Internet of things security system based on sensor network gateway
Patent Information
- Application Number
- CN202610878604.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-06-17
- Publication Date
- 2026-09-01
AI Technical Summary
[0003]然而,基于现有技术进行网关安全处理时,一方面网络报文、安全检测报文与安全日志大多沿同一处理链路或共享缓存资源流转,容易在高并发接入、小报文冲击或日志持续增长时产生队列堆积、总线争用和存储拥塞;另一方面,现有调度方式对节点负载、瓶颈类型及拥塞程度的感知和联动调整不够充分,难以及时在本地检测、日志存储和跨节点分担之间进行自适应切换,都会降低物联网安全网关在复杂场景下的处理稳定性与安全处置效率
[0050]1、本发明通过在网卡驱动层截获网络报文并配合策略映射表执行多级分流,能够在网络报文进入内核协议栈之前,针对恶意小报文执行丢弃以阻断中断过载,并将需本地检测的流量旁路至核心态,避免大量报文涌入协议栈引发拥塞;同时,在连续物理地址空间构建彼此隔离的网络输入输出环形缓冲区和存储输入输出环形缓冲区,将网络业务与安全日志的流转路径隔离,解决了报文转发、安全检测与日志写入磁盘并发时共享缓存资源所造成的队列堆积和相互挤占问题,提升了网关入口的处理效率与数据流转的有序性;
Smart Images

Figure CN122679121A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of IoT network security and gateway communication technology, specifically to an IoT security system based on a sensor network gateway. Background Technology
[0002] An IoT security gateway is a system deployed at the edge node of a sensor network to forward, process, perform security checks, and log messages entering the gateway. Current IoT security gateway processing methods typically include unified send and receive processing based on the kernel protocol stack, deep packet inspection based on local security detection processes, and security log writing to disk based on local storage media.
[0003] However, when performing gateway security processing based on existing technologies, on the one hand, network packets, security detection packets, and security logs mostly flow along the same processing link or shared cache resources, which can easily lead to queue accumulation, bus contention, and storage congestion when there is high concurrency access, small packet impact, or continuous log growth; on the other hand, existing scheduling methods do not sufficiently perceive and coordinate adjustments to node load, bottleneck type, and congestion level, making it difficult to adaptively switch between local detection, log storage, and cross-node load sharing in a timely manner, all of which reduce the processing stability and security handling efficiency of IoT security gateways in complex scenarios. Summary of the Invention
[0004] The purpose of this invention is to provide an Internet of Things (IoT) security system based on a sensor network gateway, addressing the following technical problems:
[0005] It significantly reduces direct conflicts and concentrated contention on the same resources in the concurrent processing links of network forwarding, security detection and log storage, alleviates interruption overload and protocol stack congestion caused by all packets entering the kernel protocol stack under extreme concurrency conditions, reduces the risk of continuous overload of a single path of the local node, and thus steadily maintains the basic communication processing capacity and security handling capacity of the gateway in high-concurrency access and attack traffic impact scenarios.
[0006] The objective of this invention can be achieved through the following technical solutions:
[0007] IoT security systems based on sensor network gateways include:
[0008] The traffic interception and offloading module intercepts network packets and extracts packet attribute information at the network card driver layer, queries the policy mapping table to offload the network packets, and outputs network service packets and deep packet inspection packets.
[0009] The dual-ring buffer data transfer module has a quota control item. It constructs isolated network input / output ring buffers and storage input / output ring buffers in a continuous physical address space. It performs pointer-level transfer based on memory mapping to process the above-mentioned packets, and receives the security logs generated by the local deep packet inspection process. It outputs the occupancy ratio and backpressure flag of the network input / output ring buffers and storage input / output ring buffers.
[0010] The hardware resource load monitoring module receives the occupancy ratio and back pressure flag, collects the incremental number of CPU final cache misses, the amount of data transmitted on the peripheral component interconnect bus, the backlog of data in the network card receive queue, the input / output waiting time and the CPU scheduling delay, and constructs the load assessment relationship to output the load assessment value and bottleneck type identification.
[0011] The routing and scheduling module, in conjunction with the preset storage congestion threshold and system overload threshold, makes a congestion determination based on the received load assessment value, bottleneck type identifier and occupancy ratio, generates batch storage instructions or task sharing instructions, and outputs control parameters.
[0012] The feedback policy write-back execution module writes back the control parameters to the policy mapping table, the quota control items of the network input / output ring buffer and the storage input / output ring buffer, and the log aggregation threshold, respectively, and generates system control instructions which are then handed over to the traffic interception and offloading module to adjust the offloading action.
[0013] Furthermore, the traffic interception and offloading module is specifically used for:
[0014] Intercept network packets before allocating socket buffers in the network card's receive queue and before entering the standard Transmission Control Protocol kernel protocol stack;
[0015] Extract the five-tuple, IoT protocol identifier, message length, and security policy tag from the network packet;
[0016] Query the policy mapping table maintained in real time by the routing scheduling module and execute the three-level traffic splitting action:
[0017] For malicious small packets that match known distributed denial-of-service attack patterns, a drop action is performed at the network interface card driver layer to block interruption overload;
[0018] For security traffic that requires local deep packet inspection and normal IoT business traffic, a redirection action is performed to bypass the standard transmission control protocol kernel protocol stack and bypass the kernel-mode security inspection process and routing forwarding process.
[0019] For detection traffic that is determined to be processed across nodes and whose CPU clock cycles required for a single deep packet inspection exceed a preset performance limit, redirection and encapsulation marking are performed according to the policy mapping table, and the traffic is sent to the remote processing channel.
[0020] Furthermore, the dual-ring buffer data transfer module is specifically used for:
[0021] Construct isolated but uniformly scheduled network input / output ring buffers and storage input / output ring buffers in a contiguous physical address space;
[0022] The write end of the network input / output ring buffer is connected to the bypass flow splitting thread that performs the redirection action, and the read end is the local deep packet inspection process, the basic routing forwarding process, or the remote offloading and encapsulation thread.
[0023] The write end of the storage input / output ring buffer is the security log generated by the local deep packet inspection process, and the read end is the local persistent storage process or the batch disk flushing thread;
[0024] The two types of ring buffers maintain independent write pointers, read pointers, occupancy ratios, and backpressure flags, and report the occupancy ratios and backpressure flags to the hardware resource load monitoring module in real time.
[0025] Furthermore, the specific formula for the hardware resource load monitoring module to calculate the load assessment value is as follows:
[0026]
[0027] Current sampling period The load assessment value within; In order to be in The number of cache misses in the final cache of the central processing unit within the cycle; This is the maximum allowed last-level cache miss threshold per second for the central processing unit under benchmark testing. and They are respectively in The amount of data transmitted and received on the peripheral component interconnect bus during the cycle; The maximum theoretical physical bandwidth capacity of the peripheral component interconnect bus; and These are the weighting coefficients.
[0028] Furthermore, the hardware resource load monitoring module uses the following specific rules when outputting bottleneck type identifiers:
[0029] If the rate of increase in the CPU's final cache miss and the occupancy of the network input / output ring buffer show a positive correlation and synchronous increase within a preset number of consecutive sampling periods, then the load bottleneck is determined to be on the computing side, and a computing bottleneck identifier is output.
[0030] If the throughput of the peripheral component interconnect bus, the storage input / output ring buffer occupancy, and the log generation rate show a positive correlation and synchronous increase trend within a preset number of sampling periods, then the load bottleneck is determined to be on the storage side, and a storage bottleneck identifier is output.
[0031] Simultaneously, the message fragmentation rate, log generation rate, and the water level update weight coefficient of each ring buffer are considered. and The message fragmentation rate is defined as the proportion of messages with a length less than 128 bytes to the total number of messages. As the message fragmentation rate increases, it increments by a preset step size. The value; when the log generation rate and storage level increase, it increases according to a preset step size. The value of .
[0032] Furthermore, the specific logic for setting the preset storage congestion threshold and system overload threshold is as follows:
[0033] Storage congestion threshold setting logic: When the input / output waiting time of the local persistent storage process causes the CPU scheduling delay of the deep packet inspection process to exceed 500µs, the average load assessment value at this time is recorded as the storage congestion threshold.
[0034] System overload threshold setting logic: When the utilization rate of the network card hardware receive ring queue reaches 85%, the average load assessment value at this time is recorded as the system overload threshold.
[0035] Furthermore, when the load assessment value is less than the preset storage congestion threshold, the dual-ring buffer data flow module maintains normal network packet flow and single real-time writing of security logs to disk. When the load assessment value is greater than or equal to the storage congestion threshold but less than the system overload threshold, and the bottleneck type is identified as a storage bottleneck or the storage input / output ring buffer maintains a consistently high occupancy rate, the routing scheduling module triggers batch storage mode.
[0036] Pause the real-time writing of individual security log entries to disk, allocate a large page memory buffer in kernel mode, and redirect log data to the buffer pool;
[0037] Simultaneously reduce the interruption frequency of the log flushing thread and increase the size of a single flush block;
[0038] The aggregation trigger condition is: when the number of log entries in the buffer pool reaches the preset number or the aggregation time reaches the preset time, a dedicated background thread will flush the logs to the disk in a large block of continuous input and output at once.
[0039] Furthermore, when the load assessment value is greater than or equal to the system overload threshold, or when the ratio of the network card hardware receive ring queue utilization to the network input / output ring buffer occupancy is greater than or equal to the independently set danger level threshold used to characterize the risk of queue overflow, and the bottleneck type is identified as the computational bottleneck identifier, the routing scheduling module triggers load sharing and forwarding methods:
[0040] Based on the load assessment value reported in real time by at least one target node that has established a communication connection with the gateway, the available network input / output ring buffer capacity, and the control plane connectivity status, select the sharing node with the smallest load assessment value and a reachable control plane connectivity status.
[0041] Calculate the forwarding ratio, and encapsulate deep packet inspection packets whose processing resource consumption exceeds a preset threshold (ratio equal to the forwarding ratio) into virtual scalable LAN tunnel packets, dynamically redirecting them to the target node for load sharing; the local node only retains basic routing forwarding, heartbeat maintenance, and minimal security policy handling functions;
[0042] The specific formula for calculating the forwarding ratio is:
[0043]
[0044] In the formula, Forwarding ratio, To control the smoothing coefficient of the forwarding rate, This is the current load assessment value. This is the system overload threshold.
[0045] Furthermore, the feedback strategy write-back execution module introduces a hold period and a fallback threshold when adjusting the execution strategy:
[0046] The corresponding processing mode switch will only be triggered if the trigger conditions for batch storage mode or distributed processing and forwarding mode are met for a preset period of time.
[0047] When the load assessment value falls below the first rollback threshold and the occupancy ratio of each queue is lower than the second rollback threshold, the batch storage mode or the shared processing and forwarding mode is terminated.
[0048] Restore single real-time writes to disk, gradually reduce the forwarding ratio, reclaim local processing share, and rewrite the restored parameters back to the policy mapping table, ring buffer quota control item, and log aggregation threshold.
[0049] The beneficial effects of this invention are:
[0050] 1. This invention intercepts network packets at the network card driver layer and performs multi-level traffic splitting in conjunction with a policy mapping table. Before network packets enter the kernel protocol stack, malicious small packets are dropped to prevent interruption overload, and traffic requiring local detection is bypassed to the kernel state, avoiding congestion caused by a large influx of packets into the protocol stack. At the same time, isolated network input / output ring buffers and storage input / output ring buffers are constructed in the contiguous physical address space to isolate the flow paths of network services and security logs. This solves the problem of queue accumulation and mutual crowding caused by shared cache resources when packet forwarding, security detection, and log writing to disk are concurrent, improving the processing efficiency of the gateway entry and the orderliness of data flow.
[0051] 2. This invention collects multi-dimensional hardware resource status data, such as the number of incremental cache misses in the central processing unit and the amount of data transmitted on the interconnect bus of peripheral components, and constructs a load assessment relationship by combining the occupancy ratio of each ring buffer. The system can accurately locate whether the load bottleneck belongs to the computing side or the storage side. When storage congestion is detected, batch storage mode is automatically triggered, converting the high-frequency single log writes to disk into large block continuous writes after aggregation in the large page memory buffer pool, reducing the drag on the detection process scheduling caused by log writes to disk. When computing overload is detected, task sharing is automatically triggered, dynamically redirecting security detection messages with processing resource consumption exceeding a preset threshold to remote nodes, ensuring the basic routing forwarding and minimum security handling capabilities of local nodes under extreme concurrency conditions.
[0052] 3. This invention dynamically writes control parameters back to the policy mapping table, the ring buffer quota control item, and the log aggregation threshold through a feedback policy write-back execution module, forming a closed-loop control mechanism from traffic interception and load monitoring to policy adjustment. This ensures that the ingress traffic diversion action matches the current node's hardware capacity in real time. At the same time, a hold period and fallback threshold mechanism are introduced when performing policy adjustments and cancellations. This requires the load to fall back to a safe range before smoothly and gradually recovering the local processing share. This avoids frequent policy switching oscillations caused by short-term traffic fluctuations and secondary node overload caused by a large amount of unloaded traffic switching back instantly, thus ensuring the stability of system operation. Attached Figure Description
[0053] Other features, objects, and advantages of the invention will become more apparent from the following detailed description of non-limiting embodiments with reference to the accompanying drawings:
[0054] Figure 1 This is a schematic diagram of a module of an IoT security system based on a sensor network gateway provided in an embodiment of the present invention. Detailed Implementation
[0055] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0056] Please see Figure 1 IoT security systems based on sensor network gateways include:
[0057] The traffic interception and offloading module intercepts network packets and extracts packet attribute information at the network card driver layer, queries the policy mapping table to offload network packets, and outputs network service packets and deep packet inspection packets.
[0058] The dual-ring buffer data transfer module has a quota control item. It constructs isolated network input / output ring buffers and storage input / output ring buffers in a continuous physical address space. It performs pointer-level transfer based on memory mapping to process the above packets, and receives the security log generated by the local deep packet inspection process. It outputs the occupancy ratio and backpressure flag of the network input / output ring buffers and storage input / output ring buffers.
[0059] The hardware resource load monitoring module receives the occupancy ratio and back pressure flag, collects the incremental number of CPU final cache misses, the amount of data transmitted on the peripheral component interconnect bus, the backlog of data in the network card receive queue, the input / output waiting time and the CPU scheduling delay, and constructs the load assessment relationship to output the load assessment value and bottleneck type identification.
[0060] The routing and scheduling module, in conjunction with the preset storage congestion threshold and system overload threshold, makes a congestion determination based on the received load assessment value, bottleneck type identifier and occupancy ratio, generates batch storage instructions or task sharing instructions, and outputs control parameters.
[0061] The feedback policy write-back execution module writes back the control parameters to the policy mapping table, the network input / output ring buffer, the storage input / output ring buffer quota control items, and the log aggregation threshold, respectively, and generates system control instructions which are then handed over to the traffic interception and offloading module to adjust the offloading action.
[0062] The traffic interception and offloading module is specifically used to: intercept network packets before allocating socket buffers in the network card's receive queue and before entering the standard transmission control protocol kernel protocol stack;
[0063] Extract the five-tuple, IoT protocol identifier, message length, and security policy tag from the network packet;
[0064] Query the policy mapping table maintained in real time by the routing scheduling module and execute the three-level traffic splitting action:
[0065] For malicious small packets that match known distributed denial-of-service attack patterns, a drop action is performed at the network interface card driver layer to block interruption overload;
[0066] For security traffic that requires local deep packet inspection and normal IoT business traffic, a redirection action is performed to bypass the standard transmission control protocol kernel protocol stack and bypass the kernel-mode security inspection process and routing forwarding process.
[0067] For detection traffic that is determined to be processed across nodes and whose CPU clock cycles required for a single deep packet inspection exceed the preset performance limit, redirection and encapsulation marking are performed according to the policy mapping table and sent to the remote processing channel.
[0068] The dual-ring buffer data transfer module is specifically used to: construct network input / output ring buffers and storage input / output ring buffers that are isolated from each other but subject to unified scheduling in a continuous physical address space;
[0069] The write end of the network input / output ring buffer is connected to the bypass flow splitting thread that performs the redirection action, and the read end is the local deep packet inspection process, the basic routing forwarding process, or the remote offloading and encapsulation thread.
[0070] The write end of the storage input / output ring buffer is the security log generated by the local deep packet inspection process, and the read end is the local persistent storage process or the batch disk flushing thread;
[0071] The two types of ring buffers maintain independent write pointers, read pointers, occupancy ratios, and backpressure flags, and report the occupancy ratios and backpressure flags to the hardware resource load monitoring module in real time.
[0072] In this embodiment, the IoT security system is deployed on a sensor network gateway node, which uses a general-purpose processor, a network card with a receive queue, and a local persistent storage medium.
[0073] The system processes the links as follows: first, it intercepts network packets entering the gateway at the network card driver layer, and then completes the dropping, bypass redirection, or remote load sharing marking according to the policy mapping table;
[0074] The packets entering the local processing path and the security logs generated after detection are then sent to the network input / output ring buffer and the storage input / output ring buffer for circulation, respectively.
[0075] Then, the hardware resource load monitoring module combines the occupancy status of the two types of ring buffers with hardware counting information to obtain the load assessment value and bottleneck type identification.
[0076] Based on this result, the routing scheduling module outputs control parameters, which are then written back to the policy mapping table, the ring buffer quota control item, and the log aggregation threshold by the feedback policy write-back execution module, so as to adjust the diversion and guidance actions of subsequent packets.
[0077] This approach significantly reduces contention for the same resource across processing links when network forwarding, security detection, and log storage occur simultaneously.
[0078] The system acquires communication data units sent to the gateway from sensor terminals, control terminals, or other IoT nodes as network packets. Based on the policy mapping table maintained by the routing and scheduling module, which stores the correspondence between packet attributes and processing actions, the system guides the flow of these network packets to generate network service packets and deep packet inspection packets that need to enter the local security detection process for content-level analysis.
[0079] By performing pre-processing traffic splitting at the network card driver layer, malicious small packets are blocked during the priority processing phase, and normal IoT business traffic and security traffic that requires local deep packet inspection are guided directly into the corresponding processing path, transforming the queue accumulation caused by unified processing into a controllable flow that processes traffic types separately.
[0080] Therefore, based on the network card driver layer, the processing path at the packet entry point can be divided, avoiding interrupt overload and protocol stack congestion caused by all packets entering the kernel protocol stack first.
[0081] In practice, the traffic interception and offloading module runs in the processing stage before the network card receive queue allocates socket buffers; the module extracts the five-tuple, IoT protocol identifier, message length and security policy label from each message;
[0082] The 5-tuple is used to identify a communication session; the IoT protocol identifier is used to distinguish the protocol category to which a message belongs; the message length can be used to identify fragmented small messages;
[0083] The security policy label is used to indicate whether the communication session to which the message belongs needs to perform specific security processing; after extraction, the module queries the policy mapping table and performs a three-level traffic splitting action: malicious small messages that match known distributed denial-of-service attack patterns are directly dropped;
[0084] For security traffic and normal IoT business traffic that require local deep packet inspection, redirection is performed to bypass the standard transmission control protocol kernel protocol stack and bypass to the kernel process; for inspection traffic that has been determined to consume more processing resources than a preset threshold, redirection, encapsulation and marking are performed and the traffic is sent to the remote processing channel.
[0085] In this embodiment, the policy mapping table is continuously maintained by the routing scheduling module. Therefore, the ingress traffic distribution result is not static and unchanging, but is linked to the current node load, queue occupancy and subsequent scheduling results.
[0086] When the local processing capacity of a node is strained, the mapping table can redirect some of the detection traffic that consumes processing resources higher than a preset threshold to the remote processing path; when the node status recovers, it can also bring the corresponding traffic back to the local processing path, thereby reducing the risk of continuous overload of a single path of a local node under the condition that the concurrency exceeds the system overload threshold.
[0087] The system acquires the network service packets and deep packet inspection packets after traffic splitting. Based on the purpose of the packets, it partitions and transfers the packets, constructs a network input / output ring buffer that carries the packet transfer in the network processing path and a storage input / output ring buffer that carries the security log transfer, and generates an occupancy ratio that reflects the ratio between the occupied space and the total space, as well as a back pressure flag that is used to prompt upstream flow limiting or quota adjustment when the buffer is close to the processing capacity boundary.
[0088] By using a dual-ring buffer that is isolated from each other, the network processing link and the log storage link are carried separately, so that the backlog on one side will not directly squeeze the buffer space on the other side, realizing the separate flow of network packets and security logs, and avoiding mutual contention within the same buffer area.
[0089] In its specific implementation, the dual-ring buffer data transfer module constructs two types of ring buffers that are isolated from each other but subject to unified scheduling in a continuous physical address space, and implements pointer-level transfer through memory mapping;
[0090] Pointer-level switching involves updating the address ranges of write and read pointers via memory mapping to switch data visibility, thus avoiding multiple copy operations of data blocks.
[0091] The write end of the network input / output ring buffer is connected to the bypass flow splitting thread that performs the redirection action, and the read end is the local deep packet inspection process, the basic routing forwarding process, or the remote offloading and encapsulation thread.
[0092] The write end of the storage input / output ring buffer is the security log generated by the local deep packet inspection process, and the read end is the local persistent storage process or the batch disk flushing thread;
[0093] The two types of circular buffers maintain independent write pointers, read pointers, occupancy ratios, and back pressure flags, and report the occupancy ratios and back pressure flags to the hardware resource load monitoring module in real time.
[0094] Preferably, both the network input / output ring buffer and the storage input / output ring buffer are equipped with quota control items to limit the buffer share that a single processing path can occupy within the current system cycle;
[0095] This quota control item does not require a fixed value and can be adjusted according to the system's operating status. For example, when the network backlog increases significantly, the available share of the network input / output ring buffer can be increased, and when the log backlog increases significantly, the available share of the storage input / output ring buffer can be increased.
[0096] The quota control item here serves as the recipient of subsequent scheduling results and, together with the policy mapping table and log aggregation threshold, forms a write-back control point.
[0097] Obtain the occupancy ratio and backpressure flag of the network input / output ring buffer and storage input / output ring buffer. Based on the number of CPU last-level cache misses, the amount of data transmitted on the peripheral component interconnect bus, the backlog of data in the network card receive queue, the input / output latency, and the CPU scheduling delay, construct the load assessment relationship and output the load assessment value and bottleneck type identifier.
[0098] By incorporating the occupancy information of the ring buffer along with the hardware count information into the evaluation, the scheduling module can accurately locate the specific link to which the processing latency deteriorates based on the hardware count information and the occupancy ratio, thereby improving the consistency between subsequent processing actions and the actual bottleneck.
[0099] Obtain load assessment values, bottleneck type identifiers and occupancy ratios; determine the congestion level of the current node based on preset storage congestion thresholds and system overload thresholds; generate batch storage instructions to adjust log writing methods or task sharing instructions to adjust the processing of detection traffic that consumes more processing resources than preset thresholds; and determine control parameters including at least updated mapping rules, ring buffer resource quotas and log aggregation thresholds.
[0100] After receiving the control parameters, the feedback policy write-back execution module writes them back to the quota control items of the policy mapping table, the network input / output ring buffer, and the storage input / output ring buffer, as well as the log aggregation threshold. It then outputs system control commands, which are received by the traffic interception and offloading module to adjust the packet offloading guidance action. As a result, the ingress offloading, buffer resource usage, and log writing to disk policies can remain consistent.
[0101] In high-concurrency IoT gateways, ingress-side traffic splitting, dual-ring buffering, load assessment, and parameter write-back are linked by the same scheduling link, so that malicious small packets, local detection traffic, and remotely distributed traffic are treated differently when they enter the system.
[0102] In this way, even under extreme conditions where the proportion of fragmented packets increases or the log generation rate increases, the processing channels required for basic routing forwarding and minimum security handling can still be preserved.
[0103] This implementation method achieves orderly processing of concurrent packet forwarding, security detection, and log storage in the IoT security gateway through the combination of network card driver layer traffic splitting, dual-ring buffer flow, load assessment, and parameter write-back, reducing direct conflicts between different processing links on the same resource.
[0104] In a preferred embodiment of the present invention, the specific formula for the hardware resource load monitoring module to calculate the load assessment value is as follows:
[0105]
[0106] Current sampling period The load assessment value within; In order to be in The number of cache misses in the final cache of the central processing unit within the cycle; This is the maximum allowed last-level cache miss threshold per second for the central processing unit under benchmark testing. and They are respectively in The amount of data transmitted and received on the peripheral component interconnect bus during the cycle; The maximum theoretical physical bandwidth capacity of the peripheral component interconnect bus; and These are the weighting coefficients;
[0107] When the hardware resource load monitoring module outputs a bottleneck type identifier, the specific rules include: if the rate of increase in the CPU's final cache miss and the occupancy of the network input / output ring buffer show a positive correlation and synchronous increase within a consecutive preset number of sampling periods, then the load bottleneck is determined to be on the computing side, and a computing bottleneck identifier is output.
[0108] If the throughput of the peripheral component interconnect bus, the storage input / output ring buffer occupancy, and the log generation rate show a positive correlation and synchronous increase trend within a preset number of sampling periods, then the load bottleneck is determined to be on the storage side, and a storage bottleneck identifier is output.
[0109] Simultaneously, the message fragmentation rate, log generation rate, and the water level update weight coefficient of each ring buffer are considered. and The message fragmentation rate is defined as the proportion of messages with a length less than 128 bytes to the total number of messages. As the message fragmentation rate increases, it increments by a preset step size. The value; when the log generation rate and storage level increase, it increases according to a preset step size. The value;
[0110] The specific logic for setting the preset storage congestion threshold and system overload threshold is as follows: Storage congestion threshold setting logic: When the input / output waiting time of the local persistent storage process causes the CPU scheduling delay of the deep packet inspection process to exceed 500µs, the average load assessment value at this time is recorded as the storage congestion threshold.
[0111] System overload threshold setting logic: When the utilization rate of the network card hardware receive ring queue reaches 85%, the average load assessment value at this time is recorded as the system overload threshold.
[0112] The hardware resource load monitoring module converts the device processing status of the gateway node within a single sampling period into a load assessment value for system scheduling, and further indicates whether the current bottleneck is more biased towards the computing side or the storage side.
[0113] The system maps and correlates multi-dimensional characteristic parameters such as CPU last-level cache miss, peripheral component interconnect bus throughput, ring buffer occupancy, and log generation rate in order to more accurately describe the resource contention in the message processing link;
[0114] The system load monitoring module obtains the incremental number of cache misses in the CPU's final level cache and the amount of data transferred on the peripheral component interconnect bus. Based on a preset normalization scale, it calculates the resource pressure within a single sampling interval and generates a load assessment value. ;
[0115] In the specific calculation, the sampling length is extracted. Incremental number of cache misses in the internal CPU's final cache This value reflects the frequency of cache line replacement caused by packet parsing, security detection, and kernel mode switching. It is divided by the maximum last-level cache miss threshold per second obtained during the hardware calibration phase. and The product is normalized; simultaneously, the amount of data transmitted by the peripheral component interconnect bus within the sampling interval is extracted. With the amount of data received This is used to describe the data transfer pressure between the network interface card (NIC), storage device, and host. It is calculated by dividing the sum of the two by the maximum theoretical physical bandwidth capacity of the peripheral component interconnect bus. To normalize the bus transmission load;
[0116] Because the formula numerator is represented The amount of data transmitted within a period, used as the denominator in the calculation to ensure consistency of the computational logic. The sampling length has been taken into account in the actual calculation. It is equivalently converted to the upper limit of the amount of data that can be carried within the maximum theoretical physical bandwidth within that time window, in order to eliminate the difference in units;
[0117] Introducing weighting coefficients to balance the contributions of compute-side and storage-side disturbances to the total stress on the current node. and The load assessment value is calculated using the following formula:
[0118]
[0119] In practical implementation, and The normalized weights can be combined, and their sum can be set to 1. An example value could be: , The offset can also be adjusted according to the current operating conditions;
[0120] The first item describes the cache pressure on the computation path. This item will increase significantly when the deep packet inspection process frequently accesses packet content, rule status, and log objects.
[0121] The second item describes the handling pressure on the storage path and bus transmission path. This item will increase significantly when the security log is continuously written, the disk is flushed in batches, or the network card and storage device access the bus concurrently.
[0122] This embodiment uses the cache miss ratio to reflect whether the locality of memory access space in the processing process has decreased, and uses the bus throughput ratio to reflect whether the data transportation is approaching the upper limit, thereby providing a stable basis for subsequent scheduling.
[0123] Obtain load assessment values, network input / output ring buffer usage, storage input / output ring buffer usage, and log generation rate; attribute load bottlenecks based on synchronous change relationships and generate bottleneck type identifiers.
[0124] Specifically, if the rate of cache misses in the central processing unit increases in tandem with the occupancy of the network input / output ring buffer, it is determined that the current main pressure comes from the local security detection or message processing side, and a computing bottleneck indicator is output.
[0125] If the throughput of the peripheral component interconnect bus increases in tandem with the storage input / output ring buffer usage and log generation rate, it is determined that the current main pressure comes from the log generation and disk writing side, and a storage bottleneck indicator is output.
[0126] Synchronous increase is defined as the relevant parameter showing a positive correlation growth trend within a consecutive preset number of sampling periods;
[0127] For example, when the network input / output ring buffer is consistently close to a high occupancy rate, and the last-level cache miss increment continues to rise during this period, it indicates that a large number of packets have entered the local detection path, causing a decrease in the local processing rate. In this case, it is more appropriate to determine that it is a bottleneck on the computing side.
[0128] When the storage input / output ring buffer continues to accumulate, and the security log generation rate and the throughput of the peripheral component interconnect bus increase simultaneously, it indicates that log writing and data transfer have become the main obstacles, and it is more appropriate to identify this as a storage-side bottleneck.
[0129] Furthermore, the log generation rate, the water level of each ring buffer, and the packet fragmentation rate (defined as the proportion of packets with a length less than 128 bytes to the total number of packets) are obtained, and weighting coefficients are adjusted according to a preset step size. and The update process is as follows: the packet fragmentation rate reflects the impact of high-frequency small packets on the cache and scheduling links; the log generation rate reflects the density of write requests generated after deep packet inspection; and the ring buffer level reflects the backlog of the network path and the storage path, respectively.
[0130] Optionally, the preset step size can be set to a small increment to avoid judgment jitter caused by excessively rapid weight changes. The specific value of the preset step size is set according to the maximum weight adjustment range allowed by the system within a sampling period. For example, the preset step size can be set to 0.05. When the packet fragmentation rate increases, the preset step size is incremented. The value;
[0131] As the log generation rate and storage level increase, they will increase in increments according to a preset step size. The value; in specific engineering implementations, to ensure that the evaluation results do not drift without an upper limit, the system introduces a dynamic normalization constraint mechanism when performing weight increment: when incrementing according to a preset step size When the value is [value], the system will simultaneously reduce it by an equal amount. The value, to ensure and The sum always remains 1;
[0132] Similarly, in increasing When the value is [value], it will decrease by the same amount simultaneously. The system will also provide the value; and Set separate lower bound thresholds for the weights, such as 0.1, to prevent the pressure weight on one side from being completely cleared and losing the perception of the load on that side.
[0133] This allows for dynamic balancing of computational and storage pressures based on a weight update mechanism, ensuring a constant scale for the load assessment value after each update. This ensures that the current load assessment value is always on the same benchmark as the offline measured storage congestion threshold and system overload threshold, preventing threshold judgment failure and attribution distortion due to weight accumulation and expansion.
[0134] The system obtains the input / output latency of the local persistent storage process, the CPU scheduling latency of the deep packet inspection process, and the network card hardware receive ring queue utilization. Based on the offline stress test results, it determines the storage congestion threshold used to characterize the point where log writing to disk has begun to significantly slow down the local detection process, and the system overload threshold used to characterize the point where the network card receive path is close to the physical packet loss boundary.
[0135] Specifically, when the input / output waiting time of the local persistent storage process causes the CPU scheduling delay of the deep packet inspection process to exceed 500µs, the average load assessment value at this time is recorded as the storage congestion threshold.
[0136] When the utilization rate of the network card hardware receive ring queue reaches 85%, the average load assessment value at this time is recorded as the system overload threshold.
[0137] The system uses the average load assessment value over multiple periods as a preset threshold to filter out the interference of a single sudden traffic fluctuation on the determination of hardware resource status.
[0138] Input / output latency reflects the resource constraints on the processing link when the storage medium cannot receive log write requests in a timely manner, while CPU scheduling latency reflects the extent to which the deep packet inspection process cannot obtain processing time slices in a timely manner. Both of these correspond to the storage side crowding out local processing capabilities.
[0139] When the network card hardware receive ring queue utilization reaches 85%, it indicates that the incoming packets are approaching the boundary where buffering can no longer continue. At this time, using the average of the corresponding load assessment value as the system overload threshold is more suitable as the basis for subsequent task distribution.
[0140] This implementation provides a complete path from collecting resource status to forming scheduling criteria through load evaluation formulas, bottleneck attribution rules, and dual threshold setting logic, so that subsequent scheduling actions can be based on a unified and reusable load judgment basis.
[0141] In a preferred embodiment of the present invention, when the load assessment value is less than a preset storage congestion threshold, the dual-ring buffer data transfer module maintains normal network packet transfer and single real-time writing of security logs to the disk. When the load assessment value is greater than or equal to the storage congestion threshold and less than the system overload threshold, and the bottleneck type is identified as a storage bottleneck or the storage input / output ring buffer maintains a consistently high occupancy rate, the routing scheduling module triggers batch storage mode.
[0142] Pause real-time writing of security log entries to disk, allocate a large page memory buffer in kernel mode, and redirect log data to the buffer; synchronously reduce the interrupt frequency of the log flushing thread and increase the size of a single flush block;
[0143] The aggregation trigger condition is: when the number of log entries in the buffer pool reaches the preset number or the aggregation time reaches the preset time, a dedicated background thread will flush the logs to the disk in a large block of continuous input and output at once.
[0144] When the load assessment value is greater than or equal to the system overload threshold, or the ratio of the network card hardware receive ring queue utilization rate to the network input / output ring buffer occupancy rate is greater than or equal to the independently set danger level threshold used to characterize the risk of queue overflow, and the bottleneck type is identified as the calculation bottleneck identifier, the routing scheduling module triggers load sharing and forwarding methods:
[0145] Based on the load assessment value reported in real time by at least one target node that has established a communication connection with the gateway, the available network input / output ring buffer capacity, and the control plane connectivity status, select the sharing node with the smallest load assessment value and a reachable control plane connectivity status.
[0146] Calculate the forwarding ratio, and encapsulate deep packet inspection packets whose processing resource consumption exceeds a preset threshold (ratio equal to the forwarding ratio) into virtual scalable LAN tunnel packets, dynamically redirecting them to the target node for load sharing; the local node only retains basic routing forwarding, heartbeat maintenance, and minimal security policy handling functions;
[0147] The specific formula for calculating the forwarding ratio is:
[0148]
[0149] In the formula, The forwarding ratio is [cite:8][cite_start]. To control the smoothing coefficient of the forwarding rate, This is the current load assessment value. This is the system overload threshold.
[0150] The feedback strategy write-back execution module introduces a hold period and a rollback threshold when adjusting the execution strategy: the corresponding processing mode switch is only triggered after the trigger conditions for batch storage mode or distributed processing and forwarding mode have been met for a preset hold period.
[0151] When the load assessment value falls below the first rollback threshold and the occupancy ratio of each queue is lower than the second rollback threshold, the batch storage mode or the shared processing and forwarding mode is terminated.
[0152] Restore single real-time writes to disk, gradually reduce the forwarding ratio, reclaim local processing share, and rewrite the restored parameters back to the policy mapping table, ring buffer quota control item, and log aggregation threshold.
[0153] The routing and scheduling module converts the load assessment value and bottleneck type identifiers output by the aforementioned calculation into specific dynamic collaborative processing actions, and uses the feedback policy to write back to the execution module so that subsequent packets entering the gateway directly follow the new processing path.
[0154] This implementation includes two main types of actions: one is a batch storage method used when the storage side is under pressure but the nodes have not yet reached an overall overload state; the other is a load-sharing and forwarding method used when the computing side is under pressure or the ingress receiving path is close to the danger boundary.
[0155] Obtain the load assessment value, bottleneck type identifier, and storage input / output ring buffer occupancy ratio. Based on the storage congestion threshold and system overload threshold, determine whether to trigger a batch storage mode applicable to load assessment values greater than or equal to the storage congestion threshold and less than the system overload threshold, and where the bottleneck type identifier is the storage bottleneck identifier or the storage input / output ring buffer occupancy remains in a preset high range for several consecutive system cycles. Generate log aggregation control parameters.
[0156] In response to the storage bottleneck indicator, the system suspends high-frequency write requests from the log write thread and aggregates independent log write actions into a contiguous block storage mode to reduce the CPU time slice occupation of the log processing link on the message processing link.
[0157] In the specific implementation, after the routing scheduling module triggers the batch storage mode, it pauses the real-time writing of individual security log entries to disk, allocates a large page memory buffer pool in the kernel mode, and redirects the log data to the buffer pool.
[0158] The large page memory buffer pool is used to temporarily store log data in contiguous physical memory blocks of preset capacity, reducing the system overhead of frequent memory page allocation and fragmented read / write.
[0159] At the same time, the interruption frequency of the log flushing thread is reduced and the single flush block size is increased, so that the disk write operation is changed from multiple small block writes to fewer large block continuous input and output.
[0160] The aggregation trigger condition can use both the number of log entries and the time condition. Specifically, when the number of log entries in the buffer pool reaches the preset number, or the aggregation time reaches the preset time, a dedicated background thread will flush the logs to the disk in a large block of continuous input and output at once.
[0161] The preset number of entries can be determined based on the quotient of the optimal block size for a single continuous disk write, such as 4MB, and the average length of a single log entry, for example, set to 2000 entries.
[0162] The preset time can be determined based on the maximum log tolerance delay allowed by the system security policy, for example, it can be set to 500ms. Both can be used as part of the log aggregation threshold and adjusted during subsequent write-back.
[0163] Obtain load assessment values, network card hardware receive ring queue utilization rate, network input / output ring buffer occupancy ratio and bottleneck type identification. Based on the system overload threshold and the dangerous water level threshold used to characterize that the ingress receiving path and network processing path are close to the boundary of being unable to continue to carry smoothly, determine whether to trigger the sharing processing and forwarding mode, and generate task sharing control parameters.
[0164] Specifically, when the load assessment value is greater than or equal to the system overload threshold, or the network card hardware receiving ring queue utilization rate and the network input / output ring buffer occupancy ratio are greater than or equal to the preset danger level threshold, and the bottleneck type is identified as the computing bottleneck, the load sharing and forwarding mode is triggered to process security detection messages that require more local parsing, matching and detection resources and whose processing resource consumption is higher than the preset threshold.
[0165] In specific implementation, the routing scheduling module combines the load assessment value reported in real time by the target node that can receive offloaded traffic within the same collaborative processing system, the available network input / output ring buffer capacity used to indicate the buffer share that the target node can still receive on the network processing path, and the control plane connectivity status used to exclude currently unreachable nodes, and selects the sharing node with the smallest load assessment value and a reachable control plane connectivity status.
[0166] After the target node is determined, the scheduling module calculates the forwarding ratio and encapsulates security detection packets whose processing resource consumption exceeds the preset threshold into virtual scalable LAN tunnel packets, and dynamically redirects them to the target node for load sharing. The local node only retains basic routing forwarding, heartbeat maintenance and minimal security policy handling functions.
[0167] The purpose of calculating this forwarding ratio is to ensure that the task load distribution intensity changes smoothly with the local overload level, rather than rerouting all relevant traffic at once once a threshold is reached. Specifically, it calculates the proportion of security detection packets whose processing resource consumption exceeds a preset threshold and should be redirected to the target node within the current system cycle; that is, the forwarding ratio. ;
[0168]
[0169] Based on the natural constant In the exponential decay model, the current load assessment value With system overload threshold The difference is used to measure the degree of overload and multiplied by a smoothing coefficient used to control the forwarding rate to limit rapid changes in the forwarding ratio. ;
[0170] The smoothing coefficient The value is determined based on the slope of the performance degradation curve measured by the node during the offline stress test phase. Its value range is usually between 0.1 and 0.5. In this embodiment, it is preferably set to 0.2 to ensure that the forwarding ratio increases smoothly and slowly in the early stage of overload, and to avoid the target node from experiencing system cascading overload due to a sudden large proportion of transfer.
[0171] This embodiment determines the forwarding ratio through a continuous function, so that the local node first forwards some of the detected traffic whose processing resource consumption exceeds the preset threshold in the early stage of overload, and then gradually increases the forwarding ratio when the overload worsens. This helps to preserve the basic forwarding capacity of the local node and avoids transferring all the processing load to the remote node at once.
[0172] The system obtains the duration of the trigger conditions for batch storage or distributed processing and forwarding. Based on the holding period used to prevent frequent switching caused by short-term fluctuations and the rollback threshold, it determines whether to execute a policy switch or cancel the policy and generates recovery control parameters. The rollback threshold includes a first rollback threshold used to determine whether the load assessment value has dropped to a safe range and a second rollback threshold used to determine whether the occupancy ratio of each queue has recovered.
[0173] Specifically, the corresponding processing mode switch will only be triggered if the triggering conditions for batch storage mode or distributed processing and forwarding mode are met for a preset period of time.
[0174] When the load assessment value falls below the first rollback threshold and the occupancy ratio of each queue is lower than the second rollback threshold, the batch storage mode or the shared processing and forwarding mode is released, the single real-time write to disk is restored, the forwarding ratio is gradually reduced, the local processing share is recovered, and the restored parameters are rewritten back to the policy mapping table, the ring buffer quota control item and the log aggregation threshold.
[0175] Here, the duration of the maintenance period is not limited to a fixed time length, but is set as a number of consecutive cycles based on the system cycle, for example, it can be set to 5 system cycles;
[0176] The first and second backoff thresholds are not required to be exactly the same as the trigger thresholds. They can be set to a recovery range below the trigger boundary to reduce strategy oscillations.
[0177] Specifically, the first rollback threshold can be set to 70% of the system overload threshold or 80% of the storage congestion threshold to ensure that the release is triggered only after the load has truly fallen back.
[0178] The second backoff threshold can be set to 50% of the total capacity of the corresponding queue; for example, when the storage input / output ring buffer experiences only one instantaneous flow peak and then quickly drops back, the system will not immediately switch to batch storage mode because the hold period requirement is not continuously met.
[0179] When the network input / output ring buffer occupancy and load assessment values have continued to decline and the release conditions are met, the system releases the load sharing and forwarding mode.
[0180] At this point, for the storage path, a single real-time write to disk is directly restored; for the network processing path, removing the load sharing does not mean immediately switching all remote traffic back to the local machine, but rather triggering a smooth recycling mechanism.
[0181] The system freezes the forwarding ratio calculated in real time based on the load assessment value, and instead deducts a fixed share from the current actual forwarding ratio every preset period, such as decreasing by 10% each time. This gradual reduction of the forwarding ratio smoothly restores the local processing share.
[0182] A smooth traffic recovery mechanism independent of state release determination is adopted to prevent secondary overload and strategy oscillation caused by a large-scale unloaded traffic instantaneously switching back to the local node;
[0183] The application example is as follows: The system is deployed on multiple collaborative sensor network gateway nodes. Each node has a local security detection process, a basic routing and forwarding process, a local persistent storage process, and a policy mapping table for receiving control parameters.
[0184] When a new sensor message enters a gateway node, the traffic interception and offloading module first performs discarding, local bypassing, or remote load sharing according to the updated mapping rules.
[0185] Packets entering the local processing path flow to the deep packet inspection process and the routing forwarding process through the network input / output ring buffer. Security logs generated during the inspection process flow to the persistent storage process or the batch disk flushing thread through the storage input / output ring buffer.
[0186] The hardware resource load monitoring module continuously outputs load assessment values and bottleneck type identifiers; based on this, the routing scheduling module determines whether to maintain real-time writing to disk, switch to batch storage, or increase the remote load sharing ratio of high-energy-consuming detection packets.
[0187] After the feedback strategy write-back execution module writes back the new parameters, subsequent incoming packets are immediately processed according to the new strategy; thus forming a complete engineering deployment process from new data entry, status judgment, strategy switching to parameter write-back;
[0188] This implementation method, through batch storage, distributed processing and forwarding, and the coordination of maintenance time period and rollback threshold, enables gateway nodes to take appropriate processing actions under different types of resource stress and smoothly revoke the relevant actions after the state is restored, thereby maintaining basic communication processing capabilities and security handling capabilities as much as possible under high concurrency access and attack traffic surges.
[0189] The foregoing has provided a detailed description of one embodiment of the present invention, but this description is merely a preferred embodiment and should not be construed as limiting the scope of the invention. All equivalent variations and modifications made within the scope of the claims of this invention should still fall within the patent coverage of this invention.
Claims
1. An IoT security system based on a sensor network gateway, characterized in that, include: The traffic interception and offloading module intercepts network packets and extracts packet attribute information at the network card driver layer, queries the policy mapping table to offload the network packets, and outputs network service packets and deep packet inspection packets. The dual-ring buffer data transfer module has a quota control item. It constructs isolated network input / output ring buffers and storage input / output ring buffers in a continuous physical address space. It performs pointer-level transfer based on memory mapping to process the above-mentioned packets, and receives the security logs generated by the local deep packet inspection process. It outputs the occupancy ratio and backpressure flag of the network input / output ring buffers and storage input / output ring buffers. The hardware resource load monitoring module receives the occupancy ratio and back pressure flag, collects the incremental number of CPU final cache misses, the amount of data transmitted on the peripheral component interconnect bus, the backlog of data in the network card receive queue, the input / output waiting time and the CPU scheduling delay, and constructs a load assessment relationship to output the load assessment value and bottleneck type identifier. The routing and scheduling module, in conjunction with the preset storage congestion threshold and system overload threshold, makes a congestion determination based on the received load assessment value, bottleneck type identifier and occupancy ratio, generates batch storage instructions or task sharing instructions, and outputs control parameters. The feedback policy write-back execution module writes the control parameters back to the policy mapping table, the network input / output ring buffer, the quota control items of the storage input / output ring buffer, and the log aggregation threshold, respectively, and generates system control instructions which are then handed over to the traffic interception and offloading module to adjust the offloading action.
2. The IoT security system based on a sensor network gateway according to claim 1, characterized in that, The traffic interception and offloading module is specifically used for: Intercept network packets before allocating socket buffers in the network card's receive queue and before entering the standard Transmission Control Protocol kernel protocol stack; Extract the quintuple, IoT protocol identifier, message length, and security policy tag from the network packet; Query the policy mapping table maintained in real time by the routing scheduling module and execute the three-level traffic splitting action: For malicious small packets that match known distributed denial-of-service attack patterns, a drop action is performed at the network interface card driver layer to block interruption overload; For security traffic that requires local deep packet inspection and normal IoT business traffic, a redirection action is performed to bypass the standard transmission control protocol kernel protocol stack and bypass the kernel-mode security inspection process and routing forwarding process. For detected traffic whose processing resource consumption exceeds a preset threshold and is determined to be processed across nodes, a redirection and encapsulation mark is executed according to the policy mapping table, and the traffic is sent to the remote processing channel.
3. The IoT security system based on a sensor network gateway according to claim 1, characterized in that, The dual-ring buffer data transfer module is specifically used for: Construct isolated but uniformly scheduled network input / output ring buffers and storage input / output ring buffers in a contiguous physical address space; The write end of the network input / output ring buffer is connected to the bypass splitting thread that performs the redirection action, and the read end is the local deep packet inspection process, the basic routing forwarding process, or the remote offloading and encapsulation thread. The write end of the storage input / output ring buffer is the security log generated by the local deep packet inspection process, and the read end is the local persistent storage process or the batch disk flushing thread. The two types of ring buffers maintain independent write pointers, read pointers, occupancy ratios, and backpressure flags, and report the occupancy ratios and backpressure flags to the hardware resource load monitoring module in real time.
4. The IoT security system based on a sensor network gateway according to claim 1, characterized in that, The specific formula used by the hardware resource load monitoring module to calculate the load assessment value is as follows: ; Current sampling period The load assessment value within; In order to be in The number of cache misses in the final cache of the central processing unit within the cycle; This is the maximum allowed last-level cache miss threshold per second for the central processing unit under benchmark testing. and They are respectively in The amount of data transmitted and received on the peripheral component interconnect bus during the cycle; The maximum theoretical physical bandwidth capacity of the peripheral component interconnect bus; and These are the weighting coefficients.
5. The IoT security system based on a sensor network gateway according to claim 4, characterized in that, When the hardware resource load monitoring module outputs a bottleneck type identifier, the specific rules include: If the rate of increase in the CPU's final cache miss and the occupancy of the network input / output ring buffer show a positive correlation and synchronous increase within a preset number of consecutive sampling periods, then the load bottleneck is determined to be on the computing side, and a computing bottleneck identifier is output. If the throughput of the peripheral component interconnect bus, the storage input / output ring buffer occupancy, and the log generation rate show a positive correlation and synchronous increase trend within a preset number of sampling periods, then the load bottleneck is determined to be on the storage side, and a storage bottleneck identifier is output. Simultaneously, the weighting coefficients are updated based on message fragmentation rate, log generation rate, and the water level of each ring buffer. and The packet fragmentation rate is defined as the proportion of packets with a length less than 128 bytes to the total number of packets; as the packet fragmentation rate increases, it increases by a preset step size. The value; when the log generation rate and storage level increase, it increases according to a preset step size. The value of .
6. The IoT security system based on a sensor network gateway according to claim 1, characterized in that, The specific logic for setting the preset storage congestion threshold and system overload threshold is as follows: Storage congestion threshold setting logic: When the input / output waiting time of the local persistent storage process causes the CPU scheduling delay of the deep packet inspection process to exceed 500µs, the average load assessment value at this time is recorded as the storage congestion threshold. System overload threshold setting logic: When the utilization rate of the network card hardware receive ring queue reaches 85%, the average load assessment value at this time is recorded as the system overload threshold.
7. The IoT security system based on a sensor network gateway according to claim 1, characterized in that, When the load assessment value is less than the preset storage congestion threshold, the dual-ring buffer data flow module maintains normal network packet flow and single real-time writing of security logs to disk. When the load assessment value is greater than or equal to the storage congestion threshold but less than the system overload threshold, and the bottleneck type is identified as a storage bottleneck or the storage input / output ring buffer has a consistently high occupancy rate, the routing scheduling module triggers batch storage mode. Pause the real-time writing of individual security log entries to disk, allocate a large page memory buffer in kernel mode, and redirect log data to the buffer. Synchronously reduce the interruption frequency of the log flushing thread and increase the size of a single flush block; The aggregation trigger condition is: when the number of log entries in the buffer pool reaches the preset number or the aggregation time reaches the preset time, a dedicated background thread will flush the logs to the disk in a large block of continuous input and output at once.
8. The IoT security system based on a sensor network gateway according to claim 1, characterized in that, When the load assessment value is greater than or equal to the system overload threshold, or the network card hardware receive ring queue utilization rate and network input / output ring buffer occupancy ratio are greater than or equal to the preset danger level threshold, and the bottleneck type is identified as a computational bottleneck, the routing scheduling module triggers load sharing and forwarding methods: Based on the load assessment value reported in real time by at least one target node that has established a communication connection with the gateway, the available network input / output ring buffer capacity, and the control plane connectivity status, select the sharing node with the smallest load assessment value and a reachable control plane connectivity status. Calculate the forwarding ratio, and encapsulate deep packet inspection packets whose processing resource consumption exceeds a preset threshold at the forwarding ratio into virtual scalable LAN tunnel packets, and dynamically redirect them to the target node for load sharing; the local node only retains basic routing forwarding, heartbeat maintenance and minimal security policy handling functions; The specific formula for calculating the forwarding ratio is as follows: ; In the formula, Forwarding ratio, To control the smoothing coefficient of the forwarding rate, This is the current load assessment value. This is the system overload threshold.
9. The IoT security system based on a sensor network gateway according to claim 1, characterized in that, The feedback strategy write-back execution module introduces a hold period and a fallback threshold when adjusting the execution strategy: The corresponding processing mode switch will only be triggered if the trigger conditions for batch storage mode or distributed processing and forwarding mode are met for a preset period of time. When the load assessment value falls below the first rollback threshold and the occupancy ratio of each queue is lower than the second rollback threshold, the batch storage mode or the shared processing and forwarding mode is terminated. Restore single real-time writes to disk, gradually reduce the forwarding ratio, reclaim local processing share, and rewrite the restored parameters back to the policy mapping table, ring buffer quota control item, and log aggregation threshold.