An Internet of Things environment security detection method and system

By collecting access traffic sequences and file scheduling information in the Internet of Things platform, building malicious access feature vectors and scheduling recognition, the feature extraction and threat assessment problems of multi-source heterogeneous data in the Internet of Things environment are solved, and efficient security detection and dynamic management are achieved.

CN120074951BActive Publication Date: 2025-07-18GUIZHOU BUSINESS SCHOOL
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510514721.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-23
Publication Date
2025-07-18
Estimated Expiration
2045-04-23

AI Technical Summary

Technical Problem

The prior art is difficult to efficiently perform feature extraction of multi-source heterogeneous data and threat assessment of edge device nodes in the Internet of Things environment, resulting in insufficient real-time and accuracy of security detection.

Method used

By collecting access traffic sequences from the IoT platform, malicious access feature extraction and file scheduling information analysis, malicious access feature vectors and malicious scheduling recognition, combined with weighted sum, determine malicious attack degree, and achieve security warning.

Benefits of technology

It improves the real-time and accuracy of security detection in the Internet of Things environment, can effectively identify abnormal behaviors and potential threats of equipment, and provides comprehensive security assessment and dynamic management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120074951B_ABST
    Figure CN120074951B_ABST
Patent Text Reader

Abstract

The present application provides an Internet of Things environment security detection method and system, which relates to the technical field of Internet of Things security detection. It collects the access traffic sequences of each edge device node in the Internet of Things platform; extracts malicious access features from each access traffic sequence to obtain multiple malicious access feature vectors, and determines multiple malicious access factors based on the corresponding malicious access feature vectors; obtains the file scheduling information of each edge device node for the Internet of Things platform, determines the malicious scheduling recognition degree through the corresponding file scheduling information, and determines the malicious attack degree of each edge device node for the Internet of Things platform based on the malicious access factors and the malicious scheduling recognition degree; performs security warnings on each edge device node in the Internet of Things platform according to the corresponding malicious attack degree. The present application can perform efficient feature extraction on the collected multi-source heterogeneous data and accurately evaluate the threat level of edge device nodes, so as to improve the real-time performance and accuracy of security detection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of Internet of Things security detection. More specifically, this application relates to an Internet of Things environment security detection method and system. Background Art

[0002] With the rapid development and wide application of Internet of Things technology, more and more intelligent devices are connected to various Internet of Things platforms, forming a huge and complex Internet of Things ecological environment. The security issues of the Internet of Things environment have gradually become one of the important research directions in the field of cyberspace security. Internet of Things environment security detection mainly refers to the whole process of real-time monitoring, analysis, and early warning of potential security threats and attack behaviors through various technical means for multiple levels such as Internet of Things platforms, edge devices, network communications, and data interactions. The core goal of Internet of Things security detection is to timely discover and identify security events such as malicious devices, abnormal behaviors, illegal intrusions, and data leaks, and ensure the security, stability, and reliability of the Internet of Things system.

[0003] However, in the prior art, the number of devices in the Internet of Things environment is huge, the network topology structure changes dynamically and frequently, the generated data traffic is huge and heterogeneous, which brings great challenges to data collection, transmission, and real-time analysis. Especially when facing unknown threats or new attack methods, the traditional feature library-based detection methods are insufficient. How to efficiently extract features from the collected multi-source heterogeneous data and accurately evaluate the threat level of edge device nodes to improve the real-time performance and accuracy of security detection is a key problem that urgently needs to be solved in Internet of Things security detection. Summary of the Invention

[0004] This application provides an Internet of Things environment security detection method and system, which can efficiently extract features from the collected multi-source heterogeneous data and accurately evaluate the threat level of edge device nodes to improve the real-time performance and accuracy of security detection.

[0005] In a first aspect, this application provides an Internet of Things environment security detection method, and the detection method includes the following steps:

[0006] Collect the access traffic sequences of each edge device node in the Internet of Things platform;

[0007] Respectively extract malicious access features from each access traffic sequence, and then obtain the malicious access feature vectors of each edge device node, and respectively determine the malicious access factors of each edge device node to the Internet of Things platform according to the corresponding malicious access feature vectors;

[0008] Obtain the file scheduling information of each edge device node for the Internet of Things platform, determine the malicious scheduling recognition rate of each edge device node through the corresponding file scheduling information, and determine the malicious attack degree of each edge device node on the Internet of Things platform based on the corresponding malicious access factor and the corresponding malicious scheduling recognition rate;

[0009] Conduct security warnings for each edge device node in the Internet of Things platform according to the corresponding malicious attack degree.

[0010] In this embodiment, collect the access traffic sequences of each edge device node in the Internet of Things platform through the Internet of Things gateway.

[0011] In this embodiment, extract malicious access features from each access traffic sequence respectively, and then obtain the malicious access feature vectors of each edge device node, which specifically include:

[0012] For each edge device node, extract abnormal behavior features from the access traffic sequence of the edge device node to obtain the traffic abnormal behavior features of the edge device node;

[0013] Conduct time series analysis on the access traffic sequence of the edge device node to obtain the abnormal trend of access change of the edge device node;

[0014] Conduct protocol parsing on the access traffic sequence of the edge device node to obtain the abnormal protocol distribution features of the edge device node;

[0015] Construct the malicious access feature vector of the edge device node through the traffic abnormal behavior features, the abnormal trend of access change, and the abnormal protocol distribution features, and then obtain the malicious access feature vectors of each edge device node.

[0016] In this embodiment, determine the malicious access factors of each edge device node for the Internet of Things platform based on the corresponding malicious access feature vectors respectively, which specifically include:

[0017] For an edge device node, score each malicious access feature in the malicious access feature vector of the edge device node to obtain the malicious scores of each malicious access feature in the malicious access feature vector;

[0018] Determine the malicious access factor of the edge device node for the Internet of Things platform according to the malicious scores of all malicious access features, and then obtain the malicious access factors of each edge device node for the Internet of Things platform.

[0019] In this embodiment, obtain the file scheduling information of each edge device node for the Internet of Things platform through the log mechanism of the Internet of Things platform.

[0020] In this embodiment, determining the malicious scheduling recognition degree of each edge device node according to the corresponding file scheduling information specifically includes:

[0021] For each edge device node, extract the scheduling file category set of the edge device node from the file scheduling information of the edge device node;

[0022] Determine multiple malicious scheduling coefficients of the edge device node according to the scheduling file category set;

[0023] Determine the malicious scheduling recognition degree of the edge device node based on all the malicious scheduling coefficients, and then obtain the malicious scheduling recognition degrees of each edge device node.

[0024] In this embodiment, determining the malicious attack degree of each edge device node on the IoT platform based on the corresponding malicious access factor and the corresponding malicious scheduling recognition degree specifically includes:

[0025] For each edge device node, perform weighted summation on the malicious access factor and the malicious scheduling recognition degree of the edge device node to obtain the malicious attack degree of the edge device node on the IoT platform, and then obtain the malicious attack degrees of each edge device node on the IoT platform.

[0026] In this embodiment, the malicious attack degree represents the possible degree of malicious attack when the edge device node accesses the IoT platform.

[0027] In this embodiment, performing security warning on each edge device node in the IoT platform according to the corresponding malicious attack degree specifically includes:

[0028] Determine the malicious attack degree level of each edge device node based on the preset malicious attack degree level table and the corresponding malicious attack degree;

[0029] Determine the security warning strategy of each edge device node in the IoT platform according to the corresponding malicious attack degree level.

[0030] In a second aspect, the present application provides an IoT environment security detection system for executing an IoT environment security detection method. The detection system includes:

[0031] A traffic collection module for collecting the access traffic sequences of each edge device node in the IoT platform;

[0032] A malicious access determination module for respectively extracting malicious access features from each access traffic sequence, and then obtaining the malicious access feature vectors of each edge device node, and determining the malicious access factors of each edge device node on the IoT platform according to the corresponding malicious access feature vectors;

[0033] A malicious attack determination module, configured to obtain the file scheduling information of each edge device node for the Internet of Things platform, determine the malicious scheduling recognition degree of each edge device node through the corresponding file scheduling information, and determine the malicious attack degree of each edge device node on the Internet of Things platform based on the corresponding malicious access factor and the corresponding malicious scheduling recognition degree;

[0034] A security warning module, configured to perform security warnings on each edge device node in the Internet of Things platform according to the corresponding malicious attack degree.

[0035] The technical solutions provided by the embodiments disclosed in this application have the following beneficial effects:

[0036] By collecting the access traffic sequences of each edge device node in the Internet of Things platform; respectively extracting malicious access features from each access traffic sequence, and then obtaining the malicious access feature vectors of each edge device node, and determining the malicious access factors of each edge device node for the Internet of Things platform based on the corresponding malicious access feature vectors; obtaining the file scheduling information of each edge device node for the Internet of Things platform, determining the malicious scheduling recognition degree of each edge device node through the corresponding file scheduling information, and determining the malicious attack degree of each edge device node on the Internet of Things platform based on the corresponding malicious access factor and the corresponding malicious scheduling recognition degree; performing security warnings on each edge device node in the Internet of Things platform according to the corresponding malicious attack degree.

[0037] Thus, it can be seen that in this application, firstly, by respectively extracting malicious access features from each access traffic sequence, and then obtaining the malicious access feature vectors of each edge device node, and determining the malicious access factors of the device for the Internet of Things platform based on these feature vectors, it can effectively identify the abnormal behaviors and potential threats of the device, and can comprehensively analyze multi-dimensional features such as the access patterns, behavior changes, and protocol usage of the edge device nodes, and then accurately evaluate the security risks of each edge device node; secondly, by obtaining the file scheduling information of each edge device node, and combining the malicious access factor and the malicious scheduling recognition degree to determine the malicious attack degree of the edge device node, it can comprehensively consider the access behavior and file scheduling behavior of the edge device node, provide a comprehensive security assessment, and can accurately identify the abnormal behaviors of the edge device node; finally, by evaluating the malicious attack degree of each edge device node and combining the corresponding security warning strategy, the Internet of Things platform can achieve dynamic and secure management, can discover potential threats in real time, so as to improve the real-time performance and accuracy of security detection.

[0038] In summary, the technical solution adopted in this application can efficiently extract features from the collected multi-source heterogeneous data, and accurately evaluate the threat levels of edge device nodes, so as to improve the real-time performance and accuracy of security detection. BRIEF DESCRIPTION OF THE DRAWINGS

[0039] To more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0040] Figure 1 is a flowchart of an Internet of Things environment security detection method provided according to the present application;

[0041] Figure 2 is a schematic flowchart of determining the malicious access factor of each edge device node to the Internet of Things platform provided according to the present application;

[0042] Figure 3 is a schematic flowchart of determining the malicious scheduling recognition of each edge device node provided according to the present application;

[0043] Figure 4 is a module structure diagram of an Internet of Things environment security detection system provided according to the present application. Detailed implementation manners

[0044] The following will clearly and completely describe the technical solutions in the embodiments of the present application with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present application.

[0045] The embodiments of the present application provide an Internet of Things environment security detection method and system. The core is to collect the access traffic sequences of each edge device node in the Internet of Things platform; respectively extract the malicious access features of each access traffic sequence, and then obtain the malicious access feature vectors of each edge device node. Based on the corresponding malicious access feature vectors, determine the malicious access factors of each edge device node to the Internet of Things platform; obtain the file scheduling information of each edge device node to the Internet of Things platform, determine the malicious scheduling recognition of each edge device node through the corresponding file scheduling information, and determine the malicious attack degree of each edge device node to the Internet of Things platform based on the corresponding malicious access factor and the corresponding malicious scheduling recognition; perform security warnings on each edge device node in the Internet of Things platform according to the corresponding malicious attack degree. By adopting the above solution, efficient feature extraction can be performed on the collected multi-source heterogeneous data, and the threat level of the edge device nodes can be accurately evaluated to improve the real-time performance and accuracy of security detection.

[0046] Example 1. To better understand the above technical solution, the above technical solution will be described in detail below in combination with the specification drawings and specific implementation manners. Refer to Figure 1 As shown, this figure is an exemplary flowchart of an Internet of Things environment security detection method according to this embodiment of the present application. The detection method includes the following steps:

[0047] In step S1, access traffic sequences of each edge device node in the Internet of Things platform are collected.

[0048] In specific implementation, the access traffic sequences of each edge device node in the Internet of Things platform can be collected through an Internet of Things gateway; it should be noted that the Internet of Things gateway, as a bridge between the Internet of Things platform and the edge device nodes, bears data transmission and control. The access traffic sequence refers to communication data packets, request responses, control commands, file transfers, etc. between the edge device nodes and the Internet of Things platform. In actual implementation, the traffic monitoring function of the Internet of Things gateway can be used to collect the access traffic sequences of each edge device node in the Internet of Things platform in real time.

[0049] In step S2, malicious access features are extracted from each access traffic sequence respectively, and then malicious access feature vectors of each edge device node are obtained. According to the corresponding malicious access feature vectors, malicious access factors of each edge device node to the Internet of Things platform are determined respectively.

[0050] In this embodiment, the malicious access features are extracted from each access traffic sequence respectively, and then the malicious access feature vectors of each edge device node can be obtained specifically by the following method, that is:

[0051] For each edge device node, abnormal behavior features of the access traffic sequence of the edge device node are extracted to obtain the traffic abnormal behavior features of the edge device node;

[0052] Time series analysis is performed on the access traffic sequence of the edge device node to obtain the abnormal trend of access change of the edge device node;

[0053] Protocol parsing is performed on the access traffic sequence of the edge device node to obtain the abnormal protocol distribution features of the edge device node;

[0054] The malicious access feature vector of the edge device node is constructed through the traffic abnormal behavior features, the abnormal trend of access change, and the abnormal protocol distribution features, and then the malicious access feature vectors of each edge device node are obtained.

[0055] In specific implementation, for each edge device node, first, anomaly detection algorithms (such as Isolation Forest, k-means clustering, etc.) can be used to extract the abnormal behavior features of the access traffic sequence of the edge device node, so as to obtain the traffic abnormal behavior features of the edge device node. Among them, the extraction of abnormal behavior features represents the abnormal patterns in the access traffic of the edge device node, such as overly frequent requests, abnormal communication patterns, etc. The abnormal behavior features can reflect whether the edge device node has participated in malicious activities, such as brute force cracking, DDoS attacks, etc.; then, time series analysis algorithms (such as ARIMA, LSTM neural network, etc.) can be used to perform time series analysis on the access traffic sequence of the edge device node, so as to obtain the abnormal trend of access change of the edge device node. Among them, the abnormal trend of access change represents the abnormal trend of the access traffic of the edge device node changing over time. The abnormal trend of access change is very important for detecting whether there is continuous abnormal behavior (such as continuous large-scale data transmission or requests) in the edge device node.

[0056] In addition, in specific implementation, deep packet inspection (DPI) technology can be used to parse the protocol of the access traffic sequence of the edge device node. Through deep packet inspection (DPI) technology, the protocol data in the access traffic sequence can be parsed to identify the protocol type and its content of each traffic packet, so as to obtain the abnormal characteristics of protocol distribution of the edge device node. Among them, the abnormal characteristics of protocol distribution represent the abnormal protocol hierarchy in the requests of the edge device node (for example, whether there are illegal HTTP methods or unauthorized commands in the HTTP request); finally, the malicious access feature vector of the edge device node can be constructed through the traffic abnormal behavior features, the abnormal trend of access change, and the abnormal characteristics of protocol distribution, that is, the traffic abnormal behavior features, the abnormal trend of access change, and the abnormal characteristics of protocol distribution are used as malicious access features, so that the vector composed of all malicious access features is used as the malicious access feature vector of the edge device node. Through the above method, the malicious access feature vectors of each edge device node can be obtained.

[0057] Preferably, in this embodiment, the malicious access factors of each edge device node to the IoT platform are determined according to the corresponding malicious access feature vectors. Refer to Figure 2 As shown, this figure is a schematic flow chart for determining the malicious access factors of each edge device node to the IoT platform in some embodiments of the present application. The malicious access factors of each edge device node to the IoT platform in this embodiment can be implemented by the following steps:

[0058] In step S21, for the edge device node, each malicious access feature in the malicious access feature vector of the edge device node is scored, and then the malicious scores of each malicious access feature in the malicious access feature vector are obtained;

[0059] In step S22, the malicious access factor of the edge device node to the IoT platform is determined according to the malicious scores of all malicious access features, and then the malicious access factors of each edge device node to the IoT platform are obtained.

[0060] Specifically, first, for the edge device node, each malicious access feature in the malicious access feature vector of the edge device node can be scored. The supervised learning algorithm (such as random forest, SVM, etc.) can be used to model each malicious access feature, that is, the historical access data of the edge device node with labels is collected from the IoT platform. The historical access data contains normal behavior samples and malicious behavior samples. The supervised learning model is trained through this historical access data, and the classification probability output of the supervised learning model is used to judge the tendency of the malicious access feature to cause the supervised learning model to predict "malicious", that is, the classification probability output by the supervised learning model can be used as the malicious score of the malicious access feature, so as to calculate the malicious scores of each malicious access feature in the malicious access feature vector. Among them, the malicious score represents the degree of abnormality of the edge device node in the corresponding feature dimension; then, the malicious access factor of the edge device node to the IoT platform can be determined according to the malicious scores of all malicious access features. Among them, the malicious access factor represents the degree of malice when the edge device node accesses the IoT platform. In actual implementation, the standard deviation of the malicious scores of all malicious access features can be used as the malicious access factor of the edge device node to the IoT platform. Through the above method, the malicious access factors of each edge device node to the IoT platform can be obtained.

[0061] It should be noted that by separately extracting malicious access features from each access traffic sequence, and then obtaining the malicious access feature vectors of each edge device node, and determining the malicious access factor of the device to the IoT platform based on these feature vectors, it is possible to effectively identify the abnormal behavior and potential threats of the device, and comprehensively analyze multi-dimensional features such as the access pattern, behavior change, and protocol usage of the edge device node, and then accurately evaluate the security risk of each device. Efficient feature extraction for the collected multi-source heterogeneous data can integrate information from different sources, improve the ability to identify complex threats, and at the same time improve the real-time performance and accuracy of the detection process.

[0062] In step S3, the file scheduling information of each edge device node to the IoT platform is obtained, the malicious scheduling recognition degree of each edge device node is determined through the corresponding file scheduling information, and the malicious attack degree of each edge device node to the IoT platform is determined based on the corresponding malicious access factor and the corresponding malicious scheduling recognition degree.

[0063] In specific implementation, the file scheduling information of each edge device node for the Internet of Things platform can be obtained through the log mechanism of the Internet of Things platform; it should be noted that the Internet of Things platform should enable the log recording function, especially for detailed recording of events related to file scheduling, so as to obtain the file scheduling information of each edge device node for the Internet of Things platform. Among them, the file scheduling information includes data such as edge device node identification information, file category and file name, requested operation type, file request timestamp, file size and transmission volume, request source and destination, etc.

[0064] Preferably, in this embodiment, the malicious scheduling recognition rate of each edge device node is determined based on the corresponding file scheduling information. Refer to Figure 3 As shown, this figure is a schematic flowchart of determining the malicious scheduling recognition rate of each edge device node in some embodiments of this application. The malicious scheduling recognition rate of each edge device node in this embodiment can be implemented by the following steps:

[0065] In step S31, for each edge device node, the set of scheduled file categories of the edge device node is extracted from the file scheduling information of the edge device node;

[0066] In step S32, multiple malicious scheduling coefficients of the edge device node are determined according to the set of scheduled file categories;

[0067] In step S33, the malicious scheduling recognition rate of the edge device node is determined based on all the malicious scheduling coefficients, and then the malicious scheduling recognition rate of each edge device node is obtained.

[0068] In specific implementation, first, for each edge device node, a set of scheduled file categories of the edge device node can be extracted from the file scheduling information of the edge device node, where the set of scheduled file categories represents a set of file categories requested by the edge device node, and the file categories can include configuration files, firmware files, log files, sensitive data files, etc.; then, a plurality of malicious scheduling coefficients of the edge device node can be determined according to the set of scheduled file categories, where the malicious scheduling coefficient represents the abnormal degree of the behavior of the edge device node requesting the corresponding type of scheduled file. That is, for each type of scheduled file in the set of scheduled file categories, the total number of requests for this type of scheduled file by the edge device node can be counted, and the ratio of the total number of requests to the total amount of this type of scheduled file in the IoT platform can be calculated, and the product of the calculation result and the request frequency of the edge device node for this type of scheduled file can be used as the malicious scheduling coefficient of the edge device node under this type of scheduled file. In the above way, a plurality of malicious scheduling coefficients of the edge device node can be obtained; finally, the malicious scheduling recognition degree of the edge device node can be determined based on all the malicious scheduling coefficients, where the malicious scheduling recognition degree represents the malicious degree of the scheduling behavior of the edge device node for the files in the IoT platform. The variance of all the malicious scheduling coefficients can be used as the malicious scheduling recognition degree of the edge device node. In the above way, the malicious scheduling recognition degrees of each edge device node can be obtained.

[0069] In this embodiment, to determine the malicious attack degree of each edge device node on the IoT platform based on the corresponding malicious access factor and the corresponding malicious scheduling recognition degree, the following method can be specifically adopted, that is:

[0070] For each edge device node, the malicious access factor and the malicious scheduling recognition degree of the edge device node are weighted and summed to obtain the malicious attack degree of the edge device node on the IoT platform, and then the malicious attack degrees of each edge device node on the IoT platform are obtained.

[0071] In specific implementation, first, the corresponding weights of the malicious access factor and the malicious scheduling recognition degree can be set respectively according to historical experience and data analysis; then, the malicious access factor and the malicious scheduling recognition degree of the edge device node are weighted and summed, and the dimension of the weighted sum result is eliminated, so that the final result can be used as the malicious attack degree of the edge device node on the IoT platform. In the above way, the malicious attack degrees of each edge device node on the IoT platform can be obtained; it should be noted that in this application, the malicious attack degree represents the possible degree of malicious attack when the edge device node accesses the IoT platform.

[0072] It should be noted that by obtaining the file scheduling information of each edge device node and combining the malicious access factor and the malicious scheduling recognition rate to determine the malicious attack degree of the edge device node, it is possible to comprehensively consider the access behavior and file scheduling behavior of the edge device node, provide a comprehensive security assessment, and accurately identify the abnormal behavior of the edge device node.

[0073] In step S4, security warnings are issued for each edge device node in the Internet of Things platform according to the corresponding malicious attack degree.

[0074] In this embodiment, the security warnings for each edge device node in the Internet of Things platform according to the corresponding malicious attack degree can be specifically implemented in the following manner, that is:

[0075] Determine the malicious attack degree level of each edge device node based on a preset malicious attack degree level table and the corresponding malicious attack degree;

[0076] Determine the security warning strategy for each edge device node in the Internet of Things platform according to the corresponding malicious attack degree level.

[0077] Specifically, first, a malicious attack degree level table can be set based on expert knowledge and experience. Through this malicious attack degree level table, the level of the malicious attack degree of the edge device node can be quantified. The malicious attack degree level table includes a low-risk level (the malicious attack degree value is relatively low, usually lower than 0.3. At this time, the behavior of the edge device node does not show obvious malice or abnormality and may be a normal operation), a medium-risk level (the malicious attack degree value is between 0.3 and 0.7. The behavior of the edge device node shows some abnormal patterns, which may indicate potential threats), and a high-risk level (the malicious attack degree value is greater than or equal to 0.7. The behavior of the edge device node shows serious malice or abnormal behavior, and it may be that an attacker is trying to invade or abuse the device). Then, based on the preset malicious attack degree level table and the corresponding malicious attack degree, the malicious attack degree level of each edge device node can be determined, that is, the malicious attack degree of each edge device node is mapped into the preset malicious attack degree level table, so that the malicious attack degree level of each edge device node can be obtained. For example, if the malicious attack degree of an edge device node is 0.2, the malicious attack degree level of this edge device node is low risk; if the malicious attack degree of an edge device node is 0.5, the malicious attack degree level of this edge device node is medium risk; if the malicious attack degree of an edge device node is 0.8, the malicious attack degree level of this edge device node is high risk.

[0078] In addition, during specific implementation, the security warning strategies for each edge device node in the IoT platform can be determined according to the corresponding malicious attack degree level. That is, once the malicious attack degree level of each device is determined, the system can formulate corresponding security warning strategies based on the malicious attack degree level of each edge device node. These strategies are designed to take different levels of security protection measures according to the malicious attack degree level of the edge device node. For example:

[0079] If the malicious attack degree level of the edge device node is a low risk, there is no need to perform special processing on the edge device node. Maintain regular monitoring, and continuously monitor whether the behavior of the edge device node changes. Keep log records to ensure that if the malicious behavior of the device changes, it can be captured in time. Instant warning is not required, but its behavior and access logs can be reviewed regularly.

[0080] If the malicious attack degree level of the edge device node is a medium risk, strengthen the monitoring of the edge device node, analyze its access behavior and communication mode. If further abnormal behavior is detected, an alarm can be automatically triggered, and the device can be temporarily restricted or isolated. Set medium-frequency warnings and reports to ensure timely response when the behavior of the edge device node changes.

[0081] If the malicious attack degree level of the edge device node is a high risk, immediately isolate the edge device node and trigger a high-level security response, including but not limited to disconnecting from the network, conducting a more rigorous audit on it, immediately revoking the access rights of the device, or further manual intervention. Set high-frequency real-time alarms to ensure that the system administrator can quickly understand and handle the security threats of the edge device node.

[0082] It should be noted that by evaluating the malicious attack degree of each edge device node and combining the corresponding security warning strategies, the IoT platform can achieve dynamic and secure management. It can not only discover potential threats in real time, improve the real-time performance and accuracy of security detection, but also provide corresponding protection measures according to the security level of the device to ensure the most effective allocation of resources and security measures.

[0083] It can be seen that in this application, first, by separately extracting malicious access features from each access traffic sequence, obtaining the malicious access feature vectors of each edge device node, and determining the malicious access factors of the device to the IoT platform based on these feature vectors, it is possible to effectively identify the abnormal behaviors and potential threats of the device, comprehensively analyze multi-dimensional features such as the access patterns, behavior changes, and protocol usage of the edge device nodes, and then accurately evaluate the security risks of each edge device node; then, by obtaining the file scheduling information of each edge device node and combining the malicious access factor and the malicious scheduling recognition degree to determine the malicious attack degree of the edge device node, it is possible to comprehensively consider the access behavior and file scheduling behavior of the edge device node, provide a comprehensive security assessment, and accurately identify the abnormal behaviors of the edge device node; finally, by evaluating the malicious attack degree of each edge device node and combining the corresponding security warning strategies, the IoT platform can achieve dynamic and secure management, can detect potential threats in real time, and improve the real-time performance and accuracy of security detection.

[0084] In summary, the technical solution adopted in this application can efficiently extract features from the collected multi-source heterogeneous data and accurately evaluate the threat levels of edge device nodes to improve the real-time performance and accuracy of security detection.

[0085] Embodiment 2. This application provides an IoT environment security detection system. Refer to Figure 4 As shown, this figure is a schematic diagram of the IoT environment security detection system according to this embodiment of this application. The detection system includes:

[0086] A traffic collection module 100 for collecting the access traffic sequences of each edge device node in the IoT platform;

[0087] A malicious access determination module 200 for separately extracting malicious access features from each access traffic sequence, obtaining the malicious access feature vectors of each edge device node, and respectively determining the malicious access factors of each edge device node to the IoT platform based on the corresponding malicious access feature vectors;

[0088] A malicious attack determination module 300 for obtaining the file scheduling information of each edge device node to the IoT platform, determining the malicious scheduling recognition degree of each edge device node through the corresponding file scheduling information, and determining the malicious attack degree of each edge device node to the IoT platform based on the corresponding malicious access factor and the corresponding malicious scheduling recognition degree;

[0089] A security warning module 400 for performing security warnings on each edge device node in the IoT platform according to the corresponding malicious attack degree.

[0090] This application is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to embodiments of the present application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams can be implemented by computer program instructions, and the combination of flows and / or blocks in the flowcharts and / or block diagrams can also be implemented. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate means for implementing the functions specified in one or more of the flows Figure 1 one or more flows and / or blocks Figure 1 or in multiple blocks.

[0091] Those of ordinary skill in the art can understand that all or part of the steps in the various methods of the above embodiments can be completed by instructing relevant hardware through a program, and this program can be stored in a computer-readable storage medium. The storage medium includes read-only memory (ROM), random access memory (RAM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), one-time programmable read-only memory (OTPROM), electrically-erasable programmable read-only memory (EEPROM), compact disc read-only memory (CD-ROM), or other optical disc memories, magnetic disk memories, tape memories, or any other medium that can be used to carry or store data and is computer-readable.

[0092] It should also be noted that the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed, or further includes elements inherent to such process, method, commodity or device. Without further limitation, an element defined by the statement "including one..." does not exclude the existence of another identical element in the process, method, commodity or device including the element.

Claims

1. An Internet of Things environment security detection method, characterized in that, The detection method includes the following steps: Collect the access traffic sequences of each edge device node in the Internet of Things platform; Extract malicious access features from each access traffic sequence respectively, and then obtain the malicious access feature vectors of each edge device node. Determine the malicious access factors of each edge device node to the Internet of Things platform according to the corresponding malicious access feature vectors; Obtain the file scheduling information of each edge device node to the Internet of Things platform, determine the malicious scheduling recognition degrees of each edge device node through the corresponding file scheduling information, and determine the malicious attack degrees of each edge device node to the Internet of Things platform based on the corresponding malicious access factors and the corresponding malicious scheduling recognition degrees; Perform security warnings on each edge device node in the Internet of Things platform according to the corresponding malicious attack degrees; Among them, determining the malicious access factors of each edge device node to the Internet of Things platform according to the corresponding malicious access feature vectors specifically includes: For an edge device node, score each malicious access feature in the malicious access feature vector of the edge device node, and then obtain the malicious scores of each malicious access feature in the malicious access feature vector; Determine the malicious access factor of the edge device node to the Internet of Things platform according to the malicious scores of all malicious access features, and then obtain the malicious access factors of each edge device node to the Internet of Things platform; Among them, determining the malicious scheduling recognition degrees of each edge device node through the corresponding file scheduling information specifically includes: For each edge device node, extract the scheduling file category set of the edge device node from the file scheduling information of the edge device node; Determine multiple malicious scheduling coefficients of the edge device node according to the scheduling file category set; Determine the malicious scheduling recognition degree of the edge device node according to all the malicious scheduling coefficients, and then obtain the malicious scheduling recognition degrees of each edge device node.

2. The method for detecting the environmental security of the Internet of Things according to claim 1, characterized in that, Collect the access traffic sequences of each edge device node in the Internet of Things platform through the Internet of Things gateway.

3. The method for detecting the environmental security of the Internet of Things according to claim 1, characterized in that, Extracting malicious access features from each access traffic sequence respectively, and then obtaining the malicious access feature vectors of each edge device node specifically includes: For each edge device node, extract abnormal behavior features from the access traffic sequence of the edge device node to obtain the traffic abnormal behavior features of the edge device node; Perform time series analysis on the access traffic sequence of the edge device node to obtain the abnormal trend of access change of the edge device node; Perform protocol parsing on the access traffic sequence of the edge device node to obtain the abnormal protocol distribution features of the edge device node; Construct the malicious access feature vector of the edge device node through the traffic abnormal behavior features, the abnormal trend of access change and the abnormal protocol distribution features, and then obtain the malicious access feature vectors of each edge device node.

4. The method for detecting the security of the Internet of Things environment according to claim 1, characterized in that, Obtain the file scheduling information of each edge device node to the Internet of Things platform through the log mechanism of the Internet of Things platform.

5. The method for detecting the environmental security of the Internet of Things according to claim 1, characterized in that Determining the malicious attack degrees of each edge device node to the Internet of Things platform based on the corresponding malicious access factors and the corresponding malicious scheduling recognition degrees specifically includes: For each edge device node, the malicious access factor and malicious scheduling recognition of the edge device node are weighted and summed to obtain the malicious attack degree of the edge device node on the IoT platform, and then the malicious attack degrees of each edge device node on the IoT platform are obtained.

6. The method for detecting the environmental security of the Internet of Things according to claim 1, wherein, The malicious attack degree represents the possible degree of malicious attack when the edge device node accesses the IoT platform.

7. The method for detecting the security of the Internet of Things environment according to claim 1, wherein, Performing security warnings on each edge device node in the IoT platform according to the corresponding malicious attack degree specifically includes: Determining the malicious attack degree levels of each edge device node based on a preset malicious attack degree level table and the corresponding malicious attack degree; Determining the security warning strategies of each edge device node in the IoT platform according to the corresponding malicious attack degree levels.

8. An Internet of Things environment security detection system for performing an Internet of Things environment security detection method according to any one of claims 1 to 7, characterized in that, The detection system includes: A traffic collection module for collecting the access traffic sequences of each edge device node in the IoT platform; A malicious access determination module for respectively extracting malicious access features from each access traffic sequence, and then obtaining the malicious access feature vectors of each edge device node, and respectively determining the malicious access factors of each edge device node on the IoT platform based on the corresponding malicious access feature vectors; A malicious attack determination module for obtaining the file scheduling information of each edge device node on the IoT platform, determining the malicious scheduling recognition of each edge device node through the corresponding file scheduling information, and determining the malicious attack degree of each edge device node on the IoT platform based on the corresponding malicious access factor and the corresponding malicious scheduling recognition; A security warning module for performing security warnings on each edge device node in the IoT platform according to the corresponding malicious attack degree.

Citation Information

Patent Citations

  • Abnormal equipment identification method and device, computer equipment and storage medium

    CN113920398A

  • Network event security monitoring method and system

    CN118200019A