Internet of Things data security management system based on network security

By generating multi-dimensional feature vectors and dynamic behavior baselines, combining multi-device collaborative backtracking instructions, and analyzing attack risks, accurate anomaly identification and efficient protection of device behavior in the IoT system are achieved, solving the problems of insufficient device adaptation and slow policy synchronization in existing technologies.

CN120692097AActive Publication Date: 2025-09-23XINJIANG RUISHU YUNDING INFORMATION TECH CO LTD

Patent Information

Application Number
CN202511166561.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-20
Publication Date
2025-09-23
Estimated Expiration
2045-08-20

AI Technical Summary

Technical Problem

In existing technologies, IoT systems have insufficient adaptation to dynamic device behaviors, lack of multi-device collaboration, weak identification of new attacks, and slow policy synchronization, resulting in anomaly identification being easily affected by fluctuations in device behavior and difficulty in responding to complex and changing security threats.

Method used

By obtaining the operating parameters of IoT devices, generating multi-dimensional feature vectors, building a dynamic behavior baseline, calculating anomaly scores, combining multi-device collaborative backtracking instructions, analyzing instruction characteristics and attack risks, activating isolation and baseline updates, and achieving closed-loop response.

Benefits of technology

It improves the accuracy of anomaly identification, enhances the ability to detect unknown attacks, ensures efficient synchronization of protection strategies, and effectively responds to complex security threats in the IoT environment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120692097A_ABST
    Figure CN120692097A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of network security and data security management, and particularly provides an Internet of Things data security management system based on network security, and the system mainly comprises a multi-dimensional feature generation module which is used for obtaining operation parameters of Internet of Things equipment, carrying out the preprocessing of the operation parameters, and obtaining a multi-dimensional feature vector; and the dynamic abnormal score generation module is used for constructing a dynamic behavior baseline based on historical multi-dimensional feature vector clustering, calculating the deviation degree of the current multi-dimensional feature vector relative to the baseline, and obtaining a preliminary abnormal score. According to the method and the device, the problems of insufficient equipment dynamic behavior adaptation, insufficient multi-equipment cooperation, weak novel attack identification and slow strategy synchronization in the prior art are effectively solved, and the effects of improving the anomaly identification accuracy, enhancing the unknown attack detection capability and guaranteeing efficient synchronization of the protection strategy are achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of network security and data security management, and in particular relates to an Internet of Things data security management system based on network security. Background Art

[0002] IoT data security management is the core link to ensure the stable operation of the IoT system. It mainly collects device operation data, builds security models to identify abnormal behaviors, relies on attack feature libraries to judge potential risks, and maintains the security of device communication and data transmission.

[0003] When the system detects that a device may have a security risk, the response mechanism is activated, often initiating isolation based on a single device anomaly and enhancing defense by updating rules. However, there are limitations in adapting to the dynamic behavior of the device, and in risk assessment and processing, there is a lack of effective collaboration between multiple devices, resulting in abnormal identification being susceptible to deviations caused by fluctuations in device behavior. The ability to identify new attacks is insufficient, and it is difficult to quickly synchronize security policies to associated devices after updates, which limits the protection effect and makes it difficult to cope with complex and changing security threats in the IoT environment. Summary of the Invention

[0004] This application provides an Internet of Things data security management system based on network security, which effectively solves the problems in the existing technology of insufficient adaptation to dynamic device behavior, lack of multi-device collaboration, weak identification of new attacks and slow policy synchronization, and achieves the effect of improving the accuracy of anomaly identification, enhancing the ability to detect unknown attacks and ensuring efficient synchronization of protection strategies.

[0005] In order to achieve the above object, the present invention adopts the following technical solutions: In a first aspect, the present application provides a method for managing IoT data security based on network security, comprising: The operating parameters of the IoT device are obtained and preprocessed to obtain a multidimensional feature vector; wherein the multidimensional feature vector includes a historical multidimensional feature vector and a current multidimensional feature vector.

[0006] A dynamic behavior baseline is constructed based on clustering of historical multidimensional feature vectors, and the deviation of the current multidimensional feature vector from the baseline is calculated to obtain a preliminary anomaly score.

[0007] An anomaly scoring matrix is ​​constructed based on the preliminary anomaly scores of at least three devices under the same gateway. A suspicious instruction label is generated through a majority voting mechanism, which triggers the backtracking of operation instructions and outputs the instruction sequence to be confirmed.

[0008] The instruction sequence to be confirmed is disassembled to generate instruction structure features. After matching with the known attack feature library, context semantic analysis and instruction evolution trajectory detection are performed on unknown attacks to output the attack risk index.

[0009] Activate device isolation based on risk index, update dynamic behavior baselines and synchronize devices in the same group, and implement closed-loop response control through defense effectiveness verification.

[0010] Furthermore, the operating parameters include at least three parameters of temperature sensor data, voltage and current data, communication flow value, memory occupancy rate, and CPU usage rate.

[0011] Furthermore, the operating parameters are preprocessed to obtain a multi-dimensional feature vector, including: Perform physical threshold filtering on real-time operating parameters to generate a basic operating parameter set.

[0012] The basic operating parameter set is resampled at equal intervals to generate time-aligned sampling data.

[0013] The multi-source sensor data in the time-aligned sampling data are subjected to feature fusion to generate a multi-dimensional feature vector.

[0014] Furthermore, a dynamic behavior baseline is constructed, including: An unsupervised clustering algorithm is used to identify normal data in historical multidimensional feature vectors and generate behavioral pattern cluster centers.

[0015] Based on the behavior pattern cluster center and the operating parameters in the recent specified time, the adaptive floating threshold is calculated to generate a dynamic behavior baseline.

[0016] Furthermore, the majority voting mechanism satisfies the following requirement: when the preliminary anomaly score of a single device reaches a preset specified ratio among the other devices under the same gateway and is judged to be abnormal, the operation instruction backtracking process is triggered.

[0017] Furthermore, the command evolution trajectory detection is performed on unknown attacks, including: Obtain the sequence of instructions to be confirmed and the historical records of similar instructions within a preset time range, and build a trajectory diagram of the instruction behavior evolution.

[0018] Identify whether there are cumulative parameter deviations or periodic trial call patterns in the instruction behavior evolution trajectory diagram. If so, mark potential latent attack behavior.

[0019] Furthermore, the generation of the attack risk index needs to meet the following requirements: when the known attack is determined to be an unknown attack, the potential latent attack behavior mark is incorporated into the context semantic analysis as a risk coefficient weight to regenerate the attack risk index.

[0020] Furthermore, the closed-loop response control includes: When the enhanced new attack risk index exceeds the critical value, the device isolation protocol is activated and a security blocking instruction is generated.

[0021] Update the dynamic behavior baseline of the affected device based on the security blocking instruction and generate baseline correction parameters.

[0022] Synchronize the baseline correction parameters to the security policy library of all devices in the same group; collect the real-time operating parameters of the device after the security blocking instruction is executed, compare them with the preset expected security status parameters, and output the defense effectiveness status indicator.

[0023] Furthermore, the defense effectiveness status flag triggers the following branch: If the defense effectiveness status flag is valid, a safety confirmation signal is generated.

[0024] If the defense effectiveness status is marked as invalid, the step of detecting the instruction behavior evolution trajectory is re-executed.

[0025] Furthermore, the operation instruction backtracking mechanism is specifically as follows: for the instruction sequence associated with the suspicious instruction tag, the operation code sequence and data payload are extracted.

[0026] In a second aspect, the present application provides an Internet of Things data security management system based on network security, which includes: Multidimensional feature generation module: obtains the operating parameters of the IoT device, preprocesses the operating parameters, and obtains a multidimensional feature vector; wherein the multidimensional feature vector includes a historical multidimensional feature vector and a current multidimensional feature vector.

[0027] Dynamic anomaly score generation module: constructs a dynamic behavior baseline based on historical multidimensional feature vector clustering, calculates the deviation of the current multidimensional feature vector from the baseline, and obtains a preliminary anomaly score.

[0028] Collaborative attack instruction backtracking module: Builds an anomaly scoring matrix based on the preliminary anomaly scores of at least three devices under the same gateway, generates suspicious instruction labels through a majority voting mechanism, triggers operation instruction backtracking, and outputs the instruction sequence to be confirmed.

[0029] Enhanced risk analysis module: disassembles the instruction sequence to be confirmed to generate instruction structure features. After matching the known attack feature library, it performs contextual semantic analysis and instruction evolution trajectory detection on unknown attacks and outputs the attack risk index.

[0030] Closed-loop security response module: Activates device isolation based on risk index, updates dynamic behavior baselines and synchronizes devices in the same group, and implements closed-loop response control through defense effectiveness verification.

[0031] In a third aspect, the present application provides an Internet of Things data security management device based on network security, which includes a memory and a processor; the memory is used to store computer programs; and the processor is used to implement the steps of the Internet of Things data security management method based on network security as described in the first aspect when executing the computer program.

[0032] In a fourth aspect, the present application provides a storage medium storing computer program instructions. When the computer program instructions are read and executed by a processor, the steps of the Internet of Things data security management method based on network security as described in the first aspect are executed.

[0033] Beneficial effects of the present invention: This application obtains device operating parameters to generate multi-dimensional feature vectors, constructs a dynamic behavior baseline to calculate anomaly scores, combines multi-device collaborative backtracking instructions, analyzes instruction characteristics and attack risks, and finally activates isolation and baseline updates to achieve a closed-loop response solution. It effectively solves the problems of insufficient adaptation to device dynamic behavior, lack of multi-device collaboration, weak identification of new attacks, and slow strategy synchronization in the existing technology, and achieves the effect of improving the accuracy of anomaly identification, enhancing the ability to detect unknown attacks, and ensuring efficient synchronization of protection strategies.

[0034] Other features and advantages of the present invention will be described in the following description, and in part will become apparent from the description, or will be understood by practicing the present invention. The purpose and other advantages of the present invention can be realized and obtained by the structures pointed out in the description and the drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0035] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following is a brief introduction to the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0036] Figure 1 A schematic diagram of the Internet of Things data security management system based on network security of the present invention is shown. DETAILED DESCRIPTION

[0037] In order to solve the problems raised by the background technology, this application obtains device operating parameters to generate multi-dimensional feature vectors, constructs a dynamic behavior baseline to calculate anomaly scores, combines multi-device collaborative backtracking instructions, analyzes instruction characteristics and attack risks, and finally activates isolation and baseline updates to achieve a closed-loop response solution.

[0038] To make the objectives, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the present invention.

[0039] In some embodiments, the present application provides a method for managing IoT data security based on network security, including: S1. Obtain operating parameters of the IoT device, preprocess the operating parameters, and obtain a multidimensional feature vector; wherein the multidimensional feature vector includes a historical multidimensional feature vector and a current multidimensional feature vector.

[0040] S2. Construct a dynamic behavior baseline based on historical multidimensional feature vector clustering, calculate the deviation of the current multidimensional feature vector from the baseline, and obtain a preliminary anomaly score.

[0041] S3. Build an anomaly scoring matrix based on the preliminary anomaly scores of at least three devices under the same gateway, generate suspicious instruction labels through a majority voting mechanism, trigger operation instruction backtracking, and output the instruction sequence to be confirmed.

[0042] S4. Disassemble the instruction sequence to be confirmed to generate instruction structure features. After matching the known attack feature library, perform context semantic analysis and instruction evolution trajectory detection on the unknown attack, and output the attack risk index.

[0043] S5. Activate device isolation based on risk index, update dynamic behavior baselines and synchronize devices in the same group, and implement closed-loop response control through defense effectiveness verification.

[0044] In some embodiments, the operating parameters are preprocessed in S1 to obtain a multi-dimensional feature vector, including: S11. Perform physical threshold filtering on the real-time operating parameters to generate a basic operating parameter set.

[0045] The operating parameters include temperature sensor data, voltage and current data, and communication flow values.

[0046] Temperature sensor data comes from temperature sensors deployed on IoT devices. This parameter collects the real-time temperature values ​​of the core components of the device.

[0047] Voltage and current data are generated by the device power management module and include real-time voltage and current values. They are used to analyze the device power supply stability. Abnormal voltage fluctuations may indicate a circuit attack.

[0048] The communication traffic value records the data transmission rate of the device network interface and can be directly obtained through the device network card chip. It reflects abnormal device communication behavior. For example, sudden traffic may indicate data leakage.

[0049] The physical threshold is determined according to the safety specifications provided by the device manufacturer. For example, the valid range of temperature sensor data is -40°C to 85°C. If the real-time temperature sensor data is 90°C, it is filtered out because it exceeds the physical threshold range.

[0050] The basic operating parameter set only contains valid parameter values ​​that meet the physical safety threshold. For example, after filtering, three valid parameters are obtained: voltage and current data 12.3V / 0.5A, communication traffic value 120Kbps, and memory usage rate 65%.

[0051] S12. Resample the basic operating parameter set at equal intervals to generate time-aligned sampling data.

[0052] Since the sampling frequencies of different sensor data vary, for example, the temperature sensor collects data once per second and the communication traffic value collects data 10 times per second, it is necessary to unify the multi-source data to a fixed timestamp through linear interpolation.

[0053] S13. Perform feature fusion on the multi-source sensor data in the time-aligned sampling data to generate a multi-dimensional feature vector.

[0054] Voltage and current data can be converted into power characteristics. For example, if the voltage is 12.0V and the current is 0.6A, the power is The communication traffic value and memory usage are combined into the network load characteristics. For example, if the communication traffic value is 150Kbps and the memory usage is 70%, the network load is .

[0055] Finally, the power characteristics, network load characteristics, etc. are combined into a multidimensional vector, including time-aligned fusion feature values.

[0056] In some embodiments, constructing a dynamic behavior baseline in S2 includes: S21. Use unsupervised clustering algorithm to identify normal data in historical multidimensional feature vectors and generate behavioral pattern cluster centers.

[0057] The clustering algorithm measures the similarity between vectors through Euclidean distance, classifies similar feature vectors into the same cluster, and the generated behavior pattern cluster center represents the typical feature value of the historical normal behavior pattern.

[0058] For example, the historical data of 10 lighting devices under a gateway are clustered into two main clusters: Cluster center 1 corresponds to normal working mode: voltage 220V±5%, temperature 35℃±2℃, flow rate 1KB / s±0.2).

[0059] Cluster center 2 corresponds to energy-saving mode: voltage 110V±3%, temperature 28℃±1℃, flow rate 0.5KB / s±0.1).

[0060] S22. Based on the behavioral pattern cluster center and the operating parameters within the most recent specified time, calculate the adaptive floating threshold and generate a dynamic behavioral baseline.

[0061] The length of the specified time window is preset according to the device type, such as 24 hours for gateway devices.

[0062] For each behavioral pattern cluster center, calculate the Euclidean distance set between the center and all corresponding pattern operating parameters in the last 24 hours, take the standard deviation of the distance set and multiply it by the preset coefficient K to generate the floating threshold of this dimension; where the coefficient K is determined by the equipment security level.

[0063] Finally, the floating thresholds of all dimensions are combined to form the dynamic behavior baseline.

[0064] For example, the voltage cluster center is 220 V, and the standard deviation of the voltage value in normal working mode in the last 24 hours is 4.2 V. If K = 1.5, the voltage dimension floating threshold is set to ±6.3 V (4.2 × 1.5). The final dynamic behavior baseline includes [temperature floating threshold ±2.5°C, voltage floating threshold ±6.3 V, and traffic floating threshold ±0.3 KB / s].

[0065] The process of generating the deviation and preliminary anomaly score includes the following steps: 1. For each dimension value (such as temperature, voltage, and flow) of the current multidimensional feature vector, calculate the absolute difference between it and the behavior pattern cluster center of the corresponding dimension of the dynamic behavior baseline.

[0066] 2. Divide the single-dimensional deviation distance by the adaptive floating threshold of the corresponding dimension in the dynamic behavior baseline to obtain the normalized deviation. If the normalized deviation is greater than 1, the corresponding dimension is abnormal.

[0067] 3. Take the maximum value of the standardized deviations of all dimensions as the preliminary anomaly score.

[0068] In some embodiments, when constructing the anomaly score matrix in S3, the rows of the matrix may be device identifiers under the same gateway, the columns may be continuous time windows, and the element values ​​may be the preliminary anomaly scores of the devices in the time windows.

[0069] In some embodiments, the majority voting mechanism in S3 satisfies the following conditions: when the preliminary anomaly score of a single device reaches a preset specified ratio among the rest of the devices under the same gateway and is judged to be abnormal, the operation instruction backtracking process is triggered.

[0070] The preset specified ratio can be pre-set to exclude the data of the detected device itself during calculation.

[0071] The specific execution process is as follows: count the number of abnormal judgments of the preliminary abnormality score of the target device by all devices under the same gateway except this device. When the number of abnormal judgments divided by the total number of other devices under the same gateway reaches or exceeds the preset specified ratio, a suspicious instruction label is generated and the operation instruction backtracking is activated, and finally the sequence of instructions to be confirmed after the backtracking is triggered is obtained.

[0072] For example, a gateway has four devices (devices A, B, C, and D). When detecting an abnormal state of device A, device B determines that the preliminary abnormality score of device A is abnormal; device C determines that the preliminary abnormality score of device A is abnormal; and device D determines that the preliminary abnormality score of device A is normal.

[0073] If the preset specified ratio is set to , then the abnormal judgment ratio is calculated as: the number of abnormal devices accounts for the total number of devices , reaching the preset ratio threshold, triggering the operation instruction backtracking of device A.

[0074] Output the instruction sequence to be confirmed corresponding to device A, for example, extract all the operation code sequences and data payloads executed in the last 5 minutes.

[0075] In some embodiments, disassembling the instruction sequence to be confirmed in S4 specifically involves performing in-depth analysis on the instruction sequence to be confirmed to generate two types of core features: operation code sequence features and parameter statistical features.

[0076] The opcode sequence features include extracting the frequency distribution of opcodes, calculating the length of opcode sequences, and recording sensitive opcode combinations.

[0077] Parameter statistical features include the mean and variance of numerical parameters (such as port numbers and temperature values) and the entropy of character parameters (such as keys and IP addresses).

[0078] The obtained instruction structure features include the concatenation result of the operation code feature vector and the parameter feature vector.

[0079] The similarity between the instruction structure features and the predefined attack pattern features in the known attack feature library is calculated, and a judgment threshold is set. If the similarity reaches the judgment threshold, it is determined to be a known attack, otherwise it is marked as an unknown attack, and context semantic analysis and instruction evolution trajectory detection are triggered.

[0080] The judgment threshold is determined by the historical matching accuracy statistics of the known attack signature library.

[0081] In some embodiments, the step S4 of detecting the unknown attack instruction evolution trajectory includes: S41. Obtain the sequence of instructions to be confirmed and the historical records of similar instructions within a preset specified time range, and construct an instruction behavior evolution trajectory diagram.

[0082] The instruction sequence to be confirmed comes from the suspicious operation instructions output by the coordinated attack instruction backtracking module, which includes the operation code sequence and data payload.

[0083] The preset time range is determined by the analysis results of historical attack latency periods of similar devices. For example, it is set to 240 hours for temperature control devices.

[0084] Extract instruction sequences with the same opcode from the historical records of similar instructions, sort them by timestamp, and form a three-dimensional dataset consisting of time points, opcode types, and parameter values. The resulting instruction behavior evolution trajectory graph is output. The horizontal axis of the evolution trajectory graph is the timeline, and the vertical axis is the operation parameter values.

[0085] For example, the sequence of instructions to be confirmed of a gateway device includes a port scanning instruction. The time points and target port numbers of all port scanning operations within 240 hours are extracted to generate a port number-time relationship evolution graph.

[0086] S42. Identify whether there is a cumulative parameter deviation or a periodic trial call pattern in the instruction behavior evolution trajectory diagram. If so, mark the potential latent attack behavior.

[0087] The cumulative parameter deviation judgment standard is: a one-way change in a key parameter that exceeds a specified number of times (such as 10 times) in a row (such as a continuous increase in the port number from 1000 to 65535).

[0088] The criterion for determining periodic probing calls is that the same sensitive opcode appears a specified number of times at a fixed interval. For example, if an illegal protocol handshake is initiated three times in a row every eight hours, it will be considered a periodic probing call and flagged as a potential latent attack.

[0089] If any pattern is detected, a potential attack behavior flag is output.

[0090] In some embodiments, the generation of the attack risk index in S4 must meet the following requirements: when the known attack is determined to be an unknown attack, the potential latent attack behavior mark is incorporated into the contextual semantic analysis as a risk coefficient weight to regenerate the attack risk index.

[0091] Specifically, when a known attack is marked as an unknown attack, the following operations are performed: 1. Obtain the status value of the potential latent attack behavior marker: If there is a cumulative parameter deviation or a periodic trial call pattern, set the weight coefficient ω to 0.3; otherwise ω = 0.

[0092] 2. Execution context semantic analysis: Analyze the logical relevance of the opcodes in the instruction sequence to be confirmed and output the basic risk value in percentage form .

[0093] 3. Calculate the attack risk index , .

[0094] In some embodiments, the closed-loop response control in S5 includes: S51. When the enhanced new attack risk index exceeds the critical value, the device isolation protocol is activated and a security blocking instruction is generated.

[0095] The critical value is determined by the minimum risk value statistics of high-risk attack events in the known attack signature library.

[0096] The device isolation protocol cuts off the physical connection between the target device and the network and generates a security blocking instruction containing the device ID, isolation timestamp, and blocking instruction code.

[0097] For example, the attack risk index of the air-conditioning equipment reaches 84.5%, exceeding the critical value of 80%, and a security blocking instruction is generated.

[0098] S52. Update the dynamic behavior baseline of the affected device based on the security blocking instruction and generate baseline correction parameters.

[0099] The correction logic of the dynamic behavior baseline is as follows: add an attack isolation state mode to the behavior pattern cluster center, use the operating parameters when the security blocking instruction is triggered as the benchmark, recalculate the adaptive floating threshold under this mode, and finally obtain the baseline correction parameters including the center coordinates and floating threshold of the newly added mode.

[0100] For example, when a certain air conditioner is blocked, its parameters are [temperature 32°C, voltage 240V, traffic 0bps]. Based on this, a new mode center [32,240,0] is generated. The floating threshold is then calculated to be ±1.5°C. The final baseline correction parameters are {Mode: Attack_Isolated, Center: [32,240,0], Threshold: [±1.5°C,±5V,±0bps]}.

[0101] S53. Synchronize the baseline correction parameters to the security policy library of all devices in the same group; collect the real-time operating parameters of the device after the security blocking instruction is executed, compare them with the preset expected security status parameters, and output the defense effectiveness status indicator.

[0102] The expected security status parameters are preset by the device security policy. For example, the isolated device should meet the following requirements: network traffic = 0, CPU usage < 5%, etc.

[0103] The comparison rule is: if the deviation between the actual value and the expected value of each parameter is ≤5%, it is considered to be in compliance.

[0104] The output result is a defense effectiveness status indicator: if all parameters meet expectations, it is marked as "valid"; if any parameter exceeds the tolerance, it is marked as "invalid".

[0105] In some embodiments, the defense effectiveness status indicator in S53 triggers the following branches: If the defense effectiveness status flag is valid, a safety confirmation signal is generated.

[0106] If the defense effectiveness status is marked as invalid, the step of detecting the instruction behavior evolution trajectory is re-executed.

[0107] When the defense effectiveness status indicator is marked as "valid", it means that the device isolation measures are fully effective. The generated security confirmation signal contains the unique identifier of the isolated device, the security status timestamp, and the defense effectiveness code, which is used to notify the management platform to lift the alarm.

[0108] When the defense effectiveness status flag is marked as "invalid", it means that the isolation measures have not met expectations, and the instruction evolution trajectory detection step is re-executed.

[0109] Re-execution requires clearing the original instruction sequence cache to be confirmed, obtaining the latest historical records of similar instructions within the preset specified time range, and outputting the updated instruction behavior evolution trajectory diagram and potential latent attack behavior markers.

[0110] For example, the measured CPU usage of a certain access control device after blocking is 48%. If the expected value is <10%, the deviation of 380% triggers an invalid flag. The card swiping instruction record of the device within 72 hours (historical record of similar instructions) is retrieved, and a new instruction behavior evolution trajectory diagram is constructed to re-analyze the attack mode.

[0111] In some embodiments, the operation instruction backtracking mechanism in S3 is specifically: extracting the operation code sequence and data payload for the instruction sequence associated with the suspicious instruction tag.

[0112] The opcode sequence represents a set of atomic instruction codes arranged in chronological order, such as 0x01 temperature setting and 0x02 port listening.

[0113] The data payload represents the parameter value associated with each operation code, such as the temperature setting value 32°C and the port number 8080.

[0114] Specifically, the suspicious instruction tag contains the unique identifier of the device being judged and the time point of the abnormality. It intercepts the instruction code stream of the device that is a specified time (such as 5 minutes) before the abnormal time point, binds the specific parameter values ​​of each operation code, organizes the data according to the timestamp, operation code, and data payload triple structure, and outputs a sequence of instructions to be confirmed containing complete instruction data.

[0115] In some embodiments, as Figure 1 As shown, the present application provides an Internet of Things data security management system based on network security, which includes: Multidimensional feature generation module: obtains the operating parameters of the IoT device, preprocesses the operating parameters, and obtains a multidimensional feature vector; wherein the multidimensional feature vector includes a historical multidimensional feature vector and a current multidimensional feature vector.

[0116] Dynamic anomaly score generation module: constructs a dynamic behavior baseline based on historical multidimensional feature vector clustering, calculates the deviation of the current multidimensional feature vector from the baseline, and obtains a preliminary anomaly score.

[0117] Collaborative attack instruction backtracking module: Builds an anomaly scoring matrix based on the preliminary anomaly scores of at least three devices under the same gateway, generates suspicious instruction labels through a majority voting mechanism, triggers operation instruction backtracking, and outputs the instruction sequence to be confirmed.

[0118] Enhanced risk analysis module: disassembles the instruction sequence to be confirmed to generate instruction structure features. After matching the known attack feature library, it performs contextual semantic analysis and instruction evolution trajectory detection on unknown attacks and outputs the attack risk index.

[0119] Closed-loop security response module: Activates device isolation based on risk index, updates dynamic behavior baselines and synchronizes devices in the same group, and implements closed-loop response control through defense effectiveness verification.

[0120] In some embodiments, the present application provides an Internet of Things data security management device based on network security, which includes a memory and a processor; the memory is used to store computer programs; and the processor is used to implement the steps of the Internet of Things data security management method based on network security when executing the computer program.

[0121] In some embodiments, the present application provides a storage medium storing computer program instructions. When the computer program instructions are read and executed by a processor, the steps of the Internet of Things data security management method based on network security are executed.

[0122] Any reference to memory, storage, database, or other media used in the embodiments provided herein may include non-volatile and / or volatile memory. Non-volatile memory may include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory may include random access memory (RAM) or external cache memory.

[0123] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, article, or device that includes a series of elements includes not only those elements, but also other elements that are not explicitly listed, or elements that are inherent to such process, method, article, or device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or device that includes the element.

[0124] Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. An Internet of Things data security management system based on network security, characterized in that: include: Multidimensional feature generation module: obtains the operating parameters of the IoT device, preprocesses the operating parameters, and obtains a multidimensional feature vector; the multidimensional feature vector includes a historical multidimensional feature vector and a current multidimensional feature vector; Dynamic anomaly score generation module: This module builds a dynamic behavior baseline based on historical multidimensional feature vector clustering, calculates the deviation of the current multidimensional feature vector from the baseline, and obtains a preliminary anomaly score. Collaborative attack command backtracking module: This module constructs an anomaly scoring matrix based on the preliminary anomaly scores of at least three devices under the same gateway. It generates suspicious command labels through a majority voting mechanism, triggers command backtracking, and outputs a sequence of commands to be confirmed. Enhanced risk analysis module: This module disassembles the instruction sequence to be confirmed to generate instruction structure features. After matching the known attack feature library, it performs contextual semantic analysis and instruction evolution trajectory detection on unknown attacks, and outputs an attack risk index. Closed-loop security response module: Activates device isolation based on risk index, updates dynamic behavior baselines and synchronizes devices in the same group, and implements closed-loop response control through defense effectiveness verification.

2. The Internet of Things data security management system based on network security according to claim 1 is characterized in that: The operating parameters include at least three parameters of temperature sensor data, voltage and current data, communication traffic value, memory usage, and CPU usage.

3. The Internet of Things data security management system based on network security according to claim 1 is characterized in that: Preprocess the operating parameters to obtain a multi-dimensional feature vector, including: Perform physical threshold filtering on real-time operating parameters to generate a basic operating parameter set; The basic operating parameter set is resampled at equal intervals to generate time-aligned sampling data; The multi-source sensor data in the time-aligned sampling data are subjected to feature fusion to generate a multi-dimensional feature vector.

4. The Internet of Things data security management system based on network security according to claim 1 is characterized in that: Build a dynamic behavioral baseline, including: An unsupervised clustering algorithm is used to identify normal data in historical multidimensional feature vectors and generate behavioral pattern cluster centers; Based on the behavior pattern cluster center and the operating parameters in the recent specified time, the adaptive floating threshold is calculated to generate a dynamic behavior baseline.

5. The Internet of Things data security management system based on network security according to claim 1 is characterized in that: The majority voting mechanism satisfies the following conditions: When the initial anomaly score of a single device reaches a preset specified ratio among the other devices under the same gateway and is judged to be abnormal, the operation instruction backtracking process is triggered.

6. The Internet of Things data security management system based on network security according to claim 1 is characterized in that: Detect unknown attacks by following the instruction evolution trajectory, including: Obtain the sequence of instructions to be confirmed and the historical records of similar instructions within a preset time range, and build a trajectory diagram of the instruction behavior evolution; Identify whether there are cumulative parameter deviations or periodic trial call patterns in the instruction behavior evolution trajectory diagram. If so, mark potential latent attack behavior.

7. The Internet of Things data security management system based on network security according to claim 1 is characterized in that: The generation of the attack risk index must meet the following requirements: when the known attack is determined to be an unknown attack, the potential latent attack behavior mark is incorporated into the context semantic analysis as a risk coefficient weight to regenerate the attack risk index.

8. The Internet of Things data security management system based on network security according to claim 1 is characterized in that: Closed-loop response control includes: When the enhanced new attack risk index exceeds the critical value, the device isolation protocol is activated and a security blocking instruction is generated; Update the dynamic behavior baseline of the affected device based on the security blocking instruction and generate baseline correction parameters; Synchronize the baseline correction parameters to the security policy library of all devices in the same group; collect the real-time operating parameters of the device after the security blocking instruction is executed, compare them with the preset expected security status parameters, and output the defense effectiveness status indicator.

9. The Internet of Things data security management system based on network security according to claim 8, characterized in that: The defense effectiveness status flag triggers the following branches: If the defense effectiveness status is marked as valid, a safety confirmation signal is generated; If the defense effectiveness status is marked as invalid, the step of detecting the instruction behavior evolution trajectory is re-executed.

10. The Internet of Things data security management system based on network security according to claim 1, characterized in that: The specific operation instruction backtracking mechanism is: for the instruction sequence associated with the suspicious instruction tag, extract the operation code sequence and data payload.

Citation Information

Patent Citations

  • Network data monitoring method and system

    CN117633665A

  • Internet of Things security risk event prediction method and device

    CN117879892A

  • Internet of Things equipment data security management method and system

    CN118296611A

  • Data security analysis method and intelligent calculation data security workstation

    CN119249440A

  • Intelligent security data analysis decision method and system based on artificial intelligence

    CN120216929A

Cited By

  • Network security information big data analysis system capable of comparing historical data

    CN122179238A