IOT botnet detection processing method, device and equipment and storage medium

Fecha de publicación: 23/12/2022
Fuente: Wipo "IOT"
The invention discloses an IOT botnet detection processing method. The method comprises the following steps: acquiring detection information of equipment to be detected; wherein the detection information comprises original traffic, an access relation, a malicious file and a communication protocol; judging whether the to-be-detected equipment is connected with the Internet or not through the detection information; if yes, judging whether the detection information is matched with a judgment rule or not; and if the detection information is matched with the IOT botnet, determining that the to-be-detected equipment is suspected to be infected with the IOT botnet, and judging whether the detection information meets a failure rule or not, and if the detection information meets the failure rule, determining that the to-be-detected equipment is infected with the IOT botnet. According to the method, feature analysis is performed on the IOT botnet attack principle, and the basis for discovering the lost equipment is enriched by introducing other dimensions, so that IOT botnet attack events can be quickly discovered, and the recognition accuracy is improved while misjudgment is reduced. In addition, the invention also provides an IOT botnet detection processing device and equipment, and a storage medium, which also have the above beneficial effects.