Risk signaling security protection method and device, electronic equipment and storage medium
By refining signaling classification and adopting desensitization and virtual response measures, the problems of information leakage and attack detection in the security protection of international interoperable signaling have been solved, and effective protection against combined attacks and identification of attack intentions have been achieved.
Patent Information
- Application Number
- CN202511163086.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-19
- Publication Date
- 2025-12-12
AI Technical Summary
Existing technologies are unable to effectively protect against combined attacks involving multiple signaling messages or attacks with unknown attack characteristics in international interoperability security. This poses risks of information leakage and the problem of attackers frequently improving their attack methods after being detected.
By refining the risk signaling classification, signaling is divided into signaling that obtains sensitive user information and signaling that does not obtain sensitive user information. Different protection measures are taken for different types of signaling, including de-identification processing and constructing virtual response signaling to mislead attackers and reduce the leakage of sensitive information and the perception of attacks.
It effectively prevents the leakage of users' sensitive information, reduces the risk of attackers realizing that their attacks have been discovered, encourages attackers to continue their attacks in order to understand their true intentions, and reduces the frequency of subsequent attacks.
Smart Images

Figure CN121125177A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of signaling security protection, and particularly relates to a risk signaling security protection method and device, electronic equipment and a storage medium. BACKGROUND
[0002] With the growth of communication interaction services between communication networks in different regions, the security protection of international interconnection signaling has attracted more and more attention. In the related technology, the security protection of a single signaling is usually carried out according to the division results of the signaling involved in the business process of international interconnection networking, and according to the three types of security risk signaling divided out.
[0003] However, for the combination type of multiple signaling or the combination type of unknown attack behavior characteristics, the protection scheme in the related technology is easy to leak information and easy to cause continuous attacks by the attacker, and the protection effect cannot meet the actual needs. SUMMARY
[0004] The present application aims to at least solve one of the technical problems in the related art to some extent.
[0005] To this end, a first object of the present application is to provide a risk signaling security protection method.
[0006] A second object of the present application is to provide a risk signaling security protection method and device.
[0007] A third object of the present application is to provide an electronic equipment.
[0008] A fourth object of the present application is to provide a computer readable storage medium.
[0009] A fifth object of the present application is to provide a computer program product.
[0010] To achieve the above objects, a risk signaling security protection method is provided in the first aspect of the present application, comprising:
[0011] detecting whether the received signaling is a risk signaling, and determining the type of the detected risk signaling;
[0012] in response to the type of the risk signaling being a user sensitive information acquisition signaling, intercepting a first response signaling corresponding to the user sensitive information acquisition signaling, performing desensitization processing on the first response signaling, and returning the desensitized first response signaling;
[0013] In response to the type of the risk signaling being non-acquisition of user sensitive information signaling, the non-acquisition of user sensitive information signaling is intercepted, a second response signaling corresponding to the non-acquisition of user sensitive information signaling is constructed, and the second response signaling is returned; wherein the desensitization processed first response signaling and the second response signaling are used to mislead an attack party to perform a subsequent attack operation or mislead an attack perception result of the attack party.
[0014] To achieve the above object, the second aspect of the present application proposes a risk signaling security protection device, comprising:
[0015] A detection module is configured to detect whether the received signaling is risk signaling, and determine the type of the detected risk signaling;
[0016] A desensitization module is configured to, in response to the type of the risk signaling being acquisition of user sensitive information signaling, intercept a first response signaling corresponding to the acquisition of user sensitive information signaling, perform desensitization processing on the first response signaling, and return the desensitization processed first response signaling;
[0017] A construction module is configured to, in response to the type of the risk signaling being non-acquisition of user sensitive information signaling, intercept the non-acquisition of user sensitive information signaling, construct a second response signaling corresponding to the non-acquisition of user sensitive information signaling, and return the second response signaling; wherein the desensitization processed first response signaling and the second response signaling are used to mislead an attack party to perform a subsequent attack operation or mislead an attack perception result of the attack party.
[0018] To achieve the above object, the third aspect of the present application proposes an electronic device, comprising: a processor, and a memory connected with the processor in communication;
[0019] The memory stores computer execution instructions;
[0020] The processor executes the computer execution instructions stored in the memory, so as to realize the method according to the first aspect of the present application.
[0021] To achieve the above object, the fourth aspect of the present application proposes a computer readable storage medium, wherein the computer readable storage medium stores computer execution instructions, and the computer execution instructions are executed by a processor to realize the method according to the first aspect of the present application.
[0022] To achieve the above object, the fifth aspect of the present application proposes a computer program product, comprising a computer program, wherein the computer program is executed by a processor to realize the method according to the first aspect of the present application.
[0023] The risk signaling security protection method, device, electronic equipment and storage medium provided by the application can effectively avoid the leakage of user real sensitive information, and still provide the attacker with the related information required for subsequent further attacks, so as to provide the attacker with the required information, promote the attacker to continue the attack affecting the business, and achieve the purpose of finding out the real attack intention of the attacker. On the other hand, the improved design for the attack signaling without obtaining user sensitive information helps to prevent the attacker from quickly sensing the attack behavior after the attack behavior is found and trying other new attack methods, so as to reduce the risk of receiving continuous attacks in the future.
[0024] Additional aspects and advantages of the application will be in part apparent and in part pointed out hereinafter. BRIEF DESCRIPTION OF DRAWINGS
[0025] The above and / or additional aspects and advantages of the application will become apparent and be readily appreciated from the following description, including the appended drawings.
[0026] Figure 1 A schematic diagram of an international intercommunication signaling security protection processing flow based on attack effect for related embodiments;
[0027] Figure 2 A flowchart of a risk signaling security protection method provided by the embodiments of the application;
[0028] Figure 3 A flowchart of a risk signaling type determination method provided by the embodiments of the application;
[0029] Figure 4 A schematic diagram of a specific risk signaling security protection processing flow provided by the embodiments of the application;
[0030] Figure 5 A flowchart of a risk signaling security protection method provided by the embodiments of the application;
[0031] Figure 6 A flowchart of a record updating method after direct business signaling protection provided by the embodiments of the application;
[0032] Figure 7 A schematic diagram of an international intercommunication signaling security risk misleading protection flow based on attack effect provided by the embodiments of the application;
[0033] Figure 8 A schematic diagram of a signaling message protocol consistency security protection processing flow provided by the embodiments of the application;
[0034] Figure 9 A schematic diagram of a list-based security protection processing flow provided for an embodiment of the present application is shown in FIG. 1.
[0035] Figure 10 A schematic diagram of an illegal Category 1 signaling protection processing flow based on a networking model provided for an embodiment of the present application is shown in FIG. 2.
[0036] Figure 11 A schematic diagram of an illegal Category 2 signaling protection processing flow based on a networking model provided for an embodiment of the present application is shown in FIG. 3.
[0037] Figure 12 A schematic diagram of an illegal Category 3 signaling protection processing flow based on a networking model provided for an embodiment of the present application is shown in FIG. 4.
[0038] Figure 13 A structural schematic diagram of a risk signaling security protection device provided for an embodiment of the present application is shown in FIG. 5. DETAILED DESCRIPTION
[0039] Embodiments of the present application are described in detail below, examples of which are shown in the accompanying drawings, wherein the same or similar reference numerals represent the same or similar elements or elements having the same or similar functions throughout. The embodiments described below by reference to the accompanying drawings are exemplary and are intended to explain the present application, and cannot be understood as limiting the present application.
[0040] It should be noted that, in order to facilitate understanding of the protection process and implementation principle of the risk signaling security protection of the present application, the risk signaling security protection scheme in the related embodiments is described below.
[0041] In the current international interconnection signaling security protection related scheme, the security protection of a single signaling is performed according to the division results of the signaling involved in the business process in the international interconnection networking, that is, the three types of security risk signaling (that is, the Cat1 signaling is various types of illegal signaling that should not appear in the interconnection scenario, the Cat2 signaling is the signaling sent by the imitated home network to the visited network, and the Cat3 signaling is the signaling sent by the imitated visited network to the home network), and the security protection of a single signaling is performed.
[0042] In some related embodiments, the protection scheme can kill the part of the information acquisition attack operation required to collect user or network information in advance before the operation of initiating an attack affecting business is initiated by intercommunication command, preventing the attacker from further attacking the user or network element in the home network after collecting enough relevant information to initiate an attack affecting business function. In this protection scheme, although in terms of protecting attacks, it is basically possible to protect all single attack signaling with known attack behavior characteristics, but the protection effect of combined signaling or combined attack with unknown attack behavior characteristics is poor.
[0043] Specifically, for combined signaling attack scenarios, such as the need to perform information collection or business attack auxiliary preparation before performing direct business affecting attack operations, the security protection scheme in related embodiments usually performs relevant security protection actions in the early information collection or auxiliary preparation stage of the attack, so that the attacker cannot collect enough relevant information required for subsequent business affecting attack behavior, and cannot trigger subsequent direct business affecting attack behavior.
[0044] However, this protection scheme has the defect that the relevant attack operation cannot be observed, and it is difficult to truly grasp from the perspective of protection for the real attack intention of the subsequent combined attack, and it is difficult to develop targeted subsequent active defense ideas and schemes. The scheme needs to be improved so that further active defense operations such as active paralysis can be performed on the confirmed explicit attack source, and the attacker can be prevented from continuously attacking the attacked party using the attack source, and the signaling security protection can be changed from passive to active.
[0045] Therefore, for combined attack scenarios, the international intercommunication command security protection related scheme in the above embodiments needs to be improved in the following aspects: In the early information collection or business attack auxiliary preparation stage of the combined attack, no longer targeted protection actions are performed on single information collection or auxiliary preparation class attack signaling with known attack behavior characteristics. Instead, in the information collection or business attack auxiliary preparation stage of the attacker, only the discovered information collection or auxiliary preparation class attack operation is observed, and the initiator of the attack behavior (attack source) and the attacked party (attack target user or network element) are recorded as relevant evidence for subsequent direct business affecting attack operations initiated by the attacker. Only the main attack behavior affecting business is protected, and no longer intercepts and protects all secondary attack behaviors such as information collection or auxiliary preparation class. Through this improved design, the attacker's real attack intention can be effectively discovered; at the same time, the initiator of the attack can also be observed, providing effective information support for subsequent targeted security protection of the attack source.
[0046] For example, for the security protection against the combined type signaling attack, in one related embodiment, the improved security protection idea is as follows: on the basis of the original international intercommunication signaling security risk classification based on the traditional networking model, the attack effects are classified into two types: direct influence on the service and non-direct influence on the service. On the basis of the international intercommunication signaling security risk classification based on the networking model, the specific attack effects that can be achieved by the original each type of signaling risk are further analyzed. The signaling that can directly achieve the attack effects, such as illegal positioning tracking, denial of service attack of letting the user off the network, modification of the charging mode and the like, which can directly influence the user service, are classified into the direct influence on the service type risk signaling. The other signaling, such as the non-direct influence on the user service type of obtaining information or auxiliary preparation type and the like, which are non-direct influence on the user service, are classified into the non-direct influence on the service type risk signaling.
[0047] In the improved protection scheme based on the attack effect, the signaling security risk classification list (taking the SS7 (Signaling System No. 7) signaling protocol and the Diameter signaling protocol as examples) is shown in Table 1 as follows:
[0048] Table 1 Security risk classification table based on attack effect
[0049]
[0050]
[0051]
[0052]
[0053] The flow of the international intercommunication signaling security protection processing based on the attack effect is as follows: Figure 1The improved signaling security protection scheme is based on the above two types of security risk classification. For non-directly affecting service type risk signaling, the signaling security protection scheme based on the networking model will not be directly intercepted as designed, but only observes the risk signaling and records the attack source and attack target in the gray list. The new signaling security protection system will monitor the attack source and attack target in the generated gray list for a long time. Only when the directly affecting service type risk signaling is found, the security protection action is taken. At the same time, on the basis of intercepting the directly affecting service type attack signaling, the attack target and attack source in the signaling are moved from the gray list to the black list of the signaling protection system. For any subsequent signaling sent from the attack source, whether it directly affects the service or not, it will be directly intercepted. The pass-through operation of the non-directly affecting service type risk signaling in the scheme can expose some of the information required by the attacker to implement the real service-affected attack to the attacker, trigger the attacker to perform the attack behavior of the real service-affected operation, and discover the real attack intention of the attacker. At the same time, after confirming the real attack intention of the attacker and locking the attack source, the possibility of subsequent attacks from the related attack source is completely cut off.
[0054] However, the above-mentioned international intercommunication signaling security protection scheme based on attack effect can realize the pass-through and observation of non-affecting core service type risk signaling, and only the security protection of risk signaling affecting core service, and can master the real intention of combined attack signaling. However, this scheme has the risk of leaking user sensitive information (such as IMSI identifier, authentication vector, current access network element address, current short message routing address, and current service information, etc.) after passing through the non-directly affecting service type risk signaling. The above-mentioned protection scheme cannot effectively solve the information leakage risk of passing through the non-directly affecting service type risk signaling, and needs to continue to improve the existing protection scheme to solve the above-mentioned problems.
[0055] And, in the above international intercommunication signaling security protection scheme based on attack effect, the operation for the risk signaling directly affecting the service after completing the risk judgment is direct interception, which can effectively avoid the attack risk. However, since no corresponding reply is given to the attack signaling, the attacker can infer that the attacked party has a certain security risk protection capability, and then the attacker will further improve the attack method and means to continue the new attack attempt. That is, in the above scheme, the processing method of directly intercepting the risk signaling directly affecting the service after confirming the risk is easy to be perceived by the attacker as obvious attack failure, which will cause the attacker to frequently repeat or further study the new attack method to continue attacking the user or network element. The security protection improvement method based on attack effect cannot effectively solve the problem of the attacker's perception after intercepting the risk signaling directly affecting the service, and further improvement of the protection scheme is still needed to solve the above problem.
[0056] That is, in the above security protection scheme based on attack effect of international intercommunication signaling in the related embodiments, there are the following two problems:
[0057] First, the scheme does not protect the risk signaling (information acquisition type risk signaling in the non-directly affecting service type risk signaling) that leaks the user's sensitive information in the combined signaling attack scene. Although the attack intention of the attacker can be found by triggering the directly affecting service type risk signaling through leaking the user's real sensitive information, this processing method of acquiring the real attack intention of the attacker by leaking the user's real sensitive information inevitably has the security risk of leaking the user's real sensitive information, and the user's real sensitive information may be continuously used by the attacker for other attacks. This security protection processing method needs to be further improved to ensure that the real attack intention of the attacker can be acquired while minimizing the risk of leaking the user's real sensitive information.
[0058] Second, the scheme directly intercepts the directly affecting service type risk signaling in the combined signaling attack scene after confirming the attack risk. This processing method does not respond to the attack signaling. From the perspective of the attacker, the attack signaling can be judged by judging whether there is a corresponding response, and whether the attack behavior of the attacker is found. After confirming that the attack behavior of the attacker is found, the attacker may continue to attempt attack or study new attack method to continue attack. This processing method can have a protection effect from the risk, but it will also make the attacker realize that the attack is found. This security protection processing method needs to be further improved.
[0059] Therefore, an embodiment of the present application provides a risk signaling security protection method. Figure 2 A flowchart of a risk signaling security protection method provided by an embodiment of the present application is shown in the figure.
[0060] The risk signaling security protection method, device, electronic equipment and storage medium of the embodiments of the present application are described below with reference to the accompanying drawings. As shown in the drawings, the risk signaling security protection method includes the following steps: Figure 2
[0061] Step 101, detecting whether the received signaling is risk signaling, and determining the type of the detected risk signaling.
[0062] Specifically, based on the classification of risk signaling and the core security protection process flow in the above-mentioned international intercommunication signaling security protection scheme based on attack effect, the classification of risk signaling and the subsequent protection process are further improved and optimized. The risk signaling is first refined and distinguished in order to improve the security protection disposal method for different types of refined risk signaling.
[0063] In an embodiment of the present application, the non-directly affecting service class risk signaling in the above-mentioned international intercommunication signaling security protection scheme based on attack effect is specifically subdivided into four categories: information acquisition signaling, information confirmation signaling, information notification signaling and configuration operation signaling. The directly affecting service class risk signaling is specifically subdivided into seven types of attack signaling: illegal positioning signaling, billing fraud signaling, hijacked SMS signaling, hijacked data signaling, denial of service signaling, spam SMS signaling and intercepted call signaling.
[0064] Among them, the information acquisition signaling in the non-directly affecting service class risk signaling and the illegal positioning signaling in the directly affecting service class risk signaling are the signaling for acquiring user sensitive information. The remaining other signaling in the non-directly affecting service class risk signaling and the directly affecting service class risk signaling are non-acquiring user sensitive information signaling.
[0065] Further, after detecting that the currently received signaling is risk signaling, the type of the currently detected risk signaling can be determined according to the above-mentioned classification method.
[0066] Step 102, in response to the type of the risk signaling being the signaling for acquiring user sensitive information, intercepting the first response signaling corresponding to the signaling for acquiring user sensitive information, performing desensitization processing on the first response signaling, and returning the desensitization processed first response signaling.
[0067] Among them, the desensitization processed first response signaling is used to mislead the attacker to perform subsequent attack operation or mislead the attack perception result of the attacker.
[0068] Specifically, in a case where it is determined that the currently received risk signaling is the user sensitive information acquisition signaling, the user sensitive information acquisition signaling is passed, a first response signaling generated by the user sensitive information acquisition signaling is intercepted, and the first response signaling is desensitized, i.e., sensitive information content in the first response signaling is removed. The desensitized first response signaling is returned to the attacker.
[0069] As an example, for the user sensitive information acquisition signaling in the above embodiment, after the signaling enters the network, the response signaling carrying user sensitive information corresponding to the signaling is intercepted, transformed, and then released. Thus, the attacker is prevented from directly acquiring user sensitive information through the user sensitive information acquisition signaling, but the attacker is still provided with user related information protected by desensitization of sensitive information, so as to satisfy the attacker in collecting related information (such as user identification and destination address) necessary for further attack operations, and to prompt the attacker to continue subsequent combined attack operations to trigger direct business risk signaling attack operations.
[0070] In the example, the desensitized first response signaling can mislead the attacker in subsequent attack operations.
[0071] As another example, for the illegal positioning risk signaling in the above embodiment, the signaling is not directly intercepted, but after the signaling enters the network, the response signaling carrying user location information corresponding to the signaling is intercepted, transformed, and then released, so as to prevent the attacker from directly acquiring user location information through the illegal positioning risk signaling. However, the example still provides the attacker with user location information (not real user location information) protected by desensitization, so as to mislead the attacker and make the attacker unable to position and track the real user location and mistakenly believe that the user location has been positioned and tracked.
[0072] In the example, the desensitized first response signaling can mislead the attack perception result of the attacker.
[0073] In step 103, in response to the type of the risk signaling being non-user sensitive information acquisition signaling, the non-user sensitive information acquisition signaling is intercepted, a second response signaling corresponding to the non-user sensitive information acquisition signaling is constructed, and the second response signaling is returned.
[0074] The second response signaling is used to mislead the attacker in subsequent attack operations or mislead the attack perception result of the attacker.
[0075] Specifically, in a case where it is determined that the currently received risk signaling is the above non-user sensitive information acquisition signaling, the signaling is intercepted into the network, a virtual second response signaling corresponding to the non-user sensitive information acquisition signaling is constructed, and the second response signaling is returned to the attacker.
[0076] As an example, for the confirmation information signaling, notification information signaling and configuration operation risk signaling in the non-directly affecting business class risk signaling in the above embodiment, it is no longer passed into the network. Instead, the signaling security protection related system, device, apparatus or related method for realizing signaling security protection directly constructs the related signaling messages (mainly response signaling) of the three types of risk signaling, and returns them to the attacker. Thus, the attacker is misled to believe that the three types of risk signaling have been successfully executed, prompting the attacker to continue the subsequent combined attack operation to trigger the directly affecting business class risk signaling attack operation.
[0077] Among them, the constructed second response signaling in the example can mislead the attacker to perform subsequent attack operations.
[0078] As another example, for the billing fraud signaling, hijacking SMS signaling, hijacking data signaling, denial of service signaling, spam SMS signaling and intercepting call risk signaling in the directly affecting business class risk signaling in the above embodiment, instead of just being directly intercepted, the signaling security protection related system, device, apparatus or related method for realizing signaling security protection directly constructs the related signaling messages (mainly response) of the six types of risk signaling, and returns them to the attacker to mislead the attacker, so that the attacker believes that the six types of risk signaling have been successfully executed.
[0079] Among them, the constructed second response signaling in the example can mislead the attack perception result of the attacker.
[0080] In summary, the risk signaling security protection method provided by the embodiments of the present application can effectively avoid the leakage of user real sensitive information for the improved design of the attack signaling of the acquisition information class and the illegal positioning class for acquiring user sensitive information, while still providing the attacker with the related information needed for subsequent further attacks, achieving the purpose of providing the attacker with the required information, prompting the attacker to continue the attack affecting the business to find out the real attack intention of the attacker. On the other hand, for the improved design of the attack signaling of the non-acquisition user sensitive information, it is helpful to prevent the attacker from quickly perceiving that the attack behavior has been discovered and attempting other new attack methods, which can reduce the risk of receiving continuous attacks in the future.
[0081] Based on the above embodiments, in order to more clearly illustrate the specific implementation process of determining the type of the risk signaling detected by the present application, the determination method of the type of the risk signaling proposed in one embodiment of the present application is exemplarily illustrated. Figure 3 A flowchart of a risk signaling type determination method provided by an embodiment of the present application.
[0082] As Figure 3 shown, the risk signaling type determination method can include the following steps:
[0083] Step 301, judging whether the risk signaling is a request signaling.
[0084] Specifically, after receiving the signaling message determined to be intercepted, the type of the signaling message is first judged. In this embodiment, it is first judged whether the signaling is a request signaling message type.
[0085] The request signaling includes the non-directly affecting service signaling and the directly affecting service signaling in the above embodiment.
[0086] To more clearly illustrate the specific implementation of each step in the risk signaling security protection processing flow of the present application, the specific signaling security protection processing flow shown in Figure 4 is exemplarily described below.
[0087] As shown in Figure 4 , it is first judged in this step whether the current received risk signaling is a request signaling. If not, it is judged to be a response signaling. The response signaling can be a signaling generated due to responding to a certain request signaling.
[0088] Step 302, in response to the risk signaling being a request signaling, judging whether the request signaling is a non-directly affecting service signaling or a directly affecting service signaling.
[0089] Specifically, as shown in Figure 4 , in the case of determining that the risk signaling is a request signaling, it is further judged whether the request signaling is a non-directly affecting service signaling or a directly affecting service signaling
[0090] Step 303, in response to the request signaling being a non-directly affecting service signaling, judging whether the non-directly affecting service signaling is an information acquisition signaling.
[0091] Specifically, in the case of determining that the current request signaling is a non-directly affecting service signaling, it is further judged whether the non-directly affecting service signaling is an information acquisition signaling, so as to subsequently perform corresponding security protection processing on different types of signaling.
[0092] Step 304, in response to the request signaling being a directly affecting service signaling, judging whether the directly affecting service signaling is an illegal positioning signaling.
[0093] Specifically, in the case of determining that the current request signaling is a directly affecting service signaling, it is further judged whether the directly affecting service signaling is an illegal positioning signaling, so as to subsequently perform corresponding security protection processing on different types of signaling.
[0094] It should be noted that in actual application, the subsequent step 303 or step 304 can be judged according to the specific type of the current request signaling determined in step 302.
[0095] Continuing to refer to the above embodiment, since the present application has divided the non-directly affecting service class risk signaling into four categories: acquisition information signaling, confirmation information signaling, notification information signaling, and configuration operation signaling, and divided the directly affecting service class risk signaling into seven categories of attack signaling types: illegal positioning signaling, billing fraud signaling, hijacking short message signaling, hijacking data signaling, denial of service signaling, spam short message signaling, and intercepting call signaling. Therefore, the present embodiment further subdivides the risk signaling types based on the security risk classification results in Table 1 above, and obtains the risk signaling type table shown in Table 2. When determining the specific type of the request signaling, the signaling type can be determined with reference to Table 2 below:
[0096] Table 2 Risk Signaling Type Table
[0097]
[0098]
[0099]
[0100]
[0101] As described above, the risk signaling is subdivided in the present embodiment, so as to facilitate the improvement of the security protection processing mode for the subdivided different types of risk signaling. This is conducive to achieving the attack intention of the attacker on the basis of not leaking the real sensitive information of the user, and also well achieves the security protection effect, and can also mislead the attacker to reduce the possible subsequent security risks.
[0102] Based on the above embodiment of determining the risk signaling type, in order to more clearly illustrate the security protection specific implementation process of the present application for the determined acquisition user sensitive information signaling, the following will exemplarily illustrate a security protection method for acquiring user sensitive information signaling proposed in one embodiment of the present application. Figure 5 A flowchart of a security protection method for acquiring user sensitive information signaling provided in an embodiment of the present application.
[0103] As Figure 5 shown, the method can include the following steps:
[0104] Step 501: pass the acquisition user sensitive information signaling, and record the message identifier of the acquisition user sensitive information signaling.
[0105] The message identifier includes the TCAP layer source transaction ID (OrigTransactionID, or otid for short) in the SS7 signaling protocol or the protocol layer session ID (Session-Id) in the Diameter signaling protocol.
[0106] Specifically, if the current risk signaling is determined to be a signaling to obtain sensitive user information (i.e., the aforementioned signaling to obtain information and illegal location signaling), the signaling is allowed and the message identifier in the signaling is recorded.
[0107] Continue to refer to Figure 4 To illustrate, if in the above embodiment it is determined that the current request signaling is an information-gathering attack signaling message that does not directly affect the service signaling message, then the request signaling message is allowed, and the identifier of the request signaling message is recorded (in the SS7 signaling protocol, it is the TCAP layer source transaction ID identifier, and in the Diameter signaling protocol, it is the Diameter protocol layer session ID identifier). If in the above embodiment it is determined that the current request signaling is an illegal location attack signaling message that directly affects the service signaling message, then the request signaling message is allowed, and the identifier of the request signaling message is recorded (in the SS7 signaling protocol, it is the TCAP layer source transaction ID identifier, and in the Diameter signaling protocol, it is the Diameter protocol layer session ID identifier).
[0108] Step 502: Determine whether the message identifier of the currently received response signaling matches the recorded message identifier.
[0109] Specifically, after allowing the acquisition of sensitive user information, a response signaling will be received from the network in response to this acquisition of sensitive user information signaling. For example... Figure 4 As shown, when it is determined that the currently received signaling message type is a response signaling message type, in order to identify whether the currently received response signaling is the response signaling corresponding to the previously released signaling for obtaining sensitive user information (i.e., the first response signaling), this step matches the message identifier of the currently received response signaling with the recorded message identifier.
[0110] For example, determine whether the DestTransactionID (dtid) identifier in the TCAP layer of the SS7 response signaling message is the same as the Otid identifier in the TCAP layer of the recorded request signaling message; or determine whether the Diameter protocol layer session ID (Session-Id) identifier in the Diameter response signaling message is the same as the Diameter protocol layer session ID (Session-Id) identifier in the recorded request signaling message.
[0111] Step 503, in response to the message identifier matching, determining that the currently received response signaling is the first response signaling, and intercepting the first response signaling.
[0112] Specifically, if it is determined through step 502 that the message identifier matches, i.e., the currently received response signaling is the recorded signaling message, the response signaling message is intercepted.
[0113] Continuing to refer to the example of Figure 4 If it is determined through step 502 that the current response signaling is not the recorded response signaling message, the response signaling message is directly passed through.
[0114] Step 504, desensitizing the first response signaling, and returning the desensitized first response signaling.
[0115] Specifically, the desensitizing of the first response signaling includes replacing the user-related sensitive information content (such as IMSI identifier, authentication vector, current access network element address, current short message routing address, and current service information, etc.) with other non-sensitive information or other fake related information. The desensitized response signaling message is returned to the attacker.
[0116] It should be noted that the desensitizing of the first response signaling by the embodiments of the present application, i.e., the modification of the user-related sensitive information content, is not limited to a specific modification method, and the desensitizing method can be selected according to actual conditions.
[0117] For example, the modification of the existing user real sensitive information content to non-sensitive information can be implemented by scrambling code, random code, etc.; the modification of all user real sensitive information content to a non-existent related content can also be implemented; and the modification of the existing user real sensitive information content by segmenting, scrambling, and rearranging can also be implemented.
[0118] That is, the specific modification method is not limited, and various open modification methods are supported, and the core purpose is to process the user-related sensitive information content to avoid leaking the real sensitive information content of the user to the attacker.
[0119] Step 505, clearing the record information of the message identifier of the first response signaling.
[0120] Specifically, the record information of the response signaling message corresponding identifier is cleared at the same time as the response signaling message is returned.
[0121] In summary, by improving the signaling security risk protection processing flow based on attack effect, the embodiments of the present application can, on the basis of the existing processing method, prevent various attack operations of obtaining user sensitive information through international intercommunication signaling from the root by transforming and processing the related response signaling messages that leak user sensitive information before passing them through. Moreover, some misleading information can still be returned to the attacker to prompt him to perform subsequent further attack operations that affect the business, i.e., to avoid the attacker from attempting other new attack methods after discovering that his attack behavior has been discovered. The risk of leaking various real sensitive information of the user is also actually avoided.
[0122] Based on the above embodiment of determining the risk signaling type, the security protection method of non-user sensitive information acquisition signaling is exemplarily described in an embodiment of the present application.
[0123] In the present embodiment, the current risk signaling is determined to be non-user sensitive information acquisition signaling, and the risk signaling is intercepted.
[0124] Continuing to refer to the example of Figure 4 , if it is determined in the above embodiment that the current request signaling is a non-directly affecting business signaling message, it is further determined whether the non-directly affecting business signaling message is an information acquisition type attack signaling type. If not, the request signaling message is intercepted, and the response signaling message corresponding to the request signaling message is constructed and returned to the sending network element of the request signaling message.
[0125] If it is determined in the above embodiment that the current request signaling is a directly affecting business signaling message, it is further determined whether the directly affecting business signaling message is an illegal positioning type attack signaling type. If not, the request signaling message is intercepted, and the response signaling message corresponding to the request signaling message is constructed and returned to the sending network element of the request signaling message.
[0126] For example, the direct interception manner for the direct impact service class risk signaling in the related embodiments is changed to the processing manner of forging a reply response message, such as, for illegal positioning, a non-legal address information is forged and returned to the attacker, so as to mislead the attacker and make the attacker think that the real position information of the user is obtained. For the attack signaling such as charging fraud, hijacking of short messages, hijacking of data, denial of service, junk short messages and interception of calls in the present embodiment, a response message of successful execution of the signaling is forged, so as to mislead the attacker and make the attacker think that the attack operation corresponding to the impact service has been successfully executed. The effect of the attacker to continue to further attempt a new attack method after not receiving the attack signaling response message can be effectively reduced. Through the misleading operation of the direct impact service class risk signaling, the frequency of being attacked can be greatly reduced, the attempt of the attacker to a new attack manner is reduced, and the effect of the attacker to judge the attack behavior is also misled, so that the security risk is reduced.
[0127] In summary, the present embodiment performs a related response on the non-sensitive information acquisition class attack signaling, instead of directly intercepting the related signaling message, so as to avoid the possibility that the attacker attempts other attacks after realizing that the attack behavior is discovered.
[0128] Based on the above embodiment, the processing flow after the security protection of the risk signaling is completed is described below. In one embodiment of the present application, after the security protection processing of the non-direct impact service signaling message is completed, it is judged whether the user identifier (IMSI or MSISDN) and / or source address information (SCCP layer source GT (Calling Party address) field information in SS7 signaling, Diameter protocol layer source host (Origin-Host) field information in Diameter signaling) in the request signaling message are recorded in the gray list. If not, the user identifier (IMSI or MSISDN) and / or source address and time information in the request signaling message are recorded in the gray list. If yes, the time information of the same recorded information as the user identifier (IMSI or MSISDN) and / or source address in the request signaling message in the gray list is updated.
[0129] Figure 6 A flowchart of a recording update method after the security protection of the direct impact service signaling provided by the present embodiment is shown in FIG. 6, which includes the following steps: Figure 6
[0130] In step 601, in response to the request signaling being a direct impact service signaling, it is judged whether the user identifier and / or source address information in the request signaling are recorded in the gray list.
[0131] Specifically, in cases where the request signaling directly affects the service signaling, such as... Figure 4 As shown, after completing the security protection process in the above embodiments, it is further determined whether the user identifier (IMSI or MSISDN) and / or source address information (SCCP layer source GT (Calling Party address) field information in SS7 signaling, and Diameter protocol layer source host (Origin-Host) field information in Diameter signaling) in the request signaling message are recorded in the gray list.
[0132] Furthermore, if a record exists in the gray list, the user identifier (IMSI or MSISDN) and / or source address information in the request signaling message are removed from the gray list and added to the black list.
[0133] Step 602: In response to the user identifier and / or source address information not being recorded in the gray list, determine whether the user identifier and / or source address information is recorded in the black list.
[0134] Specifically, if the user identifier and / or source address information are not recorded in the gray list, it is further determined whether the user identifier (IMSI or MSISDN) and / or source address information (SCCP layer source GT (Calling Party address) field information in SS7 signaling / Diameter protocol layer source host (Origin-Host) field information in Diameter signaling) in the request signaling message are recorded in the blacklist.
[0135] Furthermore, if the information is not recorded in the blacklist, the user identifier (IMSI or MSISDN) and / or source address and time information in the request signaling message are recorded in the blacklist.
[0136] Step 603: In response to the user identifier and / or source address information being recorded in the blacklist, update the recording time of the user identifier and / or source address information in the blacklist.
[0137] Specifically, if the user identifier and / or source address information is recorded in the blacklist, update the time information of the record containing the same user identifier (IMSI or MSISDN) and / or source address in the request signaling message in the blacklist.
[0138] The embodiments of this application update the records of user identifiers and / or source address information after the signaling message security protection processing, which helps to improve the accuracy of subsequent security protection processing of related risk signaling.
[0139] In an embodiment of the present application, the detection of whether the received signaling is risk signaling comprises: sequentially performing signaling message protocol consistency protection processing, list-based security risk protection processing and networking model-based security risk protection processing on the received signaling; in the case that the received signaling is detected to have risks in any protection processing, the received signaling is determined to be risk signaling.
[0140] Specifically, the misleading security protection method of the present application, on the basis of the attack-effect-based international intercommunication signaling security protection system, mainly improves the original attack-effect-based security risk protection processing flow and partially updates the list-based security risk protection processing steps involved, so as to realize the misleading protection of risk signaling.
[0141] As shown in Figure 7 The improvement of the present application to the core business logic of the original attack-effect-based international intercommunication signaling security protection system mainly includes: in the original list-based security risk protection processing, when the user identifier (IMSI or MSISDN) and the source address in the signaling message are determined to be in the signaling security risk blacklist, instead of performing the interception action according to the information or security protection rules recorded in the blacklist, the corresponding processing is performed in the attack-effect-based security risk misleading protection processing flow, so as to realize the misleading protection of risk signaling.
[0142] Among them, the main improvement points of the present application to the three core business logics in the original attack-effect-based international intercommunication signaling security protection system: signaling message protocol consistency protection, list-based security risk protection and networking model-based security risk protection are as shown in Figures 8 to 12
[0143] Specifically, in the above three protection processing processes, by determining whether the corresponding conditions are met, after the current signaling is detected to have risks, the original entering of the attack-effect-based security risk protection processing flow is changed to the entering of the attack-effect-based security risk misleading protection processing flow of the present application. That is, as shown in Figure 4 In the case that the received signaling is detected to have risks in any protection processing in the signaling message protocol consistency protection processing, the list-based security risk protection processing and the networking model-based security risk protection processing, the received signaling is determined to be risk signaling, and then the security protection method of risk signaling described in the above embodiments of the present application is executed.
[0144] The embodiment of the present application changes the original entering of the security risk protection processing based on attack effect into the security risk misleading protection processing based on attack effect, edits the response signaling message involved in leakage of user real sensitive information in combination signaling attack before returning, can effectively prevent the risk of leakage of user real sensitive information in the combination signaling security protection process, and can return the corresponding misleading response message to the attacker, and can prevent the attacker from trying other new attack methods after feeling that the attack behavior is found.
[0145] In order to realize the above-mentioned embodiment, the present application further provides a risk signaling security protection device.
[0146] Figure 13 A structural schematic diagram of a risk signaling security protection device provided by the embodiment of the present application.
[0147] As shown in the figure, the risk signaling security protection device comprises: Figure 13 A detection module 100, configured to detect whether the received signaling is risk signaling, and determine the type of the detected risk signaling.
[0148] A desensitization module 200, configured to, in response to the type of the risk signaling being user sensitive information acquisition signaling, intercept a first response signaling corresponding to the user sensitive information acquisition signaling, perform desensitization processing on the first response signaling, and return the first response signaling after the desensitization processing.
[0149] A construction module 300, configured to, in response to the type of the risk signaling being non-user sensitive information acquisition signaling, intercept the non-user sensitive information acquisition signaling, construct a second response signaling corresponding to the non-user sensitive information acquisition signaling, and return the second response signaling; wherein the first response signaling after the desensitization processing and the second response signaling are used to mislead the attack party to perform subsequent attack operation or mislead the attack sensing result of the attack party.
[0150] Further, in a possible implementation manner of the embodiment of the present application, the user sensitive information acquisition signaling comprises information acquisition signaling and illegal positioning signaling; the detection module 100 is configured to: judge whether the risk signaling is request signaling; in response to the risk signaling being the request signaling, judge whether the request signaling is non-directly affecting business signaling or directly affecting business signaling; in response to the request signaling being the non-directly affecting business signaling, judge whether the non-directly affecting business signaling is the information acquisition signaling.
[0151] Further, in a possible implementation manner of the embodiment of the present application, the detection module 100 is further configured to: in response to the request signaling being the directly affecting business signaling, judge whether the directly affecting business signaling is the illegal positioning signaling.
[0152]
[0153] Further, in a possible implementation of the embodiment of the application, the desensitization module 200 is configured to: pass through the acquired user sensitive information signaling and record a message identifier of the acquired user sensitive information signaling, wherein the message identifier comprises a TCAP layer source transaction ID identifier in the SS7 signaling protocol or a protocol layer session ID identifier in the Diameter signaling protocol; determine whether a message identifier of the currently received response signaling matches the recorded message identifier; in response to the message identifier matching, determine that the currently received response signaling is the first response signaling and intercept the first response signaling.
[0154] Further, in a possible implementation of the embodiment of the application, the desensitization module 200 is further configured to: replace sensitive information in the first response signaling with non-sensitive information; and clear the record information of the message identifier of the first response signaling.
[0155] Further, in a possible implementation of the embodiment of the application, the non-directly affecting service signaling further comprises confirmation information signaling, notification information signaling and configuration operation signaling, and the directly affecting service signaling further comprises charging fraud signaling, hijacking short message signaling, hijacking data signaling, denial of service signaling, spam short message signaling and intercepted call signaling; the construction module 300 is configured to: in response to the request signaling being the directly affecting service signaling, determine whether user identification and / or source address information in the request signaling is recorded in a gray list; in response to the user identification and / or source address information not being recorded in the gray list, determine whether the user identification and / or source address information is recorded in a black list; and in response to the user identification and / or source address information being recorded in the black list, update a record time of the user identification and / or source address information in the black list.
[0156] Further, in a possible implementation of the embodiment of the application, the detection module 100 is further configured to: sequentially perform signaling message protocol consistency protection processing, list-based security risk protection processing and networking model-based security risk protection processing on the received signaling; and in a case where it is detected that the received signaling has a risk in any protection processing, determine that the received signaling is a risk signaling.
[0157] In summary, the risk signaling security protection device provided by the embodiments of the present application can effectively avoid the leakage of user real sensitive information, and still provide the attacker with the related information required for subsequent further attacks, so as to achieve the purpose of providing the attacker with the required information, prompting the attacker to continue the attack affecting the business, and finding out the real attack intention of the attacker. On the other hand, the improved design for the attack signaling without obtaining user sensitive information helps to prevent the attacker from quickly sensing the attack behavior after the attack behavior is found and trying other new attack methods, so as to reduce the risk of receiving continuous attacks in the future.
[0158] In order to implement the above-mentioned embodiments, the present application further provides an electronic device, comprising a processor and a memory connected with the processor in communication; the memory stores computer execution instructions; the processor executes the computer execution instructions stored in the memory to implement the method provided by the foregoing embodiments.
[0159] In order to implement the above-mentioned embodiments, the present application further provides a computer readable storage medium, the computer readable storage medium stores computer execution instructions, and the computer execution instructions are executed by the processor to implement the method provided by the foregoing embodiments.
[0160] In order to implement the above-mentioned embodiments, the present application further provides a computer program product, comprising a computer program, the computer program is executed by the processor to implement the method provided by the foregoing embodiments.
[0161] The collection, storage, use, processing, transmission, provision and disclosure of user personal information involved in the present application comply with the relevant laws and regulations, and do not violate public order and good customs.
[0162] It should be noted that the personal information from the user should be collected for legal and reasonable purposes, and should not be shared or sold outside these legal uses. In addition, such collection / sharing should be carried out after the user's informed consent is received, including but not limited to informing the user to read the user agreement / user notice before the user uses the function, and signing the agreement / authorization including authorization of relevant user information. In addition, any necessary steps should be taken to protect and ensure access to such personal information data, and to ensure that other people with access to personal information data comply with their privacy policy and processes.
[0163] The present application contemplates an implementation that provides users with the ability to selectively opt in or opt out of permitting the collection and / or use of their personal information data. That is, the present disclosure contemplates providing users with the ability to prevent or limit the collection and / or use of their personal information data. For example, the present disclosure contemplates providing users with the ability to prevent or limit the collection and / or use of their personal information data by, for example, blocking or deleting cookies. In addition, the present disclosure contemplates providing users with the ability to determine whether and how to interact with the present disclosure by, for example, blocking web beacons. Further, the present disclosure contemplates providing users with the ability to access and / or edit their personal information data when such data is collected by the present disclosure. Additionally, the present disclosure contemplates that the collection and / or use of personal information data can be done in a manner that complies with all other applicable laws and regulations, including, for example, the European Union’s General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and / or any comparable privacy laws.
[0164] In the foregoing detailed description, the description used with respect to the terms "one embodiment", "some embodiments”, "an example”, "a specific example” or "some examples” etc. means that a particular feature, structure, material, or characteristic described in connection with the embodiment or example is included in at least one embodiment or example of the present application. The illustrative appearances of the above-mentioned terms in the description are not necessarily referred to the same embodiment or example. Moreover, the particular features, structures, materials, or characteristics can be combined in any suitable manner in one or more embodiments or examples. Furthermore, the description herein of various embodiments or examples of the present application has been made with reference to the accompanying drawings. However, the description is not intended to limit the application to the particular examples or embodiments described. As such, the scope of the present application is to be interpreted only in conjunction with the appended claims.
[0165] In addition, the terms "first", "second", etc. are used herein only to describe various features, and do not imply relative importance or a number of the features. Thus, a feature defined with "first", "second", etc. can include at least one of the feature. In the description of the present application, the meaning of "a plurality" is at least two, for example, two, three, etc., unless otherwise specifically defined.
[0166] Any processes or methods described in the flow charts or otherwise described herein can be understood as representing code modules, segments, or portions of code that include one or more executable instructions for implementing specific logic functions (or steps) of the processes. It will be understood that the scope of the preferred embodiments of the present application encompasses also other implementations that can not be exactly as described in the flow charts, but which can include fewer, additional, or different steps, performed in a different order, including substantially concurrently or in reverse order, and which can include additional, fewer, or different components.
[0167] The logic and / or steps represented in the flowcharts and / or described herein, for example, can be considered as a sequence of instructions to implement logical functions, and can be embodied in any computer-readable medium for use by an instruction execution system, apparatus, or device, such as a computer-based system, processor- based system, or other system that can fetch the instructions from the instruction execution system, apparatus, or device and execute the instructions. For purposes of this specification, a "computer-readable medium" can be any apparatus that can contain, store, communicate, propagate, or transport the program for use by or in connection with the instruction execution system, apparatus, or device. The computer-readable medium can be a computer- readable storage medium or a computer-readable signal medium. The computer- readable storage medium can be, for example, but not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples (a non-exhaustive list) of the computer-readable storage medium include the following: an electrical connection having one or more wires (electrical connections), a portable computer diskette (a magnetic device), a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, and a portable compact disc read-only memory (CDROM). In addition, the computer-readable medium can even be paper or another suitable medium upon which the program is printed, as the program can be electronically captured, for example, via optical scanning of the paper or other medium, then compiled, interpreted, or otherwise processed in a suitable manner, if necessary, and stored in a computer memory.
[0168] It should be understood that aspects of the application can be implemented in hardware, software, firmware or combinations thereof. In the above embodiments, various steps or methods can be implemented in software or firmware that is stored in memory and executed by a suitable instruction execution system. As such, in some embodiments, specifically configured hardware can be used to implement at least some of the functionality described herein. For example, if implemented in hardware, the hardware can include any or a combination of the following: a discrete logic circuit having logic gates for implementing logic functions upon data signals, an application specific integrated circuit having appropriate combinational logic gates, a programmable gate array (PGA), a field programmable gate array (FPGA), etc.
[0169] Those of skill in the art would understand that information and signals can be represented using any of a variety of technologies and techniques. For example, data, instructions, commands, information, signals, bits, symbols, and chips that can be referenced throughout the above description can be represented by voltages, currents, electromagnetic waves, magnetic fields or particles, optical fields or particles, or any combination thereof.
[0170] In addition, each of the functional units in the various embodiments of the present application can be integrated in one processing module, or each of the units can be physically present separately, or two or more units can be integrated in one module. The integrated module can be realized in the form of hardware or in the form of a software functional module. When the integrated module is realized in the form of a software functional module and sold or used as an independent product, it can also be stored in a computer readable storage medium.
[0171] The storage medium mentioned above can be a read-only memory, a magnetic disk or an optical disk, etc. Although the embodiments of the present application have been shown and described above, it should be understood that the above embodiments are exemplary and should not be construed as limiting the present application, and those skilled in the art can make changes, modifications, replacements and variations to the above embodiments within the scope of the present application.
Claims
1. A risk signaling security protection method, characterized in that, include: Detect whether the received signaling is risky signaling and determine the type of risky signaling detected; In response to the risk signaling being of the type of obtaining sensitive user information signaling, the first response signaling corresponding to the obtaining sensitive user information signaling is intercepted, the first response signaling is desensitized, and the desensitized first response signaling is returned; In response to the risk signaling being of the type of non-acquisition of sensitive user information signaling, the non-acquisition of sensitive user information signaling is intercepted, a second response signaling corresponding to the non-acquisition of sensitive user information signaling is constructed, and the second response signaling is returned; wherein, the first response signaling and the second response signaling after the de-identification process are used to mislead the attacker to perform subsequent attack operations or mislead the attacker's attack perception results.
2. The method as described in claim 1, characterized in that, The signaling for obtaining sensitive user information includes signaling for obtaining information and signaling for illegal location. Determining the type of detected risk signaling includes: Determine whether the risk signaling is a request signaling; In response to the risk signaling being a request signaling, determine whether the request signaling is a signaling that does not directly affect the business or a signaling that directly affects the business. In response to the fact that the request signaling is not directly affecting the service signaling, it is determined whether the not directly affecting the service signaling is the information acquisition signaling.
3. The method as described in claim 2, characterized in that, After determining whether the request signaling is a signaling that does not directly affect the service or a signaling that directly affects the service, the method further includes: In response to the request signaling being a signaling that directly affects services, it is determined whether the signaling that directly affects services is the illegal location signaling.
4. The method as described in claim 1, characterized in that, Before intercepting the first response signaling corresponding to the signaling for obtaining sensitive user information, the method further includes: Release the signaling for obtaining sensitive user information and record the message identifier of the signaling for obtaining sensitive user information, wherein the message identifier includes the TCAP layer source transaction ID identifier in the SS7 signaling protocol or the protocol layer session ID identifier in the Diameter signaling protocol; Determine whether the message identifier of the currently received response signaling matches the recorded message identifier; In response to a message identifier match, the currently received response signaling is determined to be the first response signaling, and the first response signaling is intercepted.
5. The method as described in claim 4, characterized in that, The desensitization process for the first response signaling includes: Replace the sensitive information in the first response signaling with non-sensitive information; Following the first response signaling after the return of the de-identification process, the following is also included: Clear the record information of the message identifier of the first response signaling.
6. The method as described in claim 3, characterized in that, The signaling that does not directly affect services also includes confirmation information signaling, notification information signaling, and configuration operation signaling; the signaling that directly affects services also includes billing fraud signaling, hijacking SMS signaling, hijacking data signaling, denial-of-service signaling, spam SMS signaling, and call interception signaling. Following the return of the second response signaling, the following is also included: In response to the request signaling being the signaling that directly affects the service, determine whether the user identifier and / or source address information in the request signaling is recorded in the gray list; In response to the fact that the user identifier and / or the source address information is not recorded in the gray list, it is determined whether the user identifier and / or the source address information is recorded in the black list; In response to the user identifier and / or the source address information being recorded in the blacklist, the recording time of the user identifier and / or the source address information in the blacklist is updated.
7. The method as described in claim 1, characterized in that, The detection of whether the received signaling is risky signaling includes: The received signaling is sequentially subjected to signaling message protocol consistency protection processing, list-based security risk protection processing, and network model-based security risk protection processing; If any risk is detected in the received signaling during any protection process, the received signaling is determined to be risky signaling.
8. A risk signaling security protection device, characterized in that, include: The detection module is used to detect whether the received signaling is risky signaling and to determine the type of risky signaling detected. The desensitization module is used to respond to the risk signaling type being the signaling to obtain sensitive user information, to intercept the first response signaling corresponding to the signaling to obtain sensitive user information, to perform desensitization processing on the first response signaling, and to return the desensitized first response signaling; The construction module is configured to, in response to the risk signaling being of the type of non-acquiring user sensitive information signaling, intercept the non-acquiring user sensitive information signaling, construct a second response signaling corresponding to the non-acquiring user sensitive information signaling, and return the second response signaling; wherein, the first response signaling and the second response signaling after de-identification processing are used to mislead the attacker to perform subsequent attack operations or mislead the attacker's attack perception results.
9. An electronic device, characterized in that, include: A processor, and a memory communicatively connected to the processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory to implement the method as described in any one of claims 1-7.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the method as described in any one of claims 1-7.
11. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements the method of any one of claims 1-7.