A detection and processing method for the Internet of Things

By employing edge computing and horizontally collaborative IoT detection and processing methods, combined with data balancing and intrusion detection models, the problem of security threats to IoT devices has been solved, achieving efficient network attack detection and reduced false negative rates.

CN119155155BActive Publication Date: 2025-11-14JIANGXI JIE XUN ENTERPRISE MANAGEMENT CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202410952833.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-07-16
Publication Date
2025-11-14
Estimated Expiration
2044-07-16

AI Technical Summary

Technical Problem

IoT devices face serious security threats and vulnerabilities. Existing technologies are unable to efficiently detect and reduce false alarm rates, which can easily lead to network paralysis.

Method used

An edge computing architecture is used for control and management to achieve horizontal collaboration and real-time control of IoT devices. It combines SMOTE+OSS+RANDOM hybrid sampling and CNN network intrusion detection model for data balancing and analysis, and performs terminal detection through OSSEC.

Benefits of technology

It effectively improves network analysis and processing efficiency, reduces request response time, enhances the ability to detect network attacks, reduces false negative rate, and strengthens security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119155155B_ABST
    Figure CN119155155B_ABST
Patent Text Reader

Abstract

This invention discloses a detection and processing method for the Internet of Things (IoT), comprising: architecture control and management of the IoT detection and processing system; horizontal collaboration and real-time control of the IoT detection and processing system; analysis and processing control of the IoT detection and processing system; and acquisition and detection management of the IoT detection and processing system. The architecture control and management of the IoT detection and processing system includes: controlling and managing the IoT detection and processing system using an edge computing structure, wherein the edge computing structure is divided into three layers: a cloud layer, an edge computing layer, and a terminal layer. Simultaneously, a core network provides network services between the cloud layer and the edge node layer. Each node connects to the cloud, and each device connects to an edge node, allowing edge nodes to communicate with each other, forming a defined cellular structure. This invention features high security and strong stability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of Internet of Things (IoT) technology, specifically to a detection and processing method for IoT. Background Technology

[0002] Building upon the traditional internet, the Internet of Things (IoT) has rapidly advanced by enabling seamless connectivity between things through intelligent sensing. In 2019, the number of consumer-grade IoT devices worldwide reached 8.1 billion, with China accounting for 29.6% of the global market. The projected compound annual growth rate (CAGR) from 2019 to 2022 is 28%. However, the increasing number of IoT devices has also brought growing concerns about potential threats. In 2019, the vulnerability growth rate for IoT devices exceeded 20%. It is predicted that in the coming years, IoT device vulnerabilities will account for 14.7% more than the overall vulnerability rate, making the security situation far from optimistic and necessitating improved IoT device security. Attackers exploit IoT infrastructure through malicious network behaviors, including man-in-the-middle attacks, denial-of-service attacks, and botnets, which can paralyze the entire network in severe cases. Therefore, designing a highly secure and stable detection and handling method for the IoT is essential. Summary of the Invention

[0003] The purpose of this invention is to provide a detection and processing method for the Internet of Things (IoT) to solve the problems mentioned in the background art.

[0004] To address the aforementioned technical problems, the present invention provides the following technical solution: a detection and processing method for the Internet of Things, comprising:

[0005] Perform architecture control and management of the Internet of Things (IoT) detection and processing system;

[0006] To enable horizontal collaboration and real-time control of IoT detection and processing systems;

[0007] To perform analysis, processing, and control of the Internet of Things (IoT) detection and processing system;

[0008] To manage the data collection and detection of the Internet of Things (IoT) detection and processing system;

[0009] The architecture control and management of the IoT detection and processing system includes:

[0010] The IoT detection and processing system adopts an edge computing structure for control and management. The edge computing structure is divided into three layers: cloud layer, edge computing layer, and terminal layer. At the same time, a core network is set up to provide network services between the cloud layer and the edge node layer. Each node is connected to the cloud, and each device is connected to the edge node. The edge nodes can communicate with each other to form a set cellular structure.

[0011] According to the above technical solution, the horizontal coordination and real-time control of the IoT detection and processing system includes:

[0012] When a single IoT device is attacked, other IoT devices collect information to determine whether a security incident has occurred, and update and upgrade the rule base of the IoT device where the security incident occurred, thus forming horizontal collaboration between IoT devices.

[0013] When the shared data volume captures data, it automatically distributes the data to the network traffic detection engine and the system call detection engine based on the file extension. Files with the .txt extension are sent to the system call detection engine, and files with the .pcap extension are sent to the network traffic detection engine, thereby achieving adaptive data processing by the system.

[0014] According to the above technical solution, the analysis, processing, and control of the IoT detection and processing system includes:

[0015] A hybrid sampling method of SMOTE+OSS+RANDOM is used for data balancing. First, random sampling is performed on the majority class samples. Random sampling values ​​that meet the set requirements are obtained through analysis experiments. Then, boundary noise points are eliminated by one-sided selection. Finally, SMOTE upsampling is used to achieve dataset balance.

[0016] According to the above technical solution, the analysis, processing, and control of the IoT detection and processing system further includes:

[0017] The pcap raw data is vectorized by converting characters into ASCII codes and then into binary data to obtain the corresponding 1*316 data. Then, it is transformed into 318-dimensional data through linear interpolation. Finally, the 318-dimensional data is converted into an 18*18 matrix, and then the data is further converted into a grayscale image using Python's PIL library.

[0018] The analysis and control processing of the CNN network intrusion detection model are carried out so that the CNN model includes one input layer, three convolutional layers, three pooling layers and one output layer.

[0019] According to the above technical solution, the data acquisition and management of the IoT detection and processing system includes:

[0020] The IoT detection and processing system collects network traffic data in real time and transmits it to the workbench for management personnel to analyze and review.

[0021] Endpoint detection uses OSSEC for rule matching to detect malicious behavior. It includes a packet decoder and a data analysis engine. First, the data information captured from the network card is decoded by the packet decoder, and then the data analysis engine analyzes the data to obtain the results and generate alarm notifications.

[0022] According to the above technical solution, an Internet of Things (IoT) detection and processing system includes:

[0023] The management and control module is used for the management and control of the IoT detection and processing system.

[0024] The analysis and processing module is used for optimization analysis and processing of the IoT detection and processing system.

[0025] The data acquisition and detection module is used for data acquisition and detection management in the IoT detection and processing system.

[0026] According to the above technical solution, the management and control module includes:

[0027] The architecture management module is used for the architecture control design of the IoT detection and processing system.

[0028] The horizontal collaboration module is used for horizontal collaborative management of IoT devices;

[0029] The real-time processing module is used for real-time adaptive processing of data information.

[0030] According to the above technical solution, the analysis and processing module includes:

[0031] The data balancing module is used for data balance management.

[0032] The image processing module is used for image processing of data information;

[0033] The management and analysis module is used for the management, analysis, and control of intrusion detection models.

[0034] According to the above technical solution, the acquisition and detection module includes:

[0035] The data acquisition and management module is used for data acquisition and management.

[0036] The terminal detection module is used for IoT terminal detection and processing.

[0037] Compared with the prior art, the beneficial effects achieved by the present invention are as follows: The present invention, by setting up a management and control module, an analysis and processing module, and a collection and detection module, can extend cloud computing to the network edge and transmit data to the cloud according to a set period, effectively improving the network analysis and processing efficiency, reducing request response time, efficiently detecting missed events, reducing the false negative rate, and strengthening the ability to detect network attacks. Attached Figure Description

[0038] The accompanying drawings are provided to further illustrate the invention and form part of the specification. They are used in conjunction with embodiments of the invention to explain the invention and do not constitute a limitation thereof. In the drawings:

[0039] Figure 1 This is a flowchart of an Internet of Things (IoT) detection and processing method provided in Embodiment 1 of the present invention;

[0040] Figure 2 This is a module configuration diagram of an Internet of Things (IoT) detection and processing system provided in Embodiment 2 of the present invention. Detailed Implementation

[0041] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0042] Example 1: Figure 1 This is a flowchart of an IoT detection and processing method provided in Embodiment 1 of the present invention. This embodiment can be applied to an IoT detection and processing system. The method can be executed by an IoT detection and processing system provided in this embodiment of the present invention. This system consists of multiple software and hardware modules, such as... Figure 1 As shown, the method specifically includes the following steps:

[0043] S101. Perform architecture control and management of the Internet of Things (IoT) detection and processing system;

[0044] For example, in this embodiment of the invention, the IoT detection and processing system adopts an edge computing structure for control and management. The edge computing structure is divided into three layers: the cloud layer, the edge computing layer, and the terminal layer. A core network provides network services between the cloud layer and the edge node layer. Each node connects to the cloud, and each device connects to an edge node. The edge nodes can communicate with each other, forming a defined cellular structure. In this step, the terminal layer consists of mobile and fixed IoT devices (propagation media, Raspberry Pi, and smartphones, etc.). Each device connects to an edge node. Locally collected data is first transmitted to the edge node, which processes the data before uploading the results to the cloud. Data that the edge node cannot process is directly uploaded to the cloud for processing. The edge computing layer consists of a large number of edge nodes. Edge layer devices (such as routers and switches) have certain computing capabilities. Their main function is to extend cloud computing to the network edge and transmit data to the cloud according to a set period, effectively improving network analysis and processing efficiency and reducing request response time.

[0045] S102. Perform horizontal coordination and real-time control of the Internet of Things detection and processing system;

[0046] For example, in this embodiment of the invention, when a single IoT device is attacked, other IoT devices collect information to determine whether a security event has occurred, and update the rule base of the OSSEC of the IoT device where the security event occurred, forming horizontal collaboration between IoT devices. In this step, when a single device in the IoT environment receives an alarm at its terminal and confirms an attack event at the edge computing layer, other IoT devices will receive alarm information from the edge computing layer. If the status of other devices also becomes abnormal, they will start capturing network data and host process information and uploading it to the corresponding integrated detection engine at the edge computing layer for detection. Taking the specific scenario of a Raspberry Pia being remotely controlled and then used to launch a DoS attack on a Raspberry Pib, the integrated detection engine a at the edge computing layer detects that the Raspberry Pia has been subjected to a remote control attack, generates an alarm, and notifies the Raspberry Pib. The Raspberry Pib detects that its CPU status is abnormal after being subjected to a DoS attack, but the Raspberry Pib's OSSEC does not generate an alarm because it detects abnormal behavior. Pib transmits the collected network traffic and system call sequence data to the integrated detection engine b at the edge computing layer for deep detection, thereby forming a horizontal collaboration between Raspberry Pia and Raspberry Pib. This can efficiently detect missed events, reduce the false negative rate, and enhance the ability to detect network attacks.

[0047] When the shared data volume captures data, it automatically distributes the data to the network traffic detection engine and the system call detection engine based on the file extension. Files with the .txt extension are sent to the system call detection engine, and files with the .pcap extension are sent to the network traffic detection engine, thereby achieving adaptive data processing by the system.

[0048] S103. Perform analysis, processing, and control of the Internet of Things (IoT) detection and processing system.

[0049] For example, in this embodiment of the invention, a hybrid sampling method of SMOTE+OSS+RANDOM is used for data balancing. First, the majority class samples are randomly sampled, and the random sampling values ​​that meet the set requirements are obtained through analysis experiments. Then, boundary noise points are eliminated by a one-sided selection method. Finally, SMOTE upsampling is used to achieve the balance of the dataset. Since the majority class samples only depend on the sample distribution and not on any distance information, only by randomly removing the number of majority class samples can higher accuracy be obtained with the loss of a small amount of original information. Therefore, this step can effectively improve the efficiency and accuracy of data balancing analysis and processing.

[0050] The pcap raw data is vectorized by converting characters into ASCII codes, then converting the data into binary data to obtain corresponding 1*316 data. This is then transformed into 318-dimensional data using linear interpolation, and finally converted into an 18*18 matrix. This 318-dimensional data is further converted into a grayscale image using Python's PIL library. Since different image conversion methods result in varying detection accuracy, and mainstream image conversion methods have certain limitations that can lead to distortion of the converted image information, this step effectively improves the accuracy of IoT detection and analysis, and effectively avoids analysis and processing errors.

[0051] The analysis and control of the CNN network intrusion detection model are performed, resulting in a CNN model consisting of one input layer, three convolutional layers, three pooling layers, and one output layer. In this step, the input layer converts the streaming data into a matrix form with a two-dimensional dimension. The convolutional layers use 16 zero-padding filters to extract the received data. The other two convolutional layers are similar, except that the number of convolutional kernels is changed to 32. The max pooling layer uses 9x9 downsampling with a stride of 2; the other two pooling layers use 3x3 downsampling with a stride of 1. The fully connected layer serves as the final layer and is used as the output. The multi-classifier ultimately outputs five features.

[0052] S104. Perform data acquisition and detection management for the Internet of Things (IoT) detection and processing system;

[0053] For example, in this embodiment of the invention, the Internet of Things detection and processing system collects network traffic data in real time and transmits it to the workbench for management personnel to analyze and view;

[0054] Endpoint detection uses OSSEC for rule matching to detect malicious behavior. It includes a packet decoder and a data analysis engine. First, the data information captured from the network card is decoded by the packet decoder, and then the data analysis engine analyzes the data to obtain the results and generate alarm notifications.

[0055] Example 2: Example 2 of the present invention provides a detection and processing system for the Internet of Things. Figure 2 This is a schematic diagram of the module structure of an Internet of Things (IoT) detection and processing system provided in Embodiment 2. Figure 2 As shown, the system includes:

[0056] The management and control module is used for the management and control of the IoT detection and processing system.

[0057] The analysis and processing module is used for optimization analysis and processing of the IoT detection and processing system.

[0058] The data acquisition and detection module is used for data acquisition and detection management in the IoT detection and processing system.

[0059] In some embodiments of the present invention, the management control module includes:

[0060] The architecture management module is used for the architecture control design of the IoT detection and processing system.

[0061] The horizontal collaboration module is used for horizontal collaborative management of IoT devices;

[0062] The real-time processing module is used for real-time adaptive processing of data information.

[0063] In some embodiments of the present invention, the analysis and processing module includes:

[0064] The data balancing module is used for data balance management.

[0065] The image processing module is used for image processing of data information;

[0066] The management and analysis module is used for the management, analysis, and control of intrusion detection models.

[0067] In some embodiments of the present invention, the acquisition and detection module includes:

[0068] The data acquisition and management module is used for data acquisition and management.

[0069] The terminal detection module is used for IoT terminal detection and processing.

[0070] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus.

[0071] Finally, it should be noted that the above descriptions are merely preferred embodiments of the present invention and are not intended to limit the present invention. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing embodiments or make equivalent substitutions for some of the technical features. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.

Claims

1. A detection and processing method for the Internet of Things, characterized in that: include: Perform architecture control and management of the Internet of Things (IoT) detection and processing system; To enable horizontal collaboration and real-time control of IoT detection and processing systems; To perform analysis, processing, and control of the Internet of Things (IoT) detection and processing system; To manage the data collection and detection of the Internet of Things (IoT) detection and processing system; The architecture control and management of the IoT detection and processing system includes: The IoT detection and processing system adopts an edge computing structure for control and management. The edge computing structure is divided into three layers: cloud layer, edge computing layer, and terminal layer. At the same time, a core network is set up to provide network services between the cloud layer and the edge node layer. Each node connects to the cloud, and each device connects to the edge node. The edge nodes can communicate with each other to form a set cellular structure. The horizontal coordination and real-time control of the IoT detection and processing system includes: When a single IoT device is attacked, other IoT devices collect information to determine whether a security event has occurred, and update the rule base of the IoT device whose security event occurred via OSSEC, forming horizontal collaboration between IoT devices. In this step, when a single device in the IoT environment triggers an alarm at the terminal and confirms an attack event at the edge computing layer, other IoT devices will receive alarm information from the edge computing layer. If the status of other devices also becomes abnormal, they will start to capture network data and host process information and upload it to the corresponding integrated detection engine at the edge computing layer for detection. When the shared data volume captures data, it automatically distributes the data to the network traffic detection engine and the system call detection engine based on the file extension. Files with the .txt extension are sent to the system call detection engine, and files with the .pcap extension are sent to the network traffic detection engine, thereby achieving adaptive data processing by the system. The data acquisition and detection management of the IoT detection and processing system includes: The IoT detection and processing system collects network traffic data in real time and transmits it to the workbench for management personnel to analyze and review. Endpoint detection uses OSSEC for rule matching to detect malicious behavior. It includes a packet decoder and a data analysis engine. First, the data information captured from the network card is decoded by the packet decoder, and then the data analysis engine analyzes the data to obtain the results and generate alarm notifications.

2. The detection and processing method for the Internet of Things according to claim 1, characterized in that: The analysis, processing, and control of the IoT detection and processing system include: A hybrid sampling method of SMOTE+OSS+RANDOM is used for data balancing. First, random sampling is performed on the majority class samples. Random sampling values ​​that meet the set requirements are obtained through analysis experiments. Then, boundary noise points are eliminated by one-sided selection. Finally, SMOTE upsampling is used to achieve dataset balance.

Citation Information

Patent Citations

  • Mongo cluster technology-based power distribution Internet of Things edge computing architecture design method

    CN112463393A

  • Edge network state sensing modeling method based on representation learning

    CN114726741A

  • APT attack detection system and detection method based on industrial Internet of Things

    CN116436691A

  • Security risk high-intensity monitoring system for different information domains

    CN116471093A