An Internet of Things device protocol analysis system and method based on edge computing

Through edge computing, the protocol traffic data packets of IoT devices are captured and analyzed in real time, and the traffic feature array is built and the degree of forgery is calculated, which solves the problem of difficult to measure the degree of abnormal forgery of IoT device protocol traffic data packets, and realizes real-time early warning and timely detection of security threats.

CN120050117BActive Publication Date: 2025-07-04SHENZHEN OMNI INTELLIGENT TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510512014.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-23
Publication Date
2025-07-04
Estimated Expiration
2045-04-23

AI Technical Summary

Technical Problem

The existing technology is difficult to effectively measure the degree of abnormal forgery of IoT device protocol traffic data packets in real time, making it difficult to detect security threats. Traditional abnormal detection algorithms are difficult to adapt to rapidly changing traffic patterns and cannot be promptly warned.

Method used

Through edge computing, real-time capture of protocol traffic data packets, perform traffic feature extraction, build a traffic feature array, determine the traffic overload coefficient and transmission mutation, extract request access information, calculate abnormal access factors, and determine the forgery degree based on traffic transmission mutation and abnormal access factors, and conduct transmission early warning.

Benefits of technology

It realizes accurate monitoring of IoT device protocol traffic data packets, timely identify traffic abnormalities and attack behaviors, improves the real-time early warning capabilities of the analysis system, and enhances network security and stability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120050117B_ABST
    Figure CN120050117B_ABST
Patent Text Reader

Abstract

The present application provides an Internet of Things device protocol analysis system and method based on edge computing, which captures protocol traffic data packets of each edge Internet of Things device in real time; extracts traffic characteristics of each protocol traffic data packet respectively to obtain an edge traffic feature array, determines the traffic overload coefficient of the Internet of Things device protocol based on the edge traffic feature array, and determines the traffic transmission mutation degree of each based on the traffic overload coefficient; extracts the request access information of each edge Internet of Things device from the corresponding protocol traffic data packet, and determines each abnormal access factor through the corresponding request access information; determines the forgery degree of each protocol traffic data packet through the corresponding traffic transmission mutation degree and the corresponding abnormal access factor, and performs transmission early warning on each edge Internet of Things device respectively based on the forgery degree of the protocol traffic data packet. By adopting the above solution, the abnormal forgery degree of the protocol traffic data packet can be measured and early warning can be given in time to improve the real-time early warning ability of the analysis system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of protocol analysis. More specifically, this application relates to an Internet of Things device protocol analysis system and method based on edge computing. Background Art

[0002] Protocol analysis of Internet of Things devices based on edge computing is an emerging network security and data optimization method, aiming to real-time parse and analyze the communication protocols of Internet of Things (IoT) devices through edge computing nodes (such as edge gateways, intelligent routers, edge servers, etc.), so as to improve data transmission efficiency, enhance security and reduce the cloud computing burden. IoT devices usually use a variety of heterogeneous communication protocols, and the analysis of these protocols requires real-time traffic monitoring, protocol parsing, traffic feature extraction, anomaly detection and behavior prediction on the edge side, so as to ensure the normal operation of the devices and timely discover potential security threats, such as forged traffic, DDoS attacks, device hijacking and abnormal behaviors.

[0003] However, in the actual application process, the traffic is highly dynamic and the anomaly detection is difficult. The Internet of Things traffic has a high degree of time-variability, and the traffic patterns vary significantly in different application scenarios. Traditional anomaly detection algorithms are difficult to adapt to the rapidly changing traffic patterns. In terms of security, it is difficult to detect forged traffic. Attackers can forge legitimate data packets to avoid detection mechanisms based on feature matching, and more advanced machine learning models need to be adopted for behavior analysis. Therefore, how to measure the degree of abnormal forgery of protocol traffic data packets and give timely warnings to improve the real-time warning ability of the analysis system is a difficult problem faced by the industry. Summary of the Invention

[0004] This application provides an Internet of Things device protocol analysis system and method based on edge computing, which can measure the degree of abnormal forgery of protocol traffic data packets and give timely warnings to improve the real-time warning ability of the analysis system.

[0005] In the first aspect, this application provides an Internet of Things device protocol analysis method based on edge computing. The analysis method includes the following steps:

[0006] Real-time capture the protocol traffic data packets of each edge Internet of Things device;

[0007] Respectively extract traffic features from the protocol traffic data packets of each edge Internet of Things device, and then obtain an edge traffic feature array. Determine the traffic overload coefficient of the Internet of Things device protocol based on the edge traffic feature array, and determine the traffic transmission mutation degree of each edge Internet of Things device based on the traffic overload coefficient;

[0008] Extract the request access information of each edge Internet of Things device from the corresponding protocol traffic data packet, and determine the abnormal access factor of each edge Internet of Things device through the corresponding request access information;

[0009] Determine the forgery degree of the protocol traffic data packet of each edge Internet of Things device through the corresponding traffic transmission mutation degree and the corresponding abnormal access factor, and perform transmission warning on each edge Internet of Things device based on the forgery degree of the corresponding protocol traffic data packet.

[0010] Preferably, the protocol traffic data packets of each edge Internet of Things device are captured in real time through the edge gateway.

[0011] Preferably, traffic feature extraction is performed on the protocol traffic data packets of each edge Internet of Things device respectively, and then the edge traffic feature array is obtained, which specifically includes:

[0012] Perform traffic feature extraction on the protocol traffic data packets of each edge Internet of Things device respectively, and then obtain the traffic feature sequence of each edge Internet of Things device;

[0013] Construct an edge traffic feature array according to all the traffic feature sequences.

[0014] Preferably, determining the traffic overload coefficient of the Internet of Things device protocol based on the edge traffic feature array specifically includes:

[0015] Determine the traffic load degree corresponding to the Internet of Things device protocol according to the edge traffic feature array;

[0016] Extract the traffic level and traffic fluctuation degree corresponding to the Internet of Things device protocol in the edge traffic feature array;

[0017] Determine the traffic overload coefficient of the Internet of Things device protocol through the traffic load degree, the traffic level and the traffic fluctuation degree.

[0018] Preferably, determining the traffic transmission mutation degree of each edge Internet of Things device based on the traffic overload coefficient specifically includes:

[0019] Determine the traffic load fluctuation degree of each edge Internet of Things device respectively according to the corresponding protocol traffic data packet and the preset sliding time window;

[0020] Determine the traffic transmission mutation degree of each edge Internet of Things device through the traffic overload coefficient and the corresponding traffic load fluctuation degree.

[0021] Preferably, determining the abnormal access factor of each edge Internet of Things device through the corresponding request access information specifically includes:

[0022] For each edge Internet of Things device, extract the edge access feature of the edge Internet of Things device from the corresponding request access information;

[0023] Determine the historical feature level and historical feature dispersion of the edge access feature;

[0024] Determine the abnormal access factor of the edge Internet of Things device through the edge access feature, the historical feature level and the historical feature dispersion, and then obtain the abnormal access factors of each edge Internet of Things device.

[0025] Preferably, performing transmission warnings on each edge Internet of Things device based on the forgery degree of the corresponding protocol traffic data packet specifically includes:

[0026] Obtain a preset forgery degree interval;

[0027] Determine the transmission warning level of each edge Internet of Things device according to the forgery degree of the corresponding protocol traffic data packet and the forgery degree interval;

[0028] Generate transmission warning information for each edge Internet of Things device according to the corresponding transmission warning level.

[0029] In a second aspect, the present application provides an Internet of Things device protocol analysis system based on edge computing, which is used to execute an Internet of Things device protocol analysis method based on edge computing. The Internet of Things device protocol analysis system based on edge computing includes a protocol transmission warning unit, and the protocol transmission warning unit includes:

[0030] A capture module, which is used to capture the protocol traffic data packets of each edge Internet of Things device in real time;

[0031] A mutation determination module, which is used to extract traffic characteristics of the protocol traffic data packets of each edge Internet of Things device respectively to obtain an edge traffic feature array, determine the traffic overload coefficient of the Internet of Things device protocol according to the edge traffic feature array, and determine the traffic transmission mutation degree of each edge Internet of Things device based on the traffic overload coefficient;

[0032] An abnormality determination module, which is used to extract the request access information of each edge Internet of Things device from the corresponding protocol traffic data packet, and determine the abnormal access factor of each edge Internet of Things device through the corresponding request access information;

[0033] A transmission warning module, which is used to determine the forgery degree of the protocol traffic data packets of each edge Internet of Things device through the corresponding traffic transmission mutation degree and the corresponding abnormal access factor, and perform transmission warnings on each edge Internet of Things device based on the forgery degree of the corresponding protocol traffic data packet.

[0034] In a third aspect, the present application provides a computer device, which includes a memory and a processor. The memory is used to store a computer program, and the processor is used to call and run the computer program from the memory, so that the computer device executes the above-mentioned method for analyzing the protocol of an Internet of Things device based on edge computing.

[0035] In a fourth aspect, the present application provides a computer-readable storage medium, in which instructions or codes are stored. When the instructions or codes run on a computer, the computer is enabled to execute the above-mentioned method for analyzing the protocol of an Internet of Things device based on edge computing.

[0036] The technical solutions provided by the disclosed embodiments of the present application have the following beneficial effects:

[0037] In the system and method for analyzing the protocol of an Internet of Things device based on edge computing provided by the present application, protocol traffic data packets of each edge Internet of Things device are captured in real time; traffic feature extraction is respectively performed on the protocol traffic data packets of each edge Internet of Things device, and then an edge traffic feature array is obtained. Based on the edge traffic feature array, a traffic overload coefficient of the Internet of Things device protocol is determined, and based on the traffic overload coefficient, the traffic transmission mutation degree of each edge Internet of Things device is determined; request access information of each edge Internet of Things device is extracted from the corresponding protocol traffic data packet, and an abnormal access factor of each edge Internet of Things device is determined through the corresponding request access information; the forgery degree of the protocol traffic data packet of each edge Internet of Things device is determined through the corresponding traffic transmission mutation degree and the corresponding abnormal access factor, and transmission warnings are respectively given to each edge Internet of Things device based on the forgery degree of the corresponding protocol traffic data packet.

[0038] It can be seen that in the present application, first, by performing traffic feature extraction on the protocol traffic data packets of each edge Internet of Things device, an edge traffic feature array is constructed, and based on this, a traffic overload coefficient is determined, and then the traffic transmission mutation degree is further evaluated, so as to realize accurate monitoring of the device traffic behavior, effectively identify situations of abnormal traffic fluctuations and device overload, and thus timely discover traffic anomalies or attack behaviors; second, by extracting the request access information of the edge Internet of Things device from the protocol traffic data packet and determining the abnormal access factor of the device accordingly, the deviation between the normal access behavior and the abnormal behavior of each device can be effectively quantified. By real-time monitoring the changes of these abnormal access factors, the system can timely discover potential security threats and trigger warnings; finally, by combining the traffic transmission mutation degree and the abnormal access factor to determine the forgery degree of the protocol traffic data packet of each edge Internet of Things device, it is possible to accurately identify whether the device is under attack by forgery or abnormal traffic and give timely warnings to improve the real-time warning ability of the analysis system.

[0039] In summary, the technical solution adopted in this application can measure the degree of abnormal forgery of protocol traffic data packets and give early warnings in a timely manner to improve the real-time warning ability of the analysis system. BRIEF DESCRIPTION OF THE DRAWINGS

[0040] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0041] Figure 1 is an exemplary flowchart of a method for analyzing an Internet of Things device protocol based on edge computing according to some embodiments of the present application;

[0042] Figure 2 is an exemplary flowchart of determining the traffic overload coefficient of an Internet of Things device protocol according to some embodiments of the present application;

[0043] Figure 3 is an exemplary flowchart of determining the abnormal access factor of each edge Internet of Things device according to some embodiments of the present application;

[0044] Figure 4 is a schematic diagram of an exemplary hardware and / or software of a protocol transmission warning unit according to some embodiments of the present application;

[0045] Figure 5 is a schematic diagram of the structure of a computer device for implementing a method for analyzing an Internet of Things device protocol based on edge computing according to some embodiments of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0046] The following will clearly and completely describe the technical solutions in the embodiments of the present application with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only some embodiments of the present application, rather than all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present application.

[0047] The embodiments of the present application provide an Internet of Things device protocol analysis system and method based on edge computing. The core is to capture the protocol traffic data packets of each edge Internet of Things device in real time; extract the traffic characteristics of the protocol traffic data packets of each edge Internet of Things device respectively, and then obtain an edge traffic feature array. Determine the traffic overload coefficient of the Internet of Things device protocol based on the edge traffic feature array, and determine the traffic transmission mutation degree of each edge Internet of Things device based on the traffic overload coefficient; extract the request access information of each edge Internet of Things device from the corresponding protocol traffic data packet, and determine the abnormal access factor of each edge Internet of Things device through the corresponding request access information; determine the forgery degree of the protocol traffic data packet of each edge Internet of Things device through the corresponding traffic transmission mutation degree and the corresponding abnormal access factor, and perform transmission early warning on each edge Internet of Things device based on the forgery degree of the corresponding protocol traffic data packet. The above scheme can measure the abnormal forgery degree of the protocol traffic data packet and give an early warning in time to improve the real-time early warning ability of the analysis system.

[0048] To better understand the above technical solution, the above technical solution will be described in detail below in conjunction with the accompanying drawings of the specification and specific implementation manners. Refer to Figure 1 , which is an exemplary flowchart of an Internet of Things device protocol analysis method based on edge computing according to some embodiments of the present application. The analysis method 100 mainly includes the following steps:

[0049] In step S101, capture the protocol traffic data packets of each edge Internet of Things device in real time.

[0050] Specifically, the protocol traffic data packets of each edge Internet of Things device can be captured in real time through an edge gateway; in an edge computing environment, the edge gateway acts as an intermediate layer between the Internet of Things device and the cloud, responsible for traffic management, security protection and data optimization. In order to realize the real-time capture of the protocol traffic data packets of each edge Internet of Things device, efficient data capture technologies such as eBPF / XDP, DPDK, PF_RING, etc. can be adopted in the edge gateway, and combined with deep protocol analysis tools (such as Wireshark, Zeek, Snort) to achieve comprehensive protocol analysis.

[0051] In step S102, extract the traffic characteristics of the protocol traffic data packets of each edge Internet of Things device respectively, and then obtain an edge traffic feature array. Determine the traffic overload coefficient of the Internet of Things device protocol based on the edge traffic feature array, and determine the traffic transmission mutation degree of each edge Internet of Things device based on the traffic overload coefficient.

[0052] In some embodiments, the traffic characteristics of the protocol traffic data packets of each edge Internet of Things device are extracted respectively, and then the edge traffic feature array can be obtained in the following specific way, that is:

[0053] Extract the traffic feature of the protocol traffic data packet of each edge Internet of Things device, and then obtain the traffic feature sequence of each edge Internet of Things device;

[0054] Construct an edge traffic feature array according to all the traffic feature sequences.

[0055] When specifically implemented, first, the traffic feature of the protocol traffic data packet of each edge Internet of Things device can be extracted respectively. That is, for the protocol traffic data packet of the edge Internet of Things device, multiple traffic features can be extracted from the protocol traffic data packet through statistical and time series analysis methods. The traffic features include data transmission rate, average traffic, traffic standard deviation, traffic load degree, data throughput, and time interval distribution. Among them, the traffic load degree represents the current network traffic load degree of the edge Internet of Things device. The ratio of the total amount of data in the protocol traffic data packet of the edge Internet of Things device to the maximum bandwidth allowed by the edge Internet of Things device can be used as the traffic load degree of the edge Internet of Things device. Thus, the sequence composed of all traffic features is used as the traffic feature sequence of the edge Internet of Things device. Through the above method, the traffic feature sequences of each edge Internet of Things device can be obtained; finally, an edge traffic feature array can be constructed according to all the traffic feature sequences, that is, all the traffic feature sequences are combined according to the corresponding edge Internet of Things device label, and the obtained matrix is used as the edge traffic feature array.

[0056] Preferably, in some embodiments, refer to Figure 2 As shown, this figure is an exemplary flowchart for determining the traffic overload coefficient of the Internet of Things device protocol in some embodiments of the present application. In this embodiment, the specific steps for determining the traffic overload coefficient of the Internet of Things device protocol based on the edge traffic feature array can be implemented as follows:

[0057] In step S1021, determine the traffic load degree corresponding to the Internet of Things device protocol according to the edge traffic feature array;

[0058] In step S1022, extract the traffic level and traffic fluctuation degree corresponding to the Internet of Things device protocol from the edge traffic feature array;

[0059] In step S1023, determine the traffic overload coefficient of the Internet of Things device protocol through the traffic load degree, the traffic level, and the traffic fluctuation degree.

[0060] In specific implementation, first, the traffic load degree corresponding to the IoT device protocol can be extracted from the edge traffic feature array. Here, the traffic load degree represents the load level of the IoT device protocol traffic. The traffic load degrees of each edge IoT device can be extracted from the edge traffic feature array, and thus the mean value of all traffic load degrees can be used as the traffic load degree corresponding to the IoT device protocol. Then, the traffic level and traffic fluctuation degree corresponding to the IoT device protocol can be extracted from the edge traffic feature array. Here, the traffic level represents the average level of the IoT device protocol traffic, and the traffic fluctuation degree represents the overall fluctuation degree of the IoT device protocol traffic. The mean value of all average traffic in the edge traffic feature array can be used as the traffic level corresponding to the IoT device protocol, and the mean value of all traffic standard deviations in the edge traffic feature array can be used as the traffic fluctuation degree corresponding to the IoT device protocol. Finally, the traffic overload coefficient of the IoT device protocol can be determined through the traffic load degree, traffic level, and traffic fluctuation degree. Here, the traffic overload coefficient is an index used to represent the overload degree of the IoT device protocol traffic. In actual implementation, the difference between the traffic load degree and the traffic level can be calculated, and thus the ratio of the calculation result to the traffic fluctuation degree can be determined, and the dimension of the final calculation result can be eliminated, and the result after dimension elimination can be used as the traffic overload coefficient of the IoT device protocol.

[0061] In some embodiments, to determine the traffic transmission mutation degree of each edge IoT device based on the traffic overload coefficient, the following method can be specifically adopted, that is:

[0062] The traffic load fluctuation degree of each edge IoT device is determined according to the corresponding protocol traffic data packet and the preset sliding time window respectively;

[0063] The traffic transmission mutation degree of each edge IoT device is determined through the traffic overload coefficient and the corresponding traffic load fluctuation degree.

[0064] In specific implementation, first, the traffic load fluctuation degree of each edge Internet of Things device can be determined according to the corresponding protocol traffic data packet and the preset sliding time window respectively. The traffic load fluctuation degree represents the degree of fluctuation of the load traffic during the data transmission of the edge Internet of Things device. For each edge Internet of Things device, the traffic load degree in each sliding time window can be calculated based on the protocol traffic data packet of the edge Internet of Things device, and then the standard deviation of all traffic load degrees is used as the traffic load fluctuation degree of the edge Internet of Things device. Through the above method, the traffic load fluctuation degree of each edge Internet of Things device can be obtained. Then, the traffic transmission mutation degree of each edge Internet of Things device can be determined through the traffic overload coefficient and the corresponding traffic load fluctuation degree. The traffic transmission mutation degree represents the severity of traffic fluctuation during the data transmission of the edge Internet of Things device. In actual implementation, the product of the traffic load fluctuation degree of the edge Internet of Things device and the traffic overload coefficient can be used as the traffic transmission mutation degree of the edge Internet of Things device. Through the above method, the traffic transmission mutation degree of each edge Internet of Things device can be obtained.

[0065] It should be noted that by extracting traffic characteristics from the protocol traffic data packets of each edge Internet of Things device, constructing an edge traffic feature array, determining the traffic overload coefficient based on this, and further evaluating the traffic transmission mutation degree, accurate monitoring of the device traffic behavior can be achieved, and situations of abnormal traffic fluctuation and device overload can be effectively identified, so as to timely detect traffic anomalies or attack behaviors (such as DDoS attacks or forged data packets).

[0066] In step S103, the request access information of each edge Internet of Things device is extracted from the corresponding protocol traffic data packet, and the abnormal access factor of each edge Internet of Things device is determined through the corresponding request access information.

[0067] In specific implementation, the request access information of each edge Internet of Things device can be extracted from the corresponding protocol traffic data packet; a protocol analysis tool (such as Wireshark, tcpdump, etc.) can be used to extract the request access information of each edge Internet of Things device from the corresponding protocol traffic data packet. The request access information includes the source IP address of the request, the destination IP address of the request, the timestamp of the request, the request type, the data volume of the request, and the request frequency.

[0068] Preferably, in some embodiments, refer to Figure 3 As shown, this figure is an exemplary flowchart for determining the abnormal access factor of each edge Internet of Things device in some embodiments of the present application. In this embodiment, the abnormal access factor of each edge Internet of Things device is determined through the corresponding request access information, which can be specifically implemented by the following steps:

[0069] In step S1031, for each edge Internet of Things device, extract the edge access features of the edge Internet of Things device from the corresponding request access information;

[0070] In step S1032, determine the historical feature level and historical feature dispersion degree of the edge access features;

[0071] In step S1033, determine the abnormal access factor of the edge Internet of Things device through the edge access features, the historical feature level, and the historical feature dispersion degree, and then obtain the abnormal access factors of each edge Internet of Things device.

[0072] When specifically implemented, first, for each edge Internet of Things device, the edge access features of the edge Internet of Things device can be extracted from the corresponding request access information, that is, feature extraction is performed on the request access information to obtain the edge access features of the edge Internet of Things device. In this application, the edge access features can be request frequency, data packet size, request time distribution, and request response time. Then, the historical feature level and historical feature dispersion degree of the edge access features can be determined. Among them, the historical feature level represents the historical average level of the corresponding edge access feature, and the historical feature dispersion degree represents the historical data dispersion degree of the corresponding edge access feature. In actual implementation, the historical request access information of the edge Internet of Things device can be obtained, and then the historical feature level and historical feature dispersion degree of the corresponding edge access feature can be calculated through the historical request access information, that is, taking the historical mean value of the corresponding edge access feature as the historical feature level, and taking the historical standard deviation of the corresponding edge access feature as the historical feature dispersion degree. Finally, the abnormal access factor of the edge Internet of Things device can be determined through the edge access features, the historical feature level, and the historical feature dispersion degree. Among them, the abnormal access factor is an index used to represent the abnormal access degree of the edge Internet of Things device. In actual implementation, the ratio of the difference between the edge access feature and the historical feature level to the historical feature dispersion degree can be calculated, and the dimensionality of the calculation result can be eliminated, and the result after dimensionality elimination is used as the abnormal access factor of the edge Internet of Things device. Through the above method, the abnormal access factors of each edge Internet of Things device can be obtained.

[0073] It should be noted that by extracting the request access information of the edge Internet of Things device from the protocol traffic data packet and determining the abnormal access factor of the device accordingly, the deviation between the normal access behavior and the abnormal behavior of each device can be effectively quantified. By real-time monitoring the changes of these abnormal access factors, the system can timely discover potential security threats and trigger early warnings, preventing data leakage, network attacks, or device abuse, thereby enhancing the real-time early warning ability of the analysis system, improving the response speed and accuracy to attacks, and thus ensuring the security and stability of the entire Internet of Things system.

[0074] In step S104, the forgery degree of the protocol traffic data packets of each edge Internet of Things device is determined based on the corresponding traffic transmission mutation degree and the corresponding abnormal access factor, and transmission warnings are given to each edge Internet of Things device respectively based on the forgery degree of the corresponding protocol traffic data packets.

[0075] In some embodiments, the forgery degree of the protocol traffic data packets of each edge Internet of Things device is determined based on the corresponding traffic transmission mutation degree and the corresponding abnormal access factor, and the following method can be specifically adopted, that is:

[0076] For each edge Internet of Things device, the weighted sum result of the traffic transmission mutation degree and the abnormal access factor of the edge Internet of Things device is used as the forgery degree of the protocol traffic data packet of the edge Internet of Things device, and thus the forgery degree of the protocol traffic data packet of each edge Internet of Things device is obtained.

[0077] It should be noted that in this application, the forgery degree is an index used to measure the forgery degree of the protocol traffic data packets of edge Internet of Things devices; in specific implementation, the weights corresponding to the traffic transmission mutation degree and the abnormal access factor of edge Internet of Things devices can be set according to historical experience and data analysis, which will not be elaborated here.

[0078] In some embodiments, transmission warnings are given to each edge Internet of Things device respectively based on the forgery degree of the corresponding protocol traffic data packets, and the following method can be specifically adopted, that is:

[0079] Obtain a preset forgery degree interval;

[0080] Determine the transmission warning level of each edge Internet of Things device according to the forgery degree of the corresponding protocol traffic data packet and the forgery degree interval;

[0081] Generate transmission warning information for each edge Internet of Things device according to the corresponding transmission warning level.

[0082] In specific implementation, first, a preset forgery degree interval can be obtained to judge whether the traffic of the device is normal according to the value of the forgery degree, and further evaluate the severity of the transmission warning. The forgery degree interval is used to quantify the abnormal degree of edge Internet of Things devices and can be defined according to historical data, normal traffic behavior and security policies, which will not be elaborated here; then, the transmission warning level of each edge Internet of Things device can be determined according to the forgery degree of the corresponding protocol traffic data packet and the forgery degree interval, that is, the forgery degree of the protocol traffic data packet of each edge Internet of Things device is mapped into the forgery degree interval, so that the transmission warning level of each edge Internet of Things device can be obtained; finally, transmission warning information for each edge Internet of Things device can be generated according to the corresponding transmission warning level. The transmission warning information includes information of the edge Internet of Things device, the transmission warning level, the forgery degree and suggested measures. The suggested measures can be generated according to the following method, for example:

[0083] Low-level warning: When the forgery degree of the device is lower than the lower bound of the forgery degree interval, it indicates that the traffic change of the edge Internet of Things device is small, and no forged traffic or abnormal requests are found. At this time, no measures need to be taken, but the device status can be recorded for subsequent monitoring.

[0084] Medium-level warning: When the forgery degree of the edge Internet of Things device is within the forgery degree interval, it indicates that there is abnormal traffic in the device, which may be an early manifestation of some forged requests or abnormal accesses. At this time, it is necessary to strengthen the monitoring of this edge Internet of Things device and warn the operation and maintenance personnel.

[0085] High-level warning: When the forgery degree of the edge Internet of Things device is higher than the upper bound of the forgery degree interval, it indicates that the traffic of the edge Internet of Things device is seriously abnormal and may be under attack. At this time, protective measures should be taken immediately, such as restricting the access frequency, triggering traffic cleaning, etc., and notify relevant personnel for further inspection.

[0086] It should be noted that by combining the traffic transmission mutation degree and the abnormal access factor to determine the forgery degree of the protocol traffic data packets of each edge Internet of Things device, it is possible to accurately identify whether the device is under attack by forged or abnormal traffic, can timely detect abnormal fluctuations in device behavior, and capture potential threats such as traffic overload and forged requests. Based on the forgery degree for transmission warning, the system can trigger an alarm in the first time to prevent the attack from further expanding or affecting the system security. Through this real-time anomaly detection and warning mechanism, the analysis system can respond quickly, improve the real-time warning ability in the Internet of Things environment, ensure the security and stability of the system, and timely prevent the negative impact of potential network attacks and forged traffic on the device and the network.

[0087] Thus, in this application, first, by extracting traffic characteristics from the protocol traffic data packets of each edge Internet of Things device, then constructing an edge traffic feature array, and based on this determining the traffic overload coefficient, and further evaluating the traffic transmission mutation degree, it is possible to achieve accurate monitoring of the device traffic behavior, can effectively identify abnormal traffic fluctuations and device overload situations, so as to timely detect traffic anomalies or attack behaviors; then, by extracting the request access information of the edge Internet of Things device from the protocol traffic data packets and determining the abnormal access factor of the device accordingly, it is possible to effectively quantify the deviation between the normal access behavior and the abnormal behavior of each device. By real-time monitoring the changes of these abnormal access factors, the system can timely detect potential security threats and trigger warnings; finally, by combining the traffic transmission mutation degree and the abnormal access factor to determine the forgery degree of the protocol traffic data packets of each edge Internet of Things device, it is possible to accurately identify whether the device is under attack by forged or abnormal traffic and give timely warnings to improve the real-time warning ability of the analysis system.

[0088] In summary, the technical solution adopted in this application can measure the degree of abnormal forgery of protocol traffic data packets and give early warnings in a timely manner to improve the real-time early warning ability of the analysis system.

[0089] In addition, on the other hand of this application, in some embodiments, this application provides an edge-computing-based Internet of Things device protocol analysis system. The edge-computing-based Internet of Things device protocol analysis system includes a protocol transmission early warning unit. Refer to Figure 4 , which is a schematic diagram of exemplary hardware and / or software of the protocol transmission early warning unit shown in some embodiments of this application. The protocol transmission early warning unit 400 includes: a capture module 401, a mutation determination module 402, an anomaly determination module 403, and a transmission early warning module 404, which are described as follows:

[0090] The capture module 401 is mainly used in this application to capture the protocol traffic data packets of each edge Internet of Things device in real time;

[0091] The mutation determination module 402 is mainly used in this application to extract the traffic characteristics of the protocol traffic data packets of each edge Internet of Things device respectively, so as to obtain an edge traffic feature array, determine the traffic overload coefficient of the Internet of Things device protocol based on the edge traffic feature array, and determine the traffic transmission mutation degree of each edge Internet of Things device based on the traffic overload coefficient;

[0092] The anomaly determination module 403 is mainly used in this application to extract the request access information of each edge Internet of Things device from the corresponding protocol traffic data packet, and determine the abnormal access factor of each edge Internet of Things device through the corresponding request access information;

[0093] The transmission early warning module 404 is mainly used in this application to determine the forgery degree of the protocol traffic data packets of each edge Internet of Things device through the corresponding traffic transmission mutation degree and the corresponding abnormal access factor, and perform transmission early warning on each edge Internet of Things device based on the forgery degree of the corresponding protocol traffic data packet.

[0094] The above text has introduced in detail an example of an Internet of Things device protocol analysis system and method based on edge computing provided by the embodiments of the present application. It can be understood that, in order to implement the above functions, the corresponding device includes the corresponding hardware structure and / or software module for executing each function. Those skilled in the art should easily realize that, combining the units and algorithm steps of each example described in the embodiments disclosed herein, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a certain function is executed in the way of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.

[0095] In some embodiments, the present application further provides a computer device, which includes a memory and a processor. The memory is used to store a computer program, and the processor is used to call and run the computer program from the memory, so that the computer device executes the above-mentioned method for analyzing the protocol of Internet of Things devices based on edge computing.

[0096] In some embodiments, referring to Figure 5 , the dotted line in this figure indicates that the unit or module is optional. This figure is a schematic structural diagram of a computer device for the method of analyzing the protocol of Internet of Things devices based on edge computing provided by the embodiments of the present application. The above-mentioned method for analyzing the protocol of Internet of Things devices based on edge computing in the above embodiments can be implemented by Figure 5 the computer device shown. The computer device 500 includes at least one processor 501, a memory 502, and at least one communication unit 505. The computer device 500 can be a terminal device, a server, or a chip.

[0097] The processor 501 can be a general-purpose processor or a special-purpose processor. For example, the processor 501 can be a central processing unit (CPU). The CPU can be used to control the computer device 500, execute software programs, and process the data of software programs. The computer device 500 can also include a communication unit 505 for implementing signal input (reception) and output (transmission).

[0098] For example, the computer device 500 can be a chip, and the communication unit 505 can be the input and / or output circuit of the chip, or the communication unit 505 can be the communication interface of the chip. The chip can be a component of a terminal device, a network device, or other devices.

[0099] For another example, the computer device 500 may be a terminal device or a server, and the communication unit 505 may be a transceiver of the terminal device or the server, or the communication unit 505 may be a transceiver circuit of the terminal device or the server.

[0100] The computer device 500 may include one or more memories 502, on which a program 504 is stored. The program 504 can be run by the processor 501 to generate instructions 503, enabling the processor 501 to execute the methods described in the above method embodiments according to the instructions 503. Optionally, data (such as a target audit model) may also be stored in the memory 502. Optionally, the processor 501 may also read the data stored in the memory 502. This data may be stored at the same storage address as the program 504, or it may be stored at a different storage address from the program 504.

[0101] The processor 501 and the memory 502 may be provided separately or integrated together. For example, they may be integrated on a system on chip (SOC) of the terminal device.

[0102] It should be understood that the steps of the above method embodiments can be completed by a logic circuit in hardware form or instructions in software form in the processor 501. The processor 501 may be a central processing unit, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), or other programmable logic devices. For example, discrete gate, transistor logic devices, or discrete hardware components.

[0103] Those skilled in the art should understand that the embodiments of the present application may be provided as a method, a system, or a computer program product. Therefore, the present application may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program codes.

[0104] For example, in some embodiments, the present application also provides a computer-readable storage medium, in which instructions or codes are stored. When the instructions or codes are run on a computer, the computer is enabled to implement the above-mentioned method for analyzing an Internet of Things device protocol based on edge computing.

[0105] Although the preferred embodiments of the present application have been described, additional changes and modifications can be made to these embodiments by those skilled in the art once they learn of the basic creative concept. Therefore, the appended claims are intended to be construed to include the preferred embodiments as well as all changes and modifications that fall within the scope of the present application.

[0106] Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalent technologies, the present application is also intended to include these modifications and variations.

Claims

1. An Internet of Things device protocol analysis method based on edge computing, characterized in that, The analysis method includes the following steps: Real-time capture of protocol traffic data packets of each edge Internet of Things device; Respectively extract traffic characteristics from the protocol traffic data packets of each edge Internet of Things device, thereby obtaining an edge traffic feature array, determine the traffic overload coefficient of the Internet of Things device protocol based on the edge traffic feature array, and determine the traffic transmission mutation degree of each edge Internet of Things device based on the traffic overload coefficient; Extract the request access information of each edge Internet of Things device from the corresponding protocol traffic data packet, and determine the abnormal access factor of each edge Internet of Things device through the corresponding request access information; Determine the forgery degree of the protocol traffic data packet of each edge Internet of Things device through the corresponding traffic transmission mutation degree and the corresponding abnormal access factor, and perform transmission warning on each edge Internet of Things device based on the forgery degree of the corresponding protocol traffic data packet.

2. The method for analyzing the protocol of an Internet of Things device based on edge computing according to claim 1, wherein Real-time capture of protocol traffic data packets of each edge Internet of Things device through the edge gateway.

3. The method for analyzing the protocol of an Internet of Things device based on edge computing according to claim 1, characterized in that, Respectively extract traffic characteristics from the protocol traffic data packets of each edge Internet of Things device, and the specific steps for obtaining the edge traffic feature array include: Respectively extract traffic characteristics from the protocol traffic data packets of each edge Internet of Things device, thereby obtaining the traffic feature sequence of each edge Internet of Things device; Construct an edge traffic feature array according to all the traffic feature sequences.

4. The protocol analysis method for Internet of Things devices based on edge computing according to claim 1, characterized in that, The specific steps for determining the traffic overload coefficient of the Internet of Things device protocol based on the edge traffic feature array include: Determine the traffic load degree corresponding to the Internet of Things device protocol according to the edge traffic feature array; Extract the traffic level and traffic fluctuation degree corresponding to the Internet of Things device protocol in the edge traffic feature array; Determine the traffic overload coefficient of the Internet of Things device protocol through the traffic load degree, the traffic level and the traffic fluctuation degree.

5. The method for analyzing the protocol of an Internet of Things device based on edge computing according to claim 1, wherein The specific steps for determining the traffic transmission mutation degree of each edge Internet of Things device based on the traffic overload coefficient include: Respectively determine the traffic load fluctuation degree of each edge Internet of Things device according to the corresponding protocol traffic data packet and the preset sliding time window; Determine the traffic transmission mutation degree of each edge Internet of Things device through the traffic overload coefficient and the corresponding traffic load fluctuation degree.

6. The method for analyzing the protocol of an Internet of Things device based on edge computing according to claim 1, wherein The specific steps for determining the abnormal access factor of each edge Internet of Things device through the corresponding request access information include: For each edge Internet of Things device, extract the edge access feature of the edge Internet of Things device from the corresponding request access information; Determine the historical feature level and historical feature dispersion degree of the edge access feature; Determine the abnormal access factor of the edge Internet of Things device through the edge access feature, the historical feature level and the historical feature dispersion degree, thereby obtaining the abnormal access factor of each edge Internet of Things device.

7. A method for analyzing the protocol of an Internet of Things device based on edge computing according to claim 1, characterized in that, The specific steps for performing transmission warning on each edge Internet of Things device based on the forgery degree of the corresponding protocol traffic data packet include: Obtain the preset forgery degree interval; Determine the transmission warning level of each edge Internet of Things device according to the forgery degree of the corresponding protocol traffic data packet and the forgery degree interval; Generate transmission warning information for each edge Internet of Things device according to the corresponding transmission warning level.

8. An Internet of Things device protocol analysis system based on edge computing, which is used to execute an Internet of Things device protocol analysis method according to any one of claims 1 to 7. The Internet of Things device protocol analysis system based on edge computing includes a protocol transmission warning unit, and is characterized in that, The protocol transmission warning unit includes: A capture module, configured to capture protocol traffic data packets of each edge Internet of Things device in real time; A mutation determination module, configured to extract traffic characteristics from the protocol traffic data packets of each edge Internet of Things device respectively, so as to obtain an edge traffic feature array, determine a traffic overload coefficient of the Internet of Things device protocol according to the edge traffic feature array, and determine the traffic transmission mutation degree of each edge Internet of Things device based on the traffic overload coefficient; An anomaly determination module, configured to extract the request access information of each edge Internet of Things device from the corresponding protocol traffic data packet, and determine the abnormal access factor of each edge Internet of Things device through the corresponding request access information; A transmission warning module, configured to determine the forgery degree of the protocol traffic data packets of each edge Internet of Things device through the corresponding traffic transmission mutation degree and the corresponding abnormal access factor, and perform transmission warnings on each edge Internet of Things device respectively based on the forgery degree of the corresponding protocol traffic data packet.

9. A computer device, characterized in that, The computer device includes a memory and a processor. The memory is used to store a computer program, and the processor is used to call and run the computer program from the memory, so that the computer device executes a method for analyzing the protocol of an Internet of Things device based on edge computing according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that, Instructions or codes are stored in the computer-readable storage medium. When the instructions or codes are run on a computer, the computer is caused to execute a method for analyzing the protocol of an Internet of Things device based on edge computing according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Security protection system for cloud side end collaborative interaction of power distribution Internet of Things

    CN119402235A

  • Systems and methods for detecting anomalous behavior in internet-of-things (IOT) devices

    US20240323208A1