the data in the database and transmits an analysis result to the unified configuration and display system; the correlation analysis method comprises the following steps: if collected safety monitoring data are all safety events, performing multivariate safety event correlation analysis on the safety events to form a global safety event; otherwise, performing multivariate alarm data association on the monitoring alarm information to form a plurality of alarm data clusters, and converting an association analysis result into a global security event by adopting a deep clustering event recognition method; and the unified decision control module generates a corresponding security disposal decision based on the early warning level corresponding to the global security event and issues the security disposal decision to the PCF network element.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of network communication, and relates to a 5G core network element device with a security control function. Background Art

[0002] With the development of mobile communication technology, especially the wide deployment of the fifth-generation (5G) mobile communication technology, both the data transmission speed of the network and the number of connected devices have been significantly improved. The 5G communication network mainly consists of three parts: the core network, the radio access network, and user equipment. The core network is the most critical part of the 5G architecture and is responsible for core functions such as mobility management, session management, and policy control.

[0003] The 5G communication network, especially the 5G core network, faces more and more security challenges. The existing security protection measures for the 5G communication network are mainly divided into two categories. The first category is IT-based protection measures, which usually deploy security protection devices at different positions in the 5G communication network to achieve network security protection. For example, a wireless signal detection system is deployed on the radio access network (RAN) side, a firewall, an intrusion detection system, and a security audit system are deployed on the core network (CN) side, and a terminal management and control system is deployed on the data network (DN) side, etc. These IT-based protection measures mainly focus on the security protection of information systems and data in the communication network, but these protection measures cannot perform signaling protection for the core network, radio access network, and terminal devices in the 5G communication network. The second category is CT-based protection measures. For example, for security threats such as illegal access of terminals, signaling traffic is collected for security detection to prevent illegal terminals from accessing. These measures have solved the CT-based security protection problems of the 5G communication network to a certain extent, but these measures only perform security protection for a certain part of the terminal, base station, and core network, the protection scope is limited, and there is a lack of overall unified security analysis ability. At the same time, the existing security protection measures also lack security disposal decision-making and security control mechanisms, making it difficult to cope with increasingly complex network threats. For example, when multiple security events occur in the core network and access network, each node is difficult to form a joint force, resulting in the security events not being handled in a timely and effective manner.

[0004] Therefore, the existing security protection of the 5G communication network focuses on separately performing security detection for different components such as terminals, base stations, and 5G core networks. This method will expose obvious deficiencies when dealing with increasingly complex network security threats:

[0005] 1) The existing technical measures lack the ability to perform global security correlation analysis on the 5G communication network. For example: in the existing security detection methods, each security detection node of the base station, terminal, and core network is relatively independent, and the scope of action of each is only limited to the location where it is deployed. It is difficult to comprehensively grasp the security situation of the entire 5G communication network and perform overall and unified security analysis on the communication network.

[0006] 2) The prior art lacks the ability to make unified security disposal decisions and issue and implement them. Currently, the security protection for 5G communication networks mainly analyzes and warns of security threats existing in the network through monitoring, lacking the ability to formulate protection strategies and perform security control on security threats. For example, in the current protection method, when a base station detects the access of an abnormal terminal, the communication network cannot effectively obtain the abnormal information and formulate a security protection strategy to perform security control on the abnormal terminal. Summary of the Invention

[0007] Aiming at the problems existing in the prior art, the purpose of the present invention is to provide a 5G core network element device with a security control function. The present invention can realize the overall security event correlation analysis, unified formulation, issuance and implementation of security disposal decisions for the mobile communication network; and uniformly monitor, analyze in real time and quickly respond to various security events in the mobile communication network, thereby significantly improving the security management ability and efficiency of the 5G communication network.

[0008] The present invention realizes the overall security perception and correlation analysis ability of the 5G communication network including the core network, radio access network and user equipment by obtaining security monitoring data from different data sources; at the same time, formulates a unified security disposal decision according to the global security correlation analysis result, and effectively issues it to quickly respond to potential security threats, thereby realizing centralized security control management. It mainly includes the following contents:

[0009] (1) A unified security control center architecture is formed. The security control center is responsible for collecting data from terminals, base stations and the 5G core network, providing a unified security disposal decision for the whole network, ensuring the consistency and real-time nature of policy formulation. Compared with the prior art, after discovering a security event, the present invention can quickly and effectively formulate and implement corresponding security disposal decisions, improving the response ability and processing efficiency for security threats.

[0010] (2) It can dynamically adjust security policies based on the reported data and seamlessly connect with the existing 5G core network architecture. Compared with the prior art, the present invention has the ability to formulate protection strategies and perform security control.

[0011] (3) It can establish a multi-level early warning mechanism, classify security events into serious, relatively large and general according to their severity and influence scope, corresponding to different levels of security threats respectively. Compared with the lack of a systematic early warning mechanism in the existing 5G core network, the present invention can more accurately identify and classify security events, ensure reasonable resource allocation and timely response, and effectively improve the refinement and systematic level of network security management.

[0012] The technical solution of the present invention is as follows:

[0013] A 5G core network element device with a security control function, characterized in that it includes a data acquisition and processing module, a global security analysis module, and a unified decision-making and control module;

[0014] The data acquisition and processing module is used to collect security monitoring data of base stations, core networks, and terminals, convert it into a unified format, and store it in a database; the security monitoring data includes monitoring alarm information and security event data;

[0015] The global security analysis module is used to perform correlation analysis on the data in the database and transfer the analysis results to a unified configuration and display system; among them, the method for performing correlation analysis on the data in the database is: if the security monitoring data collected from base stations, core networks, and terminals are all security events, then perform multi-source security event correlation analysis on the security events to form global security events; otherwise, perform multi-source alarm data correlation on the monitoring alarm information collected from base stations, core networks, and terminals to form several alarm data clusters, and then use a deep clustering event recognition method to convert the correlation analysis results into global security events;

[0016] The unified decision-making and control module is used to divide the global security events into different event levels, map different event levels to corresponding warning levels, and generate corresponding security disposal decisions based on the warning levels and send them to the PCF network element of the 5G core network.

[0017] Further, the method for performing multi-source security event correlation analysis on security events to form global security events is: define a time window τ, if the timestamps of security events from different sources are within the same time window τ, then correlate the security events from different sources to form an event cluster, and form a global security event according to the description information of the event cluster; the method for performing multi-source alarm data correlation includes, but is not limited to, timestamp correlation method, device identifier correlation method, and alarm level correlation method.

[0018] Further, the security disposal decision includes a decision identification code, an execution priority, an execution time, and a persistence.

[0019] Further, count the information with the highest frequency of occurrence in the event description information in the event cluster as the description Incident of the global security event desc , use the earliest event occurrence time in the event cluster as the occurrence time timestamp of the global security event, and determine the event type Incident of the global security event according to the event type in the event cluster type .

[0020] Further, the deep clustering event recognition method is adopted to convert the alarm data cluster into a global security event, and the conversion method is as follows: extract the alarm description keyword information with the highest occurrence frequency in the alarm description information to form the global security event description Incident desc , use the earliest alarm occurrence time in the alarm data cluster as the occurrence time timestamp of the global security event, and determine the event type Incident of the global security event according to the alarm type in the alarm data cluster type .

[0021] Further, convert the monitoring alarm data in the security monitoring data into a unified format: D AlarmData = {timestamp, ID src , ID dst , alarm type , alarm level , alarm desc}; where D AlarmDat represents the monitoring alarm data, timestamp represents the timestamp, ID src represents the source ID, ID dst represents the destination ID, alarm type represents the alarm type, alarm level represents the alarm level, alarm desc represents the alarm description; convert the security event data in the security monitoring data into a unified format: D SecurityIncident = {timestamp, Incident type , Incident desc}; where D SecurityI represents the security event data, timesta represents the event occurrence time, Incident type represents the event type, Incident desc represents the event description.

[0022] Further, the unified decision control module interacts with the PCF network element of the 5G core network through an external interface to implement the issuance of security disposal decisions; the global security analysis module transmits the monitoring alarm information data and security event data through an external interface for visual display by the unified configuration and display system; the data collection and storage module conducts data interaction with the global security analysis module and the unified decision control module through an internal interface; the internal interface uses an architecture based on a data bus for information transmission, and the external interface uses an encrypted communication protocol based on national secret TLS for communication.

[0023] Further, the monitoring and alarm information collected from the base station includes, but is not limited to, random access alarms, RRC connection establishment alarms, and RRC connection re - establishment alarms. The security event data collected from the base station includes, but is not limited to, 5G abnormal terminal access attack events and DDos attack events. The monitoring and alarm information collected from the core network includes, but is not limited to, initial registration abnormal alarms, PDU session establishment request abnormal alarms, and service request abnormal alarms. The security event data collected from the core network includes, but is not limited to, registration abnormal events, PDU session process abnormal events, and service request abnormal events. The monitoring and alarm information collected from the terminal includes, but is not limited to, terminal status alarms and illegal use alarms. The security event data collected from the terminal includes, but is not limited to, terminal status abnormal events and terminal illegal use events.

[0024] Further, a multi - dimensional scoring algorithm is used to divide the global security events into different event levels. The method is as follows: a security score corresponding to the global security event is generated according to the network harm degree, influence range, occurrence frequency, and duration of the global security event, and the event level of the corresponding global security event is determined according to the security score. The harm degree includes whether the global security event causes network interruption and whether it causes restricted access to applications. The influence range includes the number of terminals, base stations, and core network elements paralyzed by the global security event.

[0025] Further, the event levels include major, relatively large, and general. The warning levels include orange warning, yellow warning, and blue warning. The security disposal decision corresponding to the orange warning is to prohibit terminal access. The security disposal decision corresponding to the yellow warning is to prohibit network access within the next T time period, prohibit network access in a set area, or prohibit access to a set application. The security disposal decision corresponding to the blue warning is to prohibit network access within the next T short time period.

[0026] The advantages of the present invention are as follows:

[0027] 1) Unified security control center architecture. This security control center is responsible for collecting data from terminals, base stations, and the 5G core network, providing a unified security disposal decision for the entire network, ensuring the consistency and real - time nature of policy formulation. Compared with the prior art, after discovering a security event, the present invention can quickly and effectively formulate and implement corresponding security disposal decisions, improving the response ability and processing efficiency for security threats.

[0028] 2) Dynamic security policy generation. It can dynamically adjust security policies based on the reported data and seamlessly connect with the existing 5G core network architecture. Compared with the prior art, the present invention has the ability to formulate protection policies and security control.

[0029] 3) Establish a multi-level early warning mechanism, classify security events into different security levels according to their severity and scope of impact, namely severe, relatively large, and general, corresponding to different levels of security threats respectively. Compared with the lack of a systematic early warning mechanism in the existing 5G core network, the present invention can more accurately identify and classify security events, ensure reasonable resource allocation and timely response, and effectively improve the refinement and systematization level of network security management. BRIEF DESCRIPTION OF THE DRAWINGS

[0030] Figure 1 is the architecture diagram of the 5G core network security control function.

[0031] Figure 2 is the flowchart of the 5G core network security control function. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0032] The present invention will be further described in detail below with reference to the accompanying drawings. The examples given are only for explaining the present invention and are not intended to limit the scope of the present invention.

[0033] As Figure 1 shows the architecture diagram of the 5G core network security control function. The security control function proposed by the present invention consists of three functional modules, namely a data collection and processing module, a global security analysis module, and a unified decision-making and control module, as well as corresponding internal and external interfaces.

[0034] (1) Data collection and processing module. It collects security monitoring data from three different security monitoring data sources, namely the base station, the core network, and the terminal side. The collected data is stored in the database after data preprocessing operations for subsequent analysis and processing. The security monitoring data collected from the base station side includes monitoring alarm information and security event data. The monitoring alarm information includes, but is not limited to, random access alarm, RRC connection establishment alarm, RRC connection reconstruction alarm, etc.; the security event data includes, but is not limited to, 5G abnormal terminal access attack event, DDos attack event, etc. The security monitoring data collected from the core network side includes monitoring alarm information and security event data. The monitoring alarm information includes, but is not limited to, initial registration abnormal alarm, PDU session establishment request abnormal alarm, service request abnormal alarm, etc.; the security event data includes, but is not limited to, registration abnormal event, PDU session process abnormal event, service request abnormal event, etc. The security monitoring data collected from the terminal side includes monitoring alarm information and security event data. The monitoring alarm information includes, but is not limited to, terminal status alarm, illegal use alarm; the security event data includes, but is not limited to, terminal status abnormal event, terminal illegal use event. The data preprocessing uses the context completion method to convert the alarm information and security events of the three different security monitoring data sources into a unified format for storage. The context completion method uses the multi-dimensional feature information of the alarm information to complete the incomplete data. For example, for the timestamp field, the missing timestamp information can be supplemented according to the context information.

[0035] (2) Global security analysis module. It conducts data interaction with the data collection and processing module through the internal interface, and transmits the results after global security analysis to the unified configuration and display system through the external interface. This module conducts correlation analysis on the preprocessed alarm data and security events.

[0036] ● When the data reported by the three different security monitoring data sources of the base station, the core network, and the terminal side are security events, multiple security event correlations are performed on the security events, and global security events are analyzed and formed and sent to the unified decision control module. Among them, the multiple security event correlations include, but are not limited to, using the timestamp correlation method to convert the security events reported by different data sources into global security events. The timestamp correlation method refers to defining a time window τ. If the timestamps of security events from different sources are within the same time window τ, then the security events from different sources within the same time window τ are correlated according to the timestamp, and the associated events are formed into an event cluster, and the global security event is formed according to the description information of the event cluster.

[0037] ● When the monitoring data source does not report security events or only some security monitoring data sources report security events, the security control function collects monitoring alarm information from three data sources: the terminal, the base station, and the core network. The global security analysis module correlates the collected monitoring alarm information for multi-alarm data, and then uses the deep clustering event recognition method to transform the correlation analysis results into global security events, and then sends the global security events to the unified decision-making control module. Among them, the multi-alarm data correlation includes, but is not limited to, using methods such as timestamp correlation, device identifier correlation, and alarm level correlation to correlate the monitoring alarm information reported by different data sources to form an alarm data cluster, and then using the deep clustering event recognition method to transform the correlation results into global security events.

[0038] (3) Unified decision-making control module. The global security events generated by the global security analysis module are divided into different event levels using a multi-dimensional scoring algorithm, which are respectively divided into "major", "relatively large", and "general" event levels, and the event levels are mapped one by one to the warning levels of "orange warning", "yellow warning", and "blue warning". Based on the warning level, corresponding security disposal decisions are generated and sent to the external PCF network element. The multi-dimensional scoring algorithm generates a security score for the global security event according to indicators such as the network harm degree, influence range, occurrence frequency, and duration caused by the global security event, and divides it into "major", "relatively large", and "general" event levels according to the range of the security score. The harm degree includes whether the global security event causes network interruption and whether it causes restricted access to applications; the influence range includes the number of terminal, base station, and core network elements paralyzed by the global security event. Further, corresponding security disposal decisions are set for different warning levels. The security disposal decision corresponding to the "orange warning" is to prohibit the terminal from accessing; the security disposal decision corresponding to the "yellow warning" is to prohibit access to the network within a T time period (such as 5 minutes), prohibit access to the network in a certain area, or prohibit access to a certain application; the security disposal decision corresponding to the "blue warning" is to prohibit access to the network within a T short time period (such as 5 seconds). Starting from the generation of the security disposal decision, according to the warning level, T short and T are set to seconds or minutes.

[0039] (4) Data service interface module. As the interface for data transmission, it provides internal and external data exchange functions, including internal interfaces and external interfaces. The data acquisition and storage module conducts data interaction with the global security analysis module and the unified decision-making and control module through the internal interface; the unified decision-making and control module in the security control function interacts with the PCF network element of the 5G core network through the external interface to implement the function of issuing security disposal decisions; the global security analysis module in the security control function transmits monitoring alarm information data and security event data through the external interface for visual display by the unified configuration and display system. Among them, the internal interface uses an architecture based on a data bus for information transmission to achieve decoupling between system modules and support the expansion and upgrade of future new modules; the external interface uses an encryption communication protocol based on national cryptography (TLS) and adopts a two-way authentication mechanism to ensure the credibility of both communication parties.

[0040] As Figure 2 shown, the service process of the 5G core network device with security control function proposed by the present invention is as follows:

[0041] 1) After the system starts, the data acquisition and processing module will collect security monitoring data from three different data sources: the base station, the core network, and the terminal side to ensure the inflow of real-time and continuous data.

[0042] 2) Perform preprocessing operations on the collected data to ensure the data quality, provide an accurate and unified data format for subsequent analysis, and store the preprocessed data in the database.

[0043] 3) Extract data from the database for global security analysis, including multivariate alarm data correlation analysis and multivariate security event correlation analysis. For multivariate security event correlation analysis, methods such as but not limited to timestamp correlation are used to correlate security events reported in the same time interval τ to form an event cluster, and a global security event is formed according to the description information of the event cluster. For multivariate alarm data correlation analysis, methods such as but not limited to using timestamp correlation, device identifier correlation, and alarm level correlation are used to correlate monitoring alarm information reported by different data sources to form an alarm data cluster, and then a deep clustering event recognition method is used to transform the alarm data cluster into a global security event, and the generated global security event is stored in the database.

[0044] 4) According to the generated global security events, use a multi-dimensional scoring algorithm to divide different event levels into "major", "relatively large", and "general" event levels, and map each event level to the corresponding warning levels of "orange warning", "yellow warning", and "blue warning". Then, generate security disposal decisions according to the warning levels and store the security disposal decisions in the database.

[0045] 5) When a warning event occurs after the data reported by the data source is analyzed, the security control function issues security handling decisions through an external interface and interacts with the PCF network element. This includes other handling decisions such as security policy creation and adjustment to ensure the secure and stable operation of the 5G network.

[0046] 6) Extract the processed and analyzed security events and alarm data from the database and provide them to the unified configuration and display system through an external interface.

[0047] I. Data Acquisition and Processing Function

[0048] (1) The data sources of the 5G core network security control function are mainly divided into the following categories.

[0049] 1) Base station security monitoring data: Collect the monitoring and analysis data of the base station security monitoring system, including monitoring alarm information and security events. The monitoring alarm information includes alarm data such as random access behavior alarm, RRC connection establishment alarm, RRC connection reconstruction alarm, RRC connection recovery alarm, etc. These alarm information are composed of information such as cell ID, base station ID, timestamp, alarm level, alarm type, and alarm description. The security event information includes but is not limited to 5G abnormal terminal access attack events, etc. The security event information is composed of information such as timestamp, security event type, and security event name.

[0050] 2) Core network security monitoring data: Collect the monitoring and analysis data of the core network security monitoring system, including monitoring alarm information data and security events. The monitoring alarm information includes alarm data such as abnormal total registration alarm, initial registration abnormal alarm, mobility registration abnormal alarm, periodic registration abnormal alarm, emergency registration abnormal alarm, DDos attack alarm, PDU session establishment request abnormal alarm, service request abnormal alarm, UE configuration request abnormal alarm, authentication request abnormal alarm, device deviation from the specified area alarm, RRC Reject message abnormal alarm, etc. These alarm information are composed of information such as network element ID, timestamp, alarm level, alarm type, and alarm description. The security event information includes but is not limited to 5G network congestion events, PDU session process abnormal events, service request abnormal events, UE configuration request abnormal events, authentication request abnormal events, 5G terminal location violation events, 5G terminal configuration non - compliance events, etc. The security event information is composed of information such as timestamp, security event type, and security event name.

[0051] 3) Terminal security monitoring data: Collect security events and alarm information generated by the terminal security monitoring system. Among them, the monitoring alarm information includes alarm data such as terminal status alarms and illegal use alarms. These alarm information consists of information such as terminal ID, timestamp, alarm level, alarm type, and alarm description. The security event information includes, but is not limited to, terminal status abnormal events, terminal illegal use events, etc. The security event information is composed of information such as timestamp, security event type, and security event name.

[0052] (2) The data collection and processing module is mainly divided into three parts: data collection, data preprocessing, and data storage.

[0053] 1) Data collection collects data from the base station security monitoring system, core network security monitoring system, and terminal security monitoring system through external interfaces. Specifically, this module obtains data from the data source through external interfaces, and at the same time sets the data collection frequency to regularly obtain incremental data from external data sources.

[0054] 2) Data preprocessing mainly uses the context completion method and standardization method to convert the collected data into a standard format. Among them, the context completion method fills in the missing fields for a certain piece of monitoring alarm information or security event data with missing fields in the collection. For example, when the timestamp field of the collected data is missing, it is filled according to the reporting time of this piece of data; when the monitoring alarm type field is missing, it is supplemented according to the alarm type field of the monitoring alarm information reported by the same data source within a certain time period. The supplement rule is to judge whether the source ID and destination ID of this monitoring alarm information are the same as those of the source ID and destination ID of the missing alarm type field. If they are the same, the alarm type field information is supplemented. If they are different, the alarm type field is filled with NULL. When the source ID field is missing, this piece of monitoring alarm information or security event data is discarded. When the destination ID field is missing, it is supplemented according to the entity ID or IP that sends the alarm data. The standardization method is mainly because the data formats in the three types of data sources are not completely consistent. For example, the data from the base station security monitoring system includes the number of RRC connection request establishments, the number of successes, abnormal event descriptions, etc. The data in the terminal security monitoring system includes the number of initial registration success requests, the number of successes, etc. Therefore, the data standardization process preprocesses the reported monitoring alarm data into a unified format as follows.

[0055] D AlarmData ={timestamp,ID src ,ID dst ,alarm type ,alarm level ,alarm desc}

[0056] Among them, D AlarmDataIndicates monitoring and alarm data, timestamp indicates the timestamp, ID src Indicates the source ID, including information such as base station ID, device ID, cell ID, etc.; ID dst Indicates the destination ID, alarm type Indicates the alarm type, alarm level Indicates the alarm level, alarm desc Indicates the alarm description.

[0057] At the same time, data standardization processing preprocesses the reported security events into a unified format as follows:

[0058] D SecurityIncident ={timestamp, Incident type , Incident desc}

[0059] Where D SecurityIncident Indicates security event data, timestamp indicates the event occurrence time, Incident type Indicates the event type, Incident desc Indicates the event description.

[0060] Store the above unified format of monitoring and alarm data and security event data in the database.

[0061] 3) Data storage needs to store different data sources and preprocessed data, and also needs to meet the storage of data for subsequent data analysis, warning rules, and disposal decisions. Generally speaking, data storage mainly includes the following three types of data.

[0062] ● Preprocessed data. This type of data is stored in the database as basic data, which is convenient for subsequent data analysis and provides basic data support services for external interfaces.

[0063] · Global security event data. This type of data is generated based on the preprocessed monitoring and alarm data and security event data. It includes information such as the security event occurrence time, security event type, and security event description.

[0064] ● Security disposal decision data. This type of data is the security disposal decision generated according to the warning level. The disposal decision is composed of instructions recognizable by the PCF network element.

[0065] II. Data Service Interface Function

[0066] The data service interface is mainly composed of an internal interface and an external interface.

[0067] 1) Internal Interface: The database I / O interface is used as a bridge between different modules within the security control function network element to ensure the smooth transfer and processing of data during the preprocessing, analysis, and storage phases. The internal interface uses an architecture based on a data bus for information transfer to achieve decoupling between security control function modules.

[0068] 2) External Interface: The external interface is a channel for the security control function network element to interact with external data sources, systems, and the PCF network element. Its functions mainly include data collection and the transmission of security disposal decisions. The external interface uses an encryption communication protocol based on national cryptography (TLS) and adopts a two-way authentication mechanism to ensure the credibility of both communication parties. The specific functions are as follows:

[0069] ● Data Collection and Integration: Responsible for collecting data from different data sources and converting it into a format that the security control function network element can process.

[0070] ● Policy Download: When the external interface interacts with the PCF network element, the external interface uses the 5G network protocol interface. Responsible for converting the security disposal decisions of the security control function network element into instructions recognizable by the PCF network element and downloading them to the PCF network element.

[0071] · Configuration Management: Uses the front-end and back-end web interfaces to provide data for the unified configuration and display system, enabling it to display the current network security status, security events, and warning information.

[0072] III. Global Security Analysis Function

[0073] Global security analysis includes multivariate security event correlation analysis and multivariate alarm data correlation analysis. The two parts together form a comprehensive global security analysis processing engine. Correlation analysis is performed on the preprocessed alarm data and security events to form the final global security events.

[0074] (1) Multivariate Security Event Correlation Analysis

[0075] When the security monitoring systems on the terminal, base station, and core network sides provide security event monitoring data based on their own security event analysis capabilities, that is, when the security monitoring data of the base station, core network, and terminal collected from the data source is a security event, the timestamp correlation analysis method is used to correlate the security events from different sources according to the timestamp. For example, for some security events occurring on the base station or core network, a time window τ is defined for correlation. When the timestamps of the security events of the collected base station and core network are within a time window τ, it can be judged that the security events occurring are caused by the same reason, and thus the security events of the base station and core network are correlated to form an event cluster. After the event cluster is correlated, according to the description information of the event, the most frequently occurring relevant information in the description information is statistically analyzed to form the description Incident of the global security event.desc The time timestamp of the event occurrence is based on the earliest time in the event cluster, and the event type is Incident type According to the national standard, it is divided into four types, namely network attack events, abnormal behavior events, illegal operation events, and security hazard events. There is a one-to-one mapping relationship between the event description and the event type, and the relationship table is shown in Table 1 below. When the security event description contains words such as "attack", the event type is a network attack event; when it contains words such as "abnormal", the event type is an abnormal behavior event; when it contains words such as "illegal", the event type is an illegal operation event; when it contains words such as "non-compliant", the event type is a security hazard event.

[0076] Table 1 Mapping Table of Event Descriptions and Event Types

[0077] Event description Event type Contains words such as "attack" Network attack event Contains words such as "abnormal" Abnormal behavior event Contains words such as "violation" Violation operation event Contains words such as "non-compliant" Security risk event

[0078] (2) Multi-source Alarm Data Association Analysis

[0079] When the security monitoring systems on the terminal, base station, and core network sides do not provide security event analysis results or cannot effectively provide security event analysis results based on their own security event analysis capabilities, the security control function collects monitoring alarm information from three data sources: the terminal, base station, and core network sides. The global security analysis module first associates the monitoring alarm information for multi-source alarm data, and then uses the deep clustering event recognition method to convert the association analysis results into global security events. The multi-source alarm data association methods include, but are not limited to, device identifier association, timestamp association, and alarm level association.

[0080] · Device identifier association: For the alarm data information generated by illegal terminal access to the 5G core network. The alarm data occurring on 3 types of data sources is associated through the device identifier. When an illegal terminal attempts to access the network, the base station will detect an invalid device identifier and generate abnormal access alarm data. The core network will perform a registration check on the accessed terminal. If it is determined to be an illegal terminal, the core network will generate illegal terminal alarm information. Therefore, the alarm information of the base station and the core network can be associated according to the device identifier.

[0081] · Timestamp association: For some alarm information occurring on the base station or core network, a time window is defined for association. When the timestamps of the alarm information collected from the base station and the core network are within a time window τ, it can be determined that the alarm information occurring is caused by the same reason, and thus the alarm information of the base station and the core network is associated.

[0082] ● Alarm level association: Association is performed by collecting the alarm levels of information from terminals, base stations, and core networks. Alarm information of the same level can be associated. When the alarm level fields in the alarm information collected from base stations and core networks are the same, it can be determined that the occurred alarm information is caused by the same reason, and thus the alarm information is associated.

[0083] After associating the multi-source alarm data, an alarm data cluster is formed, and the depth clustering event recognition method is used to convert the association result into a global security event. The conversion method is to extract the alarm description keyword information with the highest occurrence frequency in the alarm description information to form a global security event description Incident desc , the time timestamp when the global security event occurs is based on the earliest time in the alarm data cluster, and the global security event type is the same as the security event type generation method in the above multi-source event association analysis method.

[0084] IV. Unified decision-making and control function

[0085] The unified decision-making and control function consists of two parts: monitoring and early warning, and security decision-making. Among them, monitoring and early warning define the early warning rules and divide the early warning levels based on the results of the analysis of global security events. Security decision-making generates security disposal decisions and sends the decisions to the PCF network element through the N5 interface.

[0086] 1 Monitoring and early warning function

[0087] The function of the monitoring and early warning module is to define the early warning rules for global security events and divide the early warning levels according to the early warning rules. The present invention divides the early warning rules and levels according to the severity and urgency of security events in accordance with the national standard GB / T 32924-2016 "Information Security Technology - Network Security Early Warning Guide". Identify and monitor the aggregated security events, and use a multi-dimensional scoring algorithm to divide the early warning rules according to the global security events. Among them, the divided "major", "relatively large", and "general" early warning rules are mapped one-to-one to the early warning levels of "orange early warning", "yellow early warning", and "blue early warning".

[0088] 1) Early warning rule definition. The early warning rule refers to dividing the levels of security events obtained by the global association analysis module. In the present invention, the security event levels are divided into three levels of "general", "relatively large", and "severe" according to the national standard and severity and urgency. For example, in a network attack event / an abnormal behavior event, if the PDU session process is abnormal, the level of this security event can be defined as "relatively large". Divide the early warning level according to the "relatively large" level.

[0089] 2) Early warning level classification. According to the level of security incidents, the early warning levels are divided into three categories: "Orange Early Warning", "Yellow Early Warning", and "Blue Early Warning", which is convenient for reasonably allocating resources and timely responding to base stations and the core network. Among them, the "Blue Early Warning" level represents an event with a relatively small impact on security; the "Yellow Early Warning" represents an event that has a certain impact on services and may damage the integrity and availability of data; the "Orange Early Warning" represents an event that seriously affects business operations or data security and requires an immediate response.

[0090] The formula for the multi-dimensional scoring algorithm is as follows:

[0091] Score = S + I + F + C

[0092] Among them, Score is the level quantification score of the security incident. S is the degree of harm caused by the security incident, with a value ranging from 0 to 10 points. The score of S involves whether the security incident causes network interruption, whether it causes restricted access to applications, and the importance of network elements. I is the scope of influence of the security incident, with a value ranging from 0 to 10 points. The score of I involves the number of network elements, the number of terminals, and the number of base stations in the core network. The more the number of affected elements, the higher the score of I. F is the frequency of occurrence of the security incident, with a value ranging from 0 to 10 points. The score of F is the number of times the security incident occurs within the statistical period. The more times it occurs, the higher the score of F. C is the duration of the security incident, with a value ranging from 0 to 10 points. The score of C is the duration of the event. The longer the duration, the higher the score of C.

[0093] From the above multi-dimensional scoring algorithm, the level quantification score Score of the security incident can be obtained. According to the score of Score, the corresponding security incident level can be obtained, and at the same time, the early warning level can be obtained by mapping according to the meaning of the event level, as shown in Table 2 below.

[0094] Table 2 Mapping Table of Security Incident Quantification Scores and Event Levels

[0095] Score range Event level Early warning level 0 ≤ score < 15 General Blue early warning 15 ≤ score < 30 Relatively large Yellow early warning 30 ≤ score ≤ 40 Serious Orange early warning

[0096] 2. Security decision-making function

[0097] The security decision-making function module generates and issues security handling decisions based on the early warning levels obtained from the monitoring and early warning function. In the 5G core network architecture, the PCF network element is the network function responsible for policy control. The security handling decisions are issued to the PCF through the N5 interface for execution. The set rules are used to convert the early warning levels into corresponding security handling decisions. The set rules are as follows.

[0098]

[0099] Among them, Decision(L, C) represents the security disposal decision, where L represents the warning level, which are "Orange Warning", "Yellow Warning", and "Blue Warning" respectively; C represents the restriction condition. T represents the time period in minutes; A represents a certain area, which is determined according to the cell TAI parameter; P represents a certain application, which is determined according to the application ID; t short represents the time period in seconds.

[0100] If the judgment is "Orange Warning", the generated and issued security disposal decision is to prohibit network access;

[0101] If the judgment is "Yellow Warning", it is further determined according to the restriction conditions whether to prohibit network access within the T time period, or prohibit network access in a certain area, or prohibit access to a certain application, and the corresponding security disposal decision is issued;

[0102] If the judgment is "Blue Warning", the generated and issued security disposal decision is to prohibit network access within the time period in seconds.

[0103] After the security decision is formulated, the 5G core network security control function network element can issue the decision recommendation. The main information included in the decision recommendation is as follows:

[0104] ● Decision identification code: uniquely identifies a security decision for tracking and auditing.

[0105] ● Execution priority: defines the execution order of the security decision, and high-priority decisions are executed before low-priority ones.

[0106] ● Execution time and duration: defines when the decision takes effect and the length of time it is maintained.

[0107] Target network element identification: the specific network element or device to which the security decision recommendation needs to be issued, such as being issued to the SMF network element through the Npcf_SMPolicyControl service; being issued to the AMF network element through the Npcf_AMPolicyControl service.

[0108] Although specific embodiments of the present invention are disclosed for illustrative purposes, which are intended to help understand the content of the present invention and implement it accordingly, those skilled in the art can understand that: without departing from the spirit and scope of the present invention and the appended claims, various substitutions, changes, and modifications are possible. Therefore, the present invention should not be limited to the content disclosed in the best embodiments, and the scope of protection claimed by the present invention is subject to the scope defined by the claims.

Claims

1. A 5G core network element device with security control function, characterized in that: It includes data collection and processing module, global safety analysis module and unified decision-making control module; The data collection and processing module is used to collect security monitoring data of base stations, core networks and terminals and convert them into a unified format and store them in a database; the security monitoring data includes monitoring alarm information and security event data; The global security analysis module is used to perform correlation analysis on the data in the database and transmit the analysis results to the unified configuration and display system; wherein the method for performing correlation analysis on the data in the database is: if the security monitoring data collected from the base station, the core network, and the terminal are all security events, then a multi-dimensional security event correlation analysis is performed on the security events to form a global security event; otherwise, the monitoring alarm information collected from the base station, the core network, and the terminal is subjected to multi-dimensional alarm data correlation to form a number of alarm data clusters, and then a deep clustering event recognition method is used to transform the correlation analysis results into a global security event; The unified decision control module is used to divide the global security events into different event levels, map different event levels to corresponding warning levels, and generate corresponding security handling decisions based on the warning levels and send them to the PCF network element of the 5G core network.

2. The 5G core network element device according to claim 1, characterized in that: The method of performing multi-source security event correlation analysis on security events to form a global security event is as follows: a time window τ is defined, and if the timestamps of security events from different sources are within the same time window τ, the security events from different sources are correlated to form an event cluster, and a global security event is formed according to the description information of the event cluster; Methods for associating multiple alarm data include but are not limited to a timestamp association method, a device identification association method, and an alarm level association method.

3. The 5G core network element device according to claim 1, characterized in that: The security handling decision includes a decision identification code, execution priority, execution time and duration.

4. The 5G core network element device according to claim 1 or 2, characterized in that: The most frequently appearing information in the event description information of the statistical event cluster is used as the description of the global security event Incident desc The earliest event occurrence time in the event cluster is used as the timestamp of the global security event, and the event type of the global security event is determined according to the event type in the event cluster. type .

5. The 5G core network element device according to claim 1 or 2, characterized in that: The deep clustering event recognition method is used to convert the alarm data cluster into a global security event. The conversion method is: extract the alarm description keyword information with the highest frequency in the alarm description information to form a global security event description Incident desc The earliest alarm occurrence time in the alarm data cluster is used as the timestamp of the global security event, and the event type Incident of the global security event is determined according to the alarm type in the alarm data cluster. type .

6. The 5G core network element device according to claim 1, 2 or 3, characterized in that: Convert the monitoring alarm data in the security monitoring data into a unified format: D AlarmData ={timestamp,ID src ,ID dst ,alarm type ,alarm level ,alarm desc }; where D AlarmData Indicates monitoring alarm data, timestamp indicates timestamp, ID src Indicates source ID, ID dst Indicates the destination ID, alarm type Indicates the alarm type, alarm level Indicates the alarm level, alarm desc Indicates alarm description; converts security event data in security monitoring data into a unified format: D SecurityIncident ={timestamp,Incident type ,Inciden d t esc ; where D Secur i tyInc id en Represents security event data. Timestamp indicates the time when the event occurred. Incident type Indicates the event type, Incident desc Indicates the event description.

7. The 5G core network element device according to claim 1, 2 or 3, characterized in that: The unified decision-making control module interacts with the PCF network element of the 5G core network through an external interface to implement the issuance of security disposal decisions; the global security analysis module transmits monitoring alarm information data and security event data through an external interface for visual display by the unified configuration and display system; the data acquisition and storage module interacts with the global security analysis module and the unified decision-making control module through an internal interface; the internal interface adopts a data bus-based architecture for information transmission, and the external interface adopts an encrypted communication protocol based on the national secret TLS for communication.

8. The 5G core network element device according to claim 1, 2 or 3, characterized in that: The monitoring alarm information collected from the base station includes but is not limited to random access alarms, RRC connection establishment alarms, and RRC connection reconstruction alarms. The security event data collected from the base station includes but is not limited to 5G abnormal terminal access attack events and DDos attack events. The monitoring alarm information collected from the core network includes but is not limited to initial registration abnormality alarms, PDU session establishment request abnormality alarms, and service request abnormality alarms. The security event data collected from the core network includes but is not limited to registration abnormality events, PDU session process abnormality events, and service request abnormality events. The monitoring alarm information collected from the terminal includes but is not limited to terminal status alarms and illegal use alarms. The security event data collected from the terminal includes but is not limited to terminal status abnormality events and terminal illegal use events.

9. The 5G core network element device according to claim 1, 2 or 3, characterized in that: A multi-dimensional scoring algorithm is used to divide the global security events into different event levels, and the method is as follows: a security score corresponding to the global security event is generated according to the degree of network harm caused by the global security event, the scope of impact, the frequency of occurrence, and the duration; the event level of the corresponding global security event is determined according to the security score; the degree of harm includes whether the global security event causes network interruption and whether it causes access to applications to be restricted; the scope of impact includes the number of terminals, base stations, and core network elements paralyzed by the global security event.

10. The 5G core network element device according to claim 9, characterized in that: The event levels include major, major, and general. The warning levels include orange warning, yellow warning, and blue warning. The security handling decision corresponding to the orange warning is to prohibit terminal access. The security handling decision corresponding to the yellow warning is to prohibit network access within the next T time period, prohibit network access in a set area, or prohibit access to set applications. The security handling decision corresponding to the blue warning is to prohibit in the next T time period. short Access the network within the time period.

Citation Information

Patent Citations

  • Network security early warning system and early warning method

    CN115766235A

  • Large-scale network security event analysis system

    CN117749409A

  • Network information security protection system

    CN118353702A

  • Method for managing proper operation of base station and system applying the method

    US20230034061A1