Intrusion detection and defense method and system for radio management integrated platform

By collecting and cleaning data from the integrated radio management platform, establishing a malicious intrusion signature identification database, and dynamically adjusting protection strategies, the network security risks of the integrated radio management platform were resolved, enabling real-time malicious data identification and protection, and improving the platform's security and stability.

CN120916153APending Publication Date: 2025-11-07NAT RADIO MONITORING CENT CHENGDU MONITORING STATION
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511175252.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-21
Publication Date
2025-11-07

AI Technical Summary

Technical Problem

The integrated radio management platform faces cybersecurity risks. Existing intrusion detection methods are unable to adapt to its heterogeneous data characteristics and high real-time requirements, and cannot automatically adjust the protection strength, leading to misjudgments and operational instability.

Method used

Historical data from the integrated radio management platform is collected, formatted and cleaned, and a malicious intrusion data feature identification database is established. Malicious data is automatically identified through a deep learning model, and security protection strategies are dynamically adjusted to achieve real-time protection.

Benefits of technology

The integrated radio management platform enables real-time malicious data classification and identification, as well as dynamic adjustment of protection strategies, improving security and stability and meeting high real-time requirements.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120916153A_ABST
    Figure CN120916153A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of intrusion detection and defense, in particular to an intrusion detection and defense method and system for a radio management integrated platform, and the method comprises the steps: collecting historical data of the radio management integrated platform, carrying out the format normalization and data cleaning, extracting corresponding feature data from the standardized historical data, and carrying out the recognition of the feature data; judging all malicious intrusion data based on a preset rule, and learning to establish a malicious intrusion data feature recognition library; extracting feature data corresponding to the to-be-judged data, inputting the feature data into a malicious intrusion data feature recognition library, obtaining a malicious probability value of the to-be-judged data, comparing the malicious probability value with a malicious threshold value, and if the malicious probability value exceeds the malicious threshold value, judging that the to-be-judged data is malicious intrusion data; and updating the malicious intrusion data to the malicious intrusion data feature recognition library, and lowering the malicious threshold. By establishing the malicious intrusion data feature recognition library, automatic recognition of malicious intrusion data is realized, and the protection strategy is dynamically adjusted.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of intrusion detection and prevention, and in particular to an intrusion detection and prevention method and system for a radio management integrated platform. BACKGROUND

[0002] The radio management integrated platform is a general middleware platform software built by using advanced information technology under the guidance of the "basic platform + business application" and a service-oriented architecture. It is not only a collection of multiple software modules based on service-oriented architecture (SOA), but also a PaaS (Platform as a Service) platform serving radio management. The radio management integrated platform includes modules such as unified portal, unified identity, service governance, and application security. The radio management integrated platform can receive and integrate heterogeneous data output by various radio application systems, eliminate the information island effect of business and data, and realize the globalization of various radio management data resources.

[0003] However, with the rapid development of network technology, the originally independent radio management integrated platform gradually integrates with information technology, resulting in continuous network security risks. As a key part of the network security protection system of the radio management integrated platform, intrusion detection has high practical value and significance.

[0004] The existing research on the intrusion detection method for the radio management integrated platform mainly faces the following challenges: first, the radio management integrated platform and traditional information systems or the Internet have essential differences in application scenarios, objects, performance indicators, and technical requirements. The integrated platform is mainly used in radio monitoring scenarios, and it pays more attention to platform stability and the authenticity and reliability of monitoring data. At the same time, it also requires the use of as little computing power as possible to achieve smaller network latency and shorter response time. The data characteristics collected by the platform are different from those of traditional information systems or traditional Internet traffic, and there are many invalid data that do not conform to the specifications, which are difficult to store and transmit. Therefore, the intrusion detection method for traditional information systems or the Internet cannot be directly applied to the radio management integrated platform. Second, the intrusion detection technology based on traditional methods only considers the identification of malicious intrusion data traffic, but ignores the adjustment of system risk strategies after the identification of malicious intrusion data traffic. At the same time, the detection accuracy of traditional methods is not high, and false positives are easy to occur, which affects the normal operation of the radio management integrated platform. SUMMARY

[0005] To solve one of the above-mentioned problems of the prior art, the present application provides an intrusion detection and prevention method and system for a radio management integrated platform.

[0006] To achieve the above object, the application provides an intrusion detection and prevention method for a radio management integrated platform, the radio management integrated platform comprising at least one radio monitoring device, at least one radio management integrated device and at least one data storage server; the method comprising: collecting historical data of the radio management integrated platform, the historical data comprising at least communication data between the radio monitoring device and the radio management integrated device, communication data between the radio management integrated devices and communication data between the radio management integrated device and the data storage server; performing format normalization and data cleaning on the collected historical data to obtain standardized historical data; extracting corresponding feature data from the standardized historical data, judging all malicious intrusion data based on preset rules according to the extracted feature data, learning from feature data of all the malicious intrusion data and establishing a malicious intrusion data feature recognition library; obtaining real-time data as to-be-judged data, extracting feature data corresponding to the to-be-judged data, inputting the feature data of the to-be-judged data into the malicious intrusion data feature recognition library to obtain a malicious probability value of the to-be-judged data; obtaining a preset malicious threshold, comparing the malicious probability value with the malicious threshold, if the malicious probability value exceeds the malicious threshold, determining that the to-be-judged data is the malicious intrusion data; updating the feature data corresponding to the to-be-judged data determined as the malicious intrusion data to the malicious intrusion data feature recognition library, and lowering the malicious threshold.

[0007] The application further provides an intrusion detection and defense system for a radio management integrated platform, the radio management integrated platform comprising at least one radio monitoring device, at least one radio management integrated device and at least one data storage server; the system comprising: a collection module for collecting historical data of the radio management integrated platform, the historical data comprising at least communication data between the radio monitoring device and the radio management integrated device, communication data between the radio management integrated devices and communication data between the radio management integrated device and the data storage server; a data standardization module for performing format normalization and data cleaning on the collected historical data to obtain standardized historical data; an identification library establishment module for extracting corresponding feature data from the standardized historical data, judging all malicious intrusion data based on a preset rule according to the extracted feature data, learning from the feature data of all the malicious intrusion data and establishing a malicious intrusion data feature identification library; a to-be-judged data comparison module for obtaining real-time data as to-be-judged data, extracting feature data corresponding to the to-be-judged data, inputting the feature data of the to-be-judged data into the malicious intrusion data feature identification library to obtain a malicious probability value of the to-be-judged data; a malicious judgment module for obtaining a preset malicious threshold, comparing the malicious probability value with the malicious threshold, and determining that the to-be-judged data is the malicious intrusion data if the malicious probability value exceeds the malicious threshold; and a strategy management module for updating the feature data corresponding to the to-be-judged data determined as the malicious intrusion data to the malicious intrusion data feature identification library and lowering the malicious threshold.

[0008] The application provides an intrusion detection and defense method and system for a radio management integrated platform, which collects radio management integrated platform data and automatically feeds the data into an artificial intelligence model for learning, and establishes a malicious intrusion data feature identification library, thereby realizing automatic classification and identification of normal data flow and malicious intrusion data flow, dynamically adjusting a radio management integrated platform security protection strategy after identifying malicious intrusion data, and realizing real-time protection of the radio management integrated platform. The intrusion detection and defense method and system for the radio management integrated platform solve the technical defects of being unable to automatically analyze malicious data and being unable to automatically adjust the protection strength in the existing radio management integrated platform, and further meet the high real-time requirement of the radio management integrated platform for security protection. BRIEF DESCRIPTION OF DRAWINGS

[0009] Figure 1 The application provides an intrusion detection and defense method and system for a radio management integrated platform, which collects radio management integrated platform data and automatically feeds the data into an artificial intelligence model for learning, and establishes a malicious intrusion data feature identification library, thereby realizing automatic classification and identification of normal data flow and malicious intrusion data flow, dynamically adjusting a radio management integrated platform security protection strategy after identifying malicious intrusion data, and realizing real-time protection of the radio management integrated platform. The intrusion detection and defense method and system for the radio management integrated platform solve the technical defects of being unable to automatically analyze malicious data and being unable to automatically adjust the protection strength in the existing radio management integrated platform, and further meet the high real-time requirement of the radio management integrated platform for security protection. Figure 2A deep learning model structure diagram provided by the embodiment 1 of the present application; Figure 3 A structure diagram of the attention mechanism module provided by the embodiment 1 of the present application; Figure 4 A method flowchart for periodically evaluating the system provided by the embodiment 1 of the present application; Figure 5 A structure diagram of the intrusion detection and defense system for the radio management integrated platform provided by the embodiment 1 of the present application. DETAILED DESCRIPTION

[0010] The technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative work fall within the scope of the present application.

[0011] Embodiment 1 The embodiment provides an intrusion detection and defense method for a radio management integrated platform, the radio management integrated platform comprising at least one radio monitoring device, at least one radio management integrated device and at least one data storage server. The method provided by the embodiment comprises: Step S101, collecting historical data of the radio management integrated platform, the historical data at least comprising communication data between the radio monitoring device and the radio management integrated device, communication data between the radio management integrated devices, and communication data between the radio management integrated device and the data storage server; specifically, the present application mainly considers the communication data of the radio management integrated platform, and the communication data mainly occurs in the communication between the modules in the platform and the received user input information. In addition, the data of the present application can also include the state data of the platform, such as the device state. The historical data refers to the data that has occurred, and also includes the data that is currently occurring.

[0012] In addition, from the platform data type, the radio management integrated platform mainly faces massive voice data, geographic positioning data and signal data filled by monitoring personnel in the radio monitoring work, and the heterogeneous data is collected by different monitoring devices. Therefore, in an optional embodiment, the historical data can include voice data, geographic positioning data and signal data input by the radio management integrated device, and the like. Similarly, the subsequent to-be-judged data can also include the above data types.

[0013] In an optional embodiment, the following two methods can be used to extract the historical data flow set from the radio management integrated platform (including malicious intrusion data flow and normal data flow, and the malicious intrusion data flow mainly refers to the flow affecting the stability of the platform operation): on the one hand, the original data acquisition system of the radio management integrated platform can be used to obtain system operation logs through a man-machine interface or a hardware device and perform format conversion to obtain; on the other hand, data flow sniffing software can be deployed in the data transmission path of the radio management integrated platform to directly obtain and convert the data generated by the radio management integrated platform. The first method has less impact on the original platform operation; the data obtained by the second method has higher real-time performance. The two methods can be used separately or together according to the specific situation.

[0014] In step S102, the collected historical data is normalized and cleaned to obtain standardized historical data; since the heterogeneous data of the radio management integrated platform is collected by different monitoring devices, data cleaning is needed before being used for subsequent training. Specifically, the data flow set can be normalized and cleaned, invalid and blank data can be removed and missing data can be completed to obtain a training set that can be directly used for artificial intelligence model training . In an optional embodiment, according to the running state of the radio management integrated platform at different times, the platform response time, response delay, packet loss rate and bandwidth utilization rate and other indicators are set as different columns, and the specific time is added at the end of the row, then the platform running state at multiple times can be constructed into a table form of artificial intelligence training set, and the artificial intelligence model takes this form of training set as input, and the output is the probability value of judging whether the specific flow is malicious intrusion data.

[0015] Step S103, corresponding feature data is extracted from the standardized historical data, all malicious intrusion data is judged based on the preset rules according to the extracted feature data, and a malicious intrusion data feature recognition library is established according to the feature data of all malicious intrusion data; specifically, the user sets the preset rule as the benchmark of malicious intrusion data to mark the data as malicious or normal data, or collects the user's marking results of malicious data. According to different radio data storage protocols, the system historical data and the current system state can be integrated into a unified format data packet, and the data can be marked, or the unmarked data can be used to train an unsupervised deep learning model, for example, the minimum mean algorithm is used to directly distinguish the data into normal data flow and malicious intrusion data flow. The deep learning classification model based on attention mechanism can be preliminarily trained based on the historical traffic data, and the output model is the malicious intrusion data feature recognition library fitted based on the historical traffic data. The malicious intrusion data feature recognition library takes platform data as input data and automatically identifies malicious data flow, and outputs the probability value of the data as malicious intrusion data.

[0016] In a specific embodiment, for the obtained platform data , learning is performed by the following method to determine the output value of the malicious intrusion data feature recognition library: Wherein, represents the input platform data (which can be standardized historical data), represents the output malicious probability value, is the feature value of the data obtained by the deep learning model. Wherein , , respectively represent the linear output module, the attention mechanism module and the convolution network module in the deep learning model, and the input of the deep learning model is the training data. According to the data, the back propagation algorithm is run to fit the function, and the purpose of minimizing the loss function is achieved. The output of conv is directly sent to the attention mechanism, as shown in Figure 2 . The structural diagram of the attention mechanism module is shown in Figure 3 . The attention mechanism can effectively extract the features in the text and voice data, and is suitable for data recognition of the radio management integrated platform. The calculation formulas of the above deep learning model are as follows: ; ; ; Wherein, represents the input; , is a non-zero constant; is a normalization function, is a parameter of the normalization function; , , are three attention matrices, which are three learnable matrices in deep learning, and the initial value is set to 0; is the transpose matrix of ; represents the convolution kernel size; represents the convolution padding; represents the convolution stride. The trainable parameters in the model parameters can be automatically adjusted according to the training data set and the model output using the back propagation algorithm, and the calculation formula is as follows: ; ; wherein, L indicates the mean square error. The neural network output is adjusted by using the partial derivative value of the mean square error and the actual data in the above formula, but only for the case where the malicious data has been automatically labeled by the feature library.

[0017] Step S104, real-time data is obtained as the to-be-judged data, the feature data corresponding to the to-be-judged data is extracted, the feature data of the to-be-judged data is input into the malicious intrusion data feature recognition library, and the malicious probability value of the to-be-judged data is obtained; for example, according to the malicious intrusion data feature recognition library established in the foregoing, a specific to-be-judged data is known, the malicious intrusion data feature recognition library will judge the specific to-be-judged data based on the learned malicious intrusion data features, and finally output a malicious probability value. The malicious probability value represents the probability that the specific to-be-judged data output by the recognition library is malicious intrusion data.

[0018] Step S105, a preset malicious threshold is obtained, and the malicious probability value is compared with the malicious threshold. If the malicious probability value exceeds the malicious threshold, the to-be-judged data is determined as malicious intrusion data; specifically, for data if there is: ; wherein, indicates the current preset malicious threshold of the system, and the initial value is generally set to 0.9, which means that the malicious intrusion data feature recognition library considers that 90% of the malicious traffic will be rejected, thereby ensuring the stability of the platform while ensuring the security of the platform. In addition, this threshold can be initialized by the user when the system starts. If it is necessary to strengthen the protection of the platform, the malicious threshold is appropriately lowered, which will make more traffic be rejected.

[0019] Step S106, the feature data corresponding to the to-be-judged data determined as malicious intrusion data is updated to the malicious intrusion data feature identification library, and the malicious threshold is lowered. Specifically, the following formula can be used to adjust the data threshold during system operation: ; When is less than 0.5, that is, it is more likely to be normal data traffic, the algorithm will raise the malicious threshold to release more data traffic, indicating that the platform is not under attack; similarly, when is greater than 0.5, it means it is likely to be malicious intrusion data, and the algorithm will lower the malicious threshold to intercept more data traffic, at which time the system may be under attack. At the same time, the data will be sent to the malicious intrusion data feature identification library for subsequent processing. The data traffic is sent to the artificial intelligence model for learning, and the data traffic features obtained after learning are added to the malicious intrusion data feature identification library.

[0020] The radio management integrated platform intrusion detection and defense method provided in the embodiment realizes automatic classification and identification of normal data traffic and malicious intrusion data traffic, and dynamically adjusts the security protection strategy of the radio management integrated platform after identifying the malicious intrusion data, so as to realize real-time protection of the radio management integrated platform. The radio management integrated platform intrusion detection and defense method of the embodiment solves the technical defects that the existing radio management integrated platform cannot automatically analyze malicious data and cannot automatically adjust the protection strength, and further meets the high real-time requirement of the radio management integrated platform for security defense.

[0021] In an optional implementation, the radio management integrated platform intrusion detection and defense method of the embodiment can further include: Step S107, monitoring in a preset monitoring period, if the to-be-judged data determined as malicious intrusion data meets a preset risk condition, at least adjusting the malicious threshold according to a preset first adjustment mode. Specifically, according to the risk threshold set by the user in advance, if the amount of malicious intrusion data exceeds the threshold, the integrated platform will be determined as risky; if the platform is determined as risky, the model will increase the sensitivity of malicious intrusion data, that is, part of the data with low similarity to malicious intrusion data will also be determined as malicious data, and measures such as interception will be taken to protect the data security. By comprehensively considering the security requirements and real-time requirements of the user, according to the identified normal data flow and malicious intrusion data flow, and the security requirements of the user, the wireless radio management integrated platform security protection strategy is dynamically adjusted to achieve the best protection effect.

[0022] In one specific embodiment, the preset risk condition is: ; Wherein, is the to-be-judged data, is the malicious probability value of the to-be-judged data, is the preset risk threshold, is the malicious threshold, and is the start time and end time of the preset monitoring period. By setting this risk condition formula, the control of the risk condition can be quantified, and the system can be accurately managed.

[0023] In one specific embodiment, at least the malicious threshold is adjusted according to the preset first adjustment mode, specifically including: adjusting the risk threshold and the malicious threshold according to the following mode . : ; .

[0024] In a short time after the system is determined as risky, the malicious threshold will be set to an extremely low value depending on the preset monitoring period interval, at this time almost all data flow will be determined as malicious data, and measures such as interception will be taken to protect the system security, and the risk threshold will be increased, so that the system is in a malicious data sensitive period in the next period of time, that is, the system is more inclined to be considered as risky. By comprehensively considering the security requirements and real-time requirements of the user, the wireless radio management integrated platform security protection strategy is dynamically adjusted to achieve comprehensive defense of the wireless radio management integrated platform security.

[0025] In one optional embodiment, the intrusion detection and defense method for the wireless radio management integrated platform of the present embodiment can further include: Step S108: If no data to be judged is identified as malicious intrusion data within the preset monitoring period, the risk threshold is adjusted according to the following second adjustment method. and malicious threshold Adjustments will be made: in, and This indicates the set adjustment parameters, with a default value of zero. If the platform fails to detect malicious intrusion data within a certain period or if the user manually adjusts the system settings, the model's sensitivity to malicious intrusion data will be increased. Simultaneously, data with low similarity in the malicious intrusion data feature database can be removed. Through these methods, risk thresholds and malicious thresholds can be dynamically restored after the risk is mitigated, ensuring the platform's normal operation and reducing data loss.

[0026] Therefore, in an optional implementation, the intrusion detection and defense method for an integrated radio management platform of this embodiment may further include: Step S109: Scan the malicious intrusion data feature identification database. If any data in the malicious intrusion data feature identification database... If both of the following conditions are met, then the data will be... Removed from the malicious intrusion data signature identification database: in, This is the malicious threshold before adjustment. After the risk is eliminated, the above method can be used to remove data that was previously misjudged as malicious intrusion data from the identification database, ensuring the accuracy of the malicious intrusion data feature identification database, preventing it from affecting subsequent judgment results, and enabling the system to operate stably.

[0027] In an optional implementation, the intrusion detection and prevention method for the integrated radio management platform of this embodiment may further include a method for periodically evaluating the system. By periodically outputting a score value of the security status of the entire integrated radio management platform, the system's security and stability can be improved while ensuring its availability and computational efficiency. Figure 4 As shown, the specific implementation steps include: Step S401: Determine a reference value for the frequency of malicious attacks based on the number of pending data identified as malicious intrusion data within a preset monitoring period; specifically, the reference value for the frequency of malicious attacks can be determined according to the following formula. : ; Step S402: Determine the current security score of the integrated radio management platform based on the current reference value for the frequency of malicious attacks and the reference value for the frequency of past malicious attacks; specifically, determine the current security score of the integrated radio management platform according to the following formula. : ; in, This refers to the total operating time of the integrated radio management platform to date. This refers to a reference value for the frequency of malicious attacks currently occurring on the integrated radio management platform. This refers to the reference value for the frequency of all malicious attacks recorded in the history of the integrated radio management platform.

[0028] Step S403: Periodically output the current security score value at time intervals.

[0029] Through such Figure 4 The periodic scoring system shown not only ensures the security of the integrated radio management platform but also automatically analyzes and reviews its security weaknesses, helping to improve the platform's security and stability with minimal performance cost. It periodically provides scores on whether the platform has been subjected to excessively frequent malicious intrusion data traffic attacks, outputting the results intuitively on a percentage basis. It can also prompt users to adjust the malicious threshold and use more malicious intrusion data traffic to train the deep learning model.

[0030] This embodiment also provides an intrusion detection and prevention system for an integrated radio management platform. The integrated radio management platform includes at least one radio monitoring device, at least one integrated radio management device, and at least one data storage server. The intrusion detection and prevention system for the integrated radio management platform in this embodiment is used to run the aforementioned intrusion detection and prevention method for the integrated radio management platform. The content already described in the method section will not be repeated here; only the architecture of the intrusion detection and prevention system for the integrated radio management platform will be briefly described. Figure 5 As shown, the intrusion detection and prevention system for an integrated radio management platform in this embodiment includes: The acquisition module 501 is used to acquire historical data from the integrated radio management platform. The historical data includes at least the following: communication data between the radio monitoring equipment and the integrated radio management equipment, communication data between the integrated radio management equipment, and communication data between the integrated radio management equipment and the data storage server. The data standardization module 502 is used to normalize the format and clean the collected historical data to obtain standardized historical data. The recognition library establishing module 503 is configured to extract corresponding feature data from the standardized historical data, judge all malicious intrusion data based on preset rules according to the extracted feature data, and learn from the feature data of all malicious intrusion data and establish a malicious intrusion data feature recognition library; The data to be judged comparison module 504 is configured to obtain real-time data as data to be judged, extract feature data corresponding to the data to be judged, input the feature data of the data to be judged into the malicious intrusion data feature recognition library, and obtain a malicious probability value of the data to be judged; The malicious judgment module 505 is configured to obtain a preset malicious threshold, compare the malicious probability value with the malicious threshold, and determine that the data to be judged is malicious intrusion data if the malicious probability value exceeds the malicious threshold. The strategy management module 506 is configured to update the feature data corresponding to the data to be judged determined as malicious intrusion data to the malicious intrusion data feature recognition library, and lower the malicious threshold.

[0031] The intrusion detection and defense system for the radio management integrated platform provided in the embodiment realizes automatic classification and identification of normal data flow and malicious intrusion data flow, dynamically adjusts the security protection strategy of the radio management integrated platform after identifying the malicious intrusion data, so as to realize real-time protection of the radio management integrated platform. The intrusion detection and defense system for the radio management integrated platform solves the technical defects that malicious data cannot be automatically analyzed and the protection strength cannot be automatically adjusted in the existing radio management integrated platform, and further meets the high real-time requirement of the radio management integrated platform for security protection.

[0032] In the description of the embodiments of the present application, it should be understood that the terms "upper", "lower", "front", "back", "left", "right", "vertical", "horizontal", "center", "top", "bottom", "top", "bottom", "inner", "outer", "inner side", "outer side" and the like indicate the orientation or positional relationship based on the orientation or positional relationship shown in the drawings, and are only for the convenience of describing the present application and simplifying the description, and do not indicate or imply that the devices or elements referred to must have a particular orientation, be constructed and operated in a particular orientation, and therefore cannot be understood as a limitation on the present application. Among them, "inboard" refers to the interior or enclosed area or space. "Periphery" refers to the area around a particular component or a particular area.

[0033] In the description of the embodiments of the present application, the terms "first", "second", "third", "fourth" are used only to describe purposes, and cannot be understood as indicating or implying relative importance or implicitly indicating the number of indicated technical features. Therefore, the features defined with "first", "second", "third", "fourth" can be explicitly or implicitly included one or more of the features. In the description of the present application, unless otherwise specified, the meaning of "a plurality of" is two or more.

[0034] In the description of the embodiments of the present application, it should be noted that, unless otherwise explicitly specified and limited, the terms "mounting", "connecting", "connecting", "assembling" should be understood broadly, for example, it can be fixedly connected, or it can be detachably connected, or integrally connected; it can be directly connected, or indirectly connected through an intermediate medium, or it can be the communication inside two elements. For those skilled in the art, the specific meaning of the above terms in the present application can be understood according to the specific circumstances.

[0035] In the description of the embodiments of the present application, specific features, structures, materials or characteristics can be combined in any one or more embodiments or examples in a suitable manner.

[0036] In the description of the embodiments of the present application, it should be understood that "-" and "~" represent the range between two values, and the range includes the endpoints. For example: "A-B" represents a range greater than or equal to A and less than or equal to B. "A~B" represents a range greater than or equal to A and less than or equal to B.

[0037] In the description of the embodiments of the present application, the term "and / or" herein is only a description of the association relationship between the associated objects, which means that there can be three relationships, for example, A and / or B, which can represent three cases of A alone, A and B together, and B alone. In addition, the character " / " herein generally represents that the front and rear associated objects are a "or" relationship.

[0038] Although the embodiments of the present application have been shown and described, it can be understood by those skilled in the art that various changes, modifications, replacements and variations can be made to the embodiments without departing from the principles and spirits of the present application, and the scope of the present application is defined by the appended claims and their equivalents.

Claims

1. A radio management integration platform-oriented intrusion detection and prevention method, characterized by, The radio management integrated platform comprises at least one radio monitoring device, at least one radio management integrated device and at least one data storage server; the method comprises: Collecting historical data of the radio management integrated platform, the historical data at least comprising communication data between the radio monitoring device and the radio management integrated device, communication data between the radio management integrated devices, and communication data between the radio management integrated device and the data storage server; Normalizing the format and cleaning the data of the collected historical data to obtain standardized historical data; Extracting corresponding feature data from the standardized historical data, judging all malicious intrusion data based on preset rules according to the extracted feature data, learning from the feature data of all the malicious intrusion data and establishing a malicious intrusion data feature recognition library; Obtaining real-time data as to-be-judged data, extracting the feature data corresponding to the to-be-judged data, inputting the feature data of the to-be-judged data into the malicious intrusion data feature recognition library, and obtaining a malicious probability value of the to-be-judged data; Obtaining a preset malicious threshold, comparing the malicious probability value with the malicious threshold, and determining that the to-be-judged data is the malicious intrusion data if the malicious probability value exceeds the malicious threshold; Updating the feature data corresponding to the to-be-judged data determined as the malicious intrusion data to the malicious intrusion data feature recognition library, and lowering the malicious threshold.

2. The radio management integrated platform-oriented intrusion detection and prevention method of claim 1, wherein, The historical data and the to-be-judged data comprise sound data, geographical positioning data and signal data received by the radio management integrated device. 3.The radio management integrated platform-oriented intrusion detection and prevention method according to claim 1, wherein, The method further comprises: Monitoring within a preset monitoring period, and adjusting at least the malicious threshold according to a preset first adjustment mode if the to-be-judged data determined as the malicious intrusion data meets a preset risk condition.

4. The radio management integrated platform-oriented intrusion detection and prevention method of claim 3, wherein, The preset risk condition is: ; wherein, is the data to be judged, is a malicious probability value of the data to be judged, is a preset risk threshold value, is a malicious threshold value, and are a start time and an end time of the preset monitoring period.

5. The radio management integrated platform-oriented intrusion detection and prevention method of claim 4, wherein, The adjustment of at least the malicious threshold according to the preset first adjustment mode specifically comprises: The risk threshold is adjusted according to the following manner and the malicious threshold : ; 。 6. The radio management integrated platform-oriented intrusion detection and prevention method of claim 1, wherein, The method further comprises: If the to-be-judged data is not determined as the malicious intrusion data within the preset monitoring period, the risk threshold and the malicious threshold are adjusted in the following second adjustment mode: and the malicious threshold ​ wherein and denotes a set adjustment parameter, with a default value of zero.

7. The radio management integrated platform-oriented intrusion detection and prevention method of claim 6, wherein, The method further comprises: scanning the malicious intrusion data signature library, if any data Both of the following conditions are met, the data deleting from the malicious intrusion data signature library: wherein, is the pre-adjusted malicious threshold.

8. The radio management integrated platform-oriented intrusion detection and prevention method of claim 1, wherein, The method further comprises: Determining a malicious attack frequency reference value according to the number of to-be-judged data determined as the malicious intrusion data within the preset monitoring period; Determining a current security score value of the radio management integrated platform according to the current malicious attack frequency reference value and the previous malicious attack frequency reference value; Periodically outputting the current security score value at a time interval.

9. The radio management integrated platform-oriented intrusion detection and prevention method of claim 8, wherein, The method further comprises: The malicious attack frequency reference value is determined according to the following formula : ; The current security score value of the radio management integrated platform is determined according to the following formula : ; wherein, denotes the time the radio management integration platform has been running so far, denotes the current malicious attack frequency reference value of the radio management integration platform, denotes all the malicious attack frequency reference values of the radio management integration platform history.

10. A radio management integrated platform oriented intrusion detection and prevention system, characterized by, The radio management integrated platform comprises at least one radio monitoring device, at least one radio management integrated device and at least one data storage server; the system comprises: A collecting module for collecting historical data of the radio management integrated platform, the historical data at least comprising communication data between the radio monitoring device and the radio management integrated device, communication data between the radio management integrated devices, and communication data between the radio management integrated device and the data storage server; A data standardization module is configured to normalize the format of the collected historical data and clean the data to obtain standardized historical data; A recognition library establishing module is configured to extract corresponding feature data from the standardized historical data, determine all malicious intrusion data based on a preset rule according to the extracted feature data, and learn from the feature data of all the malicious intrusion data and establish a malicious intrusion data feature recognition library; A to-be-judged data comparison module is configured to obtain real-time data as to-be-judged data, extract feature data corresponding to the to-be-judged data, input the feature data of the to-be-judged data into the malicious intrusion data feature recognition library, and obtain a malicious probability value of the to-be-judged data; A malicious judgment module is configured to obtain a preset malicious threshold, compare the malicious probability value with the malicious threshold, and determine that the to-be-judged data is the malicious intrusion data if the malicious probability value exceeds the malicious threshold; A policy management module is configured to update the feature data corresponding to the to-be-judged data determined as the malicious intrusion data to the malicious intrusion data feature recognition library, and lower the malicious threshold.