A method and apparatus for identifying Internet of Things (IoT) devices

By constructing a device identification model with multivariate temporal features and using the Inception module and residual structure, the problem of temporal noise interference in IoT device identification is solved, achieving higher identification accuracy and adaptability, and making it suitable for complex networks and encrypted traffic environments.

CN120105197BActive Publication Date: 2025-12-02HUNAN TECHN COLLEGE OF RAILWAY HIGH SPEED
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510217264.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-26
Publication Date
2025-12-02
Estimated Expiration
2045-02-26

AI Technical Summary

Technical Problem

Existing IoT device identification methods fail to effectively account for temporal noise interference, resulting in low identification accuracy, especially in complex network environments and encrypted traffic conditions.

Method used

By extracting the abnormal and length features of data packets from IoT devices, a multivariate temporal feature is constructed, and a device identification model is used for identification. The model includes an Inception module and a residual structure to characterize the impact of temporal noise interference and improve the identification accuracy.

Benefits of technology

It improves the identification accuracy of IoT devices and their ability to adapt to complex network environments, meets the identification requirements of encrypted traffic, reduces the time cost of feature extraction and identification, and is suitable for online real-time identification.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120105197B_ABST
    Figure CN120105197B_ABST
Patent Text Reader

Abstract

This invention provides a method and apparatus for identifying IoT devices, belonging to the field of IoT device identification technology. The method includes: extracting abnormal features and length features of IoT device data packets, and constructing multivariate temporal features based on the abnormal features and length features; inputting the multivariate temporal features into a fully trained device identification model to obtain the identification result of the IoT device; wherein the device identification model includes a first Inception module, a first residual structure, a second Inception module, a second residual structure, a global average pooling layer, and a fully connected layer. This invention improves the accuracy of IoT device identification by using abnormal features that characterize the impact of network environment and encrypted traffic on the traffic length sequence pattern of IoT device data packets as input to the device identification model.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of Internet of Things (IoT) device identification technology, and specifically to an IoT device identification method and apparatus. Background Technology

[0002] The Internet of Things (IoT) technology connects various devices to create a network system for data exchange and intelligent control. This important technology has been widely embedded and deployed in various consumer applications. Therefore, Consumer-Centric IoT (CIoT) has emerged, encompassing multiple application scenarios such as smart homes, smart health, and smart grids. CIoT has become a significant force in the Fifth Industrial Revolution (Industry 5.0) and the digital transformation of smart cities. With continuous technological development, CIoT will further drive the intelligent upgrading of various industries and promote sustainable socio-economic development. CIoT interacts more directly with end-users, thus often possessing a large amount of user data. Especially in smart home scenarios, the home data collected and processed by CIoT devices (such as smart speakers, smart locks, and surveillance cameras) is highly private, including users' daily habits, home environment information, and security monitoring data. However, the security vulnerabilities exposed to these devices may make them targets for cyberattacks, leading to the leakage and misuse of family privacy data. For example, attackers may gain access to family members' real-time locations, surveillance footage, or even control of smart locks by intruding into the devices, thereby committing theft or other illegal activities.

[0003] Therefore, effective protection and monitoring measures are urgently needed to address the ever-evolving cyber threats. IoT device identification, as a network management tool, has become an important research direction. It can help manage and configure devices, detect and isolate vulnerable devices, and take control measures to prevent the escalation of security threats when devices malfunction. For example, by identifying device type, behavior patterns, and network traffic, abnormal devices can be quickly identified and their access restricted, thereby reducing potential security risks. In recent years, researchers both domestically and internationally have conducted extensive research on IoT device identification. However, existing identification methods still have shortcomings: they do not consider temporal noise interference. That is, existing time-based methods only use the packet length attribute, using a single-dimensional parameter to identify IoT devices, without considering the noise superposition of network quality and encrypted data on the temporal sequence. The fingerprint of traffic length patterns is affected by these factors.

[0004] Therefore, there is an urgent need to provide a method and apparatus for identifying IoT devices that takes into account the noise superposition effect of network quality and encrypted data on timing, so as to improve the identification accuracy when identifying IoT devices. Summary of the Invention

[0005] In view of this, it is necessary to provide an IoT device identification method and apparatus to solve the technical problem that the prior art does not consider the interference of timing noise, resulting in a low accuracy of IoT device identification.

[0006] On the one hand, in order to solve the above-mentioned technical problems, the present invention provides an IoT device identification method, comprising:

[0007] Extract the anomaly features and length features of data packets from IoT devices, and construct multivariate time-series features based on the anomaly features and length features;

[0008] The multivariate time-series features are input into the fully trained device recognition model to obtain the recognition results of IoT devices;

[0009] The device identification model includes a first Inception module, a first residual structure, a second Inception module, a second residual structure, a global average pooling layer, and a fully connected layer.

[0010] In one possible implementation, the anomaly characteristics include anomaly level, anomaly grouping, and top-level protocol type.

[0011] In one possible implementation, the length characteristics of the data packets from the IoT device are extracted, including:

[0012] Determine the outbound and inbound traffic in the data packets of the IoT devices;

[0013] The outbound traffic and inbound traffic are concatenated in chronological order to obtain the target traffic, and the length of the target traffic is used as the length feature.

[0014] In one possible implementation, determining the outbound and inbound traffic in the IoT device data packets includes:

[0015] Acquire the raw data stream; the raw data stream includes multiple data packets from multiple IoT devices;

[0016] Based on the binary information, the first data packet with the source MAC address of the target IoT device and the second data packet with the destination MAC address of the target IoT device are determined from the multiple data packets. The first data packet is taken as the outbound traffic and the second data packet is taken as the inbound traffic.

[0017] In one possible implementation, multivariate time-series features are constructed based on the anomaly features and the length features, including:

[0018] The data packets of the IoT device are divided based on a preset sequence length to obtain multiple time-series features;

[0019] The temporal features of each segment are filled with a preset filling rule to obtain the multivariate temporal features;

[0020] The number of rows in the multivariate time series feature is the same as the number of types of the anomaly feature and the time series feature, and the number of columns in the multivariate time series feature is the same as the number of segments in the multi-segment time series feature.

[0021] In one possible implementation, both the first Inception module and the second Inception module include a first Inception structure, a second Inception structure, and a third Inception structure connected in sequence; the first Inception structure, the second Inception structure, and the third Inception structure all include a feature compression unit, a multi-scale convolution unit, and a feature fusion unit.

[0022] The feature compression unit is used to compress the input features to obtain compressed features;

[0023] The multi-scale convolutional unit is used to perform multi-scale convolution on the input features to obtain multiple convolutional features with different scales.

[0024] The feature fusion unit is used to fuse the compressed features and the multiple convolutional features.

[0025] In one possible implementation, the feature compression unit includes a first global average pooling layer and a first convolutional layer connected in sequence.

[0026] In one possible implementation, the multi-scale convolutional unit includes a bottleneck layer and a second, third, and fourth convolutional layer connected to the bottleneck layer, wherein the kernel sizes of the second, third, and fourth convolutional layers are all different.

[0027] In one possible implementation, the feature fusion unit includes a deep convolutional layer, a batch normalization layer, and an activation function layer connected in sequence.

[0028] On the other hand, the present invention also provides an Internet of Things (IoT) device identification device, comprising:

[0029] A multidimensional feature extraction unit is used to extract the abnormal features and length features of data packets from IoT devices, and to construct multivariate temporal features based on the abnormal features and length features;

[0030] The device identification unit is used to input the multivariate time-series features into the fully trained device identification model to obtain the identification result of the Internet of Things device;

[0031] The device identification model includes a first Inception module, a first residual structure, a second Inception module, a second residual structure, a global average pooling layer, and a fully connected layer.

[0032] The beneficial effects of this invention are as follows: The IoT device identification method provided by this invention extracts abnormal features from IoT device data packets in addition to length characteristics. These abnormal features can characterize the impact of network environment and encrypted traffic on the traffic length sequence pattern of IoT device data packets. In other words, abnormal features can characterize temporal noise interference. This means that the impact of temporal noise can be considered during the identification process of IoT devices, thereby improving the accuracy of IoT device identification. Furthermore, it can significantly improve the adaptability of the IoT device identification method to complex network environments and meet the identification requirements for encrypted traffic.

[0033] Furthermore, by including an Inception module in the device identification model, this invention can deeply analyze the network behavior of IoT devices at different times and scales, thereby further improving identification accuracy. Even further, by including a residual module in the device identification model, this invention solves the gradient vanishing problem between Inception modules, thereby further improving the identification accuracy of the device identification model.

[0034] In summary, this invention enables efficient and accurate identification of IoT devices, laying the foundation for subsequent security management and maintenance, and ensuring the safe operation of devices in the IoT environment. Attached Figure Description

[0035] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0036] Figure 1 This is a schematic flowchart of an embodiment of the IoT device identification method provided by the present invention;

[0037] Figure 2 A schematic diagram of an embodiment of the device identification model provided by the present invention;

[0038] Figure 3 For the present invention Figure 1 A schematic diagram of an embodiment of extracting length features in step S101;

[0039] Figure 4 For the present invention Figure 3A schematic diagram of an embodiment of S301;

[0040] Figure 5 For the present invention Figure 1 A flowchart illustrating an embodiment of constructing multivariate time series features in step S101;

[0041] Figure 6 A schematic diagram of an embodiment of the first Inception module provided by the present invention;

[0042] Figure 7 This is a comparison chart of evaluation metrics between the embodiments of the present invention and existing identification methods;

[0043] Figure 8 This is a comparison chart showing the time consumption of the feature extraction and recognition stages between the embodiments of the present invention and existing methods;

[0044] Figure 9 This is a comparison chart of recognition performance under different time windows in the embodiments of the present invention;

[0045] Figure 10 A comparison chart of the accuracy metrics of unidirectional and bidirectional length features on the UNSW dataset;

[0046] Figure 11 A comparison chart of the accuracy metrics of unidirectional and bidirectional length features on the CICIoT dataset;

[0047] Figure 12 This is a schematic diagram of an embodiment of the IoT device identification device provided by the present invention. Detailed Implementation

[0048] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present invention, and not all of them. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative effort are within the scope of protection of the present invention.

[0049] It should be understood that the illustrative drawings are not drawn to scale. The flowcharts used in this invention illustrate operations implemented according to some embodiments of the invention. It should be understood that the operations in the flowcharts may be implemented out of order, and steps without logical contextual relationships may be reversed or performed simultaneously. Furthermore, those skilled in the art, guided by the content of this invention, may add one or more other operations to the flowcharts, or remove one or more operations from the flowcharts. Some block diagrams shown in the drawings are functional entities and do not necessarily correspond to physically or logically independent entities. These functional entities may be implemented in software, in one or more hardware modules or integrated circuits, or in different network and / or processor systems and / or microcontroller systems.

[0050] In this document, the term "embodiment" means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of the invention. The appearance of this phrase in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a mutually exclusive, independent, or alternative embodiment. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.

[0051] This invention provides a method and apparatus for identifying Internet of Things (IoT) devices, which will be described below.

[0052] Figure 1 This is a schematic flowchart of an embodiment of the IoT device identification method provided by the present invention, as shown below. Figure 1 As shown, the methods for identifying IoT devices include:

[0053] S101. Extract the anomaly features and length features of data packets from IoT devices, and construct multivariate time-series features based on the anomaly features and length features.

[0054] Among them, abnormal features and length features constitute the device fingerprint of IoT devices.

[0055] It should be noted that: IoT device data packets refer to the data packets corresponding to a specific IoT device, that is: the data packets corresponding to a specific IoT device, rather than the data packets of multiple IoT devices.

[0056] Since IoT device data packets are time-series data, IoT device data packets refer to data packets within a specified time interval.

[0057] The specific method for extracting abnormal features from IoT device data packets is as follows: using the tshark tool to obtain expert information features for each data packet, and then manually analyzing and aggregating them to finally obtain the abnormal features of the data packet.

[0058] Expert Info refers to the advanced diagnostic information about potential problems or anomalies provided by Wireshark after analyzing captured network packets. This information is generated by Wireshark's built-in parser and protocol analysis engine and is designed to help users quickly identify problems or abnormal behavior in network communications.

[0059] S102. Input the multivariate time-series features into the fully trained device recognition model to obtain the recognition results of IoT devices.

[0060] It should be understood that before using a device recognition model, it needs to be trained, tested, and validated based on a sample set to ensure the recognition performance of the device recognition model.

[0061] In a specific embodiment of the present invention, the loss function used by the device recognition model during training is the cross-entropy loss function. Specifically, the formula for the cross-entropy loss function is:

[0062]

[0063] In the formula, N represents the number of samples in the batch; C represents the number of categories of IoT devices to be identified; y i,c This represents the truth value judgment between sample i and class C. If sample i is in class C, the value is 1; otherwise, it is 0. i,c This represents the probability that the model predicts sample i to be device category C.

[0064] Among them, multivariate time series features refer to the characteristics of multivariate time series. A multivariate time series is time series data composed of multiple variables or dimensions. Unlike univariate time series (which contain only data on the change of one variable over time), multivariate time series simultaneously record the changes of multiple related variables over time, and these variables may have interdependencies or correlations.

[0065] In some embodiments of the present invention, such as Figure 2 As shown, the device identification model includes a first Inception module, a first residual structure, a second Inception module, a second residual structure, a global average pooling layer, and a fully connected layer.

[0066] The inputs of the first residual structure are the inputs and outputs of the first Inception module, and the inputs of the second residual structure are the inputs and outputs of the second Inception module.

[0067] Compared with existing technologies, the IoT device identification method provided in this invention extracts abnormal features from IoT device data packets in addition to length characteristics. These abnormal features can characterize the impact of network environment and encrypted traffic on the traffic length sequence pattern of IoT device data packets. In other words, abnormal features characterize temporal noise interference, meaning that the impact of temporal noise can be considered during the identification process of IoT devices, thereby improving the accuracy of IoT device identification. Furthermore, it can significantly improve the adaptability of the IoT device identification method to complex network environments and meet the requirements for identifying encrypted traffic.

[0068] Furthermore, by including an Inception module in the device identification model, this embodiment of the invention can deeply mine the network behavior of IoT devices at different times and scales, thereby further improving identification accuracy. Even further, by including a residual module in the device identification model, this embodiment of the invention solves the gradient vanishing problem between Inception modules, thereby further improving the identification accuracy of the device identification model.

[0069] Furthermore, the feature extraction in this embodiment of the invention takes less time and does not require complex feature processing and calculation, thus reducing the time cost of this stage and better meeting the needs of online real-time recognition.

[0070] In summary, the embodiments of the present invention can achieve efficient and accurate identification of IoT devices, laying the foundation for subsequent security management and maintenance, and ensuring the safe operation of devices in the IoT environment.

[0071] To achieve a comprehensive characterization of IoT device data packets under noise interference, in some embodiments of the present invention, the abnormal features include abnormal level, abnormal grouping, and top-level protocol type.

[0072] The error levels, from highest to lowest, are Error, Warning, Note, and Chat (requiring user confirmation).

[0073] Among them, abnormal groups include, but are not limited to, Protocol, Malformed, Sequence, and Comment.

[0074] Here, the top-level protocol type refers to the highest-level protocol in the network protocol hierarchy. In other words, the anomalous characteristics of the i-th IoT device data packet are:

[0075] P i =(s i ,g i ,p i )

[0076] In the formula, Pi For the data packet of the i-th IoT device; s i An abnormal level; g i Grouping for abnormalities; p i This is a top-level protocol type.

[0077] To improve the recognition efficiency of the device recognition model, in some embodiments of the present invention, before constructing multivariate time-series features, the method further includes: converting anomalous features into available space in the numerical space to avoid embedding high-dimensional features.

[0078] Furthermore, to improve conversion efficiency, in a specific embodiment of the present invention, a database representing the conversion relationship is constructed, and linear values ​​corresponding to high-dimensional anomaly features can be obtained by querying the database.

[0079] In some embodiments of the present invention, such as Figure 3 As shown, step S101, extracting the length characteristics of IoT device data packets, includes:

[0080] S301. Determine the outbound and inbound traffic in the data packets of IoT devices.

[0081] In the length characteristics, outbound and inbound flow rates are represented by different symbols. Specifically, inbound flow rate is represented by -, and outbound flow rate is represented by +.

[0082] S302. The outbound flow and inbound flow are spliced ​​together in chronological order to obtain the target flow, and the length of the target flow is used as the length feature.

[0083] For example, if there is outbound flow O1 at time t1, inbound flow I1 at time t2, and outbound flow O2 at time t3, and time t1 is earlier than time t2, and time t2 is earlier than time t1, then the target flow is (O1, I1, O2).

[0084] The length feature of this invention takes into account both inbound and outbound traffic, improving the accuracy of the length feature and thus further enhancing the identification accuracy of IoT devices.

[0085] In some embodiments of the present invention, such as Figure 4 As shown, step S301 includes:

[0086] S401, Obtain the raw data stream; the raw data stream includes multiple data packets from multiple IoT devices.

[0087] The method for obtaining the original data stream is as follows: the original data stream is determined and obtained based on the traffic log that records the original data stream.

[0088] S402. Based on the binary information, determine the first data packet whose source MAC address is the target IoT device and the second data packet whose destination MAC address is the target IoT address among multiple data packets. Treat the first data packet as outbound traffic and the second data packet as inbound traffic.

[0089] The binary information refers to the source MAC address and the destination MAC address.

[0090] Since the number of each abnormal feature of the data packet in the specified time interval is not the same along the time sequence, and the number of each abnormal feature is also different from the number of the length feature along the time sequence, this inconsistency does not conform to the input of the neural network, i.e., the device identification model. Therefore, in some embodiments of the present invention, such as... Figure 5 As shown, the construction of multivariate time-series features based on anomaly features and length features in step S101 includes:

[0091] S501. Divide the data packets of IoT devices based on the preset sequence length to obtain multiple time-series features;

[0092] S502. Fill the time series features of each segment with preset filling rules to obtain multivariate time series features;

[0093] Among them, the number of rows of multivariate time series features is the same as the number of types of anomaly features and time series features, and the number of columns of multivariate time series features is the same as the number of segments of multi-segment time series features.

[0094] This invention improves the accuracy of IoT device identification by truncating and padding the data packets of IoT devices, ensuring that the number of multivariate time-series features obtained is consistent and conforms to the input of the neural network.

[0095] Specifically, let the preset sequence length be L, and within the preset time interval t, the multivariate temporal features of the IoT device D to be identified are finally generated. for:

[0096]

[0097] The preset fill rule can be: fill the missing data with a preset value.

[0098] It should be understood that the preset values ​​can be set based on experience, and will not be elaborated on here.

[0099] In some embodiments of the present invention, such as Figure 2 As shown, both the first Inception module and the second Inception module include a first Inception structure, a second Inception structure, and a third Inception structure connected in sequence; as... Figure 6As shown, the first Inception structure, the second Inception structure, and the third Inception structure all include a feature compression unit, a multi-scale convolution unit, and a feature fusion unit;

[0100] The feature compression unit is used to compress the input features to obtain compressed features;

[0101] Multi-scale convolutional units are used to perform multi-scale convolution on input features to obtain multiple convolutional features with different scales.

[0102] The feature fusion unit is used to fuse compressed features and multiple convolutional features.

[0103] The embodiments of the present invention, by setting each Inception structure to include a feature compression unit and a multi-scale convolution unit, can extract features at different temporal and spatial scales through the feature compression unit and the multi-scale convolution unit respectively, thereby improving the characterization ability of the fused features obtained by fusion to identify the IoT device, and thus ensuring the identification accuracy of the IoT device.

[0104] Furthermore, this embodiment of the invention adds a residual structure between every three Inception structures. The residual structure allows the input of the first Inception structure to be quickly accumulated into the input of the next Inception structure, thus alleviating the gradient vanishing problem through direct gradient flow.

[0105] Specifically, the input of the i-th Inception structure is defined as d in,i The output of each Inception structure is defined as d out,i The residual connection is then shown below:

[0106] d i n, i =d out,i-3 +d out,i-1 i mod 3 = 1

[0107] In the formula, mod is the modulo operator.

[0108] In some embodiments of the present invention, such as Figure 6 As shown, the feature compression unit includes a first global average pooling layer and a first convolutional layer connected in sequence.

[0109] In this system, the kernel size and stride of the first convolutional layer are both 1. The features are compressed by the first global average pooling layer, and then the time series data is expanded to a certain dimension by the first convolutional layer.

[0110] In some embodiments of the present invention, such as Figure 6As shown, the multi-scale convolutional unit includes a bottleneck layer and a second, third, and fourth convolutional layer connected to the bottleneck layer. The kernel sizes of the second, third, and fourth convolutional layers are all different.

[0111] In some embodiments of the present invention, such as Figure 6 As shown, the feature fusion unit includes a deep convolutional layer, a batch normalization layer, and an activation function layer connected in sequence.

[0112] The activation function of the activation function layer is ELU.

[0113] To verify the effectiveness and superiority of the IoT device identification method proposed in this embodiment of the invention, this embodiment compares the performance of the method with that of KNN (K-Nearest Neighbor), Decision Tree (DT), Random Forest (RF), Support Vector Machines (SVM), 1D-CNN, ByteIoT, TMC, and other algorithms on two publicly available datasets (UNSW dataset and CICIoT dataset). Evaluation metrics include accuracy (AC), precision-recall (PR) score, F1 score, and RC (recall rate). The comparison results are as follows: Figure 7 As shown, by Figure 7 It can be seen that the embodiments of the present invention are superior to other existing models in all evaluation indicators.

[0114] Furthermore, this embodiment of the invention also compares the time consumption of the ByteIoT and TMC algorithms in the feature engineering (feature extraction) and device identification stages on two datasets. The comparison results are as follows: Figure 8 As shown, by Figure 8 It can be seen that the time consumption in both stages of the present invention is significantly reduced, that is, the identification efficiency of IoT devices is improved.

[0115] This invention also compares the recognition performance of the IoT device identification method with that of other algorithms at different time windows, and the comparison results are as follows: Figure 9 As shown, by Figure 9 It can be seen that the embodiments of the present invention can achieve better recognition accuracy within a smaller time window, that is, it can better meet the timeliness requirements of recognition, in other words, it further improves the applicability of the IoT device recognition method.

[0116] To verify the superiority of the length feature selection for both inbound and outbound bidirectional lengths in the embodiments of the present invention, the accuracy metrics of unidirectional and bidirectional length features on the UNSW and CICIoT datasets are evaluated in some embodiments of the present invention. Figure 10 For the accuracy metrics in the UNSW dataset, Figure 11 For accuracy metrics on the CICIoT dataset, Figure 10 and Figure 11 The x-axis represents the average length, and the y-axis represents the accuracy. Figure 10 and Figure 11 It can be seen that the bidirectional length feature is more accurate, which verifies the superiority of the length feature proposed in the embodiments of the present invention.

[0117] To better implement the IoT device identification method in this embodiment of the invention, based on the IoT device identification method, this embodiment of the invention also provides an IoT device identification device, such as... Figure 12 As shown, the IoT device identification device 1200 includes:

[0118] The multidimensional feature extraction unit 1201 is used to extract the anomaly features and length features of data packets from IoT devices, and to construct multivariate time-series features based on the anomaly features and length features;

[0119] The device identification unit 1202 is used to input multivariate time-series features into a fully trained device identification model to obtain the identification result of the Internet of Things device;

[0120] The device identification model includes a first Inception module, a first residual structure, a second Inception module, a second residual structure, a global average pooling layer, and a fully connected layer.

[0121] The IoT device identification device 1200 provided in the above embodiments can implement the technical solutions described in the above IoT device identification method embodiments. The specific implementation principles of each module or unit can be found in the corresponding content in the above IoT device identification method embodiments, and will not be repeated here.

[0122] Those skilled in the art will understand that all or part of the processes of the methods described in the above embodiments can be implemented by a computer program instructing related hardware (such as a processor, controller, etc.), and the computer program can be stored in a computer-readable storage medium. The computer-readable storage medium may be a disk, optical disk, read-only memory, or random access memory, etc.

[0123] The present invention provides a detailed description of an IoT device identification method and apparatus. Specific examples have been used to illustrate the principles and implementation methods of the present invention. The descriptions of the above embodiments are only for the purpose of helping to understand the method and core ideas of the present invention. At the same time, those skilled in the art will recognize that there will be changes in the specific implementation methods and application scope based on the ideas of the present invention. Therefore, the content of this specification should not be construed as a limitation of the present invention.

Claims

1. A method for identifying Internet of Things (IoT) devices, characterized in that, include: Extract the anomaly features and length features of data packets from IoT devices, and construct multivariate time-series features based on the anomaly features and length features; The multivariate time-series features are input into the fully trained device recognition model to obtain the recognition results of IoT devices; The device identification model includes a first Inception module, a first residual structure, a second Inception module, a second residual structure, a global average pooling layer, and a fully connected layer. Both the first Inception module and the second Inception module include a first Inception structure, a second Inception structure, and a third Inception structure connected in sequence; each of the first Inception structure, the second Inception structure, and the third Inception structure includes a feature compression unit, a multi-scale convolution unit, and a feature fusion unit; a residual structure is added between every three Inception structures, which allows the input of the first Inception structure to be quickly accumulated into the input of the next Inception structure; The feature compression unit is used to compress the input features to obtain compressed features; The multi-scale convolutional unit is used to perform multi-scale convolution on the input features to obtain multiple convolutional features with different scales. The feature fusion unit is used to fuse the compressed features and the multiple convolutional features; The feature compression unit includes a first global average pooling layer and a first convolutional layer connected in sequence; The multi-scale convolutional unit includes a bottleneck layer and a second, third, and fourth convolutional layer connected to the bottleneck layer, wherein the kernel sizes of the second, third, and fourth convolutional layers are all different. The feature fusion unit comprises a deep convolutional layer, a batch normalization layer, and an activation function layer connected in sequence.

2. The IoT device identification method according to claim 1, characterized in that, The anomaly characteristics include anomaly level, anomaly grouping, and top-level protocol type.

3. The IoT device identification method according to claim 1, characterized in that, Extract the length characteristics of data packets from IoT devices, including: Determine the outbound and inbound traffic in the data packets of the IoT devices; The outbound traffic and inbound traffic are concatenated in chronological order to obtain the target traffic, and the length of the target traffic is used as the length feature.

4. The IoT device identification method according to claim 3, characterized in that, Determining the outbound and inbound traffic in the data packets of the IoT device includes: Acquire the raw data stream; the raw data stream includes multiple data packets from multiple IoT devices; Based on the binary information, the first data packet with the source MAC address of the target IoT device and the second data packet with the destination MAC address of the target IoT device are determined from the multiple data packets. The first data packet is taken as the outbound traffic and the second data packet is taken as the inbound traffic.

5. The IoT device identification method according to claim 1, characterized in that, Multivariate time-series features are constructed based on the aforementioned anomaly features and the aforementioned length features, including: The data packets of the IoT device are divided based on a preset sequence length to obtain multiple time-series features; The temporal features of each segment are filled with a preset filling rule to obtain the multivariate temporal features; The number of rows in the multivariate time series feature is the same as the number of types of the anomaly feature and the time series feature, and the number of columns in the multivariate time series feature is the same as the number of segments in the multi-segment time series feature.

6. An Internet of Things (IoT) device identification device, characterized in that, The apparatus is applicable to the IoT device identification method according to any one of claims 1-5, wherein the apparatus comprises: A multidimensional feature extraction unit is used to extract the abnormal features and length features of data packets from IoT devices, and to construct multivariate temporal features based on the abnormal features and length features; The device identification unit is used to input the multivariate time-series features into the fully trained device identification model to obtain the identification result of the Internet of Things device; The device identification model includes a first Inception module, a first residual structure, a second Inception module, a second residual structure, a global average pooling layer, and a fully connected layer.

Citation Information

Patent Citations

  • Internet of Things equipment identification model based on session spatio-temporal characteristic phase residual error

    CN115331068A

  • Internet of Things equipment identification method and system based on fingerprint deep extraction technology

    CN116886314A