A MQTT broker-oriented CONNECT flooding attack detection and protection method, system and storage medium

CN122764552APending Publication Date: 2026-09-15SOUTHERN UNIVERSITY OF SCIENCE AND TECHNOLOGY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610726136.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-05-25
Publication Date
2026-09-15

AI Technical Summary

Technical Problem

[0005]鉴于上述现有技术中的不足之处,本发明的目的在于为用户提供一种面向MQTT代理的CONNECT洪泛攻击检测与防护方法、系统及存储介质,克服现有技术中物联网的异常检测方法无法高效且低资源消耗检测与防护CONNECT 洪泛攻击的缺陷

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122764552A_ABST
    Figure CN122764552A_ABST
Patent Text Reader

Abstract

The application discloses a MQTT proxy-oriented CONNECT flooding attack detection and protection method and system, a storage medium, and the method comprises the following steps: constructing a multi-dimensional input feature, performing fuzzy processing on the accurate value of the multi-dimensional input feature, triggering a fuzzy interpolation mechanism when no corresponding rule antecedent exists in a rule base, generating an inference result of an abnormal degree by using an interpolation rule, and determining whether it is abnormal traffic based on the inference result of the abnormal degree. The method and system provided by the application can output effective results even if the rules are imperfect, and improve the robustness of the system and the response capability to unknown attack modes. Moreover, the fuzzy logic detection and interpolation rule calculation complexity adopted by the method are low, the storage memory is small, the method is suitable for resource-limited Internet of Things scenes, and efficient and stable detection and protection of the CONNECT flooding attack can be realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of Internet of Things (IoT) information security technology, and in particular to a method, system, and storage medium for detecting and protecting against CONNECT flood attacks targeting MQTT brokers. Background Technology

[0002] Based on the MQTT protocol's simple design and high performance on low-power and storage-constrained devices, it is widely used in the Internet of Things (IoT) field. However, because the MQTT protocol, in order to maintain its lightweight characteristics, does not enforce complex encryption verification or multi-factor authentication mechanisms, its message broker servers are vulnerable to denial-of-service attacks, especially CONNECT flood attacks.

[0003] In existing technologies, anomaly detection methods based on complete fuzzy rule bases can utilize multi-feature inputs for soft decision-making, offering advantages in handling network anomaly scenarios with ambiguous boundaries and uncertain behavior. However, existing fuzzy detection schemes typically rely on relatively complete rule bases. When the rule base coverage is insufficient or the input observations fall into rule gaps, unstable inference results and inability to effectively output anomaly judgments can easily occur. Detection based on deep learning or complex IDS may offer high accuracy and protection against various attacks, but it requires significant rule storage and computational overhead, making it unsuitable for resource-constrained IoT scenarios.

[0004] Therefore, existing technologies need to be improved. Summary of the Invention

[0005] In view of the shortcomings of the prior art, the purpose of this invention is to provide users with a method, system and storage medium for detecting and protecting against CONNECT flood attacks for MQTT brokers, overcoming the shortcomings of existing IoT anomaly detection methods that cannot efficiently and with low resource consumption detect and protect against CONNECT flood attacks.

[0006] The technical solution adopted by this invention to solve the technical problem is as follows: In a first aspect, the present invention provides a method for detecting and protecting against CONNECT flood attacks on MQTT brokers, comprising: On the message broker server side, MQTT messages are collected, and MQTT data packets contained in the MQTT messages are extracted. Basic metrics of message broker servers for each client within a preset time window are calculated, and multi-dimensional input features are constructed based on the basic metrics. Based on fuzzy rules in a preset rule base, the input feature values ​​of the multidimensional input features are fuzzified to obtain the membership values ​​corresponding to the input feature values; Based on the membership value, it is determined whether there is a rule antecedent in the preset rule base that matches the input feature value. If not, the fuzzy rule interpolation mechanism is triggered to generate interpolation rules. Fuzzy inference is performed based on the interpolation rules to obtain a comprehensive abnormal fuzzy set. The comprehensive abnormal fuzzy set is defuzzified to obtain an anomaly score. Based on the anomaly score, it is determined whether the MQTT message is normal traffic, and corresponding protection operations are performed.

[0007] Optionally, the steps of extracting MQTT data packets contained in the MQTT message, calculating the basic metrics of the message broker servers of each client within a preset time window, and constructing multi-dimensional input features based on the basic metrics include: The collected MQTT messages are parsed to extract the source address, destination address, control message type, and timestamp. For each MQTT client, the data used includes the connection request message data, connection confirmation message data, and the total number of messages processed by the message broker server within the current time window. Based on the connection request message data, connection confirmation message data, and total message count, a multidimensional input feature is constructed.

[0008] Optionally, the step of fuzzifying the input feature values ​​of the multidimensional input features based on fuzzy rules in a preset rule base to obtain the membership values ​​corresponding to the input feature values ​​includes: Each of the connection request message data, connection confirmation message data, and total message volume is defined with a domain range and multiple language variables. For each linguistic variable, a fuzzy set is constructed using membership functions; The precise values ​​of the connection request message data, connection confirmation message data, and total message count are converted into the membership values ​​of the fuzzy set through fuzzy reasoning.

[0009] Optionally, the preset rule base stores rule antecedents and rule consequents in IF-THEN format; the step of determining whether there is a rule antecedent in the preset rule base that matches the input feature value based on the membership value, and if not, triggering a fuzzy rule interpolation mechanism to generate interpolation rules, and performing fuzzy inference based on the interpolation rules to obtain a comprehensive abnormal fuzzy set includes: Determine whether there is a rule antecedent in the preset rule base that matches the input feature value; If there is no rule antecedent matching the input feature value in the preset rule base, a transformation-based fuzzy rule interpolation mechanism is triggered to generate an interpolation rule containing the construction of intermediate rules. Fuzzy inference is performed based on interpolation rules, and a comprehensive abnormal fuzzy set is output.

[0010] Optionally, if no rule antecedent matching the input feature value exists in the preset rule base, a transformation-based fuzzy rule interpolation mechanism is triggered to generate interpolation rules containing intermediate rules, including the following steps: By using the nearest neighbor rule selection method, the most closely related rules in the preset rule base are selected; Construct fuzzy intermediate rules based on the selected multiple rules; The fuzzy intermediate rules are scaled and shifted to obtain interpolation rules.

[0011] Optionally, the step of constructing fuzzy intermediate rules based on the selected multiple rules includes: Based on the selected closest multiple rules, calculate the weights of the antecedent attributes of each closest rule on the corresponding antecedent attributes in the construction of the fuzzy intermediate rules; normalize the calculated weights to obtain the weighted intermediate antecedents. Furthermore, an offset factor is constructed based on the fuzzy antecedent corresponding to the message input value, the maximum and minimum values ​​of the intermediate antecedent, and the weights; and the intermediate consequent is determined based on the average value of the antecedent attribute offset factor and the average value of the weights. Based on the intermediate antecedent and intermediate consequent, fuzzy intermediate rules are obtained.

[0012] Optionally, the step of performing scaling and displacement transformations on the fuzzy intermediate rules to obtain interpolation rules includes: Construct a scaling factor based on intermediate antecedents and input feature values; Based on the scale factor, the rule antecedent is scaled to obtain the scaled interpolation antecedent; Perform a displacement transformation on the interpolation antecedent after scaling transformation to construct the displacement factor; The scaling transformation and displacement factor are aggregated onto the consequent property to obtain the interpolated consequent. Based on the interpolation antecedent and interpolation consequent, the interpolation rule is obtained.

[0013] Optionally, the step of determining whether the MQTT message is normal traffic based on the outlier score and performing corresponding protection operations includes: Determine whether the outlier score exceeds a preset safety threshold; If the number of requests exceeds the limit, the node is identified as an abnormal node, protection instructions are invoked to perform protection operations, the information is recorded in a hash table, and repeated protection requests from the same client are suppressed within a preset cooldown period.

[0014] Secondly, this invention discloses a CONNECT flood attack detection and protection system for MQTT brokers, comprising: The feature value construction module is used to collect MQTT messages on the message broker server side, extract the MQTT data packets contained in the MQTT messages, count the basic metrics of the message broker server of each client within a preset time window, and construct multi-dimensional input features based on the basic metrics. The first fuzzy module is used to fuzzify the input feature values ​​of the multidimensional input features based on fuzzy rules in a preset rule base to obtain the membership values ​​corresponding to the input feature values. The second fuzzy module is used to determine whether there is a rule antecedent in the preset rule base that matches the input feature value based on the membership value. If there is no antecedent, the fuzzy rule interpolation mechanism is triggered to generate interpolation rules. Fuzzy inference is performed based on the interpolation rules to obtain a comprehensive abnormal fuzzy set. The protection determination module is used to defuzzify the comprehensive abnormal fuzzy set to obtain an anomaly score, determine whether the MQTT message is normal traffic based on the anomaly score, and perform corresponding protection operations.

[0015] Thirdly, the present invention also provides a computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the steps of the CONNECT flood attack detection and protection method for MQTT brokers.

[0016] Beneficial effects: This invention discloses a method, system, and storage medium for detecting and protecting against CONNECT flooding attacks on MQTT brokers. By constructing multi-dimensional input features, the input feature values ​​are fuzzified. When a corresponding rule antecedent is missing from the rule base, a fuzzy interpolation mechanism is triggered. The interpolation rules are used to generate an inference result indicating the degree of anomaly, and the inference result determines whether the traffic is abnormal. The method and system provided by this invention can still output effective results even with incomplete rules, improving the system's robustness and ability to respond to unknown attack patterns. Attached Figure Description

[0017] Figure 1 A flowchart illustrating the steps of the CONNECT flood attack detection and protection method for MQTT brokers provided by this invention; Figure 2 This is a schematic diagram of data acquisition and feature extraction in the system of the present invention; Figure 3 This is a schematic diagram of the four stages of T-FRI interpolation in an embodiment of the present invention; Figure 4 This is a schematic diagram of the execution blocking and hash deduplication mechanism in this invention; Figure 5 A flowchart illustrating the specific application steps of the method embodiments of the present invention is provided. Figure 6 This is a block diagram illustrating the principle of the CONNECT flood attack detection and protection system for MQTT brokers provided by this invention. Detailed Implementation

[0018] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0019] The Internet of Things (IoT) is a technological system that connects physical objects with virtual information systems through networks to achieve intelligent identification, positioning, tracking, monitoring, and management. It is an important component of the future industrial network architecture, enabling communication connections between different devices and is widely used in smart homes, smart healthcare, industrial automation, and many other fields.

[0020] To ensure efficient communication between IoT devices, lightweight application protocols such as MQTT (Message Queuing Telemetry Transport) are widely used. The advantages of MQTT lie in its simple design and ability to run efficiently on low-power, storage-constrained devices. However, its openness and lack of built-in security make it vulnerable to various security threats, especially denial-of-service (DoS) attacks.

[0021] To maintain its lightweight nature, the MQTT protocol does not enforce complex encryption verification or multi-factor authentication mechanisms. Therefore, the Broker is a prime target for Denial-of-Service (DoS) attacks, especially CONNECT flood attacks. Attackers can launch a large number of CONNECT connection requests against the Broker (message broker server) in a short period, consuming connection processing and session management resources, thus preventing legitimate clients from connecting and communicating normally, increasing response latency, or even causing service interruption.

[0022] While traditional TLS / SSL encryption is effective, its primary goals are encrypted transmission, authentication, and access control. It cannot directly address the detection problem under CONNECT flooding attacks and incurs significant CPU overhead, memory consumption, and multiple rounds of interaction, exceeding the capabilities of low-end IoT devices. Detection based on deep learning or complex IDS can achieve high accuracy and prevent various attacks, but it requires substantial rule storage and computational overhead, making it unsuitable for resource-constrained IoT scenarios.

[0023] To address the aforementioned issues, this invention provides a highly efficient and low-resource-consumption CONNECT flood attack detection and protection scheme to counter DoS attacks in the MQTT protocol, which is particularly suitable for resource-constrained IoT technology fields.

[0024] The following detailed description, with reference to the accompanying drawings, describes a CONNECT flood attack detection and protection method, system, and storage medium for MQTT brokers provided by this invention.

[0025] Firstly, this invention provides a method for detecting and protecting against CONNECT flood attacks targeting MQTT brokers, such as... Figure 1 As shown, it includes: Step S1: On the message broker server side, collect MQTT messages, extract the MQTT data packets contained in the MQTT messages, count the basic metrics of the message broker servers of each client within a preset time window, and construct multi-dimensional input features based on the basic metrics.

[0026] Since the message broker server is the server side of the MQTT protocol, which is used to manage and coordinate message interactions between all clients, this step involves capturing, recording, or copying all MQTT protocol packets passing through the message broker server to determine whether any abnormalities have occurred when clients are using the MQTT protocol for message interaction. This is done to facilitate data security detection and protection.

[0027] In detail, this step involves collecting network traffic, extracting MQTT data packets from the traffic, and statistically analyzing the number of CONNECT request messages, CONNACK confirmation messages, and the total number of messages processed by the broker within a preset sliding time window, based on client identifiers. A multi-dimensional input feature is constructed using three input features: the connection request ratio (CMR), the connection confirmation ratio (CAMR), and the total number of messages (N). Since the input features in this embodiment are constructed based on three input features, the input features in this embodiment are three-dimensional. It is conceivable that more dimensional basic metrics could be used to construct four-dimensional or five-dimensional input features.

[0028] In practice, MQTT traffic on a specified network port can be captured using tools like tcpdunm or Wireshark on the server hosting the message broker. Alternatively, event callbacks or plugin mechanisms can be used to asynchronously write the original data of each message to a message queue or database.

[0029] Furthermore, during the data packet collection process, a pcap packet capture mechanism can be used in conjunction with BPF rules to filter the target MQTT traffic, thereby reducing the interference of irrelevant traffic on the statistics module.

[0030] Specifically, such as Figure 2 As shown, the steps of extracting MQTT data packets contained in the MQTT message, calculating the basic metrics of the message broker server for each client within a preset time window, and constructing input feature values ​​based on the basic metrics include: Step S11: Perform protocol parsing on the collected MQTT messages to extract the source address, destination address, control message type, and timestamp.

[0031] The collected MQTT messages are parsed to extract the source address, destination address, control message type, and timestamp, and the results are written to a cache structure. Combined with... Figure 2 As shown, in practical implementation, this cache and the buffer of the window management area can be a circular buffer, and the extracted results are written to this circular buffer in a certain order. Expired data is deleted at the same time.

[0032] Step S12: For each MQTT client, use the connection request message data, connection confirmation message data, and the total number of messages processed by the message broker server within the current time window.

[0033] The basic metrics mentioned in this step include connection request message data, connection acknowledgment message data, and the total number of messages processed by the message broker server. Specifically, the connection request message data represents the number of CONNECT control messages sent by the client within the current time window; the connection acknowledgment message data represents the number of CONNACK control messages replied to the client by the message broker server within the current time window; and the total number of messages processed by the message broker server represents the total number of messages processed by the Broker within the current time window.

[0034] Step S13: Construct multi-dimensional input features based on the connection request message data, connection confirmation message data, and total message count.

[0035] Input features are constructed based on the three fundamental metrics mentioned above: .

[0036] like Figure 2 The window statistics and feature output section shown deletes expired buffer data based on timestamps for each time window, establishes an IP hash table, and counts connection request message data, connection confirmation message data, and total message volume.

[0037] This step introduces three-dimensional input features—the connection request ratio (CMR), connection acknowledgment ratio (CAMR), and total message volume (N)—within the same sliding time window, enabling a coordinated characterization of attack behavior and system pressure. Specifically, CMR reflects the proportion of connection requests from the target client within the current time window, CAMR reflects the proportion of corresponding connection acknowledgment messages, and N reflects the overall message load borne by the Broker within the current window. The combination of these three metrics can simultaneously characterize both abnormal connection behavior of a single node and the overall traffic pressure status.

[0038] Step S2: Based on fuzzy rules in the preset rule base, fuzzify the input feature values ​​of the multidimensional input features to obtain the membership values ​​corresponding to the input feature values.

[0039] After the multidimensional input features are constructed in step S1 above, the input feature values ​​corresponding to each input feature in the multidimensional input features are fuzzed to obtain the membership values ​​corresponding to each input feature value.

[0040] In detail, this step includes: Step S21: Set the domain range and multiple language variables for the connection request message data, connection confirmation message data and total message volume, respectively.

[0041] The input feature values ​​of CMR, CAMR, and N parameters are fuzzified. Specifically, the precise values ​​of the three input features are converted into membership values ​​of fuzzy sets, and the output variable is anomaly. Specifically, the domain range and multiple linguistic variables are pre-defined for each input variable. The specific implementation is as follows: The language variables for CMR are set to low, medium, and high; the language variables for CAMR are set to low, medium, and high; the language variables for N are set to low, medium, and high; and the language variables for the output variable anomaly are normal, suspicious, and attack. Step S22: For each linguistic variable, construct a fuzzy set using membership functions.

[0042] For each linguistic variable, a triangular membership function can be used to construct a fuzzy set; in other implementations, trapezoidal membership functions, Gaussian membership functions, etc., can also be used. After the input features are fuzzified, their membership values ​​to each fuzzy set are obtained, providing a foundation for subsequent rule matching and fuzzy inference.

[0043] Step S23: Convert the precise values ​​of the connection request message data, connection confirmation message data, and total message count into the membership values ​​of the fuzzy set through fuzzy inference.

[0044] After the multidimensional input features are constructed in step S1 above, the input feature values ​​of the multidimensional input features are fuzzified to obtain the membership values ​​corresponding to the input feature values.

[0045] In one implementation, the preset rule base is stored in IF-THEN format. For example, if CMR is low, CAMR is low, and N is low, then anomaly is normal; if CMR is medium, CAMR is medium, and N is medium, then anomaly is suspicious; if CMR is high, CAMR is high, and N is high, then anomaly is an attack.

[0046] In the specific reasoning process, the Mamdani fuzzy inference system is used for logical reasoning operations. In these operations, the AND operator is used to minimize the membership degree of the rule's antecedent, and the OR operator is used to maximize the membership degree of the rule's antecedent. All rules have equal weights. The min implication rule is used to obtain the output fuzzy set corresponding to each rule, and the max aggregation operator is used to combine the output fuzzy sets of each rule into a comprehensive abnormal fuzzy set.

[0047] When a matching rule exists in the preset rule base, the system directly performs fuzzy inference and obtains the output fuzzy set. The existence of a matching rule means that there exists at least one rule such that the activation strength of the current observation on the fuzzy set of the rule's antecedent is greater than a preset matching threshold.

[0048] Further, the step of fuzzifying the input feature value based on fuzzy rules in a preset rule base to obtain the membership value corresponding to the input feature value includes: First, the specific numerical values ​​of each input feature are extracted from the multidimensional input features. For example, suppose there are three features: CMR, CAMR, and N, with values ​​of 0.18, 0.25, and 0.12, respectively. Second, each input feature value is converted into a membership degree relative to each linguistic variable. Each input feature typically defines several linguistic values, such as low, medium, and high. The membership function is used to calculate the degree to which each feature value belongs to each linguistic value, with the result between 0 and 1. For example, when CMR equals 0.18, the membership degree for low might be 0.82, for medium it might be 0.18, and for high it might be 0.00.

[0049] Step S3: Based on the membership value, determine whether there is a rule antecedent in the preset rule base that matches the input feature value. If not, trigger the fuzzy rule interpolation mechanism to generate interpolation rules, and perform fuzzy inference based on the interpolation rules to obtain a comprehensive abnormal fuzzy set.

[0050] In this step, the system first checks whether there is a fuzzy rule antecedent that matches the current input feature value based on the preset rule base. If a matching rule exists, the fuzzy inference is executed directly; if no matching rule exists, the T-FRI interpolation inference module is called to generate interpolation rules.

[0051] The steps of determining whether a rule antecedent matching the input feature value exists in the preset rule base based on the membership value, and if not, triggering a fuzzy rule interpolation mechanism to generate interpolation rules, and performing fuzzy inference based on the interpolation rules to obtain a comprehensive abnormal fuzzy set include: Step S31: Determine whether there is a rule antecedent in the preset rule base that matches the input feature value.

[0052] This step iterates through each rule in the preset rule base to determine if a matching rule antecedent exists. A rule antecedent is composed of multiple sub-conditions connected by AND; for example, the antecedent of rule R1 is "CMR is low, CAMR is low, and N is low". This step specifically includes: First, extract the membership values ​​of each sub-condition required for the rule from the fuzzification results, and then aggregate them using the AND operator. The most commonly used AND operator is the minimum value operation, which takes the minimum value among all sub-condition membership values ​​as the combined membership value of the rule's antecedent. For example, if the membership values ​​of the three sub-conditions are 0.82, 0.75, and 0.88 respectively, then the combined membership value of the antecedent is min(0.82 comma 0.75 comma 0.88) = 0.75.

[0053] Secondly, determine whether each rule matches. Typically, a matching threshold needs to be pre-set, such as 0.1 or 0.5. If the overall membership degree of a rule's antecedent is greater than or equal to this threshold, the rule is considered a match to the current input; if it is less than the threshold, it is considered a mismatch. Other criteria can also be used, such as considering a match as long as the overall membership degree is greater than 0, or selecting only the rule with the highest overall membership degree as the matching rule.

[0054] Next, summarize the matching results. After traversing all rules, check if there is at least one rule that satisfies the matching condition. If there are one or more matching rules, it is determined that "there is a matching rule antecedent," and the comprehensive membership degree of all matching rules and their antecedents is recorded for subsequent fuzzy inference. If the comprehensive membership degree of no rule reaches the threshold, it is determined that "there is no matching rule antecedent," and the fuzzy rule interpolation mechanism needs to be triggered.

[0055] Ultimately, the subsequent actions are determined based on the judgment result: if a matching rule exists, fuzzy inference is executed directly; if no matching rule exists, the interpolation method is called to generate a new rule before inference is executed.

[0056] Step S32: If there is no rule antecedent matching the input feature value in the preset rule base, then a transformation-based fuzzy rule interpolation mechanism is triggered to generate an interpolation rule containing the construction of intermediate rules.

[0057] Combination Figure 3 As shown, when there is no rule antecedent in the rule base that matches the current observation, the system triggers a transformation-based fuzzy rule interpolation mechanism (T-FRI).

[0058] Specifically, if no rule antecedent matching the input feature value exists in the preset rule base, a transformation-based fuzzy rule interpolation mechanism is triggered to generate interpolation rules containing intermediate rules, including the following steps: The T-FRI interpolation process consists of four stages: nearest neighbor rule selection, intermediate rule construction, scaling transformation, and displacement transformation. The specific implementation method is as follows: The representative value (Rep) of a fuzzy set is a precise numerical value given an arbitrary polygonal fuzzy set. , Represents the feature points of a polygon. Value ( The definition is as follows: ; in, It is assigned to feature points The weights are usually the average representative values. The distance between two fuzzy sets can be simply defined as... .

[0059] When the preset rule base does not contain a value matching the current input observation. When a matching rule antecedent is found, interpolation is performed in the following four stages.

[0060] The first stage involves selecting the nearest neighbor rule by choosing the most similar rules from the preset rule base.

[0061] By calculating the aggregate distance between the observed values ​​and the rules in the rule base, the n closest rules are selected. The distance calculation formula is as follows: ; in Representative observation value , Representative Rules , This represents the number of rule predecessors, and j represents the index of the rule predecessor. Represents the antecedent of observation, This represents the antecedent in the rule base. To eliminate the influence of dimensions, the distance between the fuzzy sets of antecedents is defined as follows: ; in, , They represent the antecedents of the rule, respectively. The maximum and minimum values.

[0062] The second stage involves constructing fuzzy intermediate rules based on the selected multiple rules.

[0063] After selecting the n rules closest to the given observations in Phase 1, fuzzy intermediate rules are constructed. .

[0064] In detail, the step of constructing fuzzy intermediate rules based on the selected multiple rules includes: Based on the selected closest multiple rules, the weights attached to the corresponding antecedent attributes in the fuzzy intermediate rules for each closest rule are calculated. The calculated weights are normalized to obtain the weighted intermediate antecedent. An offset factor is constructed based on the fuzzy antecedent corresponding to the message input value, the maximum and minimum values ​​of the intermediate antecedent, and the weights. The intermediate consequent is determined based on the average value of the antecedent attribute offset factor and the average value of the weights. Based on the intermediate antecedent and intermediate consequent, the fuzzy intermediate rules are obtained.

[0065] The detailed construction process is as follows: Representing the ( Rule No. Antecedent attributes are used to construct fuzzy intermediate rules. The The weights attached to each predecessor attribute are calculated using the following formula: ; Normalize the weights over the n rules to obtain Therefore, fuzzy intermediate rules of The calculation formula is as follows: ; This represents the intermediate predecessor obtained through weighted calculation. This is to make the inserted intermediate fuzzy rules... Compared with observed values Having the same representative value, an offset factor is introduced. Its definition is as follows: ; Analogous to the antecedent attributes of the aforementioned intermediate rules, the fuzzy set of the consequent can be used to derive the intermediate consequent. : ; in, and For the maximum and minimum values ​​of the resulting attribute, The average of the normalized weights for each rule. It is the antecedent attribute offset factor ( The average value of ).

[0066] In the third stage, the fuzzy intermediate rules are scaled and shifted to obtain interpolation rules.

[0067] This step first calculates the scale and displacement factor. Since the more similar the antecedent attributes, the more similar the consequent conclusions, this step ensures the fuzzy set of the intermediate consequent is obtained. Approximate Realistic Aftermath Fuzzy Set Therefore, it is necessary to process the fuzzy set of the consequent of the intermediate rules obtained in the previous step. Scale and displacement transformations are performed to obtain the final interpolation result.

[0068] Specifically, the step of performing scaling and displacement transformations on the fuzzy intermediate rules to obtain interpolation rules includes: Step 1) Construct a scaling factor based on the intermediate antecedents and input feature values.

[0069] This step involves constructing the scale factor. The method is as follows: the intermediate predecessor obtained in the previous step calculate: .

[0070] 2) Based on the scale factor, perform a scale transformation on the rule antecedent to obtain the scale-transformed interpolation antecedent.

[0071] Scale transformation of the rule antecedent , The predecessor, representing the scale transformation, is constructed as follows: .

[0072] 3) Perform a displacement transformation on the interpolation predecessor after the scaling transformation to construct the displacement factor.

[0073] Shift transformation of the scaled fuzzy set Thus constructing the displacement factor , making After displacement and Consistent. The construction method is as follows: .

[0074] 4) Aggregate the scale transformation and displacement factor onto the consequent property to obtain the interpolated consequent.

[0075] This step is based on scale and displacement transformations to aggregate the scale and displacement transformation factors of the antecedent onto the consequent attribute, thus obtaining the final result value. .in for ( The algebraic average of ).

[0076] Scale transformation , The consequent after scaling: ; Displacement transformation , Final interpolation consequent: ; in The calculation formula is as follows: .

[0077] Based on the interpolation antecedent and interpolation consequent, the interpolation rule is obtained.

[0078] Finally, fuzzy inference is performed based on the interpolation rules to output a comprehensive abnormal fuzzy set.

[0079] Based on matching rules in the rule base or interpolation rules generated by the T-FRI mechanism, Mamdani fuzzy logic reasoning is performed to obtain a comprehensive abnormal fuzzy set.

[0080] This step introduces a dynamic inference mechanism using T-FRI interpolation. Traditional fuzzy logic detection relies on a complete rule base; when input features cannot match the rule base, the system cannot output valid results. This invention introduces an interpolation scheme that can generate new inference rules based on existing rules. This upgrades the system from a static rule system to a dynamic rule generation system, reducing reliance on a complete rule base and improving adaptability to unknown attack patterns.

[0081] Step S4: Defuzzify the comprehensive abnormal fuzzy set to obtain an anomaly score. Based on the anomaly score, determine whether the MQTT message is normal traffic and perform corresponding protection operations.

[0082] The centroid method is used to deblur the data to obtain the precise output value, anomaly_score. The obtained anomaly_score represents the probability that the MQTT client is subjected to a CONNECT flood DoS attack. Then, defensive actions are executed based on a comparison between the anomaly_score and a threshold. The output anomaly_score is compared with a preset security threshold; if it exceeds the threshold, the system determines that the node is a malicious node and immediately invokes external commands (iptables) to block the malicious IP in real time, completing the detection and defense loop.

[0083] Specifically, the step of determining whether the MQTT message is normal traffic based on the outlier score and performing corresponding protection operations includes: Step S41: Determine whether the outlier score exceeds a preset safety threshold.

[0084] Step S42: If the outlier score exceeds the preset security threshold, the node is determined to be an outlier node, the protection command is invoked to perform protection operations, the hash table is recorded, and repeated protection requests from the same client are suppressed within the preset cooling period.

[0085] To avoid excessive CPU usage caused by frequent calls to system-level instructions (such as iptables) in high-frequency attack scenarios, this invention introduces a dynamic blocking and retrieval mechanism based on a hash table. The specific process is as follows: Figure 4 As shown, a hash table is set up based on the client's IP address, and the client's flag for the current blocking time is recorded. When a client triggers the blocking condition, the system first queries the hash table: if the client is triggering a blocking for the first time or the difference between the current blocking time and the previous blocking time exceeds the cooldown period, then the blocking action is executed and the blocking time is updated. If the client is within the cooldown period, the blocking action is not executed again.

[0086] This mechanism reduces repeated blocking triggers, lowers system call and firewall retrieval overhead, and improves the stability and repeatability of defense actions in high-frequency attack scenarios. During the debugging phase, when unblocking specific IPs or clearing the firewall rule base based on hash status, the system can re-identify and repeat blocking for subsequent attacks, ensuring the effectiveness of the defense strategy and the repeatability of debugging.

[0087] This invention employs a hash table-based anti-duplicate blocking mechanism to achieve a complete closed loop from traffic collection, anomaly detection, and defense execution. In real-world attack scenarios, attack traffic often exhibits persistent characteristics. If blocking actions are immediately repeated every time an anomaly is detected, it increases the number of system-level command calls and the burden on firewall rule processing. This invention introduces a hash table-based blocking deduplication mechanism, caching the status and time information of already blocked clients, and triggering the blocking operation only when the re-execution conditions are met, thereby reducing resource consumption and improving defense stability.

[0088] like Figure 5 As shown, the method of this embodiment of the invention, in specific application implementation, includes the following steps: Step H1: Listen to the network interface through the MQTT packet acquisition module; filter MQTT traffic based on filtering rules; extract the source IP address, destination IP address, packet type and timestamp; and write the data into the cache structure.

[0089] Step H2, Window Statistics and Feature Construction Module, deletes expired data based on sliding time window; counts Nconnect, Nconnack and N within the current window; constructs input features CMR, CAMR and N.

[0090] Step H3: The fuzzing and rule matching module fuzzifies the input features CMR, CAMR, and N; and queries the rule base for matching the current observation.

[0091] Step H4: Determine if a matching rule exists in the rule base. If it does, proceed to step H5; otherwise, proceed to step H6.

[0092] Step H5: The fuzzy inference and defuzzification module performs Mamdani inference based on matching rules or interpolation rules; defuzzification is performed using the centroid method; and anomaly score is obtained.

[0093] Step H6: When no matching rule exists, the T-FRI interpolation inference module performs fuzzy rule interpolation and generates the corresponding interpolation rule.

[0094] Step H7: Determine whether the anomaly_score is higher than the preset threshold. If yes, proceed to step H8; otherwise, proceed to step H9.

[0095] Step H8, Defense Execution Module: Determines abnormal or attack traffic; triggers blocking operation.

[0096] Step H9: The normal processing module determines that the traffic is normal and allows it to pass.

[0097] The method provided in this embodiment improves the accuracy of identifying CONNECT flooding attacks by constructing a multi-dimensional input feature that combines three features and modeling attacker characteristics and system stress levels. Furthermore, by introducing a T-FRI interpolation mechanism, it still outputs valid inference results even when the rule base is incomplete, improving the system's robustness and adaptability. Moreover, the method in this embodiment employs fuzzy inference and interpolation mechanisms, resulting in low system resource consumption and suitability for resource-constrained IoT environments. By forming a complete closed loop between detection, judgment, defense execution, and hash deduplication mechanisms, it improves online protection efficiency and reduces the overhead of repeated execution under high-frequency attacks.

[0098] Secondly, this invention discloses a CONNECT flood attack detection and protection system for MQTT brokers, such as... Figure 6 As shown, it includes: The feature value construction module 100 is used to collect MQTT messages on the message broker server side, extract the MQTT data packets contained in the MQTT messages, count the basic metrics of the message broker server of each client within a preset time window, and construct input feature values ​​based on the basic metrics; its function is as described in step S1.

[0099] The first fuzzy module 200 is used to fuzzify the input feature value based on fuzzy rules in a preset rule base to obtain the membership value corresponding to the input feature value; its function is as described in step S2.

[0100] The second fuzzy module 300 is used to determine whether there is a rule antecedent in the preset rule base that matches the input feature value based on the membership value. If there is no antecedent, the fuzzy rule interpolation mechanism is triggered to generate interpolation rules. Fuzzy inference is performed based on the interpolation rules to obtain a comprehensive abnormal fuzzy set. Its function is as described in step S3.

[0101] The protection determination module 400 is used to defuzzify the comprehensive abnormal fuzzy set to obtain an anomaly score, determine whether the MQTT message is normal traffic based on the anomaly score, and perform corresponding protection operations. Its function is as described in step S4.

[0102] Thirdly, the present invention also provides a computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the steps of the CONNECT flood attack detection and protection method for MQTT brokers.

[0103] This invention discloses a method, system, and storage medium for detecting and protecting against CONNECT flooding attacks on MQTT brokers. It constructs multiple input features, performs fuzzification processing on these features, and triggers a fuzzy interpolation mechanism when a corresponding rule predecessor is missing from the rule base. The interpolation rules are used to generate an inference result indicating the degree of anomaly, and the inference result determines whether the traffic is abnormal. The method and system provided by this invention can still output effective results even with incomplete rules, improving the system's robustness and ability to respond to unknown attack patterns.

[0104] Other embodiments of the invention will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This invention is intended to cover any variations, uses, or adaptations of the invention that follow the general principles of the invention and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of the invention are indicated by the following claims.

[0105] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the invention patent. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this patent application should be determined by the appended claims.

Claims

1. A method for detecting and protecting against CONNECT flooding attacks for MQTT brokers, characterized in that, include: On the message broker server side, MQTT messages are collected, and MQTT data packets contained in the MQTT messages are extracted. Basic metrics of message broker servers for each client within a preset time window are calculated, and multi-dimensional input features are constructed based on the basic metrics. Based on fuzzy rules in a preset rule base, the input feature values ​​of the multidimensional input features are fuzzified to obtain the membership values ​​corresponding to the input feature values; Based on the membership value, it is determined whether there is a rule antecedent in the preset rule base that matches the feature value. If not, the fuzzy rule interpolation mechanism is triggered to generate interpolation rules. Fuzzy inference is performed based on the interpolation rules to obtain a comprehensive abnormal fuzzy set. The comprehensive abnormal fuzzy set is defuzzified to obtain an anomaly score. Based on the anomaly score, it is determined whether the MQTT message is normal traffic, and corresponding protection operations are performed.

2. The CONNECT flood attack detection and protection method for MQTT brokers according to claim 1, characterized in that, The steps of extracting MQTT data packets contained in the MQTT message, calculating the basic metrics of the message broker server for each client within a preset time window, and constructing multidimensional input features based on the basic metrics include: The collected MQTT messages are parsed to extract the source address, destination address, control message type, and timestamp. For each MQTT client, the data used includes the connection request message data, connection confirmation message data, and the total number of messages processed by the message broker server within the current time window. Based on the connection request message data, connection confirmation message data, and total message count, a multidimensional input feature is constructed.

3. The CONNECT flood attack detection and protection method for MQTT brokers according to claim 2, characterized in that, The step of fuzzifying the input feature values ​​of the multidimensional input features based on fuzzy rules in a preset rule base to obtain the membership values ​​corresponding to the input feature values ​​includes: Each of the connection request message data, connection confirmation message data, and total message volume is defined with a domain range and multiple language variables. For each linguistic variable, a fuzzy set is constructed using membership functions; The input feature values ​​of the connection request message data, connection confirmation message data, and total message count are converted into the membership values ​​of the fuzzy set through fuzzy inference.

4. The CONNECT flood attack detection and protection method for MQTT brokers according to claim 1, characterized in that, The preset rule base stores rule antecedents and rule consequents in IF-THEN format; the steps of determining whether a rule antecedent matching the feature value exists in the preset rule base based on the membership value, and if not, triggering a fuzzy rule interpolation mechanism to generate interpolation rules, and performing fuzzy inference based on the interpolation rules to obtain a comprehensive abnormal fuzzy set include: Determine whether there is a rule antecedent in the preset rule base that matches the input feature value; If there is no rule antecedent matching the input feature value in the preset rule base, a transformation-based fuzzy rule interpolation mechanism is triggered to generate an interpolation rule containing the construction of intermediate rules. Fuzzy inference is performed based on interpolation rules, and a comprehensive abnormal fuzzy set is output.

5. The CONNECT flood attack detection and protection method for MQTT brokers according to claim 4, characterized in that, If no rule antecedent matching the input feature value exists in the preset rule base, a transformation-based fuzzy rule interpolation mechanism is triggered. The steps to generate interpolation rules containing the construction of intermediate rules include: By using the nearest neighbor rule selection method, the most closely related rules in the preset rule base are selected; Construct fuzzy intermediate rules based on the selected multiple rules; The fuzzy intermediate rules are scaled and shifted to obtain interpolation rules.

6. The CONNECT flood attack detection and protection method for MQTT brokers according to claim 5, characterized in that, The step of constructing fuzzy intermediate rules based on the selected multiple rules includes: Based on the selected closest multiple rules, calculate the weights of the antecedent attributes of each closest rule on the corresponding antecedent attributes in the construction of the fuzzy intermediate rules; normalize the calculated weights to obtain the weighted intermediate antecedents. Furthermore, based on the fuzzy antecedent corresponding to the input feature value, the maximum and minimum values ​​of the intermediate antecedent, and the weights, an offset factor is constructed; based on the average value of the antecedent attribute offset factor and the average value of the weights, the intermediate consequent is determined. Based on the intermediate antecedent and intermediate consequent, fuzzy intermediate rules are obtained.

7. The CONNECT flood attack detection and protection method for MQTT brokers according to claim 5, characterized in that, The step of performing scaling and displacement transformations on the fuzzy intermediate rules to obtain interpolation rules includes: Construct a scaling factor based on the intermediate antecedent and the input feature value; Based on the scale factor, the rule antecedent is scaled to obtain the scaled interpolation antecedent; Perform a displacement transformation on the scaled interpolation antecedent to construct the displacement factor; The scaling transformation and displacement factor are aggregated onto the consequent property to obtain the interpolated consequent. Based on the interpolation antecedent and interpolation consequent, the interpolation rule is obtained.

8. The CONNECT flood attack detection and protection method for MQTT brokers according to claim 1, characterized in that, The steps of determining whether the MQTT message is normal traffic based on the outlier score and performing corresponding protection operations include: Determine whether the outlier score exceeds a preset safety threshold; If the number of requests exceeds the limit, the node is identified as an abnormal node, protection instructions are invoked to perform protection operations, the information is recorded in a hash table, and repeated protection requests from the same client are suppressed within a preset cooldown period.

9. A CONNECT flood attack detection and protection system for MQTT brokers, characterized in that, include: The feature value construction module is used to collect MQTT messages on the message broker server side, extract the MQTT data packets contained in the MQTT messages, count the basic metrics of the message broker server of each client within a preset time window, and construct multi-dimensional input features based on the basic metrics. The first fuzzy module is used to fuzzify the input feature values ​​of the multidimensional input features based on fuzzy rules in a preset rule base to obtain the membership values ​​corresponding to the input feature values. The second fuzzy module is used to determine whether there is a rule antecedent in the preset rule base that matches the input feature value based on the membership value. If there is no antecedent, the fuzzy rule interpolation mechanism is triggered to generate interpolation rules. Fuzzy inference is performed based on the interpolation rules to obtain a comprehensive abnormal fuzzy set. The protection determination module is used to defuzzify the comprehensive abnormal fuzzy set to obtain an anomaly score, determine whether the MQTT message is normal traffic based on the anomaly score, and perform corresponding protection operations.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the steps of the CONNECT flood attack detection and protection method for MQTT brokers as described in any one of claims 1 to 8.