Signaling attack detection method, electronic device, storage medium, and product
By statistically analyzing and classifying signaling data at both temporal and spatial granularities, signaling indicators are generated, solving the problem of low efficiency in signaling DDoS attack detection in existing technologies and achieving the effect of quickly determining the attack range and distribution patterns.
Patent Information
- Application Number
- PCT/CN2025/092578
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-07-01
- Filing Date
- 2025-04-30
- Publication Date
- 2026-01-08
AI Technical Summary
In existing technologies, signaling DDoS attack detection involves a large amount of computation and is not sensitive to abnormal fluctuations in other areas when identifying anomalies at the network element or user level, resulting in low detection efficiency.
By statistically analyzing signaling data at both temporal and spatial granular levels, signaling indicators containing temporal and spatial information are generated. Anomaly detection is performed to classify and generate alarms to determine the attack range and distribution patterns.
It reduces computational load and improves the efficiency of signaling attack detection, enabling users to quickly determine the scope, distribution pattern, and source of attacks, thus reducing the need for additional analysis.
Smart Images

Figure CN2025092578_08012026_PF_FP_ABST
Abstract
Description
Signaling attack detection method, electronic device, storage medium and product
[0001] Cross-reference to Related Applications
[0002] This application is based on the Chinese patent application No. 202410885399.X, filed on July 1, 2024, and claims priority to the Chinese patent application No. 202410885399.X, the entire contents of which are incorporated herein by reference. TECHNICAL FIELD
[0003] Embodiments of the present application relate to the technical field of network security, and in particular to a signaling attack detection method, an electronic device, a storage medium and a product. BACKGROUND
[0004] Signaling DDoS (Distributed Denial of Service) is a kind of distributed denial of service attack, which is mainly formed by intentional and malicious attack behavior. Attackers will send a large number of useless or malicious signaling requests, thereby consuming network resources and causing legitimate users to be unable to normally use network services.
[0005] In related technologies, the detection of signaling DDoS is usually abnormal identification of user terminals at network element or user granularity, which has problems such as large amount of detection calculation and insensitivity to abnormal fluctuations in other spaces. How to improve the efficiency of attack detection is a problem that needs to be discussed and solved at present. SUMMARY
[0006] Embodiments of the present application provide a signaling attack detection method, an electronic device, a storage medium and a product.
[0007] According to a first aspect of the present application, an embodiment provides a signaling attack detection method, the method comprising: acquiring signaling data; according to a pre-set time granularity and a space granularity, statistically processing the signaling data to obtain a plurality of signaling indicators, wherein each signaling indicator comprises time information and space information; classifying the plurality of signaling indicators to obtain at least one indicator type; performing abnormal detection on the plurality of signaling indicators according to the indicator type; when an abnormal indicator is detected, generating first abnormal information according to the space information of the abnormal indicator; obtaining second abnormal information according to the distribution rule of the abnormal indicator; detecting abnormal terminals according to the space information of the abnormal indicator to obtain third abnormal information; and generating an alarm according to the first abnormal information, the second abnormal information and the third abnormal information.
[0008] According to a second aspect of the present application, another embodiment provides an electronic device, comprising: at least one processor; at least one memory configured to store at least one program; and a signaling attack detection method as described in the first aspect of the present application, when the at least one program is executed by the at least one processor.
[0009] According to a third aspect of the present application, still another embodiment provides a computer readable storage medium storing computer executable instructions configured to perform a signaling attack detection method as described in the first aspect of the present application.
[0010] According to a fourth aspect of the present application, yet another embodiment provides a computer program product comprising a computer program or computer instructions, wherein the computer program or the computer instructions are stored in a computer readable storage medium, and a processor of a computer device reads the computer program or the computer instructions from the computer readable storage medium, and the processor executes the computer program or the computer instructions, so that the computer device performs a signaling attack detection method as described in the first aspect of the present application. BRIEF DESCRIPTION OF DRAWINGS
[0011] FIG. 1 is a schematic diagram of a network architecture according to an embodiment of the present application;
[0012] FIG. 2 is a flowchart of a signaling attack detection method according to an embodiment of the present application;
[0013] FIG. 3 is a schematic diagram of a signaling DDoS detection scheme according to an embodiment of the present application;
[0014] FIG. 4 is a schematic diagram of training a periodic model according to an example of the present application;
[0015] FIG. 5 is a flowchart of abnormal terminal detection according to an example of the present application;
[0016] FIG. 6 is a flowchart of signaling attack detection according to an example of the present application;
[0017] FIG. 7 is a schematic diagram of a signaling attack detection system according to an embodiment of the present application;
[0018] FIG. 8 is a structural block diagram of a part of a terminal of a signaling attack detection method according to an embodiment of the present application;
[0019] FIG. 9 is a structural block diagram of a part of a server of a signaling attack detection method according to an embodiment of the present application. DETAILED DESCRIPTION
[0020] In order to make the purposes, technical solutions and advantages of the present application clearer, further detailed description will be given to the present application in combination with the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and should not be used to limit the present application.
[0021] It should be noted that although the functional modules are divided in the device schematic diagram, and the logical sequence is shown in the flowchart, in some cases, the steps shown or described can be performed in a manner different from the module division in the device or the sequence in the flowchart. The terms "first", "second", etc. in the specification and claims and the above drawings are used to distinguish similar objects, and do not necessarily describe a specific order or sequence.
[0022] In the description of the embodiments of the present application, the words such as arrangement, installation, connection, etc. should be understood broadly, and the person skilled in the art can determine the specific meaning of the above words in the embodiments of the present application in combination with the specific content of the technical solutions.
[0023] In the embodiments of the present application, the words "further", "exemplarily" or "optionally" are used to represent as an example, illustration or description, and should not be interpreted as more preferred or more advantageous than other embodiments or design schemes. The use of the words "further", "exemplarily" or "optionally" aims to present the related concept in a specific way.
[0024] The technical solutions of the embodiments of the present application can be applied to various communication systems, for example: Wideband Code Division Multiple Access (WCDMA) mobile communication system, Evolved Universal Terrestrial Radio Access Network (E UTRAN) system, Next Generation Radio Access Network (NG RAN) system, Long Term Evolution (LTE) system, Worldwide Interoperability For Microwave Access (WiMAX) communication system, 5th Generation (5G) system, such as New Radio Access Technology (NR), and future communication systems, such as 6G system, etc.
[0025] The technical solutions of the embodiments of the present application can be applied to various communication technologies, such as microwave communication, light wave communication, millimeter wave communication, etc. The embodiments of the present application do not limit the specific technology and specific device form adopted.
[0026] In the related art, the signaling storm in the 5G network refers to that the signaling load exceeds the network capability, resulting in network congestion or collapse and unavailability, which can be inhibited or alleviated by taking certain measures on the network side. The reasons for causing the signaling storm are diverse, which may be due to holidays, specific areas, etc., or due to insufficient network design capability, faults, etc., or due to a signaling distributed denial of service (DDoS) attack, etc. Among them, the signaling DDoS is a kind of distributed denial of service attack, which is mainly formed by intentional and malicious attack behaviors, and the attacker will send a large number of useless or malicious signaling requests, thereby consuming network resources and causing legitimate users to be unable to normally use network services. The signaling DDoS attack may have the characteristics of repeatability, periodicity, slow speed, etc., and after malicious access, it is mixed with normal signaling data, has concealment, and is widely distributed, etc., and has great detection difficulty. At present, the communication industry related standards have proposed such security threats, so the identification and detection of such risks are urgent to be solved.
[0027] In the related art, the detection schemes of the signaling DDoS are: (1) an abnormality detection model of a type of network element is established by means of a hidden Markov model, which can detect the DDoS caused by a user equipment (UE). The model proposed by this method has a wide range of applications, and cannot solve the problem of different area and different UE difference identification; (2) a network detection device obtains a UE behavior sequence based on signaling data obtained from a network management, and selects a matched network element detection model to identify an abnormal UE behavior sequence. This method does not propose the identification of signaling storm or signaling DDoS fluctuation, and directly uses the abnormal behavior detection of UE, which will cause large calculation amount due to large number of users; (3) a network element that appears a signaling storm is detected through call information, and then a neural network model is used to detect which UE is abnormal and blocked based on the CHR log of the UE, wherein the CHR log refers to a log file used to record problems occurring in the call process of the user. The identification of the signaling storm in this method is at the network element granularity, and the outliers are detected by means of the isolation forest, which cannot clearly present which indicators appear the signaling DDoS and the abnormality degree, and does not analyze from other smaller spatial granularity, such as tracking area and base station, which may not be sensitive to the abnormal fluctuation of these spaces. In addition, there are some other methods, such as using information entropy to detect DDoS in the 5G multi-tenant scenario.
[0028] The above method is usually abnormal identification of user terminals in network element or user granularity for signaling DDoS detection, and has problems of large amount of detection calculation, insensitivity to abnormal fluctuations of other spaces, etc. How to improve the efficiency of attack detection is a problem to be discussed and solved.
[0029] Based on this, the embodiment of the application provides a signaling attack detection method, an electronic device, a storage medium and a product. The signaling data is counted in time granularity and space granularity to obtain signaling indicators, so that each signaling indicator includes time information and space information. Then, the multiple signaling indicators are classified to obtain at least one indicator type. Thus, based on the indicator type, abnormal detection is performed on signaling indicators of different types, so that the attack degree and the distribution in time of abnormal indicators can be quickly determined. Since the signaling indicators are also obtained based on space granularity, when the abnormal indicators are detected, the distribution of the attack in space can also be directly determined. According to the space information corresponding to the abnormal indicators, abnormal terminal detection is performed on the terminals in the abnormal occurrence space, so that the amount of calculation is reduced and the attack detection efficiency is improved. Finally, based on the abnormal information in time and space granularity and the abnormal terminals determined in the above detection process, an alarm is generated, so that the user can quickly determine the range of attack occurrence, the attack distribution rule, the attack source and other information according to the alarm, without the need for the user to additionally analyze the attack detection data, thereby improving the processing efficiency of attack detection.
[0030] The embodiments of the application will be further described below with reference to the accompanying drawings.
[0031] FIG. 1 is a schematic diagram of a network architecture provided by an embodiment of the application. As shown in FIG. 1, in the network, a core network 110, a signaling collection device 120 and a server 130 are included.
[0032] The function of the core network 110 is mainly to provide user connection, management of users and completion of service bearing, and to provide an interface to an external network as a bearing network.
[0033] The signaling collection device 120 is a computer system capable of collecting signaling data generated by the core network and capable of sending the collected signaling data to the server 130 or a user terminal. The signaling collection device 120 can be a network management device or an analysis device with signaling collection and analysis functions. The signaling collection device 120 is in communication connection with the core network 110 and the server 130 respectively for data exchange.
[0034] Server 130 refers to a computer system that carries a signaling attack detection system and is capable of analyzing and processing signaling data for signaling attack detection. Server 110 can be a single high-performance computer in a network platform, a cluster of multiple high-performance computers, a portion of a single high-performance computer (e.g., a virtual machine), or a combination of portions of multiple high-performance computers (e.g., virtual machines). Server 130 can also communicate with signaling device 120 and / or terminals via wired or wireless means to exchange data.
[0035] In this embodiment, a signaling attack detection system can also be implemented via a terminal (not shown in the figure) to analyze and process signaling data for signaling attack detection. The terminal can directly communicate with the signaling acquisition device 120 to obtain signaling data from the signaling acquisition device 120. The terminal can also communicate with the server 130 to obtain signaling data from the server 130. The terminal can take various forms, including desktop computers, laptops, PDAs (personal digital assistants), mobile phones, vehicle terminals, home theater terminals, and dedicated terminals. Furthermore, it can be a single device or a collection of multiple devices. For example, multiple devices can be connected via a local area network, sharing a single display device to work collaboratively, forming a single terminal.
[0036] In other embodiments, the signaling attack detection system can also be jointly carried by the server 130 and the terminal to analyze and process the signaling data for signaling attack detection.
[0037] The following example illustrates the application of the signaling attack detection method of this application in the network architecture shown in Figure 1:
[0038] Taking the network architecture in Figure 1 as an example, assuming that the signaling acquisition device 120 in Figure 1 is a network management system, the signaling attack detection method of this application is deployed in the server 130.
[0039] Server 130 obtains signaling data from core network 110 through network management. Server 130 performs statistical analysis on the obtained signaling data, using the cell as the spatial granularity and one hour as the time granularity, to obtain multiple signaling indicators. The signaling indicators contain both time and spatial information. For example, when a signaling indicator includes the number of times a signaling process is executed, then a signaling indicator contains information about the number of times the signaling process is executed in its corresponding cell within a certain hour.
[0040] Signaling indicators are classified based on their patterns in time, space, or other external factors. In this example, it is assumed that the classified indicator types include periodic, range, and trend types.
[0041] The three types of signaling indicators are respectively subjected to anomaly detection. When an abnormal signaling indicator is detected, the abnormal indicator is determined, and the cell where the anomaly occurs is determined through the spatial information corresponding to the abnormal indicator. The abnormal indicator and the cell where the anomaly occurs (i.e., the spatial information) are used to generate first abnormal information, and an abnormal event including the first abnormal information is generated.
[0042] The distribution of each abnormal indicator over time is analyzed to determine whether the abnormal indicator has a periodic rule, second abnormal information is generated, and the second abnormal information is updated in the abnormal event.
[0043] The UEs in each abnormal cell are subjected to anomaly detection through the cell where the anomaly occurs corresponding to the abnormal indicator, abnormal UEs are determined, third abnormal information is generated, and the third abnormal information is updated in the abnormal event.
[0044] An alarm is generated based on the abnormal event. The user can determine the specific abnormal indicator, the cell and time period where the anomaly occurs, whether the anomaly has a periodic rule, and the specific abnormal UE through the alarm.
[0045] In the present example, the signaling data is statistically analyzed in time granularity and spatial granularity to obtain signaling indicators, so that each signaling indicator includes time information and spatial information. Then, the multiple signaling indicators are classified to obtain at least one type of indicator. Thus, based on the indicator type, the abnormal indicators of different types of signaling indicators are classified and subjected to anomaly detection, so that the attack degree and the distribution over time of the abnormal indicators can be quickly determined. Since the signaling indicators are also obtained based on spatial granularity, when the abnormal indicators are detected, the distribution over space can also be directly determined. Then, according to the spatial information corresponding to the abnormal indicators, the abnormal UEs in the space where the anomaly occurs are subjected to anomaly detection, so that the calculation amount is reduced and the attack detection efficiency is improved. Finally, based on the abnormal information over time and space and the abnormal UEs determined in the above detection process, an alarm is generated, so that the user can quickly determine the range of attack, the distribution rule of attack, and the source of attack according to the alarm, without the need for the user to additionally analyze the attack detection data, thereby improving the processing efficiency of attack detection.
[0046] FIG. 2 is a flowchart of a signaling attack detection method according to an embodiment of the present application. As shown in FIG. 2, the signaling attack detection method can be applied in a server, a terminal, or the server 130 as shown in FIG. 1, but is not limited thereto. In the embodiment of FIG. 2, the signaling attack detection method can include, but is not limited to, steps 210 to 280.
[0047] In step 210, signaling data is obtained.
[0048] In step 220, the signaling data is counted according to a preset time granularity and a space granularity, to obtain a plurality of signaling indicators, wherein each signaling indicator comprises time information and space information.
[0049] In step 230, the plurality of signaling indicators are classified to obtain at least one indicator type.
[0050] In step 240, the plurality of signaling indicators are respectively subjected to abnormality detection according to the indicator type.
[0051] In step 250, when an abnormal indicator is detected, first abnormal information is generated according to the space information of the abnormal indicator.
[0052] In step 260, second abnormal information is obtained according to the distribution rule of the abnormal indicator.
[0053] In step 270, an abnormal terminal is detected according to the space information of the abnormal indicator, to obtain third abnormal information.
[0054] In step 280, an alarm is generated according to the first abnormal information, the second abnormal information and the third abnormal information.
[0055] In step 210, the signaling data refers to signaling data generated by the core network, for example, N1, N2, N SBI interface and the like. The signaling data can be obtained through network management or a parsing device with a signaling data collection function. The N1 interface is a signaling interface between the UE and the Access and Mobility Management Function (AMF); the N2 interface is a signaling interface between the (R)AN and the AMF, wherein the RAN is a Radio Access Network, and the AN is an Access Network; the N SBI interface between core network elements.
[0056] In step 220, the time granularity refers to a preset statistical time range according to requirements. For example, the time granularity can be 5 minutes, 15 minutes, 1 hour, etc., which is not limited herein. For example, when the time granularity is 5 minutes, the signaling data within every 5 minutes is counted to obtain the corresponding signaling indicator. The time granularity is not limited to one or more.
[0057] The spatial granularity refers to a statistical spatial range set in advance according to a requirement. Exemplarily, the spatial granularity can be a city, a network element, a tracking area (TA), a base station, a cell, a UE, and the like, which is not specifically limited herein. For example, when the spatial granularity is a tracking area, the signaling data in the same tracking area is counted to obtain the corresponding signaling indicators. The tracking area can be represented by a tracking area code (Tac). The spatial granularity is not limited to one or more.
[0058] The signaling indicator refers to an indicator set for attack detection based on the signaling data statistics. Exemplarily, the signaling indicator includes, but is not limited to, a UE number, an execution number of a signaling process, an execution duration, an execution interval, a user distribution, and the like. The signaling process includes, but is not limited to, registration (initial registration, mobile registration, periodic registration), service request, deregistration, session request / establishment / deletion, user context establishment, security mode command, PFCP (Packet Forwarding Control Protocol) session establishment / modification / release, Nnrf registration / change / deletion / service discovery, and the like. The Nnrf refers to a service-based interface exhibited by a network repository function (NRF).
[0059] In step 230, the classification refers to dividing the signaling indicators with the same distribution rule into the same category. The distribution rule can be a rule on time and space or other external factors. For example, taking time as an example, taking a week as a target time period, the distribution of some signaling indicators on the time axis in this week has a period, and the fluctuation every day has a regularity; the signaling indicators with the same / similar distribution period or the same / similar fluctuation rule are classified into the same category. The indicator type refers to the type of the signaling indicator after classification. Exemplarily, the indicator type includes a periodic type, an interval type, and a trend type.
[0060] In step 240, the anomaly detection refers to detecting the signaling indicators belonging to the same indicator type by using a pre-trained model or a pre-set rule, and identifying the signaling indicators with values exceeding a normal range.
[0061] In step 250, the abnormal indicator refers to the signaling indicator with a value exceeding the normal range. The first abnormal information refers to information including a specific abnormal indicator and spatial information corresponding to the abnormal indicator. For example, when the preset spatial granularity is a cell, the spatial information corresponding to the abnormal indicator is a certain cell or a certain cell range.
[0062] In step 260, the distribution rule of the abnormal index refers to the distribution rule that the abnormal index has over time. For example, the distribution of the abnormal index has periodicity. The second abnormal information refers to information including whether the corresponding abnormal index has periodicity and a specific distribution period.
[0063] In step 270, detecting the abnormal terminal refers to determining the spatial range corresponding to the abnormal index based on the spatial information of the abnormal index, detecting each terminal in the spatial range of the abnormal, and identifying the abnormal terminal therein.
[0064] In step 280, the alarm refers to information at least containing the first abnormal information, the second abnormal information, and the third abnormal information, and is set to notify the user that the signaling attack is detected.
[0065] The alarm is generated by association based on the abnormal information identified by the abnormal index detection, the abnormal index distribution rule detection, and the abnormal UE detection. For example, the alarm is generated according to the identified abnormal index, the abnormal UE, and the abnormal index distribution rule. Alternatively, the alarm is generated according to the identified abnormal index and the abnormal UE. Alternatively, the alarm is generated according to the identified abnormal UE.
[0066] The generated alarm includes, but is not limited to, threat identification, threat source, threat level, threat type, threat details, occurrence time, etc. The threat details can include DDoS attack type, malicious behavior UE, periodic attack signaling index, etc.
[0067] In the above steps 210 to 280, the server can perform the steps, the terminal can perform the steps alone, or the terminal and the server can perform the steps together.
[0068] In the above steps 210 to 280, the signaling data is counted in time granularity and space granularity to obtain the signaling index, so that each signaling index includes time information and space information. Then, the multiple signaling indexes are classified to obtain at least one index type. Thus, based on the index type, the abnormal detection is performed on the signaling indexes of different types, the attack degree of the abnormal index and the distribution over time can be quickly determined. Since the signaling index is also counted based on the space granularity, when the abnormal index is detected, the distribution of the attack in the space can also be directly determined. Then, according to the spatial information corresponding to the abnormal index, the abnormal terminal detection is performed on the terminals in the abnormal occurrence space, which can reduce the calculation amount and improve the attack detection efficiency. Finally, based on the abnormal information and the abnormal terminal in the time and space granularity determined in the above detection process, the alarm is generated, so that the user can quickly determine the attack range, attack distribution rule, attack source, etc. according to the alarm, without the user needing to analyze the attack detection data additionally, and the processing efficiency of the attack detection is improved.
[0069] The above is a general description of steps 210-280, which have been described in more detail above, so only the specific implementation process of steps 230-270 will be described in detail below.
[0070] In step 230, the plurality of signaling indicators are classified to obtain at least one indicator type.
[0071] In an embodiment, the indicator type includes periodic type, interval type, and trend type. The periodic type indicates that the signaling indicator is obviously affected by time or observable factors to present regular fluctuations. The periodic type of signaling indicators can include, but is not limited to, the number of UEs, the number of a certain signaling process in a certain state, etc. The interval type indicates that the signaling indicator fluctuates within a certain interval range, and from a time perspective, it more shows a kind of random distribution. The interval type of signaling indicators can include, but is not limited to, the number of UEs whose number of a certain signaling process in a certain state is greater than a threshold, the number of UEs whose execution duration of a certain signaling process in a certain state is greater than a threshold, etc. The trend type indicates that the data of the signaling indicator shows relatively stable and is less affected by time or external factors. The state of the signaling process can include, but is not limited to, execution success, failure, and timeout.
[0072] By classifying the signaling indicators into periodic type, interval type, and trend type, subsequent detection of abnormal signaling can be performed according to different indicator types. Compared with directly detecting all signaling indicators, additional indicator analysis is required. In this embodiment, by classifying the signaling indicators, the degree of DDoS attack and attack distribution of different types of signaling indicators can be determined when an abnormal indicator is detected, combined with the time information and spatial information of the indicator, and the attack distribution of different types of signaling indicators can be analyzed more quickly.
[0073] In step 240, the plurality of signaling indicators are classified according to the indicator type.
[0074] In an embodiment, step 240 includes:
[0075] For each indicator type of signaling indicator, the signaling indicator is input into the pre-trained abnormal detection model corresponding to the indicator type to obtain a normal indicator baseline.
[0076] When the indicator value of the signaling indicator exceeds the normal indicator baseline, the signaling indicator is determined to be an abnormal indicator.
[0077] In this embodiment, the indicator type includes periodic type, interval type, and trend type. Correspondingly, the periodic type abnormal detection model, the interval type abnormal detection model, and the trend type abnormal detection model are pre-trained.
[0078] After the signaling indicators are classified, the same type of signaling indicators are baseline predicted by calling the corresponding anomaly detection model. For example, the classification obtains multiple signaling indicators of the periodic type, and the periodic anomaly detection model is called to baseline predict these signaling indicators of the same periodic type. The periodic anomaly detection model predicts the corresponding normal indicator value based on the time information and space information corresponding to the signaling indicators to obtain the corresponding normal indicator baseline.
[0079] The signaling indicators are compared with the corresponding normal indicator baseline. When the indicator value of the signaling indicator exceeds the normal indicator baseline, it is considered that the signaling indicator has an anomaly, a signaling attack occurs, and the signaling indicator is taken as an abnormal indicator. For example, when the abnormal indicator is judged, a deviation range can be set based on the normal value predicted by the corresponding anomaly detection model, and the deviation range is taken as the normal indicator baseline. When the indicator of the signaling indicator is in the range, it is determined that the signaling indicator is normal; when the indicator value of the signaling indicator is outside the range, it is determined that the signaling indicator is an abnormal indicator.
[0080] The periodic anomaly detection model can use spatial-temporal prediction, time series algorithm, including but not limited to Spatial-Temporal-Decoupled Masked Pre-training (STD-MAE), neural network architecture based on self-attention mechanism (Transformer), etc. The interval anomaly detection model can use but is not limited to History-Max algorithm, etc. The trend anomaly detection model can use but is not limited to Light Gradient Boosting Machine (LightGBM) algorithm, etc.
[0081] For example, as shown in FIG. 3, the collected signaling data is statistically processed according to the pre-set time granularity and space granularity to obtain the signaling indicators. The signaling indicators are classified to obtain periodic indicators, interval indicators, and trend indicators. The three types of signaling indicators are respectively input into the corresponding anomaly detection model to obtain the corresponding normal indicator baseline. The indicator value of the signaling indicator is compared with the corresponding normal indicator baseline, and the indicator whose indicator value exceeds the normal indicator baseline is taken as an abnormal indicator.
[0082] In the above embodiment, after the signaling indicators are classified, the normal indicator values of the same type of signaling indicators are predicted by calling the corresponding abnormal detection model of the type to construct a normal indicator baseline, and then the abnormal indicators are detected by comparing the signaling indicators with the corresponding normal indicator baseline. Compared with using one model to detect abnormal indicators for all signaling indicators, the embodiment pre-trains the corresponding abnormal detection model for different indicator types to predict the normal indicator baseline, and the predicted normal indicator baseline is more accurate, which can improve the accuracy of abnormal indicator detection, and also realizes the detection of multiple signaling attacks (repetition, periodicity, slow speed, etc.), covering a wide range of attack types.
[0083] In an embodiment, step 240 further includes: obtaining network element load information; and performing abnormal detection on the signaling indicators according to the network element load information and the normal indicator baseline. The network element load information refers to the load condition of the related network element corresponding to the time range and the space range of the signaling indicators to be detected, for example, a load alarm.
[0084] As shown in FIG. 3, after obtaining the normal indicator baseline of different indicator types, the abnormal indicator detection is performed in combination with the network element load information to determine the abnormal indicators in the signaling indicators. By combining the network element load information with the normal indicator baseline to perform abnormal indicator detection, the accuracy of abnormal indicator detection can be further improved.
[0085] In an embodiment, the abnormal detection model is trained by the following steps:
[0086] Obtaining the historical normal values of the signaling indicators of the corresponding indicator type;
[0087] Obtaining the spatial features and the time features of the historical normal values;
[0088] Constructing training samples according to the historical normal values, the spatial features and the time features;
[0089] Training the abnormal detection model according to the training samples, so that the abnormal detection model can output the normal indicator baseline corresponding to the signaling indicators according to the time information and the space information.
[0090] In the embodiment, the historical normal values refer to the indicator values obtained by statistically analyzing the normal signaling data in a historical time period without signaling attacks. For different types of abnormal detection models, the corresponding type of historical normal values needs to be collected. For example, for a periodic abnormal detection model, the normal signaling indicators of the periodic type in a historical time period are collected. The spatial features refer to the statistical space range of the indicators corresponding to the historical normal values. The time features refer to the statistical time corresponding to the historical normal values.
[0091] Exemplarily, FIG. 4 is a schematic diagram of training a periodic model according to an example of the present application. As shown in FIG. 4, it is assumed that the periodic anomaly detection model adopts an STD-MAE model, and the periodic indicators include the number of UEs and the number of initial registration process successes. STD-MAE is a self-supervised pre-training framework that proposes to perform masking and reconstruction in the time and spatial dimensions, respectively, to learn the heterogeneity (non-stationarity) in time and space.
[0092] In STD-MAE, a decoupled masked spatial autoencoder (S-MAE) and a masked temporal autoencoder (T-MAE) are used to reconstruct spatio-temporal sequences along the spatial and temporal dimensions. The spatial encoder and the temporal encoder randomly mask the long-term historical data along the spatial axis and the temporal axis, respectively, and then the corresponding decoder reconstructs the masked input, and finally the hidden representation generated by the autoencoder. STD-MAE can effectively learn the non-stationarity of spatio-temporal data and can improve the performance of downstream spatio-temporal prediction models. The distribution of signaling indicators also has certain spatio-temporal heterogeneity, so STD-MAE framework is used for prediction analysis.
[0093] Before performing anomaly indicator detection, the statistical classification of signaling indicators has been completed based on spatio-temporal granularity. In this example, the spatial granularity is set to Tac and urban area. For periodic signaling indicators, STD-MAE is used for prediction. Here, the STD-MAE model is based on past historical periodic indicator data and influencing factors to establish a model to predict the signaling indicators of a certain area at a certain time. As shown in FIG. 4, the input historical periodic indicators include the number of UEs (urban level), the number of UEs (Tac level), the number of initial registration request process successes (urban level), and the number of initial registration request process successes (Tac level). The influencing factors include Tac, month, day, hour, minute, weekday, Saturday, Sunday, weather, holiday, etc. The trained STD-MAE model can predict the values of indicators such as the number of UEs (urban level), the number of UEs (Tac level), the number of initial registration request process successes (urban level), and the number of initial registration request process successes (Tac level).
[0094] The above embodiment trains the anomaly detection model by selecting historical indicators of the same indicator type as the signaling indicators to be detected, so that the anomaly detection model obtained by training has higher adaptation degree to the signaling indicators to be detected, and the prediction result is more accurate.
[0095] In step 250, when an anomaly indicator is detected, first anomaly information is generated according to the spatial information of the anomaly indicator.
[0096] In an embodiment, step 250 includes:
[0097] According to the spatial information, the attack spatial range is determined;
[0098] According to the abnormal value of the attack space range and the abnormal index, a first abnormal information is generated.
[0099] In the embodiment, the space information refers to a specific space corresponding to the abnormal index. For example, when the space granularity of the preset statistical signaling index is a cell, the space information of the abnormal index is a certain cell.
[0100] The attack space range refers to a set of one or more space regions where the abnormal index exists. The granularity of the actual space region depends on the space granularity when the statistical signaling index is generated, and includes but is not limited to a city, a network element, a tracking area (Tac), a base station, a cell, etc. For example, the space granularity is a cell, three abnormal indexes are detected, and the attack space range is a set of cells corresponding to the three abnormal indexes.
[0101] The abnormal value, attack type, etc. can be determined through the abnormal index. The first abnormal information at least includes but is not limited to the abnormal index, the attack space range, the DDoS attack type, etc. When the first abnormal information is generated, an abnormal event is constructed, and the content contained in the abnormal event is at least the first abnormal information.
[0102] In the above embodiment, the signaling data is statistically processed through the pre-set space-time granularity to obtain the signaling index carrying time information and space information. When the abnormal index is detected, the space region where the abnormality occurs can be determined based on the space information of the index, and the attack space range can be quickly determined according to the set of space regions corresponding to each abnormal index. Compared with the prior art, the embodiment can determine the attack space range at the same time when the abnormal index is detected, improve the efficiency of attack detection, and also improve the efficiency of subsequent abnormal attack processing of the user because the detection result with more useful information is generated.
[0103] In step 260, second abnormal information is obtained according to the distribution rule of the abnormal index.
[0104] In an embodiment, step 260 includes:
[0105] generating an abnormal index sequence according to the time information of the abnormal index;
[0106] performing Fourier transform on the abnormal index sequence to obtain an abnormal index spectrum;
[0107] calculating a distribution period corresponding to the abnormal index according to a frequency point in the abnormal index spectrum;
[0108] generating the second abnormal information according to the distribution period.
[0109] In the embodiment, the time information refers to a statistical time period determined based on a time granularity of the signaling index statistics. For example, assuming that the time granularity is 15 minutes, then in one hour, four continuous statistical time periods (0-15 minutes, 15-30 minutes, 30-45 minutes, and 45-60 minutes) can be obtained.
[0110] The abnormal index sequence refers to an index data sequence obtained by determining the time sequence of each abnormal index through the time information of the abnormal index and arranging the abnormal index in the sequence.
[0111] The abnormal index spectrum refers to a frequency spectrum based on the frequency domain obtained by performing Fourier transform on the abnormal index sequence based on the time domain. When a frequency point with a significant increase appears in the abnormal index spectrum, it indicates that the abnormal index has a periodic distribution, and the corresponding DDoS attack behavior has periodicity. Further, the distribution period is calculated by selecting a high-intensity frequency point.
[0112] The second abnormal information refers to information generated based on the distribution period and carrying the periodicity of the abnormal index. The second abnormal information is updated into the abnormal event, and at this time, the abnormal event contains at least the first abnormal information and the second abnormal information.
[0113] In the above embodiment, the abnormal index sequence is subjected to time-frequency conversion through Fourier transform to analyze the abnormal distribution period. In this way, the user can predict the time of attack occurrence according to the distribution period, perform key detection or defense in advance, and improve the network security.
[0114] In step 270, the abnormal terminal is detected according to the spatial information of the abnormal index, and third abnormal information is obtained.
[0115] In an embodiment, step 270 includes:
[0116] determining the attack space range according to the spatial information of the abnormal index;
[0117] selecting a terminal in the attack space range as a target terminal;
[0118] obtaining the signaling index of each target terminal according to a pre-set time granularity;
[0119] calling a pre-trained terminal detection model to perform reconstruction error prediction on the signaling index of each target terminal to obtain the reconstruction error of each target terminal;
[0120] when the reconstruction error is greater than a pre-set threshold, determining that the target terminal is an abnormal terminal;
[0121] generating third abnormal information according to the identifier of the abnormal terminal.
[0122] In the embodiment, the preset time granularity refers to a time granularity when the signaling index is obtained by counting the signaling data before the abnormal index detection is performed.
[0123] The pre-trained terminal detection model refers to a model obtained by model training based on historical abnormal UE behavior data. For example, as shown in FIG. 3, the terminal detection model can adopt a model of the self-encoder type. Before the abnormal terminal detection is performed, the terminal detection model needs to be constructed first, and then based on the historical abnormal UE behavior data, the model is iteratively trained through the steps of forward propagation, loss calculation, backward propagation and parameter updating, so as to minimize the difference between the input and the output of the trained model. The loss function adopted includes but is not limited to Mean-Square Error (MSE), cross-entropy loss, etc.
[0124] The reconstruction error refers to the error between the signaling index of the target terminal before input and the signaling index after being reconstructed in the model when the signaling index of the target terminal is input into the trained terminal detection model.
[0125] The preset threshold refers to a reconstruction error threshold preset based on expert experience and demand.
[0126] The third abnormal information refers to information carrying the abnormal terminal identifier. Based on the third abnormal information, the user can determine which specific abnormal terminals are. The third abnormal information is updated into the abnormal event, at this time, the content contained in the abnormal event at least includes the first abnormal information, the second abnormal information and the third abnormal information.
[0127] In the above embodiment, after the abnormal index is detected, the abnormal terminal detection is performed based on the attack space range obtained according to the abnormal index, which can reduce the calculation amount and improve the detection efficiency.
[0128] In an embodiment, in the case where the abnormal index is not detected, the abnormal terminal detection is performed on each terminal according to the preset time granularity and the terminal granularity.
[0129] In the embodiment, the preset time granularity refers to a time granularity set for the abnormal terminal detection, which can be the same as or different from the preset time granularity in step 210. The terminal granularity refers to a spatial granularity of the terminal. The abnormal terminal detection on each terminal according to the preset time granularity and the terminal granularity refers to that the signaling index of each terminal interacting with the core network is counted according to the preset time granularity and the terminal as the spatial granularity, and the abnormal terminal detection is performed based on the signaling index of each terminal.
[0130] Exemplarily, FIG. 5 is a flowchart of abnormal terminal detection provided by an example of the present application. As shown in FIG. 5, firstly, abnormal index detection is performed on the signaling indicators obtained based on the space-time granularity statistics. If no abnormal index is detected, abnormal terminal detection is performed synchronously while the abnormal index detection is performed, and the range of the abnormal terminal detection is each terminal interacting with the core network at this time.
[0131] When the abnormal index is detected, the corresponding attack space range is determined according to the abnormal index. Distribution regularity judgment is performed on the abnormal index. Whether the abnormal index has the distribution regularity, the abnormal terminal detection is performed based on the attack space range. At this time, only the terminals in the attack space range are detected, and the terminals not belonging to the attack space range are not detected.
[0132] Finally, an alarm is generated according to the detected abnormal index, distribution regularity and abnormal terminal.
[0133] In the above example, in the case where no abnormal index is detected, abnormal terminal detection is performed on the terminals not limited in range in parallel with the abnormal index detection, so as to improve the reason recognition capability of causing network abnormality. In the case where the abnormal index is detected, only the terminals in the attack space range corresponding to the abnormal index are detected, so as to reduce the calculation amount and improve the detection efficiency.
[0134] The signaling attack detection method of the present application is described in detail below through two examples. It can be understood that the following examples are only used for better exemplarily describing the signaling attack detection method of the present application, and are not limited in specific.
[0135] Example 1
[0136] FIG. 6 is a flowchart of signaling attack detection provided by an example of the present application. As shown in FIG. 6, the signaling attack detection in the present example includes:
[0137] Step 610, obtaining signaling data.
[0138] The signaling data is the signaling data generated by the core network, such as N1, N2, N SBI interface and the like. The source of the signaling can be provided by a network management, an analysis device and the like.
[0139] Step 620, statistically obtaining signaling indicators in the space-time dimension, and classifying the signaling indicators.
[0140] The statistics is based on the space granularity and the time granularity. The space granularity includes but is not limited to city, network element, Tac (tracking area), base station, cell, UE and the like. The time granularity includes but is not limited to 5 minutes, 15 minutes, 1 hour and the like. Moreover, the statistics can be performed on multiple space granularity and time granularity.
[0141] The signaling indicators include, but are not limited to, the number of UEs, the number of execution times of signaling procedures, execution time, execution interval, user distribution, etc.
[0142] The signaling indicators are classified, and the indicator types include periodic type, interval type, and trend type.
[0143] In step 630, the classified signaling indicators are respectively input into corresponding detection models for abnormal indicator detection.
[0144] Periodic indicators are input into a periodic model for detection.
[0145] Interval indicators are input into an interval model for detection.
[0146] Trend indicators are input into a trend model for detection.
[0147] In step 640, an abnormal indicator is detected, and an abnormal event is generated.
[0148] An abnormal indicator that exceeds a normal indicator baseline is detected by a model, so as to determine an abnormal indicator and an attack space range.
[0149] An abnormal event is generated according to an abnormal indicator.
[0150] In step 650, distribution regularity detection is performed on the abnormal indicator.
[0151] If an abnormal indicator is identified, it is further identified whether the abnormal indicator has a distribution regularity. For example, the distribution regularity can be periodicity, and the detection algorithm includes, but is not limited to, Fourier transform.
[0152] The distribution regularity of the abnormal indicator is identified, and is updated into the abnormal event.
[0153] If no abnormal indicator is identified, the distribution regularity detection is not required.
[0154] In step 660, abnormal UE detection is performed on the signaling indicators.
[0155] Abnormal behavior UEs are detected by an abnormal UE detection model on signaling indicators in an attack space range or an unlimited range.
[0156] The abnormal behavior UEs are identified and updated into the abnormal event.
[0157] In step 670, an abnormal event is associated to generate an alarm.
[0158] The abnormalities identified based on the abnormal indicator detection, the abnormal indicator distribution regularity detection, and the abnormal UE detection are associated to generate an alarm.
[0159] The abnormal association includes generating an alarm according to the identified abnormal indicators, distribution regularity abnormalities, and abnormal UEs.
[0160] Or, according to the identified abnormal indicators, abnormal UEs generate alarms;
[0161] Or, according to the identified abnormal UEs generate alarms.
[0162] Example 2:
[0163] In this example, a large number of initial registration success process success caused by signaling DDoS scene detection, the specific process steps are as follows:
[0164] ①Get signaling data. In this example, the eXtensible Discovery Record (XDR) bill data provided by the received signaling traffic analysis device, specifically the signaling data of N1 interface, covering the initial registration signaling related business data. The data can be obtained periodically or in real time.
[0165] ②Statistical signaling indicators in space-time dimensions, and classify the indicators. The spatial dimension (spatial granularity) selects Tac tracking area, city, and each node has indicators. The time dimension (time granularity) is set to 15 minutes as a time step, and 6 hours as a window, that is, 24 time step space-time sequences are obtained. According to the set space-time granularity, the indicator information of a period of time is sequentially counted for detection, such as 7 days, 15 days, etc. Each time window contains multiple spatial nodes, and multiple time step windows constitute a space-time sequence.
[0166] The statistical signaling indicators include the number of UEs, the number of initial registration process success, the execution time, the execution interval, and the user distribution.
[0167] Classify the indicators to obtain the indicator types, including periodic type and interval type.
[0168] Periodic indicators include the number of UEs and the number of initial registration process success.
[0169] Interval type indicators include the number of UEs with initial registration process success greater than the threshold.
[0170] ③The signaling indicators are input into the detection model of the corresponding type according to the indicator type for abnormal indicator detection.
[0171] Periodic indicators are input into the periodic model for detection. The periodic model algorithm uses STD-MAE (Spatio-Temporal-Decoupled Masked Pre-training).
[0172] The interval type index is input into the interval model for detection, and the History-Max is used for interval model algorithm. The baseline data is generated by learning the maximum value of the index in the historical data and the access upper limit of the space region, and the generated determination method is not limited.
[0173] In addition, the load information or alarm information of the network element obtained from the network management can also be combined for analysis. In this example, the load information of the AMF network element needs to be obtained from the network management.
[0174] The periodic index and the interval index are detected for index anomaly by the normal index of the periodic model, the normal index baseline of the interval model, and the network element load information, as shown in FIG. 3.
[0175] (4) An abnormal index is detected, and an abnormal event is generated. The index that exceeds the normal baseline is detected by the above model, and the abnormal index and the attack space range are determined. In this example, the number of UEs in the Tac level and the number of successful initial registration request processes exceed the baseline, and the Tac range of the attack is determined, and the index abnormal event is generated. The detection of the interval model is normal.
[0176] An abnormal event is generated according to the abnormal index. At this time, the abnormal event includes the abnormal index, the attack space range, the DDoS attack type, etc. The abnormal index includes the number of UEs, the number of successful initial registration request processes. The attack space range, for example, Tac{1001}. The DDoS attack type, for example, initial registration signaling DDoS attack.
[0177] (5) The distribution regularity of the abnormal index is detected. After the abnormal index is detected, it is further judged whether the abnormal index has periodicity, and Fourier transform is used for detection and judgment.
[0178] The abnormal index sequence is generated according to the time information, and then the sequence is transformed into the frequency domain by Fourier transform. If there is a frequency point with obvious amplitude in the frequency spectrum, it means that the abnormal index has periodic distribution, and the DDoS attack behavior has periodicity. Further, the high-intensity frequency point is selected to calculate the period. And the detected periodicity is updated and supplemented in the abnormal event.
[0179] (6) The abnormal UE of the signaling index is detected. Referring to FIG. 5, the abnormal detection process followed in this example is the abnormal index detection 510, the distribution regularity detection 520, the abnormal terminal detection 530, and the alarm 540 process. That is, if the abnormal index is detected, the space range of the attack is determined, and the malicious behavior of the UE in the space range is detected to determine the abnormal UE.
[0180] In this step, the signaling indicators are UE granularity statistics indicators, including the number of initial registration success process execution, execution duration, execution interval, etc.
[0181] The abnormal UE detection adopts a pre-trained autoencoder model, inputs the signaling data into the model to obtain an output, and identifies abnormal UEs by comparing the difference between the input data and the output data. The abnormal behavior UEs are identified and updated to the abnormal events.
[0182] The abnormal event correlation generates an alarm. The abnormalities identified by the indicator abnormality detection, the abnormal indicator distribution rule detection, and the abnormal UE detection generate an alarm through correlation. In this example, the abnormal event correlation generates an alarm according to the identified indicator abnormalities, distribution rule abnormalities, and abnormal UEs.
[0183] The generated alarm information includes, but is not limited to, threat identification, threat source (Tac{1001}), threat level, threat type, threat details, occurrence time, etc. The threat details can include DDoS attack type (initial registration signaling DDoS attack), malicious behavior UE (IMSI value), periodic attack signaling indicator (number of initial registration process success), etc.
[0184] In the above examples, the signaling data is statistically analyzed in time granularity and space granularity to obtain signaling indicators, so that each signaling indicator includes time information and space information. Then, the multiple signaling indicators are classified to obtain at least one indicator type. Thus, based on the indicator type, the abnormal detection of different types of signaling indicators can quickly determine the attack degree and the distribution in time of the abnormal indicators. Since the signaling indicators are also obtained based on the space granularity statistics, when the abnormal indicators are detected, the distribution of the attack in space can also be directly determined. According to the space information corresponding to the abnormal indicators, the abnormal terminal detection of the terminals in the abnormal occurrence space can be performed, which can reduce the calculation amount and improve the attack detection efficiency. Finally, based on the abnormal information in time and space granularity and the abnormal terminals determined in the above detection process, an alarm is generated, so that the user can quickly determine the attack range, attack distribution rule, attack source, etc. according to the alarm, without the need for the user to perform additional analysis on the attack detection data, thereby improving the processing efficiency of the attack detection.
[0185] FIG. 7 is a schematic diagram of a signaling attack detection system according to an embodiment of the present application. The signaling attack detection system 700 can be deployed in a server, or in a terminal, or jointly carried by a terminal and a server. In this embodiment, the signaling attack detection system 700 includes:
[0186] The signaling data obtaining module 710 is configured to obtain signaling data, perform statistics on the signaling data according to a pre-set time granularity and a space granularity, and obtain a plurality of signaling indexes, wherein each signaling index comprises time information and space information, and perform classification on the plurality of signaling indexes, and obtain at least one index type.
[0187] The abnormal index detecting module 720 is configured to perform abnormal detection on the plurality of signaling indexes according to the index type respectively, and when an abnormal index is detected, generate first abnormal information according to the space information of the abnormal index.
[0188] The distribution rule detecting module 730 is configured to obtain second abnormal information according to a distribution rule of the abnormal index.
[0189] The abnormal terminal detecting module 740 is configured to detect an abnormal terminal according to the space information of the abnormal index, and obtain third abnormal information.
[0190] The alarm module 750 is configured to generate an alarm according to the first abnormal information, the second abnormal information and the third abnormal information.
[0191] It should be noted that the specific implementation manners and beneficial effects of the signaling attack detection system of the embodiments of the present application correspond to the signaling attack detection method provided in the above embodiments, and will not be repeated here.
[0192] FIG. 8 is a structural block diagram of part of a terminal for implementing the signaling attack detection method of the embodiments of the present application. As shown in FIG. 8, the terminal includes a radio frequency (RF) circuit 810, a memory 815, an input unit 830, a display unit 840, a sensor 850, an audio circuit 860, a wireless fidelity (Wi-Fi) module 870, a processor 880, and a power supply 890, and the like. Those skilled in the art can understand that the structure of the terminal shown in FIG. 8 does not constitute a limitation on the mobile phone or computer, and can include more or fewer components than those shown, or combine certain components, or different component arrangements.
[0193] The RF circuit 810 can be configured to receive and send signals in the process of information transceiving or calling, in particular, receive the downlink information of the base station and process it by the processor 880; in addition, send the uplink data to the base station.
[0194] The memory 815 can be configured to store software programs and modules, and the processor 880 performs various functional applications and data processing of the content terminal by running the software programs and modules stored in the memory 815.
[0195] The input unit 830 can be configured to receive input digital or character information, and to generate a key signal input with respect to a setting of the content terminal and a function control. Specifically, the input unit 830 can include a touch panel 831 and other input devices 832.
[0196] The display unit 840 can be configured to display input or provided information, and various menus of the content terminal. The display unit 840 can include a display panel 88.
[0197] The audio circuit 860, the speaker 861, and the microphone 862 can provide an audio interface.
[0198] In the present embodiment, the processor 880 included in the terminal can perform the signaling attack detection method of the previous embodiments.
[0199] The terminal of the embodiments of the present application includes, but is not limited to, a mobile phone, a computer, a smart voice interactive device, a smart home appliance, a vehicle-mounted terminal, an aircraft, etc. The embodiments of the present application can be applied to various scenarios, including but not limited to content recommendation, data screening, etc.
[0200] FIG. 9 is a structural block diagram of a part of a server implementing the signaling attack detection method of the embodiments of the present application. The server can have a large difference due to different configurations or performances, and can include one or more central processing units (CPUs) 922 (for example, one or more processors) and a memory 932, one or more storage media 930 (for example, one or more mass storage devices) storing an application program 99 or data 944. Among them, the memory 932 and the storage medium 930 can be temporary storage or persistent storage. The program stored in the storage medium 930 can include one or more modules (not shown in the figure), and each module can include a series of instruction operations in the server. Further, the central processing unit 922 can be configured to communicate with the storage medium 930 and execute a series of instruction operations in the storage medium 930 on the server.
[0201] The server can also include one or more power supplies 926, one or more wired or wireless network interfaces 950, one or more input / output interfaces 958, and / or one or more operating systems 941, such as Windows ServerTM, Mac OS XTM, UnixTM, LinuxTM, FreeBSDTM, etc.
[0202] The central processing unit 922 in the server can be configured to perform the signaling attack detection method of the embodiments of the present application.
[0203] The embodiment of the present application further provides a computer readable storage medium, which is arranged to store program codes, and the program codes are arranged to execute the signaling attack detection method of each of the foregoing embodiments.
[0204] The embodiment of the present application further provides a computer program product, which comprises a computer program. A processor of a computer device reads the computer program and executes, so that the computer device executes the signaling attack detection method.
[0205] The terms "first", "second", "third", "fourth" and the like in the description of the present application and the above drawings, if any, are used to distinguish similar objects, and do not necessarily indicate a specific order or sequence. It should be understood that the data thus used can be interchanged under appropriate circumstances, so that the embodiments of the present application described herein can be implemented in an order other than that illustrated or described herein. In addition, the terms "comprise" and "include" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, system, product or device that includes a list of steps or units does not necessarily limit to those steps or units clearly listed, but can include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0206] It should be understood that in the present application, "at least one" means one or more, and "multiple" means two or more. "And / or" is used to describe the relationship between the associated contents, which means that there can be three relationships, for example, "A and / or B" can represent three cases: only A exists, only B exists, and A and B exist at the same time, where A and B can be singular or plural. The character " / " generally represents that the associated contents before and after are in an "or" relationship. "At least one of the following" or similar expressions means any combination of these items, including any combination of single or multiple items. For example, at least one of a, b or c can represent: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, and c can be single or multiple.
[0207] It should be understood that in the description of the embodiments of the present application, the meaning of multiple (or multiple items) is more than two, greater than, less than, more than, etc. are not included in the number, above, below, etc. are understood to include the number.
[0208] In several embodiments provided in the present application, it should be understood that the disclosed system, device and method can be implemented in other manners. For example, the described device embodiments are merely schematic. For example, the division of the units is only a logical function division. There can be another division manner for the actual implementation, for example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed mutual couplings or direct couplings or communication connections between different units, can be indirect couplings or communication connections through some interfaces, devices or units, and can be electrical, mechanical or in other forms.
[0209] The units described as separated components can or can not be physically separated, and the components displayed as units can or can not be physical units, i.e., can be located in one place, or can be distributed on a plurality of network units. Some or all of the units can be selected according to actual needs to achieve the purposes of the embodiments of the present application.
[0210] In addition, each functional unit in the embodiments of the present application can be integrated in one processing unit, or each unit can exist physically, or two or more units can be integrated in one unit. The integrated unit can be implemented in the form of hardware, or in the form of software functional units.
[0211] When the integrated unit is implemented in the form of software functional units and sold or used as an independent product, it can be stored in a computer readable storage medium. Based on such an understanding, the technical solutions of the present application essentially or the part that makes a contribution to the prior art, or all or part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium, and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in the embodiments of the present application. The foregoing storage medium includes: U disk, mobile hard disk, read-only memory (ROM), random access memory (RAM), magnetic disk or optical disk, and various media that can store program codes.
[0212] It should also be understood that the various embodiments provided by the embodiments of the present application can be combined in any manner to achieve different technical effects.
[0213] The above is a specific description of the embodiments of the present application, but the present application is not limited to the above-described embodiments, and those skilled in the art can make various equivalent modifications or replacements without departing from the spirit of the present application, and these equivalent modifications or replacements are included in the scope defined by the claims of the present application.
Claims
1. A signaling attack detection method, comprising: obtaining signaling data; statistically processing the signaling data according to a pre-set time granularity and a space granularity to obtain a plurality of signaling indicators, wherein each signaling indicator comprises time information and space information; classifying the plurality of signaling indicators to obtain at least one indicator type; performing abnormality detection on the plurality of signaling indicators according to the indicator type respectively; when an abnormal indicator is detected, generating first abnormal information according to the space information of the abnormal indicator; obtaining second abnormal information according to the distribution rule of the abnormal indicator; detecting abnormal terminals according to the space information of the abnormal indicator to obtain third abnormal information; generating an alarm according to the first abnormal information, the second abnormal information and the third abnormal information.
2. The signaling attack detection method of claim 1, wherein, The abnormality detection on the plurality of signaling indicators according to the indicator type respectively comprises: for the signaling indicators of each indicator type, inputting the signaling indicators into a pre-trained abnormality detection model corresponding to the indicator type to obtain a normal indicator baseline; when the indicator value of the signaling indicator exceeds the normal indicator baseline, determining that the signaling indicator is the abnormal indicator.
3. The signaling attack detection method of claim 2, wherein, The pre-trained abnormality detection model is obtained by the following steps: obtaining historical normal values of the signaling indicators corresponding to the indicator type; obtaining space features and time features of the historical normal values; constructing training samples according to the historical normal values, the space features and the time features; training the abnormality detection model according to the training samples, so that the abnormality detection model can output the normal indicator baseline corresponding to the signaling indicator according to the time information and the space information.
4. The signaling attack detection method of claim 3, wherein, The indicator type comprises: periodic type, interval type and trend type.
5. The signaling attack detection method of claim 2, wherein, The abnormality detection on the plurality of signaling indicators according to the indicator type respectively further comprises: obtaining network element load information; performing abnormality detection on the signaling indicators according to the network element load information and the normal indicator baseline.
6. The signaling attack detection method of claim 1, wherein, The generation of the first abnormal information according to the space information of the abnormal indicator comprises: determining an attack space range according to the space information; generating the first abnormal information according to the attack space range and the abnormal value of the abnormal indicator.
7. The signaling attack detection method of claim 1, wherein, The obtaining of the second abnormal information according to the distribution rule of the abnormal indicator comprises: generating an abnormal indicator sequence according to the time information of the abnormal indicator; performing Fourier transform on the abnormal indicator sequence to obtain an abnormal indicator frequency spectrum; calculating a distribution period corresponding to the abnormal indicator according to a frequency point in the abnormal indicator frequency spectrum; generating the second abnormal information according to the distribution period.
8. The signaling attack detection method of claim 1, wherein, The generation of the third abnormal information by detecting abnormal terminals according to the space information of the abnormal indicator comprises: determining an attack space range according to the space information of the abnormal indicator; selecting terminals in the attack space range as target terminals; obtaining signaling indicators of each target terminal according to the pre-set time granularity. The pre-trained terminal detection model is called to perform reconstruction error prediction on the signaling indicators of each target terminal, to obtain reconstruction errors of each target terminal. When the reconstruction error is greater than a preset threshold, the target terminal is determined as an abnormal terminal. The third abnormal information is generated according to the identifier of the abnormal terminal.
9. The signaling attack detection method of claim 6 or 8, further comprising: In a case where the abnormal indicator is not detected, performing abnormal terminal detection on each terminal according to a preset time granularity and terminal granularity.
10. An electronic device, comprising: at least one processor; at least one memory configured to store at least one program; when at least one of the programs is executed by the at least one processor, the method of any one of claims 1-9 is implemented.
11. A computer readable storage medium storing computer executable instructions for executing the method of any one of claims 1-9.
12. A computer program product comprising computer programs or computer instructions, wherein, The computer program or the computer instructions are stored in a computer readable storage medium, and a processor of a computer device reads the computer program or the computer instructions from the computer readable storage medium. The processor executes the computer program or the computer instructions, so that the computer device executes the method of any one of claims 1-9.
Citation Information
Patent Citations
Pseudo base station early warning method and system based on big data
CN108235323A
Data processing method and device, electronic equipment and storage medium
CN114567882A
Monitoring index anomaly detection method and system based on time sequence and medium
CN116302804A
Signaling analysis method and related apparatus
US20220286263A1
Configuration anomaly detection method, server and storage medium
WO2021104270A1