Early warning system for unlicensed mobile terminals
By dynamically constructing the mapping relationship between detection partitions and security policies, the problems of incomplete data collection, fixed partitions, static policy matching, and lagging rule updates in unauthorized mobile terminal access are solved, achieving high-precision network security protection and rapid early warning response.
Patent Information
- Application Number
- CN202511594590.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-03
- Publication Date
- 2026-02-13
- Estimated Expiration
- 2045-11-03
AI Technical Summary
Existing technologies suffer from incomplete data collection, fixed detection zones, static matching of security policies, delayed rule updates, and disordered early warning management when facing unauthorized mobile terminal access, resulting in insufficient accuracy and timeliness of network security protection.
Through the information processing and policy management module, the data from wireless detection and processing nodes are integrated to dynamically construct the mapping relationship between detection zones and security policies, identify warning targets and sequences, realize dynamic updates and policy combinations, and improve the accuracy of detection and the pertinence of security policies.
It enables highly accurate monitoring and timely protection of unauthorized mobile terminals, improving the security and control capabilities of the network environment and the efficiency of early warning response.
Smart Images

Figure CN121056247B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of mobile terminal early warning, in particular to an early warning system for unlicensed mobile terminals. BACKGROUND
[0002] In the current network security protection system, the access of unlicensed mobile terminals has always been an important hidden danger threatening network security. With the rapid development of mobile Internet technology, the popularity of mobile terminals such as smart phones, tablet computers, and portable notebooks is becoming higher and higher. These terminals frequently attempt to access the network in various scenarios, such as enterprise office areas, public places, and internal areas of parks. The access behavior of a large number of unlicensed mobile terminals can easily cause security problems such as data leakage, network congestion, and malicious attack propagation, bringing great challenges to network operation and security management.
[0003] Existing detection and early warning schemes for unlicensed mobile terminals have many limitations. At the data collection level, most schemes only focus on collecting basic detection information such as terminal access signals and connection requests obtained by wireless detection points, but often ignore the operation and maintenance information of processing nodes. The operation status, load condition, and data transmission stability of processing nodes are closely related to the security of terminal access. The lack of such information will result in a lack of comprehensiveness in subsequent detection analysis, making it difficult to accurately determine the potential risks behind terminal access.
[0004] In the detection zoning link, existing technologies usually use fixed zoning methods, such as dividing the detection range according to physical areas, without dynamically adjusting based on real-time detection information and operation and maintenance information. This fixed zoning mode cannot adapt to complex and variable network environments. For example, when the wireless signal in a certain area is enhanced due to interference, or the processing node temporarily fails, the fixed detection zoning cannot accurately cover the area with security risks, resulting in the omission of some unlicensed mobile terminal access behaviors and a significant reduction in detection accuracy.
[0005] In terms of security policy application, the matching of detection zoning and security policy in existing schemes is usually static, i.e., a single security policy is assigned to a fixed zoning in advance. This does not consider the differentiated needs of different detection zoning in actual operation, nor can it flexibly combine and adapt security policies according to terminal access conditions in the zoning, network environment changes, and other factors. This makes the security policy either too strict, causing normal terminal access to be blocked, or too lenient, failing to effectively intercept risky terminals, resulting in insufficient practicality and pertinence of the policy.
[0006] The security rule updating mechanism of the existing system is relatively lagging, mostly relying on manual periodic updating, and it is difficult to capture new unauthorized access methods, terminal attack patterns and other changes in the network environment in real time. When the security rules cannot match the latest security threats, the identification ability of the system for unauthorized mobile terminals will be greatly reduced, and the timeliness and effectiveness of the early warning are seriously affected. In addition, in the early warning management, the existing scheme can only simply identify the terminals with risks and send early warning signals, but cannot determine the priority and processing order of different early warning targets, resulting in that the operation and maintenance personnel are difficult to quickly focus on key threats when facing a large amount of early warning information, the early warning response efficiency is low, and effective protection measures cannot be taken in time, further expanding the network security risk. SUMMARY
[0007] The purpose of the present application is to provide an early warning system for unauthorized mobile terminals to solve the problems raised in the background art.
[0008] To achieve the above purpose, the present application provides an early warning system for unauthorized mobile terminals, which comprises:
[0009] An information processing and strategy management module is used to integrate the data of wireless detection and processing nodes, intelligently generate detection partitions, and dynamically construct and optimize the mapping relationship between detection partitions and security strategies.
[0010] An early warning management module is used to identify the early warning target and early warning order of the detection information according to the mapping relationship between the updated detection partitions and security strategies, and generate an early warning management library.
[0011] The early warning management module identifies the early warning target and early warning order of the detection information, and the specific process is as follows:
[0012] The characteristic values in the detection information are extracted, and the characteristic values and the corresponding standard characteristic values are compared. According to the comparison result, all the characteristic values are divided, and the first characteristic number sequence and the second characteristic number sequence are constructed according to the division result. The characteristic values in the first characteristic number sequence and the second characteristic number sequence are numerically sorted, and each two characteristic values in the first characteristic number sequence or the second characteristic number sequence are taken as the to-be-associated characteristic values. Whether the to-be-associated characteristic values are associated is verified based on a characteristic evaluation model, and the number of associations is counted according to the verification result.
[0013] The comprehensive early warning value is determined according to the number of associations and the characteristic values that have not been associated, and whether to generate an early warning is determined according to the comprehensive early warning value.
[0014] Preferably, the information processing and strategy management module comprises:
[0015] The data collection module is configured to count each wireless detection point and each processing node, and to obtain detection information of each wireless detection point and operation and maintenance information of each processing node.
[0016] The detection partition module is configured to process based on the detection information of each wireless detection point and the operation and maintenance information of each processing node to obtain detection partitions of each wireless detection point.
[0017] The partition mapping module is configured to obtain a security policy of the detection partitions and to construct a mapping relationship between the detection partitions and the security policy.
[0018] The policy combination module is configured to extract a key partition from the detection partitions and the security policy, and to determine a combination matching degree between a plurality of policies in the security policy according to the key partition to obtain a policy bias combination.
[0019] The rule updating module is configured to perform information checking on the security policy based on the policy bias combination, to identify an update situation of a rule in the security policy, and to update the mapping relationship between the detection partitions and the security policy according to the update situation of the rule.
[0020] Preferably, the detection information of each wireless detection point includes signal strength, data volume, and data transmission rate of each wireless detection point.
[0021] The operation and maintenance information of each processing node includes memory utilization, bandwidth utilization, data packet processing rate, and CPU utilization of each processing node.
[0022] Preferably, the detection partition module processes based on the detection information of each wireless detection point and the operation and maintenance information of each processing node, and the specific process is as follows:
[0023] Based on the detection information of each wireless detection point, a basic characteristic value of each wireless detection point is processed and obtained, and the basic characteristic value of each wireless detection point is used to comprehensively quantify the data detection efficiency of each wireless detection point.
[0024] Each wireless detection point is classified according to a terminal type to obtain each wireless detection point corresponding to each terminal type, and an average value of the basic characteristic value of each wireless detection point corresponding to each terminal type is obtained to obtain a basic characteristic average value of the wireless detection point corresponding to each terminal type, which is recorded as a comprehensive characteristic value of the wireless detection point corresponding to each terminal type.
[0025] The operation and maintenance information of each processing node is comprehensively analyzed to obtain a data processing energy efficiency characteristic value of each processing node, and the data processing energy efficiency characteristic value of each processing node is used to comprehensively quantify the data processing capacity of each processing node.
[0026] Preferably, the detection partition module obtains a target receiving detection point cluster of each processing node, and the specific process is as follows:
[0027] The data processing energy efficiency characteristic value of each processing node is matched with the target receiving comprehensive characteristic value range of the detection point corresponding to each data processing energy efficiency characteristic value interval stored in the information management database, and the target receiving comprehensive characteristic value range of the detection point corresponding to the data processing energy efficiency characteristic value interval of each processing node is counted, which is recorded as the target receiving comprehensive characteristic value range of the detection point of each processing node;
[0028] The comprehensive characteristic value of the wireless detection point corresponding to each terminal type is matched with the target receiving comprehensive characteristic value range of the detection point of each processing node, and if the comprehensive characteristic value of the wireless detection point corresponding to a certain terminal type is in the target receiving comprehensive characteristic value range of the detection point of a certain processing node, the terminal type is defined as the target receiving terminal type of the processing node, and all target receiving terminal types of each processing node and each wireless detection point corresponding to all target receiving terminal types are counted in turn;
[0029] The wireless detection points corresponding to all target receiving terminal types of each processing node are uniformly recorded as the target receiving wireless detection points corresponding to each processing node, and thus the target receiving wireless detection point cluster of each processing node is integrated.
[0030] Preferably, the implementation mode of the detection partition module comprises:
[0031] For the detection information of each wireless detection point, an intention classification model corresponding to the detection information is obtained;
[0032] The detection information is classified using the intention classification model, and at least one intention category is obtained;
[0033] Synonymous words, polysemous words and related words existing in the detection information under the corresponding intention category are identified to form a text sample set;
[0034] The synonymous words, polysemous words and related words in the text sample set are analyzed respectively, and the synonymous word area, polysemous word analysis area and related word association area corresponding to the text sample set are obtained in turn, and are used as the detection partition of the detection information relative to the security service.
[0035] Preferably, the implementation mode of obtaining the synonymous word area, polysemous word analysis area and related word association area corresponding to the text sample set further comprises:
[0036] The synonymous words, polysemous words and related words in the text sample set are merged according to the intention category to obtain a plurality of intention merging results;
[0037] Synonymous word pairs in the intention merging results are extracted, and the synonymous word pairs are compared with a synonymous word dictionary to obtain a synonymous word area;
[0038] The paraphrase change rate of the polysemous word in the intention merging result and the association strength of the related word are extracted, the intention merging result is divided according to the paraphrase change rate of the polysemous word and the association strength of the related word, and a polysemous word analysis area and a related word association area are obtained.
[0039] Preferably, the judgment of the detection information relative to the detection partition of the security service further includes:
[0040] The detection partition is judged, the detection times and detection times in the detection partition are analyzed, the detection partition is fitted according to the detection times and detection times, and a mapping relationship of the detection partition to the actual threat is constructed.
[0041] Preferably, the implementation of the partition mapping module includes:
[0042] The strategy and rule corresponding to the detection information are called, and a plurality of unlabeled strategy recognition results are generated, the unlabeled strategy recognition result indicating a strategy and rule not associated with the word in the detection partition;
[0043] It is judged whether the plurality of unlabeled strategy recognition results is a target strategy recognition result, if it is a target strategy recognition result, the target strategy recognition result is regarded as the security strategy of the detection information.
[0044] Preferably, the implementation of constructing the mapping relationship of the detection partition and the security strategy includes: the information representing the synonym area, the polysemous word analysis area and the related word association area existing in the detection partition, the description information of the security strategy and the category of the security strategy, and the mapping relationship of the detection partition and the security strategy.
[0045] Compared with the prior art, the present application has the following advantages:
[0046] From the data acquisition link, the data acquisition module not only counts each wireless detection point and obtains its detection information, but also synchronously counts each processing node and collects operation and maintenance information, realizing comprehensive coverage of two types of core information related to terminal access in the network. Compared with the existing scheme of collecting only single detection information, the information obtained by the module is more complete, which can provide more abundant basis for subsequent detection partition, strategy formulation and other links, enable the system to have more comprehensive cognition of the network environment and terminal access state, and avoid the detection blind area caused by information loss.
[0047] The detection partition module processes based on the detection information of each wireless detection point and the operation and maintenance information of each processing node to form the detection partition of each wireless detection point. This partitioning method breaks away from the limitations of the existing fixed partitioning, fully combines real-time network operation data, and can dynamically adjust the range and coverage focus of the detection partition according to the actual situation of changes in wireless signal strength, processing node load fluctuations, etc. For example, when the operation and maintenance information of a processing node shows that its load is too high and there is a risk of processing delay, the detection partition module can specifically reduce the detection partition granularity of the node associated area, improve the monitoring density of the terminal access behavior in this area, make the detection partition more suitable for the actual network security protection needs, and significantly improve the accuracy of detection.
[0048] The partition mapping module breaks the existing static matching mode by obtaining the security policy of the detection partition and constructing the mapping relationship between the two. Different detection partitions differ in network environment, access terminal type, and importance of the carried service, etc., and the required security policies are also different. This module can match the security policy suitable for the characteristics of each detection partition, realize the accurate correspondence between the detection partition and the security policy, avoid the adaptability problem of a single policy in different partitions, make the application of the security policy more targeted, and improve the prevention and control capability of the non-authorized terminal access risk in different partitions.
[0049] The policy combination module extracts key partitions from the detection partition and the security policy, judges the combination matching degree between multiple policies according to the key partitions, and forms a policy bias combination. This process can fully consider the applicability and complementarity of different security policies in the key partition, avoiding the singleness and blindness of policy application in the existing scheme. By reasonably combining the security policies, a more comprehensive and flexible protection system can be formed for the complex non-authorized terminal access scene in the key partition, such as combining and applying terminal identity verification, access behavior audit, risk level assessment, etc. in the key partition where terminals frequently access, to comprehensively intercept the non-authorized terminal access risk and improve the prevention and control effect of the security policy.
[0050] The rule updating module checks the information of the security policy and identifies the rule updating situation based on the policy bias combination, and then updates the mapping relationship between the detection partition and the security policy. This module realizes the dynamic updating of the security rules, no longer relies on manual operation, can capture new non-authorized access methods, terminal security threat changes, etc. in the network environment in real time, timely adjust the rule content in the security policy, and update the mapping relationship synchronously, to ensure that the security policy matched by the detection partition is always adapted to the latest security threat, keep the identification and interception capability of the system to the non-authorized mobile terminal at a high level, and guarantee the timeliness and effectiveness of the early warning.
[0051] The early warning management module identifies the early warning target and early warning sequence of the detection information according to the updated mapping relationship and generates an early warning management library. This function solves the problem of disorder of existing early warning management. Through the priority of different early warning targets, the operation and maintenance personnel can quickly lock the key threats that need to be processed in priority from the early warning management library, avoid wasting time in a large number of early warning information, and significantly improve the early warning response efficiency. At the same time, the establishment of the early warning management library also provides a clear basis for subsequent early warning tracing and risk analysis, so that the early warning management of the unlicensed mobile terminal is more standardized and efficient, and the security protection capability of the entire network is further enhanced. BRIEF DESCRIPTION OF DRAWINGS
[0052] Figure 1 A timing diagram of the early warning system for the unlicensed mobile terminal according to the present application;
[0053] Figure 2 A flowchart for calculating the data processing efficiency value of the basic features of the detection partition module;
[0054] Figure 3 A flowchart for constructing the target receiving detection point cluster of the detection partition module. DETAILED DESCRIPTION
[0055] The technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor are within the scope of protection of the present application.
[0056] Please refer to Figure 1 The present application provides an early warning system for unlicensed mobile terminals, which comprises an information processing and strategy management module and an early warning management module. The information processing and strategy management module is used to integrate and collect wireless detection and processing node data, intelligently generate a detection partition, dynamically construct and optimize the mapping relationship between the detection partition and the security strategy, and specifically comprises a data collection module, a detection partition module, a partition mapping module, a strategy combination module, and a rule updating module.
[0057] The data collection module is responsible for counting the wireless probe points and processing nodes deployed in the system, and simultaneously collecting the probe information of the wireless probe points and the operation and maintenance information of the processing nodes. The probe partition module performs processing and analysis according to the collected probe information and operation and maintenance information, and generates a probe partition corresponding to each wireless probe point. The partition mapping module obtains a security policy associated with each probe partition, and establishes a mapping relationship between the probe partition and the security policy. The policy combination module extracts key partitions from the mapped partitions and policies, evaluates the combination matching degree between multiple security policies, and then forms a policy bias combination. The rule update module performs information checking on the security policy based on the policy bias combination, identifies the update state of the rules therein, and updates the mapping relationship between the probe partition and the security policy according to the state. The early warning management module identifies the early warning target and its priority order in the probe information according to the updated mapping relationship, and finally generates an early warning management library.
[0058] Embodiment 1: see Figure 2 In the running process of the data collection module, the system will continuously count the deployment state and running identification of all wireless probe points and processing nodes in the network. The probe information of the wireless probe points covers multi-dimensional parameters such as signal strength, data volume and data transmission rate. These parameters are obtained in real time through a special sensing unit and a communication interface, and are packaged as structured data packets for transmission to the upper layer. The operation and maintenance information of the processing nodes includes performance indicators such as memory utilization rate, bandwidth utilization rate, data packet processing rate and CPU utilization rate. These indicators are periodically collected and summarized to the central data pool through the performance monitoring agent and network probe of the system kernel.
[0059] After receiving the data stream, the probe partition module starts the processing flow. It first pre-processes and extracts the features of the probe information of each wireless probe point. The signal strength is converted into a standard RSSI reference value after unit unification and attenuation compensation. The data volume is normalized according to its byte length and time window. The data transmission rate is classified according to the transmission protocol type and then takes the weighted average value. The three types of parameters are combined and scaled to obtain the basic feature value of each wireless probe point, which comprehensively reflects the efficiency of the probe point in signal acquisition, data load and transmission stability. The wireless probe points are classified according to the associated terminal type. The classification basis includes terminal MAC address prefix, protocol handshake feature and radio frequency fingerprint information. All probe points under the same terminal type are classified into the same set. The system calculates the arithmetic mean of the basic feature values of the probe points corresponding to each type of terminal. This mean value is defined as the comprehensive feature value of this type of terminal, which represents the average level of this type of terminal in overall detection efficiency.
[0060] The operation and maintenance information of the processing node also needs to be comprehensively evaluated. The memory utilization rate reflects the real-time load state of the node, the bandwidth utilization rate reflects the network throughput capacity, the data packet processing rate is directly related to the forwarding performance, and the CPU utilization rate indicates the remaining amount of computing resources. These indicators are integrated through a multi-dimensional performance model. The model uses a dynamic weighting method to adjust the weights of each indicator according to the role of the node, and finally outputs a data processing energy efficiency representation value. This value abstractly describes the overall data processing capacity of the node under a given operation and maintenance state. The calculation process of the basic characteristic value and the data processing energy efficiency representation value relies on the normalization algorithm and weight distribution strategy built into the system. The weight coefficient is dynamically adjusted according to the real-time network topology and historical performance data to ensure that the calculation result fits the actual running environment. All intermediate results and final values are stored in a specific partition of the information management database for subsequent module query and matching use.
[0061] Embodiment 2: refer to Figure 3 The information management database stores a predefined correspondence between the data processing energy efficiency representation value interval and the probe point target receiving comprehensive characteristic value range. These correspondences are pre-configured based on historical running data and system performance planning. The data processing energy efficiency representation value of each processing node is matched with the interval in the database. The matching process uses an interval boundary comparison algorithm to determine the energy efficiency representation value interval to which the node belongs, and retrieves the probe point target receiving comprehensive characteristic value range corresponding to the interval. This range defines the upper and lower limits of the wireless probe point comprehensive characteristic value that the processing node can effectively process. The wireless probe point comprehensive characteristic value corresponding to each terminal type is compared with the target receiving comprehensive characteristic value range of each processing node one by one. The comparison operation is performed through a range query algorithm. If the comprehensive characteristic value of a certain terminal type falls within the target receiving range of a certain processing node, the system marks the terminal type as the target receiving terminal type of the processing node. This marking process traverses all processing nodes and all terminal types, and finally generates a target receiving terminal type list for each processing node.
[0062] Each target receiving terminal type includes a number of specific wireless probe points. The system retrieves all wireless probe point instances belonging to the target receiving terminal type according to the association between the terminal type identifier and the wireless probe point registration information. These wireless probe points are included in the target receiving set of the processing node. The target receiving wireless probe point set of all processing nodes is integrated to form a target receiving wireless probe point cluster. The integration process of the cluster includes data deduplication, node load balancing verification, and network topology consistency check. The cluster information is stored in the distributed memory in the form of a data structure and is updated synchronously to the cluster configuration partition of the information management database.
[0063] The probe partition module realizes the dynamic association between the processing nodes and the wireless probe points through the above matching and integration mechanism. The association relationship is not statically configured, but is dynamically adjusted with the changes of the processing node operation and maintenance state and the wireless probe point detection efficiency. The system periodically re-executes the matching process to ensure that the cluster division always reflects the actual running status of the current network. The establishment of the target receiving wireless probe point cluster provides a basis for the accurate mapping of subsequent security policies. Different clusters may correspond to different security policy preferences and processing priorities. The partition mapping module can call the corresponding policy generation rules according to the cluster characteristics, and the strategy combination module can optimize the combination matching degree between strategies based on cluster division. The database query adopts index optimization to reduce the delay, and the matching algorithm is designed to be parallelly executed to improve the processing efficiency in large-scale node environment. The system also designs an exception handling mechanism to start the manual review process when the matching result is conflicted or ambiguous, to ensure the accuracy and reliability of the cluster division.
[0064] For example, a certain enterprise wireless network deploys three types of terminals: employee smartphones (Type-A), Internet of Things sensors (Type-B), and visitor terminals (Type-C), and there are three processing nodes in the network: a core switch (Node-1), a wireless access point (Node-2), and a security gateway (Node-3). After the processing of embodiment 1, the comprehensive feature values of Type-A terminals are calculated as 85, Type-B as 45, and Type-C as 30; meanwhile, the data processing efficiency characterization values of Node-1, Node-2, and Node-3 are measured as 90, 50, and 40 respectively. The information management database predefines the corresponding relationship between the efficiency characterization value interval and the receiving range: the efficiency value 80-100 corresponds to the receiving range 75-95, the efficiency value 40-60 corresponds to the receiving range 35-55, and the efficiency value 30-40 corresponds to the receiving range 25-35. The system starts the matching process, and the efficiency value 90 of Node-1 falls into the interval 80-100, so its receiving range is determined as 75-95; the efficiency value 50 of Node-2 falls into the interval 40-60, so its receiving range is 35-55; the efficiency value 40 of Node-3 falls into the interval 30-40, so the receiving range is determined as 25-35 after triggering the boundary processing mechanism.
[0065] Terminal type comprehensive feature value and processing node receiving range start matching detection, Type-A feature value 85 is in the receiving range 75-95 of Node-1, the system marks Type-A as the target receiving terminal type of Node-1. Type-B feature value 45 falls outside the receiving range 35-55 of Node-2 and the receiving range 25-35 of Node-3, and after comparing the range priority, it is determined to belong to Node-2. Type-C feature value 30 is in the receiving range 25-35 of Node-3, but at the same time close to the range boundary of Node-2, the system starts the conflict detection program, and finally divides it into Node-3 according to the preset boundary allocation rule. After determining the target receiving terminal type, the system retrieves the enterprise network equipment registration database. There are 48 employee smartphones under Type-A terminal type, with MAC address prefix 00:1A:79, which are all included in the target receiving set of Node-1. There are 120 Internet of Things sensors under Type-B terminal type, with device identifier starting with 08:BE:AC, which are divided into the target receiving set of Node-2. Type-C terminal type contains 35 visitor terminals, with random MAC address distribution but marked as visitor category, which are assigned to Node-3 processing.
[0066] The cluster integration process starts data verification, and the system finds that there are two sensor devices in the receiving set of Node-2 that overlap with the terminal MAC address of Node-3. The deduplication mechanism retains the latest record according to the device registration timestamp and removes duplicates. The load balancing check shows that the number of sensor devices currently connected to Node-2 exceeds the recommended value, and the system automatically reassigns 15 sensor devices with weak signal strength to Node-1, but the receiving range check of Node-1 rejects the operation, and the final adjustment scheme is to temporarily place these devices in the pending allocation queue. Network topology consistency verification finds that Node-3 is in the edge area of the network, and the visitor terminals in its receiving set are actually physically dispersed. The system starts the location optimization program, and according to the terminal location information reported by the wireless probe, it reassigns 8 visitor terminals located in the core area to Node-1 and 12 terminals located in the access area to Node-2, ensuring the matching degree of physical topology and logical allocation. The final target receiving wireless probe point cluster information is written to the distributed storage system: Node-1 cluster contains 56 terminals (40 Type-A + 16 reassignment Type-C), Node-2 cluster contains 113 terminals (105 Type-B + 8 Type-C), and Node-3 cluster retains 15 Type-C terminals. Cluster configuration data is synchronized to the local cache of all processing nodes and updated to the resource configuration library of the network controller. The system sets a cluster state check triggered every minute, and when it detects that the CPU utilization of Node-2 continuously exceeds 80%, it automatically tightens its receiving range to 40-50, triggering the next round of dynamic reallocation process.
[0067] In embodiment 3, the probe partition module calls a pre-trained intent classification model to perform semantic analysis on the collected probe information. The model is based on a deep neural network architecture and can extract feature vectors from input text data and perform multi-class classification. The output result includes at least one intent category label and the corresponding confidence score. During model processing, an attention mechanism is used to focus on key words, enhancing the ability to capture core semantics. After identifying the intent category, the system starts vocabulary expansion analysis to detect the presence of synonyms, polysemous words, and related words within the text range of the corresponding intent category. Synonym recognition relies on semantic similarity calculation using cosine distance in word vector space. Polysemy analysis requires determining the specific word meaning in the context. Related word discovery is achieved through co-occurrence frequency statistics and semantic association graphs. All identified words and their associated information are organized into a structured text sample set.
[0068] The text sample set is processed by a hierarchical processing procedure. First, the synonym words are clustered and analyzed. The words with a semantic distance lower than a set threshold are merged into synonym groups. Each synonym group is mapped and verified with a pre-constructed synonym dictionary. The synonym groups that pass the verification form a synonym area, which stores the equivalent replacement relationships between words. The polysemous word processing uses a context disambiguation comparison method. The semantic shift degree of a specific polysemous word in different contexts is calculated to quantify its disambiguation change rate. The calculation formula is:
[0069]
[0070] wherein: represents the disambiguation change rate, represents the number of contexts in which the polysemous word appears, represents the word vector in the i-th context, represents the reference word vector of the polysemous word. According to the size of the value, the polysemous word is divided into different analysis levels to form a polysemous word analysis area.
[0071] The related word association area is established by constructing a word association network. The association strength between any two related words is calculated. The association strength considers factors such as co-occurrence frequency, semantic correlation, and grammatical dependency. Word pairs with an association strength exceeding a threshold value are included in the association area, and their association weight values are recorded. The formation process of the three areas has an interactive verification mechanism. The words in the synonym area need to exclude polysemy interference. The polysemous word analysis needs to refer to the context constraints of related words. The association of related words needs to consider the possibility of synonym replacement. This cross-verification ensures the accuracy and consistency of the partition results. The detection partition module also monitors the dynamic behavior characteristics within each partition, records the detection times and detection times, and other time series data. These data are standardized and input into the threat assessment model. The model establishes a mapping relationship from the partition characteristics to the actual threat level through a fitting function. The mapping relationship is stored in the form of a parameter matrix, supporting real-time threat assessment calculations. The system maintains and updates the semantic knowledge base and word vector model to ensure that the partition processing can adapt to the dynamic changes of language use. The processing results are output in the form of partition identifiers and feature descriptors.
[0072] Take a set of abnormal access behaviors detected by a wireless network of a certain financial enterprise as an example. The probe information contains text data: "Repeated attempts to access encrypted channels", "Bypass authentication mechanism", "High-frequency port scanning". After the intent classification model pre-processes these texts, it generates a sequence of word vectors, calculates through a multi-layer attention mechanism, and outputs the main intent category as "Unauthorized access attempt" with a confidence score of 0.92, while identifying the secondary intent category "Network probing behavior" with a confidence score of 0.76. The system starts the vocabulary expansion analysis within the determined intent category range, and processes the original text through word segmentation and part-of-speech tagging. The near-synonym recognition module uses a pre-trained word vector model to calculate the cosine similarity between "encrypted channels" and "secure tunnels", which reaches 0.89, and the similarity between "authentication mechanism" and "verification system" is 0.85. The polysemy analysis finds that "scan" in the context is interpreted as "network probing" rather than "image processing", and the reinterpretation rate Δ is calculated to be 0.68. The related word analysis finds that the association strength index between "port" and "service discovery" is 0.79, and the association strength between "bypass" and "exploit" is 0.83. All the identified results are structured and stored as a text sample set, containing 12 core words and their associated attributes.
[0073] The text sample set enters the hierarchical processing flow, and the near-synonym clustering algorithm merges "encrypted channels", "secure tunnels", "authentication mechanism", and "verification system" into the same semantic group, with an average similarity of more than 0.75 within the group. The semantic group is mapped and verified with the near-synonym dictionary, and there are complete corresponding entries in the dictionary and the semantic consistency score meets the standard, so the system generates a near-synonym area, recording the group of words and their replaceable relationship. The polysemy processing unit analyzes the use of the word "scan" in different contexts, extracting 32 context instances containing the word from the historical corpus. The semantic vector of the word in the network security context deviates from the general context, and the reinterpretation rate Δ value continues to be higher than the threshold value 0.6, indicating that it has a stable professional interpretation in this scenario. The system classifies it into the polysemy analysis area and labels the recommended interpretation as "network probing behavior". In the construction process of the related word association area, the system establishes a word association network graph, with nodes representing words and edge weights representing association strength. The edge weight between "port" and "service discovery" is 0.79, the edge weight between "bypass" and "exploit" is 0.83, and the edge weight between "high frequency" and "brute force cracking" is 0.71. Through community discovery algorithm, three association clusters are identified, and association pairs with strength exceeding 0.75 are included in the core association area, and the rest are included in the auxiliary association area.
[0074] The formation process of the three partitions exists cross-validation, and the "authentication mechanism" in the synonym area needs to be coordinated with the "authentication" (which may exist polysemy) in the polysemy analysis area. The system starts a consistency check program and finds that "authentication" is clearly interpreted in the current context without the need for polysemy annotation. The "high frequency" in the related word association area and the "repeat" in the synonym area have semantic overlap, and after similarity calculation, they are confirmed as a synonym relationship, and the two words are merged into the synonym area. After the partition is established, the system loads the behavior monitoring data, records that the detection information appears 24 times of attempt behavior within 180 seconds, and the time interval shows a gradually shortened trend. These time series data input the threat assessment model, which uses time series analysis method to fit the behavior pattern, and calculates the threat level coefficient as 0.86 (range 0-1). The model output suggests that the detection partition is mapped to the "high-risk unauthorized access" threat category, and generates the corresponding threat identifier.
[0075] In example 4, the partition mapping module first receives output data from the detection partition module, which contains classified intent categories and corresponding text sample set partition information (synonym area, polysemy analysis area, and related word association area). The system accesses the security policy entries stored in the policy knowledge base, each of which contains policy description text, applicable condition metadata, and policy type identifier. The module uses a parallel processing mechanism to generate initial policy identification results for each detection partition, which have not been associated with specific partition features, so they are marked as unlabeled. Taking the "unauthorized device connection" detection scenario commonly seen in actual network environments as an example, assume that the detection information is identified as "illegal access intent" after intent classification, and its text sample set contains synonym area {"illegal connection", "unauthorized access", "excessive access"}, polysemy analysis area {"connection": may refer to legal link establishment or illegal session binding in a specific context}, and related word association area {"hot spot scanning"-"authentication bypass", "MAC spoofing"-"signal spoofing"}. The module simultaneously extracts 10 security policy raw texts related to device access control from the policy knowledge base.
[0076] The module calls the semantic parser to preprocess the policy text, extracts the core concepts and constraints of each policy to form a policy feature vector. The generation process of the unlabeled policy identification result uses a feature matching algorithm to calculate the similarity between the policy feature vector and the vocabulary features of the detection partition, but at this time no explicit mapping association has been established. For example, policy P-001 describes "prevent unverified terminals from accessing the network", and its feature vector contains core concepts such as {"verification", "terminal", "access", "block"}, which have potential associations with words such as "unauthorized access" and "MAC spoofing" in the detection partition, but only list them as candidate policies without assigning official labels in the initial processing stage.
[0077] The judgment of the target policy recognition result is based on multi-dimensional matching criteria. The system calculates the comprehensive matching degree of the policy feature vector and each region of the detection partition. The matching degree calculation comprehensively considers three dimensions of vocabulary overlap, semantic distance and context association strength. For the "illegal access intention" partition, policy P-001 has direct vocabulary matching with the near-synonym area "unauthorized access", and forms semantic association with the related word association area "authentication bypass", and the matching degree score reaches the threshold requirement and is determined as the target policy recognition result. On the contrary, policy P-006 describes "prevent wireless signal interference", although it has weak association with "signal camouflage" in the partition, but because the core concept does not match, it is excluded.
[0078] The mapping relationship is constructed by using a dynamic association table structure, which records the detection partition identifier, the policy unique code and the mapping weight value. The mapping weight is determined by the matching degree score, the policy priority and the real-time environmental factors. For each determined target policy, the module generates the corresponding mapping record and writes it into the partition-policy mapping table. The table contains the following fields: mapping ID, partition hash value, policy ID, near-synonym matching flag, polysemy analysis flag, related word association strength and final mapping weight, refer to Table 1.
[0079] Table 1: Partition-Policy Mapping Table
[0080] Mapping ID Partition Hash Value Policy ID Synonym Match Polysemy Resolution Correlation Word Association Strength Mapping Weight M-001 0xA3D9F2 P-001 Yes No 0.87 0.92 M-002 0xA3D9F2 P-003 No Yes 0.65 0.78 M-003 0xA3D9F2 P-007 Yes No 0.92 0.95
[0081] The mapping relationship is maintained by using a version control mechanism, and each mapping update generates a new version snapshot. When the detection partition changes or the policy knowledge base updates, the system starts the remapping process, but retains the historical mapping records for audit tracking. The module also implements consistency checking to ensure that there is no logical conflict in the policy set mapped by the same detection partition, and triggers the conflict resolution program if mutual exclusion is found between policies. The system uses distributed cache technology to store hot mapping relationships to improve response speed, and the mapping results are pushed to the policy combination module for subsequent processing in real time, and are updated to the global policy execution framework to drive actual security control actions.
[0082] In the embodiment 5, the early warning management module receives updated detection partition and security policy mapping relationship data, and a preset standard characteristic value set is loaded in the module initialization stage. The set contains benchmark parameters in various network behavior scenarios, such as signal strength fluctuation range of legal terminal connection, normal data transmission threshold, and typical authentication interaction duration interval. The system extracts dynamic characteristic values from real-time detection information stream, and the extraction objects include but are not limited to signal strength dispersion, data packet retransmission rate, connection duration, and protocol anomaly identification frequency. The characteristic value comparison process adopts a multi-level filtering mechanism. In the first level processing, the real-time characteristic values are compared with the standard characteristic values to generate original deviation data. In the second level processing, scene correction coefficients are introduced to adjust the comparison threshold for different network areas and application types. Taking the unauthorized device connection scenario as an example, the signal strength is detected as -85 dBm while the standard value is -65 dBm, the data packet retransmission rate is 30% while the standard value is 5%, and the connection duration is 120 seconds while the standard value is 300 seconds. These deviation values are weighted by scene coefficients and then enter the division process.
[0083] The characteristic value division is based on the deviation degree and risk relevance double standards. The system establishes a first characteristic sequence to store core risk characteristic values, including signal strength anomaly, data packet anomaly, and other indicators that directly affect security evaluation. A second characteristic sequence stores auxiliary characteristic values, including time parameters, protocol versions, and other context information. All characteristic values are arranged in ascending order according to their numerical values to form an ordered sequence for correlation analysis. The characteristic evaluation model adopts a hybrid architecture based on rules and statistical learning. The model receives the sorted characteristic sequence, and takes each two adjacent characteristic values as a pair of correlated characteristics for verification. The verification process analyzes the statistical correlation, time sequence synchronization, and logical dependency between the characteristic pairs. For example, signal strength anomaly and data packet anomaly appear in adjacent time sequence positions. The model calculates the consistency index and appearance time interval to determine whether there is a substantial correlation.
[0084] The correlation quantity statistics adopts a sliding window mechanism. The system records the number of successfully correlated feature pairs during the verification process, and marks isolated feature values that fail to find correlations. The statistical results are input into the comprehensive early warning value calculation algorithm, which considers the number weight of the correlated feature pairs, the risk level weight of the isolated feature values, and the deviation degree weight of the feature values themselves, and generates a numerical comprehensive early warning value through weighted fusion. The early warning triggering mechanism sets a dynamic threshold, and the comprehensive early warning value is compared with the threshold curve in the real-time risk database. When the value exceeds the threshold corresponding to the current risk level, the early warning generation process is started. The early warning target identification is based on feature value backtracking analysis. The system associates the probe device identifier, network access location and timestamp information of the feature value that produces an abnormal value, to form a clear early warning target list. The early warning priority sorting adopts a multi-dimensional evaluation model, which refers to the size of the comprehensive early warning value, the target historical behavior record, the importance of the network area and the strictness of the current security policy, and other factors. The final generated early warning management library adopts a hierarchical storage structure. The high layer stores high-priority early warnings for immediate disposal, the middle layer stores medium-priority early warnings for monitoring, and the bottom layer stores low-priority early warning records for reference. All early warning records are synchronized in real time to the network operation terminal and the security control platform, to drive the corresponding response and disposal process.
[0085] It should be noted that the relational terms herein such as first and second and the like are used solely to distinguish one entity or action from another entity or action without necessarily requiring or implying any such actual relationship or order between such entities or actions. Moreover, the terms "comprises", "comprising", or any other variations thereof, are intended to cover a non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements does not include only those elements but can include other elements not expressly listed or inherent to such process, method, article, or apparatus.
[0086] Although embodiments of the present application have been shown and described, it is to be understood that various modifications, substitutions, replacements and changes can be made to these embodiments without departing from the principles and spirit of the present application, and the scope of the present application is defined by the appended claims and their equivalents.
Claims
1. An early warning system for unauthorized mobile terminals, characterized in that, include: The information processing and policy management module is used to integrate the data collected from wireless detection and processing nodes, intelligently generate detection partitions, and dynamically construct and optimize the mapping relationship between detection partitions and security policies. The early warning management module is used to identify the early warning targets and order of detection information based on the updated mapping relationship between detection zones and security policies, and to generate an early warning management library. The early warning management module identifies the early warning targets and the order of early warnings for the detected information. The specific process is as follows: Feature values are extracted from the detection information and compared with corresponding standard feature values. Based on the comparison results, all feature values are divided. A first feature sequence and a second feature sequence are constructed based on the division results. All feature values in the first feature sequence and the second feature sequence are numerically sorted. Every two feature values in the first feature sequence or the second feature sequence are taken as feature values to be associated. The association of the feature values to be associated is verified based on the feature evaluation model. The number of associations is counted based on the verification results. A comprehensive early warning value is determined based on the number of associated features and the feature values that are not associated, and whether to generate an early warning is determined based on the comprehensive early warning value. The information processing and strategy management module includes: a detection partitioning module, which processes the detection information of each wireless detection point to obtain the basic feature value of each wireless detection point. The basic feature value of each wireless detection point is used to comprehensively quantify the data detection efficiency of each wireless detection point. The wireless detection points are classified according to the terminal type to obtain the wireless detection points corresponding to each terminal type. The average value of the basic feature values of each wireless detection point is taken to obtain the average value of the basic features of each wireless detection point, which is recorded as the comprehensive feature value of each wireless detection point corresponding to each terminal type. The data processing energy efficiency characterization value of each processing node is obtained by comprehensively analyzing the operation and maintenance information of each processing node. The data processing energy efficiency characterization value of each processing node is used to comprehensively quantify the data processing capability of each processing node. The data processing energy efficiency characterization value of each processing node is matched with the range of comprehensive characteristic values of the detection point target reception corresponding to the range of data processing energy efficiency characterization value stored in the information management database. The range of comprehensive characteristic values of the detection point target reception corresponding to the range of data processing energy efficiency characterization value of each processing node is statistically calculated and recorded as the range of comprehensive characteristic values of the detection point target reception of each processing node. The comprehensive feature value of the wireless detection point corresponding to each terminal type is matched with the range of comprehensive feature values of the detection point target reception of each processing node. If the comprehensive feature value of the wireless detection point corresponding to a certain terminal type is within the range of comprehensive feature values of the detection point target reception of a certain processing node, then the terminal type is defined as the target receiving terminal type of the processing node. The process is repeated to iterate and count all target receiving terminal types of each processing node and all wireless detection points corresponding to all target receiving terminal types. All target receiving terminal types corresponding to each processing node are uniformly recorded as target receiving wireless detection points corresponding to each processing node, thereby integrating the target receiving wireless detection point cluster of each processing node.
2. The early warning system for unauthorized mobile terminals according to claim 1, characterized in that, The information processing and strategy management module also includes: The data acquisition module is used to collect statistics on each wireless detection point and each processing node, and to obtain the detection information of each wireless detection point and the operation and maintenance information of each processing node. The partition mapping module is used to obtain the security policy of the probe partition and construct the mapping relationship between the probe partition and the security policy; The strategy combination module is used to extract key partitions from the probe partitions and security policies, and to determine the combination matching degree between multiple policies in the security policy according to the key partitions to obtain the policy bias combination. The rule update module is used to perform information verification on security policies based on policy bias combinations, identify the update status of rules in security policies, and update the mapping relationship between probe partitions and security policies according to the rule update status.
3. The early warning system for unauthorized mobile terminals according to claim 2, characterized in that, The detection information of each wireless detection point includes the signal strength, data volume, and data transmission rate of each wireless detection point; The operation and maintenance information of each processing node includes the memory utilization, bandwidth utilization, data packet processing rate, and CPU utilization of each processing node.
4. The early warning system for unauthorized mobile terminals according to claim 3, characterized in that, The detection partition module is implemented in the following ways: For the detection information from each wireless detection point, obtain the intent classification model corresponding to the detection information; Use an intent classification model to classify the probe information and obtain at least one intent category; Under the corresponding intent category, identify synonyms, polysemous words, and related words in the probe information to form a text sample set; The synonyms, polysemous words, and related words in the text sample set are analyzed separately. The synonym region, polysemous word parsing region, and related word association region corresponding to the text sample set are obtained in sequence and used as the detection partition of the detection information relative to the security service.
5. The early warning system for unauthorized mobile terminals according to claim 4, characterized in that, Other methods for obtaining the synonym region, polysemous word parsing region, and related word association region corresponding to the text sample set include: Synonyms, polysemous words, and related words in the text sample set are merged according to intent categories to obtain multiple intent merging results; Extract synonym pairs from the intended merge results, compare the synonym pairs with a synonym dictionary, and obtain the synonym region; Extract the semantic change rate of polysemous words and the association strength of related words from the intent merging results. Divide the intent merging results according to the semantic change rate of polysemous words and the association strength of related words to obtain the polysemous word parsing area and the related word association area.
6. The early warning system for unauthorized mobile terminals according to claim 5, characterized in that, Other methods for determining the detection partition relative to the security service include: The detection zones are judged, and the number of detections and the detection time in the detection zones are analyzed. The detection zones are then fitted according to the number of detections and the detection time to construct a mapping relationship between the detection zones and the actual threats.
7. The early warning system for unauthorized mobile terminals according to claim 6, characterized in that, The partition mapping module is implemented in the following ways: The strategies and rules corresponding to the probe information are invoked to generate multiple unlabeled strategy recognition results. The unlabeled strategy recognition results represent strategies and rules that are not associated with words in the probe partition. Determine whether multiple unlabeled policy identification results are the target policy identification results. If they are the target policy identification results, then the target policy identification results are regarded as the security policy of the probe information.
8. The early warning system for unauthorized mobile terminals according to claim 7, characterized in that, The implementation of the mapping relationship between detection partitions and security policies includes: using the information representation of the synonym area, polysemous word parsing area and related word association area existing in the detection partition, the description information of the security policy and the category of the security policy, to construct the mapping relationship between the detection partition and the security policy.
Citation Information
Patent Citations
Method for monitoring unauthorized network equipment based on application behaviors
CN104065539A
Distributed photovoltaic intelligent operation and maintenance system
CN120601624A