A 5G core network element device with security control function
By integrating data acquisition, global security analysis, and unified decision control modules into 5G core network elements, the problem of lacking global security correlation analysis and unified handling decision-making in existing technologies is solved, enabling rapid response and efficient security management of 5G communication networks.
Patent Information
- Application Number
- CN202510210983.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-25
- Publication Date
- 2025-11-25
- Estimated Expiration
- 2045-02-25
AI Technical Summary
The existing security protection measures of 5G communication networks lack the ability to conduct global security correlation analysis and the ability to make unified security handling decisions, making it difficult to effectively deal with complex network threats, especially the untimely and ineffective handling of security incidents between the core network, wireless access network and terminal equipment.
Design a 5G core network element device with security control function, including a data acquisition and processing module, a global security analysis module, and a unified decision control module. Through multi-dimensional security event correlation analysis and multi-dimensional alarm data correlation, a global security event is formed, a unified security handling decision is formulated and issued, and centralized security control management is achieved.
It improves the security management capabilities and efficiency of 5G communication networks, enabling the rapid and effective formulation and implementation of security response decisions, ensuring the consistency and real-time nature of strategy formulation, achieving accurate identification and classification of security threats, and enhancing the refinement and systematization of network security management.
Smart Images

Figure CN120151892B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of network communication technology and relates to a 5G core network element device with security control function. Background Technology
[0002] With the development of mobile communication technology, especially the widespread deployment of fifth-generation (5G) mobile communication technology, the data transmission speed and the number of connected devices have been significantly improved. The 5G communication network mainly consists of three parts: the core network, the radio access network, and user equipment. The core network is the most critical part of the 5G architecture, responsible for core functions such as mobility management, session management, and policy control.
[0003] 5G communication networks, especially the 5G core network, face increasing security challenges. Existing 5G communication network security measures can be broadly categorized into two types. The first type is IT-based protection measures, which typically deploy security equipment at different locations within the 5G communication network to achieve network security protection. Examples include deploying radio signal detection systems on the Radio Access Network (RAN) side, firewalls, intrusion detection systems, and security audit systems on the Core Network (CN) side, and terminal management systems on the Data Network (DN) side. These IT-based protection measures primarily target information systems and data within the communication network, but they cannot provide signaling protection for the core network, RAN, and terminal devices within the 5G communication network. The second type is CT-based protection measures, such as those targeting unauthorized terminal access by collecting signaling traffic for security detection to prevent unauthorized terminal access. These measures address CT-based security issues in 5G communication networks to some extent, but they only protect specific parts of the terminal, base station, or core network, resulting in limited protection scope and a lack of overall unified security analysis capabilities. Furthermore, existing security measures lack security response decision-making and control mechanisms, making it difficult to cope with increasingly complex network threats. When multiple security incidents occur in the core network and access network, it is difficult for the various nodes to work together, resulting in untimely and ineffective handling of security incidents.
[0004] Therefore, existing 5G communication network security protection focuses on conducting security tests on different components such as terminals, base stations, and the 5G core network separately. This approach reveals significant shortcomings when dealing with increasingly complex network security threats.
[0005] 1) Existing technical measures lack the ability to perform global security correlation analysis on 5G communication networks. For example, in existing security detection methods, base stations, terminals, and core network security detection nodes are relatively independent, and their scope of action is limited to their deployment locations. It is difficult to comprehensively control the security situation of the entire 5G communication network and to conduct overall and unified security analysis of the communication network.
[0006] 2) Existing technologies lack the capability for unified security response decision-making and implementation. Current security protection for 5G communication networks primarily relies on monitoring to analyze and warn of security threats, lacking the ability to formulate protection strategies and implement security controls. For example, in current protection methods, when a base station detects an abnormal terminal accessing the network, the communication network cannot effectively obtain abnormal information and formulate security protection strategies to control the abnormal terminal. Summary of the Invention
[0007] To address the problems existing in the prior art, the purpose of this invention is to provide a 5G core network element device with security control functions. This invention enables unified formulation, issuance, and implementation of security incident correlation analysis, security response decisions, and overall security handling decisions for the mobile communication network; as well as unified monitoring, real-time analysis, and rapid response to various security incidents in the mobile communication network, thereby significantly improving the security management capabilities and efficiency of the 5G communication network.
[0008] This invention acquires security monitoring data from various data sources to achieve overall security awareness and correlation analysis capabilities for the 5G communication network, including the core network, radio access network, and user equipment. Simultaneously, based on the results of the global security correlation analysis, it formulates unified security response decisions and effectively distributes them, enabling rapid response to potential security threats, thereby achieving centralized security control and management. The main contents include the following:
[0009] (1) A unified security control center architecture has been established. This security control center is responsible for collecting data from terminals, base stations, and the 5G core network, providing unified security response decisions across the entire network, and ensuring the consistency and real-time nature of policy formulation. Compared with existing technologies, this invention can quickly and effectively formulate and implement corresponding security response decisions after discovering a security incident, thereby improving the ability to respond to security threats and processing efficiency.
[0010] (2) It can dynamically adjust security policies based on reported data and seamlessly integrate with the existing 5G core network architecture. Compared with existing technologies, this invention has the ability to formulate protection policies and control security.
[0011] (3) It can establish a multi-level early warning mechanism, classifying security incidents into serious, major, and general categories according to their severity and scope of impact, each corresponding to a different level of security threat. Compared with the lack of a systematic early warning mechanism in the existing 5G core network, this invention can more accurately identify and classify security incidents, ensure reasonable resource allocation and timely response, and effectively improve the refinement and systematization of network security management.
[0012] The technical solution of this invention is as follows:
[0013] A 5G core network element device with security control function is characterized in that it includes a data acquisition and processing module, a global security analysis module, and a unified decision control module;
[0014] The data acquisition and processing module is used to collect security monitoring data from base stations, core networks, and terminals, convert it into a unified format, and store it in the database; the security monitoring data includes monitoring alarm information and security event data.
[0015] The global security analysis module is used to perform correlation analysis on the data in the database and transmit the analysis results to the unified configuration and display system. The method for performing correlation analysis on the data in the database is as follows: if the security monitoring data collected from the base station, core network, and terminal are all security events, then the security events are subjected to multi-dimensional security event correlation analysis to form a global security event; otherwise, the monitoring alarm information collected from the base station, core network, and terminal is subjected to multi-dimensional alarm data correlation to form several alarm data clusters, and then the correlation analysis results are transformed into a global security event using a deep clustering event identification method.
[0016] The unified decision control module is used to classify the global security events into different event levels, map different event levels to corresponding warning levels, and generate corresponding security handling decisions based on the warning levels and send them to the PCF network elements of the 5G core network.
[0017] Furthermore, the method for performing multi-source security event correlation analysis to form a global security event is as follows: Define a time window τ. If the timestamps of security events from different sources are within the same time window τ, then the security events from different sources are correlated to form an event cluster. A global security event is formed based on the description information of the event cluster. The method for correlation of multi-source alarm data includes, but is not limited to, timestamp correlation method, device identifier correlation method, and alarm level correlation method.
[0018] Furthermore, the security handling decision includes a decision identification code, execution priority, execution time, and duration.
[0019] Furthermore, the most frequently occurring information within the event description information of the statistical event cluster is used as the description of the global security event, Incident. desc The earliest occurrence time of an event in the event cluster is used as the timestamp of the global security event. The event type (Incident) of the global security event is determined based on the event types in the event cluster. type .
[0020] Furthermore, a deep clustering event identification method is used to transform alarm data clusters into global security events. The transformation method involves extracting the most frequently occurring alarm description keywords from the alarm description information to form a global security event description, "Incident". desc The earliest alarm occurrence time in the alarm data cluster is used as the timestamp of the global security event. The event type "Incident" is determined based on the alarm type in the alarm data cluster. type .
[0021] Furthermore, the monitoring and alarm data in the safety monitoring data will be converted into a unified format: D AlarmData ={timestamp,ID src ID dst ,alarm type ,alarm level ,alarm desc}; where D AlarmData This indicates monitoring and alarm data; timestamp represents the timestamp; ID src Indicates the source ID, ID dst Indicates the destination ID, alarm type Indicates the alarm type, alarm level Indicates the alarm level, alarm desc Indicates alarm description; converts security event data from security monitoring data into a unified format: D SecurityIncident ={timestamp,Incident type Incident desc}; where D SecurityIncident This represents security incident data; timestamp indicates the time the incident occurred; Incident type Indicates the event type, Incident desc This indicates an event description.
[0022] Furthermore, the unified decision control module interacts with the PCF network element of the 5G core network through an external interface to issue security handling decisions; the global security analysis module transmits monitoring alarm information data and security event data through an external interface for visualization by the unified configuration and display system; the data acquisition and storage module interacts with the global security analysis module and the unified decision control module through an internal interface; the internal interface adopts a data bus-based architecture for information transmission, and the external interface adopts a national cryptographic TLS-based encrypted communication protocol for communication.
[0023] Furthermore, the monitoring and alarm information collected from base stations includes, but is not limited to, random access alarms, RRC connection establishment alarms, and RRC connection reconstruction alarms; the security event data collected from base stations includes, but is not limited to, 5G abnormal terminal access attack events and DDoS attack events; the monitoring and alarm information collected from the core network includes, but is not limited to, initial registration abnormal alarms, PDU session establishment request abnormal alarms, and service request abnormal alarms; the security event data collected from the core network includes, but is not limited to, registration abnormal events, PDU session process abnormal events, and service request abnormal events; the monitoring and alarm information collected from terminals includes, but is not limited to, terminal status alarms and unauthorized use alarms; the security event data collected from terminals includes, but is not limited to, terminal status abnormal events and terminal unauthorized use events.
[0024] Furthermore, a multi-dimensional scoring algorithm is used to classify the global security events into different event levels. The method is as follows: a security score for the corresponding global security event is generated based on the degree of network harm caused by the global security event, the scope of impact, the frequency of occurrence, and the duration. The event level of the corresponding global security event is determined based on the security score. The degree of harm includes whether the global security event causes network interruption or whether it causes access to applications to be restricted. The scope of impact includes the number of terminals, base stations, and core network elements that are paralyzed by the global security event.
[0025] Furthermore, the event levels include major, significant, and minor; the warning levels include orange, yellow, and blue warnings; the security decision corresponding to an orange warning is to prohibit terminal access; the security decision corresponding to a yellow warning is to prohibit network access within a future time period T, prohibit network access in a designated area, or prohibit access to a designated application; and the security decision corresponding to a blue warning is to prohibit access within a future time period T. short Joining the network within the specified time period.
[0026] The advantages of this invention are as follows:
[0027] 1) Unified security control center architecture. This security control center is responsible for collecting data from terminals, base stations, and the 5G core network, providing unified security response decisions across the entire network, ensuring the consistency and real-time nature of policy formulation. Compared with existing technologies, this invention can quickly and effectively formulate and implement corresponding security response decisions after a security incident is detected, improving the ability to respond to security threats and processing efficiency.
[0028] 2) Dynamic security policy generation. It can dynamically adjust security policies based on reported data, seamlessly integrating with the existing 5G core network architecture. Compared to existing technologies, this invention possesses the capability for both protection policy formulation and security control.
[0029] 3) Establish a multi-level early warning mechanism, classifying security incidents into different security levels—severe, significant, and general—based on their severity and scope of impact, corresponding to different levels of security threats. Compared to the lack of a systematic early warning mechanism in existing 5G core networks, this invention can more accurately identify and classify security incidents, ensuring reasonable resource allocation and timely response, and effectively improving the refinement and systematization of network security management. Attached Figure Description
[0030] Figure 1 This is an architecture diagram of the 5G core network security control function.
[0031] Figure 2 This is a flowchart of the 5G core network security control functions. Detailed Implementation
[0032] The present invention will now be described in further detail with reference to the accompanying drawings. The examples given are only for explaining the present invention and are not intended to limit the scope of the present invention.
[0033] like Figure 1 The architecture diagram of the 5G core network security control function is shown. The security control function proposed in this invention consists of three functional modules: a data acquisition and processing module, a global security analysis module, and a unified decision control module, as well as corresponding internal and external interfaces.
[0034] (1) Data Acquisition and Processing Module. Security monitoring data is collected from three different security monitoring data sources: base stations, core network, and terminal side. The collected data undergoes preprocessing and is then stored in a database for subsequent analysis and processing. Security monitoring data collected from the base station side includes monitoring alarm information and security event data. Monitoring alarm information includes, but is not limited to, random access alarms, RRC connection establishment alarms, and RRC connection reconstruction alarms. Security event data includes, but is not limited to, 5G abnormal terminal access attack events and DDoS attack events. Security monitoring data collected from the core network side includes monitoring alarm information and security event data. Monitoring alarm information includes, but is not limited to, initial registration anomaly alarms, PDU session establishment request anomaly alarms, and service request anomaly alarms. Security event data includes, but is not limited to, registration anomaly events, PDU session flow anomaly events, and service request anomaly events. Security monitoring data collected from the terminal side includes monitoring alarm information and security event data. Monitoring alarm information includes, but is not limited to, terminal status alarms and unauthorized use alarms. Security event data includes, but is not limited to, terminal status anomaly events and terminal unauthorized use events. Data preprocessing employs a context-based completion method to convert alarm information and security events from three different security monitoring data sources into a unified format for storage. This method utilizes the multi-dimensional features of alarm information to complete incomplete data. For example, for the timestamp field, missing timestamp information can be supplemented based on contextual information.
[0035] (2) Global Security Analysis Module. This module interacts with the data acquisition and processing module through internal interfaces and transmits the results of the global security analysis to the unified configuration and display system through external interfaces. This module performs correlation analysis on pre-processed alarm data and security events.
[0036] ● When security events are reported by three different security monitoring data sources—base station, core network, and terminal side—multi-source security event correlation is performed to analyze and form a global security event, which is then sent to the unified decision control module. This multi-source security event correlation includes, but is not limited to, using timestamp correlation to transform security events reported from different data sources into a global security event. The timestamp correlation method defines a time window τ. If the timestamps of security events from different sources fall within the same time window τ, these events are correlated based on their timestamps, forming an event cluster. The global security event is then formed based on the description information of the event cluster.
[0037] ● When the monitoring data source does not report security events or only some security monitoring data sources report security events, the security control function collects monitoring alarm information from three data sources: terminal, base station, and core network. The global security analysis module performs multi-source alarm data association on the collected monitoring alarm information, and then uses a deep clustering event identification method to transform the association analysis results into global security events, which are then sent to the unified decision control module. Multi-source alarm data association includes, but is not limited to, using timestamp association, device identifier association, and alarm level association methods to associate monitoring alarm information reported from different data sources to form alarm data clusters, and then using a deep clustering event identification method to transform the association results into global security events.
[0038] (3) Unified Decision Control Module. Global security events generated by the global security analysis module are classified into different event levels using a multi-dimensional scoring algorithm: "Serious," "Significant," and "General." Each event level is then mapped to a corresponding "Orange Alert," "Yellow Alert," and "Blue Alert" warning level. Based on the warning level, corresponding security response decisions are generated and sent to external PCF network elements. The multi-dimensional scoring algorithm generates a security score for the global security event based on indicators such as the degree of network harm caused, the scope of impact, the frequency of occurrence, and the duration. The score is then categorized into "Serious," "Significant," and "General" event levels. The degree of harm includes whether the global security event causes network interruption or application access restrictions; the scope of impact includes the number of terminals, base stations, and core network elements paralyzed by the global security event. Further, corresponding security response decisions are set for different warning levels. The security response decision for an "Orange Alert" is to prohibit terminal access; the security response decision for a "Yellow Alert" is to prohibit network access within a time period T (e.g., 5 minutes), prohibit network access in a certain area, or prohibit access to a certain application; the security response decision for a "Blue Alert" is to prohibit access within a certain time period T (e.g., 5 minutes). short Access to the network within a time period (e.g., 5 seconds). From the generation of the security response decision, according to the warning level, T... short Set T to seconds or minutes.
[0039] (4) Data Service Interface Module. This module serves as the data transmission interface, providing internal and external data exchange functions, including internal and external interfaces. The data acquisition and storage module interacts with the global security analysis module and the unified decision control module through the internal interface; the unified decision control module in the security control function interacts with the PCF network element of the 5G core network through the external interface to implement the function of issuing security handling decisions; the global security analysis module in the security control function transmits monitoring alarm information data and security event data through the external interface for visualization display by the unified configuration and display system. The internal interface adopts a data bus-based architecture for information transmission, achieving decoupling between system modules and supporting expansion and upgrades for future added modules; the external interface adopts a TLS-based encrypted communication protocol and uses a two-way authentication mechanism to ensure the trustworthiness of both communicating parties.
[0040] like Figure 2 As shown, the service process of the 5G core network device with security control function proposed in this invention is as follows:
[0041] 1) After the system starts, the data acquisition and processing module will collect security monitoring data from three different data sources: base station, core network and terminal side, to ensure real-time and continuous data inflow.
[0042] 2) Perform preprocessing on the collected data to ensure data quality, provide an accurate and consistent data format for subsequent analysis, and store the preprocessed data in the database.
[0043] 3) Extract data from the database for global security analysis, including multi-source alarm data correlation analysis and multi-source security event correlation analysis. For multi-source security event correlation analysis, a timestamp-based correlation method is used, but not limited to, to associate security events reported within the same time interval τ, forming event clusters. Global security events are then generated based on the description information of the event clusters. For multi-source alarm data correlation analysis, methods such as timestamp correlation, device identifier correlation, and alarm level correlation are used, but not limited to, to associate monitoring alarm information reported from different data sources, forming alarm data clusters. Then, a deep clustering event identification method is used to transform the alarm data clusters into global security events, which are then stored in the database.
[0044] 4) Based on the generated global security events, a multi-dimensional scoring algorithm is used to classify different event levels into "critical," "significant," and "general" event levels, and each event level is mapped to a corresponding "orange alert," "yellow alert," and "blue alert" warning level. Then, a security response decision is generated based on the warning level, and the security response decision is stored in the database.
[0045] 5) When data reported by the data source triggers an early warning event after analysis, the security control function issues security handling decisions through an external interface and interacts with the PCF network element. This includes security policy creation, adjustment, and other handling decisions to ensure the safe and stable operation of the 5G network.
[0046] 6) Extract processed and analyzed security event and alarm data from the database and provide it to the unified configuration and display system through an external interface.
[0047] I. Data Acquisition and Processing Functions
[0048] (1) The data sources for 5G core network security control functions are mainly divided into the following categories.
[0049] 1) Base Station Security Monitoring Data: This involves collecting and analyzing monitoring and analysis data from the base station security monitoring system, including monitoring alarm information and security events. Monitoring alarm information includes alarms for random access behavior, RRC connection establishment, RRC connection reconstruction, and RRC connection recovery. These alarms consist of information such as cell ID, base station ID, timestamp, alarm level, alarm type, and alarm description. Security event information includes, but is not limited to, 5G abnormal terminal access attack events. Security event information consists of information such as timestamp, security event type, and security event name.
[0050] 2) Core Network Security Monitoring Data: This includes monitoring and analysis data collected from the core network security monitoring system, including monitoring alarm information and security events. Monitoring alarm information includes alarms for abnormal total registration counts, initial registration anomalies, mobility registration anomalies, periodic registration anomalies, emergency registration anomalies, DDoS attack alarms, PDU session establishment request anomalies, service request anomalies, UE configuration request anomalies, authentication request anomalies, device deviation from designated area alarms, and RRC Reject message anomalies. These alarm messages consist of network element ID, timestamp, alarm level, alarm type, and alarm description. Security event information includes, but is not limited to, 5G network congestion events, PDU session flow anomalies, service request anomalies, UE configuration request anomalies, authentication request anomalies, 5G terminal location violations, and 5G terminal configuration non-compliance events. Security event information consists of timestamp, security event type, and security event name.
[0051] 3) Terminal Security Monitoring Data: Collects security events and alarm information generated by the terminal security monitoring system. Alarm information includes terminal status alarms, unauthorized use alarms, etc. These alarms consist of terminal ID, timestamp, alarm level, alarm type, and alarm description. Security event information includes, but is not limited to, terminal status anomaly events and terminal unauthorized use events; security event information consists of timestamp, security event type, and security event name.
[0052] (2) The data acquisition and processing module is mainly divided into three parts: data acquisition, data preprocessing and data storage.
[0053] 1) Data acquisition involves collecting data from the base station security monitoring system, core network security monitoring system, and terminal security monitoring system via external interfaces. Specifically, this module obtains data from data sources through external interfaces and sets the data acquisition frequency to periodically acquire incremental data from external data sources.
[0054] 2) Data preprocessing mainly involves converting the collected data into a standard format using context completion and standardization methods. Context completion addresses missing fields in monitoring alarm information or security event data. For example, if the timestamp field is missing, it's filled in based on the data's reporting time. If the alarm type field is missing, it's filled in based on alarm type fields from the same data source within a certain time period. The filling rule is to check if the source ID and destination ID of the alarm information are the same as the source ID and destination ID of the missing alarm type field. If they are the same, the alarm type field is filled in; otherwise, it's filled with NULL. If the source ID field is missing, the monitoring alarm information or security event data is discarded. If the destination ID field is missing, it's filled in based on the entity ID or IP address that sent the alarm data. Standardization is mainly used because the data formats in the three types of data sources are not entirely consistent. For example, data from the base station security monitoring system includes the number of RRC connection request establishments, success counts, and abnormal event descriptions. Data from the terminal security monitoring system includes the number of initial registration success requests and success counts. Therefore, data standardization processing preprocesses the reported monitoring and alarm data into a unified format, as shown below.
[0055] D AlarmData ={timestamp,ID src ID dst ,alarm type ,alarm level ,alarm desc}
[0056] Where D AlarmDataThis indicates monitoring and alarm data; timestamp represents the timestamp; ID src The source ID includes information such as base station ID, device ID, and cell ID; ID dst Indicates the destination ID, alarm type Indicates the alarm type, alarm level Indicates the alarm level, alarm desc This indicates the alarm description.
[0057] Meanwhile, data standardization preprocesses reported security events into a unified format, as shown below:
[0058] D SecurityIncident ={timestamp,Incident type Incident desc}
[0059] Where D SecurityIncident This represents security incident data; timestamp indicates the time the incident occurred; Incident type Indicates the event type, Incident desc This indicates an event description.
[0060] The monitoring and alarm data and security incident data in the above unified format are stored in the database.
[0061] 3) Data storage needs to store data from different data sources and pre-processed data, while also storing data for subsequent data analysis, early warning rules, and decision-making. Overall, data storage mainly includes the following three types of data.
[0062] ●Preprocessed data. This type of data is stored as basic data in the database, facilitating subsequent data analysis and providing basic data support services for external interfaces.
[0063] ● Global security incident data. This type of data is generated based on preprocessed monitoring and alarm data and security incident data. It includes information such as the time of occurrence of the security incident, the type of security incident, and the description of the security incident.
[0064] ● Security Response Decision Data. This type of data generates security response decisions based on the alert level. The response decisions consist of instructions recognizable by the PCF network element.
[0065] II. Data Service Interface Functions
[0066] The data service interface mainly consists of internal interfaces and external interfaces.
[0067] 1) Internal Interface: A database I / O interface is used as a bridge between different modules within the security control function network element, ensuring smooth data flow and processing during the preprocessing, analysis, and storage stages. The internal interface adopts a data bus-based architecture for information transmission, achieving decoupling between security control function modules.
[0068] 2) External Interface: The external interface serves as the channel for security control function network elements to interact with external data sources, systems, and PCF network elements. Its main functions include data collection and the transmission of security response decisions. The external interface employs a TLS-based encrypted communication protocol and a two-way authentication mechanism to ensure the trustworthiness of both communicating parties. Specific functions include:
[0069] ●Data collection and integration: Responsible for collecting data from different data sources and converting it into a format that can be processed by security control function network elements.
[0070] ●Policy Deployment: When the external interface interacts with the PCF network element, the external interface uses the 5G network protocol interface. It is responsible for converting the security handling decisions of the security control function network element into instructions recognizable by the PCF network element and issuing them to the PCF network element.
[0071] ●Configuration Management: Use front-end and back-end web interfaces to provide data for the unified configuration and display system, enabling it to display the current network security status, security events, and early warning information.
[0072] III. Global Security Analysis Function
[0073] Global security analysis includes multi-dimensional security event correlation analysis and multi-dimensional alarm data correlation analysis. These two parts together form a comprehensive global security analysis processing engine. Correlation analysis is performed on pre-processed alarm data and security events to form the final global security events.
[0074] (1) Multi-factor security event correlation analysis
[0075] When the security monitoring systems on the terminal, base station, and core network sides provide security event monitoring data based on their own security event analysis capabilities—that is, when the security monitoring data collected from the data sources on the base station, core network, and terminal constitutes a security event—a timestamp association analysis method is used to associate security events from different sources according to their timestamps. For example, for certain security events occurring on the base station or core network, a time window τ is defined for association. When the timestamps of the collected base station and core network security events fall within one time window τ, it can be determined that the security events occurred due to the same cause. Therefore, the security events on the base station and core network are associated to form event clusters. After forming event clusters, based on the event description information, the most frequently occurring related information in the description information is statistically analyzed to form a global security event description, Incident.desc The event occurred using the earliest time in the event cluster, and the event type was Incident. type According to national standards, security incidents are classified into four types: network attack incidents, abnormal behavior incidents, violation of operation incidents, and security vulnerability incidents. There is a one-to-one mapping relationship between the incident description and the incident type, as shown in Table 1 below. When the security incident description contains words such as "attack," the incident type is a network attack incident; when it contains words such as "abnormal," the incident type is an abnormal behavior incident; when it contains words such as "violation," the incident type is a violation of operation incident; and when it contains words such as "non-compliant," the incident type is a security vulnerability incident.
[0076] Table 1 Mapping Table of Event Description and Event Type
[0077] Event Description Event Type Contains words such as "attack" Cyberattack Contains words such as "abnormal". Abnormal behavior events Contains words such as "violation". Violation of regulations Contains words such as "non-compliant" Safety hazard incidents
[0078] (2) Correlation analysis of multi-dimensional alarm data
[0079] When the security monitoring systems on the terminal, base station, and core network sides fail to provide security event analysis results or are unable to provide effective security event analysis results based on their own security event analysis capabilities, the security control function collects monitoring alarm information from three data sources: the terminal, base station, and core network side. The global security analysis module first performs multi-source alarm data correlation on the monitoring alarm information, and then uses a deep clustering event identification method to transform the correlation analysis results into global security events. The multi-source alarm data correlation methods include, but are not limited to, device identifier correlation, timestamp correlation, and alarm level correlation.
[0080] ● Device Identifier Association: This addresses alarm data generated by unauthorized terminals accessing the 5G core network. Alarm data from three types of data sources is associated with device identifiers. When an unauthorized terminal attempts to access the network, the base station detects an invalid device identifier and generates an abnormal access alarm. The core network performs a registration check on the accessing terminal; if it is identified as an unauthorized terminal, the core network generates an unauthorized terminal alarm. Therefore, alarm information can be associated between the base station and the core network based on the device identifier.
[0081] ●Timestamp Association: For certain alarm information occurring in the base station or core network, a time window is defined for association. When the timestamps of the collected alarm information from the base station and core network are within one time window τ, it can be determined that the alarm information is caused by the same reason, thereby associating the alarm information from the base station and core network.
[0082] ● Alarm Level Association: Alarm information collected from terminals, base stations, and the core network is associated by its level. Alarm information at the same level can be associated. When the alarm level fields in the collected alarm information from the base station and core network are the same, it can be determined that the alarms were caused by the same reason, and thus the alarm information can be associated.
[0083] After associating multi-source alarm data to form alarm data clusters, a deep clustering event identification method is used to transform the association results into global security events. The transformation method involves extracting the most frequently occurring alarm description keywords from the alarm description information to form the global security event description "Incident". desc The timestamp of the global security event is based on the earliest time in the alarm data cluster, and the global security event type is generated in the same way as the security event type in the above multi-dimensional event correlation analysis method.
[0084] IV. Unified Decision-Making and Control Function
[0085] The unified decision-making and control function consists of two parts: monitoring and early warning, and security decision-making. The monitoring and early warning function defines early warning rules and classifies early warning levels based on the results of global security event analysis. The security decision-making function generates security handling decisions and sends these decisions to PCF network elements through the N5 interface.
[0086] 1. Monitoring and early warning function
[0087] The monitoring and early warning module defines early warning rules for global security events and classifies early warning levels based on these rules. This invention, in accordance with the national standard GB / T 32924-2016 "Information Security Technology - Network Security Early Warning Guide," classifies early warning rules and levels according to the severity and urgency of security events. It identifies and monitors aggregated security events and uses a multi-dimensional scoring algorithm to classify early warning rules based on global security events. The "major," "relatively serious," and "general" early warning rules are mapped one-to-one with the "orange warning," "yellow warning," and "blue warning" levels, respectively.
[0088] 1) Early Warning Rule Definition. Early warning rules refer to the classification of security events obtained by the global correlation analysis module. In this invention, security event levels are divided into three levels: "General," "Significant," and "Severe," based on national standards and their severity and urgency. For example, an abnormal PDU session flow in a network attack / abnormal behavior event can be defined as a "Significant" security event. Early warning levels are then classified according to the "Significant" level.
[0089] 2) Warning Level Classification. Warning levels are divided into three categories: "Orange Warning," "Yellow Warning," and "Blue Warning," based on the severity of security incidents. This facilitates the rational allocation of resources and timely response for base stations and the core network. Specifically, a "Blue Warning" represents events with minor security impact; a "Yellow Warning" represents events with some impact on business operations, potentially compromising data integrity and availability; and an "Orange Warning" represents events that severely affect business operations or data security, requiring immediate response.
[0090] The formula for the multi-dimensional scoring algorithm is as follows:
[0091] Score = S + I + F + C
[0092] The score represents the severity of a security incident, ranging from 0 to 10. S indicates the degree of harm caused by the incident, and its value depends on factors such as whether the incident caused network outages, application access restrictions, and the importance of network elements. I indicates the scope of the incident's impact, also ranging from 0 to 10. I's score is influenced by the number of network elements, terminals, and base stations in the core network; a higher impact on a larger number of entities results in a higher I score. F indicates the frequency of the incident, also ranging from 0 to 10. F represents the number of times the incident occurred within the statistical period; a higher frequency results in a higher F score. C indicates the duration of the incident, also ranging from 0 to 10. C's score reflects the duration of the incident; a longer duration results in a higher C score.
[0093] The multi-dimensional scoring algorithm described above can be used to obtain a quantitative score for the level of a security event. Based on the score, the corresponding security event level can be determined. At the same time, the warning level can be obtained by mapping the meaning of the event level, as shown in Table 2 below.
[0094] Table 2 Mapping Table of Security Incident Quantitative Scores and Incident Levels
[0095] Score range Event Level Warning level 0≤score<15 generally Blue Alert 15≤score<30 Larger Yellow Alert 30≤score≤40 serious Orange alert
[0096] 2. Security decision-making function
[0097] The security decision-making module generates and issues security response decisions based on the warning levels derived from the monitoring and early warning functions. In the 5G core network architecture, the PCF network element is the network function responsible for policy control, and security response decisions are issued to the PCF for execution via the N5 interface. The warning levels are translated into corresponding security response decisions using predefined rules. These rules are shown below.
[0098]
[0099] Where Decision(L,C) represents the safety response decision, L represents the warning level ("Orange Warning", "Yellow Warning", "Blue Warning"), and C represents the limiting conditions. T represents a minute-level time period; A represents a certain area, determined based on the cell's TAI parameter; P represents a certain application, determined based on the application ID; t short This indicates a time period in seconds.
[0100] If the alert level is determined to be "orange", the resulting security action decision is to prohibit network access.
[0101] If it is judged as a "yellow alert", then further determine whether to prohibit network access during the T time period, or prohibit network access in a certain area, or prohibit access to a certain application based on the restriction conditions, and issue corresponding security handling decisions.
[0102] If the alert is classified as "blue", the resulting security decision will prohibit access to the network within a timeframe of seconds.
[0103] After a security decision is made, the 5G core network security control function network element can issue decision recommendations. The main information included in the decision recommendations is as follows:
[0104] ● Decision Identifier: Uniquely identifies a security decision for tracking and auditing.
[0105] ● Execution Priority: Defines the order in which security decisions are executed; higher priority decisions will be executed before lower priority decisions.
[0106] ● Execution time and duration: Define when the decision takes effect and how long it lasts.
[0107] Target network element identification: The specific network element or device to which security decision recommendations need to be distributed, such as distributing them to SMF network elements through the Npcf_SMPolicyControl service; or distributing them to AMF network elements through the Npcf_AMPolicyControl service.
[0108] Although specific embodiments of the invention have been disclosed for illustrative purposes to aid in understanding and implementing the invention, those skilled in the art will understand that various substitutions, variations, and modifications are possible without departing from the spirit and scope of the invention and the appended claims. Therefore, the invention should not be limited to the content disclosed in the preferred embodiments, and the scope of protection claimed by the invention is defined by the claims.
Claims
1. A 5G core network element device with security control function, characterized in that, It includes a data acquisition and processing module, a global security analysis module, and a unified decision control module; The data acquisition and processing module is used to collect security monitoring data from base stations, core networks, and terminals, convert it into a unified format, and store it in the database; the security monitoring data includes monitoring alarm information and security event data. The global security analysis module is used to perform correlation analysis on the data in the database and transmit the analysis results to the unified configuration and display system. The method for performing correlation analysis on the data in the database is as follows: if the security monitoring data collected from the base station, core network, and terminal are all security events, then the security events are subjected to multi-dimensional security event correlation analysis to form a global security event; otherwise, the monitoring alarm information collected from the base station, core network, and terminal is subjected to multi-dimensional alarm data correlation to form several alarm data clusters, and then the correlation analysis results are transformed into a global security event using a deep clustering event identification method. The method for forming a global security event through multi-source security event correlation analysis is as follows: Define a time window τ. If the timestamps of security events from different sources are within the same time window τ, then the security events from different sources are correlated to form an event cluster. A global security event is formed based on the description information of the event cluster. The methods for correlation of multi-source alarm data include timestamp correlation method, device identifier correlation method, and alarm level correlation method. Among these methods, a deep clustering event identification approach is used to transform alarm data clusters into global security events. The transformation method involves extracting the most frequently occurring alarm description keywords from the alarm description information to form a global security event description, "Incident." desc The earliest alarm occurrence time in the alarm data cluster is used as the timestamp of the global security event. The event type "Incident" is determined based on the alarm type in the alarm data cluster. type ; The unified decision control module is used to classify the global security events into different event levels, map different event levels to corresponding warning levels, and generate corresponding security handling decisions based on the warning levels and send them to the PCF network elements of the 5G core network.
2. The 5G core network element device according to claim 1, characterized in that, The security response decision includes a decision identification code, execution priority, execution time, and duration.
3. The 5G core network element device according to claim 1, characterized in that, The most frequently occurring information in the event description information within a statistical event cluster is used as the description of the global security event. desc The earliest occurrence time of an event in the event cluster is used as the timestamp of the global security event. The event type (Incident) of the global security event is determined based on the event types in the event cluster. type .
4. The 5G core network element device according to claim 1 or 2, characterized in that, Convert the monitoring and alarm data in the safety monitoring data into a unified format: D AlarmData ={timestamp,ID src ID dst ,alarm type ,alarm level ,alarm desc }; where D AlarmData This indicates monitoring and alarm data; timestamp represents the timestamp; ID src Indicates the source ID, ID dst Indicates the destination ID, alarm type Indicates the alarm type, alarm level Indicates the alarm level, alarm desc Indicates alarm description; converts security event data from security monitoring data into a unified format: D SecurityIncident ={timestamp,Incident type Incident desc }; where D SecurityIncident Represents security incident data. The timestamp indicates the time when the event occurred. type Indicates the event type, Incident desc This indicates an event description.
5. The 5G core network element device according to claim 1 or 2, characterized in that, The unified decision control module interacts with the PCF network element of the 5G core network through an external interface to issue security handling decisions; the global security analysis module transmits monitoring alarm information data and security event data through an external interface for visualization by the unified configuration and display system; the data acquisition and storage module interacts with the global security analysis module and the unified decision control module through an internal interface; the internal interface adopts a data bus-based architecture for information transmission, and the external interface adopts a national cryptographic TLS-based encrypted communication protocol for communication.
6. The 5G core network element device according to claim 1 or 2, characterized in that, Monitoring and alarm information collected from base stations includes random access alarms, RRC connection establishment alarms, and RRC connection reconstruction alarms. Security event data collected from base stations includes 5G abnormal terminal access attack events and DDoS attack events. Monitoring and alarm information collected from the core network includes initial registration abnormal alarms, PDU session establishment request abnormal alarms, and service request abnormal alarms. Security event data collected from the core network includes registration abnormal events, PDU session process abnormal events, and service request abnormal events. The monitoring and alarm information collected from the terminal includes terminal status alarms and unauthorized use alarms. The security event data collected from the terminal includes terminal status abnormality events and terminal unauthorized use events.
7. The 5G core network element device according to claim 1 or 2, characterized in that, The global security events are classified into different event levels using a multi-dimensional scoring algorithm. The method is as follows: a security score is generated for the global security event based on the degree of network harm caused, the scope of impact, the frequency of occurrence, and the duration. The event level of the corresponding global security event is determined based on the security score. The degree of harm includes whether the global security event causes network interruption or whether it causes application access restrictions. The scope of impact includes the number of terminals, base stations, and core network elements that are paralyzed by the global security event.
8. The 5G core network element device according to claim 7, characterized in that, The event severity levels include major, significant, and minor; the warning levels include orange, yellow, and blue; the security decision corresponding to an orange warning is to prohibit terminal access; the security decision corresponding to a yellow warning is to prohibit network access within the next T time period, prohibit network access in a designated area, or prohibit access to a designated application; and the security decision corresponding to a blue warning is to prohibit access within the next T time period. short Joining the network within the specified time period.
Citation Information
Patent Citations
Network security early warning system and early warning method
CN115766235A
Network information security protection system
CN118353702A