An intelligent big data network intrusion behavior analysis method

By classifying the power supply status and behavior frequency monitoring of IoT devices, setting up real-time monitoring of activity whistle and dynamically adjusting data frequency, the problem of network intrusion warning for IoT devices during power outage events is solved, and the security and response speed of the system are improved.

CN119728310BActive Publication Date: 2025-07-04PACIFIC BUSINESS SOLUTIONS (CHINA) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510230520.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-28
Publication Date
2025-07-04
Estimated Expiration
2045-02-28

AI Technical Summary

Technical Problem

Traditional network security measures are difficult to cope with the characteristics of resource limitation, heterogeneity and large-scale distribution in the Internet of Things environment, especially in monitoring network intrusion behavior before and after power outages, it is difficult to accurately warn.

Method used

By detecting the power supply status of IoT devices, it is divided into main power supply and backup power supply equipment, recording sensitive data access and configuration modification frequency, setting live whistle real-time monitoring, and using specific formulas to calculate intrusion probability and moment, dynamically adjusting the data acquisition and transmission frequency.

Benefits of technology

It realizes accurate security monitoring in the event of network instability, improves the security, stability and response speed of the system, and optimizes resource configuration.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119728310B_ABST
    Figure CN119728310B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of network security technology, and particularly to an intelligent big data network intrusion behavior analysis method. The method includes the following steps: S1: Detect the power supply status of all Internet of Things (IoT) devices, and classify the IoT devices into two categories according to the power connection method: one category is connected to the main power supply, defined as the main power supply IoT devices; the other category is not connected to the main power supply, defined as the backup power supply IoT devices; S2: For the main power supply IoT devices and the backup power supply IoT devices, respectively record the sensitive data access frequency and the configuration modification frequency. By detecting the power supply status of the IoT devices and classifying them, recording the sensitive data access and configuration modification frequencies of the main and backup power supply devices, setting up an "active sentry" for real-time monitoring; dynamically adjusting the data collection and sending frequencies, reasonably allocating tasks when the storage capacity reaches the limit, and optimizing the resource configuration, the present invention enhances the system security, stability and response speed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and particularly to an intelligent big data network intrusion behavior analysis method. Background Art

[0002] With the rapid development of Internet of Things (IoT) technology, more and more devices are connected to the Internet, forming a huge and complex network. These devices cover multiple fields from smart home, industrial automation to healthcare, greatly improving the convenience and efficiency of life and work. However, with the increase in the number of connected devices, network security issues have become increasingly prominent, especially network intrusion behaviors against IoT devices have become more frequent and complex.

[0003] IoT devices are usually deployed in various environments and face different power supply conditions, including main power supply and backup power supply. Since many IoT devices directly process sensitive data, once attacked, serious consequences will occur. Traditional network security measures often struggle to cope with the special challenges in the IoT environment, such as resource constraints, heterogeneity, and large-scale distribution characteristics. Therefore, it has become particularly urgent to develop security solutions specifically for the IoT.

[0004] To effectively prevent potential network intrusion behaviors, using big data analysis and intelligent monitoring technology has become a feasible approach. By collecting and analyzing the behavior data of a large number of devices, abnormal patterns are identified and early warnings are given. Especially for the behavior changes before and after a power outage event, more meticulous monitoring is needed because devices are more vulnerable to security risks in this situation. The intelligent monitoring system can dynamically adjust its strategies according to real-time data to ensure the security and reliability of the system even in a network-unstable situation. Summary of the Invention

[0005] To overcome the shortcomings of high difficulty in IoT security and intrusion detection, the present invention provides an intelligent big data network intrusion behavior analysis method.

[0006] The technical solution of the present invention is: an intelligent big data network intrusion behavior analysis method, including the following steps:

[0007] S1: Detect the power supply status of all IoT devices, and classify the IoT devices into two categories according to the power connection method: one category is connected to the main power supply, defined as main power supply IoT devices; the other category is not connected to the main power supply, defined as backup power supply IoT devices;

[0008] S2: For the main power supply IoT devices and backup power supply IoT devices, respectively record the sensitive data access frequency and configuration modification frequency;

[0009] S3: Based on the sensitive data access frequency and the configuration modification frequency, set a monitoring point for each type of IoT device and define it as an active sentry; the active sentry is used to closely monitor the access of sensitive data and the modification of the configuration of the IoT device before and after a power outage event occurs.

[0010] S4: According to the monitoring data provided by the active sentry, adjust the data collection frequency and data transmission frequency of the backup power IoT device.

[0011] Detect the power supply status of all IoT devices, and classify the IoT devices into two categories according to the power connection method: one category is connected to the main power supply, defined as the main power supply IoT device; the other category is not connected to the main power supply, defined as the backup power supply IoT device, including:

[0012] Evaluate the power supply status of all IoT devices.

[0013] For the main power supply IoT device, before and after data reception, respectively specify a backup power supply IoT device as the first response device.

[0014] If a power outage event occurs to the first response device, select other available devices within a nearby time, and the other available devices are the first response devices that have not experienced a power outage event.

[0015] For the main power supply IoT device and the backup power supply IoT device, respectively record the sensitive data access frequency and the configuration modification frequency, including:

[0016] Obtain the power outage duration of the first response device and the main power supply device, and use the intrusion probability calculation formula to calculate the occurrence probability of network intrusion behavior before and after the power outage. The intrusion probability calculation formula is as follows.

[0017]

[0018] Among them, P intrusion is the intrusion probability, A is the power outage duration of the first response device before data reception of the main power supply IoT device, C is the power outage duration of the first response device after data reception of the main power supply IoT device, and B is the power outage duration of the main power supply IoT device; based on the occurrence probability of the intrusion behavior, use the intrusion time determination formula to calculate the specific occurrence time of the network intrusion behavior before and after the power outage, and ∈ is the minimum value.

[0019] The intrusion time determination formula includes:

[0020]

[0021] Wherein, Q is the intrusion time, n1 is the sensitive data access frequency during the power-off process of the first response device before the main power Internet of Things device receives data, n3 is the sensitive data access frequency during the power-off process of the first response device after the main power Internet of Things device receives data, and n2 is the sensitive data access frequency during the power-off process of the main power Internet of Things device; A1 is the configuration modification frequency during the power-off process of the first response device before the main power Internet of Things device receives data, C1 is the configuration modification frequency during the power-off process of the first response device after the main power Internet of Things device sends data, B1 is the configuration modification frequency during the power-off process of the main power Internet of Things device, B0 is the configuration modification frequency during the non-power-off process of the main power Internet of Things device, a1 is the time from the moment when the storage capacity of the first response device reaches the limit before the main power Internet of Things device receives data to the moment when the main power Internet of Things device resumes power supply, c1 is the time from the moment when the storage capacity of the first response device reaches the limit after the main power Internet of Things device sends data to the moment when the main power Internet of Things device resumes power supply, b1 is the time from the start moment of the power-off of the main power Internet of Things device to the moment of resuming power supply, k is a minimum value; and α is an adjustment coefficient.

[0022] Preferably, A and C are respectively the power-off durations of the first response device, including:

[0023] The first response device includes at least two backup power Internet of Things devices.

[0024] Preferably, based on the sensitive data access frequency and the configuration modification frequency, a monitoring point is set for each type of Internet of Things device and defined as an active sentry, including:

[0025] Record the sensitive data access frequencies of the main power Internet of Things device and the backup power Internet of Things device respectively;

[0026] Generate an optimized configuration plan for the main power Internet of Things device and the backup power Internet of Things device according to the recorded sensitive data access frequencies;

[0027] The optimized configuration plan refers to allocating the configuration modification frequency for the main power Internet of Things device and the backup power Internet of Things device according to the sensitive data access frequency, which is defined as the first configuration modification frequency. The higher the sensitive data access frequency, the higher the device configuration modification frequency;

[0028] Record the configuration modification frequency after the main power Internet of Things device resumes power supply and define it as the second configuration modification frequency;

[0029] Set a dedicated active sentry for each type of Internet of Things device based on the first configuration modification frequency and the second configuration modification frequency.

[0030] Preferably, setting a dedicated active sentry for each type of Internet of Things device based on the first configuration modification frequency and the second configuration modification frequency includes:

[0031] Take the position where the active sentry first appears as the reference point, obtain the result of dividing the first configuration modification frequency by the second configuration modification frequency and define it as the configuration modification ratio;

[0032] If the configuration modification ratio is greater than 1, the active sentry pays attention to the access mode of the device;

[0033] If the configuration modification ratio is less than 1, the active sentry pays attention to the configuration modification mode of the device;

[0034] If the configuration modification ratio is equal to 1, a new active sentry is generated.

[0035] Preferably, the step of if the configuration modification ratio is equal to 1, generating a new active sentry includes:

[0036] Generate an active sentry based on the power-off occurrence times of the main power Internet of Things device and the backup power Internet of Things device;

[0037] Record the movement trajectory of the active sentry in the intersection part;

[0038] The intersection refers to the situation where when the storage capacity of the backup power Internet of Things device reaches the limit, the main power Internet of Things device has a configuration modification;

[0039] If the configuration modification frequency of the active sentry in the intersection part reaches the preset threshold, a warning is issued.

[0040] Preferably, the step of adjusting the data collection frequency and data sending frequency of the backup power Internet of Things device according to the monitoring data provided by the active sentry includes:

[0041] Adjust the data collection and sending frequencies of the backup power Internet of Things device based on the movement trajectory of the active sentry;

[0042] If the storage capacity of one of the backup power Internet of Things devices reaches the limit, the remaining devices are used to collect data;

[0043] Determine the data sending frequency of the backup power Internet of Things device based on the movement trajectory of the active sentry of the main power Internet of Things device.

[0044] Preferably, the step of determining the data sending frequency of the backup power Internet of Things device based on the movement trajectory of the active sentry of the main power Internet of Things device includes:

[0045] If the movement trajectory frequency of the active sentry in the intersection part is greater than the movement trajectory frequency of the non-intersection part, delay the data sending frequency of the backup power Internet of Things device;

[0046] If the movement trajectory frequency of the active sentry in the intersection part is less than the movement trajectory frequency of the non-intersection part, normally send the data sending frequency of the backup power Internet of Things device.

[0047] Beneficial effects: By detecting and classifying the power supply status of Internet of Things devices, this invention separately records the sensitive data access and configuration modification frequencies for main and backup power Internet of Things devices, and sets up "active sentinels" for real-time monitoring. On this basis, specific formulas are used to calculate the intrusion probability and time for accurate early warning. Then, according to the monitoring data of the "active sentinels", the data collection and transmission frequencies of backup power Internet of Things devices are dynamically adjusted. When the storage capacity limit of the devices is reached, the collection tasks are reasonably allocated. Also, the transmission frequency is optimized according to the active sentinel trajectory of the main power devices. Thus, on the basis of achieving accurate security monitoring, the risk prevention ability is effectively improved, the resource allocation is further optimized, and the system security, stability and response speed are comprehensively enhanced. Brief Description of the Drawings

[0048] Figure 1 is a flowchart of the intelligent big data network intrusion behavior analysis method of this invention;

[0049] Figure 2 is a schematic diagram of data collection and transmission of main power Internet of Things devices and backup power Internet of Things devices of this invention. Detailed Embodiments

[0050] Next, the technical solutions in the embodiments of this invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of this invention. Obviously, the described embodiments are only a part of the embodiments of this invention, rather than all of the embodiments. Based on the embodiments of this invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of this invention.

[0051] An intelligent big data network intrusion behavior analysis method, as Figure 1 shown, includes the following steps:

[0052] S1: Detect the power supply status of all Internet of Things devices, and classify the Internet of Things devices into two categories according to the power connection method: one category is connected to the main power supply, defined as the main power Internet of Things device; the other category is not connected to the main power supply, defined as the backup power Internet of Things device;

[0053] S2: For the main power Internet of Things devices and backup power Internet of Things devices, separately record the sensitive data access frequency and the configuration modification frequency;

[0054] S3: Based on the sensitive data access frequency and the configuration modification frequency, set up a monitoring point for each category of Internet of Things devices and define it as an active sentinel; the active sentinel is used to closely monitor the access of sensitive data and the modification of the configuration of Internet of Things devices before and after a power outage event;

[0055] S4: Adjust the data acquisition frequency and data transmission frequency of the Internet of Things devices with backup power according to the monitoring data provided by the mobile sentry.

[0056] Detect the power supply status of all Internet of Things devices, and classify the Internet of Things devices into two categories according to the power connection method: one is connected to the main power supply, defined as the main power supply Internet of Things device, and the other is not connected to the main power supply, defined as the backup power supply Internet of Things device, including:

[0057] Evaluate the power supply status of all Internet of Things devices.

[0058] For the main power supply Internet of Things devices, before and after data reception, respectively specify a backup power supply Internet of Things device as the first response device.

[0059] If a power outage event occurs to the first response device, select other available devices within a nearby time. The other available devices are the first response devices that have not experienced a power outage event.

[0060] For further explanation, as Figure 2 shown, Internet of Things devices have the characteristics of flexible deployment and automatic data collection. Therefore, not all Internet of Things devices are connected to the main power supply; due to the differences in the working environment and the uncertainty of power supply, power outage events may occur to both the main power supply Internet of Things devices and the backup power supply Internet of Things devices; and the backup power supply needs to send data to devices with the main power supply, such as the main server or the central control system; the first response device is used to help detect network intrusion behavior when the device using the main power supply has a power outage; the first response devices that have not experienced a power outage event are, for example, there are 4 Internet of Things devices with backup power, and two are specified as the first response devices. If the two specified Internet of Things devices with backup power have a power outage event, then select the remaining two Internet of Things devices with backup power that have not experienced a power outage event as the first response devices.

[0061] For the main power supply Internet of Things devices and the backup power supply Internet of Things devices, respectively record the sensitive data access frequency and the configuration modification frequency, including:

[0062] Obtain the power outage duration of the first response device and the main power supply device, and calculate the probability of network intrusion behavior before and after the power outage using the intrusion probability calculation formula. The intrusion probability calculation formula is as follows,

[0063]

[0064] where, P intrusionis the intrusion probability, A is the power-off duration of the first response device before the main power IoT device receives data, C is the power-off duration of the first response device after the main power IoT device receives data, and B is the power-off duration of the main power IoT device; based on the probability of intrusion behavior occurring, use the intrusion time determination formula to calculate the specific occurrence time of network intrusion behavior before and after power-off, where ∈ is a minimum value;

[0065] For further explanation, ∈ is a minimum value; represents the impact of the power-off duration of the main power IoT device on the intrusion probability; represents the impact of the power-off duration of the first response device on the intrusion probability; is an interaction term, representing the combined impact when both are powered off simultaneously, used to adjust the overestimation caused by a single factor; when the first response device or the main power device is powered off alone, the intrusion risk will increase; but when both are powered off simultaneously, this risk is not simply additive, but needs to be adjusted through the interaction term to avoid overestimating the intrusion probability; adding a minimum value is to prevent the denominator from being zero and ensure the mathematical stability of the formula; A is the power-off duration of the backup power IoT device specified before the main power IoT device receives data, and C is the power-off duration of the backup power IoT device specified after the main power IoT device sends data.

[0066] The intrusion time determination formula includes:

[0067]

[0068] where Q is the intrusion time, n1 is the sensitive data access frequency during the power-off process of the first response device before the main power IoT device receives data, n3 is the sensitive data access frequency during the power-off process of the first response device after the main power IoT device receives data, and n2 is the sensitive data access frequency during the power-off process of the main power IoT device; A1 is the configuration modification frequency during the power-off process of the first response device before the main power IoT device receives data, C1 is the configuration modification frequency during the power-off process of the first response device after the main power IoT device sends data, B1 is the configuration modification frequency during the power-off process of the main power IoT device, B0 is the configuration modification frequency during the non-power-off process of the main power IoT device, a1 is the time from when the storage capacity of the first response device reaches the limit before the main power IoT device receives data to when the main power IoT device resumes power supply, c1 is the time from when the storage capacity of the first response device reaches the limit after the main power IoT device sends data to when the main power IoT device resumes power supply, b1 is the time from the start of the power-off of the main power IoT device to the restoration of power supply, k is a minimum value; α is an adjustment coefficient.

[0069] For further explanation, k is a minimum value; α is an adjustment coefficient used to control the degree of influence; And represents the total sum of the configuration modification frequencies of the first response device during the power-off process. represents the total sum of the configuration modification frequencies of the main power Internet of Things device during the power-off process. Q represents the time point of potential intrusion occurrence calculated based on the sensitive data access frequency and the configuration modification frequency. n1, n2, and n3 reflect the frequencies of each device accessing sensitive data during the power-off process, which are important indicators for evaluating system behavior. A1, B1, and C1 reflect the frequencies of each device making configuration modifications during the power-off process, which helps identify abnormal behaviors. B0 serves as a reference value to help compare the changes in configuration modification frequencies before and after power-off and evaluate the impact of power-off on system behavior. Assume in a simple scenario, there is a group of Internet of Things devices. The power-off duration of the main power Internet of Things device is b1 = 10 minutes. After the power supply is restored, its sensitive data access frequency during the power-off process is n2 = 5 times / minute, and the configuration modification frequency B0 = 2 times / minute. There are two first response devices. The power-off duration of the first response device before data reception is A = 8 minutes, the sensitive data access frequency during the power-off process is n1 = 4 times / minute, and the configuration modification frequency A1 = 3 times / minute. The power-off duration of the first response device after data reception is C = 6 minutes, the sensitive data access frequency is n3 = 3 times / minute, and the configuration modification frequency C1 = 2 times / minute. Set the adjustment coefficient α = 0.5 and the minimum value k = 0.1. The time from when the storage capacity of the first response device reaches the limit to when the main power Internet of Things device restores power supply is a1 = 3 minutes and c1 = 2 minutes. Then B1 = 2.25 and Q = 29.25. The calculated Q = 29.25 represents the time point (here the unit of the time point depends on the actual scenario setting, assumed to be minutes) when potential intrusion may occur starting from some key event starting points.

[0070] A and C are respectively the power-off durations of the first response device, including:

[0071] The first response device includes at least two backup power Internet of Things devices.

[0072] For further explanation, when the main server or the central control system is powered off, the backup power Internet of Things devices continue to collect and store data. When the main server or the central control system restores power supply, the main power Internet of Things device quickly collects and sends data. At this time, the data of the backup power Internet of Things devices will not be directly sent to the main server or the central control system in its entirety, resulting in a risk of network intrusion behavior when the main server or the central control system makes configuration modifications because there is a lack of data collected by the backup power Internet of Things devices to correct the configuration modifications.

[0073] Based on the sensitive data access frequency and the configuration modification frequency, set a monitoring point for each type of Internet of Things device and define it as an active sentry, including:

[0074] Record the sensitive data access frequencies of the main - power Internet - of - Things (IoT) devices and the backup - power IoT devices respectively;

[0075] Generate an optimization configuration plan for the main - power IoT devices and the backup - power IoT devices according to the recorded sensitive data access frequencies;

[0076] The optimization configuration plan refers to allocating configuration modification frequencies for the main - power IoT devices and the backup - power IoT devices according to the sensitive data access frequencies, which is defined as the first configuration modification frequency. The higher the sensitive data access frequency, the higher the device configuration modification frequency;

[0077] Record the configuration modification frequency after the main - power IoT device resumes power supply and define it as the second configuration modification frequency;

[0078] Set a dedicated activity sentinel for each type of IoT device based on the first configuration modification frequency and the second configuration modification frequency.

[0079] For further explanation, first record the sensitive data access frequencies of the main - power IoT devices and the backup - power IoT devices respectively to establish the normal behavior baseline of each device. Based on these access frequencies, generate an optimization configuration plan to adjust the device configuration modification frequency (the first configuration modification frequency) to ensure that devices with high access frequencies have higher configuration modification frequencies. When the main - power IoT device resumes power supply, record the new configuration modification frequency (the second configuration modification frequency). Finally, based on the first and second configuration modification frequencies, set a dedicated activity sentinel for each type of device to monitor and compare the behaviors before and after power - off in real - time, promptly detect and respond to any anomalies, so as to identify potential internal network intrusions from seemingly normal accesses and modifications.

[0080] Set a dedicated activity sentinel for each type of IoT device based on the first configuration modification frequency and the second configuration modification frequency, including:

[0081] Take the position where the activity sentinel first appears as the reference point, obtain the result of dividing the first configuration modification frequency by the second configuration modification frequency and define it as the configuration modification ratio;

[0082] If the configuration modification ratio is greater than 1, the activity sentinel pays attention to the access mode of the device;

[0083] If the configuration modification ratio is less than 1, the activity sentinel pays attention to the configuration modification mode of the device;

[0084] If the configuration modification ratio is equal to 1, generate a new activity sentinel.

[0085] Further explanation is that the first configuration modification frequency is obtained based on the sensitive data access frequencies of the main - power Internet - of - Things devices and the backup - power Internet - of - Things devices, while the second configuration modification frequency is obtained when the main - power Internet - of - Things devices resume power supply; since the data collected by the backup - power devices needs to be sent to the devices with the main power, if the configuration ratio is greater than 1, it means that the sensitive data with a high access frequency when the main - power Internet - of - Things devices resume power supply has not been configured and modified, indicating an abnormal behavior; conversely, if the configuration ratio is less than 1, it means that the sensitive data with a low access frequency when the main - power Internet - of - Things devices resume power supply has been configured and modified, also indicating an abnormal problem; and when the configuration modification ratio is 1, it is determined by the movement trajectory of the active sentry.

[0086] If the configuration modification ratio is equal to 1, a new active sentry is generated, including:

[0087] Generating an active sentry based on the power - off occurrence times of the main - power Internet - of - Things devices and the backup - power Internet - of - Things devices;

[0088] Recording the movement trajectory of the active sentry in the intersection part;

[0089] The intersection refers to the situation where when the storage capacity of the backup - power Internet - of - Things devices reaches the limit, the main - power Internet - of - Things devices have configuration modifications;

[0090] If the configuration modification frequency of the active sentry in the intersection part reaches the preset threshold, a warning is issued.

[0091] To further illustrate, assume there are three devices. Device 1 and Device 2 are backup power Internet of Things devices, and Device 3 is the main power Internet of Things device. When Device 3 loses power, Devices 1 and 2 continue to collect data until the storage capacity limit is reached. At this time, since the main power supply connected to Device 3 is powered off, the data collected by Devices 1 and 2 cannot be sent. When the main power supply resumes power supply, Device 3 has a configuration modification behavior, which is the intersection part. In the active sentry monitoring mechanism, the active sentry will record the movement trajectory and configuration modification frequency in the intersection part. If the configuration modification frequency reaches the preset threshold, a warning will be issued. Because when making configuration modifications in the intersection part, the data support of Devices 1 and 2 is lacking. Normally, configuration modifications should be based on comprehensive data. Therefore, when the configuration modification frequency is abnormally high, there is likely a network intrusion behavior, and the active sentry determines whether there is a security risk by monitoring this special situation. The active sentry obtains the movement trajectory through the monitoring nodes deployed in the Internet of Things device network. These monitoring nodes record the device nodes and timestamps passed by the active sentry in real time, thereby generating the movement trajectory data of the active sentry. For the judgment of the movement trajectory frequency in the intersection part and the non-intersection part, the system will count the number of device nodes passed by the active sentry in the intersection part and the non-intersection part within a preset time period (such as every minute). If the number of device nodes passed in the intersection part is more than that in the non-intersection part, it is determined that the movement trajectory frequency in the intersection part is greater than that in the non-intersection part; otherwise, it is less. According to this judgment result, the system automatically adjusts the data sending frequency of the backup power Internet of Things devices.

[0092] Adjust the data collection frequency and data sending frequency of the backup power Internet of Things devices according to the monitoring data provided by the active sentry, including:

[0093] Based on the movement trajectory of the active sentry, adjust the data collection and sending frequencies of the backup power Internet of Things devices;

[0094] If the storage capacity of one of the backup power Internet of Things devices reaches the limit, use the remaining devices to collect data;

[0095] Based on the movement trajectory of the active sentry of the main power Internet of Things device, determine the data sending frequency of the backup power Internet of Things devices.

[0096] To further illustrate, if the storage capacity of Device 1 reaches the limit, use Device 2 to continue storing data; if the storage capacity of Device 2 reaches the limit, use Device 1 to continue storing data; the purpose of determining the data sending frequency of the backup power Internet of Things devices is to verify the occurrence of network intrusion behavior.

[0097] Based on the movement trajectory of the active sentry of the main power Internet of Things device, determine the data sending frequency of the backup power Internet of Things devices, including:

[0098] If the movement trajectory frequency of the active sentry in the intersection part is greater than that in the non-intersection part, the data sending frequency of the spare power IoT device is delayed;

[0099] If the movement trajectory frequency of the active sentry in the intersection part is less than that in the non-intersection part, the data sending frequency of the spare power IoT device is sent normally.

[0100] For further explanation, the reason for delaying the data sending frequency of the spare power IoT device is that since the configuration modification occurs when the movement trajectory frequency in the intersection part is greater than that in the non-intersection part, the configuration modification is abnormal at this time because only a small part of the data, rather than all the data, is modified in the intersection part.

[0101] The above has introduced this application in detail. Specific examples are used in this article to elaborate on the principle and implementation manner of this application. The description of the above embodiments is only used to help understand the method and its core idea of this application; at the same time, for those of ordinary skill in the art, according to the idea of this application, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to this application.

Claims

1. An intelligent big data network intrusion behavior analysis method, characterized in that It includes the following steps: S1: Detect the power supply status of all Internet of Things devices, and classify the Internet of Things devices into two categories according to the power connection method: one category is connected to the main power supply, defined as the main power supply Internet of Things devices; the other category is not connected to the main power supply, defined as the backup power supply Internet of Things devices; S2: For the main power supply Internet of Things devices and the backup power supply Internet of Things devices, respectively record the sensitive data access frequency and the configuration modification frequency; S3: Based on the sensitive data access frequency and the configuration modification frequency, set a monitoring point for each category of Internet of Things devices and define it as an active sentry; the active sentry is used to closely monitor the access of sensitive data and the modification of the configuration of the Internet of Things devices before and after a power outage event; S4: According to the monitoring data provided by the active sentry, adjust the data acquisition frequency and the data sending frequency of the backup power supply Internet of Things devices; The step of detecting the power supply status of all Internet of Things devices and classifying the Internet of Things devices into two categories according to the power connection method: one category is connected to the main power supply, defined as the main power supply Internet of Things devices; the other category is not connected to the main power supply, defined as the backup power supply Internet of Things devices, including: Evaluate the power supply status of all Internet of Things devices; For the main power supply Internet of Things devices, before and after data reception, respectively specify a backup power supply Internet of Things device as the first response device; If a power outage event occurs to the first response device, select other available devices within a nearby time, and the other available devices are the first response devices that have not experienced a power outage event; The step of respectively recording the sensitive data access frequency and the configuration modification frequency for the main power supply Internet of Things devices and the backup power supply Internet of Things devices includes: Obtain the power outage duration of the first response device and the main power supply device, and calculate the probability of network intrusion behavior before and after the power outage using the intrusion probability calculation formula. The intrusion probability calculation formula is as follows, Among them, P intrusion is the intrusion probability, A is the power-off duration of the first response device before the main power Internet of Things device receives data, C is the power-off duration of the first response device after the main power Internet of Things device receives data, and B is the power-off duration of the main power Internet of Things device; based on the occurrence probability of intrusion behavior, the specific occurrence time of network intrusion behavior before and after power-off is calculated using the intrusion time determination formula, and ∈ is the minimum value; The intrusion moment determination formula includes: where Q is the intrusion moment, n1 is the sensitive data access frequency during the power outage of the first response device before data reception of the main power supply Internet of Things device, n3 is the sensitive data access frequency during the power outage of the first response device after data reception of the main power supply Internet of Things device, n2 is the sensitive data access frequency during the power outage of the main power supply Internet of Things device; A1 is the configuration modification frequency during the power outage of the first response device before data reception of the main power supply Internet of Things device, C1 is the configuration modification frequency during the power outage of the first response device after data transmission of the main power supply Internet of Things device, B1 is the configuration modification frequency during the power outage of the main power supply Internet of Things device, B0 is the configuration modification frequency during the non-power outage process of the main power supply Internet of Things device, a1 is the time from the moment when the storage capacity of the first response device before data reception of the main power supply Internet of Things device reaches the limit to the moment when the main power supply Internet of Things device resumes power supply, c1 is the time from the moment when the storage capacity of the first response device after data transmission of the main power supply Internet of Things device reaches the limit to the moment when the main power supply Internet of Things device resumes power supply, b1 is the time from the start moment of the power outage of the main power supply Internet of Things device to the moment of resuming power supply, k is a minimum value; α is an adjustment coefficient.

2. An intelligent big data network intrusion behavior analysis method according to claim 1, It is characterized in that The power-off durations of the first response devices A and C respectively include: The first response devices include at least two backup power Internet of Things devices.

3. The intelligent big data network intrusion behavior analysis method according to claim 1, characterized in that, Based on the sensitive data access frequency and the configuration modification frequency, A monitoring point is set for each type of Internet of Things device and defined as an active sentry, including: Respectively record the sensitive data access frequencies of the main power Internet of Things devices and the backup power Internet of Things devices; According to the recorded sensitive data access frequencies, generate an optimized configuration plan for the main power Internet of Things devices and the backup power Internet of Things devices; The optimized configuration plan refers to allocating the configuration modification frequency for the main power Internet of Things devices and the backup power Internet of Things devices according to the sensitive data access frequency, which is defined as the first configuration modification frequency. The higher the sensitive data access frequency, the higher the device configuration modification frequency; Record the configuration modification frequency after the main power Internet of Things device resumes power supply and define it as the second configuration modification frequency; Based on the first configuration modification frequency and the second configuration modification frequency, set a dedicated active sentry for each type of Internet of Things device.

4. The intelligent big data network intrusion behavior analysis method according to claim 3, characterized in that, The setting of a dedicated active sentry for each type of Internet of Things device based on the first configuration modification frequency and the second configuration modification frequency includes: Take the position where the active sentry first appears as the reference point, obtain the result of dividing the first configuration modification frequency by the second configuration modification frequency and define it as the configuration modification ratio; If the configuration modification ratio is greater than 1, the active sentry pays attention to the access mode of the device; If the configuration modification ratio is less than 1, the active sentry pays attention to the configuration modification mode of the device; If the configuration modification ratio is equal to 1, generate a new active sentry.

5. An intelligent big data network intrusion behavior analysis method according to claim 4, characterized in that, The generation of a new active sentry when the configuration modification ratio is equal to 1 includes: Generate an active sentry based on the power-off occurrence times of the main power Internet of Things devices and the backup power Internet of Things devices; Record the movement trajectory of the active sentry in the intersection part; The intersection refers to the situation where when the storage capacity of the backup power Internet of Things device reaches the limit, the main power Internet of Things device undergoes a configuration modification; If the configuration modification frequency of the active sentry in the intersection part reaches the preset threshold, issue a warning.

6. The intelligent big data network intrusion behavior analysis method according to claim 1, characterized in that, The adjustment of the data collection frequency and data transmission frequency of the backup power Internet of Things device according to the monitoring data provided by the active sentry includes: Based on the movement trajectory of the active sentry, adjust the data collection and transmission frequencies of the backup power Internet of Things device; If the storage capacity of one of the backup power Internet of Things devices reaches the limit, use the remaining devices to collect data; Based on the movement trajectory of the active sentry of the main power Internet of Things device, determine the data transmission frequency of the backup power Internet of Things device.

7. An intelligent big data network intrusion behavior analysis method according to claim 6, characterized in that, The determination of the data transmission frequency of the backup power Internet of Things device based on the movement trajectory of the active sentry of the main power Internet of Things device includes: If the movement trajectory frequency of the active sentry in the intersection part is greater than the movement trajectory frequency of the non-intersection part, delay the data transmission frequency of the backup power Internet of Things device; If the movement trajectory frequency of the active sentry in the intersection part is less than the movement trajectory frequency of the non-intersection part, normally transmit the data transmission frequency of the backup power Internet of Things device.

Citation Information

Patent Citations

  • Network information intrusion detection early warning system and method based on deep learning

    CN118337512A

  • Large-scale network security defense system based on collaborative intrusion detection

    CN119544381A