Multi-plane cross-layer cooperative online flow detection system for 5G network
By designing a multi-plane cross-layer collaborative online traffic detection system in a 5G Open-RAN network, and utilizing bypass mirroring and multi-model detection technologies, the problem of insufficient cross-layer analysis capabilities is solved. This enables real-time, refined monitoring and protection of the 5G network, adapting to different service pressures and resource constraints, and possessing proactive defense capabilities.
Patent Information
- Application Number
- CN202511659334.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-13
- Publication Date
- 2026-02-13
AI Technical Summary
Existing 5G Open-RAN networks suffer from insufficient cross-layer analysis capabilities, poor model adaptability, and a disconnect between detection and defense, making it difficult to meet real-time requirements and the need for refined monitoring and protection in complex network environments.
Design a multi-plane, cross-layer collaborative online traffic detection system for 5G Open-RAN architecture. By using bypass mirroring technology to acquire control plane and data plane data, and combining finite state machine modeling, multi-model detection and cross-layer collaborative analysis, the system can achieve real-time identification and defense against network anomalies.
It enables real-time and refined monitoring and protection of 5G networks, possesses cross-layer integrated perception capabilities, adapts to different business pressures and resource constraints, has proactive defense capabilities, reduces false alarm rates, and improves detection accuracy.
Smart Images

Figure CN121531371A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of mobile communication and network security technology, and in particular relates to a multi-plane cross-layer collaborative online traffic detection system for 5G Open-RAN (Open Radio Access Network) architecture, which covers multi-dimensional analysis of the control plane and data plane, and is used for intelligent monitoring and anomaly detection of 5G networks. Background Technology
[0002] With the accelerated deployment of 5G networks, the types of critical infrastructure services and businesses they support are experiencing explosive growth, driving deep integration and application in key industries such as industrial control, telemedicine, and vehicle-to-everything (V2X). However, this has also led to a significant increase in the complexity of network structure and protocol interactions. The network side consists of multiple virtualized network elements, with frequent cross-layer and cross-module message interactions. The separation of the control plane and user plane, the diversification of service slicing, the frequent switching of mobility, and the dynamic adjustment of resource scheduling strategies pose unprecedented challenges to traditional static, rule-driven monitoring methods.
[0003] In the Open-RAN architecture, network control logic is pushed down to the CU / DU modules at the edge, and scheduling and orchestration capabilities are achieved through interfaces such as RIC and xApp, providing new opportunities for deploying external intelligent detection systems. However, at the same time, the data transmission of existing O-RAN systems relies on terminal status or deep packet inspection, which is not suitable for environments where terminals are uncontrollable and data is restricted; the state transition processes of control plane protocols such as RRC are often encapsulated internally, making it difficult for abnormal behavior to be directly perceived externally; and the large amount of GTP-U traffic carried by the data plane is highly encrypted and structurally complex, with traffic characteristics varying significantly under different service scenarios, posing challenges to real-time parsing and modeling. In addition, the openness of O-RAN brings a larger attack surface, but lacks real-time, granular security awareness mechanisms, and the response latency cannot meet the millisecond-level real-time requirements of scenarios such as autonomous driving and industrial robots. Under different network loads and service strategies, the computational performance and accuracy requirements of the detection model vary greatly, and static deployment of a single model can no longer adapt to the dynamic and ever-changing operating environment.
[0004] Therefore, there is an urgent need for an external intelligent traffic detection system with strong deployability, broad analytical dimensions, fine detection granularity, and high adaptability. This system should not only be able to accurately model and identify anomalies in control plane signaling behaviors such as RRC state transitions, but also possess the ability to perform real-time, dynamic analysis of high-throughput data streams from the user plane. Furthermore, it should be able to intelligently schedule appropriate detection models under different service pressures and resource constraints, achieving an optimal balance between detection accuracy and system performance. More importantly, the system should be able to integrate multi-layer data, establish logical connections between the control plane and the data plane, achieve cross-layer collaborative perception and decision support, and schedule system resources, thereby truly realizing continuous monitoring of the 5G network's operational status and immediate early warning and protection against abnormal behavior. Summary of the Invention
[0005] To address the shortcomings of existing 5G Open-RAN network security detection technologies, such as insufficient cross-layer analysis capabilities, poor model adaptability, and a disconnect between detection and defense, this invention proposes a multi-plane, cross-layer, collaborative online traffic detection system for the 5G Open-RAN architecture. This method deploys a non-intrusive detection device outside the 5G network to jointly collect, parse, and analyze multi-source information from the control plane and data plane, establishing a cross-layer context model to achieve real-time identification and defense against network anomalies, attack behaviors, and protocol anomalies. The system adopts a modular design, ensuring zero interference with existing network services while providing independent visualization and decision support capabilities for operator operations, network supervision, and security situation awareness.
[0006] The core idea of this invention is as follows: Under the 5G Open-RAN architecture, bypass mirroring technology is used to obtain control plane and data plane signaling and traffic data from key interfaces (such as F1 and NG interfaces); in the control plane, abnormal state transitions and signaling interactions are identified through finite state machine modeling and signaling sequence parsing; in the data plane, abnormal traffic and encryption attacks are identified through flow-level feature extraction and multi-model detection; finally, in the cross-layer collaborative analysis stage, the control plane state, data plane traffic characteristics, and PHY / MAC layer context information are integrated to construct a multi-layer, multi-dimensional anomaly detection and defense system.
[0007] The technical solution of the present invention is as follows:
[0008] A multi-plane, cross-layer collaborative online traffic detection system for 5G Open-RAN architecture, characterized by including:
[0009] The data collection module obtains control plane and user plane data packets in real-time mirroring from the gNB-side F1 interface and NG interface, including protocol data such as RRC, NAS, NG-AP, PDCP, GTP-U, etc. This module provides protocol parsing, message recombination, and multi-level caching mechanisms to ensure integrity and timing consistency under high throughput conditions.
[0010] The control plane analysis module reconstructs the RRC state evolution path of the UE based on the finite state machine (FSM) model, and establishes an end-to-end control plane behavior map in combination with NAS and NGAP processes. This module can detect typical anomalies such as illegal state jumps, signaling storms, abnormal registrations, identity forgeries, etc., and supports a detection mechanism that combines rule engines and unsupervised learning methods;
[0011] The data plane anomaly detection module uses the five-tuple as the basic unit, combines traffic statistical features and behavior patterns, and uses multiple models (KNN, random forest, CNN, LSTM, etc.) for traffic anomaly detection. The system has a dynamic model scheduling mechanism, which can select the optimal detector according to network load and computing power, quickly identify suspicious traffic in high-concurrency scenarios, and perform in-depth detection when resources are abundant;
[0012] The cross-layer cooperation module integrates the control plane (RRC state migration), data plane (flow characteristics), and MAC / PHY layer metrics (such as CQI, MCS, scheduling behavior) to construct a cross-layer context map. This module can perform multi-dimensional linkage analysis and identify hidden attacks that cannot be detected by a single layer, such as traffic flooding caused by control plane anomalies or state reconstruction tides accompanied by PHY layer degradation.
[0013] The policy linkage and defense scheduling module implements a closed-loop linkage mechanism / system from detection to defense. By docking with the O-RAN RIC control architecture, it is divided into the near-real-time (Near-RT RIC) layer and the quasi-real-time (Quasi-RT RIC) layer. In the near-real-time RIC, the xApp application is responsible for running anomaly detection and traffic classification functions (i.e., the data plane anomaly detection module), outputs the inference results, and stores them in the inference database. In the quasi-real-time RIC, the module performs scheduling weight training, traffic scheduling optimization, and abnormal traffic mitigation based on the inference results, and issues policies to the O-DU through the real-time DU interaction module to achieve control of MAC / PHY scheduling. Policy linkages can include: downweighting scheduling of abnormal UE traffic, blocking and rate-limiting of suspicious IPs, preferential guarantee of highly trusted services, and traffic isolation and resource release for signaling attacks.
[0014] An online traffic detection method based on the above system, the method includes:
[0015] Step S1: Non-intrusive traffic mirroring and collection
[0016] S1-1 mirrors F1-C / F1-U and NG-C / NG-U on switching equipment or bypass acquisition devices to obtain RRC, NGAP, NAS and GTP-U / PDCP related data;
[0017] S1-2 performs timestamp unification and serialization caching on the mirrored data, and performs on-demand filtering and sampling at the RNTI or cell granularity according to the strategy;
[0018] S1-3 Establish identifier mapping (RNTI, UE IP, etc.) to support cross-layer association. Establish and maintain a "UE context mapping table", which dynamically associates key identifiers such as RNTI, SUCI / SUPI, UE IP address, and GTP-U tunnel endpoint identifier (TEID).
[0019] Step S2: Protocol Parsing and Feature Construction
[0020] S2-1 Control plane feature extraction: Decode RRC, NGAP, and NAS, reconstruct the entire UE access and registration path (RRC Setup → Security → Reconfiguration; NAS Registration / Authentication, etc.), and extract message types, key IEs, latency, failure reason codes, timer triggers (such as T300 / T301 / T310), etc.
[0021] S2-2 Data plane feature extraction: Decapsulate GTP-U and identify the five-tuple (source / destination IP, source / destination port, protocol, direction) to construct a flow-level context;
[0022] S2-3 Cross-layer: Aggregates CQI, MCS, BLER, HARQ and scheduling / switching events from the MAC / PHY side (which can be reported by gNB or provided by the operation and maintenance interface) to form a unified feature vector and event stream.
[0023] Step S3: Control Surface Interpretable Anomaly Detection
[0024] S3-1 Constructs a UE-oriented RRC FSM (Idle, Connected, Inactive and their legal transitions) and drives state evolution with message sequences;
[0025] S3-2 uses a combination of rule engine and machine learning to detect abnormal state trajectories, such as illegal back bounce, state jitter / storm, NAS breakage, abnormal release, capability query timeout, missing security activation, replay / spoofed access, etc.
[0026] S3-3 generates anomaly event logs (event type, affected UE set, location / cell, time period, credibility score, suspected root cause).
[0027] Step S4: Adaptive Multi-Model Anomaly Detection on the Data Surface
[0028] Building upon the unified feature vector constructed in S2-3, S4-1 further performs real-time contextual classification of data plane traffic. Based on quintuples, ports, packet length sequences, etc., it infers whether traffic belongs to eMBB (eMBB, uRLLC, uRLLC, mMTC, or a specific application-driven service type. It identifies whether traffic is bursty (e.g., video download), continuous (e.g., voice call), interactive (e.g., web browsing), or low-speed long-connection.
[0029] S4-2 establishes a lightweight rule-driven model scheduler that dynamically assigns detection tasks to the most suitable model based on the context classification results from S4-1. For high-throughput scenarios requiring rapid screening, lightweight statistical models (such as isolated forests) or decision tree ensemble models are employed. This quickly identifies traffic flooding (DDoS), bandwidth abuse, and protocol format anomalies (such as GTP-U header malformations). For encrypted traffic scenarios requiring in-depth behavioral analysis, deep learning time-series models are enabled. By analyzing metadata such as packet length time series, throughput changes, and handshake intervals, covert data penetration communications and slow application-layer DDoS attacks in encrypted channels are identified. For low-rate, long-term suspicious activity scenarios, density-based clustering algorithms (such as DBSCAN) or Hidden Markov Models (HMMs) are used to identify low-frequency but persistent attacks such as slow port scanning, host liveness probing, and data leakage.
[0030] Step S5: Cross-layer context graph and causal association
[0031] S5-1 unifies the control plane state trajectory, data plane flow behavior and MAC / PHY indicators into a graph. Nodes include UE / cell / slice / session / flow, and edges represent causal or temporal relationships (e.g., "RRC reconstruction → CQI decrease → GTP-U flow surge").
[0032] S5-2 Based on windowed event correlation and path consistency verification, it determines linkage anomalies (such as air interface interference → access jitter → NAS failure → service packet loss).
[0033] S5-3 outputs cross-layer alarms and root cause explanations for policy linkage.
[0034] Step S6: Strategy Coordination and Defense Scheduling
[0035] The S6-1 system maintains real-time interaction with the O-DU through the RT-E2 interface, periodically reporting traffic status (RT-E2Report) and receiving defense policies (RT-E2 Policy).
[0036] S6-2 limits, drops, or isolates detected abnormal traffic, and if necessary, triggers the RT-E2 policy at the DU level to achieve cross-layer joint defense.
[0037] When encountering large-scale abnormal traffic, the S6-3 control plane can adjust MAC scheduling and RLC cache management strategies in real time to ensure uninterrupted base station service.
[0038] Compared with the prior art, the present invention has the following beneficial effects:
[0039] Through a closed loop of "detection-reasoning-scheduling-mitigation", this invention can not only identify anomalies, but also take targeted measures in a timely manner to form a proactive defense capability.
[0040] (1) Cross-layer integrated perception: Establish a unified timeline and identifier mapping between the control plane (RRC / NAS / NGAP) and the data plane (GTP-U / PDCP) to realize end-to-end association from access to service traffic.
[0041] (2) Control plane interpretable modeling: Anomaly identification based on RRC FSM and 3GPP timing constraints has lower false alarms and more accurate localization than methods based solely on statistical features.
[0042] (3) High-efficiency data surface detection: Through multi-model adaptive scheduling, it balances high throughput and high accuracy, and adapts to peak and valley traffic and computing power fluctuations.
[0043] (4) Context-driven root cause analysis: using cross-layer graphs to reveal the path of anomaly propagation, supporting closed-loop verification of causal chains and priority ranking of operation and maintenance.
[0044] (5) Feasibility of zero-intrusion engineering: Bypass mirroring + standard interface to connect to the original network, simple deployment, and no impact on the continuity of existing network services. Attached Figure Description Figure 1 This is a schematic diagram of the overall system deployment and architecture; Figure 2 A schematic diagram of the multi-model dynamic scheduling mechanism for the data plane anomaly detection module; Figure 3 This is a diagram illustrating the linkage and execution of defense strategies. Detailed Implementation
[0045] The multi-plane cross-layer collaborative online flow detection method of the present invention will be described in detail below with reference to the embodiments of the present invention, but this should not be construed as limiting the scope of protection of the present invention.
[0046] This embodiment proposes an intelligent traffic detection system deployed outside the 5G Open-RAN architecture. This system can non-intrusively acquire control plane and data plane signaling and traffic data, integrating multi-model algorithms and cross-layer context to achieve real-time perception and anomaly detection of the 5G network's operational status. The system modules include a data acquisition module, a control plane status analysis module, a data plane traffic detection module, a cross-layer collaboration module, a model scheduling module, and a result feedback interface, supporting flexible deployment on edge computing nodes or central analysis servers.
[0047] The intelligent traffic detection and defense system in this embodiment is deployed in a 5G Open-RAN architecture environment, such as... Figure 1 As shown, the system includes:
[0048] (1) Base station equipment (gNB): The CU / DU functional entity in the Open-RAN architecture, responsible for radio resource management and radio signaling processing, providing radio access services to UE, and interacting with the core network through the F1 interface.
[0049] (2) User Equipment (UE): 5G mobile terminal, responsible for receiving and processing wireless signals, interacting with base stations for control signaling such as RRC / NAS, and transmitting user plane data, including 5G mobile phones, analog terminals, etc.
[0050] (3) Data acquisition equipment: deployed on the gNB side or network edge node, non-intrusively mirroring the F1 interface and NG interface between gNB and core network, capturing control plane (RRC, NAS, NGAP, etc.) and data plane (user traffic encapsulated by GTP-U) data packets in real time, and performing protocol parsing.
[0051] (4) Data processing and analysis equipment: including high-performance servers or edge computing nodes, responsible for protocol reassembly, state machine modeling, multi-model anomaly detection and cross-layer collaborative analysis of collected data, to realize online monitoring of the 5G network operation status.
[0052] (5) Storage device: used to store signaling logs, traffic characteristics and training samples, supporting model training and historical data analysis.
[0053] (6) Communication interface equipment: used for data interaction between the system and upper-level platforms such as O-RAN RIC controller and network management system, and supports real-time alarm push and policy distribution.
[0054] (7) Operation and maintenance terminal equipment (optional): Provides a visual operation interface for network operation and maintenance personnel to display network anomaly detection results, traffic trends and system status.
[0055] A multi-plane, cross-layer collaborative online traffic detection and defense method includes the following steps and processes:
[0056] Step 1: Traffic Mirroring and Data Acquisition
[0057] (1-1) Without affecting the original network services, the F1-C, F1-U, NG-C, and NG-U interface traffic between the gNB and the core network is copied to the data acquisition device via the switch bypass mirroring technology. Control plane data: RRC, NAS, NGAP and other signaling messages; Data plane data: GTP-U encapsulated user traffic, PDCP fragmentation information, etc.
[0058] (1-2) The acquisition module supports data filtering and priority control, such as: only collecting traffic from the target IP or a specified device, thereby reducing system pressure.
[0059] (1-3) The acquisition module is configured with multi-level caching and flow control mechanisms to ensure data integrity and timestamp alignment even under high bandwidth and Gbps traffic.
[0060] Step 2: Protocol Parsing and Feature Extraction
[0061] (2-1) Decode the control plane signaling protocol and reconstruct the UE connection process at the RRC layer, including messages such as RRCSetup, RRCReconfiguration, and SecurityModeCommand.
[0062] (2-2) Parse NAS and NGAP messages, extract processes such as Attach, Authentication, and Registration, and construct an end-to-end control path.
[0063] (2-3) Decapsulate the GTP-U traffic on the data plane, identify the five-tuple (source IP, destination IP, source port, destination port, protocol), and calculate the characteristics such as flow duration, size distribution, uplink and downlink rates.
[0064] (2-4) Collect contextual metrics from the MAC / PHY layer, such as CQI, MCS, and HARQ retransmission counts, to form a cross-layer feature set.
[0065] Step 3: Control plane anomaly identification
[0066] (3-1) Based on the finite state machine theory, construct the user-granular RRC state map, which includes three types of states: Idle, Connected, and Inactive, as well as the transition conditions between each state.
[0067] (3-2) Track the UE's status trajectory in real time and extract features such as status dwell time, switching rate, and rollback behavior.
[0068] (3-3) Identify the following typical anomalies using rule bases and machine learning methods:
[0069] 1. Signaling storm: A large number of RRC connection requests are made in a short period of time but the subsequent process is not completed;
[0070] 2. NAS registration error: RRC connection completed but NAS messages missing or interrupted;
[0071] 3. State Reversal: The UE re-initiates RRCSetup after completing security activation;
[0072] 4. Unauthorized release: RRCRelease appears before safe activation;
[0073] 5. DoS attack: Continuously sending unnecessary ULInformationTransfers.
[0074] Step 4: Data plane traffic anomaly detection
[0075] (4-1) Construct a flow level model using quintuples as the basic unit, and combine it with flow statistics characteristics (packet rate, direction ratio, burst index).
[0076] (4-2) The system supports heterogeneous deployment of multiple detection models, see appendix. Figure 2
[0077] Lightweight models: KNN, decision trees, random forests, suitable for high-concurrency, low-latency detection;
[0078] Deep models: CNN, LSTM, suitable for complex behavior and encrypted traffic analysis.
[0079] (4-3) The model scheduling module dynamically selects the model based on network load:
[0080] Under high load, prioritize the use of lightweight models for rapid initial screening; under low load or high-value business, enable deep models to enhance detection accuracy.
[0081] (4-4) Detection targets include: encrypted DDoS (SSL Flood, SSH brute force), lateral scanning, large-scale traffic abuse, and covert data penetration.
[0082] Step 5: Cross-layer context modeling and comprehensive analysis
[0083] (5-1) Integrate the control surface RRC trajectory, data surface flow level features and PHY / MAC indices to construct a cross-layer context graph.
[0084] (5-2) Multi-level event linkage analysis can be achieved through graphs. For example, if frequent RRC reconstruction is detected and accompanied by a decrease in CQI, it can be located as air interface interference; if a sudden large flow of data plane is accompanied by NAS registration failure, it can be determined as malicious flooding.
[0085] (5-3) Supports causal chain tracing for complex attacks, such as APT penetration or resource exhaustion attacks.
[0086] Step 6: Result Output and Scheduling Defense
[0087] (6-1) The alarms and analysis results output by the detection engine are first transmitted to the defense scheduling module through a standardized interface. This module can interface with O-RAN's Near-RT RIC or operation and maintenance management platform to achieve policy linkage while maintaining independent system deployment.
[0088] (6-2) The defense scheduling module executes a multi-dimensional response strategy based on the detection results and contextual information, including:
[0089] 1. Control plane-based defense: If an RRC storm or NAS registration anomaly is detected, the system can trigger gNB-side policy adjustments, such as temporarily rejecting high-frequency abnormal requests or delaying the response to illegal UEs' RRCSetup.
[0090] 2. Data-based defense: Automatically issue flow table rules to identified malicious flows (such as encrypted DDoS attacks and lateral movement) to block corresponding 5-tuples or rate limits. See appendix. Figure 3 It can quickly identify anomalies and defend against them.
[0091] 3. Cross-layer coordinated defense: When RRC anomalies and high traffic anomalies occur simultaneously, joint defense is triggered, such as blocking the corresponding IP and restricting UE access requests.
[0092] 4. Scheduling optimization measures: Under abnormal load conditions, the system can issue scheduling parameters through the interface to prioritize the protection of critical service users and reduce the impact of abnormal traffic on normal users.
[0093] (6-3) Strategy scheduling supports multi-level triggering mechanisms:
[0094] Fast response layer: triggered directly by the detection engine, such as blocking malicious IPs;
[0095] Strategy Coordination Layer: The defense scheduling module makes judgments based on the context to prevent over-defense.
[0096] (6-4) All strategy actions are recorded and incorporated into the defense effect feedback mechanism. If a certain type of defense measure is frequently triggered, the system will optimize the strategy by combining historical data and add new detection features during the model update phase to form a closed-loop evolution capability.
[0097] Through the specific and feasible implementation methods described above, the present invention successfully combines cross-layer perception, intelligent analysis and O-RAN native control capabilities to achieve high-precision, low-latency and proactive defense against unknown threats to 5G networks, effectively solving the various challenges raised in the background technology.
[0098] Appendix: Abbreviation English-Chinese Glossary
[0099] abbreviation Full English name Chinese meaning 5G Fifth Generation Mobile Communication 5G mobile communication O-RAN Open Radio Access Network Open wireless access network RAN Radio Access Network Wireless Access Network gNB Next Generation NodeB 5G base station CU Centralized Unit Centralized Unit DU Distributed Unit Distribution Unit RIC RAN Intelligent Controller Wireless Access Network Intelligent Controller Near-RT RIC Near Real-Time RAN Intelligent Controller Near Real-Time Wireless Access Network Intelligent Controller Quasi-RT RIC Quasi Real-Time RAN Intelligent Controller Near real-time wireless access network intelligent controller xApp External Application External applications (applications running on Near-RT RIC) μApp Micro Application Micro-applications (applications running on Quasi-RT RIC) UE User Equipment User equipment RRC Radio Resource Control Wireless Resource Control FSM Finite State Machine Finite state machine NAS Non-Access Stratum Non-access layer NGAP Next Generation Application Protocol Next-generation application protocol GTP-U GPRS Tunneling Protocol - User Plane General Packet Radio Service Tunneling Protocol - User Plane PDCP Packet Data Convergence Protocol Packet Data Convergence Protocol RLC Radio Link Control Wireless link control MAC Medium Access Control Media access control PHY Physical Layer physical layer CQI Channel Quality Indicator Channel quality indication MCS Modulation and Coding Scheme Modulation coding method BLER Block Error Rate Block error rate HARQ Hybrid Automatic Repeat reQuest Hybrid Automatic Repeat Request F1-C F1 Control Plane F1 Interface Control Face F1-U F1 User Plane F1 Interface User Plane NG-C NG Control Plane NG Interface Control Facet NG-U NG User Plane NG Interface User Plane RNTI Radio Network Temporary Identifier temporary identifier for wireless networks IP Internet Protocol Internet Protocol DoS Denial of Service Denial-of-service attack DDoS Distributed Denial of Service Distributed Denial-of-Service Attack eMBB Enhanced Mobile Broadband Enhanced mobile broadband uRLLC Ultra-Reliable Low Latency Communications Ultra-reliable low-latency communication mMTC massive Machine Type Communications Massive Machine-Type Communication KNN K-Nearest Neighbor K-Nearest Neighbors Algorithm CNN Convolutional Neural Network Convolutional Neural Networks LSTM Long Short-Term Memory Long Short-Term Memory Network HMM Hidden Markov Model Hidden Markov Model DBSCAN Density-Based Spatial Clustering of Applications with Noise Density-based noise spatial clustering SSL Secure Sockets Layer Secure Sockets Layer Protocol SSH Secure Shell Enclosure Protocol APT Advanced Persistent Threat Advanced persistent threats
Claims
1. A multi-plane, cross-layer collaborative online traffic detection system for 5G networks, deployed outside the 5G Open-RAN architecture, characterized in that, The system includes: The data acquisition module is used to synchronously acquire raw data packets from the F1 interface and NG interface between the gNB and the core network through bypass mirroring, and to perform protocol parsing and unified identifier mapping on the raw data packets to output structured signaling data and traffic data. The raw data packets include control plane signaling and data plane traffic. The control plane analysis module has its input end connected to and receives the parsed control plane signaling data output from the data acquisition module. It is used to reconstruct the RRC state evolution path of the user equipment based on the finite state machine model and output control plane abnormal events with protocol semantics. The data plane anomaly detection module has its input end connected to and receives data plane traffic characteristics output from the data acquisition module. It is used to identify traffic anomalies through a dynamic scheduling multi-model mechanism and output data plane anomaly events. The cross-layer context fusion module has its input terminals connected to and receiving control plane abnormal events and status information output from the control plane analysis module, data plane abnormal events and traffic characteristics output from the data plane abnormal detection module, and context indicators from the PHY / MAC layer, respectively. It is used to construct a cross-layer context graph and perform linkage analysis, and output cross-layer correlation alarms and root cause analysis results. The strategy linkage and defense scheduling module has its input end connected to and receives cross-layer related alarms and root cause analysis results output from the cross-layer collaboration module, and its output end connected to and interacts with the O-RAN intelligent controller to generate defense strategies and send them to the network execution unit to achieve a closed loop from detection to defense.
2. The multi-plane cross-layer collaborative online traffic detection system for 5G networks according to claim 1, characterized in that, The data acquisition module is specifically used to perform protocol parsing and message reassembly on the raw data packets acquired by the mirror, and to establish an identifier mapping relationship between RNTI and UE IP; the control plane analysis module and the data plane anomaly detection module, based on this identifier mapping relationship, realize data association of the behavior of the same user equipment on different network planes.
3. The multi-plane cross-layer collaborative online traffic detection system for 5G networks according to claim 1, characterized in that, The control plane analysis module tracks state transitions by constructing an RRC finite state machine model at the user equipment granularity. The detection mechanism of the control plane analysis module integrates a rule engine and an unsupervised learning method to detect at least one of illegal state transitions, signaling storms, and abnormal registration and release.
4. The multi-plane cross-layer collaborative online traffic detection system for 5G networks according to claim 1, characterized in that, The data plane anomaly detection module includes a model scheduler, which is configured to dynamically select and call a lightweight model for rapid screening or a deep model for deep behavioral analysis based on network load signals and service type judgment signals from system monitoring. The lightweight model includes an isolated forest or a random forest, and the deep model includes a convolutional neural network or a long short-term memory network.
5. The multi-plane cross-layer collaborative online traffic detection system for 5G networks according to claim 1, characterized in that, The cross-layer collaboration module receives and integrates the RRC state trajectory from the control plane analysis module, the flow behavior features from the data plane anomaly detection module, and the CQI and MCS indicators from the PHY / MAC layer to construct a cross-layer context graph with network entities as nodes and causal temporal relationships as edges. Based on this graph, windowed event correlation analysis is performed to identify covert attacks that cannot be detected by a single layer.
6. The multi-plane cross-layer collaborative online traffic detection system for 5G networks according to claim 1, characterized in that, The policy linkage and defense scheduling module is connected to the near real-time RAN intelligent controller through the first interface for reporting abnormal inference results; and is connected to the near real-time RAN intelligent controller through the second interface for training scheduling policies; the module finally sends the generated defense policies to the O-DU through the third interface, and the defense policies include at least one of traffic de-weighting for abnormal UEs and rate limiting and blocking for suspicious IPs.
7. An online traffic detection method based on the system according to any one of claims 1 to 6, characterized in that, The method includes the following steps: S1: Non-intrusive acquisition of raw data from the control plane and user plane via bypass mirroring; S2: Parse the raw data to extract control plane features, data plane features, and PHY / MAC layer indicators; S3: Based on the control surface characteristics, control surface anomaly detection is performed using a finite state machine model to generate control surface anomaly signals; S4: Based on the data surface features, data surface anomaly detection is performed through a dynamic model scheduling mechanism to generate data surface anomaly signals; S5: Receive and fuse the control plane anomaly signal, data plane anomaly signal and PHY / MAC layer indicators, perform cross-layer causal correlation analysis, and generate cross-layer alarm signal; S6: Based on the cross-layer alarm signal, generate a defense control signal and send it to the network through the O-RAN interface to complete closed-loop control.
8. The online traffic detection method according to claim 7, characterized in that, The dynamic model scheduling mechanism described in step S4 specifically includes: monitoring system signals that characterize network load, and dynamically assigning detection tasks to a lightweight model or a deep model for execution based on the signal and the result of the service type judgment.
9. The online traffic detection method according to claim 7, characterized in that, The cross-layer causal correlation analysis described in step S5 specifically includes: constructing a cross-layer context graph, verifying the consistency of paths between control plane events, data plane events and PHY / MAC layer events based on the graph, and determining cross-layer collaboration anomalies when path consistency is violated.
10. The online traffic detection method according to claim 7, characterized in that, The completion of closed-loop control in step S6 specifically includes: converting the defense control signal into scheduling instructions that can be executed by the O-DU. The scheduling instructions include adjusting MAC scheduling parameters, updating RLC cache management strategies, or modifying flow table rules to achieve real-time mitigation of abnormal traffic.