| With the commercialization of 5G,telecom carriers have accelerated the construction and deployment of 5G technology.5G includes access network and core network.The access network is decentralized,while the core network is more centralized,and the security of the core network also directly affects the reliability of 5G system.The existing research mainly focuses on the research of 5G security solutions,and there are still potential vulnerabilities in the implementation of 5G protocol.Therefore,it has strong practical and engineering significance to study the intelligent malicious detection technology of 5G core network protocol from the perspective of traffic,without affecting the operation of 5G subjects.Based on the existing 5 G security research,this article aims at the security risks of the SBI interface of the 5G core network,combines the existing malicious web request detection technology,builds a virtual environment of the core network,analyzes the data request mode in the 5G core network,and explores the security solutions of the SBI interface of the 5G core network.The main research contents of this paper include the slow DDos attack detection scheme of the HTTP/2 protocol in the 5G core network,and the attack detection scheme of sending malicious parameters which is common in the SBI interface.Aiming at the HTTP/2 protocol adopted in 5G core network,this paper proposes the types of slow DDos attacks and the corresponding Multi-filter feature extraction method based on integration.The experimental results show that,according to the selected features,the effect of decision tree or random forest classifier with a time window of 50ms can achieve the best effect in HTTP/2 DDos attack detection.For the abnormal parameters of 5G core network SBI interface,this paper proposes an abnormal parameter detection method using intelligent regular expression and hidden Markov algorithm,which can generate a model and establish a behavior baseline without abnormal samples.Compared with the white list mechanism,it has good universality.The experiment can achieve a high recognition rate of abnormal parameters.In addition,in the process of this detection algorithm,for RESTful interface,this paper also proposes an intelligent separation path and user parameters method based on RDP algorithm. |