5G network dynamic security capability scheduling method based on deep learning
By constructing a security posture data sequence in the 5G network and dynamically scheduling security protection units, the problems of response delay and resource imbalance caused by static configuration in the existing technology are solved, and real-time security adaptation and optimization for complex network environments are achieved.
Patent Information
- Application Number
- CN202511612520.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-06
- Publication Date
- 2025-12-05
- Estimated Expiration
- 2045-11-06
AI Technical Summary
Existing 5G network security protection methods are mostly statically configured, which are difficult to adapt to complex and ever-changing network environments, resulting in large response delays, uneven resource utilization, inability to adapt to risk levels in real time, and inability to effectively deal with network attacks and security threats.
By using deep learning-based methods, the system continuously collects the state parameters of network slices, constructs a security situation data sequence, extracts security feature factors, generates dynamic risk judgment signals, and dynamically schedules security protection units based on risk intensity and resource occupancy distribution, forming a self-correcting feedback loop to achieve dynamic switching and optimization of security capabilities.
It enables real-time response and protection against cybersecurity risks, reduces the security response imbalance caused by model drift, and improves the overall security and resource utilization efficiency of 5G networks.
Smart Images

Figure CN121078436A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The application relates to the technical field of network capability scheduling, in particular to a 5G network dynamic security capability scheduling method based on deep learning. BACKGROUND
[0002] The wide-area coverage, complex topology structure and diversified service scenarios of the 5G network bring more complex security challenges. Network attack means are diversified, including distributed denial of service attack (DDoS), intrusion penetration, malicious traffic injection and the like, which seriously threaten the stability and security of the network. The 5G network adopts new technologies such as network slicing and edge computing, so that the security protection strategy needs to have dynamic adjustment capability to adapt to the real-time changes of network state and security situation. The existing network security protection methods are mostly static configuration, which is difficult to effectively defend against complex and changeable network environment, and have defects such as large response delay, unbalanced resource utilization, and inability to adapt to risk levels in real time. Therefore, a method capable of combining deep learning technology for real-time security situation awareness and based on dynamic scheduling strategy for network security capability adaptive allocation is needed to realize efficient response to network security risks and optimization of protection capability, so as to improve the overall security, stability and resource utilization efficiency of the 5G network. SUMMARY
[0003] Therefore, it is necessary to provide a 5G network dynamic security capability scheduling method based on deep learning to solve at least one of the above technical problems.
[0004] To achieve the above-mentioned purpose, a 5G network dynamic security capability scheduling method based on deep learning comprises the following steps: Step S1: During the operation of the 5G network, continuously collect the state parameters of the network slices, and construct a security situation data sequence; Step S2: Perform feature correlation analysis on the security situation data sequence, extract security feature factors reflecting the change of the security situation, and generate a security risk judgment signal according to the security feature factors; Step S3: When the security risk judgment signal reaches a preset trigger condition, determine the scheduling priority and allocation proportion of the security protection unit according to the risk intensity and resource occupation distribution; Step S4: Issue a scheduling instruction to the corresponding network node to perform dynamic switching of security capability; after the scheduling is completed, collect the execution data fed back by each node to form a dynamic capability scheduling record.
[0005] The application has the following advantages: By continuously collecting the state parameters of the network slice during the network operation and constructing the security posture data sequence, the security judgment is no longer dependent on the static information at a single moment, but forms a dynamic sample basis that can reflect the evolution law of the security state, so that the implicit correlation between the network load, delay fluctuation, resource occupation and other parameters can be captured in the algorithm training stage, providing time sequence continuity support for subsequent risk trend judgment. In the feature correlation analysis process, the extraction mechanism of security feature factors is introduced, which avoids the traditional binary judgment mode based on alarm threshold, can autonomously identify the dominant factor affecting the change of security posture from multi-dimensional state characteristics, and generate a continuous adjustable security risk judgment signal, realizing the change of risk judgment from "event trigger" to "situation awareness". When the risk judgment signal reaches the trigger condition, the scheduling logic is not directly executed with a fixed strategy, but a joint decision is made according to the risk intensity and the spatial distribution of resource occupation, so that the scheduling priority of the security protection unit can dynamically reflect the real load pressure distribution in the network, thereby realizing the differentiated allocation of protection resources in the case of multi-region and multi-service coexistence. In the process of executing the scheduling instruction and recycling the node feedback data, the dynamic capability scheduling record forms a self-correcting feedback loop, so that the model can periodically modify its judgment logic according to the scheduling results, thereby gradually stabilizing the risk judgment accuracy in the long-term operation, and significantly reducing the problem of security response imbalance caused by model drift. BRIEF DESCRIPTION OF DRAWINGS
[0006] Fig. 1 It is a step flowchart of a deep learning-based 5G network dynamic security capability scheduling method. Fig. 2 It is a risk intensity index time sequence change curve diagram. Fig. 3 It is a network resource dynamic scheduling allocation diagram. The implementation, functional characteristics and advantages of the present application will be further described with reference to the embodiments and the accompanying drawings. DETAILED DESCRIPTION
[0007] The technical method of the present application will be described clearly and completely below in combination with the drawings. Obviously, the described embodiments are part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor belong to the scope of protection of the present application.
[0008] Furthermore, the accompanying drawings are included to provide a further understanding of the present application, and are incorporated in and constitute a part of this specification. The drawings illustrate embodiments of the present application and, together with the description, serve to explain the principles of the present application. In the drawings:
[0009] It should be understood that, although the terms "first", "second" and the like can be used herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another. For example, a first element could be termed a second element, and, similarly, a second element could be termed a first element, without departing from the scope of example embodiments. The term "and / or" as used herein includes any and all combinations of one or more of the associated listed items.
[0010] To achieve the above object, there is provided Figs. 1 to 3 A deep learning-based 5G network dynamic security capability scheduling method, comprising the following steps: Step S1: During the operation of the 5G network, continuously collect the state parameters of the network slices, and construct a security posture data sequence; Step S2: Perform feature correlation analysis on the security posture data sequence, extract security feature factors reflecting the change of the security posture, and generate a security risk judgment signal according to the security feature factors; Step S3: When the security risk judgment signal reaches a preset trigger condition, determine the scheduling priority and allocation ratio of the security protection unit according to the risk intensity and resource occupation distribution; Step S4: Issue a scheduling instruction to the corresponding network node to perform dynamic switching of security capabilities; after the scheduling is completed, collect the execution data fed back by each node to form a dynamic capability scheduling record.
[0011] In one embodiment, operational monitoring data from the network core layer, transport layer, and access layer are synchronously accessed by the status acquisition module. Key parameters such as latency, packet loss rate, bandwidth usage, encrypted traffic ratio, and control signaling load for each slice are recorded in real time at a sampling frequency of 10Hz. Each parameter is timestamped and stored in the security posture buffer, forming time-series structured data. The status acquisition module sets a data window length of 5 seconds. During window updates, integrity checks are performed on the data in the previous window, eliminating sample points with missing frames or synchronization drift. The filtered data is indexed by the slice identifier (Slice_ID) to form a continuous security posture data sequence, providing input data for subsequent feature correlation analysis.
[0012] The security situation data sequence is divided into fixed-length sliding time windows, with each window corresponding to 100 consecutive sampling points. Correlation calculations are performed on the operating parameters within each window, using the Pearson correlation coefficient to measure the degree of synchronous fluctuation between parameters. When any parameter group shows a unidirectional trend and a correlation coefficient greater than 0.85 in three consecutive windows, the correlation frequency of that parameter group is recorded. Subsequently, the correlation frequency and fluctuation amplitude are normalized to generate a stability index and an intensity index, and their weighted combination is used as a security feature factor. The feature factor is compared with a preset risk threshold range. When the feature factor exceeds the upper threshold in three consecutive windows, a security risk judgment signal is triggered, and the trigger time and corresponding slice number are recorded.
[0013] Upon receiving a risk assessment signal, the system reads the current CPU utilization, bandwidth availability, and task queuing latency of each security protection unit from the real-time monitoring database. It then performs a normalized comparison between the intensity indicators contained in the risk signal and the available resources of the protection unit, calculating a comprehensive priority value. ,in Risk intensity level, To protect the resource load rate of the unit, These are the weighting coefficients. According to... The values are arranged from high to low to determine the scheduling priority of the protection units. Then, the resource allocation ratio is linearly interpolated according to the priority distribution to form a scheduling configuration table.
[0014] Scheduling instructions are sent to each target node via the control channel. Upon receiving the instructions, each node updates its policy parameters in its local security engine. After execution, the node sends the execution status code, response latency, and resource switching result back to the central controller. The controller summarizes the feedback information, generates a dynamic capability scheduling record, and records the start and end times, affected slice range, and recovery time for each switch.
[0015] In another embodiment, the clock synchronization accuracy of the network acquisition is controlled at... Within, the monitoring object is the transmission path of the bearer layer. During collection, the number of signaling requests, the number of acknowledgment responses, the handshake delay and the retransmission ratio on each path are recorded. If the handshake delay fluctuation exceeds in three consecutive sampling periods, the path is automatically marked as a potential abnormal channel. In the generated security posture data sequence, each record contains the path number, the sampling timestamp and a five-dimensional operating parameter vector. According to statistics, about effective records are generated in one collection period.
[0016] Perform principal component analysis (PCA) on the five-dimensional operating parameters obtained by sampling, and extract the first three principal components as feature mapping bases. Calculate the variance change rate of each principal component in a continuous time period. If the variance change rate exceeds the average value by 1 times, it is marked as a high-sensitive parameter set. Further, when the coupling frequency of these high-sensitive parameters between different time windows exceeds the preset frequency threshold, it is written into the security risk log as a key trigger factor and forms a risk judgment signal queue. The queue is uniformly output through the signal buffer module, providing a reference basis for subsequent capability scheduling.
[0017] The trigger signal is divided into three risk levels. When two consecutive secondary risk signals are detected, the traffic analysis module and the access control module resources are preferentially allocated; when a tertiary risk signal is present, the intrusion prevention module and the encryption key rotation module are started, and the protection unit resource allocation ratio is increased to After completing the priority sorting and ratio setting, the corresponding scheduling instruction package is generated and waits for the execution module to issue.
[0018] After scheduling is completed, consistency verification is performed on the execution data returned by each node. If there is an inconsistency mark in the node status code, the scheduling verification is re-initiated. The records that pass the verification are written into the log database in chronological order, and a scheduling trajectory file is formed. The file shows the switching state of each protection unit in different time periods in time sequence.
[0019] Preferably, step S1 comprises: During the operation of the 5G network, the operating state parameters of the 5G network are collected, including the security operating parameters of the network slice, the abnormal connection records of the access node and the real-time load information of the transmission path; After the collection is completed, the node behavior information collected in the operating period is summarized, and an event record set related to the security posture is established; The operating state parameters and the event record set are time-aligned to construct a security posture data sequence.
[0020] In an embodiment, the method is run in a joint monitoring environment of the core network and the edge node. The collection period is set to 100 ms, and a unified clock source is used to synchronously control all sampling channels. The safe operation parameters include the control plane signaling delay of the network slice, the uplink and downlink bandwidth utilization, the packet loss ratio, and the isolation interference index between slices. The collection process completes real-time data grabbing through parallel channels and forms a multi-dimensional vector sequence indexed by a time stamp in a cache area. Abnormal connection records of the access node are generated in the capture layer, and the records include the sequential number and time interval of the connection establishment request, the handshake confirmation, and the disconnection response. When the interval between two consecutive handshakes exceeds a preset threshold of 50 ms, it is automatically marked as an abnormal event. Real-time load information of the transmission path is obtained by the bearing layer sampling module, and the sampling indicators include the path utilization and the instantaneous throughput, and the endpoint identifier of each path is recorded. After preliminary cleaning of all sampling data at the collection end, the data are transmitted to the central cache unit to form an original operation state data set.
[0021] In another embodiment, after the running period ends, the node behaviors in a complete sampling window are summarized, and the connection attempt times, the abnormal retransmission times, and the load fluctuation frequencies of the node are extracted. The summary results are encoded as event record units, arranged indexed by the event ID and the time stamp, and form an event record set related to the security situation change. Subsequently, the operation state parameters and the event record set are time-aligned, and the synchronization correction of the multi-source data is realized through the time stamp comparison. When the time difference of adjacent records is less than , the data points at the same time are defined. After the alignment, the security situation data sequence is constructed indexed by the slice number, the node identifier, and the time stamp. The sequence maintains a one-to-one correspondence between the parameters, the events, and the time, and can completely reflect the dynamic security characteristics of the entire network operation process.
[0022] Preferably, the operation state parameters of each network slice are collected as follows: A parameter collection task is preset in the slice deployment node, and the operation state information is read from the control plane and the data plane according to the set sampling period; The access authentication results and the resource scheduling records collected from the control plane are written into the security monitoring buffer in chronological order; Real-time indicators in the data plane are synchronously extracted and grouped according to the node identifier; Repeated sampling is performed on the parameters that abnormally fluctuate during the sampling process, and the repeated sampling results are updated to the corresponding parameter records; At the end of the sampling period, the operation state parameter sequence of the network slice is formed.
[0023] In an embodiment, in the initialization phase of the network slice deployment node, the parameter collection task is issued to each collection end by the task management module, and a double-channel synchronization mechanism is established between the control plane and the data plane. The sampling period is set to 200 ms, and in each period, the authentication interaction log and resource scheduling record of the control plane are read at the same time, and are written into the security monitoring buffer in real time. The writing format adopts a timestamp index structure, each record corresponds to a slice identifier and a node number, and the record content includes the authentication state, the scheduling instruction execution delay and the resource occupation rate. The buffer is updated in a first-in-first-out manner to ensure the time continuity and sequence integrity of data reading. In the data plane sampling process, the interface agent program calls the underlying monitoring instruction to extract the transmission rate, packet loss count, bandwidth utilization and port activity state and other indicators in real time. The collected indicators are automatically grouped according to the node identifier to form a data block in units of nodes, and are time-matched with the sampling results of the control plane in the same period. To avoid abnormal deviation introduced by occasional fluctuations, a repeated sampling mechanism is triggered when a parameter mutation is detected. The repeated sampling is centered on the current node and is continuously performed three times. If the average deviation of the repeated results is less than 2%, the repeated average value is used to replace the original value and write into the record table; if the deviation exceeds the threshold, the node is marked as a “high fluctuation node”.
[0024] In another embodiment, when the sampling period ends, the data of all collection nodes is summarized. The summary process takes the node identifier as the main index, connects the continuous sampling results in time sequence to form a complete running state parameter sequence. Each sequence record retains three types of fields: sampling time, parameter value and abnormality marker, which can be directly used for subsequent security situation calculation and correlation analysis. The output running state parameter sequence is stored in the database in units of slices to form a traceable time sequence sample set, providing original support data for the extraction of security feature factors.
[0025] Preferably, the abnormal connection record of the access node is specifically: A connection state monitoring program is set in the access layer gateway to read the time sequence of the connection establishment request and the handshake response of the access node; When the number of consecutive requests exceeds the set threshold or the handshake response times out without completion, the connection event is marked as an abnormal connection, and the network address of the triggering node and the connection delay are recorded; The abnormal connection events are grouped according to the nodes and written into the event log buffer in real time.
[0026] In an embodiment, the connection state monitoring module is deployed in the access layer gateway, and the module is configured to collect the connection establishment request timestamps and handshake response timestamps of the access nodes continuously with a sampling period of 1 second. For each connection establishment, the request initiation time, request source IP, target IP, handshake response completion time, and handshake status code are recorded. The abnormal condition is defined as: in any 10-second time window, the number of connection establishment requests from the same access node exceeds 50 times, or the handshake response timeout exceeds 500 milliseconds. When the abnormal condition is detected to be met, the connection event is marked as abnormal, and the abnormal event record including the access node identifier, event triggering time, abnormal type, handshake delay, and related IP information is written into the access layer event log cache, and the abnormal event identifier is synchronized to the security monitoring center. The abnormal connection events are stored in groups according to the node identifiers.
[0027] In another embodiment, the connection state analysis program is embedded in the access layer core switch, and the program reads the connection establishment records and handshake process logs from different access nodes in real time with a sampling period of 0.5 seconds. The collected data is time series arranged, and abnormality is determined according to the preset threshold rule: if the handshake response failure rate of any access node exceeds 20% in the last 5 sampling periods, or the average handshake delay exceeds 300 milliseconds, it is determined that the node has an abnormal connection event. At this time, the event record is written into the node abnormal connection database, and the record content includes event ID, node ID, abnormal occurrence time, handshake failure rate, average handshake delay, and involved source / target IP address. Further, the abnormal connection information is real-time aggregated by node, and an abnormal connection statistical report is generated every minute and updated to the security posture data center.
[0028] Preferably, the real-time load information of the transmission path is specifically: The traffic distribution state between the nodes of the path is monitored at fixed time intervals during the data transmission process, and the inbound bandwidth occupancy rate and outbound transmission rate of each node are recorded; When the bandwidth utilization difference between adjacent nodes exceeds the set threshold, it is determined that there is a risk of uneven load in the path segment, and the continuous transmission packets of the path segment are captured and counted; According to the total amount of data packets and the proportion of effective transmission packets per unit time, the real-time load coefficient is calculated, and the calculation result is synchronized to the path state table; After the path state table is updated, a load change curve is generated to determine the load fluctuation trend in different time periods; When the load coefficient remains in the high threshold interval for a plurality of consecutive sampling periods, the node identifier and time label of the corresponding path segment are recorded as real-time load information.
[0029] In an embodiment, a path load monitoring module is deployed on a 5G network core routing node, with a monitoring period of 500 ms, and continuous sampling of traffic between adjacent nodes in a path. In each sampling period, the node's inbound bandwidth occupancy, outbound bandwidth occupancy, packet transmission rate, and packet loss rate are read and recorded in timestamp order. For each transmission path, the bandwidth occupancy difference between adjacent nodes is calculated. When the bandwidth difference exceeds a set threshold (e.g., 10%), a path load risk flag is triggered, and continuous transmission packets for the path segment in the next 1 minute are captured and counted, recording the number of captured packets, average latency, and effective transmission packet ratio. The above results are written synchronously to a path state table, which includes path segment ID, node ID, bandwidth occupancy curve, and real-time load coefficient. Through historical analysis of path state table data, a load change curve is generated for each path, high load time periods are identified, and path segment nodes and time labels that persistently exceed the threshold are recorded as real-time load information.
[0030] In another embodiment, a load monitoring subsystem is embedded in the switches of the 5G network access layer and core layer, with a sampling period of 1 second, collecting real-time indicators including inbound traffic, outbound traffic, bandwidth occupancy, and network latency. For each transmission path node, the bandwidth occupancy difference is calculated for each node pair, with a threshold set at 15%. When the difference of a path segment exceeds the threshold for 3 consecutive sampling periods, it is determined that the path segment has a risk of uneven load. At this time, the transmission packets of the path segment are captured, and the total number of packets, the number of effective transmission packets, and the packet loss rate are recorded, and the real-time load coefficient is calculated. The load coefficient is stored in the path state database in time sequence and a path load curve is generated. In time periods that persistently exceed the set threshold, the node identification of the related path segment, the abnormal start and end time, and the load coefficient are automatically written into the network load log and updated to the security posture database.
[0031] Preferably, step S2 comprises: time window division is performed on the security posture data sequence to sequentially intercept sequence segments with fixed-length sliding windows; In each sequence segment, multi-dimensional feature correlation calculation is performed to calculate the fluctuation correlation between security operation parameters and identify security feature factors that affect security posture changes; According to the change trend of the security feature factors in the continuous window, the risk intensity index is calculated, and the risk intensity index is compared with the preset security threshold interval to generate a risk warning identifier; When the risk warning identifier maintains the triggered state in the continuous window, a security risk determination signal is generated, and the corresponding time period and network slice number are marked.
[0032] In an embodiment, in the 5G network dynamic security capability scheduling, the sliding time window length is set to 60 seconds, the window step is 10 seconds, and the security posture data sequence is divided into multiple time windows in chronological order. The security operation parameters (including network slice bandwidth occupancy rate, abnormal connection times, transmission path load coefficient, etc.) in each time window are sequentially normalized, and the Pearson correlation coefficient matrix between the parameters is calculated to obtain a multi-dimensional feature correlation matrix. In the matrix, parameter pairs with a correlation coefficient higher than 0.8 are selected as candidate feature factors, and the average change amplitude of these parameters in the window is further calculated. Based on the change trend of these candidate feature factors in the continuous window, the risk intensity index is calculated using the weighted average algorithm, and compared with the set threshold interval. If the risk intensity index exceeds the set threshold in the continuous three window periods, the risk warning identifier is recorded, the security risk judgment signal is generated, and the trigger time period and the corresponding network slice number are marked in the security posture log.
[0033] In another embodiment, in the 5G network security monitoring platform, the sliding window length is 120 seconds and the step is 20 seconds, and the constructed security posture data sequence is segmented for processing. For the parameter sequence in each time window, outliers are removed (such as removing sampling points with bandwidth occupancy rate mutation exceeding ±20%), then the covariance matrix between parameters is calculated based on node grouping, and principal component analysis (PCA) is performed based on the covariance matrix to extract the main feature vector as the security feature factor. In the continuous window, the change trend of the security feature factor is linearly fitted, the trend slope is calculated, and the risk intensity index is generated accordingly. The risk intensity index is compared with the preset security threshold interval step by step, if the slope continuously exceeds the preset positive threshold and the risk intensity index is continuously higher than the set interval, the risk warning identifier is triggered. The network slice number and time period at the trigger time are automatically recorded, and the information is written into the security event database.
[0034] Preferably, in each sequence segment, multi-dimensional feature correlation calculation is performed, the fluctuation correlation between each security operation parameter is calculated, and the security feature factor affecting the security posture change is identified, including: The instantaneous value of the security operation parameter is read point by point in the time window, the change rate between adjacent values is calculated, and a parameter change sequence is generated; The synchronous fluctuation relationship between different parameters in the change sequence is calculated; When any parameter group shows a synchronous fluctuation feature in the continuous sampling period, the coupling frequency and amplitude ratio of the parameter group are recorded, and the dominant parameter affecting the security posture change is determined based on the coupling frequency and amplitude ratio; The dynamic characteristics of the dominant parameter in the window are aggregated, and the security feature factor affecting the security posture change is identified.
[0035] In an embodiment, in the 5G network dynamic security capability scheduling, the time window length is set to 60 seconds, and the window step is 10 seconds. In each window period, the security running parameters of the access node are read point by point, including the incoming bandwidth occupancy rate, the outgoing transmission rate, the number of abnormal connections, etc. The change rate between adjacent sampling points is calculated for each parameter sequence to form a change sequence. In the change sequence, the synchronous fluctuation correlation coefficient between different parameter sequences is calculated by using the sliding correlation analysis method, and the parameter groups with a correlation coefficient greater than 0.7 in the continuous 10 sampling periods are counted. For each parameter group that meets the condition, the coupling frequency and the average amplitude ratio are recorded, and the parameter groups are sorted from high to low according to the frequency and the amplitude ratio, and the top 10% of the parameter groups are selected as the dominant parameters. The average value, variance and maximum change rate of these dominant parameters in the time window are aggregated as dynamic characteristics to form the security characteristic factor set of the window.
[0036] In another embodiment, in the 5G network security monitoring platform, the time window length is 120 seconds, and the step is 20 seconds. The security situation data sequence is segmented and processed. In each time window, the security running parameters of multiple network slice nodes are collected in turn, including node delay, connection establishment success rate and bandwidth occupancy rate. For each parameter sequence, abnormal sampling points exceeding ±15% change amplitude are removed, and then the change rate sequence is calculated. In the change rate sequence, the synchronous fluctuation characteristics between different parameters are counted by using the weighted sliding correlation method, and the coupling frequency and the amplitude ratio are calculated. When a parameter group maintains a coupling frequency greater than a set threshold and an amplitude ratio greater than 0.6 in the continuous 5 sampling periods, the parameter group is marked as a dominant parameter group. In the time window, the change sequence of the dominant parameter group is aggregated by mean, variance and maximum value to generate the security characteristic factor of the window, which is used for subsequent risk judgment and dynamic security scheduling module calling.
[0037] Preferably, reading the instantaneous values of the security running parameters point by point in the time window, calculating the change rate between adjacent values and generating the parameter change sequence include: At the starting time of the sliding window, the current values of each security running parameter are read in turn, and are recorded as initial sampling points in time order; After the sampling interval arrives, the next time values of the same group of parameters are repeatedly collected to form a value pair at adjacent times; Difference operation is performed on each value pair to obtain the instantaneous change amplitude of the parameter; The continuous difference results are arranged in time order to generate a change sequence; In the change rate sequence, the mutation points and stable intervals are detected, and the key periods of parameter fluctuation are marked.
[0038] In an embodiment, in the 5G network dynamic security capability scheduling, the time window length is set to 60 seconds, and the sampling interval is 5 seconds. At the starting time of the sliding window, the security operation parameters of each access node are read in turn, including node delay, incoming bandwidth occupancy rate and outgoing transmission rate, and recorded as initial sampling points. After the sampling interval arrives, the security operation parameters of the same node are read again to form new value pairs. The difference operation is performed on each value pair to obtain the instantaneous change amplitude of each parameter of the node, and the timestamp is recorded. The continuous difference results are arranged in chronological order to form a change sequence. In the change sequence, the gradient change detection method is used to identify the mutation points and stable intervals, mark the key periods with large fluctuation amplitude of the node in the time window, and write them into the network state database to support subsequent security situation analysis and capability scheduling.
[0039] In another embodiment, in the 5G network security monitoring platform, the time window length is set to 120 seconds, the sliding step is 15 seconds, and the sampling frequency is 10 seconds. At the starting time of each time window, the security operation parameters including connection establishment delay, packet loss rate, bandwidth occupancy rate, etc. are read and recorded as initial sampling points in order of nodes. After the sampling interval arrives, the parameter values of the same node are obtained again to form adjacent value pairs. The difference calculation is performed on each value pair, and the change rate sequence is generated according to the sampling time. In the change rate sequence, the threshold judgment method is used to identify the change mutation points, and the judgment standard is that the change amplitude of the continuous 3 sampling periods exceeds the set threshold (such as ±10%). The time period corresponding to the mutation point and the related node identifier are stored in the log, and the parameter change report of the time window is generated.
[0040] Preferably, when any parameter group presents the same fluctuation characteristics in the continuous sampling period, the coupling frequency and amplitude ratio of the parameter group are recorded, and based on the coupling frequency and amplitude ratio, the dominant parameters that mainly affect the security situation change are determined, including: The synchronous fluctuation between the security operation parameters is counted, and the parameter groups that appear cooperative change in the same time window are recorded; The number of cooperative changes of each parameter group in the continuous window is compared, the stable interval of the coupling frequency is calculated, and the parameter group that continuously appears in the interval is identified; For the identified parameter group, the change amplitude ratio in the same time period is extracted, and the fluctuation range of the amplitude ratio is counted; When the coupling frequency of a certain parameter group remains stable in multiple window periods, and the fluctuation range of the amplitude ratio is lower than the set threshold, the main variable corresponding to the parameter group is determined as the candidate dominant parameter; The candidate dominant parameter is verified across windows to evaluate its influence on the security situation change in the continuous time period; The candidate dominant parameters are prioritized according to the influence strength and the stability, and the dominant parameters in the current stage are determined.
[0041] In an embodiment, in the 5G network dynamic security capability scheduling platform, the time window length is set to 60 seconds, and the sliding step is 10 seconds. In each time window, the delay, packet loss rate, incoming bandwidth occupancy rate, and outgoing transmission rate of the node are read in sequence. For each time window, the synchronous fluctuation between each pair of parameters is counted, and the parameter group that appears a collaborative change in the same time period is recorded. Subsequently, the number of collaborative changes of each parameter group in the last 10 time windows is counted, the coupling frequency is calculated, and the stable interval of the coupling frequency is determined. For the parameter group identified as the frequency stable, the amplitude ratio sequence in the time window is extracted, and the amplitude ratio fluctuation range is counted. When the coupling frequency of a parameter group remains stable in 3 consecutive window periods, and the amplitude ratio fluctuation range is lower than the preset threshold (such as ±5%), the main variable corresponding to the parameter group is marked as a candidate dominant parameter. All candidate dominant parameters are sorted according to the stability, and the top-ranked parameters and their associated node information are recorded to the security feature database.
[0042] In another embodiment, in the 5G network situation awareness system, the time window length is set to 120 seconds, the sliding step is 20 seconds, and the sampling frequency is 15 seconds. At the start of each window, the platform obtains the delay, bandwidth occupancy rate, packet loss rate, error code rate, and other security running parameters of all nodes in the specified slice, and generates the parameter change sequence in time order. In each time window, the synchronous fluctuation events between parameters are counted, and the corresponding parameter group is recorded according to the time tag. Subsequently, the number of synchronous fluctuations of each parameter group in the last 8 time windows is accumulated to obtain the coupling frequency, and the stable interval is determined. For the parameter group in the stable interval, the amplitude ratio data is extracted and the mean and standard deviation of the amplitude ratio are calculated. When the amplitude ratio standard deviation is lower than the set threshold (for example, 0.08), and the coupling frequency of the parameter group exceeds the set frequency threshold (such as 50 times) in the last 5 window periods, the parameter group is determined as the dominant parameter, and a priority list of the parameter group is generated. The dominant parameter and its priority result are stored in the security situation database and synchronized to the scheduling control module for dynamic security capability allocation.
[0043] Preferably, according to the change trend of the security feature factor in the consecutive windows, the risk intensity index is calculated, and the risk intensity index is compared with the preset security threshold interval to generate the risk warning identifier, including: In the consecutive time windows, the change direction and amplitude difference of the security feature factor are tracked, and the cumulative change rate of each feature quantity between adjacent windows is calculated; According to the statistical distribution of the cumulative change rate, a risk intensity index of the overall security situation fluctuation degree is generated; The risk intensity index is compared with a preset security threshold interval in stages, the risk level is determined, and the corresponding time period is marked; When the risk intensity index continuously exceeds the high threshold interval, a risk warning mark is triggered to indicate that the security situation enters an abnormal state.
[0044] In an embodiment, in a 5G network dynamic security capability scheduling platform, the time window length is set to 60 seconds, and the sliding step is 10 seconds. At the end of each time window, the change data of the security characteristic factors identified in the window is read in turn, including delay, packet loss rate, bandwidth occupancy rate, and error code rate. For each security characteristic factor, the average change rate between adjacent two windows is calculated and accumulated to obtain the cumulative change rate sequence of the factor. The cumulative change rates of all factors are weighted and summed to obtain the security situation fluctuation degree of the overall network, forming a risk intensity index. The risk intensity index is compared with a preset multi-level security threshold interval (such as a low risk interval [0, 0.3], a medium risk interval (0.3, 0.6], and a high risk interval (0.6, 1.0]), the current security situation level is determined, and the time stamp is recorded. When the risk intensity index exceeds 0.6 (high risk threshold) for 3 consecutive time windows, a risk warning mark is automatically generated, and the corresponding time period and related network slice number are marked on the scheduling platform interface.
[0045] In another embodiment, in a 5G network situation monitoring system, the time window length is set to 120 seconds, and the sliding step is 30 seconds. The security characteristic factors (such as node delay, incoming bandwidth occupancy rate, CPU utilization rate, etc.) in each time window are read point by point to generate the change sequence of each factor in the window. The cumulative change amplitude of each security characteristic factor is calculated between adjacent time windows, and a distribution model of the change amplitude is constructed based on historical data. The cumulative change amplitudes are weighted and integrated according to the factor weights to form the risk intensity index of the window. Then, the risk intensity index is compared with a preset security threshold interval in stages (for example, low risk [0, 0.25], warning risk (0.25, 0.5], high risk (0.5, 0.75], and extremely high risk (0.75, 1.0]), the risk level is determined, and the time period is marked. If the risk intensity index is in the extremely high risk interval for 5 consecutive time windows, a risk warning mark is automatically triggered, and the triggering time and the security state snapshot of the related slice are recorded for subsequent security scheduling and analysis.
[0046] Especially important is that step S3 comprises: After the security risk determination signal is triggered, the risk intensity and network resource occupancy of the corresponding time period are read; According to different intervals of risk intensity, the security protection level is determined; The computing capacity, communication bandwidth and cache available amount of each node in the network are counted to form a resource occupation information set; The security protection level and the resource occupation information set are corresponded to generate a security protection unit set participating in scheduling; The response delay, load state and historical protection effectiveness of each protection unit are evaluated in sequence to calculate the scheduling priority order; According to the priority order and risk level of each protection unit, the resource allocation proportion is determined; After completing the proportional allocation, proportional balancing is performed on the protection units of the same level to form the scheduling priority sequence and resource allocation result.
[0047] In an embodiment, when the security risk judgment signal is triggered, the risk intensity index and network resource occupation state data of the corresponding time period are read. The risk intensity index is mapped to the pre-defined security protection level interval, for example, low risk corresponds to protection level L1, medium risk corresponds to L2, and high risk corresponds to L3. The computing capacity (such as CPU utilization, GPU utilization), communication bandwidth utilization and cache available amount of each node in the network are collected, and a resource occupation information table is formed. In the resource occupation information table, each node is associated with the corresponding security protection level to generate a security protection unit set participating in scheduling. For each protection unit in the set, the response delay, current load state and past 30-day protection effect score are evaluated in sequence, and the scheduling priority order is calculated according to the evaluation result. The available computing resources, bandwidth and cache capacity are allocated according to the priority order, and the resources are allocated to each protection unit in proportion. The allocation proportion of the protection units of the same level is balanced to form the scheduling priority sequence and resource allocation scheme, and is sent to the scheduling execution module.
[0048] In another embodiment, after triggering the security risk determination signal, the risk intensity index of the time period is scheduled to be read, and the resource occupation data of the network slice is obtained, including the CPU / GPU load of the computing node, the link bandwidth occupation rate and the storage node cache usage. According to the numerical interval of the risk intensity, it is mapped to four security protection levels (L1-L4), and it is associated with the network slice number. For each protection level, the computing capacity, communication bandwidth and cache available amount of all nodes are collected to form a detailed resource occupation information set. The protection level is corresponded to the resource occupation information, and a security protection unit set participating in the current scheduling is generated. Then the protection units in the set are comprehensively evaluated, including node response delay, current load ratio and historical protection success rate. According to the evaluation result, the scheduling priority is calculated, and the resource allocation proportion is formulated combined with the risk level. The resources are allocated to each protection unit according to the proportion, and the same level unit is balancedly allocated, and the scheduling priority sequence and resource allocation result are generated for the 5G network dynamic security capability scheduling module to execute.
[0049] Especially important is that step S4 includes: The generated scheduling instructions are issued to the corresponding network nodes according to the priority order; After each node receives the scheduling instruction, the corresponding security protection component is loaded according to the allocation proportion; After the loading is completed, the dynamic switching operation of the security capability is executed; During the switching process, the node response delay, resource occupation change and security task state are recorded in real time; When the switching operation is completed, the execution feedback data is collected from each node, and the execution completion rate and time delay distribution are counted; The collected data is time-sequenced and the dynamic capability scheduling record is generated.
[0050] In an embodiment, the generated scheduling instructions are sequentially issued to the corresponding network nodes according to the previously calculated scheduling priority sequence. During the issuing process, the scheduling record instructions are sent with the time stamp and receiving node information. After receiving the scheduling instructions, each network node parses the instruction content and loads the corresponding security protection components, such as intrusion detection modules, firewall rules, and traffic isolation strategies, according to the allocation ratio. During the loading process, the node monitors the resource occupation in real time and records the component loading time and response delay. After the security protection components are loaded, the node triggers the dynamic security capability switching operation to switch the current running state to the security mode specified in the scheduling instruction. During the switching process, the node collects the response delay, CPU / GPU occupancy, memory occupancy, and network traffic changes in real time and records the security task execution state. After the switching is completed, the node reports the execution feedback data to the scheduling center, and the scheduling center calculates the execution completion rate and response delay distribution of each node and arranges the data in chronological order to generate a complete dynamic capability scheduling record.
[0051] In another embodiment, the scheduling center sends the scheduling instructions to the corresponding network nodes through the control plane according to the priority sequence, and each instruction is attached with the node number, allocation ratio, and protection task list. After receiving the instructions, each node verifies the instruction integrity and decodes it, and then loads the required security protection components, including deep learning-based anomaly detection models, traffic scheduling modules, and access control strategies, according to the allocation ratio. The loading process is monitored and recorded in real time by the node, and after the loading is completed, the dynamic switching operation of the security capability is automatically triggered. During the switching period, each node continuously collects and records the response delay, bandwidth utilization, processor occupation, and security event log. After the switching is completed, each node sends the execution feedback data to the scheduling center, and the scheduling center aggregates the feedback information of all nodes, analyzes the execution completion rate, average response delay, and node load curve, and integrates the data into a time sequence archive to form a complete dynamic capability scheduling record.
[0052] The above description is only a specific implementation of the present application, which enables those skilled in the art to understand or implement the present application. Various modifications to these embodiments will be apparent to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application will not be limited to these embodiments shown herein, but will conform to the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A method for dynamic security capability scheduling in 5G networks based on deep learning, characterized in that, Includes the following steps: Step S1: During the operation of the 5G network, continuously collect the status parameters of the network slices and construct a security situation data sequence; Step S2: Perform feature correlation analysis on the security situation data sequence, extract security feature factors that reflect changes in the security situation, and generate security risk judgment signals based on the security feature factors; Step S3: When the security risk assessment signal reaches the preset trigger condition, determine the scheduling priority and allocation ratio of the security protection unit according to the risk intensity and resource occupancy distribution; Step S4: Send the scheduling command to the corresponding network node to perform dynamic switching of security capabilities; after the scheduling is completed, collect the execution data fed back by each node to form a dynamic capability scheduling record.
2. The 5G network dynamic security capability scheduling method based on deep learning according to claim 1, characterized in that, Step S1 includes: During the operation of the 5G network, the operating status parameters of the 5G network are collected, including the security operation parameters of network slices, abnormal connection records of access nodes, and real-time load information of transmission paths. After the data collection is completed, the node behavior information collected during the operation cycle is summarized to establish an event log set related to the security situation; The runtime status parameters are aligned with the event log set in a time sequence to construct a security posture data sequence.
3. The deep learning-based dynamic security capability scheduling method for 5G networks according to claim 2, characterized in that, The specific steps for collecting the running status parameters of each network slice are as follows: Within the slice deployment node, a parameter acquisition task is pre-set, and the running status information is read from the control plane and the data plane respectively according to the set sampling period; The access authentication results and resource scheduling records collected by the control plane are written into the security monitoring buffer in chronological order; Real-time metrics are extracted from the data plane synchronously and grouped according to node identifiers; For parameters that exhibit abnormal fluctuations during the sampling process, perform resampling and update the corresponding parameter records with the resampling results; At the end of the sampling period, a sequence of running state parameters for the network slice is formed.
4. The 5G network dynamic security capability scheduling method based on deep learning according to claim 2, characterized in that, The abnormal connection records of the access nodes are collected as follows: Configure a connection status monitoring program in the access layer gateway to read the time series of connection establishment requests and handshake responses from access nodes; When the number of consecutive requests exceeds the set threshold or the handshake response times out, the connection event is marked as an abnormal connection, and the network address of the triggering node and the connection latency are recorded. Abnormal connection events are grouped by node and written to the event log cache in real time.
5. The 5G network dynamic security capability scheduling method based on deep learning according to claim 2, characterized in that, The real-time load information of the transmission path is collected as follows: During data transmission, the traffic distribution status between path nodes is monitored at fixed time intervals, and the inbound bandwidth utilization and outbound transmission rate of each node are recorded. When the difference in bandwidth utilization between adjacent nodes exceeds a set threshold, it is determined that there is a risk of uneven load in the path segment, and the continuous transmission packets of the path segment are captured and counted. The real-time load factor is calculated based on the total number of data packets and the proportion of effective transmission packets per unit time, and the calculation results are synchronized to the path status table. After the path status table is updated, a load change curve is generated to determine the load fluctuation trend in different time periods. When the load coefficient remains in the high threshold range for multiple consecutive sampling periods, the node identifier and time tag of the corresponding path segment are recorded as real-time load information.
6. The 5G network dynamic security capability scheduling method based on deep learning according to claim 1, characterized in that, Step S2 includes: The security situation data sequence is divided into time windows, and sequence segments are extracted sequentially using a sliding window of fixed length; In each sequence segment, multidimensional feature correlation calculations are performed to statistically analyze the fluctuation correlation between various safety operation parameters and identify safety feature factors that affect changes in the safety situation. Based on the changing trend of safety characteristic factors in a continuous window, the risk intensity index is calculated, and the risk intensity index is compared with the preset safety threshold range to generate a risk warning sign. When the risk warning indicator remains in the triggered state within a continuous window, a security risk judgment signal is generated, and the corresponding time period and network slice number are marked.
7. The 5G network dynamic security capability scheduling method based on deep learning according to claim 6, characterized in that, In each sequence segment, multidimensional feature correlation calculations are performed to statistically analyze the fluctuation correlations among various safety operation parameters and identify safety characteristic factors affecting changes in the safety situation, including: The instantaneous values of safe operation parameters are read point by point within the time window, the rate of change between adjacent values is calculated, and a parameter change sequence is generated. In the changing sequence, the synchronous fluctuation relationship between different parameters is statistically analyzed; When any parameter group exhibits the same directional fluctuation characteristic within a continuous sampling period, the coupling frequency and amplitude ratio of the parameter group are recorded, and based on the coupling frequency and amplitude ratio, the dominant parameters that mainly affect the change of security situation are determined. By aggregating the dynamic features of the dominant parameters within the window, the security characteristic factors that affect changes in the security situation are identified.
8. The 5G network dynamic security capability scheduling method based on deep learning according to claim 7, characterized in that, The instantaneous values of safe operating parameters are read point by point within the time window, the rate of change between adjacent values is calculated, and a parameter change sequence is generated, including: At the start of the sliding window, the current values of each safety operation parameter are read sequentially and recorded in chronological order as the initial sampling points; After the sampling interval is reached, the values of the same set of parameters are repeatedly collected at the next time step to form a pair of values at adjacent time steps. Perform a difference operation on each pair of values to obtain the instantaneous change in the parameter; Arrange the continuous difference results in chronological order to generate a change sequence; In the rate of change sequence, abrupt change points and stable intervals are detected to mark key periods of parameter fluctuation.
9. The 5G network dynamic security capability scheduling method based on deep learning according to claim 7, characterized in that, When any parameter group exhibits unidirectional fluctuation characteristics within a continuous sampling period, the coupling frequency and amplitude ratio of that parameter group are recorded. Based on the coupling frequency and amplitude ratio, the dominant parameters that primarily affect changes in the security situation are determined, including: Statistical analysis was performed on the synchronous fluctuations among various safe operating parameters, and parameter groups that showed coordinated changes within the same time window were recorded. Compare the number of cooperative changes for each parameter group in a continuous window, calculate the stable interval of coupling frequency, and identify the parameter groups that continue to appear in this interval. For the identified parameter group, extract the ratio of its change in the same time period and calculate the fluctuation range of the ratio. When the coupling frequency of a parameter group remains stable over multiple window periods and the fluctuation range of the amplitude ratio is lower than a set threshold, the main variable corresponding to the parameter group is determined as a candidate dominant parameter. Candidate dominant parameters are validated across windows to assess their impact on changes in security posture over a continuous time period. Based on the intensity of influence and the stability of persistence, the candidate dominant parameters are prioritized to determine the dominant parameters at the current stage.
10. The 5G network dynamic security capability scheduling method based on deep learning according to claim 6, characterized in that, Based on the changing trend of safety characteristic factors within a continuous window, a risk intensity index is calculated, and the risk intensity index is compared with a preset safety threshold range to generate risk warning indicators, including: Within a continuous time window, track the difference in the direction and magnitude of change of security feature factors, and calculate the cumulative rate of change of each feature quantity between adjacent windows; Based on the statistical distribution of the cumulative rate of change, a risk intensity index is generated to reflect the overall degree of fluctuation in the security situation. The risk intensity index is compared with the preset safety threshold range step by step to determine the risk level and mark the corresponding time period. When the risk intensity index continues to exceed the high threshold range, a risk warning indicator is triggered to indicate that the security situation has entered an abnormal state.
Citation Information
Patent Citations
5G network slice instance dynamic switching method and function
CN109951440A
Power business scheduling method and system based on 5G communication grading and classification
CN119402967A
Network security index evaluation system
CN120017549A
Communication base station flow prediction management system based on deep learning
CN120390231A
Dynamic encryption and authentication data transmission optimization method
CN120455038A
Cited By
Data security risk quantitative dynamic assessment method and system
CN121644199A
Safety instrument system communication method and system based on redundant control bus
CN121864528A
Mine multi-network integration security communication scheduling method and system
CN122054146A
Mine Multi-Network Integrated Safety Communication Dispatch Method and System
CN122054146B