Method, apparatus, device and medium for analyzing sip behavior based on real-time traffic

By employing a non-intrusive monitoring mechanism and utilizing network edge devices to replicate SIP messages in real time, combined with a rule engine and machine learning model, low-latency, efficient, and accurate detection of SIP behavior is achieved, solving the problem of existing technologies being unable to identify abnormal SIP behavior in real time.

CN121530751BActive Publication Date: 2026-05-01PRIMFORCE TECHNOLOGIES LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
PRIMFORCE TECHNOLOGIES LTD
Filing Date
2026-01-14
Publication Date
2026-05-01

AI Technical Summary

Technical Problem

Existing technologies cannot achieve accurate, real-time, low-latency, and low-intrusion detection of SIP behavior, making it difficult to identify malicious attacks in a timely manner.

Method used

A non-intrusive monitoring mechanism is adopted, which utilizes the traffic capture module deployed on the network edge device to copy the traffic capture module of the target network in real time, thereby achieving non-intrusive, low-latency monitoring of SIP messages.

Benefits of technology

It achieves non-intrusive, low-latency monitoring of SIP messages, quickly extracts core metadata, and accurately identifies abnormal SIP behavior through parallel detection using a rule engine and machine learning model.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121530751B_ABST
    Figure CN121530751B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of artificial intelligence, and provides a method and device for analyzing SIP behavior based on real-time traffic, equipment and a medium, which can adopt a non-intrusive monitoring mechanism, passively copy target SIP messages of a target network by using a traffic capturing module deployed on a network edge device, realize non-intrusive low-delay monitoring of the SIP messages, call a SIP protocol stack to analyze the target SIP messages, quickly extract core metadata, call a rule engine and an abnormal SIP behavior detection model pre-trained based on a machine learning model to perform parallel detection on target SIP features, obtain a target abnormal score, and generate a target response strategy according to the target abnormal score, so that the rule engine and the machine learning model are combined to realize efficient and accurate identification of abnormal SIP behavior.
Need to check novelty before this filing date? Find Prior Art

Description

Methods, apparatus, equipment, and media for real-time traffic analysis of SIP behavior Technical Field

[0001] This invention relates to the field of artificial intelligence technology, and in particular to a method, apparatus, device, and medium for analyzing SIP behavior based on real-time traffic. Background Technology

[0002] With the rapid development of mobile communication and Internet technologies, malicious attackers often use VoIP (Voice over IP) technology to launch a large number of calls through the SIP (Session Initiation Protocol) and impersonate legitimate numbers to guide users to perform insecure operations such as transactions by sending text messages or voice messages.

[0003] To address the above issue, traditional methods often rely on edge detection (such as mobile apps) or post-event log analysis, which suffers from delayed response and high false negative rates, making real-time interception impossible.

[0004] Furthermore, existing packet capture tools (such as Wireshark) are primarily used for offline analysis and cannot meet real-time requirements. Using carrier core network packet capture methods involves high load and privacy risks. Existing technologies also lack intelligent analysis algorithms for SIP, making it difficult to detect abnormal SIP behavior within milliseconds. Summary of the Invention

[0005] In view of the above, it is necessary to provide a method, apparatus, device and medium for analyzing SIP behavior based on real-time traffic, in order to solve the problem of being unable to detect abnormal SIP behavior with low latency, low intrusion and accuracy.

[0006] A method for analyzing SIP behavior based on real-time traffic, the method comprising:

[0007] In response to an abnormal SIP behavior detection command triggered by the target network, a non-intrusive monitoring mechanism is adopted, which uses a traffic capture module deployed on the network edge device to passively copy the target SIP messages of the target network in real time.

[0008] The SIP protocol stack is invoked to parse the target SIP message and obtain the target SIP characteristics;

[0009] The rule engine and the abnormal SIP behavior detection model pre-trained based on the machine learning model are invoked to perform parallel detection of the target SIP features to obtain the target abnormal score;

[0010] A target response strategy is generated based on the target anomaly score.

[0011] An apparatus for analyzing SIP behavior based on real-time traffic, the apparatus comprising:

[0012] The copying unit is used to respond to abnormal SIP behavior detection commands triggered based on the target network. It adopts a non-intrusive monitoring mechanism and uses a traffic capture module deployed on the network edge device to passively copy the target SIP messages of the target network in real time.

[0013] The parsing unit is used to call the SIP protocol stack to parse the target SIP message and obtain the target SIP characteristics;

[0014] The detection unit is used to call the rule engine and the abnormal SIP behavior detection model pre-trained based on the machine learning model to perform parallel detection of the target SIP features and obtain the target abnormal score.

[0015] The generation unit is used to generate a target response strategy based on the target anomaly score.

[0016] A computer device, the computer device comprising:

[0017] A memory for storing at least one instruction; and a processor for executing the instructions stored in the memory to implement the method for SIP behavior based on real-time traffic analysis.

[0018] A computer-readable storage medium storing at least one instruction, which is executed by a processor in a computer device to implement the method based on real-time traffic analysis of SIP behavior.

[0019] As can be seen from the above technical solutions, the present invention can adopt a non-intrusive monitoring mechanism, using a traffic capture module deployed on a network edge device to passively copy the target SIP messages of the target network, thereby achieving non-intrusive, low-latency monitoring of SIP messages; it calls the SIP protocol stack to parse the target SIP messages to quickly extract core metadata; it calls the rule engine and an abnormal SIP behavior detection model pre-trained based on a machine learning model to perform parallel detection of target SIP features, obtain a target anomaly score, and generate a target response strategy based on the target anomaly score, thereby combining the rule engine and machine learning model to achieve efficient and accurate identification of abnormal SIP behavior. Attached Figure Description

[0020] Figure 1 is a flowchart of a preferred embodiment of the method of the present invention based on real-time traffic analysis of SIP behavior;

[0021] Figure 2 is a functional block diagram of a preferred embodiment of the device for analyzing SIP behavior based on real-time traffic of the present invention;

[0022] Figure 3 is a schematic diagram of the structure of a computer device that implements a preferred embodiment of the method for real-time traffic analysis of SIP behavior according to the present invention. Detailed Implementation

[0023] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be described in detail below with reference to the accompanying drawings and specific embodiments.

[0024] Figure 1 shows a flowchart of a preferred embodiment of the method for analyzing SIP behavior based on real-time traffic according to the present invention. The order of the steps in this flowchart can be changed, and some steps can be omitted, depending on different requirements.

[0025] The method for analyzing SIP behavior based on real-time traffic is applied to one or more computer devices. The computer device is a device that can automatically perform numerical calculations and / or information processing according to pre-set or stored instructions. Its hardware includes, but is not limited to, microprocessors, application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), digital signal processors (DSPs), embedded devices, etc.

[0026] The computer device can be any electronic product that can interact with the user, such as a personal computer, tablet computer, smartphone, personal digital assistant (PDA), game console, interactive network television (IPTV), smart wearable device, etc.

[0027] The computer equipment may also include network equipment and / or user equipment. The network equipment includes, but is not limited to, a single network server, a server group consisting of multiple network servers, or a cloud based on cloud computing consisting of a large number of hosts or network servers.

[0028] The server can be a standalone server or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content delivery networks (CDN), and big data and artificial intelligence platforms.

[0029] Artificial intelligence (AI) is the theory, method, technology and application system that uses digital computers or machines controlled by digital computers to simulate, extend and expand human intelligence, perceive the environment, acquire knowledge and use knowledge to obtain the best results.

[0030] Foundational technologies for artificial intelligence generally include sensors, dedicated AI chips, cloud computing, distributed storage, big data processing, operating / interactive systems, and mechatronics. AI software technologies mainly encompass computer vision, robotics, biometrics, speech processing, natural language processing, and machine learning / deep learning.

[0031] The network in which the computer device is located includes, but is not limited to, the Internet, wide area network, metropolitan area network, local area network, and virtual private network (VPN).

[0032] S10, in response to the abnormal SIP (Session Initiation Protocol) behavior detection command triggered by the target network, adopts a non-intrusive monitoring mechanism and uses the traffic capture module deployed on the network edge device to passively copy the target SIP messages of the target network in real time.

[0033] In this embodiment, the target network may include 5G (5th Generation Mobile Communication Technology) network, IMS (IP Multimedia Subsystem) network, etc.

[0034] In this embodiment, the abnormal SIP behavior detection command can be triggered when the target network is put into use, so as to achieve comprehensive protection of network security.

[0035] In this embodiment, the network edge device may include, but is not limited to: a mirrored port SPAN (Switched Port Analyzer) of a router or switch, or a Test Access Point (TAP) device.

[0036] By deploying the traffic capture module on network edge devices, non-intrusive monitoring of SIP signaling can be achieved through passive traffic replication without interfering with the main link transmission, thus avoiding core network load and privacy risks.

[0037] In this embodiment, the method of passively copying the target SIP messages of the target network in real time using a traffic capture module deployed on a network edge device includes:

[0038] The bidirectional SIP signaling flow within the target network is copied in real time through the open mirror port of the network edge device.

[0039] The target SIP message is obtained by filtering non-SIP protocol packets in the bidirectional SIP signaling flow based on the configured five-tuple.

[0040] For example, it can support 10G, 40G, and 100G Ethernet interfaces and use efficient packet capture technology to filter out non-SIP protocol packets.

[0041] Efficient packet capture technologies can include: DPDK (Data Plane Development Kit), eBPF (Extended Berkeley Packet Filter), etc.

[0042] Non-SIP protocol packets may include: the default port 5060 UDP (User Datagram Protocol) / TCP (Transmission Control Protocol), or custom SIPS (Session Initiation Protocol Secure) ports such as 5061.

[0043] The obtained target SIP message is immediately stored in a message queue to avoid local buffer overflow.

[0044] The traffic capture module includes multiple processing nodes, which are classified according to the five-tuple for load balancing.

[0045] The bidirectional SIP signaling flow within the target network can be copied in real time using methods such as INVITE, REGISTER, and BYE.

[0046] The quintuple can be an IP (Internet Protocol) quintuple or a port quintuple. For example, the quintuple can be a set consisting of a source IP address, source port, destination IP address, destination port, and transport layer protocol, used to uniquely identify a network session.

[0047] By configuring the aforementioned five-tuple, irrelevant packets can be discarded, reducing downstream load by more than 80%.

[0048] In load balancing, traffic can be divided according to different 5-tuples to distribute traffic of different 5-tuples to different processing nodes. In this way, each processing node only handles traffic of one type of 5-tuple, thereby achieving high concurrency processing based on multi-instance deployment and effectively reducing packet loss rate.

[0049] In particular, when performing load balancing, it supports distributing traffic to multiple processing nodes based on RSS (Receive Side Scaling).

[0050] S11, invoke the SIP protocol stack to parse the target SIP message and obtain the target SIP characteristics.

[0051] In this embodiment, the step of calling the SIP protocol stack to parse the target SIP message and obtaining the target SIP characteristics includes:

[0052] Read the target SIP message from the message queue;

[0053] A state machine model is used to perform pre-compatibility processing on the read target SIP message to obtain the message to be processed;

[0054] The core metadata of the message to be processed is extracted using the SIP protocol stack.

[0055] The core metadata is converted into a structured feature vector to obtain the target SIP features.

[0056] The SIP protocol stack may include PJSIP (Project Jaken SIP) or Kamailio embedded parser, etc.

[0057] The state machine model is used to perform pre-compatibility processing on the read target SIP messages, which can tolerate malformed or incomplete SIP messages.

[0058] As a standard protocol stack, PJSIP has weak compatibility with malformed or incomplete SIP messages, which are easily discarded or fail to be parsed. Therefore, this embodiment first performs pre-compatibility processing through the state machine model, and then uses PJSIP to parse key fields. This not only takes advantage of the maturity of PJSIP, but also solves the compatibility problem of malformed packets.

[0059] The parsing process supports UDP, TCP, or TLS (Transport Layer Security) transport layers.

[0060] The core metadata may include, but is not limited to, a combination of one or more of the following key fields:

[0061] (1) Signaling header: From / To (URI of the caller / called party (Uniform Resource Identifier), including abnormal number detection), Call-ID (unique session identifier), CSeq (Client Sequence Number) (this sequence number is used to track session status);

[0062] (2) Extension headers: User-Agent (client software fingerprint, used to identify unauthorized tools such as Asterisk variants), Contact (actual contact address), Via (routing link, used to detect hop count);

[0063] (3) Payload field: Media description in SDP (Session Description Protocol) (used for subsequent RTP (Real-time Transport Protocol) extensions).

[0064] The core metadata can be converted into structured feature vectors such as JSON (JavaScript Object Notation), like {"from_uri": "sip:123456@fraud_ip", "via_hops": 7}.

[0065] The above parsing process can also support parallel multi-threaded parsing, with parsing efficiency reaching the microsecond level.

[0066] The above embodiments enable rapid parsing of SIP messages, thereby extracting core metadata.

[0067] S12, invoke the rule engine and the abnormal SIP behavior detection model pre-trained based on the machine learning model (ML) to perform parallel detection of the target SIP features and obtain the target abnormal score.

[0068] In this embodiment, the parallel detection of the target SIP features by invoking the rule engine and the abnormal SIP behavior detection model pre-trained based on the machine learning model to obtain the target anomaly score includes:

[0069] The rule engine is invoked to perform frequency anomaly detection on the target SIP features to obtain a first anomaly score;

[0070] The rule engine is invoked to perform pattern matching detection on the target SIP features to obtain a second anomaly score;

[0071] The abnormal SIP behavior detection model is invoked to perform content fingerprint detection on the target SIP features to obtain a third abnormal score.

[0072] Obtain the first weight coefficient corresponding to the pattern matching detection, and obtain the second weight coefficient corresponding to the content fingerprint detection;

[0073] The fourth abnormal score is obtained by weighting the second abnormal score, the third abnormal score, the first weighting coefficient, and the second weighting coefficient.

[0074] The larger value between the first abnormal score and the fourth abnormal score is taken as the target abnormal score.

[0075] The first weighting coefficient and the second weighting coefficient can be customized according to the accuracy requirements of the actual use scenario. For example, the first weighting coefficient can be configured to 0.6, and the second weighting coefficient can be configured to 0.4.

[0076] The rule engine may include Drools (JBoss Rules, a business rule management system) or a custom state machine, etc.

[0077] Through the above embodiments, multi-level anomaly pattern recognition can be achieved by combining rule engines and machine learning models. The rule engine handles deterministic anomalies, the machine learning model captures latent patterns, and online learning and updating can be supported.

[0078] In this embodiment, the step of calling the rule engine to perform frequency anomaly detection on the target SIP features and obtaining a first anomaly score includes:

[0079] When the same caller is detected to have more than one preset number of calls within a first preset time period and a hang-up rate greater than a hang-up rate threshold within a second preset time period in the target SIP features, a robot dialing risk event is determined to have been detected.

[0080] When the same caller is detected to make more calls to a preset region within a third preset time period than the second preset number of calls in the target SIP features, and the corresponding destination entropy is greater than a preset value, it is determined that a risk event in a sensitive region has been detected.

[0081] When the number of calls made by the same caller during non-peak business hours is greater than a third preset number and the average number of calls made within a preset period is greater than a preset multiple threshold, a risk event of robot activity during non-peak business hours is determined to have been detected.

[0082] When the short-term call hang-up rate within a preset sliding window is greater than a first threshold or the long-term call rate is greater than a second threshold in the target SIP features, it is determined that an AI voice preheating risk event has been detected.

[0083] When the call failure rate of the same call subject is greater than the failure rate threshold and the number of calls is greater than the call duration threshold in the target SIP features, it is determined that a brute-force enumeration risk event has been detected.

[0084] When it is determined that the robot dialing risk event, and / or the sensitive area risk event, and / or the robot activity risk event during non-peak business hours, and / or the AI ​​voice warm-up risk event, and / or the brute-force enumeration risk event are detected, the first preset score is determined as the first abnormal score.

[0085] For example: if the same IP / UA (User Agent) initiates more than 1000 calls within 1 minute and has a hang-up rate of more than 90% within 5 seconds, a robot dialing risk event is detected; if the same IP / UA initiates more than 500 calls to international numbers (e.g., + international area code) or marked sensitive areas within 1 hour, and the corresponding destination entropy is greater than 0.8, a sensitive area risk event is detected (the higher the destination entropy, the higher the randomness of the random dialing); if the same IP / UA initiates more than 1200 calls during off-peak hours (e.g., 2:00 AM - 5:00 AM) (or can be counted hourly, such as more than 300 calls / hour), a robot dialing risk event is detected. Furthermore, if, in conjunction with historical baselines, the number of calls exceeds the 7-day average call count multiplied by 3, a risk event of robot activity during non-peak business hours is detected. If the hang-up rate (i.e., short-term hang-up rate) of the same IP / UA within 5 seconds is greater than 95% within 1 hour, or the long-term call rate exceeding 10 minutes is greater than 80%, it indicates that speech synthesis testing or recording collection may have occurred, and an AI voice warm-up risk event is detected. If the failure rate of call attempts by the same IP / UA is greater than 70%, and the number of calls is greater than 800 (or can be counted according to time windows, such as greater than 200 times / minute), a brute-force enumeration risk event is detected.

[0086] Through the above embodiments, frequency anomaly detection can be performed through the rule engine to determine whether any behavior that triggers abnormal frequencies has occurred.

[0087] In this embodiment, the step of calling the rule engine to perform pattern matching detection on the target SIP features to obtain a second anomaly score includes:

[0088] Obtain the call transfer chain from the target SIP features; when the number of Via header hops in the call transfer chain is greater than the hop count threshold, it is determined that a proxy server link abnormality risk event has been detected.

[0089] When a call event is detected in the target SIP feature where the From header does not match the caller ID and the corresponding international area code is abnormal, it is determined that a number spoofing risk event has been detected.

[0090] When a call event is detected in the target SIP features where the deviation between the IP geographic location and the number's home location is greater than a deviation threshold, it is determined that a geographic inconsistency risk event has been detected.

[0091] Obtain the SIP REGISTER message from the target SIP feature; when the frequency of call forwarding events detected in the SIP REGISTER message is greater than the frequency threshold and / or the frequency of parameter change events is greater than the frequency threshold, and the corresponding source IP is not in the configuration list, it is determined that an account takeover risk event has been detected.

[0092] When an IP inconsistency is detected between the Contact header and the Via header in the target SIP characteristics, or when the user agent includes an abnormal string, a man-in-the-middle attack risk event is determined to have been detected.

[0093] Obtain the SIP packet sequence and real-time transport protocol stream from the target SIP features; when duplicate missing BYE / ACK packets are detected in the SIP packet sequence, or when an abnormal noise level greater than the noise threshold is detected in the real-time transport protocol stream, determine that an unauthorized access risk event of call content has been detected.

[0094] When all proxy IPs in the Via header of the target SIP feature are detected to be egress nodes of the Onion Router, or when the number of loops in the Record-Route header exceeds the threshold, an anonymous link risk event is determined to have been detected.

[0095] When it is determined that the following risk events are detected: abnormal proxy server link, number spoofing, geographical inconsistency, account takeover, man-in-the-middle attack, unauthorized access to call content, and anonymous link, the second preset score is determined as the second abnormal score.

[0096] For example: when the Via header hop count in a call forwarding chain is greater than 5, it indicates an abnormal proxy server link, thus confirming a proxy server link abnormality risk event; when the From header does not match the real Caller-ID (caller ID), and regular expression matching reveals an abnormal international area code, then a number spoofing risk event is confirmed; when the deviation between the IP geographic location and the number's home location is greater than 1000km, a geographic inconsistency risk event is confirmed; when the call forwarding (Diversion header) or credential change frequency in a SIP REGISTER message is greater than 3 times / hour, combined with the source IP not being whitelisted, an account takeover risk event is confirmed; when the IP address in the Contact header of a SIP message is inconsistent with the Via header, or the User-Agent contains known abnormal strings (such as "Asterisk"), then an account takeover risk event is confirmed. If a vulnerability (e.g., "1.x" old version) is detected, a man-in-the-middle attack risk event is identified; if a duplicate BYE / ACK is detected in the SIP packet sequence (indicating packet replay), or an abnormal noise level (e.g., greater than the threshold dB) is detected in the RTP stream, an unauthorized access risk event for call content is identified; if the proxy IPs in the Via header are all Tor (The Onion Router) egress nodes (e.g., can be matched using a specified list), or the loop count in the Record-Route header is greater than 3, an anonymous link risk event is identified.

[0097] In the above embodiments, fast pattern matching can be performed through a rule engine.

[0098] In this embodiment, the abnormal SIP behavior detection model can be a model trained based on a lightweight LSTM (Long Short-Term Memory) network. The input of this model can be a temporal feature sequence (such as the frequency vector of the past 10 sessions), and the output can be an anomaly probability score. The model can be trained using labeled datasets (such as those containing more than 100,000 real or simulated samples) and supports TensorFlow Lite edge deployment, achieving an inference latency of less than 10ms.

[0099] The abnormal SIP behavior detection model can be used to detect embedded abnormal keywords, such as prize notifications and emergency loans.

[0100] Before inputting the data into the abnormal SIP behavior detection model, feature processing can be performed using TF-IDF (Term Frequency – Inverse Document Frequency) or BERT (Bidirectional Encoder Representations from Transformers) embedding.

[0101] Through the above embodiments, it is possible to perform rapid filtering by combining a rule engine and in-depth analysis by combining an abnormal SIP behavior detection model pre-trained based on a machine learning model, thereby achieving efficient and accurate detection of abnormal SIP behavior.

[0102] S13, Generate a target response strategy based on the target anomaly score.

[0103] In this embodiment, the strategy for generating a target response based on the target anomaly score includes:

[0104] When the target anomaly score exceeds a score threshold, an abnormal SIP behavior is determined to have occurred, and the target SIP message is marked as abnormal; or

[0105] When the target anomaly score is less than or equal to the score threshold, the target SIP message is archived or discarded.

[0106] For example, when the target anomaly score is greater than 0.8, abnormal SIP behavior can be identified. In this case, the following response chain is immediately triggered: A Redis (Remote Dictionary Server) is used as a cache to store the dynamic blacklist (IP / Call-ID / UA), and blocking instructions (such as rejecting INVITE or redirecting calls) are pushed to the core network (e.g., CSCF (Call Session Control Function) or SBC (Session Border Controller)) via gRPC (Google Remote Procedure Call) or RESTful API (Representational State Transfer). Simultaneously, a standardized alarm report (JSON format) is generated and pushed to the SIEM (Security Information and Event Management) system or a visualization dashboard.

[0107] The standardized alarm report may include information such as anomaly type, evidence chain (such as the intercepted SIP header), and impact assessment.

[0108] The processing result of the blocking command can be sent back to the abnormal SIP behavior detection model for adaptive threshold adjustment of the model.

[0109] This includes recording audit logs of the response chain and anonymizing all logs based on hash IPs, thereby improving information security.

[0110] Each step in this embodiment can be deployed as a functional module at the edge of the operational network, such as a 5G base station or IMS gateway bypass, based on a distributed microservice architecture. The core of the system is to connect the SIP traffic replication, parsing, detection, and response links into a low-latency pipeline, ensuring that the end-to-end latency from traffic capture to alarm output does not exceed 50ms, thereby intercepting abnormal behavior (such as abnormal call behavior) before it is established.

[0111] Furthermore, each functional module supports horizontal scaling, supports Kubernetes container orchestration and Kafka partition scaling, and can achieve asynchronous decoupling through message queues (such as Apache Kafka), improving resource utilization and thus being able to handle peak traffic (supporting the processing of more than 100,000 SIP sessions per second).

[0112] Furthermore, each device involved in this embodiment supports fault switching mechanisms (such as module hot standby) and end-to-end encryption, which not only ensures the availability of the module, but also enables the processing of only anonymous features to avoid privacy leaks.

[0113] As can be seen from the above technical solutions, the present invention can adopt a non-intrusive monitoring mechanism, using a traffic capture module deployed on a network edge device to passively copy the target SIP messages of the target network, thereby achieving non-intrusive, low-latency monitoring of SIP messages; it calls the SIP protocol stack to parse the target SIP messages to quickly extract core metadata; it calls the rule engine and an abnormal SIP behavior detection model pre-trained based on a machine learning model to perform parallel detection of target SIP features, obtain a target anomaly score, and generate a target response strategy based on the target anomaly score, thereby combining the rule engine and machine learning model to achieve efficient and accurate identification of abnormal SIP behavior.

[0114] Figure 2 shows a functional block diagram of a preferred embodiment of the device for real-time traffic analysis of SIP behavior according to the present invention. The device 11 for real-time traffic analysis of SIP behavior includes a copying unit 110, a parsing unit 111, a detection unit 112, and a generation unit 113. The module / unit referred to in this invention refers to a series of computer program segments that can be executed by a processor and perform a fixed function, and are stored in memory. In this embodiment, the functions of each module / unit will be described in detail in subsequent embodiments.

[0115] The copying unit 110 is used to respond to an abnormal SIP behavior detection command triggered based on the target network, and adopts a non-intrusive monitoring mechanism to passively copy the target SIP messages of the target network in real time using a traffic capture module deployed on the network edge device.

[0116] The parsing unit 111 is used to call the SIP protocol stack to parse the target SIP message and obtain the target SIP characteristics;

[0117] The detection unit 112 is used to call the rule engine and the abnormal SIP behavior detection model pre-trained based on the machine learning model to perform parallel detection of the target SIP features and obtain the target abnormal score.

[0118] The generation unit 113 is used to generate a target response strategy based on the target anomaly score.

[0119] As can be seen from the above technical solutions, the present invention can adopt a non-intrusive monitoring mechanism, using a traffic capture module deployed on a network edge device to passively copy the target SIP messages of the target network, thereby achieving non-intrusive, low-latency monitoring of SIP messages; it calls the SIP protocol stack to parse the target SIP messages to quickly extract core metadata; it calls the rule engine and an abnormal SIP behavior detection model pre-trained based on a machine learning model to perform parallel detection of target SIP features, obtain a target anomaly score, and generate a target response strategy based on the target anomaly score, thereby combining the rule engine and machine learning model to achieve efficient and accurate identification of abnormal SIP behavior.

[0120] Figure 3 shows a schematic diagram of the structure of a computer device for implementing a preferred embodiment of the method for real-time traffic analysis of SIP behavior according to the present invention.

[0121] The computer device 1 may include a memory 12, a processor 13, and a bus (the arrow in the figure represents the bus), and may also include a computer program stored in the memory 12 and executable on the processor 13, such as an abnormal SIP behavior detection program.

[0122] Those skilled in the art will understand that the schematic diagram is merely an example of computer device 1 and does not constitute a limitation on computer device 1. Computer device 1 can be either a bus topology or a star topology. Computer device 1 may also include more or fewer other hardware or software than shown in the diagram, or different component arrangements. For example, computer device 1 may also include input / output devices, network access devices, etc.

[0123] It should be noted that the computer device 1 described is merely an example. Other existing or future electronic products that are adaptable to this invention should also be included within the scope of protection of this invention and are incorporated herein by reference.

[0124] The memory 12 includes at least one type of readable storage medium, such as flash memory, portable hard drive, multimedia card, card-type memory (e.g., SD or DX memory), magnetic memory, magnetic disk, optical disk, etc. In some embodiments, the memory 12 can be an internal storage unit of the computer device 1, such as a portable hard drive of the computer device 1. In other embodiments, the memory 12 can be an external storage device of the computer device 1, such as a plug-in portable hard drive, Smart Media Card (SMC), Secure Digital (SD) card, Flash Card, etc., equipped on the computer device 1. Furthermore, the memory 12 can include both internal and external storage units of the computer device 1. The memory 12 can be used not only to store application software and various types of data installed on the computer device 1, such as the code of an abnormal SIP behavior detection program, but also to temporarily store data that has been output or will be output.

[0125] In some embodiments, the processor 13 may be composed of integrated circuits, such as a single packaged integrated circuit or multiple integrated circuits packaged with the same or different functions, including combinations of one or more central processing units (CPUs), microprocessors, digital processing chips, graphics processors, and various control chips. The processor 13 is the control unit of the computer device 1, connecting various components of the computer device 1 via various interfaces and lines. It executes programs or modules stored in the memory 12 (e.g., executing abnormal SIP behavior detection programs) and calls data stored in the memory 12 to perform various functions of the computer device 1 and process data.

[0126] The processor 13 executes the operating system of the computer device 1 and various installed applications. The processor 13 executes the applications to implement the steps in the various method embodiments based on real-time traffic analysis of SIP behavior described above, such as the steps shown in FIG1.

[0127] For example, the computer program may be divided into one or more modules / units, which are stored in the memory 12 and executed by the processor 13 to complete the present invention. The one or more modules / units may be a series of computer-readable instruction segments capable of performing a specific function, which describe the execution process of the computer program in the computer device 1. For example, the computer program may be divided into a copying unit 110, a parsing unit 111, a detection unit 112, and a generation unit 113.

[0128] The integrated unit implemented as a software functional module described above can be stored in a computer-readable storage medium. This software functional module, stored in a storage medium, includes several instructions to cause a computer device (which may be a personal computer, computer equipment, or network device, etc.) or processor to execute portions of the method for analyzing SIP behavior based on real-time traffic analysis as described in the various embodiments of the present invention.

[0129] If the modules / units integrated in the computer device 1 are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the methods of the above embodiments of the present invention can also be implemented by a computer program instructing related hardware devices. The computer program can be stored in a computer-readable storage medium, and when executed by a processor, it can implement the steps of the various method embodiments described above.

[0130] The computer program includes computer program code, which may be in the form of source code, object code, executable file, or some intermediate form. The computer-readable medium may include: any entity or device capable of carrying the computer program code, recording media, USB flash drive, portable hard drive, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory, etc.

[0131] Furthermore, the computer-readable storage medium may primarily include a stored program area and a stored data area, wherein the stored program area may store the operating system, an application program required for at least one function, etc.; and the stored data area may store data created based on the use of blockchain nodes, etc.

[0132] The blockchain referred to in this invention is a novel application model of computer technologies such as distributed data storage, peer-to-peer transmission, consensus mechanisms, and encryption algorithms. Essentially, a blockchain is a decentralized database, a chain of data blocks linked together using cryptographic methods. Each data block contains information about a batch of network transactions, used to verify the validity of the information (anti-counterfeiting) and generate the next block. A blockchain can include an underlying blockchain platform, a platform product service layer, and an application service layer.

[0133] The bus can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. This bus can be divided into address bus, data bus, control bus, etc. For ease of illustration, it is represented by only one straight line in Figure 3, but this does not mean that there is only one bus or one type of bus. The bus is configured to implement communication between the memory 12 and at least one processor 13, etc.

[0134] Although not shown, the computer device 1 may also include a power supply (such as a battery) to power various components. Preferably, the power supply can be logically connected to the at least one processor 13 through a power management device, thereby enabling functions such as charging management, discharging management, and power consumption management. The power supply may also include one or more DC or AC power supplies, recharging devices, power fault detection circuits, power converters or inverters, power status indicators, and other arbitrary components. The computer device 1 may also include various sensors, Bluetooth modules, Wi-Fi modules, etc., which will not be described in detail here.

[0135] Furthermore, the computer device 1 may also include a network interface. Optionally, the network interface may include a wired interface and / or a wireless interface (such as a Wi-Fi interface, a Bluetooth interface, etc.), which is typically used to establish communication connections between the computer device 1 and other computer devices.

[0136] Optionally, the computer device 1 may further include a user interface, which may be a display, an input unit (such as a keyboard), and optionally, a standard wired interface or a wireless interface. Optionally, in some embodiments, the display may be an LED display, a liquid crystal display, a touch-sensitive liquid crystal display, or an OLED (Organic Light-Emitting Diode) touchscreen, etc. The display may also be appropriately referred to as a screen or display unit, used to display information processed in the computer device 1 and to display a visual user interface.

[0137] It should be understood that the embodiments described are for illustrative purposes only and are not limited to this structure in the scope of the patent application.

[0138] Those skilled in the art will understand that the structure shown in FIG3 does not constitute a limitation on the computer device 1, and may include fewer or more components than shown, or combine certain components, or have different component arrangements.

[0139] Referring to Figure 1, the memory 12 in the computer device 1 stores multiple instructions to implement a method for analyzing SIP behavior based on real-time traffic, and the processor 13 can execute the multiple instructions to achieve the following:

[0140] In response to an abnormal SIP behavior detection command triggered by the target network, a non-intrusive monitoring mechanism is adopted, which uses a traffic capture module deployed on the network edge device to passively copy the target SIP messages of the target network in real time.

[0141] The SIP protocol stack is invoked to parse the target SIP message and obtain the target SIP characteristics;

[0142] The rule engine and the abnormal SIP behavior detection model pre-trained based on the machine learning model are invoked to perform parallel detection of the target SIP features to obtain the target abnormal score;

[0143] A target response strategy is generated based on the target anomaly score.

[0144] Specifically, the specific implementation method of the processor 13 for the above instructions can be referred to the description of the relevant steps in the embodiment corresponding to Figure 1, which will not be repeated here.

[0145] It should be noted that all data involved in this case was legally obtained. Software tools or components not belonging to this company that appear in the embodiments of this application are merely illustrative examples and do not represent actual use.

[0146] In the several embodiments provided by this invention, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of modules is only a logical functional division, and other division methods may be used in actual implementation.

[0147] This invention can be used in a wide variety of general-purpose or special-purpose computer system environments or configurations. Examples include: personal computers, server computers, handheld or portable devices, tablet devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable consumer electronics, network PCs, minicomputers, mainframe computers, and distributed computing environments including any of the above systems or devices. This invention can be described in the general context of computer-executable instructions, such as program modules, that are executed by a computer. Generally, program modules include routines, programs, objects, components, data structures, etc., that perform specific tasks or implement specific abstract data types. This invention can also be practiced in distributed computing environments where tasks are performed by remote processing devices connected via a communication network. In distributed computing environments, program modules can reside in local and remote computer storage media, including storage devices.

[0148] The modules described as separate components may or may not be physically separate. The components shown as modules may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.

[0149] Furthermore, the functional modules in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or in the form of hardware plus software functional modules.

[0150] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above, and that the present invention can be implemented in other specific forms without departing from the spirit or essential characteristics of the present invention.

[0151] Therefore, the embodiments should be considered exemplary and non-limiting in all respects, and the scope of the invention is defined by the appended claims rather than the foregoing description. Thus, all variations falling within the meaning and scope of equivalents of the claims are intended to be embraced within the invention. No appended diagram markings in the claims should be construed as limiting the scope of the claims.

[0152] Furthermore, it is clear that the word "comprising" does not exclude other units or steps, and the singular does not exclude the plural. Multiple units or devices described in this invention can also be implemented by a single unit or device through software or hardware. Terms such as "first," "second," etc., are used to indicate names and do not indicate any specific order.

[0153] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention.

Claims

1. A method for analyzing SIP behavior based on real-time traffic, characterized in that, The method for analyzing SIP behavior based on real-time traffic includes: responding to an abnormal SIP behavior detection command triggered by a target VoIP network, employing a non-intrusive monitoring mechanism, and passively copying target SIP messages from the target network in real time using a traffic capture module deployed on a network edge device; parsing the target SIP messages using the SIP protocol stack to obtain target SIP features; and performing parallel detection on the target SIP features using a rule engine and an abnormal SIP behavior detection model pre-trained based on a lightweight LSTM machine learning model to obtain a target abnormal score, including: performing frequency abnormal detection on the target SIP features using the rule engine to obtain a first abnormal score; performing pattern matching detection on the target SIP features using the rule engine to obtain a second abnormal score; performing content fingerprint detection on the target SIP features using the abnormal SIP behavior detection model to obtain a third abnormal score; and obtaining a first weight coefficient corresponding to the pattern matching detection and a weight coefficient corresponding to the content fingerprint detection. The second weighting coefficient; a fourth anomaly score is obtained by weighting the second anomaly score, the third anomaly score, the first weighting coefficient, and the second weighting coefficient; the larger value is obtained from the first anomaly score and the fourth anomaly score, and is used as the target anomaly score; wherein, the frequency anomaly detection is used to detect robot dialing risk events, sensitive area risk events, robot activity risk events during non-peak business hours, AI voice warm-up risk events, and brute-force enumeration risk events; the pattern matching detection is used to detect proxy server link anomaly risk events, number spoofing risk events, geographical inconsistency risk events, account takeover risk events, man-in-the-middle attack risk events, unauthorized access to call content risk events, and anonymous link risk events; a target response strategy is generated based on the target anomaly score; wherein, the method is deployed on the edge of the operational line network based on a distributed microservice architecture, and the execution steps of the method are connected in series into a low-latency pipeline to achieve interception before the abnormal behavior is established by reducing end-to-end latency.

2. The method for analyzing SIP behavior based on real-time traffic analysis as described in claim 1, characterized in that, The method of passively copying the target SIP messages of the target network in real time using a traffic capture module deployed on the network edge device includes: copying the bidirectional SIP signaling flow within the target network in real time through the open mirror port of the network edge device; filtering non-SIP protocol packets in the bidirectional SIP signaling flow based on the configured five-tuple to obtain the target SIP messages; wherein the obtained target SIP messages are stored in a message queue; wherein the traffic capture module includes multiple processing nodes, and the multiple processing nodes are classified according to the five-tuple for load balancing.

3. The method for analyzing SIP behavior based on real-time traffic analysis as described in claim 2, characterized in that, The step of calling the SIP protocol stack to parse the target SIP message and obtain the target SIP features includes: reading the target SIP message from the message queue; performing pre-compatibility processing on the read target SIP message using a state machine model to obtain a message to be processed; extracting core metadata from the message to be processed using the SIP protocol stack; and converting the core metadata into a structured feature vector to obtain the target SIP features.

4. The method for analyzing SIP behavior based on real-time traffic analysis as described in claim 1, characterized in that, The step of calling the rule engine to perform frequency anomaly detection on the target SIP features to obtain a first anomaly score includes: detecting the robot dialing risk event, the sensitive area risk event, the robot activity risk event during off-peak hours, the AI ​​voice warm-up risk event, and the brute-force enumeration risk event based on the target SIP features; when it is determined that the robot dialing risk event, and / or the sensitive area risk event, and / or the robot activity risk event during off-peak hours, and / or the AI ​​voice warm-up risk event, and / or the brute-force enumeration risk event are detected, the first preset score is determined as the first anomaly score.

5. The method for analyzing SIP behavior based on real-time traffic analysis as described in claim 1, characterized in that, The step of calling the rule engine to perform pattern matching detection on the target SIP features to obtain a second anomaly score includes: detecting the following risk events based on the target SIP features: proxy server link anomaly risk event, number spoofing risk event, geographical inconsistency risk event, account takeover risk event, man-in-the-middle attack risk event, unauthorized access to call content risk event, and anonymous link risk event; when it is determined that the following risk events are detected: proxy server link anomaly risk event, and / or number spoofing risk event, and / or geographical inconsistency risk event, and / or account takeover risk event, and / or man-in-the-middle attack risk event, and / or unauthorized access to call content risk event, and / or anonymous link risk event, the second preset score is determined as the second anomaly score.

6. The method for analyzing SIP behavior based on real-time traffic analysis as described in claim 1, characterized in that, The target response strategy based on the target anomaly score includes: when the target anomaly score is greater than a score threshold, determining that an abnormal SIP behavior has occurred and marking the target SIP message as abnormal; or when the target anomaly score is less than or equal to the score threshold, archiving or discarding the target SIP message.

7. An apparatus for analyzing SIP behavior based on real-time traffic, characterized in that, The device for analyzing SIP behavior based on real-time traffic includes: a replication unit, used to respond to an abnormal SIP behavior detection command triggered by a target VoIP network, employing a non-intrusive monitoring mechanism and utilizing a traffic capture module deployed on a network edge device to passively replicate target SIP messages of the target network in real time; a parsing unit, used to call the SIP protocol stack to parse the target SIP messages and obtain target SIP features; and a detection unit, used to call a rule engine and an abnormal SIP behavior detection model pre-trained based on a lightweight LSTM machine learning model to perform parallel detection on the target SIP features and obtain a target abnormal score, including: calling the rule engine to perform frequency abnormal detection on the target SIP features and obtain a first abnormal score; calling the rule engine to perform pattern matching detection on the target SIP features and obtain a second abnormal score; calling the abnormal SIP behavior detection model to perform content fingerprint detection on the target SIP features and obtain a third abnormal score; obtaining a first weight coefficient corresponding to the pattern matching detection and obtaining a first weight coefficient corresponding to the content fingerprint detection. The device uses a second weighting coefficient corresponding to fingerprint detection; it calculates a fourth anomaly score by weighting the second anomaly score, the third anomaly score, the first weighting coefficient, and the second weighting coefficient; it selects the larger value from the first anomaly score and the fourth anomaly score as the target anomaly score; wherein, the frequency anomaly detection is used to detect robot dialing risk events, sensitive area risk events, robot activity risk events during non-peak business hours, AI voice preheating risk events, and brute-force enumeration risk events; the pattern matching detection is used to detect proxy server link anomaly risk events, number spoofing risk events, geographical inconsistency risk events, account takeover risk events, man-in-the-middle attack risk events, unauthorized access to call content risk events, and anonymous link risk events; the generation unit is used to generate a target response strategy based on the target anomaly score; wherein, the device is deployed at the edge of the operational line network based on a distributed microservice architecture, and the execution steps of the device are connected in series into a low-latency pipeline to achieve interception before the establishment of abnormal behavior by reducing end-to-end latency.

8. A computer device, characterized in that, The computer device includes: a memory storing at least one instruction; and a processor executing the instructions stored in the memory to implement the method for analyzing SIP behavior based on real-time traffic as described in any one of claims 1 to 6.

9. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores at least one instruction, which is executed by a processor in a computer device to implement the method for analyzing SIP behavior based on real-time traffic analysis as described in any one of claims 1 to 6.

Citation Information

Patent Citations

  • Data filtering method and system for digital twin industrial control safety target range

    CN120915499A

  • SIP protocol encryption malicious traffic detection method based on deep learning

    CN121239440A