Internet of Things equipment defense resource allocation method and device and terminal equipment

By obtaining the identification, status and topology information of IoT devices, calculating the importance and interaction level of devices, and using the Stackelberg game model to optimize the allocation of defense resources, the problem of insufficient security of IoT devices is solved, dynamic adaptation to topology structure and service requirements is achieved, and protection capabilities are improved.

CN120750657AActive Publication Date: 2025-10-03SICHUAN NORMAL UNIV +1

Patent Information

Application Number
CN202511231813.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-01
Publication Date
2025-10-03
Estimated Expiration
2045-09-01

AI Technical Summary

Technical Problem

Existing IoT devices do not fully consider security during the design phase, resulting in a large number of vulnerabilities, making it difficult to adapt to dynamic changes in topology and service requirements, and unable to effectively and proactively defend against attack risks.

Method used

By obtaining the identification information, operating status information, topology information and communication characterization information of IoT devices, the importance and interaction level of the devices are calculated, the initial defense resource allocation information and attack probability information are generated, and the Stackelberg game model is used to optimize the defense resource allocation and dynamically adjust the defense strategy to deal with external intrusion and lateral movement attacks.

Benefits of technology

It achieves the flexibility and timeliness of IoT device defense resources, improves the dynamic protection capability against complex attacks, and reduces the losses of devices after being attacked.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120750657A_ABST
    Figure CN120750657A_ABST
Patent Text Reader

Abstract

The invention provides an Internet of Things equipment defense resource allocation method and device and terminal equipment, and is suitable for the technical field of the Internet of Things, and the method comprises the steps: according to Internet of Things equipment identification information, Internet of Things topological structure information, Internet of Things equipment operation state information and inter-equipment communication characterization information, determining the Internet of Things equipment defense resource allocation; obtaining equipment importance degree characterization information and equipment interaction degree characterization information; obtaining net income information of attackers and total loss information of defenders according to the initial Internet of Things equipment defense resource allocation information, the equipment attacked probability information, the equipment importance degree representation information, the equipment interaction degree representation information and the equipment attack cost and defense cost information; and according to the attacker net income information, the defender total loss information and the initial Internet of Things equipment defense resource allocation information, determining target Internet of Things equipment defense resource allocation information. The method can flexibly adapt to the dynamic change of network topology and service requirements, and effectively improves the dynamic protection capability of the Internet of Things in coping with complex attacks.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application belongs to the field of Internet of Things technology, and in particular relates to a method, apparatus and terminal device for allocating defense resources to Internet of Things devices. Background Art

[0002] With the rapid development of smart device technology, the Internet of Things (IoT) has become an integral part of our daily lives. The IoT has demonstrated tremendous application potential across a wide range of industries, including smart homes, smart education, smart transportation, healthcare, and health monitoring. Compared to traditional network systems, the IoT offers significant advantages in the discovery, distribution, and sharing of network information and resources. However, with the advancement of technology and the widespread adoption of IoT applications, security issues are becoming increasingly prominent. Currently, many IoT devices lack adequate security considerations during their design phase, resulting in numerous vulnerabilities that make them easy targets for attackers, leading to privacy breaches and data security issues. Therefore, strengthening the security of IoT devices and improving their ability to resist attacks has become a critical and urgent task. This requires comprehensive measures across multiple aspects, from hardware design and software development to network monitoring, to ensure the overall security of IoT systems.

[0003] In existing technologies, some manufacturers enhance device security by integrating secure hardware encryption modules and providing remote update capabilities. They also utilize protocols such as TLS / DTLS to ensure encrypted data transmission. However, these measures often have a certain lag and struggle to adapt to the dynamic changes in IoT topology and service requirements, resulting in an inability to effectively proactively defend against attack risks. Therefore, while these technologies have helped improve device security, their limitations have weakened the overall security protection capabilities of IoT devices. To address this issue, there is an urgent need to develop security policies that can respond and adjust in real time to better cope with the dynamically changing network environment. Summary of the Invention

[0004] In light of this, embodiments of this application propose a method, apparatus, and terminal device for allocating defense resources for IoT devices, designed to adapt to the dynamic changes in IoT topology and service requirements. By optimizing defense resource management, this embodiment can protect critical network devices in real time, effectively mitigating losses to IoT systems caused by malicious threats.

[0005] A first aspect of an embodiment of the present application provides a method for allocating defense resources to an IoT device, including:

[0006] Obtain IoT device identification information, IoT device operating status information, IoT topology information, and communication characterization information between IoT devices;

[0007] Calculate the importance characterization information of multiple devices and the interaction degree characterization information of multiple devices based on the IoT device identification information, IoT topology information, IoT device operation status information, and communication characterization information between IoT devices;

[0008] Generate multiple initial IoT device defense resource allocation information and multiple device attack probability information;

[0009] Calculate the attacker's net gain information and the defender's total loss information based on the initial IoT device defense resource allocation information, device attack probability information, device importance representation information, device interaction representation information, and preset device attack cost and defense cost information;

[0010] Based on the multiple attacker net profit information and defender total loss information, the multiple initial IoT device defense resource allocation information is analyzed and calculated to determine the target IoT device defense resource allocation information.

[0011] A second aspect of an embodiment of the present application provides an apparatus for allocating defense resources to an IoT device, including:

[0012] The IoT device information acquisition module is used to obtain IoT device identification information, IoT device operating status information, IoT topology information, and communication characterization information between IoT devices;

[0013] a device importance representation information and device interaction degree representation information calculation module, configured to calculate a plurality of device importance representation information and a plurality of device interaction degree representation information based on the IoT device identification information, IoT topology information, IoT device operation status information, and communication representation information between IoT devices;

[0014] An initial IoT device defense resource allocation information and device attack probability information generation module is used to generate multiple initial IoT device defense resource allocation information and multiple device attack probability information;

[0015] An attacker's net gain information and defender's total loss information calculation module is configured to calculate the attacker's net gain information and defender's total loss information based on the initial IoT device defense resource allocation information, device attack probability information, device importance representation information, device interaction representation information, and preset device attack cost and defense cost information.

[0016] The target IoT device defense resource allocation information determination module is used to analyze and calculate the multiple initial IoT device defense resource allocation information based on the multiple attacker net profit information and defender total loss information to determine the target IoT device defense resource allocation information.

[0017] A third aspect of an embodiment of the present application provides a terminal device, which includes a memory and a processor, wherein the memory stores a computer program that can be run on the processor, and when the processor executes the computer program, it implements the steps of the IoT device defense resource allocation method described in the first aspect above.

[0018] A fourth aspect of an embodiment of the present application provides a computer-readable storage medium, comprising: storing a computer program, which, when executed by a processor, implements the steps of the IoT device defense resource allocation method as described in the first aspect above.

[0019] Compared with the prior art, the embodiments of the present application have the following beneficial effects: the present application is used to effectively adapt to the dynamic changes of the IoT topology structure, and can improve the flexibility and timeliness of allocating defense resources for IoT devices by analyzing and calculating the attack and defense process between attackers and defenders, and provide timely active defense against the two types of attack behaviors that IoT devices are extremely vulnerable to, namely external intrusion and lateral movement. Compared with traditional static defense strategies, the present application is more adaptable to the dynamic changes of the IoT topology structure and service needs, and effectively improves the dynamic protection capabilities of the IoT in dealing with various complex attacks, thereby reducing the losses of IoT devices after being attacked. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the embodiments or descriptions of the prior art. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0021] Figure 1 This is a schematic diagram of the implementation process of the method for allocating defense resources to IoT devices provided in Example 1 of the present application;

[0022] Figure 2 This is a schematic diagram of the implementation process of the method for allocating defense resources to IoT devices provided in Example 2 of the present application;

[0023] Figure 3 This is a schematic diagram of the implementation process of the method for allocating defense resources to IoT devices provided in Example 3 of the present application;

[0024] Figure 4This is a schematic diagram of the implementation process of the method for allocating defense resources to IoT devices provided in Example 4 of the present application;

[0025] Figure 5 This is a schematic diagram of the implementation process of the method for allocating defense resources to IoT devices provided in Example 5 of the present application;

[0026] Figure 6 This is a schematic diagram of the implementation flow of the method for allocating defense resources to IoT devices provided in Example 6 of the present application;

[0027] Figure 7 This is a schematic diagram of the implementation process of the method for allocating defense resources to IoT devices provided in Example 7 of the present application;

[0028] Figure 8 This is a structural diagram of the device for allocating defense resources to an IoT device provided in Example 8 of the present application;

[0029] Figure 9 This is a schematic diagram of the terminal device provided in Example 9 of the present application. DETAILED DESCRIPTION

[0030] In the following description, specific details such as specific system structures and techniques are provided for purposes of illustration rather than limitation to facilitate a thorough understanding of the embodiments of the present application. However, it will be apparent to those skilled in the art that the present application may be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to avoid obscuring the description of the present application with unnecessary detail.

[0031] In order to illustrate the technical solution described in this application, specific embodiments are provided below.

[0032] Figure 1 The following is a flowchart of the method for allocating defense resources to IoT devices provided in Example 1 of the present application, which is described in detail as follows:

[0033] Step S101: Obtain IoT device identification information, IoT device operating status information, IoT topology information, and communication characterization information between IoT devices.

[0034] In this embodiment, IoT device identification information may refer to the IoT device's ID information, such as its MAC address, or information registered via a specific communication protocol when the IoT device is connected, which can be obtained by the IoT administrator by reading the registration information. IoT device operating status information may refer to dynamic data on the IoT device's current operating status, including device online / offline status, resource utilization, battery charge, sensor readings, fault alarms, etc. This information may be obtained through operation logs regularly sent by built-in agents in each IoT device to a platform operated by the administrator. IoT topology information may refer to network structure data representing the interactive relationships between IoT devices, obtained by abstracting and modeling the interactions between IoT devices using classical graph theory methods. This data may include the organization and connection methods of devices in the network, and can be modeled by real-time collection of neighbor information exchanged during collaborative communication between IoT devices. Communication characterization information between IoT devices may refer to the number of communications between two IoT devices, or the duration of communications between two IoT devices. This information can be used to measure the closeness between two IoT devices and can be obtained by recording communication messages between two IoT devices on a platform controlled by the IoT administrator.

[0035] Step S102 : Calculate and obtain multiple device importance representation information and multiple device interaction degree representation information based on the IoT device identification information, IoT topology information, IoT device operation status information, and communication representation information between IoT devices.

[0036] In this embodiment, it is understood that in the IoT topology, an IoT device is regarded as an IoT device. By updating the IoT topology information obtained in real time, combined with the operating status information of each IoT device and the communication characterization information between IoT devices, the IoT device importance characterization information and device interaction characterization information corresponding to the identification information of each IoT device are calculated, wherein the device importance characterization information is used to characterize the comprehensive importance of each IoT device in communication and business, and the device interaction characterization information is used to characterize the intimacy of each IoT device in communicating with other IoT devices in the same IoT topology. It is understandable that when an IoT device is not only the core relay for communication between the vast majority of devices, but also provides services for most users in the network, it can be considered that the importance of the device is relatively high; when a single IoT device communicates with another IoT device for a longer time during online work, the intimacy of the device to the other device is higher.

[0037] In this embodiment, it is understandable that the bottom layer of the Internet of Things is various types of intelligent hardware devices, and its upper layer is the users who have the authority to use them. A smart hardware device, IoT devices, which are The collection of IoT devices and users is used to provide services to each user. and In the Internet of Things, the interactions between IoT devices change dynamically over time, so the topology of the network also changes dynamically. Start recording the interactions between devices and End observation. Change observation time interval Divided into A small interval, that is The length of each small interval is set to , then The small interval is recorded as In a communication network, if the device and In the operating range If there is interaction in the memory, the device With equipment There are edges between ,in Represents the set of edges between all devices in the network.

[0038] Next, this example will evaluate the importance of IoT devices from two aspects. On the one hand, IoT devices act as communication relays, responsible for receiving, processing, and forwarding data packets to expand network coverage and improve communication reliability and efficiency. In the Internet of Things, the betweenness centrality of an IoT device refers to the number of times the device appears on the shortest communication path between all devices. Devices with high betweenness centrality usually serve as key connection points or transit stations for network communication, and therefore are crucial to the overall operation of the IoT network. Internal equipment The importance of the Internet of Things can be measured by the betweenness centrality index, which is calculated as follows:

[0039]

[0040] in Indicates that the Internal slave device To device The number of shortest paths can be extracted from the IoT topology information. Indicates the devices passed through in these shortest paths the number of is the normalization factor. On the other hand, IoT devices can provide users with a variety of services, such as personalized recommendations, remote monitoring, and resource sharing. The more services a device provides to users, the more important it is in the user's life and work. Internal equipment Importance to a user group can be measured as follows:

[0041]

[0042] in Indicates that it is in the operating range The total number of users who send service requests to the Internet of Things, Indicates that the device The number of users who sent service requests.

[0043] In this embodiment, the smart devices in the Internet of Things not only bear the responsibility of data communication, but also establish direct connections with users and provide a variety of services. The dual functions of these IoT devices make them an indispensable part of the IoT ecosystem. Therefore, the importance of devices can be evaluated by considering these two factors comprehensively. In the operating range The comprehensive importance index in the equipment is the characterization information of the importance of the equipment, which is recorded as , can be measured by the following weighting method:

[0044]

[0045] In this embodiment, at the end of each operation interval, the intimacy between devices is evaluated based on the recent historical interactions between the devices. Indicates Time equipment is online, and Representation device Not online (sleep or standby); Indicates Time equipment With equipment Establish a connection, and Indicates that they are not connected. At the end, Recent devices When active with device The average probability of communication, which represents the degree of device interaction, is estimated using the following formula:

[0046]

[0047] in and They represent the starting point and end point of the historical observation interval considered when calculating intimacy, is the default value, Indicates that within the historical observation period, the device Active and connected to the device The time when the connection exists; Indicates that within the historical observation period, the device The time it is active. In particular, Representation device and equipment There is interaction within the historical observation interval, and There is no interaction between them. Quantified equipment For equipment The higher the value of this indicator, the closer the device is to the More inclined to equipment Establish communication.

[0048] Step S103: Generate multiple initial IoT device defense resource allocation information and multiple device attack probability information.

[0049] In this embodiment, the initial IoT device defense resource allocation information and the device attack probability information can be randomly generated to randomly generate the active defense and attack probabilities for multiple IoT devices. Subsequently, an iterative process can be used to select a defense resource allocation scheme that maximizes the attacker's net benefit and minimizes the defender's total loss. This information can then be used to configure defense resources for IoT devices in the actual IoT topology. IoT device defense resource allocation information refers to the amount of security protection resources (such as computing, storage, and bandwidth) allocated to each IoT device within the current IoT topology. As can be appreciated, increasing the resources allocated to a single IoT device allows for higher levels of security detection, thereby improving its defense capabilities and reducing the probability of a successful attack. However, this also increases the cost of defense. The attack probability information for multiple devices refers to the probability of each IoT device being attacked within the current IoT topology, while the attack probability information for a single device refers to the probability of a single IoT device being attacked within that IoT topology.

[0050] Step S104: Calculate the attacker's net gain information and the defender's total loss information based on the initial IoT device defense resource allocation information, device attack probability information, device importance characterization information, device interaction degree characterization information, and preset device attack cost and defense cost information.

[0051] In this embodiment, the preset attack cost information can be manually set and may refer to the price information of the hardware devices used by the attacker when conducting an online attack. It is understood that the more hardware devices the attacker uses, the higher the attack cost and the greater the probability of success in attacking IoT devices. It is also understood that an attacker can monitor certain IoT devices deployed in open areas to infer information representing the importance of these devices. In addition, by monitoring the communication between these devices and other IoT devices, the attacker can further obtain information representing the degree of device interaction. It is also understood that an external intrusion attack refers to an attacker who, when initially attacking IoT devices, does not launch a global attack against all IoT devices, but instead targets vulnerable IoT devices for intrusion. A lateral movement attack refers to an attacker using an already controlled IoT device to launch an attack against other IoT devices that are communicating with it. For example, in an IoT topology, there are devices 1, 2, and 3 communicating with each other. The communication between device 1 and device 2 is more frequent, that is, the device interaction degree representation information between device 1 and device 2 is larger, while the communication between device 1 and device 3 is relatively rare, that is, the device interaction degree representation information between device 1 and device 3 is smaller. In this network, device 2 is an ordinary IoT device, while device 1 and device 3 are important devices. Usually, important devices are usually more comprehensively and strictly protected. Cunning attackers usually do not directly attack devices 1 and 3 with better protection. Instead, they will choose ordinary device 2 as a breakthrough point, carry out external intrusion attacks on device 2, and then use device 2 as a springboard to take advantage of the close relationship between devices to further launch lateral movement attacks on devices 1 and 3, thereby expanding the scale of the attack. Defense resource allocation information affects the attacker's probability of successful attacks. The more defense resources deployed, the lower the probability of successful attacks against that device. The two are inversely proportional. Device importance information determines the attacker's profit base and the defender's loss base. The higher the importance, the greater the attacker's profit after a successful attack, and the greater the defender's loss. Device interaction information affects the attacker's success rate in lateral movement attacks. The greater the device interaction information, the closer the relationship between the devices and the higher the success rate of lateral movement. For the attacker, the benefits from external intrusion and lateral movement attacks are proportional to the device's importance and the attacker's probability of successful attack. After deducting the preset attack cost, the attacker's net profit under different attack probabilities is obtained as the attacker's net profit information. For the defender, the losses caused by external intrusion and lateral movement attacks are proportional to the device's importance, the attacker's probability of successful attack, and the preset defense cost. The total loss of the defender under different defense resource allocation strategies is obtained as the defender's total loss information.

[0052] Step S105: Analyze and calculate the defense resource allocation information of the multiple initial IoT devices based on the multiple attacker net profit information and the defender total loss information to determine the defense resource allocation information of the target IoT device.

[0053] In this embodiment, the solution can be based on the equilibrium of the Stackelberg game. It is understandable that the defender's total loss information and the attacker's net gain information are jointly determined by the defense resource allocation scheme and the attack probability. By constructing an optimization problem with the defense resource allocation vector as the decision variable, the goal is to minimize the total loss function while also considering the attacker's optimal response based on the defense strategy. That is, the attacker will adopt the attack probability that maximizes their net gain to carry out external intrusions and lateral movement. This can be achieved by iteratively searching for defense resource allocation strategies using a genetic algorithm, while also iteratively searching for the attacker's optimal attack probability under that strategy. The corresponding attacker's net gain and the defender's total loss are then calculated. Ultimately, through the genetic algorithm's selection and mutation operations, the strategy pair is converged to minimize the defender's total loss and maximize the attacker's net gain. The defense resource allocation scheme in this strategy pair is then used as the defense resource allocation information for the target IoT device.

[0054] The method for allocating defense resources for IoT devices provided in the embodiments of the present application is used to effectively adapt to the dynamic changes in the IoT topology. It can improve the flexibility and timeliness of allocating defense resources for IoT devices by analyzing and calculating the attack and defense process between attackers and defenders, and provide timely active defense against external intrusion attacks and lateral movement attacks that IoT devices are extremely vulnerable to. Compared with traditional static defense strategies, it is more adaptable to the dynamic changes in the IoT topology, effectively improving the dynamic protection capabilities of the IoT in response to various complex attacks, and reducing the losses of IoT devices after being attacked.

[0055] Figure 2 The flowchart of the implementation of the method for allocating defense resources for IoT devices provided in the second embodiment of the present application is shown. The difference between the method and the first embodiment is that step S102 specifically includes:

[0056] Step S201 : Calculate and obtain multiple pieces of device importance representation information based on the IoT device identification information, IoT topology information, and communication representation information between IoT devices.

[0057] In this embodiment, on the one hand, the identity of the IoT device is first determined using the IoT device identification information, and then a network graph model is constructed based on the IoT topology information. The communication importance of the device is quantified by betweenness centrality, that is, the number of times a device appears on the shortest communication path between all possible devices is counted. The higher the frequency of the IoT device acting as a relay in the communication path, the greater the betweenness centrality index of the IoT device, which means that the IoT device is more important in the IoT topology. On the other hand, the service importance of the IoT device can be quantified based on user service request data in the communication characterization information, such as the frequency of IoT devices providing services to users. That is, the ratio of the number of users sending requests to the IoT device to the total number of users. The higher the service coverage, the higher the service importance. Finally, the above-mentioned communication importance and service importance indicators are weighted and summed using manually preset weight values ​​to obtain comprehensive characterization information reflecting the importance of each IoT device.

[0058] Step S202: Calculate and obtain multiple device interaction degree representation information based on the IoT device identification information, IoT device operation status information, and communication representation information between IoT devices.

[0059] In this embodiment, the identity of the IoT device is first determined using the IoT device identification information, and then the operating status information of the IoT device is used to determine whether the IoT device is in an active state, and only the communication data of the device in the active state is effectively filtered. Based on the communication characterization information between IoT devices, statistics are collected within a specific operating range. Active and connected to the device The length of time it takes to establish a communication connection, and the device The total activation time in this interval is calculated, and the ratio of this time length to the total activation time length is calculated to obtain the average communication probability between devices. This probability value is the characterization information of the device interaction degree, which is used to quantify the device With equipment The frequency of communication between devices. A higher value indicates that the device When communicating with the device Show greater intimacy.

[0060] The IoT device defense resource allocation method provided in the embodiment of the present application combines IoT device identification information, topology information, operating status information and communication characterization information, calculates device importance characterization information and device interaction degree characterization information, and realizes quantitative evaluation of IoT device communication importance, service importance and the frequency of interaction between devices, provides data support for subsequent defense resource allocation, effectively adapts to the dynamic changes of IoT communication topology and business needs, improves the flexibility and timeliness of defense resource allocation, and enhances the active defense capability against external intrusion attacks and lateral movement attacks. Compared with the static defense strategy in the existing technology, it can better cope with complex attack scenarios and reduce the losses of IoT devices after being attacked.

[0061] Figure 3 The following is a flowchart of the method for allocating defense resources to IoT devices provided in Example 3 of the present application. The difference between the method and Example 2 is as follows:

[0062] The communication characterization information between the IoT devices includes information on the number of communications between the IoT devices;

[0063] The step S201 specifically includes:

[0064] Step S301: obtaining a plurality of IoT topology communication path length information corresponding to each IoT device identification information according to the IoT device identification information and IoT topology structure information.

[0065] In this embodiment, a network graph model is constructed based on IoT topology information. The devices corresponding to each IoT device identification information are used as vertices in the graph, and the physical connections or communication relationships between devices are used as edges. The edge weights can be set as communication delay or link stability indicators. Classical graph algorithms, such as the Dijkstra or Floyd-Warshall algorithms, are used to calculate the shortest path length between any two devices, thereby obtaining multiple path length values ​​corresponding to each device identification information. These values ​​reflect the importance of the device's position in the network. For example, the shortest path consumes less time and energy during data transmission. If a device is located on multiple shortest paths, then the device has a higher relay value in data transmission.

[0066] Step S302: Determine the shortest topology communication path information between IoT devices based on the length information of multiple IoT topology communication paths corresponding to the IoT device identification information.

[0067] In this embodiment, all possible communication paths corresponding to device identification information are sorted by path length to determine the specific information of the shortest communication path between devices, including details of all intermediate devices along the path. In particular, if a device is located on the shortest communication path between multiple devices, this indicates that it is a very important transit device and has a significant impact on the communication of the IoT system.

[0068] Step S303: Obtain device importance characterization information based on the shortest topology communication path information between the IoT devices and the communication characterization information between the IoT devices.

[0069] In this embodiment, a device importance characterization model is constructed by combining shortest communication path information with communication frequency information. The average frequency of each device's appearance on the shortest path between all device pairs can be calculated. This metric reflects the device's importance in the communication relay and can be used as an indicator to quantify the device's communication importance. Furthermore, by counting the number of communications between IoT devices and users, the proportion of service requests received by each device in the total number of requests is calculated. This metric reflects the urgency of the service demand provided by the device and can be used as an indicator to quantify the importance of the device's service. The communication importance and service importance are weighted using preset weights to obtain device importance characterization information.

[0070] The method for allocating defense resources for IoT devices provided in the embodiments of the present application constructs a network graph model based on IoT topology information, obtains the corresponding shortest path between any two devices, identifies key relays in network data communication, and evaluates the communication importance and service importance of each IoT device based on the interaction information between users and devices, so as to tilt defense resources towards more important IoT devices.

[0071] Figure 4 The following is a flowchart of the method for allocating defense resources to IoT devices provided in Example 4 of the present application. The difference between the method and Example 2 is as follows:

[0072] The IoT device operation status information includes the online duration information of the IoT device;

[0073] The communication characterization information between the IoT devices includes communication duration information between the IoT devices;

[0074] The step S202 specifically includes:

[0075] Step S401: Determine online duration information of each IoT device and communication duration information between IoT devices according to the IoT device identification information.

[0076] In this embodiment, the online status logs of IoT devices can be regularly collected through the agent program built into the IoT devices. Time series data can be created based on the IoT device identification information to calculate the total online time of each device within the observation interval. Simultaneously, based on the communication messages recorded by the IoT administrator platform, the message sending and receiving timestamps are extracted, the duration of each communication between any two devices is calculated, and the cumulative communication duration is aggregated by device pair. For example, by parsing the timestamp field in the message header and combining it with the device identification information, a communication duration matrix is ​​constructed, where the elements of the matrix represent the cumulative communication time of the two devices within the observation interval. This communication duration information reflects the depth and continuity of interaction between IoT devices.

[0077] Step S402 : Calculate and obtain multiple device interaction degree representation information based on the online duration information of the IoT devices corresponding to the IoT devices and the communication duration information between the IoT devices.

[0078] In this embodiment, it can be for each IoT device , by putting the device With equipment The cumulative communication time between devices is divided by Online time to quantify the device To the device The degree of interaction (that is, the device interaction degree representation information) can be the device interaction degree representation information = communication time / online time.

[0079] The method for allocating defense resources for IoT devices provided in the embodiments of the present application quantifies the device interaction relationship through the dual dimensions of online time and communication time, can capture the changes in the active status of the device in real time, and dynamically adjust the defense resource allocation strategy to cope with the frequent sleep / wake-up characteristics of IoT devices. It accurately identifies high-value communication links by accumulating communication time rather than simply the number of times, and gives priority to protecting devices that carry core services. The intimacy model established based on the interaction information in the recent period can more accurately predict the lateral movement path that attackers may exploit, deploy defense measures in advance, and focus defense resources on devices with frequent interactions and stable online status, avoiding excessive investment in low-value or intermittently active devices, thereby significantly improving the accuracy and adaptability of defense resource allocation.

[0080] Figure 5 The following is a flowchart of the method for allocating defense resources to IoT devices provided in Example 5 of the present application. The difference between the method and Example 1 is as follows:

[0081] The plurality of device interaction degree characterization information includes a plurality of device interaction degree characterization information mastered by attackers and a plurality of device interaction degree characterization information mastered by defenders;

[0082] The step S104 specifically includes:

[0083] Step S501 : generating a local device interaction degree representation matrix based on the device interaction degree representation information obtained by the multiple attackers.

[0084] In this embodiment, the interaction degree characterization information between all IoT devices is sorted by device identification to construct a complete Order matrix ( is the total number of smart hardware devices in the Internet of Things), forming a global device interaction degree representation matrix ,in Representation device To the device The degree of interaction can be obtained by the administrator of the IoT system based on the device status information collected by the management platform. At the same time, based on the partial device interaction data that the attacker can actually obtain, the corresponding rows and columns are extracted to generate a local device interaction degree representation matrix. , this matrix only contains some non-zero elements in the global matrix to reflect the attacker's information limitations.

[0085] Step S502 : performing matrix decomposition processing on the local device interaction degree representation matrix according to a preset matrix decomposition loss calculation function to obtain a device representation feature matrix combination.

[0086] In this embodiment, the permissions that the attacker can obtain are very limited, and it is usually impossible to grasp all the information about the operation of the IoT system through direct observation. In reality, the interaction process between IoT devices has a low-rank characteristic. This property stems from the correlation between the spatial distribution and functional attributes of IoT devices, which makes the interaction pattern between devices have strong structural characteristics, and devices with similar functions often show stronger interactions. Therefore, the matrix decomposition method can be used to predict information and fill in missing values ​​based on limited observation data, and accurately model the device interaction degree characterization information through dimensionality reduction and reconstruction of the potential feature space, significantly improving the information integrity in sparse perception scenarios. In this embodiment, the partial device interaction degree characterization information that the attacker can obtain is used as the local device interaction degree characterization matrix, and the attacker can use these limited local device interaction degree characterization information to predict the global device interaction degree characterization information. Let the matrix Represents the real intimacy data between all devices, that is, the global device interaction degree representation matrix, and the matrix It represents the intimacy data between some devices that the attacker can obtain, that is, the local device interaction degree representation matrix. Since the attacker has very limited information, the data It only contains For attackers, by taking advantage of the low-rank characteristics of the interaction process between IoT devices, the matrix decomposition method can help them predict the missing intimacy data. In the matrix decomposition technology, the attacker uses the matrix By decomposing it into two feature matrices and Then, we use the product of these two matrices To predict the missing intimacy data.

[0087] Step S503: Calculate the attacker's global device interaction degree representation matrix based on the device representation feature matrix combination.

[0088] In this embodiment, if the number of selected features is , then the characteristic matrix , When implementing matrix decomposition, by selecting the feature matrix and , so that their product approaches the matrix Therefore, the following loss function is introduced to calculate the matrix decomposition loss information:

[0089]

[0090] in is an indicator function and It takes the value of 1 when present and 0 when missing; Representation matrix The i-th row of Representation matrix The jth column of and It is a regularization term that can avoid overfitting problems; represents the Frobenius norm; and is a hyperparameter that satisfies .

[0091] Product of characteristic matrices The closer the matrix , then the loss function Therefore, the matrix decomposition problem is transformed into an optimization problem: how to select the optimal feature matrix and , so that the loss function The value of is the smallest. Let and represents the optimal solution to the optimization problem, then the intimacy result predicted by the attacker is .

[0092] Step S504 , calculating the attacker's net benefit information based on the attacker's global device interaction degree representation matrix, multiple initial IoT device defense resource allocation information, device attack probability information, device importance representation information, and preset attack cost information.

[0093] In this embodiment, the attacker's net gain is calculated based on the attacker's predicted global interaction matrix, combined with initial defense resource allocation information and device attack probability information. Specifically, the attacker's gain comes from two parts: the gain from a successful external intrusion and the gain from a successful lateral movement attack. The gain from an external intrusion depends on the importance of the target device and the attack success probability, while the gain from a lateral movement attack is related to the importance of the target device, the interaction intimacy between the source and target devices (derived from the attacker's predicted matrix), and the attack success probability. The attacker's net gain is the total gain minus the attack costs of external intrusion and lateral movement, where the attack costs are proportional to the attack probability. Loss information can be decomposed by traversing all matrices and selecting a combination of feature matrices with the lowest loss value. The product of this set of feature matrices best approximates the local interaction data obtained by the attacker and serves as the attacker's prediction of the global interaction level.

[0094] Step S505 : calculating a defender's global device interaction degree representation matrix based on the device interaction degree representation information mastered by the multiple defenders.

[0095] In this embodiment, the defender possesses complete device interaction data and constructs a global device interaction matrix based on the full communication records collected by the management platform. This matrix contains the actual interaction intimacy information between all devices, contrasting with the attacker's predicted matrix and highlighting the information asymmetry between the attacker and defender. The defender uses this matrix to assess the actual lateral movement risk, providing accurate data support for subsequent loss calculations.

[0096] This can be based on the Stackelberg game model, using the product of the device interaction matrix as the attacker's perceived intimacy information. Combined with defense resource allocation information and attack probability information, the probability of a successful attack on the device is calculated. The attacker's net gain is then calculated based on the device importance information and the device attack cost information. Furthermore, the probability of a successful attack on the device is calculated based on the global device interaction matrix, defense resource allocation information, and attack probability information. The defender's total loss is then calculated based on the device importance information and defense cost information.

[0097] In this embodiment, the confrontation between the attacker and the defender is essentially a game. In the network attack and defense scenario, in order to more effectively protect the system security, the defender must first understand and predict the attacker's potential intentions and the possible countermeasures, and then carefully plan a defense strategy to minimize the damage caused by the attack. In view of this, it is particularly appropriate to model the dynamic process of network attack and defense as a Stackelberg game model. First, it is necessary to model the strategies of both the attacker and the defender. For the defender, he needs to deploy defense resources to each device in the network to protect their security. Let represents the defender's defense strategy, where Indicates that the defender is on the device Deployed defense resources. and Represent the attacker's external intrusion attack and lateral movement attack strategies, respectively. Indicates that the attacker has The probability of launching an external intrusion, the probability of each attack being successful in this way is recorded as , which is combined with the defense resources deployed on the device Inversely proportional, Indicates that the attacker exploited the device To the device The probability of implementing lateral movement, the probability of each attack being successful in this way is recorded as , which is combined with the defense resources deployed on the device Inversely proportional to the device For equipment Intimacy Directly proportional.

[0098] Secondly, we need to analyze the utility of both the attacker and the defender. For the attacker, he hopes to maximize his net profit by launching an attack. The attacker’s net gain is equal to the attack gain Subtract the attack cost ,Right now:

[0099] .

[0100] The attack benefit Including benefits from external intrusion and gains from lateral movement , that is

[0101] .

[0102] External intrusion benefits With the device The probability of successful external intrusion And the importance of this device is proportional to, and the proportionality coefficient is .therefore, The calculation formula is as follows:

[0103] .

[0104] Horizontal movement benefits With the device The probability of successful external intrusion , using external intrusion devices To the neighbors of this device Success rate of lateral movement attacks and equipment Importance And is proportional to, the proportionality coefficient is Considering that the attacker cannot accurately obtain , can only be used To make an approximate estimate. Therefore, The calculation formula is as follows:

[0105] .

[0106] Attack cost Including external intrusion attack costs and lateral movement attack costs , which are proportional to the probability of carrying out an attack, and the proportionality coefficient is , then the attack cost is:

[0107] .

[0108] For the defender, he hopes to minimize the total loss caused by the attacker The total loss of the defender Including defense costs and attack losses Therefore, the defender's total loss can be expressed as follows:

[0109] ,

[0110] The defense cost Total defense resources invested is proportional to, and the proportionality coefficient is ,so ; Attack loss Including external intrusion losses and lateral movement losses , that is:

[0111] .

[0112] External intrusion losses With equipment Probability of successful external intrusion And the importance of this device is proportional to, and the proportionality coefficient is .therefore, The calculation formula is as follows:

[0113] .

[0114] Lateral movement loss With equipment Probability of successful external intrusion , using external intrusion devices To the neighbors of this device Success rate of lateral movement attacks and equipment Importance And is proportional to, the proportionality coefficient is .therefore, The calculation formula is as follows:

[0115] .

[0116] Based on the above analysis, the attack and defense interaction process between the attacker and the defender can be modeled as the following Stackelberg game model:

[0117]

[0118] .

[0119] Use triples To represent the Stackelberg equilibrium strategy, where The Stackelberg equilibrium strategy is called the defender, and This is called the attacker's Stackelberg equilibrium strategy.

[0120] Step S506: Calculate the defender's total loss information based on the attacker's global device interaction degree representation matrix, the defender's global device interaction degree representation matrix, multiple initial IoT device defense resource allocation information, device attack probability information, device importance representation information, and preset defense cost information.

[0121] In this embodiment, the defender's total loss is composed of three components: the cost of defense resources invested, the loss caused by external intrusion, and the loss caused by lateral movement attacks. The defense cost is proportional to the total amount of defense resources allocated; the external intrusion loss depends on the device's criticality and the probability of successful intrusion; and the lateral movement loss is calculated based on a true global interaction matrix, combining the target device's criticality and the probability of successful lateral movement. By combining these three components, the total loss value for different defense resource allocation strategies is derived, providing a basis for subsequent optimization decisions.

[0122] The method for allocating defense resources for IoT devices provided in the embodiments of the present application constructs a global device interaction degree characterization matrix and a local device interaction degree characterization matrix, combines matrix decomposition technology to simulate the attacker's information limitations and prediction behavior, and quantifies the attacker's cognitive process in the attack and defense game into a computable matrix decomposition problem, so that the defense strategy optimization can more accurately respond to the attacker's actual capability boundary. By introducing the matrix decomposition loss function to screen the optimal attack prediction results, it is ensured that the attacker's benefit calculation conforms to the information asymmetry characteristics in the real attack and defense scenario, which is used to realize the dynamic optimization allocation of defense resources and effectively improve the active defense capability of the IoT system against unknown attacks.

[0123] Figure 6 The flowchart of the implementation of the method for allocating defense resources for IoT devices provided in Example 6 of the present application is shown. The difference between the method and Example 5 above is that:

[0124] The preset attack cost information includes preset external intrusion cost information and preset lateral movement cost information;

[0125] The device attack probability information includes probability information of the device being subjected to external intrusion and probability information of the device being subjected to lateral movement;

[0126] The step S504 specifically includes:

[0127] Step S601: Calculate the attacker's intrusion benefit information based on the initial IoT device defense resource allocation information, IoT device intrusion attack probability information, and device importance representation information.

[0128] In this embodiment, the amount of defense resources deployed on a device in the defense resource allocation information directly affects the probability of an attacker successfully initiating an external intrusion. Generally, the probability of an attacker successfully initiating an external intrusion against a device is inversely proportional to the amount of defense resources allocated to the device. The profit an attacker gains from an external intrusion attack is proportional to the product of the device's importance and the probability of successful intrusion. This net profit is then deducted from the product of the preset attack cost and the attack probability to obtain the attacker's net profit from the external intrusion attack.

[0129] Step S602 , calculating the attacker's lateral movement benefit information based on the initial IoT device defense resource allocation information, the attacker's global device interaction degree representation matrix, and the IoT device's lateral movement attack probability information.

[0130] In this embodiment, the net benefit information of the attacker carrying out a lateral movement attack can be calculated based on the defense resource allocation information deployed by the IoT device, the probability information of the attacker's lateral movement, the combination of the device interaction degree characterization feature matrix, the device importance characterization information, and the preset lateral movement attack cost information. Among them, the product of the device interaction degree characterization feature matrix represents the device intimacy perceived by the attacker. The probability of the attacker successfully carrying out a lateral movement attack is inversely proportional to the defense resources deployed on the target device and directly proportional to the intimacy of the source device. When calculating the net benefit information of a lateral movement attack, it is necessary to comprehensively consider the importance of the target device, the probability of the source device being invaded by an external device, and the probability of lateral movement to the target device, and then deduct the preset lateral movement attack cost to finally obtain the net benefit information obtained by the attacker through the lateral movement attack.

[0131] Step S603: Calculate the attacker's net profit information based on the preset attack cost information, the attacker's intrusion profit information, and the lateral movement profit information.

[0132] In this embodiment, the attacker's total net profit for the entire attack process can be calculated by adding the external intrusion net profit information and the lateral movement net profit information. The attacker's net profit is the sum of the external intrusion profit and the lateral movement profit. By calculating the net profit of each attack method and adding them together, the attacker's total net profit for the entire attack chain is obtained. This value reflects the attacker's optimal profit level under a specific defense strategy, providing a reference for defenders to evaluate the effectiveness of the strategy.

[0133] The step S506 specifically includes:

[0134] Step S604: Calculate device intrusion defense loss information based on the initial IoT device defense resource allocation information, IoT device intrusion attack probability information, and device importance characterization information.

[0135] In this embodiment, the external intrusion loss to the defender is proportional to the device's importance, the external intrusion probability, and the success probability of the intrusion. The more important the device, the greater the loss caused by a successful intrusion. Insufficient defense resource allocation increases the success probability and also increases the loss.

[0136] Step S605 , calculating device defense lateral movement loss information based on the initial IoT device defense resource allocation information, the attacker's global device interaction degree representation matrix, IoT device lateral movement attack probability information, and device importance representation information.

[0137] In this embodiment, lateral movement loss is calculated based on the defender's real-world global interaction matrix, combined with the target device's importance, lateral movement probability, and success probability. The more frequent the interactions between devices (higher intimacy), the higher the probability of lateral movement success; the more important the target device, the greater the loss.

[0138] Step S606 , the defender's total loss information is calculated based on the preset defense cost information, the defender's global device interaction degree representation matrix, the device defense intrusion loss information, and the device defense lateral movement loss information.

[0139] In this example, the defender's total loss is the sum of defense costs, intrusion losses, and lateral movement losses. By calculating the total loss under different defense resource allocation strategies, we provide a quantitative basis for selecting the optimal strategy.

[0140] The IoT device defense resource allocation method provided in the embodiment of the present application splits the device attack cost information and the attack probability information into two attack dimensions: external intrusion and lateral movement. Combined with the attacker's ability to predict intimacy, it realizes the refined calculation of the attacker's multi-stage attack benefits, distinguishes the attack consumption of the two processes of external intrusion and lateral movement, accurately maps costs and benefits, optimizes the allocation efficiency of defense resources under different attacks, improves the dynamic adaptability of defense decisions, and thus enhances the IoT defense system's proactive response capabilities to complex attack chains.

[0141] Figure 7 The flowchart of the implementation of the method for allocating defense resources for IoT devices provided in the seventh embodiment of the present application is shown. The difference between the method and the first embodiment is that step S105 specifically includes:

[0142] Step S701, determining whether the maximum value of the attacker's net profit information is less than a preset attacker's net profit threshold information; if so, returning to step S103; if not, entering step S702.

[0143] In this embodiment, the defender automatically pre-defines device defense resource allocation information, the probability of external intrusion, and the probability of lateral movement. This information can be randomly generated based on the actual application conditions. It is then dynamically updated to find the optimal solution. As for attack cost information, it must be set based on actual conditions to ensure the accuracy and feasibility of the solution.

[0144] Step S702: Calculate the intruder attacker's loss information based on the initial IoT device defense resource allocation information corresponding to the maximum value of the attacker's net benefit information, the IoT device's probability of being attacked by intrusion, the IoT device's probability of being attacked by lateral movement, the device's importance characterization information, and the preset intrusion attack cost information.

[0145] In this embodiment, the benefit of an attacker initiating an external intrusion on a device is proportional to the product of the device's importance information and the probability of intrusion, and inversely proportional to the amount of defense resources allocated to the IoT device. The cost of an attacker initiating an external intrusion on a device is proportional to the probability of intrusion. The net benefit of an attacker initiating an external intrusion is equal to the benefit of the intrusion minus the cost of the intrusion.

[0146] Step S703: Calculate the lateral attacker loss information based on the initial IoT device defense resource allocation information corresponding to the maximum value of the attacker's net benefit information, the device characterization feature matrix combination, the IoT device's probability of being attacked by lateral movement, and the preset lateral attack cost information.

[0147] In this embodiment, the attacker's prediction of device intimacy is represented by the product of a feature matrix representing the degree of device interaction. The benefit of an attacker performing lateral movement on a device is proportional to the product of the probability information of lateral movement, the intimacy between devices, and the target device's importance representation information, and is inversely proportional to the amount of defense resources allocated to the IoT device. The attack cost of an attacker performing lateral movement on a device is proportional to the probability information of the device's lateral movement. The net benefit obtained by the attacker performing lateral movement is equal to the benefit of lateral movement minus the attack cost of lateral movement. Then, based on the intruding attacker's loss information and the lateral attacker's loss information, the attacker's loss information is calculated; then, based on the attacker's loss information, the defender's total loss information, and the global device interaction representation matrix, the target IoT device's defense resource allocation information is determined.

[0148] In this embodiment, the adjustment of the external intrusion probability information and the lateral movement probability information of the device is achieved through iterative search of a genetic algorithm.

[0149] In this embodiment, the losses incurred by a defender due to an external intrusion attack on their device are proportional to the product of the device's importance information and the external intrusion probability information, and inversely proportional to the amount of defense resources allocated to the IoT device. The losses incurred by a defender due to a lateral movement attack on their device are proportional to the product of the lateral movement probability information, the intimacy between devices, and the target device's importance information, and inversely proportional to the amount of defense resources allocated to the IoT device. The defender's defense cost is proportional to the amount of defense resources allocated to the IoT device. The defender's total losses due to attacks are equal to the sum of the external intrusion losses, lateral movement losses, and defense costs.

[0150] In this embodiment, adjustments to IoT device defense resource allocation information can be implemented through an iterative genetic algorithm search. The defender's total loss can be calculated by combining the IoT device defense resource allocation information with the acquired device external intrusion probability and lateral movement probability information. If this total loss reaches a minimum, the iterative search ceases. Otherwise, the IoT device defense resource allocation information is repeatedly adjusted until the following conditions are met: a set of external intrusion probability information, lateral movement probability information, and IoT device defense resource allocation information is found such that, if the defender adopts this set of defense resource allocation information, no matter how the attacker adjusts the intrusion probability and lateral movement probability information, the net gain cannot be increased. Furthermore, if the attacker selects this set of intrusion probability and lateral movement probability information, no matter how the defender adjusts the defense resource allocation information, the total loss cannot be reduced. The attacker aims to maximize net gain, while the defender aims to minimize total loss. By adjusting the external intrusion probability information, lateral movement probability information, and IoT device defense resource allocation information, a solution is selected that maximizes the attacker's net gain and minimizes the defender's total loss. Because this scheme can force the strategic interaction between attackers and defenders to reach a rational balance, the corresponding IoT device defense resource allocation information in this scheme can serve as the defender's optimal defense strategy.

[0151] The IoT device defense resource allocation method provided in the embodiment of the present application calculates the attacker's net gain and the defender's total loss, uses a genetic algorithm to optimize the defense resource allocation strategy, achieves dynamic blocking of the attack chain and precise control of defense costs, and effectively improves the resource allocation efficiency and security protection capabilities of the IoT system in dynamic attack and defense scenarios.

[0152] Corresponding to the method of the above embodiment, Figure 8 The structural block diagram of the IoT device defense resource allocation device provided in an embodiment of the present application is shown. For the sake of convenience, only the parts related to the embodiment of the present application are shown. Figure 8 The exemplary IoT device defense resource allocation apparatus may be an execution subject of the IoT device defense resource allocation method provided in the aforementioned first embodiment.

[0153] Reference Figure 8 , the IoT device defense resource allocation device includes:

[0154] The IoT device information acquisition module 810 is used to obtain IoT device identification information, IoT device operating status information, IoT topology information, and communication representation information between IoT devices;

[0155] Device importance representation information and device interaction degree representation information calculation module 820, configured to calculate a plurality of device importance representation information and a plurality of device interaction degree representation information based on the IoT device identification information, IoT topology information, IoT device operating status information, and communication representation information between IoT devices;

[0156] Initial IoT device defense resource allocation information and device attack probability information generation module 830, used to generate multiple initial IoT device defense resource allocation information and multiple device attack probability information;

[0157] The attacker's net gain information and defender's total loss information calculation module 840 is configured to calculate the attacker's net gain information and defender's total loss information based on the initial IoT device defense resource allocation information, device attack probability information, device importance information, device interaction information, and preset device attack cost and defense cost information.

[0158] The target IoT device defense resource allocation information determination module 850 is used to analyze and calculate the multiple initial IoT device defense resource allocation information based on the multiple attacker net profit information and defender total loss information to determine the target IoT device defense resource allocation information.

[0159] The process of each module in the IoT device defense resource allocation device provided in the embodiment of the present application realizing its own function can be specifically referred to the aforementioned Figure 1 The description of the illustrated embodiment will not be repeated here.

[0160] It should be understood that the size of the serial numbers of the steps in the above embodiments does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.

[0161] It should be understood that when used in the present specification and the appended claims, the term "comprising" indicates the presence of described features, integers, steps, operations, elements and / or components, but does not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components and / or collections thereof.

[0162] It will also be understood that the term "and / or" used in this specification and the appended claims refers to and includes any and all possible combinations of one or more of the associated listed items.

[0163] As used in this specification and the appended claims, the term "if" can be interpreted as "when" or "upon" or "in response to determining" or "in response to detecting," depending on the context. Similarly, the phrase "if it is determined" or "if [described condition or event] is detected" can be interpreted as meaning "upon determination" or "in response to determining" or "upon detection of [described condition or event]" or "in response to detecting [described condition or event]," depending on the context.

[0164] In addition, in the description of the present specification and the appended claims, the terms "first", "second", "third", etc. are only used to distinguish descriptions and should not be understood as indicating or implying relative importance. It should also be understood that although the terms "first", "second", etc. are used in the text to describe various elements in some embodiments of the present application, these elements should not be limited by these terms. These terms are only used to distinguish one element from another. For example, a first table can be named a second table, and similarly, a second table can be named a first table without departing from the scope of the various described embodiments. Both the first table and the second table are tables, but they are not the same table.

[0165] References to "one embodiment" or "some embodiments" in this specification mean that a particular feature, structure, or characteristic described in conjunction with that embodiment is included in one or more embodiments of the present application. Thus, phrases such as "in one embodiment," "in some embodiments," "in other embodiments," and "in other embodiments" appearing in various places in this specification do not necessarily refer to the same embodiment, but rather mean "one or more but not all embodiments," unless otherwise specifically emphasized. The terms "including," "comprising," "having," and variations thereof all mean "including but not limited to," unless otherwise specifically emphasized.

[0166] The IoT device defense resource allocation method provided in the embodiments of the present application can be applied to terminal devices such as mobile phones, tablet computers, wearable devices, vehicle-mounted devices, augmented reality (AR) / virtual reality (VR) devices, laptops, ultra-mobile personal computers (UMPCs), netbooks, and personal digital assistants (PDAs). The embodiments of the present application do not impose any restrictions on the specific types of terminal devices.

[0167] For example, the terminal device can be a station (S) in a WLAN, a cellular phone, a cordless phone, a Session Initiation Protocol (SIP) phone, a Wireless Local Loop (WLL) station, a Personal Digital Assistant (PDA) device, a handheld device with wireless communication capabilities, a computing device or other processing device connected to a wireless modem, a vehicle-mounted device, a vehicle networking terminal, a computer, a laptop computer, a handheld communication device, a handheld computing device, a satellite wireless device, a wireless modem card, a TV set-top box (STB), a customer premises equipment (CPE) and / or other devices for communicating on a wireless system and a next-generation communication system, such as a mobile terminal in a 5G network or a mobile terminal in a future evolved public land mobile network (PLMN) network.

[0168] As an example and not a limitation, when the terminal device is a wearable device, the wearable device can also be a general term for wearable devices that are intelligently designed and developed using wearable technology for daily wear, such as glasses, gloves, watches, clothing and shoes. A wearable device is a portable device that is worn directly on the body or integrated into the user's clothes or accessories. Wearable devices are not only hardware devices, but also achieve powerful functions through software support, data interaction, and cloud interaction. Broadly speaking, wearable smart devices include those that are full-featured, large in size, and can achieve complete or partial functions without relying on smartphones, such as smart watches or smart glasses, as well as those that only focus on a certain type of application function and need to be used in conjunction with other devices such as smartphones, such as various smart bracelets and smart jewelry for vital sign monitoring.

[0169] Figure 9This is a schematic diagram of the structure of a terminal device provided by an embodiment of the present application. Figure 9 As shown, the terminal device 9 of this embodiment includes: at least one processor 90 ( Figure 9 Only one is shown), a memory 91, wherein the memory 91 stores a computer program 92 that can be run on the processor 90. When the processor 90 executes the computer program 92, the steps in the above-mentioned embodiments of the method for allocating defense resources to IoT devices are implemented, such as Figure 1 Alternatively, when the processor 90 executes the computer program 92, the functions of the modules / units in the above-mentioned device embodiments are realized, for example, Figure 8 Functions of modules 810 to 850 are shown.

[0170] The terminal device 9 can be a computing device such as a desktop computer, a notebook, a PDA, a cloud server, etc. The terminal device can include, but is not limited to, a processor 90 and a memory 91. It can be understood by those skilled in the art that Figure 9 It is only an example of the terminal device 9 and does not constitute a limitation on the terminal device 9. It may include more or fewer components than shown in the figure, or a combination of certain components, or different components. For example, the terminal device may also include an input and sending device, a network access device, a bus, etc.

[0171] The processor 90 may be a central processing unit (CPU), other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA), other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor.

[0172] In some embodiments, the memory 91 may be an internal storage unit of the terminal device 9, such as a hard drive or memory of the terminal device 9. The memory 91 may also be an external storage device of the terminal device 9, such as a plug-in hard drive, a Smart Media Card (SMC), a Secure Digital (SD) card, a flash memory card, etc. equipped on the terminal device 9. Furthermore, the memory 91 may include both an internal storage unit of the terminal device 9 and an external storage device. The memory 91 is used to store an operating system, application programs, a boot loader, data, and other programs, such as the program code of the computer program. The memory 91 may also be used to temporarily store data that has been sent or is about to be sent.

[0173] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.

[0174] An embodiment of the present application also provides a terminal device, which includes at least one memory, at least one processor, and a computer program stored in the at least one memory and executable on the at least one processor. When the processor executes the computer program, the terminal device implements the steps of any of the above-mentioned method embodiments.

[0175] An embodiment of the present application further provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps in the above-mentioned various method embodiments can be implemented.

[0176] An embodiment of the present application provides a computer program product. When the computer program product is run on a terminal device, the terminal device can implement the steps in the above-mentioned method embodiments when executing the computer program product.

[0177] If the integrated module / unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the present application can implement all or part of the processes in the above-mentioned embodiment method by instructing the relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, it can implement the steps of each of the above-mentioned method embodiments. The computer program includes computer program code, which can be in source code form, object code form, executable file or some intermediate form. The computer-readable medium can include: any entity or device that can carry the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signal, telecommunication signal and software distribution medium.

[0178] In the above embodiments, the description of each embodiment has its own focus. For parts that are not described or recorded in detail in a certain embodiment, reference can be made to the relevant description of other embodiments.

[0179] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0180] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0181] The above-described embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. These modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present application, and should all be included in the scope of protection of the present application.

Claims

1. A method for allocating defense resources for IoT devices, characterized in that: include: Obtain IoT device identification information, IoT device operating status information, IoT topology information, and communication characterization information between IoT devices; Calculate the importance characterization information of multiple devices and the interaction degree characterization information of multiple devices based on the IoT device identification information, IoT topology information, IoT device operation status information, and communication characterization information between IoT devices; Generate multiple initial IoT device defense resource allocation information and multiple device attack probability information; Calculate the attacker's net gain information and the defender's total loss information based on the initial IoT device defense resource allocation information, device attack probability information, device importance representation information, device interaction representation information, and preset device attack cost and defense cost information; Based on the multiple attacker net profit information and defender total loss information, the multiple initial IoT device defense resource allocation information is analyzed and calculated to determine the target IoT device defense resource allocation information.

2. The method for allocating defense resources for IoT devices according to claim 1, wherein: The step of calculating and obtaining multiple device importance representation information and multiple device interaction degree representation information based on the IoT device identification information, IoT topology information, IoT device operating status information, and communication representation information between IoT devices specifically includes: Calculate the importance representation information of multiple devices based on the IoT device identification information, IoT topology information, and communication representation information between IoT devices; Based on the IoT device identification information, IoT device operating status information, and communication characterization information between IoT devices, multiple device interaction degree characterization information is calculated.

3. The method for allocating defense resources for IoT devices according to claim 2, wherein: The communication characterization information between the IoT devices includes information on the number of communications between the IoT devices; The step of calculating and obtaining the plurality of device importance representation information based on the IoT device identification information, the IoT topology information, and the communication representation information between IoT devices specifically includes: According to the IoT device identification information and IoT topology information, obtaining a plurality of IoT topology communication path length information corresponding to each IoT device identification information; Determine the shortest topology communication path information between the IoT devices based on the length information of the multiple IoT topology communication paths corresponding to the IoT device identification information; Device importance characterization information is obtained based on the shortest topology communication path information between the IoT devices and the communication characterization information between the IoT devices.

4. The method for allocating defense resources for IoT devices according to claim 2, wherein: The IoT device operation status information includes the online duration information of the IoT device; The communication characterization information between the IoT devices includes communication duration information between the IoT devices; The step of calculating and obtaining the representation information of the degree of interaction of multiple devices based on the IoT device identification information, the IoT device operating status information, and the communication representation information between IoT devices specifically includes: Determine, based on the IoT device identification information, IoT device online duration information corresponding to each IoT device and communication duration information between IoT devices; Based on the online duration information of the IoT devices corresponding to the IoT devices and the communication duration information between the IoT devices, the representation information of the degree of interaction of multiple devices is calculated.

5. The method for allocating defense resources for IoT devices according to claim 1, wherein: The plurality of device interaction degree characterization information includes a plurality of device interaction degree characterization information mastered by attackers and a plurality of device interaction degree characterization information mastered by defenders; The step of calculating the attacker's net gain information and the defender's total loss information based on the defense resource allocation information of the initial IoT devices, the device attack probability information, the device importance representation information, the device interaction degree representation information, and the preset attack cost and defense cost information specifically includes: generating a local device interaction degree representation matrix based on the device interaction degree representation information obtained by the multiple attackers; Performing matrix decomposition processing on the local device interaction degree representation matrix according to a preset matrix decomposition loss calculation function to obtain a device representation feature matrix combination; Calculate the attacker's global device interaction degree representation matrix based on the device characterization feature matrix combination; Calculate the attacker's net benefit information based on the attacker's global device interaction degree representation matrix, multiple initial IoT device defense resource allocation information, device attack probability information, device importance representation information, and preset attack cost information; Calculating a defender's global device interaction degree representation matrix based on the device interaction degree representation information mastered by the multiple defenders; The defender's total loss information is calculated based on the attacker's global device interaction degree characterization matrix, the defender's global device interaction degree characterization matrix, multiple initial IoT device defense resource allocation information, device attack probability information, device importance characterization information, and preset defense cost information.

6. The method for allocating defense resources for IoT devices according to claim 5, wherein: The preset attack cost information includes preset intrusion attack cost information and preset lateral movement attack cost information; The device attack probability information includes the IoT device intrusion attack probability information and the IoT device lateral movement attack probability information; The step of calculating the attacker's net benefit information based on the attacker's global device interaction degree representation matrix, multiple initial IoT device defense resource allocation information, device attack probability information, device importance representation information, and preset attack cost information specifically includes: Calculate the attacker's intrusion benefit information based on the initial IoT device defense resource allocation information, IoT device intrusion attack probability information, and device importance representation information; Calculate the attacker's lateral movement benefit information based on the initial IoT device defense resource allocation information, the attacker's global device interaction degree representation matrix, and the IoT device's lateral movement attack probability information; The attacker's net profit information is calculated based on the preset attack cost information, the attacker's intrusion profit information, and the lateral movement profit information; The step of calculating the defender's total loss information based on the attacker's global device interaction degree representation matrix, the defender's global device interaction degree representation matrix, multiple initial IoT device defense resource allocation information, device attack probability information, device importance representation information, and preset defense cost information specifically includes: Calculate device intrusion defense loss information based on the initial IoT device defense resource allocation information, IoT device intrusion attack probability information, and device importance representation information; Calculate device defense lateral movement loss information based on the initial IoT device defense resource allocation information, the attacker's global device interaction degree representation matrix, IoT device lateral movement attack probability information, and device importance representation information; The defender's total loss information is calculated based on the preset defense cost information, the defender's global device interaction degree representation matrix, the device defense intrusion loss information, and the device defense lateral movement loss information.

7. The method for allocating defense resources for IoT devices according to claim 6, wherein: The step of analyzing and calculating the multiple initial IoT device defense resource allocation information based on the multiple attacker net gain information and the defender total loss information to determine the target IoT device defense resource allocation information specifically includes: Determining whether the maximum value of the attacker's net profit information is less than a preset attacker's net profit threshold information; If yes, return to the step of generating multiple initial IoT device defense resource allocation information and multiple device attack probability information; If not, then calculate the intruder attacker's loss information based on the initial IoT device defense resource allocation information corresponding to the maximum value of the attacker's net benefit information, the IoT device's probability of being attacked by intrusion, the IoT device's probability of being attacked by lateral movement, the device's importance representation information, and the preset intrusion attack cost information; Calculate the lateral attacker loss information based on the initial IoT device defense resource allocation information corresponding to the maximum value of the attacker's net benefit information, the device characterization feature matrix combination, the IoT device's probability of being attacked by lateral movement, and the preset lateral attack cost information; Calculating attacker loss information based on the intrusion attacker loss information and the lateral attacker loss information; The target IoT device defense resource allocation information is determined based on the attacker's loss information, the defender's total loss information, and the global device interaction degree representation matrix.

8. A device for allocating defense resources for an Internet of Things device, characterized in that: include: The IoT device information acquisition module is used to obtain IoT device identification information, IoT device operating status information, IoT topology information, and communication characterization information between IoT devices; a device importance representation information and device interaction degree representation information calculation module, configured to calculate a plurality of device importance representation information and a plurality of device interaction degree representation information based on the IoT device identification information, IoT topology information, IoT device operation status information, and communication representation information between IoT devices; An initial IoT device defense resource allocation information and device attack probability information generation module is used to generate multiple initial IoT device defense resource allocation information and multiple device attack probability information; An attacker's net gain information and defender's total loss information calculation module is configured to calculate the attacker's net gain information and defender's total loss information based on the initial IoT device defense resource allocation information, device attack probability information, device importance representation information, device interaction representation information, and preset device attack cost and defense cost information. The target IoT device defense resource allocation information determination module is used to analyze and calculate the multiple initial IoT device defense resource allocation information based on the multiple attacker net profit information and defender total loss information to determine the target IoT device defense resource allocation information.

9. A terminal device, characterized in that: The terminal device includes a memory and a processor, wherein the memory stores a computer program that can be run on the processor, and when the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.

10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.

Citation Information

Patent Citations

  • Active defense method based on joint or non-joint attack of multiple attackers

    CN117499158A

  • Defense method and system for integrated energy information physical system

    CN118487806A

  • Game-based optimal resource allocation method for cyber-physical power system (cpps) to defend against false data injection (fdi) attack

    GB202218851D0

Cited By

  • CPE bandwidth dynamic allocation method and system based on user behavior prediction

    CN121530854A