WO2016134608A1 - 伪基站的识别方法和装置 - Google Patents

伪基站的识别方法和装置 Download PDF

Info

Publication number
WO2016134608A1
WO2016134608A1 PCT/CN2015/098230 CN2015098230W WO2016134608A1 WO 2016134608 A1 WO2016134608 A1 WO 2016134608A1 CN 2015098230 W CN2015098230 W CN 2015098230W WO 2016134608 A1 WO2016134608 A1 WO 2016134608A1
Authority
WO
WIPO (PCT)
Prior art keywords
base station
determining
cell
broadcast parameter
pseudo base
Prior art date
Application number
PCT/CN2015/098230
Other languages
English (en)
French (fr)
Inventor
张原�
Original Assignee
中兴通讯股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 中兴通讯股份有限公司 filed Critical 中兴通讯股份有限公司
Publication of WO2016134608A1 publication Critical patent/WO2016134608A1/zh

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/12Detection or prevention of fraud
    • H04W12/121Wireless intrusion detection systems [WIDS]; Wireless intrusion prevention systems [WIPS]
    • H04W12/122Counter-measures against attacks; Protection against rogue devices

Definitions

  • the present invention relates to the field of communications, and in particular to a method and apparatus for identifying a pseudo base station.
  • the pseudo base station is mainly composed of a host computer and a computer, and can search for mobile phone card information centered on a certain radius, and can pretend to be any number, forcibly send short messages such as fraud and advertising to the user's mobile phone.
  • the user's mobile phone signal is forcibly connected to the device, and cannot be connected to the public telecommunication network, so as to affect the normal use of the mobile phone user, it is easy to pose a threat to the owner's own social, work, and money.
  • the common spam interception technology on the intelligent terminal platform is mainly based on two points. First, according to the number source or the short message center number, the number of the user who has joined the blacklist is intercepted, or the suspicious number that has been set in advance is intercepted; It is intercepted according to the content of the short message, such as keyword matching or arrangement.
  • the pseudo base station may use other users' numbers to send short messages, so in many cases, the transmission number cannot be used as a reference for identification; it is not accurate only based on the short message content keywords and the short message center number.
  • the security software mainly implements the identification of the pseudo base station according to the sender number, the short message content keyword or the short message center number, the interception efficiency is low, and the fake interception of the pseudo base station is a common interception.
  • Technology is also helpless.
  • the embodiment of the invention provides a method and a device for identifying a pseudo base station, so as to at least solve the problem that the recognition rate of the pseudo base station is low in the related art.
  • a method for identifying a pseudo base station includes: acquiring a cell broadcast parameter of a base station where the terminal is located; determining whether the cell broadcast parameter is abnormal, and determining that the base station is a fake when the determination result is yes. Base station.
  • the cell broadcast parameter includes: a cell identifier, and determining whether the cell broadcast parameter is abnormal.
  • determining that the base station is a pseudo base station includes: setting a cell identifier of the base station to a preset first set. The values are compared; when the comparison result indicates that the cell identifier is an abnormal value, the base station is determined to be the pseudo base station.
  • the cell broadcast parameter further includes: a signal compensation value, wherein determining whether the cell broadcast parameter is abnormal, and determining that the base station is a pseudo base station includes: determining whether the signal compensation value is greater than And being equal to a predetermined threshold; determining that the base station is the pseudo base station when determining that the signal compensation value is greater than or equal to the predetermined threshold.
  • the foregoing cell broadcast parameter further includes: a location area code (hereinafter referred to as LAC), where it is determined whether the cell broadcast parameter is abnormal, and when the determination result is yes, determining that the base station is a pseudo base station includes: The LAC is compared with the LAC in the second set that is set in advance; when the comparison result indicates that the LAC is an abnormal LAC, the base station is determined to be the pseudo base station.
  • LAC location area code
  • the method before acquiring the cell broadcast parameter of the base station connected to the designated terminal signal, the method includes: receiving a data message sent by the base station; determining whether the data message has content that matches the preset keyword; and determining that the result is At the time, an operation of acquiring the above-mentioned cell broadcast parameter is triggered.
  • the method before acquiring the cell broadcast parameter of the base station that is connected to the designated terminal, the method includes: determining whether the cell of the terminal has a handover; and triggering, when the cell of the terminal is switched, the operation of acquiring the cell broadcast parameter .
  • the foregoing cell broadcast parameter further includes: a location area coding LAC, where determining that the base station is After the pseudo base station, the method further includes: determining whether the location area code is in a preset second set; if the location area code is not in the preset second set, adding the location area code to the second set Inside.
  • a location area coding LAC where determining that the base station is After the pseudo base station, the method further includes: determining whether the location area code is in a preset second set; if the location area code is not in the preset second set, adding the location area code to the second set Inside.
  • the method further includes: adding the cell identifier to the first set; and indicating the foregoing in the comparison result
  • the method further includes: adding the cell identifier to the first set.
  • an apparatus for identifying a pseudo base station including: an obtaining module, configured to acquire a cell broadcast parameter of a base station where the terminal is located; and a determining module, configured to determine whether the cell broadcast parameter is abnormal.
  • an obtaining module configured to acquire a cell broadcast parameter of a base station where the terminal is located
  • a determining module configured to determine whether the cell broadcast parameter is abnormal.
  • the foregoing cell broadcast parameter includes: a cell identifier, where the determining module includes: a first comparison module, configured to compare a cell identifier of the base station with a value in a preset first set; The determining module is configured to determine that the base station is the pseudo base station when the comparison result indicates that the cell identifier is an abnormal value.
  • the cell broadcast parameter further includes: a signal compensation value, where the determining module includes: a determining module, configured to determine whether the signal compensation value is greater than or equal to a predetermined threshold; and the second determining module is configured to determine When the signal compensation value is greater than or equal to the predetermined threshold, determining that the base station is the pseudo base station.
  • the determining module includes: a determining module, configured to determine whether the signal compensation value is greater than or equal to a predetermined threshold; and the second determining module is configured to determine When the signal compensation value is greater than or equal to the predetermined threshold, determining that the base station is the pseudo base station.
  • the cell broadcast parameter further includes: a location area code LAC, where the determining module includes: a second comparison module, configured to compare the LAC with a LAC in a second set that is preset; And a third determining module, configured to determine that the base station is the pseudo base station when the comparison result indicates that the LAC is an abnormal LAC.
  • a location area code LAC where the determining module includes: a second comparison module, configured to compare the LAC with a LAC in a second set that is preset; And a third determining module, configured to determine that the base station is the pseudo base station when the comparison result indicates that the LAC is an abnormal LAC.
  • the device for identifying the pseudo base station further includes: a receiving module, configured to receive a data message sent by the base station; and a first determining module, configured to determine whether the content of the data message matches the preset keyword; The module is configured to trigger an operation of acquiring the above-mentioned cell broadcast parameter when the judgment result is YES.
  • the device for identifying the pseudo base station further includes: a second determining module, configured to determine whether the cell of the terminal is switched; and the second triggering module is configured to trigger the acquiring when the cell of the terminal is switched The operation of the cell broadcast parameter.
  • the cell broadcast parameter further includes: a location area coding LAC
  • the pseudo base station identification apparatus further includes: a third determining module, configured to: when the comparison result indicates that the cell identifier is an abnormal value, determining that the base station is After the pseudo base station, determining whether the location area code is in a second set set in advance; the first adding module is configured to add the location area code to the second part if the location area code is not in the second set set in advance Inside the collection.
  • the identification device of the pseudo base station further includes: a second adding module, configured to: after determining that the base station is the pseudo base station, adding the cell identifier to the foregoing, after determining that the signal compensation value is greater than or equal to the predetermined threshold
  • the third adding module is configured to: after the comparison result indicates that the location area is encoded as an abnormal value, after determining that the base station is a pseudo base station, adding the cell identifier to the first set.
  • the cell broadcast parameter of the base station where the terminal is located is used to determine whether the cell broadcast parameter is abnormal.
  • the base station is determined to be a pseudo base station, where the broadcast message includes the cell identifier, the information compensation value, and Location area code.
  • the invention achieves the technical effect of improving the recognition rate of the pseudo base station by determining the manner in which the base station of the terminal is broadcasting the message, and further solves the problem that the related art detects the pseudo base station by only including the sensitive information when determining the received short message.
  • the problem of low recognition rate has also achieved the effect of improving the user experience.
  • FIG. 1 is a flowchart of a method for identifying a pseudo base station according to an embodiment of the present invention
  • FIG. 2 is a flowchart 1 of an optional identification method of a pseudo base station according to an embodiment of the present invention
  • FIG. 3 is a second flowchart of an optional identification method of a pseudo base station according to an embodiment of the present invention.
  • FIG. 4 is a flowchart 3 of an optional identification method of a pseudo base station according to an embodiment of the present invention.
  • FIG. 5 is a flowchart 4 of an optional identification method of a pseudo base station according to an embodiment of the present invention.
  • FIG. 6 is a structural block diagram of an apparatus for identifying a pseudo base station according to an embodiment of the present invention.
  • FIG. 7 is a block diagram 1 of an optional structure of an identification device of a pseudo base station according to an embodiment of the present invention.
  • FIG. 8 is a block diagram 2 of an optional structure of an identification device of a pseudo base station according to an embodiment of the present invention.
  • FIG. 9 is a block diagram 3 of an optional structure of an identification device of a pseudo base station according to an embodiment of the present invention.
  • FIG. 10 is a block diagram 4 of an optional structure of an identification device of a pseudo base station according to an embodiment of the present invention.
  • FIG. 11 is a block diagram 5 of an optional structure of an identification device of a pseudo base station according to an embodiment of the present invention.
  • FIG. 12 is a block diagram 6 of an optional structure of an identification device of a pseudo base station according to an embodiment of the present invention.
  • FIG. 1 is a flowchart of a method for identifying a pseudo base station according to an embodiment of the present invention. As shown in FIG. 1, the method of the embodiment of the present invention includes step S102- S104:
  • Step S102 Acquire a cell broadcast parameter of a base station where the terminal is located.
  • the terminal 10 can be, but is not limited to, a mobile phone, a network card, and a notebook.
  • the cell range of the base station 20 has a plurality of terminals 10 and maintains a communication connection with the base station 20.
  • the cell broadcast parameters of the base station 20 can be obtained by the base station 20 transmitting or forwarding the data message to the terminal 10, and the terminal 10 can also send the query cell to the base station 20.
  • the base station 20 Upon request for a broadcast parameter, the base station 20 returns the cell broadcast parameters of the base station 20 to the terminal 10.
  • Step S104 determining whether the cell broadcast parameter is abnormal. When the determination result is yes, determining that the base station is a pseudo base station.
  • the technical effect of improving the recognition rate of the pseudo base station is improved, and the related art is used to identify the pseudo base station by only including the sensitive information when determining the received short message.
  • the problem of low recognition rate has also achieved the effect of improving the user experience.
  • the cell broadcast parameter after acquiring the cell broadcast parameter of the base station 20, the cell broadcast parameter includes multiple parameters, such as a cell identifier, an information compensation value, a location area code, a downlink rate, etc., and in actual judgment, the normal communication may be selected.
  • the base station distinguishes the parameters with obvious differences, such as cell identification, information compensation value, and location area coding.
  • the base station 20 of the cell where the terminal 10 is located is a pseudo base station.
  • an alarm message may be generated to notify the terminal 10, or notify the pseudo base station 20, and may also perform marking on the network server side to give the user a risk indication.
  • FIG. 2 is a flowchart 1 of an optional identification method of a pseudo base station according to an embodiment of the present invention.
  • the cell broadcast parameter selected in this embodiment is a cell identifier.
  • steps S202-S204 are included:
  • the value in the first set may be a cell identifier of the normal base station, or may be a cell identifier of the abnormal base station, that is, the acquired cell identifier and the normal value in the cell identifier set may be compared.
  • the obtained cell identifier and the abnormal value in the cell identifier set may also be compared.
  • the cell identifier (cellID) must be switched. By comparing the cell ID after the handover, it can be determined whether the base station 20 of the cell is a pseudo base station, and whether the comparison result is indicated.
  • the cell identification code is an abnormal value.
  • the cell identifier of the normal base station is a normal value of the communication protocol
  • the cell identifier corresponding to the pseudo base station is generally an abnormal value such as 0.
  • the normal value and the abnormal value may be determined by referring to the data table of the operator.
  • the obtained cell identifier is compared with the normal cell identifier set, the acquired cell identifier is not in the normal cell identifier set, and then the base station 20 is determined to be a pseudo base station, and the acquired cell identifier and the abnormal cell identifier set are performed.
  • the alignment is performed, the acquired cell identifier is within the abnormal cell identifier set, and then the base station 20 is determined to be a pseudo base station.
  • the signal compensation value or the LAC is further determined.
  • FIG. 3 is a second flowchart of an optional identification method of a pseudo base station according to an embodiment of the present invention.
  • the cell broadcast parameter selected in this embodiment is an information compensation value.
  • the method includes steps S302-S304:
  • the predetermined threshold may be set to 10 dbm, and it is determined whether the signal compensation value in the obtained broadcast parameter message is greater than or equal to 10 dbm.
  • the pseudo base station In order to be concealed, the pseudo base station is generally small in size and the power to be transmitted is not particularly large. In order to force the connection of the user terminal signal to the device during operation, the signal compensation value is set higher.
  • the parameter In the C2 criterion of cell reselection, for the neighboring cell, the parameter is the offset of the signal strength. Compared with the setting of the value of the normal cell, the abnormal cell will attract the terminal to register with the cell even if the signal strength is much lower than that of the normal cell. Therefore, it is determined whether the signal compensation value is too high to determine whether the base station 20 is a pseudo base station.
  • the base station 20 when it is determined that the signal compensation value in the obtained broadcast parameter message is 50 dBm, the base station 20 is a pseudo base station, and when the signal compensation value in the broadcast parameter message is 2 dBm, it is less than the predetermined.
  • a threshold of 10 dbm indicates that the base station 20 is a normal base station.
  • FIG. 4 is a third flowchart of an optional identification method of a pseudo base station according to an embodiment of the present invention.
  • the cell broadcast parameter selected in this embodiment is a location area coding (LAC).
  • LAC location area coding
  • the method includes steps S402-S404:
  • the value in the second set may be a normal base station location area coding (LAC), or may be a location area coding of the abnormal base station, that is, the acquired cell identity and the normal location area code set may be performed.
  • LAC normal base station location area coding
  • the acquired cell identifier and the abnormal location area code set may also be compared. Since the coverage of the pseudo base station is extremely limited, after the user is forcibly migrated to the pseudo base station, the user will occupy the normal network at any time after a certain period of time; the user must perform a location update from the pseudo base station signal back to the normal network, and must report the pseudo when the location is updated.
  • the LAC that broadcasts the message by the base station determines whether the comparison result indicates that the LAC is an abnormal LAC.
  • the LAC of the pseudo base station signal is different from the LAC of the normal network.
  • the LAC used by the pseudo base station signal is 0, 65534, 65535 or other small values.
  • step S102 before acquiring a cell broadcast parameter of a base station connected to a designated terminal signal, the method further includes step S502- S506:
  • the data message sent by the base station 20 may be, but is not limited to, a short message message, a push link, a WAP message, and a webpage content.
  • the preset keyword may be a number in the blacklist, an abnormal center number of the data message, or an arrangement of sensitive words, such as a bank, a payment, a winning, and the like.
  • the broadcast parameter of the cell where the base station 20 is located is triggered.
  • the cell of the terminal 10 is switched before the cell broadcast parameter of the base station 20 that is connected to the designated terminal 10 is obtained.
  • the cell broadcast parameter is triggered. operating.
  • the base station 20 after determining that the base station 20 is a pseudo base station, determining whether the location area code is in a preset second set, and if the location area code is not in the second set set in advance, encoding the location area Add to the second set above.
  • determining that the signal compensation value is greater than or equal to the predetermined threshold determining that the base station is the pseudo base station, adding the cell identifier to the first set; and indicating that the location area code is an abnormal value
  • the depth of the pseudo base station masquerading is different, it may not be recognized by separately comparing or judging a broadcast parameter, but the broadcast parameters of the pseudo base station are not in conformity with the communication protocol, and the broadcast parameters of the pseudo base station to be identified are determined.
  • the non-stop addition to the local database first outlier set and the second outlier set can continuously improve and collect the broadcast parameter information of each pseudo base station, which can be more accurate and faster when the base station is next identified.
  • the cell broadcast parameter of the base station where the terminal is located is used to determine whether the cell broadcast parameter is abnormal.
  • the base station is determined to be a pseudo base station, and in actual judgment of the cell broadcast parameter. It is possible to determine only one of the broadcast parameters, or to determine two of the broadcast parameters, or to determine that the base station is a pseudo base station when the three sets of broadcast parameters are abnormal, wherein the broadcast message includes the cell identifier, the information compensation value, and the location area code. .
  • the invention achieves the technical effect of improving the recognition rate of the pseudo base station by determining the manner in which the base station of the terminal is broadcasting the message, and further solves the problem that the related art detects the pseudo base station by only including the sensitive information when determining the received short message.
  • Technical problem with low recognition rate is a problem that the related art detects the pseudo base station by only including the sensitive information when determining the received short message.
  • FIG. 6 is a structural block diagram of a device for identifying a pseudo base station according to an embodiment of the present invention. As shown in FIG. 6, the device includes: an obtaining module 40; and a determining module 42 coupled to the acquiring module 40.
  • the obtaining module 40 is configured to acquire a cell broadcast parameter of a base station where the terminal is located.
  • the terminal 10 can be, but is not limited to, a mobile phone, a network card, and a notebook.
  • the cell of the base station 20 has a plurality of terminals 10 and maintains a communication connection with the base station 20.
  • the acquisition module 40 can obtain the cell broadcast parameters of the base station 20 by using the data message sent by the base station 20 or forwarded to the terminal 10, and the obtaining module 40 can also provide the base station 20 with the base station. 20 Sending a request to query the cell broadcast parameter, the base station 20 returns the cell broadcast parameter of the base station 20 to the acquisition module 40.
  • the determining module 42 is configured to determine whether the cell broadcast parameter is abnormal, and when the determination result is yes, determine that the base station is a pseudo base station.
  • the cell broadcast parameter may include multiple parameters, such as a cell identifier, an information compensation value, a location area code, and a downlink rate.
  • the base station of normal communication is judged by a relatively different parameter, such as a cell identifier, an information compensation value, and a location area code.
  • the determining module 42 determines that the result of the cell broadcast parameter is that the broadcast parameter is abnormal, it is determined that the base station 20 of the cell where the terminal 10 is located is a pseudo base station.
  • an alarm message may be generated to notify the terminal 10, or notify the pseudo base station 20, and may also perform marking on the network server side to give the user a risk indication.
  • FIG. 7 is a block diagram of an optional structure of an apparatus for identifying a pseudo base station according to an embodiment of the present invention.
  • the cell broadcast parameter selected in this embodiment is a cell identifier
  • the determining module 42 further includes: a first ratio.
  • the first determining module 502 is coupled to the first comparing module 500.
  • the first comparison module 500 is configured to compare the cell identifier of the base station with a value in a preset first set.
  • the value in the first set may be a cell identifier of the normal base station, or may be a cell identifier of the abnormal base station, that is, the first comparison module 500 may obtain the acquired cell identifier and the normal cell identifier set. For comparison, the acquired cell identifier and the abnormal cell identifier set may also be compared.
  • the terminal After the terminal enters the cell reset of the pseudo base station from the normal base station, there must be a cell ID (cellID) handover. By comparing the cell ID after the handover, it can be determined whether the base station 20 of the cell is a pseudo base station.
  • cellID cell ID
  • the first determining module 502 is configured to determine that the base station is the pseudo base station when the comparison result indicates that the cell identifier is an abnormal value.
  • the cell identifier of the normal base station is a normal value of the communication protocol
  • the cell identifier corresponding to the pseudo base station is generally an abnormal value such as 0.
  • the normal value and the abnormal value may be determined by referring to the data table of the operator.
  • the first comparison module 500 compares the acquired cell identifier with the normal cell identifier set, and the acquired cell identifier is not in the normal cell identifier set, the base station 20 is determined to be a pseudo base station, and the first comparison module is used.
  • the acquired cell identifier is compared with the abnormal cell identifier set, the acquired cell identifier is in the abnormal cell identifier set, and the first determining module 502 determines that the base station 20 is a pseudo base station.
  • the first comparison module 500 compares the acquired cell identifier with the value in the first set, if the cell ID is not indicated as an abnormal value, then the signal compensation value or the LAC is further determined.
  • FIG. 8 is a block diagram of an optional structure of an apparatus for identifying a pseudo base station according to an embodiment of the present invention.
  • the cell broadcast parameter selected in this embodiment is a signal compensation value
  • the determining module further includes: a determining module 504.
  • the second comparison module 506 is coupled to the first comparison module 500.
  • the second determination module 506 is coupled to the determination module 504.
  • the determining module 504 is configured to determine whether the signal compensation value is greater than or equal to a predetermined threshold.
  • the predetermined threshold may be set to 10 dbm, and the determining module 504 determines whether the signal compensation value in the obtained broadcast parameter message is greater than or equal to 10 dbm.
  • the pseudo base station is generally small in size and the power to be transmitted is not particularly large.
  • the signal compensation value is set higher.
  • the parameter is the offset of the signal strength. Compared with the setting of the value of the normal cell, the abnormal cell will attract the terminal to register with the cell even if the signal strength is much lower than that of the normal cell. Therefore, it is determined whether the signal compensation value is too high to determine whether the base station 20 is a pseudo base station.
  • the second determining module 506 is configured to determine that the base station is the pseudo base station when determining that the signal compensation value is greater than or equal to the predetermined threshold.
  • the second determining module 506 determines that the base station 20 is a pseudo base station, and acquires the broadcast parameter.
  • the signal compensation value in the information is 2 dBm, it is less than the predetermined threshold 10 dbm, indicating that the base station 20 is a normal base station.
  • FIG. 9 is a block diagram 3 of an optional structure of a device for identifying a pseudo base station according to an embodiment of the present invention.
  • the cell broadcast parameter selected in this embodiment is a location area code LAC
  • the determining module 42 further includes: The second comparison module 508 is coupled to the first comparison module 500; the third determination module 510 is coupled to the second comparison module 508.
  • the second comparison module 508 is configured to compare the LAC with the LAC in the second set set in advance.
  • the value in the second set may be a normal base station location area coding (LAC), or may be a location area coding of the abnormal base station, that is, the second comparison module 508 may obtain the obtained cell identity and normal.
  • the location area code set is compared, and the acquired cell identifier and the abnormal location area code set may also be compared. Since the coverage of the pseudo base station is extremely limited, after the user is forcibly migrated to the pseudo base station, the user will occupy the normal network at any time after a certain period of time; the user must perform a location update from the pseudo base station signal back to the normal network, and must report the pseudo when the location is updated.
  • the LAC of the base station broadcast message since the coverage of the pseudo base station is extremely limited, after the user is forcibly migrated to the pseudo base station, the user will occupy the normal network at any time after a certain period of time; the user must perform a location update from the pseudo base station signal back to the normal network, and must report the pseudo when the location is updated.
  • the third determining module 510 is configured to determine that the base station is the pseudo base station when the comparison result indicates that the LAC is an abnormal LAC.
  • the LAC of the pseudo base station signal is different from the LAC of the normal network.
  • the LAC used by the pseudo base station signal is 0, 65534, 65535 or other small values.
  • FIG. 10 is a block diagram showing an optional structure of an identification device of a pseudo base station according to an embodiment of the present invention. As shown in FIG. 10, the device is combined by FIG. 7, FIG. 8, and FIG.
  • the device for identifying a pseudo base station further includes: a receiving module 60; a first determining module 62; and a triggering module 64. It is coupled to the acquisition module 40.
  • the receiving module 60 is configured to receive the data message sent by the base station.
  • the data message sent by the base station 20 may be, but is not limited to, a short message message, a push link, a WAP message, and a webpage content.
  • the first determining module 62 is configured to determine whether there is content matching the preset keyword in the data message
  • the preset keyword may be a number in the blacklist, an abnormal center number of the data message, or an arrangement of sensitive words, such as a bank, a payment, a winning, etc., that is, sensitive information in the data message.
  • the first determining module 62 is configured to determine whether there is content in the data message received by the receiving module 60 that matches the preset keyword.
  • the triggering module 64 is configured to trigger an operation of acquiring the cell broadcast parameter when the determination result is yes.
  • the first determining module 62 determines that the number of the data message received by the receiving module 60 is a number in the blacklist, the center number of the data message is an abnormal center number, and the acquired data message further includes a sensitive word, The broadcast parameters of the cell where the base station 20 is located are triggered.
  • the cell of the terminal 10 is switched before the cell broadcast parameter of the base station 20 that is connected to the designated terminal 10 is obtained.
  • the cell broadcast parameter is triggered. operating.
  • FIG. 12 is a structural block diagram 6 of a device for identifying a pseudo base station according to an embodiment of the present invention.
  • the device for identifying a pseudo base station further includes: a third determining module 70; a first adding module 72; and a second adding module.
  • the third adding module 76 wherein the third determining module 70 and the first determining module 502 are coupled, the second adding module 74 and the second determining module 506 are coupled, and the third adding module 76 and the third determining module 510 are coupled. .
  • the third determining module 70 is configured to determine, after the comparison result indicates that the cell identifier is an abnormal value, that the base station is a pseudo base station, and determine whether the location area code is in a second set that is preset;
  • the first adding module 72 is configured to add the location area code to the second set if the location area code is not in the second set set in advance.
  • the second adding module 74 is configured to: after determining that the signal compensation value is greater than or equal to the predetermined threshold, determine that the base station is the pseudo base station, and add the cell identifier to the first set;
  • the third adding module 76 is configured to: after the comparison result indicates that the location area is encoded as an abnormal value, after determining that the base station is a pseudo base station, add the cell identifier to the first set.
  • the depth of the pseudo base station masquerading is different, it may not be recognized by separately comparing or judging a broadcast parameter, but the broadcast parameters of the pseudo base station are not in conformity with the communication protocol, and the broadcast parameters of the pseudo base station to be identified are determined.
  • the non-stop addition to the local database first outlier set and the second outlier set can continuously improve and collect the broadcast parameter information of each pseudo base station, which can be more accurate and faster when the base station is next identified.
  • the cell broadcast parameter of the base station where the terminal is located is used to determine whether the cell broadcast parameter is abnormal.
  • the base station is determined to be a pseudo base station, and in actual judgment of the cell broadcast parameter. It is possible to determine only one of the broadcast parameters, or to determine two of the broadcast parameters, or to determine that the base station is a pseudo base station when the three sets of broadcast parameters are abnormal, wherein the broadcast message includes the cell identifier, the information compensation value, and the location area code. .
  • the invention achieves the technical effect of improving the recognition rate of the pseudo base station by determining the manner in which the base station of the terminal is broadcasting the message, and further solves the problem that the related technology includes sensitive information such as advertising and scams only by judging the received short message.
  • Information to identify pseudo base stations leads to technical problems with low recognition rates.
  • the disclosed apparatus may be implemented in other ways.
  • the device embodiments described above are merely illustrative.
  • the division of the above units is only a logical function division. In actual implementation, there may be another division manner.
  • multiple units or components may be combined or integrated. Go to another system, or some features can be ignored or not executed.
  • the mutual coupling or direct coupling or communication connection shown or discussed may be through some interface, device or unit.
  • the indirect coupling or communication connection can be in electrical or other form.
  • the units described above as separate components may or may not be physically separate, and the components displayed as units may or may not be physical units, that is, may be located in one place, or may be distributed to multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of the embodiment.
  • each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
  • the above integrated unit can be implemented in the form of hardware or in the form of a software functional unit.
  • the above-described integrated unit if implemented in the form of a software functional unit and sold or used as a stand-alone product, may be stored in a computer readable storage medium. Based on such understanding, the technical solution of the present invention may contribute to the related art or all or part of the technical solution may be embodied in the form of a software product stored in a storage medium.
  • a number of instructions are included to cause a computer base station (which may be a personal computer, mobile terminal, server or network base station, etc.) to perform all or part of the steps of the above-described methods of various embodiments of the present invention.
  • the foregoing storage medium includes: a U disk, a Read-Only Memory (ROM), a Random Access Memory (RAM), a removable hard disk, a magnetic disk, or an optical disk, and the like. .
  • the cell broadcast parameter of the base station where the terminal is located is used to determine whether the cell broadcast parameter is abnormal, and when the judgment result is yes, Determining that the base station is a pseudo base station, wherein the broadcast message includes a cell identifier, an information compensation value, and a location area code.
  • the invention achieves the technical effect of improving the high recognition rate of the pseudo base station by judging the manner in which the base station of the cell in which the terminal is located broadcasts the message, and further solves the problem in the related art because only the short message received by the judgment is included. Sensitive information to identify pseudo base stations leads to a low recognition rate and also improves the user experience.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

本发明公开了一种伪基站的识别方法和装置。其中,该方法包括:获取终端所在基站的小区广播参数;判断小区广播参数是否异常,在判断结果为是时,确定基站为伪基站。通过本发明,解决了现有技术中伪基站的识别率低的技术问题。

Description

伪基站的识别方法和装置 技术领域
本发明涉及通信领域,具体而言,涉及一种伪基站的识别方法和装置。
背景技术
随着通讯技术的发展,移动终端基站的功能越来越丰富,已经从基本的语音通话工具,发展成为一个功能齐全的掌上电脑。同时针对移动终端的各种诈骗方法也不断升级,社会上就存在通过伪基站,即假基站欺骗用户手机接入违法无线网络,然后通过伪造官方号码或任意冒用他人手机号码给用户手机发送消息或进行广告推销,欺骗用户进行缴费、转账、付款等金融诈骗,使很多用户蒙受了经济损失。
伪基站主要由主机和电脑组成,能够搜取以其为中心、一定半径范围内的手机卡信息,并可以冒充任意号码,强行向用户手机发送诈骗、广告推销等短信息。此类设备运行时,用户手机信号被强制连接到该设备上,无法连接到公用电信网络,以致影响手机用户的正常使用,就很容易对机主本人的社交、工作、金钱造成威胁。
目前,智能终端平台上普通的垃圾短信拦截技术主要基于两点,一是根据号码来源或短信息中心号码,拦截用户已经加入黑名单中的号码,或者拦截已提前被设定的可疑号码;二是根据短信内容进行拦截,例如关键词匹配或排列组合。
相关技术存在以下缺点和问题:伪基站可能冒用其他用户的号码发短信息,因此很多情况下发送号码不能作为识别的基准;仅仅根据短信息内容关键词和短信息中心号码也并不准确。
在相关技术方案中,安全软件主要根据发送方号码、短消息内容关键词或短信息中心号码等实现对伪基站的识别,拦截的效率低,且对于伪基站伪装出的虚假号码,普通的拦截技术也是束手无策的。
针对相关技术中对伪基站发出的消息拦截效率低且不能全部拦截的问题,目前尚未提出有效的解决方案。
发明内容
本发明实施例提供了一种识别伪基站的识别方法和装置,以至少解决相关技术中伪基站的识别率低的问题。
根据本发明实施例的一个方面,提供了一种伪基站的识别方法,包括:获取终端所在基站的小区广播参数;判断上述小区广播参数是否异常,在判断结果为是时,确定上述基站为伪基站。
可选地,上述小区广播参数包括:小区标识,判断上述小区广播参数是否异常,在判断结果为是时,确定上述基站为伪基站包括:将上述基站的小区标识与预先设置的第一集合内的值进行比对;在比对结果指示上述小区标识为异常值时,确定上述基站为上述伪基站。
可选地,上述小区广播参数还包括:信号补偿值,其中,判断所述小区广播参数是否异常,在判断结果为是时,确定所述基站为伪基站包括:判断所述信号补偿值是否大于等于预定阈值;在判断出所述信号补偿值大于等于所述预定阈值时,确定所述基站为所述伪基站。
可选地,上述小区广播参数还包括:位置区编码(Location Area Code简称为LAC),其中,判断所述小区广播参数是否异常,在判断结果为是时,确定所述基站为伪基站包括:将所述LAC与预先设置的第二集合内的LAC进行比对;在比对结果指示所述LAC为异常LAC时,确定所述基站为所述伪基站。
可选地,在获取与指定终端信号连接的基站的小区广播参数之前,包括:接收上述基站发送的数据消息;判断上述数据消息中是否有与预设关键字匹配的内容;在判断结果为是时,触发获取上述小区广播参数的操作。
可选地,在获取与指定终端信号连接的基站的小区广播参数之前,包括:判断所述终端的小区是否发生切换;在所述终端的小区发生切换时,触发获取所述小区广播参数的操作。
可选地,上述小区广播参数还包括:位置区编码LAC,其中,在确定上述基站为 伪基站之后,上述方法还包括:判断上述位置区编码是否在预先设置的第二集合内;若上述位置区编码不在预先设置的第二集合内,则将上述位置区编码添加到上述第二集合内。
可选地,在判断出上述信号补偿值大于等于上述预定阈值时,确定上述基站为上述伪基站之后,上述方法还包括:将上述小区标识添加到上述第一集合内;在比对结果指示上述位置区编码为异常值时,确定上述基站为伪基站之后,上述方法还包括:将上述小区标识添加到上述第一集合内。
根据本发明实施例的另一方面,还提供了一种伪基站的识别装置,包括:获取模块,设置为获取终端所在基站的小区广播参数;确定模块,设置为判断上述小区广播参数是否异常,在判断结果为是时,确定上述基站为伪基站。
可选地,上述小区广播参数包括:小区标识,其中,上述确定模块包括:第一比对模块,设置为将上述基站的小区标识与预先设置的第一集合内的值进行比对;第一确定模块,设置为在比对结果指示上述小区标识为异常值时,确定上述基站为上述伪基站。
可选地,上述小区广播参数还包括:信号补偿值,其中,所述确定模块包括:判断模块,设置为判断所述信号补偿值是否大于等于预定阈值;第二确定模块,设置为在判断出所述信号补偿值大于等于所述预定阈值时,确定所述基站为所述伪基站。
可选地,上述小区广播参数还包括:位置区编码LAC,其中,所述确定模块包括:第二比对模块,设置为将所述LAC与预先设置的第二集合内的LAC进行比对;第三确定模块,设置为在比对结果指示所述LAC为异常LAC时,确定所述基站为所述伪基站。
可选地,上述伪基站的识别装置还包括:接收模块,设置为接收上述基站发送的数据消息;第一判断模块,设置为判断上述数据消息中是否有与预设关键字匹配的内容;触发模块,设置为在判断结果为是时,触发获取上述小区广播参数的操作。
可选地,上述伪基站的识别装置还包括:第二判断模块,设置为判断所述终端的小区是否发生切换;第二触发模块,设置为在所述终端的小区发生切换时,触发获取 所述小区广播参数的操作。
可选地,上述小区广播参数还包括:位置区编码LAC,其中,上述伪基站识别装置还包括:第三判断模块,设置为在比对结果指示上述小区标识为异常值时,确定上述基站为伪基站之后,判断上述位置区编码是否在预先设置的第二集合内;第一添加模块,设置为若上述位置区编码不在预先设置的第二集合内,将上述位置区编码添加到上述第二集合内。
可选地,上述伪基站的识别装置还包括:第二添加模块,设置为在判断出上述信号补偿值大于等于上述预定阈值时,确定上述基站为上述伪基站之后,将上述小区标识添加到上述第一集合内;第三添加模块,设置为在比对结果指示上述位置区编码为异常值时,确定上述基站为伪基站之后,将上述小区标识添加到上述第一集合内。
在本发明实施例中,采用获取终端所在基站的小区广播参数,判断上述小区广播参数是否异常,在判断结果为是时,确定上述基站为伪基站,其中广播消息包括小区标识、信息补偿值和位置区编码。本发明通过判断终端所在小区基站广播消息的方式,实现了提高伪基站识别率高的技术效果,进而解决了相关技术中由于只通过判断接收到的短消息时候包含敏感信息来识别伪基站而导致识别率低的问题,也达到了提高用户体验的效果。
附图说明
构成本申请的一部分的附图用来提供对本发明的进一步理解,本发明的示意性实施例及其说明用于解释本发明,并不构成对本发明的不当限定。在附图中:
图1是根据本发明实施例的一种伪基站的识别方法的流程图;
图2是根据本发明实施例的伪基站的可选识别方法的流程图一;
图3是根据本发明实施例的伪基站的可选识别方法的流程图二;
图4是根据本发明实施例的伪基站的可选识别方法的流程图三;
图5是根据本发明实施例的伪基站的可选识别方法的流程图四;
图6是根据本发明实施例的一种伪基站的识别装置的结构框图;
图7是根据本发明实施例的伪基站的识别装置的可选结构框图一;
图8是根据本发明实施例的伪基站的识别装置的可选结构框图二;
图9是根据本发明实施例的伪基站的识别装置的可选结构框图三;
图10是根据本发明实施例的伪基站的识别装置的可选结构框图四;
图11是根据本发明实施例的伪基站的识别装置的可选结构框图五;以及
图12是根据本发明实施例的伪基站的识别装置的可选结构框图六。
具体实施方式
需要说明的是,在不冲突的情况下,本申请中的实施例及实施例中的特征可以相互组合。下面将参考附图并结合实施例来详细说明本发明。
为了使本技术领域的人员更好地理解本发明方案,下面将结合本发明实施例中的附图,对本发明实施例中的技术方案进行清楚、完整地描述,显然,所描述的实施例仅仅是本发明一部分的实施例,而不是全部的实施例。基于本发明中的实施例,本领域普通技术人员在没有做出创造性劳动前提下所获得的所有其他实施例,都应当属于本发明保护的范围。
需要说明的是,本发明的说明书和权利要求书及上述附图中的术语“第一”、“第二”等是用于区别类似的对象,而不必用于描述特定的顺序或先后次序。应该理解这样使用的数据在适当情况下可以互换,以便这里描述的本发明的实施例。此外,术语“包括”和“具有”以及他们的任何变形,意图在于覆盖不排他的包含,例如,包含了一系列步骤或单元的过程、方法、系统、产品或基站不必限于清楚地列出的那些步骤或单元,而是可包括没有清楚地列出的或对于这些过程、方法、产品或基站固有的其它步骤或单元。
可选实施例1
根据本发明实施例,提供了一种伪基站的识别方法,图1是根据本发明实施例的伪基站的识别方法的流程图,如图1所示,本发明实施例的方法包括步骤S102-S104:
步骤S102,获取终端所在基站的小区广播参数。
可选地,上述终端10可以但不限于手机、上网卡、笔记本。基站20的小区范围有若干个终端10并与基站20保持通讯连接,可以通过基站20发送或者转发给终端10的数据消息中获取基站20的小区广播参数,还可以终端10向基站20发送查询小区广播参数的请求,基站20向终端10返回基站20的小区广播参数。
步骤S104,判断小区广播参数是否异常,在判断结果为是时,确定上述基站为伪基站。
本实施例通过判断终端所在小区基站广播消息的方式,实现了提高伪基站识别率高的技术效果,进而解决了相关技术中由于只通过判断接收到的短消息时候包含敏感信息来识别伪基站而导致识别率低的问题,也达到了提高用户体验的效果。
可选地,获取基站20的小区广播参数之后,由于小区广播参数包括多项参数,如小区标识、信息补偿值、位置区编码、下行速率等,在实际判断过程中,可以选择和正常通信的基站差别较明显的参数来判断,如小区标识、信息补偿值、位置区编码。当判断上述小区广播参数的结果为广播参数为异常时,就确定终端10所在小区的基站20为伪基站。
可选地,在确定基站20为伪基站后,还可以生成报警消息来通知终端10,或者通知伪基站20,还可以在网络服务器侧进行标记,来给用户风险提示。
图2是根据本发明实施例的伪基站的可选识别方法的流程图一,如图2所示,该实施例中所选的小区广播参数为小区标识。如图2所示,包括步骤S202-S204:
S202,将上述基站的小区标识与预先设置的第一集合内的值进行比对;
可选地,第一集合内的值可以为正常基站的小区标识,也可以为异常基站的小区标识,也就是说,既可以将获取的小区标识和小区标识集合中的正常值进行比对,也可以将获取的小区标识和小区标识集合中异常值进行比对。终端从正常基站进去伪基站的小区复位之内后,一定会有小区标识(cellID)的切换,通过比对切换后的cellID可以得出小区的基站20是否为伪基站,判断比对结果是否指示小区标识码为异常值。
S204,在比对结果指示上述小区标识为异常值时,确定上述基站为伪基站。
可选地,由于正常基站的小区标识都是符合通信协议的正常值,而伪基站对应的小区标识一般是异常值如0,具体还可以参照运营商的数据表确定正常值和异常值,当将获取的小区标识和正常的小区标识集合进行比对时,获取的小区标识没有在正常的小区标识集合内,则确定基站20为伪基站,当将获取的小区标识和异常的小区标识集合进行比对时,获取的小区标识在异常的小区标识集合内,则确定基站20为伪基站。
而通过将获取的小区标识和第一集合内的值进行比对之后,如果指示cellID是不为异常值,则接下来结合信号补偿值或LAC做进一步的判定。
图3是根据本发明实施例的伪基站的可选识别方法的流程图二,如图3所示,该实施例中所选的小区广播参数为信息补偿值。如图2所示,该方法包括步骤S302-S304:
S302,判断上述信号补偿值是否大于等于预定阈值。
可选地,可以将预定阈值设定为10dbm,判断获取的广播参数消息中的信号补偿值是否大于等于10dbm。伪基站为了隐蔽性,一般体积不大,所发射的功率也不会特别大。而运行时为了将用户终端信号强制连接到该设备上,会将信号补偿值设置的较高。在小区重选的C2准则中,对于邻小区,该参数就是信号强度的偏移量,对比正常小区该值的设置,异常小区即使信号强度大大低于正常小区也会吸引终端向该小区进行注册,所以判断信号补偿值是否超高可以判断出基站20是否为伪基站。
S304,在判断出上述信号补偿值大于等于上述预定阈值时,确定上述基站为上述伪基站。
可选地,当判断出获取的广播参数消息中的信号补偿值为50dBm时,则大于预定阈值10dbm,基站20为伪基站,当获取广播参数消息中的信号补偿值为2dBm时,则小于预定阈值10dbm,则表示基站20为正常基站。
图4是根据本发明实施例的伪基站的可选识别方法的流程图三,如图4所示,该实施例中所选的小区广播参数为位置区编码(LAC)。如图2所示,该方法包括步骤S402-S404:
S402,将上述LAC与预先设置的第二集合内的LAC进行比对。
可选地,第二集合内的值可以为正常基站位置区编码(LAC),也可以为异常基站的位置区编码,也就是说,即可以将获取的小区标识和正常的位置区编码集合进行比对,也可以将获取的小区标识和异常的位置区编码集合进行比对。由于伪基站覆盖范围极其有限,用户被强制迁移到伪基站上后,将在一定时间后随时占上正常网络;用户从伪基站信号回到正常网络必须做一次位置更新,位置更新时必须上报伪基站广播消息的LAC,判断比对结果是否指示上述LAC为异常LAC。
S404,在比对结果指示上述LAC为异常LAC时,确定上述基站为上述伪基站。
由于一般伪基站信号的LAC和正常网络的LAC不一样,通常伪基站信号采用的LAC为0、65534、65535或其他较小的数值,具体还可以参照运营商的LAC数据表。当将获取的LAC和正常的LAC集合进行比对时,获取的LAC没有在正常的小区标识集合内,则确定基站20为伪基站,当将获取的LAC和异常的LAC集合进行比对时,获取的LAC在异常的小区标识集合内,则确定基站20为伪基站。
图5是根据本发明实施例的伪基站的可选识别方法的流程图四,如图5所示,在步骤S102,获取与指定终端信号连接的基站的小区广播参数之前,还包括步骤S502-S506:
S502,接收上述基站20发送的数据消息。
可选地,基站20发送的数据消息可以但不限于短信消息,推送链接,WAP信息,网页内容。
S504,判断上述数据消息中是否有与预设关键字匹配的内容。
可选地,预设关键字可以为黑名单中的号码、数据消息的异常中心号码,还可以是敏感词的排列组合,如银行、打款、中奖等。
S506,在判断结果为是时,触发获取上述小区广播参数的操作。
可选地,当数据消息的号码为黑名单中的号码、数据消息的中心号码为异常中心 号码、获取的数据消息中还含有敏感词时,就触发获取基站20所在小区的广播参数。
可选地,还可以通过在获取与指定终端10信号连接的基站20的小区广播参数之前判断上述终端10的小区是否发生切换,在上述终端10的小区发生切换时,触发获取上述小区广播参数的操作。
可选地,在确定上述基站20为伪基站之后,还判断上述位置区编码是否在预先设置的第二集合内,若上述位置区编码不在预先设置的第二集合内,则将上述位置区编码添加到上述第二集合内。同样地,在判断出上述信号补偿值大于等于上述预定阈值时,确定上述基站为上述伪基站之后,将上述小区标识添加到上述第一集合内;在比对结果指示上述位置区编码为异常值时,确定上述基站为伪基站之后,将上述小区标识添加到上述第一集合内。由于伪基站伪装的深度不同,通过单独比对或者判断一项广播参数可能不能识别出来,但是伪基站的各项广播参数都是不符合通信协议,通过将识别出来的伪基站的各项广播参数不停地加入到本地数据库第一异常值集合和第二异常值集合中,可以不断完善和收集各个伪基站的广播参数信息,在下一次识别基站时能够更精确和更快速。
在本发明实施例中,采用获取终端所在基站的小区广播参数,判断上述小区广播参数是否异常,在判断结果为是时,确定上述基站为伪基站,在实际对小区广播参数的判断过程中,可以只判断其中一组广播参数,也可以判断其中两组广播参数,或者在判断三组广播参数都为异常时,确定基站为伪基站,其中广播消息包括小区标识、信息补偿值和位置区编码。本发明通过判断终端所在小区基站广播消息的方式,实现了提高伪基站识别率高的技术效果,进而解决了相关技术中由于只通过判断接收到的短消息时候包含敏感信息来识别伪基站而导致识别率低的技术问题。
可选实施例2
根据本发明实施例的另一方面,还提供了一种伪基站的识别装置。图6是根据本发明实施例的一种伪基站的识别装置的结构框图,如图6所示,该装置包括:获取模块40;确定模块42,与获取模块40耦合连接。
获取模块40,设置为获取终端所在基站的小区广播参数。
可选地,上述终端10可以但不限于手机、上网卡、笔记本。基站20的小区范围有若干个终端10并与基站20保持通讯连接,获取模块40可以通过基站20发送或者转发给终端10的数据消息中获取基站20的小区广播参数,获取模块40还可以向基站20发送查询小区广播参数的请求,基站20向获取模块40返回基站20的小区广播参数。
确定模块42,设置为判断上述小区广播参数是否异常,在判断结果为是时,确定上述基站为伪基站。
可选地,获取模块40获取基站20的小区广播参数之后,由于小区广播参数包括多项参数,如小区标识、信息补偿值、位置区编码、下行速率等,在实际判断过程中,可以选择和正常通信的基站差别较明显的参数来判断,如小区标识、信息补偿值、位置区编码。当确定模块42判断上述小区广播参数的结果为广播参数为异常时,就确定终端10所在小区的基站20为伪基站。
可选地,在确定模块42确定基站20为伪基站后,还可以生成报警消息来通知终端10,或者通知伪基站20,还可以在网络服务器侧进行标记,来给用户风险提示。
图7是根据本发明实施例的伪基站的识别装置的可选结构框图一,如图7所示,该实施例中所选的小区广播参数为小区标识,确定模块42还包括:第一比对模块500;第一确定模块502,与第一比对模块500耦合连接。
第一比对模块500,设置为将上述基站的小区标识与预先设置的第一集合内的值进行比对。
可选地,第一集合内的值可以为正常基站的小区标识,也可以为异常基站的小区标识,也就是说,第一比对模块500既可以将获取的小区标识和正常的小区标识集合进行比对,也可以将获取的小区标识和异常的小区标识集合进行比对。终端从正常基站进去伪基站的小区复位之内后,一定会有小区标识(cellID)的切换,通过比对切换后的cellID可以得出小区的基站20是否为伪基站。
第一确定模块502,设置为在比对结果指示上述小区标识为异常值时,确定上述基站为上述伪基站。
可选地,由于正常基站的小区标识都是符合通信协议的正常值,而伪基站对应的小区标识一般是异常值如0,具体还可以参照运营商的数据表确定正常值和异常值,,当第一比对模块500将获取的小区标识和正常的小区标识集合进行比对时,获取的小区标识没有在正常的小区标识集合内,则确定基站20为伪基站,当第一比对模块50将获取的小区标识和异常的小区标识集合进行比对时,获取的小区标识在异常的小区标识集合内,第一确定模块502则确定基站20为伪基站。
而通过第一比对模块500将获取的小区标识和第一集合内的值进行比对之后,如果指示cellID是不为异常值,则接下来结合信号补偿值或LAC做进一步的判定。
图8是根据本发明实施例的伪基站的识别装置的可选结构框图二,如图8所示,该实施例中所选的小区广播参数为信号补偿值,确定模块还包括:判断模块504,与第一比对模块500耦合连接;第二确定模块506,与判断模块504耦合连接。
判断模块504,设置为判断上述信号补偿值是否大于等于预定阈值。
可选地,可以将预定阈值设定为10dbm,判断模块504判断获取的广播参数消息中的信号补偿值是否大于等于10dbm。伪基站为了隐蔽性,一般体积不大,所发射的功率也不会特别大。而运行时为了将用户终端信号强制连接到该设备上,会将信号补偿值设置的较高。在小区重选的C2准则中,对于邻小区,该参数就是信号强度的偏移量,对比正常小区该值的设置,异常小区即使信号强度大大低于正常小区也会吸引终端向该小区进行注册,所以判断信号补偿值是否超高可以判断出基站20是否为伪基站。
第二确定模块506,设置为在判断出上述信号补偿值大于等于上述预定阈值时,确定上述基站为上述伪基站。
可选地,当判断模块504判断出获取的广播参数消息中的信号补偿值为50dBm时,则大于预定阈值10dbm,第二确定模块506确定基站20为伪基站,当获取广播参数消 息中的信号补偿值为2dBm时,则小于预定阈值10dbm,则表示基站20为正常基站。
图9是根据本发明实施例的伪基站的识别装置的可选结构框图三,如图9所示,该实施例中所选的小区广播参数为位置区编码LAC,确定模块42还包括:第二比对模块508,与第一比对模块500耦合连接;第三确定模块510,与第二比对模块508耦合连接。
第二比对模块508,设置为将上述LAC与预先设置的第二集合内的LAC进行比对。
可选地,第二集合内的值可以为正常基站位置区编码(LAC),也可以为异常基站的位置区编码,也就是说,即第二比对模块508可以将获取的小区标识和正常的位置区编码集合进行比对,也可以将获取的小区标识和异常的位置区编码集合进行比对。由于伪基站覆盖范围极其有限,用户被强制迁移到伪基站上后,将在一定时间后随时占上正常网络;用户从伪基站信号回到正常网络必须做一次位置更新,位置更新时必须上报伪基站广播消息的LAC。
第三确定模块510,设置为在比对结果指示上述LAC为异常LAC时,确定上述基站为上述伪基站。
由于一般伪基站信号的LAC和正常网络的LAC不一样,通常伪基站信号采用的LAC为0、65534、65535或其他较小的数值,具体还可以参照运营商的LAC数据表。当第二比对模块508将获取的LAC和正常的LAC集合进行比对时,获取的LAC没有在正常的小区标识集合内,第三确定模块510则确定基站20为伪基站,当第二比对模块508将获取的LAC和异常的LAC集合进行比对时,获取的LAC在异常的小区标识集合内,第三确定模块510则确定基站20为伪基站。
图10是根据本发明实施例的伪基站的识别装置的可选结构框图四,如图10所示,该装置由图7、图8和图9组合而成。
图11是根据本发明实施例的伪基站的识别装置的可选结构框图五,如图11所示,该伪基站的识别装置还包括:接收模块60;第一判断模块62;触发模块64,与获取模块40耦合连接。
接收模块60,设置为接收上述基站发送的数据消息。
可选地,基站20发送的数据消息可以但不限于短信消息,推送链接,WAP信息,网页内容。
第一判断模块62,设置为判断上述数据消息中是否有与预设关键字匹配的内容;
可选地,预设关键字可以为黑名单中的号码、数据消息的异常中心号码,还可以是敏感词的排列组合,如银行、打款、中奖等,即数据消息中的敏感信息。第一判断模块62设置为判断接收模块60接收到的数据消息中是否有与预设关键字匹配的内容。
触发模块64,设置为在判断结果为是时,触发获取上述小区广播参数的操作。
可选地,当第一判断模块62判断出接收模块60接收到的数据消息的号码为黑名单中的号码、数据消息的中心号码为异常中心号码、获取的数据消息中还含有敏感词时,就触发获取基站20所在小区的广播参数。
可选地,还可以通过在获取与指定终端10信号连接的基站20的小区广播参数之前判断上述终端10的小区是否发生切换,在上述终端10的小区发生切换时,触发获取上述小区广播参数的操作。
图12是根据本发明实施例的伪基站的识别装置的结构框图六,如图12所示,该伪基站的识别装置还包括:第三判断模块70;第一添加模块72;第二添加模块74;第三添加模块76,其中第三判断模块70和第一确定模块502耦合连接,第二添加模块74和第二确定模块506耦合连接,第三添加模块76和第三确定模块510耦合连接。
第三判断模块70,设置为在比对结果指示上述小区标识为异常值时,确定上述基站为伪基站之后,判断上述位置区编码是否在预先设置的第二集合内;
第一添加模块72,设置为若上述位置区编码不在预先设置的第二集合内,将上述位置区编码添加到上述第二集合内。
第二添加模块74,设置为在判断出上述信号补偿值大于等于上述预定阈值时,确定上述基站为上述伪基站之后,将上述小区标识添加到上述第一集合内;
第三添加模块76,设置为在比对结果指示上述位置区编码为异常值时,确定上述基站为伪基站之后,将上述小区标识添加到上述第一集合内。
由于伪基站伪装的深度不同,通过单独比对或者判断一项广播参数可能不能识别出来,但是伪基站的各项广播参数都是不符合通信协议,通过将识别出来的伪基站的各项广播参数不停地加入到本地数据库第一异常值集合和第二异常值集合中,可以不断完善和收集各个伪基站的广播参数信息,在下一次识别基站时能够更精确和更快速。
在本发明实施例中,采用获取终端所在基站的小区广播参数,判断上述小区广播参数是否异常,在判断结果为是时,确定上述基站为伪基站,在实际对小区广播参数的判断过程中,可以只判断其中一组广播参数,也可以判断其中两组广播参数,或者在判断三组广播参数都为异常时,确定基站为伪基站,其中广播消息包括小区标识、信息补偿值和位置区编码。本发明通过判断终端所在小区基站广播消息的方式,实现了提高伪基站识别率高的技术效果,进而解决了相关技术中由于只通过判断接收到的短消息时候包含敏感信息如广告推销诈骗类的信息来识别伪基站而导致识别率低的技术问题。
需要说明的是,对于前述的各方法实施例,为了简单描述,故将其都表述为一系列的动作组合,但是本领域技术人员应该知悉,本发明并不受所描述的动作顺序的限制,因为依据本发明,某些步骤可以采用其他顺序或者同时进行。其次,本领域技术人员也应该知悉,说明书中所描述的实施例均属于优选实施例,所涉及的动作和模块并不一定是本发明所必须的。
在上述实施例中,对各个实施例的描述都各有侧重,某个实施例中没有详述的部分,可以参见其他实施例的相关描述。
在本申请所提供的几个实施例中,应该理解到,所揭露的装置,可通过其它的方式实现。例如,以上所描述的装置实施例仅仅是示意性的,例如上述单元的划分,仅仅为一种逻辑功能划分,实际实现时可以有另外的划分方式,例如多个单元或组件可以结合或者可以集成到另一个系统,或一些特征可以忽略,或不执行。另一点,所显示或讨论的相互之间的耦合或直接耦合或通信连接可以是通过一些接口,装置或单元 的间接耦合或通信连接,可以是电性或其它的形式。
上述作为分离部件说明的单元可以是或者也可以不是物理上分开的,作为单元显示的部件可以是或者也可以不是物理单元,即可以位于一个地方,或者也可以分布到多个网络单元上。可以根据实际的需要选择其中的部分或者全部单元来实现本实施例方案的目的。
另外,在本发明各个实施例中的各功能单元可以集成在一个处理单元中,也可以是各个单元单独物理存在,也可以两个或两个以上单元集成在一个单元中。上述集成的单元既可以采用硬件的形式实现,也可以采用软件功能单元的形式实现。
上述集成的单元如果以软件功能单元的形式实现并作为独立的产品销售或使用时,可以存储在一个计算机可读取存储介质中。基于这样的理解,本发明的技术方案本质上或者说对相关技术做出贡献的部分或者该技术方案的全部或部分可以以软件产品的形式体现出来,该计算机软件产品存储在一个存储介质中,包括若干指令用以使得一台计算机基站(可为个人计算机、移动终端、服务器或者网络基站等)执行本发明各个实施例上述方法的全部或部分步骤。而前述的存储介质包括:U盘、只读存储器(ROM,Read-Only Memory)、随机存取存储器(RAM,Random Access Memory)、移动硬盘、磁碟或者光盘等各种可以存储程序代码的介质。
以上上述仅为本发明的可选实施例而已,并不用于限制本发明,对于本领域的技术人员来说,本发明可以有各种更改和变化。凡在本发明的精神和原则之内,所作的任何修改、等同替换、改进等,均应包含在本发明的保护范围之内。
工业实用性
在本发明实施例提供的上述技术方案中,应用于伪基站的识别过程中,在该过程中采用获取终端所在基站的小区广播参数,判断上述小区广播参数是否异常,在判断结果为是时,确定上述基站为伪基站,其中广播消息包括小区标识、信息补偿值和位置区编码。本发明通过判断终端所在小区基站广播消息的方式,实现了提高伪基站识别率高的技术效果,进而解决了相关技术中由于只通过判断接收到的短消息时候包含 敏感信息来识别伪基站而导致识别率低的问题,也达到了提高用户体验的效果。

Claims (16)

  1. 一种伪基站的识别方法,包括:
    获取终端所在基站的小区广播参数;
    判断所述小区广播参数是否异常,在判断结果为是时,确定所述基站为伪基站。
  2. 根据权利要求1所述的方法,其中,所述小区广播参数包括:小区标识,判断所述小区广播参数是否异常,在判断结果为是时,确定所述基站为伪基站包括:
    将所述基站的小区标识与预先设置的第一集合内的值进行比对;
    在比对结果指示所述小区标识为异常值时,确定所述基站为所述伪基站。
  3. 根据权利要求1所述的方法,其中,所述小区广播参数包括:信号补偿值,判断所述小区广播参数是否异常,在判断结果为是时,确定所述基站为伪基站包括:
    判断所述信号补偿值是否大于等于预定阈值;
    在判断出所述信号补偿值大于等于所述预定阈值时,确定所述基站为所述伪基站。
  4. 根据权利要求1所述的方法,其中,所述小区广播参数包括:位置区编码LAC,判断所述小区广播参数是否异常,在判断结果为是时,确定所述基站为伪基站包括:
    将所述LAC与预先设置的第二集合内的LAC进行比对;
    在比对结果指示所述LAC为异常LAC时,确定所述基站为所述伪基站。
  5. 根据权利要求1所述的方法,其中,在获取与指定终端信号连接的基站的小区广播参数之前,包括:
    接收所述基站发送的数据消息;
    判断所述数据消息中是否有与预设关键字匹配的内容;
    在判断结果为是时,触发获取所述小区广播参数的操作。
  6. 根据权利要求1所述的方法,其中,在获取与指定终端信号连接的基站的小区广播参数之前,包括:
    判断所述终端的小区是否发生切换;
    在所述终端的小区发生切换时,触发获取所述小区广播参数的操作。
  7. 根据权利要求2所述的方法,其中,所述小区广播参数还包括:位置区编码LAC,其中,在确定所述基站为伪基站之后,所述方法还包括:
    判断所述位置区编码是否在预先设置的第二集合内;
    若所述位置区编码不在预先设置的第二集合内,则将所述位置区编码添加到所述第二集合内。
  8. 根据权利要求3或4所述的方法,其中,
    在判断出所述信号补偿值大于等于所述预定阈值时,确定所述基站为所述伪基站之后,所述方法还包括:将小区标识添加到第一集合内;
    在比对结果指示所述位置区编码为异常值时,确定所述基站为伪基站之后,所述方法还包括:将所述小区标识添加到所述第一集合内。
  9. 一种伪基站的识别装置,包括:
    获取模块,设置为获取终端所在基站的小区广播参数;
    确定模块,设置为判断所述小区广播参数是否异常,在判断结果为是时,确定所述基站为伪基站。
  10. 根据权利要求9所述的装置,其中,所述小区广播参数包括:小区标识,其中,所述确定模块包括:
    第一比对模块,设置为将所述基站的小区标识与预先设置的第一集合内的值进行比对;
    第一确定模块,设置为在比对结果指示所述小区标识为异常值时,确定所述基站为所述伪基站。
  11. 根据权利要求9所述的装置,其中,所述小区广播参数包括:信号补偿值,其中,所述确定模块包括:
    判断模块,设置为判断所述信号补偿值是否大于等于预定阈值;
    第二确定模块,设置为在判断出所述信号补偿值大于等于所述预定阈值时,确定所述基站为所述伪基站。
  12. 根据权利要求9所述的装置,其中,所述小区广播参数包括:位置区编码LAC,其中,所述确定模块包括:
    第二比对模块,设置为将所述LAC与预先设置的第二集合内的LAC进行比对;
    第三确定模块,设置为在比对结果指示所述LAC为异常LAC时,确定所述基站为所述伪基站。
  13. 根据权利要求9所述的装置,其中,所述装置还包括:
    接收模块,设置为接收所述基站发送的数据消息;
    第一判断模块,设置为判断所述数据消息中是否有与预设关键字匹配的内容;
    第一触发模块,设置为在判断结果为是时,触发获取所述小区广播参数的操作。
  14. 根据权利要求9所述的装置,其中,所述装置还包括:
    第二判断模块,设置为判断所述终端的小区是否发生切换;
    第二触发模块,设置为在所述终端的小区发生切换时,触发获取所述小区广播参数的操作。
  15. 根据权利要求10所述的装置,其中,所述小区广播参数还包括:位置区编码LAC,其中,所述装置还包括:
    第三判断模块,设置为在比对结果指示所述小区标识为异常值时,确定所述基站为伪基站之后,判断所述位置区编码是否在预先设置的第二集合内;
    第一添加模块,设置为若所述位置区编码不在预先设置的第二集合内,将所述位置区编码添加到所述第二集合内。
  16. 根据权利要求11或12所述的装置,其中,所述装置还包括:
    第二添加模块,设置为在判断出所述信号补偿值大于等于所述预定阈值时,确定所述基站为所述伪基站之后,将小区标识添加到第一集合内;
    第三添加模块,设置为在比对结果指示所述位置区编码为异常值时,确定所述基站为伪基站之后,将所述小区标识添加到所述第一集合内。
PCT/CN2015/098230 2015-02-25 2015-12-22 伪基站的识别方法和装置 WO2016134608A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201510087392.4A CN105992214A (zh) 2015-02-25 2015-02-25 伪基站的识别方法和装置
CN201510087392.4 2015-02-25

Publications (1)

Publication Number Publication Date
WO2016134608A1 true WO2016134608A1 (zh) 2016-09-01

Family

ID=56787893

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2015/098230 WO2016134608A1 (zh) 2015-02-25 2015-12-22 伪基站的识别方法和装置

Country Status (2)

Country Link
CN (1) CN105992214A (zh)
WO (1) WO2016134608A1 (zh)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN106454848A (zh) * 2016-12-21 2017-02-22 荆楚理工学院 一种伪基站识别方法及设备
CN113490143A (zh) * 2021-07-19 2021-10-08 北京工业大学 一种错误基站和重复基站筛查修正的方法

Families Citing this family (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN106792710A (zh) * 2017-01-16 2017-05-31 北京奇虎科技有限公司 基于用户终端位置识别伪基站的方法及装置
CN109068330B (zh) * 2018-10-29 2022-01-11 Oppo广东移动通信有限公司 伪基站识别处理方法、设备及存储介质

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP2003818A1 (en) * 2007-06-13 2008-12-17 Nethawk Oyj A man-in-the-middle detector and a method using It
CN103796241A (zh) * 2014-01-28 2014-05-14 工业和信息化部电信研究院 一种基于终端上报信息判断和定位伪基站的方法
CN103888965A (zh) * 2014-02-21 2014-06-25 工业和信息化部电信传输研究所 一种伪基站定位方法
CN104125571A (zh) * 2014-07-03 2014-10-29 北京大学 一种伪基站的检测与抑制方法
CN104284337A (zh) * 2014-10-11 2015-01-14 河南天安润信信息技术有限公司 一种基站检测方法及系统

Family Cites Families (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103648096B (zh) * 2013-12-11 2017-03-29 北京联合大学 一种非法基站入侵的快速检测与定位方法
CN104244250A (zh) * 2014-09-05 2014-12-24 北京金山安全软件有限公司 一种识别伪基站的方法及装置
CN104244252B (zh) * 2014-09-30 2018-06-01 北京金山安全软件有限公司 识别伪基站的方法和装置

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP2003818A1 (en) * 2007-06-13 2008-12-17 Nethawk Oyj A man-in-the-middle detector and a method using It
CN103796241A (zh) * 2014-01-28 2014-05-14 工业和信息化部电信研究院 一种基于终端上报信息判断和定位伪基站的方法
CN103888965A (zh) * 2014-02-21 2014-06-25 工业和信息化部电信传输研究所 一种伪基站定位方法
CN104125571A (zh) * 2014-07-03 2014-10-29 北京大学 一种伪基站的检测与抑制方法
CN104284337A (zh) * 2014-10-11 2015-01-14 河南天安润信信息技术有限公司 一种基站检测方法及系统

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN106454848A (zh) * 2016-12-21 2017-02-22 荆楚理工学院 一种伪基站识别方法及设备
CN106454848B (zh) * 2016-12-21 2023-07-18 荆楚理工学院 一种伪基站识别方法及设备
CN113490143A (zh) * 2021-07-19 2021-10-08 北京工业大学 一种错误基站和重复基站筛查修正的方法
CN113490143B (zh) * 2021-07-19 2022-11-29 北京工业大学 一种错误基站和重复基站筛查修正的方法

Also Published As

Publication number Publication date
CN105992214A (zh) 2016-10-05

Similar Documents

Publication Publication Date Title
CN103891332B (zh) 检测可疑无线接入点
CN105162768B (zh) 检测钓鱼Wi-Fi热点的方法及装置
CN105722090B (zh) 自动识别伪基站的控制方法和装置
CN105025490A (zh) 一种伪基站的识别方法及装置
WO2016134608A1 (zh) 伪基站的识别方法和装置
CN104244254A (zh) 基于短信中心号码检测伪基站的方法和装置
CN107343325A (zh) 一种数据传输方法、装置及终端
CN106899948B (zh) 伪基站发现方法、系统、终端及服务器
WO2016131289A1 (zh) 无线热点安全性检测方法、装置及用户设备
CN107333247A (zh) 短消息处理方法、装置及系统
CN104394533A (zh) 无线保真WiFi连接方法、服务器及终端
CN106998554B (zh) 一种伪基站的识别方法及装置
CN108093404B (zh) 一种信息处理方法及装置
CN104166917B (zh) Nfc交易事件的通知方法及系统
CN107659999A (zh) Wifi连接方法及设备
WO2019052464A1 (zh) 伪基站识别方法、设备及计算机可读存储介质
US20220408253A1 (en) Method and System for Authenticating a Base Station
CN104618853A (zh) 一种消息推送方法、装置及系统
WO2012089061A1 (zh) 一种识别并阻止设备发送垃圾短信的方法、设备和系统
CN108235310A (zh) 识别伪装电话号码的方法、服务器以及系统
CN105245494A (zh) 一种网络攻击的确定方法及装置
CN105490913A (zh) 即时消息处理方法及装置
CN108271156B (zh) 一种鉴别伪基站的方法及装置
CN103108316A (zh) 空中写卡认证方法、装置和系统
CN112567780B (zh) 一种伪基站识别方法及装置

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 15883044

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 15883044

Country of ref document: EP

Kind code of ref document: A1