FTTR-based home network security monitoring method, apparatus and device, and medium
By building an initial security detection model in the FTTR network and using the DBSCAN algorithm and similarity adjustment, the false alarm rate problem caused by the access of new devices is solved, and the accuracy of home network security monitoring is improved.
Patent Information
- Application Number
- CN202511169046.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-20
- Publication Date
- 2025-09-30
- Estimated Expiration
- 2045-08-20
AI Technical Summary
Traditional home network security monitoring methods cannot automatically adapt to the changes in feature space caused by the addition of new devices, resulting in a sharp increase in false alarm rates.
An initial security detection model is built based on FTTR. By collecting historical behavior data of home network devices, clustering is performed using the DBSCAN algorithm, and the similarity between the new device behavior data and the historical data is calculated. The preset parameters are adjusted based on the similarity and access time, and the initial model is corrected to adapt to the new device.
It effectively reduces the false alarm rate when new devices are connected and improves the accuracy of home network security monitoring.
Smart Images

Figure CN120729623A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of data processing, and in particular to a method, apparatus, device and medium for monitoring home network security based on FTTR. Background Art
[0002] Fiber to the Room (FTTR), as a next-generation home network architecture, achieves gigabit-level bandwidth coverage and millisecond-level low-latency transmission through all-optical networking, providing highly reliable connectivity for smart home devices. However, with the exponential growth of data from home network devices and the increasing heterogeneity of device types, home network security threats are becoming increasingly covert and collaborative. Traditional home network security monitoring methods rely on static rules and offline training models, making them difficult to address challenges arising from dynamic device access and sudden changes in behavior patterns.
[0003] When new devices are connected, traditional anomaly detection models trained based on historical data cannot automatically adapt to the changes in feature space caused by the connection of new devices. For example, after a smart socket is connected, its periodic signal is misjudged as a port scan attack due to differences in protocol formats, and the false alarm rate rises sharply. Summary of the Invention
[0004] The main purpose of this application is to provide a FTTR-based home network security monitoring method, device, equipment and medium, aiming to solve the technical problem that when a new device is connected, the traditional anomaly detection model trained based on historical data cannot automatically adapt to the feature space changes caused by the access of the new device, resulting in a sudden increase in the false alarm rate.
[0005] To achieve the above-mentioned objectives, the present application provides a FTTR-based home network security monitoring method, comprising: collecting historical behavior data of each device in the home network and constructing an initial security detection model based on the historical behavior data, preset parameters and the DBSCAN algorithm; when a new device is connected, collecting the behavior data of the new device and calculating the similarity between the behavior data and the historical behavior data of each of the devices; adjusting the preset parameters based on the connection time of the new device and the similarity; correcting the initial security detection model based on the adjusted preset parameters, and completing home network security monitoring based on the corrected initial security detection model.
[0006] Optionally, the input of the initial security detection model is the historical behavior data, and the output of the initial security detection model is anomalies and multiple clusters.
[0007] Optionally, the calculation of the similarity between the behavior data and the historical behavior data of each of the devices includes: determining the center point of each of the clusters based on the clustering results obtained based on the initial security detection model; and calculating the similarity between the behavior data and each cluster based on the historical behavior data corresponding to the center point of each cluster.
[0008] Optionally, adjusting the preset parameters based on the access time of the new device and the similarity includes: determining the initial dynamic parameters of each cluster based on the similarity; adjusting the preset parameters based on the initial dynamic parameters of each cluster and the access time of the new device to obtain the dynamic parameters of each cluster; and correcting the initial security detection model based on the adjusted preset parameters includes: correcting the initial security detection model based on the dynamic parameters of each cluster.
[0009] Optionally, adjusting the preset parameters based on the initial dynamic parameters of each cluster and the access time of the new device to obtain the dynamic parameters of each cluster includes: adjusting the preset parameters using the following formulas (1) and (2) to obtain the dynamic parameters of each cluster:
[0010] Where, Indicates the The dynamic parameters of the cluster, Indicates the The initial dynamic parameters of the clusters, Indicates the preset parameters, Indicates the preset maximum parameter, Indicates the The similarity of clusters, Indicates the access time of the new device, Indicates the preset adjustment constant.
[0011] Optionally, before constructing the initial security detection model based on the historical behavior data, preset parameters and DBSCAN algorithm, the method also includes: extracting features from the historical behavior data to obtain feature data; constructing the initial security detection model based on the historical behavior data, preset parameters and DBSCAN algorithm includes: constructing the initial security detection model based on the feature data, preset parameters and DBSCAN algorithm.
[0012] Optionally, the feature extraction of the historical behavior data to obtain feature data includes: determining an abnormal label based on the historical behavior data; calculating the correlation between each historical behavior data and the abnormal label; and feature extraction of the historical behavior data based on the correlation to obtain feature data.
[0013] In addition, to achieve the above-mentioned purpose, the present application also provides a FTTR-based home network security monitoring device, including: an initial security detection model construction module, used to collect historical behavior data of each device in the home network and construct an initial security detection model based on the historical behavior data, preset parameters and DBSCAN algorithm; a new device access module, used to collect the behavior data of the new device when a new device is accessed and calculate the similarity between the behavior data and the historical behavior data of each device; a parameter adjustment module, used to adjust the preset parameters based on the access time of the new device and the similarity; a model adjustment module, used to correct the initial security detection model based on the adjusted preset parameters, and complete home network security monitoring based on the corrected initial security detection model.
[0014] The present application also provides an FTTR-based home network security monitoring device, comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the above-mentioned FTTR-based home network security monitoring method.
[0015] The present application also provides a computer-readable storage medium, comprising: a computer program stored therein, wherein when the computer program is executed by a processor, the computer program implements the above-mentioned FTTR-based home network security monitoring method.
[0016] This application proposes a method, apparatus, device, and medium for monitoring home network security based on FTTR. First, an initial security detection model is constructed based on historical behavioral data representing the network status of historical devices. Second, when a new device is connected, the behavioral data of the new device is collected and the similarity between the new device's behavioral data and the historical behavioral data of each device is calculated. The preset parameters of the initial security detection model are adjusted based on the new device's connection time and similarity. This takes into account the fact that when a new device is just connected, the initial security detection model may produce misjudgments due to the small amount of data. Furthermore, this application also considers that as the new device's connection time increases, the behavioral data of the new device continues to increase, and the behavioral characteristics of the new device gradually emerge. In this case, the preset parameters are gradually reduced as the new device's connection time increases, which can also improve detection accuracy. Finally, the initial security detection model is modified based on the adjusted preset parameters, and home network monitoring is completed based on the modified initial security detection model. This solves the technical problem that when a new device is connected, traditional anomaly detection models trained based on historical data cannot automatically adapt to the changes in the feature space caused by the new device's connection, resulting in a sudden increase in the false alarm rate. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] Figure 1 Flowchart of a method for monitoring home network security based on FTTR according to one embodiment of the present application; Figure 2 This is a structural block diagram of a home network security monitoring device based on FTTR according to an embodiment of the present application; Figure 3 Schematic diagram of the structure of a FTTR-based home network security monitoring device according to one embodiment of the present application.
[0018] The realization of the objectives, functional features and advantages of this application will be further explained in conjunction with embodiments and with reference to the accompanying drawings. DETAILED DESCRIPTION
[0019] It should be understood that the specific embodiments described herein are only used to explain the present application and are not intended to limit the present application.
[0020] In the existing technology, when using anomaly detection models trained based on historical data for home network security monitoring, when new devices are connected, the anomaly detection model cannot automatically adapt to the feature space changes introduced by the connection of new devices. For example, when an anomaly detection model built using the DBSCAN algorithm is connected to a smart socket, its periodic signal is misidentified as an anomaly point by the anomaly detection model due to protocol format differences, resulting in a sudden increase in the false alarm rate.
[0021] To solve the above problems, the present application provides a method, device, equipment and medium for monitoring home network security based on FTTR. The present application solution is introduced in detail below.
[0022] Figure 1 This is a flowchart of a method for monitoring home network security based on FTTR according to an embodiment of the present application, referring to Figure 1 The FTTR-based home network security monitoring method may include the following steps: S1, collecting historical behavior data of each device in the home network and building an initial security detection model based on the historical behavior data, preset parameters and DBSCAN algorithm.
[0023] The historical behavior data for each device includes its network access data over a preset time period. This network access data includes at least network traffic data and device metadata extracted from the traffic data. The preset parameters represent the radius (Eps) and minimum number of neighbors (MinPts) required before using the DBSCAN algorithm.
[0024] It should be noted that this embodiment uses the DBSCAN algorithm to construct an initial security detection model for home network security detection. The DBSCAN algorithm is a density-based clustering algorithm that clusters data by identifying high-density areas and marking points in low-density areas as noise points. In this embodiment, these noise points are generally considered outliers in security detection.
[0025] During the specific implementation process, RF sensors are deployed in every corner of the room to collect the wireless signals of each device, that is, the metadata of each device. At the same time, the SPAN port of the FTTR main gateway is configured to mirror the network traffic to ensure that all data packets entering and leaving the home network can be captured and analyzed.
[0026] Furthermore, the network traffic data of each device within a preset time length is collected through the SPAN port, and the network traffic data includes the amount of uploaded data, the amount of downloaded data, etc.; the metadata of each device is extracted from the network traffic data, and the metadata of each device includes the MAC address, connection time, duration, etc. of each device.
[0027] It's important to note that raw historical behavior data often contains numerous redundant or irrelevant features, and using it directly for network security monitoring can lead to dimensionality problems and noise interference. Feature extraction can effectively reduce data dimensionality and improve detection efficiency by screening out multiple features related to security behavior, such as traffic entropy and cross-protocol access rates. Furthermore, multiple features related to security behavior can amplify the differences between normal and abnormal behavior, improving detection accuracy.
[0028] In one embodiment, before constructing an initial security detection model based on the historical behavior data, preset parameters, and the DBSCAN algorithm, the method of this embodiment may further include: performing feature extraction on the historical behavior data to obtain feature data.
[0029] In the specific implementation process, the historical behavior data of each device is first cleaned, where data cleaning at least includes outlier removal and missing value filling. Then, feature extraction is performed on the cleaned data to obtain feature data.
[0030] In one embodiment, feature extraction is performed on the cleaned data to obtain feature data, which may specifically include: S11. Determine an abnormal label based on the historical behavior data; S12, calculating the correlation between each of the historical behavior data and the abnormal label; S13. Extract features from the historical behavior data based on the correlation to obtain feature data.
[0031] In the specific implementation process, a clustering algorithm or anomaly detection algorithm is used to cluster or detect anomalies on the cleaned data to obtain multiple anomaly labels. It should be noted that in other embodiments, manual labeling can also be used to label the cleaned data based on existing network attack patterns to obtain multiple anomaly labels.
[0032] Furthermore, the correlation between each type of data and the abnormal label in the historical behavior data is calculated, and a preset threshold is set. The preset threshold can be set to 1 / 3 of the number of type data. In the historical behavior data, according to the order of correlation from large to small, the type data before the preset threshold is selected to form a vector as the feature data.
[0033] It is understandable that if the historical behavior data includes the amount of uploaded data and the amount of downloaded data, then the amount of uploaded data in the historical behavior data is one type of data, and the amount of downloaded data in the historical behavior data is another type of data. In addition, multiple abnormal labels are also several types of data in the historical behavior data.
[0034] It should be noted that the correlation coefficient can be used to measure the correlation between each type of data in the historical behavior data and the abnormal label, that is, the correlation coefficient between each type of data in the historical behavior data and the abnormal label is used as the numerical value of the correlation. In other embodiments, the mutual information can also be used to measure the correlation between each type of data in the historical behavior data and the abnormal label. After obtaining the feature data of each device in this embodiment, the feature data needs to be standardized to eliminate the impact of different dimensions of different types of data on the DBSCAN distance calculation.
[0035] It can be understood that in this embodiment, constructing an initial security detection model based on historical behavior data, preset parameters and the DBSCAN algorithm is essentially constructing an initial security detection model based on feature data, preset parameters and the DBSCAN algorithm.
[0036] In the specific implementation process, the construction process of the initial security detection model includes: first setting the preset parameters of the DBSCAN algorithm, inputting the feature data into the DBSCAN algorithm, obtaining multiple clusters and noise points, and then determining the abnormal points and the clusters corresponding to each device based on each cluster and noise point. Among them, the abnormal points are noise points, and the clusters corresponding to each device are determined by the clusters to which their corresponding feature data belongs in the DBSCAN clustering results.
[0037] It should be noted that when using the DBSCAN clustering algorithm to cluster the feature data of devices, since similar types of devices have high similarity in network behavior, in the clustering results, devices of the same type are usually assigned to the same cluster. For example, smart light bulbs and smart thermostats in smart homes are similar in type. Since their network traffic data and radio frequency data are similar, they will be classified into the same cluster by the DBSCAN algorithm.
[0038] S2, when a new device is connected, collecting the behavior data of the new device and calculating the similarity between the behavior data and the historical behavior data of each device; S3: Adjust the preset parameters based on the access time of the new device and the similarity.
[0039] The behavior data of the new device includes network access data at the time of access of the new device, and the network access data includes at least network traffic data and device metadata.
[0040] It's important to note that when a new device is first connected, due to the relatively small amount of data, using the initial security detection model directly for detection can result in misjudgments. Therefore, the preset radius can be adjusted based on the similarity between the new device and historical devices. Clusters with historical devices that have more similar behavior data to the new device will have larger preset radii, reducing the risk of misjudgments. The type of new device is determined and the radius of the corresponding cluster is increased to further reduce the risk of misjudgments. Furthermore, as the new device grows older and its behavioral data continues to accumulate, its behavioral characteristics gradually become apparent. The radius can then be gradually reduced to improve detection accuracy.
[0041] During the specific implementation process, when a new device is connected, the network access data of the new device is collected, and the features of the network access data are extracted to obtain the attention data of the new device. It should be noted that the attention data of the new device is also a vector, and the data type of the vector is the same as that of the feature data.
[0042] Taking any cluster as an example, the center point of the cluster is determined based on the clustering results obtained by the initial security detection model, and the similarity between the attention data of the new device and the feature data corresponding to the center point of the cluster is calculated. The calculated similarity is used as the similarity between the cluster and the behavior data, that is, the new device. It should be noted that the present embodiment may use the DTW distance to calculate the similarity. In other embodiments, other similarity calculation methods may also be used to calculate the similarity. The present embodiment does not specifically limit the similarity calculation method. However, in the present embodiment, the higher the similarity, the more similar it is. Furthermore, since the larger the DTW distance, the less similar it is, the obtained DTW distance needs to be linearly normalized, and then the normalized DTW distance is subtracted from 1 as the similarity.
[0043] In one embodiment, in step S3, adjusting the preset parameters based on the access time of the new device and the similarity may specifically include: S31, determining initial dynamic parameters of each cluster based on the similarity; S32: Adjust the preset parameters based on the initial dynamic parameters of each cluster and the access time of the new device to obtain the dynamic parameters of each cluster.
[0044] The similarity of each cluster is the similarity between the cluster and the behavior data.
[0045] It should be noted that the preset parameters include the radius and minimum number of neighbors that need to be preset before using the DBSCAN algorithm. However, due to the coupling relationship between these two parameters, adjusting both at the same time will often lead to an exponential growth in the parameter search space, increasing the complexity and uncertainty of the algorithm optimization.
[0046] Based on this, this embodiment adopts a single-parameter optimization strategy, focusing on adjusting the neighborhood radius, which is more sensitive to clustering results. It will be appreciated that in this embodiment, adjusting the preset parameter specifically refers to adjusting the preset radius, while the minimum number of neighbors is fixed using an empirical formula based on data characteristics. For example, in this embodiment, the minimum number of neighbors is equal to the number of data types in the network access data plus one. For example, when the network access data includes the amount of uploaded data, the amount of downloaded data, and the duration (i.e., three-dimensional data), the minimum number of neighbors is 4.
[0047] In the specific implementation process, For example, based on the first cluster The similarity of clusters is determined using the following formula (1): Initial dynamic parameters of clusters:
[0048] in, Indicates the The initial dynamic parameters of the clusters, Indicates the preset parameters, Indicates the preset maximum parameter, Indicates the The similarity of clusters. Great need For example, when using the DBSCAN algorithm to cluster network access data, the preset radius value range can be determined based on the k-distance graph in traditional technology. Specifically, You can take the value of a certain position before the inflection point of the k distance graph, The value of a certain position after the inflection point can be taken. Of course, in other embodiments, and Other methods may also be used for setting. This embodiment does not specifically limit the values of the preset parameters and the preset maximum parameters.
[0049] It is understandable that when the similarity between a cluster and the behavioral data is high, it means that the behavioral data of the new device is more likely to fall into the range of the cluster. At this time, increasing the preset parameters of the cluster during the initial operation of the algorithm, that is, the preset radius, can effectively reduce the risk of misjudgment due to insufficient data from new devices.
[0050] Further, the For example, based on the first cluster The initial dynamic parameters of each cluster and the access time of the device are adjusted using the following formula (2) to obtain the first Dynamic parameters of clusters:
[0051] in, Indicates the The dynamic parameters of the cluster, Indicates the The initial dynamic parameters of the clusters, Indicates the preset parameters, Indicates the access time of the new device, Indicates the preset adjustment constant, Is a positive number, in this embodiment You can choose 1.
[0052] It is understandable that as the time of new device access increases, the behavioral data of the new device continues to increase, and the behavioral characteristics of the new device gradually emerge. At this time, gradually reducing the radius can improve the accuracy of detection. Therefore, in formula (2), this embodiment sets the inverse function ,Right now With access time decreases with the increase of and Multiplying them can be understood as adding the access time As the initial dynamic parameters The attenuation factor, then, in formula (2), as the access time The increase, Continuously decreasing (gradually reducing the radius) can improve the accuracy of anomaly detection for new devices.
[0053] S4, correcting the initial security detection model based on the adjusted preset parameters, and completing the home network security monitoring based on the corrected initial security detection model.
[0054] In the specific implementation process, the initial dynamic parameters of each cluster class are used as the starting parameters of the data corresponding to each cluster class, and the initial security detection model is modified as follows: first, the preset parameters of the DBSCAN algorithm initialization phase in the initial security detection model are replaced with the starting parameters; secondly, the preset parameters during the algorithm operation are updated to dynamic parameters.
[0055] Furthermore, security monitoring is performed on the home network after the new device is connected based on the revised initial security detection model.
[0056] The present invention proposes a method for monitoring home network security based on FTTR. First, an initial security detection model is constructed based on historical behavioral data representing the network status of historical devices. Second, when a new device is connected, the behavioral data of the new device is collected and the similarity between the behavioral data of the new device and the historical behavioral data of each device is calculated. The preset parameters of the initial security detection model are adjusted based on the connection time and similarity of the new device. This method takes into account the problem that when a new device is just connected, due to the small amount of data, direct use of the initial security detection model for detection may result in misjudgment. At the same time, this application also considers that as the connection time of the new device increases, the behavioral data of the new device continues to increase, and the behavioral characteristics of the new device gradually emerge. In this case, the preset parameters are gradually reduced as the connection time of the new device increases, which can also improve the accuracy of detection. Finally, the initial security detection model is corrected based on the adjusted preset parameters, and home network monitoring is completed based on the corrected initial security detection model. This method solves the technical problem that when a new device is connected, the traditional anomaly detection model trained based on historical data cannot automatically adapt to the changes in the feature space caused by the new device connection, resulting in a sudden increase in the false alarm rate.
[0057] Based on the above embodiments, Figure 2 FIG. 1 is a structural block diagram of a home network security monitoring device based on FTTR according to an embodiment of the present application. Figure 2 As shown, the FTTR-based home network security monitoring device 200 may include: an initial security detection model building module 210, a new device access module 220, a parameter adjustment module 230 and a model adjustment module 240, wherein: The initial security detection model building module 210 is used to collect historical behavior data of each device in the home network and build an initial security detection model based on the historical behavior data, preset parameters and DBSCAN algorithm; The new device access module 220 is used to collect the behavior data of the new device and calculate the similarity between the behavior data and the historical behavior data of each device when a new device is accessed; The parameter adjustment module 230 is configured to adjust the preset parameters based on the access time of the new device and the similarity; The model adjustment module 240 is used to modify the initial security detection model based on the adjusted preset parameters, and complete the home network security monitoring based on the modified initial security detection model.
[0058] In an exemplary embodiment, the input of the initial security detection model in the initial security detection model construction module 210 is the historical behavior data, and the output of the initial security detection model is anomalies and multiple clusters.
[0059] In an exemplary embodiment, the new device access module 220 can also be used to determine the center point of each cluster based on the clustering results obtained by the initial security detection model; and calculate the similarity between the behavior data and each cluster based on the historical behavior data corresponding to the center point of each cluster.
[0060] In an exemplary embodiment, the parameter adjustment module 230 can also be used to determine the initial dynamic parameters of each cluster based on the similarity; adjust the preset parameters based on the initial dynamic parameters of each cluster and the access time of the new device to obtain the dynamic parameters of each cluster.
[0061] In an exemplary embodiment, the parameter adjustment module 230 may further use the following formulas (1) and (2) to adjust the preset parameters to obtain the dynamic parameters of each cluster:
[0062] Where, Indicates the The dynamic parameters of the cluster, Indicates the The initial dynamic parameters of the clusters, Indicates the preset parameters, Indicates the preset maximum parameter, Indicates the The similarity of clusters, Indicates the access time of the new device, Indicates the preset adjustment constant.
[0063] In an exemplary embodiment, the initial security detection model construction module 210 can also be used to extract features from the historical behavior data to obtain feature data; the construction of the initial security detection model based on the historical behavior data, preset parameters and DBSCAN algorithm includes: constructing an initial security detection model based on the feature data, preset parameters and DBSCAN algorithm.
[0064] In an exemplary embodiment, the initial security detection model construction module 210 can also be used to determine abnormal labels based on the historical behavior data; calculate the correlation between each historical behavior data and the abnormal label; and extract features from the historical behavior data based on the correlation to obtain feature data.
[0065] Those skilled in the art should understand that the division of the various modules in the embodiment is merely a division of logical functions, and in actual application, they can be fully or partially integrated into one or more actual carriers, and these modules can all be implemented in the form of software called through a processing unit, or all be implemented in the form of hardware, or implemented in the form of a combination of software and hardware. It should be noted that the modules in the FTTR-based home network security monitoring device in this embodiment correspond one-to-one to the steps in the FTTR-based home network security monitoring method in the aforementioned embodiment. Therefore, the specific implementation of this embodiment can refer to the implementation of the aforementioned FTTR-based home network security monitoring method, and will not be repeated here.
[0066] Based on the above embodiments, Figure 3 FIG. 1 is a structural diagram of a FTTR-based home network security monitoring device according to an embodiment of the present application. Figure 3 As shown, the electronic device may include: a processor 310, a communication interface 320, a memory 330, and a communication bus 340, wherein the processor 310, the communication interface 320, and the memory 330 communicate with each other via the communication bus 340. The processor 310 may call logic instructions in the memory 330 to execute a method for monitoring home network security based on FTTR, the method comprising: collecting historical behavior data of each device in the home network and constructing an initial security detection model based on the historical behavior data, preset parameters, and the DBSCAN algorithm; when a new device is connected, collecting the behavior data of the new device and calculating the similarity between the behavior data and the historical behavior data of each device; adjusting the preset parameters based on the connection time of the new device and the similarity; modifying the initial security detection model based on the adjusted preset parameters, and completing home network security monitoring based on the modified initial security detection model.
[0067] Furthermore, the logic instructions in the aforementioned memory 330 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the portion that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product, stored in a storage medium, includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as a USB flash drive, a mobile hard drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.
[0068] On the basis of the above embodiments, on the other hand, the present invention also provides a computer program product, which includes a computer program, which can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the FTTR-based home network security monitoring method provided by the above methods, the method including: collecting historical behavior data of each device in the home network and constructing an initial security detection model based on the historical behavior data, preset parameters and DBSCAN algorithm; when a new device is connected, collecting the behavior data of the new device and calculating the similarity between the behavior data and the historical behavior data of each device; adjusting the preset parameters based on the access time of the new device and the similarity; correcting the initial security detection model based on the adjusted preset parameters, and completing home network security monitoring based on the corrected initial security detection model.
[0069] On the basis of the above embodiments, on another aspect, the present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, is implemented to execute the FTTR-based home network security monitoring method provided by the above methods, the method comprising: collecting historical behavior data of each device in the home network and constructing an initial security detection model based on the historical behavior data, preset parameters and DBSCAN algorithm; when a new device is connected, collecting the behavior data of the new device and calculating the similarity between the behavior data and the historical behavior data of each of the devices; adjusting the preset parameters based on the access time of the new device and the similarity; correcting the initial security detection model based on the adjusted preset parameters, and completing the home network security monitoring based on the corrected initial security detection model.
[0070] The above are only preferred embodiments of the present application and do not limit the patent scope of the present application. Any equivalent structure or equivalent process transformation made using the contents of the present application specification and drawings, or directly or indirectly applied in other related technical fields, are also included in the patent protection scope of the present application.
Claims
1. A method for monitoring home network security based on FTTR, characterized in that: include: Collect historical behavior data of each device in the home network and build an initial security detection model based on the historical behavior data, preset parameters and DBSCAN algorithm; When a new device is connected, collect the behavior data of the new device and calculate the similarity between the behavior data and the historical behavior data of each device; Adjusting the preset parameters based on the access time of the new device and the similarity; The initial security detection model is revised based on the adjusted preset parameters, and the home network security monitoring is completed based on the revised initial security detection model.
2. The FTTR-based home network security monitoring method according to claim 1, characterized in that: The input of the initial security detection model is the historical behavior data, and the output of the initial security detection model is anomalies and multiple clusters.
3. The FTTR-based home network security monitoring method according to claim 2, characterized in that: The calculating the similarity between the behavior data and the historical behavior data of each of the devices includes: Determining the center point of each cluster based on the clustering results obtained by the initial safety detection model; The similarity between the behavior data and each cluster is calculated based on the historical behavior data corresponding to the center point of each cluster.
4. The FTTR-based home network security monitoring method according to claim 2, wherein: The adjusting the preset parameters based on the access time of the new device and the similarity includes: determining initial dynamic parameters of each of the clusters based on the similarity; Adjusting the preset parameters based on the initial dynamic parameters of each cluster and the access time of the new device to obtain the dynamic parameters of each cluster; The modifying of the initial safety detection model based on the adjusted preset parameters includes: The initial safety detection model is modified based on the dynamic parameters of each cluster.
5. The FTTR-based home network security monitoring method according to claim 4, characterized in that: The adjusting the preset parameters based on the initial dynamic parameters of each cluster and the access time of the new device to obtain the dynamic parameters of each cluster includes: The preset parameters are adjusted using the following formulas (1) and (2) to obtain the dynamic parameters of each cluster: Where, Indicates the The dynamic parameters of the cluster, Indicates the The initial dynamic parameters of the clusters, Indicates the preset parameters, Indicates the preset maximum parameter, Indicates the The similarity of clusters, Indicates the access time of the new device, Indicates the preset adjustment constant.
6. The FTTR-based home network security monitoring method according to claim 1, wherein: Before constructing the initial security detection model based on the historical behavior data, preset parameters, and the DBSCAN algorithm, the method further includes: Extracting features from the historical behavior data to obtain feature data; The constructing of the initial security detection model based on the historical behavior data, preset parameters and DBSCAN algorithm includes: An initial security detection model is constructed based on the feature data, preset parameters and DBSCAN algorithm.
7. The FTTR-based home network security monitoring method according to claim 6, characterized in that: The feature extraction of the historical behavior data to obtain feature data includes: Determining an abnormal label based on the historical behavior data; Calculating the correlation between each of the historical behavior data and the abnormal label; Feature extraction is performed on the historical behavior data based on the correlation to obtain feature data.
8. A home network security monitoring device based on FTTR, characterized in that: include: An initial security detection model building module is used to collect historical behavior data of each device in the home network and build an initial security detection model based on the historical behavior data, preset parameters and DBSCAN algorithm; A new device access module is used to collect the behavior data of a new device and calculate the similarity between the behavior data and the historical behavior data of each device when a new device is connected; A parameter adjustment module, configured to adjust the preset parameters based on the access time of the new device and the similarity; The model adjustment module is used to correct the initial security detection model based on the adjusted preset parameters, and complete the home network security monitoring based on the corrected initial security detection model.
9. A home network security monitoring device based on FTTR, characterized in that: include: at least one processor; And, a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the FTTR-based home network security monitoring method as described in any one of claims 1 to 7.
10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the FTTR-based home network security monitoring method according to any one of claims 1 to 7 is implemented.
Citation Information
Patent Citations
Integrated abnormal point and abnormal cluster detection method and device based on sequential network flow
CN117216660A
Method, device and equipment for dynamically adjusting threshold data of network security rule
CN119906557A
Methods and Systems for Cluster-Based Historical Data
US20180101907A1
Cited By
Access security protection system of electric power station network
CN121056240A