Hierarchical security management and control method and system for Internet of Things equipment in smart park
By collecting static attributes of the equipment and monitoring dynamic behavior, dynamically dividing risk levels and adjusting access permissions in real time, the problem of dynamic changes in the security control of IoT devices is solved, and efficient security management of smart parks is achieved to prevent the spread of threats.
Patent Information
- Application Number
- CN202510692887.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2025-05-12
- Filing Date
- 2025-05-27
- Publication Date
- 2025-08-15
- Estimated Expiration
- 2045-05-27
AI Technical Summary
The existing IoT device security control methods cannot effectively respond to the dynamic changes brought about by the surge in the number of devices and the complexity of the network environment, resulting in the inability to adjust security strategies in a timely manner, it is difficult to identify and isolate high-risk threats, and it is easy to lead to the spread of security incidents.
By collecting the static attributes of IoT devices and monitoring their dynamic behavior, dynamically classify risk levels, setting access permission rules, and monitoring traffic patterns in real time, discovering abnormal devices, re-rated and blocking communications at high risk, and using a virtual LAN for isolation and encrypted transmission.
It realizes efficient and dynamic hierarchical security control of IoT devices, timely discovers and isolates abnormal devices, prevents attacks from spreading, ensures the security of the park network, and improves the stability and security of equipment operation.
Smart Images

Figure CN120498804A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of Internet of Things security technology, and in particular to a hierarchical security management and control method and system for Internet of Things devices in a smart park. Background Art
[0002] With the rapid development of smart campuses, IoT devices have been widely used in various fields, including production control, environmental monitoring, and security management. These devices are interconnected through networks, enabling data collection, transmission, and processing, providing technical support for the efficient operation of smart campuses. However, the diversity and openness of IoT devices present significant security challenges in their application. Therefore, efficient security management and control of these devices, particularly dynamically adjusting security policies based on device attributes and behavior, has become a key issue in the security management of IoT devices in smart campuses.
[0003] Currently, to address security risks associated with IoT devices, a common security management approach is based on static grouping and predefined security policies. Specifically, this approach aggregates and categorizes devices' static attributes, dividing them into different groups and configuring corresponding access control rules for each group. This approach can mitigate network risks to a certain extent and is particularly suitable for scenarios with a small number of devices and a simple network topology.
[0004] However, with the surge in the number of devices in smart campuses and the increasing complexity of network environments, existing security management methods based on static grouping and predefined policies have gradually exposed certain limitations. When device operating status anomalies occur (such as a sudden increase in communication frequency or abnormal data traffic distribution), existing solutions are unable to dynamically adjust to these changes and implement corresponding security measures. Summary of the Invention
[0005] In response to the above-mentioned technical problems and defects, the purpose of this application is to provide a hierarchical security management method and system for IoT devices in a smart park, which can solve the problem of how to efficiently achieve dynamic hierarchical security management of IoT devices.
[0006] On the first aspect, the present application provides a hierarchical security management method for IoT devices in a smart park, including: collecting static attributes of each IoT device, the static attributes including production functions, data confidentiality and external network accessibility, the data confidentiality refers to the importance of the data processed by the IoT device, and the external network accessibility refers to whether the IoT device has a communication path and access rights to directly access the external network; monitoring the dynamic behavior of each IoT device, the dynamic behavior including communication frequency and traffic pattern, the communication frequency refers to the number of times the device sends or receives data per unit time, the traffic pattern refers to the traffic characteristics of the IoT device for network communication, the traffic characteristics include traffic scale, traffic direction, traffic distribution, protocol type and connection mode; according to The static attributes and the dynamic behaviors are used to classify the risk level of the IoT device to obtain a device level, which includes high risk, medium risk and low risk; based on the device level, access permission rules are set, and the access permission rules are used to limit the communication permission of the IoT device; by monitoring the traffic pattern of the IoT device in real time, it is detected whether there is an abnormal traffic pattern, and the abnormal traffic pattern means that the communication data transmission of the IoT device exceeds the access permission rules; if so, the IoT device in the abnormal traffic pattern is determined to be an abnormal device; the abnormal device is re-classified into the risk level to obtain a new device level; if the new device level is high risk, the communication of the abnormal device is blocked to prevent the attack from spreading.
[0007] By implementing this technical solution, we first collect static attributes of IoT devices. The production function reflects the device's role within the campus, the data classification reflects the importance of the processed data, and the external network reachability indicates the device's connection to the external network. This static information provides the basis for risk assessment. Next, we monitor dynamic behavior. Communication frequency and traffic patterns reflect the device's real-time communication status. By assigning risk levels based on static attributes and dynamic behavior, we can clearly define the device's risk level. Access rights rules are set to restrict communication permissions and enhance security. Real-time monitoring of traffic patterns allows for the timely identification of anomalous devices, which can be re-rated and communication blocked when high-risk occurs, effectively preventing the spread of attacks and ensuring the secure and stable operation of campus IoT devices.
[0008] Optionally, in some embodiments, the risk level of the IoT device is divided according to the static attributes and the dynamic behavior to obtain a device level, specifically including: calculating an initial risk score of the IoT device, and assigning a weighted score according to the production function, data confidentiality level, and external network accessibility in the static attributes; dynamically adjusting the initial risk score according to the communication frequency and traffic pattern monitored by the dynamic behavior to obtain an adjusted risk score; judging the adjusted risk score according to a preset risk score threshold to obtain a device level, and the device level is divided into high risk, medium risk, and low risk levels.
[0009] By employing this technical solution, the initial risk score is calculated using a weighted approach based on production function, data security level, and external network accessibility. This is because different production functions have varying impacts on the campus. Higher data security levels increase risk, while external network accessibility increases risk. These factors combine to determine the initial risk. The initial risk score is then dynamically adjusted based on the communication frequency and traffic patterns detected through dynamic behavior monitoring, ensuring it more closely reflects the device's real-time status. Finally, the device level is determined based on pre-set risk score thresholds. This allows for more scientific and accurate risk grading of IoT devices, providing a basis for subsequent security management and control.
[0010] Optionally, in some embodiments, the adjusted risk score includes a first risk score, a second risk score, or a third risk score, specifically including: dynamically adjusting the initial risk score based on the communication frequency and traffic pattern monitored by the dynamic behavior to obtain an adjusted risk score; when the communication frequency exceeds a preset frequency threshold, determining the first risk score, and the first risk score is greater than the initial risk score; when an abnormal traffic direction or protocol type is detected in the traffic pattern, determining the second risk score, and the second risk score is greater than the first risk score; when the traffic scale or traffic distribution is detected in the traffic pattern to be stable and conforms to the normal pattern, determining the third risk score, and the third risk score is less than the second risk score.
[0011] By employing this technical solution, when the communication frequency exceeds a preset frequency threshold, it indicates that the device may be under attack or experiencing abnormal operation. Therefore, the first risk score is determined to be greater than the initial risk score, reflecting a higher risk. If anomalies in the traffic pattern are detected in the traffic direction or protocol type, this may indicate a malicious attack, so the second risk score is greater than the first risk score. On the other hand, when the traffic scale or traffic distribution is stable and conforms to normal patterns, it indicates that the device is in good communication status and the risk is low, so the third risk score is smaller than the second risk score. This dynamic adjustment can more accurately reflect the device's real-time risk status.
[0012] Optionally, in some embodiments, access permission rules are set based on the device level, specifically including: establishing a virtual local area network, which isolates the communication of the IoT device; establishing a secure communication channel between the IoT devices through the virtual local area network, which is used to realize encrypted data transmission between the IoT devices; performing communication permission verification on the secure communication channel to prevent unauthorized devices from passing through the secure communication channel.
[0013] By implementing the above technical solution, a virtual local area network (VLAN) is established to isolate IoT devices and prevent the spread of malicious attacks between devices. Furthermore, a secure communication channel is established based on this. Leveraging the isolation provided by the VLAN, data transmission security is further ensured. Data encryption prevents data theft or tampering during transmission. Communication permission verification is performed on the secure communication channel, ensuring only authorized devices are allowed access and preventing unauthorized devices from accessing. This further enhances the security of IoT device communications and safeguards campus data security.
[0014] Optionally, in some embodiments, a secure communication channel is established between the IoT devices through the virtual local area network, specifically including: generating an encryption key based on the unique identifier of the IoT device; establishing a secure communication channel through the virtual local area network according to the encryption key, and the secure communication channel is an end-to-end encrypted channel; allocating the secure communication channel of the high-risk device to an independent virtual local area network, and the independent virtual local area network is used to isolate and protect the high-risk device; allocating the secure communication channel of the medium-risk device to a shared virtual local area network, and the shared virtual local area network limits direct communication with the high-risk device.
[0015] By implementing this technical solution, encryption keys are generated based on the unique identifiers of IoT devices, ensuring their uniqueness and security. This key is used to establish an end-to-end encrypted secure communication channel, effectively preventing data interception during transmission. Assigning the secure communication channels of high-risk devices to independent virtual local area networks (VLANs) prevents them from impacting other devices, achieving isolation and protection. Assigning medium-risk devices to shared virtual local area networks restricts direct communication with high-risk devices, reducing their vulnerability to attack and improving the overall security of IoT device communications on campus.
[0016] Optionally, in some embodiments, the abnormal device is reclassified into a risk level to obtain a new device level. If the new device level is high risk, the communication of the abnormal device is blocked, specifically including: after detecting the abnormal traffic pattern, recalculating the risk score of the abnormal device; if the risk score exceeds the high risk threshold, adjusting the device level of the abnormal device to obtain a new device level of high risk; if the new device level is high risk, isolating the abnormal device through an independent virtual LAN to block its external network access rights.
[0017] By employing this technical solution, after detecting abnormal traffic patterns, the risk score of the abnormal device is recalculated. If it exceeds the high-risk threshold, the device risk has significantly increased, and its device level is adjusted to high risk. At this point, the abnormal device is isolated through a separate virtual local area network, blocking its external network access. This prevents the abnormal device from maliciously communicating with the external network, preventing the further spread of the attack, protecting other IoT devices within the campus from potential threats, and ensuring the security and stability of the entire campus IoT system.
[0018] Optionally, in some embodiments, if the new device level is high risk, after blocking the communication of the abnormal device, the method further includes: copying the real-time communication traffic of the high-risk abnormal device to obtain traffic mirror data; performing a security analysis on the traffic mirror data to determine whether the abnormal device has unupdated firmware, known vulnerabilities or abnormal configurations, the security analysis including detecting firmware versions, open ports, system logs and security configuration status to identify potential vulnerabilities or unfixed weaknesses; if it is detected that the abnormal device has unupdated firmware or known vulnerabilities, installing the latest security patch or firmware update; if it is detected that the abnormal device has an abnormal configuration, resetting the access permission rules of the abnormal device; after the repair is completed, re-evaluating the risk level of the abnormal device and updating the new device level; if the new device level is reduced to medium risk or low risk, lifting the isolation and restoring communication permissions.
[0019] By implementing this technical solution, the real-time communication traffic of high-risk, abnormal devices is replicated to generate traffic mirror data, facilitating subsequent in-depth analysis. Security analysis of traffic mirror data comprehensively detects whether devices have out-of-date firmware, known vulnerabilities, or abnormal configurations. Once issues are identified, security patches or firmware updates can be installed, and access rights rules can be reset to remediate device security vulnerabilities. After the repair is complete, the risk level is reassessed. If the level decreases, isolation is lifted and communication permissions are restored. This ensures device security and allows the device to resume normal operation in a secure state, improving the availability and security of campus IoT devices.
[0020] In the second aspect, an embodiment of the present application provides a hierarchical security management and control system for IoT devices in a smart park, comprising: one or more processors and a memory; the memory is coupled to the one or more processors, the memory is used to store computer program code, the computer program code includes computer instructions, and the one or more processors call the computer instructions to enable the electronic device to execute the method described in the first aspect or the second aspect, and any possible implementation method of the first aspect or the second aspect.
[0021] In a third aspect, the present application provides a computer-readable storage medium comprising instructions, which, when executed on the electronic device, enables the electronic device to execute the method described in the first aspect or the second aspect, and any possible implementation of the first aspect or the second aspect.
[0022] In a fourth aspect, the present application provides a computer program product comprising instructions, which, when the above-mentioned computer program product is run on the above-mentioned electronic device, enables the above-mentioned electronic device to execute the method described in the first aspect or the second aspect, and any possible implementation method of the first aspect or the second aspect.
[0023] It is understood that the hierarchical security management and control system for IoT devices in a smart park provided in the second aspect, the storage medium provided in the third aspect, and the computer program product provided in the fourth aspect are all used to execute the method provided in this application. Therefore, the beneficial effects that can be achieved can be referenced to the beneficial effects of the corresponding methods and will not be repeated here.
[0024] One or more technical solutions provided in this application have at least the following technical effects or advantages: 1. By employing the above technical solution, static device attributes are collected and dynamic behavior is monitored. Risks are assessed and classified from multiple dimensions, and access rights rules are set accordingly. Real-time monitoring of traffic patterns promptly identifies abnormal devices. After re-rating, communication is blocked for high-risk abnormal devices. This effectively implements dynamic, hierarchical security management and control of IoT devices in smart campuses. Risk levels are adjusted in real time based on the device's static attributes and dynamic behavior during operation, allowing for rapid response to abnormal device behavior, ensuring the overall security of the smart campus.
[0025] 2. By adopting the above technical solution, the device risk score is recalculated after abnormal traffic patterns are discovered, and high-risk abnormal devices are isolated using independent virtual LANs to block their external network access rights. This can quickly cut off potential attack paths, prevent the spread of malicious behavior, and provide a timely and effective security protection barrier for campus IoT devices.
[0026] 3. By employing the above technical solution, we can analyze the communication traffic mirroring of high-risk, abnormal devices, accurately locate security risks, and implement targeted remediation. After remediation, we reassess the risk level and dynamically adjust the device status. This not only eliminates device security vulnerabilities but also restores normal operation, improving the security and operational efficiency of campus IoT devices. BRIEF DESCRIPTION OF THE DRAWINGS
[0027] The accompanying drawings are incorporated into and constitute a part of the specification, illustrating embodiments consistent with the present application and, together with the specification, explaining the principles of the present application. Obviously, the drawings described below are only some embodiments of the present application, and those skilled in the art can derive other drawings based on these drawings without inventive effort. In the drawings: Figure 1 This is a flow chart of a hierarchical security management method for IoT devices in a smart park according to an embodiment of the present application; Figure 2 This is another flow chart of a hierarchical security management method for IoT devices in a smart park according to an embodiment of the present application; Figure 3 This is a schematic diagram of the physical device structure of the hierarchical security management and control system of the Internet of Things equipment in the smart park in the embodiment of the present application. DETAILED DESCRIPTION
[0028] The terms used in the following examples of the present application are only for the purpose of describing specific embodiments and are not intended to limit the present application. As used in the specification of the present application, the singular expressions "a", "an", "above", "the", and "this" are intended to include plural expressions as well, unless the context clearly indicates otherwise. It should also be understood that the term "and / or" used in the present application refers to any or all possible combinations of one or more of the listed items.
[0029] In the following, the terms "first" and "second" are used for descriptive purposes only and should not be construed as implying relative importance or implicitly indicating the number of the technical features indicated. Therefore, features defined as "first" or "second" may explicitly or implicitly include one or more of such features. In the description of the embodiments of this application, unless otherwise specified, "plurality" means two or more.
[0030] It should also be noted that, unless otherwise clearly specified and limited, in the embodiments of the present application, terms such as "setting" and "connection" should be understood in a broad sense. For example, "connection" can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be a direct connection or an indirect connection through an intermediate medium, or it can be the internal connection of two components; it can be a wired communication connection or a wireless communication connection. For ordinary technicians in this field, the specific meanings of the above terms in this application can be understood according to the specific circumstances. The embodiments of the present application are described in detail below.
[0031] With the rapid development of smart campus construction, the application of Internet of Things (IoT) devices is becoming increasingly widespread. From environmental monitoring and smart buildings to security surveillance and industrial automation, they are now ubiquitous. However, the integration of massive numbers of IoT devices also presents unprecedented security challenges. These devices are diverse in type and function, often deployed in complex network environments, making them vulnerable to cyberattacks and posing a potential threat to the stable operation and data security of the campus.
[0032] Currently, security management methods for IoT devices still have some shortcomings in practice. Many related technical solutions focus on static, one-time risk assessments and access control based on universal policies. After setting a security baseline during the initial device deployment, these methods often struggle to adapt to dynamic changes in IoT device behavior, such as behavioral drift caused by firmware updates, functional adjustments, or unknown attacks. Furthermore, they may lack detailed consideration of the device's specific production functions, the importance of the data it processes, and actual network interaction patterns. This leads to inaccurate risk assessments and a "one-size-fits-all" access control policy, which can be either too lax, leaving security risks, or too strict, impacting normal business operations. When device behavior exhibits anomalies, traditional response mechanisms often rely on preset rules or manual intervention, with limited response speed and accuracy. This makes it difficult to quickly and accurately identify and isolate true high-risk threats, easily leading to the spread of security incidents.
[0033] To address the aforementioned technical issues and effectively improve the security and controllability of IoT devices in smart parks, embodiments of the present application provide a hierarchical security management and control method for IoT devices in smart parks. This method abandons the traditional static, isolated security perspective and instead constructs a dynamic, closed-loop management and control system. By combining comprehensive collection of static device attributes (such as production functions and data classification levels) with real-time monitoring of their dynamic behaviors (such as communication frequency and traffic patterns), it achieves dynamic and accurate risk assessment and classification of IoT device risks. Based on these assessment results, the system can set differentiated access rights rules for refined management and control. More importantly, upon detecting abnormal device communication data transmission exceeding preset access rights rules, this method can immediately reassess the risk of the abnormal device, comprehensively considering multiple dimensions of information, including abnormal characteristics and potential hazards. Based on the updated risk level (especially when determined to be high risk), decisive measures, such as communication blocking, can be quickly implemented.
[0034] like Figure 1 The figure shows a flow chart of a hierarchical security management method for IoT devices in a smart park according to an embodiment of the present application.
[0035] The following combination Figure 1The present embodiment specifically describes a hierarchical security management method for IoT devices in a smart park, which can be applied to a hierarchical security management system for IoT devices in a smart park (hereinafter referred to as the system). The method includes the following steps: 101. Collect static attributes of each IoT device, including production function, data confidentiality level, and external network accessibility. The data confidentiality level refers to the importance of the data processed by the IoT device, and the external network accessibility refers to whether the IoT device has a communication path and access rights to directly access the external network. When the system initiates the static attribute collection process, it first establishes an initial connection with the IoT device through the device registration interface or automatic scanning technology. For registered devices, the system retrieves basic information from the device archive; for unregistered devices, the system uses a combination of active detection and passive monitoring to identify and collect information. To obtain production function information, the system must read the device's configuration file, service description document, or interact with the device administrator. For example, in a smart factory, the production function of a CNC machine tool is precision machining, and its production function information may include detailed parameters such as machining accuracy requirements and production task types. Meanwhile, the production function of workshop environmental monitoring equipment is to collect real-time environmental data such as temperature, humidity, and hazardous gas concentrations. This information not only helps clarify the device's role in the production process but also provides business context for subsequent risk assessments. Determining data classification requires a system that combines data classification and grading standards with the actual data processing capabilities of the device. The system analyzes the content, purpose, and potential impact of the data processed by the device, categorizing the data classification as public, internal, confidential, and top secret. The system then associates this classification information with the device, serving as a key basis for risk assessment. To check external network accessibility, the system simulates a network connection request to test whether the device has the communication path and access rights to directly access the external network. The system checks the device's network configuration parameters, such as gateway address, routing rules, and firewall policies, to determine whether the device is allowed to connect to the external network. For devices deployed in industrial control networks, the system strictly verifies their network isolation measures. If an industrial control device is found to violate security policies and directly connect to an external network, even if the data is not classified highly, it will increase the potential risk. During the collection process, the system establishes a comprehensive logging mechanism to record the time, object, results, and any problems encountered during each collection operation. The system standardizes the format and performs integrity checks on collected static attribute data to ensure data accuracy and usability. Furthermore, the system regularly updates static attributes. When a device's production function changes, the data processing scope expands, or the network configuration is adjusted, relevant attribute information is promptly updated to ensure the timeliness of risk assessments.
[0036] 102. Monitor the dynamic behavior of each IoT device, including communication frequency and traffic pattern. Communication frequency refers to the number of times a device sends or receives data per unit time. Traffic pattern refers to traffic characteristics of network communications performed by the IoT device. Traffic characteristics include traffic scale, traffic direction, traffic distribution, protocol type, and connection mode. The system monitors the dynamic behavior of IoT devices in real time and continuously. To effectively monitor communication frequencies and traffic patterns, the system deploys traffic monitoring probes at key network nodes and installs lightweight monitoring agents on devices, creating a comprehensive monitoring network. To monitor communication frequency, the system sets a time window and counts the number of times a device sends or receives data within a specific timeframe. The normal range of communication frequency varies for different types of devices. For example, a smart meter might send electricity usage data to a data center every 15 minutes, with a relatively stable communication frequency. However, when a video surveillance camera transmits real-time video streaming, the communication frequency increases significantly, and the data transmission is continuous.
[0037] Traffic pattern monitoring covers multiple dimensions, including traffic volume, direction, distribution, protocol type, and connection mode. The system uses deep packet inspection (DPI) and traffic mirroring to parse and analyze device network traffic. Regarding traffic volume, the system records device traffic volume over different time periods and plots traffic curves. If a particular industrial sensor device experiences a sudden and significant increase in traffic, far exceeding normal business requirements, this may indicate a data injection attack or data theft. Monitoring traffic flow direction helps identify any unusual data outflows from devices. Normally, data from industrial production equipment flows from the device to the internal data center. If the system detects a large amount of data flowing from a device to an unknown external IP address, further investigation is necessary to determine if there is a risk of data leakage. Traffic distribution analysis focuses on how data is distributed across different time periods and applications. For example, discovering a device generating large amounts of traffic during non-business hours may indicate illegal use of the device. Monitoring protocol types and connection modes is equally important. The system identifies the network protocols used by devices, such as TCP, UDP, HTTP, and MQTT. If a device is found to be communicating using unauthorized protocols or connecting to unusual server ports, this could indicate a security risk. For example, if a device, intended to communicate only with an industrial protocol, establishes a connection to an external HTTP server, this could indicate malware has been implanted in the device. 103. Classify the IoT device into risk levels based on the static attributes and the dynamic behaviors to obtain a device level, where the device level includes high risk, medium risk, and low risk; When classifying risk levels, the system adopts a multi-dimensional weighted scoring method, assigning corresponding weights to various indicators of static properties and dynamic behaviors, and derives the risk score of the equipment through quantitative calculation, thereby determining the risk level. 104. Setting access permission rules based on the device level, wherein the access permission rules are used to limit the communication permission of the IoT device; After completing the device level classification, the system will formulate corresponding access permission rules based on the device level to ensure that the communication activities of IoT devices are carried out within a safe and controllable range.
[0038] For high-risk devices, the system implements the strictest access restrictions. These devices may only be allowed to communicate with specific secure servers, and communication protocols and ports are strictly limited. This minimizes the vulnerability of high-risk devices to external attacks and prevents them from becoming entry points for network security vulnerabilities.
[0039] Access permissions for medium-risk devices are somewhat more relaxed than those for high-risk devices, but they still remain subject to certain restrictions. The system will set more detailed access rules based on the device's specific purpose and business needs. Regarding communication protocols, in addition to commonly used security protocols, some business-specific protocols that have undergone security assessments may also be permitted. Regarding port usage, necessary business-related ports will be open, but ports that may pose security risks will be closed or have access restricted.
[0040] While low-risk devices pose a lower overall risk, the system will not completely relax its access control. Low-risk devices can typically communicate freely within a certain range, but are also subject to some basic security restrictions. For example, a standard smart socket in a smart home environment is considered a low-risk device. It can communicate normally with smart speakers, mobile apps, and other devices on the home network to achieve remote control. However, the system restricts its communication to within the home LAN and prohibits direct connection to the external internet, preventing hackers from remotely controlling the device over the internet and thus protecting the user's home network security.
[0041] When setting access rights rules, the system fully considers inter-device dependencies and business process continuity. For IoT devices that need to collaborate with other devices, the system ensures normal communication and data exchange while maintaining security. Furthermore, the system provides a flexible configuration interface, allowing administrators to fine-tune access rights rules based on actual circumstances to accommodate diverse application scenarios and security requirements.
[0042] To ensure effective enforcement of access rights rules, the system deploys access control devices, such as firewalls and intrusion detection systems, at key locations such as network boundaries and device access points. These devices monitor and filter IoT device communication requests in real time based on pre-defined access rights rules. Only traffic that complies with the rules is allowed through, thus strictly restricting device communication rights.
[0043] 105. Detecting whether there is an abnormal traffic pattern by real-time monitoring of the traffic pattern of the IoT device, wherein the abnormal traffic pattern refers to communication data transmission of the IoT device exceeding the access permission rule; The system continuously monitors the traffic patterns of IoT devices in real time through traffic monitoring probes deployed at key network nodes and lightweight monitoring agents installed on the device side to detect any abnormal traffic conditions.
[0044] During the monitoring process, the system first identifies the characteristics of normal traffic patterns. This includes the normal range of traffic volume, traffic direction, traffic distribution, protocol type, and connection mode of the device at different time periods.
[0045] The system compares and analyzes the real-time monitored device traffic patterns with pre-defined normal traffic patterns. If a device's communication data transmission exceeds access rights rules, it will be identified as an abnormal traffic pattern. For example, if the automated device is detected to generate a sudden surge in data traffic during off-hours, and this traffic is directed to an unknown external IP address, while access rights rules prohibit such high-volume communication activity during off-hours and prohibit communication with unknown external IP addresses, the system will identify this as an abnormal traffic pattern.
[0046] 106. If so, determine the IoT device in the abnormal traffic pattern as an abnormal device; When the system detects an abnormal traffic pattern in an IoT device, it immediately marks the device as an abnormal device and initiates a series of subsequent processing measures.
[0047] 107. Reclassify the risk level of the abnormal device to obtain a new device level; When the system identifies an IoT device as anomalous, it immediately initiates a new risk classification process to more accurately assess the device's current security threat level. This reclassification goes beyond the initial assessment's static attributes and dynamic behavior data. Instead, it incorporates multiple dimensions, including the specific characteristics of abnormal traffic patterns, the duration of abnormal behavior, and the potential scope of harm, to comprehensively and dynamically reassess the device's risk. The system first reviews and updates the static attributes of abnormal devices. For example, if a smart medical device is identified as abnormal due to a data leak, the system will reassess its data classification. The patient medical data processed by the device was originally classified as confidential, but because a data leak could potentially spread sensitive information, the system will upgrade the data classification to top secret. Furthermore, if abnormal behavior disrupts the device's production function or even leads to malicious tampering, the system will adjust its importance in the business process accordingly.
[0048] In terms of dynamic behavior analysis, the system will deeply analyze the security risks reflected by abnormal traffic patterns. For example, if the license plate recognition camera in the intelligent transportation system is detected to be transmitting a large amount of video data to an unknown IP address, the system will not only record the scale of this abnormal traffic but also analyze the attack intent hidden behind the traffic direction. If this abnormal traffic is found to be flowing to overseas servers, combined with the current network security situation, the system will consider the device to be a breakthrough point for data theft and will re-score its dynamic behavior indicators such as communication frequency and traffic distribution. In addition, the system will retrieve the device's operation logs for a period of time before and after the abnormal behavior occurs to check for other potential abnormal operations, such as illegal modification of device firmware or malicious replacement of communication protocols, and include these newly discovered abnormal behaviors in the risk assessment. During the risk reclassification process, the system also considers industry security standards and the latest cybersecurity threat intelligence. For example, when a new ransomware attack targeting IoT devices occurs, the system will raise the risk assessment level of abnormal devices with similar risk characteristics based on the virus's propagation characteristics and attack targets. If a smart home device is detected to have abnormal traffic patterns, and its communication characteristics are similar to the propagation patterns of known ransomware, the system will significantly increase the risk level of the device based on threat intelligence, even if the device is initially rated low risk.
[0049] Ultimately, the system will classify abnormal devices into new device levels, namely high risk, medium risk or low risk, based on the recalculated total risk score, providing a clear basis for subsequent safety disposal.
[0050] 108. If the new device level is high risk, the communication of the abnormal device is blocked to prevent the attack from spreading.
[0051] Once the system determines that an abnormal device has a new high-risk classification, it immediately triggers an emergency communication blocking mechanism to minimize the impact of the security incident and prevent the attack from spreading further within the IoT device network. This communication blocking operation is not a simple, crude severing of the device's network connection; rather, it is a refined operation implemented through multi-layered security policy verification and automated processes.
[0052] The aforementioned embodiment provides a hierarchical security management and control method for IoT devices in a smart campus, implementing a dynamic, closed-loop IoT device security management and risk control system. By collecting static attributes and monitoring dynamic behavior, comprehensive information is captured, providing a solid data foundation for risk assessment. Risk levels are categorized based on this data, and preliminary, differentiated proactive defense strategies are constructed accordingly. Continuous, real-time detection of abnormal traffic patterns ensures the immediate detection of anomalous devices whose behavior deviates from security policies. When an anomaly is detected, the system does not simply implement a fixed response, but instead conducts a precise risk reassessment of the anomalous device. If the reassessment confirms that a device poses a high risk, drastic measures such as communication blocking are implemented. This goes beyond single-point detection or defense, building a complete security closed loop. Its significant value lies in the efficient implementation of dynamic, hierarchical security management and control of IoT devices. The risk level of a device is adjusted in real time based on its static attributes and dynamic behavior during operation, and a rapid response is provided when a device exhibits abnormal behavior, preventing the spread of threats and ensuring the overall security of the smart campus.
[0053] In the above embodiments, the system sets access permission rules based on device level to restrict communication between IoT devices of different levels. In practical applications, in some embodiments, the system establishes secure communication channels through virtual local area networks to restrict and protect communication between IoT devices of different levels. Furthermore, in some embodiments, after blocking communication with an abnormal device, the system can analyze traffic mirroring data to repair the abnormal device.
[0054] The following combination Figure 2 The present invention provides a method for hierarchical security management of IoT devices in a smart park. Figure 2 This is another flow chart of a hierarchical security management method for IoT devices in a smart park according to an embodiment of the present application. The details are as follows: 201. Collect static attributes of each IoT device, including production function, data confidentiality level, and external network accessibility. The data confidentiality level refers to the importance of the data processed by the IoT device, and the external network accessibility refers to whether the IoT device has a communication path and access rights to directly access the external network. 202. Monitor the dynamic behavior of each of the IoT devices, including communication frequency and traffic pattern. Communication frequency refers to the number of times a device sends or receives data per unit time. Traffic pattern refers to traffic characteristics of the IoT device during network communication. Traffic characteristics include traffic scale, traffic direction, traffic distribution, protocol type, and connection mode. Steps 201 and 202 Figure 1 The descriptions of steps 101 and 102 in the illustrated embodiment are similar, and reference may be made to the descriptions in the relevant steps, which will not be repeated here.
[0055] 203. Calculate an initial risk score for the IoT device, where the initial risk score is weighted based on the production function, data confidentiality level, and external network accessibility in the static attributes; After collecting the static attributes of each IoT device, the system begins calculating its initial risk score. By quantifying and weighting three key static attributes—production function, data classification, and external network accessibility—it provides a preliminary measure of the device's potential risk.
[0056] When evaluating production functions, the system assigns weights and scores based on the equipment's importance and irreplaceability in the business process. In a smart factory scenario, automated processing equipment on a core production line is crucial to the overall factory's operations. A failure or attack could cause the entire line to shut down, resulting in significant economic losses. Therefore, the production function weight for this type of equipment is relatively high, such as 0.4. The system then categorizes the equipment's production functions into different levels based on its specific functions and tasks, and assigns a corresponding score. For example, if the highest level of production function is scored at 10, the automated processing equipment's production function score would be 10 x 0.4 = 4. For auxiliary equipment, such as lighting control equipment in the workshop, whose production functions are less important, the weight might be 0.1, resulting in a score of 3. The score for this item would be 3 x 0.1 = 0.3.
[0057] Assessing data confidentiality is also a crucial component of the initial risk score. The system determines the confidentiality of a device based on the sensitivity and importance of the data it processes, assigning a corresponding weight and score. In IoT applications in the financial industry, devices that process customer transaction data and identity information have a top confidentiality rating, and a weight of 0.3 can be set. Top confidential data is scored out of 10, so the device's score for data confidentiality is 10 x 0.3 = 3. On the other hand, devices that process public data, such as those at weather monitoring stations, have a public data confidentiality rating and a weight of 0.1, resulting in a score of 1. The score for this rating is 1 x 0.1 = 0.1.
[0058] External network accessibility is also crucial. The system scores and weights devices based on whether they have direct communication paths and access rights to external networks. Direct access significantly increases the risk of attack, so the weighting is higher, such as 0.2. For devices with direct access, the score is 8 points, so the score is 8 x 0.2 = 1.6. For devices that undergo strict network isolation and lack direct access, the score is 2 points, with a weight of 0.2, resulting in a score of 2 x 0.2 = 0.4.
[0059] The system adds the scores of these three static attributes to derive an IoT device's initial risk score. For example, if a device's production function score is 3, its data confidentiality score is 2, and its external network accessibility score is 1, its initial risk score would be 6. This allows the system to quantitatively assess the initial risk profile of each IoT device, providing foundational data for subsequent dynamic adjustments and risk grading.
[0060] 204. Dynamically adjust the initial risk score based on the communication frequency and traffic pattern of the dynamic behavior monitoring to obtain an adjusted risk score; When the communication frequency exceeds a preset frequency threshold, determining the first risk score, the first risk score being greater than the initial risk score; When an abnormality in traffic direction or protocol type is detected in the traffic pattern, determining the second risk score, the second risk score being greater than the first risk score; When it is detected in the traffic pattern that the traffic scale or traffic distribution is stable and conforms to a normal pattern, the third risk score is determined, and the third risk score is less than the second risk score.
[0061] After obtaining the initial risk score of the IoT device, the system will dynamically adjust the initial risk score based on the monitoring results of the device's dynamic behavior to more accurately reflect the risk status of the device during actual operation.
[0062] Communication frequency is a key factor in dynamically adjusting risk scores. The system pre-sets a frequency threshold based on the device's normal business needs and historical communication data. If a device's communication frequency exceeds the threshold, it indicates possible abnormal activity, such as an attack, malicious control, or malfunction. The system will then raise the device's risk score. For example, in a smart home system, a smart door lock normally communicates with a mobile app 10-20 times per day. If the system sets a frequency threshold of 30 times and detects that the smart door lock communicates with the mobile app 50 times on a given day, exceeding the threshold, the system will raise the device's risk score from the initial 3 to the initial risk score of 5. This is because an abnormally high communication frequency may indicate an attempt to open the door lock through unauthorized means, posing a security risk.
[0063] Monitoring traffic patterns is also a key step in dynamically adjusting risk scores. Traffic patterns encompass multiple characteristics, including traffic direction, protocol type, traffic volume, and traffic distribution. If the system detects anomalies in the traffic direction or protocol type, it will further increase the device's risk score. For example, in an enterprise's IoT network, a sensor device normally communicates only with the company's internal data center, with a fixed traffic direction. If the system detects that the device suddenly sends a large amount of data to an unknown external IP address, indicating an abnormal traffic direction, or uses an unauthorized protocol for communication—for example, using TCP instead of HTTP to connect to an external server—the system will increase the device's risk score from a primary risk score of 5 to a secondary risk score of 7. This is because abnormal traffic directions and protocol types may indicate a device has been compromised or infected with malware, posing a greater security risk to the enterprise network.
[0064] Conversely, when the system detects that the traffic scale or distribution within a traffic pattern is stable and conforms to a normal pattern, it indicates that the device's communication activity is normal, and the system will appropriately lower the device's risk score. For example, when an industrial surveillance camera is operating normally, its traffic scale and distribution are relatively stable. Through long-term monitoring, the system establishes a normal traffic model for this device. If, within a certain period of time, the system detects that the camera's traffic scale and distribution conform to this normal model, with no abnormal fluctuations, the system will lower the device's risk score from the second risk score of 7 to the third risk score of 6.
[0065] 205. According to a preset risk score threshold, the adjusted risk score is judged to obtain a device level, where the device level is divided into high risk, medium risk, and low risk levels.
[0066] After obtaining the adjusted risk score, the system will classify the risk level of each IoT device based on the preset risk score threshold, and divide the devices into three levels: high risk, medium risk and low risk, so that different security management measures can be taken.
[0067] The system pre-sets three risk score thresholds based on industry standards, historical security data, and actual business needs, corresponding to the high, medium, and low risk thresholds. For example, let's assume the system sets the high-risk threshold at 8 and the medium-risk threshold at 5. A device is considered high-risk if its adjusted risk score is 8 or greater; medium-risk if it's 5 or greater but less than 8; and low-risk if it's less than 5.
[0068] 206. Establishing a virtual local area network, wherein the virtual local area network isolates the communication of the IoT device; When setting up a virtual local area network (VLAN), the system first develops a detailed VLAN division strategy based on the enterprise or organization's network architecture, business needs, and IoT device deployment. This process involves comprehensive consideration of the functions, security levels, and communication requirements of different device types to ensure effective and appropriate communication isolation. Through the network management platform, the system configures network switches, routers, and other devices to create multiple logically independent virtual local area networks (VLANs). For example, in a large smart factory, the system assigns IoT devices responsible for core production control, such as automated production line controllers and precision machining equipment, to a dedicated production control VLAN. Environmental monitoring devices, such as temperature and humidity sensors and hazardous gas detectors, are assigned to the environmental monitoring VLAN. IoT devices in office areas, such as smart printers and conference room terminals, are assigned to the office VLAN. This division isolates devices with different functions from each other at the network level, preventing devices within one VLAN from being affected by potential security threats in other VLANs. To further enhance communication isolation, the system sets strict access control policies between VLANs. By configuring firewall rules and access control lists (ACLs), illegal communication between different VLANs is restricted.
[0069] In addition, the system regularly checks and optimizes VLAN division and configuration. As IoT devices increase, business needs change, or security policies adjust, the system promptly adjusts VLAN division to ensure that communication isolation consistently meets security requirements. Furthermore, the system records VLAN configuration information and communication logs for tracing and analysis when security issues arise. By establishing a virtual local area network, the system establishes a first line of defense for communication isolation for IoT devices, effectively reducing the spread of security risks between devices.
[0070] 207. Generate an encryption key based on the unique identifier of the IoT device; When generating encryption keys, the system uses the unique identifier (UID) of the IoT device as the core basis, combined with complex encryption algorithms and security mechanisms to ensure that the generated keys are highly unique, secure, and unbreakable.
[0071] 208. Establishing a secure communication channel through the virtual local area network according to the encryption key, wherein the secure communication channel is an end-to-end encrypted channel; Allocate the secure communication channel of the high-risk device to an independent virtual local area network, wherein the independent virtual local area network is used to isolate and protect the high-risk device; Allocating the secure communication channel of the medium-risk device to a shared virtual local area network, wherein the shared virtual local area network restricts direct communication with the high-risk device; When establishing a secure communication channel, the system will make full use of the isolation characteristics of the virtual LAN and the security of the encryption key to build an end-to-end encrypted communication link and make differentiated allocations based on the risk level of the device. The system establishes a secure communication channel between IoT devices. When devices need to communicate, the system encrypts the data using a pre-generated encryption key over a virtual local area network (VLAN) network path. This ensures that even if the data is intercepted during transmission, it cannot be illegally read. For high-risk devices, the system allocates secure communication channels to independent virtual local area networks (VLANs). This dedicated VLAN is completely isolated from other networks, allowing only specific security servers and management terminals to connect through strict access control policies. Furthermore, secure communication channels for high-risk devices utilize strong encryption algorithms and strict identity authentication mechanisms to ensure that only authorized devices and users can communicate.
[0072] For medium-risk devices, the system assigns secure communication channels to a shared VLAN, but strictly restricts direct communication with high-risk devices. These devices are grouped into a shared VLAN, allowing necessary communication between them. At the same time, strict access control policies are set between the shared VLAN and the separate VLANs containing high-risk devices, prohibiting medium-risk devices from establishing direct communication with high-risk devices.
[0073] For low-risk devices, the system will also assign their secure communication channels to the shared virtual LAN, but only allow communication data to be sent to external servers. This prevents low-risk devices from being used as a springboard for cyberattacks against IoT devices within the LAN, reducing the threat of cyberattacks.
[0074] 209. Perform communication authority verification on the secure communication channel to prevent unauthorized devices from passing through the secure communication channel; When the system performs communication permission verification on the secure communication channel, it builds a multi-level and multi-dimensional verification system to ensure that only authorized devices can transmit data through the secure communication channel, thereby effectively preventing access and attacks by illegal devices.
[0075] The system uses a digital certificate-based authentication mechanism as the foundation for authorization verification. Before a device accesses a secure communication channel, the system issues a unique digital certificate to each authorized device. This certificate contains key information such as the device's public key, unique identifier, validity period, and the issuing authority's digital signature. When a device initiates a communication request, it sends the digital certificate to the other device or server.
[0076] The system also incorporates permission management strategies based on access control lists (ACLs). The system sets detailed access control rules for each device based on its risk level, production function, and business needs. For high-risk devices, such as servers processing core business data, ACL rules are extremely strict, allowing only specific authorized devices to communicate, with clear restrictions on communication ports, protocol types, and more. For medium-risk devices, ACL rules are more relaxed, but still restrict direct communication with high-risk devices and illegal network access.
[0077] 210. Detecting whether there is an abnormal traffic pattern by real-time monitoring of the traffic pattern of the IoT device, wherein the abnormal traffic pattern refers to communication data transmission of the IoT device exceeding the access permission rule; 211. If so, determine the IoT device in the abnormal traffic pattern as an abnormal device; Steps 210, 211 and Figure 1The descriptions of steps 105 and 106 in the illustrated embodiment are similar, and reference may be made to the descriptions in the relevant steps, which will not be repeated here.
[0078] 212. After detecting an abnormal traffic pattern, recalculate the risk score of the abnormal device; When the system detects an abnormal traffic pattern on an IoT device, it immediately initiates a recalculation of the risk score for that device. This process is designed to more accurately assess the device's current risk profile so that appropriate security measures can be taken.
[0079] The system first collects detailed information about unusual traffic patterns. This includes the scale, direction, frequency, protocol type, and data content of the unusual traffic. For example, in a smart city's energy management system, if a smart meter exhibits an unusual traffic pattern, the system will record the meter sending large amounts of data to an unknown IP address during the unusual period, including the frequency of data transmission, the amount of data sent each time, and the protocol used. This information will serve as a key basis for recalculating the risk score.
[0080] The system considers the impact of multiple factors on the risk score. The larger the scale of abnormal traffic, the greater the risk score increase. If the abnormal traffic is directed to an untrusted external network or uses unauthorized protocols for communication, the risk score will also increase significantly. The system also considers factors such as the device's initial risk score and historical abnormality records.
[0081] Based on the analysis results, the system recalculates the risk score of the abnormal device to obtain a new risk score. This new risk score more accurately reflects the current security threat level faced by the device.
[0082] 213. Determine whether the risk score exceeds a high risk threshold; After the system recalculates the risk score of an abnormal device, it will immediately compare the score with the preset high-risk threshold to determine whether the risk level of the device has changed.
[0083] 214. If the risk score exceeds a high risk threshold, adjust the device level of the abnormal device to obtain a new device level of high risk; When the system determines that the risk score of an abnormal device exceeds the high-risk threshold, it will immediately adjust the device's level to high risk. This adjustment means that the device will be subject to stricter security control and monitoring.
[0084] The system also coordinates adjustments to other systems and devices associated with the abnormal device. If the device has a business connection with other devices, the system will notify the related devices to adjust their communication strategies with the abnormal device, such as reducing the frequency of data exchange and limiting the types of data transmitted, to reduce security risks. For example, in a smart factory, if a high-risk production device is connected to other auxiliary equipment, the system will notify the auxiliary equipment to reduce communication with the high-risk device and only conduct necessary emergency data exchange.
[0085] After adjusting the device level, the system will strengthen security monitoring and control of the device. It will increase the frequency of device traffic monitoring and monitor the device's operating status and communication behavior in real time to ensure that the device does not pose a greater security threat to the entire IoT system.
[0086] 215. If the new device is rated as high risk, isolate the abnormal device through an independent virtual local area network to block its external network access rights; When the system adjusts the level of an abnormal device to high risk, it will immediately isolate the device through an independent virtual LAN to block its external network access and prevent the further spread of security threats.
[0087] The system creates a separate virtual local area network (VLAN) for high-risk abnormal devices in the network architecture. This VLAN is completely isolated from the network where other normal devices are located, forming a secure island.
[0088] The system then migrates the network connections of high-risk, abnormal devices to this independent virtual local area network (VLAN). By modifying the device's network configuration parameters, such as the IP address, subnet mask, and gateway, the device's communication path is directed to the independent VLAN. Simultaneously, the system configures appropriate rules on network boundary devices (such as firewalls) to prohibit communication between the VLAN and external networks, ensuring that the device cannot access external networks.
[0089] During the isolation process, the system comprehensively monitors and records device communications. By deploying traffic monitoring devices at key nodes in the virtual local area network, the system can monitor device communication traffic in real time, including traffic volume, direction, and protocol type. If a device still exhibits abnormal communication behavior after isolation, the system will further analyze the cause and take appropriate measures, such as strengthening firewall rules and conducting in-depth security testing on the device.
[0090] The system provides security managers with detailed isolation information, including the time the device was isolated, the virtual local area network (VLAN) it resides in, and the device's communication history during the isolation period. Based on this information, security managers can conduct further security assessments and take appropriate action on the device.
[0091] 216. Copy the real-time communication traffic of the high-risk abnormal device to obtain traffic mirror data; After isolating a high-risk, abnormal device, the system immediately initiates a traffic mirroring data collection program, using network traffic mirroring technology to capture the device's real-time communication traffic data. This technology, based on the principle of port mirroring, configures a mirrored port on the network switch port or aggregation node connected to the high-risk device. This copies all traffic data sent and received by the device and transmits it to the security analysis platform, ensuring that the original communication is not disturbed while preserving the complete data sample.
[0092] The system generates a unique hash value for each piece of traffic mirror data for data integrity verification. When the security analysis platform retrieves data, it recalculates the hash value and compares it with the original record. If there is a mismatch, the data is deemed tampered with and immediately triggers data recollection, ensuring the accuracy and credibility of subsequent analysis.
[0093] 217. Perform security analysis on the traffic mirror data to determine whether the abnormal device has unupdated firmware, known vulnerabilities, or abnormal configurations, wherein the security analysis includes detecting firmware versions, open ports, system logs, and security configuration status to identify potential vulnerabilities or unpatched weaknesses. After acquiring traffic mirror data, the system initiates a multi-dimensional security analysis process, combining automated tools with machine learning algorithms to deeply identify potential security vulnerabilities in the device. The analysis begins with firmware version detection. Using protocol fingerprinting technology, the system searches the traffic data for packets indicating firmware version interactions between the device and the server. Throughout the analysis process, the system integrates all test results into a risk analysis report, presented in the form of visual charts and detailed lists. The report not only identifies specific risk items and vulnerability descriptions, but also links relevant security incident cases and remediation recommendations, providing a clear basis for subsequent decision-making.
[0094] 218. If it is detected that the abnormal device has unupdated firmware or known vulnerabilities, install the latest security patch or firmware update; When the system identifies a device with unupdated firmware or known vulnerabilities through security analysis, it initiates an automated remediation process that strictly adheres to safety protocols to ensure that no new security issues are introduced during the repair process. The system first creates a snapshot backup of the device's current operating state. Using virtualization technology or the device's own backup capabilities, the system saves configuration parameters, service data, and firmware images, enabling a quick rollback in the event of an update failure. Before installing security patches or firmware updates, the system conducts rigorous security verification of the update package. By comparing the update package's digital signature with the officially released public key, the system verifies that the update has not been tampered with. Furthermore, the system performs pre-installation testing of the update package in an isolated environment, simulating device operating scenarios to detect compatibility issues or service interruptions. For example, for intelligent traffic light controllers, the system tests new firmware in a simulated traffic flow environment to ensure that the signal switching logic is not affected. The update process uses a phased push strategy. For small devices, such as smart sensors, the system directly pushes the complete firmware package. For complex devices, such as industrial servers, the system uses a differential update method, transmitting only the code that differs from the previous version, reducing transmission volume and update time. During the update process, the system monitors the device status in real time and uses a heartbeat detection mechanism to confirm whether the device is responding normally. If the device becomes unresponsive or restarts abnormally during the update, the system immediately triggers a rollback mechanism to restore the device to its pre-update state and report the abnormality to security operations personnel. After the update is complete, the system will perform a second verification on the device, rechecking the device's firmware version and vulnerability fix status to ensure the update was successful and the vulnerability has been effectively fixed.
[0095] 219. If it is detected that the abnormal device has an abnormal configuration, reset the access permission rules of the abnormal device; When the system detects an abnormal device configuration, it first assesses the scope of the abnormal configuration's impact. By analyzing traffic data and device logs, it identifies the business modules, communication targets, and potential security risk levels involved. For example, if a cargo sorting robot in an intelligent warehouse management system has an access rights anomaly that allows remote control from unauthorized external IP addresses, the system will assess the risks this anomaly could lead to, such as cargo sorting errors and data leaks. Before resetting access rights, the system backs up the device's current configuration file, preserving the original abnormal configuration information to facilitate subsequent tracing and analysis. The system then generates a default access rights rule template based on the device's initial design documentation, business requirements, and security policies. For example, for industrial IoT devices, the default rules restrict device communication to authorized servers within the same production subnet, prohibit direct access from external networks, and employ a whitelist mechanism to manage communication ports. The system employs a gradual reset strategy to prevent sudden configuration changes from impacting normal operations. First, the system disables abnormal configuration items that clearly pose a risk, such as immediately disabling unauthorized external access ports. Then, it gradually adjusts other configuration parameters, such as resetting access control lists and updating authentication keys. During this adjustment process, the system monitors the device's operational status in real time and simulates business traffic to verify the proper functioning of communication after the configuration adjustments. For example, when resetting access rights rules for a smart access control system, the system simulates scenarios such as employee card swiping and visitor reservations to verify the correctness of the access control logic. After the reset is complete, the system will enforce the new access rights. Multi-factor authentication mechanisms will be added, such as requiring devices to use dynamic tokens or biometrics for authentication in addition to usernames and passwords. Real-time access monitoring will be enabled, analyzing the device's behavior for every communication request. If any unusual access patterns are detected, an alert will be triggered and the connection will be blocked. Furthermore, the system will align the new access rights with the device's risk level, imposing stricter rules for high-risk devices, such as limiting their communication frequency and data transmission volume.
[0096] 220. After the repair is completed, re-evaluate the risk level of the abnormal device and update the new device level; After an abnormal device completes a firmware update, vulnerability fix, or configuration reset, the system initiates a new risk assessment process. This process is more rigorous than the initial assessment and fully verifies the device's security status. The system recollects the device's static attribute information, checks whether production functions have changed due to the repair operation, updates the data classification assessment (if the data leakage risk is reduced), and reconfirms that the external network accessibility configuration meets security standards.
[0097] During the scoring process, the system incorporates a remediation effectiveness evaluation factor. Successfully remediated vulnerabilities or configuration issues will receive bonus points based on their severity; incomplete remediation or the emergence of new potential risks will result in point deductions. The system determines the device's new level based on the recalculated risk score and pre-set risk thresholds. The entire assessment process generates a detailed report, including changes in various indicators, the rationale for the risk score adjustment, and a comparative analysis with the initial assessment. This report is not only used to update the device's level but also provided to security management personnel for subsequent security policy optimization.
[0098] 221. If the new device level is reduced to medium risk or low risk, the isolation is lifted and the communication permission is restored.
[0099] Once the system determines that the abnormal device's new risk level has been reduced to medium or low risk, it initiates the process of lifting isolation and restoring communication permissions. This process must strictly adhere to security verification and permission restoration policies to prevent the device from becoming a security risk again. The system performs a final security verification on the device, using vulnerability scanning tools to conduct a deep scan to ensure that there are no known unpatched vulnerabilities. At the same time, the device's configuration parameters are reviewed to confirm that access permission rules and security feature settings meet security standards. For example, before lifting isolation, the system checks whether the firewall rules of smart office devices are correctly configured and whether data encryption functions are enabled properly.
[0100] Once permissions are restored, the system will reintegrate the device into the normal security management system and adjust monitoring frequency and protection strategies based on the new risk level. For example, low-risk devices will be monitored hourly instead of real-time during isolation. Medium-risk devices will maintain a higher frequency of monitoring and undergo regular security assessments. The system will also record the entire process from device anomaly to recovery, creating a valuable reference for subsequent handling of similar issues.
[0101] The above-mentioned embodiment provides a hierarchical security management method for IoT devices in a smart park, which systematically establishes a complete IoT device security management system. From accurate device risk assessment and hierarchical protection to the timely detection and closed-loop disposal of abnormal devices, dynamic hierarchical security management of IoT devices is achieved. This significantly reduces security risks such as device attacks and data leaks, ensuring the safe, stable, and reliable operation of the IoT system and effectively preventing business interruptions, financial losses, and privacy leaks caused by device security issues.
[0102] The method provided in the above embodiment can be executed by the hierarchical security management and control system of the Internet of Things equipment in the smart park, which is composed of electronic devices. The following describes the electronic device in the embodiment of the present application from the perspective of hardware processing. Figure 3 , which is a schematic diagram of the physical device structure of the hierarchical security management and control system of the Internet of Things equipment in the smart park in the embodiment of this application.
[0103] It should be noted that Figure 3 The structure of the hierarchical security management and control system for IoT devices in a smart park shown is only an example and should not bring any limitations to the functions and scope of use of the embodiments of this application.
[0104] like Figure 3As shown, the electronic device includes a central processing unit (CPU) 401, which can perform various appropriate actions and processes, such as the methods described in the above embodiments, based on programs stored in a read-only memory (ROM) 402 or programs loaded from a storage unit 408 into a random access memory (RAM) 403. RAM 403 also stores various programs and data required for system operation. CPU 401, ROM 402, and RAM 403 are interconnected via a bus 404. An input / output (I / O) interface 405 is also connected to bus 404.
[0105] The following components are connected to the input / output (I / O) interface 405: an input section 406 including an audio input device, push button switches, and the like; an output section 407 including a display, an audio output device, indicator lights, and the like; a storage section 408 including a hard disk and the like; and a communication section 409 including a network interface card such as a LAN (Local Area Network) card or a modem. The communication section 409 performs communication processing via a network such as the Internet. A drive 410 is also connected to the input / output (I / O) interface 405 as needed. Removable media 411, such as a magnetic disk, an optical disk, a magneto-optical disk, or a semiconductor memory, is installed in the drive 410 as needed, so that computer programs read from the media can be installed in the storage section 408 as needed.
[0106] In particular, according to an embodiment of the present application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, an embodiment of the present application includes a computer program product comprising a computer program carried on a computer-readable medium, the computer program including a computer program for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network via the communication section 409 and / or installed from a removable medium 411. When the computer program is executed by the central processing unit (CPU) 401, the various functions defined in the present application are performed.
[0107] It should be noted that specific examples of computer-readable storage media may include, but are not limited to, an electrical connection having one or more conductors, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), flash memory, optical fiber, portable compact disc read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this application, a computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.
[0108] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present application. Each box in the flowchart or block diagram can represent a module, program segment, or part of the code, and the above-mentioned module, program segment, or part of the code contains one or more executable instructions for implementing the specified logical functions. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in an order different from that marked in the accompanying drawings.
[0109] Specifically, the electronic device of this embodiment includes a processor and a memory, the memory is coupled to one or more processors, the memory is used to store computer program code, the computer program code includes computer instructions, and one or more processors call the computer instructions to enable the electronic device to execute the method provided by the above embodiment.
[0110] As another aspect, the present application further provides a computer-readable storage medium, which may be included in the electronic device described in the above embodiments, or may exist independently and not be incorporated into the electronic device. The above storage medium carries one or more computer programs, and when the one or more computer programs are executed by a processor of the electronic device, the electronic device implements the method provided in the above embodiments.
[0111] As described above, the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the above embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the above embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present application.
[0112] As used in the above embodiments, the term “when” may be interpreted to mean “if” or “after” or “in response to determining that” or “in response to detecting that”, depending on the context. Similarly, the phrases “upon determining that” or “if (stated condition or event) is detected” may be interpreted to mean “if determining that” or “in response to determining that” or “upon detecting (stated condition or event)” or “in response to detecting (stated condition or event)”, depending on the context.
[0113] Those skilled in the art will appreciate that all or part of the process steps in the above-described method embodiments can be implemented by a computer program instructing the relevant hardware. The program can be stored in a computer-readable storage medium, and when executed, the program can include the process steps in the above-described method embodiments. The aforementioned storage medium includes various media capable of storing program code, such as ROM or random access memory (RAM), magnetic disks, or optical disks.
Claims
1. A hierarchical security management and control method for IoT devices in a smart park, characterized in that: include: Collect static attributes of each IoT device, including production function, data confidentiality level, and external network accessibility. Data confidentiality level refers to the importance of the data processed by the IoT device, and external network accessibility refers to whether the IoT device has a communication path and access rights to directly access the external network. Monitoring the dynamic behavior of each IoT device, including communication frequency and traffic pattern. Communication frequency refers to the number of times a device sends or receives data per unit time. Traffic pattern refers to traffic characteristics of network communications performed by the IoT device. Traffic characteristics include traffic scale, traffic direction, traffic distribution, protocol type, and connection mode. Classifying the IoT device into risk levels based on the static attributes and the dynamic behaviors to obtain a device level, wherein the device level includes high risk, medium risk, and low risk; Setting access permission rules based on the device level, wherein the access permission rules are used to limit the communication permissions of the IoT device; detecting whether there is an abnormal traffic pattern by monitoring the traffic pattern of the IoT device in real time, wherein the abnormal traffic pattern refers to the communication data transmission of the IoT device exceeding the access permission rule; If so, determining the IoT device in the abnormal traffic pattern as an abnormal device; Reclassify the risk level of the abnormal device to obtain a new device level; If the new device level is high risk, the communication of the abnormal device will be blocked to prevent the attack from spreading.
2. The method according to claim 1, characterized in that The risk level classification of the IoT device according to the static attributes and the dynamic behavior to obtain the device level specifically includes: Calculating an initial risk score for the IoT device, wherein the initial risk score is assigned a weighted score according to the production function, data classification level, and external network accessibility in the static attributes; Dynamically adjusting the initial risk score based on the communication frequency and traffic pattern of the dynamic behavior monitoring to obtain an adjusted risk score; The adjusted risk score is judged according to a preset risk score threshold to obtain a device level, which is divided into high risk, medium risk and low risk levels.
3. The method according to claim 2, characterized in that The adjusted risk score includes the first risk score, the second risk score, or the third risk score, specifically including: Dynamically adjusting the initial risk score based on the communication frequency and traffic pattern of the dynamic behavior monitoring to obtain an adjusted risk score; When the communication frequency exceeds a preset frequency threshold, determining the first risk score, the first risk score being greater than the initial risk score; When an abnormality in traffic direction or protocol type is detected in the traffic pattern, determining the second risk score, the second risk score being greater than the first risk score; When it is detected in the traffic pattern that the traffic scale or traffic distribution is stable and conforms to a normal pattern, the third risk score is determined, and the third risk score is less than the second risk score.
4. The method according to claim 1, wherein Based on the device level, set access permission rules, including: Establishing a virtual local area network, wherein the virtual local area network isolates the communication of the IoT devices; Establishing a secure communication channel between the IoT devices through the virtual local area network, wherein the secure communication channel is used to realize encrypted data transmission between the IoT devices; Communication authority verification is performed on the secure communication channel to prevent unauthorized devices from passing through the secure communication channel.
5. The method according to claim 4, characterized in that Establishing a secure communication channel between the IoT devices through the virtual local area network specifically includes: generating an encryption key based on a unique identifier of the IoT device; Establishing a secure communication channel through the virtual local area network according to the encryption key, wherein the secure communication channel is an end-to-end encrypted channel; Allocate the secure communication channel of the high-risk device to an independent virtual local area network, wherein the independent virtual local area network is used to isolate and protect the high-risk device; The secure communication channel of the medium-risk device is allocated to a shared virtual local area network, and the shared virtual local area network restricts direct communication with the high-risk device.
6. The method according to claim 1, characterized in that Reclassify the risk level of the abnormal device to obtain a new device level. If the new device level is high risk, block the communication of the abnormal device, specifically including: Upon detecting an abnormal traffic pattern, recalculating the risk score of the abnormal device; If the risk score exceeds a high risk threshold, the device level of the abnormal device is adjusted to obtain a new device level of high risk; If the new device level is high risk, the abnormal device is isolated through an independent virtual local area network to block its external network access rights.
7. The method according to claim 1, characterized in that After blocking the communication of the abnormal device if the new device level is high risk, the method further includes: Copying the real-time communication traffic of the high-risk abnormal device to obtain traffic mirror data; Performing a security analysis on the traffic mirror data to determine whether the abnormal device has unupdated firmware, known vulnerabilities, or abnormal configurations, wherein the security analysis includes detecting firmware versions, open ports, system logs, and security configuration status to identify potential vulnerabilities or unpatched weaknesses; If it is detected that the abnormal device has unupdated firmware or known vulnerabilities, install the latest security patch or firmware update; If it is detected that the abnormal device has an abnormal configuration, resetting the access permission rules of the abnormal device; After the repair is completed, the risk level of the abnormal device is re-evaluated and the new device level is updated; If the new device level is reduced to medium risk or low risk, the isolation is lifted and the communication permission is restored.
8. A hierarchical security management and control system for IoT devices in a smart park, characterized by: including one or more processors and memory; The memory is coupled to the one or more processors, and the memory is used to store computer program code, where the computer program code includes computer instructions. The one or more processors call the computer instructions to enable the self-service baggage check-in equipment failure prediction system to execute the method according to any one of claims 1 to 7.
9. A computer-readable storage medium storing computer instructions, characterized in that: When the computer instructions are executed on a self-service baggage check-in equipment failure prediction system, the self-service baggage check-in equipment failure prediction system is caused to execute the method according to any one of claims 1 to 7.
10. A computer program product, characterized in that When the computer program product is run on a self-service baggage check-in equipment failure prediction system, the self-service baggage check-in equipment failure prediction system is caused to execute the method according to any one of claims 1 to 7.
Citation Information
Patent Citations
System and method for defending network attack in mobile network
CN101111053A
VXLAN-based method for triggering a dynamic secure channel, user side and central control board
CN113676390A
Security service system, access control method and computer readable storage medium
CN114640514A
Method, system and device for carrying out network security protection on Internet of Things system
CN116405260A
Authorization management method and device, electronic equipment and storage medium
CN117763580A
Cited By
Internet of things card equipment grouping optimization method and system based on network state awareness
CN121396795A