A method and system for wireless security detection of an internet of things terminal device

By acquiring and parsing the recorded traffic of IoT terminal devices in wireless networks, and generating and analyzing attack packets, the problem of device crashes during wireless security detection of IoT terminal devices is solved, enabling efficient wireless security detection and vulnerability database updates.

CN116600300BActive Publication Date: 2026-01-23GUANGDONG POWER GRID CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310648842.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-06-02
Publication Date
2026-01-23
Estimated Expiration
2043-06-02

AI Technical Summary

Technical Problem

Existing device security testing and evaluation products are not suitable for wireless security testing of IoT terminal devices. Traditional traffic testing and vulnerability scanning tools cannot meet the characteristics of IoT terminals, resulting in device crashes or failure to achieve complete security testing during the testing process.

Method used

In a wireless network environment, the recorded traffic of IoT terminal devices is acquired, and attack packets are generated by parsing and randomly transforming the data. An artificial intelligence engine is then used for comparative analysis to determine whether the attack was successful. The attack packets and recorded traffic are stored in a vulnerability database to optimize the accuracy of attack packet generation.

Benefits of technology

It enables wireless security testing of IoT terminal devices without affecting normal device operation, preventing device crashes, improving testing accuracy and user experience, and enriching the security function components of the devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116600300B_ABST
    Figure CN116600300B_ABST
Patent Text Reader

Abstract

The application discloses a kind of Internet of Things terminal equipment wireless security detection method and system, comprising: the first recording flow of the protection profile of the Internet of Things terminal equipment to be measured in the normal communication wireless network environment is obtained;First recording flow is parsed and randomly deformed, and first attack packet is obtained;Second recording flow of protection profile is obtained in the process of playing first attack packet in wireless network, and second recording flow is compared and analyzed with first recording flow by artificial intelligence engine;If consistent, it is judged that the attack of first attack packet to equipment succeeds, and first attack packet and second recording flow are stored to vulnerability library;If inconsistent, and the analysis result corresponding to second recording flow is that equipment is not responsive, it is judged that the attack of first attack packet to equipment fails.The application directly records the flow of each security function component of the Internet of Things terminal equipment to be measured when facing different attack packets, without being limited to the network performance of the Internet of Things terminal equipment to be measured.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of device security detection, and particularly relates to a wireless security detection method and system for Internet of Things terminal devices. BACKGROUND

[0002] In the Internet of Things environment, the security of terminal devices is the basis of the overall network security. However, the current Internet of Things terminal devices, when implemented, only consider low price and easy use, without considering the security function of the terminal devices. Once entering the Internet of Things, it is easy to invade the terminal devices and perform illegal operations. Therefore, in order to ensure the security of wireless communication of the Internet of Things terminal devices, the network security guarantee capability of the Internet of Things terminal devices should be tested and evaluated before the Internet of Things terminal devices are used for communication. However, the traditional device security testing and evaluation products still have certain disadvantages and cannot be applied to wireless security detection of the Internet of Things terminal devices. Firstly, the current testing and evaluation products are for PC and switch products, and these products have strong computing capabilities, so the testing process can load large capacity loads for testing and evaluation. However, the computing performance of the Internet of Things terminal is limited, and when the evaluation is performed by using such products, the terminal often directly crashes, and the security detection function cannot be truly realized. Secondly, these products mainly face TCP / IP protocols, while the Internet of Things terminal has multiple access methods and access protocols. Therefore, the traditional testing and evaluation method cannot perform complete wireless security evaluation on the wireless terminal. Thirdly, the testing and evaluation of the wireless terminal needs to be sealed and tested, and the firmware of the product cannot be directly read. Therefore, if the firmware reading and sealing and testing are not completed by using a special protocol, the evaluation agency needs to keep the samples. This testing method is not suitable for the rapidly developing Internet of Things terminal industry with various types.

[0003] The network security evaluation of the existing information products has two types of technologies, traffic test and vulnerability scanning. The two types of technologies do not have the conditions to carry out the test work for the characteristics of the Internet of Things terminal product, and thus are not suitable for the new Internet of Things scene. Among them, the traffic test type product can transmit various communication packets, communication sequences and certain traffic to the measured object through programming, so as to observe the response of the measured object. This type of product mainly tests the processing performance of network products to traffic, and is also used for performance testing of application systems. Since the Internet of Things terminal does not consider the need to be responsible for resisting DOS attacks, the traffic test type product cannot be applied in the Internet of Things terminal. The vulnerability scanning type tool is to obtain the measured device information and open port information by interacting with the measured device, and then match in the own vulnerability library to generate a report. This type of product mainly uses a standard vulnerability library, but in recent years, the vulnerability research of the Internet of Things terminal device is insufficient, and the vulnerability of the Internet of Things terminal in the standard vulnerability library is less. Even the operating system information of the Internet of Things terminal is different from the commercial operating system, and the open port and the format of the transmitted data are also different from the traditional network communication. In addition, the network performance of the Internet of Things terminal device is limited, and the open full network scanning may cause network crash or product crash, i.e. death, the overall test process has low automation degree, and the complete device wireless security detection cannot be directly realized. Therefore, the vulnerability scanning type tool generally cannot be applied in the Internet of Things, especially in the production type Internet of Things. SUMMARY

[0004] The application provides a wireless security detection method and system for an Internet of Things terminal device. In a wireless network environment, the recorded traffic of each security function component of the Internet of Things terminal device to be tested is directly obtained without being limited by the network performance of the Internet of Things terminal device to be tested, so as to avoid the death of the device and affect the wireless security detection of the device.

[0005] To solve the above technical problems, the application provides a wireless security detection method for an Internet of Things terminal device, which comprises the following steps:

[0006] obtaining the first recorded traffic of the protection profile of the Internet of Things terminal device to be tested in a normal communication wireless network environment;

[0007] analyzing and randomly deforming the first recorded traffic to obtain the corresponding first attack packet;

[0008] playing the first attack packet in the wireless network, and obtaining the second recorded traffic of the protection profile of the Internet of Things terminal device to be tested in real time during the playing process, and then comparing and analyzing the second recorded traffic with the first recorded traffic through an artificial intelligence engine to complete the wireless security detection of the Internet of Things terminal device to be tested;

[0009] If the comparison is consistent, it is judged that the first attack package attacks the to-be-tested Internet of Things terminal device successfully, and the first attack package and the second recorded traffic are stored in a vulnerability library;

[0010] If the comparison is inconsistent and the analysis result corresponding to the second recorded traffic is that the device does not respond, it is judged that the first attack package attacks the to-be-tested Internet of Things terminal device unsuccessfully.

[0011] The protection profile of the to-be-tested Internet of Things terminal device is composed of a plurality of security function components.

[0012] When the embodiment of the application is implemented, when the to-be-tested Internet of Things terminal device is in a normal communication wireless network environment, the first recorded traffic of the to-be-tested Internet of Things terminal device is acquired, then the first attack package obtained by analyzing and randomly deforming the first recorded traffic is played in the wireless network, and the second recorded traffic of the to-be-tested Internet of Things terminal device is acquired in real time during the playing process, so as to compare and analyze the second recorded traffic and the first recorded traffic by using an artificial intelligence engine, judge whether the first attack package attacks the to-be-tested Internet of Things terminal device successfully, and store the first attack package that attacks successfully and the second recorded traffic of the to-be-tested Internet of Things terminal device when the first attack package that attacks successfully is played in a vulnerability library, so as to enrich attack vulnerability cases of the to-be-tested Internet of Things terminal device, and improve the protection capability of the security function components of the to-be-tested Internet of Things terminal device. In addition, in the normal communication wireless network environment, the first recorded traffic of each security function component of the to-be-tested Internet of Things terminal device is directly acquired, and the second recorded traffic of each security function component of the to-be-tested Internet of Things terminal device is directly acquired during the process of playing the first attack package in the wireless network, without being limited by the network processing capability and data calculation performance of the to-be-tested Internet of Things terminal device, so that wireless security detection of the to-be-tested Internet of Things terminal device can be realized while avoiding device dead machine, and user experience is improved.

[0013] As a preferred solution, the wireless security detection method of the Internet of Things terminal device further comprises:

[0014] If the comparison is inconsistent and the analysis result corresponding to the second recorded traffic is that the device is unresponsive, it is determined that the attack of the first attack packet on the Internet of Things terminal device under test fails, and the second recorded traffic is iteratively processed. In each iteration, the current second recorded traffic is parsed and randomly deformed to obtain a second attack packet. Then, in the process of playing the second attack packet, the third recorded traffic of the Internet of Things terminal device under test is obtained in real time, and the current third recorded traffic and the current second recorded traffic are compared and analyzed by the artificial intelligence engine until the current third recorded traffic and the current second recorded traffic are consistent or the iteration number meets the preset number, and the iteration processing of the second recorded traffic is stopped to complete the wireless security detection of the Internet of Things terminal device under test.

[0015] If the current third recorded traffic and the current second recorded traffic are consistent, it is determined that the current second attack packet successfully attacks the Internet of Things terminal device under test, and the current second attack packet and the current third recorded traffic are stored in the vulnerability library.

[0016] The preferred scheme of the embodiment of the application is that when the comparison result of the second recorded traffic and the first recorded traffic is inconsistent and the analysis result is that the device is unresponsive, it is determined that the attack of the first attack packet on the Internet of Things terminal device under test fails. At this time, the second recorded traffic is iteratively processed. In each iteration, the deformation direction is adjusted, the current second recorded traffic is parsed and randomly deformed to obtain a second attack packet. Then, in the process of playing the second attack packet in the wireless network, the third recorded traffic of the Internet of Things terminal device under test is obtained in real time, and the current third recorded traffic and the current second recorded traffic are compared and analyzed by the artificial intelligence engine until the current third recorded traffic and the current second recorded traffic are consistent or the iteration number meets the preset number, and the iteration processing of the second recorded traffic is stopped, thereby gradually optimizing the attack packet and improving the generation accuracy of the attack packet.

[0017] As a preferred scheme, the wireless security detection method of the Internet of Things terminal device further comprises:

[0018] If the analysis result corresponding to the second recorded traffic is that it cannot be identified, a non-normal response signal is fed back, the attack judgment result corresponding to the second recorded traffic uploaded by the researcher is obtained, and then the attack judgment result is transmitted to the artificial intelligence engine to enable the artificial intelligence engine to learn and optimize according to the second recorded traffic and the attack judgment result;

[0019] When the attack judgment result is that the attack on the Internet of Things terminal device under test is successful, the first attack packet and the second recorded traffic are stored in the vulnerability library.

[0020] When the attack judgment result is that the attack on the to-be-tested Internet of Things terminal device fails, the second recorded traffic is parsed and randomly deformed one or more times to obtain a second attack packet that successfully attacks the to-be-tested Internet of Things terminal device, so as to complete the wireless security detection on the to-be-tested Internet of Things terminal device.

[0021] As a preferred solution of the embodiment of the present application, when the analysis result corresponding to the second recorded traffic is that it cannot be identified, a manual judgment mode is switched to and a non-normal response signal is fed back to remind researchers to give an attack judgment result corresponding to the second recorded traffic according to specific conditions, and then the attack judgment result is fed back to the generator and the discriminator of the artificial intelligence engine to simultaneously learn, so as to optimize the random deformation performance and the comparative analysis performance of the artificial intelligence engine on the recorded traffic.

[0022] As a preferred solution, the parsing and random deformation of the first recorded traffic to obtain the first attack packet are specifically as follows:

[0023] The first recorded traffic is parsed to obtain a corresponding field string;

[0024] The field string is randomly deformed through a genetic algorithm of the artificial intelligence engine, and a test packet editor is called to packetize the deformation result to obtain the corresponding first attack packet.

[0025] As a preferred solution of the embodiment of the present application, through the genetic algorithm of the artificial intelligence engine, the test packet editor is called to automatically obtain and guide an optimized search space, so that in the process of randomly deforming the field string obtained by parsing the first recorded traffic, the search direction can be adaptively adjusted to obtain an optimized random deformation result.

[0026] As a preferred solution, the first attack packet is played in the wireless network, and the second recorded traffic of the to-be-tested Internet of Things terminal device is obtained in real time during the playing process, and then the second recorded traffic and the first recorded traffic are compared and analyzed through the artificial intelligence engine to complete the wireless security detection on the to-be-tested Internet of Things terminal device, specifically as follows:

[0027] The first attack packet is played in the wireless network, and the output of the protection contour of the to-be-tested Internet of Things terminal device is recorded in real time during the playing process to obtain the second recorded traffic of the to-be-tested Internet of Things terminal device;

[0028] Through the artificial intelligence engine, a contrast algorithm is called to compare and analyze the second recorded traffic and the first recorded traffic to complete the wireless security detection on the to-be-tested Internet of Things terminal device.

[0029] In the process of playing the first attack packet in the wireless network, the output of the protection profile of the to-be-tested Internet of Things terminal device is recorded in real time, the black box detection of each security function component of the to-be-tested Internet of Things terminal device is realized, and the network processing capability and data calculation performance of the to-be-tested Internet of Things terminal device are not limited. In addition, the artificial intelligence engine is called to perform feature analysis and comparison on the second recorded traffic and the first recorded traffic, so as to improve the wireless security detection precision of the to-be-tested Internet of Things terminal device.

[0030] As a preferred solution, the first recorded traffic of the to-be-tested Internet of Things terminal device in the normal communication wireless network environment is obtained, specifically as follows:

[0031] When the to-be-tested Internet of Things terminal device operates in the normal communication wireless network environment, the output of the protection profile of the to-be-tested Internet of Things terminal device is recorded in real time, and the first recorded traffic corresponding to the to-be-tested Internet of Things terminal device is obtained.

[0032] As a preferred solution of the embodiment of the present application, when the to-be-tested Internet of Things terminal device operates in the normal communication wireless network environment, the output of the protection profile of the to-be-tested Internet of Things terminal device is recorded in real time, and the first recorded traffic obtained by recording is used as the analysis basis of the attack behavior, and is compared with the recording result of the output of the protection profile of the to-be-tested Internet of Things terminal device when each attack packet is played.

[0033] To solve the same technical problem, the embodiment of the present application also provides an Internet of Things terminal device wireless security detection system, comprising:

[0034] A traffic acquisition module is configured to acquire first recorded traffic of a protection profile of a to-be-tested Internet of Things terminal device in a normal communication wireless network environment; wherein the protection profile of the to-be-tested Internet of Things terminal device is composed of a plurality of security function components;

[0035] An analysis and deformation module is configured to analyze and deform the first recorded traffic to obtain corresponding first attack packets;

[0036] A comparative analysis module is configured to play the first attack packets in the wireless network, acquire second recorded traffic of the protection profile of the to-be-tested Internet of Things terminal device in real time during the playing process, and then compare and analyze the second recorded traffic and the first recorded traffic through an artificial intelligence engine to complete wireless security detection of the to-be-tested Internet of Things terminal device;

[0037] The first determining module is configured to determine that the first attack packet succeeds in attacking the to-be-tested Internet of Things terminal device if the second recorded traffic is consistent with the first recorded traffic, and store the first attack packet and the second recorded traffic into a vulnerability library.

[0038] The second determining module is configured to determine that the first attack packet fails in attacking the to-be-tested Internet of Things terminal device if the second recorded traffic is inconsistent with the first recorded traffic and the analysis result corresponding to the second recorded traffic is that the device is unresponsive.

[0039] As a preferred solution, the second determining module is further configured to determine that the first attack packet fails in attacking the to-be-tested Internet of Things terminal device if the comparison is inconsistent and the analysis result corresponding to the second recorded traffic is that the device is unresponsive, and perform iterative processing on the second recorded traffic. In each iteration, the current second recorded traffic is parsed and randomly deformed to obtain a second attack packet. Then, a third recorded traffic of the to-be-tested Internet of Things terminal device is obtained in real time during playing of the second attack packet. The current third recorded traffic is compared with the current second recorded traffic by the artificial intelligence engine until the current third recorded traffic is consistent with the current second recorded traffic or the number of iterations meets a preset number, and the iterative processing on the second recorded traffic is stopped, so as to complete the wireless security detection of the to-be-tested Internet of Things terminal device. If the current third recorded traffic is consistent with the current second recorded traffic, it is determined that the current second attack packet succeeds in attacking the to-be-tested Internet of Things terminal device, and the current second attack packet and the current third recorded traffic are stored into the vulnerability library.

[0040] As a preferred solution, the wireless security detection system for the Internet of Things terminal device further comprises:

[0041] The third determining module is configured to feed back an abnormal response signal if the analysis result corresponding to the second recorded traffic is that the device cannot be identified, obtain an attack judgment result corresponding to the second recorded traffic uploaded by a researcher, and then transmit the attack judgment result to the artificial intelligence engine, so that the artificial intelligence engine learns and optimizes according to the second recorded traffic and the attack judgment result. When the attack judgment result is that the attack on the to-be-tested Internet of Things terminal device succeeds, the first attack packet and the second recorded traffic are stored into a vulnerability library. When the attack judgment result is that the attack on the to-be-tested Internet of Things terminal device fails, the second recorded traffic is parsed and randomly deformed one or more times to obtain a second attack packet that successfully attacks the to-be-tested Internet of Things terminal device, so as to complete the wireless security detection of the to-be-tested Internet of Things terminal device.

[0042] As a preferred solution, the comparison analysis module specifically comprises:

[0043] The playing recording unit is configured to play the first attack packet in the wireless network and record the output of the protection profile of the to-be-tested Internet of Things terminal device in real time during the playing process to obtain the second recorded traffic of the to-be-tested Internet of Things terminal device.

[0044] The comparison analysis unit is configured to call an adversarial algorithm through the artificial intelligence engine to compare and analyze the second recorded traffic and the first recorded traffic, thereby completing the wireless security detection of the to-be-tested Internet of Things terminal device. BRIEF DESCRIPTION OF DRAWINGS

[0045] Figure 1 FIG. 1 is a flowchart of a wireless security detection method of an Internet of Things terminal device according to an embodiment of the present application.

[0046] Figure 2 FIG. 2 is a structural diagram of a wireless security detection system of an Internet of Things terminal device according to an embodiment of the present application. DETAILED DESCRIPTION

[0047] The technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative labor fall within the scope of protection of the present application.

[0048] Embodiment I:

[0049] Please refer to Figure 1 A wireless security detection method of an Internet of Things terminal device according to an embodiment of the present application is provided, which comprises steps S1 to S3, and each step is specifically as follows.

[0050] Step S1: obtaining the first recorded traffic of the protection profile of the to-be-tested Internet of Things terminal device in a normal communication wireless network environment.

[0051] The protection profile of the to-be-tested Internet of Things terminal device is composed of a plurality of security function components, including but not limited to FDP user data protection, FIA identification and authentication, FPT TSF protection, and FTA TOE access. The above security function components are adopted to focus on the session establishment, identity recognition in the establishment process, access control, and performance after the failure of the to-be-tested Internet of Things terminal device. The functions of the above security function components are specifically as follows.

[0052] 1) FDP user data protection: access control function (FDP_ACC), information flow control function (FDP_IFF);

[0053] 2) FIA class identification and authentication: authentication failure (FIA_AFL);

[0054] 3) FPT class TSF protection: failure protection (FPT_FLS), replay detection (FPT_RPL);

[0055] 4) FTA class TOE access: multiple concurrent session limitation (FTA_MCS), session lock and termination (FTA_SSL), TOE session establishment (FTA_TSE).

[0056] As a preferred solution, the implementation process of step S1 is as shown in step S11, which is specifically as follows:

[0057] In step S11, the tester registers the product and deploys the test environment, that is, the gateway device and the to-be-tested Internet of Things terminal device. When the to-be-tested Internet of Things terminal device operates in a normal communication wireless network environment, the output of the protection profile of the to-be-tested Internet of Things terminal device is recorded in real time to obtain the first recorded traffic corresponding to the to-be-tested Internet of Things terminal device.

[0058] It should be noted that the gateway device is used to communicate with the to-be-tested Internet of Things terminal device. The gateway device includes but is not limited to a Bluetooth gateway, a Zigbee gateway, a Wifi AP, and a 4G / 5G LTE base station. Different gateway devices can be selected for communication according to the communication form of the to-be-tested Internet of Things terminal device.

[0059] In this embodiment, the real-time recording of the output of the protection profile of the to-be-tested Internet of Things terminal device needs to compile full instruction test cases for the communication of the to-be-tested Internet of Things terminal device according to the full text of the communication protocol, so as to form the first recorded traffic corresponding to the to-be-tested Internet of Things terminal device by executing the full instruction test cases.

[0060] In step S2, the first recorded traffic is parsed and randomly deformed to obtain the corresponding first attack packet.

[0061] As a preferred solution, step S2 includes steps S21 to S22, and each step is specifically as follows:

[0062] In step S21, the first recorded traffic is parsed according to the relevant protocol text to decompose the first recorded traffic into each field, so as to obtain the corresponding field string.

[0063] Step S22, input the field string into the artificial intelligence engine, deform the field string randomly through the genetic algorithm of the artificial intelligence engine, and call the test package editor to package the deformation result to obtain the corresponding first attack package.

[0064] In this embodiment, in the random deformation process, the random deformation is performed on each segment and / or boundary value in the field string content on the basis of the normal execution of the function proposed by the protection profile of the to-be-tested Internet of Things terminal device, but the main instruction name is unchanged. Since the instruction name is unchanged, in theory, the normal instruction should obtain normal feedback (i.e., the first recorded traffic obtained in step S1), and the deformed instruction should not obtain the response of the to-be-tested Internet of Things terminal device, or the to-be-tested Internet of Things terminal device will only record logs according to the deformed instruction. If the deformed instruction can obtain normal feedback, it is considered that the attack is successful.

[0065] Step S3, play the first attack package in the wireless network, and obtain the second recorded traffic of the protection profile of the to-be-tested Internet of Things terminal device in real time during the playing process, and then compare and analyze the second recorded traffic and the first recorded traffic through the artificial intelligence engine to complete the wireless security detection of the to-be-tested Internet of Things terminal device.

[0066] It should be noted that the test of the security function component of the protection profile of the to-be-tested Internet of Things terminal device in the embodiment of the application is mainly in the form of black box testing.

[0067] As a preferred solution, step S3 includes steps S31 to S32, and each step is specifically as follows:

[0068] Step S31, send the first attack package to the connection manager through the test package editor, then play the first attack package in the wireless network, and record the output of the protection profile of the to-be-tested Internet of Things terminal device in real time during the playing process to obtain the second recorded traffic of the to-be-tested Internet of Things terminal device.

[0069] Step S32, input the second recorded traffic into the artificial intelligence engine, call the adversarial algorithm through the discriminator of the artificial intelligence engine to compare and analyze the second recorded traffic and the first recorded traffic, and complete the wireless security detection of the to-be-tested Internet of Things terminal device.

[0070] Step S4, if the second recorded traffic is consistent with the first recorded traffic, that is, the to-be-tested Internet of Things terminal device outputs normal feedback to the first attack package, it is judged that the attack of the first attack package on the to-be-tested Internet of Things terminal device is successful, the first attack package is regarded as an attackable input, which can also be called a vulnerability of the to-be-tested Internet of Things terminal device, and the first attack package and the second recorded traffic are stored in the vulnerability library.

[0071] It should be noted that storing the first attack package and the second recorded traffic to the vulnerability library can facilitate subsequent researchers to refine the vulnerability information and develop the current first attack package, and even the current first attack package can be re-imported into the package random transformer of the artificial intelligence engine to continue to deform according to the deformation direction of the first attack package.

[0072] In step S5, if the second recorded traffic is inconsistent with the first recorded traffic and the analysis result corresponding to the second recorded traffic is that the device does not respond, it is judged that the attack of the first attack package on the Internet of Things terminal device under test fails, and the judgment result is fed back to the artificial intelligence engine.

[0073] As a preferred solution, the specific implementation process of step S5 is described with reference to step S51, which is specifically as follows:

[0074] In step S51, if the comparison is inconsistent and the analysis result corresponding to the second recorded traffic is that the device does not respond, it is judged that the attack of the first attack package on the Internet of Things terminal device under test fails, and the second recorded traffic is iteratively processed. In each iteration, the current second recorded traffic is parsed and randomly deformed to obtain a second attack package, and then the third recorded traffic of the Internet of Things terminal device under test is obtained in real time during the playing of the second attack package. The current third recorded traffic is compared and analyzed with the current second recorded traffic by the artificial intelligence engine until the current third recorded traffic is consistent with the current second recorded traffic or the iteration number meets the preset number, and the iteration processing of the second recorded traffic is stopped to complete the wireless security detection of the Internet of Things terminal device under test. If the current third recorded traffic is consistent with the current second recorded traffic, it is judged that the current second attack package successfully attacks the Internet of Things terminal device under test, and the current second attack package is a vulnerability of the Internet of Things terminal device under test. The current second attack package and the current third recorded traffic are stored in the vulnerability library.

[0075] As a preferred solution, the wireless security detection method for the Internet of Things terminal device provided by the embodiment of the present application further includes an artificial judgment process, which includes steps S6 to S8, and each step is specifically as follows:

[0076] In step S6, if the analysis result corresponding to the second recorded traffic is that it cannot be identified, that is, the Internet of Things terminal device under test does not output normal feedback nor no response, but the discriminator of the artificial intelligence engine cannot identify the feedback of the Internet of Things terminal device under test, a non-normal response signal is fed back, the attack judgment result corresponding to the second recorded traffic uploaded by the researcher is obtained, and then the attack judgment result is transmitted to the artificial intelligence engine to enable the artificial intelligence engine to learn and optimize according to the second recorded traffic and the attack judgment result.

[0077] In the embodiment, since the discriminator of the artificial intelligence engine cannot identify the feedback of the to-be-tested Internet of Things terminal device, the artificial judgment mode is switched in, so that the researchers give the attack judgment result corresponding to the second recorded traffic according to the specific situation, and upload the attack judgment result corresponding to the second recorded traffic to the discriminator of the artificial intelligence engine for learning. After the discriminator of the artificial intelligence engine completes the learning of the attack judgment result corresponding to the second recorded traffic, the discriminator of the artificial intelligence engine can identify whether the current second recorded traffic is normal, so as to judge whether the first attack packet attacks the to-be-tested Internet of Things terminal device successfully according to the current second recorded traffic, so as to further improve the vulnerability judgment precision of the discriminator of the artificial intelligence engine. Through continuous testing work, the generator and the discriminator of the artificial intelligence engine can continuously evolve under the guidance of the genetic algorithm, and a large number of test cases and vulnerabilities will also be accumulated.

[0078] Step S7, when the attack judgment result is that the attack on the to-be-tested Internet of Things terminal device is successful, the current first attack packet is a vulnerability of the to-be-tested Internet of Things terminal device, so the first attack packet and the second recorded traffic are stored in the vulnerability library.

[0079] It should be noted that by tracking the vulnerability release of the Internet of Things terminal by the state authority, and verifying, use case development and attack packet development of the vulnerability release, the attack packet that is judged to be successful in attacking the to-be-tested Internet of Things terminal device is regarded as a vulnerability of the to-be-tested Internet of Things terminal device, and is included in the network attack packet library.

[0080] Step S8, when the attack judgment result is that the attack on the to-be-tested Internet of Things terminal device is unsuccessful, the second recorded traffic is parsed and randomly deformed one or more times to obtain a second attack packet that successfully attacks the to-be-tested Internet of Things terminal device, so as to complete the wireless security detection of the to-be-tested Internet of Things terminal device.

[0081] In the embodiment, an Internet of Things terminal wireless security monitoring device is provided, which is installed on a special device. The device supports multiple wireless connection modes, and the whole monitoring device is established on an operating system and a relational database to provide services in a B / S form. The Internet of Things terminal wireless security monitoring device uses the above-mentioned Internet of Things terminal device wireless security detection method to perform wireless security detection on the to-be-tested Internet of Things terminal device. It should be noted that the Internet of Things terminal wireless security monitoring device includes a task manager, a test management module, a use case manager, a device manager, a vulnerability manager, a connection manager, a test packet editor, an artificial intelligence learning engine and a log auditor, and the functions of each device are as follows:

[0082] 1) Task manager: oriented to evaluation institutions or laboratories affiliated to procurement departments, managed in a project manner, and one task can contain wireless security detection of multiple Internet of Things terminal devices;

[0083] 2) Test management module: wireless security detection for a single device, which needs to input device information, use case information and expected detection results of the Internet of Things terminal device, obtain test process data through the connection manager, and draw test conclusions to form a test report;

[0084] 3) Use case manager: for a type of device, the device classification can be classified according to the protection profile proposed by the measured unit, and the use cases are further classified according to the security function components in the protection profile of the Internet of Things terminal device; in addition, the same function components under the same protection profile can share test cases;

[0085] 4) Device manager: for managing a plurality of Internet of Things terminal devices to be tested, and recording and storing device information of each Internet of Things terminal device;

[0086] 5) Vulnerability manager: for encapsulating wireless drivers, which can provide a unified interface for calling by the Internet of Things terminal wireless security monitoring device after encapsulation;

[0087] 6) Connection manager: for building a connection pool for each connection method, which can simulate concurrent traffic according to hardware conditions;

[0088] 7) Test package editor: for providing a plurality of templates to edit and generate network communication packages;

[0089] 8) Artificial intelligence learning engine: encapsulating the adversarial algorithm and genetic algorithm, which can call the test package editor to deform network communication packages / traffic, and evaluate the deformation success rate in combination with the attack results of the test manager, so as to optimize the deformation direction and deformation efficiency;

[0090] 9) Log auditor: for recording and auditing all operation processes and calculation processes of the Internet of Things terminal wireless security monitoring device.

[0091] Please refer to Figure 2 , a structure diagram of an Internet of Things terminal device wireless security detection system provided by the embodiment of the application, the system comprises a traffic acquisition module M1, an analysis deformation module M2, a comparative analysis module M3, a first judgment module M4 and a second judgment module M5, and each module is as follows:

[0092] The traffic acquisition module M1 is used for acquiring first recorded traffic of a protection profile of a measured Internet of Things terminal device in a normal communication wireless network environment; wherein the protection profile of the measured Internet of Things terminal device is composed of a plurality of security function components;

[0093] The analysis deformation module M2 is used for analyzing and randomly deforming the first recorded traffic to obtain corresponding first attack packages;

[0094] The comparative analysis module M3 is configured to play the first attack packet in the wireless network, acquire the second recorded traffic of the protection profile of the to-be-tested Internet of Things terminal device in real time during the playing process, and then compare and analyze the second recorded traffic and the first recorded traffic through the artificial intelligence engine, so as to complete the wireless security detection of the to-be-tested Internet of Things terminal device.

[0095] The first judgment module M4 is configured to judge that the first attack packet succeeds in attacking the to-be-tested Internet of Things terminal device if the second recorded traffic is consistent with the first recorded traffic, and store the first attack packet and the second recorded traffic into the vulnerability library.

[0096] The second judgment module M5 is configured to judge that the first attack packet fails in attacking the to-be-tested Internet of Things terminal device if the second recorded traffic is inconsistent with the first recorded traffic and the analysis result corresponding to the second recorded traffic is that the device is unresponsive.

[0097] As a preferred solution, the second judgment module M5 is further configured to judge that the first attack packet fails in attacking the to-be-tested Internet of Things terminal device if the comparison is inconsistent and the analysis result corresponding to the second recorded traffic is that the device is unresponsive, and perform iterative processing on the second recorded traffic, analyze and randomly deform the current second recorded traffic to obtain a second attack packet each time the iterative processing is performed, acquire third recorded traffic of the to-be-tested Internet of Things terminal device in real time during the playing process of the second attack packet, and compare and analyze the current third recorded traffic and the current second recorded traffic through the artificial intelligence engine until the current third recorded traffic is consistent with the current second recorded traffic or the number of iterations meets a preset number of times, and stop the iterative processing on the second recorded traffic, so as to complete the wireless security detection of the to-be-tested Internet of Things terminal device. If the current third recorded traffic is consistent with the current second recorded traffic, it is judged that the current second attack packet succeeds in attacking the to-be-tested Internet of Things terminal device, and the current second attack packet and the current third recorded traffic are stored into the vulnerability library.

[0098] As a preferred solution, please refer to Figure 2 The system for detecting the wireless security of the Internet of Things terminal device provided by the embodiment of the application further includes a third judgment module M6, which is specifically as follows:

[0099] The third judging module M6 is configured to feed back an abnormal response signal if the analysis result corresponding to the second recorded traffic flow is unrecognizable, obtain an attack judging result corresponding to the second recorded traffic flow uploaded by a researcher, and then transmit the attack judging result to the artificial intelligence engine to enable the artificial intelligence engine to learn and optimize according to the second recorded traffic flow and the attack judging result; when the attack judging result is that the attack on the to-be-tested Internet of Things terminal device is successful, the first attack packet and the second recorded traffic flow are stored in the vulnerability library; when the attack judging result is that the attack on the to-be-tested Internet of Things terminal device is unsuccessful, the second recorded traffic flow is parsed and randomly deformed one or more times to obtain a second attack packet that successfully attacks the to-be-tested Internet of Things terminal device, so as to complete the wireless security detection of the to-be-tested Internet of Things terminal device.

[0100] As a preferred solution, the comparative analysis module M3 specifically includes a playback recording unit 31 and a comparative analysis unit 32, and each unit is specifically as follows:

[0101] The playback recording unit 31 is configured to play the first attack packet in the wireless network, and record the output of the protection profile of the to-be-tested Internet of Things terminal device in real time during the playing process to obtain a second recorded traffic flow of the to-be-tested Internet of Things terminal device.

[0102] The comparative analysis unit 32 is configured to call an adversarial algorithm by the artificial intelligence engine to compare and analyze the second recorded traffic flow and the first recorded traffic flow, and complete the wireless security detection of the to-be-tested Internet of Things terminal device.

[0103] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of the system described above can refer to the corresponding process in the foregoing method embodiments, which will not be described here.

[0104] Compared with the prior art, the embodiments of the present application have the following beneficial effects:

[0105] The application provides a kind of Internet of Things terminal equipment wireless security detection method and system, when the Internet of Things terminal equipment to be measured is in the normal communication wireless network environment, the first recording flow of the Internet of Things terminal equipment to be measured is obtained, then the first attack package obtained by the first recording flow is played in the wireless network, and the second recording flow of the Internet of Things terminal equipment to be measured is obtained in real time during the playing process, so as to compare and analyze the second recording flow and the first recording flow by artificial intelligence engine, judge whether the first attack package attacks the Internet of Things terminal equipment to be measured successfully, and store the first attack package that attacks successfully and the second recording flow of the Internet of Things terminal equipment to be measured when playing the first attack package that attacks successfully into vulnerability library, enrich the attack vulnerability use case of the Internet of Things terminal equipment to be measured, so as to improve the security function component protection capability of the Internet of Things terminal equipment to be measured.In addition, in the normal communication wireless network environment, the first recording flow of each security function component of the Internet of Things terminal equipment to be measured is directly obtained, and the second recording flow of each security function component of the Internet of Things terminal equipment to be measured is directly obtained during the process of playing the first attack package in the wireless network, without being limited by the network processing capacity and data calculation performance of the Internet of Things terminal equipment to be measured, so as to realize wireless security detection of the Internet of Things terminal equipment to be measured while avoiding device dead machine, improve user experience.

[0106] The above specific embodiments further illustrate the purpose, technical solutions and advantages of the application. It should be understood that the above description is only a specific embodiment of the application and is not intended to limit the scope of protection of the application. It should be noted that any modification, equivalent replacement, improvement, etc. made by those skilled in the art within the spirit and principles of the application should be included in the scope of protection of the application.

Claims

1. A wireless security detection method for Internet of Things (IoT) terminal devices, characterized in that, include: Acquire the protection profile of the IoT terminal device under test in the first recorded traffic under normal wireless network communication environment; The first recorded traffic is parsed and randomly transformed to obtain the corresponding first attack packet. Specifically, the first recorded traffic is parsed to obtain the corresponding field string. The field string is randomly deformed using the genetic algorithm of the artificial intelligence engine, and the test package editor is called to assemble the deformed results into packets to obtain the corresponding first attack packet. The first attack packet is played in the wireless network, and the second recorded traffic of the protection profile of the IoT terminal device under test is obtained in real time during the playback. Then, the second recorded traffic is compared and analyzed with the first recorded traffic through an artificial intelligence engine to complete the wireless security detection of the IoT terminal device under test. Specifically, the first attack packet is played in the wireless network, and the output of the protection profile of the IoT terminal device under test is recorded in real time during the playback to obtain the second recorded traffic of the IoT terminal device under test. The artificial intelligence engine is used to invoke adversarial algorithms to compare and analyze the second recorded traffic with the first recorded traffic, thereby completing the wireless security detection of the IoT terminal device under test. If the comparison is consistent, it is determined that the first attack packet successfully attacked the IoT terminal device under test, and the first attack packet and the second recorded traffic are stored in the vulnerability database. If the comparison is inconsistent and the analysis result corresponding to the second recorded traffic is that the device is unresponsive, then it is determined that the first attack packet failed to attack the IoT terminal device under test. The protection profile of the IoT terminal device under test is composed of several security functional components.

2. The wireless security detection method for IoT terminal devices as described in claim 1, characterized in that, Also includes: If the comparison is inconsistent and the analysis result corresponding to the second recorded traffic is that the device is unresponsive, it is determined that the first attack packet has failed to attack the IoT terminal device under test. The second recorded traffic is then iteratively processed. During each iteration, the current second recorded traffic is parsed and randomly transformed to obtain the second attack packet. Then, during the playback of the second attack packet, the third recorded traffic of the IoT terminal device under test is acquired in real time. The current third recorded traffic is compared and analyzed with the current second recorded traffic through the artificial intelligence engine until the current third recorded traffic matches the current second recorded traffic or the number of iterations meets the preset number. The iterative processing of the second recorded traffic is then stopped to complete the wireless security detection of the IoT terminal device under test. If the current third recorded traffic matches the current second recorded traffic, it is determined that the current second attack packet has successfully attacked the IoT terminal device under test, and the current second attack packet and the current third recorded traffic are stored in the vulnerability database.

3. The wireless security detection method for IoT terminal devices as described in claim 1, characterized in that, Also includes: If the analysis result corresponding to the second recorded traffic is unidentifiable, an abnormal response signal is fed back, and the attack judgment result corresponding to the second recorded traffic uploaded by the researchers is obtained. Then, the attack judgment result is transmitted to the artificial intelligence engine so that the artificial intelligence engine can learn and optimize based on the second recorded traffic and the attack judgment result. When the attack determination result indicates that the attack on the IoT terminal device under test is successful, the first attack packet and the second recorded traffic are stored in the vulnerability database. When the attack determination result indicates that the attack on the IoT terminal device under test has failed, the second recorded traffic is parsed and randomly transformed once or multiple times to obtain a second attack packet that successfully attacks the IoT terminal device under test, thereby completing the wireless security detection of the IoT terminal device under test.

4. The wireless security detection method for IoT terminal devices as described in claim 1, characterized in that, The acquisition of the first recorded traffic of the IoT terminal device under test in a normal wireless network environment specifically includes: When the IoT terminal device under test is running in a normal wireless network environment, the output of the protection profile of the IoT terminal device under test is recorded in real time to obtain the first recorded traffic corresponding to the IoT terminal device under test.

5. A wireless security detection system for Internet of Things (IoT) terminal devices, characterized in that, include: The traffic acquisition module is used to acquire the first recorded traffic of the protection profile of the IoT terminal device under test in a normal wireless network environment; wherein, the protection profile of the IoT terminal device under test is composed of several security function components; The parsing and deformation module is used to parse and randomly deform the first recorded traffic to obtain the corresponding first attack packet. Specifically, it parses the first recorded traffic to obtain the corresponding field string; randomly deforms the field string using the genetic algorithm of the artificial intelligence engine; and calls the test packet editor to assemble the deformation results into packets to obtain the corresponding first attack packet. The comparison and analysis module is used to play the first attack packet in the wireless network and, during the playback, acquire the second recorded traffic of the protection profile of the IoT terminal device under test in real time. Then, through an artificial intelligence engine, the second recorded traffic is compared and analyzed with the first recorded traffic to complete the wireless security detection of the IoT terminal device under test. Specifically, the first attack packet is played in the wireless network, and the output of the protection profile of the IoT terminal device under test is recorded in real time during the playback to obtain the second recorded traffic of the IoT terminal device under test; through the artificial intelligence engine, an adversarial algorithm is invoked to compare and analyze the second recorded traffic with the first recorded traffic to complete the wireless security detection of the IoT terminal device under test. The first judgment module is used to determine that the first attack packet has successfully attacked the IoT terminal device under test if the second recorded traffic is consistent with the first recorded traffic, and to store the first attack packet and the second recorded traffic in the vulnerability database. The second judgment module is used to determine that the attack packet's attack on the IoT terminal device under test fails if the second recorded traffic is inconsistent with the first recorded traffic and the analysis result corresponding to the second recorded traffic is that the device is unresponsive.

6. In the wireless security detection system for IoT terminal devices as described in claim 5, the second judgment module is further configured to: if the comparison is inconsistent and the analysis result corresponding to the second recorded traffic is that the device is unresponsive, then determine that the first attack packet has failed to attack the IoT terminal device under test, and perform iterative processing on the second recorded traffic. During each iteration, the current second recorded traffic is parsed and randomly transformed to obtain a second attack packet. Then, while playing the second attack packet, the third recorded traffic of the IoT terminal device under test is acquired in real time, and the current third recorded traffic is compared and analyzed with the current second recorded traffic through the artificial intelligence engine until the current third recorded traffic matches the current second recorded traffic or the number of iterations meets a preset number, at which point the iterative processing of the second recorded traffic is stopped, thereby completing the wireless security detection of the IoT terminal device under test; wherein... If the current third recorded traffic matches the current second recorded traffic, it is determined that the current second attack packet has successfully attacked the IoT terminal device under test, and the current second attack packet and the current third recorded traffic are stored in the vulnerability database.

7. The wireless security detection system for IoT terminal devices as described in claim 5, characterized in that, Also includes: The third judgment module is used to, if the analysis result corresponding to the second recorded traffic is unidentifiable, provide an abnormal response signal, obtain the attack judgment result corresponding to the second recorded traffic uploaded by the researchers, and then transmit the attack judgment result to the artificial intelligence engine so that the artificial intelligence engine can learn and optimize based on the second recorded traffic and the attack judgment result; when the attack judgment result indicates that the attack on the IoT terminal device under test is successful, the first attack packet and the second recorded traffic are stored in the vulnerability database; when the attack judgment result indicates that the attack on the IoT terminal device under test fails, the second recorded traffic is parsed and randomly transformed once or multiple times to obtain a second attack packet that successfully attacks the IoT terminal device under test, thereby completing the wireless security detection of the IoT terminal device under test.

Citation Information

Patent Citations

  • Network security protection method and device based on artificial intelligence, and electronic equipment

    CN111131335A

  • Programmable switching device for network infrastructures

    US20210176125A1