A network detection method, related device, equipment and storage medium
By accessing terminal devices in LoRaWAN, acquiring and analyzing sensor and Ethernet network data, and generating network detection results, the problem of insufficient security awareness in LoRaWAN deployment is solved, and the reliability of the deployment is improved.
Patent Information
- Application Number
- CN202110048551.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-01-14
- Publication Date
- 2025-08-12
- Estimated Expiration
- 2041-01-14
AI Technical Summary
In the existing LoRaWAN deployment, the project deployment personnel lack security experience or lack of security awareness, which makes it difficult to objectively evaluate network security risks, affecting the reliability of the deployment.
Provide a network detection method, which connects LoRaWAN through terminal devices, acquires sensor network and Ethernet network data, sends test data to the server for feature analysis, generates network detection results, and automatically detects the security of key components of LoRaWAN.
It improves the reliability of LoRaWAN deployment, makes up for the risks introduced due to insufficient security experience, and achieves comprehensive security detection of LoRaWAN node devices, gateway devices and network servers.
Smart Images

Figure CN113596819B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of cloud security technology, and in particular to a network detection method, related apparatus, equipment, and storage medium. Background Art
[0002] With the introduction of new infrastructure, more and more scenarios will be connected through IoT communications, such as smart cities, smart industry, and smart agriculture. In these smart scenarios, the primary communication technology is low-power wide-area networks (LPWANs). Long-range LoRa, one of the most mainstream LPWAN technology solutions, offers low power consumption and long communication distances.
[0003] Currently, industry security research on the long-range wide-area network (LoRaWAN) focuses on protocol specification flaws, aiming to provide project deployers with some security implementation standards, thereby constraining project deployers in deploying LoRaWAN.
[0004] However, the deployment of LoRaWAN based on security implementation standards relies heavily on the security awareness of project deployers, but security awareness is a subjective concept that cannot objectively evaluate the deployment of LoRaWAN. Summary of the Invention
[0005] The embodiments of the present application provide a network detection method, related apparatus, equipment, and storage medium, which automatically detect key components in LoRaWAN from the perspective of the entire network architecture, compensating for risks introduced by project deployment personnel's lack of security experience or insufficient security awareness, thereby improving the reliability of LoRaWAN deployment.
[0006] In view of this, the present application provides a network detection method, including:
[0007] Accessing a long-distance wide area network (LoRaWAN) to be detected, wherein the LoRaWAN to be detected is a network for communication between LoRaWAN node devices, LoRaWAN gateway devices, and network servers;
[0008] Acquire test data for the LoRaWAN to be tested, wherein the test data includes at least one of sensor network data and Ethernet network data, the sensor network data includes data of a LoRaWAN node device and data of a LoRaWAN gateway device, and the Ethernet network data includes data of a LoRaWAN gateway device and data of a network server;
[0009] The test data is sent to the server so that the server performs feature analysis on the test data to generate a network detection result for the LoRaWAN to be detected, wherein the network detection result represents a detection result of network security.
[0010] Another aspect of the present application provides a network detection method, comprising:
[0011] When the terminal device is connected to a LoRaWAN long-distance wide area network to be detected, receiving test data for the LoRaWAN to be detected sent by the terminal device, wherein the LoRaWAN to be detected is a network for communication between LoRaWAN node devices, LoRaWAN gateway devices, and network servers, and the test data includes at least one of sensor network data and Ethernet network data, the sensor network data includes data of the LoRaWAN node devices and data of the LoRaWAN gateway devices, and the Ethernet network data includes data of the LoRaWAN gateway devices and data of the network server;
[0012] The test data is feature analyzed to generate a network detection result for the LoRaWAN to be detected, wherein the network detection result represents a detection result of network security.
[0013] On the other hand, the present application provides a network detection device, characterized by comprising:
[0014] An access module is used to access a long-distance wide area network LoRaWAN to be detected, wherein the LoRaWAN to be detected is a network for communication between LoRaWAN node devices, LoRaWAN gateway devices and network servers;
[0015] an acquisition module, configured to acquire test data for a LoRaWAN to be tested, wherein the test data includes at least one of sensor network data and Ethernet network data, the sensor network data includes data of a LoRaWAN node device and data of a LoRaWAN gateway device, and the Ethernet network data includes data of a LoRaWAN gateway device and data of a network server;
[0016] The sending module is used to send test data to the server so that the server performs feature analysis on the test data to generate a network detection result for the LoRaWAN to be detected, wherein the network detection result represents a detection result of network security.
[0017] In one possible design, in another implementation of another aspect of the embodiment of the present application,
[0018] An acquisition module, specifically used to obtain Ethernet network data if access is made to the Ethernet network included in the LoRaWAN to be detected;
[0019] If the sensor network included in the LoRaWAN to be detected is connected, the sensor network data is obtained;
[0020] If the Ethernet network and sensor network included in the LoRaWAN to be detected are connected, the Ethernet network data and the sensor network data are obtained.
[0021] In one possible design, in another implementation of another aspect of the embodiment of the present application,
[0022] The acquisition module is specifically used to obtain the network status of the LoRaWAN to be detected as test data when the device to be detected is in the power-on state or normal operating state, wherein the device to be detected is at least one of a LoRaWAN node device, a LoRaWAN gateway device and a network server.
[0023] In one possible design, in another implementation of another aspect of the embodiments of the present application, the test data includes sensor network data;
[0024] The acquisition module is specifically used to obtain the sensor network data of the LoRaWAN to be detected when the LoRaWAN node device is in the power-on state or the normal operating state, wherein the sensor network data includes at least one of the key negotiation data message and key encryption data of the LoRaWAN node device.
[0025] In one possible design, in another implementation of another aspect of the embodiment of the present application,
[0026] The acquisition module is specifically used to generate data packets corresponding to the target attack type;
[0027] Sending a data packet corresponding to the target attack type to the device to be detected in the LoRaWAN to be detected, so that the device to be detected generates feedback data according to the data packet corresponding to the target attack type;
[0028] Receive feedback data as test data.
[0029] In one possible design, in another implementation of another aspect of the embodiments of the present application, the test data includes sensor network data;
[0030] Acquisition module, specifically used to generate data packets targeting public vulnerabilities and exposed CVE types;
[0031] A data packet for the CVE type is sent to a LoRaWAN node device in the LoRaWAN to be detected, so that the LoRaWAN node device generates feedback data according to the data packet for the CVE type.
[0032] In one possible design, in another implementation of another aspect of the embodiments of the present application, the test data includes sensor network data or Ethernet network data;
[0033] Acquisition module, specifically used to generate data packets targeting dangerous port vulnerabilities;
[0034] Alternatively, a data packet is generated for gateway authentication access;
[0035] If a data packet targeting a dangerous port vulnerability is generated, the data packet targeting the dangerous port vulnerability is sent to a LoRaWAN gateway device in the LoRaWAN to be detected, so that the device to be detected generates feedback data according to the data packet targeting the dangerous port vulnerability;
[0036] If a data packet for gateway authentication access is generated, the data packet for gateway authentication access is sent to the LoRaWAN gateway device in the LoRaWAN to be detected, so that the device to be detected generates feedback data according to the data packet for gateway authentication access.
[0037] In one possible design, in another implementation of another aspect of the embodiments of the present application, the test data includes Ethernet network data;
[0038] An acquisition module is specifically used to generate a data packet for authorized access to the communication protocol;
[0039] Alternatively, a data packet for remote procedure call (RPC) authorization access is generated;
[0040] Alternatively, generate a data packet for password login;
[0041] Alternatively, a data packet is generated for authorized access to the database;
[0042] If a data packet for authorized access to the communication protocol is generated, the data packet for authorized access to the communication protocol is sent to the network server in the LoRaWAN to be detected, so that the device to be detected generates feedback data according to the data packet for authorized access to the communication protocol;
[0043] If a data packet for RPC authorized access is generated, the data packet for RPC authorized access is sent to the network server in the LoRaWAN to be detected, so that the device to be detected generates feedback data according to the data packet for RPC authorized access;
[0044] If a data packet for password login is generated, the data packet for password login is sent to the network server in the LoRaWAN to be detected, so that the device to be detected generates feedback data according to the data packet for password login;
[0045] If a data packet for authorized database access is generated, the data packet for authorized database access is sent to a network server in the LoRaWAN to be detected, so that the device to be detected generates feedback data according to the data packet for authorized database access.
[0046] On the other hand, the present application provides a network detection device, characterized by comprising:
[0047] a receiving module, configured to receive test data for the LoRaWAN to be detected, sent by the terminal device when the terminal device is connected to the LoRaWAN long-distance wide area network to be detected, wherein the LoRaWAN to be detected is a network for communication between LoRaWAN node devices, LoRaWAN gateway devices, and network servers, and the test data includes at least one of sensor network data and Ethernet network data, the sensor network data includes data from the LoRaWAN node devices and data from the LoRaWAN gateway devices, and the Ethernet network data includes data from the LoRaWAN gateway devices and data from the network server;
[0048] The generation module is used to perform feature analysis on the test data to generate a network detection result for the LoRaWAN to be detected, wherein the network detection result represents a detection result of network security.
[0049] In one possible design, in another implementation of another aspect of the embodiments of the present application, the test data includes sensor network data;
[0050] A receiving module, specifically, when the LoRaWAN node device is in a powered-on or normal operating state, receives LoRaWAN sensor network data to be detected sent by the terminal device, wherein the sensor network data includes at least one of a key negotiation data message and key encryption data of the LoRaWAN node device;
[0051] The generation module is specifically used to perform feature analysis on at least one of the key negotiation data message and the key encryption data to generate a network detection result for the LoRaWAN node device in the LoRaWAN to be detected.
[0052] In one possible design, in another implementation of another aspect of the embodiments of the present application, the test data includes sensor network data and Ethernet network data;
[0053] The receiving module is specifically used to receive test data sent by the terminal device for common vulnerabilities and exposed CVE types in the LoRaWAN to be detected, dangerous port vulnerabilities, gateway authentication access, communication protocol authorization access, remote procedure call RPC authorization access, password login and database authorization access corresponding to the test data;
[0054] The generation module is specifically used to generate network detection results for LoRaWAN node devices, LoRaWAN gateway devices and network servers in the LoRaWAN to be tested based on the test data corresponding to CVE type, dangerous port vulnerability, gateway authentication access, communication protocol authorization access, RPC authorization access, password login and database authorization access.
[0055] On the other hand, the present application provides a terminal device, comprising: a memory, a processor, and a bus system;
[0056] Wherein, the memory is used to store programs;
[0057] The processor is used to execute the program in the memory, and the processor is used to perform the above-mentioned methods according to the instructions in the program code;
[0058] The bus system is used to connect the memory and the processor so that the memory and the processor can communicate with each other.
[0059] On the other hand, the present application provides a server, comprising: a memory, a processor, and a bus system;
[0060] Wherein, the memory is used to store programs;
[0061] The processor is used to execute the program in the memory, and the processor is used to perform the above-mentioned methods according to the instructions in the program code;
[0062] The bus system is used to connect the memory and the processor so that the memory and the processor can communicate with each other.
[0063] Another aspect of the present application provides a computer-readable storage medium, wherein instructions are stored in the computer-readable storage medium. When the computer-readable storage medium is run on a computer, the computer is enabled to execute the above-mentioned methods.
[0064] Another aspect of the present application provides a computer program product or computer program, which includes computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the methods provided in the above aspects.
[0065] It can be seen from the above technical solutions that the embodiments of the present application have the following advantages:
[0066] In an embodiment of the present application, a network detection method is provided. First, a terminal device connects to a LoRaWAN network to be detected. Then, test data for the LoRaWAN network to be detected is obtained. The test data includes at least one of sensor network data and Ethernet network data. Finally, the terminal device sends the test data to a server, which performs feature analysis on the test data to generate a network detection result for the LoRaWAN network to be detected. In this way, based on the sensor network data and Ethernet network data, LoRaWAN node devices, LoRaWAN gateway devices, and network servers are detected. That is, from the perspective of the entire network architecture, key components in the LoRaWAN network are automatically detected, compensating for risks introduced by project deployment personnel's lack of security experience or insufficient security awareness, thereby improving the reliability of the LoRaWAN deployment. BRIEF DESCRIPTION OF THE DRAWINGS
[0067] Figure 1 A schematic diagram of a LoRaWAN network architecture in an embodiment of the present application;
[0068] Figure 2 A schematic diagram of a network architecture of a network detection system in an embodiment of the present application;
[0069] Figure 3 This is a schematic diagram of an embodiment of a network detection method in an embodiment of the present application;
[0070] Figure 4 This is a schematic diagram of a workflow of a terminal test end in an embodiment of the present application;
[0071] Figure 5 A schematic diagram of a LoRaWAN node device accessing the network based on air activation in an embodiment of the present application;
[0072] Figure 6 This is a schematic diagram of an interface showing network detection results in an embodiment of the present application;
[0073] Figure 7 This is a schematic diagram of another embodiment of the network detection method in the embodiment of the present application;
[0074] Figure 8 A schematic diagram of a framework for cloud-based analysis feedback in an embodiment of the present application;
[0075] Figure 9 This is a schematic diagram of an embodiment of a network detection device in an embodiment of the present application;
[0076] Figure 10 This is a schematic diagram of another embodiment of the network detection device in the embodiment of the present application;
[0077] Figure 11This is a schematic diagram of the structure of a terminal device in an embodiment of the present application;
[0078] Figure 12 This is a structural diagram of the server in an embodiment of the present application. DETAILED DESCRIPTION
[0079] The embodiments of the present application provide a network detection method, related apparatus, equipment, and storage medium, which automatically detect key components in LoRaWAN from the perspective of the entire network architecture, compensating for risks introduced by project deployment personnel's lack of security experience or insufficient security awareness, thereby improving the reliability of LoRaWAN deployment.
[0080] The terms "first", "second", "third", "fourth", etc. (if any) in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequential order. It should be understood that the numbers used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can, for example, be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "corresponding to" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0081] With the rapid development of IoT technology, its scale and applications have become more extensive, with an increasing number of access control points. The use of long-range wide-area networks (LoRaWAN) has become a trend. LoRaWAN is a set of communication protocols and system architectures designed for long-range (LoRa) communication networks. As one of the most mainstream low-power wide-area network (LPWAN) technology solutions, LoRa offers low power consumption and long communication distances. LPWAN, also known as low-power wide-area (LPWA) or low-power network (LPN), is a wireless network used in the Internet of Things (for example, battery-powered sensors) that can communicate over long distances at low bit rates.
[0082] The LoRaWAN protocol defines how data is transmitted within the LoRaWAN network (the network here refers to LoRaWAN nodes, LoRaWAN gateways, and network servers), including message types, data frame structures, and security encryption methods. The design of the LoRaWAN protocol and network architecture takes into account factors such as node power consumption, network capacity, Quality of Service (QoS), security, and network application diversity.
[0083] For easier understanding, see Figure 1 , Figure 1 This is a schematic diagram of the LoRaWAN network architecture in the embodiment of this application. As shown in the figure, specifically, the LoRaWAN network architecture includes four parts: LoRaWAN node devices, LoRaWAN gateway devices, network servers (NS), and application servers. A star network topology is used between LoRaWAN node devices and LoRaWAN gateway devices. Due to the long-distance characteristics of LoRa, single-hop transmission can be used between them. Figure 1 As can be seen, LoRaWAN node devices can send data to multiple LoRaWAN gateway devices simultaneously. LoRaWAN gateway devices forward LoRaWAN protocol data between the network server and LoRaWAN node devices, carrying LoRaWAN data on LoRa radio frequency transmission and Transmission Control Protocol / Internet Protocol (TCP / IP). The network that transmits data via LoRa radio frequency is the sensor network, and the network that transmits data via TCP / IP is the Ethernet network. The following describes the four types of devices included in the LoRaWAN network architecture.
[0084] 1. LoRaWAN node device;
[0085] LoRaWAN nodes, also known as end nodes, are typically used with sensors to collect environmental information, such as smog or weather conditions. LoRaWAN nodes randomly switch channels each time they send a data packet to minimize co-channel interference and wireless signal attenuation.
[0086] The LoRaWAN protocol defines three classes of LoRaWAN node devices, allowing users to flexibly select the optimal class based on the application scenario, energy-saving requirements, and wake-up latency. The first class of LoRaWAN nodes belongs to the mainstream Class A. Class A applications are battery-powered sensors, offering energy-saving advantages, but with higher downlink communication latency. Class A LoRaWAN nodes include, but are not limited to, trash can monitoring, smoke alarms, and other monitoring devices. The second class of LoRaWAN nodes belongs to Class B. Class B applications are battery-powered actuators, offering energy-saving advantages and controllable wake-up latency, but with a higher implementation cost. Class B LoRaWAN nodes include, but are not limited to, valve-controlled water, gas, and electricity meters. It should be noted that the protocol allows LoRaWAN nodes to switch between Class A and Class B as needed during operation. The third class of LoRaWAN nodes belongs to Class C. Class C applications are mains-powered actuators, offering the advantage of 24 / 7 wake-up communication capability, but with higher energy consumption. Class C LoRaWAN nodes include, but are not limited to, streetlight control systems.
[0087] 2. LoRaWAN gateway device;
[0088] LoRaWAN gateways are used to forward data between LoRaWAN node devices and network servers. LoRaWAN gateways are not bound to LoRaWAN node devices; data from the same LoRaWAN node can be received by multiple LoRaWAN gateways. Data is transmitted between LoRaWAN node devices and LoRaWAN gateways using a sensor network. Currently, the 470 MHz frequency band is used in China.
[0089] 3. Network server;
[0090] The network server forwards data generated by LoRaWAN node devices to the corresponding application server and provides authentication and authorization for LoRaWAN node devices. The TCP / IP protocol stack is used between the LoRaWAN gateway device and the network server, with transparent transmission. Common protocols include packet forwarder, Message Queuing Telemetry Transport (MQTT), Constrained Application Protocol (CoAP), and Protobuf.
[0091] 4. Application server;
[0092] The application server is designed according to user needs and usually includes the display of LoRaWAN node device data (for example, data statistics and abnormal data alarms) and remote control of LoRaWAN node devices.
[0093] Depend on Figure 1 As shown in the figure, the data transmission process is as follows: LoRaWAN node devices collect data and transmit it directly to the LoRaWAN gateway device through the sensor network. The LoRaWAN gateway device then forwards the data to the network server for processing. The process of data transmission from LoRaWAN node devices to the network server is called uplink, and the process of data transmission from the network server to LoRaWAN node devices is called downlink.
[0094] In recent years, various IoT technologies have emerged one after another around the world, and low-power wide-area access technology has developed rapidly. This has led to more security issues. Currently, possible security issues include the following reasons:
[0095] Reason 1: Providing free frequency bands and open standards;
[0096] LoRa technology initially chose unlicensed frequency bands. While this facilitated the large-scale deployment of LoRa networks, it also created potential security risks. LoRaWAN operates in the unlicensed Industrial, Scientific, and Medical (ISM) frequency band, and its protocol specifications are public, making it vulnerable to attacks.
[0097] One attack method is "malicious congestion." An attacker uses a LoRa device to send a maximum-length preamble within a 125 kilohertz (kHz) bandwidth, maliciously occupying the channel. As long as the attacker adheres to duty cycle and transmit power limits, the attack is considered legal.
[0098] Reason 2: LoRaWAN node devices are weak terminals;
[0099] LoRaWAN node devices lack secure storage media similar to Subscriber Identity Modules (SIMs). Their security relies on physical protection of the terminal, which can pose a risk of key leakage for weak terminals. Weak terminals (e.g., LoRaWAN node devices like smart electricity and water meters) are easily accessible to attackers. If their identities are leaked, malicious terminals can impersonate legitimate terminals to access the network or cloud platform, potentially reporting erroneous data and causing financial losses to businesses or users. For example, impersonating legitimate users to report erroneous meter data could lead to abnormal electricity bills for power companies or incur overcharges for legitimate users.
[0100] Reason 3: Weak key management;
[0101] In terms of key management, the LoRa network layer and application transport layer are both generated by the AES algorithm using the same root key and random number. The security level and encryption strength of encryption and integrity protection depend on the application key (AppKey) stored in the device. Therefore, if secure key storage is not implemented according to specifications, key leakage may occur, leading to risks such as data privacy leakage and data tampering.
[0102] Reason 4: Large scale of deployment;
[0103] With the widespread use of LoRa technology, for example, in application scenarios such as smart cities, smart environmental protection, smart agriculture, smart medical care and smart homes, the greater the number of LoRa terminals and networks deployed, the greater the security issues and risk challenges it will bring.
[0104] For these reasons, in practical applications, it is even more important to improve the security of device deployment. If deployers ignore safety regulations, the final deployment of the project may pose a security risk. At the same time, when accepting the project, the acceptance party may not be able to truly and effectively determine whether the current deployment meets safety regulations due to a lack of relevant security knowledge. In view of the shortcomings of the above solutions, this application proposes a network detection method for LoRaWAN, mainly from the perspective of security detection.
[0105] Specifically, see Figure 2 , Figure 2 This is a network architecture diagram of a network detection system in an embodiment of the present application. As shown in the figure, the network detection system includes two parts, a terminal test end and a cloud analysis and feedback end, wherein the terminal test end can be in the form of a terminal device, and the cloud analysis and feedback end can be in the form of a server. The terminal devices involved in this application can be smart phones, tablet computers, laptops, PDAs, personal computers, smart TVs, smart watches, etc., but are not limited to these. The server involved in this application can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, content delivery networks (CDNs), and big data and artificial intelligence platforms.
[0106] A cloud server is a server implemented using cloud technology. Cloud technology refers to a hosting technology that unifies hardware, software, and network resources within a wide or local area network (WAN) to enable data computing, storage, processing, and sharing. Cloud technology is a general term for network, information technology, integration technology, management platform technology, and application technology, all of which are applied in the cloud computing business model. It can form a resource pool for on-demand, flexible and convenient use. Cloud computing technology will become a crucial support. Backend services for technical network systems, such as video websites, image websites, and more portals, require extensive computing and storage resources. With the rapid development and application of the internet industry, every item will likely have its own unique identifier, requiring transmission to backend systems for logical processing. Data of varying levels will be processed separately, and data from various industries will require a robust system backend, which can only be achieved through cloud computing.
[0107] The terminal device and the server can be connected directly or indirectly via wired or wireless communication, which is not limited in this application. There is no limit on the number of servers and terminal devices.
[0108] The terminal device, serving as the terminal test end, primarily consists of a data sniffing module, a data test and evaluation module, and a feedback reporting module. The data sniffing module is the most fundamental data collection device and requires access to the LoRaWAN test environment. Once connected, it sniffs sensor network data and Ethernet network data. The data test and evaluation module is a key module in the terminal test end, transmitting data information and network feedback status to the feedback reporting module. The feedback reporting module primarily receives feedback packets from the data test and evaluation module and reports them to the cloud via the network for subsequent analysis and processing.
[0109] The server serving as the cloud-based analysis and feedback endpoint primarily consists of a signature analysis module and a results presentation module. The signature analysis module detects risk signatures based on uploaded feedback data, loading detection signatures from a signature database before analysis. The results presentation module displays the signature analysis module's analysis results, providing risk warnings tailored to specific security risks and offering user remediation suggestions.
[0110] The network detection method provided in this application can be applied to the field of cloud security. Cloud security refers to the security software, hardware, users, organizations, and secure cloud platforms used in cloud computing business models. Cloud security integrates emerging technologies and concepts such as parallel processing, grid computing, and the identification of unknown virus behavior. Through a large number of networked clients, cloud security monitors software behavior anomalies on the network, obtains the latest information on Trojans and malicious programs on the Internet, sends it to the server for automatic analysis and processing, and then distributes virus and Trojan solutions to each client.
[0111] The main research directions of cloud security include: 1. Cloud computing security, which focuses on how to ensure the security of the cloud itself and various applications on the cloud, including cloud computer system security, secure storage and isolation of user data, user access authentication, information transmission security, network attack protection, compliance auditing, etc.; 2. Cloudification of security infrastructure, which focuses on how to use cloud computing to build and integrate security infrastructure resources and optimize security protection mechanisms, including building ultra-large-scale security event, information collection and processing platforms through cloud computing technology, realizing the collection and correlation analysis of massive amounts of information, and improving the ability to control security incidents and risks across the entire network; 3. Cloud security services, which focuses on various security services provided to users based on cloud computing platforms, such as antivirus services.
[0112] Combined with the above introduction, the network detection method in this application will be introduced below. Figure 3 , an embodiment of the network detection method in the embodiment of the present application includes:
[0113] 101. The terminal device is connected to a long-distance wide area network LoRaWAN to be detected, wherein the LoRaWAN to be detected is a network for communication between LoRaWAN node devices, LoRaWAN gateway devices and network servers;
[0114] In this embodiment, the terminal device serving as the terminal test end needs to first be connected to the LoRaWAN to be tested. The LoRaWAN to be tested includes a sensor network and an Ethernet network. The sensor network can be a Wireless Sensor Network (WSN). A WSN is a multi-hop self-organizing network system composed of a large number of sensor nodes deployed within a management area. It is formed through wireless communication to collaboratively sense, collect, and process information about objects within the network coverage area. The Ethernet network can be a TCP / IP network, where the IP address of the network layer specifies the address of each server connected to the Internet, and the TCP of the transport layer is responsible for data transmission.
[0115] 102. The terminal device obtains test data for the LoRaWAN to be tested, wherein the test data includes at least one of sensor network data and Ethernet network data, the sensor network data includes data of the LoRaWAN node device and data of the LoRaWAN gateway device, and the Ethernet network data includes data of the LoRaWAN gateway device and data of the network server;
[0116] In this embodiment, after accessing the LoRaWAN network to be tested, the terminal device can obtain test data specific to the LoRaWAN network to be tested. As described in step 101, the LoRaWAN network to be tested may include a sensor network and an Ethernet network. Sensor network data can be extracted from the sensor network, and Ethernet network data can be extracted from the Ethernet network. The sensor network data includes data from LoRaWAN node devices and LoRaWAN gateway devices, and the Ethernet network data includes data from LoRaWAN gateway devices and network server data.
[0117] It is understandable that since the LoRaWAN gateway device can communicate with both the LoRaWAN node device and the network server, the data of the LoRaWAN gateway device belongs to both sensor network data and Ethernet network data, which is not limited here.
[0118] It should be noted that the types of functions of LoRaWAN node devices, LoRaWAN gateway devices and network servers have been introduced above and will not be repeated here.
[0119] 103. The terminal device sends test data to the server, so that the server performs feature analysis on the test data to generate a network detection result for the LoRaWAN to be detected, wherein the network detection result indicates a detection result of network security.
[0120] In this embodiment, the terminal device feeds the collected test data back to the server serving as the cloud analysis feedback end. The server further performs feature analysis on the test data to generate network detection results for the LoRaWAN to be detected. The network detection results are used to represent the detection results of network security, such as the security detection results of LoRaWAN node devices, the security detection results of LoRaWAN gateway devices, and the security detection results of network servers. Specifically, the server can generate detection results for each component of the LoRaWAN to be detected (i.e., LoRaWAN node devices, LoRaWAN gateway devices, and network servers).
[0121] For easier understanding, see Figure 4 , Figure 4This is a schematic diagram of a workflow of a terminal test end in an embodiment of the present application, as shown in the figure, specifically:
[0122] In step S1, the terminal device calls the function of the data sniffing module, which is used to collect data. After accessing the LoRaWAN to be detected, the data collection function of the data sniffing module can be called.
[0123] In step S2, the terminal device determines whether it is connected to the Ethernet network included in the LoRaWAN to be detected. If it is connected to the Ethernet network, it proceeds to step S5; if it is not connected to the Ethernet network, it executes step S3.
[0124] In step S3, if the Ethernet network is not connected, it is determined whether the sensor network included in the LoRaWAN to be detected is connected. If the sensor network is connected, step S4 is executed. If the sensor network is not connected, the detection process of the LoRaWAN to be detected is ended.
[0125] It should be noted that the execution order between step S2 and step S3 can also be: first determine whether the sensor network included in the LoRaWAN to be detected is connected; if the sensor network has been connected, execute step S4; if the sensor network has not been connected, continue to determine whether the Ethernet network included in the LoRaWAN to be detected is connected; if the Ethernet network has been connected, execute step S5; if the Ethernet network has not been connected, end the detection process of the LoRaWAN to be detected.
[0126] In addition, step S2 and step S3 may be performed simultaneously, so the order of accessing the networks is not limited here.
[0127] In step S4, if the sensor network has been connected, the data sniffing module can capture the sensor network data, wherein the sensor network data includes the data of the LoRaWAN node device and the data of the LoRaWAN gateway device.
[0128] In step S5, if the Ethernet network has been connected, the data sniffing module can capture Ethernet network data, wherein the Ethernet network data includes data of the LoRaWAN gateway device and data of the network server.
[0129] In step S6, the terminal device calls the function of the data test and evaluation module. The data test and evaluation module is divided into two modes, namely active mode and passive mode.
[0130] In step S7, the passive mode is entered.
[0131] In step S8, in the passive mode, the corresponding test data is mainly generated based on the Ethernet network data and sensor network data fed back by the data sniffing module, that is, the network status of the LoRaWAN to be detected is obtained as test data.
[0132] In step S9, the active mode is entered.
[0133] In step S10, in active mode, a data packet of the corresponding attack type is generated according to the pre-set detection strategy and rules, and then the data packet is sent to the LoRaWAN component to be detected, which can be one or more of a LoRaWAN node device, a LoRaWAN gateway device, and a network server.
[0134] In step S11 , the component in the LoRaWAN to be detected is waited for to feed back test data.
[0135] In step S12, after the test evaluation in the active mode and the passive mode, the data test evaluation module sends the test data (eg, data information and network feedback status, etc.) to the feedback reporting module.
[0136] In step S13, the feedback reporting module mainly receives the test data sent from the data test evaluation module, and reports it to the cloud through the network, and the cloud analysis feedback end performs subsequent analysis and processing.
[0137] In an embodiment of the present application, a network detection method is provided. First, a terminal device connects to a LoRaWAN network to be detected. Then, test data for the LoRaWAN network to be detected is obtained. The test data includes at least one of sensor network data and Ethernet network data. Finally, the terminal device sends the test data to a server, which performs feature analysis on the test data to generate a network detection result for the LoRaWAN network to be detected. In this way, based on the sensor network data and Ethernet network data, LoRaWAN node devices, LoRaWAN gateway devices, and network servers are detected. That is, from the perspective of the entire network architecture, key components in the LoRaWAN network are automatically detected, compensating for risks introduced by project deployment personnel's lack of security experience or insufficient security awareness, thereby improving the reliability of the LoRaWAN deployment.
[0138] Optionally, in the above Figure 3 On the basis of the corresponding embodiment, in another optional embodiment provided by the embodiment of the present application, the terminal device obtains test data for the LoRaWAN to be detected, which may include:
[0139] If it is connected to the Ethernet network included in the LoRaWAN to be detected, the terminal device obtains the Ethernet network data;
[0140] If the terminal device is connected to the sensor network included in the LoRaWAN to be detected, the terminal device obtains the sensor network data;
[0141] If the terminal device is connected to the Ethernet network and sensor network included in the LoRaWAN to be detected, the terminal device obtains the Ethernet network data and the sensor network data.
[0142] This embodiment introduces a method for obtaining test data based on network access. The terminal device, acting as the terminal test end, must first connect to the LoRaWAN network to be tested. As described in the previous embodiment, the LoRaWAN network to be tested includes both a sensor network and an Ethernet network. The following will describe the sensor network and Ethernet network separately.
[0143] 1. Sensor Network;
[0144] The sensor network can be a WSN. Among them, the sensor network integrates microelectronics technology, embedded computing technology, wireless communication technology, and distributed information processing technology. It can collaboratively monitor, perceive, and collect information about various environments or monitored objects in the network coverage area in real time, and process the information. The processed information is sent wirelessly and transmitted to the observer in a self-organized multi-hop network.
[0145] A sensor network typically consists of sensor nodes, sink nodes, and management nodes. Sensor nodes are randomly distributed within a monitoring area, forming a self-organizing network. Monitoring data is transmitted to sink nodes via multi-hop relays, and finally to management nodes via the internet or other network communication methods. Similarly, users can issue commands through the management node, instructing sensor nodes to collect monitoring information.
[0146] In the sensor network, the terminal device serving as the terminal test end can obtain the sensor network data through the data sniffing module. The sensor network data is expressed as radio air interface packets, which are mainly the communication data between the LoRaWAN node device and the LoRaWAN gateway device. That is, the terminal device can not only obtain the data of the LoRaWAN node device, but also the data of the LoRaWAN gateway device.
[0147] 2. Ethernet network;
[0148] Ethernet networks can use TCP / IP, a type of local area network (LAN). From a network layer perspective, LAN protocols primarily focus on the lower layers (including the physical layer and data link layer), while Ethernet protocols primarily define the data link layer. TCP / IP, used by the Internet, primarily focuses on the middle layers (including the network layer and transport layer).
[0149] In an Ethernet network, a terminal device serving as a terminal test end can obtain Ethernet network data through a data sniffing module. Ethernet network data is expressed as TCP / IP data packets, which are mainly communication data between the LoRaWAN gateway device and the network server. That is, the terminal device can not only obtain data from the LoRaWAN gateway device, but also obtain data from the network server.
[0150] As described above, during data transmission in a sensor network, LoRaWAN node devices are typically connected to sensor nodes and used to collect data from the sensors, such as air humidity. The LoRaWAN node devices then send the collected sensor data (e.g., air humidity) to a LoRaWAN gateway device. The LoRaWAN gateway device is used to send the sensor data to a network server, completing the data conversion from LoRa mode to network mode. The LoRaWAN gateway device does not process the data; it only needs to package and encapsulate the data and then send it to the network server. The network server can choose to send the data to the user, who can view the data through an application (APP) or other means, such as checking the air humidity.
[0151] Secondly, in an embodiment of the present application, a method for obtaining test data based on network access conditions is provided. Through the above method, the terminal device can determine one or more specific network types based on the connected LoRaWAN to be detected. If only the sensor network is connected, the terminal device will subsequently only detect data related to the LoRaWAN node device and the LoRaWAN gateway device. If only the Ethernet network is connected, the terminal device will subsequently only detect data related to the server and the LoRaWAN gateway device. In this way, the flexibility of detection can be improved, and device detection can be implemented in a targeted manner, thereby improving the diversity of solutions.
[0152] Optionally, in the above Figure 3 On the basis of the corresponding embodiment, in another optional embodiment provided by the embodiment of the present application, the terminal device obtains test data for the LoRaWAN to be detected, which may specifically include:
[0153] When the device to be detected is in the power-on state or normal operating state, the terminal device obtains the network status of the LoRaWAN to be detected as test data, wherein the device to be detected is at least one of a LoRaWAN node device, a LoRaWAN gateway device and a network server.
[0154] This embodiment introduces a method for generating test data in passive mode. In passive mode, the terminal device, acting as the terminal test end, uses the data sniffing module to sniff the network status data (e.g., packet loss rate, transmitted data packets) of the device to be tested during power-on and normal operation. This network status data is used as test data and sent to the feedback reporting module. It should be noted that the device to be tested can be one or more of a LoRaWAN node device, a LoRaWAN gateway device, and a network server, and this is not limited here.
[0155] Specifically, there is a certain risk of attack during the process of powering on and joining the network, as well as during normal operation. Taking the powering on and joining of a LoRaWAN node as an example, the following describes two ways for a LoRaWAN node to join the network.
[0156] Method 1: Activation by Personalization (ABP);
[0157] In the ABP method, the communication encryption key is pre-programmed into the LoRaWAN node device, and the LoRaWAN node device is pre-registered on the network. When the LoRaWAN node device wants to communicate, the LoRaWAN node device directly uses the pre-set key to initiate the encrypted communication process without having to activate the network over the air.
[0158] ABP is a simple network access mechanism suitable for building private networks. Its core principle is that both the LoRaWAN node device and the network server store the same three parameters: the 32-bit device address (DevAddr), the 128-bit network session key (NwkSKey), and the 128-bit application session key (APPSKey). These three parameters remain unchanged throughout the entire life cycle.
[0159] Specifically, each LoRaWAN node device has a Device Extended Unique Identifier (DevEUI). This is obtained by taking the serial number (SN) of the microcontroller unit (MCU) and processing it through an algorithm to obtain a 64-bit DevEUI. This DevEUI is then processed through an algorithm to obtain the DevAddr, NwkSKey, and APPSKey. If the algorithm used is too simple, it can be easily guessed by an attacker, who can then use these values to forge a non-existent LoRaWAN node device.
[0160] Method 2: Over-the-Air Activation (OTAA);
[0161] OTAA is a LoRaWAN over-the-air network access method. When powered on, the LoRaWAN node device will communicate with the network server and eventually negotiate a communication encryption key to activate the device and access the network. Commercial LoRaWAN usually adopts the OTAA activation process to ensure security. The OTAA method requires the preparation of three parameters: DevEUI, Application Extended Unique Identifier (AppEUI), and application key (AppKey). Among them, DevEUI is used to identify a unique terminal device, and APPEUI is used to identify a unique application provider. For example, each household's trash can detection application or smoke alarm application has a unique identifier. The APPKey is assigned to the LoRaWAN node device by the application owner.
[0162] For easier understanding, see Figure 5 , Figure 5 This is a schematic diagram of the LoRaWAN node device joining the network based on air activation in an embodiment of the present application. As shown in the figure, after initiating the network joining process, the LoRaWAN node device issues a network joining command. After confirming that it is correct, the network server will give the LoRaWAN node device a network joining reply and assign DevAddr. Both parties use the relevant information in the network joining reply and AppKey to generate NwkSKey and APPSKey, and the application encrypts and verifies the data.
[0163] Thirdly, in an embodiment of the present application, a method for generating test data in passive mode is provided. Through the above method, the terminal device serving as the terminal test end can perform data sniffing based on the currently deployed network, and ultimately determine the security of the LoRaWAN to be tested based on the sniffed test data. This can accurately and objectively help project deployment personnel and acceptance personnel conduct security assessments, or perform security testing on existing network solutions, thereby improving the security of smart scenarios. In addition, in passive mode, the terminal device only needs to wait for the test data actively fed back from the LoRaWAN to be tested. On the one hand, this improves the efficiency of the test, and on the other hand, there is no need to actively send instructions to the various components in the LoRaWAN to be tested, thereby saving the power consumption of the terminal device and reducing processing resources.
[0164] Optionally, in the above Figure 3 On the basis of the corresponding embodiment, in another optional embodiment provided by the embodiment of the present application, the test data includes sensor network data;
[0165] When the device to be tested is powered on or in normal operation, the terminal device obtains the network status of the LoRaWAN to be tested as test data, which may include:
[0166] When the LoRaWAN node device is in a powered-on state or a normal operating state, the terminal device obtains the sensor network data of the LoRaWAN to be detected, wherein the sensor network data includes at least one of a key negotiation data message and key encryption data of the LoRaWAN node device.
[0167] This embodiment introduces a method for generating test data for a LoRaWAN node device. Taking a LoRaWAN node device as an example, when the LoRaWAN node device is powered on or operating normally, a terminal device can obtain the LoRaWAN test data. The sensor network data includes sensor network data, which includes at least one of a key negotiation data message and key encryption data of the LoRaWAN node device.
[0168] Specifically, the terminal device acting as the terminal test end can capture the key negotiation data packets of the LoRaWAN node device. The key negotiation data packets are used to negotiate session keys, including NwkSKey and AppSKey. Based on the characteristics of the key negotiation data packets, it can detect whether the LoRaWAN node device uses OTAA key negotiation. If the key negotiation data packets are detected, it indicates that the LoRaWAN node device has used OTAA key negotiation. If the key negotiation data packets are not detected, it indicates that the LoRaWAN node device does not use OTAA key negotiation. If the LoRaWAN node device does not use OTAA key negotiation, there may be security vulnerabilities.
[0169] The terminal device acting as the terminal test end can capture the key negotiation data packets and key encryption data of the LoRaWAN node device. Based on the key negotiation data packets and key encryption data, it can detect whether the LoRaWAN node device is using the OTAA weak key according to the protocol specification and known weak keys. If the result calculated using the weak key is consistent with the key encryption data of the LoRaWAN node device, it indicates that the LoRaWAN node device is using the OTAA weak key. If the result calculated using the weak key is inconsistent with the key encryption data of the LoRaWAN node device, it indicates that the LoRaWAN node device is not using the OTAA weak key. If a LoRaWAN node device uses the OTAA weak key, it may have a security vulnerability.
[0170] Furthermore, embodiments of the present application provide a method for generating test data for LoRaWAN node devices. This method, considering that LoRaWAN node devices typically do not actively provide data feedback for key detection, can be used in a passive mode to wait for the LoRaWAN node device to send back at least one of the key negotiation data message and key encryption data, thereby improving detection reliability. Furthermore, passive testing can be used to monitor for attacks in real time, thereby enhancing the security of communications within LoRaWAN components.
[0171] Optionally, in the above Figure 3 On the basis of the corresponding embodiment, in another optional embodiment provided by the embodiment of the present application, the terminal device obtains test data for the LoRaWAN to be detected, which may specifically include:
[0172] The terminal device generates a data packet corresponding to the target attack type;
[0173] The terminal device sends a data packet corresponding to the target attack type to the device to be detected in the LoRaWAN to be detected, so that the device to be detected generates feedback data according to the data packet corresponding to the target attack type;
[0174] The terminal device receives the feedback data as test data.
[0175] This embodiment introduces a method for obtaining test data in active mode. In active mode, the terminal device, acting as the terminal test end, generates a corresponding data packet based on the target attack type, and then sends the data packet corresponding to the target attack type to the device to be tested in the LoRaWAN network to be tested. The device to be tested generates different feedback data packets based on different attack data packets, thus obtaining feedback data. Finally, the device to be tested sends the feedback data to the terminal device, which obtains the feedback data through a data sniffing module and uses the feedback data as test data. It should be noted that the device to be tested can be one or more of a LoRaWAN node device, a LoRaWAN gateway device, and a network server, and this is not limited here.
[0176] Specifically, in active mode, it simulates a LoRaWAN gateway device connected to the LoRaWAN network under test, launching a network test scan attack against the network server, LoRaWAN gateway device, and LoRaWAN node device under test. When the active mode sends security detection traffic to each test link, it collects the feedback data status and sends it back to the reporting module.
[0177] A network test scan attack involves sending multiple packets continuously to the device under test over a period of time. For example, a packet could be sent to 10 different ports on the same IP address every 500 microseconds. This constitutes a port scan. Network test scan attacks can effectively verify protocol functionality and vulnerabilities, as well as device performance.
[0178] It should be noted that in actual applications, attack types can be expanded, meaning that detection signatures can be expanded at any time. Once new security risks emerge, they can be quickly added to the detection rules. This support for expanded custom inspection rules and content further provides an efficient and iteratively updateable LoRaWAN security detection framework.
[0179] Thirdly, in an embodiment of the present application, a method for obtaining test data in active mode is provided. Through this method, the terminal device, acting as the terminal test end, can generate and send test data packets based on the currently deployed network, and ultimately determine the security of the LoRaWAN to be tested based on the received feedback data. This can accurately and objectively help project deployment personnel and acceptance personnel conduct security assessments or conduct security testing on existing network solutions, thereby improving the security of smart scenarios. In addition, in active mode, the terminal device can actively detect the content to be tested, thereby improving the flexibility and diversity of detection.
[0180] Optionally, in the above Figure 3 On the basis of the corresponding embodiment, in another optional embodiment provided by the embodiment of the present application, the test data includes sensor network data;
[0181] The terminal device generates a data packet corresponding to the target attack type, which may include:
[0182] The terminal device generates data packets targeting public vulnerabilities and exposed CVE types;
[0183] The terminal device sends a data packet corresponding to the target attack type to the device to be detected in the LoRaWAN to be detected, so that the device to be detected generates feedback data according to the data packet corresponding to the target attack type, including:
[0184] The terminal device sends a data packet for the CVE type to a LoRaWAN node device in the LoRaWAN to be detected, so that the LoRaWAN node device generates feedback data according to the data packet for the CVE type.
[0185] This embodiment introduces a method for generating feedback data for LoRaWAN node devices. Taking the LoRaWAN node device as an example, the terminal device first generates a data packet corresponding to the target attack type based on the items to be detected. The terminal device then sends the data packet for the target attack type to the LoRaWAN node device in the LoRaWAN device to be detected, and the LoRaWAN node device generates feedback data for the target attack type.
[0186] Specifically, assuming the target attack type is a Common Vulnerabilities & Exposures (CVE) type, the terminal device, acting as the terminal test end, generates a data packet targeting the CVE type, where the CVE type can be CVE-2020-11068, simulating an attack type of CVE-2020-11068. The simulated CVE-2020-11068 type data packet is sent to the LoRaWAN node device, which generates corresponding feedback data and feeds it back to the terminal device.
[0187] For example, the feedback data generated by the LoRaWAN node device can be used as test data. For example, the feedback data includes network traffic, delay jitter, and resource utilization, etc. These feedback data can be used to analyze whether the LoRaWAN node device has the CVE-2020-11068 security vulnerability.
[0188] It should be noted that the CVE-2020-11068 vulnerability indicates a possible receive buffer overflow due to a failure to check the buffer size. Additionally, LoRaWAN node devices can be tested for other CVE-type vulnerabilities. CVE assigns a unique name and standardized description to each vulnerability and exposure.
[0189] Furthermore, in an embodiment of the present application, a method for generating feedback data for a LoRaWAN node device is provided. Through the above method, considering that for CVE vulnerability detection, the LoRaWAN node device usually actively feeds back data, an active mode can be used to send a CVE-type data packet to the LoRaWAN node device, so that the LoRaWAN node device generates feedback data based on the CVE-type data packet, thereby improving the flexibility of detection and simulating real network attacks to improve the reliability of detection.
[0190] Optionally, in the above Figure 3 On the basis of the corresponding embodiment, in another optional embodiment provided by the embodiment of the present application, the test data includes sensor network data or Ethernet network data;
[0191] The terminal device generates a data packet corresponding to the target attack type, which may include:
[0192] The terminal device generates data packets targeting dangerous port vulnerabilities;
[0193] Alternatively, the terminal device generates a data packet for gateway authentication access;
[0194] The terminal device sends a data packet corresponding to the target attack type to the device to be detected in the LoRaWAN to enable the device to be detected to generate feedback data according to the data packet corresponding to the target attack type, which may specifically include:
[0195] If a data packet targeting a dangerous port vulnerability is generated, the terminal device sends the data packet targeting the dangerous port vulnerability to the LoRaWAN gateway device in the LoRaWAN to be detected, so that the device to be detected generates feedback data according to the data packet targeting the dangerous port vulnerability;
[0196] If a data packet for gateway authentication access is generated, the terminal device sends the data packet for gateway authentication access to the LoRaWAN gateway device in the LoRaWAN to be detected, so that the device to be detected generates feedback data according to the data packet for gateway authentication access.
[0197] This embodiment introduces a method for generating feedback data for a LoRaWAN gateway device. Taking the LoRaWAN gateway device as an example, the terminal device first generates a data packet corresponding to the target attack type based on the items to be detected. The terminal device then sends the data packet for the target attack type to the LoRaWAN node device in the LoRaWAN device to be detected, and the LoRaWAN node device generates feedback data for the target attack type.
[0198] Specifically, assuming the target attack type is a dangerous port vulnerability, the terminal device, acting as the terminal test end, generates data packets targeting dangerous port vulnerabilities. Dangerous ports include but are not limited to TCP 20, TCP 21, TCP 22, TCP 25, TCP 53, TCP 69, TCP 443, and TCP 110. The terminal device can launch an attack against one or more dangerous ports, that is, send data packets to one or more high-risk ports of the LoRaWAN gateway device. The LoRaWAN gateway device generates corresponding feedback data and feeds it back to the terminal device.
[0199] For example, the feedback data generated by the LoRaWAN gateway device can be used as test data. For example, the feedback data includes vulnerability feature information, network traffic, delay jitter, and resource utilization, etc. These feedback data can be used to analyze whether the LoRaWAN gateway device has vulnerabilities such as high-risk port openings.
[0200] Specifically, assuming the target attack type is gateway authentication access, the terminal device, acting as the terminal test end, generates a data packet targeting gateway authentication access. The terminal device can launch an attack targeting gateway authentication access by sending an unauthenticated data packet to the LoRaWAN gateway. The LoRaWAN gateway generates corresponding feedback data and sends it back to the terminal device.
[0201] Exemplarily, the feedback data generated by the LoRaWAN gateway device can be used as test data. For example, the feedback data includes vulnerability feature information, network traffic, delay jitter, and resource utilization, etc. These feedback data can be used to analyze whether the LoRaWAN gateway device has unauthorized access vulnerabilities.
[0202] Furthermore, in an embodiment of the present application, a method for generating feedback data for a LoRaWAN gateway device is provided. Through the above method, considering that for dangerous port vulnerability detection and gateway authentication access detection, LoRaWAN node devices usually actively feedback data, therefore, an active mode can be adopted to send data packets for dangerous port vulnerability detection and gateway authentication access detection to the LoRaWAN node device, so that the LoRaWAN node device generates feedback data based on the data packets for dangerous port vulnerability detection and gateway authentication access detection, thereby improving the flexibility of detection, and simulating real network attacks to improve the reliability of detection.
[0203] Optionally, in the above Figure 3 On the basis of the corresponding embodiment, in another optional embodiment provided by the embodiment of the present application, the test data includes Ethernet network data;
[0204] The terminal device generates a data packet corresponding to the target attack type, which may include:
[0205] The terminal device generates a data packet for authorized access according to the communication protocol;
[0206] Alternatively, the terminal device generates a data packet for remote procedure call (RPC) authorization access;
[0207] Alternatively, the terminal device generates a data packet for password login;
[0208] Alternatively, the terminal device generates a data packet for authorized access to the database;
[0209] The terminal device sends a data packet corresponding to the target attack type to the device to be detected in the LoRaWAN to enable the device to be detected to generate feedback data according to the data packet corresponding to the target attack type, which may specifically include:
[0210] If a data packet for authorized access to the communication protocol is generated, the terminal device sends the data packet for authorized access to the communication protocol to the network server in the LoRaWAN to be detected, so that the device to be detected generates feedback data according to the data packet for authorized access to the communication protocol;
[0211] If a data packet for RPC authorized access is generated, the terminal device sends the data packet for RPC authorized access to the network server in the LoRaWAN to be detected, so that the device to be detected generates feedback data according to the data packet for RPC authorized access;
[0212] If a data packet for password login is generated, the terminal device sends the data packet for password login to the network server in the LoRaWAN to be detected, so that the device to be detected generates feedback data according to the data packet for password login;
[0213] If a data packet for authorized database access is generated, the terminal device sends the data packet for authorized database access to the network server in the LoRaWAN to be detected, so that the device to be detected generates feedback data according to the data packet for authorized database access.
[0214] This embodiment introduces a method for generating feedback data for a network server. Taking the network server as an example, the terminal device first generates a data packet corresponding to the target attack type based on the items to be detected. The terminal device then sends the data packet for the target attack type to the network server in the LoRaWAN network to be detected, and the network server generates feedback data for the target attack type.
[0215] Specifically, assuming the target attack type is communication protocol authorization access, the terminal device, acting as the terminal test end, generates a data packet targeting communication protocol authorization access. Communication protocol authorization access can refer to authorized access to the Message Queuing Telemetry Transport (MQTT) protocol. The terminal device can launch an attack targeting MQTT protocol authorization access, and the network server generates corresponding feedback data and feeds it back to the terminal device.
[0216] Exemplarily, the feedback data generated by the network server can be used as test data. For example, the feedback data includes vulnerability feature information, network traffic, delay jitter, and resource utilization, etc. These feedback data can be used to analyze whether the network server has an unauthorized access vulnerability of the MQTT protocol.
[0217] Assuming the target attack type is Remote Procedure Call (RPC) authorized access, the terminal device, acting as the terminal test end, generates a data packet targeting RPC authorized access, where RPC authorized access can refer to authorized access to Google Remote Procedure Call (gRPC). The terminal device can launch an attack targeting gRPC authorized access, and the network server generates corresponding feedback data and feeds it back to the terminal device.
[0218] Exemplarily, the feedback data generated by the network server can be used as test data. For example, the feedback data includes vulnerability feature information, network traffic, delay jitter, and resource utilization, etc. These feedback data can be used to analyze whether the network server has a gRPC unauthorized access vulnerability.
[0219] Assuming the target attack type is password login, the terminal device, acting as the terminal test end, generates a data packet targeting password login, where password login can refer to weak password login to the Hypertext Transfer Protocol (HTTP) backend server. The terminal device can launch an attack against the weak password login of the HTTP backend server, and the network server generates corresponding feedback data and feeds it back to the terminal device.
[0220] For example, the feedback data generated by the network server can be used as test data. For example, the feedback data includes vulnerability feature information, network traffic, delay jitter, and resource utilization, etc. These feedback data can be used to analyze whether the network server has a vulnerability of weak password login to the HTTP background server.
[0221] Assuming that the target attack type is database authorized access, based on this, the terminal device serving as the terminal test end generates a data packet targeting database authorized access. The terminal device can launch an attack targeting database authorized access, and the network server generates corresponding feedback data and feeds it back to the terminal device.
[0222] Exemplarily, the feedback data generated by the network server can be used as test data. For example, the feedback data includes vulnerability feature information, network traffic, delay jitter, and resource utilization, etc. These feedback data can be used to analyze whether the network server has a vulnerability of unauthorized database access.
[0223] Furthermore, in an embodiment of the present application, a method for generating feedback data for a network server is provided. Through the above method, considering that for communication protocol authorization detection, RPC authorization access detection, password login detection and database authorization access detection, LoRaWAN node devices usually actively feedback data, therefore, an active mode can be adopted to send data packets for communication protocol authorization detection, RPC authorization access detection, password login detection and database authorization access detection to the LoRaWAN node device, so that the LoRaWAN node device generates feedback data according to the data packets for communication protocol authorization detection, RPC authorization access detection, password login detection and database authorization access detection, thereby improving the flexibility of detection, and simulating real network attacks, which can improve the reliability of detection.
[0224] For easier understanding, see Figure 6 , Figure 6 This is a schematic diagram of an interface showing the network detection results in an embodiment of the present application. As shown in the figure, the server can also feed back the network detection results to the terminal device, and the terminal device displays the corresponding detection content through the interface. For example, "Node does not use OTAA key negotiation detection" is safe, and "HTTP background server weak password login" is dangerous. If the deployment personnel need to further view the specific detection data, they can click the "View details" module.
[0225] Combined with the above introduction, the network detection method in this application will be introduced below. Figure 7 Another embodiment of the network detection method in the embodiment of the present application includes:
[0226] 201. When a terminal device is connected to a LoRaWAN long-range wide area network to be detected, the server receives test data for the LoRaWAN to be detected sent by the terminal device, wherein the LoRaWAN to be detected is a network for communication between a LoRaWAN node device, a LoRaWAN gateway device, and a network server, and the test data includes at least one of sensor network data and Ethernet network data, the sensor network data includes data of the LoRaWAN node device and data of the LoRaWAN gateway device, and the Ethernet network data includes data of the LoRaWAN gateway device and data of the network server;
[0227] In this embodiment, the terminal device acting as the terminal test end must first connect to the LoRaWAN network to be tested. The LoRaWAN network to be tested includes a sensor network and an Ethernet network. The sensor network can be a WSN, and the Ethernet network can be a TCP / IP network. After connecting to the LoRaWAN network to be tested, the terminal device can obtain test data specific to the LoRaWAN network to be tested. Sensor network data can be extracted from the sensor network, and Ethernet network data can be extracted from the Ethernet network. Sensor network data includes data from LoRaWAN node devices and LoRaWAN gateway devices, while Ethernet network data includes data from LoRaWAN gateway devices and network servers.
[0228] It is understandable that since the LoRaWAN gateway device can communicate with both the LoRaWAN node device and the network server, the data of the LoRaWAN gateway device belongs to both sensor network data and Ethernet network data, which is not limited here.
[0229] It should be noted that the types of functions of LoRaWAN node devices, LoRaWAN gateway devices and network servers have been introduced above and will not be repeated here.
[0230] 202. The server performs feature analysis on the test data to generate a network detection result for the LoRaWAN to be detected, wherein the network detection result indicates a detection result of network security.
[0231] In this embodiment, the terminal device feeds the collected test data back to the server, which serves as the cloud analysis feedback end. The server further performs feature analysis on the test data to generate network detection results for the LoRaWAN network to be detected. Specifically, the server can generate detection results for each component of the LoRaWAN network to be detected (i.e., LoRaWAN node devices, LoRaWAN gateway devices, and network servers).
[0232] The server-side database stores various detection rules, which are regularly maintained and can be customized to meet diverse security requirements or anomaly detection needs. When new vulnerabilities or security risks emerge, rules can be expanded to meet dynamic security detection needs. Furthermore, network traffic analysis and clustering can be performed based on reported test data. This, combined with machine learning algorithms, complements the database's detection rules, providing a flexible detection mechanism.
[0233] In an embodiment of the present application, another network detection method is provided. First, when a terminal device is connected to a long-distance wide area network (LoRaWAN) to be detected, a server receives test data for the LoRaWAN to be detected sent by the terminal device. The test data includes at least one of sensor network data and Ethernet network data. The sensor network data includes data of LoRaWAN node devices and data of LoRaWAN gateway devices. The Ethernet network data includes data of LoRaWAN gateway devices and data of network servers. Thus, the server performs feature analysis on the test data to generate a network detection result for the LoRaWAN to be detected. In this way, based on the sensor network data and Ethernet network data, the LoRaWAN node devices, LoRaWAN gateway devices, and network servers are detected. That is, from the perspective of the entire network architecture, the key components in the LoRaWAN are automatically detected, compensating for the risks introduced by the lack of security experience or insufficient security awareness of project deployment personnel, thereby improving the reliability of the LoRaWAN deployment.
[0234] Optionally, in the above Figure 7 On the basis of the corresponding embodiment, in another optional embodiment provided by the embodiment of the present application, the test data includes sensor network data;
[0235] The server receives test data for the LoRaWAN to be tested from the terminal device, which may include:
[0236] When the LoRaWAN node device is in a powered-on or normal operating state, receiving LoRaWAN sensor network data to be detected sent by the terminal device, wherein the sensor network data includes at least one of a key negotiation data message and key encryption data of the LoRaWAN node device;
[0237] The server performs feature analysis on the test data to generate network detection results for the LoRaWAN network to be detected, which may include:
[0238] The server performs feature analysis on at least one of the key negotiation data message and the key encryption data to generate a network detection result for the LoRaWAN node device in the LoRaWAN to be detected.
[0239] This embodiment describes a method for generating test data in passive mode. In passive mode, a terminal device, acting as a terminal test end, uses a data sniffing module to sniff data from the device under test during startup and normal operation. This data is used as test data and sent to the feedback reporting module. It should be noted that the device under test can be one or more of a LoRaWAN node device, a LoRaWAN gateway device, and a network server, and this is not limited here.
[0240] Specifically, assuming the test data includes a key negotiation data message, after the server receives the key negotiation data message sent by the terminal device, it can detect whether the LoRaWAN node device uses OTAA key negotiation based on the characteristics of the key negotiation data message. If the key negotiation data message is detected, it means that the LoRaWAN node device has used OTAA key negotiation. If the key negotiation data message is not detected, it means that the LoRaWAN node device is not using OTAA key negotiation, that is, there is a security vulnerability.
[0241] Assuming the test data includes key-encrypted data, after the server receives the key-encrypted data from the terminal device, it can detect whether the LoRaWAN node device is using an OTAA weak key based on the content of the key-encrypted data, according to the protocol specification and known weak keys. If the result calculated using the weak key is consistent with the content of the key-encrypted data of the LoRaWAN node device, the LoRaWAN node device is using an OTAA weak key. If the result calculated using the weak key is inconsistent with the content of the key-encrypted data of the LoRaWAN node device, the LoRaWAN node device is not using an OTAA weak key. If a LoRaWAN node device uses an OTAA weak key, a security vulnerability may exist.
[0242] Secondly, the embodiments of the present application provide a method for generating test data in passive mode. Through this method, the terminal device acting as the terminal test end can sniff data based on the currently deployed network, and ultimately determine the security of the LoRaWAN to be tested based on the sniffed test data. This can accurately and objectively help project deployment personnel and acceptance personnel conduct security assessments, or conduct security testing on existing network solutions, thereby improving the security of smart scenarios. In addition, in passive mode, the terminal device only needs to wait for test data actively fed back from the LoRaWAN to be tested. On the one hand, this improves the efficiency of the test, and on the other hand, it does not need to actively send instructions to the various components in the LoRaWAN to be tested, thereby saving the power consumption of the terminal device and reducing processing resources.
[0243] Optionally, in the above Figure 7 On the basis of the corresponding embodiment, in another optional embodiment provided by the embodiment of the present application, the test data includes sensor network data and Ethernet network data;
[0244] The server receives test data for the LoRaWAN to be tested from the terminal device, which may include:
[0245] The server receives test data sent by the terminal device for common vulnerabilities and exposed CVE types in the LoRaWAN to be detected, dangerous port vulnerabilities, gateway authentication access, communication protocol authorization access, remote procedure call (RPC) authorization access, password login, and database authorization access.
[0246] The server performs feature analysis on the test data to generate network detection results for the LoRaWAN network to be detected, which may include:
[0247] The server generates network detection results for the LoRaWAN node devices, LoRaWAN gateway devices and network servers in the LoRaWAN to be tested based on the test data corresponding to CVE type, dangerous port vulnerability, gateway authentication access, communication protocol authorization access, RPC authorization access, password login and database authorization access.
[0248] This embodiment introduces a method for generating test data in active mode. In active mode, the terminal device serving as the terminal test end generates a corresponding data packet based on the target attack type, and then sends the data packet corresponding to the target attack type to the device to be tested in the LoRaWAN to be tested. The device to be tested generates a response based on the data packet, that is, generates feedback data, where the feedback data can serve as test data. Finally, the device to be tested sends the feedback data to the terminal device, that is, the terminal device obtains the feedback data through the data sniffing module. It should be noted that the device to be tested can be one or more of a LoRaWAN node device, a LoRaWAN gateway device, and a network server, which is not limited here.
[0249] Specifically, assuming that after sending a CVE-2020-11068 data packet to a LoRaWAN node device, the feedback data includes a CVE-2020-11068 type vulnerability detection result. The server can determine whether the LoRaWAN node device has a CVE-2020-11068 type vulnerability based on the CVE-2020-11068 type vulnerability detection result.
[0250] Assume that after sending a data packet for opening a high-risk port of a LoRaWAN gateway, the feedback data includes a detection result of the high-risk port opening. The server can determine whether the LoRaWAN gateway device has opened a high-risk port based on the detection result of the high-risk port opening.
[0251] Assume that after sending a data packet for unauthenticated access to the LoRaWAN gateway, the feedback data includes the unauthenticated access vulnerability detection result. The server can determine whether the LoRaWAN gateway device has an unauthenticated access vulnerability based on the unauthenticated access vulnerability detection result.
[0252] Assume that after sending an MQTT protocol unauthorized access data packet to the LoRaWAN network server, the feedback data includes a detection result of the MQTT protocol unauthorized access. The server can determine whether the network server has an MQTT protocol unauthorized access vulnerability based on the detection result of the MQTT protocol unauthorized access.
[0253] Assume that after sending a gRPC unauthorized access data packet to the LoRaWAN network server, the feedback data includes the detection result of the gRPC unauthorized access. The server can determine whether the network server has a gRPC unauthorized access vulnerability based on the detection result of the gRPC unauthorized access.
[0254] Assume that after sending a weak password login test data packet to the LoRaWAN network server, the feedback data includes the detection result of the weak password login of the HTTP background server. The server can determine whether the network server has a vulnerability of weak password login of the HTTP background server based on the detection result of the weak password login of the HTTP background server.
[0255] Assume that after sending a database unauthorized access test data packet to the LoRaWAN network server, the feedback data includes the detection result of the database unauthorized access. The server can determine whether the network server has a database unauthorized access vulnerability based on the detection result of the database unauthorized access.
[0256] Secondly, the embodiments of this application provide a method for generating test data in active mode. Through this method, the terminal device, acting as the terminal test end, can generate and send test data packets based on the currently deployed network, and ultimately determine the security of the LoRaWAN to be tested based on the received feedback data. This can accurately and objectively help project deployment and acceptance personnel conduct security assessments or conduct security testing on existing network solutions, thereby improving the security of smart scenarios. In addition, in active mode, the terminal device can actively detect the content to be tested, thereby increasing the flexibility and diversity of detection.
[0257] For easier understanding, see Figure 8 , Figure 8 This is a schematic diagram of the framework of cloud analysis feedback in the embodiment of this application. As shown in the figure, the feature analysis module can respectively detect LoRaWAN node devices, LoRaWAN gateway devices, and network servers. The detection content is as described in the previous embodiment, so it is not repeated here. The result display module displays the network detection results through email or platform, etc. The network detection results will give different risk warnings according to different security risks and provide users with repair suggestions. It helps acceptance members to reasonably and objectively evaluate the security of the LoRaWAN, and can also verify the security risks of the existing network and provide reinforcement suggestions, thereby improving the security of the entire LoRaWAN project and ensuring the deployment quality.
[0258] Compared with the current security research on LoRaWAN networks, this application fills the gap in the market where there are no tools or solutions for assessing and detecting LoRaWAN security flaws. At the same time, it can be used to accept or detect the security of existing LoRaWAN network project deployments. This application can effectively and objectively conduct security assessments on smart scenario solutions that have already deployed LoRaWAN, compensating for the security risks introduced by the project deployment implementers or acceptance parties due to the lack of relevant security experience or security awareness, thereby ensuring the security of LoRaWAN network projects.
[0259] The network detection device in this application is described in detail below. Figure 9 , Figure 9 This is a schematic diagram of an embodiment of a network detection device in an embodiment of the present application. The network detection device 30 includes:
[0260] An access module 301 is configured to access a long-distance wide area network (LoRaWAN) to be detected, wherein the LoRaWAN to be detected is a network for communication between LoRaWAN node devices, LoRaWAN gateway devices, and network servers;
[0261] an acquisition module 302 for acquiring test data for a LoRaWAN to be tested, wherein the test data includes at least one of sensor network data and Ethernet network data, the sensor network data includes data of a LoRaWAN node device and data of a LoRaWAN gateway device, and the Ethernet network data includes data of a LoRaWAN gateway device and data of a network server;
[0262] The sending module 303 is used to send test data to the server, so that the server performs feature analysis on the test data to generate a network detection result for the LoRaWAN to be detected, wherein the network detection result represents a detection result of network security.
[0263] In an embodiment of the present application, a network detection device is provided. The above device is used to detect LoRaWAN node devices, LoRaWAN gateway devices and network servers based on sensor network data and Ethernet network data. That is, from the perspective of the entire network architecture, the key components in LoRaWAN are automatically detected to compensate for the risks introduced by the lack of security experience or insufficient security awareness of project deployment personnel, thereby improving the reliability of LoRaWAN deployment.
[0264] Optionally, in the above Figure 9 Based on the embodiment of the present application, in another embodiment of the network detection device 30 provided in the embodiment of the present application,
[0265] The acquisition module 302 is specifically configured to acquire Ethernet network data if the Ethernet network included in the LoRaWAN to be detected is accessed;
[0266] If the sensor network included in the LoRaWAN to be detected is connected, the sensor network data is obtained;
[0267] If the Ethernet network and sensor network included in the LoRaWAN to be detected are connected, the Ethernet network data and the sensor network data are obtained.
[0268] In an embodiment of the present application, a network detection device is provided. By using the above device, a terminal device can determine one or more specific network types based on the connected LoRaWAN to be detected. If only a sensor network is connected, the terminal device will subsequently only detect data related to the LoRaWAN node device and the LoRaWAN gateway device. If only an Ethernet network is connected, the terminal device will subsequently only detect data related to the server and the LoRaWAN gateway device. As a result, the flexibility of detection can be improved, and device detection can be implemented in a targeted manner, thereby improving the diversity of solutions.
[0269] Optionally, in the above Figure 9 Based on the embodiment of the present application, in another embodiment of the network detection device 30 provided in the embodiment of the present application,
[0270] The acquisition module 302 is specifically used to obtain the network status of the LoRaWAN to be detected as test data when the device to be detected is in the power-on state or the normal operation state, wherein the device to be detected is at least one of a LoRaWAN node device, a LoRaWAN gateway device and a network server.
[0271] In an embodiment of the present application, a network detection device is provided. Using this device, a terminal device acting as a terminal test end can perform data sniffing based on the currently deployed network, ultimately determining the security of the LoRaWAN to be tested based on the sniffed test data. This can accurately and objectively assist project deployment and acceptance personnel in conducting security assessments or performing security testing on existing network solutions, thereby improving the security of smart scenarios. Furthermore, in passive mode, the terminal device simply waits for test data actively fed back from the LoRaWAN to be tested. This not only improves test efficiency, but also eliminates the need to actively send instructions to various components in the LoRaWAN to be tested, thereby saving power consumption and processing resources on the terminal device.
[0272] Optionally, in the above Figure 9 Based on the embodiment of the present application, in another embodiment of the network detection device 30 provided in the embodiment of the present application, the test data includes sensor network data;
[0273] The acquisition module 302 is specifically configured to acquire the sensor network data of the LoRaWAN to be detected when the LoRaWAN node device is in a powered-on state or a normal operating state, wherein the sensor network data includes at least one of a key negotiation data message and key encryption data of the LoRaWAN node device.
[0274] In an embodiment of the present application, a network detection device is provided. Considering that LoRaWAN nodes typically do not actively provide data for key detection, a passive mode can be used to wait for the LoRaWAN node to return at least one of the key negotiation data message and key-encrypted data, thereby improving detection reliability. Furthermore, passive testing can be used to monitor the presence of attacks in real time, thereby enhancing the security of communications between components within the LoRaWAN network.
[0275] Optionally, in the above Figure 9 Based on the embodiment of the present application, in another embodiment of the network detection device 30 provided in the embodiment of the present application,
[0276] Acquisition module 302, specifically for generating a data packet corresponding to the target attack type;
[0277] Sending a data packet corresponding to the target attack type to the device to be detected in the LoRaWAN to be detected, so that the device to be detected generates feedback data according to the data packet corresponding to the target attack type;
[0278] Receive feedback data as test data.
[0279] In an embodiment of the present application, a network detection device is provided. Using this device, a terminal device acting as a terminal test end can generate and send test data packets based on the currently deployed network. Ultimately, the security of the LoRaWAN network being tested is determined based on the received feedback data. This accurately and objectively assists project deployment and acceptance personnel in conducting security assessments or performing security testing on existing network solutions, thereby improving the security of smart scenarios. Furthermore, in active mode, the terminal device can proactively detect the content to be tested, thereby increasing the flexibility and diversity of detection.
[0280] Optionally, in the above Figure 9 Based on the embodiment of the present application, in another embodiment of the network detection device 30 provided in the embodiment of the present application, the test data includes sensor network data;
[0281] The acquisition module 302 is specifically used to generate a data packet targeting a common vulnerability and exposed CVE type;
[0282] A data packet for the CVE type is sent to a LoRaWAN node device in the LoRaWAN to be detected, so that the LoRaWAN node device generates feedback data according to the data packet for the CVE type.
[0283] In an embodiment of the present application, a network detection device is provided. Using the above device, considering that for CVE vulnerability detection, LoRaWAN node devices usually actively feedback data, an active mode can be adopted to send CVE-type data packets to the LoRaWAN node devices, so that the LoRaWAN node devices generate feedback data based on the CVE-type data packets, thereby improving the flexibility of detection and simulating real network attacks to improve the reliability of detection.
[0284] Optionally, in the above Figure 9 Based on the embodiment of the present application, in another embodiment of the network detection device 30 provided in the embodiment of the present application, the test data includes sensor network data or Ethernet network data;
[0285] The acquisition module 302 is specifically used to generate a data packet targeting a dangerous port vulnerability;
[0286] Alternatively, a data packet is generated for gateway authentication access;
[0287] If a data packet targeting a dangerous port vulnerability is generated, the data packet targeting the dangerous port vulnerability is sent to a LoRaWAN gateway device in the LoRaWAN to be detected, so that the device to be detected generates feedback data according to the data packet targeting the dangerous port vulnerability;
[0288] If a data packet for gateway authentication access is generated, the data packet for gateway authentication access is sent to the LoRaWAN gateway device in the LoRaWAN to be detected, so that the device to be detected generates feedback data according to the data packet for gateway authentication access.
[0289] In an embodiment of the present application, a network detection device is provided. Using the above device, considering that for dangerous port vulnerability detection and gateway authentication access detection, LoRaWAN node devices usually actively feedback data, an active mode can be adopted to send data packets for dangerous port vulnerability detection and gateway authentication access detection to the LoRaWAN node device, so that the LoRaWAN node device generates test data based on the data packets for dangerous port vulnerability detection and gateway authentication access detection, thereby improving the flexibility of detection and simulating real network attacks to improve the reliability of detection.
[0290] Optionally, in the above Figure 9 Based on the embodiment of the present application, in another embodiment of the network detection device 30 provided by the embodiment of the present application, the test data includes Ethernet network data;
[0291] The acquisition module 302 is specifically used to generate a data packet for authorized access according to the communication protocol;
[0292] Alternatively, a data packet for remote procedure call (RPC) authorization access is generated;
[0293] Alternatively, generate a data packet for password login;
[0294] Alternatively, a data packet is generated for authorized access to the database;
[0295] If a data packet for authorized access to the communication protocol is generated, the data packet for authorized access to the communication protocol is sent to the network server in the LoRaWAN to be detected, so that the device to be detected generates feedback data according to the data packet for authorized access to the communication protocol;
[0296] If a data packet for RPC authorized access is generated, the data packet for RPC authorized access is sent to the network server in the LoRaWAN to be detected, so that the device to be detected generates feedback data according to the data packet for RPC authorized access;
[0297] If a data packet for password login is generated, the data packet for password login is sent to the network server in the LoRaWAN to be detected, so that the device to be detected generates feedback data according to the data packet for password login;
[0298] If a data packet for authorized database access is generated, the data packet for authorized database access is sent to a network server in the LoRaWAN to be detected, so that the device to be detected generates feedback data according to the data packet for authorized database access.
[0299] In an embodiment of the present application, a network detection device is provided. Using the above-mentioned device, considering that the LoRaWAN node device usually actively feeds back data for communication protocol authorization detection, RPC authorization access detection, password login detection and database authorization access detection, an active mode can be adopted to send data packets for communication protocol authorization detection, RPC authorization access detection, password login detection and database authorization access detection to the LoRaWAN node device, so that the LoRaWAN node device generates test data according to the data packets for communication protocol authorization detection, RPC authorization access detection, password login detection and database authorization access detection, thereby improving the flexibility of detection, and simulating real network attacks to improve the reliability of detection.
[0300] The network detection device in this application is described in detail below. Figure 10 , Figure 10 This is a schematic diagram of an embodiment of a network detection device in an embodiment of the present application. The network detection device 40 includes:
[0301] a receiving module 401 configured to receive test data for the LoRaWAN to be detected, sent by the terminal device when the terminal device is connected to the LoRaWAN long-range wide area network to be detected, wherein the LoRaWAN to be detected is a network for communication between LoRaWAN node devices, LoRaWAN gateway devices, and network servers, and the test data includes at least one of sensor network data and Ethernet network data, the sensor network data includes data from the LoRaWAN node devices and data from the LoRaWAN gateway devices, and the Ethernet network data includes data from the LoRaWAN gateway devices and data from the network server;
[0302] The generating module 402 is configured to perform feature analysis on the test data to generate a network detection result for the LoRaWAN to be detected, wherein the network detection result represents a detection result of network security.
[0303] In an embodiment of the present application, a network detection device is provided. The above device is used to detect LoRaWAN node devices, LoRaWAN gateway devices and network servers based on sensor network data and Ethernet network data. That is, from the perspective of the entire network architecture, the key components in LoRaWAN are automatically detected to compensate for the risks introduced by the lack of security experience or insufficient security awareness of project deployment personnel, thereby improving the reliability of LoRaWAN deployment.
[0304] Optionally, in the above Figure 10 Based on the embodiment of the present application, in another embodiment of the network detection device 40 provided in the embodiment of the present application, the test data includes sensor network data;
[0305] The receiving module 401 specifically receives LoRaWAN sensor network data to be detected sent by the terminal device when the LoRaWAN node device is in a powered-on state or a normal operating state, wherein the sensor network data includes at least one of a key negotiation data message and key encryption data of the LoRaWAN node device;
[0306] The generating module 402 is specifically configured to perform feature analysis on at least one of the key negotiation data message and the key encryption data to generate a network detection result for a LoRaWAN node device in the LoRaWAN to be detected.
[0307] In an embodiment of the present application, a network detection device is provided. Using this device, a terminal device acting as a terminal test end can perform data sniffing based on the currently deployed network, ultimately determining the security of the LoRaWAN to be tested based on the sniffed test data. This can accurately and objectively assist project deployment and acceptance personnel in conducting security assessments or performing security testing on existing network solutions, thereby improving the security of smart scenarios. Furthermore, in passive mode, the terminal device simply waits for test data actively fed back from the LoRaWAN to be tested. This not only improves test efficiency, but also eliminates the need to actively send instructions to various components in the LoRaWAN to be tested, thereby saving power consumption and processing resources on the terminal device.
[0308] Optionally, in the above Figure 10 Based on the embodiment of the present application, in another embodiment of the network detection device 40 provided in the embodiment of the present application, the test data includes sensor network data and Ethernet network data;
[0309] The receiving module 401 is specifically configured to receive test data corresponding to common vulnerabilities and exposed CVE types, dangerous port vulnerabilities, gateway authentication access, communication protocol authorization access, remote procedure call (RPC) authorization access, password login, and database authorization access in the LoRaWAN to be detected, sent by the terminal device;
[0310] The generation module 402 is specifically used to generate network detection results for LoRaWAN node devices, LoRaWAN gateway devices and network servers in the LoRaWAN to be detected based on the test data corresponding to the CVE type, dangerous port vulnerability, gateway authentication access, communication protocol authorization access, RPC authorization access, password login and database authorization access.
[0311] In an embodiment of the present application, a network detection device is provided. Using this device, a terminal device acting as a terminal test end can generate and send test data packets based on the currently deployed network. Ultimately, the security of the LoRaWAN network being tested is determined based on the received feedback data. This accurately and objectively assists project deployment and acceptance personnel in conducting security assessments or performing security testing on existing network solutions, thereby improving the security of smart scenarios. Furthermore, in active mode, the terminal device can proactively detect the content to be tested, thereby increasing the flexibility and diversity of detection.
[0312] The embodiment of the present application also provides another network detection device, which can be deployed in a terminal device, such as Figure 11For ease of explanation, only the parts related to the embodiments of the present application are shown. For specific technical details not disclosed, please refer to the method part of the embodiments of the present application. The terminal device can be any terminal device including a mobile phone, tablet computer, personal digital assistant (PDA), point of sales (POS), car computer, etc. For example, the terminal device is a personal computer:
[0313] Figure 11 The block diagram shows a partial structure of a personal computer related to the terminal device provided in the embodiment of the present application. Figure 11 The personal computer includes components such as a radio frequency (RF) circuit 510, a memory 520, an input unit 530, a display unit 540, a sensor 550, an audio circuit 560, a wireless fidelity (WiFi) module 570, a processor 580, and a power supply 590. Those skilled in the art will understand that Figure 11 The personal computer structure shown in the figure does not constitute a limitation to the personal computer, and may include more or fewer components than shown in the figure, or combine certain components, or arrange the components differently.
[0314] The following combination Figure 11 A detailed introduction to the various components of a personal computer:
[0315] The RF circuit 510 can be used to receive and send signals during information transmission or calls. In particular, after receiving the downlink information from the base station, it is sent to the processor 580 for processing; in addition, the designed uplink data is sent to the base station. Generally, the RF circuit 510 includes but is not limited to an antenna, at least one amplifier, a transceiver, a coupler, a low noise amplifier (LNA), a duplexer, etc. In addition, the RF circuit 510 can also communicate with the network and other devices through wireless communication. The above-mentioned wireless communication can use any communication standard or protocol, including but not limited to Global System of Mobile communication (GSM), General Packet Radio Service (GPRS), Code Division Multiple Access (CDMA), Wideband Code Division Multiple Access (WCDMA), Long Term Evolution (LTE), email, Short Messaging Service (SMS), etc.
[0316] Memory 520 can be used to store software programs and modules. Processor 580 executes the various functional applications and data processing of the personal computer by running the software programs and modules stored in memory 520. Memory 520 may primarily include a program storage area and a data storage area. The program storage area may store an operating system and at least one application required for a function (such as a sound playback function, an image playback function, etc.); the data storage area may store data created based on the use of the personal computer (such as audio data, a phone book, etc.). In addition, memory 520 may include high-speed random access memory and non-volatile memory, such as at least one disk storage device, a flash memory device, or other volatile solid-state storage device.
[0317] The input unit 530 can be used to receive input digital or character information, and to generate key signal input related to the user settings and function control of the personal computer. Specifically, the input unit 530 may include a touch panel 531 and other input devices 532. The touch panel 531, also known as a touch screen, can collect user touch operations on or near it (such as operations performed by the user using any suitable object or accessory such as a finger, stylus, etc. on or near the touch panel 531) and drive the corresponding connection device according to a pre-set program. Optionally, the touch panel 531 may include two parts: a touch detection device and a touch controller. Among them, the touch detection device detects the user's touch direction and detects the signal caused by the touch operation, and transmits the signal to the touch controller; the touch controller receives the touch information from the touch detection device and converts it into touch point coordinates, which are then sent to the processor 580. It can also receive commands sent by the processor 580 and execute them. In addition, the touch panel 531 can be implemented using various types such as resistive, capacitive, infrared and surface acoustic wave. In addition to the touch panel 531, the input unit 530 may further include other input devices 532. Specifically, the other input devices 532 may include, but are not limited to, one or more of a physical keyboard, function keys (such as volume control keys, switch keys, etc.), a trackball, a mouse, and a joystick.
[0318] The display unit 540 can be used to display information input by the user or information provided to the user and various menus of the personal computer. The display unit 540 may include a display panel 541. Optionally, the display panel 541 may be configured in the form of a liquid crystal display (LCD), an organic light-emitting diode (OLED), etc. Further, the touch panel 531 may cover the display panel 541. When the touch panel 531 detects a touch operation on or near it, it is transmitted to the processor 580 to determine the type of touch event. Subsequently, the processor 580 provides corresponding visual output on the display panel 541 according to the type of touch event. Although in Figure 11 In the embodiment, the touch panel 531 and the display panel 541 are used as two independent components to realize the input and output functions of the personal computer. However, in some embodiments, the touch panel 531 and the display panel 541 can be integrated to realize the input and output functions of the personal computer.
[0319] The personal computer may also include at least one sensor 550, such as a light sensor, a motion sensor, and other sensors. Specifically, the light sensor may include an ambient light sensor and a proximity sensor, wherein the ambient light sensor may adjust the brightness of the display panel 541 according to the brightness of the ambient light, and the proximity sensor may turn off the display panel 541 and / or the backlight when the personal computer is moved to the ear. As a type of motion sensor, the accelerometer sensor can detect the magnitude of acceleration in all directions (generally three axes), and can detect the magnitude and direction of gravity when stationary. It can be used for applications that recognize the posture of the personal computer (such as horizontal and vertical screen switching, related games, magnetometer posture calibration), vibration recognition related functions (such as pedometer, tapping), etc.; as for other sensors that the personal computer can also be configured with, such as gyroscopes, barometers, hygrometers, thermometers, infrared sensors, etc., they will not be described in detail here.
[0320] Audio circuit 560, speaker 561, and microphone 562 provide an audio interface between the user and the personal computer. Audio circuit 560 converts received audio data into electrical signals and transmits them to speaker 561, where they are converted into sound signals for output. Microphone 562, on the other hand, converts collected sound signals into electrical signals, which are then received by audio circuit 560 and converted into audio data. The audio data is then processed by processor 580 and transmitted to, for example, another personal computer via RF circuit 510, or stored in memory 520 for further processing.
[0321] WiFi is a short-range wireless transmission technology. Personal computers can help users send and receive emails, browse web pages, and access streaming media through the WiFi module 570. It provides users with wireless broadband Internet access. Figure 11 A WiFi module 570 is shown, but it is understandable that it is not an essential component of the personal computer and can be omitted as needed without changing the essence of the invention.
[0322] Processor 580 is the control center of the PC. It connects all components of the PC using various interfaces and circuits. By running or executing software programs and / or modules stored in memory 520 and accessing data stored in memory 520, it performs various PC functions and processes data, thereby providing overall management of the PC. Optionally, processor 580 may include one or more processing units. Alternatively, processor 580 may integrate an application processor and a modem processor. The application processor primarily handles the operating system, user interface, and application programs, while the modem processor primarily handles wireless communications. It is understood that the modem processor may not be integrated into processor 580.
[0323] The personal computer also includes a power supply 590 (such as a battery) for supplying power to various components. Optionally, the power supply can be logically connected to the processor 580 through a power management system, thereby managing functions such as charging, discharging, and power consumption through the power management system.
[0324] Although not shown, the personal computer may also include a camera, a Bluetooth module, etc., which will not be described in detail here.
[0325] The steps performed by the terminal device in the above embodiment can be based on the Figure 11 The terminal device structure shown.
[0326] Figure 12 6 is a schematic diagram of a server structure provided in an embodiment of the present application. The server 600 may have relatively large differences due to different configurations or performances, and may include one or more central processing units (CPUs) 622 (for example, one or more processors) and a memory 632, and one or more storage media 630 (for example, one or more mass storage devices) for storing application programs 642 or data 644. Among them, the memory 632 and the storage medium 630 can be temporary storage or permanent storage. The program stored in the storage medium 630 may include one or more modules (not shown in the figure), and each module may include a series of instruction operations on the server. Furthermore, the central processing unit 622 can be configured to communicate with the storage medium 630 to execute a series of instruction operations in the storage medium 630 on the server 600.
[0327] The server 600 may also include one or more power supplies 626, one or more wired or wireless network interfaces 650, one or more input and output interfaces 658, and / or one or more operating systems 641, such as Windows Server 2000. TM , Mac OS X TM , Unix TM ,Linux TM , FreeBSD TM etc.
[0328] The steps performed by the server in the above embodiment can be based on the Figure 12 The server structure shown.
[0329] A computer-readable storage medium is also provided in an embodiment of the present application. The computer-readable storage medium stores a computer program, which, when executed on a computer, enables the computer to execute the methods described in the aforementioned embodiments.
[0330] An embodiment of the present application also provides a computer program product including a program, which, when executed on a computer, enables the computer to execute the methods described in the aforementioned embodiments.
[0331] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0332] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, devices or units, which can be electrical, mechanical or other forms.
[0333] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0334] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0335] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
[0336] As described above, the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the above embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the above embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application.
Claims
1. A network detection method, characterized in that: Used to automatically detect key components in LoRaWAN, including: Accessing a long-distance wide area network (LoRaWAN) to be detected, wherein the LoRaWAN to be detected is a network for communication between LoRaWAN node devices, LoRaWAN gateway devices, and network servers; Acquire test data for the LoRaWAN to be tested, wherein the test data includes data information and network feedback status, the test data includes at least one of sensor network data and Ethernet network data, the sensor network data includes data of the LoRaWAN node device and data of the LoRaWAN gateway device, and the Ethernet network data includes data of the LoRaWAN gateway device and data of the network server; Sending the test data to the server so that the server performs feature analysis on the test data to generate a network detection result for the LoRaWAN to be tested to determine whether the current deployment complies with security specifications, wherein the network detection result represents a network security detection result, and the detection result includes security detection of LoRaWAN node devices, security detection of LoRaWAN gateway devices, and security detection of network servers. The security detection of LoRaWAN node devices includes node non-use OTAA key negotiation detection, node OTAA weak key detection, and node protocol stack CVE-2020-11062 detection. The security detection of LoRaWAN gateway devices includes high-risk port open detection and unauthorized access detection. The security detection of network servers includes MQTT unauthorized access detection, gRPC unauthorized access detection, HTTP background server weak password login detection, and database unauthorized access detection. The obtaining of test data for the LoRaWAN to be detected includes: When the device to be detected is in a powered-on and networked state or a normal operating state, obtaining the network state of the LoRaWAN to be detected as the test data, wherein the device to be detected is at least one of the LoRaWAN node device, the LoRaWAN gateway device, and the network server, and the test data includes the sensor network data. When the device to be detected is in a powered-on and networked state or a normal operating state, obtaining the network state of the LoRaWAN to be detected as the test data includes: when the LoRaWAN node device is in a powered-on and networked state or a normal operating state, obtaining the sensor network data of the LoRaWAN to be detected, wherein the sensor network data includes at least one of a key negotiation data message and key encryption data of the LoRaWAN node device; or, Generate a data packet corresponding to the target attack type; send the data packet corresponding to the target attack type to the device to be detected in the LoRaWAN to be detected, so that the device to be detected generates feedback data according to the data packet corresponding to the target attack type; receive the feedback data as the test data.
2. The method according to claim 1, characterized in that The obtaining of test data for the LoRaWAN to be detected includes: If the Ethernet network included in the LoRaWAN to be detected is connected, the Ethernet network data is obtained; If the sensor network included in the LoRaWAN to be detected is connected, the sensor network data is obtained; If the Ethernet network and the sensor network included in the LoRaWAN to be detected are accessed, the Ethernet network data and the sensor network data are obtained.
3. The method according to claim 1, characterized in that The test data includes the sensor network data; Generating a data packet corresponding to the target attack type includes: Generate data packages targeting public vulnerabilities and exposed CVE types; The sending of a data packet corresponding to the target attack type to the device to be detected in the LoRaWAN to be detected, so that the device to be detected generates feedback data according to the data packet corresponding to the target attack type, includes: Sending a data packet for the CVE type to the LoRaWAN node device in the LoRaWAN to be detected, so that the LoRaWAN node device generates the feedback data according to the data packet for the CVE type.
4. The method according to claim 1, wherein The test data includes the sensor network data or the Ethernet network data; Generating a data packet corresponding to the target attack type includes: Generate data packets targeting dangerous port vulnerabilities; Alternatively, a data packet is generated for gateway authentication access; The sending of a data packet corresponding to the target attack type to the device to be detected in the LoRaWAN to be detected, so that the device to be detected generates feedback data according to the data packet corresponding to the target attack type, includes: If a data packet targeting the dangerous port vulnerability is generated, sending the data packet targeting the dangerous port vulnerability to the LoRaWAN gateway device in the LoRaWAN to be detected, so that the device to be detected generates the feedback data according to the data packet targeting the dangerous port vulnerability; If a data packet for the gateway authentication access is generated, the data packet for the gateway authentication access is sent to the LoRaWAN gateway device in the LoRaWAN to be detected, so that the device to be detected generates the feedback data according to the data packet for the gateway authentication access.
5. The method according to claim 1, wherein The test data includes the Ethernet network data; Generating a data packet corresponding to the target attack type includes: Generate data packets for communication protocol authorization access; Alternatively, a data packet for remote procedure call (RPC) authorization access is generated; Alternatively, generate a data packet for password login; Alternatively, a data packet is generated for authorized access to the database; The sending of a data packet corresponding to the target attack type to the device to be detected in the LoRaWAN to be detected, so that the device to be detected generates feedback data according to the data packet corresponding to the target attack type, includes: If a data packet for authorized access to the communication protocol is generated, the data packet for authorized access to the communication protocol is sent to the network server in the LoRaWAN to be detected, so that the device to be detected generates the feedback data according to the data packet for authorized access to the communication protocol; If a data packet for the RPC authorized access is generated, sending the data packet for the RPC authorized access to the network server in the LoRaWAN to be detected, so that the device to be detected generates the feedback data according to the data packet for the RPC authorized access; If a data packet for the password login is generated, sending the data packet for the password login to the network server in the LoRaWAN to be detected, so that the device to be detected generates the feedback data according to the data packet for the password login; If a data packet for authorized access to the database is generated, the data packet for authorized access to the database is sent to the network server in the LoRaWAN to be detected, so that the device to be detected generates the feedback data according to the data packet for authorized access to the database.
6. A network detection method, characterized in that: Used to automatically detect key components in LoRaWAN, including: When a terminal device is connected to a LoRaWAN long-distance wide area network to be detected, receiving test data for the LoRaWAN to be detected sent by the terminal device, wherein the LoRaWAN to be detected is a network for communication between a LoRaWAN node device, a LoRaWAN gateway device, and a network server, the test data includes data information and network feedback status, the test data includes at least one of sensor network data and Ethernet network data, the sensor network data includes data of the LoRaWAN node device and data of the LoRaWAN gateway device, and the Ethernet network data includes data of the LoRaWAN gateway device and data of the network server; Perform feature analysis on the test data to generate a network detection result for the LoRaWAN to be tested to determine whether the current deployment complies with security specifications, wherein the network detection result represents the detection result of network security, and the detection result includes security detection of LoRaWAN node devices, security detection of LoRaWAN gateway devices, and security detection of network servers. The security detection of LoRaWAN node devices includes node non-use OTAA key negotiation detection, node OTAA weak key detection, and node protocol stack CVE-2020-11062 detection. The security detection of LoRaWAN gateway devices includes high-risk port open detection and unauthorized access detection. The security detection of network servers includes MQTT unauthorized access detection, gRPC unauthorized access detection, HTTP background server weak password login detection, and database unauthorized access detection. The method of obtaining the test data for the LoRaWAN to be detected includes: When the device to be detected is in a powered-on and networked state or a normal operating state, obtaining the network state of the LoRaWAN to be detected as the test data, wherein the device to be detected is at least one of the LoRaWAN node device, the LoRaWAN gateway device, and the network server, and the test data includes the sensor network data. When the device to be detected is in a powered-on and networked state or a normal operating state, obtaining the network state of the LoRaWAN to be detected as the test data includes: when the LoRaWAN node device is in a powered-on and networked state or a normal operating state, obtaining the sensor network data of the LoRaWAN to be detected, wherein the sensor network data includes at least one of a key negotiation data message and key encryption data of the LoRaWAN node device; or, Generate a data packet corresponding to the target attack type; send the data packet corresponding to the target attack type to the device to be detected in the LoRaWAN to be detected, so that the device to be detected generates feedback data according to the data packet corresponding to the target attack type; receive the feedback data as the test data.
7. The method according to claim 6, characterized in that The test data includes the sensor network data; The receiving test data for the LoRaWAN to be detected sent by the terminal device includes: When the LoRaWAN node device is in a powered-on state or a normal operating state, receiving the sensor network data of the LoRaWAN to be detected sent by the terminal device, wherein the sensor network data includes at least one of a key negotiation data message and key encryption data of the LoRaWAN node device; The feature analysis of the test data to generate a network detection result for the LoRaWAN to be detected includes: Perform feature analysis on at least one of the key agreement data message and the key encryption data to generate a network detection result for the LoRaWAN node device in the LoRaWAN to be detected.
8. The method according to claim 6, characterized in that The test data includes the sensor network data and the Ethernet network data; The receiving test data for the LoRaWAN to be detected sent by the terminal device includes: Receive test data corresponding to common vulnerabilities and exposed CVE types in the LoRaWAN to be detected, dangerous port vulnerabilities, gateway authentication access, communication protocol authorization access, remote procedure call (RPC) authorization access, password login, and database authorization access sent by the terminal device; The feature analysis of the test data to generate a network detection result for the LoRaWAN to be detected includes: Generate network detection results for the LoRaWAN node device, the LoRaWAN gateway device, and the network server in the LoRaWAN to be detected based on the test data corresponding to the CVE type, the dangerous port vulnerability, the gateway authentication access, the communication protocol authorization access, the RPC authorization access, the password login, and the database authorization access.
9. A network detection device, characterized in that: Used to automatically detect key components in LoRaWAN, including: An access module is used to access a long-distance wide area network LoRaWAN to be detected, wherein the LoRaWAN to be detected is a network for communication between LoRaWAN node devices, LoRaWAN gateway devices and network servers; an acquisition module, configured to acquire test data for the LoRaWAN to be detected, wherein the test data includes data information and network feedback status, the test data includes at least one of sensor network data and Ethernet network data, the sensor network data includes data of the LoRaWAN node device and data of the LoRaWAN gateway device, and the Ethernet network data includes data of the LoRaWAN gateway device and data of the network server; A sending module, configured to send the test data to a server, so that the server performs feature analysis on the test data to generate a network detection result for the LoRaWAN to be detected to determine whether the current deployment complies with security specifications, wherein the network detection result represents a network security detection result, and the detection result includes security detection of LoRaWAN node devices, security detection of LoRaWAN gateway devices, and security detection of network servers. The security detection of LoRaWAN node devices includes node non-use OTAA key negotiation detection, node OTAA weak key detection, and node protocol stack CVE-2020-11062 detection. The security detection of LoRaWAN gateway devices includes high-risk port open detection and unauthorized access detection. The security detection of network servers includes MQTT unauthorized access detection, gRPC unauthorized access detection, HTTP background server weak password login detection, and database unauthorized access detection. The acquisition module is specifically configured to: When the device to be detected is in a powered-on and networked state or a normal operating state, obtaining the network state of the LoRaWAN to be detected as the test data, wherein the device to be detected is at least one of the LoRaWAN node device, the LoRaWAN gateway device, and the network server, and the test data includes the sensor network data. When the device to be detected is in a powered-on and networked state or a normal operating state, obtaining the network state of the LoRaWAN to be detected as the test data includes: when the LoRaWAN node device is in a powered-on and networked state or a normal operating state, obtaining the sensor network data of the LoRaWAN to be detected, wherein the sensor network data includes at least one of a key negotiation data message and key encryption data of the LoRaWAN node device; or, Generate a data packet corresponding to the target attack type; send the data packet corresponding to the target attack type to the device to be detected in the LoRaWAN to be detected, so that the device to be detected generates feedback data according to the data packet corresponding to the target attack type; receive the feedback data as the test data.
10. The device according to claim 9, characterized in that The acquisition module is specifically used to: If the Ethernet network included in the LoRaWAN to be detected is connected, the Ethernet network data is obtained; If the sensor network included in the LoRaWAN to be detected is connected, the sensor network data is obtained; If the Ethernet network and the sensor network included in the LoRaWAN to be detected are accessed, the Ethernet network data and the sensor network data are obtained.
11. The device according to claim 9, characterized in that The test data includes the sensor network data; The acquisition module is specifically used to: Generate data packages targeting public vulnerabilities and exposed CVE types; Sending a data packet for the CVE type to the LoRaWAN node device in the LoRaWAN to be detected, so that the LoRaWAN node device generates the feedback data according to the data packet for the CVE type.
12. The device according to claim 9, characterized in that The test data includes the sensor network data or the Ethernet network data; The acquisition module is specifically used to: Generate data packets targeting dangerous port vulnerabilities; Alternatively, a data packet is generated for gateway authentication access; If a data packet targeting the dangerous port vulnerability is generated, sending the data packet targeting the dangerous port vulnerability to the LoRaWAN gateway device in the LoRaWAN to be detected, so that the device to be detected generates the feedback data according to the data packet targeting the dangerous port vulnerability; If a data packet for the gateway authentication access is generated, the data packet for the gateway authentication access is sent to the LoRaWAN gateway device in the LoRaWAN to be detected, so that the device to be detected generates the feedback data according to the data packet for the gateway authentication access.
13. The device according to claim 9, characterized in that The test data includes the Ethernet network data; The acquisition module is specifically used to: Generate data packets for communication protocol authorization access; Alternatively, a data packet for remote procedure call (RPC) authorization access is generated; Alternatively, generate a data packet for password login; Alternatively, a data packet is generated for authorized access to the database; If a data packet for authorized access to the communication protocol is generated, the data packet for authorized access to the communication protocol is sent to the network server in the LoRaWAN to be detected, so that the device to be detected generates the feedback data according to the data packet for authorized access to the communication protocol; If a data packet for the RPC authorized access is generated, sending the data packet for the RPC authorized access to the network server in the LoRaWAN to be detected, so that the device to be detected generates the feedback data according to the data packet for the RPC authorized access; If a data packet for the password login is generated, sending the data packet for the password login to the network server in the LoRaWAN to be detected, so that the device to be detected generates the feedback data according to the data packet for the password login; If a data packet for authorized access to the database is generated, the data packet for authorized access to the database is sent to the network server in the LoRaWAN to be detected, so that the device to be detected generates the feedback data according to the data packet for authorized access to the database.
14. A network detection device, characterized in that: include: a receiving module, configured to receive test data for a LoRaWAN to be detected, sent by a terminal device when the terminal device is connected to the LoRaWAN to be detected long-distance wide area network, wherein the LoRaWAN to be detected is a network for communication between a LoRaWAN node device, a LoRaWAN gateway device, and a network server, the test data including data information and network feedback status, the test data including at least one of sensor network data and Ethernet network data, the sensor network data including data of the LoRaWAN node device and data of the LoRaWAN gateway device, and the Ethernet network data including data of the LoRaWAN gateway device and data of the network server; A generation module for performing feature analysis on the test data to generate a network detection result for the LoRaWAN to be tested to determine whether the current deployment complies with security specifications, wherein the network detection result represents a network security detection result, and the detection result includes security detection of LoRaWAN node devices, security detection of LoRaWAN gateway devices, and security detection of network servers. The security detection of LoRaWAN node devices includes node non-use OTAA key negotiation detection, node OTAA weak key detection, and node protocol stack CVE-2020-11062 detection. The security detection of LoRaWAN gateway devices includes high-risk port open detection and unauthenticated access detection. The security detection of network servers includes MQTT unauthorized access detection, gRPC unauthorized access detection, HTTP background server weak password login detection, and database unauthorized access detection; The method of obtaining the test data for the LoRaWAN to be detected includes: When the device to be detected is in a powered-on and networked state or a normal operating state, obtaining the network state of the LoRaWAN to be detected as the test data, wherein the device to be detected is at least one of the LoRaWAN node device, the LoRaWAN gateway device, and the network server, and the test data includes the sensor network data. When the device to be detected is in a powered-on and networked state or a normal operating state, obtaining the network state of the LoRaWAN to be detected as the test data includes: when the LoRaWAN node device is in a powered-on and networked state or a normal operating state, obtaining the sensor network data of the LoRaWAN to be detected, wherein the sensor network data includes at least one of a key negotiation data message and key encryption data of the LoRaWAN node device; or, Generate a data packet corresponding to the target attack type; send the data packet corresponding to the target attack type to the device to be detected in the LoRaWAN to be detected, so that the device to be detected generates feedback data according to the data packet corresponding to the target attack type; receive the feedback data as the test data.
15. A terminal device, characterized in that: include: Memory, processor, and bus system; Wherein, the memory is used to store programs; The processor is configured to execute the program in the memory, and the processor is configured to execute the method according to any one of claims 1 to 5 according to instructions in the program code; The bus system is used to connect the memory and the processor so that the memory and the processor can communicate with each other.
16. A server, characterized in that: include: Memory, processor, and bus system; Wherein, the memory is used to store programs; The processor is configured to execute the program in the memory, and the processor is configured to execute the method according to any one of claims 6 to 8 according to instructions in the program code; The bus system is used to connect the memory and the processor so that the memory and the processor can communicate with each other.
17. A computer-readable storage medium comprising instructions, which, when executed on a computer, causes the computer to execute the method according to any one of claims 1 to 5, or the method according to any one of claims 6 to 8.
18. A computer program product, characterized in that The computer program product includes computer instructions, and a processor of a computer device executes the computer instructions, so that the computer device performs the method according to any one of claims 1 to 5, or performs the method according to any one of claims 6 to 8.