Internet telephone system abnormal behavior diagnosis method based on finite state automaton

By constructing a finite state automaton model and using an expansion factor to handle intermittent observation loss in the Internet telephony system, the problem of collaborative diagnosis of abnormal behavior under DoS attacks was solved, achieving efficient detection and repair of abnormal behavior.

CN121037033APending Publication Date: 2025-11-28NANJING UNIV OF POSTS & TELECOMM
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511146194.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-15
Publication Date
2025-11-28

AI Technical Summary

Technical Problem

Existing technologies in Internet telephony systems, especially under DoS attacks, struggle to perform effective collaborative diagnosis of abnormal behavior in cases of intermittent loss of observations. This results in diagnostic tools being unable to accurately determine the system status and may even issue incorrect diagnostic decisions.

Method used

A finite state automaton-based approach is used to construct a baseline model GN for non-abnormal behavior and a model GF for abnormal behavior. An expansion factor is used to handle the intermittent observation loss of the local diagnostic tool, and a distributed abnormal behavior validator GV is constructed. The cooperative diagnosticability of the system's abnormal behavior is determined by judging whether the validator has a violation cycle.

Benefits of technology

In cases of intermittent observation loss, this method improves the diagnostic accuracy of abnormal behavior in Internet telephony systems, reduces the computational complexity of large-scale systems, and improves the efficiency of repairing abnormal behavior.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121037033A_ABST
    Figure CN121037033A_ABST
Patent Text Reader

Abstract

The invention discloses an internet telephone system abnormal behavior diagnosis method based on a finite state automaton, which comprises the following steps of: modeling the operation of an internet telephone system into a finite state automaton model, constructing an automaton with only one state, and performing product operation on the automaton and the finite state automaton model to obtain a non-abnormal behavior reference model; constructing an automaton with an abnormal behavior label, carrying out parallel combination operation on the automaton and the finite state automaton model to obtain an abnormal behavior model, setting a plurality of local diagnosers, and converting a non-abnormal behavior reference model into a non-abnormal behavior expansion model under the condition of intermittent observation loss, carrying out parallel combination operation on the abnormal behavior model and a plurality of non-abnormal behavior expansion models, judging whether the obtained distributed abnormal behavior verifier has illegal circulation or not, and analyzing step calculation complexity of the obtained distributed abnormal behavior verifier; according to the invention, distributed abnormal behavior diagnosis under the condition of intermittent observation loss can be realized.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to a communication abnormal behavior diagnosis method, and in particular to an Internet telephone system abnormal behavior diagnosis method based on finite state automata. BACKGROUND

[0002] In the Internet telephone protocol (VoIP), a typical voice call communication includes two stages of signaling and data transmission. The signaling is used to establish and maintain the end-to-end Internet call, and the actual data transmission is usually carried out in different sessions. Internet telephones can use a series of protocols (H.323, SIP) for signaling purposes. The Session Initiation Protocol (SIP) is an application layer signaling protocol for Internet telephones. It is used to establish, modify and terminate multimedia sessions between two Internet telephone clients (also known as user agents). SIP is a text-based protocol and is vulnerable to a series of denial-of-service (DoS) attacks that consume memory and CPU time, causing SIP servers or SIP proxy servers to be unavailable. In turn, this completely disrupts the communication between VoIP servers, making them unavailable. Therefore, it is very important to detect these denial-of-service attacks.

[0003] The system size is gradually increasing now, so almost all systems have a modular structure. In general, a system includes several modules, local components or subsystems, and these components can themselves contain several smaller independent modules. Such systems with a modular structure usually have a relatively large state space, and due to the problem of spatial complexity, centralized diagnosis of such systems is not only complex to operate, but also quite difficult to diagnose in an overall manner. Therefore, some subsequent scholars have proposed various expansion and improvement methods, one of which is the decentralized diagnosis method. Decentralized diagnosis refers to the deployment of several diagnostic devices, each with its own set of sensors, and there is no communication or coordinator between them.

[0004] In practical applications, the diagnosis of abnormal behavior of discrete event systems is usually performed by a deterministic automaton, called a diagnoser. It is designed based on the model of the physical system, assuming that not only all sensors work properly, but also all information delivered by the sensors always arrives correctly at the diagnoser. However, bad operation can cause a sensor to fail to report the occurrence of an event, or a bad electrical connection in the communication channel can cause the loss of communication between the sensor and the diagnoser. In this case, the diagnoser fails to observe the occurrence of part of the events, which is called intermittent observation loss. When intermittent observation loss occurs, the diagnoser can get stuck in a certain state or even make false diagnostic decisions due to the lack of observed events or the occurrence of events that are not in the event set of its current state. This shows that it is more meaningful and challenging to study the decentralized abnormal behavior collaborative diagnosability in the case of intermittent observation loss. SUMMARY

[0005] The present application provides a method for determining the abnormal behavior collaborative diagnosability of an Internet telephone system under intermittent observation loss.

[0006] Technical scheme: The Internet telephone system abnormal behavior diagnosis method based on finite state automaton provided by the present application comprises:

[0007] (1) modeling the operation of the Internet telephone system as a finite state automaton model G=(X,∑,f,x0), wherein X represents a state set, ∑ represents an event set, f represents a state transition function, and x0 represents an initial state;

[0008] (2) constructing an automaton with only one state, and performing a product operation on the finite state automaton model to obtain a non-abnormal behavior benchmark model G N ;

[0009] (3) constructing an automaton with an abnormal behavior label, and performing a parallel combination operation on the finite state automaton model to obtain an abnormal behavior model G F ;

[0010] (4) setting multiple local diagnosers, setting a label factor under intermittent observation loss, and converting the non-abnormal behavior benchmark model G N into a non-abnormal behavior expansion model G N,i ;

[0011] (5) performing a parallel combination operation on the abnormal behavior model G F and the multiple non-abnormal behavior expansion models G N,i to obtain a decentralized abnormal behavior verifier G V ;

[0012] (6) Determine whether there is a violation of the cycle, if there is, determine that the Internet telephone system is abnormal behavior of the cooperative diagnosis of non-diagnosable, otherwise determine that the abnormal behavior of the cooperative diagnosis.

[0013] (7) Analysis of the above obtained verifier G V Step complexity.

[0014] Further, the non-abnormal behavior model G N :

[0015] First, define the non-abnormal behavior event set Σ N = Σ\S f , Σ f represent the set of abnormal behavior events, second, construct a finite automaton A N with only one state, mark the only state as N, state N is directly returned to the state under the driving of any event in Σ N , thus forming a loop, finally, G and A N Non-abnormal behavior reference model G N is constructed by the complete parallel combination operator, that is, G N = A N XG = (X N , Σ N , f N , x 0,N ) where the symbol X represents the complete parallel combination operator.

[0016] Further, the abnormal behavior model G F = CoAc(G x A L ) in step (3):

[0017] (3-1) Define abnormal behavior finite state automaton A l = (X l , Σ f , f l , x 0,l ), where X l = {N, F}, F represents the state of the system after suffering DoS attack, called abnormal behavior state. x 0,l = {N} represents the initial state of A l is a safe state, f l represents the state transition function of A l , f l and F satisfy the following conditions: for any σ f ∈ Σ f , f l (N, σ f ) = F and f l (F, σ f ) = F, fl (A, Ω) represents a state A reached by event Ω.

[0018] (3-2) Finite state automaton model G is combined with A l Automaton G is obtained by parallel combination operator l , i.e. G l = G || A l , where the symbol || represents the parallel combination operator, and its calculation formula is:

[0019] G * || G # = Ac(X * × X # , Σ * ∪ Σ # , f *# , (x 0,* , x 0,# )) (1),

[0020] In the formula, G * = (X * , Σ * , f * , x 0,* ), X * , Σ * , f * , x 0,* are the state set, event set, transition function, initial state of automaton G * , respectively, G # = (X # , Σ # , f # , x 0,# ), X # , Σ # , f # , x 0,# are the state set, event set, transition function, initial state of automaton G # , respectively, Ac() represents all states and event trajectories reachable from the initial state x 0,# , and the calculation formula of f *。 is: for any (x * , x # ) ∈ X * × X # , σ ∈ Σ * ∪ Σ # ,

[0021]

[0022] (3-3) G F = CoAc(G l) represents the part left after deleting all states that are not reachable from the initial state G l

[0023] Further, in the case of intermittent observation loss in the local diagnoser in step (4):

[0024] (4-1) Let Σ i = Σ N , so Σ i = Σ o,i ∪ Σ uo,i , where Σ o,i represents the set of observable events in the i-th local diagnoser, and Σ uo,i represents the set of unobservable events in the i-th local diagnoser. Let Σ be a finite event set, and let Σ * represent the set consisting of all finite strings in Σ, and let ε represent an empty event, where ε∈Σ * , and the mapping is defined as:

[0025]

[0026] Now consider the case of intermittent observation loss in partially observable events. Let Σ ilo,i represent the set of observable events related to intermittent observation loss in the i-th local diagnoser, and let Σ nilo,i represent the set of observable events unrelated to intermittent observation loss in the i-th local diagnoser, then Σ i = Σ ilo,i ∪ Σ nilo,i ∪ Σ uo,i . To characterize the nature of intermittent observation loss, define the expansion factor:

[0027]

[0028] Define a set for the expansion factor: The events in the set satisfy:

[0029] (4-2) Construct the non-abnormal behavior expansion model G N,i = (X N , Σ N,i , f N,i , x 0,N ), i = {1, 2,..., ND}, where f N,i is defined as follows: for any σ∈Σ nilo,i , x∈X N , f N,i (x, σ) = f N (x, σ); for any​ There are

[0030] Further, the step (5) of constructing the distributed abnormal behavior verifier is:

[0031]

[0032] The state X V =(X N,1 ,X N,2 ,...,X N,ND ,X F ), X N,1 ,X N,2 ,...,X N,ND ,X F are states in G N,1 ,G N,2 ,...,G N,2 ,G F respectively, and X F =(X,X l ), X,X l are states in G,A l respectively.

[0033] In constructing the distributed abnormal behavior verifier, there is no positive way to calculate and compare the complex condition "whether all the diagnosers see the same thing", i.e. ([P1(σ) = P1(σ1), P2(σ) = P2(σ2)]). Instead, by pre-labeling the unobservable events with diagnoser-specific tags and requiring all components (including the abnormal behavior model and the non-abnormal behavior expansion model) in the verifier to be executed synchronously through parallel composition operators, that complex global observation equivalence condition which needs to be checked explicitly is successfully removed, and only the problem of searching for a violation cycle in the distributed abnormal behavior verifier is left.

[0034] Further, the step (6) of determining the abnormal behavior collaborative diagnosability is:

[0035] (6-1) Determine whether there is a cycle in the verifier according to the following method:

[0036] If there is a path in the verifier, which satisfies then the path is called a cycle pa, where denotes the i-th state of the verifier G V .

[0037] (6-2) Determine whether the cycle satisfies the following condition, and if so, determine that it is a violation cycle:

[0038] For there is a state satisfy

[0039] (6-3) If the distributed abnormal behavior verifier has a violation loop, the system is determined to be abnormal behavior collaboratively undiagnosable; otherwise, it is determined to be abnormal behavior collaboratively diagnosable.

[0040] Furthermore, the complexity in step (7) is determined by analyzing the distributed anomalous behavior validator G. V The size of the state space and event set required for each step is determined;

[0041] The second step is to construct a single-state automaton A. N And calculate the baseline model G for non-abnormal behavior. N Because A N It is a symbol marked Σ N =Σ\Σ f A self-looping single-state automaton, then G... N The maximum number of states and the number of transitions are |X| and |X|×(|Σ|-|Σ), respectively. f |);

[0042] The third step is to construct the abnormal behavior model G. F Therefore, we first need to construct a finite state automaton A with two states N and F that exhibits abnormal behavior. l Its transfer is only caused by anomalous behavioral events, and then G is obtained. l =G||A l Note G l The state is equal to (x,N) or (x,F), where x∈X, G l The maximum number of states is 2|X|, and the abnormal behavior model G F =CoAc(G l In the worst-case scenario, G F The number of states and the number of transitions are 2|X| and 2|X|×|Σ|, respectively;

[0043] In the fourth step, the expansion factor R is used. i By renaming the unobservable events for each local diagnostic tool and expanding the observable events associated with intermittent observation loss, a non-abnormal behavior expansion model G is obtained. N,i G N,i The number of states and the number of transitions are |X| and , respectively.

[0044] Finally, the fifth step is to build a distributed anomalous behavior validator G. V =(|| i={1,2,...,ND} G N,i )||G F Because of G N,i and GF The state number of G is most |X| and 2|X| respectively, then G V The state number of G is most |X| and 2|X| respectively, then G m+1 Wherein m represents the number of the diagnostic apparatuses, in addition, G V The maximum transition number of G is:

[0045]

[0046] The complexity is This shows that the method presents linear complexity on the transition number of each state

[0047] Compared with the prior art, the beneficial effects of the present application are: the present application constructs a non-abnormal behavior expansion model (G N,i ) by setting an expansion factor, effectively depicts the characteristics of intermittent observation loss, solves the problem of decline of diagnostic precision of the traditional diagnostic method in the incomplete observation scene, and is more suitable for the actual operation of the complex network environment. In addition, through complexity analysis, although the verifier state number presents exponential (2|X| m+1 ), the calculation complexity of each state transition remains linear O(|Σ|), the calculation complexity of processing large-scale Internet telephone system abnormal behavior is reduced, and the system abnormal behavior repair efficiency is improved. BRIEF DESCRIPTION OF DRAWINGS

[0048] Figure 1 It is a flowchart of the present application;

[0049] Figure 2 It is an Internet telephone system diagram;

[0050] Figure 3 It is a finite state automaton G model diagram corresponding to the Internet telephone system;

[0051] Figure 4 It is an abnormal behavior model diagram corresponding to the Internet telephone system ( Figure 3 );

[0052] Part a of Fig. 5 is a schematic diagram of a non-abnormal behavior expansion model R1 corresponding to the Internet telephone system ( Figure 3 ), and part b of Fig. 5 is a schematic diagram of a non-abnormal behavior expansion model R2 corresponding to the Internet telephone system ( Figure 3 );

[0053] Figure 6 It is a schematic diagram of a distributed abnormal behavior verifier corresponding to the Internet telephone system ( Figure 3 ). DETAILED DESCRIPTION

[0054] The embodiment is a method for diagnosing abnormal behavior of an Internet telephone system based on a finite state automaton, which comprises the following steps as shown in the figure: Figure 1

[0055] (1) modeling the operation of the Internet telephone system as a finite state automaton model G=(X,∑,f,x0), wherein X represents a state set, ∑ represents an event set, f represents a state transition function, and x0 represents an initial state.

[0056] The Internet telephone system of the present example is shown in the figure Figure 2 A typical SIP session starts with the calling party sending an invite message. When the invite message reaches the called party, the called party starts ringing and sends a Ringing message. If the called party accepts the call, the called party handset sends a 200 (OK) response, otherwise an error response will be sent. After the calling party handset receives the OK response, the calling party handset sends an ACK confirmation. In this way, the INVITE / 200 / ACK three-way handshake for establishing a SIP session is completed. After that, the media session starts. When the call is to be ended, either of the two calling parties can send a Bye message to request the call to be ended. The other calling party will respond with a 200 (OK).

[0057] In the Internet telephone system, network congestion or poor link quality can cause intermittent loss of system messages (such as Invite and Bye). Therefore, two local observers R1 and R2 can be set up to observe Invite and Bye messages respectively. The essence of abnormal behavior diagnosis is that if, for any trajectory with abnormal behavior, the observation trajectory corresponding thereto is different from the observation of any trajectory without abnormal behavior within a limited observation length, then it is called abnormal behavior co-diagnosable.

[0058] (2) constructing an automaton A N with only one state, and performing a product operation with the finite state automaton model to obtain a non-abnormal behavior benchmark model G N :

[0059] The construction method of the non-abnormal behavior benchmark model G N is as follows: first, define a non-abnormal behavior event set ∑ N =∑\∑ f , wherein ∑ f represents an abnormal behavior event set, second, construct a finite automaton A N with only one state, and mark the only state as N. The state N directly returns to the state under the driving of any event in ∑ N , thereby forming a self-loop, and finally, construct the non-abnormal behavior benchmark model G N from G and A N through a complete parallel combination operator, i.e. G​N = A N XG = (X N ,∑ N ,f N ,x 0,N ) where the symbol X represents the product operator.

[0060] (3) Construct an automaton A with an abnormal behavior label F , and combine it in parallel with the finite state automaton model G to obtain the abnormal behavior model G F = CoAc(G x A l ):

[0061] (3-1) Define the abnormal behavior finite state automaton A l = (X l ,∑ f ,f l ,x 0,l ), where X l = {N, F}, F represents the state of the system after being attacked by DoS, which is called the abnormal behavior state. x 0,l = {N} represents that the initial state of A l is a safe state, f l represents the state transition function of A l , f l and F satisfy the following conditions: for any σ f ∈∑ f , f l (N, σ f ) = F and f l (F, σ f ) = F, f l (△, Ω) represents the state reached by the state △ through the event Ω.

[0062] (3-2) Combine the finite state automaton model G with A l through the parallel composition operator to obtain the automaton G l , that is, G l = G || A l , where the symbol || represents the parallel composition operator, and its calculation formula is:

[0063] G * || G # = Ac(X * x X # ,∑ * ∪∑ # ,f *# ,(x 0,* ,x 0,# ) (1),

[0064] wherein, the automaton G* =(X * ,Σ * ,f * ,x 0,* ), X * ,Σ * ,f * ,x 0,* They are respectively automata G * State set, event set, transition function, initial state, automaton G # =(X # ,Σ # ,f # ,x 0,# ), X # ,Σ # ,f # ,x 0,# They are respectively automata G # The set of states, the set of events, the transition function, and the initial state; Ac() represents taking the initial state x. 0,# All achievable states and their event trajectories, f *。 The calculation formula is: for any (x) * ,x # )∈X * ×X # , σ∈Σ * ∪Σ # ,

[0065]

[0066] (3-3)G F =CoAc(G l ) indicates the deletion of those in G l The remaining part after all states that cannot be reached from the initial state are considered abnormal behavior states.

[0067] (4) Set up multiple local diagnostic tools. In the event of intermittent observation loss, the non-abnormal behavior baseline model G N Transform into an extended model of non-abnormal behavior G N,i :

[0068] (4-1) Let Σ i =Σ N Therefore Σ i =Σ o,i ∪Σ uo,i , where Σ o,i Let Σ represent the set of observable events in the i-th local diagnostic. uo,i Let Σ represent the set of unobservable events in the i-th local diagnostic. Let Σ be a finite set of events. *Let Σ denote the set of all finite strings over Σ, and ε denote an empty event, obviously ε∈Σ * . Mapping is defined as:

[0069]

[0070] Now consider the existence of intermittent missing observations for some observable events, let Σ ilo,i denote the set of observable events related to intermittent missing observations in the ith local diagnostic, Σ nilo,i denote the set of observable events unrelated to intermittent missing observations in the ith local diagnostic, then Σ i ilo,i ∪Σ nilo,i ∪Σ uo,i . In order to characterize the nature of intermittent missing observations, the expansion factor is defined as:

[0071]

[0072] A set is defined for the expansion factor: The events in the set satisfy:

[0073] (4-2) Construct the non-abnormal behavior expansion model G N,i =(X N ,Σ N,i ,f N,i ,x 0,N ), i={1,2,...,ND}, The definition of f N,i is as follows: for any σ∈Σ nilo,i , x∈X N , f N,i (x,σ)=f N (x,σ); for any

[0074] (5) Parallel combination operation of the abnormal behavior model G F and multiple non-abnormal behavior expansion models G N,i , to obtain the verifier G V :

[0075] The verifier is constructed The state X V =(X N,1 ,X N,2 ,...,X N,ND ,X F ) in the formula, X N,1 ,X N,2 ,...,X N,ND ,X​​F They are G N,1 G N,2 ,...,G N,2 G F The state in, and X F =(X,X) l ), X,X l They are G and A respectively l The state in.

[0076] (6) Determine whether there is a violation loop in the distributed abnormal behavior verifier. If there is, determine that the Internet telephony system is an abnormal behavior collaboration that is not diagnosable; otherwise, determine that the abnormal behavior collaboration is diagnosable.

[0077] The specific method for determining a violation loop is as follows:

[0078] (6-1) Determine if the validator has a loop using the following method:

[0079] If a path exists in the validator satisfy This path is then called the loop pa, where, Represents validator G V The *th state.

[0080] (6-2) Determine if a loop satisfies the following condition; if so, it is considered an illegal loop:

[0081] for There is a certain state in the loop. satisfy

[0082] To verify the effectiveness of the method of the present invention, an embodiment of the present invention is described below, considering an Internet telephony system (such as...). Figure 2 As shown), the pre-call state is {0}, the invite state is {1}, the Ringing state is {2}, the ok state is {3}, the call state is {4}, the bye state is {5}, the final state is {6}, and the abnormal behavior state is {7}. The finite state automaton model corresponding to the Internet telephony system is: Figure 3 ,in Figure 3 Only one abnormal behavior model is considered. Table 1 shows the meaning of events in the system.

[0083] Table 1

[0084] Event Meaning a Invite message b Ringing message c OK message u ]]> ​ ACK message (unobservable event) e Bye message d 3XX, 401, 407 (identity verification) f ]]> ​ DoS attack (abnormal behavior event)

[0085] From Table 1, we can obtain Σ={a,b,c,d,e,σ u ,σ f},Σ uo ={σu ,σ f},Σ f ={σ f In internet telephony systems, network congestion or poor link quality can cause intermittent message loss (such as Invite and Bye). Therefore, two local observers, R1 and R2, can be set up to observe the Invite and Bye messages respectively. ilo,1 ={a},Σ ilo,2 ={e}.

[0086] Figure 4 For abnormal behavior model (G F Figures 5-a and 5-b show the non-abnormal behavior expansion model G, respectively. N,1 and G N,2 A verifier is constructed by combining operators in parallel:

[0087]

[0088] like Figure 6 As shown, the state x in the formula V =(x N,1 ,x N,2 ,x F ), x N,1 ,x N,2 ,x F They are G N,1 G N,2 G F The state in can be obtained from Figure 6 The validator was found to have a loop. etc., but events in the loop do not belong to Σ, therefore the Internet telephony system ( Figure 3 There is no violation loop, and the system is capable of diagnosing abnormal behavior.

[0089] The above description is merely a preferred embodiment of the present invention and should not be construed as limiting the scope of the invention. Therefore, any equivalent variations made in accordance with the claims of the present invention are still within the scope of the present invention.

Claims

1. A method for diagnosing abnormal behavior in an Internet telephony system based on finite state automata, characterized in that, Includes the following steps: Step 1: Model the operation of the Internet telephony system as a finite state automaton model G = (X, Σ, f, x0), where X represents the set of states, Σ represents the set of events, f represents the state transition function, and x0 represents the initial state. Step two: Construct an automaton with only one state, and multiply it with a finite state automaton model to obtain the baseline model G for non-abnormal behavior. N ; Step 3: Construct an automaton labeled with anomalous behaviors, and perform parallel combination operations with a finite state automaton model to obtain the anomalous behavior model G. F ; Step four: Set up multiple local diagnostic tools. In the event of intermittent observation loss, set a label factor to ensure the non-abnormal behavior baseline model G... N Transform into an extended model of non-abnormal behavior G N,i ; Step 5, model G of abnormal behavior F With multiple non-abnormal behavior expansion models G N,i Parallel combination operations are performed to obtain a distributed anomaly behavior verifier G. V ; Step 6: Determine if there is a violation loop in the distributed abnormal behavior validator. If it exists, the Internet telephony system is determined to be an abnormal behavior collaboration that is not diagnosable; otherwise, it is determined to be an abnormal behavior collaboration that is diagnosable. Step 7: Analyze the distributed abnormal behavior validator G obtained above. V The computational complexity of the steps.

2. The method for diagnosing abnormal behavior of an Internet telephony system based on finite state automata as described in claim 1, characterized in that, In step two, a baseline model G for non-abnormal behavior is constructed. N First, define the set of non-abnormal behavior events Σ. N =Σ\Σ f , Σ f First, represent the set of abnormal behavior events. Second, construct a finite automaton A containing only one state. N Let N be the unique state, and state N be in Σ N Any event in the loop can directly return to this state, thus forming a self-loop, and finally connecting G and A. N A benchmark model G for non-abnormal behavior is constructed using the product operator. N G N =A N XG=(X N , Σ N f N x 0,N ), where the symbol X represents the product operator.

3. The method for diagnosing abnormal behavior of an Internet telephony system based on finite state automata as described in claim 1, characterized in that, In step three, an abnormal behavior model G is constructed. F =CoAc(G||A l ): Define an abnormal behavior finite state automaton A l =(X l ,Σ f ,f l ,x 0,l In the formula, X l = {N, F}, where F represents the system's abnormal behavior state after a DoS attack, x 0,l ={N} represents A l The initial state is a safe state, f l A represents l The state transition function, f l And F satisfy the following condition: for any σ f ∈Σ f All have f l (N,σ f ) = F and f l (F,σ f )=F,f l (△,Ω) represents the state that state △ reaches through event Ω; Connect the finite state automaton model G with A l The automaton G is obtained by parallel combination operators. l G l =G||A l Where, the symbol || denotes the parallel combination operator, G F =CoAc(G l ) indicates deletion in G l The remaining part after all states that cannot be reached from the initial state are considered abnormal behavior states.

4. The method for diagnosing abnormal behavior of an Internet telephony system based on finite state automata as described in claim 1, characterized in that, In step four, in the case of intermittent loss of observation by the local diagnostic instrument: Let Σ i =Σ N Therefore Σ i =Σ o,i ∪Σ uo,i , where Σ o,i Let Σ represent the set of observable events in the i-th local diagnostic. uo,i Let Σ be the set of unobservable events in the i-th local diagnostic, and let Σ be a finite set of events. * Let Σ be the set of all finite strings in Σ, and let ε be an empty event. Obviously, ε∈Σ * , mapping Defined as: Now consider that some observable events may experience intermittent observation loss, let Σ ilo,i Let Σ represent the set of observable events associated with intermittent observation loss in the i-th local diagnostic tool. nilo,i Let Σ represent the set of observable events in the i-th local diagnostic that are unrelated to intermittent observation loss. i =Σ ilo,i ∪Σ nilo,i ∪Σ uo,i To characterize the property of intermittent observation loss, we define the expansion factor: Define a set for the expansion factors: The events in the set satisfy: Constructing an extended model for non-abnormal behavior: f N,i The definition is as follows: for any σ∈Σ nilo,i , x∈X N There is f N,i (x,σ)=f N (x,σ); for any have 5. The method for diagnosing abnormal behavior of an Internet telephony system based on finite state automata as described in claim 1, characterized in that, In step five, a distributed anomaly behavior validator is constructed: The state X in the formula V =(X N,1 ,X N,2 ,...,X N,ND ,X F ), X N,1 ,X N,2 ,...,X N,ND ,X F They are G N,1 G N,2 ,...,G N,2 G F The state in, and X F =(X,X) l ), X,X l They are G and A respectively l The state in.

6. The method for diagnosing abnormal behavior of an Internet telephony system based on finite state automata as described in claim 1, characterized in that, In step six, the specific method for determining the diagnosability of abnormal behavior collaboration is as follows: Determine if the validator has a loop using the following method: If there is a path in the verifier 0 < k ≤ τ, such that then this path is called a cycle pa, where represents the *-th state of the verifier G V ; Determine if a loop meets the following conditions; if so, it is considered an illegal loop: for There is a certain state in the loop. satisfy If the distributed abnormal behavior verifier has a violation loop, the current system is determined to be abnormal behavior collaboratively undiagnosable; otherwise, it is determined to be abnormal behavior collaboratively diagnosable.

7. The method for diagnosing abnormal behavior of an Internet telephony system based on finite state automata as described in claim 1, characterized in that, In step seven: the complexity is determined by analyzing the distributed anomalous behavior validator G. V The size of the state space and event set required for each step is determined; The second step is to construct a single-state automaton A. N And calculate the baseline model G for non-abnormal behavior. N Because A N It is a symbol marked Σ N =Σ\Σ f A self-looping single-state automaton, then G... N The maximum number of states and the number of transitions are |X| and |X|×(|Σ|-|Σ), respectively. f |); The third step is to construct the abnormal behavior model G. F To this end, we first construct a finite state automaton A with two states N and F that exhibits abnormal behavior. l Its transfer is only caused by anomalous behavioral events, and then G is obtained. l =G||A l Note G l The state is equal to (x,N) or (x,F), where x∈X, G l The maximum number of states is 2|X|, and the abnormal behavior model G F =CoAc(G l In the worst-case scenario, G F The number of states and the number of transitions are 2|X| and 2|X|×|Σ|, respectively; In the fourth step, the expansion factor R is used. i By renaming the unobservable events for each local diagnostic tool and expanding the observable events associated with intermittent observation loss, a non-abnormal behavior expansion model G is obtained. N,i G N,i The number of states and the number of transitions are |X| and |X|, respectively. Finally, the fifth step is to build a distributed anomalous behavior validator G. V =(|| i={1,2,...,ND} G N,i )||G F Because of G N,i and G F If the maximum number of states are |X| and 2|X|, then G V The number of states in the worst case is equal to 2|X| m+1 Where m represents the number of diagnostic devices, and G V The maximum number of transitions is: The complexity is This indicates that the method exhibits linear complexity in terms of the number of transitions in each state.