Abnormal management device and abnormal management method
The abnormality management device addresses the challenge of managing clone SIMs by quantizing residence times and using a multinomial distribution model to generate pseudo-normal data, enhancing the detection and blocking of unauthorized communication.
Patent Information
- Application Number
- JP2025107022
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2025-06-25
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2045-06-25
AI Technical Summary
Existing systems struggle to reliably manage abnormal communications, particularly when clone SIMs illegally impersonate legitimate users, making it difficult to distinguish between legitimate and illegal location registration requests, especially when they occur from locations close to the legitimate user.
An abnormality management device that quantizes normal residence time in communication areas, uses a first learning unit to estimate probability parameters for a multinomial distribution model, and a second learning unit to generate pseudo-normal data deviating from true normal data, allowing a discriminator to accurately identify abnormal communication patterns.
Enhances the reliability of managing abnormal communications by effectively identifying and blocking unauthorized communication, even when clone SIMs are used in close proximity to legitimate users.
Smart Images

Figure 0007710636000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to an abnormality management device and an abnormality management method.
Background Art
[0002] In recent years, there has been a problem of so-called clone SIMs in which an attacker illegally obtains a legitimate user's International Mobile Subscriber Identity (IMSI), illegally accesses a mobile IP network, impersonates the legitimate user to send a location registration request signal, and intercepts the legitimate user's communication (see Non-Patent Documents 1 and 2).
[0003] As a technique for detecting such an illegal location registration request, conventionally, the base station number and the AMF (Access and Mobility Management Function) number included in the location registration request to the control device on the mobile carrier network side are checked, and for example, when a location registration request with the same IMSI is made almost simultaneously from locations far apart such as Japan and foreign countries, a technique for detecting it as an illegal access is known (see Non-Patent Document 1).
[0004] However, when there is an illegal location registration request from a location relatively close to the location of the legitimate user (for example, within Japan), it is difficult to distinguish whether it is a location registration request from the legitimate user or an illegal location registration request from an attacker. Therefore, it has been difficult to detect clone SIMs and manage such abnormal communications.
Prior Art Documents
Non-Patent Documents
[0005]
Non-Patent Document 1
Non-Patent Document 2
Summary of the Invention
Problems to be Solved by the Invention
[0006] Thus, in the prior art, it was difficult to more reliably manage abnormal communications.
[0007] The present invention has been made to solve the above-described problems, and an object thereof is to more reliably manage abnormal communications.
Means for Solving the Problems
[0008] In order to solve the above problems, the abnormality management device according to the present invention quantizes the normal residence time in the communication area of each base station where each of a plurality of communication terminals resides as it moves, and converts it into a normal residence time series of integer values. A quantization unit configured to handle each observation value of the normal residence time series as discrete values independent of each other, and estimate probability parameters of a probability model representing the normal residence time after quantization based on the appearance frequency of each observation value. A first learning unit configured to fix the generator parameters of a generator that generates pseudo-normal data that sufficiently deviates from the distribution of the true normal data, with each observation value of the normal residence time series as the true normal data, and only update the discriminator parameters of a discriminator that discriminates between the true normal data and the pseudo-normal data in a direction to maximize the discrimination accuracy based on the probability parameters of the normal residence time estimated by the first learning unit. A second learning unit configured to store the pseudo-normal data output by the generator as information indicating an abnormal residence time in the communication area of each base station by a communication terminal performing abnormal communication after the discriminator parameters of the discriminator are updated by the second learning unit. A storage unit is provided.
[0009] Further, in the abnormality management device according to the present invention, an acquisition unit configured to acquire the residence time of a communication terminal to be managed in the communication area of each base station as it moves is further provided. The quantization unit quantizes the acquired residence time of the communication terminal to be managed and converts it into a residence time series of integer values. Further, when the residence time series matches the pseudo-normal data stored in the storage unit, a determination unit configured to determine that abnormal communication has occurred by the communication terminal to be managed may be provided.
[0010] Further, in the abnormality management device according to the present invention, a communication management unit configured to issue an instruction to block the communication of the communication terminal to be managed may be provided when it is determined by the determination unit that abnormal communication has occurred.
[0011] Further, in the abnormality management apparatus according to the present invention, the communication terminal to be managed may have a plurality of identical subscriber identifiers for which it has been detected that the terminal is located in the communication areas of a plurality of different base stations in the same time zone.
[0012] In order to solve the above-described problems, an abnormality management method according to the present invention includes: a quantization step of quantizing a normal residence time in a communication area of each base station where each of a plurality of communication terminals is located as the terminals move, and converting the normal residence time into an integer-valued normal residence time series; a first learning step of treating each observed value of the normal residence time series as a discrete value independent of each other, and estimating probability parameters of a probability model representing the normal residence time after quantization based on the appearance frequency of each observed value; a second learning step of fixing generator parameters of a generator that generates pseudo-normal data that sufficiently deviates from the distribution of true normal data, with each observed value of the normal residence time series being true normal data, and updating only the discriminator parameters of a discriminator that discriminates between the true normal data and the pseudo-normal data in a direction to maximize the discrimination accuracy, based on the probability parameters of the normal residence time estimated in the first learning step; and a storage step of storing, in a storage unit, the pseudo-normal data output by the generator as information indicating an abnormal residence time in the communication area of each base station by a communication terminal that performs abnormal communication, after the update of the discriminator parameters of the discriminator in the second learning step.
[0013] Further, the abnormality management method according to the present invention may further include an acquisition step of acquiring a residence time during which a communication terminal to be managed is located in the communication area of each base station as the terminal moves, where the quantization step quantizes the residence time of the communication terminal to be managed acquired in the acquisition step and converts the residence time into an integer-valued residence time series, and further includes a determination step of determining that abnormal communication has occurred by the communication terminal to be managed when the residence time series matches the pseudo-normal data stored in the storage unit.
[0014] Further, in the abnormality management method according to the present invention, a communication management step may be further provided for issuing an instruction to cut off the communication of the communication terminal to be managed when it is determined in the determination step that abnormal communication has occurred.
[0015] Further, in the abnormality management method according to the present invention, the communication terminal to be managed may have a plurality of identical subscriber identifiers for which it has been detected that it is located in the communication areas of a plurality of different base stations in the same time zone.
Effects of the Invention
[0016] According to the present invention, after the discriminator parameter of the discriminator by the second learning unit is updated, the pseudo-normal data output by the generator is stored as information indicating the abnormal presence time in each communication area by the communication terminal performing abnormal communication. Therefore, abnormal communication can be managed more reliably.
Brief Description of the Drawings
[0017]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Mode for Carrying Out the Invention
[0018] Hereinafter, preferred embodiments of the present invention will be described in detail with reference to FIGS. 1 to 10.
[0019] [Configuration of Anomaly Management System] First, with reference to FIG. 1, an overview of an anomaly management system including the anomaly management device 1 according to an embodiment of the present invention will be described.
[0020] The anomaly management system according to the present embodiment is provided, for example, in a mobile communication network compliant with the 5G communication standard. The anomaly management system includes an anomaly management device 1, a communication terminal 2, a base station 3, and a core network 4. When there is very little abnormal data related to abnormal communication due to unauthorized use of IMSI, while a large amount of normal data related to communication by legitimate users is available, the anomaly management system generates abnormal data through learning processing based on the normal data and constructs a database of abnormal data for anomaly determination.
[0021] The communication terminal 2 can be realized by a computer including a processor, a main storage device, a communication interface, an auxiliary storage device, and input / output I / O, and a program for controlling these hardware resources. The communication terminal 2 also includes a SIM (Subscriber Identity Module) and is realized as a mobile communication terminal such as a smartphone, a tablet computer, a laptop computer, a wearable device, an industrial robot, or the like. In the present embodiment, there are a plurality of communication terminals 2.
[0022] The SIM installed in the communication terminal 2 stores the user's contract profile. The contract profile of the SIM stores the subscriber identification information of the user, including the IMSI which is a subscriber identifier assigned to the mobile phone line contract, the phone number (MSISDN: Mobile Subscriber International Subscriber Directory Number) of the user who is the subscriber, the SIM card number (ICCID: Integrated Circuit Card Identifier), and other identification information. The communication terminal 2 is uniquely identified by the assigned IMSI. Note that the actual user is called a legitimate user, and when referring to "illegal", it refers to actions such as when an attacker who is not a legitimate user uses the IMSI of a legitimate user to communicate. Also, such illegal communication is managed by the anomaly management system as abnormal communication.
[0023] The communication terminal 2 can also be configured as an IoT device to which a terminal IP address that uniquely identifies the terminal is assigned. In this embodiment, there are n (n is a positive integer of 2 or more) communication terminals 2.
[0024] Each communication terminal 2 performs mobile communication and sequentially moves from the communication area of the base station 3 in the current location to the communication area of the destination base station 3 according to the movement route. When the communication terminal 2 crosses from the communication area of the source base station 3 to the communication area of the destination base station 3, at a certain period and when power is turned on, it sends a location registration request signal to the core network 4 via the base station 3 in the communication area where it is located.
[0025] The base station 3 is composed of a radio base station compatible with the 5G communication standard and relays communication between the communication terminal 2 in the communication area and the core network 4. Each base station 3 and each communication area are specified by the address of the AMF 40. Each base station 3 is connected to the core network 4 via a network such as a backhaul link. In this embodiment, each base station 3 is assumed to cover one communication area.
[0026] The core network 4 is connected to the anomaly management device 1 via a network NW such as a LAN or WAN. The core network 4 includes an AMF 40, a UDM (Unified Data Management) 41, and a UDR 42, which are nodes in the control plane (C-plane). Note that illustration of other functions of the core network 4 is omitted.
[0027] The AMF 40 is a node that provides a mobility control function and performs mobility control such as location registration, paging, and handover. The UDM 41 is a node that manages user contract information and authentication information. The address of the AMF 40 identifies the base station 3 and the communication area covered by the base station 3.
[0028] The UDR 42 is a node that stores a subscriber profile holding the IMSI and presence information of the communication terminal 2. The UDR 42 is realized by a computer including a processor, a main storage device, a communication interface, an auxiliary storage device, and input / output I / O, and a program that controls these hardware resources. The UDR 42 also includes a communication interface 42a for communicating with the anomaly management device 1. The UDR 42 stores the time stamp of the location registration request signal transmitted for each IMSI as a transmission history.
[0029] FIG. 2 is a table 420 in which presence information for each IMSI included in the subscriber profile held by the UDR 42 is stored. As shown in the table 420, in the subscriber profile, the IMSI, the transmission time stamp of the location registration request signal, and the address of the AMF 40 as the presence information at the time of the time stamp are associated with each other. Further, in the subscriber profile, the transmission interval [s] of the location registration request signal based on the transmission time stamp of the location registration request signal for each IMSI is recorded as a history.
[0030] The communication terminal 2 moves successively into the communication area of the next base station 3 according to each movement route and stays within it for a predetermined time. Then, each time the communication area of the destination is crossed, the location registration request signal transmitted by each communication terminal 2 and the location registration request signal transmitted at a fixed period update the presence information in the table 420. As shown in the table 420, based on the address of the AMF 40 corresponding to the time of the transmission timestamp of the location registration request signal for each IMSI, the presence time of each IMSI in each communication area of the destination is obtained for every predetermined time (for example, in units of 10 minutes).
[0031] In addition, the UDR 42 detects a plurality of identical IMSIs that are present in the communication areas of a plurality of different base stations 3 in the same time zone based on the presence information of each IMSI registered in the subscriber profile. For example, if the presence information of the same IMSI is recorded in the communication areas of base stations 3 arranged at geographically different positions at intervals of less than 1 minute, the UDR 42 detects it as an IMSI with inconsistent presence information. The IMSIs with inconsistent presence information detected by the UDR 42 include a plurality of identical IMSIs that communicate in the same time zone in the communication areas of a plurality of base stations 3 arranged at a relatively short geographical distance. The UDR 42 notifies the anomaly management device 1 of the history of the presence time of the IMSI detected as having inconsistent presence information.
[0032] FIG. 3 is a bar graph showing examples of normal presence times and abnormal presence times in the communication area of each destination base station 3 in the process of the communication terminal 2 successively moving through the communication areas of a plurality of base stations 3. Each bar indicates, for example, the presence time [minutes] of the communication terminal 2 in the communication area of the destination base station 3 over 24 hours in units of 10 minutes. The bars shown in shaded are normal presence times, and the bars shown in black are abnormal presence times. FIG. 3 shows the history of the presence time of one communication terminal 2, but similarly, there is a history of the presence time of each communication terminal 2 in the communication area of the destination.
[0033] The "next destination base station" in FIG. 3 can be different base stations 3 if the movement routes are different for each communication terminal 2. That is, the residence times of the base stations 3 corresponding to the respective movement routes of the plurality of communication terminals 2 in their communication areas are collected by the abnormality management device 1 described later in a predetermined time unit such as 10 minutes.
[0034] As shown in FIG. 3, it can be seen that there is a difference in the residence time between the "normal value" indicating the normal residence time associated with the communication by a legitimate user and the "abnormal value" indicating the abnormal residence time caused by abnormal communication performed by an attacker or the like who is not a legitimate user using the IMSI of the legitimate user, and there is some tendency. Here, the normal residence time in FIG. 3 is the residence time actually observed based on the history of the residence time recorded in the subscriber profile of the UDR 42, but the data related to the abnormal residence time shows an example of a virtual abnormal residence time, and actually, it is the data registered in the abnormal residence time database 14 constructed through the learning process by the abnormality management device 1.
[0035] [Function Blocks of Abnormality Management Device] Next, the function blocks of the abnormality management device 1 according to the present embodiment will be described with reference to the block diagram of FIG. 1. As shown in FIG. 1, the abnormality management device 1 includes a collection unit 10, a quantization unit 11, a first learning unit 12, a second learning unit 13, an abnormal residence time database (storage unit) 14, an acquisition unit 15, a determination unit 16, a communication management unit 17, and a storage unit 18.
[0036] The collection unit 10 refers to the table 420 of the subscriber profile stored in the UDR 42 provided in the core network 4, and collects the residence time of each of the plurality of communication terminals 2 in the communication area of each base station 3 as it moves. The collection unit 10 collects the history of the normal residence time used by the first learning unit 12 and the second learning unit 13 for learning respectively.
[0037] The collection unit 10 collects, for example, the residence time for each destination communication area in units of 10 minutes, on a monthly basis with a 24-hour cycle, for each IMSI. In the bar graph of FIG. 3, for example, when the same communication terminal 2 is present in both the communication area of base station 3 before movement and the communication area of base station 3 after movement within a 10-minute unit, it is counted as the residence time in the communication area of base station 3 after movement. When there are, for example, 10 million communication terminals 2, the collection unit 10 collects the residence time for each communication terminal 2 at the communication area of each destination base station 3.
[0038] The quantization unit 11 quantizes the normal residence time in the communication area of each base station 3 where each of the plurality of communication terminals 2 resides due to movement, and converts it into a normal residence time series of integer values. The quantization unit 11 converts the residence time for each communication area of the destination base station 3 in units of IMSI, which can be regarded as the normal residence time and collected by the collection unit 10, into set discrete values of integers, for example, positive integer level values 1 to 7 as shown on the right vertical axis of FIG. 3. The quantization unit 11 rounds down or rounds up the value by rounding. The quantization unit 11 further quantizes the residence time of the communication terminal 2 to be managed, which is acquired by the acquisition unit 15 described later, in the communication area of each base station 3, and converts it into a residence time series of integer values.
[0039] The first learning unit 12 treats each observed value in the normal residence time series as independent discrete values from each other, and estimates the probability parameters of the probability model representing the normal residence time after quantization based on the occurrence frequency of each observed value. The first learning unit 12 sets a probability model based on a multinomial distribution for the normal residence time, estimates its probability parameters, and calculates the log-likelihood of the series of each observed value based on the probability model. That is, when the data of abnormal residence time is very small, the first learning unit 12 uses the data of normal residence time that can be obtained in large quantities to obtain a probability model of normal residence time, which is a statistical criterion, and an index of normality for it.
[0040] The first learning unit 12 focuses on the fact that the naive Bayes method treats each observed value as a conditionally independent discrete variable, and extends the naive Bayes to a multinomial distribution model to set up a probability model so that the quantized presence time can be regarded as a vector of the number of occurrences for each category for each communication area of the destination base station 3. Here, as shown in the following formula (1), the presence time observed in the communication area of each base station 3 is quantized, and the vector represented by the number of occurrences in M categories is taken as the observed value X. X = x = (x1, x2, ···, x M ) ···(1)
[0041] Also, the class label to which the observed value X belongs, that is, the event Y, is defined by the following formula (2) as a binary variable.
Number
[0042] Here, Bayes' theorem is defined by the following formula (3).
Number
[0043] In the above formula (3), P(X) is the marginal probability (result) that the observed value X is observed, P(Y) is the prior probability that the event Y occurs, P(X|Y) is the conditional probability that the observed value X occurs given that the event Y has occurred, and P(Y|X) is the conditional probability (posterior probability) that the event Y occurs given that the observed value X has occurred. Maximum likelihood estimation is known to obtain the parameter of the prior probability P(Y) such that the posterior probability P(Y|X) is maximized, with the observed value X as the teacher signal which is the correct value. In contrast, Bayesian estimation is a procedure for obtaining the parameter (probabilistic value) of the prior probability P(Y) that best explains the observed value X represented by the quantized presence time series.
[0044] That is, the parameters of the prior probability P(Y) are arbitrarily set in advance (e.g., normal distribution), and the parameters of the prior probability P(Y) that maximize P(X|Y), that is, the prior probability P(Y) that best matches the marginal probability P(X) (result) can be estimated. Thus, the advantage of Bayesian estimation is that the prior probability P(Y) can be arbitrarily specified in advance. When each of P(X|Y) is independent, the observed variables x i are conditionally independent of each other, and the likelihood ρ(x|y) is given by the simple Bayesian estimation method of the following equation (4).
[0045]
Equation
[0046] In this embodiment, in order to handle a series of integer values obtained by quantizing the dwelling time for each base station 3 (communication area), instead of a single observed value, the number-of-occurrences vector x = (x1, x2, ···, x M ) for each category is regarded as one sample, and while maintaining the naive assumption that each base station 3 (communication area) is conditionally independent, it is extended to a probability model of a multinomial distribution. The occurrence probabilities θ1, ···, θ M of each marginal probability P(X) are independent, and under the constraint that the sum of these occurrence probabilities is 1, the probability model of the multinomial distribution is represented by the following equation (5).
[0047]
Equation
[0048] As shown in the above equation (5), when the sum (x1 + x2 + ··· + x i ) of the observed values x M , which are the count values of the dwelling time in the communication area of each base station 3, is determined, the distribution becomes the product of the following equation (6), and for each observed value x i observed in the communication area of the i-th base station 3 in the series, the probability θ i ^x i can be obtained independently.
Equation
[0049] Therefore, it can be seen that the relationship is the same as that of the simple Bayes method in Equation (4) above. Here, regarding the prior probability P(Y) as a binary problem of abnormal value (Y = 0) and normal value (Y = 1), the unknown parameters are θ 0 , θ 1 respectively. Also, define D as the marginal probability (result), the observed value of the abnormal value (Y = 0) as D 0 , and the observed value of the normal value (Y = 1) as D 1 respectively. Assuming the naive Bayes independence assumption, transforming the product form into a sum form for Equation (6) above and decomposing the log-likelihood for the set of observed values D, which is the data set, by class, it can be expressed by the following Equation (7).
[0050]
Equation
[0051] Here, the constraint is expressed by the following Equation (8).
Equation
[0052] Furthermore, applying the Lagrange multiplier method, the maximum value of the log-likelihood for the i-th component of the parameter θ 0 of the abnormal value is given by the following Equation (9).
Equation
[0053] Similarly, when obtaining the maximum value of the log-likelihood for the parameter θ 1 of the normal value, under the constraint of Equation (8) above, the parameters θ 1 , θ 0 of the normal value and the abnormal value are expressed by the following Equation (10).
Equation
[0054] Note that, for x i to take an integer value, to prevent the problem that the multinomial distribution diverges when x i ^(n) is 0, smoothing can be performed by specifying +α (e.g., α = 1) smoothing. In this way, the first learning unit 12 regards the series of normal residence times for each quantized base station 3 (communication area) as a multinomial distribution, estimates the probability parameters from the count of the appearance frequencies, and measures the normality by the likelihood. Note that the first learning unit 12 does not estimate the parameter θ 0 for outliers.
[0055] With each observed value of the normal residence time series as the true normal data, while keeping the generator parameters of the generator 131 that generates pseudo-normal data that sufficiently deviates from the distribution of the true normal data fixed, the second learning unit 13 updates only the discriminator parameters of the discriminator 132 that discriminates between the true normal data and the pseudo-normal data in the direction of maximizing the discrimination accuracy, based on the probability parameters of the normal residence time estimated by the first learning unit 12.
[0056] As shown in FIG. 3, the second learning unit 13 executes a Max learning phase in which only the parameters of the discriminator 132 are updated with the generator 131 fixed in a GAN (Generative Adversarial Network) having the generator 131 and the discriminator 132. The second learning unit 13 aims to generate a residence time series that can be treated as pseudo-normal data that sufficiently deviates from the distribution of the normal data, that is, an abnormal residence time series, when the normal residence time series is regarded as the true normal data. Therefore, the learning in the Min learning phase in the adversarial learning procedure of a normal GAN that updates the generator 131 in the minimization direction is not performed.
[0057] As shown in FIG. 4, the generation model according to the present embodiment including the generator 131 and the discriminator 132 is provided for each observed value (base station 3) of the in-campus time series. Therefore, in the present embodiment, learning is performed for M generation models. Here, pseudo-normal data that is sufficiently deviated from the distribution of normal data is a generated series that is located in a region that greatly deviates from the normal region of normal data as a statistical property with respect to normal data indicating a normal in-campus time series. When the index is the log-likelihood, the series with a smaller likelihood corresponds to the distance or divergence from normal data. When the index is the cross-entropy, it can be said that the series with a larger entropy value has a greater divergence. Furthermore, when the KL distance is used as the index, the series with a large deviation of the entire distribution is treated as a sufficiently deviated series.
[0058] FIGS. 5 and 6 are diagrams schematically showing the neural network configurations of the generator 131 and the discriminator 132 of the generation model used by the second learning unit 13. As shown in FIG. 5, the generator 131 is composed of a neural network having an input layer, a hidden layer, and an output layer. The generator 131 is a model that generates pseudo-normal data from random noise. For example, a vector of Gaussian noise is randomly sampled m times and input to the input nodes of the generator 131 (z1 to z m ).
[0059] The generator 131 outputs an output G(z) through a product-sum operation of the input and weight parameters and a threshold process using an activation function. The output G(z) from the generator 131 is pseudo-normal data that deviates from the distribution of true normal data. CNN or ResNet can be used as the neural network constituting the generator 131.
[0060] The discriminator 132 shown in FIG. 6 is composed of a neural network having an input layer, a hidden layer, and an output layer. In the example of FIG. 6, as the input of the training data, the normal in-campus time series collected by the collection unit 10 and obtained by the quantization unit 11 is given as true normal data.
[0061] The discriminator 132 outputs a binary output of 1 or 0 through the product-sum operation of the input and weight parameters and the threshold processing by the activation function. When the discriminator 132 correctly identifies the training data related to the input true normal data as true normal data, it outputs the output y = 1. On the other hand, when the discriminator 132 correctly identifies the training data related to the input pseudo-normal data as pseudo-normal data, it outputs the output y = 0. In this way, the discriminator 132 is a model that distinguishes the model distribution generated by the generator 131 from the data distribution of the training data that is the true distribution. A CNN can be used as the neural network constituting the discriminator 132.
[0062] Figure 4 is a block diagram for explaining the configuration of the generation model by the second learning unit 13. The generator 131 of the generation model adopted by the second learning unit 13 is represented by the function G, and the discriminator 132 is represented by the function D. Also, the true normal data is represented by x, the predicted value that is the output by the discriminator 132 is represented by y, and the correct label is represented by t. The correct label t is set to 1 for the true normal data and 0 for the pseudo-normal data generated by the generator 131. At this time, the discriminator 132, as a binary classification problem, can be represented by the cross entropy E of the following formula (11). CE It can be represented as follows.
[0063]
Equation
[0064] In the first term within the braces of the above formula (11), for t n lny n in, the predicted value y n of the discriminator 132 n is desirably close to the value of the correct label t n = 1 of the true normal data. On the other hand, in (1 - t n )ln(1 - y n ) represented by the second term within the braces, for the predicted value y n of the discriminator 132 n it is desirably close to the value of the correct label for distinguishing as pseudo-normal data (1 - t n ) = 0. In this way, the cross entropy E CEbecomes the maximum value when the predicted value matches the value of the correct label.
[0065] Here, the generator 131 that constitutes the generation model has parameters w G , θ G and is represented by the function G(w G , θ G ). Also, the discriminator 132 has parameters w D , θ D and is represented by the function D(w D , θ D ). The objective function E of the generation model including the generator 131 and the discriminator 132 based on the cross-entropy E CE in the above formula (11) can be represented by the following formula (12).
Equation
[0066] E D(x)=1 lnD(w D , θ D ) represented by the first term of the above formula (12) is the expected value that the discriminator 132 discriminates true normal data as true normal data. E D(x)=0 ln(1 - D(G(w G , θ G ), w D , θ D ) represented by the second term of the above formula (12) is the expected value that the discriminator 132 discriminates the pseudo-normal data generated by the generator 131 as pseudo-normal data. Here, when the prior probabilities of the abnormal value (Y = 0) and the normal value (Y = 1) classes of the multinomial distribution are used and multiplied by the parameters θ 0 , θ 1 and incorporated into the objective function E of the generation model in the above formula (12), the objective function E is represented by the following formula (13).
[0067]
Equation
[0068] In the above formula (13), the parameters θ 0 , θ1 The objective function E of the i-th component is expressed by the following formula (14).
Equation
[0069] By weighting the objective function of the normal GAN (Equation (12)), an adversarial loss in which the contributions of the normal value class and the abnormal value class are proportionally distributed, as in the above equations (13) and (14), can be obtained. Here, the objective function E when the generator 131 is fixed is expressed by the following formula (15).
Equation
[0070] The convergence value (maximum value) of the discriminator 132 is expressed by the following formula (16).
Equation
[0071] The parameter θ i ^1 of the normal value is calculated from the above formula (10). For the parameter θ i ^0 of the abnormal value, since the number of abnormal data related to the abnormal presence time is small, an empirical rule or a preset value is used. The parameters θ i ^1 and θ i ^0 differ in value according to each observed value x i =(1, 2, ···, M). For the ratio of the expected values, E ρ(x|y=1) :E ρ(x|y=0) , since the number of normal data is overwhelmingly large, it is preset, for example, as 0.99:0.01.
[0072] In the learning of the generation model of the present embodiment, only the Max optimization of the objective function E is performed, and the parameters of the discriminator 132 with the generator 131 fixed are learned. Therefore, it is possible to avoid the output of the generator 131 converging to the distribution of normal data, and conversely, to maintain a sequence that is sufficiently deviated from the distribution of normal data. When the update of the discriminator 132 converges, the sequence of pseudo-normal data output by the fixed generator 131 has a low likelihood with respect to the model of normal residence time (the parameter θ of the multinomial distribution 1 ). At this time, the generator 131 can generate only pseudo-normal data, which is an abnormal sequence represented by the following formula (17).
Equation
[0073] The abnormal residence time database 14 stores the pseudo-normal data generated by the generator 131 after the update of the parameters of the discriminator 132 by the second learning unit 13, as information indicating the abnormal residence time in the communication area of each base station 3 by the communication terminal 2 that performs abnormal communication. Specifically, when the generator 131 included in the generation model corresponding to each base station 3 is trained with, for example, 10,000 pieces of training data, 10,000 pieces of pseudo-normal data are generated and registered in the abnormal residence time database 14. The abnormal residence time database 14 registers the history of abnormal residence times in the communication areas of a plurality of base stations 3 that the communication terminal 2 sequentially moves through, as a reference pattern for abnormality determination.
[0074] The acquisition unit 15 acquires the residence time of the communication terminal 2 to be managed in the communication area of each base station 3 as the communication terminal 2 moves. The acquisition unit 15 acquires, from the UDR 42 via the network NW, the communication terminal 2 to be managed, that is, in addition to the IMSI to be managed, the history of the residence time of the IMSI. Similar to the collection unit 10, the acquisition unit 15 acquires, for example, the residence time for each communication area of the base station 3 to which the IMSI to be managed moves in units of 10 minutes.
[0075] The communication terminal 2 to be managed has an IMSI with inconsistencies in the location information. Specifically, it has a plurality of the same IMSIs that have been detected by the UDR 42 as being located in the communication areas of a plurality of different base stations 3 in the same time period. For example, the communication terminal 2 related to an IMSI that may be performing abnormal communication such as a clone SIM, for which location registration requests have been received from different communication areas in a short period of time, is the one to be managed. The acquisition unit 15 acquires, from the UDR 42, the history of the location time of the IMSI with such inconsistencies in the location information.
[0076] When the location time series of the communication terminal 2 to be managed matches the pseudo-normal data stored in the abnormal location time database 14, the determination unit 16 determines that abnormal communication has occurred by the communication terminal 2 to be managed. More specifically, when the location time series converted by the quantization unit 11 in the communication area of each base station 3 where the IMSI to be managed is moving matches the pseudo-normal data stored in the abnormal location time database 14, the determination unit 16 determines that the communication terminal 2 to be managed is a terminal that performs abnormal communication. Specifically, the determination unit 16 determines that the IMSI to be managed is suspected of being misused by a clone SIM.
[0077] In addition to the case of matching the pseudo-normal data stored in the abnormal location time database 14, when the sum of the squares of the differences between the level value of the location time series of the communication terminal 2 to be managed and the level value of the pseudo-normal data stored in the abnormal location time database 14 is within the set threshold according to the following formula (18), the determination unit 16 can determine that there is an abnormal location time, that is, abnormal communication has occurred.
Equation
[0078] When the determination unit 16 determines that abnormal communication has occurred, the communication management unit 17 instructs to cut off the communication with the communication terminal 2 to be determined. For example, the communication management unit 17 designates the IMSI of the communication terminal 2 to be managed and sends an instruction to cut off the communication to the core network 4. Specifically, the communication management unit 17 instructs the UDR 42 and the UDM 41 to set access rejection for the IMSI performing abnormal communication, and further notifies the UDM 41 and the AMF 40 to cut off the communication of the IMSI.
[0079] The storage unit 18 stores the parameters of the probability model indicating the normal presence time estimated by the learning of the first learning unit 12. The storage unit 18 also stores the generator 131 included in the learned generation model constructed by the learning of the second learning unit 13.
[0080] [Hardware Configuration of Abnormality Management Device] Next, an example of the hardware configuration for realizing the abnormality management device 1 having the above-described functions will be described with reference to FIG. 7.
[0081] As shown in FIG. 7, the abnormality management device 1 can be realized by, for example, a computer including a processor 102, a main storage device 103, a communication interface 104, an auxiliary storage device 105, and an input / output I / O 106 connected via a bus 101, and a program for controlling these hardware resources. Further, the abnormality management device 1 includes a display device 107.
[0082] The processor 102 is realized by a CPU, a GPU, an FPGA, an ASIC, or the like.
[0083] In the main storage device 103, programs for the processor 102 to perform various controls and operations are stored in advance. The functions of the abnormality management device 1 such as the collection unit 10, the quantization unit 11, the first learning unit 12, the second learning unit 13, the acquisition unit 15, the determination unit 16, and the communication management unit 17 shown in FIG. 1 are realized by the processor 102 and the main storage device 103.
[0084] The communication interface 104 is an interface circuit for network-connecting the abnormality management device 1 and various external electronic devices.
[0085] The auxiliary storage device 105 is composed of a readable and writable storage medium and a driving device for reading and writing various kinds of information such as programs and data to and from the storage medium. As the storage medium, a semiconductor memory such as a hard disk or a flash memory can be used in the auxiliary storage device 105.
[0086] The auxiliary storage device 105 has a program storage area for storing an abnormality management program. Further, the auxiliary storage device 105 has a program storage area for storing a first learning program for estimating parameters related to a normal residence time using a probability model of a multinomial distribution executed by the abnormality management device 1. Further, the auxiliary storage device 105 has a program storage area for storing a second learning program for learning the discriminator 132 of the generation model executed by the abnormality management device 1. The abnormality residence time database 14 and the storage unit 18 described in FIG. 1 are realized by the auxiliary storage device 105. Furthermore, for example, it may have a backup area for backing up the above-described data, programs, and the like.
[0087] The input / output I / O 106 is an input / output device that inputs signals from external devices and outputs signals to external devices.
[0088] The display device 107 is composed of an organic EL display, a liquid crystal display, or the like. The display device 107 can display on the screen information of the communication terminal 2 that performs abnormal communication.
[0089] [Operation of the Abnormality Management Device] Next, the operation of the abnormality management device 1 having the above-described configuration will be described with reference to the sequence diagram of FIG. 8 and the flowcharts of FIGS. 9 and 10.
[0090] As shown in Fig. 8, first, the UDR42 stores, in the subscriber profile table 420, information on the communication areas of the base stations 3 of the destinations of the plurality of communication terminals 2 and the residence time in each communication area (step S1). The UDR42 updates the residence information in the table 420 based on the location registration request signal transmitted by each communication terminal 2.
[0091] Next, the collection unit 10 of the abnormality management device 1 collects the history of the residence time for each base station 3 in units of IMSI that includes a normal residence time of a certain length or more (step S2). The collection unit 10 can collect, for example, the history data of the residence time that includes 99% of the normal residence time. The normal residence time is the residence time in the communication area of each base station 3 generated by mobile communication by legitimate users.
[0092] Next, the quantization unit 11 quantizes the normal residence time in the communication area of the base station 3 of the destination of each communication terminal 2 collected in step S2 and converts it into an integer-valued normal residence time series (step S3). Next, the first learning unit 12 performs the first learning process (step S4). Fig. 9 is a flowchart for explaining the first learning process of step S4 in more detail. As shown in step S30 of Fig. 9, the first learning unit 12 models the normal residence time series obtained by the conversion in step S3 with a multinomial distribution (step S30). The first learning model sets the probability model of the above formula (5).
[0093] Next, the first learning unit 12 sets the binary classification parameters θ 1 , θ 0 for the normal residence time and the abnormal residence time (step S31). Subsequently, the first learning unit 12 defines the log-likelihood according to the above formula (7) (step S32). In step S32, the first learning unit 12 converts the objective function for optimization from the product form (formula (5)) to the sum form. Next, the first learning unit 12 uses the Lagrange multiplier method of the above formula (9) to estimate the parameter θ 1 relating to the normal residence time that maximizes the log-likelihood (formula (7)) under the constraint (formula (8)) (step S33). The estimated parameter θ 1is stored in the storage unit 18, and the process proceeds to step S5 in FIG. 8.
[0094] Subsequently, with the generator parameters of the generator 131 that generates pseudo-normal data that is sufficiently deviated from the distribution of the true normal data fixed using each observed value of the normal occupancy time series as the true normal data, the second learning unit 13, while keeping the generator parameters of the generator 131 fixed, based on the normal value parameter θ 1 estimated by the first learning unit 12 in step S4, updates only the discriminator parameters of the discriminator 132 that discriminates between the true normal data and the pseudo-normal data in the direction of maximizing the discrimination accuracy (second learning process) (step S5).
[0095] FIG. 10 is a flowchart for explaining the second learning process in step S5. First, the second learning unit 13 sets the normal value and abnormal value parameters θ 1 , θ 0 of the probability model of the multinomial distribution estimated in the first learning process in step S4 in the objective function (Equation (15)) of the generation model (step S50). More specifically, the second learning unit 13 substitutes the parameter θ i ^1 of the normal occupancy time series for each base station 3 in the probability model estimated in step S4 into the objective function when the generator 131 in the above equation (15) is fixed, and for the parameter θ i ^0 of the abnormal occupancy time series at each base station 3, adopts a rule of thumb or a preset value and substitutes it into the above equation (15). Further, for the ratio of the expected values, E ρ(x|y=1) : E ρ(x|y=0) , since the number of normal data is overwhelmingly large, for example, a preset value of 0.99:0.01 is adopted in the above equation (15).
[0096] Next, the second learning unit 13 acquires the normal occupancy time series collected in step S2 and quantized and converted in step S3 as the true normal data (step S51). Next, the second learning unit 13 inputs the true normal data as training data 134 to the discriminator 132, and the parameters w D , θ DLearn and update it (step S52). In step S52, the second learning unit 13 can cause the discriminator 132 to learn true normal data using, for example, the error backpropagation method. By step S51, the discriminator 132 that can identify true normal data as true normal data is pre-trained.
[0097] Next, the second learning unit 13 generates Gaussian noise and gives a random vector of the generated Gaussian noise to the generator 131 as an input (step S53). Subsequently, the generator 131 performs a sum-of-products operation of the input z and the weight parameters w G , θ G and threshold processing by an activation function to generate pseudo-normal data G(z) (step S54).
[0098] Next, the second learning unit 13 performs learning of the discriminator 132. The learning of the discriminator 132 is performed with the parameters w D , θ D of the generator 131 fixed. First, the second learning unit 13 gives true normal data to the discriminator 132 as training data 134. Then, the second learning unit 13 updates the parameters w D , θ D so that the objective function E in the above formula (15) is maximized by the error backpropagation method or the like (step S55). Note that the label of the training data 134 is set to 1 (true normal data).
[0099] Next, the second learning unit 13 gives the pseudo-normal data generated by the generator 131 in step S54 to the discriminator 132 as an input, and updates the parameters w D , θ D so that the objective function E in the above formula (15) is maximized by the error backpropagation method or the like (step S56).
[0100] The learning of the discriminator 132 in steps S55 and S56 corresponds to the dashed arrow shown in the block diagram of the second learning unit 13 shown in FIG. 4, in which the discriminator error is calculated in the block 135 of the objective function E based on the output 133 from the discriminator 132, and then backpropagated to the discriminator 132.
[0101] Thereafter, until the value of the objective function E converges (step S57: NO), the learning of the discriminator 132 from step S54 to step S56 is repeatedly performed. On the other hand, when the value of the objective function E converges to the optimal solution of the above formula (16) (step S57: YES), using the remaining true normal data in order, until the learning of the generator 131 and the discriminator 132 is performed (step S58: NO), the processing from step S52 to step S57 is repeated.
[0102] Thereafter, when the learning of the discriminator 132 is performed using all the true normal data (step S58: YES), the second learning unit 13 stores the generator 131 in the storage unit 18 (step S59). Also, the second learning unit 13 performs the processing from step S50 to step S59 for each generation model corresponding to the M observed values (base station 3) to learn the discriminator 132 respectively. Thereafter, the process proceeds to step S6 in FIG. 8.
[0103] Next, the anomaly presence time database 14 stores the pseudo-normal data generated by the generator 131 after the discriminator 132 is updated by the learning of the second learning unit 13 (step S6). In step S6, the pseudo-normal data respectively generated by the generators 131 corresponding to each base station 3 are registered in the anomaly presence time database 14. For example, assume that 1000 destination base stations 3 (communication areas) (M = 1000) are set. In this case, in the second learning process of step S5, if learning is performed using, for example, 10,000 pieces of training data for each of the 1000 generation models corresponding to 1000 base stations 3, the generator 131 of each generation model generates 10,000 pieces of pseudo-normal data. Therefore, 10,000 pieces of pseudo-normal data are registered in the anomaly presence time database 14 for each of the 1000 base stations 3.
[0104] Subsequently, the UDR 42 detects the simultaneous use of the same IMSI among the plurality of IMSIs stored in the subscriber profile (step S7). Specifically, in step S7, the UDR 42 detects an IMSI in which there is an inconsistency in the presence information, such as when the same IMSI is being used in a plurality of communication areas simultaneously or when voice communication and data communication are occurring simultaneously from the same IMI. Next, the UDR 42 notifies the IMSI detected in step S7 as the IMSI to be managed, and notifies the anomaly management apparatus 1 of the presence time in the communication area of each destination base station 3 of the IMSI (step S8).
[0105] Next, the acquisition unit 15 of the anomaly management apparatus 1 acquires the presence time in the communication area of each destination base station 3 of the IMSI to be managed notified by the UDR 42 (step S9). Thereafter, the quantization unit 11 quantizes the presence time in the communication area of each destination base station 3 by the IMSI to be managed acquired in step S9 and converts it into a presence time series (step S10).
[0106] Next, when the presence time series of the IMSI to be managed obtained in step S10 matches the pseudo-normal data stored in the abnormal presence time database 14, the determination unit 16 determines that abnormal communication has occurred by the IMSI to be managed (step S11). In step S11, in addition to the case where the history of the presence time of the IMSI to be managed completely matches the pseudo-normal data, when they match with a certain tolerance range, it can be determined that abnormal communication has occurred by the IMSI to be managed.
[0107] Specifically, when the value obtained by summing the squares of the differences between the level value of the presence time series of the IMSI to be managed and the level value of the pseudo-normal data is within the threshold according to the above formula (18), the determination unit 16 can determine that abnormal communication has occurred by the IMSI to be managed.
[0108] In addition, without even matching the presence time series of the communication areas of all the destination base stations 3, the pseudo-normal data of the communication areas of each base station 3 is sequentially collated. When the presence time series of the IMSI to be managed partially matches the series of pseudo-normal data, it can be determined that abnormal communication, that is, illegal communication by a cloned SIM, has occurred by the IMSI to be managed.
[0109] Next, the communication management unit 17 designates the IMSI to be managed that performs abnormal communication to the core network 4 and instructs to cut off the communication (step S12). After that, the UDR 42 performs flag setting to reject access to the target IMSI (step S13). Furthermore, the AMF 40 and the UDM 41 reject and cut off communication by the target IMSI.
[0110] As described above, according to the anomaly management device 1 according to the present embodiment, multinomial naive Bayes is adopted as a probability model of a series of integer values obtained by quantizing normal presence times, and probability parameters related to the normal presence time series are estimated. Further, by setting the probability parameters of the estimated normal presence time series in the objective function of the generative model and performing learning to update only the discriminator 132 while fixing the generator 131, pseudo-normal data that is sufficiently deviated from the distribution of true normal data indicating the normal presence time series is output from the generator 131. Since the collected pseudo-normal data is registered as a database for anomaly determination, abnormal communication can be managed more reliably.
[0111] Moreover, according to the anomaly management device 1 according to the present embodiment, in order to collect data on the presence time for each IMSI and determine abnormal data, after identifying an IMSI that may be a cloned SIM, communication is blocked. Therefore, countermeasures against cloned SIMs can be taken more effectively. In particular, even when there is use within a short period of time by the same IMSI at a relatively short distance, an IMSI performing unauthorized communication can be identified.
[0112] Furthermore, according to the anomaly management device 1 according to the present embodiment, even when there is little historical data on the presence time related to unauthorized communication such as a cloned SIM, an abnormal presence time database can be constructed based on the historical data on the normal presence time related to communication by legitimate users that can be obtained in large quantities.
[0113] In the described embodiment, the anomaly management system has been described as a system compliant with the 5G standard, but the communication standard may be 3G, 4G / LTE, 6G, or the like.
[0114] Also, in the described embodiment, the second learning unit 13 has been described for the case where the generative model has a GAN configuration. However, the generative model can be implemented using other configurations based on GAN, such as VAE (Variational Autoencoder), Energy-Based Models (EBMs), etc.
[0115] The embodiments of the abnormality management device and the abnormality management method of the present invention have been described above. However, the present invention is not limited to the described embodiments, and various modifications conceivable by those skilled in the art can be made within the scope of the invention described in the claims.
Description of Reference Numerals
[0116] 1... Abnormality management device, 2... Communication terminal, 3... Base station, 4... Core network, 10... Collection unit, 11... Quantization unit, 12... First learning unit, 13... Second learning unit, 14... Abnormality in-circle time database, 15... Acquisition unit, 16... Judgment unit, 17... Communication management unit, 18... Storage unit, 40... AMF, 41... UDM, 42... UDR, 101... Bus, 102... Processor, 103... Main memory device, 42a, 104... Communication interface, 105... Auxiliary storage device, 106... Input / output I / O, 107... Display device, 131... Generator, 132... Identifier, NW... Network.
Claims
1. A quantization unit configured to quantize the normal residence time of each base station's communication area where each of a plurality of communication terminals is located as it moves, and convert it into an integer-valued normal residence time series; A first learning unit configured to treat each observation value of the normal residence time series as discrete values independent of each other, and estimate probability parameters of a probability model representing the normal residence time after quantization based on the occurrence frequency of each observation value; With the observation values of the normal residence time series as true normal data, while fixing the generator parameters of a generator that generates pseudo-normal data that deviates sufficiently from the distribution of the true normal data, only the discriminator parameters of a discriminator that discriminates between the true normal data and the pseudo-normal data are updated in a direction to maximize the discrimination accuracy based on the probability parameters of the normal residence time estimated by the first learning unit; A storage unit configured to store, as information indicating abnormal residence time in the communication area of each base station by a communication terminal performing abnormal communication, the pseudo-normal data output by the generator after the discriminator parameters of the discriminator are updated by the second learning unit; An abnormality management device comprising the above.
2. In the abnormality management device according to Claim 1, further comprising an acquisition unit configured to acquire the residence time of a communication terminal to be managed as it moves into the communication area of each base station, wherein the quantization unit quantizes the acquired residence time of the communication terminal to be managed and converts it into an integer-valued residence time series, and further comprising a determination unit configured to determine that abnormal communication has occurred by the communication terminal to be managed when the residence time series matches the pseudo-normal data stored in the storage unit. An abnormality management device characterized by the above.
3. In the abnormality management device according to Claim 2, further comprising a communication management unit configured to issue an instruction to block the communication of the communication terminal to be managed when it is determined by the determination unit that abnormal communication has occurred. An abnormality management device characterized by the above.
4. In the abnormality management device according to Claim 2, the communication terminal to be managed has a plurality of identical subscriber identifiers for which it has been detected that it is located in the communication areas of a plurality of different base stations in the same time period. An abnormality management device characterized by the above.
5. A quantization step of quantizing the normal residence time of each of a plurality of communication terminals in the communication area of each base station as it moves, and converting it into an integer-valued normal residence time series; A first learning step of treating each observation value of the normal residence time series as discrete values independent of each other, and estimating probability parameters of a probability model representing the normal residence time after quantization based on the occurrence frequency of each observation value; With each observation value of the normal residence time series as true normal data, while keeping the generator parameters of a generator that generates pseudo-normal data that sufficiently deviates from the distribution of the true normal data fixed, only the discriminator parameters of a discriminator that discriminates between the true normal data and the pseudo-normal data are updated in a direction to maximize the discrimination accuracy based on the probability parameters of the normal residence time estimated in the first learning step; A storage step of storing, in a storage unit, the pseudo-normal data output by the generator as information indicating abnormal residence time of each base station in the communication area by a communication terminal performing abnormal communication after the update of the discriminator parameters of the discriminator in the second learning step; An anomaly management method comprising the above.
6. In the anomaly management method according to claim 5, further comprising an acquisition step of acquiring the residence time of a communication terminal to be managed in the communication area of each base station as it moves, the quantization step quantizes the residence time of the communication terminal to be managed acquired in the acquisition step and converts it into an integer-valued residence time series, further comprising a determination step of determining that abnormal communication has occurred by the communication terminal to be managed when the residence time series matches the pseudo-normal data stored in the storage unit; An anomaly management method characterized by the above.
7. In the anomaly management method according to claim 6, further comprising a communication management step of issuing an instruction to block the communication of the communication terminal to be managed when it is determined in the determination step that abnormal communication has occurred; An anomaly management method characterized by the above.
8. In the anomaly management method according to claim 6, the communication terminal to be managed has a plurality of identical subscriber identifiers for which it has been detected that it is in the communication areas of a plurality of different base stations in the same time period; An anomaly management method characterized by the above.
Citation Information
Patent Citations
Communication monitoring device and communication monitoring method
JP7541207B1
COMMUNICATION MANAGEMENT DEVICE, COMMUNICATION MANAGEMENT METHOD, AND COMMUNICATION MANAGEMENT SYSTEM
JP7639233B1
Machine learning model feature sharing for subscriber identity module hijack prevention
US20240171558A1
System and method for identifying collocated cellular devices from known fraudulent devices
US20240292223A1
JPP7541207B
Cited By
Abnormal communication detection device and abnormal communication detection method
JP7752280B1
Abnormality management device and abnormality management method
JP7762830B1
Anomaly detection device and anomaly detection method
JP7769833B1
Abnormality management device and abnormality management method
JP7820606B1