A big data security protection method and system for the Internet of Things
By establishing an attack correlation map and encrypted data processing methods, identifying and responding to the abnormal behavior of IoT terminals, the problem of low reliability of IoT big data security protection is solved, and efficient abnormal identification and data protection is achieved.
Patent Information
- Application Number
- CN202410754893.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-06-12
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2044-06-12
AI Technical Summary
In the prior art, the security protection of IoT big data is not reliable, and it is difficult to effectively identify and deal with abnormal IoT terminals and abnormal data query behaviors.
By establishing an attack association map, the association relationship between multiple IoT terminals under multiple attack modes is recorded, and abnormal IoT terminals and data query terminals are identified based on the data collection and query behavior of IoT terminals. At the same time, the data of non-abnormal IoT terminals are encrypted and closely divided and randomly spliced to reduce the risk of data leakage.
It improves the security protection reliability of IoT big data, effectively identifies and deals with abnormal IoT terminals and data query behaviors, reduces the risk of data leakage, and improves the anonymity of data.
Smart Images

Figure CN118779908B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data processing, and in particular to a big data security protection method and system for the Internet of Things. Background Art
[0002] The Internet of Things is a network that connects any object to the Internet through information sensing devices and in accordance with agreed protocols to exchange and communicate information, so as to achieve intelligent identification, positioning, tracking, monitoring and management. In layman's terms, the Internet of Things is "the Internet of Things connected to everything", which has two meanings: first, the Internet of Things is an extension and expansion of the Internet, and its core and foundation is still the Internet; second, the user end of the Internet of Things includes not only people, but also objects. The Internet of Things realizes the exchange and communication of information between people and objects, and between objects.
[0003] In many applications of the Internet of Things, a lot of data is generally generated through Internet of Things terminal devices. These massive amounts of data generally have high application value. Therefore, access protection is required. However, in the existing technology, there is a problem of low reliability of security protection.
[0004] Therefore, it is necessary to provide a big data security protection method and system for the Internet of Things to improve the security protection reliability of big data in the Internet of Things. Summary of the invention
[0005] The present invention provides a big data security protection system for the Internet of Things, comprising: a data acquisition module, comprising a plurality of Internet of Things terminals, wherein the Internet of Things terminals include at least one sensor; an abnormality identification module, used to establish an attack association map, wherein the attack association map is used to record the association relationship between the plurality of Internet of Things terminals under a plurality of attack modes, and is also used to identify whether the Internet of Things terminal is an abnormal Internet of Things terminal based on data reported by the Internet of Things terminal at a plurality of time points in a current data acquisition cycle and the attack association map, and is also used to generate a first warning message based on the identified abnormal Internet of Things terminal; a data storage module, used to collect data from the plurality of Internet of Things terminals based on the identification result of the abnormal Internet of Things terminal The data of the set is encrypted and then processed for storage; a data query module includes multiple data query terminals; a query response module is used to receive a data query request initiated by the data query terminal, and based on the historical data query requests of the data query terminal, determine whether the current query behavior of the data query terminal is an abnormal query behavior, and is also used to authenticate the data query terminal when it is determined that the current query behavior of the data query terminal is an abnormal query behavior, and based on the identity authentication result, determine whether the data query terminal is an abnormal data query terminal, and is also used to retrieve target data corresponding to the data query request initiated by the data query terminal when it is determined that the data query terminal is not an abnormal data query terminal.
[0006] Furthermore, the anomaly identification module establishes the attack association map, including: obtaining historical attack data of the multiple Internet of Things terminals; obtaining test attack data of the multiple Internet of Things terminals; calculating attack association parameters of any two of the Internet of Things terminals in each attack mode based on the historical attack data and test attack data of the multiple Internet of Things terminals; and establishing the attack association map based on the attack association parameters of any two of the Internet of Things terminals in each attack mode.
[0007] Further, the abnormality identification module includes multiple abnormality identification units; the abnormality identification module identifies whether the Internet of Things terminal is an abnormal Internet of Things terminal based on the data reported by the Internet of Things terminal at multiple time points in the current data collection cycle and the attack association map, including: determining multiple optimal abnormality identification units based on the operation parameter information of the multiple abnormality identification units; for each of the optimal abnormality identification units, determining the probability value of the Internet of Things terminal in each attack mode based on the data reported by the Internet of Things terminal at multiple time points in the current data collection cycle; determining the target attack corresponding to the Internet of Things terminal based on the probability value of the Internet of Things terminal in each attack mode determined by each optimal abnormality identification unit. attack mode; based on the attack association map, determining the associated Internet of Things terminal corresponding to the target attack mode of the Internet of Things terminal; for each of the optimal abnormality identification units, based on the data reported by the associated Internet of Things terminal at multiple time points in the current data collection cycle, determining the probability value of the associated Internet of Things terminal in each attack mode; based on the probability value of the associated Internet of Things terminal in each attack mode determined by each of the optimal abnormality identification units, determining the probability value of the associated Internet of Things terminal in the target attack mode; based on the probability value of the Internet of Things terminal in the target attack mode and the probability value of each of the associated Internet of Things terminals in the target attack mode, identifying whether the Internet of Things terminal is an abnormal Internet of Things terminal.
[0008] Furthermore, the optimal anomaly identification unit determines the probability value of the Internet of Things terminal in each attack mode based on the data reported by the Internet of Things terminal at multiple time points in the current data collection cycle, including: determining the data volume mean and data volume fluctuation parameters based on the data volume reported by the Internet of Things terminal at multiple time points in the current data collection cycle; determining the fluctuation time domain characteristics and fluctuation frequency domain characteristics of each operating parameter based on multiple operating parameters of the Internet of Things terminal at multiple time points in the current data collection cycle; determining the probability value of the Internet of Things terminal in each attack mode through an attack identification model based on the data volume mean and data volume fluctuation parameters and the fluctuation time domain characteristics and fluctuation frequency domain characteristics of each operating parameter.
[0009] Furthermore, the optimal abnormality identification unit determines the fluctuation time domain characteristics and fluctuation frequency domain characteristics of each operating parameter based on the various operating parameters of the Internet of Things terminal at multiple time points in the current data collection cycle, including: for each operating parameter, based on the various operating parameters of the Internet of Things terminal at multiple time points in the current data collection cycle, generating a parameter change curve corresponding to the operating parameter, performing empirical mode decomposition on the parameter change curve, generating multiple parameter change components and parameter change residuals corresponding to the parameter change curve, for each of the parameter change components, extracting the fluctuation time domain characteristics and fluctuation frequency domain characteristics of the parameter change component, and extracting the fluctuation time domain characteristics and fluctuation frequency domain characteristics of the parameter change residual, wherein the fluctuation time domain characteristics and fluctuation frequency domain characteristics of the operating parameters include the fluctuation time domain characteristics and fluctuation frequency domain characteristics of each of the parameter change components and the fluctuation time domain characteristics and fluctuation frequency domain characteristics of the parameter change residual.
[0010] Further, the optimal abnormality identification unit identifies whether the Internet of Things terminal is an abnormal Internet of Things terminal based on the probability value of the Internet of Things terminal in the target attack mode and the probability value of each of the associated Internet of Things terminals in the target attack mode, including: determining the probability mean and probability fluctuation parameters corresponding to the target attack mode based on the probability value of the Internet of Things terminal in the target attack mode and the probability value of each of the associated Internet of Things terminals in the target attack mode; identifying whether the Internet of Things terminal is an abnormal Internet of Things terminal based on the probability mean and probability fluctuation parameters corresponding to the target attack mode.
[0011] Furthermore, the data storage module encrypts and processes the data collected by the multiple IoT terminals based on the identification results of the abnormal IoT terminals and then stores them, including: dividing the collected data uploaded by the non-abnormal IoT terminals to generate multiple data fragments corresponding to the non-abnormal IoT terminals, encrypting each of the data fragments to generate encrypted data fragments; splicing the multiple encrypted data fragments corresponding to the multiple non-abnormal IoT terminals to generate multiple spliced data; generating a hash value corresponding to each of the encrypted data fragments; generating a splicing path for each spliced data based on the hash value corresponding to each of the encrypted data fragments; encrypting the splicing path of the spliced data; generating a hash value corresponding to the spliced data; and saving multiple spliced data, the hash value corresponding to each of the spliced data, and the encrypted splicing path corresponding to each of the spliced data.
[0012] Furthermore, the query response module determines whether the current query behavior of the data query terminal is an abnormal query behavior based on the historical data query requests of the data query terminal, including: determining the query weight parameter of the data query terminal for each of the Internet of Things terminals based on the historical data query requests of the data query terminal; determining whether the current query behavior of the data query terminal is an abnormal query behavior based on the query weight parameter of the data query terminal for each of the Internet of Things terminals, the data query requests initiated by the data query terminal in the current query cycle and the attack association map.
[0013] Furthermore, the query response module retrieves the target data corresponding to the data query request initiated by the data query terminal, including: retrieving multiple copies of target spliced data based on hash values corresponding to the multiple copies of target spliced data corresponding to the data query request initiated by the data query terminal; restoring the multiple copies of target spliced data based on the encrypted splicing paths corresponding to each copy of the target spliced data, and obtaining multiple encrypted target data fragments corresponding to the data query request initiated by the data query terminal; decrypting the multiple encrypted target data fragments to generate the target data corresponding to the data query request initiated by the data query terminal.
[0014] The present invention provides a big data security protection method for the Internet of Things, comprising: multiple Internet of Things terminals collect data; establish an attack association map, wherein the attack association map is used to record the association relationship between multiple Internet of Things terminals under multiple attack modes; based on the data reported by the Internet of Things terminal at multiple time points in the current data collection cycle and the attack association map, identify whether the Internet of Things terminal is an abnormal Internet of Things terminal; based on the identified abnormal Internet of Things terminal, generate a first warning message; based on the identification result of the abnormal Internet of Things terminal, encrypt and post-process the data collected by the multiple Internet of Things terminals and then store them; receive a data query request initiated by the data query terminal; based on the historical data query request of the data query terminal, determine whether the current query behavior of the data query terminal is an abnormal query behavior; when it is determined that the current query behavior of the data query terminal is an abnormal query behavior, authenticate the data query terminal; based on the identity authentication result, determine whether the data query terminal is an abnormal data query terminal; when it is determined that the data query terminal is not an abnormal data query terminal, retrieve the target data corresponding to the data query request initiated by the data query terminal.
[0015] Compared with the prior art, the big data security protection method and system for the Internet of Things provided by the present invention have at least the following beneficial effects:
[0016] 1. By analyzing and mining historical data and test data, the correlation between multiple IoT terminals under various attack modes is determined, and an attack correlation map is established to provide data support for the subsequent identification of abnormal IoT terminals. In addition, based on the historical data query requests of the data query terminal, it can be effectively determined whether the current query behavior of the data query terminal is an abnormal query behavior. When the current query behavior of the data query terminal is determined to be an abnormal query behavior, the data query terminal is authenticated. Through two verifications, the upload and storage of abnormal data and the leakage of data are effectively avoided.
[0017] 2. The attack identification model is based on the data volume mean and data volume fluctuation parameters and the fluctuation time domain characteristics and fluctuation frequency domain characteristics of each operating parameter, which improves the accuracy and efficiency of determining the probability value of the IoT terminal in each attack mode.
[0018] 3. Segment the collected data uploaded by non-abnormal IoT terminals to generate multiple data segments corresponding to non-abnormal IoT terminals. Randomly splicing data from different non-abnormal IoT terminals can reduce the direct correlation between the data and specific non-abnormal IoT terminals. Random splicing can also make the source of the data obscure, further reducing the risk of data leakage. Even if the data is stolen, it is difficult for attackers to determine the original source of the data. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] This specification will be further described in the form of exemplary embodiments, which will be described in detail by the accompanying drawings. These embodiments are not restrictive, and in these embodiments, the same number represents the same structure, wherein:
[0020] Figure 1 It is a module schematic diagram of a big data security protection system for the Internet of Things according to some embodiments of this specification;
[0021] Figure 2 It is a schematic diagram of a process of identifying whether an IoT terminal is an abnormal IoT terminal according to some embodiments of this specification;
[0022] Figure 3 It is a schematic diagram of a process of encrypting and processing data collected by multiple IoT terminals and then storing them according to some embodiments of this specification;
[0023] Figure 4 It is a flowchart of a big data security protection method for the Internet of Things according to some embodiments of this specification;
[0024] Figure 5 It is a schematic diagram of an attack association map shown in some embodiments of this specification. DETAILED DESCRIPTION
[0025] In order to more clearly illustrate the technical solutions of the embodiments of this specification, the following is a brief introduction to the drawings required for the description of the embodiments. Obviously, the drawings described below are only some examples or embodiments of this specification. For ordinary technicians in this field, this specification can also be applied to other similar scenarios based on these drawings without creative work. Unless it is obvious from the language environment or otherwise explained, the same reference numerals in the figures represent the same structure or operation.
[0026] Figure 1 is a module schematic diagram of a big data security protection system for the Internet of Things according to some embodiments of this specification, such as Figure 1 As shown, a big data security protection system for the Internet of Things may include a data acquisition module, an anomaly identification module, a data storage module, a data query module and a query response module.
[0027] The data acquisition module may include multiple Internet of Things terminals, wherein the Internet of Things terminal includes at least one sensor, for example, a temperature sensor, a humidity sensor, etc.
[0028] The anomaly identification module can be used to build an attack correlation map.
[0029] Among them, the attack correlation map is used to record the correlation relationship between multiple IoT terminals under various attack modes.
[0030] In some embodiments, the anomaly identification module establishes an attack association graph, including:
[0031] Obtain historical attack data of multiple IoT terminals;
[0032] Obtain test attack data of multiple IoT terminals;
[0033] Based on the historical attack data and test attack data of multiple IoT terminals, calculate the attack correlation parameters of any two IoT terminals in each attack mode;
[0034] Based on the attack correlation parameters of any two IoT terminals in each attack mode, an attack correlation map is established.
[0035] Specifically, for each attack mode, the historical number of times any two IoT terminals simultaneously experience this attack mode can be determined based on the historical attack data of multiple IoT terminals. The simulation number of times any two IoT terminals simultaneously experience this attack mode can be determined based on the test attack data of multiple IoT terminals. Based on the historical number and simulation number of times any two IoT terminals simultaneously experience this attack mode, the attack association parameters of the two IoT terminals under each attack mode can be determined.
[0036] For example, the attack correlation parameters of two IoT terminals in each attack mode can be calculated based on the following formula:
[0037] C (i,j) =a1×C ((i,j),1) +a2×C ((i,j),2)
[0038]
[0039] Among them, C (i,j) is the attack correlation parameter of the ith IoT terminal and the jth IoT terminal in a certain attack mode, C ((i,j),1) is the attack correlation parameter of the ith IoT terminal and the jth IoT terminal in this attack mode determined based on historical attack data, C ((i,j),2) is the attack correlation parameter of the ith IoT terminal and the jth IoT terminal in the attack mode determined based on the test attack data, a1 and a2 are preset weights, and a1 and a2 are both greater than 0, N ((i,j),1) N is the historical number of times the i-th IoT terminal and the j-th IoT terminal simultaneously experience this attack mode. (i,1) is the historical number of times the attack mode occurs on the i-th IoT terminal, N (j,1) is the historical number of times the jth IoT terminal has this attack mode, N ((i,j),2) N is the number of simulations of the attack mode occurring simultaneously on the i-th IoT terminal and the j-th IoT terminal, (i,2) is the number of simulations of this attack mode occurring on the i-th IoT terminal, N (j,2) is the number of simulations of this attack mode occurring on the jth IoT terminal.
[0040] For each attack mode, if the attack correlation parameter of the two IoT terminals in the attack mode is greater than a preset attack correlation parameter threshold, then the two IoT terminals are correlated in the attack mode.
[0041] Figure 5 is a schematic diagram of an attack association map according to some embodiments of this specification, such as Figure 5 As shown, for attack mode A, there is a correlation between IoT terminal 1 and IoT terminal 2, and the attack correlation parameter of IoT terminal 1 and IoT terminal 2 under attack mode A is 80%. For attack mode B, there is a correlation between IoT terminal 2 and IoT terminal 3, and the attack correlation parameter of IoT terminal 2 and IoT terminal 3 under attack mode B is 70%.
[0042] The anomaly identification module can be used to identify whether an IoT terminal is an abnormal IoT terminal based on the data reported by the IoT terminal at multiple time points in the current data collection cycle and the attack association map.
[0043] In some embodiments, the anomaly identification module includes a plurality of anomaly identification units, wherein the anomaly identification units can be executed on a cloud platform. For example, the cloud platform may include one or any combination of a private cloud, a public cloud, a hybrid cloud, a community cloud, a decentralized cloud, an internal cloud, etc.
[0044] Figure 2 is a schematic diagram of a process for identifying whether an IoT terminal is an abnormal IoT terminal according to some embodiments of this specification, such as Figure 2 As shown, in some embodiments, the abnormality identification module identifies whether the IoT terminal is an abnormal IoT terminal based on the data reported by the IoT terminal at multiple time points in the current data collection cycle and the attack association map, including:
[0045] Determine multiple optimal abnormality identification units based on operation parameter information of multiple abnormality identification units, wherein the operation parameter information may include CPU usage, memory occupancy, external memory occupancy, and data transmission parameters (e.g., bus width, I / O rate, etc.);
[0046] For each optimal anomaly identification unit, the probability value of the IoT terminal in each attack mode is determined based on the data reported by the IoT terminal at multiple time points in the current data collection cycle;
[0047] Determine the target attack mode corresponding to the IoT terminal based on the probability value of the IoT terminal in each attack mode determined by each optimal anomaly recognition unit;
[0048] Based on the attack correlation map, determine the associated IoT terminals corresponding to the target attack mode of the IoT terminals;
[0049] For each optimal anomaly identification unit, based on the data reported by the associated IoT terminal at multiple time points in the current data collection cycle, determine the probability value of the associated IoT terminal in each attack mode;
[0050] Determine the probability value of the associated IoT terminal in the target attack mode based on the probability value of the associated IoT terminal in each attack mode determined by each optimal anomaly identification unit;
[0051] Based on the probability value of the IoT terminal in the target attack mode and the probability value of each associated IoT terminal in the target attack mode, it is identified whether the IoT terminal is an abnormal IoT terminal.
[0052] Specifically, based on the operating parameter information of multiple abnormality recognition units, an abnormality recognition unit with better performance can be determined as the optimal abnormality recognition unit.
[0053] In some embodiments, the optimal anomaly identification unit determines the probability value of the IoT terminal in each attack mode based on the data reported by the IoT terminal at multiple time points in the current data collection cycle, including:
[0054] Based on the data volume reported by the IoT terminal at multiple time points in the current data collection cycle, determine the data volume mean and data volume fluctuation parameters;
[0055] Based on the various operating parameters of the IoT terminal at multiple time points in the current data collection cycle, determine the fluctuation time domain characteristics and fluctuation frequency domain characteristics of each operating parameter;
[0056] The attack identification model is used to determine the probability value of the IoT terminal in each attack mode based on the data volume mean and data volume fluctuation parameters and the fluctuation time domain characteristics and fluctuation frequency domain characteristics of each operating parameter, wherein the attack identification model can be a recurrent neural network (RNN) model.
[0057] Specifically, the data volume mean and data volume fluctuation parameter can be determined based on the following formula:
[0058]
[0059] Among them, V (i,mean) is the average data volume of the ith IoT terminal in the current data collection cycle, V (i,n) is the amount of data reported by the ith IoT terminal at the nth time point in the current data collection cycle, N is the total number of time points included in the current data collection cycle, and W (i,volume) is the data volume fluctuation parameter of the i-th IoT terminal in the current data collection cycle.
[0060] In some embodiments, the optimal anomaly identification unit determines the fluctuation time domain characteristics and fluctuation frequency domain characteristics of each operating parameter based on multiple operating parameters of the IoT terminal at multiple time points in the current data collection cycle, including:
[0061] For each operating parameter, based on the various operating parameters of the IoT terminal at multiple time points in the current data collection cycle, a parameter change curve corresponding to the operating parameter is generated, and the parameter change curve is subjected to empirical mode decomposition to generate multiple parameter change components and parameter change residuals corresponding to the parameter change curve. For each parameter change component, the fluctuation time domain characteristics and fluctuation frequency domain characteristics of the parameter change component are extracted, and the fluctuation time domain characteristics and fluctuation frequency domain characteristics of the parameter change residual are extracted, wherein the fluctuation time domain characteristics and fluctuation frequency domain characteristics of the operating parameters include the fluctuation time domain characteristics and fluctuation frequency domain characteristics of each parameter change component and the fluctuation time domain characteristics and fluctuation frequency domain characteristics of the parameter change residual.
[0062] In some embodiments, the optimal abnormality identification unit identifies whether the Internet of Things terminal is an abnormal Internet of Things terminal based on the probability value of the Internet of Things terminal in the target attack mode and the probability value of each associated Internet of Things terminal in the target attack mode, including:
[0063] Based on the probability value of the IoT terminal in the target attack mode and the probability value of each associated IoT terminal in the target attack mode, determine the probability mean and probability fluctuation parameter corresponding to the target attack mode;
[0064] Based on the probability mean and probability fluctuation parameters corresponding to the target attack mode, identify whether the IoT terminal is an abnormal IoT terminal.
[0065] Specifically, the probability value of the IoT terminal in the target attack mode and the probability value of each associated IoT terminal in the target attack mode may be averaged to determine the probability mean corresponding to the target attack mode.
[0066] The probability fluctuation parameter can be calculated based on the following formula:
[0067]
[0068] Among them, W (i,probability) is the probability fluctuation parameter corresponding to the target attack mode, P (i,m) is the probability value of the mth associated IoT terminal of the ith IoT terminal in the target attack mode, P i is the probability value of the i-th IoT terminal in the target attack mode, and M is the total number of associated IoT terminals of the i-th IoT terminal.
[0069] When the probability mean corresponding to the target attack mode is greater than the preset probability mean threshold and the probability fluctuation parameter is greater than the preset probability fluctuation parameter threshold, the IoT terminal is identified as an abnormal IoT terminal.
[0070] The abnormality identification module can be used to generate a first warning message based on the identified abnormal Internet of Things terminal.
[0071] Specifically, the first warning information may include information of the abnormal IoT terminal, such as a unique device identification code, an attack mode, etc. The abnormality identification module may send the first warning information to the management terminal.
[0072] The data storage module can be used to encrypt and process the data collected by multiple IoT terminals based on the identification results of abnormal IoT terminals and then store them.
[0073] Figure 3 This is a flow chart of encrypting and processing the data collected by multiple IoT terminals and then storing them according to some embodiments of this specification, such as Figure 3 As shown, in some embodiments, the data storage module encrypts and processes the data collected by multiple IoT terminals based on the identification results of abnormal IoT terminals and then stores the data, including:
[0074] Segment the collected data uploaded by the non-abnormal IoT terminal to generate multiple data fragments corresponding to the non-abnormal IoT terminal, encrypt each data fragment to generate encrypted data fragments;
[0075] Splicing multiple encrypted data fragments corresponding to multiple non-abnormal IoT terminals to generate multiple copies of spliced data;
[0076] Generate a hash value corresponding to each encrypted data fragment;
[0077] Based on the hash value corresponding to each encrypted data fragment, a splicing path for each spliced data is generated;
[0078] Encrypting the splicing path of the splicing data;
[0079] Generate a hash value corresponding to the spliced data;
[0080] Save multiple splicing data, the hash value corresponding to each splicing data, and the encrypted splicing path corresponding to each splicing data.
[0081] For example, the encrypted data segment 1 of the non-abnormal Internet of Things terminal 1, the encrypted data segment 2 of the non-abnormal Internet of Things terminal 2, and the encrypted data segment 1 of the non-abnormal Internet of Things terminal 3 are spliced to generate a spliced data.
[0082] The data query module may include multiple data query terminals.
[0083] As an example only, the data query terminal may be a mobile device, a tablet computer, a laptop computer, a desktop computer, or any combination thereof, of other devices having input and / or output functions.
[0084] The query response module can be used to receive a data query request initiated by a data query terminal, and determine whether a current query behavior of the data query terminal is an abnormal query behavior based on historical data query requests of the data query terminal.
[0085] In some embodiments, the query response module determines whether the current query behavior of the data query terminal is an abnormal query behavior based on the historical data query request of the data query terminal, including:
[0086] Based on the historical data query request of the data query terminal, determine the query weight parameter of the data query terminal for each IoT terminal;
[0087] Based on the query weight parameters of the data query terminal for each IoT terminal, the data query request initiated by the data query terminal in the current query cycle and the attack association map, it is determined whether the current query behavior of the data query terminal is an abnormal query behavior.
[0088] Specifically, the query weight parameter of the data query terminal for each IoT terminal can be determined based on the following formula:
[0089]
[0090] Among them, w (g,i) is the query weight parameter of the g-th data query terminal to the i-th IoT terminal, N (g,i) N is the number of data query requests from the g-th data query terminal to the i-th IoT terminal determined based on the historical data query requests of the g-th data query terminal, g The total number of data query requests initiated by the g-th data query terminal is determined based on the historical data query requests of the g-th data query terminal.
[0091] Based on the data query request initiated by the data query terminal in the current query cycle, the data query request whose query weight parameter of the corresponding Internet of Things terminal is less than the preset query weight parameter threshold is regarded as an abnormal data query request. Based on the attack association map, when the Internet of Things terminals corresponding to multiple abnormal data query requests and the Internet of Things terminals corresponding to the current query behavior of the data query terminal are mutually associated Internet of Things terminals under a certain attack mode, the current query behavior of the data query terminal is determined to be an abnormal query behavior.
[0092] The query response module can also be used to authenticate the data query terminal when determining that the current query behavior of the data query terminal is an abnormal query behavior, and determine whether the data query terminal is an abnormal data query terminal based on the identity authentication result.
[0093] Specifically, user information, such as face information, fingerprint information, and pupil information, may be collected through the data query terminal to perform identity authentication. When the identity authentication is passed, it is determined that the data query terminal is not an abnormal data query terminal.
[0094] The query response module may also be used to retrieve target data corresponding to the data query request initiated by the data query terminal when it is determined that the data query terminal is not an abnormal data query terminal.
[0095] In some embodiments, the query response module retrieves target data corresponding to the data query request initiated by the data query terminal, including:
[0096] Based on hash values corresponding to the multiple copies of target splicing data corresponding to the data query request initiated by the data query terminal, the splicing paths corresponding to the multiple copies of target splicing data are obtained, and the multiple copies of target splicing data are retrieved according to the splicing paths corresponding to the multiple copies of target splicing data;
[0097] Based on the encrypted splicing path corresponding to each target splicing data, multiple target splicing data are restored to obtain multiple encrypted target data fragments corresponding to the data query request initiated by the data query terminal;
[0098] Decrypt the multiple encrypted target data fragments to generate target data corresponding to the data query request initiated by the data query terminal.
[0099] Figure 4 is a flow chart of a big data security protection method for the Internet of Things according to some embodiments of this specification, such as Figure 4 As shown, a big data security protection method for the Internet of Things may include the following process.
[0100] Multiple IoT terminals collect data;
[0101] Establish an attack correlation map, where the attack correlation map is used to record the correlation relationship between multiple IoT terminals under various attack modes;
[0102] Based on the data reported by the IoT terminal at multiple time points in the current data collection cycle and the attack association map, identify whether the IoT terminal is an abnormal IoT terminal;
[0103] Generate a first warning message based on the identified abnormal IoT terminal;
[0104] Based on the identification results of abnormal IoT terminals, the data collected by multiple IoT terminals are encrypted, processed and stored;
[0105] Receiving a data query request initiated by a data query terminal;
[0106] Based on the historical data query requests of the data query terminal, determining whether the current query behavior of the data query terminal is an abnormal query behavior;
[0107] When determining that the current query behavior of the data query terminal is an abnormal query behavior, performing identity authentication on the data query terminal;
[0108] Based on the identity authentication result, determining whether the data query terminal is an abnormal data query terminal;
[0109] When it is determined that the data query terminal is not an abnormal data query terminal, target data corresponding to the data query request initiated by the data query terminal is retrieved.
[0110] A big data security protection method for the Internet of Things can be executed by a big data security protection system for the Internet of Things. For more descriptions of a big data security protection method for the Internet of Things, please refer to the relevant description of a big data security protection system for the Internet of Things, which will not be repeated here.
[0111] Finally, it should be understood that the embodiments described in this specification are only used to illustrate the principles of the embodiments of this specification. Other variations may also fall within the scope of this specification. Therefore, as an example and not a limitation, alternative configurations of the embodiments of this specification may be considered consistent with the teachings of this specification. Accordingly, the embodiments of this specification are not limited to the embodiments explicitly introduced and described in this specification.
Claims
1. A big data security protection system for the Internet of Things, characterized in that: include: A data acquisition module, comprising a plurality of Internet of Things terminals, wherein the Internet of Things terminals include at least one sensor; an abnormality identification module, used to establish an attack association map, wherein the attack association map is used to record the association relationship between multiple IoT terminals under multiple attack modes, and is also used to identify whether the IoT terminal is an abnormal IoT terminal based on the data reported by the IoT terminal at multiple time points in the current data collection cycle and the attack association map, and is also used to generate a first warning message based on the identified abnormal IoT terminal; A data storage module, used for encrypting and processing the data collected by the plurality of IoT terminals and then storing the data based on the identification result of the abnormal IoT terminal; A data query module, including multiple data query terminals; A query response module, used to receive a data query request initiated by the data query terminal, determine whether the current query behavior of the data query terminal is an abnormal query behavior based on the historical data query requests of the data query terminal, and authenticate the data query terminal when the current query behavior of the data query terminal is determined to be an abnormal query behavior, determine whether the data query terminal is an abnormal data query terminal based on the identity authentication result, and retrieve target data corresponding to the data query request initiated by the data query terminal when it is determined that the data query terminal is not an abnormal data query terminal; The anomaly identification module identifies whether an IoT terminal is an abnormal IoT terminal based on the data reported by the IoT terminal at multiple time points in the current data collection cycle and the attack association map, including: Determine multiple optimal abnormality identification units based on the operation parameter information of the multiple abnormality identification units, wherein the operation parameter information includes CPU usage, memory occupancy, external memory occupancy and data transmission parameters; For each optimal anomaly identification unit, the probability value of the IoT terminal in each attack mode is determined based on the data reported by the IoT terminal at multiple time points in the current data collection cycle; Determine the target attack mode corresponding to the IoT terminal based on the probability value of the IoT terminal in each attack mode determined by each optimal anomaly recognition unit; Based on the attack correlation map, determine the associated IoT terminals corresponding to the target attack mode of the IoT terminals; For each optimal anomaly identification unit, based on the data reported by the associated IoT terminal at multiple time points in the current data collection cycle, determine the probability value of the associated IoT terminal in each attack mode; Determine the probability value of the associated IoT terminal in the target attack mode based on the probability value of the associated IoT terminal in each attack mode determined by each optimal anomaly identification unit; Based on the probability value of the IoT terminal in the target attack mode and the probability value of each associated IoT terminal in the target attack mode, identifying whether the IoT terminal is an abnormal IoT terminal; Specifically, based on the operation parameter information of the plurality of abnormality recognition units, determining the abnormality recognition unit with better performance as the optimal abnormality recognition unit; The optimal anomaly identification unit determines the probability value of the IoT terminal in each attack mode based on the data reported by the IoT terminal at multiple time points in the current data collection cycle, including: Based on the data volume reported by the IoT terminal at multiple time points in the current data collection cycle, determine the data volume mean and data volume fluctuation parameters; Based on the various operating parameters of the IoT terminal at multiple time points in the current data collection cycle, determine the fluctuation time domain characteristics and fluctuation frequency domain characteristics of each operating parameter; The attack identification model is used to determine the probability value of the IoT terminal in each attack mode based on the data volume mean value, data volume fluctuation parameters, and the fluctuation time domain characteristics and fluctuation frequency domain characteristics of each operating parameter; The data volume mean and data volume fluctuation parameters are determined based on the following formula: Among them, V (i,mean) is the average data volume of the ith IoT terminal in the current data collection cycle, V (i,n) is the amount of data reported by the ith IoT terminal at the nth time point in the current data collection cycle, N is the total number of time points included in the current data collection cycle, and W (i,volume) is the data volume fluctuation parameter of the i-th IoT terminal in the current data collection cycle; The optimal anomaly identification unit determines the fluctuation time domain characteristics and fluctuation frequency domain characteristics of each operating parameter based on the multiple operating parameters of the IoT terminal at multiple time points in the current data collection cycle, including: For each operating parameter, based on the various operating parameters of the IoT terminal at multiple time points in the current data collection cycle, a parameter change curve corresponding to the operating parameter is generated, and the parameter change curve is subjected to empirical mode decomposition to generate multiple parameter change components and parameter change residuals corresponding to the parameter change curve. For each parameter change component, the fluctuation time domain characteristics and fluctuation frequency domain characteristics of the parameter change component are extracted, and the fluctuation time domain characteristics and fluctuation frequency domain characteristics of the parameter change residual are extracted, wherein the fluctuation time domain characteristics and fluctuation frequency domain characteristics of the operating parameter include the fluctuation time domain characteristics and fluctuation frequency domain characteristics of each parameter change component and the fluctuation time domain characteristics and fluctuation frequency domain characteristics of the parameter change residual; The optimal anomaly identification unit identifies whether the IoT terminal is an abnormal IoT terminal based on the probability value of the IoT terminal in the target attack mode and the probability value of each associated IoT terminal in the target attack mode, including: Based on the probability value of the IoT terminal in the target attack mode and the probability value of each associated IoT terminal in the target attack mode, determine the probability mean and probability fluctuation parameter corresponding to the target attack mode; Based on the probability mean and probability fluctuation parameters corresponding to the target attack mode, identify whether the IoT terminal is an abnormal IoT terminal; Specifically, the probability value of the IoT terminal in the target attack mode and the probability value of each associated IoT terminal in the target attack mode are averaged to determine the probability mean corresponding to the target attack mode; The probability fluctuation parameter is calculated based on the following formula: Among them, W (i,probability) is the probability fluctuation parameter corresponding to the target attack mode, P (i,m) is the probability value of the mth associated IoT terminal of the ith IoT terminal in the target attack mode, P i is the probability value of the ith IoT terminal in the target attack mode, and M is the total number of IoT terminals associated with the ith IoT terminal; When the probability mean corresponding to the target attack mode is greater than the preset probability mean threshold and the probability fluctuation parameter is greater than the preset probability fluctuation parameter threshold, the IoT terminal is identified as an abnormal IoT terminal.
2. A big data security protection system for the Internet of Things according to claim 1, characterized in that: The anomaly identification module establishes the attack association map, including: Obtaining historical attack data of the multiple IoT terminals; Acquire test attack data of the multiple IoT terminals; Based on the historical attack data and the test attack data of the plurality of IoT terminals, calculating the attack correlation parameters of any two IoT terminals in each attack mode; The attack association graph is established based on the attack association parameters of any two of the IoT terminals in each attack mode.
3. The big data security protection system for the Internet of Things according to claim 1 is characterized in that: The data storage module encrypts and processes the data collected by the plurality of IoT terminals based on the identification result of the abnormal IoT terminal and then stores the data, including: Segment the collected data uploaded by the non-abnormal IoT terminal to generate multiple data fragments corresponding to the non-abnormal IoT terminal, and encrypt each of the data fragments to generate encrypted data fragments; Splicing multiple encrypted data fragments corresponding to multiple non-abnormal IoT terminals to generate multiple copies of spliced data; Generate a hash value corresponding to each of the encrypted data fragments; Generate a splicing path for each piece of spliced data based on the hash value corresponding to each of the encrypted data fragments; Encrypting a splicing path of the splicing data; Generate a hash value corresponding to the spliced data; A plurality of splicing data, a hash value corresponding to each of the splicing data, and an encrypted splicing path corresponding to each of the splicing data are saved.
4. The big data security protection system for the Internet of Things according to claim 1, characterized in that: The query response module determines whether the current query behavior of the data query terminal is an abnormal query behavior based on the historical data query request of the data query terminal, including: Determining a query weight parameter of the data query terminal for each of the Internet of Things terminals based on a historical data query request of the data query terminal; Based on the query weight parameter of the data query terminal for each of the Internet of Things terminals, the data query request initiated by the data query terminal in the current query cycle and the attack association map, it is determined whether the current query behavior of the data query terminal is an abnormal query behavior.
5. The big data security protection system for the Internet of Things according to claim 1 is characterized in that: The query response module retrieves target data corresponding to the data query request initiated by the data query terminal, including: Retrieving the multiple copies of target spliced data based on hash values corresponding to the multiple copies of target spliced data corresponding to the data query request initiated by the data query terminal; Based on the encrypted splicing path corresponding to each of the target splicing data, the multiple copies of the target splicing data are restored to obtain multiple encrypted target data fragments corresponding to the data query request initiated by the data query terminal; The multiple encrypted target data fragments are decrypted to generate target data corresponding to the data query request initiated by the data query terminal.
6. A big data security protection method for the Internet of Things, characterized in that: include: Multiple IoT terminals collect data; Establishing an attack association map, wherein the attack association map is used to record the association relationship between multiple IoT terminals under multiple attack modes; Based on the data reported by the IoT terminal at multiple time points in the current data collection cycle and the attack association map, identifying whether the IoT terminal is an abnormal IoT terminal; Generate a first warning message based on the identified abnormal IoT terminal; Based on the identification results of the abnormal IoT terminals, encrypt and process the data collected by the multiple IoT terminals and then store them; Receiving a data query request initiated by a data query terminal; Based on the historical data query requests of the data query terminal, determining whether the current query behavior of the data query terminal is an abnormal query behavior; When determining that the current query behavior of the data query terminal is an abnormal query behavior, performing identity authentication on the data query terminal; Based on the identity authentication result, determining whether the data query terminal is an abnormal data query terminal; When it is determined that the data query terminal is not an abnormal data query terminal, retrieving target data corresponding to the data query request initiated by the data query terminal; Based on the data reported by the IoT terminal at multiple time points in the current data collection cycle and the attack association map, identify whether the IoT terminal is an abnormal IoT terminal, including: Determine multiple optimal abnormality identification units based on the operation parameter information of the multiple abnormality identification units, wherein the operation parameter information includes CPU usage, memory occupancy, external memory occupancy and data transmission parameters; For each optimal anomaly identification unit, the probability value of the IoT terminal in each attack mode is determined based on the data reported by the IoT terminal at multiple time points in the current data collection cycle; Determine the target attack mode corresponding to the IoT terminal based on the probability value of the IoT terminal in each attack mode determined by each optimal anomaly recognition unit; Based on the attack correlation map, determine the associated IoT terminals corresponding to the target attack mode of the IoT terminals; For each optimal anomaly identification unit, based on the data reported by the associated IoT terminal at multiple time points in the current data collection cycle, determine the probability value of the associated IoT terminal in each attack mode; Determine the probability value of the associated IoT terminal in the target attack mode based on the probability value of the associated IoT terminal in each attack mode determined by each optimal anomaly identification unit; Based on the probability value of the IoT terminal in the target attack mode and the probability value of each associated IoT terminal in the target attack mode, identifying whether the IoT terminal is an abnormal IoT terminal; Specifically, based on the operation parameter information of the plurality of abnormality recognition units, determining the abnormality recognition unit with better performance as the optimal abnormality recognition unit; The optimal anomaly identification unit determines the probability value of the IoT terminal in each attack mode based on the data reported by the IoT terminal at multiple time points in the current data collection cycle, including: Based on the data volume reported by the IoT terminal at multiple time points in the current data collection cycle, determine the data volume mean and data volume fluctuation parameters; Based on the various operating parameters of the IoT terminal at multiple time points in the current data collection cycle, determine the fluctuation time domain characteristics and fluctuation frequency domain characteristics of each operating parameter; The attack identification model is used to determine the probability value of the IoT terminal in each attack mode based on the data volume mean value, data volume fluctuation parameters, and the fluctuation time domain characteristics and fluctuation frequency domain characteristics of each operating parameter; The data volume mean and data volume fluctuation parameters are determined based on the following formula: Among them, V (i,mean) is the average data volume of the ith IoT terminal in the current data collection cycle, V (i,n) is the amount of data reported by the ith IoT terminal at the nth time point in the current data collection cycle, N is the total number of time points included in the current data collection cycle, and W (i,volume) is the data volume fluctuation parameter of the i-th IoT terminal in the current data collection cycle; The optimal anomaly identification unit determines the fluctuation time domain characteristics and fluctuation frequency domain characteristics of each operating parameter based on the multiple operating parameters of the IoT terminal at multiple time points in the current data collection cycle, including: For each operating parameter, based on the various operating parameters of the IoT terminal at multiple time points in the current data collection cycle, a parameter change curve corresponding to the operating parameter is generated, and the parameter change curve is subjected to empirical mode decomposition to generate multiple parameter change components and parameter change residuals corresponding to the parameter change curve. For each parameter change component, the fluctuation time domain characteristics and fluctuation frequency domain characteristics of the parameter change component are extracted, and the fluctuation time domain characteristics and fluctuation frequency domain characteristics of the parameter change residual are extracted, wherein the fluctuation time domain characteristics and fluctuation frequency domain characteristics of the operating parameter include the fluctuation time domain characteristics and fluctuation frequency domain characteristics of each parameter change component and the fluctuation time domain characteristics and fluctuation frequency domain characteristics of the parameter change residual; The optimal anomaly identification unit identifies whether the IoT terminal is an abnormal IoT terminal based on the probability value of the IoT terminal in the target attack mode and the probability value of each associated IoT terminal in the target attack mode, including: Based on the probability value of the IoT terminal in the target attack mode and the probability value of each associated IoT terminal in the target attack mode, determine the probability mean and probability fluctuation parameter corresponding to the target attack mode; Based on the probability mean and probability fluctuation parameters corresponding to the target attack mode, identify whether the IoT terminal is an abnormal IoT terminal; Specifically, the probability value of the IoT terminal in the target attack mode and the probability value of each associated IoT terminal in the target attack mode are averaged to determine the probability mean corresponding to the target attack mode; The probability fluctuation parameter is calculated based on the following formula: Among them, W (i,probability) is the probability fluctuation parameter corresponding to the target attack mode, P (i,m) is the probability value of the mth associated IoT terminal of the ith IoT terminal in the target attack mode, P i is the probability value of the ith IoT terminal in the target attack mode, and M is the total number of IoT terminals associated with the ith IoT terminal; When the probability mean corresponding to the target attack mode is greater than the preset probability mean threshold and the probability fluctuation parameter is greater than the preset probability fluctuation parameter threshold, the IoT terminal is identified as an abnormal IoT terminal.
Citation Information
Patent Citations
Safety protection method for ubiquitous power Internet of Things terminal in specific attack scene
CN111404914A
Smart park industrial control system network attack scene identification method based on multi-Agent distributed association analysis
CN114915478A