Security detection method and device of internet of things equipment and electronic equipment
By dynamically generating sampling cycles and risk values based on the type of IoT devices to select detection targets, the problem of resource waste and low detection efficiency when the number of IoT devices is large is solved, and efficient security detection is achieved.
Patent Information
- Application Number
- CN202410388762.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-04-01
- Publication Date
- 2025-11-28
- Estimated Expiration
- 2044-04-01
AI Technical Summary
With the large number of IoT devices, current technologies suffer from resource waste and low detection efficiency due to the centralized collection of data for security testing.
The sampling period is dynamically generated based on the type of IoT device to determine the security detection period. Based on the target data, the risk value of the device is calculated, and some devices are selected for security detection to reduce the number of detection targets.
By dynamically adjusting the sampling cycle and the objects being tested, resource waste is reduced, testing efficiency is improved, and the security testing process for IoT devices is optimized.
Smart Images

Figure CN118802293B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application belongs to the field of computer, and particularly relates to a security detection method and device of an Internet of Things equipment and an electronic device. BACKGROUND
[0002] Generally, in order to guarantee the safe operation of the Internet of Things, the security of each equipment in the Internet of Things needs to be detected.
[0003] The security detection scheme of the related art for the Internet of Things is to install an antivirus software or a firewall on each equipment in the Internet of Things, and when the security of each equipment in the Internet of Things is detected by running the antivirus software or the firewall, the data information of each equipment with different configurations and running conditions in the Internet of Things is collected for security detection. However, in the case of a large number of Internet of Things equipment, this method needs to occupy a large amount of resources to collect data information and perform security detection, which causes serious resource waste. SUMMARY
[0004] The embodiments of the present application provide a security detection method, device and electronic device of an Internet of Things equipment, which can solve the problem of serious resource waste caused by the related art in which the data information of each equipment in the Internet of Things is collected for security detection.
[0005] In a first aspect, the embodiments of the present application provide a security detection method of an Internet of Things equipment, and the method comprises the following steps.
[0006] Obtaining the equipment types of P Internet of Things equipment;
[0007] Based on the equipment types, determining M sampling periods of the P Internet of Things equipment; M is a positive integer; the same equipment type corresponds to the same sampling period, and different equipment types correspond to different sampling periods;
[0008] Determining at least one sampling period from the M sampling periods as a security detection period of the Internet of Things equipment;
[0009] Obtaining target data of the P Internet of Things equipment in the security detection period;
[0010] Based on the obtained target data, determining Q detection objects in the P Internet of Things equipment; Q is less than P;
[0011] Performing security detection on the Q detection objects.
[0012] In a second aspect, the embodiments of the present application provide a security detection device of an Internet of Things, and the device comprises:
[0013] An obtaining module, configured to obtain the equipment types of P Internet of Things equipment;
[0014] determine M sampling periods of the P Internet of Things devices based on the device type; M is a positive integer; the same device type corresponds to the same sampling period, and different device types correspond to different sampling periods;
[0015] The determining module is further configured to determine at least one sampling period from the M sampling periods as a security detection period of the Internet of Things device.
[0016] The obtaining module is further configured to obtain target data of the P Internet of Things devices in the security detection period.
[0017] The determining module is further configured to determine Q detection objects from the P Internet of Things devices based on the obtained target data; Q is less than P.
[0018] The detecting module is configured to perform security detection on the Q detection objects.
[0019] In a third aspect, an electronic device is provided, which includes a processor and a memory. The memory stores programs or instructions that are run on the processor. When the programs or instructions are executed by the processor, the steps of the method according to the first aspect are implemented.
[0020] In a fourth aspect, a computer readable storage medium is provided, which stores programs or instructions. When the programs or instructions are executed, the steps of the method according to the first aspect are implemented.
[0021] In a fifth aspect, a computer program product is provided, which includes a computer program. When the computer program is executed by a processor, the steps of the method according to the first aspect are implemented.
[0022] The above at least one technical solution provided by the embodiments of the present application can achieve the following technical effects:
[0023] In the embodiment of the present application, the device types of P Internet of Things devices are acquired; based on the device types, M sampling periods of the P Internet of Things devices are determined; M is a positive integer; the same device type corresponds to the same sampling period, and different device types correspond to different sampling periods; at least one sampling period is determined from the M sampling periods as a security detection period of the Internet of Things device; target data of the P Internet of Things devices in the security detection period is acquired; based on the acquired target data, Q detection objects in the P Internet of Things devices are determined; Q is less than P; and the Q detection objects are subjected to security detection. In this way, at least one sampling period is determined from the M sampling periods dynamically generated based on the device types of the P Internet of Things devices as a security detection period of the Internet of Things device, Q detection objects with a number less than P are determined in the P Internet of Things devices based on the target data of the P Internet of Things devices in the security detection period, and the Q detection objects are subjected to security detection, thereby reducing the number of devices subjected to security detection to achieve the purpose of reducing resource waste caused by collecting data information and performing security detection. BRIEF DESCRIPTION OF DRAWINGS
[0024] Figure 1 is a flowchart of a security detection method of an Internet of Things device provided by an embodiment of the present application.
[0025] Figure 2 is a flowchart of a security detection method of an Internet of Things device provided by an embodiment of the present application.
[0026] Figure 3 is a flowchart of a security detection method of an Internet of Things device provided by an embodiment of the present application.
[0027] Figure 4 is a flowchart of a security detection method of an Internet of Things device provided by an embodiment of the present application.
[0028] Figure 5 is a structural diagram of a security detection device of an Internet of Things device provided by an embodiment of the present application.
[0029] Figure 6 is a structural block diagram of an electronic device provided by an embodiment of the present application. DETAILED DESCRIPTION
[0030] The technical solutions in the embodiments of the present application will be described clearly in combination with the drawings in the embodiments of the present application. Obviously, the described embodiments are only some of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative labor fall within the scope of protection of the present application.
[0031] The terms "first", "second", etc. in the specification and claims of the present application are used to distinguish similar objects, and are not used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances, so that the embodiments of the present application can be implemented in an order other than those illustrated or described herein, and the objects distinguished by "first", "second", etc. are generally of a kind and do not limit the number of objects, for example, the first object can be one or more. In addition, "and / or" in the specification and claims indicates at least one of the connected objects, and the character " / ", generally indicates that the objects before and after are in a "or" relationship.
[0032] As discussed in the background section, in the related art, when performing security detection on various devices in the Internet of Things, data information (target data) of devices with different configurations and running conditions in the Internet of Things is collected for security detection. However, in the case of a large number of Internet of Things devices, collecting data information (target data) at the same collection period will cause the collection frequency of some Internet of Things devices to be too dense, the similarity of data collected at two consecutive times being large, resulting in resource waste, or the collection frequency of some types of devices to be too sparse, the interval between two data information collection times being too long, resulting in missing data information.
[0033] In an embodiment of the present application, a security detection method for Internet of Things devices is provided. The method first acquires device types of P Internet of Things devices, determines M sampling periods (M is a positive integer, where the same device type corresponds to the same sampling period, and different device types correspond to different sampling periods) of the P Internet of Things devices based on the device types, determines at least one sampling period from the M sampling periods as a security detection period for the Internet of Things devices, acquires target data of the P Internet of Things devices within the security detection period, determines Q detection objects (Q is less than P) from the P Internet of Things devices based on the acquired target data and performs security detection on the Q detection objects. In this way, by determining the collection period based on the device types of the Internet of Things devices, the security detection period of the Internet of Things devices is dynamically determined, the target data of the P Internet of Things devices within the security detection period is acquired according to the dynamically determined security detection period of the Internet of Things devices, avoiding the problem of resource waste caused by too dense collection period of target data for the Internet of Things devices, or the problem of missing target data caused by too sparse collection period of target data.
[0034] Moreover, the related art takes all devices in the Internet of Things as detection objects, but in actual situations, different Internet of Things devices have different possibilities of being attacked, the possibility of an Internet of Things device being attacked is related to data collected by the Internet of Things device itself, and an Internet of Things device collecting critical data is more likely to be attacked; the possibility of an Internet of Things device being attacked is also related to the protection degree of the Internet of Things device, and an Internet of Things device without any security measures is also more likely to be attacked. For an Internet of Things device that is not easy to be attacked, the related art still detects it, which wastes detection resources and reduces detection efficiency.
[0035] In an embodiment of the present application, a security detection method of an Internet of Things device is provided, which determines at least one sampling period from M sampling periods dynamically generated based on the device types of P Internet of Things devices as a security detection period of the Internet of Things device, calculates a target risk value of each of the P Internet of Things devices based on target data of the P Internet of Things devices in the security detection period, obtains P target risk values, determines Q Internet of Things devices corresponding to Q target risk values greater than a preset value from the P target risk values as Q detection objects, and performs security detection on the Q detection objects that are easy to be attacked and have high target risk values, so as to reduce the number of devices that need to be detected for security, and achieve the purpose of reducing resource waste caused by collecting data information and performing security detection.
[0036] The security detection method of the Internet of Things device provided in the embodiments of the present application can be applied to a 5G automatic driving demonstration vehicle network security situation awareness platform. The security operation of the Internet of Vehicles, which is a special type of network of the Internet of Things, is very important. The 5G automatic driving demonstration vehicle network security situation awareness platform collects attack events of automatic driving vehicles, performs statistical analysis and situation awareness, assists decision makers to make decision responses, realizes the update of security strategies, and improves the overall defense capability of vehicles. The security detection method of the Internet of Things device provided in the embodiments of the present application can be used to collect attack events of automatic driving vehicles for situation awareness, and determine a security detection period based on the types of each Internet of Vehicles device in the Internet of Vehicles (the Internet of Vehicles is a specific Internet of Things, and the security detection method of the Internet of Things device provided in the embodiments of the present application can be used for the Internet of Vehicles and can also be used for other Internet of Things). Whether to perform security detection on each Internet of Vehicles device in the current security detection period is determined according to the log information of the Internet of Vehicles device. Finally, the detection object is detected for security of the Internet of Vehicles, situation awareness is formed, and then decision makers are assisted to make decision responses, security strategies are updated, and the overall defense capability of vehicles is improved.
[0037] It should be understood that all the security detection methods of the Internet of Things device provided in the embodiments of the present application can be executed by an electronic device. The electronic device can include a server. The server can be a single server or a server cluster. In the case of the server being a server cluster, in the security detection method of the Internet of Things device provided in the present application, the steps of obtaining the device type of the Internet of Things device, determining the sampling period of the Internet of Things device, determining the security detection period of the Internet of Things device, obtaining the target data of the Internet of Things device in the security detection period, determining the detection object, and performing security detection on the detection object can be executed by the same server or different servers. The embodiments of the present application do not limit the specific hardware deployment environment.
[0038] The security detection method of all the Internet of Things devices provided in the embodiments of the present application will be described in detail below in combination with the drawings, specific embodiments and application scenarios.
[0039] Please refer to Figure 1 , Figure 1 The flowchart of the security detection method of the Internet of Things device provided in the embodiments of the present application is shown in Figure 1 , and the method includes the following steps:
[0040] Step 110: Obtain the device types of P Internet of Things devices. Wherein P is a positive integer.
[0041] In the embodiments of the present application, the device types of the P Internet of Things devices can be obtained by obtaining the device information of the P Internet of Things devices. The device information of the Internet of Things device can include at least one of the device configuration information, the location, the data information type, and the device signal of the Internet of Things device.
[0042] Step 120: Determine M kinds of sampling periods of the P Internet of Things devices based on the device types. Wherein M is a positive integer. In the embodiments of the present application, the same device type corresponds to the same sampling period, and different device types correspond to different sampling periods. For example, in the Internet of Things, there are five Internet of Things devices, wherein the device types of device 1 and device 2 are both type a, so the sampling period of device 1 and device 2 is determined to be the first sampling period, and the device type of device 3 is device type b, so the sampling period of device 3 is determined to be the second sampling period.
[0043] In the embodiments of the present application, the number of device types of the P Internet of Things devices is M, and the M kinds of device types correspond to the M kinds of sampling periods one by one.
[0044] Step 130: Determine at least one sampling period from the M kinds of sampling periods as the security detection period of the Internet of Things device. Specifically, the maximum sampling period can be selected from the M kinds of sampling periods; and the maximum sampling period is determined as the security detection period of the Internet of Things device.
[0045] Step 140: obtaining target data of P Internet of Things devices in a security detection period. In the embodiment of the present application, after determining the security detection period of the Internet of Things device, the target data of each of the P Internet of Things devices in the security detection period is obtained, for example, average CPU utilization, storage space occupancy, vulnerability impact value, number of vulnerabilities and the like.
[0046] Step 150: determining Q detection objects in the P Internet of Things devices based on the obtained target data. Wherein Q is less than P.
[0047] In the embodiment of the present application, the target risk value of each of the P Internet of Things devices can be calculated based on the obtained target data, obtaining P target risk values; Q target risk values greater than a preset value are determined from the P target risk values; and the Q Internet of Things devices corresponding to the Q target risk values are determined as the Q detection objects.
[0048] Step 160: security detection on the Q detection objects.
[0049] In the embodiment of the present application, after determining the Q detection objects from the P Internet of Things devices, the traffic data of each of the Q detection objects is obtained, and the traffic data of each of the Q detection objects is detected to determine whether the traffic data is abnormal. If it is abnormal, it means that the detection object has a security risk and a warning is given.
[0050] In the embodiment of the present application, after determining the Q detection objects from the P Internet of Things devices, the traffic information of the Q detection objects can be obtained. The traffic information is all data of the detection object, for example, packet information and network information, wherein the packet information describes the relevant information of each packet, such as packet identification, data direction (uplink), involved port, IP address, etc.; the network information describes the overall situation in the data transmission process, such as packet loss rate, maximum number of connections at the same time, traffic trend. All packets of a detection object are taken as the traffic information of the detection object, and the information of each packet is taken as a piece of data in the collected data, for example, for a packet A, the collected information is: identification of packet A, source IP, destination IP, source port, destination port, packet size, transmission start time, transmission end time, packet loss rate, maximum number of connections at the same time, traffic trend, etc. The traffic data of the detection object is detected for security, and if the traffic data of the detection object is abnormal, it means that the detection object has a security risk and a warning is given.
[0051] In the embodiment of the present application, the device types of P Internet of Things devices are acquired; based on the device types, M sampling periods of the P Internet of Things devices are determined; M is a positive integer; the same device type corresponds to the same sampling period, and different device types correspond to different sampling periods; at least one sampling period is determined from the M sampling periods as a security detection period of the Internet of Things device; target data of the P Internet of Things devices in the security detection period is acquired; based on the acquired target data, Q detection objects in the P Internet of Things devices are determined; Q is less than P; and the Q detection objects are subjected to security detection. In this way, at least one sampling period is determined from the M sampling periods dynamically generated based on the device types of the P Internet of Things devices as a security detection period of the Internet of Things device, Q detection objects with a number less than P are determined in the P Internet of Things devices based on the target data of the P Internet of Things devices in the security detection period, and the Q detection objects are subjected to security detection, thereby reducing the number of devices subjected to security detection to achieve the purpose of reducing resource waste caused by collecting data information and performing security detection.
[0052] In an embodiment of the present application, the number of device types of the P Internet of Things devices is M, and the M device types correspond to M sampling periods one by one. For example, there are 5 Internet of Things devices in the Internet of Things, the number of device types of the 5 Internet of Things devices is 4, device types of device 1 and device 2 are both type a, device type of device 3 is type b, device type of device 4 is type c, and device type of device 5 is type d. Four sampling periods of the 5 Internet of Things devices are determined, wherein device type a of device 1 and device 2 corresponds to a first sampling period, device type b of device 3 corresponds to a second sampling period, device type c of device 4 corresponds to a third sampling period, and device type d of device 5 corresponds to a fourth sampling period.
[0053] Please refer to Figure 2 , Figure 2 A flowchart of a security detection method of an Internet of Things device provided in an embodiment of the present application is shown in Figure 2 , and the method comprises the following steps:
[0054] Step 210: Acquire device types of P Internet of Things devices. Wherein P is a positive integer.
[0055] In the embodiment of the present application, device types of P Internet of Things devices can be acquired by acquiring device information of the P Internet of Things devices. The device information of the Internet of Things device can include at least one of device configuration information, location, acquired data information type, and device signal of the Internet of Things device.
[0056] Step 220: determining M sampling periods of the P Internet of Things devices based on the device types. Wherein M is a positive integer. In the embodiments of the present application, the same device type corresponds to the same sampling period, and different device types correspond to different sampling periods. For example, there are 5 Internet of Things devices in the Internet of Things, wherein the device types of device 1 and device 2 are both type a, and it is determined that the sampling period of device 1 and device 2 is a first sampling period, and the device type of device 3 is device type b, and it is determined that the sampling period of device 3 is a second sampling period.
[0057] In the embodiments of the present application, the number of device types of the P Internet of Things devices is M, and the M device types correspond to the M sampling periods one by one.
[0058] Step 230: selecting a maximum sampling period from the M sampling periods.
[0059] Step 240: determining the maximum sampling period as the security detection period of the Internet of Things device.
[0060] In the embodiments of the present application, the security detection period of the Internet of Things device can be determined by the following formula:
[0061] ΔT = max{ΔT 1 , ΔT 2 , ΔT 3 ... ΔT M}
[0062] Wherein, ΔT is the security detection period of the Internet of Things device, ΔT 1 is the collection period corresponding to the first device type in the P Internet of Things devices, ΔT 2 is the collection period corresponding to the second device type in the P Internet of Things devices, ΔT 3 is the collection period corresponding to the third device type in the P Internet of Things devices, and ΔT M is the collection period corresponding to the Mth device type in the P Internet of Things devices.
[0063] Step 250: obtaining target data of the P Internet of Things devices in the security detection period. In the embodiments of the present application, after determining the security detection period of the Internet of Things device, the target data of the P Internet of Things devices in the security detection period is obtained, such as average CPU utilization, storage space occupancy, vulnerability impact value, number of vulnerabilities and the like.
[0064] Step 260: determining Q detection objects in the P Internet of Things devices based on the obtained target data. Wherein Q is less than P.
[0065] In the embodiment of the present application, the target risk value of each of the P Internet of Things devices can be calculated based on the obtained target data, and P target risk values are obtained; Q target risk values greater than a preset value are determined from the P target risk values; and the Q Internet of Things devices corresponding to the Q target risk values are determined as Q detection objects.
[0066] Step 270: performing security detection on the Q detection objects.
[0067] In the embodiment of the present application, after the Q detection objects are determined from the P Internet of Things devices, the traffic data of each of the Q detection objects is obtained, and the traffic data of each of the Q detection objects is detected to determine whether the traffic data is abnormal. If the traffic data is abnormal, it indicates that the detection object has a security risk, and a warning is given.
[0068] In the embodiment of the present application, the security detection period of the Internet of Things device is dynamically determined by comprehensively determining the M acquisition periods of the M types of Internet of Things devices in the P Internet of Things devices, the target data of the P Internet of Things devices in the security detection period is obtained according to the dynamically determined security detection period of the Internet of Things device, and the problem of resource waste caused by too dense acquisition period of target data of the Internet of Things device, or the problem of missing target data caused by too sparse acquisition period of target data is avoided.
[0069] In an embodiment of the present application, the M types of devices include perception-type devices; and the M sampling periods include a first sampling period. In the embodiment of the present application, the sampling period corresponding to the perception-type devices in the P Internet of Things devices is the first sampling period, and the first sampling period of the perception-type devices can be calculated according to the following formula:
[0070]
[0071] wherein, ΔT 1 is the first sampling period, T0 is a predefined standard period, i represents the i-th perception-type device in the P Internet of Things devices, I is the total number of the perception-type devices in the P Internet of Things devices, represents the security vulnerability influence value of the i-th perception-type device in the P Internet of Things devices, represents the number of security vulnerabilities of the i-th perception-type device in the P Internet of Things devices, the function is used to solve the number of types of data collection types of the perception-type devices in the P Internet of Things devices, represents the amount of single upload data of the i-th perception-type device in the P Internet of Things devices, represents the data transmission period of the i-th perception-type device in the P Internet of Things devices; i and P are positive integers; i is less than or equal to P.
[0072] In the embodiments of the present application, the sensing type of the sensing device can be determined The type is consistent with the type of the Internet of Things device, such as temperature, humidity, image, etc. For example, the sensing device is a microphone, and the type of the collected data is sound. Regardless of the type of the microphone, whether it collects human voice or environmental sound, it will be classified as sound. The type of the Internet of Things device is the attribute of the Internet of Things device itself. Therefore, the sensing type of the sensing device can be obtained by reading the attribute of the sensing Internet of Things device For the sensing Internet of Things device, the main work is to collect data and then transmit the data to the server. It can be realized by real-time transmission or periodic transmission. The data transmission period of the sensing device can be obtained. If it is real-time transmission, the data transmission period is a preset minimum value. The data transmission period is set when the sensing device is configured. Therefore, the data transmission period can be obtained by reading the configuration data of the sensing device The security vulnerability influence value of the sensing device can be determined And the number of security vulnerabilities The security vulnerability is a security vulnerability configured by the sensing device itself, such as a software vulnerability. The number can be obtained from the factory parameters of the sensing device and subsequent vulnerability information. If a certain software is configured at the factory, and it is subsequently announced that it still has a certain security vulnerability, then the security vulnerability data of the sensing device is increased by 1. In addition, when the security vulnerability of the sensing device is announced, the security vulnerability will be described, and the influence of the security vulnerability will be described. The influence of the security vulnerability can be read, and the security vulnerability influence value of the sensing device can be calculated In addition, the security vulnerability influence value And the number of security vulnerabilities The security vulnerability influence value And the number of security vulnerabilities The single upload data amount of each sensing device can also be determined Because the amount of data uploaded each time has some differences, the data amount of the present application is a theoretical average value. The unit data amount of the collected data can be obtained, multiplied by the collection period, and finally based on the pre-set compression rate to obtain a theoretical single upload data amount Based on the determined sensing type of the sensing device Data transmission period The security vulnerability influence value affect1 i, the security vulnerability quantity vulnerability1 i and the single upload data volume volume1 i are calculated for a first sampling period ΔT1.
[0073] In an embodiment of the present application, the M device types include application type devices, and the M sampling periods include a second sampling period. In the embodiment of the present application, the application type devices in the P Internet of Things devices correspond to the second sampling period, and the second sampling period of the application type devices can be calculated according to the following formula:
[0074]
[0075] Wherein, ΔT 2 is the second sampling period, T0 is a predefined standard period, j represents the jth application type device in the P Internet of Things devices, J is the total number of the application type devices in the P Internet of Things devices, affectj represents the security vulnerability influence value of the jth application type device in the P Internet of Things devices; vulnerabilityj represents the security vulnerability quantity of the jth application type device in the P Internet of Things devices; j and P are positive integers; j is less than or equal to P.
[0076] In the embodiment of the present application, the security vulnerability influence value affectj of the application type device can be determined according to the following formula: and the security vulnerability quantity vulnerabilityj can be determined according to the following formula: Wherein the security vulnerability is a security vulnerability configured by the application type device itself, such as a software vulnerability, and the quantity can be obtained from the factory parameters of the application type device and subsequent published vulnerability information. If a certain software is configured at the factory and subsequent published vulnerability information still exists a certain security vulnerability, then the security vulnerability data of the application type device is added by 1. In addition, when the security vulnerability of the application type device is published, the security vulnerability is described, and the influence of the security vulnerability is described. The influence of the security vulnerability can be read, and the security vulnerability influence value affectj of the application type device can be calculated according to the following formula: In addition, the security vulnerability influence value affectj and the security vulnerability quantity vulnerabilityj can also be obtained by using existing security vulnerability detection programs. For example, the hole detection program accesses the application type device through the Internet of Things network or other networks, detects the security vulnerability of the system and program on the Internet of Things device, and obtains the security vulnerability influence value affectj and the security vulnerability quantity vulnerabilityj.
[0077] In an embodiment of the present application, the M types of device types include network devices; and the M types of sampling periods include a third sampling period. In the embodiment of the present application, the network devices in the P Internet of Things devices correspond to the third sampling period, and the third sampling period of the application device can be calculated according to the following formula:
[0078]
[0079] wherein ΔT 3 is the third sampling period, T0 is a predefined standard period, k is a number representing the kth network device in the P Internet of Things devices, represents a security vulnerability impact value of the kth network device in the P Internet of Things devices, represents a probability of being attacked of the kth network device in the P Internet of Things devices, represents a total amount of Internet of Things devices that establish a connection relationship with the kth network device in the P Internet of Things devices; j and P are positive integers; j is less than or equal to P.
[0080] In the embodiment of the present application, the security vulnerability impact value of the network device can be determined as follows: wherein the security vulnerability is a security vulnerability configured by the network device itself, such as a software vulnerability, and the number can be obtained from the factory parameters of the network device and subsequent published vulnerability information. If a certain software is configured at the factory and subsequent published vulnerability information still exists a certain security vulnerability, it is considered that the security vulnerability data of the network device is added by 1. In addition, when the security vulnerability of the network device is published, the security vulnerability will be described, and the impact of the security vulnerability will be described. The impact of the security vulnerability can be read, and the security vulnerability impact value of the network device can be calculated as follows: In addition, the security vulnerability impact value can also be obtained by using an existing security vulnerability detection program. For example, the hole detection program accesses the network device through the Internet of Things network or other networks, detects the security vulnerability of the system and program on the Internet of Things device, and obtains the security vulnerability impact value The security vulnerability impact value of the network device The CVSS value of the security vulnerability of the network-type device can also be calculated. The CVSS value includes vulnerability information of a network-type operating system or other software, which can be obtained by a crawler or a vulnerability detection program. CVSS is an industry standard designed to measure the severity of security vulnerabilities and help determine the urgency and importance of the required response. Its main purpose is to help people establish a standard for measuring the severity of vulnerabilities, so that people can compare the severity of vulnerabilities and determine the priority of handling them. The CVSS value is based on measurements in a series of dimensions, which are called metrics. The CVSS value is 10 at most and 0 at least, wherein a security vulnerability of 7-10 is generally considered to be more serious, 4-6.9 is a medium security vulnerability, and 0-3.9 is a low security vulnerability. In a specific implementation, the CVSS value can also be obtained based on a vulnerability detection program. For example, the vulnerability detection program accesses the network-type device through the Internet of Things network or other network, detects vulnerabilities of the system, program, etc. on the network-type device, and after obtaining the vulnerability information, accesses a security vulnerability library (such as the National Vulnerability Database (NVD) of the United States) to obtain the CVSS value of each vulnerability. The attack log of the network of each network-type device can be obtained in the embodiment of the application, and the attack probability is determined according to the attack log For example, for the kth network-type device, the characteristics of each attack and the attack time are determined according to the attack log of the kth network-type device, the total number of attacks with the same characteristics is determined, and the probability of the attack occurring again is calculated for each attack. Specifically, for attack x, the probability of the attack occurring again is P x The probability can be calculated by the following formula:
[0081]
[0082] wherein n x is the total number of attacks with the characteristics of attack x, N is the total number of attacks, t x (1) is the attack time of the latest attack of attack x, is the average time difference between the adjacent two times of attack x, and the attack probability of the kth network-type device can be determined by the formula In the embodiment of the application, the total number of Internet of Things devices that establish a connection relationship with the kth network-type device in the P Internet of Things devices can also be determined For the kth network-type device, the Internet of Things devices that establish a communication connection with the kth network-type device can include network-type devices, perception-type devices, and application-type devices.
[0083] In an embodiment of the present application, the device types of the P Internet of Things devices are acquired, wherein the P Internet of Things devices only include one type of device among the network type device, the perception type device and the application type device, for example, the P Internet of Things devices are all network type devices, at this time, in the case that the P Internet of Things devices only include one device type, a sampling period corresponding to the device type to which the P Internet of Things devices currently belong is determined, and the sampling period corresponding to the device type to which the P Internet of Things devices currently belong is directly taken as the security detection period of the P Internet of Things devices. For example, in the case that the P Internet of Things devices are all network type devices, a third sampling period corresponding to the network type device is calculated, and the third sampling period is directly taken as the security detection period of the P Internet of Things devices.
[0084] In an embodiment of the present application, the device types of the P Internet of Things devices are acquired, wherein the P Internet of Things devices include any two types of devices among the network type device, the perception type device and the application type device, for example, there are perception type devices and network type devices in the P Internet of Things devices, at this time, in the case that the P Internet of Things devices include any two types of devices among the network type device, the perception type device and the application type device, sampling periods corresponding to all device types in the P Internet of Things devices are determined, and one sampling period is determined from the sampling periods corresponding to all device types in the P Internet of Things devices as the security detection period of the Internet of Things device. For example, in the case that there are perception type devices and network type devices in the P Internet of Things devices, a first sampling period corresponding to the perception type device and a third sampling period corresponding to the network type device are calculated, and one sampling period is determined from the first sampling period and the third sampling period as the security detection period of the Internet of Things device, for example, the sampling period with the largest value in the first sampling period and the third sampling period is taken as the security detection period of the Internet of Things device.
[0085] In an embodiment of the present application, the security detection period of the Internet of Things device dynamically changes with the change of the device type of the device contained in the Internet of Things. For example, the devices in the Internet of Things A are all network devices, the third sampling period corresponding to the network device is calculated, and the third sampling period is taken as the security detection period a of the device in the Internet of Things A. Since the security detection period a is determined by the third sampling period corresponding to the device type of the device in the Internet of Things A, the security detection period a is a security detection period more suitable for the actual situation of the Internet of Things A. However, in another Internet of Things B, there are sensing devices and network devices, the first sampling period corresponding to the sensing device and the third sampling period corresponding to the network device are calculated, and one of the first sampling period and the third sampling period is determined as the security detection period of the Internet of Things device, such as taking the sampling period with the largest value in the first sampling period and the third sampling period as the security detection period b of the Internet of Things device. At this time, the security detection period b is determined based on the first sampling period corresponding to the sensing device and the third sampling period corresponding to the network device existing in the Internet of Things B, and thus the security detection period b is a security detection period more suitable for the actual situation of the Internet of Things B.
[0086] Please refer to Figure 3 , Figure 3 A flowchart of a security detection method of an Internet of Things device provided by an embodiment of the present application is shown in Figure 3 , and the method comprises the following steps:
[0087] Step 310: Obtain the device type of P Internet of Things devices. Wherein P is a positive integer.
[0088] In an embodiment of the present application, the device type of the P Internet of Things devices can be obtained by obtaining the device information of the P Internet of Things devices. The device information of the Internet of Things device can include at least one of the device configuration information, the location, the obtained data information type, and the device signal of the Internet of Things device.
[0089] Step 320: Determine M sampling periods of the P Internet of Things devices based on the device type. Wherein M is a positive integer. In an embodiment of the present application, the same device type corresponds to the same sampling period, and different device types correspond to different sampling periods. For example, in the Internet of Things, there are five Internet of Things devices, wherein the device type of device 1 and device 2 is type a, and the sampling period of device 1 and device 2 is determined as the first sampling period, and the device type of device 3 is device type b, and the sampling period of device 3 is determined as the second sampling period.
[0090] In an embodiment of the present application, the number of device types of the P Internet of Things devices is M, and the M device types correspond to the M sampling periods one by one.
[0091] Step 330: determining at least one sampling period from the M sampling periods as a security detection period of the Internet of Things device. Specifically, the maximum sampling period can be selected from the M sampling periods; and the maximum sampling period is determined as the security detection period of the Internet of Things device.
[0092] Step 340: obtaining target data of the P Internet of Things devices in the security detection period. In the embodiment of the present application, after the security detection period of the Internet of Things device is determined, the target data of each of the P Internet of Things devices in the security detection period is obtained, such as average CPU utilization, storage space occupancy, vulnerability impact value, number of vulnerabilities, and the like.
[0093] Step 350: calculating a target risk value of each of the P Internet of Things devices based on the obtained target data, to obtain P target risk values.
[0094] In the embodiment of the present application, the target risk value is calculated by the following formula:
[0095]
[0096] wherein, S u is the target risk value of the u-th Internet of Things device in the P Internet of Things devices, is the vulnerability impact of the u-th Internet of Things device in the P Internet of Things devices, is the average processing capacity of the u-th Internet of Things device in the P Internet of Things devices in the current security detection period, is the average processing capacity of the u-th Internet of Things device in the P Internet of Things devices in the historical security detection period, is the vulnerability impact value of the v-th Internet of Things device connected to the u-th Internet of Things device in the P Internet of Things devices, V is the total number of Internet of Things devices connected to the u-th Internet of Things device; u, v, V are all positive integers; u, v are less than or equal to P, u≠v; and the vulnerability impact value of the v-th Internet of Things device connected to the u-th Internet of Things device in the P Internet of Things devices is calculated by the following formula wherein, is the vulnerability impact of the v-th Internet of Things device connected to the u-th Internet of Things device in the P Internet of Things devices, δ is a flag value, if the v-th Internet of Things device connected to the u-th Internet of Things device is of the same device type as the u-th Internet of Things device, then δ=1, and if not, δ=V.
[0097] Step 360: determining Q target risk values greater than a preset value from the P target risk values;
[0098] Step 370: determining Q target risk values corresponding to Q target objects.
[0099] Step 380: performing security detection on the Q target objects.
[0100] In the embodiment of the present application, after determining the Q target objects from the P Internet of Things devices, the traffic data of each of the Q target objects is obtained, and the traffic data of each of the Q target objects is detected to determine whether the traffic data is abnormal. If the traffic data is abnormal, it indicates that the target object has a security risk, and a warning is given.
[0101] In the embodiment of the present application, at least one sampling period is determined from the M sampling periods dynamically generated based on the device types of the P Internet of Things devices as a security detection period of the Internet of Things device. The target risk value of each of the P Internet of Things devices is calculated based on the target data of the P Internet of Things devices in the security detection period, and P target risk values are obtained. Q target risk values greater than a preset value are determined as Q target objects corresponding to the Q target risk values. The Q target objects that are vulnerable to attacks and have high target risk values are detected for security, so as to reduce the waste of resources caused by collecting data information and performing security detection by reducing the number of devices that need to be detected for security.
[0102] Please refer to Figure 4 , Figure 4 The flowchart of the security detection method of the Internet of Things device provided in the embodiment of the present application is shown in Figure 4 The method comprises the following steps:
[0103] Step 410: obtaining the device types of the P Internet of Things devices. Wherein, P is a positive integer.
[0104] In the embodiment of the present application, the device types of the P Internet of Things devices can be obtained by obtaining the device information of the P Internet of Things devices. The device information of the Internet of Things device can include at least one of the device configuration information, the location, the type of obtained data information, and the device signal of the Internet of Things device.
[0105] Step 413: in the case where the device types include perception devices, calculating a first sampling period of the perception devices.
[0106] In the embodiment of the present application, the sampling period corresponding to the perception devices in the P Internet of Things devices is the first sampling period, and the first sampling period of the perception devices can be calculated according to the following formula:
[0107]
[0108] Wherein, ΔT 1The first sampling period is defined as T0, which is a predefined standard period. i represents the i-th sensing device among the P IoT devices, and I is the total number of sensing devices among the P IoT devices. This represents the impact value of the security vulnerability of the i-th sensing device among the P IoT devices. This represents the number of security vulnerabilities in the i-th sensing device among the P IoT devices. The function is used to calculate the number of types of data collected by the sensing devices among the P IoT devices. This represents the amount of data uploaded in a single operation by the i-th sensing device among the P IoT devices. This represents the data transmission cycle of the i-th sensing device among the P IoT devices; i and P are both positive integers; i is less than or equal to P.
[0109] In this embodiment of the application, the sensing type under the sensing device can be determined. For example, data types such as temperature, humidity, and images are consistent with the IoT device type. For instance, if a sensing device is a microphone, then its collected data type is sound, regardless of the microphone type or whether it collects human voices or ambient sounds. The IoT device type is an inherent attribute of the IoT device itself; therefore, by reading the attributes of a sensing IoT device, the sensing type under that sensing device can be obtained. For sensing-type IoT devices, their main function is to collect data and transmit it to the server. This can be achieved through real-time transmission or periodic transmission. The data transmission period of the sensing device can be obtained; if it is real-time transmission, the data transmission period is a preset minimum value. The data transmission period is set during the configuration of the sensing device; therefore, the data transmission period can be obtained by reading the configuration data of the sensing device. The impact of security vulnerabilities in sensing devices can be determined. and the number of security vulnerabilities The security vulnerabilities listed refer to inherent security flaws in the sensing devices themselves, such as software vulnerabilities. This number can be obtained from the device's factory specifications and subsequently released vulnerability information. If a software component pre-configured at the factory is later found to have a security vulnerability, the security vulnerability count for that sensing device is incremented by one. Furthermore, when security vulnerabilities in sensing devices are disclosed, a description of the vulnerability and its impact is provided. This impact can be read and the security vulnerability impact value for that sensing device can be calculated. In addition, the impact of security vulnerabilities and the number of security vulnerabilities The security vulnerability influence value can also be obtained by an existing security vulnerability detection program. For example, the hole detection program accesses the sensing device through an Internet of Things network or other network, performs vulnerability detection on a system, program, or the like on the Internet of Things device, and obtains the security vulnerability influence value and the security vulnerability quantity The single upload data quantity of each sensing device can also be determined Because the data quantity uploaded each time has some differences, the data quantity of the present application is a theoretical average value. The unit data quantity of collected data is obtained, multiplied by the collection period, and finally a theoretical single upload data quantity is obtained based on a pre-set compression rate based on the determined sensing type of the sensing device data transmission period security vulnerability influence value security vulnerability quantity and single upload data quantity The first sampling period ΔT is calculated 1 .
[0110] Step 416: In the case where the device type includes an application device, the second sampling period of the application device is calculated.
[0111] In the embodiment of the present application, the sampling period of the application device in the P Internet of Things devices is the second sampling period. The second sampling period of the application device can be calculated according to the following formula:
[0112]
[0113] wherein ΔT 2 is the second sampling period, T0 is a pre-defined standard period, j represents the jth application device in the P Internet of Things devices, J is the total number of the application devices in the P Internet of Things devices, represents the security vulnerability influence value of the jth application device in the P Internet of Things devices; represents the security vulnerability quantity of the jth application device in the P Internet of Things devices; j and P are positive integers; j is less than or equal to P.
[0114] In the embodiment of the present application, the security vulnerability influence value of the application device and the security vulnerability quantity Wherein the security vulnerability is a security vulnerability of the application-type device itself, such as a software vulnerability, and the number can be obtained from the application-type device factory parameter and subsequent published vulnerability information. If a certain software is configured at the factory and subsequent published information still exists a certain security vulnerability, the security vulnerability data of the application-type device is added by 1. In addition, when publishing the security vulnerability of the application-type device, the security vulnerability is described, and the influence of the security vulnerability is described. The influence of the security vulnerability can be read, and the security vulnerability influence value of the application-type device is calculated In addition, the security vulnerability influence value And the security vulnerability number Can also be obtained by the existing security vulnerability detection program. For example, the hole detection program accesses the application-type device through the Internet of Things network or other network, detects the security vulnerability of the system and program on the Internet of Things device, obtains the security vulnerability influence value And the security vulnerability number
[0115] Step 419: In the case where the device type includes a network-type device, the third sampling period of the network-type device is calculated.
[0116] In the embodiment of the present application, the sampling period of the network-type device in the P Internet of Things devices is the third sampling period, and the third sampling period of the application-type device can be calculated according to the following formula:
[0117]
[0118] Wherein, ΔT 3 The third sampling period, T0 is a pre-defined standard period, k represents the kth network-type device in the P Internet of Things devices, Indicates the security vulnerability influence value of the kth network-type device in the P Internet of Things devices, Indicates the probability of being attacked of the kth network-type device in the P Internet of Things devices, Indicates the total amount of Internet of Things devices establishing a connection relationship with the kth network-type device in the P Internet of Things devices; j, P are positive integers; j is less than or equal to P.
[0119] In the embodiment of the present application, the security vulnerability influence value of the network-type device can be determined The security vulnerability is a security vulnerability of the network device itself, such as a software vulnerability, and the number can be obtained from the network device factory parameters and subsequent published vulnerability information. If a certain software is configured at the factory and a certain security vulnerability still exists in the subsequent public disclosure, the security vulnerability data of the network device is increased by 1. In addition, when the security vulnerability of the network device is disclosed, the security vulnerability is described, and the influence of the security vulnerability is described. The influence of the security vulnerability can be read, and the security vulnerability influence value of the network device is calculated In addition, the security vulnerability influence value The security vulnerability influence value can also be obtained by the existing security vulnerability detection program. For example, the hole detection program accesses the network device through the Internet of Things network or other network, detects the security vulnerability of the system and program on the network device, and obtains the security vulnerability influence value The security vulnerability influence value of the network device The security vulnerability influence value of the network device can also be calculated by the Common Vulnerability Scoring System (CVSS) value of the security vulnerability of the network device. The Common Vulnerability Scoring System value includes vulnerability information of the network operating system or other software, which can be obtained by crawling or by the existing vulnerability detection program. CVSS is an industry standard designed to measure the severity of security vulnerabilities and help determine the urgency and importance of the required response. Its main purpose is to help people establish a standard for measuring the severity of vulnerabilities, so that people can compare the severity of vulnerabilities and determine their priority. The CVSS value is based on measurements in a series of dimensions, which are called metrics. The maximum CVSS value is 10, and the minimum is 0. Security vulnerabilities with a CVSS value of 7-10 are generally considered serious, 4-6.9 are moderate security vulnerabilities, and 0-3.9 are low security vulnerabilities. In specific implementation, the CVSS value can also be obtained based on the vulnerability detection program. For example, the hole detection program accesses the network device through the Internet of Things network or other network, detects the security vulnerability of the system and program on the network device, obtains the vulnerability information, and then accesses the security vulnerability library (such as the National Vulnerability Database (NVD) in the United States) to obtain the CVSS value of each vulnerability. The embodiment of the application can obtain the attack log of the network of each network device, and determine the attack probability according to the attack log For example, for the kth network device, the characteristics of each attack and the attack time are determined according to the attack log of the kth network device, the total number of attacks with the same characteristics is determined, and the probability of the attack occurring again is calculated for each attack. Specifically, for attack x, the probability of the attack occurring again is P x The probability can be calculated by the following formula:
[0120]
[0121] wherein n x is the total number of attacks with the characteristic x, N is the total number of attacks, t x (1) is the time of the last attack of x, is the average time difference between the two adjacent attacks of x, and the kth network class device attack probability can be determined by formula In the embodiments of the present application, the total number of Internet of Things devices that establish a connection relationship with the kth network class device in the P Internet of Things devices can also be determined For the kth network class device, the Internet of Things devices that establish a communication connection with it can include network class devices, perception class devices and application class devices.
[0122] Step 422: Select the maximum sampling period from the first sampling period, the second sampling period and the third sampling period.
[0123] Step 425: Determine the maximum sampling period as the security detection period of the Internet of Things device.
[0124] In the embodiments of the present application, the security detection period of the Internet of Things device can be determined by the following formula:
[0125] ΔT=max{ΔT 1 ,ΔT 2 ,ΔT 3}
[0126] wherein ΔT is the security detection period of the Internet of Things device, ΔT 1 is the first sampling period in the P Internet of Things devices, ΔT 2 is the second sampling period in the P Internet of Things devices, and ΔT 3 is the third sampling period in the P Internet of Things devices.
[0127] Step 428: Obtain the target data of the P Internet of Things devices in the security detection period. In the embodiments of the present application, after determining the security detection period of the Internet of Things device, the target data of the P Internet of Things devices in the security detection period, such as average CPU utilization, storage space occupancy, vulnerability impact value, number of vulnerabilities and the like, are obtained.
[0128] Step 431: Based on the obtained target data, calculate the target risk value of each of the P Internet of Things devices to obtain P target risk values.
[0129] In the embodiments of the present application, the target risk value is calculated by the following formula:
[0130]
[0131] wherein S u is a target risk value of a u-th Internet of Things device in the P Internet of Things devices, is a vulnerability influence of a u-th Internet of Things device in the P Internet of Things devices, is an average processing capacity of a u-th Internet of Things device in the P Internet of Things devices in a current security detection period, is an average processing capacity of a u-th Internet of Things device in the P Internet of Things devices in a historical security detection period, is a vulnerability influence value of a v-th Internet of Things device in a connection relationship with the u-th Internet of Things device in the P Internet of Things devices, V is a total amount of Internet of Things devices in a connection relationship with the u-th Internet of Things device; u, v, V are all positive integers; u, v are less than or equal to P, u≠v; and the vulnerability influence value of the v-th Internet of Things device in a connection relationship with the u-th Internet of Things device in the P Internet of Things devices is calculated by the following formula wherein is a vulnerability influence of a v-th Internet of Things device in a connection relationship with a u-th Internet of Things device in the P Internet of Things devices, and δ is a flag value, δ=1 if the v-th Internet of Things device in a connection relationship with the u-th Internet of Things device is of the same device type as the u-th Internet of Things device, and δ=V if not.
[0132] Step 434: determining Q target risk values greater than a preset value from the P target risk values. For example, as described in step 431, the target risk values of the three Internet of Things devices are calculated, wherein the target risk value of device A is 20, the target risk value of device B is 60, and the target risk value of device C is 80, and the preset value is set to 75, so the target risk value of device C greater than the preset value 75 is screened out.
[0133] Step 437: determining the Q Internet of Things devices corresponding to the Q target risk values as Q detection objects. For example, as described in the example below step 434, the target risk value of device C greater than the preset value 75 is screened out, and then device C with the target risk value greater than the preset value 75 is determined as a detection object.
[0134] Step 440: performing security detection on the Q detection objects.
[0135] In the embodiments of the present application, after determining the Q detection objects from the P Internet of Things devices, the traffic data of the Q detection objects is obtained, and the traffic data of the Q detection objects is detected to determine whether the traffic data is abnormal, and if abnormal, it indicates that the detection object has a security risk and a warning is given.
[0136] In the embodiment of the present application, after determining Q detection objects from P Internet of Things devices, the traffic information of the Q detection objects can be acquired. The traffic information is all data of the detection objects in downlink and uplink, for example, packet information and network information, wherein the packet information describes the relevant information of each packet, such as packet identifier, data direction (uplink), involved port, IP address, etc.; the network information describes the overall situation in the data transmission process, such as packet loss rate, maximum number of connections at the same time, traffic trend. All packets of a detection object are taken as the traffic information of the detection object, and the information of each packet is taken as a piece of data in the collected data. For example, for a packet A, the collected information is: identifier of the packet A, source IP, destination IP, source port, destination port, packet size, transmission start time, transmission end time, packet loss rate, maximum number of connections at the same time, traffic trend, etc. The traffic data of the detection objects is subjected to security detection, and if the traffic data of the detection object is abnormal, it indicates that the detection object has a security risk, and a warning is given.
[0137] In the embodiment of the present application, the device types of P Internet of Things devices are acquired; based on the device types, M sampling periods of the P Internet of Things devices are determined; M is a positive integer; the same device type corresponds to the same sampling period, and different device types correspond to different sampling periods; at least one sampling period is determined from the M sampling periods as a security detection period of the Internet of Things device; target data of the P Internet of Things devices in the security detection period is acquired; based on the acquired target data, Q detection objects in the P Internet of Things devices are determined; Q is less than P; the Q detection objects are subjected to security detection. In this way, at least one sampling period is determined from the M sampling periods dynamically generated based on the device types of the P Internet of Things devices as a security detection period of the Internet of Things device, the target data of the P Internet of Things devices in the security detection period is acquired, Q detection objects with a number less than P are determined from the P Internet of Things devices, and the Q detection objects are subjected to security detection, so as to reduce the waste of resources caused by collecting data information and performing security detection in the way of reducing the number of devices subjected to security detection.
[0138] Figure 5 is a structural block diagram of a security detection device 500 of an Internet of Things device provided in the embodiment of the present application. Referring to Figure 5 , the security detection device 500 of the Internet of Things device provided in the embodiment of the present application comprises:
[0139] The acquisition module 510 is configured to acquire the device types of P Internet of Things devices.
[0140] The determining module 520 is configured to determine M sampling periods of the P Internet of Things devices based on the device types; M is a positive integer; the same device type corresponds to the same sampling period, and different device types correspond to different sampling periods.
[0141] The determining module 520 is further configured to determine at least one sampling period from the M sampling periods as a security detection period of the Internet of Things device.
[0142] The obtaining module 510 is further configured to obtain target data of the P Internet of Things devices in the security detection period.
[0143] The determining module 520 is further configured to determine Q detection objects from the P Internet of Things devices based on the obtained target data; Q is less than P.
[0144] The detecting module 530 is configured to perform security detection on the Q detection objects.
[0145] In the embodiments of the present application, the device types of P Internet of Things devices are obtained; M sampling periods of the P Internet of Things devices are determined based on the device types; M is a positive integer; the same device type corresponds to the same sampling period, and different device types correspond to different sampling periods; at least one sampling period is determined from the M sampling periods as a security detection period of the Internet of Things device; target data of the P Internet of Things devices in the security detection period is obtained; Q detection objects from the P Internet of Things devices are determined based on the obtained target data; Q is less than P; and security detection is performed on the Q detection objects. In this way, at least one sampling period is determined from the M sampling periods dynamically generated based on the device types of the P Internet of Things devices as a security detection period of the Internet of Things device, Q detection objects with a number less than P are determined from the P Internet of Things devices based on the target data of the P Internet of Things devices in the security detection period, and security detection is performed on the Q detection objects, so as to reduce resource waste caused by data information collection and security detection in the manner of reducing the number of devices that need to be subjected to security detection.
[0146] In an embodiment of the present application, the number of device types of the P Internet of Things devices is M, and M device types correspond to M sampling periods one by one.
[0147] In an embodiment of the present application, in the process of determining at least one sampling period from the M sampling periods as a security detection period of the Internet of Things device, the determining module 520 is specifically configured to: select a maximum sampling period from the M sampling periods; and determine the maximum sampling period as the security detection period of the Internet of Things device.
[0148] In an embodiment of the present application, the M types of device types include perception-type devices; the M types of sampling periods include a first sampling period; in the process of determining the M types of sampling periods of the P Internet of Things devices based on the device types, the determining module 520 is specifically configured to calculate the first sampling period of the perception-type devices according to the following formula:
[0149]
[0150] wherein ΔT 1 is the first sampling period, T0 is a predefined standard period, i represents an i-th perception-type device in the P Internet of Things devices, I is a total number of the perception-type devices in the P Internet of Things devices, affect 1 i represents a security vulnerability influence value of the i-th perception-type device in the P Internet of Things devices, vulnerability 1 i represents a number of security vulnerabilities of the i-th perception-type device in the P Internet of Things devices, volume is a function for solving a type number of data types collected by the perception-type devices in the P Internet of Things devices, volume 1 i represents a single upload data volume of the i-th perception-type device in the P Internet of Things devices, period 1 i represents a data transmission period of the i-th perception-type device in the P Internet of Things devices; i and P are positive integers; i is less than or equal to P.
[0151] In an embodiment of the present application, the M types of device types include application-type devices; the M types of sampling periods include a second sampling period; in the process of determining the M types of sampling periods of the P Internet of Things devices based on the device types, the determining module 520 is specifically configured to calculate the second sampling period according to the following formula:
[0152]
[0153] wherein ΔT 2 is the second sampling period, T0 is a predefined standard period, j represents a j-th application-type device in the P Internet of Things devices, J is a total number of the application-type devices in the P Internet of Things devices, represents a security vulnerability influence value of the j-th application-type device in the P Internet of Things devices; j and P are positive integers; j is less than or equal to P.
[0154] In an embodiment of the present application, the M types of device types include network devices; the M types of sampling periods include a third sampling period; in the process of determining the M types of sampling periods of the P Internet of Things devices based on the device types, the determination module 520 is specifically configured to: calculate the third sampling period according to the following formula:
[0155]
[0156] wherein, ΔT 3 is the third sampling period, T0 is a predefined standard period, k represents the kth network device in the P Internet of Things devices, affect 3 k represents the security vulnerability influence value of the kth network device in the P Internet of Things devices, P 3 k represents the probability of being attacked of the kth network device in the P Internet of Things devices, represents the total amount of Internet of Things devices that establish a connection relationship with the kth network device in the P Internet of Things devices; j and P are positive integers; j is less than or equal to P.
[0157] In an embodiment of the present application, in the process of determining the Q detection objects in the P Internet of Things devices based on the obtained target data, the determination module 520 is specifically configured to:
[0158] based on the obtained target data, calculate the target risk value of each of the P Internet of Things devices to obtain P target risk values;
[0159] determine Q target risk values greater than a preset value from the P target risk values;
[0160] determine the Q Internet of Things devices corresponding to the Q target risk values as the Q detection objects;
[0161] wherein, the target risk value is calculated by the following formula:
[0162]
[0163] wherein, S u is the target risk value of the uth Internet of Things device in the P Internet of Things devices, is the vulnerability influence of the uth Internet of Things device in the P Internet of Things devices, is the average processing capacity of the uth Internet of Things device in the P Internet of Things devices in the current security detection period, is the average processing capacity of the uth Internet of Things device in the P Internet of Things devices in the historical security detection period, a vulnerability influence value of a vth Internet of Things device for establishing a connection relationship with a u th Internet of Things device in the P Internet of Things devices, V is a total quantity of Internet of Things devices for establishing a connection relationship with the u th Internet of Things device; u, v, V are all positive integers; u, v are less than or equal to P, and u≠v.
[0164] As shown in Figure 6 The electronic device 600 can be various types of computers and the like. The electronic device 600 includes a processor 610 and a memory 620. The memory 620 stores programs or instructions, which are executed by the processor 610 to implement the steps of any of the methods described above. For example, the programs are executed by the processor 610 to implement the following processes: obtaining device types of P Internet of Things devices; determining M sampling periods of the P Internet of Things devices based on the device types; M is a positive integer; the same device type corresponds to the same sampling period, and different device types correspond to different sampling periods; determining at least one sampling period from the M sampling periods as a security detection period of the Internet of Things device; obtaining target data of the P Internet of Things devices in the security detection period; determining Q detection objects in the P Internet of Things devices based on the obtained target data; Q is less than P; and performing security detection on the Q detection objects. In this way, at least one sampling period is determined from the M sampling periods dynamically generated based on the device types of the P Internet of Things devices as a security detection period of the Internet of Things device, Q detection objects with a quantity less than P are determined in the P Internet of Things devices based on target data of the P Internet of Things devices in the security detection period, and security detection is performed on the Q detection objects, thereby reducing the quantity of devices that need to be subjected to security detection, and achieving the purpose of reducing resource waste caused by data information collection and security detection.
[0165] The readable storage medium stores programs or instructions, which are executed by a processor to implement the steps of the security detection method of the Internet of Things device provided in any of the embodiments above, and achieve the same technical effects. To avoid repetition, details are not described herein.
[0166] The processor is the processor in the electronic device in the above embodiments. The readable storage medium includes a computer readable storage medium, such as a computer readable only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and the like.
[0167] The embodiment of the present application further provides a chip, which comprises a processor and a communication interface, the communication interface is coupled with the processor, the processor is used for running programs or instructions, realizes various processes of the above method embodiments, and can achieve the same technical effects, to avoid repetition, which will not be described here.
[0168] The embodiment of the present application provides a computer program product, which is stored in a storage medium, and the program product is executed by at least one processor to realize various processes of the above method embodiments and can achieve the same technical effects, to avoid repetition, which will not be described here.
[0169] It should be noted that in this paper, the term "including", "containing" or any other variant thereof is intended to cover non-exclusive inclusion, so that the process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed or inherent to such process, method, article or device. Without more limitations, the element defined by the statement "including a" does not exclude the presence of other identical elements in the process, method, article or device including the element. In addition, it should be pointed out that the scope of the method and device in the present application is not limited to the order of the functions shown or discussed, but also includes the functions performed in a substantially simultaneous manner or in the opposite order, for example, the described method can be performed in a different order from the described order, and various steps can also be added, omitted or combined. In addition, the features described with reference to some examples can be combined in other examples.
[0170] From the above description of the embodiments, those skilled in the art can clearly understand that the above embodiment method can be realized by software and necessary general hardware platform, of course, it can also be realized by hardware, but in many cases, the former is a better embodiment. Based on such understanding, the technical solutions of the present application can be embodied in the form of a computer software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), including a plurality of instructions for making a terminal (which can be a mobile phone, computer, server, or network equipment, etc.) execute the method described in each embodiment of the present application.
[0171] The embodiments of the present application are described above in combination with the drawings, but the present application is not limited to the above specific embodiments, the above specific embodiments are only illustrative, not restrictive, and those skilled in the art can make many forms under the inspiration of the present application without departing from the scope of the present application and the protection scope of the claims.
Claims
1. A security detection method for Internet of Things (IoT) devices, characterized in that, include: Obtain the device types of P IoT devices; Based on the device type, M sampling periods are determined for the P IoT devices; M is a positive integer; the same device type corresponds to the same sampling period, and different device types correspond to different sampling periods; At least one sampling period is determined from the M sampling periods as the security detection period of the Internet of Things device; Obtain the target data of the P IoT devices within the security detection period; Based on the acquired target data, Q detection objects are determined from the P IoT devices; Q is less than P; Q and P are both positive integers; Security checks are performed on the Q objects to be detected.
2. The method according to claim 1, characterized in that, The number of device types among the P IoT devices is M, and the M device types correspond one-to-one with the M sampling periods.
3. The method according to claim 1 or 2, characterized in that, Determining at least one sampling period from the M sampling periods as the security detection period for the IoT device includes: Select the largest sampling period from the M sampling periods; The maximum sampling period is determined as the security detection period of the IoT device.
4. The method according to claim 2, characterized in that, The M device types include sensing devices; the M sampling periods include a first sampling period; determining the M sampling periods for the P IoT devices based on the device types includes: The first sampling period of the sensing device is calculated using the following formula: Where, ΔT 1 The first sampling period is defined as T0, which is a predefined standard period. i represents the i-th sensing device among the P IoT devices, and I is the total number of sensing devices among the P IoT devices. This represents the impact value of the security vulnerability of the i-th sensing device among the P IoT devices. This represents the number of security vulnerabilities in the i-th sensing device among the P IoT devices. The function is used to calculate the number of types of data collected by the sensing devices among the P IoT devices. This represents the amount of data uploaded in a single operation by the i-th sensing device among the P IoT devices. This represents the data transmission cycle of the i-th sensing device among the P IoT devices; i and P are both positive integers; i is less than or equal to P.
5. The method according to claim 2, characterized in that, The M device types include application-type devices; the M sampling periods include a second sampling period; determining the M sampling periods for the P IoT devices based on the device types includes: The second sampling period is calculated using the following formula: Where, ΔT 2 The second sampling period is defined as T0, which is a predefined standard period, j represents the j-th application-type device among the P IoT devices, and J is the total number of application-type devices among the P IoT devices. This represents the impact value of the security vulnerability of the j-th application-type device among the P IoT devices; This represents the number of security vulnerabilities in j application-type devices among the P IoT devices; j and P are both positive integers; j is less than or equal to P.
6. The method according to claim 2, characterized in that, The M device types include network devices; the M sampling periods include a third sampling period; determining the M sampling periods for the P IoT devices based on the device types includes: The third sampling period is calculated using the following formula: Where, ΔT 3 The third sampling period is defined as T0, which is a predefined standard period, and k represents the kth network-type device among the P IoT devices. This represents the impact value of the security vulnerability of the k-th network device among the P IoT devices. This represents the probability that the k-th network device among the P IoT devices is attacked. This represents the total number of IoT devices among the P IoT devices that have established a connection with the kth network device; k and P are both positive integers; k is less than or equal to P.
7. The method according to any one of claims 1-6, characterized in that, The step of determining Q detection objects from the P IoT devices based on the acquired target data includes: Based on the acquired target data, the target risk value of each of the P IoT devices is calculated to obtain P target risk values. From the P target risk values, determine Q target risk values that are greater than a preset value; The Q IoT devices corresponding to the Q target risk values are identified as the Q detection objects; The target risk value is calculated using the following formula: Among them, S u Let be the target risk value of the u-th IoT device among the P IoT devices. Let u be the vulnerability impact value of the u-th IoT device among the P IoT devices. Let u be the average processing power of the u-th IoT device among the P IoT devices during the current security detection cycle. Let u be the average processing power of the u-th IoT device among the P IoT devices over the historical security detection period. The vulnerability impact value of the vth IoT device that establishes a connection with the uth IoT device out of the P IoT devices is given by V, where V is the total number of IoT devices that establish a connection with the uth IoT device; u, v, and V are all positive integers; u and v are both less than or equal to P, and u ≠ v; the vulnerability impact value of the vth IoT device that establishes a connection with the uth IoT device out of the P IoT devices is calculated using the following formula. in, Let δ be the vulnerability impact value of the vth IoT device that establishes a connection with the uth IoT device among the P IoT devices. δ is a flag value. If the vth IoT device that establishes a connection with the uth IoT device has the same device type as the uth IoT device, then δ = 1. If they are different, then δ = V.
8. A security detection device for Internet of Things (IoT) devices, characterized in that, include: The acquisition module is used to acquire the device types of P IoT devices; The determining module is used to determine M sampling periods for the P IoT devices based on the device type; M is a positive integer; the same device type corresponds to the same sampling period, and different device types correspond to different sampling periods; The determining module is further configured to determine at least one sampling period from the M sampling periods as the security detection period of the Internet of Things device; The acquisition module is also used to acquire target data of the P IoT devices within the security detection period; The determining module is further configured to determine Q detection objects among the P IoT devices based on the acquired target data; Q is less than P; The detection module is used to perform security detection on the Q detection objects.
9. An electronic device, characterized in that, It includes a processor and a memory, the memory storing a program or instructions that run on the processor, the program or instructions which, when executed by the processor, implement the steps of the method as described in any one of claims 1-7.
10. A computer-readable storage medium, characterized in that, The medium stores a program or instructions that, when executed, implement the steps of the method as described in any one of claims 1-7.
11. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements the steps of the method according to any one of claims 1-7.
Citation Information
Patent Citations
Parallel detection method and device of Internet of Things terminal
CN115988547A
Equipment management method and device, storage medium and electronic equipment
CN116600153A