Network security detection system and method based on Internet of Things terminal equipment

By capturing and analyzing network communication data streams from IoT terminal devices in real time, this solution addresses issues related to device authentication, protocol layer anomaly identification, content layer anomaly analysis, and threat tracing in IoT terminal network security testing. It enables multi-dimensional network behavior monitoring and comprehensive security posture reporting for IoT terminal devices, improving the accuracy and adaptability of security testing.

CN121509075APending Publication Date: 2026-02-10SHANDONG JINPU INFORMATION TECH CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202511891438.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-15
Publication Date
2026-02-10

AI Technical Summary

Technical Problem

Existing IoT terminal network security detection technologies suffer from problems such as simple device authentication, insufficient identification of protocol layer anomalies, lack of content layer anomaly analysis, insufficient ability to analyze the correlation of abnormal events, and weak threat tracing capabilities. These issues result in high false alarm rates, high false negative rates, and incomplete security posture reports, making it difficult to meet the security protection needs in complex network environments.

Method used

By capturing network communication data streams in real time, extracting device identifiers, communication protocol characteristics, and transmission content characteristics, the system performs credibility verification, establishes protocol behavior models, conducts spatiotemporal correlation analysis, dynamically adjusts terminal behavior baselines, and performs threat tracing analysis to generate a terminal security status report.

Benefits of technology

It enables multi-dimensional network behavior monitoring of IoT terminal devices, improves the ability to identify anomalies at the protocol and content layers, reduces false alarm and false negative rates, provides a comprehensive security status view, supports accurate threat tracing and effective protection measures, and adapts to the security needs of different application scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121509075A_ABST
    Figure CN121509075A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of Internet of Things security detection, and discloses a network security detection system and method based on Internet of Things terminal equipment. The method comprises the following steps: capturing a terminal network communication data flow in real time, and extracting an equipment identifier, a communication protocol feature and a transmission content feature; performing credibility verification on the equipment identifier to generate a credible equipment list, establishing a protocol behavior model according to protocol characteristics to identify a protocol layer abnormal event, and identifying a content layer abnormal event through matching of transmission content characteristics and a preset rule; performing time-space correlation analysis on the two types of abnormal events to generate a comprehensive threat event set, and constructing and dynamically adjusting a terminal behavior baseline according to the comprehensive threat event set; the method comprises the following steps: performing deviation detection on a real-time data stream based on a baseline, performing threat tracing on a result to determine a threat source and an attack path, and finally integrating a tracing result and a comprehensive threat event set to generate a terminal security situation report, thereby realizing dynamic detection and management and control on the network security of the Internet of Things terminal.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of Internet of Things security detection, in particular to a network security detection system and method based on Internet of Things terminal equipment. BACKGROUND

[0002] With the rapid development of Internet of Things technology, Internet of Things terminal equipment has been widely used in industrial control, smart home, smart city, medical health and other fields. The number of terminal equipment is growing exponentially, and the types of equipment are becoming increasingly diversified, covering sensors, controllers, cameras, smart home appliances and other forms. These terminal equipment realizes data interaction and remote control through the network, which improves production efficiency and life convenience, but also brings serious network security risks.

[0003] Currently, there are still many deficiencies in the network security detection technology of Internet of Things terminal. Most detection schemes have a simple verification mechanism for device identity, relying only on fixed device identifiers for preliminary identification, which is difficult to deal with problems such as device identifier forgery and theft, leading to illegal devices easily accessing the network and causing security incidents such as data leakage and malicious control. Although some schemes introduce an identity verification step, the verification dimension is single and cannot combine historical communication behavior, network environment and other information to comprehensively judge the credibility of the device, making it difficult to accurately define the range of trusted devices.

[0004] Existing detection technologies have obvious shortcomings in anomaly identification. At the protocol level, most schemes only set fixed detection rules for common Internet of Things communication protocols, and cannot establish dynamic behavior models according to the actual interaction rules of the protocol. When attackers launch attacks by tampering with protocol fields, adjusting interaction frequency, etc., traditional rules are difficult to effectively identify such abnormal protocol interaction behavior, leading to security vulnerabilities at the protocol level being exploited. At the content level, detection schemes focus on identifying sensitive words, malicious code and other explicit rule violations, and lack analysis of implicit features such as the format legality and logical consistency of transmitted data. For malicious instructions disguised in normal data, tampered configuration information and other rule violations, the recognition accuracy is low.

[0005] Current technologies generally lack the ability to correlate anomalies at different levels. Protocol-layer anomalies and content-layer anomalies are often handled separately, ignoring their spatiotemporal correlation. For example, if a terminal exhibits both protocol interaction anomalies and data content violations within a specific time period, it may be a manifestation of a targeted attack. However, separate detection methods will classify these as independent events, leading to high false positive and false negative rates for threat events. Furthermore, most detection solutions use fixed behavioral thresholds to establish a baseline for terminal behavior. This fails to dynamically adjust the thresholds based on changes in the terminal's usage scenario, network environment fluctuations, software version updates, and other factors. When a terminal exhibits behavioral fluctuations due to normal business needs, it is easily misjudged as a security threat. Conversely, when attackers slowly adjust their attack behavior to adapt to the fixed thresholds, the baseline cannot respond in time, resulting in detection lag.

[0006] In terms of threat attribution and situational awareness, existing solutions mostly remain at the level of simple alerts for abnormal events, lacking the ability to accurately pinpoint the source of threats, identify the initiating terminal and attack path corresponding to abnormal events, and making it difficult to trace the source of attacks and take targeted blocking measures. Meanwhile, security situation reports are often presented in the form of fragmented event lists, lacking comprehensive analysis of the severity, scope of impact, and development trends of events. This fails to provide managers with a comprehensive and clear view of the network security situation, resulting in a lack of effective guidance for subsequent security decisions and control measures. These problems make current IoT terminal network security detection technologies insufficient to meet the security protection needs of complex network environments, necessitating a more comprehensive, dynamic, and intelligent detection method to address these shortcomings. Summary of the Invention

[0007] The purpose of this invention is to provide a network security detection system and method based on Internet of Things (IoT) terminal devices to solve the problems mentioned in the background art.

[0008] To achieve the above objectives, the present invention provides a network security detection method based on Internet of Things (IoT) terminal devices, the method comprising: Real-time capture of network communication data streams from IoT terminal devices, and extraction of device identifiers, communication protocol characteristics, and transmission content characteristics from the data streams; The extracted device identifiers are verified for trustworthiness, and a list of trusted devices containing the verification results is generated. Establish a protocol behavior model based on the characteristics of the communication protocol, and identify abnormal protocol interaction behaviors through the protocol behavior model and mark them as protocol layer abnormal events. Analyze the matching degree between the characteristics of the transmitted content and the preset content rules, identify content violations and mark them as content-layer abnormal events; Spatiotemporal correlation analysis is performed on protocol layer anomalies and content layer anomalies to generate a comprehensive set of threat events. A baseline of terminal behavior is constructed based on a comprehensive set of threat events, and the judgment threshold of the terminal behavior baseline is dynamically adjusted. Deviation detection is performed on the real-time network communication data stream based on the terminal behavior baseline, and the deviation detection results are output. Threat source analysis is performed on deviations from detection results to determine the source terminals and attack paths of threats; Integrate threat attribution analysis results with a comprehensive set of threat events to generate an endpoint security posture report.

[0009] Preferably, the credibility verification of the extracted device identifier includes: Separate the factory identifier and the dynamic session identifier from the device identifier; Verify that the factory identification code exists in the pre-registered device database; Detect whether the frequency of dynamic session identifier generation complies with the preset security policy; If the factory identification code is verified and the dynamic session identifier complies with the security policy, the device identifier is added to the trusted device list and marked with a verification timestamp.

[0010] Preferably, the establishment of the protocol behavior model includes: Statistically analyze the frequency of occurrence and interaction sequence of various protocols in historical communication data streams; Extract the patterns of change in key fields during protocol interaction; Generate a protocol state transition diagram based on frequency of occurrence, interaction sequence, and key field change patterns; When real-time protocol interaction behavior deviates from the protocol state transition diagram, a protocol layer exception event flag is triggered.

[0011] Preferably, the identified content violation includes: The transmitted content characteristics are split into header metadata and payload data; Detect whether the header metadata contains unauthorized instruction code; Compare payload data with the whitelist mode of preset content rules; If unauthorized instruction code or payload data deviates from the whitelist pattern, a content layer exception event flag is triggered.

[0012] Preferably, the spatiotemporal correlation analysis includes: Record the occurrence time and source terminal address of protocol layer and content layer abnormal events; Calculate the time interval and logical dependency between two types of abnormal events with the same source terminal address; If the time interval is less than the threshold and there is a logical dependency, the related events will be merged into a comprehensive threat event.

[0013] Preferably, the construction of the terminal behavior baseline includes: Extract the frequency of protocol interactions, the amount of content transmitted, and the severity level of the incident from comprehensive threat events; Initial behavior thresholds are generated based on protocol interaction frequency and content transmission volume; The initial behavior threshold is weighted and adjusted based on the severity level of the event; The weighted and adjusted behavioral threshold is recalculated for each new integrated threat event.

[0014] Preferably, the deviation detection includes: Monitor whether the protocol interaction frequency of real-time network communication data streams exceeds the protocol threshold of the terminal behavior baseline; Statistically determine whether the amount of real-time transmitted content exceeds the content threshold of the terminal behavior baseline; When any threshold is exceeded, a deviation detection result containing the exceeded value and the time point is generated.

[0015] Preferably, the threat attribution analysis includes: Extract the communication peer address of the abnormal terminal from the deviation detection results; Retrieve the registration information of the peer address in the trusted device list; Track the historical protocol interaction records and content transmission records of the peer address; An attack path topology map is generated based on registration information and historical records.

[0016] Preferably, the generation of the terminal security posture report includes: Arrange the attack path topology map and comprehensive threat events in chronological order; Label the associated endpoint address and threat type for each event; Summarize the breakthrough numerical distribution characteristics of the deviation detection results; Generate structured reports that include timelines, threat types, and distribution characteristics.

[0017] Preferably, the present invention also includes a network security detection system based on an Internet of Things (IoT) terminal device. The system includes a memory, a processor, and a computer program stored in the memory and running on the processor. When the processor executes the computer program, it implements the steps of the network security detection method based on an IoT terminal device as described above.

[0018] Compared with the prior art, the beneficial effects of the present invention are: By capturing network communication data streams in real time and extracting device identifiers, communication protocol characteristics, and transmission content characteristics, multi-dimensional collection of network interaction information from terminal devices is achieved. Compared to traditional solutions that focus on only a single information dimension, this approach provides a more comprehensive understanding of the network behavior of terminal devices, offering richer foundational data support for subsequent security testing. Verifying the credibility of device identifiers and generating a trusted device list allows for the screening of legitimate devices at the source, reducing the risk of unauthorized devices accessing the network and avoiding security vulnerabilities caused by unidentified devices. Furthermore, the establishment of the trusted device list defines the basic scope for subsequent anomaly detection, making the detection more targeted and reducing interference with the normal operation of legitimate devices.

[0019] Building protocol behavior models based on communication protocol characteristics breaks through the limitations of traditional fixed-rule detection. By learning the normal interaction patterns of protocols, a dynamic behavioral benchmark is formed. When abnormal interaction behaviors such as protocol field tampering, abnormal interaction frequency, and disordered command sequence occur, the model can quickly identify and mark them as protocol-layer abnormal events, improving the ability to identify protocol-layer attacks and covering protocol security vulnerabilities that traditional rules cannot reach. Analyzing the matching degree between transmitted content characteristics and preset content rules to identify content violations not only focuses on explicit violations such as sensitive words and malicious code, but also verifies implicit features such as data format and logical consistency. This enables a more comprehensive discovery of security issues in transmitted content and avoids security incidents caused by the failure to identify implicit violations.

[0020] Spatiotemporal correlation analysis of protocol-layer and content-layer anomalies can uncover the inherent connections between the two types of anomalies, preventing the overlooking of potential comprehensive threats by handling anomalies in isolation. For example, if a terminal exhibits both protocol interaction anomalies and data content violations within the same time period, spatiotemporal correlation analysis can identify it as a targeted attack, effectively reducing the false positive and false negative rates of threat events and improving the ability to identify complex attack behaviors. Constructing a terminal behavior baseline based on a comprehensive set of threat events and dynamically adjusting the judgment threshold allows the baseline to better reflect the actual operating state of the terminal device. When the terminal's behavior fluctuates due to normal business needs, dynamic adjustment of the threshold can avoid misjudgments; when attackers attempt to launch slow attacks using fixed thresholds, the baseline can respond promptly to behavioral changes, ensuring the timeliness and accuracy of detection and adapting to the behavioral differences of terminal devices in different scenarios.

[0021] Deviation detection of real-time network communication data streams based on terminal behavior baselines enables real-time monitoring of terminal device network behavior. Once a deviation from the baseline is detected, a rapid warning can be issued, buying security management time to respond and preventing further escalation of threats. Threat source analysis of the deviation detection results can pinpoint the source terminal and attack path, accurately locating the attack origin and clarifying the attack propagation path. This helps management take targeted blocking measures to prevent the attack from expanding, and also provides a basis for subsequent tracing of attack responsibility and analysis of attack methods.

[0022] By integrating threat attribution analysis results with comprehensive threat event aggregation to generate endpoint security posture reports, this method can consolidate fragmented anomaly and attribution information into a comprehensive security status view. It clearly presents the severity, scope of impact, and development trend of threat events, allowing managers to intuitively grasp the overall security status of IoT terminal networks. This provides clear guidance for formulating security strategies and optimizing protective measures, helping managers to conduct security management more efficiently and ensuring the stable and secure operation of IoT terminal networks. Whether ensuring the normal operation of production equipment in industrial control scenarios, protecting user privacy and data security in smart home scenarios, or maintaining the network security of public facilities in smart city scenarios, this method can effectively detect and protect against threats, adapting to the security needs of different IoT application scenarios. Attached Figure Description

[0023] Figure 1 This is a schematic diagram illustrating the working principle of the network security detection method based on IoT terminal devices described in this invention. Figure 2 A flowchart for establishing a protocol behavior model; Figure 3 A flowchart for establishing a baseline of terminal behavior. Detailed Implementation

[0024] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0025] Please see Figure 1This invention provides a network security detection method based on IoT terminal devices. The method includes: capturing network communication data streams of IoT terminal devices in real time, wherein the network communication data streams contain all data packets exchanged between the device and the network; extracting device identifiers, communication protocol features, and transmission content features from the data streams, wherein the device identifiers are used to uniquely identify the terminal devices, the communication protocol features describe the rules and formats followed by the communication, and the transmission content features reflect the specific information of the data payload; verifying the credibility of the extracted device identifiers, the verification process assesses the legitimacy of the device identity, and generating a list of trusted devices containing the verification results; establishing a protocol behavior model based on the communication protocol features, the protocol behavior model characterizes the protocol interaction pattern under normal communication conditions, and identifying abnormal protocol interaction behaviors through the protocol behavior model and marking them as protocol-layer abnormal events; analyzing the matching degree between transmission content features and preset content rules, the preset content rules define the allowed data patterns for transmission, identifying content violations and marking them as content-layer abnormal events; and performing spatiotemporal correlation analysis on protocol-layer abnormal events and content-layer abnormal events, the spatiotemporal correlation analysis examines the temporal order and spatial source of the events, generating a comprehensive set of threat events. A baseline for endpoint behavior is constructed based on a comprehensive set of threat events. This baseline characterizes the range of behavioral parameters of an endpoint under normal security conditions. The threshold for determining the endpoint behavior baseline is dynamically adjusted to adapt to changes in the network environment. Deviation detection is performed on real-time network communication data streams based on the endpoint behavior baseline. Deviation detection determines whether real-time behavior exceeds the baseline range and outputs the deviation detection results. Threat source analysis is performed on the deviation detection results to trace the source and path of abnormal behavior, identifying the endpoint from which the threat originates and the attack path. The threat source analysis results are integrated with the comprehensive set of threat events to generate an endpoint security posture report. This report comprehensively reflects the endpoint's security status and the threats it faces.

[0026] Example 1: After capturing the network communication data stream of IoT terminal devices in real time, the system initiates the device identifier extraction process. The network communication data stream contains all data packet sequences generated during the interaction between the device and the network. Extracting the device identifier from the data stream is a fundamental step in identifying the device. The device identifier is a character sequence embedded in the communication data to uniquely identify the source or destination. The extracted device identifier undergoes credibility verification. This verification process requires separating the factory identifier and the dynamic session identifier from the device identifier. The factory identifier is an unchangeable unique code written into the hardware by the device manufacturer during the production process. The dynamic session identifier is a session identifier temporarily generated by the protocol stack or application layer when the device establishes a network connection. The system verifies whether the factory identifier exists in the pre-registered device database. This database stores basic information about all authorized IoT terminal devices accessing the network, including each device's factory identifier, device model, network access time, and department. The system checks whether the generation frequency of the dynamic session identifier complies with the preset security policy. This preset security policy is formulated by the network administrator based on business needs and security specifications, clearly defining the maximum number of times different device types are allowed to apply for or replace dynamic session identifiers within a unit of time. If the factory identification code verification passes and the dynamic session identifier conforms to the security policy, the system adds the device identifier to the trusted device list. The trusted device list is a dynamically updated list that records information about devices currently deemed trusted. The verification timestamp is a crucial component of the list record; it uses precise time synchronized with the network time protocol to record the exact moment the device identifier passed verification.

[0027] The process of separating the manufacturer identification code and the dynamic session identifier from the device identifier involves a specific parsing algorithm. This algorithm locates the identifier field based on the communication protocol type used by the device. The manufacturer identification code typically has a fixed length and encoding format, such as IEEE EUI-64 or a manufacturer-defined encoding rule. The format and location of the dynamic session identifier depend on the specific transport layer or application layer protocol, such as the Transmission Control Protocol (TCP) port number in the TCP / IP protocol stack or the session token in the application layer protocol. The separation operation ensures that the two identifiers can be verified independently, preventing the verification result of the other identifier from being affected by the anomaly of one identifier. Verifying the existence of the manufacturer identification code in the pre-registered device database is implemented through a database query interface. The system uses the separated manufacturer identification code as the query key and performs an exact match with the records in the pre-registered device database. A successful match indicates that the device has a legitimate hardware identity and is an authorized asset included in the network management system. A failed match means that the device may be unauthorized, obsolete, or the identifier may have been forged, which will trigger an identity anomaly alarm.

[0028] Detecting whether the generation frequency of dynamic session identifiers conforms to the preset security policy requires maintaining a session log table. This table records the generation of dynamic session identifiers for each factory-issued identifier code within a time window. The preset security policy defines the time granularity and counting threshold for frequency detection; for example, it allows a maximum of five new dynamic session identifiers per minute. The system updates the session log table in real time, calculates the number of dynamic session identifiers generated within the current time window, and compares it with the policy threshold. Dynamic session identifier generation behavior conforming to the security policy is characterized by frequency fluctuations within a reasonable range, reflecting normal network activity of the device. Abnormal frequencies may manifest as explosive increases in a short period or a sustained increase above the baseline level over a long period; such anomalies are often associated with port scanning, session hijacking, or resource exhaustion attacks. Dynamic session identifier generation frequency detection can effectively identify malicious behaviors attempting to hide their activities or consume system resources by rapidly changing session identifiers.

[0029] Adding a device identifier to the trusted device list and marking it with a verification timestamp is a data write operation. The trusted device list is stored in a transaction-guaranteed database to ensure record consistency and integrity. Each record in the list contains a complete device identifier string, a verification result status bit, a verification timestamp field, and an optional device metadata reference. The verification timestamp is stored in an internationally standard time format, facilitating subsequent time series analysis and cross-system time synchronization. Marking the verification timestamp gives each trusted record a clear time attribute, which can be used to calculate the duration of the device's trusted state, determine the freshness of the list record, and perform time correlation analysis with other security events. The update operation of the trusted device list must be atomic to prevent data inconsistencies under concurrent access.

[0030] For device identifiers that fail trust verification, the system transfers them to an isolation review process, which includes logging detailed information, restricting network access permissions, and notifying the security administrator. Device identifiers that fail factory identification code verification and have abnormal dynamic session identifier frequency are marked as high-risk, triggering stricter behavior monitoring or immediate blocking measures. A device identifier is only granted a trusted status when both factory identification code verification and dynamic session identifier frequency detection meet the requirements. This dual verification mechanism reduces the risk of unauthorized device access due to a single verification factor being bypassed. The trusted device list forms the core basis of network access control policies; subsequent protocol behavior analysis, content detection, and anomaly correlation are all based on the trusted device set in the list. Maintaining the pre-registered device library is an ongoing management activity, requiring timely updates to the library when new devices join the network, old devices are decommissioned, or device information changes, ensuring the accuracy of the verification benchmark. The parameter settings for preset security policies need to consider the normal behavior patterns of devices under different business scenarios. Overly strict policies may mistakenly block normal services, while overly lenient policies may overlook potential threats. The dynamic session identifier generation frequency detection algorithm needs to optimize the sliding efficiency of the time window to meet the real-time computing requirements under high-frequency data streams. The separate verification mechanism enables the system to distinguish between the authenticity of a device's permanent identity and the health of temporary sessions, making precise identity and behavior management possible. The introduction of verification timestamps provides data support for time-based security analysis, such as tracking the historical changes in a device's trusted state and analyzing the temporal patterns of attack activities.

[0031] Example 2: See Figure 2 Based on the characteristics of communication protocols, a protocol behavior model is established. This model characterizes the protocol interaction paradigm that IoT terminal devices should follow under normal communication conditions. Communication protocol characteristics are a set of parameters extracted from real-time captured network communication data streams that reflect communication rules and formats. The frequency and interaction sequence of various protocols in historical communication data streams are statistically analyzed. Historical communication data streams are a sample library of network communication data collected over a past period and deemed normal. Frequency refers to the percentage of times a specific type of communication protocol is used within the statistical period, and interaction sequence describes the order in which protocol messages are sent and received during a dialogue. The changing patterns of key fields in the protocol interaction process are extracted. The protocol interaction process consists of a series of message units exchanged according to the protocol specification. Key fields are fields in each message unit that carry decisive information such as control commands, status codes, or sequence numbers. Their changing patterns reflect the evolution of field values ​​in continuous message interaction. A protocol state transition diagram is generated based on the frequency, interaction sequence, and changing patterns of key fields. The protocol state transition diagram is a directed graph model where nodes represent possible states of protocol communication, and edges represent events or conditions that trigger state transitions. Transition conditions are defined by specific values ​​or sequence constraints of key fields.

[0032] Statistical analysis of the frequency of various protocols in historical communication data streams requires defining a sliding time window. Within this window, the system performs protocol type parsing and classification counting on all captured data packets. The frequency calculation results reflect the usage popularity and functional distribution of different protocols in specific application scenarios. For example, in a device reporting data scenario, publish-subscribe protocols will appear significantly more frequently than request-response protocols. Analysis of interaction timing requires reconstructing the complete communication session flow, reassembling discrete data packets into an ordered interaction sequence based on source address, destination address, and session identifier. The patterns in the interaction timing reveal the normal operating logic of the protocol state machine. For instance, the three-way handshake messages during connection establishment must follow a fixed order; any reversal or omission of this order indicates an anomaly. Extracting the patterns of key field changes relies on deep packet analysis of the reconstructed interaction sequence, focusing on fields that have a decisive impact on the protocol logic. For example, during connection establishment, the sequence number field of the Transmission Control Protocol needs to increment according to specific rules, and the method field of the application layer protocol needs to conform to a predefined set of operations. The patterns of key field changes constitute the core of protocol semantic constraints.

[0033] Generating a protocol state transition diagram is a model building process. The system uses statistically obtained frequency of occurrence as the weight of the state, transforms the interaction sequence into transition paths between states, and concretizes the change patterns of key fields into guard conditions on the transition paths. The protocol state transition diagram abstractly describes the legal interaction space of the protocol; any actual communication behavior must fall on the path defined in this diagram. The construction of the protocol state transition diagram can be achieved with the help of automated modeling tools, which learn from a large number of normal traffic samples to summarize the protocol's state machine model. When real-time protocol interaction behavior deviates from the protocol state transition diagram, an abnormal event flag is triggered at the protocol layer. Real-time protocol interaction behavior refers to the currently monitored communication activities of the terminal device. Deviation behaviors include accessing undefined state nodes in the protocol state transition diagram, violating the timing constraints that state transitions must satisfy, or key fields exceeding the value range of predefined patterns.

[0034] The analysis of the matching degree between transmitted content features and preset content rules identifies content violations. Transmitted content features are data patterns extracted from the application layer payload of network communication data streams. Preset content rules are a set of whitelist rules defining legitimate transmitted content features. Transmitted content features are broken down into header metadata and payload data. Header metadata is structured control information located before the payload data, typically containing fields such as data format version, instruction code, and data length. Payload data is the actual application data transmitted following the header metadata. The analysis checks whether the header metadata contains unauthorized instruction codes. Unauthorized instruction codes are a set of operation instructions explicitly listed as prohibited in the preset content rules; these instructions may involve sensitive system operations or have potential dangers. The analysis compares the payload data with the whitelist patterns of the preset content rules. The whitelist patterns specify regular expressions or syntax rules that the payload data must conform to in terms of encoding format, data structure, character set range, and length limits.

[0035] Decomposing the transmitted content characteristics into header metadata and payload data requires adherence to the format specifications of the specific application layer protocol. Header metadata typically has a fixed length or includes a length indicator field for easy parsing. Header metadata detection focuses on syntactic and command-level security, quickly identifying control commands that clearly violate policies. Detection of unauthorized command codes in the header metadata is achieved through pattern matching algorithms; the system compares the parsed command fields with a list of unauthorized command codes. This list needs to be dynamically maintained based on the device's functionality and security policies. For example, for a read-only sensor, any write command might be considered unauthorized. Payload data whitelist pattern comparison focuses more on semantic-level security and data compliance, preventing malicious code injection, data leakage, or formatting errors. The definition of the whitelist pattern needs to accurately reflect the business logic's legitimate expectations of the data content; overly broad patterns reduce security, while overly strict patterns may hinder normal functionality.

[0036] If unauthorized command code or payload data deviates from the whitelist pattern, a content-layer anomaly event is triggered. This event records detailed information about the violation, including the involved terminal address, violation type, violation data fragment, and timestamp. The marking of protocol-layer and content-layer anomaly events provides raw security event data for subsequent correlation analysis. The establishment of a protocol behavior model allows anomaly detection to move beyond static feature matching and understand the dynamic behavioral logic of the protocol. Identification of content violations filters malicious payloads from a deep data perspective. The effectiveness of the protocol state transition graph depends on the representativeness and completeness of historical normal traffic samples and requires continuous updates to adapt to protocol version evolution or changes in business models. The split detection architecture of header metadata and payload data enables layered detection responsibility, improving detection efficiency and accuracy. The unauthorized command code list and whitelist pattern need to be managed as a knowledge base, supporting version control and policy distribution. The detection points for protocol-layer and content-layer anomalies complement each other, forming a defense-in-depth system. The comparison between real-time behavior and the protocol state transition graph requires an efficient state tracking algorithm. The whitelist pattern matching engine needs optimization to handle high-speed data streams. The event information tagged needs to be standardized in a format to facilitate aggregation and association.

[0037] Example 3: Spatiotemporal correlation analysis is performed on protocol layer anomaly events and content layer anomaly events. This analysis aims to uncover the inherent connections between anomaly events generated by different security detection layers in both time and space dimensions, thereby improving the accuracy and comprehensiveness of threat identification. The occurrence time and source terminal address of protocol layer and content layer anomaly events are recorded. The occurrence time is the event trigger moment recorded based on the system's high-precision clock, with timestamp accuracy down to the millisecond level. The source terminal address is the network layer logical address of the IoT terminal device that triggered the anomaly event. The time interval and logical dependency relationship between the two types of anomaly events under the same source terminal address are calculated. The time interval refers to the difference in duration between the occurrence time of the protocol layer anomaly event and the occurrence time of the content layer anomaly event. The logical dependency relationship is used to determine whether the occurrence of the content layer anomaly event is predicated on a specific communication state or channel created by the protocol layer anomaly event. If the time interval is less than a threshold and a logical dependency relationship exists, the correlated events are merged into a comprehensive threat event. The time interval threshold is a configurable parameter. Its setting needs to take into account the latency characteristics of network communication, the processing capabilities of terminal devices, and the reasonable expectations of event response time for specific business scenarios. The determination of logical dependencies depends on a deep understanding of the communication protocol state machine and application layer business logic.

[0038] Recording the occurrence time and source terminal address of protocol layer and content layer anomaly events is the data preparation stage for correlation analysis. The system generates a unique event record for each tagged anomaly event, containing an event type field, an occurrence time field, a source terminal address field, and other relevant attributes. Precise recording of the occurrence time field allows events to be sorted and compared on a unified timeline, while the source terminal address field provides a crucial index for filtering events from the same terminal from a massive dataset. Calculating the time interval between two types of anomalies under the same source terminal address requires first extracting all protocol layer and content layer anomalies belonging to the same source terminal address and sorting them in ascending order of occurrence time. For each content layer anomaly event, the system searches for the nearest protocol layer anomaly event within a certain time window before its occurrence time and calculates the time interval between them. The size of this time window is typically set based on an estimate of the excessive length of normal business interaction links, avoiding the association of irrelevant earlier protocol events with current content events. Determining logical dependencies is a more complex analytical process, going beyond simple time proximity judgments to delve into the causal probability between events. Logical dependency analysis requires examining whether a protocol-layer anomaly event leads to an abnormal protocol state that can be exploited by subsequent content-layer anomalies. For example, a successful but non-conformist protocol connection establishment event (protocol-layer anomaly) might provide an illegal session channel for the subsequent transmission of a sensitive control command that should only be sent in an authenticated state (content-layer anomaly); in this case, a logical dependency is considered to exist. Determining logical dependencies can be based on a set of predefined rules that describe the potential causal relationship between specific protocol anomalies and specific content violations. The rule base needs to cover common protocol combinations and business patterns in the IoT environment.

[0039] Time interval threshold It is a dynamically adjustable parameter used to filter out event pairs that are too geographically dispersed and weakly correlated. When the calculated time interval... Less than the set time interval threshold If the logical dependency analysis indicates the existence of a dependency, the system performs an event merging operation. This merging operation generates a comprehensive threat event record, which includes the original information of associated protocol-layer and content-layer anomaly events, and the calculated time intervals. The system includes a description of the types of logical dependencies and a comprehensive threat level score. The comprehensive threat level score is determined by both the time interval and the strength of the logical dependencies, and its quantification is defined by the following formula:

[0040] in: This indicates the overall threat level score. This represents the calculated time interval. Indicates the time interval threshold. A quantified value representing the strength of a logical dependency (e.g., a value between 0 and 1 mapped to the dependency type). It is the weighting coefficient of the time interval factor. It is the weight coefficient of the logical dependency factor, and satisfies The formula ensures accurate scoring. The dimensions are consistent, and all terms are dimensionless weighted sums. Weighting coefficients and The specific values ​​are set by security experts based on different types of threat scenarios. For example, for attacks with strong dependencies, a certain value can be assigned... A higher value. The first term of the formula. This reflects the contribution of temporal proximity to the threat score; the shorter the time interval, the larger the value of this item.

[0041] Spatiotemporal correlation analysis can effectively reduce false positives that may arise from single-dimensional detection. An isolated protocol anomaly might stem from temporary network jitter, and a single content anomaly might be a erroneous operation. However, when both are triggered by the same terminal within a short period and have a logical sequence, the likelihood of a malicious attack increases significantly. The recorded occurrence time and source terminal address constitute the spatiotemporal framework for correlation analysis. Calculating the time interval is a crucial step in quantifying temporal proximity. Determining logical dependencies is the core of inferring the attack chain. Merging and generating comprehensive threat events achieves abstraction from low-level events to high-level threats. Time interval threshold. The setup needs to strike a balance between reducing false associations and avoiding missed associations. The rule base for logical dependencies needs continuous updating to adapt to new attack methods. A comprehensive set of threat events has a higher threat indication value than a raw set of anomalous events. The source endpoint address, as a key spatial correlation, aggregates scattered events to potential risk sources. Precise recording of occurrence times provides data support for analyzing the intervals and rhythm of attack steps. The calculation method for time intervals can consider strategies such as using the shortest or average time interval. The strength quantification value L of a logical dependency can be assigned based on the frequency of the dependency's occurrence in historical attack data or expert experience. The comprehensive threat level score S provides a quantitative basis for subsequent response prioritization.

[0042] Example 4: See Figure 3A terminal behavior baseline is constructed based on a comprehensive threat event set. This baseline serves as a reference standard to quantitatively describe the dynamic changes in the network behavior characteristics of IoT terminal devices when subjected to security threats. The comprehensive threat event set is a group of event records representing confirmed security threats, generated by spatiotemporal correlation analysis. Protocol interaction frequency, content transmission volume, and event severity level are extracted from the comprehensive threat events. Protocol interaction frequency refers to the number of complete protocol interaction transactions initiated by the affected terminal per unit time during the duration of the comprehensive threat event. Content transmission volume refers to the total number of bytes of application layer data payload sent and received by the affected terminal during the duration of the comprehensive threat event. Event severity level is a pre-classification and assignment of the degree to which the comprehensive threat event may cause security impact. Initial behavior thresholds are generated based on protocol interaction frequency and content transmission volume. These initial behavior thresholds are baseline behavioral parameters calculated statistically from historical comprehensive threat event data. The initial behavior thresholds are then weighted and corrected based on the event severity level. The event severity level acts as a weighting factor, influencing the value of the initial behavior threshold; events with higher severity levels will cause the threshold to adjust in a more sensitive direction. The weighted and corrected behavior thresholds are recalculated for each new comprehensive threat event, enabling the terminal behavior baseline to adaptively adjust as the threat situation evolves.

[0043] Extracting protocol interaction frequencies from comprehensive threat events requires clearly defining the granularity of protocol interactions. For example, a request message and its corresponding response message can be considered as a complete protocol interaction. Protocol interaction frequency is calculated using a fixed time window, such as counting the number of protocol interactions per minute. Content transmission volume statistics cover the payload portion of all data packets throughout the entire lifecycle of the comprehensive threat event, excluding overhead bytes such as protocol headers. Event severity levels typically employ a discrete grading system, such as dividing them into low, medium, high, and severe levels, and mapping them to corresponding numerical values. The extraction of these parameters provides raw data characteristics for constructing a baseline of endpoint behavior. Initial behavior thresholds are generated based on protocol interaction frequencies and content transmission volume. Historical data is processed using statistical methods. The initial behavior thresholds can be set as the mean of historical protocol interaction frequencies plus a certain number of standard deviations, and the mean of historical content transmission volume plus a certain number of standard deviations. The mean reflects the average level of behavior, the standard deviation measures the range of behavioral fluctuations, and the choice of the multiplier determines the sensitivity of the baseline to abnormal behavior. The initial behavior thresholds aim to define a typical range of behavioral parameters observed in historical threat events. By incorporating the severity level of an event into the weighted adjustment of the initial behavior threshold, the impact of the event quality dimension on the baseline is introduced. A higher event severity level indicates a greater threat and its behavioral characteristics warrant more vigilance. The weighted adjustment can be achieved by using the event severity level as a weight to calculate a weighted average and weighted standard deviation of the historical data used to calculate the initial behavior threshold, or by directly scaling the initial behavior threshold result based on its severity level. For example, a high-severity event might lead to a lowering of the protocol interaction frequency threshold and content transmission volume threshold, making the baseline more sensitive to detecting similar behaviors, even if the absolute values ​​of the behavioral parameters do not significantly exceed historical ranges. This adjustment mechanism ensures that the terminal behavior baseline not only focuses on the quantitative anomalies of behavior but also incorporates a risk assessment of the qualitative aspects of behavior.

[0044] The dynamic evolution of the endpoint behavior baseline is achieved by recalculating the weighted and corrected behavior threshold for each new integrated threat event. Newly generated integrated threat events are immediately added to the historical dataset, and the threshold calculation process is re-executed. Dynamic adjustment ensures that the endpoint behavior baseline can promptly capture new characteristics caused by changes in network attack strategies or drift in endpoint behavior patterns, avoiding detection failures due to baseline obsolescence. The endpoint behavior baseline is essentially a continuous learning process, and its accuracy depends on the size and representativeness of the integrated threat event set. Deviation detection is performed on real-time network communication data streams based on the endpoint behavior baseline. Deviation detection is a process of continuously comparing the current actual behavior parameters of the endpoint with the thresholds set in the endpoint behavior baseline in real time. The protocol interaction frequency of the real-time network communication data stream is monitored to see if it exceeds the protocol threshold of the endpoint behavior baseline. The protocol threshold is the upper limit set for the protocol interaction frequency in the endpoint behavior baseline. The amount of real-time transmitted content is statistically analyzed to see if it exceeds the content threshold of the endpoint behavior baseline. The content threshold is the upper limit set for the amount of content transmitted in the endpoint behavior baseline. When any threshold is exceeded, a deviation detection result containing the exceedance value and the time point is generated. The exceedance value records the specific amount by which the actual measured value exceeds the threshold, and the time point records the precise moment when the threshold exceedance occurred. Monitoring real-time network communication data streams requires maintaining a sliding time window. Within this window, the number of protocol interactions initiated by the terminal is accumulated in real time to calculate the current protocol interaction frequency. The calculated real-time frequency value is compared with the protocol threshold of the terminal's behavior baseline, typically through inequality checks. Similarly, calculating the real-time transmitted content volume requires accumulating the number of bytes of data payload sent and received by the terminal within the time window to obtain the real-time content transmission volume. This volume is then compared with the content threshold of the terminal's behavior baseline. The threshold comparison is performed continuously, generating a comparison result for each measurement period.

[0045] Referring to Table 1, deviation detection results are generated instantly. Once the real-time protocol interaction frequency exceeds the protocol threshold or the real-time transmitted content exceeds the content threshold, the system immediately generates a deviation detection result record. The deviation detection result record contains several key fields: the terminal identifier that triggered the deviation, the type of threshold breached (protocol threshold or content threshold), the breach value (e.g., the specific number of times or bytes exceeded the threshold), and the time point of the breach. The breach value reflects the degree of deviation, while the time point is used for subsequent time-series analysis and event correlation. Deviation detection is the primary output application of the terminal behavior baseline, applying knowledge learned from historical threat events to real-time traffic monitoring.

[0046] Table 1: Deviation Detection Result Record Table

[0047] The construction of endpoint behavior baselines is a process of transforming discrete threat events into continuous monitoring standards. Protocol interaction frequency and content transmission volume, as behavioral characteristics, are highly measurable. The introduction of event severity levels allows the baseline to distinguish threats of different degrees. A dynamic adjustment mechanism ensures the timeliness of the baseline. Deviation detection is the ultimate manifestation of the baseline's value. The setting of protocol and content thresholds directly affects the false positive and false negative rates. Recording breakthrough values ​​helps assess the severity of abnormal behavior. Precise recording of time points provides a basis for reconstructing the attack timeline. Endpoint behavior baselines can be constructed separately for different types of IoT terminal device groups to reflect the differences in their behavioral characteristics. The statistical method for initial behavior thresholds needs to be robust enough to resist interference from outliers in historical data. The specific algorithm for weighted correction can be customized according to security management strategies. The dynamic recalculation process needs to consider the balance between computational overhead and system real-time performance. Deviation detection results serve as important input signals for subsequent threat attribution analysis. The record structure shown in the table ensures standardized storage and exchange of deviation information.

[0048] Example 5: Threat source analysis is performed on deviation detection results. The goal of threat source analysis is to trace the root cause behind the abnormal network behavior that triggers the deviation detection results, identify the source device of the attack, and the propagation path of the attack in the network. Deviation detection results are the output of the terminal behavior baseline monitoring stage, indicating which IoT terminal devices' real-time behavior exceeds the security baseline. The communication peer addresses of abnormal terminals are extracted from the deviation detection results. Abnormal terminals are terminal devices recorded in the deviation detection results whose behavior exceeds the protocol threshold or content threshold. The communication peer addresses are the Internet Protocol addresses of other devices or servers that communicated with the abnormal terminal during the time period when the deviation behavior occurred. The registration information of the peer addresses in the trusted device list is traced back. The trusted device list is a database that records the identifiers and attributes of all devices that have passed trust verification. The registration information includes the device's factory identification code, network address, device type, physical location, department, and administrator contact information. The system tracks the historical protocol interaction records and content transmission records of the peer address. The historical protocol interaction records store detailed information about all protocol sessions the peer address participated in over a past period, including session establishment time, protocol type, interaction frequency, and key field sequences. The historical content transmission records save the data payload content, data size, and timestamps sent and received by the peer address. An attack path topology map is generated based on the registration information and historical records. This attack path topology map is a network graph where nodes represent involved network entities, edges represent communication connections between them, and the edges are labeled with the communication time, protocol, and abnormal characteristics.

[0049] The system integrates threat attribution analysis results with a comprehensive threat event set, a high-level threat event group generated by merging protocol-layer and content-layer anomalies through spatiotemporal correlation analysis. It generates an endpoint security posture report, a structured document comprehensively reflecting the security status, threats suffered, and threat propagation of one or more IoT endpoints within a specific time period. The attack path topology map and comprehensive threat events are sorted chronologically, a sequence of events arranged in chronological order, with each connection event in the attack path topology map and each event in the comprehensive threat event set placed in its correct position. The associated endpoint addresses and threat types for each event are labeled. Associated endpoint addresses are the source and destination endpoint addresses involved in the event, and threat types are categories categorized based on event characteristics, such as protocol abuse, data leakage, and unauthorized access. Finally, the system summarizes the distribution characteristics of breach values ​​in deviation detection results. These characteristics are obtained through statistical analysis of breach values ​​in all deviation detection results, including the frequency of breaches of different threshold types, the interval distribution of breach values, and the temporal clustering of breach behaviors. Generate structured reports that include timelines, threat types, and distribution characteristics. The structured reports organize information in a machine-readable format, such as Extensible Markup Language (EXPLAIN) or JavaScript Object Notation (JavaScript) format, which facilitates automated processing and system integration.

[0050] Threat attribution analysis connects isolated deviations into potential attack chains. Extracting the communication peer address from deviation detection results is the first step in attribution. Tracing the registration information of trusted devices is used to determine the legitimacy of the peer address. Tracking historical records reveals possible lateral movement paths of attackers. Attack path topology maps visualize the analysis results. Integrating a comprehensive set of threat events provides richer threat context. Sorting events chronologically helps in understanding attack sequences. Labeling addresses and threat types makes report information clear. Summarizing deviation distribution characteristics reveals the scale and pattern of attacks. Generating structured reports facilitates automated processing and manual review. Timelines show that attack activity has a clear temporal logic. Threat type labeling helps quickly characterize attack behavior. Distribution characteristics indicate that attacks are concentrated within specific time periods.

[0051] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus.

[0052] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.

Claims

1. A network security detection method based on Internet of Things (IoT) terminal devices, characterized in that, include: Real-time capture of network communication data streams from IoT terminal devices, and extraction of device identifiers, communication protocol characteristics, and transmission content characteristics from the data streams; The extracted device identifiers are verified for trustworthiness, and a list of trusted devices containing the verification results is generated. Establish a protocol behavior model based on the characteristics of the communication protocol, and identify abnormal protocol interaction behaviors through the protocol behavior model and mark them as protocol layer abnormal events. Analyze the matching degree between the characteristics of the transmitted content and the preset content rules, identify content violations and mark them as content-layer abnormal events; Spatiotemporal correlation analysis is performed on protocol layer anomalies and content layer anomalies to generate a comprehensive set of threat events. A baseline of terminal behavior is constructed based on a comprehensive set of threat events, and the judgment threshold of the terminal behavior baseline is dynamically adjusted. Deviation detection is performed on the real-time network communication data stream based on the terminal behavior baseline, and the deviation detection results are output. Threat source analysis is performed on deviations from detection results to determine the source terminals and attack paths of threats; Integrate threat attribution analysis results with a comprehensive set of threat events to generate an endpoint security posture report.

2. The network security detection method based on IoT terminal devices according to claim 1, characterized in that, The credibility verification of the extracted device identifier includes: Separate the factory identifier and the dynamic session identifier from the device identifier; Verify that the factory identification code exists in the pre-registered device database; Detect whether the frequency of dynamic session identifier generation complies with the preset security policy; If the factory identification code is verified and the dynamic session identifier complies with the security policy, the device identifier is added to the trusted device list and marked with a verification timestamp.

3. The network security detection method based on IoT terminal devices according to claim 2, characterized in that, The established protocol behavior model includes: Statistically analyze the frequency of occurrence and interaction sequence of various protocols in historical communication data streams; Extract the patterns of change in key fields during protocol interaction; Generate a protocol state transition diagram based on frequency of occurrence, interaction sequence, and key field change patterns; When real-time protocol interaction behavior deviates from the protocol state transition diagram, a protocol layer exception event flag is triggered.

4. The network security detection method based on IoT terminal devices according to claim 3, characterized in that, The identified violations include: The transmitted content characteristics are split into header metadata and payload data; Detect whether the header metadata contains unauthorized instruction code; Compare payload data with the whitelist mode of preset content rules; If unauthorized instruction code or payload data deviates from the whitelist pattern, a content layer exception event flag is triggered.

5. The network security detection method based on IoT terminal devices according to claim 4, characterized in that, The spatiotemporal correlation analysis includes: Record the occurrence time and source terminal address of protocol layer and content layer abnormal events; Calculate the time interval and logical dependency between two types of abnormal events with the same source terminal address; If the time interval is less than the threshold and there is a logical dependency, the related events will be merged into a comprehensive threat event.

6. The network security detection method based on IoT terminal devices according to claim 5, characterized in that, The establishment of the terminal behavior baseline includes: Extract the frequency of protocol interactions, the amount of content transmitted, and the severity level of the incident from comprehensive threat events; Initial behavior thresholds are generated based on protocol interaction frequency and content transmission volume; The initial behavior threshold is weighted and adjusted based on the severity level of the event; The weighted and adjusted behavioral threshold is recalculated for each new integrated threat event.

7. The network security detection method based on IoT terminal devices according to claim 6, characterized in that, The deviation detection includes: Monitor whether the protocol interaction frequency of real-time network communication data streams exceeds the protocol threshold of the terminal behavior baseline; Statistically determine whether the amount of real-time transmitted content exceeds the content threshold of the terminal behavior baseline; When any threshold is exceeded, a deviation detection result containing the exceeded value and the time point is generated.

8. The network security detection method based on IoT terminal devices according to claim 7, characterized in that, The threat attribution analysis includes: Extract the communication peer address of the abnormal terminal from the deviation detection results; Retrieve the registration information of the peer address in the trusted device list; Track the historical protocol interaction records and content transmission records of the peer address; An attack path topology map is generated based on registration information and historical records.

9. The network security detection method based on IoT terminal devices according to claim 8, characterized in that, The generated terminal security posture report includes: Arrange the attack path topology map and comprehensive threat events in chronological order; Label the associated endpoint address and threat type for each event; Summarize the breakthrough numerical distribution characteristics of the deviation detection results; Generate structured reports that include timelines, threat types, and distribution characteristics.

10. A network security detection system based on an Internet of Things (IoT) terminal device, comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that, When the processor executes the computer program, it implements the steps of the network security detection method based on IoT terminal devices as described in any one of claims 1 to 9.

Citation Information

Cited By

  • Enterprise-level global network equipment anomaly detection method and system

    CN122119968A