Pfc signaling exception detection method and device, electronic equipment and storage medium

CN122802273APending Publication Date: 2026-09-22CHINA MOBILE CHENGDU INFORMATION & TELECOMM TECH CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202611258014.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-08-19
Publication Date
2026-09-22

AI Technical Summary

Technical Problem

[0005]本申请提供一种PFCP信令异常检测方法、装置、电子设备及存储介质,用以解决现有技术中未能充分考虑信令传播路径和网络功能实体间的交互模式,难以有效建模PFCP信令的拓扑依赖性的缺陷

Benefits of technology

[0018]本申请还提供一种非暂态计算机可读存储介质,其上存储有计算机程序,该计算机程序被处理器执行时实现如上述任一种所述PFCP信令异常检测方法。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122802273A_ABST
    Figure CN122802273A_ABST
Patent Text Reader

Abstract

The application provides a PFCP signaling anomaly detection method and device, electronic equipment and storage medium, belonging to the artificial intelligence technical field, and the method comprises the following steps: based on the dynamic heterogeneous graph of the PFCP signaling set, the topological feature vector of the PFCP signaling set is extracted; the node of the dynamic heterogeneous graph represents the network function entity associated with the PFCP signaling; the edge of the dynamic heterogeneous graph represents the signaling interaction relationship of the PFCP signaling; the node feature of the dynamic heterogeneous graph represents the content embedding vector corresponding to the PFCP signaling associated with the network function entity; based on the time sequence feature vector and the topological feature vector of the PFCP signaling set, the global reconstruction feature vector is determined; based on the global reconstruction feature vector, the abnormal PFCP signaling in the PFCP signaling set is determined. The application fully models the topological dependence of the PFCP signaling, and realizes the detection of the abnormal PFCP signaling related to the topological structure.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of artificial intelligence technology, and in particular to a method, apparatus, electronic device and storage medium for detecting PFCP signaling anomalies. Background Technology

[0002] PFCP (Packet Forwarding Control Protocol) signaling anomaly detection is a crucial step in ensuring the secure operation of a signaling security gateway.

[0003] Currently, common solutions for PFCP signaling anomaly detection include traditional machine learning approaches. These approaches employ feature engineering-based machine learning algorithms, such as Isolation Forest and Support Vector Machine, to extract statistical features from signaling traffic for anomaly classification.

[0004] However, traditional machine learning solutions fail to fully consider the signaling propagation path and the interaction patterns between network functional entities, making it difficult to effectively model the topology dependency of PFCP signaling and detect abnormal behaviors related to the topology. Summary of the Invention

[0005] This application provides a PFCP signaling anomaly detection method, apparatus, electronic device, and storage medium to address the shortcomings of existing technologies that fail to adequately consider signaling propagation paths and interaction patterns between network functional entities, making it difficult to effectively model the topology dependencies of PFCP signaling.

[0006] This application provides a PFCP signaling anomaly detection method, including: Based on the dynamic heterogeneous graph of the PFCP signaling set, the topological feature vector of the PFCP signaling set is extracted; the nodes of the dynamic heterogeneous graph represent network functional entities associated with PFCP signaling; the edges of the dynamic heterogeneous graph represent the signaling interaction relationship of PFCP signaling; the node features of the dynamic heterogeneous graph represent the content embedding vector corresponding to the PFCP signaling associated with the network functional entities. Based on the timing feature vector of the PFCP signaling set and the topology feature vector, the global reconstruction feature vector is determined; Based on the global reconstruction feature vector, abnormal PFCP signaling in the PFCP signaling set is determined.

[0007] According to the PFCP signaling anomaly detection method provided in this application, for each PFCP signaling in the PFCP signaling set, the content embedding vector corresponding to the PFCP signaling is determined based on the following methods: The content embedding vector corresponding to the PFCP signaling is determined based on the sub-embedding vectors corresponding to multiple information elements in the PFCP signaling; for each information element in the PFCP signaling, the sub-embedding vector corresponding to the information element is determined based on the following methods: The content encoding of the information element is determined based on the content byte sequence of the information element; The attribute encoding of the information element is determined based on the attribute type of the information element; The position encoding of the information element is determined based on the position information of the information element; The sub-embedding vector corresponding to the information element is determined based on the content encoding, the attribute encoding, and the position encoding.

[0008] According to the PFCP signaling anomaly detection method provided in this application, the step of determining the location code of the information element based on the location information of the information element includes: determining the time location code of the information element according to the element sequence index of the information element in its respective PFCP signaling; determining the topology location code of the information element according to the network function entity associated with the PFCP signaling of the information element; and determining the location code of the information element based on the time location code and the topology location code.

[0009] According to the PFCP signaling anomaly detection method provided in this application, the step of determining a global reconstruction feature vector based on the temporal feature vector and the topological feature vector of the PFCP signaling set includes: extracting the temporal feature vector of the PFCP signaling set based on the content embedding vectors corresponding to multiple PFCP signaling in the PFCP signaling set; determining a global fusion feature vector based on the temporal feature vector and the topological feature vector; and performing feature representation reconstruction processing on the global fusion feature vector to obtain the global reconstruction feature vector.

[0010] According to the PFCP signaling anomaly detection method provided in this application, the step of extracting the temporal feature vector of the PFCP signaling set based on the content embedding vectors corresponding to multiple PFCP signalings in the PFCP signaling set includes: determining the overall embedding vector of the PFCP signaling set based on the content embedding vectors corresponding to multiple PFCP signalings in the PFCP signaling set; inputting the overall embedding vector into a temporal feature extraction model to obtain the temporal feature vector output by the temporal feature extraction model; wherein, the temporal feature extraction model includes a sequence mixer, a channel mixer, a residual connection layer, a normalization layer, and an output layer connected in sequence; the sequence mixer is built based on a permutation and block diagonal product matrix.

[0011] According to the PFCP signaling anomaly detection method provided in this application, the step of determining a global fusion feature vector based on the temporal feature vector and the topological feature vector includes: determining a first sub-fusion vector based on the temporal feature vector and a first weight factor; determining a second sub-fusion vector based on the topological feature vector and a second weight factor; determining a fusion feature vector based on the first sub-fusion vector and the second sub-fusion vector; and obtaining the global fusion feature vector based on the fusion feature vector and the topological feature vector; wherein the sum of the first weight factor and the second weight factor is 1; and the first weight factor and the second weight factor are determined based on a gating attention mechanism.

[0012] According to the PFCP signaling anomaly detection method provided in this application, the step of performing feature representation reconstruction processing on the global fusion feature vector to obtain the global reconstructed feature vector includes: inputting the global fusion feature vector into a temporal feature reconstruction model to obtain a reconstructed temporal feature vector output by the temporal feature reconstruction model; the structure of the temporal feature reconstruction model is symmetrical with the structure of the temporal feature extraction model; determining the global reconstructed feature vector based on the reconstructed temporal feature vector; and determining the abnormal PFCP signaling in the PFCP signaling set based on the global reconstructed feature vector, including: determining the sub-reconstructed feature vectors corresponding to multiple PFCP signalings in the PFCP signaling set based on the global reconstructed feature vector; performing cluster analysis on the multiple sub-reconstructed feature vectors, and determining the sub-reconstructed feature vectors with a classification reliability less than a preset reliability threshold as abnormal sub-reconstructed feature vectors; and determining the PFCP signaling corresponding to the abnormal sub-reconstructed feature vectors as the abnormal PFCP signaling.

[0013] According to the PFCP signaling anomaly detection method provided in this application, before extracting the topological feature vector of the PFCP signaling set based on the dynamic heterogeneous graph of the PFCP signaling set, the method further includes: updating the model parameters of the autoencoder, the model parameters of the autodecoder, and the initial cluster centers of the cluster head based on the joint training loss of the autoencoder, the autodecoder, and the cluster head; wherein, the joint training loss is determined based on the reconstruction loss, the clustering loss, and the topological consistency loss; the reconstruction loss is determined based on the global fusion feature vector and the global reconstruction feature vector during the joint training process; the topological consistency loss is determined based on the topological feature vector and the reconstructed topological graph during the joint training process; the clustering loss is determined based on the joint training loss... The classification reliability during the training process is determined; the autoencoder is used to implement the dynamic heterogeneous graph based on the PFCP signaling set, extract the topological feature vector of the PFCP signaling set, and also to implement the extraction of the temporal feature vector of the PFCP signaling set based on the content embedding vectors corresponding to multiple PFCP signaling in the PFCP signaling set, and further to implement the determination of the global fusion feature vector based on the temporal feature vector and the topological feature vector; the autodecoder is used to implement the feature representation reconstruction processing of the global fusion feature vector to obtain the global reconstructed feature vector; the clustering head is used to implement the determination of abnormal PFCP signaling in the PFCP signaling set based on the global reconstructed feature vector.

[0014] According to the PFCP signaling anomaly detection method provided in this application, the initial cluster centers are determined in the following manner: A preset number of first PFCP signaling normal samples are randomly selected to determine the initial centers of the preset number of clusters; the first PFCP signaling normal samples are used to determine the initial centers; based on the topological sensing distance between the second PFCP signaling normal samples and the first PFCP signaling normal samples, multiple second PFCP signaling normal samples are respectively assigned to the initial centers with the closest topological sensing distance; the second PFCP signaling normal samples are used to adjust the initial centers; based on the assigned second PFCP signaling normal samples and the first PFCP signaling normal samples, the initial centers are adjusted to determine the initial cluster centers.

[0015] According to the PFCP signaling anomaly detection method provided in this application, the PFCP signaling anomaly detection method is applied to the national cryptographic signaling security gateway.

[0016] This application also provides a PFCP signaling anomaly detection device, including: An extraction module is used to extract the topological feature vector of the PFCP signaling set based on a dynamic heterogeneous graph of the PFCP signaling set; the nodes of the dynamic heterogeneous graph represent network functional entities associated with PFCP signaling; the edges of the dynamic heterogeneous graph represent the signaling interaction relationships of PFCP signaling; and the node features of the dynamic heterogeneous graph represent the content embedding vectors corresponding to the PFCP signaling associated with the network functional entities. The feature reconstruction module is used to determine the global reconstruction feature vector based on the timing feature vector of the PFCP signaling set and the topology feature vector; An anomaly detection module is used to determine abnormal PFCP signaling in the PFCP signaling set based on the global reconstructed feature vector.

[0017] This application also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement any of the PFCP signaling anomaly detection methods described above.

[0018] This application also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the PFCP signaling anomaly detection method as described above.

[0019] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the PFCP signaling anomaly detection method as described above.

[0020] The PFCP signaling anomaly detection method, apparatus, electronic device, and storage medium provided in this application construct nodes and edges of a dynamic heterogeneous graph of the PFCP signaling set based on the network functional entities and signaling interaction relationships associated with the PFCP signaling. The node features of the dynamic heterogeneous graph are determined based on the content embedding vectors corresponding to the PFCP signaling associated with the network functional entities. This results in a dynamic heterogeneous graph that fully models the topological dependencies of the propagation paths between PFCP signaling and the interaction patterns between network functional entities. On one hand, topological features are extracted from the dynamic heterogeneous graph of the PFCP signaling set; on the other hand, temporal features are extracted from the content embedding vectors of each PFCP signaling in the PFCP signaling set. Feature fusion and feature reconstruction are performed on the topological and temporal features. Finally, abnormal PFCP signaling in the PFCP signaling set is detected based on the globally reconstructed feature vector after feature reconstruction. This achieves the detection of abnormal PFCP signaling related to the topology structure, improving the detection accuracy of abnormal PFCP signaling. Attached Figure Description

[0021] To more clearly illustrate the technical solutions in this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0022] Figure 1 This is a flowchart illustrating the PFCP signaling anomaly detection method provided in this application.

[0023] Figure 2 This is a schematic diagram of the structure of the national cryptographic signaling security gateway provided in this application.

[0024] Figure 3 This is a deployment diagram of the national cryptographic signaling security gateway provided in this application.

[0025] Figure 4 This is a schematic diagram of the signaling message processing flow provided in this application.

[0026] Figure 5 This is a schematic diagram of the PFCP signaling anomaly detection device provided in this application.

[0027] Figure 6 This is a schematic diagram of the structure of the electronic device provided in this application. Detailed Implementation

[0028] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0029] The following is combined Figures 1 to 6 This application describes the PFCP signaling anomaly detection method, apparatus, electronic device, and storage medium.

[0030] The main existing solutions for PFCP signaling anomaly detection include rule-based detection schemes, traditional machine learning schemes, and Transformer-based deep learning schemes.

[0031] Rule-based detection schemes rely on predefined expert rule bases to perform static verification on the format, field values, and interaction flow of PFCP signaling. This scheme is effective against known attack patterns, but it is difficult to deal with complex unknown attack patterns and variant attacks.

[0032] Traditional machine learning solutions employ feature engineering-based machine learning algorithms (such as Isolation Forest and Support Vector Machine) to extract statistical features from signaling traffic for anomaly classification. However, this approach suffers from difficulties in effectively modeling the structural variability (variable number, type, and length of IEs) and topological dependencies of PFCP signaling, as well as high feature engineering complexity. Specifically, insufficient modeling of the structural variability of PFCP signaling means that it is difficult to effectively handle the variable number of IEs and their heterogeneous attributes in PFCP signaling. Insufficient network topological dependencies mean that the signaling propagation path and the interaction patterns between network functional entities are not fully considered, making it impossible to detect abnormal behaviors related to the topology.

[0033] Transformer-based deep learning solutions utilize the self-attention mechanism of the Transformer model to process signaling sequences. While this can capture long-range dependencies to some extent, its computational complexity is high. As the sequence length increases quadratically, it becomes inefficient in processing long PFCP signaling sequences in the 5G core network, making it difficult to meet the low-latency real-time requirements of the 5G core network.

[0034] Figure 1 This is a flowchart illustrating the PFCP signaling anomaly detection method provided in this application, as follows: Figure 1 As shown, the PFCP signaling anomaly detection method includes, but is not limited to, steps 101 to 105.

[0035] It should be noted that the execution subject of the PFCP signaling anomaly detection method provided in this application can be a server, computer equipment, such as mobile phone, tablet computer, laptop computer, handheld computer, vehicle electronic equipment, wearable device, ultra-mobile personal computer (UMPC), netbook or personal digital assistant (PDA), etc.

[0036] Step 101: Extract the topological feature vector of the PFCP signaling set based on the dynamic heterogeneous graph of the PFCP signaling set.

[0037] In this context, the nodes of the dynamic heterogeneous graph represent network function entities associated with PFCP signaling; the edges of the dynamic heterogeneous graph represent the signaling interaction relationships of PFCP signaling; and the node features of the dynamic heterogeneous graph represent the content embedding vectors corresponding to the PFCP signaling associated with the network function entities.

[0038] A PFCP signaling set includes multiple PFCP signaling messages in a batch.

[0039] PFCP signaling refers to the control messages exchanged between network function entities such as the Session Management Function (SMF) and User Plane Function (UPF) to establish, modify, delete, or report data forwarding sessions. The PFCP (Packet Forwarding Control Protocol) is a key protocol in the Control and User Plane Separation (CUPS) architecture of the 5G core network (5GC).

[0040] Network functional entities are the switching entities that send and receive PFCP signaling, including but not limited to SMF and UPF; signaling interaction relationships are determined according to the control purpose of PFCP signaling exchange, including but not limited to establishment, modification, release and / or monitoring, etc.; content embedding vectors are embedding vectors determined according to the information element (IE) of PFCP signaling, and one PFCP signaling corresponds to one content embedding vector.

[0041] Specifically, before extracting the topological features of the PFCP signaling set, the PFCP signaling set is first parsed into a dynamic heterogeneous graph.

[0042] For each PFCP signaling in the PFCP signaling set, the process includes: representing the network functional entities (SMF, UPF, etc.) associated with the PFCP signaling as nodes in a dynamic heterogeneous graph; determining the edges between the nodes corresponding to the two network functional entities exchanging the PFCP signaling based on the signaling interaction relationships of the PFCP signaling; encoding the corresponding content embedding vector of the PFCP signaling based on multiple IEs of the PFCP signaling, and using the content embedding vector as the node feature of the two nodes exchanging the PFCP signaling. By traversing all PFCP signaling in the PFCP signaling set, all nodes, edges between nodes, and node features in the dynamic heterogeneous graph are determined, thus constructing the dynamic heterogeneous graph corresponding to the PFCP set.

[0043] It is understandable that in a dynamic heterogeneous graph, each node can be connected to multiple different nodes through different edges; the node features of each node may include the content embedding vectors corresponding to multiple associated PFCP signaling.

[0044] After constructing the dynamic heterogeneous graph corresponding to the PFCP set, the topological features of the PFCP set are extracted from the dynamic heterogeneous graph to obtain the topological feature vector of the PFCP set.

[0045] Optionally, the dynamic heterogeneous graph of the PFCP set is input into a pre-trained topology feature extraction model to obtain the topology feature vector output by the topology feature extraction model; the topology feature extraction model is built based on a graph neural network (GNN).

[0046] For example, the topological feature extraction model uses residual connections and layer normalization to ensure training stability, and captures k-hop neighbor information in dynamic heterogeneous graphs through convolution.

[0047] Step 102: Determine the global reconstruction feature vector based on the timing feature vector of the PFCP signaling set and the topology feature vector.

[0048] In one embodiment, based on the content embedding vectors corresponding to multiple PFCP signaling in the PFCP signaling set, the temporal feature vector of the PFCP signaling set is extracted; based on the temporal feature vector and the topological feature vector, the global fusion feature vector is determined; the global fusion feature vector is subjected to feature representation reconstruction processing to obtain the global reconstructed feature vector.

[0049] Specifically, before extracting the temporal features of the PFCP signaling set, for each PFCP signaling in the PFCP signaling set, an indefinite number of IEs in that PFCP signaling are encoded to obtain the content embedding vector corresponding to that PFCP signaling. Then, all PFCP signaling in the PFCP signaling set are traversed to determine the content embedding vector corresponding to each PFCP signaling.

[0050] Next, the temporal features of the PFCP set are extracted from all content embedding vectors to obtain the temporal feature vector of the PFCP set.

[0051] Optionally, all the embedding vectors are concatenated or merged together to obtain the overall embedding vector of the PFCP set; the temporal feature vector of the PFCP set is extracted from the overall embedding vector.

[0052] Optionally, for each PFCP signaling in the PFCP signaling set, the sub-time sequence feature vector of the PFCP signaling is extracted from the content embedding vector of the PFCP signaling; all PFCP signaling in the PFCP signaling set are traversed to extract multiple sub-time sequence feature vectors; multiple sub-time sequence feature vectors are fused or concatenated to obtain the time sequence feature vector of the PFCP signaling set.

[0053] The temporal and topological feature vectors are concatenated and fused to obtain a global fused feature vector for the PFCP signaling set. For example, during the concatenation and fusion of temporal and topological feature vectors, the temporal and topological weights are dynamically balanced to obtain the global fused feature vector.

[0054] The global fusion feature vector is reconstructed by feature representation processing to obtain the reconstructed global reconstructed feature vector corresponding to the PFCP signaling set.

[0055] Optionally, the PFCP signaling anomaly detection method provided in this application adopts an encoder-decoder structure, including an autoencoder and a self-decoder. The structure of the self-decoder is symmetrical to that of the autoencoder, and the calculation process of the self-decoder is the reverse of that of the autoencoder. The autoencoder is used to implement the step of extracting the topological feature vector of the PFCP signaling set based on the dynamic heterogeneous graph of the PFCP signaling set, and also to implement the step of extracting the temporal feature vector of the PFCP signaling set based on the content embedding vectors corresponding to multiple PFCP signalings in the PFCP signaling set, and also to implement the step of determining the global fusion feature vector based on the temporal feature vector and the topological feature vector. The self-decoder is used to implement the step of performing feature representation reconstruction processing on the global fusion feature vector to obtain the global reconstructed feature vector.

[0056] Step 103: Based on the global reconstruction feature vector, determine the abnormal PFCP signaling in the PFCP signaling set.

[0057] Specifically, based on the global reconstruction feature vector corresponding to the PFCP signaling set, the reconstruction feature vector of each PFCP signaling in the PFCP signaling set is determined, resulting in multiple reconstruction feature vectors. From these multiple reconstruction feature vectors, several abnormal reconstruction feature vectors are identified, so that the PFCP signaling corresponding to these several abnormal reconstruction feature vectors is identified as abnormal PFCP signaling.

[0058] The PFCP signaling anomaly detection method provided in this application constructs nodes and edges of a dynamic heterogeneous graph of the PFCP signaling set based on the network functional entities associated with the PFCP signaling and the signaling interaction relationships. It determines the node features of the dynamic heterogeneous graph based on the content embedding vectors corresponding to the PFCP signaling associated with the network functional entities, thus obtaining a dynamic heterogeneous graph that fully models the topological dependencies of the propagation paths between PFCP signaling and the interaction patterns between network functional entities. On one hand, it extracts topological features from the dynamic heterogeneous graph of the PFCP signaling set; on the other hand, it extracts temporal features from the content embedding vectors of each PFCP signaling in the PFCP signaling set. It performs feature fusion and feature reconstruction on the topological and temporal features, and finally detects abnormal PFCP signaling in the PFCP signaling set based on the globally reconstructed feature vector after feature reconstruction. This achieves the detection of abnormal PFCP signaling related to the topology structure, improving the detection accuracy of abnormal PFCP signaling.

[0059] Based on the above embodiments, as an optional embodiment, for each PFCP signaling in the PFCP signaling set, the content embedding vector corresponding to the PFCP signaling is determined in the following way: Based on the sub-embedding vectors corresponding to multiple information elements in the PFCP signaling, the content embedding vector corresponding to the PFCP signaling is determined. For each information element in the PFCP signaling, the sub-embedding vector corresponding to the information element is determined based on the following method; Based on the content byte sequence of the information element, determine the content encoding of the information element; Based on the attribute type of the information element, determine the attribute encoding of the information element; Based on the location information of the information element, determine the location code of the information element; Based on the content encoding, the attribute encoding, and the position encoding, the sub-embedding vector corresponding to the information element is determined.

[0060] The content encoding of an IE is a characteristic representation of the information byte content of the PFCP signaling carried by each IE in the PFCP signaling.

[0061] Attribute types are the types of attributes used in Internet Explorer to maintain consistency in protocol syntax and semantics. For example, attribute types include mandatory, optional, and conditional, etc.

[0062] Location information is used to describe the location of the IE in the PFCP signaling and the location of the IE in the PFCP signaling set; location information includes, but is not limited to, time location, topology location, etc.

[0063] Specifically, when determining the content embedding vector corresponding to each PFCP signaling, the sub-embedding vector corresponding to each IE in the PFCP signaling is first determined.

[0064] For each IE in the PFCP signaling, on the one hand, the content byte sequence of the IE is encoded into the content encoding of the IE according to a certain encoding method.

[0065] Optionally, the IE content byte sequence is converted into a one-hot vector matrix, and the content features of each byte are characterized by a parameter-learnable embedding matrix to obtain the content encoding.

[0066] For example, each IE represents a content byte sequence with a variable length. Different byte lengths in IE They can be different. Each byte of IE... The byte-level vocabulary is used to convert the data into a 256-dimensional one-hot vector. The byte value ranges from 0x00 to 0xFF, resulting in 256 possible values. For example, if the byte... The byte value is 0x41, byte This can be encoded as a 256-dimensional sparse vector where the 65th bit is 1 and the remaining 255 bits are 0. Therefore, the byte length is... IE can be converted A one-hot vector matrix of dimension. Multiply the one-hot vector matrix by the embedding matrix. ,get A content feature matrix along the sequence dimensions. One-dimensional convolution is applied, and the kernel size is... Input channel is The output channel is (e.g., 128), to obtain the convolutional output. Apply global max pooling to the convolutional output to obtain a fixed value. 3D IE content feature vector The IE content feature vectors are projected to the final dimension through a linear layer. By employing byte-level One-Hot encoding, embedding matrix, one-dimensional convolution, and global pooling, variable-length byte sequences are transformed into fixed-dimensional feature vectors, effectively solving the representation challenge caused by variable-length IE (Internet Explorer).

[0067] On the other hand, the attribute types of IE are encoded into the attribute encoding of IE according to a certain encoding method.

[0068] Optionally, the IE property type can be encoded using one-hot encoding to obtain the property code.

[0069] For example, 3GPP-defined Internet Explorer (IE) has mandatory, optional, and conditional attributes, which can be represented by one-hot encoding as [1,0,0], [0,1,0], and [0,0,1] respectively. Attribute encoding can be represented as... .

[0070] On the other hand, the location information of the IE in the PFCP signaling and the location information of the IE in the PFCP signaling set are determined, and the location information is encoded into location code according to a certain encoding method in order to model the combined behavior of the IE in different contexts.

[0071] Finally, the content encoding, attribute encoding, and position encoding are concatenated and / or merged to obtain the sub-embedded vector corresponding to IE.

[0072] By traversing all IEs in the PFCP signaling, the sub-embedding vectors corresponding to each IE are obtained, and the content embedding vector corresponding to the PFCP signaling can be determined based on all the sub-embedding vectors.

[0073] By traversing all PFCP signaling in the PFCP signaling set, the content embedding vectors corresponding to each PFCP signaling are obtained. Based on all content embedding vectors, the temporal feature vectors of the PFCP signaling set can be extracted.

[0074] The PFCP signaling anomaly detection method provided in this application determines the content encoding, attribute encoding, and position encoding based on the content byte sequence, attribute type, and position information of the information elements. It then determines the sub-embedding vector corresponding to each information element based on the content encoding, attribute encoding, and position encoding. This leads to the determination of the content embedding vector corresponding to the PFCP signaling, which is composed of the sub-embedding vectors corresponding to all information elements within a single signaling message. In other words, it effectively characterizes the structural variability of the number, type, and length of IEs in PFCP signaling using IE-level multidimensional feature embedding. On one hand, it uses the content embedding vector as a node feature of a dynamic heterogeneous graph to extract topological features; on the other hand, it extracts temporal features from the content embedding vector. By fully considering the structural variability of PFCP signaling, it achieves the detection of abnormal PFCP signaling, improves the detection accuracy of abnormal PFCP signaling, and enables effective detection of unknown attacks.

[0075] Based on the above embodiments, as an optional embodiment, determining the location code of the information element based on the location information of the information element includes: The time position code of the information element is determined based on the element sequence index of the information element in its respective PFCP signaling. The topology location code of the information element is determined based on the network function entity associated with the PFCP signaling to which the information element belongs; The location code of the information element is determined based on the time location code and the topological location code.

[0076] The element sequence index is the index of an IE in the element sequence consisting of all IEs belonging to the PFCP signaling.

[0077] Specifically, when determining the location encoding of IE, an enhanced location encoding that includes both time location and topological location is used.

[0078] On the one hand, the time position code representing the intra-sequence position of the IE is determined in sine / cosine form based on the element sequence index of the IE in the PFCP signaling, or based on the element sequence index of the IE in the PFCP signaling and the feature dimension index of the PFCP signaling.

[0079] On the other hand, based on the network function entity associated with the PFCP signaling of the IE, a pre-assigned learnable embedding vector for that network function entity is obtained. This learnable embedding vector is then aligned with the temporal location coding dimension through a linear layer projection to obtain the topological location coding of the IE. The pre-assigned learnable embedding vector can be determined based on the type of the network function entity or its unique identifier.

[0080] Finally, the time location code and topology location code of IE are concatenated or merged together to obtain the location code of IE.

[0081] Optionally, the network function entity associated with the PFCP signaling of the IE and the neighboring function entities of the associated network function entity are determined, and the location code of the IE is determined using the pre-allocated learnable embedding vectors of the network function entity and the neighboring function entity.

[0082] Optionally, the mathematical expression for time-location encoding is as follows: ; in, This is the element sequence index of the IE in its respective PFCP signaling; Indexed by feature dimension; The size of the feature dimension; For the first IE in even-numbered dimensions Time location encoding; For the first IE in odd-numbered dimensions Time location encoding.

[0083] Optionally, the formula for calculating the topology location code in IE is as follows: ; ; in, Encoding of topological positions aligned by projection; Encodes the raw topological positions that are not projected and aligned; For the first Embedded vector of the network function entity associated with the PFCP signaling of each IE; The dimension size for encoding the unprojected aligned topological positions; The weight matrix is ​​a learnable matrix; For learnable bias terms; The dimension size for encoding the topologically aligned position after projection.

[0084] Alternatively, when the positional encoding is determined based on temporal positional encoding and topological positional encoding, the expression for the sub-embedding vector of the IE is as follows: ; in, For the first Sub-embedding vectors of IE; For the first The content encoding of IE; For the first The attribute encoding of IE; For splicing operations; for Learnable projection layer; For the first The time location encoding for each IE; For the first Topological position encoding of an IE with projection alignment; For topological weight coefficients, such as .

[0085] The PFCP signaling anomaly detection method provided in this application, by assigning a learnable embedding vector to each network functional entity, introduces the network topology information of the network functional entity associated with the PFCP signaling of the information element as a topology location code into the location code of the IE-level feature representation, constructs a content embedding vector that considers network topology information, and then uses a comprehensive feature representation that integrates IE content features, attribute features, temporal location features, and topology role features to extract temporal features. It can simultaneously capture the temporal dependency and network topology propagation characteristics of PFCP signaling, track the propagation path of abnormal signaling in the network and locate the source node, is sensitive to network topology changes, and can detect topology-related abnormal behavior. It realizes the detection of abnormal PFCP signaling under the condition of fully considering the structural variability and topology dependency of PFCP signaling, improves the detection accuracy of abnormal PFCP signaling, and achieves effective detection of unknown attacks.

[0086] Based on the above embodiments, as an optional embodiment, the step of extracting the temporal feature vector of the PFCP signaling set based on the content embedding vectors corresponding to multiple PFCP signaling messages in the PFCP signaling set includes: Based on the content embedding vectors corresponding to multiple PFCP signaling messages in the PFCP signaling set, the overall embedding vector of the PFCP signaling set is determined. The overall embedding vector is input into the temporal feature extraction model to obtain the temporal feature vector output by the temporal feature extraction model; The time-series feature extraction model includes a sequence mixer, a channel mixer, a residual connection layer, a normalization layer, and an output layer connected in sequence; the sequence mixer is built based on a permutation and block diagonal product matrix.

[0087] Specifically, when extracting the temporal feature vector of the PFCP signaling set, for each PFCP signaling in the PFCP signaling set, the content embedding vector corresponding to that PFCP signaling is determined based on the content encoding, attribute encoding, and position encoding of all IEs in that PFCP signaling. All PFCP signaling in the PFCP signaling set are traversed to obtain the content embedding vectors of all PFCP signaling. All content embedding vectors are concatenated and / or merged together to obtain the overall embedding vector of the PFCP signaling set.

[0088] The overall embedding vector is input into a pre-trained temporal feature extraction model, which performs temporal feature processing across time steps on the overall embedding vector, resulting in the temporal feature vector corresponding to the PFCP signaling set output by the temporal feature extraction model. , This represents the number of PFCP signaling messages in the PFCP signaling set. The maximum number of IEs in a pre-determined PFCP signaling sequence. This represents the temporal feature dimension.

[0089] The temporal feature extraction model comprises a sequence mixer, a channel mixer, a residual connection layer, a normalization layer, and an output layer, connected in sequence. The sequence mixer replaces the standard fully connected layer with a permutation and block diagonal product matrix (such as a Monarch matrix) for cross-time step (token mixing) processing. The channel mixer fuses feature dimensional information, and the residual connection layer and normalization layer ensure training stability. The permutation and block diagonal product matrix is ​​obtained by... The weight matrix is ​​decomposed into There are 1 block, each block being 1 unit in size. It forms a diagonal block structure.

[0090] By using standard fully connected layers The weight matrix is ​​decomposed into The product of block diagonal matrices, each factor matrix is ​​composed of... The submatrices form a block diagonal structure, which can reduce the computational complexity of temporal feature extraction from that of standard self-attention. or fully connected layer Down to or ,in For sequence length, For feature dimensions.

[0091] In one embodiment, the autoencoder includes a temporal feature extraction model and a topological feature extraction model. The temporal feature vector is extracted based on the temporal feature extraction model, which includes a sequence mixer, a channel mixer, a residual connection layer, a normalization layer, and an output layer connected in sequence. The sequence mixer is constructed using a Monarch matrix. The topological feature vector is extracted based on the topological feature extraction model, which is constructed based on a GNN.

[0092] The PFCP signaling anomaly detection method provided in this application reduces computational complexity by replacing the fully connected layer of the traditional Transformer with a permutation and block diagonal product matrix. Down to This significantly reduces the overhead of long sequence processing and improves processing efficiency. Under the same hardware conditions, it can process more sequence lengths, optimizes the number of model parameters and memory usage, and has real-time processing capabilities that meet the SLA requirements of 5G networks. By adopting a neural network architecture based on the fusion of Monarch matrix and GNN for PFCP abnormal signaling analysis, it uses Monarch matrix permutation and block diagonal product matrix decomposition to replace the standard attention mechanism, reducing computational complexity. Combined with topology modeling capabilities, it achieves time-topology feature fusion, which can overcome the bottleneck of high latency in long sequence processing.

[0093] Based on the above embodiments, as an optional embodiment, determining the global fusion feature vector based on the temporal feature vector and the topological feature vector includes: Based on the temporal feature vector and the first weighting factor, the first sub-fusion vector is determined; Based on the topological feature vector and the second weighting factor, the second sub-fusion vector is determined; Based on the first sub-fusion vector and the second sub-fusion vector, the fusion feature vector is determined; Based on the fused feature vector and the topological feature vector, the global fused feature vector is obtained; Wherein, the sum of the first weighting factor and the second weighting factor is 1; the first weighting factor and the second weighting factor are determined based on the gating attention mechanism.

[0094] Specifically, in the process of determining the global fusion feature vector based on the temporal feature vector and the topological feature vector, dynamic weights are first generated using a gated network based on the gated attention mechanism. Dynamic weights It was determined to be the second weighting factor. The first weighting factor is determined. The first sub-fusion vector is determined based on the product of the temporal feature vector and the first weighting factor. The second sub-fusion vector is determined based on the product of the topological feature vector and the second weighting factor. The first and second sub-fusion vectors are concatenated to obtain the fused feature vector.

[0095] Further processing, such as splicing and / or fusing fusion feature vectors and topology feature vectors, yields a global fusion feature vector that simultaneously includes the timing pattern of the PFCP signaling set and network topology information, which can provide a comprehensive characterization for subsequent anomaly detection.

[0096] Optionally, the formula for calculating the fused feature vector is as follows: ; ; in, To fuse feature vectors; As the second weighting factor; This is a topological feature transformation function operation; These are topological feature vectors; It is the first weighting factor; This is an operation of the time-series feature transformation function; This is a time-series feature vector; Use the Sigmoid activation function; This is the weight matrix; For splicing operations; This is a pooling operation; This is a bias term.

[0097] Optionally, the formula for calculating the global fused feature vector is as follows: ; in, The first in the global fusion feature vector Partial feature vectors corresponding to each PFCP signaling; For the first The number of IEs in each PFCP signaling; For the fused feature vector, the first In the first PFCP signaling Partial feature vectors corresponding to each IE; The pre-determined topological aggregation weights, such as 0.3; It is a topological feature aggregation function; The first eigenvector in the topological feature vector Partial feature vectors corresponding to each PFCP signaling.

[0098] Optionally, the topological feature aggregation function is determined based on graph convolutional pooling.

[0099] The PFCP signaling anomaly detection method provided in this application determines the first and second weight factors through a gated attention mechanism, dynamically adjusts the contribution weights of the GNN and Monarch branches, preserves the complementary information of temporal sequence and topology, realizes the effective fusion of multimodal features, and improves the accuracy of PFCP signaling anomaly detection.

[0100] Based on the above embodiments, as an optional embodiment, the step of performing feature representation reconstruction processing on the global fused feature vector to obtain the global reconstructed feature vector includes: The global fusion feature vector is input into the temporal feature reconstruction model to obtain the reconstructed temporal feature vector output by the temporal feature reconstruction model; the structure of the temporal feature reconstruction model is symmetrical to the structure of the temporal feature extraction model. Based on the reconstructed temporal feature vector, the global reconstructed feature vector is determined; The step of determining the abnormal PFCP signaling in the PFCP signaling set based on the globally reconstructed feature vector includes: Based on the global reconstruction feature vector, determine the sub-reconstruction feature vectors corresponding to multiple PFCP signaling in the PFCP signaling set; Cluster analysis is performed on multiple sub-reconstruction feature vectors, and the sub-reconstruction feature vectors with classification reliability less than a preset reliability threshold are identified as abnormal sub-reconstruction feature vectors. The PFCP signaling corresponding to the reconstructed feature vector of the anomaly is identified as the anomalous PFCP signaling.

[0101] Optionally, the sequence mixers of both the temporal feature reconstruction model and the temporal feature extraction model use permutation and block diagonal product matrices to replace the standard fully connected layers.

[0102] For example, the permutation and block diagonal product matrix is ​​an approximately fully connected Monarch matrix, and the reconstructed temporal feature vector is obtained through the inverse calculation of the block diagonal matrix. By replacing the fully connected layers of the temporal feature reconstruction model and the temporal feature extraction model with the Monarch matrix, the temporal feature vector can be preserved. Improve computational efficiency and avoid Complexity.

[0103] Specifically, taking the encoder-decoder architecture as an example, the global fusion feature vector output by the encoder is input into the temporal feature reconstruction model of the decoder. The temporal feature reconstruction model performs temporal feature reconstruction processing (such as inverse Monarch Mixer processing) on ​​the global fusion feature vector to obtain the reconstructed temporal feature vector output by the temporal feature reconstruction model. Then, the reconstructed temporal feature vector can be directly determined as the global reconstructed feature vector.

[0104] Alternatively, in addition to reconstructing temporal features, topological features can also be reconstructed. The global fusion feature vector output by the encoder is input into the topological feature reconstruction model of the decoder. The topological feature reconstruction model performs topological feature reconstruction processing (such as inverse GNN processing) on ​​the global fusion feature vector to obtain the reconstructed topological graph output by the topological feature reconstruction model. Then, the reconstructed temporal feature vector and the reconstructed topological graph are concatenated and / or fused to obtain the global reconstructed feature vector.

[0105] After obtaining the global reconstruction feature vector corresponding to the PFCP signaling set, the global reconstruction feature vector is split into sub-reconstruction feature vectors corresponding to each PFCP signaling, resulting in multiple sub-reconstruction feature vectors.

[0106] Clustering methods such as K-means are used to perform cluster analysis on multiple sub-reconstructed feature vectors, so as to combine similar PFCP signaling data together through clustering and realize anomaly detection based on unsupervised method.

[0107] For each sub-reconstructed feature vector, several sub-classification reliability scores are obtained for different cluster centers that classify the sub-reconstructed feature vector into a normal clustering pattern. The maximum value of these sub-classification reliability scores is taken as the classification reliability. This process is repeated for all sub-reconstructed feature vectors to obtain the classification reliability of all sub-reconstructed feature vectors. Each cluster center corresponds to one normal clustering pattern.

[0108] Generally speaking, when deploying an application, the number of cluster centers... The typical number of patterns for PFCP signaling behavior set to normal clustering mode is 8~16.

[0109] Furthermore, if the classification reliability of a sub-reconstruction feature vector is less than a preset reliability threshold, it indicates that the PFCP signaling corresponding to that sub-reconstruction feature vector cannot be reliably classified as a cluster center of any normal clustering pattern. The PFCP signaling corresponding to that sub-reconstruction feature vector is very likely to be an abnormal instruction of the type, such as protocol violation, DDoS attack, session hijacking, parameter anomaly, or topology anomaly. Therefore, the PFCP signaling corresponding to sub-reconstruction feature vectors with a classification reliability less than the preset reliability threshold in the PFCP signaling set is identified as abnormal PFCP signaling, thus implementing a PFCP signaling anomaly detection method.

[0110] Optionally, before inputting the global fused feature vector into the temporal feature reconstruction model, the method further includes performing a linear transformation to expand the global fused feature vector and adding positional encoding to obtain a global fused feature vector with consistent feature dimensions and retaining the byte sequence structure information of the original PFCP signaling set.

[0111] Optionally, the formula for calculating the globally reconstructed feature vector is as follows: ; ; in, The global reconstructed feature vector is the one that has not undergone activation function and linear expansion. These are the weighting coefficients; Operations of the inverse projection transform function for reconstructing temporal features; To reconstruct the temporal feature vector; The inverse projection transformation function operation is used to reconstruct topological features; To reconstruct the topology graph; This is the final output of the globally reconstructed feature vector after activation and linear expansion; For linear extension processing; This is processed using the Sigmoid activation function.

[0112] Optionally, a topology-aware soft allocation mechanism is introduced. Based on the reliability of several subclassifications of different cluster centers that classify the sub-reconstructed feature vectors into normal clustering patterns and the network topology similarity, several enhanced subclassification reliabilitys of the sub-reconstructed feature vectors are determined, and the highest enhanced subclassification reliability is determined as the enhanced classification reliability. Sub-reconstructed feature vectors with enhanced classification reliability less than a preset enhanced reliability threshold are determined as abnormal sub-reconstructed feature vectors.

[0113] Optionally, the formula for calculating the reliability of enhanced subclassing is as follows: ; ; in, For PFCP signaling Belongs to clustering Enhanced subclassification reliability; Reconstruct the feature vector for the sub-sub; For clustering The center of mass; This is the degree of freedom parameter, such as setting it to 1.0; To reconstruct the nodes in the topology graph Clustering The strength of association in network topology; The number of cluster centers; For clustering The center of mass; To reconstruct the nodes in the topology graph Clustering The strength of association in network topology; To adjust the parameters; This is an operation on the topological distance function; For nodes ; For clustering .

[0114] Understandably, PFCP signaling They belong to different clusters. Reliability of each enhanced subclass The sum is 1.

[0115] The PFCP signaling anomaly detection method provided in this application utilizes the characteristic that the reconstruction error will significantly increase due to the deviation of abnormal PFCP signaling from the normal pattern after feature reconstruction. First, the temporal and topological features of PFCP signaling are fused, and then the fused features are used for reconstruction. Based on the reconstructed features, cluster analysis is performed to achieve unsupervised PFCP signaling anomaly detection using a topology-aware clustering mechanism that combines network topology.

[0116] In another embodiment, the step of performing feature representation reconstruction processing on the global fused feature vector to obtain the global reconstructed feature vector includes: The global fusion feature vector is input into the temporal feature reconstruction model to obtain the reconstructed temporal feature vector output by the temporal feature reconstruction model; the structure of the temporal feature reconstruction model is symmetrical to the structure of the temporal feature extraction model. The global fusion feature vector is input into the topology feature reconstruction model to obtain the reconstructed topology graph output by the topology feature reconstruction model; the structure of the topology feature reconstruction model is symmetrical to the structure of the topology feature extraction model. Based on the reconstructed temporal feature vector and the reconstructed topology graph, the global reconstructed feature vector is determined.

[0117] Based on the above embodiments, as an optional embodiment, before extracting the topological feature vector of the PFCP signaling set from the dynamic heterogeneous graph based on the PFCP signaling set, the method further includes: Based on the joint training loss of the autoencoder, autodecoder, and cluster head, the model parameters of the autoencoder, the model parameters of the autodecoder, and the initial cluster centers of the cluster head are updated. The joint training loss is determined based on reconstruction loss, clustering loss, and topology consistency loss; the reconstruction loss is determined based on the global fusion feature vector and the global reconstruction feature vector during the joint training process; the topology consistency loss is determined based on the topology feature vector and the reconstructed topology graph during the joint training process; and the clustering loss is determined based on the classification reliability during the joint training process. The autoencoder is used to implement the dynamic heterogeneous graph based on the PFCP signaling set, extract the topological feature vector of the PFCP signaling set, implement the content embedding vectors corresponding to multiple PFCP signaling in the PFCP signaling set, extract the temporal feature vector of the PFCP signaling set, and determine the global fusion feature vector based on the temporal feature vector and the topological feature vector. The self-decoder is used to perform feature representation reconstruction processing on the global fused feature vector to obtain the global reconstructed feature vector; The clustering head is used to determine the abnormal PFCP signaling in the PFCP signaling set based on the global reconstructed feature vector.

[0118] Specifically, the PFCP signaling anomaly detection method provided in this application adopts an "encoder + decoder + cluster head" architecture. Before extracting topological feature vectors and temporal feature vectors, the joint training of the encoder, decoder and cluster head is completed. This includes updating the model parameters of the autoencoder, the model parameters of the autodecoder and the initial cluster centers of the cluster head with the training objective of minimizing the joint training loss of the autoencoder, autodecoder and cluster head, so as to realize the pre-training of the encoder, decoder and cluster head.

[0119] The joint training loss is determined based on the reconstruction loss, clustering loss, and topology consistency loss. The reconstruction loss measures the decoder's ability to reconstruct the original PFCP signaling and is determined based on the globally fused feature vector and the globally reconstructed feature vector during joint training. The topology consistency loss ensures that nodes with similar topological locations have similar feature representations and is determined based on the topological feature vector and the reconstructed topology graph during joint training. The clustering loss optimizes the clustering structure in the feature space and is determined based on the classification reliability during joint training.

[0120] Optionally, the formula for calculating the joint training loss is as follows: ; in, Losses due to joint training; For reconstruction loss; Clustering loss; This is the loss due to topological consistency. The balance coefficient for clustering loss, such as ; The balancing coefficient for topology consistency loss, such as .

[0121] Optionally, the reconstruction loss is calculated using the following formula: ; ; in, For reconstruction loss; The number of PFCP signaling in the current training batch; The number of IEs in PFCP signaling; The first in the current training batch The first PFCP signaling Observations of IE; The first in the current training batch The first PFCP signaling The predicted value for each IE; Use the topology reconstruction weight, such as 0.2; For matrix reconstruction loss; This represents the number of elements in the original adjacency matrix. This represents the original adjacency matrix of the dynamic heterogeneous graph during the joint training process. This is the reconstructed adjacency matrix of the reconstructed topology graph during the joint training process.

[0122] Understandably, dynamic heterogeneous graphs Represented as , For a dynamic heterogeneous graph, the set of nodes. For the edge set of a dynamic heterogeneous graph, This is the adjacency matrix of a dynamic heterogeneous graph.

[0123] Optionally, the formula for calculating the clustering loss is as follows: ; ; ; in, Clustering loss; The number of PFCP signaling in the current training batch; To initialize the number of cluster centers; For PFCP signaling Structural importance score; For PFCP signaling Belongs to clustering Enhanced subclassification reliability; For clustering Frequency; For PFCP signaling Belongs to clustering Enhanced subclassification reliability; For clustering The frequency of.

[0124] By calculating the target distribution, confidence can be strengthened and topology awareness can be enhanced.

[0125] Optionally, the formula for calculating the topology consistency loss is as follows: ; in, This is the loss due to topological consistency. It is the set of edges of a dynamic heterogeneous graph; This is the global fusion feature vector corresponding to the first normal PFCP signaling sample; This is the global fusion feature vector corresponding to the normal sample of the second PFCP signaling; To reconstruct the edge set of the topological graph; For negative sampling weights, such as 1.0; This is the marginal threshold.

[0126] Optionally, the autoencoder includes a temporal feature extraction model and a topological feature extraction model, and the autodecoder includes a temporal feature reconstruction model and a topological feature reconstruction model.

[0127] It is understandable that determining the model parameters for updating the autoencoder and autodecoder is equivalent to updating the model parameters for the temporal feature extraction model, topological feature extraction model, temporal feature reconstruction model, and topological feature reconstruction model.

[0128] In one embodiment, the process of obtaining joint training samples for the encoder, decoder, and clustering head includes: obtaining PFCP signaling flow data from a real 5G core network through a signaling security gateway, and performing the following processing on the normal PFCP signaling data therein: constructing dynamic heterogeneous graph samples (with network functional entities such as UPF and SMF as nodes and PFCP session relationships as edges); extracting PFCP message features from the normal PFCP signaling data, including extracting message type, session ID, TEID, message length, time interval, etc.; converting IEs in the PFCP messages into content embedding vector samples to obtain normal PFCP signaling samples that include dynamic heterogeneous graph samples and content embedding vector samples in the joint training samples. Abnormal PFCP signaling data with a signaling message format conforming to 3GPP standards is generated using core network protocol programmable tools. For example, by modifying IE combination relationships, time series patterns, or topology propagation paths, five typical types of abnormal PFCP signaling data are generated, including protocol violations, DDoS attacks, session hijacking, parameter anomalies, and topology anomalies. Similarly, IE-level embedding and feature vector construction are performed on the abnormal PFCP signaling data to obtain abnormal PFCP signaling samples. The ratio of normal PFCP signaling samples to abnormal PFCP signaling samples in the joint training sample set was determined to be 8:2. The joint training sample set was then divided into a training set, a validation set, and a test set. The training set included only normal PFCP signaling samples for unsupervised learning; the validation set contained 70% normal PFCP signaling samples and 30% abnormal PFCP signaling samples; and the test set contained 50% normal PFCP signaling samples and 50% abnormal PFCP signaling samples.

[0129] The PFCP signaling anomaly detection method provided in this application improves the accuracy of PFCP signaling anomaly detection by jointly optimizing and training the various model structures based on reconstruction loss, clustering loss, and topology consistency loss. This results in a robust anomaly detection model. Topology consistency loss ensures that connected nodes in the network topology are also similar in the feature space, while unconnected nodes are far apart, thus enhancing the model's understanding of PFCP signaling network behavior. The reconstruction loss design effectively restores the original features and network topology of PFCP signaling, providing an accurate reconstruction benchmark for anomaly detection. Clustering loss measures the difference between the target distribution and the current classification reliability; minimizing clustering loss makes the cluster structure in the representation space more compact and clear, while preserving network topology information.

[0130] Based on the above embodiments, as an optional embodiment, the initial cluster centers are determined in the following manner; Based on a predetermined number of randomly selected first PFCP signaling normal samples, the predetermined number of initial centers for clusters are determined; the first PFCP signaling normal samples are the PFCP signaling normal samples used to determine the initial centers. Based on the topology-aware distance between the second PFCP signaling normal sample and the first PFCP signaling normal sample, multiple second PFCP signaling normal samples are respectively assigned to the initial center with the closest topology-aware distance; the second PFCP signaling normal sample is the PFCP signaling normal sample used to adjust the initial center. Based on the allocated second PFCP signaling normal samples and the first PFCP signaling normal samples, the initial center is adjusted to determine the initial cluster center.

[0131] Specifically, the initial cluster centers are determined before jointly training the cluster heads and updating the initial cluster centers.

[0132] First, a preset number (e.g., 8-16) of first PFCP signaling normal samples are randomly selected to determine the initial centers of the clusters. Based on the center of each first PFCP signaling normal sample in the feature space, the initial centers of the clusters are determined, resulting in a preset number of initial centers for the clusters.

[0133] Then, several second PFCP signaling normal samples are obtained for adjusting the initial center. For each second PFCP signaling normal sample, the topology sensing distance between the second PFCP signaling normal sample and each first PFCP signaling normal sample is calculated, and the second PFCP signaling normal sample is assigned to the initial center with the closest topology sensing distance. This process is repeated for all second PFCP signaling normal samples, and each second PFCP signaling normal sample is assigned to the initial center with the closest topology sensing distance.

[0134] Finally, for each initial center, using the second PFCP signaling normal sample assigned to that initial center and the first PFCP signaling normal sample corresponding to that initial center, a new cluster center point is recalculated, and the initial center is adjusted to the new cluster center point to obtain the initial cluster center, which serves as the initial value of the learnable parameters for subsequent joint training.

[0135] Optionally, the formula for calculating the topology-aware distance is as follows: ; in, For topology-aware distance; This is the global fusion feature vector corresponding to the first normal PFCP signaling sample; This is the global fusion feature vector corresponding to the normal sample of the second PFCP signaling; This is the topology weight coefficient, such as the default 0.4; For nodes and nodes The shortest path distance in the network topology.

[0136] Optionally, during joint training, each time... Step (such as) The initial cluster centers are updated, and the update mechanism is as follows: ; in, For clustering The center of mass; This is the momentum coefficient, such as the default value of 0.5; For PFCP signaling Belongs to clustering Enhanced subclassification reliability; PFCP signaling during joint training The sub-reconstructed feature vectors.

[0137] The PFCP signaling anomaly detection method provided in this application considers the network topology characteristics of PFCP signaling during the initialization process of cluster centers, enabling the initial cluster centers to reflect normal signaling behavior patterns in the 5G core network and providing a more accurate reference benchmark for subsequent anomaly detection.

[0138] Based on the above embodiments, as an optional embodiment, the PFCP signaling anomaly detection method is applied to a national cryptographic signaling security gateway.

[0139] Optionally, the FCP signaling anomaly detection method is applied to the signaling detection engine of the national cryptographic signaling security gateway.

[0140] Figure 2 This is a schematic diagram of the structure of the national cryptographic signaling security gateway provided in this application, as shown below. Figure 2 As shown, the national cryptographic signaling security gateway consists of three parts: a front-end page, a back-end, and a signaling detection engine.

[0141] The front-end page and back-end implement the configuration and status monitoring of signaling security protection of the national cryptographic signaling security gateway, providing users with a user-friendly operation and maintenance interface. The signaling detection engine is the core module of the national cryptographic signaling security gateway, mainly composed of IPSEC supporting national cryptographic standards, signaling parameter detection, signaling behavior detection, signaling routing and topology hiding functions. The rule base, model and access control policies configured on the front-end page are sent to the signaling detection engine by the back-end to support signaling-related operations.

[0142] In terms of business logic, the national cryptographic signaling security gateway is physically deployed between 5G core network elements. The network interface is configured on the front-end interface to communicate with the 5G network elements. Then, IPSEC tunnel parameters are configured on the interface to establish an encrypted tunnel with the IPSEC security gateway on the network element side. At the same time, packet analysis rules are configured to realize in-depth analysis and blocking of traffic data after decryption.

[0143] Furthermore, the signaling detection engine consists of three parts: the national cryptographic IKE key exchange protocol layer based on IPSEC components, the packet DPI analysis and detection layer based on IPS components, and the high-performance packet processing framework layer based on vector packet processing.

[0144] In the IKE key exchange protocol layer based on IPS components, the IPSEC component can be implemented using the open-source Strongswan technology. This adds support for the national cryptographic SM2 / SM3 / SM4 algorithms on top of the open-source technology, enabling authentication at both ends of the encrypted tunnel, negotiation and generation of IKE keys, and establishing a secure IPSEC encrypted tunnel to ensure the confidentiality and integrity of signaling data during transmission. The packet DPI analysis and detection layer based on IPS components interacts with the high-performance packet processing framework layer through the TAP mirroring interface mechanism to achieve the transmission of key negotiation packets and the synchronization of security policies.

[0145] By integrating Strongswan and supporting national cryptographic algorithms such as SM4 and SM2, an IPSEC encrypted tunnel based on national cryptographic standards is realized, effectively ensuring the confidentiality and integrity of signaling data during transmission and meeting high standards of information security.

[0146] In the high-performance packet processing framework layer based on vector packet processing, the high-performance packet processing framework layer is implemented based on VPP, which has the characteristics of high throughput and low latency, and is suitable for the rapid forwarding and processing of large-scale signaling data. As the core processing engine, the high-performance packet processing framework layer integrates the TAP interface mechanism, receives the key and encryption policy configuration from the IPSEC layer, and processes ESP packets that need to be encrypted and decrypted in the encryption and decryption nodes. The encryption and decryption nodes can call the CCP cryptographic unit in the Hygon server to perform cryptographic calculations, and forward the processed packets to the next layer node or output them to the network interface.

[0147] By using general-purpose servers and VPP / DPDK to build a high-performance signaling processing plane in user space, the strong coupling limitations of traditional dedicated hardware (such as ATCA architecture, NPU / FPGA) can be eliminated, significantly reducing hardware costs, improving system scalability and resource utilization, and flexibly adapting to the high-frequency evolution requirements of 5G and even 6G core networks.

[0148] In the packet DPI analysis and detection layer based on IPS components, the core function of deep analysis and detection of key signaling protocols in the 5G core network is realized by leveraging the Suricata technology and neural network technology of IPS components. To meet actual deployment requirements, the IPS components are compiled into a dynamic library and integrated into the VPP node graph as packet detection nodes, enabling real-time analysis of packet content and identification of abnormal behavior, supporting dynamic security policy adjustments, and effectively improving the detection capabilities and response speed of the national cryptographic signaling security gateway.

[0149] Furthermore, in the signaling inspection engine, the overall system operation process flows in a node-based manner: the packet is first received by the VPP framework and classified based on 5-tuples. If it is a tunnel negotiation packet, it is forwarded to the IPSEC component for processing. If it is a signaling packet, the policy routing determines whether to hand it over to Suricata for deep inspection.

[0150] The negotiation message processing method includes an interaction mechanism between VPP and IPsec components based on traffic mirroring. After VPP starts, it creates a Virtio type TAP virtual interface and a corresponding Vhost type TAP device in the host kernel. The Virtio type interface acts as a front-end driver in the VPP user space, responsible for providing a standardized virtual queue interface, while the Vhost type acts as a back-end driver in the Linux kernel, directly interacting with the TAP device. Virtio and Vhost exchange data packets through a shared memory ring. When the national cryptographic signaling security gateway establishes an encrypted tunnel as the receiving end of tunnel negotiation, it parses the received negotiation message into a 5-tuple. If the port number is 500 or 4500, it indicates an IKE key exchange protocol message. The received negotiation message is forwarded to the TAP virtual interface within the VPP. Through the Linux traffic mirroring mechanism, the message is uploaded to the host's TAP interface. The IPsec control plane (strongswan) running on the host receives the IKE negotiation message, processes it according to the IKE key negotiation procedure, triggers the generation of a corresponding response message, and then mirrors it back to the VPP through the TAP interface. The VPP then forwards the message to the IPsec peer. After negotiation, the IPsec component running on the host protocol distributes the SA / SP to the VPP through the TAP interface mechanism.

[0151] By leveraging Suricata to perform deep analysis and anomaly behavior identification of 5G core network protocols such as PFCP, HTTP / 2, and SCTP, it has the ability to quickly adapt to new protocols (such as the HTTP / 2 SBI interface), solving the problems of long support cycles for new protocols and reliance on vendor-customized development in traditional solutions.

[0152] The signaling message processing method includes raw data packet capture based on network interfaces using DPDK technology. The data format of the signaling message is a standard IP data packet, which includes transport layer protocol headers (such as TCP, UDP, SCTP) and application layer protocol content. After entering the VPP processing flow, before abnormal signaling analysis, the data packets need to undergo preprocessing such as data cleaning, normalization, and protocol identification. Data cleaning includes removing invalid or erroneous data packets such as those with checksum errors or length mismatches. Normalization includes unifying data packets from different protocols into a standard format to facilitate subsequent analysis and processing. Protocol identification includes preliminary classification based on the five-tuple of source IP, destination IP, source port, destination port, and protocol type to determine whether deep inspection or encryption is required. Among these, the preprocessing steps such as data cleaning, normalization, and protocol identification can be implemented through VPP's built-in classification mechanism, which performs fast matching and classification based on flow tables to ensure low-latency processing under high throughput.

[0153] Furthermore, taking the deployment of a national cryptographic signaling security gateway between the public network and the private network as an example, the processing flow of signaling messages that require DPI processing will be described below.

[0154] Figure 3 This is a deployment diagram of the national cryptographic signaling security gateway provided in this application, such as... Figure 3 As shown, a sunken UPF network element is deployed as the private network side, and a full set of 5G network elements is deployed as the public network side. A national cryptographic signaling security gateway is deployed between the private network elements and the public network elements. Port 1 of the national cryptographic signaling security gateway connects to the private network element, and port 2 connects to the public network element. The private network element installs the national cryptographic VPN SDK and establishes a national cryptographic encrypted tunnel with the signaling security gateway. Topology hiding and signaling forwarding rules, as well as packet parsing and protection rules, are configured within the national cryptographic signaling security gateway. This enables the signaling data from the private network side to be transmitted to the national cryptographic signaling security gateway in an encrypted manner. The national cryptographic signaling security gateway then analyzes the packet traffic before forwarding it to the corresponding public network element.

[0155] By deploying a signaling security gateway between the private network elements and the core network, topology hiding and network isolation can be achieved for the communication networks of both parties, and data transmission can be encrypted based on national cryptographic algorithms, thus protecting the operator's core network.

[0156] Figure 4 This is a schematic diagram of the signaling message processing flow provided in this application, such as... Figure 4 As shown, the message processing method of the signaling detection engine in the national cryptographic signaling security gateway is designed based on VPP nodes. To realize the overall function, message input nodes, message decryption nodes, topology hiding nodes, signaling analysis blocking nodes, route lookup nodes and forwarding nodes are designed.

[0157] For message input nodes, by designing message input nodes, after the signaling data of the private network element enters the national cryptographic signaling security gateway through the network port, the national cryptographic signaling security gateway captures the signaling and enters the signaling processing logic.

[0158] For the message decryption node, a national cryptographic encryption tunnel is established between the private network element and the signaling security gateway to ensure the confidentiality and integrity of the signaling data. Therefore, a message decryption node is designed to decrypt the message before it enters the signaling security gateway.

[0159] For topology hiding nodes, which have NAT functionality, by designing topology hiding nodes, the communication addresses of private network elements are located in the national cryptographic signaling security gateway, while the real interaction addresses of related messages are forwarded by the internal modules of the signaling security gateway, which can prevent external attacks caused by the leakage of the public network topology.

[0160] For routing lookup nodes and forwarding nodes, by designing routing lookup nodes and forwarding nodes, normal signaling message traffic that needs to be forwarded can be forwarded to the corresponding public network element according to predefined mapping rules.

[0161] For signaling analysis and blocking nodes, which are the core modules for signaling analysis and processing, the specific business logic is divided into the following processes: ① Packet capture module: Collects network data packets, encapsulates them into Packet objects, and then passes them to the Decode thread module; ② Protocol parsing module: Decodes the packet according to the 4-layer protocol model (data link layer, network layer, transport layer, application layer), obtains the protocol header and payload information, and passes the packet to the flow management module after decoding; ③ Flow Management Module: Uses flow tables to track and manage monitored network connections. Each flow is identified by a 5-tuple. It performs packet flow allocation, TCP session management, TCP reassembly, application layer data parsing and processing, and rule detection. ④ Application Layer Protocol Parsing Module: Parses the content of upper-layer protocols such as HTTP, UDP, and PFCP, extracts key fields of the upper-layer protocols, such as HTTP URI, method, and Host header, and uses these fields as matching conditions for detection rules; ⑤ Rule detection engine: This part matches the parsed message fields with preset detection rules. It can use multi-pattern matching algorithms such as Aho-Corasick algorithm and single-pattern matching algorithm such as Boyer-Moore algorithm to accelerate the matching process. After a successful match, the message is marked and enters the next processing stage. ⑥ Neural Network Detection Engine: This part is based on a GNN neural network with a monarch matrix. After pre-training, it is integrated into the signaling analysis node to perform anomaly detection of topological and temporal features for PFCP signaling. ⑦ Judgment and Response Module: Based on the condition design, after detecting a matching abnormal signaling message, it will take the next step, such as log storage, alarm, and discarding abnormal signaling messages and traffic that need to be blocked according to rules.

[0162] By adopting a layered architecture design with good modularity and decoupling characteristics, it is easy to carry out subsequent function expansion, component replacement and system maintenance.

[0163] The PFCP signaling anomaly detection method provided in this application integrates the PFCP signaling anomaly detection scheme as a neural network module of the signaling security gateway detection engine into the packet processing node graph of the VPP. That is, it integrates anomaly detection model structures such as Monarch-GNN with the signaling security gateway VPP processing pipeline, which can realize real-time anomaly detection in the high-speed data plane.

[0164] Overall, the PFCP signaling anomaly detection method provided in this application breaks through the computational bottleneck of traditional Transformer in long sequence processing. It processes IE-level temporal features through Monarch, captures network topology relationships by combining GNN, and finally achieves high-precision anomaly detection through topology-aware clustering head. It marks PFCP signaling that cannot be reliably classified into normal clustering patterns as anomalies, which is particularly suitable for real-time or near-real-time core network signaling analysis scenarios.

[0165] Figure 5 This is a schematic diagram of the PFCP signaling anomaly detection device provided in this application, as shown below. Figure 5 As shown, the PFCP signaling anomaly detection device includes, but is not limited to, an extraction module 501, a feature reconstruction module 502, and an anomaly detection module 503.

[0166] Extraction module 501 is used to extract the topological feature vector of the PFCP signaling set based on the dynamic heterogeneous graph of the PFCP signaling set; the nodes of the dynamic heterogeneous graph represent network functional entities associated with PFCP signaling; the edges of the dynamic heterogeneous graph represent the signaling interaction relationship of PFCP signaling; the node features of the dynamic heterogeneous graph represent the content embedding vector corresponding to the PFCP signaling associated with the network functional entities. Feature reconstruction module 502 is used to determine a global reconstruction feature vector based on the timing feature vector of the PFCP signaling set and the topology feature vector; Anomaly detection module 503 is used to determine abnormal PFCP signaling in the PFCP signaling set based on the global reconstructed feature vector.

[0167] It should be noted that the PFCP signaling anomaly detection device provided in this application can execute the PFCP signaling anomaly detection method described in any of the above embodiments during actual operation, which will not be elaborated in this embodiment.

[0168] The PFCP signaling anomaly detection device provided in this application constructs nodes and edges of a dynamic heterogeneous graph of the PFCP signaling set based on the network functional entities and signaling interaction relationships associated with the PFCP signaling. It determines the node features of the dynamic heterogeneous graph based on the content embedding vectors corresponding to the PFCP signaling associated with the network functional entities, thus obtaining a dynamic heterogeneous graph that fully models the topological dependencies of the propagation paths between PFCP signaling and the interaction patterns between network functional entities. On one hand, it extracts topological features from the dynamic heterogeneous graph of the PFCP signaling set; on the other hand, it extracts temporal features from the content embedding vectors of each PFCP signaling in the PFCP signaling set. It performs feature fusion and feature reconstruction on the topological and temporal features, and finally detects abnormal PFCP signaling in the PFCP signaling set based on the globally reconstructed feature vector after feature reconstruction. This achieves the detection of abnormal PFCP signaling related to the topology structure, improving the detection accuracy of abnormal PFCP signaling.

[0169] Figure 6 This is a schematic diagram of the structure of the electronic device provided in this application, such as... Figure 6 As shown, the electronic device may include: a processor 610, a communications interface 620, a memory 630, and a communication bus 640, wherein the processor 610, the communications interface 620, and the memory 630 communicate with each other through the communication bus 640. The processor 610 can call logical instructions in the memory 630 to execute the PFCP signaling anomaly detection method provided in any of the above embodiments. The PFCP signaling anomaly detection method includes, but is not limited to, the following steps: extracting the topological feature vector of the PFCP signaling set based on a dynamic heterogeneous graph of the PFCP signaling set; the nodes of the dynamic heterogeneous graph represent network functional entities associated with the PFCP signaling; the edges of the dynamic heterogeneous graph represent the signaling interaction relationships of the PFCP signaling; the node features of the dynamic heterogeneous graph represent the content embedding vector corresponding to the PFCP signaling associated with the network functional entities; determining a global reconstruction feature vector based on the temporal feature vector of the PFCP signaling set and the topological feature vector; and determining abnormal PFCP signaling in the PFCP signaling set based on the global reconstruction feature vector.

[0170] Furthermore, the logical instructions in the aforementioned memory 630 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0171] On the other hand, this application also provides a computer program product, which includes a computer program that can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the PFCP signaling anomaly detection method provided in any of the above embodiments. The PFCP signaling anomaly detection method includes, but is not limited to, the following steps: extracting the topological feature vector of the PFCP signaling set based on a dynamic heterogeneous graph of the PFCP signaling set; the nodes of the dynamic heterogeneous graph represent network functional entities associated with the PFCP signaling; the edges of the dynamic heterogeneous graph represent the signaling interaction relationships of the PFCP signaling; the node features of the dynamic heterogeneous graph represent the content embedding vector corresponding to the PFCP signaling associated with the network functional entities; determining a global reconstruction feature vector based on the temporal feature vector of the PFCP signaling set and the topological feature vector; and determining abnormal PFCP signaling in the PFCP signaling set based on the global reconstruction feature vector.

[0172] In another aspect, this application also provides a non-transitory computer-readable storage medium storing a computer program thereon. When executed by a processor, the computer program implements the PFCP signaling anomaly detection method provided in any of the above embodiments. The PFCP signaling anomaly detection method includes, but is not limited to, the following steps: extracting the topological feature vector of the PFCP signaling set based on a dynamic heterogeneous graph of the PFCP signaling set; the nodes of the dynamic heterogeneous graph represent network functional entities associated with the PFCP signaling; the edges of the dynamic heterogeneous graph represent the signaling interaction relationships of the PFCP signaling; the node features of the dynamic heterogeneous graph represent the content embedding vector corresponding to the PFCP signaling associated with the network functional entities; determining a global reconstruction feature vector based on the temporal feature vector of the PFCP signaling set and the topological feature vector; and determining abnormal PFCP signaling in the PFCP signaling set based on the global reconstruction feature vector.

[0173] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.

[0174] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.

[0175] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application.

Claims

1. A method for detecting PFCP signaling anomalies, characterized in that, include: Based on the dynamic heterogeneous graph of the PFCP signaling set, the topological feature vector of the PFCP signaling set is extracted; The nodes of the dynamic heterogeneous graph represent network function entities associated with PFCP signaling; the edges of the dynamic heterogeneous graph represent signaling interaction relationships of PFCP signaling; and the node features of the dynamic heterogeneous graph represent the content embedding vectors corresponding to the PFCP signaling associated with the network function entities. Based on the timing feature vector of the PFCP signaling set and the topology feature vector, the global reconstruction feature vector is determined; Based on the global reconstruction feature vector, abnormal PFCP signaling in the PFCP signaling set is determined.

2. The PFCP signaling anomaly detection method according to claim 1, characterized in that, For each PFCP signaling in the PFCP signaling set, the content embedding vector corresponding to the PFCP signaling is determined based on the following method: Based on the sub-embedding vectors corresponding to multiple information elements in the PFCP signaling, the content embedding vector corresponding to the PFCP signaling is determined. For each information element in the PFCP signaling, the sub-embedding vector corresponding to the information element is determined based on the following method; Based on the content byte sequence of the information element, determine the content encoding of the information element; Based on the attribute type of the information element, determine the attribute encoding of the information element; Based on the location information of the information element, determine the location code of the information element; Based on the content encoding, the attribute encoding, and the position encoding, the sub-embedding vector corresponding to the information element is determined.

3. The PFCP signaling anomaly detection method according to claim 2, characterized in that, Determining the location code of the information element based on its location information includes: The time position code of the information element is determined based on the element sequence index of the information element in its respective PFCP signaling. The topology location code of the information element is determined based on the network function entity associated with the PFCP signaling to which the information element belongs; The location code of the information element is determined based on the time location code and the topological location code.

4. The PFCP signaling anomaly detection method according to claim 1, characterized in that, The determination of the global reconstruction feature vector based on the timing feature vector of the PFCP signaling set and the topology feature vector includes: Based on the content embedding vectors corresponding to multiple PFCP signaling in the PFCP signaling set, the temporal feature vector of the PFCP signaling set is extracted; Based on the temporal feature vector and the topological feature vector, a global fusion feature vector is determined; The global fusion feature vector is subjected to feature representation reconstruction processing to obtain the global reconstructed feature vector.

5. The PFCP signaling anomaly detection method according to claim 4, characterized in that, The step of extracting the temporal feature vector of the PFCP signaling set based on the content embedding vectors corresponding to multiple PFCP signaling messages in the PFCP signaling set includes: Based on the content embedding vectors corresponding to multiple PFCP signaling messages in the PFCP signaling set, the overall embedding vector of the PFCP signaling set is determined. The overall embedding vector is input into the temporal feature extraction model to obtain the temporal feature vector output by the temporal feature extraction model; The time-series feature extraction model includes a sequence mixer, a channel mixer, a residual connection layer, a normalization layer, and an output layer connected in sequence; the sequence mixer is built based on a permutation and block diagonal product matrix.

6. The PFCP signaling anomaly detection method according to claim 4, characterized in that, The step of determining the global fusion feature vector based on the temporal feature vector and the topological feature vector includes: Based on the temporal feature vector and the first weighting factor, the first sub-fusion vector is determined; Based on the topological feature vector and the second weighting factor, the second sub-fusion vector is determined; Based on the first sub-fusion vector and the second sub-fusion vector, the fusion feature vector is determined; Based on the fused feature vector and the topological feature vector, the global fused feature vector is obtained; Wherein, the sum of the first weighting factor and the second weighting factor is 1; the first weighting factor and the second weighting factor are determined based on the gating attention mechanism.

7. The PFCP signaling anomaly detection method according to claim 4, characterized in that, The step of performing feature representation reconstruction processing on the global fused feature vector to obtain the global reconstructed feature vector includes: The global fusion feature vector is input into the temporal feature reconstruction model to obtain the reconstructed temporal feature vector output by the temporal feature reconstruction model; the structure of the temporal feature reconstruction model is symmetrical to the structure of the temporal feature extraction model. Based on the reconstructed temporal feature vector, the global reconstructed feature vector is determined; The step of determining the abnormal PFCP signaling in the PFCP signaling set based on the globally reconstructed feature vector includes: Based on the global reconstruction feature vector, determine the sub-reconstruction feature vectors corresponding to multiple PFCP signaling in the PFCP signaling set; Cluster analysis is performed on multiple sub-reconstruction feature vectors, and the sub-reconstruction feature vectors with classification reliability less than a preset reliability threshold are identified as abnormal sub-reconstruction feature vectors. The PFCP signaling corresponding to the reconstructed feature vector of the anomaly is identified as the anomalous PFCP signaling.

8. The PFCP signaling anomaly detection method according to claim 7, characterized in that, Before extracting the topological feature vector of the PFCP signaling set from the dynamic heterogeneous graph based on the PFCP signaling set, the method further includes: Based on the joint training loss of the autoencoder, autodecoder, and cluster head, the model parameters of the autoencoder, the model parameters of the autodecoder, and the initial cluster centers of the cluster head are updated. The joint training loss is determined based on reconstruction loss, clustering loss, and topology consistency loss; the reconstruction loss is determined based on the global fusion feature vector and the global reconstruction feature vector during the joint training process; the topology consistency loss is determined based on the topology feature vector and the reconstructed topology graph during the joint training process; and the clustering loss is determined based on the classification reliability during the joint training process. The autoencoder is used to implement the dynamic heterogeneous graph based on the PFCP signaling set, extract the topological feature vector of the PFCP signaling set, implement the content embedding vectors corresponding to multiple PFCP signaling in the PFCP signaling set, extract the temporal feature vector of the PFCP signaling set, and determine the global fusion feature vector based on the temporal feature vector and the topological feature vector. The self-decoder is used to perform feature representation reconstruction processing on the global fused feature vector to obtain the global reconstructed feature vector; The clustering head is used to determine the abnormal PFCP signaling in the PFCP signaling set based on the global reconstructed feature vector.

9. The PFCP signaling anomaly detection method according to claim 8, characterized in that, The initial cluster centers are determined based on the following method; Based on a predetermined number of randomly selected first PFCP signaling normal samples, determine the predetermined number of initial centers for clusters; The first PFCP signaling normal sample is the PFCP signaling normal sample used to determine the initial center; Based on the topological sensing distance between the second PFCP signaling normal sample and the first PFCP signaling normal sample, the multiple second PFCP signaling normal samples are respectively assigned to the initial center with the closest topological sensing distance; The second PFCP signaling normal sample is a PFCP signaling normal sample used to adjust the initial center; Based on the allocated second PFCP signaling normal samples and the first PFCP signaling normal samples, the initial center is adjusted to determine the initial cluster center.

10. The PFCP signaling anomaly detection method according to claim 1, characterized in that, The PFCP signaling anomaly detection method is applied to the national cryptographic signaling security gateway.

11. A PFCP signaling anomaly detection device, characterized in that, include: The extraction module is used to extract the topological feature vector of the PFCP signaling set based on the dynamic heterogeneous graph of the PFCP signaling set; The nodes of the dynamic heterogeneous graph represent network function entities associated with PFCP signaling; the edges of the dynamic heterogeneous graph represent signaling interaction relationships of PFCP signaling; and the node features of the dynamic heterogeneous graph represent the content embedding vectors corresponding to the PFCP signaling associated with the network function entities. The feature reconstruction module is used to determine the global reconstruction feature vector based on the timing feature vector of the PFCP signaling set and the topology feature vector; An anomaly detection module is used to determine abnormal PFCP signaling in the PFCP signaling set based on the global reconstructed feature vector.

12. An electronic device comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that, When the processor executes the computer program, it implements the PFCP signaling anomaly detection method as described in any one of claims 1 to 10.

13. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the PFCP signaling anomaly detection method as described in any one of claims 1 to 10.

14. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the PFCP signaling anomaly detection method as described in any one of claims 1 to 10.