An Internet of Things device networking security auditing method, system, device and medium

By obtaining operation mode and network traffic data in the Internet of Things device networking, building a dynamic security baseline, analyzing network traffic using deep learning models, and dynamically adjusting security strategies, the problem of poor flexibility in the existing IoT device security audit mechanism is solved, and security early warning and response efficiency is improved.

CN119675986BActive Publication Date: 2025-05-30SHENZHEN TG NET BOTONE TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510175143.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-18
Publication Date
2025-05-30
Estimated Expiration
2045-02-18

AI Technical Summary

Technical Problem

The security audit mechanism of existing IoT devices is poor in flexibility and lacks adaptability, making it difficult to effectively deal with complex and changing network environments and emerging attack methods, resulting in inefficient security warning and response.

Method used

A security audit method for networking of IoT devices is adopted. By obtaining the operating mode data of the device and network traffic data, identifying the normal behavior patterns of the device, building a dynamic security baseline, analyzing network traffic using deep learning models, evaluating risk levels, generating a security policy comparison table and adjustment model, and dynamically adjusting security strategies to improve security protection effects.

Benefits of technology

Real-time monitoring and dynamic security management of IoT device networking are realized, potential security threats can be discovered in a timely manner, security warning and response efficiency are improved, and system is in the best security protection state.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119675986B_ABST
    Figure CN119675986B_ABST
Patent Text Reader

Abstract

The present application discloses an Internet of Things device networking security auditing method, system, device and medium, relating to the field of Internet of Things security technologies. The method includes identifying the normal behavior patterns of devices according to the obtained operation mode data and network traffic data, and constructing a dynamic security baseline; analyzing the network traffic of the target Internet of Things device networking by using a deep learning model, and evaluating the risk level of each data stream according to the dynamic security baseline; generating a security policy comparison table according to the risk level; obtaining a security policy adjustment reference range representing the security policy adjustment threshold, and generating a security policy adjustment model according to the security policy adjustment reference range and the security policy comparison table; obtaining the current network traffic data and inputting it into the security policy adjustment model; adjusting the security policy of the target Internet of Things device networking based on the calculated device security risk data. The Internet of Things security auditing mechanism of the present application can adapt to dynamic environments and new attacks, and improve the security warning and response efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of Internet of Things security technologies, and in particular, to a method, system, device, and medium for network security auditing of Internet of Things devices. Background Art

[0002] With the wide application of Internet of Things technologies, the security issues of Internet of Things devices have become increasingly prominent. In particular, illegal access and network attack incidents occur frequently, affecting the stable operation and data security of Internet of Things systems. Currently, Internet of Things security protection technologies mainly include measures such as device identity authentication, encrypted transmission, and access control. However, in a large-scale heterogeneous device networking environment, there is a lack of an effective security auditing mechanism, making it difficult to monitor network status and abnormal behaviors in real time.

[0003] Existing Internet of Things devices generally use a static security auditing strategy based on rule matching, relying on preset security rules to detect potential threats. However, this static strategy is difficult to cope with the dynamically changing Internet of Things environment and cannot detect new attack patterns in a timely manner, resulting in a lag in security response and easy to cause security risks.

[0004] In summary, the existing Internet of Things security auditing mechanism has poor flexibility and insufficient adaptability, making it difficult to effectively cope with complex and changing network environments and emerging attack techniques, resulting in low security warning and response efficiency, and urgently needs to be improved. Summary of the Invention

[0005] In order to solve the problem that the existing Internet of Things security auditing mechanism is difficult to adapt to dynamic environments and new attacks and improve the security warning and response efficiency, the present application provides a method, system, device, and medium for network security auditing of Internet of Things devices.

[0006] In a first aspect, the inventive object of the present application is achieved by adopting the following technical solution:

[0007] A method for network security auditing of Internet of Things devices includes:

[0008] Obtaining operation mode data and network traffic data of devices in a target Internet of Things device network;

[0009] Identifying normal behavior patterns of devices according to the operation mode data and network traffic data, and constructing corresponding dynamic security baselines;

[0010] Analyzing the network traffic of the target Internet of Things device network by using a deep learning model, and evaluating the risk level of each data stream according to the dynamic security baseline;

[0011] Generate a security policy comparison table for adjusting security policies according to the risk level; and obtain a security policy adjustment reference range representing the security policy adjustment threshold, and generate a security policy adjustment model according to the security policy adjustment reference range and the security policy comparison table;

[0012] Obtain the current network traffic data, input the current network traffic data into the security policy adjustment model, calculate the device security risk data of the entire target Internet of Things device network, and adjust the security policy of the target Internet of Things device network based on the device security risk data.

[0013] By adopting the above technical solution, the operation mode data of the device includes the operation status of the device and the skin containment parameter wind, and the network traffic data is used to reflect the communication situation between devices in the target Internet of Things device network. Through the operation mode data and the network traffic data, the actual operation situation of the device in the network can be comprehensively understood, the normal behavior mode of the device (also known as the standard and typical behavior mode) can be identified, and a dynamic security baseline can be constructed to provide a benchmark for the subsequent security assessment of the Internet of Things device; by using the deep learning model to analyze the network traffic data, real-time analysis of the Internet of Things device network is carried out to identify abnormal behaviors, and the risk levels of each data stream and data packet are evaluated through the dynamic security baseline to discover potential security threats in a timely manner; by comparing the risk level of each data stream with the preset security policy, a security policy comparison table is generated, and the security policy comparison table helps to clarify the specific security measures corresponding to different risk levels; then, by defining the threshold range of security policy adjustment and combining the security policy comparison table, a security policy adjustment model is generated to dynamically adjust the security policy according to the real-time risk data, ensuring that the system of the target Internet of Things device network is in the best security protection state and improving the security warning and response efficiency; thus, through the security audit prevention mechanisms such as comprehensive monitoring, dynamic security baseline, real-time analysis, flexible adjustment, and efficient protection, this application solves the problem that the existing Internet of Things security audit mechanism is difficult to adapt to the dynamic environment and new attacks, and improves the security warning and response efficiency.

[0014] In a preferred example of this application: The obtaining the current network traffic data, inputting the current network traffic data into the security policy adjustment model, and calculating the device security risk data of the entire target Internet of Things device network includes:

[0015] Obtain the current network traffic data, and input the current network traffic data into the security policy adjustment model;

[0016] In the security policy adjustment model, combine the network topology structure and device basic information of the target Internet of Things network to determine the audit scope;

[0017] Evaluate the device security performance of each Internet of Things device within the audit scope according to the preset security audit factors to obtain the corresponding device security index;

[0018] According to the device security index and combined with the device connection relationship in the network topology structure, analyze and calculate the security risk data of the entire target Internet of Things network.

[0019] By adopting the above technical solution, the current network traffic data is obtained in real time, ensuring the timeliness and accuracy of the data during the security audit analysis. Analyzing the real-time data using the security policy adjustment model ensures the real-time and dynamic nature of the security audit; and by combining the network topology structure and device basic information, the key areas and critical devices for auditing are identified, improving the pertinence and efficiency of the audit. Through the preset security audit factors, a comprehensive security performance evaluation is carried out on each Internet of Things device to obtain a detailed device security index, and then based on multi-factor comprehensive evaluation, the reliability and practicality of the security management and risk assessment of the Internet of Things device network are improved.

[0020] In a preferred example of the present application: the security risk data includes device behavior risk data and network traffic risk data; the analysis and calculation of the security risk data of the entire target Internet of Things network according to the device security index and combined with the device connection relationship in the network topology structure includes:

[0021] Generate multiple device behavior units in the Internet of Things environment of the target Internet of Things device network based on the device security index, the operation mode data, and the device connection relationship in the network topology structure;

[0022] Taking each device behavior unit as a basic unit, conduct device behavior analysis according to the preset first evaluation factor to obtain the corresponding device behavior score, and calculate the corresponding device behavior risk data according to the device behavior score;

[0023] Taking each device behavior unit as a basic unit, conduct network traffic analysis according to the preset second evaluation factor to obtain the corresponding network traffic score, and calculate the corresponding network traffic risk data according to the network traffic score;

[0024] Generate a comprehensive security audit result based on the device behavior risk data and network traffic risk data corresponding to each device behavior unit.

[0025] By adopting the above technical solution, multiple device behavior units are generated by combining the device security index, the operation mode data, and the device connection relationship in the network topology structure, ensuring the accuracy and meticulousness of device behavior analysis and being able to more comprehensively reflect the behavior patterns of devices during actual operation; through the preset first evaluation factor, a comprehensive behavior analysis is carried out on each device behavior unit to obtain a detailed device behavior score, which can evaluate the behavior risks of devices from multiple dimensions and ensure the comprehensiveness of risk assessment; through the preset second evaluation factor, a comprehensive analysis is carried out on the network traffic of each device behavior unit to obtain a detailed network traffic score, which can evaluate the risks of network traffic from multiple dimensions. The comprehensive security audit results provide a scientific basis for the security management and risk prevention and control of the Internet of Things system, enhancing the overall security of the Internet of Things system.

[0026] In a preferred example of the present application: generating multiple device behavior units in the Internet of Things environment formed by the target Internet of Things devices networking based on the device security index, the operation mode data, and the device connection relationship in the network topology structure specifically includes:

[0027] Performing data preprocessing on the device operation mode data and the network topology structure data in the Internet of Things environment to obtain preprocessed device operation mode data and device connection relationship data;

[0028] Generating a device behavior pattern diagram based on the preprocessed device operation mode data;

[0029] Calculating the correlation degree data between devices according to the device behavior pattern diagram and the device connection relationship data to generate a device connection relationship diagram;

[0030] Generating initial device behavior units according to the device connection relationship diagram and the preprocessed device operation mode data;

[0031] Correcting the initial device behavior units according to the device security index and the device connection relationship data to form the final device behavior units.

[0032] By adopting the above technical solutions, data preprocessing eliminates noise and redundant data, ensuring the accuracy and efficiency of subsequent analysis; by generating device behavior pattern diagrams, the operating modes of devices are visually displayed, and through visualization methods, it helps supervisors and machine learning algorithms quickly identify the normal and abnormal behavior patterns of devices. Then, by generating initial device behavior units, the devices in the Internet of Things environment are divided into multiple fine-grained behavior units, and each unit contains a group of devices with similar behavior patterns, making the objects of security audit more specific and refined, improving the accuracy and efficiency of audit; finally, by combining device security indices and device connection relationship data, the initial device behavior units are corrected to ensure the accuracy and representativeness of each behavior unit. The finally formed device behavior units can better reflect the true behavior patterns of devices, providing a reliable basis for subsequent risk assessment.

[0033] In a preferred example of the present application: taking each device behavior unit as a basic unit, device behavior analysis is performed according to a preset first evaluation factor to obtain corresponding device behavior scores, and corresponding device behavior risk data is calculated according to the device behavior scores, specifically including:

[0034] The first evaluation factor includes device type, device online time, device online duration, device communication frequency, device data transmission volume, and the number of device abnormal behaviors;

[0035] The device behavior units in the Internet of Things environment are evenly divided to determine all devices involved in a single device behavior unit, and each device within the single device behavior unit is assigned a value according to the first evaluation factor to obtain a first device score;

[0036] The arithmetic mean of the first device scores of all devices involved in a single device behavior unit is calculated to obtain the discriminant score of the first evaluation factor for the single device behavior unit, and the device behavior score is calculated using the discriminant score of the first evaluation factor and the comprehensive index method;

[0037] Corresponding device behavior risk data is calculated according to the device behavior score;

[0038] Or,

[0039] The calculation of the corresponding device behavior risk data according to the device behavior score specifically includes:

[0040] Historical security event data is obtained, and the abnormal probability data of the device behavior unit is obtained based on the historical security event data; the device behavior risk data is calculated using the device behavior score and the abnormal probability data of the device behavior unit.

[0041] By adopting the above technical solution, multiple dimensions of the first evaluation factors are introduced, which can comprehensively evaluate the behavior characteristics of the device, ensuring the accuracy and reliability of device behavior analysis. The first evaluation factors cover the basic attributes and behavior characteristics of the Internet of Things devices, and can effectively identify the normal and abnormal behaviors of the devices; by evenly dividing the device behavior units, it is ensured that the number of devices in each unit is appropriate for refined analysis. Each device is assigned a value according to the first evaluation factors to obtain the first device score; the discriminant score of the first evaluation factors of the device behavior units is calculated by arithmetic mean, and then the comprehensive index method is used to calculate the device behavior score, ensuring the scientificity and objectivity of the scoring result, comprehensively considering the influence of multiple first evaluation factors, and improving the accuracy of the scoring result; further, through the device behavior score, the device behavior risk data is calculated, which can quantitatively evaluate the risk degree of the device behavior, help identify high-risk device behavior units, take preventive measures in advance, and reduce the security risk.

[0042] In a preferred example of the present application: taking each device behavior unit as a basic unit, network traffic analysis is carried out according to a preset second evaluation factor to obtain a corresponding network traffic score, and corresponding network traffic risk data is calculated according to the network traffic score, which specifically includes:

[0043] The second evaluation factor includes network traffic size, peak traffic time, traffic direction, protocol type, packet length, and abnormal traffic ratio;

[0044] The device behavior units in the Internet of Things environment are evenly divided to determine all network connections involved in a single device behavior unit, and each network connection in the single device behavior unit is assigned a value according to the second evaluation factor to obtain a second network connection score;

[0045] The arithmetic mean of the second network connection scores of all network connections involved in a single device behavior unit is calculated to obtain the discriminant score of the second evaluation factor of the single device behavior unit, and the network traffic score is calculated by using the discriminant score of the second evaluation factor and the comprehensive index method;

[0046] Corresponding network traffic risk data is calculated according to the network traffic score.

[0047] By adopting the above technical solutions, multiple dimensions of second evaluation factors are introduced, which can comprehensively evaluate the characteristics of network traffic, ensure the accuracy and comprehensiveness of network traffic analysis. The multiple second evaluation factors cover the basic attributes and abnormal characteristics of network traffic, and can effectively identify normal traffic and abnormal traffic. By evenly dividing the network connections within the device behavior unit, it is ensured that the number of network connections within each unit is appropriate for refined analysis; each network connection is assigned a value according to the second evaluation factor to obtain the second network connection score; the discriminant score of the second evaluation factor of the device behavior unit is calculated by arithmetic mean, and then the comprehensive index method is used to calculate the network traffic score to ensure the scientificity and objectivity of the scoring result. Through the network traffic score, network traffic risk data is calculated, and the risk degree of network traffic can be quantitatively evaluated.

[0048] In a preferred example of the present application: generating a comprehensive security audit result based on the device behavior risk data and network traffic risk data corresponding to each device behavior unit specifically includes:

[0049] Taking each device behavior unit as a basic unit, inputting the corresponding device behavior risk data as row vector data and the corresponding network traffic risk data as column vector data into a preset security risk discriminant matrix to obtain the corresponding security risk level data;

[0050] Generating a comprehensive security audit result of the Internet of Things networking according to the security risk level data corresponding to each device behavior unit.

[0051] In a second aspect, the invention object of the present application is achieved by adopting the following technical solutions:

[0052] An Internet of Things device networking security audit system, the system includes:

[0053] A data acquisition module, configured to acquire the operation mode data and network traffic data of devices in a target Internet of Things device networking; a dynamic security baseline construction module, configured to identify the normal behavior mode of the devices according to the operation mode data and network traffic data, and construct a corresponding dynamic security baseline;

[0054] A risk assessment module, configured to analyze the network traffic of the target Internet of Things device networking by using a deep learning model, and evaluate the risk level of each data stream according to the dynamic security baseline;

[0055] A security policy generation module, configured to generate a security policy comparison table for adjusting security policies according to the risk level, and obtain a security policy adjustment reference range representing the security policy adjustment threshold, and generate a security policy adjustment model according to the security policy adjustment reference range and the security policy comparison table;

[0056] A security audit module, which is used to obtain current network traffic data, input the current network traffic data into the security policy adjustment model, calculate the device security risk data of the entire target Internet of Things device network, and adjust the security policy of the target Internet of Things device network based on the device security risk data.

[0057] In a third aspect, the invention object of the present application is achieved by the following technical solutions:

[0058] A computer device includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps of the above-mentioned security audit method for an Internet of Things device network are implemented.

[0059] In a fourth aspect, the invention object of the present application is achieved by the following technical solutions:

[0060] A computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the above-mentioned security audit method for an Internet of Things device network are implemented.

[0061] In summary, the present application includes at least one of the following beneficial technical effects:

[0062] 1. By comparing the risk level of each data stream with the preset security policy, a security policy comparison table is generated. The security policy comparison table helps to clarify the specific security measures corresponding to different risk levels; then, by defining the threshold range for security policy adjustment and combining the security policy comparison table, a security policy adjustment model is generated to dynamically adjust the security policy according to real-time risk data, ensuring that the system of the target Internet of Things device network is in the best security protection state and improving the security warning and response efficiency; 2. Inputting the device behavior risk data and network traffic risk data as row vectors and column vectors into the preset security risk discrimination matrix can systematically evaluate the security risks of each device behavior unit. The security risk discrimination matrix can calculate the security risk level data of each device behavior unit according to the device behavior risk data and network traffic risk data, and the security risk level data can reflect the risk level of each device behavior unit in detail, providing an accurate basis for subsequent security management. BRIEF DESCRIPTION OF THE DRAWINGS

[0063] Figure 1 is a flowchart of a security audit method for an Internet of Things device network in an embodiment of the present application;

[0064] Figure 2 is a flowchart of step S5 in a security audit method for an Internet of Things device network in an embodiment of the present application;

[0065] Figure 3 It is a schematic diagram of the device in an embodiment of the present application. Detailed implementation manners

[0066] The present application will be further described in detail below with reference to the accompanying drawings.

[0067] In one embodiment, as Figure 1 shown, the present application discloses a method for network security auditing of Internet of Things devices, which specifically includes the following steps:

[0068] S1: Obtain the operation mode data and network traffic data of the devices in the target Internet of Things device network.

[0069] In this embodiment, the operation mode data includes information such as the working state, operation logs, and device configurations of the Internet of Things devices; the network traffic data includes information such as the data transfer volume, transfer time, and transfer frequency between the Internet of Things devices and between the Internet of Things devices and the external network.

[0070] Specifically, use network monitoring tools and log management systems to collect the operation mode data of the devices, and capture the network traffic data through network traffic analysis tools (such as Wireshark, NetFlow, etc.).

[0071] S2: According to the operation mode data and network traffic data, identify the normal behavior patterns of the devices and construct corresponding dynamic security baselines.

[0072] In this embodiment, the normal behavior pattern is the typical behavior pattern and regular behavior pattern of the Internet of Things devices, and the dynamic security baseline is a benchmark for subsequent security evaluation and anomaly detection.

[0073] Specifically, use statistical analysis methods (such as mean, standard deviation, etc.) and time series analysis methods (such as ARIMA model) to identify the normal behavior patterns of the devices; combine machine learning algorithms (such as clustering algorithms, decision trees, etc.) to further optimize the identification of the normal behavior patterns.

[0074] S3: Use a deep learning model to analyze the network traffic of the target Internet of Things device network, and evaluate the risk level of each data stream according to the dynamic security baseline.

[0075] In this embodiment, the security policy adjustment model is used to guide how to adjust the security policy according to the risk level. Specifically, select a suitable deep learning model (such as LSTM, CNN, etc.) for network traffic analysis. When training the model, use the known normal traffic and abnormal traffic data as the training set, and set the risk assessment criteria according to the dynamic security baseline. For example, the greater the degree of deviation from the baseline, the higher the risk level. Use the model to evaluate the real-time network traffic and output the risk level of each data stream.

[0076] S4: Generate a security policy comparison table for adjusting security policies according to the risk level; and obtain a security policy adjustment reference range representing the security policy adjustment threshold. Generate a security policy adjustment model based on the security policy adjustment reference range and the security policy comparison table.

[0077] In this embodiment, the security policy comparison table is a tool used to compare and verify security policies between different versions or different organizations to ensure the consistency and integrity of security policies.

[0078] Specifically, classify data streams into different levels (such as low risk, medium risk, high risk) according to the risk level, define corresponding security policy adjustment measures for each risk level, generate a security policy comparison table, and set the security policy adjustment threshold. For example, when the proportion of high-risk data streams exceeds a certain threshold, trigger the adjustment of security policies.

[0079] S5: Obtain the current network traffic data, input the current network traffic data into the security policy adjustment model, calculate the device security risk data of the entire target Internet of Things device network; adjust the security policy of the target Internet of Things device network based on the device security risk data.

[0080] In this embodiment, the adjustment measures may include but are not limited to adding firewall rules, restricting access permissions of certain devices, updating device firmware, etc.

[0081] In one embodiment, as Figure 2 shown, in step S5, obtain the current network traffic data, input the current network traffic data into the security policy adjustment model, and calculate the device security risk data of the entire target Internet of Things device network, including:

[0082] S51: Obtain the current network traffic data and input the current network traffic data into the security policy adjustment model.

[0083] In this embodiment, the current network traffic data includes information such as the data transfer volume, transfer time, and transfer frequency between devices.

[0084] S52: In the security policy adjustment model, combine the network topology structure and device basic information of the target Internet of Things network to determine the audit scope.

[0085] In this embodiment, obtain the network topology structure diagram of the target Internet of Things network, understand the connection relationship between devices, collect the basic information of each device. The device basic information includes device type, model, operating system, firmware version, etc. According to the network topology structure and device basic information, determine the devices and network connection scope that need to be audited for security, and input the determined audit scope into the security policy adjustment model for subsequent analysis and evaluation.

[0086] S53: Evaluate the device security performance of each IoT device within the audit scope according to the preset security audit factors to obtain a corresponding device security index.

[0087] In this embodiment, the security audit factors include, but are not limited to, the device's firmware version, security patch status, network connection security, encryption method, data privacy, and access control policy, etc., which can be customized according to specific needs.

[0088] Specifically, after determining several security review factors that affect the security of IoT devices, a scoring standard is designed for each security audit factor, and the evaluation results of each factor are quantified into scores. The scoring standard can be divided into several levels, for example:

[0089] Excellent (5 points): Fully complies with security requirements and has no known vulnerabilities.

[0090] Good (4 points): Most of the security requirements are met, with a few minor vulnerabilities.

[0091] General (3 points): basically meets security requirements, but has some moderate vulnerabilities.

[0092] Poor (2 points): Partially meets security requirements but has many serious vulnerabilities.

[0093] Poor (1 point): Does not meet security requirements and has major vulnerabilities.

[0094] Next, collect device-related information of the IoT device, including but not limited to device model and manufacturer, firmware version, current configuration, usage environment, known security issues and vulnerabilities, and then calculate the comprehensive security index of the device based on the determined security audit factors and scoring criteria. The weighted average method can be used to calculate the corresponding device security index.

[0095] S54: Based on the device security index and the device connection relationship in the network topology, the security risk data of the entire target IoT network is analyzed and calculated.

[0096] In this embodiment, the security risk data reflects the security status and potential risks of the entire network; the security index of each device is mapped to the network topology to form a device security index graph, the device connection relationship is analyzed, the critical paths and high-risk nodes are identified, and graph theory algorithms (such as the shortest path algorithm, the maximum flow algorithm, etc.) are used to analyze the connectivity and security of the network. The device security index and the network connection relationship are combined to calculate the security risk data of the entire network. The security risk data may include the overall risk score of the network, the risk score of the critical path, the risk score of the high-risk node, etc.

[0097] In this embodiment, the security audit method includes performing a detailed audit on each device according to the determined security audit factors and scoring criteria, and recording the audit results. The format of the audit result record is as follows:

[0098]

[0099] In one embodiment, in step S54, the security risk data includes device behavior risk data and network traffic risk data; according to the device security index, combined with the device connection relationship in the network topology, analyze and calculate the security risk data of the entire target Internet of Things network, including:

[0100] S541: Generate multiple device behavior units in the Internet of Things environment of the target Internet of Things device network based on the device security index, operation mode data, and device connection relationship in the network topology.

[0101] In this embodiment, a device behavior unit refers to a group of devices with the same or similar behavior characteristics in the Internet of Things environment. To address the situation of a large number of Internet of Things devices in the target Internet of Things device network and improve the audit effect of security audits, this application divides several Internet of Things devices with the same or similar characteristics in the Internet of Things environment into one device behavior unit.

[0102] Specifically, according to the device security index, operation mode data, and device connection relationship in the network topology, use clustering algorithms (such as K-means, DBSCAN, etc.) to group the devices and generate multiple device behavior units.

[0103] S542: Using each device behavior unit as a basic unit, perform device behavior analysis according to the preset first evaluation factor to obtain the corresponding device behavior score, and calculate the corresponding device behavior risk data based on the device behavior score.

[0104] In this embodiment, the first evaluation factor includes device type, device online time, device online duration, device communication frequency (referring to the number of communications of the device within a certain period of time), device data transmission volume, and the number of device abnormal behaviors (referring to the number of abnormal behaviors of the device within a certain period of time, such as frequent restart, communication interruption, etc.).

[0105] Specifically, use statistical analysis methods (such as mean, standard deviation, etc.) and time series analysis methods (such as ARIMA model) to analyze the device behavior of each device behavior unit, and score each device behavior unit according to the preset first evaluation factor weight and scoring criteria.

[0106] For example, statistical analysis is performed on the collected mechanical energy of device behavior data, such as calculating the average value and standard deviation of each device behavior data (the standard deviation evaluates the volatility of the data), plotting a histogram or box plot, and observing the data distribution; using time series analysis methods (such as the ARIMA model) to deeply analyze the device behavior data: select appropriate ARIMA model parameters (p, d, q), model the device behavior data, train the ARIMA model using historical data, and enable the trained model to predict future behavior data.

[0107] According to the preset first evaluation factor weights and scoring criteria, score each device behavior unit. First, set the weights: assign weights to each evaluation factor. For example: device type: 0.1, device online time: 0.1, device online duration: 0.2, device communication frequency: 0.2, device data transmission volume: 0.2, number of device abnormal behaviors: 0.2; then set the scoring criteria for each evaluation factor. For example: device type: common device type gets 1 point, special device type gets 2 points; device online time: those with an online time exceeding 1 year get 1 point, those less than 1 year get 0.5 points; device online duration: those with an average online duration greater than 10 hours get 2 points, 5 - 10 hours get 1 point, less than 5 hours get 0.5 points; device communication frequency: those with more than 10 communication times per minute get 2 points, 5 - 10 times get 1 point, less than 5 times get 0.5 points; device data transmission volume: those with a daily data transmission volume greater than 1MB get 2 points, 500KB - 1MB get 1 point, less than 500KB get 0.5 points; number of device abnormal behaviors: those with less than 5 abnormal behaviors per month get 2 points, 5 - 10 times get 1 point, more than 10 times get 0.5 points; then calculate the score of each device behavior unit according to the weights and scoring criteria: the device behavior score is equal to the sum of the scores of each first evaluation factor multiplied by the corresponding weight coefficient. Finally, calculate the corresponding device behavior risk data according to the device behavior score. The device behavior risk data of device A is equal to the device behavior score of device A divided by the total score of a group of devices of the entire device behavior unit.

[0108] S543: Taking each device behavior unit as the basic unit, perform network traffic analysis according to the preset second evaluation factor to obtain the corresponding network traffic score, and calculate the corresponding network traffic risk data according to the network traffic score.

[0109] In this embodiment, the second evaluation factor includes network traffic size, traffic peak time, traffic direction, protocol type, packet length, and abnormal traffic ratio.

[0110] Specifically, network traffic analysis tools (such as Wireshark, NetFlow, etc.) are used to analyze the network traffic of each device behavior unit, and then each device behavior unit is scored according to the preset second evaluation factor weights and scoring criteria (the network traffic scoring methods and device behavior scoring methods of each device behavior unit are the same, and the calculation of the network traffic risk data of each device behavior unit is the same as that of the device behavior risk data, which will not be elaborated here).

[0111] S544: Generate a comprehensive security audit result based on the device behavior risk data and network traffic risk data corresponding to each device behavior unit.

[0112] In this embodiment, calculations are performed based on the device behavior risk data and network traffic risk data of each device behavior unit. The weighted average method is used to calculate the comprehensive score of each device behavior unit. According to the comprehensive score, the device behavior units are divided into different risk levels (such as low risk, medium risk, high risk), and a comprehensive security audit report is generated, including the comprehensive score, risk level, main risk points, and recommended improvement measures of each device behavior unit.

[0113] In one embodiment, in step S541, multiple device behavior units are generated in the Internet of Things environment of the target Internet of Things device networking based on the device security index, operation mode data, and device connection relationship in the network topology. Specifically, it includes: S5411: Perform data preprocessing on the device operation mode data and network topology data in the Internet of Things environment to obtain the preprocessed device operation mode data and device connection relationship data.

[0114] In this embodiment, the device operation mode data includes the operation mode data obtained by collecting the operation status, communication frequency, data transmission volume, and number of abnormal behaviors of the device from sources such as device logs, sensor data, and network traffic; the network topology data refers to the connection relationship data of devices collected from sources such as network configuration files, routing tables, and topology diagrams.

[0115] S5412: Generate a device behavior pattern graph based on the preprocessed device operation mode data. Specifically, statistical indicators such as the mean and standard deviation of the operation mode data of each device are calculated, and the K-means or DBSCAN clustering algorithm is used to group devices with similar behavior patterns.

[0116] S5413: Calculate the correlation data between devices according to the device behavior pattern graph and the device connection relationship data, and generate a device connection relationship graph.

[0117] In this embodiment, the cosine similarity or Jaccard similarity method is used to calculate the behavioral similarity between devices, and the connection strength between devices is calculated based on the network topology structure data, such as through metrics like path length and bandwidth. Then, a graph theory method is used to construct a device connection relationship graph, where nodes represent devices and edges represent the connection relationships between devices. A graphical tool (such as Gephi, NetworkX) is used to display the device connection relationship graph.

[0118] S5414: Generate initial device behavior units based on the device connection relationship graph and the processed device operation mode data.

[0119] In this embodiment, a unique identifier and description information, i.e., a device label, are generated for each initial device behavior unit. Then, the key attributes of each behavior unit are extracted, such as the number of devices, behavior patterns, connection relationships, etc. Devices with similar behavior patterns and close connection relationships are grouped into the same initial device behavior unit.

[0120] S5415: Modify the initial device behavior units according to the device security index and the device connection relationship data to form the final device behavior units.

[0121] In this embodiment, the overall security of each initial device behavior unit is evaluated according to the device security index, and devices with a lower security index are identified and separated from the current behavior unit for separate management to complete the security index verification. Then, the division of the behavior units is optimized according to the device connection relationship data to ensure that the device connection relationships within the unit are closer, and the boundaries of the behavior units are adjusted by removing or adding devices to complete the connection relationship verification. The members and attributes of each final device behavior unit are confirmed, and a detailed device behavior unit report is generated, including a list of unit members, behavior patterns, connection relationships, and security assessment results.

[0122] In one embodiment, in step S542, taking each device behavior unit as a basic unit, device behavior analysis is performed according to a preset first evaluation factor to obtain a corresponding device behavior score, and corresponding device behavior risk data is calculated based on the device behavior score, specifically including:

[0123] S5241: Evenly divide the device behavior units in the Internet of Things environment to determine all the devices involved in a single device behavior unit, and assign values to each device in the single device behavior unit according to the first evaluation factor to obtain the first device score.

[0124] In this embodiment, the first evaluation factor is a series of important metrics for evaluating the behavior of Internet of Things (IoT) devices, including device type, device online time (the time when the device first accesses the IoT), device online duration, device communication frequency, device data transmission volume, and the number of device abnormal behaviors; the device behavior score is the score obtained after comprehensively evaluating the device behavior, reflecting the normality of the device behavior; the device behavior risk data is the data calculated based on the device behavior score, reflecting the risk level of the device behavior.

[0125] S5242: Calculate the arithmetic mean of the first device scores of all devices involved in a single device behavior unit to obtain the discriminant score of the first evaluation factor for the single device behavior unit, and use the discriminant score of the first evaluation factor and the comprehensive index method to calculate the device behavior score.

[0126] Specifically, divide all device behavior units into several groups on average, with each group containing a certain number of devices; collect the first evaluation factor data of each device from sources such as device logs, sensor data, and network traffic, and assign corresponding scores to each evaluation factor according to the pre-set scoring rules. For example:

[0127] Device type: Different types of devices are assigned different scores.

[0128] Device online time: The earlier the online time, the higher the possible score.

[0129] Device online duration: The longer the online duration, the higher the possible score.

[0130] Device communication frequency: A moderate communication frequency may result in a higher score.

[0131] Device data transmission volume: A moderate data transmission volume may result in a higher score.

[0132] Number of device abnormal behaviors: The fewer the abnormal behaviors, the higher the possible score.

[0133] Then, according to the weighted summation method, based on the weight of each evaluation factor, calculate the total score of each device. First, calculate the arithmetic mean of the first device scores of all devices within a single device behavior unit to obtain the discriminant score of the first evaluation factor for this unit. Then, assign weights to each evaluation factor to reflect its importance in the evaluation. Use the comprehensive index method to combine the discriminant score of the first evaluation factor and the weights to calculate the device behavior score.

[0134] S5243: Calculate the corresponding device behavior risk data based on the device behavior score.

[0135] In this embodiment, the device behavior risk data refers to the quantitative data reflecting the potential risks of device behavior calculated by comprehensively evaluating the behavior characteristics of IoT devices and historical security events. It is used to evaluate the security status of devices within a specific time period, helping administrators identify potential security threats and take corresponding preventive measures; set thresholds for different risk levels, such as low risk (0 - 30 points), medium risk (31 - 60 points), high risk (61 - 100 points), and then divide the device behavior units into different risk levels according to the device behavior scores to obtain the device behavior risk data.

[0136] Specifically, in step S5243, the corresponding device behavior risk data is calculated based on the device behavior scores, which specifically includes:

[0137] S52431: Obtain the historical security event data, and obtain the abnormal probability data of the device behavior unit based on the historical security event data.

[0138] S52432: Calculate the device behavior risk data by using the device behavior scores and the abnormal probability data of the device behavior unit.

[0139] In this embodiment, assume that we have a device behavior unit, which includes the following devices (as shown in the following table):

[0140]

[0141] Assignment rules:

[0142] Device type: Common device is 1 point, special device is 2 points. Online time: Devices with an online time exceeding 1 year are 1 point, and those with less than 1 year are 0.5 points. Online duration: Devices with an online duration greater than 10 hours are 2 points, 5 - 10 hours are 1 point, and less than 5 hours are 0.5 points. Communication frequency: Devices with more than 10 communication times per minute are 2 points, 5 - 10 times are 1 point, and less than 5 times are 0.5 points. Data transmission volume: Devices with a daily data transmission volume greater than 1MB are 2 points, 500KB - 1MB are 1 point, and less than 500KB are 0.5 points. Number of abnormal behaviors: Devices with less than 5 abnormal behaviors per month are 2 points, 5 - 10 times are 1 point, and more than 10 times are 0.5 points.

[0143] Calculate the scores: Device A: 1×0.1 + 1×0.1 + 2×0.2 + 1×0.2 + 2×0.2 + 1×0.2 = 1.4; Device B: 2×0.1 + 0.5×0.1 + 1×0.2 + 2×0.2 + 0.5×0.2 + 1×0.2 = 1.45; Device C: 1×0.1 + 1×0.1 + 2×0.2 + 0.5×0.2 + 2×0.2 + 2×0.2 = 1.6;

[0144] Arithmetic mean: Device behavior unit score: (1.4 + 1.45 + 1.6) / 3 = 1.483.

[0145] Step 2: Calculate the abnormal probability data of the device behavior unit

[0146] Assume that the number of abnormal events of the device behavior unit in the past year is 12 times, and the total number of devices in the unit is 3. Calculate the abnormal probability: 12 times / (3 devices × 12 months) = 0.333.

[0147] Step 3: Calculate the device behavior risk data

[0148] Weight setting: Assume that the weight of the device behavior score is 0.7, and the weight of the abnormal probability data is 0.3.

[0149] Device behavior risk data: (1.483 × 0.7) + (0.333 × 0.3) = 1.0821.

[0150] Through the above steps, we obtained the device behavior risk data of the device behavior unit as 1.0821, which reflects the comprehensive risk level of the device behavior unit.

[0151] Specifically, the device behavior score of 1.483 indicates that the device behavior is relatively normal; the abnormal probability of 0.333 indicates that the device behavior unit has a certain probability of abnormal behavior in the past year; the device behavior risk data of 1.0821 comprehensively considers the device behavior score and the abnormal probability, reflecting the overall risk level of the device behavior unit.

[0152] In one embodiment, in step S544, based on the device behavior risk data and the network traffic risk data corresponding to each device behavior unit, a comprehensive security audit result is generated, specifically including:

[0153] S5441: Taking each device behavior unit as a basic unit, input the corresponding device behavior risk data as row vector data and the corresponding network traffic risk data as column vector data into a preset security risk discrimination matrix to obtain the corresponding security risk level data.

[0154] Specifically, collect the behavioral characteristic data of the device from sources such as device logs, sensor data, and network traffic. Evaluate according to the preset first evaluation factors (such as device type, device online time, device online duration, device communication frequency, device data transmission volume, and number of device abnormal behaviors), calculate the behavioral score of each device, and combine the abnormal probability data to calculate the device behavioral risk data of each device behavior unit; collect network traffic data from sources such as network traffic logs and intrusion detection systems (IDS), and according to the preset second evaluation factors (such as network traffic size, traffic peak time, traffic direction, protocol type, packet length, and abnormal traffic ratio), use traffic analysis tools to analyze network traffic characteristics, identify abnormal traffic, and evaluate according to traffic characteristics (such as traffic size, traffic frequency, protocol type, source IP address, destination IP address, etc.), and calculate the network traffic risk data of each device behavior unit.

[0155] In this embodiment, use the device behavioral risk data of each device behavior unit as a row vector and the network traffic risk data of each device behavior unit as a column vector to construct a security risk discrimination matrix. The number of rows of the matrix is equal to the number of device behavior units, and the number of columns is also equal to the number of device behavior units. Then, set weights for the device behavioral risk data and the network traffic risk data respectively. For example, the weight of the device behavioral risk data is 0.7, and the weight of the network traffic risk data is 0.3. Use the weighted average method to calculate the comprehensive risk value of each device behavior unit. Then, according to the range of the comprehensive risk value, set different risk level thresholds, such as low risk (0 - 0.5), medium risk (0.51 - 1.0), high risk (1.01 - 1.5), and map the comprehensive risk value of each device behavior unit to the corresponding risk level.

[0156] S5442: Generate the comprehensive security audit result of the IoT network according to the security risk level data corresponding to each device behavior unit.

[0157] In this embodiment, the comprehensive security audit result can be output in the form of a comprehensive security audit report. The generated comprehensive security audit report includes the name of the device behavior unit, device behavioral risk data, device traffic risk data, comprehensive risk value, and security risk level, etc. Then, use charts (such as bar charts, pie charts) to display the distribution of different risk levels, and according to the security audit result, put forward corresponding security management suggestions and improvement measures.

[0158] It should be understood that the sequence numbers of the steps in the above embodiments do not mean the order of execution. The execution order of each process should be determined according to its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application.

[0159] In one embodiment, a security audit system for networking Internet of Things (IoT) devices is provided. This security audit system for networking IoT devices corresponds to the security audit method for networking IoT devices in the above embodiment.

[0160] A security audit system for networking IoT devices includes a data acquisition module, a dynamic security baseline construction module, a risk assessment module, a security policy generation module, and a security audit module. The detailed descriptions of each functional module are as follows:

[0161] The data acquisition module is used to acquire the operation mode data and network traffic data of the devices in the target IoT device network; the dynamic security baseline construction module is used to identify the normal behavior patterns of the devices according to the operation mode data and network traffic data, and construct corresponding dynamic security baselines.

[0162] The risk assessment module is used to analyze the network traffic of the target IoT device network by using a deep learning model, and evaluate the risk level of each data stream according to the dynamic security baseline.

[0163] The security policy generation module is used to generate a security policy comparison table for adjusting security policies according to the risk level, and obtain a security policy adjustment reference range representing the security policy adjustment threshold. According to the security policy adjustment reference range and the security policy comparison table, a security policy adjustment model is generated.

[0164] The security audit module is used to acquire the current network traffic data, input the current network traffic data into the security policy adjustment model, calculate the device security risk data of the entire target IoT device network, and adjust the security policy of the target IoT device network based on the device security risk data.

[0165] For the specific limitations of the security audit system for networking IoT devices, reference can be made to the limitations of the security audit method for networking IoT devices in the above text, which will not be elaborated here; each module in the above security audit system for networking IoT devices can be implemented in whole or in part by software, hardware, and their combination; the above modules can be embedded in the processor of the computer device in hardware form or be independent of it, or can be stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to the above modules.

[0166] In one embodiment, a computer device is provided. This computer device can be a server, and its internal structure diagram can be as Figure 3As shown in the figure. The computer device includes a processor, a memory, a network interface, and a database connected via a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store operation mode data, network traffic data, security policy adjustment models, etc. The network interface of the computer device is used to communicate with external terminals via a network connection. When the computer program is executed by the processor, it implements an Internet of Things device networking security auditing method.

[0167] In one embodiment, a computer device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the following steps are implemented:

[0168] S1: Obtain the operation mode data and network traffic data of the devices in the target Internet of Things device network;

[0169] S2: According to the operation mode data and network traffic data, identify the normal behavior patterns of the devices and construct corresponding dynamic security baselines;

[0170] S3: Use a deep learning model to analyze the network traffic of the target Internet of Things device network, and evaluate the risk level of each data stream according to the dynamic security baseline;

[0171] S4: Generate a security policy comparison table for adjusting security policies according to the risk level; and obtain a security policy adjustment reference range representing the security policy adjustment threshold, and generate a security policy adjustment model according to the security policy adjustment reference range and the security policy comparison table;

[0172] S5: Obtain the current network traffic data, input the current network traffic data into the security policy adjustment model, calculate the device security risk data of the entire target Internet of Things device network; adjust the security policy of the target Internet of Things device network based on the device security risk data.

[0173] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by the processor, the following steps are implemented:

[0174] S1: Obtain the operation mode data and network traffic data of the devices in the target Internet of Things device network;

[0175] S2: According to the operation mode data and network traffic data, identify the normal behavior patterns of the devices and construct corresponding dynamic security baselines;

[0176] S3: Analyze the network traffic of the target IoT device network using a deep learning model, and evaluate the risk level of each data stream according to the dynamic security baseline;

[0177] S4: Generate a security policy comparison table for adjusting the security policy according to the risk level; and obtain a security policy adjustment reference range representing the security policy adjustment threshold. According to the security policy adjustment reference range and the security policy comparison table, generate a security policy adjustment model;

[0178] S5: Obtain the current network traffic data, input the current network traffic data into the security policy adjustment model, and calculate the device security risk data of the entire target IoT device network; adjust the security policy of the target IoT device network based on the device security risk data.

[0179] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the above method embodiments. Among them, any reference to memory, storage, database, or other media used in the various embodiments provided in the present application can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and Rambus dynamic RAM (RDRAM), etc.

[0180] Those skilled in the art can clearly understand that for the convenience and simplicity of description, only the above division of each functional unit and module is used as an example. In actual applications, the above functions can be allocated to different functional units and modules according to needs, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above.

[0181] The above-described embodiments are only used to illustrate the technical solutions of the present application, rather than limiting them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some of the features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present application, and should all be included in the protection scope of the present application.

Claims

1. A method for security auditing of Internet of Things devices, characterized in that: include: Obtain the operation mode data and network traffic data of the devices in the target IoT device network; According to the operation mode data and network traffic data, a normal behavior mode of the device is identified, and a corresponding dynamic security baseline is constructed; Analyze the network traffic of the target IoT device network using a deep learning model, and evaluate the risk level of each data flow according to the dynamic security baseline; generating a security policy comparison table for adjusting the security policy according to the risk level; and obtaining a security policy adjustment reference range representing a security policy adjustment threshold, and generating a security policy adjustment model according to the security policy adjustment reference range and the security policy comparison table; Acquire current network traffic data, input the current network traffic data into the security policy adjustment model, and calculate device security risk data of the entire target IoT device network; The security policy of the target IoT device networking is adjusted based on the device security risk data.

2. According to claim 1, a method for security auditing of Internet of Things devices is characterized in that: The obtaining of current network traffic data, inputting the current network traffic data into the security policy adjustment model, and calculating the device security risk data of the entire target IoT device network includes: Acquire current network traffic data, and input the current network traffic data into the security policy adjustment model; In the security policy adjustment model, the audit scope is determined in combination with the network topology structure and basic device information of the target IoT network; Performing a device security performance evaluation on each IoT device within the audit scope according to a preset security audit factor to obtain a corresponding device security index; According to the device security index, combined with the device connection relationship in the network topology, the security risk data of the entire target Internet of Things network is analyzed and calculated.

3. According to claim 2, a method for security auditing of Internet of Things devices is characterized in that: The security risk data includes device behavior risk data and network traffic risk data; The security risk data of the entire target Internet of Things network is analyzed and calculated based on the device security index and the device connection relationship in the network topology, including: Generate multiple device behavior units in the IoT environment of the target IoT device network based on the device security index, the operation mode data, and the device connection relationship in the network topology structure; Taking each device behavior unit as a basic unit, performing device behavior analysis according to a preset first evaluation factor to obtain a corresponding device behavior score, and calculating corresponding device behavior risk data according to the device behavior score; Taking each device behavior unit as a basic unit, performing network traffic analysis according to a preset second evaluation factor to obtain a corresponding network traffic score, and calculating corresponding network traffic risk data according to the network traffic score; Based on the device behavior risk data and network traffic risk data corresponding to each of the device behavior units, a comprehensive security audit result is generated.

4. According to claim 3, a method for security auditing of Internet of Things devices is characterized in that: The generating of a plurality of device behavior units in the IoT environment of the target IoT device network based on the device security index, the operation mode data and the device connection relationship in the network topology structure specifically includes: Preprocessing the device operation mode data and the network topology data in the IoT environment to obtain preprocessed device operation mode data and device connection relationship data; generating a device behavior pattern diagram based on the preprocessed device operation mode data; According to the device behavior pattern diagram and the device connection relationship data, calculating the correlation data between the devices, and generating a device connection relationship diagram; Generate an initial device behavior unit according to the device connection relationship diagram and the preprocessed device operation mode data; The initial device behavior unit is modified according to the device safety index and the device connection relationship data to form a final device behavior unit.

5. According to claim 3, a method for security auditing of Internet of Things devices is characterized in that: The method takes each device behavior unit as a basic unit, performs device behavior analysis according to a preset first evaluation factor, obtains a corresponding device behavior score, and calculates corresponding device behavior risk data according to the device behavior score, specifically including: The first evaluation factor includes device type, device online time, device online duration, device communication frequency, device data transmission volume, and number of abnormal device behaviors; Evenly divide the device behavior units in the Internet of Things environment, determine all devices involved in a single device behavior unit, and assign a value to each device in the single device behavior unit according to a first evaluation factor to obtain a first device score; Taking the arithmetic average of the first device scores of all devices involved in a single device behavior unit, calculating the first evaluation factor discrimination score of the single device behavior unit, and using the first evaluation factor discrimination score and the comprehensive index method to calculate the device behavior score; Calculating corresponding device behavior risk data according to the device behavior score; or, The calculating corresponding device behavior risk data according to the device behavior score specifically includes: Acquire historical security event data, and acquire abnormal probability data of device behavior units based on the historical security event data; The device behavior risk data is calculated using the device behavior score and the abnormal probability data of the device behavior unit.

6. According to claim 3, a method for security auditing of Internet of Things devices is characterized in that: The method takes each device behavior unit as a basic unit, performs network traffic analysis according to a preset second evaluation factor, obtains a corresponding network traffic score, and calculates corresponding network traffic risk data according to the network traffic score, specifically including: The second evaluation factor includes network traffic size, traffic peak time, traffic direction, protocol type, data packet length and abnormal traffic ratio; Evenly divide the device behavior units in the Internet of Things environment, determine all network connections involved in a single device behavior unit, and assign a value to each network connection in the single device behavior unit according to a second evaluation factor to obtain a second network connection score; Taking the arithmetic average of the second network connection scores of all network connections involved in a single device behavior unit, calculating the second evaluation factor discrimination score of the single device behavior unit, and using the second evaluation factor discrimination score and the comprehensive index method to calculate the network traffic score; Corresponding network traffic risk data is calculated according to the network traffic score.

7. A method for security auditing of Internet of Things devices according to claim 3, characterized in that: The generating of a comprehensive security audit result based on the device behavior risk data and network traffic risk data corresponding to each of the device behavior units specifically includes: Taking each device behavior unit as the basic unit, the corresponding device behavior risk data is used as the row vector data, and the corresponding network traffic risk data is used as the column vector data, which are input into the preset security risk discrimination matrix to obtain the corresponding security risk level data; Based on the security risk level data corresponding to each device behavior unit, a comprehensive security audit result of the Internet of Things network is generated.

8. An Internet of Things device networking security audit system, characterized in that: The system comprises: A data acquisition module is used to acquire the operation mode data and network flow data of the devices in the target IoT device network; A dynamic security baseline building module, used to identify the normal behavior mode of the device according to the operation mode data and the network traffic data, and build a corresponding dynamic security baseline; A risk assessment module, used to analyze the network traffic of the target IoT device network using a deep learning model, and assess the risk level of each data flow according to the dynamic security baseline; A security policy generation module, configured to generate a security policy comparison table for adjusting the security policy according to the risk level, obtain a security policy adjustment reference range representing a security policy adjustment threshold, and generate a security policy adjustment model according to the security policy adjustment reference range and the security policy comparison table; The security audit module is used to obtain current network traffic data, input the current network traffic data into the security policy adjustment model, calculate the device security risk data of the entire target Internet of Things device network, and adjust the security policy of the target Internet of Things device network based on the device security risk data.

9. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the steps of the method for security auditing of Internet of Things devices network as described in any one of claims 1 to 7 are implemented.

10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by the processor, the steps of a method for security auditing a network of Internet of Things devices as described in any one of claims 1 to 7 are implemented.

Citation Information

Patent Citations

  • Network attack and defense decision support method and system based on artificial intelligence

    CN119155099A

  • Network space anti-mapping method and device, computer equipment and storage medium

    CN119254507A