Internet of Things card abnormal behavior monitoring method, device and equipment
By acquiring basic information and communication behavior information of IoT cards, dynamic behavioral features are extracted using the Count-Min Sketch algorithm and then concatenated with static features to generate entity profile features. These features are then input into the entity comprehensive risk assessment model, solving the accuracy problem of IoT card abnormal behavior monitoring and achieving accurate identification and improved interpretability.
Patent Information
- Application Number
- CN202512014131.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-29
- Publication Date
- 2026-02-24
AI Technical Summary
Existing methods for monitoring abnormal behavior of IoT cards are unable to effectively identify such behavior, especially in the IoT technology field where the number of terminals is surging and the types are diverse. Traditional analysis methods based on traffic characteristics have insufficient coverage.
By acquiring basic information and communication behavior information of IoT cards, dynamic behavioral features are extracted using the Count-Min Sketch algorithm and then concatenated with static features to generate entity profile features. These features are then input into the entity comprehensive risk assessment model for abnormal behavior monitoring.
It achieves accurate identification of abnormal behavior of IoT cards, increases the interpretability and accuracy of identification, and can identify abnormal behavior at the depth of business logic that is difficult to detect by traditional methods.
Smart Images

Figure CN121568115A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of Internet of Things (IoT) technology, specifically to a method, apparatus, and device for monitoring abnormal behavior of IoT cards. Background Technology
[0002] An IoT SIM card is a dedicated number card used to provide data transmission for IoT devices, such as smart home devices, wearable devices, shared bicycles, smart meters, and POS machines. Because IoT SIM cards have a wide range of applications, low costs, and diverse packages, there is a possibility of unauthorized use.
[0003] Current network information security monitoring and protection efforts largely rely on security devices monitoring the characteristics of access requests from IoT cards. However, this approach has inherent flaws such as outdated feature databases and insufficient coverage. Especially in the field of IoT technology, with the surge in the number and diversity of terminals, traditional traffic feature-based analysis methods may not be effective in identifying abnormal behavior of IoT cards. Summary of the Invention
[0004] In view of this, embodiments of this application provide a method, apparatus, and device for monitoring abnormal behavior of IoT cards, so as to improve the accuracy of identifying abnormal behavior of IoT cards.
[0005] To address the above problems, the technical solutions provided in this application are as follows:
[0006] In a first aspect, embodiments of this application provide a method for monitoring abnormal behavior of an Internet of Things (IoT) card, the method comprising:
[0007] Obtain basic information and communication behavior information of IoT cards. The basic information includes card identifier, industry type, card type and package information. The communication behavior information includes internet traffic data, voice and SMS data and location update information.
[0008] Extract dynamic behavior features of the IoT card based on the communication behavior information;
[0009] Extract the static features of the IoT card based on the aforementioned basic information;
[0010] The dynamic behavior features and static features of the IoT card are spliced together to generate the physical profile features of the IoT card.
[0011] The entity profile features of the IoT card are input into the entity comprehensive risk assessment model to obtain the abnormal behavior monitoring results of the IoT card.
[0012] In one possible implementation, the step of extracting the dynamic behavior features of the IoT card based on the communication behavior information includes:
[0013] The Count-Min Sketch algorithm is used to extract connection behavior features, network topology features, and application layer behavior features in parallel from the communication behavior information.
[0014] The connection behavior characteristics include one or more of the following: the request frequency of the source IP address and destination port combination, the occurrence frequency of the 5-tuple, and the distribution of session duration.
[0015] The network topology features include one or more of the following: the proportion of communication within an Autonomous System (AS), the hop count distribution under a specific path, and the geographic location entropy value.
[0016] The application layer behavioral characteristics include one or more of the following: domain name length distribution, access frequency of a specific user agent, and access frequency of a specific Uniform Resource Locator (URL) path prefix.
[0017] In one possible implementation, the step of extracting the static features of the IoT card based on the basic information includes:
[0018] The industry type, card type, and package information corresponding to the card identifier are encoded to generate static features of the IoT card.
[0019] In one possible implementation, the step of concatenating the dynamic behavioral features and static features of the IoT card to generate the entity profile features of the IoT card includes:
[0020] Device fingerprints and basic behavioral characteristics are determined from the communication behavior information. The device fingerprint includes one or more of the following: access point APN type, default route, heartbeat cycle, and protocol stack. The basic behavioral characteristics include one or more of the following: active time period, communication preference, traffic mutation time period, and geographical location information.
[0021] The dynamic behavior features, static features, device fingerprint, and basic behavior features of the IoT card are combined to generate the physical profile features of the IoT card.
[0022] In one possible implementation, the step of concatenating the dynamic behavioral features and static features of the IoT card to generate the entity profile features of the IoT card includes:
[0023] Obtain the weights of the target IoT card dynamic behavior features corresponding to the static features of the IoT card, wherein the target IoT card dynamic behavior features are one or more of the IoT card dynamic behavior features;
[0024] The dynamic behavior characteristics of the target IoT card are weighted according to their respective weights.
[0025] The weighted dynamic behavior features of the IoT card and the static features of the IoT card are combined to generate the entity profile features of the IoT card.
[0026] In one possible implementation, the entity comprehensive risk assessment model includes risk thresholds for the dynamic behavioral characteristics of the IoT card corresponding to the static characteristics of the IoT card;
[0027] The step of inputting the entity profile features of the IoT card into the entity comprehensive risk assessment model to obtain the abnormal behavior monitoring results of the IoT card includes:
[0028] The entity profile features of the IoT card are input into the entity comprehensive risk assessment model. When the dynamic behavior features of the IoT card in the entity profile features exceed the risk threshold corresponding to the static features of the IoT card in the entity profile features, the entity comprehensive risk assessment model outputs the abnormal behavior monitoring result of the IoT card as indicating that an anomaly exists.
[0029] In one possible implementation, the method further includes:
[0030] The IoT cards whose abnormal behavior monitoring results indicate abnormalities will be processed.
[0031] Based on the confirmation of the processing results, the entity profile features of the IoT card are used as samples to continue training the entity comprehensive risk assessment model.
[0032] Secondly, embodiments of this application provide an IoT card abnormal behavior monitoring device, the device comprising:
[0033] The acquisition unit is used to acquire basic information and communication behavior information of the Internet of Things card. The basic information includes card identifier, industry type, card type and package information. The communication behavior information includes Internet traffic data, voice and SMS data and location update information.
[0034] The first extraction unit is used to extract the dynamic behavior features of the IoT card based on the communication behavior information.
[0035] The second extraction unit is used to extract static features of the IoT card based on the basic information.
[0036] The generation unit is used to splice the dynamic behavior features and static features of the IoT card to generate the entity profile features of the IoT card.
[0037] The identification unit is used to input the entity profile features of the IoT card into the entity comprehensive risk assessment model to obtain the abnormal behavior monitoring results of the IoT card.
[0038] Thirdly, embodiments of this application provide an IoT card abnormal behavior monitoring device, including: a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the IoT card abnormal behavior monitoring method as described in any of the above claims.
[0039] Fourthly, embodiments of this application provide a computer-readable storage medium storing instructions that, when executed on a terminal device, cause the terminal device to perform the IoT card abnormal behavior monitoring method as described in any of the preceding claims.
[0040] Therefore, the embodiments of this application have the following beneficial effects:
[0041] This application embodiment extracts static and dynamic behavioral features of the IoT card based on its basic information and communication behavior information. These multi-dimensional features, including static and dynamic behavioral features, are then concatenated to obtain the entity profile features of the IoT card. The entity profile features are input into an entity comprehensive risk assessment model to obtain abnormal behavior monitoring results. During the identification process of the entity comprehensive risk assessment model, the scenario corresponding to the static features of the IoT card can be used as prior knowledge before identifying the dynamic behavioral features. This allows for accurate identification of abnormal IoT card behavior by analyzing the unique behavioral patterns of the IoT card in specific scenarios, and also increases the interpretability of the identification. Attached Figure Description
[0042] Figure 1 A schematic diagram illustrating an exemplary application scenario provided in this application embodiment;
[0043] Figure 2 A flowchart illustrating an IoT card abnormal behavior monitoring method provided in this application embodiment;
[0044] Figure 3 This is a schematic diagram of an IoT card abnormal behavior monitoring device provided in an embodiment of this application. Detailed Implementation
[0045] To make the above-mentioned objectives, features and advantages of the embodiments of this application more apparent and understandable, the embodiments of this application will be further described in detail below with reference to the accompanying drawings and specific implementation methods.
[0046] To facilitate understanding and explanation of the technical solutions provided in the embodiments of this application, the background technology of the embodiments of this application will be described first below.
[0047] IoT SIM cards are designed for IoT devices. Their wide range of applications, low cost, and diverse service packages create opportunities for misuse. For example, some users may exploit the lower cost of IoT SIM cards compared to traditional SIM cards to illegally use them as data SIM cards for internet-based activities; others may use their voice and SMS functions to make harassing calls or design various fraudulent scenarios to commit online scams.
[0048] Current network information security monitoring and protection efforts largely rely on security devices monitoring the characteristics of access requests from IoT cards. However, analyzing traffic characteristics may not be effective in identifying abnormal behavior from IoT cards.
[0049] Based on this, embodiments of this application provide a method, apparatus, and device for monitoring abnormal behavior of IoT cards. Based on a more multidimensional dataset, it integrates communication behavior information such as internet traffic data, voice and SMS data, and location update information, as well as basic IoT card information such as card identifier, industry type, card type, and package information. Dynamic and static features of the IoT card are extracted from this dataset. These multidimensional features, including static and dynamic features, are then concatenated to obtain the entity profile features of the IoT card. This represents a leap from a simple "IP profile" to an "entity profile," moving beyond simply viewing an IoT card's IP address as the start or end point of a data flow. Instead, it restores the IoT card to an IoT entity with identity, attributes, and business logic in the real world. By constructing a multidimensional feature space that integrates dynamic and static features, and using static features as prior knowledge for dynamic behavior analysis, it is possible to identify IoT card abnormal behaviors with deeper business logic that are difficult to detect with traditional traffic analysis.
[0050] To facilitate understanding of the IoT card abnormal behavior monitoring method provided in this application embodiment, the following is combined with... Figure 1 The example scenario is shown below. See also... Figure 1 As shown in the figure, this figure is a schematic diagram of an exemplary application scenario provided in the embodiments of this application.
[0051] This application embodiment can be applied to security detection equipment. The security detection equipment can acquire data from a data acquisition layer, which may include, for example, a network device / internet traffic data acquisition system, a signaling acquisition system, an IoT card information system, and an abnormal data intelligence system. The collected data may include basic information and communication behavior information of the IoT card. Basic information may include card identifier, industry type, card type, and package information, while communication behavior information may include internet traffic data, voice and SMS data, and location update information. Feature extraction can be performed using the communication behavior information and basic information to obtain dynamic and static features of the IoT card. The dynamic and static features of the IoT card are then concatenated to generate a physical profile feature of the IoT card. Finally, using the physical profile feature and a comprehensive entity risk assessment model, the abnormal behavior monitoring results of the IoT card can be obtained.
[0052] Those skilled in the art will understand that Figure 1 The schematic diagram shown is merely one example in which embodiments of this application can be implemented. The scope of application of the embodiments of this application is not limited by any aspect of this framework.
[0053] To facilitate understanding of the embodiments of this application, the following description, in conjunction with the accompanying drawings, illustrates a method for monitoring abnormal behavior of an IoT card provided by the embodiments of this application.
[0054] See Figure 2 As shown, this figure is a flowchart of an IoT card abnormal behavior monitoring method provided in an embodiment of this application. Figure 2 As shown, the method may include S201-S205:
[0055] S201: Obtain basic information and communication behavior information of the IoT card. The basic information includes card identifier, industry type, card type and package information. The communication behavior information includes Internet traffic data, voice and SMS data and location update information.
[0056] In practical applications, basic information about IoT cards can be obtained from the operator's BSS (Business Support Systems) / OSS (Operation Support Systems) system, which may include: card identifier, industry type, card type, and package information.
[0057] The card identification includes, for example, ICCID (Integrated Circuit Card Identity), IMSI (International Mobile Subscriber Identity), and the associated initial IMEI (International Mobile Equipment Identity). The industry type indicates the industry to which the IoT card is used, such as smart meters, in-vehicle navigation, or shared devices. The card type can be a plug-in or patch card, etc. Package information can include package type, such as a data plan or a single-card plan, or operator-specific tariff plans, and can also include package configurations, such as voice plan details (voice minutes), SMS plan details, data plan details, and service area.
[0058] Basic information for IoT cards can also include account opening information, such as account type (operator, virtual operator, industry customer, etc.), account opening channel (direct sales, agent, etc.), account opening time, and business functions (whether SMS and voice are enabled).
[0059] In addition, basic information about IoT SIM cards may include card device binding type, targeted whitelist, and card geographical restriction type. Card device binding type includes allowing binding to different devices, fixed binding to a single device, and periodically changing bound devices. Targeted whitelist includes specifying that for this IoT SIM card, voice calls are only allowed to calls from numbers on the specified list, SMS messages are only allowed to calls from numbers on the specified list, and internet access is only allowed to a specified range of IP addresses and domain names. Card geographical restriction type includes allowing use within a specific province or city; or allowing nationwide use, etc.
[0060] Near real-time data streams can be collected from operator network equipment / internet traffic data collection systems and signaling collection systems to obtain IoT card communication behavior information, which may include internet traffic data, voice and SMS data, and location update information. Internet traffic data may include session start / end time, source / destination IP address, destination port, uplink / downlink traffic, and accessed domain name. Voice and SMS data may include calling and called numbers, voice call duration, SMS duration, SMS length, and SMS type (uplink SMS MO / downlink SMS MT). Location update information may include Location Area Identity (LAI) and timestamps.
[0061] Additionally, external data can be acquired, such as by periodically synchronizing with anomaly data intelligence systems provided by relevant organizations via APIs (Application Programming Interfaces) to obtain anomalous samples such as anomalous IP address database, anomalous domain name database, and anomalous SMS content. These anomalous samples can be used to train the entity comprehensive risk assessment model in the embodiments of this application.
[0062] Once the basic information and communication behavior information of the IoT card are obtained, the data can be preprocessed. First, data association is performed, using ICCID or IMSI as the primary key to associate data from different sources within a time window, forming a complete record of "card number - communication behavior information - time". Second, data cleaning is performed, such as handling missing values and outliers.
[0063] By integrating basic information, communication behavior information, and existing abnormal samples of IoT cards, and performing preprocessing such as data cleaning, normalization, and correlation, a high-quality data foundation is provided for further identification of abnormal IoT card behavior.
[0064] S202: Extract dynamic behavior features of IoT cards based on communication behavior information.
[0065] To address the challenge of real-time feature extraction from massive, high-speed internet traffic data, this application's embodiments draw upon the efficient probabilistic statistical algorithm concept of Count-Min Sketch and systematically optimize it for analyzing abnormal behavior of IoT cards.
[0066] The basic principle of Count-Min Sketch is to estimate the frequency of elements in a data stream using a two-dimensional counting array of width w and depth d and d independent hash functions, with sublinear time and constant space complexity.
[0067] The Count-Min Sketch algorithm is used to efficiently process massive amounts of internet traffic tuples. Its advantage lies in utilizing probabilistic data structures to perform frequency statistics with sublinear time and space complexity. Therefore, in this embodiment, the Count-Min Sketch algorithm can be used to extract dynamic behavioral features of IoT cards from communication behavior information.
[0068] In practical applications, multiple parallel Count-Min Sketch structures can be constructed to extract dynamic behavioral features of different types of IoT cards from communication behavior information. This design retains the efficiency of the algorithm in processing massive streaming data, while establishing independent feature views for different dynamic behavior dimensions.
[0069] S203: Extract static features of IoT cards based on basic information.
[0070] For static basic information, this application embodiment converts card identifier, industry type, card type and package information into structured feature vectors to construct feature vectors that can characterize the static attributes of IoT cards.
[0071] It is understood that the execution order between S202 and S203 is not limited in the embodiments of this application.
[0072] S204: Combine the dynamic behavior features and static features of the IoT card to generate the physical profile features of the IoT card.
[0073] The primary challenge in identifying abnormal behavior of IoT cards lies in the heterogeneity of the data. In the embodiments of this application, internet traffic data is high-frequency, high-volume streaming data, voice SMS data has timestamps and event attributes, while data such as industry type, card type, and package information are low-frequency, static data. How to organically unify these "fast variables" and "slow variables" under a single analysis and identification framework is one of the problems that this application aims to solve.
[0074] This application proposes an innovative heterogeneous data fusion and analysis method. Its core lies in the deep and effective fusion of the static basic information unique to IoT cards (such as industry type, card type, issuing company, channel, and package information) with dynamic behavioral features extracted in real time based on the Count-Min Sketch algorithm. This constructs a unified feature representation that can simultaneously characterize the "identity attributes" and "behavioral patterns" of IoT cards. This solution not only solves the problem of the separation between static metadata and dynamic behavioral data in traditional methods but also significantly improves the interpretability and accuracy of subsequent security analysis tasks such as abnormal behavior identification by introducing static features of IoT cards as business semantics.
[0075] In practical applications, the dynamic behavioral features of the IoT card output by the above multiple Sketch samples can be combined with the static features of the IoT card to generate the entity profile features of the IoT card, thereby forming a complete feature description of the IoT card entity.
[0076] The specific implementation of S202-S204 can be found in the description of the following embodiments, and will not be repeated here.
[0077] S205: Input the entity profile features of the IoT card into the entity comprehensive risk assessment model to obtain the abnormal behavior monitoring results of the IoT card.
[0078] In this embodiment, dynamic and static behavioral features of abnormal samples can be extracted as entity profile features of abnormal samples, and dynamic and static behavioral features of normal samples can be extracted as entity profile features of normal samples. By training an entity comprehensive risk assessment model, the model can obtain the abnormal behavior monitoring results of the IoT card when the entity profile features of the IoT card are input. The abnormal behavior monitoring results can include the risk level of abnormal behavior of the IoT card.
[0079] The risk level of abnormal behavior of IoT cards can be identified by combining dynamic and static behavioral characteristics. For example, if two IoT cards with similar dynamic behavioral characteristics are used, one for smart door locks and the other for shared bicycles, it is normal for the IoT card used for shared bicycles to appear in different locations, but if the IoT card used for smart door locks appears in different locations, it is very likely to be abnormal. The risk level of abnormal behavior of IoT cards can be identified by matching the static business attributes with the behavioral patterns.
[0080] This application embodiment extracts static and dynamic behavioral features of the IoT card based on its basic information and communication behavior information. These multi-dimensional features, including static and dynamic behavioral features, are then concatenated to obtain the entity profile features of the IoT card. The entity profile features are input into an entity comprehensive risk assessment model to obtain abnormal behavior monitoring results. During the identification process of the entity comprehensive risk assessment model, the scenario corresponding to the static features of the IoT card can be used as prior knowledge before identifying the dynamic behavioral features. This allows for accurate identification of abnormal IoT card behavior by analyzing the unique behavioral patterns of the IoT card in specific scenarios, and also increases the interpretability of the identification.
[0081] The following section will further explain the specific implementation of each of the above steps.
[0082] Regarding feature extraction:
[0083] In one possible implementation, the specific implementation of S202 extracting the dynamic behavior characteristics of the IoT card based on communication behavior information may include:
[0084] The Count-Min Sketch algorithm is used to extract connection behavior features, network topology features, and application layer behavior features in parallel from communication behavior information.
[0085] Among them, connection behavior characteristics include one or more of the following: the frequency of requests for the source IP address and destination port combination, the frequency of occurrence of the 5-tuple, and the distribution of session duration.
[0086] Network topology characteristics include one or more of the following: the proportion of communication within an AS (Autonomous System) domain, the hop count distribution under a specific path, and the geographic location entropy value.
[0087] Application layer behavioral characteristics include one or more of the following: domain name length distribution, access frequency of a specific user agent, and access frequency of a specific URL (Uniform Resource Locator) path prefix.
[0088] Unlike a single Sketch used for macro-level traffic statistics, this application embodiment designs multiple parallel Count-Min Sketch structures to perform refined feature extraction for traffic tuples of different dimensions.
[0089] One of the Sketch structures is used to statistically analyze connection behavior characteristics, including the frequency of combinations of "source IP address and destination port," to identify patterns such as scanning and high-frequency access. Its core objective is to identify abnormal connection patterns, such as scanning and DDoS (Distributed Denial of Service) attacks. Specifically, the request frequency of source IP address and destination port combinations, counting the number of requests initiated from a specific source, can be used to detect port scanning. The frequency of the 5-tuple occurrence, i.e., 5-tuple activity, is calculated by counting the occurrence frequency of source IP, destination IP, and protocol, which can be used to identify botnet C&C (Command and Control) communication. Session duration distribution estimates the proportion of short-lived flows, as abnormal traffic typically has a very short lifespan.
[0090] A Sketch structure is used to statistically analyze network topology characteristics, including the communication frequency between the source IP and the target AS, which can be used to depict the location and connection preferences of IoT SIM cards within the network. Specifically, it tracks the proportion of communication within the AS domain, statistically analyzing the communication proportion of nodes within the source AS to distinguish between internal and cross-network traffic. It also tracks the hop count distribution along a specific path, i.e., routing hop count statistics, statistically analyzing the hop count distribution along a specific path to identify routing loops or abnormal routing choices. Finally, it calculates the geographic entropy value, combining IP geographic location data to determine the degree of geographic distribution disorder in traffic flow; high entropy values may indicate distributed attacks.
[0091] A Sketch structure is used for application-layer behavioral characteristics, including statistical analysis of the frequency of DNS query domain names or HTTP (Hypertext Transfer Protocol) URL paths, for analyzing application-layer protocol activities and content. Specifically, it tracks DNS domain name length distribution, statistically analyzing the query frequency of domain names of different lengths; DGA (Destination Randomization Algorithm) attacks typically manifest as the high frequency of long, random string domain names. It also tracks the access frequency of specific user agents, i.e., the HTTP User-Agent spectrum, statistically analyzing the access frequency of specific user agents to identify crawlers or automated tools. Finally, it tracks the access frequency of URL path prefixes, used to statistically analyze the access frequency of sensitive paths such as / admin / and / login / , for web application security monitoring.
[0092] After a preset time window, the Top-K high-frequency terms and entropy values of various dimensions of features are extracted from these parallel Sketch structures. After processing, these are combined to form a multi-dimensional dynamic feature vector representing the dynamic behavior pattern of IoT cards. This method achieves a multi-dimensional quantitative description of the dynamic behavior of IoT cards while ensuring efficiency in processing massive streaming data (O(d) time complexity, fixed memory usage).
[0093] In one possible implementation, the specific implementation of S203 extracting the static features of the IoT card based on the basic information may include:
[0094] The industry type, card type, and package information corresponding to the card identifier are encoded to generate static features of the IoT card.
[0095] This application innovatively introduces the static characteristics unique to IoT cards, namely static business attribute data, and integrates them with the aforementioned dynamic behavioral characteristics in a structured manner, realizing the leap of data analysis from "pure behavioral statistics" to "behavior-identity association analysis".
[0096] In practical applications, basic information that is static or changes infrequently can be encoded and vectorized. For example, industry type and package type can be represented by one-hot encoding or embedding, card type and account opening channel can be used as classification features, and package configuration can be quantified into numerical features, such as monthly data allowance.
[0097] These codes together form a structured static feature of the IoT card, providing a priori business semantic labels for identifying abnormal behavior of the IoT card.
[0098] In terms of building entity profiles:
[0099] In one possible implementation, S204 concatenates the dynamic behavior features and static features of the IoT card to generate the entity profile features of the IoT card. Specific implementations of this process may include:
[0100] A1: Determine the device fingerprint and basic behavioral characteristics from the communication behavior information. The device fingerprint includes one or more of the following: access point APN type, default route, heartbeat cycle, and protocol stack. The basic behavioral characteristics include one or more of the following: active period, communication preference, traffic mutation period, and geographical location information.
[0101] Device fingerprints and basic behavioral characteristics can also be determined from communication behavior information. Device fingerprints may include APN (Access Point Name) type, such as Private APN / Public APN, default route, such as whether NAT (Network Address Translation) mode is enabled, heartbeat period, which refers to a fixed heartbeat packet interval, such as 60 seconds / 300 seconds, etc., and protocol stack, such as one or more of MQTT (Message Queuing Telemetry Transport), CoAP (Constrained Application Protocol), HTTP, LWM2M (Lightweight Machine-to-Machine), etc.
[0102] Behavioral characteristics may include one or more of the following: active time periods, such as daytime / nighttime based on connection frequency; communication preferences, internal / external communication; periods of sudden traffic changes, such as periods of sudden large-volume downloads or uploads; and geographic location information, such as place of residence / movement trajectory.
[0103] A2: By combining the dynamic behavior features, static features, device fingerprint, and basic behavior features of the IoT card, a physical profile feature of the IoT card is generated.
[0104] The dynamic behavior feature vector, static business attribute feature vector, device fingerprint, and basic behavioral features are concatenated to form the final unified entity profile feature representation for each IoT card entity.
[0105] This implementation provides context for behavioral interpretation. Dynamic behavioral features (such as frequent access to specific IPs) may themselves be sparse and ambiguous. When combined with "industry type = smart water meter," the behavior can be interpreted as normal periodic data reporting; however, if combined with "industry type = vehicle rearview mirror" but the behavior is characterized by high frequency, small packets, and continuous connection, it may indicate anomalies. A "normal" benchmark is defined: in subsequent identification, feature vectors that integrate static features enable the algorithm to more accurately identify groups of "normal" devices with similar static and dynamic behavioral characteristics. This significantly improves the accuracy and interpretability of anomaly detection. An IoT card entity may be flagged as abnormal due to a significant deviation between its behavior and identity. An entity's profile may show "smart meter industry, patch card," but its dynamic behavioral features, such as frequent video streaming and access to social network IPs, strongly suggest that the IoT card may have been tampered with, transplanted, or stolen for unauthorized use.
[0106] In one possible implementation, S204 concatenates the dynamic behavior features and static features of the IoT card to generate the entity profile features of the IoT card. Specific implementations of this process may include:
[0107] B1: Obtain the weights of the target IoT card's dynamic behavior features corresponding to the IoT card's static features. The target IoT card's dynamic behavior features are one or more of the IoT card's dynamic behavior features.
[0108] Traditional statistical threshold-based identification methods are insufficiently adaptable to the heterogeneous scenarios of IoT cards in the Internet of Things (IoT) era. For example, the normal roaming behavior of a logistics vehicle terminal and the occasional roaming behavior of a fixed smart meter may have similar statistical values, but their business risks are drastically different. To address this, this application innovatively introduces a dynamic behavioral feature weighting mechanism. The core idea of this mechanism is to utilize the static characteristics of the IoT card entity (such as industry type, card type, issuing company, and package information) as prior knowledge to dynamically and differentially adjust the weights of various dynamic behavioral features in the final identification. Specifically, a configurable weight matrix or a lightweight model can be used to map the static features of the IoT card to a set of targeted dynamic behavioral feature weight coefficients.
[0109] B2: Weight the dynamic behavior characteristics of the target IoT card according to their respective weights.
[0110] B3: The weighted dynamic behavior features and static features of the IoT card are combined to generate the physical profile features of the IoT card.
[0111] One or more of the dynamic behavioral characteristics of an IoT SIM card can be used as the target IoT SIM card dynamic behavioral characteristics, weighted, and then the weighted IoT SIM card dynamic behavioral characteristics can be concatenated with the IoT SIM card static characteristics to generate the entity profile features of the IoT SIM card. Similarly, the weighted IoT SIM card dynamic behavioral characteristics, IoT SIM card static characteristics, device fingerprint, and basic behavioral characteristics can be concatenated to generate the entity profile features of the IoT SIM card.
[0112] The following section explains the dynamic behavioral feature weighting mechanism in the context of practical application scenarios.
[0113] For IoT SIM card A (smart meter), the static feature characterization is "power industry, patch card," indicating prior knowledge that it should be fixedly installed. The weighting mechanism assigns extremely high weight to the "signaling roaming frequency" feature within the dynamic behavior characteristics. Therefore, even if it generates a few roaming records, it produces a significant anomaly score in the model identification, thus being accurately captured.
[0114] For IoT SIM card B (logistics tracker), the static feature characterization of "logistics industry, card insertion / removal" indicates that it is expected to move nationwide. The weighting mechanism assigns a lower weight to the "signaling roaming frequency" in the dynamic behavior features, so similar roaming behavior will be considered normal, avoiding false alarms.
[0115] For IoT SIM card C (devices with low-data-rate plans), the weighting mechanism assigns a higher weight to the "daily average / instantaneous data consumption" feature in dynamic behavior characteristics. When its data consumption suddenly spikes to an abnormal level, even if the absolute value is lower than that of users with high data rates, it will trigger a serious alarm due to its deviation from the plan baseline and its high weight, indicating that it may be hijacked for proxy or DDoS attack purposes.
[0116] For IoT SIM card D (unlimited data plan device), the weighting mechanism will assign a lower weight to the "daily average / instantaneous data consumption" feature in the dynamic behavior characteristics, focusing on detecting its behavior patterns, such as anomalies in connection targets, protocols, etc.
[0117] Based on the efficient extraction of entity profile features, this application's embodiments construct a refined and personalized IoT card abnormal behavior monitoring system by introducing a "dynamic behavioral feature weighting mechanism." This system achieves a fundamental leap from "statistically based universal anomaly" detection to "integrated business semantics-based individual anomaly" intelligent judgment.
[0118] Regarding the identification of abnormal behavior:
[0119] In one possible implementation, the entity-wide risk assessment model includes risk thresholds for the dynamic behavioral characteristics of the IoT card corresponding to its static characteristics.
[0120] S205 inputs the entity profile features of the IoT card into the entity comprehensive risk assessment model to obtain the abnormal behavior monitoring results of the IoT card. The specific implementation of this can include:
[0121] The entity profile features of the IoT card are input into the entity comprehensive risk assessment model. When the dynamic behavior features of the IoT card in the entity profile features exceed the risk threshold corresponding to the static features of the IoT card in the entity profile features, the entity comprehensive risk assessment model outputs the abnormal behavior monitoring result of the IoT card as an anomaly.
[0122] In this embodiment, the entity-wide risk assessment model also sets risk thresholds for the dynamic behavior characteristics of the IoT card corresponding to its static characteristics, in order to identify abnormal behavior of the IoT card. For example, if the industry type in the static characteristics is smart door lock, then the location update information in its dynamic behavior characteristics should not change frequently. If the frequency of change of its location update information exceeds the threshold, then abnormal behavior of the IoT card can be identified.
[0123] In the comprehensive risk assessment model, the first layer uses preset expert experience and risk thresholds for rapid filtering to quickly identify high-risk targets exhibiting abnormal behavior. The second layer, based on statistical learning and pattern recognition, performs in-depth mining and correlation analysis on complex and concealed abnormal behaviors. The analysis results from both layers are combined using a weighted fusion algorithm to generate the final abnormal behavior monitoring results for the IoT cards. Based on this, the IoT cards are classified into different risk levels, triggering different handling strategies ranging from real-time interception to observation and monitoring.
[0124] In this embodiment, the "one-size-fits-all" global threshold is evolved into a personalized entity comprehensive risk assessment model, significantly reducing false alarms (e.g., misclassifying normal logistics roaming as abnormal) and false negatives (e.g., ignoring abnormal movement of fixed equipment), greatly improving identification accuracy. Each alarm can be traced back to specific abnormal characteristics (e.g., "abnormal roaming") and the specific business context leading to its high risk (e.g., "fixed installation equipment should not roam"), greatly assisting maintenance personnel in rapid judgment and significantly enhancing alarm interpretability. Deep integration with business logic systematically and automatically injects static business knowledge into the dynamic security analysis pipeline, enabling the security system to understand the "ought" behavior of different devices, achieving a leap from "seeing anomalies" to "understanding risks." The architecture is efficient and scalable; entity profile feature construction is based on the efficient Sketch algorithm, and the weighting mechanism can be implemented based on configuration or lightweight models. The overall solution meets the requirements of real-time processing of massive IoT data and is easy to incorporate new business attributes and risk strategies.
[0125] In summary, the solution proposed in this application achieves efficient dynamic behavioral feature extraction through Count-Min Sketch and innovatively integrates static features to construct a unified "behavior-identity" feature space, which has the following comprehensive advantages:
[0126] Excellent processing efficiency: The dynamic behavior feature extraction part inherits the sublinear time and constant space complexity of Count-Min Sketch, which can handle massive streaming data in IoT scenarios.
[0127] Comprehensive feature representation: It overcomes the one-sidedness of traditional methods that rely solely on traffic features, and integrates the fundamental static features and business attributes that determine the behavior patterns of IoT cards, making the entity profile more complete and more interpretable.
[0128] Intelligent security analysis: The entity comprehensive risk assessment model, combined with semantically rich input, enables abnormal behavior detection to accurately locate high-risk entities with "inconsistent identity and behavior", realizing an upgrade from "discovering statistical anomalies" to "assessing business risks".
[0129] Highly scalable: Both static feature vectors and dynamic Sketch architecture can be flexibly extended to adapt to new business data types or traffic analysis dimensions.
[0130] In addition, based on the above embodiments, one possible implementation may further include:
[0131] Process IoT cards whose abnormal behavior monitoring results indicate abnormality;
[0132] Based on the confirmed processing results, the entity profile features of the IoT card are used as samples to continue training the entity comprehensive risk assessment model.
[0133] This application embodiment allows for risk-level classification and handling of abnormal IoT cards, and provides feedback channels. The results of the handling are verified. If there are no complaints after the card is shut down, it is a true positive; if there are complaints of misidentification, it is a false positive.
[0134] This includes obtaining the list of anomalies confirmed by relevant departments and the responses and confirmations from enterprise clients regarding anomaly notifications. Newly confirmed samples (especially false positive samples and newly discovered true positive samples) are added to the training set, and the supervised entity comprehensive risk assessment model is periodically retrained to adapt to changes in anomaly patterns.
[0135] To address the challenge of fusing multi-source heterogeneous data in IoT security analysis, this application proposes a method for constructing multi-dimensional entity profiles based on an improved Count-Min Sketch algorithm. Currently, with the surge in enterprise terminal access and the fact that terminal types are no longer limited to office terminals, the emergence of various "generalized terminals" increases the difficulty of information security management, leading to significant data heterogeneity. This application draws on the advantages of the Count-Min Sketch algorithm, which utilizes probabilistic data structures to perform frequency statistics with sublinear time and space complexity, but makes key adaptive modifications.
[0136] The unified feature space construction for dynamic and static data fusion vectorizes low-frequency static basic information (such as account opening company, card type, and package information) to form structured static feature vectors, which are then concatenated and aligned with dynamic behavioral features generated by multiple Sketch structures. For the first time, it organically integrates temporal streaming features with attribute static features to form a complete multi-dimensional feature representation of IoT card entities, solving the challenge of representing heterogeneous data within a unified analysis framework. For high-frequency dynamic communication behavior information such as internet traffic data and voice / SMS data, it innovatively constructs multiple parallel Sketch structures, establishing independent feature views for different behavioral dimensions while preserving the algorithm's efficiency in processing massive streaming data. By independently establishing Sketches for different behavioral dimensions, it constructs multi-angle streaming feature views while maintaining sublinear spatiotemporal complexity, achieving efficient statistics and feature extraction of massive "fast variables."
[0137] Basic information such as industry type and card type is transformed into structured static feature vectors, which are then concatenated with dynamic behavioral features to construct the "fingerprint information" of the IoT card. Ultimately, this embodiment successfully unifies "fast variables" and "slow variables" into a multi-dimensional feature space, laying a solid foundation for subsequent accurate anomaly detection. Through the above collaborative design, this embodiment not only significantly improves the processing efficiency and scalability of multi-source heterogeneous IoT data but also constructs a unified feature space supporting in-depth security analysis, laying a crucial foundation for downstream tasks such as anomaly detection and behavioral modeling.
[0138] Entity profiling feature construction based on weighted clustering: By utilizing weighted multidimensional dynamic behavioral feature vectors that integrate business logic, an entity profiling system based on real data-driven approaches is constructed, breaking through the limitations of traditional reliance on expert rules.
[0139] The abnormal behavior detection mechanism that integrates business context not only reflects abnormal behavior, but also directly points to high-risk scenarios such as "business deviation" (such as mismatch between card type and behavior pattern), which greatly improves the interpretability and threat targeting of alarms.
[0140] Multi-dimensional cross-validation enhances the credibility of the judgment. By cross-validating the detection results with other business rule anomalies (such as abnormal roaming), the overall credibility and actionability of anomaly judgment are significantly improved. This mechanism achieves closed-loop mutual verification between algorithm recognition and business logic, enabling the system not only to detect anomalies but also to assist in judging the risk level and type of anomalies, providing a reliable basis for automated response and precise operation and maintenance.
[0141] Through a progressive analysis framework of "group profiling - individual detection - cross-validation", potential threats and business anomalies can be automatically and intelligently discovered from massive amounts of behavior, effectively improving the initiative and accuracy of IoT security protection.
[0142] Based on the IoT card abnormal behavior monitoring method provided in the above method embodiments, this application also provides an IoT card abnormal behavior monitoring device, which will be described below with reference to the accompanying drawings.
[0143] See Figure 3 As shown in the figure, this is a schematic diagram of the structure of an IoT card abnormal behavior monitoring device provided in an embodiment of this application. Figure 3 As shown, the IoT card abnormal behavior monitoring device includes:
[0144] The acquisition unit 301 is used to acquire basic information and communication behavior information of the Internet of Things card. The basic information includes card identifier, industry type, card type and package information. The communication behavior information includes Internet traffic data, voice and SMS data and location update information.
[0145] The first extraction unit 302 is used to extract the dynamic behavior features of the IoT card based on the communication behavior information.
[0146] The second extraction unit 303 is used to extract static features of the IoT card based on the basic information.
[0147] The generation unit 304 is used to splice the dynamic behavior features and static features of the IoT card to generate the physical profile features of the IoT card.
[0148] The identification unit 305 is used to input the entity profile features of the IoT card into the entity comprehensive risk assessment model to obtain the abnormal behavior monitoring results of the IoT card.
[0149] In one possible implementation, the first extraction unit is specifically used for:
[0150] The Count-Min Sketch algorithm is used to extract connection behavior features, network topology features, and application layer behavior features in parallel from the communication behavior information.
[0151] The connection behavior characteristics include one or more of the following: the request frequency of the source IP address and destination port combination, the occurrence frequency of the 5-tuple, and the distribution of session duration.
[0152] The network topology features include one or more of the following: the proportion of communication within an Autonomous System (AS), the hop count distribution under a specific path, and the geographic location entropy value.
[0153] The application layer behavioral characteristics include one or more of the following: domain name length distribution, access frequency of a specific user agent, and access frequency of a specific Uniform Resource Locator (URL) path prefix.
[0154] In one possible implementation, the second extraction unit is specifically used for:
[0155] The industry type, card type, and package information corresponding to the card identifier are encoded to generate static features of the IoT card.
[0156] In one possible implementation, the generation unit is specifically used for:
[0157] Device fingerprints and basic behavioral characteristics are determined from the communication behavior information. The device fingerprint includes one or more of the following: access point APN type, default route, heartbeat cycle, and protocol stack. The basic behavioral characteristics include one or more of the following: active time period, communication preference, traffic mutation time period, and geographical location information.
[0158] The dynamic behavior features, static features, device fingerprint, and basic behavior features of the IoT card are combined to generate the physical profile features of the IoT card.
[0159] In one possible implementation, the generation unit is specifically used for:
[0160] Obtain the weights of the target IoT card dynamic behavior features corresponding to the static features of the IoT card, wherein the target IoT card dynamic behavior features are one or more of the IoT card dynamic behavior features;
[0161] The dynamic behavior characteristics of the target IoT card are weighted according to their respective weights.
[0162] The weighted dynamic behavior features of the IoT card and the static features of the IoT card are combined to generate the entity profile features of the IoT card.
[0163] In one possible implementation, the entity comprehensive risk assessment model includes risk thresholds for the dynamic behavioral characteristics of the IoT card corresponding to the static characteristics of the IoT card;
[0164] The identification unit is specifically used for:
[0165] The entity profile features of the IoT card are input into the entity comprehensive risk assessment model. When the dynamic behavior features of the IoT card in the entity profile features exceed the risk threshold corresponding to the static features of the IoT card in the entity profile features, the entity comprehensive risk assessment model outputs the abnormal behavior monitoring result of the IoT card as indicating that an anomaly exists.
[0166] In one possible implementation, the device further includes:
[0167] The processing unit is used to process the IoT cards whose abnormal behavior monitoring results indicate that there is an anomaly.
[0168] The training unit is used to further train the entity comprehensive risk assessment model based on the confirmation result of the processing result, using the entity profile features of the IoT card as samples.
[0169] In addition, this application embodiment also provides an IoT card abnormal behavior monitoring device, including: a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the IoT card abnormal behavior monitoring method as described in any of the above claims.
[0170] This application also provides a computer-readable storage medium storing instructions that, when executed on a terminal device, cause the terminal device to perform the IoT card abnormal behavior monitoring method as described in any of the above embodiments.
[0171] This application also provides a computer program product, including computer program instructions, which, when executed on a computer, cause the computer to perform the IoT card abnormal behavior monitoring method as described in any of the above embodiments.
[0172] This application embodiment extracts static and dynamic behavioral features of the IoT card based on its basic information and communication behavior information. These multi-dimensional features, including static and dynamic behavioral features, are then concatenated to obtain the entity profile features of the IoT card. The entity profile features are input into an entity comprehensive risk assessment model to obtain abnormal behavior monitoring results. During the identification process of the entity comprehensive risk assessment model, the scenario corresponding to the static features of the IoT card can be used as prior knowledge before identifying the dynamic behavioral features. This allows for accurate identification of abnormal IoT card behavior by analyzing the unique behavioral patterns of the IoT card in specific scenarios, and also increases the interpretability of the identification.
[0173] It should be noted that the various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For the systems or apparatus disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the descriptions are relatively simple, and relevant parts can be referred to the method section.
[0174] It should be understood that in this application, "at least one (item)" means one or more, and "more than" means two or more. "And / or" is used to describe the relationship between related objects, indicating that three relationships can exist. For example, "A and / or B" can represent three cases: only A exists, only B exists, and both A and B exist simultaneously, where A and B can be singular or plural. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship. "At least one (item) of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one (item) of a, b, or c can represent: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, and c can be single or multiple.
[0175] It should also be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0176] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein can be implemented directly by hardware, a software module executed by a processor, or a combination of both. The software module can be located in random access memory (RAM), main memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium known in the art.
[0177] The above description of the disclosed embodiments enables those skilled in the art to make or use this application. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of this application. Therefore, this application is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A method for monitoring abnormal behavior of an Internet of Things (IoT) card, characterized in that, The method includes: Obtain basic information and communication behavior information of IoT cards. The basic information includes card identifier, industry type, card type and package information. The communication behavior information includes internet traffic data, voice and SMS data and location update information. Extract dynamic behavior features of the IoT card based on the communication behavior information; Extract the static features of the IoT card based on the aforementioned basic information; The dynamic behavior features and static features of the IoT card are spliced together to generate the physical profile features of the IoT card. The entity profile features of the IoT card are input into the entity comprehensive risk assessment model to obtain the abnormal behavior monitoring results of the IoT card.
2. The method according to claim 1, characterized in that, The step of extracting dynamic behavior features of the IoT card based on the communication behavior information includes: The Count-Min Sketch algorithm is used to extract connection behavior features, network topology features, and application layer behavior features in parallel from the communication behavior information. The connection behavior characteristics include one or more of the following: the request frequency of the source IP address and destination port combination, the occurrence frequency of the 5-tuple, and the distribution of session duration. The network topology features include one or more of the following: the proportion of communication within an Autonomous System (AS), the hop count distribution under a specific path, and the geographic location entropy value. The application layer behavioral characteristics include one or more of the following: domain name length distribution, access frequency of a specific user agent, and access frequency of a specific Uniform Resource Locator (URL) path prefix.
3. The method according to claim 1, characterized in that, The step of extracting static features of the IoT card based on the basic information includes: The industry type, card type, and package information corresponding to the card identifier are encoded to generate static features of the IoT card.
4. The method according to any one of claims 1-3, characterized in that, The step of concatenating the dynamic behavioral features and static features of the IoT card to generate the entity profile features of the IoT card includes: Device fingerprints and basic behavioral characteristics are determined from the communication behavior information. The device fingerprint includes one or more of the following: access point APN type, default route, heartbeat cycle, and protocol stack. The basic behavioral characteristics include one or more of the following: active time period, communication preference, traffic mutation time period, and geographical location information. The dynamic behavior features, static features, device fingerprint, and basic behavior features of the IoT card are combined to generate the physical profile features of the IoT card.
5. The method according to any one of claims 1-3, characterized in that, The step of concatenating the dynamic behavioral features and static features of the IoT card to generate the entity profile features of the IoT card includes: Obtain the weights of the target IoT card dynamic behavior features corresponding to the static features of the IoT card, wherein the target IoT card dynamic behavior features are one or more of the IoT card dynamic behavior features; The dynamic behavior characteristics of the target IoT card are weighted according to their respective weights. The weighted dynamic behavior features of the IoT card and the static features of the IoT card are combined to generate the entity profile features of the IoT card.
6. The method according to claim 1, characterized in that, The entity comprehensive risk assessment model includes risk thresholds for the dynamic behavioral characteristics of the IoT card corresponding to the static characteristics of the IoT card. The step of inputting the entity profile features of the IoT card into the entity comprehensive risk assessment model to obtain the abnormal behavior monitoring results of the IoT card includes: The entity profile features of the IoT card are input into the entity comprehensive risk assessment model. When the dynamic behavior features of the IoT card in the entity profile features exceed the risk threshold corresponding to the static features of the IoT card in the entity profile features, the entity comprehensive risk assessment model outputs the abnormal behavior monitoring result of the IoT card as indicating that an anomaly exists.
7. The method according to claim 1, characterized in that, The method further includes: The IoT cards whose abnormal behavior monitoring results indicate abnormalities will be processed. Based on the confirmation of the processing results, the entity profile features of the IoT card are used as samples to continue training the entity comprehensive risk assessment model.
8. An IoT card abnormal behavior monitoring device, characterized in that, The device includes: The acquisition unit is used to acquire basic information and communication behavior information of the Internet of Things card. The basic information includes card identifier, industry type, card type and package information. The communication behavior information includes Internet traffic data, voice and SMS data and location update information. The first extraction unit is used to extract the dynamic behavior features of the IoT card based on the communication behavior information. The second extraction unit is used to extract static features of the IoT card based on the basic information. The generation unit is used to splice the dynamic behavior features and static features of the IoT card to generate the entity profile features of the IoT card. The identification unit is used to input the entity profile features of the IoT card into the entity comprehensive risk assessment model to obtain the abnormal behavior monitoring results of the IoT card.
9. An IoT card abnormal behavior monitoring device, characterized in that, include: A memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, it implements the IoT card abnormal behavior monitoring method as described in any one of claims 1-7.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores instructions that, when executed on a terminal device, cause the terminal device to perform the IoT card abnormal behavior monitoring method as described in any one of claims 1-7.