Web application security protection method for basic platform of Internet of Things

By acquiring and analyzing the hardware feature information and data transmission information of IoT terminal devices, establishing an analysis platform for security assessment, solving the shortcomings of IoT systems in device legality judgment and real-time security monitoring, achieving comprehensive security analysis and abnormal detection of IoT systems, and improving the reliability of the system.

CN119996027APending Publication Date: 2025-05-13GUANGXI LVFA TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510236694.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-28
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

The Internet of Things system has shortcomings in determining the legality of equipment and real-time security monitoring, which leads to illegal devices not being detected and accessed to the system, and lacks an effective real-time security monitoring mechanism, making it difficult to detect equipment abnormalities in a timely manner, resulting in an expansion of the impact of security incidents.

Method used

Hardware feature information and data transmission information are obtained through the Internet of Things terminal device interface, serialize encryption and upload, establish an IoT terminal device analysis platform, feature marking and whitelisting of hardware information, compare and analyze data transmission information, traffic analysis, business analysis and behavior analysis, comprehensive analysis results to conduct security assessment, and determine whether there are abnormalities in the equipment.

Benefits of technology

It realizes comprehensive security analysis and abnormal detection of IoT devices, effectively reduces the risk of system failure caused by device security issues, improves the overall reliability of IoT systems, ensures the stable operation of the system, and provides support for the promotion and popularization of IoT applications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119996027A_ABST
    Figure CN119996027A_ABST
Patent Text Reader

Abstract

The invention discloses an Internet of Things basic platform Web application security protection method, which comprises the following steps of: acquiring a hardware feature information set through an Internet of Things terminal equipment interface, and acquiring a data transmission information set of Internet of Things terminal equipment; serialized encryption is carried out on the obtained hardware information feature set and the data transmission information feature set; the Internet of Things terminal analysis platform carries out comparative analysis on the obtained data transmission information and the hardware information feature set; obtaining a second analysis result of flow analysis, service analysis and behavior analysis of the data transmission information; and performing security analysis on the Internet of Things terminal equipment according to the first analysis result and the second analysis result, and judging whether the Internet of Things terminal equipment is abnormal or not according to a security analysis result. According to the invention, the security analysis and anomaly detection of the infrastructure of the Internet of Things and the corresponding Web application can be realized, the system fault risk caused by the security problem of the equipment is effectively reduced, and the overall reliability of the system of the Internet of Things is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of Internet of Things security technology, and in particular to a method for protecting the security of Web applications on an Internet of Things infrastructure platform. Background Art

[0002] The Internet of Things is an "Internet of Things" that covers everything in the world, based on the computer Internet, using technologies such as RFID and wireless data communication. In this network, objects (goods) can "communicate" with each other without human intervention. Its essence is to use radio frequency automatic identification (RFID) technology to achieve automatic identification of objects (goods) and interconnection and sharing of information through the computer Internet. RFID is a technology that can make objects "speak". In the concept of the "Internet of Things", RFID tags store standardized and interoperable information, which is automatically collected to the central information system through the wireless data communication network to achieve the identification of objects (goods), and then realize information exchange and sharing through open computer networks, and achieve "transparent" management of objects.

[0003] At present, the Internet of Things technology is showing a booming development trend. By connecting a large number of terminal devices, it realizes the interconnection and data sharing between devices. However, the current Internet of Things system has obvious deficiencies in device legitimacy judgment and real-time security monitoring. Some existing methods for judging the legitimacy of devices are often not accurate and comprehensive enough, and cannot comprehensively consider the various characteristics and operation information of the devices. They are prone to misjudgment or omission, which makes it possible for illegal devices to access the system without being noticed. At the same time, there is a lack of effective real-time security monitoring mechanism, and abnormal conditions during the operation of the equipment cannot be discovered in time. When the equipment is abnormal, it is difficult to take timely measures to deal with it, resulting in the expansion of the scope of the impact of the security incident, which may cause system failures and bring serious economic losses to users and enterprises. Summary of the invention

[0004] The present invention provides a method for protecting the security of Web applications on an IoT infrastructure platform, which can realize security analysis and anomaly detection of IoT infrastructure equipment and corresponding Web applications, effectively reduce the risk of system failures caused by equipment security issues, and improve the overall reliability of the IoT system. The specific technical solution is as follows:

[0005] A method for protecting the security of a Web application on an Internet of Things infrastructure platform comprises the following steps:

[0006] Obtain a set of hardware feature information through an IoT terminal device interface, and obtain a set of data transmission information of an IoT terminal device;

[0007] Serializing and encrypting the acquired hardware information feature collection and data transmission information feature collection, and uploading the encrypted hardware information feature collection and data transmission information feature collection;

[0008] Establish an IoT terminal equipment analysis platform; the IoT terminal analysis platform obtains a collection of hardware information features and a collection of data transmission information features;

[0009] The IoT terminal analysis platform performs feature marking on the acquired hardware information feature collection and establishes a hardware feature whitelist; the IoT terminal analysis platform performs comparative analysis on the acquired data transmission information and the hardware information feature collection; the IoT terminal analysis platform performs traffic analysis, business analysis, and behavior analysis on the acquired data transmission information;

[0010] Obtain a first analysis result of comparative analysis of data transmission information and hardware information feature collection; obtain a second analysis result of flow analysis, business analysis and behavior analysis of data transmission information;

[0011] A security analysis is performed on the IoT terminal device according to the first analysis result and the second analysis result, and it is determined whether there is an abnormality in the IoT terminal device according to the result of the security analysis.

[0012] Preferably, the hardware feature information set is a set including a MAC address, chip information and hardware configuration information.

[0013] Preferably, the data transmission information feature set is a set including a data transmission source address, a data transmission destination address, a data transmission frequency, a transmission protocol and a data packet transmission volume.

[0014] Preferably, the serialization and encryption of the acquired hardware information feature collection and data transmission information feature collection comprises the following steps:

[0015] Serializing and encoding the hardware information feature collection and the data transmission information feature collection;

[0016] The serialized hardware information feature collection and data transmission information feature collection are encrypted using the AES-GCM algorithm;

[0017] The encrypted hardware information feature collection and data transmission information feature collection are stored in blocks.

[0018] Preferably, the IoT terminal analysis platform includes a distributed feature extraction module and a hardware feature whitelist generation module; the distributed feature extraction module is used to parse encrypted data packets; the hardware whitelist generation module is used to establish a device identification library based on hardware feature information collection.

[0019] Preferably, the IoT terminal analysis platform performs comparative analysis on the acquired data transmission information and the hardware information feature collection, comprising the following steps:

[0020] Compare the data transmission source address and destination address of the data transmission information with the legal address range recorded in the hardware information feature collection;

[0021] Compare the data transmission frequency of the data transmission information with the data transmission frequency range supported by the normal operation of the corresponding device in the hardware information feature collection;

[0022] Obtain the hardware configuration information of the hardware information feature collection and the business logic of the corresponding device, and compare the current data packet transmission volume with the historical data transmission volume.

[0023] Preferably, performing security analysis on the IoT terminal device according to the first analysis result and the second analysis result comprises the following steps:

[0024] Establish risk weights for abnormal situations of the first analysis result and the second analysis result;

[0025] Establish a device security assessment coefficient based on the device's network environment threat index and device security history coefficient;

[0026] Determine whether there is an abnormality in the IoT terminal device based on the abnormal situation risk weight and device safety assessment coefficient;

[0027] Generate security analysis and assessment results for IoT terminal devices that are judged to have abnormalities.

[0028] A Web application security protection system for an Internet of Things basic platform includes a first processing unit for obtaining a hardware feature information set through an Internet of Things terminal device interface and obtaining a data transmission information set of an Internet of Things terminal device;

[0029] A second processing unit is used to serialize and encrypt the acquired hardware information feature collection and data transmission information feature collection, and upload the encrypted hardware information feature collection and data transmission information feature collection;

[0030] The third processing unit is used to establish an IoT terminal device analysis platform; the IoT terminal analysis platform obtains a hardware information feature collection and a data transmission information feature collection;

[0031] The fourth processing unit is used for the IoT terminal analysis platform to feature-mark the acquired hardware information feature collection and establish a hardware feature whitelist; the IoT terminal analysis platform compares and analyzes the acquired data transmission information with the hardware information feature collection; the IoT terminal analysis platform performs traffic analysis, business analysis and behavior analysis on the acquired data transmission information;

[0032] A fifth processing unit is used to obtain a first analysis result of comparing and analyzing the data transmission information with the hardware information feature collection; and obtain a second analysis result of performing flow analysis, business analysis, and behavior analysis on the data transmission information;

[0033] The sixth processing unit is used to perform a security analysis on the Internet of Things terminal device according to the first analysis result and the second analysis result, and determine whether there is an abnormality in the Internet of Things terminal device according to the result of the security analysis.

[0034] A Web application security protection device for an Internet of Things basic platform, the device comprising a processor and a memory; the memory is used to store program codes and transmit the program codes to the processor;

[0035] The processor is used to execute the steps of the above-mentioned method for protecting the security of Web applications on the basic platform of the Internet of Things according to the instructions in the program code.

[0036] A computer-readable storage medium is used to store program code, and the program code is used to execute the steps of the above-mentioned method for protecting the security of Web applications on an Internet of Things infrastructure platform.

[0037] Compared with the prior art, the present invention has the following beneficial effects:

[0038] The present invention obtains hardware feature information set and data transmission information set through the interface of the Internet of Things terminal device, and realizes the comprehensive collection of basic information and operation information of the device. The information is serialized, encrypted and uploaded, which effectively guarantees the security of the information during the transmission process; and by establishing an Internet of Things terminal device analysis platform, the hardware information feature set is feature-marked and a hardware feature whitelist is established, which provides a benchmark for the subsequent judgment of the legitimacy of the device. By comparing and analyzing the acquired data transmission information with the hardware information feature set, it is possible to accurately identify whether the device is a legal device, effectively prevent illegal devices from accessing the Internet of Things system, and avoid potential security threats. Finally, by combining the first analysis result and the second analysis result, the Internet of Things terminal device is security analyzed, and it is possible to judge in real time whether the device is abnormal. Once an abnormality is found, the system can send an early warning signal in time to notify the management personnel to take corresponding measures, thereby realizing real-time security monitoring of the Internet of Things system and reducing the probability and loss of security incidents. The present invention effectively reduces the risk of system failure caused by equipment security issues and improves the overall reliability of the Internet of Things system by performing comprehensive security analysis and abnormality detection on the Internet of Things terminal device. This not only ensures the stable operation of the Internet of Things system, but also provides strong support for the promotion and popularization of Internet of Things applications. BRIEF DESCRIPTION OF THE DRAWINGS

[0039] In order to more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the following is a brief introduction to the drawings required for the specific embodiments or the description of the prior art. In all the drawings, similar elements or parts are generally identified by similar reference numerals. In the drawings, the elements or parts are not necessarily drawn according to the actual scale.

[0040] Figure 1 The figure is a flow chart of the method of the present invention. DETAILED DESCRIPTION

[0041] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0042] It should be understood that when used in this specification and the appended claims, the terms "include" and "comprises" indicate the presence of described features, integers, steps, operations, elements and / or components, but do not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components and / or combinations thereof.

[0043] It should also be understood that the terms used in the present specification are only for the purpose of describing specific embodiments and are not intended to limit the present invention. As used in the present specification and the appended claims, unless the context clearly indicates otherwise, the singular forms "a", "an" and "the" are intended to include plural forms.

[0044] It should be further understood that the term "and / or" used in the present description and the appended claims refers to any and all possible combinations of one or more of the associated listed items, and includes these combinations.

[0045] Example 1

[0046] A method for protecting the security of a Web application on an Internet of Things infrastructure platform comprises the following steps:

[0047] Obtain a set of hardware feature information through an IoT terminal device interface, and obtain a set of data transmission information of an IoT terminal device;

[0048] Serializing and encrypting the acquired hardware information feature collection and data transmission information feature collection, and uploading the encrypted hardware information feature collection and data transmission information feature collection;

[0049] Establish an IoT terminal equipment analysis platform; the IoT terminal analysis platform obtains a collection of hardware information features and a collection of data transmission information features;

[0050] The IoT terminal analysis platform performs feature marking on the acquired hardware information feature collection and establishes a hardware feature whitelist; the IoT terminal analysis platform performs comparative analysis on the acquired data transmission information and the hardware information feature collection; the IoT terminal analysis platform performs traffic analysis, business analysis, and behavior analysis on the acquired data transmission information;

[0051] Obtain a first analysis result of comparative analysis of data transmission information and hardware information feature collection; obtain a second analysis result of flow analysis, business analysis and behavior analysis of data transmission information;

[0052] A security analysis is performed on the IoT terminal device according to the first analysis result and the second analysis result, and it is determined whether there is an abnormality in the IoT terminal device according to the result of the security analysis.

[0053] First, the hardware feature information set and data transmission information set are obtained through the IoT terminal device interface, which is the collection of basic device information and operation information. Then, this information is serialized, encrypted and uploaded to ensure the security of the information during transmission. An IoT terminal device analysis platform is established. After obtaining the uploaded information, the platform features the hardware information feature set and establishes a hardware feature whitelist to provide a benchmark for subsequent judgment of the legitimacy of the device. At the same time, the data transmission information is compared and analyzed with the hardware information feature set, and traffic analysis, business analysis and behavior analysis are performed to evaluate the security of data transmission from multiple dimensions. Finally, these analysis results are combined to conduct a security analysis of the IoT terminal device to determine whether there are any abnormalities.

[0054] Example 2

[0055] The difference between this embodiment and embodiment 1 is that the hardware feature information set is a set including a MAC address, chip information and hardware configuration information.

[0056] The hardware feature information is used in the subsequent analysis process. The MAC address can uniquely identify the device, the chip information reflects the core processing capability of the device, and the hardware configuration information reflects the overall performance and resource status of the device. By obtaining this detailed hardware feature information, the IoT terminal device analysis platform can more accurately feature the device and establish a hardware feature whitelist, providing more accurate basic data for subsequent security analysis.

[0057] Example 3

[0058] This embodiment differs from Embodiment 2 in that the data transmission information feature set is a set including a data transmission source address, a data transmission destination address, a data transmission frequency, a transmission protocol, and a data packet transmission volume.

[0059] The data transmission information feature collection reflects the data transmission behavior of the IoT terminal device. The analysis platform collects and analyzes this data transmission information and combines it with the hardware information feature collection to evaluate the security of data transmission from different angles. For example, by comparing the data transmission source address and destination address with the legal address range in the hardware information, it is determined whether there are abnormal communication targets; the data transmission frequency, transmission protocol, and data packet transmission volume are analyzed to see if they meet the normal working mode of the device, so as to more deeply discover potential security risks. The data transmission information feature collection is defined in detail so that the analysis platform can have a deep insight into the data transmission behavior pattern of the IoT terminal device. By analyzing this information, abnormal data transmission behavior can be discovered in a timely manner, such as abnormal communication addresses, uncommon transmission frequencies or protocol usage, etc., providing a more detailed monitoring dimension for security protection.

[0060] Example 4

[0061] The difference between this embodiment and embodiment 3 is that the serialization and encryption of the acquired hardware information feature set and data transmission information feature set includes the following steps:

[0062] Serializing and encoding the hardware information feature collection and the data transmission information feature collection;

[0063] The serialized hardware information feature collection and data transmission information feature collection are encrypted using the AES-GCM algorithm;

[0064] The encrypted hardware information feature collection and data transmission information feature collection are stored in blocks.

[0065] The two collections are serialized and encoded, and converted into a format suitable for subsequent encryption processing. This step enables the data structure to be better recognized and processed by the encryption algorithm. Next, the serialized collection is encrypted using the AES-GCM algorithm. The AES-GCM algorithm has high security and efficiency, and can provide data integrity authentication and certain anti-replay attack capabilities while ensuring data confidentiality. Encrypting data with this algorithm ensures the security of data during storage and transmission, and prevents data from being illegally obtained and tampered with. Finally, the encrypted collection is stored in blocks. The purpose of block storage is to improve the reliability and flexibility of data storage, and it also helps to improve efficiency in subsequent data retrieval and processing. Different blocks can be stored on different storage media or storage nodes, reducing the risk of data loss due to single point failures.

[0066] Example 5

[0067] The difference between this embodiment and Embodiment 4 is that the Internet of Things terminal analysis platform includes a distributed feature extraction module and a hardware feature whitelist generation module; the distributed feature extraction module is used to parse encrypted data packets; the hardware whitelist generation module is used to establish a device identification library based on hardware feature information collection.

[0068] The platform includes a distributed feature extraction module and a hardware feature whitelist generation module.

[0069] The distributed feature extraction module is responsible for parsing encrypted data packets. In the process of data transmission, in order to ensure security, data is usually encrypted. This module uses a specific decryption algorithm and key to parse the encrypted data packet, extract the hardware information feature collection and data transmission information feature collection contained therein, and provide raw data support for subsequent analysis work. The hardware whitelist generation module uses the hardware feature information set obtained by parsing to establish a device identification library. It analyzes, classifies and marks the hardware features, and classifies them into corresponding categories according to the different feature attributes of the device, forming a database that can accurately identify different IoT terminal devices. This device identification library is used as a hardware feature whitelist to judge the legitimacy and normality of the device during subsequent comparative analysis. The distributed feature extraction module can quickly and accurately parse encrypted data packets, improve the efficiency of data processing, ensure that the analysis platform can obtain the required information in a timely manner, and monitor the status of IoT terminal devices in real time.

[0070] Example 6

[0071] The difference between this embodiment and embodiment 5 is that the IoT terminal analysis platform performs comparative analysis on the acquired data transmission information and the hardware information feature collection, including the following steps:

[0072] Compare the data transmission source address and destination address of the data transmission information with the legal address range recorded in the hardware information feature collection;

[0073] Compare the data transmission frequency of the data transmission information with the data transmission frequency range supported by the normal operation of the corresponding device in the hardware information feature collection;

[0074] Obtain the hardware configuration information of the hardware information feature collection and the business logic of the corresponding device, and compare the current data packet transmission volume with the historical data transmission volume.

[0075] By comparing the data transmission source address and destination address of the data transmission information with the legal address range recorded in the hardware information feature collection. The hardware information feature collection records the source address and destination address range allowed when the device is communicating normally. Through this comparison, it can be determined whether the current data transmission is carried out within the legal communication range. If an address outside this range appears, it may mean that there is abnormal communication behavior. Then, the data transmission frequency of the data transmission information is compared with the data transmission frequency range supported by the corresponding device in the hardware information feature collection for normal operation. Due to differences in their functions and performance, different IoT terminal devices have different data transmission frequencies during normal operation. By comparing the actual transmission frequency with the normal frequency range, it can be found whether there is abnormal high-frequency or low-frequency transmission, which may indicate that the device is attacked or malfunctions. Finally, the hardware configuration information of the hardware information feature collection and the business logic of the corresponding device are obtained, and the current data packet transmission volume and the historical data transmission volume are compared. The hardware configuration information and business logic determine the data packet transmission volume range of the device under normal circumstances. By comparing with the historical data transmission volume, it can be determined whether the current data packet transmission volume is reasonable. For example, if the current data packet transmission volume is much higher than the historical average level and does not match the hardware configuration and business logic, there may be a problem of abnormal data transmission.

[0076] Example 7

[0077] The difference between this embodiment and embodiment 6 is that the security analysis of the IoT terminal device according to the first analysis result and the second analysis result includes the following steps:

[0078] Establish risk weights for abnormal situations of the first analysis result and the second analysis result;

[0079] Establish a device security assessment coefficient based on the device's network environment threat index and device security history coefficient;

[0080] Determine whether there is an abnormality in the IoT terminal device based on the abnormal situation risk weight and device safety assessment coefficient;

[0081] Generate security analysis and assessment results for IoT terminal devices that are judged to have abnormalities.

[0082] By establishing the risk weights of abnormal situations for the first analysis result and the second analysis result, different risk weights are assigned to various abnormal situations that appear in the comparative analysis of the data transmission information and the hardware information feature collection (the first analysis result) and the data transmission information flow, business and behavior analysis (the second analysis result), according to factors such as the severity of their impact on device security and the probability of occurrence. For example, a higher risk weight is assigned to an abnormal data transmission source address, while a lower risk weight is assigned to a slight fluctuation in the data packet transmission volume.

[0083] Secondly, establish a device security assessment coefficient based on the device's network environment threat index and device security history coefficient. The network environment threat index takes into account the security of the network environment in which the IoT terminal device is located, such as the degree of openness of the network, whether there are known security vulnerabilities, and other factors; the device security history coefficient refers to the device's past security records, including whether it has ever been attacked or has experienced abnormal situations. By combining these two factors, an assessment coefficient that can reflect the overall security status of the device is calculated. Then, based on the risk weight of the abnormal situation and the device security assessment coefficient, determine whether the IoT terminal device has abnormalities. Combine the risk weights of each abnormal situation with the device security assessment coefficient, and use a specific calculation model or rule to derive a comprehensive security assessment value.

[0084] Example 8

[0085] A Web application security protection system for an Internet of Things basic platform includes a first processing unit for obtaining a hardware feature information set through an Internet of Things terminal device interface and obtaining a data transmission information set of an Internet of Things terminal device;

[0086] A second processing unit is used to serialize and encrypt the acquired hardware information feature collection and data transmission information feature collection, and upload the encrypted hardware information feature collection and data transmission information feature collection;

[0087] The third processing unit is used to establish an IoT terminal device analysis platform; the IoT terminal analysis platform obtains a hardware information feature collection and a data transmission information feature collection;

[0088] The fourth processing unit is used for the IoT terminal analysis platform to feature-mark the acquired hardware information feature collection and establish a hardware feature whitelist; the IoT terminal analysis platform compares and analyzes the acquired data transmission information with the hardware information feature collection; the IoT terminal analysis platform performs traffic analysis, business analysis and behavior analysis on the acquired data transmission information;

[0089] A fifth processing unit is used to obtain a first analysis result of comparing and analyzing the data transmission information with the hardware information feature collection; and obtain a second analysis result of performing flow analysis, business analysis, and behavior analysis on the data transmission information;

[0090] The sixth processing unit is used to perform a security analysis on the Internet of Things terminal device according to the first analysis result and the second analysis result, and determine whether there is an abnormality in the Internet of Things terminal device according to the result of the security analysis.

[0091] Example 9

[0092] A Web application security protection device for an Internet of Things basic platform, the device comprising a processor and a memory; the memory is used to store program codes and transmit the program codes to the processor;

[0093] The processor is used to execute the steps of the above-mentioned method for protecting the security of Web applications on the basic platform of the Internet of Things according to the instructions in the program code.

[0094] Example 10

[0095] A computer-readable storage medium is used to store program code, and the program code is used to execute the steps of the above-mentioned method for protecting the security of Web applications on an Internet of Things infrastructure platform.

[0096] In summary, the present invention obtains hardware feature information set and data transmission information set through the interface of the Internet of Things terminal device, and realizes the comprehensive collection of basic information and operation information of the device. The information is serialized, encrypted and uploaded, which effectively guarantees the security of the information during the transmission process; and by establishing an Internet of Things terminal device analysis platform, the hardware information feature collection is feature-marked and a hardware feature whitelist is established, which provides a benchmark for the subsequent judgment of the legitimacy of the device. By comparing and analyzing the acquired data transmission information with the hardware information feature collection, it is possible to accurately identify whether the device is a legal device, effectively prevent illegal devices from accessing the Internet of Things system, and avoid potential security threats. Finally, by combining the first analysis result and the second analysis result, the Internet of Things terminal device is security analyzed, and it is possible to judge in real time whether the device is abnormal. Once an abnormality is found, the system can send an early warning signal in time to notify the management personnel to take corresponding measures, thereby realizing real-time security monitoring of the Internet of Things system and reducing the probability and loss of security incidents. The present invention effectively reduces the risk of system failure caused by equipment security issues and improves the overall reliability of the Internet of Things system by performing comprehensive security analysis and abnormality detection on the Internet of Things terminal device. This not only ensures the stable operation of the Internet of Things system, but also provides strong support for the promotion and popularization of Internet of Things applications.

[0097] Those of ordinary skill in the art will appreciate that the units of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition of each example has been generally described in terms of function in the above description. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the present invention.

[0098] In the embodiments provided by the present invention, it should be understood that the division of units is only a logical function division, and there may be other division methods in actual implementation, for example, multiple units can be combined into one unit, one unit can be split into multiple units, or some features can be ignored, etc.

[0099] In addition, each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.

[0100] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product, which is stored in a storage medium and includes several instructions for a computer device (which can be a personal computer, a server or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, read-only memory (ROM, Read-0nlyMemory), random access memory (RAM, RandomAccessMemory), mobile hard disk, magnetic disk or optical disk, etc., which can store program code.

[0101] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or replace some or all of the technical features therein by equivalents. These modifications or replacements do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of the embodiments of the present invention, and they should all be included in the scope of the claims and specification of the present invention.

Claims

1. A method for protecting the security of Web applications on an Internet of Things infrastructure platform, characterized in that: The following steps are involved: Obtain a set of hardware feature information through an IoT terminal device interface, and obtain a set of data transmission information of an IoT terminal device; Serializing and encrypting the acquired hardware information feature collection and data transmission information feature collection, and uploading the encrypted hardware information feature collection and data transmission information feature collection; Establish an IoT terminal equipment analysis platform; the IoT terminal analysis platform obtains a collection of hardware information features and a collection of data transmission information features; The IoT terminal analysis platform performs feature marking on the acquired hardware information feature collection and establishes a hardware feature whitelist; The IoT terminal analysis platform conducts comparative analysis on the acquired data transmission information and hardware information feature collection; the IoT terminal analysis platform conducts traffic analysis, business analysis and behavior analysis on the acquired data transmission information; Obtaining a first analysis result of comparing and analyzing the data transmission information with the hardware information feature collection; Obtaining the second analysis result of data transmission information for flow analysis, business analysis and behavior analysis; A security analysis is performed on the IoT terminal device according to the first analysis result and the second analysis result, and it is determined whether there is an abnormality in the IoT terminal device according to the result of the security analysis.

2. According to claim 1, a method for protecting the security of Web applications on an Internet of Things infrastructure platform is characterized in that: The hardware feature information set is a set including MAC address, chip information and hardware configuration information.

3. According to claim 1, a method for protecting the security of Web applications on an Internet of Things infrastructure platform is characterized in that: The data transmission information feature set is a set, including a data transmission source address, a data transmission destination address, a data transmission frequency, a transmission protocol and a data packet transmission volume.

4. According to claim 1, a method for protecting the security of Web applications on an Internet of Things infrastructure platform is characterized in that: The serialization and encryption of the acquired hardware information feature collection and data transmission information feature collection comprises the following steps: Serializing and encoding the hardware information feature collection and the data transmission information feature collection; The serialized hardware information feature collection and data transmission information feature collection are encrypted using the AES-GCM algorithm; The encrypted hardware information feature collection and data transmission information feature collection are stored in blocks.

5. According to claim 1, a method for protecting the security of Web applications on an Internet of Things infrastructure platform is characterized in that: The Internet of Things terminal analysis platform includes a distributed feature extraction module and a hardware feature whitelist generation module; the distributed feature extraction module is used to parse encrypted data packets; the hardware whitelist generation module is used to establish a device identification library based on hardware feature information collection.

6. According to claim 1, a method for protecting the security of Web applications on an Internet of Things infrastructure platform is characterized in that: The IoT terminal analysis platform performs comparative analysis on the acquired data transmission information and the hardware information feature collection, including the following steps: Compare the data transmission source address and destination address of the data transmission information with the legal address range recorded in the hardware information feature collection; Compare the data transmission frequency of the data transmission information with the data transmission frequency range supported by the normal operation of the corresponding device in the hardware information feature collection; Obtain the hardware configuration information of the hardware information feature collection and the business logic of the corresponding device, and compare the current data packet transmission volume with the historical data transmission volume.

7. According to claim 1, a method for protecting the security of Web applications on an Internet of Things infrastructure platform is characterized in that: The method of performing security analysis on the IoT terminal device according to the first analysis result and the second analysis result includes the following steps: Establish risk weights for abnormal situations of the first analysis result and the second analysis result; Establish a device security assessment coefficient based on the device's network environment threat index and device security history coefficient; Determine whether there is an abnormality in the IoT terminal device based on the abnormal situation risk weight and device safety assessment coefficient; Generate security analysis and assessment results for IoT terminal devices that are judged to have abnormalities.

8. A Web application security protection system for an Internet of Things basic platform, comprising a first processing unit, for obtaining a hardware feature information set through an Internet of Things terminal device interface, and obtaining a data transmission information set of an Internet of Things terminal device; A second processing unit is used to serialize and encrypt the acquired hardware information feature collection and data transmission information feature collection, and upload the encrypted hardware information feature collection and data transmission information feature collection; The third processing unit is used to establish an IoT terminal device analysis platform; the IoT terminal analysis platform obtains a hardware information feature collection and a data transmission information feature collection; The fourth processing unit is used for the IoT terminal analysis platform to feature-mark the acquired hardware information feature collection and establish a hardware feature whitelist; The IoT terminal analysis platform conducts comparative analysis on the acquired data transmission information and hardware information feature collection; the IoT terminal analysis platform conducts traffic analysis, business analysis and behavior analysis on the acquired data transmission information; A fifth processing unit, configured to obtain a first analysis result of comparing and analyzing the data transmission information with the hardware information feature collection; Obtaining the second analysis result of data transmission information for flow analysis, business analysis and behavior analysis; The sixth processing unit is used to perform a security analysis on the Internet of Things terminal device according to the first analysis result and the second analysis result, and determine whether there is an abnormality in the Internet of Things terminal device according to the result of the security analysis.

9. A Web application security protection device for an Internet of Things infrastructure platform, the device comprising a processor and a memory; the memory is used to store program code and transmit the program code to the processor; The processor is used to execute the steps of the above-mentioned method for protecting the security of Web applications on the basic platform of the Internet of Things according to the instructions in the program code.

10. A computer-readable storage medium, wherein the computer-readable storage medium is used to store program code, and the program code is used to execute the steps of the above-mentioned method for protecting the security of Web applications based on the basic platform of the Internet of Things.