Internet of Things protocol behavior abnormity real-time detection method based on parallel analysis and semantic modeling

Through the IoT protocol behavior abnormality detection method of parallel analysis and semantic modeling, the problem of inefficient protocol resolution in IoT devices is solved, efficient and accurate real-time abnormality detection is achieved, and the adaptability and stability of IoT security is improved.

CN120474751APending Publication Date: 2025-08-12ZHANGZHOU POWER SUPPLY COMPANY STATE GRID FUJIANELECTRIC POWER +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510549748.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-29
Publication Date
2025-08-12

AI Technical Summary

Technical Problem

IoT devices have low protocol resolution efficiency, difficult to balance real-time and accuracy, and lack multi-dimensional feature fusion, resulting in fragility of security detection and difficulty in dealing with complex attacks.

Method used

The parallel analysis and semantic modeling method is adopted to conduct in-depth analysis of the Internet of Things protocol, establish a frequency and sequential model of the key fields, and conduct real-time anomaly detection in combination with the conditional random field model.

Benefits of technology

It significantly improves the accuracy and stability of detection, shortens detection time, reduces false alarm rate, and improves the dynamic adaptability of IoT security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120474751A_ABST
    Figure CN120474751A_ABST
Patent Text Reader

Abstract

The invention provides an internet of things protocol behavior abnormity real-time detection method based on parallel analysis and semantic modeling, which comprises the following steps: step 1, deeply analyzing an internet of things architecture and an internet of things communication protocol, and analyzing and modeling behavior characteristics of a service protocol from two levels of grammar and semantics; 2, key fields in the protocol serve as main investigation objects, and a protocol behavior model is established according to the occurrence frequency of the key fields and the sequence of the key fields; and step 3, proposing a behavior anomaly detection method based on a service protocol message, and identifying an abnormal condition in a protocol behavior in real time. By applying the technical scheme, the accuracy and stability of anomaly detection can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of security protection technology for the Internet of Things (IoT), and in particular to a real-time detection method for abnormal behavior of IoT protocols based on parallel parsing and semantic modeling. Background Art

[0002] The large-scale deployment of Internet of Things (IoT) devices has driven the intelligent transformation of industries, energy, transportation, and other sectors. However, limited device resources, diverse protocols, and dynamic nature have led to increasingly complex security threats. With the rapid development of IoT technology, traditional network security detection methods (such as signature-based intrusion detection systems) have exposed three core issues in IoT scenarios: First, protocol parsing efficiency is low. Commonly used lightweight protocols in IoT, such as CoAP and MQTT, have compact message structures and highly correlated fields. Traditional sequential parsing methods struggle to meet the real-time demands of high-concurrency scenarios. For example, in the power IoT, sequential parsing of tens of thousands of messages per second can result in detection delays exceeding 100ms, hindering timely response to anomalies. Furthermore, the sheer number and widespread distribution of IoT devices makes traditional manual detection methods difficult to comprehensively monitor. The generally weak computing power of these devices makes it difficult to execute complex security algorithms, leaving them vulnerable to attacks. The limited security vulnerability detection and defense methods are unable to cope with diverse attacks. These factors contribute to the vulnerability of IoT security. Second, semantic anomaly detection capabilities are insufficient. Existing technologies focus primarily on protocol syntax compliance (e.g., field length and checksum), lacking in-depth analysis of protocol behavior logic. Attackers can construct semantically abnormal requests (e.g., forged device control instructions in the power IoT) by combining legitimate fields. Traditional methods have difficulty identifying such attacks. IoT protocols also have poor dynamic adaptability, resulting in frequent changes in their behavior patterns to accommodate business needs. For example, after a device firmware upgrade, the frequency and timing of key protocol fields can change significantly, making it difficult to update detection models based on static rules in a timely manner, rendering the original models ineffective.

[0003] Current IoT security detection technologies have three limitations: First, protocol reverse engineering relies on manual labor, has a low degree of automation, and is susceptible to noise. For example, the Pi project only identifies message structure but cannot extract semantic information, while the Discoverer solution, while capable of semantic analysis, does not consider the dynamic nature of state machines. Second, balancing real-time performance and accuracy is difficult. Deep learning models, such as recurrent neural networks, have high computational complexity when processing long sequences of data, making them difficult to deploy on resource-constrained IoT devices. For example, in certain industrial IoT scenarios, RNN model inference latency exceeds 500ms, failing to meet real-time requirements. Third, multi-dimensional feature integration is insufficient. Existing methods often analyze protocol field frequency or timing in isolation, lacking the collaborative modeling of syntactic and semantic features. For example, in the power IoT, a single field frequency anomaly may be caused by a peak in traffic, but combining the frequency and time intervals of combined fields can more accurately identify attacks. Case studies of big data applications in IoT security demonstrate that analyzing household data using big data technologies and building intelligent recognition models can promptly detect and prevent anomalous behavior, demonstrating that balancing real-time performance and accuracy can be achieved through technological advancement. Summary of the Invention

[0004] In view of this, the purpose of the present invention is to provide a real-time detection method for IoT protocol behavior anomalies based on parallel parsing and semantic modeling to improve the accuracy and stability of anomaly detection.

[0005] To achieve the above objectives, the present invention adopts the following technical solution: a real-time detection method for abnormal behavior of Internet of Things protocols based on parallel parsing and semantic modeling, comprising the following steps: Step 1: Conduct an in-depth analysis of the IoT architecture and IoT communication protocols, analyzing and modeling the behavioral characteristics of the service protocols from both the syntactic and semantic levels. Step 2: Taking the key fields in the protocol as the main investigation object, establish a protocol behavior model based on the frequency of occurrence of the key fields and the order of the keywords; Step 3: Propose a behavior anomaly detection method based on business protocol messages to identify anomalies in protocol behavior in real time.

[0006] In a preferred embodiment, in step 1, for plaintext traffic, the message content and protocol operation are judged to be abnormal from both the grammatical and semantic levels; at the grammatical level, a protocol parallel parsing technology is proposed to extract the key fields of the protocol and their corresponding values from the message, and then these field values are compared one by one with the preset whitelist. Any field value not in the whitelist is regarded as a business security anomaly; at the semantic level, the frequency and sequence of occurrence of protocol keywords are used to establish a protocol behavior model, and based on the protocol behavior model, business operation anomalies are detected; for the power Internet of Things business protocol, its message contains multiple key fields, and the key fields in the message are processed simultaneously.

[0007] In a preferred embodiment, the specific content of step 2 is as follows: Step 21: Count the occurrence frequencies of protocol keywords; Step 22: Count the frequency of protocol keyword combinations; Step 23: Count the time intervals between two keywords that appear before and after each other; Step 24: Build a protocol behavior model to detect abnormal protocol messages.

[0008] In a preferred embodiment, the specific content of step 24 is as follows: Step 241: Construct a protocol behavior model. Specifically, the node attributes include the key field name and the frequency of occurrence, and the edge attributes include the time interval and the frequency of occurrence of the keyword combination. Step 242: Traverse the protocol behavior model graph, and if the occurrence frequency of a key field exceeds a preset threshold, it is determined to be abnormal; Step 243: If the frequency of the keyword combination exceeds the set threshold, it is determined to be abnormal; Step 244: If the time interval between the previous and next keywords deviates from the normal distribution, it is determined to be abnormal.

[0009] In a preferred embodiment, step 3 specifically includes first collecting a data packet observation sequence X from the network data flow in units of network connections, and then marking each data packet with a normality y_i, thereby generating a labeling sequence Y; realizing the conversion from the observation sequence to the labeling sequence, selecting a conditional random field as an efficient sequence labeling model; for each protocol observation sequence within the network connection, where N represents the length of the network connection, and each observation value corresponds to a protocol data packet; according to the constructed protocol behavior model, if there is a protocol anomaly within the connection, the conditional probability of the normal labeling sequence should exceed a preset threshold, thereby determining whether the protocol behavior is abnormal based on the threshold, and the conditional probability ) should be greater than the pre-set threshold , determine whether the protocol behavior is abnormal or not based on the threshold.

[0010] Compared with the existing technology, the present invention has the following beneficial effects: This invention combines parallel parsing technology with semantic modeling methods, successfully overcoming the limitations of traditional Internet of Things security detection in terms of efficiency, accuracy and dynamic adaptability. BRIEF DESCRIPTION OF THE DRAWINGS

[0011] Figure 1 is an overall flow chart of a preferred embodiment of the present invention; Figure 2 A flowchart of network order detection according to a preferred embodiment of the present invention; Figure 3 This is a schematic diagram of parallel parsing of power Internet of Things service protocol messages in a preferred embodiment of the present invention; Figure 4 A schematic diagram of a protocol behavior model according to a preferred embodiment of the present invention; Figure 5 This is a flowchart of protocol behavior anomaly detection in a preferred embodiment of the present invention. DETAILED DESCRIPTION

[0012] The present invention will be further described below with reference to the accompanying drawings and embodiments.

[0013] It should be noted that the following detailed descriptions are illustrative and intended to provide further explanation of the present application. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the art to which the present application belongs.

[0014] It should be noted that the terms used herein are only for describing specific embodiments and are not intended to limit the exemplary embodiments according to the present application; as used herein, unless the context clearly indicates otherwise, the singular form is also intended to include the plural form, and it should be understood that when the terms "comprise" and / or "include" are used in this specification, they indicate the presence of features, steps, operations, devices, components and / or their combinations.

[0015] The present invention proposes a real-time detection method for IoT protocol behavior anomalies based on parallel parsing and semantic modeling. First, the architecture of the IoT and commonly used communication protocols are deeply analyzed, and the behavioral characteristics of the business protocol are analyzed and modeled from the two levels of syntax and semantics. Then, the key fields in the protocol are taken as the main objects of investigation, and a detailed protocol behavior model is established based on the frequency of occurrence of these key fields and the order between them. In addition, the present invention also proposes a behavior anomaly detection method based on business protocol messages, which can identify anomalies in protocol behavior in real time. The technical architecture is as follows: Figure 1The process is shown in Figure 1. Specifically, it includes: Step 1: Conduct an in-depth analysis of the IoT architecture and IoT communication protocols, analyzing and modeling the behavioral characteristics of the business protocols at both the syntactic and semantic levels. This in-depth analysis of the IoT architecture and communication protocols clarifies the environment and basic characteristics of the business protocols, providing background information for subsequent analysis. Modeling the behavioral characteristics of the business protocols at the syntactic and semantic levels enables targeted extraction of key information in subsequent steps.

[0016] Step 2: Take the key fields in the protocol as the main object of investigation, and establish a protocol behavior model based on the frequency of occurrence of the key fields and the order of the keywords; the analysis of the business protocol behavior characteristics in step 1 helps to determine which fields may be key fields, and from which angles (frequency, order) to analyze these key fields. For example, in the analysis of the power Internet of Things business protocol, step 1 understands its message structure and business logic, so that in step 2, multiple key fields in the message can be accurately selected, and their frequency and order of occurrence can be counted according to business rules, and then a protocol behavior model can be constructed. The protocol behavior model defines the characteristics and rules of normal protocol behavior at the semantic level. Step 3: A behavioral anomaly detection method based on service protocol packets is proposed to identify anomalies in protocol behavior in real time. During anomaly detection, Step 3 collects packet observation sequences per network connection. These observation sequences are then analyzed based on the protocol behavior model constructed in Step 2. Specifically, the observed protocol behavior data (such as the occurrence of key fields) is compared with the normal behavior characteristics defined in the model. The conditional random field model is used to calculate the conditional probability and compare it with a preset threshold to determine whether the protocol behavior is abnormal.

[0017] Specifically, the analysis of IoT architecture and communication protocols includes research on IoT architecture and research on IoT-related communication protocols.

[0018] IoT Architecture Research: From a development perspective, the core technology of IoT devices is wireless access, while the cloud focuses on identity device management, message push technology, and mobile front-end development technology to enhance the scene experience. IP interconnection architecture has become the de facto standard for IoT. Figure 2 The components of the Internet of Things (IoT) based on IP architecture are presented. The security objectives of the IoT are essentially the same as those of other networks, primarily encompassing confidentiality, integrity, availability, non-repudiation, and data freshness. Additionally, the IoT's security objectives include privacy, anonymity, and trust.

[0019] Research on IoT-related communication protocols: In order to better complete the parallel parsing of service protocol messages and construct a protocol behavior model, the present invention first studies the communication protocols related to the Internet of Things.

[0020] Adaptation layer protocol - 6LoWPAN The current Internet protocol is based on IP technology. The Internet of Things is an extension of the Internet. Applying IP technology to the Internet of Things can bring many benefits, such as facilitating interoperability with other IP networks, using mature security mechanisms of IP networks, and load balancing.

[0021] ②MTQQ MQTT is a lightweight protocol developed by IBM for the Internet of Things (IoT). Built on top of the TCP / IP layer, it is a crucial component of the IoT and may become the de facto standard. It features QoS, message buffering, and a retransmission mechanism to ensure that messages reach end devices. Its message format is extremely simplified, with the shortest message length being only two bytes. It offers both subscription and publishing modes for efficient message push.

[0022] ③CoAP CoAP is an IoT application layer protocol based on the REST architecture, with a minimum packet length of only 4 bytes. The key difference between CoAP and HTTP is that the former is based on the UDP transport protocol, while the latter is based on the TCP transport protocol. This is primarily due to the complexity of the TCP protocol, which includes complex features such as flow control and retransmission mechanisms, making it difficult to run on resource-constrained embedded devices. In contrast, the UDP protocol is simpler and supports multicast. CoAP provides a request / response communication model, where a CoAP client node sends a request to a server, which responds. Because CoAP uses the UDP transport protocol, CoAP communication does not require a pre-established connection. CoAP also provides a lightweight reliable mechanism. The CoAP protocol consists of two layers: the request / response layer and the session layer. The session layer is responsible for controlling end-to-end message exchange, while the request / response layer is responsible for transmitting requests and responses for resource operations.

[0023] Through in-depth analysis of IoT architecture and communication protocols, we can determine the specific targets and scope of subsequent research at the syntactic and semantic levels. IoT architecture encompasses multiple components, including the device side and the cloud side, and communication protocols encompass a wide variety of types. Clarifying these clearly defines the research boundaries for service protocols and ensures targeted analysis. For example, when studying power IoT service protocols, understanding their IP-based architecture, device-side core technologies, and cloud-side functionality allows us to focus on the syntactic and semantic analysis of the relevant communication protocols.

[0024] In-depth analysis of IoT architecture and communication protocols can reveal information such as the protocol's structural characteristics, data transmission methods, and interaction processes. This information is crucial for analyzing the behavioral characteristics of business protocols at the syntactic and semantic levels. For example, understanding the MQTT protocol's TCP / IP layer and simplified message format can help extract key fields and their corresponding values at the syntactic level and analyze the frequency and order of keyword occurrence at the semantic level.

[0025] Identifying potential factors within IoT architectures and communication protocols that influence the behavior of service protocols provides insights for syntactic and semantic analysis. For example, the resource-constrained nature of IoT devices can influence the selection and design of communication protocols, which in turn influences the behavior of service protocols. These factors must be considered during syntactic and semantic analysis.

[0026] Specifically, the parallel parsing and syntax anomaly detection of business protocol messages include protocol parallel parsing technology and protocol behavior modeling methods.

[0027] Protocol parallel parsing technology: terminal layer business security anomaly analysis based on deep protocol parsing, mainly targeting plaintext traffic, judging whether the message content and protocol operation are abnormal from the two levels of syntax and semantics. At the syntax level, the present invention innovatively proposes a protocol parallel parsing technology, which can quickly extract the key fields of the protocol and their corresponding values from the message, and then compare these field values with the preset whitelist one by one. Any field value not in the whitelist is regarded as a business security anomaly. In addition, a deep learning model is also combined to perform anomaly detection on message protocol data. At the semantic level, the present invention uses the frequency and order of occurrence of protocol keywords to establish a behavioral model of the protocol. Based on this model, business operation anomalies are detected.

[0028] For the power Internet of Things business protocol, its message contains multiple key fields. The core principle of parallel parsing is to process the key fields in the message at the same time, such as field 1, field 2 and field 3, rather than parsing them one by one in sequence, such as parsing field 1 first, then field 2 and field 3. Parallel processing can significantly improve the message parsing speed, thereby accelerating the business protocol anomaly detection based on whitelist matching. The principle diagram of parallel parsing is as follows: Figure 3 shown.

[0029] Protocol Behavior Modeling Method: To achieve semantic anomaly detection for all-service power IoT service protocols, this paper proposes a practical protocol behavior modeling method. This method examines key protocol fields and establishes a protocol behavior model based on the frequency and order of occurrence of these key fields. The specific steps are as follows: Step 21: Count the frequency of occurrence of protocol keywords; Step 22: Count the frequency of protocol keyword combinations; Step 23: Count the time intervals between two keywords that appear before and after each other; Step 24: Build a protocol behavior model to detect abnormal protocol messages.

[0030] Based on the statistical results of steps 1 to 3, a behavior model of the protocol can be constructed, and abnormal protocol messages can be detected accordingly.

[0031] Step 1) Construct a protocol behavior model, such as Figure 4 As shown. Figure 4 In ,node attributes include key field names and ,occurrence frequencies, and edge attributes include time interval and the ,occurrence frequency of keyword combinations; Step 2) Traverse the protocol behavior model graph. If the occurrence frequency of a key field exceeds the preset threshold, it is determined to be abnormal.

[0032] Step 3) If the frequency of the keyword combination exceeds the set threshold, it is judged as abnormal; Step 4) If the time interval between the previous and next keywords deviates from the normal distribution, it is judged to be abnormal.

[0033] The preset thresholds described in step 2) are critical values set for the frequency of occurrence of key fields and keyword combinations in the protocol behavior model. They are used to measure the reasonable range of the frequency of occurrence of key fields and their combinations under normal business operations, and are a limitation on the frequency indicators related to node attributes and edge attributes in the protocol behavior model. By comparing the actual statistical frequency of occurrence of key fields and keyword combinations in the protocol behavior model with the set thresholds, it is directly determined whether the occurrence of a single key field or keyword combination is abnormal, and protocol behavior anomalies are captured at the local detail level. For example, when the frequency of occurrence of a key field exceeds its corresponding threshold, it can be preliminarily determined that the protocol behavior related to the field is abnormal.

[0034] Thresholds are typically set based on statistical analysis of the frequency of key fields and their combinations in historical, normal business data. For example, a large amount of protocol message data from normal business operations is collected, and the distribution of the frequency of key fields and keyword combinations is statistically analyzed. Based on actual business needs and experience, the frequency value corresponding to an appropriate percentile (such as the 95th percentile, 99th percentile, etc.) is selected as the threshold. Alternatively, a reasonable threshold range can be manually set based on the experience and knowledge of business experts, industry standards, or the operational experience of similar systems.

[0035] Specifically, the behavior anomaly detection method based on business protocol packets includes protocol data packet feature selection and protocol behavior model CRF establishment.

[0036] Protocol Data Packet Feature Selection: Protocol behavior is reflected in the interaction between a series of protocol keywords. Protocol keywords are words that reflect user behavior when using application-layer protocols and can be used to distinguish message types within the protocol. For example, the key fields of the HTTP protocol consist of method words such as OPTION, GET, HEAD, and POST, and response codes such as 100, 202, 301, and 404. Therefore, this paper proposes using protocol keyword sequences as observation sequences to characterize protocol behavior.

[0037] Establishing the CRF protocol behavior model: In the abnormal protocol behavior detection task, we first collect a packet observation sequence X from the network data stream, based on the network connection. Each packet is then labeled with its normality y_i, generating a labeled sequence Y. This process transforms the observation sequence into a labeled sequence. This paper selects conditional random fields as an efficient sequence labeling model.

[0038] After the conditional random field model is established, its application principle for real-time protocol anomaly detection is as follows: for each protocol observation sequence within a network connection, where N represents the length of the network connection and each observation value corresponds to a protocol data packet. According to the constructed CRF model, if there is a protocol anomaly within the connection, the conditional probability of the normal tag sequence (1 indicates a normal state) should exceed the preset threshold, thereby determining whether the protocol behavior is abnormal based on the threshold. Conditional probability ) should be greater than the pre-set threshold The protocol behavior is determined to be abnormal based on a threshold. This threshold, based on a conditional random field model, is used to determine whether the conditional probability of a protocol observation sequence being normal is within the normal range. It reflects the critical probability threshold for normal protocol behavior given the observation sequence and model parameters. Based on the conditional random field model, a comprehensive assessment of the protocol observation sequence within the entire network connection is performed. By comparing the conditional probability with the threshold, the protocol behavior within the network connection is determined to be abnormal at the overall level, providing a comprehensive and integrated assessment of protocol behavior. Even if the frequency of some key fields or combinations is abnormal, the protocol behavior may not be considered abnormal if the overall conditional probability does not exceed the threshold. Setting this threshold requires comprehensive consideration of various factors, such as network stability and the service requirements for detection accuracy and real-time performance. Extensive experiments in different network environments and service scenarios, using methods such as cross-validation, can be used to identify a conditional probability threshold that achieves a good balance between false positive and false negative rates in detection results. Alternatively, parameter optimization algorithms in machine learning can be used to automatically adjust the threshold during model training to adapt to varying service needs and network conditions.

[0039] Threshold Determination method: It is determined by integrating a large amount of experimental data and actual business scenario requirements. In different network environments, business loads, and IoT application scenarios, normal protocol behavior data and known abnormal protocol behavior data are collected. Through cross-validation, machine learning parameter adjustment, and other methods, the conditional probability value that can achieve a good balance between the false alarm rate and the missed alarm rate of the detection results is found. For example, in the power Internet of Things, various normal business operations and possible attack scenarios are simulated, protocol data packets are obtained, and the conditional probability distribution of normal tag sequences is calculated based on the CRF model. Then, combined with the business requirements for detection accuracy and real-time performance, the final threshold is determined.

[0040] Threshold The judgment function of the probability factor is: During anomaly detection, the system collects a sequence of packet observations, $X$, per network connection. The CRF model then labels each packet for normality, generating a labeled sequence, $Y$. This sequence then calculates the conditional probability ${{P(y|x,θ}}$}} of a normal labeled sequence. This conditional probability is then compared with the threshold. If ${{P(y|x,θ}}$}}$ exceeds the threshold, the protocol behavior within the current network connection is normal. If it is less than or equal to the threshold, the protocol behavior is considered abnormal. This serves as a dividing line, providing a comprehensive and holistic assessment of protocol behavior based on the probabilistic model.

[0041] The specific abnormal protocol behavior process is as follows Figure 5 As shown: Figure 5 This paper presents a complete flowchart for detecting anomalous protocol behavior. Initially, the system extracts packet observation sequences from the network data stream, ensuring real-time and comprehensive detection. Next, a conditional random field model is used to label the packets for normality, generating a labeled sequence. This model is crucial because of its exceptional sequence labeling capabilities, enabling it to accurately capture subtle changes in protocol behavior.

[0042] In the real-time monitoring phase, the system uses the output of the CRF model to determine whether the protocol behavior in the network connection is abnormal. If the value of the protocol exceeds the set threshold, it is considered normal; otherwise, it is considered abnormal. This judgment mechanism takes into account the comprehensive characteristics of the protocol behavior and the real-time requirements.

[0043] Furthermore, this detection technology is adaptive, dynamically adjusting thresholds based on changes in the network environment to enhance detection accuracy and stability. By continuously optimizing the CRF model and threshold configuration, this technology enables precise, real-time monitoring of anomalies in IoT protocol behavior, building a solid defense for IoT security.

[0044] This invention combines parallel parsing technology with semantic modeling, successfully overcoming the limitations of traditional IoT security detection in terms of efficiency, accuracy, and dynamic adaptability. Experimental results show a reduction in detection time of over 80%, an increase in accuracy by 15 to 23 percentage points, and a significant reduction in false alarm rates by 93%. Its effectiveness has been demonstrated through practical application cases in fields such as power and industry, providing an efficient and reliable solution for IoT security protection.

Claims

1. A real-time detection method for abnormal behavior of Internet of Things protocols based on parallel parsing and semantic modeling, characterized by: The following steps are involved: Step 1: Conduct an in-depth analysis of the IoT architecture and IoT communication protocols, analyzing and modeling the behavioral characteristics of the service protocols from both the syntactic and semantic levels. Step 2: Taking the key fields in the protocol as the main investigation object, establish a protocol behavior model based on the frequency of occurrence of the key fields and the order of the keywords; Step 3: Propose a behavior anomaly detection method based on business protocol messages to identify anomalies in protocol behavior in real time.

2. The method for real-time detection of abnormal behavior of Internet of Things protocols based on parallel parsing and semantic modeling according to claim 1 is characterized in that: In step 1, the plaintext traffic is judged from both the grammatical and semantic levels to determine whether the message content and protocol operation are abnormal. At the grammatical level, a parallel protocol parsing technology is proposed to extract the key fields of the protocol and their corresponding values from the message. These field values are then compared one by one with a preset whitelist. Any field value not in the whitelist is considered a business security anomaly. At the semantic level, the frequency and order of occurrence of protocol keywords are used to establish a protocol behavior model. Based on this protocol behavior model, business operation anomalies are detected. For the power Internet of Things business protocol, its message contains multiple key fields, and the key fields in the message are processed simultaneously.

3. The method for real-time detection of abnormal behavior of Internet of Things protocols based on parallel parsing and semantic modeling according to claim 1 is characterized in that: The specific content of step 2 is as follows: Step 21: Count the occurrence frequencies of protocol keywords; Step 22: Count the frequency of protocol keyword combinations; Step 23: Count the time intervals between two keywords that appear before and after each other; Step 24: Build a protocol behavior model to detect abnormal protocol messages.

4. The method for real-time detection of abnormal behavior of Internet of Things protocols based on parallel parsing and semantic modeling according to claim 3 is characterized in that: The specific content of step 24 is as follows: Step 241: Construct a protocol behavior model. Specifically, the node attributes include the key field name and the frequency of occurrence, and the edge attributes include the time interval and the frequency of occurrence of the keyword combination. Step 242: Traverse the protocol behavior model graph, and if the occurrence frequency of a key field exceeds a preset threshold, it is determined to be abnormal; Step 243: If the frequency of the keyword combination exceeds the set threshold, it is determined to be abnormal; Step 244: If the time interval between the previous and next keywords deviates from the normal distribution, it is determined to be abnormal.

5. The method for real-time detection of abnormal behavior of Internet of Things protocols based on parallel parsing and semantic modeling according to claim 4 is characterized in that: Step 3 specifically includes first collecting a packet observation sequence X from the network data stream in units of network connections, and then marking each packet with a normality y_i to generate a labeling sequence Y; To achieve the conversion from observation sequence to label sequence, conditional random field is selected as an efficient sequence labeling model; for the protocol observation sequence within each network connection, N represents the length of the network connection, and each observation value corresponds to a protocol data packet; according to the constructed protocol behavior model, if there is a protocol anomaly within the connection, the conditional probability of the normal label sequence should exceed the preset threshold, so as to determine whether the protocol behavior is abnormal based on the threshold, and the conditional probability ) should be greater than the pre-set threshold , determine whether the protocol behavior is abnormal or not based on the threshold.