Primary User Emulation / Signal Jamming Attack Detection Method

The method addresses inefficiencies in existing attack detection by using sparse coding and machine learning to differentiate between legitimate users and attackers in cognitive radio systems, enhancing security and reducing complexity.

JP7808850B2Active Publication Date: 2026-01-30イスタンブール メディポル ユニベルシテシ
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2022537431
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2019-12-25
Filing Date
2020-12-02
Publication Date
2026-01-30
Estimated Expiration
2040-12-02

AI Technical Summary

Technical Problem

Current methods for detecting primary user emulation and signal jamming attacks in cognitive radio systems are inefficient, requiring significant hardware and software overhead, and lack effective machine learning-based classification procedures.

Method used

A method utilizing sparse coding convergence patterns to distinguish between legitimate users, signal jammers, and emulators by training a dictionary with sparse coding residual energy profiles and employing a machine learning-based classification algorithm.

Benefits of technology

Effectively detects primary user emulation and signal jamming attacks with reduced complexity and false alarm rates, enabling secure spectrum utilization in cognitive radio systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007808850000001
    Figure 0007808850000001
  • Figure 0007808850000002
    Figure 0007808850000002
  • Figure 0007808850000003
    Figure 0007808850000003
Patent Text Reader

Abstract

The method of the present invention relates to utilizing the convergence patterns of sparse coding for detecting primary user emulation / signal jamming attacks in cognitive radio settings. The method basically comprises a training phase and a testing phase. The method can distinguish between the following hypotheses: H0, which indicates that there is no primary user, only noise; H1, which indicates that there is a legitimate primary user with the right to use the spectrum and that secondary users should not use the spectrum; and H2, which indicates that there is a primary user emulator / signal jammer in the environment.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to the detection of primary user emulation / signal jamming attacks, and more particularly to utilizing sparse coding convergence patterns in the detection of primary user emulation / signal jamming attacks. [Background technology]

[0002] Due to the rapid development of wireless communication technologies and services, wireless spectrum scarcity has become a serious problem (1). Cognitive radio (CR) is one of the most promising solutions for bridging the gap between future wireless service requirements and spectrum scarcity. CR enables spectrum sharing between primary and secondary users (2). Although CR is a promising solution for ameliorating the spectrum scarcity problem, it is inherently vulnerable to both traditional and new security threats (3). This stems from the nature of wireless systems and the unique characteristics of CR. Traditional security threats include eavesdropping, fraud, and signal jamming (4). Among new security threats, spectrum sensing data fraud (SSDF) and primary user emulation attacks (PUEA) (5) are notable examples. In an SSDF attack, a malicious CR generates false data to degrade the performance of cooperative spectrum sensing techniques. On the other hand, a PUEA attempts to mimic transmission characteristics to deceive secondary users and prevent them from using existing spectrum space. (5) In each case, developing new and effective solutions to detect the attacks is a key requirement for practical and secure CR systems.

[0003] Various techniques have been proposed in the literature for detecting signal jamming and primary user emulation attacks (PUEA). It was suggested in [6] that signals can be relied upon for their power level source by means of energy detection. While energy detection-based techniques are simple, they have a high false alarm rate. The inherent physical characteristics of wireless channels and communication devices are also effective for PUEA detection [7] (8) (9). However, applying these techniques requires additional software and hardware overhead. Location estimation-based detection is also widespread for PUEA detection. The basic idea is to use the received signal to determine the location of the signal source by comparing it with a database of previously known locations of legitimate primary users (PUs). However, these techniques can only be used in the case of static primary user scenarios

[10] (11). At the same time, compressed sensing (CS) (12), which is used in various application areas, is also used in detecting primary user emulation attacks (PUEAs). Research in this field includes PUEA detection based on CS and received signal power (13). This approach requires many sensors throughout the network and is quite complex. Another example considers taking advantage of the belief propagation algorithm and CS for PUEA detection (14). Again, a central node is required for this application.

[0004] Prior art patent document CN105743594(A) proposes a method based on user collaboration for detecting primary user emulation attacks (PUEA) in CR systems. The method is based on the signal energy systems of users and attackers. However, the method does not provide any recommendations related to sparse coding. In addition, the document does not describe a machine learning-based classification procedure.

[0005] Consequently, due to the above-described shortcomings and inadequacies of current solutions related to the subject matter, advances in the related art are needed. [Prior art documents] [Patent documents]

[0006] [Patent Document 1] CN105743594(A) Summary of the Invention

[0007] Goal of the Invention The present invention was inspired by the current situation and aims to overcome the above-mentioned disadvantages.

[0008] The main goal of this invention is to detect primary user emulator / signal jamming attacks.

[0009] Another goal of this invention is to design a dictionary corresponding to the sparse coding of the received distorted signal and connected to the real channel corresponding to the legitimate primary user, and to propose an algorithm for the detection of signal jamming and primary user emulation attacks for cognitive radio.

[0010] Another goal of the present invention is to exploit the convergence pattern, characterized by the sparse coding residual signal energy convergence rate with respect to these dictionaries, to distinguish between spectrum space, legitimate users, or signal jammers / emulators.

[0011] Another goal of the present invention is to distinguish between these assumptions during attack detection: The assumption (H0) that there are no primary users, only noise. Assumption (H1) that states that there are legitimate primary users who exist with the right to use the spectrum and that secondary users should not use the spectrum; and Hypothesis (H2) states that there is a primary user emulator / signal jammer in the environment.

[0012] To achieve the above-described objectives, the primary user emulator / signal jamming attack detection method of the present invention basically includes a training phase and a testing phase.

[0013] The training phase mentioned earlier involves the following process steps: A process step of combining the channels corresponding to the regular primary users and the random data sets for each of the three signals mentioned to calculate a primary user dependent dictionary. To obtain classification features, each signal of the three signals mentioned previously is filtered through this dictionary (D PU ) are subjected to a sparse coding (SC) process. Their characteristic is the sparse coding residual energy profile. This profile is the energy profile of the dictionary (D PU ) can be obtained by quantifying the convergence pattern of sparse coding with respect to the residual norm (||r||2). This pattern can be quantified by calculating the absolute gradient (|G|) of the residual norm (||r||2). A sparse representation can be obtained using a greedy sparse coding algorithm, for example, the orthogonal matching pursuit algorithm. The process step of obtaining a classification model with class tags from the previously mentioned training feature vectors as a result of a machine learning (ML) based classification procedure.

[0014] The testing stage includes the following process steps: A process step of obtaining a dictionary as a result of dictionary calculation from sampled data for channels corresponding to legitimate users. a process step of performing sparse coding on said dictionary for each test signal to provide feature extraction; The process step is to feed the extracted feature vector to the classifier along with the classifier model. A process step in which the classifier makes a decision about the hypothesis corresponding to the current test signal.

[0015] All of the structure and characteristic features and advantages of the present invention will be more clearly understood from the figures given below and the detailed description written by making reference to these figures, and therefore an appreciation should be made in consideration of these figures and the detailed description. [Brief explanation of the drawings]

[0016] [Figure 1] A schematic diagram of the primary user emulator / signal jammer in the environment. [Figure 2] 1 is a schematic diagram of the training phase of the primary user emulator / signal jammer detection method of the present invention. [Figure 3] 1 is a schematic diagram of the testing phase of the primary user emulator / signal jammer detection method of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0017] (Explanation of reference symbols for parts of the present invention) PU: Primary User SU: Secondary user PUE / J: Primary user emulator / signal jammer SD: Sampled dictionary h i PU :Channels corresponding to legitimate primary users h PU :Channels corresponding to regular users DC: Dictionary calculation D PU :Dictionary connected to the regular primary user y0 i : A signal corresponding to the assumption that there is no primary user, but only noise. y1 i : a signal corresponding to an assumption that there is a legitimate primary user present with the right to use the spectrum and that secondary users should not use the spectrum. y2 i : Signals corresponding to assumptions indicating the presence of a primary user emulator / signal jammer in the environment f0 i : Feature data corresponding to the assumption that there is no primary user, only noise f1 i : characteristic data corresponding to the assumption that there is a legitimate primary user with the right to use the spectrum and that secondary users should not use the spectrum. f2 i : Feature data corresponding to the assumption that a primary user emulator / signal jammer is present in the environment y: test signal f: feature data SC: Sparse coding FE: Feature extraction C:Classification CM: Classified model D:Decision

[0018] In this detailed description, the method and system for providing phase and frequency synchronization of the present invention will be explained to provide a better understanding of the subject matter.

[0019] The system model used by the method of the present invention is shown in Figure 1. This model includes a legitimate Primary User (PU) node, a Secondary User (SU) node, and a rogue node (Primary User Emulator / Signal Jammer (PUE / J)). The Secondary User (SU) node wishes to benefit from the spectrum in the presence of the rogue node, which can launch a signal jamming attack or a Primary User Emulator Attack (PUEA). The legitimate Primary User (PU) node and the Primary User Emulator (PUE) transmit structured signals, while the signal jammer transmits random signals. The signal transmitted from any node is expressed as y = h x +n format. x represents the general channel vector (or matrix) between any transmitter-receiver pair, and n represents additive white Gaussian noise. Due to the concept of spatial uncorrelation, the channel h between different transmitter-receiver pairs x are different (1). A typical channel between a transmitter node and a receiver node is h x Based on the channel model presented in (2).

[0020] The method basically includes two stages: a training stage and a testing stage.

[0021] 2 shows the training stage involved in the method of the present invention. During the training stage, y0 corresponding to the H0 hypothesis is i , y1 corresponding to the H1 assumption i , y2 corresponding to the H2 assumption i A test signal of 100 kJ / s is used. Thereby, the training phase includes the following process steps, respectively: The channel (h) corresponding to the regular primary user (PU) i PU), and a dictionary (D) that combines randomly selected data sets (SD) for each of the three signals and is primary user (PU) dependent. PU ) process steps. Each of the three signals is stored in a dictionary (D PU ) is subjected to a sparse coding (SC) process. Sparse coding can be achieved using any sparse recovery algorithm, such as the orthogonal matching pursuit algorithm. While performing sparse coding, the energy (norm) of the representation residual signal (||r||2) is calculated for each iteration. The decay of the residual energy is then quantified in terms of its absolute gradient (|G|) to yield a so-called residual energy profile. This profile is taken as the classification feature data point (f) corresponding to the received signal of interest. A process step of obtaining a classification model (CM) with class tags from said training feature vectors as a result of a machine learning (ML) based classification (C) procedure.

[0022] In a preferred embodiment of the method of the present invention, the feature data f0 i , f1 i , f2 i However, these feature data are added to the corresponding training feature vectors as 0, 1, and 2, respectively, and thus the attack is detected.

[0023] In another preferred embodiment of the method of the present invention, a dictionary (D PU ) calculation process is D PU =h PU This is accomplished by using the formula for *SD, where * represents a convolution.

[0024] Figure 3 includes a testing step of the method of the present invention. ·Channels corresponding to legitimate users (h PU ) for the sampled data (SD) dictionary calculation (DC) results in a dictionary (D PU) to get the process steps, For each test signal (y), the dictionary (D PU ) and perform sparse coding (SC) using Feature Extraction (FE) process steps. A process step of feeding the extracted feature data points (f) to a classifier (C) along with a classifier model (CM); A process step in which the classifier (C) makes a decision (D) about a hypothesis corresponding to the current feature data (f) in question. Includes.

Claims

1. 1. A method for detecting a primary user emulator / signal jammer (PUE / J), comprising: a system including a classifier (C) performing a training phase and a testing phase; The training stage comprises: The assumption (H 0 ) corresponding to the signal (y 0 i ), The assumption (H) indicates that there is a legitimate primary user (PU) with the right to use the spectrum, and that secondary users (SU) should not use the spectrum. 1 ) corresponding to the signal (y 1 i ), The assumption (H) indicates that a primary user emulator / signal jammer (PUE / J) exists in the environment. 2 ) corresponding to the signal (y 2 i ) and Using The system selects a channel (h) corresponding to the regular primary user (PU). i PU ), and a dictionary (D) that combines randomly selected data sets (SD) for each of the three signals and is primary user (PU) dependent. PU ) and The system converts each of the three signals into a dictionary (D PU ) to a sparse coding (SC) process to obtain the three hypotheses (H 0 , H 1 , H 2 ) corresponding to each of the feature data (f 0 i , f 1 i , f 2 i ), where the residual energy profile (||r|| 2 ), and the sparse coding algorithm that calculates the corresponding training feature vectors to calculate the absolute gradient (|G|) and quantify the convergence pattern of the sparse coding. the system obtaining a classification model (CM) with class tags from the training feature vectors as a result of a machine learning (ML)-based classification (C) procedure; Including, The testing stage comprises: The system receives a channel (h) corresponding to a legitimate user. PU ) the dictionary calculation (DC) of the randomly selected data set (SD) results in a dictionary (D PU ) and The system selects the dictionary (D PU ) to perform sparse coding (SC) and feature extraction (FE); the system providing the extracted feature vector together with the classification model (CM) to a classifier (C); the system causing the classifier (C) to make a decision (D) about the hypothesis corresponding to the current feature data (f) of interest; A method comprising:

2. The three assumptions (H 0 , H 1 , H 2 ) are feature data corresponding to each of 0 i , f 1 i , and f 2 i 2. The method for detecting a Primary User Emulator / Signal Jammer (PUE / J) attack of claim 1, wherein:

3. The dictionary (D PU ) is calculated by PU =h PU 2. The method for detection of a Primary User Emulator / Signal Jammer (PUE / J) attack according to claim 1, characterized in that it is performed by using the formula: *SD.

4. The method for detection of Primary User Emulator / Signal Jammer (PUE / J) attacks according to claim 1 , wherein the sparse coding algorithm is an Orthogonal Matching Pursuit algorithm.

Citation Information

Patent Citations

  • PUEA detection method based on inter-user cooperation in cognitive radio system

    CN105743594A

  • Learning data generating apparatus, intrusion detection system, and its program

    JP2004312083A

  • Scheduling a network attack to train a machine learning model

    US20150195145A1