Botnet detection system and method for IoT environment, and storage medium
A botnet and environment technology, applied in the field of intrusion detection, can solve problems such as failure to operate normally, and achieve the effect of reducing complexity and reducing complexity
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Publication Date
- 2021-11-16
Smart Images

Figure 1 
Figure 2 
Figure 3
Abstract
Description
technical field
[0001] A system and method for detecting a botnet in an IoT environment, which is used for detecting a botnet in an IoT environment, belongs to the field of intrusion detection technology, and specifically adopts an offline method to design an automated IoT traffic detection system, and can use The detection model of the detection system is updated in a plug-in way. Background technique
[0002] IoT devices are showing a momentum of rapid development in today's Internet. Communication technologies such as the Internet of Things significantly surpass the perception of the surrounding environment by traditional technologies, which endow devices with the ability to collect, quantify and understand the surrounding environment. The Internet of Things is one of the fastest growing fields in the history of computers. A survey conducted by CISCO shows that the number of Internet of Things devices is rising every year, exceeding 50 billion in 2020, and 44ZB of data w...
Examples
Embodiment Construction
[0050] The present invention will be further described below in conjunction with the accompanying drawings and specific embodiments.
[0051] The system is deployed for the IoT device RaspberryPi 4B, the open source IoT botnet dataset N-baiot is used as the detection core plug-in training data, and the open source IoT botnet dataset Kitsune:Mirai is used as the simulated network environment data for system description.
[0052] A system for detecting botnets in an IoT environment, including:
[0053] Traffic collector: used to monitor the traffic of monitored IoT devices, and obtain traffic data packets that meet the rules to be detected based on the whitelist mechanism;
[0054] Storage unit: used to store the traffic data packets acquired by the traffic collector;
[0055] Data packet parser: Based on the improved wireless packet capture tool under the linux system, it analyzes the content of the traffic data packet in the storage unit, and obtains IP information after pars...