Mine Multi-Network Integrated Safety Communication Dispatch Method and System
By capturing and parsing registration request signaling in real time in a multi-network converged environment in coal mines, and combining the mine's digital twin model and historical statistical curves, abnormal terminals are identified and attack injection nodes are located. Abnormal signaling is dynamically isolated, solving the problem of the impact of abnormal signaling on the system in the underground communication environment. This achieves optimization of signaling security control and resource scheduling, and improves system stability and reliability.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- BEIJING TANGBAI COMM TECH
- Filing Date
- 2026-03-25
- Publication Date
- 2026-08-04
AI Technical Summary
In the multi-network converged communication environment of underground coal mines, abnormal terminals and abnormal signaling can easily impact the access capabilities of base stations and the processing capabilities of the core network. Existing technologies are insufficient to effectively isolate and process abnormal signaling while ensuring normal communication.
By capturing registration request signaling in the underground multi-network converged environment in real time, parsing base station identifiers, and combining the mine digital twin model and historical statistical curves, abnormal terminals are identified and attack injection nodes are located. The signaling bandwidth ratio is dynamically calculated, and abnormal signaling traffic is directed to the bypass sandbox environment for in-depth analysis and interception, and the signaling bandwidth resources of legitimate terminals are reallocated.
It achieves coordinated optimization of signaling security control and resource scheduling in underground communication scenarios, improves system stability and operational reliability, and ensures the continuity of normal communication.
Smart Images

Figure CN122054146B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of secure communication technology, and more specifically, to a method and system for secure communication scheduling in mines that integrates multiple networks. Background Technology
[0002] In the underground working environment of coal mines, due to the enclosed space and complex structure of the roadways and the frequent dynamic changes in the working area, it is usually necessary to deploy multiple wireless communication networks to achieve personnel positioning, equipment monitoring and production scheduling. These networks are connected to the ground communication core system through multi-network convergence to support unified business operation.
[0003] In actual operation, the number of downhole terminals fluctuates significantly with work shifts, equipment start-up and shutdown, and area switching. Registration request signaling may be reported in a concentrated manner in a short period of time. At the same time, due to differences in equipment, changes in network environment, or abnormal access behavior, some terminals have inconsistent signaling characteristics, which further increases the load uncertainty on the access side.
[0004] Furthermore, underground network links involve multiple levels of forwarding and proxy nodes. Signaling along different paths is prone to latency differences and path overlap during transmission, making it difficult for the core network to identify the source of abnormal traffic in a timely and accurate manner. In a multi-network converged architecture, when abnormal terminals or abnormal signaling occur in concentrated bursts, it can easily impact the base station's access capabilities and the core network's processing capabilities, affecting the establishment of communication and service continuity for normal terminals. Existing technologies mostly rely on static thresholds or single features to process signaling, lacking a dynamic analysis mechanism that combines historical distribution characteristics with real-time behavioral characteristics. Additionally, there is a lack of a handling method that links anomaly identification with bandwidth resource scheduling, making it difficult to effectively isolate and process abnormal signaling while ensuring normal communication. Summary of the Invention
[0005] In order to overcome the above-mentioned defects of the prior art, embodiments of the present invention provide a mine multi-network integrated security communication scheduling method and system to solve the problems mentioned in the background art.
[0006] To achieve the above objectives, the present invention provides the following technical solution: The mine multi-network integrated safety communication scheduling method includes the following steps: S1. Capture the complete message data of the bidirectional registration request signaling transmitted between the underground multi-network converged access layer and the ground IMS core network in real time, and parse out the base station identifier; S2. Based on all the parsed base station identifiers, retrieve the historical statistical curve of the number of terminal registration requests in the corresponding base station coverage area from the mine digital twin model, compare it with the frequency of terminal registration requests reported in the current signaling cycle, and calculate the registration request burst coefficient. S3. When the burst coefficient exceeds the threshold of the base station's rated capacity, parse the terminal capability set field in the registration request signaling, extract the list of voice codec formats supported by the terminal and the network protocol stack fingerprint features, and compare them with the pre-stored legitimate terminal feature library to identify abnormal terminals. S4. Identify the attack injection nodes in the signaling proxy path corresponding to the abnormal terminal, and calculate the attack intensity level of the attacked base station based on the number of abnormal registration request signaling of the attack injection nodes. S5. Dynamically calculate the required isolation signaling bandwidth ratio based on the attack intensity level, and redirect the isolated abnormal signaling traffic to the bypass sandbox environment for deep trapping, parsing, and matching interception. At the same time, reallocate the remaining signaling bandwidth resources to legitimate terminal registration requests.
[0007] As a further aspect of the present invention, in step S1, capturing the complete message data of the bidirectional transmission registration request signaling and parsing out the base station identifier specifically includes: The complete message data of the registration request signaling includes the network layer protocol header, the transport layer protocol header, and the session initiation protocol message and its message body; The message type is identified by the method field in the request line of the session initiation protocol message. When the message type is a registration request, the access identifier domain name is extracted from the host part of the Uniform Resource Identifier of the message, and the domain name is converted into a base station identifier through a pre-set domain name resolution table. The local system time of the session boundary controller capturing the registration request signaling is recorded as the signaling time stamp, and the arrival time interval distribution between consecutive signaling is statistically analyzed according to the base station dimension. Based on the time interval distribution, the network transmission delay characteristics are estimated, and the corresponding transmission delay compensation value is generated. The signaling time stamp is uniformly calibrated and mapped based on the transmission delay compensation value. The signaling time stamp and the base station identifier are used as the association index to store the complete message data in a shared memory queue.
[0008] As a further aspect of the present invention, in step S2, calculating the registration request burst coefficient specifically includes: Read all base station identifiers parsed within the current signaling period from the shared memory queue. Using the base station identifiers as indexes, retrieve the historical statistical curves of the number of terminal registration requests for the corresponding base station within the same historical signaling period from the mine digital twin model constructed based on historical communication records and base station coverage models. The total number of registration request signaling messages actually received by the base station in the current signaling period is counted, and the total number of messages is divided by the duration of the current signaling period to obtain the current average registration request frequency. The current average registration request frequency is compared with the average registration request frequency for the corresponding period in the historical statistical curve, and the result of the ratio is used as the registration request burst coefficient.
[0009] As a further aspect of the present invention, in step S3, extracting the list of voice codec formats supported by the terminal and the fingerprint features of the network protocol stack, and comparing them with a pre-stored legitimate terminal feature library to identify abnormal terminals specifically includes: When the burst coefficient meets the preset triggering conditions, the complete message data of the registration request signaling of the corresponding base station is extracted from the shared memory queue and parsed. The media description line and corresponding attribute line in the message body of the session initiation protocol message are extracted, and the set of voice codec format names supported by the terminal is obtained from it to form a codec format list. Multiple protocol field values are extracted from the network layer protocol header, transport layer protocol header, and session initiation protocol message header fields of the registration request signaling, and then combined and encoded across protocol layers to generate a fixed-length network protocol stack fingerprint feature vector. Using the base station identifier as an index, retrieve the codec format list and fingerprint feature vector of all legal terminals under the corresponding base station from the legal terminal feature library, calculate the matching degree between the current terminal codec format list and the legal terminal list, and calculate the similarity between the current terminal fingerprint feature vector and the legal terminal feature vector. Terminals whose codec format matching degree is lower than a preset matching threshold and whose fingerprint feature vector similarity is lower than a preset similarity threshold are identified as abnormal terminals.
[0010] As a further aspect of the present invention, in step S4, calculating the attack intensity level of the attacked base station specifically includes: Obtain the terminal identifier list marked as abnormal terminal, extract the registration request signaling corresponding to all abnormal terminals under the same base station using the base station identifier as the group key, parse the via field and routing field in the session initiation protocol header field of each registration request signaling, and construct the sequence of proxy nodes traversed by the complete signaling path from the abnormal terminal to the ground IMS core network. Using the base station identifier as an index, the similarity of the signaling proxy path sequences corresponding to each abnormal terminal under the same base station is compared, and the overlap of common nodes between the path sequences is calculated. When the overlap exceeds the preset same-source judgment threshold, it is determined that the abnormal terminals under the base station share the same signaling proxy path. In the shared signaling proxy path, identify proxy nodes that are not included in the set list of legitimate network nodes, treat the proxy nodes as attack injection nodes, and count the number of abnormal registration request signaling corresponding to the attack injection nodes within a preset time window. Determine the attack intensity level of the attacked base station based on the ratio of the number of abnormal registration request signaling to the frequency of normal registration requests.
[0011] As a further aspect of the present invention, in S5, dynamically calculating the required isolation signaling bandwidth ratio based on the attack strength level, and redirecting the isolated abnormal signaling traffic to a bypass sandbox environment for deep trapping, analysis, and matching interception specifically includes: Read the attack intensity level of the attacked base station, set the bandwidth ratio to be isolated according to the attack intensity level and convert it into the corresponding rate-limiting token bucket, identify the abnormal registration request signaling stream corresponding to the attacked base station, copy it, and mirror it to the independent receiving queue in the bypass sandbox environment. In the bypass sandbox environment, the received abnormal registration request signaling stream is simulated to return a temporary response code from the ground IMS core network side to prolong the session duration, inducing the attack source to continuously send the complete signaling payload. The real network layer address and transport layer port of the attack source are then parsed from the captured signaling payload.
[0012] As a further aspect of the present invention, in step S5, reallocating the remaining signaling bandwidth resources to legitimate terminal registration requests specifically includes: The real network layer address and transport layer port of the attack source are parsed and written into a dynamic blacklist. This blacklist is then sent to the access control list to perform a drop action. At the same time, the rate-limiting token bucket quota is released, and the released bandwidth quota is redistributed to the registration request signaling corresponding to the non-attack injection nodes under the attacked base station.
[0013] On the other hand, the present invention provides a mine multi-network integrated safety communication and dispatch system, comprising: The signaling parsing module is used to capture complete message data of registration request signaling in real time between the underground multi-network converged access layer and the ground IMS core network, parse the message type and extract the access network identification field information, and generate the base station identifier by combining the preset mapping relationship; The calibration module is used to record the local system time of the session boundary controller as a signaling time stamp, statistically analyze the signaling arrival time interval distribution by base station dimension, extract transmission delay feature parameters, and complete the time unified calibration mapping. The burst detection module is used to retrieve the historical terminal distribution density curve in the mine digital twin model based on the base station identifier, compare it with the current registration request frequency and calculate the registration request burst coefficient to achieve preliminary identification of abnormal traffic; The abnormal terminal identification module is used to extract the terminal encoding and decoding format list and protocol stack fingerprint features, match them with the legitimate terminal feature library to identify abnormal terminals, and parse the signaling proxy path to locate the attack injection node. The security handling module is used to calculate the signaling bandwidth isolation ratio based on the attack intensity level, redirect abnormal signaling traffic to a bypass sandbox environment for trapping, parsing, and interception, and allocate the remaining bandwidth resources to legitimate terminal registration requests.
[0014] The technical effects and advantages of the mine multi-network integrated security communication scheduling method and system of the present invention are as follows: This invention achieves precise location of signaling sources by real-time capture and parsing of registration request signaling in a multi-network converged environment underground, combined with the mapping relationship between access network identifiers and base stations. Furthermore, it improves data timing consistency and comparability by constructing a time interval distribution-based delay feature model to uniformly calibrate signaling time. Based on this, it accurately identifies sudden traffic scenarios by comparing historical terminal distribution characteristics in the mine's digital twin model with current signaling behavior. It further achieves multi-dimensional abnormal terminal identification by combining terminal encoding / decoding capabilities and protocol stack fingerprint characteristics. Simultaneously, it enhances the ability to trace abnormal sources by locating attack injection nodes through signaling proxy path analysis. During the handling phase, it links attack intensity with bandwidth scheduling strategies, isolating abnormal signaling proportionally and guiding it to a bypass environment for in-depth parsing and interception, while prioritizing legitimate terminal access by releasing resources. This achieves coordinated optimization of signaling security control and resource scheduling in complex underground communication scenarios, improving overall system stability and operational reliability. Attached Figure Description
[0015] Figure 1 This is a schematic diagram of the mine multi-network integrated security communication scheduling method of the present invention; Figure 2 This is a schematic diagram of the structure of the mine multi-network integrated safety communication and dispatch system of the present invention. Detailed Implementation
[0016] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of the present invention. Example 1
[0017] Figure 1 The present invention provides a mine multi-network integrated security communication scheduling method and system, which includes the following steps: S1. Capture the complete message data of the bidirectional registration request signaling transmitted between the underground multi-network converged access layer and the ground IMS core network in real time, and parse out the base station identifier; S2. Based on all the parsed base station identifiers, retrieve the historical statistical curve of the number of terminal registration requests in the corresponding base station coverage area from the mine digital twin model, compare it with the frequency of terminal registration requests reported in the current signaling cycle, and calculate the registration request burst coefficient. S3. When the burst coefficient exceeds the threshold of the base station's rated capacity, parse the terminal capability set field in the registration request signaling, extract the list of voice codec formats supported by the terminal and the network protocol stack fingerprint features, and compare them with the pre-stored legitimate terminal feature library to identify abnormal terminals. S4. Identify the attack injection nodes in the signaling proxy path corresponding to the abnormal terminal, and calculate the attack intensity level of the attacked base station based on the number of abnormal registration request signaling of the attack injection nodes. S5. Dynamically calculate the required isolation signaling bandwidth ratio based on the attack intensity level, and redirect the isolated abnormal signaling traffic to the bypass sandbox environment for deep trapping, parsing, and matching interception. At the same time, reallocate the remaining signaling bandwidth resources to legitimate terminal registration requests.
[0018] In step S1, capturing the complete message data of the bidirectional transmission registration request signaling and parsing out the base station identifier specifically includes: When parsing the complete message data of the registration request signaling, the session boundary controller is selected as the unified acquisition node between the underground multi-network converged access link and the ground IMS core network. The signaling passing through this node is captured packet by packet and written to the buffer in the order of arrival. The captured content covers the network layer protocol header, the transport layer protocol header, and the session initiation protocol message and its message body. In the parsing phase, the request line of the session initiation protocol message is read first, and the method field is identified byte by byte. When the identification result is REGISTER, it is determined to be a registration request signaling. Subsequently, the host field in the Uniform Resource Identifier is no longer relied on as the access source. Instead, the access network identifier field is extracted from the message header. This field is preferentially selected from the P-Access-Network-Info field or other custom extended fields carrying network-related information. When this field exists, the access type and cell identifier information carried in it are parsed, and the access node identifier that can represent the access location is extracted from it. When this field is missing, the source access node address is extracted from the first hop address of the Via field as a supplementary identifier. For the extracted access node identifier, a pre-established mapping table between access nodes and base stations is invoked to complete the conversion. This mapping table is configured according to the mine wireless network deployment topology; for example, it binds the IP address range of wireless access nodes in a specific tunnel to the corresponding base station number, thus obtaining a unique base station identifier. During the parsing process, missing fields or abnormal formats are checked. When a field is incomplete, the signaling message is marked as an abnormal source and recorded separately to ensure that the source of the base station identifier is stable and unique in subsequent processing.
[0019] Using the local system clock of the session boundary controller as a unified time reference, a high-precision timestamp is recorded at the moment of signaling acquisition as a signaling time stamp. Signaling is grouped and stored according to the parsed base station identifier. Within each base station group, continuously arriving registration request signaling is arranged in chronological order. For the same base station, the difference between the arrival times of adjacent signaling is calculated one by one within a fixed time window, forming a time interval sequence. Statistical processing is performed on this sequence, extracting its mean and fluctuation range as network transmission delay characteristic parameters. The time window is set using a fixed configuration, for example, selecting 10 seconds as a statistical period, explicitly derived from empirical statistical results of the underground communication load variation cycle. To avoid interference from individual outliers, intervals exceeding twice the mean are removed during the calculation process to ensure that the obtained delay characteristics stably reflect the actual transmission situation. Subsequently, this delay characteristic parameter is used as a transmission delay compensation value for signaling time processing. The original signaling time stamp is uniformly adjusted according to the compensation value, ensuring that signaling arriving from different paths under the same base station maintains a consistent order on the time axis. The process is performed in a line-by-line correction manner, that is, the corresponding compensation value is subtracted from the time stamp of each signaling and the calibrated time series is regenerated, thereby eliminating the time deviation caused by the multi-level forwarding path.
[0020] The signaling data, after time calibration, is stored using a combined index of base station identifiers and calibrated timestamps. A circular shared memory queue is used as the storage medium to meet the requirements of high-frequency writing and fast reading. Specifically, the base station identifier is used as the primary index to divide the data into multiple independent queue partitions. Signaling data is written sequentially within each partition according to time order. The queue capacity is set using a fixed configuration; for example, each base station partition is set to hold the data of all registration request signaling within the last 60 seconds. When the capacity limit is reached, the oldest data is overwritten in a first-in, first-out (FIFO) manner to ensure the queue is always up-to-date. During the writing process, complete message data is bound to the corresponding base station identifier and calibrated timestamp for storage, and the writing order is strictly controlled to avoid out-of-order writing. Simultaneously, the reading phase provides a fast retrieval capability by base station, enabling subsequent steps to directly obtain the complete signaling set of a specified base station within a specific time range.
[0021] In step S2, the burst coefficient of the registration request is calculated.
[0022] All registration request signaling data within the current signaling period is read from the shared memory queue according to the time window range. During reading, the calibrated signaling timestamp is used as the filtering criterion, and only data records falling within the time interval of the current signaling period are extracted. These data are then grouped and aggregated according to the base station identifier, forming multiple signaling sets corresponding to different base stations. For each base station identifier, after reading, the integrity of the corresponding signaling set is verified, and data entries with abnormal timestamps or missing base station identifiers are removed to ensure that the data participating in the statistics have a unified time reference and clear spatial attribution. Subsequently, using the base station identifier as the search key, historical statistical curves are retrieved from a pre-constructed mine digital twin model. The mine digital twin model is constructed based on communication records and base station coverage data collected during long-term operation. During the construction process, historical registration request signaling is archived according to the time and spatial dimensions, and combined with the coverage area division of the base station in the mine roadway, a three-dimensional relational data structure of "base station-time period-number of registration requests" is established. During the specific invocation, matching is performed based on the time period type corresponding to the current signaling cycle. For example, the day is divided into three fixed time intervals according to shift type: morning shift, afternoon shift, and night shift. For example, the morning shift is from 08:00 to 16:00, the afternoon shift is from 16:00 to 24:00, and the night shift is from 00:00 to 08:00. Historical statistical curves consistent with the shift to which the current signaling cycle belongs are invoked. At the same time, the mine production status labels are used for filtering. The production status labels are derived from the equipment operation status and work area markings in the historical records. For example, tunneling operations, transportation operations, and maintenance status are distinguished as different categories to ensure that the selected historical curves are consistent with the current scenario in terms of time attributes and production status.
[0023] The signaling sets of each base station within the current signaling period are statistically processed base station by base station. First, all registration request signaling corresponding to that base station is counted to obtain the total number of registration requests within the current signaling period. During the counting process, only signaling records that have been fully parsed and have valid identification are counted, excluding duplicate messages and messages with abnormal formats to avoid statistical bias. Then, the average registration request frequency is calculated based on the actual duration of the current signaling period. The signaling period duration is set using a fixed configuration method, for example, setting the statistical period to 10 seconds. This value is explicitly derived from empirical data on the rhythm of changes in field communication load, so that the statistical period can reflect short-term sudden changes without being affected by instantaneous jitter. After obtaining the current average registration request frequency, the average registration request frequency matching the current time period is extracted from the historical statistical curve of the corresponding base station. This historical average is obtained by smoothing the statistical data within multiple historical periods. Specifically, the average of data from multiple consecutive days within the same time period is taken, and outliers that deviate significantly from the normal range are removed, such as records exceeding twice the historical average, to ensure the stability of the historical benchmark. Finally, the ratio of the current average registration request frequency to the historical average registration request frequency is calculated to obtain the burst coefficient, which reflects the degree of change in the current load relative to historical levels. This coefficient is then bound to the base station identifier and stored. This process provides a quantitative description of the current signaling load status of each base station, ensuring that the burst coefficient accurately reflects the deviation of the actual communication pressure from historical benchmarks, while avoiding statistical errors caused by time period differences or changes in production status.
[0024] In step S3, the list of voice codec formats supported by the terminal and the fingerprint features of the network protocol stack are extracted and compared with the pre-stored legitimate terminal feature library to identify abnormal terminals.
[0025] When the burst coefficient corresponding to a base station reaches a pre-set trigger condition, all complete registration request signaling message data for that base station within the current signaling period are extracted from the shared memory queue according to the base station identifier and time range, and the message data is parsed line by line. During parsing, the message body of the session initiation protocol message is located first, and the message body is scanned line by line to identify the media description line with a specific beginning and its associated attribute line. The media type and payload number carried in the media description line are read, and the corresponding codec format name is parsed in conjunction with the attribute line fields. All identifiable codec format names in the same signaling message are written into a list structure in the order of appearance to form the codec format list of that terminal. To ensure the stability of the parsing results, duplicate registration request signaling messages repeatedly reported by the same terminal within a short period are deduplicated, and the first occurrence of the complete codec format list is selected as the representative feature of that terminal. At the same time, messages lacking media description lines or attribute lines are marked and recorded separately, and are not included in subsequent matching calculations to avoid abnormal messages interfering with the identification results. For the standardization of the codec format list, the format names are converted into standard string form according to unified encoding rules, and the order is fixed, such as sorting them alphabetically and then concatenating them, in order to eliminate the differences in field arrangement between different terminals.
[0026] Key field values are extracted from the network layer protocol header, transport layer protocol header, and session initiation protocol message header fields of the parsed registration request signaling, and then combined and encoded across protocol layers according to a predefined field order. Specifically, the source address type identifier and message length fields are extracted at the network layer; the source port range identifier and connection mode identifier are extracted at the transport layer; and the first-hop parameter of the Via field, the content length feature of the User-Agent field, and the Call-ID structure feature are extracted from the session initiation protocol message header field. These field values are concatenated in a fixed order, and each field is discretized. For example, the port range is divided into several intervals and represented by numbers, and the User-Agent length is mapped to interval encoding, thus converting the original diverse fields into a unified discrete encoding sequence. After concatenation, the encoded sequence undergoes fixed-length mapping processing. Specifically, a fixed-length binary bit string is used, and each discrete code is mapped to a corresponding bit segment and filled into the bit string in sequence. If the bit string length is insufficient, a fixed padding value is used to complete the process, ultimately generating a network protocol stack fingerprint feature vector of consistent length. To ensure the stability of fingerprint features, consistency checks are performed on the feature vectors generated by multiple registration requests from the same terminal during the construction process. When the results generated consecutively are consistent, the feature is confirmed to be valid. When there are differences, the result with the highest frequency is selected as the final fingerprint feature, thereby avoiding the impact of field fluctuations caused by network jitter on recognition accuracy.
[0027] Using the base station identifier as the search key, the system retrieves the codec format list and corresponding network protocol stack fingerprint feature vectors of all registered terminals under that base station from the legitimate terminal feature database. This feature database is built based on terminal registration data collected during historical normal operation, and during its construction, the features of each terminal undergo stability screening, retaining only feature records that remain consistent across multiple periods. For the terminal to be identified, its codec format list is first compared item by item with the list of legitimate terminals in the feature database. The percentage of identical codec formats between the two is counted as the codec format matching degree, and a matching threshold is set according to a fixed method. For example, a matching degree below 0.7 is used as an anomaly judgment boundary. This threshold is derived from the overlapping distribution range of normal terminal codec sets in historical statistics. Subsequently, the similarity of the fingerprint feature vector of the current terminal with the fingerprint vectors of each legitimate terminal in the feature database is calculated. Specifically, the similarity value is obtained by comparing each bit and counting the percentage of identical bits, and a similarity threshold is set. For example, a similarity below 0.8 is considered a mismatch. This threshold is determined based on the historical stability analysis results of normal terminal fingerprints. In the final determination process, a terminal is identified as an abnormal terminal and its related signaling records are marked as abnormal data only when both the encoding / decoding format matching degree and the fingerprint similarity are below the corresponding thresholds. In step S4, the attack intensity level of the attacked base station is calculated.
[0028] The system reads the corresponding registration request signaling records one by one from the list of terminal identifiers marked as abnormal terminals. Abnormal terminals are then categorized using the base station identifier as the grouping key. Within each base station group, the complete registration request signaling messages corresponding to all abnormal terminals of that base station are extracted. For each signaling message, the session initiation protocol header field is parsed field by field. Priority is given to reading the forwarding node information at each level recorded sequentially in the Via field, and combining this with the routing nodes explicitly marked in the Route field, a proxy node sequence is constructed according to the actual transmission order of the signaling in the network. During the parsing process, multi-level records in the Via field are extracted in order from the first hop to the last hop. Simultaneously, the address and port information of each hop node are standardized, for example, uniformly converted to the format of "IP address + port" to eliminate differences in field representation between different devices. For the Route field, records are inserted into the corresponding path positions according to their order to form a complete path chain. To avoid instability in path information due to the presence of address translation devices or load balancing nodes in the network, a node merging rule is introduced during path construction. Nodes belonging to the same address range or the same device cluster are merged into the same logical node. For example, consecutive nodes with the same address prefix are merged into a single node identifier, thereby improving the stability of path representation. After path extraction, the proxy node sequence corresponding to each signaling message is bound and stored with its terminal identifier and base station identifier. Signaling messages with abnormal path lengths or missing nodes are removed to ensure that the path data participating in subsequent analysis is complete and structurally consistent.
[0029] Using base station identifiers as indexes, the proxy path sequences corresponding to abnormal terminals under the same base station are compared one by one. First, the length of all path sequences is normalized. For paths with inconsistent lengths, they are unified to a fixed length by padding or truncation. For example, the maximum path length is set to 8 nodes. When the path length is insufficient, empty node identifiers are added to the end. When the path length exceeds the limit, the first 8 key nodes are truncated, thus ensuring that the comparison process is carried out under a unified dimension. Then, any two path sequences are compared at the node level. The nodes corresponding to the positions in the two paths are counted to see if they are the same, and the proportion of the number of identical nodes to the path length is calculated as the path overlap. To avoid overall judgment distortion due to changes in individual nodes in the path, a sliding window comparison method is introduced. That is, continuous subsequences are selected in the path sequence for matching. When there are three or more consecutive nodes that are completely identical, they are included in the overlap statistics. After the overlap calculation of all paths is completed, the results are compared with a pre-set homogeneity judgment threshold. The threshold is set in a fixed configuration manner. For example, 0.6 is used as the judgment boundary. This value is derived from the statistical analysis results of the overlap of historical normal paths and abnormal paths. When the path overlap among a group of abnormal terminals all exceeds a certain threshold, it is determined that the terminals in this group share the same signaling proxy path, and this path is marked as a suspected path of unified origin. A time concentration constraint is added to the determination process; that is, path comparison is only performed on abnormal terminals appearing within the same time window. The time window is set with a fixed configuration, such as 10 seconds, to ensure that the signaling involved in the comparison has temporal correlation, thereby avoiding misjudgment of the same source relationship due to path overlap occurring over a long period of time. Through the above multi-dimensional constraint path similarity analysis, stable clustering and identification of the source paths of abnormal terminals are achieved.
[0030] A node-by-node scan is performed on the sequence of proxy nodes identified as sharing paths. All nodes in the path are compared with a pre-established list of legitimate network nodes. This list is generated based on the mine communication network topology configuration and includes the addresses of all registered access nodes, core network nodes, and intermediate forwarding devices. This list is derived from the network deployment list and device configuration records. During the comparison, if a node in the path does not appear in the list of legitimate network nodes, it is marked as an abnormal node. Furthermore, the frequency of its appearance in different abnormal terminal paths is statistically analyzed to filter out stable nodes. Nodes whose appearance frequency exceeds a set threshold are identified as attack injection nodes. This frequency threshold is set in a fixed manner; for example, a node is considered stable if it appears more than 5 times within a 10-second time window. After identifying the attack injection node, the number of abnormal registration request signaling messages corresponding to that node is counted within the same time window. Simultaneously, the normal registration request frequency is extracted from the normal signaling statistics of the same base station as a reference value. The ratio of the abnormal signaling quantity to the normal frequency is calculated to obtain a quantitative indicator reflecting the attack intensity. Attack strength is graded based on this ratio range. For example, a ratio greater than 1 and less than 2 is defined as Level 1 strength, a ratio greater than 2 and less than 4 is defined as Level 2 strength, and a ratio greater than 4 is defined as Level 3 strength. The grading intervals are determined based on the range of signaling load changes in historical attack events. Finally, the attack injection node and its corresponding attack strength level are associated and recorded with the base station identifier, and the remaining signaling bandwidth resources are reallocated to legitimate terminal registration requests.
[0031] In S5, the required isolation signaling bandwidth ratio is dynamically calculated based on the attack intensity level, and the isolated abnormal signaling traffic is directed to the bypass sandbox environment for deep trapping, analysis, and matching interception.
[0032] The attack intensity level corresponding to the base station identified as being under attack is read, and the corresponding bandwidth isolation ratio is determined by looking up a table based on this level. The bandwidth isolation ratio is set using a fixed configuration method. For example, the attack intensity level is divided into three levels, where level one corresponds to an isolation ratio of 0.2, level two to 0.4, and level three to 0.6. These ratio values are derived from statistical results of the impact of different attack intensities on the base station's access capabilities in historical attack scenarios. After determining the isolation ratio, it is converted into rate-limiting token bucket parameters, specifically including the token generation rate and bucket capacity. The token generation rate is set according to the base station's current available bandwidth multiplied by the remaining ratio, and the bucket capacity is set according to the maximum number of signaling requests allowed per second. For example, when the base station's rated processing capacity is 1,000 registration request signaling requests per second, under level two attack intensity, the token generation rate is set to 600 tokens per second, and the bucket capacity is set to 600, thereby achieving rate limiting control for abnormal signaling. In actual execution, the signaling flow is first classified according to the aforementioned abnormal terminal identification results. Registration request signaling marked as abnormal terminals is assigned to the abnormal signaling flow, while the remaining signaling is assigned to the normal signaling flow. Before entering the core network, the abnormal signaling flow is copied, and the copied signaling messages are written to the bypass channel. At the same time, the original abnormal signaling is no longer forwarded to the terrestrial IMS core network, but is directly discarded or blocked according to the rate-limiting policy to avoid impacting the core network. During the copying process, the message content is kept complete and consistent, and a base station identifier and time stamp are added to each signaling in the bypass channel. Then, the copied signaling is written sequentially to the independent receiving queue in the bypass sandbox environment to ensure that bypass processing is executed in isolation from the main path.
[0033] Each abnormal registration request signaling entering the bypass sandbox environment is processed interactively. A simulated terrestrial IMS core network response logic is constructed, returning a temporary response message to each registration request signaling to maintain the session state. This response message is generated using the standard session initiation protocol format, such as returning "100 Trying" and "401 Unauthorized" or other custom response codes, while maintaining necessary header field consistency to induce the attacking source to continue subsequent authentication interactions, thereby inducing it to send the complete signaling payload. During the interaction process, the correlation between each round of requests and responses is recorded, and the signaling content during continuous interactions is fully captured, including subsequent authentication information, additional header fields, and potentially carried source address information. To ensure the real address of the attacking source can be obtained, address fields in the message that may have been modified by intermediate devices are restored during processing. Specifically, the source address in the network layer protocol header is compared with the first-hop node address recorded in the session protocol header. When there is a difference, the source address in the network layer protocol header is taken as the real source address, and the communication port of the attacking source is determined by combining the source port information in the transport layer protocol header. For scenarios involving multi-level proxy forwarding, consistency checks are performed on address changes across multiple interaction messages. Addresses that remain unchanged throughout these interactions are selected as the final identification result, thus avoiding misjudgments caused by changes in intermediate node addresses. After parsing, the actual network layer address and transport layer port corresponding to each attack source are recorded and associated with the corresponding base station identifier for storage.
[0034] During the blacklist update and bandwidth reallocation phase, the parsed attack source network layer address and transport layer port are written into a dynamic blacklist. This blacklist is maintained using an expiration-limited recording method. Each record includes the address, port, and effective time, with a fixed validity period, such as 30 minutes. Records expire automatically after this time to prevent long-term false blocking. After writing, the blacklist is synchronously distributed to the access control list execution unit. Signaling matching the blacklist rules is directly discarded on the data forwarding path, blocking attack traffic at the source. Simultaneously, tokens released from the aforementioned rate-limiting token bucket due to blocked abnormal traffic are counted. The number of released tokens is converted into available bandwidth quotas and reallocated according to base station identifiers to the registration request signaling processing queues corresponding to legitimate terminals. This means the remaining terminals after removing all terminals corresponding to attack injection nodes are allocated proportionally based on the current number of requests from legitimate terminals, for example, based on the proportion of requests from each terminal in the current period, ensuring resource allocation aligns with actual demand. By implementing the above methods, the attack traffic blocking and resource recovery are executed simultaneously. After the abnormal traffic of the attacked base station is isolated, its remaining bandwidth can be quickly restored and the access requests of legitimate terminals can be prioritized. The entire process is completed continuously within the same time window, ensuring a stable linkage between bandwidth scheduling and security handling. Example 2
[0035] The difference between Embodiment 2 and Embodiment 1 is that this embodiment introduces a multi-network integrated safety communication and dispatching system for mines.
[0036] Figure 2 A schematic diagram of the mine multi-network integrated safety communication and dispatch system of the present invention is given. The mine multi-network integrated safety communication and dispatch system includes: The signaling parsing module is used to capture complete message data of registration request signaling in real time between the underground multi-network converged access layer and the ground IMS core network, parse the message type and extract the access network identification field information, and generate the base station identifier by combining the preset mapping relationship; The calibration module is used to record the local system time of the session boundary controller as a signaling time stamp, statistically analyze the signaling arrival time interval distribution by base station dimension, extract transmission delay feature parameters, and complete the time unified calibration mapping. The burst detection module is used to retrieve the historical terminal distribution density curve in the mine digital twin model based on the base station identifier, compare it with the current registration request frequency and calculate the registration request burst coefficient to achieve preliminary identification of abnormal traffic; The abnormal terminal identification module is used to extract the terminal encoding and decoding format list and protocol stack fingerprint features, match them with the legitimate terminal feature library to identify abnormal terminals, and parse the signaling proxy path to locate the attack injection node. The security handling module is used to calculate the signaling bandwidth isolation ratio based on the attack intensity level, redirect abnormal signaling traffic to a bypass sandbox environment for trapping, parsing, and interception, and allocate the remaining bandwidth resources to legitimate terminal registration requests.
[0037] The above embodiments can be implemented, in whole or in part, by software, hardware, firmware, or any other combination thereof. When implemented using software, the above embodiments can be implemented, in whole or in part, as a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more sets of available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium. The semiconductor medium can be a solid-state drive.
[0038] Those skilled in the art will recognize that the modules and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0039] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and modules described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0040] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of modules is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple modules or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or modules may be electrical, mechanical, or other forms.
[0041] The modules described as separate components may or may not be physically separate. The components shown as modules may or may not be physical modules; they may be located in one place or distributed across multiple network modules. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.
[0042] In addition, the functional modules in the various embodiments of this application can be integrated into one processing module, or each module can exist physically separately, or two or more modules can be integrated into one module.
[0043] If the aforementioned functions are implemented as software functional modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0044] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
[0045] In conclusion, the above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. A mine multi-network fusion safety communication dispatching method, characterized in that, Includes the following steps: S1. Capture the complete message data of the bidirectional registration request signaling transmitted between the underground multi-network converged access layer and the ground IMS core network in real time, and parse out the base station identifier; S2. Based on all the parsed base station identifiers, retrieve the historical statistical curve of the number of terminal registration requests in the corresponding base station coverage area from the mine digital twin model, compare it with the frequency of terminal registration requests reported in the current signaling cycle, and calculate the registration request burst coefficient. In step S2, calculating the registration request burst coefficient specifically includes: Read all base station identifiers parsed within the current signaling period from the shared memory queue. Using the base station identifiers as indexes, retrieve the historical statistical curves of the number of terminal registration requests for the corresponding base station within the same historical signaling period from the mine digital twin model constructed based on historical communication records and base station coverage models. The total number of registration request signaling messages actually received by the base station in the current signaling period is counted, and the total number of messages is divided by the duration of the current signaling period to obtain the current average registration request frequency. The current average registration request frequency is compared with the average registration request frequency for the corresponding period in the historical statistical curve, and the result of the ratio is used as the registration request burst coefficient. S3. When the burst coefficient exceeds the threshold of the base station's rated capacity, parse the terminal capability set field in the registration request signaling, extract the list of voice codec formats supported by the terminal and the network protocol stack fingerprint features, and compare them with the pre-stored legitimate terminal feature library to identify abnormal terminals. S4. Identify the attack injection nodes in the signaling proxy path corresponding to the abnormal terminal, and calculate the attack intensity level of the attacked base station based on the number of abnormal registration request signaling of the attack injection nodes. S5. Dynamically calculate the required isolation signaling bandwidth ratio based on the attack intensity level, and redirect the isolated abnormal signaling traffic to the bypass sandbox environment for deep trapping, parsing, and matching interception. At the same time, reallocate the remaining signaling bandwidth resources to legitimate terminal registration requests.
2. The mine multi-network integrated security communication scheduling method according to claim 1, characterized in that, In step S1, capturing the complete message data of the bidirectional transmission registration request signaling and parsing out the base station identifier specifically includes: The complete message data of the registration request signaling includes the network layer protocol header, the transport layer protocol header, and the session initiation protocol message and its message body; The message type is identified by the method field in the request line of the session initiation protocol message. When the message type is a registration request, the access identifier domain name is extracted from the host part of the Uniform Resource Identifier of the message, and the domain name is converted into a base station identifier through a pre-set domain name resolution table. The local system time of the session boundary controller capturing the registration request signaling is recorded as the signaling time stamp, and the arrival time interval distribution between consecutive signaling is statistically analyzed according to the base station dimension. Based on the time interval distribution, the network transmission delay characteristics are estimated, and the corresponding transmission delay compensation value is generated. The signaling time stamp is uniformly calibrated and mapped based on the transmission delay compensation value. The signaling time stamp and the base station identifier are used as the association index to store the complete message data in a shared memory queue.
3. The mine multi-network integrated security communication scheduling method according to claim 1, characterized in that, In step S3, extracting the list of voice codec formats supported by the terminal and the fingerprint features of the network protocol stack, and comparing them with the pre-stored legitimate terminal feature library to identify abnormal terminals specifically includes: When the burst coefficient meets the preset triggering conditions, the complete message data of the registration request signaling of the corresponding base station is extracted from the shared memory queue and parsed. The media description line and corresponding attribute line in the message body of the session initiation protocol message are extracted, and the set of voice codec format names supported by the terminal is obtained from it to form a codec format list. Multiple protocol field values are extracted from the network layer protocol header, transport layer protocol header, and session initiation protocol message header fields of the registration request signaling, and then combined and encoded across protocol layers to generate a fixed-length network protocol stack fingerprint feature vector. Using the base station identifier as an index, retrieve the codec format list and fingerprint feature vector of all legal terminals under the corresponding base station from the legal terminal feature library, calculate the matching degree between the current terminal codec format list and the legal terminal list, and calculate the similarity between the current terminal fingerprint feature vector and the legal terminal feature vector. Terminals whose codec format matching degree is lower than a preset matching threshold and whose fingerprint feature vector similarity is lower than a preset similarity threshold are identified as abnormal terminals.
4. The mine multi-network integrated security communication scheduling method according to claim 1, characterized in that, In step S4, calculating the attack strength level of the attacked base station specifically includes: Obtain the terminal identifier list marked as abnormal terminal, extract the registration request signaling corresponding to all abnormal terminals under the same base station using the base station identifier as the group key, parse the via field and routing field in the session initiation protocol header field of each registration request signaling, and construct the sequence of proxy nodes traversed by the complete signaling path from the abnormal terminal to the ground IMS core network. Using the base station identifier as an index, the similarity of the signaling proxy path sequences corresponding to each abnormal terminal under the same base station is compared, and the overlap of common nodes between the path sequences is calculated. When the overlap exceeds the preset same-source judgment threshold, it is determined that the abnormal terminals under the base station share the same signaling proxy path. In the shared signaling proxy path, identify proxy nodes that are not included in the set list of legitimate network nodes, treat the proxy nodes as attack injection nodes, and count the number of abnormal registration request signaling corresponding to the attack injection nodes within a preset time window. Determine the attack intensity level of the attacked base station based on the ratio of the number of abnormal registration request signaling to the frequency of normal registration requests.
5. The mine multi-network integrated security communication scheduling method according to claim 1, characterized in that, In S5, the required isolation signaling bandwidth ratio is dynamically calculated based on the attack strength level, and the isolated abnormal signaling traffic is directed to a bypass sandbox environment for deep trapping, analysis, and matching interception. This specifically includes: Read the attack intensity level of the attacked base station, set the bandwidth ratio to be isolated according to the attack intensity level and convert it into the corresponding rate-limiting token bucket, identify the abnormal registration request signaling stream corresponding to the attacked base station, copy it, and mirror it to the independent receiving queue in the bypass sandbox environment. In the bypass sandbox environment, the received abnormal registration request signaling stream is simulated to return a temporary response code from the ground IMS core network side to prolong the session duration, inducing the attack source to continuously send the complete signaling payload. The real network layer address and transport layer port of the attack source are then parsed from the captured signaling payload.
6. The mine multi-network integrated security communication scheduling method according to claim 1, characterized in that, In step S5, reallocating the remaining signaling bandwidth resources to legitimate terminal registration requests specifically includes: The real network layer address and transport layer port of the attack source are parsed and written into a dynamic blacklist. This blacklist is then sent to the access control list to perform a drop action. At the same time, the rate-limiting token bucket quota is released, and the released bandwidth quota is redistributed to the registration request signaling corresponding to the non-attack injection nodes under the attacked base station.
7. A mine multi-network integrated safety communication and dispatch system, used to implement the mine multi-network integrated safety communication and dispatch method according to any one of claims 1-6, characterized in that, include: The signaling parsing module is used to capture complete message data of registration request signaling in real time between the underground multi-network converged access layer and the ground IMS core network, parse the message type and extract the access network identification field information, and generate the base station identifier by combining the preset mapping relationship; The calibration module is used to record the local system time of the session boundary controller as a signaling time stamp, statistically analyze the signaling arrival time interval distribution by base station dimension, extract transmission delay feature parameters, and complete the time unified calibration mapping. The burst detection module is used to retrieve the historical terminal distribution density curve in the mine digital twin model based on the base station identifier, compare it with the current registration request frequency and calculate the registration request burst coefficient to achieve preliminary identification of abnormal traffic; The abnormal terminal identification module is used to extract the terminal encoding and decoding format list and protocol stack fingerprint features, match them with the legitimate terminal feature library to identify abnormal terminals, and parse the signaling proxy path to locate the attack injection node. The security handling module is used to calculate the signaling bandwidth isolation ratio based on the attack intensity level, redirect abnormal signaling traffic to a bypass sandbox environment for trapping, parsing, and interception, and allocate the remaining bandwidth resources to legitimate terminal registration requests.