A method for enabling, blocking, and testing blacklisted services based on protocol identification.
By adopting a protocol-based method for blacklist service activation, interception, and testing, this approach addresses the issues of insufficient interception accuracy, low activation efficiency, and high rule maintenance costs in existing technologies. It achieves highly accurate and automated blacklist management, adapting to the rapid development of IoT services.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- E SURFING IOT CO LTD
- Filing Date
- 2026-03-02
- Publication Date
- 2026-05-26
AI Technical Summary
Existing blacklist technologies suffer from insufficient accuracy in blocking, low efficiency in opening accounts, lack of verification of effectiveness, and high cost of rule maintenance, making them particularly difficult to manage effectively in IoT businesses.
It adopts a protocol-based approach to enable, block, and test-verify blacklist services. Through multi-dimensional protocol-level identification rules and an automatic rule analysis engine, it achieves automated configuration and blocking of blacklist rules. Combined with the automated management of 5G core network elements, it supports accurate blocking of IP addresses, domain names, URLs, and apps, and ensures the effectiveness of the rules through automatic testing-verification.
It has achieved a blacklist blocking accuracy of 99.9%, an activation efficiency of over 80%, a 70% reduction in operation and maintenance costs, and a significant reduction in rule maintenance costs, thus adapting to the needs of large-scale IoT business.
Smart Images

Figure CN122093142A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of network security, and in particular relates to a method for enabling, blocking and testing blacklisted services based on protocol identification. Background Technology
[0002] With the rapid development of IoT services, the security risks of IoT cards being used unauthorizedly to access IoT services are becoming increasingly prominent, making blacklisting a key means of controlling this risk. Existing blacklisting technologies have the following shortcomings: (1) Insufficient interception accuracy: Traditional blacklists are mostly based on single IP / domain blocking, lacking in-depth identification of L3-L7 protocols and application characteristics, which easily leads to false blocking or missed blocking; (2) Low activation efficiency: The blacklist configuration relies on manual rule parsing and manual issuance of network element instructions. The process is cumbersome and prone to errors, and cannot meet the needs of rapid activation of large-scale blacklists.
[0003] (3) Lack of validity verification: After the blacklist is configured, it needs to be manually tested and verified, which has problems such as untimely verification and incomplete coverage, making it difficult to ensure that the rules are 100% effective; (4) High rule maintenance cost: When adding / deleting blacklist protocol rules, multiple network element configurations need to be updated manually, which is inefficient and prone to configuration inconsistencies. Summary of the Invention
[0004] In view of the shortcomings of the prior art, the purpose of this invention is to provide a method for enabling, blocking and testing blacklisted services based on protocol identification, which can improve the efficiency and security of service management.
[0005] This invention proposes a method for enabling, blocking, and testing blacklisted services based on protocol identification, including: S1, Configure multi-dimensional protocol layer identification rules and blacklist rule priorities, wherein the multi-dimensional protocol layer identification rules include: protocol features based on L3 network layer, L4 transport layer, L7 application layer and deep packet inspection (XDPI) rule base, protocol type and application identifier corresponding to target traffic; the blacklist rule priority corresponds one-to-one with the rule type of the blacklist rule; S2, the rule automatic analysis engine receives blacklist rules, parses the blacklist rules according to the multi-dimensional protocol layer identification rules, identifies the rule type of the blacklist, automatically assigns the priority of the blacklist rule according to the rule type, converts the blacklist rule into a standardized rule, and automatically converts the standardized rule into a dedicated configuration instruction adapted to the 5G core network element according to the configuration requirements of each 5G core network element. S3, the exclusive configuration command is automatically sent to the corresponding 5G core network element through a standardized interface to realize the automated management of the entire life cycle of blacklist services; S4. After the blacklist is configured, a test task is generated. Simulated traffic is actively generated based on the protocol characteristics of the blacklist rules. The user plane function UPF network element intercepts the simulated traffic, compares the actual interception results with the expected rules, and generates a verification report to achieve automatic verification of the interception effect.
[0006] Furthermore, in S2, the rule automatic analysis engine receives a custom protocol blacklist, which includes protocol features containing IP address, domain name, URL address or APP application identifier.
[0007] Furthermore, in S2, the rule type for identifying the blacklist includes: protocol features for identifying blacklist rules, wherein the protocol features include: the protocol name PROTOCOLNAME corresponding to the APP, the IPv4 type or IPv6 type corresponding to the IP, and the HTTP protocol or HTTPS protocol corresponding to the URL address.
[0008] Furthermore, in S2, the blacklist rules are converted into standardized rules, including converting unstructured rules into service names and rule names that can be recognized by network elements.
[0009] Furthermore, by combining the characteristics of the Zixiang system's APPID protocol and the priority of the blacklist rules, the blacklist rules are converted into standardized rules.
[0010] Furthermore, in S2, the 5G core network elements include: Policy Control Function (PCF) network elements, Session Management Function (SMF) network elements, and User Plane Function (UPF) network elements; Based on the configuration requirements of PCF, SMF, and UPF network elements, the standardized rules are automatically converted into PCF service subscription instructions, SMF rule binding instructions, and UPF filter configuration instructions.
[0011] Furthermore, in S3, the automated management of the entire lifecycle of the blacklist service includes: automated activation, automated modification, and automated deletion of the blacklist service.
[0012] Furthermore, the automated activation of blacklist services includes: after the IoT customer relationship management system (CRM) accepts the business, it automatically completes rule parsing, parameter matching, instruction encapsulation and network element distribution through cross-system collaborative links, and synchronously triggers the functions of various 5G core network elements; The automated changes to the blacklist service include: when a change in business requirements is detected, the Customer Relationship Management System (CRM) receives the change request, the Online Signalling Monitoring System (OSS) automatically updates the rule information, the Resource Sharing System synchronizes the parameter adjustment, and the API instructions are repackaged to achieve cross-system parameter synchronization and network element rule updates; The automated removal of blacklisted services includes: when a service is terminated, the Customer Relationship Management (CRM) system initiates a cancellation request, automatically executes the command to revoke the network element, clears rule information, and synchronizes the invalidation of parameters.
[0013] Furthermore, in S4, after the user plane function UPF network element intercepts the simulated traffic, it automatically reports the interception log; the interception log includes: traffic characteristics, interception time, and rule ID.
[0014] Furthermore, in S4, the verification report includes: an identifier indicating whether the verification passed and the reason for the anomaly; If the actual interception result fails to match the expected rule, the verification is deemed to have failed, exception handling is executed, the configuration verification process is automatically triggered, the configuration command is reissued, and the test is repeated.
[0015] The beneficial effects of this invention are as follows: 1. Employing a multi-protocol layer precision interception mechanism significantly improves interception accuracy. This invention innovatively integrates L3-L7 protocol features with the XDPI rule base, supporting protocol-level identification of multiple target types such as IP, domain name, URL, and APP. Combined with priority planning (12700-12801), it achieves precise blacklist interception. This invention achieves precise blacklist interception based on multiple protocol layers (L3 / L4 / L7 / XDPI), solving the problems of single-layer and insufficient accuracy in traditional interception methods. Based on multi-protocol layer identification, this invention avoids false / missed interceptions, achieving a blacklist interception accuracy rate of ≥99.9%, meeting the security control requirements of the Ministry of Industry and Information Technology. This invention relies on the priority parameters of the resource sharing system and the APPID protocol feature code, combined with the network element protocol identification capabilities (L3-L7 / XDPI), ensuring a blacklist and whitelist interception accuracy rate of ≥99.9%, meeting security control requirements, and achieving precise and controllable rule execution.
[0016] 2. Employing blacklist-based automated activation technology improves activation efficiency by over 80%. This invention pioneers a fully automated architecture encompassing "automatic rule analysis - network element adaptation - automatic command issuance," eliminating the need for manual rule parsing and network element configuration. It supports batch operations in new installation / removal scenarios and adapts to large-scale blacklist business needs. This invention constructs an automated process for blacklist rule analysis and network element configuration, replacing manual operations with automated processes. The time for opening a single batch of blacklists is reduced from several hours to minutes, supporting tens of thousands of rule configurations per day. It adapts to large-scale IoT applications, improving the efficiency of blacklist opening and maintenance and reducing human error. This invention achieves an automated configuration engine that replaces the traditional method of manually parsing rules and issuing commands, improving opening / modification / deletion efficiency by over 80% and reducing the human error rate to near zero, significantly enhancing the level of automation. Furthermore, this invention breaks down data barriers between CRM, OSS, resource sharing systems, and network elements, achieving seamless information flow through standardized interfaces and processes. It solves the problems of system isolation and data inconsistency in traditional models, enabling efficient cross-system collaboration.
[0017] 3. Adopting a proactive automatic dial-up testing and verification solution reduces operation and maintenance costs by 70%. This invention achieves real-time verification of blacklist effectiveness by simulating protocol characteristic traffic and automatically comparing interception results, forming a closed loop of "configuration-verification-correction" to solve the problems of low efficiency and incomplete coverage in traditional manual verification. It designs a proactive automatic dial-up testing verification mechanism to verify the blacklist interception effect in real time, ensuring the rules take effect and thus solving the problems of untimely and incomplete verification in traditional methods. This invention uses automatic dial-up testing to replace manual verification; configuration consistency is guaranteed by the system, reducing human error and maintenance workload; automatic dial-up testing reports record the interception effect, supporting rapid location of anomalies and ensuring the long-term stable operation of the blacklist service, achieving traceable rule effectiveness.
[0018] 4. Standardized configuration interface adaptation, strong scalability This invention is based on standardized configuration instructions from PCF / SMF / UPF. Its automatic rule analysis engine can adaptively convert different types of blacklist rules, ensuring cross-network element configuration consistency and reducing maintenance costs. This invention forms a closed-loop management system of "rule parsing - automatic configuration - effect verification," reducing the operational costs of blacklist services and adapting to large-scale IoT application scenarios. This invention supports adding new protocol types (such as new 5G application protocols) and blacklist categories, adapting to future network upgrades and service expansion needs. This invention supports four types of blacklists and whitelists: APP, IP, URL, and domain name, adapting to 5G / 4G multi-network element environments in multiple provinces and cities, meeting the batch configuration needs of large-scale IoT services, and demonstrating strong adaptability across all scenarios. Attached Figure Description
[0019] The accompanying drawings are for illustrative purposes only and are not intended to limit the invention. Throughout the drawings, the same reference numerals denote the same parts. It is obvious that the drawings described below are merely some embodiments of the present invention, and those skilled in the art can obtain other drawings based on these drawings.
[0020] Figure 1 This is a flowchart illustrating a method for enabling, blocking, and testing blacklisted services based on protocol identification, according to an embodiment of the present invention. Detailed Implementation
[0021] To enable those skilled in the art to better understand the technical solutions in the embodiments of the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. It should be understood that these descriptions are merely exemplary and are not intended to limit the scope of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.
[0022] Furthermore, descriptions of well-known structures and techniques are omitted in the following description to avoid unnecessarily obscuring the concepts disclosed in this invention.
[0023] In the description of this invention, it should be noted that, unless otherwise explicitly specified and limited, the terms "center," "upper," "lower," "left," "right," "vertical," "horizontal," "inner," and "outer," etc., indicating orientation or positional relationships based on the orientation or positional relationships shown in the accompanying drawings, are only for the convenience of describing the invention and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation, and therefore should not be construed as a limitation of the invention. Furthermore, the terms "first," "second," and "third" are used for descriptive purposes only and should not be construed as indicating or implying relative importance. The terms "installed," "connected," and "linked" should be interpreted broadly; for example, they can refer to a fixed connection, a detachable connection, or an integral connection; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; and they can refer to the internal communication of two components. Those skilled in the art can understand the specific meaning of the above terms in this invention based on the specific circumstances.
[0024] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numerals in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present invention. Rather, they are merely examples of methods and systems consistent with some aspects of the invention as detailed in the appended claims.
[0025] This invention proposes a method for enabling, blocking, and testing blacklisted services based on protocol identification. It involves network technology, network security, and 5G core network applications. It is a blacklist technology solution with protocol-level accurate blocking, automated enabling, and automated testing capabilities. It collaboratively completes the entire lifecycle management of the blacklist, improving the efficiency and security of service control.
[0026] like Figure 1 As shown, the method for enabling, blocking, and testing blacklisted services based on protocol identification proposed in this invention includes: S1, configure multi-dimensional protocol layer identification rules and blacklist rule priorities.
[0027] In this invention, the multi-dimensional protocol layer identification rules include: protocol features based on the L3 network layer, L4 transport layer, and L7 application layer, as well as the Deep Packet Inspection (XDPI) rule base, the protocol type (e.g., HTTP, HTTPS, DNS) and application identifier (e.g., iQiyi, Youku) corresponding to the target traffic. That is, this invention has a multi-dimensional protocol identification capability integrating L3 (IP address), L4 (port), L7 (URL / application protocol), and XDPI rule bases. The rule types for the blacklist include: IP-based, domain-based, URL-based, and XDPI-based rules, etc.
[0028] Among them, L3 network layer, L4 transport layer, and L7 application layer are layers in the OSI 7-layer model. The DPI rule base is a database that pre-stores the feature codes of various application protocols, supporting the accurate identification of more than 128 applications and providing protocol-level feature support for blacklist interception.
[0029] The priority of blacklist rules corresponds one-to-one with the rule type of the blacklist rules. Specifically, the blacklist rule priorities defined in this invention are: IP / domain name: 12800; URL: 12801; XPI: 12700.
[0030] In this invention, priority is given to traffic over the default public network rules to ensure effective blocking. The User Plane Function (UPF) executes a discard policy on target traffic based on protocol characteristics to ensure accurate blocking.
[0031] S2, the rule automatic analysis engine receives blacklist rules, parses the blacklist rules according to multi-dimensional protocol layer identification rules, identifies the rule type of the blacklist, automatically assigns the priority of the blacklist rule according to the rule type, converts the blacklist rule into a standardized rule, and automatically converts the standardized rule into a dedicated configuration instruction adapted to the 5G core network element according to the configuration requirements of each 5G core network element.
[0032] Specifically, the first step is to input the blacklist rules into the automatic rule analysis engine. These blacklist rules include both those required by the Ministry of Industry and Information Technology (MIIT) and custom protocol-based blacklists. Custom protocol-based blacklists include protocol characteristics such as IP addresses, domain names, URL addresses, or app identifiers. For example: "Block iQiyi (protocol names: qiyi, qiyi_browsing) and IP [157.0.3.1](157.0.3.1), domain name *.pddpic.com, URL .cf.qq.com / ".
[0033] Then, the rule analysis engine parses the blacklist rules based on multi-dimensional protocol layer identification rules to identify the rule types of the blacklist.
[0034] Protocol Recognition Based on Multi-Dimensional Protocol Layer Identification Rules: This technology accurately identifies the protocol type (such as HTTP, HTTPS, DNS) and application identifier (such as iQiyi, Youku) corresponding to target traffic based on L3 (network layer), L4 (transport layer), and L7 (application layer) protocol features and the XDPI (Deep Packet Inspection) rule base.
[0035] Specifically, the protocol characteristics for identifying blacklist rules include: the protocol name PROTOCOLNAME corresponding to the APP, the IPv4 / IPv6 type corresponding to the IP address, and the HTTP / HTTPS protocol corresponding to the URL address.
[0036] After identifying the rule type of the blacklist rule, the priority of the blacklist rule is automatically assigned according to the rule type (e.g., 12800 for IP class and 1280 for URL class), and the blacklist rule is converted into a standardized rule.
[0037] In this invention, the blacklist rules are converted into standardized rules by combining the characteristics of the APPID protocol of the Zixiang system and the priority of the blacklist rules.
[0038] Convert blacklist rules into standardized rules, including converting unstructured rules into service names and rule names that can be recognized by network elements.
[0039] Specifically, the blacklist rules are standardized by converting unstructured rules into service names and rule names that can be recognized by network elements.
[0040] For example, the standardized PCF service configuration is as follows: Business Name: 701000018; Rule Name: iot_up_701000018; Associated with N7 policy, adapted to the Ministry of Industry and Information Technology's blacklist requirements.
[0041] For example, the standardized UPF user template configuration is as follows: Name: iot_up_701000018; Binding URR group: iot_urrg_3700000000; Unified traffic statistics and blocking policy execution standard.
[0042] After the above standardization process, the standardized rules are automatically converted into exclusive configuration instructions adapted to the 5G core network elements according to their configuration requirements.
[0043] In this invention, the adapted 5G core network elements include: PCF (Policy Control Function) network elements, SMF (Session Management Function) network elements, and UPF (User Plane Function) network elements, etc.
[0044] PCF is a key network element in the 5G core network responsible for policy decisions. It undertakes functions such as service contract management and policy rule distribution, and is the core control node for the activation of blacklisted services.
[0045] SMF is a core network element for session management in the 5G core network. It is responsible for receiving blacklist rules issued by PCF, synchronizing them to UPF, and maintaining session-level policy execution.
[0046] UPF is a user plane forwarding network element in the 5G core network, responsible for filtering and intercepting user traffic based on protocol rules. It is the execution node for blacklist interception.
[0047] Correspondingly, the exclusive configuration instructions for 5G core network elements generated by this invention include: PCF service configuration, SMF rule binding, and UPF filter settings, etc.
[0048] Specifically, this invention automatically converts standardized rules into PCF service subscription instructions, SMF rule binding instructions, and UPF filter configuration instructions based on the configuration requirements of PCF, SMF, and UPF network elements.
[0049] In summary, the automatic rule analysis engine has core modules capable of parsing blacklist rules, standardizing formats, and adapting to network elements. It can automatically identify information such as protocol characteristics and target addresses (IP / domain / URL) in the blacklist and generate configuration instructions adapted to PCF / SMF / UPF.
[0050] S3 automatically sends exclusive configuration commands to the corresponding 5G core network elements through standardized interfaces, realizing full-process automation of PCF service signing, SMF rule binding, and UPF filter configuration, so as to complete the full lifecycle automation management of blacklist services.
[0051] Specifically, this invention adopts a "cross-system collaborative architecture + automated configuration engine + full lifecycle management" to construct a three-in-one technical system of "cross-system collaborative linkage - automated intelligent configuration engine - full-process closed-loop control". This breaks through the pain points of system isolation and excessive manual intervention in traditional blacklist and whitelist services, and realizes standardized, automated, and large-scale management of four types of blacklists and whitelists (APP, IP, URL, domain name, etc.) in 5G / 4G network elements (PCF / SMF / UPF, etc.) in 31 provinces. The core architecture and process are as follows: 1. Cross-system collaborative architecture: Multi-system linkage to connect data and command channels With the new generation operating system as the core hub, and linking the IoT customer relationship management system (CRM), online signaling monitoring system (OSS), asset sharing system (asset sharing / asset management system), and acquisition and control module (acquisition and control module), an end-to-end collaborative link is constructed: (1) Business entry layer: Accept targeted blacklist and whitelist business requirements through IoT CRM, and clarify the business type (activation / change / deletion), target object (APP / IP / URL / domain name) and applicable scope (e.g., 5G / 4G networks in 31 provinces).
[0052] (2) Rule Standardization Layer: After receiving CRM business orders, the OSS system automatically parses the requirements and outputs standardized rule information, providing a basis for subsequent instruction generation. Among them, the standardized rule information is used to send standardized messages to network elements, which can be translated into business names and rule names.
[0053] (3) Parameter empowerment layer: The resource sharing system synchronously outputs key configuration parameters, including the priority of blacklist and whitelist rules (such as IP / domain name 12800, URL 12801, XDPI 12700) and the protocol feature code corresponding to APPID, to ensure that the interception strategy is accurately adapted to the network element requirements.
[0054] (4) Instruction Encapsulation Layer: The acquisition and control module integrates OSS standardized rules and resource sharing system parameters (i.e., the resource sharing system synchronously outputs key configuration parameters) and encapsulates them into standardized API instructions that meet the PCF / SMF / UPF network element adaptation requirements, solving the configuration compatibility issues across network elements and provinces. Among them, the standardized API instructions are instruction templates. The dedicated configuration instructions are instructions issued to network elements according to business needs.
[0055] (5) Execution layer: Through the new generation of operation system, standardized API instructions are directed to 5G / 4G network elements in 31 provinces to complete the implementation of rules.
[0056] 2. The automated configuration engine serves as the core technology supporting efficient execution. The automated configuration engine, consisting of an automatic rule analysis engine and an automated configuration module, enables unmanned operation throughout the entire process from rule parsing to network element deployment. (1) Intelligent rule parsing: The engine automatically identifies the standardized rule type (APP / IP / URL / domain name) output by OSS, and combines the APPID protocol characteristics and priority parameters of the resource sharing system to complete the standardization of rule format (e.g., converting it into a service name and rule name that can be recognized by network elements).
[0057] (2) Cross-network element adaptation and conversion: For the configuration requirements of different network elements such as PCF (Policy Control), SMF (Session Management), and UPF (User Plane Forwarding), the standardized rules are automatically converted into dedicated configuration instructions. For example, the service subscription instructions of PCF, the rule binding instructions of SMF, and the filter configuration instructions of UPF.
[0058] (3) Batch automated execution: Supports parallel instruction issuance for network elements in 31 provinces, eliminating the need for manual operation of each province and network element. The time for configuring rules in a single batch is reduced from several hours to minutes, and it can support the processing of tens of thousands of rules per day.
[0059] The configuration automation module receives configuration instructions output by the rule automatic analysis engine and automatically distributes them to PCF, SMF, and UPF network elements through standardized interfaces, completing the entire automated process of blacklist service activation without manual intervention.
[0060] This invention provides automated management of the entire lifecycle of blacklist services, including automated activation, automated modification, and automated deletion, covering a closed loop across all scenarios. Starting with business requirements and ending with the verification of network element rules, this invention achieves automated closed-loop control of the entire lifecycle of blacklists and whitelists.
[0061] (1) Automated activation of blacklist services, including: After the IoT customer relationship management system (CRM) accepts the business, it automatically completes rule parsing, parameter matching, instruction encapsulation and network element distribution through cross-system collaborative links, and synchronously triggers the functions of each 5G core network element (e.g., UPF filter configuration, PCF policy binding, etc.) without manual intervention.
[0062] (2) Automated changes to blacklist services include: when a change in business requirements is detected (such as adding a target IP or modifying the APP interception range), the customer relationship management system (CRM) receives the change request, the online signaling monitoring system (OSS) automatically updates the rule information, the resource sharing system synchronizes the parameter adjustment, and the acquisition and control module repackages the API instructions to achieve cross-system parameter synchronization and one-click update of network element rules.
[0063] (3) Automatic deletion of blacklisted services, including: when the service is terminated, the customer relationship management system (CRM) initiates a cancellation application and executes it automatically in the order of "network element instruction cancellation → rule information clearing → parameter synchronization failure" to avoid invalid rules occupying network element resources.
[0064] This invention enables full-process traceability: the new generation operation system records cross-system collaborative logs, command issuance status, and network element execution results, supports full lifecycle trajectory query of business, and provides support for problem localization and operation and maintenance management.
[0065] S4. After the blacklist is configured, a test task is generated. Based on the protocol characteristics of the blacklist rules, simulated traffic is actively generated. The user plane function UPF network element intercepts the simulated traffic, compares the actual interception results with the expected rules, and generates a verification report to achieve automatic verification of the interception effect.
[0066] This step proactively generates simulated traffic, accesses blacklisted targets based on protocol characteristics, compares the UPF interception results with the expected targets, and generates a verification report to automatically verify the interception effect. This step employs a test task scheduler, a traffic simulation generator, and a rule comparison engine to proactively generate simulated traffic that conforms to the blacklist protocol characteristics, verify the interception effect, and automatically compare the execution results with the expected targets.
[0067] (1) Triggering the test task: After the blacklist is configured, the automatic test module receives the trigger signal and generates the test task.
[0068] Specifically, the testing frequency is set, and testing is conducted immediately after the blacklist is configured; subsequent automatic retesting is performed every 24 hours to ensure that the blacklist rules are effective in the long term.
[0069] (2) Simulated traffic generation: Based on the characteristics of the blacklist protocol, generate targeted simulated traffic.
[0070] Examples of simulated traffic are as follows: Accessing the App: Simulates traffic from the iQiyi app (protocol name: qiyi_browsing).
[0071] Access IP / domain / URL: Simulate access to [157.0.3.1](157.0.3.1), .pddpic.com, and .cf.qq.com / *.
[0072] (3) Interception effect collection: After UPF intercepts the simulated traffic, it automatically reports the interception log (including traffic characteristics, interception time, rule ID). In this invention, after the User Plane Function (UPF) network element intercepts simulated traffic, it automatically reports the interception log; the interception log includes: traffic characteristics, interception time, and rule ID.
[0073] (4) Automatic comparison and verification: The rule comparison engine compares the actual interception results with the expected rules (such as "iQiyi traffic should be blocked") and generates a verification report. In this invention, the verification report includes: an identifier indicating whether the verification passed ("pass / fail" identifier) and the reason for the exception.
[0074] (5) Anomaly handling: If the actual interception result fails to match the expected rule (e.g., the target traffic is not intercepted), the verification is judged to have failed, anomaly handling is executed, the configuration verification process is automatically triggered, the configuration command is reissued and the test is repeated.
[0075] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the embodiments of the present invention, and are not intended to limit them. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention. Any changes or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in the present invention should be included within the protection scope of the present invention.
Claims
1. A method for activating, blocking, and testing blacklisted services based on protocol identification, characterized in that, include: S1, Configure multi-dimensional protocol layer identification rules and blacklist rule priorities, wherein the multi-dimensional protocol layer identification rules include: protocol features based on L3 network layer, L4 transport layer, L7 application layer and deep packet inspection (XDPI) rule base, protocol type and application identifier corresponding to target traffic; the blacklist rule priority corresponds one-to-one with the rule type of the blacklist rule; S2, the rule automatic analysis engine receives blacklist rules, parses the blacklist rules according to the multi-dimensional protocol layer identification rules, identifies the rule type of the blacklist, automatically assigns the priority of the blacklist rule according to the rule type, converts the blacklist rule into a standardized rule, and automatically converts the standardized rule into a dedicated configuration instruction adapted to the 5G core network element according to the configuration requirements of each 5G core network element. S3, the exclusive configuration command is automatically sent to the corresponding 5G core network element through a standardized interface to realize the automated management of the entire life cycle of blacklist services; S4. After the blacklist is configured, a test task is generated. Simulated traffic is actively generated based on the protocol characteristics of the blacklist rules. The user plane function UPF network element intercepts the simulated traffic, compares the actual interception results with the expected rules, and generates a verification report to achieve automatic verification of the interception effect.
2. The method for enabling, blocking, and testing blacklisted services based on protocol identification according to claim 1, characterized in that, In S2, the rule automatic analysis engine receives a custom protocol blacklist, which includes protocol features such as IP address, domain name, URL address or APP application identifier.
3. The method for enabling, blocking, and testing blacklisted services based on protocol identification according to claim 1, characterized in that, In S2, the rule type for identifying the blacklist includes: protocol features for identifying blacklist rules, wherein the protocol features include: the protocol name PROTOCOLNAME corresponding to the APP, the IPv4 type or IPv6 type corresponding to the IP, and the HTTP protocol or HTTPS protocol corresponding to the URL address.
4. The method for enabling, blocking, and testing blacklisted services based on protocol identification according to claim 1, characterized in that, In S2, the blacklist rules are converted into standardized rules, including converting unstructured rules into service names and rule names that can be recognized by network elements.
5. The method for enabling, blocking, and testing blacklisted services based on protocol identification according to claim 4, characterized in that, By combining the characteristics of the Zixiang system's APPID protocol and the priority of blacklist rules, the blacklist rules are converted into standardized rules.
6. The method for enabling, blocking, and testing blacklisted services based on protocol identification according to claim 1, characterized in that, In S2, the 5G core network elements include: Policy Control Function (PCF) network elements, Session Management Function (SMF) network elements, and User Plane Function (UPF) network elements. Based on the configuration requirements of PCF, SMF, and UPF network elements, the standardized rules are automatically converted into PCF service subscription instructions, SMF rule binding instructions, and UPF filter configuration instructions.
7. The method for enabling, blocking, and testing blacklisted services based on protocol identification according to claim 1, characterized in that, In S3, the automated management of the entire lifecycle of the blacklist service includes: automated activation, automated modification, and automated deletion of the blacklist service.
8. The method for enabling, blocking, and testing blacklisted services based on protocol identification according to claim 7, characterized in that, The automated activation of blacklist services includes: after the IoT customer relationship management system (CRM) accepts the business, it automatically completes rule parsing, parameter matching, instruction encapsulation and network element distribution through cross-system collaborative links, and synchronously triggers the functions of various 5G core network elements; The automated changes to the blacklist service include: when a change in business requirements is detected, the Customer Relationship Management System (CRM) receives the change request, the Online Signalling Monitoring System (OSS) automatically updates the rule information, the Resource Sharing System synchronizes the parameter adjustment, and the API instructions are repackaged to achieve cross-system parameter synchronization and network element rule updates; The automated removal of blacklisted services includes: when a service is terminated, the Customer Relationship Management (CRM) system initiates a cancellation request, automatically executes the command to revoke the network element, clears rule information, and synchronizes the invalidation of parameters.
9. The method for enabling, blocking, and testing blacklisted services based on protocol identification according to claim 1, characterized in that, In S4, the UPF network element of the user plane function automatically reports the interception log after intercepting the simulated traffic; The interception log includes: traffic characteristics, interception time, and rule ID.
10. The method for enabling, blocking, and testing blacklisted services based on protocol identification according to claim 1, characterized in that, In S4, the verification report includes: an identifier indicating whether the verification passed and the reason for the exception; If the actual interception result fails to match the expected rule, the verification is deemed to have failed, exception handling is executed, the configuration verification process is automatically triggered, the configuration command is reissued, and the test is repeated.