Multi-mode IOT security and protection equipment grading response device and multi-mode IOT security and protection equipment grading response method
Through the hierarchical response devices and methods of multimodal IOT security equipment, the problems of extensive hierarchy and low security response accuracy in the prior art are solved, and the hierarchy is refined and the response accuracy is improved, and the security effect is improved.
Patent Information
- Application Number
- CN202510252556.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-05
- Publication Date
- 2025-06-13
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
When faced with complex and changing target scenarios, existing IOT security equipment cannot flexibly adjust according to different security tasks and equipment performance, resulting in waste of resources and poor security effects.
Provides multi-modal IOT security equipment hierarchical response devices and methods, including device initialization module, security task analysis module, modal performance analysis module, modal matching module, hierarchical response definition module and hierarchical response execution module. Through the coordinated work of these modules, equipment configuration optimization, task decomposition, modal matching and hierarchical response are realized.
It has achieved refinement of hierarchical and improved response accuracy, avoided waste of resources and improved security effects.
Smart Images

Figure CN120144196A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of security technologies, and particularly to a hierarchical response device and method for multi-modal IOT security devices. Background Art
[0002] IOT security devices are increasingly widely used in various fields. However, existing IOT security devices usually adopt a single response mode. When facing complex and changeable target scenarios, they cannot be flexibly adjusted according to different security tasks and device performances, resulting in waste of resources and poor security effects. There are technical problems such as rough classification and low accuracy of security response. Summary of the Invention
[0003] The present invention provides a hierarchical response device and method for multi-modal IOT security devices to solve the technical problems of rough classification and low accuracy of security response in the prior art, and achieve the technical effects of refined classification and improved response accuracy.
[0004] In a first aspect, the present invention provides a hierarchical response device for multi-modal IOT security devices, wherein the hierarchical response device for multi-modal IOT security devices includes: A device initialization module for analyzing IOT security devices in a target scenario to optimize device configuration.
[0005] A security task parsing module for parsing a security task book of a target scenario, decomposing the task into a plurality of logically related subtask sets, and setting a priority label for each subtask.
[0006] A modal performance parsing module for collecting and analyzing historical protection records to obtain typical protection performance information of IOT security devices.
[0007] A modal matching module for establishing a modal mapping matching relationship between the subtask sets and IOT security devices according to the typical protection performance information, and generating a matching relationship table.
[0008] A hierarchical response definition module for constructing a hierarchical response binary tree based on the matching relationship table, where the hierarchical response binary tree includes a root node, a plurality of sub-binary trees, and a response promotion logic.
[0009] A hierarchical response execution module for establishing a data connection between IOT security devices and the hierarchical response binary tree, and performing hierarchical response according to the security monitoring data of IOT security devices.
[0010] In a second aspect, the present invention further provides a hierarchical response method for multi-modal IOT security devices, wherein the hierarchical response method for multi-modal IOT security devices includes: Analyzing IOT security devices in a target scenario to optimize device configuration.
[0011] Analyze the security task book of the target scenario, decompose the tasks into multiple logically related subtask sets, and set priority tags for each subtask.
[0012] Collect and analyze historical protection records to obtain typical protection performance information of IOT security devices.
[0013] According to the typical protection performance information, establish a modal mapping and matching relationship between the subtask set and the IOT security device, and generate a matching relationship table.
[0014] Based on the matching relationship table, construct a hierarchical response binary tree, which includes a root node, multiple sub-binary trees, and response escalation logic.
[0015] Establish a data connection between the IOT security device and the hierarchical response binary tree, and perform hierarchical responses according to the security monitoring data of the IOT security device.
[0016] In a third aspect, the present invention also provides a computer-readable storage medium storing a computer program, which when executed by a processor, implements the multi-modal IOT security device hierarchical response device provided by the present invention.
[0017] The present invention discloses a multi-modal IOT security device hierarchical response device and method, including: a device initialization module for optimizing the device configuration of the IOT security device for analyzing the target scenario; a security task parsing module for parsing the security task book of the target scenario, decomposing the tasks into multiple logically related subtask sets, and setting priority tags for each subtask; a modal performance parsing module for collecting and analyzing historical protection records to obtain typical protection performance information of the IOT security device; a modal matching module for establishing a modal mapping and matching relationship between the subtask set and the IOT security device according to the typical protection performance information, and generating a matching relationship table; a hierarchical response definition module for constructing a hierarchical response binary tree based on the matching relationship table, the hierarchical response binary tree including a root node, multiple sub-binary trees, and response escalation logic; a hierarchical response execution module for establishing a data connection between the IOT security device and the hierarchical response binary tree, and performing hierarchical responses according to the security monitoring data of the IOT security device. The multi-modal IOT security device hierarchical response device and method disclosed by the present invention solve the technical problems of rough classification and low accuracy of security response, and achieve the technical effects of refined classification and improved response accuracy. Description of the Drawings
[0018] Figure 1 It is a structural schematic diagram of the multi-modal IOT security device hierarchical response device of the present invention; Figure 2This is a schematic flowchart of the hierarchical response method for the multi-modal IOT security device of the present invention.
[0019] Explanation of reference numerals in the drawings: Device initialization module 11, security task analysis module 12, modal performance analysis module 13, modal matching module 14, hierarchical response definition module 15, hierarchical response execution module 16. Specific implementation mode
[0020] The following will combine the description of the drawings and specific implementation modes to elaborate on the above technical solutions in detail to better understand the above technical solutions. Obviously, the described embodiments are only part of the embodiments of the present invention, rather than all the embodiments of the present invention. It should be understood that the present invention is not limited to the example embodiments for explaining the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention. In addition, it should be noted that for the sake of description, only the parts related to the present invention are shown in the drawings rather than all of them.
[0021] Embodiment 1 Figure 1 This is a schematic structural diagram of the hierarchical response device for the multi-modal IOT security device of the present invention. Among them, the hierarchical response device for the multi-modal IOT security device includes: Device initialization module 11, which is used to analyze the IOT security devices in the target scenario for device configuration optimization.
[0022] The device initialization module 11 is a module in the hierarchical response device for the multi-modal IOT security device that is used to perform initial configuration and optimization on the IOT security devices in the target scenario. This module analyzes the standard device configuration information and the actual device configuration information of the target scenario, generates a device configuration update instruction and executes it, thereby realizing the optimization of the device configuration. Among them, the standard device configuration information refers to the device configuration information required according to the security task book, and the actual device configuration information refers to the configuration information of the actual device.
[0023] In some embodiments, the device initialization module 11 includes: Initial configuration acquisition unit, which is used to obtain the standard device configuration information and the actual device configuration information of the target scenario.
[0024] Configuration optimization unit, which is used to compare the standard device configuration information with the actual device configuration information according to the security task book, generate a device configuration update instruction and execute it.
[0025] Specifically, the standard device configuration information is the ideal IOT security device configuration status of the target scenario, including the types, quantities, layouts, parameter settings, etc. of the devices; while the actual device configuration information is the actual device status in the target scenario, which may differ from the standard configuration and needs to be collected through sensors, device interfaces or manual input, etc., including whether the device is operating normally, the network connection status, the current parameters of the device, etc.
[0026] Specifically, according to the security task book, by comparing the standard device configuration information with the actual device configuration information, the differences can be identified and corresponding device configuration update instructions can be generated and executed to optimize the device configuration. Among them, the device configuration update instructions involve adjustments to the device hardware and modifications to the device parameters, and the task book specifies the requirements, goals, tasks and device configuration requirements of the project, providing the specific details and standards for task execution.
[0027] Through the above process, the accuracy of the device configuration is improved, and the adaptability and reliability of the device are also enhanced, enabling it to better meet the requirements of the security task book.
[0028] In some embodiments, the initial configuration acquisition unit further includes: A network topology acquisition subunit, configured to communicate with the IOT central gateway of the target scenario to obtain the device network topology, and extract the standard device configuration information according to the device network topology.
[0029] A multi-mode information acquisition subunit, configured to activate the IOT device network of the target scenario and acquire the current multi-mode information.
[0030] A configuration analysis subunit, configured to analyze the current multi-mode information and extract the actual device configuration information, where the actual device configuration information includes a device failure identifier and a network connection anomaly identifier.
[0031] Specifically, first, communicate with the IoT central gateway through the network topology acquisition subunit to obtain the network topology structure of the devices in the target scenario; then, based on the network topology data, extract the standard configuration information related to each device, such as device type, specification, working parameters, communication protocol, etc.; among them, the IoT central gateway usually manages various intelligent devices connected to the network and is responsible for coordinating the communication and data flow between devices; the network topology describes the connection relationship between devices, the distribution of nodes, the working status of devices, etc.
[0032] Specifically, the multi-mode information acquisition sub-unit collects the current multi-mode information by activating the IOT device network of the target scenario. First, the multi-mode information acquisition sub-unit sends an activation instruction to the IOT device network to make the devices enter the working state; then, it collects the real-time status information of the devices, including the current parameters of the devices, network connection status, device operation status, etc., and outputs it as the current multi-mode information. In other words, the current multi-mode information is the actual operation status information of the devices, which is used to provide real-time data support for subsequent configuration optimization.
[0033] Specifically, the current multi-mode information obtained from the multi-mode information acquisition sub-unit is parsed. First, data preprocessing is performed, including data cleaning, formatting, conversion, etc.; then, a data parsing library, such as JSON parser, XML parser, Protocol Buffers and other technologies, is used to parse the multi-mode data to extract the actual device configuration information, including: device failure identifier, which identifies whether the device has a fault, failure or is unavailable, and can be determined by checking the health status, response time, error log, etc. of the device; network connection anomaly identifier, which checks the network connection status of the device and identifies whether the device is in an offline state, whether there are problems such as connection loss, delay or interruption; through the real-time monitoring of device failures and connection anomalies, the device can timely detect anomalies in the device or network and take measures to repair or reconfigure, so as to ensure the stability and high availability of the entire system.
[0034] In some embodiments, the configuration optimization unit further includes: The first difference comparison sub-unit is used to compare the security task book with the standard device configuration information to generate the first configuration difference information.
[0035] The second difference comparison sub-unit is used to compare the security task book with the actual device configuration information to generate the second configuration difference information.
[0036] The optimization decision sub-unit is used to compare the first configuration difference information with the second configuration difference information and output a hardware configuration optimization form and a set configuration optimization form, where: Obtain the intersection of the first configuration difference information and the second configuration difference information, add the corresponding IOT security devices to the hardware configuration optimization form, and trigger a device update instruction.
[0037] Obtain the difference set of the first configuration difference information and the second configuration difference information, add the corresponding IOT security devices to the set configuration optimization form, and trigger a device parameter adjustment instruction.
[0038] Specifically, first, obtain the security task book from the project management system or relevant departments, understand the specific requirements and standard configurations of the project, and read the device configuration requirements in the security task book; then, compare the requirements in the security task book with the standard device configuration to identify the different parts and generate the first configuration difference information. This first configuration difference information reflects the theoretical device configuration differences and provides a basis for subsequent optimization decisions.
[0039] Subsequently, compare the requirements in the security task book with the actual device configuration to identify the different parts and generate the second configuration difference information. This second configuration difference information reflects the differences between the actual device configuration and the requirements of the task book and provides actual data support for subsequent optimization decisions.
[0040] Furthermore, compare the first configuration difference information with the second configuration difference information and output the hardware configuration optimization form and the setting configuration optimization form to determine which devices need to be replaced and which devices need to have their parameters adjusted, including: analyze the intersection part of the first and second configuration difference information to determine the devices that need to be replaced or repaired, add the devices that need to be replaced to the hardware configuration optimization form, and generate device update instructions; analyze the difference set part of the first and second configuration difference information to determine the devices that need to have their configurations adjusted, add the devices that need to have their configurations adjusted to the setting configuration optimization form, and generate device parameter adjustment instructions.
[0041] Through the comparison by the first difference comparison subunit and the second difference comparison subunit in the above process, the theoretical and actual differences in device configuration can be comprehensively understood, providing accurate data support for optimization decisions; the optimization decision subunit can accurately determine which devices need to be replaced and which devices need to have their parameters adjusted by comparing the intersection and difference set of the first configuration difference information and the second configuration difference information, thus realizing the refined optimization of device configuration.
[0042] The security task analysis module 12 is used to analyze the security task book of the target scenario, decompose the task into multiple logically related subtask sets, and set priority labels for each subtask.
[0043] Specifically, by analyzing the security task book of the target scenario, decomposing the complex security task into multiple logically related subtask sets, and setting priority labels for each subtask, the security task can be managed and executed more precisely. The complex security task is decomposed into smaller and more manageable subtasks, which is convenient for subsequent modality matching and hierarchical response, improving the response efficiency and protection effect of the security system.
[0044] In some embodiments, the security task analysis module 12 includes: A task decomposition unit, configured to decompose a task into a set of subtasks with logical dependencies according to the protection nature and constraint conditions in the security task book.
[0045] A priority annotation unit, configured to extract the influence weight of a subtask on the security task book and assign a priority label to each subtask.
[0046] Specifically, the protection nature refers to the characteristics of the object or area to be protected in the security task, and the constraint conditions refer to the specific conditions that need to be met when executing the security task, such as time, device type, security performance indicators (such as protection distance, security response delay, efficiency), etc.; the priority label is used to identify the priority execution order of the subtasks, that is, the security response level corresponding to the subtasks.
[0047] Specifically, the task decomposition unit first reads the security task book, extracts the protection nature and constraint conditions therein, and then, according to the protection nature and constraint conditions, decomposes the security task into multiple sets of subtasks with logical dependencies. For example, the fire prevention task may include subtasks such as fire monitoring, installation of alarm systems, and configuration of fire extinguishing equipment, and each subtask includes multiple response levels.
[0048] Exemplarily, if the security task book requires 24-hour monitoring in a specific area and three-level responses are set respectively, the task decomposition unit can decompose the task into two sets of subtasks including three subtasks, namely "daytime monitoring" and "nighttime monitoring", and there are logical dependencies between different-level subtasks in each set.
[0049] Specifically, the priority annotation unit extracts the influence weight of each subtask on the security task book from the set of subtasks and assigns a priority label to each subtask. This priority label reflects the logical dependencies between the subtasks. For example, a subtask with a primary response may need to be completed before a subtask with an intermediate response, and a subtask with an intermediate response needs to be completed before a subtask with a high-level response. Then the priority label of the subtask with a primary response is less than the priority label of the subtask with an intermediate response.
[0050] By decomposing complex security tasks into multiple sets of operable subtasks with logical dependencies, the task decomposition unit makes the management of security tasks more refined, facilitating subsequent modal matching and hierarchical response.
[0051] A modal performance analysis module 13, configured to collect and analyze historical protection records to obtain typical protection performance information of IOT security devices.
[0052] Specifically, the typical protection performance information refers to the actual protection effect data of the IOT security device in historical security tasks, including device modality markers, protection achievement rates, protection response delays, etc., which are used to provide data support for subsequent modality matching and hierarchical response.
[0053] In some embodiments, the modality performance analysis module 13 includes: A data acquisition unit, configured to use the subtask set as a retrieval constraint and interact with the protection record library to obtain the historical protection records of the IOT security device for each subtask.
[0054] A performance analysis unit, configured to calculate a central value based on the historical protection records and output it as the typical protection performance information, where the typical protection performance information includes at least device modality markers, protection achievement rates, and protection response delays.
[0055] Specifically, first, the data acquisition unit uses the subtask set as a retrieval constraint and interacts with the protection record library to obtain the historical protection records of the IOT security device for each subtask. These records include the protection results of the device in different modalities, such as whether the protection is successful and the response delay, etc.; then, the performance analysis unit performs central value calculation and analysis on these historical protection records to extract the typical protection performance information; where the device modality refers to the security monitoring state of the IOT security device, which involves sampling accuracy, security monitoring granularity, or device power consumption level, etc.
[0056] Exemplarily, calculating the central value according to the historical protection records includes statistically calculating the ratio of the number of times the device successfully completes protection to the total number of attempts for each subtask to calculate the protection achievement rate; calculating the median or average protection response delay in the historical protection records.
[0057] By obtaining and analyzing the historical protection records of the IOT security device, the protection performance of the device in different modalities, that is, the typical protection performance information, can be accurately evaluated, providing data support for subsequent modality matching and ensuring the accuracy and effectiveness of modality matching.
[0058] A modality matching module 14, configured to establish a modality mapping and matching relationship between the subtask set and the IOT security device according to the typical protection performance information, and generate a matching relationship table.
[0059] Specifically, the modality matching module 14 is used to match device modalities that meet the security response requirements for the set of subtasks according to the typical protection performance information, that is, to determine which devices are suitable to execute which subtasks in what state, and output a matching relationship table. The matching relationship table is a data table used to store the modality mapping relationship between subtasks and devices, and its structure includes fields such as subtask identification, device identification, modality identification, and matching degree, presenting the relationship between subtasks and device modalities in a concise and clear manner, facilitating quick query and invocation, thereby providing intuitive data support for subsequent hierarchical response definition and execution.
[0060] In some embodiments, the modality matching module 14 includes: A single modality matching unit, which is used to take the protection nature and the constraint conditions as the matching targets, and screen and determine the optimal device modality according to the typical protection performance information.
[0061] A multi-modal collaboration unit, which is used to generate a collaborative execution plan for multi-modal devices when a single modality cannot meet the protection nature and the constraint conditions.
[0062] Specifically, the single modality matching unit is used to match and select the data in the typical protection performance information that is most suitable for a specific subtask. For example, in a certain security task, the protection nature is to prevent illegal intrusion, then the modality matching module 14 will find device modalities with high protection achievement rate and low response delay from the typical protection performance information, such as the high-sensitivity working condition modality of infrared induction alarm.
[0063] Furthermore, if a single modality cannot meet the requirements, the multi-modal collaboration unit will generate a collaborative execution plan for multi-modal devices. For example, in the task of emergency entrance and exit control, if relying solely on the access control system may not be efficient, device modalities such as video surveillance and emergency door locks will be coordinated to complete complex tasks.
[0064] Specifically, to generate a collaborative execution plan for multi-modal devices, first, based on the single-modal matching unit, according to the protection nature and constraint conditions, the top N optimal device modalities are selected from the typical protection performance information. These modalities include various protection types, such as video surveillance, intrusion alarm, temperature sensor, etc. For example, in a fire protection task, the top N unit modalities may include video flame detectors, temperature sensors, smoke detectors, etc.; then, the multi-modal collaboration unit randomly combines these top N unit modalities to generate multiple possible device modality combination plans. For example, combining a video flame detector with a temperature sensor, or combining a temperature sensor with a smoke detector, etc. Through random combination, different modality combination methods can be tried to find the optimal collaboration plan; next, the multi-modal collaboration unit interacts with the protection record library to obtain the response records of each generated modality combination plan in historical security tasks, and statistically analyzes the obtained historical security response records to calculate the coordinated protection performance information. For example, calculating the joint protection achievement rate and the joint protection response delay; furthermore, according to the coordinated protection performance information, it is judged whether the current modality combination meets the protection nature and constraint conditions. If the conditions are met, the modality combination is determined as the final collaboration plan; if the conditions are not met, a new modality combination plan is regenerated and the above process is repeated until a modality combination that meets the conditions is found.
[0065] Through the above steps and technical means, the modality matching module 14 can effectively match the sub-task set with IoT security devices, generate a matching relationship table, and provide data support for subsequent task scheduling and execution.
[0066] The hierarchical response definition module 15 is used to construct a hierarchical response binary tree based on the matching relationship table. The hierarchical response binary tree includes a root node, multiple sub-binary trees, and response escalation logic.
[0067] Specifically, the hierarchical response definition module 15 is used to construct a hierarchical response binary tree based on the matching relationship table generated by the modality matching module 14. Among them, the hierarchical response binary tree is a data structure used to represent different response levels and their logical relationships, which helps to reasonably allocate resources and efficiently execute responses when facing complex security tasks.
[0068] Specifically, the hierarchical response binary tree includes a root node, multiple sub-binary trees, and response escalation logic. Among them, the root node represents the highest level of response, each sub-binary tree represents a type of sub-task, including the response levels of that task, and the response escalation logic describes the conversion conditions from a low-level response to a high-level response. Exemplarily, it includes multiple response thresholds and corresponding response paths.
[0069] By constructing a hierarchical response binary tree, a clear division of response levels is achieved, which helps to accurately call the corresponding device modes according to the importance and urgency of different subtasks, avoiding resource waste and unnecessary over-response. At the same time, the flexibility and adaptability of the system are enhanced to ensure stable and efficient security support in various complex scenarios.
[0070] In some embodiments, the hierarchical response definition module 15 includes: A threshold configuration unit for configuring a monitoring response threshold and an execution response threshold for each sub-binary tree node, where the execution response threshold is higher than the monitoring response threshold.
[0071] An emergency protocol association unit for binding the leaf node with the highest response level to a preset emergency protection protocol, where the emergency protection protocol includes a standby device forced start instruction and a multi-modal device linkage instruction.
[0072] Specifically, the monitoring response threshold is a threshold lower than the normal operation requirements, used to detect whether the task enters a critical state. In other words, this threshold is used to trigger real-time monitoring and determine the level of triggered real-time monitoring; the execution response threshold is used to trigger actual countermeasures. For example, when there is a device anomaly or the task is urgent, the execution response threshold will determine whether to enable standby devices or trigger automated tasks (such as automatically extinguishing the fire with a gas extinguishing device, closing the ventilation system, etc.).
[0073] Specifically, the execution response threshold is usually higher than the monitoring response threshold to ensure that higher-level response measures are taken only when necessary. For example, in a fire monitoring node, a lower smoke concentration value is set as the monitoring response threshold to trigger an alarm or increase the monitoring level of IOT security devices, and a higher smoke concentration value is set as the execution response threshold to start the fire extinguishing equipment.
[0074] Specifically, the emergency protection protocol is a set of predefined instructions and operation procedures for quickly starting standby devices and linking multiple device modes in an emergency. Among them, the leaf node with the highest response level represents the most urgent or critical task. When the task execution reaches this leaf node, it indicates that an immediate response is required for protection or fault repair.
[0075] Exemplarily, for a fire monitoring node, the standby device forced start instruction corresponds to: when the main fire hydrant cannot work properly, the standby fire hydrant is forced to start; the multi-modal device linkage instruction corresponds to: when the smoke alarm triggers an alarm, link the video monitoring device to record video, and at the same time start the fire hydrant to extinguish the fire.
[0076] The hierarchical response definition module 15 configures monitoring response thresholds and execution response thresholds for each node, enabling precise control of the system's response level and avoiding over-response or under-response. At the same time, binding the leaf nodes with the highest response level to the preset emergency protection protocol can quickly start backup devices and link multiple device modes in case of emergency, improving the system's response speed, enhancing the system's reliability, and ensuring effective implementation of protection measures in complex and emergency situations.
[0077] The hierarchical response execution module 16 is used to establish a data connection between the IOT security device and the hierarchical response binary tree, and perform hierarchical responses based on the security monitoring data of the IOT security device.
[0078] Specifically, the hierarchical response execution module 16 first establishes a data connection with the IOT security device and receives the security monitoring data of the device in real time, including device status information, sensor data (such as temperature, humidity, smoke concentration, etc.), and the operating parameters of the device. Then, the obtained real-time security monitoring data is used as input and sent to the hierarchical response binary tree for discrimination to determine whether the current state of the device is normal. For example, by comparing the current data with the preset normal range value, it is detected whether there is an abnormal situation. Among them, the data input of each node needs to match the attributes of the node. If the monitoring data meets the threshold conditions of a certain response level, the corresponding response path is activated and enters the next level of comparison (sub-node) to further analyze whether higher response conditions are met. Finally, according to the definition in the hierarchical response binary tree, the corresponding response action is triggered. Among them, the response action can be device status adjustment (such as device restart, mode switching) or triggering an emergency protocol (such as enabling backup devices, linking other modal devices, etc.).
[0079] By combining real-time monitoring data with the hierarchical response binary tree, the hierarchical response execution module 16 can dynamically adjust the response strategy, reduce manual intervention, ensure reasonable and efficient responses in various environments and states, have good adaptability and efficient fault recovery capabilities, and at the same time optimize the use of resources.
[0080] In summary, the multi-modal IOT security device hierarchical response method provided by the present invention has the following technical effects: An equipment initialization module for optimizing equipment configuration through IOT security equipment for analyzing target scenarios; a security task parsing module for parsing the security task book of the target scenario, decomposing the task into multiple logically related subtask sets, and setting priority tags for each subtask; a modal performance parsing module for collecting and analyzing historical protection records to obtain typical protection performance information of the IOT security equipment; a modal matching module for establishing a modal mapping matching relationship between the subtask set and the IOT security equipment according to the typical protection performance information, and generating a matching relationship table; a hierarchical response definition module for constructing a hierarchical response binary tree based on the matching relationship table, the hierarchical response binary tree including a root node, multiple sub-binary trees and response escalation logic; a hierarchical response execution module for establishing a data connection between the IOT security equipment and the hierarchical response binary tree, and performing hierarchical response according to the security monitoring data of the IOT security equipment, so as to achieve the technical effects of hierarchical refinement and improved response accuracy.
[0081] Embodiment 2 Figure 2 is a schematic flow chart of the multi-modal IOT security equipment hierarchical response method of the present invention. For example, Figure 1 in the schematic structural diagram of the multi-modal IOT security equipment hierarchical response device of the present invention can be used to implement as Figure 2 shown in the process.
[0082] Based on the same concept as the multi-modal IOT security equipment hierarchical response device in the above embodiment, the multi-modal IOT security equipment hierarchical response method provided by the present invention further includes: S100: Analyze the IOT security equipment of the target scenario to optimize the equipment configuration.
[0083] S200: Parse the security task book of the target scenario, decompose the task into multiple logically related subtask sets, and set priority tags for each subtask.
[0084] S300: Collect and analyze historical protection records to obtain typical protection performance information of the IOT security equipment.
[0085] S400: Establish a modal mapping matching relationship between the subtask set and the IOT security equipment according to the typical protection performance information, and generate a matching relationship table.
[0086] S500: Based on the matching relationship table, construct a hierarchical response binary tree, the hierarchical response binary tree including a root node, multiple sub-binary trees and response escalation logic.
[0087] S600: Establish a data connection between the IOT security equipment and the hierarchical response binary tree, and perform hierarchical response according to the security monitoring data of the IOT security equipment.
[0088] In some embodiments, for the IOT security devices analyzing the target scenario, device configuration optimization is performed, including: Obtain the standard device configuration information and the actual device configuration information of the target scenario.
[0089] According to the security task book, compare the standard device configuration information with the actual device configuration information, generate a device configuration update instruction and execute it.
[0090] In some implementation manners, obtaining the standard device configuration information and the actual device configuration information of the target scenario includes: Interact with the IOT central gateway of the target scenario, obtain the device network topology, and extract the standard device configuration information according to the device network topology.
[0091] Activate the IOT device network of the target scenario and collect the current multi-mode information.
[0092] Analyze the current multi-mode information and extract the actual device configuration information, where the actual device configuration information includes a device failure identifier and a network connection anomaly identifier.
[0093] In some implementation manners, according to the security task book, comparing the standard device configuration information with the actual device configuration information, generating a device configuration update instruction and executing it includes: Compare the security task book with the standard device configuration information to generate first configuration difference information.
[0094] Compare the security task book with the actual device configuration information to generate second configuration difference information.
[0095] Compare the first configuration difference information with the second configuration difference information, and output a hardware configuration optimization form and a setting configuration optimization form, where: Obtain the intersection of the first configuration difference information and the second configuration difference information, add the corresponding IOT security devices to the hardware configuration optimization form, and trigger a device update instruction.
[0096] Obtain the difference set of the first configuration difference information and the second configuration difference information, add the corresponding IOT security devices to the setting configuration optimization form, and trigger a device parameter adjustment instruction.
[0097] In some embodiments, analyze the security task book of the target scenario, decompose the task into multiple logically related subtask sets, and set a priority label for each subtask, including: According to the protection nature and constraint conditions in the security task book, decompose the task into subtask sets with logical dependencies.
[0098] Extract the impact weight of the subtasks on the security task book and assign a priority label to each subtask.
[0099] In some embodiments, collect and analyze historical protection records to obtain typical protection performance information of IOT security devices, including: Using the subtask set as a retrieval constraint, interact with the protection record library to obtain the historical protection records of IOT security devices for each subtask.
[0100] Calculate the central value based on the historical protection records and output it as the typical protection performance information, where the typical protection performance information includes at least a device mode marker, a protection achievement rate, and a protection response delay.
[0101] In some embodiments, based on the typical protection performance information, establish a modal mapping matching relationship between the subtask set and IOT security devices, and generate a matching relationship table, including: Using the protection nature and the constraint conditions as matching targets, screen and determine the optimal device mode according to the typical protection performance information.
[0102] When a single mode cannot meet the protection nature and the constraint conditions, generate a multi-mode device collaborative execution plan.
[0103] In some embodiments, based on the matching relationship table, construct a hierarchical response binary tree, where the hierarchical response binary tree includes a root node, multiple sub-binary trees, and a response escalation logic, including: Configure a monitoring response threshold and an execution response threshold for each sub-binary tree node, where the execution response threshold is higher than the monitoring response threshold.
[0104] Bind the leaf node with the highest response level to a preset emergency protection protocol, where the emergency protection protocol includes a standby device forced start instruction and a multi-mode device linkage instruction.
[0105] It should be understood that the embodiments mentioned in this specification focus on their differences from other embodiments. The specific embodiments in the foregoing Embodiment 1 are equally applicable to the multi-mode IOT security device hierarchical response method described in Embodiment 2. For the sake of simplicity of the specification, no further expansion will be made here.
[0106] It should be understood that the embodiments and the above descriptions disclosed in the present invention enable those skilled in the art to implement the present invention using the present invention. At the same time, the present invention is not limited to the above-mentioned part of the embodiments. It should be understood that those of ordinary skill in the art can still modify the technical solutions recorded in the foregoing embodiments or perform equivalent replacements on some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be included within the protection scope of the present invention.
Claims
1. A multi-modal IOT security equipment hierarchical response device, characterized in that: The multi-modal IOT security equipment hierarchical response device comprises: Device initialization module, used to analyze IoT security devices in target scenarios and optimize device configuration; The security task analysis module is used to analyze the security task book of the target scenario, decompose the task into multiple logically related subtask sets, and set a priority label for each subtask; Modal performance analysis module, used to collect and analyze historical protection records and obtain typical protection performance information of IoT security equipment; A modal matching module, used to establish a modal mapping matching relationship between the subtask set and the IoT security device according to the typical protection performance information, and generate a matching relationship table; A hierarchical response definition module, used to construct a hierarchical response binary tree based on the matching relationship table, wherein the hierarchical response binary tree includes a root node, multiple sub-binary trees and response promotion logic; The hierarchical response execution module is used to establish a data connection between the IOT security device and the hierarchical response binary tree, and perform a hierarchical response according to the security monitoring data of the IOT security device.
2. The multi-modal IOT security equipment hierarchical response device according to claim 1, characterized in that: The device initialization module includes: An initial configuration acquisition unit, used to obtain standard device configuration information and live device configuration information of a target scene; The configuration optimization unit is used to compare the standard device configuration information with the actual device configuration information according to the security task book, generate and execute device configuration update instructions.
3. The multi-modal IOT security equipment hierarchical response device according to claim 2, characterized in that: The initial configuration collection unit further includes: A network topology acquisition subunit is used to interact with the IoT hub gateway of the target scene, acquire the device network topology, and extract the standard device configuration information according to the device network topology; The multi-mode information collection sub-unit is used to activate the IoT device network of the target scene and collect the current multi-mode information; The configuration parsing subunit is used to parse the current multi-mode information and extract live device configuration information, wherein the live device configuration information includes a device failure mark and a network connection abnormality mark.
4. The multi-modal IOT security equipment hierarchical response device according to claim 3, characterized in that: The configuration optimization unit further includes: A first difference comparison subunit is used to compare the security task book with the standard equipment configuration information to generate first configuration difference information; A second difference comparison subunit is used to compare the security task book with the live device configuration information to generate second configuration difference information; The optimization decision subunit is used to compare the first configuration difference information with the second configuration difference information, and output a hardware configuration optimization form and a setting configuration optimization form, wherein: Obtaining the intersection of the first configuration difference information and the second configuration difference information, adding the corresponding IoT security device to the hardware configuration optimization form, and triggering a device update instruction; Obtain the difference between the first configuration difference information and the second configuration difference information, add the corresponding IOT security device to the setting configuration optimization form, and trigger the device parameter adjustment instruction.
5. The multi-modal IOT security equipment hierarchical response device according to claim 4, characterized in that: The security task parsing module includes: A task decomposition unit, used to decompose the task into a set of subtasks with logical dependencies according to the protection properties and constraints in the security task book; The priority labeling unit is used to extract the influence weight of the subtask on the security task book and assign a priority label to each subtask.
6. The multi-modal IOT security equipment hierarchical response device according to claim 5, characterized in that: The modal performance analysis module includes: A data collection unit is used to obtain the historical protection record of each subtask of the IOT security device by using the subtask set as a retrieval constraint and the interactive protection record library; A performance analysis unit is used to calculate a concentration value based on the historical protection record and output it as the typical protection performance information, wherein the typical protection performance information includes at least a device mode mark, a protection achievement rate, and a protection response delay.
7. The multi-modal IOT security equipment hierarchical response device according to claim 6, characterized in that: The modal matching module comprises: A single-mode matching unit, used to select and determine the optimal device mode based on the typical protection performance information, taking the protection property and the constraint condition as matching targets; The multimodal collaboration unit is used to generate a multimodal device collaborative execution plan when a single mode cannot meet the protection properties and the constraint conditions.
8. The multi-modal IOT security equipment hierarchical response device according to claim 7, characterized in that: The hierarchical response definition module includes: A threshold configuration unit, used to configure a monitoring response threshold and an execution response threshold for each child binary tree node, wherein the execution response threshold is higher than the monitoring response threshold; The emergency protocol association unit is used to bind the leaf node of the highest response level to the preset emergency protection protocol, and the emergency protection protocol includes a backup device forced startup instruction and a multi-modal device linkage instruction.
9. A hierarchical response method for multimodal IOT security equipment, characterized in that: The multimodal IOT security equipment hierarchical response method is applied to the multimodal IOT security equipment hierarchical response device according to any one of claims 1 to 8, comprising: Analyze IoT security devices in target scenarios to optimize device configuration; Analyze the security task book of the target scenario, decompose the task into multiple logically related subtask sets, and set a priority label for each subtask; Collect and analyze historical protection records to obtain typical protection performance information of IoT security equipment; According to the typical protection performance information, a modal mapping matching relationship between the subtask set and the IoT security device is established to generate a matching relationship table; Based on the matching relationship table, construct a hierarchical response binary tree, wherein the hierarchical response binary tree includes a root node, multiple sub-binary trees and response promotion logic; A data connection is established between the IOT security device and the hierarchical response binary tree, and a hierarchical response is performed according to the security monitoring data of the IOT security device.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed, the multimodal IOT security equipment hierarchical response device as described in any one of claims 1 to 8 is implemented.
Citation Information
Patent Citations
MSP protection configuration inter-block time sequence suppression method and system
CN110784782A
Intelligent task alarm rule self-learning method and system based on support priority
CN119441832A
Asset security protection strategy adaptive adjustment method and system
CN119449411A
Electric power cross-modal knowledge fusion multi-agent cooperative processing method and system
CN119477235A