Remote peeping and listening device detection method and system combined with tscm

By employing multi-band scanning with an RF scanner, adaptive interference compensation, and spectrum analysis, combined with infrared detection and network traffic logs, the accuracy and reliability issues of remote eavesdropping device detection have been resolved, enabling more efficient identification of suspicious devices.

CN120223561BActive Publication Date: 2026-01-27JIANGSU KEMANDE INFORMATION SECURITY TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510486963.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-18
Publication Date
2026-01-27
Estimated Expiration
2045-04-18

AI Technical Summary

Technical Problem

The accuracy and reliability of existing remote eavesdropping device detection technologies are low. Single signal detection methods are prone to missed detections or false detections, and it is difficult to accurately distinguish between normal signals and suspicious signals in complex environments.

Method used

Multi-band scanning is performed using an RF scanner, combined with adaptive interference compensation and analysis by multiple spectrum analyzers to construct a reliable signal feature space. Risk assessment is conducted through infrared detection and network traffic logs to generate a detection report.

Benefits of technology

It improves the accuracy and reliability of remote eavesdropping device detection, reduces false detections and missed detections, and can accurately identify suspicious devices in complex environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120223561B_ABST
    Figure CN120223561B_ABST
Patent Text Reader

Abstract

The application discloses a remote peeping and eavesdropping equipment detection method and system combined with TSCM, relates to the related field of eavesdropping equipment detection, and comprises the following steps: a target area is scanned by a RF scanner in multiple frequency bands to obtain a first set of captured signals; adaptive interference compensation is performed according to multi-band scanning scene feature data to obtain a second set of captured signals; spectrum analysis is performed by multiple spectrum analyzers to construct frequency band captured signal feature curves; the target area is subjected to credible signal feature mining to construct a credible signal feature space, the frequency band captured signal feature curves are input, and a first result is determined; infrared detection compensation is performed according to the first result to obtain a second result; and risk evaluation is performed on the second result according to real-time network traffic logs of the target area to obtain a suspicious equipment detection report. The application solves the technical problems of low accuracy and poor reliability of existing eavesdropping equipment detection, and achieves the technical effects of improving detection accuracy and reliability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of eavesdropping device detection, and in particular to a method and system for detecting remote eavesdropping devices combined with TSCM. Background Technology

[0002] TSCM (Technical Surveillance Countermeasures) is a crucial means of ensuring information security and preventing illegal surveillance. In many sectors, including government and commerce, the security of sensitive information is paramount. The illegal theft of information by remote eavesdropping devices can lead to serious consequences such as leaks of confidential information and financial losses. Therefore, accurate and efficient detection of remote eavesdropping devices is of great significance. Currently, the main approach to detecting remote eavesdropping devices is the traditional single-signal detection method, such as relying solely on RF (radio frequency) scanners for simple frequency band scanning or simply using a spectrum analyzer to analyze the signal. Single-signal detection methods have many limitations. When using only an RF scanner for multi-band scanning, the complex and varied detection environment and various interference factors can lead to inaccurate signal capture, resulting in missed or false detections. On the other hand, simply using a spectrum analyzer lacks effective identification of reliable signals, making it difficult to accurately distinguish between normal and suspicious signals. Furthermore, it cannot comprehensively evaluate the detection results in conjunction with the actual network environment, resulting in low accuracy and reliability of the detection results.

[0003] Currently, remote eavesdropping device detection suffers from low accuracy and poor reliability. Summary of the Invention

[0004] This application provides a method and system for detecting remote eavesdropping devices by combining TSCM (Transmission Transmission Detection and Monitoring). The method employs several techniques: first, using an RF scanner to scan a target area across multiple frequency bands to obtain a first set of captured signals; then, using scene feature data for adaptive interference compensation to obtain a second set of captured signals; next, using multiple spectrum analyzers to analyze and construct signal characteristic curves for each frequency band; then, mining reliable signal features in the target area to construct a spatial model and inputting the characteristic curves to determine the first result of suspicious device detection; subsequently, using this result for infrared detection compensation to obtain a second result; and finally, using real-time network traffic logs to assess the risk of the second result and obtain a detection report. These techniques effectively improve the accuracy and reliability of remote eavesdropping device detection.

[0005] This application provides a method for detecting remote eavesdropping devices combined with TSCM, comprising: scanning a target area using an RF scanner to obtain a first set of captured signals, the first set of captured signals including multi-band captured signals; performing adaptive interference compensation on the first set of captured signals based on multi-band scanning scene feature data to obtain a second set of captured signals; performing spectrum analysis on the second set of captured signals using multiple spectrum analyzers to construct characteristic curves for each frequency band captured signal; performing trusted signal feature mining on the target area to construct a trusted signal feature space, and inputting the characteristic curves for each frequency band captured signal into the trusted signal feature space to determine a first result of suspicious device detection; performing infrared detection compensation based on the first result of suspicious device detection to obtain a second result of suspicious device detection; and performing a risk assessment on the second result of suspicious device detection based on real-time network traffic logs of the target area to obtain a suspicious device detection report.

[0006] In a possible implementation, adaptive interference compensation is performed on the first captured signal set based on multi-band scanning scene feature data to obtain a second captured signal set. The following processing is then performed: Based on the first captured signal set and the multi-band scanning scene feature data, a first frequency band captured signal and the corresponding first frequency band scanning scene feature data are extracted; RF scanner status parameters corresponding to the first frequency band captured signal are collected to obtain first scanning device status information; interference coupling analysis is performed on the first frequency band captured signal based on the first frequency band scanning scene feature data and the first scanning device status information to determine a first interference compensation factor; interference compensation is performed on the first frequency band captured signal based on the first interference compensation factor to obtain a first optimized captured signal, and the first optimized captured signal is added to the second captured signal set.

[0007] In a possible implementation, interference coupling analysis is performed on the first frequency band captured signal based on the first frequency band scanning scene feature data and the first scanning device status information to determine a first interference compensation factor. The following processing is then performed: anomaly detection is performed on the first frequency band scanning scene feature data to obtain a first scanning scene anomaly detection result; interference identification is performed on the first frequency band captured signal based on the first scanning scene anomaly detection result to obtain a first interference identification result; anomaly detection is performed on the first scanning device status information to obtain a first scanning device anomaly detection result; interference identification is performed on the first frequency band captured signal based on the first scanning device anomaly detection result to obtain a second interference identification result; and a fusion analysis is performed on the first interference identification result and the second interference identification result to generate the first interference compensation factor.

[0008] In a possible implementation, the second captured signal set is subjected to spectral analysis by multiple spectrum analyzers to construct characteristic curves for each frequency band captured signal, and the following processing is performed: the first optimized captured signal is subjected to spectral analysis by the multiple spectrum analyzers to obtain multiple sets of signal spectral analysis results; reliable filtering is performed based on the multiple sets of signal spectral analysis results to establish a first spectral analysis reliable space; data fusion is performed based on the first spectral analysis reliable space to obtain a first spectral analysis reliable result; characteristic curves for the first frequency band captured signal are constructed based on the first spectral analysis reliable result, and the first frequency band captured signal characteristic curves are added to the characteristic curves of each frequency band captured signal.

[0009] In a possible implementation, based on the multiple sets of signal spectrum analysis results, a reliable filtering is performed to establish a first reliable spectrum analysis space, and the following processing is executed: when the multiple spectrum analyzers perform spectrum analysis on the first optimized capture signal, the status parameters of the multiple spectrum analyzers are collected in real time to obtain multiple analyzer monitoring sequences; anomaly detection is performed based on the multiple analyzer monitoring sequences to determine multiple analyzer status anomaly coefficients; it is determined whether the multiple analyzer status anomaly coefficients are less than a predetermined status anomaly coefficient to obtain multiple analyzer status judgment results; the multiple sets of signal spectrum analysis results are filtered and cleaned based on the multiple analyzer status judgment results to generate the first reliable spectrum analysis space.

[0010] In a possible implementation, a trusted signal feature mining is performed on the target area to construct a trusted signal feature space, and the following processes are performed: signal feature sample retrieval is performed on each trusted device in the target area to obtain multiple device signal feature sample sets; a first device signal feature sample set is extracted based on the multiple device signal feature sample sets; confidence is evaluated for each signal feature sample in the first device signal feature sample set to obtain a confidence coefficient for each feature sample; the first device signal feature sample set is optimized and filtered based on the confidence coefficients of each feature sample to generate a first confidence signal feature sample set that satisfies a predetermined confidence coefficient; a first trusted signal feature curve is constructed based on the first confidence signal feature sample set, and the first trusted signal feature curve is added to the trusted signal feature space.

[0011] In a possible implementation, the characteristic curves of the captured signals in each frequency band are input into the trusted signal feature space to determine the first result of suspicious device detection. The following processing is then performed: based on each trusted signal characteristic curve in the trusted signal feature space, a twin comparison is performed on the characteristic curve of the captured signal in the first frequency band to obtain a first captured signal feature twin evaluation matrix; the first captured signal feature twin evaluation matrix is ​​filtered for maximum value to determine the first captured signal confidence coefficient; it is determined whether the first captured signal confidence coefficient is less than the captured signal confidence threshold; if the first captured signal confidence coefficient is less than the captured signal confidence threshold, device tracing is performed on the characteristic curve of the captured signal in the first frequency band to determine the first suspicious device, and the first suspicious device is added to the first result of suspicious device detection.

[0012] In a possible implementation, infrared detection compensation is performed based on the first result of the suspected device detection to obtain a second result of the suspected device detection, and the following processing is performed: the target area is scanned by an infrared thermal imager to obtain a regional infrared thermal image; the regional infrared thermal image is used to identify suspected devices based on a reliable device reference thermal image of the target area to obtain an infrared suspected device detection result; the first result of the suspected device detection is compensated based on the infrared suspected device detection result to generate the second result of the suspected device detection.

[0013] In a possible implementation, a risk assessment is performed on the second result of the suspicious device detection based on the real-time network traffic logs of the target area to obtain a suspicious device detection report. The following processing is then performed: the real-time network traffic logs are correlated and captured based on the second result of the suspicious device detection to obtain the associated logs of each suspicious device; the associated logs of each suspicious device are input into a risk assessment model to obtain the risk coefficient of each suspicious device; the second result of the suspicious device detection, the associated logs of each suspicious device, and the risk coefficients of each suspicious device are combined to generate the suspicious device detection report.

[0014] This application also provides a remote eavesdropping device detection system combined with TSCM, comprising: a multi-band scanning module for scanning a target area using an RF scanner to obtain a first capture signal set, the first capture signal set including multi-band capture signals; an adaptive interference compensation module for adaptively compensating the first capture signal set for interference based on multi-band scanning scene feature data to obtain a second capture signal set; a spectrum analysis module for performing spectrum analysis on the second capture signal set using multiple spectrum analyzers to construct characteristic curves for each frequency band capture signal; a suspicious device detection module for mining credible signal features in the target area to construct a credible signal feature space, and inputting the characteristic curves for each frequency band capture signal into the credible signal feature space to determine a first result of suspicious device detection; an infrared detection compensation module for performing infrared detection compensation based on the first result of suspicious device detection to obtain a second result of suspicious device detection; and a risk assessment module for performing a risk assessment on the second result of suspicious device detection based on real-time network traffic logs of the target area to obtain a suspicious device detection report.

[0015] The proposed method and system for detecting remote eavesdropping devices, combining TSCM (Transmission Transmission Detection and Compensation), firstly involves multi-band scanning of a target area using an RF scanner to obtain a first set of captured signals, which includes multi-band captured signals. Next, adaptive interference compensation is applied to the first set of captured signals based on the multi-band scanning scene feature data to obtain a second set of captured signals. Then, spectrum analysis is performed on the second set of captured signals using multiple spectrum analyzers to construct characteristic curves for each frequency band. Next, reliable signal feature mining is performed on the target area to construct a reliable signal feature space. The characteristic curves for each frequency band are input into the reliable signal feature space to determine a first result of suspicious device detection. Subsequently, infrared detection compensation is applied based on the first result to obtain a second result of suspicious device detection. Finally, a risk assessment is performed on the second result of suspicious device detection based on real-time network traffic logs of the target area to obtain a suspicious device detection report. This achieves the technical effect of improving the accuracy and reliability of remote eavesdropping device detection. Attached Figure Description

[0016] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings of the embodiments of the present invention will be briefly described below. Flowcharts are used in this application to illustrate the operations performed by the system according to the embodiments of the present application. It should be understood that the preceding or following operations are not necessarily performed precisely in sequence. Instead, various steps can be processed in reverse order or simultaneously as needed. Furthermore, other operations can be added to these processes, or one or more steps can be removed from these processes.

[0017] Figure 1This is a flowchart illustrating the remote eavesdropping device detection method combined with TSCM provided in an embodiment of this application.

[0018] Figure 2 This is a schematic diagram of the structure of a remote eavesdropping device detection system combined with TSCM provided in an embodiment of this application.

[0019] Explanation of reference numerals in the attached diagram: Multi-band scanning module 10, Adaptive interference compensation module 20, Spectrum analysis module 30, Suspicious device detection module 40, Infrared detection compensation module 50, Risk assessment module 60. Detailed Implementation

[0020] The above description is merely an overview of the technical solution of this application. In order to better understand the technical means of this application and to implement it in accordance with the contents of the specification, and to make the above and other objects, features and advantages of this application more obvious and understandable, specific embodiments of this application are given below.

[0021] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description of this application will be provided in conjunction with the accompanying drawings. The described embodiments should not be considered as limitations on this application. All other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0022] In the following description, references to "some embodiments" describe a subset of all possible embodiments. However, it is understood that "some embodiments" can be the same or different subsets of all possible embodiments and can be combined with each other without conflict. The terms "first" and "second" are used merely to distinguish similar objects and do not represent a specific ordering of objects. The terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or server that includes a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or modules not explicitly listed or inherent to these processes, methods, products, or devices. Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terminology used herein is for the purpose of describing embodiments of this application only.

[0023] This application provides a method for detecting remote eavesdropping devices combined with TSCM, such as Figure 1 As shown, the method includes:

[0024] Step S100: The target area is scanned by an RF scanner using multiple frequency bands to obtain a first set of capture signals, which includes multiple frequency band capture signals.

[0025] Specifically, an RF scanner, or radio frequency scanner, is a device used to detect and analyze radio signals. It scans a target area by transmitting and receiving radio frequency signals to obtain characteristic information such as the signal's frequency, intensity, and phase. This device can cover a wide frequency range, from low frequencies (e.g., tens of kHz) to high frequencies (e.g., GHz levels). The RF scanner scans the target area by transmitting and receiving radio frequency signals. During the scan, the scanner gradually changes the transmission frequency according to a preset frequency step value, while simultaneously recording the signal strength and characteristics at each frequency point. The RF scanner is equipped with a highly sensitive antenna for receiving radio signals within the target area. The internal signal processing unit performs a Fast Fourier Transform (FFT) on the received signal, converting the time-domain signal into a frequency-domain signal, thereby obtaining the signal strength and phase information at different frequency points. This signal data is stored as a first captured signal set for subsequent processing.

[0026] For example, an RF scanner can be set to scan within a frequency band from 100MHz to 3GHz, with frequency steps of 1MHz. The scanner stays at each frequency point for a certain period of time (e.g., 10ms), recording the signal strength and phase information at that frequency point. Ultimately, the first captured signal set contains one signal strength and phase data point every 1MHz within the 100MHz to 3GHz range.

[0027] Step S200: Perform adaptive interference compensation on the first captured signal set based on the multi-band scanning scene feature data to obtain the second captured signal set.

[0028] Specifically, adaptive interference compensation is a signal processing technique used to eliminate or reduce the impact of background interference signals on target signals. This technique is based on adaptive filters, which adjust the filter parameters in real time to adapt to different interference environments. First, the system collects feature data of a multi-band scanning scene, including background noise levels, frequency distribution, and intensity of interference signals. Then, using this feature data, the filter weights are adjusted through adaptive algorithms (such as Least Mean Square Error (LMS) or Recursive Least Squares (RLS)) to minimize the impact of interference signals. In practice, each signal component in the first captured signal set can be processed by an adaptive filter to obtain compensated signal components, ultimately forming the second captured signal set.

[0029] For example, suppose a strong interference signal with a frequency of 1.5 GHz and an intensity of -30 dBm is detected in the background during scanning. Using an adaptive interference compensation algorithm, the system adjusts the filter parameters to appropriately attenuate the signal component near 1.5 GHz, thereby reducing the impact of the interference signal. After compensation, the signal strength near 1.5 GHz in the second captured signal set will be closer to the actual target signal strength.

[0030] In one possible implementation, adaptive interference compensation is performed on the first captured signal set based on multi-band scanning scene feature data to obtain a second captured signal set. Step S200 further includes step S210, which involves extracting a first-band captured signal and the corresponding first-band scanning scene feature data based on the first captured signal set and the multi-band scanning scene feature data. Specifically, signals in a specific frequency band (e.g., 1.4GHz to 1.6GHz) are selected from the first captured signal set, and scanning scene feature data corresponding to that frequency band is extracted, including background noise level, interference signal distribution, etc. For example, if the first captured signal set covers a frequency band from 100MHz to 3GHz, signals and their feature data within the 1.4GHz to 1.6GHz frequency band are extracted using a signal processing algorithm.

[0031] Step S220: Collect the RF scanner status parameters corresponding to the first frequency band capture signal to obtain the first scanning device status information. Specifically, record the operating status parameters of the RF scanner when scanning the first frequency band, such as antenna gain, scanning step, and scanning speed. For example, when the RF scanner scans the 1.4GHz to 1.6GHz frequency band, the antenna gain is 20dB, the scanning step is 100kHz, and the scanning speed is 100MHz per second.

[0032] Step S230: Perform interference coupling analysis on the first frequency band captured signal based on the first frequency band scanning scene feature data and the first scanning device status information to determine a first interference compensation factor. Specifically, an adaptive filter algorithm (such as the LMS algorithm) is used, combined with the scanning scene feature data and device status information, to calculate the interference compensation factor. This factor is used to adjust the filter weights to minimize the impact of interference signals. For example, using the LMS algorithm, based on the background noise level and the antenna gain of the RF scanner, the first interference compensation factor is calculated to be 0.0002.

[0033] Step S240: Interference compensation is applied to the first frequency band capture signal according to the first interference compensation factor to obtain a first optimized capture signal, and this optimized capture signal is added to the second capture signal set. Specifically, the first frequency band capture signal is processed through an adaptive filter, and the signal is adjusted using the first interference compensation factor to remove interference components, resulting in an optimized signal. For example, after adaptive filter processing, signal interference in the 1.4GHz to 1.6GHz frequency band is effectively reduced, signal quality is significantly improved, and the optimized signal is added to the second capture signal set. Through adaptive interference compensation, the impact of background noise and interference signals on the target signal is effectively reduced, making the detection of suspicious devices more accurate.

[0034] In one possible implementation, interference coupling analysis is performed on the first frequency band captured signal based on the first frequency band scanning scene feature data and the first scanning device status information to determine a first interference compensation factor. Step S230 further includes step S231, which involves performing anomaly detection on the first frequency band scanning scene feature data to obtain a first scanning scene anomaly detection result, and then performing interference identification on the first frequency band captured signal based on the first scanning scene anomaly detection result to obtain a first interference identification result. Specifically, statistical analysis or machine learning methods, such as cluster analysis and support vector machines, are used to analyze the first frequency band scanning scene feature data to detect whether there are any abnormal features. Based on the anomaly detection result, the characteristics of the interference signal, such as frequency, intensity, and phase, are identified. For example, assuming that the background noise level suddenly increases in the first frequency band scanning scene feature data, this anomaly is detected by the anomaly detection algorithm, and the frequency of the interference signal is identified as 1.5 GHz, and the intensity is -20 dBm.

[0035] Step S232 involves performing anomaly detection on the status information of the first scanning device to obtain anomaly detection results. Based on these results, interference identification is performed on the captured signal in the first frequency band to obtain a second interference identification result. Specifically, the status parameters of the RF scanner (such as antenna gain, scanning step size, and scanning speed) are monitored in real time to detect any anomalies. Based on the anomaly detection results, interference signals caused by device status anomalies are identified. For example, assuming the antenna gain of the RF scanner suddenly drops, this anomaly is detected by the anomaly detection algorithm, and the characteristics of the resulting interference signals are then identified.

[0036] Step S233: A fusion analysis is performed on the first interference identification result and the second interference identification result to generate the first interference compensation factor. Specifically, the two interference identification results are fused to comprehensively consider the impact of the scanning scene and device status on the interference. An adaptive filter algorithm (such as the LMS algorithm) is used to calculate the first interference compensation factor based on the fused interference characteristics. For example, assuming the first interference identification result is a frequency of 1.5 GHz and an intensity of -20 dBm, and the second interference identification result is interference caused by a decrease in antenna gain, the first interference compensation factor generated after fusion analysis is 0.0002. By performing anomaly detection and interference identification on the scanning scene feature data and the scanning device status information respectively, the source and characteristics of the interference signal can be more comprehensively identified, thereby improving the reliability of the detection system.

[0037] Step S300: Perform spectrum analysis on the second captured signal set using multiple spectrum analyzers to construct characteristic curves for each frequency band captured signal.

[0038] Specifically, a spectrum analyzer is used to measure the spectral characteristics of a signal, decomposing it into different frequency components and displaying their amplitude and phase information. Multiple spectrum analyzers are used to analyze a second set of captured signals, each focusing on a different frequency band to improve analysis accuracy and efficiency. The spectrum analyzer scans the spectrum of the input signal, recording the signal amplitude and phase information at each frequency point. These data points are then connected to form characteristic curves for each frequency band of the captured signal. For example, three spectrum analyzers are used to analyze signals in the 0-1 GHz, 1-2 GHz, and 2-3 GHz frequency bands, respectively. Each spectrum analyzer records the signal amplitude at each frequency point in 100 kHz increments during the scan. Ultimately, three characteristic curves are obtained, representing the amplitude distribution of the signal within the 0-1 GHz, 1-2 GHz, and 2-3 GHz frequency bands, respectively.

[0039] In one possible implementation, the second captured signal set is analyzed using multiple spectrum analyzers to construct characteristic curves for each frequency band. Step S300 further includes step S310, where the first optimized captured signal is analyzed using the multiple spectrum analyzers to obtain multiple sets of signal spectrum analysis results. Specifically, the second captured signal set contains multiple optimized frequency band signals. For each frequency band signal, multiple spectrum analyzers are used simultaneously for spectrum analysis to improve the accuracy and reliability of the analysis. Each spectrum analyzer performs spectrum analysis on the first optimized captured signal, converting the time-domain signal into a frequency-domain signal using algorithms such as FFT, and recording the signal amplitude and phase information at each frequency point. Due to hardware differences or measurement errors among different spectrum analyzers, multiple sets of different spectrum analysis results will be obtained. For example, suppose three spectrum analyzers simultaneously analyze signals in the 1.4GHz to 1.6GHz frequency band. Each spectrum analyzer records the signal amplitude and phase information at each frequency point in 100kHz increments during the scanning process. Finally, three different sets of spectrum analysis results are obtained.

[0040] Step S320: Perform reliable filtering based on the multiple sets of signal spectrum analysis results to establish a first reliable spectrum analysis space. Specifically, perform reliable filtering on each set of spectrum analysis results to remove noise and abnormal data. Reliable filtering can be implemented by setting a threshold or using statistical methods (such as mean filtering or median filtering). The filtered results are stored as the first reliable spectrum analysis space. For example, suppose that in the spectrum analysis results, the signal amplitude at some frequency points is significantly higher than at other frequency points, which may be noise or abnormal signals. Through reliable filtering, these abnormal data are removed, and reliable signal spectrum data is retained.

[0041] Step S330: Data fusion is performed based on the first reliable spectrum analysis space to obtain a first reliable spectrum analysis result. Specifically, reliable spectrum data from multiple spectrum analyzers are fused. Data fusion can be achieved through methods such as weighted averaging and maximum value selection to obtain more accurate spectrum analysis results. For example, suppose the spectrum data obtained by three spectrum analyzers differ at certain frequency points. By using a weighted averaging method, these data are fused to obtain a more accurate spectrum analysis result. For example, if the signal amplitudes of the three spectrum analyzers at the 1.5GHz frequency point are -20dBm, -21dBm, and -22dBm respectively, the final signal amplitude obtained by the weighted averaging method is -21dBm.

[0042] Step S340: Based on the first reliable spectrum analysis result, construct a characteristic curve for the first frequency band capture signal, and add the first frequency band capture signal characteristic curve to the characteristic curves of each frequency band capture signal. Specifically, based on the first reliable spectrum analysis result, construct a characteristic curve for the first frequency band capture signal. The characteristic curve can be represented by plotting the relationship between frequency and signal amplitude. Add the constructed characteristic curve to the characteristic curves of each frequency band capture signal. For example, assuming the first frequency band is 1.4GHz to 1.6GHz, plot the curve of signal amplitude changing with frequency for this frequency band based on the reliable spectrum analysis result. Finally, add this curve to the characteristic curves of each frequency band capture signal to form a complete set of frequency band characteristic curves. By simultaneously analyzing signals in the same frequency band using multiple spectrum analyzers, and combining reliable filtering and data fusion techniques, noise and abnormal data can be effectively removed, improving the accuracy of spectrum analysis.

[0043] In one possible implementation, based on the multiple sets of signal spectrum analysis results, a reliable filtering is performed to establish a first reliable spectrum analysis space. Step S320 further includes step S321, whereby, when the multiple spectrum analyzers perform spectrum analysis on the first optimized captured signal, the status parameters of the multiple spectrum analyzers are collected in real time to obtain multiple analyzer monitoring sequences. Specifically, during the spectrum analysis process, the status parameters of each spectrum analyzer, such as antenna gain, scan step, scan speed, and device temperature, are collected in real time. Changes in these parameters may affect the accuracy of the spectrum analysis results. The collected status parameters are recorded in chronological order to form multiple analyzer monitoring sequences. For example, assuming there are three spectrum analyzers, their antenna gain, scan step, and device temperature are recorded respectively. The status parameters of each spectrum analyzer are recorded in chronological order to form three monitoring sequences.

[0044] Step S322: Anomaly detection is performed based on the monitoring sequences of the multiple analyzers to determine the state anomaly coefficients of the multiple analyzers. Specifically, statistical methods (such as Z-Score) or machine learning methods (such as KNN) are used to detect anomalies in the monitoring sequences. Based on the anomaly detection results, the state anomaly coefficient of each spectrum analyzer is calculated. The anomaly coefficient can represent the degree of deviation of each data point from the normal state. For example, the Z-Score method is used to detect anomalies in the monitoring sequences. Suppose that in the antenna gain monitoring sequence of a spectrum analyzer, the gain value at a certain time point deviates significantly from the normal range, and its Z-Score value is greater than 3, then the state anomaly coefficient at that time point is considered to be high.

[0045] Step S323: Determine whether the abnormality coefficients of the multiple analyzers are less than a predetermined abnormality coefficient to obtain the status judgment results of the multiple analyzers. Specifically, a predetermined abnormality coefficient threshold is set to determine whether the spectrum analyzer is in normal condition. The abnormality coefficient of each spectrum analyzer is compared with the threshold. If it is less than the threshold, the spectrum analyzer is considered to be in normal condition; otherwise, it is considered to be in abnormal condition. For example, the abnormality coefficient threshold is set to 0.5. Assuming the abnormality coefficients of three spectrum analyzers are 0.3, 0.4, and 0.6 respectively, the status judgment results of the first two spectrum analyzers are normal, and the third is abnormal.

[0046] Step S324: Based on the status judgment results of the multiple analyzers, the multiple sets of signal spectrum analysis results are filtered and cleaned to generate the first spectrum analysis reliability space. Specifically, based on the status judgment results, the spectrum analysis results corresponding to the spectrum analyzers with normal status are retained, while the spectrum analysis results corresponding to the spectrum analyzers with abnormal status are discarded or corrected. The filtered and cleaned spectrum analysis results are stored as the first spectrum analysis reliability space. For example, if the first two spectrum analyzers are in normal status, their corresponding spectrum analysis results are retained; if the third spectrum analyzer is in abnormal status, its corresponding spectrum analysis results are discarded. Finally, the first spectrum analysis reliability space is generated. By monitoring the status parameters of the spectrum analyzers in real time and performing anomaly detection and filtering, noise and erroneous data caused by abnormal equipment status can be effectively removed, improving the reliability of the spectrum analysis results.

[0047] Step S400: Perform trusted signal feature mining on the target area, construct a trusted signal feature space, and input the captured signal feature curves of each frequency band into the trusted signal feature space to determine the first result of suspicious device detection.

[0048] Specifically, data mining techniques are used to extract reliable signal features from signal data in the target area, constructing a reliable signal feature space. Machine learning algorithms (such as cluster analysis and support vector machines) are then used to analyze the signal data in the target area and extract reliable signal features. These extracted reliable signal features are stored in the feature space for subsequent signal comparison and analysis. The signal feature curves captured by each frequency band are input into the reliable signal feature space, and comparative analysis is used to determine the first result for detecting suspicious devices. For example, cluster analysis algorithms are used to analyze the signal data in the target area and extract features of normal signals. These normal signal features are stored in the reliable signal feature space. The signal feature curves captured by each frequency band are input into the reliable signal feature space, and comparative analysis reveals abnormally high signal amplitudes in certain frequency bands, which may indicate the presence of suspicious devices.

[0049] In one possible implementation, trusted signal feature mining is performed on the target area to construct a trusted signal feature space. Step S400 further includes step S410, which involves retrieving signal feature samples for each trusted device in the target area to obtain multiple device signal feature sample sets. Specifically, signal feature samples are extracted from each trusted device in the target area. These samples may include time-domain features (such as mean, standard deviation, peak value, etc.) and frequency-domain features (such as spectral mean, frequency centroid, root mean square frequency, etc.). For example, assuming there are three trusted devices in the target area, their signal feature samples are extracted respectively to obtain three device signal feature sample sets.

[0050] Step S420: Extract a first device signal feature sample set based on the multiple device signal feature sample sets. Specifically, extract any one sample set from the multiple device signal feature sample sets as the first device signal feature sample set. For example, select a trusted device's signal feature sample set as the first device signal feature sample set using a traversal algorithm.

[0051] Step S430: Analyze the confidence level of each signal feature sample within the first device signal feature sample set to obtain a confidence coefficient for each feature sample. Specifically, statistical methods or machine learning models are used to evaluate the confidence level of each signal feature sample. The confidence coefficient can be expressed as the similarity between each sample and known reliable signal features.

[0052] Step S440: The first device signal feature sample set is optimized and filtered based on the confidence coefficients of each feature sample to generate a first confidence signal feature sample set that satisfies a predetermined confidence coefficient. Specifically, a predetermined confidence coefficient threshold is set, and signal feature samples with confidence coefficients higher than the threshold are filtered out. This can be achieved through threshold comparison or sorting methods. For example, a confidence coefficient threshold of 0.8 is set, and signal feature samples with confidence coefficients higher than 0.8 are filtered out to generate the first confidence signal feature sample set.

[0053] Step S450: Based on the first confidence signal feature sample set, a first reliable signal feature curve is constructed, and the first reliable signal feature curve is added to the reliable signal feature space. Specifically, the first reliable signal feature curve is constructed based on the first confidence signal feature sample set. The feature curve can be represented by plotting the relationship between frequency and signal amplitude. The constructed feature curve is added to the reliable signal feature space to form a complete reliable signal feature space. By retrieving and filtering signal feature samples from legitimate devices, reliable signal features can be extracted more accurately, reducing false alarms. Through confidence evaluation and optimization screening, high-confidence signal feature samples are selected, further improving the reliability of the system.

[0054] In one possible implementation, the characteristic curves of the captured signals in each frequency band are input into the trusted signal feature space to determine the first result of suspicious device detection. Step S400 further includes step S460, which involves performing a twin comparison on the characteristic curve of the first frequency band captured signal based on each trusted signal characteristic curve in the trusted signal feature space to obtain a first capture signal feature twin evaluation matrix. Specifically, a twin network or other similarity measurement method is used to calculate the similarity between the characteristic curve of the first frequency band captured signal and each trusted signal characteristic curve in the trusted signal feature space. The twin network can learn the similarity between signal features and output a similarity score. For example, assuming there are 5 trusted signal characteristic curves, the similarity between the characteristic curve of the first frequency band captured signal and these 5 trusted signal characteristic curves is calculated respectively to obtain 5 twin coefficients, forming the first capture signal feature twin evaluation matrix.

[0055] Step S470: The maximum value of the twin evaluation matrix of the first captured signal is filtered to determine the confidence coefficient of the first captured signal. Specifically, the maximum value, i.e., the twin coefficient corresponding to the most similar confidence signal feature curve, is selected from the twin evaluation matrix as the confidence coefficient of the first captured signal. For example, in the twin evaluation matrix, the five twin coefficients are 0.7, 0.8, 0.6, 0.5, and 0.9, with a maximum value of 0.9; therefore, the confidence coefficient of the first captured signal is 0.9.

[0056] Step S480: Determine whether the confidence coefficient of the first captured signal is less than a confidence threshold for the captured signal. Specifically, a predetermined confidence threshold for the captured signal is set, such as 0.8. If the confidence coefficient of the first captured signal is less than this threshold, the signal is considered unreliable and may be from a suspicious device. For example, if the confidence threshold for the captured signal is set to 0.8 and the confidence coefficient of the first captured signal is 0.9, which is greater than the threshold, the signal is considered reliable.

[0057] Step S490: If the confidence coefficient of the first captured signal is less than the confidence threshold of the captured signal, device tracing is performed on the characteristic curve of the first frequency band captured signal to determine the first suspicious device, and the first suspicious device is added to the first result of suspicious device detection. Specifically, if the confidence coefficient of the first captured signal is less than the threshold, the device corresponding to the signal is determined by signal tracing technology. This can be achieved by analyzing information such as the signal propagation path and signal strength. For example, suppose the confidence coefficient of the first captured signal is 0.7, which is less than the threshold of 0.8. By tracing the device, it is determined that the signal comes from a specific device, which is marked as the first suspicious device and added to the first result of suspicious device detection. Through twin comparison and maximum value screening, the similarity between the captured signal and the reliable signal can be accurately evaluated, thereby effectively identifying suspicious devices.

[0058] Step S500: Perform infrared detection compensation based on the first result of the suspected device detection to obtain the second result of the suspected device detection.

[0059] Specifically, infrared detection technology is used for further inspection of suspicious devices, and the results are combined with the initial detection results for compensation. Specifically, an infrared detector scans the target area to detect the infrared radiation characteristics of the devices. Based on the initial detection results, the infrared detection results are compensated; that is, the infrared detection results are fused with the initial detection results to obtain a second detection result. For example, an infrared detector scans the target area and detects the infrared radiation characteristics of a certain device. Based on the initial detection results, the infrared detection results are compensated to eliminate background interference. Finally, the infrared detection results are fused with the initial detection results to determine the location and characteristics of the suspicious device.

[0060] In one possible implementation, infrared detection compensation is performed based on the first result of the suspected device detection to obtain a second result of the suspected device detection. Step S500 further includes step S510, whereby an infrared thermal imager scans the target area to obtain a regional infrared thermal image. Specifically, an infrared thermal imager is used to scan the target area and capture infrared radiation signals within the target area. The infrared thermal imager collects the infrared radiation energy of the target through an optical system and converts it into an electrical signal to generate a regional infrared thermal image. For example, assuming the target area is a conference room, the infrared thermal imager generates an infrared thermal image of the area after scanning, showing the heat distribution of different devices and objects.

[0061] Step S520: Based on the reliable device reference thermal image of the target area, perform suspicious device identification on the infrared thermal image of the area to obtain infrared suspicious device detection results. Specifically, use the reference thermal image of a known reliable device in the target area and compare it with the infrared thermal image of the area. By analyzing the temperature distribution, shape, and other features in the thermal image, identify areas that do not match the reference thermal image; these areas may correspond to suspicious devices. For example, assuming a reference thermal image of an air conditioning unit in a conference room is known, comparison reveals that the temperature distribution of one area in the thermal image does not match the reference thermal image, and the shape is abnormal; it is preliminarily determined that this area may contain suspicious devices.

[0062] Step S530: Compensate the first result of suspicious device detection based on the infrared suspicious device detection result to generate the second result of suspicious device detection. Specifically, the infrared suspicious device detection result is fused with the first result of suspicious device detection. If the infrared detection result is consistent with or similar to the first result, the confidence level of the suspicious device is enhanced; if the infrared detection result is inconsistent with the first result, the first result is corrected or supplemented. For example, suppose that the location of a suspicious device in the first result of suspicious device detection is consistent with the location in the infrared suspicious device detection result, and the thermal image shows that the temperature of the device is abnormally high, the device is further confirmed as a suspicious device and added to the second result of suspicious device detection. By scanning with an infrared thermal imager and comparing with a reference thermal image, suspicious devices can be identified from the perspective of heat distribution. After being combined with the first detection result, the accuracy of detection is further improved.

[0063] Step S600: Perform a risk assessment on the second result of the suspicious device detection based on the real-time network traffic log of the target area, and obtain a suspicious device detection report.

[0064] Specifically, this method analyzes real-time network traffic logs of the target area to conduct a risk assessment of the second result of suspicious device detection. Specifically, network traffic analysis tools are used to monitor network traffic in the target area in real time and record traffic logs. Based on abnormal traffic characteristics in the network traffic logs, a risk assessment is conducted on the second result of suspicious device detection, generating a suspicious device detection report that details the characteristics, location, and risk level of the suspicious device. This embodiment employs the following techniques: first, using an RF scanner to scan the target area across multiple frequency bands to obtain a first set of captured signals; then, using scene feature data for adaptive interference compensation to obtain a second set of captured signals; next, using multiple spectrum analyzers to analyze and construct signal characteristic curves for each frequency band; then, mining the credible signal features of the target area to construct a spatial model and inputting the characteristic curves to determine the first result of suspicious device detection; then, using this result for infrared detection compensation to obtain a second result; and finally, using real-time network traffic logs to conduct a risk assessment of the second result and obtain a detection report. These techniques achieve the technical effect of improving the accuracy and reliability of remote eavesdropping device detection.

[0065] In one possible implementation, a risk assessment is performed on the second result of the suspicious device detection based on the real-time network traffic logs of the target area to obtain a suspicious device detection report. Step S600 further includes step S610, which involves performing correlation capture on the real-time network traffic logs based on the second result of the suspicious device detection to obtain the associated logs for each suspicious device. Specifically, based on the device information (such as IP address, device type, etc.) recorded in the second result of the suspicious device detection, log records related to these suspicious devices are extracted from the real-time network traffic logs. For example, assuming that the IP address of a suspicious device in the second result of the suspicious device detection is 192.168.1.100, all log records related to this IP address are extracted from the real-time network traffic logs as the associated logs for this suspicious device.

[0066] Step S620: Input the association logs of each suspicious device into the risk assessment model to obtain the risk coefficient of each suspicious device. Specifically, use a pre-trained risk assessment model to analyze the association logs of each suspicious device and calculate the risk coefficient of each suspicious device. The risk assessment model can be based on machine learning algorithms, such as random forests and support vector machines, or it can be a rule-based model. For example, the extracted association logs are input into the risk assessment model, and the model calculates the risk coefficient of the suspicious device based on the traffic characteristics in the logs (such as traffic volume, connection frequency, abnormal behavior, etc.), for example, 0.8 represents high risk and 0.3 represents low risk.

[0067] Step S630: Compile the second results of the suspicious device detection, the associated logs of each suspicious device, and the risk coefficients of each suspicious device to generate a suspicious device detection report. Specifically, the second results of the suspicious device detection, the associated logs, and the risk coefficients are integrated to generate a detailed suspicious device detection report. The report includes basic information about the suspicious devices, a summary of the associated logs, the risk coefficients, and suggested countermeasures. For example, the generated suspicious device detection report lists the IP addresses, device types, associated log summaries, and risk coefficients of all suspicious devices. For high-risk devices, further investigation or security measures are recommended.

[0068] In the above text, refer to Figure 1 A method for detecting remote eavesdropping devices in conjunction with TSCM according to embodiments of the present invention is described in detail. Next, reference will be made to... Figure 2 A remote eavesdropping device detection system incorporating TSCM is described according to an embodiment of the present invention.

[0069] The remote eavesdropping device detection system combined with TSCM according to embodiments of the present invention addresses the technical problems of low accuracy and poor reliability in existing remote eavesdropping device detection methods, thereby improving the accuracy and reliability of remote eavesdropping device detection. The remote eavesdropping device detection system combined with TSCM includes: a multi-band scanning module 10, an adaptive interference compensation module 20, a spectrum analysis module 30, a suspicious device detection module 40, an infrared detection compensation module 50, and a risk assessment module 60.

[0070] The system includes a multi-band scanning module 10, which performs multi-band scanning on the target area using an RF scanner to obtain a first set of captured signals, the first set of captured signals including multi-band captured signals; an adaptive interference compensation module 20, which performs adaptive interference compensation on the first set of captured signals based on multi-band scanning scene feature data to obtain a second set of captured signals; a spectrum analysis module 30, which performs spectrum analysis on the second set of captured signals using multiple spectrum analyzers to construct characteristic curves for each frequency band captured signal; a suspicious device detection module 40, which performs credible signal feature mining on the target area to construct a credible signal feature space, and inputs the characteristic curves for each frequency band captured signal into the credible signal feature space to determine a first result of suspicious device detection; an infrared detection compensation module 50, which performs infrared detection compensation based on the first result of suspicious device detection to obtain a second result of suspicious device detection; and a risk assessment module 60, which performs risk assessment on the second result of suspicious device detection based on real-time network traffic logs of the target area to obtain a suspicious device detection report.

[0071] The specific configuration of the adaptive interference compensation module 20 will be described in detail below. As mentioned above, adaptive interference compensation is performed on the first captured signal set based on the multi-band scanning scene feature data to obtain a second captured signal set. The adaptive interference compensation module 20 may further include: a data extraction unit for extracting a first frequency band captured signal and the first frequency band scanning scene feature data corresponding to the first frequency band captured signal based on the first captured signal set and the multi-band scanning scene feature data; a first scanning device status information acquisition unit for acquiring RF scanner status parameters corresponding to the first frequency band captured signal to obtain first scanning device status information; an interference coupling analysis unit for performing interference coupling analysis on the first frequency band captured signal based on the first frequency band scanning scene feature data and the first scanning device status information to determine a first interference compensation factor; and an interference compensation unit for performing interference compensation on the first frequency band captured signal based on the first interference compensation factor to obtain a first optimized captured signal and adding the first optimized captured signal to the second captured signal set.

[0072] The interference coupling analysis unit further includes: a first interference identification subunit for performing anomaly detection on the first frequency band scanning scene feature data and the first scanning device status information to determine a first interference compensation factor; a second interference identification subunit for performing anomaly detection on the first frequency band scanning scene feature data to obtain a first scanning scene anomaly detection result, and for performing interference identification on the first frequency band captured signal based on the first scanning scene anomaly detection result to obtain a first interference identification result; a third interference identification subunit for performing anomaly detection on the first scanning device status information to obtain a first scanning device anomaly detection result, and for performing interference identification on the first frequency band captured signal based on the first scanning device anomaly detection result to obtain a second interference identification result; and a fourth fusion analysis subunit for performing fusion analysis based on the first interference identification result and the second interference identification result to generate the first interference compensation factor.

[0073] The specific configuration of the spectrum analysis module 30 will be described in detail below. As mentioned above, based on the spectrum analysis of the second captured signal set by multiple spectrum analyzers, and the construction of characteristic curves for each frequency band captured signal, the spectrum analysis module 30 may further include: a spectrum analysis unit for performing spectrum analysis on the first optimized captured signal based on the multiple spectrum analyzers to obtain multiple sets of signal spectrum analysis results; a reliable filtering unit for performing reliable filtering based on the multiple sets of signal spectrum analysis results to establish a first spectrum analysis reliable space; a data fusion unit for performing data fusion based on the first spectrum analysis reliable space to obtain a first spectrum analysis reliable result; and a first frequency band captured signal characteristic curve construction unit for constructing a first frequency band captured signal characteristic curve based on the first spectrum analysis reliable result, and adding the first frequency band captured signal characteristic curve to the characteristic curves of each frequency band captured signal.

[0074] The first reliable spectrum analysis space is established by performing reliable filtering based on the spectrum analysis results of the multiple sets of signals. The reliable filtering unit may further include: a multiple analyzer monitoring sequence acquisition subunit, which is used to collect the status parameters of the multiple spectrum analyzers in real time when the multiple spectrum analyzers perform spectrum analysis on the first optimized capture signal, and obtain multiple analyzer monitoring sequences; an anomaly detection subunit, which is used to perform anomaly detection based on the multiple analyzer monitoring sequences and determine the multiple analyzer status anomaly coefficients; a judgment subunit, which is used to judge whether the multiple analyzer status anomaly coefficients are less than a predetermined status anomaly coefficient, and obtain multiple analyzer status judgment results; and a filtering and cleaning subunit, which is used to filter and clean the multiple sets of signal spectrum analysis results based on the multiple analyzer status judgment results, and generate the first reliable spectrum analysis space.

[0075] The specific configuration of the suspicious device detection module 40 will be described in detail below. As mentioned above, the suspicious device detection module 40 can further include: a signal feature sample retrieval unit for retrieving signal feature samples for each credible device in the target area to obtain multiple device signal feature sample sets; a first device signal feature sample set extraction unit for extracting a first device signal feature sample set based on the multiple device signal feature sample sets; a confidence evaluation unit for evaluating the confidence of each signal feature sample in the first device signal feature sample set to obtain the confidence coefficient of each feature sample; an optimization and screening unit for optimizing and screening the first device signal feature sample set based on the confidence coefficients of each feature sample to generate a first confidence signal feature sample set that meets a predetermined confidence coefficient; and a first credible signal feature curve construction unit for constructing a first credible signal feature curve based on the first credible signal feature sample set and adding the first credible signal feature curve to the credible signal feature space.

[0076] The suspected device detection module 40 further includes: a twin comparison unit for performing twin comparisons on the first frequency band capture signal feature curves according to each reliable signal feature curve in the reliable signal feature space to obtain a first capture signal feature twin evaluation matrix; a maximum value filtering unit for performing maximum value filtering on the first capture signal feature twin evaluation matrix to determine a first capture signal reliability coefficient; a judgment unit for judging whether the first capture signal reliability coefficient is less than the capture signal reliability threshold; and a device tracing unit for performing device tracing on the first frequency band capture signal feature curves if the first capture signal reliability coefficient is less than the capture signal reliability threshold, determining a first suspected device, and adding the first suspected device to the suspected device detection first result.

[0077] The specific configuration of the infrared detection compensation module 50 will be described in detail below. As mentioned above, infrared detection compensation is performed based on the first result of suspicious device detection to obtain a second result of suspicious device detection. The infrared detection compensation module 50 may further include: a regional infrared thermal image acquisition unit for obtaining a regional infrared thermal image by scanning the target area with an infrared thermal imager; a suspicious device identification unit for identifying suspicious devices in the regional infrared thermal image based on a reliable device reference thermal image of the target area to obtain an infrared suspicious device detection result; and a compensation unit for compensating the first result of suspicious device detection based on the infrared suspicious device detection result to generate the second result of suspicious device detection.

[0078] The specific configuration of the risk assessment module 60 will be described in detail below. As mentioned above, the risk assessment module 60 performs a risk assessment on the second result of the suspicious device detection based on the real-time network traffic logs of the target area to obtain a suspicious device detection report. The risk assessment module 60 may further include: an association capture unit for performing association capture on the real-time network traffic logs based on the second result of the suspicious device detection to obtain association logs for each suspicious device; a risk assessment unit for inputting the association logs for each suspicious device into a risk assessment model to obtain a risk coefficient for each suspicious device; and a suspicious device detection report generation unit for compiling the second result of the suspicious device detection, the association logs for each suspicious device, and the risk coefficients for each suspicious device to generate the suspicious device detection report.

[0079] The remote eavesdropping device detection system combined with TSCM provided in the embodiments of the present invention can execute the remote eavesdropping device detection method combined with TSCM provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the method execution.

[0080] Although this application makes various references to certain modules in the system according to the embodiments of this application, any number of different modules can be used and run on user terminals and / or servers. The various units and modules included are only divided according to functional logic, but are not limited to the above division, as long as the corresponding functions can be achieved; in addition, the specific names of each functional unit are only for easy distinction between each other and are not used to limit the scope of protection of this invention.

[0081] The specific embodiments described above do not constitute a limitation on the scope of protection of this application. Those skilled in the art should understand that various modifications, combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this application should be included within the scope of protection of this application. In some cases, the actions or steps described in this application can be performed in a different order than that shown in the embodiments and still achieve the desired results. Furthermore, the processes depicted in the accompanying drawings do not necessarily require a specific or sequential order to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.

Claims

1. A remote eavesdropping device detection method combined with TSCM, characterized in that, include: The target area is scanned by an RF scanner in multiple frequency bands to obtain a first set of captured signals, which includes multi-frequency captured signals. Based on the multi-band scanning scene feature data, adaptive interference compensation is performed on the first captured signal set to obtain the second captured signal set; The second captured signal set is subjected to spectrum analysis by multiple spectrum analyzers to construct characteristic curves of captured signals in each frequency band; Trusted signal feature mining is performed on the target area to construct a trusted signal feature space, and the captured signal feature curves of each frequency band are input into the trusted signal feature space to determine the first result of suspicious device detection. Infrared detection compensation is performed based on the first result of the suspected device detection to obtain a second result of the suspected device detection. Based on the real-time network traffic logs of the target area, a risk assessment is performed on the second result of the suspicious device detection to obtain a suspicious device detection report; Based on the multi-band scanning scene feature data, adaptive interference compensation is performed on the first captured signal set to obtain a second captured signal set, including: Based on the first captured signal set and the multi-band scanning scene feature data, extract the first frequency band captured signal and the first frequency band scanning scene feature data corresponding to the first frequency band captured signal; Collect the RF scanner status parameters corresponding to the first frequency band capture signal to obtain the first scanning device status information; Based on the feature data of the first frequency band scanning scene and the status information of the first scanning device, an interference coupling analysis is performed on the first frequency band captured signal to determine the first interference compensation factor. The first frequency band capture signal is subjected to interference compensation based on the first interference compensation factor to obtain a first optimized capture signal, and the first optimized capture signal is added to the second capture signal set.

2. The remote eavesdropping device detection method combined with TSCM as described in claim 1, characterized in that, Based on the feature data of the first frequency band scanning scene and the status information of the first scanning device, interference coupling analysis is performed on the first frequency band captured signal to determine the first interference compensation factor, including: Anomaly detection is performed on the feature data of the first frequency band scanning scene to obtain the anomaly detection result of the first scanning scene, and interference identification is performed on the captured signal of the first frequency band based on the anomaly detection result of the first scanning scene to obtain the first interference identification result of the signal. Anomaly detection is performed on the status information of the first scanning device to obtain the anomaly detection result of the first scanning device, and interference identification is performed on the first frequency band captured signal based on the anomaly detection result of the first scanning device to obtain the second interference identification result of the signal. The first interference compensation factor is generated by fusing the first interference identification result and the second interference identification result of the signal.

3. The remote eavesdropping device detection method combined with TSCM as described in claim 1, characterized in that, Based on the spectral analysis of the second captured signal set using multiple spectrum analyzers, characteristic curves of the captured signals in each frequency band are constructed, including: The first optimized capture signal is analyzed by the multiple spectrum analyzers to obtain multiple sets of signal spectrum analysis results; Based on the results of the spectrum analysis of the multiple sets of signals, a reliable filtering is performed to establish a first reliable spectrum analysis space. Data fusion is performed based on the first spectral analysis confidence space to obtain the first spectral analysis confidence result; Based on the first reliable spectrum analysis results, a first frequency band capture signal characteristic curve is constructed, and the first frequency band capture signal characteristic curve is added to the capture signal characteristic curves of each frequency band.

4. The remote eavesdropping device detection method combined with TSCM as described in claim 3, characterized in that, Based on the spectral analysis results of the multiple sets of signals, reliable filtering is performed to establish a first spectral analysis reliable space, including: When the multiple spectrum analyzers perform spectrum analysis on the first optimized capture signal, the status parameters of the multiple spectrum analyzers are collected in real time to obtain multiple analyzer monitoring sequences; Anomaly detection is performed based on the monitoring sequences of the multiple analyzers to determine the anomaly coefficients of the multiple analyzer states. Determine whether the abnormality coefficients of the multiple analyzers are less than the predetermined abnormality coefficients, and obtain the status judgment results of the multiple analyzers. Based on the status judgment results of the multiple analyzers, the multiple sets of signal spectrum analysis results are filtered and cleaned to generate the first spectrum analysis confidence space.

5. The remote eavesdropping device detection method combined with TSCM as described in claim 1, characterized in that, The target region is subjected to reliable signal feature mining to construct a reliable signal feature space, including: For each trusted device in the target area, a signal feature sample retrieval is performed to obtain multiple device signal feature sample sets; Based on the multiple device signal feature sample sets, extract the first device signal feature sample set; Confidence evaluation is performed on each signal feature sample in the first device signal feature sample set to obtain the confidence coefficient of each feature sample; The first device signal feature sample set is optimized and filtered based on the confidence coefficients of each feature sample to generate a first confidence signal feature sample set that satisfies a predetermined confidence coefficient. Based on the first set of confidence signal feature samples, a first confidence signal feature curve is constructed, and the first confidence signal feature curve is added to the confidence signal feature space.

6. The remote eavesdropping device detection method combined with TSCM as described in claim 1, characterized in that, Input the characteristic curves of the captured signals in each frequency band into the reliable signal feature space to determine the first result of the suspected device detection, including: Based on each credible signal feature curve in the credible signal feature space, a twin comparison is performed on the feature curve of the first frequency band capture signal to obtain the first capture signal feature twin evaluation matrix. The maximum value of the first captured signal feature twin evaluation matrix is ​​filtered to determine the confidence coefficient of the first captured signal; Determine whether the confidence coefficient of the first captured signal is less than the confidence threshold of the captured signal; If the confidence coefficient of the first captured signal is less than the confidence threshold of the captured signal, the device traceability is performed on the characteristic curve of the first frequency band captured signal to identify the first suspicious device, and the first suspicious device is added to the first result of the suspicious device detection.

7. The remote eavesdropping device detection method combined with TSCM as described in claim 1, characterized in that, Based on the first result of the suspected device detection, infrared detection compensation is performed to obtain a second result of the suspected device detection, including: The target area is scanned by an infrared thermal imager to obtain an infrared thermal image of the area; Based on the reliable device reference thermal image of the target area, the infrared thermal image of the area is used to identify suspicious devices and obtain the infrared suspicious device detection result. The first result of the suspected device detection is compensated based on the infrared suspected device detection result, and a second result of the suspected device detection is generated.

8. The remote eavesdropping device detection method combined with TSCM as described in claim 1, characterized in that, A risk assessment is performed on the second result of the suspicious device detection based on the real-time network traffic logs of the target area to obtain a suspicious device detection report, including: Based on the second result of the suspicious device detection, the real-time network traffic logs are correlated and captured to obtain the associated logs of each suspicious device. Input the associated logs of each suspicious device into the risk assessment model to obtain the risk coefficient of each suspicious device; The second results of the suspicious device detection, the associated logs of each suspicious device, and the risk coefficient of each suspicious device are compiled to generate the suspicious device detection report.

9. A remote eavesdropping device detection system combined with TSCM, characterized in that, The system is used to implement the remote eavesdropping device detection method combined with TSCM as described in any one of claims 1-8, and the system comprises: A multi-band scanning module is used to perform multi-band scanning on a target area using an RF scanner to obtain a first set of captured signals, wherein the first set of captured signals includes multi-band captured signals. The adaptive interference compensation module is used to perform adaptive interference compensation on the first captured signal set based on the multi-band scanning scene feature data to obtain the second captured signal set. The spectrum analysis module is used to perform spectrum analysis on the second captured signal set based on multiple spectrum analyzers and to construct characteristic curves of the captured signals in each frequency band. The suspicious device detection module is used to mine credible signal features in the target area, construct a credible signal feature space, and input the captured signal feature curves of each frequency band into the credible signal feature space to determine the first result of suspicious device detection. The infrared detection compensation module is used to perform infrared detection compensation based on the first result of the suspicious device detection to obtain a second result of the suspicious device detection. The risk assessment module is used to perform a risk assessment on the second result of the detection of the suspicious device based on the real-time network traffic log of the target area, and obtain a suspicious device detection report.

Citation Information

Patent Citations

  • Environment detection system and method based on multi-source detection and auxiliary positioning

    CN118354278A

  • Operation mode estimating apparatus for detecting malicious behavior of target device and method thereof

    KR1020170129489A