Communication signaling storm interception method and device and computer program product
Through a neural architecture search framework based on photonic hardware perception and a customized detection model generated by spatiotemporal topology graphs, combined with adversarial contrastive learning and Beidou spatiotemporal stamps, the problems of missed reports and false alarms in 5G signaling storm detection are solved, achieving high-precision real-time interception.
Patent Information
- Application Number
- CN202510667216.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-22
- Publication Date
- 2025-09-12
AI Technical Summary
Existing 5G signaling storm detection technology has a missed alarm rate of up to 42% and a false alarm rate of over 5.2%. It is difficult to meet the real-time requirements of specific scenarios and cannot effectively intercept cross-protocol layer collaborative attacks and AI adversarial sample attacks.
A customized detection model based on a neural architecture search framework based on photonic hardware perception and space-time topology map generation is adopted. Through adversarial contrastive learning, perturbed signaling samples are injected, and a self-supervisory signal is constructed in combination with Beidou space-time stamps to achieve high-precision real-time detection of signaling storm attacks, and trigger signaling obfuscation strategies or slice service quality degradation strategies for interception.
It improves the accuracy and real-time performance of signaling storm detection, reduces the missed alarm rate and false alarm rate, realizes the effective interception of communication signaling storms, and ensures the stable operation, security and reliability of the communication network.
Smart Images

Figure CN120640296A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communication network technology, and in particular to a communication signaling storm interception method, device and computer program product. Background Art
[0002] With the deep penetration of 5G networks into high-value scenarios such as the Industrial Internet and the Internet of Vehicles, signaling storm attacks have evolved from traditional flooding attacks to a new threat that combines cross-protocol layer coordinated attacks with AI adversarial attack patterns. Mainstream technologies for 5G signaling storm detection fall into two categories: one based on static rule-based threshold determination, but with a high false negative rate of 42% for covert attacks; the other based on deep learning dynamic models, but due to the fragmentation of cross-protocol features and the inconsistency of hardware heterogeneity, they are difficult to implement in practice, resulting in a false positive rate exceeding 5.2% and an end-to-end latency standard deviation of 2.1ms, which cannot meet the stringent requirements of specific scenarios.
[0003] Therefore, how to improve the accuracy and real-time performance of communication signaling storm detection, reduce the missed alarm rate and false alarm rate, and intercept the communication signaling storm has become an urgent problem to be solved in this application.
[0004] The above content is only used to assist in understanding the technical solution of this application and does not constitute an admission that the above content is prior art. Summary of the Invention
[0005] The main purpose of this application is to provide a communication signaling storm interception method, device and computer program product, aiming to improve the accuracy and real-time performance of communication signaling storm detection, reduce the missed alarm rate and false alarm rate, and achieve interception of communication signaling storms.
[0006] To achieve the above objectives, the present application proposes a communication signaling storm interception method, the method comprising:
[0007] Load a pre-built customized detection model and use it to infer the signaling flow of the communication network interface to obtain the signaling storm attack probability. The customized detection model is generated based on the photonic hardware-aware neural architecture search framework and spatiotemporal topology graph. The training process of the customized detection model injects perturbed signaling samples through adversarial contrastive learning and constructs a self-supervised signal in combination with Beidou spatiotemporal stamps.
[0008] According to the signaling storm attack probability, the signaling confusion strategy and / or slice service quality degradation strategy are triggered to intercept the communication signaling storm.
[0009] In one embodiment, before the step of loading a pre-built customized detection model and using the customized detection model to perform reasoning on the signaling flow of the network interface to obtain the signaling storm attack probability, the step further includes:
[0010] Collecting sample signaling data packets from the communication network interface, and performing preprocessing, feature dimensionality reduction, and cross-protocol feature alignment on the sample signaling data packets to obtain a cross-protocol spatiotemporal correlation feature vector;
[0011] Based on the multi-wavelength modulation characteristics of the silicon photonic matrix multiplier, the cross-protocol spatiotemporal correlation feature vector is encoded into a spatiotemporal topology graph driven by photon interference;
[0012] Inputting complexity parameters and hardware performance parameters of the spatiotemporal topology graph into a neural architecture search framework based on photonic hardware perception to generate candidate models;
[0013] Injecting perturbation signaling samples for adversarial contrastive learning, generating a self-supervisory signal in combination with BeiDou space-time stamps, and training the candidate model based on the perturbation signaling samples and the self-supervisory signal;
[0014] The proximal strategy optimization algorithm is started to adjust the search strategy, and a candidate model whose model structure parameters meet the preset conditions is selected from the trained candidate model structures according to the search strategy to obtain a customized detection model.
[0015] In one embodiment, the step of collecting sample signaling data packets from the communication network interface, and performing preprocessing, feature dimensionality reduction, and cross-protocol feature alignment on the sample signaling data packets to obtain a cross-protocol spatiotemporal correlation feature vector includes:
[0016] Collecting sample signaling data packets from the communication network interface, extracting key information fields from the sample signaling data packets according to a signaling format definition, and performing digital encoding and standardization processing on the key information fields to obtain a high-dimensional feature vector;
[0017] Using a distributed random neighborhood embedding algorithm to reduce the dimensionality of the high-dimensional feature vector to obtain a low-dimensional feature vector;
[0018] Converting geographic coordinates into one-dimensional index values through a curve mapping algorithm, and mapping the one-dimensional index values into a low-dimensional vector space to generate a geographic information feature vector;
[0019] Extracting a signaling timestamp of the sample signaling data packet, and encoding the signaling timestamp into a time vector;
[0020] Fusing the time vector and the geographic information feature vector to obtain a spatiotemporal position coding vector;
[0021] The spatiotemporal position encoding vector is embedded in the low-dimensional feature vector to obtain a cross-protocol spatiotemporal correlation feature vector.
[0022] In one embodiment, the step of encoding the cross-protocol spatiotemporal correlation feature vector into a photon interference-driven spatiotemporal topology map based on the multi-wavelength modulation characteristics of the silicon photonic matrix multiplier includes:
[0023] dividing the fast protocol spatiotemporal correlation feature vector into a NAS layer feature subvector and an NGAP layer feature subvector;
[0024] Based on the multi-wavelength modulation characteristics of the silicon photonic matrix multiplier, optical signals of different wavelengths are modulated to encode the NAS layer characteristic subvector and the NGAP layer characteristic subvector respectively, so as to obtain a NAS layer characteristic optical signal and an NGAP layer characteristic optical signal;
[0025] The NAS layer characteristic light signal and the NGAP layer characteristic light signal are coupled to a photon interference array to obtain a light intensity distribution value after interference, and a spatiotemporal topology map is generated based on the light intensity distribution value.
[0026] In one embodiment, the step of loading a pre-built customized detection model and performing reasoning on a signaling flow of a communication network interface using the customized detection model includes:
[0027] Loading a pre-built customized detection model from a storage device to a memory device, wherein the customized detection model is adapted to the target hardware;
[0028] The parallel computing unit of the target hardware is used to process the signaling data segments of the real-time signaling flow in parallel, and the signaling data segments are input into the customized detection model for millisecond-level reasoning to obtain the signaling storm attack probability.
[0029] In one embodiment, the step of triggering a signaling obfuscation strategy and / or a slice service quality degradation strategy to intercept a communication signaling storm according to the signaling storm attack probability includes:
[0030] When the signaling storm attack probability exceeds a preset threshold, triggering a signaling confusion strategy and / or a slice service quality degradation strategy, and determining the attacked signaling data based on the signaling storm attack probability;
[0031] Randomly changing the field value of the attacked signaling data based on the signaling obfuscation strategy to intercept the communication signaling storm; and / or
[0032] Based on the slice service quality degradation strategy, the slice service quality of the attacked signaling data is reduced to intercept the communication signaling storm.
[0033] In one embodiment, after the step of triggering a signaling obfuscation strategy and / or a slice service quality degradation strategy according to the signaling storm attack probability to intercept a communication signaling storm, the step further includes:
[0034] Calculate the hash value of the attacked signaling data according to the hash algorithm, and obtain the time and space stamp of the attacked signaling data;
[0035] The hash value and the timestamp are stored in the blockchain.
[0036] In one embodiment, after the step of triggering a signaling obfuscation strategy and / or a slice service quality degradation strategy according to the signaling storm attack probability to intercept a communication signaling storm, the step further includes:
[0037] Based on differential privacy technology, noise data that follows the Laplace distribution is added to the signaling metadata for desensitization.
[0038] In addition, to achieve the above-mentioned purpose, the present application also proposes a communication signaling storm interception device, which includes:
[0039] A detection module is used to load a pre-built customized detection model and use it to infer the signaling flow of the communication network interface to obtain the probability of a signaling storm attack. The customized detection model is generated based on a neural architecture search framework and spatiotemporal topology graph based on photonic hardware perception. The customized detection model is trained by injecting perturbed signaling samples through adversarial contrastive learning and constructing a self-supervised signal in combination with Beidou spatiotemporal stamps.
[0040] A response module is used to trigger a signaling confusion strategy and / or a slice service quality degradation strategy to intercept communication signaling storms based on the signaling storm attack probability.
[0041] In addition, to achieve the above-mentioned purpose, the present application also provides a computer program product, which includes a computer program, and when the computer program is executed by a processor, it implements the steps of the communication signaling storm interception method as described above.
[0042] One or more technical solutions proposed in this application have at least the following technical effects:
[0043] First, the spatiotemporal topology map enables dynamic cross-layer correlation of protocol fields. Furthermore, the introduced photonic hardware-aware neural architecture search framework enables real-time optimization of model structures. Consequently, the customized detection model generated based on the photonic hardware-aware neural architecture search framework and the spatiotemporal topology map improves the accuracy of signaling data slice hijacking attack detection, compresses the standard deviation of inference latency, and thus enhances the real-time performance of communication signaling storm detection. Furthermore, the customized detection model's training process injects perturbed signaling samples through adversarial contrastive learning and constructs a self-supervised signal based on BeiDou spatiotemporal stamps. This allows the trained model to effectively reduce the bypass rate of generative attacks while maintaining high-precision detection of communication signaling storms. Furthermore, signaling obfuscation strategies and / or slice quality of service degradation strategies are triggered based on the signaling storm attack probability to intercept communication signaling storms. These strategies effectively intercept and defend against communication signaling storm attacks, ensuring the stable operation, security, and reliability of the communication network. To summarize, this application introduces a neural architecture search framework for photonic hardware perception through a spatiotemporal topological map, injects perturbed signaling samples through adversarial contrastive learning during the training of a customized detection model, and combines the Beidou spatiotemporal stamp to construct a self-supervisory signal. The resulting customized detection model can improve the accuracy and real-time performance of communication signaling storm detection, reduce the missed alarm rate and false alarm rate, and thus achieve interception of communication signaling storms. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.
[0045] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0046] Figure 1 A flowchart of the first embodiment of the communication signaling storm interception method provided in this application;
[0047] Figure 2 A flowchart of the second embodiment of the communication signaling storm interception method provided in this application;
[0048] Figure 3 A flowchart of the third embodiment of the communication signaling storm interception method provided in this application;
[0049] Figure 4 A flowchart of the fourth embodiment of the communication signaling storm interception method provided in this application;
[0050] Figure 5 This is a schematic diagram of the overall process of the communication signaling storm interception method for this application;
[0051] Figure 6 This is a schematic diagram of the module structure of the communication signaling storm interception device according to an embodiment of the present application;
[0052] Figure 7 This is a schematic diagram of the device structure of the hardware operating environment involved in the communication signaling storm interception method in the embodiment of the present application.
[0053] The purpose, features and advantages of this application will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. DETAILED DESCRIPTION
[0054] It should be understood that the specific embodiments described herein are merely used to explain the technical solutions of the present application and are not intended to limit the present application.
[0055] In order to better understand the technical solution of the present application, a detailed description will be given below in conjunction with the accompanying drawings and specific implementation methods.
[0056] The embodiments of this application take into account that, as 5G networks penetrate deeper into high-value scenarios such as the Industrial Internet and the Internet of Vehicles, signaling storm attacks have evolved from traditional flooding attacks to a new threat that combines cross-protocol layer coordinated attacks with AI adversarial sample attacks. Mainstream technologies for detecting 5G signaling storms fall into two categories: one is based on static rule-based threshold determination, but its false negative rate for covert attacks is as high as 42%. The other is based on dynamic models based on deep learning, but due to the fragmentation of cross-protocol features and the conflict with hardware heterogeneity, it is difficult to implement in practice, resulting in a false positive rate exceeding 5.2% and an end-to-end latency standard deviation of 2.1ms, which cannot meet the strict requirements of specific scenarios.
[0057] Therefore, the present application provides a solution. First, the spatiotemporal topology map realizes the cross-layer dynamic association of protocol fields. The introduced photonic hardware-aware neural architecture search framework can optimize the model structure in real time. Therefore, the customized detection model generated based on the photonic hardware-aware neural architecture search framework and the spatiotemporal topology map improves the accuracy of signaling data slice hijacking attack detection, compresses the standard deviation of inference delay, and thus improves the real-time performance of communication signaling storm detection. The training process of the customized detection model injects perturbed signaling samples through adversarial contrast learning, and combines the Beidou spatiotemporal stamp to construct a self-supervisory signal, so that the trained model effectively reduces the bypass rate of generative attacks while still maintaining high-precision detection of communication signaling storms. According to the signaling storm attack probability, the signaling obfuscation strategy and / or the slice service quality degradation strategy are triggered to intercept the communication signaling storm. The signaling obfuscation strategy and / or the slice service quality degradation strategy are used to effectively intercept and defend against the communication signaling storm attack, thereby ensuring the stable operation, security and reliability of the communication network. This application introduces a photonic hardware-aware neural architecture search framework through a spatiotemporal topological map, injects perturbed signaling samples through adversarial contrast learning during the training of a customized detection model, and combines the Beidou spatiotemporal stamp to construct a self-supervisory signal. The resulting customized detection model can improve the accuracy and real-time performance of communication signaling storm detection, reduce the missed alarm rate and false alarm rate, and thus achieve interception of communication signaling storms.
[0058] Based on this, the embodiment of the present application provides a communication signaling storm interception method, referring to Figure 1 , Figure 1 This is a flow chart of the first embodiment of the communication signaling storm interception method of this application.
[0059] In this embodiment, the communication signaling storm interception method includes steps S10 to S20:
[0060] Step S10: Load a pre-built customized detection model and use the customized detection model to perform inference on the signaling flow of the communication network interface to obtain the signaling storm attack probability, wherein the customized detection model is generated based on the neural architecture search framework and spatiotemporal topology graph of photonic hardware perception. The training process of the customized detection model injects perturbed signaling samples through adversarial contrastive learning and constructs a self-supervised signal in combination with the Beidou spatiotemporal stamp.
[0061] Loading a pre-built customized detection model refers to loading a model that has been trained and adapted to the target hardware from a storage device to a memory device so that it can be called in real time. The customized detection model is generated based on a photonic hardware-aware neural architecture search framework and a spatiotemporal topology map. The photonic hardware-aware neural architecture search framework refers to a framework that can dynamically adjust the model structure according to the performance parameters of the target hardware. Its purpose is to generate customized models that adapt to hardware such as FPGA (Field-Programmable Gate Array) and ASIC (Application-Specific Integrated Circuit). The spatiotemporal topology map refers to the encoding of the signaling stream into a photon interference-driven graph through the multi-wavelength modulation characteristics of the silicon photonic matrix multiplier, which is used to realize cross-layer dynamic association of protocol fields.
[0062] The training process of the customized detection model injects perturbed signaling samples through adversarial contrastive learning and combines them with BeiDou time-space stamps to construct self-supervisory signals. Perturbed signaling samples, such as compliant attack flows generated by Projected Gradient Descent (PGD), are used to provide the model with precise temporal and spatial information. The self-supervisory signal is a supervisory signal generated by the model through its own input-output relationship, which guides model training and optimization. The training and optimization of the customized detection model enables millisecond-level inference on real-time signaling flows of 5G network interfaces in practical applications, determining the probability of signaling storm attacks, improving detection accuracy and real-time performance, and effectively addressing new signaling storm attacks.
[0063] Step S20: trigger the signaling confusion strategy and / or slice service quality degradation strategy to intercept the communication signaling storm according to the signaling storm attack probability.
[0064] The signaling storm attack probability refers to the likelihood that the current signaling flow is vulnerable to a signaling storm attack, as determined by the standardized detection model's inference of real-time signaling flows. The signaling obfuscation strategy involves randomly changing the values of some fields in the signaling to interfere with the attacker, making it difficult for them to identify the true signaling intent. The slice service quality degradation strategy involves reducing the service quality of the attacked slice according to the slice management provisions of the 3GPP (3rd Generation Partnership Project) agreement.
[0065] The thresholds for triggering signaling obfuscation and slice QoS degradation policies can be set based on actual needs. When the attack probability exceeds this threshold, the corresponding defense policy is triggered. Signaling obfuscation is implemented by randomly changing the values of certain identification fields in the signaling while ensuring that the signaling format still complies with the protocol specification. The degradation coefficient of the slice QoS degradation policy can be dynamically adjusted based on the severity of the attack, ensuring the normal operation of core network services while avoiding unnecessary impacts caused by excessive degradation.
[0066] This embodiment provides a method for intercepting communication signaling storms. First, the spatiotemporal topology map realizes the dynamic cross-layer association of protocol fields. Furthermore, the introduced photonic hardware-aware neural architecture search framework can optimize the model structure in real time. Therefore, the customized detection model generated based on the photonic hardware-aware neural architecture search framework and the spatiotemporal topology map improves the accuracy of signaling data slice hijacking attack detection, compresses the standard deviation of inference delay, and thus improves the real-time performance of communication signaling storm detection. Furthermore, the training process of the customized detection model injects perturbed signaling samples through adversarial contrastive learning and combines the Beidou spatiotemporal stamp to construct a self-supervised signal. This allows the trained model to effectively reduce the bypass rate of generative attacks while still maintaining high-precision detection of communication signaling storms. Furthermore, based on the signaling storm attack probability, a signaling obfuscation strategy and / or a slice service quality degradation strategy is triggered to intercept the communication signaling storm. The signaling obfuscation strategy and / or the slice service quality degradation strategy effectively intercept and defend against the communication signaling storm attack, ensuring the stable operation, security and reliability of the communication network. To summarize, this application introduces a neural architecture search framework for photonic hardware perception through a spatiotemporal topological graph, injects perturbed signaling samples through adversarial contrastive learning during the training process of a customized detection model, and combines the Beidou space-time stamp to construct a self-supervisory signal. The resulting customized detection model can improve the accuracy and real-time performance of communication signaling storm detection, reduce the missed alarm rate and false alarm rate, and thereby achieve interception of communication signaling storms.
[0067] In a feasible implementation, step S10 may include steps S11 to S12:
[0068] Step S11, loading a pre-built customized detection model from a storage device to a memory device, wherein the customized detection model is adapted to the target hardware;
[0069] Customized detection model adaptation to target hardware means that the model is optimized based on the performance parameters of the target hardware (such as FPGA, ASIC, etc.) (such as the number of logic units and computing frequency of FPGA, transistor density and power consumption of ASIC, etc.), which can give full play to the performance advantages of the hardware, so that the customized detection model can run efficiently on the target hardware and provide support for the detection of real-time signaling flows.
[0070] For models running on ASIC chips, the high-speed data transmission channels within the chip are used to quickly transfer model parameters to the chip's internal cache, ensuring rapid access to model parameters and supporting real-time inference. Specifically, during the loading process, model parameters are integrity checked to prevent errors or loss during transmission.
[0071] Step S12: utilizing the parallel computing unit of the target hardware to process the signaling data segments of the real-time signaling flow in parallel, inputting the signaling data segments into the customized detection model for millisecond-level reasoning, and obtaining the signaling storm attack probability.
[0072] Using the parallel computing units of the target hardware to parallel process the signaling data segments of the real-time signaling stream refers to using the parallel computing units in the target hardware (such as FPGA, ASIC, etc.) to efficiently process the real-time signaling stream. A parallel computing unit refers to a unit in the hardware that can execute multiple computing tasks simultaneously, such as a logic unit in an FPGA and a dedicated computing circuit in an ASIC. Signaling data segments refer to dividing the real-time signaling stream into multiple small data blocks for processing, so that the parallel computing units can perform efficient processing. The signaling data segments are input into the customized detection model, and the signaling storm attack probability is obtained through the inference calculation of the model.
[0073] The processing of real-time signaling streams involves preprocessing signaling data segments, feature extraction, and model inference. Preprocessing can include format conversion and normalization to ensure that the signaling data segments meet model input requirements. The feature extraction step extracts key feature vectors from the signaling data segments based on the needs of the customized detection model, enabling the model to accurately perform inference. Using the parameters and structure of the customized detection model, the input feature vectors are calculated to determine the probability of a signaling storm attack.
[0074] When utilizing the target hardware's parallel computing units for processing, both data parallelism and model parallelism can be employed. Data parallelism involves assigning different signaling data segments to different parallel computing units for processing, with each unit independently performing inference calculations on its assigned data. Model parallelism involves assigning different parts of a customized detection model to different parallel computing units for processing, with each unit responsible for calculating a specific portion of the model. The results from each part are then aggregated to produce the final attack probability.
[0075] In a feasible implementation, step S20 may include steps S21 to S23:
[0076] Step S21: When the signaling storm attack probability exceeds a preset threshold, triggering a signaling obfuscation strategy and / or a slice service quality degradation strategy, and determining the attacked signaling data based on the signaling storm attack probability;
[0077] When the signaling storm attack probability exceeds the preset threshold, the signaling obfuscation strategy and / or slice service quality degradation strategy are triggered, and the attacked signaling data is determined based on the signaling storm attack probability. The preset threshold is a judgment standard set according to actual needs and is used to decide whether to activate the defense strategy.
[0078] For example, the customized model calculates the detection probability p of a signaling storm attack based on the characteristics of the input signaling flow through an internal algorithm. attack , when a signaling storm attack p is detected attack When ≥0.93, signaling confusion or slice QoS degradation policy is triggered.
[0079] Step S22: randomly changing the field value of the attacked signaling data based on the signaling obfuscation strategy to intercept the communication signaling storm;
[0080] A field value refers to the content of a specific field in signaling data, such as the source address, destination address, port number, etc. Randomly changing field values can be done in a variety of ways, such as random number generation and pseudo-random number generation. By changing the characteristics of the attacked signaling data so that it no longer conforms to the attack pattern, the purpose of intercepting signaling storm attacks is achieved. When implementing a signaling obfuscation strategy, it should be ensured that the changed field values still comply with the protocol specifications to avoid affecting normal communications. A set of legal field value ranges can be pre-defined based on the rules and requirements of the signaling protocol. When changing a field value, a value within this range is randomly selected for replacement. In addition, the method of changing field values can be optimized for different attack types and signaling characteristics to improve interception effectiveness.
[0081] For example, when p attack When the value is ≥0.93, the signaling obfuscation strategy is triggered. Signaling obfuscation is achieved by randomly changing the values of some fields in the signaling while ensuring that the signaling format still complies with the protocol specifications. Randomly changing the values of certain identification fields in the signaling makes it difficult for attackers to identify the true signaling intent, effectively disrupting attack behavior.
[0082] Step S23: based on the slice service quality degradation strategy, reduce the slice service quality of the attacked signaling data to intercept the communication signaling storm.
[0083] Slice service quality refers to the level of service provided by a network slice, typically including metrics such as bandwidth, latency, and packet loss rate. Slice service quality can be reduced in various ways, such as reducing bandwidth allocation and increasing latency. This approach limits the propagation and impact of attacked signaling data, thereby ensuring the normal operation of core network services. When implementing a slice service quality degradation strategy, the impact on normal services should be minimized. The service quality of different slices can be differentiated based on the importance and priority of the services. For example, for critical service slices, maintain high service quality; while for attacked slices, appropriately reduce the service quality. Furthermore, the intensity of the degradation strategy can be dynamically adjusted based on the severity of the signaling storm attack to achieve optimal interception effectiveness.
[0084] For example, for the slice QoS (Quality of Service) degradation strategy, the service quality level of the attacked slice is reduced according to the provisions of the slice management in the 3GPP protocol. For example, the bandwidth resources available to the slice are reduced. The formula is expressed as: B new =B old ×(1-α)
[0085] Among them, B old is the original bandwidth of the slice, B new is the bandwidth after degradation, and α is the degradation coefficient, which can be dynamically adjusted based on the severity of the attack. By reducing the QoS of the attacked slice, the scope of the attack is limited, ensuring the normal operation of core network services while avoiding unnecessary impact on normal services caused by excessive degradation.
[0086] Based on the first embodiment of the present application, the second embodiment of the present application is proposed. In the second embodiment of the present application, the same or similar contents as those of the first embodiment can be referred to the above introduction and will not be repeated hereafter.
[0087] On this basis, please refer to Figure 2 , Figure 2 A flow chart of the second embodiment of the communication signaling storm interception method provided in this application.
[0088] In this embodiment, before step S10, the communication signaling storm interception method further includes steps S01 to S05:
[0089] Step S01, collecting sample signaling data packets from the communication network interface, and performing preprocessing, feature dimensionality reduction, and cross-protocol feature alignment on the sample signaling data packets to obtain a cross-protocol spatiotemporal correlation feature vector;
[0090] Preprocessing involves preliminary cleaning and format conversion of the collected raw signaling data to remove noise and erroneous data. Feature dimensionality reduction involves mapping high-dimensional signaling feature vectors to a low-dimensional space using the t-SNE (t-Distributed Stochastic Neighbor Embedding) algorithm to reduce data dimensionality while retaining key feature information. Cross-protocol feature alignment involves using a specific algorithm (based on Hilbert curve mapping and spatiotemporal position encoding) to uniformly process signaling features from different protocol layers, aligning them in spatial and temporal dimensions to generate cross-protocol spatiotemporal correlation feature vectors.
[0091] Sample signaling data packets can be collected by deploying data collection equipment at 5G base stations and key nodes at the core network edge. These devices are equipped with network interface cards that support 5G network interface standards and can establish stable communication links with corresponding interfaces according to the interface specifications in the 3GPP protocol stack. During the preprocessing phase, various methods are used to cleanse the data, such as removing duplicate data and filling missing values. Feature dimensionality reduction aims to reduce computational complexity and improve the efficiency of model training and inference. Cross-protocol feature alignment integrates signaling information from different protocol layers to enhance the model's ability to identify signaling storm attacks.
[0092] Step S02: encoding the cross-protocol spatiotemporal correlation feature vector into a spatiotemporal topology graph driven by photon interference based on the multi-wavelength modulation characteristics of the silicon photonic matrix multiplier;
[0093] A silicon photonic matrix multiplier (SiPM) is a photonic device that utilizes silicon photonics technology to perform matrix multiplication operations, enabling efficient optical signal processing. Multi-wavelength modulation allows SiPMs to modulate optical signals of different wavelengths to carry different information. The cross-protocol spatiotemporal correlation feature vector is a feature vector that has undergone preprocessing, feature dimensionality reduction, and cross-protocol feature alignment. It contains the protocol layer, spatial, and temporal information of the signaling. The encoding process converts the information in the feature vector into parameters such as the phase and amplitude of the optical signal. Multi-wavelength modulation is used to encode information from different protocol layers into optical signals of different wavelengths. The photon interference-driven spatiotemporal topology map is a graphical representation of the cross-protocol spatiotemporal correlation of the signaling, generated by interferometric processing of the encoded optical signal.
[0094] The multi-wavelength modulation capabilities of the silicon photonic matrix multiplier enable simultaneous processing of multiple optical signals of different wavelengths on the same device, each of which can carry information at different protocol layers. By precisely controlling the phase and amplitude of the optical signals, efficient encoding of signaling information is possible. The spatiotemporal topology map driven by photon interference can intuitively reflect the correlation between signaling at different protocol layers and in spatiotemporal dimensions, providing richer feature information for model training.
[0095] Step S03, inputting the complexity parameters and hardware performance parameters of the spatiotemporal topology graph into a neural architecture search framework based on photonic hardware perception to generate a candidate model;
[0096] The complexity parameters of a spatiotemporal topology graph refer to the number of nodes and edges in the graph, the complexity of the connectivity relationships, and other factors, reflecting the complexity of signaling across different protocol layers and spatiotemporal dimensions. Hardware performance parameters refer to the performance metrics of the target hardware (e.g., FPGA, ASIC, etc.), such as the number of logic units, computing frequency, transistor density, and power consumption.
[0097] Photonics' hardware-aware neural architecture search framework dynamically adjusts model structures based on hardware performance parameters, generating customized models tailored to different hardware. Candidate models refer to the multiple possible model structures generated within the neural architecture search framework. After further training and evaluation, the final customized detection model is obtained.
[0098] The complexity parameter of the spatiotemporal topological graph can be quantified in various ways, such as the number of nodes, the number of edges, and the average path length. Hardware performance parameters help the neural architecture search framework understand the capabilities and limitations of the target hardware, thereby generating model structures that are more suitable for running on the hardware.
[0099] Step S04: injecting disturbance signaling samples for adversarial contrastive learning, generating a self-supervisory signal in combination with BeiDou space-time stamps, and training the candidate model based on the disturbance signaling samples and the self-supervisory signal;
[0100] Perturbed signaling samples are generated through specific algorithms (such as the PGD algorithm) that are similar to real signaling samples but have different characteristics. They are used to simulate potential attack patterns. Beidou time-space stamping uses the precise time and space information provided by the Beidou satellite system to add time and space labels to each signaling sample. Self-supervisory signals are supervisory signals generated by the model through its own input-output relationship. They are used to guide model training and optimization, conduct adversarial training on candidate models, and enable them to better identify and resist signaling storm attacks. Self-supervisory signals are also used to improve the efficiency and effectiveness of model training.
[0101] Various methods can be used to generate perturbed signaling samples, such as gradient-based perturbation generation algorithms. The addition of BeiDou time and space stamps can help the model better understand the temporal and spatial characteristics of signaling samples, enhancing the model's ability to identify the spatiotemporal correlations of signaling storm attacks. Self-supervisory signal generation can be achieved through contrastive learning, which compares perturbed signaling samples with real signaling samples to learn their differences and similarities, thereby guiding model training.
[0102] In one possible implementation, the PGD algorithm is used to generate perturbed signaling samples and input them into the candidate model along with real signaling samples. Furthermore, BeiDou time and space stamps are used to accurately label each sample with time and space. Through comparative learning, the model learns the differences between the perturbed and real samples and generates self-supervisory signals. These self-supervisory signals are used to update the model's parameters, improving its ability to identify signaling storm attacks.
[0103] Step S05: start the proximal strategy optimization algorithm to adjust the search strategy, and select a candidate model whose model structure parameters meet preset conditions from the trained candidate model structures according to the search strategy to obtain a customized detection model.
[0104] The proximal strategy optimization algorithm is used to find the optimal model structure within the model structure search space. The search strategy refers to the methods and rules used during the search process, guiding the direction and scope of the search. Pre-conditions refer to model performance indicators set based on actual needs, such as accuracy, computational speed, and energy consumption. The optimization algorithm selects the best-performing model from among the trained candidate models as the final customized detection model to meet application requirements on specific hardware. Pre-conditions refer to model performance indicators set based on actual needs, such as accuracy, computational speed, energy consumption, and maximum number of searches.
[0105] The proximal strategy optimization algorithm balances exploration and exploitation during the search process, avoiding regression into local optimal solutions. By continuously adjusting the search strategy, it finds a model structure that meets the pre-defined conditions within the model structure search space. These pre-defined conditions can be flexibly configured based on the specific application scenario and hardware requirements.
[0106] In one possible implementation, a proximal policy optimization algorithm is initiated to explore the model structure search space. Based on the performance of trained candidate models, such as accuracy, computational speed, and energy consumption, the algorithm adjusts its search strategy and gradually converges to a model structure that meets preset conditions. These conditions may include a model accuracy exceeding 95% and an inference latency of less than 5ms.
[0107] In this embodiment, through precise feature vector construction, efficient photonic feature representation, hardware-adaptive model generation, robust model training, and final model optimization selection, while improving detection accuracy and real-time performance, the missed alarm rate and false alarm rate are effectively reduced, achieving reliable interception of 5G communication signaling storms.
[0108] In a feasible implementation, step S01 of collecting sample signaling data packets from the communication network interface, and performing preprocessing, feature dimensionality reduction, and cross-protocol feature alignment on the sample signaling data packets to obtain a cross-protocol spatiotemporal correlation feature vector may include steps A01 to A06:
[0109] Step A01: collecting sample signaling data packets from the communication network interface, extracting key information fields from the sample signaling data packets according to a signaling format definition, and performing digital encoding and standardization processing on the key information fields to obtain a high-dimensional feature vector;
[0110] The signaling format definition refers to the 3GPP protocol's specifications for the format and meaning of each field in a signaling packet. Key information fields include the 5G-GUTI (5G Globally Unique Temporary Identifier) and QFI (QoS Flow Identifier), which are crucial for detecting signaling storm attacks. A high-dimensional feature vector is a 256-dimensional feature vector obtained through numerical encoding and standardization, with each dimension corresponding to the processing result of a key information field.
[0111] Sample signaling data packets are collected by deploying data collection equipment at key nodes in the 5G network, such as base stations and the core network edge. Network interface cards (NICs) supporting 5G network interface standards are used to establish stable communication links with the corresponding N2 / N4 / N11 interfaces in the 3GPP protocol stack according to their specifications. Numerical encoding methods can be selected based on the type and meaning of the field, such as converting enumeration fields to one-hot encoding and normalizing integer fields. Standardization methods such as Z-score and Min-Max normalization can be used to ensure comparability of values across different fields.
[0112] The 5G-GUTI field has a clear byte offset and data format within the signaling packet. For example, in a specific signaling message type, the y-byte field starting from byte x is the 5G-GUTI field. By locating this location and parsing it according to the corresponding data format, its value can be accurately obtained. Similarly, according to the protocol specification, the QFI field is extracted according to specific encoding rules within the relevant QoS parameter subfields, providing key data for subsequent analysis of signaling characteristics at different quality of service levels.
[0113] Step A02, using a distributed random neighborhood embedding algorithm to reduce the dimension of the high-dimensional feature vector to obtain a low-dimensional feature vector;
[0114] The t-SNE algorithm is used to reduce the feature dimension from 256 to 32. Specifically, the t-SNE algorithm describes the similarity of data points by constructing the probability distribution between high-dimensional data points. First, the data point x in the high-dimensional space is calculated. i and x j The similarity probability p between ij , the formula is:
[0115]
[0116] Among them, ||x i -x j || 2 is the data point x i and x j The Euclidean distance between k Indicates that in the high-dimensional space except the current data point x i For all other data points except i is the data point x i The related bandwidth parameter controls the size of the neighborhood of data points.
[0117] Furthermore, a similar probability distribution q is constructed in the low-dimensional space ij , by minimizing the KL divergence:
[0118]
[0119] Among them, the data point x in the high-dimensional space i and x j The similarity probability between them is expressed as p ij , constructing a similar probability distribution in low-dimensional space is expressed as q ij , minimizing the KL divergence means minimizing the KL divergence of the probability distribution between data points in high-dimensional space and low-dimensional space.
[0120] This process effectively reduces the data dimension and computational complexity while preserving the data's key feature information to the greatest extent possible, allowing the data to maintain its original relative relationships in the low-dimensional space.
[0121] Step A03: converting geographic coordinates into one-dimensional index values using a curve mapping algorithm, and mapping the one-dimensional index values into a low-dimensional vector space to generate a geographic information feature vector;
[0122] Mapping geographic coordinates to low-dimensional vectors is done using the Hilbert curve. The Hilbert curve is a space-filling curve that can map points in a multidimensional space to a one-dimensional space. Specifically, for geographic coordinates (x, y), a specific Hilbert curve mapping algorithm is used to first convert the geographic coordinates into a one-dimensional index value h. Based on the fractal structure of the Hilbert curve, the curve mapping algorithm gradually maps the two-dimensional coordinates to a one-dimensional value. Once the one-dimensional index value h is obtained, h is then mapped to a low-dimensional vector space through a linear transformation, resulting in a geographic information feature vector, which is used to represent the characteristics of the geographic information.
[0123] For example, map h to a 32-dimensional vector v, vi =f(h,i), where f is a function that generates vector elements based on the Hilbert curve index value. In this way, geographic information is integrated into signaling features, facilitating unified processing and analysis of cross-protocol features and enhancing the correlation of signaling at different protocol layers in the spatial dimension.
[0124] Step A04: extracting the signaling timestamp of the sample signaling data packet and encoding the signaling timestamp into a time vector;
[0125] The signaling timestamp is the time when an event occurs in a sample signaling packet and can be expressed in Unix timestamp or a specific time format. The time vector is the conversion of the timestamp into a vector. The formula for encoding the signaling timestamp T into a time vector is as follows:
[0126]
[0127] Where T is the signaling timestamp, i represents the dimension index, d is the dimension of the encoding vector (here 32 dimensions), and t represents the encoded time vector.
[0128] Step A05: fusing the time vector and the geographic information feature vector to obtain a spatiotemporal position coding vector;
[0129] A spatiotemporal position encoding vector is a vector derived from the fusion of a time vector and a geographic information feature vector. It represents the temporal and spatial location information of signaling data. This process aims to combine time and geographic information to generate an encoding vector that reflects the spatiotemporal characteristics of signaling data, enhancing the model's ability to utilize these characteristics.
[0130] There are various fusion methods, such as direct concatenation and linear transformation. In this application, direct concatenation can be used to concatenate the time vector and the geographic information feature vector into a longer vector, which serves as the spatiotemporal position encoding vector. Alternatively, a linear transformation method can be used to fuse the time vector and the geographic information feature vector using a linear transformation matrix to generate a new spatiotemporal position encoding vector. The time vector t and the geographic information feature vector s are fused to obtain the spatiotemporal position encoding vector e, where e = s + t.
[0131] Step A06: embed the spatiotemporal position coding vector into the low-dimensional feature vector to obtain a cross-protocol spatiotemporal correlation feature vector.
[0132] Cross-protocol spatiotemporal correlation feature vectors are derived by combining the spatiotemporal position encoding vector with a low-dimensional feature vector. They represent the correlation characteristics of signaling data across different protocol layers and spatiotemporal dimensions. Combining spatiotemporal information with the protocol-layer characteristics of signaling generates feature vectors that reflect the cross-protocol spatiotemporal correlation of signaling data, enhancing the model's ability to identify signaling storm attacks.
[0133] In a feasible embodiment, based on the multi-wavelength modulation characteristics of the silicon photonic matrix multiplier, step S02 of encoding the cross-protocol spatiotemporal correlation feature vector into a spatiotemporal topology graph driven by photon interference may include steps B01 to B03:
[0134] Step B01, dividing the fast protocol spatiotemporal correlation feature vector into a NAS layer feature subvector and an NGAP layer feature subvector;
[0135] The NAS (Non-Access Stratum) layer feature subvector refers to the features related to the non-access layer of the 5G network, primarily involving functions such as mobility management and session management. The NGAP (Next Generation Application Protocol) layer feature subvector refers to the features related to the application layer of the 5G network, primarily involving signaling interactions between base stations and the core network.
[0136] It should also be noted that the division of cross-protocol spatiotemporal correlation feature vectors can be based on the field definitions and functional divisions of the protocol layers. For example, based on the 3GPP protocol's definition of NAS and NGAP signaling, it is determined which feature dimensions belong to the NAS layer and which to the NGAP layer. In practice, the division can be performed based on the semantic information of each dimension in the feature vector, ensuring that each feature sub-vector accurately reflects the characteristics of the corresponding protocol layer.
[0137] Step B02: Based on the multi-wavelength modulation characteristics of the silicon photonic matrix multiplier, modulate optical signals of different wavelengths to encode the NAS layer characteristic subvector and the NGAP layer characteristic subvector respectively, to obtain a NAS layer characteristic optical signal and an NGAP layer characteristic optical signal;
[0138] The multi-wavelength modulation capabilities of the silicon photonic matrix multiplier enable simultaneous processing of multiple optical signals of different wavelengths on the same device, each of which can carry information from different protocol layers. By precisely controlling the phase and amplitude of the optical signal, efficient encoding of signaling information is achieved. In practice, the appropriate wavelength for modulation is selected based on the dimensionality and information content of the characteristic subvector, ensuring that the optical signal accurately carries the characteristic information.
[0139] For example, for authentication information of the NAS layer characteristic subvector, an optical signal with a wavelength of λ1 is modulated. The authentication information is encoded by changing parameters such as the phase and amplitude of the optical signal. For example, different phase offsets are associated with authentication success or failure. For handover request information of the NGAP interface, an optical signal with a wavelength of λ2 is modulated and encoded, resulting in the NAS layer characteristic optical signal and the NGAP layer characteristic optical signal, respectively.
[0140] Step B03: coupling the NAS layer characteristic optical signal and the NGAP layer characteristic optical signal to a photon interference array to obtain a light intensity distribution after interference, and generating a spatiotemporal topology map based on the light intensity distribution.
[0141] The encoded multiple characteristic optical signals are coupled to the optical waveguide for transmission, where interference occurs. The spatiotemporal topology is generated based on the light intensity distribution obtained after interference. For example, for an n×n (n=16) photon interference array, the light intensity distribution after interference I ij It can be described by the following formula:
[0142]
[0143] Among them, a k and φk are the amplitude and phase of the kth optical signal, respectively. m is the number of optical signals participating in the interference. e represents the spatiotemporal position coding vector. By accurately analyzing the distribution of interfering light intensity, a topological graph reflecting the spatiotemporal correlation of signaling across protocols is constructed. This enables efficient encoding and processing of signaling information from electrical signals to optical signals, and dynamically correlates signaling information from different protocol layers across layers through optical interference.
[0144] Based on the first embodiment and / or the second embodiment of the present application, the third embodiment of the present application is proposed. In the third embodiment of the present application, the same or similar contents as those in the above embodiments can be referred to the above introduction and will not be repeated hereafter.
[0145] On this basis, please refer to Figure 3 , Figure 3 A flow chart of a third embodiment of the communication signaling storm interception method provided in this application. In this embodiment, after step S20, the method further includes steps S30 to S40:
[0146] Step S30: collecting attack signaling data, calculating a hash value of the attack signaling data according to a hash algorithm, and obtaining a time and space stamp of the attack signaling data;
[0147] Use the SHA3-512 hash algorithm and BeiDou time-space stamp to solidify the attack evidence. Specifically, for the collected relevant attacked signaling data, first use the SHA3-512 hash algorithm to calculate the hash value H of the data. The formula is: H = SHA3-512 (data)
[0148] Where data is the attacked signaling data. The SHA3-512 algorithm performs multiple rounds of complex bitwise operations and permutations on the data to generate a 512-bit hash value H. This hash value is highly unique and collision-resistant, accurately identifying the content of the signaling data. Simultaneously, through communication with the Beidou satellite, the precise time and space stamp T′ of the attacked signaling data is obtained.
[0149] Step S40: storing the hash value and the timestamp in the blockchain.
[0150] The hash value H, time stamp T′, and related signaling data summaries are stored in the blockchain. Blockchain uses distributed ledger technology to store data across multiple nodes, with each node maintaining a complete copy of the ledger. This ensures that attack evidence cannot be tampered with, providing a reliable basis for subsequent attack tracing.
[0151] In this embodiment, by ensuring the integrity and authenticity of attack signaling data and utilizing blockchain technology for secure, tamper-proof storage, reliable data support is provided for subsequent attack tracing. This helps accurately identify the attack source, understand the full scope of the attack, and take appropriate countermeasures.
[0152] Based on the above embodiments of the present application, a fourth embodiment of the present application is proposed. In the fourth embodiment of the present application, the same or similar contents as those of the above embodiments can be referred to the above introduction and will not be repeated hereafter.
[0153] On this basis, please refer to Figure 4 , Figure 4 A flowchart of the fourth embodiment of the communication signaling storm interception method provided in this application.
[0154] In this embodiment, after step S20 of triggering a signaling obfuscation strategy and / or a slice service quality degradation strategy to intercept a communication signaling storm according to the signaling storm attack probability, step S50 is also included:
[0155] Step S50: Add noise data that follows the Laplace distribution to the signaling metadata based on differential privacy technology to perform desensitization processing.
[0156] Signaling metadata refers to metadata related to 5G signaling. This data provides context and background information for the signaling, but does not include the specific signaling payload. Signaling metadata primarily includes the following sensitive information: user identification information, 5G-GUTI, IMSI, etc.
[0157] Specifically, differential privacy protects data privacy by adding noise to the data. Let the original signaling metadata be x, and the desensitized data x after adding noise n ′ is x′ =x+n, where the noise n follows the Laplace distribution, and its probability density function is:
[0158]
[0159] Where μ is the mean of the distribution (usually set to 0), and b is a scale parameter that is adjusted according to the privacy budget ∈. The privacy budget ∈ controls the intensity of the added noise. The smaller ∈, the higher the privacy protection, but the data availability will be reduced accordingly.
[0160] By properly setting the value of ∈, sensitive information in signaling metadata (such as IMSI and 5G-GUTI) can be desensitized while ensuring data availability. For example, based on the type and sensitivity of the signaling metadata, an appropriate value of ∈ is selected, the corresponding scaling parameter b is calculated, noise is generated, and added to the original data, making it impossible for third parties to accurately infer sensitive user information from the shared data.
[0161] In this embodiment, by adding Laplace-distributed noise data to signaling metadata, sensitive user information is prevented from being leaked during data sharing and cross-domain collaboration, thereby protecting user privacy. Despite the addition of noise data, by properly setting differential privacy parameters, the data's key statistical characteristics and relevant information are preserved while protecting privacy. This means that desensitized data can still be used for attack tracing and analysis.
[0162] The following combination Figure 5 The communication signaling storm interception method provided by this application is briefly summarized, wherein: Figure 5 This application provides a schematic diagram of the overall process of the communication signaling storm interception method. Figure 5 As shown, the overall idea of this application is to adopt a distributed architecture and closely collaborate among modules to achieve efficient interception of 5G signaling storms and network security protection.
[0163] The acquisition equipment for the training dataset module is deployed at 5G network base stations and at the edge of the core network. High-performance servers and 5G network interface cards capture signaling streams from the N2 / N4 / N11 interfaces. Preprocessing performs preliminary data cleaning and field extraction. The optical computing acceleration module is connected to the acquisition equipment for the training dataset module via high-speed optical fiber. It uses multi-wavelength modulation and a 16×16 photon interference array to encode the signaling stream into a spatiotemporal topology map. Simultaneously, the Photon-NAS framework on the silicon photonic chip optimizes the model structure based on hardware performance parameters, generating a customized model compatible with FPGAs and ASICs. The real-time detection and response module's equipment is deployed in the network security management center and connected to the optical computing acceleration module via a dedicated network. The real-time detection equipment loads the customized model and performs millisecond-level inference on the signaling stream. The equipment of the cross-domain collaboration and traceability module is deployed in the cross-domain data coordination center. Through the blockchain node equipment, the SHA3-512 hash algorithm and Beidou time-space stamp are used to solidify the attack evidence, realizing minute-level cross-operator attack chain traceability. The signaling metadata is desensitized based on differential privacy technology through privacy protection processing equipment to ensure the compliance of cross-domain data sharing.
[0164] like Figure 5 As shown, the S1 dataset training module constructs a high-quality, feature-rich dataset suitable for model training. This overcomes the high dimensionality, complex features, and cross-protocol feature inconsistencies of the original signaling data, providing a solid data foundation for subsequent model training and enhancing the model's ability to identify and respond to various 5G signaling storm attack scenarios. S1 specifically includes S11 to S13. S11 Data Collection and Preprocessing: Signaling flows are captured in real time from the N2 / N4 / N11 interfaces. Based on the detailed signaling format definition of the 3GPP protocol, the captured signaling packets are parsed and extracted using the 5G-GUTI and QFI key information fields. S12 Feature Dimensionality Reduction: The t-SNE algorithm is used to reduce the feature dimension from 256 to 32, mapping the original 256-dimensional signaling feature vectors into a 32-dimensional space. This process effectively reduces data dimensionality and computational complexity while preserving the data's key features to the greatest extent possible, ensuring that the data maintains its original relative relationships in the low-dimensional space. S13 cross-protocol feature alignment: Map geographic coordinates to low-dimensional vectors based on the Hilbert curve, and then embed spatiotemporal position encoding (STPE) in the protocol. The spatiotemporal position encoding combines time and space information to generate a coding vector.
[0165] The S2 optical computing acceleration module leverages the high-speed parallel processing capabilities of optical computing to accelerate 5G signaling data processing and model optimization. This module addresses the high latency and energy consumption challenges faced by traditional hardware when processing large-scale, complex signaling data, enabling efficient real-time analysis of 5G signaling flows. In its implementation, S2 may include the following steps: S21: Multi-wavelength modulation: Encodes the signaling flow into a spatiotemporal topology driven by photon interference. The multi-wavelength modulation characteristics of silicon photonic matrix multipliers are used to encode optical signals for different protocol fields in the signaling flow. S22: Hardware-aware optimization: Executes neural architecture search (Photon-NAS) on the silicon photonic chip. Based on the characteristics of the input signaling data and hardware performance parameters, the framework initiates a proximal strategy optimization algorithm. This algorithm explores the model architecture search space to determine model architecture parameters such as the photonic convolution kernel size and residual connection path. The optimal residual connection path is determined to achieve efficient collaboration between the model and the hardware. Simultaneously, the framework monitors the model's operational status on the specific hardware in real time, including power consumption and computational latency. When the model performance reaches the preset optimization goal (such as accuracy reaching a certain threshold or computational latency falling within a specific range) or the maximum number of searches is reached, the search process is stopped and a customized model adapted for hardware such as FPGAs and ASICs is generated. For FPGAs, customized model structures tend to adopt a more flexible parallel computing architecture, fully leveraging the advantages of FPGA reconfigurable logic resources to improve the model's computational speed and parallel processing capabilities. For ASICs, customized model structures focus on optimizing circuit layout, reducing the number of transistors and signal transmission delays to reduce power consumption and improve computational efficiency, thereby meeting the performance requirements of different hardware platforms for the model.
[0166] S3 detection and response module, which uses an optimized customized model to quickly and accurately detect real-time 5G signaling flows, promptly identify signaling storm attacks, and take effective defense strategies, including the following steps: S31: Lightweight model execution, loading the customized model generated by Photon-NAS, and simultaneously processing multiple signaling data fragments through the hardware's parallel computing unit, shortening the inference time to milliseconds, meeting the strict time requirements of 5G signaling real-time detection, and timely analyzing and judging the signaling flow. S32: Dynamic defense strategy, when a signaling storm attack is detected attack When ≥0.93, signaling confusion or slice QoS degradation policy is triggered.
[0167] S4: Cross-domain collaborative tracing module. This module enables cross-operator collaborative analysis of 5G signaling data and attack tracing, addressing the data heterogeneity and privacy leakage risks faced by existing cross-domain data sharing, and improving overall defense capabilities and tracing efficiency against signaling storm attacks. This module includes the following steps: S41: Blockchain evidence storage, using the SHA3-512 hash algorithm and Beidou time-space stamps to consolidate attack evidence. S42: Privacy protection, using differential privacy technology to desensitize signaling metadata.
[0168] It should be noted that the proposed photonic computing collaborative architecture has achieved breakthrough improvements in detection accuracy, real-time performance and cross-domain collaborative capabilities through three technological innovations: cross-protocol optical topology mapping, dynamic neural architecture search and adversarial comparative learning.
[0169] Specifically, in cross-protocol correlation modeling, leveraging the multi-wavelength modulation characteristics of silicon photonic matrix multipliers, the N2 / N4 / N11 interface signaling streams are encoded as a spatiotemporal topology driven by photon interference, enabling dynamic cross-layer correlation of protocol fields (such as the spatiotemporal coupling of NAS authentication failure events and NGAP handover requests). This technology increases the detection rate of slice hijacking attacks from 82.7% with traditional solutions to 99.3%, while maintaining a stable false alarm rate below 0.7%.
[0170] To address hardware heterogeneity, we introduced the Photon Hardware-Aware Neural Architecture Search framework (Photon-NAS). This framework optimizes model structures (such as photonic convolution kernel size and residual connection paths) in real time on silicon photonic chips, generating customized models that are compatible with hardware such as FPGAs and ASICs. Tests have shown that this technology reduces the standard deviation of inference latency from 2.1ms to 0.28ms and achieves an energy efficiency of 8.5TOPS / W at 25Gbps signaling throughput, a 2.7x improvement over traditional GPU solutions.
[0171] In terms of adversarial attack defense, by injecting perturbed signaling samples (such as compliant attack flows generated by PGD) through Adversarial Contrastive Learning (ACL), and combining them with BeiDou time and space stamps to construct self-supervisory signals, the model's bypass rate for generative attacks (such as DeepFake signaling flows) dropped from 19.1% to 2.7%. Even in scenarios with scarce labeled data (less than 50 items), detection accuracy remained at 94.6%, significantly outperforming the 78.2% achieved by traditional supervised learning solutions.
[0172] The above examples and specific data are only used to understand the present application and do not constitute a limitation of the present application. Simple transformations in more forms based on this technical concept are all within the scope of protection of the present application.
[0173] This application also provides a communication signaling storm interception device, please refer to Figure 6 , the communication signaling storm interception device includes:
[0174] Detection module 10, for loading a pre-built customized detection model, using the customized detection model to perform inference on the signaling flow of the communication network interface to obtain the signaling storm attack probability, wherein the customized detection model is generated based on the neural architecture search framework and spatiotemporal topology graph of photonic hardware perception, and the training process of the customized detection model injects perturbed signaling samples through adversarial contrastive learning and constructs a self-supervised signal in combination with Beidou spatiotemporal stamps;
[0175] The response module 20 is used to trigger the signaling confusion strategy and / or the slice service quality degradation strategy to intercept the communication signaling storm according to the signaling storm attack probability.
[0176] The communication signaling storm interception device provided in the present application adopts the communication signaling storm interception method in the above embodiment, which can solve the technical problem of communication signaling storm interception.
[0177] The present application provides a communication signaling storm interception device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the communication signaling storm interception method in the above-mentioned embodiment one.
[0178] Reference below Figure 7 , which shows a schematic diagram of the structure of a communication signaling storm interception device suitable for implementing the embodiments of the present application. The communication signaling storm interception device in the embodiments of the present application may include, but is not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Portable Application Descriptions), PMPs (Portable Media Players), vehicle-mounted terminals (such as vehicle-mounted navigation terminals), and fixed terminals such as digital TVs and desktop computers. Figure 7 The communication signaling storm interception device shown is merely an example and should not impose any limitations on the functions and scope of use of the embodiments of the present application.
[0179] like Figure 7As shown, the communication signaling storm interception device may include a processing device 1001 (e.g., a central processing unit, a graphics processing unit, etc.), which can perform various appropriate actions and processes based on programs stored in a read-only memory 1002 or programs loaded from a storage device 1003 into a random access memory 1004. The random access memory 1004 also stores various programs and data required for the operation of the communication signaling storm interception device. The processing device 1001, the read-only memory 1002, and the random access memory 1004 are connected to each other via a bus 1005. An input / output interface 1006 is also connected to the bus. Typically, the following systems can be connected to the input / output interface 1006: an input device 1007 including, for example, a touch screen, touchpad, keyboard, mouse, image sensor, microphone, accelerometer, gyroscope, etc.; an output device 1008 including, for example, a liquid crystal display (LCD), speaker, vibrator, etc.; a storage device 1003 including, for example, a magnetic tape, hard disk, etc.; and a communication device 1009. The communication device 1009 can allow the communication signaling storm interception device to communicate with other devices wirelessly or wired to exchange data. Although the figure shows a communication signaling storm interception device with various systems, it should be understood that it is not required to implement or have all of the systems shown. More or fewer systems can be implemented or provided instead.
[0180] In particular, according to the embodiments disclosed in the present application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, the embodiments disclosed in the present application include a computer program product comprising a computer program carried on a computer-readable medium, the computer program comprising program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network via a communication device, or installed from a storage device 1003, or installed from a read-only memory 1002. When the computer program is executed by the processing device 1001, the above-mentioned functions defined in the method of the embodiment disclosed in the present application are performed.
[0181] The communication signaling storm interception device provided in this application adopts the communication signaling storm interception method of the above-mentioned embodiment to solve the technical problem of communication signaling storm interception. Compared with the prior art, the beneficial effects of the communication signaling storm interception device provided in this application are the same as the beneficial effects of the communication signaling storm interception method provided in the above-mentioned embodiment, and the other technical features of the communication signaling storm interception device are the same as those disclosed in the method of the above-mentioned embodiment, and are not further described here.
[0182] It should be understood that the various parts disclosed in this application can be implemented using hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics can be combined in any one or more embodiments or examples in a suitable manner.
[0183] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.
[0184] The present application provides a computer-readable storage medium having computer-readable program instructions (ie, computer programs) stored thereon, and the computer-readable program instructions are used to execute the communication signaling storm interception method in the above-mentioned embodiment.
[0185] The computer-readable storage medium provided in this application may be, for example, a USB flash drive, but is not limited to electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems or devices, or any combination thereof. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In this embodiment, the computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system or device. The program code contained on the computer-readable storage medium may be transmitted using any appropriate medium, including but not limited to: wires, optical cables, RF (Radio Frequency), etc., or any suitable combination thereof.
[0186] The computer-readable storage medium may be included in the communication signaling storm interception device; or it may exist independently without being assembled into the communication signaling storm interception device.
[0187] The above-mentioned computer-readable storage medium carries one or more programs. When the above-mentioned one or more programs are executed by the communication signaling storm interception device, the communication signaling storm interception device: loads a pre-built customized detection model, uses the customized detection model to perform inference on the signaling flow of the communication network interface, and obtains the signaling storm attack probability, wherein the customized detection model is generated based on the neural architecture search framework and space-time topology map of photon hardware perception, and the training process of the customized detection model injects perturbed signaling samples through adversarial contrast learning, and constructs a self-supervised signal in combination with the Beidou space-time stamp; triggers the signaling confusion strategy and / or slice service quality degradation strategy according to the signaling storm attack probability to perform communication signaling storm interception.
[0188] Computer program code for performing the operations of the present application may be written in one or more programming languages, or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, C++, and conventional procedural programming languages such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on the remote computer or server. In cases involving a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., through the Internet using an Internet service provider).
[0189] The flow charts and block diagrams in the accompanying drawings illustrate the possible architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present application. In this regard, each box in the flow chart or block diagram can represent a module, program segment or a part of code, and the module, program segment or a part of code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order than that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flow chart, and the combination of the boxes in the block diagram and / or flow chart can be implemented by a dedicated hardware-based system that performs the specified function or operation, or can be implemented by a combination of dedicated hardware and computer instructions.
[0190] The modules described in the embodiments of the present application may be implemented in software or hardware, wherein the name of a module does not necessarily limit the unit itself.
[0191] The readable storage medium provided in this application is a computer-readable storage medium, which stores computer-readable program instructions (i.e., a computer program) for executing the above-mentioned communication signaling storm interception method, and can solve the technical problem of communication signaling storm interception. Compared with the prior art, the beneficial effects of the computer-readable storage medium provided in this application are the same as the beneficial effects of the communication signaling storm interception method provided in the above-mentioned embodiment, and will not be repeated here.
[0192] The present application also provides a computer program product, including a computer program, which implements the steps of the communication signaling storm interception method as described above when executed by a processor.
[0193] The computer program product provided in this application can solve the technical problem of intercepting communication signaling storms. Compared with the prior art, the beneficial effects of the computer program product provided in this application are the same as those of the communication signaling storm interception method provided in the above embodiment, and will not be repeated here.
[0194] The above description is only part of the embodiments of the present application and does not limit the patent scope of the present application. All equivalent structural transformations made by using the contents of the present application specification and drawings under the technical concept of the present application, or direct / indirect application in other related technical fields are included in the patent protection scope of the present application.
Claims
1. A communication signaling storm interception method, characterized in that: The signaling storm interception method includes: Load a pre-built customized detection model and use it to infer the signaling flow of the communication network interface to obtain the signaling storm attack probability. The customized detection model is generated based on the photonic hardware-aware neural architecture search framework and spatiotemporal topology graph. The training process of the customized detection model injects perturbed signaling samples through adversarial contrastive learning and constructs a self-supervised signal in combination with Beidou spatiotemporal stamps. According to the signaling storm attack probability, the signaling confusion strategy and / or slice service quality degradation strategy are triggered to intercept the communication signaling storm.
2. The communication signaling storm interception method according to claim 1, characterized in that: Before the step of loading a pre-built customized detection model and using the customized detection model to perform reasoning on the signaling flow of the network interface to obtain the signaling storm attack probability, the method further includes: Collecting sample signaling data packets from the communication network interface, and performing preprocessing, feature dimensionality reduction, and cross-protocol feature alignment on the sample signaling data packets to obtain a cross-protocol spatiotemporal correlation feature vector; Based on the multi-wavelength modulation characteristics of the silicon photonic matrix multiplier, the cross-protocol spatiotemporal correlation feature vector is encoded into a spatiotemporal topology graph driven by photon interference; Inputting complexity parameters and hardware performance parameters of the spatiotemporal topology graph into a neural architecture search framework based on photonic hardware perception to generate candidate models; Injecting perturbation signaling samples for adversarial contrastive learning, generating a self-supervisory signal in combination with BeiDou space-time stamps, and training the candidate model based on the perturbation signaling samples and the self-supervisory signal; The proximal strategy optimization algorithm is started to adjust the search strategy, and a candidate model whose model structure parameters meet the preset conditions is selected from the trained candidate model structure according to the search strategy to obtain a customized detection model.
3. The communication signaling storm interception method according to claim 2, characterized in that: The step of collecting sample signaling data packets from the communication network interface, and performing preprocessing, feature dimensionality reduction, and cross-protocol feature alignment on the sample signaling data packets to obtain a cross-protocol spatiotemporal correlation feature vector includes: Collecting sample signaling data packets from the communication network interface, extracting key information fields from the sample signaling data packets according to a signaling format definition, and performing digital encoding and standardization processing on the key information fields to obtain a high-dimensional feature vector; Using a distributed random neighborhood embedding algorithm to reduce the dimensionality of the high-dimensional feature vector to obtain a low-dimensional feature vector; Converting geographic coordinates into one-dimensional index values through a curve mapping algorithm, and mapping the one-dimensional index values into a low-dimensional vector space to generate a geographic information feature vector; Extracting a signaling timestamp of the sample signaling data packet, and encoding the signaling timestamp into a time vector; Fusing the time vector and the geographic information feature vector to obtain a spatiotemporal position coding vector; The spatiotemporal position encoding vector is embedded in the low-dimensional feature vector to obtain a cross-protocol spatiotemporal correlation feature vector.
4. The communication signaling storm interception method according to claim 2, characterized in that: The step of encoding the cross-protocol spatiotemporal correlation feature vector into a photon interference-driven spatiotemporal topology map based on the multi-wavelength modulation characteristics of the silicon photonic matrix multiplier includes: Dividing the cross-protocol spatiotemporal correlation feature vector into a NAS layer feature sub-vector and an NGAP layer feature sub-vector; Based on the multi-wavelength modulation characteristics of the silicon photonic matrix multiplier, optical signals of different wavelengths are modulated to encode the NAS layer characteristic subvector and the NGAP layer characteristic subvector respectively, so as to obtain a NAS layer characteristic optical signal and an NGAP layer characteristic optical signal; The NAS layer characteristic light signal and the NGAP layer characteristic light signal are coupled to a photon interference array to obtain a light intensity distribution after interference, and a spatiotemporal topology map is generated based on the light intensity distribution.
5. The communication signaling storm interception method according to claim 1, characterized in that: The step of loading a pre-built customized detection model and using the customized detection model to perform reasoning on the signaling flow of the communication network interface includes: Loading a pre-built customized detection model from a storage device to a memory device, wherein the customized detection model is adapted to the target hardware; The signaling data segments of the signaling flow are processed in parallel by the parallel computing unit of the target hardware, and the signaling data segments are input into the customized detection model for millisecond-level reasoning to obtain the signaling storm attack probability.
6. The communication signaling storm interception method according to claim 1, characterized in that: The step of triggering a signaling obfuscation strategy and / or a slice service quality degradation strategy to intercept a communication signaling storm according to the signaling storm attack probability includes: When the signaling storm attack probability exceeds a preset threshold, triggering a signaling confusion strategy and / or a slice service quality degradation strategy, and determining the attacked signaling data based on the signaling storm attack probability; Randomly changing the field value of the attacked signaling data based on the signaling obfuscation strategy to intercept the communication signaling storm; and / or Based on the slice service quality degradation strategy, the slice service quality of the attacked signaling data is reduced to intercept the communication signaling storm.
7. The communication signaling storm interception method according to claim 1, wherein: After the step of triggering a signaling obfuscation strategy and / or a slice service quality degradation strategy to intercept a communication signaling storm according to the signaling storm attack probability, the step further includes: Collect attack signaling data, calculate the hash value of the attack signaling data according to the hash algorithm, and obtain the time and space stamp of the attack signaling data; The hash value and the timestamp are stored in the blockchain.
8. The communication signaling storm interception method according to claim 1, wherein: After the step of triggering a signaling obfuscation strategy and / or a slice service quality degradation strategy to intercept a communication signaling storm according to the signaling storm attack probability, the step further includes: Based on differential privacy technology, noise data that follows the Laplace distribution is added to the signaling metadata for desensitization.
9. A communication signaling storm interception device, characterized in that: The communication signaling storm interception device includes: A detection module is used to load a pre-built customized detection model and use it to infer the signaling flow of the communication network interface to obtain the probability of a signaling storm attack. The customized detection model is generated based on a neural architecture search framework and spatiotemporal topology graph based on photonic hardware perception. The customized detection model is trained by injecting perturbed signaling samples through adversarial contrastive learning and constructing a self-supervised signal in combination with Beidou spatiotemporal stamps. A response module is used to trigger a signaling confusion strategy and / or a slice service quality degradation strategy to intercept communication signaling storms based on the signaling storm attack probability.
10. A computer program product, characterized in that The computer program product includes a computer program, and when the computer program is executed by a processor, the steps of the communication signaling storm interception method according to any one of claims 1 to 8 are implemented.