A Threat Defense Method and System for Power Internet of Things Access Terminals
By using a pre-trained trusted computing model to analyze the identity and network data of access terminals in the power Internet of Things (IoT), threats can be identified and defended against. This solves the problem of insufficient defense capabilities of access terminals in the existing power IoT technology and achieves more efficient threat identification and defense.
Patent Information
- Application Number
- CN202211702701.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-29
- Publication Date
- 2025-11-14
- Estimated Expiration
- 2042-12-29
AI Technical Summary
Existing technologies are insufficient in their ability to defend against threats to access terminals in the power Internet of Things (IoT), leading to unauthorized terminal intrusions that affect the normal operation of the power IoT. Furthermore, existing models are not effective in identifying new viruses or attack methods.
By identifying the identity fingerprint information, network trusted data, and extended data of the access terminal, a pre-trained trusted computing model is used to perform trusted computing analysis, generate behavioral analysis results, and execute corresponding security protection strategies.
It improves the sensitivity and accuracy of threat perception of power Internet of Things access terminals, enhances the defense capabilities of the access control system, and reduces the risk of unauthorized terminal intrusion.
Smart Images

Figure CN116232671B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of the Internet of Things (IoT) for power, and in particular to a threat defense method and system for IoT access terminals. Background Technology
[0002] In the power Internet of Things (IoT), terminals include at least dumb terminal devices such as cameras and voltage / current sensors used to monitor the operation of power equipment, as well as several power equipment terminals controlled by the power equipment command center. These dumb terminal devices connect to the network via wired or wireless connections, with IP addresses statically assigned by the administrator. The gateway is located at the aggregation layer, and the entire network adopts a routing structure. Currently, power IoT application devices and systems are relatively dispersed, mostly deployed locally and in independent networks. Furthermore, terminals in the power IoT may be connected to physical systems, such as distribution terminals connected to circuit breakers. If a hacker controls a distribution terminal, it means controlling the power dispatch system. This could lead to more serious situations, where terminals in the power IoT could be used as "botnets" to further infiltrate the power IoT, resulting in data leaks, loss of control over connected devices, and other serious consequences. Therefore, to protect the power IoT and ensure its normal operation and power supply, access control and monitoring of terminals connected to the power IoT are necessary to prevent malicious and unauthorized terminals from accessing the power IoT.
[0003] Current terminal intrusion behaviors mainly include threats such as abnormal network connections, brute-force password cracking, abnormal port opening, and the access of viruses and Trojans. When a new terminal device applies to access the power Internet of Things (IoT), trusted computing needs to be performed on the terminal device, and then behavioral analysis should be conducted on the accessing terminal device to prevent unauthorized or abnormal terminals from intruding into the power IoT and affecting its normal operation.
[0004] Existing main techniques for threatening terminal devices connected to the power Internet of Things (IoT) directly train models using raw data from the access terminals or historical data on access requests. The resulting models are inaccurate in their threat analysis, leading to poor control over access risk defense and increased risk of threats impacting the operation of the power IoT. Furthermore, relying on signature databases or virus databases for pattern matching of network traffic is ineffective against new viruses or attack methods. Summary of the Invention
[0005] This invention provides a threat defense method and system for power Internet of Things (IoT) access terminals, enabling the power IoT to perceive threatening access terminals, improving sensitivity and accuracy, and enhancing the defense capabilities of the access control system.
[0006] To address the aforementioned technical problems, embodiments of the present invention provide a threat defense method for power Internet of Things (IoT) access terminals, comprising:
[0007] Identify the current terminal device requesting access to the power Internet of Things and extract the current access data; wherein, the current access data includes current identity fingerprint information, current network trusted data and current extended data;
[0008] Based on the current access data, trusted computing analysis is performed on the current terminal device using a pre-trained trusted computing model to obtain the current behavior analysis results.
[0009] Based on the current behavior analysis results, identify the current threat type and implement the corresponding security protection strategy.
[0010] Implementing this embodiment of the invention involves identifying the current terminal device requesting access to the power Internet of Things (IoT) and extracting its current identity fingerprint information. Based on the current access data, a pre-trained trusted computing model is used to perform trusted computing analysis on the current terminal device to obtain the current behavior analysis results. The current access data includes the current identity fingerprint information, current network trusted data, and current extended data. Based on the current behavior analysis results, the current threat type is identified, and the corresponding security protection strategy is executed. In addition to basic identity fingerprint information and device characteristics, the terminal device fingerprint recognition adds network trusted data and extended data, employing a relatively unique trusted computing model to identify the behavior types of the terminal device. This improves the sensitivity and accuracy of the power IoT in perceiving threatening access terminals, enhances the accuracy of trusted computing in analyzing abnormal behavior, and improves the access control system's ability to defend against threats.
[0011] As a preferred option, a pre-trained reliable computing model is used, specifically:
[0012] The system acquires the identity fingerprint information and network trusted data of several terminal devices requesting access in the power Internet of Things (IoT). It preprocesses each identity fingerprint information and each network trusted data to obtain each extended data. It marks the behavior type of each terminal device according to each access data to obtain positive sample labels. It obtains positive sample information according to each access data and positive sample labels. The access data includes identity fingerprint information, network trusted data and extended data.
[0013] Based on the fingerprint information of each identity and the trusted data of each network, negative sample information is generated;
[0014] When positive and negative sample information meet preset conditions, the positive and negative sample information are divided into training and test sets according to a preset ratio. The trusted computing model is trained through the training set to predict the behavior analysis results, and the trusted computing model is verified through the test set to obtain the pre-trained trusted computing model. The behavior analysis results include the relationship between access data and behavior types, and the probability score of behavior types.
[0015] As a preferred approach, negative sample information is generated based on the fingerprint information of each identity and the trusted data of each network, specifically as follows:
[0016] Modify one piece of data from each identity fingerprint information or each network trusted data to generate negative sample identity fingerprint information and negative sample network trusted data.
[0017] The negative sample identity fingerprint information and negative sample network trusted data are preprocessed to obtain negative sample extended data. The behavior types of each terminal device are marked according to the negative sample access data to obtain negative sample tags. Negative sample information is obtained according to the negative sample access data and negative sample tags. The negative sample access data includes negative sample identity fingerprint information, negative sample network trusted data and negative sample extended data.
[0018] By implementing the embodiments of the present invention, the possibility of threats such as intrusion and data leakage occurring in daily operation is relatively small. The training set has a relatively small number of samples for various threat types. By creating negative sample data, the problem of insufficient negative samples during the training process of the trusted computing model is solved, which leads to inaccurate judgment of threat types by the trusted model and thus low sensitivity of the power Internet of Things to threat perception. This improves the accuracy of trusted computing in analyzing abnormal behavior and enhances the access control system's ability to defend against threats.
[0019] As a preferred approach, based on the current access data, a pre-trained trusted computing model is used to perform trusted computing analysis on the current terminal device to obtain the current behavior analysis results, specifically:
[0020] The current access data is input into a pre-trained trusted computing model, and trusted computing analysis is performed on the current terminal device through the pre-trained trusted computing model to output the current behavior analysis results.
[0021] The current behavior analysis results include the current behavior type and the probability score of the current behavior type. The current behavior type is one or more of the following: normal behavior, abnormal network connection, password brute-force attack, abnormal port opening, and virus / Trojan program implantation.
[0022] As a preferred solution, the current terminal device requesting access to the power Internet of Things is identified, and the current access data is extracted, specifically as follows:
[0023] Scan the current wireless network of the power Internet of Things (IoT) to discover the current terminal devices and send them to the group in the inventory file; scan to obtain the current device list of the power IoT, compare the current device list with the historical device list, and select the corresponding device terminal that exists in the current device list but does not exist in the historical device list as the current terminal device requesting access to the power IoT;
[0024] Extract the current identity fingerprint information of the current terminal device using a preset collection method;
[0025] Obtain trusted network data from the current terminal device; the trusted network data includes process information, resource traffic information, power data, and monitoring data.
[0026] The current identity fingerprint information and current trusted network data are preprocessed to obtain the current extended data.
[0027] As a preferred approach, the current identity fingerprint information and current trusted network data are preprocessed to obtain the current extended data, specifically:
[0028] The current identity fingerprint information and the related content in the current network trusted data are combined again to generate trusted feature data;
[0029] The system performs integrated calculations on the current trusted network data within a preset time period to generate integrated data.
[0030] The current identity fingerprint information and current trusted network data are compared with standard data in the standard library to generate comparison markers;
[0031] Trustworthy feature data, integrated data, and contrast markers are used as the current extended data.
[0032] Implementing this invention addresses the challenge of relying solely on single data points for device trust computing predictions, which can be hampered by data discreteness and spatiotemporal dispersion, making it difficult to detect device threats. By preprocessing the collected device data (identity fingerprint information and current network trust data), highly correlated device data is combined to generate new trust feature data, known as extended data. This generation of new trust feature data improves the accuracy of the pre-trained trust computing model in assessing threat risks related to identity trust, network trust, and environmental trust, thereby enhancing the defense capabilities of the access control system in the power IoT system. Furthermore, preprocessing various types of identity fingerprint information and network trust data improves the efficiency of the pre-trained trust computing model in perceiving threats in the power IoT and reduces the interference of large amounts of discrete data in threat assessment.
[0033] As a preferred approach, based on the current behavior analysis results, the current threat type is identified, and the corresponding security protection strategy is implemented, specifically:
[0034] Based on the current behavior analysis results, determine whether the current behavior of the terminal device poses a threat;
[0035] If there is no threat, switch the current terminal device's port to the normal VLAN and connect it to the power IoT intranet;
[0036] If a threat exists, the current threat type is identified based on the current behavior type, a security protection strategy is implemented based on the probability score corresponding to the current threat type, and a warning is issued indicating that the power Internet of Things has been illegally attacked.
[0037] As a preferred approach, a security protection strategy is implemented based on the probability score corresponding to the current threat type, and a warning is issued indicating that the power Internet of Things (IoT) is under attack. Specifically:
[0038] The probability score corresponding to the current threat type is compared with a preset score threshold. When the probability score of the current threat type is higher than the preset score threshold, the security protection strategy corresponding to the current threat type is executed, and a risk alert is sent to the power Internet of Things (IoT) management platform to indicate that there is a threat risk in the power IoT. The security protection strategy includes abnormal connection disconnection, brute-force attack locking, abnormal port closure, and abnormal program detection and removal. The risk alert includes the type of threat, the time of occurrence, the corresponding identity fingerprint information, and the location of the threat in the power IoT.
[0039] When the number of current threat types exceeds the preset threshold, a high threat alert is sent to the power IoT management platform to notify the administrator that a threat exists in the power IoT.
[0040] As a preferred option, before performing trusted computing analysis on the current terminal device based on the current access data and obtaining the current behavior analysis results through a pre-trained trusted computing model, the option further includes: switching the port of the current terminal device to an isolated VLAN.
[0041] To address the same technical problem, this invention also provides a threat defense system for a power Internet of Things access terminal, comprising: an identification module, an isolation module, an analysis module, and a defense module;
[0042] The identification module is used to identify the current terminal device requesting access to the power Internet of Things and extract the current access data; the current access data includes current identity fingerprint information, current network trusted data, and current extended data.
[0043] The isolation module is used to switch the port of the current terminal device to an isolated VLAN;
[0044] The analysis module is used to perform trusted computing analysis on the current terminal device based on the current access data and through a pre-trained trusted computing model to obtain the current behavior analysis results;
[0045] The defense module is used to identify the current threat type based on the current behavior analysis results and execute the corresponding security protection strategy for the current threat type. Attached Figure Description
[0046] Figure 1 : A flowchart illustrating an embodiment of a threat defense method for a power Internet of Things access terminal provided by the present invention;
[0047] Figure 2 : A diagram showing the information collected and the method of collecting data in one embodiment of a threat defense method for a power Internet of Things access terminal provided by the present invention;
[0048] Figure 3 This is a schematic diagram of an embodiment of a threat defense system for a power Internet of Things access terminal provided by the present invention. Detailed Implementation
[0049] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0050] Example 1
[0051] Please refer to Figure 1 This is a flowchart illustrating a threat defense method for a power Internet of Things (IoT) access terminal provided in an embodiment of the present invention. The threat defense method of this embodiment is applicable to access control and monitoring of terminals accessing the power IoT, preventing unauthorized terminals with threats from accessing the power IoT. This embodiment improves sensitivity and accuracy by sensing threatening access terminals through the power IoT, thereby enhancing the access control system's defense capabilities. The threat defense method includes steps 101 to 104, each step as follows:
[0052] Step 101: Identify the current terminal device requesting access to the power Internet of Things and extract the current access data; wherein, the current access data includes the current identity fingerprint information, the current network trusted data, and the current extended data.
[0053] Optionally, step 101 specifically includes steps 1011 to 1014, each step as follows:
[0054] Step 1011: Scan the current wireless network of the power IoT, discover the current terminal devices, and send the current terminal devices to the group in the inventory file; scan to obtain the current device list of the power IoT, compare the current device list with the historical device list, and select the corresponding device terminals that exist in the current device list but do not exist in the historical device list as the current terminal devices requesting access to the power IoT.
[0055] In this embodiment, before automatically identifying access terminals, the monitoring server of the power Internet of Things (IoT) is configured using an agentless automation tool. The current wireless network is scanned to discover access terminals (current terminal devices), and these terminals are added to a group in the inventory file. All access terminals in this group will be discovered by the monitoring server. The agentless automation tool is used to monitor new access terminals. To prevent SSH key verification, certain default functions in the agentless configuration file need to be disabled first to facilitate the collection of identity fingerprint information for new access terminals. The current device list is scanned and obtained. The current device list is compared with the historical device list, and the terminal devices that appear in the current device list but not in the historical device list are identified as the terminal devices requesting access to the power IoT.
[0056] Step 1012: Extract the current identity fingerprint information of the current terminal device using a preset acquisition method.
[0057] In this embodiment, the identity fingerprint information of the access terminal device (current terminal device) is collected, and the collected information and collection method are as follows: Figure 2 As shown, as an example, an agentless automation tool is used to connect all monitored objects and collect the identity fingerprint information of various devices in the network through APR and SNMP interfaces, including IP address, MAC address, device type, etc.
[0058] Step 1013: Obtain trusted network data of the current terminal device; wherein, trusted network data includes process information, resource traffic information, power data and monitoring data.
[0059] In this embodiment, trusted network data corresponding to the access terminal (current terminal device) is obtained, including: process information, resource traffic information, etc., power data (power equipment) or monitoring data (monitoring terminal) corresponding to the device. As an example of this embodiment, trusted data is stored in the node server of the blockchain and can be obtained from the node server.
[0060] Step 1014: Preprocess the current identity fingerprint information and the current trusted network data to obtain the current extended data.
[0061] Optionally, step 1014 specifically involves: recombining the current identity fingerprint information and the related content in the current network trusted data to generate trusted feature data; performing integrated calculations on the current network trusted data within a preset time period to generate integrated data; comparing the current identity fingerprint information and the current network trusted data with standard data in the standard library to generate comparison markers; and using the trusted feature data, integrated data, and comparison markers as current extended data.
[0062] It should be noted that relying solely on single data points for device trust computing predictions may lead to difficulties in detecting device threats due to data dispersion and spatiotemporal dispersion. Therefore, the collected device data is preprocessed, and highly correlated device data is combined to generate new trust feature data, i.e., extended data. By generating new trust feature data, the accuracy of the trust computing model in judging threat risks in identity trust, network trust, and environmental trust is improved, thereby enhancing the defense capabilities of the access control system in the power Internet of Things (IoT) system. Furthermore, by preprocessing various types of identity fingerprint information and network trust data, the efficiency of the trust computing model in perceiving threats in the power IoT can be improved, and the interference of a large amount of discrete data on threat judgment can be reduced.
[0063] In this embodiment, the current identity fingerprint information and current network trusted data are preprocessed to obtain current extended data. The current extended data may include various types of data, specifically: 1) Multiple pieces of network trusted data are combined again with highly correlated content from the identity fingerprint information to generate new trusted feature data for the access terminal, which serves as extended data. For example, banner information from SSH and server information from HTTP are combined, or firewall policies and current network traffic are combined, or process information and network traffic are combined to generate extended data. 2) Network trusted data within a certain time period is integrated and calculated to generate extended data, such as calculating the average network traffic within a preset time period or the number of connection requests within a preset time period. 3) Compare the identity fingerprint information and network trusted data of the access terminal (current terminal device) with the standard data in the standard library or the data in the VLAN network to be accessed, and generate a comparison mark as extended data. For example, the standard library specifies that non-camera devices should not open the HTTP port, while cameras should open the HTTP port. If an access terminal with a printer device type is detected to have an open HTTP port, which is inconsistent with the data in the standard library, then the comparison mark is set to 0 (inconsistent). If an access terminal with a printer device type is detected to not have an open HTTP port, which is consistent with the data in the standard library, then the comparison mark is set to 1 (consistent). For example, the standard library specifies that Windows systems generally open ports 135, 139, 445, etc., and printer terminals open port 215. If the monitored access terminal with a printer device type has port 445, it may be forged, which is inconsistent with the data in the standard library, then the comparison mark corresponding to this rule is set to 0 (inconsistent). Multiple comparison marks can be set according to actual requirements.
[0064] Step 102: Switch the port of the current terminal device to the isolated VLAN.
[0065] Step 103: Based on the current access data, perform trusted computing analysis on the current terminal device using a pre-trained trusted computing model to obtain the current behavior analysis results.
[0066] Optionally, a pre-trained trusted computing model is used, specifically: acquiring the identity fingerprint information and network trusted data of several terminal devices requesting access in the power Internet of Things; preprocessing each identity fingerprint information and each network trusted data to obtain each extended data; labeling the behavior type of each terminal device according to each access data to obtain positive sample labels; and obtaining positive sample information according to each access data and positive sample labels; wherein, the access data includes identity fingerprint information, network trusted data, and extended data;
[0067] Based on the fingerprint information of each identity and the trusted data of each network, negative sample information is generated;
[0068] When positive and negative sample information meet preset conditions, the positive and negative sample information are divided into training and test sets according to a preset ratio. The trusted computing model is trained through the training set to predict the behavior analysis results, and the trusted computing model is verified through the test set to obtain the pre-trained trusted computing model. The behavior analysis results include the relationship between access data and behavior types, and the probability score of behavior types.
[0069] In this embodiment, the identity fingerprint information and operation information corresponding to several terminal devices that have requested access in the power Internet of Things are obtained. Preprocessing is performed according to steps 1012-1014, and the devices are then labeled, i.e., the behavior types of the access terminals are marked. Since the possibility of threats such as intrusion and data leakage during daily operation is relatively small, the samples for each threat type in the training set are relatively small. Therefore, more negative samples need to be created. When the ratio of negative samples to positive samples reaches a certain threshold, the sample data is divided into a training set and a test set according to a certain ratio. The training set is used to train a trusted computing model, and the test set is used for verification, resulting in a trained trusted computing model. The trusted computing model can predict the relationship between variables (access data) and behavior types. The predicted variables are identity fingerprint information, operation information (network trusted data), extended information, and results (extended data). It can also obtain the probability score for the corresponding behavior type.
[0070] Optionally, negative sample information is generated based on each identity fingerprint information and each network trusted data, specifically as follows:
[0071] The negative sample identity fingerprint information and negative sample network trusted data are generated by modifying a certain data in each identity fingerprint information or each network trusted data; the negative sample identity fingerprint information and negative sample network trusted data are preprocessed to obtain negative sample extended data; the behavior type of each terminal device is marked according to the negative sample access data to obtain negative sample tags; and negative sample information is obtained according to the negative sample access data and negative sample tags; wherein, the negative sample access data includes negative sample identity fingerprint information, negative sample network trusted data and negative sample extended data.
[0072] In this embodiment, the identity fingerprint information and network trusted data in the positive sample are copied as negative samples. Then, a certain piece of data in the identity fingerprint information or network trusted data is modified to generate corresponding negative sample data, and the behavior type label is changed. For example, the open port data is reversed and a random value is added to create a new open port, and the behavior type is labeled as an abnormal port opening. Network traffic is multiplied by a random function to create new traffic data, and the behavior type is recorded as an abnormal network connection. Two sets of sample data are randomly swapped; that is, some network trusted data in one set of sample data remains unchanged, while some data interacts with the other set of sample data to generate negative sample data, and the behavior type is labeled as a virus / Trojan program implantation. When generating negative sample information, it is also necessary to preprocess the modified identity fingerprint information and network trusted data according to the method in step 1014 to generate extended data, which serves as the extended data for the negative samples.
[0073] Optionally, step 103 specifically involves: inputting the current access data into a pre-trained trusted computing model, performing trusted computing analysis on the current terminal device through the pre-trained trusted computing model, and outputting the current behavior analysis results; wherein, the current behavior analysis results include the current behavior type and the probability score of the current behavior type, and the current behavior type is one or more of the following: normal behavior, abnormal network connection, password brute-force attack, abnormal port opening, and virus / Trojan program implantation.
[0074] In this embodiment, the current access data includes current identity fingerprint information, current network trusted data, and current extended data. The corresponding identity fingerprint information, network trusted data, and extended data are selected, and the access terminal is analyzed using a pre-trained model. That is, the current terminal device is analyzed by trusted computing through a pre-trained trusted computing model to analyze the behavior types of the access terminal (current terminal device). The behavior types include normal behavior, abnormal network connection, password brute-force attack, abnormal port opening, and virus / Trojan program implantation, etc. After analysis, the current behavior type of the current terminal device may be one or more of various behavior types.
[0075] Step 104: Based on the current behavior analysis results, identify the current threat type and execute the corresponding security protection strategy.
[0076] Optionally, step 104 specifically involves: determining whether the behavior of the current terminal device poses a threat based on the current behavior analysis results; if no threat exists, switching the port of the current terminal device to a normal VLAN and connecting it to the internal network of the power IoT; if a threat exists, confirming the current threat type based on the current behavior type, implementing a security protection strategy based on the probability score corresponding to the current threat type, and alerting the power IoT that it has been illegally attacked.
[0077] In this embodiment, the behavior of the access terminal is determined based on the current behavior type of the analysis results to determine whether the behavior is abnormal, generating a behavior analysis result. For example, all behavior types other than normal behavior types are listed as threats. If the behavior analysis result of the access terminal device is normal, i.e., there is no threat, the terminal device's port is switched to a normal VLAN and connected to the intranet. The access terminal requesting access to the power IoT is successfully connected to the power IoT and added to the power IoT whitelist. The access terminal is then connected to the monitoring service of the agentless automation tool, i.e., the agentless automation tool's configuration file is enabled, allowing the agentless automation tool to verify SSH keys. Specifically, the server's IP address and SSH certificate are obtained, and SSH key verification is performed based on the IP address and SSH certificate. Once the verification is successful, the agentless automation tool and the access terminal are connected, enabling the access terminal to be connected to the power IoT. At this point, the new access terminal becomes a monitoring object of the power IoT, and the agentless automation tool can then monitor this access terminal. If the behavior analysis result of the connected terminal device is a threat, i.e., a threat exists, then the corresponding security protection strategy will be executed according to the corresponding behavior analysis result, and a danger alarm will be sent to alert staff that the current power Internet of Things may be under illegal attack.
[0078] Optionally, a security protection strategy can be implemented based on the probability score corresponding to the current threat type, and a warning can be issued that the power IoT has been illegally attacked. Specifically, the probability score corresponding to the current threat type is compared with a preset score threshold. When the probability score of the current threat type is higher than the preset score threshold, the security protection strategy corresponding to the current threat type is executed, and a risk alert is sent to the power IoT management platform, indicating that there is a threat risk to the power IoT. The security protection strategy includes abnormal connection disconnection, brute-force attack locking, abnormal port closure, and abnormal program detection and removal. The risk alert includes the type of threat, the time of occurrence, the corresponding identity fingerprint information, and the location of the threat in the power IoT. When the number of current threat types exceeds a preset threshold for the number of threat types, a high-threat alert is sent to the power IoT management platform to notify the administrator that there is a threat to the power IoT.
[0079] In this embodiment, the probability score corresponding to each threat type is obtained from the behavioral analysis results. The probability score of each threat type is compared with a preset score threshold. If the preset score of a certain threat type is higher than the preset score threshold, the corresponding security protection strategy is executed. The comparison between threat types and security protection strategies is shown in Table 1 below. For different threat types, their corresponding security protection strategies are executed: abnormal network connection corresponds to abnormal connection disconnection, brute-force password attack corresponds to brute-force attack lockout, abnormal port open corresponds to abnormal port closure, and virus / Trojan program implantation corresponds to abnormal program detection and removal.
[0080] Table 1 Threat Types and Security Protection Strategies
[0081] Threat types Security protection strategy Network connection error Abnormal connection disconnection Brute-force password cracking Brute-force lock Abnormal port open Abnormal port closed Virus and Trojan program implantation Abnormal program detection and removal
[0082] If the probability scores of multiple behavior types all exceed the corresponding score thresholds, then the security protection policies corresponding to those multiple behavior types will be executed.
[0083] While implementing security protection strategies, risk alerts are sent to the power Internet of Things (IoT) management platform to inform users of existing threats. The risk alerts include the type of threat, the time of occurrence, the corresponding identity fingerprint information, and the corresponding location of the threat in the power IoT.
[0084] If the number of threat types exceeds a preset threshold, a high-threat alert is sent to the power IoT management platform to promptly notify management personnel of the potential threat situation.
[0085] Implementing this embodiment of the invention involves identifying the current terminal device requesting access to the power Internet of Things (IoT) and extracting its current identity fingerprint information. Based on the current access data, a pre-trained trusted computing model is used to perform trusted computing analysis on the current terminal device to obtain the current behavior analysis results. The current access data includes the current identity fingerprint information, current network trusted data, and current extended data. Based on the current behavior analysis results, the current threat type is identified, and the corresponding security protection strategy is executed. In addition to basic identity fingerprint information and device characteristics, the terminal device fingerprint recognition adds network trusted data and extended data, employing a relatively unique trusted computing model to identify the behavior types of the terminal device. This improves the sensitivity and accuracy of the power IoT in perceiving threatening access terminals, enhances the accuracy of trusted computing in analyzing abnormal behavior, and improves the access control system's ability to defend against threats.
[0086] Example 2
[0087] Accordingly, see Figure 3 , Figure 3This is a schematic diagram of a second embodiment of a threat defense system for a power Internet of Things access terminal provided by the present invention. Figure 3 As shown, the threat defense system for the power Internet of Things access terminal includes an identification module 301, an isolation module 302, an analysis module 303, and a defense module 304.
[0088] The identification module 301 is used to identify the current terminal device requesting access to the power Internet of Things and extract the current access data; the current access data includes current identity fingerprint information, current network trusted data and current extended data;
[0089] Isolation module 302 is used to switch the port of the current terminal device to the isolated VLAN;
[0090] Analysis module 303 is used to perform trusted computing analysis on the current terminal device based on the current access data and through a pre-trained trusted computing model to obtain the current behavior analysis results;
[0091] Defense module 304 is used to identify the current threat type based on the current behavior analysis results and execute the security protection strategy corresponding to the current threat type.
[0092] This invention addresses the problems encountered during trusted computing model training, such as incomplete access information data and insufficient negative samples leading to inaccurate threat type identification and consequently low threat perception sensitivity in the power IoT. In addition to basic device characteristics, the device fingerprinting system employs a unique algorithm model (pre-trained trusted computing model) to improve the sensitivity and accuracy of the power IoT in detecting threatening access terminals, thereby enhancing the access control system's defense capabilities.
[0093] The specific embodiments described above further illustrate the purpose, technical solution, and beneficial effects of the present invention. It should be understood that the above descriptions are merely specific embodiments of the present invention and are not intended to limit the scope of protection of the present invention. In particular, it should be noted that any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention for those skilled in the art.
Claims
1. A threat defense method for power Internet of Things (IoT) access terminals, characterized in that, include: Identify the current terminal device requesting access to the power Internet of Things and extract the current access data; wherein, the current access data includes the current identity fingerprint information, current network trusted data, and current extended data; Based on the current access data, a trusted computing analysis is performed on the current terminal device using a pre-trained trusted computing model to obtain the current behavior analysis results. Based on the current behavior analysis results, the current threat type is identified, and the corresponding security protection strategy is executed. Specifically, the pre-trained reliable computing model is as follows: The system acquires the identity fingerprint information and network trusted data of several terminal devices requesting access in the power Internet of Things (IoT). It preprocesses each of the identity fingerprint information and network trusted data to obtain extended data. Based on each access data, it marks the behavior type of each terminal device to obtain a positive sample label. Based on each access data and the positive sample label, it obtains positive sample information. The access data includes the identity fingerprint information, the network trusted data, and the extended data. Based on the identity fingerprint information and the trusted network data, negative sample information is generated. When the positive sample information and the negative sample information meet the preset conditions, the positive sample information and the negative sample information are divided into a training set and a test set according to a preset ratio. A trusted computing model is trained through the training set to predict the behavior analysis results, and the trusted computing model is verified through the test set to obtain the pre-trained trusted computing model. The behavior analysis results include the relationship between the access data and the behavior type, and the probability score of the behavior type.
2. The threat defense method for power Internet of Things access terminals as described in claim 1, characterized in that, The step of generating negative sample information based on the identity fingerprint information and the trusted network data is as follows: By modifying one of the aforementioned identity fingerprint information or one of the aforementioned network trusted data, negative sample identity fingerprint information and negative sample network trusted data are generated. The negative sample identity fingerprint information and the negative sample network trusted data are preprocessed to obtain negative sample extended data. The behavior types of each terminal device are marked according to the negative sample access data to obtain negative sample tags. Negative sample information is obtained according to the negative sample access data and the negative sample tags. The negative sample access data includes the negative sample identity fingerprint information, the negative sample network trusted data and the negative sample extended data.
3. The threat defense method for power Internet of Things access terminals as described in claim 1, characterized in that, The step of performing trusted computing analysis on the current terminal device based on the current access data using a pre-trained trusted computing model to obtain the current behavior analysis result is as follows: The current access data is input into the pre-trained trusted computing model, and the current terminal device is subjected to trusted computing analysis through the pre-trained trusted computing model to output the current behavior analysis result. The current behavior analysis results include the current behavior type and the probability score of the current behavior type. The current behavior type is one or more of the following: normal behavior, abnormal network connection, password brute-force attack, abnormal port opening, and virus / Trojan program implantation.
4. The threat defense method for power Internet of Things access terminals as described in claim 1, characterized in that, The process of identifying the current terminal device requesting access to the power Internet of Things and extracting the current access data specifically involves: Scan the current wireless network of the power Internet of Things, discover the current terminal device, and send the current terminal device to the group of the inventory file; scan to obtain the current device list of the power Internet of Things, compare the current device list with the historical device list, and select the corresponding device terminal that exists in the current device list but does not exist in the historical device list as the current terminal device requesting access to the power Internet of Things; The current identity fingerprint information of the current terminal device is extracted using a preset acquisition method; Obtain trusted network data from the current terminal device; wherein, the trusted network data includes process information, resource traffic information, power data, and monitoring data; The current identity fingerprint information and the current network trusted data are preprocessed to obtain the current extended data.
5. The threat defense method for power Internet of Things access terminals as described in claim 4, characterized in that, The step of preprocessing the current identity fingerprint information and the current trusted network data to obtain the current extended data specifically involves: The current identity fingerprint information and the related content in the current network trusted data are combined again to generate trusted feature data; The current trusted network data within a preset time period is aggregated and calculated to generate aggregated data. The current identity fingerprint information and the current network trusted data are compared with standard data in the standard library to generate comparison markers; The trusted feature data, the integrated data, and the comparison markers are used as the current extended data.
6. The threat defense method for power Internet of Things access terminals as described in claim 3, characterized in that, Based on the current behavior analysis results, the current threat type is identified, and the corresponding security protection strategy is executed, specifically as follows: Based on the current behavior analysis results, determine whether the current behavior of the terminal device poses a threat; If there is no threat, the port of the current terminal device will be switched to a normal VLAN and connected to the internal network of the power Internet of Things; If a threat exists, the current threat type is identified based on the current behavior type, a security protection strategy is implemented based on the probability score corresponding to the current threat type, and the power Internet of Things is alerted that it has been illegally attacked.
7. The threat defense method for power Internet of Things access terminals as described in claim 6, characterized in that, The security protection strategy based on the probability score corresponding to the current threat type, and the notification that the power Internet of Things has been illegally attacked, specifically includes: The probability score corresponding to the current threat type is compared with a preset score threshold. When the probability score of the current threat type is higher than the preset score threshold, the security protection strategy corresponding to the current threat type is executed, and a risk alert is sent to the power Internet of Things (IoT) management platform to indicate that there is a threat risk in the power IoT. The security protection strategy includes abnormal connection disconnection, brute-force attack locking, abnormal port closure, and abnormal program detection and removal. The risk alert includes the type of threat, the time of occurrence, the corresponding identity fingerprint information, and the location of the threat in the power IoT. When the number of current threat types exceeds a preset threshold, a high-threat alert is sent to the power IoT management platform to notify the administrator that a threat currently exists in the power IoT.
8. The threat defense method for power Internet of Things access terminals as described in any one of claims 1-7, characterized in that, Before performing trusted computing analysis on the current terminal device based on the current access data and obtaining the current behavior analysis results through a pre-trained trusted computing model, the method further includes: switching the port of the current terminal device to an isolated VLAN.
9. A threat defense system for a power Internet of Things (IoT) access terminal, characterized in that, include: Identification module, isolation module, analysis module, and defense module; The identification module is used to identify the current terminal device requesting access to the power Internet of Things and extract the current access data; wherein the current access data includes the current identity fingerprint information, the current network trusted data, and the current extended data; The isolation module is used to switch the port of the current terminal device to the isolation VLAN; The analysis module is used to perform trusted computing analysis on the current terminal device based on the current access data using a pre-trained trusted computing model to obtain the current behavior analysis result. Specifically, the pre-trained trusted computing model involves: acquiring the identity fingerprint information and network trusted data of several terminal devices requesting access in the power Internet of Things; preprocessing each identity fingerprint information and each network trusted data to obtain extended data; labeling the behavior type of each terminal device according to each access data to obtain positive sample labels; and obtaining positive sample information based on each access data and the positive sample labels. The access data includes the identity fingerprint information, the network trusted data, and the extended data. Negative sample information is generated based on each identity fingerprint information and each network trusted data. When the positive sample information and the negative sample information meet preset conditions, the positive sample information and the negative sample information are divided into a training set and a test set according to a preset ratio. The trusted computing model is trained using the training set to predict the behavior analysis result, and the trusted computing model is verified using the test set to obtain the pre-trained trusted computing model. The behavior analysis result includes the relationship between the access data and the behavior type, and the probability score of the behavior type. The defense module is used to identify the current threat type based on the current behavior analysis results and execute the security protection strategy corresponding to the current threat type.
Citation Information
Patent Citations
Threat processing method and device, electronic equipment and computer readable storage medium
CN112671807A