WO2011147249A1 - 一种对wap业务订购过程进行监控的方法及装置 - Google Patents

一种对wap业务订购过程进行监控的方法及装置 Download PDF

Info

Publication number
WO2011147249A1
WO2011147249A1 PCT/CN2011/073746 CN2011073746W WO2011147249A1 WO 2011147249 A1 WO2011147249 A1 WO 2011147249A1 CN 2011073746 W CN2011073746 W CN 2011073746W WO 2011147249 A1 WO2011147249 A1 WO 2011147249A1
Authority
WO
WIPO (PCT)
Prior art keywords
service
information
requesting terminal
wap
subscribed
Prior art date
Application number
PCT/CN2011/073746
Other languages
English (en)
French (fr)
Inventor
李守平
Original Assignee
华为技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 华为技术有限公司 filed Critical 华为技术有限公司
Priority to EP11786021.3A priority Critical patent/EP2579637B1/en
Publication of WO2011147249A1 publication Critical patent/WO2011147249A1/zh

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W4/00Services specially adapted for wireless communication networks; Facilities therefor
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1408Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
    • H04L63/1416Event detection, e.g. attack signature detection
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1441Countermeasures against malicious traffic
    • H04L63/1466Active attacks involving interception, injection, modification, spoofing of data unit addresses, e.g. hijacking, packet injection or TCP sequence number attacks
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/08Access security
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/12Detection or prevention of fraud
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W8/00Network data management
    • H04W8/02Processing of mobility data, e.g. registration information at HLR [Home Location Register] or VLR [Visitor Location Register]; Transfer of mobility data, e.g. between HLR, VLR or external networks
    • H04W8/08Mobility data transfer
    • H04W8/12Mobility data transfer between location registers or mobility servers

Definitions

  • the embodiments of the present invention relate to the field of wireless communications technologies, and in particular, to a method and apparatus for monitoring a WAP service subscription process. Background technique
  • WAP Wireless Application Protocol
  • Implanting an illegal program in the WAP system is a common means of attacking a WAP service. Specifically, the attack is performed by embedding an illegal program in the WAP system, and the service order request message is constructed by the illegal program (in the illegal service order request message) Carrying someone's mobile phone number) Sending to the business processing system, and then confirming the order message twice to realize the illegal business order, and illegally profit from it.
  • the existing WAP service subscription process lacks an effective security protection mechanism, and after the illegal program is implanted in the WAP system, the system cannot identify the illegal message.
  • the WAP service is illegally ordered or used free of charge, resulting in economic loss of legitimate users or operators. Summary of the invention
  • Embodiments of the present invention provide a method and apparatus for monitoring a WAP service subscription process, thereby effectively improving the security of the WAP service subscription process.
  • a first aspect of the present invention provides a method for monitoring a WAP service subscription process, including:
  • a second aspect of the present invention provides an apparatus for monitoring a WAP service subscription process, including:
  • the first monitoring module is disposed at an exit of the access network gateway, and is configured to obtain information about the service to be subscribed and corresponding request terminal information;
  • a cache module configured to cache information acquired by the first monitoring module
  • a second monitoring module configured to obtain information about the service to be subscribed and corresponding request terminal information, where the wireless application protocol WAP gateway exits the communication with the access network gateway;
  • a service judging module configured to determine whether the information cached by the second monitoring module includes the information of the to-be-ordered service and the corresponding requesting terminal information;
  • the service processing module is configured to: when the judgment result of the service judging module is yes, continue the WAP service ordering process, and if the judgment result of the service judging module is no, the alarm information is sent.
  • FIG. 1 is a flowchart of a method according to an embodiment of the present invention
  • FIG. 2 is a schematic structural diagram of a system according to an embodiment of the present invention.
  • Embodiment 1 of the present invention is a signaling flowchart of Embodiment 1 of the present invention.
  • FIG. 5 is a schematic structural diagram of an apparatus according to an embodiment of the present invention. detailed description
  • the embodiment of the present invention provides a method for monitoring a WAP service subscription process.
  • the process of the method is shown in FIG. 1 , and the specific implementation manner is as follows:
  • the egress direction of the WAP gateway refers to the direction in which the WAP gateway sends data to the core network/service network; the egress direction of the access network gateway refers to the direction in which the access network gateway sends data to the WAP gateway.
  • the access network gateway refers to a gateway that forwards communication data between the requesting terminal and the WAP gateway.
  • the method provided by the embodiment of the present invention compares the information obtained by the exit of the WAP gateway with the information obtained by the exit of the access network gateway. If the illegal service request is sent by an illegal program implanted in the WAP gateway, the service request information cannot be obtained. It is found in the cache information obtained from the exit of the access network gateway, so that it can determine whether the WAP service subscription is legal, and effectively prevent the illegal subscription of the WAP service.
  • the method provided by the embodiment of the present invention specifically sets a probe point at the exit of the WAP gateway and the exit of the access network gateway that communicates with the WAP gateway, and the WAP service subscription is implemented by parsing the information acquired by the probe point. Process monitoring.
  • the embodiment of the present invention provides two implementations of information acquisition according to different information obtained by the detection point:
  • the specific implementation manner of the foregoing S102 includes: the probe point set at the exit of the WAP gateway acquires the service request message of the requesting terminal, and obtains the information of the service to be subscribed and the corresponding request terminal information by parsing the service request message, and the information of the service to be subscribed
  • the network address of the service to be subscribed (in the embodiment of the present invention, the address may be an IP address or a URL (Uniform Resource Locator) address)
  • the request terminal information includes the identifier information of the requesting terminal.
  • the identifier information may be a mobile phone number of the requesting terminal, an IMSI (International Mobile Subscriber Identity, an international mobile subscriber identity, or a user pseudo code, etc.).
  • the specific implementation manner of the foregoing S101 includes: the detection point set by the access gateway gateway is configured to acquire an online request message of the requesting terminal, and the requesting terminal information carried by the requesting terminal information is obtained by parsing the online request message, where the requesting terminal information includes the requesting terminal.
  • the identification information of the terminal further caches the correspondence between the IP address of the requesting terminal and the identification information of the requesting terminal; the probe point set by the outlet of the access network gateway also obtains the service request message of the requesting terminal, and parses the service
  • the request message acquires and caches the information of the service to be subscribed, and the information of the service to be subscribed includes the network address of the service to be subscribed, and also caches the correspondence between the IP address of the requesting terminal and the network address of the service to be subscribed. .
  • the set target WAP service may be monitored.
  • the identifier information of the WAP service to be monitored may be specifically set according to the preset (the identifier information may be the IP of the WAP service).
  • the address, or the URL address of the WAP service, and the like obtains the network address of the service to be subscribed and the identification information of the requesting terminal carried in the service request message for the WAP service to be monitored.
  • the embodiment of the present invention further includes: S106a: the probe point set by the access gateway gateway to obtain the offline request message of the requesting terminal, parse the offline request message, and obtain the IP address of the requesting terminal carried therein And the identification information of the requesting terminal; deleting the IP address of the corresponding requesting terminal in the cache and the identification information of the requesting terminal according to the IP address of the requesting terminal and the identification information of the requesting terminal, and the IP address of the requesting terminal and the requesting terminal Corresponding relationship of the identification information, and deleting the correspondence between the IP address of the corresponding requesting terminal in the cache and the network address of the service to be subscribed, and the network address of the service to be subscribed.
  • the specific implementation manner of monitoring the WAP service ordering process is as follows:
  • S1033a is executed to determine whether the cached information includes the correspondence between the IP address of the requesting terminal and the network address of the service to be subscribed and the corresponding network address; if the judgment result of S1032a is not , executing the above S105;
  • S1034a is executed to determine whether the cached network address is the same as the network address of the to-be-ordered service obtained from the WAP gateway exit. If the same, the current subscription service is considered as a legitimate service, and the foregoing operation is performed. S104; Otherwise, it is an illegal service, and the above S105 is performed.
  • the specific implementation manner of the foregoing S102 includes: the probe point set at the exit of the WAP gateway acquires the service request message of the requesting terminal, and obtains the information of the service to be subscribed and the corresponding request terminal information by parsing the service request message, where the service to be subscribed The information includes a network address of the service to be subscribed, and the request terminal information includes the identification information of the requesting terminal.
  • the specific implementation manner of the foregoing S101 includes: the detection point set by the access gateway gateway is configured to acquire an online request message of the requesting terminal, and the requesting terminal information is obtained by parsing the online request message, and the requesting terminal information includes the requesting terminal.
  • the information about the to-be-ordered service includes the service request message of the requesting terminal, and the information of the to-be-ordered service carried by the service request message is obtained by parsing the service request message, and the information of the to-be-ordered service includes the to-be-ordered service information.
  • the network address of the subscription service also caches the correspondence between the identification information of the requesting terminal and the network address of the service to be subscribed.
  • only the set target WAP service may be monitored.
  • the service for the WAP service to be monitored may be obtained according to the identifier information of the WAP service to be monitored.
  • the network location of the service to be subscribed carried in the request message Address and identification information of the requesting terminal.
  • the embodiment of the present invention further includes
  • the probe point set by the access gateway gateway is configured to obtain the offline request message of the requesting terminal, parse the offline request message, and obtain the identifier information of the requesting terminal carried in the requesting terminal; and delete the cache according to the identifier information of the requesting terminal. And correspondingly requesting the identification information of the terminal, and deleting the correspondence between the identifier information of the corresponding requesting terminal in the cache and the network address of the service to be subscribed, and the network address of the service to be subscribed.
  • the above specific implementation of monitoring the WAP service ordering process is as follows:
  • the method of determining the cached information includes the correspondence between the identifier information of the requesting terminal and the network address of the service to be subscribed, and the corresponding network address; if the judgment result of S1032b is not , executing the above S105;
  • S1033b is executed to determine whether the network address of the cache is the same as the network address of the service to be subscribed from the exit of the WAP gateway. If the same, the current subscription service is considered as a legitimate service, and the foregoing operation is performed. S104; Otherwise, it is an illegal service, and the above S105 is performed. Description.
  • a GGSN Gateway GPRS Support Node, GPRS General Packet Radio Service, General Packet Radio Technology
  • the WAP gateway is responsible for transmitting communication messages between the GGSN and the WAP service server.
  • Portal Page application technology) Server, AS (Application Server, Application Server) and SP/CP (Service Provider/Content Provider) are used to provide network service services for terminals.
  • the network architecture diagram shown in Figure 2 only gives a GGSN, in actual application, multiple GGSNs can communicate with the same WAP gateway.
  • a probe point 2 is set at the exit of the WAP gateway, and the device for monitoring the WAP service ordering process is connected to the probe point 1 and the probe point 2 for analyzing and processing the monitoring data.
  • the WAP service ordering process using the monitoring method provided by the embodiment of the present invention is as shown in FIG. 3, and the specific implementation manner is as follows:
  • the GGSN receives and forwards the online request message initiated by the requesting terminal, Accounting-Request Start;
  • the WAP gateway After receiving the online request message, the WAP gateway responds to the requesting terminal with the online response message Accounting-Response through the GGSN.
  • the GGSN receives and forwards the service request message initiated by the requesting terminal.
  • the network address is a URL address of the WAP service to be subscribed.
  • the WAP gateway After receiving the service request message, the WAP gateway forwards the user's pre-transmission information to the service request message, and as an example, but not limited thereto, the user pre-transmission information may be added through the X-Up-Calling-Line-ID field.
  • the preamble information may be the mobile phone number of the requesting terminal);
  • the device that monitors the WAP service ordering process searches for the cache information in S303 according to the mobile phone number obtained by the probe point 2, and if the same mobile phone number is found, the device finds the same If the IP address corresponding to the mobile phone number is executed, S311 is performed; otherwise, the service request message is considered as an illegal message, and the alarm information is sent to the system;
  • the device that monitors the WAP service ordering process searches for the URL address of the WAP service to be subscribed according to the IP address according to the information cached by the S307. If the URL address of the WAP service to be subscribed is found, the process proceeds to S312. Otherwise, the device considers The service request message is an illegal message, and sends an alarm message to the system.
  • the device that monitors the WAP service ordering process determines whether the URL address in the cached message found by S311 is the same as the URL address obtained by the probe point 2. If the same, the service request message is considered as a legal message. The service request message is an illegal message, and sends an alarm message to the system.
  • the GGSN receives and forwards the offline request message initiated by the requesting terminal, Accounting-Request Stop;
  • the WAP gateway After receiving the offline request message, the WAP gateway responds to the requesting terminal with the offline response message Accounting-Response through the GGSN.
  • the foregoing alarm information may include information about the WAP service to be subscribed to and/or information of the requesting terminal, so that the system retains the information of the illegal service, facilitates forensics, or actively monitors the illegal service.
  • the device that monitors the WAP service subscription process sends an alarm message, it can notify the WAP gateway. This WAP service order is terminated.
  • the information of the requesting terminal is obtained by acquiring and parsing the Radius message (for example, the online request message, the offline request message, etc.) at the probe point 1, and acquiring and parsing the HTTP message and the WSP at the probe point 1.
  • the message (such as a service request message), obtains the information of the WAP service to be subscribed, and the information of the requesting terminal, and compares the information obtained by the two detection points to determine whether the service request message of the WAP gateway exit is a legitimate service request sent by the requesting terminal. , effectively improve the security of the WAP service ordering process, and avoid the economic loss of users and operators.
  • the device that monitors the WAP service subscription process can set the identity information of the target WAP service, and only monitors the target WAP service.
  • the device that monitors the WAP service subscription process saves the IP address of the service (for example: 218. 200.169.*).
  • S309 in the first embodiment of the application of the present invention acquires the URL address of the WAP service to be subscribed and the mobile phone number of the requesting terminal.
  • the application embodiment 2 provided by the present invention still takes the network architecture shown in FIG. 2 as an example, and the processing procedure thereof is shown in FIG. 4, and the specific implementation manner is as follows:
  • the GGSN receives and forwards the online request message initiated by the requesting terminal, Accounting-Request Start;
  • the WAP gateway After receiving the online request message, the WAP gateway responds to the requesting terminal with the online response message Accounting-Response through the GGSN.
  • the GGSN receives and forwards the service request message initiated by the requesting terminal.
  • the network address is a URL address of the WAP service to be subscribed.
  • the WAP gateway After receiving the service request message, the WAP gateway adds the user pre-transmission information to the service request message and forwards the information, as an example and not a limitation, and adds the user pre-transmission information through the X-Up-Calling-Line-ID field.
  • the preamble information may be the mobile phone number of the requesting terminal);
  • the device for monitoring the WAP service ordering process searches for the cache information in S407 according to the mobile phone number obtained by the probe point 2, and if the same mobile phone number is found, the device finds the same If the URL address corresponding to the mobile phone number is S411, the service request message is considered as an illegal message, and the alarm information is sent to the system;
  • the device that monitors the WAP service ordering process determines whether the URL address in the cached message found by S410 is the same as the URL address obtained by the probe point 2, and if the same, the service request message is considered to be a legitimate message.
  • the service request message is an illegal message, and sends an alarm message to the system.
  • the GGSN receives and forwards the offline request message initiated by the requesting terminal, Accounting-Request Stop;
  • the WAP gateway After receiving the offline request message, the WAP gateway responds to the requesting terminal with the offline response message Accounting-Response through the GGSN.
  • the application embodiment 2 of the present invention further simplifies the monitoring and analysis process and improves the monitoring efficiency.
  • the foregoing program may be stored in a computer readable storage medium, and when executed, the program includes the steps of the foregoing method embodiments;
  • the foregoing storage medium includes: a medium that can store program codes, such as a ROM, a RAM, a magnetic disk, or an optical disk.
  • the embodiment of the present invention further provides an apparatus for monitoring a WAP service ordering process, and the structure thereof is as shown in FIG. 5, and the specific implementation structure includes:
  • the first monitoring module 501 is disposed at an exit of the access network gateway, and is configured to obtain information about the service to be subscribed and corresponding request terminal information;
  • the cache module 502 is configured to cache information acquired by the first monitoring module 501.
  • the second monitoring module 503 is configured to be configured to obtain information about the service to be subscribed and corresponding request terminal information, where the wireless application protocol WAP gateway is connected to the access network gateway.
  • the service judging module 504 is configured to determine whether the information cached by the second monitoring module 503 and the corresponding request terminal information are included in the information cached by the caching module 502;
  • the service processing module 505 is configured to: when the judgment result of the service judging module 504 is yes (that is, the cached information includes the information of the to-be-ordered service acquired by the WAP gateway egress, and includes the corresponding requesting terminal information), the WAP service subscription process is continued. If the judgment result of the service judging module is no (that is, the cached information does not include at least one of the following: the information of the to-be-ordered service acquired by the WAP gateway egress, and the corresponding requesting terminal information), an alarm message is sent.
  • the device provided by the embodiment of the present invention compares the information obtained by the WAP gateway exit with the information obtained by the access gateway gateway to determine whether the WAP service subscription is legal, thereby effectively preventing the illegal subscription of the WAP service.
  • the second monitoring module 503 is specifically configured to obtain a service request message of the requesting terminal, and obtain information about the to-be-ordered service and the corresponding requesting terminal information by parsing the service request message, where the information of the to-be-ordered service includes the network to be subscribed to the service. Address, the request terminal information includes identification information of the requesting terminal.
  • the first monitoring module 501 operates in two ways according to different information acquired by the first monitoring module 501.
  • the first monitoring module 501 is configured to obtain an online request message of the requesting terminal, and parse the The online message acquires the request terminal information carried in the request terminal, and the request terminal information includes the IP address of the requesting terminal and the identifier information of the requesting terminal.
  • the first monitoring module 501 is further configured to obtain the service request message of the requesting terminal, by parsing the The service request message obtains information about the service to be subscribed, and the information of the service to be subscribed includes the network address of the service to be subscribed.
  • the cache module 502 is configured to cache the IP address of the requesting terminal, the identifier information of the requesting terminal, and the correspondence between the IP address of the requesting terminal and the identification information of the requesting terminal, and cache the IP address of the requesting terminal.
  • the second monitoring module 503 is specifically configured to obtain a service request message for the WAP service to be monitored according to the preset identifier information of the WAP service to be monitored.
  • the network address of the service to be subscribed and the identification information of the requesting terminal carried in the network.
  • the first monitoring module 501 is further configured to acquire the offline request message of the requesting terminal, and obtain an IP address of the requesting terminal and the requesting terminal that are carried in the offline request message.
  • the cache module 502 is further configured to delete the IP address of the corresponding requesting terminal and the identification information of the requesting terminal, and the IP address of the requesting terminal according to the IP address of the requesting terminal and the identification information of the requesting terminal. Corresponding relationship with the identification information of the requesting terminal, and deleting the correspondence between the IP address of the corresponding requesting terminal and the network address of the service to be subscribed, and the network address of the service to be subscribed.
  • the service determining module 504 is specifically configured to determine whether the cached information includes the identifier information of the requesting terminal that is obtained from the WAP gateway egress; if yes, determine whether the cached information includes the identifier information and the IP address of the requesting terminal.
  • Corresponding relationship and corresponding IP address if yes, determining whether the cached information includes a correspondence between the IP address of the requesting terminal and a network address of the service to be subscribed and a corresponding network address; if yes, determining Whether the cached network address is related to The network address of the to-be-ordered service obtained from the WAP gateway exit is the same; the service processing module 505 is specifically configured to continue the WAP service ordering process when the determination result of the service determining module 504 is yes, otherwise, the alarm information is sent.
  • the first monitoring module 501 is configured to obtain an online request message of the requesting terminal, and obtain the request terminal information carried in the request by parsing the online message, where the requesting terminal information includes the identification information of the requesting terminal; Obtaining the service request message of the requesting terminal, and obtaining the information of the to-be-ordered service carried in the service request message by parsing the service request message, where the information of the to-be-ordered service includes a network address of the service to be subscribed.
  • the cache module 402 is configured to cache the identifier information of the requesting terminal, and also cache the correspondence between the identifier information of the requesting terminal and the network address of the service to be subscribed, and the network address of the service to be subscribed.
  • the second monitoring module 503 is specifically configured to obtain a service request message for the WAP service to be monitored according to the preset identifier information of the WAP service to be monitored.
  • the first monitoring module 501 is further configured to obtain the offline request message of the requesting terminal, and obtain the identifier information of the requesting terminal that is carried in the offline request message; the cache module 502 further And deleting the identifier information of the corresponding requesting terminal according to the identifier information of the requesting terminal, and deleting the correspondence between the identifier information of the corresponding requesting terminal and the network address of the service to be subscribed, and the network address of the service to be subscribed.
  • the service determining module 504 is specifically configured to determine whether the cached information includes the identifier information of the requesting terminal that is obtained from the WAP gateway egress; if yes, determine whether the cached information includes the identifier information of the requesting terminal and the to-be-ordered Corresponding relationship between the network addresses of the service and the corresponding network address; if yes, determining whether the cached network address is related to the to-be-ordered service acquired from the WAP gateway exit
  • the service processing module 505 is specifically configured to continue the WAP service subscription process when the determination result of the service determination module 504 is yes, otherwise, issue an alarm message.
  • the service judging module 504, the service processing module 505, and the caching module 502 may be disposed on the WAP gateway, or may be configured as a separate monitoring device in the network architecture as shown in FIG. 2.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Mobile Radio Communication Systems (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Description

一种对 WAP业务订购过程进行监控的方法及装置 本申请要求于 2010年 5月 28日提交中国专利局、 申请号为 CN 201010193907.6、 发明名称为"一种对 WAP业务订购过程进行监控的 方法及装置"的中国专利申请的优先权, 其全部内容通过引用结合在本申请 中。 技术领域
本发明实施例涉及无线通信技术领域,尤其涉及一种对 WAP业务订购过 程进行监控的方法及装置。 背景技术
随着 WAP ( Wireless Application Protocol, 无线应用协议)业务的迅猛 发展, 对针对 WAP业务的攻击也日趋频繁。 在 WAP系统中植入非法程序是 常见的 WAP业务攻击手段, 这种攻击方式具体是通过在 WAP系统中植入非 法程序, 并由非法程序构造业务订购请求消息(该非法的业务订购请求消息 中携带他人的手机号码) 向业务处理系统发送, 然后对订购消息进行二次 确认实现非法业务订购, 从中非法牟利。
发明人在实现本发明的过程中, 发现现有技术中至少存在如下问题: 现有的 WAP业务订购流程缺乏有效的安全保护机制, WAP系统中被植 入了非法程序后, 系统无法识别非法消息,使得 WAP业务被非法订购或免费 使用, 从而导致合法用户或运营商的经济损失。 发明内容
本发明的实施例提供了一种对 WAP业务订购过程进行监控的方法及装 置, 从而有效提高 WAP业务订购流程的安全性。
本发明的第一方面, 提供了一种对 WAP业务订购过程进行监控的方法, 包括:
緩存从接入网网关出口获取的待订购业务的信息和对应的请求终端信 自 ·
从与所述接入网网关通信的无线应用协议 WAP网关出口获取待订购的 业务的信息和对应的请求终端信息;
判断所述緩存的从接入网网关出口获取的待订购业务的信息和对应的 请求终端信息中,是否包括所述从 WAP网关出口获取的待订购业务的信息和 对应的请求终端信息;
如果判断结果为是, 则继续 WAP业务订购流程;
如果判断结果为否, 则发出告警信息。
本发明的第二方面, 提供了一种对 WAP业务订购过程进行监控的装置, 包括:
第一监测模块, 设置于接入网网关出口处, 用于获取待订购业务的信息 和对应的请求终端信息;
緩存模块, 用于緩存所述第一监测模块获取的信息;
第二监测模块,设置于与所述接入网网关通信的无线应用协议 WAP网关 出口处, 用于获取待订购业务的信息和对应的请求终端信息; 业务判断模块, 用于判断所述緩存模块緩存的信息中是否包括所述第二 监测模块获取的待订购业务的信息和对应的请求终端信息;
业务处理模块,用于当所述业务判断模块的判断结果为是,则继续 WAP 业务订购流程, 如果所述业务判断模块的判断结果为否, 则发出告警信息。
由上述本发明的实施例提供的技术方案可以看出, 本发明实施例中, 由 于通过将 WAP网关出口获得的信息与接入网网关出口获得的信息进行比较, 来判断 WAP业务订购是否合法, 从而有效阻止在 WAP网关中植入非法程序 订购 WAP业务的行为, 避免合法用户或运营商的经济损失。 附图说明
为了更清楚地说明本发明实施例的技术方案, 下面将对实施例描述中所 需要使用的附图作一简单地介绍, 显而易见地, 下面描述中的附图仅仅是本 发明的一些实施例, 对于本领域普通技术人员来讲, 在不付出创造性劳动性 的前提下, 还可以根据这些附图获得其他的附图。
图 1为本发明实施例提供的方法流程图;
图 2为本发明实施例提供的系统结构示意图;
图 3为本发明实施例一的信令流程图;
图 4为本发明实施例二的信令流程图;
图 5为本发明实施例提供的装置结构示意图。 具体实施方式
下面将结合本发明实施例中的附图,对本发明实施例中的技术方案进行 清楚、 完整地描述, 显然, 所描述的实施例仅仅是本发明一部分实施例, 而 不是全部的实施例。 基于本发明中的实施例, 本领域普通技术人员在没有作 出创造性劳动前提下所获得的所有其他实施例, 都属于本发明保护的范围。
为了提高 WAP业务订购过程的安全性, 本发明实施例提供了一种对 WAP业务订购过程进行监控的方法, 该方法流程如图 1所示, 具体实现方式 如下:
5101、 緩存从接入网网关出口获取的待订购业务的信息和对应的请求 终端信息;
5102、 从与上述接入网网关通信的 WAP网关出口获取待订购的业务的 信息和对应的请求终端信息;
5103、 判断上述緩存的从接入网网关出口获取的待订购业务的信息和 对应的请求终端信息中,是否包括上述从 WAP网关出口获取的待订购业务的 信息和对应的请求终端信息;
如果判断结果为是(即緩存的信息中包括 WAP网关出口获取的待订购业 务的信息, 且包括对应的请求终端信息) , 则执行 S104、 继续 WAP业务订 购流程;
如果判断结果为否(即緩存的信息中至少没有包括以下一个: WAP网关 出口获取的待订购业务的信息、 对应的请求终端信息) , 则执行 S105、 发 出告警信息。
本发明实施例中, WAP网关的出口方向是指 WAP网关向核心网 /业务网 发送数据的方向;接入网网关的出口方向是指接入网网关向 WAP网关发送数 据的方向。 本发明实施例中,接入网网关是指转发请求终端与 WAP网关之间通信数 据的网关。
本发明实施例提供的方法,通过将 WAP网关出口获得的信息与接入网网 关出口获得的信息进行比较,如果是由植入 WAP网关的非法程序发送的非法 业务请求, 则该业务请求信息无法在从接入网网关出口处获取的緩存信息中 查找到, 从而可以判断 WAP业务订购是否合法, 有效阻止非法订购 WAP业 务的行为。
本发明实施例提供的方法, 具体是在 WAP网关的出口处以及与该 WAP 网关通信的接入网网关的出口处分别设置探测点, 并通过对探测点获取的信 息进行解析实现的 WAP业务订购过程的监测。 根据探测点获取信息的不同, 本发明实施例提供两种信息获取的实现方式:
方式一
上述 S102具体实现方式包括: WAP网关出口处设置的探测点获取请求 终端的业务请求消息, 通过解析该业务请求消息获取其中的待订购业务的信 息和对应的请求终端信息, 该待订购业务的信息包括待订购业务的网络地址 (本发明实施例中,该地址可以是 IP地址,也可以是 URL( Uniform Resource Location, 统一资源定位符)地址) , 该请求终端信息包括上述请求终端的 标识信息(本发明实施例中,该标识信息可以是该请求终端的手机号码、 IMSI ( International Mobile Subscriber Identity, 国际移动用户识另' J码 )或用户伪 码等) 。 上述 S101的具体实现方式包括: 上述接入网网关出口设置的探测 点获取请求终端的上线请求消息, 通过解析该上线请求消息获取并緩存其中 携带的请求终端信息, 该请求终端信息包括上述请求终端的 IP地址和该请求 终端的标识信息 , 还緩存该请求终端的 I P地址与该请求终端的标识信息之间 的对应关系; 上述接入网网关出口设置的探测点还获取上述请求终端的业务 请求消息, 通过解析该业务请求消息获取并緩存其中携带的待订购业务的信 息, 该待订购业务的信息包括该待订购业务的网络地址, 还緩存该请求终端 的 IP地址与该待订购业务的网络地址之间的对应关系。 本发明实施例中, 为 了提高监控效率, 可以只对设定的目标 WAP业务进行监控, 则 S102中, 具 体可以根据预先设置的待监控 WAP业务的标识信息 (该标识信息可以是 WAP业务的 IP地址, 或者 WAP业务的 URL地址等等) , 获取针对该待监控 WAP业务的业务请求消息中携带的待订购业务的网络地址和该请求终端的 标识信息。
另外, 进行判断之后, 本发明实施例还包括 S106a: 接入网网关出口设 置的探测点获取上述请求终端的下线请求消息, 解析该下线请求消息并获取 其中携带的该请求终端的 I P地址和该请求终端的标识信息; 根据该请求终端 的 I P地址和该请求终端的标识信息, 删除緩存中相应的请求终端的 I P地址和 请求终端的标识信息, 及该请求终端的 I P地址和请求终端的标识信息的对应 关系, 并删除緩存中相应的请求终端的 IP地址和待订购业务的网络地址的对 应关系, 及该待订购业务的网络地址。相应的, 上述对 WAP业务订购过程进 行监控的具体实现方式如下:
S 1031 a、 判断緩存的信息中是否包括从 WAP网关出口获取的请求终端 的标识信息;
如果 S1031 a的判断结果为是, 执行 S1032a、 判断緩存的信息中是否包 括该请求终端的标识信息与请求终端的 IP地址之间的对应关系及相应的 IP 地址; 如果 S1031 a的判断结果为不是, 则执行上述 S105;
如果 S1032a的判断结果为是, 则执行 S1033a、 判断緩存的信息中是否 包含上述请求终端的 IP地址与待订购业务的网络地址之间的对应关系及相 应的网络地址; 如果 S1032a的判断结果为不是, 则执行上述 S105;
如果 S1033a的判断结果为是, 则执行 S1034a、 判断上述緩存的网络地 址是否与上述从 WAP网关出口获取的待订购业务的网络地址相同, 如果相 同, 则认为本次订购业务为合法业务, 执行上述 S104; 否则为非法业务, 执行上述 S105。
方式二
上述 S102的具体实现方式包括: WAP网关出口处设置的探测点获取请 求终端的业务请求消息, 通过解析该业务请求消息获取其中的待订购业务的 信息和对应的请求终端信息, 该待订购业务的信息包括待订购业务的网络地 址, 该请求终端信息包括上述请求终端的标识信息。 上述 S101具体实现方 式包括: 上述接入网网关出口设置的探测点获取请求终端的上线请求消息, 通过解析该上线请求消息获取并緩存其中携带的请求终端信息, 该请求终端 信息包括上述请求终端的标识信息; 上述接入网网关出口设置的探测点还获 取上述请求终端的业务请求消息, 通过解析该业务请求消息获取并緩存其中 携带的待订购业务的信息, 该待订购业务的信息包括该待订购业务的网络地 址,还緩存该请求终端的标识信息与该待订购业务的网络地址之间的对应关 系。 本发明实施例中, 为了提高监控效率, 可以只对设定的目标 WAP业务进 行监控, 则 S102中, 具体可以根据预先设置的待监控 WAP业务的标识信息, 获取针对该待监控 WAP业务的业务请求消息中携带的待订购业务的网络地 址和该请求终端的标识信息。 另外, 进行判断之后, 本发明实施例还包括
S106b: 接入网网关出口设置的探测点获取上述请求终端的下线请求消息, 解析该下线请求消息并获取其中携带的该请求终端的标识信息; 根据该请求 终端的标识信息, 删除緩存中相应的请求终端的标识信息, 并删除緩存中相 应的请求终端的标识信息和待订购业务的网络地址的对应关系, 及该待订购 业务的网络地址。相应的,上述对 WAP业务订购过程进行监控的具体实现方 式如下:
S 1031 b、 判断緩存的信息中是否包括从 WAP网关出口获取的请求终端 的标识信息;
如果 S1031 b的判断结果为是, 执行 S1032b、 判断緩存的信息中是否包 含上述请求终端的标识信息与待订购业务的网络地址之间的对应关系及相 应的网络地址; 如果 S1032b的判断结果为不是, 则执行上述 S105;
如果 S1032b的判断结果为是, 则执行 S1033b、 判断上述緩存的网络地 址是否与上述从 WAP网关出口获取的待订购业务的网络地址相同, 如果相 同, 则认为本次订购业务为合法业务, 执行上述 S104; 否则为非法业务, 执行上述 S105。 说明。
在如图 2所示的网络架构中, GGSN ( Gateway GPRS Support Node, 网关 GPRS支持节点, GPRS General Packet Radio Service, 通用分组无 线技术)作为接入网网关, 负责传输终端与无线网络之间的通信消息。 WAP 网关负责传输 GGSN与 WAP业务服务器之间的通信消息。 Portal (—种网 页应用技术)服务器、 AS ( Application Server, 应用服务器) 以及 SP/CP ( Service Provider/Content Provider, 服务提供商 /内容提供商)用于为终 端提供网络业务服务。 在 GGSN出口处设置探测点 1 , 应当指出的是, 虽然 图 2所示的网络架构示意图仅给出了一个 GGSN ,但实际应用过程中,可以 有多个 GGSN与同一个 WAP网关通信, 相应的, 在每个 GGSN的出口处 设置探测点 1。 在 WAP网关出口处设置探测点 2, 对 WAP业务订购过程进 行监控的装置与探测点 1和探测点 2连接, 用来对监测数据进行分析处理。
实施例一
以图 2所示的网络架构为例,应用本发明实施例提供的监控方法的 WAP 业务订购流程如图 3所示, 具体实现方式如下:
S301 、 GGSN 接收并转发请求终端发起的上线请求消息 Accounting-Request Start;
5302、 通过探测点 1 获取上述上线请求消息并解析获得其中携带的该 请求终端的 IP地址和该移动终端的标识信息, 在本应用实施例中, 该标识 信息是手机号码;
5303、緩存该请求终端的 IP地址和手机号码, 以及 IP地址和手机号码 的对应关系, 作为举例而非限定, 可以表格形式緩存, 具体实现方式如表 1 所示:
表 1
IP地址 手机号码 请求终端 1 211.200.138.0 13811122111 请求终端 2 211.200.131.3 13400011000 211.200.124.0 13633355000
5304、 WAP网关接收到上述上线请求消息后,通过上述 GGSN向请求 终端回应上线响应消息 Accounting-Response;
5305、 GGSN接收并转发上述请求终端发起的业务请求消息;
5306、通过探测点 1获取上述 WAP业务请求消息并解析获得其中携带 的待订购 WAP业务的网络地址, 在本应用实施例中, 该网络地址为待订购 WAP业务的 URL地址;
5307、緩存上述待订购 WAP业务的 URL地址,及该待订购 WAP业务 的 URL地址与 S302获取的请求终端的 IP地址的对应关系, 作为举例而非 限定, 可以表格形式緩存, 具体实现方式如表 2所示:
表 2
Figure imgf000012_0001
5308、 WAP网关接收到上述业务请求消息后, 将用户前传信息添加到 该业务请求消息后转发, 作为举例而非限定, 可通过 X-Up-Calling-Line-ID 字段添加用户前传信息 (该用户前传信息可以是请求终端的手机号码);
5309、 通过探测点 2获取上述添加了用户前传信息的业务请求消息并 解析获得待订购 WAP业务的 URL地址和请求终端的手机号码;
5310、对 WAP业务订购过程进行监控的装置根据探测点 2获取的手机 号码, 查找 S303中的緩存信息, 如果查找到相同的手机号码, 并查找到该 手机号码对应的 IP地址, 则执行 S311 , 否则, 认为上述业务请求消息为非 法消息, 向系统发送告警信息;
S311、 对 WAP业务订购过程进行监控的装置根据 S307緩存的信息, 查找上述 IP地址对应的待订购 WAP业务的 URL地址, 如果找到对应的待 订购 WAP业务的 URL地址, 则执行 S312, 否则, 认为上述业务请求消息 为非法消息, 向系统发送告警信息;
S312、 对 WAP业务订购过程进行监控的装置判断 S311查找到的緩存 消息中的 URL地址与探测点 2获取的 URL地址是否相同, 如果相同, 则认 为上述业务请求消息为合法消息, 如果不同, 认为上述业务请求消息为非法 消息, 向系统发送告警信息;
S313 、 GGSN 接收并转发请求终端发起的下线请求消息 Accounting-Request Stop;
5314、 通过探测点 1 获取上述下线请求消息并解析获得其中携带的请 求终端的 IP地址和手机号码, 根据解析获得的信息删除緩存中对应的信息, 该对应的信息包括请求终端的 IP地址、 该请求终端的手机号码及对应的待 订购 WAP业务的 URL地址, 以及请求终端的 IP地址与手机号码的对应关 系、 请求终端的 IP地址与待订购 WAP业务的 URL地址;
5315、 WAP网关接收到上述下线请求消息后,通过 GGSN向请求终端 回应下线响应消息 Accounting-Response。
上述的告警信息中可以包含待订购 WAP业务的信息和 /或请求终端的信 息, 以便系统保留非法业务的信息, 便于取证或者主动监控非法业务。 对 WAP业务订购过程进行监控的装置发送告警信息后,可以通知 WAP网关中 止本次 WAP业务订购。
上述本发明应用实施例一,通过在探测点 1获取并解析 Radius消息(例 如: 上线请求消息、 下线请求消息等), 获取请求终端的信息, 通过在探测 点 1获取并解析 HTTP消息及 WSP消息等(例如: 业务请求消息), 获取 待订购 WAP业务的信息及请求终端的信息, 并通过比较两个探测点获取的 信息判断 WAP网关出口的业务请求消息是否是请求终端发送的合法业务请 求, 有效提高了 WAP业务订购过程的安全性, 避免了用户和运营商的经济 损失。
在实际应用过程中, 如果对所有的 WAP业务都进行监控, 可能会系统 带宽的负担。 为了兼顾安全性与监控效率, 对 WAP业务订购过程进行监控 的装置可以设置目标 WAP业务的标识信息, 仅对目标 WAP业务进行监控, 作为举例而非限定, 设定彩铃下载为目标 WAP业务, 则对 WAP业务订购 过程进行监控的装置保存该业务的 IP地址(例如: 218。 200.169.* )。 相应 的, 上述本发明应用实施例一中的 S309获取目标待订购 WAP业务的 URL 地址和请求终端的手机号码。
实施例二
本发明提供的应用实施例二仍然以图 2所示的网络架构为例,其处理过 程如图 4所示, 具体实现方式如下:
S401 、 GGSN 接收并转发请求终端发起的上线请求消息 Accounting-Request Start;
S402、 通过探测点 1 获取上述上线请求消息并解析获得其中携带的该 请求终端的手机号码; 5403、 緩存该请求终端的手机号码;
5404、 WAP网关接收到上述上线请求消息后,通过上述 GGSN向请求 终端回应上线响应消息 Accounting-Response;
5405、 GGSN接收并转发上述请求终端发起的业务请求消息;
5406、通过探测点 1获取上述 WAP业务请求消息并解析获得其中携带 的待订购 WAP业务的网络地址, 在本应用实施例中, 该网络地址为待订购 WAP业务的 URL地址;
5407、緩存上述待订购 WAP业务的 URL地址,及该待订购 WAP业务 的 URL地址与 S402获取的请求终端的手机号码的对应关系, 作为举例而 非限定, 可以表格形式緩存, 具体实现方式如表 3所示:
表 3
Figure imgf000015_0001
S408、 WAP网关接收到上述业务请求消息后, 将用户前传信息添加到 该业务请求消息后转发, 作为举例而非限定, 可通过 X-Up-Calling-Line-ID 字段添加用户前传信息 (该用户前传信息可以是请求终端的手机号码);
5409、 通过探测点 2获取上述添加了用户前传信息的业务请求消息并 解析获得待订购 WAP业务的 URL地址和请求终端的手机号码;
5410、对 WAP业务订购过程进行监控的装置根据探测点 2获取的手机 号码, 查找 S407中的緩存信息, 如果查找到相同的手机号码, 并查找到该 手机号码对应的 URL地址, 则执行 S411 , 否则, 认为上述业务请求消息为 非法消息, 向系统发送告警信息;
5411、 对 WAP业务订购过程进行监控的装置判断 S410查找到的緩存 消息中的 URL地址与探测点 2获取的 URL地址是否相同, 如果相同, 则认 为上述业务请求消息为合法消息, 如果不同, 认为上述业务请求消息为非法 消息, 向系统发送告警信息;
5412 、 GGSN 接收并转发请求终端发起的下线请求消息 Accounting-Request Stop;
5413、 通过探测点 1 获取上述下线请求消息并解析获得其中携带的请 求终端的手机号码, 根据解析获得的信息删除緩存中对应的信息, 该对应的 信息包括请求终端的手机号码及对应的待订购 WAP业务的 URL地址,以及 请求终端的标识信息与待订购 WAP业务的 URL地址;
5414、 WAP网关接收到上述下线请求消息后,通过 GGSN向请求终端 回应下线响应消息 Accounting-Response。
可见, 本发明应用实施例二进一步简化了监控分析过程, 提高了监控效 率。
实现上述方法实施例的全部或部分步骤可以通过程序指令相关的硬件 来完成, 前述的程序可以存储于一计算机可读取存储介质中, 该程序在执行 时,执行包括上述方法实施例的步骤;而前述的存储介质包括: ROM、 RAM, 磁碟或者光盘等各种可以存储程序代码的介质。
本发明实施例还提供了一种对 WAP业务订购过程进行监控的装置,其结 构如图 5所示, 具体实现结构包括: 第一监测模块 501 , 设置于接入网网关出口处, 用于获取待订购业务的 信息和对应的请求终端信息;
緩存模块 502, 用于緩存第一监测模块 501获取的信息;
第二监测模块 503, 设置于与上述接入网网关通信的无线应用协议 WAP 网关出口处, 用于获取待订购业务的信息和对应的请求终端信息;
业务判断模块 504, 用于判断緩存模块 502緩存的信息中是否包括第二 监测模块 503获取的待订购业务的信息和对应的请求终端信息;
业务处理模块 505, 用于当业务判断模块 504的判断结果为是(即緩存 的信息中包括 WAP网关出口获取的待订购业务的信息,且包括对应的请求终 端信息)时, 继续 WAP业务订购流程, 如果所述业务判断模块的判断结果为 否(即緩存的信息中至少没有包括以下一个: WAP网关出口获取的待订购业 务的信息、 对应的请求终端信息) 时, 发出告警信息。
本发明实施例提供的装置,通过将 WAP网关出口获得的信息与接入网网 关出口获得的信息进行比较,来判断 WAP业务订购是否合法,从而有效阻止 非法订购 WAP业务的行为。
上述第二监测模块 503具体用于获取请求终端的业务请求消息, 通过解 析该业务请求消息获取其中的待订购业务的信息和对应的请求终端信息, 该 待订购业务的信息包括待订购业务的网络地址, 该请求终端信息包括所述请 求终端的标识信息。
本发明实施例中, 根据第一监测模块 501获取信息的不同, 该第一监测 模块 501的工作方式有二。
其一, 第一监测模块 501用于获取请求终端的上线请求消息, 通过解析 该上线消息获取其中携带的请求终端信息, 该请求终端信息包括上述请求终 端的 IP地址和上述请求终端的标识信息; 第一监测模块 501还用于获取该请 求终端的业务请求消息, 通过解析该业务请求消息获取其中携带的待订购业 务的信息, 该待订购业务的信息包括待订购业务的网络地址。 相应的, 緩存 模块 502具体用于緩存上述请求终端的 IP地址、 该请求终端的标识信息和该 请求终端的 I P地址与请求终端的标识信息之间的对应关系, 还緩存该请求终 端的 IP地址与待订购业务的网络地址之间的对应关系, 以及该待订购业务的 网络地址。 为了提高监控效率, 可以只对设定的目标 WAP业务进行监控, 则 第二监测模块 503具体用于根据预先设置的待监控 WAP业务的标识信息, 获 取针对所述待监控 WAP业务的业务请求消息中携带的所述待订购业务的网 络地址和所述请求终端的标识信息。 当业务判断模块 504进行判断后, 第一 监测模块 501还用于获取所述请求终端的下线请求消息, 获取所述下线请求 消息中携带的所述请求终端的 I P地址和所述请求终端的标识信息; 緩存模块 502还用于根据所述请求终端的 IP地址和所述请求终端的标识信息, 删除相 应的请求终端的 I P地址和请求终端的标识信息, 及所述请求终端的 I P地址和 请求终端的标识信息的对应关系, 并删除相应的请求终端的 IP地址和待订购 业务的网络地址的对应关系, 及所述待订购业务的网络地址。 相应的, 上述 业务判断模块 504具体用于判断緩存的信息中是否包括从 WAP网关出口获 取的请求终端的标识信息; 如果是, 判断緩存的信息中是否包括所述标识信 息与请求终端的 IP地址之间的对应关系及相应的 IP地址; 如果是, 判断緩存 的信息中是否包含所述请求终端的 IP地址与待订购业务的网络地址之间的 对应关系及相应的网络地址; 如果是, 判断所述緩存的网络地址是否与所述 从 WAP网关出口获取的待订购业务的网络地址相同; 业务处理模块 505具体 用于当所述业务判断模块 504的判断结果均为是时, 继续 WAP业务订购流 程, 否则, 发出告警信息。
其二, 第一监测模块 501用于获取请求终端的上线请求消息, 通过解析 该上线消息获取其中携带的上述请求终端信息, 该请求终端信息包括请求终 端的标识信息; 第一监测模块 501还用于获取该请求终端的业务请求消息, 通过解析该业务请求消息获取其中携带的待订购业务的信息, 该待订购业务 的信息包括待订购业务的网络地址。 相应的, 緩存模块 402具体用于緩存上 述请求终端的标识信息,还緩存该请求终端的标识信息与待订购业务的网络 地址之间的对应关系, 以及该待订购业务的网络地址。 为了提高监控效率, 可以只对设定的目标 WAP业务进行监控, 则第二监测模块 503具体用于根据 预先设置的待监控 WAP业务的标识信息, 获取针对所述待监控 WAP业务的 业务请求消息中携带的所述待订购业务的网络地址和所述请求终端的标识 信息。 当业务判断模块 504进行判断后, 第一监测模块 501还用于获取所述 请求终端的下线请求消息, 获取所述下线请求消息中携带的所述请求终端的 标识信息; 緩存模块 502还用于根据所述请求终端的标识信息, 删除相应的 请求终端的标识信息, 并删除相应的请求终端的标识信息和待订购业务的网 络地址的对应关系, 及所述待订购业务的网络地址。 相应的, 上述业务判断 模块 504具体用于判断緩存的信息中是否包括从 WAP网关出口获取的请求 终端的标识信息; 如果是, 判断緩存的信息中是否包含所述请求终端的标识 信息与待订购业务的网络地址之间的对应关系及相应的网络地址; 如果是, 判断所述緩存的网络地址是否与所述从 WAP网关出口获取的待订购业务的 网络地址相同; 业务处理模块 505具体用于当所述业务判断模块 504的判断 结果均为是时, 继续 WAP业务订购流程, 否则, 发出告警信息。
本发明实施例提供的装置中, 业务判断模块 504、 业务处理模块 505及 緩存模块 502可以设置在 WAP网关上, 也可以在如图 2所示的网络架构中, 作为单独的监控装置设置。
以上所述, 仅为本发明较佳的具体实施方式, 但本发明的保护范围并不 局限于此, 任何熟悉本技术领域的技术人员在本发明揭露的技术范围内, 可 轻易想到的变化或替换, 都应涵盖在本发明的保护范围之内。 因此, 本发明 的保护范围应该以权利要求的保护范围为准。

Claims

权 利 要 求 书
1、 一种对 WAP业务订购过程进行监控的方法, 其特征在于, 包括: 緩存从接入网网关出口获取的待订购业务的信息和对应的请求终端信 自 ·
从与所述接入网网关通信的无线应用协议 WAP网关出口获取待订购的 业务的信息和对应的请求终端信息;
判断所述緩存的从接入网网关出口获取的待订购业务的信息和对应的 请求终端信息中,是否包括所述从 WAP网关出口获取的待订购业务的信息和 对应的请求终端信息;
如果判断结果为是, 则继续 WAP业务订购流程;
如果判断结果为否, 则发出告警信息。
2、 根据权利要求 1所述的方法, 其特征在于, 从与所述 WAP网关出口 获取待订购的业务的信息和对应的请求终端信息包括:
在所述 WAP网关出口获取请求终端的业务请求消息,获取所述业务请求 消息中的待订购业务的信息和对应的请求终端信息, 所述待订购业务的信息 包括待订购业务的网络地址, 所述请求终端信息包括所述请求终端的标识信 自
3、 根据权利要求 2所述的方法, 其特征在于, 緩存从接入网网关出口获 取的待订购业务的信息和对应的请求终端信息包括:
在所述接入网网关出口获取请求终端的上线请求消息, 获取并緩存所述 上线消息中携带的请求终端信息 , 所述请求终端信息包括所述请求终端的 IP 地址和所述请求终端的标识信息, 还緩存所述请求终端的 IP地址与所述请求 终端的标识信息之间的对应关系;
在所述接入网网关出口获取所述请求终端的业务请求消息, 获取并緩存 所述业务请求消息中携带的待订购业务的信息, 所述待订购业务的信息包括 所述待订购业务的网络地址, 还緩存所述请求终端的 I P地址与所述待订购业 务的网络地址之间的对应关系。
4、 根据权利要求 3所述的方法, 其特征在于, 判断緩存的信息中是否包 括从 WAP网关出口获取的待订购业务的信息和对应的请求终端信息包括: 判断緩存的信息中是否包括从 WAP网关出口获取的请求终端的标识信 自 ·
如果是, 判断緩存的信息中是否包括所述标识信息与请求终端的 IP地址 之间的对应关系及相应的 IP地址;
如果是, 判断緩存的信息中是否包含所述请求终端的 IP地址与待订购业 务的网络地址之间的对应关系及相应的网络地址;
如果是,判断所述緩存的网络地址是否与所述从 WAP网关出口获取的待 订购业务的网络地址相同。
5、 根据权利要求 2所述的方法, 其特征在于, 緩存从接入网网关出口获 取的待订购业务的信息和对应的请求终端信息包括:
在所述接入网网关出口获取请求终端的上线请求消息, 获取并緩存所述 上线消息中携带的请求终端信息, 所述请求终端信息包括请求终端的标识信 息;
在所述接入网网关出口获取所述请求终端的业务请求消息, 获取并緩存 所述业务请求消息中携带的待订购业务的信息, 所述待订购业务的信息包括 待订购业务的网络地址,还緩存所述请求终端的标识信息与所述待订购业务 的网络地址之间的对应关系。
6、 根据权利要求 5所述的方法, 其特征在于, 判断緩存的信息中是否包 括从 WAP网关出口获取的待订购业务的信息和对应的请求终端信息包括: 判断緩存的信息中是否包括从 WAP网关出口获取的请求终端的标识信 自 ·
如果是, 判断緩存的信息中是否包括所述请求终端的标识信息与待订购 业务的网络地址之间的对应关系及相应的网络地址;
如果是,判断所述緩存的网络地址是否与所述从 WAP网关出口获取的待 订购业务的网络地址相同。
7、 根据权利要求 1 ~ 6任意一项所述的方法, 其特征在于, 根据预先设 置的待监控 WAP业务的标识信息, 对所述待监控 WAP业务的订购过程进行 监控。
8、 根据权利要求 3 ~ 6任意一项所述的方法, 其特征在于, 进行判断之 后, 该方法还包括:
在所述接入网网关出口获取所述请求终端的下线请求消息, 获取所述下 线请求消息中携带的所述请求终端的标识信息;
根据所述请求终端的标识信息, 删除緩存中相应的信息。
9、 根据权利要求 1 ~ 6任意一项所述的方法, 其特征在于, 所述告警信 息中包括所述待订购业务的信息和 /或对应的请求终端信息。
10、 一种对 WAP业务订购过程进行监控的装置, 其特征在于, 包括: 第一监测模块, 设置于接入网网关出口处, 用于获取待订购业务的信息 和对应的请求终端信息;
緩存模块, 用于緩存所述第一监测模块获取的信息;
第二监测模块,设置于与所述接入网网关通信的无线应用协议 WAP网关 出口处, 用于获取待订购业务的信息和对应的请求终端信息;
业务判断模块, 用于判断所述緩存模块緩存的信息中是否包括所述第二 监测模块获取的待订购业务的信息和对应的请求终端信息;
业务处理模块,用于当所述业务判断模块的判断结果为是,则继续 WAP 业务订购流程, 如果所述业务判断模块的判断结果为否, 则发出告警信息。
1 1、 根据权利要求 10所述的装置, 其特征在于, 所述第二监测模块具体 用于获取请求终端的业务请求消息, 获取所述业务请求消息中的待订购业务 的信息和对应的请求终端信息, 所述待订购业务的信息包括待订购业务的网 络地址, 所述请求终端信息包括所述请求终端的标识信息。
12、 根据权利要求 11所述的装置, 其特征在于, 所述第一监测模块具体 用于获取请求终端的上线请求消息 , 获取所述上线消息中携带的请求终端信 息, 所述请求终端信息包括请求终端的 IP地址和所述请求终端的标识信息; 还用于获取所述请求终端的业务请求消息, 获取所述业务请求消息中携带的 待订购业务的信息, 所述待订购业务的信息包括待订购业务的网络地址; 所 述緩存模块具体用于緩存所述请求终端的 IP地址、 所述请求终端的标识信息 和所述请求终端的 IP地址与所述请求终端的标识信息之间的对应关系, 还緩 存所述请求终端的 IP地址与所述待订购业务的网络地址之间的对应关系, 以 及所述待订购业务的网络地址。
13、 根据权利要求 12所述的装置, 其特征在于, 所述业务判断模块具体 用于判断緩存的信息中是否包括从 WAP网关出口获取的请求终端的标识信 息; 如果是, 判断緩存的信息中是否包括所述标识信息与请求终端的 IP地址 之间的对应关系及相应的 IP地址; 如果是, 判断緩存的信息中是否包含所述 请求终端的 IP地址与待订购业务的网络地址之间的对应关系及相应的网络 地址;如果是,判断所述緩存的网络地址是否与所述从 WAP网关出口获取的 待订购业务的网络地址相同;
所述业务处理模块具体用于当所述业务判断模块的判断结果均为是时, 继续 WAP业务订购流程, 否则, 发出告警信息。
14、 根据权利要求 11所述的装置, 其特征在于, 所述第一监测模块具体 用于获取请求终端的上线请求消息 , 获取所述上线消息中携带的请求终端信 息, 所述请求终端信息包括请求终端的标识信息; 还用于获取所述请求终端 的业务请求消息, 获取所述业务请求消息中携带的待订购业务的信息, 所述 待订购业务的信息包括待订购业务的网络地址; 所述緩存模块具体用于緩存 所述请求终端的标识信息,还緩存所述请求终端的标识信息与所述待订购业 务的网络地址之间的对应关系, 以及所述待订购业务的网络地址。
15、 根据权利要求 14所述的装置, 其特征在于, 所述业务判断模块具体 用于判断緩存的信息中是否包括从 WAP网关出口获取的请求终端的标识信 息; 如果是, 判断緩存的信息中是否包含所述请求终端的标识信息与待订购 业务的网络地址之间的对应关系及相应的网络地址; 如果是, 判断所述緩存 的网络地址是否与所述从 WAP网关出口获取的待订购业务的网络地址相同; 所述业务处理模块具体用于当所述业务判断模块的判断结果均为是时, 继续 WAP业务订购流程, 否则, 发出告警信息。
16、 根据权利要求 10 ~ 15任意一项所述的装置, 其特征在于, 所述装 置具体用于根据预先设置的待监控 WAP业务的标识信息, 对所述待监控 WAP业务的订购过程进行监控。
PCT/CN2011/073746 2010-05-28 2011-05-06 一种对wap业务订购过程进行监控的方法及装置 WO2011147249A1 (zh)

Priority Applications (1)

Application Number Priority Date Filing Date Title
EP11786021.3A EP2579637B1 (en) 2010-05-28 2011-05-06 Method and apparatus for monitoring process of subscribing wap services

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201010193907.6A CN102264073B (zh) 2010-05-28 2010-05-28 一种对wap业务订购过程进行监控的方法及装置
CN201010193907.6 2010-05-28

Publications (1)

Publication Number Publication Date
WO2011147249A1 true WO2011147249A1 (zh) 2011-12-01

Family

ID=45003293

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2011/073746 WO2011147249A1 (zh) 2010-05-28 2011-05-06 一种对wap业务订购过程进行监控的方法及装置

Country Status (3)

Country Link
EP (1) EP2579637B1 (zh)
CN (1) CN102264073B (zh)
WO (1) WO2011147249A1 (zh)

Families Citing this family (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2016177460A (ja) * 2015-03-19 2016-10-06 株式会社リコー システム及びプログラム

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101304434A (zh) * 2008-05-21 2008-11-12 中国联合通信有限公司 防止wap业务非法订购的系统及方法
CN101378551A (zh) * 2008-09-26 2009-03-04 中兴通讯股份有限公司 一种wap业务系统和方法
CN101635895A (zh) * 2009-07-31 2010-01-27 青岛海信移动通信技术股份有限公司 一种网站内容订阅系统、方法、移动通信终端和服务器

Family Cites Families (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7120148B1 (en) * 2002-02-12 2006-10-10 Cisco Technology, Inc. System and method for providing source awareness in a wireless application protocol network environment
US7068999B2 (en) * 2002-08-02 2006-06-27 Symbol Technologies, Inc. System and method for detection of a rogue wireless access point in a wireless communication network
US7620808B2 (en) * 2003-06-19 2009-11-17 Nokia Corporation Security of a communication system
CN1905593A (zh) * 2005-07-26 2007-01-31 中国移动通信集团公司 通信增值业务订购信息的处理方法
CN101137160B (zh) * 2006-09-01 2010-04-21 华为技术有限公司 检测跟踪状态的方法和系统及跟踪代理、跟踪控制服务器
US20080065746A1 (en) * 2006-09-07 2008-03-13 Ace*Comm Corporation Consumer configurable mobile communication web filtering solution

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101304434A (zh) * 2008-05-21 2008-11-12 中国联合通信有限公司 防止wap业务非法订购的系统及方法
CN101378551A (zh) * 2008-09-26 2009-03-04 中兴通讯股份有限公司 一种wap业务系统和方法
CN101635895A (zh) * 2009-07-31 2010-01-27 青岛海信移动通信技术股份有限公司 一种网站内容订阅系统、方法、移动通信终端和服务器

Also Published As

Publication number Publication date
CN102264073B (zh) 2014-04-16
EP2579637A1 (en) 2013-04-10
CN102264073A (zh) 2011-11-30
EP2579637A4 (en) 2013-04-10
EP2579637B1 (en) 2014-04-02

Similar Documents

Publication Publication Date Title
EP3573311B1 (en) Service management method and device thereof
EP3008935B1 (en) Mobile device authentication in heterogeneous communication networks scenario
US9237154B2 (en) Secure and automatic connection to wireless network
US9781137B2 (en) Fake base station detection with core network support
KR101769222B1 (ko) 서비스 불법 액세스를 예방하는 방법 및 장치
AU2020204346B2 (en) Multi-access distributed edge security in mobile networks
US10506440B2 (en) Method and apparatus for detecting tethering in a communications network
EP2456246A1 (en) Network selection method based on multi-link and apparatus thereof
CN105611534B (zh) 无线终端识别伪WiFi网络的方法及其装置
EP2901614A1 (en) Co-activation for authenticating a user's registration
US8274985B2 (en) Control of cellular data access
EP2890170A1 (en) Method and system for barcode and link initiated hotspot auto-login in WLANs
WO2011103835A2 (zh) 用户访问的控制方法、装置及系统
WO2011147249A1 (zh) 一种对wap业务订购过程进行监控的方法及装置
US20020042820A1 (en) Method of establishing access from a terminal to a server
JP2009296494A (ja) 情報通信ネットワーク、ゲートウェイ、課金サーバ、情報通信ネットワークの課金方法、及び課金プログラム
CN106878032B (zh) 一种认证方法和装置
KR101771617B1 (ko) 푸시 서비스 제공 시스템 및 방법
US20100255811A1 (en) Transmission of messages
CN104581658A (zh) 终呼处理方法和装置
CN114945173B (zh) 跨plmn信令转发方法、电子设备及存储介质
CN106792690B (zh) 基于net验证平台的公共wifi登录方法及装置
EP2278834A1 (en) A method for transferring data between a client and a server in a telecommunication network, as well as a system, a server, a client and a node
CN116193421A (zh) 网络连接信息的验证方法、装置、系统及电子设备
CN107241310B (zh) 一种客户端身份验证方法与装置

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 11786021

Country of ref document: EP

Kind code of ref document: A1

WWE Wipo information: entry into national phase

Ref document number: 2011786021

Country of ref document: EP

NENP Non-entry into the national phase

Ref country code: DE