Abnormality determination method and device for internet of things card, equipment and medium
By using ETL data processing and pre-defined rule analysis, IoT card anomalies are identified, solving the problems of misjudgment and timeliness in IoT card anomaly monitoring, and ensuring the security and controllability of IoT cards.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CHINA UNITED NETWORK COMM GRP CO LTD
- Filing Date
- 2024-08-19
- Publication Date
- 2026-04-21
AI Technical Summary
Existing technologies are prone to misjudging internal test data as abnormal data in IoT card anomaly monitoring, and cannot detect and resolve problems in a timely manner, resulting in insufficient security and controllability.
The data from IoT cards is integrated into the data to be tested through ETL data processing. The behavioral data is analyzed according to preset rules to identify abnormal IoT cards, and the accuracy is ensured through whitelists and review mechanisms.
It enables timely identification and handling of IoT card anomalies, improving security and controllability, and protecting users' legitimate rights and interests.
Smart Images

Figure CN118921297B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of Internet of Things (IoT) cards, specifically to a method, apparatus, device, and medium for determining anomalies in IoT cards. Background Technology
[0002] With continuous technological innovation, IoT cards have developed rapidly and are widely used in daily life, bringing many conveniences to people. However, this development is also accompanied by certain security risks. Therefore, ensuring the security, controllability, and compliant operation of IoT cards, and promptly identifying their abnormal states, is particularly important.
[0003] In existing technologies, data from various nodes of the system are often integrated. When an anomaly is detected, abnormal data is extracted from each node, analyzed and processed according to preset rules, and the anomaly problem corresponding to the abnormal data is resolved based on the analysis results.
[0004] However, by first extracting abnormal data from the data of each node and then analyzing and processing the abnormal data, it is highly likely that internal test data will be treated as abnormal data, and problems cannot be detected and resolved in a timely manner during the entire anomaly monitoring process. Summary of the Invention
[0005] This application provides a method, apparatus, device, and medium for determining abnormalities in Internet of Things (IoT) cards, which are used to determine abnormal situations of IoT cards, strengthen the security management of IoT cards, and protect the legitimate rights and interests of users.
[0006] In a first aspect, embodiments of this application provide a method for determining anomalies in IoT cards, comprising: acquiring initial data sent by an upstream device, wherein the initial data is data corresponding to multiple IoT cards; performing ETL data processing on the initial data to obtain data to be detected, wherein the data to be detected includes: behavioral data of the multiple IoT cards; analyzing and processing the behavioral data of the multiple IoT cards according to preset rules to obtain anomaly results, and determining an abnormal IoT card from the multiple IoT cards based on the anomaly results, wherein the anomaly results are used to indicate whether the behavior of the corresponding IoT card is abnormal.
[0007] In one possible implementation, the above-mentioned ETL data processing of the initial data to obtain the data to be tested includes: determining and removing duplicate data from the data corresponding to the multiple IoT cards based on the business content; filling or discarding empty and dirty data in the data corresponding to the multiple IoT cards to obtain processed IoT card data; and converting the IoT card data if the data format and / or type of the IoT card data are inconsistent to obtain the data to be tested.
[0008] In one possible implementation, the above-described conversion processing of the IoT card data to obtain the data to be detected includes: converting the IoT card data and storing the converted IoT card data in a first data warehouse layer; filtering the data in the first data warehouse layer according to business rules to obtain first filtered data and storing the first filtered data in a second data warehouse layer; and filtering the first filtered data in the second data warehouse layer based on whitelist parameters to obtain the data to be detected.
[0009] In one possible implementation, the behavioral data includes: a package identifier and the package fee corresponding to the package identifier. The behavioral data of the multiple IoT cards are analyzed and processed according to preset rules to obtain anomaly results, including: for any one of the multiple IoT cards, determining whether the package identifier in the behavioral data of the IoT card matches the corresponding package fee; if the package identifier and the corresponding package fee do not match, determining the abnormal result of the IoT card as a first abnormal result, the first abnormal result being used to indicate that the IoT card's behavior is abnormal.
[0010] In one possible implementation, the above-mentioned method of determining an abnormal IoT card from the plurality of IoT cards based on the abnormal result includes: receiving a verification result sent by a verification personnel when the abnormal result indicates that the IoT card is behaving abnormally; and determining that the IoT card is an abnormal IoT card when the verification result indicates that the IoT card is abnormal.
[0011] In one possible implementation, the above-mentioned method of determining the abnormal IoT card from the plurality of IoT cards based on the abnormal result further includes determining the IoT card as a normal IoT card and adding the normal IoT card to the whitelist if the review result indicates that the IoT card is not abnormal.
[0012] In one possible implementation, the above-mentioned acquisition of initial data sent by upstream devices includes: determining multiple data sources corresponding to the initial data and a scheduling policy corresponding to each data source; and acquiring the initial data from the corresponding data sources based on the multiple scheduling policies, wherein the data formats and / or data types corresponding to different data sources are different or the same.
[0013] Secondly, embodiments of this application provide an anomaly determination device for an IoT card, comprising:
[0014] The acquisition module is used to acquire initial data sent by the upstream device, wherein the initial data is data corresponding to multiple IoT cards;
[0015] The processing module is used to perform ETL data processing on the initial data to obtain the data to be detected, the data to be detected including: the behavioral data of the multiple IoT cards;
[0016] The analysis module is used to analyze and process the behavioral data of the multiple IoT cards according to preset rules, obtain abnormal results, and determine abnormal IoT cards from the multiple IoT cards based on the abnormal results. The abnormal results are used to indicate whether the behavior of the corresponding IoT card is abnormal.
[0017] In one possible implementation, the above-mentioned processing module is further configured to: determine and remove duplicate data from the data corresponding to the plurality of IoT cards based on the business content; fill or discard empty and dirty data in the data corresponding to the plurality of IoT cards to obtain processed IoT card data; and, if the data format and / or type of the IoT card data are inconsistent, convert the IoT card data to obtain the data to be detected.
[0018] In one possible implementation, the above-mentioned processing module is further configured to convert the IoT card data and store the converted IoT card data in a first data warehouse layer; filter the data in the first data warehouse layer according to business rules to obtain first filtered data, and store the first filtered data in a second data warehouse layer; and filter the first filtered data in the second data warehouse layer based on whitelist parameters to obtain the data to be detected.
[0019] In one possible implementation, the analysis module is further configured to determine, for any one of the multiple IoT cards, whether the package identifier in the behavior data of the IoT card matches the corresponding package fee; if the package identifier does not match the corresponding package fee, determine the abnormal result of the IoT card as a first abnormal result, the first abnormal result being used to indicate that the IoT card's behavior is abnormal.
[0020] In one possible implementation, the device further includes: a determining module;
[0021] The determination module is used to receive a verification result sent by a verification personnel when the abnormal result indicates that the IoT card is behaving abnormally; and to determine that the IoT card is an abnormal IoT card when the verification result indicates that the IoT card is abnormal.
[0022] In one possible implementation, the determination module is further configured to determine that the IoT card is a normal IoT card and add the normal IoT card to the whitelist if the verification result indicates that the IoT card is not abnormal.
[0023] In one possible implementation, the acquisition module is further configured to determine multiple data sources corresponding to the initial data and a scheduling strategy corresponding to each data source; based on the multiple scheduling strategies, the initial data is acquired from the corresponding data sources, wherein the data formats and / or data types corresponding to different data sources are different or the same.
[0024] Thirdly, embodiments of this application provide an anomaly detection device for an IoT card, including: a memory and a processor;
[0025] The memory stores computer-executed instructions;
[0026] The processor executes computer execution instructions stored in the memory, causing the processor to perform the first aspect and / or various possible implementations of the first aspect as described above.
[0027] Fourthly, embodiments of this application provide a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the first aspect and / or various possible implementations of the first aspect.
[0028] Fifthly, embodiments of this application provide a computer program product, including a computer program that, when executed by a processor, implements the first aspect and / or various possible implementations of the first aspect.
[0029] The IoT card anomaly determination method, apparatus, device, and medium provided in this application embodiment acquire IoT card data information, process the data through ETL, obtain the data to be detected, analyze it according to rules, and obtain anomaly results. Based on the results, staff can strengthen the security management of IoT cards and protect the legitimate rights and interests of users. Attached Figure Description
[0030] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.
[0031] Figure 1 A flowchart illustrating an anomaly determination method for an IoT card provided in this application embodiment. Figure 1 ;
[0032] Figure 2 A flowchart illustrating an anomaly determination method for an IoT card provided in this application embodiment. Figure 2 ;
[0033] Figure 3 A schematic diagram of the structure of an IoT card anomaly determination device provided in an embodiment of this application;
[0034] Figure 4 This is a schematic diagram of the structure of an IoT card anomaly detection device provided in an embodiment of this application. Detailed Implementation
[0035] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0036] "Multiple" refers to two or more, and other quantifiers are similar. "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, or B alone. The character " / " generally indicates that the preceding and following objects have an "or" relationship.
[0037] In this application, the terms "exemplary" or "for example" are used to indicate examples, illustrations, or descriptions. Any embodiment or design described as "exemplary" or "for example" in this application should not be construed as being more preferred or advantageous than other embodiments or designs. Specifically, the use of terms such as "exemplary" or "for example" is intended to present the relevant concepts in a concrete manner.
[0038] With continuous technological innovation, IoT cards have developed rapidly and are widely used in daily life, bringing many conveniences to people. However, this development is also accompanied by certain security risks. Therefore, ensuring the security, controllability, and compliant operation of IoT cards, and promptly identifying their abnormal states, is particularly important.
[0039] ETL is the process of extracting, cleaning, and transforming data from business systems and then loading it into a data warehouse. Its purpose is to integrate scattered, disorganized, and inconsistent data.
[0040] In existing technologies, when processing data through ETL, the data from the front end, middle end, and back end are often integrated into a whole link, and the data of each node in the whole link is monitored. Based on the monitoring results, data analysis and problem processing are carried out.
[0041] However, this approach is highly likely to treat internal test data as anomalous data, and it will be impossible to detect and resolve problems in a timely manner throughout the entire anomaly monitoring process.
[0042] To address the aforementioned issues, this application provides a method for identifying anomalies in IoT cards. This method acquires IoT card data, performs ETL processing on the data to obtain data to be detected, performs behavioral data analysis on the data to be detected according to preset rules, obtains anomaly results, and identifies abnormal IoT cards based on these results. This method can promptly identify and handle abnormal states of IoT cards, ensuring their security, controllability, and compliant operation.
[0043] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will be described below with reference to the accompanying drawings.
[0044] Figure 1 A flowchart illustrating an anomaly determination method for an IoT card provided in this application embodiment. Figure 1 .like Figure 1 As shown, the method includes:
[0045] S101. Obtain the initial data sent by the upstream device.
[0046] The initial data consists of data corresponding to multiple IoT cards, and the upstream devices can be distributed, heterogeneous data sources.
[0047] Data corresponding to multiple IoT cards sent by upstream devices is obtained to facilitate analysis, processing, and data mining of the data corresponding to multiple IoT cards.
[0048] S102. Perform ETL data processing on the initial data to obtain the data to be detected, which includes the behavioral data of the multiple IoT cards.
[0049] ETL data processing refers to the process of extracting, transforming, and loading data from the source to the destination.
[0050] The data corresponding to the IoT cards obtained from the upstream equipment is cleaned, processed, and transformed, and then loaded onto the destination. This integrates the originally scattered, disorganized, and inconsistent data of a large number of IoT cards to obtain the data to be tested. The data to be tested includes behavioral data of multiple IoT cards, providing a basis for subsequent behavioral data analysis of IoT cards.
[0051] For example, data from multiple IoT cards obtained from upstream devices are processed, and IoT card data with the same user data are integrated together through ETL data processing to obtain the data to be tested.
[0052] S103. Analyze and process the behavioral data of the multiple IoT cards according to preset rules to obtain abnormal results, and determine the abnormal IoT card from the multiple IoT cards based on the abnormal results.
[0053] The preset rules could include, for example, exceeding usage limits, network disconnection due to timeout, duplicate account binding, or abnormal service plans. Abnormal results are used to indicate whether the IoT SIM card exhibits abnormal behavior.
[0054] According to preset rules, the behavioral data corresponding to multiple IoT cards are analyzed and processed to obtain anomaly results. Specifically, if the behavioral data of an IoT card does not conform to the preset rules during analysis and processing, the anomaly result indicates that the IoT card has behavioral anomalies; if the behavioral data of an IoT card conforms to the preset rules during analysis and processing, the anomaly result indicates that the IoT card does not have behavioral anomalies.
[0055] Staff members review the IoT cards based on the abnormal results of the behavioral data analysis and processing corresponding to the IoT cards.
[0056] For example, when analyzing and processing the behavioral data corresponding to IoT cards, IoT card A exhibits abnormal plan behavior, IoT card B exhibits duplicate account binding behavior, and IoT card C meets the preset rules. Therefore, the abnormal results include IoT card A's abnormal plan and IoT card B's duplicate account binding. Based on the abnormal results, staff will conduct further verification of IoT cards A and B.
[0057] This application provides a method for determining anomalies in IoT cards. The method acquires data information from the IoT card, performs ETL data processing to extract, transform, and load the data, obtaining data to be analyzed. This data includes behavioral data from multiple IoT cards. The behavioral data is analyzed according to rules to obtain anomaly results. These results indicate whether there are any abnormalities in the behavioral data of the multiple IoT cards. This method enables the analysis and processing of IoT card information data, yielding anomaly handling results. Based on these results, staff can strengthen the security management of IoT cards and protect the legitimate rights and interests of users.
[0058] Figure 2 A flowchart illustrating an anomaly determination method for an IoT card provided in this application embodiment. Figure 2 .like Figure 2 As shown, in this embodiment... Figure 1 Based on the embodiments, a possible implementation of an anomaly determination method for an IoT card is described in detail. The method includes:
[0059] S201. Obtain the initial data sent by the upstream device, wherein the initial data is data corresponding to multiple IoT cards.
[0060] Step S201 is similar to step S101, and will not be described again here.
[0061] S202. Based on the business content, identify and remove duplicate data from the data corresponding to the multiple IoT cards.
[0062] The initial data volume is huge. Before processing the initial data, it is necessary to identify the duplicate data in the initial data based on the business content. For the duplicate data, only one record should be kept. All other data should be removed except for the record that is kept.
[0063] S203. Fill or discard empty and dirty data in the data corresponding to the multiple IoT cards to obtain the processed IoT card data.
[0064] After the above deduplication process, the data corresponding to the multiple IoT cards are filled or discarded for any empty or dirty data. After filling or discarding, the processed IoT card data is obtained.
[0065] IoT SIM card data includes various types of data, and there are corresponding filling rules for each type of data. For example, when the data type is whether it has SMS function, the filling rule is yes.
[0066] S204. The IoT card data is converted and the converted IoT card data is stored in the first data warehouse layer.
[0067] The conversion process includes standardizing the format, units, and types. The first data warehouse layer is used to store the converted IoT card data.
[0068] For IoT SIM card data of the same type, standardize the format, units, and types, and store them in the first data warehouse layer. Format standardization can be achieved by following the same standards and rules, unit standardization can be achieved by standardizing the measurement standards and units, and type standardization can be achieved by grouping IoT SIM cards from the same customer together.
[0069] For example, the unit for data traffic in IoT cards is uniformly megabytes (MB).
[0070] S205. According to the business rules, the data in the first data warehouse layer is filtered to obtain the first filtered data, and the first filtered data is stored in the second data warehouse layer.
[0071] For example, business rules could include retaining only commercial accounts, with the second data warehouse layer used to store the first-filtered data.
[0072] According to business rules, the data that has undergone deduplication, padding, discarding, and transformation processes is filtered out. Data that does not conform to the business rules is filtered out; data that conforms to the business rules is stored in the second data warehouse layer.
[0073] For example, the data in the first data warehouse layer includes commercial accounts, internal test accounts, and accounts given away as part of promotions. Following the business rule of retaining only commercial accounts, the above data is filtered out. Therefore, internal test accounts and accounts given away as part of promotions are filtered out, and only commercial accounts are retained and stored in the second data warehouse layer.
[0074] S206. Based on the whitelist parameters, the first filtered data in the second data warehouse layer is filtered to obtain the data to be detected.
[0075] The whitelist parameter filters out IoT card data protected by the whitelist, and the data to be tested includes behavioral data from multiple IoT cards.
[0076] Data from IoT cards that are not protected by the whitelist can be, for example, internal accounts or test data. Based on the whitelist parameters, the data from IoT cards that are not protected by the whitelist and the first filtered data in the second data warehouse layer are used as the data to be tested. The data to be tested includes behavioral data from multiple IoT cards.
[0077] S207. Determine whether the package identifier in the data to be detected of the IoT card matches the corresponding package fee. If yes, proceed to step S208; if no, proceed to step S209.
[0078] The package identifier refers to the package parameters of the IoT card, and the package fee refers to the actual package value of the IoT card.
[0079] The system determines whether the package identifier in the data to be tested of the IoT card matches the corresponding package fee. If the package identifier in the data to be tested of the IoT card matches the corresponding package fee, the IoT card is determined to be the first abnormal result; if the package identifier in the data to be tested of the IoT card does not match the corresponding package fee, the IoT card is determined to be the second abnormal result.
[0080] S208. Determine the abnormal result of the IoT card as the first abnormal result.
[0081] S209. Determine the abnormal result of the IoT card as the second abnormal result.
[0082] S2010. Based on the abnormal results, identify the abnormal IoT card from among the multiple IoT cards.
[0083] Among them, abnormal IoT cards may be IoT cards involved in fraud or criminal cases.
[0084] In one possible implementation, determining the abnormal IoT card from multiple IoT cards based on the abnormal result includes:
[0085] If the abnormal result indicates that the IoT card is behaving abnormally, receive the verification result sent by the verification personnel; if the verification result indicates that the IoT card is abnormal, determine that the IoT card is an abnormal IoT card; if the verification result indicates that the IoT card is not abnormal, determine that the IoT card is a normal IoT card and add the normal IoT card to the whitelist.
[0086] The abnormal results include IoT cards, abnormal behaviors, and the validity period of the processing. The validity period of the processing will vary depending on the different abnormal behaviors.
[0087] For example, the abnormal result is that IoT card A package is abnormal, and its processing validity period is 5 days, while IoT card B is suspected of being involved in fraud, and its validity period is only 1 day.
[0088] Based on the attribution information of IoT SIM cards A and B, staff from the corresponding provinces are assigned to conduct verification. This ensures that staff promptly verify IoT SIM cards A and B within their validity period, guaranteeing that every anomaly receives appropriate attention and handling. Staff will then analyze the background of the abnormal behavior based on the detailed information provided in the anomaly report, and conduct further investigations or evidence collection.
[0089] For IoT SIM card A, staff will conduct a detailed review of its abnormal service plan within the 5-day validity period to ensure the issue is properly resolved. For IoT SIM card B, due to its suspected involvement in fraud, staff must complete the review within a tight 1-day timeframe.
[0090] The review results showed that the abnormality of IoT SIM card A was due to billing anomalies, so IoT SIM card A was determined to be a normal IoT SIM card and added to the whitelist; while IoT SIM card B was suspected of being repeatedly bound to fraudulent accounts, so IoT SIM card B was determined to be an abnormal IoT SIM card and was immediately shut down.
[0091] In one possible implementation, obtaining the initial data sent by the upstream device includes:
[0092] The initial data is determined by identifying multiple data sources and scheduling strategies for each data source; based on the multiple scheduling strategies, the initial data is obtained from the corresponding data sources, wherein the data formats and / or data types of different data sources are different or the same.
[0093] Upstream devices can be distributed, heterogeneous data sources. Therefore, initial data is obtained based on scheduling strategies corresponding to multiple data sources. Scheduling strategies can include directly retrieving files of a specified format sent by upstream devices, or scanning files sent by upstream devices using a script and retrieving only files that conform to certain rules.
[0094] For example, the scheduling strategy of data source A is to directly obtain files of a specified format, while the scheduling strategy of data source B is to scan and obtain initial data that conforms to the rules through a script.
[0095] Therefore, when retrieving files from data source A, the initial data provided by data source A can be quickly accessed and extracted; when retrieving files from data source B, it is necessary to scan and determine the data that conforms to the rules provided by data source B before retrieving the initial data.
[0096] In one possible implementation, an anomaly determination method for an IoT card also includes:
[0097] The entire workflow consists of acquiring initial data, performing ETL data processing on the initial data to obtain the data to be tested, and performing anomaly analysis on the data to be tested. The working status of the entire workflow is monitored, and retry mechanisms are configured for most tasks in the entire workflow.
[0098] If an abnormal workflow is detected, such as a task failure or the need for fault tolerance, a retry mechanism will be automatically initiated to ensure that the task can resume normal operation as soon as possible. At the same time, the system will immediately generate an alarm message to notify relevant personnel in a timely manner so that they can take measures to deal with the situation quickly.
[0099] Simultaneously, detailed error messages and retries are recorded to help staff better understand the severity and potential impact of the problem. If a task fails to complete successfully after multiple retries, the system will take further emergency measures, proactively contacting the task's developers. The developers will be notified of the problem so they can conduct in-depth root cause analysis, pinpoint the source of the failure, and make necessary adjustments and optimizations. This series of response measures not only improves workflow reliability but also ensures that problems are resolved as quickly as possible, thereby minimizing the impact on business operations.
[0100] This application provides a method for determining the anomalies of IoT cards. This method uses different scheduling techniques to acquire IoT card data from different sources. The IoT card data undergoes deduplication, empty data filling, dirty data discarding, and filtering to obtain data to be detected. This data includes behavioral data. The method analyzes whether the package identifier in the behavioral data matches the corresponding package fee to determine if the corresponding IoT card is abnormal. Staff review the abnormal IoT cards based on the anomaly results. According to the anomaly results and review results, the corresponding IoT cards are processed, thus achieving the determination of IoT card anomalies for easier management. Different work order processing timelines are set for different abnormal behaviors, and differentiated processing validity periods can more effectively cope with various abnormal situations. The efficient processing flow can minimize potential risks, protect the security of IoT cards and the interests of users. By monitoring the entire workflow, erroneous processes can be repaired promptly, problems can be detected and handled in a timely manner, and the efficient operation of the entire system is ensured.
[0101] Figure 3 This is a schematic diagram of the structure of an IoT card anomaly determination device provided in this application embodiment. The IoT card anomaly determination device 40 provided in this embodiment includes:
[0102] The acquisition module 301 is used to acquire the initial data sent by the upstream device. The initial data is the data corresponding to multiple IoT cards.
[0103] Processing module 302 is used to perform ETL data processing on the initial data to obtain the data to be detected, which includes: behavioral data of multiple IoT cards;
[0104] The analysis module 303 is used to analyze and process the behavioral data of multiple IoT cards according to preset rules, obtain abnormal results, and determine the abnormal IoT card from the multiple IoT cards based on the abnormal results. The abnormal results are used to indicate whether the behavior of the corresponding IoT card is abnormal.
[0105] In one possible implementation, the processing module 302 is further configured to: determine and remove duplicate data from the data corresponding to multiple IoT cards based on the business content; fill or discard empty and dirty data in the data corresponding to multiple IoT cards to obtain processed IoT card data; and convert the IoT card data to obtain the data to be detected if the data format and / or type of the IoT card data are inconsistent.
[0106] In one possible implementation, the processing module 302 is further configured to convert the IoT card data and store the converted IoT card data in the first data warehouse layer; filter the data in the first data warehouse layer according to business rules to obtain first filtered data, and store the first filtered data in the second data warehouse layer; and filter the first filtered data in the second data warehouse layer based on whitelist parameters to obtain the data to be detected.
[0107] In one possible implementation, the analysis module 303 is further configured to determine, for any one of the multiple IoT cards, whether the package identifier in the behavior data of the IoT card matches the corresponding package fee; if the package identifier does not match the corresponding package fee, the abnormal result of the IoT card is determined as the first abnormal result, and the first abnormal result is used to indicate that the IoT card's behavior is abnormal.
[0108] In one possible implementation, the device further includes: a determining module 304;
[0109] The determination module 304 is used to receive the verification result sent by the verification personnel when the abnormal result indicates that the IoT card is behaving abnormally; and to determine that the IoT card is an abnormal IoT card when the verification result indicates that the IoT card is abnormal.
[0110] In one possible implementation, the determination module 304 is further configured to determine that the IoT card is a normal IoT card and add the normal IoT card to the whitelist if the verification result indicates that the IoT card is not abnormal.
[0111] In one possible implementation, the acquisition module 301 is further configured to determine multiple data sources corresponding to the initial data and a scheduling strategy corresponding to each data source; based on the multiple scheduling strategies, the initial data is acquired from the corresponding data sources, wherein the data formats and / or data types corresponding to different data sources are different or the same.
[0112] This embodiment provides an anomaly determination device for an IoT card, which can execute the method provided in the above method embodiment. Its implementation principle and technical effect are similar, and will not be described in detail here.
[0113] Figure 4 This is a schematic diagram of the structure of an IoT card anomaly detection device provided in an embodiment of this application. Figure 4 As shown, the IoT card anomaly detection device 40 provided in this embodiment includes at least one processor 401 and a memory 402. Optionally, the device 40 further includes a communication component 403. The processor 401, memory 402, and communication component 403 are connected via a bus 404.
[0114] In the specific implementation process, at least one processor 401 executes computer execution instructions stored in memory 402, causing at least one processor 401 to execute the IoT card anomaly determination method shown in the above embodiment.
[0115] The specific implementation process of processor 401 can be found in the above method embodiments, and its implementation principle and technical effect are similar. It will not be repeated here.
[0116] In the above embodiments, it should be understood that the processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), etc. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in this invention can be directly implemented by a hardware processor, or implemented by a combination of hardware and software modules within the processor.
[0117] The memory may include random access memory (RAM) and may also include non-volatile memory (NVM), such as at least one disk storage device.
[0118] The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. Buses can be categorized as address buses, data buses, control buses, etc. For ease of illustration, the buses shown in the accompanying drawings are not limited to a single bus or a single type of bus.
[0119] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the method for determining the anomaly of an IoT card as described in the above embodiments.
[0120] This application also provides a computer-readable storage medium storing computer-executable instructions. When the processor executes the computer-executable instructions, it implements the IoT card anomaly determination method shown in the above embodiments.
[0121] The aforementioned readable storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk. The readable storage medium can be any available medium accessible to a general-purpose or special-purpose computer.
[0122] An exemplary readable storage medium is coupled to a processor, enabling the processor to read information from and write information to the readable storage medium. Of course, the readable storage medium can also be a component of the processor. The processor and the readable storage medium can reside in an Application Specific Integrated Circuit (ASIC). Alternatively, the processor and the readable storage medium can exist as discrete components in the device.
[0123] The division of units is merely a logical functional division; in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be indirect coupling or communication connection through some interfaces, devices, or units, and may be electrical, mechanical, or other forms.
[0124] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment, depending on actual needs.
[0125] In addition, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.
[0126] If a function is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0127] Those skilled in the art will understand that all or part of the steps of the above-described method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When executed, the program performs the steps of the above-described method embodiments; and the aforementioned storage medium includes various media capable of storing program code, such as ROM, RAM, magnetic disks, or optical disks.
[0128] Finally, it should be noted that other embodiments of the invention will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This invention is intended to cover any variations, uses, or adaptations of the invention that follow the general principles of the invention and include common knowledge or customary techniques in the art not disclosed herein, and is not limited to the precise structures described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of the invention is limited only by the appended claims.
Claims
1. A method for determining anomalies in an IoT card, characterized in that, include: Obtain initial data sent by the upstream device, wherein the initial data is data corresponding to multiple IoT cards; Based on the business content, duplicate data in the data corresponding to the multiple IoT cards are identified and removed. Empty and dirty data in the data corresponding to the multiple IoT cards are filled or discarded to obtain the processed IoT card data; If the data format and / or type of the IoT card data are inconsistent, the IoT card data is converted and the converted IoT card data is stored in the first data warehouse layer; according to business rules, the data in the first data warehouse layer is filtered to obtain the first filtered data, and the first filtered data is stored in the second data warehouse layer. Based on the whitelist parameters, the first filtering data in the second data warehouse layer is filtered to obtain the data to be detected, which includes the behavioral data of the multiple IoT cards. According to preset rules, the behavioral data of the multiple IoT cards are analyzed and processed to obtain abnormal results. The preset rules are overuse, duplicate account binding, and abnormal package. Based on the abnormal results, abnormal IoT cards are identified from the multiple IoT cards. The abnormal results are used to indicate whether the behavior of the corresponding IoT card is abnormal.
2. The method according to claim 1, characterized in that, The behavioral data includes: a package identifier and the corresponding package fee. The analysis and processing of the behavioral data from the multiple IoT cards according to preset rules to obtain abnormal results includes: For any one of multiple IoT cards, determine whether the package identifier in the behavior data of the IoT card matches the corresponding package fee; If the package identifier does not match the corresponding package fee, the abnormal result of the IoT card is determined as the first abnormal result, which is used to indicate that the IoT card is behaving abnormally.
3. The method according to claim 1, characterized in that, The step of determining the abnormal IoT card from the plurality of IoT cards based on the abnormal result includes: If the abnormal result indicates that the IoT card is behaving abnormally, receive the verification result sent by the verification personnel; If the verification result indicates that the IoT card is abnormal, the IoT card is determined to be an abnormal IoT card.
4. The method according to claim 3, characterized in that, The method further includes: If the verification result indicates that the IoT card is not abnormal, the IoT card is determined to be a normal IoT card and added to the whitelist.
5. The method according to claim 1, characterized in that, The acquisition of initial data sent by the upstream device includes: Determine the multiple data sources corresponding to the initial data and the scheduling strategy corresponding to each data source; Based on multiple scheduling strategies, the initial data is obtained from the corresponding data sources, wherein the data formats and / or data types corresponding to different data sources are different or the same.
6. An anomaly detection device for an Internet of Things (IoT) card, characterized in that, include: The acquisition module is used to acquire initial data sent by the upstream device, wherein the initial data is data corresponding to multiple IoT cards; Processing module, used for Based on the business content, duplicate data in the data corresponding to the multiple IoT cards are identified and removed. Empty and dirty data in the data corresponding to the multiple IoT cards are filled or discarded to obtain the processed IoT card data; If the data format and / or type of the IoT card data are inconsistent, the IoT card data is converted and the converted IoT card data is stored in the first data warehouse layer; according to business rules, the data in the first data warehouse layer is filtered to obtain the first filtered data, and the first filtered data is stored in the second data warehouse layer. Based on the whitelist parameters, the first filtering data in the second data warehouse layer is filtered to obtain the data to be detected, which includes the behavioral data of the multiple IoT cards. The analysis module is used to analyze and process the behavioral data of the multiple IoT cards according to preset rules to obtain abnormal results. The preset rules are overuse, duplicate account binding, and abnormal package. Based on the abnormal results, the abnormal IoT card is identified from the multiple IoT cards. The abnormal results are used to indicate whether the behavior of the corresponding IoT card is abnormal.
7. An anomaly detection device for an Internet of Things (IoT) card, characterized in that, include: Memory, processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory, causing the processor to perform the anomaly determination method for the Internet of Things card as described in any one of claims 1-5.
8. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the method for determining anomalies in an IoT card as described in any one of claims 1-5.
Citation Information
Patent Citations
Internet of Things card service anomaly detection method and device, equipment and medium
CN111371581A
Internet of Things card control method and electronic equipment
CN114091563A