Signaling firewall system and implementation method
Technical field
The present invention relates to network communications technology field, relate in particular to a kind of signaling firewall system and implementation method.
Background technology
Along with the development of mobile network value-added service, increasing third party's value increasing platform is used the signaling network of access telecom operators.The concept that signaling network in the traditional concept is perfectly safe is gradually desalination, along with the increase of using, has also occurred dividing of " credible " signaling and " insincere " signaling in the signaling message.
So-called " insincere " signaling typically refers to because the signaling message part that third party's application platform is initiated, and the signaling of this part is because varying of using, and often has personalized and can writing.Namely " insincere " signaling exists according to the feature of using rewritable, and this feature has caused safeguards upper great pressure, so that manage more disordering, also causes very big hidden danger for signaling network safety.
At present, telecom operators mainly realize by system the management of this part " insincere " signaling, for the business supervision of third-party platform, still are blank on technological means.Can only by complain afterwards or regularly signalling analysis find that third-party platform sends the situations such as unauthorized message, inefficiency can't be accomplished real-time guarantee.
The applicant is on December 31st, 2009 in the applying date, application number discloses based on the thought without signalling point mode access signaling fire compartment wall in the patent of invention of " 200910247839.4 ", that is: system is made of some the Message Processing machines and the management server that access in signaling network, the Message Processing machine need to carry out in the signaling link of gating and filtration signaling message to be serially connected with without the signaling point code mode, when signaling message is flowed through this device, carry out gating and filter operation to signaling message, reach the effect of signaling fire compartment wall.Yet, but not from the signaling management and control angle of signaling fire compartment wall to third-party platform, set forth the signaling fire compartment wall for the signaling message management and control mode of platform application, and application rule is formulated principle.
Summary of the invention
The object of the invention is to overcome the defective of prior art and a kind of signaling firewall system and implementation method are provided, thereby on the basis that does not change existing telecommunications network, by in the signaling link of third-party platform access, introducing independently firewall system, conveniently, safely, effectively realize the legal standard of signaling network message, simultaneously existing communication net switching equipment and signaling equipment are not needed to increase extra disposal ability yet.
The technical scheme that realizes above-mentioned purpose is:
A kind of signaling firewall system of one of the present invention, it is connected between signaling network and the some third-party platforms by signaling link, this system comprises and described some third-party platforms some signaling firewall boxs one to one, and a Business Management Platform, wherein:
Every signaling firewall box is connected between described signaling network and the corresponding third-party platform by described each signaling link, connects simultaneously described Business Management Platform; Described every signaling firewall box has three functions, and the first, gather and analyze the signaling message that transmits in the link, message code and content are judged in the identification message source, carry out the message of triggering rule is carried out masking operation; The second, the related signaling message of collection and the signaling message of shielding are sent to described Business Management Platform; The 3rd, carry out from the business rule of the described affair management platform of industry and revise synchronously order, and regularly to the described Business Management Platform state of reporting;
Business Management Platform links to each other with described each signaling firewall box by data-interface; It has three functions, and the first, receive the related signaling message of described each signaling firewall box transmission and the signaling message of shielding, and message is carried out statistical analysis by business rule, form the business rule of invalid message interception quasi real time; The second, described each signaling firewall box database is implemented the synchronous modification of invalid message interception service regular data, finish the loading of this database or check request; The 3rd, detect the operating state of described each signaling firewall box.
Above-mentioned signaling firewall system, wherein, described signaling link comprises the IP link of TDM (time division multiplexing) link and IP (internet communication agreement) carrying.
Above-mentioned signaling firewall system, wherein, described each signaling firewall box is connected on the described signaling link in coupling serial connection mode, and each signaling firewall box detects the two-way signaling message of flowing through separately.
Above-mentioned signaling firewall system, wherein, described each signaling firewall box is connected on the described signaling link in the high-ohmic cross-connection mode, and each signaling firewall box detects the two-way signaling message of flowing through separately.
Above-mentioned signaling firewall system, wherein, described each signaling firewall box is the autonomous device without signaling point code, and it is connected in separately needs between described signaling network and the corresponding third-party platform identify and the described signaling link of processing operation signaling message.
Above-mentioned signaling firewall system, wherein, described each signaling firewall box is when carrying out the message screening operation, initiate user's number inquiry number-associated database according to the business in the address message, it is tables of data, detect to analyze the logic rules that is associated with this number, when recognizing the professional number of initiating when being the white list user, the then straight-through transmission of message; When business is initiated number when being unauthorized message for black list user or message, with message screening, and done corresponding processing the such as follow-up storage by described Business Management Platform.
Above-mentioned signaling firewall system, wherein, described each signaling firewall box is equipment independently separately, can be integrated in the telecommunication apparatus, also can attachedly make the essential companion's formula safety guarantee equipment of third-party platform.
The implementation method of a kind of signaling firewall system of two of the present invention comprises the following steps:
Event detection and event handling allocation step, described signaling firewall box detects a kind of event, if this event is the signaling message that detects in the transmission, and to recognize this signaling message be business rule when triggering type of message, carries out next step;
The shield analysis treatment step, described signaling firewall box is identified according to the service-user number that message source address, message destination address, message opcode, message contain, select this signaling message is shielded according to each recognition result, or this signaling message of transparent transmission.
In the implementation method of above-mentioned signaling firewall system, wherein, described shield analysis treatment step comprises:
At first, described signaling firewall box extracts message opcode, judge whether service authorization type of message of described signaling message, if not, then this signaling message is shielded and will shield the result and send described Business Management Platform record statistics to, if grant message type is then carried out next step;
Secondly, described signaling firewall box is analyzed message source and the destination address of this signaling message, judge whether this signaling message is initiated by the platform of authorizing, and the receiving end network element that whether mails to mandate, if all meet, further next step then then shields and will shield the result and send described Business Management Platform record to and add up otherwise this signaling message shielded to this signaling message;
At last, described signaling firewall box is analyzed contained Subscriber Number in this signaling message, and the registered user who whether registers is if meet, then this message of transparent transmission does not send described Business Management Platform record statistics to if meet then this signaling message is shielded and will shield the result.
The invention has the beneficial effects as follows: the present invention realizes the legal standard of signaling network message conveniently, safely, effectively by introduce independently firewall system in the signaling link of third-party platform access.Simultaneously, the existing communication network configuration is not being carried out under the large transformation prerequisite, by the signaling Real Time Monitoring to access third-party platform in the signaling network, analyze the signaling message of " insincere " and shield, filled up blank to the supervision of third-party platform, avoided transforming that the operation flow that related network elements brings changes, investment is large, performance difficulty, be difficult for introducing new function, safeguard the problems such as complicated.Do not need to increase the extra process ability of conventional network equipment yet, with less input, be independent of the existing communication network, online in multi-operator mobile communication in large scale, the safety guarantee to signaling network is provided.
Description of drawings
Fig. 1 is the networking schematic diagram of one of the present invention's signaling firewall system;
Fig. 2 is one of the present invention's signaling firewall box application protocol figure;
Fig. 3 is the handling process schematic diagram of one of the present invention's signaling firewall system.
Embodiment
The invention will be further described below in conjunction with accompanying drawing.
See also Fig. 1 and in conjunction with Fig. 2, one of the present invention's signaling firewall system, it is connected between signaling network 1 and the some third-party platforms 2 by signaling link, this system comprises and some third-party platforms 2 some signaling firewall boxs 3 one to one, and a Business Management Platform 4, wherein:
Every signaling firewall box 3 is connected between signaling network 1 and the corresponding third-party platform 2 by each signaling link, connects simultaneously Business Management Platform 4; Every signaling firewall box 3 has three functions, and the first, gather and analyze the signaling message that transmits in the link, message code and content are judged in the identification message source, carry out the message of triggering rule is carried out masking operation; The second, the related signaling message of collection and the signaling message of shielding are sent to Business Management Platform 4; The 3rd, carry out and to revise synchronously order from the business rule of Business Management Platform 4, and regularly to Business Management Platform 4 state of reporting;
Business Management Platform 4 links to each other with each signaling firewall box 3 by data-interface; It has three functions, and the first, receive the related signaling message of each signaling firewall box 3 transmission and the signaling message of shielding, and message is carried out statistical analysis by business rule, form the business rule of invalid message interception quasi real time; The second, each signaling firewall box 3 database (not shown) is implemented the synchronous modification of invalid message interception service regular data, finish the loading of this database (not shown) or check request; The 3rd, detect the operating state of each signaling firewall box 3.
The signaling link of signaling firewall box 3 accesses is not limited only to the TDM link, is equally applicable to access the IP link of IP carrying.
Signaling firewall box 3 can be to mate the serial connection mode to be connected on the signaling link, and each signaling firewall box 3 detects the two-way signaling message of flowing through separately; Signaling firewall box 3 also can be to be connected on the signaling link in the high-ohmic cross-connection mode, and each signaling firewall box 3 detects the two-way signaling message of flowing through separately.
Signaling firewall box 3 is the autonomous devices without signaling point code, it is connected in separately needs between signaling network 1 and the corresponding third-party platform 2 identify and the signaling link of processing operation signaling message, or be integrated in the telecommunication apparatus, or the attached essential companion's formula safety guarantee equipment of third-party platform 2 of doing.
Each signaling firewall box 3 is when carrying out the message screening operation, initiate user's number inquiry number-associated database according to the business in the address message, it is tables of data, detect and analyze the logic rules that is associated with this number, when recognizing the professional number of initiating when being the white list user, then message is straight-through transmits; When business is initiated number when being unauthorized message for black list user or message, with message screening, and done corresponding processing the such as follow-up storage by Business Management Platform 4.
See also Fig. 3, the implementation method of a kind of signaling firewall system of two of the present invention comprises the following steps:
Event detection and event handling allocation step, signaling firewall box 3 detects a kind of event, if this event is the signaling message that detects in the transmission, and to recognize this signaling message be business rule when triggering type of message, carries out next step;
The shield analysis treatment step, signaling firewall box 3 is identified according to the service-user number that message source address, message destination address, message opcode, message contain, select this signaling message is shielded according to each recognition result, or this signaling message of transparent transmission.
Above-mentioned shield analysis treatment step comprises:
At first, signaling firewall box 3 extracts message opcode, judges whether service authorization type of message of described signaling message, if not, then this signaling message is shielded and will shield the result and send Business Management Platform 4 record statistics to, if grant message type is then carried out next step;
Secondly, signaling firewall box 3 is analyzed message source and the destination address of this signaling message, judge whether this signaling message is initiated by the platform of authorizing, and the receiving end network element that whether mails to mandate, if all meet, further next step then then shields and will shield the result and send Business Management Platform 4 records to and add up otherwise this signaling message shielded to this signaling message;
At last, signaling firewall box 3 is analyzed contained Subscriber Number in this signaling message, and the registered user who whether registers is if meet, then this message of transparent transmission does not send Business Management Platform 4 record statistics to if meet then this signaling message is shielded and will shield the result.
Consult Fig. 1, the bearing mode of the signaling link of signaling firewall box 3 accesses can be TDM or IP.This kind networking is applicable to all commmunication companies, CHINAUNICOM, telecommunications company, for the signaling message from third-party platform 2, realizes gating and function of shielding.
Fig. 2 is the application scenarios of signaling firewall box, and the access point of mobile service platform MAP (Mobile Application Part) message core network access is STP; The access point of mobile service platform voice telephone traffic core network access is mobile network TMGW (Trunking Media Gateway) gateway exchange; The access point that the fixed network services platform is opened ISUP (ISDN User Part) relaying core network access takes tandem exchange for the spy; The access point that the fixed network services platform is opened IP relaying core network access is overlay network SS (Softswtich) or IMS (IP Multimedia Subsystem) IP multimedia system, signaling flow is linked into overlay network SS or IMS by I-SBC, and (Session Border Controll between net: Inter-network Session BordorControllor) the media switching enters soft exchanging network or IMS circuit domain to Media Stream by I-SBC.In addition, in Fig. 2, E1 represents the pulse-code modulation standard, and RTP represents real time transport protocol, and PABX represents stored-program control exchange.
This signaling firewall system is applicable in these mobile services and fixed network services to be connected in series the application of support basic agreement, MAP as shown in Figure 2, ISUP, SIP (Session Initiation Protocol) without the signalling point mode.
Fig. 3 be one of the present invention the handling process schematic diagram of signaling firewall system, after signaling firewall box 3 enters event detection and event handling allocator, detect the signaling message in the transmission, command code, source and destination address and the message content of identification signaling message, to meeting the message transparent transmission that lays down a regulation and authorize, the message that breaks the rules is shielded.
In sum, 3 pairs of signaling messages of flowing through of signaling firewall box among the present invention carry out collection analysis, according to built-in rule the signaling message of flowing through is judged, message to triggering rule shields, carry out the data management statistics by Business Management Platform 4, and the generation black and white lists, signaling firewall box 3 is carried out business rule and user data synchronization.Thereby on the basis that does not change existing telecommunications network, conveniently, safely, effectively realize the legal standard of signaling network message, simultaneously existing communication net switching equipment and signaling equipment are not needed to increase extra disposal ability yet.
Above-described embodiment provides to being familiar with the person in the art and realizes or use of the present invention; those skilled in the art can be in the situation that do not break away from invention thought of the present invention; above-described embodiment is made various modifications or variation; thereby protection scope of the present invention do not limit by above-described embodiment, and should be the maximum magnitude that meets the inventive features that claims mention.