A real-time data based radio assurance monitoring method
By analyzing the stability and sporadic tags of radio signal sources, marking the area type and identifying suspected sources during monitoring periods, the problem of regional adaptability in radio anomaly detection is solved, achieving efficient and intelligent radio management.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-29
- Publication Date
- 2026-04-07
AI Technical Summary
Existing technologies are insufficient for detecting radio anomalies in different regions and situations, especially for monitoring radio spectrum usage habits.
By acquiring the source of radio signals, we label them as stable or intermittent based on the duration of their daily occurrence, and mark the areas as stable or erratic based on the proportion of these labels. When the monitoring period arrives, we acquire the real-time source objects and mark them as suspected sources according to specific requirements for targeted investigation.
It has enabled intelligent and automated radio monitoring, reducing the waste of manpower, financial resources and time, improving the efficiency of radio management, and avoiding errors in simple troubleshooting.
Smart Images

Figure CN120751434B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of radio security monitoring technology, specifically a radio security monitoring method based on real-time data. Background Technology
[0002] Patent application number CN201910253245.8 discloses a radio frequency gene bank system and an illegal and irregular radio wave detection system. The radio frequency gene bank system includes: an individual segmentation device configured to determine the range of a target geographical area, determine an individual segmentation method based on the communication environment of the target geographical area, and divide the target geographical area into multiple individuals according to the individual segmentation method; a wireless detector configured to detect each individual and acquire basic radio frequency data for each individual; a radio frequency gene bank generation device configured to perform deep neural network calculations based on the basic radio frequency data of each individual to acquire the radio frequency genes of each individual; and to store the radio frequency genes of each individual to generate a radio frequency gene bank for the target geographical area. The technical solution provided by this invention can realize the intelligentization and automation of radio monitoring work, reduce unnecessary waste of manpower, financial resources, materials, and time, improve the efficiency of radio management, and improve the radio management system.
[0003] For radio monitoring, how to monitor different areas and situations, especially the anomaly detection related to the usage habits of radio on different spectrums, is a difficult problem. Based on this, a solution is provided. Summary of the Invention
[0004] This invention aims to solve at least one of the technical problems existing in the prior art;
[0005] To achieve the above objectives, a radio security monitoring method based on real-time data is proposed, including:
[0006] The source object of the radio signal appearing in the target area is obtained. The source object is labeled as stable or occasional based on the duration of its appearance each day. The target area is marked as stable or random based on the ratio between stable and occasional labels.
[0007] When the monitoring period arrives, all real-time source objects will be acquired. Real-time source objects will be marked as suspected sources if they meet the following requirements:
[0008] The real-time source object does not belong to the source objects in the source library;
[0009] The real-time interval between the last time the real-time source object and the same source object were used is not within the interval range or the expanded fluctuation range.
[0010] The continuous real-time usage duration during use exceeds the duration range or the expanded fluctuation duration range;
[0011] The source database contains all source objects that have appeared within the specified number of days.
[0012] The interval range or fluctuation range is determined by analyzing the dispersion of the time interval between each occurrence of the source object in the past, and the duration range or fluctuation duration range is determined by analyzing the dispersion of the duration of each occurrence of the source object in the past.
[0013] Furthermore, the method for determining the stable or occasional labels of the source object is as follows:
[0014] Get the duration of the source object's appearance within the last set number of days, and get the percentage of days with a non-zero duration out of the total number of days;
[0015] The number of non-zero durations whose absolute value of the difference from the mean duration does not exceed X1 is obtained as a stable ratio of the total number of non-zero durations.
[0016] After assigning different weights to the stability ratio and the occupancy ratio, the stability rating is obtained by adding them together. Source objects with stability ratings exceeding a set value of X2 are labeled as stable, and source objects with stability values less than or equal to X4 are labeled as occasional. X4 is 0.65 times X2.
[0017] Furthermore, when the random occurrence ratio exceeds the set ratio B2, the corresponding target area is marked as a random occurrence area; if it is less than 0.4 times B2, it is marked as a stable area.
[0018] Furthermore, the interval range and fluctuation range are determined as follows:
[0019] Obtain the time interval between each occurrence of the source object in the past, resulting in several time intervals Zi, i=1, ..., m. Calculate the mean of Zi and label it U. Then, automatically calculate its deviation value Q using the following formula:
[0020] ;
[0021] When Q does not exceed the preset value X3, the range from the minimum to the maximum value of Zi is marked as the interval range;
[0022] When Q exceeds X3, Zi is automatically sorted in descending order of |Zi-U| values. Then, Zi values are selected sequentially, and each selected value is deleted. After deletion, the Q value of the remaining Zi is recalculated. When Q still exceeds X3, the next Zi value is selected and deleted until Q does not exceed X3. The number of deleted Zi values is obtained and divided by m. The resulting value is marked as the deletion ratio. When the deletion ratio does not exceed the set ratio B3, the range from the minimum to the maximum value of the remaining Zi after deletion is marked as the fluctuation interval range.
[0023] Furthermore, the duration range and fluctuation duration range are determined as follows:
[0024] The duration of each occurrence of the source object in the past is obtained, and the duration is processed in the same way according to the time interval to obtain the duration range and the fluctuation duration range.
[0025] Furthermore, the range of fluctuations and the range of fluctuation duration are expanded in the following ways:
[0026] Add one to the expansion ratio and multiply by the maximum value in the range; subtract the expansion ratio from one and multiply by the minimum value in the range.
[0027] Furthermore, when the target region is a stable region, the expansion ratio is 0.3;
[0028] When the target area is a region with disorderly distribution, the expansion ratio is 0.15.
[0029] Furthermore, X1 is a preset value.
[0030] Furthermore, X1 is determined in the following manner:
[0031] Select several stable source objects after labeling, then obtain all source objects, calculate the stability assessment value of all source objects, obtain several stability assessment values, calculate their deviation values, and filter the stability assessment values according to the relationship between the deviation values and the preset value X4 until the deviation value is less than X4.
[0032] Get the deleted stability assessment values, get the sum of the deleted stability assessment values that are greater than the mean, and mark it as the total value above the mean; get the sum of the deleted stability assessment values that are less than the mean, and mark it as the total value below the mean.
[0033] When the value of (total upper average - total lower average) / total lower average exceeds B1, the median of the mean of the undeleted stable rating values and the minimum value among the stable rating values is marked as the corresponding value of X2; otherwise, the minimum value among the undeleted stable rating values is marked as the value of X2. If the deviation value is less than X4 from the beginning, the minimum value among the stable rating values is also marked as the value of X2.
[0034] Compared with the prior art, the beneficial effects of the present invention are:
[0035] This application obtains the source object of the radio signal appearing in the target area, assigns a stable tag or an occasional tag to the source object based on the duration of the source object's appearance each day, and marks the target area as a stable area or an uncontrolled area based on the ratio between the stable tag and the occasional tag.
[0036] When the monitoring period arrives, all real-time source objects will be acquired. When a real-time source object meets the relevant requirements, it will be marked as a suspected source. Targeted investigation will be carried out on the suspected source, thereby avoiding the situation of simply investigating based on usage. At the same time, the spectrum signal of usage can also be monitored. This invention is simple, effective and easy to use. Attached Figure Description
[0037] Figure 1 This is a flowchart of the method of the present invention. Detailed Implementation
[0038] The technical solution of the present invention will be clearly and completely described below with reference to the embodiments. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0039] Please see Figure 1 This application provides a radio security monitoring method based on real-time data;
[0040] As an embodiment of this application, the specific steps include the following:
[0041] The system identifies the source objects of radio signals appearing in the target area. Based on the duration of each day's occurrence, the source objects are tagged as either stable or intermittent. The target area is then marked as either a stable area or a region with erratic radio signals based on the ratio between stable and intermittent tags.
[0042] When the monitoring period arrives, all real-time source objects will be acquired. Real-time source objects will be marked as suspected sources if they meet the following requirements:
[0043] The real-time source object does not belong to the source objects in the source library;
[0044] The real-time interval between the last time the real-time source object and the same source object were used is not within the interval range or the fluctuation range after the expansion ratio.
[0045] The expansion ratio of continuous real-time usage time exceeding the time range or fluctuating time range during use;
[0046] The source library contains all source objects that have appeared within the most recent set number of days;
[0047] The interval range or fluctuation range is determined by analyzing the dispersion of the time interval between each occurrence of the source object in the past, and the duration range or fluctuation duration range is determined by analyzing the dispersion of the duration of each occurrence of the source object in the past.
[0048] As a second embodiment of this application, the method specifically includes the following steps:
[0049] Step 1: Monitor the preset target area, which is the target location to be monitored. Then, monitor the radio spectrum data that appears in the target area every day in the recent period. The recent period mentioned here refers to the period 30 days before the present, but it can also be modified to 60 days, depending on the administrator's needs. For ease of description, the corresponding radio spectrum data is marked as the source object.
[0050] Step 2: Select any source object and obtain its duration of occurrence on each day. The duration of occurrence is the total duration of the spectrum signal from its appearance to its end on that day. This will result in several durations Wi, i=1,...,n, indicating that a total of n days of data have been obtained, and the duration of occurrence on the i-th day is Wi.
[0051] Obtain the number of days with a non-zero duration of maintenance, divide it by n, and mark the resulting value as the occupancy ratio;
[0052] Remove those with a duration of 0, then obtain the average of the remaining durations Wi, and mark it as P. Use the filtering condition |Wi-P|≤X1, where X1 is a preset value set by the administrator; obtain the number of Wi that meet the filtering condition, and mark it as the stability ratio.
[0053] The stability assessment value of the corresponding source object is calculated using the following formula:
[0054] Stability rating = 0.42 * Occupancy rate + 0.58 * Stability ratio;
[0055] The stability rating of the corresponding source object is obtained. When it exceeds the preset value X2, the source object is automatically labeled as stable; when it is less than or equal to X4, it is automatically labeled as occasional. X4 is 0.65 times X2.
[0056] Perform the same processing on all other source objects to obtain all source objects with either a stable tag or an occasional tag;
[0057] Step 3: Then obtain all tagged source objects in the target area;
[0058] The number of objects with the occasional tag source is obtained, divided by the number of objects with the stable tag source, and marked as the occasional ratio.
[0059] When the frequency of occasional occurrences exceeds the set ratio B2, the corresponding area is marked as an area with random occurrences. B2 is generally set to 0.35, but the administrator can set it to other values according to actual needs. If it is less than 0.4 times B2, it is marked as a stable area.
[0060] Step 4: Upon arrival at the designated monitoring period for the target area, conduct follow-up monitoring. The specific monitoring method is as follows:
[0061] It will obtain all source objects that have occurred in the target area, and verify that all source objects are problem-free before the monitoring period. Here, "no problem-free" means that all source objects are legitimate and regular signal exchanges.
[0062] All source objects are constructed into a source library;
[0063] Inertial analysis is performed on all source objects within the target area, specifically as follows:
[0064] Choose any source object and obtain the duration of each occurrence of that source object, the time interval between the previous and next occurrences, and the user that communicates through the source object. The user includes the sender and the receiver. "Single occurrence" means that the source object does not reappear within a time interval T1 after it is interrupted. It is represented as "in sequence". T1 is a preset value, which is usually half a minute.
[0065] Obtain the offset values for all time intervals. The specific method for obtaining these values is as follows:
[0066] The time interval is labeled Zi, i=1,...,m, indicating that there are m source objects;
[0067] The mean of Zi is automatically obtained and labeled as U, and then its deviation value Q is automatically calculated. The specific calculation formula is as follows:
[0068] ;
[0069] When Q does not exceed the preset value X3, the range from the minimum to the maximum value of Zi is automatically marked as the interval range.
[0070] When Q exceeds the preset value X3, Zi is automatically sorted in descending order of |Zi-U|. Then, Zi values are selected sequentially, and each selected value is deleted. After deletion, the Q value of the remaining Zi is recalculated. When Q still exceeds X3, the next Zi value is selected and deleted until Q does not exceed X3. The number of deleted Zi values is obtained and divided by m. The resulting value is marked as the deletion ratio. When the deletion ratio does not exceed the set ratio B3, the range from the minimum to the maximum value of the remaining Zi after deletion is marked as the fluctuation interval range.
[0071] If the deletion ratio exceeds B3, no action will be taken.
[0072] By applying the same processing to the time length, we can obtain the duration range or fluctuation range of the corresponding time length.
[0073] Step 5: Then obtain all users and establish a user database, which includes the sender and receiver;
[0074] All real-time sources are obtained. When a source is newly added, it means that there is no corresponding source object in the source database. The newly added source is automatically marked as a suspected source, and the management personnel verify the suspected source.
[0075] When the real-time source is not a newly added source, if it is verified whether it belongs to both parties in the database, no processing is done if it does, otherwise the real-time time interval of the last time the real-time source was used will be obtained. At this time, the interval range or fluctuation interval range of the corresponding source object will be obtained.
[0076] If there is an interval range and the real-time time interval is within the fluctuation range, no action will be taken. If it exceeds the real-time interval range, the corresponding real-time source will be marked as a suspected source.
[0077] If the fluctuation interval range exists, the real-time time interval is compared with the fluctuation interval range. If it does not exceed the expansion ratio of the fluctuation interval range, no action is taken. If it does exceed the expansion ratio, the real-time source is marked as a suspected source.
[0078] The expansion ratio is determined as follows:
[0079] When the target area is a random area, the expansion ratio is 0.15, which means that the maximum value in the range will be multiplied by 1.15 and the minimum value will be multiplied by 0.85.
[0080] When the target region is a stable region, an expansion ratio of 0.3 means that the maximum value in the range will be multiplied by 1.3 and the minimum value by 0.7.
[0081] During use, the real-time usage duration of the real-time source will be continuously monitored. If the continuous real-time usage duration exceeds the duration range or the expansion ratio of the fluctuation duration range, the real-time source will be marked as a suspected source.
[0082] Of course, as a third embodiment of this application, X2 in the first embodiment can be determined in the following way, specifically as follows:
[0083] The administrator selects several stable source objects after labeling, then obtains all source objects, calculates the stability evaluation value of all source objects, obtains several stability evaluation values, calculates their deviation values, and filters the stability evaluation values according to the relationship between the deviation value and X4 in the method provided in Example 1, until the deviation value is less than X4; X4 is a preset value;
[0084] Get the deleted stability assessment values, get the sum of the deleted stability assessment values that are greater than the mean, and mark it as the total value above the mean; get the sum of the deleted stability assessment values that are less than the mean, and mark it as the total value below the mean.
[0085] When the value of (total upper average - total lower average) / total lower average exceeds B1, the median of the mean of the undeleted stable rating values and the minimum value among the stable rating values is marked as the corresponding value of X2; otherwise, the minimum value among the undeleted stable rating values is marked as the value of X2; if the deviation value is less than X4 from the beginning, the minimum value among the stable rating values is also marked as the value of X2.
[0086] The data in the above formula are all calculated by removing the dimensions and taking the numerical values. The formula is the closest to the real situation obtained by software simulation of a large amount of collected data. The preset parameters and preset thresholds in the formula are set by those skilled in the art according to the actual situation or obtained through simulation of a large amount of data.
[0087] The above embodiments are only used to illustrate the technical methods of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical methods of the present invention without departing from the spirit and scope of the technical methods of the present invention.
Claims
1. A radio reliability monitoring method based on real-time data, characterized in that, include: The source object of the radio signal appearing in the target area is obtained. The source object is labeled as stable or occasional based on the duration of its appearance each day. The target area is marked as stable or random based on the ratio between stable and occasional labels. When the monitoring period arrives, all real-time source objects will be acquired. A real-time source object will be marked as a suspected source if it meets the following requirements: The real-time source object does not belong to the source objects in the source library; The real-time interval between the last time the real-time source object and the same source object were used is not within the interval range or the expanded fluctuation range. The continuous real-time usage duration during use exceeds the duration range or the expanded fluctuation duration range; The source database contains all source objects that have appeared within the specified number of days. The interval range or fluctuation range is determined by analyzing the dispersion of the time interval between each occurrence of the source object in the past, and the duration range or fluctuation duration range is determined by analyzing the dispersion of the duration of each occurrence of the source object in the past.
2. The radio reliability monitoring method based on real-time data according to claim 1, characterized in that, The method for determining stable or occasional tags for source objects is as follows: Get the duration of the source object's appearance within the last set number of days, and get the percentage of days with a non-zero duration out of the total number of days; The number of non-zero durations whose absolute value of the difference from the mean duration does not exceed X1 is obtained as a stable ratio of the total number of non-zero durations. After assigning different weights to the stability ratio and the occupancy ratio, the stability rating is obtained by adding them together. Source objects with stability ratings exceeding a set value of X2 are labeled as stable, and source objects with stability values less than or equal to X4 are labeled as occasional. X4 is 0.65 times X2.
3. The radio reliability monitoring method based on real-time data according to claim 1, characterized in that, When the random occurrence ratio exceeds the set ratio B2, the corresponding target area is marked as a random occurrence area; if it is less than 0.4 times B2, it is marked as a stable area.
4. The radio reliability monitoring method based on real-time data according to claim 1, characterized in that, The expansion of the fluctuation range and fluctuation duration range is carried out in the following ways: Add one to the expansion ratio and multiply by the maximum value in the range; subtract the expansion ratio from one and multiply by the minimum value in the range.
5. The radio reliability monitoring method based on real-time data according to claim 4, characterized in that, When the target region is a stable region, the expansion ratio is 0.3; When the target area is a region with disorderly distribution, the expansion ratio is 0.
15.
6. The radio reliability monitoring method based on real-time data according to claim 2, characterized in that, X1 is a preset value.
7. The radio reliability monitoring method based on real-time data according to claim 2, characterized in that, X1 is determined in the following way: Select several stable source objects after labeling, then obtain all source objects, calculate the stability assessment value of all source objects, obtain several stability assessment values, calculate their deviation values, and filter the stability assessment values according to the relationship between the deviation values and the preset value X4 until the deviation value is less than X4. Get the deleted stability assessment values, get the sum of the deleted stability assessment values that are greater than the mean, and mark it as the total value above the mean; get the sum of the deleted stability assessment values that are less than the mean, and mark it as the total value below the mean. When the value of (total upper average - total lower average) / total lower average exceeds B1, the median of the mean of the undeleted stable rating values and the minimum value among the stable rating values is marked as the corresponding value of X2; otherwise, the minimum value among the undeleted stable rating values is marked as the value of X2. If the deviation value is less than X4 from the beginning, the minimum value among the stable rating values is also marked as the value of X2.
Citation Information
Patent Citations
Radio frequency gene pool system and illegal radio wave detection system
CN111010240A
Method for automatically identifying and learning abnormal radio signal type
CN103812577A
Automatic recognition system of abnormal radio signal and method thereof
CN106936517A