Docker-based easy-to-expand privacy protection type Internet of Things malicious traffic detection method and device

By deploying the model architecture in Docker containers and leveraging federated learning and blockchain + IPFS storage systems, privacy protection and scalability issues in IoT malicious traffic detection are solved, real-time, accurate detection of IoT malicious traffic and rapid system expansion are achieved.

CN119966646APending Publication Date: 2025-05-09NORTHEAST FORESTRY UNIV
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202410973025.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-07-19
Publication Date
2025-05-09

AI Technical Summary

Technical Problem

Existing IoT malicious traffic detection methods have failed to effectively solve the privacy protection and scalability issues, and are insufficient in resilience to unknown types of malicious traffic.

Method used

Adopt Docker-based, easy-to-scaling privacy-protected IoT malicious traffic detection method, and by deploying a model architecture in Docker containers, using federated learning and blockchain + IPFS storage systems, decentralized data storage and rapid expansion of models are achieved.

Benefits of technology

Real-time detection of malicious IoT traffic is realized, the accuracy of detection and system scalability is improved, user privacy is protected, and the dependence on central servers is reduced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure SMS_1
    Figure SMS_1
  • Figure SMS_2
    Figure SMS_2
  • Figure SMS_3
    Figure SMS_3
Patent Text Reader

Abstract

The invention designs an extensible privacy protection type Internet of Things malicious traffic detection method and device based on Docker. In order to solve the privacy problem existing in malicious traffic defense of current Internet of Things equipment, a Docker container is deployed in an edge server node, and an intrusion detection model is constructed in the container by using a machine learning algorithm, so that real-time malicious traffic detection is realized under the condition of protecting user privacy. And meanwhile, detection model parameters are stored by using a block chain and an IPFS technology, so that the data security and the system expandability are ensured. The method has the advantages of being easy to expand, safe, reliable and efficient in management, and is suitable for malicious traffic detection in various Internet of Things environments.
Need to check novelty before this filing date? Find Prior Art

Description

Technical field:

[0001] The present invention designs an Internet of Things malicious traffic detection system, specifically a Docker-based, easily extensible, privacy-preserving Internet of Things malicious traffic detection method and device. Background technology:

[0002] With the development of Internet technology and the popularization of smart devices, the Internet of Things (IoT) was born out of people's pursuit of connectivity and intelligence. Nowadays, not only smart devices such as smartphones and smart homes are popular, but also the IoT technology is widely used in industries such as industry, transportation, medical care, and agriculture, forming concepts such as smart cities, smart agriculture, and smart factories. The IoT connects various devices and sensors and transmits data to the cloud for processing and analysis, thus achieving interconnection between devices and providing people with a smarter and more convenient way of living and working.

[0003] However, the development of the Internet of Things also faces some challenges and problems. These include network security risks, data privacy protection, and the unification of standards and protocols. Unlike Internet traffic, the scale of traffic is larger due to the large number of devices connected to the Internet of Things, including various smart devices and sensors. In addition, Internet of Things devices usually involve personal sensitive information, such as home security cameras, health monitoring equipment, etc., and many products on the market currently do not consider the privacy protection of Internet of Things users. This makes it easier for illegal users to steal user information in Internet of Things devices and conduct illegal activities.

[0004] Most of the existing commercial IoT defense products on the market focus on detection efficiency and real-time detection capabilities, using distributed computing to reduce the bandwidth pressure on cloud computing centers caused by large amounts of IoT traffic data, thereby improving the real-time performance of malicious traffic.

[0005] Chinese patent CN115174237B proposes a method for detecting malicious traffic in the Internet of Things. It screens out features by the kernel density of each traffic feature, and then uses the screened features to train a detection model, and uses the model to detect malicious traffic in the Internet of Things terminal.

[0006] Although the above method can enhance the security of IoT terminals to a certain extent, there are still some problems. For example, it does not take into account the privacy issues and scalability issues of IoT devices, and it does not have the ability to resist unknown types of malicious traffic, which is a big flaw for the rapidly developing IoT. Summary of the invention:

[0007] This paper proposes a Docker-based, easily scalable, privacy-preserving IoT malicious traffic detection method and architecture for malicious traffic in the IoT. In a real IoT environment, we select different edge servers as nodes, each with a different number of IoT devices under its jurisdiction.

[0008] We deploy the model architecture in a Docker container, which is the foundation of the architecture. Docker has environmental isolation and portability, which makes it cross-platform compatible and easy to deploy on different operating systems and hardware platforms. It can also be quickly expanded and decommissioned as needed, which is of great significance for the replacement and addition of IoT devices.

[0009] In our design, we plan to detect IoT traffic data packets, so that we can detect them when the packets arrive, avoiding the delay caused by waiting. At the same time, we use binary representation of traffic instead of decimal representation, which can effectively improve the accuracy of traffic prediction. Multiple nodes use the data collected from different device sources to collect data features of normal traffic data and malicious traffic. Since these data are similar in type, after federated learning through multiple nodes, the final aggregation parameters can ensure the accuracy of identifying malicious traffic.

[0010] In addition, we have built a parameter storage system using blockchain and IPFS file storage system. This system can realize decentralized reference and verification of data, which ensures that newly added devices in different regions can directly load model parameters if allowed by smart contracts, thereby realizing rapid expansion of model architecture and avoiding the scalability and cost issues of blockchain.

[0011] Through the above three parts, we have built a malicious traffic detection architecture for the Internet of Things, which directly discards the detected malicious traffic data packets. At the same time, for the update of the model, it only needs to upload the trained model parameters to the storage system, and the remaining architectures in the model architecture can directly load the parameters for use. Description of the drawings:

[0012] The accompanying drawings are intended to provide further understanding and description of the present invention.

[0013] Figure 1 This is the system structure diagram involved in the present invention

[0014] Figure 2 This is a flow chart of the malicious traffic detection model training involved in the present invention

[0015] Figure 3 This is a module composition diagram of the system and device involved in the present invention

[0016] Figure 4This is the system workflow diagram involved in the present invention Specific implementation method:

[0017] 1. Method Introduction

[0018] This method is mainly based on Docker technology. Docker containers can be quickly expanded as needed to handle more devices and traffic, which helps to cope with the growing IoT network and traffic requirements. Using the malicious traffic detection model in the architecture, data packets to edge nodes can be detected immediately. Abnormal traffic packets will be directly discarded and warnings will be generated, while normal traffic data will be allowed to be received normally.

[0019] The system structure of this architecture is shown in the figure. It mainly consists of two parts: edge nodes and storage systems. The edge nodes are responsible for model training and malicious traffic detection, and the storage system is responsible for storing model parameters and ensuring parameter security. Models are trained and traffic detection is performed on edge nodes, while the existence of the storage system facilitates the expansion of this architecture for widely distributed IoT devices.

[0020] In the edge node, the Model is responsible for model training and malicious traffic detection, the Socket API is responsible for inter-node communication, and the Function is mainly responsible for loading model parameters from the storage system. There are some special nodes in the edge node (such as edge node 0). They have an additional function FedAVG, which is mainly responsible for parameter aggregation. In addition, its Function part also has the function of uploading parameters to the storage system.

[0021] In the storage system, IPFS is the part that actually stores the model parameters, and the blockchain stores the index returned by IPFS, which can ensure the security of the parameters and prevent them from being illegally obtained.

[0022] This method uses a deep learning algorithm called one-dimensional convolution, which is an algorithm for sequence data. This method can automatically extract features from traffic data and then determine the type of traffic based on these features. At the same time, we use the federated learning model to locally process and analyze data, and integrate data from multiple participants for model training to ensure that the original data is not leaked, thereby protecting user privacy.

[0023] In order to protect the privacy of users, we use the local data on the edge server to train the intrusion detection model, send the model parameters to a central entity, and then calculate a global model parameter (Formula 1), which is loaded by each related device. The model aggregation parameter formula can be expressed as follows:

[0024]

[0025] Where k represents the number of edge servers participating in the aggregation, and n represents the number of model parameters.

[0026] Model Evaluation:

[0027] P (Positive Sample): The number of positive samples.

[0028] N (Negative Sample): The number of negative samples.

[0029] TP (True Positive): The number of correctly predicted positive examples.

[0030] FP (False Positive): The number of negative examples predicted as positive examples.

[0031] FN (False Negative): The number of positive examples predicted as negative examples.

[0032] TN (True Negative): The number of correctly predicted negative examples.

[0033] Classification accuracy is the probability that positive and negative samples are correctly classified, which can provide an overview of the overall prediction results. The calculation formula is:

[0034]

[0035] The recall rate is the probability that a positive sample is identified, and the calculation formula is:

[0036]

[0037] The false alarm rate is the probability that a negative sample is mistakenly classified as a positive sample. The calculation formula is:

[0038]

[0039] Precision is the degree of authenticity of the classification result as a positive sample, and the calculation formula is:

[0040]

[0041] 2. Device Introduction

[0042] This device is mainly composed of three parts: traffic monitoring module, traffic detection module and response module. After deploying the above three modules on the edge service node with CPU and memory hardware, malicious traffic can be detected.

[0043] The traffic monitoring module mainly includes traffic capture functions, etc. This module mainly uses Google's open source project gopacket to capture and analyze network traffic. It can capture data packets flowing through the network card, including Ethernet, IP and TCP, etc., and this lightweight Go language library is compatible with pcap, supports offline and real-time traffic capture, and has good performance. In this module, gopacket is used to monitor the specified network interface, and all inbound and outbound traffic on the interface is captured and transmitted to the traffic detection module for detection.

[0044] The traffic detection module is implemented using a Docker-based deep learning model. Docker has significant advantages in detecting malicious traffic in the Internet of Things. Its lightweight, portability, isolation, and easy deployment make it an ideal deployment solution. By providing the advantages of fast startup, efficient resource utilization, version control, and easy expansion, Docker simplifies the deployment and management of the system while maintaining consistency in different environments, providing strong support for efficient, flexible, and secure malicious traffic detection on IoT devices. Therefore, given the characteristics of IoT devices, we built this module in Docker to facilitate the deployment of the architecture. In addition, federated learning allows the knowledge of multiple devices to be aggregated while protecting privacy, thereby establishing a more comprehensive and accurate malicious traffic detection model, thereby effectively reducing the amount of data transmission and reducing the risk of data concentration on the central server. Therefore, we adopt the idea of ​​federated learning for model training, and we store the final model parameters in a storage system that combines IPFS and blockchain to facilitate the expansion of the architecture.

[0045] The response module mainly processes the detected malicious traffic packets. The IoT malicious traffic detection architecture we have established is for packet-level detection to ensure the real-time detection. For the detected malicious traffic packets, the flow to which the packet belongs will be immediately isolated and judged. If there are two or more packets in the flow that are judged as malicious traffic packets, the flow will be directly discarded. If there is only one malicious traffic packet, it will be discarded and wait for the retransmission of the packet. If the retransmitted packet is still malicious, the flow to which it belongs will also be discarded. Otherwise, a log record will be generated for the flow and the flow will be allowed to pass.

[0046] 3. Working steps

[0047] Step 1: Deploy the above modules on the edge server of the IoT network.

[0048] Step 2 uses the labeled data to train the model in a federated learning manner on multiple edge nodes, and uploads the final trained model parameters to the blockchain;

[0049] Step 3: Decentralize the storage of parameters and store their indexes in the blockchain.

[0050] Step 4: All edge nodes load the index from the blockchain and the model parameters from IPFS to deploy the malicious traffic detection model locally.

[0051] Step 5: The detection system starts running and submits abnormal traffic to the corresponding module for processing;

[0052] Step 6: When malicious traffic is detected twice or more in a flow, the flow is discarded and a record is generated.

Claims

1. A Docker-based, easily scalable, privacy-preserving IoT malicious traffic detection method, characterized in that: The following steps are involved: Deploy Docker containers in edge server nodes; The Docker container uses a deep learning algorithm to build an intrusion detection model; the intrusion detection model realizes real-time detection of malicious traffic while protecting user privacy; the malicious traffic detection model detects traffic data packets based on a one-dimensional convolution algorithm; The parameter storage system built based on blockchain and IPFS file storage system; wherein the blockchain storage system is used to store model parameters and ensure their security; the IPFS file storage system is used to achieve decentralized reference and verification of data, so that all edge nodes can achieve rapid expansion by loading parameter models; Through the federated learning model, model training and parameter aggregation are performed on multiple edge nodes, and the final trained model parameters are uploaded to the storage system; The traffic packets received by the edge node are detected. Malicious traffic packets are directly discarded and a warning is generated. Normal traffic packets are allowed to pass normally.

2. The method according to claim 1, characterized in that The deep learning algorithm is a one-dimensional convolutional neural network that can automatically extract features from traffic data and determine traffic types.

3. The method according to claim 1 or 2, characterized in that: In the federated learning mode, multiple edge nodes train the intrusion detection model through local data, and send the local model parameters to the central node to calculate the global model parameters to form an aggregated parameter for sharing.

4. The method according to any one of claims 1 to 3, characterized in that: The parameter index returned by IPFS is stored through the blockchain storage system, and the security of data storage and access is ensured through smart contracts.

5. The method according to any one of claims 1 to 4, characterized in that: The edge node includes a traffic monitoring module, a traffic detection module and a response module, which are respectively used for traffic capture, malicious traffic detection and abnormal traffic processing.

6. The method according to claim 5, characterized in that The traffic monitoring module captures and analyzes network traffic through Google's open source project gopacket.

7. A Docker-based, easily extensible, privacy-preserving IoT malicious traffic detection device, characterized in that: The device comprises: Docker containers deployed in edge server nodes; An intrusion detection model deployed in the Docker container detects IoT traffic packets using a deep learning algorithm; Docker containers deployed in central server nodes; The blockchain and IPFS file storage system deployed in the Docker container is used to store and manage the parameters of the intrusion detection model to ensure data security and system scalability; Federated learning module, used for local model training and global parameter aggregation of edge nodes.

8. The device according to claim 7, characterized in that The intrusion detection model uses a one-dimensional convolutional neural network, which can automatically extract features from traffic data and determine the type of traffic.

9. The device according to claim 7 or 8, characterized in that The traffic monitoring module in the device captures and analyzes network traffic through Google's open source project gopacket.

10. The device according to any one of claims 7 to 9, characterized in that The response module is used to detect and respond to malicious traffic data packets. The detected malicious traffic data packets are directly discarded and a warning is generated. For normal traffic data packets, the normal traffic data packets are allowed to pass normally and a log record is generated.

Citation Information

Patent Citations

  • A method, apparatus, and electronic device for detecting malicious traffic in an Internet of Things (IoT) system.

    CN115174237B