5G communication server access control method and system
The 5G communication server access control method improves access control accuracy by clustering users based on risk scores and network data, dynamically assigning server levels, and utilizing edge computing to optimize resource allocation and response speed.
Patent Information
- Application Number
- CN202510469499.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-15
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2045-04-15
AI Technical Summary
The high mobility and short connection cycle of terminal devices in existing 5G networks make it difficult for traditional access control technology to ensure the real-time and consistency of attribute data, resulting in errors in abnormal server judgments and low access control accuracy.
By obtaining the user's risk coefficient and network environment data, using the edge computing architecture to cluster users into different types of clusters, calculating edge allocation weights and computing power allocation coefficients, dynamically adjusting the server level and location, and filtering abnormal servers for control.
It realizes rapid response to access requests in 5G networks, improves the accuracy and security of access control, dynamically share the access pressure of the main server, and adapts to changes in the network environment.
Smart Images

Figure CN120321653A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and particularly relates to a 5G communication server access control method and system. Background Art
[0002] With the rapid development of 5G communication technology, the connectivity of the network and the data transmission speed have been greatly improved, giving rise to emerging application scenarios such as the Internet of Things, intelligent transportation, and remote healthcare. However, the accompanying security risks and access control challenges have become increasingly prominent. In the 5G environment, the sharp increase in the number of users, the diversity of devices, and the demand for real-time data processing make it difficult for traditional access control methods to meet the requirements of a dynamic and complex network environment.
[0003] In the prior art, the existing mainstream access control technologies are mainly based on role, attribute, or capability models, relying on preset policies and centralized privilege management. However, due to the characteristics of high mobility and short connection cycles of terminal devices in the 5G network, attributes such as location, network status, and security level need to be dynamically updated at the millisecond level, resulting in the difficulty of the mainstream access control technologies that rely on static or low-frequency updated attribute libraries to ensure the real-time and consistency of attribute data during policy decision-making, which may lead to errors in abnormal server judgment, and thus the access control accuracy is relatively low. Summary of the Invention
[0004] In order to solve the technical problem that the mainstream access control technology depends on static and leads to errors in abnormal server judgment, the purpose of the present invention is to provide a 5G communication server access control method and system, and the specific technical solutions adopted are as follows:
[0005] In a first aspect, an embodiment of the present invention provides a 5G communication server access control method, and the method includes:
[0006] Obtain the risk coefficients of different tags of each user accessing the server at each moment, and the network environment data of the server at each moment;
[0007] Cluster the users accessing the server at each moment into different clusters; according to the risk coefficients of the tags of the users within each cluster at each moment, and the influence degree of the tags of the users on the corresponding cluster, obtain the marginal allocation weights of each cluster at each moment;
[0008] According to the number of tags of the users within each cluster at each moment and the marginal allocation weights, obtain the marginal computing power allocation coefficients of each cluster at each moment; use the marginal allocation weights and the marginal computing power allocation coefficients of the clusters at each moment to divide the servers accessed by the users at each moment into different levels;
[0009] Select abnormal servers for control from the servers accessed by the user at each moment according to the network environment data between each server and the remaining servers and the differences in the levels they are in.
[0010] Further, clustering the users accessing the server at each moment into different clusters includes:
[0011] Taking the sum of the risk coefficients of all tags of each user at each moment as the portrait factor of each user at each moment; clustering the users accessing the server at the same moment based on the portrait factor to obtain the clusters at each moment.
[0012] Further, obtaining the edge assignment weight of each cluster at each moment includes:
[0013] Respectively, recording the variance of the risk coefficients of the same tag of all users within each cluster at each moment as the within-cluster variance of the corresponding tag in the cluster, and recording the variance of the risk coefficients of the same tag of all users within all clusters at each moment as the global variance of each tag; taking the ratio of the global variance to the within-cluster variance as the clustering influence degree of each tag on each cluster at each moment; selecting the largest N clustering influence degree corresponding tags from the clustering influence degrees of all tags on each cluster at each moment as the influence tags of each cluster at each moment.
[0014] Based on the risk coefficient, select the valid tags of each user at each moment; count the number of valid tags that are the same as the influence tags among the valid tags of all users within each cluster at each moment, and record it as the tag influence degree of the corresponding cluster.
[0015] According to the mean value of the portrait factors of all users within each cluster of each user, the number of tag types of all users, and the tag influence degree, obtain the edge assignment weight of the corresponding cluster.
[0016] Further, obtaining the edge computing power allocation coefficient of each cluster at each moment includes:
[0017] Taking the ratio of the number of tag types of users within each cluster at each moment to the maximum value of the number of tag types of users within all clusters at each moment as the type proportion of each cluster at each moment.
[0018] According to the edge assignment weight and the type proportion of each cluster at each moment, obtain the edge computing power allocation coefficient of the corresponding cluster.
[0019] Further, dividing the servers accessed by the user at each moment into different levels includes:
[0020] Forming an analysis set from the edge assignment weights of all clusters at each moment.
[0021] Select the edge allocation weight with the largest value in the analysis set as the initial analysis value. Use the servers accessed by the users within the cluster corresponding to the analysis value at each moment as the first-level servers at each moment. Delete the analysis value from the analysis set and update the analysis set.
[0022] Use the gradient descent method to select the edge allocation weight closest to the analysis value from the updated analysis set, denoted as the new analysis value. Use the servers accessed by the users within the cluster corresponding to the new analysis value at each moment as the second-level servers at each moment. Delete the new analysis value from the updated analysis set and update the analysis set.
[0023] And so on until the updated analysis set is an empty set.
[0024] Further, the step of selecting abnormal servers from the servers accessed by the users at each moment includes:
[0025] The network environment data includes the access frequency and network load. Use the product of the access frequency and network load of each server at each moment as the status value of each server at each moment.
[0026] For the servers accessed by the users at each moment, arbitrarily select a server as the analysis server. Perform negative correlation and normalization processing on the level difference between the level where the analysis server is located and the other levels except the level where the analysis server is located to obtain the level weight. According to the level weight, perform weighted summation on the absolute value of the difference between the status value of the analysis server at each moment and the mean value of the status values of all servers at each moment in all other levels except the level where the analysis server is located to obtain the neighborhood status difference of the analysis server at each moment.
[0027] Use the sum of the status value of the analysis server at each moment and the neighborhood status difference as the anomaly value of the analysis server at each moment.
[0028] Select the servers with values greater than the preset anomaly threshold from the servers accessed by the users at each moment as the abnormal servers at each moment.
[0029] Further, the mean value of the portrait factors of all users within the cluster has a positive correlation with the number of label types of all users and the edge allocation weight, and the label influence degree has a negative correlation with the edge allocation weight.
[0030] Further, the method for clustering the users accessing the servers at the same moment is the hierarchical clustering algorithm.
[0031] Further, the preset anomaly threshold is 0.7.
[0032] Second aspect, another embodiment of the present invention provides a 5G communication server access control system, which includes:
[0033] A data acquisition module, configured to obtain the risk coefficients of different tags of each user accessing the server at each moment, as well as the network environment data of the server at each moment;
[0034] An edge allocation analysis module, configured to cluster the users accessing the server at each moment into different clusters; according to the risk coefficients of the tags of the users within each cluster at each moment, and the influence degree of the tags of the corresponding cluster on the users, obtain the edge allocation weights of each cluster at each moment;
[0035] A server level division module, configured to obtain the edge computing power allocation coefficients of each cluster at each moment according to the number of tags of the users within each cluster at each moment and the edge allocation weights; use the edge allocation weights and the edge computing power allocation coefficients of the clusters at each moment to divide the servers accessed by the users at each moment into different levels;
[0036] An access control module, configured to select abnormal servers from the servers accessed by the users at each moment for control according to the network environment data and the level differences between each server and the other servers.
[0037] The present invention has the following beneficial effects:
[0038] In the embodiments of the present invention, in order to enable the 5G communication server to quickly respond to access requests, an edge computing architecture is used to share the access pressure of the main server, realizing dynamic resource allocation and intelligent scheduling; different users have different dangerous situations when accessing the server. In order to improve access security, users accessing the server at each moment are clustered into user clusters with different levels of danger; the risk coefficient of the labels of users within a cluster at each moment reflects the access behavior risk of the users within the cluster, and the access behavior risk determines the possibility of collaborative processing of access requests. The degree of influence of the cluster by the labels of the users determines the possibility of collaborative control. By analyzing the above factors, the possibility of collaborative processing required by users within the cluster to access the server is obtained, and the edge allocation weight is obtained; the number of labels of users within each cluster reflects the diversity of service types involved in the requests of the users within the cluster, and the edge allocation weight reflects the possibility of collaborative access processing. Both determine resource allocation, and the edge computing power allocation coefficient is obtained; by combining the edge allocation weight and the edge computing power allocation coefficient, the location of the edge server is allocated, realizing hierarchical division of the servers accessed by users at each moment and adaptively and dynamically adjusting the server location; the server occupying network resources will cause abnormal fluctuations in adjacent edge servers. The lower the value of the abnormal fluctuations of adjacent servers farther away from the server for the abnormal judgment of this server, the network environment data of the server reflects the abnormal fluctuations. Combining the network environment data of each server with that of the other servers and the hierarchical differences can improve the accuracy of abnormal server screening and improve the access control accuracy rate. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] In order to more clearly illustrate the technical solutions and advantages in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for description in the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0040] Figure 1 It is a step flow chart of a 5G communication server access control method provided by an embodiment of the present invention;
[0041] Figure 2 It is a system structure diagram of a 5G communication server access control system provided by an embodiment of the present invention;
[0042] Figure 3 It is a schematic diagram of a computer device of a 5G communication server access control device provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0043] To further elaborate on the technical means and effects adopted by the present invention to achieve the intended invention purpose, the following, in conjunction with the accompanying drawings and preferred embodiments, details a 5G communication server access control method and system proposed according to the present invention, including its specific implementation manner, structure, features, and effects. In the following description, different "one embodiment" or "another embodiment" do not necessarily refer to the same embodiment. In addition, the specific features, structures, or characteristics in one or more embodiments can be combined in any suitable form.
[0044] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the technical field to which the present invention belongs.
[0045] The following specifically describes the specific solutions of a 5G communication server access control method and system provided by the present invention in conjunction with the accompanying drawings.
[0046] Embodiment 1:
[0047] The present invention proposes a 5G communication server access control method. Please refer to Figure 1 , which shows the step flow chart of a 5G communication server access control method provided by an embodiment of the present invention. The method includes:
[0048] Step S1: Obtain the risk coefficients of different tags of each user accessing the server at each moment, and the network environment data of the server at each moment.
[0049] When describing the user portrait of the access server, describe its access behavior and obtain the risk coefficients of different tags of each user accessing the server. The tags are used to determine whether the access behavior is abnormal. In the embodiment of the present invention, the tags include: geographical distribution tags, network type tags, access activity tags, and can also be other access behavior data, which will not be limited here. The geographical distribution tags are divided into domestic and foreign. The risk of domestic access is lower than that of foreign access, so the risk coefficients of users accessing domestically and abroad are set to 0 and 1 respectively; the network type tags are divided into 5G, Wi-Fi, and broadband. The risks from large to small are Wi-Fi, 5G, and broadband. Therefore, the risk coefficients of users using broadband, 5G, and Wi-Fi are set to 0, 1, and 2 respectively; the access activity tags are divided into high-active users and low-active users. If the weekly access times are greater than or equal to 3 times, it is a high-active user; if it is less than 3 times, it is a low-active user. Then the risk coefficients of high-active users and low-active users are set to 0 and 1 respectively.
[0050] Obtain the network environment data of the server at each moment; in the embodiment of the present invention, the network data includes access frequency and network load. In other embodiments, it can also be other network data.
[0051] For example, high-frequency domestic Wi-Fi users can be automatically allocated high-priority bandwidth, while low-frequency overseas 5G users need to execute security detection and network acceleration strategies simultaneously.
[0052] Step S2: Cluster the users accessing the server at each moment into different clusters; according to the risk coefficients of the labels of the users within each cluster at each moment, and the degree of influence of the labels of the corresponding cluster on the users, obtain the edge allocation weights of each cluster at each moment.
[0053] In order to enable the 5G communication server to quickly respond to access requests, the edge computing architecture is used to share the access pressure of the main server, and dynamic resource allocation and intelligent scheduling are realized based on user portraits. The access risks of different users to the server are different. To improve access security, users with different risk levels need to be allocated to corresponding servers for processing. For example, users with a higher risk level are placed on the edge server for processing to reduce the computing pressure and access risks of the main server. It is necessary to cluster the users accessing the server at each moment into user groups with different risk levels.
[0054] In the embodiment of the present invention, the sum of the risk coefficients of all the labels of each user at each moment is used as the portrait factor of each user at each moment; based on the portrait factor, the users accessing the server at the same moment are clustered to obtain the clusters at each moment. The risk coefficient of the category label of each user at each moment reflects the user image, and the portrait factor reflects the dynamic risk characteristics of the user's behavior.
[0055] In one implementation manner of the embodiment of the present invention, the hierarchical clustering algorithm is selected to cluster the users accessing the server at the same moment. Other embodiments can use the K-means clustering algorithm, DBSCAN algorithm, etc.
[0056] The risk coefficient of the label of the users within the cluster at each moment reflects the access behavior risk of the users within the cluster. The access behavior risk determines the possibility of needing to jointly process the access request; the degree of influence of the label of the cluster on the users determines the possibility of joint control. Combining the above factors to analyze the possibility of jointly processing the access request of the users within the cluster to obtain the edge allocation weight.
[0057] Preferably, in some possible implementation manners of the embodiments of the present invention, the method for obtaining the edge allocation weight includes: respectively recording the variance of the risk coefficients of the same label of all users in each cluster at each moment as the within-cluster variance of each label in the corresponding cluster, and recording the variance of the risk coefficients of the same label of users in all clusters at each moment as the global variance of each label; taking the ratio of the global variance to the within-cluster variance as the clustering influence degree of each label on each cluster at each moment; selecting the top N labels corresponding to the largest clustering influence degrees from the clustering influence degrees of all labels on each cluster at each moment as the influence labels of each cluster at each moment; selecting the effective labels of each user at each moment based on the risk coefficients; counting the number of effective labels that are the same as the influence labels among the effective labels of all users in each cluster at each moment as the label influence degree of the corresponding cluster; and obtaining the edge allocation weight of the corresponding cluster according to the mean value of the portrait factors of all users in each cluster for each user, the number of label types of all users, and the label influence degree.
[0058] Analyze the labels with greater clustering influence on each cluster through F-value test; if the within-cluster variance of each label is smaller than the global variance, that is, the clustering influence degree is greater, it indicates that the consistency of each label within each cluster is higher, and the influence of this label on the clustering of each cluster is greater, and the influence label represents the group characteristics of users within the cluster. If the number of effective labels that are the same as the influence labels among the effective labels of all users in each cluster at each moment is larger, it indicates that the users within this cluster are more affected by the influence label. When performing edge server allocation, single allocation can be performed, and the required edge allocation is less, without the need for multi-server collaborative control, and the edge allocation weight is smaller. If the portrait factor of users within the cluster is larger, it indicates that the access behavior risk of users within the cluster is greater. In order to limit high-risk users within a controllable range, the high-risk cluster users need to be deployed to the proximal edge server to facilitate real-time traffic cleaning, behavior analysis, and rapid blocking, so as to meet the requirements of collaborative processing of access requests. The more edge allocation required for users within the cluster to access the server, the greater the edge allocation weight. If the number of label types of users within the cluster is larger, it indicates that the users within the cluster are affected by more factors and the similarity in access behavior is greater. The distance between the edge nodes deployed for users within the cluster should be closer to meet the requirements of collaborative processing of access requests. Then, the more edge allocation required for users within the cluster to access the server. Therefore, there is a positive correlation between the mean value of the portrait factors of all users in each cluster for each user, the number of label types of all users, and the edge allocation weight, and there is a negative correlation between the label influence degree and the edge allocation weight.
[0059] In the embodiments of the present invention, the product of the mean value of the portrait factors of all users in each cluster for each user, the number of label types of all users, and the reciprocal of the label influence degree is used as the edge allocation weight of the cluster. The edge allocation weight is used to allocate the positions of each edge server.
[0060] In the embodiments of the present invention, the mean value of the portrait factors of all users within each cluster for each user can also be constructed through other basic mathematical operations, the number of types of all users' labels, and the correlation between the label influence degree and the edge allocation weight, which will not be limited and elaborated herein.
[0061] In the embodiments of the present invention, a valid label is a label whose risk coefficient is not equal to a preset value. The minimum value of the label is 0, which represents that the access behavior is not dangerous and it is meaningless to perform subsequent analysis. Therefore, labels with a risk coefficient of 0 need to be excluded.
[0062] In an implementation manner of the embodiments of the present invention, N is equal to the integer result of taking one-fourth of the number of types of users' labels.
[0063] In other embodiments of the present invention, the risk coefficients of the same label of all users within each cluster at each moment and the risk coefficients of the same label of users within all clusters at each moment are respectively clustered to obtain two clustering center points, and the corresponding numerical values of the clustering center points are sequentially recorded as the first central value of each label in the corresponding cluster and the second central value of each label; the absolute value of the difference between the first central value and the second central value is used as the clustering influence degree of each label on each cluster at each moment.
[0064] Step S3: Obtain the edge computing power allocation coefficient of each cluster at each moment according to the number of labels of users within each cluster at each moment and the edge allocation weight; use the edge allocation weight and the edge computing power allocation coefficient of the cluster at each moment to divide the servers accessed by the user at each moment into different levels.
[0065] The local deployment of the server is fixed, and only the edge computing power needs to be allocated to realize the allocation of the location of the edge server; the number of labels of users within each cluster reflects the diversity of service types involved in the requests of users within the cluster, and the edge allocation weight reflects the possibility of collaborative processing of access. Both determine the resource allocation, so as to obtain the edge computing power allocation coefficient. Combining the edge allocation weight and the edge computing power allocation coefficient to allocate the location of the edge server, realizing the hierarchical division of the servers accessed by the user at each moment, adaptively and dynamically adjusting the server location, and improving the response speed of the service.
[0066] Preferably, in some possible implementation manners of the embodiments of the present invention, the method for obtaining the edge computing power allocation coefficient includes: taking the ratio of the number of types of labels of users within each cluster at each moment to the maximum value of the number of types of labels of users within all clusters at each moment as the type proportion of each cluster at each moment; obtaining the edge computing power allocation coefficient of the corresponding cluster according to the edge allocation weight and the type proportion of each cluster at each moment.
[0067] The more diverse the service types involved in user requests within a cluster with a higher category proportion, there may be concurrent multi-label tasks, and redundant computing power needs to be reserved to avoid response delays caused by resource contention. Thus, the larger the edge computing power allocation coefficient. The more collaborative processing is required for users within a cluster with a larger edge allocation weight to access the server, the greater the required edge computing power, and the larger the edge computing power allocation coefficient. Therefore, both the edge allocation weight and the category proportion are positively correlated with the edge computing power allocation coefficient.
[0068] In the embodiments of the present invention, the product of the edge allocation weight and the category proportion of each cluster at each moment is used as the edge computing power allocation coefficient of the corresponding cluster; the relevant relationship between the edge allocation weight, the category proportion, and the edge computing power allocation coefficient can also be constructed through other basic mathematical operations, which will not be limited and elaborated here.
[0069] Preferably, in some possible implementation manners of the embodiments of the present invention, the method for dividing the servers into levels is as follows: the edge allocation weights of all clusters at each moment form an analysis set; the largest edge allocation weight in the analysis set is selected as the initial analysis value, and the servers accessed by the users within the cluster corresponding to the analysis value at each moment are used as the servers of the first level at each moment, and the analysis value is deleted from the analysis set and the analysis set is updated; the gradient descent method is used to select the edge allocation weight closest to the analysis value from the updated analysis set, denoted as the new analysis value, and the servers accessed by the users within the cluster corresponding to the new analysis value at each moment are used as the servers of the second level at each moment, and the new analysis value is deleted from the updated analysis set and the analysis set is updated; and so on until the updated analysis set is an empty set. Among them, the gradient descent method is a well-known technology to those skilled in the art and will not be elaborated here.
[0070] In the embodiments of the present invention, the method for the gradient descent method to select the edge allocation weight is as follows: calculate the square of the absolute value of the difference between the edge allocation weights in the updated analysis set and the analysis value respectively, and the edge allocation weight corresponding to the smallest square is the edge allocation weight closest to the analysis value in the updated analysis set. Among them, the square of the absolute value of the difference between the edge allocation weight and the analysis value in the analysis set is equivalent to the loss function.
[0071] The first-level server is the central server. The central server needs to handle a large amount of access information in real time and quickly. The cluster with the larger edge allocation weight is more satisfied with the collaborative processing of access requests. Therefore, the server accessed by the user in the cluster with the largest edge allocation weight in the analysis set at each moment is selected as the first-level server at each moment, so as to ensure that a large amount of normal access data can be processed quickly. The gradient descent method starts from the central server and gradually finds the optimal edge server. It can adapt to different load changes and network environments, and gradually adjust the distribution strategy to ensure that the server can be dynamically adjusted and always remain in an optimized state. According to the real-time adjustment of computing power distribution according to the network environment and load conditions, avoid some nodes carrying too many tasks. In the face of network fluctuations or equipment failures, it quickly responds and adjusts node allocation to improve the response speed of the service.
[0072] It should be noted that each user can only access one server at each time; the level determined by the server increases successively each time.
[0073] Step S4: According to the network environment data and the hierarchical differences between each server and the other servers, an abnormal server is selected from the servers accessed by the user at each moment for control.
[0074] Based on the dynamic optimization of server location distribution, a server occupying network resources will cause abnormal fluctuations in adjacent edge servers, and the abnormal fluctuations of adjacent servers that are farther away from a server will have a lower value for abnormal judgment of the server; the server's network environment data reflects abnormal fluctuations, and combining the network environment data of each server with the other servers and the differences in the levels at which they are located can improve the accuracy of abnormal server screening.
[0075] Preferably, in some possible implementations of the embodiments of the present invention, the screening method of abnormal servers includes: the network environment data includes access frequency and network load; the product of the access frequency and network load of each server at each moment is used as the state value of each server at each moment; for the server accessed by the user at each moment, any server is selected as the analysis server, and the level difference between the level where the analysis server is located and the level difference of the remaining levels except the level where the analysis server is located is negatively correlated and normalized to obtain the level weight; according to the level weight, the state value of the analysis server at each moment is weighted and summed with the absolute value of the difference between the mean of the state value of all servers of all levels except the level where the analysis server is located at each moment, and the neighborhood state difference of the analysis server at each moment is obtained; the sum of the state value of the analysis server at each moment and the neighborhood state difference is used as the abnormal value of the analysis server at each moment. Among them, the access frequency represents the number of times the user accesses the server within 1 second.
[0076] When an external network element attacks a server, it will access the server frequently and occupy a large network bandwidth. The greater the access frequency and network load of the server, the greater the possibility that the server is attacked by the external network, and the greater the possibility that the server is in an attacked state. Occupying network resources will cause abnormal fluctuations in adjacent edge servers, affecting the data processing speed. When the possible difference in the attacked state between the analysis server and the other servers is smaller, it indicates that the influence degree of the analysis server on the other servers is greater, then the analysis server is more severely attacked by the external network, and the greater the outlier value; at the same time, if the levels of the analysis server and the other servers are closer, the influence degree of the analysis server on the other servers is more referenceable.
[0077] In a specific implementation manner of the embodiment of the present invention, the outlier value Y of the analysis server at each moment is expressed by the formula:
[0078]
[0079] In the formula, K is the state value of the analysis server at each moment; M is the total number of levels of the servers accessed by the user at each moment; C m is the level difference between the level where the analysis server is located and the m-th level other than the level where the analysis server is located. For example, the level difference between the first level and the third level is 2; is the average value of the state values of all servers at the m-th level other than the level where the analysis server is located at each moment; is the neighborhood state difference of the analysis server at each moment; || is the absolute value function; Norm is the normalization function.
[0080] Select the servers with outlier values greater than the preset outlier threshold from the servers accessed by the user at each moment as the outlier servers at each moment. The outlier servers have anomalies and need to be controlled accordingly. In an implementation manner of the embodiment of the present invention, the preset outlier threshold takes an empirical value of 0.7.
[0081] The control process of the outlier servers is as follows:
[0082] (1) Quickly disconnect the Internet or intranet connection: Immediately close the server network port or physical network card to prevent attackers from continuously penetrating and laterally moving; Pause external services: Stop allocating traffic to this server through the load balancer or gateway to avoid affecting the user experience. (2) Isolate the attacked node: Remove the attacked server from the edge cluster to prevent the attack from spreading to other nodes; Limit the access scope: Only allow the operation and maintenance IP to access the management port through the firewall policy to block unauthorized connections. (3) Enable the dynamic protection mechanism: Use the edge firewall or dedicated device to identify and intercept malicious traffic, and only allow legitimate requests to pass through; Enable the intrusion detection system: Monitor abnormal access behaviors such as high-frequency requests and unconventional protocols in real time, and automatically trigger blocking rules. (4) Strengthen the access control policy: Tighten identity authentication: Force the use of multi-factor authentication and reset all account passwords to avoid secondary intrusion caused by credential leakage; Close unnecessary ports and services: Disable unused remote management ports and redundant background services to minimize the attack surface.
[0083] So far, the present invention is completed.
[0084] Embodiment 2:
[0085] The present invention proposes a 5G communication server access control system. Please refer to Figure 2 , which shows the system structure diagram of a 5G communication server access control system provided by an embodiment of the present invention. The system includes:
[0086] The data acquisition module 510 is used to obtain the risk coefficients of different tags of each user accessing the server at each moment, as well as the network environment data of the server at each moment;
[0087] The edge allocation analysis module 520 is used to cluster the users accessing the server at each moment into different clusters; According to the risk coefficients of the tags of the users within each cluster at each moment, and the degree of influence of the tags of the users on the corresponding cluster, obtain the edge allocation weights of each cluster at each moment.
[0088] The server layer division module 530 is used to obtain the edge computing power allocation coefficients of each cluster at each moment according to the number of tags of the users within each cluster at each moment and the edge allocation weights; Use the edge allocation weights and edge computing power allocation coefficients of the clusters at each moment to divide the servers accessed by the users at each moment into different layers;
[0089] The access control module 540 is used to select abnormal servers for control from the servers accessed by the users at each moment according to the network environment data and the layer differences between each server and the other servers.
[0090] It should be noted that: For the device provided in the above embodiments, only the division of the above functional modules is used for illustration. In actual applications, the above functions can be allocated to different functional modules as needed, that is, the internal structure of the computer device is divided into different functional modules to complete all or part of the functions described above. In addition, a 5G communication server access control system and a 5G communication server access control method provided in the above embodiments belong to the same concept. For the specific implementation process, please refer to the method embodiments and will not be elaborated here.
[0091] Embodiment 3:
[0092] Figure 3 It is a schematic diagram of a computer device of a 5G communication server access control device provided by an embodiment of the present invention. Exemplarily, as Figure 3 shown, the computer device includes: a memory 601, a processor 602, and a computer program 603 stored in the memory 601 and running on the processor 602. When the processor 602 executes the computer program 603, the computer device can execute any one of the 5G communication server access control methods introduced above.
[0093] In addition, an embodiment of the present application also protects a device, which may include a memory and a processor. Among them, an executable program code is stored in the memory, and the processor is used to call and execute the executable program code to execute a 5G communication server access control method provided by an embodiment of the present application.
[0094] In this embodiment, the functions of the device can be divided according to the above method examples. For example, each function module can be corresponded, or two or more functions can be integrated into one processing module. The above integrated module can be implemented in the form of hardware. It should be noted that the division of modules in this embodiment is illustrative, only a logical function division, and there may be other division methods in actual implementation.
[0095] It should be understood that the device provided in this embodiment is used to execute the above 5G communication server access control method, so the same effect as the above implementation method can be achieved.
[0096] In the case of adopting an integrated unit, the device may include a processing module and a storage module. Among them, when the device is applied to a device, the processing module can be used to control and manage the actions of the device. The storage module can be used to support the device to execute mutual program codes, etc.
[0097] Among them, the processing module can be a processor or a controller, which can implement or execute various exemplary logical blocks, modules, and circuits included in combination with the disclosure of this application. The processor can also be a combination that implements computing functions, such as including a combination of one or more microprocessors, a combination of digital signal processing (DSP) and a microprocessor, etc. The storage module can be a memory.
[0098] It should be noted that the above sequence of embodiments of the present invention is only for description and does not represent the superiority or inferiority of the embodiments. The processes depicted in the drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0099] Each embodiment in this specification is described in a progressive manner. The same or similar parts among the embodiments can be referred to each other, and the differences between each embodiment and other embodiments are emphasized.
[0100] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the principles of the present invention shall be included in the protection scope of the present invention.
Claims
1. A 5G communication server access control method, characterized in that, The method includes: Obtaining the risk coefficients of different tags of each user accessing the server at each moment, and the network environment data of the server at each moment; Clustering the users accessing the server at each moment into different clusters; obtaining the marginal allocation weights of each cluster at each moment according to the risk coefficients of the tags of the users within each cluster at each moment and the degree of influence of the tags of the users on the corresponding cluster; Obtaining the marginal computing power allocation coefficients of each cluster at each moment according to the number of tags of the users within each cluster at each moment and the marginal allocation weights; using the marginal allocation weights and the marginal computing power allocation coefficients of the clusters at each moment to divide the servers accessed by the users at each moment into different levels; Selecting abnormal servers for control from the servers accessed by the users at each moment according to the network environment data and the level differences between each server and the other servers.
2. The access control method for a 5G communication server according to claim 1, wherein The clustering of the users accessing the server at each moment into different clusters includes: Taking the sum of the risk coefficients of all tags of each user at each moment as the portrait factor of each user at each moment; clustering the users accessing the server at the same moment based on the portrait factor to obtain the clusters at each moment.
3. A 5G communication server access control method according to claim 2, characterized in that, The obtaining of the marginal allocation weights of each cluster at each moment includes: Respectively denoting the variance of the risk coefficients of the same tag of all users within each cluster at each moment as the within-cluster variance of the corresponding cluster of each tag, and denoting the variance of the risk coefficients of the same tag of all users within all clusters at each moment as the global variance of each tag; taking the ratio of the global variance to the within-cluster variance as the clustering influence degree of each tag on each cluster at each moment; selecting the largest N clustering influence degrees corresponding tags from all the clustering influence degrees of each tag on each cluster at each moment, and denoting them as the influence tags of each cluster at each moment; Selecting the effective tags of each user at each moment based on the risk coefficients; counting the number of effective tags that are the same as the influence tags among the effective tags of all users within each cluster at each moment, and denoting it as the tag influence degree of the corresponding cluster; Obtaining the marginal allocation weights of the corresponding clusters according to the mean value of the portrait factors of all users within each cluster of each user, the number of tag types of all users, and the tag influence degree.
4. A 5G communication server access control method according to claim 1, characterized in that, The obtaining of the marginal computing power allocation coefficients of each cluster at each moment includes: Taking the ratio of the number of tag types of the users within each cluster at each moment to the maximum value of the number of tag types of the users within all clusters at each moment as the proportion of each cluster at each moment; Obtaining the marginal computing power allocation coefficients of the corresponding clusters according to the marginal allocation weights and the proportion of each cluster at each moment.
5. A 5G communication server access control method according to claim 1, characterized in that, The dividing of the servers accessed by the users at each moment into different levels includes: Forming an analysis set from the marginal allocation weights of all clusters at each moment; Select the maximum edge allocation weight in the analysis set as the initial analysis value. Take the servers accessed by the users within the corresponding cluster of the analysis value at each moment as the first-level servers at each moment. Delete the analysis value from the analysis set and update the analysis set. Use the gradient descent method to select the edge allocation weight closest to the analysis value from the updated analysis set, denoted as the new analysis value. Take the servers accessed by the users within the corresponding cluster of the new analysis value at each moment as the second-level servers at each moment. Delete the new analysis value from the updated analysis set and update the analysis set. And so on until the updated analysis set is an empty set.
6. A 5G communication server access control method according to claim 1, characterized in that, The selection of abnormal servers from the servers accessed by the users at each moment includes: The network environment data includes access frequency and network load. Take the product of the access frequency and network load of each server at each moment as the state value of each server at each moment. For the servers accessed by the users at each moment, arbitrarily select a server as the analysis server. Perform negative correlation and normalization processing on the level difference between the level where the analysis server is located and the remaining levels except the level where the analysis server is located to obtain the level weight. According to the level weight, perform weighted summation on the absolute value of the difference between the state value of the analysis server at each moment and the mean value of the state values of all servers at each moment in the remaining levels except the level where the analysis server is located to obtain the neighborhood state difference of the analysis server at each moment. Take the sum of the state value of the analysis server at each moment and the neighborhood state difference as the anomaly value of the analysis server at each moment. Select the servers greater than the preset anomaly threshold from the servers accessed by the users at each moment as the abnormal servers at each moment.
7. A 5G communication server access control method according to claim 3, characterized in that, The mean value of the portrait factors of all users within the cluster has a positive correlation with the number of label types of all users and the edge allocation weight, and the label influence degree has a negative correlation with the edge allocation weight.
8. A 5G communication server access control method according to claim 2, characterized in that, The method for clustering the users accessing the servers at the same moment is the hierarchical clustering algorithm.
9. A 5G communication server access control method according to claim 6, characterized in that, The preset anomaly threshold is 0.
7.
10. A 5G communication server access control system, characterized in that, The system includes: A data acquisition module for obtaining the risk coefficients of different labels of each user accessing the server at each moment, and the network environment data of the server at each moment. An edge allocation analysis module for clustering the users accessing the server at each moment into different clusters; obtaining the edge allocation weight of each cluster at each moment according to the risk coefficients of the labels of the users within each cluster at each moment and the influence degree of the labels of the corresponding cluster on the users. A server level division module for obtaining the edge computing power allocation coefficient of each cluster at each moment according to the number of labels of the users within each cluster at each moment and the edge allocation weight; using the edge allocation weight and the edge computing power allocation coefficient of the cluster at each moment to divide the servers accessed by the users at each moment into different levels. An access control module, which is used to select abnormal servers for control from the servers accessed by a user at each moment according to the network environment data and the differences in the levels of each server and the remaining servers.
Citation Information
Patent Citations
Method to personalize workspace experience based on user's available time
CN114008646A
Network request processing method and device and electronic equipment
CN114285901A
Server access monitoring method based on artificial intelligence
CN118157983A
Internet of Things information security access control method and system
CN119767307A