Suspicious WiFi signal source detection method and system based on multi-source signal fusion

By using a multi-source signal fusion method, combining radio frequency physical characteristics and network behavior characteristics, and employing clustering algorithms and baseband signature authentication, the problem of traditional detection methods being vulnerable to attacks is solved, enabling accurate identification and risk assessment of suspicious WiFi signal sources.

CN121056873AActive Publication Date: 2025-12-02BEIJING JUNAN ZHONGKE INFORMATION TECHNOLOGY CO LTD
View PDF 10 Cites 0 Cited by

Patent Information

Application Number
CN202511121141.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-12
Publication Date
2025-12-02
Estimated Expiration
2045-08-12

AI Technical Summary

Technical Problem

In existing technologies, traditional methods for detecting suspicious WiFi signals rely on a single detection dimension, which is easily bypassed by attackers. Furthermore, signal distortion in high-noise and multipath environments leads to incorrect labeling, making it difficult to effectively identify suspicious signal sources.

Method used

A multi-source signal fusion method is adopted. By collecting radio frequency physical characteristics and network behavior characteristics in the target area, the first and second clustering algorithms are used for grouping and cross-layer consistency verification. Combined with baseband signature authentication, a signal security assessment report is generated.

Benefits of technology

It improves the accuracy of identifying suspicious WiFi signal sources, reduces the risk of being impersonated by a single feature, generates detailed signal security assessment reports, and provides a more comprehensive signal profile and risk assessment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121056873A_ABST
    Figure CN121056873A_ABST
Patent Text Reader

Abstract

The invention discloses a suspicious WiFi signal source detection method and system based on multi-source signal fusion, and the method comprises the steps: reducing the safety risk that a single feature is liable to be specifically counterfeited through a hardware layer + protocol layer feature fusion strategy, and carrying out the preliminary clustering processing based on physical features, and the secondary clustering and cross-layer detection based on behavior features. On the basis of hardware grouping, network behavior characteristics are introduced for secondary clustering, cross-layer consistency check is executed, and finally suspicious signal sources are marked; and finally, performing further verification and risk assessment on the suspicious signal source through deep verification and security assessment processing, and finally generating an operable signal security assessment report.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of suspicious WiFi signal source detection, and in particular to a method and system for detecting suspicious WiFi signal sources based on multi-source signal fusion. Background Technology

[0002] With the explosive growth in the number of public WiFi access points and the continuous evolution of wireless attack techniques, traditional methods for detecting suspicious WiFi signals often rely on a single detection dimension (such as MAC address filtering, signal strength thresholds, or isolated physical fingerprints). Attackers can bypass MAC cloning attacks (i.e., forging the MAC address of a legitimate access point to evade blacklist detection) and CFO simulation techniques (i.e., using software-defined radio (SDR) to simulate the carrier frequency offset characteristics of a target device) at low cost. Furthermore, in mainstream detection frameworks, physical clustering and behavioral clustering operate independently, ignoring the core security assumption that "the same hardware device should have consistent behavior." Attackers can construct combined attacks of "hardware spoofing + behavioral masquerading" (such as cloning a router's hardware fingerprint but injecting malicious data packets).

[0003] Meanwhile, noise in high-noise environments can cause signal distortion during signal transmission, or signal distortion due to fading and phase rotation in multipath environments, which can also lead to incorrect labeling of signal sources. Therefore, how to detect suspicious signal sources by comprehensively analyzing and suppressing noise at both the physical and network behavior levels is an urgent problem to be solved. Summary of the Invention

[0004] The purpose of this invention is to provide a method and system for detecting suspicious WiFi signal sources based on multi-source signal fusion, which solves the above-mentioned technical problems pointed out in the prior art.

[0005] This invention provides a method for detecting suspicious WiFi signal sources based on multi-source signal fusion, comprising the following steps:

[0006] Collect the radio frequency physical characteristics and network behavior characteristics of WiFi signal sources within the target area;

[0007] The radio frequency physical features are grouped using a first clustering algorithm to generate physical feature clusters;

[0008] Suspicious signal sources are identified by combining network behavior characteristics with cross-layer consistency checks on physical feature clusters using a second clustering algorithm.

[0009] Based on the analysis and processing of the signal source through local baseband signature authentication and regional security level, a signal security assessment report is generated.

[0010] Preferably, a second clustering algorithm is used to mark suspicious signal sources based on network behavior features and cross-layer consistency checks on physical feature clusters, including the following steps:

[0011] Calculate the network behavior feature vector based on the network behavior characteristics; calculate the physical feature vector based on the radio frequency physical characteristics;

[0012] Using physical feature clusters as grouping constraints, constrained hierarchical clustering analysis is performed on network behavior feature vectors. Then, combined with the behavior consistency analysis of physical feature vectors and network behavior feature vectors, the mapping relationship between network behavior feature clusters and physical feature clusters is output.

[0013] Based on the mapping relationship between network behavior feature clusters and physical feature clusters, a feature matrix is ​​established;

[0014] The mean value of the network behavior feature vector of the signal source within the physical feature cluster is recorded as the centroid coordinate of the physical feature cluster. Then, the centroid coordinates corresponding to the signal sources within multiple physical feature clusters are collected to form a set of centroid coordinates of the physical feature cluster.

[0015] The joint similarity between each pair of signal sources is calculated by combining the IQ sampling data of each signal source with the centroid coordinate set of the physical feature cluster and the feature matrix; a joint similarity matrix is ​​constructed based on the joint similarity.

[0016] Suspicious signal sources are identified by combining spectral clustering optimization with cross-layer consistency checks based on the joint similarity matrix.

[0017] Preferably, the joint similarity between any two signal sources is calculated by combining the IQ sampling data of each signal source with the set of centroid coordinates of the physical feature clusters, including the following steps:

[0018] Extract 64-QAM constellation points of OFDM symbols from IQ sampling data of each signal source, calculate constellation diagram distortion based on 64-QAM constellation points, and obtain constellation diagram compression factor based on constellation diagram distortion.

[0019] A constellation graph compression factor table is constructed based on the constellation graph compression factor.

[0020] The feature matrix is ​​scaled based on the constellation graph compression factor table to obtain the adjusted feature matrix.

[0021] The physical feature similarity between each two signal sources is calculated based on the distance from the current signal source to the centroid coordinates of the corresponding physical feature cluster; the network behavior feature similarity is calculated based on the adjusted network behavior features in the adjusted feature matrix corresponding to each two signal sources; and the joint similarity is calculated based on the physical feature similarity and the network behavior feature similarity.

[0022] Preferably, suspicious signal sources are obtained based on the joint similarity matrix by using spectral clustering optimization combined with cross-layer consistency checks, including the following steps:

[0023] A three-layer feature tensor is constructed based on the physical feature matrix, the network behavior feature matrix, and the physical feature cluster; cross-layer covariance is calculated based on the three-layer feature tensor.

[0024] Tensor singular value decomposition is performed on the three-layer feature tensor to extract the diagonal matrix; principal singular values ​​are then extracted from the diagonal matrix.

[0025] Suspicious signal sources are obtained by combining the main singular value with cross-layer deviation analysis of the signal source and multi-dimensional joint determination output based on projection clustering.

[0026] Preferably, the suspected signal source is obtained by combining the main singular value with the signal source cross-layer deviation analysis and the multidimensional joint determination output based on projection clustering, including the following steps:

[0027] The cross-layer deviation of the signal source is calculated based on the principal singular value, network behavior feature matrix, physical feature matrix, and constellation diagram distortion.

[0028] A Laplacian matrix is ​​constructed based on the signal source cross-layer deviation, joint similarity matrix, and constellation diagram distortion; the Laplacian matrix is ​​solved to obtain the first n eigenvectors v1, v2, v3...vn;

[0029] Construct a projection matrix based on the first n feature vectors; randomly generate multiple initial cluster centers z based on the projection matrix; cluster each signal source based on the minimum distance from each feature vector vn to the initial cluster center z, and stop clustering when the clustering reaches the convergence condition, and output multiple clusters;

[0030] Suspicious signal sources are obtained by multi-dimensional joint judgment based on the cross-layer deviation of signal sources in each cluster, the distortion of the constellation diagram, and the feature vector vn in each cluster.

[0031] Preferably, the calculation of the signal source cross-layer deviation includes:

[0032] The degree of deviation is calculated using the physical eigenvalues ​​in the physical feature matrix and the network behavior eigenvalues ​​in the network behavior feature matrix. The principal component weights are calculated using the principal singular values ​​and the sum of all singular values. The cross-layer deviation of the signal source is calculated based on the degree of deviation and the principal component weights.

[0033] A preferred approach is to use physical feature clusters as grouping constraints, perform constrained hierarchical clustering analysis on network behavior feature vectors, and then combine this with behavioral consistency analysis of physical feature vectors and network behavior feature vectors to filter and output the mapping relationship between network behavior feature clusters and physical feature clusters. This includes the following steps:

[0034] Identify cellular hotspot signal sources and extract the corresponding baseband modulation fingerprints. Calculate the spatial compression factor of network behavior features based on the baseband modulation fingerprints.

[0035] The second network behavior feature vector is obtained by adjusting the behavior feature vector in reverse based on the spatial compression factor.

[0036] A joint similarity matrix is ​​constructed based on the second network behavior feature vector and physical feature vector; a secondary clustering process is performed based on the joint similarity matrix to generate behavior-consistent clusters;

[0037] The behavioral consistency clusters with cluster stability indices greater than the physical behavioral consistency threshold are selected from the behavioral consistency clusters and form a mapping table between behavioral feature clusters and physical feature clusters.

[0038] Preferably, the process involves identifying cellular hotspot signals and extracting baseband modulation fingerprints, then calculating the network behavior feature spatial compression factor based on the baseband modulation fingerprints, including the following steps:

[0039] The SSID and MAC address in the signal source are parsed, and the SSID and MAC address are matched with the cellular identifier database to output the cellular tag vector of each signal source, thus obtaining the cellular signal source;

[0040] The autocorrelation function of each cellular signal source is calculated based on the Schmidl-Cox algorithm, and the starting position of OFDM symbols is determined based on the autocorrelation function and the energy function.

[0041] The frequency offset estimate is calculated by using the autocorrelation function of the OFDM symbol start position through phase rotation of the pre-trained sequence;

[0042] Phase compensation is performed on the cellular signal source using the frequency offset estimate to obtain the compensated cellular signal source;

[0043] The spatial compression factor is obtained by combining transformation correction processing with distortion compensation processing based on the symbol segments in the compensated cellular signal source.

[0044] Preferably, the spatial compression factor is obtained by combining transform correction processing with distortion compensation processing based on the symbol segments in the compensated cellular signal source, including the following steps:

[0045] FFT transformation is performed on each symbol segment in the compensated cellular signal source, and the transformed data subcarrier wind volume is extracted; phase rotation is performed on each data subcarrier component through the optimal rotation angle to obtain the corrected data subcarrier component;

[0046] Calculate the minimum Euclidean distance between every two corrected data subcarrier components; distribute the minimum Euclidean distance into a preset interval to obtain an Euclidean distance histogram; calculate the data subcarrier component distortion based on the Euclidean distance histogram, the number of corrected data subcarrier components, and the preset mean value of the data subcarrier components.

[0047] Cellular compensation is performed on the cellular signal source based on the distortion of the data subcarrier components to obtain the spatial compression factor.

[0048] Accordingly, the present invention also proposes a suspicious WiFi signal source detection system based on multi-source signal fusion, including a feature acquisition module, a first clustering module, a second clustering and labeling module, and an evaluation module;

[0049] Among them, the feature acquisition module is used to collect the radio frequency physical characteristics and network behavior characteristics of WiFi signal sources in the target area;

[0050] The first clustering module is used to group the radio frequency physical features using a first clustering algorithm to generate physical feature clusters;

[0051] The second clustering and labeling module is used to label suspicious signal sources by combining network behavior characteristics with cross-layer consistency checks on physical feature clusters through the second clustering algorithm.

[0052] The evaluation module is used to analyze and process the signal source based on local baseband signature authentication and regional security level to generate a signal security evaluation report.

[0053] Compared with the prior art, the embodiments of the present invention have at least the following technical advantages:

[0054] Analysis of the above-mentioned method and system for detecting suspicious WiFi signal sources based on multi-source signal fusion provided by this invention reveals that, in practical applications, firstly, a basic data layer for signal sources is constructed through multi-dimensional feature acquisition and processing. A "hardware layer + protocol layer feature fusion" strategy is used to reduce the security risk of targeted imitation of single features. By constructing a multi-dimensional profile, a comprehensive "signal profile" including both physical and protocol layers is established for each observable WiFi signal source within the target area. Further, through preliminary clustering based on physical features, WiFi signal sources within the target area are initially grouped using density-based DBSCAN based on hardware fingerprints to identify physically different transmitting devices and classify the signal sources according to physical devices. Further, based on behavioral features, secondary clustering and cross-layer verification are performed. On the basis of hardware grouping, network behavioral features are introduced for secondary clustering, and cross-layer consistency verification is executed, ultimately marking suspicious signal sources. Finally, through deep verification and security assessment (report generation), suspicious signal sources are further verified and risk assessed, ultimately generating an operable signal security assessment report. Attached Figure Description

[0055] Figure 1 This is a schematic diagram of the main process of a method and system for detecting suspicious WiFi signal sources based on multi-source signal fusion;

[0056] Figure 2 This is a schematic diagram simulating physical feature clusters in a method for detecting suspicious WiFi signal sources based on multi-source signal fusion.

[0057] Figure 3 This is a schematic diagram simulating the process of marking suspicious signal sources in a method for detecting suspicious WiFi signal sources based on multi-source signal fusion.

[0058] Figure 4 This is a schematic diagram of a 64-QAM constellation in a method for detecting suspicious WiFi signal sources based on multi-source signal fusion.

[0059] Figure 5 A schematic diagram simulating 64-QAM constellation diagram distortion in a method for detecting suspicious WiFi signal sources based on multi-source signal fusion;

[0060] Figure 6 This is a schematic diagram of the overall architecture of a suspicious WiFi signal source detection system based on multi-source signal fusion.

[0061] Figure labeling: Feature acquisition module 10, first clustering module 20, second clustering and labeling module 30, evaluation module 40. Detailed Implementation

[0062] The technical solution of the present invention will now be clearly and completely described with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0063] The present invention will now be described in further detail with reference to specific embodiments and accompanying drawings.

[0064] Example 1

[0065] like Figure 1 As shown, Embodiment 1 of the present invention provides a method for detecting suspicious WiFi signal sources based on multi-source signal fusion, including the following steps:

[0066] Step S10: Collect the radio frequency physical characteristics and network behavior characteristics of WiFi signal sources within the target area;

[0067] The aforementioned radio frequency physical characteristics include hardware fingerprints such as signal strength distribution, carrier frequency offset (CFO), and modulation error rate (EVM); the aforementioned network behavior characteristics include packet retransmission rate, connection request delay variation coefficient, and encrypted handshake anomaly count.

[0068] It should be noted that the above-described embodiments of this application establish a multi-dimensional signal profile of the WiFi signal source at the physical and protocol levels within the target area through hardware layer + protocol layer feature fusion, in order to identify and crack single feature spoofing (such as CFO simulation attack).

[0069] Step S20: Group the radio frequency physical features using the first clustering algorithm to generate physical feature clusters;

[0070] It should be noted that, as Figure 2 As shown, the above embodiments of this application distinguish between different hardware devices, and signals within the same cluster should originate from the same physical device (such as a router or mobile hotspot). In this embodiment, the first clustering process for radio frequency physical features is performed using a density-based DBSCAN clustering algorithm. Specifically, the radio frequency physical features of each WiFi signal source are combined into a feature vector. Then, a neighborhood radius is set, considering both the distance threshold between adjacent points and the minimum number of points (including itself) required for the cluster to form a dense region. Next, clustering begins. For each point, the number of points within its neighborhood radius is calculated. If the number of points within a point's neighborhood radius is greater than or equal to the minimum number of points threshold, then that point is marked. Take the core point as the starting point and create a new cluster. Then, starting from the core point, recursively add all points that are density-reachable to the cluster. Repeat the above process until all points are visited, resulting in multiple physical feature clusters (each cluster contains multiple points, i.e., multiple signal sources). Cluster the WIFI signal sources in the current target area based on radio frequency physical characteristics to output physical feature clusters (so physical feature clusters are data clusters obtained by clustering based on radio frequency physical characteristics). In subsequent processing, clustering is performed again based on the protocol layer and logistics layer (i.e., step S30) to closely integrate the physical layer and protocol layer, thereby improving the accuracy of signal source analysis and security assessment processing.

[0071] Step S30: Using the second clustering algorithm, based on network behavior characteristics, physical feature clusters are combined with cross-layer consistency checks to mark suspicious signal sources;

[0072] Step S40: Based on the signal source's local baseband signature authentication and regional security level, analyze and process the data to generate a signal security assessment report.

[0073] It should be noted that the above-described embodiments of this application employ a method of hierarchical feature acquisition, step-by-step clustering fusion, and cross-layer consistency verification to construct a "multi-dimensional signal profile" of the WiFi signal source from two dimensions: the hardware physical layer and the network protocol layer. By comparing whether the features of these two layers are consistent (whether they come from the same real device), the disguised or abnormal suspicious signal sources (such as malicious APs or phishing hotspots) can be detected.

[0074] Specifically, this application first constructs a basic data layer for signal sources through multi-dimensional feature acquisition and processing. It then reduces the security risk of targeted imitation (such as "CFO simulation attacks") of single features (e.g., relying solely on CFO) through a "hardware layer + protocol layer feature fusion" strategy. By constructing a multi-dimensional profile, it establishes a comprehensive "signal profile" encompassing both physical and protocol layers for each observable WiFi signal source (SSID / BSSID) within the target area. Further, it performs preliminary clustering (hardware grouping) based on physical features, using density-based DBSCAN to initially group WiFi signal sources within the target area according to hardware fingerprints (i.e., radio frequency physical features), identifying physically different transmitting devices. First, signal sources are categorized by physical device at the most stable and difficult-to-imitate hardware level. Further, based on behavioral features, secondary clustering and cross-layer verification (marking suspicious sources) are performed. Building upon hardware grouping (physical feature clusters), network behavioral features are introduced for secondary clustering, and cross-layer consistency verification is executed, ultimately marking suspicious signal sources.

[0075] Finally, through in-depth verification and security assessment (report generation), the suspicious signal sources marked in step S30 are further verified and risk assessed, ultimately generating an actionable signal security assessment report. For example, through local baseband signature authentication, suspicious signal sources are authenticated more deeply and potentially more resource-intensively, analyzing lower-level baseband signal characteristics (such as subtle signatures specific to certain chipsets), attempting to establish a secure connection with the signal source and verify its certificate or preset legitimate signature, and querying local or cloud-based databases of known malicious signatures for comparison. Regional security level analysis is also conducted, assessing the security context of the target area, for example, in high-security locations such as airports and banks. In high-risk areas, any suspicious signals should be given high priority. In public areas such as cafes, the assessment may be more lenient, or historical data can be used to determine the risk. Consider the threat level in the current network environment and generate a signal security assessment report. Based on the above analysis, the report outputs a list of confirmed suspicious signal sources (SSID / BSSID), a description of the suspicious reasons (e.g., physical imitation but abnormal behavior, highly malicious behavior, inconsistent cross-layer attribution), baseband authentication results (e.g., signature mismatch, invalid certificate), risk assessment level based on the area's security level (e.g., high risk, medium risk, low risk), and recommended measures (e.g., alarms, blocking, further monitoring).

[0076] Specifically, such as Figure 3 As shown, in step S30, the second clustering algorithm uses network behavior features to combine physical feature clusters with cross-layer consistency checks to mark suspicious signal sources, including the following steps:

[0077] Step S31: Obtain the network behavior characteristics (including packet retransmission rate, connection request delay variation coefficient, and encryption handshake anomaly count) of the data packet streams of each signal source obtained from the process in step S10; calculate the network behavior feature vector based on the network behavior characteristics; calculate the physical feature vector based on the radio frequency physical characteristics;

[0078] Step S32: Using physical feature clusters as grouping constraints, perform constrained hierarchical clustering analysis on network behavior feature vectors, and then combine the behavior consistency analysis of physical feature vectors and network behavior feature vectors to filter and output the mapping relationship between network behavior feature clusters and physical feature clusters.

[0079] Step S33: Based on the mapping relationship between network behavior feature clusters and physical feature clusters, establish a feature matrix; record the mean value of the network behavior feature vector of the signal source within the physical feature cluster (which is a cluster of multiple signal sources) as the centroid (i.e., the centroid of the cluster) coordinate of the physical feature cluster, and then gather the centroid coordinates corresponding to the signal sources within multiple physical feature clusters to form a set of centroid coordinates of the physical feature cluster.

[0080] Explanation: Physical feature clusters are obtained by clustering radio frequency physical features (such as CFO, EVM, etc.), reflecting the similarity of hardware devices (i.e., devices of the same physical device or model will be clustered together). Network behavior features (such as packet retransmission rate, connection request delay variation coefficient, encryption handshake anomaly count, etc.) reflect the device's performance at the protocol layer, which is usually related to hardware device type, device status, and network environment. The mean of the network behavior feature vectors of signal sources (i.e., devices with similar hardware) within the same physical feature cluster is taken. This mean can represent the typical network behavior of that hardware type under normal conditions. In other words, devices in the same physical cluster should have similar network behaviors. If a device is in the same physical cluster but its network behavior deviates significantly from the typical behavior (mean) of that cluster, it may indicate that the device is abnormal (e.g., controlled by an attacker or a counterfeit device). This application embodiment combines the physical layer and the network behavior layer, which is the core of cross-layer consistency verification. It uses physical layer grouping (hardware grouping) to establish a normal benchmark for the network behavior layer, and then detects the behavioral deviations of individuals within the group (i.e., within the physical layer group), thereby identifying suspicious signal sources.

[0081] In practice, based on the division of physical feature clusters, the behavioral feature vectors of signal sources within each physical cluster are extracted. For each physical cluster, the mean of the behavioral feature vectors of all signal sources within it is calculated to obtain the behavioral centroid of that physical cluster (note: this centroid is a point in the behavioral feature space). The physical layer and the network behavior layer are combined, meaning that the network behavior of devices in the same physical cluster should be close to this behavioral centroid. If the network behavior characteristics of a device deviate significantly from the behavioral centroid of its physical cluster, then the device may be abnormal. Subsequent steps (S34 and later) use the network behavior centroid to calculate the behavioral deviation of each signal source, and then combine it with other indicators (such as constellation diagram distortion) to mark suspicious signal sources.

[0082] Network behavior features are essentially a quantitative analysis of data packets and network behavior characteristics. However, the aforementioned physical feature clusters are feature labels for nodes (hot spots), terminals, and / or routers that adapt to different types of network behavior.

[0083] For example, Table 1 below shows the feature matrix established based on the mapping relationship. The horizontal columns represent five feature vector items: signal source, physical feature cluster, packet retransmission rate, connection request delay variation coefficient, and encrypted handshake anomaly count. The vertical columns represent the numerical values ​​corresponding to the feature vector items.

[0084] signal source Physical feature clusters Packet retransmission rate (%) Connection request latency variation coefficient Encrypted handshake exception count AP1 Cluster 1 1.2 0.15 0 AP2 Cluster 2 0.8 0.12 1 AP3 Cluster 3 15.7 0.83 5

[0085] In Table 1 above, the 15.7% retransmission rate (normal <5%) and 0.83 coefficient of variation of delay (normal <0.3) of signal source 3 (i.e. AP3) indicate anomalies; steps S31-S33 are all traversal and analysis processing performed on each signal source, and the subsequent step S34 continues to analyze the constellation diagram distortion and constellation diagram compression factor (constellation diagram compression factor or first compression factor) of each signal source.

[0086] Step S34: Extract the 64-QAM constellation points of OFDM symbols (OFDM symbols are the basic transmission units of the 802.11 standard, composed of multiple orthogonal subcarriers) from the IQ sampling data (i.e., the IQ sampling data is a complex signal sequence (I is the real part, Q is the imaginary part), from the ADC output of the WiFi receiver, which can be extracted from the signal source) from each signal source; calculate the constellation diagram distortion based on the 64-QAM constellation points; obtain the constellation diagram compression factor based on the constellation diagram distortion; construct a constellation diagram compression factor table based on the constellation diagram compression factor.

[0087] It should be noted that in the above embodiments of this application, 64-QAM (64th-order quadrature amplitude modulation) is a modulation method commonly used in digital communication systems. It achieves high data transmission rates by combining 6 bits of information (each bit representing a state). 64-QAM has 64 different constellation points, each representing a different 6-bit binary number; the 64-QAM constellation diagram is a two-dimensional diagram, as shown below. Figure 4 As shown, each point represents a specific complex value, typically on orthogonal I (in-phase) and Q (orthogonal) axes. For a more intuitive understanding, these constellation points are arranged in an 8×8 grid. Specifically, the 64 constellation points are distinguished by eight different horizontal and vertical positions, the intervals of which depend on the amplitude and phase of the signal. In 64-QAM, the I and Q axes are usually arranged with positive integer intervals (e.g., -7, -5, -3, -1, 1, 3, 5, 7). Each combination of points represents a different symbol, and the coordinates (I, Q) of each constellation point correspond to a specific bit sequence. In 64-QAM, each constellation point corresponds to a specific bit value, and these bits are typically arranged according to the following rules:

[0088] Six bits can represent 64 possible combinations, each combination corresponding to a different constellation point;

[0089] Each point in the constellation diagram is distinguished by its coordinates on the I-axis and Q-axis. For example, (3,5) may represent 011010, while (-1,-3) may represent 101101.

[0090] The above-described embodiments of this application employ 64-QAM, which, since each constellation point represents 6 bits, provides a higher data rate compared to QPSK (each point represents 2 bits) and 16-QAM (each point represents 4 bits).

[0091] like Figure 5 As shown, the constellation diagram distortion described above describes the offset and shape deformation of constellation points in their ideal positions due to various factors (such as noise, channel fading, nonlinear effects, etc.). Ideally, each constellation point in the constellation diagram should be uniformly distributed according to prescribed rules (such as the I-axis and Q-axis coordinates of QAM modulation) and maintain a fixed relative position. However, in actual communication, the signal may be distorted after transmission, affecting the system performance. That is, during transmission, the signal may be interfered with by noise, causing the constellation points at the receiving end to shift, thus producing distortion. Or, in a multipath environment, the signal may experience fading and phase rotation, causing changes in the position of the constellation points. Alternatively, the nonlinear characteristics of devices such as modems and power amplifiers may cause deformation of the constellation points, resulting in constellation diagram distortion. The constellation diagram compression factor is inversely proportional to the constellation diagram distortion; as the distortion increases, the constellation diagram compression factor decreases.

[0092] Constellation diagram compression factor is typically used to describe the changes that occur in a signal during certain processing (such as signal compression or encoding). In particular, in digital signal processing, the constellation diagram compression factor is used to quantify the degree of compression of a signal or data. In this application embodiment, the constellation diagram compression factor is calculated by constellation diagram distortion to compress the behavioral feature weights of high-distortion signals (such as malicious devices), thereby avoiding excessive noise interference caused by high-distortion signals.

[0093] For example, Table 2 below shows the compression factor table for the constructed constellation diagram:

[0094] signal source Distortion of constellation chart Constellation chart compression factor AP1 0.05 0.95 AP3 0.41 0.71

[0095] Step S35: Perform feature scaling on the feature matrix based on the constellation graph compression factor table to obtain the adjusted feature matrix (the adjusted feature matrix is ​​the feature matrix after scaling by the constellation graph compression factor based on the mapping relationship between network behavior feature clusters and physical feature clusters in S33 above).

[0096] For example, Table 3 below shows the adjusted feature matrices of each signal source after feature scaling based on the compression factor table:

[0097] signal source Physical feature clusters Adjusted packet retransmission rate Adjusted connection request latency variation coefficient Adjusted encrypted handshake anomaly count AP1 Cluster 1 1.14 0.1425 0 AP3 Cluster 2 11.15 0.589 3.55

[0098] Based on the constellation diagram compression factor table mentioned above, the feature matrix is ​​scaled. Taking signal source 3 (i.e. AP3) as an example, the abnormal features are attenuated (scaled from 15.7 to 11.15), reducing the impact on subsequent clustering.

[0099] Step S36: Calculate the physical feature similarity between each two signal sources based on the distance from the current signal source to the centroid coordinates of the corresponding physical feature cluster; calculate the network behavior feature similarity based on the adjusted network behavior features in the adjusted feature matrix corresponding to each two signal sources; calculate the joint similarity based on the physical feature similarity and the network behavior feature similarity.

[0100] It should be noted that the above-described embodiment of this application first calculates the single-point physical feature similarity (single-point physical feature similarity refers to the similarity of the centroid coordinates of a single signal source and its corresponding physical feature cluster) based on the Mahalanobis distance between the centroid coordinates of the i-th signal source and the corresponding physical feature cluster. Then, it calculates the physical feature similarity between every two single-point physical feature similarities (i.e., the sum of the two single-point physical feature similarities divided by 2). Then, it calculates the comprehensive similarity of the adjusted network behavior features (i.e., the adjusted data packet retransmission rate, the adjusted connection request delay variation coefficient, and the adjusted encrypted handshake anomaly count) in the adjusted feature matrix of every two signal sources as the network behavior feature similarity. Finally, it performs a weighted summation of the physical feature similarity and the network behavior feature similarity to obtain the joint similarity.

[0101] For example, Table 4 below shows the generated joint similarity matrix:

[0102] AP1 AP2 AP3 AP1 1.00 0.92 0.15 AP2 0.92 1.00 0.18 AP3 0.15 0.18 1.00

[0103] In Table 4 above, the intersection of the horizontal and vertical signal sources represents the joint similarity between the two signal sources. Analyzing Table 4, it can be seen that signal source 1 (i.e., AP1) and signal source 2 (i.e., AP2) are highly similar, while signal source 3 (i.e., AP3) is less similar to other points.

[0104] Step S37: Based on the joint similarity matrix, suspicious signal sources are obtained by combining spectral clustering optimization with cross-layer consistency testing.

[0105] It should be noted that the above embodiments of this application first construct the data foundation of protocol layer behavioral features through network behavioral feature extraction. Then, using physical feature clusters (hardware groups) as boundaries, behavioral clustering is performed only on signal sources within the same physical cluster. Behavioral features are analyzed within the physical grouping framework to establish a cross-layer mapping (i.e., the mapping table between the aforementioned behavioral clusters and physical clusters). The "normal behavioral benchmark" of the physical cluster is quantified through feature matrix construction and centroid calculation to provide a reference for anomaly detection. Then, signal quality interference sources are identified by constellation diagram distortion and constellation diagram compression factor calculation to suppress the noise impact of high-distortion signals. In a further scheme of step S35, feature scaling is used to dynamically adjust the weight of behavioral features based on signal quality, so that the features of high-distortion signals are attenuated to prevent them from dominating clustering, and the abnormal information is retained but the amplitude is reduced to avoid misjudgment caused by signal quality. Then, through the joint similarity matrix generation in S36, the similarity between the physical layer and the protocol layer is fused to construct a cross-layer association model. Finally, suspicious signal sources are marked through spectral clustering optimization, and high-confidence suspicious signal sources are locked based on cross-layer consistency.

[0106] Specifically, in step S37, suspicious signal sources are obtained based on the joint similarity matrix by using spectral clustering optimization combined with cross-layer consistency verification, including the following steps:

[0107] Step S371: Construct a three-layer feature tensor based on the physical feature matrix, network behavior feature matrix, and physical feature clusters; calculate the cross-layer covariance based on the three-layer feature tensor;

[0108] It should be noted that in the above three-layer feature tensors, tensor slices represent the joint distribution of physical-behavioral features of all signal sources within the physical feature cluster;

[0109] Step S372: Perform tensor singular value decomposition on the three-layer feature tensor and extract the diagonal matrix; extract the principal singular values ​​from the diagonal matrix;

[0110] It should be noted that in the above embodiments of this application, the three-layer feature tensor is decomposed by singular value decomposition to obtain the left singular matrix, the diagonal matrix and the right singular matrix. The elements on the diagonal of the diagonal matrix are the singular values ​​of the three-layer feature tensor. In this embodiment, the singular values ​​reflect the joint distribution of the physical-behavioral features of the signal source in the three-layer feature vector. This embodiment extracts the singular values ​​on the diagonal of the diagonal matrix and performs principal component extraction to obtain the principal singular values, which reflect the cross-layer correlation strength of the physical-behavioral features of the signal source.

[0111] Step S373: Calculate the cross-layer deviation of the signal source based on the principal singular value, network behavior feature matrix, physical feature matrix, and constellation diagram distortion.

[0112] The method for calculating the cross-layer deviation of the signal source is as follows: ;

[0113] In the formula, The signal source cross-layer deviation of the i-th signal source (the larger the value, the more suspicious); The number of dimensions of the physical feature matrix; The number of dimensions in the network behavior feature matrix; Let j be the physical characteristic value of the i-th signal source; This represents the k-th network behavior feature value of the i-th signal source. Let be the expected value of the cross-layer features of the m-th physical feature cluster of the i-th signal source; Let be the covariance between the j-th physical feature and the k-th network behavior feature of the m-th physical feature cluster of the i-th signal source (i.e., the correlation strength between the j-th physical feature and the k-th network behavior feature). It is a natural constant (to prevent the denominator from being 0); Let be the principal singular value of the m-th physical feature cluster of the i-th signal source; It is the sum of the singular values ​​of the m-th physical feature cluster of the i-th signal source;

[0114] It should be noted that the above embodiments of this application are achieved through... The degree to which the quantized signal source i deviates from the expected value of its physical cluster in the product of physical feature j and behavioral feature k is determined by utilizing... Principal component weights are allocated, and then a multi-dimensional joint evaluation is achieved by comprehensively calculating the weighted average deviation of all physical-behavioral feature combinations. This includes preventing suspicious signal sources caused by MAC cloning through joint verification at the physical layer (CFO) and the behavioral layer (retransmission rate), and preventing suspicious signal sources caused by hardware emulation by quantifying the degree of hardware and protocol correlation disruption. Forced binding of hardware and network behavior to prevent suspicious signal sources caused by protocol stack spoofing;

[0115] Step S374: Construct the Laplacian matrix based on the signal source cross-layer deviation, joint similarity matrix, and constellation diagram distortion; solve the Laplacian matrix to obtain the first n eigenvectors v1, v2, v3...vn;

[0116] Step S375: Construct a projection matrix based on the first n feature vectors; randomly generate multiple initial cluster centers z based on the projection matrix; cluster each signal source based on the minimum distance from each feature vector vn to the initial cluster center z, and stop clustering when the clustering reaches the convergence condition, and output multiple clusters;

[0117] Step S376: Based on the cross-layer deviation of the signal source in each cluster, the constellation diagram distortion, and the feature vector vn in each cluster, perform a multi-dimensional joint judgment output to obtain the suspicious signal source;

[0118] The specific method for multi-dimensional joint determination is as follows:

[0119] ;

[0120] In the above formula, Let be the cross-layer deviation of the signal source for the i-th signal source. The threshold for cross-layer deviation; The threshold for constellation diagram distortion. For baseband signature verification;

[0121] It should be noted that in the above embodiments of this application, the signal sources marked as high-risk suspicious signal sources have extremely large deviations and fail baseband signature verification, while the medium-risk suspicious signal sources have large deviations or high modulation distortions. In this embodiment of the application, cross-layer deviation is introduced as a weight into clustering, making it easier to identify points with large deviations (which may be anomalies) during the clustering process (which may form small clusters or outliers), so that subsequent threat determination can focus more on these anomalous clusters.

[0122] Specifically, in step S32, using physical feature clusters as grouping constraints, constrained hierarchical clustering analysis is performed on the network behavior feature vectors. Then, combined with the behavior consistency analysis of physical feature vectors and network behavior feature vectors, the mapping relationship between network behavior feature clusters and physical feature clusters is output, including the following steps:

[0123] Step S321: Identify cellular hotspot signal sources and extract the baseband modulation fingerprints corresponding to the cellular hotspot signal sources; calculate the network behavior feature spatial compression factor based on the baseband modulation fingerprints.

[0124] Step S322: Adjust the behavior feature vector in reverse based on the spatial compression factor to obtain the second network behavior feature vector;

[0125] Step S323: Construct a joint similarity matrix based on the second network behavior feature vector and physical feature vector; perform secondary clustering based on the joint similarity matrix to generate behavior-consistent clusters;

[0126] Step S324: Select behaviorally consistent clusters whose cluster stability index is greater than the physical behavioral consistency threshold and form a mapping table between behavioral feature clusters and physical feature clusters.

[0127] It should be noted that in the above embodiments of this application, the hotspot signals (such as mobile hotspots) and ordinary WiFi signals from cellular networks are first distinguished by identifying cellular hotspot signals. Cellular hotspot signals and WiFi signals have different behavioral characteristics, so they need to be specially processed. That is, the baseband modulation fingerprint is extracted, and the modulation layer features (such as modulation error) are obtained by analyzing the baseband modulation characteristics (such as constellation diagram). Then, based on the baseband modulation fingerprint, a spatial compression factor is calculated to adjust the weight of the behavioral feature vector. For example, if the baseband modulation fingerprint shows that the signal quality is poor (large distortion), the behavioral characteristics of the signal may be considered unreliable. Therefore, the influence of its behavioral characteristics in clustering is reduced by the compression factor. The behavioral characteristics are adjusted by the compression factor to reduce the weight of abnormal behavioral characteristics caused by poor channel conditions or device hardware problems, so as to avoid misjudging these situations as malicious behavior.

[0128] Furthermore, the original behavioral feature vector is adjusted using the compression factor obtained in step S322. The feature is scaled according to the compression factor (for example, the feature value decreases when the compression factor is less than 1 and increases when it is greater than 1) to obtain a new behavioral feature vector (second network behavioral feature vector). The adjusted behavioral feature vector can better reflect the real device behavior, eliminate the distortion caused by channel or hardware problems, and make subsequent clustering more accurate.

[0129] The above steps comprehensively consider the adjusted behavioral and physical characteristics, calculate the similarity between signal sources, construct a joint similarity matrix, and use the joint similarity matrix for clustering (e.g., hierarchical clustering) to generate new clusters (called behavioral consistency clusters). These new clusters simultaneously consider the characteristics of the physical and behavioral layers. Through cross-layer joint clustering, signals that are inconsistent between the physical and behavioral layers are detected. For example, if devices in the same physical cluster (with similar hardware) are assigned to different behavioral clusters, it may indicate abnormal behavior and thus be identified as suspicious. Further, the stability index (e.g., the density of samples within the cluster) of each behavioral consistency cluster is calculated through the processing in step S325. Only clusters with high stability are retained as valid mapping relationships to ensure the reliability of the mapping relationships. Only stable mapping relationships are adopted. In the subsequent cross-layer consistency test, signals with unclear mapping relationships (i.e., signals not in stable clusters) can be directly regarded as abnormal and thus marked as suspicious signals.

[0130] The above-described embodiments of this application achieve clustering of behavioral features under the constraint of physical grouping through steps S321-S325, and establish a mapping relationship between physical clusters and behavioral clusters. This mapping relationship is used for subsequent cross-layer consistency checks. If a signal source physically belongs to a certain cluster, but its behavioral features do not belong to the behavioral cluster corresponding to that physical cluster, it is considered inconsistent and may be marked as suspicious. In addition, the sensitivity to malicious signals is improved by adjusting the behavioral features through compression factors, and the reliability of the mapping is ensured by stability screening to reduce false alarms.

[0131] Additionally, it should be noted that the spatial compression factor in step S322 of the above-mentioned embodiment of this application is fundamentally different from the compression factor in step S34. The spatial compression factor in step S322 is a pre-filter of the behavioral feature space, which dynamically scales the feature vector through baseband distortion and belongs to the category of data preprocessing. For example, the high distortion signal of a malicious device will be compressed with weights (α=0.66), just like putting noise-canceling headphones on noisy data. On the other hand, the constellation diagram compression factor in step S34 is a post-adjustment in the deviation calculation. It standardizes the cross-layer deviation based on the covariance matrix and belongs to statistical processing technology. When the feature fluctuation is large (covariance 1.5), a larger deviation is allowed without triggering an alarm.

[0132] Specifically, in step S322, cellular hotspot signals are identified and baseband modulation fingerprints are extracted. Based on the baseband modulation fingerprints, the network behavior feature space compression factor is calculated, including the following steps:

[0133] Step S3221: Parse the SSID and MAC address in the signal source, match the SSID and MAC address with the cellular identifier database, and output the cellular marker vector of each signal source to obtain the cellular signal source;

[0134] It should be noted that in the above embodiment of this application, the cellular tag vector of the signal source is set to 1 when the SSID and MAC address of the signal source simultaneously meet the matching conditions of the cellular identifier library; otherwise, it is set to 0. Thus, a cellular signal source with the tag vector set to 1 (i.e., a cellular hotspot signal source) can be obtained.

[0135] Step S3222: Calculate the autocorrelation function of each cellular signal source based on the Schmidl-Cox algorithm, and determine the starting position of the OFDM symbol based on the autocorrelation function and the energy function; calculate the frequency offset estimate by using the autocorrelation function of the OFDM symbol starting position through phase rotation of the pre-trained sequence; use the frequency offset estimate to perform phase compensation on the cellular signal source to obtain the compensated cellular signal source.

[0136] It should be noted that in the above embodiments of this application, since the received signal is continuous, the starting position of each OFDM symbol is determined to ensure correct segmentation, thereby improving the accuracy of subsequent analysis of suspicious signal sources. The Schmidl-Cox algorithm is employed, which uses the autocorrelation of the training sequence (a known repeating structure) to locate the starting point of the OFDM symbol. Furthermore, due to the local oscillator frequency deviation between the transmitting and receiving ends and the Doppler effect, the signal exhibits carrier frequency offset, causing constellation rotation. The frequency offset is estimated using the phase rotation information of the training sequence, and then the estimated frequency offset is used to perform phase compensation processing on the cellular signal source, resulting in a compensated cellular signal source. This eliminates time and frequency offsets during signal transmission, establishing a reference coordinate system for accurate analysis. Additionally, it should be noted that in the compensated cellular signal source, since the above compensation is achieved by processing and adjusting the segmented signal, the compensated cellular signal source is displayed in segmented form, for example, Ri={r1, r2, ...rn}.

[0137] Step S3223: Perform FFT transformation on each symbol segment in the compensated cellular signal source and extract the transformed data subcarrier wind volume; perform phase rotation processing on each data subcarrier component through the optimal rotation angle to obtain the corrected data subcarrier component;

[0138] It should be noted that in the above embodiments of this application, the symbol segment of the compensated cellular signal source consists of multiple subcarriers in the frequency domain, and each subcarrier is modulated with data symbols. Therefore, it is necessary to convert to the frequency domain for analysis. Thus, this embodiment of the application uses FFT transformation to process and extract the data subcarrier components. In addition, although step S3222 compensates for the common carrier frequency offset, each subcarrier may still have residual phase offset (due to channel phase response, etc.). Therefore, this embodiment of the application corrects each data subcarrier component by performing phase rotation processing with the optimal rotation angle to obtain the corrected data subcarrier components. Specifically, by finding the optimal rotation angle of the data subcarrier components, and then performing phase rotation on the data subcarrier components according to the optimal rotation angle, the phase rotation caused by the channel, etc., is eliminated, so that the distribution of the corrected data subcarrier components reflects the modulation characteristics of the device itself.

[0139] Step S3224: Calculate the minimum Euclidean distance between every two corrected data subcarrier components; distribute the minimum Euclidean distance into a preset interval to obtain an Euclidean distance histogram; calculate the data subcarrier component distortion based on the Euclidean distance histogram, the number of corrected data subcarrier components, and the preset mean value of the data subcarrier components.

[0140] Step S3226: Perform cellular compensation on the cellular signal source based on the distortion of the data subcarrier components to obtain the spatial compression factor;

[0141] It should be noted that in the above embodiments of this application, firstly, by parsing the SSID (network name) and MAC address (hardware address) in the beacon frame and comparing them with a predefined cellular identifier database, operator equipment (mobile hotspots) and ordinary WiFi devices (routers) are distinguished, avoiding operator equipment being misjudged as malicious signals. For example, a user's mobile hotspot (f_i=1) in a shopping mall will not be misjudged. Further, in step S3222, time-frequency synchronization and compensation are used to optimize the time misalignment and frequency drift problems in signal transmission, establishing a reference coordinate system for accurate analysis and eliminating constellation rotation caused by environmental interference. Further, through subcarrier correction processing, channel influence and inherent device characteristics are separated to extract a pure hardware modulation fingerprint. Then, in S3224, the distortion of data subcarrier components is used to quantify the degree of device modulation defects, providing a basis for behavioral feature compression and directly reflecting hardware anomalies. Finally, in S3225, the behavioral feature weights are dynamically adjusted according to the modulation quality to suppress the impact of highly suspicious signals on clustering.

[0142] Example 2

[0143] like Figure 6As shown, on the other hand, based on the method for detecting suspicious WiFi signal sources based on multi-source signal fusion provided in Embodiment 1 of the invention, this second embodiment also provides a system for detecting suspicious WiFi signal sources based on multi-source signal fusion, including a feature acquisition module 10, a first clustering module 20, a second clustering and labeling module 30, and an evaluation module 40.

[0144] The feature acquisition module 10 is used to acquire the radio frequency physical characteristics and network behavior characteristics of WiFi signal sources within the target area.

[0145] The first clustering module 20 is used to group the radio frequency physical features using a first clustering algorithm to generate physical feature clusters;

[0146] The second clustering and labeling module 30 is used to label suspicious signal sources by combining network behavior characteristics with cross-layer consistency checks on physical feature clusters through the second clustering algorithm.

[0147] The evaluation module 40 is used to analyze and process the signal source based on local baseband signature authentication and regional security level to generate a signal security evaluation report.

[0148] In summary, the present invention proposes a method and system for detecting suspicious WiFi signal sources based on multi-source signal fusion. By employing hierarchical feature acquisition, step-by-step clustering fusion, and cross-layer consistency verification, a "multi-dimensional signal profile" of WiFi signal sources is constructed from two dimensions: the hardware physical layer and the network protocol layer. By comparing whether the features of these two layers are consistent (whether they come from the same real device), the disguised or abnormal suspicious signal sources (such as malicious APs or phishing hotspots) can be detected.

[0149] In practice, based on physical feature clusters, a cross-layer mapping between network behavior features and the physical layer is established. The constellation diagram distortion and constellation diagram compression factor are calculated to identify signal quality interference sources. The feature matrix is ​​scaled. By calculating joint similarity, spectral clustering optimization is used to mark suspicious signal sources. Based on cross-layer consistency, high-confidence suspicious signal sources are locked.

[0150] Furthermore, by calculating the cross-layer deviation of signal sources at both the physical and network behavior characteristic levels, subsequent threat assessments can be more focused on these anomalous clusters.

[0151] Furthermore, by introducing spatial compression factor identification of cellular hotspot signals and performing secondary clustering based on joint similarity matrix to generate behaviorally consistent clusters, clusters with high stability are selected and retained as effective mapping relationships to ensure the reliability of the mapping relationships.

[0152] Furthermore, by transforming, correcting, and compensating the cellular signal source, a spatial compression factor is obtained. The weights of behavioral features are dynamically adjusted according to the modulation quality to suppress the influence of highly suspicious signals on clustering.

[0153] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; those skilled in the art can modify the technical solutions described in the foregoing embodiments, or make equivalent substitutions for some or all of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method for detecting suspicious WiFi signal sources based on multi-source signal fusion, characterized in that, The following steps are included: Collect the radio frequency physical characteristics and network behavior characteristics of WiFi signal sources within the target area; The radio frequency physical features are grouped using a first clustering algorithm to generate physical feature clusters; Suspicious signal sources are identified by combining network behavior characteristics with cross-layer consistency checks on physical feature clusters using a second clustering algorithm. Based on the analysis and processing of the signal source through local baseband signature authentication and regional security level, a signal security assessment report is generated.

2. The method for detecting suspicious WiFi signal sources based on multi-source signal fusion according to claim 1, characterized in that, The second clustering algorithm, based on network behavior characteristics and combined with cross-layer consistency checks, identifies suspicious signal sources. The steps include: Calculate the network behavior feature vector based on the network behavior characteristics; calculate the physical feature vector based on the radio frequency physical characteristics; Using physical feature clusters as grouping constraints, constrained hierarchical clustering analysis is performed on network behavior feature vectors. Then, combined with the behavior consistency analysis of physical feature vectors and network behavior feature vectors, the mapping relationship between network behavior feature clusters and physical feature clusters is output. Based on the mapping relationship between network behavior feature clusters and physical feature clusters, a feature matrix is ​​established; The mean value of the network behavior feature vector of the signal source within the physical feature cluster is recorded as the centroid coordinate of the physical feature cluster. Then, the centroid coordinates corresponding to the signal sources within multiple physical feature clusters are collected to form a set of centroid coordinates of the physical feature cluster. The joint similarity between each pair of signal sources is calculated by combining the IQ sampling data of each signal source with the centroid coordinate set of the physical feature cluster and the feature matrix; a joint similarity matrix is ​​constructed based on the joint similarity. Suspicious signal sources are identified by combining spectral clustering optimization with cross-layer consistency checks based on the joint similarity matrix.

3. The method for detecting suspicious WiFi signal sources based on multi-source signal fusion according to claim 2, characterized in that, The joint similarity between any two signal sources is calculated by combining the IQ sampling data of each signal source with the centroid coordinate set of the physical feature cluster. The steps include the following: Extract 64-QAM constellation points of OFDM symbols from IQ sampling data of each signal source, calculate constellation diagram distortion based on 64-QAM constellation points, and obtain constellation diagram compression factor based on constellation diagram distortion. A constellation graph compression factor table is constructed based on the constellation graph compression factor. The feature matrix is ​​scaled based on the constellation graph compression factor table to obtain the adjusted feature matrix. The physical feature similarity between each two signal sources is calculated based on the distance from the current signal source to the centroid coordinates of the corresponding physical feature cluster; the network behavior feature similarity is calculated based on the adjusted network behavior features in the adjusted feature matrix corresponding to each two signal sources; and the joint similarity is calculated based on the physical feature similarity and the network behavior feature similarity.

4. The method for detecting suspicious WiFi signal sources based on multi-source signal fusion according to claim 3, characterized in that, Based on the joint similarity matrix, suspicious signal sources are identified through spectral clustering optimization combined with cross-layer consistency checks. The steps include: A three-layer feature tensor is constructed based on the physical feature matrix, the network behavior feature matrix, and the physical feature cluster; cross-layer covariance is calculated based on the three-layer feature tensor. Tensor singular value decomposition is performed on the three-layer feature tensor to extract the diagonal matrix; principal singular values ​​are then extracted from the diagonal matrix. Suspicious signal sources are obtained by combining the main singular value with cross-layer deviation analysis of the signal source and multi-dimensional joint determination output based on projection clustering.

5. The method for detecting suspicious WiFi signal sources based on multi-source signal fusion according to claim 4, characterized in that, Suspicious signal sources are identified by combining cross-layer deviation analysis of the signal source with multidimensional joint determination output based on projection clustering, based on the principal singular value, including the following steps: The cross-layer deviation of the signal source is calculated based on the principal singular value, network behavior feature matrix, physical feature matrix, and constellation diagram distortion. A Laplacian matrix is ​​constructed based on the signal source cross-layer deviation, joint similarity matrix, and constellation diagram distortion; the Laplacian matrix is ​​solved to obtain the first n eigenvectors v1, v2, v3...vn; Construct a projection matrix based on the first n feature vectors; randomly generate multiple initial cluster centers z based on the projection matrix; cluster each signal source based on the minimum distance from each feature vector vn to the initial cluster center z, and stop clustering when the clustering reaches the convergence condition, and output multiple clusters; Suspicious signal sources are obtained by multi-dimensional joint judgment based on the cross-layer deviation of signal sources in each cluster, the distortion of the constellation diagram, and the feature vector vn in each cluster.

6. The method for detecting suspicious WiFi signal sources based on multi-source signal fusion according to claim 5, characterized in that, The calculation of the signal source cross-layer deviation includes: The degree of deviation is calculated using the physical eigenvalues ​​in the physical feature matrix and the network behavior eigenvalues ​​in the network behavior feature matrix. The principal component weights are calculated using the principal singular values ​​and the sum of all singular values. The cross-layer deviation of the signal source is calculated based on the degree of deviation and the principal component weights.

7. The method for detecting suspicious WiFi signal sources based on multi-source signal fusion according to claim 6, characterized in that, Using physical feature clusters as grouping constraints, constrained hierarchical clustering analysis is performed on network behavior feature vectors. Then, combined with behavioral consistency analysis of physical feature vectors and network behavior feature vectors, the mapping relationship between network behavior feature clusters and physical feature clusters is output, including the following steps: Identify cellular hotspot signal sources and extract the corresponding baseband modulation fingerprints. Calculate the spatial compression factor of network behavior features based on the baseband modulation fingerprints. The second network behavior feature vector is obtained by adjusting the behavior feature vector in reverse based on the spatial compression factor. A joint similarity matrix is ​​constructed based on the second network behavior feature vector and physical feature vector; a secondary clustering process is performed based on the joint similarity matrix to generate behavior-consistent clusters; The behavioral consistency clusters with cluster stability indices greater than the physical behavioral consistency threshold are selected from the behavioral consistency clusters and form a mapping table between behavioral feature clusters and physical feature clusters.

8. The method for detecting suspicious WiFi signal sources based on multi-source signal fusion according to claim 7, characterized in that, Identifying cellular hotspot signals and extracting baseband modulation fingerprints, and calculating the network behavior feature spatial compression factor based on the baseband modulation fingerprints, includes the following steps: The SSID and MAC address in the signal source are parsed, and the SSID and MAC address are matched with the cellular identifier database to output the cellular tag vector of each signal source, thus obtaining the cellular signal source; The autocorrelation function of each cellular signal source is calculated based on the Schmidl-Cox algorithm, and the starting position of OFDM symbols is determined based on the autocorrelation function and the energy function. The frequency offset estimate is calculated by using the autocorrelation function of the OFDM symbol start position through phase rotation of the pre-trained sequence; Phase compensation is performed on the cellular signal source using the frequency offset estimate to obtain the compensated cellular signal source; The spatial compression factor is obtained by combining transformation correction processing with distortion compensation processing based on the symbol segments in the compensated cellular signal source.

9. A method for detecting suspicious WiFi signal sources based on multi-source signal fusion according to claim 8, characterized in that, Based on the symbol segments in the compensated cellular signal source, the spatial compression factor is obtained through transform correction and distortion compensation operations, including the following steps: FFT transformation is performed on each symbol segment in the compensated cellular signal source, and the transformed data subcarrier wind volume is extracted; phase rotation is performed on each data subcarrier component through the optimal rotation angle to obtain the corrected data subcarrier component; Calculate the minimum Euclidean distance between every two corrected data subcarrier components; distribute the minimum Euclidean distances into a preset interval to obtain an Euclidean distance histogram; The distortion of the data subcarrier components is calculated based on the Euclidean distance histogram, the number of corrected data subcarrier components, and the preset mean value of the data subcarrier components. Cellular compensation is performed on the cellular signal source based on the distortion of the data subcarrier components to obtain the spatial compression factor.

10. A suspicious WiFi signal source detection system based on multi-source signal fusion, characterized in that, It includes a feature acquisition module, a first clustering module, a second clustering and labeling module, and an evaluation module; The feature acquisition module is used to acquire the radio frequency physical characteristics and network behavior characteristics of WiFi signal sources within the target area; the first clustering module is used to group the radio frequency physical characteristics using a first clustering algorithm to generate physical feature clusters; the second clustering and labeling module is used to label suspicious signal sources by combining network behavior characteristics with cross-layer consistency checks on the physical feature clusters using a second clustering algorithm; and the evaluation module is used to analyze and process the signal sources based on local baseband signature authentication and regional security levels to generate a signal security evaluation report.

Citation Information

Patent Citations

  • Method and system for recognizing camouflaged WiFi by use of physical layer information

    CN106973387A

  • Wi-Fi location deception detection method and device based on radio frequency fingerprint

    CN109151827A

  • Pseudo access point detection method and device and computer readable storage medium

    CN109936848A

  • Intelligent risk control method, device and equipment for multi-source data fusion and storage medium

    CN119046647A

  • Data security analysis system and method based on artificial intelligence

    CN119179987A