Rail transit signal system network abnormal flow detection method and system

By acquiring network traffic data and electromagnetic signals under different operating conditions in the rail transit signaling system, and combining multi-channel filtering and electromagnetic shielding effectiveness assessment, abnormal traffic can be accurately identified, solving the problem of distinguishing between electromagnetic disturbances and malicious attacks, and improving the accuracy and stability of detection.

CN121396584AActive Publication Date: 2026-01-23BEIJING ITECHSHARE NETWORK INFORMATION TECH CO LTD
View PDF 9 Cites 0 Cited by

Patent Information

Application Number
CN202511499034.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-10-20
Publication Date
2026-01-23
Estimated Expiration
2045-10-20

AI Technical Summary

Technical Problem

Existing technologies struggle to effectively distinguish between physical layer signal distortion caused by electromagnetic disturbances and genuine malicious traffic anomalies, resulting in a high false alarm rate. Furthermore, the false alarm rate increases in scenarios with frequent changes in operating conditions, making it unsuitable for stable detection in complex electromagnetic environments and dynamic operating conditions.

Method used

By acquiring normal network traffic transmission parameter data of core equipment in the rail transit signaling system under different operating conditions, and combining electromagnetic signal data and electromagnetic shielding design standards, a multi-channel signal filtering method is used to filter out electromagnetic interference noise, extract multi-dimensional features, and compare them with normal feature models. Combined with the electromagnetic shielding effectiveness judgment results, the accurate identification of abnormal traffic is achieved.

Benefits of technology

It improves the accuracy of identifying real network anomalies, enhances the system's adaptability to complex electromagnetic environments and dynamic operating conditions, avoids misjudgments during operating condition switching, and improves the reliability and accuracy of detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121396584A_ABST
    Figure CN121396584A_ABST
Patent Text Reader

Abstract

The invention provides a network abnormal flow detection method and system for a rail transit signal system, and relates to the technical field of network flow detection, and the method comprises the steps: determining normal multi-dimensional features under different operation conditions through the obtained normal network flow transmission parameter data of core equipment in the rail transit signal system under different operation conditions; acquiring electromagnetic signal data around the connection port of the core equipment, and determining a judgment result that the electromagnetic shielding effectiveness reaches the standard in combination with the electromagnetic shielding design standard value; performing filtering and feature extraction processing on the network flow signal transmitted by the connection port of the core equipment by adopting a multi-channel signal filtering mode to obtain a real-time multi-dimensional feature; and comparing the characteristics with normal multi-dimensional characteristics to obtain the total number of abnormal types, and judging whether the network flow transmitted by the connection port of the core equipment is abnormal network flow or not by combining an electromagnetic shielding effectiveness standard judgment result, so that cross-layer collaborative accurate identification of the network flow abnormality of the rail transit signal system is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of traffic flow detection technology for rail transit signaling networks, and in particular to a method and system for detecting abnormal traffic flow in rail transit signaling systems. Background Technology

[0002] With the rapid development of urban rail transit networks, the signaling system, as the core component ensuring the safe and efficient operation of trains, faces increasingly prominent cybersecurity issues. Rail transit signaling systems involve several key subsystems, including automatic train monitoring, automatic train protection, and computer interlocking. These systems interact with each other in real time via dedicated networks, demanding extremely high reliability and real-time performance. Any anomalies in network traffic, such as malicious attacks, equipment malfunctions, or sudden increases, delays, or packet losses due to external electromagnetic interference, can directly lead to train delays or even safety accidents. Currently, research and applications for network anomaly detection in rail transit signaling systems tend to employ machine learning-based traffic behavior analysis methods. Existing solutions collect historical normal traffic data, extract statistical features including packet rate, connection frequency, and protocol distribution, construct a behavioral model of normal traffic, and then use algorithms such as support vector machines or isolated forests to classify and identify abnormal traffic deviating from normal patterns. However, these detection methods based on pure traffic behavior modeling still have significant shortcomings in practical applications. Because it only focuses on the statistical characteristics of the network protocol layer, it is difficult to distinguish between signal distortion caused by external electromagnetic disturbances and genuine malicious traffic anomalies, which can easily lead to misjudgment. It does not fully consider the differences in normal traffic baselines of the device under different operating conditions, and lacks refined modeling of traffic patterns under typical operating conditions such as standby, startup, and braking, which leads to an increase in false alarm rate in scenarios with frequent switching of operating conditions. Summary of the Invention

[0003] The purpose of this invention is to provide a method and system for detecting abnormal network traffic in rail transit signaling systems, in order to solve the problems in the prior art, such as the difficulty in effectively distinguishing between physical layer signal distortion caused by electromagnetic environmental disturbances and real malicious traffic anomalies, the high false judgment rate, and the inability to adapt to the stable detection requirements under scenarios with frequent changes in operating conditions.

[0004] This invention provides a method for detecting abnormal network traffic in a rail transit signaling system, comprising: acquiring normal network traffic transmission parameter data of core equipment in the rail transit signaling system under different operating conditions, including standby and working conditions; determining normal multi-dimensional characteristics under different operating conditions based on the normal network traffic transmission parameter data; acquiring electromagnetic signal data around the connection port of the core equipment, and determining the electromagnetic shielding effectiveness compliance judgment result by combining the electromagnetic shielding design standard value of the connection port of the core equipment; using a multi-channel signal filtering method to filter electromagnetic interference noise in the network traffic signal transmitted by the connection port of the core equipment to obtain a filtered signal; extracting data features from the filtered signal to obtain real-time multi-dimensional features; comparing the normal multi-dimensional features with the real-time multi-dimensional features to obtain the total number of abnormal types, and determining whether the network traffic transmitted by the connection port of the core equipment in the rail transit signaling system is abnormal network traffic by combining the electromagnetic shielding effectiveness compliance judgment result.

[0005] The main technical effects of the network abnormal traffic detection method for a rail transit signaling system provided by this invention are as follows: It acquires normal network traffic transmission parameter data of core equipment in the rail transit signaling system under different operating conditions, including standby and working conditions; based on the normal network traffic transmission parameter data, it determines normal multi-dimensional characteristics under different operating conditions; it acquires electromagnetic signal data around the connection port of the core equipment, and, combined with the electromagnetic shielding design standard value of the connection port of the core equipment, determines the electromagnetic shielding effectiveness compliance judgment result; it uses a multi-channel signal filtering method to filter electromagnetic interference noise in the network traffic signal transmitted through the connection port of the core equipment to obtain a filtered signal; it extracts data features from the filtered signal to obtain real-time multi-dimensional characteristics; and it compares the normal multi-dimensional characteristics with the real-time multi-dimensional characteristics. By acquiring normal network traffic transmission parameter data of core equipment under different operating conditions and establishing a multi-dimensional normal feature model accordingly, combined with monitoring of electromagnetic signals around the connection port and comparison with electromagnetic shielding design standards, it is determined whether the current electromagnetic environment meets the conditions for safe transmission. Multi-channel filtering technology is used to effectively suppress electromagnetic interference clutter in the transmitted signal, thereby obtaining a cleaner network traffic signal. The normal multi-dimensional features are compared with the real-time multi-dimensional features to obtain the total number of anomaly types. Combined with the electromagnetic shielding effectiveness compliance judgment result, it is determined whether the network traffic transmitted through the connection port of the core equipment in the rail transit signaling system is abnormal network traffic (i.e., real-time multi-dimensional features are extracted and compared with the normal feature model, and a final judgment is made based on the number of anomaly types and the electromagnetic shielding status). The above implementation process achieves collaborative detection from physical layer interference suppression to protocol layer behavior analysis, which not only improves the accuracy of identifying real network anomalies but also enhances the system's performance in complex electromagnetic environments. The system enhances adaptability and stability under varying magnetic environments and dynamic operating conditions. Furthermore, in practice, it extracts transmission rate, data frame interval, data packet length distribution, and integrity information of key protocol fields from normal traffic data under different time periods. It then constructs normal fluctuation ranges and characteristic patterns for each operating condition, integrating them to form a baseline model of normal behavior encompassing temporal, structural, and semantic dimensions. This modeling approach can precisely depict the differences in network communication behavior of core equipment under different operating states, improving tolerance for non-aggressive traffic fluctuations. This allows the detection system to more accurately distinguish between traffic changes caused by equipment state transitions and potential security threats, avoiding misjudging reasonable communication fluctuations during state transitions as abnormal events. Simultaneously, modeling the structure and relationships of protocol fields enhances the ability to identify spoofed traffic or protocol violations. Without relying on external attack signature databases, it alleviates the high false alarm problem caused by ignoring the operating context in traditional methods. Attached Figure Description

[0006] Figure 1 A flowchart illustrating a method for detecting abnormal network traffic in a rail transit signaling system provided by the present invention; Figure 2 A schematic diagram of a network abnormal traffic detection method for a rail transit signaling system provided by the present invention; Figure 3 This is a schematic diagram of the network abnormal traffic detection system for a rail transit signaling system provided by the present invention. Detailed Implementation

[0007] Research has found that during the operation of rail transit signaling systems, dynamic changes in the external electromagnetic environment can trigger physical layer disturbances in network signals. These disturbances are easily misinterpreted as network attacks in traditional detection mechanisms, leading to increased risk of misjudgment. Furthermore, core equipment exhibits differentiated communication modes under different operating conditions, such as standby, startup, and operation. Existing solutions fail to adequately characterize the traffic flow characteristics boundaries under these normal states and lack the ability to perceive the operational context. Consequently, in scenarios with frequent changes in operating conditions, it is difficult to reliably distinguish between normal fluctuations and abnormal behavior, limiting the reliable application of the detection system in real-world complex environments. This invention introduces normal traffic flow data acquisition and multi-dimensional feature modeling under multiple operating conditions, combined with electromagnetic environment monitoring and shielding effectiveness assessment around connection ports. It collaboratively analyzes network traffic status from both the physical and protocol layers. First, the original signal undergoes multi-channel filtering to suppress interference clutter. Then, the filtered real-time features are extracted and compared with normal features under different operating conditions. Finally, the number of abnormal features and the electromagnetic environment compliance judgment results are fused to achieve accurate identification of abnormal traffic, thereby improving the accuracy of the detection method under complex electromagnetic environments and dynamic operating conditions.

[0008] This invention discloses a method for detecting abnormal network traffic in a rail transit signaling system, comprising: Step 101: acquiring normal network traffic transmission parameter data of core equipment in the rail transit signaling system under different operating conditions, including standby and working conditions. In this step, the rail transit signaling system refers to a dedicated signaling system that ensures the safe and efficient operation of rail transit trains, including subsystems such as automatic train monitoring, automatic train protection, and computer interlocking, used to realize key functions such as train positioning, speed control, and route interlocking, and to achieve real-time data interaction between each subsystem and the core equipment based on a dedicated network. Core equipment refers to equipment in the rail transit signaling system that undertakes core functions of data processing and signal transmission, such as interlocking machines and automatic train protection hosts, used to receive, process, and send network traffic data; its operating status directly affects the reliability of the signaling system. The normal network traffic transmission parameter data refers to the set of network traffic-related parameters generated by the core equipment during normal operation in both standby and working conditions, including data such as transmission rate, data frame interval, data packet length, and protocol fields, collected by dedicated acquisition equipment at a preset cycle, and used to construct a normal traffic characteristic baseline. Standby mode refers to the operating state where core equipment maintains only basic power supply and minimal operation, without transmitting business data such as train positioning and speed control. Under this mode, the network traffic transmission parameters of the core equipment are within a low and stable range. Operating mode refers to the operating state where core equipment transmits business data such as train positioning, speed control, and route interlocking. Under this mode, the network traffic transmission parameters of the core equipment change dynamically with business needs, and should be statistically analyzed within the normal range according to the actual business scenario.

[0009] In this embodiment of the invention, a communication connection is first established with the core equipment of the rail transit signaling system through a dedicated data acquisition device. The acquisition device collects network traffic data sent and received by the core equipment according to a preset acquisition cycle, when the core equipment is in standby mode (i.e., the core equipment only maintains basic power supply and has no business data transmission) and working mode (i.e., the core equipment performs business data transmission such as train positioning and speed control). The data includes parameters such as transmission rate, data frame interval, data packet length, and protocol fields. Finally, the data is summarized to form normal network traffic transmission parameter data.

[0010] Step 102: Determine normal multi-dimensional characteristics under different operating conditions based on normal network traffic transmission parameter data. In this step, normal multi-dimensional characteristics refer to the multi-dimensional normal traffic feature set constructed based on normal network traffic transmission parameter data for standby and operating conditions, including normal transmission rate range, normal data frame interval threshold range, normal data packet length distribution characteristics, and normal protocol field integrity characteristics, which are used as the benchmark for real-time traffic anomaly judgment.

[0011] Step 103: Obtain electromagnetic signal data around the connection port of the core device, and combine it with the electromagnetic shielding design standard value of the connection port of the core device to determine the electromagnetic shielding effectiveness compliance judgment result. In this step, the area around the connection port of the core device refers to the specific area around the physical port (such as an Ethernet port) used by the core device to access the network. This area is susceptible to external electromagnetic environment influences, and electromagnetic signal monitoring points need to be set up here to collect electromagnetic interference data. Electromagnetic signal data refers to the electromagnetic radiation signal data in the area around the connection port of the core device, including the instantaneous peak signal strength and the average signal strength within a period of different monitoring frequency bands. It is collected based on preset electromagnetic signal monitoring points and is used to evaluate the electromagnetic shielding effectiveness. The electromagnetic shielding design standard value refers to the electromagnetic shielding performance standard parameters set during the design phase of the connection port of the core device, including the average allowable electromagnetic signal strength limit and the peak allowable electromagnetic signal strength limit corresponding to each monitoring frequency band, and is used to determine whether the actual electromagnetic shielding effectiveness meets the standard. The electromagnetic shielding effectiveness compliance judgment result refers to the judgment result obtained by comparing the collected electromagnetic signal data with the electromagnetic shielding design standard value. If the electromagnetic signal strength of all monitoring frequency bands does not exceed the standard limit, it is considered compliant; otherwise, it is considered non-compliant. It is used to assist in the judgment of abnormal network traffic.

[0012] Step 104: Employ a multi-channel signal filtering method to filter electromagnetic interference (EMI) noise in the network traffic signal transmitted through the connection port of the core device, obtaining the filtered signal. In this step, the multi-channel signal filtering method refers to dividing the network traffic signal into multiple independent filtering channels based on its frequency characteristics, and setting specific filtering parameters for different channel interference types. This method is used to specifically remove EMI noise from the network traffic signal, avoiding signal distortion caused by single filtering. The network traffic signal refers to the electrical or optical signal containing service data transmitted through the connection port of the core device. This signal is easily affected by the surrounding electromagnetic environment, resulting in EMI noise, and requires filtering before feature extraction. EMI noise refers to the interference signal generated by electromagnetic radiation around the connection port of the core device on the network traffic signal. Its frequency may overlap with the fundamental frequency of the network traffic signal, causing distortion of network traffic parameters, and needs to be removed through filtering. The filtered signal is the pure signal of the network traffic signal after multi-channel signal filtering, removing EMI noise. This signal retains the original service data characteristics of the network traffic and is used for subsequent real-time multi-dimensional feature extraction.

[0013] Step 105: Extract data features from the filtered signal to obtain real-time multi-dimensional features; in this step, real-time multi-dimensional features refer to the set of real-time traffic features extracted from the filtered signal that correspond to normal multi-dimensional features, including real-time transmission rate, real-time data frame interval threshold, real-time data packet length distribution features, and real-time protocol field integrity features, which are used to compare with normal multi-dimensional features to identify anomalies.

[0014] In this embodiment of the invention, a combination of statistical analysis and data parsing is used to extract real-time parameters according to dimensions consistent with normal multi-dimensional characteristics: For the real-time transmission rate, the filtered signal is divided into preset short time segments, and the total number of bytes of data packets transmitted within each time segment is counted. The total number of bytes is divided by the duration of the time segment to obtain the transmission rate value for each time segment, and these rate values ​​are integrated to form the real-time transmission rate; For the real-time data frame interval threshold, the time interval between two adjacent data packets is recorded frame by frame according to the signal transmission time sequence, and the interval with the highest frequency among all intervals is determined as the real-time data frame interval threshold; For the real-time data packet length distribution, a preset length interval consistent with the normal data packet length distribution characteristics is first determined, and the data packets in the filtered signal are parsed packet by packet, the length of each data packet is recorded and assigned to the corresponding preset length interval, and the data is then integrated to form the real-time transmission rate; For the real-time data packet length distribution, a preset length interval consistent with ... is determined, and the data is then parsed packet by packet, packet by packet, and the data is then assigned to the corresponding preset length interval. The number of data packets in each interval is counted, and the number of data packets in each interval is divided by the total number of data packets in all intervals to obtain the real-time proportion of each interval. These proportions are then integrated to form the real-time data packet length distribution. For the real-time protocol field integrity, the protocol structure of the data packets in the filtered signal is analyzed packet by packet. The real-time key protocol fields required for communication of core devices are extracted, and the field bit position, data content (i.e., field bit information) of each real-time key protocol field are recorded, as well as the order of appearance and dependency relationship (i.e., field association relationship) of different real-time key protocol fields in the same data packet. This information is then integrated to form the real-time protocol field integrity. The four types of real-time parameters extracted—real-time transmission rate, real-time data frame interval threshold, real-time data packet length distribution, and real-time protocol field integrity—are combined according to their corresponding dimensions to ensure that each parameter matches the corresponding dimension of the normal multi-dimensional features, ultimately forming real-time multi-dimensional features.

[0015] Step 106: Compare the normal multi-dimensional features with the real-time multi-dimensional features to obtain the total number of anomaly types. Combined with the electromagnetic shielding effectiveness compliance judgment result, determine whether the network traffic transmitted through the connection ports of the core equipment in the rail transit signaling system is abnormal network traffic. In this step, the total number of anomaly types refers to the number of abnormal dimensions counted after comparing the real-time multi-dimensional features with the normal multi-dimensional features dimension by dimension (such as abnormal transmission rate, abnormal data frame interval, etc. are each counted as one anomaly type). This is used to quantify the degree of anomaly in the real-time traffic and assist in the final anomaly judgment.

[0016] This invention constructs a precise baseline by collecting normal flow parameters under multiple operating conditions, and combines electromagnetic shielding effectiveness assessment and multi-channel filtering to achieve accurate determination of abnormal flow. It solves the problem of missing baselines under multiple operating conditions, takes into account electromagnetic interference monitoring and removal, and integrates multi-dimensional features and electromagnetic state determination. It can distinguish between electromagnetic disturbances and malicious anomalies, avoid false alarms during operating condition switching, improve the reliability of network flow detection in the signal system, and ensure train operation safety.

[0017] This invention provides a specific embodiment. Step 102, based on normal network traffic transmission parameter data, determines the normal multi-dimensional characteristics under different operating conditions, specifically including the following steps: Step 201: Extract the standby mode transmission rate set and the working mode transmission rate set from the normal network traffic transmission parameter data to calculate the normal transmission rate fluctuation range under different operating conditions within a preset time-series statistical window. In this step, the standby mode transmission rate set refers to the dataset composed of the transmission rate of each time node extracted from the standby mode period data when the core device is in standby mode, including the transmission rate value of the core device at different time points, used to calculate the normal transmission rate fluctuation range under standby mode. The working mode transmission rate set refers to the dataset composed of the transmission rate of each time node extracted from the working mode period data when the core device is in working mode, including the transmission rate value of the core device at different time points, used to calculate the normal transmission rate fluctuation range under working mode. The preset time-series statistical window refers to a fixed time length interval set for analyzing transmission rate and data frame interval, determined based on the signal transmission cycle of the core device, used to divide data segments to statistically analyze fluctuation range or frequency proportion. The normal transmission rate fluctuation range refers to the range of maximum and minimum transmission rates determined by analyzing the transmission rate set under standby or working conditions within a preset time-series statistical window. It reflects the normal transmission rate boundary of the core device under the corresponding working conditions and is used to determine whether the real-time transmission rate is abnormal.

[0018] Step 202: Extract the standby mode data frame interval set and the working mode data frame interval set from the normal network traffic transmission parameter data to calculate the normal data frame interval threshold range under different operating conditions where the frequency percentage of occurrence within a preset time-series statistical window exceeds a preset percentage threshold. In this step, the standby mode data frame interval set refers to the dataset consisting of the time intervals between adjacent data packets when the core device is in standby mode, including the interval duration of all adjacent data packets, used to calculate the normal data frame interval threshold range. The working mode data frame interval set refers to the dataset consisting of the time intervals between adjacent data packets when the core device is in working mode, including the interval duration of all adjacent data packets, used to calculate the normal data frame interval threshold range. The frequency percentage refers to the ratio of the number of times a certain data frame interval occurs within the preset time-series statistical window to the total number of intervals within that window, obtained based on the statistical occurrence of adjacent data packet intervals, used to filter representative interval ranges. The preset percentage threshold refers to the minimum frequency percentage standard for determining whether a data frame interval is representative, set based on the interval patterns during normal communication of the core device, used to determine the normal data frame interval threshold range. The normal data frame interval threshold range refers to the data frame interval range within the preset time sequence statistics window where the frequency percentage exceeds the preset percentage threshold. It reflects the interval pattern of normal communication of the core equipment under the corresponding operating conditions and is used to determine whether the real-time data frame interval is abnormal.

[0019] Step 203: Extract the set of data packet lengths in the device sending direction and the set of data packet lengths in the device receiving direction from the normal network traffic transmission parameter data, and calculate the proportion of the number of data packets within a preset length interval to the total number of the corresponding set, so as to form the normal data packet length distribution characteristics under different operating conditions. In this step, the set of data packet lengths in the device sending direction refers to the dataset composed of the lengths of all data packets sent by the core device to other devices, including the number of bytes of each sent data packet, used to calculate the normal data packet length distribution characteristics. The set of data packet lengths in the device receiving direction refers to the dataset composed of the lengths of all data packets received by the core device from other devices, including the number of bytes of each received data packet, used to calculate the normal data packet length distribution characteristics. The preset length interval refers to a fixed byte range divided for analyzing the data packet length distribution, set based on the data packet length pattern of normal communication of the core device, used to classify and count the number of data packets. The number of data packets refers to the number of data packets contained in a certain preset length interval, obtained based on the classification and counting of data packet lengths in the sending or receiving direction, used to calculate the proportion. The total number of sets refers to the total number of all data packets in the set of data packet lengths in the device sending or receiving direction, obtained based on the counting of data packets in the set, used to calculate the proportion of each preset length interval. Normal data packet length distribution characteristics refer to the characteristic set composed of the proportion of the number of data packets in different preset length intervals to the total number of corresponding sets. It reflects the data packet length distribution pattern of the core equipment under normal communication under corresponding operating conditions and is used to determine whether the real-time data packet length distribution is abnormal.

[0020] Step 204: Extract the key protocol fields required for network communication by the core device from normal network traffic transmission parameter data. This determines the field bit requirements and inter-field association rules for the key protocol fields, forming the integrity characteristics of normal protocol fields under different operating conditions. Key protocol fields include standby key protocol fields and operational key protocol fields. In this step, key protocol fields refer to protocol-related fields that the core device must include when conducting network communication, including protocol type, device identifier, data verification, and other fields to ensure normal communication. These are extracted from normal network traffic transmission parameter data and used to determine field bit requirements and association rules. Field bit requirements refer to the specifications of the key protocol fields in the data packet, such as their position, length, and allowed value range, including specific requirements for required and optional field bits. These are obtained based on statistical analysis of key protocol fields and used to determine the integrity of real-time protocol fields. Inter-field association rules refer to the patterns of multiple key protocol fields appearing together in the same data packet. These are obtained based on the frequency ratio of common occurrences of statistical fields in the data packet and used to determine whether the association between real-time protocol fields is normal. Normal protocol field integrity features refer to a feature set consisting of the field bit requirements and inter-field association rules of key protocol fields. Divided into standby and operating conditions, these features reflect the protocol field specifications of the core device during normal communication under the corresponding operating conditions, and are used to determine whether the real-time protocol field integrity is abnormal. Standby key protocol fields refer to the key protocol fields required for network communication when the core device is in standby mode. Extracted from the standby protocol data set, they are used to determine the field bit requirements and association rules under standby mode. Operating key protocol fields refer to the key protocol fields required for network communication when the core device is in operating mode. Extracted from the operating protocol data set, they are used to determine the field bit requirements and association rules under operating mode.

[0021] Step 205: Combine the normal transmission rate range, normal data frame interval threshold range, normal data packet length distribution characteristics, and normal protocol field integrity characteristics to obtain normal multi-dimensional characteristics. Step 201: Extract the standby mode transmission rate set and the working mode transmission rate set from the normal network traffic transmission parameter data to calculate the normal transmission rate fluctuation range under different operating conditions within a preset time-series statistical window. Specifically, this includes the following steps: Step 211: Based on the core device's operating status identification information in the normal network traffic transmission parameter data, divide the normal network traffic transmission parameter data into standby mode time period data and working mode time period data. The operating status identification information refers to the mode switching command or mode time period division rule sent by the core device. In this step, the operating status identification information refers to the identification data used to distinguish the operating conditions of the core device, including the mode switching command sent by the core device or the preset mode time period division rule (i.e., the allocation relationship between standby and working mode time periods), obtained based on the core device's operating log or control system settings, used to divide the standby and working mode time period data. Standby mode data refers to normal network traffic transmission parameter data generated when the core device is in standby mode, used to extract parameters such as the standby mode transmission rate set. Operating mode data refers to normal network traffic transmission parameter data generated when the core device is in operating mode, used to extract parameters such as the operating mode transmission rate set. Mode switching command refers to the command signal sent by the core device when switching between standby and operating modes, containing the switching time and target mode information, used to accurately divide mode period data. Mode period division rules refer to preset time interval rules for the core device in standby or operating mode, based on the core device's operating plan, used to divide mode period data when there is no switching command.

[0022] Step 212: Extract the transmission rate of each time node from the standby operating condition data to form a standby operating condition transmission rate set, and extract the transmission rate of each time node from the operating condition data to form an operating condition transmission rate set. In this step, the standby operating condition transmission rate set refers to the ordered dataset composed of the transmission rates of each time node extracted from the standby operating condition data when the core equipment is in standby mode (maintaining only basic power supply and no service data transmission). It includes the transmission rate values ​​of the core equipment at each time point under a preset time sampling interval. It is extracted based on the standby operating condition data and a fixed time sampling interval and arranged in chronological order. It is used to divide the data into segments according to a preset time sequence statistical window, and then calculate the normal transmission rate fluctuation range under standby mode. The working condition transmission rate set refers to the ordered dataset composed of the transmission rate of each time node extracted from the working condition data when the core equipment is in working condition (the state of transmitting business data such as train positioning and speed control). It includes the transmission rate value of the core equipment at each time point under the preset time sampling interval consistent with the standby condition. It is formed by extracting data based on the working condition data and fixed time sampling interval and arranging them in chronological order. It is used to divide the data into segments according to the preset time sequence statistical window, and then calculate the normal transmission rate fluctuation range under the working condition.

[0023] Step 213: Based on the signal transmission cycle of the core device under different operating conditions, set a first preset window duration corresponding to the standby condition and a second preset window duration corresponding to the operating condition. In this step, the signal transmission cycle refers to the fixed time interval for the core device to send signals in standby or operating conditions, set based on the communication protocol of the core device, and used to determine the duration of the preset timing statistics window. The first preset window duration refers to the preset timing statistics window duration set for analyzing the transmission rate in standby conditions, determined based on the signal transmission cycle in standby conditions, and used to divide the standby condition transmission rate set. The second preset window duration refers to the preset timing statistics window duration set for analyzing the transmission rate in operating conditions, determined based on the signal transmission cycle in operating conditions, and used to divide the operating condition transmission rate set.

[0024] Step 214: Divide the standby transmission rate set into multiple standby window data segments according to the first preset window duration, and divide the working transmission rate set into multiple working window data segments according to the second preset window duration. In this step, a standby window data segment refers to multiple subsets of the standby transmission rate set obtained by dividing it according to the first preset window duration. Each subset contains all transmission rate values ​​within its corresponding window and is used to calculate the standby window rate extrema pairs. A working window data segment refers to multiple subsets of the working transmission rate set obtained by dividing it according to the second preset window duration. Each subset contains all transmission rate values ​​within its corresponding window and is used to calculate the working window rate extrema pairs.

[0025] Step 215: Based on the maximum and minimum transmission rates in each standby window data segment and working window data segment, form multiple standby window rate extreme value pairs and working window rate extreme value pairs. In this step, the standby window rate extreme value pair refers to the paired data consisting of the maximum and minimum transmission rates extracted from each standby window data segment, obtained based on the extreme value statistics of each window data segment, and used to determine the normal transmission rate fluctuation range under standby conditions. The working window rate extreme value pair refers to the paired data consisting of the maximum and minimum transmission rates extracted from each working window data segment, obtained based on the extreme value statistics of each window data segment, and used to determine the normal transmission rate fluctuation range under working conditions.

[0026] Step 216: Based on the maximum and minimum standby rates among all standby window rate extreme value pairs, determine the normal transmission rate fluctuation range under standby conditions. Based on the maximum and minimum working rates among all working window rate extreme value pairs, determine the normal transmission rate fluctuation range under working conditions. In this step, the maximum standby rate refers to the largest transmission rate value among all standby window rate extreme value pairs, obtained by statistical analysis of the maximum values ​​of all standby window rate extreme value pairs, and is used to determine the upper limit of the normal transmission rate fluctuation range under standby conditions. The minimum standby rate refers to the smallest transmission rate value among all standby window rate extreme value pairs, obtained by statistical analysis of the minimum values ​​of all standby window rate extreme value pairs, and is used to determine the lower limit of the normal transmission rate fluctuation range under standby conditions. The maximum working rate refers to the largest transmission rate value among all working window rate extreme value pairs, obtained by statistical analysis of the maximum values ​​of all working window rate extreme value pairs, and is used to determine the upper limit of the normal transmission rate fluctuation range under working conditions. The minimum operating rate refers to the minimum transmission rate value among all extreme pairs of operating window rates. It is obtained by statistically analyzing the minimum value of all extreme pairs of operating window rates and is used to determine the lower limit of the normal transmission rate fluctuation range under operating conditions.

[0027] Step 204: Extract the key protocol fields required for network communication by the core device from the normal network traffic transmission parameter data to determine the field bit requirements and inter-field association rules corresponding to the key protocol fields. Specifically, this includes the following steps: Step 221: Based on the operating conditions of the core device, split the normal network traffic transmission parameter data into a standby protocol data set and a working protocol data set, and extract the standby key protocol fields and working key protocol fields from the standby protocol data set and working protocol data set respectively. In this step, the standby protocol data set refers to the set of protocol data transmitted when the core device is in standby mode, obtained by splitting it from the normal network traffic transmission parameter data based on the operating conditions of the core device, and is used to extract the standby key protocol fields. The working protocol data set refers to the set of protocol data transmitted when the core device is in working mode, obtained by splitting it from the normal network traffic transmission parameter data based on the operating conditions of the core device, and is used to extract the working key protocol fields.

[0028] Step 222: Integrate the first field position, first data length, and first allowed value range of the mandatory fields in the standby key protocol fields, and combine them with the first preset omission condition to form the standby mandatory field requirements and standby optional field requirements. In this step, the mandatory field position in the standby key protocol fields refers to the field position that must appear in the standby key protocol fields, determined based on the frequency of field occurrence and communication necessity in the standby protocol data set, and is used to form the standby mandatory field requirements. The first field position refers to the specific position of the mandatory field position in the standby key protocol fields in the data packet, obtained based on the parsing of the standby protocol data set, and is used to standardize the position of the mandatory field. The first data length refers to the data byte length of the mandatory field position in the standby key protocol fields, obtained based on statistics of the standby protocol data set, and is used to standardize the length of the mandatory field. The first allowed value range refers to the effective data value range of the mandatory field position in the standby key protocol fields, obtained based on the analysis of the standby protocol data set, and is used to standardize the value of the mandatory field. The first preset omission condition refers to the condition for determining whether a certain field in the standby critical protocol fields is optional. It is set based on the field's role and occurrence pattern in communication, and is used to distinguish between mandatory and optional standby fields. The mandatory standby field requirements refer to the specifications for the position, length, and value range of mandatory fields in the standby critical protocol fields. These are derived from the integration of the first field position, the first data length, and the first allowed value range, and are used to determine whether the mandatory fields of the real-time standby protocol fields are complete. The optional standby field requirements refer to the specifications for the position, length, and value range of optional fields in the standby critical protocol fields, and are used to determine whether the optional fields of the real-time standby protocol fields conform to the specifications.

[0029] Step 223: Based on the second field position, second data length, and second allowed value range of the mandatory field bits in the critical protocol fields, and combined with the second preset omission condition, the requirements for mandatory field bits and optional field bits are formed. In this step, the mandatory field bits in the critical protocol fields refer to the field positions that must appear in the critical protocol fields, determined based on the frequency of field occurrence and communication necessity in the protocol data set, and used to form the mandatory field bit requirements. The second field position refers to the specific location of the mandatory field bits in the critical protocol fields within the data packet, obtained based on the parsing of the protocol data set, and used to standardize the position of the mandatory field bits. The second data length refers to the data byte length of the mandatory field bits in the critical protocol fields, obtained based on statistics from the protocol data set, and used to standardize the length of the mandatory field bits. The second allowed value range refers to the effective data value range of the mandatory field bits in the critical protocol fields, obtained based on the analysis of the protocol data set, and used to standardize the values ​​of the mandatory field bits. The second preset omission condition refers to the condition for determining whether a certain field in the critical protocol fields is optional. It is set based on the field's role and occurrence pattern in communication, and is used to distinguish between mandatory and optional fields. The mandatory field requirements specify the position, length, and value range of mandatory fields in the critical protocol fields. This is derived from the integration of the second field position, second data length, and second allowed value range, and is used to determine whether the mandatory fields of the real-time protocol fields are complete. The optional field requirements specify the position, length, and value range of optional fields in the critical protocol fields, and are used to determine whether the optional fields of the real-time protocol fields conform to the specifications.

[0030] Step 224: Establish standby association rules between two standby key protocol fields whose frequency share in the same data packet exceeds a preset ratio, and establish work association rules between two working key protocol fields whose frequency share in the same data packet exceeds a preset ratio. In this step, the frequency share refers to the ratio of the number of times two key protocol fields appear together in the same data packet to the total number of data packets, obtained based on statistics of the protocol data set, and used to determine the association rules between fields. The preset ratio refers to the minimum frequency share standard for determining whether an association rule exists between two key protocol fields, set based on the field association patterns during normal communication of the core device, and used to filter valid association rules. The standby association rule refers to the association pattern between two standby key protocol fields whose frequency share in the same data packet exceeds a preset ratio, obtained based on statistics of the standby protocol data set, and used to determine whether the association between real-time standby protocol fields is normal. The work association rule refers to the association pattern between two working key protocol fields whose frequency share in the same data packet exceeds a preset ratio, obtained based on statistics of the working protocol data set, and used to determine whether the association between real-time working protocol fields is normal.

[0031] Step 225: Combine the optional and required field positions of the standby key protocol fields, along with the corresponding standby optional and required field position requirements, with the standby association rules to form the field position requirements and inter-field association rules corresponding to the standby key protocol fields. In this step, the optional field positions of the standby key protocol fields refer to the field positions that may or may not appear in the standby key protocol fields when the first preset omission condition is met. These positions are determined based on the occurrence patterns of fields in the standby protocol data set and are used to form the standby optional field position requirements.

[0032] Step 226: Combine the optional and required field positions of the key work agreement fields, along with the corresponding optional and required field position requirements, with the work association rules to form the field position requirements and inter-field association rules for the key work agreement fields. In this step, the optional field positions of the key work agreement fields refer to the field positions that may or may not appear in the key work agreement fields when the second preset omission condition is met. These positions are determined based on the occurrence patterns of fields in the work agreement data set and are used to form the optional field position requirements.

[0033] In this embodiment of the invention, firstly, step 201 is executed, specifically through the following sub-steps: Execution step: Read the running status identification information attached to each piece of data in the normal network traffic transmission parameter data. If the identification information is a working condition switching command sent by the core device (such as the command containing standby start and working start identification codes), then the data before the switching command is classified as the previous working condition, and the data after the command is classified as the next working condition, using the time point of the switching command as the dividing line. If the identification information is a preset working condition time period division rule (such as pre-setting 00:00-06:00 as the standby time period and 06:00-24:00 as the working time period), then the data is filtered according to this time interval, and finally the standby working condition time period data and the working condition data are obtained. Time period data; Execution step 212: Set a fixed time sampling interval (e.g., every 50 milliseconds as a time node), traverse the standby time period data, read the number of bytes of data transmitted by the core device at each time node, divide the number of bytes by the time sampling interval (unit converted to seconds), calculate the transmission rate value of each time node, arrange all these rate values ​​in chronological order to form a standby transmission rate set; Using the same time sampling interval and calculation method, extract the transmission rate value of each time node from the working time period data, arrange them in chronological order to form a working transmission rate set; Execution step 213: Query the signal transmission cycle of the core device in standby mode (i.e., the core device in... During standby, the basic status signal is sent at fixed intervals (e.g., 1 second). The first preset window duration is set to 10 times the signal transmission cycle (e.g., 10 seconds) to ensure that each window covers multiple signal transmission cycles to reflect rate fluctuations. Then, the signal transmission cycle of the core device under working conditions is queried (e.g., the interval for sending service data every 0.5 seconds during operation). The second preset window duration is set to 10 times the signal transmission cycle (e.g., 5 seconds) to ensure that the window covers multiple transmission cycles. Step 214 is executed: starting from the first rate value of the standby mode transmission rate set, according to the time span corresponding to the first preset window duration (e.g., 10 seconds) (each time node is spaced 50 milliseconds apart, 10 seconds corresponds to...). (Based on 200 time nodes), extract 200 consecutive rate values ​​as a standby window data segment, and extract them sequentially until the entire standby mode transmission rate set is traversed, resulting in multiple standby window data segments; using the same extraction method, according to the time span corresponding to the second preset window duration (e.g., 5 seconds) (corresponding to 100 time nodes), extract 100 consecutive rate values ​​from the working mode transmission rate set as a working window data segment, resulting in multiple working window data segments; then execute step 215: traverse and compare all transmission rate values ​​in each standby window data segment, find the rate value with the largest value and the rate value with the smallest value, and combine these two values ​​into a standby window rate extreme value pair;The transmission rate values ​​in each working window data segment are traversed and compared in the same way to find the maximum and minimum rate values, which are then combined into working window rate extreme value pairs. Then, step 216 is executed: the maximum rate values ​​in all standby window rate extreme value pairs are collected, and these maximum rate values ​​are compared again to find the largest value as the maximum standby rate. At the same time, the minimum rate values ​​in all standby window rate extreme value pairs are collected, and the smallest value is compared to find the smallest value as the minimum standby rate. The interval formed by the maximum standby rate and the minimum standby rate is determined as the normal transmission rate fluctuation range under standby conditions. Using the same method, the maximum working rate and the minimum working rate are found from all working window rate extreme value pairs, and the interval formed by them is used as the normal transmission rate fluctuation range under working conditions. Next, execute step 202: Filter all data packets under standby mode from the normal network traffic transmission parameter data, arrange them in the order of data packet reception time, calculate the difference in reception time between two adjacent data packets to obtain the time interval between each adjacent data packet, and arrange all these interval values ​​in order to form a standby mode data frame interval set; use the same method to filter all data packets under working mode, calculate the time interval between adjacent data packets to form a working mode data frame interval set; then set a preset timing statistics window (e.g., 20 seconds), traverse the standby mode data frame interval set, and count the statistics in each 20-second window. The number of times each interval value appears within the 20-second window (e.g., 15 times at an 80ms interval, 20 times at a 90ms interval, etc.); the frequency percentage of each interval value is calculated, which is the number of times the interval value appears divided by the total number of times all interval values ​​appear within the 20-second window; all interval values ​​whose frequency percentage exceeds a preset percentage threshold (e.g., 60%) are sorted out, and the minimum and maximum values ​​among these interval values ​​are taken to form an interval (e.g., 80ms-100ms) to determine the normal data frame interval threshold range under standby conditions; the same statistical and calculation methods are used to determine the normal data frame interval threshold range under working conditions. Step 203: Filter all data packets sent by the core device to other devices from the normal network traffic transmission parameter data, record the byte length of each sent data packet, and arrange them in order to form a set of data packet lengths in the device sending direction; simultaneously, filter all data packets received by the core device from other devices, record the byte length of each received data packet, and form a set of data packet lengths in the device receiving direction; preset multiple length ranges (such as 0-64 bytes, 65-128 bytes, 129-256 bytes, etc.), traverse the set of data packet lengths in the device sending direction, match the byte length of each data packet with the preset length range, and count the number of data packets contained in each range (e.g., 80 data packets in the 0-64 byte range); calculate the proportion of the number of data packets in each range to the total number of data packets in the set of data packet lengths in the device sending direction; use the same method to count the number and proportion of data packets in the set of data packet lengths in the device receiving direction within each preset length range;By combining standby and operating conditions, the proportion data for both sending and receiving directions are compiled to form the normal data packet length distribution characteristics under different operating conditions.

[0034] Step 204 is implemented through the following sub-steps: Step 221 is executed, which involves first splitting the data into a standby protocol data set (containing all complete protocol data packets under standby conditions) and a working protocol data set (containing all complete protocol data packets under working conditions) based on the operating status identification information in the normal network traffic transmission parameter data; traversing each protocol data packet in the standby protocol data set, parsing the protocol structure of the data packet, and extracting fields that are crucial to communication (such as the device unique identifier field and the basic status feedback field), which are the standby key protocol fields; using the same parsing method, traversing the protocol data packets in the working protocol data set, and extracting fields necessary for business communication (such as train speed characters). The segment and location coordinate fields are used as key protocol fields for operation. Step 222 is executed, which involves traversing each key protocol field in the standby mode, parsing its specific position in the protocol data packet (e.g., starting from the 5th byte of the data packet and ending at the 8th byte, i.e., the first field position is 5-8 bytes), data length (e.g., the field occupies 4 bytes, i.e., the first data length is 4 bytes), and the allowed valid value range of the field (e.g., the device identifier field allows a numeric code of 0001-9999, i.e., the first allowed value range is 0001-9999). The frequency of each field bit in the standby protocol data set is counted. If a certain field bit appears in all data packets (occurrence rate of 100%), it is determined to be a standby field. The required fields in the key protocol fields are combined with their first field position, first data length, and first allowed value range to form the standby required field requirements. If a field only appears in some data packets (e.g., only when the core device communicates with a specific peripheral device), a first preset omission condition is set (e.g., when the core device does not communicate with the specific peripheral device, the field can be omitted). The parameters of the field and the first preset omission condition are combined to form the standby optional field requirements. Step 223: Traverse each working key protocol field and parse its second field position (e.g., the train speed field from byte 10 to byte 13), second data length (e.g., 4 bytes), and second allowed value range in the protocol data packet. (e.g., 0-120km / h); Count the frequency of each field in the working protocol data set, and determine the field with a 100% frequency as the mandatory field in the working key protocol fields, and integrate its parameters to form the working mandatory field requirements; Set a second preset omission condition for field that only appears in some scenarios (e.g., when the train enters the station) (e.g., the field can be omitted when the train is running in the section), and integrate the parameters and conditions to form the working optional field requirements; Execute step 224: Traverse each data packet in the standby protocol data set, record the two standby key protocol fields (e.g., device identification field and basic status feedback field) contained in it at the same time, and count the number of times these two fields appear together in the same data packet;Calculate the ratio of the co-occurrence frequency to the total number of data packets in the standby protocol data set, i.e., the frequency percentage. If the frequency percentage exceeds a preset ratio (e.g., 85%), it is determined that these two fields have a fixed association, and a standby association rule is established (e.g., when the device identifier field appears, the basic status feedback field must also appear). Using the same method, calculate the co-occurrence frequency percentage of each pair of fields in the key working protocol fields. If it exceeds a preset ratio, establish a working association rule (e.g., when the train speed field appears, the position coordinate field must also appear). Execute step 225, that is, connect all the required standby field bits and optional standby field bits of the key standby protocol fields with... The corresponding standby mandatory field requirements and standby optional field requirements are organized and then added to the established standby association rules to ensure that the requirements of each field match the association rules, forming complete field requirements and inter-field association rules for the standby key protocol fields; then, step 226 is executed, first organizing the work-critical protocol fields' mandatory field requirements, work-critical protocol fields' optional field requirements and corresponding requirements, adding work-critical protocol association rules, forming field requirements and inter-field association rules for the work-critical protocol fields; combining standby and work conditions, the above rules are categorized to form the normal protocol field integrity characteristics under different working conditions.

[0035] Finally, step 205 is executed. First, the system is categorized into standby and working conditions. The normal transmission rate fluctuation range, normal data frame interval threshold range, normal data packet length distribution characteristics, and normal protocol field integrity characteristics under standby conditions are integrated together. Then, the normal transmission rate range, normal data frame interval threshold range, normal data packet length distribution characteristics, and normal protocol field integrity characteristics under working conditions are integrated together. This results in normal multi-dimensional features corresponding to both standby and working conditions, ensuring that the feature dimensions under each condition are complete and correspond one-to-one. This embodiment of the invention extracts and integrates four types of features—transmission rate, data frame interval, data packet length, and protocol fields—by different working conditions to construct a refined baseline for normal multi-dimensional features. It considers the differences in traffic patterns under different working conditions, solving the false alarm problem caused by working condition switching; and it integrates protocol field details and statistical characteristics to improve the ability to distinguish abnormal traffic.

[0036] This invention provides a specific embodiment. Step 103 involves acquiring electromagnetic signal data around the connection port of the core device and, in conjunction with the electromagnetic shielding design standard value of the connection port of the core device, determining the electromagnetic shielding effectiveness compliance judgment result. Specifically, this includes the following steps: Step 301: Performing functional checks on multiple electromagnetic signal monitoring points pre-positioned around the connection port of the core device to filter out a list of valid monitoring points. In this step, "around the connection port" refers to a specific area within a certain distance around the physical port (such as an Ethernet port or fiber optic port) used by the core device to access a dedicated network. This area is a critical range where electromagnetic interference easily radiates to the port and affects network traffic signal transmission. The size of the area is determined based on the electromagnetic radiation protection requirements of the core device, and is used to pre-position electromagnetic signal monitoring points to collect surrounding electromagnetic environment data in real time. The list of valid monitoring points refers to an ordered list composed of monitoring points that can normally receive, process, and feed back electromagnetic signal data after performing functional checks on multiple pre-positioned electromagnetic signal monitoring points around the connection port. The validity of the monitoring points is determined based on the stability of their response to standard test signals, and is used for subsequent periodic and accurate collection of electromagnetic signal data around the connection port to avoid data loss or distortion caused by invalid monitoring points.

[0037] In this embodiment of the invention, a standard test electromagnetic signal of preset strength (i.e., the signal frequency covers the possible communication frequency of the core equipment) is sent to each electromagnetic signal monitoring point. It is observed whether each monitoring point can accurately receive the test signal and provide complete signal strength data. If the monitoring point can receive the signal stably and the feedback data is complete and undistorted, the monitoring point is determined to be functioning normally and is included in the list of valid monitoring points. If the monitoring point cannot receive the signal or the feedback data is abnormal, it is determined to be invalid and is not included in the list. Finally, a list of valid monitoring points for subsequent collection of electromagnetic signal data is formed.

[0038] Step 302: Combine the first network communication frequency of the core equipment in standby mode and the second network communication frequency in operating mode into a total network communication frequency range, and divide the total network communication frequency range into multiple monitoring frequency bands. In this step, the first network communication frequency refers to the specific frequency range used by the core equipment in standby mode to transmit basic status signals (such as equipment power supply status and connection status). It is determined based on the communication protocol of the core equipment in standby mode and reflects the frequency characteristics of signal transmission in standby mode. It is used to combine with the communication frequency in operating mode to form the total monitoring range. The second network communication frequency refers to the specific frequency range used by the core equipment in operating mode to transmit business data (such as train positioning data and speed control commands). It is determined based on the communication protocol of the core equipment in operating mode and reflects the frequency characteristics of signal transmission in operating mode. It together with the first network communication frequency constitutes the total network communication frequency range. The total network communication frequency range refers to the complete frequency interval formed by merging the first network communication frequency under the standby condition and the second network communication frequency under the working condition of the core equipment. The minimum value of the first network communication frequency is taken as the lower limit of the interval, and the maximum value of the second network communication frequency is taken as the upper limit of the interval. It is used to cover the signal transmission frequency under all working conditions of the core equipment and to provide a basic range for dividing the monitoring frequency band.

[0039] In this embodiment of the invention, when the first network communication frequency of the core device in standby mode and the second network communication frequency in working mode are combined into a total network communication frequency range, and the total network communication frequency range is divided into multiple monitoring frequency bands, the communication protocol document of the core device is first queried to determine the first network communication frequency (e.g., 100MHz-200MHz) for transmitting basic status signals in standby mode and the second network communication frequency (e.g., 300MHz-500MHz) for transmitting service data in working mode. The minimum value of the first network communication frequency and the maximum value of the second network communication frequency are taken to form a total network communication frequency range from the minimum value of the former to the maximum value of the latter (e.g., 100MHz-500MHz). Then, the total network communication frequency range is evenly divided according to a fixed frequency interval (e.g., every 20MHz is a frequency band) to obtain multiple continuous and non-overlapping monitoring frequency bands (e.g., 100MHz-120MHz, 120MHz-140MHz...480MHz-500MHz).

[0040] Step 303: Set the electromagnetic signal acquisition cycle according to the operating conditions of the core equipment. In this step, the electromagnetic signal acquisition cycle refers to the fixed time interval for the monitoring points in the effective monitoring point list to collect electromagnetic signal data around the connection port. It is set based on the electromagnetic environment stability under different operating conditions of the core equipment (longer cycle for standby mode, shorter cycle for working mode) and is used to periodically acquire electromagnetic signal data to ensure timely capture of changes in the electromagnetic environment.

[0041] In this embodiment of the invention, the core device only intermittently sends basic status signals during standby mode, and the electromagnetic environment is relatively stable. Therefore, the electromagnetic signal acquisition cycle is set to a relatively long time interval (e.g., 10 seconds / time). During working mode, the core device needs to continuously send service data, and the electromagnetic environment may fluctuate due to changes in service volume. Therefore, the electromagnetic signal acquisition cycle is set to a relatively short time interval (e.g., 2 seconds / time) to ensure that the acquisition cycle can cover the changes in the electromagnetic environment under working conditions while avoiding unnecessary redundant acquisition.

[0042] Step 304: Using the effective monitoring point list, collect electromagnetic signal data around the connection port according to the electromagnetic signal acquisition cycle. The electromagnetic signal data includes the instantaneous peak signal strength and the average signal strength within each monitoring frequency band. In this step, the instantaneous peak signal strength refers to the maximum value of the electromagnetic signal strength within a certain monitoring frequency band collected by the electromagnetic signal monitoring point within one electromagnetic signal acquisition cycle. It is obtained by filtering the signal strength data continuously sampled within the cycle and reflects the instantaneous strongest degree of electromagnetic interference in that frequency band within that cycle, used to evaluate the peak resistance capability of the shielding effectiveness. The average signal strength within the cycle refers to the average value of all sampled signal strengths within a certain monitoring frequency band collected by the electromagnetic signal monitoring point within one electromagnetic signal acquisition cycle. It is calculated by dividing the sum of all sampled strengths within the cycle by the number of samples, reflecting the average level of electromagnetic interference in that frequency band within that cycle, used to evaluate the continuous resistance capability of the shielding effectiveness.

[0043] Step 305: The instantaneous peak signal strength with the largest value within each monitoring frequency band of the same electromagnetic signal acquisition period is taken as the peak characteristic value of the electromagnetic environment for the corresponding monitoring frequency band. The arithmetic mean of the average signal strength within each monitoring frequency band of the same electromagnetic signal acquisition period is taken as the average characteristic value of the electromagnetic environment for the corresponding monitoring frequency band. In this step, the peak characteristic value of the electromagnetic environment refers to the maximum value among the instantaneous peak signal strengths collected by all effective monitoring points within a certain monitoring frequency band within the same electromagnetic signal acquisition period. It is obtained by comparing and filtering the peak data from multiple monitoring points within the same frequency band, reflecting the worst peak state of the electromagnetic environment in that frequency band within that period, and is used to compare with the peak allowable limit to determine the shielding effectiveness. The average characteristic value of the electromagnetic environment refers to the arithmetic mean of the average signal strength within a certain monitoring frequency band collected by all effective monitoring points within the same electromagnetic signal acquisition period. It is calculated by dividing the sum of the average strengths within the period of all monitoring points in the same frequency band by the number of monitoring points, reflecting the overall average state of the electromagnetic environment in that frequency band within that period, and is used to compare with the average allowable limit to determine the shielding effectiveness.

[0044] In this embodiment of the invention, the electromagnetic signal acquisition cycles are grouped, and the instantaneous peak signal intensities of the same monitoring frequency band collected by all monitoring points within the same cycle are compared. The instantaneous peak signal intensity with the largest value is selected and determined as the peak characteristic value of the electromagnetic environment of the monitoring frequency band within the cycle. The average signal intensities of the same monitoring frequency band within the same cycle are added together and then divided by the number of monitoring points that provide the average intensity of the frequency band to obtain the average characteristic value of the electromagnetic environment of the monitoring frequency band within the cycle, ensuring that each monitoring frequency band has a unique peak and average characteristic value in each cycle.

[0045] Step 306: Obtain the electromagnetic shielding design standard values ​​for the connection ports of the core equipment. These values ​​include the average permissible electromagnetic signal strength limit and the peak permissible electromagnetic signal strength limit for each monitoring frequency band. In this step, the average permissible electromagnetic signal strength limit refers to the maximum permissible average electromagnetic signal strength value set for each monitoring frequency band in the electromagnetic shielding design standard of the core equipment's connection ports. Determined based on the electromagnetic compatibility design requirements of the core equipment, it is used to determine whether the collected average characteristic values ​​of the electromagnetic environment are within a safe range and is one of the key bases for achieving shielding effectiveness. The peak permissible electromagnetic signal strength limit refers to the maximum permissible instantaneous peak electromagnetic signal strength value set for each monitoring frequency band in the electromagnetic shielding design standard of the core equipment's connection ports. Determined based on the electromagnetic impulse protection requirements of the core equipment, it is used to determine whether the collected peak characteristic values ​​of the electromagnetic environment are within a safe range and is one of the key bases for achieving shielding effectiveness.

[0046] In this embodiment of the invention, the design manual of the core equipment or the technical specification document provided by the manufacturer is retrieved. The document will clearly indicate the shielding performance standard set by the connection port to resist electromagnetic interference. According to the previously divided multiple monitoring frequency bands, the maximum allowable average electromagnetic signal strength (i.e., the average allowable electromagnetic signal strength limit) and the maximum allowable instantaneous electromagnetic signal strength (i.e., the peak allowable electromagnetic signal strength limit) corresponding to each frequency band are extracted from the document. After sorting, a complete electromagnetic shielding design standard value is formed to ensure that the limit of each monitoring frequency band can correspond to the specific standard.

[0047] Step 307: Compare the peak and average electromagnetic environment characteristic values ​​of each monitoring frequency band with the corresponding electromagnetic shielding design standard values ​​to determine whether the electromagnetic shielding effectiveness of the core equipment connection port meets the standard, and generate an electromagnetic shielding effectiveness compliance determination result. In this embodiment of the invention, each monitoring frequency band is compared separately: if the peak electromagnetic environment characteristic value of the frequency band is less than or equal to the corresponding peak allowable electromagnetic signal strength limit, and the average electromagnetic environment characteristic value is less than or equal to the corresponding average allowable electromagnetic signal strength limit, then the shielding effectiveness of the frequency band is determined to meet the standard; if the peak characteristic value of any frequency band exceeds the peak limit, or the average characteristic value exceeds the average limit, then the shielding effectiveness of the frequency band is determined to be substandard; only when all monitoring frequency bands meet the standard is the overall electromagnetic shielding effectiveness of the core equipment connection port determined to meet the standard, otherwise it is determined to be substandard, and finally, a compliance or non-compliance electromagnetic shielding effectiveness compliance determination result is generated. This invention ensures accurate electromagnetic data acquisition by screening effective monitoring points, merging operating condition communication frequencies to form a comprehensive monitoring range, setting the acquisition cycle according to operating conditions to adapt to environmental fluctuations, and combining peak and average characteristic values ​​with standard values ​​to accurately determine the shielding effectiveness of connection ports. This avoids errors caused by invalid monitoring points and single-dimensional judgments, providing a reliable environmental basis for distinguishing between electromagnetic interference and actual traffic anomalies, and improving the accuracy of network anomaly detection in rail transit signaling systems.

[0048] The present invention provides a specific embodiment. Step 104 involves using a multi-channel signal filtering method to filter the electromagnetic interference noise in the network traffic signal transmitted through the connection port of the core device to obtain the filtered signal. Specifically, the steps include: Step 401: Collecting the basic frequency range of the network traffic signal transmitted through the connection port of the core device under different operating conditions, and the characteristic frequency range of the electromagnetic interference noise.

[0049] In this step, the fundamental frequency range refers to the main frequency interval covered by the network traffic signals transmitted through the connection port of the core equipment under different operating conditions such as standby and operation. It is obtained based on frequency analysis of the network traffic signals under different operating conditions, reflecting the frequency distribution characteristics of the network traffic signals. This range is used for comparison with the characteristic frequency range of electromagnetic interference (EMI) clutter, providing a basis for subsequent filtering frequency band division. The characteristic frequency range refers to the typical frequency interval covered by EMI clutter present around the connection port of the core equipment. It is obtained based on equipment technical documentation or on-site electromagnetic environment monitoring, reflecting the frequency distribution pattern of EMI. This range is used for comparison with the fundamental frequency range to identify frequency bands susceptible to interference.

[0050] In this embodiment of the invention, a frequency analysis tool is connected to the connection port of the core device. In standby mode (transmitting only basic status signals) and working mode (transmitting service data), network traffic signals are continuously collected and their frequency distribution is analyzed to determine the frequency range in which the signals are mainly concentrated. This range is the basic frequency range. At the same time, by searching the technical documents provided by the core device manufacturer, the typical frequency range of electromagnetic interference clutter generated by common electromagnetic interference sources (such as power supply equipment and wireless equipment) around the device is obtained, or the frequency distribution when interference occurs is recorded by on-site monitoring. This range is the characteristic frequency range of electromagnetic interference clutter, ensuring that the interference-related frequency bands can be identified by comparing the two.

[0051] Step 402: Compare the base frequency range with the characteristic frequency range to identify the interference-related frequency bands and pure signal frequency bands within the base frequency range. Based on the number and frequency span of the interference-related frequency bands and the pure signal frequency bands, divide the base frequency range into multiple filter frequency bands. Each filter frequency band corresponds to either an interference-related frequency band or a pure signal frequency band, and corresponds to one filter channel. In this step, the interference-related frequency band refers to the frequency interval within the base frequency range that overlaps with the characteristic frequency range, identified based on a comparison of the two frequency bands. Network traffic signals within this interval are susceptible to electromagnetic interference clutter, and are used to set strict filtering parameters to achieve precise clutter suppression. The pure signal frequency band refers to the frequency interval within the base frequency range that does not overlap with the characteristic frequency range, identified based on a comparison of the two frequency bands. Network traffic signals within this interval are not easily affected by electromagnetic interference clutter, and are used to set lenient filtering parameters to avoid distortion of the effective signal. The number of frequency bands refers to the total number of interference-related frequency bands and pure signal frequency bands, obtained based on the statistical classification of frequency bands within the basic frequency range. It is used to determine the required number of filtering channels, ensuring that each frequency band has a corresponding processing channel. The frequency span refers to the difference between the upper and lower limits of a single frequency band, obtained based on the frequency range measurement of each interference-related or pure signal frequency band. It is used to determine the width of the frequency band and provide a reference for dividing the specific range of filtering frequency bands. A filtering frequency band refers to an independent frequency interval obtained by dividing the basic frequency range into interference-related and pure signal frequency bands. Each interval contains only one type of frequency band (interference-related or pure signal), obtained based on the number of frequency bands and the frequency span. It is used to correspond one-to-one with filtering channels to achieve segmented processing. A filtering channel refers to an independent signal processing unit used to perform clutter processing on the channel signal corresponding to a single filtering frequency band. Each filtering channel corresponds to one filtering frequency band, obtained based on the number of frequency bands, and is used to process the corresponding frequency band signal according to specific parameters, improving the accuracy of clutter suppression.

[0052] In this embodiment of the invention, the frequency bands of the two frequency ranges are compared one by one: if a frequency band in the base frequency range overlaps with the characteristic frequency range (i.e., the frequency band is susceptible to interference), it is marked as an interference-related frequency band; if a frequency band in the base frequency range does not overlap with the characteristic frequency range (i.e., the frequency band is not susceptible to interference), it is marked as a pure signal frequency band; then, the total number of interference-related frequency bands and pure signal frequency bands is counted, the frequency span of each frequency band (the difference between the upper and lower limits of the frequency band) is measured, and the base frequency range is divided into multiple consecutive filter frequency bands according to the principle of one filter channel per frequency band. Each filter frequency band contains only one type of frequency band (interference-related or pure signal), and an independent filter channel is assigned to each filter frequency band to ensure that subsequent targeted processing is possible.

[0053] Step 403: Based on the operating conditions of the core equipment and the filtering frequency band, set the channel filtering parameters for each filtering channel. In this step, the channel filtering parameters refer to the specific parameters (such as cutoff frequency and attenuation coefficient) set for each filtering channel for clutter suppression and signal preservation. These parameters are determined based on the operating conditions of the core equipment and the filtering frequency band type (interference-related or pure signal) and are used to guide the filtering channels to process signals in a targeted manner, balancing clutter removal effectiveness with signal integrity.

[0054] In this embodiment of the invention, the adaptation requirements of different operating conditions and filtering frequency bands are analyzed: Under standby conditions, the network traffic signal is relatively stable, and the channel filtering parameters of the interference-related frequency band need to be more stringent (such as setting a lower clutter cutoff frequency and a higher clutter attenuation) to completely suppress interference; Under operating conditions, the network traffic signal needs to ensure real-time performance, and the parameters of the interference-related frequency band can be appropriately relaxed (such as adjusting the cutoff frequency to reduce signal delay), while the channel filtering parameters of the pure signal frequency band are based on the principle of preserving the original signal (such as setting a higher cutoff frequency and a lower attenuation) to avoid signal distortion; Finally, specific channel filtering parameters (such as cutoff frequency and attenuation coefficient) are determined for each filtering channel to ensure that the parameters match the operating conditions and frequency band characteristics.

[0055] Step 404: Obtain the network traffic signal transmitted through the connection port of the core device. Based on the frequency range of each filter band, decompose the network traffic signal into multiple sub-channel signals. In this step, the sub-channel signal refers to the sub-signal obtained by splitting the complete network traffic signal transmitted through the connection port of the core device according to the frequency range of the filter band. Each sub-signal corresponds to a filter band and is obtained based on signal decomposition processing. It is used to input the corresponding filter channel for specific processing.

[0056] In this embodiment of the invention, the complete network traffic signal transmitted through the connection port of the core device is acquired in real time by a signal acquisition device; then, a signal decomposition tool is used to split the complete network traffic signal into multiple sub-signals according to the frequency range of each previously divided filter band: the signal components whose frequency falls within a certain filter band range are separated to form the sub-signals corresponding to that frequency band. Each sub-signal is a sub-channel signal, and each sub-channel signal corresponds one-to-one with a filter channel, providing objects for subsequent sub-channel processing.

[0057] Step 405: Transmit each sub-channel signal to its corresponding filtering channel. Based on the channel filtering parameters of each filtering channel, perform clutter suppression and interference removal processing on the sub-channel signals to obtain the processed sub-channel signals. In this step, the processed sub-channel signal refers to the signal obtained after the sub-channel signal has been processed by the corresponding filtering channel according to the channel filtering parameters. This signal has removed electromagnetic interference clutter from the corresponding frequency band, retaining the effective network traffic signal components. It is obtained based on clutter suppression processing and is used for subsequent integration into a complete filtered signal.

[0058] In this embodiment of the invention, each sub-channel signal is input to its corresponding filtering channel. For the filtering channel corresponding to the interference-related frequency band, electromagnetic interference clutter in the sub-channel signal is suppressed according to the channel filtering parameters (e.g., filtering out clutter components exceeding the cutoff frequency and reducing the intensity of clutter signals). For the filtering channel corresponding to the pure signal frequency band, the effective components in the signal are retained according to the parameters, and only a very small amount of accidentally mixed clutter is removed. After each filtering channel is processed, the output signal is the sub-channel processed signal, ensuring that the target interference has been removed from the signal.

[0059] Step 406: Based on the frequency range corresponding to each sub-channel signal, integrate the sub-channel processed signals according to the original frequency order of the network traffic signals to obtain the filtered signal. In this step, the original frequency order of the network traffic signals refers to the natural arrangement order of each frequency component from low to high (or from high to low) in the complete network traffic signal transmitted through the core device connection port. This arrangement is used to maintain the signal structure consistent with the original when integrating the sub-channel processed signals, thus avoiding signal disorder.

[0060] In this embodiment of the invention, the frequency range of the filtered frequency band corresponding to the processed signal of each sub-channel is recorded to clarify the frequency position of each processed signal in the original network traffic signal; then, according to the original frequency order of the network traffic signal (from low frequency to high frequency, or from high frequency to low frequency, consistent with the original signal), all processed signals of the sub-channel are spliced ​​together in sequence: first, the processed signal of the lowest frequency band is placed, and then the processed signals of other frequency bands are superimposed in ascending order of frequency to finally form a complete and continuous signal, which is the filtered signal, and its frequency structure is consistent with the original network traffic signal, only removing electromagnetic interference noise.

[0061] This invention achieves targeted removal of electromagnetic interference clutter by identifying interference and pure signal bands in different frequency bands, setting filtering parameters according to operating conditions, and accurately processing and integrating them in different channels. This avoids signal distortion caused by excessive filtering in pure signal bands and suppresses interference-related frequency band clutter. It solves the problem that traditional filtering easily damages signal integrity, lays the foundation for subsequent extraction of accurate real-time multi-dimensional features, and improves the reliability of network anomaly detection in rail transit signaling systems.

[0062] This invention provides a specific embodiment, such as... Figure 2 As shown, step 106 compares the normal multi-dimensional features and the real-time multi-dimensional features to obtain the total number of abnormal types. Combined with the electromagnetic shielding effectiveness compliance judgment result, it is determined whether the network traffic transmitted at the connection port of the core equipment in the rail transit signaling system is abnormal network traffic. Specifically, it includes the following steps: Step 1061: Compare the real-time transmission rate of different working conditions in the real-time multi-dimensional features with the corresponding normal transmission rate range in the normal multi-dimensional features to identify abnormal transmission rates.

[0063] In this step, the real-time transmission rate under different operating conditions refers to the real-time transmission rate value extracted from the filtered signal by the core device under different operating conditions such as standby or operation. This value is extracted based on real-time multi-dimensional features categorized by operating condition and reflects the real-time transmission speed of network traffic under the current operating condition. It is used to compare with the normal transmission rate range to identify whether the transmission rate deviates from the normal level. The normal transmission rate range refers to the interval consisting of the maximum and minimum transmission rate values ​​calculated by the core device under different operating conditions based on normal network traffic transmission parameter data. It is part of the normal multi-dimensional features and reflects the normal transmission rate boundary under the corresponding operating condition, serving as a benchmark for determining whether the real-time transmission rate under different operating conditions is abnormal. Abnormal transmission rate refers to the state where the real-time transmission rate under different operating conditions falls outside the normal transmission rate range for the corresponding operating condition. This reflects that the current network traffic transmission speed deviates from the normal level and is an important component of the total number of abnormal types.

[0064] In this embodiment of the invention, the current operating condition (standby or working) of the core device is determined, and the real-time transmission rate corresponding to the current operating condition is extracted from the real-time multi-dimensional features. At the same time, the normal transmission rate range corresponding to the current operating condition is extracted from the normal multi-dimensional features. If the real-time transmission rate falls outside the normal transmission rate range (e.g., the real-time rate is lower than the lower limit of the range or higher than the upper limit of the range), an abnormal transmission rate is recorded. If it falls within the range, the transmission rate is determined to be normal, and no abnormality is recorded.

[0065] Step 1062: Compare the real-time data frame interval thresholds for different operating conditions in the real-time multi-dimensional features with the corresponding normal data frame interval threshold range in the normal multi-dimensional features to identify abnormal data frame intervals. In this step, the real-time data frame interval thresholds for different operating conditions refer to the typical thresholds of the current data frame interval extracted from the real-time multi-dimensional features under different operating conditions of the core device. These thresholds are obtained based on statistics of real-time data frame intervals and reflect the actual state of the data frame interval under the current operating conditions. They are used to compare with the normal data frame interval threshold range to identify anomalies. The normal data frame interval threshold range refers to the range of data frame intervals where the frequency exceeds a preset threshold, obtained from statistics of normal network traffic transmission parameter data under different operating conditions of the core device. This range is part of the normal multi-dimensional features and reflects the normal data frame interval pattern under the corresponding operating conditions. It is used to determine whether the real-time data frame interval threshold is abnormal. Data frame interval anomaly refers to a state in which the real-time data frame interval threshold for different operating conditions falls outside the normal data frame interval threshold range for the corresponding operating condition. It is determined based on the comparison results between the real-time threshold and the normal range, reflecting the deviation of the current data frame interval from the normal pattern, and is a component of the total number of anomaly types.

[0066] In this embodiment of the invention, based on the current operating condition of the core equipment, real-time data frame interval thresholds for different operating conditions under the current operating condition are extracted from real-time multi-dimensional features, and normal data frame interval threshold ranges corresponding to the current operating condition are extracted from normal multi-dimensional features. If the real-time data frame interval threshold is not within the normal data frame interval threshold range, a data frame interval anomaly is recorded; if it is within the range, the data frame interval is determined to be normal, and no anomaly is recorded.

[0067] Step 1063: Extract the corresponding normal proportion within a preset length interval from the normal data packet length distribution feature in the normal multi-dimensional features, and extract the corresponding real-time proportion within a preset length interval from the real-time data packet length distribution feature in the real-time multi-dimensional features. If the difference between the normal proportion and the real-time proportion in at least one preset length interval exceeds the preset proportion deviation allowable range, record the data packet length distribution as abnormal. In this step, the normal data packet length distribution feature refers to the set of proportions of the number of data packets within each preset length interval to the total number of data packets, statistically analyzed based on normal network traffic transmission parameter data under different operating conditions of the core device. It is part of the normal multi-dimensional features, reflecting the normal data packet length distribution pattern under the corresponding operating conditions, and is used to extract the normal proportion as a comparison benchmark. The preset length interval refers to a fixed byte range pre-divided for statistical data packet length distribution. It is set based on the data packet length pattern of normal communication of the core device and is used to unify the statistical dimensions of normal and real-time data packet length distribution to ensure the consistency of proportion comparison. The normal percentage refers to the ratio of the number of data packets within a preset length interval extracted from the normal data packet length distribution characteristics to the total number of data packets under the corresponding operating conditions. It is obtained based on normal network traffic parameters and is used to compare with the real-time percentage to determine whether the data packet length distribution is abnormal. The real-time data packet length distribution characteristics refer to the set of ratios of the number of data packets within each preset length interval to the total number of data packets under the current operating conditions of the core equipment, extracted from the filtered signal. It is part of the real-time multi-dimensional characteristics and reflects the actual distribution state of the current data packet length. It is used to extract the real-time percentage for anomaly detection. The real-time percentage refers to the ratio of the number of data packets within a preset length interval extracted from the real-time data packet length distribution characteristics to the total number of data packets under the current operating conditions. It is obtained based on real-time network traffic signals and is used to calculate the difference with the normal percentage to determine whether the data packet length distribution is abnormal. The preset percentage deviation allowable range refers to the maximum range within which the normal percentage and real-time percentage are allowed to differ. It is set based on the percentage fluctuation pattern during normal operation of the core equipment and is used to determine whether the percentage difference exceeds a reasonable range. It is a key standard for determining abnormal data packet length distribution. Abnormal data packet length distribution refers to a state in which the difference between the normal proportion and the real-time proportion of at least one preset length interval exceeds the preset allowable deviation range. It is determined based on the comparison result of the proportion difference and the allowable range, reflecting that the current data packet length distribution deviates from the normal pattern, and is a component of the total number of abnormal types.

[0068] In this embodiment of the invention, a preset length range (such as 0-64 bytes, 65-128 bytes, etc.) consistent with the normal data packet length distribution characteristics is determined. The normal proportion corresponding to each preset length range is read from the normal data packet length distribution characteristics, and the real-time proportion corresponding to each preset length range is read from the real-time data packet length distribution characteristics. The difference between the normal proportion and the real-time proportion in each range is calculated (the larger value is subtracted from the smaller value). If the difference in any range exceeds the preset proportion deviation allowable range, a data packet length distribution anomaly is recorded. If the differences in all ranges are within the range, the feature is determined to be normal, and no anomaly is recorded.

[0069] Step 1064: Extract the field bit information and field association relationships of real-time key protocol fields from the real-time protocol field integrity features in the real-time multi-dimensional features. If the field bit information of the real-time key protocol fields does not meet the field bit requirements corresponding to the key protocol fields in the normal multi-dimensional features, or if the field association relationships do not meet the field association rules, then record a protocol field integrity anomaly. In this step, the real-time protocol field integrity features refer to the set of field bit information and field association relationships of real-time key protocol fields extracted from the filtered signal under the current operating conditions of the core equipment. It is part of the real-time multi-dimensional features, reflecting the integrity and association status of the current protocol fields, and is used to compare with normal features to identify anomalies. Real-time key protocol fields refer to the protocol fields (such as device identifiers and data verification fields) that the core equipment must rely on for network communication under the current operating conditions. They are extracted from the real-time protocol field integrity features and reflect the core protocol elements required for current communication, used to parse the field bit information and association relationships. Field bit information refers to the specific position, data length, and value of the real-time key protocol fields in the data packet. It is parsed from the real-time protocol field integrity features and reflects the structural details of the protocol fields, used to compare with the field bit requirements in normal features. Field correlation refers to the co-occurrence pattern of different real-time key protocol fields in the same data packet (e.g., the appearance of one field always indicates the appearance of another field). Extracted from the real-time protocol field integrity features, it reflects the normal correlation logic between protocol fields and is used for comparison with the field correlation rules in normal features. Protocol field integrity anomalies refer to the state where the field bit information of real-time key protocol fields does not meet normal field bit requirements, or the field correlation does not conform to normal field correlation rules. Determined based on the comparison results of protocol field-related information with normal features, it reflects structural or correlation defects in the current protocol field and is a component of the total number of anomaly types. In this embodiment of the invention, the field bit information (such as field position, data length, and value) and field association relationships (such as co-occurrence patterns between fields) of real-time key protocol fields are parsed from the real-time protocol field integrity features. The field bit information is compared with the field bit requirements corresponding to the key protocol fields under the same working conditions in the normal multi-dimensional features, and the field association relationships are compared with the field association rules in the normal multi-dimensional features. If any comparison fails (such as incorrect field position, value out of range, or field association not conforming to the rules), a protocol field integrity anomaly is recorded. If both comparisons pass, the feature is determined to be normal, and no anomaly is recorded.

[0070] Step 1065: Count the total number of anomaly types, including abnormal transmission rate, abnormal data frame interval, abnormal data packet length distribution, and abnormal protocol field integrity. In this step, the total number of anomaly types refers to the sum of the number of records for the four anomaly types: abnormal transmission rate, abnormal data frame interval, abnormal data packet length distribution, and abnormal protocol field integrity. This reflects the number of deviations between real-time characteristics and normal characteristics, and is used to determine the traffic status in conjunction with electromagnetic shielding results. In this embodiment of the invention, the anomaly types recorded in the first four steps (abnormal transmission rate, abnormal data frame interval, abnormal data packet length distribution, and abnormal protocol field integrity) are integrated. Each recorded anomaly type is counted as 1 type, and unrecorded anomalies are counted as 0 types. The recording results for the four anomaly types are added together (e.g., if 2 anomalies are recorded, the total is 2) to obtain the total number of anomaly types, ensuring that the total number reflects the number of deviations between the current real-time characteristics and normal characteristics.

[0071] Step 1066: If the electromagnetic shielding effectiveness compliance determination result is non-compliant, and the total number of abnormal types is not zero, then the network traffic transmitted through the core device connection port is determined to be abnormal network traffic. If the electromagnetic shielding effectiveness compliance determination result is compliant, and the total number of abnormal types is greater than or equal to the preset abnormal number, then it is determined to be abnormal network traffic. If the electromagnetic shielding effectiveness compliance determination result is compliant, and the total number of abnormal types is less than the preset abnormal number, then it is determined to be normal network traffic. In this step, normal network traffic refers to network traffic transmitted through the core device connection port whose real-time multi-dimensional characteristics deviate from normal multi-dimensional characteristics within a reasonable range (electromagnetic shielding compliant and the total number of abnormal types < the preset abnormal number), reflecting that the current network traffic conforms to normal communication patterns and ensuring the stable operation of the signal system. In this embodiment of the invention, based on the electromagnetic shielding effectiveness compliance determination result (compliant or non-compliant), combined with a preset number of anomalies (e.g., 2 types); if the determination result is non-compliant and the total number of anomaly types is not 0, i.e., ≥1, then it is determined to be abnormal network traffic; if the determination result is compliant and the total number of anomaly types is ≥ the preset number of anomalies, then it is determined to be abnormal network traffic; if the determination result is compliant and the total number of anomaly types is < the preset number of anomalies, then it is determined to be normal network traffic, and finally a clear traffic anomaly determination result is output. This embodiment of the invention accurately identifies anomaly types such as transmission rate and data frame interval by comparing multi-dimensional features one by one, and outputs traffic status according to different scenarios based on the electromagnetic shielding effectiveness determination result: when electromagnetic shielding is non-compliant, a small number of anomalies are determined to be anomalies; when compliant, the severity is distinguished according to a preset number, avoiding misjudgment due to a single feature and environmental interference, taking into account differences in operating conditions and protocol integrity requirements, improving the reliability of network anomaly detection in rail transit signaling systems, and ensuring that traffic determination is consistent with actual operating scenarios.

[0072] Furthermore, based on the above-provided solution, the following is an analysis of the main shortcomings of step 106 and its sub-steps: The normal transmission rate range and normal data frame interval threshold range used in the solution are all static thresholds calculated based on historical data. However, the network load fluctuations of the rail transit signaling system may cause the static thresholds to become invalid, leading to misjudgments (such as misjudging normal fluctuations as abnormalities or missing new types of abnormalities). In the original solution of the above embodiment, steps 1061 and 1062 use static thresholds for comparison: Step 1061: Compare the real-time transmission rate with the normal transmission rate range. Step 1062: Compare the real-time data frame interval threshold with the normal data frame interval threshold range. These normal ranges are static values ​​calculated based on historical data and do not consider the real-time fluctuations of network load.

[0073] To overcome the dependence on static thresholds, the processing method in this embodiment introduces dynamic thresholds, which are adjusted according to the current network load. Network load fluctuations can affect the normal range of transmission rate and data frame interval; therefore, this embodiment defines a dynamic threshold formula that includes a network load factor. This embodiment adds a new step to calculate the dynamic thresholds instead of using static thresholds. This new step should precede steps 1061 and 1062, as steps 1061 and 1062 require the dynamic thresholds.

[0074] Specifically: A new step 1060 is added: Calculate the dynamic threshold based on the current network load. Then, steps 1061 and 1062 are modified to use the dynamic threshold for comparison and introduce a network load fluctuation factor. The new step 1060: Calculate the dynamic threshold based on the current network load; this step extracts the current network load value from real-time multi-dimensional features, calculates the dynamic normal range from historical data using radial basis function interpolation, and introduces a network load fluctuation factor to adjust the range width to cope with the impact of load fluctuations. This includes the following sub-steps: Extracting Current Network Load Value: Extracting the current network load value from real-time multi-dimensional features. (Such as total data packets per second or bandwidth utilization), reflecting the real-time network load status.

[0075] Obtaining historical load points and statistics: Extracting the set of historical load points from normal multi-dimensional features. (common (Points) and corresponding characteristic statistics, including the average transmission rate. Transmission rate standard deviation Average data frame interval Standard deviation of data frame interval ; Calculate the network load fluctuation factor: Calculate the standard deviation of the load values ​​within the most recent time window (e.g., the last 10 sampling points) as the network load fluctuation factor. The formula is: ;in, The size of the time window. For the first in the window One load value, This represents the average load within the window.

[0076] Modify step 1061: Identify abnormal transmission rates based on dynamic transmission rate range; compare the real-time transmission rates of different operating conditions in the real-time multi-dimensional features with the dynamic normal transmission rate range (i.e., the dynamic normal transmission rate range) calculated in step 1060. If the real-time transmission rate falls outside the range, record the transmission rate as abnormal; otherwise, determine that the transmission rate is normal.

[0077] Modify step 1062: Identify abnormal data frame intervals based on the dynamic data frame interval threshold range; compare the real-time data frame interval thresholds for different operating conditions in the real-time multi-dimensional features with the dynamic normal data frame interval threshold range (i.e., dynamic) calculated in step 1060. If the real-time data frame interval threshold falls outside the range, record the data frame interval as abnormal; otherwise, determine that the data frame interval is normal.

[0078] The subsequent steps remain unchanged; steps 1063-1066 are executed according to the original plan: Step 1063: Compare the data packet length distribution and record anomalies. Step 1064: Compare the protocol field integrity and record anomalies. Step 1065: Count the total number of anomaly types. Step 1066: Combine the electromagnetic shielding effectiveness compliance judgment result and the total number of anomaly types to determine whether the network traffic is abnormal.

[0079] Calculate the dynamic characteristic mean and standard deviation: Use radial basis function interpolation to calculate the current load. Average dynamic transmission rate under and current load The standard deviation of dynamic transmission rate under and the average dynamic data frame interval and standard deviation The formula is as follows: ; Represents the average transmission rate, RBF width parameter in the transmission rate dimension; Transmission rate standard deviation ;in, The RBF width parameter is used for the transmission rate dimension (optimized using historical data). Similarly, the data frame interval is calculated. and , using parameters .

[0080] Dynamic data frame interval mean : ; in: : in the Historical load points The mean of the normal data frame interval obtained from the statistics. : RBF width parameter dedicated to the data frame interval dimension, which controls the smoothness of interpolation.

[0081] Dynamic data frame interval standard deviation : ;in: : in the Historical load points The standard deviation of the normal data frame interval is obtained statistically.

[0082] The core idea of ​​the two formulas above is: with the current load The more similar the historical load points The more significant the value, the greater the influence of its corresponding statistic (mean or standard deviation) in calculating the current dynamic value. Weights are determined using the Gaussian radial basis function. To quantify.

[0083] Formula for the mean and standard deviation of dynamic characteristics (in terms of transmission rate) (For example) ; : The current network load value, which is the input for the calculation. The total number of reference load points selected from historical data. These points should cover as many load conditions as possible that the system may encounter. : No. One historical reference load point. Pre-marked in historical data. A representative load level. At historical load points During a given period, the average transmission rate is calculated based on all normal traffic. It represents the normal "average speed" under that specific load. The RBF width parameter (sometimes called the smoothing factor or bandwidth parameter) is specific to the transmission rate dimension. It determines the "sharpness" of the interpolation. When the value is small, only with Very close Only points have significant weights, and the results can vary drastically, potentially leading to overfitting. When the value is larger, the farther away Points can also contribute to the weights, resulting in a smoother outcome, but potentially leading to underfitting. This parameter is typically determined through optimization methods such as cross-validation. Gaussian radial basis function. It calculates the current load. Compared with historical load The similarity weight between them. When When , the function value is 1 (maximum weight). When As the value increases, the function value rapidly decays to 0. This weight ensures that historical data from "nearest neighbors" have a greater impact on the current estimate. : The calculated average dynamic transmission rate. It is based on the current load. The following is the best estimate of the "normal" average transmission rate. It is a weighted average of all historical means, with the weights determined by load similarity.

[0084] Step 1060 involves calculating the dynamic normal range, which combines the network load fluctuation factor. Calculate the dynamic normal transmission rate range and the dynamic normal data frame interval range. The formula is as follows: Dynamic normal transmission rate range: in, Partially represents the minimum value in the range. Represents the maximum value within the range.

[0085] Dynamic normal data frame interval threshold range: ;in and Range width constant (usually taken as 2-3). and A constant for adjusting the fluctuation factor (obtained through training on historical data) is used to control the degree of influence of the fluctuation factor on the range. The above-mentioned dynamic threshold processing method includes obtaining multiple load points and corresponding feature statistics from historical data, including the mean transmission rate, standard deviation of transmission rate, mean data frame interval, and standard deviation of data frame interval; calculating the network load fluctuation factor as the standard deviation of the load value within the most recent time window; using radial basis function interpolation to calculate the mean and standard deviation of the dynamic features under the current load, where the interpolation weight is based on the Euclidean distance between the current load and historical load points; combining the upper and lower bounds of the normal range of the network load fluctuation factor adjustment feature to generate the dynamic normal transmission rate range and the dynamic normal data frame interval threshold range; comparing the real-time features with the dynamic range to identify anomalies.

[0086] It should be noted that the formula for calculating the dynamic normal range is as follows: ; and The dynamic mean and dynamic standard deviation, calculated in the previous step, form the core of the normal range under the current load. Range width constant. It determines how wide the normal range is based on the standard deviation. It is usually chosen based on the properties of the normal distribution. For example, ... This means the normal range covers approximately The normal data points. It is a static, pre-set scaling factor. Volatility factor adjustment constant. It quantifies the volatility of network load. How much impact should it have on the width of the normal range?

[0087] if In this case, the volatility factor has no effect, and the range width is fixed. .

[0088] if , then when When the load increases (due to unstable load), the upper and lower bounds of the normal range will expand outwards. This is equivalent to the system automatically "relaxing" the criteria for judging normalcy when there are large load fluctuations, because the traffic characteristics themselves naturally fluctuate more greatly at this time, thus avoiding misjudging normal drastic fluctuations as abnormal. This parameter needs to be learned through training with historical data. Network load fluctuation factor. As mentioned above, it serves as a "signal" for dynamically adjusting the range width.

[0089] Specific data example: Example 1: Normal load fluctuation scenario; Time: 2024-06-01 10:30:00; Input data: Current load L = 28.3 Mbps; Historical load points: [15, 20, 25, 30, 35] Mbps; The corresponding average transmission rate is [120, 135, 150, 165, 180] kbps; the load fluctuation factor ΔL = 3.2. RBF interpolation calculation: μ_R(28.3) = 162.4 kbps; σ_R(28.3) = 18.7 kbps; Dynamic range = [162.4 - 2.2×18.7×(1+0.1×3.2), 162.4 + 2.2×18.7×(1+0.1×3.2)] = [162.4 - 47.8, 162.4 + 47.8] = [114.6, 210.2] kbps; Real-time transmission rate: 168.9 kbps, which is within the range after checking → no abnormality is determined.

[0090] Example 2: High load fluctuation scenario; Time: 2024-06-01 15:45:00; Input data: Current load L = 42.1 Mbps; Load fluctuation factor ΔL = 8.5 (high fluctuation); RBF interpolation calculation: μ_R(42.1) = 192.6 kbps; σ_R(42.1) = 22.3 kbps; Dynamic range = [192.6 - 2.2×22.3×(1+0.1×8.5), 192.6 + 2.2×22.3×(1+0.1×8.5)] = [192.6 - 92.7, 192.6 + 92.7] = [99.9, 285.3] kbps; Real-time transmission rate: 210.8 kbps → After investigation, it was found to be within the relaxed range → No abnormality was found; (Static thresholds may be false alarms in this scenario); The following performance comparison results were summarized after research: For example, the false alarm rate of a certain static threshold scheme is 12.5%, and the average response time is 45 (ms). Although its detection response time is short, its false alarm rate is high and its fluctuation tolerance is worse. However, when the same data is executed with the dynamic threshold scheme, its false alarm rate is 4.8% and the average response time is 93.5 (ms). Therefore, it has better high load adaptability and higher fluctuation tolerance.

[0091] Example 3: An abnormal network traffic detection system for a rail transit signaling system provided in this embodiment of the invention; Figure 3 This is a schematic diagram illustrating a specific implementation of a network abnormal traffic detection system for a rail transit signaling system provided in this invention. (Refer to...) Figure 3 The system may include: an acquisition module 21, used to acquire normal network traffic transmission parameter data of core equipment in the rail transit signaling system under different operating conditions, the operating conditions including standby and working conditions; a first determination module 22, used to determine normal multi-dimensional features under different operating conditions based on the normal network traffic transmission parameter data; a second determination module 23, used to acquire electromagnetic signal data around the connection port of the core equipment, and determine the electromagnetic shielding effectiveness compliance judgment result in combination with the electromagnetic shielding design standard value of the connection port of the core equipment; a filtering module 24, used to filter electromagnetic interference noise in the network traffic signal transmitted by the connection port of the core equipment using a multi-channel signal filtering method to obtain a filtered signal; an extraction module 25, used to extract data features from the filtered signal to obtain real-time multi-dimensional features; and a judgment module 26, used to compare the normal multi-dimensional features and the real-time multi-dimensional features to obtain the total number of abnormal types, and determine whether the network traffic transmitted by the connection port of the core equipment in the rail transit signaling system is abnormal network traffic in combination with the electromagnetic shielding effectiveness compliance judgment result. It should be noted that those skilled in the art can make various improvements and modifications to this invention without departing from its principles, and these improvements and modifications also fall within the scope of protection of this invention.

Claims

1. A method for detecting abnormal network traffic in a rail transit signaling system, characterized in that, include: Acquire normal network traffic transmission parameter data of core equipment in the rail transit signaling system under different operating conditions, including standby and working conditions. Based on the normal network traffic transmission parameter data, normal multi-dimensional characteristics under different operating conditions are determined. Electromagnetic signal data around the connection port of the core device is obtained, and the electromagnetic shielding design standard value of the connection port of the core device is combined to determine the electromagnetic shielding effectiveness compliance judgment result. A multi-channel signal filtering method is used to filter electromagnetic interference noise in the network traffic signal transmitted through the connection port of the core device to obtain a filtered signal. Data feature extraction is performed on the filtered signal to obtain real-time multi-dimensional features; By comparing the normal multi-dimensional features with the real-time multi-dimensional features, the total number of abnormal types is obtained. Combined with the electromagnetic shielding effectiveness compliance judgment result, it is determined whether the network traffic transmitted through the connection port of the core equipment in the rail transit signaling system is abnormal network traffic.

2. The method according to claim 1, characterized in that, Based on the normal network traffic transmission parameter data, determine the normal multi-dimensional characteristics under different operating conditions, including: The standby mode transmission rate set and the working mode transmission rate set are extracted from the normal network traffic transmission parameter data to calculate the normal transmission rate fluctuation range under different operating conditions within a preset time sequence statistical window. Extract the standby mode data frame interval set and the working mode data frame interval set from the normal network traffic transmission parameter data, so as to calculate the normal data frame interval threshold range under different operating conditions where the frequency ratio exceeds the preset ratio threshold within the preset time sequence statistics window. Extract the set of data packet lengths in the device sending direction and the set of data packet lengths in the device receiving direction from the normal network traffic transmission parameter data, and calculate the ratio of the number of data packets in the preset length interval to the total number of the corresponding set, so as to form the normal data packet length distribution characteristics under different operating conditions. The key protocol fields required for network communication of the core device are extracted from the normal network traffic transmission parameter data to determine the field bit requirements and field association rules corresponding to the key protocol fields, so as to form the integrity characteristics of normal protocol fields under different operating conditions. The key protocol fields include standby key protocol fields and working key protocol fields. By combining the normal transmission rate range, the normal data frame interval threshold range, the normal data packet length distribution characteristics, and the normal protocol field integrity characteristics, we obtain normal multi-dimensional characteristics.

3. The method according to claim 2, characterized in that, The standby transmission rate set and the working transmission rate set are extracted from the normal network traffic transmission parameter data to calculate the normal transmission rate fluctuation range under different operating conditions within a preset time-series statistical window, including: Based on the operating status identification information of the core device in the normal network traffic transmission parameter data, the normal network traffic transmission parameter data is divided into standby operating condition time period data and working operating condition time period data. The operating status identification information is the operating condition switching command or operating condition time period division rule sent by the core device. The transmission rate of each time node is extracted from the standby mode data to form a standby mode transmission rate set, and the transmission rate of each time node is extracted from the working mode data to form a working mode transmission rate set. Based on the signal transmission cycle of the core device under different operating conditions, a first preset window duration corresponding to the standby operating condition and a second preset window duration corresponding to the working operating condition are set. According to the first preset window duration, the set of standby mode transmission rates is divided into multiple standby window data segments, and according to the second preset window duration, the set of working mode transmission rates is divided into multiple working window data segments. Based on the maximum and minimum transmission rates in each standby window data segment and working window data segment, multiple standby window rate extreme value pairs and working window rate extreme value pairs are formed. Based on the maximum and minimum standby rates among all standby window rate extreme pairs, the normal transmission rate fluctuation range under standby conditions is determined. Based on the maximum and minimum working rates among all working window rate extreme pairs, the normal transmission rate fluctuation range under working conditions is determined.

4. The method according to claim 2, characterized in that, Extracting the key protocol fields required for network communication by the core device from the normal network traffic transmission parameter data, and determining the field bit requirements and inter-field association rules corresponding to the key protocol fields, including: Based on the operating conditions of the core equipment, the normal network traffic transmission parameter data is split into a standby protocol data set and a working protocol data set, and standby key protocol fields and working key protocol fields are extracted from the standby protocol data set and the working protocol data set, respectively. Based on the first field position, first data length, and first allowed value range of the required fields in the standby key protocol fields, and combined with the first preset omission condition, standby required field requirements and standby optional field requirements are formed. Based on the second field position, second data length, and second allowed value range of the required fields in the key work protocol fields, and combined with the second preset omission conditions, the work required field requirements and work optional field requirements are formed. Establish standby association rules between two standby key protocol fields whose frequency proportion in the same data packet exceeds a preset ratio, and establish work association rules between two work key protocol fields whose frequency proportion in the same data packet exceeds a preset ratio; The optional and required fields of the standby key protocol fields, as well as the corresponding standby optional and required field requirements, are combined with the standby association rules to form the field requirements and field association rules corresponding to the standby key protocol fields. The optional and required fields of the key work protocol fields, along with the corresponding optional and required field requirements, are combined with the work association rules to form the field requirements and field association rules corresponding to the key work protocol fields.

5. The method according to claim 1, characterized in that, Obtain electromagnetic signal data around the connection port of the core device, and combine it with the electromagnetic shielding design standard value of the connection port of the core device to determine the electromagnetic shielding effectiveness compliance judgment result, including: Functional checks are performed on multiple electromagnetic signal monitoring points pre-installed around the connection port of the core device to filter out a list of valid monitoring points. The first network communication frequency of the core device in standby mode and the second network communication frequency in working mode are combined into a total network communication frequency range, and the total network communication frequency range is divided into multiple monitoring frequency bands. The electromagnetic signal acquisition cycle is set according to the operating conditions of the core equipment; Electromagnetic signal data around the connection port is collected according to the electromagnetic signal acquisition cycle using the list of effective monitoring points. The electromagnetic signal data includes the instantaneous peak signal strength and the average signal strength within each monitoring frequency band. The instantaneous peak signal strength with the largest value in each monitoring frequency band belonging to the same electromagnetic signal acquisition cycle is taken as the peak characteristic value of the electromagnetic environment of the corresponding monitoring frequency band, and the arithmetic mean of the average signal strength in each monitoring frequency band belonging to the same electromagnetic signal acquisition cycle is taken as the average characteristic value of the electromagnetic environment of the corresponding monitoring frequency band. Obtain the electromagnetic shielding design standard value of the connection port of the core device. The electromagnetic shielding design standard value includes the average allowable electromagnetic signal strength limit and the peak allowable electromagnetic signal strength limit corresponding to each monitoring frequency band. The peak and average electromagnetic environment characteristics of each monitoring frequency band are compared with the corresponding electromagnetic shielding design standard values ​​to determine whether the electromagnetic shielding effectiveness of the core equipment connection port meets the standard, and an electromagnetic shielding effectiveness compliance determination result is generated.

6. The method according to claim 1, characterized in that, A multi-channel signal filtering method is used to filter electromagnetic interference noise in the network traffic signal transmitted through the connection port of the core device, resulting in a filtered signal, including: The fundamental frequency range of network traffic signals transmitted through the connection ports of the core device under different operating conditions, and the characteristic frequency range of electromagnetic interference noise are collected. The base frequency range is compared with the characteristic frequency range to identify the interference-related frequency bands and pure signal frequency bands in the base frequency range. Based on the number and frequency span of the interference-related frequency bands and the pure signal frequency bands, the base frequency range is divided into multiple filter frequency bands. Each filter frequency band corresponds to an interference-related frequency band or a pure signal frequency band and corresponds to a filter channel. Based on the operating conditions of the core equipment and the filtering frequency band, set the channel filtering parameters for each filtering channel; The network traffic signal transmitted through the connection port of the core device is obtained, and the network traffic signal is decomposed into multiple sub-channel signals according to the frequency range of each filter frequency band. Each sub-channel signal is transmitted to the corresponding filtering channel, and clutter suppression and interference removal are performed on the sub-channel signal according to the channel filtering parameters of each filtering channel to obtain the sub-channel processed signal; Based on the frequency range corresponding to each sub-channel signal, the sub-channel processed signals are integrated according to the original frequency order of the network traffic signals to obtain the filtered signal.

7. The method according to claim 1, characterized in that, The normal multi-dimensional features and the real-time multi-dimensional features are compared to obtain the total number of anomaly types. Combined with the electromagnetic shielding effectiveness compliance determination result, it is determined whether the network traffic transmitted through the connection ports of core equipment in the rail transit signaling system is abnormal network traffic, including: The real-time transmission rate of different working conditions in the real-time multi-dimensional features is compared with the corresponding normal transmission rate range in the normal multi-dimensional features to identify abnormal transmission rates. The real-time data frame interval thresholds for different working conditions in the real-time multi-dimensional features are compared with the corresponding normal data frame interval threshold range in the normal multi-dimensional features to identify abnormal data frame intervals. Extract the normal proportion within a preset length range from the normal data packet length distribution features in the normal multi-dimensional features, and extract the real-time proportion within a preset length range from the real-time data packet length distribution features in the real-time multi-dimensional features. If the difference between the normal proportion and the real-time proportion in at least one preset length range exceeds the preset proportion deviation allowable range, then record the data packet length distribution as abnormal. Extract the field bit information and field association relationship of the real-time key protocol field from the real-time protocol field integrity feature in the real-time multi-dimensional feature. If the field bit information of the real-time key protocol field does not meet the field bit requirements of the key protocol field in the normal multi-dimensional feature, or the field association relationship does not meet the association rules between fields, then record the protocol field integrity as abnormal. The total number of anomaly types, including abnormal transmission rate, abnormal data frame interval, abnormal data packet length distribution, and abnormal protocol field integrity, was recorded. If the electromagnetic shielding effectiveness meets the standard but is not up to standard, and the total number of abnormal types is not zero, then the network traffic transmitted through the core device connection port is determined to be abnormal network traffic. If the electromagnetic shielding effectiveness meets the standard but is up to standard, and the total number of abnormal types is greater than or equal to the preset number of abnormalities, then it is determined to be abnormal network traffic. If the electromagnetic shielding effectiveness meets the standard but is up to standard, and the total number of abnormal types is less than the preset number of abnormalities, then it is determined to be normal network traffic.

8. A network abnormal traffic detection system for a rail transit signaling system, characterized in that, include: The acquisition module is used to acquire normal network traffic transmission parameter data of core equipment in the rail transit signaling system under different operating conditions, including standby conditions and working conditions. The first determining module is used to determine the normal multi-dimensional characteristics under different operating conditions based on the normal network traffic transmission parameter data. The second determining module is used to acquire electromagnetic signal data around the connection port of the core device, and combine it with the electromagnetic shielding design standard value of the connection port of the core device to determine the electromagnetic shielding effectiveness compliance judgment result. The filtering module is used to filter electromagnetic interference noise in the network traffic signal transmitted through the connection port of the core device using a multi-channel signal filtering method to obtain a filtered signal. The extraction module is used to extract data features from the filtered signal to obtain real-time multi-dimensional features; The determination module is used to compare the normal multi-dimensional features and the real-time multi-dimensional features to obtain the total number of abnormal types. Combined with the electromagnetic shielding effectiveness compliance determination result, it determines whether the network traffic transmitted through the connection port of the core equipment in the rail transit signaling system is abnormal network traffic.

9. A computing device, characterized in that, It includes a processing component and a storage component; the storage component stores one or more computer instructions; the one or more computer instructions are invoked and executed by the processing component to implement a network abnormal traffic detection method for a rail transit signaling system as described in any one of claims 1 to 7.

10. A computer storage medium, characterized in that, The system contains a computer program that, when executed by a computer, implements a network abnormal traffic detection method for a rail transit signaling system as described in any one of claims 1 to 7.

Citation Information

Patent Citations

  • Flow length sensing congestion control method

    CN116527585A

  • Communication signal detection device and detection method

    CN118714607A

  • Intelligent network connection automobile anomaly detection system and method based on big data analysis

    CN119946640A

  • Communication network optimization method and device for rail transit

    CN120186094A

  • Rail transit customer service robot operation control method and device

    CN120523079A