An AI industrial Internet of Things platform security access method, terminal and system
By analyzing the user's instruction sequence and historical operation data on the AI industrial Internet of Things platform, and comprehensively judging the user's abnormal status value, the problem of the security access mechanism being vulnerable to attack in the existing technology is solved, and more efficient secure access verification is achieved.
Patent Information
- Application Number
- CN202510268632.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-07
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2045-03-07
AI Technical Summary
The secure access mechanism of the existing industrial IoT platform is susceptible to brute-force cracking and phishing attacks, and security verification faces challenges.
By obtaining the user's current instruction sequence and historical operation data on the AI industrial Internet of Things platform, determine the behavior abnormality, the degree of impact of operation inertia and the abnormal risk coefficient, comprehensively judge the user's abnormal status value, and control user access.
Improve the verification security of secure access, ensure the security and reliability of AI industrial Internet of Things platform, and prevent illegal access and abnormal attacks.
Smart Images

Figure CN119788422B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of digital information transmission, and particularly relates to a security access method, a terminal and a system for an AI industrial Internet of Things platform. Background Art
[0002] Currently, industrial Internet of Things platforms, by integrating advanced AI technologies and powerful Internet of Things infrastructures, achieve intelligent interconnection and efficient collaboration among devices, bringing real-time data analysis and decision-making support to enterprises, greatly improving production efficiency and reducing operating costs; at the same time enhancing production safety and reliability, making the industrial production process more intelligent and automated, bringing unprecedented competitive advantages and development opportunities to enterprises.
[0003] Currently, for early-deployed industrial Internet of Things platforms, the identity authentication mechanisms for secure access often use simple usernames and passwords, making them vulnerable to brute-force cracking and phishing attacks, and facing certain challenges in security verification. Summary of the Invention
[0004] To solve the above technical problems, the purpose of the present invention is to provide a security access method, a terminal and a system for an AI industrial Internet of Things platform, and the specific technical solutions adopted are as follows:
[0005] In a first aspect, an embodiment of the present application provides a method for secure access to an AI industrial Internet of Things platform, including:
[0006] Obtain a number of current instruction sequences and historical operation data output by a user on the AI industrial Internet of Things platform;
[0007] According to the current instruction sequences and the historical operation data, respectively determine the behavior anomaly degree of each current instruction sequence, the operation inertia influence degree of each current instruction sequence, and the anomaly risk coefficient of each current instruction sequence;
[0008] According to the behavior anomaly degree, the operation inertia influence degree, and the anomaly risk coefficient, determine the user anomaly state value;
[0009] According to the user anomaly state value, control the user's access to the AI industrial Internet of Things platform.
[0010] In an implementation manner, determining the behavior anomaly degree of each current instruction sequence according to the current instruction sequences and the historical operation data includes:
[0011] Determine a first instruction sequence from the current instruction sequences, and construct a first instruction group with any two instructions in the first instruction sequence to obtain a number of first instruction groups;
[0012] Determine the mean of the first position distances at which two instructions in each of the first instruction groups appear in the corresponding historical instruction sequence according to the historical operation data, and determine the second position distance at which the two instructions in each of the first instruction groups appear in the first instruction sequence;
[0013] Determine the first ratio of the second position distance to the mean of the first position distances and the first difference between a preset value and the first ratio;
[0014] Determine the degree of cooperation between two instructions in each of the first instruction groups, and calculate the first product of the absolute value of the difference between the degree of cooperation corresponding to each of the first instruction groups and the first difference respectively;
[0015] Sum according to the first product and the number of the first instruction groups, and obtain the behavior anomaly degree of the first instruction sequence according to the summation result and the normalization function, and return the step of determining the first instruction sequence from the current instruction sequence until the behavior anomaly degree of each of the current instruction sequences is determined.
[0016] In one implementation manner, determining the degree of cooperation between two instructions in each of the first instruction groups includes:
[0017] Determine the first position and the second position at which two instructions in each of the first instruction groups appear in the first instruction sequence respectively, and determine the Pearson correlation coefficient between the first position and the second position;
[0018] Determine the frequency at which any instruction in each of the first instruction groups appears in the first instruction sequence, and obtain the degree of cooperation between the two instructions in each of the first instruction groups respectively according to the product of the Pearson correlation coefficient and the frequency.
[0019] In one implementation manner, determining the degree of influence of operation inertia of each of the current instruction sequences according to the current instruction sequence and the historical operation data includes:
[0020] Determine a second instruction sequence from the current instruction sequence, divide the second instruction sequence into sequence segments with a preset number of segments, divide the first two sequence segments with a higher sort order into a module, add a sequence segment arranged after the module to the module according to the sort order to obtain a new module, and return the step of adding a sequence segment arranged after the module to the module according to the sort order until the last sequence segment is added to obtain several modules;
[0021] Determine the target coordination degree corresponding to the last sequence segment and each of the remaining sequence segments in each of the said modules, construct a two-dimensional curve based on the target coordination degree, and determine the integral of the first derivative of the two-dimensional curve;
[0022] Respectively determine the second differences of the integrals of each pair of adjacent modules, calculate the arithmetic mean based on the absolute values of the second differences and the number of the modules, and perform normalization processing to obtain the operation inertia influence degree of the second instruction sequence. Return to the step of determining the second instruction sequence from the current instruction sequence until the operation inertia influence degree of each current instruction sequence is determined.
[0023] In one implementation, determining the abnormal risk coefficient of each current instruction sequence according to the current instruction sequence and the historical operation data includes:
[0024] Split the historical operation data to determine a number of historical instruction sequences, and perform semantic vectorization on the historical instruction sequences to obtain corresponding first vector sequences;
[0025] Cluster the first vector sequences to determine the operation intentions corresponding to different categories;
[0026] Respectively determine the second vector sequence of each current instruction sequence and the Euclidean distance between each second vector sequence and the operation intention, and determine the minimum target Euclidean distance corresponding to each second vector sequence;
[0027] Determine the sudden change degree of each current instruction sequence according to the operation intentions corresponding to different categories and the historical instruction sequences;
[0028] Respectively determine the second ratio of the sudden change degree to the corresponding target Euclidean distance, and determine the abnormal risk coefficient of each current instruction sequence according to the second ratio and the normalization function.
[0029] In one implementation, the determining the sudden change degree of each current instruction sequence according to the operation intentions corresponding to different categories and the historical instruction sequences includes:
[0030] Determine the occurrence frequency of each first vector sequence in the historical operation data, and assign different amplitudes to the first vector sequences according to different occurrence frequencies;
[0031] According to different occurrence frequencies, split the second vector sequence of each current instruction sequence into multiple sub-sequence vectors, match the sub-sequence vectors with the first vector sequences, and determine the target amplitude corresponding to each sub-sequence vector;
[0032] Calculate the amplitude mean of each of the current instruction sequences according to the target amplitude respectively, and calculate the mean absolute error according to the amplitude mean and the target amplitude respectively, so as to obtain the degree of sudden change of each of the current instruction sequences.
[0033] In one implementation manner, the determining the user abnormal state value according to the behavior abnormality degree, the operation inertia influence degree and the abnormal risk coefficient includes:
[0034] Determine the product of the abnormal risk coefficient and the behavior abnormality degree of each of the current instruction sequences respectively, and determine the third ratio of the product to the corresponding operation inertia influence degree;
[0035] Calculate the arithmetic mean according to each of the third ratios and the number of the current instruction sequences, so as to obtain the user abnormal state value.
[0036] In one implementation manner, the controlling the user to access the AI industrial Internet of Things platform according to the user abnormal state value includes:
[0037] When the user abnormal state value is greater than the interception probability threshold, prohibit the user from accessing the AI industrial Internet of Things platform;
[0038] Wherein, the interception probability threshold is calculated based on the abnormal behavior interception probability of the AI industrial Internet of Things platform in the recent preset number of days.
[0039] In a second aspect, an AI industrial Internet of Things platform security access system provided by an embodiment of the present application includes:
[0040] An acquisition module, configured to acquire a plurality of current instruction sequences and historical operation data output by a user on the AI industrial Internet of Things platform;
[0041] A first determination module, configured to determine the behavior abnormality degree of each of the current instruction sequences, the operation inertia influence degree of each of the current instruction sequences, and the abnormal risk coefficient of each of the current instruction sequences respectively according to the current instruction sequences and the historical operation data;
[0042] A second determination module, configured to determine a user abnormal state value according to the behavior abnormality degree, the operation inertia influence degree and the abnormal risk coefficient;
[0043] A control module, configured to control the user to access the AI industrial Internet of Things platform according to the user abnormal state value.
[0044] In a third aspect, an embodiment of the present application provides a terminal, including: a processor and a memory. Instructions are stored in the memory and loaded and executed by the processor to implement the method in any one of the above aspects.
[0045] The present invention has the following beneficial effects:
[0046] By obtaining a number of current instruction sequences and historical operation data output by a user on an AI industrial Internet of Things platform, and respectively determining the behavior abnormality degree of each current instruction sequence, the influence degree of operation inertia of each current instruction sequence, and the abnormal risk coefficient of each current instruction sequence according to the current instruction sequence and the historical operation data, and determining the user abnormal state value according to multi-layer verification factors such as the behavior abnormality degree, the influence degree of operation inertia, and the abnormal risk coefficient, it is beneficial to improve the verification security; according to the user abnormal state value, controlling the user's access to the AI industrial Internet of Things platform is beneficial to ensure the secure access of the AI industrial Internet of Things platform. BRIEF DESCRIPTION OF THE DRAWINGS
[0047] In order to more clearly illustrate the technical solutions and advantages in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0048] Figure 1 It is a schematic flowchart of the steps of a method for secure access to an AI industrial Internet of Things platform provided by an embodiment of the present invention;
[0049] Figure 2 It is a schematic diagram of multi-layer verification provided by an embodiment of the present invention;
[0050] Figure 3 It is a structural block diagram of a system for secure access to an AI industrial Internet of Things platform provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0051] In order to further elaborate on the technical means and effects adopted by the present invention to achieve the intended invention purpose, the following will, in conjunction with the accompanying drawings and preferred embodiments, describe in detail the specific implementation manners, structures, features, and effects of a method, terminal, and system for secure access to an AI industrial Internet of Things platform proposed according to the present invention. In the following description, different "one embodiment" or "another embodiment" do not necessarily refer to the same embodiment. In addition, the specific features, structures, or characteristics in one or more embodiments can be combined in any suitable form.
[0052] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the technical field to which this invention belongs.
[0053] It should be noted that the "exemplary" in the embodiments of this application refers to examples listed for convenience of description, and other embodiments are not limited to the listed examples.
[0054] The following specifically describes the specific solutions of an AI industrial Internet of Things platform security access method, terminal, and system provided by the present invention in conjunction with the accompanying drawings.
[0055] Please refer to Figure 1 , which shows a flowchart of an AI industrial Internet of Things platform security access method provided by an embodiment of the present invention. The AI industrial Internet of Things platform security access method may at least include steps S100 - S400:
[0056] S100. Obtain a plurality of current instruction sequences and historical operation data output by a user on the AI industrial Internet of Things platform.
[0057] S200. According to the current instruction sequences and historical operation data, respectively determine the behavior abnormality degree of each current instruction sequence, the operation inertia influence degree of each current instruction sequence, and the abnormal risk coefficient of each current instruction sequence.
[0058] S300. Determine the user abnormal state value according to the behavior abnormality degree, the operation inertia influence degree, and the abnormal risk coefficient.
[0059] S400. Control the user's access to the AI industrial Internet of Things platform according to the user abnormal state value.
[0060] The technical solution of the embodiments of this application, by obtaining a plurality of current instruction sequences and historical operation data output by a user on the AI industrial Internet of Things platform, respectively determining the behavior abnormality degree of each current instruction sequence, the operation inertia influence degree of each current instruction sequence, and the abnormal risk coefficient of each current instruction sequence according to the current instruction sequences and historical operation data, and determining the user abnormal state value according to multi - layer verification factors such as the behavior abnormality degree, the operation inertia influence degree, and the abnormal risk coefficient, is beneficial to improving the verification security; controlling the user's access to the AI industrial Internet of Things platform according to the user abnormal state value is beneficial to ensuring the secure access of the AI industrial Internet of Things platform.
[0061] In one embodiment, the data transmission system framework of the AI industrial Internet of Things platform (hereinafter referred to as the Internet of Things platform) is pre-configured. The Internet of Things platform mainly includes two major modules: the user terminal and the device terminal. The central data processing platform between the user terminal and the device terminal includes an encryption verification module and a communication module, which are mainly responsible for security verification and communication of the information exchanged under the two major ports. Among them, on the user terminal side, there is mainly user operation data with different operation permissions. The relevant instruction information sent by the user terminal is transmitted to the central processing platform. First, it is identified by the encryption verification end and then transmitted to the communication layer, and then transmitted to the corresponding device by the communication layer; the user of the user terminal can select or input an operation instruction to control the device terminal to perform a specific task. At the same time, the user can view the real-time data of the device terminal within the corresponding permissions and collect information such as the status of the device terminal. In addition, the collected data of the device terminal is also first sent to the central processing platform, and the relevant instruction information for operating the device terminal is transmitted by the processing platform.
[0062] As Figure 2 shown, in the embodiment of the present application, by adopting multi-dimensional and multi-level verification of operations, data transmission, device interaction and other behaviors, the security and compliance are verified layer by layer. A five-layer verification method is adopted for users / devices in the overall system architecture, including physical layer verification, network layer verification, behavior verification, transport layer verification and monitoring layer verification.
[0063] Specifically, when a user and a device (i.e., the user terminal and the device terminal) access the AI industrial Internet of Things platform (hereinafter referred to as the Internet of Things platform), first, the physical layer verifies the access device at the physical layer to prevent illegal devices from entering the internal network or forged devices, and verifies according to the digital certificate of the device itself. At the same time, the network layer passes the network layer verification to ensure that the device and the user access the system through legal channels, and uses multi-factor authentication or TLS / SSL certificates for communication authentication. After accessing the Internet of Things platform, during the overall information interaction process, the transport layer encrypts the transmitted information by combining AES and RSA at the transport layer verification, and at the same time adds a timestamp and a sequence number to the data packet to prevent replay attacks and illegal data packet attacks. Each operation information (such as each instruction) transmitted by the transport layer is recorded in the operation log. Therefore, the operation log has historical operation data of the user or the device on the Internet of Things platform. The behavior verification of the behavior layer analyzes the behaviors of the user and the device to ensure that the operations conform to the normal business process and prevent malicious operations and other behaviors; the monitoring layer verification of the monitoring layer saves the relevant information generated by the above monitoring, and globally evaluates the running state of the entire system framework and the risks existing on each node to ensure the healthy operation of the entire system framework environment.
[0064] Optionally, in the data transmission system framework of the Internet of Things platform, the types of instructions usually involve aspects such as device control, data collection, and configuration management. Therefore, different instructions have different degrees of impact on the system. Therefore, an assessment of the impact degree of the existing instructions is carried out. According to the permission allocation restrictions, the proportion of personnel who can operate the corresponding instructions is obtained respectively. The larger the proportion of personnel, the smaller the restrictions required for the corresponding operation, and the relatively smaller the impact on the device. The usage frequency under different instructions is obtained. When the usage frequency is less, the probability of abnormal behavior occurring when this instruction appears is higher.
[0065] It should be noted that in the current multi-layer verification design, the physical layer and the network layer can effectively intercept a large number of illegally accessing users. However, for users who bypass these two layers of verification, the system fails to completely prevent their instruction operations on the device. These users who bypass the verification may input abnormal instructions, which may have a greater verification impact on the device. For instructions with a high impact degree, the system usually conducts strict reviews. However, the continuous input of low-impact instructions will cause the device to gradually exhibit abnormalities during operation, and it is relatively difficult to identify the intentions of these low-impact operation instructions, which are easily overlooked or misjudged, resulting in potential risks. At the same time, if there is an attacker who bypasses the physical layer verification and the network layer verification through stealing an account or other means and performs some abnormal attack operations on the device, during this operation process, the interactive behavior of the current user can be analyzed. Since each user will have their own operation bias during the operation, compared with different behavior habits, the operation bias is some subtle operation biases during the operation process. Therefore, if there is a mutation in the behavior habit of this user during the monitoring process, it is very likely that the account has been stolen.
[0066] In the embodiment of the present application, analysis can be carried out through the historical operation data in the operation log. By mining the operation time of a single user, the interactive device, and the instruction sequence during the instruction combination process, the operation fingerprint of the single user itself is extracted. According to each instruction sequence of the single user, combined with the time and interactive device of this instruction, multi-dimensional interactive operation data is constructed, denoted as , where represents the serial number of the instruction, represents the operation behavior of this instruction sequence, represents the operation time, represents the interactive object. Among them, for a single operation instruction of the current user, there are different association strengths, that is, for some instructions, they usually follow other instructions to be output together. Therefore, according to the historical operation data of this user in the operation log, the cooperation of this instruction with other instructions can be analyzed for a single numbered instruction.
[0067] In one implementation, in step S100, after the user accesses the AI industrial Internet of Things platform, operations can be performed on the user terminal, and several current instruction sequences are output by the AI industrial Internet of Things platform. Therefore, several current instruction sequences output by the user on the AI industrial Internet of Things platform can be obtained, and historical operation data of the user on the AI industrial Internet of Things platform can be obtained from the operation log. Among them, the historical operation data may include several historical instruction sequences, and each historical instruction sequence may include several instructions.
[0068] In one implementation, in step S200, according to the current instruction sequence and the historical operation data, the behavior abnormality degree of each current instruction sequence is determined respectively, including steps S201 - S205:
[0069] S201. Determine a first instruction sequence from the current instruction sequence, and construct a first instruction group with any two instructions in the first instruction sequence to obtain several first instruction groups.
[0070] Optionally, determine a first instruction sequence from the current instruction sequence, for example, the th current instruction sequence, = 1, and construct a first instruction group with any two instructions in the first instruction sequence, and finally obtain several first instruction groups.
[0071] S202. According to the historical operation data, determine the mean value of the first position distances at which the two instructions in each first instruction group appear in the corresponding historical instruction sequences, and determine the second position distance at which the two instructions in each first instruction group appear in the first instruction sequence.
[0072] Optionally, according to the historical operation data, determine the mean value of the first position distances at which the two instructions in each first instruction group appear in the corresponding historical instruction sequences. For example, there are two instructions A1 and A2, which both appear in the corresponding historical instruction sequences B1 and B2. The instructions A1 and A2 appear in the historical instruction sequence B1 and the distance between them is the first position distance L1, and the instructions A1 and A2 appear in the historical instruction sequence B2 and the distance between them is the first position distance L2. Calculate the mean value of the first position distances according to L1 and L2. Therefore, the mean value of the first position distances at which the two instructions in each first instruction group appear in the corresponding historical instruction sequences can be determined. Similarly, the second position distance at which the instructions A1 and A2 appear in the first instruction sequence can be determined, so as to determine the second position distance at which the two instructions in each first instruction group appear in the first instruction sequence.
[0073] S203. Determine the first ratio of the second position distance to the mean value of the first position distances and the first difference between the preset value and the first ratio.
[0074] Optionally, taking the preset value as 1 as an example, determine the first ratio of the mean value of the second position distance to the first position distance respectively and the preset value 1 and the first ratio of the first difference , representing the first ratio of the mean value of the second position distance to the first position distance corresponding to the th first instruction group. Assume there are first instruction groups in total.
[0075] S204. Determine the degree of cooperation between two instructions in each first instruction group, and calculate the first product of the degree of cooperation corresponding to each first instruction group and the absolute value of the first difference respectively.
[0076] It should be noted that for a single instruction in the current instruction sequence, if there is a strong cooperative behavior between this instruction and the remaining instructions, this instruction will first appear in a large number of instruction sequences of the current remaining instructions, and the position where this instruction appears in the corresponding instruction sequence is affected by these remaining instructions.
[0077] Optionally, determining the degree of cooperation between two instructions in each first instruction group includes:
[0078] First, determine the first position where two instructions in each first instruction group appear in the first instruction sequence (for example, the th current instruction sequence, = 1), where one instruction in the first instruction sequence is the th instruction in the first instruction sequence) and the second position where the other instruction in the first instruction sequence is the th instruction in the first instruction sequence), and determine the Pearson correlation coefficient between the first position and the second position .
[0079] Second, determine the frequency at which any instruction (for example, the th instruction or the th instruction, this embodiment of the present application takes the th instruction as an example) in each first instruction group appears in the first instruction sequence, and respectively obtain the degree of cooperation between two instructions in each first instruction group according to the product of the Pearson correlation coefficient and the frequency , that is, the degree of cooperation between two instructions in the th first instruction group. The formula is:
[0080] ;
[0081] Among them, represents the degree of coordination between two instructions corresponding to the th first instruction group, represents the th first instruction group corresponding to the th instruction in the first instruction sequence. Then, calculate the coordination degree corresponding to each first instruction group and the first difference respectively, and then calculate the first product of the absolute value of the coordination degree and the first difference .
[0082] S205. Sum according to the first product and the number of first instruction groups, and obtain the behavior abnormality degree of the first instruction sequence according to the sum result and the normalization function, and return the step of determining the first instruction sequence from the current instruction sequence until the behavior abnormality degree of each current instruction sequence is determined.
[0083] Optionally, sum according to the first product and the number of first instruction groups , and obtain the behavior abnormality degree of the first instruction sequence according to the sum result and the normalization function . The formula is:
[0084] ;
[0085] Among them, is the behavior abnormality degree of the th current instruction sequence. At this time, =1 represents the first instruction sequence. Therefore, return the step of determining the first instruction sequence from the current instruction sequence until the behavior abnormality degree of each current instruction sequence is determined . At this time, takes different values to represent different current instruction sequences. It should be noted that represents the position deviation degree between the instructions included in the th first instruction group and the historical operation data. When there is a large deviation in some highly coordinated instructions included in a single th first instruction group, it means that the behavior of the current instruction sequence is relatively abnormal.
[0086] It should be noted that during the user's operation, there may be a deviation in the intention of the operation instruction due to the user's non-subjective instruction error. Therefore, during the abnormal user detection process, such instructions need to be identified. When the instruction sequence of this user is affected by the user's inertial operation mode, it is manifested as a relatively high degree of cooperation between adjacent two instruction segments in the instruction sequence. As the distance between the instruction segments increases, the degree of cooperation between the two decreases, that is, the purpose of the starting operation instruction deviates as the instruction increases, and the subsequent operation has a strong cooperation with the most recent previous operation.
[0087] In one implementation manner, in step S200, according to the current instruction sequence and historical operation data, to determine the operation inertia influence degree of each current instruction sequence, it includes steps S211 - S213:
[0088] S211. Determine a second instruction sequence from the current instruction sequence, divide the second instruction sequence into sequence segments with a preset number of segments, divide the first two sequence segments with a higher ranking into a module, add a sequence segment arranged after this module according to the ranking to this module to obtain a new module, and according to this new module, return the step of adding a sequence segment arranged after this module according to the ranking to this module until the sequence segment with the last ranking is added to obtain several modules.
[0089] Optionally, determine a second instruction sequence from the current instruction sequence. Similarly, for example, the nth current instruction sequence. = 1. As the second instruction sequence, divide the second instruction sequence into sequence segments of a preset number of segments. For example, if the preset number of segments is 5, it is evenly divided into 5 sequence segments. Then, divide the first two sequence segments with the frontmost sorting into one module, and add a sequence segment arranged after this module according to the sorting to this module to obtain a new module. For example, there are sequence segments 1, 2, 3, 4, and 5. The first two sequence segments with the frontmost sorting, namely sequence segments 1 and 2, are divided into one module, denoted as module 1, and return the step of adding a sequence segment arranged after this module according to the sorting to this module based on this new module until the last sequence segment is added, obtaining several modules. At this time, based on module 1, add a sequence segment arranged after this module 1, namely sequence segment 3, to module 1 to obtain a new module 2 including sequence segments 1, 2, and 3. Then, based on the new module 2, add a sequence segment arranged after this module 2, namely sequence segment 4, to module 2 to obtain a new module 3 including sequence segments 1, 2, 3, and 4. Until the last sequence segment 5 is added to the new module 3, obtaining a new module 4 including sequence segments 1, 2, 3, 4, and 5. Finally, several modules are obtained, specifically 4 modules.
[0090] S212. Determine the target coordination degree corresponding to the last sequence segment and the remaining each sequence segment in each module, construct a two-dimensional curve according to the target coordination degree, and determine the integral of the first derivative of the two-dimensional curve.
[0091] Optionally, determine the target coordination degree corresponding to the last sequence segment and the remaining each sequence segment in each module, construct a two-dimensional curve according to the target coordination degree, and determine the integral of the first derivative of the two-dimensional curve , that is, the integral of the first derivative of the two-dimensional curve corresponding to the th module.
[0092] Among them, the target coordination degree between sequence segments can be obtained by calculating the coordination degree between the instructions included in different sequence segments and then accumulating and averaging all the coordination degrees. The coordination degree between instructions refers to S204 and will not be elaborated here.
[0093] S213. Respectively determine the second differences of the integrals of each adjacent module, calculate the arithmetic mean according to the absolute value of the second difference and the number of modules and perform normalization processing to obtain the influence degree of the operation inertia of the second instruction sequence, and return the step of determining the second instruction sequence from the current instruction sequence until the influence degree of the operation inertia of each current instruction sequence is determined.
[0094] Optionally, respectively determine the second differences of the integrals of each adjacent module , is the integral of the first derivative of the two-dimensional curve corresponding to the +1 module, and according to the second difference absolute value | and the number of modules calculate the arithmetic mean and normalize it according to the normalization function to obtain the influence degree of the operation inertia of the second instruction sequence:
[0095] ;
[0096] wherein, represents the influence degree of the operation inertia of the th current instruction sequence. At this time, =1, representing the influence degree of the operation inertia of the second instruction sequence; the greater the influence degree of the operation inertia, the higher the influence of the corresponding instruction of the user's operation by the user's inertia, and the higher the possibility that the intention contained in the instruction is caused by the user's misoperation, and the lower the reference value of the corresponding instruction.
[0097] Optionally, return the steps of determining the second instruction sequence from the current instruction sequence until the influence degree of the operation inertia of each current instruction sequence is determined , at this time takes different values, representing the influence degrees of the operation inertia of different current instruction sequences.
[0098] It should be noted that there are various instructions with different degrees under some operations of the user on the device, and different instructions have different adjustment degrees on the device. When the user performs instruction operations on the device, there is a clear intention for the issued instruction sequence, and different instruction sequences have different influence degrees on the current device. For this reason, in order to avoid system monitoring, the attacker uses an instruction sequence with a low influence degree, and some specific instruction combinations usually indicate high-risk operations or attack behaviors.
[0099] In one implementation, in step S200, according to the current instruction sequence and historical operation data, determine the abnormal risk coefficient of each current instruction sequence, including steps S221 - S225:
[0100] S221. Split the historical operation data to determine several historical instruction sequences, and perform semantic vectorization on the historical instruction sequences to obtain the corresponding several first vector sequences.
[0101] Optionally, the historical operation data is split to determine a number of historical instruction sequences, and the number of splits is determined based on the actual situation. In the embodiments of the present application, each individual instruction in each historical instruction sequence is numbered, and the historical instruction sequence is semantically vectorized, that is, BERT is used to convert the context information of the corresponding instruction in the historical instruction sequence into a semantic vector, and the semantic vector is denoted as . Then, the semantic vectors of each instruction are concatenated into a long vector, and after weighted averaging according to the influence degree under each semantic vector, a vector representing the corresponding historical instruction sequence is generated, that is, the first vector sequence, denoted as . It should be noted that the influence degree under each semantic vector can be normalized based on the derivative of the product of the permission ratio of the corresponding individual instruction (that is, the ratio of the number of people who can input the instruction for operation to the total number of people) and the usage frequency (the usage frequency corresponding to different instructions) as the influence degree of the semantic vector of the individual instruction, denoted as
[0102]
[0103] Optionally, DBSCAN is used to cluster the first vector sequence to construct a relationship model between instruction sequences, and the operation intentions corresponding to different categories are obtained. For example, different categories have corresponding operation intentions Figure 1 , operation intentions Figure 2 , etc. Each first vector sequence has a corresponding operation intention, that is, an operation behavior.
[0104] S223. Respectively determine the second vector sequence of each current instruction sequence and the Euclidean distance between each second vector sequence and the operation intention, and determine the minimum target Euclidean distance corresponding to each second vector sequence.
[0105] Optionally, the second vector sequence of each current instruction sequence is determined respectively (the determination method is the same as the principle of the first vector sequence and will not be elaborated), and the Euclidean distance between each second vector sequence and the operation intention , that is, the Euclidean distance between the th current instruction sequence and each operation intention, and the minimum target Euclidean distance corresponding to each second vector sequence is determined .
[0106] S224. According to the operation intentions corresponding to different categories and the historical instruction sequences, determine the degree of sudden change of each current instruction sequence.
[0107] It should be noted that for some illegal operation instruction sequences of the attacker, the matching of the operation intention matched by the instruction sequence is weak, and there are some sudden changes (the combination of instructions, the target device or the operation intensity has changed drastically, which may be that the attacker attempts to execute malicious operations).
[0108] First, determine the occurrence frequency of each first vector sequence in the historical operation data, and then, according to different occurrence frequencies, assign different amplitudes to the first vector sequences respectively. For example, the higher the frequency, the higher the amplitude that can be assigned.
[0109] Secondly, according to different occurrence frequencies, split the second vector sequence of each current instruction sequence into multiple subsequence vectors. For example, split the second vector sequence corresponding to the first vector sequence into subsequence vectors with the number of corresponding occurrence frequencies according to the occurrence frequency of the first vector sequence, and match the subsequence vectors with the first vector sequence to determine the target amplitude corresponding to each subsequence vector. For example, use the amplitude of the first vector sequence with the highest matching degree (such as similarity) as the target amplitude corresponding to the corresponding subsequence vector , that is, the th current instruction sequence's th subsequence vector's target amplitude.
[0110] Then, respectively calculate the amplitude mean of each current instruction sequence according to the target amplitude , and respectively calculate the mean absolute error according to the amplitude mean and the target amplitude to obtain the degree of sudden change of each current instruction sequence , that is, the degree of sudden change of the th current instruction sequence, . .
[0111] S225. Respectively determine the second ratio of the degree of sudden change to the corresponding target Euclidean distance , and determine the abnormal risk coefficient of each current instruction sequence according to the second ratio and the normalization function .
[0112] Specifically, the calculation formula of the abnormal risk coefficient is:
[0113] ;
[0114] where is the abnormal risk coefficient of the th current instruction sequence, represents the The degree of abnormal risk contained in the current instruction sequence. When the current instruction sequence of a single user has a large degree of mutation and the matching degree of the current instruction sequence with each sequence in its environment is low, the risk of abnormality in the current instruction sequence is high.
[0115] In one implementation, step S300 includes steps S301 - S302:
[0116] S301. Determine the product of the abnormal risk coefficient and the behavior abnormality degree of each current instruction sequence respectively, and determine the third ratio of the product to the corresponding operation inertia influence degree.
[0117] Optionally, determine the abnormal risk coefficient of each current instruction sequence respectively and the behavior abnormality degree of the product , and determine the third ratio of the product to the corresponding operation inertia influence degree . .
[0118] S302. Calculate the arithmetic mean according to each third ratio and the number of current instruction sequences to obtain the user abnormal state value.
[0119] Optionally, the calculation formula of the user abnormal state value is:
[0120] ;
[0121] In the embodiments of the present application, by evaluating the user's operation time, operation behavior, operation content, and operation intention from multiple dimensions, the user abnormal state value of the user during this login process is comprehensively judged.
[0122] In one implementation, in step S400, when the user abnormal state value is greater than the interception probability threshold ', remotely close the connection channel of the user to the AI industrial Internet of Things platform, and prohibit the user from accessing the AI industrial Internet of Things platform, so as to better maintain the security of the Internet of Things platform and prevent the impact of abnormal user access and attacks on the Internet of Things platform and devices.
[0123] Optionally, the interception probability threshold ' is calculated based on the abnormal behavior interception probability of the AI industrial Internet of Things platform in the recent preset number of days. The specific formula is:
[0124] ' = ;
[0125] Exemplarily, the preset number of days is 3. The total number of abnormal interceptions at the physical layer, network layer, and transport layer within the last 3 days is counted, and then the total number of abnormal interceptions is divided by the total number of detections to obtain the interception probability , so that the interception probability threshold can be determined based on the above formula '.
[0126] In the embodiment of the present application, a multi-layer verification mode is constructed to improve security. The current instruction sequence of the user is used for verification and evaluation. Specifically, by extracting and analyzing the user's historical operation data and the current instruction sequence, the deviation of the coordination degree is determined. Finally, the behavior abnormality degree of the current instruction sequence, the influence degree of the operation inertia of each current instruction sequence, and the abnormal risk coefficient of each current instruction sequence can be determined. Among them, the influence degree of the operation inertia can prevent the unconscious habitual instructions of the user from deviating from the intention of the instruction sequence. Through the semantic vectorization of the instruction sequence, the operation intention can be identified to determine the abnormal risk coefficient. Based on the behavior abnormality degree, the influence degree of the operation inertia, and the abnormal risk coefficient, the user abnormal state value is comprehensively determined, so as to achieve accurate abnormal screening and ensure the secure access of the AI industrial Internet of Things platform
[0127] Referring to Figure 3 , a structural block diagram of the AI industrial Internet of Things platform secure access system according to an embodiment of the present application is shown. The system may include:
[0128] An acquisition module, configured to acquire a plurality of current instruction sequences and historical operation data output by the user on the AI industrial Internet of Things platform
[0129] A first determination module, configured to determine the behavior abnormality degree of each current instruction sequence, the influence degree of the operation inertia of each current instruction sequence, and the abnormal risk coefficient of each current instruction sequence according to the current instruction sequence and the historical operation data
[0130] A second determination module, configured to determine the user abnormal state value according to the behavior abnormality degree, the influence degree of the operation inertia, and the abnormal risk coefficient
[0131] A control module, configured to control the user's access to the AI industrial Internet of Things platform according to the user abnormal state value
[0132] In the embodiment of the present application, the functions of the modules in the system can refer to the corresponding descriptions in the above method, and will not be elaborated here
[0133] In the embodiment of the present application, a terminal is further provided, including: a processor and a memory. Instructions are stored in the memory, and the instructions are loaded and executed by the processor to implement the above method for secure access to the AI industrial Internet of Things platform
[0134] It should be noted that the above sequence of embodiments of the present invention is only for description and does not represent the superiority or inferiority of the embodiments. The processes depicted in the accompanying drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0135] Each embodiment in this specification is described in a progressive manner. For the same or similar parts among the embodiments, reference can be made to each other. Each embodiment focuses on the differences from other embodiments.
Claims
1. A security access method for an AI industrial Internet of Things platform, characterized in that, The method includes: Obtaining a number of current instruction sequences and historical operation data output by a user on an AI industrial Internet of Things platform; According to the current instruction sequences and the historical operation data, respectively determining the behavior abnormality degree of each current instruction sequence, the operation inertia influence degree of each current instruction sequence, and the abnormal risk coefficient of each current instruction sequence; Determining a user abnormal state value according to the behavior abnormality degree, the operation inertia influence degree, and the abnormal risk coefficient; Controlling the user's access to the AI industrial Internet of Things platform according to the user abnormal state value; The method for obtaining the behavior abnormality degree includes: Determining a first instruction sequence from the current instruction sequences, and constructing a first instruction group with any two instructions in the first instruction sequence to obtain a number of first instruction groups; According to the historical operation data, determining the mean value of the first position distances at which the two instructions in each first instruction group appear in the corresponding historical instruction sequence, and determining the second position distance at which the two instructions in each first instruction group appear in the first instruction sequence; Determining a first ratio of the second position distance to the mean value of the first position distances and a first difference between a preset value and the first ratio; Determining the degree of coordination between the two instructions in each first instruction group, and respectively calculating a first product of the absolute value of the difference between the degree of coordination corresponding to each first instruction group and the first difference; Summing according to the first product and the number of the first instruction groups, and obtaining the behavior abnormality degree of the first instruction sequence according to the summation result and a normalization function, and returning to the step of determining the first instruction sequence from the current instruction sequences until the behavior abnormality degree of each current instruction sequence is determined; Determining the operation inertia influence degree of each current instruction sequence according to the current instruction sequences and the historical operation data includes: Determining a second instruction sequence from the current instruction sequences, dividing the second instruction sequence into sequence segments with a preset number of segments, dividing the first two sequence segments with a higher order into a module, adding a sequence segment arranged after the module to the module according to the order, obtaining a new module, and returning to the step of adding a sequence segment arranged after the module to the module according to the order until the last sequence segment is added to obtain a number of modules; Determining the target degree of coordination between the last sequence segment and the remaining respective sequence segments in each module, constructing a two-dimensional curve according to the target degree of coordination, and determining the integral of the first derivative of the two-dimensional curve; Respectively determining a second difference between the integrals of each adjacent module, calculating the arithmetic mean according to the absolute value of the second difference and the number of the modules and performing normalization processing to obtain the operation inertia influence degree of the second instruction sequence, and returning to the step of determining the second instruction sequence from the current instruction sequences until the operation inertia influence degree of each current instruction sequence is determined; Determining the abnormal risk coefficient of each of the current instruction sequences according to the current instruction sequence and the historical operation data includes: Splitting the historical operation data to determine a number of historical instruction sequences, and performing semantic vectorization on the historical instruction sequences to obtain corresponding first vector sequences; Clustering the first vector sequences to determine the operation intents corresponding to different categories; Respectively determining the second vector sequence of each of the current instruction sequences and the Euclidean distance between each second vector sequence and the operation intent, and determining the minimum target Euclidean distance corresponding to each second vector sequence; Determining the degree of sudden change of each of the current instruction sequences according to the operation intents corresponding to different categories and the historical instruction sequences; Respectively determining the second ratio of the degree of sudden change to the corresponding target Euclidean distance, and determining the abnormal risk coefficient of each of the current instruction sequences according to the second ratio and the normalization function.
2. The AI industrial Internet of things platform security access method according to claim 1, wherein: Determining the degree of collaboration between two instructions in each of the first instruction groups includes: Determining that two instructions in each of the first instruction groups appear at the first position and the second position of the first instruction sequence respectively, and determining the Pearson correlation coefficient between the first position and the second position; Determining the frequency of occurrence of any instruction in each of the first instruction groups in the first instruction sequence, and respectively obtaining the degree of collaboration between the two instructions in each of the first instruction groups according to the product of the Pearson correlation coefficient and the frequency.
3. The AI industrial Internet of Things platform security access method according to claim 1, wherein: Determining the degree of sudden change of each of the current instruction sequences according to the operation intents corresponding to different categories and the historical instruction sequences includes: Determining the frequency of occurrence of each of the first vector sequences in the historical operation data, and assigning different amplitudes to the first vector sequences according to different frequencies of occurrence; According to different frequencies of occurrence, splitting the second vector sequence of each of the current instruction sequences into multiple subsequence vectors, and matching the subsequence vectors with the first vector sequences to determine the target amplitude corresponding to each subsequence vector; Respectively calculating the amplitude mean of each of the current instruction sequences according to the target amplitude, and calculating the mean absolute error according to the amplitude mean and the target amplitude respectively to obtain the degree of sudden change of each of the current instruction sequences.
4. The AI industrial Internet of Things platform security access method according to claim 1, characterized in that: Determining the user abnormal state value according to the behavior abnormality degree, the operation inertia influence degree, and the abnormal risk coefficient includes: Respectively determining the product of the abnormal risk coefficient and the behavior abnormality degree of each of the current instruction sequences, and determining the third ratio of the product to the corresponding operation inertia influence degree; Calculating the arithmetic mean according to each of the third ratios and the number of the current instruction sequences to obtain the user abnormal state value.
5. The AI industrial Internet of things platform security access method according to claim 1, wherein: Controlling the user's access to the AI industrial Internet of Things platform according to the user abnormal state value includes: When the user abnormal state value is greater than the interception probability threshold, prohibiting the user from accessing the AI industrial Internet of Things platform; Among them, the interception probability threshold is calculated based on the abnormal behavior interception probability of the AI industrial Internet of Things platform in the recent preset number of days.
6. An AI industrial Internet of Things platform security access system, characterized in that, The steps for implementing the method according to any one of claims 1-5 include: An acquisition module, configured to acquire a plurality of current instruction sequences and historical operation data output by a user on the AI industrial Internet of Things platform; A first determination module, configured to respectively determine the behavior abnormality degree of each current instruction sequence, the influence degree of operation inertia of each current instruction sequence, and the abnormal risk coefficient of each current instruction sequence according to the current instruction sequence and the historical operation data; A second determination module, configured to determine a user abnormal state value according to the behavior abnormality degree, the influence degree of operation inertia, and the abnormal risk coefficient; A control module, configured to control the user's access to the AI industrial Internet of Things platform according to the user abnormal state value.
7. A terminal, characterized in that, Including: A processor and a memory, wherein instructions are stored in the memory, and the instructions are loaded and executed by the processor to implement the method according to any one of claims 1-5.
Citation Information
Patent Citations
Vehicle-mounted terminal control method and device, computer equipment and storage medium
CN117445856A