Automatic evidence obtaining method and device for botnet of Internet of Things
Through the collaborative analysis of multi-dimensional evaluation strategy and decision tree model, the problem of rapid identification and evidence collection of IoT botnets is solved, and efficient and accurate abnormal detection and evidence collection of IoT devices is achieved.
Patent Information
- Application Number
- CN202510911554.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-02
- Publication Date
- 2025-08-15
AI Technical Summary
The existing technology is difficult to quickly and accurately identify botnets and collect evidence in IoT devices. Traditional methods are inefficient and have high misjudgment rates. Automation solutions lack dynamic learning capabilities, making it difficult to deal with new attack variants.
A multi-dimensional evaluation strategy and decision tree model are used to collaborate analysis. Network traffic, process operation and system file information are collected in real time through the data acquisition module, network behavior evaluation model is constructed and scored, and anomaly detection and evidence collection is used to use the decision tree model.
It realizes rapid and accurate detection of IoT botnets, improves the timeliness and accuracy of evidence collection, reduces the system's computing burden, and ensures the efficiency and reliability of evidence collection.
Smart Images

Figure CN120498886A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of Internet of Things security technology, and specifically relates to an Internet of Things botnet automated evidence collection method and device based on a multi-dimensional evaluation strategy and a decision tree, which is used to quickly identify infected Internet of Things devices and complete electronic evidence collection. Background Art
[0002] With the widespread deployment of IoT devices, botnets are exploiting their weak security to launch DDoS attacks, data theft, and other malicious activities. Traditional forensic methods rely on manual analysis of logs and traffic data, which is inefficient and prone to false positives. Existing automated solutions, while incorporating policy scoring mechanisms, lack dynamic learning capabilities and are unable to address new attack variants. Therefore, an automated forensic approach that integrates multi-dimensional behavioral evaluation with machine learning decision-making is urgently needed. Summary of the Invention
[0003] The present invention proposes an automated evidence collection method for IoT botnets, which achieves efficient detection and evidence collection through collaborative analysis of multi-strategy scoring and decision tree models.
[0004] The present invention proposes an automated evidence collection method for IoT botnets based on a multi-dimensional evaluation strategy and a decision tree, the method comprising the following steps: S1, through the data collection modules deployed in IoT devices and network nodes at all levels, collects network traffic data, process operation information and system file information of the IoT devices to be evaluated in real time during their operation; S2, constructing a network behavior evaluation model including a multi-dimensional evaluation strategy, extracting the network traffic data of the IoT device to be evaluated, and inputting the network traffic data into the network behavior evaluation model to obtain a network behavior score; S3, comparing the network behavior score with a preset threshold, and generating abnormal network behavior alarm information if the score is higher than the preset threshold; S4, extracting the process operation information and system file information based on the abnormal network behavior alarm information and inputting them into a decision tree model to obtain an abnormal network behavior decision result; S5: Based on the abnormal network behavior decision result, automatically collect evidence on the IoT device to be evaluated.
[0005] In step S1, the network traffic data includes communication data packets between the device and external nodes, DNS resolution records, and network connection establishment and disconnection information; The process running information includes process name, process ID, startup parameters, system resource usage, and port monitoring status; The system file information includes file type, file size, file hash value, file name characteristics, and binary file structure characteristics.
[0006] The IoT device to be evaluated is any one or more IoT devices selected by the user from the current network through the operation interface.
[0007] Step S2 specifically includes: S21, building a basic rule base for network behavior evaluation models, including: matching the target IP / domain name in the DNS resolution record to see if it exists in the predefined malicious database; counting the communication frequency between the device and nodes inside and outside the domain in the network connection establishment and disconnection information, and determining whether the communication frequency between devices within the domain exceeds the preset value or whether the connection frequency between a single device and a node outside the domain exceeds the preset value; detecting the traffic protocol type and port number in the communication data packet to determine whether non-standard ports are used or whether communication with ports commonly used by botnets is carried out; S22, performing structured processing on the network traffic data during the operation of the IoT device to be evaluated, including: extracting five-tuple information including source IP, destination IP, protocol, source port, destination port, packet size, and timestamp sequence, and standardizing them into a unified format; S23, performing rule matching on information in the network traffic data based on the basic rule base; S24, performing weighted summation according to the scores of the hit rules in the rule base to obtain a network behavior score.
[0008] In step S3, the abnormal network behavior alarm information includes the identifier of the Internet of Things device.
[0009] In step S4, the decision tree model is specifically: S41: Extract historical process operation information and historical system file information to build a structured data set.
[0010] S42: Extracting statistical features from the historical process operation information and the historical system file information, and generating labels in combination with expert rules as training targets for a decision tree model.
[0011] S43: Construct a training set based on the labels and use the CART algorithm to train the decision tree model. The Gini impurity index is used when splitting nodes. Feature selection prioritizes high information gain attributes to generate interpretable classification rules. S44: According to the identifier of the IoT device in the abnormal network behavior alarm information, the process operation information and system file information of the IoT device are extracted, input into the trained decision tree model, and the confidence and judgment results of the abnormal network behavior are output along the rule path.
[0012] Step S5 specifically includes: S51 triggers the forensic program based on the abnormal network behavior decision results, automatically collecting device memory images, process snapshots, network connection records, system logs and suspicious file copies, and uses digital signature technology to ensure data integrity; S52 automatically generates a structured report containing timestamp, device ID, forensic data summary and risk level, simultaneously triggers a security alarm and pushes it to the security management personnel, completing the forensic closed loop.
[0013] The present invention also proposes an automated evidence collection device for IoT botnets based on a multi-dimensional evaluation strategy and a decision tree, which is characterized by comprising: The data collection module is deployed in IoT devices and network nodes at all levels to collect real-time network traffic data, process operation information, and system file information during the operation of the IoT devices to be evaluated; A scoring module is used to construct a network behavior evaluation model including a multi-dimensional evaluation strategy, extract the network traffic data of the IoT device to be evaluated, and input the network traffic data into the network behavior evaluation model to obtain a network behavior score; An alarm module is used to compare the network behavior score with a preset threshold and generate abnormal network behavior alarm information if the score is higher than the preset threshold; A decision module is used to extract the process operation information and system file information according to the abnormal network behavior alarm information and input them into a decision tree model to obtain an abnormal network behavior decision result; The evidence collection module is used to automatically collect evidence on the IoT device to be evaluated based on the abnormal network behavior decision result.
[0014] The present invention also proposes an automated evidence collection device for an Internet of Things botnet based on a multi-dimensional evaluation strategy and a decision tree, comprising a processor and a memory, wherein the memory stores computer program code, and is characterized in that when the computer program code is executed by the processor, the steps of an automated evidence collection method for an Internet of Things botnet based on a multi-dimensional evaluation strategy and a decision tree are implemented.
[0015] The present invention also proposes a computer-readable storage medium having computer program code stored thereon, characterized in that: when the computer program code is executed, the steps of an automated forensics method for an Internet of Things botnet based on a multi-dimensional evaluation strategy and a decision tree are implemented.
[0016] The beneficial effects of the present invention include: (1) through the collaborative analysis of multi-dimensional evaluation strategy and decision tree model, rapid and accurate detection of IoT botnet attacks is achieved, significantly improving the timeliness and accuracy of evidence collection; (2) a hierarchical processing mechanism of multi-dimensional evaluation followed by decision-making is adopted, and decision tree analysis is triggered only when the network behavior score exceeds the threshold, effectively reducing the system's computational load while taking into account the forensic performance. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] Figure 1 Flow chart of the method of the present invention. DETAILED DESCRIPTION
[0018] An IoT botnet is a remotely controllable attack network created by attackers who infect a large number of IoT devices (such as smart cameras, routers, and smart home appliances) with malware. These devices are vulnerable to compromise and malware implantation due to common security vulnerabilities such as weak passwords and unpatched vulnerabilities, turning them into "zombie nodes." Attackers centrally control these devices through command and control (C&C) servers, launching malicious activities such as distributed denial of service (DDoS) attacks, data theft, and spam. Defense requires a combination of technical measures such as device hardening, abnormal traffic monitoring, and automated forensics.
[0019] The present invention proposes an automated evidence collection method for IoT botnets based on a multi-dimensional evaluation strategy and a decision tree, the method comprising the following steps: S1, through the data collection modules deployed in IoT devices and network nodes at all levels, collects network traffic data, process operation information and system file information of the IoT devices to be evaluated in real time during their operation; S2, constructing a network behavior evaluation model including a multi-dimensional evaluation strategy, extracting the network traffic data of the IoT device to be evaluated, and inputting the network traffic data into the network behavior evaluation model to obtain a network behavior score; S3, comparing the network behavior score with a preset threshold, and generating abnormal network behavior alarm information if the score is higher than the preset threshold; S4, extracting the process operation information and system file information based on the abnormal network behavior alarm information and inputting them into a decision tree model to obtain an abnormal network behavior decision result; S5: Based on the abnormal network behavior decision result, automatically collect evidence on the IoT device to be evaluated.
[0020] In step S1, the network traffic data includes communication data packets between the device and external nodes, DNS resolution records, and network connection establishment and disconnection information; The process running information includes process name, process ID, startup parameters, system resource usage, and port monitoring status; The system file information includes file type, file size, file hash value, file name characteristics, and binary file structure characteristics.
[0021] The IoT device to be evaluated is any one or more IoT devices selected by the user from the current network through the operation interface.
[0022] Step S2 specifically includes: S21, building a basic rule base for network behavior evaluation models, including: matching the target IP / domain name in the DNS resolution record to see if it exists in the predefined malicious database; counting the communication frequency between the device and nodes inside and outside the domain in the network connection establishment and disconnection information, and determining whether the communication frequency between devices within the domain exceeds the preset value or whether the connection frequency between a single device and a node outside the domain exceeds the preset value; detecting the traffic protocol type and port number in the communication data packet to determine whether non-standard ports are used or whether communication with ports commonly used by botnets is carried out; S22, performing structured processing on the network traffic data during the operation of the IoT device to be evaluated, including: extracting five-tuple information including source IP, destination IP, protocol, source port, destination port, packet size, and timestamp sequence, and standardizing them into a unified format; S23, performing rule matching on information in the network traffic data based on the basic rule base; S24, performing weighted summation according to the scores of the hit rules in the rule base to obtain a network behavior score.
[0023] In step S3, the abnormal network behavior alarm information includes the identifier of the Internet of Things device.
[0024] In step S4, the decision tree model is specifically: S41: Extract historical process operation information and historical system file information to build a structured data set.
[0025] S42: Extracting statistical features from the historical process operation information and the historical system file information, and generating labels in combination with expert rules as training targets for a decision tree model.
[0026] S43: Construct a training set based on the labels and use the CART algorithm to train the decision tree model. The Gini impurity index is used when splitting nodes. Feature selection prioritizes high information gain attributes to generate interpretable classification rules. S44: According to the identifier of the IoT device in the abnormal network behavior alarm information, the process operation information and system file information of the IoT device are extracted, input into the trained decision tree model, and the confidence and judgment results of the abnormal network behavior are output along the rule path.
[0027] Step S5 specifically includes: S51 triggers the forensic program based on the abnormal network behavior decision results, automatically collecting device memory images, process snapshots, network connection records, system logs and suspicious file copies, and uses digital signature technology to ensure data integrity; S52 automatically generates a structured report containing timestamp, device ID, forensic data summary and risk level, simultaneously triggers a security alarm and pushes it to the security management personnel, completing the forensic closed loop.
[0028] The present invention also proposes an automated evidence collection device for IoT botnets based on a multi-dimensional evaluation strategy and a decision tree, which is characterized by comprising: The data collection module is deployed in IoT devices and network nodes at all levels to collect real-time network traffic data, process operation information, and system file information during the operation of the IoT devices to be evaluated; A scoring module is used to construct a network behavior evaluation model including a multi-dimensional evaluation strategy, extract the network traffic data of the IoT device to be evaluated, and input the network traffic data into the network behavior evaluation model to obtain a network behavior score; An alarm module is used to compare the network behavior score with a preset threshold and generate abnormal network behavior alarm information if the score is higher than the preset threshold; A decision module is used to extract the process operation information and system file information according to the abnormal network behavior alarm information and input them into a decision tree model to obtain an abnormal network behavior decision result; The evidence collection module is used to automatically collect evidence on the IoT device to be evaluated based on the abnormal network behavior decision result.
[0029] The present invention also proposes an automated evidence collection device for an Internet of Things botnet based on a multi-dimensional evaluation strategy and a decision tree, comprising a processor and a memory, wherein the memory stores computer program code, and is characterized in that when the computer program code is executed by the processor, the steps of an automated evidence collection method for an Internet of Things botnet based on a multi-dimensional evaluation strategy and a decision tree are implemented.
[0030] The present invention also proposes a computer-readable storage medium having computer program code stored thereon, characterized in that: when the computer program code is executed, the steps of an automated forensics method for an Internet of Things botnet based on a multi-dimensional evaluation strategy and a decision tree are implemented.
[0031] The embodiments of the present invention are described above in conjunction with the accompanying drawings, but the present invention is not limited to the above-mentioned specific implementation methods. The above-mentioned specific implementation methods are merely illustrative and not restrictive. Under the guidance of the present invention, ordinary technicians in this field can also make many forms without departing from the scope of protection of the present invention and the claims, all of which are protected by the present invention.
Claims
1. An automated evidence collection method for IoT botnets based on a multi-dimensional evaluation strategy and decision tree, characterized by: The method comprises the following steps: S1, through the data collection modules deployed in IoT devices and network nodes at all levels, collects network traffic data, process operation information and system file information of the IoT devices to be evaluated in real time during their operation; S2, constructing a network behavior evaluation model including a multi-dimensional evaluation strategy, extracting the network traffic data of the IoT device to be evaluated, and inputting the network traffic data into the network behavior evaluation model to obtain a network behavior score; S3, comparing the network behavior score with a preset threshold, and generating abnormal network behavior alarm information if the score is higher than the preset threshold; S4, extracting the process operation information and system file information based on the abnormal network behavior alarm information and inputting them into a decision tree model to obtain an abnormal network behavior decision result; S5: Based on the abnormal network behavior decision result, automatically collect evidence on the IoT device to be evaluated.
2. The method according to claim 1, wherein In step S1, the network traffic data includes communication data packets between the device and external nodes, DNS resolution records, and network connection establishment and disconnection information; The process running information includes process name, process ID, startup parameters, system resource usage, and port monitoring status; The system file information includes file type, file size, file hash value, file name characteristics, and binary file structure characteristics.
3. The method according to claim 1, wherein The IoT device to be evaluated is any one or more IoT devices selected by the user from the current network through the operation interface.
4. The method according to claim 2, wherein Step S2 specifically includes: S21, building a basic rule base for network behavior evaluation models, including: matching the target IP / domain name in the DNS resolution record to see if it exists in the predefined malicious database; counting the communication frequency between the device and nodes inside and outside the domain in the network connection establishment and disconnection information, and determining whether the communication frequency between devices within the domain exceeds the preset value or whether the connection frequency between a single device and a node outside the domain exceeds the preset value; detecting the traffic protocol type and port number in the communication data packet to determine whether non-standard ports are used or whether communication with ports commonly used by botnets is carried out; S22, performing structured processing on the network traffic data during the operation of the IoT device to be evaluated, including: extracting five-tuple information including source IP, destination IP, protocol, source port, destination port, packet size, and timestamp sequence, and standardizing them into a unified format; S23, performing rule matching on information in the network traffic data based on the basic rule base; S24, performing weighted summation according to the scores of the hit rules in the rule base to obtain a network behavior score.
5. The method according to claim 2, wherein In step S3, the abnormal network behavior alarm information includes the identifier of the Internet of Things device.
6. The method according to claim 5, wherein In step S4, the decision tree model is specifically: S41: extract historical process operation information and historical system file information to build a structured data set; S42: extracting statistical features from the historical process operation information and historical system file information, and generating labels based on expert rules as training targets for a decision tree model; S43: Construct a training set based on the labels and use the CART algorithm to train the decision tree model. The Gini impurity index is used when splitting nodes. Feature selection prioritizes high information gain attributes to generate interpretable classification rules. S44: According to the identifier of the IoT device in the abnormal network behavior alarm information, the process operation information and system file information of the IoT device are extracted, input into the trained decision tree model, and the confidence and judgment results of the abnormal network behavior are output along the rule path.
7. The method according to claim 6, wherein Step S5 specifically includes: S51 triggers the forensic program based on the abnormal network behavior decision results, automatically collecting device memory images, process snapshots, network connection records, system logs and suspicious file copies, and uses digital signature technology to ensure data integrity; S52 automatically generates a structured report containing timestamp, device ID, forensic data summary and risk level, simultaneously triggers a security alarm and pushes it to the security management personnel, completing the forensic closed loop.
8. An automated evidence collection device for IoT botnets based on a multi-dimensional evaluation strategy and a decision tree, characterized in that: include: The data collection module is deployed in IoT devices and network nodes at all levels to collect real-time network traffic data, process operation information, and system file information during the operation of the IoT devices to be evaluated; A scoring module is used to construct a network behavior evaluation model including a multi-dimensional evaluation strategy, extract the network traffic data of the IoT device to be evaluated, and input the network traffic data into the network behavior evaluation model to obtain a network behavior score; An alarm module is used to compare the network behavior score with a preset threshold and generate abnormal network behavior alarm information if the score is higher than the preset threshold; A decision module is used to extract the process operation information and system file information according to the abnormal network behavior alarm information and input them into a decision tree model to obtain an abnormal network behavior decision result; The evidence collection module is used to automatically collect evidence on the IoT device to be evaluated based on the abnormal network behavior decision result.
9. An automated IoT botnet evidence collection device based on a multi-dimensional evaluation strategy and a decision tree, comprising a processor and a memory, wherein the memory stores computer program code, characterized in that: When the computer program code is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium having computer program code stored thereon, characterized in that: When the computer program code is executed, the steps of the method according to any one of claims 1 to 7 are implemented.