A method, apparatus and electrical distribution box for monitoring security protection

By detecting the access protocol and service type of monitoring equipment, calculating risk values, and taking corresponding measures, the problem that the security of monitoring equipment depends on strong password policies and terminal device security policies is solved, thereby improving the security and data protection of monitoring equipment without increasing energy consumption and cost.

CN115914551BActive Publication Date: 2026-07-31ZHEJIANG UNIVIEW TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
ZHEJIANG UNIVIEW TECH CO LTD
Filing Date
2021-08-20
Publication Date
2026-07-31

AI Technical Summary

Technical Problem

The security of existing surveillance camera equipment relies on strong password policies and terminal device security policies, which poses risks of password leakage and increases equipment performance consumption and costs.

Method used

By detecting the access protocol and monitoring service type of the monitoring equipment, calculating the risk value, and determining whether to issue an alarm or cut off the power based on the risk value, the security protection of the monitoring equipment is achieved, avoiding increased energy consumption and costs.

Benefits of technology

Without increasing energy consumption and cost, it improves the security of monitoring equipment, prevents hijacking, and protects the data security of the monitoring system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115914551B_ABST
    Figure CN115914551B_ABST
Patent Text Reader

Abstract

This application discloses a monitoring security protection method, device, and distribution box. The method includes: detecting whether the monitoring equipment is abnormal; when any of the monitoring equipment is abnormal, obtaining the access protocol type and monitoring service type of the abnormal monitoring equipment; obtaining the risk value of the abnormal monitoring equipment based on the access protocol type and / or the monitoring service type; and determining whether to issue an alarm based on the risk value. This embodiment improves the security of monitoring equipment, protects the data security of monitoring equipment, and prevents hijacked monitoring equipment from compromising the security of the entire monitoring system without requiring a password or increasing energy consumption or cost.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This article relates to monitoring technology, and more particularly to a monitoring security protection method, device and distribution box. Background Technology

[0002] As a carrier of "intelligent edge-end products" in the "cloud, edge, and terminal" system, the intelligent communication distribution box brings computing and storage to the data source, integrating power distribution, intelligent analysis, storage, data exchange, and communication. It is the central node of future smart streetlights. It can provide AC and DC power supply to the equipment and supports network access, making it widely applicable in smart cities, safe cities, intelligent transportation, and other fields.

[0003] With the continuous development of the internet, the security issues of video surveillance equipment have become increasingly prominent. We frequently see reports of community surveillance cameras being illegally hijacked, intersection surveillance checkpoints being illegally accessed, and industrial park surveillance cameras being illegally used to collect facial data. As the carrier of intelligent edge products, the power distribution box is used to connect surveillance cameras and other monitoring equipment. As the last line of defense for video surveillance equipment, it bears an undeniable responsibility for its security.

[0004] Currently, the security of surveillance camera equipment can only be protected through its own security mechanisms, such as strong passwords, terminal device security policies, and external security devices. These solutions have the following drawbacks:

[0005] 1. Strong password strategies can only ensure that devices are not easily cracked by brute force, but cannot guarantee against security risks caused by password leakage.

[0006] 2. Terminal device security policies, such as software firewalls, can increase device performance consumption and cause problems and troubles to normal device use.

[0007] 3. Adding other external security equipment will increase material costs and thus increase overall costs. Summary of the Invention

[0008] This application provides a monitoring security protection method, device, and power distribution box, which can improve the security of monitoring equipment, protect the data security of monitoring equipment, and prevent hijacked monitoring equipment from compromising the security of the entire monitoring system without requiring a password or increasing energy consumption and cost.

[0009] This application provides a monitoring security protection method applied to a video surveillance system. The system includes a video management server, a power distribution box, and one or more monitoring devices. The method may include:

[0010] Detect whether the monitoring equipment is malfunctioning;

[0011] When any of the monitoring devices is detected to be abnormal, the access protocol type and monitoring service type of the abnormal monitoring device are obtained; the access protocol type is the type of access protocol by which the monitoring device accesses the video management server.

[0012] The risk value of the monitoring device that malfunctions is obtained based on the access protocol type and / or the monitoring service type.

[0013] Whether to issue an alarm is determined based on the risk value.

[0014] In an exemplary embodiment of this application, detecting whether the monitoring device is malfunctioning may include:

[0015] The system detects whether the access information of the monitoring device when it accesses the video management server via the access protocol is consistent with the pre-registered information; if any one or more of the access information is inconsistent with the pre-registered information, the monitoring device is determined to be abnormal; the access information includes: the source MAC address, source IP address, destination MAC address, and destination IP address of the information packets exchanged during the information interaction process of the monitoring device accessing the video management server; and / or,

[0016] The system detects whether the execution information of the monitoring service of the video management server for the monitoring device is consistent with the historical execution information; when the execution information is inconsistent with the historical execution information, it determines that the monitoring device has malfunctioned; the execution information includes: the request duration and duration of the monitoring service request and / or the IP address of the media stream received.

[0017] In an exemplary embodiment of this application, obtaining the risk value of the monitoring device exhibiting an anomaly based on the access protocol type and / or the monitoring service type may include:

[0018] A first weight is assigned to different access protocols based on their risk parameters, and a second weight is assigned to different monitoring services based on their risk parameters; wherein, the risk parameters include any one or more of the following: frequency of attacks, number of attacks, and number of vulnerabilities;

[0019] The risk value of the monitoring device that has an anomaly is calculated based on the access protocol type and its corresponding first weight, and / or the monitoring service type and its corresponding second weight.

[0020] In an exemplary embodiment of this application, calculating the risk value of the monitoring device exhibiting an anomaly based on the access protocol type and its corresponding first weight, and / or the monitoring service type and its corresponding second weight, may include:

[0021] The first weight and the second weight are input into a preset risk calculation formula, and the calculation result of the risk calculation formula is used as the risk value.

[0022] The risk calculation formula may include:

[0023] V = Σn*W1*W2;

[0024] Where V is the risk value, n is the number of times the anomaly was detected, n is a positive integer, W1 is the first weight, W2 is the second weight; Σ represents summation.

[0025] In an exemplary embodiment of this application, the access protocol type may include: national standard, Open Network Video Interface Forum (ONVIF) protocol, proprietary protocol, or Hypertext Transfer Protocol (HTTP) protocol used for its own management;

[0026] The monitoring service types may include: live feed, playback, PTZ, patrol, service configuration, or system configuration.

[0027] In an exemplary embodiment of this application, determining whether to issue an alarm based on the risk value may include:

[0028] When the risk value meets the first risk value range, no action is taken;

[0029] An alarm is triggered when the risk value meets the second risk value range.

[0030] When the risk value meets the third risk value range, an alarm will be triggered and the network will be disconnected.

[0031] When the risk value meets the fourth risk value range, an alarm is triggered and power is cut off;

[0032] Wherein, any risk value within the first risk value range is less than any risk value within the second risk value range; any risk value within the second risk value range is less than any risk value within the third risk value range; and any risk value within the third risk value range is less than any risk value within the fourth risk value range.

[0033] In an exemplary embodiment of this application, the method further includes:

[0034] Upon detecting a preset intervention or a power outage of the distribution box, the abnormal status of the corresponding monitoring equipment is restored, and the risk value corresponding to the monitoring equipment is reset to zero; and / or,

[0035] After issuing an alarm and controlling the power distribution box to shut down, if no preset intervention is detected, the network and power supply of the corresponding monitoring equipment will be restarted after a preset power outage duration.

[0036] In an exemplary embodiment of this application, the method further includes configuring the power outage duration according to the following power outage duration configuration calculation formula:

[0037] T = 5 + (m - 1) * 2;

[0038] Where T is the power outage duration, m is the number of power outages without the preset intervention, and m is a positive integer.

[0039] This application embodiment also provides a monitoring security protection device applied to the power distribution box of a video surveillance system. The video surveillance system may further include a video management server and one or more monitoring devices. The monitoring security protection device may include:

[0040] An anomaly detection module is configured to detect whether the monitoring device is malfunctioning.

[0041] The type acquisition module is configured to acquire the access protocol type and monitoring service type of any of the monitoring devices when an anomaly is detected; the access protocol type is the access protocol type by which the monitoring device accesses the video management server.

[0042] The risk value acquisition module obtains the risk value of the monitoring device that has an anomaly based on the access protocol type and / or the monitoring service type.

[0043] The alarm module is configured to determine whether to issue an alarm based on the risk value.

[0044] In an exemplary embodiment of this application, the anomaly detection module detecting whether the monitoring device is malfunctioning may include:

[0045] The system detects whether the access information of the monitoring device when it accesses the video management server via the access protocol is consistent with the pre-registered information; if any one or more of the access information is inconsistent with the pre-registered information, the monitoring device is determined to be abnormal; the access information includes: the source MAC address, source IP address, destination MAC address, and destination IP address of the monitoring device during information exchange when accessing the video management server; and / or,

[0046] The system detects whether the execution information of the monitoring service of the video management server for the monitoring device is consistent with the historical execution information; when the execution information is inconsistent with the historical execution information, it determines that the monitoring device is abnormal; the execution information includes: the request duration and duration of the monitoring service request and / or the IP address of the media stream reception. This application embodiment also provides a power distribution box, which may include a processor and a computer-readable storage medium, wherein the computer-readable storage medium stores instructions, and when the instructions are executed by the processor, the monitoring security protection method described above is implemented.

[0047] Compared with related technologies, the embodiments of this application may include: detecting whether a monitoring device is malfunctioning; when any monitoring device malfunctions, obtaining the access protocol type and monitoring service type of the malfunctioning monitoring device; the access protocol type being the type of access protocol by which the monitoring device accesses the video management server; obtaining a risk value of the malfunctioning monitoring device based on the access protocol type and / or the monitoring service type; and determining whether to issue an alarm based on the risk value. This embodiment improves the security of monitoring devices, protects their data security, and prevents hijacked monitoring devices from compromising the security of the entire monitoring system, without requiring a password or increasing energy consumption or cost.

[0048] Other features and advantages of this application will be set forth in the following description, and will be apparent in part from the description, or may be learned by practicing the application. Other advantages of this application can be realized and obtained by means of the solutions described in the description and the accompanying drawings. Attached Figure Description

[0049] The accompanying drawings are used to provide an understanding of the technical solutions of this application and constitute a part of the specification. They are used together with the embodiments of this application to explain the technical solutions of this application and do not constitute a limitation on the technical solutions of this application.

[0050] Figure 1 This is a flowchart of a monitoring security protection method according to an embodiment of this application;

[0051] Figure 2 This is a schematic diagram of the connection structure of the distribution box according to an embodiment of this application;

[0052] Figure 3 This is a block diagram of the monitoring and security protection device according to an embodiment of this application;

[0053] Figure 4 This is a block diagram of the power distribution box according to an embodiment of this application. Detailed Implementation

[0054] This application describes several embodiments, but these descriptions are exemplary and not restrictive, and it will be apparent to those skilled in the art that many more embodiments and implementations are possible within the scope of the embodiments described herein. Although many possible combinations of features are shown in the drawings and discussed in the detailed description, many other combinations of the disclosed features are also possible. Unless specifically limited, any feature or element of any embodiment may be used in combination with, or may replace, any feature or element of any other embodiment.

[0055] This application includes and contemplates combinations of features and elements known to those skilled in the art. The embodiments, features, and elements disclosed in this application may also be combined with any conventional features or elements to form a unique inventive scheme as defined by the claims. Any feature or element of any embodiment may also be combined with features or elements from other inventive schemes to form another unique inventive scheme as defined by the claims. Therefore, it should be understood that any feature shown and / or discussed in this application may be implemented individually or in any suitable combination. Therefore, the embodiments are not limited except by the limitations imposed by the appended claims and their equivalents. Furthermore, various modifications and changes may be made within the scope of the appended claims.

[0056] Furthermore, in describing representative embodiments, the specification may have presented methods and / or processes as a specific sequence of steps. However, the method or process should not be limited to the specific order of steps described herein, to the extent that it does not depend on such a specific order. As will be understood by those skilled in the art, other sequences of steps are also possible. Therefore, the specific order of steps set forth in the specification should not be construed as a limitation of the claims. Moreover, the claims concerning the method and / or process should not be limited to the steps performed in the written order, and those skilled in the art will readily understand that these orders can be varied and still remain within the spirit and scope of the embodiments of this application.

[0057] This application provides a monitoring security protection method applied to a video surveillance system. The system includes a video management server 3, a power distribution box 1, and one or more monitoring devices 2, such as... Figure 1 As shown, the method may include steps S101-S104:

[0058] S101. Detect whether the monitoring device 2 is malfunctioning;

[0059] S102. When any of the monitoring devices 2 is detected to be abnormal, the access protocol type and monitoring service type of the abnormal monitoring device 2 are obtained.

[0060] S103. Obtain the risk value of the monitoring device 2 that has an anomaly based on the access protocol type and / or the monitoring service type;

[0061] S104. Determine whether to issue an alarm based on the risk value.

[0062] In an exemplary embodiment of this application, the solution provides a security measure for monitoring equipment (such as cameras) based on a power distribution box. By monitoring the monitoring services of various monitoring devices 2 connected to the power distribution box 1, it is ensured that when suspicious operations occur on the monitoring devices, corresponding countermeasures can be taken through the power distribution box (e.g., controlling the monitoring devices' access to the network and power supply), thereby ensuring the security of the monitoring devices and preventing further contamination of the monitoring system by the monitoring devices, which could lead to risks such as data leakage.

[0063] In exemplary embodiments of this application, for example, by intelligently identifying the real-time, playback, pan-tilt, and patrol monitoring services of the monitoring device 2 connected to the distribution box 1, and by combining historical operating habits and operation records, it is possible to more accurately determine whether the monitoring device 2 has been hijacked. Furthermore, by strategically controlling the access to the network and power supply based on the level of security risk assessment, the security control of the monitoring device 2 can be made more refined and user-friendly.

[0064] In an exemplary embodiment of this application, the distribution box 1 serves as a carrier for intelligent terminal products and can be used to provide network and power access functions. Common application scenarios for the distribution box 1 include... Figure 2 As shown, the dashed lines represent network data flow, and the solid lines represent power flow. The distribution box connects to the power supply and network, and then provides network and power access capabilities to the monitoring equipment 2 connected to the distribution box 1.

[0065] In an exemplary embodiment of this application, the distribution box 1 can be fixed to a pole such as a light pole using clamps. The monitoring device 2 is supplied with network and power interfaces through the distribution box 1. The distribution box 1 can connect to the background video management server 3 via the network according to a preset access protocol. The video management server 3 manages and controls the monitoring device 2, and can perform business operations such as live streaming, playback, and pan / tilt / zoom on the monitoring device 2. Since the data exchange between the video management server 3 and the monitoring device 2 must pass through the distribution box, the distribution box 1 can provide bidirectional protection for both the monitoring device 2 and the monitoring system.

[0066] In an exemplary embodiment of this application, during the implementation phase of the distribution box 1, the security services of the distribution box 1 can be configured to ensure that the security and performance of the distribution box 1 reach the optimal state. For example, the access protocol of the monitoring device 2 connected to the distribution box to the access management platform (such as the video management server 3 mentioned above) and the monitoring services that need to be protected can be configured to ensure that the function of the distribution box is maximized.

[0067] In an exemplary embodiment of this application, the access protocol type may include: national standard, ONVIF protocol, proprietary protocol, or HTTP protocol used for its own management;

[0068] The monitoring service types may include: live feed, playback, PTZ, patrol, service configuration, or system configuration.

[0069] In an exemplary embodiment of this application, the access protocol type for the monitoring device 2 to access the management platform may include, but is not limited to, national standards, ONVIF (Open Network Video Interface Forum) protocol, proprietary protocols, and HTTP (Hypertext Transfer Protocol) protocol used for its own management. The access protocols listed in the embodiments of this application are merely examples, and more protocol types can be added in combination with the development of the monitoring industry. For example, they may include, but are not limited to, RTSP (Real-Time Streaming Protocol), RTP (Real-Time Transport Protocol), SIP (Signaling Control Protocol), SNMP (Simple Network Management Protocol), etc. The monitoring service types that need protection may include, but are not limited to, the following key services: live monitoring, playback, PTZ (pan-tilt-zoom), patrol, service configuration, system configuration, etc.

[0070] In an exemplary embodiment of this application, obtaining the risk value of the monitoring device exhibiting an anomaly based on the access protocol type and / or the monitoring service type may include:

[0071] The first weight W1 is set for different access protocols based on the risk parameters of different access protocols, and the second weight W2 is set for different monitoring services based on the risk parameters of different monitoring services; wherein, the risk parameters may include, but are not limited to, any one or more of the following: frequency of attacks, number of attacks, and number of vulnerabilities;

[0072] The risk value of the monitoring device that has an anomaly is calculated based on the access protocol type and its corresponding first weight, and / or the monitoring service type and its corresponding second weight.

[0073] In the exemplary embodiments of this application, the weight configuration for access protocols and monitoring services can be based on the frequency, number of attacks, and number of vulnerabilities of each access protocol and monitoring service published by the security vendor. Different weights can be assigned to different monitoring services and different access protocols, allowing for reasonable and effective configuration according to the actual application scenario.

[0074] In the exemplary embodiments of this application, based on the actual network topology, the following are examples of risk weights (i.e., first weight W1) for different access protocols and risk weights (i.e., second weight W2) for different monitoring services. Table 1 shows the risk weight examples for different access protocols, and Table 2 shows the risk weight examples for different monitoring services.

[0075] Table 1

[0076] Access Protocol Weight W1 ONVIF 0.8 National Standard 0.5 Private Protocol 0.2 HTTP 0.7

[0077] Table 2

[0078] Monitoring services Weight W2 Live 0.8 Replay 0.7 gimbal 0.6 cruise 0.3 Business Configuration 0.5 System Configuration 0.4

[0079] In an exemplary embodiment of this application, calculating the risk value of the monitoring device exhibiting an anomaly based on the access protocol type and its corresponding first weight W1, and / or the monitoring service type and its corresponding second weight W2, may include:

[0080] The first weight W1 and the second weight W2 are input into a preset risk calculation formula, and the calculation result of the risk calculation formula is used as the risk value.

[0081] In an exemplary embodiment of this application, the risk calculation formula may include, but is not limited to:

[0082] V = Σn*W1*W2;

[0083] Where V is the risk value, n is the number of times the anomaly was detected, n is a positive integer, W1 is the first weight, W2 is the second weight; Σ represents summation.

[0084] In an exemplary embodiment of this application, n represents the sequence number of the detected anomaly; W1 represents the weight of the access protocol when the anomaly is detected; W2 represents the weight of the monitoring service when the anomaly is detected; Σ represents the sum of the results of the number of detected anomalies to obtain the final risk value V.

[0085] In an exemplary embodiment of this application, the response strategy may include, but is not limited to: taking no action (which may be referred to as "none"), issuing an alarm, issuing an alarm and disconnecting the network, and issuing an alarm and disconnecting the power.

[0086] In an exemplary embodiment of this application, determining whether to issue an alarm based on the risk value may include:

[0087] When the risk value meets the first risk value range, no action is taken;

[0088] An alarm is triggered when the risk value meets the second risk value range.

[0089] When the risk value meets the third risk value range, an alarm will be triggered and the network will be disconnected.

[0090] When the risk value meets the fourth risk value range, an alarm is triggered and power is cut off;

[0091] Wherein, any risk value within the first risk value range is less than any risk value within the second risk value range; any risk value within the second risk value range is less than any risk value within the third risk value range; and any risk value within the third risk value range is less than any risk value within the fourth risk value range.

[0092] In the exemplary embodiments of this application, the specific values ​​of the first risk value range, the second risk value range, the third risk value range, and the fourth risk value range are not limited, and can be defined according to different application scenarios.

[0093] In the exemplary embodiments of this application, as shown in Table 3, specific embodiments of the first risk value range, the second risk value range, the third risk value range, and the fourth risk value range are given, as well as embodiments of the corresponding response strategies for different risk value ranges.

[0094] Table 3

[0095] Response strategies Risk Value V none 0<V≤5 Alarm 5<V≤10 Alarm + Internet Disconnection 10<V≤15 Alarm + Power Outage 15<V

[0096] In the exemplary embodiments of this application, a specific embodiment of the scheme of this application is given below.

[0097] In an exemplary embodiment of this application, as shown in Table 4, there is an example of an anomaly detection situation of a certain monitoring device 2.

[0098] Table 4

[0099] Abnormal situation number n Access Protocol Monitoring services The first anomaly detected National Standard Live The second anomaly was detected HTTP System Configuration The third anomaly was detected. National Standard cruise The fourth anomaly was detected. HTTP Business Configuration The fifth anomaly detected ONVIF gimbal

[0100] In an exemplary embodiment of this application, for the embodiment in Table 4, the risk value can be calculated using the risk calculation formula described above, by combining the weight values ​​in Tables 1 and 2:

[0101] V 五=0.5*0.8+2*0.7*0.4+3*0.5*0.3+4*0.7*0.4+5*0.8*0.6=4.93;

[0102] At this point, the risk value is less than 5. Therefore, according to the response strategy in Table 3, no action needs to be taken.

[0103] In an exemplary embodiment of this application, when the sixth anomaly is detected, as shown in Table 5, this is an example of the sixth anomaly detection situation of the monitoring device, and the risk value V at this time is... 六 =V 五 +6*0.7*0.7=7.87, at this point the risk value V 六 If the value is greater than 5 and less than 10, the distribution box can notify the user or the video management platform to issue an alarm notification that the current monitoring equipment has an abnormal situation, as well as a list of each abnormal situation.

[0104] Table 5

[0105] The sixth anomaly detected HTTP System Configuration

[0106] In an exemplary embodiment of this application, when the user does not intervene and the distribution box continues to detect the seventh anomaly, as shown in Table 6, which illustrates the sixth anomaly detection scenario of the monitoring device, the risk value V at this time is... 七 =V 六 +7*0.8*0.6=11.23, at this point the risk value V 七 If the value is greater than 10 and less than 15, the distribution box can send alarm notifications of abnormal situations of the current monitoring equipment, as well as detailed information of each abnormal situation, to the user or video management platform, and disconnect the network where the monitoring equipment is located.

[0107] Table 6

[0108] The seventh anomaly detected ONVIF Replay

[0109] In an exemplary embodiment of this application, the method may further include:

[0110] Upon detecting a preset intervention or a power outage of the distribution box, the abnormal status of the corresponding monitoring equipment is restored, and the risk value corresponding to the monitoring equipment is reset to zero; and / or,

[0111] After issuing an alarm and controlling the power distribution box to shut down, if no preset intervention is detected, the network and power supply of the corresponding monitoring equipment will be restarted after a preset power outage duration.

[0112] In an exemplary embodiment of this application, when an anomaly is detected for the seventh time and the user still does not intervene, and the distribution box continues to detect anomalies, a corresponding response strategy can be executed based on the calculated risk value until the user intervenes (i.e., a preset intervention is executed) or the distribution box performs a power-off operation. After the user intervenes or the distribution box performs a power-off operation, the distribution box can restore the abnormal situation corresponding to the monitoring device and reset the risk value to 0.

[0113] In an exemplary embodiment of this application, the distribution box can determine which monitoring device it is based on the MAC address (physical address) of the monitoring device connected to each network port. The MAC address is used as a unique identifier to identify the monitoring device, and the risk value can be calculated on a per-monitoring-device basis.

[0114] In an exemplary embodiment of this application, when a user intervenes, for example, when the user confirms an alarm, the power distribution box can be notified. At this time, the power distribution box resets the risk value of the corresponding monitoring device and restores the network and power input of the monitoring device. If the user does not intervene, the power distribution box can restart the network and power of the corresponding camera device after a period of power outage.

[0115] In an exemplary embodiment of this application, the method further includes configuring the power outage duration according to the following power outage duration configuration formula:

[0116] T = 5 + (m - 1) * 2;

[0117] Where T is the power outage duration, m is the number of power outages without the preset intervention, and m is a positive integer.

[0118] In an exemplary embodiment of this application, the distribution box can be configured with the power outage duration, for example, an initial power outage of 5 minutes. T = 5 + (m-1)*2, in minutes. Where m represents the number of power outages without user intervention; T1 = 5 minutes (m = 1), T2 = 5 + (2-1)*2 = 7 minutes (m = 2), and so on. If the user intervenes, m restarts from 1.

[0119] In an exemplary embodiment of this application, detecting whether each monitoring device connected to the distribution box is malfunctioning may include:

[0120] The system detects whether the access information of the monitoring device when it accesses the video management server via the access protocol is consistent with the pre-registered information; if any one or more of the access information is inconsistent with the pre-registered information, the monitoring device is determined to be abnormal; the access information includes: the source MAC address, source IP address, destination MAC address, and destination IP address of the information packets exchanged by the monitoring device during its access to the video management server; and / or,

[0121] The system detects whether the execution information of the monitoring service of the video management server for the monitoring device is consistent with the historical execution information; when the execution information is inconsistent with the historical execution information, it determines that the monitoring device has malfunctioned; the execution information includes: the request duration and duration of the monitoring service request and / or the IP address of the media stream received.

[0122] In the exemplary embodiments of this application, the following example illustrates how to determine whether a monitoring device is malfunctioning, using the method of determining whether the real-time monitoring service of a monitoring device accessed via a national standard protocol is abnormal. The methods for other access protocols and monitoring services are similar:

[0123] When monitoring equipment connects to the video management server via the national standard protocol, the source MAC address and source IP address (Internet Protocol address) of the registration message are recorded.

[0124] The video management server records the request time, duration, and IP address of each live service request from the monitoring equipment. Other services can record relevant information based on the actual situation.

[0125] The server address of the monitoring device's live service request is consistent with the registered server IP address. That is, whether the source MAC address, source IP address, destination MAC address, and destination IP address of the live service request message are consistent with the address recorded during registration. If they are inconsistent, the live service is considered to be at risk.

[0126] The system tracks the request time, duration, and IP address of the media stream received when requesting a live monitoring service. If the request time, duration, and IP address of the media stream received in a particular live monitoring request are significantly different from historical statistical data (i.e., historical execution information), then the live monitoring service is considered to be at risk.

[0127] In the exemplary embodiments of this application, as historical statistical data is continuously collected, analyzed, and updated, the accuracy of the analysis and judgment will increase, thus making the determination of the possibility of anomalies in the monitoring business more accurate. The weighting of each influencing factor in the specific real-time business can be configured as needed according to actual circumstances, and the calculated weights can be used to determine whether an anomaly has occurred. The threshold for anomalies can be reasonably configured according to actual circumstances.

[0128] In the exemplary embodiments of this application, similar schemes can be used for judgment in monitoring services such as playback and PTZ. For example, frequent PTZ operation commands, abnormal patrol trajectories, etc. The factors for judging abnormalities are not exactly the same for different monitoring services. For example, the PTZ service can judge abnormalities based on the frequency of command operations, the risk of different commands, etc., which will not be elaborated on in this embodiment.

[0129] In the exemplary embodiments of this application, the security of each monitoring device under the distribution box, as well as the security of the entire monitoring system, can be effectively protected. This embodiment does not limit the type of device connected to the distribution box; only a corresponding anomaly detection method is required.

[0130] This application embodiment also provides a monitoring security protection device 2, applied to the power distribution box of a video surveillance system. The video surveillance system may further include a video management server and one or more monitoring devices, such as... Figure 3 As shown, the monitoring and security protection device 2 may include:

[0131] Anomaly detection module 21 is configured to detect whether the monitoring device is malfunctioning;

[0132] The type acquisition module 22 is configured to acquire the access protocol type and monitoring service type of any of the monitoring devices when an anomaly is detected; the access protocol type is the access protocol type by which the monitoring device accesses the video management server.

[0133] The risk value acquisition module 23 obtains the risk value of the monitoring device that has an anomaly based on the access protocol type and / or the monitoring service type.

[0134] The alarm module 24 is configured to determine whether to issue an alarm based on the risk value.

[0135] In an exemplary embodiment of this application, the anomaly detection module 21 detects whether the monitoring device has an anomaly, which may include:

[0136] The system detects whether the access information of the monitoring device when it accesses the video management server via the access protocol is consistent with the pre-registered information; if any one or more of the access information is inconsistent with the pre-registered information, the monitoring device is determined to be abnormal; the access information includes: the source MAC address, source IP address, destination MAC address, and destination IP address of the monitoring device during information exchange when accessing the video management server; and / or,

[0137] The system detects whether the execution information of the monitoring service of the video management server for the monitoring device is consistent with the historical execution information; when the execution information is inconsistent with the historical execution information, it determines that the monitoring device has malfunctioned; the execution information includes: the request duration and duration of the monitoring service request and / or the IP address of the media stream received.

[0138] In an exemplary embodiment of this application, the risk value acquisition module 23 obtains the risk value of the monitoring device that has malfunctioned based on the access protocol type and / or the monitoring service type, which may include:

[0139] The first weight is set for different access protocols based on the risk parameters of different access protocols, and the second weight is set for different monitoring services based on the risk parameters of different monitoring services; wherein, the risk parameters include any one or more of the following: frequency of attacks, number of attacks, and number of vulnerabilities;

[0140] The risk value of the monitoring device that has an anomaly is calculated based on the access protocol type and its corresponding first weight, and / or the monitoring service type and its corresponding second weight.

[0141] In an exemplary embodiment of this application, the risk value acquisition module 23 calculates the risk value of the monitoring device that has malfunctioned based on the access protocol type and its corresponding first weight, and / or the monitoring service type and its corresponding second weight, which may include:

[0142] The first weight and the second weight are input into a preset risk calculation formula, and the calculation result of the risk calculation formula is used as the risk value.

[0143] In an exemplary embodiment of this application, the risk calculation formula may include:

[0144] V = Σn*W1*W2;

[0145] Where V is the risk value, n is the number of times the anomaly was detected, n is a positive integer, W1 is the first weight, W2 is the second weight; Σ represents summation.

[0146] In an exemplary embodiment of this application, the alarm module 24 may determine whether to issue an alarm based on the risk value, and may include:

[0147] When the risk value meets the first risk value range, no action is taken;

[0148] An alarm is triggered when the risk value meets the second risk value range.

[0149] When the risk value meets the third risk value range, an alarm will be triggered and the network will be disconnected.

[0150] When the risk value meets the fourth risk value range, an alarm is triggered and power is cut off;

[0151] Wherein, any risk value within the first risk value range is less than any risk value within the second risk value range; any risk value within the second risk value range is less than any risk value within the third risk value range; and any risk value within the third risk value range is less than any risk value within the fourth risk value range.

[0152] In an exemplary embodiment of this application, the device may further include a recovery module 25; the recovery module 25 is configured as follows:

[0153] Upon detecting a preset intervention or a power outage of the distribution box, the abnormal status of the corresponding monitoring equipment is restored, and the risk value corresponding to the monitoring equipment is reset to zero; and / or,

[0154] After implementing the response strategy and controlling the power distribution box to shut down, if no preset intervention is detected, the network and power supply of the corresponding monitoring equipment will be restarted after a preset power outage duration.

[0155] In an exemplary embodiment of this application, the device may further include a calculation module 26; the calculation module 26 may be configured to configure the power outage duration according to the following power outage duration configuration formula:

[0156] T = 5 + (m - 1) * 2;

[0157] Where T is the power outage duration, m is the number of power outages without the preset intervention, and m is a positive integer.

[0158] In the exemplary embodiments of this application, any of the embodiments in the above method embodiments are applicable to the device embodiments, and will not be described in detail here.

[0159] This application embodiment also provides a distribution box 1, such as Figure 4 As shown, it may include a processor 11 and a computer-readable storage medium 12, wherein the computer-readable storage medium 12 stores instructions, and when the instructions are executed by the processor 11, the monitoring security protection method described above is implemented.

[0160] In the exemplary embodiments of this application, any of the embodiments in the above method embodiments are applicable to the distribution box embodiment, and will not be described in detail here.

[0161] It will be understood by those skilled in the art that all or some of the steps, systems, or apparatuses disclosed above, and their functional modules / units, can be implemented as software, firmware, hardware, or suitable combinations thereof. In hardware implementations, the division between functional modules / units mentioned above does not necessarily correspond to the division of physical components; for example, a physical component may have multiple functions, or a function or step may be performed collaboratively by several physical components. Some or all components may be implemented as software executed by a processor, such as a digital signal processor or microprocessor, or as hardware, or as an integrated circuit, such as an application-specific integrated circuit (ASIC). Such software may be distributed on a computer-readable medium, which may include computer storage media (or non-transitory media) and communication media (or transient media). As is known to those skilled in the art, the term computer storage media includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information (such as computer-readable instructions, data structures, program modules, or other data). Computer storage media include, but are not limited to, RAM, ROM, EEPROM, flash memory or other memory technologies, CD-ROM, digital versatile disc (DVD) or other optical disc storage, magnetic cartridges, magnetic tape, disk storage or other magnetic storage devices, or any other medium that can be used to store desired information and can be accessed by a computer. Furthermore, it is well known to those skilled in the art that communication media typically contain computer-readable instructions, data structures, program modules, or other data in modulated data signals such as carrier waves or other transmission mechanisms, and may include any information delivery medium.

Claims

1. A method of monitoring a security shield, characterized by, Applied to a video surveillance system, the system including a video management server, a power distribution box, and one or more monitoring devices, the method includes: Detect whether the monitoring equipment is malfunctioning; When any of the monitoring devices is detected to be abnormal, the access protocol type and monitoring service type of the abnormal monitoring device are obtained; the access protocol type is the type of access protocol by which the monitoring device accesses the video management server; The risk value of the monitoring device that malfunctions is obtained based on the access protocol type and / or the monitoring service type. Determine whether to issue an alarm based on the risk value; The detection of whether the monitoring equipment is malfunctioning includes: The system detects whether the access information of the monitoring device when it accesses the video management server via the access protocol is consistent with the pre-registered information; if any one or more of the access information is inconsistent with the pre-registered information, the monitoring device is determined to be abnormal; the access information includes: the source MAC address, source IP address, destination MAC address, and destination IP address of the information packets exchanged during the information interaction process of the monitoring device accessing the video management server; and / or, The system detects whether the execution information of the monitoring service of the video management server for the monitoring device is consistent with the historical execution information; when the execution information is inconsistent with the historical execution information, it determines that the monitoring device has malfunctioned; the execution information includes: the request duration, duration and / or IP address of the media stream received by the monitoring service request; The step of obtaining the risk value of the monitoring device that has malfunctioned based on the access protocol type and / or the monitoring service type includes: A first weight is assigned to different access protocols based on their risk parameters, and a second weight is assigned to different monitoring services based on their risk parameters; wherein, the risk parameters include any one or more of the following: frequency of attacks, number of attacks, and number of vulnerabilities; The risk value of the monitoring device that has an anomaly is calculated based on the access protocol type and its corresponding first weight, and / or the monitoring service type and its corresponding second weight.

2. The method of claim 1, wherein, The step of calculating the risk value of the monitoring device that exhibited an anomaly based on the access protocol type and its corresponding first weight, and / or the monitoring service type and its corresponding second weight, includes: The first weight and the second weight are input into a preset risk calculation formula, and the calculation result of the risk calculation formula is used as the risk value. The risk calculation formula includes: V = Σn * W1*W2; Where V is the risk value, n is the number of times the anomaly was detected, n is a positive integer, W1 is the first weight, W2 is the second weight; Σ represents summation.

3. The monitoring and security protection method according to any one of claims 1-2, characterized in that, The access protocol types include: national standard, ONVIF protocol (Open Network Video Interface Forum), proprietary protocol, or HTTP protocol (Hypertext Transfer Protocol) used for its own management. The monitoring service types include: live, playback, PTZ, patrol, service configuration, or system configuration.

4. The method of claim 3, wherein, The step of determining whether to issue an alarm based on the risk value includes: When the risk value meets the first risk value range, no action is taken; An alarm is triggered when the risk value meets the second risk value range. When the risk value meets the third risk value range, an alarm will be triggered and the network will be disconnected. When the risk value meets the fourth risk value range, an alarm is triggered and power is cut off; Wherein, any risk value within the first risk value range is less than any risk value within the second risk value range; any risk value within the second risk value range is less than any risk value within the third risk value range; and any risk value within the third risk value range is less than any risk value within the fourth risk value range.

5. The method of claim 4, wherein, The method further includes: Upon detecting a preset intervention or a power outage of the distribution box, the abnormal status of the corresponding monitoring equipment is restored, and the risk value corresponding to the monitoring equipment is reset to zero; and / or, After issuing an alarm and controlling the power distribution box to shut down, if no preset intervention is detected, the network and power supply of the corresponding monitoring equipment will be restarted after a preset power outage duration.

6. A security monitoring device, characterized by A power distribution box used in a video surveillance system, the video surveillance system also including a video management server and one or more monitoring devices, the monitoring security protection device including: Anomaly detection module is configured to detect whether the monitoring device is malfunctioning. The type acquisition module is configured to acquire the access protocol type and monitoring service type of any of the monitoring devices when an anomaly is detected; the access protocol type is the access protocol type by which the monitoring device accesses the video management server. The risk value acquisition module obtains the risk value of the monitoring device that has an anomaly based on the access protocol type and / or the monitoring service type. The alarm module is configured to determine whether to issue an alarm based on the risk value. The anomaly detection module detects whether the monitoring device is malfunctioning, including: The system detects whether the access information of the monitoring device when it accesses the video management server via the access protocol is consistent with the pre-registered information; if any one or more of the access information is inconsistent with the pre-registered information, the monitoring device is determined to be abnormal; the access information includes: the source MAC address, source IP address, destination MAC address, and destination IP address of the monitoring device during information exchange when accessing the video management server; and / or, The system detects whether the execution information of the monitoring service of the video management server for the monitoring device is consistent with the historical execution information; when the execution information is inconsistent with the historical execution information, it determines that the monitoring device has malfunctioned; the execution information includes: the request duration, duration and / or IP address of the media stream received by the monitoring service request; The step of obtaining the risk value of the monitoring device that has malfunctioned based on the access protocol type and / or the monitoring service type includes: A first weight is assigned to different access protocols based on their risk parameters, and a second weight is assigned to different monitoring services based on their risk parameters; wherein, the risk parameters include any one or more of the following: frequency of attacks, number of attacks, and number of vulnerabilities; The risk value of the monitoring device that has an anomaly is calculated based on the access protocol type and its corresponding first weight, and / or the monitoring service type and its corresponding second weight.

7. A distribution box characterized by The device includes a processor and a computer-readable storage medium, wherein the computer-readable storage medium stores instructions that, when executed by the processor, implement the monitoring and security protection method as described in any one of claims 1-5.