A network security intelligent monitoring method and related device for Internet of Things devices

By building a traffic security baseline and access behavior abnormality detection, the accuracy problem in network security monitoring of IoT devices is solved, efficient abnormality detection and emergency response are achieved, and the network security of the equipment is ensured.

CN119922018BActive Publication Date: 2025-07-04广东宜通衡睿科技有限公司
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510406289.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-02
Publication Date
2025-07-04
Estimated Expiration
2045-04-02

AI Technical Summary

Technical Problem

In the prior art, the network security monitoring of IoT devices has problems such as low accuracy in traffic abnormality detection and high error detection rate of user access behavior abnormality detection, which leads to the inability to accurately monitor the network security status of the equipment.

Method used

The traffic security baseline is constructed based on correlation feature selection and attack path impact analysis, and the access behavior abnormality detection is carried out based on user historical access behavior information, and the traffic security baseline and access behavior abnormality detection results determine whether to initiate emergency response policies.

Benefits of technology

It improves the accuracy of Internet of Things equipment network security monitoring, reduces the error of traffic abnormality detection and missed detection of access behavior abnormality detection, and can promptly activate emergency response strategies to ensure the network security of the equipment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119922018B_ABST
    Figure CN119922018B_ABST
Patent Text Reader

Abstract

The present invention discloses a network security intelligent monitoring method and related device for Internet of Things devices, which relates to the technical field of network security. The method includes: performing feature screening and integration on preliminary traffic feature data generated from Internet of Things device traffic data based on correlation feature selection to obtain target traffic feature data; performing a protection ability assessment of the traffic abnormal state based on attack path impact analysis to construct a traffic security baseline; using the target traffic feature data to perform traffic anomaly detection based on the traffic security baseline; determining a focus time window and an abnormal access behavior sequence based on user historical access behavior information; performing access behavior anomaly detection on user behavior monitoring information based on the access behavior distribution generated by the focus time window and the abnormal access behavior sequence; and determining whether to send a warning message based on the traffic anomaly detection result and the access behavior anomaly detection result. The present invention can more effectively improve the reliability of network security monitoring of Internet of Things devices.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a network security intelligent monitoring method and related device for Internet of Things devices. Background Art

[0002] With the development of information technology, more and more Internet of Things devices are connected to the network. Once a certain Internet of Things device is maliciously attacked, it will also pose security problems to other Internet of Things devices. Therefore, the network security monitoring of Internet of Things devices has become a top priority. Network traffic anomaly detection is a very important part of security monitoring. Network traffic anomaly detection needs to first extract traffic feature data. Currently, traffic feature data is usually extracted by a fixed threshold method, but this method will cause the loss of important features, thus reducing the accuracy of traffic anomaly detection. Network traffic anomaly detection is usually achieved by comparing traffic features with a traffic security baseline. At present, the construction of the traffic security baseline does not consider the protection ability of Internet of Things devices in the traffic anomaly state, resulting in insufficient reliability of the constructed traffic security baseline and large errors in traffic anomaly detection results. At the same time, in the current network security monitoring of Internet of Things devices, the anomaly detection of user access behavior is usually achieved by keyword matching of network logs, but this method will cause a high false detection rate, resulting in the inability to accurately monitor the actual network security status of Internet of Things devices. Summary of the Invention

[0003] The purpose of the present invention is to overcome the deficiencies of the prior art. The present invention provides a network security intelligent monitoring method and related device for Internet of Things devices, which can more accurately detect abnormal situations existing in Internet of Things devices, so as to be able to promptly initiate an emergency response strategy and ensure the network security of Internet of Things devices.

[0004] To solve the above technical problems, the present invention provides a network security intelligent monitoring method for Internet of Things devices, and the method includes:

[0005] Performing feature screening and integration on the preliminary traffic feature data generated from the traffic data of Internet of Things devices based on correlation feature selection to obtain target traffic feature data;

[0006] Evaluating the protection ability of Internet of Things devices in the traffic anomaly state based on attack path impact analysis to obtain a protection ability evaluation result, and constructing a traffic security baseline based on the protection ability evaluation result;

[0007] Performing traffic anomaly detection using the target traffic feature data based on the traffic security baseline to obtain a traffic anomaly detection result;

[0008] Determining a focus time window and an abnormal access behavior sequence based on the user historical access behavior information of the Internet of Things device;

[0009] Perform access behavior anomaly detection on the user behavior monitoring information based on the access behavior distribution and abnormal access behavior sequence generated by the focus time window, and obtain the access behavior anomaly detection result;

[0010] Judge whether it is necessary to start the emergency response strategy based on the traffic anomaly detection result and the access behavior anomaly detection result.

[0011] Optionally, the feature screening and integration of the preliminary traffic feature data generated from the Internet of Things device traffic data based on the correlation feature selection to obtain the target traffic feature data includes:

[0012] Perform preliminary feature extraction on the Internet of Things device traffic data based on the attention mechanism to obtain the preliminary traffic feature data;

[0013] Calculate the feature correlation of the feature attribute set for the preliminary traffic feature data, and remove redundancy from the feature attribute set based on the feature correlation to obtain the target feature attribute set;

[0014] Calculate the correlation coefficient between the target feature attribute set and the category feature set in the preliminary traffic feature data, and screen the first feature sequence set based on the correlation coefficient;

[0015] Calculate the mutual information between the target feature attribute set and the category feature set, screen the second feature sequence set based on the mutual information, and perform feature integration based on the first feature sequence set and the second feature sequence set to obtain the target traffic feature data.

[0016] Optionally, the evaluation of the protection ability of the Internet of Things device in the traffic anomaly state based on the attack path impact analysis to obtain the protection ability evaluation result includes:

[0017] Perform attack path analysis based on the vulnerability information obtained by the Internet of Things device in the past traffic anomaly state to obtain several corresponding attack paths, and calculate the impact value of the attack path based on the fuzzy evaluation matrix;

[0018] Extract the feature information of the defense mechanism adopted for each attack path to obtain the defense mechanism feature information;

[0019] Calculate the defense success rate based on the defense mechanism feature information using resource dependency analysis, and calculate the attack path utilization value based on the impact value of the attack path combined with the attack path probability value;

[0020] Evaluate the protection ability of the traffic anomaly state based on the attack path utilization value and the defense success rate to obtain the protection ability evaluation result.

[0021] Optionally, constructing a traffic security baseline based on the protection ability evaluation result includes:

[0022] Determine the baseline range based on the periodic distribution law of historical traffic data, and perform fluctuation statistics on the historical traffic data to obtain the normal traffic fluctuation range;

[0023] Determine the upper and lower limit tolerances of traffic based on the protection ability evaluation results, and construct a traffic security baseline based on the baseline range, the normal traffic fluctuation range, and the upper and lower limit tolerances of traffic.

[0024] Optionally, performing traffic anomaly detection using the target traffic feature data based on the traffic security baseline to obtain a traffic anomaly detection result, including:

[0025] Compare the target traffic feature data with each parameter in the traffic security baseline to obtain a comparison result, and perform traffic anomaly detection based on the comparison result to obtain a traffic anomaly detection result.

[0026] Optionally, determining the focus time window and the abnormal access behavior sequence based on the user's historical access behavior information of the Internet of Things device, including:

[0027] Determine the number of historical access behaviors of the user's historical access behavior information in each preset time window, and use the preset time window corresponding to the number of historical access behaviors greater than or equal to the preset number threshold as the focus time window;

[0028] Classify a number of behavior sequences generated from the user's historical access behavior information based on a clustering algorithm to obtain a number of behavior sequence classes;

[0029] Calculate the correlation coefficient between each user access behavior based on a number of behavior sequence classes;

[0030] Determine the abnormal access behavior sequence based on the correlation coefficient combined with the output probability of each behavior sequence class.

[0031] Optionally, performing access behavior anomaly detection on the user behavior monitoring information based on the access behavior distribution and the abnormal access behavior sequence generated from the focus time window to obtain an access behavior anomaly detection result, including:

[0032] Perform distribution statistics on the historical access behavior information in the focus time window to obtain an access behavior distribution;

[0033] Construct an access behavior line based on the access behavior distribution, and perform access behavior anomaly detection on the user behavior monitoring information based on the access behavior line to obtain a first preliminary access behavior anomaly detection result;

[0034] Match the user behavior monitoring information with the abnormal access behavior sequence to obtain a matching result, and determine a second preliminary access behavior anomaly monitoring result based on the matching result;

[0035] Perform duplicate redundancy removal on the first preliminary access behavior anomaly detection result and the second preliminary access behavior anomaly detection result to obtain an access behavior anomaly detection result.

[0036] In addition, the present invention also provides a network security intelligent monitoring device for an Internet of Things device, and the device includes:

[0037] A traffic feature extraction module: used to perform feature screening and integration on the preliminary traffic feature data generated from the traffic data of the Internet of Things device based on correlation feature selection to obtain target traffic feature data;

[0038] A traffic baseline construction module: used to evaluate the protection ability of the Internet of Things device against traffic anomaly states based on attack path impact analysis to obtain a protection ability evaluation result, and construct a traffic security baseline based on the protection ability evaluation result;

[0039] A traffic anomaly detection module: used to perform traffic anomaly detection using the target traffic feature data based on the traffic security baseline to obtain a traffic anomaly detection result;

[0040] A time window and behavior sequence determination module: used to determine a focus time window and an abnormal access behavior sequence based on the user's historical access behavior information of the Internet of Things device;

[0041] An access behavior anomaly detection module: used to perform access behavior anomaly detection on the user behavior monitoring information based on the access behavior distribution generated by the focus time window and the abnormal access behavior sequence to obtain an access behavior anomaly detection result;

[0042] An emergency response judgment module: used to judge whether it is necessary to start an emergency response strategy based on the traffic anomaly detection result and the access behavior anomaly detection result.

[0043] In addition, the present invention also provides an electronic device, which includes a processor and a memory. The memory is used to store instructions, and the processor is used to call the instructions in the memory so that the electronic device executes the above-mentioned network security intelligent monitoring method for the Internet of Things device.

[0044] In addition, the present invention also provides a computer-readable storage medium, which stores computer instructions. When the computer instructions run on an electronic device, the electronic device is caused to execute the above-mentioned network security intelligent monitoring method for the Internet of Things device.

[0045] In the embodiments of the present invention, feature screening and integration are performed on the preliminary traffic feature data generated from the traffic data of Internet of Things (IoT) devices based on correlation feature selection, which can avoid the loss of important features, ensure the accuracy of feature extraction while removing redundant features. The protection ability of IoT devices in a traffic abnormal state is evaluated based on the analysis of the impact of the attack path, which can accurately evaluate the protection ability of IoT devices in a traffic abnormal state. A traffic security baseline is constructed based on the evaluation result of the protection ability, making the constructed traffic security baseline more reliable. Traffic anomaly detection is performed through this traffic security baseline, which can greatly reduce the error of traffic anomaly detection. The focus time window and the abnormal access behavior sequence are determined based on the user's historical access behavior information of the IoT device. Abnormal access behavior detection is performed on the user behavior monitoring information based on the access behavior distribution generated by the focus time window and the abnormal access behavior sequence, which can improve the accuracy of abnormal access behavior detection and avoid missed detection and false detection. The actual network security status of IoT devices can be accurately monitored. When an abnormal situation is detected, an emergency response strategy can be initiated in a timely manner to ensure the network security of IoT devices. BRIEF DESCRIPTION OF THE DRAWINGS

[0046] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0047] Figure 1 It is a schematic flowchart of the network security intelligent monitoring method for IoT devices in the embodiments of the present invention;

[0048] Figure 2 It is a schematic flowchart of the network security intelligent monitoring method for IoT devices in another embodiment of the present invention;

[0049] Figure 3 It is a schematic diagram of the structural composition of the network security intelligent monitoring device for IoT devices in the embodiments of the present invention;

[0050] Figure 4 It is a schematic diagram of the structural composition of an electronic device in the embodiments of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0051] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0052] Embodiment 1

[0053] Please refer to Figure 1 , Figure 1 , which is a schematic flowchart of the network security intelligent monitoring method for Internet of Things devices in the embodiments of the present invention. The method includes:

[0054] S11: Based on correlation feature selection, perform feature screening and integration on the preliminary traffic feature data generated from the Internet of Things device traffic data to obtain target traffic feature data;

[0055] In the specific implementation process of the present invention, the performing feature screening and integration on the preliminary traffic feature data generated from the Internet of Things device traffic data based on correlation feature selection to obtain target traffic feature data includes: performing preliminary feature extraction on the Internet of Things device traffic data based on the attention mechanism to obtain preliminary traffic feature data; calculating the feature correlation of the feature attribute set for the preliminary traffic feature data, and removing redundancy from the feature attribute set based on the feature correlation to obtain a target feature attribute set; calculating the correlation coefficient between the target feature attribute set and the category feature set in the preliminary traffic feature data, and screening the first feature sequence set based on the correlation coefficient; calculating the mutual information between the target feature attribute set and the category feature set, screening the second feature sequence set based on the mutual information, and performing feature integration based on the first feature sequence set and the second feature sequence set to obtain target traffic feature data.

[0056] Specifically, obtain the traffic data of IoT devices. The traffic data of IoT devices includes source IP packet data, packet duration, interval, flow duration, etc. Based on the attention mechanism, perform preliminary feature extraction on the traffic data of IoT devices. Use the normal network traffic sample data in the normal state and the abnormal network traffic sample data in the abnormal network state as the total traffic sample data. Perform feature extraction on each traffic sample data in the total traffic sample data to obtain the feature vectors corresponding to each traffic sample data. Assign corresponding weights to each feature vector. Train the bidirectional long short-term memory network with the attention mechanism according to the feature vectors and their corresponding weights. Input the traffic data of IoT devices into the trained bidirectional long short-term memory network for feature extraction to obtain preliminary traffic feature data, including category features and attribute features. Calculate the feature correlation of the feature attribute set for the preliminary traffic feature data. The feature attributes in the feature attribute set may include, but are not limited to, the number of source IP packets, the number of source ports, etc. Use information entropy as the measurement standard for feature correlation, that is, calculate the feature correlation between the feature attributes in the feature attribute set and the corresponding traffic categories through information entropy. The traffic categories include normal traffic, abnormal traffic, video streaming media traffic, etc. And perform redundancy removal on the feature attribute set based on the feature correlation. Calculate the first standard deviation of the feature correlation between the feature attribute and the corresponding traffic category. Calculate the feature correlation between the first feature attribute and the second feature attribute in the feature attribute set. The first feature attribute is the feature attribute used for the first standard deviation, and the second feature attribute is randomly selected except for the first feature attribute. Calculate the second standard deviation according to the feature correlation between the feature attributes. Determine whether the feature correlation between the feature attribute and the corresponding traffic category is greater than or equal to the first standard deviation, and determine whether the feature correlation between the first feature attribute and the second feature attribute in the feature attribute set is greater than or equal to the second standard deviation. If the feature correlation between the feature attribute and the corresponding traffic category is greater than or equal to the first standard deviation and the feature correlation between the first feature attribute and the second feature attribute in the feature attribute set is greater than or equal to the second standard deviation, then the first feature attribute is a redundant feature. Remove the redundant feature to obtain the target feature attribute set, thereby reducing the complexity and computational overhead of traffic detection and reducing the impact of redundant data on network traffic detection. In order to further reduce the consumption of time and space resources for subsequent data processing, it is necessary to perform a certain degree of screening and integration on the feature data. Calculate the correlation coefficient between the target feature attribute set and the category feature set in the preliminary traffic feature data, that is, calculate the correlation coefficient between each feature attribute in the target feature attribute set and each category feature in the category feature set. And screen the first feature sequence set based on the correlation coefficient, that is, sort the traffic feature data in the preliminary traffic feature data according to the correlation coefficient from large to small, and divide it into three feature data subsets on average, namely the priority feature data subset and the useful feature data subset, to obtain the final first feature sequence set.Calculate the mutual information between the target feature attribute set and the categorical feature set, and filter the second feature sequence set based on the mutual information, that is, sort the traffic feature data in the preliminary traffic feature data from large to small according to the mutual information, divide it into a priority feature data subset and a useful feature data subset on average, obtain the final second feature sequence set, and perform feature integration based on the first feature sequence set and the second feature sequence set. Perform a union operation on the priority feature data subset in the first feature sequence set and the priority feature data subset in the second feature sequence set to obtain a priority feature data set, perform an intersection operation on the useful feature data subset in the first feature sequence set and the useful feature data subset in the second feature sequence set to obtain a useful feature data set, and perform a union operation on the priority feature data set and the useful feature data set to obtain the target traffic feature data, making the obtained traffic feature data more accurate, while eliminating redundant features and ensuring the reliable extraction of important features.

[0057] S12: Evaluate the protection ability of the IoT device against traffic anomaly status based on the attack path impact analysis, obtain the protection ability evaluation result, and construct a traffic security baseline based on the protection ability evaluation result;

[0058] In the specific implementation process of the present invention, the evaluation of the protection ability of the IoT device against traffic anomaly status based on the attack path impact analysis to obtain the protection ability evaluation result includes: performing attack path analysis based on the vulnerability information obtained by the IoT device in the past traffic anomaly status to obtain a corresponding number of attack paths, and calculating the impact value of the attack path based on the fuzzy evaluation matrix; extracting the feature information of the defense mechanism for each attack path to obtain the defense mechanism feature information; calculating the defense success rate based on the defense mechanism feature information using the resource dependency relationship analysis, and calculating the attack path utilization value based on the impact value of the attack path combined with the attack path probability value; evaluating the protection ability of the traffic anomaly status based on the attack path utilization value and the defense success rate to obtain the protection ability evaluation result.

[0059] Further, the construction of the traffic security baseline based on the protection ability evaluation result includes: determining the baseline range based on the periodic distribution law of the historical traffic data, and performing fluctuation statistics on the historical traffic data to obtain the normal traffic fluctuation range; determining the traffic upper and lower limit tolerances based on the protection ability evaluation result, and constructing the traffic security baseline based on the baseline range, the normal traffic fluctuation range, and the traffic upper and lower limit tolerances.

[0060] Specifically, based on the vulnerability information obtained in the past traffic anomaly state of the Internet of Things device, the vulnerability information includes vulnerability categories, vulnerability severity metrics of the Common Vulnerability Scoring System, vulnerability reachability, and vulnerability impact scope, etc. A vulnerability exploitation graph is constructed by combining the network topology information and vulnerability information of the Internet of Things device with corresponding open-source tools. The nodes in the graph are vulnerabilities, and the edges are the dependency relationships between vulnerabilities. It is a directed graph. The vulnerability exploitation graph defines the vulnerabilities existing in the device and the influence relationships between them. If the second vulnerability is to be exploited, the first vulnerability needs to be exploited first. Graph algorithms are used to analyze the nodes, edges, and paths in the vulnerability exploitation graph to obtain corresponding attack paths, and the influence values of the attack paths are calculated based on the fuzzy evaluation matrix. Taking the attack paths as the evaluation objects, the corresponding evaluation factor sets are established, including vulnerability type, operating system version, asset importance, and user permissions, etc., and weights are assigned to each evaluation factor. The weights are set by experts' threat scores for each factor on the device to obtain the weight fuzzy set. A fuzzy evaluation matrix is constructed through the fuzzy weight set, and the influence values of each attack path are evaluated through the fuzzy evaluation matrix. Feature extraction is performed on the defense mechanisms adopted by each attack path. The defense mechanisms include firewalls, endpoint security policies, intrusion detection systems, etc. The defense mechanism feature information includes the configuration parameters of the defense mechanism, the actual operating conditions, the execution effect of the protection strategy, etc., to obtain the defense mechanism feature information. Based on the defense mechanism feature information, the defense success rate is calculated using resource dependency analysis, and the network resource graph of the Internet of Things device is obtained. The network resource graph characterizes the dependency relationship between the defense mechanisms used and the network resources that need to be scheduled. The defense mechanism feature information and the resource dependency relationship generated by the network resource graph are input into the simulation software. According to the defense mechanism feature information and the network resource graph, the possibility of intrusion using the vulnerability during resource scheduling is analyzed when scheduling the corresponding network resources. According to each attack path and the corresponding defense mechanism feature information, combined with the possibility of intrusion, attack simulation and network defense simulation are carried out in the simulation software. Security indicators such as the number of denial-of-service attacks and the security event response time during the simulation process are analyzed. According to the parameter values of these indicators compared with the preset security coefficient, if it is greater than the preset security coefficient, the defense is successful. The defense success rate is calculated through multiple simulations, and the attack path utilization value is calculated based on the influence value of the attack path combined with the attack path probability value, that is, the possibility of attacking using each attack path is calculated according to the influence value of the attack path and the attack path probability value combined with the corresponding weights. The protection ability of the traffic anomaly state is evaluated based on the attack path utilization value and the defense success rate. According to the attack path utilization value and the defense success rate, the protection ability level of the Internet of Things device against network attacks in the traffic anomaly state is matched, that is, the protection ability evaluation result is obtained.Determine the baseline range based on the periodic distribution law of historical traffic data. The historical traffic data is non-abnormal network traffic data. Analyze the periodic distribution law of the historical traffic data according to a preset periodic detection algorithm, such as the distribution of flow duration and packet interval at the same hour every day. Divide the upper and lower bounds of each parameter of the baseline according to its periodic distribution law, and perform fluctuation statistics on the historical traffic data, that is, obtain the normal traffic fluctuation range according to the fluctuation range of each parameter in the historical traffic data. Determine the upper and lower limit tolerances of the traffic based on the protection ability evaluation result. Match the corresponding upper and lower limit tolerances of the traffic according to the protection ability level of the IoT device in the traffic abnormal state facing network attacks. And construct a traffic security baseline based on the baseline range, the normal traffic fluctuation range, and the upper and lower limit tolerances of the traffic. Determine the adjustment coefficient of the range of each parameter of the baseline according to the normal traffic fluctuation range and the upper and lower limit tolerances of the traffic. Thus, construct a traffic security baseline to make the constructed traffic security baseline more in line with the actual situation of the IoT device, and avoid sending unnecessary warning messages when the defense mechanism of the IoT device itself is sufficient to handle the ordinary traffic over-threshold state.

[0061] S13: Use the target traffic feature data to perform traffic anomaly detection based on the traffic security baseline, and obtain a traffic anomaly detection result;

[0062] In the specific implementation process of the present invention, the using the target traffic feature data to perform traffic anomaly detection based on the traffic security baseline and obtaining a traffic anomaly detection result includes: comparing the target traffic feature data with each parameter in the traffic security baseline to obtain a comparison result, and performing traffic anomaly detection based on the comparison result to obtain a traffic anomaly detection result.

[0063] Specifically, compare the target traffic feature data with each parameter in the traffic security baseline to obtain a comparison result, and perform traffic anomaly detection based on the comparison result, that is, compare whether each feature data in the target traffic feature data exceeds the range boundary value of each parameter in the traffic security baseline. If it exceeds the range boundary value of each parameter in the traffic security baseline, then the target traffic feature data is abnormal traffic, and the defense mechanism of the IoT device itself can no longer handle this situation, and there is an abnormal traffic situation in the IoT device. If it does not exceed the range boundary value, then the traffic data is within the normal range or the defense mechanism of the IoT device itself can handle this situation, that is, obtain a traffic anomaly detection result.

[0064] S14: Determine the focus time window and the abnormal access behavior sequence based on the user's historical access behavior information of the IoT device;

[0065] In the specific implementation process of the present invention, determining the focus time window and the abnormal access behavior sequence based on the user's historical access behavior information of the Internet of Things device includes: determining the number of historical access behaviors of the user's historical access behavior information in each preset time end window, and using the preset time end window corresponding to the number of historical access behaviors greater than or equal to the preset quantity threshold as the focus time window; classifying a plurality of behavior sequences generated from the user's historical access behavior information based on a clustering algorithm to obtain a plurality of behavior sequence classes; calculating the correlation coefficient between each user access behavior based on the plurality of behavior sequence classes; and determining the abnormal access behavior sequence based on the correlation coefficient in combination with the output probability of each behavior sequence class.

[0066] Specifically, determine the number of historical access behaviors of the user's historical access behavior information in each preset time window, that is, count the number of different access behaviors in each preset time window. The user's historical access information includes different access behaviors of each user in each time period. Take the preset time window corresponding to the number of historical access behaviors greater than or equal to the preset quantity threshold as the focus time window. That is, if the number of historical access behaviors in the preset time window is greater than or equal to the preset quantity threshold, then this preset time window is the focus time window. The focus time window indicates that the user's access behavior is relatively frequent during this time period. Classify a number of behavior sequences generated from the user's historical access behavior information based on a clustering algorithm. The behavior sequence is a sequence rule for user access. For example, for posting a message, its behavior sequence is login page - posting page - leaving a message. The clustering algorithm uses a hidden Markov model, calculates the output probability function according to the hidden Markov model of each behavior sequence, and determines whether the function value satisfies the convergence condition. If the convergence condition is satisfied, the iteration ends and a number of behavior sequence classes are obtained. Calculate the correlation coefficient between the access behaviors of each user based on a number of behavior sequence classes, calculate the behavior similarity between each user in the preset time window, which can be calculated through the length of the behavior sequences of each user, calculate the correlation coefficient between the user's access behaviors according to the behavior similarity, and the correlation coefficient between users can describe the degree of proximity of the user's behavior relationship. Determine the abnormal access behavior sequence based on the correlation coefficient combined with the output probability of each behavior sequence class. Calculate the variance and average value of the correlation coefficient according to the correlation coefficient between each user. Take the average value of the correlation coefficient minus the variance of the correlation coefficient as one endpoint of the interval, and take the average value of the correlation coefficient plus the variance of the correlation coefficient as the other endpoint of the interval to form a judgment interval. Take the user combination whose correlation coefficient does not reach the judgment interval as the abnormal user combination, take the behavior sequence class corresponding to the abnormal user combination as the first initial abnormal access behavior sequence, and take the behavior sequence class with an output probability less than the preset probability threshold as the second initial abnormal access behavior sequence. Since most users' access behaviors are normal access behaviors, an output probability less than the preset probability threshold indicates that the access behavior is abnormal. Delete the repeated access behavior sequences in the first initial abnormal access behavior sequence and the second initial abnormal access behavior sequence to form an abnormal access behavior sequence, making the obtained abnormal access behavior sequence more comprehensive and avoiding the limitations of single abnormal access behavior analysis.

[0067] S15: Perform access behavior anomaly detection on the user behavior monitoring information based on the access behavior distribution and abnormal access behavior sequence generated from the focus time window, and obtain the access behavior anomaly detection result;

[0068] In the specific implementation process of the present invention, the access behavior anomaly detection of the user behavior monitoring information based on the access behavior distribution and the abnormal access behavior sequence generated by the focus time window to obtain the access behavior anomaly detection result includes: screening the features of the historical access behavior information in the focus time window to obtain the access behavior feature information, and performing distribution statistics based on the access behavior feature information to obtain the access behavior distribution; constructing an access behavior line based on the access behavior distribution, performing access behavior anomaly detection on the user behavior monitoring information based on the access behavior line to obtain the first preliminary access behavior anomaly detection result; matching the user behavior monitoring information with the abnormal access behavior sequence to obtain a matching result, and determining the second preliminary access behavior anomaly monitoring result based on the matching result; removing duplicate redundancies from the first preliminary access behavior anomaly detection result and the second preliminary access behavior anomaly detection result to obtain the access behavior anomaly detection result.

[0069] Specifically, performing distribution statistics on the historical access behavior information in the focus time window, that is, counting the frequency distribution of each historical access behavior in the focus time window, such as the success frequency distribution of logging into the network in the focus time window, etc., to obtain the access behavior distribution. Constructing an access behavior line based on the access behavior distribution, calculating the target entropy value according to the statistically obtained access behavior distribution, forming an access behavior line according to the target entropy value, performing access behavior anomaly detection on the user behavior monitoring information based on the access behavior line, and judging whether there is an access behavior frequency exceeding the access behavior line in the user behavior monitoring information according to the access behavior line, such as whether the frequency of the user connecting to the Internet of Things device exceeds the device connection frequency in the access behavior line. If it exceeds the access behavior line, it is judged that the user has one or more abnormal access behaviors. If it does not exceed the access behavior line, it indicates that the user's access behavior is still normal, that is, the first preliminary access behavior anomaly detection result is obtained. Matching the user behavior monitoring information with the abnormal access behavior sequence, matching whether there is an abnormal access behavior between the user behavior sequence in the user behavior monitoring information and the abnormal access behavior sequence to obtain a matching result, and determining the second preliminary access behavior anomaly monitoring result based on the matching result. For example, if the user behavior has continuous page registration - continuous device login and information modification, it is judged that the user access behavior is abnormal. If no access behavior matching the abnormal access behavior sequence can be found in the user behavior monitoring information, it indicates that the user's current access behavior is normal. Removing duplicate redundancies from the first preliminary access behavior anomaly detection result and the second preliminary access behavior anomaly detection result. If any one of the first preliminary access behavior anomaly detection result and the second preliminary access behavior anomaly detection result detects an abnormal situation, it is regarded as an access anomaly. Only when both do not detect an abnormal situation is it a normal access situation. When both detect an abnormal access behavior, the same abnormal access behavior detected by both is deleted to obtain the access behavior anomaly detection result.

[0070] S16: Determine whether it is necessary to initiate an emergency response strategy based on the traffic anomaly detection result and the access behavior anomaly detection result.

[0071] In the specific implementation process of the present invention, when traffic anomalies and / or access behavior anomalies are detected, the corresponding emergency response strategy is initiated according to the detection results. For example, when a traffic anomaly is detected, the intrusion prevention system deployed at the external zone boundary is started to block abnormal traffic and remove malicious codes. When an abnormal access behavior is detected, the access security management center is started to block the behavior of the accessing user and disconnect the access permission, thereby ensuring the network security of the Internet of Things devices.

[0072] In the embodiment of the present invention, based on the correlation feature selection, the preliminary traffic feature data generated from the Internet of Things device traffic data is subjected to feature screening and integration, which can avoid the loss of important features and ensure the accuracy of feature extraction while removing redundant features. Based on the attack path impact analysis, the protection ability of the Internet of Things device in the traffic anomaly state is evaluated, which can accurately evaluate the protection ability of the Internet of Things device in the traffic anomaly state. Based on the protection ability evaluation result, a traffic security baseline is constructed, making the constructed traffic security baseline more reliable. Through this traffic security baseline, traffic anomaly detection is performed, which can greatly reduce the error of traffic anomaly detection. Based on the user's historical access behavior information of the Internet of Things device, the focus time window and the abnormal access behavior sequence are determined. Based on the access behavior distribution generated by the focus time window and the abnormal access behavior sequence, access behavior anomaly detection is performed on the user behavior monitoring information, which can improve the accuracy of access behavior anomaly detection and avoid missed detection and false detection. The actual network security status of the Internet of Things device can be accurately monitored. When abnormal situations are detected, the emergency response strategy can be started in a timely manner to ensure the network security of the Internet of Things device.

[0073] Embodiment 2

[0074] Please refer to Figure 2 , Figure 2 which is a schematic flowchart of the network security intelligent monitoring method for Internet of Things devices in another embodiment of the present invention. The method includes:

[0075] S201: Based on the correlation feature selection, perform feature screening and integration on the preliminary traffic feature data generated from the Internet of Things device traffic data to obtain the target traffic feature data;

[0076] S202: Perform attack path analysis based on the vulnerability information obtained by the Internet of Things device in the past traffic anomaly state to obtain several corresponding attack paths, and calculate the influence value of the attack path based on the fuzzy evaluation matrix;

[0077] S203: Extract features from the defense mechanisms adopted for each attack path to obtain defense mechanism feature information;

[0078] S204: Calculate the defense success rate based on the defense mechanism feature information using resource dependency analysis, and calculate the attack path utilization value based on the impact value of the attack path combined with the attack path probability value;

[0079] S205: Evaluate the protection ability of the traffic abnormal state based on the attack path utilization value and the defense success rate to obtain the protection ability evaluation result, and construct a traffic security baseline based on the protection ability evaluation result;

[0080] S206: Perform traffic anomaly detection on the target traffic feature data based on the traffic security baseline to obtain a traffic anomaly detection result;

[0081] S207: Determine the focus time window and the abnormal access behavior sequence based on the user's historical access behavior information of the Internet of Things device;

[0082] S208: Perform access behavior anomaly detection on the user behavior monitoring information based on the access behavior distribution generated by the focus time window and the abnormal access behavior sequence to obtain an access behavior anomaly detection result;

[0083] S209: Judge whether it is necessary to start an emergency response strategy based on the traffic anomaly detection result and the access behavior anomaly detection result.

[0084] In the embodiment of the present invention, feature screening and integration are performed on the preliminary traffic feature data generated from the Internet of Things device traffic data based on correlation feature selection, which can avoid the loss of important features and ensure the accuracy of feature extraction while removing redundant features. The protection ability of the Internet of Things device in the traffic abnormal state is evaluated based on the attack path impact analysis, which can accurately evaluate the protection ability of the Internet of Things device when it is in the traffic abnormal state. A traffic security baseline is constructed based on the protection ability evaluation result, making the constructed traffic security baseline more reliable. Traffic anomaly detection is performed through this traffic security baseline, which can greatly reduce the error of traffic anomaly detection. The focus time window and the abnormal access behavior sequence are determined based on the user's historical access behavior information of the Internet of Things device, and access behavior anomaly detection is performed on the user behavior monitoring information based on the access behavior distribution generated by the focus time window and the abnormal access behavior sequence, which can improve the accuracy of access behavior anomaly detection and avoid missed detection and false detection. The actual network security status of the Internet of Things device can be accurately monitored. When an abnormal situation is detected, the emergency response strategy can be started in time to ensure the network security of the Internet of Things device.

[0085] Embodiment III

[0086] Please refer to Figure 3, Figure 3 It is a schematic structural diagram of a network security intelligent monitoring device for an Internet of Things device in an embodiment of the present invention. The device includes:

[0087] Traffic feature extraction module 31: used to perform feature screening and integration on the preliminary traffic feature data generated from the Internet of Things device traffic data based on correlation feature selection to obtain target traffic feature data;

[0088] Traffic baseline construction module 32: used to evaluate the protection ability of the Internet of Things device against traffic anomaly status based on attack path impact analysis to obtain a protection ability evaluation result, and construct a traffic security baseline based on the protection ability evaluation result;

[0089] Traffic anomaly detection module 33: used to perform traffic anomaly detection on the target traffic feature data based on the traffic security baseline to obtain a traffic anomaly detection result;

[0090] Time window and behavior sequence determination module 34: used to determine a focus time window and an abnormal access behavior sequence based on the user's historical access behavior information of the Internet of Things device;

[0091] Access behavior anomaly detection module 35: used to perform access behavior anomaly detection on the user behavior monitoring information based on the access behavior distribution generated by the focus time window and the abnormal access behavior sequence to obtain an access behavior anomaly detection result;

[0092] Emergency response judgment module 36: used to judge whether it is necessary to start an emergency response strategy based on the traffic anomaly detection result and the access behavior anomaly detection result.

[0093] In the specific implementation process of the present invention, the specific implementation manner of the device item can refer to the implementation manner of the above method item, which will not be elaborated here.

[0094] In the embodiments of the present invention, feature screening and integration are performed on the preliminary traffic feature data generated from the Internet of Things (IoT) device traffic data based on correlation feature selection, which can avoid the loss of important features and ensure the accuracy of feature extraction while removing redundant features. The protection ability of IoT devices in a traffic abnormal state is evaluated based on the analysis of the impact of the attack path, which can accurately evaluate the protection ability of IoT devices in a traffic abnormal state. A traffic security baseline is constructed based on the evaluation result of the protection ability, making the constructed traffic security baseline more reliable. Traffic abnormal detection is performed through this traffic security baseline, which can greatly reduce the error of traffic abnormal detection. The focus time window and the abnormal access behavior sequence are determined based on the historical access behavior information of the users of IoT devices. Access behavior abnormal detection is performed on the user behavior monitoring information based on the access behavior distribution generated by the focus time window and the abnormal access behavior sequence, which can improve the accuracy of access behavior abnormal detection and avoid missed detection and false detection. The actual network security status of IoT devices can be accurately monitored. When an abnormal situation is detected, an emergency response strategy can be started in a timely manner to ensure the network security of IoT devices.

[0095] A computer-readable storage medium provided by an embodiment of the present invention has a computer program stored thereon. When the program is executed by a processor, it implements the network security intelligent monitoring method for IoT devices in any one of the above embodiments. Among them, the computer-readable storage medium includes, but is not limited to, any type of disk (including floppy disks, hard disks, optical disks, CD-ROMs, and magneto-optical disks), ROM (Read-Only Memory), RAM (Random Access Memory), EPROM (Erasable Programmable Read-Only Memory), EEPROM (Electrically Erasable Programmable Read-Only Memory), flash memory, magnetic cards, or optical cards. That is, the storage device includes any medium that can store or transmit information in a readable form by a device (such as a computer or a mobile phone), and can be a read-only memory, a magnetic disk, or an optical disk, etc.

[0096] Embodiment 4

[0097] Please refer to Figure 4 , Figure 4 which is a schematic diagram of the structural composition of the electronic device in the embodiment of the present invention.

[0098] The embodiment of the present invention also provides an electronic device, such as Figure 4As shown, the electronic device includes a memory 41, a processor 43, and a computer program 42 stored in the memory 41 and executable on the processor 43. Those skilled in the art can understand that Figure 3 the illustrated electronic device does not constitute a limitation on all devices and may include more or fewer components than shown, or combine certain components. The memory 41 can be used to store the computer program 42 and each functional module. The processor 43 runs the computer program 42 stored in the memory 41 to perform various functional applications and data processing of the device. The memory can be an internal memory or an external memory, or include both an internal memory and an external memory. The internal memory can include a read-only memory (ROM), a programmable ROM (PROM), an electrically programmable ROM (EPROM), an electrically erasable programmable ROM (EEPROM), a flash memory, or a random access memory. The external memory can include a hard disk, a floppy disk, a ZIP disk, a USB flash drive, a magnetic tape, etc. The processor 43 can be a central processing unit (CPU), or can also be other general-purpose processors, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor, a single-chip microcomputer, or the processor 43 can also be any conventional processor, etc. The processors and memories disclosed in the present invention include but are not limited to these types of processors and memories. The processors and memories disclosed in the present invention are only examples and not limitations.

[0099] As an embodiment, the electronic device includes: one or more processors 43, a memory 41, one or more computer programs 42, where the one or more computer programs 42 are stored in the memory 41 and are configured to be executed by the one or more processors 43. The one or more computer programs 42 are configured to execute the network security intelligent monitoring method of the Internet of Things device in any of the above embodiments. For the specific implementation process, please refer to the above embodiments and will not be elaborated here.

[0100] In the embodiments of the present invention, feature screening and integration are performed on the preliminary traffic feature data generated from the Internet of Things (IoT) device traffic data based on correlation feature selection, which can avoid the loss of important features and ensure the accuracy of feature extraction while eliminating redundant features. The protection ability evaluation of the IoT device for traffic abnormal states is performed based on the analysis of the impact of the attack path, which can accurately evaluate the protection ability of the IoT device in the traffic abnormal state. A traffic security baseline is constructed based on the protection ability evaluation result, making the constructed traffic security baseline more reliable. Traffic abnormal detection is performed through this traffic security baseline, which can greatly reduce the error of traffic abnormal detection. The focus time window and the abnormal access behavior sequence are determined based on the user's historical access behavior information of the IoT device. Access behavior abnormal detection is performed on the user behavior monitoring information based on the access behavior distribution generated by the focus time window and the abnormal access behavior sequence, which can improve the accuracy of access behavior abnormal detection and avoid missed detection and false detection. The actual network security status of the IoT device can be accurately monitored. When an abnormal situation is detected, an emergency response strategy can be started in a timely manner to ensure the network security of the IoT device.

[0101] In addition, the above has introduced in detail a network security intelligent monitoring method and related device for an IoT device provided by the embodiments of the present invention. Specific examples should have been used in this article to elaborate on the principle and implementation manner of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention. At the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to the present invention.

Claims

1. A network security intelligent monitoring method for Internet of Things devices, characterized in that, The method includes: Based on correlation feature selection, perform feature screening and integration on the preliminary traffic feature data generated from the traffic data of IoT devices to obtain target traffic feature data; Based on attack path impact analysis, evaluate the protection ability of IoT devices against traffic anomaly states to obtain a protection ability evaluation result, and construct a traffic security baseline based on the protection ability evaluation result; Based on the traffic security baseline, use the target traffic feature data to perform traffic anomaly detection to obtain a traffic anomaly detection result; Determine a focus time window and an abnormal access behavior sequence based on the historical access behavior information of IoT device users; Based on the access behavior distribution generated by the focus time window and the abnormal access behavior sequence, perform access behavior anomaly detection on the user behavior monitoring information to obtain an access behavior anomaly detection result; Based on the traffic anomaly detection result and the access behavior anomaly detection result, determine whether to initiate an emergency response strategy; Among them, the step of performing feature screening and integration on the preliminary traffic feature data generated from the traffic data of IoT devices based on correlation feature selection to obtain target traffic feature data includes: performing preliminary feature extraction on the traffic data of IoT devices based on an attention mechanism to obtain preliminary traffic feature data; calculating the feature correlation of the feature attribute set for the preliminary traffic feature data, and removing redundancy from the feature attribute set based on the feature correlation to obtain a target feature attribute set; calculating the correlation coefficient between the target feature attribute set and the category feature set in the preliminary traffic feature data, and screening a first feature sequence set based on the correlation coefficient; calculating the mutual information between the target feature attribute set and the category feature set, screening a second feature sequence set based on the mutual information, and performing feature integration based on the first feature sequence set and the second feature sequence set to obtain target traffic feature data.

2. The network security intelligent monitoring method for the Internet of Things device according to claim 1, wherein The step of evaluating the protection ability of IoT devices against traffic anomaly states based on attack path impact analysis to obtain a protection ability evaluation result includes: Perform attack path analysis based on the vulnerability information obtained by IoT devices in past traffic anomaly states to obtain several corresponding attack paths, and calculate the impact value of the attack paths based on a fuzzy evaluation matrix; Extract the feature information of the defense mechanisms adopted by each attack path to obtain defense mechanism feature information; Based on the defense mechanism feature information, calculate the defense success rate using resource dependency analysis, and calculate the attack path utilization value by combining the impact value of the attack path with the attack path probability value; Based on the attack path utilization value and the defense success rate, evaluate the protection ability of the traffic anomaly state to obtain a protection ability evaluation result.

3. The network security intelligent monitoring method for the Internet of Things device according to claim 1, characterized in that The step of constructing a traffic security baseline based on the protection ability evaluation result includes: Determine the baseline range based on the periodic distribution law of historical traffic data, and perform fluctuation statistics on the historical traffic data to obtain the normal traffic fluctuation range; Determine the upper and lower traffic tolerance limits based on the protection ability evaluation result, and construct a traffic security baseline based on the baseline range, the normal traffic fluctuation range, and the upper and lower traffic tolerance limits.

4. The network security intelligent monitoring method for the Internet of Things device according to claim 1, characterized in that, The step of performing traffic anomaly detection based on the traffic security baseline using the target traffic feature data to obtain a traffic anomaly detection result includes: Compare the target traffic feature data with each parameter in the traffic security baseline to obtain a comparison result, and perform traffic anomaly detection based on the comparison result to obtain a traffic anomaly detection result.

5. The network security intelligent monitoring method for the Internet of Things device according to claim 1, characterized in that The determination of the focus time window and the abnormal access behavior sequence based on the user's historical access behavior information of the Internet of Things device includes: Determine the number of historical access behaviors of the user's historical access behavior information in each preset time window, and use the preset time window corresponding to the number of historical access behaviors greater than or equal to the preset number threshold as the focus time window; Classify a number of behavior sequences generated from the user's historical access behavior information based on a clustering algorithm to obtain a number of behavior sequence classes; Calculate the correlation coefficient between each user access behavior based on a number of behavior sequence classes; Determine the abnormal access behavior sequence based on the correlation coefficient combined with the output probability of each behavior sequence class.

6. The network security intelligent monitoring method for the Internet of Things device according to claim 1, wherein The access behavior anomaly detection of the user behavior monitoring information based on the access behavior distribution and the abnormal access behavior sequence generated by the focus time window to obtain an access behavior anomaly detection result includes: Perform distribution statistics on the historical access behavior information in the focus time window to obtain an access behavior distribution; Construct an access behavior line based on the access behavior distribution, and perform access behavior anomaly detection on the user behavior monitoring information based on the access behavior line to obtain a first preliminary access behavior anomaly detection result; Match the user behavior monitoring information with the abnormal access behavior sequence to obtain a matching result, and determine a second preliminary access behavior anomaly monitoring result based on the matching result; Perform duplicate redundancy removal on the first preliminary access behavior anomaly detection result and the second preliminary access behavior anomaly detection result to obtain an access behavior anomaly detection result.

7. A network security intelligent monitoring device for an Internet of Things device, characterized in that, The device includes: A traffic feature extraction module: used to perform feature screening and integration on the preliminary traffic feature data generated from the Internet of Things device traffic data based on correlation feature selection to obtain target traffic feature data; A traffic baseline construction module: used to evaluate the protection ability of the Internet of Things device against traffic anomaly states based on attack path impact analysis to obtain a protection ability evaluation result, and construct a traffic security baseline based on the protection ability evaluation result; A traffic anomaly detection module: used to perform traffic anomaly detection using the target traffic feature data based on the traffic security baseline to obtain a traffic anomaly detection result; A time window and behavior sequence determination module: used to determine a focus time window and an abnormal access behavior sequence based on the user's historical access behavior information of the Internet of Things device; An access behavior anomaly detection module: used to perform access behavior anomaly detection on the user behavior monitoring information based on the access behavior distribution and the abnormal access behavior sequence generated by the focus time window to obtain an access behavior anomaly detection result; An emergency response judgment module: used to judge whether it is necessary to initiate an emergency response strategy based on the traffic anomaly detection result and the access behavior anomaly detection result. Among them, the feature screening and integration of the preliminary traffic feature data generated from the Internet of Things device traffic data based on the correlation feature selection to obtain the target traffic feature data includes: performing preliminary feature extraction on the Internet of Things device traffic data based on the attention mechanism to obtain the preliminary traffic feature data; calculating the feature correlation of the feature attribute set for the preliminary traffic feature data, and removing redundancy from the feature attribute set based on the feature correlation to obtain the target feature attribute set; calculating the correlation coefficient between the target feature attribute set and the category feature set in the preliminary traffic feature data, and screening the first feature sequence set based on the correlation coefficient; calculating the mutual information between the target feature attribute set and the category feature set, screening the second feature sequence set based on the mutual information, and performing feature integration based on the first feature sequence set and the second feature sequence set to obtain the target traffic feature data.

8. An electronic device, the electronic device comprising a processor and a memory, characterized in that, The memory is used to store instructions, and the processor is used to call the instructions in the memory, so that the electronic device executes the network security intelligent monitoring method of the Internet of Things device according to any one of claims 1 to 6.

9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions, and when the computer instructions run on the electronic device, the electronic device executes the network security intelligent monitoring method of the Internet of Things device according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Exception access behavior detection method and device

    CN106027577A

  • Performance index monitoring method and device

    CN106856442A

  • Network security defense capability quantitative evaluation method and system based on attack surface

    CN117411668A