Internet of Things environment security detection method and system
By performing malicious access feature extraction and file scheduling information analysis on the access traffic sequence of edge device nodes in the IoT platform, the degree of malicious attack is determined, and the real-time and accuracy of security detection in the IoT environment is solved, and efficient feature extraction and threat assessment of multi-source heterogeneous data is achieved.
Patent Information
- Application Number
- CN202510514721.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-23
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2045-04-23
AI Technical Summary
The huge number of devices and frequent dynamic changes in the network topology in the Internet of Things environment leads to huge challenges in data collection, transmission and real-time analysis, especially when facing unknown threats or new attack methods, traditional feature library-based detection methods seem unscrupulous.
By collecting access traffic sequences from each edge device node in the Internet of Things platform, malicious access feature extraction is performed on each access traffic sequence, malicious access feature vectors are constructed, malicious access factors are determined, and malicious scheduling recognition is determined based on file scheduling information. Finally, malicious attack degree is determined based on these factors and security warning is performed.
It realizes efficient feature extraction of multi-source heterogeneous data and accurate assessment of edge device node threat level, improves the real-time and accuracy of security detection, can effectively identify abnormal behaviors and potential threats of devices, and provides comprehensive security assessment and dynamic management.
Smart Images

Figure CN120074951A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of Internet of Things (IoT) security detection. More specifically, this application relates to a method and system for IoT environment security detection. Background Art
[0002] With the rapid development and wide application of IoT technology, more and more intelligent devices are connected to various IoT platforms, forming a huge and complex IoT ecological environment. The security issues of the IoT environment have gradually become one of the important research directions in the field of cyberspace security. IoT environment security detection mainly refers to the whole process of real-time monitoring, analysis, and early warning of potential security threats and attack behaviors through various technical means for multiple levels such as IoT platforms, edge devices, network communications, and data interactions. The core goal of IoT security detection is to timely discover and identify security events such as malicious devices, abnormal behaviors, illegal intrusions, and data leaks, and ensure the security, stability, and reliability of the IoT system.
[0003] However, in the existing technology, the number of devices in the IoT environment is huge, the network topology structure changes dynamically and frequently, the generated data traffic is huge and heterogeneous, which brings great challenges to data collection, transmission, and real-time analysis. Especially when facing unknown threats or new attack methods, the traditional feature library-based detection methods are insufficient. How to efficiently extract features from the collected multi-source heterogeneous data and accurately evaluate the threat level of edge device nodes to improve the real-time performance and accuracy of security detection is a key problem that urgently needs to be solved in IoT security detection. Summary of the Invention
[0004] This application provides a method and system for IoT environment security detection, which can efficiently extract features from the collected multi-source heterogeneous data and accurately evaluate the threat level of edge device nodes to improve the real-time performance and accuracy of security detection.
[0005] In a first aspect, this application provides a method for IoT environment security detection. The detection method includes the following steps: Collect the access traffic sequences of each edge device node in the IoT platform; Extract malicious access features from each access traffic sequence respectively, and then obtain the malicious access feature vectors of each edge device node. Determine the malicious access factors of each edge device node to the IoT platform based on the corresponding malicious access feature vectors; Obtain the file scheduling information of each edge device node for the Internet of Things platform, determine the malicious scheduling recognition rate of each edge device node through the corresponding file scheduling information, and determine the malicious attack degree of each edge device node on the Internet of Things platform based on the corresponding malicious access factor and the corresponding malicious scheduling recognition rate; Perform security warnings on each edge device node in the Internet of Things platform according to the corresponding malicious attack degree.
[0006] In this embodiment, the access traffic sequences of each edge device node in the Internet of Things platform are collected through the Internet of Things gateway.
[0007] In this embodiment, malicious access feature extraction is respectively performed on each access traffic sequence, and then the malicious access feature vectors of each edge device node are obtained, specifically including: For each edge device node, extract the abnormal behavior features of the access traffic sequence of the edge device node to obtain the traffic abnormal behavior features of the edge device node; Perform time series analysis on the access traffic sequence of the edge device node to obtain the abnormal trend of access change of the edge device node; Perform protocol parsing on the access traffic sequence of the edge device node to obtain the abnormal protocol distribution features of the edge device node; Construct the malicious access feature vector of the edge device node through the traffic abnormal behavior features, the abnormal trend of access change, and the abnormal protocol distribution features, and then obtain the malicious access feature vectors of each edge device node.
[0008] In this embodiment, determine the malicious access factors of each edge device node for the Internet of Things platform according to the corresponding malicious access feature vectors, specifically including: For the edge device node, score each malicious access feature in the malicious access feature vector of the edge device node to obtain the malicious scores of each malicious access feature in the malicious access feature vector; Determine the malicious access factor of the edge device node for the Internet of Things platform according to the malicious scores of all malicious access features, and then obtain the malicious access factors of each edge device node for the Internet of Things platform.
[0009] In this embodiment, obtain the file scheduling information of each edge device node for the Internet of Things platform through the log mechanism of the Internet of Things platform.
[0010] In this embodiment, determine the malicious scheduling recognition rate of each edge device node through the corresponding file scheduling information, specifically including: For each edge device node, extract the set of scheduled file categories of the edge device node from the file scheduling information of the edge device node; Determine a plurality of malicious scheduling coefficients of the edge device nodes according to the set of scheduling file categories; Determine the malicious scheduling recognition degree of the edge device nodes based on all the malicious scheduling coefficients, and then obtain the malicious scheduling recognition degrees of each edge device node.
[0011] In this embodiment, determining the malicious attack degree of each edge device node on the IoT platform based on the corresponding malicious access factor and the corresponding malicious scheduling recognition degree specifically includes: For each edge device node, perform a weighted sum of the malicious access factor and the malicious scheduling recognition degree of the edge device node to obtain the malicious attack degree of the edge device node on the IoT platform, and then obtain the malicious attack degrees of each edge device node on the IoT platform.
[0012] In this embodiment, the malicious attack degree represents the possible degree of malicious attack when the edge device node accesses the IoT platform.
[0013] In this embodiment, performing security warnings on each edge device node in the IoT platform according to the corresponding malicious attack degree specifically includes: Determine the malicious attack degree levels of each edge device node based on a preset malicious attack degree level table and the corresponding malicious attack degree; Determine the security warning strategies of each edge device node in the IoT platform according to the corresponding malicious attack degree levels.
[0014] In a second aspect, the present application provides an IoT environment security detection system for executing an IoT environment security detection method. The detection system includes: A traffic collection module for collecting the access traffic sequences of each edge device node in the IoT platform; A malicious access determination module for respectively extracting malicious access features from each access traffic sequence, and then obtaining the malicious access feature vectors of each edge device node, and determining the malicious access factors of each edge device node on the IoT platform based on the corresponding malicious access feature vectors; A malicious attack determination module for obtaining the file scheduling information of each edge device node on the IoT platform, determining the malicious scheduling recognition degrees of each edge device node through the corresponding file scheduling information, and determining the malicious attack degrees of each edge device node on the IoT platform based on the corresponding malicious access factors and the corresponding malicious scheduling recognition degrees; A security warning module for performing security warnings on each edge device node in the IoT platform according to the corresponding malicious attack degree.
[0015] The technical solutions provided by the disclosed embodiments of the present application have the following beneficial effects: By collecting the access traffic sequences of each edge device node in the Internet of Things platform; extracting malicious access features from each access traffic sequence respectively, and then obtaining the malicious access feature vectors of each edge device node, determining the malicious access factors of each edge device node to the Internet of Things platform according to the corresponding malicious access feature vectors; obtaining the file scheduling information of each edge device node to the Internet of Things platform, determining the malicious scheduling recognition degree of each edge device node through the corresponding file scheduling information, and determining the malicious attack degree of each edge device node to the Internet of Things platform based on the corresponding malicious access factor and the corresponding malicious scheduling recognition degree; performing security warnings on each edge device node in the Internet of Things platform according to the corresponding malicious attack degree.
[0016] It can be seen that in this application, first, by extracting malicious access features from each access traffic sequence respectively, and then obtaining the malicious access feature vectors of each edge device node, and determining the malicious access factors of the device to the Internet of Things platform based on these feature vectors, it can effectively identify the abnormal behaviors and potential threats of the device, comprehensively analyze multi-dimensional features such as the access patterns, behavior changes, and protocol usage of the edge device nodes, and then accurately evaluate the security risks of each edge device node; then, by obtaining the file scheduling information of each edge device node, and combining the malicious access factor and the malicious scheduling recognition degree to determine the malicious attack degree of the edge device node, it can comprehensively consider the access behavior and file scheduling behavior of the edge device node, provide a comprehensive security assessment, and accurately identify the abnormal behaviors of the edge device node; finally, by evaluating the malicious attack degree of each edge device node and combining the corresponding security warning strategy, the Internet of Things platform can achieve dynamic and secure management, can discover potential threats in real time, so as to improve the real-time performance and accuracy of security detection.
[0017] In summary, the technical solution adopted in this application can efficiently extract features from the collected multi-source heterogeneous data, and accurately evaluate the threat levels of edge device nodes, so as to improve the real-time performance and accuracy of security detection. Brief Description of the Drawings
[0018] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0019] Figure 1 is a flowchart of an Internet of Things environment security detection method provided by the present application; Figure 2It is a schematic flow chart for determining the malicious access factor of each edge device node to the Internet of Things platform provided by this application; Figure 3 It is a schematic flow chart for determining the malicious scheduling recognition of each edge device node provided by this application; Figure 4 It is a module structure diagram of an Internet of Things environment security detection system provided by this application. Specific implementation mode
[0020] Next, the technical solutions in the embodiments of this application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all the embodiments. Based on the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of this application.
[0021] The embodiments of this application provide an Internet of Things environment security detection method and system. The core is to collect the access traffic sequences of each edge device node in the Internet of Things platform; respectively extract malicious access features from each access traffic sequence, and then obtain the malicious access feature vectors of each edge device node. According to the corresponding malicious access feature vectors, determine the malicious access factors of each edge device node to the Internet of Things platform; obtain the file scheduling information of each edge device node to the Internet of Things platform, determine the malicious scheduling recognition of each edge device node through the corresponding file scheduling information, and determine the malicious attack degree of each edge device node to the Internet of Things platform based on the corresponding malicious access factor and the corresponding malicious scheduling recognition; perform security warnings on each edge device node in the Internet of Things platform according to the corresponding malicious attack degree. By adopting the above solution, efficient feature extraction can be performed on the collected multi-source heterogeneous data, and the threat level of edge device nodes can be accurately evaluated to improve the real-time performance and accuracy of security detection.
[0022] Embodiment 1. To better understand the above technical solution, the above technical solution will be described in detail below in conjunction with the specification drawings and specific implementation manners. Refer to Figure 1 As shown, this figure is an exemplary flow chart of an Internet of Things environment security detection method shown in this embodiment of this application. The detection method includes the following steps: In step S1, collect the access traffic sequences of each edge device node in the Internet of Things platform.
[0023] In specific implementation, the access traffic sequences of each edge device node in the Internet of Things platform can be collected through the Internet of Things gateway; it should be noted that the Internet of Things gateway, as a bridge between the Internet of Things platform and the edge device nodes, bears data transmission and control. The access traffic sequence refers to information such as communication data packets, request responses, control commands, and file transfers between the edge device nodes and the Internet of Things platform. In actual implementation, the traffic monitoring function of the Internet of Things gateway can be used to collect the access traffic sequences of each edge device node in the Internet of Things platform in real time.
[0024] In step S2, malicious access feature extraction is performed on each access traffic sequence respectively, and then the malicious access feature vectors of each edge device node are obtained. According to the corresponding malicious access feature vectors, the malicious access factors of each edge device node to the Internet of Things platform are determined respectively.
[0025] In this embodiment, malicious access feature extraction is performed on each access traffic sequence respectively, and then the malicious access feature vectors of each edge device node can be obtained specifically by the following method, that is: For each edge device node, abnormal behavior feature extraction is performed on the access traffic sequence of the edge device node to obtain the traffic abnormal behavior features of the edge device node; Time series analysis is performed on the access traffic sequence of the edge device node to obtain the abnormal trend of access change of the edge device node; Protocol parsing is performed on the access traffic sequence of the edge device node to obtain the abnormal protocol distribution features of the edge device node; The malicious access feature vector of the edge device node is constructed through the traffic abnormal behavior features, the abnormal trend of access change, and the abnormal protocol distribution features, and then the malicious access feature vectors of each edge device node are obtained.
[0026] In specific implementation, for each edge device node, first, an anomaly detection algorithm (such as Isolation Forest, k-means clustering, etc.) can be used to extract the abnormal behavior features of the access traffic sequence of the edge device node, so as to obtain the traffic abnormal behavior features of the edge device node. Among them, the extraction of abnormal behavior features represents the abnormal patterns in the access traffic of the edge device node, such as overly frequent requests, abnormal communication patterns, etc. The abnormal behavior features can reflect whether the edge device node participates in malicious activities, such as brute force cracking, DDoS attacks, etc.; then, a time series analysis algorithm (such as ARIMA, LSTM neural network, etc.) can be used to perform time series analysis on the access traffic sequence of the edge device node, so as to obtain the abnormal trend of access change of the edge device node. Among them, the abnormal trend of access change represents the abnormal trend of the access traffic of the edge device node changing over time. The abnormal trend of access change is very important for detecting whether there is continuous abnormal behavior (such as continuous large-scale data transmission or requests) in the edge device node.
[0027] In addition, in specific implementation, the deep packet inspection (DPI) technology can be used to parse the protocol of the access traffic sequence of the edge device node. Through the deep packet inspection (DPI) technology, the protocol data in the access traffic sequence can be parsed, the protocol type and its content of each traffic packet can be identified, so as to obtain the abnormal feature of protocol distribution of the edge device node. Among them, the abnormal feature of protocol distribution represents the abnormal protocol hierarchy structure in the requests of the edge device node (for example, whether there are illegal HTTP methods or unauthorized commands in the HTTP request); finally, the malicious access feature vector of the edge device node can be constructed through the traffic abnormal behavior feature, the abnormal trend of access change and the abnormal feature of protocol distribution, that is, the traffic abnormal behavior feature, the abnormal trend of access change and the abnormal feature of protocol distribution are used as malicious access features, so that the vector composed of all malicious access features is used as the malicious access feature vector of the edge device node. Through the above method, the malicious access feature vectors of each edge device node can be obtained.
[0028] Preferably, in this embodiment, the malicious access factors of each edge device node to the IoT platform are determined according to the corresponding malicious access feature vectors. Refer to Figure 2 As shown, this figure is a schematic flowchart of determining the malicious access factors of each edge device node to the IoT platform in some embodiments of the present application. The malicious access factors of each edge device node to the IoT platform in this embodiment can be implemented by the following steps: In step S21, for the edge device node, each malicious access feature in the malicious access feature vector of the edge device node is scored, and then the malicious scores of each malicious access feature in the malicious access feature vector are obtained; In step S22, the malicious access factor of the edge device node to the IoT platform is determined according to the malicious scores of all malicious access features, and then the malicious access factors of each edge device node to the IoT platform are obtained.
[0029] Specifically, first, for the edge device node, each malicious access feature in the malicious access feature vector of the edge device node can be scored. The supervised learning algorithm (such as random forest, SVM, etc.) can be used to model each malicious access feature, that is, the historical access data of the edge device node with labels is collected from the IoT platform. The historical access data contains normal behavior samples and malicious behavior samples. The supervised learning model is trained through this historical access data, and the classification probability output of the supervised learning model is used to judge the tendency of the malicious access feature to cause the supervised learning model to predict "malicious", that is, the classification probability output by the supervised learning model can be used as the malicious score of the malicious access feature, so as to calculate the malicious scores of each malicious access feature in the malicious access feature vector. Among them, the malicious score represents the abnormal degree of the edge device node in the corresponding feature dimension; then, the malicious access factor of the edge device node to the IoT platform can be determined according to the malicious scores of all malicious access features. Among them, the malicious access factor represents the malicious degree when the edge device node accesses the IoT platform. In actual implementation, the standard deviation of the malicious scores of all malicious access features can be used as the malicious access factor of the edge device node to the IoT platform. Through the above method, the malicious access factors of each edge device node to the IoT platform can be obtained.
[0030] It should be noted that by extracting malicious access features from each access traffic sequence respectively, and then obtaining the malicious access feature vectors of each edge device node, and determining the malicious access factor of the device to the IoT platform based on these feature vectors, the abnormal behavior and potential threats of the device can be effectively identified, and the multi-dimensional features such as the access pattern, behavior change, and protocol usage of the edge device node can be comprehensively analyzed, and then the security risk of each device can be accurately evaluated. For the multi-source heterogeneous data collected, efficient feature extraction can integrate information from different sources, improve the ability to identify complex threats, and at the same time improve the real-time performance and accuracy of the detection process.
[0031] In step S3, the file scheduling information of each edge device node to the IoT platform is obtained, the malicious scheduling recognition degree of each edge device node is determined through the corresponding file scheduling information, and the malicious attack degree of each edge device node to the IoT platform is determined based on the corresponding malicious access factor and the corresponding malicious scheduling recognition degree.
[0032] In specific implementation, the file scheduling information of each edge device node for the Internet of Things platform can be obtained through the log mechanism of the Internet of Things platform. It should be noted that the Internet of Things platform should enable the log recording function, especially for detailed recording of events related to file scheduling, so that the file scheduling information of each edge device node for the Internet of Things platform can be obtained. Among them, the file scheduling information includes data such as edge device node identification information, file category and file name, requested operation type, time stamp of file request, file size and transmission volume, source and destination of the request, etc.
[0033] Preferably, in this embodiment, the malicious scheduling recognition rate of each edge device node is determined based on the corresponding file scheduling information. Refer to Figure 3 As shown, this figure is a schematic flowchart of determining the malicious scheduling recognition rate of each edge device node in some embodiments of the present application. The malicious scheduling recognition rate of each edge device node in this embodiment can be implemented by the following steps: In step S31, for each edge device node, extract the set of scheduled file categories of the edge device node from the file scheduling information of the edge device node; In step S32, determine multiple malicious scheduling coefficients of the edge device node according to the set of scheduled file categories; In step S33, determine the malicious scheduling recognition rate of the edge device node based on all the malicious scheduling coefficients, and then obtain the malicious scheduling recognition rate of each edge device node.
[0034] In specific implementation, first, for each edge device node, a set of scheduled file categories of the edge device node can be extracted from the file scheduling information of the edge device node. Among them, the set of scheduled file categories represents a set of file categories requested by the edge device node, and the file categories can include configuration files, firmware files, log files, sensitive data files, etc.; then, a plurality of malicious scheduling coefficients of the edge device node can be determined according to the set of scheduled file categories. The malicious scheduling coefficient represents the degree of abnormality of the behavior of the edge device node requesting the corresponding type of scheduled file. That is, for each type of scheduled file in the set of scheduled file categories, the total number of requests for this type of scheduled file by the edge device node can be counted, and the ratio of the total number of requests to the total number of this type of scheduled file in the IoT platform can be calculated. The product of the calculation result and the request frequency of the edge device node for this type of scheduled file is used as the malicious scheduling coefficient of the edge device node under this type of scheduled file. Through the above method, a plurality of malicious scheduling coefficients of the edge device node can be obtained; finally, the malicious scheduling recognition degree of the edge device node can be determined based on all the malicious scheduling coefficients. The malicious scheduling recognition degree represents the degree of malice of the scheduling behavior of the edge device node for the files in the IoT platform. The variance of all the malicious scheduling coefficients can be used as the malicious scheduling recognition degree of the edge device node. Through the above method, the malicious scheduling recognition degrees of each edge device node can be obtained.
[0035] In this embodiment, to determine the malicious attack degree of each edge device node on the IoT platform based on the corresponding malicious access factor and the corresponding malicious scheduling recognition degree, the following method can be specifically adopted, that is: For each edge device node, the malicious access factor and the malicious scheduling recognition degree of the edge device node are weighted and summed to obtain the malicious attack degree of the edge device node on the IoT platform, and then the malicious attack degrees of each edge device node on the IoT platform are obtained.
[0036] In specific implementation, first, the corresponding weights of the malicious access factor and the malicious scheduling recognition degree can be set respectively according to historical experience and data analysis; then, the malicious access factor and the malicious scheduling recognition degree of the edge device node are weighted and summed, and the dimension of the weighted sum result is eliminated, so that the final result can be used as the malicious attack degree of the edge device node on the IoT platform. Through the above method, the malicious attack degrees of each edge device node on the IoT platform can be obtained; it should be noted that in this application, the malicious attack degree represents the possible degree of malicious attack when the edge device node accesses the IoT platform.
[0037] It should be noted that by obtaining the file scheduling information of each edge device node and combining the malicious access factor and the malicious scheduling recognition rate to determine the malicious attack degree of the edge device node, it is possible to comprehensively consider the access behavior and file scheduling behavior of the edge device node, provide a comprehensive security assessment, and accurately identify the abnormal behavior of the edge device node.
[0038] In step S4, security warnings are issued for each edge device node in the Internet of Things platform according to the corresponding malicious attack degree.
[0039] In this embodiment, the security warning for each edge device node in the Internet of Things platform according to the corresponding malicious attack degree can be specifically implemented in the following manner, that is: Determine the malicious attack degree level of each edge device node based on the preset malicious attack degree level table and the corresponding malicious attack degree; Determine the security warning strategy for each edge device node in the Internet of Things platform according to the corresponding malicious attack degree level.
[0040] When specifically implemented, first, a malicious attack degree level table can be set based on expert knowledge and experience, and the level of the malicious attack degree of the edge device node can be quantified through this malicious attack degree level table. The malicious attack degree level table includes a low-risk level (the malicious attack degree value is relatively low, usually lower than 0.3. At this time, the behavior of the edge device node does not show obvious malice or abnormality and may be normal operation), a medium-risk level (the malicious attack degree value is between 0.3 and 0.7, and the behavior of the edge device node shows some abnormal patterns, which may indicate potential threats), and a high-risk level (the malicious attack degree value is greater than or equal to 0.7, and the behavior of the edge device node shows serious malicious or abnormal behavior, which may be that an attacker attempts to invade or abuse the device); then, the malicious attack degree level of each edge device node can be determined based on the preset malicious attack degree level table and the corresponding malicious attack degree, that is, map the malicious attack degree of each edge device node to the preset malicious attack degree level table, so that the malicious attack degree level of each edge device node can be obtained. For example, if the malicious attack degree of an edge device node is 0.2, the malicious attack degree level of this edge device node is low risk; if the malicious attack degree of an edge device node is 0.5, the malicious attack degree level of this edge device node is medium risk; if the malicious attack degree of an edge device node is 0.8, the malicious attack degree level of this edge device node is high risk.
[0041] In addition, during specific implementation, the security warning strategies for each edge device node in the IoT platform can be determined according to the corresponding malicious attack degree level. That is, once the malicious attack degree level of each device is determined, the system can formulate corresponding security warning strategies based on the malicious attack degree level of each edge device node. These strategies aim to take different levels of security protection measures according to the malicious attack degree level of the edge device node. For example: If the malicious attack degree level of the edge device node is low risk, there is no need to specifically process the edge device node, maintain regular monitoring, and continuously monitor whether the behavior of the edge device node changes, keep log records to ensure that if the malicious behavior of the device changes, it can be captured in a timely manner. Immediate warning is not required, but its behavior and access logs can be reviewed regularly.
[0042] If the malicious attack degree level of the edge device node is medium risk, strengthen the monitoring of the edge device node, analyze its access behavior and communication mode. If further abnormal behavior is detected, an alarm can be automatically triggered and the device can be temporarily restricted or isolated, and medium-frequency warnings and reports are set to ensure timely response when the behavior of the edge device node changes.
[0043] If the malicious attack degree level of the edge device node is high risk, immediately isolate the edge device node and trigger a high-level security response, including but not limited to disconnecting the connection to the network, conducting a more rigorous audit of it, immediately revoking the access rights to the device, or further manual intervention, and set high-frequency real-time alarms to ensure that the system administrator can quickly understand and handle the security threats of the edge device node.
[0044] It should be noted that by evaluating the malicious attack degree of each edge device node and combining the corresponding security warning strategies, the IoT platform can achieve dynamic and secure management. It can not only detect potential threats in real time, improve the real-time performance and accuracy of security detection, but also provide corresponding protection measures according to the security level of the device to ensure the most effective allocation of resources and security measures.
[0045] It can be seen that in this application, first, by separately extracting malicious access features from each access traffic sequence, malicious access feature vectors of each edge device node are obtained, and based on these feature vectors, malicious access factors of the device to the IoT platform are determined, which can effectively identify abnormal behaviors and potential threats of the device, comprehensively analyze multi-dimensional features such as access patterns, behavior changes, and protocol usage of edge device nodes, and then accurately evaluate the security risks of each edge device node; then, by obtaining the file scheduling information of each edge device node and combining the malicious access factor with the malicious scheduling recognition degree to determine the malicious attack degree of the edge device node, the access behavior and file scheduling behavior of the edge device node can be comprehensively considered, a comprehensive security assessment can be provided, and abnormal behaviors of the edge device node can be accurately identified; finally, by evaluating the malicious attack degree of each edge device node and combining the corresponding security warning strategy, the IoT platform can achieve dynamic and secure management, potential threats can be discovered in real time, and the real-time performance and accuracy of security detection can be improved.
[0046] In summary, the technical solution adopted in this application can efficiently extract features from the collected multi-source heterogeneous data and accurately evaluate the threat levels of edge device nodes to improve the real-time performance and accuracy of security detection.
[0047] Embodiment 2. This application provides an IoT environment security detection system. Refer to Figure 4 As shown in the figure, which is a schematic diagram of the IoT environment security detection system according to this embodiment of this application, the detection system includes: A traffic collection module 100, configured to collect access traffic sequences of each edge device node in the IoT platform; A malicious access determination module 200, configured to separately extract malicious access features from each access traffic sequence, thereby obtaining malicious access feature vectors of each edge device node, and respectively determining malicious access factors of each edge device node to the IoT platform based on the corresponding malicious access feature vectors; A malicious attack determination module 300, configured to obtain file scheduling information of each edge device node to the IoT platform, determine the malicious scheduling recognition degree of each edge device node through the corresponding file scheduling information, and determine the malicious attack degree of each edge device node to the IoT platform based on the corresponding malicious access factor and the corresponding malicious scheduling recognition degree; A security warning module 400, configured to perform security warnings on each edge device node in the IoT platform according to the corresponding malicious attack degree.
[0048] This application is described with reference to the flowcharts and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the present application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams can be implemented by computer program instructions, and the combination of flows and / or blocks in the flowcharts and / or block diagrams can also be implemented. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate a means for implementing the functions specified in one Figure 1 flow or multiple flows and / or blocks Figure 1 or a means for implementing the functions specified in multiple blocks.
[0049] Those of ordinary skill in the art can understand that all or part of the steps in the various methods of the above embodiments can be completed by instructing relevant hardware through a program. This program can be stored in a computer-readable storage medium, and the storage medium includes read-only memory (ROM), random access memory (RAM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), one-time programmable read-only memory (OTPROM), electrically-erasable programmable read-only memory (EEPROM), compact disc read-only memory (CD-ROM), or other optical disc memories, magnetic disc memories, tape memories, or any other medium that can be used to carry or store data and is computer-readable.
[0050] It should also be noted that the term "comprising", "including", or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, commodity, or device comprising a series of elements not only includes those elements, but also includes other elements not explicitly listed, or further includes elements inherent to such a process, method, commodity, or device. Without further limitations, an element defined by the statement "comprising one..." does not exclude the existence of another identical element in the process, method, commodity, or device comprising the element.
Claims
1. A method for detecting environmental security of the Internet of Things, characterized in that: The detection method comprises the following steps: Collect the access traffic sequence of each edge device node in the IoT platform; Malicious access features are extracted for each access traffic sequence, and then malicious access feature vectors of each edge device node are obtained. The malicious access factor of each edge device node to the IoT platform is determined based on the corresponding malicious access feature vectors. Obtain file scheduling information of each edge device node to the Internet of Things platform, determine the malicious scheduling recognition degree of each edge device node through the corresponding file scheduling information, and determine the malicious attack degree of each edge device node to the Internet of Things platform based on the corresponding malicious access factor and the corresponding malicious scheduling recognition degree; Provide security warnings for each edge device node in the IoT platform based on the corresponding malicious attack degree.
2. The method for detecting environmental safety of the Internet of Things according to claim 1, characterized in that: The access traffic sequence of each edge device node in the IoT platform is collected through the IoT gateway.
3. The method for detecting environmental safety of the Internet of Things according to claim 1, characterized in that: Malicious access features are extracted for each access traffic sequence, and the malicious access feature vectors of each edge device node are obtained, including: For each edge device node, extract abnormal behavior features of the access traffic sequence of the edge device node to obtain the traffic abnormal behavior features of the edge device node; Performing time series analysis on the access traffic sequence of the edge device node to obtain an abnormal access change trend of the edge device node; Performing protocol parsing on the access traffic sequence of the edge device node to obtain protocol distribution anomaly characteristics of the edge device node; The malicious access feature vector of the edge device node is constructed by using the abnormal traffic behavior characteristics, the abnormal access change trend and the abnormal protocol distribution characteristics, and then the malicious access feature vector of each edge device node is obtained.
4. The method for detecting environmental safety of the Internet of Things according to claim 1, characterized in that: According to the corresponding malicious access feature vector, the malicious access factors of each edge device node to the IoT platform are determined separately, including: For the edge device node, scoring each malicious access feature in the malicious access feature vector of the edge device node, and then obtaining a malicious score of each malicious access feature in the malicious access feature vector; The malicious access factor of the edge device node to the Internet of Things platform is determined according to the malicious scores of all malicious access features, and then the malicious access factor of each edge device node to the Internet of Things platform is obtained.
5. The method for detecting environmental safety of the Internet of Things according to claim 1, characterized in that: The file scheduling information of each edge device node on the IoT platform is obtained through the log mechanism of the IoT platform.
6. The method for detecting environmental safety of the Internet of Things according to claim 1, characterized in that: The malicious scheduling recognition of each edge device node is determined by the corresponding file scheduling information, including: For each edge device node, extracting a scheduling file category set of the edge device node from the file scheduling information of the edge device node; Determining a plurality of malicious scheduling coefficients of the edge device node according to the scheduling file category set; The malicious scheduling recognition degree of the edge device node is determined according to all malicious scheduling coefficients, and then the malicious scheduling recognition degree of each edge device node is obtained.
7. The method for detecting environmental safety of the Internet of Things according to claim 1, characterized in that: The malicious attack degree of each edge device node on the IoT platform is determined based on the corresponding malicious access factor and the corresponding malicious scheduling recognition degree, including: For each edge device node, a weighted sum is performed on the malicious access factor and malicious scheduling recognition degree of the edge device node to obtain the malicious attack degree of the edge device node on the Internet of Things platform, and then the malicious attack degree of each edge device node on the Internet of Things platform is obtained.
8. The method for detecting environmental safety of the Internet of Things according to claim 1, characterized in that: The malicious attack degree indicates the possibility of an edge device node conducting a malicious attack when accessing the Internet of Things platform.
9. The method for detecting environmental safety of the Internet of Things according to claim 1, characterized in that: According to the corresponding malicious attack degree, the security warning of each edge device node in the IoT platform includes: Determine the malicious attack degree level of each edge device node based on a preset malicious attack degree level table and the corresponding malicious attack degree; Determine the security warning strategy for each edge device node in the IoT platform according to the corresponding malicious attack level.
10. An Internet of Things environment security detection system, used to execute an Internet of Things environment security detection method as claimed in any one of claims 1 to 9, characterized in that: The detection system comprises: Traffic collection module, used to collect access traffic sequences of each edge device node in the IoT platform; A malicious access determination module is used to extract malicious access features from each access traffic sequence, thereby obtaining malicious access feature vectors of each edge device node, and determining malicious access factors of each edge device node to the IoT platform based on the corresponding malicious access feature vectors; A malicious attack determination module is used to obtain file scheduling information of each edge device node to the Internet of Things platform, determine the malicious scheduling recognition degree of each edge device node through the corresponding file scheduling information, and determine the malicious attack degree of each edge device node to the Internet of Things platform based on the corresponding malicious access factor and the corresponding malicious scheduling recognition degree; The security warning module is used to issue security warnings to each edge device node in the Internet of Things platform according to the corresponding malicious attack degree.
Citation Information
Patent Citations
Flow detection method and device
CN113489709A
Abnormal equipment identification method and device, computer equipment and storage medium
CN113920398A
Network event security monitoring method and system
CN118200019A
Method and system for intelligent and scalable misbehavior detection of heterogeneous IoT devices at network edge
WO2022221389A1