Computer defense system based on Internet of Things
Through IoT technology, the operation data of computers, printers and webcams are monitored in real time, and access permissions are dynamically adjusted, which solves the problem of insufficient learning of dynamic characteristics of equipment operation status in the existing technology, and improves the defense capability and response efficiency of the computer's anti-leakage system.
Patent Information
- Application Number
- CN202510483030.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-17
- Publication Date
- 2025-07-22
AI Technical Summary
Existing computer anti-leakage technology lacks the ability to continuously learn the dynamic characteristics of the device's operating status, and it is difficult to adapt to new attack methods. Traditional encryption and access controls are difficult to identify the hidden leak behavior of legitimate users and the response is lagging.
The Internet of Things computer defense system is adopted to collect the operating data of computers, printers and webcams through the IoT device feature acquisition module, build a dynamic benchmark model, monitor behavior deviations in real time, assess risk status, and dynamically adjust access rights.
It realizes all-round dynamic monitoring of equipment behavior, reduces the misjudgment rate and delay of manual analysis, and improves the active defense ability and response timeliness in data leakage prevention.
Smart Images

Figure CN120354405A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of computer anti-disclosure, and particularly relates to a computer defense system based on the Internet of Things. Background Art
[0002] The technical field of computer anti-disclosure focuses on preventing sensitive data from being accessed, stolen or leaked without authorization during storage, transmission or processing. The core covers technical directions such as data encryption, access control, behavior auditing, intrusion detection, and data residue clearing.
[0003] Existing computer anti-disclosure lacks the ability to continuously learn the dynamic characteristics of device operation status and is difficult to adapt to the behavior pattern deviation caused by new attack means. For example, traditional data encryption only protects storage media and is difficult to identify hidden disclosure behaviors implemented by legitimate users through high-frequency file copying or abnormal peripheral access; role-based access control relies on predefined policies and is difficult to dynamically adjust permission levels according to real-time risks, resulting in over-restriction in low-risk scenarios or lag in response to high-risk operations. Therefore, improvements are needed. Summary of the Invention
[0004] The purpose of the present invention is to solve the drawbacks existing in the prior art and propose a computer defense system based on the Internet of Things.
[0005] To achieve the above purpose, the present invention adopts the following technical solutions: A computer defense system based on the Internet of Things includes:
[0006] An Internet of Things device feature acquisition module, which acquires the operation data of a computer and associated printers and network cameras, aggregates instruction timing, memory access, and peripheral interaction information, calculates the fluctuation and frequency data of instruction timing, memory access, and peripheral interaction information, and establishes a set of quantified device behavior indicators;
[0007] A behavior benchmark construction module, based on the set of quantified device behavior indicators, analyzes the statistical characteristics of each indicator during the target operation period, defines the normal range and change pattern, obtains the statistical boundary of device indicators, integrates the statistical boundary of device indicators, and establishes a device specification operation map;
[0008] A real-time access monitoring module, based on the device specification operation map, continuously performs compliance tests on the current operation indicators of the computer and associated printers and network cameras, generates real-time behavior deviation signals, evaluates the current risk status according to the amplitude of the real-time behavior deviation signals and the associated computer data access risk scenarios, and generates an access condition risk degree;
[0009] The access control module makes a determination based on the risk level of the access conditions according to a preset access policy, selects the corresponding control level, issues an access control response instruction, and adjusts the access restrictions of computer data according to the access control response instruction, including isolating the storage area or notifying the supervision node, to obtain the updated access permission status.
[0010] Preferably, the steps for obtaining the set of quantified device behavior metrics are as follows:
[0011] Collect the instruction timing signals, memory access signals, and peripheral interaction signals of the computer, printer, and network camera. Perform sliding window segmentation on the instruction timing signals, and count the discrete values of the timing intervals within each window to generate an original timing data set. Perform time-frequency segmentation on the memory access signals and extract the frequency domain amplitude spectrum of each segment to generate a memory access frequency domain set. Count the number of trigger times of interaction events per unit time for the peripheral interaction signals to generate a peripheral interaction count set;
[0012] Based on the original timing data set, calculate the instruction timing fluctuation data;
[0013] Based on the memory access frequency domain set, calculate the memory access fluctuation data;
[0014] Based on the peripheral interaction count set, calculate the peripheral interaction frequency data;
[0015] Integrate the instruction timing fluctuation data, memory access fluctuation data, and peripheral interaction frequency data to establish a set of quantified device behavior metrics.
[0016] Preferably, the steps for obtaining the statistical boundary of the device metrics are as follows:
[0017] Based on the set of quantified device behavior metrics, calculate the mean, variance, and range of all sampling points of the instruction timing fluctuation data within the target operation period, synchronously calculate the mean, variance, and range of the memory access fluctuation data, and the mean, variance, and range of the peripheral interaction frequency data to generate a set of statistical characteristics;
[0018] Based on the mean, variance, and range of the instruction timing fluctuations, memory access fluctuations, and peripheral interaction frequency data in the statistical characteristic set, extract the mean sequence of the same metrics from the historical normal operation data. Use a dynamic sliding window with a window length covering 80% of the target running period and a sliding step of 10% of the window length. Sort the mean sequence in ascending order of numerical value, eliminate the extreme values in the first 5% and the last 5%, and the mean range of the remaining 90% is the 90% confidence interval of the window. Take the lower limit of the confidence interval as the minimum allowable value of the mean and the upper limit as the maximum allowable value of the mean; for the variance, statistically analyze the variance distribution of the historical normal data and take the 95th percentile as the upper limit of variance tolerance; for the range, use the moving average of the range values within the sliding window and superimpose 3 times the standard deviation as the dynamic threshold to obtain the statistical boundary of the device metrics.
[0019] Preferably, the steps for obtaining the device specification operation map are as follows:
[0020] Based on the statistical boundary of the device metrics, use the mean range of each metric as an independent dimension, and the upper limit of variance tolerance and the dynamic threshold of the range as additional constraint conditions for each dimension to generate a multi-dimensional state space model;
[0021] Based on the multi-dimensional state space model, extract the real-time instruction timing fluctuation mean as the X-axis coordinate value, the memory access fluctuation mean as the Y-axis coordinate value, and the peripheral interaction frequency mean as the Z-axis coordinate value. Determine whether the coordinate values simultaneously satisfy the X-axis range, Y-axis range, and Z-axis range. The X-axis range includes the lower limit of the normal mean of instruction timing fluctuations and the upper limit of the normal mean of instruction timing fluctuations; the Y-axis range includes the lower limit of the normal mean of memory access fluctuations and the upper limit of the normal mean of memory access fluctuations; the Z-axis range includes the lower limit of the normal mean of peripheral interaction frequency and the upper limit of the normal mean of peripheral interaction frequency; and the real-time variance value is lower than the upper limit of variance tolerance of the statistical boundary, and the real-time range value is lower than the dynamic threshold of the range. If all are satisfied, mark it as an allowed operation state point, otherwise mark it as an abnormal state point, and generate a set of allowed operation state points;
[0022] According to the set of allowed operation state points, extract the spatial coordinates of all allowed operation state points, and delimit the boundary of the allowed operation area in the three-dimensional state space coordinate system to obtain the device specification operation map.
[0023] Preferably, the steps for obtaining the real-time behavior deviation signal are as follows:
[0024] Real-time collect the current operation metrics of the computer and associated printer and network camera, including the mean of instruction timing fluctuations, the mean of memory access fluctuations, and the mean of peripheral interaction frequency, and store them classified by device type to generate a set of current operation metrics;
[0025] Based on the boundary of the allowable operation area defined in the device specification operation map, perform a spatial mapping on the current set of operating metrics: map the average instruction timing fluctuation, average memory access fluctuation, and average peripheral interaction frequency of the computer into three-dimensional coordinate points, and determine whether the three-dimensional coordinate points are within the boundary of the allowable operation area; synchronously map the metrics of the printer and the webcam into the corresponding allowable operation area boundary to generate a compliance inspection result containing compliance or out-of-bounds labels;
[0026] If there is an out-of-bounds label in the compliance inspection result, extract the out-of-bounds device type, out-of-bounds metric name, real-time value, and timestamp, and generate a real-time behavior deviation signal in a preset format.
[0027] Preferably, the step of obtaining the risk degree of the access condition is as follows:
[0028] Extract the real-time value, allowable boundary range, and associated device type in the set of real-time behavior deviation signals, sort them according to the absolute value of the difference between the real-time value and the upper limit of the allowable boundary, mark the signals with a difference exceeding the preset tolerance value as high-risk signals, and generate a high-risk signal list;
[0029] Based on the high-risk signal list, match the corresponding risk scenarios in the data access risk scenario library, extract the data sensitivity level, access frequency threshold, and peripheral permission requirements defined in the scenarios, and generate a set of risk-associated parameters;
[0030] Calculate the risk degree of the access condition according to the set of risk-associated parameters.
[0031] Preferably, the step of obtaining the access control response instruction is as follows:
[0032] Based on the risk degree of the access condition, extract the control level interval defined in the preset access policy library to generate a control level interval mapping table;
[0033] Calculate the dynamic control priority according to the control level interval mapping table;
[0034] Based on the dynamic control priority, match the mapping relationship between the priority and the instruction in the preset access policy library to generate an access control response instruction.
[0035] Preferably, the step of obtaining the updated access permission status is as follows:
[0036] Based on the access control response instruction, if the instruction type is an isolated storage area, create an independent storage partition directory named with the device ID and the current timestamp, configure the firewall rule to prohibit unauthorized IP access to this directory, modify the storage path mapping table of the target device, redirect the original storage path to the isolated partition directory, and record the corresponding relationship between the isolated path and the original path;
[0037] If the instruction type is to notify the supervision node, call the HTTP notification interface of the supervision platform, send a JSON format data packet through a POST request. The data packet includes the device ID, risk level, trigger time, and a summary of the current operation log. Receive the status code returned by the interface. If the status code is not 200, retry 3 times and record the exception; generate an operation completion status record form including the operation result, execution time, and log path.
[0038] According to the operation completion status record form, for the devices successfully isolated, add an isolation partition field to the operation completion status record form, and write the isolation path, firewall rule version number, and effective time; for the devices that have been notified to the supervision node, mark the supervision notification status as sent in the operation completion status record form, and associate the notification receipt number with the timestamp; obtain the updated access permission status.
[0039] Compared with the prior art, the advantages and positive effects of the present invention are as follows:
[0040] In the present invention, by collecting multi-source operation data of computers, printers, and network cameras, extracting quantization indicators such as instruction timing fluctuations, memory access fluctuations, and peripheral interaction frequencies, and constructing a dynamic benchmark model covering the full behavior dimension of the device, it breaks through the traditional static protection mode of single encryption or access control. Based on the dynamic benchmark, perform spatial mapping and boundary inspection on real-time operation indicators, and combine with the data access risk scenario matching mechanism to achieve an automated closed-loop from abnormal signal detection to risk level assessment, effectively reducing the misjudgment rate and delay of manual judgment. Screen high-risk signals through absolute value difference sorting and a preset tolerance value, incorporate data sensitivity, access frequency, and peripheral permission requirements into the risk degree calculation, and use a non-linear product function to quantify the threat level to ensure that high-risk operations are blocked first. The dynamic control level coefficient discretizes continuous risk values into multi-level response strategies through an interpolation algorithm, and cooperates with isolation storage path redirection, real-time update of firewall rules, and automated call of supervision interfaces to form a seamless connection from risk identification to permission adjustment, improving the active defense ability and response timeliness of data leakage prevention in complex environments. Brief Description of the Drawings
[0041] Figure 1 It is the system flow chart of the present invention. Detailed Embodiments
[0042] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0043] Please refer toFigure 1 , the present invention provides a technical solution: An Internet of Things-based computer defense system includes:
[0044] An Internet of Things device feature acquisition module, which acquires the operation data of a computer and associated printers and network cameras, converges instruction timing, memory access, and peripheral interaction information, calculates the fluctuation and frequency data of instruction timing, memory access, and peripheral interaction information, and establishes a set of quantified device behavior metrics;
[0045] A behavior benchmark construction module, which, based on the set of quantified device behavior metrics, analyzes the statistical characteristics of each metric within the target operation period, defines the normal range and change pattern, obtains the statistical boundaries of device metrics, and integrates the statistical boundaries of device metrics to establish a device specification operation map;
[0046] A real-time access monitoring module, which, based on the device specification operation map, continuously performs compliance checks against the current operation metrics of the computer and associated printers and network cameras, generates real-time behavior deviation signals, and evaluates the current risk status based on the amplitude of the real-time behavior deviation signals and the associated computer data access risk scenarios, generating an access condition risk level;
[0047] An access permission control module, which makes a determination based on the access condition risk level, selects the corresponding control level according to the preset access policy, issues an access control response instruction, and adjusts the access restrictions of computer data according to the access control response instruction, including isolating the storage area or notifying the supervision node, to obtain the updated access permission status.
[0048] The steps for obtaining the set of quantified device behavior metrics are as follows:
[0049] Collect the instruction timing signals, memory access signals, and peripheral interaction signals of the computer, printer, and network camera. Perform sliding window segmentation on the instruction timing signals, count the discrete values of the timing intervals within each window to generate an original timing data set. Perform time-frequency segmentation on the memory access signals and extract the frequency domain amplitude spectrum of each segment to generate a memory access frequency domain set. Count the number of trigger times of interaction events per unit time for the peripheral interaction signals to generate a peripheral interaction count set;
[0050] Based on the original timing data set, calculate the instruction timing fluctuation data , and the calculation formula is:
[0051] ;
[0052] Wherein, is the th timing interval value within the window, is the mean value of all timing interval values within the window, is the total amount of data within the window;
[0053] Calculate the memory access fluctuation data based on the memory access frequency domain set , and the calculation formula is:
[0054] ;
[0055] Among them, is the average value of the frequency domain amplitude of the th segment, is the average value of the average values of the frequency domain amplitudes of all segmented frequency domains, is the number of segments;
[0056] Calculate the peripheral interaction frequency data based on the peripheral interaction count set , and the calculation formula is:
[0057] ;
[0058] Among them, is the interaction count within the th unit time, is the total monitoring duration, is the total number of unit time segments;
[0059] Integrate the instruction timing fluctuation data, memory access fluctuation data, and peripheral interaction frequency data to establish a set of quantitative device behavior indicators.
[0060] Specifically, for the signal data of the computer, printer, and network camera collected, first, for the instruction timing signal, set a sliding window with a fixed length. For example, set the window size to 1024 instruction cycles and the sliding step to 128 instruction cycles. Segment the continuous instruction timing signals. Inside each window, measure the time interval between adjacent instruction completion time points to obtain a series of timing interval values. For example, obtain the timing interval value sequence inside window one Nanoseconds (ns), then, these interval values are discretized, according to the preset interval interval, for example, 0-5ns is counted as gear 1, 6-10ns is counted as gear 2, 11-15ns is counted as gear 3, etc., the frequency of occurrence of each gear is counted to form the discrete value distribution characteristics of the window, for example, the distribution of window one is {gear 2: 2 times, gear 3: 4 times, ...}, the discrete value distribution data of all windows are collected to form the original time series data set; then the memory access signal is processed, and the short-time Fourier transform (STFT) is used for time-frequency analysis, and the continuous memory access signal stream is divided into several time periods, for example, each time period is 500 milliseconds (ms), the spectrum of the signal in each time period is calculated, and its amplitude information within a specific frequency range is extracted, for example, the characteristic frequency range of 1kHz-10kHz related to memory operations is focused on, and the amplitude square sum or average amplitude of all frequency components in this range is calculated to obtain a single value or vector representing the frequency domain characteristics of memory access in this time period. For example, the frequency domain amplitude spectrum mean of time period one is (The unit is determined by the signal acquisition device, and is a schematic unit here). The frequency domain feature data of all time periods are collected to form a memory access frequency domain set. Finally, the peripheral interaction signals are processed to monitor events such as USB insertion / removal, print task submission / completion, camera video stream start / stop, etc. A statistical unit time is set, such as 10 seconds, and the total number of triggering of various peripheral interaction events in each 10-second time unit is recorded. For example, in the first 10 seconds, USB insertion occurs once, print task submission occurs once, and camera is turned on once, with a total number of interactions of 3 times. In the second 10 seconds, USB removal occurs once, with a total number of interactions of 1 time. These interaction count data counted by time unit are serialized to obtain a peripheral interaction count set. times / 10 seconds. By integrating the discrete value distribution of instruction timing, the frequency domain characteristics of memory access, and the event counts of peripheral interactions obtained by the aforementioned processing, a basic data set reflecting the operating status of the device is preliminarily formed, laying the foundation for the subsequent calculation of quantitative indicators.
[0061] Based on the original timing data set, extract the quantitative indicators about the instruction timing volatility , this calculation needs to be performed independently on each data segment separated by the sliding window. The calculation process within a single window is detailed below: First, determine the total amount of data in the window , which is equal to the total number of instruction timing interval values contained in the window length. For example, in a window set to contain 100 instruction intervals, ; Next, calculate the arithmetic mean of all time interval values in the window, recorded as the window mean ,in Represents the window Measurement values for a time interval. For example, if the 5 interval values within the window are respectively ns, then , and the window mean is ns; then, calculate the deviation of each interval value from the window mean , that is . For the example data, the deviations are respectively , , , , ; then calculate the squares of these deviations to obtain ; sum up all the squared deviation values within the window to obtain , which is in the example; divide this sum of squares by the total number of data within the window to calculate the variance, that is , which is in the example; finally, take the square root of the variance to obtain the standard deviation of the instruction timing fluctuation , which is ns in the example. This value is the instruction timing fluctuation data for this window; repeat this calculation process for all windows in the original timing dataset to generate a series of values, which together constitute the instruction timing fluctuation data sequence.
[0062] Formula Explanation:
[0063] This formula is used to calculate the standard deviation of the instruction timing interval values within a data window. The parameter represents the value of the th timing interval within the window, and the subscript ranges from 1 to ; is the total number of timing interval values included in this window; the inner summation calculates the sum of all interval values within the window, divides it by to obtain the average value of the interval values within the window. The subscript also ranges from 1 to and is used to calculate the average value; calculates the deviation of the th interval value from the average value; calculates the square of the deviation; the outer summation calculates the sum of all squared deviations within the window; divides it by to obtain the variance; finally, take the square root to obtain the standard deviation ; The operation logic of the entire formula is the classic sample standard deviation calculation method, which quantifies the dispersion or volatility of the instruction execution time interval relative to its average value.
[0064] Formula parameter acquisition and calculation example:
[0065] For example, through signal acquisition, a window data containing instruction timing interval values is obtained. ns, and these values are actual time measurement values obtained by monitoring the processor instruction execution unit.
[0066] Calculate the window mean: ns.
[0067] Calculate the sum of squared deviations: .
[0068] Calculate : ns.
[0069] Explanation of the formula innovation point: The application is to use this statistic to quantify the microscopic volatility of the instruction execution timing, as a fine-grained indicator of the device behavior. Compared with only using the average execution time, it can better reveal the internal dynamic stability and potential abnormal interference of the system.
[0070] Result interpretation:
[0071] The calculated ns indicates that within this observation window, the instruction timing interval values deviate from their mean by about 2.449 ns on average by 14 ns. This value reflects the stability of the instruction execution rhythm, and this calculation result will be added as a data point to the instruction timing fluctuation data sequence.
[0072] Based on the memory access frequency domain set, extract the quantization index regarding the memory access volatility , and the calculation needs to process a series of frequency domain amplitude mean data extracted by time segmentation. For example, the memory access frequency domain set contains frequency domain amplitude means for time segments. The calculation process is as follows: First, determine the number of segments for analysis , and this value is determined by the time-frequency segmentation setting. For example, if a 10-second memory access signal is processed in segments of 500 ms each, then segments are obtained; then, calculate the total average value of the frequency domain amplitude means of these segments, denoted as , where represents the frequency domain amplitude mean of the th segment. For example, currently The amplitude mean data of each segment , whose total average value is ; Then, calculate the frequency-domain amplitude mean of each segment and the total average value to obtain the absolute difference, that is . For the example data, the absolute differences are respectively , , , ; Then sum up these absolute differences to get . In the example, it is ; Finally, divide the sum of the absolute differences by the number of segments to calculate the mean absolute deviation . In the example, it is . This value is the memory access fluctuation data of this group of data; Record this value
[0073] Formula Explanation:
[0074] This formula is used to calculate the mean absolute deviation of a series of memory access frequency-domain amplitude means. The parameter represents the frequency-domain amplitude mean of the th time segment, and the subscript ranges from 1 to ; is the total number of segments; The inner summation calculates the sum of all segment amplitude means, and divides it by to obtain the average value of these means . The subscript also ranges from 1 to for calculating the mean; calculates the absolute difference between the mean of the th segment and the total mean, indicating the degree of deviation from the average level; The outer summation calculates the sum of all segment absolute deviations; Finally, divide it by to obtain the mean absolute deviation ; The operation logic of the entire formula is to calculate the mean absolute deviation, which measures the variation amplitude or instability of the memory access frequency-domain characteristics in different time periods. Compared with the standard deviation, it is less sensitive to extreme values
[0075] Formula parameter acquisition and calculation example:
[0076] For example, through time-frequency analysis of the memory access signal, obtain the frequency-domain amplitude means of ), these values are the average amplitudes calculated after analyzing the memory bus monitoring data and performing FFT transformation in a specific frequency band (such as 1 kHz - 10 kHz): .
[0077] Calculate the total average value: .
[0078] Calculate the sum of absolute deviations: .
[0079] Calculate : . Therefore, the memory access fluctuation data .
[0080] Explanation of the innovation point of the formula:
[0081] The formula itself is the mean absolute deviation, and its innovative application lies in applying it to the mean sequence of the frequency domain characteristics of the memory access signal. By the volatility of the frequency domain amplitude, it indirectly reflects the dynamic changes of the memory access pattern, which provides a perspective different from the traditional time-domain analysis to evaluate the behavioral stability of the memory subsystem.
[0082] Result interpretation:
[0083] The calculated indicates that the mean of the memory access frequency domain amplitude in different time periods deviates from its total mean by approximately . This value quantifies the degree of fluctuation of the memory access activity in the frequency domain, and this calculation result will be used as a data point and added to the memory access fluctuation data sequence.
[0084] Based on the peripheral interaction count set, extract the quantization index regarding the peripheral interaction frequency , and this calculation requires summarizing the total number of peripheral interaction events during the entire monitoring duration and averaging it over the unit time period. The calculation process is as follows: First, determine the total monitoring duration (for example, seconds) and the number of unit time segments (for example, if the unit time is 10 seconds, then unit time periods); obtain the peripheral interaction count set, that is, the sequence of the number of trigger times of interaction events in each unit time , for example, in 6 ten-second time periods, the interaction times are respectively times / 10 seconds; then, calculate the total number of all interaction events that occurred during the total monitoring duration , which is achieved by summing all elements in the count set, that is , and in the example, the total number is times; then, according to the formula Calculate the number of interactions per unit time on average by dividing the total number of times by the total number of unit - time segments , to obtain , in the example it is times / 10 seconds. This value is the peripheral interaction frequency data; this value represents the number of peripheral interaction events that occur on average within each 10 - second time window during the monitoring period.
[0085] Formula Explanation:
[0086] This formula calculates the peripheral interaction frequency. The parameter is the count value of interaction events within the th unit time, and the subscript ranges from 1 to ; is the total number of unit - time segments; is the total number of all interaction events that occur during the entire monitoring duration; is the total monitoring duration.
[0087] Formula parameter acquisition and calculation example:
[0088] For example, by monitoring system logs or hardware interrupts, within the total monitoring duration seconds, with 10 seconds as the unit time for statistics, the sequence of the number of peripheral interaction times (such as USB plug - in / out, print commands) for time periods is times / 10 seconds.
[0089] Calculate the total number of interactions: times.
[0090] Calculate (by the number of times per unit time on average): times / 10 seconds.
[0091] Explanation of the formula innovation point:
[0092] The formula itself calculates the average frequency or average count. Its innovative application lies in quantifying discrete events such as peripheral interactions to form a continuously changing indicator , which is used to reflect the interaction activity degree between the device and the external interface and serves as a dimension of the overall behavior state of the device.
[0093] Result interpretation:
[0094] The calculated Times / 10 seconds indicates that during the observed 60 seconds, an average of approximately 1.333 peripheral interaction events occurred every 10 seconds. This value reflects the average intensity of peripheral usage. The calculation result will be added as a data point to the peripheral interaction frequency data series.
[0095] Integrate the instruction timing fluctuation data series obtained by the above calculation (a series of values), memory access fluctuation data sequence (a series of value) and peripheral interaction frequency data sequence (a series of These time series data together constitute a multi-dimensional, quantitative representation of device behavior. These sequence data are organized into a structured data set. For example, for a certain time point or time period, a triple can be obtained. ,like , this triplet is a sample of an instantaneous quantitative device behavior indicator set; the samples collected or calculated at different times are combined together to form a quantitative device behavior indicator set that reflects the dynamic behavior of the device over a period of time. This indicator set is the basis for the subsequent establishment of a normal device behavior model and identification of abnormal deviations. For example, collect one hour of data to form a A data matrix, where is the number of sampling points, and 3 represents the three core indicator dimensions.
[0096] The steps to obtain the statistical boundaries of equipment indicators are as follows:
[0097] Based on the quantitative device behavior indicator set, the mean, variance and range of the instruction timing fluctuation data at all sampling points in the target operating period are calculated respectively, and the mean, variance and range of the memory access fluctuation data and the mean, variance and range of the peripheral interaction frequency data are calculated simultaneously to generate a set of statistical characteristics;
[0098] Based on the mean, variance and range of instruction timing fluctuation, memory access fluctuation data and peripheral interaction frequency data in the statistical feature set, the mean sequence of the same indicator is extracted from the historical normal operation data. A dynamic sliding window is used with a window length covering 80% of the target operating period and a sliding step of 10% of the window length. The mean sequence is sorted from small to large by value, and the extreme values of the first 5% and the last 5% are removed. The remaining 90% of the mean range is the 90% confidence interval of the window. The lower limit of the confidence interval is taken as the minimum allowable value of the mean, and the upper limit is taken as the maximum allowable value of the mean. For variance, the variance distribution of historical normal data is statistically analyzed, and the 95% quantile is taken as the upper limit of variance tolerance. For range, the moving average of the range value in the sliding window is used, and 3 times the standard deviation is superimposed as the dynamic threshold to obtain the statistical boundary of the equipment indicator.
[0099] Specifically, based on a set of quantitative device behavior indicators (i.e., historical records data sequence), for a specific "target operation period", such as analyzing the device behavior in the past 24 hours, first, it is necessary to calculate the statistical characteristics of all sampling points within this period. The specific operation is as follows: extract all the instruction timing fluctuation data within the target operation period values, and calculate the arithmetic mean of this batch of values , sample variance and range ; using the same method, for the memory access fluctuation data within the target operation period values, calculate its mean , variance and range ; and for the peripheral interaction frequency data values, calculate its mean , variance and range , gather these nine statistical values ( ) together to form the statistical characteristic set of this target operation period; next, use the "historical normal operation data", that is, a large amount of indicator set data accumulated when the device was operating normally in the past, to set the boundary for whether the current behavior is normal. For the mean indicator ( ), adopt the dynamic sliding window method to process the historical normal mean sequence. For example, if the target operation period is 1 hour, the window length is set to cover 80% of this period, that is minutes, and the sliding step is 10% of the window length, that is minutes. Slide this window on the historical normal data. Each time the window moves, calculate the mean of the corresponding indicator (such as ) within the window to obtain a historical mean sequence. Sort the historical mean data within each window, remove the lowest 5% and the highest 5%, and determine the minimum and maximum values of the remaining 90% of the data as the 90% confidence interval of this window. Traverse all windows, and take the minimum value among all as the global minimum allowable value of the mean of this indicator, and take the maximum value among all as the global maximum allowable value . For example, through this method, the allowable range of the mean of is calculated to be ; for the variance indicator ( ), analyze the variance value distribution of the corresponding indicator in the historical normal operation data, determine its probability density function or cumulative distribution function, and select the 95% quantile of the distribution (that is, 95% of the normal variance values are lower than this value) as the variance tolerance upper limit of this indicator. For example, historical data shows that 95% of the normal The variance is less than 0.8 , then ; for the range index ( ), also use a sliding window on the historical normal data (the window setting can be the same as the mean calculation), and calculate the moving average of the range values within each window and the moving standard deviation , and set the dynamic threshold to . This threshold will be adaptively adjusted according to the volatility of the recent historical data. For example, at a certain moment the moving average of the range is 1.5 ns and the moving standard deviation is 0.2 ns, then the dynamic threshold of the range at this moment is ns. Through the above steps, the allowable range of the mean value is determined for each index ( ), the upper tolerance limit of the variance and the dynamic threshold of the range . These together constitute the statistical boundary of the device indicators.
[0100] The steps to obtain the device specification operation map are as follows:
[0101] Based on the statistical boundary of the device indicators, take the mean value range of each indicator as an independent dimension, and the upper tolerance limit of the variance and the dynamic threshold of the range as additional constraint conditions for each dimension to generate a multi-dimensional state space model;
[0102] Based on the multi-dimensional state space model, extract the mean value of the real-time instruction timing fluctuation as the X-axis coordinate value, the mean value of the memory access fluctuation as the Y-axis coordinate value, and the mean value of the peripheral interaction frequency as the Z-axis coordinate value, and judge whether the coordinate values simultaneously satisfy the X-axis range, the Y-axis range, and the Z-axis range. The X-axis range includes the lower limit of the normal mean value of the instruction timing fluctuation and the upper limit of the normal mean value of the instruction timing fluctuation; the Y-axis range includes the lower limit of the normal mean value of the memory access fluctuation and the upper limit of the normal mean value of the memory access fluctuation; the Z-axis range includes the lower limit of the normal mean value of the peripheral interaction frequency and the upper limit of the normal mean value of the peripheral interaction frequency; and the real-time variance value is lower than the upper tolerance limit of the variance of the statistical boundary, and the real-time range value is lower than the dynamic threshold of the range. If all are satisfied, it is marked as an allowable operation state point, otherwise it is marked as an abnormal state point, and a set of allowable operation state points is generated;
[0103] According to the set of allowable operation state points, extract the spatial coordinates of all allowable operation state points, and delimit the boundary of the allowable operation area in the three-dimensional state space coordinate system to obtain the device specification operation map.
[0104] Specifically, based on the statistical boundary of the device indicators, this boundary is for each core indicator (instruction timing fluctuation , memory access fluctuation , peripheral interaction frequency )Both define the normal fluctuation range and limiting conditions, and construct a multi-dimensional model for describing the normal operation state space of the device. Specifically, the allowable range of the mean value of each indicator is regarded as an independent dimension in the state space. For example, the mean value range of is used as the effective interval of the X-axis, and the mean value range of is used as the effective interval of the Y-axis, and the mean value range of is used as the effective interval of the Z-axis. These three groups of ranges jointly define a cuboid region in a three-dimensional space, representing the core space where the mean values of the device indicators are in a normal state; at the same time, the upper limit of variance tolerance (such as )and the dynamic threshold of range (such as ns) are imposed as additional constraint conditions on each dimension, meaning that not only the mean coordinates of a state point must fall within the above cuboid, but also its corresponding real-time variance and real-time range must satisfy their respective upper limit constraints; Next, use this multi-dimensional state space model with constraints to determine the real-time device state, extract the real-time instruction timing fluctuation mean (such as 2.5 ns), the memory access fluctuation mean (such as ), the mean value of the peripheral interaction frequency (such as 1.1 times / 10 seconds), and use these three values as the coordinates of the current state point in the three-dimensional space , and execute the judgment logic: First, check whether the coordinate values are simultaneously within their respective allowable ranges, that is and and . In the example, meets all the mean value range requirements; then, further check whether the real-time variance value and real-time range value associated with this state point satisfy the constraints, that is, check whether the real-time variance (such as 0.6 )is lower than , whether the real-time range (such as 1.9 ns)is lower than ns, and perform the same variance and range checks on and (such as also satisfied); if all conditions (three mean value ranges, three variance upper limits, three range thresholds) are met, then this real-time state point Points marked as allowing operating status, otherwise, as long as any one condition is not met, they are marked as abnormal status points; by processing a large amount of historical normal operation data or simulation data, collect the set of spatial coordinates of all points determined to be allowing operating status points, and the set of these points outlines a region in the three-dimensional state space coordinate system. The boundary of this region precisely defines the normal operation range of the device in a statistical sense, and this boundary and the space it encloses are the device specification operation atlas.
[0105] The steps for obtaining the real-time behavior deviation signal are as follows:
[0106] Collect the current operation metrics of the computer and associated printer and network camera in real time, including the mean value of instruction timing fluctuations, the mean value of memory access fluctuations, and the mean value of peripheral interaction frequencies, store them classified by device type, and generate the current operation metric set;
[0107] Based on the boundary of the allowing operation area defined in the device specification operation atlas, perform spatial mapping on the current operation metric set: map the mean value of instruction timing fluctuations, the mean value of memory access fluctuations, and the mean value of peripheral interaction frequencies of the computer into three-dimensional coordinate points, and determine whether the three-dimensional coordinate points are within the boundary of the allowing operation area; synchronously map the metrics of the printer and network camera into the corresponding boundary of the allowing operation area to generate a compliance test result including compliance or out-of-bounds labels.
[0108] If there are out-of-bounds labels in the compliance test result, extract the out-of-bounds device type, out-of-bounds metric name, real-time value, and timestamp, and generate a real-time behavior deviation signal in a preset format.
[0109] Specifically, collect the current operation metric data from the running computer and its associated printer and network camera in real time. Specifically, continuously calculate the latest mean value of instruction timing fluctuations , the mean value of memory access fluctuations and the mean value of peripheral interaction frequencies , for example, at time point , the metrics of the computer are , the metrics of the printer are , the metrics of the network camera are , store the real-time metric data collected and classified by device type to form the current operation metric set; then, use the boundary of the allowing operation area defined for each device type (computer, printer, camera) in the device specification operation atlas established in the previous step to perform spatial mapping and compliance testing on the data in the current operation metric set. Taking the computer as an example, use its current metrics as a three-dimensional coordinate point, and determine whether this point falls within the boundary of the allowing operation area of the computer. For example, the mean allowable range of the computer is ns, while the current value is 3.1 ns, exceeding the upper limit. Therefore, this point is outside the allowable operation area. At the same time, it is also necessary to check whether the real-time variance and range at this time point also meet their respective boundary conditions (for example, variance , range ns ns. These two meet, but the mean value has exceeded the limit). Since the mean has exceeded the limit, the computer status is determined to be non-compliant, generating a compliance test result containing the "out-of-bounds" label. The same spatial mapping and boundary compliance checks are also performed on the printer and webcam to obtain their respective compliance test results (which may be "compliant" or "out-of-bounds"), and the test results of all devices are summarized; if in the summarized compliance test results, it is detected that the label of any device is "out-of-bounds", for example, the indicator of the computer is out of bounds, then relevant information is immediately extracted: the type of the out-of-bounds device (Computer), the name of the out-of-bounds indicator (Mean Sigma S of instruction timing fluctuation ), the real-time value of this indicator (3.1 ns), the corresponding allowable boundary range ( ns), and the current exact timestamp (for example, "2025-04-16T18:40:00Z"). These information are organized according to a pre-set data structure (for example, JSON format: {"timestamp": "2025-04-16T18:40:00Z", "device_type": "Computer", "metric_name": "Mean_Sigma_S", "realtime_value": 3.1, "allowed_min": 2.10, "allowed_max": 2.95, "unit": "ns"}) to generate a real-time behavior deviation signal.
[0110] The steps to obtain the risk degree of access conditions are as follows:
[0111] Extract the real-time value, allowable boundary range, and associated device type in the set of real-time behavior deviation signals, sort them according to the absolute value of the difference between the real-time value and the upper limit of the allowable boundary, mark the signals with a difference exceeding the preset tolerance value as high-risk signals, and generate a high-risk signal list;
[0112] Based on the high-risk signal list, match the corresponding risk scenarios in the data access risk scenario library, extract the data sensitivity level, access frequency threshold, and peripheral permission requirements defined in the scenarios, and generate a set of risk-associated parameters;
[0113] According to the set of risk-associated parameters, calculate the risk degree of access conditions. The calculation formula is:
[0114] ;
[0115] Among them, is the access condition risk degree, is the difference between the real-time value of the th high-risk signal and the upper limit of the allowable boundary, is the corresponding data sensitivity level, is the current peripheral device call frequency, is the total number of high-risk signals.
[0116] Specifically, extract key information from the set of real-time behavior deviation signals collected, including the real-time value in each deviation signal, the corresponding allowable boundary range (upper limit or lower limit, depending on the direction of the excess), and the associated device type. For example, two deviation signals are received: Signal 1 {device: computer, metric: , real-time value: 3.1 ns, boundary: [2.10, 2.95] ns}, Signal 2 {device: printer, metric: , real-time value: 1.8 times / 10 seconds, boundary: [0.8, 1.5] times / 10 seconds}, calculate the absolute value of the deviation for each signal, which here refers to the closest boundary. The deviation of Signal 1 is ns, and the deviation of Signal 2 is times / 10 seconds. Sort all deviation signals in descending order according to their absolute deviation , for example , after sorting it is [Signal 2, Signal 1]. Set a deviation tolerance threshold, which is set based on historical experience or risk assessment. For example, it is set to 0.5 times the standard deviation of the corresponding metric, or a fixed small percentage value. For example, the tolerance value is 0.1 ns, the tolerance value is 0.2 times / 10 seconds. Determine whether the deviation of each signal exceeds its corresponding tolerance value. The deviation of Signal 1 is , and the deviation of Signal 2 is . Therefore, both signals are marked as high-risk signals. Collect these marked signals to generate a high-risk signal list; then, based on the information (device type, out-of-bounds metric) in the high-risk signal list, query the pre-established "data access risk scenario library", which stores risk parameters under different scenarios. For example, the entry in the library defines that when the " " metric of the "computer" abnormally increases, the associated risk scenario is "potential malware execution", and the data sensitivity level of this scenario is defined as 4 (level 1 - 5, 5 is the highest), the access frequency threshold is 10 times / minute, and the peripheral device permission requirement is "ordinary user permission"; when the " When the index abnormally increases, the associated risk scenario is "unauthorized batch printing", and the data sensitivity level is defined as 3, the access frequency threshold is 5 times / minute, the peripheral device permission requirement is "print queue access permission", and by matching each signal in the high-risk signal list, the corresponding risk association parameter set is extracted. For example, the high-risk signal 1 associated parameter set { ,...}, the high-risk signal 2 associated parameter set { ,...}, and at the same time, the current peripheral device call frequency needs to be obtained. For example, the associated peripheral device call frequency of the current computer times / 10 seconds, and the current call frequency of the printer times / 10 seconds (i.e., its out-of-bounds value); then, according to the risk association parameter set, the access condition risk degree is calculated, and the formula is applied, where is the total number of high-risk signals. Here .
[0117] Formula Description:
[0118] This formula calculates the comprehensive risk degree of the access condition . is the total number of currently identified high-risk behavior deviation signals. The summation symbol means traversing and calculating all high-risk signals and accumulating them. is the deviation magnitude of the th high-risk signal, that is, the absolute value of the difference between the real-time value and its allowed boundary. is the data sensitivity level defined for the risk scenario associated with the th high-risk signal. This is a quantitative value, such as 1 to 5, and the higher the value, the more sensitive the data. is the current peripheral device call frequency related to the th high-risk signal, which reflects the usage intensity of the peripheral device when the abnormal behavior occurs. is the logarithmic transformation (base 2) of the peripheral device call frequency, and adding 1 is to avoid the logarithm being meaningless when the frequency is 0. The logarithmic transformation can compress the range of frequency values and reduce the influence weight of extremely high frequency values. calculates the risk contribution of a single high-risk signal, which comprehensively considers the severity of the deviation, the sensitivity of the involved data, and the intensity of the related activities. Finally, the risk contributions of all high-risk signals are summed and divided by the total number of high-risk signals to obtain the average risk degree .
[0119] Formula parameter acquisition and calculation example:
[0120] Based on the foregoing scenarios, there are high-risk signals.
[0121] Signal 1 (computer anomaly): ns. Query the risk scenario library to obtain . Obtain the call frequency of the current computer-related peripherals times / 10 seconds.
[0122] Signal 2 (printer anomaly): times / 10 seconds. Query the risk scenario library to obtain . Obtain the call frequency of the current printer times / 10 seconds.
[0123] Substitute into the formula for calculation :
[0124] ;
[0125] ;
[0126] ;
[0127] ;
[0128] Use for calculation: , .
[0129] ;
[0130] ;
[0131] ;
[0132] Explanation of the innovation point of the formula:
[0133] The innovation of this formula lies in constructing a risk assessment model that integrates multiple factors. It not only considers the magnitude of the behavior deviation ( ), but also introduces the data sensitivity at the business level ( ) and the real-time activity intensity ( ) as weight factors, and smooths the influence of frequency through logarithmic transformation, making the risk assessment result closer to the actual threat level.
[0134] The calculated access condition risk degree . This value is a comprehensive score that quantifies the overall access risk level brought by the currently detected high-risk behaviors, and it will be used to determine the intensity of the subsequent decision-making access control response.
[0135] The steps for obtaining the access control response instruction are as follows:
[0136] Based on the access condition risk level, extract the defined control level interval in the preset access policy library to generate a control level interval mapping table;
[0137] According to the control level interval mapping table, calculate the dynamic control priority. The calculation formula is:
[0138] ;
[0139] Wherein, is the baseline weight of the th control level, is the lower limit value of the th level, is the total number of control levels, is the dynamic control priority, is the access condition risk level;
[0140] Based on the dynamic control priority, match the mapping relationship between the priority and the instruction in the preset access policy library to generate the access control response instruction.
[0141] Specifically, based on the calculated access condition risk level (for example ), first, it is necessary to extract the mapping relationship between the control level and the risk level interval from the preset access policy library. This library defines the intensity level of control measures corresponding to different risk levels. For example, establish the following control level interval mapping table:
[0142] Table 1: Control Level Interval Mapping Table
[0143] Control level (g) Level name Risk level interval#timg#] Benchmark weight#timg# 1 Observation and record #timg#] 1.1 2 Warning and audit #timg#] 1.5 3 Restricted operation #timg#] 2.0 4 Isolation and block #timg#] 3.0
[0144] As shown in Table 1, this table lists four control levels, and each level is associated with a lower limit value of the risk level ( ) and a baseline weight ( ), and the total number of control levels ; then, according to the current risk level and this mapping table, calculate the dynamic control priority , and apply the formula .
[0145] Formula Explanation:
[0146] This formula calculates the dynamic control priority . means for all control levels (from to perform a successive multiplication on the calculation results of is the benchmark weight of the th control level, reflecting the basic priority or influence degree of this level. is the risk degree of the input access condition. is the th lower limit value of the risk degree of the control level. is the lower limit value of the next level (for the highest level , can be regarded as infinity or a sufficiently large value). The exponential part calculates the risk degree exceeding the lower limit of the th level, relative to the interval width of the th level, and rounds down. This indicates how many unit widths the risk degree completely "spans" within the interval of the th level (if the interval width is 1), or rather, this exponent measures the depth to which the risk penetrates into the th level and above. The premise for the exponent calculation is , otherwise the contribution of this item is . The entire formula obtains a priority score that grows non-linearly with the risk degree by successively multiplying the weighted contributions of each level (the weight is exponentiated by the risk penetration depth) . .
[0147] Formula parameter acquisition and calculation example:
[0148] The current risk degree . The control level parameters are shown in Table 1: , , .
[0149] Calculate the contributions of each level:
[0150] : . The interval width . The exponent . The contribution .
[0151] : . The interval width . The exponent . The contribution .
[0152] : The exponent is 0 (or this term does not participate in the product). Contribution .
[0153] : The exponent is 0 (or this term does not participate in the product). Contribution .
[0154] Calculate the final priority : .
[0155] Explanation of the innovation point of the formula:
[0156] The characteristic of this formula lies in its dynamic nature and non-linear amplification effect. It does not simply map the risk level to a fixed priority, but dynamically calculates the priority according to the relative position (penetration depth) of the risk level within each control level interval. The selection of the reference weight and the product form cause the priority to increase significantly as the risk crosses higher levels, and can more sensitively reflect the urgency of risk escalation.
[0157] Result interpretation:
[0158] The calculated dynamic control priority . This priority value will be used to precisely match the specific response actions defined in the access policy library. Then, based on the calculated dynamic control priority , query the preset access policy library again to find the specific access control response instructions corresponding to this priority value (or its interval). For example, it is defined in the policy library that for priority Instruction: "Record detailed logs and send a low-priority warning to the administrator"; for priority Instruction: "Trigger the audit process and send a medium-priority warning", etc. Since falls within the interval , the instruction matched is "Record detailed logs and send a low-priority warning to the administrator", which is the finally generated access control response instruction.
[0159] The steps to obtain the updated access permission status are as follows:
[0160] Based on the access control response instruction, if the instruction type is an isolated storage area, create an independent storage partition directory named with the device ID and the current timestamp, configure the firewall rules to prohibit unauthorized IP access to this directory, modify the storage path mapping table of the target device, redirect the original storage path to the isolated partition directory, and record the correspondence between the isolated path and the original path;
[0161] If the instruction type is to notify the supervision node, call the HTTP notification interface of the supervision platform, send a JSON-formatted data packet via a POST request. The data packet includes the device ID, risk level, trigger time, and a summary of the current operation log. Receive the status code returned by the interface. If the status code is not 200, retry 3 times and record the exception; generate an operation completion status record table including the operation result, execution time, and log path.
[0162] According to the operation completion status record table, for the devices that have been successfully isolated, add an isolation partition field to the operation completion status record table, and write the isolation path, firewall rule version number, and effective time; for the devices that have been notified to the supervision node, mark the supervision notification status as sent in the operation completion status record table, and associate the notification receipt number with the timestamp; obtain the updated access permission status.
[0163] Specifically, based on the received access control response instruction, the system performs corresponding operations to update the access permission status of the device. The specific execution process depends on the instruction type: If the instruction type is "isolate storage area", the system first creates an independent storage directory for the device to be isolated (for example, the device ID is "CompXYZ"), and the directory name combines the device ID and the current timestamp, such as / secure_storage / CompXYZ_20250416184500. Subsequently, configure the firewall at the operating system level (such as using iptables or Windows Firewall) to add rules to prohibit all network addresses except the authorized management server IP (for example, 192.168.1.100) from accessing the newly created directory / secure_storage / CompXYZ_20250416184500. Then, modify the storage path configuration related to the target device CompXYZ in the operating system. By modifying the mount point, symbolic link, or application configuration file, redirect the originally pointed storage path (for example, / userdata / CompXYZ) to the newly created isolation directory / secure_storage / CompXYZ_20250416184500. At the same time, record this redirection relationship in a mapping table, such as {'device': 'CompXYZ', 'original_path': ' / userdata / CompXYZ', 'isolated_path': ' / secure_storage / CompXYZ_20250416184500', 'timestamp': '2025-04-16T18:45:05Z'}; If the instruction type is "notify the supervision node" (corresponding to our example For the instruction "Record detailed logs and send low-priority warnings to the administrator", the system will call the pre-configured regulatory platform notification interface, usually an HTTP(S) API endpoint, such as https: / / regulator.example.com / api / v1 / alert. By initiating an HTTP POST request, it will send a JSON-formatted data packet containing event details to this interface. Example of the data packet content: {"alert_level": "low", "device_id": "CompXYZ", "risk_score": 1.0097, "trigger_time": "2025-04-16T18:40:00Z", "details": "MeanSigma_Svalue3.1 exceeded boundary [2.10, 2.95]", "source_log_path": " / var / log / device_monitor / CompXYZ.log"}. After sending the request, the system needs to check the status code of the HTTP response. If it receives the status code 200 OK, it means the notification has been successfully sent. If it receives a non-200 status code (such as 500 Internal Server Error or 403 Forbidden), the system will attempt to resend the notification, with a maximum of 3 retries, and a set time interval (such as 10 seconds) between each retry. If all retries fail, it will record an abnormal event of notification sending in the system log. Whether it is performing isolation or notification operations, after completion, it is necessary to generate a record of the operation completion status and store it in the status record table. This record table contains fields such as: operation type, target device ID, execution result (success / failure / failure reason), execution timestamp, associated log file path, etc. For example, for a successful notification operation, the record is {'action_type': 'notify_supervisor', 'device_id': 'CompXYZ','result':'success', 'completion_time': '2025-04-16T18:45:10Z', 'log_ref':'syslog_entry_id_12345'}; Based on these detailed operation completion status records, update the overall access permission view of the system: For devices where storage isolation has been successfully executed, supplement isolation-related information in their status records, such as adding an isolation_details field, which contains the isolation path / secure_storage / CompXYZ_20250416184500, the version number of the applied firewall rules fw_rule_v3.2 and the rule effective time is 2025-04-16T18:45:08Z; for the devices that have successfully completed notifying the regulatory nodes, update the regulatory notification status field in their status records to "sent", and associate the confirmation receipt number returned by the regulatory platform (if provided by the interface, such as receipt_id: 'ACKN-98765') and the notification confirmation timestamp 2025-04-16T18:45:12Z. By summarizing the operation completion status records and supplementary information of all devices, obtain the latest access permission status set reflecting the current access control interventions of each device.
Claims
1. An Internet of Things-based computer defense system, characterized in that, The system includes: An Internet of Things device feature acquisition module that collects the operation data of a computer and associated printer and network camera, aggregates instruction timing, memory access, and peripheral interaction information, calculates the fluctuation and frequency data of instruction timing, memory access, and peripheral interaction information, and establishes a set of quantified device behavior indicators; A behavior benchmark construction module that, based on the set of quantified device behavior indicators, analyzes the statistical characteristics of each indicator within a target operation period, defines the normal range and change pattern, obtains the device indicator statistical boundary, and integrates the device indicator statistical boundary to establish a device specification operation map; A real-time access monitoring module that, based on the device specification operation map, continuously performs compliance checks against the current operation indicators of the computer and associated printer and network camera, generates a real-time behavior deviation signal, and evaluates the current risk status based on the amplitude of the real-time behavior deviation signal and the associated computer data access risk scenario to generate an access condition risk degree; An access permission control module that, based on the access condition risk degree, makes a determination according to a preset access policy, selects the corresponding control level, issues an access control response instruction, and adjusts the access restriction of computer data according to the access control response instruction, including isolating the storage area or notifying the supervision node to obtain the updated access permission status.
2. The computer defense system based on the Internet of Things according to claim 1, wherein The steps for obtaining the set of quantified device behavior indicators are as follows: Collect the instruction timing signal, memory access signal, and peripheral interaction signal of the computer, printer, and network camera, perform sliding window segmentation on the instruction timing signal, count the discrete values of the timing intervals within each window to generate an original timing data set, perform time-frequency segmentation on the memory access signal, extract the frequency domain amplitude spectrum of each segment to generate a memory access frequency domain set, and count the number of trigger times of interaction events per unit time for the peripheral interaction signal to generate a peripheral interaction count set; Based on the original timing data set, calculate the instruction timing fluctuation data; Based on the memory access frequency domain set, calculate the memory access fluctuation data; Based on the peripheral interaction count set, calculate the peripheral interaction frequency data; Integrate the instruction timing fluctuation data, memory access fluctuation data, and peripheral interaction frequency data to establish a set of quantified device behavior indicators.
3. The computer defense system based on the Internet of Things according to claim 1, characterized in that, The steps for obtaining the device indicator statistical boundary are as follows: Based on the set of quantified device behavior indicators, calculate the mean, variance, and range of the instruction timing fluctuation data at all sampling points within the target operation period, synchronously calculate the mean, variance, and range of the memory access fluctuation data, and the mean, variance, and range of the peripheral interaction frequency data to generate a set of statistical characteristics; Based on the mean, variance, and range of instruction timing fluctuations, memory access fluctuations, and peripheral interaction frequency data in the statistical property set, extract the mean sequence of the same metrics from historical normal operation data. Use a dynamic sliding window with a window length covering 80% of the target running period and a sliding step of 10% of the window length. Sort the mean sequence in ascending order of values, remove the extreme values in the first 5% and the last 5%, and the remaining 90% mean range is the 90% confidence interval of the window. Take the lower limit of the confidence interval as the minimum allowable value of the mean and the upper limit as the maximum allowable value of the mean; for the variance, statistically analyze the variance distribution of historical normal data and take the 95th percentile as the upper limit of variance tolerance; For the range, use the moving average of the range values within the sliding window and superimpose 3 times the standard deviation as the dynamic threshold to obtain the statistical boundary of the device metrics.
4. The computer defense system based on the Internet of Things according to claim 1, characterized in that, The steps for obtaining the device specification operation map are as follows: Based on the statistical boundary of the device metrics, use the mean range of each metric as an independent dimension, and the upper limit of variance tolerance and the dynamic threshold of the range as additional constraint conditions for each dimension to generate a multi-dimensional state space model; Based on the multi-dimensional state space model, extract the real-time instruction timing fluctuation mean as the X-axis coordinate value, the memory access fluctuation mean as the Y-axis coordinate value, and the peripheral interaction frequency mean as the Z-axis coordinate value, and determine whether the coordinate values simultaneously satisfy the X-axis range, Y-axis range, and Z-axis range. The X-axis range includes the lower limit of the normal mean of instruction timing fluctuations and the upper limit of the normal mean of instruction timing fluctuations; The Y-axis range includes the lower limit of the normal mean of memory access fluctuations and the upper limit of the normal mean of memory access fluctuations; The Z-axis range includes the lower limit of the normal mean of peripheral interaction frequency and the upper limit of the normal mean of peripheral interaction frequency; and the real-time variance value is lower than the upper limit of variance tolerance of the statistical boundary, and the real-time range value is lower than the dynamic threshold of the range. If all are satisfied, mark it as an allowed operation state point, otherwise mark it as an abnormal state point, and generate a set of allowed operation state points; According to the set of allowed operation state points, extract the spatial coordinates of all allowed operation state points, and delimit the boundary of the allowed operation area in the three-dimensional state space coordinate system to obtain the device specification operation map.
5. The computer defense system based on the Internet of Things according to claim 1, characterized in that, The steps for obtaining the real-time behavior deviation signal are as follows: Real-time collect the current operation metrics of the computer and associated printer and network camera, including the mean of instruction timing fluctuations, the mean of memory access fluctuations, and the mean of peripheral interaction frequency, and store them classified by device type to generate the current operation metric set; Based on the boundary of the allowed operation area defined in the device specification operation map, perform a spatial mapping on the current operation metric set: map the mean of instruction timing fluctuations, the mean of memory access fluctuations, and the mean of peripheral interaction frequency of the computer to three-dimensional coordinate points, and determine whether the three-dimensional coordinate points are within the boundary of the allowed operation area; synchronously map the metrics of the printer and network camera to within the corresponding boundary of the allowed operation area to generate a compliance test result containing compliance or out-of-bounds labels; If there are out-of-bounds labels in the compliance test result, extract the out-of-bounds device type, out-of-bounds metric name, real-time value, and timestamp, and generate a real-time behavior deviation signal in a preset format.
6. The computer defense system based on the Internet of Things according to claim 1, characterized in that, The steps for obtaining the access condition risk level are as follows: Extract the real-time values, allowable boundary ranges, and associated device types from the real-time behavior deviation signal set, sort them according to the absolute value of the difference between the real-time value and the upper allowable boundary, mark the signals with a difference exceeding the preset tolerance value as high-risk signals, and generate a high-risk signal list; Based on the high-risk signal list, match the corresponding risk scenarios in the data access risk scenario library, extract the data sensitivity level, access frequency threshold, and peripheral permission requirements defined in the scenarios, and generate a risk association parameter set; Calculate the access condition risk level according to the risk association parameter set.
7. The computer defense system based on the Internet of Things according to claim 1, characterized in that, The steps for obtaining the access control response instruction are as follows: Based on the access condition risk level, extract the control level intervals defined in the preset access policy library and generate a control level interval mapping table; Calculate the dynamic control priority according to the control level interval mapping table; Based on the dynamic control priority, match the mapping relationship between the priority and the instruction in the preset access policy library and generate an access control response instruction.
8. The computer defense system based on the Internet of Things according to claim 1, characterized in that, The steps for obtaining the updated access permission status are as follows: Based on the access control response instruction, if the instruction type is to isolate the storage area, create an independent storage partition directory named with the device ID and the current timestamp, configure the firewall rule to prohibit unauthorized IPs from accessing this directory, modify the storage path mapping table of the target device, redirect the original storage path to the isolated partition directory, and record the corresponding relationship between the isolated path and the original path; If the instruction type is to notify the supervision node, call the HTTP notification interface of the supervision platform, send a JSON format data packet through a POST request, where the data packet includes the device ID, risk level, trigger time, and the current operation log summary, receive the status code returned by the interface, and if the status code is not 200, retry 3 times and record the exception; generate an operation completion status record table including the operation result, execution time, and log path; According to the operation completion status record table, for the devices successfully isolated, add an isolated partition field to the operation completion status record table, write in the isolated path, firewall rule version number, and effective time; for the devices that have notified the supervision node, mark the supervision notification status as sent in the operation completion status record table, and associate the notification receipt number with the timestamp; obtain the updated access permission status.
Citation Information
Cited By
Method and device for improving read-write performance of solid state disk and computer equipment
CN120872258A
A method, device and computer equipment for improving read-write performance of a solid state disk
CN120872258B
Internet of Things network security optimization method and related equipment
CN121012697A
Data security acquisition and processing system in MES system
CN121167734A