Method, device, server, electronic device and storage medium for detecting hidden Internet of Things devices
Through network sniffing technology and fingerprint feature recognition model, combined with wireless signal strength and visual inertial odometer, the problem of users' difficulty in identifying concealed IoT devices is solved, and the accurate identification and positioning of concealed devices is achieved, and the security of user privacy is improved.
Patent Information
- Application Number
- CN202210355989.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-04-06
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2042-04-06
AI Technical Summary
In unfamiliar environments, it is difficult for users to effectively identify whether there are hidden IoT devices, making it difficult to ensure privacy and security.
The metadata attributes of network data packets are collected by enabling network sniffing technology, and the fingerprint feature recognition model is used to determine the IoT device type, combining wireless signal strength and visual inertial odometer for positioning, and using AR technology to visually display the device position.
It realizes the accurate identification and location of hidden IoT devices without the need for IP/DNS layer information and wireless channel allocation, thereby improving the security of user privacy.
Smart Images

Figure CN114827990B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of Internet of Things security technology, and in particular to a method, device, server, electronic device and storage medium for detecting hidden Internet of Things devices. Background Art
[0002] With the development of network technology, IoT devices have become popularized. However, they are sometimes used to spy on or even steal user privacy. For example, a hidden IoT device (such as a camera, microphone, or speaker) is installed in an unfamiliar environment. When you walk into the unfamiliar environment, it monitors the user and steals the privacy.
[0003] Currently, ordinary users usually do not carry expensive and professional sensor detection equipment. It is difficult to discover whether there are hidden IoT devices in unfamiliar environments to spy on user privacy, making it difficult to effectively ensure user privacy security. Summary of the invention
[0004] In view of this, the embodiments of the present invention provide a method, apparatus, server, electronic device and storage medium for detecting hidden IoT devices, which are convenient for identifying whether there are hidden IoT devices in the user's environment, thereby protecting the user's privacy security to a certain extent.
[0005] In order to achieve the above-mentioned invention object, the following technical scheme is adopted:
[0006] In a first aspect, an embodiment of the present invention provides a method for detecting hidden Internet of Things devices. The method for detecting hidden Internet of Things devices includes: after enabling network sniffing, collecting network data packets on different channels that are searched;
[0007] Parse the network data packet to obtain metadata attributes of the network data packet; determine the type of IoT device corresponding to the metadata attributes based on a fingerprint feature recognition model according to the metadata attributes; wherein the fingerprint feature recognition model is a relationship between the IoT device type and the metadata attributes.
[0008] Optionally, the network sniffing is wireless network sniffing; after determining the type of IoT device corresponding to the metadata attribute, the method further includes:
[0009] The location information of the IoT device relative to the current network sniffing user device is determined based on the received network signal strength of the IoT device and the visual inertial odometer.
[0010] Optionally, determining the location information of the IoT device relative to the current network sniffing user device according to the received network signal strength of the IoT device and the visual inertial odometer includes:
[0011] Detecting the coordinate value of the first position of the current network sniffing user device and the first network signal strength received from the Internet of Things device;
[0012] Move the current network sniffing user device to a second location, detect the coordinate value of the second location and the received second network signal strength of the Internet of Things device;
[0013] Calculate the average network signal strength in the first grid area based on at least the network signal strength of the Internet of Things device received at the first location and the second location;
[0014] Repeat the above steps, and at least calculate the average network signal strength of the network signal strengths of the plurality of IoT devices in the second grid area;
[0015] At least comparing the average network signal strengths of the first grid area and the second grid area;
[0016] Based on the signal strength of the center point of the grid area with stronger average network signal strength, the location of the IoT device is determined according to the RSSI positioning algorithm.
[0017] Optionally, the method further includes: after determining the location of the IoT device, using AR technology to visually display the location information of the IoT device.
[0018] Optionally, the fingerprint feature recognition model is obtained by training a selected machine learning classifier based on metadata attribute features in network data packets of a large number of IoT devices. Optionally, the metadata attributes include: arrival time, data packet size, data packet length, and data packet subtype specific to a standard communication protocol; wherein the data packet subtype is attribute data that characterizes a certain type of IoT device.
[0019] Optionally, the network data packet carries unique identification code information of the Internet of Things device. After collecting the searched network data packets on different channels, the method further includes: grouping the collected network data packets according to the unique identification code information they carry; wherein the unique identification code information includes: MAC address.
[0020] In a second aspect, an embodiment of the present invention further provides a device for detecting hidden Internet of Things devices, comprising: a data acquisition module, a data analysis module and a device fingerprint recognition module; the data acquisition module is used to collect network data packets on different channels searched after enabling the network sniffing program; the data analysis module is used to parse the network data packets to obtain metadata attributes of the network data packets; the device fingerprint recognition module is used to determine the type of Internet of Things device corresponding to the metadata attributes based on a fingerprint feature recognition model according to the metadata attributes; wherein the fingerprint feature recognition model is a relationship formula that characterizes the relationship between the type of Internet of Things device and the metadata attributes.
[0021] In a third aspect, an embodiment of the present invention provides an electronic device, comprising: one or more processors; a memory; one or more executable programs are stored in the memory, and the one or more processors read the executable program code stored in the memory to execute the method for detecting hidden Internet of Things devices described in any one of the first aspects.
[0022] In a fourth aspect, an embodiment of the present invention provides a computer-readable storage medium, wherein the computer-readable storage medium stores one or more programs, and the one or more programs can be executed by one or more processors to implement the method for detecting hidden Internet of Things devices as described in any one of the first aspects.
[0023] In a fifth aspect, an embodiment of the present invention provides a server, comprising: a host, for receiving network data packets on different channels collected and searched and sent by a user device installed with a network sniffer program; parsing the network data packets to obtain metadata attributes of the network data packets; determining the type of Internet of Things device corresponding to the metadata attributes based on a fingerprint feature recognition model according to the metadata attributes; wherein the fingerprint feature recognition model is a relationship equation that characterizes the relationship between the type of Internet of Things device and the metadata attributes.
[0024] The method, device, server, electronic device and storage medium for detecting hidden IoT devices provided by the embodiments of the present invention enable network sniffing to collect coarse-grained network layer features, such as wireless layer features, i.e., metadata attributes of network data packets, to identify different devices without IP / DNS layer information or knowing the wireless channel allocation of hidden IoT devices. According to the metadata attributes, the type of IoT device corresponding to the metadata attributes can be accurately determined based on the fingerprint feature recognition model, thereby comparing the determined IoT device type with the visible IoT devices in the current user's environment to identify whether there are hidden IoT devices in the current user's environment. Therefore, the present invention facilitates the identification of whether there are hidden IoT devices in the user's environment, thereby protecting the user's privacy and security to a certain extent. BRIEF DESCRIPTION OF THE DRAWINGS
[0025] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0026] Figure 1 A schematic diagram of a flow chart of an embodiment of a method for detecting hidden IoT devices according to the present invention;
[0027] Figure 2 A schematic diagram of another embodiment of the method for detecting hidden IoT devices according to the present invention;
[0028] Figure 3 A flowchart of another embodiment of the method for detecting hidden IoT devices according to the present invention
[0029] Figure 4 This is a schematic block diagram of an embodiment of the apparatus for detecting hidden IoT devices according to the present invention;
[0030] Figure 5 The figure is a schematic diagram of the structure of an embodiment of the electronic device of the present invention. DETAILED DESCRIPTION
[0031] The embodiments of the present invention are described in detail below with reference to the accompanying drawings.
[0032] It should be clear that the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0033] The method and device for detecting hidden IoT devices provided by the embodiments of the present invention can be applied to user privacy and security protection scenarios, and can conveniently detect whether there are hidden IoT devices in the user's environment, such as cameras, microphones, speakers, etc.
[0034] By using the fingerprint feature recognition model trained by network sniffing technology and machine learning algorithms, based on the metadata attributes of the collected network data packets, it is possible to easily and accurately determine whether there are hidden IoT devices in the current user's environment, thereby improving the security of user privacy to a certain extent. It should be noted that the method can be solidified in a certain manufactured physical product in the form of software, such as a laptop computer, a smart phone, an IPAD or other electronic device, and when the user uses the product, the method flow of the present application can be reproduced.
[0035] Figure 1FIG. 1 is a flow chart of an embodiment of a method for detecting hidden IoT devices according to the present invention; see FIG. Figure 1 As shown, the method for detecting hidden IoT devices may include the steps of:
[0036] S110, after enabling network sniffing, collecting the network data packets found on different channels.
[0037] In this embodiment, a network sniffer program (tool) can be pre-installed on electronic products that users can carry with them, such as laptop computers or smart phones. When the user enters an unfamiliar environment, such as a hotel, the network sniffer program can be turned on. The network sniffer program can run in the background and automatically collect network data packets on different channels that are searched.
[0038] The network data packet may be a sent network data packet or a received network data packet, and is named according to the different directions in which the data packet is transmitted, but is essentially the transmission of a data packet.
[0039] As an optional embodiment, the network sniffing is wireless network sniffing, and the network data packet is a wireless network data packet.
[0040] It is understandable that IoT devices may be located on different wireless networks, distributed on 30 channels within the 2.4ghz and 5ghzWIFI frequency range. Therefore, in order to avoid missing "packet capture", a mechanism is needed to monitor various signal channels in order to collect network data packets of all IoT devices near the user for fingerprint feature recognition of hidden IoT devices.
[0041] However, the user does not know which channel the multiple IoT devices used by the attacker are on, and the transmission time of each physical network device to transmit the network data packet. In order to avoid wasting time on sensing inactive signals that are invalid for identifying hidden IoT devices, in some embodiments, a fast loop iteration is used to discover the active channel, and the active channel is discovered based on whether any beacon frame is sensed, and the existence of IoT devices in the channel corresponds to the active access point communicating with it; in this way, a subset of active channels can be found by round-robin channel hopping, and network data packets of possible target IoT devices can be quickly collected and searched.
[0042] In order to improve the comprehensiveness of subsequent identification, in this embodiment, by adopting network sniffing technology and cyclic channel hopping, as many wireless data packets as possible on different channels can be collected to a certain extent, thereby avoiding missing key data.
[0043] When dealing with IoT devices with different transmission behaviors, for devices with high transmission rates, a sufficient number of data packets can be sniffed very quickly; and for data packet capture of devices with low transmission rates, a classification engine can be used to determine the device type, and a small number of data packets transmitted by the low transmission rate device can be collected at the moment of transmission. Then, for each type of device, the metadata attributes of the data packet are predicted according to the device type, and the average arrival time of the data packets corresponding to the first three predictions are obtained directly from the training data (the data is the various metadata attribute values corresponding to different types of devices prepared in advance during the training process of the fingerprint feature recognition model). In this way, the data packet attributes of the low transmission rate device can be quickly obtained.
[0044] S120: Parse the network data packet to obtain metadata properties of the network data packet.
[0045] The analysis of network data can be implemented according to the existing technology, which will not be described in detail here.
[0046] In this embodiment, metadata attributes refer to attributes that describe data, such as the arrival time of a data packet, the size of a data packet, the length of a data packet, and a data packet subtype specific to a standard communication protocol.
[0047] The data packet subtype is a unique attribute data that characterizes a certain type of IoT device; for example, the subtype attribute is used in a certain manufacturer's IoT doorbell to notify the access point device to enter sleep mode; for another example, in the camera of the same manufacturer, this attribute means something else. These attributes can serve as the basis for defining the fingerprint characteristics of IoT devices.
[0048] S130. Determine the IoT device type corresponding to the metadata attribute based on a fingerprint feature recognition model according to the metadata attribute; wherein the fingerprint feature recognition model is a relationship formula that represents the relationship between the IoT device type and the metadata attribute.
[0049] The fingerprint feature recognition model is obtained by training based on the metadata attribute features in the network data packets of a large number of IoT devices and based on the selected machine learning classifier.
[0050] For wireless network data packets, data transmission is generally based on the 802.11 standard communication protocol. However, the data packets of the 802.11 standard communication protocol can generally only obtain the MAC layer information of the header, and need to process various devices with different transmission rates, which is relatively cumbersome.
[0051] In some solutions, the fingerprint characteristics of IoT devices are first extracted using high-level information such as IP, DNS, port number and NTP protocol to identify different IoT devices. However, due to limited network visibility, only the 802.11 header can be sniffed.
[0052] In order to solve these problems, a systematic machine learning framework is designed in the present invention. In this embodiment, these problems are solved by designing a machine learning framework. In order to achieve a wide range of observable feature sets, rather than the traditional hand-crafted feature library with a small amount of data, and to solve the problem of device diversity, the system uses multiple time scales to extract specific attributes of different types of IoT devices, and trains the attributes as feature sets, which enables the trained feature recognition model to generalize predictions for a large number of device types from different manufacturers and different hardware settings.
[0053] In addition, even in a single protocol like 802.11, hidden IoT devices can use a large number of channels. In an unfamiliar environment, it is unknown when hidden devices use what channels and how long each device transmits. In this embodiment, the approximate transmission pattern of each device over time is collected in advance, and this pattern is used to inform the channel sensing strategy to detect network data packets on different channels.
[0054] As mentioned earlier, in some solutions, IoT devices are associated with their fingerprint characteristics by identifying the IP, DNS and NTP packets of different devices. Due to limited network visibility, the encrypted wireless 802.11 header is the only coarse attribute available to the user device, resulting in low detection accuracy.
[0055] To solve this problem, in this solution, the widest feature set is considered, and a machine learning framework is used to extract effective fingerprint features (features that can be used to identify the uniqueness of a device type) for each device type in time and available 802.11 packet header attributes. In addition, the machine learning framework used to train the fingerprint feature recognition model in this embodiment automatically adjusts the time scale of the aggregated features according to the transmission rate of each device, and the classification engine used accepts wireless 802.11 network packets sent to or from all available IoT devices as input.
[0056] In some embodiments, the network data packet carries unique identification code information of the IoT device. After collecting the searched network data packets on different channels, the method further includes: grouping the collected network data packets according to the unique identification code information they carry.
[0057] The unique identification code information includes: MAC address. The collected network data packets (messages) are grouped according to their MAC addresses, and the device type corresponding to each MAC address is predicted through feature engineering and classification methods, that is, the fingerprint feature recognition model obtained by training.
[0058] In order to automatically extract the attributes of each device, all possible 802.11 packet headers are first collected, and then all attributes of each packet are extracted, which will result in a total of 125 attributes. However, some of these attributes have the same value on different devices (e.g., AP-specific attributes) and do not carry any useful information. In order to simplify the process and prevent overfitting, we discard these attributes. In the model of the present invention, 52 of the 125 attributes are retained after this pruning step. Therefore, the metadata attributes of the network data packets listed above are not exhaustive.
[0059] After processing the collected fingerprint features, proceed to train a machine learning prediction model, namely the fingerprint feature recognition model; select a one-to-one classifier and train a binary classifier for each class. Select XGBoost as the machine learning classifier, which has a high verification accuracy. Train the classifier based on the last set of features and define the following device types as classes, such as: smart cameras, speakers, TVs, plugs, security systems, kitchen appliances, light bulbs, and doorbells.
[0060] In this embodiment, a machine learning algorithm is used to train based on the fingerprint features collected from a large number of types of IoT devices to obtain a fingerprint feature recognition model, which can be used to more accurately identify the type of IoT device based on the metadata attributes of the network data packet.
[0061] It is understandable that after determining the types of IoT devices around the current user's environment, it is possible to determine whether there are any hidden IoT devices by comparing them with the visible IoT devices in the current environment. After determining that there are hidden IoT devices, they need to be further located. It is difficult for ordinary users to quickly find hidden IoT devices without the support of professional positioning equipment.
[0062] Therefore, in order to solve the above-mentioned problem of locating hidden IoT devices, such as Figure 2 and Figure 3 As shown, in some embodiments, the network sniffing is wireless network sniffing; after determining the type of IoT device corresponding to the metadata attribute, the method further includes step S140: determining the location information of the IoT device relative to the current network sniffing user device based on the received network signal strength of the IoT device and the visual inertial odometry (VIO).
[0063] Among them, the visual inertial odometry is mainly based on integrating the inertial sensor IMU readings of the user's device with the camera to determine the changes in the user's position and direction over time. The signal strength from different distances to the device is measured by the user's movement in the environment and the change in direction over a period of time.
[0064] Specifically, determining the location information of the Internet of Things device relative to the current network sniffing user device based on the received network signal strength of the Internet of Things device and the visual inertial odometer includes: detecting the coordinate value of the first position of the current network sniffing user device and the received first network signal strength of the Internet of Things device; moving the current network sniffing user device to a second position, detecting the coordinate value of the second position and the received second network signal strength of the Internet of Things device.
[0065] Among them, the location change of the current network sniffing user device is detected by the inertial sensor IMU and camera in the user device. The network signal strength can be detected by the wireless sensor network chip in the user device to sense the signal strength.
[0066] The average network signal strength in the first grid area is calculated based on at least the network signal strength of the Internet of Things device received at the first location and the second location.
[0067] Repeat the above steps to at least calculate the average network signal strength of the network signal strengths of the plurality of IoT devices in the second grid area.
[0068] The first grid area and the second grid area are grids of a predetermined size formed according to the area where the user walks back and forth, for example, the grid size is 0.5CMx0.5CM.
[0069] In order to improve the accuracy of detection, multiple grid areas can be divided. At least the average network signal strength of the first grid area and the second grid area is compared; based on the signal strength of the center point of the grid area with stronger average network signal strength, the location of the IoT device is determined according to the RSSI positioning algorithm.
[0070] Among them, the RSSI positioning algorithm is a mature positioning algorithm, for example, three-side positioning, three-point positioning algorithm, etc. In order to highlight the invention and innovation, it will not be repeated here.
[0071] Exemplarily, when a user enters an unfamiliar environment, the server collects (x, y, rssi) data samples, where x and y are the initial point relative to where the user starts walking, i.e., the reference point; when the user moves in the environment, different data samples can be collected, and the position of each device can be estimated using the RSSI value and the changed position point.
[0072] Among them, a simple method to estimate the IoT device is to select the sample with the highest RSSI value (x, y, RSSI), which means that the user is closest to the device. However, this method is only effective and accurate when the user is close to the IoT device. In this system, a grid-based modeling method is adopted, which is widely used in sparse sample parameter calculation. A grid is formed according to the user's walking area, and the observed average RSSI value is calculated for each grid area. Then the signal strength of the grid center point with the largest RSSI average value is selected to determine the device location, which can improve the effectiveness and accuracy of detection.
[0073] In order to more accurately refine the positioning, in some embodiments, the location of the IoT device can also be determined by taking sparse samples, fitting a surface in the form of V=f(x,y) to the scattered data in the (x,y,RSSI) vector, forming a 1x1cm grid of intersection coordinates (xq,yq) as a query point (i.e., a positioning point), and interpolating a linear surface based on three-dimensional triangles at each point, and then extracting the surface area maximum as the location of the hidden IoT device.
[0074] The method of generating a surface of the form V = f(x, y) can be found in the academic journal published in 1997 and included in the VIP website, entitled: Generation of Arbitrary Surfaces of the Form Z = f(x, y). We will not elaborate on this here.
[0075] A linear surface based on three-dimensional triangles is interpolated at each point to realize three-dimensional triangulation of the surface into surface fragments, so as to find the maximum point of the surface area.
[0076] To help users find the devices deployed by attackers and eliminate security risks. Figure 3 As shown, in some embodiments, the method further includes: after determining the location of the IoT device, executing step S150, using AR (Augmented Reality) technology to visually display the location information of the IoT device, including the direction of the hidden device and the distance from the user.
[0077] The method for detecting hidden IoT devices provided by the embodiment of the present invention enables network sniffing to collect coarse-grained network layer features, such as wireless layer features, that is, metadata attributes of network data packets, to identify different devices. No IP / DNS layer information is required, and no wireless channel allocation of hidden IoT devices is required. According to the metadata attributes, the type of IoT device corresponding to the metadata attributes can be accurately determined based on the fingerprint feature recognition model, so as to compare the determined IoT device type with the visible IoT devices in the current user's environment, and identify whether there are hidden IoT devices in the current user's environment. Therefore, the present invention facilitates the identification of whether there are hidden IoT devices in the user's environment, thereby protecting the user's privacy security to a certain extent.
[0078] Embodiment 2
[0079] Figure 4 This is a schematic block diagram of an embodiment of the apparatus for detecting hidden IoT devices according to the present invention. Figure 4 As shown, the device for detecting hidden IoT devices provided by the embodiment of the present invention includes: a data acquisition module 210, a data analysis module 220 and a device fingerprint recognition module 230;
[0080] The data collection module 210 is used to collect network data packets on different channels after enabling network sniffing;
[0081] The data parsing module 220 is used to parse the network data packet to obtain metadata attributes of the network data packet;
[0082] The device fingerprint recognition module 230 is used to determine the IoT device type corresponding to the metadata attribute based on the fingerprint feature recognition model according to the metadata attribute; wherein the fingerprint feature recognition model is a relationship formula that represents the relationship between the IoT device type and the metadata attribute.
[0083] The device of this embodiment can be used to perform Figure 1 The technical solution of the method embodiment shown, the server of this embodiment, its implementation principle and technical effect are similar to those of embodiment 1, and will not be described in detail here, and can be referenced by each other.
[0084] The present invention also provides a server according to an embodiment, including: a host, configured to:
[0085] Receiving network data packets collected and searched on different channels sent by a user device installed with a network sniffer program;
[0086] Parsing the network data packet to obtain metadata attributes of the network data packet;
[0087] According to the metadata attribute, the IoT device type corresponding to the metadata attribute is determined based on a fingerprint feature recognition model; wherein the fingerprint feature recognition model is a relationship formula that characterizes the relationship between the IoT device type and the metadata attribute.
[0088] The server of this embodiment can be used to execute Figure 1 The technical solution of the method embodiment shown, the server of this embodiment, its implementation principle and technical effect are similar to those of embodiment 1, and will not be described in detail here, and can be referenced by each other.
[0089] Embodiment 3
[0090] The present invention also provides an electronic device according to an embodiment, comprising one or more processors; a memory; the memory stores one or more executable programs, the one or more processors read the executable program code stored in the memory, and run the program corresponding to the executable program code to execute the method for detecting hidden Internet of Things devices described in any one of Embodiment 1.
[0091] Figure 5 FIG. 1 is a schematic diagram of the structure of an embodiment of an electronic device of the present invention, which can implement any method described in Embodiment 1 of the present invention, such as Figure 5 As shown, as an optional embodiment, the above-mentioned electronic device may include: a shell 41, a processor 42, a memory 43, a circuit board 44 and a power supply circuit 45, wherein the circuit board 44 is arranged inside the space enclosed by the shell 41, and the processor 42 and the memory 43 are arranged on the circuit board 44; the power supply circuit 45 is used to supply power to various circuits or devices of the above-mentioned electronic device; the memory 43 is used to store executable program codes; the processor 42 runs an application corresponding to the executable program code by reading the executable program code stored in the memory 43, so as to execute the method for detecting hidden Internet of Things devices described in any of the above-mentioned embodiments one.
[0092] The specific execution process of the above steps by the processor 42 and the steps further executed by the processor 42 by running the executable program code can be found in the description of the first embodiment of the method for detecting hidden Internet of Things devices of the present invention, which will not be repeated here.
[0093] The electronic device exists in various forms, including but not limited to: (1) Mobile communication devices: This type of device is characterized by having mobile communication functions and providing voice and data communication as its main goal. Such terminals include: smart phones (such as iPhones), multimedia phones, functional phones, and low-end phones. (2) Ultra-mobile personal computer devices: This type of device belongs to the category of personal computers, has computing and processing functions, and generally also has mobile Internet access features. Such terminals include: PDA, MID and UMPC devices, such as iPad. (3) Portable entertainment devices: This type of device can display and play multimedia content. Such devices include: audio and video playback modules (such as iPods), handheld game consoles, e-books, as well as smart toys and portable car navigation devices. (4) Servers: Devices that provide computing services. The server's composition includes processors, hard disks, memory, system buses, etc. The server is similar to the general computer architecture, but because it needs to provide highly reliable services, it has higher requirements in terms of processing power, stability, reliability, security, scalability, manageability, etc. (5) Other electronic devices with data interaction functions.
[0094] An embodiment of the present invention also provides a computer-readable storage medium, which stores one or more programs. The one or more programs can be executed by one or more processors to implement the method for detecting hidden Internet of Things devices described in any one of the above-mentioned embodiments.
[0095] According to the description of the above embodiments, the method and device for detecting hidden IoT devices disclosed in the present embodiment predict the corresponding IoT device type based on sniffed network data packets and trained fingerprint feature recognition models, thereby facilitating the determination of whether there are hidden IoT devices in the user's environment; further, hidden IoT devices can be located using only laptop or mobile phone sensors and wireless signal strength, and the location of the hidden IoT devices can be visualized on AR, thereby ensuring the security of user privacy to a certain extent.
[0096] It should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the existence of other identical elements in the process, method, article or device including the elements.
[0097] Each embodiment in this specification is described in a related manner, and the same or similar parts between the embodiments can be referenced to each other, and each embodiment focuses on the differences from other embodiments.
[0098] A person skilled in the art can understand that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program, and the program can be stored in a computer-readable storage medium, and when the program is executed, it can include the processes of the embodiments of the above-mentioned methods. The storage medium can also be a disk, an optical disk, a read-only memory (ROM) or a random access memory (RAM).
[0099] The above is only a specific embodiment of the present invention, but the protection scope of the present invention is not limited thereto. Any changes or substitutions that can be easily thought of by a person skilled in the art within the technical scope disclosed by the present invention should be included in the protection scope of the present invention. Therefore, the protection scope of the present invention shall be subject to the protection scope of the claims.
Claims
1. A method for detecting hidden IoT devices, characterized in that: The method comprises the steps of: After enabling network sniffing, collect the network data packets found on different channels; Parsing the network data packet to obtain metadata attributes of the network data packet; the metadata attributes include: arrival time, data packet size, data packet length, and data packet subtype specific to a standard communication protocol; wherein the data packet subtype is attribute data that characterizes a certain type of IoT device; Use a machine learning framework to extract effective fingerprint features for each device type in time and available 802.11 packet header attributes; The machine learning framework for training the fingerprint feature recognition model automatically adjusts the time scale of the aggregated features according to the transmission rate of each device; for devices with different transmission rates, chooses whether to use the classification engine to determine the device type; According to the metadata attribute, the type of IoT device corresponding to the metadata attribute is determined based on a fingerprint feature recognition model; wherein the fingerprint feature recognition model is a relationship between the type of IoT device and the metadata attribute; The collecting of the network data on different channels searched includes: discovering active channels by using round-robin channel hopping, discovering active channels based on whether any beacon frames are sensed, and determining a subset of active channels based on the presence of IoT devices in the channels corresponding to active access points communicating with them; After determining the type of IoT device corresponding to the metadata attribute, the method further includes: Detecting the coordinate value of the first position of the current network sniffing user device and the first network signal strength received from the Internet of Things device; Move the current network sniffing user device to a second location, detect the coordinate value of the second location and the received second network signal strength of the Internet of Things device; Calculate the average network signal strength in the first grid area based on at least the network signal strength of the Internet of Things device received at the first location and the second location; Repeat the above steps, and at least calculate the average network signal strength of the network signal strengths of the plurality of IoT devices in the second grid area; At least comparing the average network signal strengths of the first grid area and the second grid area; Based on the signal strength of the center point of the grid area with stronger average network signal strength, the location of the IoT device is determined according to the RSSI positioning algorithm; The fingerprint feature recognition model is obtained by training based on the metadata attribute features in the network data packets of a large number of IoT devices and based on the selected machine learning classifier.
2. The method for detecting hidden IoT devices according to claim 1, characterized in that: The method also includes: after determining the location of the IoT device, using AR technology to visualize and display the location information of the IoT device.
3. The method for detecting hidden IoT devices according to claim 1, characterized in that: The network data packet carries unique identification code information of the IoT device. After collecting the searched network data packets on different channels, the method further includes: grouping the collected network data packets according to the unique identification code information they carry; wherein the unique identification code information includes: MAC address.
4. An electronic device, characterized in that: include: One or more processors; Memory; One or more executable programs are stored in the memory, and the one or more processors read the executable program code stored in the memory to execute the method for detecting hidden Internet of Things devices described in any one of claims 1 to 3.
5. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores one or more programs, and the one or more programs can be executed by one or more processors to implement the method for detecting hidden Internet of Things devices as described in any one of claims 1 to 3.
Citation Information
Patent Citations
Wi-Fi video acquisition equipment detection method and system based on encrypted stream identification
CN110247819A
Wireless equipment fingerprint identification method and system, equipment and readable storage medium
CN111385297A
Relative positioning method, device and system between intelligent devices
CN112261573A