A method for monitoring secure access to Internet of Things servers

By using multi-source data acquisition and multiple algorithm processing methods on the Internet of Things server, real-time access monitoring and security risk assessment is solved, and the problem of traditional methods being difficult to deal with dynamically changing attack methods is improved, and the security and reliability of the server are improved.

CN119071049BActive Publication Date: 2025-05-09SHENZHEN GUANGTAI FEDERAL TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411130510.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-08-16
Publication Date
2025-05-09
Estimated Expiration
2044-08-16

AI Technical Summary

Technical Problem

Traditional server security access monitoring methods are difficult to adapt to the dynamic changes in attack methods and vulnerabilities after large-scale access to IoT devices, and cannot effectively deal with diversified security threats.

Method used

Multi-source data collection and multiple algorithm processing methods are used to realize real-time access monitoring of IoT servers, automatically conduct security risk assessment and analysis, predict potential security threats, and alert and control. Specific steps include data acquisition and preprocessing, security risk assessment, real-time analysis, risk prediction and multi-level security alerts and control.

Benefits of technology

Through comprehensive monitoring and analysis of multi-source data, the comprehensive monitoring and analysis capabilities of server access behavior are improved, the accurate assessment and prediction of security risks are enhanced, the system's forward-looking and defense capabilities are improved, and the security and reliability of the server are ensured.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119071049B_ABST
    Figure CN119071049B_ABST
Patent Text Reader

Abstract

The invention discloses a method for monitoring server security access based on the Internet of Things, which relates to the field of network security monitoring. First, server access data is collected and preprocessed, and then security risk assessment is performed on server access data from different sources through a security situation assessment model, and different server access sources are divided into high and low risk levels through a risk scoring threshold, and then dynamically changing server security risks are predicted, and then server security alarm strategies are formulated according to the real-time analysis results of server security risks and the server security risk prediction results, and a network multi-level access control mechanism is constructed to perform security management and control on server access behaviors; the problem that traditional server security access monitoring methods cannot adapt to constantly changing attack methods and vulnerabilities is solved, and the invention effectively guarantees the secure access of Internet of Things servers, and also helps to improve the overall security and stability of Internet of Things networks.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security monitoring, and in particular to a method for monitoring secure access based on an Internet of Things server. Background Art

[0002] In today's growing IoT environment, more and more devices and sensors are connected to the Internet. The massive data generated by these devices and sensors needs to be centrally managed and processed by servers. As the central node of data, the server is crucial to the stable operation and data security of IoT applications. At the same time, due to various reasons, the server faces various security risks and threats. Therefore, improving the security and reliability of the server and ensuring its normal operation is a prerequisite for the rapid development of IoT applications.

[0003] Traditional server security access monitoring methods often monitor common vulnerabilities such as fixed hardware, operating systems, network ports, and service processes, and are difficult to deal with dynamically changing attack methods and vulnerabilities. With the massive access of IoT devices, the attack surface is getting wider and wider, and the attack methods are becoming more and more diverse. Traditional server security access monitoring methods cannot adapt to the ever-changing attack methods and vulnerabilities.

[0004] Therefore, a method for monitoring secure access to IoT servers is needed to solve the above problems. Summary of the invention

[0005] In view of the shortcomings of the prior art, the present invention discloses a method for monitoring security access to an Internet of Things server. By adopting multi-source data collection and multiple algorithm processing methods, real-time access monitoring of the Internet of Things server is realized, security risk assessment and analysis are automatically performed, potential security threats are predicted, and alarms and controls are performed.

[0006] The present invention adopts the following technical solutions:

[0007] A method for monitoring secure access to an Internet of Things server comprises the following steps:

[0008] Step 1: collecting and preprocessing server access data, receiving server multi-source access data in real time through a message queue, and using a data processor to format, clean and aggregate the received data, wherein the server multi-source access data includes at least server logs, network traffic data, application access data and device status data;

[0009] Step 2: Security risk assessment of server access sources: security risk assessment is performed on server access data from different sources through a security situation assessment model, and different server access sources are divided into high and low risk levels through a risk score threshold. The security situation assessment model automatically extracts security risk features, optimizes feature subsets, and establishes a multi-layer neural network based on the characteristics and rules of server access data from different sources;

[0010] Step 3: Real-time analysis of server security risks. The data routing mechanism is used to transmit the access data of server access sources of different risk levels to different types of edge nodes for analysis and processing. The edge nodes include high-risk edge nodes and low-risk edge nodes. The high-risk edge nodes use potential malicious behavior mining algorithms to perform real-time potential security threat mining on the input high-risk access source server access data. The low-risk edge nodes use pattern matching algorithms to perform real-time security risk analysis on the input low-risk access source server access data.

[0011] Step 4: Server security risk prediction: transmitting the real-time analysis results of server security risks to the cloud platform for hierarchical storage and further processing according to the risk level of the server access source. The cloud platform uses an incremental method to store the real-time analysis results of server security risks in the historical security event database in real time, and predicts the dynamically changing server security risks based on the historical security events of the server and the current server security status;

[0012] Step 5: Multi-level server security alarm and control: formulate server security alarm strategies based on the real-time analysis results of server security risks and the server security risk prediction results, and build a network multi-level access control mechanism to securely manage and control server access behaviors.

[0013] Furthermore, the working steps of the security situation assessment model include:

[0014] Step 1: Obtain all access data from different access server sources, and divide the server access data from different sources into several access source windows in chronological order, extract and encode the access data in each access source window to generate a feature vector representation of the access data, and obtain key feature vectors through selection, crossover and mutation operations, and calculate the fitness value of the key feature vectors;

[0015] Step 2: construct a multi-layer neural network structure according to the complexity of risk assessment and the dimension of the feature vector, wherein the multi-layer neural network includes an input layer, a hidden layer and an output layer, input the generated key feature vector into the multi-layer neural network, calculate the output value of the network through forward propagation, and compare the output value with the actual value to obtain the loss function value, then, use the back propagation algorithm and the optimization algorithm to update the parameters of the multi-layer neural network until a predetermined training round is reached or a stop condition is met;

[0016] Step 3: construct risk assessment indicators and indicator weight coefficients based on the output value of the neural network, wherein the risk assessment indicators include access source reputation, response status abnormality, content sensitivity, access mode deviation degree, and access frequency abnormality degree;

[0017] Step 4: Use the constructed risk assessment indicators to calculate the key feature vectors in each access source window for comprehensive assessment and analysis, obtain the access source credibility, response status abnormality, content sensitivity, access mode deviation and access frequency abnormality of each access source window, and perform weighted summation through weight coefficients to obtain a comprehensive risk score.

[0018] Furthermore, the potential malicious behavior mining algorithm trains a deep learning model through an anomaly detection loss function, which measures the anomaly weight based on reconstruction error or probability distribution difference. The high-risk access source set is {y1,...,y k ,...,y m},y k represents the kth high-risk access source of the server, m is the total number of high-risk access sources of the server, and the access data set x of the kth high-risk access source is x = {x1,...,x i ,...,x n}, x i represents the i-th server access data, n is the total number of k-th high-risk access source server access data, 1≤i≤n, and the output function expression of the k-th high-risk access source anomaly detection loss function is:

[0019]

[0020] In formula (1), L k represents the anomaly detection loss function of the k-th high-risk access source, represents the reconstructed output of the deep learning model for the i-th server access data, a represents the hidden layer dimension of the deep learning model, δ represents the damping attenuation factor, which is used to control the model complexity and prevent overfitting. Represents the L2 norm square of the reconstruction error, which is used to measure the difference between the output of the deep learning model and the real data. represents the L2 norm square of the deep learning model parameter θ, and represents the penalty term of the model complexity; the potential malicious behavior mining algorithm calculates the abnormal score of each access data sample through the autoencoder of the deep learning model, and the calculation formula is:

[0021]

[0022] In formula (2), S i It represents the anomaly score of the access data of the i-th server in the k-th high-risk access source. The access data with potential threats is screened out according to the set anomaly score threshold and the calculated anomaly score.

[0023] Furthermore, the pattern matching algorithm converts the input low-risk level access source server access data into a feature vector or a feature set, and uses a distance or similarity measurement to calculate the similarity or distance between the input data features and the feature vectors of the existing access anomaly patterns, and screens out access data with potential threats based on the similarity threshold and the calculated similarity.

[0024] Furthermore, in step 4, a potential malicious behavior time series prediction algorithm is used to dynamically predict server security risks, and the historical security event data set is Q = {q1, q2, ..., q t -1,q t}, q t is the server access data set at time t, t≥1, and the access frequency abnormality and response status abnormality data sets of historical security events are V is the access frequency anomaly degree dataset of historical security events, and U is the response status anomaly degree dataset of historical security events. The access frequency anomaly degree of the server at the next moment is predicted based on the access frequency anomaly degree of historical security events. The output function formula is:

[0025]

[0026] In formula (3), v t is the abnormal degree of server access frequency at time t, v t-1 is the abnormal degree of server access frequency at time t-1, is the weighted function of the abnormal degree of server access frequency at time t+1, is the weighted coefficient of the abnormal degree of server access frequency at time t+1, ξ is the auxiliary weighted parameter of the abnormal degree of server access frequency, 0<ξ≤1, and max() is the maximum value function; according to the change law of the abnormal degree of access frequency of historical security events, the abnormal degree of server access response status at the next moment is predicted, and the output function formula is:

[0027]

[0028] In formula (4), u t is the abnormality degree of the server access response status at time t, u t-1 is the abnormality degree of the server access response status at time t-1, is the weighted function of the abnormality of the server access response status at time t+1, is the weighted coefficient of the abnormality of the server access response status at time t+1, δ is the auxiliary weighted parameter of the abnormality of the server access response status, 0<δ≤1.

[0029] Furthermore, the server security alarm strategy includes an immediate alarm strategy and a predictive alarm strategy. The immediate alarm strategy prompts the administrator via email, text message, phone call, visual billboard and alarm, and automatically isolates the affected server or network segment in a virtual isolation manner. The predictive alarm strategy uses a data traffic patrol tool to monitor the flow time distribution characteristics of potential threat access data traffic between nodes, and measures the potential threat access data flow path based on the difference between the total path time between two nodes and a given time, realizes data patrol tracing from the access layer to the output layer, and marks and analyzes data calls that do not comply with traffic routing rules.

[0030] Furthermore, the network multi-level access control mechanism includes a network access control unit, a transmission channel access control unit and a mobile terminal device access control unit. The network access control unit uses firewalls, logical isolation and physical isolation to control access to the network boundary. The transmission channel access control unit controls potential malicious data transmission by real-time monitoring of network transmission content and security threat detection. The mobile terminal device access control unit performs identity determination, authority management and behavior auditing of server access users through an identity authentication mechanism.

[0031] Furthermore, the cloud platform protects cloud data security, kernel platform security and operation service security through a double-layer security firewall. The double-layer security firewall classifies, monitors and protects sensitive data in the cloud platform through the collaborative work of the network security protection layer and the application security protection layer, and identifies SQL database injection, cross-site scripting attack XSS and command injection attack behaviors through the intelligent security engine. The double-layer security firewall uses an SSL secure socket layer protocol accelerator card to speed up data calls and processing.

[0032] The beneficial effects of the present invention are:

[0033] 1. The present invention receives and processes multi-source server access data in real time through message queues, including logs, network traffic, application access, and device status data. This method of integrating multi-source data ensures comprehensive monitoring and analysis of server access behavior, which helps to fully understand the server security status.

[0034] 2. The present invention performs security risk assessment on server access data from different sources based on a security situation assessment model, automatically learns the characteristics and rules of data from different sources, extracts security risk features, and optimizes feature subsets, thereby improving the accuracy and reliability of security risk assessment of server access sources and reducing manual intervention.

[0035] 3. The present invention divides server access sources into high-risk and low-risk levels according to risk assessment results, and diverts server access data to high-risk edge nodes and low-risk edge nodes for differentiated processing, which effectively improves the efficiency and accuracy of data processing and analysis, while reducing the pressure on the cloud platform and network traffic. High-risk edge nodes use potential malicious behavior mining algorithms, while low-risk edge nodes use pattern matching algorithms. This differentiated processing strategy not only improves processing efficiency, but also ensures targeted analysis of different risk levels.

[0036] 4. The present invention uses a historical security event database to store the real-time analysis results of server security risks, and predicts dynamically changing server security risks based on historical server security events and the current server security status, to provide early warning and prevent security threats, thereby enhancing the system's foresight and defense capabilities. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] Figure 1 It is a schematic diagram of the overall method flow of the present invention;

[0038] Figure 2 It is a flowchart of the security situation assessment model in the present invention;

[0039] Figure 3 This is a schematic diagram of the architecture of the server security alarm strategy in the present invention;

[0040] Figure 4 It is a schematic diagram of the architecture of the network multi-level access control mechanism in the present invention. DETAILED DESCRIPTION

[0041] The following will be combined with the attached embodiment of the present invention Figure 1 To Attachment Figure 4, the technical solutions in the embodiments of the present invention are clearly and completely described. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0042] The embodiment of the present invention discloses a method for monitoring secure access to an Internet of Things server, comprising the following steps:

[0043] Step 1: Collection and preprocessing of server access data

[0044] Deploy data collection agents on the server to capture server logs, network traffic data (such as collected through protocols such as SNMP, NetFlow, or sFlow), application access data (such as API call logs, user session data), and device status data (such as CPU usage, memory usage, disk space, etc.) in real time. The data collection agent sends the collected data to a message queue (such as RabbitMQ, Kafka) for temporary storage and queuing to ensure the order and reliability of the data. Use data processors (such as Apache Flink, Spark Streaming) to read data from the message queue and format it to ensure that the data format is unified for subsequent processing. Clean the data to remove duplicate, erroneous, or insignificant records, such as invalid IP addresses, abnormally large requests, etc. Aggregate the data and merge related data items into meaningful data units, such as counting the number of visits and traffic by time window.

[0045] Step 2: Security risk assessment of server access sources

[0046] Based on the characteristics and rules of different source data, feature extraction algorithms (such as PCA, LDA, etc.) are used to extract security risk features from the data, such as abnormal access patterns, sudden increases in traffic, illegal API calls, etc. The extracted features are optimized to remove redundant and irrelevant features to form the optimal feature subset. Multi-layer neural networks (such as convolutional neural networks CNN and long short-term memory networks LSTM) are used to train feature subsets and build a security situation assessment model. During the model training process, known security event data is used as positive samples and normal access data is used as negative samples for supervised learning. After the training is completed, the risk scores output by the model are divided by the risk score threshold, and the server access sources are divided into high-risk and low-risk levels.

[0047] Step 3: Real-time analysis of server security risks

[0048] Adopt data routing mechanisms (such as Nginx, Zookeeper, etc.) to route access data to corresponding edge nodes according to the risk level of the server access source. High-risk edge nodes deploy potential malicious behavior mining algorithms (such as behavior-based anomaly detection algorithms, machine learning classification algorithms, etc.) to perform real-time analysis of high-risk access data and identify potential malicious behaviors. Low-risk edge nodes use pattern matching algorithms (such as regular expression matching, string matching, etc.) to perform real-time security analysis of low-risk access data and detect whether there are known security threats.

[0049] Step 4: Server security risk prediction

[0050] The real-time analysis results of security risks are transmitted to the cloud platform for hierarchical storage according to risk levels. The cloud platform uses an incremental method to store the analysis results in real time in the historical security event database to ensure the integrity and traceability of the data. Based on the historical security events and current security status of the server, prediction algorithms (such as time series analysis, machine learning regression models, etc.) are used to predict dynamically changing server security risks. The prediction results can be used to guide future security policies and resource allocation.

[0051] Step 5: Multi-level server security alerts and controls

[0052] According to the real-time analysis and prediction results of security risks, formulate server security alarm strategies in a hierarchical manner. The alarm strategy includes the alarm level (such as urgent, important, general), alarm content (such as attack type, affected server, time, etc.) and alarm method (such as email, SMS, system log, etc.). Build a multi-level network access control mechanism, including firewalls, intrusion detection systems (IDS), intrusion prevention systems (IPS), etc. According to the alarm strategy and security risk level, dynamically adjust the access control strategy to securely manage and control server access behavior. Implement security reinforcement measures, such as updating server patches, restricting access rights, and shutting down unnecessary services.

[0053] The working steps of the security situation assessment model include:

[0054] Step 1: Data preprocessing and feature extraction

[0055] Collect access data from different access server sources in real time, including logs, traffic, application access records, and device status. Divide the data into multiple access source windows by access source, and each window contains all data within a fixed time period. Perform a detailed analysis of the data in each access source window to extract key features, such as IP address, access time, request type, response code, request content size, access frequency, etc. Encode the extracted features to generate feature vectors. Feature encoding can be numerical (such as direct mapping, normalization), one-hot encoding (for classification features), or word embedding (for text content).

[0056] Apply selection, crossover, and mutation operations (these are usually used in genetic algorithms, but in this context can be understood as feature selection and optimization techniques such as principal component analysis PCA, feature importance assessment, etc.) to identify key feature vectors. Calculate the fitness value of the key feature vectors, that is, the effectiveness of these features in distinguishing normal from abnormal access behavior.

[0057] Step 2: Multi-layer neural network construction and training

[0058] According to the complexity of risk assessment and the dimension of feature vector, the structure of multi-layer neural network is designed. It usually includes input layer (feature vector size), one or more hidden layers (each layer contains a certain number of neurons), and output layer (usually one neuron, outputting risk score). The generated key feature vector is sent as input to the multi-layer neural network. The output value of the network, that is, the predicted risk score, is calculated by forward propagation. The output value is compared with the actual risk score (or label) to calculate the loss function value (such as mean square error MSE). Backpropagation algorithm (such as gradient descent method, Adam optimizer, etc.) and optimization algorithm are used to update the weights and biases of the network to minimize the loss function.

[0059] The training process is repeated until the predetermined number of training rounds is reached or the stopping condition is met (such as the loss value no longer decreases significantly, the performance on the validation set begins to decrease, etc.).

[0060] Step 3: Risk assessment indicators and weight construction

[0061] Define risk assessment indicators, including but not limited to: Access source reputation: evaluate the reliability of the access source based on historical records. Response status abnormality: check whether the response code, response time, etc. are abnormal. Content sensitivity: analyze whether the request content contains sensitive information. Access pattern deviation: compare the difference between the current access pattern and the historical pattern. Access frequency abnormality: monitor whether the access frequency suddenly increases or decreases.

[0062] Assign weight coefficients to each indicator based on business needs and the importance of risk assessment. The weight coefficients can be automatically learned through expert scoring, analytic hierarchy process (AHP) or machine learning models.

[0063] Step 4: Comprehensive risk assessment

[0064] Use the risk assessment model and indicators to comprehensively evaluate the key feature vectors in each access source window. Calculate the value of each indicator and perform weighted summation using the weight coefficient. Add the weighted indicator values ​​to obtain the comprehensive risk score of each access source window. According to the risk score threshold, the access source is divided into high-risk and low-risk levels. Output the assessment results to the monitoring system or cloud platform for subsequent alarms, control or further optimization. Continuously collect new access data for iterative training and performance improvement of the model.

[0065] The potential malicious behavior mining algorithm trains the deep learning model through the anomaly detection loss function. The anomaly detection loss function measures the anomaly weight based on the reconstruction error or probability distribution difference. The high-risk access source set is {y1,...,y k ,...,y m},y k represents the kth high-risk access source of the server, m is the total number of high-risk access sources of the server, and the access data set x of the kth high-risk access source is x = {x1,...,x i ,...,x n}, x i represents the i-th server access data, n is the total number of k-th high-risk access source server access data, 1≤i≤n, and the output function expression of the k-th high-risk access source anomaly detection loss function is:

[0066]

[0067] In formula (1), L k represents the anomaly detection loss function of the k-th high-risk access source, represents the reconstructed output of the deep learning model for the i-th server access data, a represents the hidden layer dimension of the deep learning model, δ represents the damping attenuation factor, which is used to control the model complexity and prevent overfitting. Represents the L2 norm square of the reconstruction error, which is used to measure the difference between the output of the deep learning model and the real data. represents the L2 norm square of the deep learning model parameter θ, and represents the penalty term of the model complexity; the potential malicious behavior mining algorithm calculates the abnormal score of each access data sample through the autoencoder of the deep learning model, and the calculation formula is:

[0068]

[0069] In formula (2), S i It represents the anomaly score of the access data of the i-th server in the k-th high-risk access source. The access data with potential threats is screened out according to the set anomaly score threshold and the calculated anomaly score. The hardware working environment of the potential malicious behavior mining algorithm usually includes:

[0070] Processor (CPU): Use a multi-core, high-frequency CPU to support parallel processing and fast computing.

[0071] Graphics Processing Unit (GPU): For deep learning models, the parallel computing capability of GPU is particularly important, which can significantly accelerate the model training and reasoning process.

[0072] Memory (RAM): Equipped with large-capacity memory to support the loading and processing of large-scale data sets.

[0073] Solid-state drive (SSD): Provides fast data read and write speeds, reducing data loading time.

[0074] Network Attached Storage (NAS) or Storage Area Network (SAN): For large-scale data sets, efficient network storage solutions are required to support centralized management and access of data.

[0075] Network traffic collector: used to capture network traffic data in real time.

[0076] Log Collector: Collects log files from various servers and applications.

[0077] Preprocessing server: performs preprocessing operations such as cleaning, deduplication, and feature extraction on the collected raw data.

[0078] High-speed network interface card (NIC): Provides high-speed, stable network connection and supports large-scale data transmission and exchange.

[0079] Load balancer: When the network request volume is large, it can reasonably distribute the requests to multiple servers to improve system stability and throughput.

[0080] Firewalls and intrusion detection systems: Protect the hardware environment from external attacks and malicious access.

[0081] Data backup system: Regularly back up key data and model parameters to prevent data loss or damage.

[0082] Monitor, keyboard and mouse: used by algorithm developers and operation and maintenance personnel for daily operations and management.

[0083] UPS (Uninterruptible Power Supply): Ensures that the system can continue to run for a period of time when power is cut off, protecting data and system security.

[0084] In summary, the hardware working environment of the potential malicious behavior mining algorithm is a comprehensive system that integrates high-performance computing, high-speed storage, data acquisition and processing, network communication, security backup, and auxiliary equipment. Such an environment can support the algorithm to efficiently process and analyze network data, and timely discover and respond to potential malicious behaviors.

[0085] The laboratory configuration uses a Core i9 64+128G memory computer, and the simulation environment is established using simulation software. The on-site experimental environment is set up, the simulation data accuracy is 95%, and the algorithm operation error does not exceed 2.5%. The potential malicious behavior mining algorithm (Group A) and the traditional malicious behavior mining algorithm based on rules and feature engineering (Group B) are used for comparative experiments. Four malicious access behaviors are artificially set, namely high-risk behavior 1, high-risk behavior 2, low-risk behavior 1 and low-risk behavior 2. Simulation work is carried out in the experimental environment, and the detection accuracy and time consumption of malicious behaviors are recorded. The experiment is repeated 5 times to calculate the average value, and the record is shown in Table 1.

[0086] Table 1 Results Statistics

[0087]

[0088] According to the data in the table above, the potential malicious behavior mining algorithm in group A is superior to the traditional malicious behavior mining algorithm based on rules and feature engineering in group B in terms of detection accuracy and time consumption. This shows that in this experiment, the potential malicious behavior mining algorithm is better than the traditional malicious behavior mining algorithm in terms of accuracy and efficiency in detecting malicious behaviors. Note that in the experiment, four malicious access behaviors were set, so we need to conduct further experiments to determine the performance of these algorithms in detecting different types of malicious behaviors, and verify the effectiveness of these experimental results on a larger data set.

[0089] In the IoT server security access monitoring method, the pattern matching algorithm is used to identify potential threats in the access data of the low-risk access source server, convert the input data into a feature vector or feature set, and use a similarity metric to calculate the similarity or distance between the existing access anomaly patterns, so as to identify the access data of potential threats. The following steps are included:

[0090] 1. Construction of feature vector or feature set

[0091] Collect server access data from low-risk access sources, including log records, request parameters, response status, etc. Clean the collected data to remove invalid, redundant or malformed records. Extract key features, such as IP address, request time, request type, request URL, request parameters, response code, response time, etc. Convert the extracted features into numeric or comparable formats. For example, IP addresses can be hashed, and request types, response codes, etc. can be one-hot encoded or mapped to numeric values. Combine all features into a feature vector or feature set, where each vector represents an access event.

[0092] 2. Similarity measurement and pattern matching

[0093] Collect known abnormal access patterns in historical access data, such as malicious login attempts, SQL injection attacks, cross-site scripting attacks (XSS), etc. Extract and encode features for each abnormal pattern, construct a feature vector or feature set, and store it in the abnormal pattern library. For each feature vector of low-risk access data input, use a similarity measurement method (such as Euclidean distance, cosine similarity, Jaccard similarity, etc.) to compare it with the feature vector in the abnormal pattern library. Select an appropriate similarity threshold and determine whether the input data is similar to a certain abnormal pattern based on the threshold and the calculated similarity or distance value.

[0094] If the similarity between the feature vector of the input data and a feature vector in the abnormal pattern library exceeds the preset threshold, the input data is considered to have a potential threat. Detailed information about the potential threat, such as access time, IP address, request type, etc., is recorded for subsequent security analysis and processing.

[0095] In summary, the pattern matching algorithm can convert low-risk access source server access data into feature vectors or feature sets, and calculate the similarity or distance between the input data features and the feature vectors of existing access anomaly patterns through distance or similarity measurement to discover potential malicious behaviors. Through risk response and management, the security and reliability of the server can be effectively improved.

[0096] In step 4, a potential malicious behavior time series prediction algorithm is used to dynamically predict server security risks. The historical security event data set is Q = {q1, q2, ..., q t-1 ,q t}, q t is the server access data set at time t, t≥1, and the access frequency abnormality and response status abnormality data sets of historical security events are V is the access frequency anomaly degree dataset of historical security events, and U is the response status anomaly degree dataset of historical security events. The access frequency anomaly degree of the server at the next moment is predicted based on the access frequency anomaly degree of historical security events. The output function formula is:

[0097]

[0098] In formula (3), v t is the abnormal degree of server access frequency at time t, v t-1 is the abnormal degree of server access frequency at time t-1, is the weighted function of the abnormal degree of server access frequency at time t+1, is the weighted coefficient of the abnormal degree of server access frequency at time t+1, ξ is the auxiliary weighted parameter of the abnormal degree of server access frequency, 0<ξ≤1, and max() is the maximum value function; according to the change law of the abnormal degree of access frequency of historical security events, the abnormal degree of server access response status at the next moment is predicted, and the output function formula is:

[0099]

[0100] In formula (4), u t is the abnormality degree of the server access response status at time t, u t-1 is the abnormality degree of the server access response status at time t-1, is the weighted function of the abnormality of the server access response status at time t+1, is the weighted coefficient of the abnormality of the server access response status at time t+1, δ is the auxiliary weighted parameter of the abnormality of the server access response status, 0<δ≤1.

[0101] The hardware working environment of the potential malicious behavior timing prediction algorithm may vary depending on the specific application scenario, algorithm complexity and performance requirements. But in general, a typical hardware working environment may include the following aspects:

[0102] 1. Processor (CPU): The processor is the core component for executing algorithms. For complex timing prediction algorithms, high-performance processors are required to ensure computing speed and efficiency. Multi-core processors or processors with strong parallel processing capabilities (such as Intel's Xeon series or AMD's EPYC series) are common choices.

[0103] 2. Graphics Processing Unit (GPU): For time series prediction algorithms that require large-scale data processing and parallel computing, GPU can provide significant performance advantages due to its powerful parallel processing capabilities.

[0104] 3. Memory (RAM): Sufficient memory capacity is key to ensure that the algorithm can run smoothly. For large data sets and complex algorithms, a larger memory capacity is required to store intermediate data and results. High-speed memory (such as DDR4 or DDR5) can reduce data access latency and improve algorithm execution efficiency.

[0105] Hard disk or solid-state drive (HDD / SSD): used to store algorithm code, data sets, and results. For application scenarios that require frequent read and write operations, solid-state drives can provide faster read and write speeds.

[0106] Network storage devices: For distributed computing or big data processing scenarios, network storage devices (such as NAS, SAN) can provide larger storage capacity and higher data access efficiency.

[0107] Network Interface Card (NIC): For timing prediction algorithms that need to process network data (such as network traffic prediction), high-performance network interface cards can ensure high-speed data transmission and real-time processing.

[0108] Cooling system: High-performance hardware devices will generate a lot of heat during operation, so a good cooling system is required to ensure the stable operation of the equipment.

[0109] The laboratory configuration uses a Core i9 64+128G memory computer, and the simulation environment is established using simulation software. The on-site experimental environment is set up, the simulation data accuracy is 95%, and the algorithm operation error does not exceed 2.5%. The potential malicious behavior time series prediction algorithm (Group A) and the traditional method based on feature engineering and statistical analysis (Group B) are used for comparative experiments. Four potential malicious access behaviors are set, namely potential high-risk behavior 1, potential high-risk behavior 2, potential low-risk behavior 1 and potential low-risk behavior 2. Simulation work is carried out in the experimental environment, and the detection accuracy and time consumption of malicious behaviors are recorded. The experiment is repeated 5 times to calculate the average value, and the record is shown in Table 2.

[0110] Table 2 Results Statistics

[0111]

[0112] According to the results of the experimental data, the potential malicious behavior timing prediction algorithm can perform better in detecting four potential malicious access behaviors. Its average detection accuracy is about 8.6% higher than that of traditional methods, and it is also more efficient. However, it should be noted that in the experimental data, the accuracy and time consumption recorded are only the performance of the algorithm in some specific cases, and cannot fully represent the performance of the algorithm. The performance of various algorithms in different situations is also different. Therefore, it is necessary to further expand the scale of the experiment and the scope of the data to deepen the understanding of its effectiveness.

[0113] The server security alarm strategy includes an immediate alarm strategy and a predictive alarm strategy. The immediate alarm strategy prompts the administrator through email, text message, phone, visual billboard and alarm, and automatically isolates the affected server or network segment in a virtual isolation manner. The predictive alarm strategy uses a data traffic patrol tool to monitor the flow time distribution characteristics of potential threat access data traffic between nodes, and measures the potential threat access data flow path based on the difference between the total path time between two nodes and the given time, realizes data patrol tracing from the access layer to the output layer, and marks and analyzes data calls that do not comply with traffic routing rules.

[0114] The server security alarm strategy includes an immediate alarm strategy and a predictive alarm strategy;

[0115] 1. Immediate warning strategy

[0116] The system implements real-time monitoring, and through uninterrupted scanning and monitoring of network activities, it promptly checks whether network activities comply with security regulations, such as unauthorized access, suspicious file transfers and other abnormal activities. When suspicious network activities are found, the system will send warning information to the administrator through various means such as email, SMS, phone, visual signage and alarm, reminding the administrator to take timely measures to deal with them. When an affected server or network segment appears, the system can automatically isolate it through virtual isolation to prevent the attacker from using the server to further attack other servers or systems.

[0117] 2. Prediction and Alert Strategy

[0118] Data traffic inspection tools are used to monitor the time distribution characteristics of the access data traffic of potential threats between nodes in order to detect abnormal behavior in a timely manner. The difference between the total path time between two nodes and the given time is measured to achieve data inspection and tracing from the access layer to the output layer, so that abnormal behavior can be discovered and quickly checked in a timely manner. Data calls that do not comply with traffic routing rules are marked and analyzed to detect abnormal behavior in a timely manner, thereby avoiding security incidents such as network attacks or data leaks.

[0119] Through the effective implementation of the above strategies, potential threats can be discovered and isolated in a timely manner, security incidents such as network attacks and data leakage can be avoided, and the stability and reliability of the system in network security can be guaranteed.

[0120] The cloud platform protects cloud data security, kernel platform security and operation service security through a double-layer security firewall. The double-layer security firewall classifies, monitors and protects sensitive data in the cloud platform through the coordinated work of the network security protection layer and the application security protection layer. The network security protection layer refers to the use of host firewalls, Web application firewalls and other technical means to provide security protection for the cloud platform's systems and applications. This layer is mainly used to prevent external attacks and threats. The application security protection layer refers to the use of WAF (Web Application Firewall) and other technical means to provide security protection for Web applications in the cloud platform. This layer is mainly used to prevent internal attacks and threats.

[0121] The double-layer security firewall uses an intelligent security engine to identify SQL database injection, cross-site scripting attack XSS and command injection attack behaviors, as well as some other common attacks and threats, to achieve security management and control. The double-layer security firewall uses SSL secure socket layer protocol accelerator card to speed up data call and processing, improving the security and operation speed of the cloud platform.

[0122] Through the comprehensive application of technical means such as double-layer security firewalls, intelligent security engines and SSL secure socket layer protocol accelerator cards, it is possible to classify, monitor and protect sensitive data in the cloud platform, ensure the stability and reliability of the cloud platform in network security, and provide enterprise users with more secure, reliable and efficient cloud computing services.

[0123] So far, the technical solutions of the present invention have been described in conjunction with the preferred embodiments shown in the accompanying drawings. However, it is easy for those skilled in the art to understand that the protection scope of the present invention is obviously not limited to these specific embodiments. Without departing from the principle of the present invention, those skilled in the art can make equivalent changes or substitutions to the relevant technical features, and the technical solutions after these changes or substitutions will fall within the protection scope of the present invention.

Claims

1. A method for monitoring secure access to an Internet of Things server, characterized in that: The following steps are involved: Step 1: collecting and preprocessing server access data, receiving server multi-source access data in real time through a message queue, and using a data processor to format, clean and aggregate the received data, wherein the server multi-source access data includes at least server logs, network traffic data, application access data and device status data; Step 2: Security risk assessment of server access sources: security risk assessment is performed on server access data from different sources through a security situation assessment model, and different server access sources are divided into high and low risk levels through a risk score threshold. The security situation assessment model automatically extracts security risk features, optimizes feature subsets, and establishes a multi-layer neural network based on the characteristics and rules of server access data from different sources; The working steps of the security situation assessment model include: Step 1: Obtain all access data from different access server sources, and divide the server access data from different sources into several access source windows in chronological order, extract and encode the access data in each access source window to generate a feature vector representation of the access data, and obtain key feature vectors through selection, crossover and mutation operations, and calculate the fitness value of the key feature vectors; Step 2: construct a multi-layer neural network structure according to the complexity of risk assessment and the dimension of the feature vector, wherein the multi-layer neural network includes an input layer, a hidden layer and an output layer, input the generated key feature vector into the multi-layer neural network, calculate the output value of the network through forward propagation, and compare the output value with the actual value to obtain the loss function value, then, use the back propagation algorithm and the optimization algorithm to update the parameters of the multi-layer neural network until a predetermined training round is reached or a stop condition is met; Step 3: construct risk assessment indicators and indicator weight coefficients based on the output value of the neural network, wherein the risk assessment indicators include access source reputation, response status abnormality, content sensitivity, access mode deviation degree, and access frequency abnormality degree; Step 4: Use the constructed risk assessment indicators to calculate the key feature vectors in each access source window for comprehensive assessment and analysis, obtain the access source reputation, response status abnormality, content sensitivity, access mode deviation and access frequency abnormality of each access source window, and perform weighted summation through weight coefficients to obtain a comprehensive risk score; Step 3: Real-time analysis of server security risks. The data routing mechanism is used to transmit the access data of server access sources of different risk levels to different types of edge nodes for analysis and processing. The edge nodes include high-risk edge nodes and low-risk edge nodes. The high-risk edge nodes use potential malicious behavior mining algorithms to perform real-time potential security threat mining on the input high-risk access source server access data. The potential malicious behavior mining algorithm trains the deep learning model through anomaly detection loss function, which measures the anomaly weight based on reconstruction error or probability distribution difference. The high-risk access source set is {y1,...,y k ,...,y m },y k represents the kth high-risk access source of the server, m is the total number of high-risk access sources of the server, and the access data set x of the kth high-risk access source is x = {x1,...,x i ,...,x n }, x i represents the i-th server access data, n is the total number of k-th high-risk access source server access data, 1≤i≤n, and the output function expression of the k-th high-risk access source anomaly detection loss function is: In formula (1), L k represents the anomaly detection loss function of the k-th high-risk access source, represents the reconstructed output of the deep learning model for the i-th server access data, a represents the hidden layer dimension of the deep learning model, δ represents the damping attenuation factor, which is used to control the model complexity and prevent overfitting. Represents the L2 norm square of the reconstruction error, which is used to measure the difference between the output of the deep learning model and the real data. represents the L2 norm square of the deep learning model parameter θ, and represents the penalty term of the model complexity; the potential malicious behavior mining algorithm calculates the abnormal score of each access data sample through the autoencoder of the deep learning model, and the calculation formula is: In formula (2), S i Indicates the anomaly score of the i-th server access data in the k-th high-risk access source. The access data with potential threats is screened out according to the set anomaly score threshold and the calculated anomaly score. The low-risk edge node uses a pattern matching algorithm to perform real-time security risk analysis on the input low-risk level access source server access data; The pattern matching algorithm converts the input low-risk access source server access data into a feature vector or feature set, and uses a distance or similarity metric to calculate the similarity or distance between the input data features and the feature vectors of the existing access anomaly patterns, and screens out access data with potential threats based on a similarity threshold and the calculated similarity; Step 4: Server security risk prediction: transmitting the real-time analysis results of server security risks to the cloud platform for hierarchical storage and further processing according to the risk level of the server access source. The cloud platform uses an incremental method to store the real-time analysis results of server security risks in the historical security event database in real time, and predicts the dynamically changing server security risks based on the historical security events of the server and the current server security status; Step 5: Multi-level server security alarm and control: formulate server security alarm strategies based on the real-time analysis results of server security risks and the server security risk prediction results, and build a network multi-level access control mechanism to securely manage and control server access behaviors.

2. According to claim 1, a method for monitoring secure access to an Internet of Things server is characterized in that: In step 4, a potential malicious behavior time series prediction algorithm is used to dynamically predict server security risks. The historical security event data set is Q = {q1, q2, ..., q t-1 ,q t }, q t is the server access data set at time t, t≥1, and the access frequency abnormality and response status abnormality data sets of historical security events are V is the access frequency anomaly degree dataset of historical security events, and U is the response status anomaly degree dataset of historical security events. The access frequency anomaly degree of the server at the next moment is predicted based on the access frequency anomaly degree of historical security events. The output function formula is: In formula (3), v t is the abnormal degree of server access frequency at time t, v t-1 is the abnormal degree of server access frequency at time t-1, is the weighted function of the abnormal degree of server access frequency at time t+1, is the weighted coefficient of the abnormal degree of server access frequency at time t+1, ξ is the auxiliary weighted parameter of the abnormal degree of server access frequency, 0<ξ≤1, and max() is the maximum value function; according to the change law of the abnormal degree of access frequency of historical security events, the abnormal degree of server access response status at the next moment is predicted, and the output function formula is: In formula (4), u t is the abnormality degree of the server access response status at time t, u t-1 is the abnormality degree of the server access response status at time t-1, is the weighted function of the abnormality of the server access response status at time t+1, is the weighted coefficient of the abnormality of the server access response status at time t+1, δ is the auxiliary weighted parameter of the abnormality of the server access response status, 0<δ≤1.

3. According to claim 1, a method for monitoring secure access to an Internet of Things server is characterized in that: The server security alarm strategy includes an immediate alarm strategy and a predictive alarm strategy. The immediate alarm strategy prompts the administrator through email, text message, phone, visual billboard and alarm, and automatically isolates the affected server or network segment in a virtual isolation manner. The predictive alarm strategy uses a data traffic patrol tool to monitor the flow time distribution characteristics of potential threat access data traffic between nodes, and measures the potential threat access data flow path based on the difference between the total path time between two nodes and the given time, realizes data patrol tracing from the access layer to the output layer, and marks and analyzes data calls that do not comply with traffic routing rules.

4. A method for monitoring secure access to an Internet of Things server according to claim 1, characterized in that: The network multi-level access control mechanism includes a network access control unit, a transmission channel access control unit and a mobile terminal device access control unit. The network access control unit uses firewalls, logical isolation and physical isolation to control access to the network boundary. The transmission channel access control unit controls potential malicious data transmission by real-time monitoring of network transmission content and security threat detection. The mobile terminal device access control unit performs identity determination, authority management and behavior auditing on server access users through an identity authentication mechanism.

5. The method for monitoring secure access to an Internet of Things server according to claim 1, characterized in that: The cloud platform protects cloud data security, kernel platform security and operation service security through a double-layer security firewall. The double-layer security firewall classifies, monitors and protects sensitive data in the cloud platform through the collaborative work of the network security protection layer and the application security protection layer, and identifies SQL database injection, cross-site scripting attack XSS and command injection attack behaviors through the intelligent security engine. The double-layer security firewall uses an SSL secure socket layer protocol accelerator card to speed up data calls and processing.

Citation Information

Patent Citations

  • Cloud asset security risk assessment method, apparatus and device, and storage medium

    CN112348371A

  • System for automated capture and analysis of business information for reliable business venture outcome prediction

    US20170124497A1