A control method of an internet of things card and an electronic device
By acquiring behavioral data from IoT cards and classifying it based on multi-level anomaly threshold rules, the anomaly categories are determined and corresponding strategies are executed. This solves the problem of low reliability in IoT card management methods and achieves efficient and accurate anomaly detection and processing.
Patent Information
- Application Number
- CN202010855846.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-08-24
- Publication Date
- 2025-11-07
- Estimated Expiration
- 2040-08-24
AI Technical Summary
Existing technologies for managing IoT cards have low reliability and are difficult to effectively address user violations and illegal resale, leading to problems such as telecommunications network fraud.
By acquiring behavioral data from IoT cards, classification is performed based on multi-level anomaly threshold rules to determine the target behavioral anomaly category, and corresponding control strategies are executed, including shutdown, disabling internet access, disabling voice function, disabling SMS function, or limiting data traffic, thereby achieving multi-level classification and control.
It improves the reliability and accuracy of IoT card control methods, enabling timely identification and handling of abnormal behaviors, reducing the impact on normal business operations, and improving management efficiency.
Smart Images

Figure CN114091563B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of Internet of Things, and in particular to a control method of an Internet of Things card and an electronic device. BACKGROUND
[0002] The Internet of Things card is a mobile phone card provided for customers in the field of Internet of Things, which is used for mobile communication access services of Internet of Things devices and supports communication modes such as short message, data communication and voice. The user scale of the Internet of Things card in the country has reached billions, and while gradually forming an "Internet of Things" industrial ecology, the scale development has also led to an increase in illegal behavior of Internet of Things card users and an increase in the difficulty of control. Because the Internet of Things card package has a large discount and weak control means, it is often illegally resold and misused for non-Internet of Things services. In addition, the Internet of Things card terminal device is usually unattended and is extremely easy to be illegally taken out, which also provides an opportunity for criminals to misappropriate or maliciously use the Internet of Things card for telecommunications network fraud. The abnormal detection and processing control of the Internet of Things card has become a pain point that needs to be solved for each Internet of Things customer and telecommunications operator.
[0003] At present, when controlling the Internet of Things card, the abnormal card is implemented to be closed, and the control method of the Internet of Things card has insufficient consideration for the complexity of actual business and low reliability. SUMMARY
[0004] The embodiments of the present application provide a control method of an Internet of Things card and an electronic device to solve the problem of low reliability of the control method of the Internet of Things card in the prior art.
[0005] To solve the above problems, the present application is implemented as follows:
[0006] In a first aspect, the embodiments of the present application provide a control method of an Internet of Things card, applied to an electronic device, and the method comprises:
[0007] Obtaining behavior data of the Internet of Things card;
[0008] Based on the behavior data, determining a target behavior abnormal category of the Internet of Things card;
[0009] In a case where the target behavior abnormal category is any category in preset abnormal behavior categories, executing a first control strategy corresponding to the target behavior abnormal category on the Internet of Things card.
[0010] In a second aspect, the embodiments of the present application further provide an electronic device, which comprises:
[0011] A first processor is configured to:
[0012] Obtain behavior data of the Internet of Things card;
[0013] determine a target behavior anomaly category of the Internet of Things card based on the behavior data;
[0014] in a case where the target behavior anomaly category is any one of preset behavior anomaly categories, execute a first control strategy corresponding to the target behavior anomaly category on the Internet of Things card.
[0015] In a third aspect, the present application also provides a computer readable storage medium, which stores a first computer program, and the first computer program is executed by a second processor to implement the steps of the control method of the Internet of Things card.
[0016] In the present application, the electronic device obtains the behavior data of the Internet of Things card, determines the target behavior anomaly category of the Internet of Things card based on the behavior data, and in a case where the target behavior anomaly category is any one of preset behavior anomaly categories, executes a first control strategy corresponding to the target behavior anomaly category on the Internet of Things card. In the present application, the behavior data is obtained from multiple dimensions, and any one of the preset behavior anomaly categories corresponds to a control strategy. The preset behavior anomaly categories and control strategies of the Internet of Things card are classified and controlled in multiple levels, which improves the reliability of the control method of the Internet of Things card compared with the existing technology of shutting down the abnormal card. BRIEF DESCRIPTION OF DRAWINGS
[0017] In order to more clearly illustrate the technical solutions of the present application, the following will briefly introduce the drawings needed to be used in the description of the present application. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.
[0018] Figure 1 is a flow chart of the control method of the Internet of Things card provided by the present application;
[0019] Figure 2 is a flow chart of the abnormal detection and processing of the Internet of Things card provided by the present application;
[0020] Figure 3 is a schematic diagram of the abnormal behavior detection and classification of the Internet of Things card provided by the present application;
[0021] Figure 4 is a flow chart of the review and processing of the abnormal behavior of the Internet of Things card provided by the present application;
[0022] Figure 5 is one of the structural diagrams of the electronic device provided by the present application;
[0023] Figure 6 This is the second structural diagram of an electronic device provided in an embodiment of the present invention. Detailed Implementation
[0024] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0025] The terms "first," "second," etc., used in this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or apparatus that includes a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to these processes, methods, products, or apparatuses. Additionally, the use of "and / or" in this application indicates at least one of the connected objects, such as A and / or B and / or C, representing seven possibilities: including A alone, B alone, C alone, and the presence of both A and B, both B and C, both A and C, and the presence of A, B, and C.
[0026] See Figure 1 , Figure 1 This is a flowchart illustrating a control method for an Internet of Things (IoT) card according to an embodiment of the present invention. The IoT card control method of this embodiment can be applied to electronic devices, such as… Figure 1 As shown, the control method for an IoT card may include the following steps:
[0027] Step 101: Obtain the behavior data of the IoT card.
[0028] An IoT SIM card is a mobile phone card provided to customers in the Internet of Things (IoT) field for IoT devices to access mobile communication services. It supports communication methods such as SMS, data communication, and voice.
[0029] The IoT SIM card can be any IoT SIM card to be tested. IoT SIM cards can be tested in batches or individually; that is, this step can acquire behavioral data from a batch of IoT SIM cards or data from a single IoT SIM card, without limitation. This step can acquire IoT behavioral data in real time or historical behavioral data of the IoT SIM cards; this embodiment of the invention does not limit the specific method of acquiring behavioral data. Behavioral data of IoT SIM cards can be acquired from multiple network locations.
[0030] Step 102, determining a target behavior abnormality category of the Internet of Things card based on the behavior data.
[0031] After obtaining the behavior data of the Internet of Things card, the behavior data corresponds to one of the behavior abnormality categories according to the multi-level abnormality threshold rule, and each behavior abnormality category corresponds to a control strategy.
[0032] The multi-level abnormality threshold rule refers to that, according to the multiple security risk degrees of the terminal of the Internet of Things card in actual complex business applications, the preset abnormal behavior category is divided into multiple behavior categories, for example, extremely high abnormal behavior, higher abnormal behavior, medium abnormal behavior, low abnormal behavior or safe behavior; each behavior category can include multiple situations, and the multiple situations refer to the behavior data of multiple situations of the Internet of Things card, and the behavior data can include Internet access flow data, Internet access location data, Internet access terminal data, Internet access quality data, Internet access address data, subscription data of a tariff package, call data and card separation data. The control method of the Internet of Things further divides a security white list, an abnormal behavior white list and a behavior restriction white list and the like for part of the Internet of Things cards. According to the behavior data of the Internet of Things card, the target behavior abnormality category of the Internet of Things card is determined, whether the Internet of Things card has abnormal behavior or illegal behavior is determined, preventive measures are taken for the Internet of Things card that may have abnormal behavior, and control strategies are executed for the Internet of Things card that has abnormal behavior, so as to reduce the adverse effects of abnormal Internet of Things cards on illegal use, and to timely stop the abnormal behavior of the Internet of Things card.
[0033] The behavior restriction white list further limits the minimum compliance behavior set that can occur for the Internet of Things card. The abnormal behavior white list further limits the abnormal behavior set that can occur for the Internet of Things card.
[0034] Step 103, in the case that the target behavior abnormality category is any of the preset abnormal behavior categories, a first control strategy corresponding to the target behavior abnormality category is executed on the Internet of Things card.
[0035] In the embodiment of the application, the electronic device obtains the behavior data of the Internet of Things card; determines a target behavior abnormality category of the Internet of Things card based on the behavior data; and in the case that the target behavior abnormality category is any of the preset abnormal behavior categories, a first control strategy corresponding to the target behavior abnormality category is executed on the Internet of Things card. In the embodiment of the application, the behavior data is obtained from multiple dimensions, any of the preset abnormal behavior categories corresponds to a control strategy, and the preset abnormal behavior categories and the control strategies of the Internet of Things card are classified and controlled in multiple levels. Compared with the existing technology of shutting down abnormal cards, the embodiment of the application fully considers the complexity of the actual business of the Internet of Things card, and improves the reliability of the control method of the Internet of Things card.
[0036] Optionally, the target behavior abnormality category includes: extremely high abnormal behavior, higher abnormal behavior, medium abnormal behavior, low abnormal behavior, or safe behavior.
[0037] The behavior data includes at least one of the following: online location, online terminal, online access address, fee package subscription data, call bill data, and card separation data.
[0038] In this embodiment, in addition to extremely high abnormal behavior, higher abnormal behavior, medium abnormal behavior, low abnormal behavior, or safe behavior, the target behavior abnormality category can also include other categories of behavior according to the actual business scenario or security control requirements of the Internet of Things. This embodiment does not limit the number of preset abnormal behavior categories, and according to the actual business situation of the Internet of Things card, the preset abnormal behavior category of the Internet of Things card can include multiple categories. For example, the target behavior abnormality category can include: extremely high abnormal behavior, higher abnormal behavior, medium-high abnormal behavior, medium abnormal behavior, medium-low abnormal behavior, low abnormal behavior, extremely low abnormal behavior, or safe behavior. The preset abnormal behavior category includes multiple categories, which improves the rationality of the classification of the Internet of Things card, and the preset abnormal behavior category of the Internet of Things card is classified and controlled in multiple levels, fully considering the complexity of the actual business of the Internet of Things card, and improves the reliability and accuracy of the control method of the Internet of Things card.
[0039] The fee package subscription data can include traffic package subscription data, short message package subscription data, and voice package subscription data of the Internet of Things card. The traffic service can be divided into directional traffic service and non-directional traffic service, the short message service can be divided into directional short message service and non-directional short message service, and the voice service can be divided into directional voice service and non-directional voice service.
[0040] In some embodiments, the directional traffic service can be understood as a traffic service that limits the target address, and the non-directional traffic service can be understood as a traffic service that does not limit the target address. The directional short message service can be understood as a short message service that limits the target object, and the non-directional short message service can be understood as a short message service that does not limit the target object. The non-directional voice service can be understood as a voice service that does not limit the target object, and the directional voice service can be understood as a short message service that limits the target object.
[0041] The online traffic data can include time nodes of online traffic of the Internet of Things card, terminal IP, access IP, consumed uplink traffic, consumed downlink traffic, and access content, and can also include online network speed, network quality, access network type, attachment location, and charging policy. The online terminal data can include terminal identification number, terminal type, terminal standard, terminal brand, and terminal price of the terminal associated with the electronic device of the Internet of Things card. The subscription data of the tariff package can include subscription data of various tariff packages such as traffic, voice, or short message of the Internet of Things card. The call record data can include detail information of actual usage of traffic, voice, or short message. The acquisition of the behavior data of the Internet of Things card can include the following seven cases:
[0042] (1) Collecting online behavior data of the Internet of Things card from a P-GW (PDN GateWay) of a core network, the online behavior data including online time, online traffic, online location, online terminal IMEI (International Mobile Equipment Identity), online QOS (Quality of Service), and access address detail information;
[0043] (2) Collecting service subscription relationship data and call record data of the Internet of Things card from an Internet of Things service support system, wherein the service subscription relationship data includes various tariff package subscription data of the Internet of Things card, and the call record data contains actual usage detail information of traffic, voice, and short message of the Internet of Things card;
[0044] (3) Collecting terminal card separation data and on-off state of the Internet of Things card from an HLR (Home Location Register) network element of the core network;
[0045] (4) Collecting policy rules associated with the Internet of Things card from a PCRF (Policy and Charging Rules Function) network element of the core network;
[0046] (5) Collecting physical attribute information of the Internet of Things card from a card manufacturer, including information such as whether it is a patch card or a card-locking card, i.e., a security whitelist;
[0047] (6) Obtaining a set of abnormal behaviors of the Internet of Things card under an enterprise client allowed to occur due to maintaining normal business from enterprise client opening information or Internet of Things card operation management information, i.e., an abnormal behavior whitelist;
[0048] (7) Collecting a set of minimum compliance behaviors of the Internet of Things card under the enterprise client restricted to occur from enterprise client opening information, i.e., a behavior restriction whitelist.
[0049] After the behavior data of the IoT card is acquired, the behavior data of the terminal of the IoT card acquired in real time can be extracted and converted, and the behavior feature data of the IoT card is extracted, so as to prepare for the detection and recognition of the subsequent link. For example, the mature ETL (Extract-Transform-Load, data extraction, conversion and loading) technology component can be used to realize the extraction, conversion and cleaning of the key fields of the behavior data.
[0050] Optionally, the target behavior abnormality category of the IoT card is determined based on the behavior data, and the method comprises the following steps of:
[0051] In any of the following cases, the target behavior abnormality category of the IoT card is determined as a first-level abnormal behavior:
[0052] The IoT card is in a roaming state, and the online location of the IoT card belongs to a preset risk area, and the tariff package subscription data includes non-directional voice service or non-directional traffic service;
[0053] The online terminal of the IoT card belongs to a preset sensitive terminal, and the tariff package subscription data includes non-directional voice service or non-directional traffic service;
[0054] The online terminal of the IoT card belongs to a preset sensitive terminal, and the machine-card separation data indicates that a machine-card separation behavior occurs between a first terminal and the IoT card, and the first terminal is associated with the IoT card.
[0055] In some embodiments, the preset sensitive terminal can refer to a non-business terminal, such as a mobile phone that is not used for IoT business. The IoT card in a roaming state can be understood as that the IoT card leaves the service area where it is registered and moves to another service area, and the mobile communication system still provides communication services to the IoT card in this state.
[0056] The directional traffic can refer to the data traffic generated when the IoT card selects a specified access point to use a specific service. The non-directional traffic can be understood as general traffic, and the use mode, use location and use terminal of the traffic are not limited. The non-directional voice can be understood as general voice, and the call object, use mode, use location and use terminal of the voice are not limited. The non-directional short message can be understood as general short message, and the sending object, use mode, use location and use terminal of the short message are not limited.
[0057] According to the security risk degree of the abnormal behavior of the terminal of the IoT card in the actual business scene, a multi-level abnormal threshold rule is defined, and based on the preset abnormal threshold rule, the behavior data of the terminal of the IoT card to be detected in real time is used for abnormality discrimination and classification.
[0058] The first level of abnormal behavior is also referred to as extremely high abnormal behavior, and the threshold rule of the extremely high abnormal behavior is as follows.
[0059] (1) The preset risk area includes but is not limited to: an area listed as a high incidence area of telecom fraud by a specific department, an area listed as a high incidence area of telecom fraud by an operator or an enterprise customer, or an area where other security incidents frequently occur and are monitored, etc. Combined with the online location data and subscription relationship data of the to-be-detected Internet of Things card, it is determined whether the terminal of the Internet of Things card uses roaming in the preset risk area and subscribes to non-directional voice services or non-directional traffic services. If the determination result is yes, it is determined that the Internet of Things card has extremely high abnormal behavior.
[0060] (2) According to the pre-stored terminal information library, combined with the subscription relationship data and online terminal data of the to-be-detected Internet of Things card, it is determined whether the Internet of Things card is used on a non-business terminal such as a mobile phone terminal and subscribes to non-directional voice or non-directional traffic services. If the determination result is yes, it is determined that the Internet of Things card has extremely high abnormal behavior.
[0061] (3) According to the pre-stored terminal information library, combined with the online terminal data and card separation data of the to-be-detected Internet of Things card, it is determined whether the Internet of Things card is used on a non-business terminal such as a mobile phone terminal and has a card separation behavior. If the determination result is yes, it is determined that the Internet of Things card has extremely high abnormal behavior.
[0062] The first terminal can refer to the terminal where the Internet of Things card is placed for the first time or the terminal where the fixed binding relationship is established, and the association information of the Internet of Things card and the first terminal is recorded in the server of the Internet of Things card management party. The preset sensitive terminal includes but is not limited to a mobile phone terminal. The card separation behavior can refer to the card separation between the Internet of Things card and the terminal where the Internet of Things card is placed for the first time or the terminal where the fixed binding relationship is established.
[0063] Optionally, the target behavior abnormality category of the Internet of Things card is determined based on the behavior data, including:
[0064] In any of the following cases, the target behavior abnormality category of the Internet of Things card is determined to be the second level of abnormal behavior:
[0065] The subscription data of the Internet of Things card includes non-directional voice services;
[0066] The online terminal of the Internet of Things card belongs to a preset sensitive terminal;
[0067] The Internet of Things card belongs to a behavior restriction whitelist, and the behavior data of the Internet of Things card exceeds the preset behavior content of the behavior restriction whitelist;
[0068] The online access address of the Internet of Things card belongs to a preset unreasonable access address.
[0069] The behavior restriction whitelist of each enterprise client of the IoT card can be different in the scope of the minimum compliance behavior set of the IoT card, that is, the permissions of the whitelist of different enterprise clients or different IoT cards can be inconsistent.
[0070] The second-level abnormal behavior is also referred to as a higher abnormal behavior. The higher abnormal behavior threshold rule is as follows.
[0071] (1) In combination with the subscription relationship data of the terminal of the IoT card to be detected, it is determined whether the terminal of the IoT card subscribes to a non-directional voice communication service. If the determination result is yes, it is determined that the IoT card has a higher abnormal behavior.
[0072] (2) According to the pre-stored terminal information library, in combination with the online terminal data of the IoT card to be detected, it is determined whether the IoT card is used on a non-business terminal such as a mobile phone terminal. If the determination result is yes, it is determined that the IoT card has a higher abnormal behavior.
[0073] (3) The behavior restriction whitelist further limits the minimum compliance behavior set that the IoT card can have, for example, limits the main called number, SMS sending and receiving number, or use location of the IoT card, and the like. According to the pre-stored behavior restriction whitelist, in combination with the behavior data such as the call data and online location data of the IoT card to be detected, it is determined whether the main called number, SMS sending and receiving number, or use location in the communication call of the IoT card corresponds to the voice number, SMS number, or use location limited by the enterprise client. If the determination result is yes, it is determined that the IoT card has a higher abnormal behavior.
[0074] The behavior data of the IoT card exceeding the preset behavior content of the behavior restriction whitelist can be understood as the behavior data of the IoT card exceeding the minimum compliance behavior set of the behavior restriction whitelist. The content involved in the minimum compliance behavior set includes but is not limited to the main called number, SMS sending and receiving number, or use location of the call data.
[0075] (4) In combination with the online behavior data of the terminal of the IoT card to be detected, it is determined whether the access address of the terminal of the IoT card has an unreasonable access, for example, a URL address of typical human networking. If the determination result is yes, it is determined that the IoT card has a higher abnormal behavior.
[0076] Optionally, the determining the target behavior abnormal category of the IoT card based on the behavior data comprises:
[0077] In any of the following cases, the target behavior abnormal category of the IoT card is determined to be a third-level abnormal behavior:
[0078] The tariff package subscription data of the IoT card includes a non-directional traffic service or a non-directional SMS service.
[0079] The machine-card separation data indicates that the first terminal has a machine-card separation behavior with the Internet of Things card, and the first terminal is associated with the Internet of Things card;
[0080] The usage amount of traffic, short message or voice in the bill data of the Internet of Things card exceeds a preset threshold;
[0081] The Internet of Things card is in a roaming state, and the online location of the Internet of Things card belongs to a preset risk area.
[0082] The usage amount of short message can refer to the number of sent or received short messages, and the usage amount of voice can refer to the duration of outgoing or incoming calls.
[0083] The third level of abnormal behavior is also called the medium abnormal behavior. The medium abnormal behavior threshold rule is as follows.
[0084] (1) In combination with the subscription relationship data of the Internet of Things card to be detected, it is determined whether the Internet of Things card subscribes to non-directional traffic or short message communication service. If the determination result is yes, it is determined that the Internet of Things card has a medium abnormal behavior.
[0085] (2) In combination with the machine-card separation data of the Internet of Things card to be detected, it is determined whether the Internet of Things card has a machine-card separation behavior. If the determination result is yes, it is determined that the Internet of Things card has a medium abnormal behavior.
[0086] (3) In combination with the bill data of the Internet of Things card to be detected, it is determined whether the traffic, short message or voice usage amount of the terminal of the Internet of Things card exceeds a preset threshold, for example, whether the usage amount of short message, traffic or voice of the Internet of Things card exceeds the available free resources of the subscription package, and is greater than 2 times the monthly average traffic usage amount in the previous three months. If the determination result is yes, it is determined that the Internet of Things card has a medium abnormal behavior.
[0087] (4) According to a preset risk area, which includes but is not limited to: an area listed as a high incidence area of telecommunications fraud by a specific department, an area listed as a high incidence area of telecommunications fraud by an operator or enterprise customer, or an area that is frequently monitored due to other security incidents, in combination with the online location data of the Internet of Things card to be detected, it is determined whether the Internet of Things card uses roaming in the preset risk area. If the determination result is yes, it is determined that the Internet of Things card has a medium abnormal behavior.
[0088] Optionally, the target behavior abnormal category of the Internet of Things card is determined based on the behavior data, including:
[0089] In the following cases, the target behavior abnormal category of the Internet of Things card is determined as a fourth level of abnormal behavior:
[0090] determine a third behavior anomaly category of the IoT card based on the behavior data; in a case where the third behavior anomaly category is any one of an extremely high abnormal behavior, a higher abnormal behavior, and a medium abnormal behavior, if the IoT card is a card belonging to an abnormal behavior whitelist, and the third behavior anomaly category belongs to an abnormal behavior allowed to occur in the abnormal behavior whitelist.
[0091] In this embodiment, a third behavior anomaly category of the IoT card is determined based on the behavior data; in a case where the third behavior anomaly category is an extremely high abnormal behavior, it can be understood that a target behavior anomaly category of the IoT card is determined to be a first level abnormal behavior based on the behavior data.
[0092] In this embodiment, a third behavior anomaly category of the IoT card is determined based on the behavior data; in a case where the third behavior anomaly category is a higher abnormal behavior, it can be understood that a target behavior anomaly category of the IoT card is determined to be a second level abnormal behavior based on the behavior data.
[0093] In this embodiment, a third behavior anomaly category of the IoT card is determined based on the behavior data; in a case where the third behavior anomaly category is a medium abnormal behavior, it can be understood that a target behavior anomaly category of the IoT card is determined to be a third level abnormal behavior based on the behavior data.
[0094] The fourth level abnormal behavior is also called a low abnormal behavior, and a low abnormal behavior threshold rule is as follows.
[0095] According to the abnormal behavior whitelist of the IoT card of the enterprise customer allowed to occur a specific abnormal behavior, it is determined whether the IoT card to be detected only occurs an abnormal behavior allowed to occur in the preset abnormal behavior whitelist. If the determination result is yes, it is determined that the IoT card has a low abnormal behavior.
[0096] Optionally, the determining the target behavior anomaly category of the IoT card based on the behavior data comprises:
[0097] In the following cases, the target behavior anomaly category of the IoT card is determined to be a fifth level abnormal behavior:
[0098] The IoT card is a card belonging to a security whitelist.
[0099] In this embodiment, the fifth level abnormal behavior can correspond to a security behavior. According to the security whitelist of the patch card or the machine card interlocking card, it is determined whether the IoT card to be detected exists in the security whitelist, for example, whether it is a patch card or a machine card interlocking card. If the determination result is yes, it is determined that the target behavior anomaly category of the IoT card is a security behavior.
[0100] Based on the above multi-level abnormal threshold rule, after the behavior data of the to-be-detected Internet of Things card is classified, the terminals of the batch of to-be-detected Internet of Things cards are classified into the following categories: extremely high abnormal behavior, relatively high abnormal behavior, medium abnormal behavior, low abnormal behavior, or safe behavior.
[0101] In the detection and processing of abnormal behaviors of the Internet of Things card, the application proposes a whitelist concept, which includes a safe whitelist, an abnormal behavior whitelist, and a behavior restriction whitelist. The safe whitelist can include information of the Internet of Things card classified into the safe whitelist and the corresponding Internet of Things card terminal. The abnormal behavior whitelist can include information of the Internet of Things card classified into the abnormal behavior whitelist and the corresponding Internet of Things card terminal. The behavior restriction whitelist can include information of the Internet of Things card classified into the behavior restriction whitelist and the corresponding Internet of Things card terminal.
[0102] The safe whitelist and the abnormal behavior whitelist are used in the abnormal detection process of the Internet of Things card to filter out the Internet of Things card terminals that have been guaranteed in terms of physical attributes, or to filter out part of the Internet of Things card terminals that are allowed to produce specific abnormal behaviors due to maintaining normal business, which can effectively avoid the influence of the misjudgment of these Internet of Things cards on normal use of business. The behavior restriction whitelist is used to detect the scene where part of the Internet of Things cards can only produce minimum compliance behavior operations within a limited range in actual business application, including but not limited to voice, short message, online behavior, or use location, etc. If it exceeds the limited range of the whitelist, it is regarded as an abnormal violation operation, which is suitable for accurate detection of Internet of Things card terminals with relatively fixed behaviors.
[0103] By proposing the detection method of the whitelist, on the one hand, it can effectively avoid the influence of the misjudgment of part of the safe Internet of Things cards on normal use of business, and on the other hand, it can accurately detect the Internet of Things card terminals with relatively fixed behaviors.
[0104] Optionally, the target behavior abnormal category of the Internet of Things card is determined based on the behavior data, including:
[0105] The first behavior abnormal category of the Internet of Things card is determined according to the behavior data.
[0106] The second behavior abnormal category input for the behavior data is received.
[0107] In the case where the first behavior abnormal category and the second behavior abnormal category do not match, the second behavior abnormal category is determined as the target behavior abnormal category.
[0108] The first behavior abnormality category does not match the second behavior abnormality category can mean that the first behavior abnormality category and the second behavior abnormality are two different categories. For example, if the first behavior abnormality category is extremely high abnormal behavior, and the second behavior abnormality category is medium abnormal behavior, the second behavior abnormality category is determined as the target behavior abnormality category, that is, the target behavior abnormality category is medium abnormal behavior.
[0109] According to the preset abnormal behavior automatic processing control policy, the Internet of Things card with the determination result of extremely high abnormal behavior, high abnormal behavior or medium abnormal behavior is automatically processed according to the corresponding processing policy, including but not limited to: shutdown, closing the Internet function, closing the voice function, closing the short message function or flow speed limit, etc., to avoid the illegal operation of the abnormal Internet of Things card in time, and improve the timeliness of safety control.
[0110] The behavior data of the abnormal Internet of Things card and the automatic processing result data are saved into a database to be audited, waiting for a secondary audit by an auditor. The auditor can comprehensively evaluate whether the terminal of the Internet of Things card with abnormal behavior belongs to the business allowed category or belongs to the bad illegal operation by combining the multi-dimensional behavior details of the abnormal Internet of Things card or offline channel verification, and performs a secondary processing operation according to the audit result, for example, reprocessing the abnormal Internet of Things card that is not automatically processed or is not reasonably automatically processed, including but not limited to: shutdown, restart, closing the Internet function, opening the Internet function, closing the voice function, opening the voice function, closing the short message function, opening the short message function, flow speed limit, flow speed limit off, etc. Through the secondary audit operation, the illegally used Internet of Things card can be accurately controlled, and the actual business of the terminal of the normal Internet of Things card can be avoided from being affected by unreasonable control.
[0111] Before the auditor performs the audit confirmation, the automatic audit processing of the abnormal Internet of Things card is performed according to the preset automatic audit rule: combining the abnormal behavior data of the terminal of the Internet of Things card, it is judged whether the same abnormal behavior of the Internet of Things card occurs in a preset time period and is processed, if so, the automatic audit processing is performed according to the previous processing mode, including but not limited to: shutdown, restart, closing the Internet function, opening the Internet function, closing the voice function, opening the voice function, closing the short message function, opening the short message function, flow speed limit, flow speed limit off, etc. Through the automatic audit rule, the number of Internet of Things cards that need to be audited manually can be reduced, thereby solving the problem of low efficiency in the audit confirmation link.
[0112] Optionally, the preset abnormal behavior category includes at least one of a first level abnormal behavior, a second level abnormal behavior and a third level abnormal behavior, and the first control policy includes at least one of shutdown, closing the Internet function, closing the voice function, closing the short message function and flow speed limit.
[0113] The first level of abnormal behavior is also referred to as extremely high abnormal behavior, the second level of abnormal behavior is also referred to as higher abnormal behavior, the third level of abnormal behavior is also referred to as medium abnormal behavior, the fourth level of abnormal behavior is also referred to as low abnormal behavior, and the fifth level of abnormal behavior is also referred to as safe behavior.
[0114] The application forms an efficient management and control closed loop of abnormal detection, abnormal review and abnormal processing of the Internet of Things card, and combines multiple behavior dimensions for abnormal detection, covers high-risk or high-frequency illegal behaviors in the actual business scenarios of the terminal of the Internet of Things card, has high detection accuracy, strong real-time performance and high management and control efficiency, and is suitable for abnormal real-time monitoring and management and control of massive Internet of Things cards in most business scenarios.
[0115] Figure 2 is a flowchart of the abnormal detection and processing of the Internet of Things card provided by the embodiment of the application. As shown in Figure 2 , the abnormal detection and processing of the Internet of Things card based on behavior data can include the following steps:
[0116] (1) Real-time acquisition of behavior data of the Internet of Things card.
[0117] (2) According to the multi-level abnormal threshold rule, the Internet of Things card to be detected is classified into extremely high abnormal behavior, higher abnormal behavior, medium abnormal behavior, low abnormal behavior or safe behavior.
[0118] (3) The terminal of the Internet of Things card determined as extremely high abnormal behavior, higher abnormal behavior or medium abnormal behavior is automatically processed and reviewed and confirmed, and is processed and controlled.
[0119] Figure 3 is a schematic diagram of the abnormal behavior detection and classification of the Internet of Things card provided by the embodiment of the application. As shown in Figure 3 , according to the behavior data of the Internet of Things card, the behavior of the Internet of Things card is determined as extremely high abnormal behavior, higher abnormal behavior, medium abnormal behavior, low abnormal behavior or safe behavior.
[0120] Figure 4 is a flowchart of the review and processing of the Internet of Things card with abnormal behavior provided by the embodiment of the application. As shown in Figure 4 , the review and processing of the Internet of Things card with abnormal behavior includes the following steps:
[0121] (1) The Internet of Things card to be detected is classified into extremely high abnormal behavior, higher abnormal behavior, medium abnormal behavior, low abnormal behavior or safe behavior according to the multi-level abnormal threshold rule.
[0122] (2) According to the preset automatic processing strategy, the terminal of the Internet of Things card determined as extremely high abnormal behavior, higher abnormal behavior or medium abnormal behavior is automatically processed and controlled.
[0123] (3) The behavior data of the Internet of Things card with the determination result of extremely high abnormal behavior, high abnormal behavior or medium abnormal behavior and the processing result data thereof are stored into an audit database.
[0124] (4) According to a preset automatic audit rule, a terminal of a physical network card that has the same abnormal behavior before a preset time is automatically audited and processed according to a previous audit processing mode.
[0125] (5) An audit personnel manually audits and processes a terminal of an abnormal Internet of Things card in the audit database.
[0126] The present application proposes a multi-level threshold rule, which covers high-risk or high-frequency abnormal behaviors in the actual business of the Internet of Things card, combines multiple behavior dimensions to jointly determine the abnormal degree of the terminal of the Internet of Things card from multiple aspects, and fully considers the position dimension, terminal type dimension and subscription dimension and other related behavior characteristic values and threshold rules of the behavior data.
[0127] The present application proposes an efficient management and control closed loop of Internet of Things card anomaly detection, abnormal Internet of Things card audit and abnormal Internet of Things card processing. The automatic processing strategy is proposed, which can automatically manage and control the abnormal Internet of Things card through a preset processing strategy, including but not limited to shutdown, closing voice function, closing Internet access function, closing SMS function or flow speed limit, etc. The abnormal operation of the abnormal Internet of Things card can be processed in time to avoid the abnormal operation of the abnormal Internet of Things card after the abnormal Internet of Things card is found. The automatic audit rule is also proposed. If the same abnormal behavior occurs before a preset time, the automatic audit processing is automatically processed according to the previous processing mode, which can reduce the number of Internet of Things cards that need to be audited by manual, and improve the work efficiency of the audit confirmation link.
[0128] The present application more comprehensively covers the detection of high-risk or high-frequency abnormal behaviors of the Internet of Things card, has high accuracy, strong real-time performance and is not limited by the scene. By defining a multi-level abnormal threshold rule, the position dimension, subscription dimension, terminal dimension, call dimension, Internet dimension and card physical property dimension and other behavior data are obtained in real time, and the behavior abnormality of the Internet of Things card is jointly determined by combining multiple behavior dimensions. The high-risk / high-frequency abnormal behaviors existing in the actual business scene of the Internet of Things card are classified into different abnormal levels. Compared with the detection and determination from a single behavior dimension or the simple classification into two results of abnormal and normal, the accuracy is higher, and the abnormal threshold rule more comprehensively covers the abnormal and illegal behaviors in the actual business of the Internet of Things card, which is not limited by the scene. The reliability and accuracy of the control method of the Internet of Things card of the present application are higher.
[0129] Referring to Figure 5 , Figure 5 is one of the structural diagrams of an electronic device provided by the embodiments of the present application, such as Figure 5As shown, the electronic device 500 includes:
[0130] a first processor 501, configured to:
[0131] obtain behavior data of the IoT card;
[0132] determine a target behavior abnormality category of the IoT card based on the behavior data;
[0133] in a case where the target behavior abnormality category is any one of preset abnormality categories, perform a first control strategy corresponding to the target behavior abnormality category on the IoT card.
[0134] Optionally, the target behavior abnormality category includes: extremely high abnormality behavior, relatively high abnormality behavior, medium abnormality behavior, low abnormality behavior, or safe behavior.
[0135] The behavior data includes at least one of the following: online location, online terminal, online access address, subscription data of a tariff package, call data, and machine-card separation data.
[0136] Optionally, the first processor 501 is specifically configured to:
[0137] in any one of the following cases, determine that the target behavior abnormality category of the IoT card is first-level abnormality behavior:
[0138] the IoT card is in a roaming state, and an online location of the IoT card belongs to a preset risk area, and the subscription data of the tariff package includes non-directional voice service or non-directional traffic service;
[0139] the online terminal of the IoT card belongs to a preset sensitive terminal, and the subscription data of the tariff package includes non-directional voice service or non-directional traffic service;
[0140] the online terminal of the IoT card belongs to a preset sensitive terminal, and the machine-card separation data indicates that a first terminal and the IoT card have a machine-card separation behavior, and the first terminal is associated with the IoT card.
[0141] Optionally, the first processor 501 is specifically configured to:
[0142] in any one of the following cases, determine that the target behavior abnormality category of the IoT card is second-level abnormality behavior:
[0143] the subscription data of the tariff package of the IoT card includes non-directional voice service;
[0144] the online terminal of the IoT card belongs to a preset sensitive terminal;
[0145] The Internet of Things card belongs to a behavior restriction whitelist card, and behavior data of the Internet of Things card exceeds preset behavior content of the behavior restriction whitelist;
[0146] The Internet of Things card belongs to a behavior restriction whitelist card, and behavior data of the Internet of Things card exceeds preset behavior content of the behavior restriction whitelist;
[0147] Optionally, the first processor 501 is specifically configured to:
[0148] In any of the following cases, the target behavior anomaly category of the Internet of Things card is determined to be a third-level abnormal behavior:
[0149] The tariff package subscription data of the Internet of Things card includes non-directional traffic services or non-directional short message services;
[0150] The machine-card separation data indicates that the first terminal has a machine-card separation behavior with the Internet of Things card, and the first terminal is associated with the Internet of Things card;
[0151] The usage amount of traffic, short message or voice in the bill data of the Internet of Things card exceeds a preset threshold;
[0152] The Internet of Things card is in a roaming state, and the Internet of Things card is in a preset risk area.
[0153] Optionally, the first processor 501 is specifically configured to:
[0154] In the following case, the target behavior anomaly category of the Internet of Things card is determined to be a fourth-level abnormal behavior:
[0155] Based on the behavior data, a third behavior anomaly category of the Internet of Things card is determined; in a case where the third behavior anomaly category is any one of an extremely high abnormal behavior, a higher abnormal behavior and a medium abnormal behavior, if the Internet of Things card belongs to an abnormal behavior whitelist card, and the third behavior anomaly category belongs to an abnormal behavior allowed to occur in the abnormal behavior whitelist.
[0156] Optionally, the first processor 501 is specifically configured to:
[0157] In the following case, the target behavior anomaly category of the Internet of Things card is determined to be a fifth-level abnormal behavior:
[0158] The Internet of Things card belongs to a security whitelist card.
[0159] Optionally, the first processor 501 is specifically configured to:
[0160] According to the behavior data, a first behavior anomaly category of the Internet of Things card is determined;
[0161] receive a second behavior abnormality category input for the behavior data;
[0162] In a case where the first behavior abnormality category does not match the second behavior abnormality category, determine the second behavior abnormality category as the target behavior abnormality category.
[0163] Optionally, the preset abnormal behavior category includes at least one of a first-level abnormal behavior, a second-level abnormal behavior, and a third-level abnormal behavior, and the first control strategy includes at least one of shutdown, turning off an online function, turning off a voice function, turning off a short message function, and flow rate limiting.
[0164] It should be noted that the present embodiment is an implementation of an electronic device corresponding to the above-mentioned method embodiment, and thus the relevant descriptions in the above-mentioned method embodiment can be referred to, and the same beneficial effects can be achieved. To avoid repetition, no further description is given here.
[0165] The present embodiment also provides an electronic device. Referring to Figure 6 The electronic device can include a second processor 601, a first memory 602, and a first computer program 6021 stored in the first memory 602 and executable on the second processor 601, and the first computer program 6021, when executed by the second processor 601, can implement Figure 1 any step in the corresponding method embodiment and achieve the same beneficial effects, which will not be repeated here.
[0166] Those skilled in the art can understand that all or part of the steps of the above-mentioned embodiment methods can be completed by program instructions related to hardware, and the programs can be stored in a computer readable medium. The present embodiment also provides a computer readable storage medium, and the computer readable storage medium stores a second computer program, and the second computer program, when executed by a third processor, can implement any step in the above-mentioned Figure 1 corresponding method embodiment and achieve the same technical effects. To avoid repetition, no further description is given here.
[0167] The storage medium, such as a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, etc.
[0168] The above is the preferred embodiment of the present application. It should be noted that for those skilled in the art, without departing from the principles of the present application, a number of improvements and refinements can be made, which should also be considered within the scope of protection of the present application.
Claims
1. A control method for an Internet of Things (IoT) card, applied to electronic devices, characterized in that, The method comprises: acquiring behavior data of the Internet of Things card; determining a target behavior anomaly category of the Internet of Things card based on the behavior data; in a case where the target behavior anomaly category is any one of preset abnormal behavior categories, performing a first control strategy corresponding to the target behavior anomaly category on the Internet of Things card, the preset abnormal behavior categories comprising at least one of a first level abnormal behavior, a second level abnormal behavior, a third level abnormal behavior, a fourth level abnormal behavior and a fifth level abnormal behavior; wherein the Internet of Things card comprises a security whitelist, an abnormal behavior whitelist and a behavior restriction whitelist, the abnormal behavior whitelist being used to limit a set of abnormal behaviors of the Internet of Things card allowed to occur due to maintaining normal business, and the behavior restriction whitelist being used to limit a minimum set of compliant behaviors of the Internet of Things card that can occur; the determination of the target behavior anomaly category of the Internet of Things card based on the behavior data comprises at least one of: in a case where the Internet of Things card belongs to the card of the behavior restriction whitelist and the behavior data of the Internet of Things card exceeds preset behavior content of the behavior restriction whitelist, determining the target behavior anomaly category of the Internet of Things card as the second level abnormal behavior; in a case where a third behavior anomaly category of the Internet of Things card is determined to be any one of the first level abnormal behavior, the second level abnormal behavior and the third level abnormal behavior based on the behavior data, if the Internet of Things card belongs to the card of the abnormal behavior whitelist and the third behavior anomaly category belongs to an abnormal behavior allowed to occur in the abnormal behavior whitelist, determining the target behavior anomaly category of the Internet of Things card as the fourth level abnormal behavior; in a case where the Internet of Things card belongs to the card of the security whitelist, determining the target behavior anomaly category of the Internet of Things card as the fifth level abnormal behavior. 2.The control method of the IoT card according to claim 1, characterized in that, The first level abnormal behavior is an extremely high abnormal behavior; the second level abnormal behavior is a higher abnormal behavior; the third level abnormal behavior is a medium abnormal behavior; the fourth level abnormal behavior is a low abnormal behavior; the fifth level abnormal behavior is a security behavior; The behavior data comprises at least one of online location, online terminal, online access address, subscription data of a tariff package, call data and machine-card separation data. 3.The control method of the IoT card of claim 2, wherein, The determination of the target behavior anomaly category of the Internet of Things card based on the behavior data comprises: in any one of the following cases, determining the target behavior anomaly category of the Internet of Things card as the first level abnormal behavior: the Internet of Things card is in a roaming state, and the online location of the Internet of Things card belongs to a preset risk area, and the subscription data of the tariff package comprises non-directional voice service or non-directional traffic service; the online terminal of the Internet of Things card belongs to a preset sensitive terminal, and the subscription data of the tariff package comprises non-directional voice service or non-directional traffic service; the online terminal of the Internet of Things card belongs to a preset sensitive terminal, and the machine-card separation data indicates that a first terminal and the Internet of Things card have occurred a machine-card separation behavior, and the first terminal is associated with the Internet of Things card. 4.The control method of the IoT card of claim 2, wherein, The target behavior abnormality category of the Internet of Things card is determined based on the behavior data, and the target behavior abnormality category of the Internet of Things card is determined based on the behavior data. In any of the following cases, the target behavior abnormality category of the Internet of Things card is determined to be a second level abnormal behavior: The tariff package subscription data of the Internet of Things card includes non-directional voice service; The online terminal of the Internet of Things card belongs to a preset sensitive terminal; The online access address of the Internet of Things card belongs to a preset unreasonable access address. 5.The control method of the IoT card of claim 2, wherein, The target behavior abnormality category of the Internet of Things card is determined based on the behavior data, and the target behavior abnormality category of the Internet of Things card is determined based on the behavior data. In any of the following cases, the target behavior abnormality category of the Internet of Things card is determined to be a third level abnormal behavior: The tariff package subscription data of the Internet of Things card includes non-directional traffic service or non-directional short message service; The machine card separation data indicates that the first terminal has a machine card separation behavior with the Internet of Things card, and the first terminal is associated with the Internet of Things card; The usage amount of traffic, short message or voice in the bill data of the Internet of Things card exceeds a preset threshold; The Internet of Things card is in a roaming state, and the online location of the Internet of Things card belongs to a preset risk area. 6.The control method of an IoT card according to claim 1, characterized in that, The target behavior abnormality category of the Internet of Things card is determined based on the behavior data, and the target behavior abnormality category of the Internet of Things card is determined based on the behavior data. According to the behavior data, the first behavior abnormality category of the Internet of Things card is determined; A second behavior abnormality category input for the behavior data is received; In the case where the first behavior abnormality category and the second behavior abnormality category do not match, the second behavior abnormality category is determined as the target behavior abnormality category. 7.The control method of an IoT card according to claim 1, characterized in that, The first control strategy includes at least one of shutdown, closing online function, closing voice function, closing short message function and traffic speed limit.
8. An electronic device, comprising: The electronic device comprises: A first processor is configured to: Obtain behavior data of an Internet of Things card; Determine a target behavior abnormality category of the Internet of Things card based on the behavior data; In the case where the target behavior abnormality category is any of a preset abnormal behavior category, execute a first control strategy corresponding to the target behavior abnormality category on the Internet of Things card, and the preset abnormal behavior category includes at least one of a first level abnormal behavior, a second level abnormal behavior, a third level abnormal behavior, a fourth level abnormal behavior and a fifth level abnormal behavior; The Internet of Things card includes a security white list, an abnormal behavior white list and a behavior restriction white list, the abnormal behavior white list is used to limit the set of abnormal behaviors allowed to occur due to maintaining normal business of the Internet of Things card, and the behavior restriction white list is used to limit the minimum compliance behavior set of the Internet of Things card; The first processor is specifically configured to perform at least one of the following: In the case where the Internet of Things card belongs to the behavior restriction white list, and the behavior data of the Internet of Things card exceeds the preset behavior content of the behavior restriction white list, the target behavior abnormality category of the Internet of Things card is determined to be the second level abnormal behavior. In a case where it is determined, based on the behavior data, that the third behavior anomaly category of the Internet of Things card is any one of a first level of abnormal behavior, a second level of abnormal behavior and a third level of abnormal behavior, if the Internet of Things card belongs to the card of the abnormal behavior whitelist, and the third behavior anomaly category belongs to the abnormal behavior allowed to occur in the abnormal behavior whitelist, the target behavior anomaly category of the Internet of Things card is determined as the fourth level of abnormal behavior; In a case where the Internet of Things card belongs to the card of the security whitelist, the target behavior anomaly category of the Internet of Things card is determined as the fifth level of abnormal behavior.
9. An electronic device, comprising: The first computer program stored on the first memory and executable on the second processor, when executed by the second processor, implements the steps of the control method of the Internet of Things card according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, The second computer program stored on the computer readable storage medium, when executed by the third processor, implements the steps of the control method of the Internet of Things card according to any one of claims 1 to 7.
Citation Information
Patent Citations
Internet of Things card service anomaly detection method and device, equipment and medium
CN111371581A
Method, device and equipment for detecting abnormal use of Internet of Things card, and medium
CN111371633A