Terminal security monitoring and early warning method, device and equipment based on 5g internet of things, and medium

By actively and passively monitoring IoT terminals that are not connected to or are connected to 5G networks, and combining scanning strategies and network attack monitoring, the problem of timely detection of security risks of IoT terminals in 5G scenarios is solved, and the security and stability of terminals are improved.

CN117014879BActive Publication Date: 2026-05-22E SURFING IOT CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
E SURFING IOT CO LTD
Filing Date
2023-08-08
Publication Date
2026-05-22

AI Technical Summary

Technical Problem

In 5G scenarios, security risks of IoT terminals are difficult to detect in a timely manner, resulting in poor security stability and an inability to provide timely warnings.

Method used

By combining proactive and passive security monitoring, we can comprehensively identify IoT terminals that are not connected to or connected to 5G networks. By utilizing configured scanning strategies, malicious program propagation monitoring, and network attack monitoring methods, we can obtain monitoring results and issue early warnings.

Benefits of technology

It enables comprehensive security monitoring of IoT terminals, timely detection of vulnerabilities, and improved security and stability of terminals.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117014879B_ABST
    Figure CN117014879B_ABST
Patent Text Reader

Abstract

Embodiments of the present application disclose a terminal security monitoring and early warning method and device based on 5G Internet of Things, equipment and medium. The method belongs to the technical field of Internet of Things, which comprises: if it is detected that a to-be-tested terminal has not accessed a 5G network and meets a security monitoring condition, then based on a configured scanning strategy, active security monitoring is performed on the to-be-tested terminal to obtain a non-access monitoring result; if it is detected that the to-be-tested terminal has accessed the 5G network and received service data collected and sent by a 5G Internet of Things data collection device, then through a harmful program propagation monitoring method and a network attack monitoring method, passive monitoring is performed on the service data to obtain an access monitoring result; and according to the non-access monitoring result and the access monitoring result, the security of the to-be-tested terminal is warned. Through the combination of active monitoring and passive monitoring, the embodiments of the present application can comprehensively identify and warn the security of Internet of Things terminals, discover the self-vulnerability of the Internet of Things terminals in time, and improve the security and stability of the Internet of Things terminals.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of Internet of Things (IoT) technology, and in particular to a method, apparatus, device, and medium for terminal security monitoring and early warning based on 5G IoT. Background Technology

[0002] With the development of technology, traditional communication technology can no longer meet people's communication needs. 5G technology not only provides faster speeds, lower latency and greater network capacity, but also opens the door to connecting everything and realizing the Internet of Things. The scale of IoT terminals is also constantly expanding.

[0003] As a result, IoT terminal security incidents are occurring frequently, affecting not only the security and stability of application services but also posing security threats to the nation, society, and individuals. Therefore, the secure and stable operation of IoT terminals in 5G scenarios is particularly important. However, currently, in 5G scenarios, it is not possible to detect IoT terminal security risks in a timely manner or provide timely warnings, resulting in relatively poor security and stability of IoT terminals. Summary of the Invention

[0004] This invention provides a method, device, equipment, and medium for terminal security monitoring and early warning based on 5G Internet of Things (IoT), aiming to improve the security and stability of IoT terminals.

[0005] In a first aspect, embodiments of the present invention provide a terminal security monitoring and early warning method based on 5G Internet of Things, comprising:

[0006] If it is detected that the terminal under test is not connected to the 5G network and meets the security monitoring conditions, then the terminal under test is actively monitored for security based on the configured scanning strategy to obtain the non-connection monitoring result.

[0007] If it is detected that the terminal under test has accessed the 5G network and received service data collected and sent by the 5G IoT data acquisition device, the access monitoring result is obtained by passively monitoring the service data through malicious program propagation monitoring method and network attack monitoring method.

[0008] The security of the terminal under test is warned based on the non-access monitoring results and the access monitoring results.

[0009] Secondly, embodiments of the present invention also provide a terminal security monitoring and early warning device based on 5G Internet of Things, comprising:

[0010] The first monitoring unit is used to perform active security monitoring on the terminal under test based on the configured scanning strategy to obtain the non-access monitoring result if it is detected that the terminal under test is not connected to the 5G network and meets the security monitoring conditions.

[0011] The second monitoring unit is used to passively monitor the service data and obtain access monitoring results by means of malicious program propagation monitoring method and network attack monitoring method if it is detected that the terminal under test has accessed the 5G network and received service data collected and sent by the 5G Internet of Things data acquisition device.

[0012] The early warning unit is used to issue an early warning on the security of the terminal under test based on the non-access monitoring results and the access monitoring results.

[0013] Thirdly, embodiments of the present invention also provide a computer device, which includes a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the above-described method.

[0014] Fourthly, embodiments of the present invention also provide a computer-readable storage medium storing a computer program that, when executed by a processor, can implement the above-described method.

[0015] This invention provides a method, apparatus, device, and medium for terminal security monitoring and early warning based on 5G IoT. The method includes: if a terminal under test is detected not connected to the 5G network and meets security monitoring conditions, then actively monitors the terminal under test based on a configured scanning strategy to obtain a non-connection monitoring result; if the terminal under test is detected connected to the 5G network and receives service data collected and sent by a 5G IoT data acquisition device, then passively monitors the service data using a malicious program propagation monitoring method and a network attack monitoring method to obtain an access monitoring result; and provides an early warning on the security of the terminal under test based on the non-connection monitoring result and the access monitoring result. This invention, by combining active monitoring when not connected to the 5G network with passive monitoring when connected to the 5G network, can comprehensively identify and warn of the security of IoT terminals, promptly discover vulnerabilities in IoT terminals, and improve the security stability of IoT terminals. Attached Figure Description

[0016] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the following description of the embodiments will be briefly introduced. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0017] Figure 1 A flowchart illustrating a terminal security monitoring and early warning method based on 5G Internet of Things provided in an embodiment of the present invention;

[0018] Figure 2A schematic diagram illustrating the security of an active detection terminal based on 5G Internet of Things, provided as an embodiment of the present invention;

[0019] Figure 3 This is a schematic diagram illustrating the conversion of 5G HE AV to 5G AV in an embodiment of the present invention;

[0020] Figure 4 A schematic diagram illustrating the security of a passive detection terminal based on 5G Internet of Things, provided as an embodiment of the present invention;

[0021] Figure 5 This is a schematic diagram illustrating the intrusion rule detection model, MD5 detection model, and sandbox malware detection model obtained by analyzing the initial intrusion rule detection model, initial MD5 detection model, and initial sandbox malware detection model in an embodiment of the present invention.

[0022] Figure 6 A schematic block diagram of a terminal security monitoring and early warning device based on 5G Internet of Things provided in an embodiment of the present invention;

[0023] Figure 7 This is a schematic block diagram of a computer device provided in an embodiment of the present invention. Detailed Implementation

[0024] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0025] It should be understood that, when used in this specification and the appended claims, the terms "comprising" and "including" indicate the presence of the described features, integrals, steps, operations, elements and / or components, but do not exclude the presence or addition of one or more other features, integrals, steps, operations, elements, components and / or collections thereof.

[0026] It should also be understood that the terminology used in this specification is for the purpose of describing particular embodiments only and is not intended to limit the invention. As used in this specification and the appended claims, the singular forms “a,” “an,” and “the” are intended to include the plural forms unless the context clearly indicates otherwise.

[0027] It should also be further understood that the term "and / or" as used in this specification and the appended claims refers to any combination of one or more of the associated listed items and all possible combinations, and includes such combinations.

[0028] As used in this specification and the appended claims, the term "if" may be interpreted, depending on the context, as "when," "once," "in response to determination," or "in response to detection." Similarly, the phrase "if determined" or "if [the described condition or event] is detected" may be interpreted, depending on the context, as "once determined," "in response to determination," "once [the described condition or event] is detected," or "in response to detection of [the described condition or event]."

[0029] Please see Figure 1 , Figure 1 This is a flowchart illustrating a terminal security monitoring and early warning method based on 5G IoT provided in an embodiment of the present invention. The terminal security monitoring and early warning method based on 5G IoT of this embodiment can be applied to 5G IoT platforms. For example, it can be implemented through software programs configured on a 5G IoT platform to promptly detect vulnerabilities in IoT terminals, thereby improving the security and stability of IoT terminals. Figure 1 As shown, the method includes the following steps S100-S120.

[0030] S100. If it is detected that the terminal under test is not connected to the 5G network and meets the security monitoring conditions, then the terminal under test is actively monitored for security based on the configured scanning strategy to obtain the non-connection monitoring result.

[0031] In this embodiment of the invention, if it is detected that the terminal under test is not connected to the 5G network, such as Figure 2 As shown, Figure 2This invention provides a schematic diagram of proactive terminal security detection based on 5G IoT. The process of proactively detecting terminal security specifically includes the following steps: Step 1: Configure a dedicated safeDNN (safe Data Network Name) for security monitoring through UDM (Unified Data Management), SMF (Session Management Function), and UPF (User Plane Function); Step 2: Batch sign up safeDNNs for IoT cards in the terminal under test; Step 3: The security scanning server can access the IoT 5G network through a 5G CPE (a type of 5G terminal device), and the IoT cards in the 5G CPE sign up safeDNNs; Step 4: The terminal under test re-initiates a registration request and selects the corresponding AMF (Access and Mobility Management Function) through the base station; Step 5: AMF communicates with ASF (Authentication Server). The authentication server (AMF) completes bidirectional authentication between the terminal under test and the network, and obtains mobility subscription data and registration from the UDM; Step 6: The AMF sends a registration acceptance request to the terminal under test; Step 7: The terminal under test initiates a session establishment request to the SMF to obtain relevant data such as safeDNN and TAI; Step 8: The SMF obtains session subscription data from the UDM and registers with the UDM; Step 9: The SMF obtains user policy subscription information from the PCF; Step 10: The SMF establishes a session request to the UPF and assigns the same segment of private network IP (as shown in the figure, the 10.0.0.X segment); Step 11: The security scanning server configures scanning policies to discover terminal security issues from aspects such as device firmware, vulnerability mining, protocol analysis, and cloud security, playing a preventive role.

[0032] Further, step 5 specifically includes: step 51, authentication initialization and authentication method selection process; specifically, (1) the terminal under test reports SUCI (Subscription Concealed Identifier) ​​or 5G-GUTI (Globally Unique Temporary UE Identity) to SEAF (Security Anchor Function), which is used by SEAF to create a unified anchor key for UE authentication and communication protection in the network; (2) SEAF sends Nausf_UE Authentication_Authenticate Request message to AUSF to inform AUSF that the terminal needs to make an authentication request; (3) after receiving the message, AUSF compares whether the expected network service name is consistent with the name reported by SEAF. If they are consistent, it will send Nudm_UEAuthentication_Get Request message to UDM. If they are inconsistent, AUSF will return "Unauthorized Service Network" to SEAF and end the process; (4) after AUSF successfully verifies, it sends Nudm_UEAuthentication_Get The Request message is sent to the UDM. After receiving the message, the UDM calls the SIDF (Subscription Identifier De-concealing Function) to de-conceal the SUCI and obtain the SUPI. Based on the obtained SUPI (Subscription Permanent Identifier), the UDM / ARPF (Authentication Credential Repository and Processing Function) selects the final authentication method, and finally selects the AKA authentication method.

[0033] Step 52, 5G AKA process; specifically, (1) for each Nudm_Authenticate_Get Request message, UDM / ARPF will generate a 5G HE AV, such as Figure 3 As shown, Figure 3This is a schematic diagram of the conversion of 5G HE AV to 5G AV in an embodiment of the present invention. The vector consists of four parts: random number RAND, AUTN, authentication information XRES*, and Kausf; (2) UDM returns 5G HE AV and SUPI (Subscription Permanent Identifier) ​​information to AUSF; (3) AUSF keeps XRES* in the 5G vector locally and generates HXRES* using the SHA256 algorithm to generate a new 5G AV, which consists of the quadruple tuple of RAND, AUTN, HXRES*, and Kseaf; (4) After AUSF deletes Kseaf, it returns 5G SE AV (RAND, AUTN, HXRES*) to SEAF. SEAF sends RAND and AUTN information to the terminal under test through NAS authentication message; (5) After receiving RAND and AUTN information, USIM verifies 5G. If the AV is valid, the USIM calculates RES, CK, and IK using the long-term K and RAND in the 5G core network and returns this information to the terminal under test. The ME calculates RES* and Kseaf based on the above information. (6) The terminal under test returns RES* to SEAF in the NAS authentication response message. After obtaining it, SEAF calculates HRES* and compares HRES* with HXRES* to see if they are consistent. If they are consistent, subsequent verification is performed; otherwise, authentication fails. (7) If authentication is successful, SEAF sends the RES* returned by the terminal under test to AUSF. AUSF completes the second authentication. AUSF compares the RES* of the UE with the XRES* stored locally in AUSF. If they are consistent, authentication is successful; otherwise, authentication fails.

[0034] Furthermore, meeting the security monitoring conditions specifically includes: obtaining the private network IP and security data network identifier of the terminal under test; comparing whether the private network IP of the terminal under test is consistent with the pre-assigned private network IP; if they are consistent, then comparing whether the security data network identifier of the terminal under test is consistent with the pre-assigned security data network identifier; if they are consistent, then it is determined that the security monitoring conditions are met. Understandably, if the private network IP of the terminal under test is inconsistent with the pre-assigned private network IP, or if the security data network identifier of the terminal under test is inconsistent with the pre-assigned security data network identifier, then it will be determined that the security monitoring conditions are not met. It should be noted that in this embodiment, the pre-assigned private network IP and the pre-assigned security data network identifier are both private network IPs and security data network identifiers in the security scanning server.

[0035] Furthermore, the security scanning server proactively monitors the firmware, vulnerabilities, protocols, and cloud security of the terminal under test using configured device firmware monitoring methods, vulnerability discovery methods, protocol analysis methods, and cloud security methods to obtain unconnected monitoring results. It should be noted that the device firmware monitoring methods, vulnerability discovery methods, protocol analysis methods, and cloud security methods are all existing methods and will not be elaborated upon here for simplicity. It should also be noted that in this embodiment, a dedicated safeDNN for security monitoring is configured based on the 5G core network through UDM, SMF, and UPF, enabling the terminal under test to detect risks related to device firmware, vulnerability discovery, protocol analysis, and cloud security as early as possible before accessing the network.

[0036] S110. If it is detected that the terminal under test has accessed the 5G network and received service data collected and sent by the 5G IoT data acquisition device, then the access monitoring result is obtained by passively monitoring the service data through the malicious program propagation monitoring method and the network attack monitoring method.

[0037] In this embodiment of the invention, if it is detected that the terminal under test has accessed the 5G network, such as Figure 4 As shown, Figure 4 This illustration provides a security diagram for a passive detection terminal based on 5G IoT, as provided in an embodiment of the present invention. It describes how a 5G IoT service usage data acquisition device (i.e., a 5G IoT data acquisition device) acquires IoT-related service usage data, parses, segments, and processes the usage data to generate traffic session data, a restoration program file, and session records at each layer. The session records at each layer include transport layer and application layer session records. Understandably, the service data includes traffic session data, the restoration program file, and session records. The IoT platform monitors the traffic session data, the restoration program file, and the session records using any one of the following detection methods: malicious IP detection, malicious URL detection, malicious domain name detection, web attack detection, scanning and detection, and vulnerability exploitation detection, to obtain network attack monitoring results. It also monitors the traffic session data, the restoration program file, and the session records using any one of the following detection models: intrusion rule detection model, virus database-based MD5 detection model, and sandbox malware detection model, to obtain malicious program propagation monitoring results. The network attack monitoring results and the malicious program propagation monitoring results are used as the access monitoring results.

[0038] Furthermore, the intrusion rule detection model, the virus database-based MD5 detection model, and the sandbox malware detection model are obtained by analyzing the initial intrusion rule detection model, the initial MD5 detection model, and the initial sandbox malware detection model using suspected virus samples. Specifically, as... Figure 5 As shown, Figure 5 This is a schematic diagram illustrating the analysis of the initial intrusion rule detection model, initial MD5 detection model, and initial sandbox malware detection model in this embodiment of the invention. Suspected virus samples are collected and matched against a preset malware database. If a suspected virus sample matches the preset malware database, it is preprocessed to obtain a virus sample. Preprocessing includes deduplication and removal of virus samples with incomplete features. Understandably, if a suspected virus sample does not match the preset malware database, it indicates that the suspected virus sample is in a whitelist, and no further processing is required; the process ends there. The virus sample is then used to analyze the initial intrusion rule detection model and the initial MD5 detection model. The detection model and the initial sandbox malware detection model are analyzed to obtain intrusion rule reports and prevention strategies, MD5 detection reports and prevention strategies, and sandbox malware detection reports and prevention strategies. Specifically, the initial intrusion rule detection model and the initial MD5 detection model are statically analyzed using the virus sample to obtain intrusion rule reports and prevention strategies, and MD5 detection reports and prevention strategies; the initial sandbox malware detection model is dynamically sandboxed using the virus sample to obtain sandbox malware detection reports and prevention strategies; the virus sample is renamed and added to the preset malware database to obtain the intrusion rule detection model, the virus database-based MD5 detection model, and the sandbox malware detection model.

[0039] It should be noted that in this embodiment, by deploying 5G IoT data acquisition equipment to collect data from the security risk detection equipment in the associated IoT platform, malicious program propagation events and network attack events can be detected in a timely manner, thereby improving the security and stability of IoT terminals.

[0040] S120. Issue a security warning for the terminal under test based on the non-access monitoring results and the access monitoring results.

[0041] In this embodiment of the invention, if both the non-access monitoring result and the access monitoring result indicate that there are no security risks, it means that the terminal under test is relatively safe and no security warning is required; if the non-access monitoring result and / or the access monitoring result indicate that there are security risks, it means that the terminal under test has security risks and a security warning is required.

[0042] Figure 6 This is a schematic block diagram of a terminal security monitoring and early warning device 200 based on 5G Internet of Things provided in an embodiment of the present invention. Figure 6 As shown, corresponding to the above-described terminal security monitoring and early warning method based on 5G IoT, the present invention also provides a terminal security monitoring and early warning device 200 based on 5G IoT. This terminal security monitoring and early warning device 200 based on 5G IoT includes units for executing the above-described terminal security monitoring and early warning method based on 5G IoT. Specifically, please refer to... Figure 6 The 5G IoT-based terminal security monitoring and early warning device 200 includes a first monitoring unit 201, a second monitoring unit 202, and an early warning unit 203.

[0043] The first monitoring unit 201 is configured to perform active security monitoring on the terminal under test based on a configured scanning strategy to obtain a non-access monitoring result if it detects that the terminal under test has not accessed the 5G network and meets the security monitoring conditions; the second monitoring unit 202 is configured to perform passive monitoring on the service data through malicious program propagation monitoring methods and network attack monitoring methods to obtain an access monitoring result if it detects that the terminal under test has accessed the 5G network and received service data collected and sent by the 5G IoT data acquisition device; and the early warning unit 203 is configured to issue an early warning on the security of the terminal under test based on the non-access monitoring result and the access monitoring result.

[0044] In some embodiments, such as this one, the first monitoring unit 201 includes an acquisition unit, a determination unit, and a first monitoring subunit.

[0045] The acquisition unit is used to acquire the private network IP and security data network identifier of the terminal under test; the determination unit is used to determine that the security monitoring conditions are met if the private network IP is consistent with the pre-assigned private network IP and the security data network identifier is consistent with the pre-assigned security data network identifier; the first monitoring subunit is used to actively monitor the firmware, vulnerabilities, protocols and cloud security of the terminal under test according to the configured device firmware monitoring method, vulnerability mining method, protocol analysis method and cloud security method to obtain the non-access monitoring result.

[0046] In some embodiments, such as this one, the second monitoring unit 202 includes a second monitoring subunit, a third monitoring subunit, and a monitoring unit.

[0047] The second monitoring subunit is used to monitor the traffic session data, the restore program file, and the session records using any one of the following detection methods: malicious IP detection, malicious URL detection, malicious domain name detection, web attack detection, scanning detection, and vulnerability exploitation detection, to obtain network attack monitoring results. The third monitoring subunit is used to monitor the traffic session data, the restore program file, and the session records using any one of the following detection models: intrusion rule detection model, virus database-based MD5 detection model, and sandbox malware detection model, to obtain malicious program propagation monitoring results. The receiving unit is used to receive the network attack monitoring results and the malicious program propagation monitoring results as the access monitoring results.

[0048] In some embodiments, such as this one, the 5G IoT-based terminal security monitoring and early warning device 200 further includes an analysis unit.

[0049] The analysis unit is used to analyze the initial intrusion rule detection model, the initial MD5 detection model based on the virus database, and the initial sandbox malware detection model using suspected virus samples.

[0050] In some embodiments, such as this one, the analysis unit includes an acquisition unit, a preprocessing unit, a first analysis subunit, and an addition unit.

[0051] The acquisition unit is used to acquire suspected virus samples and match them with a preset malware database. The preprocessing unit is used to preprocess the suspected virus samples to obtain virus samples if they match the preset malware database. The first analysis subunit is used to analyze the initial intrusion rule detection model, the initial MD5 detection model, and the initial sandbox malware detection model using the virus samples to obtain intrusion rule reports and prevention strategies, MD5 detection reports and prevention strategies, and sandbox malware detection reports and prevention strategies. The adding unit is used to rename the virus samples and add the renamed virus samples to the preset malware database to obtain the intrusion rule detection model, the virus database-based MD5 detection model, and the sandbox malware detection model.

[0052] In some embodiments, such as this one, the first analysis subunit includes a second analysis subunit and a third analysis subunit.

[0053] The second analysis subunit is used to perform static analysis on the initial intrusion rule detection model and the initial MD5 detection model using the virus sample to obtain an intrusion rule report and prevention strategy, and an MD5 detection report and prevention strategy; the third analysis subunit is used to perform dynamic sandbox analysis on the initial sandbox malware detection model using the virus sample to obtain a sandbox malware detection report and prevention strategy.

[0054] It should be noted that those skilled in the art can clearly understand that the specific implementation process of the above-mentioned 5G IoT-based terminal security monitoring and early warning device 200 and its various units can be referred to the corresponding descriptions in the foregoing method embodiments. For the sake of convenience and brevity, these details will not be repeated here.

[0055] The aforementioned 5G IoT-based terminal security monitoring and early warning device can be implemented as a computer program, which can, for example... Figure 7 It runs on the computer device shown.

[0056] Please see Figure 7 , Figure 7 This is a schematic block diagram of a computer device provided in an embodiment of this application. The computer device 900 is a device equipped with an Internet of Things (IoT) platform.

[0057] See Figure 7 The computer device 900 includes a processor 902, a memory, and an interface 907 connected via a system bus 901, wherein the memory may include a storage medium 903 and internal memory 904.

[0058] The storage medium 903 can store an operating system 9031 and a computer program 9032. When the computer program 9032 is executed, it enables the processor 902 to execute a terminal security monitoring and early warning method based on 5G Internet of Things.

[0059] The processor 902 provides computing and control capabilities to support the operation of the entire computer device 900.

[0060] The internal memory 904 provides an environment for the computer program 9032 in the storage medium 903 to run. When the computer program 9032 is executed by the processor 902, the processor 902 can execute a terminal security monitoring and early warning method based on 5G Internet of Things.

[0061] This interface 905 is used for communication with other devices. Those skilled in the art will understand that... Figure 7The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device 900 to which the present application is applied. The specific computer device 900 may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.

[0062] The processor 902 is used to run a computer program 9032 stored in a memory to implement any embodiment of the above-described terminal security monitoring and early warning method based on 5G Internet of Things.

[0063] It should be understood that in the embodiments of this application, the processor 902 may be a central processing unit (CPU), or it may be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor.

[0064] It will be understood by those skilled in the art that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a storage medium, which is a computer-readable storage medium. The computer program is executed by at least one processor in the wireless communication system to implement the process steps of the embodiments of the above methods.

[0065] Therefore, the present invention also provides a storage medium. This storage medium can be a computer-readable storage medium. The storage medium stores a computer program. When executed by a processor, the computer program causes the processor to perform any of the embodiments of the above-described terminal security monitoring and early warning method based on 5G Internet of Things.

[0066] The storage medium can be any computer-readable storage medium capable of storing program code, such as a USB flash drive, portable hard drive, read-only memory (ROM), magnetic disk, or optical disk.

[0067] In the several embodiments provided by this invention, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative. For example, the division of each unit is merely a logical functional division, and there may be other division methods in actual implementation. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed.

[0068] The steps in the method of this invention can be adjusted, merged, or reduced in order according to actual needs. The units in the device of this invention can be merged, divided, or reduced according to actual needs. Furthermore, the functional units in the various embodiments of this invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.

[0069] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This wireless communication software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal wireless communication device, a terminal, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention.

[0070] In the above embodiments, the descriptions of each embodiment have different focuses. For parts that are not described in detail in a certain embodiment, please refer to the relevant descriptions in other embodiments.

[0071] Obviously, those skilled in the art can make various modifications and variations to this invention without departing from its spirit and scope. Since these modifications and variations fall within the scope of the claims and their equivalents, this invention also intends to include these modifications and variations.

[0072] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in the present invention, and these modifications or substitutions should all be covered within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.

Claims

1. A terminal security monitoring and early warning method based on 5G Internet of Things, characterized in that, include: If it is detected that the terminal under test is not connected to the 5G network and meets the security monitoring conditions, then the terminal under test is actively monitored for security based on the configured scanning strategy to obtain the non-connection monitoring result. If it is detected that the terminal under test has accessed the 5G network and received service data collected and sent by the 5G IoT data acquisition device, the access monitoring result is obtained by passively monitoring the service data through malicious program propagation monitoring method and network attack monitoring method. The security of the terminal under test is warned based on the non-access monitoring results and the access monitoring results; The conditions for meeting safety monitoring include: Obtain the private network IP and secure data network identifier of the terminal under test; If the private network IP is the same as the pre-assigned private network IP and the security data network identifier is the same as the pre-assigned security data network identifier, then the security monitoring conditions are met. The active security monitoring of the terminal under test based on the configured scanning strategy to obtain the non-access monitoring result includes: Based on the configured device firmware monitoring method, vulnerability mining method, protocol analysis method, and cloud security method, proactive security monitoring is performed on the firmware, vulnerabilities, protocols, and cloud security of the terminal under test to obtain the unconnected monitoring results. The business data includes traffic session data, restoration program files, and session records; the passive monitoring of the business data using malicious program propagation monitoring methods and network attack monitoring methods to obtain access monitoring results includes: The network attack monitoring results are obtained by monitoring the traffic session data, the restoration program file, and the session records using any one of the following detection methods: malicious IP detection, malicious URL detection, malicious domain name detection, web attack detection, scanning and detection, and vulnerability exploitation detection. The traffic session data, the restoration program file, and the session records are monitored for network worms, Trojans, and mobile malware using any one of the following detection models: intrusion rule detection model, virus database-based MD5 detection model, and sandbox malware detection model. The results of the monitoring are obtained. The network attack monitoring results and the malicious program propagation monitoring results are used as the access monitoring results.

2. The terminal security monitoring and early warning method based on 5G Internet of Things according to claim 1, characterized in that, The method further includes: The intrusion rule detection model, the virus database-based MD5 detection model, and the sandbox malware detection model are obtained by analyzing the initial intrusion rule detection model, the initial MD5 detection model, and the initial sandbox malware detection model using suspected virus samples.

3. The terminal security monitoring and early warning method based on 5G Internet of Things according to claim 2, characterized in that, The intrusion rule detection model, the virus database-based MD5 detection model, and the sandbox malware detection model are obtained by analyzing suspected virus samples against the initial intrusion rule detection model, the initial MD5 detection model, and the initial sandbox malware detection model, including: Collect suspected virus samples and match them with a preset malware database; If the suspected virus sample matches the preset malware database, the suspected virus sample is preprocessed to obtain a virus sample. Using the virus samples, the initial intrusion rule detection model, the initial MD5 detection model, and the initial sandbox malware detection model are analyzed to obtain intrusion rule reports and prevention strategies, MD5 detection reports and prevention strategies, and sandbox malware detection reports and prevention strategies; The virus sample is renamed and added to the preset malware database to obtain the intrusion rule detection model, the virus database-based MD5 detection model, and the sandbox malware detection model.

4. The terminal security monitoring and early warning method based on 5G Internet of Things according to claim 3, characterized in that, The process of analyzing the initial intrusion rule detection model, initial MD5 detection model, and initial sandbox malware detection model using the virus sample to obtain intrusion rule reports and prevention strategies, MD5 detection reports and prevention strategies, and sandbox malware detection reports and prevention strategies includes: Static analysis of the initial intrusion rule detection model and the initial MD5 detection model using the virus samples yields intrusion rule reports and prevention strategies, as well as MD5 detection reports and prevention strategies. The virus samples were used to perform dynamic sandbox analysis on the initial sandbox malware detection model to obtain a sandbox malware detection report and prevention strategies.

5. A terminal security monitoring and early warning device based on 5G Internet of Things, characterized in that, include: The first monitoring unit is used to perform active security monitoring on the terminal under test based on the configured scanning strategy to obtain the non-access monitoring result if it is detected that the terminal under test is not connected to the 5G network and meets the security monitoring conditions. The second monitoring unit is used to passively monitor the service data and obtain access monitoring results by means of malicious program propagation monitoring method and network attack monitoring method if it is detected that the terminal under test has accessed the 5G network and received service data collected and sent by the 5G Internet of Things data acquisition device. The early warning unit is used to issue an early warning regarding the security of the terminal under test based on the non-access monitoring results and the access monitoring results; The first monitoring unit includes: The acquisition unit is used to acquire the private network IP and secure data network identifier of the terminal under test; The determination unit is used to determine that the security monitoring conditions are met if the private network IP is consistent with the pre-allocated private network IP and the security data network identifier is consistent with the pre-allocated security data network identifier. The first monitoring subunit is used to perform proactive security monitoring on the firmware, vulnerabilities, protocols, and cloud security of the terminal under test according to the configured device firmware monitoring method, vulnerability mining method, protocol analysis method, and cloud security method to obtain the non-access monitoring result. The business data includes traffic session data, recovery program files, and session records; the second monitoring unit includes: The second monitoring subunit is used to monitor the traffic session data, the restoration program file, and the session records using any one of the following detection methods: malicious IP detection, malicious URL detection, malicious domain name detection, web attack detection, scanning detection, and vulnerability exploitation detection, to obtain network attack monitoring results. The third monitoring subunit is used to monitor the traffic session data, the restore program file, and the session records for network worms, Trojans, and mobile malware by any one of the following detection models: intrusion rule detection model, virus database-based MD5 detection model, and sandbox malware detection model, to obtain the harmful program propagation monitoring results. As a unit, it is used to use the network attack monitoring results and the malicious program propagation monitoring results as the access monitoring results.

6. A computer device, characterized in that, The computer device is equipped with an Internet of Things (IoT) platform. The computer device includes a memory and a processor. The memory stores a computer program. When the processor executes the computer program, it implements the method as described in any one of claims 1-4.

7. A computer-readable storage medium, characterized in that, The storage medium stores a computer program that, when executed by a processor, can implement the method as described in any one of claims 1-4.