Communication analysis method based on Internet of Things

By building a hierarchical information flow model in the Internet of Things environment and using CSP models for analysis, combining historical data optimization algorithms and self-learning mechanisms, the problems of poor adaptability and insufficient privacy protection in the Internet of Things environment are solved, and more efficient data flow capture and privacy protection are achieved.

CN120128607APending Publication Date: 2025-06-10魏承敏
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510314273.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-17
Publication Date
2025-06-10

AI Technical Summary

Technical Problem

Traditional communication analysis methods are difficult to capture complex dynamic information flows, poor adaptive heterogeneity, insufficient privacy protection and efficiency improvement, especially in IoT environments.

Method used

Using the Internet of Things communication analysis method, we collect communication data from IoT devices, build a layered information flow model, use the CSP model to perform local information flow analysis, generate privacy protection strategies, and optimize the information flow modeling algorithm through historical data, and introduce a self-learning mechanism.

Benefits of technology

It significantly improves the ability to capture dynamic and multi-source data flows, achieves more effective privacy protection and communication path optimization, and improves the stability and response capabilities of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120128607A_ABST
    Figure CN120128607A_ABST
Patent Text Reader

Abstract

The invention discloses a communication analysis method based on the Internet of Things, and relates to the technical field of communication analys.The method comprises the steps that a layered information flow model is constructed, local features and global features of communication data are separated, a local layer focuses on data flow behavior in single equipment, and interaction logic between nodes is quantized; the global layer integrates an interaction relationship between devices, generates a complete network view, comprehensively captures complex interaction behaviors between the devices, adopts a CSP model at a device side to monitor a data flow event, expresses internal behavior logic and constraint conditions of the devices through a formalized language, and facilitates real-time analysis of a data path and a sensitive data flow direction; when an abnormal behavior is detected, triggering deep analysis based on an event-driven strategy, expanding to a global range, and quantifying the risk through abnormal propagation path modeling and sensitive data risk scoring; in addition, dynamic privacy protection policies are generated, including restrictions of sensitive data flow, encrypted transmissions, and adjustments of communication paths.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of communication analysis, and particularly to a communication analysis method based on the Internet of Things. Background Art

[0002] The rapid development of Internet of Things technology has brought profound changes to fields such as smart home, smart city, and industrial control. A large number of devices transmit data through communication networks, constructing an unprecedented connection ecosystem.

[0003] Communication analysis methods play an important role in data transmission efficiency and system stability. Traditional methods mainly use static analysis or dynamic tracking for monitoring and verification; static analysis can detect problems in advance through code review and model verification, but it is often powerless against complex data flows in dynamic scenarios; dynamic tracking captures data flow directions in real time during operation, enabling more flexible handling of dynamic changes, but its implementation cost is high and there are performance bottlenecks; these methods perform well in a single and controllable environment, but in the Internet of Things environment with a large number of devices, heterogeneity, and complex data interaction patterns, their effects are difficult to meet the requirements.

[0004] Especially in the Internet of Things scenario, due to the large number of devices, heterogeneity of hardware capabilities and communication protocols, and complexity of dynamic communication behaviors, traditional communication analysis is difficult to capture the information flow paths across devices and cannot effectively prevent privacy leakage caused by multi-device collaboration; some traditional solutions attempt to optimize efficiency and accuracy through distributed analysis and hybrid analysis modes, but still difficult to fundamentally solve the dynamic association problems in complex information flows. There is an urgent need for an innovative communication analysis method that is more suitable for the Internet of Things environment. Summary of the Invention

[0005] In view of the above existing problems, the present invention is proposed.

[0006] The present invention provides a communication analysis method based on the Internet of Things to solve the problems that traditional solutions are difficult to capture complex dynamic information flows, have poor adaptability to heterogeneity, and are insufficient in privacy protection and efficiency improvement.

[0007] To solve the above technical problems, the present invention provides the following technical solutions:

[0008] An embodiment of the present invention provides a communication analysis method based on the Internet of Things, which includes,

[0009] Step S1, collecting communication data from Internet of Things devices, including sensor inputs, communication logs, and data flow directions;

[0010] Step S2, constructing a hierarchical information flow model based on the communication data preprocessed in step S1;

[0011] Step S3: Capture data stream events on the device side, convert them into a Communicating Sequential Processes (CSP) model, and perform local information flow analysis;

[0012] Step S4: Generate targeted privacy protection policies based on the analysis results of Step S3;

[0013] Step S5: Continuously optimize the information flow modeling algorithm using historical data;

[0014] In Step S5, by collecting and analyzing the behavior patterns and anomaly records in historical data, dynamically adjust the information flow modeling algorithm in Step S2 and introduce a self-learning mechanism.

[0015] As a preferred solution of the communication analysis method based on the Internet of Things according to the present invention, in the communication data collection process, standard protocols are used to uniformly encapsulate data in different formats, and at the same time, edge computing technology is used to complete data preprocessing at the collection end, including data denoising and compression.

[0016] As a preferred solution of the communication analysis method based on the Internet of Things according to the present invention, the hierarchical information flow model includes a local layer and a global layer. The local layer models the information flow behavior of a single Internet of Things device, extracts its data stream characteristics, and describes the key data flow directions and interaction logics inside the device; the global layer integrates the data interaction relationships between multiple devices to form an overall network view and describes the cooperation modes and data transfer paths between devices.

[0017] As a preferred solution of the communication analysis method based on the Internet of Things according to the present invention, the steps of constructing a hierarchical information flow model based on the communication data preprocessed in Step S1 are as follows:

[0018] Extract the local device data set L and the global interaction data set G from the preprocessed communication data D. The extraction formulas are:

[0019]

[0020] where D represents the set of preprocessed communication data, L represents the set of data characteristics of the local device layer, m represents the number of devices, l i represents the original data set of device i, f(l i ) is the local data feature extraction function, G represents the set of global interaction data features, and g(D) is the global data feature extraction function.

[0021] For a single device l i , construct its information flow matrix M i , which is expressed as:

[0022]

[0023] Among them, M i represents the information flow matrix of device i, k represents the number of logical nodes inside the device, and p xy represents the data flow weight from node x to node y inside the device;

[0024] Integrate the local feature matrices M i of all m devices and the interaction weights E ij between devices to construct the global information flow matrix N, which is expressed as:

[0025]

[0026] Among them, N represents the global information flow matrix, M i represents the local information flow matrix of device i, and E ij represents the data interaction weight between device i and device j.

[0027] As a preferred solution of the communication analysis method based on the Internet of Things according to the present invention, wherein: the local information flow analysis monitors the data flow of a single device through the CSP model, and analyzes its path, the flow direction of sensitive data, and the interaction behavior between devices in real time. An event-driven strategy is introduced in the analysis, and in-depth analysis is triggered when an abnormal behavior is detected;

[0028] The in-depth analysis combines the hierarchical information flow model constructed in step S2, extends the local analysis to the global scope, analyzes the cross-device propagation characteristics of abnormal behaviors and the risk of sensitive data leakage, and outputs the analysis results of abnormal impacts.

[0029] As a preferred solution of the communication analysis method based on the Internet of Things according to the present invention, wherein: the step of capturing data flow events on the device side and converting them into a communication sequential process CSP model for local information flow analysis is,

[0030] Capture data flow event e k on the device side to form an event set E:

[0031] E = {e k |e k = (s k , d k , t k ), k = 1, 2,..., p},

[0032] Among them, E represents the set of all captured data flow events, e k represents the kth data flow event, s k represents the source node of the event, d k represents the target node of the event, t k represents the timestamp when the event occurs, and p represents the number of captured events;

[0033] Based on E, model the event path for each device to form a path set P:

[0034] P = {p i | p i = (e 1 → e 2 → … → e n ), i = 1, 2, …, q},

[0035] where P represents the set of data flow paths on the device side, p i represents the data flow path of device i, e n represents the nth event in the path, and q represents the number of devices,

[0036] Based on the path set P, convert the data flow into a Communicating Sequential Processes model C:

[0037] C = {C i | C i = <A i , R i , O i >, i = 1, 2, …, q},

[0038] where C represents the set of CSP models of all devices, C i represents the CSP model of device i, A i represents the set of activities of device i, R i represents the constraint rules of device i, and O i represents the output behavior of device i,

[0039] By monitoring A i , R i , O i in C i in real time, analyze the data flow behavior and sensitive data flow direction of device i. The analysis formula is:

[0040] F i = Analyze(C i , Event Stream (E i ))

[0041] where F i represents the local information flow analysis result of device i, Analyze represents the information flow analysis function, and Event Stream (E i ) represents the real-time event flow of device i.

[0042] As a preferred solution of the communication analysis method based on the Internet of Things according to the present invention, wherein: the step of triggering in-depth analysis when detecting abnormal behavior is as follows,

[0043] Based on the local information flow model C on the device side i , define the abnormal detection rule R a :

[0044] R a ={r k |r k =v(C i ,e k ),k = 1,2,...,t},

[0045] wherein, R a represents the abnormal detection rule set, r k represents the k-th abnormal rule, v(C i ,e k ) represents the abnormal determination function based on the CSP model C i of the device i and the event e k , and t represents the number of defined abnormal rules,

[0046] When detecting behavior that does not conform to R a , record the abnormal behavior set A:

[0047] A={a k |a k =(e k ,r k ),k = 1,2,...,v},

[0048] wherein, A represents the captured abnormal behavior set, a k represents the k-th abnormal behavior, e k represents the event that triggers the abnormality, r k represents the corresponding abnormal rule, and v represents the number of captured abnormalities,

[0049] Combine the hierarchical information flow model constructed in step S2 to extend the local abnormal analysis to the global scope, and record the abnormal propagation path P a :

[0050] P a ={p i |p i =(e i1 →e i2 →…→e in ),i = 1,2,...,w},

[0051] wherein, P a represents the abnormal propagation path set, p iDenote the i-th abnormal propagation path as e ij Denote the j-th abnormal event in the path as w, and w represents the number of captured abnormal propagation paths;

[0052] Based on the propagation path P a , quantify the impact of the anomaly on sensitive data and generate a sensitive data risk score S:

[0053]

[0054] where S represents the sensitive data risk score, and ψ(e ij , d) represents the risk assessment function of event e ij on the data in the sensitive data set d, and d represents the sensitive data set;

[0055] Integrate A, P a , S to generate an abnormal impact analysis result set R o :

[0056] R o = {(A, P a , S)},

[0057] where R o represents the abnormal impact analysis result, A represents the captured abnormal behavior, P a represents the abnormal propagation path set, and S represents the sensitive data risk score.

[0058] As a preferred solution of the communication analysis method based on the Internet of Things described in the present invention, wherein: the privacy protection strategy includes but is not limited to the following: dynamically restricting the flow of sensitive data, dynamically adjusting the communication path, and encrypting the transmission of key data; when the edge node analysis cannot fully determine the problem, a warning signal is sent to the cloud, triggering an advanced dynamic constraint check, and the cloud further confirms the problem source by integrating global data and historical records and optimizes the protection strategy.

[0059] As a preferred solution of the communication analysis method based on the Internet of Things described in the present invention, wherein: the step of generating a targeted privacy protection strategy according to the analysis result of step S3 is

[0060] According to the sensitive data risk score S in step S3, define a dynamic restriction strategy set L s :

[0061] L s = {l k |l k = η(d k , S), k = 1, 2,..., n},

[0062] where L sDenote the set of dynamic restriction policies, l k Denote the restriction policy for sensitive data d k η(d k , S) represents the dynamic restriction function based on data d k and risk score S, where n represents the number of sensitive data items;

[0063] Based on the abnormal propagation path P a , optimize the communication path set T, and the optimization formula is:

[0064] T = {t i | t i = γ(p i ), i = 1, 2, …, m},

[0065] where T represents the optimized communication path set, t i represents the i-th communication path, and γ(p i ) represents the communication path adjustment function based on the abnormal propagation path p i , and m represents the number of communication paths;

[0066] For the critical data set D k , generate the encryption policy set E c :

[0067] E c = {e k | e k = λ(d k ), k = 1, 2, …, n},

[0068] where E c represents the data encryption policy set, e k represents the encryption policy for sensitive data d k , and λ(d k ) represents the data encryption policy generation function;

[0069] When the edge node cannot fully determine the problem, send a warning signal W to the cloud:

[0070] W = {C i , A, S},

[0071] where W represents the warning signal set, C i represents the local device model, A represents the set of abnormal behaviors, and S represents the risk score.

[0072] As a preferred solution of the communication analysis method based on the Internet of Things described in the present invention, wherein: the step of continuously optimizing the information flow modeling algorithm by using historical data is

[0073] Extract the set of behavior patterns H from historical data:

[0074] H = {h i | h i = ξ(d i , t i ), i = 1, 2, …, n},

[0075] where H represents the set of historical behavior patterns, h i represents the i-th historical behavior pattern, ξ(d i , t i ) represents the behavior pattern function extracted based on data d i and time t i , n represents the number of historical data records,

[0076] Based on the set of behavior patterns H, adjust the set of information flow modeling parameters P m :

[0077] P m = {p k | p k = ζ(h k ), k = 1, 2, …, m},

[0078] where P m represents the set of information flow modeling parameters, p k represents the k-th modeling parameter, ζ(h k ) represents the function for optimizing parameters based on the historical behavior pattern h k , m represents the number of modeling parameters;

[0079] Based on the updated set of modeling parameters P m , generate the self-learning optimization model M opt :

[0080] M opt = Learn(M, P m , H),

[0081] where M opt represents the optimized information flow modeling algorithm, Learn represents the self-learning optimization function, M represents the initial information flow modeling algorithm, P m represents the optimized set of modeling parameters, and H represents the set of historical behavior patterns.

[0082] The beneficial effects of the present invention are as follows: The present invention constructs a hierarchical information flow model to separate the local features and global features of communication data. The local layer focuses on the data flow behavior within a single device, quantifying the interaction logic between nodes; the global layer integrates the interaction relationships between devices to generate a complete network view, comprehensively capturing the complex interaction behaviors between devices, and significantly improving the ability to capture dynamic and multi-source data flows; on the device side, the CSP model is used to monitor data flow events, and the internal behavior logic and constraint conditions of the device are expressed through a formal language, facilitating real-time analysis of the data path and the flow direction of sensitive data; when an abnormal behavior is detected, a depth analysis is triggered based on an event-driven strategy, extended to the global scope, and the risk is quantified through abnormal propagation path modeling and sensitive data risk scoring, accurately evaluating the impact of the abnormal behavior on sensitive data; in addition, dynamic privacy protection strategies are generated, including restrictions on the flow direction of sensitive data, encrypted transmission, and adjustment of the communication path; when edge analysis cannot fully confirm the problem, a warning signal is uploaded to the cloud, and the strategy is optimized by integrating global data and historical records, realizing cloud-edge collaborative protection; in terms of long-term optimization, a self-learning mechanism is introduced, and the information flow modeling parameters are dynamically adjusted using historical data to continuously improve the adaptability of the model to new data flow behaviors and complex dynamic environments.

[0083] In summary, the present invention provides a more efficient and reliable solution for communication analysis and privacy protection in the Internet of Things scenario. BRIEF DESCRIPTION OF THE DRAWINGS

[0084] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0085] Figure 1 It is a flowchart of the communication analysis method based on the Internet of Things of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0086] In order to make the above objects, features, and advantages of the present invention more obvious and understandable, the following will make a detailed description of the specific embodiments of the present invention in conjunction with the drawings of the specification.

[0087] In the following description, many specific details are set forth in order to fully understand the present invention. However, the present invention can also be implemented in other ways different from those described herein. Those skilled in the art can make similar extensions without departing from the connotation of the present invention. Therefore, the present invention is not limited by the specific embodiments disclosed below.

[0088] Second, the "one embodiment" or "embodiment" referred to herein means a specific feature, structure, or characteristic that may be included in at least one implementation of the present invention. The phrase "in one embodiment" appearing in different places in this specification does not necessarily refer to the same embodiment, nor is it an individual or alternative embodiment that is mutually exclusive with other embodiments.

[0089] Embodiment 1, referring to Figure 1 , this embodiment provides a communication analysis method based on the Internet of Things, including the following steps:

[0090] Step S1, collect communication data from Internet of Things devices, including sensor inputs, communication logs, and data flow directions;

[0091] During the communication data collection process, standardize protocols to uniformly encapsulate data in different formats, and at the same time use edge computing technology to complete data preprocessing at the collection end, including data denoising and compression;

[0092] Step S2, based on the preprocessed communication data in Step S1, construct a hierarchical information flow model;

[0093] The hierarchical information flow model includes a local layer and a global layer. The local layer models the information flow behavior of a single Internet of Things device, extracts its data flow characteristics, and describes the key data flow directions and interaction logics inside the device; the global layer integrates the data interaction relationships between multiple devices to form an overall network view, and describes the cooperation modes and data transfer paths between devices;

[0094] The steps to construct a hierarchical information flow model based on the preprocessed communication data in Step S1 are as follows:

[0095] From the preprocessed communication data D, extract the local device data set L and the global interaction data set G. The extraction formulas are:

[0096]

[0097] where D represents the set of preprocessed communication data, L represents the set of data characteristics of the local device layer, m represents the number of devices, l i represents the original data set of device i, f(l i ) is the local data feature extraction function, G represents the set of global interaction data characteristics, and g(D) is the global data feature extraction function.

[0098] For a single device l i , construct its information flow matrix M i , expressed as:

[0099]

[0100] where Mi represents the information flow matrix of device i, k represents the number of logical nodes inside the device, and p xy represents the data flow weight from node x to node y inside the device;

[0101] Integrate the local feature matrices M of all m devices i and the interaction weights E between devices ij , and construct the global information flow matrix N, which is expressed as:

[0102]

[0103] where N represents the global information flow matrix, M i represents the local information flow matrix of device i, and E ij represents the data interaction weight between device i and device j;

[0104] Specifically, in step S2, by separating the local and global features of communication data, the information flow characteristics inside the device and across devices are extracted respectively. The local information flow matrix describes the key data flow behaviors inside a single device, quantifies the interaction logic between nodes, and the global information flow matrix constructs a complete network view by integrating the interaction weights between devices.

[0105] In step S3, capture the data flow events on the device side and convert them into a Communicating Sequential Processes (CSP) model for local information flow analysis;

[0106] Local information flow analysis monitors the data flow of a single device through the CSP model, and analyzes its path, the flow direction of sensitive data, and the interaction behaviors between devices in real time. An event-driven strategy is introduced in the analysis, and in-depth analysis is triggered when abnormal behaviors are detected;

[0107] In-depth analysis combines the hierarchical information flow model constructed in step S2, extends the local analysis to the global scope, analyzes the cross-device propagation characteristics of abnormal behaviors and the risk of sensitive data leakage, and outputs the analysis results of the impact of anomalies;

[0108] The steps of capturing the data flow events on the device side and converting them into a CSP model for local information flow analysis are as follows

[0109] Capture the data flow event e on the device side k , and form an event set E:

[0110] E = {e k |e k =(s k ,d k ,t k ), k = 1, 2, …, p},

[0111] Among them, E represents the set of all captured data stream events, and e k represents the k-th data stream event, s k represents the source node of the event, d k represents the target node of the event, t k represents the timestamp when the event occurs, and p represents the number of captured events;

[0112] Based on E, model the event paths of each device to form a path set P:

[0113] P = {p i |p i = (e 1 →e 2 →…→e n ), i = 1, 2, …, q},

[0114] Among them, P represents the set of data stream paths on the device side, p i represents the data stream path of device i, e n represents the n-th event in the path, and q represents the number of devices,

[0115] Based on the path set P, convert the data stream into a Communicating Sequential Processes model C:

[0116] C = {C i |C i = <A i , R i , O i >, i = 1, 2, …, q},

[0117] Among them, C represents the set of CSP models of all devices, C i represents the CSP model of device i, A i represents the set of activities of device i, R i represents the constraint rules of device i, O i represents the output behavior of device i,

[0118] By monitoring A i , R i , O i in C i in real time, analyze the data flow behavior and sensitive data flow direction of device i. The analysis formula is:

[0119] F i = Analyze(C i , Event Stream (E i ))

[0120] Among them, F iRepresents the local information flow analysis result of device i, Analyze represents the information flow analysis function, Event Stream (E i ) represents the real-time event stream of device i;

[0121] Specifically, step S3 captures data flow events on the device side, constructs paths and converts them into a CSP model to monitor the local data flow of the device; introducing the CSP model, expressing the internal behavior logic and constraint conditions of the device in a formal language for easy analysis.

[0122] The steps to trigger in-depth analysis when detecting abnormal behavior are as follows.

[0123] Based on the local information flow model C on the device side i , define the abnormal detection rule R a :

[0124] R a ={r k |r k =φ(C i ,e k ),k = 1,2,…,t},

[0125] where, R a represents the abnormal detection rule set, r k represents the k-th abnormal rule, φ(C i ,e k ) represents the abnormal determination function based on the CSP model C i of device i and event e k , t represents the number of defined abnormal rules,

[0126] When detecting behavior that does not conform to R a , record the abnormal behavior set A:

[0127] A={a k |a k =(e k ,r k ),k = 1,2,…,v},

[0128] where, A represents the captured abnormal behavior set, a k represents the k-th abnormal behavior, e k represents the event that triggers the abnormality, r k represents the corresponding abnormal rule, v represents the number of captured abnormalities,

[0129] Combined with the hierarchical information flow model constructed in step S2, extend the local abnormal analysis to the global scope and record the abnormal propagation path P a :

[0130] Pa = {p i | p i = (e i1 → e i2 → … → e in ), i = 1, 2, …, w},

[0131] where P a represents the set of exception propagation paths, p i represents the i-th exception propagation path, e ij represents the j-th exception event in the path, and w represents the number of captured exception propagation paths;

[0132] Based on the propagation path P a , quantify the impact of the exception on sensitive data and generate a sensitive data risk score S:

[0133]

[0134] where S represents the sensitive data risk score, ψ(e ij , d) represents the risk assessment function of event e ij on the data in the sensitive data set d, and d represents the sensitive data set;

[0135] Integrate A, P a , S to generate an exception impact analysis result set R o :

[0136] R o = {(A, P a , S)},

[0137] where R o represents the exception impact analysis result, A represents the captured exception behavior, P a represents the set of exception propagation paths, and S represents the sensitive data risk score;

[0138] Specifically, in this step, capture the exception behavior, extend the local analysis to the global scope, and combine with the hierarchical information flow model to comprehensively evaluate the impact of the exception behavior and its propagation risk, model the exception propagation path, and quantify the risk using the sensitive data risk score, making the analysis result more specific and operable and reducing the impact scope of potential security hazards.

[0139] Step S4, generate a targeted privacy protection strategy according to the analysis result of step S3;

[0140] The privacy protection policies include, but are not limited to, the following: dynamically restricting the flow of sensitive data, dynamically adjusting the communication path, and encrypting the transmission of critical data; when the edge node analysis cannot fully determine the problem, sending a warning signal to the cloud to trigger an advanced dynamic constraint check. The cloud further confirms the source of the problem by integrating global data and historical records and optimizes the protection policies;

[0141] According to the analysis result of step S3, the steps to generate targeted privacy protection policies are as follows:

[0142] Define the dynamic restriction policy set L according to the sensitive data risk score S in step S3 s :

[0143] L s ={l k |l k =η(d k ,S),k = 1,2,…,n},

[0144] where L s represents the dynamic restriction policy set, l k represents the restriction policy for sensitive data d k , η(d k ,S) represents the dynamic restriction function based on data d k and risk score S, and n represents the number of sensitive data items;

[0145] Based on the abnormal propagation path P a , optimize the communication path set T, and the optimization formula is:

[0146] T={t i |t i =γ(p i ),i = 1,2,…,m},

[0147] where T represents the optimized communication path set, t i represents the i-th communication path, and γ(p i ) represents the communication path adjustment function based on the abnormal propagation path p i , and m represents the number of communication paths;

[0148] For the critical data set D k , generate the encryption policy set E c :

[0149] E c ={e k |e k =λ(d k ),k = 1,2,…,n},

[0150] where Ec Represents a set of data encryption policies, e k Represents the encryption policy for sensitive data d k The encryption policy of, λ(d k ) represents the data encryption policy generation function;

[0151] When the edge node cannot fully determine the problem, a warning signal W is sent to the cloud:

[0152] W = {C i , A, S},

[0153] where W represents the warning signal set, C i Represents the local device model, A represents the set of abnormal behaviors, and S represents the risk score;

[0154] Specifically, step S4, according to the abnormal analysis result, realizes a multi-level privacy protection scheme by dynamically restricting the flow of sensitive data, optimizing the communication path, generating encryption policies, and triggering advanced dynamic checks, and dynamically restricts the flow of sensitive data to be secure; the encryption policy further improves the data protection intensity. When the edge node cannot fully process the problem, the cloud comprehensively optimizes the protection policy based on global data to ensure the overall privacy security and response efficiency.

[0155] Step S5, continuously optimize the information flow modeling algorithm using historical data;

[0156] In step S5, by collecting and analyzing the behavior patterns and abnormal records in historical data, the information flow modeling algorithm in step S2 is dynamically adjusted, and a self-learning mechanism is introduced;

[0157] The steps of continuously optimizing the information flow modeling algorithm using historical data are,

[0158] Extract the set of behavior patterns H from historical data:

[0159] H = {h i |h i = ξ(d i , t i ), i = 1, 2,..., n},

[0160] where H represents the set of historical behavior patterns, h i Represents the i-th historical behavior pattern, ξ(d i , t i ) represents the behavior pattern function extracted based on data d i and time t i The number of historical data records,

[0161] Based on the set of behavior patterns H, adjust the set of information flow modeling parameters P m :

[0162] P m = {p k | p k = ζ(h k ), k = 1, 2, …, m},

[0163] where P m represents the set of information flow modeling parameters, p k represents the k-th modeling parameter, ζ(h k ) represents a function for optimizing parameters based on the historical behavior pattern h k , and m represents the number of modeling parameters;

[0164] Based on the updated set of modeling parameters P m , generate a self-learning optimization model M opt :

[0165] M opt = Learn(M, P m , H),

[0166] where M opt represents the optimized information flow modeling algorithm, Learn represents the self-learning optimization function, M represents the initial information flow modeling algorithm, P m represents the optimized set of modeling parameters, and H represents the set of historical behavior patterns;

[0167] Specifically, in step S5, by analyzing the behavior patterns in the historical data, the information flow modeling parameters are dynamically optimized, and a self-learning mechanism is introduced to continuously improve the adaptability and accuracy of the algorithm, enhance the accuracy of information flow modeling, and improve the response ability of the model to complex dynamic environments.

[0168] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the present invention, and they should all be covered by the scope of the claims of the present invention.

Claims

1. A communication analysis method based on the Internet of Things, characterized in that: include, Step S1, collecting communication data from IoT devices, including sensor input, communication logs, and data flow; Step S2, constructing a hierarchical information flow model based on the communication data preprocessed in step S1; Step S3, capturing data flow events on the device side and converting them into a communication sequence process CSP model to perform local information flow analysis; Step S4, generating a targeted privacy protection strategy based on the analysis result of step S3; Step S5, continuously optimizing the information flow modeling algorithm using historical data; In step S5, by collecting and analyzing the behavior patterns and abnormal records in the historical data, the information flow modeling algorithm in step S2 is dynamically adjusted and a self-learning mechanism is introduced.

2. A communication analysis method based on the Internet of Things as claimed in claim 1, characterized in that: During the communication data collection process, a standardized protocol is used to uniformly encapsulate data in different formats, and edge computing technology is used to complete data preprocessing at the collection end, including data denoising and compression.

3. A communication analysis method based on the Internet of Things as described in claim 2, characterized in that: The hierarchical information flow model includes a local layer and a global layer. The local layer models the information flow behavior of a single IoT device and extracts its data flow characteristics. Describes the key data flow and interaction logic within the device; the global layer integrates the data interaction relationship between multiple devices to form an overall network view, describing the collaboration mode and data transmission path between devices.

4. A communication analysis method based on the Internet of Things as claimed in claim 3, characterized in that: The step of constructing a hierarchical information flow model based on the communication data preprocessed in step S1 is: From the preprocessed communication data D, extract the local device data set L and the global interaction data set G. The extraction formula is: Where D represents the preprocessed communication data set, L represents the data feature set of the local device layer, m represents the number of devices, and l i represents the original data set of device i, f(l i ) is the local data feature extraction function, G represents the global interaction data feature set, g(D) is the global data feature extraction function, For a single device i , construct its information flow matrix M i , expressed as: Among them, M i represents the information flow matrix of device i, k represents the number of logical nodes inside the device, and p xy Indicates the weight of the data flow from node x to node y within the device; Integrate the local feature matrix M of all m devices i and the interaction weight E between devices ij , construct the global information flow matrix N, expressed as: Where N represents the global information flow matrix, M i represents the local information flow matrix of device i, E ij Represents the data interaction weight between device i and device j.

5. A communication analysis method based on the Internet of Things as claimed in claim 4, characterized in that: The local information flow analysis monitors the data flow of a single device through the CSP model, analyzes its path, the flow of sensitive data and the interaction between devices in real time, introduces event-driven strategies in the analysis, and triggers in-depth analysis when abnormal behavior is detected; The in-depth analysis is combined with the hierarchical information flow model constructed in step S2 to expand the local analysis to the global scope, analyze the cross-device propagation characteristics of abnormal behavior and the risk of sensitive data leakage, and output the abnormal impact analysis results.

6. A communication analysis method based on the Internet of Things as claimed in claim 5, characterized in that: The steps of capturing data flow events on the device side and converting them into a communication sequence process CSP model and performing local information flow analysis are: Capture data stream events on the device side k , forming the event set E: E={e k |e k =(s k ,d k ,t k ),k=1,2,…,p}, Among them, E represents the set of all captured data flow events, e k represents the kth data stream event, s k Indicates the source node of the event, d k Indicates the target node of the event, t k represents the timestamp of the event, and p represents the number of events captured; Based on E, the event path of each device is modeled to form a path set P: P={p i |p i =(e1→e2→…→e n ),i=1,2,…,q}, Where P represents the set of data flow paths on the device side, p i represents the data flow path of device i, e n represents the nth event in the path, q represents the number of devices, Based on the path set P, the data flow is transformed into a communication sequence process model C: C={C i |C i =<A i ,R i ,O i >,i=1,2,…,q}, Where C represents the CSP model set of all devices, C i represents the CSP model of device i, A i represents the activity set of device i, R i represents the constraint rules of device i, O i Indicates the output behavior of device i, By real-time monitoring C i A in i , R i , O i , analyze the data flow behavior and sensitive data flow direction of device i, the analysis formula is: F i =Analyze(C i ,Event Stream (E i )), Among them, F i Indicates the local information flow analysis result of device i, Analyze indicates the information flow analysis function, Event Stream (E i ) represents the real-time event stream of device i.

7. A communication analysis method based on the Internet of Things as claimed in claim 6, characterized in that: The step of triggering deep analysis when abnormal behavior is detected is: Local information flow model based on the device side C i , define the anomaly detection rule R a : R a ={r k |r k =v(C i ,e k ),k=1,2,…,t}, Among them, R a represents the set of anomaly detection rules, r k represents the kth abnormal rule, v(C i ,e k ) represents the CSP model C based on device i i and event k The anomaly determination function, t represents the number of defined anomaly rules, When it is detected that R a When the behavior is , record the abnormal behavior set A: A={a k |a k =(e k ,r k ),k=1,2,…,v}, Among them, A represents the set of abnormal behaviors captured, a k represents the kth abnormal behavior, e k Indicates the event that triggers the exception, r k Indicates the corresponding exception rule, v indicates the number of exceptions captured, Combined with the hierarchical information flow model constructed in step S2, the local anomaly analysis is extended to the global scope, and the anomaly propagation path P is recorded. a : P a ={p i |p i =(e i1 →e i2 →…→e in ),i=1,2,…,w}, Among them, P a represents the set of abnormal propagation paths, p i represents the ith abnormal propagation path, e ij represents the jth abnormal event in the path, and w represents the number of abnormal propagation paths captured; Based on the propagation path P a , quantify the impact of anomalies on sensitive data and generate a sensitive data risk score S: Among them, S represents the risk score of sensitive data, ψ(e ij ,d) represents event e ij The risk assessment function for the data in the sensitive data set d, where d represents the sensitive data set; Comprehensive A, P a , S, generate the abnormal impact analysis result set R o : R o ={(A,P a ,S)}, Among them, R o Indicates the abnormal impact analysis results, A indicates the captured abnormal behavior, P a represents the set of abnormal propagation paths, and S represents the sensitive data risk score.

8. A communication analysis method based on the Internet of Things as claimed in claim 7, characterized in that: The privacy protection strategy includes but is not limited to the following: dynamically restricting the flow of sensitive data, dynamically adjusting communication paths, and encrypting the transmission of key data; when the edge node analysis cannot fully determine the problem, a warning signal is sent to the cloud, triggering an advanced dynamic constraint check, and the cloud will further confirm the source of the problem through comprehensive global data and historical records, and optimize the protection strategy.

9. A communication analysis method based on the Internet of Things as claimed in claim 8, characterized in that: The step of generating a targeted privacy protection strategy according to the analysis result of step S3 is: According to the sensitive data risk score S in step S3, define the dynamic restriction strategy set L s : L s ={l k |l k =η(d k ,S),k=1,2,…,n}, Among them, L s Represents a set of dynamic restriction policies, l k Indicates sensitive data k The restriction strategy, η(d k ,S) represents the data based on d k and a dynamic restriction function of the risk score S, where n represents the number of sensitive data items; Based on the abnormal propagation path P a , optimize the communication path set T, the optimization formula is: T={t i |t i =γ(p i ),i=1,2,…,m}, Where T represents the optimized communication path set, t i represents the i-th communication path, γ(p i ) represents the abnormal propagation path p i The communication path adjustment function, m represents the number of communication paths; For key data set D k , generate encryption strategy set E c : AND c {e k |and k =λ(d k ),k=1,2,...,n}, Among them, E c Represents a set of data encryption policies, e k Indicates sensitive data k The encryption strategy, λ(d k ) represents the data encryption strategy generation function; When the edge node cannot fully determine the problem, a warning signal W is sent to the cloud: W={C i ,A,S}, Where W represents the set of warning signals, C i represents the local device model, A represents the abnormal behavior set, and S represents the risk score.

10. A communication analysis method based on the Internet of Things as claimed in claim 9, characterized in that: The step of continuously optimizing the information flow modeling algorithm using historical data is: Extract the behavior pattern set H from historical data: H={h i |h i =ξ(d i ,t i ),i=1,2,…,n}, Among them, H represents the set of historical behavior patterns, h i represents the i-th historical behavior pattern, ξ(d i ,t i ) indicates that based on data d i and time t i The extracted behavior pattern function, n represents the number of historical data records, Based on the behavior pattern set H, adjust the information flow modeling parameter set P m : P m ={p k |p k =ζ(h k ),k=1,2,…,m}, Among them, P m represents the information flow modeling parameter set, p k represents the kth modeling parameter, ζ(h k ) represents the historical behavior pattern h k The function of optimizing parameters, m represents the number of modeling parameters; Based on the updated modeling parameter set P m , generate a self-learning optimization model M opt : M opt =Learn(M,P m ,H), Among them, M opt represents the optimized information flow modeling algorithm, Learn represents the self-learning optimization function, M represents the initial information flow modeling algorithm, P m represents the optimized modeling parameter set, and H represents the historical behavior pattern set.

Citation Information

Cited By

  • Low-delay network security detection method and system

    CN120415923A