Monitoring method and system for intelligently sensing security information of Internet of Things

By establishing an information analysis model and BP neural network, we automatically monitor and process the information security status of intelligently sensed the Internet of Things, and solve the problem of manual intervention in the existing technology and realize automated exception handling.

CN120389893AInactive Publication Date: 2025-07-29SHENZHEN CHUANGHE TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510581694.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-07
Publication Date
2025-07-29
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The existing intelligent sensing IoT security information monitoring methods can only detect abnormal results and cannot automatically handle abnormalities. They need to rely on managers, resulting in persistence of abnormal conditions.

Method used

By obtaining historical information data, establishing an information analysis model, using BP neural network for feature extraction and training, monitoring real-time information security status, analyzing the causes of abnormalities and judging the levels, and automatically finding and implementing countermeasures.

Benefits of technology

It realizes automatic monitoring and processing of intelligently sensed IoT information security status, reduces dependence on managers, and improves the efficiency of handling abnormal conditions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120389893A_ABST
    Figure CN120389893A_ABST
Patent Text Reader

Abstract

The invention relates to the field of information monitoring, and particularly discloses a monitoring method and system for intelligently sensing security information of the Internet of Things, and the method comprises the steps: obtaining historical information data, carrying out the feature extraction of the historical information data, and building an information analysis model; an information analysis model is adopted to monitor the information security state of the intelligent sensing Internet of Things; when it is monitored that the information security state is abnormal, analyzing the reason that the information security state is abnormal, and judging the abnormal level of the information security state; and searching a countermeasure library according to the abnormal level of the information security state and executing a corresponding countermeasure. According to the method, the analysis model is firstly established according to the historical information, then the analysis model is utilized to monitor the real-time information, whether the information security state is normal or not is judged, the abnormal information security state is automatically processed, and the situation that the exception can be processed only through assistance of management personnel is avoided to the maximum extent.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information monitoring, and particularly to a monitoring method and system for intelligent perception of Internet of Things security information. Background Art

[0002] The intelligent perception Internet of Things is a network that connects any item to the Internet through information sensing devices such as radio frequency identification (RFID), infrared sensors, global positioning systems, and laser scanners, and conducts information exchange and communication according to an agreed protocol to achieve intelligent identification, positioning, tracking, monitoring, and management. The intelligent perception Internet of Things integrates many intelligent technologies in recent years to provide better services for people's lives.

[0003] The information of the intelligent perception Internet of Things is the guarantee for its normal operation. Therefore, the information security of the intelligent perception Internet of Things is particularly important. Therefore, the security information of the intelligent perception Internet of Things will be monitored. However, the existing monitoring methods only monitor abnormal results and cannot process abnormal results, and still require management personnel to process them, which will cause abnormal situations to continue. Summary of the Invention

[0004] The purpose of the present invention is to provide a monitoring method and system for intelligent perception of Internet of Things security information to solve the problems raised in the above background art.

[0005] To achieve the above purpose, the present invention provides the following technical solutions: A monitoring method for intelligent perception of Internet of Things security information, the method comprising: Obtaining historical information data, extracting features from the historical information data, and establishing an information analysis model; Monitoring the information security status of the intelligent perception Internet of Things by using the information analysis model; When the information security status is monitored to be abnormal, analyzing the reason for the abnormal information security status and judging the abnormal level of the information security status; Searching for a countermeasure library according to the abnormal level of the information security status and executing corresponding countermeasures.

[0006] As a further solution of the present invention: the step of extracting features from the historical information data and establishing an information analysis model includes: Randomly dividing the historical information data into a training set and a validation set, the quantity ratio of the training set to the validation set being 4:1, extracting eigenvalue and feature words from the training set to obtain feature data; Substituting the feature data into a BP neural network to obtain an initial analysis model; Substituting the validation set into the initial analysis model, and if the validation passes, the initial analysis model is the information analysis model.

[0007] As a further solution of the present invention, the steps of monitoring the information security status of the intelligent perception Internet of Things by using the information analysis model include: Substitute the real-time information of the intelligent perception Internet of Things into the information analysis model to obtain the security status score of the real-time information; Compare the security status score with a preset threshold to determine whether the information security status of the real-time information is abnormal.

[0008] As a further solution of the present invention, the steps of analyzing the reason for the abnormal information security status and determining the abnormal level of the information security status when the information security status is monitored to be abnormal include: When the information security status is monitored to be abnormal, analyze the device information, traffic information, network information, and environmental information to obtain the device score, traffic score, network score, and environmental score; Multiply the device score, traffic score, network score, and environmental score by the corresponding weights and add them up to obtain the abnormal score; Obtain the abnormal level of the information security status based on the abnormal score.

[0009] The technical solution of the present invention also provides a monitoring system for the security information of the intelligent perception Internet of Things, and the system includes: A model establishment module, configured to obtain historical information data, extract features from the historical information data, and establish an information analysis model; A monitoring module, configured to monitor the information security status of the intelligent perception Internet of Things by using the information analysis model; An analysis module, configured to analyze the reason for the abnormal information security status and determine the abnormal level of the information security status when the information security status is monitored to be abnormal; An execution module, configured to search for a countermeasure library according to the abnormal level of the information security status and execute corresponding countermeasures.

[0010] As a further solution of the present invention, the model establishment module includes: A data acquisition unit, configured to obtain historical information data; A feature extraction unit, configured to randomly divide the historical information data into a training set and a validation set, the quantity ratio of the training set to the validation set is 4:1, extract feature values and feature words from the training set to obtain feature data; A model establishment unit, configured to substitute the feature data into a BP neural network to obtain an initial analysis model; A validation unit, configured to substitute the validation set into the initial analysis model, and if the validation passes, the initial analysis model is the information analysis model.

[0011] As a further solution of the present invention, the monitoring module includes: A score generation unit, configured to substitute the real-time information of the intelligent perception Internet of Things into an information analysis model to obtain the security status score of the real-time information; A status judgment unit, configured to compare the security status score with a preset threshold to judge whether the information security status of the real-time information is abnormal.

[0012] As a further solution of the present invention: the analysis module includes: A single-item score generation unit, configured to analyze device information, traffic information, network information, and environmental information when the information security status is detected to be abnormal, and obtain a device score, a traffic score, a network score, and an environmental score; An abnormal score generation unit, configured to multiply the device score, the traffic score, the network score, and the environmental score by corresponding weights and add them up to obtain an abnormal score; A level judgment unit, configured to obtain the abnormal level of the information security status based on the abnormal score.

[0013] Compared with the prior art, the beneficial effects of the present invention are as follows: The present invention first establishes an analysis model based on historical information, and then uses the analysis model to monitor real-time information, judge whether the information security status is normal, and automatically process the abnormal information security status, thus avoiding the need for the assistance of management personnel to process abnormalities to the greatest extent. Description of the Drawings

[0014] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings in the following description are only some embodiments of the present invention.

[0015] Figure 1 It is a flow block diagram of a monitoring method for security information of an intelligent perception Internet of Things.

[0016] Figure 2 It is a partial first sub-flow block diagram of a monitoring method for security information of an intelligent perception Internet of Things.

[0017] Figure 3 It is a second sub-flow block diagram of a monitoring method for security information of an intelligent perception Internet of Things.

[0018] Figure 4 It is a third sub-flow block diagram of a monitoring method for security information of an intelligent perception Internet of Things.

[0019] Figure 5 It is a composition structure block diagram of a monitoring system for security information of an intelligent perception Internet of Things.

[0020] Figure 6 It is a composition structure block diagram of a model establishment module in a monitoring system for security information of an intelligent perception Internet of Things.

[0021] Figure 7 It is a block diagram of the composition structure of the monitoring module in the monitoring system for intelligent perception of Internet of Things security information.

[0022] Figure 8 It is a block diagram of the composition structure of the analysis module in the monitoring system for intelligent perception of Internet of Things security information. Specific implementation manners

[0023] Currently, it is still necessary to manually judge the situation captured by the camera before taking measures. The monitoring personnel monitor multiple cameras at the same time and rely on the experience of the monitoring personnel for judgment. It may be that due to the experience of the monitoring personnel, unsafe behaviors are judged as safe behaviors, or the monitoring personnel cannot discover unsafe behaviors in time.

[0024] In order to make the technical problems, technical solutions and beneficial effects to be solved by the present invention clearer and more understandable, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0025] Embodiment 1: Figure 1 It is a flowchart of the monitoring method for intelligent perception of Internet of Things security information. In an embodiment of the present invention, a monitoring method for intelligent perception of Internet of Things security information, the method includes: Step S100: Obtain historical information data, extract features from the historical information data, and establish an information analysis model; Each information data represents its information security status. By obtaining all the historical information data and extracting features from it, the common features of the information data can be obtained. These common features can represent the corresponding information security status, and then these common features can be used to establish a model that can indicate the information security status, which is convenient for subsequent judgment of whether the information security status is normal.

[0026] Step S200: Monitor the information security status of the intelligent perception Internet of Things by using the information analysis model; An analysis model has been established based on the common features of the information data, and then this analysis model is applied to the real-time monitoring of the information security status, and it can be known whether the information security status is normal.

[0027] Step S300: When the information security status is monitored to be abnormal, analyze the reason for the abnormal information security status and judge the abnormal level of the information security status; The analysis model determines whether the information security status is normal. When the information security status is normal, no operation is required. When the information security status is abnormal, finding out the reasons for the abnormal information security status helps to more accurately restore the abnormal information security status to normal. According to the degree of impact on information security, information security statuses are divided into different abnormal levels.

[0028] Step S400: Search the countermeasure library according to the abnormal level of the information security status and execute the corresponding countermeasures.

[0029] The countermeasure strategies for information security statuses with different abnormal levels are different. Each abnormal level of information security status has corresponding countermeasure strategies, and these countermeasure strategies together form the countermeasure library. When the abnormal level of the information security status is known, finding out the corresponding countermeasure strategy from the countermeasure library and executing it can restore the information security status to normal.

[0030] Figure 2 It is the first sub-process block diagram of the monitoring method for intelligently perceiving Internet of Things security information. The steps of extracting features from historical information data and establishing an information analysis model include: Randomly divide the historical information data into a training set and a validation set. The quantity ratio of the training set to the validation set is 4:1. Extract eigenvalue and eigenword from the training set to obtain feature data. All historical information data constitutes samples. The training set is used to establish an analysis model, and the validation set is used to ensure the accuracy of the established analysis model. Randomly dividing the training set and the validation set can better utilize the common features of information data, making the subsequent established model more accurate. Information data includes the content of information, the transmission speed of information, the transmission path of information, etc. Feature words can be extracted from the content of information, and representative features of the transmission speed of information, the transmission path of information, etc. can be extracted to obtain eigenvalues. The eigenvalues and eigenwords together constitute the feature data.

[0031] Substitute the feature data into the BP neural network to obtain an initial analysis model.

[0032] The BP neural network is a multi-layer feedforward network trained by the error backpropagation algorithm and is one of the most widely used neural network models currently. The BP network can learn and store a large number of input-output pattern mapping relationships without revealing the mathematical equations describing this mapping relationship in advance. Training the eigenwords and eigenvalues using the BP neural network can obtain an analysis model established using the common features of information data, and this analysis model is the initial analysis model.

[0033] Substitute the validation set into the initial analysis model. If the verification passes, the initial analysis model is the information analysis model.

[0034] To ensure that the performance of the established analysis model meets the requirements, it is also necessary to verify the initial analysis model using the validation set. Substitute the validation set into the initial analysis model. When the number of iterations reaches the preset number or the performance converges, the initial analysis model at this time can be regarded as meeting the requirements, and the verification is passed. The initial analysis model can be used as the information analysis model; when the number of iterations does not reach the preset number or the performance does not converge, the initial analysis model at this time is regarded as an unqualified model, the verification fails, and the samples are randomly divided into a training set and a validation set again, and a new initial analysis model is established until the verification is passed.

[0035] Figure 3 It is the second sub - process block diagram of the monitoring method for the security information of the intelligent perception Internet of Things. The steps of monitoring the information security status of the intelligent perception Internet of Things using the information analysis model include: Substitute the real - time information of the intelligent perception Internet of Things into the information analysis model to obtain the security status score of the real - time information. Obtain the real - time information data of the intelligent perception Internet of Things, and use the information analysis model to judge the real - time information data, then the specific information security status of the real - time information data can be obtained. Each information security status has a corresponding security status score, and thus the security status score of the real - time information data can be known.

[0036] Compare the security status score with the preset threshold to judge whether the information security status of the real - time information is abnormal.

[0037] Each security status score has a corresponding security level. Compare the security status score with the preset threshold. When the security status score is not greater than the preset threshold, the information security status of the real - time information is normal, and no subsequent work is required at this time; when the security status score is greater than the preset threshold, the information security status of the real - time information is abnormal, and at this time, it is necessary to further judge the degree of abnormality to determine whether the server can solve it automatically.

[0038] Figure 4 It is the third sub - process block diagram of the monitoring method for the security information of the intelligent perception Internet of Things. The steps of analyzing the reason for the abnormal information security status and judging the abnormal level of the information security status when the information security status is monitored as abnormal include: When the information security status is monitored as abnormal, analyze the device information, traffic information, network information, and environmental information to obtain the device score, traffic score, network score, and environmental score. When the information security status is confirmed to be abnormal, it is necessary to know the reason for the abnormality so that the problem can be solved. Generally, it is analyzed from four aspects: the device itself, traffic, communication network, and environment. Whether there is a failure in the device itself, whether the traffic exceeds the originally required traffic, whether the communication network is secure, and whether the environment such as the temperature and humidity of the device is normal will all cause the information security status to become abnormal. According to the actual situation and judgment criteria of each aspect, the device score, traffic score, network score, and environment score are obtained respectively.

[0039] The device score, traffic score, network score, and environment score are multiplied by the corresponding weights and added together to obtain the abnormality score. The degrees of contribution of the four aspects of the device itself, traffic, communication network, and environment to the abnormal state are different. The management personnel set the weights of the device itself, traffic, communication network, and environment based on experience. The greater the degree of contribution to the abnormal state, the greater the weight. The sum of the scores obtained by multiplying the scores of each aspect by their respective weights is the comprehensive abnormality score.

[0040] The abnormal level of the information security status is obtained based on the abnormality score.

[0041] The abnormality score is compared with the preset abnormal level scores. The information security status belongs to the abnormal level within the range of the abnormal level scores where the abnormality score is located.

[0042] Embodiment 2: Figure 5 It is a block diagram of the composition structure of a monitoring system for intelligently perceiving the security information of the Internet of Things. In the embodiment of the present invention, a monitoring system for intelligently perceiving the security information of the Internet of Things, the system includes: A model establishment module, configured to obtain historical information data, extract features from the historical information data, and establish an information analysis model; A monitoring module, configured to monitor the information security status of the intelligent perception Internet of Things by using the information analysis model; An analysis module, configured to analyze the reason for the abnormal information security status and judge the abnormal level of the information security status when the information security status is monitored to be abnormal; An execution module, configured to search for a countermeasure library according to the abnormal level of the information security status and execute corresponding countermeasures.

[0043] Figure 6 It is a block diagram of the composition structure of the model establishment module in the monitoring system for intelligently perceiving the security information of the Internet of Things. In the embodiment of the present invention, the model establishment module includes: A data acquisition unit, configured to acquire historical information data; A feature extraction unit, configured to randomly divide the historical information data into a training set and a validation set, the quantity ratio of the training set to the validation set is 4:1, extract eigenvalue and feature words from the training set, and obtain feature data. A model building unit for substituting feature data into a BP neural network to obtain an initial analysis model; A verification unit for substituting a verification set into the initial analysis model. If the verification passes, the initial analysis model becomes an information analysis model.

[0044] Figure 7 It is a block diagram of the composition structure of the monitoring module in the monitoring system for the security information of the intelligent perception Internet of Things. In an embodiment of the present invention, the monitoring module includes: A score generation unit for substituting the real-time information of the intelligent perception Internet of Things into the information analysis model to obtain the security status score of the real-time information; A status judgment unit for comparing the security status score with a preset threshold to judge whether the information security status of the real-time information is abnormal.

[0045] Figure 8 It is a block diagram of the composition structure of the analysis module in the monitoring system for the security information of the intelligent perception Internet of Things. In an embodiment of the present invention, the analysis module includes: A single-item score generation unit for analyzing device information, traffic information, network information, and environmental information when the information security status is detected to be abnormal, and obtaining a device score, a traffic score, a network score, and an environmental score; An abnormal score generation unit for multiplying the device score, the traffic score, the network score, and the environmental score by corresponding weights and adding them up to obtain an abnormal score; A level judgment unit for obtaining the abnormal level of the information security status based on the abnormal score.

[0046] All functions that the monitoring method for the security information of the intelligent perception Internet of Things can achieve are completed by a computer device. The computer device includes one or more processors and one or more memories. At least one program code is stored in the one or more memories, and the program code is loaded and executed by the one or more processors to implement the functions of the user behavior prediction method based on big data.

[0047] The processor fetches instructions from the memory one by one, analyzes the instructions, and then completes corresponding operations according to the requirements of the instructions, generating a series of control commands to make each part of the computer operate automatically, continuously, and coordinately, becoming an organic whole to realize the input of the program, the input of data, and the operation and output of results. All arithmetic operations or logical operations generated in this process are completed by the arithmetic unit; the memory includes a read-only memory (ROM), and the read-only memory is used to store computer programs. A protection device is provided outside the memory.

[0048] Exemplarily, a computer program can be segmented into one or more modules. One or more modules are stored in a memory and executed by a processor to implement the present invention. One or more modules can be a series of computer program instruction segments capable of performing specific functions, and these instruction segments are used to describe the execution process of the computer program in a terminal device.

[0049] Those skilled in the art can understand that the above description of the service device is merely an example and does not constitute a limitation on the terminal device. It may include more or fewer components than the above description, or combine certain components, or different components. For example, it may include input / output devices, network access devices, buses, etc.

[0050] The so-called processor may be a central processing unit (CPU), or may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The above processor is the control center of the above terminal device, and uses various interfaces and lines to connect all parts of the entire user terminal.

[0051] The above memory can be used to store computer programs and / or modules. The above processor realizes various functions of the above terminal device by running or executing the computer programs and / or modules stored in the memory, and calling the data stored in the memory. The memory mainly includes a program storage area and a data storage area. Among them, the program storage area can store an operating system, application programs required for at least one function (such as an information collection template display function, a product information release function, etc.); the data storage area can store data created according to the use of the berth status display system (such as product information collection templates corresponding to different product types, product information to be released by different product providers, etc.). In addition, the memory may include high-speed random access memory, and may also include non-volatile memory, such as hard disks, memory, plug-in hard disks, smart media cards (SMCs), secure digital (SD) cards, flash cards, at least one magnetic disk storage device, flash memory device, or other volatile solid-state storage devices.

[0052] When the modules / units integrated in a terminal device are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, to implement all or part of the modules / units in the above-mentioned embodiment systems of the present invention, it can also be completed by instructing relevant hardware through a computer program. The above computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, it can implement the functions of the above various system embodiments. Among them, the computer program includes computer program code, and the computer program code can be in the form of source code, object code, executable file or some intermediate form, etc. The computer-readable medium can include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disc, computer memory, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), electrical carrier signal, telecommunication signal, and software distribution medium, etc.

[0053] It should be noted that in this article, the term "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed, or further includes elements inherent to such process, method, article or device. Without further limitations, an element defined by the statement "including a..." does not exclude the existence of another identical element in the process, method, article or device including the element.

[0054] The above are only the preferred embodiments of the present invention, and do not limit the patent scope of the present invention accordingly. Any equivalent structure or equivalent process transformation made by using the specification and drawings of the present invention, or directly or indirectly applied in other related technical fields, shall be equally included in the patent protection scope of the present invention.

Claims

1. A monitoring method for intelligently perceiving security information of the Internet of Things, characterized in that, The method includes: Obtaining historical information data, extracting features from the historical information data, and establishing an information analysis model; Using the information analysis model to monitor the information security status of the intelligent perception Internet of Things; When the information security status is monitored as abnormal, analyzing the reason for the abnormal information security status and judging the abnormal level of the information security status; Searching the countermeasure library according to the abnormal level of the information security status and executing the corresponding countermeasures.

2. The monitoring method for intelligent perception of Internet of Things security information according to claim 1, wherein The steps of extracting features from the historical information data and establishing an information analysis model include: Randomly dividing the historical information data into a training set and a validation set, with the quantity ratio of the training set to the validation set being 4:1, extracting eigenvalue and feature words from the training set to obtain feature data; Substituting the feature data into a BP neural network to obtain an initial analysis model; Substituting the validation set into the initial analysis model, and if the validation passes, the initial analysis model is the information analysis model.

3. The monitoring method for intelligent perception of Internet of Things security information according to claim 1, characterized in that, The steps of using the information analysis model to monitor the information security status of the intelligent perception Internet of Things include: Substituting the real-time information of the intelligent perception Internet of Things into the information analysis model to obtain the security status score of the real-time information; Comparing the security status score with a preset threshold to judge whether the information security status of the real-time information is abnormal.

4. The monitoring method for intelligent perception of Internet of Things security information according to claim 1 or 3, characterized in that, The steps of analyzing the reason for the abnormal information security status and judging the abnormal level of the information security status when the information security status is monitored as abnormal include: When the information security status is monitored as abnormal, analyzing device information, traffic information, network information, and environmental information to obtain a device score, a traffic score, a network score, and an environmental score; Multiplying the device score, traffic score, network score, and environmental score by the corresponding weights and adding them up to obtain an abnormal score; Obtaining the abnormal level of the information security status based on the abnormal score.

5. An intelligent perception Internet of Things security information monitoring system, characterized in that, The system includes: A model establishment module for obtaining historical information data, extracting features from the historical information data, and establishing an information analysis model; A monitoring module for using the information analysis model to monitor the information security status of the intelligent perception Internet of Things; An analysis module for analyzing the reason for the abnormal information security status and judging the abnormal level of the information security status when the information security status is monitored as abnormal; An execution module for searching the countermeasure library according to the abnormal level of the information security status and executing the corresponding countermeasures.

6. The monitoring system for intelligently perceiving Internet of Things security information according to claim 5, characterized in that, The model establishment module includes: A data acquisition unit for obtaining historical information data; A feature extraction unit for randomly dividing the historical information data into a training set and a validation set, with the quantity ratio of the training set to the validation set being 4:1, extracting eigenvalue and feature words from the training set to obtain feature data; A model establishment unit for substituting the feature data into a BP neural network to obtain an initial analysis model; A validation unit for substituting the validation set into the initial analysis model, and if the validation passes, the initial analysis model is the information analysis model.

7. The monitoring system for intelligent perception of Internet of Things security information according to claim 5, characterized in that, The monitoring module includes: A score generation unit for substituting the real-time information of the intelligent perception Internet of Things into the information analysis model to obtain the security status score of the real-time information; A status judgment unit for comparing the security status score with a preset threshold to judge whether the information security status of the real-time information is abnormal.

8. The monitoring system for intelligently perceiving Internet of Things security information according to claim 5 or 7, characterized in that, The analysis module includes: A single-item score generation unit, which is used to analyze device information, traffic information, network information, and environmental information when the information security status is monitored to be abnormal, and obtain a device score, a traffic score, a network score, and an environmental score; An abnormal score generation unit, which is used to multiply the device score, the traffic score, the network score, and the environmental score by corresponding weights and add them up to obtain an abnormal score; A level judgment unit, which is used to obtain the abnormal level of the information security status based on the abnormal score.