Internet of things security management system and method

By monitoring the historical access records of IoT devices and the user's network behavior in real time, combining the feature matching mechanism, predicting the user's incident response permissions and executing trust constraints, the problem of abuse of IoT devices in complex network environments is solved, and the security of IoT network communication is improved.

CN119449447BActive Publication Date: 2025-06-06GUANGZHOU INST OF INFORMATION TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411656231.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-19
Publication Date
2025-06-06
Estimated Expiration
2044-11-19

AI Technical Summary

Technical Problem

IoT devices operate in complex and unsecure network environments, resulting in abuse of permissions, and attackers are able to access sensitive data and perform unauthorized operations, affecting system stability and security.

Method used

By monitoring the historical access records of IoT devices in real time, determining the authorization feedback information of the device in different network event scenarios, and combining the user's historical network behavior, calculating the trust index, determining the security baseline, judging event correlation and behavior credibility based on the feature matching mechanism, predicting the user's event response permissions, and executing trust constraints when the permissions exceed the security baseline.

Benefits of technology

It effectively improves the security of IoT network communications, reduces the risk of permission abuse, ensures that the Internet of Things can quickly respond and restrict user operations in abnormal situations, and enhances overall security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119449447B_ABST
    Figure CN119449447B_ABST
Patent Text Reader

Abstract

The present application provides an Internet of Things security management system and method, which determines the authorization feedback information in each network event scenario through the historical access records of the network device; when the user sends a network communication request to the network device, the security baseline is determined through the user's trust index during network interaction and all the authorization feedback information; the credibility of the behavior authorized by the network device in the network communication request is determined according to the event correlation between each network event scenario and the network communication request, and then the user's event response authority in the network communication request is predicted through the behavioral credibility and each authorization feedback information; if the event response authority is greater than the security baseline, the user's event response authority is trusted based on the security baseline. Based on the above scheme, the user's access rights can be trusted in combination with different network event scenarios in the Internet of Things, thereby improving the security of network communications in the Internet of Things.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of Internet of Things security technology, and more specifically, to an Internet of Things security management system and method. Background Art

[0002] With the rapid development of the Internet of Things, more and more devices are connected to the Internet, forming a huge network ecosystem. The widespread application of IoT devices has brought convenience and efficiency to smart homes, industrial automation, smart cities and other fields. IoT devices usually have limited computing and storage capabilities and often operate in complex and insecure network environments, which makes them more vulnerable to network attacks. Network security protocols play a vital role in ensuring the security and integrity of data transmission. Effectively integrating network security protocols into IoT security requires not only adaptation and optimization for the IoT environment, but also the development of new protocols and standards to cope with increasingly complex security threats.

[0003] When a user or device obtains access rights beyond the scope of their duties, permission abuse occurs. Permission abuse of network devices in the Internet of Things stems from the lack of an effective access control mechanism or unreasonable permission allocation, which allows attackers to access sensitive data and perform unauthorized operations. This not only leads to sensitive data leakage, but may also cause illegal operations and device control. In severe cases, it can cause device failure or data corruption, which in turn affects the stability and security of the entire system and is also a serious security risk. Establishing a scenario-based trust constraint mechanism can effectively solve the problem of permission abuse. Therefore, how to combine different network event scenarios in the Internet of Things to trust the user's access rights and thereby improve the security of network communications in the Internet of Things is a difficult problem faced by the industry. Summary of the invention

[0004] The present application provides an Internet of Things security management system and method, which can perform trust constraints on user access rights in combination with different network event scenarios in the Internet of Things, thereby improving the security of network communications in the Internet of Things.

[0005] In a first aspect, the present application provides an IoT security permission constraint method, comprising:

[0006] Real-time monitoring of network devices connected to the Internet of Things, collecting historical access records of network devices within a specified time period, and then determining the authorization feedback information of network devices in various network event scenarios through the historical access records;

[0007] When a user sends a network communication request to a network device, the user's historical network behavior is collected, and the user's trust index during network interaction is determined based on the historical network behavior, and then the security baseline of the network device's authorization to the user is determined through the trust index and all authorization feedback information;

[0008] Determine the event correlation between each network event scenario and the network communication request based on the feature matching mechanism, determine the behavior credibility of the network device in the network communication request according to each event correlation and the network fluctuation characteristics of the network device, and then predict the event response authority of the user in the network communication request through the behavior credibility and each authorization feedback information;

[0009] If the event response authority is greater than the security baseline, trust constraints are imposed on the user's event response authority based on the security baseline.

[0010] In some embodiments, determining the authorization feedback information of the network device in each network event scenario through the historical access record specifically includes:

[0011] For each network event scenario, filter out access data of the network event scenario from the historical access records;

[0012] determining authorization success rate, access privilege level, and response time based on the access data;

[0013] The authorization success rate, the access permission level and the response time are used as authorization feedback information of the network device in a network event scenario, thereby obtaining authorization feedback information of the network device in each network event scenario.

[0014] In some embodiments, determining the trust index of the user during network interaction according to the historical network behavior specifically includes:

[0015] Determine the user's network interaction frequency through the historical network behavior;

[0016] Extracting all abnormal behaviors of the user from the historical network behaviors, and then determining the behavior frequency of each abnormal behavior;

[0017] The trust index of the user during network interaction is determined according to the network interaction frequency and all behavior frequencies.

[0018] In some embodiments, determining the security baseline of the network device's authorization to the user through the trust index and all authorization feedback information specifically includes:

[0019] For each network event scenario, determining the authorization security of the network device in the network event scenario according to the authorization feedback information of the network device in the network event scenario;

[0020] Determine the scenario security value of the network device authorizing the user in the network event scenario through the authorization security and the trust index, and then obtain the scenario security value of the network device authorizing the user in each network event scenario;

[0021] Determine the security baseline for network devices to authorize users based on the security values ​​of all scenarios.

[0022] In some embodiments, determining the event correlation between each network event scenario and the network communication request based on the feature matching mechanism specifically includes:

[0023] For each network event scenario, extract event features from the network event scenario;

[0024] extracting a communication request feature from the network communication request;

[0025] Based on the feature matching mechanism, feature matching is performed on the event feature and the communication request feature to obtain the event correlation between the network event scenario and the network communication request, and then obtain the event correlation between each network event scenario and the network communication request.

[0026] In some embodiments, determining the credibility of the behavior authorized by the network device in the network communication request according to the correlation of each event and the network fluctuation characteristics of the network device specifically includes:

[0027] For each network event scenario, obtaining an event correlation between the network event scenario and the network communication request;

[0028] Determining the response adaptability between the network communication request and the network event scenario according to the event correlation and the network fluctuation characteristics of the network device, and then obtaining the response adaptability between the network communication request and each network event scenario;

[0029] The credibility of the authorized behavior of the network device in the network communication request is determined through all response adaptability.

[0030] In some embodiments, predicting the event response authority of the user in the network communication request by using the behavior credibility and each authorization feedback information specifically includes:

[0031] Determine feedback consistency between the user and the network device based on all authorized feedback information;

[0032] Based on the feedback consistency and the behavior credibility, a regression prediction is performed on the user's authority in the network communication request to obtain the user's event response authority in the network communication request.

[0033] In a second aspect, the present application provides an Internet of Things security management system, including an authority constraint unit, wherein the authority constraint unit includes:

[0034] A monitoring module is used to monitor network devices connected to the Internet of Things in real time, collect historical access records of network devices within a specified time period, and then determine the authorization feedback information of network devices in various network event scenarios through the historical access records;

[0035] A processing module, used for collecting the user's historical network behavior when the user sends a network communication request to the network device, determining the user's trust index during network interaction based on the historical network behavior, and then determining the security baseline of the network device's authorization to the user through the trust index and all authorization feedback information;

[0036] The processing module is also used to determine the event correlation between each network event scenario and the network communication request based on a feature matching mechanism, determine the behavior credibility of the network device in the network communication request according to the correlation of each event and the network fluctuation characteristics of the network device, and then predict the event response authority of the user in the network communication request through the behavior credibility and each authorization feedback information;

[0037] The execution module is used to perform trust constraints on the user's event response authority based on the security baseline if the event response authority is greater than the security baseline.

[0038] In a third aspect, the present application provides a computer device, comprising a memory and a processor, wherein the memory is used to store a computer program, and the processor is used to call and run the computer program from the memory, so that the computer device executes the above-mentioned Internet of Things security permission constraint method.

[0039] In a fourth aspect, the present application provides a computer-readable storage medium, in which instructions or codes are stored. When the instructions or codes are run on a computer, the computer implements the above-mentioned Internet of Things security permission constraint method when executed.

[0040] The technical solution provided by the embodiments disclosed in this application has the following beneficial effects:

[0041] In an Internet of Things security management system and method provided by the present application, network devices connected to the Internet of Things are monitored in real time, historical access records of the network devices within a specified time period are collected, and then the authorization feedback information of the network devices in various network event scenarios is determined through the historical access records; when a user sends a network communication request to a network device, the user's historical network behavior is collected, and the trust index of the user in network interaction is determined based on the historical network behavior, and then the security baseline of the network device's authorization to the user is determined through the trust index and all the authorization feedback information; based on a feature matching mechanism, the event correlation between each network event scenario and the network communication request is determined, and the credibility of the behavior authorized by the network device in the network communication request is determined based on the correlation of each event and the network fluctuation characteristics of the network device, and then the user's event response authority in the network communication request is predicted through the credibility of the behavior and each authorization feedback information; if the event response authority is greater than the security baseline, the user's event response authority is trusted based on the security baseline.

[0042] It can be seen that in this application, if the event response authority is greater than the security baseline, the user's event response authority is trusted based on the security baseline. First, by determining the security baseline, the minimum security authorization level of the network device for the user in the network event scenario can be obtained. When the user's request exceeds the security baseline, the Internet of Things can issue an alarm and implement restrictions in time, reducing the risk of abuse of authority. The mechanism of the security baseline can remain stable and secure when network communications are threatened, thereby enhancing the overall security of the Internet of Things environment. Among them, by determining the trust index, the Internet of Things can identify normal operations and abnormal operations in real time, thereby defending the subsequent guarantee that each user's access rights can be dynamically adjusted based on their historical behavior and current network event scenarios, ensuring that when an abnormality occurs, the Internet of Things can To respond quickly and limit the user's operations; then, by determining the event response authority, the response authority level that the user can obtain under the network communication request can be obtained. Through event response authority, the Internet of Things can not only timely limit operations that do not meet expectations, but also automatically adjust its authority when there is a deviation between the user request and the actual event. Among them, through the feature matching mechanism, the Internet of Things can quickly determine the correlation between the user's request and the specific network event scenario, thereby determining the user's operation authority in the network event scenario. The Internet of Things can flexibly respond to potential security threats and reduce the risks caused by user abuse of authority; in summary, based on the above scheme, the user's access rights can be trusted and constrained in combination with different network event scenarios in the Internet of Things, thereby improving the security of network communications in the Internet of Things. BRIEF DESCRIPTION OF THE DRAWINGS

[0043] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative labor.

[0044] Figure 1 is an exemplary flow chart of a method for constraining Internet of Things security permissions according to some embodiments of the present application;

[0045] Figure 2 It is a structural diagram of the Internet of Things shown in some embodiments of the present application;

[0046] Figure 3 It is a schematic diagram of a process for determining a security baseline according to some embodiments of the present application;

[0047] Figure 4 is a schematic diagram of the structure of a permission constraint unit according to some embodiments of the present application;

[0048] Figure 5 It is a structural diagram of a computer device for implementing the method for constraining Internet of Things security permissions according to some embodiments of the present application. DETAILED DESCRIPTION

[0049] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.

[0050] In order to better understand the technical solution of the present application, the technical solution of the present application will be described in detail below in conjunction with the accompanying drawings and specific implementation methods.

[0051] refer to Figure 1 , which is an exemplary flow chart of a method for constraining Internet of Things security permissions according to some embodiments of the present application, and the method for constraining Internet of Things security permissions mainly includes the following steps:

[0052] In step 101, the network devices connected to the Internet of Things are monitored in real time, and the historical access records of the network devices within a specified time period are collected, and then the authorization feedback information of the network devices in various network event scenarios is determined through the historical access records.

[0053] It should be noted that in this application, historical access records represent the record data of access requests of network devices within a specified time period; in specific implementation, network devices connected to the Internet of Things are monitored in real time, and a collection of access requests of network devices within a specified time period (the default is the most recent month) is collected as historical access records. Each access request contains access scenarios, access results, access rights and access duration.

[0054] In some embodiments, reference Figure 2 , this figure is a structural diagram of the Internet of Things shown in some embodiments of the present application, and the figure depicts the three-layer architecture of the Internet of Things. The three-layer architecture works together to realize the entire process of the Internet of Things from data collection, transmission to processing and application. The perception layer is responsible for data collection, the network transmission layer ensures the effective transmission of data, and the processing application layer performs in-depth processing on the data and provides intelligent services. This layered design not only improves the flexibility and scalability of the Internet of Things system, but also allows each layer to be independently optimized to meet the ever-changing technical and business needs, and together constitute a complete Internet of Things system.

[0055] The bottom layer is the perception layer, which is the data collection front end of the Internet of Things. The perception layer mainly includes RFID systems and RFID readers, which are used to identify and read RFID tags attached to objects to obtain relevant information of the objects; the network transmission layer is located above the perception layer. The function of the network transmission layer is to transmit the data collected by the perception layer to the processing application layer. The network transmission layer includes various network types, such as telecommunications network / Internet, private network and mobile communication network; the processing application layer is the intelligent core of the Internet of Things. The processing application layer includes intelligent processing, data storage and computing services. Intelligent processing involves analyzing and processing the collected data to extract useful information and knowledge. Data storage is responsible for saving the processed data for subsequent query and analysis. Computing services provide the necessary computing resources to support complex data processing and intelligent decision-making. The goal of the processing application layer is to convert raw data into valuable information and provide users with intelligent services and applications.

[0056] In some embodiments, determining the authorization feedback information of the network device in each network event scenario through the historical access record can be implemented by the following steps:

[0057] For each network event scenario, filter out access data of the network event scenario from the historical access records;

[0058] determining authorization success rate, access privilege level, and response time based on the access data;

[0059] The authorization success rate, the access permission level and the response time are used as authorization feedback information of the network device in a network event scenario, thereby obtaining authorization feedback information of the network device in each network event scenario.

[0060] It should be noted that in this application, authorization feedback information is reference information used to judge and feedback permission policies in authorization decisions; network event scenarios refer to specific situations of network devices under different access conditions, and the network event scenarios are used to associate changes in access behavior and authorization modes of associated devices; access permission levels refer to the scope of permissions granted to users in network event scenarios, such as read-only, read-write, and management permissions, etc., which are used to determine the scope of user control over device resources.

[0061] In specific implementation, first, for each network event scenario, a set of all access requests whose access scenarios are consistent with the network event scenarios is screened from historical access records as access data; then, the number of all access requests is counted as the total number of authorizations, and the number of access requests with successful access results is counted as the number of successful authorizations. The ratio of the number of successful authorizations to the total number of authorizations can be used as the authorization success rate, and a classification algorithm (such as K-means or a rule-based classification method) can be used to statistically classify each access request in the access data according to its access rights, thereby dividing the rights into multiple permission levels, and the set of all permission levels can be used as the value range of the access right level, and the ratio of the mean access time in all access requests in the access data to the total number of authorizations can be used as the response time; finally, the set of the authorization success rate, the access right level and the response time can be used as the authorization feedback information of the network device in the network event scenario. The authorization feedback information of the network device in each network event scenario can be obtained in the above manner.

[0062] In step 102, when a user sends a network communication request to a network device, the user's historical network behavior is collected, and the user's trust index during network interaction is determined based on the historical network behavior. The security baseline of the network device's authorization to the user is then determined through the trust index and all authorization feedback information.

[0063] It should be noted that historical network behavior refers to all behavioral records of users interacting with network devices within a certain period of time in the past; in specific implementation, when a user sends a network communication request to a network device, a collection of interaction behaviors between the user and the network device within a specified time period is collected as the user's historical network behavior, and the interaction behavior includes request content, access time, and result feedback.

[0064] In some embodiments, determining the trust index of the user in network interaction according to the historical network behavior can be implemented by the following steps:

[0065] Determine the user's network interaction frequency through the historical network behavior;

[0066] Extracting all abnormal behaviors of the user from the historical network behaviors, and then determining the behavior frequency of each abnormal behavior;

[0067] The trust index of the user during network interaction is determined according to the network interaction frequency and all behavior frequencies.

[0068] It should be noted that in this application, the trust index is an indicator used to measure the degree of trustworthiness of users in network interactions; the network interaction frequency indicates the number of times a user interacts with a network device within a specific time period; abnormal behavior refers to behavior that deviates from the user's normal access pattern, which includes frequent failed requests, abnormal request content, or a large number of access requests in a short period of time; the behavior frequency indicates the proportion of abnormal behavior in total access.

[0069] In specific implementation, first, the ratio of the number of interactions in historical network behaviors to the number of seconds in a specified time period can be used as the user's network interaction frequency; then, the interaction behaviors with abnormal results in historical network behaviors are used as abnormal behaviors of the user, and the interaction behaviors with the same request content and access time intervals less than a preset normal interval threshold in historical network behaviors are also used as abnormal behaviors, so that all abnormal behaviors of the user can be obtained. For each abnormal behavior, the number of all interaction behaviors with the same request content as the abnormal behavior in the historical network behaviors can be counted as the behavior frequency of the abnormal behavior. The behavior frequency of each abnormal behavior can be obtained in the above manner; finally, the inverse of the ratio of the mean of all behavior frequencies to the network interaction frequency is used as the user's trust index during network interaction.

[0070] In some embodiments, the security baseline of the network device for user authorization is determined by the trust index and all authorization feedback information, referring to Figure 3 The figure is a schematic diagram of a process for determining a security baseline in some embodiments of the present application. In this embodiment, determining the security baseline can be implemented by the following steps:

[0071] In step 1021, for each network event scenario, the authorization security of the network device in the network event scenario is determined according to the authorization feedback information of the network device in the network event scenario;

[0072] In step 1022, the scenario security value of the network device authorizing the user in the network event scenario is determined by the authorization security and the trust index, and then the scenario security value of the network device authorizing the user in each network event scenario is obtained;

[0073] In step 1023, a security baseline for the network device to authorize the user is determined based on all scenario security values.

[0074] It should be noted that in this application, the security baseline is the minimum security authorization level of the network device for the user in the network event scenario; the scenario security value refers to the security baseline value authorized by the network device to the user in each network event scenario; and the authorization security represents the security authorization level of the network device in each network event scenario.

[0075] In specific implementation, first, for each network event scenario, the authorization security of the network device in the network event scenario can be obtained by multiplying the authorization success rate in the authorization feedback information of the network device in the network event scenario by the access permission level and the ratio of the response time; then, the product of the authorization security and the trust index can be used as the scenario security value of the network device authorizing the user in the network event scenario. The scenario security value of the network device authorizing the user in each network event scenario can be obtained in the above manner; finally, the ratio of the number of access requests in each network event scenario in the historical access records to the total number of authorizations is used as the weight of the corresponding scenario security value, and the weighted value of all scenario security values ​​is calculated. The minimum value of all weighted values ​​can be used as the security baseline for the network device to authorize the user.

[0076] In step 103, the event correlation between each network event scenario and the network communication request is determined based on the feature matching mechanism, and the behavior credibility of the network device authorized in the network communication request is determined according to the event correlation and the network fluctuation characteristics of the network device, and then the user's event response authority in the network communication request is predicted through the behavior credibility and each authorization feedback information.

[0077] In some embodiments, determining the event correlation between each network event scenario and the network communication request based on the feature matching mechanism can be implemented by the following steps:

[0078] For each network event scenario, extract event features from the network event scenario;

[0079] extracting a communication request feature from the network communication request;

[0080] Based on the feature matching mechanism, feature matching is performed on the event feature and the communication request feature to obtain the event correlation between the network event scenario and the network communication request, and then obtain the event correlation between each network event scenario and the network communication request.

[0081] It should be noted that, in the present application, event relevance refers to the degree of correlation between communication request characteristics and various network event scenarios; communication request characteristics refer to the key information contained when a user issues a network communication request, and the communication request characteristics include source information, target information, data type, and request method. The communication request characteristics are used to determine whether the request is related to a specific event scenario; event characteristics refer to key attribute information of a network event scenario.

[0082] In the specific implementation, first, for each network event scenario, the access IP, port number, protocol type and operation content can be extracted from the event log of the network event scenario as event features; then, the source information, target information, data type and request method can be extracted from the parsed package of the network communication request as communication request features; finally, a feature matching model based on the feature matching mechanism is initialized, and the event features and communication request features are used as matching objects of the feature matching model. The feature matching model is used to perform feature matching, and the result of feature matching can be used as the event correlation between the network event scenario and the network communication request. The event correlation between each network event scenario and the network communication request can be obtained in the above manner.

[0083] In some embodiments, determining the credibility of the authorized behavior of the network device in the network communication request according to the correlation of each event and the network fluctuation characteristics of the network device can be implemented by the following steps:

[0084] For each network event scenario, obtaining an event correlation between the network event scenario and the network communication request;

[0085] Determining the response adaptability between the network communication request and the network event scenario according to the event correlation and the network fluctuation characteristics of the network device, and then obtaining the response adaptability between the network communication request and each network event scenario;

[0086] The credibility of the authorized behavior of the network device in the network communication request is determined through all response adaptability.

[0087] It should be noted that in this application, behavior credibility refers to the degree of credibility of the network device in the user's authorized behavior under the network communication request; response adaptability refers to the adaptability of the response of various network event scenarios in the network device to the network communication request; network fluctuation characteristics refer to the volatility of network performance parameters in the network device. The fluctuation characteristics can be obtained through a large number of experiments. Network performance parameters such as delay and packet loss, etc., the standard deviation of all network performance parameters is normalized, and the result of the normalization can be used as the network fluctuation characteristics of the device in the current scenario.

[0088] In the specific implementation, first, for each network event scenario, the event correlation between the network event scenario and the network communication request is obtained; then, the normal value of the network fluctuation is obtained from the performance parameters of the network device, and the absolute value of the difference between the ratio of the network fluctuation characteristic to the normal value and 1 can be multiplied by the event correlation result as the response adaptability between the network communication request and the network event scenario. The response adaptability between the network communication request and each network event scenario can be obtained in the above manner; finally, the minimum value of all response adaptabilities can be used as the credibility of the behavior authorized by the network device in the network communication request.

[0089] In some embodiments, predicting the event response authority of the user in the network communication request by using the behavior credibility and each authorization feedback information can be implemented by the following steps:

[0090] Determine feedback consistency between the user and the network device based on all authorized feedback information;

[0091] Based on the feedback consistency and the behavior credibility, a regression prediction is performed on the user's authority in the network communication request to obtain the user's event response authority in the network communication request.

[0092] It should be noted that, in this application, event response authority refers to the level of response authority that a user can obtain under a network communication request; feedback consistency is used to measure the degree of authorization consistency of a user's behavior pattern under a network communication request.

[0093] In the specific implementation, first, the authorization security corresponding to each authorization feedback information is obtained, and the absolute value of the difference between the ratio of the standard deviation of all authorization security and the mean of all authorization security and 1 can be used as the feedback consistency between the user and the network device; then, a permission prediction model based on linear regression is initialized, and the feedback consistency after standardization can be used as the regression parameter of the permission prediction model, and the behavior credibility can be used as the regression coefficient of the permission prediction model. The permission prediction model is used to predict the user's permissions in the network communication request, and the predicted results of the permissions can be used as the event response permissions of the user in the network communication request.

[0094] In step 104, if the event response authority is greater than the security baseline, a trust constraint is imposed on the user's event response authority based on the security baseline.

[0095] In some embodiments, trust constraints on the user's event response permissions based on the security baseline can be implemented in the following manner, namely: using the existing permission constraint mechanism to proportionally constrain and downgrade the user's event response permissions until the event response permissions are less than or equal to the security baseline.

[0096] In this application, if the event response authority is greater than the security baseline, the user's event response authority is trusted based on the security baseline. First, by determining the security baseline, the minimum security authorization level of the network device for the user in the network event scenario can be obtained. When the user's request exceeds the security baseline, the Internet of Things can issue an alarm and implement restrictions in a timely manner, reducing the risk of abuse of authority. The mechanism of the security baseline can remain stable and secure when network communications are threatened, thereby enhancing the overall security of the Internet of Things environment. Among them, by determining the trust index, the Internet of Things can identify normal operations and abnormal operations in real time, thereby defending the subsequent guarantee that each user's access rights can be dynamically adjusted based on their historical behavior and current network event scenarios, ensuring that when an abnormality occurs, the Internet of Things can quickly Respond to and restrict the user's operations; then, determine the event response authority to obtain the response authority level that the user can obtain under the network communication request. Through event response authority, the Internet of Things can not only timely restrict operations that do not meet expectations, but also automatically adjust its authority when there is a deviation between the user request and the actual event. Among them, through the feature matching mechanism, the Internet of Things can quickly determine the correlation between the user's request and the specific network event scenario, thereby determining the user's operation authority in the network event scenario. The Internet of Things can flexibly respond to potential security threats and reduce the risks caused by user abuse of authority; in summary, based on the above scheme, the user's access rights can be trusted and constrained in combination with different network event scenarios in the Internet of Things, thereby improving the security of network communications in the Internet of Things.

[0097] In addition, in another aspect of the present application, in some embodiments, the present application provides an Internet of Things security management system, the Internet of Things security management system includes an authority constraint unit, reference Figure 4 , which is a schematic diagram of the structure of a permission constraint unit according to some embodiments of the present application, and the permission constraint unit includes: a monitoring module 201, a processing module 202 and an execution module 203, which are described as follows:

[0098] Monitoring module 201, in this application, monitoring module 201 is mainly used to monitor network devices connected to the Internet of Things in real time, collect historical access records of network devices within a specified time period, and then determine the authorization feedback information of the network devices in various network event scenarios through the historical access records;

[0099] Processing module 202, in the present application, is used to collect the user's historical network behavior when the user sends a network communication request to the network device, determine the user's trust index during network interaction based on the historical network behavior, and then determine the security baseline of the network device's authorization to the user through the trust index and all authorization feedback information;

[0100] It should be noted that the processing module 202 is also used to determine the event correlation between each network event scenario and the network communication request based on the feature matching mechanism, determine the behavior credibility of the network device authorized in the network communication request according to the correlation of each event and the network fluctuation characteristics of the network device, and then predict the user's event response authority in the network communication request through the behavior credibility and each authorization feedback information;

[0101] Execution module 203, in the present application, execution module 203 is mainly used to perform trust constraints on the user's event response authority based on the security baseline if the event response authority is greater than the security baseline.

[0102] The above describes in detail the examples of the Internet of Things security management system and method provided by the embodiments of the present application. It can be understood that in order to realize the above functions, the corresponding device includes hardware structures and / or software modules corresponding to the execution of each function. It should be easily appreciated by those skilled in the art that, in combination with the units and algorithm steps of each example described in the embodiments disclosed herein, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in the form of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.

[0103] In some embodiments, the present application also provides a computer device, comprising a memory and a processor, wherein the memory is used to store a computer program, and the processor is used to call and run the computer program from the memory, so that the computer device executes the above-mentioned Internet of Things security permission constraint method.

[0104] In some embodiments, reference Figure 5 , the dotted line in the figure indicates that the unit or the module is optional, and the figure is a schematic diagram of the structure of a computer device for implementing the method for restricting the security rights of the Internet of Things according to an embodiment of the present application. The method for restricting the security rights of the Internet of Things described in the above embodiment can be Figure 5 The computer device shown in the figure is implemented, and the computer device includes at least one processor 301, a memory 302 and at least one communication unit 305. The computer device can be a terminal device, a server or a chip.

[0105] The processor 301 may be a general-purpose processor or a special-purpose processor. For example, the processor 301 may be a central processing unit (CPU), which may be used to control the computer device, execute software programs, and process data of the software programs. The computer device may also include a communication unit 305 to implement signal input (reception) and output (transmission).

[0106] For example, the computer device may be a chip, the communication unit 305 may be an input and / or output circuit of the chip, or the communication unit 305 may be a communication interface of the chip, and the chip may be a component of a terminal device, a network device, or other devices.

[0107] For another example, the computer device may be a terminal device or a server, and the communication unit 305 may be a transceiver of the terminal device or the server, or the communication unit 305 may be a transceiver circuit of the terminal device or the server.

[0108] The computer device may include one or more memories 302, on which a program 304 is stored. The program 304 can be executed by the processor 301 to generate instructions 303, so that the processor 301 performs the method described in the above method embodiment according to the instructions 303. Optionally, data (such as a target audit model) can also be stored in the memory 302. Optionally, the processor 301 can also read the data stored in the memory 302, and the data can be stored at the same storage address as the program 304, or the data can be stored at a different storage address from the program 304.

[0109] The processor 301 and the memory 302 may be provided separately or integrated together, for example, integrated on a system on chip (SOC) of the terminal device.

[0110] It should be understood that each step of the above method embodiment can be completed by a hardware-based logic circuit or software-based instructions in the processor 301. The processor 301 can be a CPU, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), or other programmable logic devices, such as discrete gates, transistor logic devices, or discrete hardware components.

[0111] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present application may adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program codes.

[0112] For example, in some embodiments, the present application also provides a computer-readable storage medium, in which instructions or codes are stored. When the instructions or codes are executed on a computer, the computer implements the above-mentioned Internet of Things security permission constraint method when executing.

[0113] Although the preferred embodiments of the present application have been described, those skilled in the art may make other changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications falling within the scope of the present application.

[0114] Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalents, the present application is also intended to include these modifications and variations.

Claims

1. A method for constraining security permissions in the Internet of Things, characterized in that: The steps include: Real-time monitoring of network devices connected to the Internet of Things, collecting historical access records of network devices within a specified time period, and then determining the authorization feedback information of network devices in various network event scenarios through the historical access records; When a user sends a network communication request to a network device, the user's historical network behavior is collected, and the user's trust index during network interaction is determined based on the historical network behavior, and then the security baseline of the network device's authorization to the user is determined through the trust index and all authorization feedback information; Determine the event correlation between each network event scenario and the network communication request based on the feature matching mechanism, determine the behavior credibility of the network device in the network communication request according to each event correlation and the network fluctuation characteristics of the network device, and then predict the event response authority of the user in the network communication request through the behavior credibility and each authorization feedback information; If the event response authority is greater than the security baseline, trust constraints are imposed on the user's event response authority based on the security baseline.

2. The method according to claim 1, characterized in that Determining the authorization feedback information of the network device in each network event scenario through the historical access record specifically includes: For each network event scenario, filter out access data of the network event scenario from the historical access records; determining authorization success rate, access privilege level, and response time based on the access data; The authorization success rate, the access permission level and the response time are used as authorization feedback information of the network device in a network event scenario, thereby obtaining authorization feedback information of the network device in each network event scenario.

3. The method according to claim 1, characterized in that Determining the trust index of the user during network interaction according to the historical network behavior specifically includes: Determine the user's network interaction frequency through the historical network behavior; Extracting all abnormal behaviors of the user from the historical network behaviors, and then determining the behavior frequency of each abnormal behavior; The trust index of the user during network interaction is determined according to the network interaction frequency and all behavior frequencies.

4. The method according to claim 1, characterized in that Determining the security baseline of the network device's authorization to the user through the trust index and all authorization feedback information specifically includes: For each network event scenario, determining the authorization security of the network device in the network event scenario according to the authorization feedback information of the network device in the network event scenario; Determine the scenario security value of the network device authorizing the user in the network event scenario through the authorization security and the trust index, and then obtain the scenario security value of the network device authorizing the user in each network event scenario; Determine the security baseline for network devices to authorize users based on the security values ​​of all scenarios.

5. The method according to claim 1, characterized in that Determining the event correlation between each network event scenario and the network communication request based on the feature matching mechanism specifically includes: For each network event scenario, extract event features from the network event scenario; extracting a communication request feature from the network communication request; Based on the feature matching mechanism, feature matching is performed on the event feature and the communication request feature to obtain the event correlation between the network event scenario and the network communication request, and then obtain the event correlation between each network event scenario and the network communication request.

6. The method according to claim 1, characterized in that Determining the credibility of the behavior authorized by the network device in the network communication request according to the correlation of each event and the network fluctuation characteristics of the network device specifically includes: For each network event scenario, obtaining an event correlation between the network event scenario and the network communication request; Determining the response adaptability between the network communication request and the network event scenario according to the event correlation and the network fluctuation characteristics of the network device, and then obtaining the response adaptability between the network communication request and each network event scenario; The credibility of the authorized behavior of the network device in the network communication request is determined through all response adaptability.

7. The method according to claim 1, characterized in that Predicting the event response authority of the user in the network communication request by using the behavior credibility and each authorization feedback information specifically includes: Determine feedback consistency between the user and the network device based on all authorized feedback information; Based on the feedback consistency and the behavior credibility, a regression prediction is performed on the user's authority in the network communication request to obtain the user's event response authority in the network communication request.

8. An Internet of Things security management system, comprising an authority constraint unit, characterized in that: The authority constraint unit includes: A monitoring module is used to monitor network devices connected to the Internet of Things in real time, collect historical access records of network devices within a specified time period, and then determine the authorization feedback information of network devices in various network event scenarios through the historical access records; A processing module, used for collecting the user's historical network behavior when the user sends a network communication request to the network device, determining the user's trust index during network interaction based on the historical network behavior, and then determining the security baseline of the network device's authorization to the user through the trust index and all authorization feedback information; The processing module is also used to determine the event correlation between each network event scenario and the network communication request based on a feature matching mechanism, determine the behavior credibility of the network device in the network communication request according to the correlation of each event and the network fluctuation characteristics of the network device, and then predict the event response authority of the user in the network communication request through the behavior credibility and each authorization feedback information; The execution module is used to perform trust constraints on the user's event response authority based on the security baseline if the event response authority is greater than the security baseline.

9. A computer device, characterized in that: The computer device includes a memory and a processor, the memory is used to store a computer program, and the processor is used to call and run the computer program from the memory, so that the computer device executes the Internet of Things security authority constraint method described in any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores instructions or codes, and when the instructions or codes are executed on a computer, the computer implements the Internet of Things security authority constraint method as described in any one of claims 1 to 7.

Citation Information

Patent Citations

  • Dynamic access control method and system based on programmable network

    CN116846642A

  • Access control strategy self-adaption method and system based on attribute trust

    CN117371007A