Internet of Things Security Active Defense Method, Device and Medium Based on Bypass Mirroring
Bypass monitoring and constructing blocked data packets, the timely detection and blocking of IoT security risks is solved, and the network security of industrial production systems is improved.
Patent Information
- Application Number
- CN202510106221.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-23
- Publication Date
- 2025-07-25
- Estimated Expiration
- 2045-01-23
AI Technical Summary
How to detect and block IoT security risks in a timely manner without affecting industrial production to prevent data leakage and system paralysis.
Obtain network traffic through bypass monitoring, detect attack behavior, and construct blocked packet interruption subsequent sessions based on the characteristics of IoT devices, actively defend against distributed attack behavior, simulate traffic details, and block packets for outgoing.
It realizes timely discovering and blocking IoT attacks without affecting production, improving network security, especially for various business units in the production operation system.
Smart Images

Figure CN119561786B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present invention relate to the field of network security technology, and in particular, to an active defense method, device, and medium for Internet of Things security based on bypass mirroring. Background Art
[0002] With the development of network technology, Internet of Things technology has been widely applied in fields such as enterprise production, urban operation, and personal privacy, bringing conveniences such as comprehensive interconnection, global perception, and remote control, while also bringing new network security risks.
[0003] In industrial production, if the Internet of Things security risks are not properly handled or are not timely, it may cause serious impacts such as data leakage, system paralysis, and production stagnation. How to detect and block Internet of Things security risks in a timely manner without affecting industrial production is an urgent problem to be solved.
[0004] In view of this, the present invention is proposed. In the prior art, Patent CN111478888A discloses a bypass blocking method, device, and storage medium, and CN117914605A provides a micro-segmentation protection method and related products for industrial Internet of Things, which are all different from the present invention. Summary of the Invention
[0005] The embodiments of the present invention provide an active defense method, device, and medium for Internet of Things security based on bypass mirroring, which actively block dangerous situations by detecting Internet of Things traffic.
[0006] In a first aspect, the embodiments of the present invention provide an active defense method for Internet of Things security based on bypass mirroring, including:
[0007] Obtaining the network traffic between an external device and an Internet of Things device through a bypass listening method;
[0008] In the case of detecting an attack behavior in the network traffic, constructing and sending a blocking data packet according to the characteristics of the Internet of Things device to interrupt subsequent sessions;
[0009] Specifically, in the case where the internal network includes fixed-length subnets, detecting the distribution law of attack behaviors in the internal network segment in the network traffic; if the attack behaviors show the characteristics of segmented repetition in the internal network segment, constructing and sending a blocking data packet according to the number of IP addresses in each segment and the number of IP addresses in each fixed-length subnet to interrupt subsequent sessions, and destroying the characteristics of segmented repetition or disrupting the IP address allocation law of Internet of Things devices in each segment.
[0010] In a second aspect, the embodiments of the present invention provide an electronic device, which includes:
[0011] One or more processors;
[0012] A memory for storing one or more programs
[0013] When the one or more programs are executed by the one or more processors, the one or more processors implement the active defense method for Internet of Things security based on bypass mirroring according to any embodiment.
[0014] In a third aspect, an embodiment of the present invention further provides a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, it implements the active defense method for Internet of Things security based on bypass mirroring according to any embodiment.
[0015] An embodiment of the present invention provides an active defense method for Internet of Things security based on bypass mirroring. In the bypass deployment monitoring mode, active defense is carried out on the detected attack behaviors; when an attack behavior is detected, the communication details of both sides of the traffic are simulated, and blocking data packets are actively constructed and sent out to interrupt subsequent sessions, so as to achieve the purpose of blocking. Among them, the blocking data packets are constructed according to the communication protocols of Internet of Things devices, and Internet of Things devices with different protocols will correspond to different blocking data packets.
[0016] In particular, in view of the weakness that the network structures and IP planning of each business unit in some production operation systems are similar, this embodiment provides a detection method for distributed attack behaviors, which can timely detect distributed attack behaviors that adopt the same attack strategy for each business unit; and combined with subnet division, it analyzes the risk levels in various situations, clarifies the high-risk IP addresses that need to be key protected in various situations and specific protection measures, and improves the network security of the multi-business unit production operation system. Description of the Drawings
[0017] In order to more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the following will briefly introduce the drawings required for use in the description of the specific embodiments or the prior art. Obviously, the following drawings are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0018] Figure 1 It is a functional structure diagram of an Internet of Things security active defense device provided by an embodiment of the present invention;
[0019] Figure 2 It is a schematic diagram of the deployment method of an Internet of Things security active defense device provided by an embodiment of the present invention;
[0020] Figure 3 It is a flowchart of an active defense method for Internet of Things security based on bypass mirroring provided by an embodiment of the present invention;
[0021] Figure 4 It is a schematic diagram of another deployment method of the Internet of Things security active defense device provided by the embodiments of the present invention;
[0022] Figure 5 It is a schematic diagram of the IP address distribution of a first subnet and a second subnet provided by the embodiments of the present invention;
[0023] Figure 6 It is another schematic diagram of the IP address distribution of a first subnet and a second subnet provided by the embodiments of the present invention;
[0024] Figure 7 It is another schematic diagram of the IP address distribution of a first subnet and a second subnet provided by the embodiments of the present invention;
[0025] Figure 8 It is another schematic diagram of the IP address distribution of a first subnet and a second subnet provided by the embodiments of the present invention;
[0026] Figure 9 It is a schematic diagram of the structure of an electronic device provided by the embodiments of the present invention. Detailed implementation manners
[0027] To make the objectives, technical solutions and advantages of the present invention clearer, the technical solutions of the present invention will be described clearly and completely below. Apparently, the described embodiments are only a part rather than all of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art without making creative efforts based on the embodiments of the present invention fall within the scope protected by the present invention.
[0028] In the description of the present invention, it should be noted that the orientation or positional relationship indicated by the terms "center", "upper", "lower", "left", "right", "vertical", "horizontal", "inner", "outer", etc. is based on the orientation or positional relationship shown in the drawings, and is only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and thus should not be construed as a limitation of the present invention. In addition, the terms "first", "second", and "third" are only used for descriptive purposes and cannot be construed as indicating or implying relative importance.
[0029] In the description of the present invention, it should also be noted that unless otherwise clearly specified and defined, the terms "installation", "connection", and "coupling" should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be a direct connection or an indirect connection through an intermediate medium, and it can be the communication inside two components. For those of ordinary skill in the art, the specific meanings of the above terms in the present invention can be understood according to specific circumstances.
[0030] The embodiment of the present invention provides an Internet of Things security active defense method based on bypass mirroring. To illustrate this method, the Internet of Things security active defense device that supports the implementation of this method and its deployment method are introduced first. Figure 1 is a functional structure diagram of an Internet of Things security active defense device provided by the embodiment of the present invention, as Figure 1 shown. The device includes a terminal collection module, a terminal management module, a security detection module, and a traffic traceability module, etc., and can perform asset identification, risk monitoring, and traffic traceability on Internet of Things terminals. Specifically, the device can access traffic through multiple methods such as traffic access and offline import, and combine with a passive asset learning mechanism to perform data preprocessing, protocol parsing, and fingerprint matching on the traffic to accurately identify Internet of Things terminals; it can combine technologies such as intrusion detection and virus detection to accurately analyze and judge deep attack behaviors in the network, and actively and effectively protect the security of Internet of Things terminals in combination with professional treatment opinions; at the same time, it can further analyze risk behaviors by retaining original traffic data and restoring and extracting suspected malicious samples.
[0031] Among them, in terms of intrusion detection, the device is based on a comprehensive and in-depth protocol analysis, integrates comprehensive technical means such as data packet decoding and feature rule matching, deeply analyzes the L2-L7 layer network to judge intrusion behaviors, and accurately discovers more than 15,000 types of network attack behaviors in large categories including phishing attacks, malicious SSL certificates, redirection attacks, privilege acquisition, denial of service, and vulnerability exploitation, fully ensuring the security of the Internet of Things. It should be noted that Figure 1 only shows an Internet of Things security active defense device, and new devices obtained by adding, reducing, or replacing individual modules or functions on the basis of this device all belong to the protection scope of this embodiment.
[0032] Combined with Figure 2 , in actual application, the device can be connected to one side of the internal network core or the access switch in a bypass deployment manner, monitor the network without affecting the performance of the service network, learn the assets of Internet of Things terminals, and provide real-time detection of internal attacks and external attacks to improve the security of the network. In the figure, the external network can be the Internet or a wide area network outside the internal network; the firewall can also be replaced by other security devices or omitted, and this embodiment does not make specific restrictions.
[0033] Based on the above devices and deployment methods, Figure 3 is a flowchart of an active defense method for Internet of Things security based on bypass mirroring provided by an embodiment of the present invention. This method is executed by the above-mentioned Internet of Things security active defense device or other electronic devices, such as Figure 3 shown, the method specifically includes:
[0034] S110. Obtain the network traffic between external devices and Internet of Things devices through bypass listening.
[0035] The Internet of Things devices in this embodiment are a broad concept, including Internet of Things terminals (such as fuel dispensers, sensors, inspection instruments, etc.), and other devices (such as network communication devices, industrial control computers, office computers) that connect the Internet of Things terminals to the network and cooperate with them. External devices refer to devices from the external network. Combining Figure 2 , external devices can access Internet of Things devices in the internal network through firewalls and switches. This embodiment detects the network traffic between external devices and Internet of Things devices to promptly discover attack behaviors and perform active defenses.
[0036] S120. When an attack behavior is detected in the network traffic, construct a blocking data packet according to the characteristics of the Internet of Things device and send it out to interrupt subsequent sessions.
[0037] In the bypass deployment listening mode, when an attack behavior is detected, this embodiment simulates the communication details of both sides of the traffic, actively constructs a blocking data packet for external transmission, and interrupts subsequent sessions, thereby achieving the purpose of blocking. Optionally, the detection of attack behaviors can be implemented through the above-mentioned intrusion detection function. The characteristics of Internet of Things devices can include communication protocols, interface characteristics, device vulnerability libraries, etc.
[0038] In a specific implementation manner, if an IP address in the blacklist of a certain Internet of Things device is detected in the network traffic and is requesting access to the Internet of Things device, it can be considered that an attack behavior has been detected. At this time, a data packet for terminating the session can be constructed according to the communication protocol of the Internet of Things device and sent out. Exemplarily, when the Internet of Things device follows the TCP / IP protocol, an incorrect acknowledgment message can be returned in the third handshake message to block the communication connection.
[0039] In addition, there is also such a situation in the existing Internet of Things network: If a certain production operation system includes multiple business units, and the Internet of Things devices and networking requirements of each business unit are basically the same, then in network planning, some internal network segments are usually divided into multiple fixed-length subnets, and each fixed-length subnet is respectively assigned to each business unit; at the same time, since the types of Internet of Things devices and data transmission requirements of each business unit are basically the same, the same network structure and IP address allocation scheme are usually adopted within each fixed-length subnet to facilitate unified network management and operation and maintenance. Exemplarily, in a gas station system in a region, each gas station can be used as a business unit, and the types of Internet of Things devices within each business unit are basically the same, including office computers, industrial control computers, network communication devices (switches, routers), fuel dispensers, liquid level gauges, POS machines, and other sensors, etc. The business data that each Internet of Things device needs to collect and transmit is also basically the same, such as fuel delivery data, safety inspection data, etc. Assuming that the continuous network segment of the internal network in this area is 10.192.x.x, then usually a part of the continuous network segment is used for business units, and this network segment is divided into multiple fixed-length subnets, and each fixed-length subnet is respectively assigned to a business unit. The number of IP addresses in each subnet is the same and can accommodate the number of Internet of Things devices in each business unit. Assuming that the number of IP addresses in each subnet is 32, each IP address includes 27 bits of network number and 5 bits of host number, a total of 32 bits of binary numbers. The first IP address in the subnet segment is the network number, and the last IP address is the broadcast address. These two addresses cannot be used, and the remaining IP addresses can be assigned to Internet of Things devices. At the same time, the IP address planning scheme within each subnet is usually also the same. The corresponding IP address segments are planned in sequence according to different device types, and the same type of Internet of Things devices are assigned continuous IP addresses. For example, the 2nd and 3rd IP addresses in the subnet are assigned to office computers, the next 4 IP addresses are assigned to network communication devices, the next 7 IP addresses are assigned to fuel dispensers, and the next 3 IP addresses are assigned to liquid level gauges, etc.; the IP address allocation within each business unit is carried out according to this planning scheme.
[0040] When an attacker encounters the above-mentioned business unit system, they may assume that each business unit uses the same fixed-length subnet and the same IP address allocation scheme within the subnet. After learning the network segments of the business units in the entire area, they can divide them into multiple fixed-length subnets and adopt the same or similar attack strategies for each fixed-length subnet to detect the actual fixed-length subnet structure and at the same time increase the probability of successful attacks on the same type of devices. This embodiment refers to this attack strategy as a distributed attack behavior. However, since the attacker may not accurately know the subnet length and the IP address allocation scheme within the subnet, the fixed-length subnets divided by the attacker may not match the actual fixed-length subnets. For the convenience of distinction and description, this embodiment refers to the actual fixed-length subnet used within the business unit as the first subnet and the fixed-length subnets divided by the attacker as the second subnets. The attacker hopes that the second subnets are as close as possible to the first subnets (including the subnet capacity and the IP address allocation scheme of various types of devices within the subnet) to facilitate accurate attacks on the devices within the business unit. The so-called accurate attack means launching the same attack on IP addresses of the same device type and / or launching an attack against the vulnerabilities of the device types connected to the IP addresses. Exemplarily, when the attacker believes that the 2nd and 3rd IP addresses in each second subnet correspond to the same type of device, the same attack behavior can be launched on these two IP addresses. Then the probability of hitting any one of the two devices by this attack behavior is greater than the probability of hitting a specific one of them; and / or when the attacker believes that the 4th - 6th IP addresses in each second subnet are connected to fuel dispensers, the same attack behavior can be launched on these three IP addresses against the vulnerabilities of the fuel dispensers to further increase the probability of successful attacks on the same type of device. At the same time, the first example of the above accurate attack is also the reason why adopting the same attack strategy for multiple second subnets can increase the attack success rate. For example, there may be no vulnerabilities in the fuel dispensers in the first second subnet, but there may be vulnerabilities in the fuel dispensers in other second subnets. Therefore, launching attacks on the fuel dispensers in multiple subnets simultaneously is more likely to succeed in the attack.
[0041] To cope with this distributed attack behavior, in this embodiment, the above-mentioned Internet of Things security active defense device or other electronic devices are bypass-deployed on one side of the upper-level gateway (such as a switch) of all business units to monitor the network traffic of all business units, detect this distributed attack behavior from it and block it in a timely manner. The deployment method is as Figure 4 shown. The figure shows 3 business units.
[0042] In a specific implementation, based on the above deployment method, the Internet of Things security active defense device can be used to detect the distribution law of attack behaviors in the internal network segment in the network traffic and verify whether the attack behaviors show the characteristic of segmented repetition in the internal network segment. Optionally, first, the network segments in the internal network segment that are divided into fixed-length subnets (i.e., Figure 4The IP addresses in the business unit network segment) are arranged in ascending order; then, the attack behaviors with each IP address as the target address are arranged in the order of the IP addresses to obtain an attack behavior sequence. Specifically, from the network traffic over a period of time, the attack behaviors with each IP address as the target address can be detected; then, the detected attack behaviors are represented as type variables, each attack behavior is represented by a value, and the values of the type variables are weighted and averaged according to the number of occurrences to obtain the attack behavior values corresponding to each IP address. These values are arranged in the order of the IP addresses to obtain an attack behavior sequence.
[0043] Then, perform a Fourier transform on the attack behavior sequence to check whether the sequence spectrum is concentrated near a certain frequency. For example, check whether 80% of the energy in the sequence spectrum is concentrated in a set interval centered on a certain frequency. If so, it indicates that the attack behavior sequence shows a periodic repetition characteristic in the sequence with the IP address as the independent variable. Corresponding to the IP network segment, it means that the attack behavior shows a segmented repetition characteristic in the IP network segment, that is, there is a set of attack behaviors in a section of IP addresses, and the same set of attack behaviors appears in the next section of IP addresses. At this time, it can be considered that the above-mentioned distributed attack behavior based on the second subnet has occurred, or there is a tendency of this distributed attack behavior, and the repetition period or frequency of the attack behavior corresponds to the capacity of the second subnet. Of course, the above-mentioned periodic or segmented repetition characteristics can also be determined manually by network security personnel, and this embodiment does not make specific limitations.
[0044] Furthermore, since fixed-length subnet division is achieved by borrowing the host bits (the number of bits of the host number) in the IP address as network bits (the number of bits of the network number), for each additional bit of the network bit, the host bit will decrease by one bit, and the corresponding subnet network address will be halved. Therefore, the frequency at which the energy is concentrated in the above spectrum has a power-of-two relationship with the periodic repetition frequency of the fixed-length subnet in the business unit network segment. Through this relationship, the length of the second subnet can be calculated. Since the attacker may not accurately know the true length of the first subnet, the length of the second subnet divided by the attacker may be 2 to the nth power times the length of the first subnet, or one over 2 to the nth power, or may be equal, where n is a natural number. At this time, according to the length relationship between the second subnet and the first subnet, blocking data packets can be constructed and sent out to interrupt subsequent sessions and destroy the segmented repetition characteristic of the network structure that the attacker may know, or disrupt the IP address allocation rule of the Internet of Things devices that the attacker may know within each IP subnet. Specifically, this embodiment provides the following three alternative implementation manners:
[0045] The first alternative implementation manner is applicable to the case where the length of the second subnet is greater than the length of the first subnet, that is, the length of the second subnet is 2 to the nth power times the length of the first subnet, such as 2 times, 4 times, 8 times... Figure 5Taking 2 times as an example, the IP address distributions of two subnets are shown. As Figure 5 shown, the horizontal axis represents the IP addresses arranged in ascending order within the business unit network segment. Assuming there are 128 consecutive IP addresses, they are arranged in ascending order of host number as IP0, IP1, IP2, IP3, … IP127. Each first subnet within the business unit covers 32 IP addresses, and the entire network segment includes 4 first subnets in total; among the detected attack traffic, each second subnet covers 64 IP addresses, and the entire network segment includes 2 second subnets in total; the attacker will initiate the same or similar attack behaviors on the IP addresses in the same position within the second subnets. For example, the same or similar attack behaviors are initiated on the 1st IP in each second subnet. As Figure 5 shown, since there will be no repetition of attack strategies in the first half and the second half of the second subnet (if there is repetition, the frequency of segmented repetition will double, and the second subnet will not be the current length), when the same attack strategy is adopted for each second subnet, even in the extreme case where the attack behaviors on each IP address in the first half of the second subnet all match the device vulnerability libraries of each IP address in the first subnet, only all the devices in the first half will be hit, and all the devices in the second half will not be hit. Therefore, it will not cause the paralysis of all the first subnets. Moreover, normally, all the devices in the first half will not all be hit. Therefore, the crisis level of this situation is relatively low.
[0046] However, if the attacker has pre-mastered the allocation order of IP addresses within the subnet according to the types of Internet of Things devices, for example, has mastered that the IP addresses will be allocated in the order of office computers, network communication devices, fuel dispensers, liquid level gauges, and POS machines within each subnet, then during the attack, it may also initiate attacks on the arranged IP addresses in the order of the vulnerabilities of office computers, the vulnerabilities of network communication devices, the vulnerabilities of fuel dispensers, the vulnerabilities of liquid level gauges, and the vulnerabilities of POS machines. This situation usually occurs when the attacker has hit some devices in a certain business unit, obtained the IP allocation order of these device types, and then applied this allocation order to other business units. However, since the number of each type of device within each business unit is different, there are still differences between the allocation order and the specific IP address allocation scheme. Then combined with Figure 5It can be seen that if the attacker has the correct allocation order, the starting and ending IP addresses of each second subnet and the device types considered by the attacker are most likely to match their actual device types in the first subnet, and the probability of a successful attack is the highest. For example, after the attacker knows that the IP addresses are allocated in the order of office computers, network communication devices, fuel dispensers, liquid level gauges, and POS machines within the subnet, and assumes that the starting IP address IP1 of the first second subnet is an office computer and the ending IP address IP62 is a POS machine. Coincidentally, the starting IP address IP1 of the first first subnet is indeed an office computer, and the ending IP address IP62 of the second first subnet is also indeed a POS machine. As for whether the device types considered by the attacker for the other IP addresses in the second subnet except the starting and ending IP addresses match their actual device types in the first subnet, it is related to the specific number of devices in the business unit, and the matching probability cannot be accurately estimated. The risks of these IP addresses are lower than those of the starting and ending IP addresses of the second subnet. Therefore, in this embodiment, the repeated IP addresses (in this optional implementation, actually the starting and ending IP addresses of each second subnet) between the starting and ending IP addresses of each second subnet and those of each first subnet are used as high-risk IP addresses.
[0047] When an attack behavior targeting the high-risk IP address is detected again later, on the one hand, the IoT security active defense device constructs a blocking data packet that conforms to the protocol used by the IoT device at this address and sends it to the IoT device to prevent the IoT device from continuing to exchange data. On the other hand, it selects other devices with the lowest similarity to the IoT device at the high-risk IP address, constructs a blocking data packet according to the communication protocol of the other devices, and sends it out to deceive the attacker into changing the judgment of the device type of this IP address, making it think that the device type of this IP address is other devices, thereby affecting the IP address allocation order and subnet segment structure it has. For IP addresses other than high-risk IP addresses, conventional blocking can be performed without simulating other IoT devices to deceive the attacker. Among them, the device similarity can be determined manually or pre-calculated based on device attributes and stored in the IoT security active defense device. The specific calculation method will be described in detail in subsequent embodiments.
[0048] In addition, in addition to simulating high-risk IP addresses as other devices, the endpoint IP addresses between adjacent second subnets can also be used as interference IP addresses to interfere with the attacker's setting of the length of the second subnet. Exemplarily, combined with Figure 5, IP63 and IP64 can be used as interference addresses, where IP63 is a broadcast address in the second first subnet, and IP64 is a network number in the third first subnet, which will not be assigned to a specific IoT device. Therefore, under normal circumstances, when the access traffic of these two IP addresses is received, the connection will fail. However, after using these addresses as interference IP addresses, when an attack behavior with the interference IP as the target address is detected again (this behavior may be a detection behavior, or it may be an attack behavior generated when the above periodicity is not strict), the interference IP address can be simulated as any IoT device, and a blocking data packet is constructed and sent out according to the communication protocol of the IoT device, gradually deceiving the attacker into mistakenly believing that the IP address is an available IP address, thereby increasing the length of the second subnet. The longer the length of the second subnet, the lower the risk, thereby reducing the harm caused by distributed attack behaviors to the entire network.
[0049] The second optional implementation is applicable to the case where the length of the second subnet is the same as the length of the first subnet, such as Figure 6 As shown. At this time, if the attacker further grasps the IP allocation order of the IoT devices in the subnet, and adopts corresponding attack behaviors for the vulnerabilities of various device types, the probability of hitting the device in each first subnet will be very high. Still taking the extreme case in the first optional implementation as an example, if the attack behaviors on each IP address of the second subnet are respectively consistent with the device vulnerability library of each IP address of the first subnet, all first subnets will be hit at the same time, so the crisis level of this situation is the highest among the three optional implementations. In view of this, in addition to treating the start and end IPs of each second subnet and the repeated IPs in the start and end IPs of each first subnet (in this embodiment, it is actually the start IP address and end IP address of each second subnet) as high-risk IPs, this embodiment also extracts several IPs from the inside of the first subnet and adds them to the high-risk IP list.
[0050] When attacks targeting high-risk IP addresses are detected again in the future, the IoT active security defense device, on the one hand, constructs a blocking data packet that complies with the protocol used by the IoT device at the address and sends it to the IoT device, thereby preventing the IoT device from continuing to interact with data. On the other hand, it selects other devices with the lowest similarity to the IoT device at the current high-risk IP address, constructs a blocking data packet based on the communication protocol of the other devices, and sends it out, in order to trick the attacker into changing its judgment of the device type at the IP address, causing it to mistakenly believe that the device type at the IP address is some other device, thereby affecting the IP address allocation order and subnet segment structure that it has mastered.
[0051] Similarly, in addition to simulating high-risk IP addresses as other devices, the end IP addresses between adjacent second subnets can also be used as interference IP addresses to interfere with the attacker's setting of the length of the second subnet. Exemplarily, in combination with Figure 6 , IP31, IP32, IP95, and IP96 can be used as interference addresses. Since IP31 and IP95 are broadcast addresses in the first subnet, and IP32 and IP96 are network numbers in the first subnet, neither will be assigned to specific Internet of Things devices. Therefore, under normal circumstances, when access traffic to these IP addresses is received, it will end in a connection failure. However, after using these addresses as interference IP addresses, when an attack behavior targeting the interference IP as the destination address is detected again later, the interference IP address can be simulated as any type of Internet of Things device, and a blocking data packet can be constructed and sent out according to the communication protocol of the Internet of Things device, gradually tricking the attacker into thinking that this IP address is an available IP address, thereby increasing the length of the second subnet. The greater the length of the second subnet, the lower the risk, thus reducing the harm brought by distributed attack behaviors to the entire network.
[0052] The third optional implementation method is applicable to the case where the length of the second subnet is less than the length of the first subnet, that is, the length of the second subnet is one over 2 to the power of n of the first subnet, such as 1 / 2, 1 / 4, 1 / 8... Figure 7 Taking 1 / 2 as an example shows the IP address distribution of the two subnets, as Figure 7 shown. Although the attacker uses the same attack strategy for each second subnet, due to the different distributions of device types in the first half and the second half of the first subnet, the Internet of Things devices corresponding to the IP addresses in the same order within each second subnet are not necessarily exactly the same. The higher the similarity between the two devices, the greater the risk of this IP address. Exemplarily, for an attack behavior on a certain IP address IP2 within the second subnet, it will act on the Internet of Things devices corresponding to the IP address IP18 at the same position (same order) within two second subnets in the same first subnet. Then, the higher the similarity between the Internet of Things devices of IP2 and IP18, the greater the probability that any one of the two Internet of Things devices will be hit by the same attack behavior, thereby increasing the network risk. Therefore, in this embodiment, in addition to using the repeated IPs (in this embodiment, actually the start IP address and the end IP address of each first subnet) between the start and end IPs of each second subnet and the start and end IPs of each first subnet as high-risk IPs, the similarity of the Internet of Things devices corresponding to the IP addresses at the same position (or called the same order) within each second subnet is also calculated respectively, and the IP addresses with a similarity higher than the set threshold are also used as high-risk IP addresses.
[0053] Furthermore, the device similarity can be determined manually or calculated in the following way: First, according to the vulnerability libraries or baseline standards of two Internet of Things (IoT) devices, determine the similarity of the two IoT devices in terms of known risks, which is called the known-risk similarity. In this embodiment, the vulnerability library of each type of IoT device is obtained in advance. The more the number of the same vulnerabilities in the vulnerability libraries of the two IoT devices, the higher the known-risk similarity of the two IoT devices. Additionally, the known-risk similarity can also be determined according to the security baseline of each type of IoT device. The more the number of the same requirements in the security baselines of the two IoT devices, the higher the known-risk similarity of the two IoT devices. Optionally, the known-risk similarity can be expressed as the proportion of the number of the same vulnerabilities in the union of the vulnerability libraries of the two devices, or the proportion of the number of the same baseline requirements in the union of the baseline requirements of the two devices.
[0054] Meanwhile, the potential-risk similarity can also be determined according to the basic attributes of the two IoT devices, where the basic attributes include device usage, device form, device installation location, etc. Specifically, the similarity degree of the basic attributes between every two IoT devices is different. For example, the device similarity between an office computer and an industrial control computer is higher than that between an office computer and a fuel dispenser. Different device basic attributes mean that the security standards and attack methods of the devices are also different. Therefore, according to the device basic attributes, the similarity of the IoT devices in terms of unknown risks can be calculated, which is called the potential-risk similarity. These risks may not be identified in the existing vulnerability libraries but also need potential protection. Specifically, the potential-risk similarity can be determined manually according to the basic attributes of the devices, or can be measured by the vector similarity after converting the description of the basic attributes of the devices into an embedded vector. After obtaining the known-risk similarity and the potential-risk similarity, the two similarities are weighted and summed to determine the comprehensive similarity of the two IoT devices.
[0055] By using the above method, the similarity of the IoT devices with IP addresses assigned at the same position in two second subnets can be obtained. If there are more than two second subnets, the similarity of the IoT devices with IP addresses at the same position in every two second subnets can be calculated, and the average of these similarities can be taken as the device similarity corresponding to these IP addresses. By performing the above operations on the IP addresses at each position in each second subnet respectively, the device similarity of the IP addresses at each position can be obtained. If the device similarity at a certain position is greater than the set threshold, then the IP addresses at this position in each second subnet are regarded as high-risk IP addresses.
[0056] When an attack behavior targeting each high-risk IP address is detected again subsequently, on the one hand, the IoT security active defense device constructs a blocking data packet conforming to the protocol used by the IoT device at this address and sends it to the IoT device to prevent the IoT device from continuing to exchange data; on the other hand, it selects other devices with the lowest similarity to the IoT device at the current high-risk IP address, constructs a blocking data packet according to the communication protocol of the other devices and sends it out to deceive the attacker into changing the judgment of the device type of this IP, making it think that the device type under this IP is other devices, thereby affecting the IP address allocation order and subnet segment structure it has mastered.
[0057] In summary, the above three alternative implementation manners are all applicable to the situation where the attacker has pre-obtained the business unit network segment. Therefore Figure 5 、 Figure 6 、 Figure 7 the endpoint IP addresses of the first subnet and the second subnet overlap. If the attacker does not know the business unit network segment in advance, it may perform distributed attack or detection behaviors on a wider IP range outside the business unit network segment. At this time, the IoT security active defense device can be deployed at the entrance of a wider IP range including the business unit network segment for traffic monitoring. When a distributed attack behavior occurs, the second subnet detected may show a situation as Figure 8 shown. At this time, regardless of whether the length of the second subnet is greater than, less than or equal to the length of the first subnet, and regardless of whether the attacker has mastered the IP address allocation order of various device types inside the subnet, all first subnets will not be accurately attacked simultaneously. The attack effect more depends on the similarity of the IoT devices at the IP addresses in the same position in each second subnet. If the similarity of the IoT devices at the IP addresses in the same position is greater than the set threshold, all the IP addresses corresponding to this similarity are regarded as high-risk IP addresses, and the same operations as in the above embodiments are performed.
[0058] Exemplarily, in combination with Figure 8, Assume that IP8 and IP70 are respectively the 5th IP addresses in two second subnets. Since the positions of the two IP addresses in the two second subnets are the same, the similarity of the IoT devices actually assigned to the two IP addresses can be calculated. For example, if IP8 is assigned to a fuel dispenser and IP70 is assigned to a POS machine, then the above method is used to calculate the similarity between the fuel dispenser and the POS machine, which is used as the device similarity corresponding to the 5th IP address within the second subnet. If there are more than two second subnets, the similarities of the IoT devices corresponding to the 5th IP in each pair of second subnets are calculated respectively, and the average of these similarities is obtained to get the device similarity corresponding to the 5th IP address within the second subnet. When the length of the second subnet is 64, the same method is used to calculate a device similarity for each of the 64 IP positions in the second subnet. If the device similarity at a certain IP position is greater than the set threshold, for example, the similarity of the 5th IP address is greater than the set threshold, then the 5th IP address in each second subnet is used as a high-risk IP address, and the same operations as those in the above embodiments are performed.
[0059] In summary, this embodiment provides an active defense method for IoT security based on bypass mirroring. By using the IoT security active defense device in the bypass deployment monitoring mode, active defense is carried out on the detected attack behaviors. Specifically, when an attack behavior is detected, the communication details of both sides of the traffic are simulated, and blocking data packets are actively constructed and sent out to interrupt subsequent sessions, thereby achieving the purpose of blocking. Among them, the blocking data packets are constructed according to the communication protocols of IoT devices, and IoT devices with different protocols will correspond to different blocking data packets.
[0060] In particular, this embodiment aims at the weakness that the network structures and IP planning of each business unit in some production operation systems are similar, and provides a detection method for distributed attack behaviors, which can timely detect distributed attack behaviors that adopt the same attack strategy for each business unit; and combines subnet division to analyze the risk levels in various situations, clarifies the high-risk IP addresses that need to be key protected in various situations and specific protection measures, and improves the network security of the production operation system with multiple business units.
[0061] It can be understood that the IoT security active defense devices in the above embodiments and beneficial effects can all be replaced by other electronic devices as long as they meet the bypass deployment conditions.
[0062] Figure 9 The following is a schematic structural diagram of an electronic device provided by an embodiment of the present invention. As Figure 9 shown, the device includes a processor 60, a memory 61, an input device 62, and an output device 63; the number of processors 60 in the device can be one or more. Figure 9Taking a processor 60 as an example; the processor 60, the memory 61, the input device 62, and the output device 63 in the device can be connected through a bus or other means. Figure 9 Taking the connection through the bus as an example.
[0063] The memory 61, as a computer-readable storage medium, can be used to store software programs, computer-executable programs, and modules, such as the program instructions / modules corresponding to the Internet of Things security proactive defense method based on bypass mirroring in the embodiments of the present invention. The processor 60 executes various functional applications and data processing of the device by running the software programs, instructions, and modules stored in the memory 61, that is, implements the above-mentioned Internet of Things security proactive defense method based on bypass mirroring.
[0064] The memory 61 may mainly include a program storage area and a data storage area. Among them, the program storage area can store an operating system and application programs required for at least one function; the data storage area can store data created according to the use of the terminal, etc. In addition, the memory 61 may include high-speed random access memory, and may also include non-volatile memory, such as at least one magnetic disk storage device, a flash memory device, or other non-volatile solid-state storage devices. In some instances, the memory 61 may further include a memory remotely set relative to the processor 60, and these remote memories can be connected to the device through a network. Examples of the above network include but are not limited to the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.
[0065] The input device 62 can be used to receive input digital or character information, and generate key signal inputs related to the user settings and function controls of the device. The output device 63 may include a display device such as a display screen.
[0066] The embodiments of the present invention also provide a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, it implements the Internet of Things security proactive defense method based on bypass mirroring in any embodiment.
[0067] The computer storage medium of the embodiments of the present invention may adopt any combination of one or more computer-readable media. The computer-readable media may be computer-readable signal media or computer-readable storage media. The computer-readable storage media may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples (non-exhaustive list) of the computer-readable storage media include: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In this document, the computer-readable storage media may be any tangible medium that contains or stores a program, which can be used by or in conjunction with an instruction execution system, apparatus, or device.
[0068] The computer-readable signal media may include data signals propagated in a baseband or as part of a carrier wave, which carry computer-readable program codes. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The computer-readable signal media may also be any computer-readable media other than the computer-readable storage media, which can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device.
[0069] The program codes contained on the computer-readable media may be transmitted by any appropriate media, including but not limited to wireless, wire, optical fiber cable, RF, etc., or any suitable combination of the above.
[0070] The computer program codes for performing the operations of the present invention may be written in one or more programming languages or combinations thereof. The programming languages include object-oriented programming languages - such as Java, Smalltalk, C++, and also include conventional procedural programming languages - such as the C language or similar programming languages. The program codes may be executed entirely on the user's computer, partially on the user's computer, executed as an independent software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (for example, by using an Internet service provider to connect through the Internet).
[0071] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some or all of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the technical solutions of the embodiments of the present invention.
Claims
1. An active defense method for Internet of Things security based on bypass mirroring, characterized in that, Including: Obtain the network traffic between an external device and an Internet of Things device through bypass monitoring; When an attack behavior is detected in the network traffic, construct and send a blocking data packet according to the characteristics of the Internet of Things device to interrupt subsequent sessions; Specifically, when the internal network includes fixed-length subnets, detect the distribution law of attack behaviors in the internal network segment in the network traffic; if the attack behaviors show the characteristic of segmental repetition in the internal network segment, construct and send a blocking data packet according to the number of IP addresses in each segment and the number of IP addresses in each fixed-length subnet to interrupt subsequent sessions and destroy the characteristic of segmental repetition or disrupt the IP address allocation law of Internet of Things devices in each segment; Among them, the constructing and sending a blocking data packet according to the number of IP addresses in each segment and the number of IP addresses in each fixed-length subnet includes: taking the repeated IP addresses between the start and end IP addresses of each segment and the start and end IP addresses of each fixed-length subnet as high-risk IP addresses; if the number of IP addresses in each segment is the same as the number of IP addresses in each fixed-length subnet, extract the IP addresses inside each fixed-length subnet and add them to the high-risk IP addresses; if the number of IP addresses in each segment is less than the number of IP addresses in each fixed-length subnet, calculate the similarity of Internet of Things devices corresponding to the IP addresses at the same position in each segment, and add the IP addresses with a similarity higher than the set threshold to the high-risk IP addresses; when an attack behavior targeting each high-risk IP address is detected again, select other devices with the lowest similarity to the Internet of Things devices of each high-risk IP address, and construct and send a blocking data packet according to the communication protocols of each other device.
2. The method according to claim 1, characterized in that, The detecting the distribution law of attack behaviors in the internal network segment in the network traffic includes: Arrange the IP addresses in the segments of the internal network divided into fixed-length subnets in sequence; Arrange the attack behaviors targeting each IP address in sequence according to the order of the IP addresses to obtain an attack behavior sequence; Perform a Fourier transform on the attack behavior sequence to check whether the sequence spectrum is concentrated at a certain frequency; If so, determine that the attack behaviors show the characteristic of segmental repetition in the internal network segment.
3. The method according to claim 2, wherein If the segment of the internal network divided into fixed-length subnets is used as the target segment, the certain frequency has a power-of-two relationship with the periodic repetition frequency of the fixed-length subnets in the target segment.
4. According to the method described in claim 1, the calculating the similarity of Internet of Things devices corresponding to the IPs at the same position in each segment includes: Determine the known risk similarity according to the vulnerability library or baseline standard of two Internet of Things devices; Determine the potential risk similarity according to the basic attributes of two Internet of Things devices, where the basic attributes include at least one of device use, device form, and device installation location; Determine the comprehensive similarity of two Internet of Things devices according to the known risk similarity and potential risk similarity.
5. The method according to claim 1, wherein Replace the specific steps of constructing and sending a blocking data packet according to the number of IP addresses in each segment and the number of IP addresses in each fixed-length subnet with: When the number of IP addresses in each segment is greater than or equal to the number of IP addresses in each fixed-length subnet, the endpoint IP addresses between adjacent segments are used as interfering IP addresses; When an attack behavior targeting the interfering IP address is detected again, a blocking data packet is constructed according to the communication protocol of the Internet of Things device and sent out.
6. The method according to claim 1, wherein When an attack behavior is detected in the network traffic, constructing and sending out a blocking data packet according to the characteristics of the Internet of Things device to interrupt subsequent sessions further includes: When a blacklisted access IP of an Internet of Things device is detected in the network traffic, a data packet for terminating the session is constructed according to the communication protocol of the Internet of Things device and sent out to interrupt subsequent sessions.
7. An active defense device for Internet of Things security based on bypass mirroring, characterized in that, It includes: A traffic acquisition module, configured to acquire the network traffic between an external device and an Internet of Things device through a bypass listening method; An attack blocking module, configured to construct and send out a blocking data packet according to the characteristics of the Internet of Things device when an attack behavior is detected in the network traffic to interrupt subsequent sessions; Specifically, when the internal network includes fixed-length subnets, detect the distribution law of attack behaviors in the internal network segments in the network traffic; if the attack behaviors show the characteristic of segment repetition in the internal network segments, construct and send out a blocking data packet according to the number of IP addresses in each segment and the number of IP addresses in each fixed-length subnet to interrupt subsequent sessions and destroy the characteristic of segment repetition or disrupt the IP address allocation law of the Internet of Things devices in each segment; Among them, constructing and sending out a blocking data packet according to the number of IP addresses in each segment and the number of IP addresses in each fixed-length subnet includes: using the repeated IP addresses between the start and end IP addresses of each segment and the start and end IP addresses of each fixed-length subnet as high-risk IP addresses; if the number of IP addresses in each segment is the same as the number of IP addresses in each fixed-length subnet, extract the IP addresses inside each fixed-length subnet and add them to the high-risk IP addresses; if the number of IP addresses in each segment is less than the number of IP addresses in each fixed-length subnet, calculate the similarity of the Internet of Things devices corresponding to the IP addresses at the same position in each segment, and add the IP addresses with similarity higher than the set threshold to the high-risk IP addresses; when an attack behavior targeting each high-risk IP address is detected again, select other devices with the lowest similarity to the Internet of Things devices of each high-risk IP address, and construct and send out a blocking data packet according to the communication protocol of each other device.
8. An electronic device, characterized in that, It includes: One or more processors; A memory, configured to store one or more programs, When the one or more programs are executed by the one or more processors, the one or more processors implement the method for active defense of Internet of Things security based on bypass mirroring according to any one of claims 1-6.
9. A computer-readable storage medium, characterized in that, A computer program is stored thereon, and when the program is executed by a processor, it implements the method for active defense of Internet of Things security based on bypass mirroring according to any one of claims 1-6.
Citation Information
Patent Citations
Attack detection method and system for big data application
CN115865517A
Vulnerability protection method using blocking packet for blocking
CN119341830A