A deep learning-based 5G network dynamic security capability scheduling method

By collecting and analyzing status parameters in 5G networks, constructing security situation data sequences, generating risk assessment signals, and dynamically scheduling resources, the response delay and uneven resource utilization problems of existing 5G network security protection methods are solved. Real-time security situation awareness and optimized resource allocation are achieved, thereby improving network security and stability.

CN121078436BActive Publication Date: 2026-04-14SHENZHEN ZHIBOTONG ELECTRONICS CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-11-06
Publication Date
2026-04-14

AI Technical Summary

Technical Problem

Existing 5G network security protection methods are mostly statically configured, which are difficult to adapt to complex and ever-changing network environments, resulting in large response delays, uneven resource utilization, and an inability to adapt to risk levels in real time. There is an urgent need for a network security capability adaptive allocation method that can combine deep learning technology for real-time security situation awareness and is based on dynamic scheduling strategies.

Method used

By continuously collecting network slice status parameters in the 5G network, a security situation data sequence is constructed, feature correlation analysis is performed, security feature factors are extracted to generate security risk judgment signals, the scheduling priority and allocation ratio of security protection units are determined based on risk intensity and resource occupancy distribution, and dynamic switching is performed to form a dynamic capability scheduling record.

Benefits of technology

It realizes the transformation from event-triggered to situational awareness, dynamically reflects the distribution of network load pressure, realizes differentiated allocation of protection resources, reduces the security response imbalance caused by model drift, and improves the security and resource utilization efficiency of 5G networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121078436B_ABST
    Figure CN121078436B_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of network capability scheduling, and particularly relates to a 5G network dynamic security capability scheduling method based on deep learning. The method comprises the following steps: continuously collecting state parameters of network slices during the operation of the 5G network, and constructing a security posture data sequence; performing feature correlation analysis on the security posture data sequence, extracting security feature factors reflecting changes in the security posture, and generating a security risk judgment signal according to the security feature factors; when the security risk judgment signal reaches a preset trigger condition, determining the scheduling priority and allocation proportion of the security protection unit according to the risk intensity and resource occupation distribution; the present application realizes adaptive scheduling of security capability based on dynamic situation awareness through 5G network dynamic security capability scheduling, significantly improving the risk judgment accuracy and resource allocation coordination.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network capability scheduling technology, and in particular to a method for dynamic security capability scheduling of 5G networks based on deep learning. Background Technology

[0002] The wide-area coverage, complex topology, and diverse service scenarios of 5G networks bring more complex security challenges. Network attack methods are diversified, including distributed denial-of-service (DDoS) attacks, intrusion penetration, and malicious traffic injection, posing serious threats to network stability and security. 5G networks employ new technologies such as network slicing and edge computing, requiring security protection strategies to be dynamically adjustable to adapt to real-time changes in network status and security posture. Existing network security protection methods are mostly statically configured, making it difficult to effectively defend against complex and ever-changing network environments. They suffer from drawbacks such as large response delays, uneven resource utilization, and inability to adapt to risk levels in real time. There is an urgent need for a method that can combine deep learning technology for real-time security situation awareness and adaptively allocate network security capabilities based on dynamic scheduling strategies. This would enable efficient response to network security risks and optimized protection capabilities, thereby improving the overall security, stability, and resource utilization efficiency of 5G networks. Summary of the Invention

[0003] Therefore, it is necessary to provide a deep learning-based method for dynamic security capability scheduling in 5G networks to solve at least one of the aforementioned technical problems.

[0004] To achieve the above objectives, a deep learning-based dynamic security capability scheduling method for 5G networks includes the following steps:

[0005] Step S1: During the operation of the 5G network, continuously collect the status parameters of the network slices and construct a security situation data sequence;

[0006] Step S2: Perform feature correlation analysis on the security situation data sequence, extract security feature factors that reflect changes in the security situation, and generate security risk judgment signals based on the security feature factors;

[0007] Step S3: When the security risk assessment signal reaches the preset trigger condition, determine the scheduling priority and allocation ratio of the security protection unit according to the risk intensity and resource occupancy distribution;

[0008] Step S4: Send the scheduling command to the corresponding network node to perform dynamic switching of security capabilities; after the scheduling is completed, collect the execution data fed back by each node to form a dynamic capability scheduling record.

[0009] The beneficial effects of this invention are as follows:

[0010] By continuously collecting network slice status parameters and constructing security posture data sequences during network operation, security judgment no longer relies on static information at a single moment, but forms a dynamic sample basis that reflects the evolution of security status. This allows the algorithm to capture the implicit correlations between parameters such as network load, latency fluctuations, and resource consumption during the training phase, providing temporal continuity support for subsequent risk trend judgment. A security feature factor extraction mechanism is introduced during feature correlation analysis, avoiding the traditional binary judgment method based on alarm thresholds. It can autonomously identify the dominant factors affecting changes in security posture from multi-dimensional status features, generating continuously adjustable security risk judgment signals, thus realizing the transformation of risk judgment from "event-triggered" to "situational awareness." When the risk judgment signal reaches the trigger condition, the scheduling logic does not directly execute a fixed strategy, but makes a joint decision based on the spatial distribution of risk intensity and resource consumption. This allows the scheduling priority of security protection units to dynamically reflect the actual load pressure distribution in the network, thereby achieving differentiated allocation of protection resources in the context of multiple regions and multiple services coexisting. During the execution of scheduling instructions and the collection of node feedback data, the dynamic capability scheduling record forms a self-correcting feedback loop, enabling the model to periodically correct its own judgment logic based on the scheduling results. This gradually stabilizes the accuracy of risk judgment in long-term operation and significantly reduces the safety response imbalance caused by model drift. Attached Figure Description

[0011] Figure 1 This is a flowchart illustrating the steps of a deep learning-based dynamic security capability scheduling method for 5G networks.

[0012] Figure 2 This is a schematic diagram of the time-series variation curve of the risk intensity index;

[0013] Figure 3 A diagram illustrating the dynamic scheduling and allocation of network resources;

[0014] The realization of the objective, functional features and advantages of the present invention will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation

[0015] The technical method of the present invention will now be clearly and completely described with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without inventive effort are within the scope of protection of the present invention.

[0016] Furthermore, the accompanying drawings are merely illustrative of the invention and are not necessarily drawn to scale. The same reference numerals in the drawings denote the same or similar parts, and therefore repeated descriptions of them will be omitted. Some block diagrams shown in the drawings are functional entities and do not necessarily correspond to physically or logically independent entities. These functional entities can be implemented in software, in one or more hardware modules or integrated circuits, or in different network and / or processor methods and / or microcontroller methods.

[0017] It should be understood that although the terms "first," "second," etc., may be used herein to describe various units, these units should not be limited by these terms. These terms are used merely to distinguish one unit from another. For example, without departing from the scope of the exemplary embodiments, a first unit may be referred to as a second unit, and similarly, a second unit may be referred to as a first unit. The term "and / or" as used herein includes any and all combinations of one or more of the associated listed items.

[0018] To achieve the above objectives, please refer to Figures 1 to 3 A deep learning-based method for dynamic security capability scheduling in 5G networks includes the following steps:

[0019] Step S1: During the operation of the 5G network, continuously collect the status parameters of the network slices and construct a security situation data sequence;

[0020] Step S2: Perform feature correlation analysis on the security situation data sequence, extract security feature factors that reflect changes in the security situation, and generate security risk judgment signals based on the security feature factors;

[0021] Step S3: When the security risk assessment signal reaches the preset trigger condition, determine the scheduling priority and allocation ratio of the security protection unit according to the risk intensity and resource occupancy distribution;

[0022] Step S4: Send the scheduling command to the corresponding network node to perform dynamic switching of security capabilities; after the scheduling is completed, collect the execution data fed back by each node to form a dynamic capability scheduling record.

[0023] In one embodiment, operational monitoring data from the network core layer, transport layer, and access layer are synchronously accessed by the status acquisition module. Key parameters such as latency, packet loss rate, bandwidth usage, encrypted traffic ratio, and control signaling load for each slice are recorded in real time at a sampling frequency of 10Hz. Each parameter is timestamped and stored in the security posture buffer, forming time-series structured data. The status acquisition module sets a data window length of 5 seconds. During window updates, integrity checks are performed on the data in the previous window, eliminating sample points with missing frames or synchronization drift. The filtered data is indexed by the slice identifier (Slice_ID) to form a continuous security posture data sequence, providing input data for subsequent feature correlation analysis.

[0024] The security situation data sequence is divided into fixed-length sliding time windows, with each window corresponding to 100 consecutive sampling points. Correlation calculations are performed on the operating parameters within each window, using the Pearson correlation coefficient to measure the degree of synchronous fluctuation between parameters. When any parameter group shows a unidirectional trend and a correlation coefficient greater than 0.85 in three consecutive windows, the correlation frequency of that parameter group is recorded. Subsequently, the correlation frequency and fluctuation amplitude are normalized to generate a stability index and an intensity index, and their weighted combination is used as a security feature factor. The feature factor is compared with a preset risk threshold range. When the feature factor exceeds the upper threshold in three consecutive windows, a security risk judgment signal is triggered, and the trigger time and corresponding slice number are recorded.

[0025] Upon receiving a risk assessment signal, the system reads the current CPU utilization, bandwidth availability, and task queuing latency of each security protection unit from the real-time monitoring database. It then performs a normalized comparison between the intensity indicators contained in the risk signal and the available resources of the protection unit, calculating a comprehensive priority value. ,in Risk intensity level, To protect the resource load rate of the unit, These are the weighting coefficients. According to... The values ​​are arranged from high to low to determine the scheduling priority of the protection units. Then, the resource allocation ratio is linearly interpolated according to the priority distribution to form a scheduling configuration table.

[0026] Scheduling instructions are sent to each target node via the control channel. Upon receiving the instructions, each node updates its policy parameters in its local security engine. After execution, the node sends the execution status code, response latency, and resource switching result back to the central controller. The controller summarizes the feedback information, generates a dynamic capability scheduling record, and records the start and end times, affected slice range, and recovery time for each switch.

[0027] In another embodiment, the clock synchronization accuracy of the network acquisition is controlled at... Within this range, the monitoring target is the transmission path of the bearer layer. During data collection, the number of signaling requests, acknowledgment responses, handshake latency, and retransmission ratio on each path are recorded. If the handshake latency fluctuation exceeds [a certain value] in three consecutive sampling periods, [further action will be taken]. The path is automatically marked as a potential anomaly channel. Each record in the generated security situation data sequence contains a path number, sampling timestamp, and a five-dimensional operational parameter vector. Statistically, approximately [number missing] records are generated per data collection cycle. One valid record.

[0028] Principal component analysis (PCA) is performed on the sampled five-dimensional operating parameters to extract the first three principal components as feature mapping bases. The variance change rate of each principal component over a continuous time period is calculated. If the variance change rate exceeds 1 times the average value, it is marked as a set of highly sensitive parameters. The coupling frequency of these highly sensitive parameters across different time windows is further counted. When the coupling frequency exceeds a preset frequency threshold, it is written as a key triggering factor into the security risk log, forming a risk assessment signal queue. This queue is output uniformly through the signal caching module, providing a reference for subsequent capacity scheduling.

[0029] Trigger signals are categorized into three risk levels. When consecutive level-two risk signals are detected, resources are prioritized for the traffic analysis and access control modules. When a level-three risk signal appears, the intrusion prevention and encryption key rotation modules are activated, and the resource allocation ratio for the protection units is increased. After completing the priority sorting and ratio setting, the corresponding scheduling instruction package is generated and awaits issuance by the execution module.

[0030] After scheduling is completed, consistency verification is performed on the execution data returned by each node. If an inconsistency flag is found in the node status code, scheduling verification is re-initiated. Records that pass verification are written to the log database in chronological order, forming a scheduling trajectory file. This file displays the switching status of each protection unit at different time periods in a time-series format.

[0031] Preferably, step S1 includes:

[0032] During the operation of the 5G network, the operating status parameters of the 5G network are collected, including the security operation parameters of network slices, abnormal connection records of access nodes, and real-time load information of transmission paths.

[0033] After the data collection is completed, the node behavior information collected during the operation cycle is summarized to establish an event log set related to the security situation;

[0034] The runtime status parameters are aligned with the event log set in a time sequence to construct a security posture data sequence.

[0035] In one embodiment, it operates in a joint monitoring environment of the core network and edge nodes. The acquisition cycle is set to 100ms, with a unified clock source for synchronous control of all sampling channels. Safe operation parameters include control plane signaling latency of network slices, uplink and downlink bandwidth utilization, packet loss ratio, and inter-slice isolation interference index. The acquisition process uses parallel channels to capture real-time data and forms a multi-dimensional vector sequence indexed by timestamps in the buffer. Abnormal connection records of access nodes are generated in the capture layer, containing the sequence number and time interval of connection establishment requests, handshake confirmations, and disconnection responses. When the interval between two consecutive handshakes exceeds a preset threshold of 50ms, it is automatically marked as an abnormal event. Real-time load information of the transmission path is obtained by the bearer layer sampling module, with sampling indicators including path utilization and instantaneous throughput, and the endpoint identifier of each path is recorded. All sampled data is initially cleaned at the acquisition end and then transmitted to the central buffer unit to form the original operating status dataset.

[0036] In another embodiment, after the runtime cycle ends, the node behavior within a complete sampling window is summarized, extracting the number of connection attempts, abnormal retransmissions, and load fluctuation frequency. The summarized results are encoded into event recording units, arranged indexed by event ID and timestamp, forming an event record set related to changes in security posture. Subsequently, the runtime parameters and event record set are time-series aligned, and synchronization correction of multi-source data is achieved through timestamp comparison. When the time difference between adjacent records is less than... Time is defined as a data point at the same moment. After alignment, a security posture data sequence is constructed using the slice number, node identifier, and timestamp as triple indices. This sequence maintains a one-to-one correspondence between parameters, events, and time in its structure, and can fully reflect the dynamic security characteristics of the entire network operation process.

[0037] Preferably, the specific steps for collecting the running status parameters of each network slice are as follows:

[0038] Within the slice deployment node, a parameter acquisition task is pre-set, and the running status information is read from the control plane and the data plane respectively according to the set sampling period;

[0039] The access authentication results and resource scheduling records collected by the control plane are written into the security monitoring buffer in chronological order;

[0040] Real-time metrics are extracted from the data plane synchronously and grouped according to node identifiers;

[0041] For parameters that exhibit abnormal fluctuations during the sampling process, perform resampling and update the corresponding parameter records with the resampling results;

[0042] At the end of the sampling period, a sequence of running state parameters for the network slice is formed.

[0043] In one embodiment, during the initialization phase of the network slice deployment nodes, a parameter collection task is issued to each collection terminal through the task management module, and a dual-channel synchronization mechanism is established between the control plane and the data plane. The sampling period is set to 200ms. Within each period, the authentication interaction log and resource scheduling record of the control plane are read simultaneously and written to the security monitoring buffer in real time. The writing format adopts a timestamp index structure, with each record corresponding to a slice identifier and node number. The record content includes authentication status, scheduling instruction execution latency, and resource utilization. The buffer is updated in a first-in-first-out manner to ensure the temporal continuity and sequence integrity of data reading. During the data plane sampling process, the underlying monitoring instructions are called through the interface proxy program to extract indicators such as transmission rate, packet loss count, bandwidth utilization, and port activity status in real time. The collected indicators are automatically grouped according to the node identifier, forming data blocks by node, and time-matched with the sampling results of the control plane within the same period. To avoid abnormal deviations introduced by occasional fluctuations, a resampling mechanism is triggered when a parameter mutation is detected. Repeated sampling is performed three times consecutively with the current node as the center. If the average deviation of the repeated results is less than 2%, the original value is replaced by the average of the repeated results and written into the record table; if the deviation exceeds the threshold, the node is marked as a "high fluctuation node".

[0044] In another embodiment, after the sampling period ends, the data from all collected nodes are summarized. The summarization process uses node identifiers as the primary index, connecting consecutive sampling results in chronological order to form a complete sequence of operational status parameters. Each sequence record retains three types of fields: sampling time, parameter value, and anomaly marker, which can be directly used for subsequent security posture calculations and correlation analysis. The output operational status parameter sequence is stored in the database in slices, forming a traceable time-series sample set, providing raw supporting data for the extraction of security feature factors.

[0045] Preferably, the abnormal connection records of the access node are collected as follows:

[0046] Configure a connection status monitoring program in the access layer gateway to read the time series of connection establishment requests and handshake responses from access nodes;

[0047] When the number of consecutive requests exceeds the set threshold or the handshake response times out, the connection event is marked as an abnormal connection, and the network address of the triggering node and the connection latency are recorded.

[0048] Abnormal connection events are grouped by node and written to the event log cache in real time.

[0049] In one embodiment, a connection status monitoring module is deployed on the access layer gateway, configured to continuously collect connection establishment request timestamps and handshake response timestamps from access nodes with a sampling period of 1 second. For each connection establishment, the request initiation time, source IP, destination IP, handshake response completion time, and handshake status code are recorded. An abnormal condition is defined as: within any 10-second time window, the number of connection establishment requests from the same access node exceeds 50, or the handshake response timeout exceeds 500 milliseconds. When an abnormal condition is detected, the connection event is marked as abnormal, and the abnormal event record, including the access node identifier, event trigger time, abnormal type, handshake delay, and related IP information, is written to the access layer event log cache. Simultaneously, the abnormal event identifier is synchronized to the security monitoring center. Abnormal connection events are stored in groups according to node identifiers.

[0050] In another embodiment, a connection status analysis program is embedded in the access layer core switch. The program reads connection establishment records and handshake process logs from different access nodes in real time, with a sampling period of 0.5 seconds. The collected data is processed as a time series and anomaly detection is performed based on preset threshold rules: if any access node experiences a handshake response failure rate exceeding 20% ​​or an average handshake latency exceeding 300 milliseconds within five consecutive sampling periods, an abnormal connection event is determined to have occurred at that node. At this time, the event record is written to the node abnormal connection database, including the event ID, node ID, anomaly occurrence time, handshake failure rate, average handshake latency, and the source / destination IP addresses involved. Furthermore, the abnormal connection information is aggregated in real time by node, generating an abnormal connection statistics report every minute and updating it to the security posture data center.

[0051] Preferably, the real-time load information of the transmission path is collected as follows:

[0052] During data transmission, the traffic distribution status between path nodes is monitored at fixed time intervals, and the inbound bandwidth utilization and outbound transmission rate of each node are recorded.

[0053] When the difference in bandwidth utilization between adjacent nodes exceeds a set threshold, it is determined that there is a risk of uneven load in the path segment, and the continuous transmission packets of the path segment are captured and counted.

[0054] The real-time load factor is calculated based on the total number of data packets and the proportion of effective transmission packets per unit time, and the calculation results are synchronized to the path status table.

[0055] After the path status table is updated, a load change curve is generated to determine the load fluctuation trend in different time periods.

[0056] When the load coefficient remains in the high threshold range for multiple consecutive sampling periods, the node identifier and time tag of the corresponding path segment are recorded as real-time load information.

[0057] In one embodiment, a path load monitoring module is deployed on the core routing node of the 5G network, with a monitoring period of 500ms, to continuously sample the traffic between adjacent nodes in the path. Within each sampling period, the inbound bandwidth utilization, outbound bandwidth utilization, data packet transmission rate, and packet loss rate of each node are read and recorded in timestamp order. For each transmission path, the bandwidth utilization difference between adjacent nodes is calculated. When the bandwidth difference exceeds a set threshold (e.g., 10%), a path load risk marker is triggered, and continuous transmission packets for that path segment are captured and statistically analyzed within the following minute, recording the number of captured data packets, average latency, and the proportion of effective transmission packets. These results are synchronously written to a path status table, which includes path segment ID, node ID, bandwidth utilization curve, and real-time load coefficient. Through historical analysis of the path status table data, a load change curve for each path is generated, high-load time periods are identified, and the node identifiers and timestamps of path segments that consistently exceed the threshold are recorded as real-time load information.

[0058] In another embodiment, a load monitoring subsystem is embedded in the switches of the 5G network access layer and core layer. It collects real-time indicators including inbound traffic, outbound traffic, bandwidth utilization, and network latency, with a sampling period of 1 second. For each transmission path node, the bandwidth utilization difference is calculated for each node pair, with a threshold of 15%. When the difference for a certain path segment exceeds the threshold for three consecutive sampling periods, it is determined that the path segment has a risk of uneven load distribution. At this time, the transmission packets of that path segment are captured, recording the total number of packets, the number of valid transmission packets, and the packet loss rate, and a real-time load coefficient is calculated. The load coefficient is stored in the path status database in a time series, and a path load curve is generated. During periods when the load consistently exceeds the set threshold, the node identifiers, abnormal start and end times, and load coefficients of the relevant path segments are automatically written to the network load log and updated to the security posture database.

[0059] Preferably, step S2 includes:

[0060] The security situation data sequence is divided into time windows, and sequence segments are extracted sequentially using a sliding window of fixed length;

[0061] In each sequence segment, multidimensional feature correlation calculations are performed to statistically analyze the fluctuation correlation between various safety operation parameters and identify safety feature factors that affect changes in the safety situation.

[0062] Based on the changing trend of safety characteristic factors in a continuous window, the risk intensity index is calculated, and the risk intensity index is compared with the preset safety threshold range to generate a risk warning sign.

[0063] When the risk warning indicator remains in the triggered state within a continuous window, a security risk judgment signal is generated, and the corresponding time period and network slice number are marked.

[0064] In one embodiment, in the dynamic security capability scheduling of a 5G network, a sliding time window length of 60 seconds and a window step size of 10 seconds are set, and the security situation data sequence is divided into multiple time windows in chronological order. The security operation parameters (including network slice bandwidth utilization, abnormal connection count, transmission path load coefficient, etc.) within each time window are sequentially normalized, and the Pearson correlation coefficient matrix between the parameters is calculated to obtain a multidimensional feature correlation matrix. In this matrix, parameter pairs with correlation coefficients higher than 0.8 are selected as candidate feature factors, and the average change magnitude of these parameters within the window is further calculated. Based on the changing trends of these candidate feature factors within consecutive windows, a weighted average algorithm is used to calculate the risk intensity index, which is then compared with a set threshold range. If the risk intensity index exceeds the set threshold for three consecutive window periods, a risk warning indicator is recorded, a security risk judgment signal is generated, and the trigger time period and corresponding network slice number are marked in the security situation log.

[0065] In another embodiment, the 5G network security monitoring platform uses a sliding window of 120 seconds with a step size of 20 seconds to segment the constructed security situation data sequence. For the parameter sequence within each time window, outliers are removed (e.g., sampling points with bandwidth occupancy fluctuations exceeding ±20%). Then, the covariance matrix between parameters is calculated by grouping by node, and principal component analysis (PCA) is performed based on the covariance matrix to extract the main eigenvectors as security feature factors. Within a continuous window, the changing trend of the security feature factors is linearly fitted, the trend slope is calculated, and a risk intensity index is generated accordingly. The risk intensity index is compared step-by-step with a preset security threshold range. If the slope continuously exceeds the preset positive threshold and the risk intensity index remains above the set range, a risk warning is triggered. The network slice number and time period at the trigger time are automatically recorded and written to the security event database.

[0066] Preferably, in each sequence segment, multidimensional feature correlation calculation is performed to statistically analyze the fluctuation correlation between various safety operation parameters and identify safety characteristic factors affecting changes in the safety situation, including:

[0067] The instantaneous values ​​of safe operation parameters are read point by point within the time window, the rate of change between adjacent values ​​is calculated, and a parameter change sequence is generated.

[0068] In the changing sequence, the synchronous fluctuation relationship between different parameters is statistically analyzed;

[0069] When any parameter group exhibits the same directional fluctuation characteristic within a continuous sampling period, the coupling frequency and amplitude ratio of the parameter group are recorded, and based on the coupling frequency and amplitude ratio, the dominant parameters that mainly affect the change of security situation are determined.

[0070] By aggregating the dynamic features of the dominant parameters within the window, the security characteristic factors that affect changes in the security situation are identified.

[0071] In one embodiment, in the dynamic security capability scheduling of the 5G network, a time window length of 60 seconds and a window step size of 10 seconds are set. Within each window period, the security operation parameters of the access nodes are read point by point, including inbound bandwidth utilization, outbound transmission rate, and number of abnormal connections. The rate of change between adjacent sampling points is calculated for each parameter sequence to form a change sequence. In the change sequence, a sliding correlation analysis method is used to calculate the correlation coefficient of synchronous fluctuations between different parameter sequences, and parameter groups with a correlation coefficient greater than 0.7 in 10 consecutive sampling periods are identified. For each parameter group that meets the criteria, its coupling frequency and average amplitude ratio are recorded, and the parameters are sorted from high to low according to frequency and amplitude ratio, selecting the top 10% of parameter groups as dominant parameters. The average value, variance, and maximum rate of change of these dominant parameters within the time window are aggregated as dynamic features to form the security feature factor set for that window.

[0072] In another embodiment, the 5G network security monitoring platform uses a 120-second time window with a 20-second step to segment the security situation data sequence. Within each time window, security operation parameters of multiple network slice nodes are collected sequentially, including node latency, connection establishment success rate, and bandwidth utilization. For each parameter sequence, abnormal sampling points exceeding ±15% variation are removed, and then the rate of change sequence is calculated. In the rate of change sequence, the weighted moving correlation method is used to statistically analyze the synchronous fluctuation characteristics between different parameters, and the coupling frequency and amplitude ratio are calculated. When a parameter group maintains a coupling frequency greater than a set threshold and an amplitude ratio greater than 0.6 for five consecutive sampling periods, the parameter group is marked as the dominant parameter group. Within this time window, the mean, variance, and maximum value of the variation sequence of the dominant parameter group are aggregated to generate the security feature factor for this window, which is used for subsequent risk assessment and dynamic security scheduling module calls.

[0073] Preferably, reading the instantaneous values ​​of the safety operation parameters point by point within the time window, calculating the rate of change between adjacent values, and generating a parameter change sequence includes:

[0074] At the start of the sliding window, the current values ​​of each safety operation parameter are read sequentially and recorded in chronological order as the initial sampling points;

[0075] After the sampling interval is reached, the values ​​of the same set of parameters are repeatedly collected at the next time step to form a pair of values ​​at adjacent time steps.

[0076] Perform a difference operation on each pair of values ​​to obtain the instantaneous change in the parameter;

[0077] Arrange the continuous difference results in chronological order to generate a change sequence;

[0078] In the rate of change sequence, abrupt change points and stable intervals are detected to mark key periods of parameter fluctuation.

[0079] In one embodiment, in the dynamic security capability scheduling of the 5G network, the time window length is set to 60 seconds and the sampling interval is 5 seconds. At the start of the sliding window, the security operation parameters of each access node are read sequentially, including node latency, inbound bandwidth utilization, and outbound transmission rate, and recorded as the initial sampling point. After the sampling interval is reached, the security operation parameters of the same node are read again to form new value pairs. Differential operation is performed on each value pair to obtain the instantaneous change amplitude of each node parameter, and the timestamp is recorded. The continuous differential results are arranged in chronological order to form a change sequence. In the change sequence, the gradient change detection method is used to identify abrupt change points and stable intervals, marking the key periods when the node fluctuates significantly within the time window, and writing them into the network state database to support subsequent security situation analysis and capability scheduling.

[0080] In another embodiment, in the 5G network security monitoring platform, the time window length is set to 120 seconds, the sliding step is 15 seconds, and the sampling frequency is 10 seconds. At the beginning of each time window, security operation parameters, including connection establishment delay, packet loss rate, and bandwidth utilization, are read and recorded as initial sampling points in node order. After the sampling interval is reached, the parameter values ​​of the same node are acquired again to form adjacent value pairs. Differential calculation is performed on each pair of values, and a change rate sequence is generated according to the sampling time. In the change rate sequence, a threshold judgment method is used to identify abrupt change points. The judgment criterion is that the change amplitude exceeds a set threshold (e.g., ±10%) for three consecutive sampling periods. The time period corresponding to the abrupt change point and the relevant node identifier are stored in the log, and a parameter change report for that time window is generated.

[0081] Preferably, when any parameter group exhibits unidirectional fluctuation characteristics within a continuous sampling period, the coupling frequency and amplitude ratio of that parameter group are recorded, and based on the coupling frequency and amplitude ratio, the dominant parameters that mainly affect changes in the security situation are determined, including:

[0082] Statistical analysis was performed on the synchronous fluctuations among various safe operating parameters, and parameter groups that showed coordinated changes within the same time window were recorded.

[0083] Compare the number of cooperative changes for each parameter group in a continuous window, calculate the stable interval of coupling frequency, and identify the parameter groups that continue to appear in this interval.

[0084] For the identified parameter group, extract the ratio of its change in the same time period and calculate the fluctuation range of the ratio.

[0085] When the coupling frequency of a parameter group remains stable over multiple window periods and the fluctuation range of the amplitude ratio is lower than a set threshold, the main variable corresponding to the parameter group is determined as a candidate dominant parameter.

[0086] Candidate dominant parameters are validated across windows to assess their impact on changes in security posture over a continuous time period.

[0087] Based on the intensity of influence and the stability of persistence, the candidate dominant parameters are prioritized to determine the dominant parameters at the current stage.

[0088] In one embodiment, in the 5G network dynamic security capability scheduling platform, a time window length of 60 seconds and a sliding step of 10 seconds are set. Within each time window, security operation parameters such as node latency, packet loss rate, inbound bandwidth utilization, and outbound transmission rate are read sequentially. For each time window, the synchronization fluctuation between each pair of parameters is statistically analyzed, and parameter groups that exhibit coordinated changes within the same time period are recorded. Subsequently, the number of coordinated changes of each parameter group in 10 consecutive time windows is statistically analyzed to calculate the coupling frequency and define the stable interval of the coupling frequency. For parameter groups identified as having stable frequencies, their amplitude ratio sequence within that time window is extracted, and the amplitude ratio fluctuation range is statistically analyzed. When the coupling frequency of a parameter group remains stable within 3 consecutive window periods, and the amplitude ratio fluctuation range is lower than a preset threshold (e.g., ±5%), the main variable corresponding to that parameter group is marked as a candidate dominant parameter. All candidate dominant parameters are sorted according to their continuous stability, and the top-ranked parameters and their associated node information are recorded in the security feature database.

[0089] In another embodiment, in the 5G network situational awareness system, the time window length is set to 120 seconds, the sliding step is 20 seconds, and the sampling frequency is 15 seconds. At the beginning of each window, the platform acquires security operation parameters such as latency, bandwidth utilization, packet loss rate, and error code rate of all nodes in the specified slice, and generates a parameter change sequence in chronological order. Within each time window, the synchronization fluctuation events between each parameter are counted, and the corresponding parameter groups are recorded according to time labels. Subsequently, the number of synchronization fluctuations of each parameter group in eight consecutive time windows is accumulated to obtain the coupling frequency, and its stable interval is determined. For parameter groups within the stable interval, the amplitude ratio data is extracted, and the mean and standard deviation of the amplitude ratio are calculated. When the standard deviation of the amplitude ratio is lower than a set threshold (e.g., 0.08), and the coupling frequency of the parameter group exceeds the set frequency threshold (e.g., 50 times) in five consecutive window periods, the parameter group is determined to be the dominant parameter, and a priority list for the parameter group is generated. The dominant parameters and their priority results are stored in the security situation database and synchronized to the scheduling control module for dynamic security capability allocation.

[0090] Preferably, based on the changing trend of safety characteristic factors within a continuous window, a risk intensity index is calculated, and the risk intensity index is compared with a preset safety threshold range to generate a risk warning indicator, including:

[0091] Within a continuous time window, track the difference in the direction and magnitude of change of security feature factors, and calculate the cumulative rate of change of each feature quantity between adjacent windows;

[0092] Based on the statistical distribution of the cumulative rate of change, a risk intensity index is generated to reflect the overall degree of fluctuation in the security situation.

[0093] The risk intensity index is compared with the preset safety threshold range step by step to determine the risk level and mark the corresponding time period.

[0094] When the risk intensity index continues to exceed the high threshold range, a risk warning indicator is triggered to indicate that the security situation has entered an abnormal state.

[0095] In one embodiment, in the 5G network dynamic security capability scheduling platform, the time window length is set to 60 seconds, and the sliding step is 10 seconds. At the end of each time window, the change data of the identified security feature factors within that window are read sequentially, including latency, packet loss rate, bandwidth utilization, and error code rate. For each security feature factor, the average rate of change between two adjacent windows is calculated and accumulated to obtain the cumulative rate of change sequence of that factor. The cumulative rate of change of all factors is weighted and summed to obtain the overall network security situation fluctuation level, forming a risk intensity index. This risk intensity index is compared with a pre-set multi-level security threshold interval (such as low-risk interval [0, 0.3], medium-risk interval (0.3, 0.6], and high-risk interval (0.6, 1.0]) to determine the current security situation level and record the timestamp. When the risk intensity index exceeds 0.6 (high-risk threshold) for three consecutive time windows, a risk warning label is automatically generated, and the corresponding time period and related network slice number are marked on the scheduling platform interface.

[0096] In another embodiment, in the 5G network situation monitoring system, the time window length is set to 120 seconds, and the sliding step is 30 seconds. Security characteristic factors (such as node latency, inbound bandwidth utilization, CPU utilization, etc.) within each time window are read point by point, generating a change sequence for each factor within that window. Between adjacent time windows, the cumulative change amplitude of each security characteristic factor is calculated, and a distribution model of the change amplitude is constructed based on historical data. The cumulative change amplitude is weighted and integrated according to factor weights to form the risk intensity index for that window. Subsequently, the risk intensity index is compared with a preset security threshold range (e.g., low risk [0, 0.25], warning risk (0.25, 0.5], high risk (0.5, 0.75], extremely high risk (0.75, 1.0]) to determine the risk level and mark the time period. If the risk intensity index is in the extremely high risk range for five consecutive time windows, a risk warning is automatically triggered, and the trigger time and a snapshot of the security status of the relevant slice are recorded for subsequent security scheduling and analysis.

[0097] Of particular importance, step S3 includes:

[0098] After the security risk assessment signal is triggered, the risk intensity and network resource usage for the corresponding time period are read.

[0099] Safety protection levels are determined based on different risk intensity ranges;

[0100] The computing power, communication bandwidth, and available cache of each node in the network are statistically analyzed to form a resource usage information set;

[0101] By mapping security protection levels to resource occupancy information sets, a set of security protection units participating in scheduling is generated;

[0102] The response latency, load status, and historical protection effectiveness of each protection unit are evaluated sequentially, and the scheduling priority is calculated.

[0103] The resource allocation ratio is determined according to the priority and risk level of each protection unit;

[0104] After the proportional allocation is completed, proportional balancing is performed on the same level of protection units to form a scheduling priority sequence and resource allocation results.

[0105] In one embodiment, when a security risk assessment signal is triggered, the risk intensity index and network resource occupancy status data for the corresponding time period are read. The risk intensity index is mapped to a predefined security protection level range, for example, low risk corresponds to protection level L1, medium risk to L2, and high risk to L3. The computing power (such as CPU utilization, GPU utilization), communication bandwidth utilization, and available cache for each node in the network are collected, and a resource occupancy information table is formed. In the resource occupancy information table, each node is associated with its corresponding security protection level to generate a set of security protection units participating in the scheduling. For each protection unit in the set, its response latency, current load status, and protection effectiveness score over the past 30 days are evaluated in sequence, and the scheduling priority is calculated based on the evaluation results. Available computing resources, bandwidth, and cache capacity are allocated according to the priority, and resources are allocated to each protection unit proportionally. The allocation ratio of protection units at the same level is balanced to form a scheduling priority sequence and resource allocation scheme, which is then sent to the scheduling execution module.

[0106] In another embodiment, after triggering a security risk assessment signal, the scheduler reads the risk intensity index for that time period and obtains the resource usage data of the network slice, including the CPU / GPU load of computing nodes, link bandwidth utilization, and cache usage of storage nodes. Based on the numerical range of the risk intensity, it is mapped to four security protection levels (L1–L4) and associated with the network slice number. For each protection level, the computing power, communication bandwidth, and available cache of all nodes are collected to form a detailed resource usage information set. The protection levels are mapped to the resource usage information to generate a set of security protection units participating in this round of scheduling. The protection units in the set are then comprehensively evaluated, including node response latency, current load ratio, and historical protection success rate. Based on the evaluation results, the scheduling priority is calculated, and a resource allocation ratio is determined in conjunction with the risk level. Resources are allocated proportionally to each protection unit, and a balanced allocation is performed for units of the same level, generating a scheduling priority sequence and resource allocation results for execution by the 5G network dynamic security capability scheduling module.

[0107] Of particular importance, step S4 includes:

[0108] The generated scheduling instructions are sent to the corresponding network nodes in order of priority.

[0109] After receiving the scheduling instruction, each node loads the corresponding security protection components according to the allocation ratio;

[0110] After loading is complete, perform a dynamic switching operation on security capabilities;

[0111] During the switchover process, node response latency, resource usage changes, and security task status are recorded in real time.

[0112] After the switching operation is completed, execution feedback data is collected from each node to calculate the execution completion rate and latency distribution.

[0113] The collected data is processed in a time series to generate dynamic capacity scheduling records.

[0114] In one embodiment, the generated scheduling instructions are sequentially distributed to the corresponding network nodes according to the previously calculated scheduling priority sequence. During the distribution process, the scheduling records the timestamp of the instruction transmission and the receiving node information. After receiving the scheduling instructions, each network node parses the instruction content and loads the corresponding security protection components, such as intrusion detection modules, firewall rules, and traffic isolation policies, according to the allocation ratio. During the loading process, the nodes monitor resource usage in real time and record component loading time and response latency. After the security protection components are loaded, the nodes trigger a dynamic security capability switching operation, switching the current operating state to the security mode specified by the scheduling instructions. During the switching process, the nodes collect response latency, CPU / GPU utilization, memory usage, and network traffic changes in real time and record the security task execution status. After the switching is completed, the nodes report the execution feedback data to the scheduling center. The scheduling center calculates the execution completion rate and response latency distribution of each node and organizes the data in chronological order to generate a complete dynamic capability scheduling record.

[0115] In another embodiment, the scheduling center sends scheduling instructions to the corresponding network nodes via the control plane according to priority. Each instruction includes a node number, allocation ratio, and a list of protection tasks. Upon receiving the instruction, each node verifies its integrity and decodes it. Then, based on the allocation ratio, it loads the required security protection components, including a deep learning-based anomaly detection model, a traffic scheduling module, and access control policies. The loading process is recorded in real-time by the node's local monitoring system, and a dynamic switching operation of security capabilities is automatically triggered upon completion. During the switching process, each node continuously collects and records response latency, bandwidth utilization, processor usage, and security event logs. After the switching is complete, each node sends execution feedback data to the scheduling center. The scheduling center aggregates the feedback information from all nodes, performs statistical analysis on the execution completion rate, average response latency, and node load curves, and integrates the data into a time-series archive, forming a complete dynamic capability scheduling record.

[0116] The above description is merely a specific embodiment of the present invention, enabling those skilled in the art to understand or implement the invention. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the invention. Therefore, the present invention is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features of the invention herein.

Claims

1. A method for dynamic security capability scheduling in 5G networks based on deep learning, characterized in that, Includes the following steps: Step S1: During the operation of the 5G network, continuously collect the status parameters of the network slices and construct a security situation data sequence; Step S2: Perform feature correlation analysis on the security situation data sequence, extract security feature factors reflecting changes in the security situation, and generate a security risk judgment signal based on the security feature factors; wherein, step S2 includes: The security situation data sequence is divided into time windows, and sequence segments are extracted sequentially using a sliding window of fixed length; In each sequence segment, multidimensional feature correlation calculations are performed to statistically analyze the fluctuation correlations among various safety operation parameters and identify safety characteristic factors affecting changes in the safety situation, including: Within a time window, instantaneous values ​​of safe operating parameters are read point by point. The rate of change between adjacent values ​​is calculated, and a parameter change sequence is generated, including: At the start of the sliding window, the current values ​​of each safety operation parameter are read sequentially and recorded in chronological order as the initial sampling points; After the sampling interval is reached, the values ​​of the same set of parameters are repeatedly collected at the next time step to form a pair of values ​​at adjacent time steps. Perform a difference operation on each pair of values ​​to obtain the instantaneous change in the parameter; Arrange the continuous difference results in chronological order to generate a change sequence; Detect abrupt changes and stable intervals in rate of change sequences to mark key periods of parameter fluctuations. In the changing sequence, the synchronous fluctuation relationship between different parameters is statistically analyzed; When any parameter group exhibits the same directional fluctuation characteristic within a continuous sampling period, the coupling frequency and amplitude ratio of the parameter group are recorded, and based on the coupling frequency and amplitude ratio, the dominant parameter affecting the change of security situation is determined. By aggregating the dynamic characteristics of the dominant parameters within the window, the security characteristic factors affecting changes in the security situation are identified. Based on the changing trend of safety characteristic factors within a continuous window, a risk intensity index is calculated, and the risk intensity index is compared with a preset safety threshold range to generate a risk warning indicator, which includes: Within a continuous time window, track the difference in the direction and magnitude of change of security feature factors, and calculate the cumulative rate of change of each feature quantity between adjacent windows; Based on the statistical distribution of the cumulative rate of change, a risk intensity index is generated to reflect the overall degree of fluctuation in the security situation. The risk intensity index is compared with the preset safety threshold range step by step to determine the risk level and mark the corresponding time period. When the risk intensity index continues to exceed the high threshold range, a risk warning sign is triggered to indicate that the security situation has entered an abnormal state. When the risk warning indicator remains in the triggered state within a continuous window, a security risk judgment signal is generated, and the corresponding time period and network slice number are marked. Step S3: When the security risk assessment signal reaches the preset trigger condition, determine the scheduling priority and allocation ratio of the security protection unit according to the risk intensity and resource occupancy distribution; Step S4: Send the scheduling command to the corresponding network node to perform dynamic switching of security capabilities; after the scheduling is completed, collect the execution data fed back by each node to form a dynamic capability scheduling record.

2. The 5G network dynamic security capability scheduling method based on deep learning according to claim 1, characterized in that, Step S1 includes: During the operation of the 5G network, the operating status parameters of the 5G network are collected, including the security operation parameters of network slices, abnormal connection records of access nodes, and real-time load information of transmission paths. After the data collection is completed, the node behavior information collected during the operation cycle is summarized to establish an event log set related to the security situation; The runtime status parameters are aligned with the event log set in a time sequence to construct a security posture data sequence.

3. The 5G network dynamic security capability scheduling method based on deep learning according to claim 2, characterized in that, The specific steps for collecting the running status parameters of each network slice are as follows: Within the slice deployment node, a parameter acquisition task is pre-set, and the running status information is read from the control plane and the data plane respectively according to the set sampling period; The access authentication results and resource scheduling records collected by the control plane are written into the security monitoring buffer in chronological order; Real-time metrics are extracted from the data plane synchronously and grouped according to node identifiers; For parameters that exhibit abnormal fluctuations during the sampling process, perform resampling and update the corresponding parameter records with the resampling results; At the end of the sampling period, a sequence of running state parameters for the network slice is formed.

4. The 5G network dynamic security capability scheduling method based on deep learning according to claim 2, characterized in that, The abnormal connection records of the access nodes are collected as follows: Configure a connection status monitoring program in the access layer gateway to read the time series of connection establishment requests and handshake responses from access nodes; When the number of consecutive requests exceeds the set threshold or the handshake response times out, the connection event is marked as an abnormal connection, and the network address of the triggering node and the connection latency are recorded. Abnormal connection events are grouped by node and written to the event log cache in real time.

5. The 5G network dynamic security capability scheduling method based on deep learning according to claim 2, characterized in that, The real-time load information of the transmission path is collected as follows: During data transmission, the traffic distribution status between path nodes is monitored at fixed time intervals, and the inbound bandwidth utilization and outbound transmission rate of each node are recorded. When the difference in bandwidth utilization between adjacent nodes exceeds a set threshold, it is determined that there is a risk of uneven load in the path segment, and the continuous transmission packets of the path segment are captured and counted. The real-time load factor is calculated based on the total number of data packets and the proportion of effective transmission packets per unit time, and the calculation results are synchronized to the path status table. After the path status table is updated, a load change curve is generated to determine the load fluctuation trend in different time periods. When the load coefficient remains in the high threshold range for multiple consecutive sampling periods, the node identifier and time tag of the corresponding path segment are recorded as real-time load information.

6. The 5G network dynamic security capability scheduling method based on deep learning according to claim 1, characterized in that, When any parameter group exhibits unidirectional fluctuation characteristics within a continuous sampling period, the coupling frequency and amplitude ratio of that parameter group are recorded. Based on the coupling frequency and amplitude ratio, the dominant parameters affecting changes in the security situation are determined, including: Statistical analysis was performed on the synchronous fluctuations among various safe operating parameters, and parameter groups that showed coordinated changes within the same time window were recorded. Compare the number of cooperative changes for each parameter group in a continuous window, calculate the stable interval of coupling frequency, and identify the parameter groups that continue to appear in this interval. For the identified parameter group, extract the ratio of its change in the same time period and calculate the fluctuation range of the ratio. When the coupling frequency of a parameter group remains stable over multiple window periods and the fluctuation range of the amplitude ratio is lower than a set threshold, the main variable corresponding to the parameter group is determined as a candidate dominant parameter. Candidate dominant parameters are validated across windows to assess their impact on changes in security posture over a continuous time period. Based on the intensity of influence and the stability of persistence, the candidate dominant parameters are prioritized to determine the dominant parameters at the current stage.

Citation Information

Patent Citations

  • Network security index evaluation system

    CN120017549A

  • Resource allocation system and method for 5G-A Internet of Vehicles network slices

    CN120456066A